c65df5ec5152af018ff362039351255ba7b59ea844639619f73d96ea135ab1f0 (SHA256)
CUsersGrujaAppDataRoaming6Xx3WI1ICfwJbN6F1OD~1.EXE
Created at 2019-01-18 08:45:00
Notifications (2/2)
The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.
The operating system was rebooted during the analysis.
Severity | Category | Operation | Classification | |
---|---|---|---|---|
5/5
|
File System | Encrypts content of user files | Ransomware | |
|
||||
5/5
|
Device | Writes to Master Boot Record (MBR) | - | |
|
||||
4/5
|
OS | Modifies Windows automatic backups | - | |
|
||||
4/5
|
File System | Known malicious file | Trojan | |
|
||||
3/5
|
Kernel | Executes code with kernel privileges | - | |
|
||||
2/5
|
Device | Sends control codes to connected devices | - | |
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
1/5
|
Process | Creates system object | - | |
|
||||
|
||||
1/5
|
Process | Creates process with hidden window | - | |
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
1/5
|
File System | Modifies application directory | - | |
|
||||
|
||||
1/5
|
File System | Creates an unusually large number of files | - | |
|
||||
1/5
|
PE | Drops PE file | Dropper | |
|
||||
|
||||
|