Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * ID: 4989
- * MalFamily: "AgentTesla"
- * MalScore: 10.0
- * File Name: "Exes_255daa6722de6ad03545070dfbef3330.exe"
- * File Size: 159744
- * File Type: "PE32 executable (console) Intel 80386, for MS Windows"
- * SHA256: "86dd21b8388f23371d680e2632d0855b442f0fa7e93cd009d6e762715ba2d054"
- * MD5: "255daa6722de6ad03545070dfbef3330"
- * SHA1: "80aedf2eddc9e2f39306cbaa63e59c7a08468699"
- * SHA512: "ed629f4cfa2cabb1cf6199766531ec9e947aee8c0b67fd84def96f8861ef98a3b985d2e3e89ecc9e322efc9d35a7a4264bf679e98eb47ac0e83f8031275b7ace"
- * CRC32: "71DC93A2"
- * SSDEEP: "3072:ikmVcWhCz7cruMlg+PtBxp3bTsZiVXBeN/2KD2VD:/muoCz7cyUP9dbTYipBGG"
- * Process Execution:
- "XFi8bQy7dEFCCQX.exe"
- * Executed Commands:
- * Signatures Detected:
- "Description": "SetUnhandledExceptionFilter detected (possible anti-debug)",
- "Details":
- "Description": "File has been identified by 53 Antiviruses on VirusTotal as malicious",
- "Details":
- "MicroWorld-eScan": "Trojan.Banker.MPZ"
- "FireEye": "Trojan.Banker.MPZ"
- "CAT-QuickHeal": "Trojan.Dynamer"
- "McAfee": "Generic.dx!255DAA6722DE"
- "Cylance": "Unsafe"
- "SUPERAntiSpyware": "Trojan.Agent/Gen-Banker"
- "K7AntiVirus": "Spyware ( 004e12d21 )"
- "Alibaba": "TrojanSpy:Win32/Kaptoxa.e02bb05f"
- "K7GW": "Spyware ( 004e12d21 )"
- "CrowdStrike": "win/malicious_confidence_100% (W)"
- "Arcabit": "Trojan.Banker.MPZ"
- "TrendMicro": "TSPY_POCARDL.AI"
- "Cyren": "W32/Trojan.FLYY-1205"
- "Symantec": "Hacktool.Poscard"
- "Avast": "Win32:CardStealer-B Trj"
- "ClamAV": "Win.Trojan.Agent-797751"
- "Kaspersky": "Trojan-Spy.Win32.Kaptoxa.f"
- "BitDefender": "Trojan.Banker.MPZ"
- "NANO-Antivirus": "Trojan.Win32.POS.cubaqj"
- "Paloalto": "generic.ml"
- "AegisLab": "Trojan.Win32.Kaptoxa.4!c"
- "Tencent": "Win32.Trojan-spy.Kaptoxa.Hpsf"
- "Ad-Aware": "Trojan.Banker.MPZ"
- "Emsisoft": "Trojan.Banker.MPZ (B)"
- "Comodo": "Malware@#1wcmt8j8shg8i"
- "DrWeb": "Trojan.DownLoader9.23976"
- "Zillya": "Trojan.POS.Win32.1"
- "McAfee-GW-Edition": "Generic.dx!255DAA6722DE"
- "Sophos": "Troj/Trackr-AF"
- "Ikarus": "Trojan-Spy.POSCard"
- "F-Prot": "W32/Trojan3.KQU"
- "Jiangmin": "TrojanSpy.POS.a"
- "MAX": "malware (ai score=100)"
- "Antiy-AVL": "TrojanSpy/Win32.POS"
- "Microsoft": "TrojanSpy:Win32/Posokap.A!bit"
- "Endgame": "malicious (high confidence)"
- "ViRobot": "Backdoor.Win32.Hesetox.159744"
- "ZoneAlarm": "Trojan-Spy.Win32.Kaptoxa.f"
- "GData": "Trojan.Banker.MPZ"
- "AhnLab-V3": "HackTool/Win32.Agent.C1230346"
- "ALYac": "Spyware.Infostealer.POS.KAPTOXA"
- "VBA32": "BScope.TrojanSpy.POS"
- "Malwarebytes": "Spyware.Agent"
- "ESET-NOD32": "Win32/Spy.POSCardStealer.C"
- "TrendMicro-HouseCall": "TSPY_POCARDL.AI"
- "Rising": "Spyware.POSCardStealer!8.644 (TFE:5:S9joKTdd2XV)"
- "Yandex": "TrojanSpy.POS!ZPEogJGw1RE"
- "MaxSecure": "Trojan.Malware.5501008.susgen"
- "Fortinet": "W32/Generic.AC.2090302"
- "Webroot": "W32.Trojan.Gen"
- "AVG": "Win32:CardStealer-B Trj"
- "Panda": "HackingTool/VulnerabilityScanner"
- "Qihoo-360": "Malware.Radar01.Gen"
- "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
- "Details":
- "target": "clamav:Win.Trojan.Agent-797751, sha256:86dd21b8388f23371d680e2632d0855b442f0fa7e93cd009d6e762715ba2d054, type:PE32 executable (console) Intel 80386, for MS Windows"
- * Started Service:
- * Mutexes:
- * Modified Files:
- * Deleted Files:
- * Modified Registry Keys:
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment