Enter the MD5, SHA1 or SHA256 hash to search for:        

Summary

Sections


MD5:975dc355e8fcaec11d5b1ab5ce995acc
SHA1:e89b05c49076600fa4d8a56de851aa951460b41c
SHA256:2c8f5e67db8c1ae700ae780d760d516aa1b671eb6b906818bcf86c06e08d4cc2
Date Submitted:1/16/2012 1:10:01 PM
Malicious:True
Executable:True
Minotaur Sample ID
110563

FileType Statistics

FileType:
 38.4% (.EXE) Win32 Executable Generic (8527/13/3)
 34.1% (.DLL) Win32 Dynamic Link Library (generic) (7583/30/2)
  9.3% (.EXE) Win16/32 Executable Delphi generic (2072/23)
  9.0% (.EXE) Generic Win/DOS Executable (2002/3)
  9.0% (.EXE) DOS Executable Generic (2000/1)


Identity Statistics

Vendors Declaring Malicious:
TotalVendors:
VirusTotal Report:
http://www.virustotal.com/file/2c8f5e67db8c1ae700ae780d760d516aa1b671eb6b906818bcf86c06e08d4cc2/analysis/

Malware Family Detections:TR/Crypt.XPACK.Gen5
Gen:Variant.Kazy.53213
W32/Kryptik.XUW!tr
Suspicious file

Static Analysis Data

CRC Data
ClaimedActual
891944891944


Claimed Compile Date:
Sat Jan 20 12:54:51 2007 UTC

CountLanguage Reference Counts
1LANG_NORWEGIAN SUBLANG_NORWEGIAN_BOKMAL

Screenshots


Click here to start video playback

Origin Statistics

URL IDDate AddedURLIPSource
1119041/16/2012 1:10:01 PMhttp://uvoaflzwxu.dns2.us/ivanp34.exe91.217.153.130vxVault

Primary Domain Information

Domain not found

Network Traffic Analysis



HTTP Request Data

HostPortHTTP URIMethod
98.223.246.1380/aYkpTghnswEVQXw.htmGET
97.101.137.1580/kHM8.htmGET
97.85.58.1480/zZk0pubhEyiDwUgf7U.htmGET
93.113.217.1780/cjGl.htmGET
89.116.28.4980/8I6JhjdL8FhGK.htmGET
91.220.90.3380/rehC12OFBWGWL35.htmGET
79.112.67.6080/SShG.htmGET
82.49.196.480/CA0oGEk7.htmGET
82.49.196.480/U67D1T.htmGET
84.205.167.3480/8Hwr6KXcGswKG.htmGET
84.91.28.6280/vHfB89FAdI6.htmGET
85.120.148.3380/djtncP526.htmGET
87.242.57.4080/P6V4Efa.htmGET
77.78.234.2480/gbSy5rqKhQqodklZ.htmGET
77.77.229.5780/HvbQy4.htmGET
76.85.133.1480/BfWX.htmGET
75.23.37.3580/Ya50i.htmGET
76.186.28.4180/ISJF9AuF.htmGET
69.144.28.3180/xmj7dCIm4z6.htmGET
71.203.120.4380/NOkJSY/.htmGET
72.185.8.3080/KbGO.htmGET
74.72.100.5180/aAgm.htmGET
31.11.199.4380/fPcyADRYQnxsDdw0p.htmGET
31.13.208.4780/oxXpVU2wPF.htmGET
31.170.134.1380/ZCJK.htmGET
31.216.189.5780/1p7vW59yW.htmGET
31.42.174.980/41x166tjyF417mawY.htmGET
46.234.144.4480/cFpvqSSZ.htmGET
67.165.216.6680/hmSZVjkx15M.htmGET
213.92.178.5980/TbwBXyh9mJjU.htmGET
217.129.169.5680/8iPZ5wFKkOvIi/lmOHb.htmGET
217.129.230.580/86PCa8uA.htmGET
217.129.230.580/MJLfWpHFyDKBsqE.htmGET
24.12.67.4580/GEfqo/cfEs05.htmGET
24.21.137.6680/RjboocrgCubEgIzmKd.htmGET
24.225.32.5080/MqNLGkZoFCg.htmGET
188.244.25.1980/XDldNnJIq5ZfittSHa.htmGET
190.2.126.580/FSWI16f/iUUt.htmGET
190.2.126.580/tzFMyLVAYs8wH.htmGET
190.238.120.1180/JI9l3kQ4Oa5rHc.htmGET
190.238.120.1180/wKCNf3Ib.htmGET
200.112.142.3480/vjTL.htmGET
200.120.90.3680/LfpGLZFyF3AOwgCVtsF.htmGET
201.224.178.4180/Wkka.htmGET
112.203.89.5780/0BZt5.htmGET
151.0.2.780/cSgT.htmGET
151.0.2.780/QbZ1NULy4X7sG.htmGET
151.27.190.4780/H/2UKGb.htmGET
178.149.196.5980/oly0o2CWwBznI.htmGET
178.216.212.3980/6Suc.htmGET
178.90.58.6080/W5MQaLDhX65up50Nz.htmGET
188.230.107.3980/uT8qlVy9Ih2ed.htmGET
188.24.211.880/9pJ5VbuUOpbq71I.htmGET
107.3.193.3680/yzKBC/nFBNE8/ifDvC.htmGET
109.185.188.4880/IHnawT5pV.htmGET

Discussion

blog comments powered by Disqus