d45dfa19...b6e5 | VTI
Try VMRay Analyzer
VTI SCORE: 90/100
Dynamic Analysis Report
Classification: Backdoor, Dropper, Downloader

d45dfa19146949ef791c96b183f04f1b2ba480d32308b39a32976a2f30ecb6e5 (SHA256)

sample.exe

Windows Exe (x86-32)

Created at 2019-03-08 08:37:00

Notifications (1/1)

The operating system was rebooted during the analysis.

Severity Category Operation Classification
4/5
Information Stealing Reads browser data -
2/5
Injection Writes into the memory of a process running from a created or modified executable -
  • "c:\windows\syswow64\indexerneutral.exe" modifies memory of "c:\windows\syswow64\indexerneutral.exe"
  • "c:\windows\syswow64\indexerneutral.exe" modifies memory of "c:\windows\syswow64\indexerneutrala.exe"
  • "c:\windows\syswow64\indexerneutral.exe" modifies memory of "c:\windows\syswow64\indexerneutralb.exe"
2/5
Injection Modifies control flow of a process running from a created or modified executable -
  • "c:\windows\syswow64\indexerneutral.exe" alters context of "c:\windows\syswow64\indexerneutral.exe"
  • "c:\windows\syswow64\indexerneutral.exe" alters context of "c:\windows\syswow64\indexerneutrala.exe"
  • "c:\windows\syswow64\indexerneutral.exe" alters context of "c:\windows\syswow64\indexerneutralb.exe"
2/5
Network Sets up server that accepts incoming connections Backdoor
1/5
Process Creates system object -
1/5
Process Creates process with hidden window -
  • The process "C:\Users\CIiHmnxMn6Ps\Desktop\sample.exe" starts with hidden window.
  • The process "C:\Windows\SysWOW64\indexerneutral.exe" starts with hidden window.
  • The process ""C:\Windows\SysWOW64\indexerneutral.exe" /scomma "C:\Windows\TEMP\3256.tmp"" starts with hidden window.
  • The process ""C:\Windows\SysWOW64\indexerneutral.exe" "C:\Windows\TEMP\3267.tmp"" starts with hidden window.
  • The process ""C:\Windows\SysWOW64\indexerneutral.exe" /scomma "C:\Windows\TEMP\2ECB.tmp"" starts with hidden window.
  • The process ""C:\Windows\SysWOW64\indexerneutral.exe" "C:\Windows\TEMP\3595.tmp"" starts with hidden window.
  • The process ""C:\Windows\SysWOW64\indexerneutrala.exe" "C:\Windows\TEMP\3595.tmp"" starts with hidden window.
  • The process ""C:\Windows\SysWOW64\indexerneutralb.exe" "C:\Windows\TEMP\3267.tmp"" starts with hidden window.
1/5
File System Modifies operating system directory -
  • Creates file "C:\Windows\SysWOW64\indexerneutral.exe" in the OS directory.
  • Creates file "C:\Windows\SysWOW64\indexerneutralb.exe" in the OS directory.
  • Creates file "C:\Windows\SysWOW64\indexerneutrala.exe" in the OS directory.
1/5
Persistence Installs system service -
1/5
Anti Analysis Resolves APIs dynamically -
1/5
Process Creates a page with write and execute permissions -
  • Allocates a page in a foreign process with "PAGE_EXECUTE_READWRITE" permissions, often used to dynamically unpack code.
1/5
Network Performs DNS request -
1/5
Static Unparsable sections in file -
  • Static analyzer was unable to completely parse the analyzed file: C:\Users\CIiHmnxMn6Ps\Desktop\sample.exe.
1/5
Network Downloads data Downloader
1/5
Network Connects to HTTP server -
1/5
PE Drops PE file Dropper
1/5
PE Executes dropped PE file -
  • Executes dropped file "C:\Windows\SysWOW64\indexerneutralb.exe".
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image