paladin316

Exes_8567ff8096bcd6b85c6389a8da735d99_exe_2019-08-04_07_30.txt

Aug 5th, 2019
2,052
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 11.03 KB | None | 0 0
  1.  
  2. * MalFamily: ""
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_8567ff8096bcd6b85c6389a8da735d99.exe"
  7. * File Size: 383664
  8. * File Type: "MS-DOS executable"
  9. * SHA256: "287f430b130c655fb7cc205e8b2de6a156b52afd7baef81510c63881dba7542e"
  10. * MD5: "8567ff8096bcd6b85c6389a8da735d99"
  11. * SHA1: "ad4c9953aaa1f561d6e1e1612e3c13a6c64cbb53"
  12. * SHA512: "218577a4b95173f6b65516ef1a548232cc4e629999789ee08664c5266b220ec4763adf3d69f8d3b6517f0587da68835edd919be776c5908885df23105e3d5e5d"
  13. * CRC32: "31CE15F6"
  14. * SSDEEP: "6144:tvZzQJVb5p72cHF1ybDFwekh212KhvwIb759QOaBjpaVRPu23E2rJmWjFS:tYVOiF1WD7kE1dTYOi8V5u23zmWFS"
  15.  
  16. * Process Execution:
  17. "Exes_8567ff8096bcd6b85c6389a8da735d99.exe",
  18. "SQLServse.exe",
  19. "services.exe",
  20. "SQLServse.exe",
  21. "SQLServse.exe",
  22. "svchost.exe",
  23. "WerFault.exe",
  24. "wermgr.exe",
  25. "sc.exe",
  26. "svchost.exe"
  27.  
  28.  
  29. * Executed Commands:
  30. "C:\\Program Files (x86)\\Microsoft SQL Server\\SQLServse.exe ",
  31. "C:\\Program Files (x86)\\Microsoft SQL Server\\SQLServse.exe",
  32. "C:\\Windows\\System32\\svchost.exe -k WerSvcGroup",
  33. "C:\\Windows\\system32\\sc.exe start w32time task_started",
  34. "C:\\Windows\\system32\\svchost.exe -k LocalService",
  35. "C:\\Windows\\SysWOW64\\WerFault.exe -u -p 2220 -s 400",
  36. "\"C:\\Windows\\system32\\wermgr.exe\" \"-queuereporting_svc\" \"C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_SQLServse.exe_90787af212b8bb9775629dd7ac9cd8723398f5f7_cab_024ad4c4\""
  37.  
  38.  
  39. * Signatures Detected:
  40.  
  41. "Description": "At least one process apparently crashed during execution",
  42. "Details":
  43.  
  44.  
  45. "Description": "Creates RWX memory",
  46. "Details":
  47.  
  48.  
  49. "Description": "A process attempted to delay the analysis task.",
  50. "Details":
  51.  
  52. "Process": "SQLServse.exe tried to sleep 508 seconds, actually delayed analysis time by 0 seconds"
  53.  
  54.  
  55.  
  56.  
  57. "Description": "Drops a binary and executes it",
  58. "Details":
  59.  
  60. "binary": "C:\\Program Files (x86)\\Microsoft SQL Server\\SQLServse.exe"
  61.  
  62.  
  63.  
  64.  
  65. "Description": "Unconventionial language used in binary resources: Chinese (Simplified)",
  66. "Details":
  67.  
  68.  
  69. "Description": "The binary likely contains encrypted or compressed data.",
  70. "Details":
  71.  
  72. "section": "name: .MPRESS1, entropy: 8.00, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00056800, virtual_size: 0x00061000"
  73.  
  74.  
  75.  
  76.  
  77. "Description": "Deletes its original binary from disk",
  78. "Details":
  79.  
  80.  
  81. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  82. "Details":
  83.  
  84. "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 12418449 times"
  85.  
  86.  
  87.  
  88.  
  89. "Description": "Installs itself for autorun at Windows startup",
  90. "Details":
  91.  
  92. "service name": "Microsoft SQL Server"
  93.  
  94.  
  95. "service path": "C:\\Program Files (x86)\\Microsoft SQL Server\\SQLServse.exe"
  96.  
  97.  
  98.  
  99.  
  100. "Description": "File has been identified by 46 Antiviruses on VirusTotal as malicious",
  101. "Details":
  102.  
  103. "MicroWorld-eScan": "Gen:Variant.Strictor.199506"
  104.  
  105.  
  106. "FireEye": "Generic.mg.8567ff8096bcd6b8"
  107.  
  108.  
  109. "CAT-QuickHeal": "Trojan.Magania.18692"
  110.  
  111.  
  112. "Qihoo-360": "HEUR/QVM18.1.F963.Malware.Gen"
  113.  
  114.  
  115. "McAfee": "GenericRXDW-XG!F5B08463CD43"
  116.  
  117.  
  118. "Cylance": "Unsafe"
  119.  
  120.  
  121. "K7AntiVirus": "Trojan ( 004c81771 )"
  122.  
  123.  
  124. "BitDefender": "Gen:Variant.Strictor.199506"
  125.  
  126.  
  127. "K7GW": "Trojan ( 004c81771 )"
  128.  
  129.  
  130. "Cybereason": "malicious.096bcd"
  131.  
  132.  
  133. "Cyren": "W32/S-5b8046aa!Eldorado"
  134.  
  135.  
  136. "Symantec": "ML.Attribute.HighConfidence"
  137.  
  138.  
  139. "APEX": "Malicious"
  140.  
  141.  
  142. "Avast": "Win32:Malware-gen"
  143.  
  144.  
  145. "Kaspersky": "Trojan.Win32.Tick.q"
  146.  
  147.  
  148. "Rising": "Backdoor.Farfli!8.B4 (TFE:5:bL8vVvLdNzM)"
  149.  
  150.  
  151. "Ad-Aware": "Gen:Variant.Strictor.199506"
  152.  
  153.  
  154. "Comodo": "TrojWare.Win32.Fusing.CF@5afr59"
  155.  
  156.  
  157. "F-Secure": "Heuristic.HEUR/AGEN.1042577"
  158.  
  159.  
  160. "DrWeb": "BackDoor.Farfli.96"
  161.  
  162.  
  163. "Invincea": "heuristic"
  164.  
  165.  
  166. "McAfee-GW-Edition": "GenericRXDW-XG!F5B08463CD43"
  167.  
  168.  
  169. "CMC": "Virus.Win32.Sality!O"
  170.  
  171.  
  172. "Emsisoft": "Gen:Variant.Strictor.199506 (B)"
  173.  
  174.  
  175. "SentinelOne": "DFI - Malicious PE"
  176.  
  177.  
  178. "F-Prot": "W32/S-5b8046aa!Eldorado"
  179.  
  180.  
  181. "Jiangmin": "Backdoor.Farfli.cmb"
  182.  
  183.  
  184. "Avira": "HEUR/AGEN.1042577"
  185.  
  186.  
  187. "Fortinet": "W32/Midie.26C0!tr"
  188.  
  189.  
  190. "Antiy-AVL": "Trojan/Win32.SGeneric"
  191.  
  192.  
  193. "Arcabit": "Trojan.Strictor.D30B52"
  194.  
  195.  
  196. "Microsoft": "Backdoor:Win32/PcClient.ZR"
  197.  
  198.  
  199. "AhnLab-V3": "Malware/Win32.Generic.C2832100"
  200.  
  201.  
  202. "Acronis": "suspicious"
  203.  
  204.  
  205. "VBA32": "BScope.Trojan-GameThief.Magania"
  206.  
  207.  
  208. "ALYac": "Gen:Variant.Strictor.199506"
  209.  
  210.  
  211. "MAX": "malware (ai score=88)"
  212.  
  213.  
  214. "Panda": "Trj/Genetic.gen"
  215.  
  216.  
  217. "ESET-NOD32": "Win32/Farfli.BGG"
  218.  
  219.  
  220. "Yandex": "Packed/MPress"
  221.  
  222.  
  223. "Ikarus": "Trojan.Win32.Farfli"
  224.  
  225.  
  226. "eGambit": "PE.Heur.InvalidSig"
  227.  
  228.  
  229. "GData": "Gen:Variant.Strictor.199506"
  230.  
  231.  
  232. "AVG": "Win32:Malware-gen"
  233.  
  234.  
  235. "Paloalto": "generic.ml"
  236.  
  237.  
  238. "CrowdStrike": "win/malicious_confidence_80% (D)"
  239.  
  240.  
  241.  
  242.  
  243. "Description": "Checks the CPU name from registry, possibly for anti-virtualization",
  244. "Details":
  245.  
  246.  
  247. "Description": "Checks the system manufacturer, likely for anti-virtualization",
  248. "Details":
  249.  
  250.  
  251.  
  252. * Started Service:
  253. "Microsoft SQL Server",
  254. "WerSvc",
  255. "W32Time"
  256.  
  257.  
  258. * Mutexes:
  259. "Local\\WERReportingForProcess2220",
  260. "Global\\9d5b06bd-b684-11e9-81e8-18c086cd4733",
  261. "Global\\\\xed\\xbc\\xa0\\xc7\\x88",
  262. "WERUI_APPCRASH-90787af212b8bb9775629dd7ac9cd8723398f5f7"
  263.  
  264.  
  265. * Modified Files:
  266. "C:\\Program Files (x86)\\Microsoft SQL Server\\SQLServse.exe",
  267. "C:\\Windows\\sysnative\\LogFiles\\Scm\\7bbc503c-5977-4798-a4ae-61483a7e030d",
  268. "C:\\Windows\\sysnative\\LogFiles\\Scm\\0efb1c2e-8bcc-468c-aa07-37b1f761840f",
  269. "C:\\Windows\\Temp\\WER8F8F.tmp.appcompat.txt",
  270. "C:\\Windows\\Temp\\WER90A9.tmp.WERInternalMetadata.xml",
  271. "C:\\Windows\\Temp\\WER9166.tmp.hdmp",
  272. "C:\\Windows\\Temp\\WER9D6D.tmp.mdmp",
  273. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_SQLServse.exe_90787af212b8bb9775629dd7ac9cd8723398f5f7_cab_024ad4c4\\WER8F8F.tmp.appcompat.txt",
  274. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_SQLServse.exe_90787af212b8bb9775629dd7ac9cd8723398f5f7_cab_024ad4c4\\WER90A9.tmp.WERInternalMetadata.xml",
  275. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_SQLServse.exe_90787af212b8bb9775629dd7ac9cd8723398f5f7_cab_024ad4c4\\WER9166.tmp.hdmp",
  276. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_SQLServse.exe_90787af212b8bb9775629dd7ac9cd8723398f5f7_cab_024ad4c4\\WER9D6D.tmp.mdmp",
  277. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_SQLServse.exe_90787af212b8bb9775629dd7ac9cd8723398f5f7_cab_024ad4c4\\Report.wer",
  278. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_SQLServse.exe_90787af212b8bb9775629dd7ac9cd8723398f5f7_cab_024ad4c4\\Report.wer.tmp",
  279. "\\??\\PIPE\\lsarpc"
  280.  
  281.  
  282. * Deleted Files:
  283. "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_8567ff8096bcd6b85c6389a8da735d99.exe",
  284. "C:\\Windows\\Temp\\WER8F8F.tmp",
  285. "C:\\Windows\\Temp\\WER8F8F.tmp.appcompat.txt",
  286. "C:\\Windows\\Temp\\WER90A9.tmp",
  287. "C:\\Windows\\Temp\\WER90A9.tmp.WERInternalMetadata.xml",
  288. "C:\\Windows\\Temp\\WER9166.tmp",
  289. "C:\\Windows\\Temp\\WER9166.tmp.hdmp",
  290. "C:\\Windows\\Temp\\WER9D6D.tmp",
  291. "C:\\Windows\\Temp\\WER9D6D.tmp.mdmp",
  292. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_SQLServse.exe_90787af212b8bb9775629dd7ac9cd8723398f5f7_cab_024ad4c4\\Report.wer.tmp"
  293.  
  294.  
  295. * Modified Registry Keys:
  296. "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Microsoft SQL Server",
  297. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Microsoft SQL Server\\DeleteFiles",
  298. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Microsoft SQL Server\\ConnectGroup",
  299. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Microsoft SQL Server\\Description",
  300. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
  301. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Type",
  302. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Microsoft SQL Server\\MarkTime",
  303. "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MediaResources\\msvideo",
  304. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Debug",
  305. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\Windows Error Reporting\\Debug\\ExceptionRecord",
  306. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\TimeProviders\\NtpClient\\SpecialPollTimeRemaining"
  307.  
  308.  
  309. * Deleted Registry Keys:
  310. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Microsoft SQL Server\\DeleteFiles"
  311.  
  312.  
  313. * DNS Communications:
  314.  
  315. "type": "A",
  316. "request": "da.vollar.ga",
  317. "answers":
  318.  
  319. "data": "172.245.82.4",
  320. "type": "A"
  321.  
  322.  
  323.  
  324.  
  325.  
  326. * Domains:
  327.  
  328. "ip": "172.245.82.4",
  329. "domain": "da.vollar.ga"
  330.  
  331.  
  332.  
  333. * Network Communication - ICMP:
  334.  
  335. * Network Communication - HTTP:
  336.  
  337. * Network Communication - SMTP:
  338.  
  339. * Network Communication - Hosts:
  340.  
  341. * Network Communication - IRC:
Add Comment
Please, Sign In to add comment