Analysis Date2015-12-30 12:28:32
MD57e87faed84600bbd4b28cda0a91a54cf
SHA16b3218c96da2fe82aa1d8f46d3f070655bbfe8ef

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: e706a207f405f5d7ec330beb0a3b8f1d sha1: d1e70c0c92236b93c3973a19531642ab987321d2 size: 28160
Section.rdata md5: 4963847c65e27fd5de15c1a9012d515a sha1: ad4e0d80103d79ae5209822f6621e431d79f4911 size: 14848
Section.data md5: 1832a80b0d8f9e70d581324a645d0cc7 sha1: cd57b979fd9975a9c2e076eb8e284de90a65de40 size: 8704
Section.trhdtr md5: f538e12bdb83abf6ac0917a3bf5e2498 sha1: a3542b99b2c8855d50d2c9e29f121f3da1f2f390 size: 31232
Section.rsrc md5: 5451e0d02f40243772d7013cfbebaac7 sha1: 903f3f6ecc80ed7847bea4eacf9bb9d264a03161 size: 17408
Section.reloc md5: 8362179184f5309cf8ce9856b48b1af0 sha1: 4d770dc234534b6edbf0c3d81c1797e37fc9bed9 size: 4096
Timestamp2015-10-31 15:00:09
PackerMicrosoft Visual C++ ?.?
PEhash51799e600a5386fceb1956addc7007ab3e03cd13
IMPhash87dd5c9b4d5a7a0c583ab6a9ee90f872
AVClamAVno_virus
AVMcafeeGenericR-EYN!7E87FAED8460
AVFrisk (f-prot)no_virus
AVBullGuardGen:Variant.Kazy.762151
AVMicrosoft Security EssentialsWorm:Win32/Gamarue!rfn
AVAvira (antivir)TR/Crypt.Xpack.313767
AVF-SecureGen:Variant.Kazy.762151
AVMicroWorld (escan)Gen:Variant.Kazy.762151
AVDr. WebTrojan.DownLoader17.37757
AVAlwil (avast)Dorder-E [Trj]
AVGrisoft (avg)Crypt5.ILA
AVCA (E-Trust Ino)no_virus
AVRisingno_virus
AVEmsisoftGen:Variant.Kazy.762151
AVIkarusTrojan.Win32.Crypt
AVAuthentiumW32/Trojan.RSYX-8830
AVBitDefenderGen:Variant.Kazy.762151
AVSymantecTrojan.Gen
AVK7Trojan ( 004d58e61 )
AVEset (nod32)Win32/Kryptik.ECXX
AVTrend Microno_virus
AVCAT (quickheal)Worm.Gamarue.r6
AVKasperskyBackdoor.Win32.Androm.ioky
AVTwisterno_virus
AVArcabit (arcavir)Gen:Variant.Kazy.762151
AVFortinetW32/Kryptik.EEAE!tr
AVVirusBlokAda (vba32)no_virus
AVMalwareBytesTrojan.Downloader
AVAd-AwareGen:Variant.Kazy.762151
AVZillya!no_virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

Creates ProcessC:\WINDOWS\system32\msiexec.exe

Process
↳ C:\WINDOWS\system32\msiexec.exe

RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\Explorer\TaskbarNoNotification ➝
1
RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\Policies\Explorer\Run\317606753 ➝
"C:\Documents and Settings\All Users\msvgqh.exe"\\x00
RegistryHKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\advanced\ShowSuperHidden ➝
NULL
RegistryHKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\Explorer\TaskbarNoNotification ➝
1
RegistryHKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\Windows\Load ➝
\\x00
Creates FilePIPE\lsarpc
Creates FileC:\Documents and Settings\All Users\msvgqh.exe
Creates File\Device\Afd\Endpoint
Creates FileC:\Documents and Settings\All Users\116265
Deletes FileC:\malware.exe
Winsock DNSmicrosoft.com
Winsock DNSpool.ntp.org
Winsock DNSnorth-america.pool.ntp.org
Winsock DNSafrica.pool.ntp.org
Winsock DNSoceania.pool.ntp.org
Winsock DNSasia.pool.ntp.org
Winsock DNSsouth-america.pool.ntp.org
Winsock DNSeurope.pool.ntp.org

Network Details:

DNSeurope.pool.ntp.org
Type: A
129.70.132.37
DNSeurope.pool.ntp.org
Type: A
193.190.147.153
DNSeurope.pool.ntp.org
Type: A
213.239.154.12
DNSeurope.pool.ntp.org
Type: A
46.175.224.7
DNSnorth-america.pool.ntp.org
Type: A
108.61.194.85
DNSnorth-america.pool.ntp.org
Type: A
198.55.111.50
DNSnorth-america.pool.ntp.org
Type: A
206.108.0.132
DNSnorth-america.pool.ntp.org
Type: A
216.93.242.12
DNSsouth-america.pool.ntp.org
Type: A
54.232.82.232
DNSsouth-america.pool.ntp.org
Type: A
186.103.182.15
DNSsouth-america.pool.ntp.org
Type: A
200.93.227.170
DNSsouth-america.pool.ntp.org
Type: A
201.217.3.85
DNSasia.pool.ntp.org
Type: A
52.69.228.202
DNSasia.pool.ntp.org
Type: A
128.199.84.169
DNSasia.pool.ntp.org
Type: A
157.7.154.23
DNSasia.pool.ntp.org
Type: A
202.156.0.34
DNSoceania.pool.ntp.org
Type: A
121.0.0.42
DNSoceania.pool.ntp.org
Type: A
202.22.158.31
DNSoceania.pool.ntp.org
Type: A
103.242.68.68
DNSoceania.pool.ntp.org
Type: A
121.0.0.41
DNSafrica.pool.ntp.org
Type: A
41.73.42.10
DNSafrica.pool.ntp.org
Type: A
196.41.127.42
DNSafrica.pool.ntp.org
Type: A
196.223.19.3
DNSafrica.pool.ntp.org
Type: A
197.84.150.123
DNSpool.ntp.org
Type: A
207.196.240.30
DNSpool.ntp.org
Type: A
108.61.194.85
DNSpool.ntp.org
Type: A
129.6.15.30
DNSpool.ntp.org
Type: A
204.2.134.164
DNSmicrosoft.com
Type: A
191.239.213.197
DNSmicrosoft.com
Type: A
104.43.195.251
DNSmicrosoft.com
Type: A
104.40.211.35
DNSmicrosoft.com
Type: A
23.100.122.175
DNSmicrosoft.com
Type: A
23.96.52.53
DNSexpediteddocs.com
Type: A
Flows UDP192.168.1.1:1043 ➝ 8.8.4.4:53
Flows TCP192.168.1.1:1044 ➝ 191.239.213.197:80
Flows UDP192.168.1.1:1045 ➝ 8.8.4.4:53

Raw Pcap

Strings