Analysis Date | 2016-02-03 06:30:32 |
---|---|
MD5 | a749c3fc32abae52f5c397485b673f56 |
SHA1 | 1521f352dd916501faef2eb2f0a472a9c27f981c |
Static Details:
File type | PE32 executable for MS Windows (GUI) Intel 80386 32-bit | |
---|---|---|
Section | .text md5: a2675bc12eb43192612074f4e1a91f29 sha1: da5e0cc818c5a2bf22c1fad37232c44a5de5d729 size: 183296 | |
Section | .rdata md5: f8fe40ff545e98d7f54ec15a1ad14d1e sha1: 258d7beed461cc93506ec4a9a0313f5eba221cec size: 2560 | |
Section | .data md5: b21c7c0b205272badda0ba9f0e23e3ae sha1: d1b5b2ec40476cce2782e336647694ac2c069b68 size: 15360 | |
Section | .reloc md5: 136762baf35231de923a991a63ea9add sha1: 38f027469a0bd6ae895fafe40f3792a87b7dee40 size: 30208 | |
Timestamp | 2014-09-10 22:10:59 | |
PEhash | e02820a9069823db221a97e514bee71bfa476431 | |
IMPhash | 986f8ccf0000d342f4fdacb47f8d0f1f | |
AV | CA (E-Trust Ino) | No Virus |
AV | Rising | No Virus |
AV | Mcafee | Trojan-FHQT!A749C3FC32AB |
AV | Avira (antivir) | TR/Nivdort.A.22269 |
AV | Twister | No Virus |
AV | Ad-Aware | Trojan.Generic.15789896 |
AV | Alwil (avast) | Vupa [Cryp] |
AV | Eset (nod32) | Win32/Bayrob.BA |
AV | Grisoft (avg) | Generic37.WIM |
AV | Symantec | Trojan.Bayrob!gen6 |
AV | Fortinet | W32/Bayrob.AQ!tr |
AV | BitDefender | Trojan.Generic.15789896 |
AV | K7 | Trojan ( 004dc2a31 ) |
AV | Microsoft Security Essentials | TrojanSpy:Win32/Nivdort!rfn |
AV | MicroWorld (escan) | Gen:Variant.Kazy.788903 |
AV | MalwareBytes | No Virus |
AV | Authentium | W32/Nivdort.G.gen!Eldorado |
AV | Emsisoft | Trojan.Generic.15789896 |
AV | Frisk (f-prot) | W32/Nivdort.G.gen!Eldorado |
AV | Ikarus | Trojan.Win32.Bayrob |
AV | Zillya! | No Virus |
AV | Kaspersky | Trojan.Win32.Generic |
AV | Trend Micro | No Virus |
AV | VirusBlokAda (vba32) | No Virus |
AV | CAT (quickheal) | No Virus |
AV | BullGuard | Trojan.Generic.15789896 |
AV | Arcabit (arcavir) | Trojan.Generic.15789896 |
AV | ClamAV | No Virus |
AV | Dr. Web | Trojan.DownLoader19.6065 |
AV | F-Secure | Trojan.Generic.15789896 |
Runtime Details:
Screenshot | ![]() |
---|
Process
↳ C:\malware.exe
Creates File | C:\jhielseic\iy7fqhct |
---|---|
Creates File | C:\jhielseic\gbu41l1tchppua2llg.exe |
Creates File | C:\WINDOWS\jhielseic\iy7fqhct |
Deletes File | C:\WINDOWS\jhielseic\iy7fqhct |
Creates Process | C:\jhielseic\gbu41l1tchppua2llg.exe |
Process
↳ C:\jhielseic\gbu41l1tchppua2llg.exe
Registry | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Machine Group Connect Drive Event ➝ C:\jhielseic\ticvooyyw.exe |
---|---|
Creates File | C:\jhielseic\iy7fqhct |
Creates File | PIPE\lsarpc |
Creates File | C:\WINDOWS\jhielseic\iy7fqhct |
Creates File | C:\jhielseic\ticvooyyw.exe |
Creates File | C:\jhielseic\xvuk2dgc |
Deletes File | C:\WINDOWS\jhielseic\iy7fqhct |
Creates Process | C:\jhielseic\ticvooyyw.exe |
Creates Service | Studio Routing Multimedia Brightness - C:\jhielseic\ticvooyyw.exe |
Process
↳ C:\WINDOWS\system32\svchost.exe
Process
↳ Pid 804
Process
↳ Pid 848
Process
↳ C:\WINDOWS\System32\svchost.exe
Process
↳ Pid 1204
Process
↳ C:\WINDOWS\system32\spoolsv.exe
Registry | HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\BeepEnabled ➝ NULL |
---|---|
Registry | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System\Print\TypesSupported ➝ 7 |
Registry | HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers\SymbolicLinkValue ➝ NULL |
Registry | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory ➝ C:\WINDOWS\System32\spool\PRINTERS\\x00 |
Process
↳ Pid 1864
Process
↳ Pid 1124
Process
↳ C:\jhielseic\ticvooyyw.exe
Creates File | C:\jhielseic\iy7fqhct |
---|---|
Creates File | pipe\net\NtControlPipe10 |
Creates File | C:\jhielseic\dcnhrhylwmt |
Creates File | C:\jhielseic\mytobhbsldt.exe |
Creates File | C:\WINDOWS\jhielseic\iy7fqhct |
Creates File | \Device\Afd\Endpoint |
Creates File | C:\jhielseic\xvuk2dgc |
Deletes File | C:\WINDOWS\jhielseic\iy7fqhct |
Creates Process | ezl9byg3ubqp "c:\jhielseic\ticvooyyw.exe" |
Process
↳ C:\jhielseic\ticvooyyw.exe
Creates File | C:\jhielseic\iy7fqhct |
---|---|
Creates File | C:\WINDOWS\jhielseic\iy7fqhct |
Deletes File | C:\WINDOWS\jhielseic\iy7fqhct |
Process
↳ ezl9byg3ubqp "c:\jhielseic\ticvooyyw.exe"
Creates File | C:\jhielseic\iy7fqhct |
---|---|
Creates File | C:\WINDOWS\jhielseic\iy7fqhct |
Deletes File | C:\WINDOWS\jhielseic\iy7fqhct |
Network Details:
Raw Pcap
Strings