|
Analyzing...
|
File Name:   exe
SHA1:   10f5a1e5338f23e5fef246e0c1cf517f637e7109
MD5:   d8c9f4b0ed094c10b66d509deddd5dac
First Seen Date:  2018-01-17 14:57:53.710320 ( )
Number of Clients Seen:   3
Last Analysis Date:  2019-06-10 07:25:40.788836 ( )
Human Expert Analysis Date:  2019-06-10 07:06:03.047178 ( )Human Expert Analysis Result:   Malware
Analysis Summary
| Analysis Type | Date | Verdict | |
|---|---|---|---|
| Signature Based Detection | 2019-06-10 07:25:27.565850 | Malware | |
| Static Analysis Overall Verdict | 2019-06-10 07:25:40.788836 | No Threat Found | help |
| Dynamic Analysis Overall Verdict | 2019-06-10 07:25:40.788836 | No Threat Found | help |
| Precise Detectors Overall Verdict | 2019-06-10 07:25:40.788836 | No Match | help |
| Human Expert Analysis Overall Verdict | 2019-06-10 07:06:03.047178 | Malware | |
Static Analysis
| Static Analysis Overall Verdict | Result |
|---|---|
| No Threat Found | help |
| Detector | Result | |
|---|---|---|
| Optional Header LoaderFlags field is valued illegal | Clean | |
| Non-ascii or empty section names detected | Clean | |
| Illegal size of optional Header | Clean | |
| Packer detection on signature database | Unknown | help |
| Based on the sections entropy check! file is possibly packed | Clean | |
| Timestamp value suspicious | Clean | |
| Header Checksum is zero! | Clean | |
| Enrty point is outside the 1st(.code) section! Binary is possibly packed | Clean | |
| Optional Header NumberOfRvaAndSizes field is valued illegal | Clean | |
| Anti-vm present | Suspicious | |
| The Size Of Raw data is valued illegal! Binary might crash your disassembler/debugger | Clean | |
| TLS callback functions array detected | Clean | |
Dynamic Analysis
| Dynamic Analysis Overall Verdict | Result |
|---|---|
| No Threat Found | help |
| Suspicious Behaviors | |
|---|---|
| Opens a file in a system directory | |
| Logs user key strokes | |
| Uses a function clandestinely | |
Behavioral Information
OLEAUT32.DLL
SXS.DLL
kernel32
comctl32.dll
advapi32.dll
C:\Windows\system32\vb6chs.dll
ADVAPI32.dll
CRYPTBASE.dll
UxTheme.dll
IMM32.dll
User32.dll
OLEPRO32.DLL
GDI32.dll
user32
C:\Windows\system32\kernel32.dll
C:\Windows\system32\asycfilt.dll
kernel32.dll
api-ms-win-downlevel-shlwapi-l2-1-0.dll
api-ms-win-downlevel-ole32-l1-1-0.dll
urlmon.dll
propsys.dll
ole32.dll
OLEAUT32.dll
Secur32.dll
API-MS-WIN-DOWNLEVEL-SHLWAPI-L1-1-0.DLL
SHELL32.dll
SHLWAPI.dll
ieframe.dll
WININET.dll
api-ms-win-downlevel-advapi32-l2-1-0.dll
MSHTML.dll
shell32.dll
WS2_32.dll
winhttp.dll
IPHLPAPI.DLL
API-MS-Win-Security-LSALookup-L1-1-0.dll
DNSAPI.dll
dhcpcsvc.DLL
SHELL32.DLL
C:\Windows\system32\ole32.dll
PSAPI.DLL
mshtml.dll
IEFRAME.dll
user32.dll
MLANG.dll
PROPSYS.dll
CRYPTSP.dll
d2d1.dll
DWrite.dll
dxgi.dll
C:\DXGIDebug.dll
C:\Windows\system32\DXGIDebug.dll
gdi32.dll
setupapi.dll
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
WINTRUST.dll
d3d11.dll
D3D10Warp.dll
C:\Windows\system32\D3D10Warp.dll
msls31.dll
ntmarta.dll
file
http
res
WSearch
<NULL>
Local\ZonesCacheCounterMutex
Local\ZonesLockedCacheCounterMutex
!IECompat!Mutex
Local\MSCTF.Asm.MutexDefault1
_!SHMSFTHISTORY!_
C:\Users\win7\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0Q58CC5A\NewErrorPageTemplate[1]
C:\Users\win7\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\89Q863BS\errorPageStrings[1]
C:\Users\win7\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RGC5OOPI\dnserrordiagoff[1]
C:\WH_Set.ini
\\.\Nsi
C:\Users\win7\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H0G27RVV\navcancl[1]
C:\Users\win7\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H0G27RVV\httpErrorPagesScripts[1]
C:\Windows\system32\ieframe.dll
C:\Windows\Fonts\staticcache.dat
C:\Windows\SysWOW64\stdole2.tlb
C:\Windows\SysWOW64\ieframe.dll
C:\Users\win7\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000008.db
C:\Users\desktop.ini
C:\Users
C:\Users\win7
C:\Users\win7\AppData
C:\Users\win7\AppData\Local
C:\Users\win7\AppData\Local\Microsoft
C:\Users\win7\AppData\Local\Microsoft\Windows
C:\Users\win7\AppData\Local\Microsoft\Windows\History\desktop.ini
C:\exe
C:\Windows\system32\MSVBVM60.DLL
C:\Windows\SysWOW64\ieframe.dll
C:\Windows\system32\PROPSYS.dll
C:\Windows\SysWOW64\mshtml.dll
C:\Windows\syswow64\MSCTF.dll
C:\Windows\SysWOW64\jscript9.dll
C:\Windows\system32\dxgi.dll
C:\Windows\system32\d3d11.dll
C:\Windows\system32\D3D10Warp.dll
\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Application Compatibility
\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft
\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Accepted Documents
\REGISTRY\MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\text/xml
\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
\REGISTRY\MACHINE\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler
\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_OBJECT_CACHING
\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK
\REGISTRY\USER\S-1-5-21-3979321414-2393373014-2172761192-1000\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ZONE_ELEVATION
\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_PROTOCOL_LOCKDOWN
\REGISTRY\USER\S-1-5-21-3979321414-2393373014-2172761192-1000\Software\Microsoft\Internet Explorer\PageSetup
\REGISTRY\USER\S-1-5-21-3979321414-2393373014-2172761192-1000\Software\Microsoft\Internet Explorer\International
\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_HANDLING
\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_RESTRICT_FILEDOWNLOAD
\REGISTRY\USER\S-1-5-21-3979321414-2393373014-2172761192-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent
\REGISTRY\USER\S-1-5-21-3979321414-2393373014-2172761192-1000\Software\Microsoft\Internet Explorer\Security
\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION
\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_MIME_SNIFFING
\REGISTRY\MACHINE\SOFTWARE\M
\REGISTRY\USER\S-1-5-21-3979321414-2393373014-2172761192-1000\Software\Microsoft\Internet Explorer\Settings
\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_LEGACY_DISPPARAMS
\REGISTRY\USER\S-1-5-21-3979321414-2393373014-2172761192-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN
\REGISTRY\USER\S-1-5-21-3979321414-2393373014-2172761192-1000\Software\Microsoft\Windows\CurrentVersion\Policies
\REGISTRY\USER\S-1-5-21-3979321414-2393373014-2172761192-1000\Software\Microsoft\Internet Explorer\DOMStorage
\REGISTRY\USER\S-1-5-21-3979321414-2393373014-2172761192-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform
\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_SAFE_BINDTOOBJECT
Precise Detectors Analysis Results
| Detector Name | Date | Verdict | Reason | |
|---|---|---|---|---|
| Static Precise PUA Detector 1 | 2019-06-10 07:25:30.324536 | No Match | help | NotDetected |
| Static Precise PUA Detector 4 | 2019-06-10 07:25:30.320737 | No Match | help | NotDetected |
| Static Precise NI Detector 3 | 2019-06-10 07:25:30.368778 | No Match | help | NotDetected |
| Static Precise PUA Detector 5 | 2019-06-10 07:25:30.410155 | No Match | help | NotDetected |
| Static Precise Trojan Detector 3 | 2019-06-10 07:25:30.411353 | No Match | help | NotDetected |
| Static Precise Trojan Detector 1 | 2019-06-10 07:25:30.446231 | No Match | help | NotDetected |
| Static Precise PUA Detector 6 | 2019-06-10 07:25:30.445080 | No Match | help | NotDetected |
| Static Precise Trojan Detector 12 | 2019-06-10 07:25:30.460392 | No Match | help | NotDetected |
| Static Precise Virus Detector 1 | 2019-06-10 07:25:30.508929 | No Match | help | NotDetected |
| Static Precise Virus Detector 2 | 2019-06-10 07:25:30.510034 | No Match | help | NotDetected |
| Static Precise Trojan Detector 13 | 2019-06-10 07:25:30.543552 | No Match | help | NotDetected |
| Static Precise PUA Detector 2 | 2019-06-10 07:25:30.563660 | No Match | help | NotDetected |
Advance Heuristics
No Advanced Heuristic Analysis Result Received
Human Expert Analysis Results
Analysis Start Date:   2018-08-10 10:07:45.135867 ( )
Analysis End Date:  2019-06-10 07:06:03.047178 ( )
File Upload Date:  2018-08-10 08:39:51.353359 ( )
Update Date:  2019-06-10 07:06:03.073703 ( )
Human Expert Analyst Feedback:   Malware
Verdict:   Malware
Malware Family:   Trojware.Win32.Agent
Malware Type:   Trojan Generic
Additional File Information
| Property | Value |
|---|
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | MD5 |
|---|