Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: ""
- * MalScore: 7.0
- * File Name: "Exes_a69ffd76d836c0aa7e399309afea6555.exe"
- * File Size: 184320
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "7299715a52cb70ae74c35539de0cb2cd4e9e48861c46542648d1a3cd4414def4"
- * MD5: "a69ffd76d836c0aa7e399309afea6555"
- * SHA1: "227df5925ab9e3744c338b7719b45114b64bc3a8"
- * SHA512: "500f74767c33031319f83366fb0db152930970e1cd19becbd511c3be43bfadbd74e96196127847c09f196455f5a2dc89d55d1dddc3ecbb4cfea3fa680e016359"
- * CRC32: "5F75DFDA"
- * SSDEEP: "3072:VmtqxrrQEjmD2e8eo8imNNMiePZ3EiN8Xy5:vrr3Kl838jNMjZ3/N9"
- * Process Execution:
- "Exes_a69ffd76d836c0aa7e399309afea6555.exe",
- "cmd.exe",
- "services.exe",
- "systeminfo.exe",
- "svchost.exe",
- "svchost.exe",
- "WMIADAP.exe"
- * Executed Commands:
- "\"C:\\Windows\\system32\\cmd.exe\" /c del C:\\Users\\user\\AppData\\Local\\Temp\\EXES_A~1.EXE > nul",
- "C:\\Windows\\System32\\cmd.exe /c del C:\\Users\\user\\AppData\\Local\\Temp\\EXES_A~1.EXE > nul",
- "C:\\Windows\\SysWOW64\\systeminfo.exe",
- "C:\\Windows\\system32\\svchost.exe -k netsvcs",
- "\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE wmiadap.exe /F /T /R"
- * Signatures Detected:
- "Description": "A process created a hidden window",
- "Details":
- "Process": "Exes_a69ffd76d836c0aa7e399309afea6555.exe -> C:\\Windows\\System32\\cmd.exe"
- "Process": "svchost.exe -> \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE"
- "Description": "Deletes its original binary from disk",
- "Details":
- "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
- "Details":
- "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 17778120 times"
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "service name": "dazsks gmeakjwxo"
- "service path": "C:\\Windows\\system32\\systeminfo.exe"
- * Started Service:
- "dazsks gmeakjwxo"
- * Mutexes:
- "Local\\ZoneAttributeCacheCounterMutex",
- "Local\\ZonesCacheCounterMutex",
- "Local\\ZonesLockedCacheCounterMutex",
- "Global\\ADAP_WMI_ENTRY",
- "Global\\RefreshRA_Mutex",
- "Global\\RefreshRA_Mutex_Lib",
- "Global\\RefreshRA_Mutex_Flag"
- * Modified Files:
- "C:\\Windows\\System32\\systeminfo.exe",
- "\\??\\WMIDataDevice",
- "\\??\\PIPE\\samr",
- "C:\\Windows\\sysnative\\wbem\\repository\\WRITABLE.TST",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING1.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING2.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING3.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\OBJECTS.DATA",
- "C:\\Windows\\sysnative\\wbem\\repository\\INDEX.BTR",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
- "\\??\\nul",
- "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl_new.h"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_a69ffd76d836c0aa7e399309afea6555.exe"
- * Modified Registry Keys:
- "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\dazsks gmeakjwxo",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dazsks gmeakjwxo\\MarkTime",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Type",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ProcessID",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ThrottleDrege",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Parameters\\ServiceDllUnloadOnStop",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Wbem\\Transports\\Decoupled\\Server",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\CreationTime",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\MarshaledProxy",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\ProcessIdentifier",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ConfigValueEssNeedsLoading",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\List of event-active namespaces",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\ESS\\//./root/CIMV2\\SCM Event Provider"
- * Deleted Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName"
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Add Comment
Please, Sign In to add comment