Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Malicious"
- * MalScore: 10.0
- * File Name: "Exes_69acd31494f926f8121166408ab1b367.exe"
- * File Size: 283136
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "4645e8e9f756ff7ebd12fb1f0810a6be7cfd8894aea7747d8f66b0a67bc34e49"
- * MD5: "69acd31494f926f8121166408ab1b367"
- * SHA1: "6daddde25af846f41875c72e1deb51d486a924b5"
- * SHA512: "0cc13e8c37989ddaecbfcb47912ba12204429773fd6c5cfc8a7f43de75e99c0d4eb06ea6cd992bb711a9f647d1f57bbfa18456203dc5bb9ea2b15bc1d1cf34a1"
- * CRC32: "20BA5808"
- * SSDEEP: "3072:uswchDvFxTdkisfsVHeSXBKBlzU4XOHsdknsAdH4ge6BRHRwSe/zSRLthTKWR0e5:uswctcsHe0BiVqpx7eaxw9rahVSNf2"
- * Process Execution:
- "Exes_69acd31494f926f8121166408ab1b367.exe"
- * Executed Commands:
- * Signatures Detected:
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: Exes_69acd31494f926f8121166408ab1b367.exe, pid: 1908, offset: 0x00000000, length: 0x00045200"
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details":
- "section": "name: .reloc, entropy: 7.88, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ, raw_size: 0x0002b200, virtual_size: 0x0002b0ce"
- "Description": "File has been identified by 15 Antiviruses on VirusTotal as malicious",
- "Details":
- "FireEye": "Generic.mg.69acd31494f926f8"
- "APEX": "Malicious"
- "Endgame": "malicious (high confidence)"
- "DrWeb": "Trojan.PWS.Banker1.34248"
- "Invincea": "heuristic"
- "Trapmine": "suspicious.low.ml.score"
- "Paloalto": "generic.ml"
- "Antiy-AVL": "Trojan/Generic.ASVCS3S.187"
- "Acronis": "suspicious"
- "VBA32": "BScope.TrojanPSW.Banker"
- "Cylance": "Unsafe"
- "ESET-NOD32": "a variant of Win32/Kryptik.GVFZ"
- "Cybereason": "malicious.25af84"
- "CrowdStrike": "win/malicious_confidence_80% (W)"
- "Qihoo-360": "HEUR/QVM10.1.02B9.Malware.Gen"
- "Description": "Anomalous binary characteristics",
- "Details":
- "anomaly": "Actual checksum does not match that reported in PE header"
- * Started Service:
- * Mutexes:
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1"
- * Modified Files:
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_69acd31494f926f8121166408ab1b367.exe"
- * Modified Registry Keys:
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Add Comment
Please, Sign In to add comment