Analysis Date2018-02-12 06:31:03
MD5274836a935628077fa517506ed534366
SHA1b4cd9c0ea659d930aa277daf20c60dc780de45af

Static Details:

File typePE32 executable (GUI) Intel 80386, for MS Windows
PEhash
AVArcabit (arcavir)Gen:Variant.Adware.Diley.1
AVAuthentiumW32/Upatre.GJ.gen!Eldorado
AVGrisoft (avg)PSW.Generic13.APFW
AVAvira (antivir)TR/Crypt.ZPACK.mppsc
AVAlwil (avast)Adware-gen [Adw]
AVAd-AwareGen:Variant.Adware.Diley.1
AVBitDefenderGen:Variant.Adware.Diley.1
AVBullGuardGen:Variant.Adware.Diley.1
AVClamAVNo Virus
AVDr. WebTrojan.Bayrob.1
AVEmsisoftGen:Variant.Adware.Diley.1
AVMicroWorld (escan)Gen:Variant.Adware.Diley.1
AVCA (E-Trust Ino)Gen:Variant.Adware.Diley.1
AVFortinetW32/Bayrob.AQ!tr
AVFrisk (f-prot)W32/Upatre.GJ.gen!Eldorado
AVF-SecureNo Virus
AVIkarusTrojan.Win32.Bayrob
AVK7Trojan ( 004da8bd1 )
AVKasperskyTrojan.Win32.Generic
AVMalwareBytesError Scanning File
AVMcafeePWS-FCCE!274836A93562
AVMicrosoft Security EssentialsTrojanSpy:Win32/Nivdort
AVNANOTrojan.Win32.Bayrob.extbwn
AVEset (nod32)Win32/Bayrob.W
AVPadvishNo Virus
AVCAT (quickheal)TrojanSpy.Nivdort.OD4
AVRisingTrojan.Win32.Bayrod.b
AV360 SafeNo Virus
AVSUPERAntiSpywareError Scanning File
AVSymantecDownloader.Upatre!g15
AVTrend MicroNo Virus
AVTwisterNo Virus
AVVirusBlokAda (vba32)No Virus
AVWindows DefenderTrojanSpy:Win32/Nivdort
AVZillya!Error Scanning File

Runtime Details:

Screenshot

Process
↳ C:\Windows\System32\lsass.exe

Process
↳ C:\Users\THX1138\AppData\Local\Temp\b4cd9c0ea659d930aa277daf20c60dc780de45af.exe

Network Details:


Raw Pcap

Strings