Analysis Date | 2015-08-12 03:08:34 |
---|---|
MD5 | 6de6321a4a80572aac277a9136075d8c |
SHA1 | 612ca6b0bf769a15e0252cc4eba37ef7f4bf60de |
Static Details:
File type | PE32 executable for MS Windows (GUI) Intel 80386 32-bit | |
---|---|---|
Section | .text md5: 41fd62c5c2c732a4206063a445252f54 sha1: 8d940425bb2ba586bfb0dc7c313ecbf75f97f84b size: 161280 | |
Section | .rdata md5: 0da9ceab0ba6a8af030a3a242b3fc078 sha1: e72732cccc32137b0f4866ea74101d7737fea691 size: 39936 | |
Section | .data md5: aee2119f5a4bc24d8d379158b7a83cfa sha1: 6c9ad86a818eb5c181dc20ce3d56de17f8cf98df size: 7168 | |
Timestamp | 2015-03-13 09:26:37 | |
Packer | Microsoft Visual C++ ?.? | |
PEhash | a4b432f22495691aeb9db6531fd08529db3f912e | |
IMPhash | d29446a09275467c1386df60d7edf4ef | |
AV | CA (E-Trust Ino) | no_virus |
AV | Rising | 0x58e8bb09 |
AV | Mcafee | Trojan-FEVX!6DE6321A4A80 |
AV | Avira (antivir) | TR/Crypt.XPACK.Gen2 |
AV | Twister | no_virus |
AV | Ad-Aware | Gen:Variant.Rodecap.1 |
AV | Alwil (avast) | Malware-gen:Win32:Malware-gen |
AV | Eset (nod32) | Win32/Rodecap.BJ |
AV | Grisoft (avg) | Win32/Cryptor |
AV | Symantec | Downloader.Upatre!g15 |
AV | Fortinet | W32/Rodecap.BJ!tr |
AV | BitDefender | Gen:Variant.Rodecap.1 |
AV | K7 | Trojan ( 004bda2e1 ) |
AV | Microsoft Security Essentials | Trojan:Win32/Dynamer!ac |
AV | MicroWorld (escan) | Gen:Variant.Rodecap.1 |
AV | MalwareBytes | Trojan.Agent |
AV | Authentium | W32/Nivdort.A.gen!Eldorado |
AV | Frisk (f-prot) | no_virus |
AV | Ikarus | Trojan.Win32.Rodecap |
AV | Emsisoft | Gen:Variant.Rodecap.1 |
AV | Zillya! | no_virus |
AV | Kaspersky | Trojan.Win32.Generic |
AV | Trend Micro | no_virus |
AV | CAT (quickheal) | no_virus |
AV | VirusBlokAda (vba32) | no_virus |
AV | Padvish | no_virus |
AV | BullGuard | Gen:Variant.Rodecap.1 |
AV | Arcabit (arcavir) | Gen:Variant.Rodecap.1 |
AV | ClamAV | no_virus |
AV | Dr. Web | Trojan.DownLoader14.729 |
AV | F-Secure | Gen:Variant.Rodecap.1 |
Runtime Details:
Screenshot | ![]() |
---|
Process
↳ C:\malware.exe
Creates File | C:\cbncsyoiyogog\wmqdt1ldjyqiyl0osgwr.exe |
---|---|
Creates File | C:\cbncsyoiyogog\ycjf8lc7v |
Creates File | C:\WINDOWS\cbncsyoiyogog\ycjf8lc7v |
Deletes File | C:\WINDOWS\cbncsyoiyogog\ycjf8lc7v |
Creates Process | C:\cbncsyoiyogog\wmqdt1ldjyqiyl0osgwr.exe |
Process
↳ C:\cbncsyoiyogog\wmqdt1ldjyqiyl0osgwr.exe
Registry | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\File Connections Port Detection ➝ C:\cbncsyoiyogog\shguwkpjlz.exe |
---|---|
Creates File | C:\cbncsyoiyogog\ycjf8lc7v |
Creates File | C:\cbncsyoiyogog\caapfxd |
Creates File | C:\cbncsyoiyogog\shguwkpjlz.exe |
Creates File | C:\WINDOWS\cbncsyoiyogog\ycjf8lc7v |
Deletes File | C:\WINDOWS\cbncsyoiyogog\ycjf8lc7v |
Creates Process | C:\cbncsyoiyogog\shguwkpjlz.exe |
Creates Service | RPC Copy Image Ordering Shell - C:\cbncsyoiyogog\shguwkpjlz.exe |
Process
↳ C:\WINDOWS\system32\svchost.exe
Process
↳ Pid 816
Process
↳ Pid 860
Process
↳ C:\WINDOWS\System32\svchost.exe
Creates File | C:\WINDOWS\system32\WBEM\Logs\wbemess.log |
---|
Process
↳ Pid 1216
Process
↳ C:\WINDOWS\system32\spoolsv.exe
Registry | HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\BeepEnabled ➝ NULL |
---|---|
Registry | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System\Print\TypesSupported ➝ 7 |
Registry | HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers\SymbolicLinkValue ➝ NULL |
Registry | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory ➝ C:\WINDOWS\System32\spool\PRINTERS\\x00 |
Process
↳ Pid 1880
Process
↳ Pid 1184
Process
↳ C:\cbncsyoiyogog\shguwkpjlz.exe
Creates File | pipe\net\NtControlPipe10 |
---|---|
Creates File | C:\cbncsyoiyogog\rweubgt.exe |
Creates File | C:\cbncsyoiyogog\ycjf8lc7v |
Creates File | \Device\Afd\Endpoint |
Creates File | C:\cbncsyoiyogog\uxvi3rji |
Creates File | C:\cbncsyoiyogog\caapfxd |
Creates File | C:\WINDOWS\cbncsyoiyogog\ycjf8lc7v |
Deletes File | C:\WINDOWS\cbncsyoiyogog\ycjf8lc7v |
Creates Process | n0m3vs2uqgxb "c:\cbncsyoiyogog\shguwkpjlz.exe" |
Process
↳ C:\cbncsyoiyogog\shguwkpjlz.exe
Creates File | C:\cbncsyoiyogog\ycjf8lc7v |
---|---|
Creates File | C:\WINDOWS\cbncsyoiyogog\ycjf8lc7v |
Deletes File | C:\WINDOWS\cbncsyoiyogog\ycjf8lc7v |
Process
↳ n0m3vs2uqgxb "c:\cbncsyoiyogog\shguwkpjlz.exe"
Creates File | C:\cbncsyoiyogog\ycjf8lc7v |
---|---|
Creates File | C:\WINDOWS\cbncsyoiyogog\ycjf8lc7v |
Deletes File | C:\WINDOWS\cbncsyoiyogog\ycjf8lc7v |
Network Details:
Raw Pcap
Strings