The document is a malware analysis report that details malicious activity detected on a system. It found that a 3.4MB executable file behaved like known malware and displayed ransomware-like behavior, encrypting over 30 files on the system and leaving encryption extensions. The malware made modifications to the registry and spawned multiple suspicious processes during its emulated execution.
4. Malware Report
Table of Contents 4
4/16
Malware Residues 5-9
Unexpected Activities By Time 10-16
5. Malware Report
Malware Residues ( 1 out of 5 ) 5
5/16
Suspicious Activities
Behaves like a known malware ( Generic.MALWARE.1b25 )
Malware activity observed ( Trojan-Ransom.Win32.Wanna.b )
Malware detected ( Gen:Variant.Graftor.369176 )
Malware signature matched ( Trojan-ransom.Win32.Wcry.U.lzpjh )
Processes Spawned or Interacted with
C:WINDOWSsystem32attrib.exe (Terminated ,Started)
C:WINDOWSsystem32cmd.exe (Started)
C:WINDOWSsystem32cscript.exe (Started)
C:te_filestaskdl.exe (Terminated ,Started)
Files Changed
C:$LogFile (Modified)
C:Documents and SettingsadminDesktop@Please_Read_Me@.txt (Created ,Modified)
C:Documents and SettingsadminDesktop@WanaDecryptor@.exe (Created ,Modified)
C:Documents and SettingsadminDesktopa glimpse into the future.bmp (Modified)
C:Documents and SettingsadminDesktopa glimpse into the future.bmp.WNCRYT (Created ,Modified)
6. Malware Report
Malware Residues ( 2 out of 5 ) 6
6/16
Files Changed
C:Documents and SettingsadminDesktopconfidential.docx (Modified)
C:Documents and SettingsadminDesktopconfidential.docx.WNCRYT (Created ,Modified)
C:Documents and SettingsadminDesktopimportant DOCs@Please_Read_Me@.txt (Created ,Modified)
C:Documents and SettingsadminDesktopimportant DOCsClassifed.zip (Modified)
C:Documents and SettingsadminDesktopimportant DOCsClassifed.zip.WNCRYT (Created ,Modified)
C:Documents and SettingsadminDesktopimportant DOCsClassifed@Please_Read_Me@.txt (Created ,Modified)
C:Documents and SettingsadminDesktopimportant DOCsClassifeda glimpse.bmp (Modified)
C:Documents and SettingsadminDesktopimportant DOCsClassifeda glimpse.bmp.WNCRYT (Created ,Modified)
C:Documents and SettingsadminDesktopimportant DOCsClassifedconfidential.docx (Modified)
C:Documents and SettingsadminDesktopimportant DOCsClassifedconfidential.docx.WNCRYT (Created ,Modified)
C:Documents and SettingsadminDesktopimportant DOCsClassifedroadmap_2021.pptx (Modified)
7. Malware Report
Malware Residues ( 3 out of 5 ) 7
7/16
Files Changed
C:Documents and SettingsadminDesktopimportant DOCsClassifed~SD3.tmp (Created ,Deleted)
C:Documents and SettingsadminDesktopimportant DOCsa glimpse into the future.bmp (Modified)
C:Documents and SettingsadminDesktopimportant DOCsa glimpse into the future.bmp.WNCRYT (Created ,Modified)
C:Documents and SettingsadminDesktopimportant DOCsconfidential.docx (Modified)
C:Documents and SettingsadminDesktopimportant DOCsconfidential.docx.WNCRYT (Created ,Modified)
C:Documents and SettingsadminDesktopimportant DOCsroadmap_2021.pptx (Modified)
C:Documents and SettingsadminDesktopimportant DOCsroadmap_2021.pptx.WNCRYT (Created ,Modified)
C:Documents and SettingsadminDesktopimportant DOCs~SD2.tmp (Created ,Deleted)
C:Documents and SettingsadminDesktop~SD1.tmp (Created ,Deleted)
10. Malware Report
Unexpected Activities By Time ( 1 out of 7 ) 10
10/16
Elapsed Time Type Action
00:00:04 Registry Create C:te_filesemulatedFile58511_1.exe Created HKLMSOFTWAREWanaCrypt0r
00:00:04 Registry Set C:te_filesemulatedFile58511_1.exe Set HKLMSOFTWAREWanaCrypt0rwd
00:00:05 File Create C:te_filesemulatedFile58511_1.exe Created C:te_filestaskdl.exe
00:00:05 File Create C:te_filesemulatedFile58511_1.exe Created C:te_filestaskse.exe
00:00:05 Process Creation C:te_filesemulatedFile58511_1.exe Created C:WINDOWSsystem32attrib.exe
00:00:09 Registry Set C:WINDOWSsystem32attrib.exe Set HKLMSOFTWAREMicrosoftCryptographyRNGSeed
00:00:09 Registry Create C:WINDOWSsystem32attrib.exe Created HKCUSoftwareMicrosoftMultimediaAudio
00:00:13 Registry Create C:WINDOWSsystem32attrib.exe Created HKCUSoftwareMicrosoftMultimediaAudio Compression Manager
00:00:13 Registry Create C:WINDOWSsystem32attrib.exe Created HKCUSoftwareMicrosoftMultimediaAudio Compression ManagerMSACM
00:00:13 Registry Create C:WINDOWSsystem32attrib.exe Created HKCUSoftwareMicrosoftMultimediaAudio Compression ManagerPriority v4.00
00:00:17 Process Termination C:te_filesemulatedFile58511_1.exe Terminated C:WINDOWSsystem32attrib.exe
00:00:17 Registry Set C:te_filesemulatedFile58511_1.exe Set HKLMSOFTWAREMicrosoftCryptographyRNGSeed
00:00:19 Process Creation C:te_filesemulatedFile58511_1.exe Created C:te_filestaskdl.exe
00:00:20 Process Termination C:te_filesemulatedFile58511_1.exe Terminated C:te_filestaskdl.exe
00:00:21 Process Creation C:te_filesemulatedFile58511_1.exe Created C:WINDOWSsystem32cmd.exe
00:00:21 File Create C:te_filesemulatedFile58511_1.exe Created C:te_files@WanaDecryptor@.exe
00:00:21 File Create C:te_filesemulatedFile58511_1.exe Created C:te_files219161325495940.bat
11. Malware Report
Unexpected Activities By Time ( 2 out of 7 ) 11
11/16
Elapsed Time Type Action
00:00:22 File Create C:te_filesemulatedFile58511_1.exe Created C:Documents and SettingsadminDesktop~SD1.tmp
00:00:22 File Delete C:te_filesemulatedFile58511_1.exe Deleted C:Documents and SettingsadminDesktop~SD1.tmp
00:00:22 File Create C:te_filesemulatedFile58511_1.exe Created C:Documents and SettingsadminDesktopconfidential.docx.WNCRYT
00:00:22 File Write C:te_filesemulatedFile58511_1.exe Wrote To C:Documents and SettingsadminDesktopconfidential.docx.WNCRYT
00:00:23 File Write C:te_filesemulatedFile58511_1.exe Wrote To C:Documents and SettingsadminDesktopconfidential.docx
00:00:23 File Write C:te_filesemulatedFile58511_1.exe Wrote To C:$LogFile
00:00:23 File Create C:te_filesemulatedFile58511_1.exe Created C:Documents and SettingsadminDesktop@Please_Read_Me@.txt
00:00:23 File Write C:te_filesemulatedFile58511_1.exe Wrote To C:Documents and SettingsadminDesktop@Please_Read_Me@.txt
00:00:23 File Create C:te_filesemulatedFile58511_1.exe Created C:Documents and SettingsadminDesktop@WanaDecryptor@.exe
00:00:23 File Write C:te_filesemulatedFile58511_1.exe Wrote To C:Documents and SettingsadminDesktop@WanaDecryptor@.exe
00:00:23 File Create C:te_filesemulatedFile58511_1.exe Created C:Documents and SettingsadminDesktopimportant DOCs~SD2.tmp
00:00:23 File Delete C:te_filesemulatedFile58511_1.exe Deleted C:Documents and SettingsadminDesktopimportant DOCs~SD2.tmp
12. Malware Report
Unexpected Activities By Time ( 3 out of 7 ) 12
12/16
Elapsed Time Type Action
00:00:24 File Create C:te_filesemulatedFile58511_1.exe Created C:Documents and SettingsadminDesktopimportant DOCsconfidential.docx.WNCRYT
00:00:24 File Write C:te_filesemulatedFile58511_1.exe Wrote To C:Documents and SettingsadminDesktopimportant DOCsconfidential.docx.WNCRYT
00:00:25 File Write C:te_filesemulatedFile58511_1.exe Wrote To C:Documents and SettingsadminDesktopimportant DOCsconfidential.docx
00:00:25 File Create C:te_filesemulatedFile58511_1.exe Created C:Documents and SettingsadminDesktopimportant DOCsroadmap_2021.pptx.WNCRYT
00:00:25 File Write C:te_filesemulatedFile58511_1.exe Wrote To C:Documents and SettingsadminDesktopimportant DOCsroadmap_2021.pptx.WNCRYT
00:00:25 Process Creation C:WINDOWSsystem32cmd.exe Created C:WINDOWSsystem32cscript.exe
00:00:25 File Write C:te_filesemulatedFile58511_1.exe Wrote To C:Documents and SettingsadminDesktopimportant DOCsroadmap_2021.pptx
00:00:25 File Create C:te_filesemulatedFile58511_1.exe Created C:Documents and SettingsadminDesktopimportant DOCs@Please_Read_Me@.txt
00:00:25 File Write C:te_filesemulatedFile58511_1.exe Wrote To C:Documents and SettingsadminDesktopimportant DOCs@Please_Read_Me@.txt
00:00:25 File Create C:te_filesemulatedFile58511_1.exe Created C:Documents and SettingsadminDesktopimportant DOCsClassifed~SD3.tmp
13. Malware Report
Unexpected Activities By Time ( 4 out of 7 ) 13
13/16
Elapsed Time Type Action
00:00:25 File Delete C:te_filesemulatedFile58511_1.exe Deleted C:Documents and SettingsadminDesktopimportant DOCsClassifed~SD3.tmp
00:00:25 File Create
C:te_filesemulatedFile58511_1.exe Created C:Documents and SettingsadminDesktopimportant
DOCsClassifedconfidential.docx.WNCRYT
00:00:25 File Write
C:te_filesemulatedFile58511_1.exe Wrote To C:Documents and SettingsadminDesktopimportant
DOCsClassifedconfidential.docx.WNCRYT
00:00:25 File Write C:te_filesemulatedFile58511_1.exe Wrote To C:Documents and SettingsadminDesktopimportant DOCsClassifedconfidential.docx
00:00:25 Registry Set C:WINDOWSsystem32cscript.exe Set HKLMSOFTWAREMicrosoftCryptographyRNGSeed
00:00:26 Registry Create C:WINDOWSsystem32cscript.exe Created HKCUSoftwareMicrosoftMultimediaAudio
00:00:28 Registry Create C:WINDOWSsystem32cscript.exe Created HKCUSoftwareMicrosoftMultimediaAudio Compression Manager
00:00:29 Registry Create C:WINDOWSsystem32cscript.exe Created HKCUSoftwareMicrosoftMultimediaAudio Compression ManagerMSACM
00:00:29 Registry Create C:WINDOWSsystem32cscript.exe Created HKCUSoftwareMicrosoftMultimediaAudio Compression ManagerPriority v4.00
00:00:29 File Create
C:te_filesemulatedFile58511_1.exe Created C:Documents and SettingsadminDesktopimportant
DOCsClassifedroadmap_2021.pptx.WNCRYT
00:00:29 File Write
C:te_filesemulatedFile58511_1.exe Wrote To C:Documents and SettingsadminDesktopimportant
DOCsClassifedroadmap_2021.pptx.WNCRYT
14. Malware Report
Unexpected Activities By Time ( 5 out of 7 ) 14
14/16
Elapsed Time Type Action
00:00:31 Registry Create C:WINDOWSsystem32cscript.exe Created HKLMSOFTWAREMicrosoftWindows Script HostSettings
00:00:31 Registry Create C:WINDOWSsystem32cscript.exe Created HKCUSoftwareMicrosoftWindows Script HostSettings
00:00:31 File Write C:te_filesemulatedFile58511_1.exe Wrote To C:Documents and SettingsadminDesktopimportant DOCsClassifedroadmap_2021.pptx
00:00:32 File Create
C:te_filesemulatedFile58511_1.exe Created C:Documents and SettingsadminDesktopimportant
DOCsClassifed@Please_Read_Me@.txt
00:00:32 File Write
C:te_filesemulatedFile58511_1.exe Wrote To C:Documents and SettingsadminDesktopimportant
DOCsClassifed@Please_Read_Me@.txt
00:00:33 File Create C:te_filesemulatedFile58511_1.exe Created C:Documents and SettingsadminDesktopimportant DOCsClassifed.zip.WNCRYT
00:00:33 File Write C:te_filesemulatedFile58511_1.exe Wrote To C:Documents and SettingsadminDesktopimportant DOCsClassifed.zip.WNCRYT
00:00:34 File Write C:te_filesemulatedFile58511_1.exe Wrote To C:Documents and SettingsadminDesktopimportant DOCsClassifed.zip
00:00:34 File Create C:te_filesemulatedFile58511_1.exe Created C:Documents and SettingsadminDesktopa glimpse into the future.bmp.WNCRYT
00:00:34 File Write C:te_filesemulatedFile58511_1.exe Wrote To C:Documents and SettingsadminDesktopa glimpse into the future.bmp.WNCRYT
15. Malware Report
Unexpected Activities By Time ( 6 out of 7 ) 15
15/16
Elapsed Time Type Action
00:00:36 File Write C:te_filesemulatedFile58511_1.exe Wrote To C:Documents and SettingsadminDesktopa glimpse into the future.bmp
00:00:36 File Create
C:te_filesemulatedFile58511_1.exe Created C:Documents and SettingsadminDesktopimportant DOCsa glimpse into the
future.bmp.WNCRYT
00:00:36 File Write
C:te_filesemulatedFile58511_1.exe Wrote To C:Documents and SettingsadminDesktopimportant DOCsa glimpse into the
future.bmp.WNCRYT
00:00:36 File Write C:te_filesemulatedFile58511_1.exe Wrote To C:Documents and SettingsadminDesktopimportant DOCsa glimpse into the future.bmp
00:00:36 File Create
C:te_filesemulatedFile58511_1.exe Created C:Documents and SettingsadminDesktopimportant DOCsClassifeda
glimpse.bmp.WNCRYT
00:00:36 File Write
C:te_filesemulatedFile58511_1.exe Wrote To C:Documents and SettingsadminDesktopimportant DOCsClassifeda
glimpse.bmp.WNCRYT
00:00:36 File Write C:te_filesemulatedFile58511_1.exe Wrote To C:Documents and SettingsadminDesktopimportant DOCsClassifeda glimpse.bmp
00:00:36 Registry Create C:te_filesemulatedFile58511_1.exe Created HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerUser Shell Folders
00:00:36 Registry Create C:te_filesemulatedFile58511_1.exe Created HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerShell Folders
00:00:37 Registry Set C:te_filesemulatedFile58511_1.exe Set HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerShell FoldersPersonal
00:00:37 File Create C:te_filesemulatedFile58511_1.exe Created C:Documents and SettingsadminMy Documents~SD4.tmp
00:00:37 File Delete C:te_filesemulatedFile58511_1.exe Deleted C:Documents and SettingsadminMy Documents~SD4.tmp
00:00:37 File Create C:te_filesemulatedFile58511_1.exe Created C:Documents and SettingsadminMy Documentsroadmap_2021.pptx.WNCRYT
00:00:37 File Write C:te_filesemulatedFile58511_1.exe Wrote To C:Documents and SettingsadminMy Documentsroadmap_2021.pptx.WNCRYT
16. Malware Report
Unexpected Activities By Time ( 7 out of 7 ) 16
16/16
Elapsed Time Type Action
00:00:37 Registry Create
C:WINDOWSsystem32cscript.exe Created HKCUSoftwareMicrosoftWindowsCurrentVersionWinTrustTrust ProvidersSoftware
Publishing
00:00:39 File Write C:te_filesemulatedFile58511_1.exe Wrote To C:Documents and SettingsadminMy Documentsroadmap_2021.pptx