paladin316

remcos_driverquery_exe_2019-08-21_11_40.txt

Aug 21st, 2019
2,114
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.40 KB | None | 0 0
  1.  
  2. * MalFamily: "Remcos"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "driverquery.exe"
  7. * File Size: 3034968
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "7226f09afaf19cfb171fc66b021452f191d231e5b7947e4b031b05cb649808b7"
  10. * MD5: "31111857efb3138eb8f2b1146656d753"
  11. * SHA1: "5486c4a03c069481d63c44b61a933f982280e087"
  12. * SHA512: "f1b7223dd04728804798f891a7addfe56d79668bd1813d6edd853fec69b2ec1ac42c317bc84737783450d9c067ef07884c9f00537116cb364eb8a6f9311a3621"
  13. * CRC32: "8955D920"
  14. * SSDEEP: "49152:hh+ZkldoPK8Yad7cwj644Mh+ZkldoPK8YaLDNck:C2cPK8YwjE2cPK8t"
  15.  
  16. * Process Execution:
  17. "driverquery.exe",
  18. "remcos_agent_Protected.exe",
  19. "remcos_agent_Protected.exe",
  20. "schtasks.exe",
  21. "AcroRd32.exe",
  22. "Eula.exe",
  23. "schtasks.exe",
  24. "svchost.exe"
  25.  
  26.  
  27. * Executed Commands:
  28. "\"C:\\Users\\user\\AppData\\Roaming\\remcos_agent_Protected.exe\"",
  29. "C:\\Users\\user\\AppData\\Roaming\\remcos_agent_Protected.exe "
  30.  
  31.  
  32. * Signatures Detected:
  33.  
  34. "Description": "Creates RWX memory",
  35. "Details":
  36.  
  37.  
  38. "Description": "Possible date expiration check, exits too soon after checking local time",
  39. "Details":
  40.  
  41. "process": "schtasks.exe, PID 1884"
  42.  
  43.  
  44.  
  45.  
  46. "Description": "Reads data out of its own binary image",
  47. "Details":
  48.  
  49. "self_read": "process: remcos_agent_Protected.exe, pid: 2404, offset: 0x00000000, length: 0x0011fe00"
  50.  
  51.  
  52. "self_read": "process: Eula.exe, pid: 2284, offset: 0x00000000, length: 0x00000040"
  53.  
  54.  
  55. "self_read": "process: Eula.exe, pid: 2284, offset: 0x00000100, length: 0x00000018"
  56.  
  57.  
  58. "self_read": "process: Eula.exe, pid: 2284, offset: 0x000001f8, length: 0x000000a0"
  59.  
  60.  
  61. "self_read": "process: Eula.exe, pid: 2284, offset: 0x00012600, length: 0x00000010"
  62.  
  63.  
  64.  
  65.  
  66. "Description": "Drops a binary and executes it",
  67. "Details":
  68.  
  69. "binary": "C:\\Users\\user\\AppData\\Roaming\\remcos_agent_Protected.exe"
  70.  
  71.  
  72.  
  73.  
  74. "Description": "Executed a process and injected code into it, probably while unpacking",
  75. "Details":
  76.  
  77. "Injection": "remcos_agent_Protected.exe(2404) -> remcos_agent_Protected.exe(2988)"
  78.  
  79.  
  80.  
  81.  
  82. "Description": "A potential decoy document was displayed to the user",
  83. "Details":
  84.  
  85. "disguised_executable": "The submitted file was an executable indicative of an attempt to get a user to run executable content disguised as a document"
  86.  
  87.  
  88. "Decoy Document": "\"c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\acrord32.exe\" \"c:\\users\\user\\appdata\\local\\temp\\medical-application-form.pdf\""
  89.  
  90.  
  91.  
  92.  
  93. "Description": "Installs itself for autorun at Windows startup",
  94. "Details":
  95.  
  96. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\remcos"
  97.  
  98.  
  99. "data": "\"C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe\""
  100.  
  101.  
  102. "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\remcos"
  103.  
  104.  
  105. "data": "\"C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe\""
  106.  
  107.  
  108.  
  109.  
  110. "Description": "Creates a hidden or system file",
  111. "Details":
  112.  
  113. "file": "C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe"
  114.  
  115.  
  116. "file": "C:\\Users\\user\\AppData\\Roaming\\remcos"
  117.  
  118.  
  119.  
  120.  
  121. "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
  122. "Details":
  123.  
  124. "target": "clamav:Win.Downloader.LokiBot-6962970-0, sha256:7226f09afaf19cfb171fc66b021452f191d231e5b7947e4b031b05cb649808b7, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  125.  
  126.  
  127.  
  128.  
  129. "Description": "Anomalous binary characteristics",
  130. "Details":
  131.  
  132. "anomaly": "Actual checksum does not match that reported in PE header"
  133.  
  134.  
  135.  
  136.  
  137.  
  138. * Started Service:
  139.  
  140. * Mutexes:
  141. "bderepair",
  142. "Local\\ZoneAttributeCacheCounterMutex",
  143. "Local\\ZonesCacheCounterMutex",
  144. "Local\\ZonesLockedCacheCounterMutex",
  145. "MDMAppInstaller",
  146. "Remcos_Mutex_Inj",
  147. "Remcos-S1KNPZ",
  148. "Global\\ARM Update Mutex",
  149. "Global\\Acro Update Mutex",
  150. "Local\\WininetStartupMutex",
  151. "Local\\ZonesCounterMutex"
  152.  
  153.  
  154. * Modified Files:
  155. "C:\\Users\\user\\AppData\\Roaming\\remcos_agent_Protected.exe",
  156. "C:\\Users\\user\\AppData\\Local\\Temp\\medical-application-form.pdf",
  157. "C:\\Users\\user\\AppData\\Roaming\\CapabilityAccessHandlers\\sfc.exe",
  158. "C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe",
  159. "C:\\Users\\user\\AppData\\Local\\Temp\\install.vbs",
  160. "C:\\Windows\\sysnative\\Tasks\\setx",
  161. "C:\\Windows\\appcompat\\Programs\\RecentFileCache.bcf"
  162.  
  163.  
  164. * Deleted Files:
  165. "C:\\Windows\\Tasks\\setx.job"
  166.  
  167.  
  168. * Modified Registry Keys:
  169. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
  170. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
  171. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\remcos",
  172. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\remcos",
  173. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\3F840E57-A70C-4327-8D4C-6299DE36D6F0\\Path",
  174. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\3F840E57-A70C-4327-8D4C-6299DE36D6F0\\Hash",
  175. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\setx\\Id",
  176. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\setx\\Index",
  177. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\3F840E57-A70C-4327-8D4C-6299DE36D6F0\\Triggers",
  178. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\3F840E57-A70C-4327-8D4C-6299DE36D6F0\\DynamicInfo"
  179.  
  180.  
  181. * Deleted Registry Keys:
  182. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  183. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  184. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  185. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  186. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\setx.job",
  187. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\setx.job.fp"
  188.  
  189.  
  190. * DNS Communications:
  191.  
  192. * Domains:
  193.  
  194. * Network Communication - ICMP:
  195.  
  196. * Network Communication - HTTP:
  197.  
  198. * Network Communication - SMTP:
  199.  
  200. * Network Communication - Hosts:
  201.  
  202. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment