Analysis Date2018-05-19 15:22:36
MD51a4c50a51f7e26e8aebe9795c6f9d428
SHA15252ae48e3b2b3fa612a5191bb531db834e046ce

Static Details:

AVArcabit (arcavir)Gen:Variant.Barys.58165
AVAuthentiumW32/Nivdort.L.gen!Eldorado
AVGrisoft (avg)Win32/Cryptor
AVAvira (antivir)TR/Nivdort.Gen2
AVAlwil (avast)Evo-gen [Susp]
AVAd-AwareGen:Variant.Barys.58165
AVBitDefenderGen:Variant.Barys.58165
AVBullGuardGen:Variant.Barys.58165
AVClamAVNo Virus
AVDr. WebTrojan.Bayrob.57
AVEmsisoftGen:Variant.Barys.58165
AVMicroWorld (escan)Gen:Variant.Barys.58165
AVCA (E-Trust Ino)Gen:Variant.Zusy.189044
AVFortinetW32/Bayrob.BT!tr
AVFrisk (f-prot)W32/Nivdort.L.gen!Eldorado
AVF-SecureTrojan:W32/Bayrob.F
AVIkarusTrojan.Win32.Bayrob
AVK7Error Scanning File
AVKasperskyTrojan.Win32.Bayrob.gen
AVMalwareBytesNo Virus
AVMcafeeTrojan-FINB!1A4C50A51F7E
AVMicrosoft Security EssentialsTrojanSpy:Win32/Nivdort
AVNANOTrojan.Win32.Bayrob.eciqdd
AVEset (nod32)Win32/Bayrob.BS
AVPadvishNo Virus
AVCAT (quickheal)TrojanSpy.Nivdort.DR3
AVRisingNo Virus
AV360 SafeNo Virus
AVSUPERAntiSpywareError Scanning File
AVSymantecTrojan.Bayrob!gen8
AVTrend MicroNo Virus
AVTwisterNo Virus
AVVirusBlokAda (vba32)SScope.Malware-Cryptor.Bayrob
AVWindows DefenderTrojanSpy:Win32/Nivdort
AVZillya!Trojan.SwizzorGen.Win32.1

Runtime Details:

Screenshot

Process
↳ C:\Windows\System32\lsass.exe

Process
↳ C:\Users\Phil\AppData\Local\Temp\5252ae48e3b2b3fa612a5191bb531db834e046ce.exe

Creates Mutex
Creates Mutex
Creates Mutex
Creates Mutex
Creates FileC:\Windows\gcldobpgmi\hngcchdq
Creates FileC:\gcldobpgmi\hngcchdq
Creates Filec:\Users\Phil\AppData\Local\Temp\5252ae48e3b2b3fa612a5191bb531db834e046ce.exe
Creates FileC:\gcldobpgmi\pn51sdns7gbzenvlblk.exe

Process
↳ C:\gcldobpgmi\pn51sdns7gbzenvlblk.exe

Creates Mutex
Creates Mutex
Creates Mutex
Creates Mutex
Creates FileC:\Windows\gcldobpgmi\hngcchdq
Creates FileC:\gcldobpgmi\hngcchdq
Creates FileC:\gcldobpgmi\nlzzvt699
Creates FileC:\gcldobpgmi\run

Process
↳ C:\gcldobpgmi\ghnskrdshegw.exe

Creates Mutex
Creates Mutex
Creates Mutex
Creates Mutex
Creates FileC:\Windows\gcldobpgmi\hngcchdq
Creates FileC:\gcldobpgmi\hngcchdq
Creates FileC:\gcldobpgmi\nlzzvt699

Network Details:


Raw Pcap

Strings