Analysis Date | 2015-10-04 20:18:35 |
---|---|
MD5 | c6f52e5d9c81bf2f7234f1da5f4e9956 |
SHA1 | 60f2edcd5cb346b76e1831228d39d9f25e6ced3d |
Static Details:
File type | PE32 executable for MS Windows (GUI) Intel 80386 32-bit | |
---|---|---|
Section | .text md5: 4a25c0f241a86f18a53ec06c1590a508 sha1: a6cfdabc70d05cca7825a6799a3333e7650ca3d3 size: 512 | |
Section | .rdata md5: ab29002ea2e7c0d91a2bde1d817ca366 sha1: ced738602e81801744fe86d982895b06b7ce5a58 size: 104960 | |
Section | .data md5: d41d8cd98f00b204e9800998ecf8427e sha1: da39a3ee5e6b4b0d3255bfef95601890afd80709 size: 0 | |
Section | .rsrc md5: bf619eac0cdf3f68d496ea9344137e8b sha1: 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 size: 512 | |
Section | .reloc md5: d8e444f61f8807b8b50ecd9c6efdb68f sha1: 2a25cc59a47133acb40ec3e96c18319ae89dab1e size: 512 | |
Timestamp | 2014-04-25 13:50:12 | |
Packer | Borland Delphi 3.0 (???) | |
PEhash | 1a43470255bbd861b6601e7df35ca42f31b78ac6 | |
IMPhash | 5d907e4f447d6c7f2275c3923df49f63 | |
AV | CA (E-Trust Ino) | no_virus |
AV | F-Secure | no_virus |
AV | Dr. Web | no_virus |
AV | ClamAV | no_virus |
AV | Arcabit (arcavir) | no_virus |
AV | BullGuard | no_virus |
AV | Padvish | no_virus |
AV | VirusBlokAda (vba32) | no_virus |
AV | CAT (quickheal) | no_virus |
AV | Trend Micro | BKDR_PLUGX.EO |
AV | Kaspersky | Backdoor.Win32.Gulpix.vks |
AV | Zillya! | Trojan.FakeAV.Win32.316300 |
AV | Emsisoft | no_virus |
AV | Ikarus | Win32.SuspectCrc |
AV | Frisk (f-prot) | no_virus |
AV | Authentium | no_virus |
AV | MalwareBytes | no_virus |
AV | MicroWorld (escan) | Gen:Variant.Kazy.306055 |
AV | Microsoft Security Essentials | no_virus |
AV | K7 | Trojan ( 004967951 ) |
AV | BitDefender | no_virus |
AV | Fortinet | W32/FakeAV.BVQC!tr |
AV | Symantec | no_virus |
AV | Grisoft (avg) | Crypt3.LML |
AV | Eset (nod32) | Win32/Kryptik.BVQC |
AV | Alwil (avast) | MalOb-HP [Cryp] |
AV | Ad-Aware | no_virus |
AV | Twister | Virus.56576A406800100000.mg |
AV | Avira (antivir) | TR/Dropper.Gen |
AV | Mcafee | RDN/Generic.bfr |
AV | Rising | no_virus |
Runtime Details:
Screenshot | ![]() |
---|
Process
↳ C:\malware.exe
Creates File | C:\Documents and Settings\All Users\DRM\XXX\.exe |
---|---|
Creates Process | C:\Documents and Settings\All Users\DRM\XXX\.exe |
Creates Mutex | Global\afudrymmy |
Process
↳ C:\Documents and Settings\All Users\DRM\XXX\.exe
Creates Process | C:\WINDOWS\system32\svchost.exe |
---|---|
Creates Mutex | Global\uecpg |
Creates Mutex | Global\gbunwodqgillmltcd |
Creates Mutex | Global\eknwzrskinjqgsrwl |
Creates Mutex | Global\wylurrybkdlyonkut |
Creates Mutex | Global\eklrhgdvaqrfzgugv |
Creates Mutex | Global\ommdvtuqnjwvdfajh |
Creates Mutex | Global\ufiggmvpeeiwv |
Creates Mutex | Global\ssmuagced |
Creates Mutex | Global\mschu |
Creates Mutex | Global\gxklm |
Creates Mutex | Global\gxkrqsnwbuyet |
Creates Mutex | Global\inkxsdwqbtist |
Creates Mutex | Global\uimnyxkbx |
Creates Mutex | Global\iqlpefsfveadljlia |
Creates Mutex | Global\aelyqgtun |
Creates Mutex | Global\mwmjwuuwpuvcczsph |
Creates Mutex | Global\oibsb |
Creates Mutex | Global\afudrymmy |
Process
↳ C:\WINDOWS\system32\svchost.exe
Registry | HKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable ➝ NULL |
---|---|
Registry | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass ➝ 1 |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20151004182206.jpg |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20151004182226.jpg |
Creates File | C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20151004182156.jpg |
Creates File | C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20151004182216.jpg |
Creates File | C:\Documents and Settings\All Users\DRM\XXX\nprqyjadoqkp |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20151004182221.jpg |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20151004182211.jpg |
Creates File | C:\Documents and Settings\Administrator\Cookies\index.dat |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20151004182231.jpg |
Creates File | PIPE\lsarpc |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20151004182201.jpg |
Creates File | \Device\Afd\Endpoint |
Creates Mutex | c:!documents and settings!administrator!local settings!history!history.ie5! |
Creates Mutex | c:!documents and settings!administrator!cookies! |
Creates Mutex | c:!documents and settings!administrator!local settings!temporary internet files!content.ie5! |
Creates Mutex | Global\000000010000000000000100 |
Creates Mutex | MMMM |
Winsock DNS | 127.0.0.1 |
Network Details:
Flows UDP | 192.168.1.1:53 ➝ 192.168.1.1:53 |
---|
Raw Pcap
Strings