Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Sober"
- * MalScore: 10.0
- * File Name: "csrss.exe"
- * File Size: 55390
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "6c2368ae2d0f379640aa7e801a13790a83303dc83ba30566e21c7006b96f4ef4"
- * MD5: "248639727ebeccff6208ec8e0c7c3656"
- * SHA1: "e976afdc52350173f633e211a1fdbc5ba627ce84"
- * SHA512: "3da23f1ca172b735d8ef80067029b54ff214a670ebf571cf4d4f1826c93c0194be55113dd71aedd2b68dcb341cca92d9549728a5e3bb04b37713c2c99d0c4f7d"
- * CRC32: "55990726"
- * SSDEEP: "1536:IEbBPkeCBrZHVX5mXgwp3tEuitdLKrzTHZ:IImFPigwVtHitdLKt"
- * Process Execution:
- "csrss.exe"
- * Executed Commands:
- * Signatures Detected:
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: csrss.exe, pid: 2960, offset: 0x000000a0, length: 0x00000001"
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details":
- "section": "name: , entropy: 7.87, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x0000cc00, virtual_size: 0x0000d000"
- "Description": "File has been identified by 55 Antiviruses on VirusTotal as malicious",
- "Details":
- "MicroWorld-eScan": "Win32.Sober.AH@mm"
- "nProtect": "Worm/W32.Sober.55390"
- "McAfee": "W32/Sober@MM!M681"
- "Cylance": "Unsafe"
- "TheHacker": "W32/Sober.y"
- "K7GW": "Trojan ( 0000416a1 )"
- "K7AntiVirus": "Trojan ( 0000416a1 )"
- "Arcabit": "Win32.Sober.E999E7"
- "TrendMicro": "WORM_SOBER.AG"
- "Baidu": "Win32.Trojan.WisdomEyes.16070401.9500.9988"
- "F-Prot": "W32/Sober.Z@mm"
- "Symantec": "W32.Sober.X@mm"
- "TotalDefense": "Win32/Sober.W"
- "ClamAV": "Win.Worm.Sober-52"
- "Kaspersky": "Email-Worm.Win32.Sober.y"
- "BitDefender": "Win32.Sober.AH@mm"
- "NANO-Antivirus": "Trojan.Win32.Sober.enwv"
- "ViRobot": "I-Worm.Win32.Sober.AD"
- "AegisLab": "W32.W.Sober.y!c"
- "Ad-Aware": "Win32.Sober.AH@mm"
- "Sophos": "W32/Sober-Z"
- "Comodo": "Worm.Win32.Sober.Y"
- "F-Secure": "Win32.Sober.AH@mm"
- "DrWeb": "Win32.HLLM.Sober.43"
- "VIPRE": "Trojan.Win32.Generic!BT"
- "Invincea": "heuristic"
- "McAfee-GW-Edition": "BehavesLike.Win32.VBObfus.qc"
- "Emsisoft": "Win32.Sober.AH@mm (B)"
- "SentinelOne": "static engine - malicious"
- "Cyren": "W32/Sober.OJVA-1916"
- "Jiangmin": "I-Worm/Sober.s"
- "Webroot": "W32.Trojan.Worm-Sober"
- "Avira": "WORM/Sober.Y"
- "Antiy-AVL": "WormEmail/Win32.Sober"
- "Microsoft": "Worm:Win32/Sober.Z@mm!CME681"
- "Endgame": "malicious (high confidence)"
- "SUPERAntiSpyware": "Worm.Sober Variant"
- "ZoneAlarm": "Email-Worm.Win32.Sober.y"
- "GData": "Win32.Sober.AH@mm"
- "AhnLab-V3": "Trojan/Win32.HDC.C43004"
- "ALYac": "Win32.Sober.AH@mm"
- "AVware": "Trojan.Win32.Generic!BT"
- "MAX": "malware (ai score=83)"
- "VBA32": "suspected of Email-Worm.Sober.2"
- "Malwarebytes": "Worm.Sober"
- "Panda": "W32/Sober.AH.worm!CME-681"
- "Zoner": "I-Worm.Sober.Y"
- "ESET-NOD32": "Win32/Sober.Y"
- "Tencent": "Win32.Worm-email.Sober.Hqlq"
- "Yandex": "I-Worm.Sober.AO"
- "Ikarus": "Email-Worm.Win32.Sober"
- "AVG": "Win32:Sober-AB Wrm"
- "Avast": "Win32:Sober-AB Wrm"
- "CrowdStrike": "malicious_confidence_100% (D)"
- "Qihoo-360": "Win32/Worm.33c"
- "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
- "Details":
- "target": "clamav:Win.Worm.Sober-52, sha256:6c2368ae2d0f379640aa7e801a13790a83303dc83ba30566e21c7006b96f4ef4, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "Description": "Anomalous binary characteristics",
- "Details":
- "anomaly": "Found duplicated section names"
- * Started Service:
- * Mutexes:
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\csrss.exe",
- "C:\\Windows\\WinSecurity\\socket3.ifo"
- * Deleted Files:
- * Modified Registry Keys:
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Add Comment
Please, Sign In to add comment