Analysis Date2018-02-06 11:42:52
MD5de21408d5899d865fa13ba32607e93b2
SHA110a6fbf59916fa6f02d9a1fe5219f0b00a527857

Static Details:

File typePE32 executable (GUI) Intel 80386, for MS Windows
PEhash
AVArcabit (arcavir)Gen:Variant.Adware.ConvertAd.23
AVAuthentiumW32/Scar.R.gen!Eldorado
AVGrisoft (avg)Win32/Cryptor
AVAvira (antivir)TR/Kryptik.qgmpd
AVAlwil (avast)Malware-gen
AVAlwil (avast)Win32:Malware-gen
AVAd-AwareGen:Variant.Adware.ConvertAd.23
AVBitDefenderGen:Variant.Adware.ConvertAd.23
AVBullGuardGen:Variant.Adware.ConvertAd.23
AVClamAVNo Virus
AVDr. WebTrojan.Bayrob.1
AVEmsisoftGen:Variant.Adware.ConvertAd.23
AVMicroWorld (escan)Gen:Variant.Adware.ConvertAd.23
AVCA (E-Trust Ino)Gen:Variant.Adware.ConvertAd.23
AVFortinetW32/Bayrob.AQ!tr
AVFrisk (f-prot)W32/Scar.R.gen!Eldorado
AVF-SecureNo Virus
AVIkarusError Scanning File
AVK7Trojan ( 004da8bd1 )
AVKasperskyTrojan.Win32.Generic
AVMalwareBytesTrojan.Agent.KVTGen
AVMcafeeTrojan-FGIJ!DE21408D5899
AVMicrosoft Security EssentialsTrojanSpy:Win32/Nivdort
AVNANOTrojan.Win32.Bayrob.exlpsv
AVEset (nod32)Win32/Bayrob.T
AVPadvishNo Virus
AVCAT (quickheal)TrojanSpy.Nivdort.OD4
AVRisingTrojan.Win32.Bayrod.a
AV360 SafeNo Virus
AVSUPERAntiSpywareNo Virus
AVSymantecDownloader.Upatre!g15
AVTrend MicroNo Virus
AVTwisterW32.Toolbar.CrossRider.AE.lfcr.mg
AVVirusBlokAda (vba32)No Virus
AVWindows DefenderTrojanSpy:Win32/Nivdort
AVZillya!Trojan.Scar.Win32.90251

Runtime Details:

Screenshot

Process
↳ C:\Windows\System32\lsass.exe

Process
↳ C:\Users\THX1138\AppData\Local\Temp\10a6fbf59916fa6f02d9a1fe5219f0b00a527857.exe

Network Details:


Raw Pcap

Strings