Analysis Date2018-05-05 01:19:33
MD5f29c8040ff4be11707637e282a55b390
SHA164f7853617b8b5aca2ffc773afc67a727eded18f

Static Details:

File typePE32 executable (GUI) Intel 80386, for MS Windows
PEhash
AVArcabit (arcavir)Gen:Variant.Symmi.22722
AVAuthentiumW32/Wonton.B.gen!Eldorado
AVGrisoft (avg)Win32/Cryptor
AVAvira (antivir)TR/Nivdort.Gen2
AVAlwil (avast)Downloader-TLD [Trj]
AVAd-AwareError Scanning File
AVBitDefenderError Scanning File
AVBullGuardGen:Variant.Symmi.22722
AVClamAVNo Virus
AVDr. WebNo Virus
AVEmsisoftGen:Variant.Symmi.22722
AVMicroWorld (escan)Gen:Variant.Symmi.22722
AVCA (E-Trust Ino)Gen:Variant.Symmi.22722
AVFortinetW32/Wonton.FE!tr
AVFrisk (f-prot)W32/Wonton.B.gen!Eldorado
AVF-SecureGen:Variant.Symmi.22722
AVIkarusTrojan.FBAccountLock
AVK7Trojan ( 004cb2771 )
AVKasperskyTrojan.Win32.Generic
AVMalwareBytesTrojan.Zbot.WHE
AVMcafeeTrojan-FEMT!F29C8040FF4B
AVMicrosoft Security EssentialsTrojanSpy:Win32/Nivdort
AVNANONo Virus
AVEset (nod32)Win32/Agent.VNC
AVPadvishNo Virus
AVCAT (quickheal)Trojan.Dynamer.AC3
AVRisingNo Virus
AV360 SafeNo Virus
AVSUPERAntiSpywareNo Virus
AVSymantecDownloader.Upatre!g15
AVTrend MicroTSPY_NIVDORT.SMB
AVTwisterNo Virus
AVVirusBlokAda (vba32)BScope.Trojan.Bayrob
AVWindows DefenderTrojanSpy:Win32/Nivdort
AVZillya!No Virus

Runtime Details:

Screenshot

Process
↳ C:\Windows\System32\lsass.exe

Process
↳ C:\Users\Phil\AppData\Local\Temp\64f7853617b8b5aca2ffc773afc67a727eded18f.exe

Network Details:


Raw Pcap

Strings