paladin316

Exes_545b49d45f865b18e8f8448896112d97_exe_2019-07-16_04_30.txt

Jul 16th, 2019
2,141
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 11.84 KB | None | 0 0
  1.  
  2. * MalFamily: ""
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_545b49d45f865b18e8f8448896112d97.exe"
  7. * File Size: 1367552
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "22b6db2c54db6ae7c84f1f23bd37e9820f5c7c141646c4fdfc7a198e568c8e79"
  10. * MD5: "545b49d45f865b18e8f8448896112d97"
  11. * SHA1: "a5fd846a19fe8b9cb858d52b7d8338488c98aae3"
  12. * SHA512: "946c33e2a8952f82250cdd7f837d40efd265e4918fb414e149e9897dd2259c7a52da6389b841d6348d8b9c0174381c2e3c4d1d7c0788326778eba3bde5f5c282"
  13. * CRC32: "3A1FAA7A"
  14. * SSDEEP: "24576:L6EJtqwC8O4TId8ovFfBiYVaXelWwnBKKlip/auzRRZl8qlNXkKTrzlE+2:Oj+1BlNXkerzl"
  15.  
  16. * Process Execution:
  17. "Exes_545b49d45f865b18e8f8448896112d97.exe",
  18. "cmd.exe",
  19. "reg.exe",
  20. "images.exe",
  21. "cmd.exe",
  22. "services.exe",
  23. "svchost.exe",
  24. "WmiPrvSE.exe",
  25. "lsass.exe",
  26. "taskhost.exe",
  27. "svchost.exe"
  28.  
  29.  
  30. * Executed Commands:
  31. "cmd.exe /c REG ADD \"HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\" /f /v Load /t REG_SZ /d \"C:\\ProgramData\\images.exe\"",
  32. "C:\\Windows\\system32\\reg.exe REG ADD \"HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\" /f /v Load /t REG_SZ /d \"C:\\ProgramData\\images.exe\"",
  33. "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding",
  34. "C:\\Windows\\system32\\lsass.exe",
  35. "taskhost.exe $(Arg0)",
  36. "C:\\Windows\\System32\\svchost.exe -k WerSvcGroup"
  37.  
  38.  
  39. * Signatures Detected:
  40.  
  41. "Description": "Creates RWX memory",
  42. "Details":
  43.  
  44.  
  45. "Description": "A process attempted to delay the analysis task.",
  46. "Details":
  47.  
  48. "Process": "images.exe tried to sleep 254 seconds, actually delayed analysis time by 0 seconds"
  49.  
  50.  
  51. "Process": "WmiPrvSE.exe tried to sleep 360 seconds, actually delayed analysis time by 0 seconds"
  52.  
  53.  
  54.  
  55.  
  56. "Description": "Expresses interest in specific running processes",
  57. "Details":
  58.  
  59. "process": "spoolsv.exe"
  60.  
  61.  
  62. "process": "explorer.exe"
  63.  
  64.  
  65.  
  66.  
  67. "Description": "Repeatedly searches for a not-found process, may want to run with startbrowser=1 option",
  68. "Details":
  69.  
  70.  
  71. "Description": "Reads data out of its own binary image",
  72. "Details":
  73.  
  74. "self_read": "process: images.exe, pid: 1832, offset: 0x00000000, length: 0x0014de00"
  75.  
  76.  
  77.  
  78.  
  79. "Description": "A process created a hidden window",
  80. "Details":
  81.  
  82. "Process": "images.exe -> C:\\Windows\\System32\\cmd.exe"
  83.  
  84.  
  85.  
  86.  
  87. "Description": "Drops a binary and executes it",
  88. "Details":
  89.  
  90. "binary": "C:\\ProgramData\\images.exe"
  91.  
  92.  
  93.  
  94.  
  95. "Description": "Attempts to remove evidence of file being downloaded from the Internet",
  96. "Details":
  97.  
  98. "file": "C:\\ProgramData\\images.exe:Zone.Identifier"
  99.  
  100.  
  101.  
  102.  
  103. "Description": "Code injection with CreateRemoteThread in a remote process",
  104. "Details":
  105.  
  106. "Injection": "images.exe(1832) -> cmd.exe(1760)"
  107.  
  108.  
  109.  
  110.  
  111. "Description": "Attempts to restart the guest VM",
  112. "Details":
  113.  
  114.  
  115. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  116. "Details":
  117.  
  118. "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 4251372 times"
  119.  
  120.  
  121.  
  122.  
  123. "Description": "Steals private information from local Internet browsers",
  124. "Details":
  125.  
  126. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data"
  127.  
  128.  
  129.  
  130.  
  131. "Description": "Installs itself for autorun at Windows startup",
  132. "Details":
  133.  
  134. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\Load"
  135.  
  136.  
  137. "data": "C:\\ProgramData\\images.exe"
  138.  
  139.  
  140.  
  141.  
  142. "Description": "File has been identified by 19 Antiviruses on VirusTotal as malicious",
  143. "Details":
  144.  
  145. "MicroWorld-eScan": "Gen:Variant.Sinowal.1"
  146.  
  147.  
  148. "FireEye": "Gen:Variant.Sinowal.1"
  149.  
  150.  
  151. "K7AntiVirus": "Riskware ( 0040eff71 )"
  152.  
  153.  
  154. "BitDefender": "Gen:Variant.Sinowal.1"
  155.  
  156.  
  157. "K7GW": "Riskware ( 0040eff71 )"
  158.  
  159.  
  160. "APEX": "Malicious"
  161.  
  162.  
  163. "Ad-Aware": "Gen:Variant.Sinowal.1"
  164.  
  165.  
  166. "Emsisoft": "Gen:Variant.Sinowal.1 (B)"
  167.  
  168.  
  169. "DrWeb": "Trojan.PWS.Maria.4"
  170.  
  171.  
  172. "Antiy-AVL": "Trojan/Win32.Wacatac"
  173.  
  174.  
  175. "Endgame": "malicious (moderate confidence)"
  176.  
  177.  
  178. "Microsoft": "Trojan:Win32/Wacatac.B!ml"
  179.  
  180.  
  181. "GData": "Gen:Variant.Sinowal.1"
  182.  
  183.  
  184. "MAX": "malware (ai score=85)"
  185.  
  186.  
  187. "ESET-NOD32": "a variant of Win32/Kryptik.GUQJ"
  188.  
  189.  
  190. "SentinelOne": "DFI - Suspicious PE"
  191.  
  192.  
  193. "Cybereason": "malicious.45f865"
  194.  
  195.  
  196. "CrowdStrike": "win/malicious_confidence_80% (D)"
  197.  
  198.  
  199. "Qihoo-360": "HEUR/QVM20.1.8DB5.Malware.Gen"
  200.  
  201.  
  202.  
  203.  
  204. "Description": "Creates a copy of itself",
  205. "Details":
  206.  
  207. "copy": "C:\\ProgramData\\images.exe"
  208.  
  209.  
  210.  
  211.  
  212. "Description": "Harvests information related to installed mail clients",
  213. "Details":
  214.  
  215. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows Messaging Subsystem\\Profiles\\9375CFF0413111d3B88A00104B2A6676"
  216.  
  217.  
  218. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676"
  219.  
  220.  
  221. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\POP3 Server"
  222.  
  223.  
  224. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\SMTP Password"
  225.  
  226.  
  227. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\Account Name"
  228.  
  229.  
  230. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\SMTP Server"
  231.  
  232.  
  233. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\Email"
  234.  
  235.  
  236. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\HTTP Password"
  237.  
  238.  
  239. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676"
  240.  
  241.  
  242. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\HTTP Password"
  243.  
  244.  
  245. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\IMAP Password"
  246.  
  247.  
  248. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\POP3 Password"
  249.  
  250.  
  251. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\Email"
  252.  
  253.  
  254. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\POP3 User"
  255.  
  256.  
  257. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\POP3 Server"
  258.  
  259.  
  260. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\SMTP Password"
  261.  
  262.  
  263. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\POP3 User"
  264.  
  265.  
  266. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\Account Name"
  267.  
  268.  
  269. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\IMAP Password"
  270.  
  271.  
  272. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001"
  273.  
  274.  
  275. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\SMTP Server"
  276.  
  277.  
  278. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\POP3 Password"
  279.  
  280.  
  281. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002"
  282.  
  283.  
  284.  
  285.  
  286. "Description": "Collects information to fingerprint the system",
  287. "Details":
  288.  
  289.  
  290.  
  291. * Started Service:
  292. "VaultSvc",
  293. "WerSvc"
  294.  
  295.  
  296. * Mutexes:
  297.  
  298. * Modified Files:
  299. "C:\\ProgramData\\images.exe",
  300. "C:\\Users\\user\\AppData\\Local\\Microsoft Vision\\16-07-2019_02.17.48",
  301. "C:\\Users\\user\\AppData\\Roaming\\k.Jwn.n.tmp",
  302. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
  303. "C:\\Windows\\sysnative\\LogFiles\\Scm\\4963ad21-c4a5-42a5-b9bd-e441d57204fe",
  304. "C:\\Windows\\sysnative\\LogFiles\\Scm\\8d661786-e909-433d-bd16-a47ccb39306a"
  305.  
  306.  
  307. * Deleted Files:
  308. "C:\\ProgramData\\images.exe:Zone.Identifier",
  309. "C:\\Users\\user\\AppData\\Roaming\\k.Jwn.n.tmp"
  310.  
  311.  
  312. * Modified Registry Keys:
  313. "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MediaResources\\msvideo",
  314. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\MaxConnectionsPer1_0Server",
  315. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\MaxConnectionsPerServer",
  316. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\M3APTTBVA7",
  317. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\M3APTTBVA7\\inst",
  318. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\Load",
  319. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type"
  320.  
  321.  
  322. * Deleted Registry Keys:
  323.  
  324. * DNS Communications:
  325.  
  326. * Domains:
  327.  
  328. * Network Communication - ICMP:
  329.  
  330. * Network Communication - HTTP:
  331.  
  332. * Network Communication - SMTP:
  333.  
  334. * Network Communication - Hosts:
  335.  
  336. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment