Malware Analysis Malware Network Analysis 23.03.2016

JM Safe

Level 39
Thread author
Verified
Top Poster
Apr 12, 2015
2,882
Hi all.

I made an analysis of a ransomware malware, and the detection ratio is not so high.

Here is the VirusTotal results: https://www.virustotal.com/it/file/...0f0d465a8e8a1f5a53c6e875f6eba676678/analysis/

Detection ratio: 9/56

It is a ransomware, and Malwarebytes, as you can see, detects it as Ransom.TeslaCrypt.

Here are the host contacted:

Code:
toolaria.com
diwali2k15.in   
samuday.org
maxmpl.com

And here are the IPs contacted:

Code:
160.153.49.102
64.20.35.186
50.31.14.17
103.27.87.88

Please be sure to do not open this sites on your web browser, they could be really dangerous!

Here are additional informations about the malware:

Filename: ooswbd.exe

MD5: ff647c0de1d0186f5e5e9819d09829d0

SHA1: 125f6d0820632b15e527a00f49dcf4556627084c

SHA256: 78d384fec2fed75aac1d42c1399fc0f0d465a8e8a1f5a53c6e875f6eba676678

I've also scanned 2 of the links above with JM Web Filter, and it detected them as surely malicious:

Cattura.PNG Cattura1.PNG
 

harlan4096

Moderator
Verified
Staff Member
Malware Hunter
Well-known
Apr 28, 2015
8,657
I just downloaded it from M a l w . com and KTS2016MR1 detected it with KSN (UDS) :)
 
  • Like
Reactions: JM Safe

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top