Report #9529 cancel

AVclass
banload
1
VirusTotal
md5
7ac7f1986b6ce19a97b7c4647edc0c83
sha1
9dca3bf02cadd64f379b52471dff66697fa0b1fc
SCANS (DETECTION RATE = 66.67%)
AVG
result: Win32:Dropper-gen [Drp]
update: 20200110
version: 18.4.3895.0
detected: True check_circle

CMC
update: 20190321
version: 1.1.0.977
detected: False cancel

MAX
result: malware (ai score=99)
update: 20200111
version: 2019.9.16.1
detected: True check_circle

APEX
update: 20200110
version: 5.104
detected: False cancel

Bkav
update: 20200110
version: 1.3.0.9899
detected: False cancel

K7GW
result: Trojan-Downloader ( 004d63041 )
update: 20200110
version: 11.86.33014
detected: True check_circle

ALYac
result: Trojan.Generic.11623760
update: 20200110
version: 1.1.1.5
detected: True check_circle

Avast
result: Win32:Dropper-gen [Drp]
update: 20200110
version: 18.4.3895.0
detected: True check_circle

Avira
result: HEUR/AGEN.1003864
update: 20200110
version: 8.3.3.8
detected: True check_circle

Baidu
update: 20190318
version: 1.0.0.2
detected: False cancel

Cyren
update: 20200110
version: 6.2.2.2
detected: False cancel

DrWeb
result: Trojan.PWS.Banker1.14975
update: 20200110
version: 7.0.42.9300
detected: True check_circle

GData
result: Trojan.Generic.11623760
update: 20200110
version: A:25.24529B:26.17309
detected: True check_circle

Panda
result: Trj/CI.A
update: 20200110
version: 4.6.4.2
detected: True check_circle

VBA32
result: TrojanPSW.Banker
update: 20200110
version: 4.3.0
detected: True check_circle

VIPRE
result: Trojan.Win32.Generic!BT
update: 20200110
version: 80684
detected: True check_circle

Zoner
update: 20200109
version: 1.0.0.1
detected: False cancel

ClamAV
update: 20200110
version: 0.102.1.0
detected: False cancel

Comodo
result: Malware@#2p9vndurymv5p
update: 20200110
version: 31946
detected: True check_circle

F-Prot
update: 20200110
version: 4.7.1.166
detected: False cancel

Ikarus
result: Trojan-Downloader.Win32.Banload
update: 20200110
version: 0.1.5.2
detected: True check_circle

McAfee
result: Artemis!7AC7F1986B6C
update: 20200110
version: 6.0.6.653
detected: True check_circle

Rising
result: Downloader.Banload!8.15B (TFE:4:D1HU2FE5M9S)
update: 20200110
version: 25.0.0.24
detected: True check_circle

Sophos
update: 20200110
version: 4.98.0
detected: False cancel

Yandex
result: Trojan.DL.Banload!M2J0EPuapSI
update: 20200110
version: 5.5.2.24
detected: True check_circle

Zillya
result: Downloader.Banload.Win32.58529
update: 20200110
version: 2.0.0.3994
detected: True check_circle

Acronis
result: suspicious
update: 20200107
version: 1.1.1.58
detected: True check_circle

Alibaba
update: 20190527
version: 0.3.0.5
detected: False cancel

Arcabit
result: Trojan.Generic.DB15D50
update: 20200110
version: 1.0.0.869
detected: True check_circle

Cylance
result: Unsafe
update: 20200111
version: 2.3.1.101
detected: True check_circle

Endgame
result: malicious (high confidence)
update: 20190918
version: 3.0.15
detected: True check_circle

FireEye
result: Generic.mg.7ac7f1986b6ce19a
update: 20200110
version: 29.7.0.0
detected: True check_circle

Sangfor
result: Malware
update: 20200107
version: 1.0
detected: True check_circle

TACHYON
update: 20200110
version: 2020-01-10.02
detected: False cancel

Tencent
update: 20200111
version: 1.0.0.1
detected: False cancel

ViRobot
update: 20200110
version: 2014.3.20.0
detected: False cancel

Webroot
update: 20200111
version: 1.0.0.403
detected: False cancel

eGambit
result: Generic.PSW
update: 20200111
detected: True check_circle

Ad-Aware
result: Trojan.Generic.11623760
update: 20200110
version: 3.0.5.370
detected: True check_circle

