VMRay Analyzer Report for Sample #20158 VMRay Analyzer 2.2.0 Process 1 2556 ofgzdr.exe 1488 ofgzdr.exe "C:\Users\EEBsYm5\Desktop\ofgzdr.exe" C:\Users\EEBsYm5\Desktop\ c:\users\eebsym5\desktop\ofgzdr.exe Created Opened Opened Opened Mutex HSDFSD-HFSD-3241-91E7-ASDGSDGHH WinRegistryKey Software\Borland\Locales HKEY_CURRENT_USER WinRegistryKey Software\Borland\Locales HKEY_LOCAL_MACHINE WinRegistryKey Software\Borland\Delphi\Locales HKEY_CURRENT_USER Analyzed Sample #20158 Malware Artifacts 20158 Sample-ID: #20158 Job-ID: #13469 This sample was analyzed by VMRay Analyzer 2.2.0 on a Windows 7 system 0 VTI Score based on VTI Database Version 2.6 Metadata of Sample File #20158 Submission-ID: #20342 C:\Users\EEBsYm5\Desktop\ofgzdr.exe exe MD5 870acd0ca66986cc20ab0a655fbc5873 SHA1 4a1b74432e38a1dfbd0b3336547cd764a25886e2 SHA256 085256b114079911b64f5826165f85a28a2a4ddc2ce0d935fa8545651ce5ab09 Opened_By Metadata of Analysis for Job-ID #13469 Timeout True x86 32-bit PAE 6.1.7601.17514 (684da42a-30cc-450f-81c5-35b4d18944b1) win7_32_sp1 True 140.681 Windows 7 This is a property collection for additional information of VMRay analysis VMRay Analyzer File System VTI rule match with VTI rule score 4/5 vmray_delete_user_files Delete multiple user files. This is an indicator for wiper malware. Delete user files Process VTI rule match with VTI rule score 1/5 vmray_install_ipc_endpoint Create mutex with name "HSDFSD-HFSD-3241-91E7-ASDGSDGHH". Create system object