Analyzing...
|
File Name:   Installer.exe
SHA1:   8d3e23e2d627c900979ef231ed228c136dac6f4b
MD5:   797cc44dbbb1e12e7e9c6f3494490249
First Seen Date:  2017-09-02 23:31:45.674723 ( )
Number of Clients Seen:   4
Last Analysis Date:  2017-09-02 23:31:45.674723 ( )
Human Expert Analysis Date:  2017-09-04 09:09:30.330724 ( )Human Expert Analysis Result:   Malware
Analysis Summary
Analysis Type | Date | Verdict | |
---|---|---|---|
Signature Based Detection | 2017-09-02 23:31:45.674723 | Malware | |
Static Analysis Overall Verdict | 2017-09-02 23:31:45.674723 | No Threat Found | help |
Dynamic Analysis Overall Verdict | 2017-09-02 23:31:45.674723 | No Threat Found | help |
Precise Detectors Overall Verdict | 2017-09-02 23:31:45.674723 | No Match | help |
Human Expert Analysis Overall Verdict | 2017-09-04 09:09:30.330724 | Malware |
Static Analysis
Static Analysis Overall Verdict | Result |
---|---|
No Threat Found | help |
Detector | Result | |
---|---|---|
Optional Header LoaderFlags field is valued illegal | Clean | |
Non-ascii or empty section names detected | Clean | |
Illegal size of optional Header | Clean | |
Packer detection on signature database | Unknown | help |
Based on the sections entropy check! file is possibly packed | Clean | |
Timestamp value suspicious | Clean | |
Header Checksum is zero! | Clean | |
Enrty point is outside the 1st(.code) section! Binary is possibly packed | Clean | |
Optional Header NumberOfRvaAndSizes field is valued illegal | Clean | |
Anti-vm present | Clean | |
The Size Of Raw data is valued illegal! Binary might crash your disassembler/debugger | Suspicious | |
TLS callback functions array detected | Clean |
Dynamic Analysis
Dynamic Analysis Overall Verdict | Result |
---|---|
No Threat Found | help |
Suspicious Behaviors | |
---|---|
Opens a file in a system directory | |
Logs user key strokes | |
Uses a function clandestinely |
Behavioral Information
C:\Installer.exe
C:\Windows\system32\RichEd20.dll
C:\Windows\syswow64\MSCTF.dll
C:\Windows\syswow64\USER32.dll
{"lDistanceToMove": "6c4d", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "144"}
{"lDistanceToMove": "8a1c", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "174"}
{"lDistanceToMove": "1a49", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "144"}
{"lDistanceToMove": "0", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "144"}
{"lDistanceToMove": "e530", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "174"}
26c
1dc
210
194
22c
238
234
230
254
1c0
1a0
2c4
344
340
348
260
1b0
c8
350
274
2cc
imm32.dll
C:\Windows\system32\UXTHEME.dll
C:\Windows\system32\USERENV.dll
C:\Windows\system32\SETUPAPI.dll
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
advapi32.dll
C:\Windows\system32\APPHELP.dll
C:\Windows\system32\PROPSYS.dll
ADVAPI32.dll
propsys.dll
C:\Windows\system32\DWMAPI.dll
C:\Windows\system32\CRYPTBASE.dll
C:\Windows\system32\OLEACC.dll
OLEACCRC.DLL
C:\Windows\system32\CLBCATQ.dll
C:\Windows\system32\SHFOLDER.dll
ole32.dll
comctl32.dll
SHELL32.dll
ntmarta.dll
C:\Windows\system32\RichEd20.dll
C:\Windows\system32\ole32.dll
C:\Windows\syswow64\MSCTF.dll
C:\Users\win7\AppData\Local\Temp\nsxC625.tmp\System.dll
OLEAUT32.DLL
C:\Users\win7\AppData\Local\Temp\nsxC625.tmp\inetc.dll
Secur32.dll
api-ms-win-downlevel-advapi32-l2-1-0.dll
api-ms-win-downlevel-ole32-l1-1-0.dll
WS2_32.dll
winhttp.dll
IPHLPAPI.DLL
wininet.dll
CRYPT32.dll
USERENV.dll
api-ms-win-downlevel-shlwapi-l2-1-0.dll
DNSAPI.dll
API-MS-Win-Security-LSALookup-L1-1-0.dll
dhcpcsvc.DLL
CRYPTBASE.dll
OLEAUT32.dll
urlmon.dll
DnsCacheEntries
DisableKeepAlive
CacheMode
ProxyHttp1.1
DisableBasicOverClearChannel
DisableBranchCache
ScavengeCacheLowerBound
CertCacheNoValidate
IdnEnabled
LeashLegacyCookies
EnablePunycode
Plane16
MaxConnectionsPer1_0Server
Plane14
Plane15
Plane12
Plane13
Plane10
Plane11
MaxConnectionsPerProxy
DnsCacheTimeout
UseFirstAvailable
FrameMerging
SendTimeOut
DefaultConnectionSettings
WpadSearchAllDomains
ProxyOverride
Plane4
Plane5
Plane6
Plane7
BadProxyExpiresTime
Plane2
Plane3
HttpDefaultExpiryTimeSecs
FromCacheTimeout
Plane8
Plane9
ProxyEnable
SendExtraCRLF
DisableNTLMPreAuth
ShareCredsWithWinHttp
SocketSendBufferLength
ReceiveTimeOut
WarnOnPost
EnforceP3PValidity
ServerInfoTimeout
ConnectTimeOut
AlwaysDrainOnRedirect
WarnOnZoneCrossing
DontUseDNSLoadBalancing
EnableSpdyDebugAsserts
SecureProtocols
UseDoubleClickTimer
AutoConfigURL
WpadOverride
PreConnectLimit
SavedLegacySettings
WarnAlwaysOnPost
MaxConnectionsPerServer
TcpAutotuning
TabProcGrowth
CreateUriCacheSize
EnableNegotiate
WarnOnBadCertRecving
EnableHttp1_1
SocketReceiveBufferLength
ClientAuthBuiltInUI
FtpDefaultExpiryTimeSecs
ScavengeCacheFileLimit
Tahoma
SyncMode5
CombineFalseStartData
Plane1
DnsCacheEnabled
DisableReadRange
DisableFalseStartBlocklist
ConnectRetries
SqmHttpStreamRandomUploadPoolSize
WarnOnPostRedirect
MS Shell Dlg 2
DisableSecuritySettingsCheck
Disable
FrameTabWindow
MaxHttpRedirects
DataFilePath
AutoDetect
SystemSetupInProgress
AutoProxyDetectType
SessionMerging
ScavengeCacheFileLifeTime
FEATURE_CLIENTAUTHCERTFILTER
KeepAliveTimeout
WarnOnHTTPSToHTTPRedirect
PreResolveLimit
ProgramFilesDir
ProxyServer
DuoProtocols
AdminTabProcs
{"Reserved": "0", "hKey": "2cc", "lpData": "3503e8", "dwType": "3", "lpValueName": "SavedLegacySettings", "cbData": "b8"}
{"Reserved": "0", "hKey": "350", "lpData": "760c48bc", "dwType": "1", "lpValueName": "CachePrefix", "cbData": "12"}
{"Reserved": "0", "hKey": "350", "lpData": "76089c98", "dwType": "1", "lpValueName": "CachePrefix", "cbData": "10"}
{"Reserved": "0", "hKey": "350", "lpData": "76086a44", "dwType": "1", "lpValueName": "CachePrefix", "cbData": "2"}
{"Reserved": "0", "hKey": "2c4", "lpData": "366f330", "dwType": "4", "lpValueName": "ProxyEnable", "cbData": "4"}
{"h_key": "80000001", "samDesired": "1", "Reserved": "0", "lpSecurityAttributes": "0", "lpdwDisposition": "0", "dwOptions": "0", "lpClass": "", "phkResult": "366f214", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections"}
{"h_key": "80000001", "samDesired": "20006", "Reserved": "0", "lpSecurityAttributes": "0", "lpdwDisposition": "0", "dwOptions": "0", "lpClass": "", "phkResult": "366f334", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings"}
{"h_key": "80000001", "samDesired": "1", "Reserved": "0", "lpSecurityAttributes": "0", "lpdwDisposition": "0", "dwOptions": "0", "lpClass": "", "phkResult": "366ee2c", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections"}
{"h_key": "80000001", "samDesired": "1", "Reserved": "0", "lpSecurityAttributes": "0", "lpdwDisposition": "0", "dwOptions": "0", "lpClass": "", "phkResult": "366f318", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections"}
{"h_key": "80000001", "samDesired": "2001f", "Reserved": "0", "lpSecurityAttributes": "0", "lpdwDisposition": "366f580", "dwOptions": "0", "lpClass": "<NULL>", "phkResult": "366f584", "lpSubKey": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings"}
{"h_key": "80000001", "samDesired": "1", "Reserved": "0", "lpSecurityAttributes": "0", "lpdwDisposition": "0", "dwOptions": "0", "lpClass": "", "phkResult": "366f334", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections"}
{"h_key": "80000001", "samDesired": "1", "Reserved": "0", "lpSecurityAttributes": "0", "lpdwDisposition": "0", "dwOptions": "0", "lpClass": "", "phkResult": "366f294", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections"}
{"h_key": "80000001", "samDesired": "2001f", "Reserved": "0", "lpSecurityAttributes": "0", "lpdwDisposition": "0", "dwOptions": "0", "lpClass": "<NULL>", "phkResult": "2a7fc08", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad"}
{"h_key": "80000001", "samDesired": "2001f", "Reserved": "0", "lpSecurityAttributes": "0", "lpdwDisposition": "0", "dwOptions": "0", "lpClass": "<NULL>", "phkResult": "287fc08", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad"}
{"h_key": "80000001", "samDesired": "2", "Reserved": "0", "lpSecurityAttributes": "0", "lpdwDisposition": "0", "dwOptions": "0", "lpClass": "", "phkResult": "366f2d4", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections"}
{"dwCreationDisposition": "1", "path": "C:\\Users\\win7\\AppData\\Local\\Temp\\nsxC625.tmp\\System.dll", "dwDesiredAccess": "40000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "\\\\.\\Nsi", "dwDesiredAccess": "0", "dwShareMode": "3"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7\\AppData\\Local\\Microsoft\\Windows\\Caches\\cversions.1.db", "dwDesiredAccess": "80000000", "dwShareMode": "3"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\system32\\rsaenh.dll", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Windows", "dwDesiredAccess": "100081", "dwShareMode": "7"}
{"dwCreationDisposition": "2", "path": "C:\\Users\\win7\\AppData\\Local\\Temp\\nsxC588.tmp", "dwDesiredAccess": "c0000000", "dwShareMode": "0"}
{"dwCreationDisposition": "4", "path": "C:\\Users\\win7\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\counters.dat", "dwDesiredAccess": "c0000000", "dwShareMode": "3"}
{"dwCreationDisposition": "1", "path": "C:\\Users\\win7\\AppData\\Local\\Temp\\nsxC625.tmp\\inetc.dll", "dwDesiredAccess": "40000000", "dwShareMode": "1"}
{"dwCreationDisposition": "2", "path": "196992", "dwDesiredAccess": "40000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\", "dwDesiredAccess": "100081", "dwShareMode": "7"}
{"dwCreationDisposition": "3", "path": "C:\\Installer.exe", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7\\AppData\\Local\\Microsoft\\Windows\\Caches\\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000008.db", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\Fonts\\staticcache.dat", "dwDesiredAccess": "80000000", "dwShareMode": "5"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Internet Explorer"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB941001"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_EXCLUDE_INVALID_CLIENT_CERT_KB929477"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_DIGEST_NO_EXTRAS_IN_URI"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "System\\Setup"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_MIME_HANDLING"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache"}
{"hKey": "340", "phkResult": "0", "lpSubKey": "History"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_HTTP_USERNAME_PASSWORD_DISABLE"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Internet Explorer\\Main"}
{"hKey": "38c", "phkResult": "0", "lpSubKey": "{35B2A6E5-E669-426E-AFB6-1C7A607735EF}"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_BYPASS_CACHE_FOR_CREDPOLICY_KB936611"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_BUFFERBREAKING_818408"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Internet Explorer\\Main"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Internet Explorer\\Main"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_SKIP_POST_RETRY_ON_INTERNETWRITEFILE_KB895954"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Internet Explorer\\Main"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows NT\\CurrentVersion\\FontSubstitutes"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_ENABLE_PASSPORT_SESSION_STORE_KB948608"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_USE_CNAME_FOR_SPN_KB911149"}
{"hKey": "340", "phkResult": "0", "lpSubKey": "Content"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_PRESERVE_SPACES_IN_FILENAMES_KB952730"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_LOCALMACHINE_LOCKDOWN"}
{"hKey": "1c0", "phkResult": "0", "lpSubKey": "MS Shell Dlg 2"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Internet Explorer\\Main\\FeatureControl"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "RETRY_HEADERONLYPOST_ONCONNECTIONRESET"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Policies"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Internet Explorer"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_DISALLOW_NULL_IN_RESPONSE_HEADERS"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_INCLUDE_PORT_IN_SPN_KB908209"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_IGNORE_MAPPINGS_FOR_CREDPOLICY"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_COMPAT_USE_CONNECTION_BASED_NEGOTIATE_AUTH_KB2151543"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_PERMIT_CACHE_FOR_AUTHENTICATED_FTP_KB910274"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_USE_UTF8_FOR_BASIC_AUTH_KB967545"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Internet Explorer\\Main\\FeatureControl"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Wpad"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_ENABLE_PROXY_CACHE_REFRESH_KB2983228"}
{"hKey": "224", "phkResult": "0", "lpSubKey": "Microsoft\\Internet Explorer\\Security"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_SCH_SEND_AUX_RECORD_KB_2618444"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_FIX_CHUNKED_PROXY_SCRIPT_DOWNLOAD_KB843289"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\PeerDist\\Service"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_RETURN_FAILED_CONNECT_CONTENT_KB942615"}
{"hKey": "20c", "phkResult": "0", "lpSubKey": "FEATURE_DISABLE_NOTIFY_UNVERIFIED_SPN_KB2385266"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontLink\\SystemLink"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows NT\\CurrentVersion\\PeerDist\\Service"}
{"hKey": "33c", "phkResult": "0", "lpSubKey": "{35B2A6E5-E669-426E-AFB6-1C7A607735EF}"}
{"hKey": "228", "phkResult": "0", "lpSubKey": "Microsoft\\Internet Explorer\\Security"}
{"hKey": "340", "phkResult": "0", "lpSubKey": "Cookies"}
<NULL>
Local\ZonesCacheCounterMutex
Local\ZonesLockedCacheCounterMutex
Local\MSCTF.Asm.MutexDefault1
{"nNumberOfBytesToWrite": "2c00", "lpOverlapped": "0", "lpBuffer": "791118", "lpNumberOfBytesWritten": "2bffd88", "hFile": "1c4"}
{"nNumberOfBytesToWrite": "66a7", "lpOverlapped": "0", "lpBuffer": "789118", "lpNumberOfBytesWritten": "18fc78", "hFile": "144"}
{"nNumberOfBytesToWrite": "1200", "lpOverlapped": "0", "lpBuffer": "791118", "lpNumberOfBytesWritten": "2bffd88", "hFile": "1c4"}
{"nNumberOfBytesToWrite": "8000", "lpOverlapped": "0", "lpBuffer": "789118", "lpNumberOfBytesWritten": "18fc78", "hFile": "144"}
{"nNumberOfBytesToWrite": "4000", "lpOverlapped": "0", "lpBuffer": "791118", "lpNumberOfBytesWritten": "2bffd88", "hFile": "1c4"}
C:\Users\win7\AppData\Local\Temp\nsxC587.tmp
C:\Users\win7\AppData\Local\Temp\nsxC625.tmp
196992
Precise Detectors Analysis Results
Detector Name | Date | Verdict | Reason | |
---|---|---|---|---|
Static Precise Adware Prepscram 1 | 2017-09-02 23:30:20.580626 | No Match | help | No match. |
Static Precise Trojan Cryptor Detector 1 | 2017-09-02 23:30:20.559478 | No Match | help | No match. |
Yara Rule Static Malware Detector | 2017-09-02 23:30:20.571279 | No Match | help | No match. |
Static Precise PUA Detector 1 | 2017-09-02 23:30:20.580869 | No Match | help | NotDetected |
Static Precise Virus Detector | 2017-09-02 23:30:20.598541 | No Match | help | NotDetected |
Static Precise Trojan Detector | 2017-09-02 23:30:20.625404 | No Match | help | NotDetected |
Static Precise PUA Detector 2 | 2017-09-02 23:30:20.623845 | No Match | help | No match. |
Static Precise PUA Detector 3 | 2017-09-02 23:30:20.624598 | No Match | help | No match. |
Static Precise Virus Hezhi Detector | 2017-09-02 23:30:20.605907 | No Match | help | No match. |
Ransomware Chunk Detector | 2017-09-02 23:30:20.923591 | No Match | help | No match. |
Static Precise Virus Detector 2 | 2017-09-02 23:30:20.633268 | No Match | help | NotDetected |
Static Precise Trojan Detector 2 | 2017-09-02 23:30:20.622994 | No Match | help | NotDetected |
Static Precise Trojan Detector 3 | 2017-09-02 23:30:20.621368 | No Match | help | NotDetected |
Static Precise Adware InstallCore Detector 1 | 2017-09-02 23:30:20.620322 | No Match | help | NotDetected |
Static Precise Trojan Generic Cryptor Detector 1 | 2017-09-02 23:30:20.632503 | No Match | help | NotDetected |
Static Precise MD5 Detector | 2017-09-02 23:30:21.325151 | No Match | help | No match. |
Malicious Url Detector | 2017-09-02 23:31:45.287460 | No Match | help | No match. |
Advance Heuristics
No Advanced Heuristic Analysis Result Received
Human Expert Analysis Results
Analysis Start Date:   2017-09-04 06:28:04.229623 ( )
Analysis End Date:  2017-09-04 09:09:30.330724 ( )
File Upload Date:  2017-09-02 23:31:48.534975 ( )
Update Date:  2017-09-04 06:28:04.229651 ( )
Human Expert Analyst Feedback:  
Verdict:   Malware
Malware Family:   Trojware
Malware Type:   0
Additional File Information
Property | Value |
---|
Name | Virtual Address | Virtual Size | Raw Size | Entropy | MD5 |
---|