cc30bd2a...7a80 | VMRay Analyzer Report
Try VMRay Analyzer
VTI SCORE: 100/100
Dynamic Analysis Report
Classification: Ransomware

Remarks (2/2)

(0x200000e): The overall sleep time of all monitored processes was truncated from "1 minute, 30 seconds" to "30 seconds" to reveal dormant functionality.

(0x2000004): The operating system was rebooted during the analysis because the sample installed a startup script, task or application for persistence.

VMRay Threat Indicators (15 rules, 471 matches)

Severity Category Operation Count Classification
5/5
File System Encrypts content of user files 1 Ransomware
  • Encrypts the content of multiple user files. This is an indicator for ransomware.
5/5
Local AV Malicious content was detected by heuristic scan 1 -
4/5
OS Modifies Windows automatic backups 1 -
3/5
OS Modifies system security configuration 1 -
3/5
File System Possibly drops ransom note files 1 Ransomware
  • Possibly drops ransom note files (creates 266 instances of the file "Decoding help.hta" in different locations).
2/5
Information Stealing Reads sensitive browser data 1 -
  • Trying to read sensitive data of web browser "Google Chrome" by file.
1/5
Persistence Installs system startup script or application 2 -
  • Adds ""c:\Decoding help.hta"" to Windows startup via registry.
  • Adds "C:\windows\searchfiles.exe" to Windows startup via registry.
1/5
File System Modifies operating system directory 1 -
1/5
Hide Tracks Writes an unusually large amount of data to the registry 1 -
  • Hides 1280 byte in "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DateTime\\rsa".
1/5
Process Creates process with hidden window 1 -
  • The process "C:\Windows\system32\cmd.exe" starts with hidden window.
1/5
File System Modifies application directory 427 -
  • Modifies "c:\program files\microsoft synchronization services\ado.net\v1.0\microsoft.synchronization.data.dll.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files\microsoft synchronization services\ado.net\v1.0\microsoft.synchronization.data.server.dll.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files\microsoft synchronization services\ado.net\v1.0\microsoft.synchronization.data.sqlserverce.dll.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\office14\1033\decoding help.hta".
  • Modifies "c:\program files\microsoft office\media\office14\decoding help.hta".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\decoding help.hta".
  • Modifies "c:\program files\microsoft office\stationery\1033\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppcext.dll.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\reference assemblies\microsoft\framework\v3.0\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\ink\en-us\decoding help.hta".
  • Modifies "c:\program files\windows sidebar\gadgets\clock.gadget\decoding help.hta".
  • Modifies "c:\program files\windows sidebar\gadgets\rssfeeds.gadget\decoding help.hta".
  • Modifies "c:\program files\windows sidebar\gadgets\weather.gadget\decoding help.hta".
  • Modifies "c:\program files\windows sidebar\gadgets\cpu.gadget\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\ink\1.7\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\ca_es\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\translat\esen\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\ink\1.0\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\portal\1033\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\translat\fren\decoding help.hta".
  • Modifies "c:\program files (x86)\microsoft analysis services\as oledb\10\cartridges\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\decoding help.hta".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\publicassemblies\decoding help.hta".
  • Modifies "c:\program files\microsoft office\office14\1033\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\translat\enes\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\aftrnoon\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\translat\frar\decoding help.hta".
  • Modifies "c:\program files\windows sidebar\gadgets\currency.gadget\decoding help.hta".
  • Modifies "c:\program files\windows sidebar\gadgets\picturepuzzle.gadget\decoding help.hta".
  • Modifies "c:\program files\microsoft office\media\cagcat10\decoding help.hta".
  • Modifies "c:\program files\microsoft office\clipart\pub60cor\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\vsto\10.0\decoding help.hta".
  • Modifies "c:\program files\windows sidebar\gadgets\mediacenter.gadget\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\ar-sa\decoding help.hta".
  • Modifies "c:\program files (x86)\reference assemblies\microsoft\framework\v3.5\decoding help.hta".
  • Modifies "c:\program files\microsoft office\templates\1033\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\blueprnt\decoding help.hta".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\vsta\bin\1033\decoding help.hta".
  • Modifies "c:\program files\reference assemblies\microsoft\framework\v3.5\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\web folders\1033\decoding help.hta".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\calendar.gadget\en-us\decoding help.hta".
  • Modifies "c:\program files\common files\system\ado\en-us\decoding help.hta".
  • Modifies "c:\program files\windows sidebar\gadgets\calendar.gadget\en-us\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\equation\eqnedt32.exe.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\currency.gadget\en-us\decoding help.hta".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\cpu.gadget\en-us\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\grphflt\cgmimp32.cfg.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files\microsoft sql server compact edition\v3.5\sqlcecompact35.dll.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files\common files\microsoft shared\smart tag\fperson.dll.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files\common files\microsoft shared\proof\mswds_en.lex.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files\common files\microsoft shared\vc\msdia90.dll.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\vsta\bin\vstaclientpkg.dll.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppobjs-spp-plugin-manifest-signed.xrm-ms.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\vsta\pipeline.v10.0\pipelinesegments.store.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files\common files\microsoft shared\textconv\wks9pxy.cnv.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\portal\portalconnectcore.dll.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\vsta\appinfodocument\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\canyon\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\boldstri\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\breeze\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\arctic\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\axis\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\blends\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\bluecalm\decoding help.hta".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\esl\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\web server extensions\14\bin\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\office14\csi.dll.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\calendar.gadget\images\decoding help.hta".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\rssfeeds.gadget\en-us\decoding help.hta".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\slideshow.gadget\en-us\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\vsta\pipeline.v10.0\addinviews\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\vsta\pipeline.v10.0\contracts\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\vsta\pipeline.v10.0\hostsideadapters\decoding help.hta".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\picturepuzzle.gadget\en-us\decoding help.hta".
  • Modifies "c:\program files\microsoft office\media\cagcat10\1033\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\fr_fr\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\vba\vba7\1033\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\es_es\decoding help.hta".
  • Modifies "c:\program files\windows sidebar\gadgets\mediacenter.gadget\css\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\translat\arfr\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\1028\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\cs_cz\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\da_dk\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\de_de\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\en_us\decoding help.hta".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\slideshow.gadget\images\decoding help.hta".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\picturepuzzle.gadget\images\decoding help.hta".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\weather.gadget\images\decoding help.hta".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\clock.gadget\en-us\decoding help.hta".
  • Modifies "c:\program files\windows sidebar\gadgets\mediacenter.gadget\en-us\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\fi_fi\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\zh_tw\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\pt_br\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\ja_jp\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\hr_hr\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\zh_cn\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\uk_ua\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\tr_tr\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\sv_se\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\sl_si\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\sk_sk\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\ru_ru\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\ro_ro\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\pl_pl\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\nl_nl\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\nb_no\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\ko_kr\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\it_it\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\hu_hu\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\eu_es\decoding help.hta".
  • Modifies "c:\program files\microsoft office\media\office14\1033\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\visio shared\fonts\decoding help.hta".
  • Modifies "c:\program files\microsoft sync framework\v1.0\documentation\1033\license agreements\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\vsta\pipeline.v10.0\addinsideadapters\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\2052\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\1031\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\1033\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\1036\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\1040\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\1041\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\1042\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\1046\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\3082\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\bg-bg\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\pl-pl\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\ru-ru\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\de-de\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\1049\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\ro-ro\decoding help.hta".
  • Modifies "c:\program files\microsoft office\office14\accddsf.dll.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\microsoft.net\primary interop assemblies\microsoft.mshtml.dll.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\liesmich.htm.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\microsoft analysis services\as oledb\10\cartridges\as80.xsl.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\java\jre7\lib\calendars.properties.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\arm\1.0\adobeextractfiles.dll.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\system\ole db\xmlrwbin.dll.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\java\jre7\bin\axbridge.dll.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\java\java update\jucheck.exe.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files\dvd maker\shared\dvdstyles\performance\decoding help.hta".
  • Modifies "c:\program files\microsoft office\media\office14\bullets\decoding help.hta".
  • Modifies "c:\program files\microsoft office\clipart\publisher\backgrounds\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\textconv\wksconv\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\vsto\10.0\1033\decoding help.hta".
  • Modifies "c:\program files\windows sidebar\gadgets\cpu.gadget\en-us\decoding help.hta".
  • Modifies "c:\program files\microsoft office\media\office14\autoshap\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\decoding help.hta".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\cpu.gadget\en-us\js\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\fr_fr\reader_10.0.helpcfg.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\es_es\reader_10.0.helpcfg.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\currency.gadget\en-us\css\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\hr_hr\reader_10.0.helpcfg.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files\common files\microsoft shared\filters\offfiltx.dll.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files\common files\microsoft shared\web server extensions\14\bin\decoding help.hta".
  • Modifies "c:\program files\reference assemblies\microsoft\framework\v3.5\redistlist\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\sl-si\decoding help.hta".
  • Modifies "c:\program files\reference assemblies\microsoft\framework\v3.0\redistlist\decoding help.hta".
  • Modifies "c:\program files (x86)\reference assemblies\microsoft\framework\v3.5\redistlist\decoding help.hta".
  • Modifies "c:\program files (x86)\reference assemblies\microsoft\framework\v3.5\subsetlist\decoding help.hta".
  • Modifies "c:\program files (x86)\reference assemblies\microsoft\framework\v3.0\redistlist\decoding help.hta".
  • Modifies "c:\program files (x86)\reference assemblies\microsoft\framework\v3.0\subsetlist\decoding help.hta".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\calendar.gadget\en-us\css\decoding help.hta".
  • Modifies "c:\program files\windows sidebar\gadgets\calendar.gadget\en-us\css\decoding help.hta".
  • Modifies "c:\program files\windows sidebar\gadgets\calendar.gadget\en-us\js\decoding help.hta".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\slideshow.gadget\en-us\js\decoding help.hta".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\cpu.gadget\en-us\css\decoding help.hta".
  • Modifies "c:\program files\windows sidebar\gadgets\mediacenter.gadget\images\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\en-us\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\layers\decoding help.hta".
  • Modifies "c:\program files\dvd maker\shared\dvdstyles\push\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\studio\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\uk_ua\reader_10.0.helpcfg.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\da_dk\reader_10.0.helpcfg.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\reference assemblies\microsoft\framework\v3.0\winfxlist.xml.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\portal\1033\portalconnect.dll.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files\common files\microsoft shared\themes14\sumipntg\decoding help.hta".
  • Modifies "c:\program files\microsoft office\stationery\1033\currency.gif.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files\microsoft office\media\office14\office10.dll.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\microsoft.net\redistlist\assemblylist_4_extended.xml.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\mozilla firefox\crashreporter.ini.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\msenv\publicassemblies\extensibility.dll.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files\microsoft office\office14\1036\mso.acl.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files\common files\microsoft shared\dw\dw20.exe.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\fi_fi\reader_10.0.helpcfg.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\tr_tr\reader_10.0.helpcfg.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\sv_se\reader_10.0.helpcfg.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\sl_si\reader_10.0.helpcfg.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\sk_sk\reader_10.0.helpcfg.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\ru_ru\reader_10.0.helpcfg.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\ro_ro\reader_10.0.helpcfg.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\pl_pl\reader_10.0.helpcfg.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\nl_nl\reader_10.0.helpcfg.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\nb_no\reader_10.0.helpcfg.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\ko_kr\reader_10.0.helpcfg.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\it_it\reader_10.0.helpcfg.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\hu_hu\reader_10.0.helpcfg.[id]g9uzrlhjaygpwrm1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\eu_es\reader_10.0.helpcfg.[id]g9uzrlhjaygpwrm1[id]".
1/5
Masquerade Changes folder appearance 30 -
  • Folder "c:\program files" has a changed appearance.
  • Folder "c:\program files (x86)" has a changed appearance.
  • Folder "c:\$recycle.bin\s-1-5-21-3388679973-3930757225-3770151564-1000" has a changed appearance.
  • Folder "c:\users\public" has a changed appearance.
  • Folder "c:\users\default\links" has a changed appearance.
  • Folder "c:\users\5p5nrgjn0js halpmcxz\saved games" has a changed appearance.
  • Folder "c:\users\5p5nrgjn0js halpmcxz\searches" has a changed appearance.
  • Folder "c:\users\5p5nrgjn0js halpmcxz\videos" has a changed appearance.
  • Folder "c:\users\5p5nrgjn0js halpmcxz\desktop" has a changed appearance.
  • Folder "c:\users\5p5nrgjn0js halpmcxz\downloads" has a changed appearance.
  • Folder "c:\users\5p5nrgjn0js halpmcxz\music" has a changed appearance.
  • Folder "c:\program files\common files\microsoft shared\stationery" has a changed appearance.
  • Folder "c:\users\default\contacts" has a changed appearance.
  • Folder "c:\users\default\downloads" has a changed appearance.
  • Folder "c:\users\5p5nrgjn0js halpmcxz\documents" has a changed appearance.
  • Folder "c:\users\5p5nrgjn0js halpmcxz\links" has a changed appearance.
  • Folder "c:\users\public\documents" has a changed appearance.
  • Folder "c:\users\public\pictures" has a changed appearance.
  • Folder "c:\users\public\videos" has a changed appearance.
  • Folder "c:\users\public\downloads" has a changed appearance.
  • Folder "c:\users\public\recorded tv" has a changed appearance.
  • Folder "c:\users\public\libraries" has a changed appearance.
  • Folder "c:\users\default\desktop" has a changed appearance.
  • Folder "c:\users\default\music" has a changed appearance.
  • Folder "c:\users\default\favorites" has a changed appearance.
  • Folder "c:\users\public\music" has a changed appearance.
  • Folder "c:\users\5p5nrgjn0js halpmcxz\favorites" has a changed appearance.
  • Folder "c:\users\default\documents" has a changed appearance.
  • Folder "c:\users\5p5nrgjn0js halpmcxz\contacts" has a changed appearance.
1/5
Information Stealing Possibly does reconnaissance 1 -
  • Possibly trying to gather information about application "Mozilla Firefox" by file.
1/5
File System Creates an unusually large number of files 1 -
0/5
Process Enumerates running processes 1 -

Screenshots

Monitored Processes

Sample Information

ID #83262
MD5 30c6ac2bd181d92490bcdbc440d527b1 Copy to Clipboard
SHA1 e3ac4120d556fc527320f883a36c445914afbc79 Copy to Clipboard
SHA256 cc30bd2a55abc25681990a831539c393f086b5720ee27266e1c4b1abc1ac7a80 Copy to Clipboard
SSDeep 384:bo6O5Rtl1Hz8s+DgS3sUShMFWrHx6mG0dimylQC9q9yYoOKTqoptTPgnsmEEFEE3:bWxYse3rAMguQCQ9Et4nsmEEFEEBU8 Copy to Clipboard
ImpHash 0a98a06f576cfeebd2f91325d9ccac02 Copy to Clipboard
Filename C_932.NLS.exe
File Size 44.83 KB
Sample Type Windows Exe (x86-32)

Analysis Information

Creation Time 2019-06-19 18:00 (UTC+2)
Analysis Duration 00:04:29
Number of Monitored Processes 3
Execution Successful True
Reputation Enabled True
WHOIS Enabled False
Local AV Enabled True
YARA Enabled True
Number of AV Matches 1
Number of YARA Matches 0
Termination Reason Timeout
Tags
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image