Analysis Date | 2016-02-09 21:51:47 |
---|---|
MD5 | 69ca2bec571f1a1515000681283ef079 |
SHA1 | d70dd37cdbfcbc648f228e619deabe572a0f7da6 |
Static Details:
File type | PE32 executable for MS Windows (GUI) Intel 80386 32-bit | |
---|---|---|
Section | .text md5: c814a56e44b6219e7ec4bc154841090a sha1: a8dd7557772ef7f741b71cf58a9b5f691d155d8f size: 261120 | |
Section | .rdata md5: 614a754cd10d8257e5b12ead6e700fe8 sha1: ec009b8e74146d5779e16bb29122f9574367be68 size: 43520 | |
Section | .data md5: 28acce6cfa592fffedd52916f6366ddb sha1: fd885ce8fbbf9788839871dd0af723b7c6bba0e9 size: 1536 | |
Section | .reloc md5: 9e6627da3830c0476a8b2d196539c85a sha1: 10c1998fce3df3ba633e61256ddad200195e3abc size: 51712 | |
Timestamp | 2015-12-23 05:00:45 | |
Packer | Borland Delphi 3.0 (???) | |
PEhash | 81d5ca0864f8cba8986bdda17458a687bba1c5b7 | |
IMPhash | a1e864ac53df0658702f62f602cc8631 | |
AV | CA (E-Trust Ino) | Gen:Variant.Razy.11545 |
AV | Rising | No Virus |
AV | Mcafee | Trojan-FHPD!69CA2BEC571F |
AV | Avira (antivir) | TR/Crypt.Xpack.444700 |
AV | Twister | No Virus |
AV | Ad-Aware | Gen:Variant.Razy.11545 |
AV | Alwil (avast) | Win32:Malware-gen |
AV | Eset (nod32) | Win32/Bayrob.AQ |
AV | Grisoft (avg) | Generic37.QFY |
AV | Symantec | Trojan.Bayrob!gen6 |
AV | Fortinet | W32/Bayrob.AQ!tr |
AV | BitDefender | Gen:Variant.Razy.11545 |
AV | K7 | Trojan ( 004db0c61 ) |
AV | Microsoft Security Essentials | TrojanSpy:Win32/Nivdort.CW |
AV | MicroWorld (escan) | Gen:Variant.Razy.11545 |
AV | MalwareBytes | No Virus |
AV | Authentium | W32/Nivdort.F.gen!Eldorado |
AV | Emsisoft | Gen:Variant.Razy.11545 |
AV | Frisk (f-prot) | W32/Nivdort.F.gen!Eldorado |
AV | Ikarus | Trojan.Win32.Bayrob |
AV | Zillya! | No Virus |
AV | Kaspersky | Trojan.Win32.Generic |
AV | Trend Micro | No Virus |
AV | VirusBlokAda (vba32) | BScope.Malware-Cryptor.Msgfake |
AV | CAT (quickheal) | No Virus |
AV | BullGuard | Gen:Variant.Razy.11545 |
AV | Arcabit (arcavir) | Gen:Variant.Razy.11545 |
AV | ClamAV | No Virus |
AV | Dr. Web | Trojan.DownLoader18.46251 |
AV | F-Secure | Gen:Variant.Razy.11545 |
Runtime Details:
Screenshot | ![]() |
---|
Process
↳ C:\malware.exe
Creates File | C:\boysctnqmxlwjz\hhdcsoiqj7ik |
---|---|
Creates File | C:\WINDOWS\boysctnqmxlwjz\hhdcsoiqj7ik |
Creates File | C:\boysctnqmxlwjz\xb3wb1kosxjmeafuwl.exe |
Deletes File | C:\WINDOWS\boysctnqmxlwjz\hhdcsoiqj7ik |
Creates Process | C:\boysctnqmxlwjz\xb3wb1kosxjmeafuwl.exe |
Process
↳ C:\boysctnqmxlwjz\xb3wb1kosxjmeafuwl.exe
Registry | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Acquisition Group Reports RPC Service ➝ C:\boysctnqmxlwjz\njcrgct.exe |
---|---|
Creates File | C:\boysctnqmxlwjz\njcrgct.exe |
Creates File | C:\boysctnqmxlwjz\ccofdortlau |
Creates File | C:\boysctnqmxlwjz\hhdcsoiqj7ik |
Creates File | PIPE\lsarpc |
Creates File | C:\WINDOWS\boysctnqmxlwjz\hhdcsoiqj7ik |
Deletes File | C:\WINDOWS\boysctnqmxlwjz\hhdcsoiqj7ik |
Creates Process | C:\boysctnqmxlwjz\njcrgct.exe |
Creates Service | Base Spooler Access Installer Coordinator - C:\boysctnqmxlwjz\njcrgct.exe |
Process
↳ C:\WINDOWS\system32\svchost.exe
Process
↳ Pid 804
Process
↳ Pid 856
Process
↳ C:\WINDOWS\System32\svchost.exe
Creates File | C:\WINDOWS\system32\WBEM\Logs\wbemess.log |
---|
Process
↳ Pid 1212
Process
↳ C:\WINDOWS\system32\spoolsv.exe
Process
↳ Pid 1868
Process
↳ Pid 1184
Process
↳ C:\boysctnqmxlwjz\njcrgct.exe
Creates File | pipe\net\NtControlPipe10 |
---|---|
Creates File | C:\boysctnqmxlwjz\ccofdortlau |
Creates File | C:\boysctnqmxlwjz\hhdcsoiqj7ik |
Creates File | C:\WINDOWS\boysctnqmxlwjz\hhdcsoiqj7ik |
Creates File | \Device\Afd\Endpoint |
Creates File | C:\boysctnqmxlwjz\axapczcmbr |
Creates File | C:\boysctnqmxlwjz\nmthjgsusz.exe |
Deletes File | C:\WINDOWS\boysctnqmxlwjz\hhdcsoiqj7ik |
Creates Process | jpm2kdzvcsdo "c:\boysctnqmxlwjz\njcrgct.exe" |
Process
↳ C:\boysctnqmxlwjz\njcrgct.exe
Creates File | C:\boysctnqmxlwjz\hhdcsoiqj7ik |
---|---|
Creates File | C:\WINDOWS\boysctnqmxlwjz\hhdcsoiqj7ik |
Deletes File | C:\WINDOWS\boysctnqmxlwjz\hhdcsoiqj7ik |
Process
↳ jpm2kdzvcsdo "c:\boysctnqmxlwjz\njcrgct.exe"
Creates File | C:\boysctnqmxlwjz\hhdcsoiqj7ik |
---|---|
Creates File | C:\WINDOWS\boysctnqmxlwjz\hhdcsoiqj7ik |
Deletes File | C:\WINDOWS\boysctnqmxlwjz\hhdcsoiqj7ik |
Network Details:
Raw Pcap
Strings