VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Backdoor, Dropper, Spyware, Downloader |
6ded37a61962a6a6626bd47adb66f5f73742d8d2125cdff1dc3f932d0a8e5d2e (SHA256)
gootkit_vbs-6ded37a6.vir.vbs
VBScript
Created at 2018-12-13 14:00:00
Notifications (2/2)
The overall sleep time of all monitored processes was truncated from "29 minutes, 45 seconds" to "1 minute, 40 seconds" to reveal dormant functionality.
This is a filtered view
This list contains only the embedded files and created files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\Nd9E1FYi\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_0ac90668-b7fb-46d6-80e6-01a947284e18 | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2016-04-29 10:14 (UTC+2) |
Last Seen | 2017-10-06 18:19 (UTC+2) |
C:\Users\Nd9E1FYi\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_96fb2ebe-5768-403c-8fbc-1b0ef0323733 | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2016-05-09 14:28 (UTC+2) |
Last Seen | 2017-10-07 22:08 (UTC+2) |
C:\Users\Nd9E1FYi\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_41c67784-5a05-4d3a-a346-47e4d3e9d32f | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2016-05-09 14:28 (UTC+2) |
Last Seen | 2017-10-07 22:08 (UTC+2) |
C:\Users\Nd9E1FYi\AppData\Local\Temp\bwaykzvy.uyx.ps1 | Created File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2011-06-14 17:40 (UTC+2) |
Last Seen | 2018-12-04 20:02 (UTC+1) |
C:\Users\Nd9E1FYi\AppData\Local\Temp\tmp8C77.tmp | Created File | Unknown |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2011-05-27 11:27 (UTC+2) |
Last Seen | 2017-04-19 12:47 (UTC+2) |
C:\Users\Nd9E1FYi\Desktop\gootkit_vbs-6ded37a6.vir.vbs | Sample File | Text |
Unknown
|
...
|
»
c:\users\nd9e1fyi\appdata\local\microsoft\windows\inetcache\counters.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Nd9E1FYi\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Nd9E1FYi\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Nd9E1FYi\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Nd9E1FYi\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Nd9E1FYi\AppData\Local\Temp\SMSvcHost32.inf | Created File | Unknown |
Unknown
|
...
|
»
C:\Users\Nd9E1FYi\AppData\Local\Temp\SMSvcHost32.inf | Created File | Unknown |
Unknown
|
...
|
»
c:\users\nd9e1fyi\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-2172869166-1497266965-2109836178-1000\578c3c4f2234dc4bd77dc4898cd130e8_94f34c22-5cd3-4d50-aa5e-52adff408a05 | Created File | Stream |
Unknown
|
...
|
»
C:\Users\Nd9E1FYi\AppData\Local\Temp\tmp8C77.tmp | Created File | Binary |
Unknown
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x405000 |
Size Of Code | 0x5e00 |
Size Of Initialized Data | 0x37600 |
File Type | executable |
Subsystem | windows_gui |
Machine Type | i386 |
Compile Timestamp | 2015-04-07 23:02:24+00:00 |
Sections (2)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x5cbf | 0x5e00 | 0x200 | mem_execute, mem_read, mem_write | 2.31 |
.xyl | 0x407000 | 0x3759c | 0x37600 | 0x6000 | cnt_initialized_data, mem_write | 7.79 |
Imports (5)
»
dsprop.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CrackName | 0x0 | 0x407000 | 0x3e1a8 | 0x3d1a8 | 0x0 |
CheckADsError | 0x0 | 0x407004 | 0x3e1ac | 0x3d1ac | 0x0 |
FindSheet | 0x0 | 0x407008 | 0x3e1b0 | 0x3d1b0 | 0x0 |
eappcfg.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EapHostPeerFreeErrorMemory | 0x0 | 0x407010 | 0x3e1b8 | 0x3d1b8 | 0x0 |
EapHostPeerConfigBlob2Xml | 0x0 | 0x407014 | 0x3e1bc | 0x3d1bc | 0x0 |
kernel32.dll (19)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetDateFormatA | 0x0 | 0x40701c | 0x3e1c4 | 0x3d1c4 | 0x21c |
InterlockedIncrement | 0x0 | 0x407020 | 0x3e1c8 | 0x3d1c8 | 0x2ed |
FindFirstFileW | 0x0 | 0x407024 | 0x3e1cc | 0x3d1cc | 0x134 |
GetTempPathA | 0x0 | 0x407028 | 0x3e1d0 | 0x3d1d0 | 0x1f2 |
CopyFileExA | 0x0 | 0x40702c | 0x3e1d4 | 0x3d1d4 | 0x1a1 |
CreateProcessA | 0x0 | 0x407030 | 0x3e1d8 | 0x3d1d8 | 0x265 |
FindClose | 0x0 | 0x407034 | 0x3e1dc | 0x3d1dc | 0xad |
WriteFile | 0x0 | 0x407038 | 0x3e1e0 | 0x3d1e0 | 0x7f |
GetCurrentThread | 0x0 | 0x40703c | 0x3e1e4 | 0x3d1e4 | 0x1c8 |
VirtualAllocEx | 0x0 | 0x407040 | 0x3e1e8 | 0x3d1e8 | 0x4b6 |
GetEnvironmentVariableW | 0x0 | 0x407044 | 0x3e1ec | 0x3d1ec | 0x3a0 |
GetModuleHandleA | 0x0 | 0x407048 | 0x3e1f0 | 0x3d1f0 | 0x218 |
UpdateResourceA | 0x0 | 0x40704c | 0x3e1f4 | 0x3d1f4 | 0x160 |
ReplaceFileA | 0x0 | 0x407050 | 0x3e1f8 | 0x3d1f8 | 0xd5 |
ReadProcessMemory | 0x0 | 0x407054 | 0x3e1fc | 0x3d1fc | 0xcd |
FileTimeToLocalFileTime | 0x0 | 0x407058 | 0x3e200 | 0x3d200 | 0x126 |
SetLastError | 0x0 | 0x40705c | 0x3e204 | 0x3d204 | 0x4c8 |
SetErrorMode | 0x0 | 0x407060 | 0x3e208 | 0x3d208 | 0x459 |
OpenSemaphoreW | 0x0 | 0x407064 | 0x3e20c | 0x3d20c | 0x37e |
odbctrac.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
TraceSQLError | 0x0 | 0x40706c | 0x3e214 | 0x3d214 | 0x0 |
TraceSQLBindCol | 0x0 | 0x407070 | 0x3e218 | 0x3d218 | 0x0 |
advapi32.dll (14)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegDeleteValueW | 0x0 | 0x407078 | 0x3e220 | 0x3d220 | 0x658 |
RegCreateKeyExA | 0x0 | 0x40707c | 0x3e224 | 0x3d224 | 0x664 |
RegRestoreKeyW | 0x0 | 0x407080 | 0x3e228 | 0x3d228 | 0x684 |
IsValidAcl | 0x0 | 0x407084 | 0x3e22c | 0x3d22c | 0x583 |
RegUnLoadKeyA | 0x0 | 0x407088 | 0x3e230 | 0x3d230 | 0x144 |
RegOpenKeyW | 0x0 | 0x40708c | 0x3e234 | 0x3d234 | 0x670 |
CryptSignHashA | 0x0 | 0x407090 | 0x3e238 | 0x3d238 | 0x67d |
IsValidAcl | 0x0 | 0x407094 | 0x3e23c | 0x3d23c | 0x641 |
InitializeAcl | 0x0 | 0x407098 | 0x3e240 | 0x3d240 | 0x662 |
RegReplaceKeyA | 0x0 | 0x40709c | 0x3e244 | 0x3d244 | 0x682 |
RegSaveKeyA | 0x0 | 0x4070a0 | 0x3e248 | 0x3d248 | 0x686 |
RegLoadKeyW | 0x0 | 0x4070a4 | 0x3e24c | 0x3d24c | 0x66a |
RegEnumKeyW | 0x0 | 0x4070a8 | 0x3e250 | 0x3d250 | 0x65e |
OpenEventLogA | 0x0 | 0x4070ac | 0x3e254 | 0x3d254 | 0x648 |
C:\Users\Nd9E1FYi\AppData\Local\Temp\SMSvcHost32.inf | Created File | Unknown |
Unknown
|
...
|
»
C:\Users\Nd9E1FYi\AppData\Local\Temp\SMSvcHost32.exe | Created File | Binary |
Unknown
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x401400 |
Size Of Code | 0x5200 |
Size Of Initialized Data | 0x34e00 |
File Type | executable |
Subsystem | windows_gui |
Machine Type | i386 |
Compile Timestamp | 2013-07-12 03:05:39+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.code | 0x401000 | 0x51c6 | 0x5200 | 0x400 | mem_execute, mem_read | 3.97 |
.tss | 0x407000 | 0x462 | 0x600 | 0x5600 | mem_read, mem_write | 3.54 |
.fdata | 0x408000 | 0x938 | 0xa00 | 0x5c00 | mem_read, mem_write | 6.16 |
.rssc | 0x409000 | 0x33cba | 0x33e00 | 0x6600 | cnt_initialized_data, mem_read, mem_write | 7.99 |
Imports (3)
»
cmpbk32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PhoneBookFreeFilter | 0x0 | 0x407000 | 0x70f8 | 0x56f8 | 0x0 |
PhoneBookCopyFilter | 0x0 | 0x407004 | 0x70fc | 0x56fc | 0x0 |
PhoneBookEnumCountries | 0x0 | 0x407008 | 0x7100 | 0x5700 | 0x0 |
PhoneBookLoad | 0x0 | 0x40700c | 0x7104 | 0x5704 | 0x0 |
PhoneBookEnumNumbers | 0x0 | 0x407010 | 0x7108 | 0x5708 | 0x0 |
user32.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadIconA | 0x0 | 0x407018 | 0x7110 | 0x5710 | 0x0 |
GetMessageW | 0x0 | 0x40701c | 0x7114 | 0x5714 | 0x0 |
LoadBitmapW | 0x0 | 0x407020 | 0x7118 | 0x5718 | 0x0 |
GetClassLongA | 0x0 | 0x407024 | 0x711c | 0x571c | 0x0 |
FindWindowA | 0x0 | 0x407028 | 0x7120 | 0x5720 | 0x0 |
DrawStateW | 0x0 | 0x40702c | 0x7124 | 0x5724 | 0x0 |
FindWindowExA | 0x0 | 0x407030 | 0x7128 | 0x5728 | 0x0 |
InsertMenuA | 0x0 | 0x407034 | 0x712c | 0x572c | 0x0 |
CreateDesktopA | 0x0 | 0x407038 | 0x7130 | 0x5730 | 0x0 |
PostMessageW | 0x0 | 0x40703c | 0x7134 | 0x5734 | 0x0 |
GetDlgItemTextA | 0x0 | 0x407040 | 0x7138 | 0x5738 | 0x0 |
kernel32.dll (23)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VirtualProtect | 0x0 | 0x407048 | 0x7140 | 0x5740 | 0x0 |
GetFileAttributesW | 0x0 | 0x40704c | 0x7144 | 0x5744 | 0x0 |
SetErrorMode | 0x0 | 0x407050 | 0x7148 | 0x5748 | 0x0 |
CreateFileMappingW | 0x0 | 0x407054 | 0x714c | 0x574c | 0x0 |
CreateNamedPipeA | 0x0 | 0x407058 | 0x7150 | 0x5750 | 0x0 |
FindClose | 0x0 | 0x40705c | 0x7154 | 0x5754 | 0x0 |
GetWindowsDirectoryA | 0x0 | 0x407060 | 0x7158 | 0x5758 | 0x0 |
FileTimeToSystemTime | 0x0 | 0x407064 | 0x715c | 0x575c | 0x0 |
DeleteFileW | 0x0 | 0x407068 | 0x7160 | 0x5760 | 0x0 |
LoadLibraryW | 0x0 | 0x40706c | 0x7164 | 0x5764 | 0x0 |
GetSystemTime | 0x0 | 0x407070 | 0x7168 | 0x5768 | 0x0 |
GetStartupInfoA | 0x0 | 0x407074 | 0x716c | 0x576c | 0x0 |
OpenJobObjectW | 0x0 | 0x407078 | 0x7170 | 0x5770 | 0x0 |
OpenEventA | 0x0 | 0x40707c | 0x7174 | 0x5774 | 0x0 |
FindNextFileA | 0x0 | 0x407080 | 0x7178 | 0x5778 | 0x0 |
CreateFileA | 0x0 | 0x407084 | 0x717c | 0x577c | 0x0 |
MoveFileExW | 0x0 | 0x407088 | 0x7180 | 0x5780 | 0x0 |
OpenSemaphoreA | 0x0 | 0x40708c | 0x7184 | 0x5784 | 0x0 |
LoadLibraryA | 0x0 | 0x407090 | 0x7188 | 0x5788 | 0x0 |
SleepEx | 0x0 | 0x407094 | 0x718c | 0x578c | 0x0 |
GetDateFormatW | 0x0 | 0x407098 | 0x7190 | 0x5790 | 0x0 |
CreateMutexA | 0x0 | 0x40709c | 0x7194 | 0x5794 | 0x0 |
VirtualAlloc | 0x0 | 0x4070a0 | 0x7198 | 0x5798 | 0x0 |
C:\Users\Nd9E1FYi\AppData\Local\Temp\SMSvcHost32.inf | Created File | Unknown |
Unknown
|
...
|
»
c:\users\nd9e1fyi\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-2172869166-1497266965-2109836178-1000\578c3c4f2234dc4bd77dc4898cd130e8_94f34c22-5cd3-4d50-aa5e-52adff408a05 | Created File | Stream |
Unknown
|
...
|
»
C:\Users\Nd9E1FYi\AppData\Local\Temp\SMSvcHost32.inf | Created File | Unknown |
Unknown
|
...
|
»