Threat Database Ransomware Filecoder.DAY Ransomware

Filecoder.DAY Ransomware

By CagedTech in Ransomware

Analysis Report

General information

Family Name: Filecoder.DAY Ransomware
Signature status: Self Signed

Known Samples

MD5: da700804ddaae7d545a44fad842c8cda
SHA1: 6aab7cbe87af7cc6da6ebd8cd461c1d39f50fbe5
SHA256: 5C9B7F488699EBAA44FF011309A4AB15206064BDFED25080EB1836E96A482745
File Size: 418.14 KB, 418144 bytes
MD5: fbc2c87a67a053443e74374058afde05
SHA1: 59e628d383c98f27ee011c53065be9d1b285a80a
SHA256: 6F5C1CAA9B2640C6A9FF5F8A5C367D051BF4222BCF1A1F11FE56B61C3C405A7C
File Size: 418.14 KB, 418144 bytes
MD5: a1c1cd47cc8ecb80ab41e4aea446e83b
SHA1: 619b97c28d20e6f0c93534c3e76c060b1e8cc795
SHA256: F91C21027AB9D67099F623D33397F2F70E0A8637ADCD16F8E88D26ED18DA9111
File Size: 417.13 KB, 417128 bytes
MD5: bec38497685387d05930e9f116682da2
SHA1: abb824d2a238e877427b7a1c9de2857f27cd9734
SHA256: 19E40662172B349D3280B785661535DB623C115488B2A954B06F222ECE658719
File Size: 417.13 KB, 417128 bytes
MD5: 31768443f5ce2ae59e71cb03dfbc6013
SHA1: ac7c60b3f09d8dff042e5976fbfb8fa5e648ce22
SHA256: 36AAE7B99E30AF3E81F1B64097AFC38135E47DF4EE876F6CA1AA864C374B0F23
File Size: 417.13 KB, 417128 bytes
Show More
MD5: f388e3564aaa6dcb46a1c75e60dc2b9e
SHA1: cfb26513c5c2b85d59977dafbf82dfddf45411df
SHA256: 7D68380C12B79610D96F2320EE11430B6AAB67A51192327DEC884B3538FDE03C
File Size: 417.13 KB, 417128 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • 1072c
  • 1076g
  • 1078b
  • 1083f
  • 1086h
  • 1088s
Company Name Fast Corporate LTD.
File Description
  • 1072c
  • 1076g
  • 1078b
  • 1083f
  • 1086h
  • 1088s
File Version
  • 1.0.0.1088s
  • 1.0.0.1086h
  • 1.0.0.1083f
  • 1.0.0.1078b
  • 1.0.0.1076g
  • 1.0.0.1072c
Internal Name auto_updater.exe
Legal Copyright
  • 1072c
  • 1076g
  • 1078b
  • 1083f
  • 1086h
  • 1088s
Original Filename AutoUpdater.exe
Product Name
  • 1072c
  • 1076g
  • 1078b
  • 1083f
  • 1086h
  • 1088s
Product Version
  • 1.0.0.1088s
  • 1.0.0.1086h
  • 1.0.0.1083f
  • 1.0.0.1078b
  • 1.0.0.1076g
  • 1.0.0.1072c

Digital Signatures

Signer Root Status
Fast Corporate LTD DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 Self Signed
PC APP STORE ONLINE LTD Sectigo Public Code Signing Root R46 Root Not Trusted

File Traits

  • HighEntropy
  • x86

Block Information

Total Blocks: 1,648
Potentially Malicious Blocks: 68
Whitelisted Blocks: 1,580
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 x x x x x x x x 0 x 0 x x x 0 0 0 x 0 0 0 x 0 0 0 0 x x 0 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x x x 0 x x 0 0 0 0 x 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x x x x 0 x x x x x x x x x 0 x 0 0 0 0 0 0 0 0 0 x x x 0 0 x 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 x x 0 x 0 x x 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 2 3 1 1 1 1 1 0 0 1 1 0 0 0 0 0 0 2 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 2 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 1 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 1 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 1 1 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Filecoder.DAY
  • Trojan.Downloader.Gen.BU

Trending

Most Viewed

Loading...