Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: ""
- * MalScore: 10.0
- * File Name: "Exes_0b3abdc421f2b01f6b72e5b914c9cd59.exe"
- * File Size: 1635328
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "144c93cb9567a66bbb851197330d8cff1e31defd4a88a6bcc3cfcf400ed7fdf0"
- * MD5: "0b3abdc421f2b01f6b72e5b914c9cd59"
- * SHA1: "10685ef16dfdd3e303c36473c5a3ef755e024ae8"
- * SHA512: "1833ff5e74f04ebda2587d636fa1f1d21ded3e4cabd095b637379e14ddb325a7316732cd542ead9ecd1a614b425ec358ea1e3ee85b58f53a9aa4125e431d6187"
- * CRC32: "1A37936B"
- * SSDEEP: "24576:WAHnh+eWsN3skA4RV1Hom2KXMmHaaqGPK5y5TubWNK1v7co3S3AnjnY+Lu5:xh+ZkldoPK8YaaqGz5iqNKx7f3So7I"
- * Process Execution:
- "Exes_0b3abdc421f2b01f6b72e5b914c9cd59.exe"
- * Executed Commands:
- * Signatures Detected:
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: Exes_0b3abdc421f2b01f6b72e5b914c9cd59.exe, pid: 2236, offset: 0x00000000, length: 0x0018f400"
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\mlAVtQVMSX"
- "data": "C:\\Users\\Public\\mlAVtQVMSX.vbs"
- "Description": "File has been identified by 21 Antiviruses on VirusTotal as malicious",
- "Details":
- "FireEye": "Generic.mg.0b3abdc421f2b01f"
- "Qihoo-360": "HEUR/QVM10.1.8079.Malware.Gen"
- "McAfee": "Trojan-AitInject.aq"
- "Cylance": "Unsafe"
- "Cyren": "W32/AutoIt.IJ.gen!Eldorado"
- "Symantec": "ML.Attribute.HighConfidence"
- "ESET-NOD32": "a variant of Win32/Injector.Autoit.EDA"
- "APEX": "Malicious"
- "ClamAV": "Win.Dropper.Cryptinject-7049492-0"
- "Rising": "Trojan.Win32.Agent_.sa (CLASSIC)"
- "DrWeb": "Trojan.PWS.Maria.3"
- "Invincea": "heuristic"
- "McAfee-GW-Edition": "BehavesLike.Win32.Downloader.th"
- "Ikarus": "Trojan.Autoit"
- "F-Prot": "W32/AutoIt.IJ.gen!Eldorado"
- "Endgame": "malicious (moderate confidence)"
- "Acronis": "suspicious"
- "Malwarebytes": "Trojan.MalPack.AutoIt"
- "Fortinet": "AutoIt/Injector.EDA!tr"
- "CrowdStrike": "win/malicious_confidence_70% (D)"
- "MaxSecure": "Trojan.Malware.300983.susgen"
- "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
- "Details":
- "target": "clamav:Win.Dropper.Cryptinject-7049492-0, sha256:144c93cb9567a66bbb851197330d8cff1e31defd4a88a6bcc3cfcf400ed7fdf0, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Dropper.Cryptinject-7049492-0, sha256:8c5f570342da8e0cbbaf15c2b505352087014f476f17a3cb8083e27475230ae0 , guest_paths:C:\\Users\\user\\eventcreate\\RunLegacyCPLElevated.bat, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "Description": "Creates a slightly modified copy of itself",
- "Details":
- "file": "C:\\Users\\user\\eventcreate\\RunLegacyCPLElevated.bat"
- "percent_match": 100
- "Description": "Anomalous binary characteristics",
- "Details":
- "anomaly": "Actual checksum does not match that reported in PE header"
- * Started Service:
- * Mutexes:
- * Modified Files:
- "C:\\Users\\user\\eventcreate\\RunLegacyCPLElevated.bat",
- "C:\\Users\\Public\\mlAVtQVMSX.vbs"
- * Deleted Files:
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\mlAVtQVMSX"
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment