paladin316

Exes_fe30ef5095e5d017a7d34b7766101a00_exe_2019-08-01_04_30.txt

Aug 1st, 2019
2,313
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.03 KB | None | 0 0
  1.  
  2. * MalFamily: "Razy"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_fe30ef5095e5d017a7d34b7766101a00.exe"
  7. * File Size: 292352
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "1474aa853a43261ec302ec417d29f183211d7647483acbf133a8caae86a1a58a"
  10. * MD5: "fe30ef5095e5d017a7d34b7766101a00"
  11. * SHA1: "e53dbb5d5a9b63c6675ad50029b990f922a3e662"
  12. * SHA512: "a5780e593281d41bacfd4ec7b065588142964a8dad173955ece2ec0d8e53b9d5e08180c47d5ee01b87b926dac1628f1975140092872dbdcf4d631b51eb1ac987"
  13. * CRC32: "20A0EB8A"
  14. * SSDEEP: "3072:ouTfBg9Y4hPxijgfdseE/pr4AXlfrkMkGL6Z8cpLD:oQg9Y4MgVse+r4yfrMx6S"
  15.  
  16. * Process Execution:
  17.  
  18. * Executed Commands:
  19.  
  20. * Signatures Detected:
  21.  
  22. "Description": "File has been identified by 25 Antiviruses on VirusTotal as malicious",
  23. "Details":
  24.  
  25. "MicroWorld-eScan": "Gen:Variant.Razy.525582"
  26.  
  27.  
  28. "ALYac": "Gen:Variant.Razy.525582"
  29.  
  30.  
  31. "Cylance": "Unsafe"
  32.  
  33.  
  34. "Cybereason": "malicious.d5a9b6"
  35.  
  36.  
  37. "Symantec": "ML.Attribute.HighConfidence"
  38.  
  39.  
  40. "APEX": "Malicious"
  41.  
  42.  
  43. "BitDefender": "Gen:Variant.Razy.525582"
  44.  
  45.  
  46. "Rising": "[email protected] (RDML:kQvMLqTAKpOTr4u9Uj2fxw)"
  47.  
  48.  
  49. "Emsisoft": "Gen:Variant.Razy.525582 (B)"
  50.  
  51.  
  52. "F-Secure": "Trojan.TR/Crypt.XPACK.Gen2"
  53.  
  54.  
  55. "Invincea": "heuristic"
  56.  
  57.  
  58. "FireEye": "Generic.mg.fe30ef5095e5d017"
  59.  
  60.  
  61. "Webroot": "W32.Trojan.Gen"
  62.  
  63.  
  64. "Avira": "TR/Crypt.XPACK.Gen2"
  65.  
  66.  
  67. "MAX": "malware (ai score=81)"
  68.  
  69.  
  70. "GData": "Gen:Variant.Razy.525582"
  71.  
  72.  
  73. "Acronis": "suspicious"
  74.  
  75.  
  76. "VBA32": "Malware-Cryptor.General.3"
  77.  
  78.  
  79. "Ad-Aware": "Gen:Variant.Razy.525582"
  80.  
  81.  
  82. "ESET-NOD32": "a variant of Win32/GenKryptik.DOWB"
  83.  
  84.  
  85. "SentinelOne": "DFI - Suspicious PE"
  86.  
  87.  
  88. "Fortinet": "W32/Agent.F609!tr"
  89.  
  90.  
  91. "AVG": "FileRepMalware"
  92.  
  93.  
  94. "CrowdStrike": "win/malicious_confidence_80% (D)"
  95.  
  96.  
  97. "Qihoo-360": "HEUR/QVM20.1.E4C1.Malware.Gen"
  98.  
  99.  
  100.  
  101.  
  102.  
  103. * Started Service:
  104.  
  105. * Mutexes:
  106.  
  107. * Modified Files:
  108.  
  109. * Deleted Files:
  110.  
  111. * Modified Registry Keys:
  112.  
  113. * Deleted Registry Keys:
  114.  
  115. * DNS Communications:
  116.  
  117. * Domains:
  118.  
  119. * Network Communication - ICMP:
  120.  
  121. * Network Communication - HTTP:
  122.  
  123. * Network Communication - SMTP:
  124.  
  125. * Network Communication - Hosts:
  126.  
  127. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment