paladin316

Exes_3000503a2c640778508d76a50c71df20_iso_2019-06-24_13_30.json

Jun 24th, 2019
1,727
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.00 KB | None | 0 0
  1.  
  2. [*] MalFamily: "Ditertag"
  3.  
  4. [*] MalScore: 10.0
  5.  
  6. [*] File Name: "Exes_3000503a2c640778508d76a50c71df20.iso"
  7. [*] File Size: 1114112
  8. [*] File Type: "ISO 9660 CD-ROM filesystem data 'PO 55491MPV-BLOUSE KAAN'"
  9. [*] SHA256: "ced4223aefd706bf5ef98221787d2481eafab51d6cbd1308b18e87ca3fa12d5d"
  10. [*] MD5: "3000503a2c640778508d76a50c71df20"
  11. [*] SHA1: "adeded8d19d1bc6ab3c95f3af1c7b030e912ed1d"
  12. [*] SHA512: "6373d502a86a476d8ac590adcab0d9c6a54374807eb1ad4148872e093d3f131c4af157bd15e9c4682cfbb3615ecd46b41a0b8ea77eedbcbe12cbe3191f3e839a"
  13. [*] CRC32: "2DE51949"
  14. [*] SSDEEP: "24576:4AHnh+eWsN3skA4RV1Hom2KXMmHaOo6Y5KCjH5:/h+ZkldoPK8YaIY5td"
  15.  
  16. [*] Process Execution: [
  17. "isoburn.exe"
  18. ]
  19.  
  20. [*] Signatures Detected: [
  21. {
  22. "Description": "File has been identified by 11 Antiviruses on VirusTotal as malicious",
  23. "Details": [
  24. {
  25. "McAfee": "Artemis!8B8DFD8DD8B6"
  26. },
  27. {
  28. "AegisLab": "Trojan.Win32.Generic.4!c"
  29. },
  30. {
  31. "F-Secure": "Dropper.DR/AutoIt.Gen8"
  32. },
  33. {
  34. "DrWeb": "Trojan.MulDrop9.15725"
  35. },
  36. {
  37. "Invincea": "heuristic"
  38. },
  39. {
  40. "McAfee-GW-Edition": "Artemis!8B8DFD8DD8B6"
  41. },
  42. {
  43. "Ikarus": "Win32.Outbreak"
  44. },
  45. {
  46. "Cyren": "W32/AutoIt.IT.gen!Eldorado"
  47. },
  48. {
  49. "Microsoft": "Trojan:Win32/Ditertag.B"
  50. },
  51. {
  52. "Rising": "Trojan.Win32.Agent_.sa (CLASSIC)"
  53. },
  54. {
  55. "GData": "Win32.Trojan-Stealer.Azorult.W6VWJA"
  56. }
  57. ]
  58. }
  59. ]
  60.  
  61. [*] Started Service: []
  62.  
  63. [*] Executed Commands: []
  64.  
  65. [*] Mutexes: [
  66. "CicLoadWinStaWinSta0",
  67. "Local\\MSCTF.CtfMonitorInstMutexDefault1"
  68. ]
  69.  
  70. [*] Modified Files: []
  71.  
  72. [*] Deleted Files: []
  73.  
  74. [*] Modified Registry Keys: []
  75.  
  76. [*] Deleted Registry Keys: []
  77.  
  78. [*] DNS Communications: []
  79.  
  80. [*] Domains: []
  81.  
  82. [*] Network Communication - ICMP: []
  83.  
  84. [*] Network Communication - HTTP: []
  85.  
  86. [*] Network Communication - SMTP: []
  87.  
  88. [*] Network Communication - Hosts: []
  89.  
  90. [*] Network Communication - IRC: []
  91.  
  92. [*] Static Analysis: {}
  93.  
  94. [*] Resolved APIs: [
  95. "cryptbase.dll.SystemFunction036",
  96. "kernel32.dll.IsProcessorFeaturePresent",
  97. "kernel32.dll.InterlockedPopEntrySList",
  98. "kernel32.dll.InterlockedPushEntrySList",
  99. "kernel32.dll.InterlockedCompareExchange",
  100. "uxtheme.dll.ThemeInitApiHook",
  101. "user32.dll.IsProcessDPIAware",
  102. "dwmapi.dll.DwmIsCompositionEnabled",
  103. "comctl32.dll.RegisterClassNameW",
  104. "kernel32.dll.SortGetHandle",
  105. "kernel32.dll.SortCloseHandle",
  106. "uxtheme.dll.EnableThemeDialogTexture",
  107. "uxtheme.dll.OpenThemeData",
  108. "uxtheme.dll.IsThemePartDefined",
  109. "uxtheme.dll.GetThemeMargins",
  110. "uxtheme.dll.GetThemeBool",
  111. "uxtheme.dll.GetThemeInt",
  112. "uxtheme.dll.SetWindowTheme",
  113. "uxtheme.dll.CloseThemeData",
  114. "gdi32.dll.GetLayout",
  115. "gdi32.dll.GdiRealizationInfo",
  116. "gdi32.dll.FontIsLinked",
  117. "advapi32.dll.RegOpenKeyExW",
  118. "advapi32.dll.RegQueryInfoKeyW",
  119. "gdi32.dll.GetTextFaceAliasW",
  120. "advapi32.dll.RegEnumValueW",
  121. "advapi32.dll.RegCloseKey",
  122. "advapi32.dll.RegQueryValueExW",
  123. "gdi32.dll.GetFontAssocStatus",
  124. "advapi32.dll.RegQueryValueExA",
  125. "advapi32.dll.RegEnumKeyExW",
  126. "gdi32.dll.GdiIsMetaPrintDC",
  127. "ole32.dll.CoInitializeEx",
  128. "ole32.dll.CoUninitialize",
  129. "uxtheme.dll.BufferedPaintInit",
  130. "uxtheme.dll.BufferedPaintRenderAnimation",
  131. "uxtheme.dll.BeginBufferedAnimation",
  132. "uxtheme.dll.IsThemeBackgroundPartiallyTransparent",
  133. "uxtheme.dll.DrawThemeParentBackgroundEx",
  134. "uxtheme.dll.DrawThemeBackground",
  135. "uxtheme.dll.DrawThemeText",
  136. "uxtheme.dll.EndBufferedAnimation",
  137. "uxtheme.dll.GetThemeTextExtent",
  138. "uxtheme.dll.DrawThemeParentBackground",
  139. "uxtheme.dll.GetThemePartSize",
  140. "uxtheme.dll.GetThemeBackgroundContentRect",
  141. "uxtheme.dll.GetThemeTransitionDuration"
  142. ]
  143.  
  144. [*] Static Analysis: {}
Advertisement
Add Comment
Please, Sign In to add comment