Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Emotet"
- * MalScore: 10.0
- * File Name: "Exes_3a9868788c609828c155ed449d86b9d0.exe"
- * File Size: 1489920
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "299233458cd5b31c1c713b57dfe71be8bb128e04b03a9fc25a765237c5b6f2aa"
- * MD5: "3a9868788c609828c155ed449d86b9d0"
- * SHA1: "6fc102a1dde9ce403607d1751fd2c4301f0d8f89"
- * SHA512: "dc11e1db3b76b8c80558f06a4301032875eb3302263d78edff1143b8f7b12f0f4b25b8964e9b6d2c23cb1c840227f507e97a502e88ba7e3c90fe8d5631240d54"
- * CRC32: "D48653A9"
- * SSDEEP: "24576:NXrKaMKciX/82A/JhHJNHKePMqRUQBwtBYerGrCfQpdJWq25IBlSBK4:5Kwl8F/J5nH5zf+dpmU"
- * Process Execution:
- "Exes_3a9868788c609828c155ed449d86b9d0.exe",
- "Isass.exe",
- "schtasks.exe",
- "schtasks.exe",
- "cmd.exe",
- "cscript.exe",
- "Isass.exe",
- "schtasks.exe",
- "schtasks.exe",
- "cmd.exe",
- "cscript.exe",
- "cmd.exe",
- "taskkill.exe",
- "svchost.exe",
- "taskeng.exe",
- "wscript.exe",
- "cmd.exe",
- "powershell.exe",
- "Isass.exe",
- "schtasks.exe",
- "schtasks.exe",
- "cmd.exe",
- "cscript.exe",
- "taskeng.exe",
- "Isass.exe",
- "schtasks.exe",
- "schtasks.exe",
- "cmd.exe",
- "cscript.exe",
- "Isass.exe",
- "schtasks.exe",
- "schtasks.exe",
- "cmd.exe",
- "cscript.exe",
- "Isass.exe",
- "schtasks.exe",
- "schtasks.exe",
- "cmd.exe",
- "cscript.exe",
- "Isass.exe",
- "schtasks.exe",
- "schtasks.exe",
- "cmd.exe",
- "cscript.exe",
- "Isass.exe",
- "schtasks.exe",
- "schtasks.exe",
- "cmd.exe",
- "cscript.exe",
- "Isass.exe",
- "schtasks.exe",
- "schtasks.exe",
- "cmd.exe",
- "cscript.exe",
- "svchost.exe",
- "WmiPrvSE.exe",
- "WmiPrvSE.exe",
- "WMIADAP.exe"
- * Executed Commands:
- "C:\\ProgramData\\MicrosoftCorporation\\Windows\\System32\\Isass.exe ",
- "C:\\Windows\\System32\\cmd.exe /c taskkill /im Exes_3a9868788c609828c155ed449d86b9d0.exe /f & erase C:\\Users\\user\\AppData\\Local\\Temp\\Exes_3a9868788c609828c155ed449d86b9d0.exe & exit",
- "schtasks.exe /Create /SC MINUTE /MO 30 /TN \"Windows_Antimalware_Host\" /TR \"C:\\ProgramData\\WindowsAppCertification\\checker.vbs\" /F",
- "schtasks.exe /Create /SC MINUTE /MO 5 /TN \"Windows_Antimalware_Host_Systm\" /TR \"C:\\ProgramData\\MicrosoftCorporation\\Windows\\System32\\Isass.exe\" /F",
- "C:\\Windows\\System32\\cmd.exe /c echo Set oWS = WScript.CreateObject(\"WScript.Shell\") > CreateShortcut.vbs & echo sLinkFile = \"%USERPROFILE%\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Isass.lnk\" >> CreateShortcut.vbs & echo Set oLink = oWS.CreateShortcut(sLinkFile) >> CreateShortcut.vbs & echo oLink.TargetPath = \"C:\\ProgramData\\MicrosoftCorporation\\Windows\\System32\\Isass.exe\" >> CreateShortcut.vbs & echo oLink.Save >> CreateShortcut.vbs & cscript CreateShortcut.vbs & del CreateShortcut.vbs",
- "taskkill /im Exes_3a9868788c609828c155ed449d86b9d0.exe /f",
- "cscript CreateShortcut.vbs",
- "taskeng.exe 5BEFDD64-06BD-4B7E-A05C-8D7E9D1F61C9 S-1-5-21-0000000000-0000000000-0000000000-1000:Host\\user:Interactive:1",
- "taskeng.exe 0626EAAF-54BA-4F58-BD44-A8A7F8D937BC S-1-5-21-0000000000-0000000000-0000000000-1000:Host\\user:Interactive:1",
- "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding",
- "C:\\Windows\\system32\\wbem\\wmiprvse.exe -Embedding",
- "C:\\Windows\\System32\\WScript.exe \"C:\\ProgramData\\WindowsAppCertification\\checker.vbs\"",
- "C:\\ProgramData\\MicrosoftCorporation\\Windows\\System32\\Isass.exe",
- "\"C:\\ProgramData\\WindowsAppCertification\\cert.cmd\"",
- "C:\\ProgramData\\WindowsAppCertification\\cert.cmd ",
- "powershell -WindowStyle Hidden -ExecutionPolicy Bypass -NoP -file C:\\ProgramData\\WindowsAppCertification\\WindowHelperStorageHostSystemThread.ps1"
- * Signatures Detected:
- "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
- "Details":
- "IP": "37.1.206.48:80"
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Possible date expiration check, exits too soon after checking local time",
- "Details":
- "process": "Exes_3a9868788c609828c155ed449d86b9d0.exe, PID 744"
- "Description": "Detected script timer window indicative of sleep style evasion",
- "Details":
- "Window": "WSH-Timer"
- "Window": "WSH-Timer"
- "Description": "Expresses interest in specific running processes",
- "Details":
- "process": "System"
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: cscript.exe, pid: 2972, offset: 0x00000000, length: 0x00000040"
- "self_read": "process: cscript.exe, pid: 2972, offset: 0x000000e8, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 2972, offset: 0x000001e0, length: 0x00000078"
- "self_read": "process: cscript.exe, pid: 2972, offset: 0x00015e00, length: 0x00000020"
- "self_read": "process: cscript.exe, pid: 2972, offset: 0x00015e58, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 2972, offset: 0x00015f50, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 2972, offset: 0x00016110, length: 0x00000010"
- "self_read": "process: cscript.exe, pid: 2972, offset: 0x00016230, length: 0x00000012"
- "self_read": "process: wscript.exe, pid: 2420, offset: 0x00000000, length: 0x00000040"
- "self_read": "process: wscript.exe, pid: 2420, offset: 0x000000f8, length: 0x00000018"
- "self_read": "process: wscript.exe, pid: 2420, offset: 0x00000200, length: 0x7fe00000028"
- "self_read": "process: wscript.exe, pid: 2420, offset: 0x0001f200, length: 0x00000020"
- "self_read": "process: wscript.exe, pid: 2420, offset: 0x0001f258, length: 0x00000018"
- "self_read": "process: wscript.exe, pid: 2420, offset: 0x0001f3a8, length: 0x7fe00000018"
- "self_read": "process: wscript.exe, pid: 2420, offset: 0x0001f670, length: 0x00000010"
- "self_read": "process: wscript.exe, pid: 2420, offset: 0x0001f840, length: 0x00000012"
- "self_read": "process: wscript.exe, pid: 2420, offset: 0x7fe00000228, length: 0x7fe00000078"
- "self_read": "process: cscript.exe, pid: 2124, offset: 0x00000000, length: 0x00000040"
- "self_read": "process: cscript.exe, pid: 2124, offset: 0x000000e8, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 2124, offset: 0x000001e0, length: 0x00000078"
- "self_read": "process: cscript.exe, pid: 2124, offset: 0x00015e00, length: 0x00000020"
- "self_read": "process: cscript.exe, pid: 2124, offset: 0x00015e58, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 2124, offset: 0x00015f50, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 2124, offset: 0x00016110, length: 0x00000010"
- "self_read": "process: cscript.exe, pid: 2124, offset: 0x00016230, length: 0x00000012"
- "self_read": "process: cscript.exe, pid: 856, offset: 0x00000000, length: 0x00000040"
- "self_read": "process: cscript.exe, pid: 856, offset: 0x000000e8, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 856, offset: 0x000001e0, length: 0x00000078"
- "self_read": "process: cscript.exe, pid: 856, offset: 0x00015e00, length: 0x00000020"
- "self_read": "process: cscript.exe, pid: 856, offset: 0x00015e58, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 856, offset: 0x00015f50, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 856, offset: 0x00016110, length: 0x00000010"
- "self_read": "process: cscript.exe, pid: 856, offset: 0x00016230, length: 0x00000012"
- "self_read": "process: cscript.exe, pid: 1880, offset: 0x00000000, length: 0x00000040"
- "self_read": "process: cscript.exe, pid: 1880, offset: 0x000000e8, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 1880, offset: 0x000001e0, length: 0x00000078"
- "self_read": "process: cscript.exe, pid: 1880, offset: 0x00015e00, length: 0x00000020"
- "self_read": "process: cscript.exe, pid: 1880, offset: 0x00015e58, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 1880, offset: 0x00015f50, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 1880, offset: 0x00016110, length: 0x00000010"
- "self_read": "process: cscript.exe, pid: 1880, offset: 0x00016230, length: 0x00000012"
- "self_read": "process: cscript.exe, pid: 2416, offset: 0x00000000, length: 0x00000040"
- "self_read": "process: cscript.exe, pid: 2416, offset: 0x000000e8, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 2416, offset: 0x000001e0, length: 0x00000078"
- "self_read": "process: cscript.exe, pid: 2416, offset: 0x00015e00, length: 0x00000020"
- "self_read": "process: cscript.exe, pid: 2416, offset: 0x00015e58, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 2416, offset: 0x00015f50, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 2416, offset: 0x00016110, length: 0x00000010"
- "self_read": "process: cscript.exe, pid: 2416, offset: 0x00016230, length: 0x00000012"
- "self_read": "process: cscript.exe, pid: 1480, offset: 0x00000000, length: 0x00000040"
- "self_read": "process: cscript.exe, pid: 1480, offset: 0x000000e8, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 1480, offset: 0x000001e0, length: 0x00000078"
- "self_read": "process: cscript.exe, pid: 1480, offset: 0x00015e00, length: 0x00000020"
- "self_read": "process: cscript.exe, pid: 1480, offset: 0x00015e58, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 1480, offset: 0x00015f50, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 1480, offset: 0x00016110, length: 0x00000010"
- "self_read": "process: cscript.exe, pid: 1480, offset: 0x00016230, length: 0x00000012"
- "self_read": "process: cscript.exe, pid: 2580, offset: 0x00000000, length: 0x00000040"
- "self_read": "process: cscript.exe, pid: 2580, offset: 0x000000e8, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 2580, offset: 0x000001e0, length: 0x00000078"
- "self_read": "process: cscript.exe, pid: 2580, offset: 0x00015e00, length: 0x00000020"
- "self_read": "process: cscript.exe, pid: 2580, offset: 0x00015e58, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 2580, offset: 0x00015f50, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 2580, offset: 0x00016110, length: 0x00000010"
- "self_read": "process: cscript.exe, pid: 2580, offset: 0x00016230, length: 0x00000012"
- "self_read": "process: cscript.exe, pid: 1804, offset: 0x00000000, length: 0x00000040"
- "self_read": "process: cscript.exe, pid: 1804, offset: 0x000000e8, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 1804, offset: 0x000001e0, length: 0x00000078"
- "self_read": "process: cscript.exe, pid: 1804, offset: 0x00015e00, length: 0x00000020"
- "self_read": "process: cscript.exe, pid: 1804, offset: 0x00015e58, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 1804, offset: 0x00015f50, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 1804, offset: 0x00016110, length: 0x00000010"
- "self_read": "process: cscript.exe, pid: 1804, offset: 0x00016230, length: 0x00000012"
- "self_read": "process: cscript.exe, pid: 324, offset: 0x00000000, length: 0x00000040"
- "self_read": "process: cscript.exe, pid: 324, offset: 0x000000e8, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 324, offset: 0x000001e0, length: 0x00000078"
- "self_read": "process: cscript.exe, pid: 324, offset: 0x00015e00, length: 0x00000020"
- "self_read": "process: cscript.exe, pid: 324, offset: 0x00015e58, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 324, offset: 0x00015f50, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 324, offset: 0x00016110, length: 0x00000010"
- "self_read": "process: cscript.exe, pid: 324, offset: 0x00016230, length: 0x00000012"
- "Description": "A process created a hidden window",
- "Details":
- "Process": "Exes_3a9868788c609828c155ed449d86b9d0.exe -> C:\\ProgramData\\MicrosoftCorporation\\Windows\\System32\\Isass.exe"
- "Process": "Exes_3a9868788c609828c155ed449d86b9d0.exe -> C:\\Windows\\System32\\cmd.exe"
- "Process": "Isass.exe -> schtasks.exe"
- "Process": "Isass.exe -> schtasks.exe"
- "Process": "Isass.exe -> C:\\Windows\\System32\\cmd.exe"
- "Process": "Isass.exe -> C:\\ProgramData\\MicrosoftCorporation\\Windows\\System32\\Isass.exe"
- "Process": "wscript.exe -> C:\\ProgramData\\WindowsAppCertification\\cert.cmd"
- "Process": "Isass.exe -> schtasks.exe"
- "Process": "Isass.exe -> schtasks.exe"
- "Process": "Isass.exe -> C:\\Windows\\System32\\cmd.exe"
- "Process": "cmd.exe -> C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe"
- "Process": "Isass.exe -> schtasks.exe"
- "Process": "Isass.exe -> schtasks.exe"
- "Process": "Isass.exe -> C:\\Windows\\System32\\cmd.exe"
- "Process": "Isass.exe -> schtasks.exe"
- "Process": "Isass.exe -> schtasks.exe"
- "Process": "Isass.exe -> C:\\Windows\\System32\\cmd.exe"
- "Process": "Isass.exe -> C:\\ProgramData\\MicrosoftCorporation\\Windows\\System32\\Isass.exe"
- "Process": "Isass.exe -> schtasks.exe"
- "Process": "Isass.exe -> schtasks.exe"
- "Process": "Isass.exe -> C:\\Windows\\System32\\cmd.exe"
- "Process": "Isass.exe -> C:\\ProgramData\\MicrosoftCorporation\\Windows\\System32\\Isass.exe"
- "Process": "Isass.exe -> schtasks.exe"
- "Process": "Isass.exe -> schtasks.exe"
- "Process": "Isass.exe -> C:\\Windows\\System32\\cmd.exe"
- "Process": "Isass.exe -> C:\\ProgramData\\MicrosoftCorporation\\Windows\\System32\\Isass.exe"
- "Process": "Isass.exe -> schtasks.exe"
- "Process": "Isass.exe -> schtasks.exe"
- "Process": "Isass.exe -> C:\\Windows\\System32\\cmd.exe"
- "Process": "Isass.exe -> C:\\ProgramData\\MicrosoftCorporation\\Windows\\System32\\Isass.exe"
- "Process": "Isass.exe -> schtasks.exe"
- "Process": "Isass.exe -> schtasks.exe"
- "Process": "Isass.exe -> C:\\Windows\\System32\\cmd.exe"
- "Process": "Isass.exe -> C:\\ProgramData\\MicrosoftCorporation\\Windows\\System32\\Isass.exe"
- "Process": "Isass.exe -> schtasks.exe"
- "Process": "Isass.exe -> schtasks.exe"
- "Process": "Isass.exe -> C:\\Windows\\System32\\cmd.exe"
- "Process": "Isass.exe -> C:\\ProgramData\\MicrosoftCorporation\\Windows\\System32\\Isass.exe"
- "Description": "Drops a binary and executes it",
- "Details":
- "binary": "C:\\ProgramData\\MicrosoftCorporation\\Windows\\System32\\Isass.exe"
- "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
- "Details":
- "post_no_referer": "HTTP traffic contains a POST request with no referer header"
- "suspicious_request": "http://api2.checkingsite.site/2.0/method/checkConnection"
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://api2.checkingsite.site/2.0/method/checkConnection"
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details":
- "section": "name: \\x00 , entropy: 7.98, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00032a00, virtual_size: 0x0006c000"
- "section": "name: .rsrc, entropy: 7.43, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00001800, virtual_size: 0x00005a7a"
- "section": "name: eiljzjew, entropy: 7.92, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00136400, virtual_size: 0x00137000"
- "section": "name: jqewjwee, entropy: 7.31, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00000200, virtual_size: 0x00001000"
- "Description": "Deletes its original binary from disk",
- "Details":
- "Description": "Checks for the presence of known windows from debuggers and forensic tools",
- "Details":
- "Window": "OLLYDBG"
- "Window": "GBDYLLO"
- "Window": "pediy06"
- "Window": "FilemonClass"
- "Window": "File Monitor - Sysinternals: www.sysinternals.com"
- "Window": "PROCMON_WINDOW_CLASS"
- "Window": "Process Monitor - Sysinternals: www.sysinternals.com"
- "Window": "RegmonClass"
- "Window": "Registry Monitor - Sysinternals: www.sysinternals.com"
- "Window": "18467-41"
- "Window": "OLLYDBG"
- "Window": "GBDYLLO"
- "Window": "pediy06"
- "Window": "FilemonClass"
- "Window": "File Monitor - Sysinternals: www.sysinternals.com"
- "Window": "PROCMON_WINDOW_CLASS"
- "Window": "Process Monitor - Sysinternals: www.sysinternals.com"
- "Window": "RegmonClass"
- "Window": "Registry Monitor - Sysinternals: www.sysinternals.com"
- "Window": "18467-41"
- "Description": "A process attempted to delay the analysis task by a long amount of time.",
- "Details":
- "Process": "taskeng.exe tried to sleep 360 seconds, actually delayed analysis time by 0 seconds"
- "Process": "Isass.exe tried to sleep 4740 seconds, actually delayed analysis time by 0 seconds"
- "Process": "WmiPrvSE.exe tried to sleep 420 seconds, actually delayed analysis time by 0 seconds"
- "Description": "Attempts to execute a Living Off The Land Binary command for post exeploitation",
- "Details":
- "MITRE T1078 - schtask": "(Tactic: Execution, Persistence, Privilege Escalation)"
- "Description": "The following process appear to have been packed with Themida: Isass.exe, Exes_3a9868788c609828c155ed449d86b9d0.exe, Isass.exe, Isass.exe, Isass.exe, Isass.exe, Isass.exe, Isass.exe, Isass.exe, Isass.exe",
- "Details":
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Windows_Antimalware_Host_Syst"
- "data": "C:\\ProgramData\\MicrosoftCorporation\\Windows\\System32\\Isass.exe"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Isass.lnk"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Isass.lnk"
- "task": "schtasks.exe /Create /SC MINUTE /MO 30 /TN \"Windows_Antimalware_Host\" /TR \"C:\\ProgramData\\WindowsAppCertification\\checker.vbs\" /F"
- "Description": "Creates a hidden or system file",
- "Details":
- "file": "C:\\ProgramData\\MicrosoftCorporation"
- "file": "C:\\ProgramData\\MicrosoftCorporation\\Windows"
- "file": "C:\\ProgramData\\MicrosoftCorporation\\Windows\\System32"
- "file": "C:\\ProgramData\\WindowsAppCertification"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF2112ef2.TMP"
- "Description": "Checks for the presence of known devices from debuggers and forensic tools",
- "Details":
- "Description": "Detects the presence of Wine emulator via registry key",
- "Details":
- "Description": "File has been identified by 51 Antiviruses on VirusTotal as malicious",
- "Details":
- "Bkav": "W32.HfsAutoB."
- "MicroWorld-eScan": "Gen:Variant.Zusy.277440"
- "CAT-QuickHeal": "Trojan.Generic"
- "McAfee": "Artemis!3A9868788C60"
- "VIPRE": "Trojan.Win32.Generic!BT"
- "BitDefender": "Gen:Variant.Zusy.277440"
- "K7GW": "Trojan ( 00529ea11 )"
- "K7AntiVirus": "Trojan ( 00529ea11 )"
- "TrendMicro": "TROJ_GEN.R049C0OCD18"
- "NANO-Antivirus": "Trojan.Win32.BtcMine.eywevo"
- "Cyren": "W32/Trojan.VWER-3454"
- "Symantec": "Trojan Horse"
- "TrendMicro-HouseCall": "TROJ_GEN.R049C0OCD18"
- "Paloalto": "generic.ml"
- "ClamAV": "Win.Trojan.Emotet-6472129-0"
- "Kaspersky": "HEUR:Trojan.Win32.Generic"
- "AegisLab": "Troj.W32.Generic!c"
- "Tencent": "Win32.Trojan.Generic.Lmbg"
- "Ad-Aware": "Gen:Variant.Zusy.277440"
- "Sophos": "Mal/Generic-S"
- "F-Secure": "Gen:Variant.Zusy.277440"
- "DrWeb": "Trojan.BtcMine.1812"
- "Zillya": "Trojan.Packed.Win32.125001"
- "Invincea": "heuristic"
- "McAfee-GW-Edition": "BehavesLike.Win32.Backdoor.tc"
- "Fortinet": "W32/PossibleThreat"
- "Emsisoft": "Gen:Variant.Zusy.277440 (B)"
- "Ikarus": "Trojan.Win32.Themida"
- "Webroot": "Trojan.Spy.Emotet"
- "Avira": "TR/Crypt.TPM.zkvff"
- "MAX": "malware (ai score=98)"
- "Antiy-AVL": "Trojan/Win32.AGeneric"
- "Endgame": "malicious (high confidence)"
- "Arcabit": "Trojan.Zusy.D43BC0"
- "ZoneAlarm": "HEUR:Trojan.Win32.Generic"
- "Microsoft": "Trojan:Win32/Tiggre!rfn"
- "AhnLab-V3": "Trojan/Win32.Generic.C2418350"
- "ALYac": "Gen:Variant.Zusy.277440"
- "AVware": "Trojan.Win32.Generic!BT"
- "VBA32": "Trojan.BtcMine"
- "Cylance": "Unsafe"
- "Panda": "Trj/CI.A"
- "ESET-NOD32": "a variant of Win32/Packed.Themida.AQA"
- "Rising": "Trojan.Generic!8.C3 (CLOUD)"
- "Yandex": "Trojan.Agent!ci5cNF/xOiM"
- "SentinelOne": "static engine - malicious"
- "GData": "Gen:Variant.Zusy.277440"
- "AVG": "Win32:Malware-gen"
- "Cybereason": "malicious.88c609"
- "Avast": "Win32:Malware-gen"
- "CrowdStrike": "malicious_confidence_80% (D)"
- "Description": "Checks the version of Bios, possibly for anti-virtualization",
- "Details":
- "Description": "Detects VirtualBox using ACPI tricks",
- "Details":
- "Description": "Detects VirtualBox through the presence of a registry key",
- "Details":
- "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
- "Details":
- "target": "clamav:Win.Trojan.Emotet-6472129-0, sha256:299233458cd5b31c1c713b57dfe71be8bb128e04b03a9fc25a765237c5b6f2aa, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Emotet-6472129-0, sha256:299233458cd5b31c1c713b57dfe71be8bb128e04b03a9fc25a765237c5b6f2aa , guest_paths:C:\\ProgramData\\MicrosoftCorporation\\Windows\\System32\\Isass.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "Description": "Creates a copy of itself",
- "Details":
- "copy": "C:\\ProgramData\\MicrosoftCorporation\\Windows\\System32\\Isass.exe"
- "Description": "Anomalous binary characteristics",
- "Details":
- "anomaly": "Unprintable characters found in section name"
- * Started Service:
- * Mutexes:
- "DBWinMutex",
- "Local\\ZoneAttributeCacheCounterMutex",
- "Local\\ZonesCacheCounterMutex",
- "Local\\ZonesLockedCacheCounterMutex",
- "Global\\CLR_CASOFF_MUTEX",
- "Global\\ADAP_WMI_ENTRY",
- "Global\\RefreshRA_Mutex",
- "Global\\RefreshRA_Mutex_Lib",
- "Global\\RefreshRA_Mutex_Flag"
- * Modified Files:
- "\\??\\SICE",
- "\\??\\SIWVID",
- "\\??\\NTICE",
- "C:\\ProgramData\\MicrosoftCorporation\\Windows\\System32\\Isass.exe",
- "C:\\ProgramData\\WindowsAppCertification\\WindowHelperStorageHostSystemThread.ps1",
- "C:\\ProgramData\\WindowsAppCertification\\checker.vbs",
- "C:\\ProgramData\\WindowsAppCertification\\cert.cmd",
- "C:\\Users\\user\\AppData\\Local\\Temp\\CreateShortcut.vbs",
- "C:\\Windows\\sysnative\\Tasks\\Windows_Antimalware_Host",
- "C:\\Windows\\appcompat\\Programs\\RecentFileCache.bcf",
- "C:\\Windows\\sysnative\\Tasks\\Windows_Antimalware_Host_Systm",
- "C:\\Windows\\SoftwareDistribution\\DataStore\\DataStore.edb",
- "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edb.chk",
- "\\??\\PIPE\\srvsvc",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Isass.lnk",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
- "C:\\Windows\\sysnative\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\N4LPOFHOFJOSIAOUCWP7.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF2112ef2.TMP",
- "C:\\Windows\\SysWOW64\\CreateShortcut.vbs",
- "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl_new.h",
- "\\??\\WMIDataDevice"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_3a9868788c609828c155ed449d86b9d0.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\CreateShortcut.vbs",
- "C:\\Windows\\Tasks\\Windows_Antimalware_Host.job",
- "C:\\Windows\\Tasks\\Windows_Antimalware_Host_Systm.job",
- "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edbtmp.log",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF2112ef2.TMP",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1032.34681343",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1032.34681359",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1032.34681359",
- "C:\\Windows\\System32\\CreateShortcut.vbs"
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Windows_Antimalware_Host_Syst",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\2C551989-1171-4867-83CD-A7BFD5CD4D6A\\Path",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\2C551989-1171-4867-83CD-A7BFD5CD4D6A\\Hash",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Windows_Antimalware_Host\\Id",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Windows_Antimalware_Host\\Index",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\2C551989-1171-4867-83CD-A7BFD5CD4D6A\\Triggers",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\2C551989-1171-4867-83CD-A7BFD5CD4D6A\\DynamicInfo",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\5BEFDD64-06BD-4B7E-A05C-8D7E9D1F61C9",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\23A33C0C-CE41-4DB7-8264-3905DCBCFC10\\DynamicInfo",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Windows_Antimalware_Host_Systm\\Index",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\23A33C0C-CE41-4DB7-8264-3905DCBCFC10\\Hash",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\23A33C0C-CE41-4DB7-8264-3905DCBCFC10\\Triggers",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\0626EAAF-54BA-4F58-BD44-A8A7F8D937BC",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\5BEFDD64-06BD-4B7E-A05C-8D7E9D1F61C9\\data",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
- "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\0626EAAF-54BA-4F58-BD44-A8A7F8D937BC\\data",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\IDE\\DiskVBOX_HARDDISK___________________________1.0_____\\5&33d1638a&0&0.0.0_0-00000000-0000-0000-0000-000000000000",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\advapi32.dllMofResourceName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\en-US\\advapi32.dll.muiMofResourceName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\ACPI.sysACPIMOFResource",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\en-US\\ACPI.sys.muiACPIMOFResource",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\ndis.sysMofResourceName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\en-US\\ndis.sys.muiMofResourceName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\mssmbios.sysMofResource",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\en-US\\mssmbios.sys.muiMofResource",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\HDAudBus.sysHDAudioMofName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\en-US\\HDAudBus.sys.muiHDAudioMofName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\intelppm.sysPROCESSORWMI",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\en-US\\intelppm.sys.muiPROCESSORWMI",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\System32\\Drivers\\portcls.SYSPortclsMof",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\System32\\Drivers\\en-US\\portcls.SYS.muiPortclsMof",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\monitor.sysMonitorWMI"
- * Deleted Registry Keys:
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\Windows_Antimalware_Host.job",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\Windows_Antimalware_Host.job.fp",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\Windows_Antimalware_Host_Systm.job",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\Windows_Antimalware_Host_Systm.job.fp",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\monitor.sysMonitorWMI"
- * DNS Communications:
- "type": "A",
- "request": "api2.checkingsite.site",
- "answers":
- "data": "checkingsite.site",
- "type": "CNAME"
- "data": "37.1.206.48",
- "type": "A"
- "type": "A",
- "request": "api.hdjahw223aw.site",
- "answers":
- "data": "",
- "type": "NXDOMAIN"
- "type": "A",
- "request": "api.opndfnsh22afd.site",
- "answers":
- "data": "",
- "type": "NXDOMAIN"
- "type": "A",
- "request": "api.pojbhjdsg223dd.online",
- "answers":
- "data": "",
- "type": "NXDOMAIN"
- "type": "A",
- "request": "api.ewjdfbhe2jdg.online",
- "answers":
- "data": "",
- "type": "NXDOMAIN"
- * Domains:
- "ip": "",
- "domain": "api.pojbhjdsg223dd.online"
- "ip": "",
- "domain": "api.opndfnsh22afd.site"
- "ip": "",
- "domain": "api.hdjahw223aw.site"
- "ip": "",
- "domain": "api.ewjdfbhe2jdg.online"
- "ip": "37.1.206.48",
- "domain": "api2.checkingsite.site"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 26,
- "body": "",
- "uri": "http://api2.checkingsite.site/2.0/method/checkConnection",
- "user-agent": "Mozilla/5.0 (Windows NT 6.1) Rarog/5.0",
- "method": "POST",
- "host": "api2.checkingsite.site",
- "version": "1.1",
- "path": "/2.0/method/checkConnection",
- "data": "POST /2.0/method/checkConnection HTTP/1.1\r\nConnection: Keep-Alive\r\nContent-Type: application/x-www-form-urlencoded\r\nUser-Agent: Mozilla/5.0 (Windows NT 6.1) Rarog/5.0\r\nContent-Length: 0\r\nHost: api2.checkingsite.site\r\n\r\n",
- "port": 80
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Add Comment
Please, Sign In to add comment