Architecture |
IMAGE_FILE_MACHINE_AMD64
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2020-Jan-10 19:56:41 |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
Malicious | The PE contains functions mostly used by malware. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 45/73 (Scanned on 2020-01-14 06:06:16) |
MicroWorld-eScan:
Generic.Ransom.Ryuk.6921BED2
FireEye: Generic.mg.3ba338d8ce6e68cb McAfee: Ransom-Ryuk!3BA338D8CE6E Cylance: Unsafe Sangfor: Malware Alibaba: Ransom:Win32/generic.ali2000010 K7GW: Trojan ( 00558f321 ) Cybereason: malicious.8ce6e6 Arcabit: Generic.Ransom.Ryuk.6921BED2 TrendMicro: Ransom.Win64.RYUK.SM Symantec: Ransom.Ryuk APEX: Malicious Avast: Win64:RansomX-gen [Ransom] ClamAV: Win.Ransomware.Generic-6545091-0 Kaspersky: HEUR:Backdoor.Win32.Androm.vho BitDefender: Generic.Ransom.Ryuk.6921BED2 Paloalto: generic.ml Rising: Ransom.Ryuk!1.B855 (CLOUD) Ad-Aware: Generic.Ransom.Ryuk.6921BED2 Sophos: Troj/Ryuk-G F-Secure: Heuristic.HEUR/AGEN.1043293 Invincea: heuristic McAfee-GW-Edition: Ransom-Ryuk!3BA338D8CE6E Fortinet: W64/Filecoder.AC!tr Trapmine: malicious.high.ml.score Emsisoft: Generic.Ransom.Ryuk.6921BED2 (B) Webroot: W32.Trojan.Gen Avira: HEUR/AGEN.1043293 MAX: malware (ai score=89) Endgame: malicious (high confidence) Microsoft: Ransom:Win64/Ryuk.PA!MTB AegisLab: Trojan.Win32.Encoder.tqSm ZoneAlarm: HEUR:Backdoor.Win32.Androm.vho AhnLab-V3: Malware/Win64.Ransom.C3520810 Acronis: suspicious ALYac: Generic.Ransom.Ryuk.6921BED2 Malwarebytes: Ransom.Ryuk ESET-NOD32: a variant of Win64/Filecoder.Ryuk.E TrendMicro-HouseCall: Ransom.Win64.RYUK.SM Tencent: Win32.Backdoor.Androm.Lmut Ikarus: Trojan-Ransom.Ryuk GData: Generic.Ransom.Ryuk.6921BED2 AVG: Win64:RansomX-gen [Ransom] Panda: Trj/CI.A CrowdStrike: win/malicious_confidence_80% (W) |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xf0 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_AMD64
|
NumberofSections | 6 |
TimeDateStamp | 2020-Jan-10 19:56:41 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xf0 |
Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
Magic | PE32+ |
---|---|
LinkerVersion | 14.0 |
SizeOfCode | 0x14600 |
SizeOfInitializedData | 0x15bc00 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x0000000000005E78 (Section: .text) |
BaseOfCode | 0x1000 |
ImageBase | 0x140000000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 5.2 |
ImageVersion | 0.0 |
SubsystemVersion | 5.2 |
Win32VersionValue | 0 |
SizeOfImage | 0x175000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
IPHLPAPI.DLL |
IcmpCloseHandle
IcmpCreateFile GetAdaptersAddresses IcmpSendEcho GetIpNetTable |
---|---|
KERNEL32.dll |
SetLastError
WriteProcessMemory WaitForMultipleObjects Sleep GetLogicalDrives SetFilePointer CloseHandle WinExec GetTickCount GetLastError LoadLibraryA GetModuleFileNameW GetModuleHandleA GetCommandLineW GetTempPathW GetWindowsDirectoryW CreateFileW DeleteFileW CopyFileW GetVersionExW CreateToolhelp32Snapshot Process32FirstW Process32NextW GetCurrentThread CreateRemoteThread CreateThread ExitProcess GetCurrentProcess OpenProcess GetProcessHeap HeapFree HeapAlloc VirtualFreeEx VirtualAllocEx VirtualFree VirtualAlloc LocalFree GlobalFree GlobalAlloc GetProcAddress FreeLibrary SetFilePointerEx HeapReAlloc HeapSize GetConsoleMode GetConsoleCP FlushFileBuffers WriteConsoleW SetStdHandle FreeEnvironmentStringsW GetEnvironmentStringsW GetCommandLineA QueryPerformanceCounter GetCurrentProcessId GetCurrentThreadId GetSystemTimeAsFileTime InitializeSListHead RtlCaptureContext RtlLookupFunctionEntry RtlVirtualUnwind IsDebuggerPresent UnhandledExceptionFilter SetUnhandledExceptionFilter GetStartupInfoW IsProcessorFeaturePresent GetModuleHandleW RtlUnwindEx RtlPcToFileHeader RaiseException EnterCriticalSection LeaveCriticalSection DeleteCriticalSection InitializeCriticalSectionAndSpinCount TlsAlloc TlsGetValue TlsSetValue TlsFree LoadLibraryExW TerminateProcess GetModuleHandleExW GetStdHandle WriteFile MultiByteToWideChar WideCharToMultiByte GetACP GetStringTypeW LCMapStringW GetFileType FindClose FindFirstFileExW FindNextFileW IsValidCodePage GetOEMCP GetCPInfo |
ADVAPI32.dll |
OpenProcessToken
OpenThreadToken GetTokenInformation AdjustTokenPrivileges LookupAccountSidW OpenSCManagerW EnumServicesStatusW LookupPrivilegeValueW ImpersonateSelf |
SHELL32.dll |
ShellExecuteW
CommandLineToArgvW |
WS2_32.dll |
#23
#21 #20 #115 #8 #3 #2 #116 #9 #11 |
Characteristics |
0
|
---|---|
TimeDateStamp | 2020-Jan-10 19:56:41 |
Version | 0.0 |
SizeofData | 736 |
AddressOfRawData | 0x1ed2c |
PointerToRawData | 0x1d72c |
Characteristics |
0
|
---|---|
TimeDateStamp | 2020-Jan-10 19:56:41 |
Version | 0.0 |
SizeofData | 0 |
AddressOfRawData | 0 |
PointerToRawData | 0 |
Size | 0x94 |
---|---|
TimeDateStamp | 1970-Jan-01 00:00:00 |
Version | 0.0 |
GlobalFlagsClear | (EMPTY) |
GlobalFlagsSet | (EMPTY) |
CriticalSectionDefaultTimeout | 0 |
DeCommitFreeBlockThreshold | 0 |
DeCommitTotalFreeThreshold | 0 |
LockPrefixTable | 0 |
MaximumAllocationSize | 0 |
VirtualMemoryThreshold | 0 |
ProcessAffinityMask | 0 |
ProcessHeapFlags | (EMPTY) |
CSDVersion | 0 |
Reserved1 | 0 |
EditList | 0 |
SecurityCookie | 0x140031798 |
XOR Key | 0xe301606b |
---|---|
Unmarked objects | 0 |
241 (40116) | 6 |
243 (40116) | 126 |
242 (40116) | 13 |
ASM objects (VS2015 UPD3 build 24123) | 6 |
C++ objects (VS2015 UPD3 build 24123) | 34 |
C objects (VS2015 UPD3 build 24123) | 20 |
Imports (VS2008 SP1 build 30729) | 11 |
Total imports | 151 |
C++ objects (VS2015 UPD3.1 build 24215) | 2 |
Linker (VS2015 UPD3.1 build 24215) | 1 |