Analysis Date2018-05-19 17:06:59
MD5831cb25017bd7c6522aa1b668578b218
SHA1420e2c707db5d5081ed34919f418d52e419135f8

Static Details:

AVArcabit (arcavir)Gen:Variant.Barys.58165
AVAuthentiumW32/Nivdort.L.gen!Eldorado
AVGrisoft (avg)Error Scanning File
AVAvira (antivir)TR/Taranis.3762
AVAlwil (avast)Evo-gen [Susp]
AVAd-AwareGen:Variant.Barys.58165
AVBitDefenderGen:Variant.Barys.58165
AVBullGuardGen:Variant.Barys.58165
AVClamAVNo Virus
AVDr. WebTrojan.Bayrob.57
AVEmsisoftGen:Variant.Barys.58165
AVMicroWorld (escan)Gen:Variant.Barys.58165
AVCA (E-Trust Ino)Gen:Variant.Zusy.189044
AVFortinetW32/Bayrob.BT!tr
AVFrisk (f-prot)W32/Nivdort.L.gen!Eldorado
AVF-SecureTrojan:W32/Bayrob.F
AVIkarusTrojan.Win32.Bayrob
AVK7Trojan ( 004dc2a31 )
AVKasperskyTrojan.Win32.Bayrob.gen
AVMalwareBytesTrojan.Nivdort
AVMcafeeGenericR-HBV!831CB25017BD
AVMicrosoft Security EssentialsTrojanSpy:Win32/Nivdort
AVNANOTrojan.Win32.Nivdort.ebuqrb
AVEset (nod32)Win32/Bayrob.BS
AVPadvishNo Virus
AVCAT (quickheal)TrojanSpy.Nivdort.DR3
AVRisingNo Virus
AV360 SafeNo Virus
AVSUPERAntiSpywareError Scanning File
AVSymantecTrojan.Bayrob!gen8
AVTrend MicroNo Virus
AVTwisterW32.Toolbar.CrossRider.AE.czia.mg
AVVirusBlokAda (vba32)BScope.Trojan.Bayrob
AVWindows DefenderTrojanSpy:Win32/Nivdort
AVZillya!Trojan.SwizzorGen.Win32.1

Runtime Details:

Screenshot

Process
↳ C:\Windows\System32\lsass.exe

Process
↳ C:\Users\Phil\AppData\Local\Temp\420e2c707db5d5081ed34919f418d52e419135f8.exe

Creates Mutex
Creates Mutex
Creates Mutex
Creates Mutex
Creates FileC:\Windows\pyoupmqlufwvz\xhjneuxhvug
Creates FileC:\pyoupmqlufwvz\xhjneuxhvug
Creates Filec:\Users\Phil\AppData\Local\Temp\420e2c707db5d5081ed34919f418d52e419135f8.exe
Creates FileC:\pyoupmqlufwvz\ixoyv27s4pjijliuyab.exe

Process
↳ C:\pyoupmqlufwvz\ixoyv27s4pjijliuyab.exe

Creates Mutex
Creates Mutex
Creates Mutex
Creates Mutex
Creates FileC:\Windows\pyoupmqlufwvz\xhjneuxhvug
Creates FileC:\pyoupmqlufwvz\xhjneuxhvug
Creates FileC:\pyoupmqlufwvz\ikbaxvbidxc
Creates FileC:\pyoupmqlufwvz\run

Process
↳ C:\pyoupmqlufwvz\zvtdldcl.exe

Creates Mutex
Creates Mutex
Creates Mutex
Creates Mutex
Creates FileC:\Windows\pyoupmqlufwvz\xhjneuxhvug
Creates FileC:\pyoupmqlufwvz\xhjneuxhvug
Creates FileC:\pyoupmqlufwvz\ikbaxvbidxc

Network Details:


Raw Pcap

Strings