paladin316

Exes_6740d71b001ec5223840697ccc4e45e8_exe_2019-07-19_17_30.txt

Jul 19th, 2019
2,377
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 13.76 KB | None | 0 0
  1.  
  2. * MalFamily: "Malware-gen"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_6740d71b001ec5223840697ccc4e45e8.exe"
  7. * File Size: 1902080
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "97b4385cf3cca677da6cfa4fbba2927e350e6144e388cdcca2e615d0066d1536"
  10. * MD5: "6740d71b001ec5223840697ccc4e45e8"
  11. * SHA1: "06d35c8d144c72c311c4cbf5e60be6d69142929e"
  12. * SHA512: "e5f2a1db3f9ccd2fdc053cd15b37ba4c3fac2990ec64be1a90992b1238bd1232347c87931de65aa61f81c6851ea53d7acd6e6433bbf29f99ba731c091dc77739"
  13. * CRC32: "AB5DF764"
  14. * SSDEEP: "49152:sLjX0CsZAA3HyKxZtIrdgRu+J2eSt+xRNvxXu8iRLNI:sHXVoHjZt8Wce795e"
  15.  
  16. * Process Execution:
  17. "Exes_6740d71b001ec5223840697ccc4e45e8.exe",
  18. "notepad.exe",
  19. "cmd.exe",
  20. "wscript.exe",
  21. "notepad.exe"
  22.  
  23.  
  24. * Executed Commands:
  25. "\"C:\\Windows\\notepad.exe\" -c \"C:\\ProgramData\\IlKTmhStyg\\cfgi\"",
  26. "cmd.exe /C WScript \"C:\\ProgramData\\IlKTmhStyg\\r.vbs\"",
  27. "\"C:\\Windows\\notepad.exe\" -c \"C:\\ProgramData\\IlKTmhStyg\\cfg\"",
  28. "C:\\Windows\\system32\\wscript.exe WScript \"C:\\ProgramData\\IlKTmhStyg\\r.vbs\""
  29.  
  30.  
  31. * Signatures Detected:
  32.  
  33. "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
  34. "Details":
  35.  
  36. "IP": "193.32.161.73:7777"
  37.  
  38.  
  39.  
  40.  
  41. "Description": "Creates RWX memory",
  42. "Details":
  43.  
  44.  
  45. "Description": "Detected script timer window indicative of sleep style evasion",
  46. "Details":
  47.  
  48. "Window": "WSH-Timer"
  49.  
  50.  
  51.  
  52.  
  53. "Description": "At least one IP Address, Domain, or File Name was found in a crypto call",
  54. "Details":
  55.  
  56. "ioc": "r.9z"
  57.  
  58.  
  59. "ioc": "fitovov.exe"
  60.  
  61.  
  62. "ioc": "32.dll"
  63.  
  64.  
  65. "ioc": "9.06.8"
  66.  
  67.  
  68. "ioc": "6..2"
  69.  
  70.  
  71. "ioc": "2.92"
  72.  
  73.  
  74. "ioc": "4.77"
  75.  
  76.  
  77. "ioc": "2-.51"
  78.  
  79.  
  80. "ioc": "7.81"
  81.  
  82.  
  83. "ioc": "3.0."
  84.  
  85.  
  86. "ioc": "4.812"
  87.  
  88.  
  89. "ioc": "-.5."
  90.  
  91.  
  92. "ioc": "3.47"
  93.  
  94.  
  95. "ioc": "2.4.7"
  96.  
  97.  
  98. "ioc": "5.99"
  99.  
  100.  
  101. "ioc": "0.70"
  102.  
  103.  
  104. "ioc": "..78"
  105.  
  106.  
  107. "ioc": "761-84.88"
  108.  
  109.  
  110. "ioc": "8.62"
  111.  
  112.  
  113. "ioc": "8.235"
  114.  
  115.  
  116. "ioc": "4.06"
  117.  
  118.  
  119. "ioc": "4.28"
  120.  
  121.  
  122. "ioc": "..25"
  123.  
  124.  
  125. "ioc": "45.34"
  126.  
