paladin316

Exes_36e115843cfc23b428018b56fc009c14_exe_2019-08-01_12_30.txt

Aug 1st, 2019
2,339
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 6.31 KB | None | 0 0
  1.  
  2. * MalFamily: "Ispy"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_36e115843cfc23b428018b56fc009c14.exe"
  7. * File Size: 560640
  8. * File Type: "PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows"
  9. * SHA256: "8bac9d33487f7cbabce247af4cc82fe0d60a8934b573b5a544ff253739cab073"
  10. * MD5: "36e115843cfc23b428018b56fc009c14"
  11. * SHA1: "28e3c809196f6d4914f068b7eb7c96594585bb3e"
  12. * SHA512: "6a23cfc8e5ccdf5ef483d71f31be6af4f1dd70ca331dafa68230a1279bd9aeb4e42d0992107a8f1bb17b476a5e805e663531ef1c9a3c20ff7f4101b0e96bfb17"
  13. * CRC32: "0BAD9A19"
  14. * SSDEEP: "12288:ybKrwOfYr9ZDrE+t5EdEq+4Vm7kvUBtMIK4X:y61fyNt5Qq3OUB+IK"
  15.  
  16. * Process Execution:
  17. "Exes_36e115843cfc23b428018b56fc009c14.exe",
  18. "Exes_36e115843cfc23b428018b56fc009c14.exe",
  19. "svchost.exe",
  20. "WmiPrvSE.exe",
  21. "WMIADAP.exe"
  22.  
  23.  
  24. * Executed Commands:
  25. "\"C:\\Users\\user\\AppData\\Local\\Temp\\Exes_36e115843cfc23b428018b56fc009c14.exe\"",
  26. "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding"
  27.  
  28.  
  29. * Signatures Detected:
  30.  
  31. "Description": "Creates RWX memory",
  32. "Details":
  33.  
  34.  
  35. "Description": "A process attempted to delay the analysis task.",
  36. "Details":
  37.  
  38. "Process": "Exes_36e115843cfc23b428018b56fc009c14.exe tried to sleep 845 seconds, actually delayed analysis time by 0 seconds"
  39.  
  40.  
  41.  
  42.  
  43. "Description": "A process created a hidden window",
  44. "Details":
  45.  
  46. "Process": "Exes_36e115843cfc23b428018b56fc009c14.exe -> C:\\Users\\user\\AppData\\Local\\Temp\\Exes_36e115843cfc23b428018b56fc009c14.exe"
  47.  
  48.  
  49.  
  50.  
  51. "Description": "The binary likely contains encrypted or compressed data.",
  52. "Details":
  53.  
  54. "section": "name: .text, entropy: 7.99, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ, raw_size: 0x00088400, virtual_size: 0x00088264"
  55.  
  56.  
  57.  
  58.  
  59. "Description": "Attempts to remove evidence of file being downloaded from the Internet",
  60. "Details":
  61.  
  62. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_36e115843cfc23b428018b56fc009c14.exe:Zone.Identifier"
  63.  
  64.  
  65.  
  66.  
  67. "Description": "Executed a process and injected code into it, probably while unpacking",
  68. "Details":
  69.  
  70. "Injection": "Exes_36e115843cfc23b428018b56fc009c14.exe(3036) -> Exes_36e115843cfc23b428018b56fc009c14.exe(2632)"
  71.  
  72.  
  73.  
  74.  
  75. "Description": "Exhibits behavior characteristic of iSpy Keylogger",
  76. "Details":
  77.  
  78.  
  79. "Description": "Installs itself for autorun at Windows startup",
  80. "Details":
  81.  
  82. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell"
  83.  
  84.  
  85. "data": "\"C:\\Users\\user\\AppData\\Roaming\\E3NLGH1IcXAauTXi\\emdSIQ4UGKDF.exe\",explorer.exe"
  86.  
  87.  
  88.  
  89.  
  90. "Description": "Creates a hidden or system file",
  91. "Details":
  92.  
  93. "file": "C:\\Users\\user\\AppData\\Roaming\\E3NLGH1IcXAauTXi"
  94.  
  95.  
  96. "file": "C:\\Users\\user\\AppData\\Roaming\\E3NLGH1IcXAauTXi\\emdSIQ4UGKDF.exe"
  97.  
  98.  
  99.  
  100.  
  101. "Description": "File has been identified by 22 Antiviruses on VirusTotal as malicious",
  102. "Details":
  103.  
  104. "Cylance": "Unsafe"
  105.  
  106.  
  107. "Symantec": "ML.Attribute.HighConfidence"
  108.  
  109.  
  110. "ESET-NOD32": "a variant of MSIL/Kryptik.QME"
  111.  
  112.  
  113. "APEX": "Malicious"
  114.  
  115.  
  116. "Kaspersky": "HEUR:Backdoor.MSIL.Androm.gen"
  117.  
  118.  
  119. "Avast": "Win32:CrypterX-gen Trj"
  120.  
  121.  
  122. "Rising": "Dropper.Generic!8.35E (TFE:C:q6pABlz8FJJ)"
  123.  
  124.  
  125. "F-Secure": "Heuristic.HEUR/AGEN.1035809"
  126.  
  127.  
  128. "Invincea": "heuristic"
  129.  
  130.  
  131. "McAfee-GW-Edition": "BehavesLike.Win32.Generic.hc"
  132.  
  133.  
  134. "Trapmine": "malicious.moderate.ml.score"
  135.  
  136.  
  137. "FireEye": "Generic.mg.36e115843cfc23b4"
  138.  
  139.  
  140. "SentinelOne": "DFI - Malicious PE"
  141.  
  142.  
  143. "Avira": "HEUR/AGEN.1035809"
  144.  
  145.  
  146. "Endgame": "malicious (moderate confidence)"
  147.  
  148.  
  149. "ZoneAlarm": "HEUR:Backdoor.MSIL.Androm.gen"
  150.  
  151.  
  152. "Microsoft": "Trojan:Win32/Wacatac.B!ml"
  153.  
  154.  
  155. "Acronis": "suspicious"
  156.  
  157.  
  158. "Malwarebytes": "Spyware.HawkEyeKeyLogger"
  159.  
  160.  
  161. "AVG": "Win32:CrypterX-gen Trj"
  162.  
  163.  
  164. "CrowdStrike": "win/malicious_confidence_100% (D)"
  165.  
  166.  
  167. "Qihoo-360": "HEUR/QVM03.0.CD51.Malware.Gen"
  168.  
  169.  
  170.  
  171.  
  172. "Description": "Checks the CPU name from registry, possibly for anti-virtualization",
  173. "Details":
  174.  
  175.  
  176. "Description": "Creates a copy of itself",
  177. "Details":
  178.  
  179. "copy": "C:\\Users\\user\\AppData\\Roaming\\E3NLGH1IcXAauTXi\\emdSIQ4UGKDF.exe"
  180.  
  181.  
  182.  
  183.  
  184.  
  185. * Started Service:
  186.  
  187. * Mutexes:
  188. "Global\\CLR_CASOFF_MUTEX",
  189. "227611df-00df-4778-b5bf-29785eda7a06",
  190. "Global\\ADAP_WMI_ENTRY"
  191.  
  192.  
  193. * Modified Files:
  194. "C:\\Users\\user\\AppData\\Local\\GDIPFONTCACHEV1.DAT",
  195. "C:\\Users\\user\\AppData\\Roaming\\E3NLGH1IcXAauTXi\\emdSIQ4UGKDF.exe",
  196. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
  197. "\\??\\WMIDataDevice"
  198.  
  199.  
  200. * Deleted Files:
  201. "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_36e115843cfc23b428018b56fc009c14.exe:Zone.Identifier"
  202.  
  203.  
  204. * Modified Registry Keys:
  205. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Shell"
  206.  
  207.  
  208. * Deleted Registry Keys:
  209.  
  210. * DNS Communications:
  211.  
  212. * Domains:
  213.  
  214. * Network Communication - ICMP:
  215.  
  216. * Network Communication - HTTP:
  217.  
  218. * Network Communication - SMTP:
  219.  
  220. * Network Communication - Hosts:
  221.  
  222. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment