paladin316

NetWire_5c70d24926d53852c684cfe26e834373_exe_2019-07-30_09_30.txt

Jul 30th, 2019
2,267
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 9.03 KB | None | 0 0
  1.  
  2. * MalFamily: "NetWire"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_3a6d508b889744582e491c00335c0146.exe"
  7. * File Size: 1119232
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "03cc1c1ecb9dd74046e7d946ce87a63bde852a7678705de0c61cdbeda1e9e11e"
  10. * MD5: "3a6d508b889744582e491c00335c0146"
  11. * SHA1: "98b16698d5b89fe823bac3d57dd823b5ba0e0ed3"
  12. * SHA512: "475970c52270afb9cbcb1dddac03264196c5a47e487b7ab34554ce6105f1e1705f6ebe30a16c8f59aef976a4199f5c6ce9a5b3725ea21df8dc63b402a157e83c"
  13. * CRC32: "FC21F48F"
  14. * SSDEEP: "24576:rGkzpSn5ydgh2Fck3B/jVgFr70PqRnwLvkGhBoT1oZI3:akzpS55hs3B/jVgFrHuzkjT1oZI3"
  15.  
  16. * Process Execution:
  17. "Exes_3a6d508b889744582e491c00335c0146.exe",
  18. "nslookup.exe",
  19. "svchost.exe"
  20.  
  21.  
  22. * Executed Commands:
  23. "\"C:\\Windows\\System32\\nslookup.exe\""
  24.  
  25.  
  26. * Signatures Detected:
  27.  
  28. "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
  29. "Details":
  30.  
  31. "IP": "5.252.176.94:80"
  32.  
  33.  
  34.  
  35.  
  36. "Description": "Creates RWX memory",
  37. "Details":
  38.  
  39.  
  40. "Description": "Installs itself for autorun at Windows startup",
  41. "Details":
  42.  
  43. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\ahdyzuap.exe"
  44.  
  45.  
  46. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\bfhost.lnk"
  47.  
  48.  
  49. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\bfhost.lnk"
  50.  
  51.  
  52.  
  53.  
  54. "Description": "File has been identified by 43 Antiviruses on VirusTotal as malicious",
  55. "Details":
  56.  
  57. "MicroWorld-eScan": "Trojan.GenericKD.41509578"
  58.  
  59.  
  60. "FireEye": "Generic.mg.3a6d508b88974458"
  61.  
  62.  
  63. "McAfee": "Artemis!3A6D508B8897"
  64.  
  65.  
  66. "AegisLab": "Trojan.Win32.Yakes.4!c"
  67.  
  68.  
  69. "Alibaba": "Trojan:Win32/Yakes.4f481288"
  70.  
  71.  
  72. "K7GW": "Trojan ( 005538ed1 )"
  73.  
  74.  
  75. "Arcabit": "Trojan.Generic.D27962CA"
  76.  
  77.  
  78. "Invincea": "heuristic"
  79.  
  80.  
  81. "Symantec": "Trojan.Gen.MBT"
  82.  
  83.  
  84. "APEX": "Malicious"
  85.  
  86.  
  87. "Paloalto": "generic.ml"
  88.  
  89.  
  90. "Kaspersky": "Trojan.Win32.Yakes.yvqe"
  91.  
  92.  
  93. "BitDefender": "Trojan.GenericKD.41509578"
  94.  
  95.  
  96. "Avast": "Win32:Trojan-gen"
  97.  
  98.  
  99. "Tencent": "Win32.Trojan.Yakes.Lkxx"
  100.  
  101.  
  102. "Ad-Aware": "Trojan.GenericKD.41509578"
  103.  
  104.  
  105. "Emsisoft": "Trojan.GenericKD.41509578 (B)"
  106.  
  107.  
  108. "F-Secure": "Trojan.TR/Kryptik.ajylq"
  109.  
  110.  
  111. "DrWeb": "Trojan.Inject3.21262"
  112.  
  113.  
  114. "McAfee-GW-Edition": "BehavesLike.Win32.Generic.tm"
  115.  
  116.  
  117. "Trapmine": "suspicious.low.ml.score"
  118.  
  119.  
  120. "Sophos": "Mal/Generic-S"
  121.  
  122.  
  123. "SentinelOne": "DFI - Suspicious PE"
  124.  
  125.  
  126. "Avira": "TR/Kryptik.ajylq"
  127.  
  128.  
  129. "MAX": "malware (ai score=99)"
  130.  
  131.  
  132. "Antiy-AVL": "Trojan/Win32.Yakes"
  133.  
  134.  
  135. "Microsoft": "PWS:Win32/Banker.UD!bit"
  136.  
  137.  
  138. "Endgame": "malicious (high confidence)"
  139.  
  140.  
  141. "ZoneAlarm": "Trojan.Win32.Yakes.yvqe"
  142.  
  143.  
  144. "GData": "Trojan.GenericKD.41509578"
  145.  
  146.  
  147. "AhnLab-V3": "Malware/Win32.Generic.C3357688"
  148.  
  149.  
  150. "Acronis": "suspicious"
  151.  
  152.  
  153. "ALYac": "Trojan.GenericKD.41509578"
  154.  
  155.  
  156. "Cylance": "Unsafe"
  157.  
  158.  
  159. "ESET-NOD32": "a variant of Win32/GenKryptik.DOCM"
  160.  
  161.  
  162. "TrendMicro-HouseCall": "TROJ_GEN.R002H0CGR19"
  163.  
  164.  
  165. "Rising": "[email protected] (RDMK:0uKwEoP21EvbdV1xwcbeXw)"
  166.  
  167.  
  168. "Ikarus": "Trojan.Win32.Krypt"
  169.  
  170.  
  171. "Webroot": "W32.Trojan.Gen"
  172.  
  173.  
  174. "AVG": "Win32:Trojan-gen"
  175.  
  176.  
  177. "Panda": "Trj/GdSda.A"
  178.  
  179.  
  180. "CrowdStrike": "win/malicious_confidence_60% (W)"
  181.  
  182.  
  183. "Qihoo-360": "Win32/Trojan.b04"
  184.  
  185.  
  186.  
  187.  
  188. "Description": "Creates a copy of itself",
  189. "Details":
  190.  
  191. "copy": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\ahdyzuap.exe"
  192.  
  193.  
  194.  
  195.  
  196.  
  197. * Started Service:
  198.  
  199. * Mutexes:
  200.  
  201. * Modified Files:
  202. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\bfhost.lnk",
  203. "C:\\Users\\user\\AppData\\Roaming\\Adobe\\Flash Player\\Services\\Frame Host\\fhost.exe"
  204.  
  205.  
  206. * Deleted Files:
  207. "C:\\Windows\\SysWOW64\\nslookup.exe"
  208.  
  209.  
  210. * Modified Registry Keys:
  211.  
  212. * Deleted Registry Keys:
  213.  
  214. * DNS Communications:
  215.  
  216. * Domains:
  217.  
  218. * Network Communication - ICMP:
  219.  
  220. "src": "185.30.98.6",
  221. "dst": "169.254.255.254
  222. "type": 3,
  223. "data": ""
  224.  
  225.  
  226. "src": "185.30.98.6",
  227. "dst": "169.254.255.254
  228. "type": 3,
  229. "data": ""
  230.  
  231.  
  232. "src": "185.30.98.6",
  233. "dst": "169.254.255.254
  234. "type": 3,
  235. "data": ""
  236.  
  237.  
  238. "src": "185.30.98.6",
  239. "dst": "169.254.255.254
  240. "type": 3,
  241. "data": ""
  242.  
  243.  
  244. "src": "185.30.98.6",
  245. "dst": "169.254.255.254
  246. "type": 3,
  247. "data": ""
  248.  
  249.  
  250. "src": "185.30.98.6",
  251. "dst": "169.254.255.254
  252. "type": 3,
  253. "data": ""
  254.  
  255.  
  256. "src": "185.30.98.6",
  257. "dst": "169.254.255.254
  258. "type": 3,
  259. "data": ""
  260.  
  261.  
  262. "src": "185.30.98.6",
  263. "dst": "169.254.255.254
  264. "type": 3,
  265. "data": ""
  266.  
  267.  
  268. "src": "185.30.98.6",
  269. "dst": "169.254.255.254
  270. "type": 3,
  271. "data": ""
  272.  
  273.  
  274. "src": "185.30.98.6",
  275. "dst": "169.254.255.254
  276. "type": 3,
  277. "data": ""
  278.  
  279.  
  280. "src": "185.30.98.6",
  281. "dst": "169.254.255.254
  282. "type": 3,
  283. "data": ""
  284.  
  285.  
  286. "src": "185.30.98.6",
  287. "dst": "169.254.255.254
  288. "type": 3,
  289. "data": ""
  290.  
  291.  
  292. "src": "185.30.98.6",
  293. "dst": "169.254.255.254
  294. "type": 3,
  295. "data": ""
  296.  
  297.  
  298. "src": "185.30.98.6",
  299. "dst": "169.254.255.254
  300. "type": 3,
  301. "data": ""
  302.  
  303.  
  304. "src": "185.30.98.6",
  305. "dst": "169.254.255.254
  306. "type": 3,
  307. "data": ""
  308.  
  309.  
  310. "src": "185.30.98.6",
  311. "dst": "169.254.255.254
  312. "type": 3,
  313. "data": ""
  314.  
  315.  
  316. "src": "185.30.98.6",
  317. "dst": "169.254.255.254
  318. "type": 3,
  319. "data": ""
  320.  
  321.  
  322. "src": "185.30.98.6",
  323. "dst": "169.254.255.254
  324. "type": 3,
  325. "data": ""
  326.  
  327.  
  328. "src": "185.30.98.6",
  329. "dst": "169.254.255.254
  330. "type": 3,
  331. "data": ""
  332.  
  333.  
  334. "src": "185.30.98.6",
  335. "dst": "169.254.255.254
  336. "type": 3,
  337. "data": ""
  338.  
  339.  
  340. "src": "185.30.98.6",
  341. "dst": "169.254.255.254
  342. "type": 3,
  343. "data": ""
  344.  
  345.  
  346. "src": "185.30.98.6",
  347. "dst": "169.254.255.254
  348. "type": 3,
  349. "data": ""
  350.  
  351.  
  352. "src": "185.30.98.6",
  353. "dst": "169.254.255.254
  354. "type": 3,
  355. "data": ""
  356.  
  357.  
  358. "src": "185.30.98.6",
  359. "dst": "169.254.255.254
  360. "type": 3,
  361. "data": ""
  362.  
  363.  
  364. "src": "185.30.98.6",
  365. "dst": "169.254.255.254
  366. "type": 3,
  367. "data": ""
  368.  
  369.  
  370. "src": "185.30.98.6",
  371. "dst": "169.254.255.254
  372. "type": 3,
  373. "data": ""
  374.  
  375.  
  376. "src": "185.30.98.6",
  377. "dst": "169.254.255.254
  378. "type": 3,
  379. "data": ""
  380.  
  381.  
  382. "src": "185.30.98.6",
  383. "dst": "169.254.255.254
  384. "type": 3,
  385. "data": ""
  386.  
  387.  
  388. "src": "185.30.98.6",
  389. "dst": "169.254.255.254
  390. "type": 3,
  391. "data": ""
  392.  
  393.  
  394. "src": "185.30.98.6",
  395. "dst": "169.254.255.254
  396. "type": 3,
  397. "data": ""
  398.  
  399.  
  400.  
  401. * Network Communication - HTTP:
  402.  
  403. * Network Communication - SMTP:
  404.  
  405. * Network Communication - Hosts:
  406.  
  407. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment