paladin316

AgentTesla_f96a7b2aef7aa8c897c4e30027efb0e5_exe_2019-08-05_06_30.txt

Aug 5th, 2019
2,859
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 12.30 KB | None | 0 0
  1.  
  2. * MalFamily: "AgentTesla"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "AgentTesla_f96a7b2aef7aa8c897c4e30027efb0e5.exe"
  7. * File Size: 510976
  8. * File Type: "PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows"
  9. * SHA256: "ed24236643d954599057d3d203fd4c9ffa2f0d29e6aafd10b81e717d963e514c"
  10. * MD5: "f96a7b2aef7aa8c897c4e30027efb0e5"
  11. * SHA1: "a3ecedfdc20a83746136dfa2f395d2a43317d5f3"
  12. * SHA512: "9e6e2311b912a7659bfe4d2592ca06e4cccd8cbe4a909fe141cd80a31a5c97fc5e40ad77e58990339014a5a38cf0ce4eceb0b53fee4415d79e3635a4a2dce273"
  13. * CRC32: "97B0278D"
  14. * SSDEEP: "12288:njELRSfQgHj9oVoJHYati/AIHq7hMKzK:DQgH+VoYa0/XHqK"
  15.  
  16. * Process Execution:
  17. "AgentTesla_f96a7b2aef7aa8c897c4e30027efb0e5.exe",
  18. "AgentTesla_f96a7b2aef7aa8c897c4e30027efb0e5.exe",
  19. "services.exe",
  20. "svchost.exe",
  21. "WmiPrvSE.exe",
  22. "lsass.exe",
  23. "taskhost.exe",
  24. "sc.exe",
  25. "svchost.exe",
  26. "svchost.exe",
  27. "WerFault.exe",
  28. "wermgr.exe",
  29. "WMIADAP.exe"
  30.  
  31.  
  32. * Executed Commands:
  33. "\"C:\\Users\\user\\AppData\\Local\\Temp\\AgentTesla_f96a7b2aef7aa8c897c4e30027efb0e5.exe\"",
  34. "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding",
  35. "C:\\Windows\\system32\\lsass.exe",
  36. "taskhost.exe $(Arg0)",
  37. "C:\\Windows\\system32\\sc.exe start w32time task_started",
  38. "C:\\Windows\\system32\\svchost.exe -k LocalService",
  39. "C:\\Windows\\System32\\svchost.exe -k WerSvcGroup",
  40. "C:\\Windows\\system32\\WerFault.exe -u -p 2608 -s 292",
  41. "\"C:\\Windows\\system32\\wermgr.exe\" \"-queuereporting_svc\" \"C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_d9cea5d53964d256a96f47a4e221d2152335d_cab_028dd289\""
  42.  
  43.  
  44. * Signatures Detected:
  45.  
  46. "Description": "At least one process apparently crashed during execution",
  47. "Details":
  48.  
  49.  
  50. "Description": "Creates RWX memory",
  51. "Details":
  52.  
  53.  
  54. "Description": "A process attempted to delay the analysis task.",
  55. "Details":
  56.  
  57. "Process": "AgentTesla_f96a7b2aef7aa8c897c4e30027efb0e5.exe tried to sleep 1002 seconds, actually delayed analysis time by 0 seconds"
  58.  
  59.  
  60.  
  61.  
  62. "Description": "The binary likely contains encrypted or compressed data.",
  63. "Details":
  64.  
  65. "section": "name: .text, entropy: 7.96, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ, raw_size: 0x0007c200, virtual_size: 0x0007c0a4"
  66.  
  67.  
  68.  
  69.  
  70. "Description": "Executed a process and injected code into it, probably while unpacking",
  71. "Details":
  72.  
  73. "Injection": "AgentTesla_f96a7b2aef7aa8c897c4e30027efb0e5.exe(696) -> AgentTesla_f96a7b2aef7aa8c897c4e30027efb0e5.exe(2204)"
  74.  
  75.  
  76.  
  77.  
  78. "Description": "Attempts to restart the guest VM",
  79. "Details":
  80.  
  81.  
  82. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  83. "Details":
  84.  
  85. "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 7026230 times"
  86.  
  87.  
  88.  
  89.  
  90. "Description": "Steals private information from local Internet browsers",
  91. "Details":
  92.  
  93. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data"
  94.  
  95.  
  96.  
  97.  
  98. "Description": "Retrieves Windows ProductID, probably to fingerprint the sandbox",
  99. "Details":
  100.  
  101.  
  102. "Description": "Checks the CPU name from registry, possibly for anti-virtualization",
  103. "Details":
  104.  
  105.  
  106. "Description": "Checks the system manufacturer, likely for anti-virtualization",
  107. "Details":
  108.  
  109.  
  110. "Description": "Harvests credentials from local FTP client softwares",
  111. "Details":
  112.  
  113. "file": "C:\\Users\\user\\AppData\\Roaming\\FileZilla\\recentservers.xml"
  114.  
  115.  
  116. "file": "C:\\Users\\user\\AppData\\Roaming\\SmartFTP\\Client 2.0\\Favorites\\Quick Connect\\"
  117.  
  118.  
  119. "file": "C:\\Users\\user\\AppData\\Roaming\\SmartFTP\\Client 2.0\\Favorites\\Quick Connect\\*.xml"
  120.  
  121.  
  122. "file": "C:\\Users\\user\\AppData\\Roaming\\FTPGetter\\servers.xml"
  123.  
  124.  
  125. "file": "C:\\Users\\user\\AppData\\Roaming\\Ipswitch\\WS_FTP\\Sites\\ws_ftp.ini"
  126.  
  127.  
  128. "file": "C:\\cftp\\Ftplist.txt"
  129.  
  130.  
  131. "key": "HKEY_CURRENT_USER\\Software\\FTPWare\\COREFTP\\Sites"
  132.  
  133.  
  134.  
  135.  
  136. "Description": "Harvests information related to installed mail clients",
  137. "Details":
  138.  
  139. "file": "C:\\Users\\user\\AppData\\Roaming\\Thunderbird\\profiles.ini"
  140.  
  141.  
  142. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows Messaging Subsystem\\Profiles\\9375CFF0413111d3B88A00104B2A6676"
  143.  
  144.  
  145. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676"
  146.  
  147.  
  148. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\SMTP Password"
  149.  
  150.  
  151. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\Email"
  152.  
  153.  
  154. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\HTTP Password"
  155.  
  156.  
  157. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676"
  158.  
  159.  
  160. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\HTTP Password"
  161.  
  162.  
  163. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676"
  164.  
  165.  
  166. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\POP3 Password"
  167.  
  168.  
  169. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\Email"
  170.  
  171.  
  172. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\SMTP Password"
  173.  
  174.  
  175. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\IMAP Password"
  176.  
  177.  
  178. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001"
  179.  
  180.  
  181. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\IMAP Password"
  182.  
  183.  
  184. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\POP3 Password"
  185.  
  186.  
  187. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002"
  188.  
  189.  
  190.  
  191.  
  192. "Description": "Collects information to fingerprint the system",
  193. "Details":
  194.  
  195.  
  196.  
  197. * Started Service:
  198. "VaultSvc",
  199. "WerSvc",
  200. "W32Time"
  201.  
  202.  
  203. * Mutexes:
  204. "Global\\CLR_CASOFF_MUTEX",
  205. "Local\\_!MSFTHISTORY!_",
  206. "Local\\c:!users!user!appdata!local!microsoft!windows!temporary internet files!content.ie5!",
  207. "Local\\c:!users!user!appdata!roaming!microsoft!windows!cookies!",
  208. "Local\\c:!users!user!appdata!local!microsoft!windows!history!history.ie5!",
  209. "Local\\WERReportingForProcess2608",
  210. "Global\\\\xe5\\x88\\x90\\xc2\\x8c",
  211. "Global\\\\xed\\x95\\xb0\\xc7\\x83",
  212. "WERUI_BEX64-d9cea5d53964d256a96f47a4e221d2152335d",
  213. "Global\\ADAP_WMI_ENTRY",
  214. "Global\\RefreshRA_Mutex",
  215. "Global\\RefreshRA_Mutex_Lib",
  216. "Global\\RefreshRA_Mutex_Flag"
  217.  
  218.  
  219. * Modified Files:
  220. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\index.dat",
  221. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\index.dat",
  222. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\index.dat",
  223. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
  224. "\\??\\WMIDataDevice",
  225. "C:\\Windows\\sysnative\\LogFiles\\Scm\\4963ad21-c4a5-42a5-b9bd-e441d57204fe",
  226. "C:\\Windows\\sysnative\\LogFiles\\Scm\\7bbc503c-5977-4798-a4ae-61483a7e030d",
  227. "C:\\Windows\\sysnative\\LogFiles\\Scm\\0cac2e9c-ea8f-4241-b7b0-43263f35a662",
  228. "\\??\\PIPE\\lsarpc",
  229. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA1B1.tmp.appcompat.txt",
  230. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERB162.tmp.WERInternalMetadata.xml",
  231. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERB22E.tmp.hdmp",
  232. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERCB06.tmp.mdmp",
  233. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_d9cea5d53964d256a96f47a4e221d2152335d_cab_028dd289\\WERA1B1.tmp.appcompat.txt",
  234. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_d9cea5d53964d256a96f47a4e221d2152335d_cab_028dd289\\WERB162.tmp.WERInternalMetadata.xml",
  235. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_d9cea5d53964d256a96f47a4e221d2152335d_cab_028dd289\\WERB22E.tmp.hdmp",
  236. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_d9cea5d53964d256a96f47a4e221d2152335d_cab_028dd289\\WERCB06.tmp.mdmp",
  237. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_d9cea5d53964d256a96f47a4e221d2152335d_cab_028dd289\\Report.wer",
  238. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_d9cea5d53964d256a96f47a4e221d2152335d_cab_028dd289\\Report.wer.tmp"
  239.  
  240.  
  241. * Deleted Files:
  242. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.696.29102093",
  243. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.696.29102093",
  244. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.696.29102093",
  245. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA1B1.tmp",
  246. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA1B1.tmp.appcompat.txt",
  247. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERB162.tmp",
  248. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERB162.tmp.WERInternalMetadata.xml",
  249. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERB22E.tmp",
  250. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERB22E.tmp.hdmp",
  251. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERCB06.tmp",
  252. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERCB06.tmp.mdmp",
  253. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_d9cea5d53964d256a96f47a4e221d2152335d_cab_028dd289\\Report.wer.tmp"
  254.  
  255.  
  256. * Modified Registry Keys:
  257. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Type",
  258. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
  259. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\TimeProviders\\NtpClient\\SpecialPollTimeRemaining",
  260. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent",
  261. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent\\DefaultConsent"
  262.  
  263.  
  264. * Deleted Registry Keys:
  265.  
  266. * DNS Communications:
  267.  
  268. * Domains:
  269.  
  270. * Network Communication - ICMP:
  271.  
  272. * Network Communication - HTTP:
  273.  
  274. * Network Communication - SMTP:
  275.  
  276. * Network Communication - Hosts:
  277.  
  278. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment