bbace4f4...d9d2 | Kernel
Try VMRay Analyzer
VTI SCORE: 100/100
Dynamic Analysis Report
Classification: Spyware, Ransomware, Dropper

Kernel Graph 1

Kernel Graph

Kernel Graph Legend
Code Block #1 (EP #2)
»
Information Value
Trigger ExpWorkerThread+0x10f
Start Address 0xfffffa80019b9fc0
Execution Path #2 (length: 2, count: 1, processes: 1 incomplete)
»
Information Value
Sequence Length 2
Processes
»
Process Count
Process 35 (System, PID: 4) 1
Sequence
»
Symbol Parameters
ExAllocatePoolWithTag PoolType_unk = 0x0, NumberOfBytes_ptr = 0x1d259, Tag = 0x5746744e, ret_val_ptr_out = 0xfffffa80035b8000
KeDelayExecutionThread WaitMode_unk = 0x0, Alertable = 0, Interval_ptr = 0xfffff88002f885a8, Interval = -1266199646

Kernel Graph 2

Kernel Graph

Kernel Graph Legend
Code Block #2 (EP #1)
»
Information Value
Trigger unknown_0xfffffa800197b000+0xc0
Start Address 0xfffff8000289dc10
Execution Path #1 (length: 1, count: 1, processes: 1)
»
Information Value
Sequence Length 1
Processes
»
Process Count
Process 36 (ehrecvr.exe, PID: 1572) 1
Sequence
»
Symbol Parameters
ExQueueWorkItem WorkItem_ptr = 0xfffffa800197b240, WorkItem_deref_List.Flink_unk = 0x0, WorkItem_deref_List.Blink_unk = 0x0, WorkItem_deref_WorkerRoutine_unk = 0xfffffa800197fe35, WorkItem_deref_Parameter_ptr = 0xfffffa800197b000, QueueType_unk = 0x1, WorkItem_ptr_out = 0xfffffa800197b240, WorkItem_deref_List.Flink_unk_out = 0xfffff80002a2e670, WorkItem_deref_List.Blink_unk_out = 0xfffff80002a2ffc0, WorkItem_deref_WorkerRoutine_unk_out = 0xfffffa800197fe35, WorkItem_deref_Parameter_ptr_out = 0xfffffa800197b000
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image