| File name: | GandCrab.exe |
| Full analysis: | https://app.any.run/tasks/f0def37a-9c98-4584-9a75-917938f7cd96 |
| Verdict: | Malicious activity |
| Threats: | GandCrab is probably one of the most famous Ransomware. A Ransomware is a malware that asks the victim to pay money in order to restore access to encrypted files. If the user does not cooperate the files are forever lost. |
| Analysis date: | August 03, 2025, 02:29:16 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 9 sections |
| MD5: | E6B43B1028B6000009253344632E69C4 |
| SHA1: | E536B70E3FFE309F7AE59918DA471D7BF4CADD1C |
| SHA256: | BFB9DB791B8250FFA8EBC48295C5DBBCA757A5ED3BBB01DE12A871B5CD9AFD5A |
| SSDEEP: | 6144:nSRCSpUtLz+/enihebWBUOP3yIhLVMmi0CtG7go+Iq:SUOEnNnHbmP3yIE3tGXs |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:04:28 17:40:56+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 129536 |
| InitializedDataSize: | 82364928 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x2cfb |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2276 | "C:\Users\admin\AppData\Local\Temp\GandCrab.exe" | C:\Users\admin\AppData\Local\Temp\GandCrab.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 3412 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2276 | GandCrab.exe | C:\Users\admin\AppData\Local\VirtualStore\QXKHQ-MANUAL.txt | text | |
MD5:DA91750E79F011EF712401977307F9E2 | SHA256:4EA46FFB8A50974DE2FE86DA1AE909A415EC7345A7D19E9B7D964AB8856E412A | |||
| 2276 | GandCrab.exe | C:\Users\admin\AppData\Local\VirtualStore\Program Files\QXKHQ-MANUAL.txt | text | |
MD5:DA91750E79F011EF712401977307F9E2 | SHA256:4EA46FFB8A50974DE2FE86DA1AE909A415EC7345A7D19E9B7D964AB8856E412A | |||
| 2276 | GandCrab.exe | C:\Users\admin\QXKHQ-MANUAL.txt | text | |
MD5:DA91750E79F011EF712401977307F9E2 | SHA256:4EA46FFB8A50974DE2FE86DA1AE909A415EC7345A7D19E9B7D964AB8856E412A | |||
| 2276 | GandCrab.exe | C:\Users\admin\AppData\Roaming\Adobe\Acrobat\QXKHQ-MANUAL.txt | text | |
MD5:DA91750E79F011EF712401977307F9E2 | SHA256:4EA46FFB8A50974DE2FE86DA1AE909A415EC7345A7D19E9B7D964AB8856E412A | |||
| 2276 | GandCrab.exe | C:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestamp | binary | |
MD5:A1C4283D38E5EAC7C719E0F5D8291380 | SHA256:234E71B3FB6E0E977857753732D3D6C3D42608D36B62810F199F292451B6DDE0 | |||
| 2276 | GandCrab.exe | C:\Users\admin\AppData\QXKHQ-MANUAL.txt | text | |
MD5:DA91750E79F011EF712401977307F9E2 | SHA256:4EA46FFB8A50974DE2FE86DA1AE909A415EC7345A7D19E9B7D964AB8856E412A | |||
| 2276 | GandCrab.exe | C:\Users\admin\AppData\Roaming\QXKHQ-MANUAL.txt | text | |
MD5:DA91750E79F011EF712401977307F9E2 | SHA256:4EA46FFB8A50974DE2FE86DA1AE909A415EC7345A7D19E9B7D964AB8856E412A | |||
| 2276 | GandCrab.exe | C:\MSOCache\QXKHQ-MANUAL.txt | text | |
MD5:DA91750E79F011EF712401977307F9E2 | SHA256:4EA46FFB8A50974DE2FE86DA1AE909A415EC7345A7D19E9B7D964AB8856E412A | |||
| 2276 | GandCrab.exe | C:\Users\admin\.oracle_jre_usage\QXKHQ-MANUAL.txt | text | |
MD5:DA91750E79F011EF712401977307F9E2 | SHA256:4EA46FFB8A50974DE2FE86DA1AE909A415EC7345A7D19E9B7D964AB8856E412A | |||
| 2276 | GandCrab.exe | C:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\QXKHQ-MANUAL.txt | text | |
MD5:DA91750E79F011EF712401977307F9E2 | SHA256:4EA46FFB8A50974DE2FE86DA1AE909A415EC7345A7D19E9B7D964AB8856E412A | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |