Enter the MD5, SHA1 or SHA256 hash to search for:        

Summary

Sections


MD5:7b55cab3983f73642dd0340000b623f8
SHA1:701a957460980a46f0e209968fc7c36308294f9a
SHA256:5d038d0fdf544e1fad104838f47562e3d12d36508f82f5c3e9632392a407a1cf
Date Submitted:2/2/2012 4:00:30 AM
Malicious:True
Executable:True
Minotaur Sample ID
119042

FileType Statistics

FileType:
 38.4% (.EXE) Win32 Executable Generic (8527/13/3)
 34.1% (.DLL) Win32 Dynamic Link Library (generic) (7583/30/2)
  9.3% (.EXE) Win16/32 Executable Delphi generic (2072/23)
  9.0% (.EXE) Generic Win/DOS Executable (2002/3)
  9.0% (.EXE) DOS Executable Generic (2000/1)


Identity Statistics

Vendors Declaring Malicious:
TotalVendors:
VirusTotal Report:
http://www.virustotal.com/file/5d038d0fdf544e1fad104838f47562e3d12d36508f82f5c3e9632392a407a1cf/analysis/

Malware Family Detections:Win32/Cryptor
Gen:Variant.Kazy.53951
W32/Kryptik.XUW!tr
a variant of Win32/Kryptik.ZXC
Suspicious file
Mal/Agent-AFY

Static Analysis Data

CRC Data
ClaimedActual
935321935321


Claimed Compile Date:
Mon Jun 26 00:25:35 2006 UTC

CountLanguage Reference Counts
1LANG_NEUTRAL SUBLANG_SYS_DEFAULT
1LANG_NEUTRAL SUBLANG_NEUTRAL
1LANG_GERMAN SUBLANG_GERMAN_AUSTRIAN
1LANG_FRENCH SUBLANG_FRENCH
1LANG_FINNISH SUBLANG_NEUTRAL
1LANG_ENGLISH SUBLANG_ENGLISH_UK

Screenshots


Click here to start video playback

Origin Statistics

URL IDDate AddedURLIPSource
1210082/2/2012 4:00:30 AMhttp://xyrpavu.eu/rtce002.exe195.28.8.121Clean-MX

Primary Domain Information

Domain not found

Network Traffic Analysis



HTTP Request Data

HostPortHTTP URIMethod
95.68.53.3480/BfWX.htmGET
96.10.251.10880/uT8qlVy9Ih2ed.htmGET
97.101.137.1580/cSgT.htmGET
97.101.137.1580/QbZ1NULy4X7sG.htmGET
98.218.107.9980/8Hwr6KXcGswKG.htmGET
98.230.203.11180/P6V4Efa.htmGET
117.204.70.20780/hmSZVjkx15M.htmGET
118.41.235.19080/SShG.htmGET
139.30.121.13280/8iPZ5wFKkOvIi/lmOHb.htmGET
174.134.71.11580/ISJF9AuF.htmGET
175.205.116.5780/gbSy5rqKhQqodklZ.htmGET
186.137.172.11680/NOkJSY/.htmGET
187.184.33.5680/XDldNnJIq5ZfittSHa.htmGET
189.202.35.180/CA0oGEk7.htmGET
189.202.35.180/U67D1T.htmGET
189.220.155.6980/rehC12OFBWGWL35.htmGET
190.245.137.2880/aYkpTghnswEVQXw.htmGET
201.158.81.16680/oly0o2CWwBznI.htmGET
213.113.51.5080/cjGl.htmGET
217.144.24.10280/Ya50i.htmGET
222.108.148.11980/GEfqo/cfEs05.htmGET
24.11.239.11880/cFpvqSSZ.htmGET
24.12.67.4580/kHM8.htmGET
24.163.56.12480/IHnawT5pV.htmGET
24.2.231.12880/aAgm.htmGET
46.105.114.12080/H/2UKGb.htmGET
50.128.166.15280/TbwBXyh9mJjU.htmGET
50.82.135.9480/vjTL.htmGET
61.61.219.6480/xmj7dCIm4z6.htmGET
66.8.220.1280/86PCa8uA.htmGET
66.8.220.1280/MJLfWpHFyDKBsqE.htmGET
66.91.51.2380/41x166tjyF417mawY.htmGET
66.91.51.2380/dV9VHjt.htmGET
68.114.12.15080/HvbQy4.htmGET
68.42.204.1280/FSWI16f/iUUt.htmGET
68.42.204.1280/tzFMyLVAYs8wH.htmGET
68.51.242.2180/9pJ5VbuUOpbq71I.htmGET
68.51.242.2180/AjEt2kCCV/1m88taLY.htmGET
69.110.8.14780/1p7vW59yW.htmGET
69.142.73.10980/6Suc.htmGET
69.253.127.8780/djtncP526.htmGET
69.27.61.14480/0BZt5.htmGET
69.47.94.10380/LfpGLZFyF3AOwgCVtsF.htmGET
71.196.251.11680/fPcyADRYQnxsDdw0p.htmGET
71.204.9.12580/8I6JhjdL8FhGK.htmGET
71.86.102.11580/Wkka.htmGET
75.64.6.18380/W5MQaLDhX65up50Nz.htmGET
75.81.232.12180/oxXpVU2wPF.htmGET
76.90.46.10680/yzKBC/nFBNE8/ifDvC.htmGET
77.81.50.2880/103PMNPCOnPnBzrlK8.htmGET
77.81.50.2880/ZCJK.htmGET
85.122.82.12680/MqNLGkZoFCg.htmGET
87.97.204.20280/RjboocrgCubEgIzmKd.htmGET
88.222.176.5980/KbGO.htmGET
91.220.90.3380/zZk0pubhEyiDwUgf7U.htmGET
93.116.9.19680/vHfB89FAdI6.htmGET
98.240.212.2680/JI9l3kQ4Oa5rHc.htmGET
98.240.212.2680/wKCNf3Ib.htmGET

Discussion

blog comments powered by Disqus