Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Malicious"
- * MalScore: 10.0
- * File Name: "NanoCore_64f5f10a120ba024c618a3fe63e07615.exe"
- * File Size: 1135104
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "b4f67e3b69eff2012f0fbc993c717ffc7f285e450c9d44ea3dd14c0676c7e76a"
- * MD5: "64f5f10a120ba024c618a3fe63e07615"
- * SHA1: "49387857162478f6ea52e570c6ef4cbeb89d7b46"
- * SHA512: "834d1d7afe01ec9703ebae4a1c62fa7b53ad6f500ab85f2fd85340908a0fe199442814ed1fa07a000aa69e8bcda3606b78c3bd4b0ecb24aa20678d6b7ece6df7"
- * CRC32: "90761461"
- * SSDEEP: "24576:lAHnh+eWsN3skA4RV1Hom2KXMmHa1X1ZsnGzqgjZq5:Uh+ZkldoPK8Ya1X1ZtZjm"
- * Process Execution:
- "NanoCore_64f5f10a120ba024c618a3fe63e07615.exe"
- * Executed Commands:
- * Signatures Detected:
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: NanoCore_64f5f10a120ba024c618a3fe63e07615.exe, pid: 1840, offset: 0x00000000, length: 0x00115200"
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details":
- "section": "name: .rsrc, entropy: 7.85, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ, raw_size: 0x0004ac00, virtual_size: 0x0004aa0c"
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\AwRsuPGigl"
- "data": "C:\\Users\\Public\\AwRsuPGigl.vbs"
- "Description": "File has been identified by 18 Antiviruses on VirusTotal as malicious",
- "Details":
- "Cylance": "Unsafe"
- "ESET-NOD32": "a variant of Win32/Injector.Autoit.EDH"
- "APEX": "Malicious"
- "Kaspersky": "UDS:DangerousObject.Multi.Generic"
- "Invincea": "heuristic"
- "McAfee-GW-Edition": "BehavesLike.Win32.Downloader.tc"
- "Trapmine": "suspicious.low.ml.score"
- "FireEye": "Generic.mg.64f5f10a120ba024"
- "SentinelOne": "DFI - Suspicious PE"
- "Antiy-AVL": "Trojan/Generic.ASVCS3S.1E5"
- "ZoneAlarm": "UDS:DangerousObject.Multi.Generic"
- "AhnLab-V3": "Malware/Win32.RL_Generic.R278988"
- "Acronis": "suspicious"
- "Rising": "Trojan.Win32.Agent_.sa (CLASSIC)"
- "MaxSecure": "Trojan.Malware.300983.susgen"
- "Fortinet": "AutoIt/Injector.EDG!tr"
- "CrowdStrike": "win/malicious_confidence_70% (D)"
- "Qihoo-360": "HEUR/QVM10.1.88DF.Malware.Gen"
- "Description": "Creates a slightly modified copy of itself",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Local\\Temp\\WinBioDataModelOOBE\\UpdateNotificationMgr.bat"
- "percent_match": 100
- "Description": "Anomalous binary characteristics",
- "Details":
- "anomaly": "Actual checksum does not match that reported in PE header"
- * Started Service:
- * Mutexes:
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\WinBioDataModelOOBE\\UpdateNotificationMgr.bat",
- "C:\\Users\\Public\\AwRsuPGigl.vbs"
- * Deleted Files:
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\AwRsuPGigl"
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment