Analysis Date2018-04-20 03:44:43
MD5b9a74ee2bd6b482cd6dc8c3ffd9c4c80
SHA1d57f976c14182bd68f389b27cb04388a13acfae0

Static Details:

AVArcabit (arcavir)Gen:Variant.Razy.11545
AVAuthentiumW32/Nivdort.F.gen!Eldorado
AVGrisoft (avg)Win32/Heur
AVAvira (antivir)TR/Nivdort.Gen2
AVAlwil (avast)Evo-gen [Susp]
AVAd-AwareGen:Variant.Razy.11545
AVBitDefenderGen:Variant.Razy.11545
AVBullGuardGen:Variant.Razy.11545
AVClamAVNo Virus
AVDr. WebTrojan.DownLoader18.45035
AVEmsisoftGen:Variant.Razy.11545
AVMicroWorld (escan)Gen:Variant.Razy.11545
AVCA (E-Trust Ino)Gen:Variant.Razy.11545
AVFortinetW32/Bayrob.AQ!tr
AVFrisk (f-prot)W32/Nivdort.F.gen!Eldorado
AVF-SecureGen:Variant.Razy.11545
AVIkarusPUA.ConvertAd
AVK7Error Scanning File
AVKasperskyTrojan.Win32.Generic
AVMalwareBytesNo Virus
AVMcafeeTrojan-FHPD!B9A74EE2BD6B
AVMicrosoft Security EssentialsTrojanSpy:Win32/Nivdort
AVNANOTrojan.Win32.Dwn.dznmfp
AVEset (nod32)Win32/Bayrob.AQ
AVPadvishNo Virus
AVCAT (quickheal)TrojanSpy.Nivdort.WR4
AVRisingNo Virus
AV360 SafeNo Virus
AVSUPERAntiSpywareError Scanning File
AVSymantecTrojan.Bayrob
AVTrend MicroNo Virus
AVTwisterNo Virus
AVVirusBlokAda (vba32)BScope.Malware-Cryptor.Msgfake
AVWindows DefenderTrojanSpy:Win32/Nivdort
AVZillya!Trojan.Bayrob.Win32.31966

Runtime Details:

Screenshot

Process
↳ C:\Windows\System32\lsass.exe

Process
↳ C:\Users\Phil\AppData\Local\Temp\d57f976c14182bd68f389b27cb04388a13acfae0.exe

Creates Mutex
Creates Mutex
Creates Mutex
Creates FileC:\Windows\vbqfbzmbxryx\qxgcxhwzleqa
Creates FileC:\vbqfbzmbxryx\qxgcxhwzleqa
Creates Filec:\Users\Phil\AppData\Local\Temp\d57f976c14182bd68f389b27cb04388a13acfae0.exe
Creates FileC:\vbqfbzmbxryx\gl5ac6fdta2ys2sna.exe

Process
↳ C:\vbqfbzmbxryx\gl5ac6fdta2ys2sna.exe

Creates Mutex
Creates Mutex
Creates Mutex
Creates FileC:\Windows\vbqfbzmbxryx\qxgcxhwzleqa
Creates FileC:\vbqfbzmbxryx\qxgcxhwzleqa
Creates FileC:\vbqfbzmbxryx\jtuuftsvcy
Creates FileC:\vbqfbzmbxryx\run

Network Details:


Raw Pcap

Strings