AegisLab
result: Trojan.Multi.Generic.4!c
update: 20200110
version: 4.2
detected: True check_circle

Emsisoft
result: Trojan.Generic.11623760 (B)
update: 20200110
version: 2018.12.0.1641
detected: True check_circle

F-Secure
result: Heuristic.HEUR/AGEN.1003864
update: 20200110
version: 12.0.86.52
detected: True check_circle

Fortinet
update: 20200110
version: 6.2.137.0
detected: False cancel

Invincea
result: heuristic
update: 20191211
version: 6.3.6.26157
detected: True check_circle

Jiangmin
update: 20200110
version: 16.0.100
detected: False cancel

Kingsoft
update: 20200111
version: 2013.8.14.323
detected: False cancel

Paloalto
result: generic.ml
update: 20200111
version: 1.0
detected: True check_circle

Trapmine
result: suspicious.low.ml.score
update: 20191216
version: 3.2.16.890
detected: True check_circle

AhnLab-V3
update: 20200110
version: 3.17.0.26111
detected: False cancel

Antiy-AVL
result: Trojan[Downloader]/Win32.Banload
update: 20200110
version: 3.0.0.1
detected: True check_circle

Kaspersky
result: UDS:DangerousObject.Multi.Generic
update: 20200110
version: 15.0.1.13
detected: True check_circle

MaxSecure
update: 20200108
version: 1.0.0.1
detected: False cancel

Microsoft
result: Trojan:Win32/Wacatac.B!ml
update: 20200110
version: 1.1.16600.7
detected: True check_circle

Qihoo-360
result: Trojan.Generic
update: 20200111
version: 1.0.0.1120
detected: True check_circle

ZoneAlarm
result: UDS:DangerousObject.Multi.Generic
update: 20200110
version: 1.0
detected: True check_circle

Cybereason
result: malicious.86b6ce
update: 20190616
version: 1.2.449
detected: True check_circle

ESET-NOD32
result: a variant of Win32/TrojanDownloader.Banload.UDV
update: 20200110
version: 20649
detected: True check_circle

TrendMicro
result: TROJ_BANKER.XXUF
update: 20200110
version: 11.0.0.1006
detected: True check_circle

BitDefender
result: Trojan.Generic.11623760
update: 20200110
version: 7.2
detected: True check_circle

CrowdStrike
result: win/malicious_confidence_90% (W)
update: 20190702
version: 1.0
detected: True check_circle

K7AntiVirus
result: Trojan-Downloader ( 004d63041 )
update: 20200110
version: 11.86.33012
detected: True check_circle

SentinelOne
result: DFI - Malicious PE
update: 20191218
version: 1.12.1.57
detected: True check_circle

Avast-Mobile
update: 20200110
version: 200110-00
detected: False cancel

Malwarebytes
update: 20200110
version: 3.6.4.330
detected: False cancel

TotalDefense
update: 20200110
version: 37.1.62.1
detected: False cancel

CAT-QuickHeal
update: 20200110
version: 14.00
detected: False cancel

NANO-Antivirus
result: Trojan.Win32.Banload.decqce
update: 20200110
version: 1.0.134.25031
detected: True check_circle

BitDefenderTheta
result: Gen:NN.ZelphiF.34080.@J0@a0IlIEiQ
update: 20200110
version: 7.2.37796.0
detected: True check_circle

MicroWorld-eScan
result: Trojan.Generic.11623760
update: 20200110
version: 14.0.297.0
detected: True check_circle

SUPERAntiSpyware
update: 20200103
version: 5.6.0.1032
detected: False cancel

McAfee-GW-Edition
result: BehavesLike.Win32.Dropper.vz
update: 20200110
version: v2017.3010
detected: True check_circle

TrendMicro-HouseCall
result: TROJ_BANKER.XXUF
update: 20200110
version: 10.0.0.1040
detected: True check_circle

total
72
sha256
e2a3e3dc406bc8f553b4ce463697a645311491cae7c379678a57d8187539b09b
scan_id
e2a3e3dc406bc8f553b4ce463697a645311491cae7c379678a57d8187539b09b-1578720279
resource
7ac7f1986b6ce19a97b7c4647edc0c83
positives
48
scan_date
2020-01-11 05:24:39
verbose_msg
Scan finished, information embedded
response_code
1
File
Trace
12/3/2020 - 15:45:43.168Read2308C:\malware.exeC:\Windows\SysWOW64\EhStorShell.dllEhStorShell.dll
12/3/2020 - 15:45:43.215Open2308C:\malware.exeC:\Windows\SysWOW64\pt-BR\EhStorShell.dll.mui
12/3/2020 - 15:45:43.262Read2308C:\malware.exeC:\Windows\SysWOW64\pt-BR\EhStorShell.dll.muiEhStorShell.dll.mui
12/3/2020 - 15:45:43.309Open2308C:\malware.exeC:\Windows\SysWOW64\EhStorShell.dll
12/3/2020 - 15:45:43.309Unknown2308C:\malware.exeC:\Windows\SysWOW64\EhStorShell.dllEhStorShell.dll
12/3/2020 - 15:45:43.309Open2308C:\malware.exeC:\Windows\SysWOW64\EhStorShell.dll
12/3/2020 - 15:45:43.309Unknown2308C:\malware.exeC:\Windows\SysWOW64\EhStorShell.dllEhStorShell.dll
12/3/2020 - 15:45:43.309Open2308C:\malware.exeC:\Windows\SysWOW64\pt-BR\EhStorShell.dll.mui
12/3/2020 - 15:45:43.309Unknown2308C:\malware.exeC:\Windows\SysWOW64\pt-BR\EhStorShell.dll.muiEhStorShell.dll.mui
12/3/2020 - 15:45:43.309Open2308C:\malware.exeC:\Windows\SysWOW64\EhStorShell.dll
12/3/2020 - 15:45:43.309Open2308C:\malware.exeC:\Windows\SysWOW64\EhStorShell.dll
12/3/2020 - 15:45:43.309Read2308C:\malware.exeC:\Windows\SysWOW64\EhStorShell.dllEhStorShell.dll
12/3/2020 - 15:45:43.309Read2308C:\malware.exeC:\Windows\SysWOW64\EhStorShell.dllEhStorShell.dll
12/3/2020 - 15:45:43.309Read2308C:\malware.exeC:\Windows\SysWOW64\EhStorShell.dllEhStorShell.dll
12/3/2020 - 15:45:43.309Unknown2308C:\malware.exeC:\Windows\SysWOW64\EhStorShell.dllEhStorShell.dll
12/3/2020 - 15:45:43.309Open2308C:\malware.exeC:\Windows\SysWOW64\EhStorShell.dll
12/3/2020 - 15:45:43.309Open2308C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
12/3/2020 - 15:45:43.309Open2308C:\malware.exeC:\Windows\AppPatch\sysmain.sdb
12/3/2020 - 15:45:43.309Open2308C:\malware.exeC:\Windows\SysWOW64
12/3/2020 - 15:45:43.309Unknown2308C:\malware.exeC:\Windows\SysWOW64
12/3/2020 - 15:45:43.309Open2308C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
12/3/2020 - 15:45:43.309Open2308C:\malware.exeC:\
12/3/2020 - 15:45:43.309Unknown2308C:\malware.exeC:\
12/3/2020 - 15:45:43.309Open2308C:\malware.exeC:\Windows
12/3/2020 - 15:45:43.309Unknown2308C:\malware.exeC:\Windows
12/3/2020 - 15:45:43.309Open2308C:\malware.exeC:\Windows\SysWOW64
12/3/2020 - 15:45:43.309Unknown2308C:\malware.exeC:\Windows\SysWOW64
12/3/2020 - 15:45:43.309Open2308C:\malware.exeC:\Windows\SysWOW64
12/3/2020 - 15:45:43.309Unknown2308C:\malware.exeC:\Windows\SysWOW64
12/3/2020 - 15:45:43.309Open2308C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
12/3/2020 - 15:45:43.309Open2308C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
12/3/2020 - 15:45:43.325Open2308C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
12/3/2020 - 15:45:43.325Open2308C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
12/3/2020 - 15:45:43.325Open2308C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
12/3/2020 - 15:45:43.325Open2308C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
12/3/2020 - 15:45:43.325Read2308C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
12/3/2020 - 15:45:43.325Read2308C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
12/3/2020 - 15:45:43.325Open2308C:\malware.exeC:\Windows\SysWOW64\ntshrui.dll
12/3/2020 - 15:45:43.325Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.325Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.325Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.325Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.325Open2308C:\malware.exeC:\Windows\SysWOW64\pt-BR\imageres.dll.mui
12/3/2020 - 15:45:43.325Open2308C:\malware.exeC:\Windows\System32\pt-BR\imageres.dll.mui
12/3/2020 - 15:45:43.325Open2308C:\malware.exeC:\windows\SysWOW64\pt\imageres.dll.mui
12/3/2020 - 15:45:43.325Open2308C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.mui
12/3/2020 - 15:45:43.325Read2308C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.muiimageres.dll.mui
12/3/2020 - 15:45:43.340Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.340Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.340Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.340Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.340Open2308C:\malware.exeC:\Windows\SysWOW64\pt-BR\imageres.dll.mui
12/3/2020 - 15:45:43.340Open2308C:\malware.exeC:\Windows\System32\pt-BR\imageres.dll.mui
12/3/2020 - 15:45:43.340Open2308C:\malware.exeC:\windows\SysWOW64\pt\imageres.dll.mui
12/3/2020 - 15:45:43.340Open2308C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.mui
12/3/2020 - 15:45:43.340Unknown2308C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.muiimageres.dll.mui
12/3/2020 - 15:45:43.340Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.340Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.340Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.340Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.340Open2308C:\malware.exeC:\Windows\SysWOW64\pt-BR\imageres.dll.mui
12/3/2020 - 15:45:43.340Open2308C:\malware.exeC:\Windows\System32\pt-BR\imageres.dll.mui
12/3/2020 - 15:45:43.340Open2308C:\malware.exeC:\windows\SysWOW64\pt\imageres.dll.mui
12/3/2020 - 15:45:43.340Open2308C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.mui
12/3/2020 - 15:45:43.528Unknown2308C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.muiimageres.dll.mui
12/3/2020 - 15:45:43.528Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.528Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.528Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.528Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.528Open2308C:\malware.exeC:\Windows\SysWOW64\pt-BR\imageres.dll.mui
12/3/2020 - 15:45:43.528Open2308C:\malware.exeC:\Windows\System32\pt-BR\imageres.dll.mui
12/3/2020 - 15:45:43.528Open2308C:\malware.exeC:\windows\SysWOW64\pt\imageres.dll.mui
12/3/2020 - 15:45:43.528Open2308C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.mui
12/3/2020 - 15:45:43.528Unknown2308C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.muiimageres.dll.mui
12/3/2020 - 15:45:43.528Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.528Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.528Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.528Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.528Open2308C:\malware.exeC:\Windows\SysWOW64\pt-BR\imageres.dll.mui
12/3/2020 - 15:45:43.528Open2308C:\malware.exeC:\Windows\System32\pt-BR\imageres.dll.mui
12/3/2020 - 15:45:43.528Open2308C:\malware.exeC:\windows\SysWOW64\pt\imageres.dll.mui
12/3/2020 - 15:45:43.528Open2308C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.mui
12/3/2020 - 15:45:43.528Unknown2308C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.muiimageres.dll.mui
12/3/2020 - 15:45:43.528Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.528Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.528Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\pt-BR\imageres.dll.mui
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\System32\pt-BR\imageres.dll.mui
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\windows\SysWOW64\pt\imageres.dll.mui
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.mui
12/3/2020 - 15:45:43.543Unknown2308C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.muiimageres.dll.mui
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\pt-BR\imageres.dll.mui
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\System32\pt-BR\imageres.dll.mui
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\windows\SysWOW64\pt\imageres.dll.mui
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.mui
12/3/2020 - 15:45:43.543Unknown2308C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.muiimageres.dll.mui
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\pt-BR\imageres.dll.mui
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\System32\pt-BR\imageres.dll.mui
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\windows\SysWOW64\pt\imageres.dll.mui
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.mui
12/3/2020 - 15:45:43.543Unknown2308C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.muiimageres.dll.mui
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\pt-BR\imageres.dll.mui
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\System32\pt-BR\imageres.dll.mui
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\windows\SysWOW64\pt\imageres.dll.mui
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.mui
12/3/2020 - 15:45:43.543Unknown2308C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.muiimageres.dll.mui
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\pt-BR\imageres.dll.mui
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\System32\pt-BR\imageres.dll.mui
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\windows\SysWOW64\pt\imageres.dll.mui
12/3/2020 - 15:45:43.543Open2308C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.mui
12/3/2020 - 15:45:43.543Unknown2308C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.muiimageres.dll.mui
12/3/2020 - 15:45:43.559Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.559Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.559Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.559Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.559Open2308C:\malware.exeC:\Windows\SysWOW64\pt-BR\imageres.dll.mui
12/3/2020 - 15:45:43.559Open2308C:\malware.exeC:\Windows\System32\pt-BR\imageres.dll.mui
12/3/2020 - 15:45:43.559Open2308C:\malware.exeC:\windows\SysWOW64\pt\imageres.dll.mui
12/3/2020 - 15:45:43.559Open2308C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.mui
12/3/2020 - 15:45:43.559Unknown2308C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.muiimageres.dll.mui
12/3/2020 - 15:45:43.559Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.559Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.559Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.559Open2308C:\malware.exeC:\Windows\SysWOW64\imageres.dll
12/3/2020 - 15:45:43.559Open2308C:\malware.exeC:\Windows\SysWOW64\pt-BR\imageres.dll.mui
12/3/2020 - 15:45:43.559Open2308C:\malware.exeC:\Windows\System32\pt-BR\imageres.dll.mui
12/3/2020 - 15:45:43.559Open2308C:\malware.exeC:\windows\SysWOW64\pt\imageres.dll.mui
12/3/2020 - 15:45:43.559Open2308C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.mui
12/3/2020 - 15:45:43.559Unknown2308C:\malware.exeC:\Windows\SysWOW64\en-US\imageres.dll.muiimageres.dll.mui
12/3/2020 - 15:45:43.668Open2308C:\malware.exeC:\malware.exe
12/3/2020 - 15:45:43.668Unknown2308C:\malware.exeC:\malware.exe
12/3/2020 - 15:45:43.668Open2308C:\malware.exeC:\malware.exe
12/3/2020 - 15:45:43.668Unknown2308C:\malware.exeC:\malware.exe
12/3/2020 - 15:45:43.668Open2308C:\malware.exeC:\malware.exe
12/3/2020 - 15:45:43.668Unknown2308C:\malware.exeC:\malware.exe
12/3/2020 - 15:45:43.668Open2308C:\malware.exeC:\Monitor\Malware
12/3/2020 - 15:45:43.668Unknown2308C:\malware.exeC:\Monitor\Malware
12/3/2020 - 15:45:43.668Open2308C:\malware.exeC:\
12/3/2020 - 15:45:43.668Unknown2308C:\malware.exeC:\
12/3/2020 - 15:45:43.668Open2308C:\malware.exeC:\Monitor
12/3/2020 - 15:45:43.668Unknown2308C:\malware.exeC:\Monitor
12/3/2020 - 15:45:43.668Open2308C:\malware.exeC:\Monitor\Malware
12/3/2020 - 15:45:43.668Unknown2308C:\malware.exeC:\Monitor\Malware
12/3/2020 - 15:45:43.747Open2308C:\malware.exeC:\Windows\Fonts\sserife.fon
12/3/2020 - 15:45:43.793Open2308C:\malware.exeC:\malware.exe.Local
12/3/2020 - 15:45:43.793Open2308C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.7600.16385_pt-br_039faf2d05cfba61
12/3/2020 - 15:45:43.887Unknown2308C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.7600.16385_pt-br_039faf2d05cfba61
12/3/2020 - 15:45:43.887Open2308C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.7600.16385_pt-br_039faf2d05cfba61
12/3/2020 - 15:45:43.887Open2308C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.7600.16385_pt-br_039faf2d05cfba61\comctl32.dll.mui
12/3/2020 - 15:45:43.934Read2308C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.7600.16385_pt-br_039faf2d05cfba61\comctl32.dll.muicomctl32.dll.mui
12/3/2020 - 15:45:44.122Open2308C:\malware.exeC:\Windows\SysWOW64\uxtheme.dll.Config
12/3/2020 - 15:45:44.122Open2308C:\malware.exeC:\Windows\SysWOW64\uxtheme.dll
12/3/2020 - 15:45:44.122Open2308C:\malware.exeC:\malware.exe.Local
12/3/2020 - 15:45:44.122Open2308C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
12/3/2020 - 15:45:44.122Unknown2308C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
12/3/2020 - 15:45:44.122Open2308C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
12/3/2020 - 15:45:44.122Unknown2308C:\malware.exeC:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d
12/3/2020 - 15:46:4.12Open2308C:\malware.exeC:\Windows\Fonts\meiryo.ttc
12/3/2020 - 15:46:4.293Open2308C:\malware.exeC:\Windows\Fonts\msgothic.ttc
12/3/2020 - 15:46:4.622Open2308C:\malware.exeC:\Windows\Fonts\meiryo.ttc
12/3/2020 - 15:46:4.622Open2308C:\malware.exeC:\Windows\Fonts\meiryo.ttc
12/3/2020 - 15:46:4.856Open2308C:\malware.exeC:\Windows\Fonts\msgothic.ttc
12/3/2020 - 15:46:4.856Open2308C:\malware.exeC:\Windows\Fonts\msgothic.ttc
12/3/2020 - 15:46:5.90Open2308C:\malware.exeC:\Windows\Fonts\msjh.ttf
12/3/2020 - 15:46:5.184Open2308C:\malware.exeC:\Windows\Fonts\msjh.ttf
12/3/2020 - 15:46:5.512Open2308C:\malware.exeC:\Windows\Fonts\msyh.ttf
12/3/2020 - 15:46:5.653Open2308C:\malware.exeC:\Windows\Fonts\msyh.ttf
12/3/2020 - 15:46:5.887Open2308C:\malware.exeC:\Windows\Fonts\malgun.ttf
12/3/2020 - 15:46:6.28Open2308C:\malware.exeC:\Windows\Fonts\malgun.ttf
12/3/2020 - 15:46:6.168Open2308C:\malware.exeC:\Windows\Fonts\mingliu.ttc
12/3/2020 - 15:46:6.309Open2308C:\malware.exeC:\Windows\Fonts\mingliu.ttc
12/3/2020 - 15:46:6.590Open2308C:\malware.exeC:\Windows\Fonts\simsun.ttc
12/3/2020 - 15:46:6.590Open2308C:\malware.exeC:\Windows\Fonts\simsun.ttc
12/3/2020 - 15:46:6.590Open2308C:\malware.exeC:\Windows\Fonts\gulim.ttc
12/3/2020 - 15:46:6.825Open2308C:\malware.exeC:\Windows\Fonts\gulim.ttc
12/3/2020 - 15:46:7.153Open2308C:\malware.exeC:\Windows\SysWOW64\ole32.dll
12/3/2020 - 15:46:7.153Open2308C:\malware.exeC:\Windows\SysWOW64\ole32.dll

Process
Trace

Analysis
Reason
Timeout

Status
Sucessfully Executed

Results
1

Registry
Trace

File Summary
Created
Identified: False cancel

Deleted
Identified: False cancel

Process Summary
Created
Identified: False cancel

Deleted
Identified: False cancel

Registry Summary
Proxy
Identified: False cancel

AutoRun
Identified: False cancel

Created
Identified: False cancel

Deleted
Identified: False cancel

Browsers
Identified: False cancel

Internet
Identified: False cancel

DNS
Query

Response

TCP
Info

UDP
Info

HTTP
Info

Summary
DNS
False cancel

TCP
False cancel

UDP
False cancel

HTTP
False cancel

Results
BINARY
KNN (K=3, NFS-BRMalware)
confidence: 100.00%
suspicious: True check_circle

Decision Tree (NFS-BRMalware)
confidence: 100.00%
suspicious: True check_circle

SVC (Kernel=Linear, NFS-BRMalware)
confidence: 61.62%
suspicious: False cancel

MalConv (Ember: Raw Bytes, Threshold=0.5)
confidence: 74.67%
suspicious: True check_circle

Random Forest (100 estimators, NFS-BRMalware)
confidence: 56.00%
suspicious: True check_circle

Non-Negative MalConv (Ember: Raw Bytes, Threshold=0.35)
confidence: 81.52%
suspicious: False cancel

LightGDM (Ember: File Characteristics, Threshold=0.8336)
confidence: 87.62%
suspicious: False cancel