Analysis Date | 2016-02-08 15:14:36 |
---|---|
MD5 | b233d67445791c30868cc1795fadc6c7 |
SHA1 | 6c0f6955928df0cbbda830e3bec2960670316804 |
Static Details:
File type | PE32 executable for MS Windows (GUI) Intel 80386 32-bit | |
---|---|---|
Section | .text md5: 4c52f15e8ba74731fc0092dbe75315d0 sha1: bf3b500da971ed00260ac3fb17264e8b6652fcfe size: 217088 | |
Section | .rdata md5: 7b89ad4ee2618a877c314347f682f5fc sha1: eaeab43899366c6eb0d1dd49279edae80cff6d04 size: 18944 | |
Section | .data md5: 07b5472d347d42780469fb2654b7fc54 sha1: 943ae54f4818e52409fbbaf60ffd71318d966b0d size: 512 | |
Section | .reloc md5: 959d85e50bffb49b522c1ed804e491c4 sha1: 6a21b28238bd06f11d6131c701e56b3e803f60b6 size: 40960 | |
Timestamp | 2016-01-03 13:47:46 | |
PEhash | 8a8e8cd28559a390d4fe83a377662dbd69d6314a | |
IMPhash | 81df9c9efcd8bfadf6ff4c2907fd8a04 | |
AV | CA (E-Trust Ino) | Gen:Variant.Razy.12226 |
AV | Rising | No Virus |
AV | Mcafee | Trojan-FHOH!B233D6744579 |
AV | Avira (antivir) | TR/Crypt.Xpack.444040 |
AV | Twister | No Virus |
AV | Ad-Aware | Gen:Variant.Razy.12226 |
AV | Alwil (avast) | Win32:Malware-gen |
AV | Eset (nod32) | Win32/Bayrob.AT.gen |
AV | Grisoft (avg) | Win32/Heur |
AV | Symantec | Trojan.Bayrob!gen6 |
AV | Fortinet | W32/Bayrob.AQ!tr |
AV | BitDefender | Gen:Variant.Razy.12226 |
AV | K7 | Trojan ( 004db0c61 ) |
AV | Microsoft Security Essentials | TrojanSpy:Win32/Nivdort.DD |
AV | MicroWorld (escan) | Gen:Variant.Razy.12226 |
AV | MalwareBytes | No Virus |
AV | Authentium | W32/BayRob.D.gen!Eldorado |
AV | Emsisoft | Gen:Variant.Razy.12226 |
AV | Frisk (f-prot) | W32/BayRob.D.gen!Eldorado |
AV | Ikarus | Trojan.Win32.Bayrob |
AV | Zillya! | Trojan.Bayrob.Win32.13308 |
AV | Kaspersky | Trojan.Win32.Bayrob.gid |
AV | Trend Micro | No Virus |
AV | VirusBlokAda (vba32) | No Virus |
AV | CAT (quickheal) | No Virus |
AV | BullGuard | Gen:Variant.Razy.12226 |
AV | Arcabit (arcavir) | Gen:Variant.Razy.12226 |
AV | ClamAV | No Virus |
AV | Dr. Web | No Virus |
AV | F-Secure | Gen:Variant.Razy.12226 |
Runtime Details:
Screenshot | ![]() |
---|
Process
↳ C:\malware.exe
Creates File | C:\dasxifbrhongxn\sxu1o6amummd |
---|---|
Creates File | C:\WINDOWS\dasxifbrhongxn\sxu1o6amummd |
Creates File | C:\dasxifbrhongxn\m4c1klbdlawmged.exe |
Deletes File | C:\WINDOWS\dasxifbrhongxn\sxu1o6amummd |
Creates Process | C:\dasxifbrhongxn\m4c1klbdlawmged.exe |
Process
↳ C:\dasxifbrhongxn\m4c1klbdlawmged.exe
Registry | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Trap Grouping DLL Brightness Studio Resolution ➝ C:\dasxifbrhongxn\atizoyix.exe |
---|---|
Creates File | C:\dasxifbrhongxn\atizoyix.exe |
Creates File | C:\dasxifbrhongxn\sxu1o6amummd |
Creates File | C:\WINDOWS\dasxifbrhongxn\sxu1o6amummd |
Creates File | C:\dasxifbrhongxn\pcnfiglme |
Creates File | PIPE\lsarpc |
Deletes File | C:\WINDOWS\dasxifbrhongxn\sxu1o6amummd |
Creates Process | C:\dasxifbrhongxn\atizoyix.exe |
Creates Service | Adaptive Manager Discovery - C:\dasxifbrhongxn\atizoyix.exe |
Process
↳ C:\WINDOWS\system32\svchost.exe
Process
↳ Pid 808
Process
↳ Pid 852
Process
↳ C:\WINDOWS\System32\svchost.exe
Creates File | C:\WINDOWS\system32\WBEM\Logs\wbemess.log |
---|
Process
↳ Pid 1208
Process
↳ C:\WINDOWS\system32\spoolsv.exe
Process
↳ Pid 1844
Process
↳ Pid 1132
Process
↳ C:\dasxifbrhongxn\atizoyix.exe
Creates File | C:\dasxifbrhongxn\oabeifsyarne.exe |
---|---|
Creates File | C:\dasxifbrhongxn\sxu1o6amummd |
Creates File | C:\WINDOWS\dasxifbrhongxn\sxu1o6amummd |
Creates File | pipe\net\NtControlPipe10 |
Creates File | C:\dasxifbrhongxn\pcnfiglme |
Creates File | \Device\Afd\Endpoint |
Creates File | C:\dasxifbrhongxn\yekwnjza |
Deletes File | C:\WINDOWS\dasxifbrhongxn\sxu1o6amummd |
Creates Process | k6dyxiun0rm8 "c:\dasxifbrhongxn\atizoyix.exe" |
Process
↳ C:\dasxifbrhongxn\atizoyix.exe
Creates File | C:\dasxifbrhongxn\sxu1o6amummd |
---|---|
Creates File | C:\WINDOWS\dasxifbrhongxn\sxu1o6amummd |
Deletes File | C:\WINDOWS\dasxifbrhongxn\sxu1o6amummd |
Process
↳ k6dyxiun0rm8 "c:\dasxifbrhongxn\atizoyix.exe"
Creates File | C:\dasxifbrhongxn\sxu1o6amummd |
---|---|
Creates File | C:\WINDOWS\dasxifbrhongxn\sxu1o6amummd |
Deletes File | C:\WINDOWS\dasxifbrhongxn\sxu1o6amummd |
Network Details:
Raw Pcap
Strings