Analyzing...
|
File Name:   setup_mbot_nl.exe
SHA1:   a454a4fc29cc0686d8ec1e4bdf3f5ffa9676cb32
MD5:   537b8f10ede4b178366faa3023d31349
First Seen Date:  2016-01-30 10:43:37.406408 ( )
Number of Clients Seen:   7
Last Analysis Date:  2016-04-09 02:27:51.074435 ( )
Human Expert Analysis Date:  2016-02-11 14:33:49.543326 ( )Human Expert Analysis Result:   PUA
Analysis Summary
Analysis Type | Date | Verdict | |
---|---|---|---|
Signature Based Detection | 2016-04-09 02:27:51.074435 | Malware | |
Static Analysis Overall Verdict | 2016-04-09 02:27:51.074435 | Highly Suspicious | |
Human Expert Analysis Overall Verdict | 2016-02-11 14:33:49.543326 | PUA |
Static Analysis
Static Analysis Overall Verdict | Result |
---|---|
Highly Suspicious |
Detector | Result | |
---|---|---|
Optional Header LoaderFlags field is valued illegal | Clean | |
Non-ascii or empty section names detected | Clean | |
Illegal size of optional Header | Clean | |
Optional Header NumberOfRvaAndSizes field is valued illegal | Clean | |
Based on the sections entropy check! file is possibly packed | Clean | |
Timestamp value suspicious | Suspicious | |
Header Checksum is zero! | Suspicious | |
Enrty point is outside the 1st(.code) section! Binary is possibly packed | Clean | |
Packer detection on signature database | Unknown | help |
Anti-vm present | Clean | |
The Size Of Raw data is valued illegal! Binary might crash your disassembler/debugger | Suspicious | |
TLS callback functions array detected | Suspicious |
Dynamic Analysis
No Dynamic Analysis Result Received
Behavioral Information is not Available
Precise Detectors Analysis Results
No Detector Result Received
Advance Heuristics
No Advanced Heuristic Analysis Result Received
Human Expert Analysis Results
Analysis Start Date:   2016-02-06 07:11:03.888874 ( )
Analysis End Date:  2016-02-11 14:33:49.543326 ( )
File Upload Date:  2016-02-05 09:01:59.208290 ( )
Update Date:  2016-02-11 14:33:49.543331 ( )
Human Expert Analyst Feedback:   Download and Drops/install multiple files without user concern.
Verdict:   PUA
Malware Family:   Application.win32.MyBestOffersToday
Malware Type:   Virus
Additional File Information
Property | Value |
---|
Name | Virtual Address | Virtual Size | Raw Size | Entropy | MD5 |
---|