c04c541f...d341 | VTI
Try VMRay Analyzer
VTI SCORE: 100/100
Target: win7_64_sp1 | exe
Classification: Trojan, Dropper, Ransomware

c04c541f066a2b089bdc261616894a2f6bd49fca2e29350698175d9fc51cd341 (SHA256)

c04c541f066a2b089bdc261616894a2f6bd49fca2e29350698175d9fc51c.exe

Windows Exe (x86-32)

Created at 2018-07-13 07:59:00

Notifications (1/1)

The operating system was rebooted during the analysis.

Severity Category Operation Classification
5/5
File System Encrypts content of user files Ransomware
  • Encrypts the content of multiple user files. This is an indicator for ransomware.
5/5
Device Writes to Master Boot Record (MBR) -
4/5
OS Modifies Windows automatic backups -
4/5
File System Associated with malicious files Trojan
2/5
Hide Tracks Uses Alternate Data Stream (ADS) for interprocess communication -
2/5
Device Sends control codes to connected devices -
  • Controls device "C:\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000" through API DeviceIOControl.
  • Controls device "C:\MSOCache\All Users" through API DeviceIOControl.
  • Controls device "C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C" through API DeviceIOControl.
  • Controls device "C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C" through API DeviceIOControl.
  • Controls device "C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C" through API DeviceIOControl.
  • Controls device "C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C" through API DeviceIOControl.
  • Controls device "C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C" through API DeviceIOControl.
  • Controls device "C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C" through API DeviceIOControl.
  • Controls device "C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en" through API DeviceIOControl.
  • Controls device "C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es" through API DeviceIOControl.
  • Controls device "C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr" through API DeviceIOControl.
  • Controls device "C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C" through API DeviceIOControl.
  • Controls device "C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C" through API DeviceIOControl.
  • Controls device "C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C" through API DeviceIOControl.
  • Controls device "C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C" through API DeviceIOControl.
  • Controls device "C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C" through API DeviceIOControl.
  • Controls device "C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C" through API DeviceIOControl.
1/5
Process Creates system object -
  • Creates mutex with name "Global\{FD64C8AB-F74D-C8D4-F31D-96A1BB45705E}".
1/5
Process Creates process with hidden window -
  • The process "C:\Users\5P5NRG~1\AppData\Roaming\VQBKVY~1:bin" starts with hidden window.
  • The process "C:\Windows\system32\vssadmin.exe" starts with hidden window.
  • The process "C:\Windows\system32\diskshadow.exe" starts with hidden window.
  • The process "C:\Windows\system32\icacls.exe" starts with hidden window.
  • The process "C:\Users\5P5NRG~1\AppData\Roaming\\V5HW0H~1:bin" starts with hidden window.
  • The process "C:\Windows\system32\arp.exe" starts with hidden window.
  • The process "C:\Windows\system32\nslookup.exe" starts with hidden window.
  • The process "C:\Windows\system32\net.exe" starts with hidden window.
1/5
File System Modifies operating system directory -
  • Modifies file "C:\Windows\servicing\TrustedInstaller.exe" in the OS directory.
  • Modifies file "C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe" in the OS directory.
  • Creates file "C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe:0" in the OS directory.
1/5
File System Creates an unusually large number of files -
1/5
PE Drops PE file Dropper
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image