Analysis Date2018-02-14 16:55:58
MD55f45640625fad490e1535e1011c43281
SHA1883fb3a3388b3b797d3e6a5214d670290e3c626c

Static Details:

File typePE32 executable (GUI) Intel 80386, for MS Windows
PEhash
AVArcabit (arcavir)Gen:Variant.Adware.ConvertAd.33
AVAuthentiumW32/Scar.R.gen!Eldorado
AVGrisoft (avg)Win32/Cryptor
AVAvira (antivir)TR/Kryptik.qgmpd
AVAlwil (avast)Trojan-gen
AVAlwil (avast)Win32:Trojan-gen
AVAd-AwareGen:Variant.Adware.ConvertAd.33
AVBitDefenderGen:Variant.Adware.ConvertAd.33
AVBullGuardGen:Variant.Adware.ConvertAd.33
AVClamAVNo Virus
AVDr. WebTrojan.Bayrob.1
AVEmsisoftGen:Variant.Adware.ConvertAd.33
AVMicroWorld (escan)Gen:Variant.Adware.ConvertAd.33
AVCA (E-Trust Ino)Gen:Variant.Adware.ConvertAd.33
AVFortinetW32/Bayrob.AQ!tr
AVFrisk (f-prot)W32/Scar.R.gen!Eldorado
AVF-SecureNo Virus
AVIkarusTrojan.Win32.Bayrob
AVK7Error Scanning File
AVKasperskyTrojan.Win32.Generic
AVMalwareBytesTrojan.Agent.KVTGen
AVMcafeeTrojan-FGIJ!5F45640625FA
AVMicrosoft Security EssentialsTrojanSpy:Win32/Nivdort
AVNANOTrojan.Win32.Bayrob.exywwh
AVEset (nod32)Win32/Bayrob.T
AVPadvishNo Virus
AVCAT (quickheal)TrojanSpy.Nivdort.OD4
AVRisingTrojan.Win32.Bayrod.a
AV360 SafeNo Virus
AVSUPERAntiSpywareError Scanning File
AVSymantecDownloader.Upatre!g15
AVTrend MicroNo Virus
AVTwisterW32.Toolbar.CrossRider.AE.lfcr.mg
AVVirusBlokAda (vba32)No Virus
AVWindows DefenderTrojanSpy:Win32/Nivdort
AVZillya!Error Scanning File

Runtime Details:

Screenshot

Process
↳ C:\Windows\System32\lsass.exe

Process
↳ C:\Users\THX1138\AppData\Local\Temp\883fb3a3388b3b797d3e6a5214d670290e3c626c.exe

Network Details:


Raw Pcap

Strings