Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Trojan.Drixed
- Reported by neonprimetime security
- http://neonprimetime.blogspot.com
- *****
- 123.30.210.118
- 199.16.199.2
- hxxp://meostore.net/js/bin.exe
- hxxp://199.16.199.2/js/bin.exe
- *****
- Trojan.Downloader.Drixed
- Trojan.Drixed
- xls
- md5sum: ee3dd31abd4fc9af4214df7d385c5c4e
- *****
- From: "faxtastic!" <[email protected]>
- Subject: Fax from +4921154767199 Pages: 1
- 3l71l93Nvnz3mH7b-0-2015031714240625332.xls
- *****
- It appears Office12\EXCEL.EXE is using VBA Macros to make udp dns queries about for meostore.net
- It appears Office12\EXCEL.EXE makes tcp calls port 80 then out to meostore.net
- It appears Office12\EXCEL.EXE is looking for Office14\EXCEL.EXE (different versions) as well ad Acrobat, Powerpoint, and Word
- *****
- Files touched:
- \AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat
- \AppData\Roaming\Microsoft\Windows\Cookies
- \AppData\Local\Temp\2015031714240625332-1.xls
- \AppData\Roaming\Microsoft\Office\Excel12.pip
- \AppData\Local\Temp\CVR7C40.tmp.cvr
- \AppData\Local\Temp\97344.od
- \Local Settings\History\History.IE5\index.dat
- \Application Data\Microsoft\Office\Recent\2015031714240625332-1.LNK
- \Application Data\Microsoft\Office\Recent\2015031714240625332-2.LNK
- \Application Data\Microsoft\Office\Recent\index.dat
- *****
- Processes C:\Program Files\Microsoft Office\Office12\EXCEL.EXE is looking for:
- \Windows\explorer.exe
- \Windows\System32\taskhost.exe
- \Program Files\Microsoft Office\Office14\EXCEL.EXE
- \Program Files\Microsoft Office\Office12\POWERPNT.EXE
- \Program Files\Microsoft Office\Office14\POWERPNT.EXE
- \Program Files\Microsoft Office\Office12\WINWORD.EXE
- \Windows\System32\cmd.exe
- \Program Files\Adobe\Reader 9.0\Reader\AcroRd32.exe
- \Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe
- \Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exe
- \WINDOWS\system32\ctfmon.exe
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement