Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Zenpak"
- * MalScore: 10.0
- * File Name: "Exes_613de73abe3865ee4adeee7813c7eddc.exe"
- * File Size: 420352
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "039e952cadb9e3933b298f13c50518793161420a7712a44afa443aab5e053392"
- * MD5: "613de73abe3865ee4adeee7813c7eddc"
- * SHA1: "ab2495c820f0e131ac7f2468be35f3e36a08fb89"
- * SHA512: "3f8f7bf5dd6edaba932d9457e18574b5d6a4f7c434a3eef6ee62499e842d7f70a409640faa15d5894c147013f515ac952ace4a746f00c84b27f5b4a362075ffd"
- * CRC32: "4FC8995C"
- * SSDEEP: "12288:pHw07KeqC5zRItV1QR15FjzDqjSpvt8TmutnxPolZ:pHh7pqC5aO15F3Jx7utnJo"
- * Process Execution:
- "Exes_613de73abe3865ee4adeee7813c7eddc.exe",
- "splwow64.exe"
- * Executed Commands:
- "C:\\Windows\\splwow64.exe 12288"
- * Signatures Detected:
- "Description": "Attempts to connect to a dead IP:Port (2 unique times)",
- "Details":
- "IP": "72.21.81.240:80"
- "IP": "192.35.177.64:80"
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Mimics the system's user agent string for its own requests",
- "Details":
- "Description": "Possible date expiration check, exits too soon after checking local time",
- "Details":
- "process": "Exes_613de73abe3865ee4adeee7813c7eddc.exe, PID 1380"
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://apps.identrust.com/roots/dstrootcax3.p7c"
- "url": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab"
- "Description": "Detects VirtualBox through the presence of a library",
- "Details":
- "Description": "File has been identified by 33 Antiviruses on VirusTotal as malicious",
- "Details":
- "MicroWorld-eScan": "Trojan.GenericKD.41460175"
- "FireEye": "Generic.mg.613de73abe3865ee"
- "McAfee": "RDN/Generic.ole"
- "CrowdStrike": "win/malicious_confidence_100% (W)"
- "Alibaba": "Trojan:Win32/Zenpak.5a3cfabe"
- "Arcabit": "Trojan.Generic.D278A1CF"
- "TrendMicro": "TROJ_GEN.R04AC0WGE19"
- "Symantec": "Trojan Horse"
- "APEX": "Malicious"
- "Kaspersky": "Trojan.Win32.Zenpak.fix"
- "BitDefender": "Trojan.GenericKD.41460175"
- "Avast": "Win32:Trojan-gen"
- "Tencent": "Win32.Trojan.Zenpak.Wlfp"
- "Endgame": "malicious (high confidence)"
- "Emsisoft": "Trojan.GenericKD.41460175 (B)"
- "Invincea": "heuristic"
- "McAfee-GW-Edition": "BehavesLike.Win32.Ransom.gh"
- "Sophos": "Mal/Generic-S"
- "Avira": "TR/AD.MalwareCrypter.gzfzk"
- "Microsoft": "Trojan:Win32/Tiggre!plock"
- "ZoneAlarm": "Trojan.Win32.Zenpak.fix"
- "GData": "Win32.Packed.Kryptik.HIADUV"
- "AhnLab-V3": "Malware/Win32.Generic.C3335991"
- "Acronis": "suspicious"
- "Ad-Aware": "Trojan.GenericKD.41460175"
- "Malwarebytes": "Trojan.Crypt"
- "ESET-NOD32": "a variant of Win32/GenKryptik.DNEI"
- "TrendMicro-HouseCall": "TROJ_GEN.R04AC0WGE19"
- "Ikarus": "Trojan.Win32.Krypt"
- "Fortinet": "W32/Zenpak.DNEI!tr"
- "AVG": "Win32:Trojan-gen"
- "Panda": "Trj/CI.A"
- "Qihoo-360": "Win32/Trojan.4d9"
- * Started Service:
- * Mutexes:
- "Local\\WinSpl64To32Mutex_1d3fb_0_3000",
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\aptitudes Japan prtends",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\E0F5C59F9FA661F6F4C50B87FEF3A15A",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\E0F5C59F9FA661F6F4C50B87FEF3A15A",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\94308059B57B3142E455B38A6EB92015",
- "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\94308059B57B3142E455B38A6EB92015"
- * Deleted Files:
- * Modified Registry Keys:
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Code Store Database\\NT5LockDownTest"
- * Deleted Registry Keys:
- * DNS Communications:
- "type": "A",
- "request": "adminfinacex.com",
- "answers":
- "data": "192.64.116.142",
- "type": "A"
- "type": "A",
- "request": "apps.identrust.com",
- "answers":
- "data": "192.35.177.64",
- "type": "A"
- "data": "apps.digsigtrust.com",
- "type": "CNAME"
- * Domains:
- "ip": "192.35.177.64",
- "domain": "apps.identrust.com"
- "ip": "192.64.116.142",
- "domain": "adminfinacex.com"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 1,
- "body": "",
- "uri": "http://apps.identrust.com/roots/dstrootcax3.p7c",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "apps.identrust.com",
- "version": "1.1",
- "path": "/roots/dstrootcax3.p7c",
- "data": "GET /roots/dstrootcax3.p7c HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: apps.identrust.com\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "www.download.windowsupdate.com",
- "version": "1.1",
- "path": "/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
- "data": "GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1\r\nCache-Control: max-age = 86400\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Fri, 22 Feb 2019 16:53:13 GMT\r\nIf-None-Match: \"80e22c19cfcad41:0\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: www.download.windowsupdate.com\r\n\r\n",
- "port": 80
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment