Classification: Malicious
peremena.exe is a malicious file sample. Reported by 1 threat source, last seen 2018-07-19. Detected by 20 antivirus engines.
Detection summary
- 20 antivirus detections (30% detection ratio)
- 0 IDS alerts
- 1 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Ransom_GANDCRAB.SMALY |
Hybrid-Analysis |
2018-07-19 12:45:13 |
2018-07-19 12:45:13 |
|
|
Sample information
- Filenames
- peremena.exe
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 228352 bytes
- MD5
e5d1503657a6e51546cd31086675857f
- SHA-1
8f4be30eef17a5b885f1db206baf9aef1722a30d
- SHA-256
3d2777b748e805c0463c0c6d0fef8280ad197bea1dd0a25e30ed71199989a6b9
- First indexed
- 2018-07-19 12:45:13
- Last updated
- 2018-07-19 12:45:13
Antivirus detections
| Engine | Detection |
| McAfee | Trojan-FPST!E5D1503657A6 |
| TrendMicro | Ransom_GANDCRAB.SMALY-3 |
| Baidu | Win32.Trojan.WisdomEyes.16070401.9500.9999 |
| Symantec | ML.Attribute.HighConfidence |
| ESET-NOD32 | a variant of Win32/Kryptik.GJAB |
| TrendMicro-HouseCall | Ransom_GANDCRAB.SMALY-3 |
| Paloalto | generic.ml |
| Kaspersky | UDS:DangerousObject.Multi.Generic |
| ViRobot | Trojan.Win32.GandCrab.247296 |
| AegisLab | Ransom.Gandcrab.Smaly!c |
| Rising | Ransom.GandCrypt!8.F33E (TFE:dGZlOgFfuqN+379qxw) |
| Invincea | heuristic |
| Webroot | W32.Adware.Gen |
| Endgame | malicious (high confidence) |
| ZoneAlarm | UDS:DangerousObject.Multi.Generic |
| AhnLab-V3 | Win-Trojan/Gandcrab04.Exp |
| VBA32 | Malware-Cryptor.Limpopo |
| AVG | FileRepMalware |
| Avast | FileRepMalware |
| CrowdStrike | malicious_confidence_90% (W) |
Process list
| Name | Command line |
| peremena.exe | |