  127.  
  128. "ioc": "8.31"
  129.  
  130.  
  131. "ioc": "0.99"
  132.  
  133.  
  134. "ioc": "4.03"
  135.  
  136.  
  137. "ioc": "5..1"
  138.  
  139.  
  140. "ioc": "1.9.-"
  141.  
  142.  
  143. "ioc": "1.57"
  144.  
  145.  
  146. "ioc": "7.73:7"
  147.  
  148.  
  149. "ioc": "8.80"
  150.  
  151.  
  152. "ioc": "-.47"
  153.  
  154.  
  155. "ioc": "3.86"
  156.  
  157.  
  158. "ioc": "63.73"
  159.  
  160.  
  161. "ioc": "9.54"
  162.  
  163.  
  164. "ioc": "34.7."
  165.  
  166.  
  167. "ioc": "-.286"
  168.  
  169.  
  170. "ioc": "39.231"
  171.  
  172.  
  173. "ioc": "2.25"
  174.  
  175.  
  176. "ioc": "0.84/6"
  177.  
  178.  
  179. "ioc": "4.79"
  180.  
  181.  
  182. "ioc": "..83"
  183.  
  184.  
  185. "ioc": "4.38"
  186.  
  187.  
  188. "ioc": "4.34"
  189.  
  190.  
  191. "ioc": "0.84"
  192.  
  193.  
  194. "ioc": "5.13"
  195.  
  196.  
  197. "ioc": "3.66"
  198.  
  199.  
  200. "ioc": "3.94"
  201.  
  202.  
  203. "ioc": "65..53"
  204.  
  205.  
  206. "ioc": "..2."
  207.  
  208.  
  209. "ioc": "2.70"
  210.  
  211.  
  212. "ioc": "2.59"
  213.  
  214.  
  215. "ioc": "9.99"
  216.  
  217.  
  218. "ioc": "6.05"
  219.  
  220.  
  221. "ioc": "36.28"
  222.  
  223.  
  224. "ioc": "..840"
  225.  
  226.  
  227. "ioc": "8.0."
  228.  
  229.  
  230. "ioc": "8.75"
  231.  
  232.  
  233. "ioc": "0.1."
  234.  
  235.  
  236. "ioc": "1.69"
  237.  
  238.  
  239. "ioc": "7.935"
  240.  
  241.  
  242. "ioc": "6.82"
  243.  
  244.  
  245. "ioc": "84.43"
  246.  
  247.  
  248. "ioc": "1.474."
  249.  
  250.  
  251. "ioc": "44.70"
  252.  
  253.  
  254. "ioc": "3-.67"
  255.  
  256.  
  257. "ioc": "..41"
  258.  
  259.  
  260. "ioc": "5.03"
  261.  
  262.  
  263. "ioc": "24.3536"
  264.  
  265.  
  266. "ioc": "5.9."
  267.  
  268.  
  269. "ioc": "-.468"
  270.  
  271.  
  272. "ioc": "1..4"
  273.  
  274.  
  275. "ioc": "-.588"
  276.  
  277.  
  278. "ioc": "7.87"
  279.  
  280.  
  281. "ioc": "3.92"
  282.  
  283.  
  284. "ioc": "6..68"
  285.  
  286.  
  287. "ioc": "1.45"
  288.  
  289.  
  290. "ioc": "7.1."
  291.  
  292.  
  293. "ioc": "7.36"
  294.  
  295.  
  296. "ioc": "--.91"
  297.  
  298.  
  299. "ioc": "10.18"
  300.  
  301.  
  302. "ioc": "8.13"
  303.  
  304.  
  305. "ioc": "9.08"
  306.  
  307.  
  308. "ioc": "-.24"
  309.  
  310.  
  311. "ioc": "1.89"
  312.  
  313.  
  314.  
  315.  
  316. "Description": "Repeatedly searches for a not-found process, may want to run with startbrowser=1 option",
  317. "Details":
  318.  
  319.  
  320. "Description": "Reads data out of its own binary image",
  321. "Details":
  322.  
  323. "self_read": "process: Exes_6740d71b001ec5223840697ccc4e45e8.exe, pid: 2556, offset: 0x00000000, length: 0x001cde00"
  324.  
  325.  
  326. "self_read": "process: wscript.exe, pid: 1232, offset: 0x00000000, length: 0x00000040"
  327.  
  328.  
  329. "self_read": "process: wscript.exe, pid: 1232, offset: 0x000000f0, length: 0x00000018"
  330.  
  331.  
  332. "self_read": "process: wscript.exe, pid: 1232, offset: 0x000001e8, length: 0x00000078"
  333.  
  334.  
  335. "self_read": "process: wscript.exe, pid: 1232, offset: 0x00018000, length: 0x00000020"
  336.  
  337.  
  338. "self_read": "process: wscript.exe, pid: 1232, offset: 0x00018058, length: 0x00000018"
  339.  
  340.  
  341. "self_read": "process: wscript.exe, pid: 1232, offset: 0x000181a8, length: 0x00000018"
  342.  
  343.  
  344. "self_read": "process: wscript.exe, pid: 1232, offset: 0x00018470, length: 0x00000010"
  345.  
  346.  
  347. "self_read": "process: wscript.exe, pid: 1232, offset: 0x00018640, length: 0x00000012"
  348.  
  349.  
  350.  
  351.  
  352. "Description": "A process created a hidden window",
  353. "Details":
  354.  
  355. "Process": "Exes_6740d71b001ec5223840697ccc4e45e8.exe -> cmd.exe /C WScript \"C:\\ProgramData\\IlKTmhStyg\\r.vbs\""
  356.  
  357.  
  358.  
  359.  
  360. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  361. "Details":
  362.  
  363. "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
  364.  
  365.  
  366. "suspicious_request": "http://193.32.161.73/update.txt"
  367.  
  368.  
  369.  
  370.  
  371. "Description": "Performs some HTTP requests",
  372. "Details":
  373.  
  374. "url": "http://193.32.161.73/update.txt"
  375.  
  376.  
  377.  
  378.  
  379. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  380. "Details":
  381.  
  382. "Spam": "Exes_6740d71b001ec5223840697ccc4e45e8.exe (2556) called API GlobalMemoryStatus 416539 times"
  383.  
  384.  
  385. "Spam": "Exes_6740d71b001ec5223840697ccc4e45e8.exe (2556) called API NtOpenFile 445615 times"
  386.  
  387.  
  388.  
  389.  
  390. "Description": "Installs itself for autorun at Windows startup",
  391. "Details":
  392.  
  393. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\KmJlZQXSMi.url"
  394.  
  395.  
  396. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\KmJlZQXSMi.url"
  397.  
  398.  
  399.  
  400.  
  401. "Description": "File has been identified by 37 Antiviruses on VirusTotal as malicious",
  402. "Details":
  403.  
  404. "MicroWorld-eScan": "Trojan.GenericKD.41477142"
  405.  
  406.  
  407. "FireEye": "Generic.mg.6740d71b001ec522"
  408.  
  409.  
  410. "McAfee": "Artemis!6740D71B001E"
  411.  
  412.  
  413. "SUPERAntiSpyware": "Trojan.Agent/Gen-Dropper"
  414.  
  415.  
  416. "K7GW": "Trojan ( 00552cd41 )"
  417.  
  418.  
  419. "K7AntiVirus": "Trojan ( 00552cd41 )"
  420.  
  421.  
  422. "Invincea": "heuristic"
  423.  
  424.  
  425. "Symantec": "Trojan.Gen.2"
  426.  
  427.  
  428. "APEX": "Malicious"
  429.  
  430.  
  431. "Avast": "Win32:Malware-gen"
  432.  
  433.  
  434. "Kaspersky": "Trojan.Win32.Agent.xaaqwi"
  435.  
  436.  
  437. "BitDefender": "Trojan.GenericKD.41477142"
  438.  
  439.  
  440. "Paloalto": "generic.ml"
  441.  
  442.  
  443. "AegisLab": "Trojan.Multi.Generic.4!c"
  444.  
  445.  
  446. "Endgame": "malicious (high confidence)"
  447.  
  448.  
  449. "Emsisoft": "Trojan.GenericKD.41477142 (B)"
  450.  
  451.  
  452. "F-Secure": "Trojan.TR/Crypt.XPACK.sheua"
  453.  
  454.  
  455. "McAfee-GW-Edition": "BehavesLike.Win32.Pykse.th"
  456.  
  457.  
  458. "Sophos": "Mal/Generic-S"
  459.  
  460.  
  461. "SentinelOne": "DFI - Suspicious PE"
  462.  
  463.  
  464. "Webroot": "W32.Trojan.Gen"
  465.  
  466.  
  467. "Avira": "TR/Crypt.XPACK.sheua"
  468.  
  469.  
  470. "Microsoft": "Trojan:Win32/Wacatac.B!ml"
  471.  
  472.  
  473. "ZoneAlarm": "Trojan.Win32.Agent.xaaqwi"
  474.  
  475.  
  476. "GData": "Win32.Packed.Kryptik.D9AUR3"
  477.  
  478.  
  479. "Acronis": "suspicious"
  480.  
  481.  
  482. "MAX": "malware (ai score=99)"
  483.  
  484.  
  485. "Ad-Aware": "Trojan.GenericKD.32162811"
  486.  
  487.  
  488. "Malwarebytes": "Trojan.MalPack.GS"
  489.  
  490.  
  491. "ESET-NOD32": "a variant of Win32/Kryptik.GUSN"
  492.  
  493.  
  494. "Rising": "[email protected] (RDML:1N9+fflM35HOaygW9m1/9Q)"
  495.  
  496.  
  497. "Ikarus": "Trojan.Win32.Crypt"
  498.  
  499.  
  500. "Fortinet": "W32/GenKryptik.DNNQ!tr"
  501.  
  502.  
  503. "AVG": "Win32:Malware-gen"
  504.  
  505.  
  506. "Cybereason": "malicious.d144c7"
  507.  
  508.  
  509. "CrowdStrike": "win/malicious_confidence_60% (W)"
  510.  
  511.  
  512. "Qihoo-360": "HEUR/QVM10.2.98C7.Malware.Gen"
  513.  
  514.  
  515.  
  516.  
  517. "Description": "Anomalous binary characteristics",
  518. "Details":
  519.  
  520. "anomaly": "Found duplicated section names"
  521.  
  522.  
  523.  
  524.  
  525.  
  526. * Started Service:
  527.  
  528. * Mutexes:
  529. "4bc51895c182ff487f0e"
  530.  
  531.  
  532. * Modified Files:
  533. "C:\\ProgramData\\IlKTmhStyg\\sysdrv32.exe",
  534. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\KmJlZQXSMi.url"
  535.  
  536.  
  537. * Deleted Files:
  538. "C:\\ProgramData\\IlKTmhStyg\\r.vbs",
  539. "C:\\ProgramData\\IlKTmhStyg\\sysdrv32.exe",
  540. "C:\\ProgramData\\IlKTmhStyg\\sysdrv32"
  541.  
  542.  
  543. * Modified Registry Keys:
  544.  
  545. * Deleted Registry Keys:
  546.  
  547. * DNS Communications:
  548.  
  549. * Domains:
  550.  
  551. * Network Communication - ICMP:
  552.  
  553. * Network Communication - HTTP:
  554.  
  555. "count": 2,
  556. "body": "",
  557. "uri": "http://193.32.161.73/update.txt",
  558. "user-agent": "WinInetGet/0.1",
  559. "method": "GET",
  560. "host": "193.32.161.73",
  561. "version": "1.1",
  562. "path": "/update.txt",
  563. "data": "GET /update.txt HTTP/1.1\r\nAccept: text/*, application/exe, application/zlib, application/gzip, application/applefile\r\nUser-Agent: WinInetGet/0.1\r\nHost: 193.32.161.73\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  564. "port": 80
  565.  
  566.  
  567.  
  568. * Network Communication - SMTP:
  569.  
  570. * Network Communication - Hosts:
  571.  
  572. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment