peremena.exe

Classification: Malicious

peremena.exe is a malicious file sample. Reported by 1 threat source, last seen 2018-07-19. Detected by 20 antivirus engines.

Detection summary

  • 20 antivirus detections (30% detection ratio)
  • 0 IDS alerts
  • 1 processes observed
  • 0 contacted hosts
  • 0 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Ransom_GANDCRAB.SMALY Hybrid-Analysis 2018-07-19 12:45:13 2018-07-19 12:45:13

Tags

ransomware

Sample information

Filenames
peremena.exe
File type
PE32 executable (GUI) Intel 80386, for MS Windows
Size
228352 bytes
MD5
e5d1503657a6e51546cd31086675857f
SHA-1
8f4be30eef17a5b885f1db206baf9aef1722a30d
SHA-256
3d2777b748e805c0463c0c6d0fef8280ad197bea1dd0a25e30ed71199989a6b9
First indexed
2018-07-19 12:45:13
Last updated
2018-07-19 12:45:13

Antivirus detections

EngineDetection
McAfeeTrojan-FPST!E5D1503657A6
TrendMicroRansom_GANDCRAB.SMALY-3
BaiduWin32.Trojan.WisdomEyes.16070401.9500.9999
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GJAB
TrendMicro-HouseCallRansom_GANDCRAB.SMALY-3
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
ViRobotTrojan.Win32.GandCrab.247296
AegisLabRansom.Gandcrab.Smaly!c
RisingRansom.GandCrypt!8.F33E (TFE:dGZlOgFfuqN+379qxw)
Invinceaheuristic
WebrootW32.Adware.Gen
Endgamemalicious (high confidence)
ZoneAlarmUDS:DangerousObject.Multi.Generic
AhnLab-V3Win-Trojan/Gandcrab04.Exp
VBA32Malware-Cryptor.Limpopo
AVGFileRepMalware
AvastFileRepMalware
CrowdStrikemalicious_confidence_90% (W)

Process list

NameCommand line
peremena.exe