Analysis Date2018-05-19 15:50:30
MD5e52deeb46b2948a2d180f0114e2bce51
SHA1d619db89d5b8645e7f21c8165d4ef95b5db16b73

Static Details:

AVArcabit (arcavir)Gen:Variant.Barys.57495
AVAuthentiumW32/Nivdort.L.gen!Eldorado
AVGrisoft (avg)Win32/Cryptor
AVAvira (antivir)TR/Nivdort.Gen2
AVAlwil (avast)Error Scanning File
AVAd-AwareGen:Variant.Barys.57495
AVBitDefenderGen:Variant.Barys.57495
AVBullGuardGen:Variant.Barys.57495
AVClamAVError Scanning File
AVDr. WebTrojan.Bayrob.57
AVEmsisoftGen:Variant.Barys.57495
AVMicroWorld (escan)Gen:Variant.Zusy.191969
AVCA (E-Trust Ino)Error Scanning File
AVFortinetW32/Bayrob.BT!tr
AVFrisk (f-prot)W32/Nivdort.L.gen!Eldorado
AVF-SecureTrojan:W32/Bayrob.F
AVIkarusError Scanning File
AVK7Trojan ( 004dc2a31 )
AVKasperskyError Scanning File
AVMalwareBytesNo Virus
AVMcafeeTrojan-FINB!E52DEEB46B29
AVMicrosoft Security EssentialsTrojanSpy:Win32/Nivdort
AVNANOTrojan.Win32.Bayrob.ecliku
AVEset (nod32)Win32/Bayrob.BS
AVPadvishNo Virus
AVCAT (quickheal)TrojanSpy.Nivdort.DR3
AVRisingNo Virus
AV360 SafeNo Virus
AVSUPERAntiSpywareNo Virus
AVSymantecTrojan.Bayrob!gen8
AVTrend MicroNo Virus
AVTwisterW32.Toolbar.CrossRider.AE.lfcr.mg
AVVirusBlokAda (vba32)SScope.Malware-Cryptor.Bayrob
AVWindows DefenderTrojanSpy:Win32/Nivdort
AVZillya!Trojan.SwizzorGen.Win32.1

Runtime Details:

Screenshot

Process
↳ C:\Windows\System32\lsass.exe

Process
↳ C:\Users\Phil\AppData\Local\Temp\d619db89d5b8645e7f21c8165d4ef95b5db16b73.exe

Creates Mutex
Creates Mutex
Creates Mutex
Creates Mutex
Creates FileC:\Windows\pdqspexzmbdfkg\k7qlfpd
Creates FileC:\pdqspexzmbdfkg\k7qlfpd
Creates Filec:\Users\Phil\AppData\Local\Temp\d619db89d5b8645e7f21c8165d4ef95b5db16b73.exe
Creates FileC:\pdqspexzmbdfkg\cko4c4gtzpy8kwov.exe

Process
↳ C:\pdqspexzmbdfkg\cko4c4gtzpy8kwov.exe

Creates Mutex
Creates Mutex
Creates Mutex
Creates Mutex
Creates FileC:\Windows\pdqspexzmbdfkg\k7qlfpd
Creates FileC:\pdqspexzmbdfkg\k7qlfpd
Creates FileC:\pdqspexzmbdfkg\qwmzjt
Creates FileC:\pdqspexzmbdfkg\run

Process
↳ C:\pdqspexzmbdfkg\jdofyuij.exe

Creates Mutex
Creates Mutex
Creates Mutex
Creates Mutex
Creates FileC:\Windows\pdqspexzmbdfkg\k7qlfpd
Creates FileC:\pdqspexzmbdfkg\k7qlfpd
Creates FileC:\pdqspexzmbdfkg\qwmzjt

Network Details:


Raw Pcap

Strings