Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Malicious"
- * MalScore: 10.0
- * File Name: "FTPxWIN-sctned.exe"
- * File Size: 387876
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "5029ac35429825628a6332a62c5ca054c46b0108c986171906ae23bce3bc105a"
- * MD5: "5cd41461efba56186607acb3d62474b4"
- * SHA1: "de62696ac23d29e70fc69574a7851a05cda910a3"
- * SHA512: "35746bb14d20acaf8fc73c38e13783b06ba6a965357f7d091e5371e4d9a58ccd1e5f8b8489607829b58e06e1295b15ecb9738b9e36399ff75368675ef1f3acbf"
- * CRC32: "D744A231"
- * SSDEEP: "6144:JsCwu+mWhJifvtNP/7YXSLB80PbstY0c9diGYOi/p/fPvt2u5+KIohR3pK0qXh:+xmIJQvPkit5yY0c9diGYOi/p/fPvt2x"
- * Process Execution:
- "FTPxWIN-sctned.exe"
- * Executed Commands:
- * Signatures Detected:
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00000000, length: 0x00000007"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00000000, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00000007, length: 0x0005eb1d"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00001ff0, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00003fe0, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00005fd0, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00007fc0, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00009fb0, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x0000bfa0, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x0000df90, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x0000ff80, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00011f70, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00013f60, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00015f50, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00017f40, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00019f30, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x0001bf20, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x0001df10, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x0001ff00, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00021ef0, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00023ee0, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00025ed0, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00027ec0, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00029eb0, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x0002bea0, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x0002de90, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x0002fe80, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00031e70, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00033e60, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00035e50, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00037e40, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00039e30, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x0003be20, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x0003de10, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x0003fe00, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00041df0, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00043de0, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00045dd0, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00047dc0, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00049db0, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x0004bda0, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x0004dd90, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x0004fd80, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00051d70, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00053d60, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00055d50, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00057d40, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x00059d30, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x0005bd20, length: 0x00002000"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x0005ca00, length: 0x00000030"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x0005ca18, length: 0x000020c3"
- "self_read": "process: FTPxWIN-sctned.exe, pid: 996, offset: 0x0005eb1c, length: 0x00000008"
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\bT3NEfMGHNBatch58.vbe"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\__tmp_rar_sfx_access_check_13055328"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\bT3NEfMGHNBatch58.vbe"
- "Description": "File has been identified by 12 Antiviruses on VirusTotal as malicious",
- "Details":
- "FireEye": "Generic.mg.5cd41461efba5618"
- "Cybereason": "malicious.ac23d2"
- "APEX": "Malicious"
- "Kaspersky": "UDS:DangerousObject.Multi.Generic"
- "NANO-Antivirus": "Trojan.Script.ExpKit.eurlzq"
- "Endgame": "malicious (moderate confidence)"
- "Invincea": "heuristic"
- "McAfee-GW-Edition": "BehavesLike.Win32.Backdoor.fh"
- "ZoneAlarm": "HEUR:Trojan-Downloader.Script.Generic"
- "Acronis": "suspicious"
- "CrowdStrike": "win/malicious_confidence_70% (D)"
- "Qihoo-360": "HEUR/QVM10.1.C937.Malware.Gen"
- * Started Service:
- * Mutexes:
- "DefaultTabtip-MainUI",
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\__tmp_rar_sfx_access_check_13055328",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\bT3NEfMGHNBatch58.vbe"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\__tmp_rar_sfx_access_check_13055328"
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\WinRAR SFX",
- "HKEY_CURRENT_USER\\Software\\WinRAR SFX\\C%%Users%user%AppData%Roaming%Microsoft%Windows%Start Menu%Programs%Startup"
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment