MALICIOUS
Classifications: Injector
Threat Names:
Mal/Generic-S Mal/HTMLGen-A Generic.Exploit.Shellcode.RDI.2.848912F9 Gen:Variant.Strictor.46025
Verdict Reason: -
Sample Type Windows Exe (x86-32)
File Name 0d2805a84af62c765ac706960cd2a4a1.exe
ID #1077621
MD5 592cbf02a35ee0358194b33c483be874
SHA1 ae04e74a104cd6d2d00331111f0f2596c86eeb2e
SHA256 2c12f9be67bf31375db1b0578920fa37b415ec1a2df56cc1f3dacd9985f60100
File Size 339.00 KB
Report Created 2021-10-26 16:21 (UTC+2)
Target Environment win10_64_th2_en_mso2016 | exe
OVERVIEW
VMRay Threat Identifiers (17 rules, 47 matches)
Score Category Operation Count Classification
4/5 Defense Evasion Obscures a file's origin 2 -
(Process #2) 0d2805a84af62c765ac706960cd2a4a1.exe tries to delete zone identifier of file "C:\ProgramData\images.exe".
(Process #11) images.exe tries to delete zone identifier of file "C:\Users\RDhJ0CNFevzX\AppData\Roaming\images.exe".
•
•
4/5 Injection Writes into the memory of another process 1 Injector
(Process #7) images.exe modifies memory of (process #8) cmd.exe.
•
4/5 Injection Modifies control flow of another process 1 Injector
(Process #7) images.exe creates thread in (process #8) cmd.exe.
•
4/5 Antivirus Malicious content was detected by heuristic scan 4 -
Built-in AV detected a memory dump of (process #2) 0d2805a84af62c765ac706960cd2a4a1.exe as "Generic.Exploit.Shellcode.RDI.2.848912F9".
Built-in AV detected a memory dump of (process #2) 0d2805a84af62c765ac706960cd2a4a1.exe as "Gen:Variant.Strictor.46025".
Built-in AV detected a memory dump of (process #7) images.exe as "Generic.Exploit.Shellcode.RDI.2.848912F9".
Built-in AV detected a memory dump of (process #11) images.exe as "Generic.Exploit.Shellcode.RDI.2.848912F9".
•
•
•
•
4/5 Reputation Known malicious file 1 -
Reputation analysis labels the sample itself as "Mal/Generic-S".
•
4/5 Reputation Resolves known malicious domain 1 -
Reputation analysis labels the resolved domain "nan.ydns.eu" as "Mal/HTMLGen-A".
•
2/5 Injection Writes into the memory of a process started from a created or modified executable 3 -
(Process #1) 0d2805a84af62c765ac706960cd2a4a1.exe modifies memory of (process #2) 0d2805a84af62c765ac706960cd2a4a1.exe.
(Process #4) images.exe modifies memory of (process #7) images.exe.
(Process #10) images.exe modifies memory of (process #11) images.exe.
•
•
•
2/5 Injection Modifies control flow of a process started from a created or modified executable 3 -
(Process #1) 0d2805a84af62c765ac706960cd2a4a1.exe alters context of (process #2) 0d2805a84af62c765ac706960cd2a4a1.exe.
(Process #4) images.exe alters context of (process #7) images.exe.
(Process #10) images.exe alters context of (process #11) images.exe.
•
•
•
1/5 Privilege Escalation Enables process privilege 3 -
(Process #1) 0d2805a84af62c765ac706960cd2a4a1.exe enables process privilege "SeDebugPrivilege".
(Process #4) images.exe enables process privilege "SeDebugPrivilege".
(Process #10) images.exe enables process privilege "SeDebugPrivilege".
•
•
•
1/5 Hide Tracks Creates process with hidden window 8 -
X-Ray Vision for Malware - www.vmray.com 2 / 31
Score Category Operation Count Classification
(Process #1) 0d2805a84af62c765ac706960cd2a4a1.exe starts (process #2) 0d2805a84af62c765ac706960cd2a4a1.exe with a hidden window.
(Process #2) 0d2805a84af62c765ac706960cd2a4a1.exe starts (process #3) cmd.exe with a hidden window.
(Process #2) 0d2805a84af62c765ac706960cd2a4a1.exe starts (process #4) images.exe with a hidden window.
(Process #4) images.exe starts (process #7) images.exe with a hidden window.
(Process #7) images.exe starts (process #8) cmd.exe with a hidden window.
(Process #10) images.exe starts (process #11) images.exe with a hidden window.
(Process #11) images.exe starts (process #12) cmd.exe with a hidden window.
(Process #11) images.exe starts (process #13) images.exe with a hidden window.
•
•
•
•
•
•
•
•
1/5 Discovery Enumerates running processes 3 -
(Process #1) 0d2805a84af62c765ac706960cd2a4a1.exe enumerates running processes.
(Process #4) images.exe enumerates running processes.
(Process #10) images.exe enumerates running processes.
•
•
•
1/5 Obfuscation Reads from memory of another process 3 -
(Process #1) 0d2805a84af62c765ac706960cd2a4a1.exe reads from (process #2) 0d2805a84af62c765ac706960cd2a4a1.exe.
(Process #4) images.exe reads from (process #7) images.exe.
(Process #10) images.exe reads from (process #11) images.exe.
•
•
•
1/5 Obfuscation Creates a page with write and execute permissions 4 -
(Process #1) 0d2805a84af62c765ac706960cd2a4a1.exe allocates a page in a foreign process with "PAGE_EXECUTE_READWRITE" permissions, often used to dynamically unpack code.
(Process #4) images.exe allocates a page in a foreign process with "PAGE_EXECUTE_READWRITE" permissions, often used to dynamically unpack code.
(Process #7) images.exe allocates a page in a foreign process with "PAGE_EXECUTE_READWRITE" permissions, often used to dynamically unpack code.
(Process #10) images.exe allocates a page in a foreign process with "PAGE_EXECUTE_READWRITE" permissions, often used to dynamically unpack code.
•
•
•
•
1/5 Anti Analysis Tries to detect analyzer sandbox 1 -
(Process #2) 0d2805a84af62c765ac706960cd2a4a1.exe is possibly trying to detect analyzer sandbox by checking for patched sleep.
•
1/5 System Modification Modifies application directory 3 -
(Process #2) 0d2805a84af62c765ac706960cd2a4a1.exe modifies "c:\program files\microsoft dn1".
(Process #7) images.exe modifies "c:\program files\microsoft dn1".
(Process #11) images.exe modifies "c:\program files\microsoft dn1".
•
•
•
1/5 Network Connection Performs DNS request 1 -
(Process #7) images.exe resolves host name "nan.ydns.eu" to IP "-".
•
1/5 Execution Executes itself 5 -
(Process #1) 0d2805a84af62c765ac706960cd2a4a1.exe executes a copy of the sample at C:\Users\RDhJ0CNFevzX\Desktop\0d2805a84af62c765ac706960cd2a4a1.exe.
(Process #2) 0d2805a84af62c765ac706960cd2a4a1.exe executes a copy of the sample at C:\Users\RDhJ0CNFevzX\Desktop\0d2805a84af62c765ac706960cd2a4a1.exe.
(Process #4) images.exe executes a copy of the sample at C:\Users\RDhJ0CNFevzX\Desktop\0d2805a84af62c765ac706960cd2a4a1.exe.
(Process #10) images.exe executes a copy of the sample at C:\Users\RDhJ0CNFevzX\Desktop\0d2805a84af62c765ac706960cd2a4a1.exe.
(Process #11) images.exe executes a copy of the sample at C:\Users\RDhJ0CNFevzX\Desktop\0d2805a84af62c765ac706960cd2a4a1.exe.
•
•
•
•
•
Mitre ATT&CK Matrix
Initial Access Execution Persistence Privilege Escalation
Defense Evasion
Credential
Access Discovery Lateral
Movement Collection Command
and Control Exfiltration Impact
#T1143 Hidden Window
#T1057 Process Discovery
#T1045 Software Packing
#T1497 Virtualization/
Sandbox Evasion
#T1497 Virtualization/
Sandbox Evasion
#T1124 System Time
Discovery
#T1096 NTFS File Attributes
X-Ray Vision for Malware - www.vmray.com 4 / 31
Sample Information
Analysis Information
ID #1077621
MD5 592cbf02a35ee0358194b33c483be874
SHA1 ae04e74a104cd6d2d00331111f0f2596c86eeb2e
SHA256 2c12f9be67bf31375db1b0578920fa37b415ec1a2df56cc1f3dacd9985f60100
SSDeep 6144:BQIxNYrJYEfv9Ykr7DVLq1YV+8TzAB/KOnTSE0K8LvfDEQXWUtin2H+:yrZfeec1Yf/AwOn3094Kb3+
ImpHash f34d5f2d4577ed6d9ceec516c1f5a744
File Name 0d2805a84af62c765ac706960cd2a4a1.exe
File Size 339.00 KB
Sample Type Windows Exe (x86-32)
Has Macros
Creation Time 2021-10-26 16:21 (UTC+2)
Analysis Duration 00:04:00
Termination Reason Timeout
Number of Monitored Processes 12
Execution Successful False
Reputation Enabled
WHOIS Enabled
Built-in AV Enabled
Built-in AV Applied On Sample Files, PCAP File, Downloaded Files, Dropped Files, Modified Files, Memory Dumps, Embedded Files
Number of AV Matches 40
YARA Enabled
YARA Applied On Sample Files, PCAP File, Downloaded Files, Dropped Files, Modified Files, Memory Dumps, Embedded Files
Number of YARA Matches 0
X-Ray Vision for Malware - www.vmray.com 6 / 31
Screenshots truncated
NETWORK
General
DNS
HTTP/S
DNS Requests
Type Hostname Response Code Resolved IPs CNames Verdict
0 bytes total sent
0 bytes total received 0 ports
1 contacted IP addresses
0 URLs extracted 0 files downloaded
0 malicious hosts detected
1 DNS requests for 1 domains 1 nameservers contacted
0 total requests returned errors
0 URLs contacted, 0 servers
0 sessions, 0 bytes sent, 0 bytes received
A nan.ydns.eu NoError 195.133.40.125 NA
X-Ray Vision for Malware - www.vmray.com 8 / 31
BEHAVIOR
Process Graph
Sample Start #1
0d2805a84af62c765ac706960cd2a4a1.exe #2
0d2805a84af62c765ac706960cd2a4a1.exe Modify Memory
Modify Control Flow Child Process
#3 cmd.exe Child Process
#4 images.exe Child Process
#6 reg.exe Child Process
#7 images.exe Modify Memory
Modify Control Flow Child Process
#8 cmd.exe Modify Memory
Create Remote Thread Child Process
Reboot #1 #10
images.exe
#11 images.exe Modify Memory
Modify Control Flow Child Process
#12 cmd.exe Child Process
#13 images.exe Child Process
#15 reg.exe Child Process
Process #1: 0d2805a84af62c765ac706960cd2a4a1.exe
Dropped Files (1)
File Name File Size SHA256 YARA Match
Host Behavior
Type Count
ID 1
File Name c:\users\rdhj0cnfevzx\desktop\0d2805a84af62c765ac706960cd2a4a1.exe Command Line "C:\Users\RDhJ0CNFevzX\Desktop\0d2805a84af62c765ac706960cd2a4a1.exe"
Initial Working Directory C:\Users\RDhJ0CNFevzX\Desktop\
Monitor Start Time Start Time: 51003, Reason: Analysis Target Unmonitor End Time End Time: 115609, Reason: Terminated
Monitor duration 64.61s
Return Code 0
PID 5032
Parent PID 1636
Bitness 32 Bit
C:
\Users\RDhJ0CNFevzX\AppData\Local\Temp\0d2805a84af62c765ac
706960cd2a4a1.exe 339.00 KB 2c12f9be67bf31375db1b0578920fa37b415ec1a2df56cc1f3dacd9985f60
100
File 5
User 1
Process 111
Module 57
- 3
System 111
- 9
X-Ray Vision for Malware - www.vmray.com 10 / 31
Process #2: 0d2805a84af62c765ac706960cd2a4a1.exe
Injection Information (8)
Injection Type Source Process Source / Target TID Address / Name Size Success Count
Dropped Files (1)
File Name File Size SHA256 YARA Match
Host Behavior
Type Count
ID 2
File Name c:\users\rdhj0cnfevzx\appdata\local\temp\0d2805a84af62c765ac706960cd2a4a1.exe Command Line C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\0d2805a84af62c765ac706960cd2a4a1.exe
Initial Working Directory C:\Users\RDhJ0CNFevzX\Desktop\
Monitor Start Time Start Time: 104515, Reason: Child Process Unmonitor End Time End Time: 125847, Reason: Terminated
Monitor duration 21.33s
Return Code 0
PID 3528
Parent PID 5032
Bitness 32 Bit
Modify Memory
#1: c:
\users\rdhj0cnfevzx\desktop
\0d2805a84af62c765ac7069 60cd2a4a1.exe
0x13a0 0x400000(4194304) 0x400 1
Modify Memory
#1: c:
\users\rdhj0cnfevzx\desktop
\0d2805a84af62c765ac7069 60cd2a4a1.exe
0x13a0 0x401000(4198400) 0x15200 1
Modify Memory
#1: c:
\users\rdhj0cnfevzx\desktop
\0d2805a84af62c765ac7069 60cd2a4a1.exe
0x13a0 0x417000(4288512) 0x5000 1
Modify Memory
#1: c:
\users\rdhj0cnfevzx\desktop
\0d2805a84af62c765ac7069 60cd2a4a1.exe
0x13a0 0x41c000(4308992) 0xa800 1
Modify Memory
#1: c:
\users\rdhj0cnfevzx\desktop
\0d2805a84af62c765ac7069 60cd2a4a1.exe
0x13a0 0x55b000(5615616) 0x1200 1
Modify Memory
#1: c:
\users\rdhj0cnfevzx\desktop
\0d2805a84af62c765ac7069 60cd2a4a1.exe
0x13a0 0x55d000(5623808) 0x200 1
Modify Memory
#1: c:
\users\rdhj0cnfevzx\desktop
\0d2805a84af62c765ac7069 60cd2a4a1.exe
0x13a0 0x245008(2379784) 0x4 1
Modify Control Flow
#1: c:
\users\rdhj0cnfevzx\desktop
\0d2805a84af62c765ac7069 60cd2a4a1.exe
0x13a0 / 0x600 - 1
C:\ProgramData\images.exe 339.00 KB 2c12f9be67bf31375db1b0578920fa37b415ec1a2df56cc1f3dacd9985f60
100
Mutex 14
COM 1
Type Count
System 142
- 8
Module 18
File 8
Registry 7
Process 2
X-Ray Vision for Malware - www.vmray.com 12 / 31
Process #3: cmd.exe
Host Behavior
Type Count
ID 3
File Name c:\windows\syswow64\cmd.exe
Command Line cmd.exe /c REG ADD "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" /f /v Load /t REG_SZ /d "C:\ProgramData\images.exe"
Initial Working Directory C:\Users\RDhJ0CNFevzX\Desktop\
Monitor Start Time Start Time: 121592, Reason: Child Process Unmonitor End Time End Time: 140075, Reason: Terminated
Monitor duration 18.48s
Return Code 0
PID 3136
Parent PID 3528
Bitness 32 Bit
Module 8
Registry 17
File 17
Environment 19
System 1
Process 1
Process #4: images.exe
Dropped Files (1)
File Name File Size SHA256 YARA Match
Host Behavior
Type Count
ID 4
File Name c:\programdata\images.exe
Command Line "C:\ProgramData\images.exe"
Initial Working Directory C:\Users\RDhJ0CNFevzX\Desktop\
Monitor Start Time Start Time: 121953, Reason: Child Process Unmonitor End Time End Time: 159891, Reason: Terminated
Monitor duration 37.94s
Return Code 0
PID 2908
Parent PID 3528
Bitness 32 Bit
C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\images.exe 339.00 KB 2c12f9be67bf31375db1b0578920fa37b415ec1a2df56cc1f3dacd9985f60 100
File 5
User 1
Process 108
Module 56
- 3
System 108
- 9
X-Ray Vision for Malware - www.vmray.com 14 / 31
Process #6: reg.exe
Host Behavior
Type Count
ID 6
File Name c:\windows\syswow64\reg.exe
Command Line REG ADD "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" /f /v Load /t REG_SZ /d "C:\ProgramData\images.exe"
Initial Working Directory C:\Users\RDhJ0CNFevzX\Desktop\
Monitor Start Time Start Time: 138732, Reason: Child Process Unmonitor End Time End Time: 140051, Reason: Terminated
Monitor duration 1.32s
Return Code 0
PID 1256
Parent PID 3136
Bitness 32 Bit
Module 1
Registry 4
File 6
Process #7: images.exe
Injection Information (8)
Injection Type Source Process Source / Target TID Address / Name Size Success Count
Host Behavior
Type Count
ID 7
File Name c:\users\rdhj0cnfevzx\appdata\local\temp\images.exe Command Line C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\images.exe
Initial Working Directory C:\Users\RDhJ0CNFevzX\Desktop\
Monitor Start Time Start Time: 157628, Reason: Child Process Unmonitor End Time End Time: 169969, Reason: Terminated
Monitor duration 12.34s
Return Code 1073807364
PID 3168
Parent PID 2908
Bitness 32 Bit
Modify Memory #4: c:
\programdata\images.exe 0x960 0x400000(4194304) 0x400 1
Modify Memory #4: c:
\programdata\images.exe 0x960 0x401000(4198400) 0x15200 1
Modify Memory #4: c:
\programdata\images.exe 0x960 0x417000(4288512) 0x5000 1
Modify Memory #4: c:
\programdata\images.exe 0x960 0x41c000(4308992) 0xa800 1
Modify Memory #4: c:
\programdata\images.exe 0x960 0x55b000(5615616) 0x1200 1
Modify Memory #4: c:
\programdata\images.exe 0x960 0x55d000(5623808) 0x200 1
Modify Memory #4: c:
\programdata\images.exe 0x960 0x37f008(3665928) 0x4 1
Modify Control Flow #4: c:
\programdata\images.exe 0x960 / 0x6a0 - 1
Mutex 8
COM 1
System 144
- 8
Module 19
File 5
Registry 6
Process 2
- 5
- 1
X-Ray Vision for Malware - www.vmray.com 16 / 31
Network Behavior
Type Count
DNS 1
Process #8: cmd.exe
Injection Information (3)
Injection Type Source Process Source / Target TID Address / Name Size Success Count
Host Behavior
Type Count
ID 8
File Name c:\windows\syswow64\cmd.exe
Command Line "C:\Windows\System32\cmd.exe"
Initial Working Directory C:\Users\RDhJ0CNFevzX\Desktop\
Monitor Start Time Start Time: 163834, Reason: Child Process Unmonitor End Time End Time: 170277, Reason: Terminated
Monitor duration 6.44s
Return Code 1073807364
PID 3672
Parent PID 3168
Bitness 32 Bit
Modify Memory #7: c:
\users\rdhj0cnfevzx\appdata
\local\temp\images.exe 0x6a0 0x1f0000(2031616) 0x800 1
Modify Memory #7: c:
\users\rdhj0cnfevzx\appdata
\local\temp\images.exe 0x6a0 0x440000(4456448) 0x103 1
Create Remote Thread #7: c:
\users\rdhj0cnfevzx\appdata
\local\temp\images.exe 0x6a0 0x1f010e(2031886) - 1
Module 11
Registry 17
File 62
Environment 12
System 3
X-Ray Vision for Malware - www.vmray.com 18 / 31
Process #10: images.exe
Host Behavior
Type Count
ID 10
File Name c:\programdata\images.exe
Command Line "C:\ProgramData\images.exe"
Initial Working Directory C:\Windows\
Monitor Start Time Start Time: 244271, Reason: Autostart Unmonitor End Time End Time: 276885, Reason: Terminated
Monitor duration 32.61s
Return Code 0
PID 3272
Parent PID 1528
Bitness 32 Bit
File 5
User 1
Process 36
Module 56
- 3
System 36
- 9
Process #11: images.exe
Injection Information (8)
Injection Type Source Process Source / Target TID Address / Name Size Success Count
Dropped Files (1)
File Name File Size SHA256 YARA Match
Host Behavior
Type Count
ID 11
File Name c:\users\rdhj0cnfevzx\appdata\local\temp\images.exe Command Line C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\images.exe
Initial Working Directory C:\Windows\
Monitor Start Time Start Time: 274317, Reason: Child Process Unmonitor End Time End Time: 279450, Reason: Terminated
Monitor duration 5.13s
Return Code 0
PID 3612
Parent PID 3272
Bitness 32 Bit
Modify Memory #10: c:
\programdata\images.exe 0xccc 0x400000(4194304) 0x400 1
Modify Memory #10: c:
\programdata\images.exe 0xccc 0x401000(4198400) 0x15200 1
Modify Memory #10: c:
\programdata\images.exe 0xccc 0x417000(4288512) 0x5000 1
Modify Memory #10: c:
\programdata\images.exe 0xccc 0x41c000(4308992) 0xa800 1
Modify Memory #10: c:
\programdata\images.exe 0xccc 0x55b000(5615616) 0x1200 1
Modify Memory #10: c:
\programdata\images.exe 0xccc 0x55d000(5623808) 0x200 1
Modify Memory #10: c:
\programdata\images.exe 0xccc 0x36e008(3596296) 0x4 1
Modify Control Flow #10: c:
\programdata\images.exe 0xccc / 0xe20 - 1
C:\Users\RDhJ0CNFevzX\AppData\Roaming\images.exe 339.00 KB 2c12f9be67bf31375db1b0578920fa37b415ec1a2df56cc1f3dacd9985f60 100
Mutex 14
COM 1
System 142
- 8
Module 18
File 8
Registry 7
Process 2
X-Ray Vision for Malware - www.vmray.com 20 / 31
Process #12: cmd.exe
Host Behavior
Type Count
ID 12
File Name c:\windows\syswow64\cmd.exe
Command Line cmd.exe /c REG ADD "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" /f /v Load /t REG_SZ /d "C:
\Users\RDhJ0CNFevzX\AppData\Roaming\images.exe"
Initial Working Directory C:\Windows\
Monitor Start Time Start Time: 276888, Reason: Child Process Unmonitor End Time End Time: 279760, Reason: Terminated
Monitor duration 2.87s
Return Code 0
PID 3644
Parent PID 3612
Bitness 32 Bit
Module 8
Registry 17
File 15
Environment 19
System 1
Process 1
Process #13: images.exe
Host Behavior
Type Count
ID 13
File Name c:\users\rdhj0cnfevzx\appdata\roaming\images.exe Command Line "C:\Users\RDhJ0CNFevzX\AppData\Roaming\images.exe"
Initial Working Directory C:\Windows\
Monitor Start Time Start Time: 276924, Reason: Child Process Unmonitor End Time End Time: 298617, Reason: Terminated by Timeout
Monitor duration 21.69s
Return Code Unknown
PID 3652
Parent PID 3612
Bitness 32 Bit
File 1
X-Ray Vision for Malware - www.vmray.com 22 / 31
Process #15: reg.exe
Host Behavior
Type Count
ID 15
File Name c:\windows\syswow64\reg.exe
Command Line REG ADD "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" /f /v Load /t REG_SZ /d "C:
\Users\RDhJ0CNFevzX\AppData\Roaming\images.exe"
Initial Working Directory C:\Windows\
Monitor Start Time Start Time: 278464, Reason: Child Process Unmonitor End Time End Time: 279333, Reason: Terminated
Monitor duration 0.87s
Return Code 0
PID 3696
Parent PID 3644
Bitness 32 Bit
Module 1
Registry 4
File 6
ARTIFACTS
File
SHA256 File Names Category File Size MIME Type Operations Verdict
Filename
File Name Category Operations Verdict
2c12f9be67bf31375db1b057 8920fa37b415ec1a2df56cc1f 3dacd9985f60100
C:
\Users\RDhJ0CNFevzX\AppData\Ro aming\images.exe, C:
\ProgramData\images.exe, C:
\Users\RDhJ0CNFevzX\Desktop\0d2 805a84af62c765ac7069... ...C:
\Users\RDhJ0CNFevzX\AppData\Loc al\Temp\images.exe, C:
\Users\RDhJ0CNFevzX\AppData\Loc al\Temp\0d2805a84af62c765ac706960 cd2a4a1.exe
Sample File 339.00 KB application/
vnd.microsoft.portable-
executable Read, Create, Access, Write MALICIOUS
C:
\Users\RDhJ0CNFevzX\Desktop\0d2805a84af62c765ac706960cd2a4
a1.exe.config Accessed File Access CLEAN
C:
\Users\RDhJ0CNFevzX\Desktop\0d2805a84af62c765ac706960cd2a4
a1.exe Sample File Access CLEAN
C:\Windows\SYSTEM32\ntdll.dll Accessed File Access CLEAN
C:\Windows\SYSTEM32\MSCOREE.DLL Accessed File Access CLEAN
C:\Windows\SYSTEM32\KERNEL32.dll Accessed File Access CLEAN
C:\Windows\SYSTEM32\KERNELBASE.dll Accessed File Access CLEAN
C:\Windows\system32\apphelp.dll Accessed File Access CLEAN
C:\Windows\SYSTEM32\ADVAPI32.dll Accessed File Access CLEAN
C:\Windows\SYSTEM32\msvcrt.dll Accessed File Access CLEAN
C:\Windows\SYSTEM32\sechost.dll Accessed File Access CLEAN
C:\Windows\SYSTEM32\RPCRT4.dll Accessed File Access CLEAN
C:\Windows\SYSTEM32\SspiCli.dll Accessed File Access CLEAN
C:\Windows\SYSTEM32\CRYPTBASE.dll Accessed File Access CLEAN
C:\Windows\SYSTEM32\bcryptPrimitives.dll Accessed File Access CLEAN
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll Accessed File Access CLEAN
C:\Windows\SYSTEM32\SHLWAPI.dll Accessed File Access CLEAN
C:\Windows\SYSTEM32\combase.dll Accessed File Access CLEAN
C:\Windows\SYSTEM32\GDI32.dll Accessed File Access CLEAN
C:\Windows\SYSTEM32\USER32.dll Accessed File Access CLEAN
C:\Windows\SYSTEM32\IMM32.DLL Accessed File Access CLEAN
C:\Windows\SYSTEM32\kernel.appcore.dll Accessed File Access CLEAN
C:\Windows\SYSTEM32\VERSION.dll Accessed File Access CLEAN
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll Accessed File Access CLEAN
C:\Windows\SYSTEM32\MSVCR120_CLR0400.dll Accessed File Access CLEAN
C:
\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\8062d42
7acd64e37f4fded7b00f4a869\mscorlib.ni.dll Accessed File Access CLEAN
X-Ray Vision for Malware - www.vmray.com 24 / 31
File Name Category Operations Verdict
Domain
Domain IP Address Country Protocols Verdict
IP
IP Address Domains Country Protocols Verdict
Registry
Registry Key Operations Parent Process Name Verdict
C:\Windows\SYSTEM32\ole32.dll Accessed File Access CLEAN
C:\Windows\system32\uxtheme.dll Accessed File Access CLEAN
C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll Accessed File Access CLEAN
C:\Windows\SYSTEM32\OLEAUT32.dll Accessed File Access CLEAN
C:
\Windows\assembly\NativeImages_v4.0.30319_32\System\cc4e5d11
0dd318e8b7d61a9ed184ab74\System.ni.dll Accessed File Access CLEAN
C:\Windows\SYSTEM32\psapi.dll Accessed File Access CLEAN
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Itself.exe Accessed File Access CLEAN
C:
\Users\RDhJ0CNFevzX\AppData\Local\Temp\0d2805a84af62c765ac
706960cd2a4a1.exe Sample File Read, Create, Access, Write CLEAN
C:\Program Files\Microsoft DN1 Accessed File Create, Access CLEAN
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft Vision\ Accessed File Create, Access CLEAN
C:\ProgramData Accessed File Create, Access CLEAN
C:\ProgramData\images.exe Sample File Create, Access, Write CLEAN
C:\ProgramData\images.exe:Zone.Identifier Accessed File Delete, Access CLEAN
C:\Windows\SysWOW64\cmd.exe Accessed File Access CLEAN
C:\Users\RDhJ0CNFevzX\Desktop Accessed File Access CLEAN
C:\ProgramData\images.exe.config Accessed File Access CLEAN
C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\images.exe Sample File Read, Create, Access, Write CLEAN
C:\Users\RDhJ0CNFevzX\AppData\Roaming Accessed File Create, Access CLEAN
C:\Users\RDhJ0CNFevzX\AppData\Roaming\images.exe Sample File Create, Access, Write CLEAN
C:
\Users\RDhJ0CNFevzX\AppData\Roaming\images.exe:Zone.Identifi
er Accessed File Delete, Access CLEAN
C:\Windows Accessed File Access CLEAN
C:\Users\RDhJ0CNFevzX\AppData\Roaming\images.exe.config Accessed File Access CLEAN
nan.ydns.eu 195.133.40.125 - DNS MALICIOUS
192.168.0.1 - - DNS, UDP CLEAN
195.133.40.125 nan.ydns.eu Czech Rep. DNS CLEAN
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVer
sion\Internet Settings create, access 0d2805a84af62c765ac706960cd2a4a1.exe, images.exe CLEAN
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVer
sion\Internet Settings\MaxConnectionsPer1_0Server write, access 0d2805a84af62c765ac706960cd2a4a1.exe, images.exe CLEAN
Registry Key Operations Parent Process Name Verdict
Process
Process Name Commandline Verdict
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVer
sion\Internet Settings\MaxConnectionsPerServer write, access 0d2805a84af62c765ac706960cd2a4a1.exe, images.exe CLEAN
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVer
sion\Explorer\1VDK9FWJ7BWX4Q78 create, access 0d2805a84af62c765ac706960cd2a4a1.exe, images.exe CLEAN
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVer
sion\Explorer\1VDK9FWJ7BWX4Q78\inst read, write, access 0d2805a84af62c765ac706960cd2a4a1.exe, images.exe CLEAN
HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Sy
stem access cmd.exe CLEAN
HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor access cmd.exe CLEAN
HKEY_LOCAL_MACHINE\Software\Microsoft\Command
Processor\DisableUNCCheck read, access cmd.exe CLEAN
HKEY_LOCAL_MACHINE\Software\Microsoft\Command
Processor\EnableExtensions read, access cmd.exe CLEAN
HKEY_LOCAL_MACHINE\Software\Microsoft\Command
Processor\DelayedExpansion read, access cmd.exe CLEAN
HKEY_LOCAL_MACHINE\Software\Microsoft\Command
Processor\DefaultColor read, access cmd.exe CLEAN
HKEY_LOCAL_MACHINE\Software\Microsoft\Command
Processor\CompletionChar read, access cmd.exe CLEAN
HKEY_LOCAL_MACHINE\Software\Microsoft\Command
Processor\PathCompletionChar read, access cmd.exe CLEAN
HKEY_LOCAL_MACHINE\Software\Microsoft\Command
Processor\AutoRun read, access cmd.exe CLEAN
HKEY_CURRENT_USER\Software\Microsoft\Command Processor access cmd.exe CLEAN
HKEY_CURRENT_USER\Software\Microsoft\Command
Processor\DisableUNCCheck read, access cmd.exe CLEAN
HKEY_CURRENT_USER\Software\Microsoft\Command
Processor\EnableExtensions read, access cmd.exe CLEAN
HKEY_CURRENT_USER\Software\Microsoft\Command
Processor\DelayedExpansion read, access cmd.exe CLEAN
HKEY_CURRENT_USER\Software\Microsoft\Command
Processor\DefaultColor read, access cmd.exe CLEAN
HKEY_CURRENT_USER\Software\Microsoft\Command
Processor\CompletionChar read, access cmd.exe CLEAN
HKEY_CURRENT_USER\Software\Microsoft\Command
Processor\PathCompletionChar read, access cmd.exe CLEAN
HKEY_CURRENT_USER\Software\Microsoft\Command
Processor\AutoRun read, access cmd.exe CLEAN
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVer
sion\Policies\System access reg.exe CLEAN
HKEY_CURRENT_USER\Software\Microsoft\Windows
NT\CurrentVersion\Windows create, access reg.exe CLEAN
HKEY_CURRENT_USER\Software\Microsoft\Windows
NT\CurrentVersion\Windows\Load read, write, access reg.exe CLEAN
0d2805a84af62c765ac706960cd2a4a1.exe "C:\Users\RDhJ0CNFevzX\Desktop\0d2805a84af62c765ac706960cd2a4a1.exe" MALICIOUS
images.exe "C:\ProgramData\images.exe" MALICIOUS
images.exe "C:\Users\RDhJ0CNFevzX\AppData\Roaming\images.exe" MALICIOUS
0d2805a84af62c765ac706960cd2a4a1.exe C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\0d2805a84af62c765ac706960cd2a4a1.exe SUSPICIOUS
images.exe C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\images.exe SUSPICIOUS
images.exe "C:\ProgramData\images.exe" SUSPICIOUS
X-Ray Vision for Malware - www.vmray.com 26 / 31
Process Name Commandline Verdict cmd.exe cmd.exe /c REG ADD "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" /f /v Load
/t REG_SZ /d "C:\ProgramData\images.exe" CLEAN
reg.exe REG ADD "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" /f /v Load /t REG_SZ
/d "C:\ProgramData\images.exe" CLEAN
cmd.exe "C:\Windows\System32\cmd.exe" CLEAN
cmd.exe cmd.exe /c REG ADD "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" /f /v Load
/t REG_SZ /d "C:\Users\RDhJ0CNFevzX\AppData\Roaming\images.exe" CLEAN
reg.exe REG ADD "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" /f /v Load /t REG_SZ
/d "C:\Users\RDhJ0CNFevzX\AppData\Roaming\images.exe" CLEAN
YARA / AV
Antivirus (40)
File Type Threat Name File Name Verdict
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Gen:Variant.Strictor.46025 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
X-Ray Vision for Malware - www.vmray.com 28 / 31
File Type Threat Name File Name Verdict
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
Memory Dump Generic.Exploit.Shellcode.RDI.2.848912F9 - MALICIOUS
ENVIRONMENT
Virtual Machine Information
Platform Information
Anti Virus Information
Software Information
System Information
Name win10_64_th2_en_mso2016
Description win10_64_th2_en_mso2016
Architecture x86 64-bit
Operating System Windows 10 Threshold 2
Kernel Version 10.0.10586.0 (0de6dc23-8e19-4bb7-8608-d54b1e6fa379)
Network Scheme Name Local Gateway
Network Config Name Local Gateway
Platform Version 4.3.0
Dynamic Engine Version 4.3.0 / 09/20/2021 03:59
Static Engine Version 4.3.0.0 / 2021-09-20 03:00:12
AV Exceptions Version 4.3.1.6 / 2021-09-21 13:25:28 Link Detonation Heuristics Version 4.3.1.6 / 2021-09-21 13:25:28
Signature Trust Store Version 4.3.1.6 / 2021-09-21 13:25:28
VMRay Threat Identifiers Version 4.3.1.16 / 2021-10-20 13:20:51 YARA Built-in Ruleset Version 4.3.1.11
Built-in AV Version AVCORE v2.2 Linux/x86_64 11.0.1.19 (March 15, 2021) Built-in AV Database Update Release
Date 2021-10-26 11:48:59+00:00
Built-in AV Database Records 11041076
Adobe Acrobat Reader Version Not installed
Microsoft Office 2016
Microsoft Office Version 16.0.4266.1003
Hangul Office Not installed
Hangul Office Version Not installed
Internet Explorer Version 11.0.10586.0
Chrome Version Not installed
Firefox Version Not installed
Flash Version Not installed
Java Version Not installed
Sample Directory C:\Users\RDhJ0CNFevzX\Desktop
Computer Name XC64ZB
User Domain XC64ZB
X-Ray Vision for Malware - www.vmray.com 30 / 31
User Name RDhJ0CNFevzX
User Profile C:\Users\RDhJ0CNFevzX
Temp Directory C:\Users\RDHJ0C~1\AppData\Local\Temp
System Root C:\Windows