SecondWrite’s DeepView Sandbox analyzed this file last week and declared it to be 82%  malicious using our proprietary techniques. At the time of detection, this malware did not appear on leading malware black-lists. A link to the full report is below but here are some key highlights: 

Type of Malware:  Infostealer – Installs a hook procedure to monitor for mouse events- Sniffs keystrokes- Creates an Alternative Data Stream (ADS)- Creates a suspicious Powershell process- More than 50% of the external calls do not go through the import address table

Evasiveness Indicators:– Checks amount of memory in the system, this can be used to detect virtual machines that have a low amount of memory available- Queries for the computername- Attempts to repeatedly call a single API many times in order to delay analysis time- Checks amount of memory in the system, this can be used to detect virtual machines that have a low amount of memory available

Other Compelling Indicators:– Creates a hidden or system file- Attempts to create or modify system certificates- Attempts to identify installed AV products by installation directory- Creates executable files on the filesystem- Reads data out of its own binary image

