Download PDF Report
DYNAMIC ANALYSIS REPORT #6812059 Classifications: Spyware Keylogger MALICIOUS Threat Names: Phoenix Verdict Reason: - Sample Type Windows Exe (x86-32) File Name 53695f461f19fcb5440ac85f777de093824ca61c777ff1c8b77001bf7eff4a76.exe ID #2586838 MD5 23c6a9b7cacf900035cfac74aeae1c7f SHA1 b81b431eaafe067c8025609fa2240308c49266eb SHA256 53695f461f19fcb5440ac85f777de093824ca61c777ff1c8b77001bf7eff4a76 File Size 787.50 KB Report Created 2021-08-06 18:25 (UTC+2) Target Environment win10_64_th2_en_mso2016 | exe X-Ray Vision for Malware - www.vmray.com 1 / 25 DYNAMIC ANALYSIS REPORT #6812059 OVERVIEW VMRay Threat Identifiers (21 rules, 47 matches) Score Category Operation Count Classification 5/5 YARA Malicious content matched by YARA rules 1 Keylogger, Spyware • Rule "PhoenixKeylogger" from ruleset "Malware" has matched on the function strings for (process #5) 53695f461f19fcb5440ac85f777de093824ca61c777ff1c8b77001bf7eff4a76.exe. 5/5 Data Collection Tries to read cached credentials of various applications 1 Spyware • Tries to read sensitive data of: FileZilla, Vivaldi, Opera, Pidgin, Chromium, Comodo Dragon, Torch, Kometa, Chrome Canary, 7Star, ... ...er, Orbitum, Epic Privacy Browser, Yandex Browser, Maple Studio, Uran, CentBrowser, Amigo, CocCoc, Chedot, Google Chrome, Sputnik. 2/5 Data Collection Reads sensitive mail data 1 - • (Process #5) 53695f461f19fcb5440ac85f777de093824ca61c777ff1c8b77001bf7eff4a76.exe tries to read sensitive data of mail application "Microsoft Outlook" by registry. 2/5 Data Collection Reads sensitive browser data 20 - •
[Show full text]