VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: | - |
Threat Names: |
Generic.EmotetU.4295B2B2
|
p.exe
Windows Exe (x86-32)
Created at 2020-09-03T22:53:00
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 Bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\p.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x793f23 |
Size Of Code | 0x1d000 |
Size Of Initialized Data | 0x7a000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-09-01 08:21:52+00:00 |
Version Information (8)
»
Article | www.codeproject.com |
hdietrich@gmail.com | |
FileDescription | XColorPickerXPTest MFC Application |
FileVersion | 1, 0, 0, 1 |
LegalCopyright | Copyright © 2008 Hans Dietrich |
OriginalFilename | XColorPickerXPTest.exe |
ProductName | XColorPickerXPTest Application |
ProductVersion | 1, 0, 0, 1 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1c1b4 | 0x0 | 0x0 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 0.0 |
.rdata | 0x41e000 | 0x8418 | 0x0 | 0x0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.0 |
.data | 0x427000 | 0x72b4 | 0x0 | 0x0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.vmp0 | 0x42f000 | 0x35c308 | 0x0 | 0x0 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 0.0 |
.vmp1 | 0x78c000 | 0x559e70 | 0x55a000 | 0x1000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.96 |
.rsrc | 0xce6000 | 0x3a269 | 0x3b000 | 0x55b000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.66 |
Imports (15)
»
KERNEL32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetVersion | 0x0 | 0xc2f000 | 0x8bd600 | 0x532600 | 0x0 |
GetVersionExA | 0x0 | 0xc2f004 | 0x8bd604 | 0x532604 | 0x0 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetSysColorBrush | 0x0 | 0xc2f00c | 0x8bd60c | 0x53260c | 0x0 |
GDI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ScaleWindowExtEx | 0x0 | 0xc2f014 | 0x8bd614 | 0x532614 | 0x0 |
comdlg32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ChooseColorA | 0x0 | 0xc2f01c | 0x8bd61c | 0x53261c | 0x0 |
WINSPOOL.DRV (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
OpenPrinterA | 0x0 | 0xc2f024 | 0x8bd624 | 0x532624 | 0x0 |
ADVAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryValueExA | 0x0 | 0xc2f02c | 0x8bd62c | 0x53262c | 0x0 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteA | 0x0 | 0xc2f034 | 0x8bd634 | 0x532634 | 0x0 |
COMCTL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x11 | 0xc2f03c | 0x8bd63c | 0x53263c | - |
SHLWAPI.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathFindFileNameA | 0x0 | 0xc2f044 | 0x8bd644 | 0x532644 | 0x0 |
OLEAUT32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VariantClear | 0x9 | 0xc2f04c | 0x8bd64c | 0x53264c | - |
WTSAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WTSSendMessageW | 0x0 | 0xc2f054 | 0x8bd654 | 0x532654 | 0x0 |
KERNEL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VirtualQuery | 0x0 | 0xc2f05c | 0x8bd65c | 0x53265c | 0x0 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetUserObjectInformationW | 0x0 | 0xc2f064 | 0x8bd664 | 0x532664 | 0x0 |
KERNEL32.dll (12)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LocalAlloc | 0x0 | 0xc2f06c | 0x8bd66c | 0x53266c | 0x0 |
LocalFree | 0x0 | 0xc2f070 | 0x8bd670 | 0x532670 | 0x0 |
GetModuleFileNameW | 0x0 | 0xc2f074 | 0x8bd674 | 0x532674 | 0x0 |
GetProcessAffinityMask | 0x0 | 0xc2f078 | 0x8bd678 | 0x532678 | 0x0 |
SetProcessAffinityMask | 0x0 | 0xc2f07c | 0x8bd67c | 0x53267c | 0x0 |
SetThreadAffinityMask | 0x0 | 0xc2f080 | 0x8bd680 | 0x532680 | 0x0 |
Sleep | 0x0 | 0xc2f084 | 0x8bd684 | 0x532684 | 0x0 |
ExitProcess | 0x0 | 0xc2f088 | 0x8bd688 | 0x532688 | 0x0 |
FreeLibrary | 0x0 | 0xc2f08c | 0x8bd68c | 0x53268c | 0x0 |
LoadLibraryA | 0x0 | 0xc2f090 | 0x8bd690 | 0x532690 | 0x0 |
GetModuleHandleA | 0x0 | 0xc2f094 | 0x8bd694 | 0x532694 | 0x0 |
GetProcAddress | 0x0 | 0xc2f098 | 0x8bd698 | 0x532698 | 0x0 |
USER32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetProcessWindowStation | 0x0 | 0xc2f0a0 | 0x8bd6a0 | 0x5326a0 | 0x0 |
GetUserObjectInformationW | 0x0 | 0xc2f0a4 | 0x8bd6a4 | 0x5326a4 | 0x0 |
Memory Dumps (21)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
buffer | 1 | 0x00220000 | 0x00220FFF | Content Changed | 32-bit | - |
...
|
|||
buffer | 1 | 0x00220000 | 0x00220FFF | First Execution | 32-bit | 0x0022000F |
...
|
|||
buffer | 1 | 0x00240000 | 0x00240FFF | Content Changed | 32-bit | - |
...
|
|||
buffer | 1 | 0x00240000 | 0x00240FFF | First Execution | 32-bit | 0x00240015 |
...
|
|||
buffer | 1 | 0x00260000 | 0x00260FFF | Content Changed | 32-bit | - |
...
|
|||
buffer | 1 | 0x00260000 | 0x00260FFF | Content Changed | 32-bit | - |
...
|
|||
buffer | 1 | 0x00280000 | 0x00280FFF | Content Changed | 32-bit | - |
...
|
|||
buffer | 1 | 0x00280000 | 0x00280FFF | Content Changed | 32-bit | - |
...
|
|||
buffer | 1 | 0x00290000 | 0x00290FFF | Content Changed | 32-bit | - |
...
|
|||
buffer | 1 | 0x00290000 | 0x00290FFF | Content Changed | 32-bit | - |
...
|
|||
buffer | 1 | 0x002A0000 | 0x002A0FFF | Content Changed | 32-bit | - |
...
|
|||
buffer | 1 | 0x002A0000 | 0x002A0FFF | Content Changed | 32-bit | - |
...
|
|||
buffer | 1 | 0x002B0000 | 0x002B0FFF | First Execution | 32-bit | 0x002B000F |
...
|
|||
buffer | 1 | 0x002B0000 | 0x002B0FFF | Marked Executable | 32-bit | 0x002B000F |
...
|
|||
buffer | 1 | 0x00300000 | 0x00300FFF | First Execution | 32-bit | 0x00300000 |
...
|
|||
buffer | 1 | 0x003A0000 | 0x003CAFFF | First Execution | 32-bit | 0x003A0000 |
...
|
|||
buffer | 1 | 0x003D0000 | 0x003FCFFF | First Execution | 32-bit | 0x003D2A20 |
...
|
|||
buffer | 1 | 0x02800000 | 0x0282AFFF | Marked Executable | 32-bit | - |
...
|
|||
ntdll.dll | 1 | 0x77C40000 | 0x77DBFFFF | First Execution | 32-bit | 0x77C6002D |
...
|
|||
ntdll.dll | 1 | 0x77C40000 | 0x77DBFFFF | Content Changed | 32-bit | 0x77C6002D |
...
|
|||
ntdll.dll | 1 | 0x77C40000 | 0x77DBFFFF | Content Changed | 32-bit | 0x77C6E198 |
...
|
C:\Program Files (x86)\desktop.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Mozilla Firefox\application.ini.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Mozilla Firefox\crashreporter.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Mozilla Firefox\dependentlibs.list | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Mozilla Firefox\install.log.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Mozilla Firefox\freebl3.chk | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Mozilla Firefox\nssdbm3.chk.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Mozilla Firefox\platform.ini.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Mozilla Firefox\precomplete | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Mozilla Firefox\softokn3.chk.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Mozilla Firefox\removed-files.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Mozilla Firefox\update-settings.ini.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Mozilla Firefox\updater.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Mozilla Maintenance Service\updater.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\MSBuild\Microsoft.Office.InfoPath.targets.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Mozilla Firefox\omni.ja | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\Hx.hxn.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.EXCEL.14.1033.hxn.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.EXCEL.DEV.14.1033.hxn.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.GRAPH.14.1033.hxn.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.GROOVE.14.1033.hxn | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.INFOPATH.14.1033.hxn | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.INFOPATHEDITOR.14.1033.hxn.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.MSACCESS.14.1033.hxn | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.MSACCESS.DEV.14.1033.hxn | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.MSPUB.DEV.14.1033.hxn.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.MSTORE.14.1033.hxn | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.MSOUC.14.1033.hxn | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.OIS.14.1033.hxn.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.OUTLOOK.DEV.14.1033.hxn | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.OUTLOOK.14.1033.hxn.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.POWERPNT.14.1033.hxn | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.ONENOTE.14.1033.hxn.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.MSPUB.14.1033.hxn.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.SETLANG.14.1033.hxn | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.VISIO.SHAPESHEET.14.1033.hxn | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.VISIO.DEV.14.1033.hxn.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.VISIO_STD.14.1033.hxn | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.VISIO.14.1033.hxn.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.POWERPNT.DEV.14.1033.hxn.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.WINPROJ.14.1033.hxn | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.WINWORD.DEV.14.1033.hxn | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.WINPROJ.DEV.14.1033.hxn.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.VISIO_PRM.14.1033.hxn | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\MS.WINWORD.14.1033.hxn | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft Help\nslist.hxl.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\boot.sdi.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\ntuser.ini.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT.LOG | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT.LOG1.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Default\ntuser.ini.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\desktop.ini.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\OWOW32LR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\Setup.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\Winre.wim | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml | Modified File | Stream |
Unknown
|
...
|
»