Analysis Date2018-04-24 21:02:30
MD55affdb4b0a43a23587c2859c7980ac2a
SHA1fb525f6b82a3acaed655f0517efc5f4965ed1737

Static Details:

File typePE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
PEhash
AVArcabit (arcavir)No Virus
AVAuthentiumW32/Strictor.M.gen!Eldorado
AVGrisoft (avg)Error Scanning File
AVAvira (antivir)DR/Delphi.Gen4
AVAlwil (avast)Malware-gen
AVAlwil (avast)Win32:Malware-gen
AVAd-AwareNo Virus
AVBitDefenderNo Virus
AVBullGuardError Scanning File
AVClamAVError Scanning File
AVDr. WebNo Virus
AVEmsisoftNo Virus
AVMicroWorld (escan)No Virus
AVCA (E-Trust Ino)Error Scanning File
AVFortinetPossibleThreat
AVFrisk (f-prot)W32/Strictor.M.gen!Eldorado
AVF-SecureNo Virus
AVIkarusError Scanning File
AVK7Trojan ( 7000000f1 )
AVKasperskyError Scanning File
AVMalwareBytesTrojan.Agent.PFD
AVMcafeeNo Virus
AVMicrosoft Security EssentialsNo Virus
AVNANOTrojan.Win32.Delphi.dkaibg
AVEset (nod32)Win32/Packed.Molebox.G suspicious
AVPadvishNo Virus
AVCAT (quickheal)No Virus
AVRisingNo Virus
AV360 SafeNo Virus
AVSUPERAntiSpywareNo Virus
AVSymantecNo Virus
AVTrend MicroNo Virus
AVTwisterNo Virus
AVVirusBlokAda (vba32)No Virus
AVWindows DefenderNo Virus
AVZillya!Error Scanning File

Runtime Details:

Screenshot

Process
↳ C:\Windows\System32\lsass.exe

Process
↳ C:\Users\Phil\AppData\Local\Temp\fb525f6b82a3acaed655f0517efc5f4965ed1737.exe

Creates FileC:\Users\Phil\AppData\Local\Temp\fb525f6b82a3acaed655f0517efc5f4965ed1737.exe
Creates FileC:\Users\Phil\AppData\Local\Temp\FB525F6B82A3ACAED655F0517EFC5F4965ED1737.EXE
Creates FileC:\Users\Phil\AppData\Local\Temp\FB525F6B82A3ACAED655F0517EFC5F4965ED1737.EXE
Creates FileC:\Windows\Globalization\Sorting\sortdefault.nls
Creates FileC:\Users\Phil\AppData\Local\Temp\AdobeARM.log
Creates FileC:\Users\Phil\AppData\Local\Temp\AdobeSFX.log
Creates FileC:\Users\Phil\AppData\Local\Temp\DD_VCREDIST_AMD64_20180305201021.LOG
Creates FileC:\Users\Phil\AppData\Local\Temp\DD_VCREDIST_AMD64_20180305201021_0_VCRUNTIMEMINIMUM_X64.LOG
Creates FileC:\Users\Phil\AppData\Local\Temp\DD_VCREDIST_AMD64_20180305201021_1_VCRUNTIMEADDITIONAL_X64.LOG
Creates FileC:\Users\Phil\AppData\Local\Temp\DD_VCREDIST_AMD64_20180305201037.LOG
Creates FileC:\Users\Phil\AppData\Local\Temp\DD_VCREDIST_AMD64_20180305201037_000_VCRUNTIMEMINIMUM_X64.LOG
Creates FileC:\Users\Phil\AppData\Local\Temp\DD_VCREDIST_AMD64_20180305201037_001_VCRUNTIMEADDITIONAL_X64.LOG
Creates FileC:\Users\Phil\AppData\Local\Temp\FXSAPIDEBUGLOGFILE.TXT
Creates FileC:\Users\Phil\AppData\Local\Temp\JAVA_INSTALL.LOG
Creates FileC:\Users\Phil\AppData\Local\Temp\JAVA_INSTALL_REG.LOG
Creates FileC:\Users\Phil\AppData\Local\Temp\jusched.log
Creates FileC:\Users\Phil\AppData\Local\Temp\Phil.bmp
Creates FileC:\Users\Phil\AppData\Local\Temp\wmsetup.log

Process
↳ C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe

Process
↳ C:\Program Files (x86)\Adobe\Reader 10.0\Reader\wow_helper.exe

Network Details:


Raw Pcap
0x00000000 (00000)   47455420 2f6e6373 692e7478 74204854   GET /ncsi.txt HT
0x00000010 (00016)   54502f31 2e310d0a 436f6e6e 65637469   TP/1.1..Connecti
0x00000020 (00032)   6f6e3a20 436c6f73 650d0a55 7365722d   on: Close..User-
0x00000030 (00048)   4167656e 743a204d 6963726f 736f6674   Agent: Microsoft
0x00000040 (00064)   204e4353 490d0a48 6f73743a 20777777    NCSI..Host: www
0x00000050 (00080)   2e6d7366 746e6373 692e636f 6d0d0a0d   .msftncsi.com...
0x00000060 (00096)   0a                                    .


Strings