paladin316

AgentTesla_44273c17f687f6b76c3afbb5be38932b_exe_2019-07-09_09_30.txt

Jul 9th, 2019
2,143
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.04 KB | None | 0 0
  1.  
  2. * MalFamily: "Malicious"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "AgentTesla_44273c17f687f6b76c3afbb5be38932b.exe"
  7. * File Size: 573440
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "df0b0985285aa11c107ecb0d3f4bc0964341ba1eb1bcd5a835d7c01ec780e1ab"
  10. * MD5: "44273c17f687f6b76c3afbb5be38932b"
  11. * SHA1: "3bc33013f4190f3b6c456d96ba35a4090a9e8843"
  12. * SHA512: "6ec1b201ceeb2260849020f0ca5989492e6438204b7cf42270589f2e89fe11fb92e553011736bfc3193b3cd7beca5e48a9c4c9cbda5bef9feb507e9fb4fcf73a"
  13. * CRC32: "F33AF81F"
  14. * SSDEEP: "6144:gU2d/baX4seZx3NvY3LcgljX7FMiL4NC7Im4WeMEp7gPZNzyheRddcwrJnc6lVoF:Md/2GrNgjjpMiL4N9OaOGhEdGt6VoMo"
  15.  
  16. * Process Execution:
  17. "AgentTesla_44273c17f687f6b76c3afbb5be38932b.exe"
  18.  
  19.  
  20. * Executed Commands:
  21.  
  22. * Signatures Detected:
  23.  
  24. "Description": "Creates RWX memory",
  25. "Details":
  26.  
  27.  
  28. "Description": "Reads data out of its own binary image",
  29. "Details":
  30.  
  31. "self_read": "process: AgentTesla_44273c17f687f6b76c3afbb5be38932b.exe, pid: 2952, offset: 0x00000000, length: 0x0008c000"
  32.  
  33.  
  34.  
  35.  
  36. "Description": "File has been identified by 18 Antiviruses on VirusTotal as malicious",
  37. "Details":
  38.  
  39. "FireEye": "Generic.mg.44273c17f687f6b7"
  40.  
  41.  
  42. "CrowdStrike": "win/malicious_confidence_100% (W)"
  43.  
  44.  
  45. "Invincea": "heuristic"
  46.  
  47.  
  48. "APEX": "Malicious"
  49.  
  50.  
  51. "Paloalto": "generic.ml"
  52.  
  53.  
  54. "Kaspersky": "UDS:DangerousObject.Multi.Generic"
  55.  
  56.  
  57. "McAfee-GW-Edition": "BehavesLike.Win32.Fareit.hh"
  58.  
  59.  
  60. "Trapmine": "malicious.moderate.ml.score"
  61.  
  62.  
  63. "Microsoft": "Trojan:Win32/Wacatac.B!ml"
  64.  
  65.  
  66. "Endgame": "malicious (high confidence)"
  67.  
  68.  
  69. "ZoneAlarm": "UDS:DangerousObject.Multi.Generic"
  70.  
  71.  
  72. "AhnLab-V3": "Win-Trojan/VBKrypt.RP09"
  73.  
  74.  
  75. "McAfee": "RDN/Generic.dx"
  76.  
  77.  
  78. "Cylance": "Unsafe"
  79.  
  80.  
  81. "ESET-NOD32": "a variant of Win32/GenKryptik.DMUB"
  82.  
  83.  
  84. "Rising": "Trojan.Wacatac!8.10C01 (CLOUD)"
  85.  
  86.  
  87. "SentinelOne": "DFI - Malicious PE"
  88.  
  89.  
  90. "Cybereason": "malicious.3f4190"
  91.  
  92.  
  93.  
  94.  
  95.  
  96. * Started Service:
  97.  
  98. * Mutexes:
  99.  
  100. * Modified Files:
  101. "C:\\Users\\user\\subfolder\\filename.exe",
  102. "C:\\Users\\user\\subfolder\\filename.vbs"
  103.  
  104.  
  105. * Deleted Files:
  106.  
  107. * Modified Registry Keys:
  108.  
  109. * Deleted Registry Keys:
  110.  
  111. * DNS Communications:
  112.  
  113. * Domains:
  114.  
  115. * Network Communication - ICMP:
  116.  
  117. * Network Communication - HTTP:
  118.  
  119. * Network Communication - SMTP:
  120.  
  121. * Network Communication - Hosts:
  122.  
  123. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment