Analysis Date | 2015-08-13 05:06:46 |
---|---|
MD5 | 2072d0d6b6e1dc3762b71b4105aff0dc |
SHA1 | b5d9a8b187e8c60eeb54d14172ddb818d6682c70 |
Static Details:
File type | PE32 executable for MS Windows (GUI) Intel 80386 32-bit | |
---|---|---|
Section | .text md5: 8248b5cf89ca7cb1d4dad2654f2db1f7 sha1: a8ed47414964505bde13c6661004ede32703e69f size: 512 | |
Section | .rdata md5: ab29002ea2e7c0d91a2bde1d817ca366 sha1: ced738602e81801744fe86d982895b06b7ce5a58 size: 104960 | |
Section | .data md5: d41d8cd98f00b204e9800998ecf8427e sha1: da39a3ee5e6b4b0d3255bfef95601890afd80709 size: 0 | |
Section | .rsrc md5: bf619eac0cdf3f68d496ea9344137e8b sha1: 5c3eb80066420002bc3dcc7ca4ab6efad7ed4ae5 size: 512 | |
Section | .reloc md5: 9a4760d3041e6a0a3311f9bebf38fab8 sha1: 43e4ab5bc19a4413dce8695f92f7e4a0480637cb size: 512 | |
Timestamp | 2014-04-25 13:59:36 | |
Packer | Borland Delphi 3.0 (???) | |
PEhash | 1a43470255bbd861b6601e7df35ca42f31b78ac6 | |
IMPhash | 5d907e4f447d6c7f2275c3923df49f63 | |
AV | CA (E-Trust Ino) | no_virus |
AV | F-Secure | Gen:Variant.Kazy.306055 |
AV | Dr. Web | Trojan.PWS.Ibank.809 |
AV | ClamAV | no_virus |
AV | Arcabit (arcavir) | Gen:Variant.Kazy.306055 |
AV | BullGuard | Gen:Variant.Kazy.306055 |
AV | Padvish | no_virus |
AV | VirusBlokAda (vba32) | no_virus |
AV | CAT (quickheal) | no_virus |
AV | Trend Micro | BKDR_PLUGX.EO |
AV | Kaspersky | Backdoor.Win32.Gulpix.alc |
AV | Zillya! | Trojan.FakeAV.Win32.316308 |
AV | Emsisoft | Gen:Variant.Kazy.306055 |
AV | Ikarus | Win32.SuspectCrc |
AV | Frisk (f-prot) | no_virus |
AV | Authentium | no_virus |
AV | MalwareBytes | Error Scanning File |
AV | MicroWorld (escan) | Gen:Variant.Kazy.306055 |
AV | Microsoft Security Essentials | no_virus |
AV | K7 | Trojan ( 004967951 ) |
AV | BitDefender | Gen:Variant.Kazy.306055 |
AV | Fortinet | W32/FakeAV.BVQC!tr |
AV | Symantec | Trojan.Gen |
AV | Grisoft (avg) | Crypt3.LMO |
AV | Eset (nod32) | Win32/Kryptik.BVQC |
AV | Alwil (avast) | MalOb-HP [Cryp] |
AV | Ad-Aware | Gen:Variant.Kazy.306055 |
AV | Twister | Virus.56576A406800100000.mg |
AV | Avira (antivir) | TR/Dropper.Gen |
AV | Mcafee | RDN/Generic FakeAlert |
AV | Rising | no_virus |
Runtime Details:
Screenshot | ![]() |
---|
Process
↳ C:\malware.exe
Creates File | C:\Documents and Settings\All Users\DRM\XXX\.exe |
---|---|
Creates Process | C:\Documents and Settings\All Users\DRM\XXX\.exe |
Creates Mutex | Global\ufkaq |
Process
↳ C:\Documents and Settings\All Users\DRM\XXX\.exe
Creates Process | C:\WINDOWS\system32\svchost.exe |
---|---|
Creates Mutex | Global\gbunwodqgillmltcd |
Creates Mutex | Global\wylurrybkdlyonkut |
Creates Mutex | Global\ommdvtuqnjwvdfajh |
Creates Mutex | Global\sodkb |
Creates Mutex | Global\yomxamirg |
Creates Mutex | Global\ssmuagced |
Creates Mutex | Global\mschu |
Creates Mutex | Global\aabhnqurdbfoh |
Creates Mutex | Global\ypuijjqib |
Creates Mutex | Global\stuxkwabijxwwaxrh |
Creates Mutex | Global\wubqw |
Creates Mutex | Global\uimnyxkbx |
Creates Mutex | Global\ufkaq |
Creates Mutex | Global\mticc |
Creates Mutex | Global\iqlpefsfveadljlia |
Creates Mutex | Global\mwmjwuuwpuvcczsph |
Creates Mutex | Global\sslavrbgy |
Creates Mutex | Global\ojkxy |
Process
↳ C:\WINDOWS\system32\svchost.exe
Registry | HKEY_CURRENT_CONFIG\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable ➝ NULL |
---|---|
Registry | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\ProxyBypass ➝ 1 |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20150813040248.jpg |
Creates File | C:\Documents and Settings\Administrator\Local Settings\History\History.IE5\index.dat |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20150813040242.jpg |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20150813040218.jpg |
Creates File | C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\index.dat |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20150813040222.jpg |
Creates File | C:\Documents and Settings\All Users\DRM\XXX\nprqyjadoqkp |
Creates File | C:\Documents and Settings\Administrator\Cookies\index.dat |
Creates File | PIPE\lsarpc |
Creates File | \Device\Afd\Endpoint |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20150813040237.jpg |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20150813040227.jpg |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20150813040212.jpg |
Creates File | C:\Documents and Settings\All Users\DRM\XXX-SCREEN\Administrator\20150813040233.jpg |
Creates Mutex | c:!documents and settings!administrator!local settings!history!history.ie5! |
Creates Mutex | c:!documents and settings!administrator!cookies! |
Creates Mutex | c:!documents and settings!administrator!local settings!temporary internet files!content.ie5! |
Creates Mutex | Global\000000010000000000000100 |
Creates Mutex | MMMM |
Winsock DNS | 127.0.0.1 |
Network Details:
Flows UDP | 192.168.1.1:53 ➝ 192.168.1.1:53 |
---|
Raw Pcap
Strings