Enter the MD5, SHA1 or SHA256 hash to search for:        

Summary

Sections


MD5:6cd64647499a408a1fff91b1de8682e8
SHA1:e7f460ac4dc7fd8d10b76f3ccb0bb5f15c88e154
SHA256:10686d5999f02937a7166bb041606a83fdd05cc7c9f58494f54da349485424d7
Date Submitted:1/21/2012 6:22:27 AM
Malicious:True
Executable:True
Minotaur Sample ID
111959

FileType Statistics

FileType:
 38.4% (.EXE) Win32 Executable Generic (8527/13/3)
 34.1% (.DLL) Win32 Dynamic Link Library (generic) (7583/30/2)
  9.3% (.EXE) Win16/32 Executable Delphi generic (2072/23)
  9.0% (.EXE) Generic Win/DOS Executable (2002/3)
  9.0% (.EXE) DOS Executable Generic (2000/1)


Identity Statistics

Vendors Declaring Malicious:
TotalVendors:
VirusTotal Report:
http://www.virustotal.com/file/10686d5999f02937a7166bb041606a83fdd05cc7c9f58494f54da349485424d7/analysis/

Malware Family Detections:TR/Crypt.ZPACK.Gen2
Win32:MalOb-HX [Cryp]
Win32/Cryptor
Gen:Variant.Kazy.53213
Heuristic.LooksLike.Win32.Winwebsec.E

Static Analysis Data

CRC Data
ClaimedActual
949425949425


Claimed Compile Date:
Fri Apr 7 12:21:00 2006 UTC

CountLanguage Reference Counts
1LANG_FRENCH SUBLANG_FRENCH

Screenshots


Click here to start video playback

Origin Statistics

URL IDDate AddedURLIPSource
1133031/21/2012 6:22:27 AMhttp://fjsknh.trickip.org/franki2.exe91.217.153.130Clean-MX

Primary Domain Information

Domain not found

Network Traffic Analysis



HTTP Request Data

HostPortHTTP URIMethod
107.10.81.280/tzFMyLVAYs8wH.htmGET
109.122.4.20480/rIP67tC.htmGET
109.185.188.4880/GEfqo/cfEs05.htmGET
109.185.216.4680/FN1B1.htmGET
112.204.4.4280/Wkka.htmGET
1.22.16.8380/RjboocrgCubEgIzmKd.htmGET
132.235.229.4180/ISJF9AuF.htmGET
151.0.10.7580/1p7vW59yW.htmGET
151.28.113.1980/gbSy5rqKhQqodklZ.htmGET
178.148.80.8680/103PMNPCOnPnBzrlK8.htmGET
178.148.80.8680/AavSLDTiwAzICh5.htmGET
178.165.69.1280/41x166tjyF417mawY.htmGET
186.136.24.2580/djtncP526.htmGET
186.19.181.1680/cjGl.htmGET
186.23.135.23280/OANFjjB9N9.htmGET
186.35.101.880/QbZ1NULy4X7sG.htmGET
188.230.98.2580/vjTL.htmGET
190.18.64.14280/QO9vEZL2Zj.htmGET
190.245.69.5080/G84C.htmGET
190.6.225.23180/WSYuO/qEndDrOYe.htmGET
190.6.4.080/CA0oGEk7.htmGET
195.174.26.1480/aYkpTghnswEVQXw.htmGET
200.127.182.3580/uT8qlVy9Ih2ed.htmGET
201.231.3.4780/cFpvqSSZ.htmGET
201.239.11.22280/U67D1T.htmGET
202.150.185.7080/7d0TU.htmGET
202.150.185.7080/AjEt2kCCV/1m88taLY.htmGET
212.1.99.8280/vHfB89FAdI6.htmGET
24.12.67.4580/2FGq4HQ/jMT.htmGET
24.232.129.5180/oxXpVU2wPF.htmGET
24.29.200.6080/MqNLGkZoFCg.htmGET
31.11.199.4380/fPcyADRYQnxsDdw0p.htmGET
31.14.236.4980/H/2UKGb.htmGET
31.170.134.1380/JI9l3kQ4Oa5rHc.htmGET
31.41.8.2580/rehC12OFBWGWL35.htmGET
31.47.25.16480/6Ynqm9wIB.htmGET
31.47.3.24180/9TBfsyPLMcJn.htmGET
50.131.15.7180/8iPZ5wFKkOvIi/lmOHb.htmGET
62.178.159.7580/HvbQy4.htmGET
66.168.199.15480/aJEE.htmGET
66.215.158.3780/6Suc.htmGET
67.165.216.6680/aAgm.htmGET
68.225.61.3180/LfpGLZFyF3AOwgCVtsF.htmGET
68.43.2.10380/iEHigDHVjaWS7cZS.htmGET
68.62.236.20880/wKCNf3Ib.htmGET
69.142.117.1680/kHM8.htmGET
71.196.72.6080/8I6JhjdL8FhGK.htmGET
71.203.120.4380/NOkJSY/.htmGET
71.60.28.8580/hmSZVjkx15M.htmGET
74.62.40.7380/0BZt5.htmGET
75.139.33.3980/P6V4Efa.htmGET
75.176.46.19980/kE3GzZPf5Z9Sk.htmGET
75.24.144.13080/Xu5yqDlrdja7v.htmGET
75.64.6.18380/GpMqkHToD.htmGET
75.64.6.18380/M/RN38hmnTpS8r4wFc.htmGET
75.72.144.9280/jK5f.htmGET
75.72.144.9280/Wvn9nhOFaKR.htmGET
75.72.144.9280/yqKb.htmGET
75.76.3.15480/dV9VHjt.htmGET
75.76.3.15480/erdj.htmGET
76.186.22.5780/IHnawT5pV.htmGET
76.29.208.24780/Pu6D88534SwA.htmGET
76.85.133.1480/BfWX.htmGET
77.120.146.21080/gEFD.htmGET
77.78.234.2480/xmj7dCIm4z6.htmGET
77.81.134.8180/SShG.htmGET
77.81.50.2880/8Hwr6KXcGswKG.htmGET
80.65.171.7980/W5MQaLDhX65up50Nz.htmGET
81.191.41.7880/oly0o2CWwBznI.htmGET
82.131.1.15980/cSgT.htmGET
83.3.31.2280/KbGO.htmGET
84.73.146.15780/OGFy.htmGET
85.122.52.1080/9pJ5VbuUOpbq71I.htmGET
86.38.209.6580/HxoBTXGmspTaG5.htmGET
88.207.56.21280/dIhPf7YJ4cf.htmGET
88.207.56.21280/mUmmyfT0OZdOvzzz.htmGET
88.207.56.21280/samA0.htmGET
88.216.55.16880/GwXA.htmGET
88.216.55.16880/stesTnHdCP.htmGET
88.216.55.16880/szuTuNhgsi4I32.htmGET
88.216.55.16880/TSV9BFIw11Q.htmGET
88.216.55.16880/wO2yc9F4PIFYHQ.htmGET
89.19.149.380/MJLfWpHFyDKBsqE.htmGET
89.34.175.18480/5bPTSno.htmGET
91.220.90.3380/yzKBC/nFBNE8/ifDvC.htmGET
92.39.51.6180/8j/vHZLGu.htmGET
93.113.217.1780/XDldNnJIq5ZfittSHa.htmGET
93.123.69.2980/Ya50i.htmGET
95.87.57.16280/FSWI16f/iUUt.htmGET
97.85.58.1480/zZk0pubhEyiDwUgf7U.htmGET
98.223.246.1380/ZCJK.htmGET
98.248.74.23680/86PCa8uA.htmGET
99.139.26.7880/TbwBXyh9mJjU.htmGET

DNS Request Data


DNS Requests
Query
akinard.com

DNS Responses
QueryResponse
akinard.com109.122.4.204
akinard.com109.185.216.46
akinard.com178.148.80.86
akinard.com186.23.135.232
akinard.com190.18.64.142
akinard.com190.245.69.50
akinard.com190.6.225.231
akinard.com201.239.11.222
akinard.com202.150.185.70
akinard.com24.12.67.45
akinard.com31.47.25.164
akinard.com31.47.3.241
akinard.com66.168.199.154
akinard.com68.43.2.103
akinard.com68.62.236.208
akinard.com75.176.46.199
akinard.com75.24.144.130
akinard.com75.64.6.183
akinard.com75.72.144.92
akinard.com75.76.3.154
akinard.com76.29.208.247
akinard.com77.120.146.210
akinard.com82.131.1.159
akinard.com84.73.146.157
akinard.com86.38.209.65
akinard.com88.207.56.212
akinard.com88.216.55.168
akinard.com89.34.175.184
akinard.com92.39.51.61
akinard.com95.87.57.162
akinard.com98.248.74.236

Discussion

blog comments powered by Disqus