Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "RevengeRat"
- * MalScore: 10.0
- * File Name: "Exes_3d96c186b74d4c766bce7096a974c2ac.exe"
- * File Size: 17408
- * File Type: "PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows"
- * SHA256: "47ebadfc0f8a06eadb5f096950052949273be20f198399c15df1a1f14c6a0df0"
- * MD5: "3d96c186b74d4c766bce7096a974c2ac"
- * SHA1: "72ae1ee9918aedcb9a54be38f41dff9dd77400d4"
- * SHA512: "5c5038d55c64d66f5461a56d5d85a26bfc354a427b4777a2fca22e13b23a8f1ded1ebd8ed95a6ceb454c6dfdf1827476a38334a8b24cf3402490e832da572a46"
- * CRC32: "3E7E5298"
- * SSDEEP: "384:A5ILfEYRKVf2uMvnODO2TbcsVKHymahq:hLfWFBO3LM"
- * Process Execution:
- "Exes_3d96c186b74d4c766bce7096a974c2ac.exe",
- "svchost.exe",
- "WmiPrvSE.exe",
- "WmiPrvSE.exe",
- "WMIADAP.exe"
- * Executed Commands:
- "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding",
- "C:\\Windows\\system32\\wbem\\wmiprvse.exe -Embedding"
- * Signatures Detected:
- "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
- "Details":
- "IP": "127.0.0.1:40938"
- "Description": "Creates RWX memory",
- "Details":
- "Description": "A process attempted to delay the analysis task.",
- "Details":
- "Process": "Exes_3d96c186b74d4c766bce7096a974c2ac.exe tried to sleep 475 seconds, actually delayed analysis time by 0 seconds"
- "Description": "Anomalous .NET characteristics",
- "Details":
- "anomalous_version": "Assembly version is set to 0"
- "Description": "Retrieves Windows ProductID, probably to fingerprint the sandbox",
- "Details":
- "Description": "File has been identified by 45 Antiviruses on VirusTotal as malicious",
- "Details":
- "MicroWorld-eScan": "Gen:Variant.Razy.125160"
- "FireEye": "Generic.mg.3d96c186b74d4c76"
- "McAfee": "GenericRXEK-KS!3D96C186B74D"
- "Malwarebytes": "Backdoor.RevengeRAT"
- "BitDefender": "Gen:Variant.Razy.125160"
- "K7GW": "Trojan ( 700000121 )"
- "K7AntiVirus": "Trojan ( 700000121 )"
- "TrendMicro": "BKDR_REVET.SM"
- "Cyren": "W32/Revetrat.A.gen!Eldorado"
- "Symantec": "Trojan.Revetrat"
- "APEX": "Malicious"
- "Avast": "Win32:MalwareX-gen Trj"
- "ClamAV": "Win.Trojan.RevengeRat-6344273-0"
- "Kaspersky": "HEUR:Trojan.Win32.RRAT.gen"
- "Rising": "Trojan.Agent!8.B1E (TFE:C:dUZ8BHmey9D)"
- "Ad-Aware": "Gen:Variant.Razy.125160"
- "Emsisoft": "Gen:Variant.Razy.125160 (B)"
- "Comodo": "TrojWare.MSIL.Revetrat.A@7osjcj"
- "F-Secure": "Trojan.TR/ATRAPS.Gen"
- "DrWeb": "BackDoor.RevetRat.2"
- "Invincea": "heuristic"
- "McAfee-GW-Edition": "BehavesLike.Win32.Generic.lm"
- "Trapmine": "malicious.moderate.ml.score"
- "Sophos": "Mal/Revet-A"
- "Ikarus": "Backdoor-Rat.Revenge"
- "F-Prot": "W32/Revetrat.A.gen!Eldorado"
- "Avira": "TR/ATRAPS.Gen"
- "Fortinet": "MSIL/Agent.APN!tr"
- "Endgame": "malicious (high confidence)"
- "Arcabit": "Trojan.Razy.D1E8E8"
- "ZoneAlarm": "HEUR:Trojan.Win32.RRAT.gen"
- "Microsoft": "Backdoor:MSIL/Revetrat.A!bit"
- "Acronis": "suspicious"
- "ALYac": "Gen:Variant.Razy.125160"
- "MAX": "malware (ai score=83)"
- "Cylance": "Unsafe"
- "ESET-NOD32": "a variant of MSIL/Agent.APN"
- "TrendMicro-HouseCall": "BKDR_REVET.SM"
- "SentinelOne": "DFI - Malicious PE"
- "eGambit": "Trojan.Generic"
- "GData": "MSIL.Backdoor.RevengeRAT.B"
- "AVG": "Win32:MalwareX-gen Trj"
- "Cybereason": "malicious.6b74d4"
- "CrowdStrike": "win/malicious_confidence_100% (D)"
- "Qihoo-360": "HEUR/QVM03.0.6A9D.Malware.Gen"
- "Description": "Checks the CPU name from registry, possibly for anti-virtualization",
- "Details":
- "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
- "Details":
- "target": "clamav:Win.Trojan.RevengeRat-6344273-0, sha256:47ebadfc0f8a06eadb5f096950052949273be20f198399c15df1a1f14c6a0df0, type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows"
- "Description": "Collects information to fingerprint the system",
- "Details":
- * Started Service:
- * Mutexes:
- "Global\\CLR_CASOFF_MUTEX",
- "RV_MUTEX-anFwUnoWrUUg",
- "Global\\.net clr networking",
- "Global\\ADAP_WMI_ENTRY",
- "Global\\RefreshRA_Mutex",
- "Global\\RefreshRA_Mutex_Lib",
- "Global\\RefreshRA_Mutex_Flag"
- * Modified Files:
- "C:\\Windows\\sysnative\\drivers\\etc\\hosts",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
- "\\??\\PIPE\\wkssvc",
- "\\??\\PIPE\\srvsvc",
- "\\??\\WMIDataDevice",
- "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl_new.h",
- "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl.h",
- "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl_new.ini"
- * Deleted Files:
- "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl.h",
- "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl_new.h"
- * Modified Registry Keys:
- "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MediaResources\\msvideo",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\IDE\\DiskVBOX_HARDDISK___________________________1.0_____\\5&33d1638a&0&0.0.0_0-00000000-0000-0000-0000-000000000000",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\advapi32.dllMofResourceName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\en-US\\advapi32.dll.muiMofResourceName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\ACPI.sysACPIMOFResource",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\en-US\\ACPI.sys.muiACPIMOFResource",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\ndis.sysMofResourceName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\en-US\\ndis.sys.muiMofResourceName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\mssmbios.sysMofResource",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\en-US\\mssmbios.sys.muiMofResource",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\HDAudBus.sysHDAudioMofName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\en-US\\HDAudBus.sys.muiHDAudioMofName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\intelppm.sysPROCESSORWMI",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\en-US\\intelppm.sys.muiPROCESSORWMI",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\System32\\Drivers\\portcls.SYSPortclsMof",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\System32\\Drivers\\en-US\\portcls.SYS.muiPortclsMof",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\monitor.sysMonitorWMI"
- * Deleted Registry Keys:
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\monitor.sysMonitorWMI"
- * DNS Communications:
- "type": "A",
- "request": "grandeurr.duckdns.org",
- "answers":
- "data": "185.200.117.131",
- "type": "A"
- * Domains:
- "ip": "185.200.117.131",
- "domain": "grandeurr.duckdns.org"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment