dba40065b6efc6ae10e26ba608817ff04bdbc976e07016d78d0b4a63492e3ae4 (SHA256)
educat.exe
Created at 2018-11-06 11:23:00
Notifications (2/3)
The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.
The operating system was rebooted during the analysis.
Severity | Category | Operation | Classification | |
---|---|---|---|---|
4/5
|
Injection | Writes into the memory of another running process | - | |
|
||||
|
||||
|
||||
|
||||
4/5
|
Injection | Modifies control flow of another process | - | |
|
||||
|
||||
|
||||
|
||||
|
||||
3/5
|
Browser | Changes security-related browser settings | - | |
|
||||
3/5
|
Device | Monitors keyboard input | Keylogger | |
|
||||
2/5
|
Browser | Reads data related to browser cookies | - | |
|
||||
|
||||
|
||||
2/5
|
Anti Analysis | Makes direct system call to possibly evade hooking based sandboxes | - | |
|
||||
|
||||
|
||||
|
||||
|
||||
2/5
|
Injection | Writes into the memory of a process running from a created or modified executable | - | |
|
||||
|
||||
2/5
|
Injection | Modifies control flow of a process running from a created or modified executable | - | |
|
||||
|
||||
1/5
|
Process | Creates process with hidden window | - | |
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
1/5
|
Process | Reads from memory of another process | - | |
|
||||
|
||||
|
||||
|
||||
1/5
|
Information Stealing | Reads system data | Spyware | |
|
||||
|
||||
1/5
|
Persistence | Installs system startup script or application | - | |
|
||||
1/5
|
Process | Creates a page with write and execute permissions | - | |
|
||||
1/5
|
Anti Analysis | Resolves APIs dynamically | - | |
|
||||
1/5
|
Process | Creates system object | - | |
|
||||
|
||||
|
||||
|
||||
|
||||
1/5
|
File System | Creates an unusually large number of files | - | |
|
||||
1/5
|
Process | Overwrites code | - | |
|
||||
1/5
|
Static | Unparsable sections in file | - | |
|
||||
1/5
|
Network | Downloads data | Downloader | |
|
||||
|
||||
1/5
|
Network | Connects to HTTP server | - | |
|
||||
|