Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Ramnit"
- * MalScore: 10.0
- * File Name: "Exes_4a9fa8b7f56205eee13d20211a026261.exe"
- * File Size: 1693864
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive"
- * SHA256: "a94d83c7fb1bea5a111a7a8e9277183b958cd7930e6766468c48016669967795"
- * MD5: "4a9fa8b7f56205eee13d20211a026261"
- * SHA1: "1029045dcb0ed3b00e266bff74263a4e9a16b858"
- * SHA512: "cf809d661e84eae8796cb01ca7ef31f0e986147225f0b19d7acc0394c9bf99347584053d8a70d3352dd97cb05299840097596457cd9c47186fbef7fa8e2d1e37"
- * CRC32: "355B7C85"
- * SSDEEP: "49152:wC9y2tqlYht3WV1uwdVdYCxFnoxSOScLzNjzG9Qzwn:byhlYhBquwdVddFqicLzNjzxwn"
- * Process Execution:
- "Exes_4a9fa8b7f56205eee13d20211a026261.exe",
- "Exes_4a9fa8b7f56205eee13d20211a026261Srv.exe",
- "DesktopLayer.exe"
- * Executed Commands:
- "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_4a9fa8b7f56205eee13d20211a026261Srv.exe",
- "C:\\Program Files (x86)\\Microsoft\\DesktopLayer.exe",
- "C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe"
- * Signatures Detected:
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: Exes_4a9fa8b7f56205eee13d20211a026261.exe, pid: 1640, offset: 0x00000000, length: 0x0019d8a4"
- "self_read": "process: Exes_4a9fa8b7f56205eee13d20211a026261.exe, pid: 1640, offset: 0x0001b01c, length: 0x0012c000"
- "self_read": "process: Exes_4a9fa8b7f56205eee13d20211a026261.exe, pid: 1640, offset: 0x0019d8a4, length: 0x00000004"
- "Description": "Drops a binary and executes it",
- "Details":
- "binary": "C:\\Program Files (x86)\\Microsoft\\DesktopLayer.exe"
- "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_4a9fa8b7f56205eee13d20211a026261Srv.exe"
- "Description": "Tries to suspend Cuckoo threads to prevent logging of malicious activity",
- "Details":
- "Process": "DesktopLayer.exe (3032)"
- "Description": "File has been identified by 37 Antiviruses on VirusTotal as malicious",
- "Details":
- "MicroWorld-eScan": "Dropped:Trojan.Zbot.IVF"
- "CAT-QuickHeal": "W32.Ramnit.A"
- "ALYac": "Dropped:Trojan.Zbot.IVF"
- "Malwarebytes": "HackTool.WinActivator"
- "TrendMicro": "PE_RAMNIT.H"
- "Baidu": "Multi.Threats.InArchive"
- "Cyren": "W32/Ramnit.B!Generic"
- "TrendMicro-HouseCall": "PE_RAMNIT.H"
- "Avast": "Win32:RmnDrp"
- "ClamAV": "Win.Trojan.Ramnit-1847"
- "Kaspersky": "Virus.Win32.Nimnul.a"
- "BitDefender": "Dropped:Trojan.Zbot.IVF"
- "NANO-Antivirus": "Virus.Win32.Nimnul.bpchjo"
- "Rising": "Ransom.PolyRansom!8.32D6 (CLOUD)"
- "Ad-Aware": "Dropped:Trojan.Zbot.IVF"
- "Sophos": "W32/Patched-I"
- "F-Secure": "Win32.Ramnit.Dam"
- "DrWeb": "Win32.Rmnet"
- "Emsisoft": "Dropped:Trojan.Zbot.IVF (B)"
- "Ikarus": "Virus.Ramnit"
- "F-Prot": "W32/Ramnit.B!Generic"
- "Jiangmin": "Win32/PatchFile.et"
- "Avira": "W32/Ramnit.CD"
- "MAX": "malware (ai score=94)"
- "Antiy-AVL": "Virus/Win32.Nimnul.a"
- "Arcabit": "Trojan.Zbot.IVF"
- "ZoneAlarm": "Virus.Win32.Nimnul.a"
- "Microsoft": "Virus:Win32/Vigorf.A"
- "VBA32": "Malware-Cryptor.Win32.073"
- "Zoner": "Win32.Agent.QFO"
- "ESET-NOD32": "Win32/Ramnit.A"
- "Tencent": "Win32.Virus.Nimnul.Pfad"
- "GData": "Dropped:Trojan.Zbot.IVF"
- "AVG": "Win32:RmnDrp"
- "Cybereason": "malicious.7f5620"
- "Paloalto": "generic.ml"
- "Qihoo-360": "Win32/Trojan.3c1"
- "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
- "Details":
- "target": "clamav:Win.Trojan.Ramnit-1847, sha256:a94d83c7fb1bea5a111a7a8e9277183b958cd7930e6766468c48016669967795, type:PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive"
- "dropped": "clamav:Win.Trojan.Ramnit-1847, sha256:0249501ba5ea2cb21a1f4433a7840636db4f594af317312bc7c163991aba8e9d , guest_paths:C:\\Windows\\Temp\\\\xc3\\x90\\xc2\\xa1\\xc3\\x82\\xc3\\xad\\xc2\\xbc\\xc2\\xa4\\xc2\\xbb\\xc3\\xae\\xc2\\xb9\\xc2\\xa4\\xc2\\xbe\\xc3\\x9fOem7F7(\\xc3\\x8c\\xc3\\x98\\xc3\\x8a\\xc3\\xa2\\xc3\\x90\\xc3\\x8d).exe, type:PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive"
- "dropped": "clamav:Win.Trojan.Generic-53, sha256:fd6c69c345f1e32924f0a5bb7393e191b393a78d58e2c6413b03ced7482f2320 , guest_paths:C:\\Users\\user\\AppData\\Local\\Temp\\Exes_4a9fa8b7f56205eee13d20211a026261Srv.exe*C:\\Program Files (x86)\\Microsoft\\DesktopLayer.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed"
- "dropped": "clamav:Win.Trojan.Ramnit-1847, sha256:60b4baa11dcbcab53c55cf45d49b324a785c8cbf51c33ea97c38ed8f11d0e9c6 , guest_paths:C:\\Users\\user\\AppData\\Local\\Temp\\nsw1F34.tmp\\System.dll, type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows"
- * Started Service:
- * Mutexes:
- "KyUffThOkYwRRtgPP",
- "SAMPLE_MUTEX_Shelling"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\nsg1F23.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\nsw1F34.tmp\\System.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_4a9fa8b7f56205eee13d20211a026261Srv.exe",
- "C:\\Windows\\Temp\\\\xc3\\x90\\xc2\\xa1\\xc3\\x82\\xc3\\xad\\xc2\\xbc\\xc2\\xa4\\xc2\\xbb\\xc3\\xae\\xc2\\xb9\\xc2\\xa4\\xc2\\xbe\\xc3\\x9fOem7F7(\\xc3\\x8c\\xc3\\x98\\xc3\\x8a\\xc3\\xa2\\xc3\\x90\\xc3\\x8d).exe",
- "C:\\Program Files (x86)\\Microsoft\\px1FCE.tmp",
- "C:\\Program Files (x86)\\Microsoft\\DesktopLayer.exe"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\nsr1EC5.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\nsw1F34.tmp",
- "C:\\Program Files (x86)\\Microsoft\\px1FCE.tmp"
- * Modified Registry Keys:
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment