Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Zpevdo"
- * MalScore: 10.0
- * File Name: "Exes_e5d522f99fc5a02a44ae263252a0298b.exe"
- * File Size: 4803168
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "97c4ddf913a08529ae83d035ae47a2c99b8721bfabb4d51200159ec99a752773"
- * MD5: "e5d522f99fc5a02a44ae263252a0298b"
- * SHA1: "8bc6d637950a6f81174555c6a2d09140c76d81a1"
- * SHA512: "507701310d18439b2960f011a0d62e8b2dea2e2aeed7f0a867675cc847645ff6fba4cd39a21ca346b12562e8766d26e3398008611394659f8567599a0ffc4605"
- * CRC32: "80E649F0"
- * SSDEEP: "98304:Gb7OWvxKJ0QXurxr/pnHUzV68E4LbWeF6xEdruKK+oTD4g8S:o7RZK+2YxrpnkVNZLbWeMqruKK+oTkgj"
- * Process Execution:
- "Exes_e5d522f99fc5a02a44ae263252a0298b.exe"
- * Executed Commands:
- * Signatures Detected:
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: Exes_e5d522f99fc5a02a44ae263252a0298b.exe, pid: 2688, offset: 0x000003f4, length: 0x001e808c"
- "self_read": "process: Exes_e5d522f99fc5a02a44ae263252a0298b.exe, pid: 2688, offset: 0x00048006, length: 0x00012e52"
- "Description": "File has been identified by 11 Antiviruses on VirusTotal as malicious",
- "Details":
- "CAT-QuickHeal": "Trojan.Multi"
- "McAfee": "Artemis!E5D522F99FC5"
- "Cylance": "Unsafe"
- "Kaspersky": "UDS:DangerousObject.Multi.Generic"
- "AegisLab": "Trojan.Multi.Generic.4!c"
- "DrWeb": "Trojan.PWS.Stealer.26633"
- "McAfee-GW-Edition": "Artemis!Trojan"
- "CMC": "Trojan.Win32.Swizzor.2!O"
- "Jiangmin": "Trojan.Selfdel.hqv"
- "Microsoft": "Trojan:Win32/Zpevdo.B"
- "eGambit": "PE.Heur.InvalidSig"
- * Started Service:
- * Mutexes:
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1"
- * Modified Files:
- * Deleted Files:
- * Modified Registry Keys:
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment