Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * ID: 1662
- * MalFamily: "Troldesh"
- * MalScore: 10.0
- * File Name: "Troldesh_f148900c917e058cbaf155e4ab61bf67.1"
- * File Size: 1968640
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "f48824d00a5e0d8e4a45d007997b7f2b6b6665990fb0bd71b275a9765c73fd12"
- * MD5: "f148900c917e058cbaf155e4ab61bf67"
- * SHA1: "47b12e079fe91be357f8a2484b836d934e120d2d"
- * SHA512: "1a95e4c00b843a9d62792bf4c7dcf4510284e488eb9f177092d5f85a8e0fd1f1c5fe662d287417ea5ddb86f812a082aa85275fa15b0cb9deff2fb2977059fe14"
- * CRC32: "295B4606"
- * SSDEEP: "49152:gHRXRyY8U3fSxIcYHmoDG/7FLowa0BdWpTOp63WX:gHRXvJfSxInHRKj1G0BdWpTN"
- * Process Execution:
- "zXRgyWuI9ZF.exe",
- "zXRgyWuI9ZF.exe"
- * Executed Commands:
- "C:\\Users\\user\\AppData\\Local\\Temp\\zXRgyWuI9ZF.exe"
- * Signatures Detected:
- "Description": "SetUnhandledExceptionFilter detected (possible anti-debug)",
- "Details":
- "Description": "Behavioural detection: Executable code extraction",
- "Details":
- "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
- "Details":
- "IP_ioc": "128.31.0.39:9101 (United States)"
- "Description": "Scheduled file move on reboot detected",
- "Details":
- "File Move on Reboot": "Old: C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\state.tmp -> New: C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\state"
- "Description": "Possible date expiration check, exits too soon after checking local time",
- "Details":
- "process": "zXRgyWuI9ZF.exe, PID 1460"
- "Description": "Starts servers listening on 127.0.0.1:58046",
- "Details":
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: zXRgyWuI9ZF.exe, pid: 1776, offset: 0x00000000, length: 0x001e0a00"
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details":
- "section": "name: .rsrc, entropy: 7.99, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ, raw_size: 0x00159e00, virtual_size: 0x00159d24"
- "Description": "Behavioural detection: Injection (Process Hollowing)",
- "Details":
- "Injection": "zXRgyWuI9ZF.exe(1460) -> zXRgyWuI9ZF.exe(1776)"
- "Description": "Executed a process and injected code into it, probably while unpacking",
- "Details":
- "Injection": "zXRgyWuI9ZF.exe(1460) -> zXRgyWuI9ZF.exe(1776)"
- "Description": "Behavioural detection: Injection (inter-process)",
- "Details":
- "Description": "Installs Tor on the infected machine",
- "Details":
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Client Server Runtime Subsystem"
- "data": "\"C:\\ProgramData\\Windows\\csrss.exe\""
- "Description": "Collects information about installed applications",
- "Details":
- "Program": "Google Update Helper"
- "Program": "Microsoft Excel MUI 2013"
- "Program": "Microsoft Outlook MUI 2013"
- "Program": "Google Chrome"
- "Program": "Adobe Flash Player 29 NPAPI"
- "Program": "Adobe Flash Player 29 ActiveX"
- "Program": "Microsoft DCF MUI 2013"
- "Program": "Microsoft Access MUI 2013"
- "Program": "Microsoft Office Proofing Tools 2013 - English"
- "Program": "Adobe Acrobat Reader DC"
- "Program": "Microsoft Publisher MUI 2013"
- "Program": "Microsoft Office Shared MUI 2013"
- "Program": "Microsoft Office OSM MUI 2013"
- "Program": "Microsoft InfoPath MUI 2013"
- "Program": "Microsoft Office Shared Setup Metadata MUI 2013"
- "Program": "Outils de v\\xc3\\xa9rification linguistique 2013 de Microsoft Office\\xc2\\xa0- Fran\\xc3\\xa7ais"
- "Program": "Microsoft Word MUI 2013"
- "Program": "Microsoft OneDrive"
- "Program": "Microsoft Groove MUI 2013"
- "Program": "Microsoft Office Proofing Tools 2013 - Espa\\xc3\\xb1ol"
- "Program": "Microsoft Access Setup Metadata MUI 2013"
- "Program": "Microsoft Office OSM UX MUI 2013"
- "Program": "Java Auto Updater"
- "Program": "Microsoft PowerPoint MUI 2013"
- "Program": "Microsoft Office Professional Plus 2013"
- "Program": "Adobe Refresh Manager"
- "Program": "Microsoft Office Proofing 2013"
- "Program": "Microsoft Lync MUI 2013"
- "Program": "Microsoft OneNote MUI 2013"
- "Description": "Creates a hidden or system file",
- "Details":
- "file": "C:\\ProgramData\\Windows\\"
- "Description": "File has been identified by 27 Antiviruses on VirusTotal as malicious",
- "Details":
- "MicroWorld-eScan": "Trojan.GenericKD.32425516"
- "McAfee": "Artemis!F148900C917E"
- "Malwarebytes": "Trojan.Dropper"
- "CrowdStrike": "win/malicious_confidence_90% (W)"
- "Arcabit": "Trojan.Generic.D1EEC62C"
- "TrendMicro": "Possible_HPGen-38"
- "Symantec": "Trojan Horse"
- "APEX": "Malicious"
- "Paloalto": "generic.ml"
- "Kaspersky": "Trojan.Win32.Fsysna.fsiw"
- "BitDefender": "Trojan.GenericKD.32425516"
- "Ad-Aware": "Trojan.GenericKD.32425516"
- "Emsisoft": "Trojan.GenericKD.32425516 (B)"
- "DrWeb": "Trojan.Encoder.858"
- "Invincea": "heuristic"
- "McAfee-GW-Edition": "BehavesLike.Win32.Generic.tc"
- "FireEye": "Generic.mg.f148900c917e058c"
- "Sophos": "Mal/Generic-S"
- "Avira": "TR/AD.Troldesh.okrph"
- "Microsoft": "Trojan:Win32/Dynamer!rfn"
- "ZoneAlarm": "Trojan.Win32.Fsysna.fsiw"
- "GData": "Win32.Trojan-Ransom.Shade.XBKET1"
- "Acronis": "suspicious"
- "Cylance": "Unsafe"
- "TrendMicro-HouseCall": "Possible_HPGen-38"
- "Ikarus": "Trojan-Ransom.Troldesh"
- "Fortinet": "W32/Kryptik.GVSM!tr"
- "Description": "Creates a copy of itself",
- "Details":
- "copy": "C:\\ProgramData\\Windows\\csrss.exe"
- * Started Service:
- * Mutexes:
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\Clip",
- "\\??\\PIPE\\wkssvc",
- "\\??\\PIPE\\srvsvc",
- "C:\\ProgramData\\Windows\\csrss.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\lock",
- "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\state.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\state"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\2972.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\6893A5D897\\state.tmp"
- * Modified Registry Keys:
- "HKEY_LOCAL_MACHINE\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\System32\\Configuration\\",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\System32\\Configuration\\xi",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Client Server Runtime Subsystem",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\System32\\Configuration\\xVersion"
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- "country_name": "Netherlands",
- "ip": "194.109.206.212",
- "inaddrarpa": "",
- "hostname": ""
- "country_name": "Germany",
- "ip": "131.188.40.189",
- "inaddrarpa": "",
- "hostname": ""
- "country_name": "United States",
- "ip": "128.31.0.39",
- "inaddrarpa": "",
- "hostname": ""
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment