Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Chapak"
- * MalScore: 10.0
- * File Name: "Exes_f104480eee65d69032f6ba6b26a3dcc4.exe"
- * File Size: 2795776
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "deb1b68a1b27087c80600887413199c3a9f4cc41026bec91413735ada7cbe72e"
- * MD5: "f104480eee65d69032f6ba6b26a3dcc4"
- * SHA1: "c855a56a0d7e0df6ae6ede9c0746016d65b0bd74"
- * SHA512: "2f500a8bd84cf8adacc62b29c4ff8feb340511f7d23cf6ba592efa508c868f2081ff3290f0fa8da75dfe005329226b36ae4a0e3e9f4327c281e2c4c794d49bb2"
- * CRC32: "64D72015"
- * SSDEEP: "49152:jwTZ7sYnCsGi0i8e1nEqwkvM4lG+MD5APONG2DWySUl0zGS6TRG+SoFEcB3N:MTZ7pUi039kvElVSa0q5GAFEcB9"
- * Process Execution:
- "Exes_f104480eee65d69032f6ba6b26a3dcc4.exe",
- "cmd.exe",
- "PING.EXE",
- "attrib.exe",
- "attrib.exe"
- * Executed Commands:
- "\"C:\\Users\\user\\AppData\\Roaming\\Roaming\\Swap\\gook.exe\"",
- "C:\\Users\\user\\AppData\\Roaming\\Roaming\\Swap\\gook.exe ",
- "C:\\Windows\\system32\\cmd.exe /C \"C:\\Users\\user\\AppData\\Local\\Temp\\del.cmd\"",
- "C:\\Windows\\system32\\PING.EXE ping 1.1.1.1 -n 5 -w 5000",
- "attrib -a -h -s -r \"C:\\Users\\user\\AppData\\Local\\Temp\\A94C.tmp\"",
- "attrib -a -h -s -r C:\\Users\\user\\AppData\\Local\\Temp\\del.cmd"
- * Signatures Detected:
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Possible date expiration check, exits too soon after checking local time",
- "Details":
- "process": "attrib.exe, PID 660"
- "Description": "A process attempted to delay the analysis task.",
- "Details":
- "Process": "Exes_f104480eee65d69032f6ba6b26a3dcc4.exe tried to sleep 1020 seconds, actually delayed analysis time by 0 seconds"
- "Description": "Network anomalies occured during the analysis.",
- "Details":
- "Anomaly": "'1.1.1.1' getaddrinfo with no actual connection to the IP."
- "Description": "A process created a hidden window",
- "Details":
- "Process": "Exes_f104480eee65d69032f6ba6b26a3dcc4.exe -> C:\\Users\\user\\AppData\\Roaming\\Roaming\\Swap\\gook.exe"
- "Process": "Exes_f104480eee65d69032f6ba6b26a3dcc4.exe -> C:\\Windows\\system32\\cmd.exe /C \"C:\\Users\\user\\AppData\\Local\\Temp\\del.cmd\""
- "Description": "Drops a binary and executes it",
- "Details":
- "binary": "C:\\Users\\user\\AppData\\Roaming\\Roaming\\Swap\\gook.exe"
- "Description": "Deletes its original binary from disk",
- "Details":
- "Description": "Creates a hidden or system file",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Local\\Temp\\del.cmd"
- "Description": "File has been identified by 33 Antiviruses on VirusTotal as malicious",
- "Details":
- "MicroWorld-eScan": "Trojan.GenericKD.32144125"
- "FireEye": "Generic.mg.f104480eee65d690"
- "McAfee": "Artemis!F104480EEE65"
- "Cylance": "Unsafe"
- "Alibaba": "Trojan:Win32/Chapak.3d4e63e1"
- "Symantec": "Trojan Horse"
- "Avast": "Win32:DangerousSig Trj"
- "Kaspersky": "Trojan.Win32.Chapak.dvik"
- "BitDefender": "Trojan.GenericKD.32144125"
- "Paloalto": "generic.ml"
- "AegisLab": "Trojan.Multi.Generic.4!c"
- "Tencent": "Win32.Trojan.Chapak.Dypg"
- "Emsisoft": "Trojan.GenericKD.32144125 (B)"
- "Invincea": "heuristic"
- "McAfee-GW-Edition": "Artemis!Trojan"
- "Webroot": "W32.Trojan.Gen"
- "Antiy-AVL": "Trojan/Win32.Kryptik"
- "Microsoft": "Trojan:Win32/Dynamer!ac"
- "ZoneAlarm": "Trojan.Win32.Chapak.dvik"
- "GData": "Trojan.GenericKD.32144125"
- "AhnLab-V3": "Win-Trojan/Suspig2.Exp"
- "Acronis": "suspicious"
- "ALYac": "Trojan.GenericKD.32144125"
- "Ad-Aware": "Trojan.GenericKD.32144125"
- "Malwarebytes": "Trojan.MalPack.GS"
- "ESET-NOD32": "a variant of Win32/Kryptik.GUOI"
- "TrendMicro-HouseCall": "Trojan.Win32.WACATAC.USXVPGC19"
- "Ikarus": "Trojan.Win32.Crypt"
- "Fortinet": "W32/Kryptik.GUKZ!tr"
- "AVG": "Win32:DangerousSig Trj"
- "Panda": "Trj/GdSda.A"
- "CrowdStrike": "win/malicious_confidence_60% (D)"
- "Qihoo-360": "Win32/Trojan.9a5"
- "Description": "Generates some ICMP traffic",
- "Details":
- * Started Service:
- * Mutexes:
- "0xffffaaa0",
- "Local\\ZoneAttributeCacheCounterMutex",
- "Local\\ZonesCacheCounterMutex",
- "Local\\ZonesLockedCacheCounterMutex"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\A94C.tmp",
- "C:\\Users\\user\\AppData\\Roaming\\Roaming\\Swap\\gook.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\del.cmd",
- "\\??\\nul"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_f104480eee65d69032f6ba6b26a3dcc4.exe",
- "C:\\Users\\user\\AppData\\Roaming\\Roaming\\Swap\\gook.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\A94C.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\del.cmd"
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect"
- * Deleted Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName"
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- "src": "169.254.255.254
- "dst": "1.1.1.1",
- "type": 8,
- "data": "abcdefghijklmnopqrstuvwabcdefghi"
- "src": "1.1.1.1",
- "dst": "169.254.255.254
- "type": 0,
- "data": "abcdefghijklmnopqrstuvwabcdefghi"
- "src": "169.254.255.254
- "dst": "1.1.1.1",
- "type": 8,
- "data": "abcdefghijklmnopqrstuvwabcdefghi"
- "src": "1.1.1.1",
- "dst": "169.254.255.254
- "type": 0,
- "data": "abcdefghijklmnopqrstuvwabcdefghi"
- "src": "169.254.255.254
- "dst": "1.1.1.1",
- "type": 8,
- "data": "abcdefghijklmnopqrstuvwabcdefghi"
- "src": "1.1.1.1",
- "dst": "169.254.255.254
- "type": 0,
- "data": "abcdefghijklmnopqrstuvwabcdefghi"
- "src": "169.254.255.254
- "dst": "1.1.1.1",
- "type": 8,
- "data": "abcdefghijklmnopqrstuvwabcdefghi"
- "src": "1.1.1.1",
- "dst": "169.254.255.254
- "type": 0,
- "data": "abcdefghijklmnopqrstuvwabcdefghi"
- "src": "169.254.255.254
- "dst": "1.1.1.1",
- "type": 8,
- "data": "abcdefghijklmnopqrstuvwabcdefghi"
- "src": "1.1.1.1",
- "dst": "169.254.255.254
- "type": 0,
- "data": "abcdefghijklmnopqrstuvwabcdefghi"
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment