Analysis Date | 2016-02-03 01:26:58 |
---|---|
MD5 | 9ee803efb6ce3c8f97e184191cec5447 |
SHA1 | 8619a2541146702fdfe4e989a67736d0bab557d4 |
Static Details:
File type | PE32 executable for MS Windows (GUI) Intel 80386 32-bit | |
---|---|---|
Section | .text md5: d03296f85282b8bf5848d77b8dadc694 sha1: 1523c7a529f990644dcd782b4699a8f0c452e2a9 size: 217600 | |
Section | .rdata md5: 357c179cb39c4871c446e290d10b8431 sha1: 9d0d30af9f45293461c32a8e98269246ee4083fb size: 18944 | |
Section | .data md5: 07b5472d347d42780469fb2654b7fc54 sha1: 943ae54f4818e52409fbbaf60ffd71318d966b0d size: 512 | |
Section | .reloc md5: 5cb72d2069514f0cda116ff4e11d493c sha1: 4822f0d4462b785b57af85bc98fe5e69c74b44b7 size: 40448 | |
Timestamp | 2016-01-03 14:41:54 | |
PEhash | fb7c3b91db9969ac3a5989b4c8d62b31d138d3b3 | |
IMPhash | 9c09e92005d2bc76297ded48266d6623 | |
AV | Fortinet | W32/Bayrob.AQ!tr |
AV | MicroWorld (escan) | Gen:Variant.Kazy.784853 |
AV | F-Secure | Gen:Variant.Razy.11545 |
AV | MalwareBytes | No Virus |
AV | Mcafee | Trojan-FHOH!9EE803EFB6CE |
AV | Ikarus | Trojan.Win32.Bayrob |
AV | Trend Micro | No Virus |
AV | Dr. Web | Trojan.DownLoader19.16750 |
AV | Microsoft Security Essentials | TrojanSpy:Win32/Nivdort.CW |
AV | Authentium | W32/BayRob.D.gen!Eldorado |
AV | Grisoft (avg) | Win32/Heur |
AV | Twister | No Virus |
AV | BullGuard | Gen:Variant.Razy.11545 |
AV | Zillya! | No Virus |
AV | Frisk (f-prot) | W32/BayRob.D.gen!Eldorado |
AV | Kaspersky | Trojan.Win32.Bayrob.dqb |
AV | CAT (quickheal) | No Virus |
AV | ClamAV | No Virus |
AV | Eset (nod32) | Win32/Bayrob.AT.gen |
AV | Alwil (avast) | Win32:Malware-gen |
AV | CA (E-Trust Ino) | No Virus |
AV | BitDefender | Gen:Variant.Razy.11545 |
AV | Emsisoft | Gen:Variant.Razy.11545 |
AV | Symantec | Trojan.Bayrob!gen6 |
AV | K7 | Trojan ( 004db0c61 ) |
AV | Ad-Aware | Gen:Variant.Razy.11545 |
AV | Avira (antivir) | TR/Crypt.Xpack.440395 |
AV | Arcabit (arcavir) | Gen:Variant.Razy.11545 |
AV | VirusBlokAda (vba32) | No Virus |
AV | Rising | No Virus |
Runtime Details:
Screenshot | ![]() |
---|
Process
↳ C:\malware.exe
Creates File | C:\WINDOWS\bvrghbtuclen\rmtdseupjg |
---|---|
Creates File | C:\bvrghbtuclen\nk3we1kg4kzrewvwlwta.exe |
Creates File | C:\bvrghbtuclen\rmtdseupjg |
Deletes File | C:\WINDOWS\bvrghbtuclen\rmtdseupjg |
Creates Process | C:\bvrghbtuclen\nk3we1kg4kzrewvwlwta.exe |
Process
↳ C:\bvrghbtuclen\nk3we1kg4kzrewvwlwta.exe
Registry | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Machine Auto-Discovery Windows CNG Locator ➝ C:\bvrghbtuclen\csicsjqxzbcv.exe |
---|---|
Creates File | C:\bvrghbtuclen\csicsjqxzbcv.exe |
Creates File | C:\WINDOWS\bvrghbtuclen\rmtdseupjg |
Creates File | PIPE\lsarpc |
Creates File | C:\bvrghbtuclen\b4rvzi |
Creates File | C:\bvrghbtuclen\rmtdseupjg |
Deletes File | C:\WINDOWS\bvrghbtuclen\rmtdseupjg |
Creates Process | C:\bvrghbtuclen\csicsjqxzbcv.exe |
Creates Service | WMI Superfetch Engine - C:\bvrghbtuclen\csicsjqxzbcv.exe |
Process
↳ C:\WINDOWS\system32\svchost.exe
Process
↳ Pid 800
Process
↳ Pid 848
Process
↳ C:\WINDOWS\System32\svchost.exe
Creates File | C:\WINDOWS\system32\WBEM\Logs\wbemess.log |
---|
Process
↳ Pid 1204
Process
↳ C:\WINDOWS\system32\spoolsv.exe
Registry | HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\BeepEnabled ➝ NULL |
---|---|
Registry | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System\Print\TypesSupported ➝ 7 |
Registry | HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers\SymbolicLinkValue ➝ NULL |
Registry | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory ➝ C:\WINDOWS\System32\spool\PRINTERS\\x00 |
Process
↳ Pid 1868
Process
↳ Pid 1168
Process
↳ C:\bvrghbtuclen\csicsjqxzbcv.exe
Creates File | pipe\net\NtControlPipe10 |
---|---|
Creates File | C:\WINDOWS\bvrghbtuclen\rmtdseupjg |
Creates File | C:\bvrghbtuclen\c4nxmppsiy |
Creates File | C:\bvrghbtuclen\cigmtniilyp.exe |
Creates File | C:\bvrghbtuclen\b4rvzi |
Creates File | \Device\Afd\Endpoint |
Creates File | C:\bvrghbtuclen\rmtdseupjg |
Deletes File | C:\WINDOWS\bvrghbtuclen\rmtdseupjg |
Creates Process | frmimahcbcuz "c:\bvrghbtuclen\csicsjqxzbcv.exe" |
Process
↳ C:\bvrghbtuclen\csicsjqxzbcv.exe
Creates File | C:\WINDOWS\bvrghbtuclen\rmtdseupjg |
---|---|
Creates File | C:\bvrghbtuclen\rmtdseupjg |
Deletes File | C:\WINDOWS\bvrghbtuclen\rmtdseupjg |
Process
↳ frmimahcbcuz "c:\bvrghbtuclen\csicsjqxzbcv.exe"
Creates File | C:\WINDOWS\bvrghbtuclen\rmtdseupjg |
---|---|
Creates File | C:\bvrghbtuclen\rmtdseupjg |
Deletes File | C:\WINDOWS\bvrghbtuclen\rmtdseupjg |
Network Details:
Raw Pcap
Strings