Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Razy"
- * MalScore: 10.0
- * File Name: "Exes_3101bb379708ababc689dd12dd246c11.msi"
- * File Size: 430080
- * File Type: "Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Code page: 1252, Last Printed: Fri Sep 21 09:56:09 2012, Create Time/Date: Fri Sep 21 09:56:09 2012, Name of Creating Application: Windows Installer, Title: Exe to msi converter free, Author: www.exetomsi.com, Template: ;0, Last Saved By: devuser, Revision Number: C35CF0AA-9B3F-4903-9F05-EBF606D58D3E Last Saved Time/Date: Tue May 21 11:56:44 2013, Number of Pages: 100, Number of Words: 0, Security: 0"
- * SHA256: "aedb498efd50d33cf899ec1affb4af6b3502a852384d6f44e4bc154bf2d7a89a"
- * MD5: "3101bb379708ababc689dd12dd246c11"
- * SHA1: "c6d5542ba0b2bf17802d7759e2e5a4c538b8e67f"
- * SHA512: "f2ac3406d1d4b6c9efef3504aeb901f9cf7f70bc71ca9fd3228247ea659f55d7683153db09c7e0dbcdd5e356bd778f99ec8379a5dc18270f03c5d453c078458b"
- * CRC32: "01B4D73F"
- * SSDEEP: "12288:0EFpMm/mmmTiIlmmDWmmmmmmmmmmmmmmmmmmmmmmmmmmmmR/Kcz1WalW7TlK22U9:0EFiCKK127cQWG5M"
- * Process Execution:
- "msiexec.exe"
- * Executed Commands:
- * Signatures Detected:
- "Description": "File has been identified by 19 Antiviruses on VirusTotal as malicious",
- "Details":
- "FireEye": "Gen:Variant.Razy.529852"
- "McAfee": "GenericRXHU-ZV!1017BD43F49F"
- "Arcabit": "Trojan.Razy.D815BC"
- "TrendMicro": "BKDR_HPXORSIL.SM"
- "TrendMicro-HouseCall": "BKDR_HPXORSIL.SM"
- "Avast": "Win32:TrojanX-gen Trj"
- "Kaspersky": "HEUR:Trojan.Win32.Generic"
- "BitDefender": "Gen:Variant.Razy.529852"
- "Emsisoft": "Gen:Variant.Razy.529852 (B)"
- "Invincea": "heuristic"
- "McAfee-GW-Edition": "GenericRXHU-ZV!1017BD43F49F"
- "Microsoft": "Trojan:Win32/Wacatac.B!ml"
- "ZoneAlarm": "HEUR:Trojan.Win32.Generic"
- "GData": "Gen:Variant.Razy.529852"
- "MAX": "malware (ai score=83)"
- "ESET-NOD32": "a variant of MSIL/Kryptik.RYY"
- "Rising": "Trojan.MSIL/Kryptik!1.B1DC (CLASSIC)"
- "Ikarus": "Trojan.MSIL.Inject"
- "AVG": "Win32:TrojanX-gen Trj"
- * Started Service:
- * Mutexes:
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1",
- "Global\\_MSIExecute",
- "Global\\MSILOG_186e96161d5362eGOL.7337aISM_pmeT_lacoL_ataDppA_ubs_sresU_:C"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\MSIa7337.LOG"
- * Deleted Files:
- * Modified Registry Keys:
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment