Analysis Date | 2015-09-30 06:44:02 |
---|---|
MD5 | a74f8bb071de766f259fbbce20949429 |
SHA1 | 647ac31144ee730bd94ee06a2dc9fba23efb90ae |
Static Details:
File type | PE32 executable for MS Windows (GUI) Intel 80386 32-bit | |
---|---|---|
Section | .text md5: 4335eb2a0fdb607d36491699e1813496 sha1: 6b0cd6f90a33b1b6289931384f18cd1ed67478cc size: 512 | |
Section | .rdata md5: ab29002ea2e7c0d91a2bde1d817ca366 sha1: ced738602e81801744fe86d982895b06b7ce5a58 size: 104960 | |
Section | .data md5: d41d8cd98f00b204e9800998ecf8427e sha1: da39a3ee5e6b4b0d3255bfef95601890afd80709 size: 0 | |
Section | .rsrc md5: bf619eac0cdf3f68d496ea9344137e8b sha1: 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 size: 512 | |
Section | .reloc md5: b3555202f7072510d3326ebc139e0b32 sha1: 6e875aab431fa0e6319b47bc45e12bac978d3584 size: 512 | |
Timestamp | 2014-04-25 13:53:08 | |
Packer | Borland Delphi 3.0 (???) | |
PEhash | 1a43470255bbd861b6601e7df35ca42f31b78ac6 | |
IMPhash | 5d907e4f447d6c7f2275c3923df49f63 | |
AV | CA (E-Trust Ino) | no_virus |
AV | Rising | no_virus |
AV | Mcafee | RDN/Generic FakeAlert |
AV | Avira (antivir) | TR/Dropper.Gen |
AV | Twister | Virus.535657@24000FF@2FF.mg |
AV | Ad-Aware | Gen:Variant.Kazy.306055 |
AV | Alwil (avast) | MalOb-HP [Cryp] |
AV | Eset (nod32) | Win32/Kryptik.BVQC |
AV | Grisoft (avg) | Crypt3.LMM |
AV | Symantec | Trojan.Gen.2 |
AV | Fortinet | W32/FakeAV.BVQC!tr |
AV | BitDefender | Gen:Variant.Kazy.306055 |
AV | K7 | Trojan ( 004967951 ) |
AV | Microsoft Security Essentials | no_virus |
AV | MicroWorld (escan) | Gen:Variant.Kazy.306055 |
AV | MalwareBytes | no_virus |
AV | Authentium | no_virus |
AV | Frisk (f-prot) | no_virus |
AV | Ikarus | Win32.SuspectCrc |
AV | Emsisoft | Gen:Variant.Kazy.306055 |
AV | Zillya! | Trojan.FakeAV.Win32.316299 |
AV | Kaspersky | Backdoor.Win32.Gulpix.vkb |
AV | Trend Micro | BKDR_PLUGX.EO |
AV | CAT (quickheal) | no_virus |
AV | VirusBlokAda (vba32) | no_virus |
AV | Padvish | no_virus |
AV | BullGuard | Gen:Variant.Kazy.306055 |
AV | Arcabit (arcavir) | Gen:Variant.Kazy.306055 |
AV | ClamAV | no_virus |
AV | Dr. Web | Trojan.DownLoader15.52543 |
AV | F-Secure | Gen:Variant.Kazy.306055 |
Runtime Details:
Screenshot | ![]() |
---|
Process
↳ C:\malware.exe
Creates File | C:\Documents and Settings\All Users\DRM\XXX\.exe |
---|---|
Creates Process | C:\Documents and Settings\All Users\DRM\XXX\.exe |
Creates Mutex | Global\mxtlmjiopofvathee |
Process
↳ C:\Documents and Settings\All Users\DRM\XXX\.exe
Creates Process | C:\WINDOWS\system32\svchost.exe |
---|---|
Creates Mutex | Global\ommdvtuqnjwvdfajh |
Creates Mutex | Global\ssmuagced |
Creates Mutex | Global\mschu |
Creates Mutex | Global\onuteywax |
Creates Mutex | Global\iqlgrgyod |
Creates Mutex | Global\qydypagscilex |
Creates Mutex | Global\aemuqqzto |
Creates Mutex | Global\ehjwk |
Creates Mutex | Global\ehkzbwkeeajtl |
Creates Mutex | Global\mxtlmjiopofvathee |
Creates Mutex | Global\ommintqmj |
Creates Mutex | Global\uimnyxkbx |
Creates Mutex | Global\wyllxlzfs |
Creates Mutex | Global\yolmkdfltbeiyknbl |
Creates Mutex | Global\cvupekdinrlasigei |
Creates Mutex | Global\ykbchaeqgqtdt |
Creates Mutex | Global\mwmjwuuwpuvcczsph |
Creates Mutex | Global\crikh |
Process
↳ C:\WINDOWS\system32\svchost.exe
Registry | HKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable ➝ NULL |
---|---|
Registry | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass ➝ 1 |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20150930060900.jpg |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20150930060850.jpg |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20150930060840.jpg |
Creates File | C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20150930060855.jpg |
Creates File | C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat |
Creates File | C:\Documents and Settings\All Users\DRM\XXX\nprqyjadoqkp |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20150930060830.jpg |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20150930060835.jpg |
Creates File | C:\Documents and Settings\Administrator\Cookies\index.dat |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20150930060845.jpg |
Creates File | PIPE\lsarpc |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20150930060825.jpg |
Creates File | \Device\Afd\Endpoint |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20150930060905.jpg |
Creates Mutex | c:!documents and settings!administrator!local settings!history!history.ie5! |
Creates Mutex | c:!documents and settings!administrator!cookies! |
Creates Mutex | c:!documents and settings!administrator!local settings!temporary internet files!content.ie5! |
Creates Mutex | Global\000000010000000000000100 |
Creates Mutex | MMMM |
Winsock DNS | 127.0.0.1 |
Network Details:
Flows UDP | 192.168.1.1:53 ➝ 192.168.1.1:53 |
---|
Raw Pcap
Strings