top title background image
flash

Filecoder Nemty 64bit.exe

Status: finished
Submission Time: 2020-08-01 21:45:30 +02:00
Malicious
Ransomware
Evader
Nefilim

Comments

Tags

Details

  • Analysis ID:
    255761
  • API (Web) ID:
    407060
  • Analysis Started:
    2020-08-02 01:08:19 +02:00
  • Analysis Finished:
    2020-08-02 01:13:07 +02:00
  • MD5:
    9a59c5c95c68d06ccf2a38cd40d67a40
  • SHA1:
    ad530c2f6291a7ca1001b8698cf6587c70aba47c
  • SHA256:
    f9ed3c070a2731acbfef6d4b2af980b6e922b2dda0e9227e02f4b4f3821f4b17
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
Score: 60
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

URLs

Name Detection
http://hxt254aygrsziejn.onion
http://crl.sectigo.com/SectigoRSACodeSigningCA.crl0s
https://sectigo.com/CPS0
Click to see the 3 hidden entries
http://ocsp.sectigo.com0
http://crt.sectigo.com/SectigoRSACodeSigningCA.crt0#
http://corpleaks.net

Dropped files

Name File Type Hashes Detection
C:\Users\user\Desktop\NWTVCDUMOB\NWTVCDUMOB.docx
data
#
C:\Users\user\Desktop\WUTJSCBCFX\WUTJSCBCFX.docx
data
#
C:\Users\user\Desktop\ZBEDCJPBEY.pdf
data
#
Click to see the 97 hidden entries
C:\Users\user\Documents\NWTVCDUMOB\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\user\Documents\NWTVCDUMOB\NWTVCDUMOB.docx
data
#
C:\Users\user\Documents\NWTVCDUMOB\KZWFNRXYKI.jpg
data
#
C:\Users\user\Documents\NWTVCDUMOB\JSDNGYCOWY.png
data
#
C:\Users\user\Documents\NWTVCDUMOB.docx
data
#
C:\Users\user\Documents\NIKHQAIQAU\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\user\Documents\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\user\Documents\KZWFNRXYKI.xlsx
data
#
C:\Users\user\Documents\KZWFNRXYKI.jpg
data
#
C:\Users\user\Documents\JSDNGYCOWY.png
data
#
C:\Users\user\Documents\FENIVHOIKN.png
data
#
C:\Users\user\Documents\BPMLNOBVSB\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\user\Documents\BPMLNOBVSB.jpg
data
#
C:\Users\user\Desktop\ZBEDCJPBEY.mp3
data
#
C:\Users\user\Desktop\YPSIACHYXW.pdf
data
#
C:\Users\user\Desktop\WUTJSCBCFX\ZBEDCJPBEY.pdf
data
#
C:\Users\user\Desktop\WUTJSCBCFX\WKXEWIOTXI.mp3
data
#
C:\Users\user\Desktop\WUTJSCBCFX\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\user\Desktop\WUTJSCBCFX\KZWFNRXYKI.xlsx
data
#
C:\Users\user\Desktop\WUTJSCBCFX\FENIVHOIKN.png
data
#
C:\Users\user\Desktop\WUTJSCBCFX\BPMLNOBVSB.jpg
data
#
C:\Users\user\Desktop\WUTJSCBCFX.xlsx
data
#
C:\Users\user\Desktop\WUTJSCBCFX.docx
data
#
C:\Users\user\Documents\WUTJSCBCFX\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\user\Downloads\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\user\Downloads\KZWFNRXYKI.xlsx
data
#
C:\Users\user\Downloads\KZWFNRXYKI.jpg
data
#
C:\Users\user\Downloads\JSDNGYCOWY.png
data
#
C:\Users\user\Downloads\FENIVHOIKN.png
data
#
C:\Users\user\Downloads\BPMLNOBVSB.jpg
data
#
C:\Users\user\Documents\ZBEDCJPBEY.pdf
data
#
C:\Users\user\Documents\ZBEDCJPBEY.mp3
data
#
C:\Users\user\Documents\YPSIACHYXW.pdf
data
#
C:\Users\user\Documents\WUTJSCBCFX\ZBEDCJPBEY.pdf
data
#
C:\Users\user\Documents\WUTJSCBCFX\WUTJSCBCFX.docx
PGP\011Secret Sub-key -
#
C:\Users\user\Documents\WUTJSCBCFX\WKXEWIOTXI.mp3
data
#
C:\Users\user\Desktop\WKXEWIOTXI.mp3
data
#
C:\Users\user\Documents\WUTJSCBCFX\KZWFNRXYKI.xlsx
data
#
C:\Users\user\Documents\WUTJSCBCFX\FENIVHOIKN.png
data
#
C:\Users\user\Documents\WUTJSCBCFX\BPMLNOBVSB.jpg
data
#
C:\Users\user\Documents\WUTJSCBCFX.xlsx
data
#
C:\Users\user\Documents\WUTJSCBCFX.docx
data
#
C:\Users\user\Documents\WKXEWIOTXI.mp3
data
#
C:\Users\user\Documents\VAMYDFPUND\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\user\Documents\UOOJJOZIRH\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\user\Documents\NWTVCDUMOB\ZBEDCJPBEY.mp3
data
#
C:\Users\user\Documents\NWTVCDUMOB\YPSIACHYXW.pdf
data
#
C:\Users\user\Documents\NWTVCDUMOB\WUTJSCBCFX.xlsx
data
#
C:\Users\Default\NTUSER.DAT.LOG1
data
#
C:\Users\Public\Libraries\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\Public\Downloads\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\Public\Documents\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\Public\Desktop\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\Public\AccountPictures\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\Default\Videos\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\Default\Saved Games\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\Default\Pictures\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\Default\NTUSER.DAT{8ebe95f7-3dcb-11e8-a9d9-7cfe90913f50}.TMContainer00000000000000000002.regtrans-ms
data
#
C:\Users\Default\NTUSER.DAT{8ebe95f7-3dcb-11e8-a9d9-7cfe90913f50}.TMContainer00000000000000000001.regtrans-ms
data
#
C:\Users\Default\NTUSER.DAT{8ebe95f7-3dcb-11e8-a9d9-7cfe90913f50}.TM.blf
data
#
C:\Users\Public\Libraries\RecordedTV.library-ms
data
#
C:\Users\Default\NTUSER.DAT
data
#
C:\Users\Default\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\Default\Music\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\Default\Links\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\Default\Favorites\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\Default\Downloads\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\Default\Documents\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\Default\Desktop\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Recovery\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\PerfLogs\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\user\Desktop\KZWFNRXYKI.xlsx
data
#
C:\Users\user\Desktop\VAMYDFPUND\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\user\Desktop\UOOJJOZIRH\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\user\Desktop\NWTVCDUMOB\ZBEDCJPBEY.mp3
data
#
C:\Users\user\Desktop\NWTVCDUMOB\YPSIACHYXW.pdf
data
#
C:\Users\user\Desktop\NWTVCDUMOB\WUTJSCBCFX.xlsx
data
#
C:\Users\user\Desktop\NWTVCDUMOB\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\user\Desktop\NWTVCDUMOB\KZWFNRXYKI.jpg
data
#
C:\Users\user\Desktop\NWTVCDUMOB\JSDNGYCOWY.png
data
#
C:\Users\user\Desktop\NWTVCDUMOB.docx
data
#
C:\Users\user\Desktop\NIKHQAIQAU\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\user\Desktop\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Config.Msi\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\user\Desktop\KZWFNRXYKI.jpg
data
#
C:\Users\user\Desktop\JSDNGYCOWY.png
data
#
C:\Users\user\Desktop\FENIVHOIKN.png
data
#
C:\Users\user\Desktop\BPMLNOBVSB\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\user\Desktop\BPMLNOBVSB.jpg
data
#
C:\Users\user\Contacts\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\user\3D Objects\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\Public\Videos\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\Public\Pictures\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\Public\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#
C:\Users\Public\Music\NEF1LIM-DECRYPT.txt
ASCII text, with CRLF line terminators
#