File name:

GandCrab.exe

Full analysis: https://app.any.run/tasks/f0def37a-9c98-4584-9a75-917938f7cd96
Verdict: Malicious activity
Threats:

GandCrab is probably one of the most famous Ransomware. A Ransomware is a malware that asks the victim to pay money in order to restore access to encrypted files. If the user does not cooperate the files are forever lost.

Analysis date: August 03, 2025, 02:29:16
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
gandcrab
ransomware
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 9 sections
MD5:

E6B43B1028B6000009253344632E69C4

SHA1:

E536B70E3FFE309F7AE59918DA471D7BF4CADD1C

SHA256:

BFB9DB791B8250FFA8EBC48295C5DBBCA757A5ED3BBB01DE12A871B5CD9AFD5A

SSDEEP:

6144:nSRCSpUtLz+/enihebWBUOP3yIhLVMmi0CtG7go+Iq:SUOEnNnHbmP3yIE3tGXs

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • GANDCRAB mutex has been found

      • GandCrab.exe (PID: 2276)
    • Writes a file to the Word startup folder

      • GandCrab.exe (PID: 2276)
    • Renames files like ransomware

      • GandCrab.exe (PID: 2276)
  • SUSPICIOUS

    • There is functionality for taking screenshot (YARA)

      • GandCrab.exe (PID: 2276)
    • Reads browser cookies

      • GandCrab.exe (PID: 2276)
  • INFO

    • Checks supported languages

      • GandCrab.exe (PID: 2276)
    • Reads the computer name

      • GandCrab.exe (PID: 2276)
    • Reads Environment values

      • GandCrab.exe (PID: 2276)
    • Reads product name

      • GandCrab.exe (PID: 2276)
    • Reads CPU info

      • GandCrab.exe (PID: 2276)
    • Reads the machine GUID from the registry

      • GandCrab.exe (PID: 2276)
    • Manual execution by a user

      • explorer.exe (PID: 3412)
    • Creates files or folders in the user directory

      • GandCrab.exe (PID: 2276)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:04:28 17:40:56+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 129536
InitializedDataSize: 82364928
UninitializedDataSize: -
EntryPoint: 0x2cfb
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #GANDCRAB gandcrab.exe explorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2276"C:\Users\admin\AppData\Local\Temp\GandCrab.exe" C:\Users\admin\AppData\Local\Temp\GandCrab.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\gandcrab.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3412"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
22 849
Read events
22 849
Write events
0
Delete events
0

Modification events

No data
Executable files
12
Suspicious files
998
Text files
356
Unknown types
0

Dropped files

PID
Process
Filename
Type
2276GandCrab.exeC:\Users\admin\AppData\Local\VirtualStore\QXKHQ-MANUAL.txttext
MD5:DA91750E79F011EF712401977307F9E2
SHA256:4EA46FFB8A50974DE2FE86DA1AE909A415EC7345A7D19E9B7D964AB8856E412A
2276GandCrab.exeC:\Users\admin\AppData\Local\VirtualStore\Program Files\QXKHQ-MANUAL.txttext
MD5:DA91750E79F011EF712401977307F9E2
SHA256:4EA46FFB8A50974DE2FE86DA1AE909A415EC7345A7D19E9B7D964AB8856E412A
2276GandCrab.exeC:\Users\admin\QXKHQ-MANUAL.txttext
MD5:DA91750E79F011EF712401977307F9E2
SHA256:4EA46FFB8A50974DE2FE86DA1AE909A415EC7345A7D19E9B7D964AB8856E412A
2276GandCrab.exeC:\Users\admin\AppData\Roaming\Adobe\Acrobat\QXKHQ-MANUAL.txttext
MD5:DA91750E79F011EF712401977307F9E2
SHA256:4EA46FFB8A50974DE2FE86DA1AE909A415EC7345A7D19E9B7D964AB8856E412A
2276GandCrab.exeC:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestampbinary
MD5:A1C4283D38E5EAC7C719E0F5D8291380
SHA256:234E71B3FB6E0E977857753732D3D6C3D42608D36B62810F199F292451B6DDE0
2276GandCrab.exeC:\Users\admin\AppData\QXKHQ-MANUAL.txttext
MD5:DA91750E79F011EF712401977307F9E2
SHA256:4EA46FFB8A50974DE2FE86DA1AE909A415EC7345A7D19E9B7D964AB8856E412A
2276GandCrab.exeC:\Users\admin\AppData\Roaming\QXKHQ-MANUAL.txttext
MD5:DA91750E79F011EF712401977307F9E2
SHA256:4EA46FFB8A50974DE2FE86DA1AE909A415EC7345A7D19E9B7D964AB8856E412A
2276GandCrab.exeC:\MSOCache\QXKHQ-MANUAL.txttext
MD5:DA91750E79F011EF712401977307F9E2
SHA256:4EA46FFB8A50974DE2FE86DA1AE909A415EC7345A7D19E9B7D964AB8856E412A
2276GandCrab.exeC:\Users\admin\.oracle_jre_usage\QXKHQ-MANUAL.txttext
MD5:DA91750E79F011EF712401977307F9E2
SHA256:4EA46FFB8A50974DE2FE86DA1AE909A415EC7345A7D19E9B7D964AB8856E412A
2276GandCrab.exeC:\Users\admin\AppData\Roaming\Adobe\Acrobat\DC\JSCache\QXKHQ-MANUAL.txttext
MD5:DA91750E79F011EF712401977307F9E2
SHA256:4EA46FFB8A50974DE2FE86DA1AE909A415EC7345A7D19E9B7D964AB8856E412A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.206
whitelisted

Threats

No threats detected
No debug info