Analysis Date2018-05-13 20:58:20
MD55df61c38e50fa7b1764803629b7ef693
SHA1076cdb883fecc6bf7b60aa1de48eac80e91bf00e

Static Details:

AVArcabit (arcavir)Gen:Variant.Barys.57495
AVAuthentiumW32/Nivdort.L.gen!Eldorado
AVGrisoft (avg)Win32/Cryptor
AVAvira (antivir)TR/Nivdort.Gen2
AVAlwil (avast)Malware-gen
AVAlwil (avast)Win32:Malware-gen
AVAd-AwareGen:Variant.Barys.57495
AVBitDefenderGen:Variant.Barys.57495
AVBullGuardGen:Variant.Barys.57495
AVClamAVNo Virus
AVDr. WebTrojan.Bayrob.57
AVEmsisoftGen:Variant.Barys.57495
AVMicroWorld (escan)Gen:Variant.Barys.57495
AVCA (E-Trust Ino)Gen:Variant.Zusy.191969
AVFortinetW32/Bayrob.BT!tr
AVFrisk (f-prot)W32/Nivdort.L.gen!Eldorado
AVF-SecureTrojan:W32/Bayrob.F
AVIkarusTrojan.Win32.Bayrob
AVK7Trojan ( 004dc2a31 )
AVKasperskyTrojan.Win32.Bayrob.gen
AVMalwareBytesNo Virus
AVMcafeeTrojan-FINB!5DF61C38E50F
AVMicrosoft Security EssentialsTrojanSpy:Win32/Nivdort
AVNANOTrojan.Win32.Bayrob.ecdzdi
AVEset (nod32)Win32/Bayrob.BS
AVPadvishNo Virus
AVCAT (quickheal)TrojanSpy.Nivdort.DR3
AVRisingNo Virus
AV360 SafeNo Virus
AVSUPERAntiSpywareNo Virus
AVSymantecTrojan.Bayrob!gen8
AVTrend MicroNo Virus
AVTwisterNo Virus
AVVirusBlokAda (vba32)BScope.Trojan.Bayrob
AVWindows DefenderTrojanSpy:Win32/Nivdort
AVZillya!Trojan.SwizzorGen.Win32.1

Runtime Details:

Screenshot

Process
↳ C:\Windows\System32\lsass.exe

Process
↳ C:\Users\Phil\AppData\Local\Temp\076cdb883fecc6bf7b60aa1de48eac80e91bf00e.exe

Creates Mutex
Creates Mutex
Creates Mutex
Creates Mutex
Creates FileC:\Windows\wdovtfdckucm\o5dnueizovl
Creates FileC:\wdovtfdckucm\o5dnueizovl
Creates Filec:\Users\Phil\AppData\Local\Temp\076cdb883fecc6bf7b60aa1de48eac80e91bf00e.exe
Creates FileC:\wdovtfdckucm\d8swcksgjhnaztnhxkj4v.exe

Process
↳ C:\wdovtfdckucm\d8swcksgjhnaztnhxkj4v.exe

Creates Mutex
Creates Mutex
Creates Mutex
Creates Mutex
Creates FileC:\Windows\wdovtfdckucm\o5dnueizovl
Creates FileC:\wdovtfdckucm\o5dnueizovl
Creates FileC:\wdovtfdckucm\ghqrprls3
Creates FileC:\wdovtfdckucm\run

Process
↳ C:\wdovtfdckucm\cdzfgdlz.exe

Creates Mutex
Creates Mutex
Creates Mutex
Creates Mutex
Creates FileC:\Windows\wdovtfdckucm\o5dnueizovl
Creates FileC:\wdovtfdckucm\o5dnueizovl
Creates FileC:\wdovtfdckucm\ghqrprls3

Network Details:


Raw Pcap

Strings