Advertisement
thlnk3r

removeAttr.scr-03072016

Mar 7th, 2016
555
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.79 KB | None | 0 0
  1. Online Analysis:
  2. https://www.hybrid-analysis.com/sample/b66d3904c6cbbdedc880d9784e8b028f2d59278def689ad995c93a1b2aebbac5?environmentId=1
  3.  
  4. Virustotal:
  5. https://www.virustotal.com/en/file/b66d3904c6cbbdedc880d9784e8b028f2d59278def689ad995c93a1b2aebbac5/analysis/1457385949/
  6.  
  7. --- VxStream Sandbox Analysis Summary ---
  8.  
  9. File Name: removeAttr.scr
  10. Analysis State: SUCCESS
  11. Threat Verdict: malicious
  12. Threat Score: 86/100
  13. AV Detection Ratio: 7%
  14. AV Family Name: BehavesLike.Expiro
  15. Time of analysis: 2016-03-07 15:08:13
  16. File Size (bytes): 197120
  17. File Type: PE32 executable (GUI) Intel 80386, for MS Windows
  18. Contacted Domains: none
  19. Contacted Hosts: 89.108.85.163
  20. Environment: Windows 7 32 bit - Usermode Monitor (EID: 1)
  21.  
  22. Recovery Instructions:
  23. !!! IMPORTANT INFORMATION !!!!
  24.  
  25. All of your files are encrypted with RSA-2048 and AES-128 ciphers.
  26. More information about the RSA and AES can be found here:
  27. http://en.wikipedia.org/wiki/RSA_(cryptosystem)
  28. http://en.wikipedia.org/wiki/Advanced_Encryption_Standard
  29.  
  30. Decrypting of your files is only possible with the private key and decrypt program, which is on our secret server.
  31. To receive your private key follow one of the links:
  32. 1. http://i3ezlvkoi7fwyood.tor2web.org/32C0D883E1644D0A
  33. 2. http://i3ezlvkoi7fwyood.onion.to/32C0D883E1644D0A
  34. 3. http://i3ezlvkoi7fwyood.onion.cab/32C0D883E1644D0A
  35.  
  36. If all of this addresses are not available, follow these steps:
  37. 1. Download and install Tor Browser: https://www.torproject.org/download/download-easy.html
  38. 2. After a successful installation, run the browser and wait for initialization.
  39. 3. Type in the address bar: i3ezlvkoi7fwyood.onion/32C0D883E1644D0A
  40. 4. Follow the instructions on the site.
  41.  
  42. !!! Your personal identification ID: 32C0D883E1644D0A !!!
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement