Detections

Yara:

jRat

Analysis

Category Package Started Completed Duration Options Log
FILE zip 2020-06-23 05:56:25 2020-06-23 06:02:42 377 seconds Show Options Show Log
route = tor
2020-05-13 09:30:36,266 [root] INFO: Date set to: 20200623T05:56:24, timeout set to: 200
2020-06-23 05:56:24,062 [root] DEBUG: Starting analyzer from: C:\tmplodztmkc
2020-06-23 05:56:24,062 [root] DEBUG: Storing results at: C:\FUsnYZaB
2020-06-23 05:56:24,062 [root] DEBUG: Pipe server name: \\.\PIPE\BBzlJCLa
2020-06-23 05:56:24,062 [root] DEBUG: Python path: C:\Users\Louise\AppData\Local\Programs\Python\Python38-32
2020-06-23 05:56:24,062 [root] DEBUG: No analysis package specified, trying to detect it automagically.
2020-06-23 05:56:24,062 [root] INFO: Automatically selected analysis package "zip"
2020-06-23 05:56:24,062 [root] DEBUG: Trying to import analysis package "zip"...
2020-06-23 05:56:24,125 [root] DEBUG: Imported analysis package "zip".
2020-06-23 05:56:24,125 [root] DEBUG: Trying to initialize analysis package "zip"...
2020-06-23 05:56:24,125 [root] DEBUG: Initialized analysis package "zip".
2020-06-23 05:56:24,187 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.browser"...
2020-06-23 05:56:24,187 [root] DEBUG: Imported auxiliary module "modules.auxiliary.browser".
2020-06-23 05:56:24,187 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.curtain"...
2020-06-23 05:56:24,203 [root] DEBUG: Imported auxiliary module "modules.auxiliary.curtain".
2020-06-23 05:56:24,203 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.digisig"...
2020-06-23 05:56:24,218 [root] DEBUG: Imported auxiliary module "modules.auxiliary.digisig".
2020-06-23 05:56:24,218 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.disguise"...
2020-06-23 05:56:24,234 [root] DEBUG: Imported auxiliary module "modules.auxiliary.disguise".
2020-06-23 05:56:24,234 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.human"...
2020-06-23 05:56:24,249 [root] DEBUG: Imported auxiliary module "modules.auxiliary.human".
2020-06-23 05:56:24,249 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.procmon"...
2020-06-23 05:56:24,249 [root] DEBUG: Imported auxiliary module "modules.auxiliary.procmon".
2020-06-23 05:56:24,249 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.screenshots"...
2020-06-23 05:56:24,249 [modules.auxiliary.screenshots] DEBUG: Importing 'time'
2020-06-23 05:56:24,249 [modules.auxiliary.screenshots] DEBUG: Importing 'StringIO'
2020-06-23 05:56:24,249 [modules.auxiliary.screenshots] DEBUG: Importing 'Thread'
2020-06-23 05:56:24,249 [modules.auxiliary.screenshots] DEBUG: Importing 'Auxiliary'
2020-06-23 05:56:24,249 [modules.auxiliary.screenshots] DEBUG: Importing 'NetlogFile'
2020-06-23 05:56:24,249 [modules.auxiliary.screenshots] DEBUG: Importing 'Screenshot'
2020-06-23 05:56:24,265 [lib.api.screenshot] DEBUG: Importing 'math'
2020-06-23 05:56:24,265 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageChops'
2020-06-23 05:56:24,406 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageGrab'
2020-06-23 05:56:24,421 [lib.api.screenshot] DEBUG: Importing 'PIL.ImageDraw'
2020-06-23 05:56:24,421 [modules.auxiliary.screenshots] DEBUG: Imports OK
2020-06-23 05:56:24,421 [root] DEBUG: Imported auxiliary module "modules.auxiliary.screenshots".
2020-06-23 05:56:24,421 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.sysmon"...
2020-06-23 05:56:24,437 [root] DEBUG: Imported auxiliary module "modules.auxiliary.sysmon".
2020-06-23 05:56:24,437 [root] DEBUG: Trying to import auxiliary module "modules.auxiliary.usage"...
2020-06-23 05:56:24,437 [root] DEBUG: Imported auxiliary module "modules.auxiliary.usage".
2020-06-23 05:56:24,437 [root] DEBUG: Trying to initialize auxiliary module "Browser"...
2020-06-23 05:56:24,437 [root] DEBUG: Initialized auxiliary module "Browser".
2020-06-23 05:56:24,437 [root] DEBUG: Trying to start auxiliary module "Browser"...
2020-06-23 05:56:24,437 [root] DEBUG: Started auxiliary module Browser
2020-06-23 05:56:24,437 [root] DEBUG: Trying to initialize auxiliary module "Curtain"...
2020-06-23 05:56:24,437 [root] DEBUG: Initialized auxiliary module "Curtain".
2020-06-23 05:56:24,453 [root] DEBUG: Trying to start auxiliary module "Curtain"...
2020-06-23 05:56:24,453 [root] DEBUG: Started auxiliary module Curtain
2020-06-23 05:56:24,453 [root] DEBUG: Trying to initialize auxiliary module "DigiSig"...
2020-06-23 05:56:24,453 [root] DEBUG: Initialized auxiliary module "DigiSig".
2020-06-23 05:56:24,453 [root] DEBUG: Trying to start auxiliary module "DigiSig"...
2020-06-23 05:56:24,453 [modules.auxiliary.digisig] DEBUG: Checking for a digital signature.
2020-06-23 05:56:25,656 [modules.auxiliary.digisig] DEBUG: File format not recognized.
2020-06-23 05:56:25,656 [modules.auxiliary.digisig] INFO: Uploading signature results to aux/DigiSig.json
2020-06-23 05:56:25,656 [root] DEBUG: Started auxiliary module DigiSig
2020-06-23 05:56:25,656 [root] DEBUG: Trying to initialize auxiliary module "Disguise"...
2020-06-23 05:56:25,656 [root] DEBUG: Initialized auxiliary module "Disguise".
2020-06-23 05:56:25,656 [root] DEBUG: Trying to start auxiliary module "Disguise"...
2020-06-23 05:56:25,687 [root] DEBUG: Started auxiliary module Disguise
2020-06-23 05:56:25,687 [root] DEBUG: Trying to initialize auxiliary module "Human"...
2020-06-23 05:56:25,687 [root] DEBUG: Initialized auxiliary module "Human".
2020-06-23 05:56:25,687 [root] DEBUG: Trying to start auxiliary module "Human"...
2020-06-23 05:56:25,703 [root] DEBUG: Started auxiliary module Human
2020-06-23 05:56:25,703 [root] DEBUG: Trying to initialize auxiliary module "Procmon"...
2020-06-23 05:56:25,718 [root] DEBUG: Initialized auxiliary module "Procmon".
2020-06-23 05:56:25,718 [root] DEBUG: Trying to start auxiliary module "Procmon"...
2020-06-23 05:56:25,718 [root] DEBUG: Started auxiliary module Procmon
2020-06-23 05:56:25,718 [root] DEBUG: Trying to initialize auxiliary module "Screenshots"...
2020-06-23 05:56:25,718 [root] DEBUG: Initialized auxiliary module "Screenshots".
2020-06-23 05:56:25,718 [root] DEBUG: Trying to start auxiliary module "Screenshots"...
2020-06-23 05:56:25,718 [root] DEBUG: Started auxiliary module Screenshots
2020-06-23 05:56:25,718 [root] DEBUG: Trying to initialize auxiliary module "Sysmon"...
2020-06-23 05:56:25,718 [root] DEBUG: Initialized auxiliary module "Sysmon".
2020-06-23 05:56:25,718 [root] DEBUG: Trying to start auxiliary module "Sysmon"...
2020-06-23 05:56:25,718 [root] DEBUG: Started auxiliary module Sysmon
2020-06-23 05:56:25,718 [root] DEBUG: Trying to initialize auxiliary module "Usage"...
2020-06-23 05:56:25,718 [root] DEBUG: Initialized auxiliary module "Usage".
2020-06-23 05:56:25,718 [root] DEBUG: Trying to start auxiliary module "Usage"...
2020-06-23 05:56:25,734 [root] DEBUG: Started auxiliary module Usage
2020-06-23 05:56:25,734 [root] INFO: Analyzer: Package modules.packages.zip does not specify a DLL option
2020-06-23 05:56:25,734 [root] INFO: Analyzer: Package modules.packages.zip does not specify a DLL_64 option
2020-06-23 05:56:25,734 [root] INFO: Analyzer: Package modules.packages.zip does not specify a loader option
2020-06-23 05:56:25,734 [root] INFO: Analyzer: Package modules.packages.zip does not specify a loader_64 option
2020-06-23 05:56:26,625 [modules.packages.zip] DEBUG: Missing file option, auto executing: META-INF/MANIFEST.MF
2020-06-23 05:56:26,625 [modules.packages.zip] DEBUG: file_name: "META-INF/MANIFEST.MF"
2020-06-23 05:56:26,625 [lib.api.process] ERROR: Failed to execute process from path "C:\Users\Louise\AppData\Local\Temp\META-INF/MANIFEST.MF" with arguments "None" (Error: %1 is not a valid Win32 application (ERROR_BAD_EXE_FORMAT))
2020-06-23 05:56:26,640 [root] ERROR: Traceback (most recent call last):
  File "C:/tmplodztmkc/analyzer.py", line 509, in run
    pids = self.package.start(self.target)
  File "C:\tmplodztmkc\modules\packages\zip.py", line 169, in start
    return self.execute(file_path, self.options.get("arguments"), file_path)
  File "C:\tmplodztmkc\lib\common\abstracts.py", line 127, in execute
    raise CuckooPackageError("Unable to execute the initial process, "
lib.common.exceptions.CuckooPackageError: Unable to execute the initial process, analysis aborted.

During handling of the above exception, another exception occurred:

Traceback (most recent call last):
  File "C:/tmplodztmkc/analyzer.py", line 1469, in <module>
    success = analyzer.run()
  File "C:/tmplodztmkc/analyzer.py", line 514, in run
    raise CuckooError("The package \"{0}\" start function raised an "
lib.common.exceptions.CuckooError: The package "modules.packages.zip" start function raised an error: Unable to execute the initial process, analysis aborted.
Traceback (most recent call last):
  File "C:/tmplodztmkc/analyzer.py", line 509, in run
    pids = self.package.start(self.target)
  File "C:\tmplodztmkc\modules\packages\zip.py", line 169, in start
    return self.execute(file_path, self.options.get("arguments"), file_path)
  File "C:\tmplodztmkc\lib\common\abstracts.py", line 127, in execute
    raise CuckooPackageError("Unable to execute the initial process, "
lib.common.exceptions.CuckooPackageError: Unable to execute the initial process, analysis aborted.

During handling of the above exception, another exception occurred:

Traceback (most recent call last):
  File "C:/tmplodztmkc/analyzer.py", line 1469, in <module>
    success = analyzer.run()
  File "C:/tmplodztmkc/analyzer.py", line 514, in run
    raise CuckooError("The package \"{0}\" start function raised an "
lib.common.exceptions.CuckooError: The package "modules.packages.zip" start function raised an error: Unable to execute the initial process, analysis aborted.
2020-06-23 05:56:26,640 [root] WARNING: Folder at path "C:\FUsnYZaB\debugger" does not exist, skip.
2020-06-23 05:56:26,640 [root] INFO: Analysis completed.

Machine

Name Label Manager Started On Shutdown On
win7x64_4 win7x64_8 KVM 2020-06-23 05:56:25 2020-06-23 06:02:42

File Details

File Name Mzyzvg1CUgodl3r
File Size 185967 bytes
File Type Zip archive data, at least v2.0 to extract
MD5 18d03b485eefbe58d3bae1c3eff49357
SHA1 fef25ab8c1396737552bfeafb9354d9b066ed951
SHA256 2fa5fae0c2c9933044085f0d555b0453f1027cd11731ca3164673a6175b41476
SHA512 27b2e60c6171a66904b23aa19bcd58812957260535e7bcba560333a8be915a038934b8be2ab9bb5f9be4a7d4c28fbb307341512899ea5d2a138cadaed4466e43
CRC32 BF6A23A0
Ssdeep 3072:IT7cVR8m7iKhmTxgxmwBpPk87AktqgcNi/GCYSyqkjq2bIR0KBXn3MJ9T:gorKfopsIzAvi/jXkHbIR3RnK1
CAPE Yara
Download Download ZIP Resubmit sample

Signatures

Queries or connects to DNS-Over-HTTPS/DNS-Over-TLS domain or IP address
ip: 1.1.1.1
CAPE detected the jRat malware family
File has been identified by 33 Antiviruses on VirusTotal as malicious
MicroWorld-eScan: Java.Backdoor.Jacksbot.A
FireEye: Java.Backdoor.Jacksbot.A
McAfee: JV/BackDoor-FAZY!18D03B485EEF
Zillya: Trojan.Jacksbot.JS.45
Alibaba: Backdoor:JAVA/Kryptik.d717ce80
Arcabit: Java.Trojan.GenericGB.D699E
Cyren: Java/Jacksbot.I
Symantec: Backdoor.Jeetrat
ESET-NOD32: Java/Jacksbot.O
TrendMicro-HouseCall: JAVA_JACKSBOT.AC
Avast: Java:Agent-HCH [Trj]
Kaspersky: Backdoor.Java.Agent.d
BitDefender: Java.Backdoor.Jacksbot.A
NANO-Antivirus: Trojan.Java.Jrat.cpocnu
AegisLab: Trojan.Java.Agent.m!c
Ad-Aware: Java.Backdoor.Jacksbot.A
Emsisoft: Java.Backdoor.Jacksbot.A (B)
Comodo: [email protected]#18k9ucv4rlzz
F-Secure: Exploit.EXP/CVE-2011-3544.U.Gen
DrWeb: Java.Jrat.1
TrendMicro: JAVA_JACKSBOT.AC
McAfee-GW-Edition: JV/BackDoor-FAZY!18D03B485EEF
Sophos: Mal/Jacksbot-A
Ikarus: Trojan.Java.Jacksbot
F-Prot: Java/Jacksbot.I
Jiangmin: Backdoor.Java.ea
Avira: ie.class
ZoneAlarm: Backdoor.Java.Agent.d
MAX: malware (ai score=85)
Tencent: Java.Backdoor.Agent.Eaxk
GData: Java.Trojan.GenericGB.27038
AVG: Java:Agent-HCH [Trj]
Qihoo-360: Generic/Backdoor.790

Screenshots


Hosts

Direct IP Country Name
Y 8.8.8.8 [VT] United States
Y 1.1.1.1 [VT] Australia

DNS

No domains contacted.


Summary

No static analysis available.
META-INF/MANIFEST.MF
a.classuPMK
[y)'.
M1ojO0
ab.class]PMK
ac.classuSmSRA
S*,{1
obNiSJ[D
e9:]T*
Uk'7/
ad.class
szm8V
;5:h$
| 54d$
Ay:cNW
)ZXVU]
6qB}+N
a=gE<
#m"m%
ae.classuR]s
0;,,v
VMnXJ
C%H%Ex
}=C`7
af.classmR
o$V$V
b.class
Y<c`F
cnLs"S
X,OHY`
)rT">d
bb.class
0x_-%
QwOf~
_188T
l!|as
,kl=.
x^[B'
bc.class]
bd.class
3fjC'
8CA<I
(,GQK3']6
_PaA8?
g[r(>
GqAHyZ
F)-/q
be.class
Shu:3f
9sh92
oqW[(
]@5]B
S|#9w
JWhHC
bf.class
=aFU|
L~p*W(Z
#i9xO
=TF[d
;|QWC
;xXF.
c.class
<i&8N
l?**\
cb.class}SmS
eZj D?
cc.class
f%Htj7VW
&yk-g
.l>.&
`$,?A T
cd.class
FLL(1
e<`)K
,8d61
ce.class
&WicO
Y:IHa
Qt3uw
cf.classmQMs
Yx2B*<
aJ4UB
d.class
EdUPT\P
/Lo0}
}"D&?S
1U1U3-`Z
f+u_?
\@v$>
XrIgN
}+Fwv
:zSRfk
uUC~:?
AM7)w]}
u%TXm
1*KFk
R2N{/'
2K{^';]
W12O{n"[
o%;_M
PEXHh"
0F8J8N8Ix
&l"l'
I7O4d
>7/3d
9}KSXk
>CNf-
R.pM8
CT`>D
#'Ayd!TD.
db.class
s:t4)qXG%
b*Ite
sRst9
dc.class
@H"j4
8<jDC
Mc6Uz
swgmYmY
EFMcw
q#aNP
0Wm1W
f)@q=E
\KY8O
HYwj$
eXh!2S_
dd.class
,e!$!
%NI$$NK
v\BWu
*X6iv
:^K$9
OR+r%S9
de.classU
6nmUD/
bH4b
hdJc/
df.class
p_nqc
`_kvZ
K|4>c
//RJW.
`(HmD'
m4K6t
2-vO\
E0IY/
${Il$GIN
e.class
KQ Y?
eb.class
Gjv}~
T*4|2
/m7)K
Q(p8dK
-eHH'i
P8tNq
ec.classmPMK
(^D/
ed.classmP
QHLHL0n
!\1LQ
)p{Q-
ee.class
7%xqN
naG/Z
ef.class
&iJkC
Q|,"*
s"&E\
gi|?c
f.class
I9u=78
={&;U
fb.class
8m"%yc
2S[3q
Dr9e
^ClIz=
fc.class
6aa`q
Z+fEe
fd.class
Fq/gT
GBIDC
fe.class
5&4.k\
X81KgW
5nv1la
XA)m.
ff.classuQ
#%Uzwx
g.class
?gfvfv2$
@ @\@
sf7d!
)(hp*
]lAz>
)*~s+
hd9r"p
{k" =
;;a}\f
|DmCB2
d]Bb?bx]'
]MGkB8:YX
Dkf_g
jVoOCg
.+22%8
\q>QC
> zPxAx
hTxZx
^h$Z*
K%D5)W
[Z/Q|
gb.classuP
9686S`
gc.class
ym]kY
65_c,
\p~_
AR*?|y
P;#<f
?!V)~
gd.class]O
ge.class
op&3~p
9F8F9b
c<1J.X=
yhw4%
F4A[P
aYAb(2
C+QIA
C9-e]
c%Im^
y?*ON
gf.classmSKO
\Wq_z3
h.class
Zy|TE
vwUwuuuuU
N $;zLT
<BzME
2HZ?R
py=<ht
V,s0id
>W`KQ
HwxMjN_j
|FeL&
{',es
's4{2
DLBfU
^w0`,u
?8I0b
F7+^Ti
X7yyj[
8}<B3k
%f}+]j
PCpVU
$.Sl#B
E\Vp9
&pgq'.
waZu'
'b6*q<
(#Mz9&
Py\y]y
*\BN\J
mfTPMn
x={{Z1{=3
wtQ|g{L
TjpAZA
hb.classuP
I)`KJ
*vQPQA
hc.classe
:aO6w
fEkOl>
hd.class]NMK
.fi&h
he.class
U{i=zi
BE#CH%S>
C3j1l;
TX+0'i
kC^^@[88`Z
O'wAq
Io5kc
;K.q83c
}M|(>"
9qJ!,
hf.class
U[SSW
1"#*#&
Z"JZr
j|R;2
(!MO0
7'f "
i.class
?HoW1
mw;mL
|ulk7
5g-N^
ib.classuTYS
U(8'E
(89?^Br
]X7RY1
ic.classuRMo
YH!gA
(XH#o
T#1F<
id.classuQ
CF!H+
!$U,cA
VUlJV
ie.class
NH <J
NJHHHJ
)3nw5
gPo}8
r8F]B
4F3/-
j.classmQ]K
sFN=%
P_GD~:k
jb.class
Lf:>T
pFBTBL
O34143
45LaD
Q*q$:.
0"3IHcjhT
jc.class
UKo[E
Kr]?R
!qSbJ"
R!i\1
@]:IFI
Cqs1B[Y
.1KMJ
=:V+Ib
^n[j}_
jd.class]PMO
WJW*((
CILHL0^
2KZ}3
kme7RjJ CpF1
je.class
%}L-m
i}$Z8'<
]XG7^
jf.class
/+xE!(D
-R(W!
MEu}c
EKM5o
8Ffxc
11-9og
?dhTF
k.class
OGHpCBe
*Zwr>
Tn<13O{
B*3K?
;Z;Z;
"FD^T
r"#z,
(w/0W
`Ni[E
x$\P=
4$ @%Y
kb.class
[fX_W
f<V3kd
hd4::
B%X,P
kc.class
(8TaZ
C{rKL
kd.class
D?+.X
ke.class
W[T[Y
qVgd:
%BLWH
D$6M'
!ZMCU
{/5pCjL
aIRj&
0E0G-
J<WC'A
a-y{x
l.class
b*Bx[
Y[w)d
%.!Jq
lb.class
VktSY
+q\A%z
`J(kT
=#F~D
2)F(l
=Ir[(
ILgq?x:x
lc.classuRMo
ahICK
8e"P"
2]"#!
ld.class
Co0vB
3o$MR
=}{h{V
.#e}y
U(,B]
le.class
Wy|TW
odc!nSaG
<##z`
2$>78
nUbh`O
~,I"K`
CCGUe
=)?yT
,agROI
VB*@-
m.class
RI_ y(
;z7Ei
=-Lu*hM
mb.class]OMK
**Ocg
mc.class
IHJHIxM
[V8pV
(c7>*
\$Xa[Zb
ec"o0
lK0L3
3:mI4x}
,z}fG!
TNR9K
md.classuQ]K
me.class
mG.>lG
5>OOO
\nSyv
e:wJ`
n%KsFB
6ge+!
e*K!K
<SU?V
b)b)f)a)e)c)g
a]s?"
TC'o:
eE}Xp
f)k0[i
zT({0W
<x<7K
f)@.E
[x)nevs
|qw1y,
r,Ob4
7M%3=
Lc.?gc
/|Fq~
n.class
e!zex
`V#5wt
2Bb1MV
8_-0r<[05}&#"
T<6:<ms4
GV:&+h
|Y\4z3
nb.class
vw0*#
;p2Ogg
eJG}XR2
JG]Ri7K1
m../%
+C=c.4
nc.classmP]K
TAHIH
kXFFBV
C (Pa
@yBl)
nd.classmRKs
9LjXD
:oqi!
ne.class
kfwfv
o.class
Li+$%|C
W((\W(
|e0^|
|}~,5
$Sl^+
1=fv0t;f
ob.class
_(U#X5
$r=!RG
>gXcd
T1ZQe?
oc.classuRkO
8v8v9
!]u=y
od.class
9=R]d
}U1f
hYJK#
oe.class
ryiWa
jq_FT
v}<Yg0
qet[s0
5V~hk
zO|rD
|oh9^
QO6"n
3Xbq*
zL\OAJ
5i!5r
_E&Q!
4<(^A
5<Xt%ym
p.class;
^VbY"#
pb.class
ng\F*e&
H<9H/
hc1`.
HOgkUs
.P.0[
aKS8d
Q[8*9
pc.classuR]O
]EO4Ca
pd.classuQ]K
,YybF,
pe.class
+H(H*8
AD4DqHC
jgH%x
HL#m#
z"+9e
q.class]
nw](X
ZEkH$$
XN,/V
qb.classeRmS
eX$/54M
qc.class]OMO
qc.IL2
qd.class
E?G/G
qe.class
W{x[e
2A}DQ
=*R*FU
{*d_wwOAKck
}KWGQ
[W~iGk
HAbgR?
pv5yO
Z](A!
9>H&"D{80
OV=}r
^kOB[Zj
g/-QoN
].OG.
y;=:I,
[hhzA
zFEiJ
fQsS[Fm
r.classuP]K
rb.classmS]O
'Tz$'L#zr
rc.classuR[O
0:HZZ5:;
rd.classe
@T`XE
re.class
P:<rz
M:ffy
2s%+q
W%2o`
0x3x9X
_2tO5
\qeE9A/c
s.class
T[sSU
$-A%+
HIaqY
I^x,l
;6Q}4b
sb.class
}cu^x?
^E\r$
/<WB_
8u.CN
h>zWQJ
sc.class
60: H29
h+Z1,`D
QLV]'[j]
O;Y( I
kAD>@?
sd.class
BkcC5M
3PwA`W
fbv(!
#;9'P
CT!A}
:2Jsp
se.classmS
ZN+]3
SFpi.
t.class
Kj1^j
sz.=d'!]
4\93KZj
8)^s;%.
T/5R<fn|Iyd
e./)c
8^XJ}
M7y1*G
l71*'
Rfj>j
@Csm}
<A_4,
}GOBGy
/2T((
u^n3|
>Y,S]
^O+Dz
!(e^X
G)vcK
tb.class
%1'q[
\drO!
tc.classeP]K
td.classUOMK
te.classmR
&e<3+J
g_ ;L
u.classuR
k;9oo
ub.class
!%e}x
ALcFB
5Mn -
uc.classmS_SRQ
#^Ep.
"ps898
ud.classmPMK
(^D/6^"
@K`Y`E`U
2j0Ymf
ue.classuR]O
"~C_k
f.R/R
v.class
s,p$8
b`ho
g{TxaP
/5;71:1z
@:&f*'f%/
-$*I
%Bt9!
S^2]1
vb.class
Z/i1Y
vcM,s
$$6Rv
]dc!(
Skwa?"a
d.}m0
vc.class}U
e,!.C
K2VqY
vK)(Ae
m1o*Veqw
n|UMY
5N'3a
T3J>k
CU$G=
vd.class]
ve.class
RJ[JK
0-aFBDBT
fm5v1
ZT?
I5\H"
Q})\>
EMjL}
4[Awg
w<IXK
6{aj>
w.class]NMK
\x3og
Th),+
4+.M:
n|p*XLJ3x
wb.class
3D8Z(
B`i
jZGj&
wc.classuR
.aK,I
vaK f
wd.class]OMO
we.classuT]W
Pmb[;In`
CSH[m
LT1\C
x.classeR
Kl#kS
$6%nK
s Q5P3p
xb.class
3*>P1
N^mWF
xc.classuS]S
8f8f9
UO<ln
&i5B3
xd.classePMO
dHU=_
X"#W`
.A1EU
xe.classuS
]Q~!v%5%
y.class
]Ag9*
H.ceEZ)
zFIIFR
$A%:Rj
yb.class]OMK
yc.class]O
yd.classmR]O
Hd]Lc
9\uQD
nSmo3O
}J23gq
INN1:F
ye.class
vz{WA
s?.P3a
5[~Xk
;$<s<
dh0oUa(
QU#2kf
z.class]PMK
u>InS
zb.class
]+Ykkn<
!"xZyiM
AJA'6D
zc.class]PMk
dO*Z2#
zd.class]OMK
T2aE,
+B=6j
ze.class
U[SSW
-sRfz
V"? Y
npFkV
9iU6Kw
kf.class
lIe[^$[
~Xo~Zo>
O[?{#3
_y:_?
XSns$|2
^~9r;v
J=><>
awRtH
z}z7w
Vo.y;
i)w#CK
!vN"1n
q.t0#[j
3_G!
'He/^
d9{F8X
{#s7v
Cx>w6
C/_|%
IlZp(
3VS>6
b;d+f
gr0^%l0
WY9{w
\fhwDY
f7TLq
vGvlZ
p.?2B
Y"r2C
D{6acg
8 %dl
nG)uN
3nO]C
Vo>\'L
-H=sp
?Sn{,
qHEW'
<>,rd
gs-dX
L%I3)qnc
HKaR{
Q8vK`
)5 kzq
]M -Hb
A*!4LJY
F's i
0SqlGa
6PT,S
dPxr0
T3T:y
)9X[v
N[-~i
}[f}6
*zlT<
\N9YS
@I;CkQA
\ ;hZ
]9FChXc
Q^)s1
d?T^u(r
@G|Wn
=#1OX
GIsYQn~IB
Z(n1rS(
z`d`=?
d[U!2.
\w}1M6
nOq8V
qMrN}
q&6v8
xQ5MS
r7}k|A
N]T$Z
k;.J.
@*0.J
LG9*pC
g[}:Y>
:L-H]$
4HG&u
k"TF&z
`%3)7
u0TX02
S%WqY
g2+^B
-laO
ZBX&1
OiG}Iz!P
W6kcz
3I?tT
S-P64
p1Jvl
4EX0iu
sB`i|Y$H
$lMp=
>[[0/
a[Yj:
/(n=9m
:A{Tb_
6*M/Z
TFAcr*
thqLS
6w=NuQx{&v
&Tds>k
*l0l:
b-d. 81
kO8PL
$BaNb
T$q=c\8
5$$DO0
^Tp:b
"}iIa
CKm2d4#y&
<tO3t
_0(V7O
cjv*;
)FnCn1
o<Z.~-
0^V1w,
Ak=B8
~y6VC
QZ?,e
j0jD(m$
Dbs59(t
(1ahY
jfu24/
21Z]_
:lnB`
bw P?
L?Uy]
S68XT
e{y^KCW0
v"[f5
Tj$a)
.U\^w
^u/+,<.
j{r<y
a$/X8
g2]4.
^'&To
-#w2\J
/;HlI`L9
G>M`t!
z~c}ca
HQv1yJ?HI
,g$KGk-
Om&0A3
foF,B
1_tlA
GOml6-C
U^Wp~
ve"MG
sU#e[=
Mye-b^Pt
< &H;
3[xU=
m.oUk.
lyhq&&:e
Uc+]ag
'bMY7
Z+) l
mcbIj
lHL(,
E2[S~/
.gC:G
bX1G[
DheT17?
q2wC1R
+7{,_
}e\x_
uox8^
}iOvC
GA{o:
"}|MFU3
y|Nzn
jKj&v
tyEmN
TmQmxG
)+Dv)
H6c5';
UAz4b
@n'b7
NfM&s
/bcXS
#\Bf-"
o$o?D
.ro!<Hx7
qrW"t
7MXDn5
02k`/
config.dat
I!1%>?R
key.dat+
META-INF/MANIFEST.MFPK
a.classPK
ab.classPK
ac.classPK
ad.classPK
ae.classPK
af.classPK
b.classPK
bb.classPK
bc.classPK
bd.classPK
be.classPK
bf.classPK
c.classPK
cb.classPK
cc.classPK
cd.classPK
ce.classPK
cf.classPK
d.classPK
db.classPK
dc.classPK
dd.classPK
de.classPK
df.classPK
e.classPK
eb.classPK
ec.classPK
ed.classPK
ee.classPK
ef.classPK
f.classPK
fb.classPK
fc.classPK
fd.classPK
fe.classPK
ff.classPK
g.classPK
gb.classPK
gc.classPK
gd.classPK
ge.classPK
gf.classPK
h.classPK
hb.classPK
hc.classPK
hd.classPK
he.classPK
hf.classPK
i.classPK
ib.classPK
ic.classPK
id.classPK
ie.classPK
j.classPK
jb.classPK
jc.classPK
jd.classPK
je.classPK
jf.classPK
k.classPK
kb.classPK
B%X,P
kc.classPK
kd.classPK
ke.classPK
l.classPK
lb.classPK
lc.classPK
ld.classPK
le.classPK
m.classPK
mb.classPK
mc.classPK
md.classPK
me.classPK
n.classPK
nb.classPK
nc.classPK
nd.classPK
ne.classPK
o.classPK
ob.classPK
oc.classPK
od.classPK
oe.classPK
p.classPK
pb.classPK
pc.classPK
pd.classPK
pe.classPK
q.classPK
qb.classPK
qc.classPK
qd.classPK
qe.classPK
r.classPK
rb.classPK
rc.classPK
rd.classPK
re.classPK
s.classPK
sb.classPK
sc.classPK
sd.classPK
se.classPK
t.classPK
tb.classPK
tc.classPK
td.classPK
te.classPK
u.classPK
ub.classPK
uc.classPK
ud.classPK
ue.classPK
v.classPK
vb.classPK
vc.classPK
vd.classPK
ve.classPK
w.classPK
wb.classPK
wc.classPK
wd.classPK
we.classPK
x.classPK
xb.classPK
xc.classPK
xd.classPK
xe.classPK
y.classPK
yb.classPK
yc.classPK
yd.classPK
ye.classPK
z.classPK
zb.classPK
zc.classPK
zd.classPK
ze.classPK
kf.classPK
config.datPK
key.datPK

Full Results

Engine Signature Engine Signature Engine Signature
Bkav Clean TotalDefense Clean MicroWorld-eScan Java.Backdoor.Jacksbot.A
FireEye Java.Backdoor.Jacksbot.A McAfee JV/BackDoor-FAZY!18D03B485EEF Malwarebytes Clean
Zillya Trojan.Jacksbot.JS.45 SUPERAntiSpyware Clean Sangfor Clean
Trustlook Clean Alibaba Backdoor:JAVA/Kryptik.d717ce80 K7GW Clean
K7AntiVirus Clean Arcabit Java.Trojan.GenericGB.D699E BitDefenderTheta Clean
Cyren Java/Jacksbot.I Symantec Backdoor.Jeetrat ESET-NOD32 Java/Jacksbot.O
Baidu Clean TrendMicro-HouseCall JAVA_JACKSBOT.AC Avast Java:Agent-HCH [Trj]
ClamAV Clean Kaspersky Backdoor.Java.Agent.d BitDefender Java.Backdoor.Jacksbot.A
NANO-Antivirus Trojan.Java.Jrat.cpocnu AegisLab Trojan.Java.Agent.m!c Rising Clean
Ad-Aware Java.Backdoor.Jacksbot.A Emsisoft Java.Backdoor.Jacksbot.A (B) Comodo [email protected]#18k9ucv4rlzz
F-Secure Exploit.EXP/CVE-2011-3544.U.Gen DrWeb Java.Jrat.1 VIPRE Clean
TrendMicro JAVA_JACKSBOT.AC McAfee-GW-Edition JV/BackDoor-FAZY!18D03B485EEF CMC Clean
Sophos Mal/Jacksbot-A Ikarus Trojan.Java.Jacksbot F-Prot Java/Jacksbot.I
Jiangmin Backdoor.Java.ea Avira ie.class Fortinet Clean
Antiy-AVL Clean Kingsoft Clean Microsoft Clean
ViRobot Clean ZoneAlarm Backdoor.Java.Agent.d Avast-Mobile Clean
AhnLab-V3 Clean VBA32 Clean ALYac Clean
MAX malware (ai score=85) Zoner Clean Tencent Java.Backdoor.Agent.Eaxk
Yandex Clean TACHYON Clean MaxSecure Clean
GData Java.Trojan.GenericGB.27038 AVG Java:Agent-HCH [Trj] Panda Clean
Qihoo-360 Generic/Backdoor.790
Sorry! No behavior.

Hosts

Direct IP Country Name
Y 8.8.8.8 [VT] United States
Y 1.1.1.1 [VT] Australia

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.1.9 51751 1.1.1.1 53
192.168.1.9 53599 1.1.1.1 53
192.168.1.9 54190 1.1.1.1 53
192.168.1.9 54609 1.1.1.1 53
192.168.1.9 55233 1.1.1.1 53
192.168.1.9 55319 1.1.1.1 53
192.168.1.9 57309 1.1.1.1 53
192.168.1.9 59058 1.1.1.1 53
192.168.1.9 59225 1.1.1.1 53
192.168.1.9 63630 1.1.1.1 53
192.168.1.9 64674 1.1.1.1 53
192.168.1.9 137 192.168.1.255 137
192.168.1.9 51751 8.8.8.8 53
192.168.1.9 53599 8.8.8.8 53
192.168.1.9 54190 8.8.8.8 53
192.168.1.9 54609 8.8.8.8 53
192.168.1.9 55233 8.8.8.8 53
192.168.1.9 55319 8.8.8.8 53
192.168.1.9 57309 8.8.8.8 53
192.168.1.9 59058 8.8.8.8 53
192.168.1.9 59225 8.8.8.8 53
192.168.1.9 63630 8.8.8.8 53
192.168.1.9 64674 8.8.8.8 53

DNS

No domains contacted.

HTTP Requests

No HTTP requests performed.

SMTP traffic

No SMTP traffic performed.

IRC traffic

No IRC requests performed.

ICMP traffic

No ICMP traffic performed.

CIF Results

No CIF Results

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Suricata HTTP

No Suricata HTTP

Sorry! No dropped Suricata Extracted files.

JA3

No JA3 hashes found.

Sorry! No dropped files.
Sorry! No CAPE files.
Sorry! No process dumps.

Processing ( 0.647 seconds )

  • 0.246 NetworkAnalysis
  • 0.183 VirusTotal
  • 0.075 Deduplicate
  • 0.067 Static
  • 0.025 CAPE
  • 0.021 AnalysisInfo
  • 0.02 TargetInfo
  • 0.006 Strings
  • 0.004 Debug

Signatures ( 0.056000000000000015 seconds )

  • 0.009 ransomware_files
  • 0.006 antiav_detectreg
  • 0.006 ransomware_extensions
  • 0.005 persistence_autorun
  • 0.004 antiav_detectfile
  • 0.003 antianalysis_detectfile
  • 0.003 infostealer_ftp
  • 0.003 territorial_disputes_sigs
  • 0.002 infostealer_bitcoin
  • 0.002 infostealer_im
  • 0.001 betabot_behavior
  • 0.001 system_network_discovery_cmd
  • 0.001 kibex_behavior
  • 0.001 rat_nanocore
  • 0.001 tinba_behavior
  • 0.001 antianalysis_detectreg
  • 0.001 antivm_vbox_files
  • 0.001 geodo_banking_trojan
  • 0.001 browser_security
  • 0.001 disables_browser_warn
  • 0.001 infostealer_mail
  • 0.001 masquerade_process_name
  • 0.001 revil_mutexes

Reporting ( 0.846 seconds )

  • 0.842 BinGraph
  • 0.004 PCAP2CERT