paladin316

Exes_77272a5d82af94936cf755d90c8ebd37_exe_2019-07-09_08_30.txt

Jul 9th, 2019
2,053
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 9.36 KB | None | 0 0
  1.  
  2. * MalFamily: "Nanocore"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_77272a5d82af94936cf755d90c8ebd37.exe"
  7. * File Size: 207872
  8. * File Type: "PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows"
  9. * SHA256: "976a601972a8eef3aa75a1f39050020e8eb0e3a50f7e012d3e82ff2fc9e9f2b1"
  10. * MD5: "77272a5d82af94936cf755d90c8ebd37"
  11. * SHA1: "d65bf37b9f386306f369adc9890445405b6d09d0"
  12. * SHA512: "2f300c0e393c258bff8566b26897a725cfff91b052186b6562e9f07278c124c3bdbfb495a242f01181ac7aa631d461a192eb6df120a122551f44059d958ef3e7"
  13. * CRC32: "4FA73608"
  14. * SSDEEP: "6144:sLV6Bta6dtJmakIM5d8GL+1WUQ52F+/8Ej4emw:sLV6BtpmkRGLUcQsEEj46"
  15.  
  16. * Process Execution:
  17. "Exes_77272a5d82af94936cf755d90c8ebd37.exe",
  18. "schtasks.exe",
  19. "schtasks.exe",
  20. "svchost.exe"
  21.  
  22.  
  23. * Executed Commands:
  24. "\"schtasks.exe\" /create /f /tn \"DSL Subsystem\" /xml \"C:\\Users\\user\\AppData\\Local\\Temp\\tmp73DD.tmp\"",
  25. "\"schtasks.exe\" /create /f /tn \"DSL Subsystem Task\" /xml \"C:\\Users\\user\\AppData\\Local\\Temp\\tmp7CF6.tmp\""
  26.  
  27.  
  28. * Signatures Detected:
  29.  
  30. "Description": "Attempts to connect to a dead IP:Port (2 unique times)",
  31. "Details":
  32.  
  33. "IP": "127.0.0.1:40938"
  34.  
  35.  
  36. "IP": "185.200.117.131:40938"
  37.  
  38.  
  39.  
  40.  
  41. "Description": "Creates RWX memory",
  42. "Details":
  43.  
  44.  
  45. "Description": "A process attempted to delay the analysis task.",
  46. "Details":
  47.  
  48. "Process": "Exes_77272a5d82af94936cf755d90c8ebd37.exe tried to sleep 838 seconds, actually delayed analysis time by 0 seconds"
  49.  
  50.  
  51. "Process": "svchost.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
  52.  
  53.  
  54.  
  55.  
  56. "Description": "At least one IP Address, Domain, or File Name was found in a crypto call",
  57. "Details":
  58.  
  59. "ioc": "v2.0.50727"
  60.  
  61.  
  62.  
  63.  
  64. "Description": "Reads data out of its own binary image",
  65. "Details":
  66.  
  67. "self_read": "process: Exes_77272a5d82af94936cf755d90c8ebd37.exe, pid: 2636, offset: 0x00000000, length: 0x00001000"
  68.  
  69.  
  70. "self_read": "process: Exes_77272a5d82af94936cf755d90c8ebd37.exe, pid: 2636, offset: 0x00000080, length: 0x00000200"
  71.  
  72.  
  73.  
  74.  
  75. "Description": "A process created a hidden window",
  76. "Details":
  77.  
  78. "Process": "Exes_77272a5d82af94936cf755d90c8ebd37.exe -> \"schtasks.exe\" /create /f /tn \"DSL Subsystem\" /xml \"C:\\Users\\user\\AppData\\Local\\Temp\\tmp73DD.tmp\""
  79.  
  80.  
  81. "Process": "Exes_77272a5d82af94936cf755d90c8ebd37.exe -> \"schtasks.exe\" /create /f /tn \"DSL Subsystem Task\" /xml \"C:\\Users\\user\\AppData\\Local\\Temp\\tmp7CF6.tmp\""
  82.  
  83.  
  84.  
  85.  
  86. "Description": "The binary likely contains encrypted or compressed data.",
  87. "Details":
  88.  
  89. "section": "name: .rsrc, entropy: 8.00, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ, raw_size: 0x00016000, virtual_size: 0x00015fc8"
  90.  
  91.  
  92.  
  93.  
  94. "Description": "Attempts to remove evidence of file being downloaded from the Internet",
  95. "Details":
  96.  
  97. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_77272a5d82af94936cf755d90c8ebd37.exe:Zone.Identifier"
  98.  
  99.  
  100.  
  101.  
  102. "Description": "A process was set to shut the system down when terminated",
  103. "Details":
  104.  
  105. "process": "Exes_77272a5d82af94936cf755d90c8ebd37.exe:2636"
  106.  
  107.  
  108.  
  109.  
  110. "Description": "Attempts to execute a Living Off The Land Binary command for post exeploitation",
  111. "Details":
  112.  
  113. "MITRE T1078 - schtask": "(Tactic: Execution, Persistence, Privilege Escalation)"
  114.  
  115.  
  116.  
  117.  
  118. "Description": "Installs itself for autorun at Windows startup",
  119. "Details":
  120.  
  121. "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\DSL Subsystem"
  122.  
  123.  
  124. "data": "C:\\Program Files (x86)\\DSL Subsystem\\dslss.exe"
  125.  
  126.  
  127.  
  128.  
  129. "Description": "Exhibits behavior characteristic of Nanocore RAT",
  130. "Details":
  131.  
  132.  
  133. "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
  134. "Details":
  135.  
  136. "target": "clamav:Win.Trojan.Nanocore-5, sha256:976a601972a8eef3aa75a1f39050020e8eb0e3a50f7e012d3e82ff2fc9e9f2b1, type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows"
  137.  
  138.  
  139. "dropped": "clamav:Win.Trojan.Nanocore-5, sha256:976a601972a8eef3aa75a1f39050020e8eb0e3a50f7e012d3e82ff2fc9e9f2b1 , guest_paths:C:\\Program Files (x86)\\DSL Subsystem\\dslss.exe, type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows"
  140.  
  141.  
  142.  
  143.  
  144. "Description": "Creates a copy of itself",
  145. "Details":
  146.  
  147. "copy": "C:\\Program Files (x86)\\DSL Subsystem\\dslss.exe"
  148.  
  149.  
  150.  
  151.  
  152. "Description": "Collects information to fingerprint the system",
  153. "Details":
  154.  
  155.  
  156. "Description": "Created network traffic indicative of malicious activity",
  157. "Details":
  158.  
  159. "signature": "ET TROJAN Possible NanoCore C2 60B"
  160.  
  161.  
  162.  
  163.  
  164.  
  165. * Started Service:
  166.  
  167. * Mutexes:
  168. "Global\\CLR_CASOFF_MUTEX",
  169. "Global\\c50044a7-ad71-4407-b902-d8d6ed3132e0",
  170. "Global\\.net clr networking"
  171.  
  172.  
  173. * Modified Files:
  174. "C:\\Users\\user\\AppData\\Roaming\\C1515A12-1764-4632-ACE9-A9DFF9253200\\run.dat",
  175. "C:\\Program Files (x86)\\DSL Subsystem\\dslss.exe",
  176. "C:\\Users\\user\\AppData\\Local\\Temp\\tmp73DD.tmp",
  177. "C:\\Users\\user\\AppData\\Roaming\\C1515A12-1764-4632-ACE9-A9DFF9253200\\task.dat",
  178. "C:\\Users\\user\\AppData\\Local\\Temp\\tmp7CF6.tmp",
  179. "C:\\Windows\\sysnative\\Tasks\\DSL Subsystem",
  180. "C:\\Windows\\sysnative\\Tasks\\DSL Subsystem Task",
  181. "C:\\Windows\\SoftwareDistribution\\DataStore\\DataStore.edb",
  182. "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edb.chk"
  183.  
  184.  
  185. * Deleted Files:
  186. "C:\\Program Files (x86)\\DSL Subsystem\\dslss.exe",
  187. "C:\\Users\\user\\AppData\\Roaming\\C1515A12-1764-4632-ACE9-A9DFF9253200\\DSL Subsystem\\dslss.exe",
  188. "C:\\Users\\user\\AppData\\Local\\Temp\\tmp73DD.tmp",
  189. "C:\\Users\\user\\AppData\\Local\\Temp\\tmp7CF6.tmp",
  190. "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_77272a5d82af94936cf755d90c8ebd37.exe:Zone.Identifier",
  191. "C:\\Windows\\Tasks\\DSL Subsystem.job",
  192. "C:\\Windows\\Tasks\\DSL Subsystem Task.job",
  193. "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edbtmp.log"
  194.  
  195.  
  196. * Modified Registry Keys:
  197. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\DSL Subsystem",
  198. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\A1AA291B-3BCB-43BF-96F4-D85996580F80\\Path",
  199. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\A1AA291B-3BCB-43BF-96F4-D85996580F80\\Hash",
  200. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\DSL Subsystem\\Id",
  201. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\DSL Subsystem\\Index",
  202. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\A1AA291B-3BCB-43BF-96F4-D85996580F80\\Triggers",
  203. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\A3B84170-26E8-412F-AAD7-FA6C2D04C052\\Path",
  204. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\A3B84170-26E8-412F-AAD7-FA6C2D04C052\\Hash",
  205. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\DSL Subsystem Task\\Id",
  206. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\DSL Subsystem Task\\Index",
  207. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\A3B84170-26E8-412F-AAD7-FA6C2D04C052\\Triggers"
  208.  
  209.  
  210. * Deleted Registry Keys:
  211. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\DSL Subsystem.job",
  212. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\DSL Subsystem.job.fp",
  213. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\DSL Subsystem Task.job",
  214. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\DSL Subsystem Task.job.fp"
  215.  
  216.  
  217. * DNS Communications:
  218.  
  219. "type": "A",
  220. "request": "fabulous.ddns.net",
  221. "answers":
  222.  
  223. "data": "185.200.117.131",
  224. "type": "A"
  225.  
  226.  
  227.  
  228.  
  229.  
  230. * Domains:
  231.  
  232. "ip": "185.200.117.131",
  233. "domain": "fabulous.ddns.net"
  234.  
  235.  
  236.  
  237. * Network Communication - ICMP:
  238.  
  239. * Network Communication - HTTP:
  240.  
  241. * Network Communication - SMTP:
  242.  
  243. * Network Communication - Hosts:
  244.  
  245. * Network Communication - IRC:
Add Comment
Please, Sign In to add comment