Analysis Date | 2016-01-29 03:26:43 |
---|---|
MD5 | b5c8b6205b7a9cec612c09bce95220cb |
SHA1 | 47aa0a81c09ccf53c74be2bfb705c080d25a9ea4 |
Static Details:
File type | PE32 executable for MS Windows (GUI) Intel 80386 32-bit | |
---|---|---|
Section | .text md5: 463aed84ce5a8159ddf83c74c6fecc76 sha1: 064fc4dfb493e3b831d1681cb821f8169fdb7b55 size: 201728 | |
Section | .rdata md5: bf80ad9e37d2da669fb58dbb1f113e14 sha1: d86e78b5e52ee5dc1f1bca5af18e782956ce9b32 size: 3072 | |
Section | .data md5: 9eaded51536458ccc4690767de5b3027 sha1: dd6e44a33a48df241f645ec90d3417a622623229 size: 14848 | |
Section | .reloc md5: 69df6507c2b08d939268dc353b37b8a6 sha1: d129eeb0740f396a416008b78864139290bca6e8 size: 31744 | |
Timestamp | 2014-12-14 11:30:07 | |
PEhash | f5c84412cf57966df48acc0071bdba4d7899db1e | |
IMPhash | 56e1461701d7cfc42889238375e6bf80 | |
AV | CA (E-Trust Ino) | No Virus |
AV | Rising | No Virus |
AV | Mcafee | Trojan-FHRG!B5C8B6205B7A |
AV | Avira (antivir) | TR/Nivdort.A.31033 |
AV | Twister | No Virus |
AV | Ad-Aware | Gen:Variant.Kazy.788903 |
AV | Alwil (avast) | Vupa [Cryp] |
AV | Eset (nod32) | Win32/Bayrob.AT.gen |
AV | Grisoft (avg) | Generic_r.GVH |
AV | Symantec | Trojan.Bayrob!gen6 |
AV | Fortinet | W32/Bayrob.AT!tr |
AV | BitDefender | Gen:Variant.Kazy.788903 |
AV | K7 | Trojan ( 004dc2a31 ) |
AV | Microsoft Security Essentials | TrojanSpy:Win32/Nivdort.DD |
AV | MicroWorld (escan) | Gen:Variant.Kazy.788903 |
AV | MalwareBytes | No Virus |
AV | Authentium | W32/Nivdort.H.gen!Eldorado |
AV | Emsisoft | Gen:Variant.Kazy.788903 |
AV | Frisk (f-prot) | W32/Nivdort.H.gen!Eldorado |
AV | Ikarus | Trojan.Win32.Bayrob |
AV | Zillya! | No Virus |
AV | Kaspersky | Trojan.Win32.Generic |
AV | Trend Micro | No Virus |
AV | VirusBlokAda (vba32) | No Virus |
AV | CAT (quickheal) | No Virus |
AV | BullGuard | Gen:Variant.Kazy.788903 |
AV | Arcabit (arcavir) | Gen:Variant.Kazy.788903 |
AV | ClamAV | No Virus |
AV | Dr. Web | No Virus |
AV | F-Secure | Gen:Variant.Kazy.788903 |
Runtime Details:
Screenshot | ![]() |
---|
Process
↳ C:\malware.exe
Creates File | C:\rwdmkwubewoa\bhi4guai4e |
---|---|
Creates File | C:\rwdmkwubewoa\way3wfwfwyiauxqrda.exe |
Creates File | C:\WINDOWS\rwdmkwubewoa\bhi4guai4e |
Deletes File | C:\WINDOWS\rwdmkwubewoa\bhi4guai4e |
Creates Process | C:\rwdmkwubewoa\way3wfwfwyiauxqrda.exe |
Process
↳ C:\rwdmkwubewoa\way3wfwfwyiauxqrda.exe
Registry | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\DLL Card Host Sharing Thread ➝ C:\rwdmkwubewoa\tcgdvceyuenf.exe |
---|---|
Creates File | C:\rwdmkwubewoa\tcgdvceyuenf.exe |
Creates File | C:\rwdmkwubewoa\bhi4guai4e |
Creates File | C:\rwdmkwubewoa\hktstcxa |
Creates File | PIPE\lsarpc |
Creates File | C:\WINDOWS\rwdmkwubewoa\bhi4guai4e |
Deletes File | C:\WINDOWS\rwdmkwubewoa\bhi4guai4e |
Creates Process | C:\rwdmkwubewoa\tcgdvceyuenf.exe |
Creates Service | UPnP Discovery PNRP CNG Power Launcher NetBIOS - C:\rwdmkwubewoa\tcgdvceyuenf.exe |
Process
↳ C:\WINDOWS\system32\svchost.exe
Process
↳ Pid 796
Process
↳ Pid 848
Process
↳ C:\WINDOWS\System32\svchost.exe
Creates File | C:\WINDOWS\Prefetch\RUNDLL32.EXE-1BC69D2D.pf |
---|---|
Creates File | C:\WINDOWS\Prefetch\WAY3WFWFWYIAUXQRDA.EXE-2F073F49.pf |
Creates File | C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf |
Creates File | C:\WINDOWS\Prefetch\monitor.exe-1949D260.pf |
Creates File | C:\WINDOWS\Prefetch\USERINIT.EXE-30B18140.pf |
Creates File | C:\WINDOWS\Prefetch\READER_SL.EXE-3614FA6E.pf |
Creates File | C:\WINDOWS\Prefetch\NXYBDAXX.EXE-01552070.pf |
Creates File | C:\WINDOWS\Prefetch\TCGDVCEYUENF.EXE-00238559.pf |
Creates File | C:\WINDOWS\system32\WBEM\Logs\wbemess.log |
Creates File | C:\WINDOWS\Prefetch\svchost.EXE-0C867EC1.pf |
Process
↳ Pid 1204
Process
↳ Pid 1328
Process
↳ Pid 1864
Process
↳ Pid 976
Process
↳ C:\rwdmkwubewoa\tcgdvceyuenf.exe
Creates File | pipe\net\NtControlPipe10 |
---|---|
Creates File | C:\rwdmkwubewoa\nxybdaxx.exe |
Creates File | C:\rwdmkwubewoa\bhi4guai4e |
Creates File | C:\rwdmkwubewoa\y9wdcwjyc |
Creates File | C:\rwdmkwubewoa\hktstcxa |
Creates File | C:\WINDOWS\rwdmkwubewoa\bhi4guai4e |
Creates File | \Device\Afd\Endpoint |
Deletes File | C:\WINDOWS\rwdmkwubewoa\bhi4guai4e |
Creates Process | bpued90y2aj7 "c:\rwdmkwubewoa\tcgdvceyuenf.exe" |
Process
↳ C:\rwdmkwubewoa\tcgdvceyuenf.exe
Creates File | C:\rwdmkwubewoa\bhi4guai4e |
---|---|
Creates File | C:\WINDOWS\rwdmkwubewoa\bhi4guai4e |
Deletes File | C:\WINDOWS\rwdmkwubewoa\bhi4guai4e |
Process
↳ bpued90y2aj7 "c:\rwdmkwubewoa\tcgdvceyuenf.exe"
Creates File | C:\rwdmkwubewoa\bhi4guai4e |
---|---|
Creates File | C:\WINDOWS\rwdmkwubewoa\bhi4guai4e |
Deletes File | C:\WINDOWS\rwdmkwubewoa\bhi4guai4e |
Network Details:
Raw Pcap
Strings