Report #5549 check_circle
- Creation Date: Feb. 11, 2020, 12:02 p.m.
- Last Update: Feb. 11, 2020, 2:09 p.m.
- File: A.tmp.exe
- Results:
Binary
DLL
False cancel
Size
148.00KB
trid
61.7% Win64 Executable14.7% Win32 Dynamic Link Library10.0% Win32 Executable4.5% OS/2 Executable4.4% Generic Win/DOS Executable
type
PE
wordsize
32
Subsystem
Windows GUI
Hashes
md5
9dc487176719fc91813b56badd0eca2f
sha1
58acb487b5e3e2118150c16b2927712deda13753
crc32
0xad5aeafd
sha224
6069fdba1131f7e13bfc27606b26067a075fd71825cc6e2c8528de80
sha256
97fdd9719283a3853f517a2dcd3c1858ad2bfac0b1b5362f2c846018c6462181
sha384
dfac6f4a4b702d6938d58699cd5a1d8b238dd62195bb62b633c083574d01c6ca086e406eac975b9b6e9f6aa1283a22c6
sha512
2b9c18e3e23b10ae48e1868d5f7c4e193d0f2735c2e229a66f374c64deb1730156456cefa5624e3915d9ce533b96862f7cc62f9354a1ae15e1999e690160241d
ssdeep
3072:nAFBisCZUFi6bh0jQSOqW8NYWuAg0FujU1rJ1GnCcMf:nAFB/Fvbh0krAOmrJwCcMf
Community
Google
False cancel
HashLib
False cancel
YARA
Matches
VC8_Microsoft_Corporation, domain, anti_dbg, url, HasRichSignature, contentis_base64, Microsoft_Visual_Cpp_8, HasDebugData, maldoc_find_kernel32_base_method_1, network_dropper, network_http, win_files_operation, IsPE32, IsWindowsGUI
Suspicious
True check_circle
Strings
List
http://install.portmdfmoon.com/download/APSFPangohttp://www.safefinder.com/faq/SafeFinder/FAQ_ENG.htmlhttp://www.safefinder.com/privacy.htmlhttp://www.safefinder.com/terms.htmlhttp://www.safefinder.com/eula.htmlC:\Work\installer\Release\safefinder.pdbgoogle-analytics.comWININET.dllurlmon.dllDidn't downloadfish.exeSoftware\RtpSoftware\Smartbarv=1&tid=%s&cid=%s&t=event&ec=case&ea=%s&el=%sfr-cafr-chfr-befr-befr-cafr-choperator ""no space on deviceno such processThis product is compatible with Windows and installs on IE, Firefox and/or Chrome.resource deadlock would occurno such device or addressoperation in progresstoo many files open in systemfile too largetoo many linkstoo many files openvalue too largedevice or resource busyno such deviceoperation canceledAre you sure? Do you want to continue installation?operation not permittedset SafeFinder as my home page and new tab in my browsers.Software\PserviceSoftware\RGMserviceFor uninstall instructions click here.HttpOpenRequestWHttpSendRequestWmscoree.dll<requestedPrivileges>IsProcessorFeaturePresentGetProcAddressExitProcessSShUidentifier removedIn age of too much information, SafeFinder presents the perfect tool.operation would blockStartProcess failedIsDebuggerPresentexecutable format errorCopyright (c) by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.Simplify the web, SafeFinder gives you the optimal way to share, search, work & play.CreateProcessWTerminateProcessDownloadedShellExecuteWtoo many symbolic link levelsInternetConnectWpermission deniedRegOpenKeyExWInternetOpenWLoadLibraryExWFreeLibraryQueryPerformanceCounterGetModuleFileNameWFindNextFileWFindFirstFileExWCreateFileWGetModuleHandleWRegQueryValueExWInternetReadFileRegOpenKeyWWriteFileClick 'Accept' now to continue and set SafeFinder as my default search provider andhost unreachablenetwork resetAFX_DIALOG_LAYOUTnetwork downbroken pipenot a socketMS Shell DlgSleepsystem{"packer":{"DistributerName":"APSFPango","ChannelId":"3"},"Agent":{"SetAll":"true"}}api-ms-win-security-systemfunctions-l1-1-0<requestedExecutionLevel level='requireAdministrator' uiAccess='false' />POST0"0(0.04090?0E0K0P0V0\0b0g0m0s0y0~0GetCPInfofr-CHfr-CAfr-LUfr-LUfr-CHfr-CA
Foremost
Matches
0.exe, 148 KB
Suspicious
True check_circle
Heuristics
IPs
hasIPs: False cancelAllowedSuspicioushasAllowed: False cancelhasSuspicious: False cancel
