Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Feodo"
- * MalScore: 10.0
- * File Name: "Exes_d2250f61638aee0c13a0c55b5e8fb075.exe"
- * File Size: 126976
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "9f6663222c360ecb5aa2364789fc9ab08d027a28bc4c237223f2566e3572e8ab"
- * MD5: "d2250f61638aee0c13a0c55b5e8fb075"
- * SHA1: "c1a62199e5abe563fbffcc3a1532b5868b7c5cd5"
- * SHA512: "0addbae328bf2cc332f27c1ea7c9adb87aba57d9e984769b487e59f0b0ebb61f576f8599698799474b9b4d5dcdbe441fa33525cc0192f9145a7954caf7c1e1da"
- * CRC32: "89986365"
- * SSDEEP: "3072:WVL/sKavKBYKuvsvYTDfA/xX6Xi4fX4J:ysnvdvLA/x6XiYX"
- * Process Execution:
- "Exes_d2250f61638aee0c13a0c55b5e8fb075.exe",
- "cmd.exe",
- "powershell.exe"
- * Executed Commands:
- "C:\\Windows\\system32\\cmd.exe /C PowerShell \"Start-Sleep 10; Remove-Item C:\\Users\\user\\AppData\\Local\\Temp\\Exes_d2250f61638aee0c13a0c55b5e8fb075.exe\"",
- "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe PowerShell \"Start-Sleep 10; Remove-Item C:\\Users\\user\\AppData\\Local\\Temp\\Exes_d2250f61638aee0c13a0c55b5e8fb075.exe\""
- * Signatures Detected:
- "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
- "Details":
- "IP": "169.254.255.254:445"
- "Description": "Creates RWX memory",
- "Details":
- "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
- "Details":
- "get_no_useragent": "HTTP traffic contains a GET request with no user-agent header"
- "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
- "suspicious_request": "http://212.38.166.79/sin.png"
- "suspicious_request": "http://212.38.166.79/win.png"
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://212.38.166.79/sin.png"
- "url": "http://212.38.166.79/win.png"
- "url": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab"
- "Description": "Deletes its original binary from disk",
- "Details":
- "Description": "Created network traffic indicative of malicious activity",
- "Details":
- "signature": "ET CNC Feodo Tracker Reported CnC Server group 20"
- "signature": "ET CNC Feodo Tracker Reported CnC Server group 15"
- * Started Service:
- * Mutexes:
- "Global\\CLR_CASOFF_MUTEX"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\S-1-5-21-0000000000-0000000000-0000000000-1000\\00000000-0000-0000-0000-000000000000b_00000000-0000-0000-0000-000000000000",
- "\\Device\\LanmanDatagramReceiver",
- "\\??\\PIPE\\browser",
- "C:\\Windows\\SysWOW64\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
- "\\??\\PIPE\\srvsvc",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\5UJKZKUJODBZ2A4XAQ00.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\5UJKZKUJODBZ2A4XAQ00.temp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_d2250f61638aee0c13a0c55b5e8fb075.exe",
- "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.1044.2355531",
- "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1044.2355531",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.1044.2355531"
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList"
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 1,
- "body": "",
- "uri": "http://212.38.166.79/sin.png",
- "user-agent": "",
- "method": "GET",
- "host": "212.38.166.79",
- "version": "1.1",
- "path": "/sin.png",
- "data": "GET /sin.png HTTP/1.1\r\nConnection: Keep-Alive\r\nHost: 212.38.166.79\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://212.38.166.79/win.png",
- "user-agent": "",
- "method": "GET",
- "host": "212.38.166.79",
- "version": "1.1",
- "path": "/win.png",
- "data": "GET /win.png HTTP/1.1\r\nConnection: Keep-Alive\r\nHost: 212.38.166.79\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "www.download.windowsupdate.com",
- "version": "1.1",
- "path": "/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
- "data": "GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1\r\nCache-Control: max-age = 86402\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: www.download.windowsupdate.com\r\n\r\n",
- "port": 80
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Add Comment
Please, Sign In to add comment