Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Neshta"
- * MalScore: 10.0
- * File Name: "Exes_2c318834ff59c14cc7b7cceb36e92088.exe"
- * File Size: 354304
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "9058f5f5c21a16936ef277efdcc8cf0ff58398b37dfafb1cc8ca644db9b121af"
- * MD5: "2c318834ff59c14cc7b7cceb36e92088"
- * SHA1: "c0387214e740b571c26af4eb073f82a986c73c86"
- * SHA512: "3e2c573d968d403fdbd46f3242ce942d8f6269f1a4247d949d9410af74f3b9cb6050aba050cc6d6a9c9e4f5351cc15880dfcca3b2365d65669547f886b8fdf73"
- * CRC32: "F2371C9C"
- * SSDEEP: "6144:k9g4SlvT7Vh3zhJt52MsNOEtrpmRnP0pOs/IJjs+Q3axzTnVU2Ur71Pds98j:F4Stv3zh9dIgRnVGZ4ULPd08j"
- * Process Execution:
- * Executed Commands:
- * Signatures Detected:
- "Description": "File has been identified by 65 Antiviruses on VirusTotal as malicious",
- "Details":
- "Bkav": "W32.NeshtaB.PE"
- "MicroWorld-eScan": "Win32.Neshta.A"
- "FireEye": "Generic.mg.2c318834ff59c14c"
- "CAT-QuickHeal": "W32.Neshta.C8"
- "McAfee": "W32/HLLP.41472.e"
- "Malwarebytes": "Virus.Neshta"
- "K7AntiVirus": "Virus ( 700000131 )"
- "K7GW": "Virus ( 700000131 )"
- "Cybereason": "malicious.4ff59c"
- "Arcabit": "Win32.Neshta.A"
- "TrendMicro": "PE_NESHTA.A"
- "Baidu": "Win32.Virus.Neshta.a"
- "F-Prot": "W32/Trojan2.PZKG"
- "Symantec": "W32.Neshuta"
- "TotalDefense": "Win32/Neshta.A"
- "APEX": "Malicious"
- "Avast": "Win32:Apanas Trj"
- "ClamAV": "Win.Trojan.Neshuta-1"
- "Kaspersky": "Virus.Win32.Neshta.a"
- "BitDefender": "Win32.Neshta.A"
- "NANO-Antivirus": "Trojan.Win32.Winlock.fmobyw"
- "Paloalto": "generic.ml"
- "AegisLab": "Virus.Win32.Neshta.tn9H"
- "Tencent": "Virus.Win32.Neshta.a"
- "Endgame": "malicious (high confidence)"
- "Emsisoft": "Win32.Neshta.A (B)"
- "Comodo": "Win32.Neshta.A@3ypg"
- "F-Secure": "Malware.W32/Neshta.A"
- "DrWeb": "Win32.HLLP.Neshta"
- "Zillya": "Virus.Neshta.Win32.1"
- "Invincea": "heuristic"
- "McAfee-GW-Edition": "BehavesLike.Win32.HLLP.fc"
- "Trapmine": "malicious.high.ml.score"
- "CMC": "Virus.Win32.Neshta!O"
- "Sophos": "W32/Bloat-A"
- "SentinelOne": "DFI - Malicious PE"
- "Cyren": "W32/Trojan.OBIX-2981"
- "Jiangmin": "Virus.Neshta.a"
- "Avira": "W32/Neshta.A"
- "Antiy-AVL": "Virus/Win32.Neshta.a"
- "Kingsoft": "Win32.Neshta.nl.30720"
- "Microsoft": "Virus:Win32/Neshta.A"
- "ViRobot": "Win32.Neshta.Gen.A"
- "ZoneAlarm": "Virus.Win32.Neshta.a"
- "GData": "Win32.Virus.Neshta.A"
- "TACHYON": "Virus/W32.Neshta"
- "AhnLab-V3": "Win32/Neshta"
- "Acronis": "suspicious"
- "VBA32": "Virus.Win32.Neshta.a"
- "ALYac": "Win32.Neshta.A"
- "MAX": "malware (ai score=88)"
- "Ad-Aware": "Win32.Neshta.A"
- "Cylance": "Unsafe"
- "Zoner": "Virus.Win32.19514"
- "ESET-NOD32": "Win32/Neshta.A"
- "TrendMicro-HouseCall": "PE_NESHTA.A"
- "Rising": "PUF.Patcher!1.B3BB (RDM+:cmRtazqeuDdQIxSGhBYOeRVFPiVt)"
- "Yandex": "Win32.Neshta.A"
- "Ikarus": "Virus.Win32.Neshta"
- "eGambit": "Unsafe.AI_Score_99%"
- "Fortinet": "W32/Neshta.A"
- "AVG": "Win32:Apanas Trj"
- "Panda": "W32/Neshta.A"
- "CrowdStrike": "win/malicious_confidence_100% (W)"
- "Qihoo-360": "Virus.Win32.Neshta.B"
- "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
- "Details":
- "target": "clamav:Win.Trojan.Neshuta-1, sha256:9058f5f5c21a16936ef277efdcc8cf0ff58398b37dfafb1cc8ca644db9b121af, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "Description": "Anomalous binary characteristics",
- "Details":
- "anomaly": "Timestamp on binary predates the release date of the OS version it requires by at least a year"
- * Started Service:
- * Mutexes:
- * Modified Files:
- * Deleted Files:
- * Modified Registry Keys:
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Add Comment
Please, Sign In to add comment