General Information

  • Date:05.07.2016
  • Duration:0h 9m 23s
  • Sample Name:212127.exe
  • Cookbook:default.jbs
  • Icon:
  • Filetype:exe

Detection

MALICIOUS
    • Found 1 malicious signature
    • Contacts 110 domains/IPs
    • Launches 23 processes
    • Drops 1574 files

Signature Overview

    • No. of IPs < 25%
    • 25% < No. of IPs < 50%
    • 50% < No. of IPs < 75%
    • 75% < No. of IPs

    Contacted IPs

    IP Country Flag ASN ASN Name
    31.184.234.22 Russian Federation
    41122 GTOLTD
    31.184.234.23 Russian Federation
    41122 GTOLTD
    31.184.234.24 Russian Federation
    41122 GTOLTD
    31.184.234.25 Russian Federation
    41122 GTOLTD
    31.184.239.90 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.234.20 Russian Federation
    41122 GTOLTD
    31.184.239.91 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.234.21 Russian Federation
    41122 GTOLTD
    31.184.234.190 Russian Federation
    41122 GTOLTD
    31.184.234.191 Russian Federation
    41122 GTOLTD
    31.184.234.192 Russian Federation
    41122 GTOLTD
    31.184.234.193 Russian Federation
    41122 GTOLTD
    31.184.234.188 Russian Federation
    41122 GTOLTD
    31.184.239.89 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.234.187 Russian Federation
    41122 GTOLTD
    65.55.252.93 United States
    3598 MicrosoftCorporation
    31.184.234.189 Russian Federation
    41122 GTOLTD
    31.184.234.184 Russian Federation
    41122 GTOLTD
    31.184.234.183 Russian Federation
    41122 GTOLTD
    31.184.234.186 Russian Federation
    41122 GTOLTD
    31.184.234.185 Russian Federation
    41122 GTOLTD
    31.184.239.82 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.239.81 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.239.84 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.239.83 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.239.86 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.234.27 Russian Federation
    41122 GTOLTD
    31.184.239.85 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.234.26 Russian Federation
    41122 GTOLTD
    31.184.239.88 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.234.29 Russian Federation
    41122 GTOLTD
    31.184.239.87 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.234.28 Russian Federation
    41122 GTOLTD
    31.184.234.13 Russian Federation
    41122 GTOLTD
    31.184.234.14 Russian Federation
    41122 GTOLTD
    31.184.234.11 Russian Federation
    41122 GTOLTD
    31.184.234.12 Russian Federation
    41122 GTOLTD
    31.184.234.10 Russian Federation
    41122 GTOLTD
    31.184.234.199 Russian Federation
    41122 GTOLTD
    31.184.234.198 Russian Federation
    41122 GTOLTD
    31.184.234.197 Russian Federation
    41122 GTOLTD
    31.184.234.196 Russian Federation
    41122 GTOLTD
    31.184.234.195 Russian Federation
    41122 GTOLTD
    31.184.234.194 Russian Federation
    41122 GTOLTD
    31.184.239.95 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.239.94 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.239.93 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.239.92 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.234.19 Russian Federation
    41122 GTOLTD
    31.184.239.99 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.234.18 Russian Federation
    41122 GTOLTD
    31.184.239.98 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.234.17 Russian Federation
    41122 GTOLTD
    31.184.239.97 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.234.16 Russian Federation
    41122 GTOLTD
    31.184.239.96 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.234.15 Russian Federation
    41122 GTOLTD
    31.184.234.40 Russian Federation
    41122 GTOLTD
    31.184.234.41 Russian Federation
    41122 GTOLTD
    31.184.234.42 Russian Federation
    41122 GTOLTD
    31.184.234.43 Russian Federation
    41122 GTOLTD
    31.184.234.44 Russian Federation
    41122 GTOLTD
    31.184.234.45 Russian Federation
    41122 GTOLTD
    31.184.234.46 Russian Federation
    41122 GTOLTD
    31.184.234.47 Russian Federation
    41122 GTOLTD
    31.184.239.68 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.239.67 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.239.69 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.239.64 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.234.49 Russian Federation
    41122 GTOLTD
    31.184.239.63 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.234.48 Russian Federation
    41122 GTOLTD
    31.184.239.66 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.239.65 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.239.60 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.239.62 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.239.61 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.234.31 Russian Federation
    41122 GTOLTD
    31.184.239.80 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.234.32 Russian Federation
    41122 GTOLTD
    31.184.234.30 Russian Federation
    41122 GTOLTD
    31.184.234.35 Russian Federation
    41122 GTOLTD
    31.184.234.36 Russian Federation
    41122 GTOLTD
    31.184.234.33 Russian Federation
    41122 GTOLTD
    31.184.234.34 Russian Federation
    41122 GTOLTD
    31.184.239.79 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.239.78 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.239.77 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.239.76 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.234.39 Russian Federation
    41122 GTOLTD
    31.184.239.75 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.234.38 Russian Federation
    41122 GTOLTD
    31.184.239.74 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.234.37 Russian Federation
    41122 GTOLTD
    31.184.239.73 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.239.72 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.239.71 Russian Federation
    44050 PetersburgInternetNetworkltd
    31.184.239.70 Russian Federation
    44050 PetersburgInternetNetworkltd
    23.7.233.120 United States
    3257 TinetSpA
    31.184.234.102 Russian Federation
    41122 GTOLTD

    Contacted Domains

    Name IP Active
    www.microsoft.com 23.0.91.168 true
    27lelchgcvs2wpm7.fgfid6.top 216.189.148.182 true
    iecvlist.microsoft.com 72.21.81.200 true
    ipinfo.io 54.88.175.149 true
    ocsp.verisign.com 23.4.43.27 true
    crl.microsoft.com 181.174.80.144 true
    sqm.telemetry.microsoft.com 65.55.252.93 true
    r20swj13mr.microsoft.com 72.21.81.200 true
    ieonline.microsoft.com 204.79.197.200 true
    go.microsoft.com 23.7.233.120 true