Windows
Analysis Report
FpDGxxu5mz.exe
Overview
General Information
Sample name: | FpDGxxu5mz.exerenamed because original name is a hash value |
Original sample name: | 58ea56177cf0e8a863d6e9f11570a3e61239e21e1d0b5667537b7223d4131c42.exe |
Analysis ID: | 1670867 |
MD5: | 28103f745f58a2af71d327012846c022 |
SHA1: | a2aac68296750c9299123611e4801b3e91b0747d |
SHA256: | 58ea56177cf0e8a863d6e9f11570a3e61239e21e1d0b5667537b7223d4131c42 |
Tags: | cactusexeransomwareuser-TheRavenFile |
Infos: | |
Detection
Score: | 64 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
FpDGxxu5mz.exe (PID: 7156 cmdline:
"C:\Users\ user\Deskt op\FpDGxxu 5mz.exe" d umpChromeC ache MD5: 28103F745F58A2AF71D327012846C022) conhost.exe (PID: 2352 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Babuk | Babuk Ransomware is a sophisticated ransomware compiled for several platforms. Windows and ARM for Linux are the most used compiled versions, but ESX and a 32bit old PE executable were observed over time. as well It uses an Elliptic Curve Algorithm (Montgomery Algorithm) to build the encryption keys. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_babuk | Yara detected Babuk Ransomware | Joe Security | ||
JoeSecurity_babuk | Yara detected Babuk Ransomware | Joe Security | ||
JoeSecurity_babuk | Yara detected Babuk Ransomware | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_babuk | Yara detected Babuk Ransomware | Joe Security | ||
JoeSecurity_babuk | Yara detected Babuk Ransomware | Joe Security |
- • AV Detection
- • Compliance
- • Networking
- • Spam, unwanted Advertisements and Ransom Demands
- • System Summary
- • Data Obfuscation
- • Persistence and Installation Behavior
- • Malware Analysis System Evasion
- • Anti Debugging
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link |
Source: | Static PE information: |
Networking |
---|
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Binary or memory string: |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 2 Command and Scripting Interpreter | 1 Bootkit | 1 Process Injection | 1 Bootkit | OS Credential Dumping | 1 System Information Discovery | Remote Services | Data from Local System | 1 Proxy | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 DLL Side-Loading | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 File Deletion | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
62% | Virustotal | Browse |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1670867 |
Start date and time: | 2025-04-22 08:47:41 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 2m 7s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 2 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Power Change |
Sample name: | FpDGxxu5mz.exerenamed because original name is a hash value |
Original Sample Name: | 58ea56177cf0e8a863d6e9f11570a3e61239e21e1d0b5667537b7223d4131c42.exe |
Detection: | MAL |
Classification: | mal64.rans.evad.winEXE@2/0@0/0 |
EGA Information: | Failed |
HCA Information: | Failed |
Cookbook Comments: |
|
- Execution Graph export aborted
for target FpDGxxu5mz.exe, PI D 7156 because it is empty - Not all processes where analyz
ed, report is missing behavior information
File type: | |
Entropy (8bit): | 6.418322954960814 |
TrID: |
|
File name: | FpDGxxu5mz.exe |
File size: | 9'222'221 bytes |
MD5: | 28103f745f58a2af71d327012846c022 |
SHA1: | a2aac68296750c9299123611e4801b3e91b0747d |
SHA256: | 58ea56177cf0e8a863d6e9f11570a3e61239e21e1d0b5667537b7223d4131c42 |
SHA512: | 13cd94ca0f93ad8c256aad7e2420e1faa3a9b36e08a68eeab6a6541fedf479dd5c52b1ea27eeddeb1cac4b07b35386a9f672c53d3e9c7a3bd64083a4f26ef322 |
SSDEEP: | 98304:+acgM8gcIKsM+eF+zBzYDrOm+rtqycR3oJtOUHu345hsMXWrGBbFF:vcKpW6vToJtOUHh |
TLSH: | 65965B5365AB0CEDDDDA67B492C76336A734FD218A796F3B6604C6302D139C06E6BB00 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...55Se..d.......&....(.0@..&S..>.............@.............................Pi...........`... ............................ |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x1400013f0 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x140000000 |
Subsystem: | windows cui |
Image File Characteristics: | EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LARGE_ADDRESS_AWARE |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT |
Time Stamp: | 0x65533535 [Tue Nov 14 08:52:05 2023 UTC] |
TLS Callbacks: | 0x4032b450, 0x1, 0x4032b420, 0x1, 0x4033fa10, 0x1 |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | 420a466cfef422c9552b63a4268b7c26 |
Instruction |
---|
dec eax |
sub esp, 28h |
dec eax |
mov eax, dword ptr [004BE4A5h] |
mov dword ptr [eax], 00000000h |
call 00007F75F0DE0BAFh |
nop |
nop |
dec eax |
add esp, 28h |
ret |
nop dword ptr [eax] |
dec eax |
sub esp, 28h |
call 00007F75F111C604h |
dec eax |
cmp eax, 01h |
sbb eax, eax |
dec eax |
add esp, 28h |
ret |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
dec eax |
lea ecx, dword ptr [00000009h] |
jmp 00007F75F0DE0E09h |
nop dword ptr [eax+00h] |
ret |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
push ebp |
dec eax |
mov ebp, esp |
dec eax |
sub esp, 00000090h |
dec eax |
mov eax, dword ptr [0056B7EEh] |
call eax |
dec eax |
mov dword ptr [ebp-08h], eax |
mov ecx, 00000008h |
call 00007F75F111C763h |
dec eax |
mov dword ptr [ebp-10h], eax |
mov edx, 00000028h |
mov ecx, 00000040h |
dec eax |
mov eax, dword ptr [0056B931h] |
call eax |
dec eax |
mov dword ptr [ebp-18h], eax |
dec eax |
mov eax, dword ptr [ebp-10h] |
inc ecx |
mov eax, 00000004h |
mov edx, 00000008h |
dec eax |
mov ecx, eax |
dec eax |
mov eax, dword ptr [0056B66Ah] |
call eax |
mov dword ptr [ebp-26h], 00000000h |
mov word ptr [ebp-22h], 0100h |
dec eax |
lea eax, dword ptr [ebp+00h] |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x56c000 | 0x2cc8 | .idata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x571000 | 0x4e8 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x4d6000 | 0x27954 | .pdata |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x572000 | 0x9f24 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x4bd9a0 | 0x28 | .rdata |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x402ea0 | 0x403000 | a700c361bf7ff1f054258ad5859bd39f | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.data | 0x404000 | 0x5120 | 0x5200 | 1e2068f38e1e5ae194417fca611a179a | False | 0.13743330792682926 | data | 2.1653355379041606 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rdata | 0x40a000 | 0xcb020 | 0xcb200 | 8687c5e6e518238808aaaf28411d3776 | False | 0.2903569711538462 | data | 5.092681150806435 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.pdata | 0x4d6000 | 0x27954 | 0x27a00 | ff7fb169aa1eca4c0bcc0bf7757f8756 | False | 0.5123533615930599 | data | 6.27886994966621 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.xdata | 0x4fe000 | 0x29fa4 | 0x2a000 | 73658f427523bb7f3687805d7ac4df69 | False | 0.17534528459821427 | data | 4.696488064345917 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.bss | 0x528000 | 0x43c90 | 0x0 | d41d8cd98f00b204e9800998ecf8427e | False | 0 | empty | 0.0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.idata | 0x56c000 | 0x2cc8 | 0x2e00 | 69746e9a4bc654ad2d3879f76aef4067 | False | 0.23887567934782608 | data | 4.1612110610475375 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.CRT | 0x56f000 | 0x68 | 0x200 | 21c93f2bcee1c688b9fe8b9ddec69da7 | False | 0.078125 | data | 0.40517793218226683 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.tls | 0x570000 | 0x10 | 0x200 | bf619eac0cdf3f68d496ea9344137e8b | False | 0.02734375 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x571000 | 0x4e8 | 0x600 | 7bb75ff0b08b50c6eac14449d8033074 | False | 0.333984375 | data | 4.7823913622889584 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.reloc | 0x572000 | 0x9f24 | 0xa000 | b40bdd14ef25f83c3b734dc8494f1af3 | False | 0.280615234375 | data | 5.447732730518641 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/4 | 0x57c000 | 0x2320 | 0x2400 | 155d205b7768319fc16c6193547ced31 | False | 0.2290581597222222 | data | 2.4823784798357296 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/19 | 0x57f000 | 0xc5491 | 0xc5600 | 9621ad865609ce01f20e476941f326e0 | False | 0.2964804167986067 | data | 5.99720512724903 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/31 | 0x645000 | 0xc344 | 0xc400 | d0dae32b904e99bb4130f2e43cd8fd71 | False | 0.23513233418367346 | data | 4.949853175205664 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/45 | 0x652000 | 0x19938 | 0x19a00 | dbaf734d802fe9954edfc2a126761d8b | False | 0.43200266768292683 | data | 5.228436165097792 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/57 | 0x66c000 | 0x7e28 | 0x8000 | 09f255d888f36f7d4c31f945010f3441 | False | 0.202728271484375 | data | 4.5543712468317326 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/70 | 0x674000 | 0x2bca | 0x2c00 | 97f29411b63f8b434953d3282e700b41 | False | 0.2785866477272727 | data | 4.556736428924381 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/81 | 0x677000 | 0x6dad | 0x6e00 | 4ed97bfeb189274bc8b5b75aea293de0 | False | 0.11484375 | data | 5.032229185084522 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/97 | 0x67e000 | 0x14aab | 0x14c00 | 1be73727f80219b15607329ef6e261e8 | False | 0.5041886295180723 | data | 5.96849766260411 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/113 | 0x693000 | 0x1b33 | 0x1c00 | 1678cb88d45355fbfb5c65063ca38aa7 | False | 0.5418526785714286 | data | 5.468883146113603 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_MANIFEST | 0x571058 | 0x48f | XML 1.0 document, ASCII text | 0.40102827763496146 |
DLL | Import |
---|---|
KERNEL32.DLL | AcquireSRWLockExclusive, AcquireSRWLockShared, AddVectoredExceptionHandler, CloseHandle, ConvertFiberToThread, ConvertThreadToFiberEx, CopyFileW, CreateDirectoryW, CreateEventA, CreateFiberEx, CreateFileW, CreateHardLinkW, CreateMutexW, CreateProcessW, CreateSemaphoreA, CreateToolhelp32Snapshot, DeleteCriticalSection, DeleteFiber, DeleteFileW, DuplicateHandle, EnterCriticalSection, FindClose, FindFirstFileW, FindFirstVolumeW, FindNextFileW, FindNextVolumeW, FindVolumeClose, FormatMessageA, FormatMessageW, FreeLibrary, GetACP, GetConsoleMode, GetConsoleWindow, GetCurrentProcess, GetCurrentProcessId, GetCurrentThread, GetCurrentThreadId, GetDiskFreeSpaceExW, GetDriveTypeW, GetEnvironmentVariableW, GetFileAttributesW, GetFileInformationByHandle, GetFileSizeEx, GetFileType, GetFullPathNameW, GetHandleInformation, GetLastError, GetLogicalDriveStringsW, GetModuleFileNameA, GetModuleFileNameW, GetModuleHandleExA, GetModuleHandleExW, GetModuleHandleW, GetProcAddress, GetProcessAffinityMask, GetProcessHeap, GetProcessId, GetStdHandle, GetSystemDirectoryA, GetSystemInfo, GetSystemTimeAsFileTime, GetTempPathW, GetThreadContext, GetThreadPriority, GetTickCount64, GetVersion, GetVolumeInformationW, HeapAlloc, HeapFree, InitializeCriticalSection, InitializeSRWLock, IsDBCSLeadByteEx, IsDebuggerPresent, IsProcessorFeaturePresent, K32GetProcessImageFileNameW, LeaveCriticalSection, LoadLibraryA, LoadLibraryW, LocalAlloc, LocalFree, MoveFileExW, MultiByteToWideChar, OpenProcess, OutputDebugStringA, Process32NextW, RaiseException, ReadConsoleA, ReadConsoleW, ReleaseSRWLockExclusive, ReleaseSRWLockShared, ReleaseSemaphore, RemoveDirectoryW, RemoveVectoredExceptionHandler, ResetEvent, ResumeThread, RtlCaptureContext, RtlLookupFunctionEntry, RtlUnwindEx, RtlVirtualUnwind, SetConsoleMode, SetEndOfFile, SetEvent, SetFileAttributesW, SetFilePointer, SetLastError, SetProcessAffinityMask, SetThreadContext, SetThreadPriority, SetUnhandledExceptionFilter, Sleep, SuspendThread, SwitchToFiber, TerminateProcess, TlsAlloc, TlsFree, TlsGetValue, TlsSetValue, TryEnterCriticalSection, VirtualAlloc, VirtualFree, VirtualLock, VirtualProtect, VirtualQuery, WaitForMultipleObjects, WaitForSingleObject, WideCharToMultiByte, WriteFile |
ADVAPI32.dll | AddAccessDeniedAce, AllocateAndInitializeSid, CloseServiceHandle, ControlService, CryptAcquireContextW, CryptGenRandom, CryptReleaseContext, DeregisterEventSource, InitializeAcl, OpenSCManagerA, OpenServiceA, RegisterEventSourceW, ReportEventW, SetSecurityInfo |
msvcrt.dll | __C_specific_handler, ___lc_codepage_func, ___mb_cur_max_func, __getmainargs, __initenv, __iob_func, __set_app_type, __setusermatherr, _amsg_exit, _beginthreadex, _cexit, _close, _commode, _endthreadex, _errno, _exit, _fdopen, _fileno, _findclose, _fileno, _fmode, _fstat64, _get_osfhandle, _gmtime64, _initterm, _localtime64, _lock, _lseeki64, _onexit, _read, _setjmp, _setmode, _stat64, _strdup, _strdup, _strtoi64, _strtoui64, _telli64, _time64, _ultoa, _unlock, _vsnprintf, _vsnwprintf, _wchdir, _wchmod, _wfindfirst64, _wfindnext64, _wfopen, _wfullpath, _wgetcwd, _wmkdir, _wopen, _wremove, _wrename, _write, _wstat64, _wsystem, _wutime64, abort, atoi, calloc, clock, exit, fclose, feof, ferror, fflush, fgets, fopen, fprintf, fputc, fputs, fputwc, fread, free, fwprintf, fseek, ftell, fwrite, getc, getenv, isspace, iswctype, isxdigit, localeconv, longjmp, malloc, memchr, memcmp, memcpy, memmove, memset, printf, qsort, raise, rand, realloc, remove, setlocale, setvbuf, signal, sprintf, srand, strcat, strchr, strcmp, strcoll, strcpy, strcspn, strerror, strftime, strlen, strncmp, strncpy, strrchr, strspn, strstr, strtol, strtoul, strxfrm, tolower, towlower, towupper, ungetc, vfprintf, wcscat, wcscmp, wcscoll, wcscpy, wcsftime, wcslen, wcsncmp, wcsstr, wcstol, wcstombs, wcsxfrm |
RstrtMgr.DLL | RmEndSession, RmGetList, RmRegisterResources, RmShutdown, RmStartSession |
SHELL32.dll | IsUserAnAdmin, StrStrIW |
USER32.dll | GetProcessWindowStation, GetUserObjectInformationW, MessageBoxW, ShowWindow |
WS2_32.dll | gethostbyaddr, getservbyname, getservbyport, htonl, htons, inet_addr, inet_ntoa |
WSOCK32.dll | WSACleanup, WSAGetLastError, WSASetLastError, WSAStartup, accept, bind, closesocket, connect, gethostbyname, getsockname, getsockopt, ioctlsocket, listen, ntohs, recv, select, send, setsockopt, shutdown, socket |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 02:48:39 |
Start date: | 22/04/2025 |
Path: | C:\Users\user\Desktop\FpDGxxu5mz.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff60e5a0000 |
File size: | 9'222'221 bytes |
MD5 hash: | 28103F745F58A2AF71D327012846C022 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 02:48:39 |
Start date: | 22/04/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff642da0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|