paladin316

Exes_a69ffd76d836c0aa7e399309afea6555_exe_2019-07-10_02_30.txt

Jul 9th, 2019
2,141
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.39 KB | None | 0 0
  1.  
  2. * MalFamily: ""
  3.  
  4. * MalScore: 7.0
  5.  
  6. * File Name: "Exes_a69ffd76d836c0aa7e399309afea6555.exe"
  7. * File Size: 184320
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "7299715a52cb70ae74c35539de0cb2cd4e9e48861c46542648d1a3cd4414def4"
  10. * MD5: "a69ffd76d836c0aa7e399309afea6555"
  11. * SHA1: "227df5925ab9e3744c338b7719b45114b64bc3a8"
  12. * SHA512: "500f74767c33031319f83366fb0db152930970e1cd19becbd511c3be43bfadbd74e96196127847c09f196455f5a2dc89d55d1dddc3ecbb4cfea3fa680e016359"
  13. * CRC32: "5F75DFDA"
  14. * SSDEEP: "3072:VmtqxrrQEjmD2e8eo8imNNMiePZ3EiN8Xy5:vrr3Kl838jNMjZ3/N9"
  15.  
  16. * Process Execution:
  17. "Exes_a69ffd76d836c0aa7e399309afea6555.exe",
  18. "cmd.exe",
  19. "services.exe",
  20. "systeminfo.exe",
  21. "svchost.exe",
  22. "svchost.exe",
  23. "WMIADAP.exe"
  24.  
  25.  
  26. * Executed Commands:
  27. "\"C:\\Windows\\system32\\cmd.exe\" /c del C:\\Users\\user\\AppData\\Local\\Temp\\EXES_A~1.EXE > nul",
  28. "C:\\Windows\\System32\\cmd.exe /c del C:\\Users\\user\\AppData\\Local\\Temp\\EXES_A~1.EXE > nul",
  29. "C:\\Windows\\SysWOW64\\systeminfo.exe",
  30. "C:\\Windows\\system32\\svchost.exe -k netsvcs",
  31. "\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE wmiadap.exe /F /T /R"
  32.  
  33.  
  34. * Signatures Detected:
  35.  
  36. "Description": "A process created a hidden window",
  37. "Details":
  38.  
  39. "Process": "Exes_a69ffd76d836c0aa7e399309afea6555.exe -> C:\\Windows\\System32\\cmd.exe"
  40.  
  41.  
  42. "Process": "svchost.exe -> \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE"
  43.  
  44.  
  45.  
  46.  
  47. "Description": "Deletes its original binary from disk",
  48. "Details":
  49.  
  50.  
  51. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  52. "Details":
  53.  
  54. "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 17778120 times"
  55.  
  56.  
  57.  
  58.  
  59. "Description": "Installs itself for autorun at Windows startup",
  60. "Details":
  61.  
  62. "service name": "dazsks gmeakjwxo"
  63.  
  64.  
  65. "service path": "C:\\Windows\\system32\\systeminfo.exe"
  66.  
  67.  
  68.  
  69.  
  70.  
  71. * Started Service:
  72. "dazsks gmeakjwxo"
  73.  
  74.  
  75. * Mutexes:
  76. "Local\\ZoneAttributeCacheCounterMutex",
  77. "Local\\ZonesCacheCounterMutex",
  78. "Local\\ZonesLockedCacheCounterMutex",
  79. "Global\\ADAP_WMI_ENTRY",
  80. "Global\\RefreshRA_Mutex",
  81. "Global\\RefreshRA_Mutex_Lib",
  82. "Global\\RefreshRA_Mutex_Flag"
  83.  
  84.  
  85. * Modified Files:
  86. "C:\\Windows\\System32\\systeminfo.exe",
  87. "\\??\\WMIDataDevice",
  88. "\\??\\PIPE\\samr",
  89. "C:\\Windows\\sysnative\\wbem\\repository\\WRITABLE.TST",
  90. "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING1.MAP",
  91. "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING2.MAP",
  92. "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING3.MAP",
  93. "C:\\Windows\\sysnative\\wbem\\repository\\OBJECTS.DATA",
  94. "C:\\Windows\\sysnative\\wbem\\repository\\INDEX.BTR",
  95. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER",
  96. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
  97. "\\??\\nul",
  98. "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl_new.h"
  99.  
  100.  
  101. * Deleted Files:
  102. "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_a69ffd76d836c0aa7e399309afea6555.exe"
  103.  
  104.  
  105. * Modified Registry Keys:
  106. "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\dazsks gmeakjwxo",
  107. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dazsks gmeakjwxo\\MarkTime",
  108. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
  109. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
  110. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Type",
  111. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ProcessID",
  112. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ThrottleDrege",
  113. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Parameters\\ServiceDllUnloadOnStop",
  114. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
  115. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Wbem\\Transports\\Decoupled\\Server",
  116. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\CreationTime",
  117. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\MarshaledProxy",
  118. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\ProcessIdentifier",
  119. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ConfigValueEssNeedsLoading",
  120. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\List of event-active namespaces",
  121. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\ESS\\//./root/CIMV2\\SCM Event Provider"
  122.  
  123.  
  124. * Deleted Registry Keys:
  125. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  126. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  127. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  128. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName"
  129.  
  130.  
  131. * DNS Communications:
  132.  
  133. * Domains:
  134.  
  135. * Network Communication - ICMP:
  136.  
  137. * Network Communication - HTTP:
  138.  
  139. * Network Communication - SMTP:
  140.  
  141. * Network Communication - Hosts:
  142.  
  143. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment