Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Generickdz"
- * MalScore: 10.0
- * File Name: "rat_73f93180ed4bb8df8661d340a5dea4d5.msi"
- * File Size: 421888
- * File Type: "Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Code page: 1252, Last Printed: Fri Sep 21 09:56:09 2012, Create Time/Date: Fri Sep 21 09:56:09 2012, Name of Creating Application: Windows Installer, Title: Exe to msi converter free, Author: www.exetomsi.com, Template: ;0, Last Saved By: devuser, Revision Number: C35CF0AA-9B3F-4903-9F05-EBF606D58D3E Last Saved Time/Date: Tue May 21 11:56:44 2013, Number of Pages: 100, Number of Words: 0, Security: 0"
- * SHA256: "75258e30830056f136db0b55474cdc1b001c190e9e8317fbe7d3a838a903b2c7"
- * MD5: "73f93180ed4bb8df8661d340a5dea4d5"
- * SHA1: "4cb7758ca67fc17ead6ecdc20bfa5d5a6ebb1bf6"
- * SHA512: "1ca8e389ed3d6cdccdc99696a54948aee9f66c127385637f13b09387fd1fc953263fe406757c24443ed3060ec4f67dbd5acefc61d08a19ee4a42e8d7e4439850"
- * CRC32: "006851B9"
- * SSDEEP: "12288:xEzFqY+TEAVFqY+TEAn1Xn0cFB+cSomHl:xEzFqYyEAVFqYyEAtNhSoYl"
- * Process Execution:
- "msiexec.exe"
- * Executed Commands:
- * Signatures Detected:
- "Description": "File has been identified by 17 Antiviruses on VirusTotal as malicious",
- "Details":
- "FireEye": "Trojan.GenericKDZ.56935"
- "Arcabit": "Trojan.Generic.DDE67"
- "Invincea": "heuristic"
- "Avast": "Win32:CrypterX-gen Trj"
- "Kaspersky": "HEUR:Trojan-Dropper.MSIL.Dapato.gen"
- "BitDefender": "Trojan.GenericKDZ.56935"
- "Sophos": "Mal/Kryptik-DL"
- "DrWeb": "Trojan.PWS.Stealer.23680"
- "Emsisoft": "Trojan.GenericKDZ.56935 (B)"
- "Ikarus": "Trojan.MSIL.Inject"
- "Cyren": "W32/Trojan.SW.gen!Eldorado"
- "MAX": "malware (ai score=89)"
- "Microsoft": "Trojan:Win32/Wacatac.B!ml"
- "ZoneAlarm": "HEUR:Trojan-Dropper.MSIL.Dapato.gen"
- "GData": "Trojan.GenericKDZ.56935"
- "ESET-NOD32": "a variant of MSIL/Kryptik.SEM"
- "AVG": "Win32:CrypterX-gen Trj"
- * Started Service:
- * Mutexes:
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1",
- "Global\\_MSIExecute",
- "Global\\MSILOG_2908a65a1d5379cGOL.75d7cISM_pmeT_lacoL_ataDppA_ubs_sresU_:C"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\MSIc7d57.LOG"
- * Deleted Files:
- * Modified Registry Keys:
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment