Windows
Analysis Report
H6VMxCA4Pn.exe
Overview
General Information
Sample name: | H6VMxCA4Pn.exerenamed because original name is a hash value |
Original sample name: | 871b245bd87dbb3ed064e9e42522dcb7dee8d80b9463f8ee4bcf9da184dd5e87.exe |
Analysis ID: | 1675331 |
MD5: | 466a8e120c75770ecbc0c73f0439d304 |
SHA1: | fd7a5b83989667fca0a7e8c39ea46f0fbafc4bd3 |
SHA256: | 871b245bd87dbb3ed064e9e42522dcb7dee8d80b9463f8ee4bcf9da184dd5e87 |
Tags: | cactusexeransomwareuser-TheRavenFile |
Infos: | |
Detection
Score: | 64 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
H6VMxCA4Pn.exe (PID: 7352 cmdline:
"C:\Users\ user\Deskt op\H6VMxCA 4Pn.exe" MD5: 466A8E120C75770ECBC0C73F0439D304) conhost.exe (PID: 7360 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Babuk | Babuk Ransomware is a sophisticated ransomware compiled for several platforms. Windows and ARM for Linux are the most used compiled versions, but ESX and a 32bit old PE executable were observed over time. as well It uses an Elliptic Curve Algorithm (Montgomery Algorithm) to build the encryption keys. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_babuk | Yara detected Babuk Ransomware | Joe Security | ||
JoeSecurity_babuk | Yara detected Babuk Ransomware | Joe Security | ||
JoeSecurity_babuk | Yara detected Babuk Ransomware | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_babuk | Yara detected Babuk Ransomware | Joe Security | ||
JoeSecurity_babuk | Yara detected Babuk Ransomware | Joe Security |
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Static PE information: |
Networking |
---|
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Binary or memory string: |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 2 Command and Scripting Interpreter | 1 Bootkit | 1 Process Injection | 1 Bootkit | OS Credential Dumping | 1 Security Software Discovery | Remote Services | Data from Local System | 1 Proxy | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Process Injection | LSASS Memory | 1 Process Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 DLL Side-Loading | Security Account Manager | 1 System Information Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 File Deletion | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
65% | Virustotal | Browse | ||
69% | ReversingLabs | Win64.Ransomware.Kaktos |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
true |
| unknown |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1675331 |
Start date and time: | 2025-04-27 05:37:16 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 19s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 11 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | H6VMxCA4Pn.exerenamed because original name is a hash value |
Original Sample Name: | 871b245bd87dbb3ed064e9e42522dcb7dee8d80b9463f8ee4bcf9da184dd5e87.exe |
Detection: | MAL |
Classification: | mal64.rans.evad.winEXE@2/0@0/0 |
EGA Information: | Failed |
HCA Information: | Failed |
Cookbook Comments: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, S IHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 184.29.183.29, 172 .202.163.200 - Excluded domains from analysis
(whitelisted): a-ring-fallbac k.msedge.net, fs.microsoft.com , slscr.update.microsoft.com, fe3cr.delivery.mp.microsoft.co m - Execution Graph export aborted
for target H6VMxCA4Pn.exe, PI D 7352 because it is empty - Not all processes where analyz
ed, report is missing behavior information
File type: | |
Entropy (8bit): | 6.417471372544136 |
TrID: |
|
File name: | H6VMxCA4Pn.exe |
File size: | 9'301'424 bytes |
MD5: | 466a8e120c75770ecbc0c73f0439d304 |
SHA1: | fd7a5b83989667fca0a7e8c39ea46f0fbafc4bd3 |
SHA256: | 871b245bd87dbb3ed064e9e42522dcb7dee8d80b9463f8ee4bcf9da184dd5e87 |
SHA512: | ebbe62fb8fabc044ed6c6d5ec42a4766d891eff64eb7b67d11e02411eaddc07653d48b41e157e858ea41ee020d78421fc4c06f0c8235df68bbab6d1c93571fae |
SSDEEP: | 98304:n+FfIxhQ8w+eR3P6R+mze17zynFVyMWMpMeXyoNdtOUHF345hnMXWcegplh:gEiP6RtqNaMeiqdtOUH9 |
TLSH: | BF964B5365AB0CE9DDD667B492C76336A734FD218A792F3F6604C6302D13AC06E6BB10 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d......g..e.&.....&....(.R@..VS..>.............@..............................j...........`... ............................ |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x1400013f0 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x140000000 |
Subsystem: | windows cui |
Image File Characteristics: | EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LARGE_ADDRESS_AWARE |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT |
Time Stamp: | 0x67A31B93 [Wed Feb 5 08:04:35 2025 UTC] |
TLS Callbacks: | 0x4032d4e0, 0x1, 0x4032d4b0, 0x1, 0x40341a90, 0x1 |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | 48804626b2034b9fcb4423433f85c971 |
Instruction |
---|
dec eax |
sub esp, 28h |
dec eax |
mov eax, dword ptr [004C1B95h] |
mov dword ptr [eax], 00000000h |
call 00007FA4B0B13CBFh |
nop |
nop |
dec eax |
add esp, 28h |
ret |
nop dword ptr [eax] |
dec eax |
sub esp, 28h |
call 00007FA4B0E517A4h |
dec eax |
cmp eax, 01h |
sbb eax, eax |
dec eax |
add esp, 28h |
ret |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
dec eax |
lea ecx, dword ptr [00000009h] |
jmp 00007FA4B0B13F19h |
nop dword ptr [eax+00h] |
ret |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
push ebp |
dec eax |
mov ebp, esp |
dec eax |
add esp, FFFFFF80h |
mov ecx, 00000008h |
call 00007FA4B0E51913h |
dec eax |
mov dword ptr [ebp-08h], eax |
dec eax |
mov eax, dword ptr [ebp-08h] |
inc ecx |
mov eax, 00000004h |
mov edx, 00000008h |
dec eax |
mov ecx, eax |
dec eax |
mov eax, dword ptr [0056F6B1h] |
call eax |
mov dword ptr [ebp-1Eh], 00000000h |
mov word ptr [ebp-1Ah], 0100h |
dec eax |
lea eax, dword ptr [ebp-1Eh] |
dec eax |
lea edx, dword ptr [ebp-18h] |
dec eax |
mov dword ptr [esp+50h], edx |
mov dword ptr [esp+48h], 00000000h |
mov dword ptr [esp+40h], 00000000h |
mov dword ptr [esp+38h], 00000000h |
mov dword ptr [esp+30h], 00000000h |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x570000 | 0x2d20 | .idata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x575000 | 0x4e8 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x4d9000 | 0x27abc | .pdata |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x576000 | 0x9f84 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x4c10a0 | 0x28 | .rdata |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x4051f0 | 0x405200 | 440705eff85c3bda8bfc14157e75fbf4 | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.data | 0x407000 | 0x51e0 | 0x5200 | 73af51cc3739f2c3f0dfb50ea58aade1 | False | 0.13943407012195122 | data | 2.2188756964962106 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rdata | 0x40d000 | 0xcb700 | 0xcb800 | 11254cdcf40a54b2e9532121127f2449 | False | 0.2905381411240786 | data | 5.089672235716194 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.pdata | 0x4d9000 | 0x27abc | 0x27c00 | f1c14e7c1264031e90ca35d34d40f739 | False | 0.5108404579402516 | data | 6.265608697581868 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.xdata | 0x501000 | 0x2a4ec | 0x2a600 | a5b318a574255623eee27921d197f01f | False | 0.17778046644542772 | data | 4.679106316051192 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.bss | 0x52c000 | 0x43d90 | 0x0 | d41d8cd98f00b204e9800998ecf8427e | False | 0 | empty | 0.0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.idata | 0x570000 | 0x2d20 | 0x2e00 | 45eca9c5745836ab6bf5c8a728ac0ff8 | False | 0.24150815217391305 | data | 4.019757774332753 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.CRT | 0x573000 | 0x68 | 0x200 | 1e7a582f0adf512a237e416b59bf7320 | False | 0.078125 | data | 0.41055857183492983 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.tls | 0x574000 | 0x10 | 0x200 | bf619eac0cdf3f68d496ea9344137e8b | False | 0.02734375 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x575000 | 0x4e8 | 0x600 | 030ae0ffd84f4d5fb35bebea560e68c7 | False | 0.3333333333333333 | data | 4.780597815738071 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.reloc | 0x576000 | 0x9f84 | 0xa000 | 27bfddca032fa717ae92280a0c5ee036 | False | 0.2821044921875 | data | 5.451010052213658 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/4 | 0x580000 | 0x2480 | 0x2600 | 4d4328f90a39c6229ef29c32e68ede66 | False | 0.2235814144736842 | data | 2.4302295398813785 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/19 | 0x583000 | 0xd13a2 | 0xd1400 | 53e5847e2c6e27bdae10bda4247dd7d1 | False | 0.29473636312724016 | data | 5.990824587660499 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/31 | 0x655000 | 0xc67f | 0xc800 | 7e215954acbf12192f47b807559b13ad | False | 0.23375 | data | 4.948696830329289 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/45 | 0x662000 | 0x1b0de | 0x1b200 | 56ac9802930ed2e2265816dbe76e5de8 | False | 0.4290214573732719 | data | 5.240525868884352 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/57 | 0x67e000 | 0x8450 | 0x8600 | 99688471e59c08db44c95d893b76c6d2 | False | 0.20157999067164178 | data | 4.562752306631266 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/70 | 0x687000 | 0x3028 | 0x3200 | 7bae741bf9ee07263757d3e91680566c | False | 0.254921875 | data | 4.510426403615046 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/81 | 0x68b000 | 0x6e43 | 0x7000 | cc1d7c67863cde6f3c8504ca31b9d1a3 | False | 0.11324637276785714 | data | 5.017648937189938 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/97 | 0x692000 | 0x14aab | 0x14c00 | 6423425a63adf7c25c5e1397587b3fd5 | False | 0.5042239269578314 | data | 5.968226727632548 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
/113 | 0x6a7000 | 0x1cd1 | 0x1e00 | 974a80b66ebfffcfddb96a0ec9719d50 | False | 0.5291666666666667 | data | 5.381567916499713 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_MANIFEST | 0x575058 | 0x48f | XML 1.0 document, ASCII text | 0.40102827763496146 |
DLL | Import |
---|---|
KERNEL32.DLL | AcquireSRWLockExclusive, AcquireSRWLockShared, AddVectoredExceptionHandler, CloseHandle, ConvertFiberToThread, ConvertThreadToFiberEx, CopyFileW, CreateDirectoryW, CreateEventA, CreateFiberEx, CreateFileW, CreateHardLinkW, CreateProcessW, CreateSemaphoreA, CreateToolhelp32Snapshot, DeleteCriticalSection, DeleteFiber, DeleteFileW, DuplicateHandle, EnterCriticalSection, FindClose, FindFirstFileW, FindFirstVolumeW, FindNextFileW, FindNextVolumeW, FindVolumeClose, FormatMessageA, FormatMessageW, FreeLibrary, GetACP, GetConsoleMode, GetConsoleWindow, GetCurrentProcess, GetCurrentProcessId, GetCurrentThread, GetCurrentThreadId, GetDiskFreeSpaceExW, GetDriveTypeW, GetEnvironmentVariableW, GetFileAttributesW, GetFileInformationByHandle, GetFileSizeEx, GetFileType, GetFullPathNameW, GetHandleInformation, GetLastError, GetLogicalDriveStringsW, GetModuleFileNameA, GetModuleFileNameW, GetModuleHandleExA, GetModuleHandleExW, GetModuleHandleW, GetProcAddress, GetProcessAffinityMask, GetProcessHeap, GetProcessId, GetStdHandle, GetSystemDirectoryA, GetSystemInfo, GetSystemTimeAsFileTime, GetTempPathW, GetThreadContext, GetThreadPriority, GetTickCount64, GetVersion, GetVolumeInformationW, HeapAlloc, HeapFree, InitializeCriticalSection, InitializeSRWLock, IsDBCSLeadByteEx, IsDebuggerPresent, IsProcessorFeaturePresent, K32GetProcessImageFileNameW, LeaveCriticalSection, LoadLibraryA, LoadLibraryW, LocalFree, MoveFileExW, MultiByteToWideChar, OpenProcess, OutputDebugStringA, Process32NextW, RaiseException, ReadConsoleA, ReadConsoleW, ReleaseSRWLockExclusive, ReleaseSRWLockShared, ReleaseSemaphore, RemoveDirectoryW, RemoveVectoredExceptionHandler, ResetEvent, ResumeThread, RtlCaptureContext, RtlLookupFunctionEntry, RtlUnwindEx, RtlVirtualUnwind, SetConsoleMode, SetEndOfFile, SetEvent, SetFileAttributesW, SetFilePointer, SetLastError, SetProcessAffinityMask, SetThreadContext, SetThreadPriority, SetUnhandledExceptionFilter, Sleep, SuspendThread, SwitchToFiber, TerminateProcess, TlsAlloc, TlsFree, TlsGetValue, TlsSetValue, TryEnterCriticalSection, VirtualAlloc, VirtualFree, VirtualLock, VirtualProtect, VirtualQuery, WaitForMultipleObjects, WaitForSingleObject, WideCharToMultiByte, WriteFile |
ADVAPI32.dll | AddAccessDeniedAce, AllocateAndInitializeSid, CloseServiceHandle, ControlService, CryptAcquireContextW, CryptGenRandom, CryptReleaseContext, DeregisterEventSource, InitializeAcl, OpenSCManagerA, OpenServiceA, RegisterEventSourceW, ReportEventW, SetSecurityInfo |
msvcrt.dll | __C_specific_handler, ___lc_codepage_func, ___mb_cur_max_func, __getmainargs, __initenv, __iob_func, __set_app_type, __setusermatherr, _amsg_exit, _beginthreadex, _cexit, _close, _commode, _endthreadex, _errno, _exit, _fdopen, _fileno, _findclose, _fileno, _fmode, _fstat64, _get_osfhandle, _gmtime64, _initterm, _localtime64, _lock, _lseeki64, _onexit, _read, _setjmp, _setmode, _stat64, _strdup, _strdup, _strtoi64, _strtoui64, _telli64, _time64, _ultoa, _unlock, _vsnprintf, _vsnwprintf, _wchdir, _wchmod, _wfindfirst64, _wfindnext64, _wfopen, _wfullpath, _wgetcwd, _wmkdir, _wopen, _wremove, _wrename, _write, _wstat64, _wsystem, _wutime64, abort, atoi, calloc, clock, exit, fclose, feof, ferror, fflush, fgets, fopen, fprintf, fputc, fputs, fputwc, fread, free, fwprintf, fseek, ftell, fwrite, getc, getenv, isspace, iswctype, isxdigit, localeconv, longjmp, malloc, memchr, memcmp, memcpy, memmove, memset, printf, qsort, raise, rand, realloc, remove, setlocale, setvbuf, signal, sprintf, srand, strcat, strchr, strcmp, strcoll, strcpy, strcspn, strerror, strftime, strlen, strncmp, strncpy, strrchr, strspn, strstr, strtol, strtoul, strxfrm, tolower, towlower, towupper, ungetc, vfprintf, wcscat, wcscmp, wcscoll, wcscpy, wcsftime, wcslen, wcsncmp, wcsstr, wcstol, wcstombs, wcsxfrm |
NETAPI32.dll | NetApiBufferFree, NetShareDel, NetShareEnum |
RstrtMgr.DLL | RmEndSession, RmGetList, RmRegisterResources, RmShutdown, RmStartSession |
SHELL32.dll | IsUserAnAdmin, StrStrIW |
USER32.dll | GetProcessWindowStation, GetUserObjectInformationW, MessageBoxW, ShowWindow |
WS2_32.dll | gethostbyaddr, getservbyname, getservbyport, htonl, htons, inet_addr, inet_ntoa |
WSOCK32.dll | WSACleanup, WSAGetLastError, WSASetLastError, WSAStartup, accept, bind, closesocket, connect, gethostbyname, getsockname, getsockopt, ioctlsocket, listen, ntohs, recv, select, send, setsockopt, shutdown, socket |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 23:38:14 |
Start date: | 26/04/2025 |
Path: | C:\Users\user\Desktop\H6VMxCA4Pn.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6f3150000 |
File size: | 9'301'424 bytes |
MD5 hash: | 466A8E120C75770ECBC0C73F0439D304 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 23:38:14 |
Start date: | 26/04/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff62fc20000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|