Report #9524 cancel

  • Creation Date: March 12, 2020, 12:53 p.m.
  • Last Update: March 12, 2020, 4:30 p.m.
  • File: Comentario.de.voz.exe
  • Results:
AVclass
banload
1
VirusTotal
md5
fb3bb425b33efeaf474c6aa0d7b3f553
sha1
b652dccde69b879065f9bce79feff8a7356fbf10
SCANS (DETECTION RATE = 74.24%)
AVG
result: Win32:Dropper-gen [Drp]
update: 20180325
version: 18.2.3827.0
detected: True check_circle

CMC
update: 20180324
version: 1.1.0.977
detected: False cancel

MAX
result: malware (ai score=86)
update: 20180325
version: 2017.11.15.1
detected: True check_circle

Bkav
result: W32.DownloadLeodon.Trojan
update: 20180325
version: 1.3.0.9466
detected: True check_circle

K7GW
result: Riskware ( 0040eff71 )
update: 20180325
version: 10.42.26600
detected: True check_circle

ALYac
result: Gen:Variant.Symmi.79654
update: 20180325
version: 1.1.1.5
detected: True check_circle

Avast
result: Win32:Dropper-gen [Drp]
update: 20180325
version: 18.2.3827.0
detected: True check_circle

Avira
result: TR/Leodon.A
update: 20180324
version: 8.3.3.6
detected: True check_circle

Baidu
result: Win32.Trojan.WisdomEyes.16070401.9500.9999
update: 20180323
version: 1.0.0.2
detected: True check_circle

Cyren
result: W32/Injector.WQZL-5372
update: 20180325
version: 5.4.30.7
detected: True check_circle

DrWeb
result: Trojan.DownLoader10.27009
update: 20180325
version: 7.0.28.2020
detected: True check_circle

GData
result: Gen:Variant.Symmi.79654
update: 20180325
version: A:25.16493B:25.11870
detected: True check_circle

Panda
result: Generic Malware
update: 20180324
version: 4.6.4.2
detected: True check_circle

VBA32
result: Malware-Cryptor.Inject.gen
update: 20180323
version: 3.12.28.0
detected: True check_circle

VIPRE
result: Trojan.Win32.Generic!BT
update: 20180325
version: 65504
detected: True check_circle

Zoner
update: 20180325
version: 1.0
detected: False cancel

AVware
result: Trojan.Win32.Generic!BT
update: 20180325
version: 1.5.0.42
detected: True check_circle

ClamAV
update: 20180324
version: 0.99.2.0
detected: False cancel

Comodo
update: 20180325
detected: False cancel

F-Prot
result: W32/Injector.FLD
update: 20180325
version: 4.7.1.166
detected: True check_circle

Ikarus
result: Backdoor.Win32.Rbot
update: 20180324
version: 0.1.5.2
detected: True check_circle

McAfee
result: Generic.dx!FB3BB425B33E
update: 20180325
version: 6.0.6.653
detected: True check_circle

Rising
result: Malware.Undefined!8.C (TFE:4:ZGDnaXKdyAN)
update: 20180325
version: 25.0.0.1
detected: True check_circle

Sophos
result: Troj/DwnLdr-LKC
update: 20180325
version: 4.98.0
detected: True check_circle

Yandex
result: Trojan.Inject!qhWXyLBClL8
update: 20180324
version: 5.5.1.3
detected: True check_circle

Zillya
update: 20180323
version: 2.0.0.3519
detected: False cancel

Arcabit
update: 20180325
version: 1.0.0.831
detected: False cancel

Cylance
result: Unsafe
update: 20180325
version: 2.3.1.101
detected: True check_circle

Endgame
result: malicious (moderate confidence)
update: 20180316
version: 2.0.5
detected: True check_circle

Tencent
result: Win32.Trojan.Inject.Ednn
update: 20180325
version: 1.0.0.1
detected: True check_circle

ViRobot
update: 20180324
version: 2014.3.20.0
detected: False cancel

eGambit
update: 20180325
version: v4.3.5
detected: False cancel

Ad-Aware
result: Gen:Variant.Symmi.79654
update: 20180325
version: 3.0.3.1010
detected: True check_circle

AegisLab
result: Troj.W32.Inject.ilvo!c
update: 20180325
version: 4.2
detected: True check_circle

Emsisoft
result: Gen:Variant.Symmi.79654 (B)
update: 20180325
version: 4.0.2.899
detected: True check_circle

F-Secure
result: Gen:Variant.Symmi.79654
update: 20180325
version: 11.0.19100.45
detected: True check_circle

Fortinet
result: W32/Injector.fam!tr
update: 20180325
version: 5.4.247.0
detected: True check_circle

Invincea
result: heuristic
update: 20180121
version: 6.3.4.26036
detected: True check_circle

Jiangmin
result: Trojan/Inject.arpk
update: 20180325
version: 16.0.100
detected: True check_circle

Kingsoft
update: 20180325
version: 2013.8.14.323
detected: False cancel

Paloalto
result: generic.ml
update: 20180325
version: 1.0
detected: True check_circle

Symantec
result: Trojan.ADH
update: 20180324
version: 1.5.0.0
detected: True check_circle

nProtect
update: 20180325
version: 2018-03-25.01
detected: False cancel

AhnLab-V3
result: Trojan/Win32.Banload.C284656
update: 20180324
version: 3.12.0.20130
detected: True check_circle

Antiy-AVL
result: Trojan/Win32.Inject
update: 20180325
version: 3.0.0.1
detected: True check_circle

Kaspersky
result: HEUR:Trojan.Win32.Generic
update: 20180325
version: 15.0.1.13
detected: True check_circle

Microsoft
update: 20180325
version: 1.1.14600.4
detected: False cancel

Qihoo-360
result: Win32/Trojan.455
update: 20180325
version: 1.0.0.1120
detected: True check_circle

TheHacker
update: 20180319
version: 6.8.0.5.2551
detected: False cancel

ZoneAlarm
result: HEUR:Trojan.Win32.Generic
update: 20180325
version: 1.0
detected: True check_circle

ESET-NOD32
result: Win32/TrojanDownloader.Banload.SPT
update: 20180325
version: 17111
detected: True check_circle

TrendMicro
result: TROJ_GEN.R002C0PBF18
update: 20180325
version: 9.862.0.1074
detected: True check_circle

WhiteArmor
update: 20180324
detected: False cancel

BitDefender
result: Gen:Variant.Symmi.79654
update: 20180325
version: 7.2
detected: True check_circle

CrowdStrike
result: malicious_confidence_80% (W)
update: 20170201
version: 1.0
detected: True check_circle

K7AntiVirus
result: Riskware ( 0040eff71 )
update: 20180325
version: 10.42.26601
detected: True check_circle

SentinelOne
result: static engine - malicious
update: 20180225
version: 1.0.15.206
detected: True check_circle

Avast-Mobile
update: 20180324
version: 180324-00
detected: False cancel

Malwarebytes
update: 20180324
version: 2.1.1.1115
detected: False cancel

TotalDefense
update: 20180324
version: 37.1.62.1
detected: False cancel

CAT-QuickHeal
result: Trojan.Generic
update: 20180324
version: 14.00
detected: True check_circle

NANO-Antivirus
result: Trojan.Win32.Inject.cuytdv
update: 20180325
version: 1.0.100.22043
detected: True check_circle

MicroWorld-eScan
result: Gen:Variant.Symmi.79654
update: 20180325
version: 14.0.297.0
detected: True check_circle

SUPERAntiSpyware
update: 20180324
version: 5.6.0.1032
detected: False cancel

McAfee-GW-Edition
result: Generic.dx!FB3BB425B33E
update: 20180324
version: v2015
detected: True check_circle

TrendMicro-HouseCall
result: TROJ_GEN.R002C0PBF18
update: 20180324
version: 9.950.0.1006
detected: True check_circle

total
66
sha256
942862d9de4477c51b4060cc5b79f9103c2838cf9eae7fe68df9f8621be62e89
scan_id
942862d9de4477c51b4060cc5b79f9103c2838cf9eae7fe68df9f8621be62e89-1521947400
resource
fb3bb425b33efeaf474c6aa0d7b3f553
positives
49
scan_date
2018-03-25 03:10:00
verbose_msg
Scan finished, information embedded
response_code
1
File
Trace
12/3/2020 - 15:45:43.59Unknown1480C:\malware.exeC:\Windows
12/3/2020 - 15:45:43.59Unknown1480C:\malware.exeC:\Monitor
12/3/2020 - 15:45:43.59Unknown1480C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc
12/3/2020 - 15:45:43.59Unknown1480C:\malware.exeC:\Windows\Fonts\StaticCache.datStaticCache.dat

Process
Trace

Analysis
Reason
Finished

Status
Sucessfully Executed

Results
1

Registry
Trace

File Summary
Created
Identified: False cancel

Deleted
Identified: False cancel

Process Summary
Created
Identified: False cancel

Deleted
Identified: False cancel

Registry Summary
Proxy
Identified: False cancel

AutoRun
Identified: False cancel

Created
Identified: False cancel

Deleted
Identified: False cancel

Browsers
Identified: False cancel

Internet
Identified: False cancel

DNS
Query
computer localhost arrow_forward computer gateway:50273 code pfa17.fr.
computer localhost arrow_forward computer gateway:50043 code isrg.trustid.ocsp.identrust.com.
computer localhost arrow_forward computer gateway:DNS code angeriennes.le-choix-funeraire.com.
computer localhost arrow_forward computer gateway:DNS code isrg.trustid.ocsp.identrust.com.
computer localhost arrow_forward computer gateway:59829 code apps.identrust.com.
computer localhost arrow_forward computer gateway:49551 code crl.identrust.com.
computer localhost arrow_forward computer gateway:DNS code ocsp.int-x3.letsencrypt.org.
computer localhost arrow_forward computer gateway:DNS code pfa17.fr.
computer localhost arrow_forward computer gateway:54285 code dns.msftncsi.com.
computer localhost arrow_forward computer gateway:DNS code apps.identrust.com.
computer localhost arrow_forward computer gateway:51595 code ocsp.int-x3.letsencrypt.org.
computer localhost arrow_forward computer gateway:DNS code crl.identrust.com.
computer localhost arrow_forward computer gateway:DNS code dns.msftncsi.com.

Response
computer gateway:DNS arrow_forward computer localhost code isrg.trustid.ocsp.identrust.com. reply_all 186.192.152.219

computer gateway:DNS arrow_forward computer localhost code crl.identrust.com. reply_all 192.35.177.64

computer gateway:DNS arrow_forward computer localhost code pfa17.fr. reply_all 185.31.40.131

computer gateway:DNS arrow_forward computer localhost code angeriennes.le-choix-funeraire.com. reply_all 185.31.40.131

computer gateway:DNS arrow_forward computer localhost code apps.identrust.com. reply_all 192.35.177.64

computer gateway:DNS arrow_forward computer localhost code dns.msftncsi.com. reply_all 131.107.255.255

computer gateway:DNS arrow_forward computer localhost code ocsp.int-x3.letsencrypt.org. reply_all 186.192.152.218


TCP
Info
computer localhost:65195 arrow_forward 192.35.177.64:80
185.31.40.131:443 arrow_forward computer localhost:65192
computer localhost:65191 arrow_forward 185.31.40.131:80
192.35.177.64:80 arrow_forward computer localhost:65195
186.192.152.200:80 arrow_forward computer localhost:65194
185.31.40.131:80 arrow_forward computer localhost:65191
computer localhost:65193 arrow_forward 192.35.177.64:80
computer localhost:65192 arrow_forward 185.31.40.131:443
computer localhost:65194 arrow_forward 186.192.152.200:80
186.192.152.75:80 arrow_forward computer localhost:65196
192.35.177.64:80 arrow_forward computer localhost:65193
computer localhost:65196 arrow_forward 186.192.152.75:80

UDP
Info
computer localhost:51595 arrow_forward computer localhost:53
computer localhost:49551 arrow_forward computer localhost:53
computer localhost:55394 arrow_forward computer localhost:53
computer localhost:53 arrow_forward computer localhost:59829
computer localhost:54285 arrow_forward computer localhost:53
computer localhost:53 arrow_forward computer localhost:51595
computer localhost:53 arrow_forward computer localhost:49551
computer localhost:50273 arrow_forward computer localhost:53
computer localhost:53 arrow_forward computer localhost:50043
computer localhost:53 arrow_forward computer localhost:50273
computer localhost:50043 arrow_forward computer localhost:53
computer localhost:53 arrow_forward computer localhost:54285
computer localhost:53 arrow_forward computer localhost:55394
computer localhost:59829 arrow_forward computer localhost:53
computer localhost:67 arrow_forward computer localhost:68
computer localhost:68 arrow_forward help_outline 255.255.255.255:67

HTTP
Info
computer localhost send GET apps.identrust.com attach_file /roots/dstrootcax3.p7c
computer localhost send GET pfa17.fr attach_file /Javar.exe
computer localhost send GET isrg.trustid.ocsp.identrust.com attach_file /MFEwTzBNMEswSTAJBgUrDgMCGgUABBRv9GhNQxLSSGKBnMArPUcsHYovpgQUxKexpHsscfrb4UuQdf%2FEFWCFiRACEAoBQUIAAAFThXNqC4Xspwg%3D
computer localhost send GET ocsp.int-x3.letsencrypt.org attach_file /MFMwUTBPME0wSzAJBgUrDgMCGgUABBR%2B5mrncpqz%2FPiiIGRsFqEtYHEIXQQUqEpqYwR93brm0Tm3pkVl7%2FOo7KECEgO4ruvXxHfKl5EwKGhECOzlwQ%3D%3D
computer localhost send GET crl.identrust.com attach_file /DSTROOTCAX3CRL.crl

Summary
DNS
True check_circle

TCP
True check_circle

UDP
True check_circle

HTTP
True check_circle

Results
BINARY
KNN (K=3, NFS-BRMalware)
confidence: 100.00%
suspicious: True check_circle

Decision Tree (NFS-BRMalware)
confidence: 100.00%
suspicious: True check_circle

SVC (Kernel=Linear, NFS-BRMalware)
confidence: 61.23%
suspicious: False cancel

MalConv (Ember: Raw Bytes, Threshold=0.5)
confidence: 59.00%
suspicious: False cancel

Random Forest (100 estimators, NFS-BRMalware)
confidence: 64.00%
suspicious: True check_circle

Non-Negative MalConv (Ember: Raw Bytes, Threshold=0.35)
confidence: 38.05%
suspicious: True check_circle

LightGDM (Ember: File Characteristics, Threshold=0.8336)
confidence: 99.84%
suspicious: True check_circle