VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Dropper
Downloader
Exploit
...
|
Threat Names: |
Equation Group
Mimikatz
Gen:Trojan.Downloader.fmqaa08eR0ii
...
|
down.txt.exe
Windows Exe (x86-32)
Created at 2020-01-13T14:40:00
Remarks (2/3)
(0x02000008): One or more processes crashed during the analysis. Analysis results may be incomplete.
(0x0200000E): The overall sleep time of all monitored processes was truncated from "58 minutes" to "4 minutes" to reveal dormant functionality.
Indicators
File (60)
»
Registry (27)
»
Mutex (3)
»
Mutex Name | Operations |
---|---|
Access | |
5ss5c_CRYPT | Access |
SSSS_Scan | Access |
Domain (1)
»
Domain | Sources | Severity |
---|---|---|
xduwtfono | Function Log |
Unknown
|
URL (3)
»
URL | Operations | Category | Severity |
---|---|---|---|
http://58.221.158.90:88/car/c.dat | GET | Contacted |
Unknown
|
http://58.221.158.90:88/car/cpt.dat | GET | Contacted |
Unknown
|
http://58.221.158.90:88/car/down.txt | GET | Contacted |
Unknown
|
IP (646)
»