URLs
AllowedhasURLs: True check_circleSuspicious: http://www.safefinder.com/eula.html, http://install.portmdfmoon.com/download/apsfpango, http://www.safefinder.com/terms.html, http://www.safefinder.com/privacy.html, http://www.safefinder.com/faq/safefinder/faq_eng.htmlhasAllowed: False cancelhasSuspicious: True check_circle
Files
Allowed: mscoree.dll, kernel32.dll, WININET.dll, ADVAPI32.dll, USER32.dll, SHELL32.dll, RPCRT4.dll, GDI32.dll, urlmon.dllhasFiles: True check_circleSuspicioushasAllowed: True check_circlehasSuspicious: False cancel
Binary
Sizes
RVARVA: 16Suspicious: False cancelCodeSize: 74240Suspicious: False cancelImageAddress: 4194304Suspicious: False cancelStackStack: 4096Suspicious: False cancelHeadersHeaders: 1024Suspicious: False cancelSuspicious: False cancel
Symbols
NumberNumber: 0Suspicious: True check_circlePointerPointer: 0Suspicious: True check_circleDirectoriesNumber: 16Suspicious: False cancel
Checksum
Value: 0Suspicous: True check_circle
Sections
Allowed: .text, .rdata, .data, .rsrc, .relocSuspicioushasAllowed: True check_circlehasSections: True check_circlehasSuspicious: False cancel
Versions
OSVersion: 5Suspicious: False cancelImageVersion: True check_circleSuspicious: 5LinkerVersion: 14.16Suspicious: False cancelSubsystemVersion: 5.1Suspicious: False cancelSuspicious: False cancel
EntryPoint
Address: 31810Suspicious: False cancel
Anomalies
Anomalies: The header checksum and the calculated checksum do not match.hasAnomalies: True check_circle
Libraries
Allowed: mscoree.dll, kernel32.dll, wininet.dll, advapi32.dll, user32.dll, shell32.dll, rpcrt4.dll, gdi32.dll, urlmon.dllhasLibs: True check_circleSuspicioushasAllowed: True check_circlehasSuspicious: False cancel
Timestamp
Past: False cancelValid: True check_circleValue: 2019-04-02 12:59:01Future: False cancel
Compilation
Packed: False cancelMissing: False cancelPackersCompiled: True check_circleCompilers: Microsoft Visual C++ 8, VC8 -> Microsoft Corporation
Obfuscation
XOR: False cancelFuzzing: False cancel
PEDetector
Matches
None
Suspicious
False cancel
Disassembly
hasTricks
True check_circle
Tricks
ldr
.text: 1
pushret
.rdata: 2
pushpopmath
.rdata: 8.reloc: 6
sizeofimage
.text: 1
garbagebytes
.rdata: 2
hookdetection
.rdata: 1
stealthimport
.rdata: 1
peb ntglobalflag
.text: 1
software breakpoint
.rdata: 1.reloc: 1
programcontrolflowchange
.rdata: 2
AVclass
oxypumper
1
VirusTotal
md5
9dc487176719fc91813b56badd0eca2f
sha1
58acb487b5e3e2118150c16b2927712deda13753
SCANS (DETECTION RATE = 79.17%)
AVG
result: Win32:Adware-gen [Adw]update: 20191207version: 18.4.3895.0detected: True check_circle
CMC
update: 20190321version: 1.1.0.977detected: False cancel
MAX
result: malware (ai score=99)update: 20191207version: 2019.9.16.1detected: True check_circle
APEX
result: Maliciousupdate: 20191207version: 5.93detected: True check_circle
Bkav
update: 20191207version: 1.3.0.9899detected: False cancel
K7GW
result: Adware ( 005524301 )update: 20191207version: 11.81.32762detected: True check_circle
ALYac
result: Trojan.GenericKD.41172374update: 20191207version: 1.1.1.5detected: True check_circle
Avast
result: Win32:Adware-gen [Adw]update: 20191207version: 18.4.3895.0detected: True check_circle
Avira
result: ADWARE/OxyPumper.mwfxvupdate: 20191207version: 8.3.3.8detected: True check_circle
Baidu
update: 20190318version: 1.0.0.2detected: False cancel
Cyren
result: W32/Adware.ZRME-0226update: 20191207version: 6.2.2.2detected: True check_circle
DrWeb
result: Adware.OxyPumper.3update: 20191207version: 7.0.42.9300detected: True check_circle
GData
result: Trojan.GenericKD.41172374update: 20191207version: A:25.24195B:26.16911detected: True check_circle
Panda
result: Trj/CI.Aupdate: 20191207version: 4.6.4.2detected: True check_circle
VBA32
result: BScope.Adware.Linkuryupdate: 20191206version: 4.2.0detected: True check_circle
VIPRE
result: Trojan.Win32.Generic!BTupdate: 20191207version: 79854detected: True check_circle
Zoner
update: 20191207version: 1.0.0.1detected: False cancel
ClamAV
update: 20191207version: 0.102.1.0detected: False cancel
Comodo
result: ApplicUnwnt@#1owsxvngh5wl4update: 20191207version: 31813detected: True check_circle
F-Prot
update: 20191207version: 4.7.1.166detected: False cancel
Ikarus
result: PUA.OxyPumperupdate: 20191207version: 0.1.5.2detected: True check_circle
McAfee
result: RDN/Generic PUP.cjsupdate: 20191207version: 6.0.6.653detected: True check_circle
Rising
result: Adware.SafeFinder!1.BB2E (CLASSIC)update: 20191207version: 25.0.0.24detected: True check_circle
Sophos
result: Generic PUA FI (PUA)update: 20191207version: 4.98.0detected: True check_circle
Yandex
result: Trojan.Cryptos!K3ReBoIrGhcupdate: 20191205version: 5.5.2.24detected: True check_circle
Zillya
update: 20191206version: 2.0.0.3968detected: False cancel
Acronis
update: 20191205version: 1.1.1.58detected: False cancel
Alibaba
result: Trojan:MSIL/Cryptos.c925e798update: 20190527version: 0.3.0.5detected: True check_circle
Arcabit
result: Trojan.Generic.D2743D96update: 20191207version: 1.0.0.865detected: True check_circle
Cylance
result: Unsafeupdate: 20191207version: 2.3.1.101detected: True check_circle
Endgame
result: malicious (high confidence)update: 20190918version: 3.0.15detected: True check_circle
FireEye
result: Generic.mg.9dc487176719fc91update: 20191207version: 29.7.0.0detected: True check_circle
Sangfor
result: Malwareupdate: 20191031version: 1.0detected: True check_circle
TACHYON
update: 20191207version: 2019-12-07.01detected: False cancel
Tencent
update: 20191207version: 1.0.0.1detected: False cancel
ViRobot
result: Trojan.Win32.Z.Oxypumper.151552.Bupdate: 20191206version: 2014.3.20.0detected: True check_circle
Webroot
result: W32.Adware.Genupdate: 20191207version: 1.0.0.403detected: True check_circle
Ad-Aware
result: Trojan.GenericKD.41172374update: 20191207version: 3.0.5.370detected: True check_circle
AegisLab
result: Trojan.MSIL.Cryptos.4!cupdate: 20191207version: 4.2detected: True check_circle
Emsisoft
result: Trojan.GenericKD.41172374 (B)update: 20191207version: 2018.12.0.1641detected: True check_circle
F-Secure
result: Adware.ADWARE/OxyPumper.mwfxvupdate: 20191207version: 12.0.86.52detected: True check_circle
Fortinet
result: Riskware/OxyPumperupdate: 20191207version: 6.2.137.0detected: True check_circle
Invincea
result: heuristicupdate: 20190904version: 6.3.6.26157detected: True check_circle
Jiangmin
result: Trojan.MSIL.lepgupdate: 20191207version: 16.0.100detected: True check_circle
Kingsoft
update: 20191207version: 2013.8.14.323detected: False cancel
Paloalto
result: generic.mlupdate: 20191207version: 1.0detected: True check_circle
Symantec
result: ML.Attribute.HighConfidenceupdate: 20191206version: 1.11.0.0detected: True check_circle
Trapmine
update: 20190826version: 3.1.81.800detected: False cancel
AhnLab-V3
result: PUP/Win32.Agent.C3296420update: 20191207version: 3.16.5.25880detected: True check_circle
Antiy-AVL
result: Trojan/MSIL.Cryptosupdate: 20191207version: 3.0.0.1detected: True check_circle
Kaspersky
result: Trojan.MSIL.Cryptos.debxupdate: 20191207version: 15.0.1.13detected: True check_circle
MaxSecure
result: Trojan.Malware.74227051.susgenupdate: 20191206version: 1.0.0.1detected: True check_circle
Microsoft
result: Trojan:Win32/Stealer.J!ibtupdate: 20191207version: 1.1.16600.7detected: True check_circle
Qihoo-360
result: Win32/Trojan.cdbupdate: 20191207version: 1.0.0.1120detected: True check_circle
ZoneAlarm
result: Trojan.MSIL.Cryptos.debxupdate: 20191207version: 1.0detected: True check_circle
Cybereason
result: malicious.76719fupdate: 20190616version: 1.2.449detected: True check_circle
ESET-NOD32
result: a variant of Win32/Adware.OxyPumper.BTupdate: 20191207version: 20471detected: True check_circle
TrendMicro
result: TROJ_FRS.VSNW11G19update: 20191207version: 11.0.0.1006detected: True check_circle
BitDefender
result: Trojan.GenericKD.41172374update: 20191207version: 7.2detected: True check_circle
CrowdStrike
result: win/malicious_confidence_60% (W)update: 20190702version: 1.0detected: True check_circle
K7AntiVirus
result: Adware ( 005524301 )update: 20191207version: 11.81.32762detected: True check_circle
SentinelOne
update: 20191203version: 1.9.0.2431detected: False cancel
Avast-Mobile
update: 20191205version: 191205-00detected: False cancel
Malwarebytes
result: PUP.Optional.SafeFinderupdate: 20191207version: 2.1.1.1115detected: True check_circle
TotalDefense
update: 20191207version: 37.1.62.1detected: False cancel
CAT-QuickHeal
result: Trojan.MSILupdate: 20191207version: 14.00detected: True check_circle
NANO-Antivirus
result: Trojan.Win32.Cryptos.fovdqgupdate: 20191207version: 1.0.134.24859detected: True check_circle
BitDefenderTheta
result: Gen:NN.ZexaF.32519.juW@aSzLc6diupdate: 20191204version: 7.2.37796.0detected: True check_circle
MicroWorld-eScan
result: Trojan.GenericKD.41172374update: 20191207version: 14.0.297.0detected: True check_circle
SUPERAntiSpyware
result: Trojan.Agent/Gen-Kryptikupdate: 20191203version: 5.6.0.1032detected: True check_circle
McAfee-GW-Edition
result: RDN/Generic PUP.cjsupdate: 20191207version: v2017.3010detected: True check_circle
TrendMicro-HouseCall
result: TROJ_FRS.VSNW11G19update: 20191207version: 10.0.0.1040detected: True check_circle
total
72
sha256
97fdd9719283a3853f517a2dcd3c1858ad2bfac0b1b5362f2c846018c6462181
scan_id
97fdd9719283a3853f517a2dcd3c1858ad2bfac0b1b5362f2c846018c6462181-1575719064
resource
9dc487176719fc91813b56badd0eca2f
positives
57
scan_date
2019-12-07 11:44:24
verbose_msg
Scan finished, information embedded
response_code
1
File
Trace
Process
Trace
Analysis
Reason
Blue Screen
Status
Execution Failed
Results
0
Registry
Trace
File Summary
Created
Identified: False cancel
Deleted
Identified: False cancel
Process Summary
Created
Identified: False cancel
Deleted
Identified: False cancel
Registry Summary
Proxy
Identified: False cancel
AutoRun
Identified: False cancel
Created
Identified: False cancel
Deleted
Identified: False cancel
Browsers
Identified: False cancel
Internet
Identified: False cancel
Loading...
DNS
Query
Response
TCP
Info
UDP
Info
HTTP
Info
Summary
DNS
False cancel
TCP
False cancel
UDP
False cancel
HTTP
False cancel
Results
BINARY
KNN (K=3, NFS-BRMalware)
confidence: 66.67%suspicious: False cancel
Decision Tree (NFS-BRMalware)
confidence: 100.00%suspicious: True check_circle
SVC (Kernel=Linear, NFS-BRMalware)
confidence: 99.83%suspicious: False cancel
MalConv (Ember: Raw Bytes, Threshold=0.5)
confidence: 83.43%suspicious: True check_circle
Random Forest (100 estimators, NFS-BRMalware)
confidence: 54.00%suspicious: True check_circle
Non-Negative MalConv (Ember: Raw Bytes, Threshold=0.35)
confidence: 45.39%suspicious: True check_circle
LightGDM (Ember: File Characteristics, Threshold=0.8336)
confidence: 98.70%suspicious: True check_circle