Enter the MD5, SHA1 or SHA256 hash to search for:        

Summary

Sections


MD5:bf055d2e6aa03b9a574b8d848d80b1bb
SHA1:0bc9406011d80fd646691a091e4f3e5f1634042b
SHA256:f55bec20b8fc010e659cdd024cd817a5193df62e83318c0dc9031918ad907d99
Date Submitted:3/4/2012 7:39:37 PM
Malicious:True
Executable:True
Minotaur Sample ID
131352

FileType Statistics

FileType:
 38.4% (.EXE) Win32 Executable Generic (8527/13/3)
 34.1% (.DLL) Win32 Dynamic Link Library (generic) (7583/30/2)
  9.3% (.EXE) Win16/32 Executable Delphi generic (2072/23)
  9.0% (.EXE) Generic Win/DOS Executable (2002/3)
  9.0% (.EXE) DOS Executable Generic (2000/1)


Identity Statistics

Vendors Declaring Malicious:
TotalVendors:
VirusTotal Report:
http://www.virustotal.com/file/f55bec20b8fc010e659cdd024cd817a5193df62e83318c0dc9031918ad907d99/analysis/

Malware Family Detections:TR/Crypt.ZPACK.Gen2
Win32:MalOb-JI [Cryp]
Win32/Cryptor
Gen:Variant.Kazy.59549
Heuristic.LooksLike.Win32.Winwebsec.E
a variant of Win32/Kryptik.ABTV
Suspicious file
Suspicious.Cloud.5

Static Analysis Data

CRC Data
ClaimedActual
949829949829


Claimed Compile Date:
Sun Jun 25 15:12:36 2006 UTC

CountLanguage Reference Counts
1LANG_PORTUGUESE SUBLANG_PORTUGUESE
1LANG_NORWEGIAN SUBLANG_NORWEGIAN_BOKMAL
1LANG_NEUTRAL SUBLANG_NEUTRAL
1LANG_NEUTRAL SUBLANG_DEFAULT

Screenshots


Click here to start video playback

Origin Statistics

URL IDDate AddedURLIPSource

Primary Domain Information

Network Traffic Analysis



HTTP Request Data

HostPortHTTP URIMethod
173.18.17.19480/QO9vEZL2Zj.htmGET
153.19.164.21080/Wvn9nhOFaKR.htmGET
173.18.17.19480/8j/vHZLGu.htmGET
151.28.113.3680/aJEE.htmGET
153.19.164.21080/szuTuNhgsi4I32.htmGET
174.109.151.10480/mUmmyfT0OZdOvzzz.htmGET
176.240.131.2180/vjTL.htmGET
176.73.170.680/41x166tjyF417mawY.htmGET
176.9.229.13380/7d0TU.htmGET
178.165.69.1280/zZk0pubhEyiDwUgf7U.htmGET
178.168.91.280/CA0oGEk7.htmGET
178.235.51.2980/uT8qlVy9Ih2ed.htmGET
178.48.122.1980/djtncP526.htmGET
178.48.73.2480/Ya50i.htmGET
178.48.86.11980/gEFD.htmGET
178.48.86.11980/TyaG.htmGET
178.90.10.5480/W5MQaLDhX65up50Nz.htmGET
178.95.172.2780/yzKBC/nFBNE8/ifDvC.htmGET
186.19.60.23880/103PMNPCOnPnBzrlK8.htmGET
186.22.136.5380/oly0o2CWwBznI.htmGET
186.97.111.17180/HxoBTXGmspTaG5.htmGET
188.124.101.1780/xmj7dCIm4z6.htmGET
188.2.220.4680/0BZt5.htmGET
188.230.107.3980/AjEt2kCCV/1m88taLY.htmGET
190.112.101.3480/rIP67tC.htmGET
190.114.149.19980/8N1TX7gjlwZz3JIVU.htmGET
190.121.69.13980/wKCNf3Ib.htmGET
190.160.160.1680/KbGO.htmGET
190.162.137.6080/Xu5yqDlrdja7v.htmGET
190.191.213.18980/U67D1T.htmGET
196.202.56.1080/aYkpTghnswEVQXw.htmGET
201.213.176.1480/2FGq4HQ/jMT.htmGET
201.213.176.1480/OGFy.htmGET
212.52.46.2480/8Hwr6KXcGswKG.htmGET
213.113.55.19480/iEHigDHVjaWS7cZS.htmGET
24.178.227.880/JI9l3kQ4Oa5rHc.htmGET
24.241.206.3580/cFpvqSSZ.htmGET
31.133.32.5080/HvbQy4.htmGET
31.207.220.21780/GwXA.htmGET
31.41.12.3280/Wkka.htmGET
31.6.149.1380/kHM8.htmGET
46.249.143.380/MJLfWpHFyDKBsqE.htmGET
46.49.52.2980/6Suc.htmGET
62.143.199.2480/LfpGLZFyF3AOwgCVtsF.htmGET
62.221.134.3980/H/2UKGb.htmGET
62.231.125.3480/fPcyADRYQnxsDdw0p.htmGET
67.172.102.5980/hmSZVjkx15M.htmGET
67.49.92.18980/M/RN38hmnTpS8r4wFc.htmGET
68.119.169.480/Pu6D88534SwA.htmGET
68.185.226.19880/86PCa8uA.htmGET
69.142.117.1680/gbSy5rqKhQqodklZ.htmGET
69.203.114.15180/erdj.htmGET
72.182.9.5580/cSgT.htmGET
72.182.9.5580/wO2yc9F4PIFYHQ.htmGET
72.42.146.23880/G84C.htmGET
76.174.35.21680/FN1B1.htmGET
76.84.14.7180/FSWI16f/iUUt.htmGET
77.120.133.5580/SShG.htmGET
77.91.4.1880/rehC12OFBWGWL35.htmGET
78.142.39.3080/ISJF9AuF.htmGET
78.88.37.3080/P6V4Efa.htmGET
78.92.186.480/QbZ1NULy4X7sG.htmGET
79.124.88.1480/XDldNnJIq5ZfittSHa.htmGET
79.175.219.12480/jK5f.htmGET
79.175.219.12480/KvPZl5HFMP.htmGET
80.27.172.14580/GpMqkHToD.htmGET
81.15.207.4380/8I6JhjdL8FhGK.htmGET
82.237.8.5280/TbwBXyh9mJjU.htmGET
83.251.52.14980/dV9VHjt.htmGET
84.205.164.4680/8iPZ5wFKkOvIi/lmOHb.htmGET
84.38.80.980/ZCJK.htmGET
85.121.218.3980/oxXpVU2wPF.htmGET
86.106.53.16180/OANFjjB9N9.htmGET
87.248.90.3680/GEfqo/cfEs05.htmGET
88.132.4.5680/vHfB89FAdI6.htmGET
88.188.78.5380/9TBfsyPLMcJn.htmGET
88.220.103.5680/dIhPf7YJ4cf.htmGET
89.133.241.280/tzFMyLVAYs8wH.htmGET
89.148.84.4580/MqNLGkZoFCg.htmGET
89.174.234.5680/AavSLDTiwAzICh5.htmGET
89.204.243.3080/5bPTSno.htmGET
89.205.96.12380/jBbzofqNsafxn7.htmGET
89.205.96.12380/samA0.htmGET
89.228.29.4080/IHnawT5pV.htmGET
89.235.225.10180/kE3GzZPf5Z9Sk.htmGET
89.46.237.1280/BfWX.htmGET
89.69.4.4880/1p7vW59yW.htmGET
91.189.34.1480/cjGl.htmGET
91.220.90.3380/NOkJSY/.htmGET
92.47.86.4580/aAgm.htmGET
95.77.237.580/9pJ5VbuUOpbq71I.htmGET
99.135.245.4980/stesTnHdCP.htmGET
99.135.245.4980/TSV9BFIw11Q.htmGET
99.40.31.5880/RjboocrgCubEgIzmKd.htmGET
147.83.118.9280/6Ynqm9wIB.htmGET
130.255.134.6680/yqKb.htmGET
115.43.223.2180/WSYuO/qEndDrOYe.htmGET

DNS Request Data


DNS Requests
Query
akinard.com

DNS Responses
QueryResponse
akinard.com115.43.223.21
akinard.com130.255.134.66
akinard.com147.83.118.92
akinard.com151.28.113.36
akinard.com153.19.164.210
akinard.com173.18.17.194
akinard.com174.109.151.104
akinard.com176.9.229.133
akinard.com178.48.86.119
akinard.com186.19.60.238
akinard.com186.97.111.171
akinard.com188.230.107.39
akinard.com190.112.101.34
akinard.com190.114.149.199
akinard.com190.121.69.139
akinard.com190.162.137.60
akinard.com190.191.213.189
akinard.com201.213.176.14
akinard.com213.113.55.194
akinard.com31.207.220.217
akinard.com67.49.92.189
akinard.com68.119.169.4
akinard.com68.185.226.198
akinard.com99.135.245.49
akinard.com89.235.225.101
akinard.com89.205.96.123
akinard.com89.204.243.30
akinard.com89.174.234.56
akinard.com88.220.103.56
akinard.com88.188.78.53
akinard.com86.106.53.161
akinard.com83.251.52.149
akinard.com80.27.172.145
akinard.com79.175.219.124
akinard.com76.84.14.71
akinard.com76.174.35.216
akinard.com72.42.146.238
akinard.com72.182.9.55
akinard.com69.203.114.151

Discussion

blog comments powered by Disqus