Analysis Date2015-11-12 13:50:37
MD501f92a6f972ae7c5be06c08fefe57bc3
SHA124b1b36300897f7934d379c071a03b889ffe0993

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 1e045ecfc6f99a89699348747b7455ae sha1: a31d878b34174bc224f78a8374636dd61f7a934b size: 6144
Section.rdata md5: 81abcd4be37fbf5a36cd944574f088ce sha1: 30335fd2f2421c3cefa3037f86d6b2b264a0d298 size: 4096
Section.data md5: 49f2de540c93b29faca4294d4082e102 sha1: acd51dc46f4e19872e7dabecee3f1e3ee6e74a62 size: 2048
Section.rsrc md5: a1293f8869017440215fb858c5197b4b sha1: 337e0152fc51ff24c9317a78e7d213b370e3ca37 size: 19968
Timestamp2013-06-30 21:53:32
PackerMicrosoft Visual C 2.0
PEhashf0254163396cc975a66ac694a20d074f92c8815b
IMPhash012c63bb5f7f1ff21471f621b5d79f47
AVRisingTrojan.Win32.Kryptik.af
AVMcafeeDownloader-FASG!01F92A6F972A
AVAvira (antivir)TR/Crypt.ZPACK.161083
AVTwisterTrojanDldr.Upatre.addk.mauo
AVAd-AwareTrojan.Downloader.JRTI
AVAlwil (avast)GenMalicious-KNL [Trj]
AVEset (nod32)Win32/Kryptik.DIGI
AVGrisoft (avg)Crypt_s.IMB
AVSymantecDownloader.Upatre!gen5
AVFortinetW32/Kryptic.ABGK!tr
AVBitDefenderTrojan.Downloader.JRTI
AVK7Trojan ( 004c29131 )
AVMicrosoft Security EssentialsTrojanDownloader:Win32/Upatre.G
AVMicroWorld (escan)Trojan.Downloader.JRTI
AVMalwareBytesTrojan.Upatre
AVAuthentiumW32/Dalexis.Q.gen!Eldorado
AVFrisk (f-prot)W32/Dalexis.Q.gen!Eldorado
AVIkarusTrojan.VB.Crypt
AVEmsisoftTrojan.Downloader.JRTI
AVZillya!No Virus
AVKasperskyTrojan-Downloader.Win32.Upatre.aetm
AVTrend MicroTROJ_UP.9EED1BD4
AVCAT (quickheal)Trojan.Kadena.B4
AVVirusBlokAda (vba32)No Virus
AVPadvishNo Virus
AVBullGuardTrojan.Downloader.JRTI
AVArcabit (arcavir)Trojan.Downloader.JRTI
AVClamAVNo Virus
AVDr. WebTrojan.Upatre.1072
AVF-SecureTrojan.Downloader.JRTI
AVCA (E-Trust Ino)No Virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\Xulantar.exe
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\InstallXul.tmp
Creates ProcessC:\Documents and Settings\Administrator\Local Settings\Temp\Xulantar.exe

Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\Xulantar.exe

Creates FilePIPE\lsarpc
Creates FileC:\Documents and Settings\Administrator\Local Settings\Temp\29e9_appcompat.txt
Creates ProcessC:\WINDOWS\system32\dwwin.exe -x -s 200
Creates ProcessC:\WINDOWS\system32\drwtsn32 -p 1448 -e 156 -g

Process
↳ C:\WINDOWS\system32\dwwin.exe -x -s 200

Process
↳ C:\WINDOWS\system32\drwtsn32 -p 1448 -e 156 -g

Network Details:


Raw Pcap

Strings

Button1
Button2
Dina-download ang Justefy... Nabigong i-download ang Justefy.
Downloading Justefy...
Ini-extract ang Justefy...)Dina-download ang nilalaman ng partner...
Installer ng Justefy
@jjj
Justefy
Kasalukuyang nag-i-installdHindi pa kumpletong nai-install ang Justefy. Sigurado ka bang gusto mong kanselahin ang pag-install?
MessageBoxLabel
msctls_progress32
MS Shell Dlg
Nabigong i-extract ang Justefy.
                />
 $$&& 
-!&(#,
,-!+"+*
!//+)#)%
/-#)&,%#
/..$&--.
/*%+ )&
/+.&%-'#
.#%)&-,/
"-/$(,
$".,&  $
*//!"$
#-)$"..
#!",'../ ""
#$!+($
%#$%(+
	/!/*--
-,0%(..
$+#&(0
*&.0/"$#.
#+0'%!
%"!'*0
%$ "0*
0"# )%* ""
0"+% "
+'*0 0/
0(""&!,0
$(00"!0
*"%'2(
2.'-+#
&2+$$-1
321,	+
3	32!*
_acmdln_dll
ad7`U*
</assembly>
<assemblyIdentity
                <assemblyIdentity
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
button
Cancel
_commode_dll
CreateWindowExA
CRTDLL.dll
@.data
DefWindowProcA
</dependency>
<dependency>
        </dependentAssembly>
        <dependentAssembly>
<description>Justefy</description>
DestroyWindow
DialogBoxParamA
DispatchMessageA
EndDialog
ExtractIconA
_fmode_dll
GetLastError
GetLocalTime
__GetMainArgs
GetMessageA
GetModuleFileNameA
GetModuleHandleA
GetStartupInfoA
_global_unwind2
_initterm
InterlockedDecrement
InterlockedIncrement
jdhHM@
jI?XW?,
KERNEL32.dll
,	KUh@
                        language="*"
listbox
LoadCursorA
LoadIconA
LoadLibraryA
LoadStringA
_local_unwind2
lstrcpyA
      <ms_asmv3:requestedExecutionLevel level="asInvoker" uiAccess="false" />
    </ms_asmv3:requestedPrivileges>
    <ms_asmv3:requestedPrivileges>
  </ms_asmv3:security>
  <ms_asmv3:security>
</ms_asmv3:trustInfo>
<ms_asmv3:trustInfo xmlns:ms_asmv3="urn:schemas-microsoft-com:asm.v3">
NameFile:
        name="Justefy"
                        name="Microsoft.Windows.Common-Controls"
newfile
PathAddExtensionW
PathGetDriveNumberW
PathIsRelativeW
PostMessageA
PostQuitMessage
p'RichW
                        processorArchitecture="*"
        processorArchitecture="*"
                        publicKeyToken="6595b64144ccf1df"
`.rdata
RegisterClassExA
riched32.dll
richedit
SendMessageA
SetFocus
SHELL32.dll
SHLWAPI.dll
SleepEx
static
STATIC
!This program cannot be run in DOS mode.
TranslateMessage
                        type="win32"
        type="win32"
USER32.dll
VC20XC00U
        version="1.0.0.0"
                        version="6.0.0.0"
WClass1
WindowA
_XcptFilter
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>