| download: | zkNH48 |
| Full analysis: | https://app.any.run/tasks/59f7f5aa-5ac5-4a8c-b4ce-042aebfeb09b |
| Verdict: | Malicious activity |
| Threats: | GandCrab is probably one of the most famous Ransomware. A Ransomware is a malware that asks the victim to pay money in order to restore access to encrypted files. If the user does not cooperate the files are forever lost. |
| Analysis date: | January 18, 2019, 09:55:26 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 24F030B17DD8152A3CD04253DD648690 |
| SHA1: | 456FB8F627C1E28745C9F63FAF2615E1A0CC1D66 |
| SHA256: | 57ACEA19D6B84C350A6C9CF2B55794377C7D12491B65AF1D06C7F857316F1D7B |
| SSDEEP: | 12288:QasyKZffHK7s1cLOhTpOfekiImLZGMn55aYEO:AH+LOF8ek6fn5I7 |
| .exe | | | Win32 Executable MS Visual C++ (generic) (41) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (36.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.6) |
| .exe | | | Win32 Executable (generic) (5.9) |
| .exe | | | Clipper DOS Executable (2.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:01:17 16:14:17+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 10 |
| CodeSize: | 189952 |
| InitializedDataSize: | 290304 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x16d5a |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 6.9.7.6 |
| ProductVersionNumber: | 6.9.7.6 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| FileDescription: | Vbprj Feed Folderbrowserdialog Livermre |
| LegalCopyright: | Copyright © 1995-Present Domo Technologies |
| InternalName: | Protection |
| OriginalFileName: | Protection.exe |
| CompanyName: | Domo Technologies |
| Comments: | Vbprj Feed Folderbrowserdialog Livermre |
| ProductName: | Protection |
| ProductVersion: | 6.9.7.6 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 17-Jan-2019 15:14:17 |
| Detected languages: |
|
| Debug artifacts: |
|
| FileDescription: | Vbprj Feed Folderbrowserdialog Livermre |
| LegalCopyright: | Copyright © 1995-Present Domo Technologies |
| InternalName: | Protection |
| OriginalFilename: | Protection.exe |
| CompanyName: | Domo Technologies |
| Comments: | Vbprj Feed Folderbrowserdialog Livermre |
| ProductName: | Protection |
| ProductVersion: | 6.9.7.6 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000F0 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 17-Jan-2019 15:14:17 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x0002E536 | 0x0002E600 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.73045 |
.rdata | 0x00030000 | 0x0000BAB6 | 0x0000BC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.8855 |
.data | 0x0003C000 | 0x00004A64 | 0x00002C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.91848 |
.rsrc | 0x00041000 | 0x000348AC | 0x00034A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.32468 |
.reloc | 0x00076000 | 0x00003B94 | 0x00003C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.09054 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.11681 | 530 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 4.18613 | 1128 | Latin 1 / Western European | English - United States | RT_ICON |
3 | 3.37186 | 9640 | Latin 1 / Western European | English - United States | RT_ICON |
4 | 3.74274 | 4264 | Latin 1 / Western European | English - United States | RT_ICON |
5 | 1.74461 | 10344 | Latin 1 / Western European | English - United States | RT_ICON |
6 | 3.22704 | 16936 | Latin 1 / Western European | English - United States | RT_ICON |
101 | 2.76051 | 90 | Latin 1 / Western European | English - United States | RT_GROUP_ICON |
179 | 7.9558 | 7951 | Latin 1 / Western European | English - United States | PNG |
285 | 7.94932 | 11390 | Latin 1 / Western European | English - United States | TYPELIB |
1229 | 6.50383 | 128 | Latin 1 / Western European | English - United States | RT_RCDATA |
ADVAPI32.dll |
COMCTL32.dll |
COMDLG32.dll |
DWrite.dll |
GDI32.dll |
GLU32.dll |
IMM32.dll |
KERNEL32.dll |
MSIMG32.dll |
MSVFW32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 184 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\KMZVGVFMF-DECRYPT.txt | C:\Windows\system32\NOTEPAD.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2332 | "C:\Windows\system32\wbem\wmic.exe" shadowcopy delete | C:\Windows\system32\wbem\wmic.exe | zkNH48.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: WMI Commandline Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2876 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3108 | "C:\Users\admin\AppData\Local\Temp\zkNH48.exe" | C:\Users\admin\AppData\Local\Temp\zkNH48.exe | explorer.exe | ||||||||||||
User: admin Company: Domo Technologies Integrity Level: MEDIUM Description: Vbprj Feed Folderbrowserdialog Livermre Exit code: 0 Modules
| |||||||||||||||
| 3280 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Desktop\storiesos.rtf.kmzvgvfmf | C:\Windows\system32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3600 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\storiesos.rtf.kmzvgvfmf | C:\Windows\system32\NOTEPAD.EXE | — | rundll32.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3108) zkNH48.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\ex_data\data |
| Operation: | write | Name: | ext |
Value: 2E006B006D007A0076006700760066006D0066000000 | |||
| (PID) Process: | (3108) zkNH48.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\keys_data\data |
| Operation: | write | Name: | public |
Value: 0602000000A40000525341310008000001000100A54031C9C2479963F2B85B86002D75E69761208CFB0B10F17C31AF60E1604C50CA71855777D04E4F34158F062F9C230E0D36EF2DB51EBA383BA3158595F671D1CA03548E56B32EFB49334916A5EAF5EE289FC5FB0EE16F656BD24622362521A5B1C6F82B1A7533C75A1556FD5A0B842DBCCF16D26C2A971267A82DAEB560D7BA6D61C7B6524CBB28A498D47C940152CB885396EB391586F83B70092CDB7227DFD3BD97E85EC3C070B569C0D58CD4C6A81DFB4B9E053C27F2EC772009320E5473F19E9D5CFF93B3DB3779DDD8B147211E5455B12D35AFB879662DBBC6865B81A8C13955CF42E50FDBD2684A92A05E3034E57086E0153E54B14BBAE2A8A392F1B3 | |||
| (PID) Process: | (3108) zkNH48.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\keys_data\data |
| Operation: | write | Name: | private |
Value: 94040000EDDB8E30B3D2DFA333E3E9AC0346E37CDD172D1E95442ED44054F680038357C08EFE2F8A0306039649FACC47ED325DBFA0A51D66D162C995F9E898B405DF8E1D7FEEE60ACEF1FD4C40F7778D91F812596DAF6171826C0BE5F29218DA35A0A6EBA39719E5F7339FB443BFBD559C8353E27D30F3DE7CF7652423FC04F0C962E890CD1342C5805C29BF80E63EC2C95AF691EA61DAFE2B9CD26325C3B7E31A8B11FCFC64FB319AF6A94DB391804D471E43C90B397E38DC10E200E4806D86465CA5CB0FAEDE49B98EF1F30DF56FCFFC9B8761D197AF435B495D7B49083461C0230433E538D49A18D66617FBEB762B5660DEF9605AEC0694FB409980E46019EF8538946802BEFF28760A520EB93D488E65C2451EEC1FF6BA5B86DFE8EEF829918C58D8877F6B43BAE3A8F7843B87E93D633980E62DC0229F2F02FBC193C95E3182339F3B34C794D586A3ED57796639765FEEAE1D76A5F20AFFDBDFD1673EB92F996AFCE2B00EA0A1F911DCACAFD952DF76555F22C914E67376C77C70B081FB8C6682BFECFF897EBA5A8CD91F238D7C2800E352AED12E72D4E389462F0D957E5119D218AAEC663C5CF4865231B97A8A13D7DF244064C56E10A46AC00C52B53B9E7F61451DECE93246220A2BB724C58DD131DAFB32F3C7D69490BD8F3789A4F6B7A654565C99D1114A0EE4631DC2BFF15F530633646156D66A583D6A050B19024E3266010B55F6C0771560DBCDE219E336D7BF8E7FB26E6784AE767B86612A26FA7A527F1958CC4145403F7065A7F35BDE2392932AF9FABD99251B6AA797872D2A1BC730AC071A54674BF5BB5A3C4FCD8DD2CA832E85A94CA03E64148538E34E55A0796491004981C97F697DE6B8968937ECC0143158BAD5E6050F427C75CEEFF8570893DB44B9A593FA20C629782F1F6707763CB6A5EE3642FC8148011632D25847FC4373D24D0B526C9E7CF6AAF43A1D21655A8624AA6292AF6C61FA486C7290F5BDBE53E1E3D6B73E0EEEBDD8D53341D073577104FDC46CF5A7022692F6E4400C952A4868845993522DAE94AC1CA8C35FE63042BF1C8717B5F8309FDF5359B1D64BEC26CE8DDFC2BB6C1410E9017433FB0DD50620F924606766C0351DF372443C6EC18C8473F993D86903ED4C1DA6602F358CB785EECEA7C0D6BE871C0193F453B630A6C1543131DC8F034F0B0CB2846CA25693FBB96532B22CA33CAE10720095C9AA741A89C2653BD377EA62575B2A92881211030349157D84C59DF3135B020EB79681261537593B593C054E6E45AB83BA33E2BAA0BC4C581173DD3A66CC01905E80F20410103A55561720ECA138FD07906C21B5C5D791A1335598A354511B1D34BFE065054282A81779306465CB54D59ED6A8F5873093849B62A54CA4F3F4A923D08218AA818001F545C1D9CF03780F3428E7CFE82FD29DED19975AC0E4962164FD239F33EAF30068ED8B0C1E8979FFF9B3AA3B43F0259D1E95E90E224A031BC756EBC301BFD804B49638B6982B42084D2076A5D21BAF9B24FC07049792C343ADA7F2D7DFA086128CD8FF6B08ACC6E327363051BC6E6245EEE0EE4B762EE0C0794496DF219C45C3C4A31AC85CF6770159F48FED55BF2557B6C24BA2EA12A9833C1D993893198D2DE0A559C313A551D98A7C3AD7168BD53AEE3DF8F294B3BAFFDB5F6A4623FE34899D5A9C1A5314834F5EFD6AFD692F4B34FF48EF0EC5FC5B5586CF2F687EA27EE4467F2E84B6C9FB014907773EA71997B91F2E97E6F10BFBC5D601E2475DDFD1A9B2EF66E30405C299A8EDC2CA4F947A777383B7E1E5D78EB4FB1E5A740E638A6D42B893D49CDF6843CDD7F0D4D1166B2BFA43616C1EB71A84F3F224E05B2BA8C0451ECF4AC1B62F15E6207F4D680A2C50B6A7015F9261E11C02DD56B78931A8792B1A5A9C8A7135AAB6CACEDB7A2D5D7221FA2B241A50F10043A943B8CF349A13069A327BA6B70FA72F38C8AE087C500EF759AB7F312F201CE5B449784671A81710CBB8CC05A6C6B34D89B9F7C7F0C2F73285A34FA91B9756AE6FC9A00AAFB549E3020A0F27B6AA1FC808A33D6BED66B9F0CE7199D41F4B5E3BCC1876B3E1CEB1DB6244577F00E2126A8567A6E003DE18928151B48F8B0DB8CC92DBCB6F3BEA96BB2394DE4972B69A0E524A53688446690001AC2AECD0545C8C4B35F9E07F0D937548FA96429E7668B2B765BD26D0470C995D71031B761B25E3048D83046E287F4F4322086F274F467B54CD02FC19EAE1D195FA79660605A50A1C45B83274485BEFC3AE252CED91C671D8B61F607D0A6B8F4A798314ED95EDC64C692D2FEF0BB2117E81D5945B2D5621DBE96E05EDFEFCD4948D990C7CB324CA7E143E446C6A66C7D7A7A03A64D1D493530F744C8A | |||
| (PID) Process: | (3108) zkNH48.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3108) zkNH48.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (3108) zkNH48.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\zkNH48_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (3108) zkNH48.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\zkNH48_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (3108) zkNH48.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\zkNH48_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (3108) zkNH48.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\zkNH48_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (3108) zkNH48.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\zkNH48_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3108 | zkNH48.exe | C:\Recovery\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\boot.sdi | — | |
MD5:— | SHA256:— | |||
| 3108 | zkNH48.exe | C:\Recovery\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\Winre.wim.kmzvgvfmf | — | |
MD5:— | SHA256:— | |||
| 3108 | zkNH48.exe | C:\Recovery\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\Winre.wim | — | |
MD5:— | SHA256:— | |||
| 3108 | zkNH48.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{05ed3515-06b3-48f6-8cf2-bf24b1bf0727}_OnDiskSnapshotProp | — | |
MD5:— | SHA256:— | |||
| 3108 | zkNH48.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{16d74681-6bc3-4c44-97f0-8b8dfefe2355}_OnDiskSnapshotProp | — | |
MD5:— | SHA256:— | |||
| 3108 | zkNH48.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{38e8535f-27d0-4352-aa3a-ce4178930102}_OnDiskSnapshotProp | — | |
MD5:— | SHA256:— | |||
| 3108 | zkNH48.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{3cc0f82b-873a-4e59-b89f-689fbdf88af9}_OnDiskSnapshotProp | — | |
MD5:— | SHA256:— | |||
| 3108 | zkNH48.exe | C:\Recovery\KMZVGVFMF-DECRYPT.txt | text | |
MD5:— | SHA256:— | |||
| 3108 | zkNH48.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{5c4beaff-a038-4df7-9b35-072a18f8e3d6}_OnDiskSnapshotProp | — | |
MD5:— | SHA256:— | |||
| 3108 | zkNH48.exe | C:\$Recycle.Bin\S-1-5-21-1302019708-1500728564-335382590-500\KMZVGVFMF-DECRYPT.txt | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3108 | zkNH48.exe | GET | 301 | 138.201.162.99:80 | http://www.kakaocorp.link/ | DE | html | 162 b | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3108 | zkNH48.exe | 138.201.162.99:80 | www.kakaocorp.link | Hetzner Online GmbH | DE | malicious |
3108 | zkNH48.exe | 138.201.162.99:443 | www.kakaocorp.link | Hetzner Online GmbH | DE | malicious |
Domain | IP | Reputation |
|---|---|---|
www.kakaocorp.link |
| malicious |