top title background image
flash

7rcpejVLGa.exe

Status: finished
Submission Time: 2020-09-11 10:26:52 +02:00
Malicious
Ransomware
Adware
Evader
Crysis Wadhrama

Comments

Tags

  • Crysis
  • Dharma
  • Ransomware

Details

  • Analysis ID:
    284375
  • API (Web) ID:
    463949
  • Analysis Started:
    2020-09-11 10:26:53 +02:00
  • Analysis Finished:
    2020-09-11 10:38:57 +02:00
  • MD5:
    95f91f236cf95d698d9195690133265b
  • SHA1:
    29f3c5cc44709847c416bc35b3043d3da1392a8c
  • SHA256:
    085105e613ad37808a8db9a3c2ba5561d5d38d5c5c43b469c93d15f0d64af0c1
  • Technologies:

Joe Sandbox

Engine Download Report Detection Info
malicious
malicious
Score: 100
System: Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01

Third Party Analysis Engines

malicious
Score: 56/65
malicious
Score: 47/48
malicious

Dropped files

Name File Type Hashes Detection
C:\$Recycle.Bin\S-1-5-21-3853321935-2125563209-4053062332-1000\desktop.ini.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\IRMProtectors\Microsoft.Office.Irm.MsoProtector.dll.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\IRMProtectors\Microsoft.Office.Irm.OfcProtector.dll.id-9807782D.[zphc@cock.li].zphs
data
#
Click to see the 97 hidden entries
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\IRMProtectors\microsoft.office.irm.pdfprotector.dll.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\FileSyncViews.dll.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\FileSyncShell.dll.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\imagestore\dikxvqf\imagestore.dat.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\LogUploader.dll.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\LoggingPlatform.dll.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\FileSyncFALWB.dll.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\FileSyncFAL.dll.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\FileSyncConfig.exe.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\FileSyncApi.dll.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\FileSync.LocalizedResources.dll.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\FileCoAuth.exe.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\FileCoAuthLib.dll.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\AutoPlayOptIn.gif.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\UserCache.bin.id-9807782D.[zphc@cock.li].zphs
data
#
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\7rcpejVLGa.exe
PE32 executable (GUI) Intel 80386, for MS Windows
#
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\IconCacheRdr65536.dat.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\ETWlog.dll.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\AdobeSysFnt19.lst.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\CollectSyncLogs.bat.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\LogoImages\OneDriveSmallTile.contrast-black_scale-125.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\ElevatedAppBlue.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\FileSyncSessions.dll.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\ElevatedAppWhite.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\FileSyncHelper.exe.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\Error.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\FileSyncClient.dll.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\ErrorPage.html.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\FileSync.Resources.dll.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\LogoImages\OneDriveMedTile.contrast-white_scale-125.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\$Recycle.Bin\S-1-5-18\desktop.ini.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\LogoImages\OneDriveSmallTile.contrast-black_scale-100.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\LogoImages\OneDriveMedTile.scale-400.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\LogoImages\OneDriveMedTile.scale-200.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\LogoImages\OneDriveMedTile.scale-150.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\LogoImages\OneDriveMedTile.scale-125.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\LogoImages\OneDriveMedTile.scale-100.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\LogoImages\OneDriveMedTile.contrast-white_scale-400.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\LogoImages\OneDriveMedTile.contrast-white_scale-200.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\LogoImages\OneDriveMedTile.contrast-white_scale-150.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\FloodgateClientLibraryDllWin32Client.dll.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\LogoImages\OneDriveMedTile.contrast-white_scale-100.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\LogoImages\OneDriveMedTile.contrast-black_scale-400.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\LogoImages\OneDriveMedTile.contrast-black_scale-200.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\LogoImages\OneDriveMedTile.contrast-black_scale-150.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\LogoImages\OneDriveMedTile.contrast-black_scale-125.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\LogoImages\OneDriveMedTile.contrast-black_scale-100.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\LoadingPage.html.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\KFMScanExclusionToast.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\KFMLockedFileToast.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\KFMHeroToast.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Comms\UnistoreDB\USStmp.jtx.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\Credentials\DFBE70A7E5CC19A398EBF1B96859CE5D.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\powershell.exe.log.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\NGenTask.exe.log.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\sdiagnhost.exe.log.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\powershell.exe.log.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\CLR_v2.0_32\UsageLogs\unarchiver.exe.log.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\CLR_v2.0\UsageLogs\addinutil.exe.log.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\IconCache.db.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\ConnectedDevicesPlatform\CDPGlobalSettings.cdp.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Comms\Unistore\data\AggregateCache.uca.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\IECompatData\iecompatdata.xml.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Comms\UnistoreDB\USSres00002.jrs.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Comms\UnistoreDB\USSres00001.jrs.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Comms\UnistoreDB\USS.jcp.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Adobe\Color\ACECache11.lst.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\Cache\AcroFnt19.lst.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\AdobeCMapFnt19.lst.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\3D Objects\desktop.ini.id-9807782D.[zphc@cock.li].zphs
data
#
C:\$Recycle.Bin\S-1-5-21-3853321935-2125563209-4053062332-1002\desktop.ini.id-9807782D.[zphc@cock.li].zphs
data
#
C:\$Recycle.Bin\S-1-5-21-3853321935-2125563209-4053062332-1001\desktop.ini.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00007464\05_Pictures_taken_in_the_last_month.wpl.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\AppWhite.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\AppErrorWhite.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\AppErrorBlue.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\AppBlue.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00007464\12_All_Video.wpl.id-9807782D.[zphc@cock.li].zphs
SysEx File - JEN
#
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00007464\11_All_Pictures.wpl.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00007464\10_All_Music.wpl.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00007464\09_Music_played_the_most.wpl.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00007464\08_Video_rated_at_4_or_5_stars.wpl.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00007464\07_TV_recorded_in_the_last_week.wpl.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00007464\06_Pictures_rated_4_or_5_stars.wpl.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\OneDrive\19.086.0502.0006\AutoPlayOptIn.png.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00007464\04_Music_played_in_the_last_month.wpl.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00007464\03_Music_rated_at_4_or_5_stars.wpl.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00007464\02_Music_added_in_the_last_month.wpl.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00007464\01_Music_auto_rated_at_5_stars.wpl.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\ie4uinit-UserConfig.log.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\ie4uinit-ClearIconCache.log.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\brndlog.txt.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Tiles\pin-314712940\msapplication.xml.id-9807782D.[zphc@cock.li].zphs
data
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\Last Active\{7B1657B8-990A-11E9-90DB-ECF4BB570DC9}.dat.id-9807782D.[zphc@cock.li].zphs
Dzip archive data, version 195.208
#
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\Recovery\Last Active\RecoveryStore.{71FBE94F-990A-11E9-90DB-ECF4BB570DC9}.dat.id-9807782D.[zphc@cock.li].zphs
data
#