Report #6340 check_circle

  • Creation Date: Feb. 17, 2020, 12:20 p.m.
  • Last Update: Feb. 17, 2020, 12:33 p.m.
  • File: DjINehIBta.exe
  • Results:
Binary
DLL
False cancel
Size
3.00MB
trid
35.7% Win32 Executable
16.4% Win16/32 Executable Delphi generic
16.0% OS/2 Executable
15.8% Generic Win/DOS Executable
15.8% DOS Executable Generic
type
PE
wordsize
0
Subsystem
unknown
Hashes
md5
7f82a91ce1c1dd4ab90f256faf670be4
sha1
4630a949a7775f58620e310479af530d039922b3
crc32
0x17f0fd00
sha224
8d1fd9a72c0879e19df9ab1e46b3877e0f8273a44ef409f1009809bf
sha256
e0ffa8da727cd158c06e0d42fa27eee3d159eb2770b48b843ae04cd459f2458c
sha384
d400491ee9c0c42a1aad103833f038e2789a9c7a952b7183e7306aaf25917262057356a254d2dbb75bad7fadd5740597
sha512
c945a236b975aafc4f60e557147a3e9b6eb37e4aaeec137e07a375e2144c767c8e266531f1af84a27fc81ff7a5c6230e66b0df37c80fde1385853cb06af5ce27
ssdeep
49152:E1m5PCzhk5TwZrUXyIiQhsJL0ZqF0iP8KfJx1V1DHUnLcvxtyaXaV4eqofbAcF9P:KmtWcSzfQhZfiP8sBjvxhXadqofMcF7
Community
Google
False cancel
HashLib
False cancel
YARA
Matches
HasModified_DOS_Message, domain, HasDigitalSignature, screenshot, url, contentis_base64, win_registry, IsPacked, HasOverlay, Big_Numbers1, IsPE32, IsWindowsGUI, FSG_v110_Eng_dulekxt_

Suspicious
True check_circle

Strings
List
;http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q
2http://crl.comodoca.com/COMODORSACodeSigningCA.crl0t
2http://crt.comodoca.com/COMODORSACodeSigningCA.crt0$
/http://crt.comodoca.com/COMODORSAAddTrustCA.crt0$
https://secure.comodo.net/CPS0C
%http://crl.globalsign.net/root-r3.crl0
<http://secure.globalsign.com/cacert/gstimestampingsha2g2.crt0
5http://crl.globalsign.com/gs/gstimestampingsha2g2.crl0X
3http://crl.usertrust.com/AddTrustExternalCARoot.crl05
https://www.youtube.com/0
&https://www.globalsign.com/repository/0
&https://www.globalsign.com/repository/06
ehttp://pki-crl.symauth.com/offlineca/TheInstituteofElectricalandElectronicsEngineersIncIEEERootCA.crl0
yu.iL
D.Kh.GT
iu.LB
http://ocsp.comodoca.com0
http://ocsp.comodoca.com0
Lhttp://pki-crl.symauth.com/ca_219679623e6b4fa507d638cbeba72ecb/LatestCRL.crl07
N.nE
J.al
_.Do
-I.CK
l.pA
i.fK
S.gg
U.cy
N3.Hk
P.nU
2.BLoG
SKTX.ml
|shell32.dll
C.BZ
O.ZW
Z.hu
zP.aU
A.zm
S.iS
Aw.tZ
FUz.ml
http://ocsp.usertrust.com0
wsock32.dll
windowscodecs.dll
WTSAPI32.dll
winspool.drv
wtsapi32.dll
comctl32.dll
msimg32.dll
si&user32.dll
version.dll
uxtheme.dll
Counts.dll
winmm.dll
SHFolder.dll
1%2,232:2A2H2O2V2]2d2n2v2
%/50
*.wMw4aS@
I40A'd
}hN-D
%/tnB
@=%/
"%/+
\?%-
sRm*
RdAd+
T<AIFh
(cTMFh
2O1aP
2%n&\=aw
%s#7<Dl2
L8%oc
9_%pths
H1ai
K6%A$yt
7@+uT%i
=su'9%A
5Te=%Ak
`%%35
@%i9~a
%e7H!
%E02?
%i|aU4
%Fi&HC'&
#}B%iF^*S
1%1A1U1t1
%9geR
9%EFh
%er6Ad
&r%n%
_~%si
`<h*%e
%I%n(;
_%E`E
%Ea|V
I[a%n
%AT|;
AO%c;
I:%to
.D%nU}
caN6%FL

Foremost
Matches
0.exe, 2 MB
Suspicious
True check_circle
Heuristics
IPs
hasIPs: False cancel
Allowed
Suspicious
hasAllowed: False cancel
hasSuspicious: False cancel

URLs
Allowed
hasURLs: False cancel
Suspicious
hasAllowed: False cancel
hasSuspicious: False cancel

Files
Allowed
hasFiles: False cancel
Suspicious
hasAllowed: False cancel
hasSuspicious: False cancel

Binary
Sizes
RVA
RVA: 16
Suspicious: False cancel
Code
Size: 1044480
Suspicious: False cancel
Image
Address: 13107200
Suspicious: False cancel
Stack
Stack: 16384
Suspicious: False cancel
Headers
Headers: 1536
Suspicious: False cancel
Suspicious: False cancel

Symbols
Number
Number: 0
Suspicious: True check_circle
Pointer
Pointer: 0
Suspicious: True check_circle
Directories
Number: 16
Suspicious: False cancel

Checksum
Value: 3196146
Suspicous: False cancel

Sections
Allowed: .text, .itext, .data, .bss, .idata, .didata, .tls, .rdata, .vmp0, .vmp1, .newimp, .vmp2, .vmp3, .reloc
Suspicious
hasAllowed: True check_circle
hasSections: True check_circle
hasSuspicious: False cancel

Versions
OS
Version: 5
Suspicious: False cancel
Image
Version: True check_circle
Suspicious: 5
Linker
Version: 2.25
Suspicious: False cancel
Subsystem
Version: 5.0
Suspicious: False cancel
Suspicious: False cancel

EntryPoint
Address: 5759193
Suspicious: False cancel

Anomalies
Anomalies
hasAnomalies: False cancel

Libraries
Allowed
hasLibs: False cancel
Suspicious
hasAllowed: False cancel
hasSuspicious: False cancel

Timestamp
Past: False cancel
Valid: False cancel
Value: 0
Future: False cancel

Compilation
Packed: False cancel
Missing: True check_circle
Packers
Compiled: False cancel
Compilers

Obfuscation
XOR: False cancel
Fuzzing: False cancel

PEDetector
Matches
None
Suspicious
False cancel
Disassembly
hasTricks
False cancel
Tricks
AVclass
banload
1
VirusTotal
md5
7f82a91ce1c1dd4ab90f256faf670be4
sha1
4630a949a7775f58620e310479af530d039922b3
SCANS (DETECTION RATE = 62.32%)
AVG
result: Win32:DangerousSig [Trj]
update: 20181005
version: 18.4.3895.0
detected: True check_circle

CMC
update: 20181004
version: 1.1.0.977
detected: False cancel

MAX
result: malware (ai score=89)
update: 20181005
version: 2018.9.12.1
detected: True check_circle

Bkav
update: 20181003
version: 1.3.0.9898
detected: False cancel

K7GW
result: Unwanted-Program ( 005146e21 )
update: 20181003
version: 11.6.28590
detected: True check_circle

ALYac
result: Trojan.GenericKD.30425240
update: 20181004
version: 1.1.1.5
detected: True check_circle

Avast
result: Win32:DangerousSig [Trj]
update: 20181005
version: 18.4.3895.0
detected: True check_circle

Avira
result: TR/Black.Gen2
update: 20181004
version: 8.3.3.6
detected: True check_circle

Baidu
update: 20180930
version: 1.0.0.2
detected: False cancel

Cyren
result: W32/Trojan.CLYH-8710
update: 20181005
version: 6.0.0.4
detected: True check_circle

DrWeb
result: Trojan.PWS.Banker1.22805
update: 20181005
version: 7.0.33.6080
detected: True check_circle

GData
result: Trojan.GenericKD.30425240
update: 20181005
version: A:25.18773B:25.13369
detected: True check_circle

Panda
result: Trj/CI.A
update: 20181004
version: 4.6.4.2
detected: True check_circle

VBA32
result: TScope.Malware-Cryptor.SB
update: 20181004
version: 3.33.0
detected: True check_circle

VIPRE
result: Trojan.Win32.Generic!BT
update: 20181005
version: 70058
detected: True check_circle

Zoner
update: 20181004
version: 1.0
detected: False cancel

AVware
result: Trojan.Win32.Generic!BT
update: 20180925
version: 1.6.0.52
detected: True check_circle

ClamAV
update: 20181004
version: 0.100.2.0
detected: False cancel

Comodo
result: CloudScanner.Trojan.Gen
update: 20181005
version: 29775
detected: True check_circle

F-Prot
update: 20181005
version: 4.7.1.166
detected: False cancel

Ikarus
result: Trojan.Win32.VMProtect
update: 20181004
version: 0.1.5.2
detected: True check_circle

McAfee
result: Packed-GV!7F82A91CE1C1
update: 20181005
version: 6.0.6.653
detected: True check_circle

Rising
result: Downloader.Banload!8.15B (CLOUD)
update: 20181005
version: 25.0.0.24
detected: True check_circle

Sophos
result: Mal/Generic-S
update: 20181004
version: 4.98.0
detected: True check_circle

Yandex
result: Trojan.Agent!9V/umsq2QPA
update: 20181004
version: 5.5.1.3
detected: True check_circle

Zillya
result: Downloader.BanloadCRTD.Win32.11978
update: 20181003
version: 2.0.0.3661
detected: True check_circle

Alibaba
update: 20180921
version: 0.1.0.2
detected: False cancel

Arcabit
result: Trojan.Generic.D1D04098
update: 20181004
version: 1.0.0.833
detected: True check_circle

Babable
update: 20180918
version: 9107201
detected: False cancel

Cylance
result: Unsafe
update: 20181005
version: 2.3.1.101
detected: True check_circle

Endgame
result: malicious (high confidence)
update: 20180730
version: 3.0.1
detected: True check_circle

TACHYON
update: 20181005
version: 2018-10-04.02
detected: False cancel

Tencent
result: Win32.Trojan.Symmi.Aliw
update: 20181005
version: 1.0.0.1
detected: True check_circle

ViRobot
update: 20181004
version: 2014.3.20.0
detected: False cancel

Webroot
update: 20181005
version: 1.0.0.403
detected: False cancel

eGambit
update: 20181005
detected: False cancel

Ad-Aware
result: Trojan.GenericKD.30425240
update: 20181005
version: 3.0.5.370
detected: True check_circle

AegisLab
update: 20181004
version: 4.2
detected: False cancel

Emsisoft
result: Trojan-Spy.Banker (A)
update: 20181005
version: 2018.4.0.1029
detected: True check_circle

F-Secure
result: Trojan.GenericKD.30425240
update: 20181004
version: 11.0.19100.45
detected: True check_circle

Fortinet
result: W32/Generic.GV!tr
update: 20181005
version: 5.4.247.0
detected: True check_circle

Invincea
result: heuristic
update: 20180717
version: 6.3.5.26121
detected: True check_circle

Jiangmin
update: 20181004
version: 16.0.100
detected: False cancel

Kingsoft
update: 20181005
version: 2013.8.14.323
detected: False cancel

Paloalto
result: generic.ml
update: 20181005
version: 1.0
detected: True check_circle

Symantec
result: Trojan.Gen.2
update: 20181004
version: 1.7.0.0
detected: True check_circle

AhnLab-V3
result: Malware/Win32.Generic.C2016424
update: 20181004
version: 3.13.1.21616
detected: True check_circle

Antiy-AVL
result: Trojan/Win32.AGeneric
update: 20181005
version: 3.0.0.1
detected: True check_circle

Kaspersky
result: HEUR:Trojan.Win32.Generic
update: 20181005
version: 15.0.1.13
detected: True check_circle

Microsoft
result: TrojanDownloader:Win32/Banload
update: 20181004
version: 1.1.15300.6
detected: True check_circle

Qihoo-360
result: Win32/Trojan.9ad
update: 20181005
version: 1.0.0.1120
detected: True check_circle

TheHacker
update: 20181001
version: 6.8.0.5.3723
detected: False cancel

ZoneAlarm
result: HEUR:Trojan.Win32.Generic
update: 20181004
version: 1.0
detected: True check_circle

Cybereason
update: 20180225
version: 1.2.27
detected: False cancel

ESET-NOD32
result: a variant of Win32/Packed.VMProtect.AB
update: 20181005
version: 18162
detected: True check_circle

TrendMicro
update: 20181004
version: 10.0.0.1040
detected: False cancel

BitDefender
result: Trojan.GenericKD.30425240
update: 20181004
version: 7.2
detected: True check_circle

CrowdStrike
update: 20180723
version: 1.0
detected: False cancel

K7AntiVirus
result: Unwanted-Program ( 005146e21 )
update: 20181004
version: 11.6.28608
detected: True check_circle

SentinelOne
update: 20180926
version: 1.0.19.242
detected: False cancel

Avast-Mobile
update: 20181004
version: 181004-00
detected: False cancel

Malwarebytes
update: 20181005
version: 2.1.1.1115
detected: False cancel

TotalDefense
update: 20181004
version: 37.1.62.1
detected: False cancel

CAT-QuickHeal
update: 20181004
version: 14.00
detected: False cancel

NANO-Antivirus
result: Trojan.Win32.Banker1.eqhssa
update: 20181004
version: 1.0.134.24036
detected: True check_circle

MicroWorld-eScan
result: Trojan.GenericKD.30425240
update: 20181005
version: 14.0.297.0
detected: True check_circle

SUPERAntiSpyware
update: 20181004
version: 5.6.0.1032
detected: False cancel

McAfee-GW-Edition
result: Packed-GV!7F82A91CE1C1
update: 20181004
version: v2017.3010
detected: True check_circle

TrendMicro-HouseCall
update: 20181005
version: 10.0.0.1040
detected: False cancel

total
69
sha256
e0ffa8da727cd158c06e0d42fa27eee3d159eb2770b48b843ae04cd459f2458c
scan_id
e0ffa8da727cd158c06e0d42fa27eee3d159eb2770b48b843ae04cd459f2458c-1538699771
resource
7f82a91ce1c1dd4ab90f256faf670be4
positives
43
scan_date
2018-10-05 00:36:11
verbose_msg
Scan finished, information embedded
response_code
1
File
Trace

Process
Trace

Analysis
Reason
Blue Screen

Status
Execution Failed

Results
0

Registry
Trace

File Summary
Created
Identified: False cancel

Deleted
Identified: False cancel

Process Summary
Created
Identified: False cancel

Deleted
Identified: False cancel

Registry Summary
Proxy
Identified: False cancel

AutoRun
Identified: False cancel

Created
Identified: False cancel

Deleted
Identified: False cancel

Browsers
Identified: False cancel

Internet
Identified: False cancel

Loading...

DNS
Query

Response

TCP
Info

UDP
Info

HTTP
Info

Summary
DNS
False cancel

TCP
False cancel

UDP
False cancel

HTTP
False cancel

Results
BINARY
KNN (K=3, NFS-BRMalware)
confidence: 100.00%
suspicious: True check_circle

Decision Tree (NFS-BRMalware)
confidence: 100.00%
suspicious: True check_circle

SVC (Kernel=Linear, NFS-BRMalware)
confidence: 95.56%
suspicious: True check_circle

MalConv (Ember: Raw Bytes, Threshold=0.5)
confidence: 65.73%
suspicious: False cancel

Random Forest (100 estimators, NFS-BRMalware)
confidence: 77.00%
suspicious: True check_circle

Non-Negative MalConv (Ember: Raw Bytes, Threshold=0.35)
confidence: 53.88%
suspicious: True check_circle

LightGDM (Ember: File Characteristics, Threshold=0.8336)
confidence: 25.05%
suspicious: False cancel

Add to Collection
Download