paladin316

Exes_d2250f61638aee0c13a0c55b5e8fb075_exe_2019-07-18_14_30.txt

Jul 18th, 2019
2,244
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.68 KB | None | 0 0
  1.  
  2. * MalFamily: "Feodo"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_d2250f61638aee0c13a0c55b5e8fb075.exe"
  7. * File Size: 126976
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "9f6663222c360ecb5aa2364789fc9ab08d027a28bc4c237223f2566e3572e8ab"
  10. * MD5: "d2250f61638aee0c13a0c55b5e8fb075"
  11. * SHA1: "c1a62199e5abe563fbffcc3a1532b5868b7c5cd5"
  12. * SHA512: "0addbae328bf2cc332f27c1ea7c9adb87aba57d9e984769b487e59f0b0ebb61f576f8599698799474b9b4d5dcdbe441fa33525cc0192f9145a7954caf7c1e1da"
  13. * CRC32: "89986365"
  14. * SSDEEP: "3072:WVL/sKavKBYKuvsvYTDfA/xX6Xi4fX4J:ysnvdvLA/x6XiYX"
  15.  
  16. * Process Execution:
  17. "Exes_d2250f61638aee0c13a0c55b5e8fb075.exe",
  18. "cmd.exe",
  19. "powershell.exe"
  20.  
  21.  
  22. * Executed Commands:
  23. "C:\\Windows\\system32\\cmd.exe /C PowerShell \"Start-Sleep 10; Remove-Item C:\\Users\\user\\AppData\\Local\\Temp\\Exes_d2250f61638aee0c13a0c55b5e8fb075.exe\"",
  24. "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe PowerShell \"Start-Sleep 10; Remove-Item C:\\Users\\user\\AppData\\Local\\Temp\\Exes_d2250f61638aee0c13a0c55b5e8fb075.exe\""
  25.  
  26.  
  27. * Signatures Detected:
  28.  
  29. "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
  30. "Details":
  31.  
  32. "IP": "169.254.255.254:445"
  33.  
  34.  
  35.  
  36.  
  37. "Description": "Creates RWX memory",
  38. "Details":
  39.  
  40.  
  41. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  42. "Details":
  43.  
  44. "get_no_useragent": "HTTP traffic contains a GET request with no user-agent header"
  45.  
  46.  
  47. "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
  48.  
  49.  
  50. "suspicious_request": "http://212.38.166.79/sin.png"
  51.  
  52.  
  53. "suspicious_request": "http://212.38.166.79/win.png"
  54.  
  55.  
  56.  
  57.  
  58. "Description": "Performs some HTTP requests",
  59. "Details":
  60.  
  61. "url": "http://212.38.166.79/sin.png"
  62.  
  63.  
  64. "url": "http://212.38.166.79/win.png"
  65.  
  66.  
  67. "url": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab"
  68.  
  69.  
  70.  
  71.  
  72. "Description": "Deletes its original binary from disk",
  73. "Details":
  74.  
  75.  
  76. "Description": "Created network traffic indicative of malicious activity",
  77. "Details":
  78.  
  79. "signature": "ET CNC Feodo Tracker Reported CnC Server group 20"
  80.  
  81.  
  82. "signature": "ET CNC Feodo Tracker Reported CnC Server group 15"
  83.  
  84.  
  85.  
  86.  
  87.  
  88. * Started Service:
  89.  
  90. * Mutexes:
  91. "Global\\CLR_CASOFF_MUTEX"
  92.  
  93.  
  94. * Modified Files:
  95. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\S-1-5-21-0000000000-0000000000-0000000000-1000\\00000000-0000-0000-0000-000000000000b_00000000-0000-0000-0000-000000000000",
  96. "\\Device\\LanmanDatagramReceiver",
  97. "\\??\\PIPE\\browser",
  98. "C:\\Windows\\SysWOW64\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
  99. "\\??\\PIPE\\srvsvc",
  100. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\5UJKZKUJODBZ2A4XAQ00.temp",
  101. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms"
  102.  
  103.  
  104. * Deleted Files:
  105. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\5UJKZKUJODBZ2A4XAQ00.temp",
  106. "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_d2250f61638aee0c13a0c55b5e8fb075.exe",
  107. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.1044.2355531",
  108. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1044.2355531",
  109. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.1044.2355531"
  110.  
  111.  
  112. * Modified Registry Keys:
  113. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList"
  114.  
  115.  
  116. * Deleted Registry Keys:
  117.  
  118. * DNS Communications:
  119.  
  120. * Domains:
  121.  
  122. * Network Communication - ICMP:
  123.  
  124. * Network Communication - HTTP:
  125.  
  126. "count": 1,
  127. "body": "",
  128. "uri": "http://212.38.166.79/sin.png",
  129. "user-agent": "",
  130. "method": "GET",
  131. "host": "212.38.166.79",
  132. "version": "1.1",
  133. "path": "/sin.png",
  134. "data": "GET /sin.png HTTP/1.1\r\nConnection: Keep-Alive\r\nHost: 212.38.166.79\r\n\r\n",
  135. "port": 80
  136.  
  137.  
  138. "count": 1,
  139. "body": "",
  140. "uri": "http://212.38.166.79/win.png",
  141. "user-agent": "",
  142. "method": "GET",
  143. "host": "212.38.166.79",
  144. "version": "1.1",
  145. "path": "/win.png",
  146. "data": "GET /win.png HTTP/1.1\r\nConnection: Keep-Alive\r\nHost: 212.38.166.79\r\n\r\n",
  147. "port": 80
  148.  
  149.  
  150. "count": 1,
  151. "body": "",
  152. "uri": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
  153. "user-agent": "Microsoft-CryptoAPI/6.1",
  154. "method": "GET",
  155. "host": "www.download.windowsupdate.com",
  156. "version": "1.1",
  157. "path": "/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
  158. "data": "GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1\r\nCache-Control: max-age = 86402\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: www.download.windowsupdate.com\r\n\r\n",
  159. "port": 80
  160.  
  161.  
  162.  
  163. * Network Communication - SMTP:
  164.  
  165. * Network Communication - Hosts:
  166.  
  167. * Network Communication - IRC:
Add Comment
Please, Sign In to add comment