Malware Uses JAR | VTI by Category
Try VMRay Analyzer
VTI Information
VTI Score
94 / 100
VTI Database Version2.3
VTI Rule Match Count32
VTI Rule TypeDefault (PE, ...)
Detected Threats
ArrowAnti Analysis
Arrow
Dynamic API usage
Resolve more than 50 APIs.
Arrow
Delay execution
One thread sleeps more than 5 minutes.
ArrowBrowser
Arrow
Change security related browser settings
Disable signature check for executables downloaded by Microsoft Internet Explorer.
ArrowInjection
Arrow
Write into memory of an other process
"c:\windows\system32\regsvr32.exe" modifies memory of "c:\windows\explorer.exe"
Arrow
Modify control flow of an other process
"c:\windows\system32\regsvr32.exe" creates thread in "c:\windows\explorer.exe"
ArrowNetwork
Arrow
Perform DNS request
Resolve "N3EErvtwsM".
Resolve "adom2.com.br".
Resolve "carvas32ltda.com".
Resolve "carva32ssa.com".
Resolve "bandeivacomercial.com".
Resolve "bandeivacomercio.com".
Arrow
Connect to remote host
Outgoing TCP connection to host "None:80".
Outgoing TCP connection to host "187.191.100.112:80".
Arrow
Download data
Url "http://None/nosoanfhtympkl50tre/ljk32g1.txt".
Url "http://None/nosoanfhtympkl50tre/ljk32g2.txt".
Url "http://None/nosoanfhtympkl50tre/ljk32g4.txt".
Url "http://127.0.0.1/nosoanfhtympkl50tre/infx/s1/conta.php?chave=s3n4&url=N3EERVTWSM%20*%20%2032%20bits%20*%202626.5%20kb%20*%20%20*%20English%20(United%20States)".
Arrow
Connect to HTTP server
Remote address "None".
Remote address "127.0.0.1".
ArrowOS
Arrow
Modfiy system security configuration
Disable UAC notification.
Disable Windows Security Center antivirus notification.
Disable Windows Security Center warning about disabled system updates.
Arrow
Disable crucial system service
Disable "Windows Defender Service" by ChangeServiceConfigW.
ArrowPE
Arrow
Drop PE file
Drop file "c:\users\public\n3eg\ljkg4".
Drop file "c:\users\public\n3eg\ljkg2".
ArrowPersistence
Arrow
Install system startup script or application
Add "regsvr32.exe /s "C:\Users\Public\N3Eg\N3Eg2.51N3E" #96" to windows startup via registry.
ArrowProcess
Arrow
Create process with hidden window
The process "regsvr32.exe \s \"C:\Users\Public\N3Eg\N3Eg2.51N3E\" #96" starts with hidden window.
The process "cmd /k "C:\Users\Public\N3Eg\N3E.vbs"" starts with hidden window.
The process "sc" starts with hidden window.
The process "net" starts with hidden window.
The process "cmd" starts with hidden window.
Arrow
Allocate a page with write and execute permissions
Allocate a page with "PAGE_EXECUTE_READWRITE" permissions, often used to dynamically unpack code.
-Device
-File System
-Hide Tracks
-Information Stealing
-Kernel
-Masquerade
-VBA Macro
-YARA
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefox with deactivated setting "security.fileuri.strict_origin_policy".


Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image