paladin316

Exes_4a9fa8b7f56205eee13d20211a026261_exe_2019-07-12_08_30.txt

Jul 12th, 2019
2,184
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.65 KB | None | 0 0
  1.  
  2. * MalFamily: "Ramnit"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_4a9fa8b7f56205eee13d20211a026261.exe"
  7. * File Size: 1693864
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive"
  9. * SHA256: "a94d83c7fb1bea5a111a7a8e9277183b958cd7930e6766468c48016669967795"
  10. * MD5: "4a9fa8b7f56205eee13d20211a026261"
  11. * SHA1: "1029045dcb0ed3b00e266bff74263a4e9a16b858"
  12. * SHA512: "cf809d661e84eae8796cb01ca7ef31f0e986147225f0b19d7acc0394c9bf99347584053d8a70d3352dd97cb05299840097596457cd9c47186fbef7fa8e2d1e37"
  13. * CRC32: "355B7C85"
  14. * SSDEEP: "49152:wC9y2tqlYht3WV1uwdVdYCxFnoxSOScLzNjzG9Qzwn:byhlYhBquwdVddFqicLzNjzxwn"
  15.  
  16. * Process Execution:
  17. "Exes_4a9fa8b7f56205eee13d20211a026261.exe",
  18. "Exes_4a9fa8b7f56205eee13d20211a026261Srv.exe",
  19. "DesktopLayer.exe"
  20.  
  21.  
  22. * Executed Commands:
  23. "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_4a9fa8b7f56205eee13d20211a026261Srv.exe",
  24. "C:\\Program Files (x86)\\Microsoft\\DesktopLayer.exe",
  25. "C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe"
  26.  
  27.  
  28. * Signatures Detected:
  29.  
  30. "Description": "Creates RWX memory",
  31. "Details":
  32.  
  33.  
  34. "Description": "Reads data out of its own binary image",
  35. "Details":
  36.  
  37. "self_read": "process: Exes_4a9fa8b7f56205eee13d20211a026261.exe, pid: 1640, offset: 0x00000000, length: 0x0019d8a4"
  38.  
  39.  
  40. "self_read": "process: Exes_4a9fa8b7f56205eee13d20211a026261.exe, pid: 1640, offset: 0x0001b01c, length: 0x0012c000"
  41.  
  42.  
  43. "self_read": "process: Exes_4a9fa8b7f56205eee13d20211a026261.exe, pid: 1640, offset: 0x0019d8a4, length: 0x00000004"
  44.  
  45.  
  46.  
  47.  
  48. "Description": "Drops a binary and executes it",
  49. "Details":
  50.  
  51. "binary": "C:\\Program Files (x86)\\Microsoft\\DesktopLayer.exe"
  52.  
  53.  
  54. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_4a9fa8b7f56205eee13d20211a026261Srv.exe"
  55.  
  56.  
  57.  
  58.  
  59. "Description": "Tries to suspend Cuckoo threads to prevent logging of malicious activity",
  60. "Details":
  61.  
  62. "Process": "DesktopLayer.exe (3032)"
  63.  
  64.  
  65.  
  66.  
  67. "Description": "File has been identified by 37 Antiviruses on VirusTotal as malicious",
  68. "Details":
  69.  
  70. "MicroWorld-eScan": "Dropped:Trojan.Zbot.IVF"
  71.  
  72.  
  73. "CAT-QuickHeal": "W32.Ramnit.A"
  74.  
  75.  
  76. "ALYac": "Dropped:Trojan.Zbot.IVF"
  77.  
  78.  
  79. "Malwarebytes": "HackTool.WinActivator"
  80.  
  81.  
  82. "TrendMicro": "PE_RAMNIT.H"
  83.  
  84.  
  85. "Baidu": "Multi.Threats.InArchive"
  86.  
  87.  
  88. "Cyren": "W32/Ramnit.B!Generic"
  89.  
  90.  
  91. "TrendMicro-HouseCall": "PE_RAMNIT.H"
  92.  
  93.  
  94. "Avast": "Win32:RmnDrp"
  95.  
  96.  
  97. "ClamAV": "Win.Trojan.Ramnit-1847"
  98.  
  99.  
  100. "Kaspersky": "Virus.Win32.Nimnul.a"
  101.  
  102.  
  103. "BitDefender": "Dropped:Trojan.Zbot.IVF"
  104.  
  105.  
  106. "NANO-Antivirus": "Virus.Win32.Nimnul.bpchjo"
  107.  
  108.  
  109. "Rising": "Ransom.PolyRansom!8.32D6 (CLOUD)"
  110.  
  111.  
  112. "Ad-Aware": "Dropped:Trojan.Zbot.IVF"
  113.  
  114.  
  115. "Sophos": "W32/Patched-I"
  116.  
  117.  
  118. "F-Secure": "Win32.Ramnit.Dam"
  119.  
  120.  
  121. "DrWeb": "Win32.Rmnet"
  122.  
  123.  
  124. "Emsisoft": "Dropped:Trojan.Zbot.IVF (B)"
  125.  
  126.  
  127. "Ikarus": "Virus.Ramnit"
  128.  
  129.  
  130. "F-Prot": "W32/Ramnit.B!Generic"
  131.  
  132.  
  133. "Jiangmin": "Win32/PatchFile.et"
  134.  
  135.  
  136. "Avira": "W32/Ramnit.CD"
  137.  
  138.  
  139. "MAX": "malware (ai score=94)"
  140.  
  141.  
  142. "Antiy-AVL": "Virus/Win32.Nimnul.a"
  143.  
  144.  
  145. "Arcabit": "Trojan.Zbot.IVF"
  146.  
  147.  
  148. "ZoneAlarm": "Virus.Win32.Nimnul.a"
  149.  
  150.  
  151. "Microsoft": "Virus:Win32/Vigorf.A"
  152.  
  153.  
  154. "VBA32": "Malware-Cryptor.Win32.073"
  155.  
  156.  
  157. "Zoner": "Win32.Agent.QFO"
  158.  
  159.  
  160. "ESET-NOD32": "Win32/Ramnit.A"
  161.  
  162.  
  163. "Tencent": "Win32.Virus.Nimnul.Pfad"
  164.  
  165.  
  166. "GData": "Dropped:Trojan.Zbot.IVF"
  167.  
  168.  
  169. "AVG": "Win32:RmnDrp"
  170.  
  171.  
  172. "Cybereason": "malicious.7f5620"
  173.  
  174.  
  175. "Paloalto": "generic.ml"
  176.  
  177.  
  178. "Qihoo-360": "Win32/Trojan.3c1"
  179.  
  180.  
  181.  
  182.  
  183. "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
  184. "Details":
  185.  
  186. "target": "clamav:Win.Trojan.Ramnit-1847, sha256:a94d83c7fb1bea5a111a7a8e9277183b958cd7930e6766468c48016669967795, type:PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive"
  187.  
  188.  
  189. "dropped": "clamav:Win.Trojan.Ramnit-1847, sha256:0249501ba5ea2cb21a1f4433a7840636db4f594af317312bc7c163991aba8e9d , guest_paths:C:\\Windows\\Temp\\\\xc3\\x90\\xc2\\xa1\\xc3\\x82\\xc3\\xad\\xc2\\xbc\\xc2\\xa4\\xc2\\xbb\\xc3\\xae\\xc2\\xb9\\xc2\\xa4\\xc2\\xbe\\xc3\\x9fOem7F7(\\xc3\\x8c\\xc3\\x98\\xc3\\x8a\\xc3\\xa2\\xc3\\x90\\xc3\\x8d).exe, type:PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive"
  190.  
  191.  
  192. "dropped": "clamav:Win.Trojan.Generic-53, sha256:fd6c69c345f1e32924f0a5bb7393e191b393a78d58e2c6413b03ced7482f2320 , guest_paths:C:\\Users\\user\\AppData\\Local\\Temp\\Exes_4a9fa8b7f56205eee13d20211a026261Srv.exe*C:\\Program Files (x86)\\Microsoft\\DesktopLayer.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed"
  193.  
  194.  
  195. "dropped": "clamav:Win.Trojan.Ramnit-1847, sha256:60b4baa11dcbcab53c55cf45d49b324a785c8cbf51c33ea97c38ed8f11d0e9c6 , guest_paths:C:\\Users\\user\\AppData\\Local\\Temp\\nsw1F34.tmp\\System.dll, type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows"
  196.  
  197.  
  198.  
  199.  
  200.  
  201. * Started Service:
  202.  
  203. * Mutexes:
  204. "KyUffThOkYwRRtgPP",
  205. "SAMPLE_MUTEX_Shelling"
  206.  
  207.  
  208. * Modified Files:
  209. "C:\\Users\\user\\AppData\\Local\\Temp\\nsg1F23.tmp",
  210. "C:\\Users\\user\\AppData\\Local\\Temp\\nsw1F34.tmp\\System.dll",
  211. "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_4a9fa8b7f56205eee13d20211a026261Srv.exe",
  212. "C:\\Windows\\Temp\\\\xc3\\x90\\xc2\\xa1\\xc3\\x82\\xc3\\xad\\xc2\\xbc\\xc2\\xa4\\xc2\\xbb\\xc3\\xae\\xc2\\xb9\\xc2\\xa4\\xc2\\xbe\\xc3\\x9fOem7F7(\\xc3\\x8c\\xc3\\x98\\xc3\\x8a\\xc3\\xa2\\xc3\\x90\\xc3\\x8d).exe",
  213. "C:\\Program Files (x86)\\Microsoft\\px1FCE.tmp",
  214. "C:\\Program Files (x86)\\Microsoft\\DesktopLayer.exe"
  215.  
  216.  
  217. * Deleted Files:
  218. "C:\\Users\\user\\AppData\\Local\\Temp\\nsr1EC5.tmp",
  219. "C:\\Users\\user\\AppData\\Local\\Temp\\nsw1F34.tmp",
  220. "C:\\Program Files (x86)\\Microsoft\\px1FCE.tmp"
  221.  
  222.  
  223. * Modified Registry Keys:
  224.  
  225. * Deleted Registry Keys:
  226.  
  227. * DNS Communications:
  228.  
  229. * Domains:
  230.  
  231. * Network Communication - ICMP:
  232.  
  233. * Network Communication - HTTP:
  234.  
  235. * Network Communication - SMTP:
  236.  
  237. * Network Communication - Hosts:
  238.  
  239. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment