Report #9535 cancel

AVclass
banload
1
VirusTotal
md5
dc35d52404b7d1dfd8d03854a6b37e43
sha1
61256768fa6b131386dde5a70e41aa3d36773f58
SCANS (DETECTION RATE = 72.73%)
AVG
result: Win32:Malware-gen
update: 20180325
version: 18.2.3827.0
detected: True check_circle

CMC
update: 20180324
version: 1.1.0.977
detected: False cancel

MAX
result: malware (ai score=100)
update: 20180325
version: 2017.11.15.1
detected: True check_circle

Bkav
update: 20180325
version: 1.3.0.9466
detected: False cancel

K7GW
result: Riskware ( 0040eff71 )
update: 20180325
version: 10.42.26600
detected: True check_circle

ALYac
result: Gen:Variant.Graftor.163352
update: 20180325
version: 1.1.1.5
detected: True check_circle

Avast
result: Win32:Malware-gen
update: 20180325
version: 18.2.3827.0
detected: True check_circle

Avira
result: TR/ATRAPS.Gen
update: 20180324
version: 8.3.3.6
detected: True check_circle

Baidu
result: Win32.Trojan.WisdomEyes.16070401.9500.9741
update: 20180323
version: 1.0.0.2
detected: True check_circle

Cyren
result: W32/Trojan.CUGO-6493
update: 20180325
version: 5.4.30.7
detected: True check_circle

DrWeb
result: Trojan.DownLoader11.39962
update: 20180325
version: 7.0.28.2020
detected: True check_circle

GData
result: Gen:Variant.Graftor.163352
update: 20180325
version: A:25.16493B:25.11870
detected: True check_circle

Panda
result: Generic Suspicious
update: 20180324
version: 4.6.4.2
detected: True check_circle

VBA32
result: TScope.Trojan.Delf
update: 20180323
version: 3.12.28.0
detected: True check_circle

VIPRE
result: Trojan.Win32.Generic!BT
update: 20180325
version: 65504
detected: True check_circle

Zoner
update: 20180325
version: 1.0
detected: False cancel

AVware
result: Trojan.Win32.Generic!BT
update: 20180325
version: 1.5.0.42
detected: True check_circle

ClamAV
update: 20180324
version: 0.99.2.0
detected: False cancel

Comodo
result: TrojWare.Win32.Amtar.amu
update: 20180325
version: 28740
detected: True check_circle

F-Prot
update: 20180325
version: 4.7.1.166
detected: False cancel

Ikarus
result: Trojan-Downloader.Win32.Banload
update: 20180324
version: 0.1.5.2
detected: True check_circle

McAfee
result: Generic.yk
update: 20180325
version: 6.0.6.653
detected: True check_circle

Rising
result: Malware.Undefined!8.C (TFE:4:geJERelvRtK)
update: 20180325
version: 25.0.0.1
detected: True check_circle

Sophos
result: Mal/Generic-S
update: 20180325
version: 4.98.0
detected: True check_circle

Yandex
result: Trojan.DL.Banload!YHX0fE1Zfnk
update: 20180324
version: 5.5.1.3
detected: True check_circle

Zillya
update: 20180323
version: 2.0.0.3519
detected: False cancel

Arcabit
result: Trojan.Graftor.D27E18
update: 20180325
version: 1.0.0.831
detected: True check_circle

Cylance
result: Unsafe
update: 20180325
version: 2.3.1.101
detected: True check_circle

Endgame
result: malicious (moderate confidence)
update: 20180316
version: 2.0.5
detected: True check_circle

Tencent
update: 20180325
version: 1.0.0.1
detected: False cancel

ViRobot
result: Trojan.Win32.Z.Graftor.937472
update: 20180324
version: 2014.3.20.0
detected: True check_circle

eGambit
update: 20180325
version: v4.3.5
detected: False cancel

Ad-Aware
result: Gen:Variant.Graftor.163352
update: 20180325
version: 3.0.3.1010
detected: True check_circle

AegisLab
result: Troj.Generickd!c
update: 20180325
version: 4.2
detected: True check_circle

Emsisoft
result: Gen:Variant.Graftor.163352 (B)
update: 20180325
version: 4.0.2.899
detected: True check_circle

F-Secure
result: Gen:Variant.Graftor.163352
update: 20180325
version: 11.0.19100.45
detected: True check_circle

Fortinet
result: W32/Banload.UQI!tr.dldr
update: 20180325
version: 5.4.247.0
detected: True check_circle

Invincea
update: 20180121
version: 6.3.4.26036
detected: False cancel

Jiangmin
result: Trojan-Downloader.Win32.c
update: 20180325
version: 16.0.100
detected: True check_circle

Kingsoft
update: 20180325
version: 2013.8.14.323
detected: False cancel

Paloalto
result: generic.ml
update: 20180325
version: 1.0
detected: True check_circle

Symantec
result: Trojan.Gen
update: 20180324
version: 1.5.0.0
detected: True check_circle

nProtect
update: 20180325
version: 2018-03-25.01
detected: False cancel

AhnLab-V3
result: Trojan/Win32.Dloadr.R124551
update: 20180324
version: 3.12.0.20130
detected: True check_circle

Antiy-AVL
result: Trojan[Downloader]/Win32.AGeneric
update: 20180325
version: 3.0.0.1
detected: True check_circle

Kaspersky
result: HEUR:Trojan-Downloader.Win32.Generic
update: 20180325
version: 15.0.1.13
detected: True check_circle

Microsoft
result: TrojanDownloader:Win32/Banload
update: 20180325
version: 1.1.14600.4
detected: True check_circle

Qihoo-360
result: HEUR/QVM05.1.Malware.Gen
update: 20180325
version: 1.0.0.1120
detected: True check_circle

TheHacker
update: 20180319
version: 6.8.0.5.2551
detected: False cancel

ZoneAlarm
result: HEUR:Trojan-Downloader.Win32.Generic
update: 20180325
version: 1.0
detected: True check_circle

ESET-NOD32
result: a variant of Win32/TrojanDownloader.Banload.UQI
update: 20180325
version: 17111
detected: True check_circle

TrendMicro
result: TROJ_DLOADR.YYMK
update: 20180325
version: 9.862.0.1074
detected: True check_circle

WhiteArmor
update: 20180324
detected: False cancel

BitDefender
result: Gen:Variant.Graftor.163352
update: 20180325
version: 7.2
detected: True check_circle

CrowdStrike
result: malicious_confidence_60% (W)
update: 20170201
version: 1.0
detected: True check_circle

K7AntiVirus
result: Riskware ( 0040eff71 )
update: 20180325
version: 10.42.26601
detected: True check_circle

SentinelOne
update: 20180225
version: 1.0.15.206
detected: False cancel

Avast-Mobile
update: 20180324
version: 180324-00
detected: False cancel

Malwarebytes
update: 20180325
version: 2.1.1.1115
detected: False cancel

TotalDefense
update: 20180324
version: 37.1.62.1
detected: False cancel

CAT-QuickHeal
result: TrojanDownloader.Banload
update: 20180324
version: 14.00
detected: True check_circle

NANO-Antivirus
result: Trojan.Win32.MlwGen.difkij
update: 20180325
version: 1.0.100.22043
detected: True check_circle

MicroWorld-eScan
result: Gen:Variant.Graftor.163352
update: 20180325
version: 14.0.297.0
detected: True check_circle

SUPERAntiSpyware
update: 20180324
version: 5.6.0.1032
detected: False cancel

McAfee-GW-Edition
result: BehavesLike.Win32.AdwareDealPly.dh
update: 20180324
version: v2015
detected: True check_circle

TrendMicro-HouseCall
result: TROJ_DLOADR.YYMK
update: 20180325
version: 9.950.0.1006
detected: True check_circle

total
66
sha256
50beaf164cb14441c6f147a6d95490b4dd5eaf8b654c665a569657110ebfeffb
scan_id
50beaf164cb14441c6f147a6d95490b4dd5eaf8b654c665a569657110ebfeffb-1521949667
resource
dc35d52404b7d1dfd8d03854a6b37e43
positives
48
scan_date
2018-03-25 03:47:47
verbose_msg
Scan finished, information embedded
response_code
1
File
Trace

Process
Trace

Analysis
Reason
Blue Screen

Status
Machine Crashed

Results
0

Registry
Trace

File Summary
Created
Identified: False cancel

Deleted
Identified: False cancel

Process Summary
Created
Identified: False cancel

Deleted
Identified: False cancel

Registry Summary
Proxy
Identified: False cancel

AutoRun
Identified: False cancel

Created
Identified: False cancel

Deleted
Identified: False cancel

Browsers
Identified: False cancel

Internet
Identified: False cancel

DNS
Query
computer localhost arrow_forward computer gateway:51330 code ipv6.msftncsi.com.
computer localhost arrow_forward computer gateway:56497 code time.windows.com.
computer localhost arrow_forward computer gateway:DNS code www.neusiedl-zaya.gv.at.
computer localhost arrow_forward computer gateway:DNS code ctldl.windowsupdate.com.
computer localhost arrow_forward computer gateway:61450 code teredo.ipv6.microsoft.com.
computer localhost arrow_forward computer gateway:DNS code time.windows.com.
computer localhost arrow_forward computer gateway:54594 code www.msftncsi.com.
computer localhost arrow_forward computer gateway:50273 code www.neusiedl-zaya.gv.at.
computer localhost arrow_forward computer gateway:DNS code teredo.ipv6.microsoft.com.
computer localhost arrow_forward computer gateway:DNS code www.msftncsi.com.
computer localhost arrow_forward computer gateway:60975 code teredo.ipv6.microsoft.com.
computer localhost arrow_forward computer gateway:63286 code ctldl.windowsupdate.com.
computer localhost arrow_forward computer gateway:DNS code ipv6.msftncsi.com.

Response
computer gateway:DNS arrow_forward computer localhost code ctldl.windowsupdate.com. reply_all 13.107.4.50

computer gateway:DNS arrow_forward computer localhost code time.windows.com. reply_all 51.137.137.111

computer gateway:DNS arrow_forward computer localhost code www.neusiedl-zaya.gv.at. reply_all 52.155.171.125

computer gateway:DNS arrow_forward computer localhost code ipv6.msftncsi.com. reply_all a978.i6g1.akamai.net.

computer gateway:DNS arrow_forward computer localhost code www.msftncsi.com. reply_all 200.143.247.9


TCP
Info
13.107.4.50:80 arrow_forward computer localhost:49159
computer localhost:49159 arrow_forward 13.107.4.50:80
200.143.247.8:80 arrow_forward computer localhost:49157
computer localhost:49157 arrow_forward 200.143.247.8:80

UDP
Info
computer localhost:63286 arrow_forward computer localhost:53
computer localhost:58083 arrow_forward help_outline 224.0.0.252:5355
computer localhost:51330 arrow_forward computer localhost:53
computer localhost:60975 arrow_forward computer localhost:53
computer localhost:53 arrow_forward computer localhost:50273
computer localhost:53 arrow_forward computer localhost:60975
computer localhost:53 arrow_forward computer localhost:51330
computer localhost:53556 arrow_forward help_outline 239.255.255.250:3702
51.137.137.111:123 arrow_forward computer localhost:123
computer localhost:56497 arrow_forward computer localhost:53
computer localhost:62990 arrow_forward help_outline 224.0.0.252:5355
computer localhost:60490 arrow_forward help_outline 224.0.0.252:5355
computer localhost:53 arrow_forward computer localhost:54594
computer localhost:54435 arrow_forward help_outline 224.0.0.252:5355
computer localhost:53 arrow_forward computer localhost:61450
computer localhost:68 arrow_forward help_outline 255.255.255.255:67
computer localhost:67 arrow_forward computer localhost:68
computer localhost:53 arrow_forward computer localhost:56497
computer localhost:123 arrow_forward 51.137.137.111:123
computer localhost:61450 arrow_forward computer localhost:53
computer localhost:50273 arrow_forward computer localhost:53
computer localhost:64151 arrow_forward help_outline 224.0.0.252:5355
computer localhost:61576 arrow_forward help_outline 224.0.0.252:5355
computer localhost:54594 arrow_forward computer localhost:53
computer localhost:53 arrow_forward computer localhost:63286

HTTP
Info
computer localhost send GET ctldl.windowsupdate.com attach_file /msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?36c7e9561097a34e
computer localhost send GET www.msftncsi.com attach_file /ncsi.txt

Summary
DNS
True check_circle

TCP
True check_circle

UDP
True check_circle

HTTP
True check_circle

Results
BINARY
KNN (K=3, NFS-BRMalware)
confidence: 100.00%
suspicious: True check_circle

Decision Tree (NFS-BRMalware)
confidence: 100.00%
suspicious: True check_circle

SVC (Kernel=Linear, NFS-BRMalware)
confidence: 56.46%
suspicious: False cancel

MalConv (Ember: Raw Bytes, Threshold=0.5)
confidence: 98.53%
suspicious: True check_circle

Random Forest (100 estimators, NFS-BRMalware)
confidence: 68.00%
suspicious: True check_circle

Non-Negative MalConv (Ember: Raw Bytes, Threshold=0.35)
confidence: 81.45%
suspicious: False cancel

LightGDM (Ember: File Characteristics, Threshold=0.8336)
confidence: 89.47%
suspicious: False cancel