paladin316

Exes_e75be7590e86df92f785d01ed83b66bb_exe_2019-07-24_22_30.txt

Jul 24th, 2019
2,148
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.08 KB | None | 0 0
  1.  
  2. * MalFamily: "Skillis"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_e75be7590e86df92f785d01ed83b66bb.exe"
  7. * File Size: 1157638
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed"
  9. * SHA256: "e6bdf8d61d47e762c1c093967df8ffaefc5d495bc30deb131cbfe838fbcdb717"
  10. * MD5: "e75be7590e86df92f785d01ed83b66bb"
  11. * SHA1: "227b963f82e54c3ea95ebcf168ed2742f6e3ee9c"
  12. * SHA512: "14779e133a91945b305e3b29c763a7daee39cc1db8f2488eeb07124788953d3274bba199368004d8889b5329cf94ae10d56634fd8a32a500d8244f217bf9b228"
  13. * CRC32: "CA324A8A"
  14. * SSDEEP: "24576:e6eLO+MRifC8t1Fw0AOL8AWaq060awACzxG7OKZ:/eLA0aGFw0JdWaqhfwAC+OU"
  15.  
  16. * Process Execution:
  17. "Exes_e75be7590e86df92f785d01ed83b66bb.exe",
  18. "cmd.exe",
  19. "mode.com",
  20. "PING.EXE",
  21. "cmd.exe",
  22. "cscript.exe",
  23. "cmd.exe"
  24.  
  25.  
  26. * Executed Commands:
  27. "bat2exe.bat ",
  28. "C:\\Windows\\system32\\mode.com MODE 80,50",
  29. "PING 127.0.0.1 -w 1 -n 1",
  30. "C:\\Windows\\system32\\cmd.exe /c cscript //nologo bin\\browse.vbs",
  31. "C:\\Windows\\system32\\cmd.exe /c dir /b /OD \"C:\\Users\\user\\Desktop\\*.bat\" \"C:\\Users\\user\\Desktop\\*.cmd\"",
  32. "cscript //nologo bin\\browse.vbs"
  33.  
  34.  
  35. * Signatures Detected:
  36.  
  37. "Description": "Possible date expiration check, exits too soon after checking local time",
  38. "Details":
  39.  
  40. "process": "mode.com, PID 2468"
  41.  
  42.  
  43.  
  44.  
  45. "Description": "Detected script timer window indicative of sleep style evasion",
  46. "Details":
  47.  
  48. "Window": "WSH-Timer"
  49.  
  50.  
  51.  
  52.  
  53. "Description": "Reads data out of its own binary image",
  54. "Details":
  55.  
  56. "self_read": "process: Exes_e75be7590e86df92f785d01ed83b66bb.exe, pid: 1764, offset: 0x00000000, length: 0x00029d47"
  57.  
  58.  
  59. "self_read": "process: Exes_e75be7590e86df92f785d01ed83b66bb.exe, pid: 1764, offset: 0x00000000, length: 0x0002fff7"
  60.  
  61.  
  62. "self_read": "process: Exes_e75be7590e86df92f785d01ed83b66bb.exe, pid: 1764, offset: 0x00000000, length: 0x001000e1"
  63.  
  64.  
  65. "self_read": "process: Exes_e75be7590e86df92f785d01ed83b66bb.exe, pid: 1764, offset: 0x00029cac, length: 0x000f0d5a"
  66.  
  67.  
  68. "self_read": "process: cscript.exe, pid: 1444, offset: 0x00000000, length: 0x00000040"
  69.  
  70.  
  71. "self_read": "process: cscript.exe, pid: 1444, offset: 0x000000e8, length: 0x00000018"
  72.  
  73.  
  74. "self_read": "process: cscript.exe, pid: 1444, offset: 0x000001e0, length: 0x00000078"
  75.  
  76.  
  77. "self_read": "process: cscript.exe, pid: 1444, offset: 0x00015e00, length: 0x00000020"
  78.  
  79.  
  80. "self_read": "process: cscript.exe, pid: 1444, offset: 0x00015e58, length: 0x00000018"
  81.  
  82.  
  83. "self_read": "process: cscript.exe, pid: 1444, offset: 0x00015f50, length: 0x00000018"
  84.  
  85.  
  86. "self_read": "process: cscript.exe, pid: 1444, offset: 0x00016110, length: 0x00000010"
  87.  
  88.  
  89. "self_read": "process: cscript.exe, pid: 1444, offset: 0x00016230, length: 0x00000012"
  90.  
  91.  
  92.  
  93.  
  94. "Description": "The binary likely contains encrypted or compressed data.",
  95. "Details":
  96.  
  97. "section": "name: UPX1, entropy: 7.67, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x0000d400, virtual_size: 0x0000e000"
  98.  
  99.  
  100.  
  101.  
  102. "Description": "The executable is compressed using UPX",
  103. "Details":
  104.  
  105. "section": "name: UPX0, entropy: 0.00, characteristics: IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00000000, virtual_size: 0x00012000"
  106.  
  107.  
  108.  
  109.  
  110. "Description": "Attempts to execute a Living Off The Land Binary command for post exeploitation",
  111. "Details":
  112.  
  113. "MITRE T1064 - cscript": "(Tactic: Defense Evasion, Execution)"
  114.  
  115.  
  116.  
  117.  
  118. "Description": "File has been identified by 17 Antiviruses on VirusTotal as malicious",
  119. "Details":
  120.  
  121. "CAT-QuickHeal": "Trojan.Skillis"
  122.  
  123.  
  124. "Cylance": "Unsafe"
  125.  
  126.  
  127. "CrowdStrike": "win/malicious_confidence_100% (W)"
  128.  
  129.  
  130. "TrendMicro-HouseCall": "TROJ_GEN.R002H07C119"
  131.  
  132.  
  133. "Kaspersky": "Trojan.Win32.Skillis.bjjt"
  134.  
  135.  
  136. "Tencent": "Win32.Trojan.Skillis.Ajvf"
  137.  
  138.  
  139. "F-Secure": "Heuristic.HEUR/AGEN.1033686"
  140.  
  141.  
  142. "Webroot": "Trojan.Dropper.Gen"
  143.  
  144.  
  145. "Avira": "HEUR/AGEN.1033686"
  146.  
  147.  
  148. "AegisLab": "Trojan.Win32.Skillis.4!c"
  149.  
  150.  
  151. "ZoneAlarm": "Trojan.Win32.Skillis.bjjt"
  152.  
  153.  
  154. "Sophos": "Mal/Generic-S"
  155.  
  156.  
  157. "VBA32": "Trojan.Skillis"
  158.  
  159.  
  160. "TACHYON": "Trojan/W32.Skillis.1197062"
  161.  
  162.  
  163. "Rising": "Trojan.Skillis!8.353 (CLOUD)"
  164.  
  165.  
  166. "Yandex": "Trojan.Agent!1T6/uINIYTs"
  167.  
  168.  
  169. "SentinelOne": "static engine - malicious"
  170.  
  171.  
  172.  
  173.  
  174.  
  175. * Started Service:
  176.  
  177. * Mutexes:
  178. "CicLoadWinStaWinSta0",
  179. "Local\\MSCTF.CtfMonitorInstMutexDefault1",
  180. "DefaultTabtip-MainUI"
  181.  
  182.  
  183. * Modified Files:
  184. "C:\\Users\\user\\AppData\\Local\\Temp\\7ZipSfx.000\\bat2exe.bat",
  185. "C:\\Users\\user\\AppData\\Local\\Temp\\7ZipSfx.000\\bin\\browse.vbs",
  186. "C:\\Users\\user\\AppData\\Local\\Temp\\7ZipSfx.000\\bin\\7z.exe",
  187. "C:\\Users\\user\\AppData\\Local\\Temp\\7ZipSfx.000\\bin\\choice.exe",
  188. "C:\\Users\\user\\AppData\\Local\\Temp\\7ZipSfx.000\\bin\\res.exe",
  189. "C:\\Users\\user\\AppData\\Local\\Temp\\7ZipSfx.000\\bin\\upx.exe",
  190. "C:\\Users\\user\\AppData\\Local\\Temp\\7ZipSfx.000\\bin\\7z.dll",
  191. "C:\\Users\\user\\AppData\\Local\\Temp\\7ZipSfx.000\\bin\\7ZSD_LZMAi.sfx",
  192. "\\??\\NUL",
  193. "C:\\Users\\user\\AppData\\Local\\Temp\\BAT2EXE_WS.ini",
  194. "\\Device\\NamedPipe",
  195. "\\??\\PIPE\\samr"
  196.  
  197.  
  198. * Deleted Files:
  199.  
  200. * Modified Registry Keys:
  201. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  202. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browse For Folder Width",
  203. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browse For Folder Height"
  204.  
  205.  
  206. * Deleted Registry Keys:
  207.  
  208. * DNS Communications:
  209.  
  210. * Domains:
  211.  
  212. * Network Communication - ICMP:
  213.  
  214. * Network Communication - HTTP:
  215.  
  216. * Network Communication - SMTP:
  217.  
  218. * Network Communication - Hosts:
  219.  
  220. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment