Analysis Date2016-01-28 12:57:46
MD52fee7f9292e148923a3e7a035be2b4ef
SHA15f95077b22e7ef0baf2cff94cf735f287c103590

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 1ebeab1b431f45c181999a126105f5af sha1: ad482fba968c4dd83f4023aad6b8561fbbb838cc size: 74752
Section.rdata md5: a2655dcf1a49601504a5fb96585905d5 sha1: 8adb0eb9c7327934f19134e592c351f431f28a2f size: 16384
Section.data md5: 9117be1dd31998b0ae236a2501585926 sha1: 242847d1120e03e75658f17ad59c07d8d0fdcb34 size: 51712
Section.reloc md5: 443ce7f8483c73031c0b32a11d3a0ad2 sha1: d00bea05d61971d795de02dff7b86dcaf694b4d2 size: 5120
Timestamp2016-01-11 16:15:04
PackerMicrosoft Visual C++ ?.?
PEhash65e817ebd52d4986edf3cd4a07c883a7f2691622
IMPhash60902beae54c4b546295641e8914b8e2
AVCA (E-Trust Ino)No Virus
AVRisingNo Virus
AVMcafeeNo Virus
AVAvira (antivir)TR/Crypt.Xpack.422155
AVTwisterNo Virus
AVAd-AwareGen:Variant.Zusy.176907
AVAlwil (avast)Dorder-E [Trj]
AVEset (nod32)Win32/Kryptik.EKGL
AVGrisoft (avg)Crypt5.AAFT
AVSymantecNo Virus
AVFortinetW32/Kryptik.EKGL!tr
AVBitDefenderGen:Variant.Zusy.176907
AVK7Trojan ( 004dbe611 )
AVMicrosoft Security EssentialsWorm:Win32/Gamarue!rfn
AVMicroWorld (escan)Gen:Variant.Zusy.176907
AVMalwareBytesWorm.Gamarue
AVAuthentiumW32/Trojan.XSUB-3764
AVEmsisoftGen:Variant.Zusy.176907
AVFrisk (f-prot)No Virus
AVIkarusTrojan.Win32.Crypt
AVZillya!No Virus
AVKasperskyTrojan.Win32.Generic
AVTrend MicroNo Virus
AVVirusBlokAda (vba32)No Virus
AVCAT (quickheal)No Virus
AVBullGuardGen:Variant.Zusy.176907
AVArcabit (arcavir)Gen:Variant.Zusy.176907
AVClamAVNo Virus
AVDr. WebTrojan.DownLoader18.50422
AVF-SecureGen:Variant.Zusy.176907

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

Creates ProcessC:\WINDOWS\system32\msiexec.exe

Process
↳ C:\WINDOWS\system32\msiexec.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\Explorer\TaskbarNoNotification ➝
1
RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\Policies\Explorer\Run\317606753 ➝
C:\Documents and Settings\All Users\msvgqh.exe\\x00
RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\advanced\ShowSuperHidden ➝
NULL
RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\Explorer\TaskbarNoNotification ➝
1
RegistryHKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\Windows\Load ➝
\\x00
Creates FilePIPE\lsarpc
Creates FileC:\Documents and Settings\All Users\msvgqh.exe
Creates File\Device\Afd\Endpoint
Creates FileC:\Documents and Settings\All Users\118375
Deletes FileC:\5F9507~1.EXE
Winsock DNSmicrosoft.com
Winsock DNSpool.ntp.org
Winsock DNSnorth-america.pool.ntp.org
Winsock DNSafrica.pool.ntp.org
Winsock DNSoceania.pool.ntp.org
Winsock DNSasia.pool.ntp.org
Winsock DNSsouth-america.pool.ntp.org
Winsock DNSeurope.pool.ntp.org

Network Details:

DNSeurope.pool.ntp.org
Type: A
5.135.3.88
DNSeurope.pool.ntp.org
Type: A
85.254.216.1
DNSeurope.pool.ntp.org
Type: A
193.228.143.13
DNSeurope.pool.ntp.org
Type: A
212.18.3.19
DNSnorth-america.pool.ntp.org
Type: A
204.2.134.164
DNSnorth-america.pool.ntp.org
Type: A
50.116.52.97
DNSnorth-america.pool.ntp.org
Type: A
74.120.8.2
DNSnorth-america.pool.ntp.org
Type: A
174.123.154.242
DNSsouth-america.pool.ntp.org
Type: A
200.89.75.198
DNSsouth-america.pool.ntp.org
Type: A
164.73.227.4
DNSsouth-america.pool.ntp.org
Type: A
164.73.232.34
DNSsouth-america.pool.ntp.org
Type: A
190.15.141.64
DNSasia.pool.ntp.org
Type: A
118.67.201.10
DNSasia.pool.ntp.org
Type: A
157.7.152.213
DNSasia.pool.ntp.org
Type: A
202.65.114.202
DNSasia.pool.ntp.org
Type: A
202.162.32.12
DNSoceania.pool.ntp.org
Type: A
130.102.2.123
DNSoceania.pool.ntp.org
Type: A
202.127.210.37
DNSoceania.pool.ntp.org
Type: A
54.252.165.245
DNSoceania.pool.ntp.org
Type: A
121.0.0.42
DNSafrica.pool.ntp.org
Type: A
196.10.54.57
DNSafrica.pool.ntp.org
Type: A
41.73.42.10
DNSafrica.pool.ntp.org
Type: A
41.78.128.17
DNSafrica.pool.ntp.org
Type: A
41.231.7.85
DNSpool.ntp.org
Type: A
209.118.204.201
DNSpool.ntp.org
Type: A
209.208.79.69
DNSpool.ntp.org
Type: A
107.170.242.27
DNSpool.ntp.org
Type: A
132.163.4.102
DNSmicrosoft.com
Type: A
23.96.52.53
DNSmicrosoft.com
Type: A
23.100.122.175
DNSmicrosoft.com
Type: A
104.40.211.35
DNSmicrosoft.com
Type: A
104.43.195.251
DNSmicrosoft.com
Type: A
191.239.213.197
DNSringplanet.eu
Type: A
Flows UDP192.168.1.1:1043 ➝ 8.8.4.4:53
Flows TCP192.168.1.1:1044 ➝ 23.96.52.53:80
Flows UDP192.168.1.1:1045 ➝ 8.8.4.4:53

Raw Pcap

Strings