Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: ""
- * MalScore: 10.0
- * File Name: "EBSEHV.exe"
- * File Size: 844403
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed"
- * SHA256: "2edee6e3b3a94ed434cb8e409517376ded87234ff1c043066768e944a365dc43"
- * MD5: "0fa88fe980af46d3219f702d78474903"
- * SHA1: "aeb728b38317a3ad25ee25db3c3628cbd0a26caa"
- * SHA512: "66b64e41918b7600bcedaaa2176979bb4d045f0e2bea11f32c75e5db0e3bd6f27aee86ea91be2278afb734b9e4c4e1fef446a651a9ddbe6f2c34b271aa6834b7"
- * CRC32: "88AE9DC9"
- * SSDEEP: "12288:u6Wq4aaE6KwyF5L0Y2D1PqLbECBcZfdU8T7ycXDX1fjC64bbkR:0thEVaPqLGC8T7F5bC64bb2"
- * Process Execution:
- "EBSEHV.exe",
- "cmd.exe",
- "schtasks.exe",
- "svchost.exe",
- "svchost.exe",
- "taskeng.exe",
- "MLVORU.exe",
- "taskeng.exe",
- "MLVORU.exe",
- "MLVORU.exe"
- * Executed Commands:
- "C:\\Windows\\system32\\cmd.exe /c schtasks /create /tn TNFNVA.exe /tr C:\\Users\\user\\AppData\\Roaming\\Windata\\MLVORU.exe /sc minute /mo 1",
- "schtasks /create /tn TNFNVA.exe /tr C:\\Users\\user\\AppData\\Roaming\\Windata\\MLVORU.exe /sc minute /mo 1",
- "taskeng.exe 090AE7EA-5381-4CB4-9A67-9E269A2B2025 S-1-5-21-0000000000-0000000000-0000000000-1000:Host\\user:Interactive:1",
- "taskeng.exe F27504D5-4548-4D02-BEE8-C2F73AC66E56 S-1-5-21-0000000000-0000000000-0000000000-1000:Host\\user:Interactive:1",
- "C:\\Users\\user\\AppData\\Roaming\\Windata\\MLVORU.exe"
- * Signatures Detected:
- "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
- "Details":
- "IP": "172.82.179.254:30805"
- "Description": "Possible date expiration check, exits too soon after checking local time",
- "Details":
- "process": "schtasks.exe, PID 2628"
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: EBSEHV.exe, pid: 1948, offset: 0x00000000, length: 0x00010000"
- "self_read": "process: EBSEHV.exe, pid: 1948, offset: 0x00000000, length: 0x000ce273"
- "self_read": "process: EBSEHV.exe, pid: 1948, offset: 0x0000ffec, length: 0x00010000"
- "self_read": "process: EBSEHV.exe, pid: 1948, offset: 0x0001ffd8, length: 0x00010000"
- "self_read": "process: EBSEHV.exe, pid: 1948, offset: 0x0002ffc4, length: 0x00010000"
- "self_read": "process: EBSEHV.exe, pid: 1948, offset: 0x0003ffb0, length: 0x00010000"
- "self_read": "process: EBSEHV.exe, pid: 1948, offset: 0x0004da14, length: 0x00001000"
- "self_read": "process: EBSEHV.exe, pid: 1948, offset: 0x0004da28, length: 0x00000200"
- "self_read": "process: EBSEHV.exe, pid: 1948, offset: 0x0004dabf, length: 0x00000200"
- "self_read": "process: EBSEHV.exe, pid: 1948, offset: 0x0004dadb, length: 0x00080798"
- "self_read": "process: EBSEHV.exe, pid: 1948, offset: 0x000ce26b, length: 0x00000008"
- "self_read": "process: MLVORU.exe, pid: 1392, offset: 0x00000000, length: 0x00010000"
- "self_read": "process: MLVORU.exe, pid: 1392, offset: 0x0000ffec, length: 0x00010000"
- "self_read": "process: MLVORU.exe, pid: 1392, offset: 0x0001ffd8, length: 0x00010000"
- "self_read": "process: MLVORU.exe, pid: 1392, offset: 0x0002ffc4, length: 0x00010000"
- "self_read": "process: MLVORU.exe, pid: 1392, offset: 0x0003ffb0, length: 0x00010000"
- "self_read": "process: MLVORU.exe, pid: 1392, offset: 0x0004da14, length: 0x00001000"
- "self_read": "process: MLVORU.exe, pid: 1392, offset: 0x0004da28, length: 0x00000200"
- "self_read": "process: MLVORU.exe, pid: 1392, offset: 0x0004dabf, length: 0x00000200"
- "self_read": "process: MLVORU.exe, pid: 1392, offset: 0x0004dadb, length: 0x00080798"
- "self_read": "process: MLVORU.exe, pid: 1392, offset: 0x000ce26b, length: 0x00000008"
- "self_read": "process: MLVORU.exe, pid: 2984, offset: 0x00000000, length: 0x00010000"
- "self_read": "process: MLVORU.exe, pid: 2984, offset: 0x0000ffec, length: 0x00010000"
- "self_read": "process: MLVORU.exe, pid: 2984, offset: 0x0001ffd8, length: 0x00010000"
- "self_read": "process: MLVORU.exe, pid: 2984, offset: 0x0002ffc4, length: 0x00010000"
- "self_read": "process: MLVORU.exe, pid: 2984, offset: 0x0003ffb0, length: 0x00010000"
- "self_read": "process: MLVORU.exe, pid: 2984, offset: 0x0004da14, length: 0x00001000"
- "self_read": "process: MLVORU.exe, pid: 2984, offset: 0x0004da28, length: 0x00000200"
- "self_read": "process: MLVORU.exe, pid: 2984, offset: 0x0004dabf, length: 0x00000200"
- "self_read": "process: MLVORU.exe, pid: 2984, offset: 0x0004dadb, length: 0x00080798"
- "self_read": "process: MLVORU.exe, pid: 2984, offset: 0x000ce26b, length: 0x00000008"
- "self_read": "process: MLVORU.exe, pid: 1560, offset: 0x00000000, length: 0x00010000"
- "self_read": "process: MLVORU.exe, pid: 1560, offset: 0x0000ffec, length: 0x00010000"
- "self_read": "process: MLVORU.exe, pid: 1560, offset: 0x0001ffd8, length: 0x00010000"
- "self_read": "process: MLVORU.exe, pid: 1560, offset: 0x0002ffc4, length: 0x00010000"
- "self_read": "process: MLVORU.exe, pid: 1560, offset: 0x0003ffb0, length: 0x00010000"
- "self_read": "process: MLVORU.exe, pid: 1560, offset: 0x0004da14, length: 0x00001000"
- "self_read": "process: MLVORU.exe, pid: 1560, offset: 0x0004da28, length: 0x00000200"
- "self_read": "process: MLVORU.exe, pid: 1560, offset: 0x0004dabf, length: 0x00000200"
- "self_read": "process: MLVORU.exe, pid: 1560, offset: 0x0004dadb, length: 0x00080798"
- "self_read": "process: MLVORU.exe, pid: 1560, offset: 0x000ce26b, length: 0x00000008"
- "Description": "Drops a binary and executes it",
- "Details":
- "binary": "C:\\Users\\user\\AppData\\Roaming\\Windata\\MLVORU.exe"
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details":
- "section": "name: UPX1, entropy: 7.93, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00042200, virtual_size: 0x00043000"
- "Description": "The executable is compressed using UPX",
- "Details":
- "section": "name: UPX0, entropy: 0.00, characteristics: IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00000000, virtual_size: 0x0007a000"
- "Description": "Attempts to execute a Living Off The Land Binary command for post exeploitation",
- "Details":
- "MITRE T1078 - schtask": "(Tactic: Execution, Persistence, Privilege Escalation)"
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "task": "C:\\Windows\\system32\\cmd.exe /c schtasks /create /tn TNFNVA.exe /tr C:\\Users\\user\\AppData\\Roaming\\Windata\\MLVORU.exe /sc minute /mo 1"
- "Description": "File has been identified by 40 Antiviruses on VirusTotal as malicious",
- "Details":
- "MicroWorld-eScan": "AIT:Trojan.Nymeria.219"
- "McAfee": "Artemis!0FA88FE980AF"
- "AegisLab": "Trojan.Win32.Fakeoff.tpw9"
- "BitDefender": "AIT:Trojan.Nymeria.219"
- "K7GW": "Riskware ( 0040eff71 )"
- "K7AntiVirus": "Riskware ( 0040eff71 )"
- "Invincea": "heuristic"
- "F-Prot": "W32/Kryptik.AIY"
- "APEX": "Malicious"
- "ClamAV": "Win.Packed.LokiBot-6963314-0"
- "Kaspersky": "Trojan-PSW.Win32.Autoit.bag"
- "Ad-Aware": "AIT:Trojan.Nymeria.219"
- "Sophos": "Mal/Generic-S"
- "F-Secure": "Trojan.TR/Autoit.hgyym"
- "McAfee-GW-Edition": "BehavesLike.Win32.Backdoor.cc"
- "Fortinet": "AutoIt/Agent.DB!tr"
- "FireEye": "Generic.mg.0fa88fe980af46d3"
- "Emsisoft": "AIT:Trojan.Nymeria.219 (B)"
- "SentinelOne": "DFI - Suspicious PE"
- "Cyren": "W32/Kryptik.QUZK-7259"
- "Jiangmin": "Backdoor.Androm.algc"
- "Webroot": "W32.Rogue.Gen"
- "Avira": "TR/Autoit.hgyym"
- "MAX": "malware (ai score=87)"
- "Endgame": "malicious (moderate confidence)"
- "Arcabit": "AIT:Trojan.Nymeria.219"
- "ZoneAlarm": "Trojan-PSW.Win32.Autoit.bag"
- "AhnLab-V3": "Trojan/Win32.AutoIt.C2019675"
- "Acronis": "suspicious"
- "VBA32": "Trojan-Downloader.Autoit.gen"
- "ALYac": "AIT:Trojan.Nymeria.219"
- "Malwarebytes": "Trojan.Script.AI"
- "ESET-NOD32": "a variant of Win32/Autoit.DB"
- "TrendMicro-HouseCall": "TROJ_GEN.R015H0CGS19"
- "Tencent": "Win32.Trojan-qqpass.Qqrob.Jmm"
- "Ikarus": "Trojan.Autoit"
- "GData": "AIT:Trojan.Nymeria.219 (2x)"
- "Cybereason": "malicious.980af4"
- "CrowdStrike": "win/malicious_confidence_90% (W)"
- "Qihoo-360": "HEUR/QVM11.1.D997.Malware.Gen"
- "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
- "Details":
- "target": "clamav:Win.Packed.LokiBot-6963314-0, sha256:2edee6e3b3a94ed434cb8e409517376ded87234ff1c043066768e944a365dc43, type:PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed"
- "dropped": "clamav:Win.Packed.LokiBot-6963314-0, sha256:2edee6e3b3a94ed434cb8e409517376ded87234ff1c043066768e944a365dc43 , guest_paths:C:\\Users\\user\\AppData\\Roaming\\Windata\\MLVORU.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed"
- "Description": "Creates a copy of itself",
- "Details":
- "copy": "C:\\Users\\user\\AppData\\Roaming\\Windata\\MLVORU.exe"
- * Started Service:
- * Mutexes:
- * Modified Files:
- "C:\\Users\\user\\AppData\\Roaming\\Windata\\MLVORU.exe",
- "C:\\Windows\\sysnative\\Tasks\\TNFNVA.exe",
- "\\Device\\LanmanDatagramReceiver",
- "C:\\Windows\\appcompat\\Programs\\RecentFileCache.bcf"
- * Deleted Files:
- "C:\\Windows\\Tasks\\TNFNVA.exe.job"
- * Modified Registry Keys:
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\957F6605-234F-4D35-A57B-7E4E7059548F\\Path",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\957F6605-234F-4D35-A57B-7E4E7059548F\\Hash",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\TNFNVA.exe\\Id",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\TNFNVA.exe\\Index",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\957F6605-234F-4D35-A57B-7E4E7059548F\\Triggers",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\957F6605-234F-4D35-A57B-7E4E7059548F\\DynamicInfo",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\090AE7EA-5381-4CB4-9A67-9E269A2B2025",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\F27504D5-4548-4D02-BEE8-C2F73AC66E56",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\090AE7EA-5381-4CB4-9A67-9E269A2B2025\\data",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\F27504D5-4548-4D02-BEE8-C2F73AC66E56\\data"
- * Deleted Registry Keys:
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\TNFNVA.exe.job",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\TNFNVA.exe.job.fp"
- * DNS Communications:
- "type": "A",
- "request": "worldbest.duckdns.org",
- "answers":
- "data": "172.82.179.254",
- "type": "A"
- * Domains:
- "ip": "172.82.179.254",
- "domain": "worldbest.duckdns.org"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment