Enter the MD5, SHA1 or SHA256 hash to search for:        

Summary

Sections


MD5:8048d065f8e12d6cda926974d6e6a459
SHA1:9412b94068d48e596550f50bcecfdb8e90348b45
SHA256:b27c45a1879c8638fbca68502a5873c2e050bf018fa9cafc82efef8cf88ea28f
Date Submitted:12/31/2011 9:09:35 AM
Malicious:True
Executable:True
Minotaur Sample ID
106180

FileType Statistics

FileType:
 58.4% (.EXE) Win32 Executable Generic (8527/13/3)
 13.8% (.EXE) Clipper DOS Executable (2018/12)
 13.7% (.EXE) Generic Win/DOS Executable (2002/3)
 13.7% (.EXE) DOS Executable Generic (2000/1)
  0.2% (.VXD) VXD Driver (31/22)


Identity Statistics

Vendors Declaring Malicious:
TotalVendors:
VirusTotal Report:
http://www.virustotal.com/file-scan/report.html?id=b27c45a1879c8638fbca68502a5873c2e050bf018fa9cafc82efef8cf88ea28f-1325340192

Malware Family Detections:Generic26.AXKL
Gen:Variant.Graftor.11895
(Suspicious) - DNAScan
UnclassifiedMalware
BackDoor.Maxplus.519
Trojan.Win32.Sirefef
HEUR:Trojan.Win32.Generic
Generic Dropper.ace
Artemis!8048D065F8E1
Trojan:Win32/Sirefef.P
a variant of Win32/Kryptik.YFV
Trj/CI.A
Trojan.Gen
Trojan.Gen.2
Trojan.Agent/Gen-FraudScan[Prod]
Trojan.Win32.Sirefef!IK
Trojan.Win32.Generic!BT

Static Analysis Data

CRC Data
ClaimedActual
242737242737


Claimed Compile Date:
Fri Dec 30 17:47:30 2011 UTC

CountLanguage Reference Counts
2LANG_NEUTRAL SUBLANG_NEUTRAL

Screenshots


Click here to start video playback

Origin Statistics

URL IDDate AddedURLIPSource
10750512/31/2011 9:09:35 AMhttp://lovelebanon.org/st.exe64.202.102.234Clean-MX

Primary Domain Information

Level 3 (control)64.202.102.234Control
Google64.202.102.234ALLOWED
OpenDNS64.202.102.234ALLOWED
Norton198.153.192.4BLOCKED
Comodo64.202.102.234ALLOWED

Network Traffic Analysis



HTTP Request Data

HostPortHTTP URIMethod
j.maxmind.com80/app/geoip.jsGET
promos.fling.com80/geo/txt/city.phpGET

DNS Request Data


DNS Requests
Query
www.google.com
promos.fling.com
j.maxmind.com
www.yahoo.com
www.msn.com
www.google.com
www.bing.com
simplexstored.com
ourdatatransfers.com
mektek.net
logstoreonline.com
letraff.com
jumptomoon.com
gfjdyrfcb.net
findtouch.org
findsuppose.org
engineeringcrossing.com
electronicstheory.com
battleon.com
armoredlegion.com

DNS Responses
QueryResponse
www.yahoo.com98.139.180.149
www.msn.com65.55.84.56
www.google.com74.125.47.105,74.125.47.99,74.125.47.103,74.125.47.106,74.125.47.104,74.125.47.147
www.google.com72.14.204.99,72.14.204.103,72.14.204.104,72.14.204.105,72.14.204.147
www.bing.com65.121.208.242,65.121.208.218,65.121.208.232
promos.fling.com208.91.207.10
simplexstored.com66.96.217.37
ourdatatransfers.com
mektek.net69.162.123.226
letraff.com74.200.72.198
jumptomoon.com
j.maxmind.com74.86.64.162
gfjdyrfcb.net
findtouch.org
findsuppose.org
engineeringcrossing.com75.126.76.35
electronicstheory.com206.188.192.55
battleon.com70.86.82.20
armoredlegion.com216.157.39.209

Discussion

blog comments powered by Disqus