Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: ""
- * MalScore: 10.0
- * File Name: "Exes_f734bced23aef410e3a723a5226e1c60.exe"
- * File Size: 1280512
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "9fcccddd5eb0b89160a600c8c4fead60666f952407ab45463e79326a8a37355b"
- * MD5: "f734bced23aef410e3a723a5226e1c60"
- * SHA1: "849fa4483b5f42d9b55464779e9255bff2632bf9"
- * SHA512: "80c82b5b2002b31bc4faa44c3c2ca3cde083d80ef12c0d4c0a3e8964caa56a6cc7175ebe9d6fb82f430d5971c2edf4efcec550902b496466bd4e45b05697ad14"
- * CRC32: "75F98379"
- * SSDEEP: "24576:VAHnh+eWsN3skA4RV1Hom2KXMmHaVpr3pM8KTEeU6mnReD2a5:Eh+ZkldoPK8YaVU7TZU6mQv"
- * Process Execution:
- "PGZxPlNW.exe",
- "RegSvcs.exe",
- "svchost.exe",
- "WmiPrvSE.exe",
- "svchost.exe"
- * Executed Commands:
- "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding"
- * Signatures Detected:
- "Description": "SetUnhandledExceptionFilter detected (possible anti-debug)",
- "Details":
- "Description": "Behavioural detection: Executable code extraction",
- "Details":
- "Description": "Guard pages use detected - possible anti-debugging.",
- "Details":
- "Description": "A process attempted to delay the analysis task.",
- "Details":
- "Process": "RegSvcs.exe tried to sleep 420 seconds, actually delayed analysis time by 0 seconds"
- "Description": "Expresses interest in specific running processes",
- "Details":
- "process": "RegSvcs.exe"
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: PGZxPlNW.exe, pid: 2408, offset: 0x00000000, length: 0x00138a00"
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details":
- "section": "name: .rsrc, entropy: 7.95, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ, raw_size: 0x0006e400, virtual_size: 0x0006e288"
- "Description": "Behavioural detection: Injection (Process Hollowing)",
- "Details":
- "Injection": "PGZxPlNW.exe(2408) -> RegSvcs.exe(2416)"
- "Description": "Executed a process and injected code into it, probably while unpacking",
- "Details":
- "Injection": "PGZxPlNW.exe(2408) -> RegSvcs.exe(2416)"
- "Description": "Behavioural detection: Injection (inter-process)",
- "Details":
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\fjfbmtlwgoacezqljpwo"
- "data": "C:\\Users\\Public\\fjfbmtlwgoacezqljpwo.vbs"
- "Description": "Stack pivoting was detected when using a critical API",
- "Details":
- "process": "svchost.exe:2716"
- "process": "WmiPrvSE.exe:1824"
- "Description": "File has been identified by 22 Antiviruses on VirusTotal as malicious",
- "Details":
- "McAfee": "Artemis!F734BCED23AE"
- "Cylance": "Unsafe"
- "Alibaba": "Trojan:Win32/AutoitInject.7f6e5f64"
- "F-Prot": "W32/AutoIt.KF.gen!Eldorado"
- "Symantec": "ML.Attribute.HighConfidence"
- "APEX": "Malicious"
- "Kaspersky": "HEUR:Trojan.Win32.Generic"
- "Paloalto": "generic.ml"
- "Endgame": "malicious (high confidence)"
- "F-Secure": "Heuristic.HEUR/AGEN.1038811"
- "McAfee-GW-Edition": "BehavesLike.Win32.Downloader.tc"
- "Cyren": "W32/AutoIt.KF.gen!Eldorado"
- "Avira": "HEUR/AGEN.1038811"
- "Microsoft": "Trojan:Win32/Wacatac.B!ml"
- "ZoneAlarm": "HEUR:Trojan.Win32.Generic"
- "Acronis": "suspicious"
- "ESET-NOD32": "a variant of Win32/Injector.Autoit.EGA"
- "Rising": "Trojan.Obfus/Autoit!1.BB81 (CLASSIC)"
- "Fortinet": "AutoIt/Injector.EGA!tr"
- "Panda": "Trj/Genetic.gen"
- "CrowdStrike": "win/malicious_confidence_70% (D)"
- "Qihoo-360": "HEUR/QVM10.1.79E1.Malware.Gen"
- "Description": "Checks the CPU name from registry, possibly for anti-virtualization",
- "Details":
- "Description": "Creates a slightly modified copy of itself",
- "Details":
- "file": "C:\\Users\\user\\RMActivate\\amstream.bat"
- "percent_match": 100
- "Description": "Anomalous binary characteristics",
- "Details":
- "anomaly": "Actual checksum does not match that reported in PE header"
- * Started Service:
- * Mutexes:
- "Global\\CLR_PerfMon_WrapMutex",
- "Global\\CLR_CASOFF_MUTEX"
- * Modified Files:
- "C:\\Users\\user\\RMActivate\\amstream.bat",
- "C:\\Users\\Public\\fjfbmtlwgoacezqljpwo.vbs",
- "\\??\\PIPE\\samr",
- "C:\\Windows\\sysnative\\wbem\\repository\\WRITABLE.TST",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING1.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING2.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING3.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\OBJECTS.DATA",
- "C:\\Windows\\sysnative\\wbem\\repository\\INDEX.BTR",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER",
- "\\??\\WMIDataDevice"
- * Deleted Files:
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\fjfbmtlwgoacezqljpwo",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Wbem\\Transports\\Decoupled\\Server",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\CreationTime",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\MarshaledProxy",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\ProcessIdentifier",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ConfigValueEssNeedsLoading",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\List of event-active namespaces",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\ESS\\//./root/CIMV2\\SCM Event Provider"
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment