Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Remcos"
- * MalScore: 10.0
- * File Name: "driverquery.exe"
- * File Size: 3034968
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "7226f09afaf19cfb171fc66b021452f191d231e5b7947e4b031b05cb649808b7"
- * MD5: "31111857efb3138eb8f2b1146656d753"
- * SHA1: "5486c4a03c069481d63c44b61a933f982280e087"
- * SHA512: "f1b7223dd04728804798f891a7addfe56d79668bd1813d6edd853fec69b2ec1ac42c317bc84737783450d9c067ef07884c9f00537116cb364eb8a6f9311a3621"
- * CRC32: "8955D920"
- * SSDEEP: "49152:hh+ZkldoPK8Yad7cwj644Mh+ZkldoPK8YaLDNck:C2cPK8YwjE2cPK8t"
- * Process Execution:
- "driverquery.exe",
- "remcos_agent_Protected.exe",
- "remcos_agent_Protected.exe",
- "schtasks.exe",
- "AcroRd32.exe",
- "Eula.exe",
- "schtasks.exe",
- "svchost.exe"
- * Executed Commands:
- "\"C:\\Users\\user\\AppData\\Roaming\\remcos_agent_Protected.exe\"",
- "C:\\Users\\user\\AppData\\Roaming\\remcos_agent_Protected.exe "
- * Signatures Detected:
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Possible date expiration check, exits too soon after checking local time",
- "Details":
- "process": "schtasks.exe, PID 1884"
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: remcos_agent_Protected.exe, pid: 2404, offset: 0x00000000, length: 0x0011fe00"
- "self_read": "process: Eula.exe, pid: 2284, offset: 0x00000000, length: 0x00000040"
- "self_read": "process: Eula.exe, pid: 2284, offset: 0x00000100, length: 0x00000018"
- "self_read": "process: Eula.exe, pid: 2284, offset: 0x000001f8, length: 0x000000a0"
- "self_read": "process: Eula.exe, pid: 2284, offset: 0x00012600, length: 0x00000010"
- "Description": "Drops a binary and executes it",
- "Details":
- "binary": "C:\\Users\\user\\AppData\\Roaming\\remcos_agent_Protected.exe"
- "Description": "Executed a process and injected code into it, probably while unpacking",
- "Details":
- "Injection": "remcos_agent_Protected.exe(2404) -> remcos_agent_Protected.exe(2988)"
- "Description": "A potential decoy document was displayed to the user",
- "Details":
- "disguised_executable": "The submitted file was an executable indicative of an attempt to get a user to run executable content disguised as a document"
- "Decoy Document": "\"c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\acrord32.exe\" \"c:\\users\\user\\appdata\\local\\temp\\medical-application-form.pdf\""
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\remcos"
- "data": "\"C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe\""
- "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\remcos"
- "data": "\"C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe\""
- "Description": "Creates a hidden or system file",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe"
- "file": "C:\\Users\\user\\AppData\\Roaming\\remcos"
- "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
- "Details":
- "target": "clamav:Win.Downloader.LokiBot-6962970-0, sha256:7226f09afaf19cfb171fc66b021452f191d231e5b7947e4b031b05cb649808b7, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "Description": "Anomalous binary characteristics",
- "Details":
- "anomaly": "Actual checksum does not match that reported in PE header"
- * Started Service:
- * Mutexes:
- "bderepair",
- "Local\\ZoneAttributeCacheCounterMutex",
- "Local\\ZonesCacheCounterMutex",
- "Local\\ZonesLockedCacheCounterMutex",
- "MDMAppInstaller",
- "Remcos_Mutex_Inj",
- "Remcos-S1KNPZ",
- "Global\\ARM Update Mutex",
- "Global\\Acro Update Mutex",
- "Local\\WininetStartupMutex",
- "Local\\ZonesCounterMutex"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Roaming\\remcos_agent_Protected.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\medical-application-form.pdf",
- "C:\\Users\\user\\AppData\\Roaming\\CapabilityAccessHandlers\\sfc.exe",
- "C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\install.vbs",
- "C:\\Windows\\sysnative\\Tasks\\setx",
- "C:\\Windows\\appcompat\\Programs\\RecentFileCache.bcf"
- * Deleted Files:
- "C:\\Windows\\Tasks\\setx.job"
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\remcos",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\remcos",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\3F840E57-A70C-4327-8D4C-6299DE36D6F0\\Path",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\3F840E57-A70C-4327-8D4C-6299DE36D6F0\\Hash",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\setx\\Id",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\setx\\Index",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\3F840E57-A70C-4327-8D4C-6299DE36D6F0\\Triggers",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\3F840E57-A70C-4327-8D4C-6299DE36D6F0\\DynamicInfo"
- * Deleted Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\setx.job",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\setx.job.fp"
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment