Enter the MD5, SHA1 or SHA256 hash to search for:        

Summary

Sections


MD5:f94e26d1bb5f61b3ffc1c1cba4c9ec1b
SHA1:e7b48ff551a0deb00b6ee2ce38fb947f4d40b265
SHA256:f2ee318b3233229f1626a6b94f9f11b47190d40e19932a90c8b065d73c566b36
Date Submitted:1/15/2012 2:02:29 AM
Malicious:True
Executable:True
Minotaur Sample ID
110091

FileType Statistics

FileType:
 38.4% (.EXE) Win32 Executable Generic (8527/13/3)
 34.1% (.DLL) Win32 Dynamic Link Library (generic) (7583/30/2)
  9.3% (.EXE) Win16/32 Executable Delphi generic (2072/23)
  9.0% (.EXE) Generic Win/DOS Executable (2002/3)
  9.0% (.EXE) DOS Executable Generic (2000/1)


Identity Statistics

Vendors Declaring Malicious:
TotalVendors:
VirusTotal Report:
http://www.virustotal.com/file/f2ee318b3233229f1626a6b94f9f11b47190d40e19932a90c8b065d73c566b36/analysis/

Malware Family Detections:TR/ATRAPS.Gen2
Gen:Variant.Kazy.52571
W32/Kryptik.XUW!tr
Generic BackDoor.wl
Heuristic.LooksLike.Win32.Winwebsec.E
a variant of Win32/Kryptik.YWJ
Suspicious file
Suspicious.Cloud.5

Static Analysis Data

CRC Data
ClaimedActual
902781902781


Claimed Compile Date:
Fri Mar 30 15:11:12 2007 UTC

CountLanguage Reference Counts
1LANG_ENGLISH SUBLANG_ENGLISH_UK

Screenshots


Click here to start video playback

Origin Statistics

URL IDDate AddedURLIPSource
1114321/15/2012 2:02:30 AMhttp://ahczbhl.ddns.me.uk/ivanp33.exe91.217.153.130Clean-MX

Primary Domain Information

Domain not found

Network Traffic Analysis



HTTP Request Data

HostPortHTTP URIMethod
124.96.161.5280/oxXpVU2wPF.htmGET
180.235.176.5380/IHnawT5pV.htmGET
186.136.202.4180/NOkJSY/.htmGET
188.244.25.1980/XDldNnJIq5ZfittSHa.htmGET
189.143.88.4180/ISJF9AuF.htmGET
190.19.221.6680/1p7vW59yW.htmGET
190.192.2.7080/TbwBXyh9mJjU.htmGET
190.213.142.3480/LfpGLZFyF3AOwgCVtsF.htmGET
190.6.237.3880/yzKBC/nFBNE8/ifDvC.htmGET
190.6.4.080/CA0oGEk7.htmGET
197.220.154.4080/P6V4Efa.htmGET
200.120.164.7180/oly0o2CWwBznI.htmGET
212.52.48.6780/HvbQy4.htmGET
218.171.56.7280/W5MQaLDhX65up50Nz.htmGET
24.107.187.4780/H/2UKGb.htmGET
24.129.73.4780/GEfqo/cfEs05.htmGET
24.2.29.480/MJLfWpHFyDKBsqE.htmGET
24.29.200.6080/8iPZ5wFKkOvIi/lmOHb.htmGET
31.129.106.6080/aAgm.htmGET
31.133.43.4380/cFpvqSSZ.htmGET
31.134.213.7380/SShG.htmGET
31.170.134.1380/aYkpTghnswEVQXw.htmGET
31.170.137.7480/hmSZVjkx15M.htmGET
31.216.189.5780/8I6JhjdL8FhGK.htmGET
31.223.221.780/9pJ5VbuUOpbq71I.htmGET
31.42.167.1680/kHM8.htmGET
41.77.12.3980/uT8qlVy9Ih2ed.htmGET
50.134.152.4180/Wkka.htmGET
62.84.50.680/QbZ1NULy4X7sG.htmGET
66.177.116.2380/gbSy5rqKhQqodklZ.htmGET
66.74.52.2580/KbGO.htmGET
67.190.236.280/tzFMyLVAYs8wH.htmGET
68.113.109.1080/JI9l3kQ4Oa5rHc.htmGET
69.142.117.1680/zZk0pubhEyiDwUgf7U.htmGET
72.185.8.3080/djtncP526.htmGET
75.131.253.1280/ZCJK.htmGET
76.17.124.4080/6Suc.htmGET
77.77.229.5780/MqNLGkZoFCg.htmGET
85.120.148.3380/Ya50i.htmGET
85.122.52.1080/41x166tjyF417mawY.htmGET
86.38.209.6580/0BZt5.htmGET
91.220.90.3380/8Hwr6KXcGswKG.htmGET
91.73.53.3080/vjTL.htmGET
92.115.124.1680/BfWX.htmGET
93.113.217.1780/cjGl.htmGET
93.113.38.2980/xmj7dCIm4z6.htmGET
93.95.70.2980/rehC12OFBWGWL35.htmGET
97.88.24.7480/vHfB89FAdI6.htmGET
98.228.111.4280/fPcyADRYQnxsDdw0p.htmGET
98.233.107.7480/RjboocrgCubEgIzmKd.htmGET

Discussion

blog comments powered by Disqus