paladin316

Exes_f104480eee65d69032f6ba6b26a3dcc4_exe_2019-07-14_08_30.txt

Jul 14th, 2019
2,085
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 8.61 KB | None | 0 0
  1.  
  2. * MalFamily: "Chapak"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_f104480eee65d69032f6ba6b26a3dcc4.exe"
  7. * File Size: 2795776
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "deb1b68a1b27087c80600887413199c3a9f4cc41026bec91413735ada7cbe72e"
  10. * MD5: "f104480eee65d69032f6ba6b26a3dcc4"
  11. * SHA1: "c855a56a0d7e0df6ae6ede9c0746016d65b0bd74"
  12. * SHA512: "2f500a8bd84cf8adacc62b29c4ff8feb340511f7d23cf6ba592efa508c868f2081ff3290f0fa8da75dfe005329226b36ae4a0e3e9f4327c281e2c4c794d49bb2"
  13. * CRC32: "64D72015"
  14. * SSDEEP: "49152:jwTZ7sYnCsGi0i8e1nEqwkvM4lG+MD5APONG2DWySUl0zGS6TRG+SoFEcB3N:MTZ7pUi039kvElVSa0q5GAFEcB9"
  15.  
  16. * Process Execution:
  17. "Exes_f104480eee65d69032f6ba6b26a3dcc4.exe",
  18. "cmd.exe",
  19. "PING.EXE",
  20. "attrib.exe",
  21. "attrib.exe"
  22.  
  23.  
  24. * Executed Commands:
  25. "\"C:\\Users\\user\\AppData\\Roaming\\Roaming\\Swap\\gook.exe\"",
  26. "C:\\Users\\user\\AppData\\Roaming\\Roaming\\Swap\\gook.exe ",
  27. "C:\\Windows\\system32\\cmd.exe /C \"C:\\Users\\user\\AppData\\Local\\Temp\\del.cmd\"",
  28. "C:\\Windows\\system32\\PING.EXE ping 1.1.1.1 -n 5 -w 5000",
  29. "attrib -a -h -s -r \"C:\\Users\\user\\AppData\\Local\\Temp\\A94C.tmp\"",
  30. "attrib -a -h -s -r C:\\Users\\user\\AppData\\Local\\Temp\\del.cmd"
  31.  
  32.  
  33. * Signatures Detected:
  34.  
  35. "Description": "Creates RWX memory",
  36. "Details":
  37.  
  38.  
  39. "Description": "Possible date expiration check, exits too soon after checking local time",
  40. "Details":
  41.  
  42. "process": "attrib.exe, PID 660"
  43.  
  44.  
  45.  
  46.  
  47. "Description": "A process attempted to delay the analysis task.",
  48. "Details":
  49.  
  50. "Process": "Exes_f104480eee65d69032f6ba6b26a3dcc4.exe tried to sleep 1020 seconds, actually delayed analysis time by 0 seconds"
  51.  
  52.  
  53.  
  54.  
  55. "Description": "Network anomalies occured during the analysis.",
  56. "Details":
  57.  
  58. "Anomaly": "'1.1.1.1' getaddrinfo with no actual connection to the IP."
  59.  
  60.  
  61.  
  62.  
  63. "Description": "A process created a hidden window",
  64. "Details":
  65.  
  66. "Process": "Exes_f104480eee65d69032f6ba6b26a3dcc4.exe -> C:\\Users\\user\\AppData\\Roaming\\Roaming\\Swap\\gook.exe"
  67.  
  68.  
  69. "Process": "Exes_f104480eee65d69032f6ba6b26a3dcc4.exe -> C:\\Windows\\system32\\cmd.exe /C \"C:\\Users\\user\\AppData\\Local\\Temp\\del.cmd\""
  70.  
  71.  
  72.  
  73.  
  74. "Description": "Drops a binary and executes it",
  75. "Details":
  76.  
  77. "binary": "C:\\Users\\user\\AppData\\Roaming\\Roaming\\Swap\\gook.exe"
  78.  
  79.  
  80.  
  81.  
  82. "Description": "Deletes its original binary from disk",
  83. "Details":
  84.  
  85.  
  86. "Description": "Creates a hidden or system file",
  87. "Details":
  88.  
  89. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\del.cmd"
  90.  
  91.  
  92.  
  93.  
  94. "Description": "File has been identified by 33 Antiviruses on VirusTotal as malicious",
  95. "Details":
  96.  
  97. "MicroWorld-eScan": "Trojan.GenericKD.32144125"
  98.  
  99.  
  100. "FireEye": "Generic.mg.f104480eee65d690"
  101.  
  102.  
  103. "McAfee": "Artemis!F104480EEE65"
  104.  
  105.  
  106. "Cylance": "Unsafe"
  107.  
  108.  
  109. "Alibaba": "Trojan:Win32/Chapak.3d4e63e1"
  110.  
  111.  
  112. "Symantec": "Trojan Horse"
  113.  
  114.  
  115. "Avast": "Win32:DangerousSig Trj"
  116.  
  117.  
  118. "Kaspersky": "Trojan.Win32.Chapak.dvik"
  119.  
  120.  
  121. "BitDefender": "Trojan.GenericKD.32144125"
  122.  
  123.  
  124. "Paloalto": "generic.ml"
  125.  
  126.  
  127. "AegisLab": "Trojan.Multi.Generic.4!c"
  128.  
  129.  
  130. "Tencent": "Win32.Trojan.Chapak.Dypg"
  131.  
  132.  
  133. "Emsisoft": "Trojan.GenericKD.32144125 (B)"
  134.  
  135.  
  136. "Invincea": "heuristic"
  137.  
  138.  
  139. "McAfee-GW-Edition": "Artemis!Trojan"
  140.  
  141.  
  142. "Webroot": "W32.Trojan.Gen"
  143.  
  144.  
  145. "Antiy-AVL": "Trojan/Win32.Kryptik"
  146.  
  147.  
  148. "Microsoft": "Trojan:Win32/Dynamer!ac"
  149.  
  150.  
  151. "ZoneAlarm": "Trojan.Win32.Chapak.dvik"
  152.  
  153.  
  154. "GData": "Trojan.GenericKD.32144125"
  155.  
  156.  
  157. "AhnLab-V3": "Win-Trojan/Suspig2.Exp"
  158.  
  159.  
  160. "Acronis": "suspicious"
  161.  
  162.  
  163. "ALYac": "Trojan.GenericKD.32144125"
  164.  
  165.  
  166. "Ad-Aware": "Trojan.GenericKD.32144125"
  167.  
  168.  
  169. "Malwarebytes": "Trojan.MalPack.GS"
  170.  
  171.  
  172. "ESET-NOD32": "a variant of Win32/Kryptik.GUOI"
  173.  
  174.  
  175. "TrendMicro-HouseCall": "Trojan.Win32.WACATAC.USXVPGC19"
  176.  
  177.  
  178. "Ikarus": "Trojan.Win32.Crypt"
  179.  
  180.  
  181. "Fortinet": "W32/Kryptik.GUKZ!tr"
  182.  
  183.  
  184. "AVG": "Win32:DangerousSig Trj"
  185.  
  186.  
  187. "Panda": "Trj/GdSda.A"
  188.  
  189.  
  190. "CrowdStrike": "win/malicious_confidence_60% (D)"
  191.  
  192.  
  193. "Qihoo-360": "Win32/Trojan.9a5"
  194.  
  195.  
  196.  
  197.  
  198. "Description": "Generates some ICMP traffic",
  199. "Details":
  200.  
  201.  
  202.  
  203. * Started Service:
  204.  
  205. * Mutexes:
  206. "0xffffaaa0",
  207. "Local\\ZoneAttributeCacheCounterMutex",
  208. "Local\\ZonesCacheCounterMutex",
  209. "Local\\ZonesLockedCacheCounterMutex"
  210.  
  211.  
  212. * Modified Files:
  213. "C:\\Users\\user\\AppData\\Local\\Temp\\A94C.tmp",
  214. "C:\\Users\\user\\AppData\\Roaming\\Roaming\\Swap\\gook.exe",
  215. "C:\\Users\\user\\AppData\\Local\\Temp\\del.cmd",
  216. "\\??\\nul"
  217.  
  218.  
  219. * Deleted Files:
  220. "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_f104480eee65d69032f6ba6b26a3dcc4.exe",
  221. "C:\\Users\\user\\AppData\\Roaming\\Roaming\\Swap\\gook.exe",
  222. "C:\\Users\\user\\AppData\\Local\\Temp\\A94C.tmp",
  223. "C:\\Users\\user\\AppData\\Local\\Temp\\del.cmd"
  224.  
  225.  
  226. * Modified Registry Keys:
  227. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
  228. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect"
  229.  
  230.  
  231. * Deleted Registry Keys:
  232. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  233. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  234. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  235. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName"
  236.  
  237.  
  238. * DNS Communications:
  239.  
  240. * Domains:
  241.  
  242. * Network Communication - ICMP:
  243.  
  244. "src": "169.254.255.254
  245. "dst": "1.1.1.1",
  246. "type": 8,
  247. "data": "abcdefghijklmnopqrstuvwabcdefghi"
  248.  
  249.  
  250. "src": "1.1.1.1",
  251. "dst": "169.254.255.254
  252. "type": 0,
  253. "data": "abcdefghijklmnopqrstuvwabcdefghi"
  254.  
  255.  
  256. "src": "169.254.255.254
  257. "dst": "1.1.1.1",
  258. "type": 8,
  259. "data": "abcdefghijklmnopqrstuvwabcdefghi"
  260.  
  261.  
  262. "src": "1.1.1.1",
  263. "dst": "169.254.255.254
  264. "type": 0,
  265. "data": "abcdefghijklmnopqrstuvwabcdefghi"
  266.  
  267.  
  268. "src": "169.254.255.254
  269. "dst": "1.1.1.1",
  270. "type": 8,
  271. "data": "abcdefghijklmnopqrstuvwabcdefghi"
  272.  
  273.  
  274. "src": "1.1.1.1",
  275. "dst": "169.254.255.254
  276. "type": 0,
  277. "data": "abcdefghijklmnopqrstuvwabcdefghi"
  278.  
  279.  
  280. "src": "169.254.255.254
  281. "dst": "1.1.1.1",
  282. "type": 8,
  283. "data": "abcdefghijklmnopqrstuvwabcdefghi"
  284.  
  285.  
  286. "src": "1.1.1.1",
  287. "dst": "169.254.255.254
  288. "type": 0,
  289. "data": "abcdefghijklmnopqrstuvwabcdefghi"
  290.  
  291.  
  292. "src": "169.254.255.254
  293. "dst": "1.1.1.1",
  294. "type": 8,
  295. "data": "abcdefghijklmnopqrstuvwabcdefghi"
  296.  
  297.  
  298. "src": "1.1.1.1",
  299. "dst": "169.254.255.254
  300. "type": 0,
  301. "data": "abcdefghijklmnopqrstuvwabcdefghi"
  302.  
  303.  
  304.  
  305. * Network Communication - HTTP:
  306.  
  307. * Network Communication - SMTP:
  308.  
  309. * Network Communication - Hosts:
  310.  
  311. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment