Report #5318 check_circle
- Creation Date: Nov. 21, 2019, 5:42 p.m.
- Last Update: Nov. 21, 2019, 6:23 p.m.
- File: 009
- Results:
Binary
DLL
False cancel
Size
132.00KB
trid
34.2% Win32 Dynamic Link Library23.4% Win32 Executable10.7% Win16/32 Executable Delphi generic10.5% OS/2 Executable10.4% Generic Win/DOS Executable
type
PE
wordsize
0
Subsystem
unknown
Hashes
md5
0e0776034e5e096704cd28cbd40cdaa3
sha1
a0a25395bcb3d5d592c49e5244ea2226801bad03
crc32
0x393e8871
sha224
b1e8093fae87749aea821d7b4ceda00f709a431b9720944782e50523
sha256
186ff276e9a955faecfd2a6d2f13681836dd07a65b16d09cd49446c413a8ef69
sha384
adee14a8f9f4c1e4be005a4227c6901c201b65445a0b27eeeb9779e7299b84d4cc8b42633bb9698c7ad4dfb9d03855ac
sha512
f0118594d11060ea50f3b15d239e66ca9793032c372f56985156b0f4640280663edfc6924dc12504e640a8469d36e270e497fed43d02afe5eb22b71ef5f2c3d6
ssdeep
3072:e1u8LBv/zUg+wxBtYhI97Q55Rt9JjHdanD1bqCD8ORGs:e1vLpUg/i67ut9enDle
Community
Google
True check_circle
HashLib
False cancel
YARA
Matches
domain, HasDebugData, contentis_base64, IsPacked, IsPE32, IsWindowsGUI
Suspicious
True check_circle
Strings
List
lehAh.pdbO.cxESENT.dllmicro.exeY^fDS{]UtI%uHint Designer Form:TsFrameAdapter adapter must be placed on the handled framemajor%minor%build%patch%2100 bDlpFQbHOPRVGAKqXWRe 1001101010101000GetForegroundWindowSetTimer9AUG7'Se#-TyKiV>*S=G.6eiS@opS42 2$2,2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2]c`sEl01 1$1(1,1014181<1@1D1H1L1P1T1\1p1t1x1|1/eIGkVrc:Microsoft~rNO.H,D$C5HTMain palette :Preserved settings :`lAIv?nPCompanyName^FN1O:Eo<hPw/M)VReIProductNameDecimal -/(,1#117HuM"Dr1Ld-Aupdate statistics :P3P,oNAdditional colors :mGtMvp1OilQN?H.VarFileInfoFileDescriptionOriginalFilenameeachinfiniteGoogleQHInternalNameEAKpndAmcEAEenaAiStringFileInfoFileVersionR6rpN-mTranslationApplication023223742392312937 33@.datapK1LAd4aimttLqaw+[DgR/&meR/&meR/&meAiF-)"orc;SOA;DH;RT>s\Green :The communityTUmD\Ad+OwapyrightBlue :doB@L.codeHbIl|Style :Arrow lengthOSG<lsHak$tI]ksdecoder not found error.ft=L-everybody usedDefine colors8923745 392044.dUPkRWr(rEM{rEmVKBevel widthcarmen logoRed :7>"1:`)Nc.LHY\-pr362388 7848 1 992 92782sliaBiO1DaIct3iaY23inFPbsWj AND jAwSinhaAfOiFRSDSU(nl.H
Foremost
Matches
0.exe, 132 KB
Suspicious
True check_circle
Heuristics
IPs
hasIPs: False cancelAllowedSuspicioushasAllowed: False cancelhasSuspicious: False cancel
URLs
AllowedhasURLs: False cancelSuspicioushasAllowed: False cancelhasSuspicious: False cancel
Files
Allowed: ADVAPI32.dll, ESENT.dll, USER32.dll, KERNEL32.dllhasFiles: True check_circleSuspicioushasAllowed: True check_circlehasSuspicious: False cancel
Binary
Sizes
RVARVA: 16Suspicious: False cancelCodeSize: 0Suspicious: True check_circleImageAddress: 4194304Suspicious: False cancelStackStack: 4096Suspicious: False cancelHeadersHeaders: 4096Suspicious: False cancelSuspicious: False cancel
Symbols
NumberNumber: 0Suspicious: True check_circlePointerPointer: 0Suspicious: True check_circleDirectoriesNumber: 16Suspicious: False cancel
Checksum
Value: 0Suspicous: True check_circle
Sections
Allowed: sijj, .mr, .data, code, .crt, .code, j, .relocSuspicioushasAllowed: True check_circlehasSections: True check_circlehasSuspicious: False cancel
Versions
OSVersion: 6Suspicious: False cancelImageVersion: True check_circleSuspicious: 6LinkerVersion: 14.0Suspicious: False cancelSubsystemVersion: 5.0Suspicious: False cancelSuspicious: False cancel
EntryPoint
Address: 13200Suspicious: False cancel
Anomalies
Anomalies: The Debug TimeDateStamp(s) and the file header TimeDateStamp do not match., The header checksum and the calculated checksum do not match.hasAnomalies: True check_circle
Libraries
Allowed: advapi32.dll, esent.dll, user32.dll, kernel32.dllhasLibs: True check_circleSuspicioushasAllowed: True check_circlehasSuspicious: False cancel
Timestamp
Past: True check_circleValid: True check_circleValue: 1995-11-13 21:08:05Future: False cancel
Compilation
Packed: False cancelMissing: True check_circlePackersCompiled: False cancelCompilers
Obfuscation
XOR: False cancelFuzzing: False cancel
PEDetector
Matches
None
Suspicious
False cancel
Disassembly
hasTricks
False cancel
Tricks
AVclass
emotet
1
VirusTotal
md5
0e0776034e5e096704cd28cbd40cdaa3
sha1
a0a25395bcb3d5d592c49e5244ea2226801bad03
SCANS (DETECTION RATE = 89.86%)
AVG
result: Win32:Trojan-genupdate: 20191117version: 18.4.3895.0detected: True check_circle
CMC
update: 20190321version: 1.1.0.977detected: False cancel
MAX
result: malware (ai score=100)update: 20191117version: 2019.9.16.1detected: True check_circle
APEX
result: Maliciousupdate: 20191116version: 5.86detected: True check_circle
K7GW
result: Trojan ( 0053b3091 )update: 20191117version: 11.78.32579detected: True check_circle
ALYac
result: Trojan.Agent.Emotetupdate: 20191117version: 1.1.1.5detected: True check_circle
Avast
result: Win32:Trojan-genupdate: 20191117version: 18.4.3895.0detected: True check_circle
Avira
result: TR/AD.Emotet.zdeunupdate: 20191117version: 8.3.3.8detected: True check_circle
Baidu
update: 20190318version: 1.0.0.2detected: False cancel
Cyren
result: W32/Emotet.JI.gen!Eldoradoupdate: 20191117version: 6.2.2.2detected: True check_circle
DrWeb
result: Trojan.EmotetENT.304update: 20191117version: 7.0.41.7240detected: True check_circle
GData
result: Win32.Trojan-Spy.Emotet.8QV6X9update: 20191117version: A:25.24008B:26.16683detected: True check_circle
Panda
result: Trj/WLT.Eupdate: 20191117version: 4.6.4.2detected: True check_circle
VBA32
result: BScope.Trojan.Emotetupdate: 20191116version: 4.2.0detected: True check_circle
VIPRE
result: Trojan.Win32.Generic!BTupdate: 20191117version: 79394detected: True check_circle
Zoner
result: Trojan.Win32.75135update: 20191116version: 1.0.0.1detected: True check_circle
ClamAV
result: Win.Trojan.Emotet-6758463-0update: 20191117version: 0.102.0.0detected: True check_circle
Comodo
result: Malware@#33nzc6n97w6gtupdate: 20191117version: 31733detected: True check_circle
F-Prot
result: W32/Emotet.JI.gen!Eldoradoupdate: 20191117version: 4.7.1.166detected: True check_circle
Ikarus
result: Trojan.Win32.Emotetupdate: 20191117version: 0.1.5.2detected: True check_circle
McAfee
result: Generic.bukupdate: 20191113version: 6.0.6.653detected: True check_circle
Rising
result: Trojan.Kryptik!1.B4D6 (KTSE)update: 20191117version: 25.0.0.24detected: True check_circle
Sophos
result: Mal/EncPk-ANYupdate: 20191117version: 4.98.0detected: True check_circle
Yandex
result: Trojan.PWS.Emotet!update: 20191114version: 5.5.2.24detected: True check_circle
Zillya
result: Trojan.Emotet.Win32.7537update: 20191115version: 2.0.0.3952detected: True check_circle
Acronis
result: suspiciousupdate: 20191113version: 1.1.1.58detected: True check_circle
Alibaba
result: Trojan:Win32/Emotet.6504311eupdate: 20190527version: 0.3.0.5detected: True check_circle
Arcabit
result: Trojan.Autoruns.GenericS.D1DECFF2update: 20191117version: 1.0.0.861detected: True check_circle
Cylance
result: Unsafeupdate: 20191117version: 2.3.1.101detected: True check_circle
Endgame
result: malicious (high confidence)update: 20190918version: 3.0.15detected: True check_circle
FireEye
result: Generic.mg.0e0776034e5e0967update: 20191117version: 29.7.0.0detected: True check_circle
TACHYON
result: Trojan/W32.Emotet.135168.Gupdate: 20191117version: 2019-11-17.02detected: True check_circle
Tencent
update: 20191117version: 1.0.0.1detected: False cancel
ViRobot
result: Trojan.Win32.Agent.135168.EWupdate: 20191117version: 2014.3.20.0detected: True check_circle
Webroot
result: W32.Trojan.Emotetupdate: 20191117version: 1.0.0.403detected: True check_circle
Ad-Aware
result: Trojan.Autoruns.GenericKDS.31379442update: 20191117version: 3.0.5.370detected: True check_circle
AegisLab
result: Trojan.Win32.Emotet.4!cupdate: 20191116version: 4.2detected: True check_circle
Emsisoft
result: Trojan.Emotet (A)update: 20191031version: 2018.12.0.1641detected: True check_circle
F-Secure
result: Trojan.TR/AD.Emotet.zdeunupdate: 20191117version: 12.0.86.52detected: True check_circle
Fortinet
result: W32/Emotet.BN!trupdate: 20191117version: 5.4.247.0detected: True check_circle
Invincea
result: heuristicupdate: 20190904version: 6.3.6.26157detected: True check_circle
Jiangmin
result: Trojan.Banker.Emotet.ecwupdate: 20191117version: 16.0.100detected: True check_circle
Kingsoft
update: 20191117version: 2013.8.14.323detected: False cancel
Paloalto
update: 20191117version: 1.0detected: False cancel
Symantec
result: Trojan.Emotetupdate: 20191116version: 1.11.0.0detected: True check_circle
Trapmine
result: malicious.high.ml.scoreupdate: 20190826version: 3.1.81.800detected: True check_circle
AhnLab-V3
result: Trojan/Win32.Emotet.R246431update: 20191117version: 3.16.4.25692detected: True check_circle
Antiy-AVL
result: Trojan[Banker]/Win32.Emotetupdate: 20191117version: 3.0.0.1detected: True check_circle
Kaspersky
result: Trojan-Banker.Win32.Emotet.brjmupdate: 20191117version: 15.0.1.13detected: True check_circle
Microsoft
result: Trojan:Win32/Emotet.BU!bitupdate: 20191117version: 1.1.16500.1detected: True check_circle
Qihoo-360
result: HEUR/QVM20.1.63CA.Malware.Genupdate: 20191117version: 1.0.0.1120detected: True check_circle
ZoneAlarm
result: Trojan-Banker.Win32.Emotet.brjmupdate: 20191117version: 1.0detected: True check_circle
Cybereason
result: malicious.34e5e0update: 20190616version: 1.2.449detected: True check_circle
ESET-NOD32
result: Win32/Emotet.BNupdate: 20191117version: 20361detected: True check_circle
TrendMicro
result: TSPY_EMOTET.THAABGAHupdate: 20191117version: 11.0.0.1006detected: True check_circle
BitDefender
result: Trojan.Autoruns.GenericKDS.31379442update: 20191117version: 7.2detected: True check_circle
CrowdStrike
result: win/malicious_confidence_100% (W)update: 20190702version: 1.0detected: True check_circle
K7AntiVirus
result: Trojan ( 0053b3091 )update: 20191117version: 11.78.32579detected: True check_circle
SentinelOne
result: DFI - Malicious PEupdate: 20191115version: 1.0.31.33detected: True check_circle
Avast-Mobile
update: 20191115version: 191114-10detected: False cancel
Malwarebytes
result: Trojan.Emotetupdate: 20191117version: 2.1.1.1115detected: True check_circle
TotalDefense
update: 20191117version: 37.1.62.1detected: False cancel
CAT-QuickHeal
result: Trojan.Fuerboosupdate: 20191116version: 14.00detected: True check_circle
NANO-Antivirus
result: Trojan.Win32.EmotetENT.fknjtoupdate: 20191117version: 1.0.134.24859detected: True check_circle
BitDefenderTheta
result: Gen:Trojan.Heur2.PPBB.3.0.iG0@b8UnT!kG5cupdate: 20191113version: 7.2.37796.0detected: True check_circle
MicroWorld-eScan
result: Trojan.Autoruns.GenericKDS.31379442update: 20191117version: 14.0.297.0detected: True check_circle
SUPERAntiSpyware
result: Trojan.Agent/Gen-Emotetupdate: 20191115version: 5.6.0.1032detected: True check_circle
McAfee-GW-Edition
result: BehavesLike.Win32.Emotet.ccupdate: 20191117version: v2017.3010detected: True check_circle
TrendMicro-HouseCall
result: TSPY_EMOTET.THAABGAHupdate: 20191117version: 10.0.0.1040detected: True check_circle
total
69
sha256
186ff276e9a955faecfd2a6d2f13681836dd07a65b16d09cd49446c413a8ef69
scan_id
186ff276e9a955faecfd2a6d2f13681836dd07a65b16d09cd49446c413a8ef69-1573985642
resource
0e0776034e5e096704cd28cbd40cdaa3
positives
62
scan_date
2019-11-17 10:14:02
verbose_msg
Scan finished, information embedded
response_code
1
File
Trace
21/11/2019 - 17:45:43.575 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\kernel32.dll | |
21/11/2019 - 17:45:43.575 | Open | 1480 | C:\malware.exe | C:\Windows\Globalization\Sorting\SortDefault.nls | |
21/11/2019 - 17:45:43.590 | Unknown | 1480 | C:\malware.exe | C:\Windows\Globalization\Sorting\SortDefault.nls | SortDefault.nls |
21/11/2019 - 17:45:43.622 | Open | 1480 | C:\malware.exe | C:\malware.exe | |
21/11/2019 - 17:45:43.622 | Open | 1480 | C:\malware.exe | C:\malware.exe | |
21/11/2019 - 17:45:43.622 | Open | 1480 | C:\malware.exe | C:\malware.exe | |
21/11/2019 - 17:45:43.622 | Unknown | 1480 | C:\malware.exe | C:\malware.exe | |
21/11/2019 - 17:45:43.622 | Unknown | 1480 | C:\malware.exe | C:\malware.exe | |
21/11/2019 - 17:45:43.622 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\apphelp.dll | |
21/11/2019 - 17:45:43.622 | Open | 1480 | C:\malware.exe | C:\Windows\SysWOW64\apphelp.dll | |
21/11/2019 - 17:45:43.622 | Open | 2076 | C:\malware.exe | C:\Windows\Prefetch\MALWARE.EXE-20920919.pf | |
21/11/2019 - 17:45:43.622 | Open | 2076 | C:\malware.exe | C:\Windows | |
21/11/2019 - 17:45:43.622 | Open | 2076 | C:\malware.exe | C:\Windows\System32\wow64.dll | |
21/11/2019 - 17:45:43.622 | Open | 2076 | C:\malware.exe | C:\Windows\System32\wow64.dll | |
21/11/2019 - 17:45:43.622 | Open | 2076 | C:\malware.exe | C:\Windows\System32\wow64win.dll | |
21/11/2019 - 17:45:43.622 | Open | 2076 | C:\malware.exe | C:\Windows\System32\wow64win.dll | |
21/11/2019 - 17:45:43.622 | Open | 2076 | C:\malware.exe | C:\Windows\System32\wow64cpu.dll | |
21/11/2019 - 17:45:43.622 | Open | 2076 | C:\malware.exe | C:\Windows\System32\wow64cpu.dll | |
21/11/2019 - 17:45:43.622 | Open | 2076 | C:\malware.exe | C:\Windows\System32\wow64log.dll | |
21/11/2019 - 17:45:43.622 | Open | 2076 | C:\malware.exe | C:\Windows | |
21/11/2019 - 17:45:43.622 | Unknown | 2076 | C:\malware.exe | C:\Windows | |
21/11/2019 - 17:45:43.622 | Open | 2076 | C:\malware.exe | C:\Monitor | |
21/11/2019 - 17:45:43.622 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\sechost.dll | |
21/11/2019 - 17:45:43.622 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\sechost.dll | |
21/11/2019 - 17:45:43.622 | Open | 2076 | C:\malware.exe | C:\ESENT.dll | |
21/11/2019 - 17:45:43.622 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\esent.dll | |
21/11/2019 - 17:45:43.622 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\esent.dll | |
21/11/2019 - 17:45:43.622 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\imm32.dll | |
21/11/2019 - 17:45:43.622 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\imm32.dll | |
21/11/2019 - 17:45:43.622 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\imm32.dll | |
21/11/2019 - 17:45:43.622 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\imm32.dll | |
21/11/2019 - 17:45:43.622 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\imm32.dll | |
21/11/2019 - 17:45:43.622 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\imm32.dll | |
21/11/2019 - 17:45:43.622 | Unknown | 1480 | C:\malware.exe | C:\malware.exe | |
21/11/2019 - 17:45:43.637 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\kernel32.dll | |
21/11/2019 - 17:45:43.637 | Open | 2076 | C:\malware.exe | C:\Windows\Globalization\Sorting\SortDefault.nls | |
21/11/2019 - 17:45:43.637 | Unknown | 2076 | C:\malware.exe | C:\Windows\Globalization\Sorting\SortDefault.nls | SortDefault.nls |
21/11/2019 - 17:45:43.637 | Open | 2076 | C:\malware.exe | C:\ | |
21/11/2019 - 17:45:43.637 | Unknown | 2076 | C:\malware.exe | C:\ | |
21/11/2019 - 17:45:43.637 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\uxtheme.dll | |
21/11/2019 - 17:45:43.637 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\uxtheme.dll | |
21/11/2019 - 17:45:43.653 | Unknown | 1480 | C:\malware.exe | C:\Windows | |
21/11/2019 - 17:45:43.653 | Unknown | 1480 | C:\malware.exe | C:\Monitor | |
21/11/2019 - 17:45:43.731 | Open | 2076 | C:\malware.exe | C:\dwmapi.dll | |
21/11/2019 - 17:45:43.731 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\dwmapi.dll | |
21/11/2019 - 17:45:43.731 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\dwmapi.dll | |
21/11/2019 - 17:45:49.731 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64 | |
21/11/2019 - 17:45:49.731 | Unknown | 2076 | C:\malware.exe | C:\Windows\SysWOW64 | |
21/11/2019 - 17:45:49.731 | Open | 2076 | C:\malware.exe | C:\malware.exe | |
21/11/2019 - 17:45:49.731 | Unknown | 2076 | C:\malware.exe | C:\malware.exe | |
21/11/2019 - 17:45:49.731 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\bundlebuild.exe | |
21/11/2019 - 17:45:49.731 | Open | 2076 | C:\malware.exe | C:\ | |
21/11/2019 - 17:45:49.731 | Unknown | 2076 | C:\malware.exe | C:\ | |
21/11/2019 - 17:45:49.731 | Open | 2076 | C:\malware.exe | C:\Windows | |
21/11/2019 - 17:45:49.731 | Unknown | 2076 | C:\malware.exe | C:\Windows | |
21/11/2019 - 17:45:49.731 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64 | |
21/11/2019 - 17:45:49.731 | Unknown | 2076 | C:\malware.exe | C:\Windows\SysWOW64 | |
21/11/2019 - 17:45:49.731 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\rpcss.dll | |
21/11/2019 - 17:45:49.731 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\rpcss.dll | |
21/11/2019 - 17:45:49.731 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\shell32.dll | |
21/11/2019 - 17:45:49.731 | Open | 2076 | C:\malware.exe | C:\malware.exe.Local | |
21/11/2019 - 17:45:49.731 | Open | 2076 | C:\malware.exe | C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d | |
21/11/2019 - 17:45:49.731 | Unknown | 2076 | C:\malware.exe | C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d | |
21/11/2019 - 17:45:49.731 | Open | 2076 | C:\malware.exe | C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d | |
21/11/2019 - 17:45:49.731 | Open | 2076 | C:\malware.exe | C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d\comctl32.dll | |
21/11/2019 - 17:45:49.731 | Open | 2076 | C:\malware.exe | C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d\comctl32.dll | |
21/11/2019 - 17:45:49.731 | Open | 2076 | C:\malware.exe | C:\Windows\WindowsShell.Manifest | |
21/11/2019 - 17:45:49.731 | Unknown | 2076 | C:\malware.exe | C:\Windows\WindowsShell.Manifest | WindowsShell.Manifest |
21/11/2019 - 17:45:49.731 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\dsmcaching.exe | |
21/11/2019 - 17:45:49.731 | Open | 2076 | C:\malware.exe | C:\ | |
21/11/2019 - 17:45:49.731 | Unknown | 2076 | C:\malware.exe | C:\ | |
21/11/2019 - 17:45:49.731 | Open | 2076 | C:\malware.exe | C:\Monitor | |
21/11/2019 - 17:45:49.731 | Unknown | 2076 | C:\malware.exe | C:\Monitor | |
21/11/2019 - 17:45:49.731 | Open | 2076 | C:\malware.exe | C:\ | |
21/11/2019 - 17:45:49.731 | Unknown | 2076 | C:\malware.exe | C:\ | |
21/11/2019 - 17:45:49.731 | Open | 2076 | C:\malware.exe | C:\ | |
21/11/2019 - 17:45:49.731 | Unknown | 2076 | C:\malware.exe | C:\ | |
21/11/2019 - 17:45:49.731 | Open | 2076 | C:\malware.exe | C:\Windows | |
21/11/2019 - 17:45:49.731 | Unknown | 2076 | C:\malware.exe | C:\Windows | |
21/11/2019 - 17:45:49.731 | Open | 2076 | C:\malware.exe | C:\ | |
21/11/2019 - 17:45:49.731 | Unknown | 2076 | C:\malware.exe | C:\ | |
21/11/2019 - 17:45:49.731 | Open | 2076 | C:\malware.exe | C:\Monitor | |
21/11/2019 - 17:45:49.731 | Unknown | 2076 | C:\malware.exe | C:\Monitor | |
21/11/2019 - 17:45:49.731 | Open | 2076 | C:\malware.exe | C:\Monitor\Malware | |
21/11/2019 - 17:45:49.731 | Unknown | 2076 | C:\malware.exe | C:\Monitor\Malware | |
21/11/2019 - 17:45:49.747 | Open | 2076 | C:\malware.exe | C:\PROPSYS.dll | |
21/11/2019 - 17:45:49.747 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\propsys.dll | |
21/11/2019 - 17:45:49.747 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\propsys.dll | |
21/11/2019 - 17:45:49.747 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\propsys.dll | |
21/11/2019 - 17:45:49.747 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\propsys.dll | |
21/11/2019 - 17:45:49.747 | Open | 2076 | C:\malware.exe | C:\Windows\System32\propsys.dll | |
21/11/2019 - 17:45:49.747 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\propsys.dll | |
21/11/2019 - 17:45:49.747 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\propsys.dll | |
21/11/2019 - 17:45:49.747 | Open | 2076 | C:\malware.exe | C:\Windows\System32\propsys.dll | |
21/11/2019 - 17:45:49.747 | Open | 2076 | C:\malware.exe | C:\ | |
21/11/2019 - 17:45:49.747 | Unknown | 2076 | C:\malware.exe | C:\ | |
21/11/2019 - 17:45:49.747 | Open | 2076 | C:\malware.exe | C:\malware.exe | |
21/11/2019 - 17:45:49.747 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64 | |
21/11/2019 - 17:45:49.747 | Unknown | 2076 | C:\malware.exe | C:\malware.exe | |
21/11/2019 - 17:45:49.747 | Unknown | 2076 | C:\malware.exe | C:\Windows\SysWOW64 | |
21/11/2019 - 17:45:49.747 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64 | |
21/11/2019 - 17:45:49.747 | Unknown | 2076 | C:\malware.exe | C:\Windows\SysWOW64 | |
21/11/2019 - 17:45:49.747 | Open | 2076 | C:\malware.exe | C:\ntmarta.dll | |
21/11/2019 - 17:45:49.747 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\ntmarta.dll | |
21/11/2019 - 17:45:49.747 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\ntmarta.dll | |
21/11/2019 - 17:45:49.747 | Open | 2076 | C:\malware.exe | C:\Monitor\Malware | |
21/11/2019 - 17:45:49.747 | Unknown | 2076 | C:\malware.exe | C:\Monitor\Malware | |
21/11/2019 - 17:45:49.747 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64 | |
21/11/2019 - 17:45:49.747 | Unknown | 2076 | C:\malware.exe | C:\Windows\SysWOW64 | |
21/11/2019 - 17:45:49.747 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\dsmcaching.exe | |
21/11/2019 - 17:45:49.747 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64 | |
21/11/2019 - 17:45:49.762 | Unknown | 2076 | C:\malware.exe | C:\Windows\SysWOW64 | |
21/11/2019 - 17:45:49.762 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\dsmcaching.exe:Zone.Identifier | |
21/11/2019 - 17:45:49.872 | Open | 2076 | C:\malware.exe | C:\CRYPTSP.dll | |
21/11/2019 - 17:45:49.872 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\cryptsp.dll | |
21/11/2019 - 17:45:49.872 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\cryptsp.dll | |
21/11/2019 - 17:45:49.872 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\rsaenh.dll | |
21/11/2019 - 17:45:49.872 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\rsaenh.dll | |
21/11/2019 - 17:45:49.872 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\rsaenh.dll | |
21/11/2019 - 17:45:49.872 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\rsaenh.dll | |
21/11/2019 - 17:45:49.872 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\rsaenh.dll | |
21/11/2019 - 17:45:49.872 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\rsaenh.dll | |
21/11/2019 - 17:45:49.872 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\rsaenh.dll | |
21/11/2019 - 17:45:49.872 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\rsaenh.dll | |
21/11/2019 - 17:45:49.872 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\rsaenh.dll | |
21/11/2019 - 17:45:49.872 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\rsaenh.dll | |
21/11/2019 - 17:45:49.872 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\rsaenh.dll | |
21/11/2019 - 17:45:49.872 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\rsaenh.dll | |
21/11/2019 - 17:45:49.872 | Open | 2076 | C:\malware.exe | C:\RpcRtRemote.dll | |
21/11/2019 - 17:45:49.872 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\RpcRtRemote.dll | |
21/11/2019 - 17:45:49.872 | Unknown | 2076 | C:\malware.exe | C:\Windows\SysWOW64\RpcRtRemote.dll | RpcRtRemote.dll |
21/11/2019 - 17:45:49.872 | Open | 2076 | C:\malware.exe | C:\Windows\SysWOW64\RpcRtRemote.dll | |
21/11/2019 - 17:45:49.872 | Unknown | 2076 | C:\malware.exe | C:\Windows\SysWOW64\RpcRtRemote.dll | RpcRtRemote.dll |
21/11/2019 - 17:45:49.950 | Unknown | 2076 | C:\malware.exe | C:\Windows | |
21/11/2019 - 17:45:49.950 | Unknown | 2076 | C:\malware.exe | C:\Monitor | |
21/11/2019 - 17:45:49.950 | Unknown | 2076 | C:\malware.exe | C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d |
Process
Trace
21/11/2019 - 17:45:43.622 | Create | 1480 | C:\malware.exe | 2076 | C:\malware.exe |
21/11/2019 - 17:45:49.950 | Terminate | 1480 | C:\malware.exe | 2076 | C:\malware.exe |
Analysis
Reason
Finished
Status
Sucessfully Executed
Results
1
Registry
Trace
File Summary
Created
Identified: False cancel
Deleted
Identified: False cancel
Process Summary
Created
Identified: True check_circle
Deleted
Identified: True check_circle
Registry Summary
Proxy
Identified: False cancel
AutoRun
Identified: False cancel
Created
Identified: False cancel
Deleted
Identified: False cancel
Browsers
Identified: False cancel
Internet
Identified: False cancel
Loading...
DNS
Query
computer localhost arrow_forward computer gateway:50273 code dns.msftncsi.com. computer localhost arrow_forward computer gateway:59829 code dns.msftncsi.com. computer localhost arrow_forward computer gateway:50043 code dns.msftncsi.com. computer localhost arrow_forward computer gateway:DNS code dns.msftncsi.com. computer localhost arrow_forward computer gateway:49551 code dns.msftncsi.com.
Response
computer gateway:DNS arrow_forward computer localhost code dns.msftncsi.com. reply_all 131.107.255.255
TCP
Info
computer localhost:65195 arrow_forward 104.136.151.73:80computer localhost:65200 arrow_forward 105.224.170.204:80computer localhost:65194 arrow_forward 200.54.111.170:80computer localhost:65199 arrow_forward 105.224.170.204:80computer localhost:65191 arrow_forward 186.159.186.156:8080computer localhost:65192 arrow_forward 186.159.186.156:8080computer localhost:65197 arrow_forward 66.112.88.78:80computer localhost:65201 arrow_forward 190.194.71.111:443computer localhost:65193 arrow_forward 200.54.111.170:80computer localhost:65198 arrow_forward 66.112.88.78:80computer localhost:65196 arrow_forward 104.136.151.73:80
UDP
Info
computer localhost:49551 arrow_forward computer localhost:53computer localhost:55394 arrow_forward computer localhost:53computer localhost:53 arrow_forward computer localhost:59829computer localhost:53 arrow_forward computer localhost:49551computer localhost:50273 arrow_forward computer localhost:53computer localhost:53 arrow_forward computer localhost:50043computer localhost:53 arrow_forward computer localhost:50273computer localhost:50043 arrow_forward computer localhost:53computer localhost:53 arrow_forward computer localhost:55394computer localhost:59829 arrow_forward computer localhost:53computer localhost:67 arrow_forward computer localhost:68computer localhost:68 arrow_forward help_outline 255.255.255.255:67
HTTP
Info
Summary
DNS
True check_circle
TCP
True check_circle
UDP
True check_circle
HTTP
False cancel
Results
BINARY
KNN (K=3, NFS-BRMalware)
confidence: 100.00%suspicious: False cancel
Decision Tree (NFS-BRMalware)
confidence: 100.00%suspicious: False cancel
SVC (Kernel=Linear, NFS-BRMalware)
confidence: 72.50%suspicious: True check_circle
MalConv (Ember: Raw Bytes, Threshold=0.5)
confidence: 99.81%suspicious: True check_circle
Random Forest (100 estimators, NFS-BRMalware)
confidence: 65.00%suspicious: False cancel
Non-Negative MalConv (Ember: Raw Bytes, Threshold=0.35)
confidence: 59.95%suspicious: True check_circle
LightGDM (Ember: File Characteristics, Threshold=0.8336)
confidence: 100.00%suspicious: True check_circle