Report #5553 check_circle
- Creation Date: Feb. 11, 2020, 12:02 p.m.
- Last Update: Feb. 11, 2020, 2:34 p.m.
- File: NFeletronicaBR263658774157912547417.exe
- Results:
Binary
DLL
False cancel
Size
661.00KB
trid
81.0% Generic CIL Executable7.2% Win32 Dynamic Link Library4.9% Win32 Executable2.2% OS/2 Executable2.2% Generic Win/DOS Executable
type
PE
wordsize
32
Subsystem
Windows CLI
Hashes
md5
e5dc914237fbb4e5da5cde1bb99dc8ee
sha1
e1e84a58b375d1d6516e494b6c8213afece670d7
crc32
0x35cd5ea8
sha224
d2262926e551cdf7819dfc9a39a4224d5a1614bfe9625efddcb522dc
sha256
5358f5e39e69be6e06d00aa37e7441b8ddce91bc94e9371548e40766b86eb1b9
sha384
6693fa9727f926fdac4ae46fcfcf57d1597de33b44cf75b593e06a021f2b055504f479a72bfa37574733e3a97f7e310f
sha512
d3b1899e5f3d1b05a2316b076767201ae45ca850f663930f7df079359ba028a1e9db853ff6f64046e74f16a6bb0b649cc1a65e4392f658711bac7fdb906d1d17
ssdeep
6144:ZCR/JtfdfcqkaBVDIVeTF6VFIIdViuuTTHQUYsTAXJPRXbbO9tgsTin60acuZFWy:Zvage4VZWZ6Rb2gsk6
Community
Google
False cancel
HashLib
False cancel
YARA
Matches
NET_executable, contentis_base64, Microsoft_Visual_Studio_NET_additional, IP, IsNET_EXE, NETexecutableMicrosoft, Microsoft_Visual_Studio_NET, HasDebugData, IsConsole, NET_executable_, domain, IsPE32
Suspicious
True check_circle
Strings
List
c:\Users\usuario\source\repos\ConsoleApp5\ConsoleApp5\obj\Release\ConsoleApp1.pdbSystem.IOSystem.Net<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>System.Security.CryptographySystem.IO.Compression.FileSystemSystem.IO.Compression1.0.0.01.0.0.01.0.0.01.0.0.0ConsoleApp1.exeConsoleApp1.exeConsoleApp1.exebutton83button83DeleteNextSystem.Windows.Formsmscoree.dlllSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSetlSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSetlSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSetDebuggableAttributeDebuggingModesExtractToDirectorynCmdShowGetTempPathIvan MedvedevSleepCryptoStreamModeCreateDecryptorCryptoStreamICryptoTransform<PrivateImplementationDetails>{E5CD0814-F20C-43ED-8E80-24F60456816D}Randomrandom<requestedExecutionLevel level="asInvoker" uiAccess="false"/>Crypt$$method0x600000e-1_CorExeMain<GWOu>b__0IEnumerable`1set_AutoScaleModeget_Controlsset_ClientSizebutton135button134button133button145button144button143button154button147button153button152button136button137button138button139button140button141button142button146button144button145button146button148button149button150button151button143button150button147button160button108button107button106button105button104button157button158button159button161button148button162button163button164button165button166button167button168button169button109button110button111button112button149button131button155
Foremost
Matches
0.exe, 661 KB
Suspicious
True check_circle
Heuristics
IPs
hasIPs: False cancelAllowedSuspicioushasAllowed: False cancelhasSuspicious: False cancel
URLs
AllowedhasURLs: False cancelSuspicioushasAllowed: False cancelhasSuspicious: False cancel
Files
Allowed: user32.dll, mscoree.dll, kernel32.dllhasFiles: True check_circleSuspicioushasAllowed: True check_circlehasSuspicious: False cancel
Binary
Sizes
RVARVA: 16Suspicious: False cancelCodeSize: 2048Suspicious: False cancelImageAddress: 4194304Suspicious: False cancelStackStack: 4096Suspicious: False cancelHeadersHeaders: 512Suspicious: False cancelSuspicious: False cancel
Symbols
NumberNumber: 0Suspicious: True check_circlePointerPointer: 0Suspicious: True check_circleDirectoriesNumber: 16Suspicious: False cancel
Checksum
Value: 0Suspicous: True check_circle
Sections
Allowed: .text, .rsrc, .relocSuspicioushasAllowed: True check_circlehasSections: True check_circlehasSuspicious: False cancel
Versions
OSVersion: 4Suspicious: False cancelImageVersion: True check_circleSuspicious: 4LinkerVersion: 11.0Suspicious: False cancelSubsystemVersion: 6.0Suspicious: False cancelSuspicious: False cancel
EntryPoint
Address: 682462Suspicious: False cancel
Anomalies
Anomalies: The header checksum and the calculated checksum do not match.hasAnomalies: True check_circle
Libraries
Allowed: user32.dll, mscoree.dll, kernel32.dllhasLibs: True check_circleSuspicioushasAllowed: True check_circlehasSuspicious: False cancel
Timestamp
Past: False cancelValid: True check_circleValue: 2019-04-26 13:05:24Future: False cancel
Compilation
Packed: False cancelMissing: False cancelPackersCompiled: True check_circleCompilers: Microsoft Visual C# / Basic .NET, Microsoft Visual Studio .NET, .NET executable, Microsoft Visual C# v7.0 / Basic .NET
Obfuscation
XOR: False cancelFuzzing: True check_circle
PEDetector
Matches
None
Suspicious
False cancel
Disassembly
hasTricks
True check_circle
Tricks
pushret
.text: 1
pushpopmath
.text: 23
garbagebytes
.text: 1
programcontrolflowchange
.text: 1
cpuinstructionsresultscomparison
.text: 1987
AVclass
moderate
1
VirusTotal
md5
e5dc914237fbb4e5da5cde1bb99dc8ee
sha1
e1e84a58b375d1d6516e494b6c8213afece670d7
SCANS (DETECTION RATE = 30.00%)
AVG
update: 20190426version: 18.4.3895.0detected: False cancel
CMC
update: 20190321version: 1.1.0.977detected: False cancel
MAX
result: malware (ai score=85)update: 20190426version: 2018.9.12.1detected: True check_circle
Bkav
update: 20190425version: 1.3.0.9899detected: False cancel
K7GW
update: 20190426version: 11.40.30725detected: False cancel
Avast
update: 20190426version: 18.4.3895.0detected: False cancel
Avira
result: TR/Dropper.Genupdate: 20190426version: 8.3.3.8detected: True check_circle
Baidu
update: 20190318version: 1.0.0.2detected: False cancel
Cyren
update: 20190426version: 6.2.0.1detected: False cancel
DrWeb
result: Trojan.DownLoader27.54092update: 20190426version: 7.0.34.11020detected: True check_circle
GData
result: Gen:Variant.Johnnie.129970update: 20190426version: A:25.21690B:25.14941detected: True check_circle
Panda
update: 20190426version: 4.6.4.2detected: False cancel
VBA32
update: 20190426version: 4.0.0detected: False cancel
Zoner
update: 20190426version: 1.0detected: False cancel
ClamAV
update: 20190426version: 0.101.2.0detected: False cancel
Comodo
update: 20190426version: 30775detected: False cancel
F-Prot
update: 20190426version: 4.7.1.166detected: False cancel
McAfee
result: GenericRXHL-PL!E5DC914237FBupdate: 20190426version: 6.0.6.653detected: True check_circle
Rising
update: 20190426version: 25.0.0.24detected: False cancel
Sophos
update: 20190426version: 4.98.0detected: False cancel
Yandex
update: 20190426version: 5.5.1.3detected: False cancel
Zillya
update: 20190426version: 2.0.0.3804detected: False cancel
Acronis
update: 20190425version: 1.0.1.48detected: False cancel
Alibaba
update: 20190426version: 0.4.0.6detected: False cancel
Arcabit
result: Trojan.Johnnie.D1FBB2update: 20190426version: 1.0.0.845detected: True check_circle
Babable
update: 20190424version: 9107201detected: False cancel
Cylance
update: 20190426version: 2.3.1.101detected: False cancel
Endgame
result: malicious (moderate confidence)update: 20190403version: 3.0.9detected: True check_circle
FireEye
result: Gen:Variant.Johnnie.129970update: 20190426version: 29.7.0.0detected: True check_circle
TACHYON
update: 20190426version: 2019-04-26.02detected: False cancel
Tencent
update: 20190426version: 1.0.0.1detected: False cancel
ViRobot
update: 20190426version: 2014.3.20.0detected: False cancel
Webroot
update: 20190426version: 1.0.0.403detected: False cancel
eGambit
update: 20190426version: v4.3.6detected: False cancel
Ad-Aware
result: Gen:Variant.Johnnie.129970update: 20190426version: 3.0.5.370detected: True check_circle
AegisLab
update: 20190426version: 4.2detected: False cancel
Emsisoft
result: Gen:Variant.Johnnie.129970 (B)update: 20190426version: 2018.4.0.1029detected: True check_circle
F-Secure
result: Trojan.TR/Dropper.Genupdate: 20190426version: 12.0.86.52detected: True check_circle
Fortinet
result: MSIL/Banload.IA!trupdate: 20190426version: 5.4.247.0detected: True check_circle
Invincea
update: 20190313version: 6.3.6.26157detected: False cancel
Jiangmin
update: 20190426version: 16.0.100detected: False cancel
Kingsoft
update: 20190426version: 2013.8.14.323detected: False cancel
Paloalto
update: 20190426version: 1.0detected: False cancel
Symantec
update: 20190426version: 1.9.0.0detected: False cancel
Trapmine
result: malicious.moderate.ml.scoreupdate: 20190325version: 3.1.52.760detected: True check_circle
AhnLab-V3
result: Trojan/Win32.Banload.C2721948update: 20190426version: 3.15.0.23609detected: True check_circle
Antiy-AVL
update: 20190426version: 3.0.0.1detected: False cancel
Kaspersky
update: 20190426version: 15.0.1.13detected: False cancel
MaxSecure
update: 20190426version: 1.0.0.1detected: False cancel
Microsoft
update: 20190426version: 1.1.15900.4detected: False cancel
Qihoo-360
update: 20190426version: 1.0.0.1120detected: False cancel
TheHacker
update: 20190421version: 6.8.0.5.4174detected: False cancel
Trustlook
update: 20190426version: 1.0detected: False cancel
ZoneAlarm
update: 20190426version: 1.0detected: False cancel
Cybereason
result: malicious.237fbbupdate: 20190417version: 1.2.449detected: True check_circle
ESET-NOD32
result: a variant of MSIL/Kryptik.PDKupdate: 20190426version: 19260detected: True check_circle
TrendMicro
update: 20190426version: 10.0.0.1040detected: False cancel
BitDefender
result: Gen:Variant.Johnnie.129970update: 20190426version: 7.2detected: True check_circle
CrowdStrike
result: win/malicious_confidence_80% (D)update: 20190212version: 1.0detected: True check_circle
K7AntiVirus
update: 20190426version: 11.40.30727detected: False cancel
SentinelOne
result: DFI - Malicious PEupdate: 20190420version: 1.0.25.316detected: True check_circle
Avast-Mobile
update: 20190426version: 190426-00detected: False cancel
Malwarebytes
update: 20190426version: 2.1.1.1115detected: False cancel
TotalDefense
update: 20190426version: 37.1.62.1detected: False cancel
CAT-QuickHeal
update: 20190426version: 14.00detected: False cancel
NANO-Antivirus
update: 20190426version: 1.0.134.24788detected: False cancel
MicroWorld-eScan
result: Gen:Variant.Johnnie.129970update: 20190426version: 14.0.297.0detected: True check_circle
SUPERAntiSpyware
update: 20190423version: 5.6.0.1032detected: False cancel
McAfee-GW-Edition
result: GenericRXHL-PL!E5DC914237FBupdate: 20190426version: v2017.3010detected: True check_circle
TrendMicro-HouseCall
update: 20190426version: 10.0.0.1040detected: False cancel
total
70
sha256
5358f5e39e69be6e06d00aa37e7441b8ddce91bc94e9371548e40766b86eb1b9
scan_id
5358f5e39e69be6e06d00aa37e7441b8ddce91bc94e9371548e40766b86eb1b9-1556304653
resource
e5dc914237fbb4e5da5cde1bb99dc8ee
positives
21
scan_date
2019-04-26 18:50:53
verbose_msg
Scan finished, information embedded
response_code
1
File
Trace
11/2/2020 - 13:45:42.762 | Open | 1480 | C:\malware.exe | C:\Windows\System32\MUI\0416\mscorees.dll | |
11/2/2020 - 13:45:42.762 | Open | 1480 | C:\malware.exe | C:\Windows\System32\MUI\0416\mscorees.dll | |
11/2/2020 - 13:45:42.762 | Open | 1480 | C:\malware.exe | C:\Windows\System32\mscorrc.dll | |
11/2/2020 - 13:45:42.762 | Open | 1480 | C:\malware.exe | C:\Windows\System32\mscorrc.dll.DLL | |
11/2/2020 - 13:45:42.762 | Open | 1480 | C:\malware.exe | C:\mscorrc.dll | |
11/2/2020 - 13:45:42.762 | Open | 1480 | C:\malware.exe | C:\Windows\System32\mscorrc.dll | |
11/2/2020 - 13:45:42.762 | Open | 1480 | C:\malware.exe | C:\Windows\system\mscorrc.dll | |
11/2/2020 - 13:45:42.762 | Open | 1480 | C:\malware.exe | C:\Windows\mscorrc.dll | |
11/2/2020 - 13:45:42.762 | Open | 1480 | C:\malware.exe | C:\Monitor\mscorrc.dll | |
11/2/2020 - 13:45:42.762 | Open | 1480 | C:\malware.exe | C:\Windows\System32\mscorrc.dll | |
11/2/2020 - 13:45:42.762 | Open | 1480 | C:\malware.exe | C:\Windows\mscorrc.dll | |
11/2/2020 - 13:45:42.762 | Open | 1480 | C:\malware.exe | C:\Windows\System32\wbem\mscorrc.dll | |
11/2/2020 - 13:45:42.762 | Open | 1480 | C:\malware.exe | C:\Windows\System32\WindowsPowerShell\v1.0\mscorrc.dll | |
11/2/2020 - 13:45:42.762 | Open | 1480 | C:\malware.exe | C:\malware.exe.config | |
11/2/2020 - 13:45:42.762 | Open | 1480 | C:\malware.exe | C:\Windows\Microsoft.NET\Framework64\v4.0.40305 | |
11/2/2020 - 13:45:42.762 | Open | 1480 | C:\malware.exe | C:\Windows\Microsoft.NET\Framework64\v4.0.40305 | |
11/2/2020 - 13:45:42.762 | Open | 1480 | C:\malware.exe | C:\Windows\Fonts\StaticCache.dat | |
11/2/2020 - 13:45:42.762 | Read | 1480 | C:\malware.exe | C:\Windows\Fonts\StaticCache.dat | StaticCache.dat |
11/2/2020 - 13:45:42.778 | Open | 1480 | C:\malware.exe | C:\Windows\System32\uxtheme.dll | |
11/2/2020 - 13:45:42.778 | Open | 1480 | C:\malware.exe | C:\Windows\System32\uxtheme.dll | |
11/2/2020 - 13:45:42.840 | Open | 1480 | C:\malware.exe | C:\dwmapi.dll | |
11/2/2020 - 13:45:42.840 | Open | 1480 | C:\malware.exe | C:\Windows\System32\dwmapi.dll | |
11/2/2020 - 13:45:42.840 | Open | 1480 | C:\malware.exe | C:\Windows\System32\dwmapi.dll | |
11/2/2020 - 13:45:42.840 | Open | 1480 | C:\malware.exe | C:\Windows\System32\ole32.dll | |
11/2/2020 - 13:45:42.840 | Open | 1480 | C:\malware.exe | C:\Windows\System32\ole32.dll | |
11/2/2020 - 13:45:42.840 | Open | 1480 | C:\malware.exe | C:\Windows\System32\rpcss.dll | |
11/2/2020 - 13:45:42.840 | Open | 1480 | C:\malware.exe | C:\Windows\System32\rpcss.dll | |
11/2/2020 - 13:45:42.840 | Open | 1480 | C:\malware.exe | C:\Windows\System32\rpcss.dll | |
11/2/2020 - 13:45:42.840 | Open | 1480 | C:\malware.exe | C:\Windows\System32\rpcss.dll | |
11/2/2020 - 13:45:42.840 | Open | 1480 | C:\malware.exe | C:\CRYPTBASE.dll | |
11/2/2020 - 13:45:42.840 | Open | 1480 | C:\malware.exe | C:\Windows\System32\cryptbase.dll | |
11/2/2020 - 13:45:42.840 | Unknown | 1480 | C:\malware.exe | C:\Windows\System32\cryptbase.dll | cryptbase.dll |
11/2/2020 - 13:45:42.840 | Open | 1480 | C:\malware.exe | C:\Windows\System32\cryptbase.dll | |
11/2/2020 - 13:45:42.840 | Unknown | 1480 | C:\malware.exe | C:\Windows\System32\cryptbase.dll | cryptbase.dll |
11/2/2020 - 13:45:42.840 | Open | 1480 | C:\malware.exe | C:\Windows\Globalization\Sorting\SortDefault.nls | |
11/2/2020 - 13:45:42.840 | Unknown | 1480 | C:\malware.exe | C:\Windows\Globalization\Sorting\SortDefault.nls | SortDefault.nls |
Process
Trace
Analysis
Reason
Timeout
Status
Sucessfully Executed
Results
1
Registry
Trace
File Summary
Created
Identified: False cancel
Deleted
Identified: False cancel
Process Summary
Created
Identified: False cancel
Deleted
Identified: False cancel
Registry Summary
Proxy
Identified: False cancel
AutoRun
Identified: False cancel
Created
Identified: False cancel
Deleted
Identified: False cancel
Browsers
Identified: False cancel
Internet
Identified: False cancel
Loading...
DNS
Query
Response
TCP
Info
UDP
Info
HTTP
Info
Summary
DNS
False cancel
TCP
False cancel
UDP
False cancel
HTTP
False cancel
Results
BINARY
KNN (K=3, NFS-BRMalware)
confidence: 66.67%suspicious: False cancel
Decision Tree (NFS-BRMalware)
confidence: 100.00%suspicious: True check_circle
SVC (Kernel=Linear, NFS-BRMalware)
confidence: 70.17%suspicious: False cancel
MalConv (Ember: Raw Bytes, Threshold=0.5)
confidence: 85.63%suspicious: False cancel
Random Forest (100 estimators, NFS-BRMalware)
confidence: 60.00%suspicious: True check_circle
Non-Negative MalConv (Ember: Raw Bytes, Threshold=0.35)
confidence: 36.40%suspicious: True check_circle
LightGDM (Ember: File Characteristics, Threshold=0.8336)
confidence: 99.97%suspicious: False cancel