62dcc35536fc49377722d40cf6fe4d924bd415aeb9a9036be067b25a306dd845 (SHA256)
muziko66.EXE
Created at 2018-11-20 16:22:00
Notifications (2/3)
Some extracted files may be missing in the report since the maximum number of extracted files was reached during the analysis. You can increase the limit in the configuration settings.
The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.
The operating system was rebooted during the analysis.
Severity | Category | Operation | Classification | |
---|---|---|---|---|
4/5
|
File System | Known malicious file | Trojan | |
|
||||
4/5
|
Injection | Writes into the memory of another running process | - | |
|
||||
|
||||
4/5
|
Injection | Modifies control flow of another process | - | |
|
||||
2/5
|
Anti Analysis | Delays execution | - | |
|
||||
2/5
|
Anti Analysis | Tries to detect virtual machine | - | |
|
||||
2/5
|
File System | Known suspicious file | Trojan | |
|
||||
1/5
|
Persistence | Installs system startup script or application | - | |
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
1/5
|
Process | Creates process with hidden window | - | |
|
||||
|
||||
1/5
|
Process | Creates system object | - | |
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
1/5
|
File System | Modifies operating system directory | - | |
|
||||
|
||||
|
||||
1/5
|
Process | Creates a page with write and execute permissions | - | |
|
||||
1/5
|
Anti Analysis | Resolves APIs dynamically | - | |
|
||||
1/5
|
Device | Monitors keyboard input | Keylogger | |
|
||||
1/5
|
Information Stealing | Reads system data | - | |
|
||||
1/5
|
Network | Performs DNS request | - | |
|
||||
1/5
|
Static | Unparsable sections in file | - | |
|
||||
1/5
|
PE | Drops PE file | Dropper | |
|
||||
1/5
|
PE | Executes dropped PE file | - | |
|