Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Skillis"
- * MalScore: 10.0
- * File Name: "Exes_e75be7590e86df92f785d01ed83b66bb.exe"
- * File Size: 1157638
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed"
- * SHA256: "e6bdf8d61d47e762c1c093967df8ffaefc5d495bc30deb131cbfe838fbcdb717"
- * MD5: "e75be7590e86df92f785d01ed83b66bb"
- * SHA1: "227b963f82e54c3ea95ebcf168ed2742f6e3ee9c"
- * SHA512: "14779e133a91945b305e3b29c763a7daee39cc1db8f2488eeb07124788953d3274bba199368004d8889b5329cf94ae10d56634fd8a32a500d8244f217bf9b228"
- * CRC32: "CA324A8A"
- * SSDEEP: "24576:e6eLO+MRifC8t1Fw0AOL8AWaq060awACzxG7OKZ:/eLA0aGFw0JdWaqhfwAC+OU"
- * Process Execution:
- "Exes_e75be7590e86df92f785d01ed83b66bb.exe",
- "cmd.exe",
- "mode.com",
- "PING.EXE",
- "cmd.exe",
- "cscript.exe",
- "cmd.exe"
- * Executed Commands:
- "bat2exe.bat ",
- "C:\\Windows\\system32\\mode.com MODE 80,50",
- "PING 127.0.0.1 -w 1 -n 1",
- "C:\\Windows\\system32\\cmd.exe /c cscript //nologo bin\\browse.vbs",
- "C:\\Windows\\system32\\cmd.exe /c dir /b /OD \"C:\\Users\\user\\Desktop\\*.bat\" \"C:\\Users\\user\\Desktop\\*.cmd\"",
- "cscript //nologo bin\\browse.vbs"
- * Signatures Detected:
- "Description": "Possible date expiration check, exits too soon after checking local time",
- "Details":
- "process": "mode.com, PID 2468"
- "Description": "Detected script timer window indicative of sleep style evasion",
- "Details":
- "Window": "WSH-Timer"
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: Exes_e75be7590e86df92f785d01ed83b66bb.exe, pid: 1764, offset: 0x00000000, length: 0x00029d47"
- "self_read": "process: Exes_e75be7590e86df92f785d01ed83b66bb.exe, pid: 1764, offset: 0x00000000, length: 0x0002fff7"
- "self_read": "process: Exes_e75be7590e86df92f785d01ed83b66bb.exe, pid: 1764, offset: 0x00000000, length: 0x001000e1"
- "self_read": "process: Exes_e75be7590e86df92f785d01ed83b66bb.exe, pid: 1764, offset: 0x00029cac, length: 0x000f0d5a"
- "self_read": "process: cscript.exe, pid: 1444, offset: 0x00000000, length: 0x00000040"
- "self_read": "process: cscript.exe, pid: 1444, offset: 0x000000e8, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 1444, offset: 0x000001e0, length: 0x00000078"
- "self_read": "process: cscript.exe, pid: 1444, offset: 0x00015e00, length: 0x00000020"
- "self_read": "process: cscript.exe, pid: 1444, offset: 0x00015e58, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 1444, offset: 0x00015f50, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 1444, offset: 0x00016110, length: 0x00000010"
- "self_read": "process: cscript.exe, pid: 1444, offset: 0x00016230, length: 0x00000012"
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details":
- "section": "name: UPX1, entropy: 7.67, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x0000d400, virtual_size: 0x0000e000"
- "Description": "The executable is compressed using UPX",
- "Details":
- "section": "name: UPX0, entropy: 0.00, characteristics: IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00000000, virtual_size: 0x00012000"
- "Description": "Attempts to execute a Living Off The Land Binary command for post exeploitation",
- "Details":
- "MITRE T1064 - cscript": "(Tactic: Defense Evasion, Execution)"
- "Description": "File has been identified by 17 Antiviruses on VirusTotal as malicious",
- "Details":
- "CAT-QuickHeal": "Trojan.Skillis"
- "Cylance": "Unsafe"
- "CrowdStrike": "win/malicious_confidence_100% (W)"
- "TrendMicro-HouseCall": "TROJ_GEN.R002H07C119"
- "Kaspersky": "Trojan.Win32.Skillis.bjjt"
- "Tencent": "Win32.Trojan.Skillis.Ajvf"
- "F-Secure": "Heuristic.HEUR/AGEN.1033686"
- "Webroot": "Trojan.Dropper.Gen"
- "Avira": "HEUR/AGEN.1033686"
- "AegisLab": "Trojan.Win32.Skillis.4!c"
- "ZoneAlarm": "Trojan.Win32.Skillis.bjjt"
- "Sophos": "Mal/Generic-S"
- "VBA32": "Trojan.Skillis"
- "TACHYON": "Trojan/W32.Skillis.1197062"
- "Rising": "Trojan.Skillis!8.353 (CLOUD)"
- "Yandex": "Trojan.Agent!1T6/uINIYTs"
- "SentinelOne": "static engine - malicious"
- * Started Service:
- * Mutexes:
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1",
- "DefaultTabtip-MainUI"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\7ZipSfx.000\\bat2exe.bat",
- "C:\\Users\\user\\AppData\\Local\\Temp\\7ZipSfx.000\\bin\\browse.vbs",
- "C:\\Users\\user\\AppData\\Local\\Temp\\7ZipSfx.000\\bin\\7z.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\7ZipSfx.000\\bin\\choice.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\7ZipSfx.000\\bin\\res.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\7ZipSfx.000\\bin\\upx.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\7ZipSfx.000\\bin\\7z.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\7ZipSfx.000\\bin\\7ZSD_LZMAi.sfx",
- "\\??\\NUL",
- "C:\\Users\\user\\AppData\\Local\\Temp\\BAT2EXE_WS.ini",
- "\\Device\\NamedPipe",
- "\\??\\PIPE\\samr"
- * Deleted Files:
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browse For Folder Width",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browse For Folder Height"
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment