Report #5476 check_circle
- Creation Date: Feb. 10, 2020, 4:24 p.m.
- Last Update: Feb. 10, 2020, 5:58 p.m.
- File: 9k2vBbHr.exe
- Results:
Binary
DLL
False cancel
Size
418.52KB
trid
61.7% Win64 Executable14.7% Win32 Dynamic Link Library10.0% Win32 Executable4.5% OS/2 Executable4.4% Generic Win/DOS Executable
type
PE
wordsize
32
Subsystem
Windows CLI
Hashes
md5
dc5532e5ea9ac29014118b397d3f387b
sha1
a6bed53af015148e2f4f7c3d507b83a7b4c1e153
crc32
0x802964f3
sha224
6104800ad56b505bcbbc41028a620fb0d0776904455fbdf3dacdcf71
sha256
90b13f3aa9d4bfe5859218aef13c0da5816ba6a877ea7545e1d4c72b0271b433
sha384
883a7bda9f1cfbc4b7286ed36de61fc58be065252f3be21e2f7ceef71b3b56540ca49ef5b26130ebfee77b15dabc0557
sha512
63db9059d1dd896cfab2b48cecbac6b63b8f10c1fb22bf2d7300c51aa792521528c98acaf2a0fa01da51ff8f3ac046c660fbdb361f84276aec4ff8544341067e
ssdeep
12288:fM9Ay2i6ZZQV02Rm5O2/PDqW/WBdrisxnTO7TsLYOs:fM9Api6ZZQW2aUd2sBO7ThOs
Community
Google
False cancel
HashLib
False cancel
YARA
Matches
VC8_Microsoft_Corporation, domain, anti_dbg, HasDigitalSignature, url, IP, contentis_base64, HasOverlay, Microsoft_Visual_Cpp_8, CRC32_table, win_registry, IsConsole, CRC32_poly_Constant, win_files_operation, IsPE32, HasRichSignature, Big_Numbers0
Suspicious
True check_circle
Strings
List
http://sv.symcb.com/sv.crt0http://sv.symcb.com/sv.crl0fhttps://d.symcb.com/rpa0https://d.symcb.com/cps0%http://s1.symcb.com/pca3-g5.crl0+http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(.http://crl.thawte.com/ThawteTimestampingCA.crl0+http://ts-aia.ws.symantec.com/tss-ca-g2.cer0<http://www.symauth.com/rpa00http://www.symauth.com/cps0(Executor.exec():msiexec.exec:/re/workspace/8-2-build-windows-i586-cygwin/jdk8u131/8869/install/src/windows/common/Resources.cpphttp://sv.symcd.com0&http://s2.symcb.com0c:/re/workspace/8-2-build-windows-i586-cygwin/jdk8u131/8869/install/src/windows/common/Registry.cppc:/re/workspace/8-2-build-windows-i586-cygwin/jdk8u131/8869/install/src/windows/au/jaureg/jaureg.cppc:/re/workspace/8-2-build-windows-i586-cygwin/jdk8u131/8869/install/src/windows/common/Bundle.cppc:/re/workspace/8-2-build-windows-i586-cygwin/jdk8u131/8869/install/src/windows/common/SysInfo.cppc:/re/workspace/8-2-build-windows-i586-cygwin/jdk8u131/8869/install/src/windows/common/unzip/unzip.cppc:/re/workspace/8-2-build-windows-i586-cygwin/jdk8u131/8869/install/src/windows/common/Jep223UpgradeCodeInstalledJavaTracker.cppc:/re/workspace/8-2-build-windows-i586-cygwin/jdk8u131/8869/install/src/windows/common/KnownProductCodeInstalledJavaTracker.cppc:/re/workspace/8-2-build-windows-i586-cygwin/jdk8u131/8869/install/src/windows/common/Guid.cppc:/re/workspace/8-2-build-windows-i586-cygwin/jdk8u131/8869/install/src/windows/common/Executor.cppc:/re/workspace/8-2-build-windows-i586-cygwin/jdk8u131/8869/install/src/common/share/tstrings.cppc:/re/workspace/8-2-build-windows-i586-cygwin/jdk8u131/8869/install/src/windows/common/FileUtils.cppc:/re/workspace/8-2-build-windows-i586-cygwin/jdk8u131/8869/install/src/windows/common/MsiUtils.cppc:/re/workspace/8-2-build-windows-i586-cygwin/jdk8u131/8869/install/src/windows/common/Dll.cppc:/re/workspace/8-2-build-windows-i586-cygwin/jdk8u131/8869/install/src/common/windows/WinAutoHandle.cppc:/re/workspace/8-2-build-windows-i586-cygwin/jdk8u131/8869/install/src/windows/common/JavaEnvironment.cppc:/re/workspace/8-2-build-windows-i586-cygwin/jdk8u131/8869/install/src/common/windows/WinErrorHandling.cppc:/re/workspace/8-2-build-windows-i586-cygwin/jdk8u131/8869/install/src/common/share/Version.cppc:/re/workspace/8-2-build-windows-i586-cygwin/jdk8u131/8869/install/src/common/share/JavaVersion.cppjusched.logSOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SOFTWARE\Microsoft\Windows\CurrentVersion\Installerrt.jarVERSION.dllmsimsg.dllmsi.dlljaureg.exejavac.exe2.8.131.112.8.131.112.8.131.11http://ts-ocsp.ws.symantec.com07c:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u131\8869\install\src\common\share\Version.hc:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u131\8869\install\src\windows\common\InstalledJavaTracker.hc:\re\workspace\8-2-build-windows-i586-cygwin\jdk8u131\8869\install\src\windows\common\Dll.hExecutor.exec(): CreateProcessSoftware\JavaSoft\JDKSoftware\JavaSoft\JRE():address.Deleted [] failed" MSI property is [n%%%OgaagOLoadLibraryW(LoadLibraryExW(Given version is [No such processFailed to delete existing [nOOOOgaagO%%%ONo such device or addressfromResult too largeNo such devicefailedzip file is emptyfailedToo many linksToo many open files in systemToo many open filescannot load resourcecannot find resourceResource deviceA\Oracle\Java\java.settings.cfgOperation not permitted[%d < %d] failedValue of file version extracted fromarchive is too large to be extracted into memoryarchive is a directory and can't be extracted into memorySoftware\JavaSoft\Java Runtime Environment%s failed with %sSoftware\JavaSoft\Java Development Kitjaureglist.xmlmscoree.dll.?AVExecutorError@Executor@@Executor::ExecProcessExecutor::ExecutorExecutorError in Executor::ExecProcessExecutor::startExecutionMsiViewExecute(Executor::execRegistry::getValue%2dA3A4F4-B792-11D6-A78A-00B0D02%04d0Executor::createPipe<requestedPrivileges>Registry::getString
Foremost
Matches
0.exe, 412 KB
Suspicious
True check_circle
Heuristics
IPs
hasIPs: True check_circleAllowed: 2.8.131.11, 1, anantes-650-1-198-11.w2-8.abo.wanadoo.fr.SuspicioushasAllowed: True check_circlehasSuspicious: False cancel
URLs
AllowedhasURLs: True check_circleSuspicious: http://s2.symcb.com0, http://www.symauth.com/rpa00, http://sv.symcb.com/sv.crt0, http://crl.thawte.com/thawtetimestampingca.crl0, http://sv.symcd.com0&, http://www.symauth.com/cps0(, http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(, http://sv.symcb.com/sv.crl0f, http://ocsp.thawte.com0, https://d.symcb.com/cps0%, http://s1.symcb.com/pca3-g5.crl0, http://ts-aia.ws.symantec.com/tss-ca-g2.cer0<, https://d.symcb.com/rpa0, http://ts-ocsp.ws.symantec.com07hasAllowed: False cancelhasSuspicious: True check_circle
Files
Allowed: WUSER32.DLL, nKERNEL32.DLL, mscoree.dll, ADVAPI32.dll, SHELL32.dll, OLEAUT32.dll, USER32.dll, VERSION.dll, msimsg.dll, ole32.dll, msi.dll, KERNEL32.dllhasFiles: True check_circleSuspicious: jaureglist.xml, rt.jar, jusched.loghasAllowed: True check_circlehasSuspicious: True check_circle
Binary
Sizes
RVARVA: 16Suspicious: False cancelCodeSize: 161280Suspicious: False cancelImageAddress: 4194304Suspicious: False cancelStackStack: 4096Suspicious: False cancelHeadersHeaders: 1024Suspicious: False cancelSuspicious: False cancel
Symbols
NumberNumber: 0Suspicious: True check_circlePointerPointer: 0Suspicious: True check_circleDirectoriesNumber: 16Suspicious: False cancel
Checksum
Value: 438290Suspicous: False cancel
Sections
Allowed: .text, .rdata, .data, .rsrc, .relocSuspicioushasAllowed: True check_circlehasSections: True check_circlehasSuspicious: False cancel
Versions
OSVersion: 5Suspicious: False cancelImageVersion: True check_circleSuspicious: 5LinkerVersion: 10.0Suspicious: False cancelSubsystemVersion: 5.1Suspicious: False cancelSuspicious: False cancel
EntryPoint
Address: 160529Suspicious: False cancel
Anomalies
AnomalieshasAnomalies: False cancel
Libraries
Allowed: mscoree.dll, advapi32.dll, shell32.dll, oleaut32.dll, user32.dll, version.dll, msimsg.dll, ole32.dll, msi.dll, kernel32.dllhasLibs: True check_circleSuspicious: wuser32.dll, nkernel32.dllhasAllowed: True check_circlehasSuspicious: True check_circle
Timestamp
Past: False cancelValid: True check_circleValue: 2017-03-15 06:43:13Future: False cancel
Compilation
Packed: False cancelMissing: False cancelPackersCompiled: True check_circleCompilers: Microsoft Visual C++ 8, VC8 -> Microsoft Corporation
Obfuscation
XOR: False cancelFuzzing: True check_circle
PEDetector
Matches
None
Suspicious
False cancel
Disassembly
hasTricks
True check_circle
Tricks
pushret
.data: 1.rsrc: 6.text: 2.rdata: 8
pushpopmath
.rsrc: 5.text: 4.rdata: 13.reloc: 14
garbagebytes
.data: 1.rsrc: 1.text: 2.rdata: 3
hookdetection
.rdata: 1
stealthimport
.text: 3
software breakpoint
.text: 8.rdata: 1.reloc: 7
fakeconditionaljumps
.text: 2
programcontrolflowchange
.data: 1.rsrc: 1.text: 2.rdata: 3
cpuinstructionsresultscomparison
.rdata: 4
AVclass
None
1
VirusTotal
md5
dc5532e5ea9ac29014118b397d3f387b
sha1
a6bed53af015148e2f4f7c3d507b83a7b4c1e153
SCANS (DETECTION RATE = 0.00%)
AVG
update: 20200202version: 18.4.3895.0detected: False cancel
CMC
update: 20190321version: 1.1.0.977detected: False cancel
MAX
update: 20200202version: 2019.9.16.1detected: False cancel
APEX
update: 20200201version: 5.113detected: False cancel
K7GW
update: 20200202version: 11.89.33166detected: False cancel
ALYac
update: 20200202version: 1.1.1.5detected: False cancel
Avast
update: 20200202version: 18.4.3895.0detected: False cancel
Avira
update: 20200202version: 8.3.3.8detected: False cancel
Baidu
update: 20190318version: 1.0.0.2detected: False cancel
Cyren
update: 20200202version: 6.2.2.2detected: False cancel
DrWeb
update: 20200202version: 7.0.44.12030detected: False cancel
GData
update: 20200202version: A:25.24775B:26.17573detected: False cancel
Panda
update: 20200202version: 4.6.4.2detected: False cancel
VBA32
update: 20200131version: 4.3.0detected: False cancel
VIPRE
update: 20200202version: 81230detected: False cancel
Zoner
update: 20200202version: 1.0.0.1detected: False cancel
ClamAV
update: 20200201version: 0.102.1.0detected: False cancel
Comodo
update: 20200202version: 32035detected: False cancel
F-Prot
update: 20200202version: 4.7.1.166detected: False cancel
Ikarus
update: 20200201version: 0.1.5.2detected: False cancel
McAfee
update: 20200202version: 6.0.6.653detected: False cancel
Rising
update: 20200202version: 25.0.0.24detected: False cancel
Sophos
update: 20200202version: 4.98.0detected: False cancel
Yandex
update: 20200131version: 5.5.2.24detected: False cancel
Zillya
update: 20200201version: 2.0.0.4011detected: False cancel
Acronis
update: 20200128version: 1.1.1.58detected: False cancel
Alibaba
update: 20190527version: 0.3.0.5detected: False cancel
Arcabit
update: 20200202version: 1.0.0.869detected: False cancel
Cylance
update: 20200202version: 2.3.1.101detected: False cancel
Endgame
update: 20200131version: 3.0.16detected: False cancel
FireEye
update: 20200202version: 29.7.0.0detected: False cancel
Sangfor
update: 20200114version: 1.0detected: False cancel
TACHYON
update: 20200202version: 2020-02-02.01detected: False cancel
Tencent
update: 20200202version: 1.0.0.1detected: False cancel
ViRobot
update: 20200201version: 2014.3.20.0detected: False cancel
Webroot
update: 20200202version: 1.0.0.403detected: False cancel
eGambit
update: 20200202detected: False cancel
Ad-Aware
update: 20200202version: 3.0.5.370detected: False cancel
AegisLab
update: 20200202version: 4.2detected: False cancel
Emsisoft
update: 20200202version: 2018.12.0.1641detected: False cancel
F-Secure
update: 20200202version: 12.0.86.52detected: False cancel
Fortinet
update: 20200202version: 6.2.137.0detected: False cancel
Invincea
update: 20191211version: 6.3.6.26157detected: False cancel
Jiangmin
update: 20200202version: 16.0.100detected: False cancel
Kingsoft
update: 20200202version: 2013.8.14.323detected: False cancel
Paloalto
update: 20200202version: 1.0detected: False cancel
Symantec
update: 20200201version: 1.11.0.0detected: False cancel
Trapmine
update: 20200123version: 3.2.22.914detected: False cancel
AhnLab-V3
update: 20200201version: 3.17.0.26111detected: False cancel
Antiy-AVL
update: 20200202version: 3.0.0.1detected: False cancel
Kaspersky
update: 20200202version: 15.0.1.13detected: False cancel
MaxSecure
update: 20200131version: 1.0.0.1detected: False cancel
Microsoft
update: 20200202version: 1.1.16700.3detected: False cancel
Qihoo-360
update: 20200202version: 1.0.0.1120detected: False cancel
ZoneAlarm
update: 20200202version: 1.0detected: False cancel
Cybereason
update: 20190616version: 1.2.449detected: False cancel
ESET-NOD32
update: 20200202version: 20771detected: False cancel
TrendMicro
update: 20200202version: 11.0.0.1006detected: False cancel
BitDefender
update: 20200202version: 7.2detected: False cancel
CrowdStrike
update: 20190702version: 1.0detected: False cancel
K7AntiVirus
update: 20200202version: 11.89.33166detected: False cancel
SentinelOne
update: 20191218version: 1.12.1.57detected: False cancel
Avast-Mobile
update: 20200130version: 200130-00detected: False cancel
CAT-QuickHeal
update: 20200201version: 14.00detected: False cancel
NANO-Antivirus
update: 20200202version: 1.0.134.25031detected: False cancel
BitDefenderTheta
update: 20200120version: 7.2.37796.0detected: False cancel
MicroWorld-eScan
update: 20200202version: 14.0.405.0detected: False cancel
SUPERAntiSpyware
update: 20200131version: 5.6.0.1032detected: False cancel
McAfee-GW-Edition
update: 20200202version: v2017.3010detected: False cancel
TrendMicro-HouseCall
update: 20200202version: 10.0.0.1040detected: False cancel
total
70
sha256
90b13f3aa9d4bfe5859218aef13c0da5816ba6a877ea7545e1d4c72b0271b433
scan_id
90b13f3aa9d4bfe5859218aef13c0da5816ba6a877ea7545e1d4c72b0271b433-1580633262
resource
dc5532e5ea9ac29014118b397d3f387b
positives
0
scan_date
2020-02-02 08:47:42
verbose_msg
Scan finished, information embedded
response_code
1
File
Trace
Process
Trace
Analysis
Reason
Blue Screen
Status
Execution Failed
Results
0
Registry
Trace
File Summary
Created
Identified: False cancel
Deleted
Identified: False cancel
Process Summary
Created
Identified: False cancel
Deleted
Identified: False cancel
Registry Summary
Proxy
Identified: False cancel
AutoRun
Identified: False cancel
Created
Identified: False cancel
Deleted
Identified: False cancel
Browsers
Identified: False cancel
Internet
Identified: False cancel
Loading...
DNS
Query
Response
TCP
Info
UDP
Info
HTTP
Info
Summary
DNS
False cancel
TCP
False cancel
UDP
False cancel
HTTP
False cancel
Results
BINARY
KNN (K=3, NFS-BRMalware)
confidence: 100.00%suspicious: False cancel
Decision Tree (NFS-BRMalware)
confidence: 100.00%suspicious: False cancel
SVC (Kernel=Linear, NFS-BRMalware)
confidence: 64.31%suspicious: False cancel
MalConv (Ember: Raw Bytes, Threshold=0.5)
confidence: 86.64%suspicious: True check_circle
Random Forest (100 estimators, NFS-BRMalware)
confidence: 70.00%suspicious: False cancel
Non-Negative MalConv (Ember: Raw Bytes, Threshold=0.35)
confidence: 52.45%suspicious: True check_circle
LightGDM (Ember: File Characteristics, Threshold=0.8336)
confidence: 99.92%suspicious: False cancel