Analysis Date | 2016-02-09 20:59:18 |
---|---|
MD5 | 195145a755d25978423e9df4000f668e |
SHA1 | d4c0975d95a648447d5875309a3caa89219e1ede |
Static Details:
File type | PE32 executable for MS Windows (GUI) Intel 80386 32-bit | |
---|---|---|
Section | .text md5: b8417be854e565414851c9148266537a sha1: 75174623ac8fc9f5aafeb7d9b12712d3e5724671 size: 218624 | |
Section | .rdata md5: b3c7f49366549b38806a1ef9d5e151bf sha1: 3920202a44cf78eaefc27c66f5c030ba12cebc37 size: 18944 | |
Section | .data md5: 07b5472d347d42780469fb2654b7fc54 sha1: 943ae54f4818e52409fbbaf60ffd71318d966b0d size: 512 | |
Section | .reloc md5: 69e5da8ac85ba68e959ed1dce167679c sha1: ba2179a403420aed05395f192.168.1.1f11d966828 size: 40448 | |
Timestamp | 2016-01-03 14:27:21 | |
PEhash | 7c02ae9f54d47cd00270329386945a1cc4196a96 | |
IMPhash | 97dcf8b1651dcd510ef2bce5be268c87 | |
AV | CA (E-Trust Ino) | Gen:Variant.Razy.11545 |
AV | F-Secure | Gen:Variant.Razy.11545 |
AV | Dr. Web | No Virus |
AV | ClamAV | No Virus |
AV | Arcabit (arcavir) | Gen:Variant.Razy.11545 |
AV | BullGuard | Gen:Variant.Razy.11545 |
AV | CAT (quickheal) | No Virus |
AV | VirusBlokAda (vba32) | No Virus |
AV | Trend Micro | No Virus |
AV | Kaspersky | Trojan.Win32.Bayrob.hud |
AV | Zillya! | No Virus |
AV | Ikarus | Trojan.Win32.Bayrob |
AV | Frisk (f-prot) | W32/BayRob.D.gen!Eldorado |
AV | Emsisoft | Gen:Variant.Razy.11545 |
AV | Authentium | W32/BayRob.D.gen!Eldorado |
AV | MalwareBytes | No Virus |
AV | MicroWorld (escan) | Gen:Variant.Razy.11545 |
AV | Microsoft Security Essentials | TrojanSpy:Win32/Nivdort.DE |
AV | K7 | Trojan ( 004db0c61 ) |
AV | BitDefender | Gen:Variant.Razy.11545 |
AV | Fortinet | W32/Bayrob.AQ!tr |
AV | Symantec | Trojan.Bayrob!gen6 |
AV | Grisoft (avg) | Win32/Heur |
AV | Eset (nod32) | Win32/Bayrob.AT.gen |
AV | Alwil (avast) | Evo-gen [Susp] |
AV | Rising | No Virus |
AV | Ad-Aware | Gen:Variant.Razy.11545 |
AV | Twister | No Virus |
AV | Avira (antivir) | No Virus |
AV | Mcafee | Trojan-FHOH!195145A755D2 |
Runtime Details:
Screenshot | ![]() |
---|
Process
↳ C:\malware.exe
Creates File | C:\nhowqnkxvyav\uhmh1k4uxnliiospsp.exe |
---|---|
Creates File | C:\nhowqnkxvyav\vfxjagqro |
Creates File | C:\WINDOWS\nhowqnkxvyav\vfxjagqro |
Deletes File | C:\WINDOWS\nhowqnkxvyav\vfxjagqro |
Creates Process | C:\nhowqnkxvyav\uhmh1k4uxnliiospsp.exe |
Process
↳ C:\nhowqnkxvyav\uhmh1k4uxnliiospsp.exe
Registry | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Biometric Solutions Log Alerts PnP-X ➝ C:\nhowqnkxvyav\lmzdtxpd.exe |
---|---|
Creates File | PIPE\lsarpc |
Creates File | C:\nhowqnkxvyav\vfxjagqro |
Creates File | C:\nhowqnkxvyav\lmzdtxpd.exe |
Creates File | C:\WINDOWS\nhowqnkxvyav\vfxjagqro |
Creates File | C:\nhowqnkxvyav\zwodun |
Deletes File | C:\WINDOWS\nhowqnkxvyav\vfxjagqro |
Creates Process | C:\nhowqnkxvyav\lmzdtxpd.exe |
Creates Service | Notification Secondary Session Certificate - C:\nhowqnkxvyav\lmzdtxpd.exe |
Process
↳ C:\WINDOWS\system32\svchost.exe
Process
↳ Pid 812
Process
↳ Pid 856
Process
↳ C:\WINDOWS\System32\svchost.exe
Creates File | pipe\PCHFaultRepExecPipe |
---|
Process
↳ Pid 1212
Process
↳ C:\WINDOWS\system32\spoolsv.exe
Registry | HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\BeepEnabled ➝ NULL |
---|---|
Registry | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System\Print\TypesSupported ➝ 7 |
Registry | HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers\SymbolicLinkValue ➝ NULL |
Registry | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory ➝ C:\WINDOWS\System32\spool\PRINTERS\\x00 |
Process
↳ Pid 1872
Process
↳ Pid 1172
Process
↳ C:\nhowqnkxvyav\lmzdtxpd.exe
Creates File | pipe\net\NtControlPipe10 |
---|---|
Creates File | \Device\Afd\Endpoint |
Creates File | C:\nhowqnkxvyav\qpfjpzvh.exe |
Creates File | C:\nhowqnkxvyav\vfxjagqro |
Creates File | C:\WINDOWS\nhowqnkxvyav\vfxjagqro |
Creates File | C:\nhowqnkxvyav\hkkfmyy2tvnp |
Creates File | C:\nhowqnkxvyav\zwodun |
Deletes File | C:\WINDOWS\nhowqnkxvyav\vfxjagqro |
Creates Process | ad38cvo2edlv "c:\nhowqnkxvyav\lmzdtxpd.exe" |
Process
↳ C:\nhowqnkxvyav\lmzdtxpd.exe
Creates File | C:\nhowqnkxvyav\vfxjagqro |
---|---|
Creates File | C:\WINDOWS\nhowqnkxvyav\vfxjagqro |
Deletes File | C:\WINDOWS\nhowqnkxvyav\vfxjagqro |
Process
↳ ad38cvo2edlv "c:\nhowqnkxvyav\lmzdtxpd.exe"
Creates File | C:\nhowqnkxvyav\vfxjagqro |
---|---|
Creates File | C:\WINDOWS\nhowqnkxvyav\vfxjagqro |
Deletes File | C:\WINDOWS\nhowqnkxvyav\vfxjagqro |
Network Details:
Raw Pcap
Strings