paladin316

Exes_9758efcf96343d0ef83854860195c4b4_tmp_2019-07-31_04_30.txt

Jul 31st, 2019
2,108
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.53 KB | None | 0 0
  1.  
  2. * MalFamily: ""
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_9758efcf96343d0ef83854860195c4b4.tmp"
  7. * File Size: 75232
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed"
  9. * SHA256: "315c06bd8c75f99722fd014b4fb4bd8934049cde09afead9b46bddf4cdd63171"
  10. * MD5: "9758efcf96343d0ef83854860195c4b4"
  11. * SHA1: "ad46a37b3151587649525278d6a1a6f74b1d9acb"
  12. * SHA512: "c1eea870e8a6e0a7b27d23d8673ca81165b66db3f82bc97619b2301bd1bd918a73cb27405c9af7ef5c77af5bf25a31e1ad9563b8e04df2775c55a90749e6b1c4"
  13. * CRC32: "85D7C804"
  14. * SSDEEP: "1536:iDUO7U2qxEquCB9xiJkv6hw/+6LPLdodmM5aCXqxdT+BkDT:iw7yFC1MkCIIj5aCBB4"
  15.  
  16. * Process Execution:
  17. "Exes_9758efcf96343d0ef83854860195c4b4.tmp",
  18. "cmd.exe",
  19. "schtasks.exe",
  20. "svchost.exe"
  21.  
  22.  
  23. * Executed Commands:
  24. "C:\\Windows\\System32\\cmd.exe /c schtasks /create /tn \"Java Maintenance64\" /sc daily /ri 120 /du 9999:59 /tr \"C:\\Users\\user\\AppData\\Local\\Temp\\Exes_9758efcf96343d0ef83854860195c4b4.tmp\" >> NUL",
  25. "schtasks /create /tn \"Java Maintenance64\" /sc daily /ri 120 /du 9999:59 /tr \"C:\\Users\\user\\AppData\\Local\\Temp\\Exes_9758efcf96343d0ef83854860195c4b4.tmp\""
  26.  
  27.  
  28. * Signatures Detected:
  29.  
  30. "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
  31. "Details":
  32.  
  33. "IP": "51.254.60.208:443"
  34.  
  35.  
  36.  
  37.  
  38. "Description": "Possible date expiration check, exits too soon after checking local time",
  39. "Details":
  40.  
  41. "process": "schtasks.exe, PID 2432"
  42.  
  43.  
  44.  
  45.  
  46. "Description": "A process created a hidden window",
  47. "Details":
  48.  
  49. "Process": "Exes_9758efcf96343d0ef83854860195c4b4.tmp -> C:\\Windows\\System32\\cmd.exe"
  50.  
  51.  
  52.  
  53.  
  54. "Description": "The binary likely contains encrypted or compressed data.",
  55. "Details":
  56.  
  57. "section": "name: UPX1, entropy: 7.91, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00010600, virtual_size: 0x00011000"
  58.  
  59.  
  60.  
  61.  
  62. "Description": "The executable is compressed using UPX",
  63. "Details":
  64.  
  65. "section": "name: UPX0, entropy: 0.00, characteristics: IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00000000, virtual_size: 0x0003a000"
  66.  
  67.  
  68.  
  69.  
  70. "Description": "A process attempted to delay the analysis task by a long amount of time.",
  71. "Details":
  72.  
  73. "Process": "Exes_9758efcf96343d0ef83854860195c4b4.tmp tried to sleep 7260 seconds, actually delayed analysis time by 0 seconds"
  74.  
  75.  
  76.  
  77.  
  78. "Description": "Attempts to execute a Living Off The Land Binary command for post exeploitation",
  79. "Details":
  80.  
  81. "MITRE T1078 - schtask": "(Tactic: Execution, Persistence, Privilege Escalation)"
  82.  
  83.  
  84.  
  85.  
  86. "Description": "Installs itself for autorun at Windows startup",
  87. "Details":
  88.  
  89. "task": "C:\\Windows\\System32\\cmd.exe /c schtasks /create /tn \"Java Maintenance64\" /sc daily /ri 120 /du 9999:59 /tr \"C:\\Users\\user\\AppData\\Local\\Temp\\Exes_9758efcf96343d0ef83854860195c4b4.tmp\" >> NUL"
  90.  
  91.  
  92.  
  93.  
  94. "Description": "File has been identified by 26 Antiviruses on VirusTotal as malicious",
  95. "Details":
  96.  
  97. "FireEye": "Generic.mg.9758efcf96343d0e"
  98.  
  99.  
  100. "ALYac": "Trojan.Agent.75232"
  101.  
  102.  
  103. "K7GW": "Riskware ( 0040eff71 )"
  104.  
  105.  
  106. "K7AntiVirus": "Riskware ( 0040eff71 )"
  107.  
  108.  
  109. "Symantec": "Infostealer"
  110.  
  111.  
  112. "APEX": "Malicious"
  113.  
  114.  
  115. "Kaspersky": "Trojan-Banker.Win32.Alreay.gen"
  116.  
  117.  
  118. "BitDefender": "Gen:Variant.Jaiko.2546"
  119.  
  120.  
  121. "Avast": "Win32:Malware-gen"
  122.  
  123.  
  124. "Emsisoft": "Gen:Variant.Jaiko.2546 (B)"
  125.  
  126.  
  127. "F-Secure": "Trojan.TR/Spy.Banker.vbfql"
  128.  
  129.  
  130. "McAfee-GW-Edition": "Artemis!Trojan"
  131.  
  132.  
  133. "Avira": "TR/Spy.Banker.vbfql"
  134.  
  135.  
  136. "Microsoft": "Trojan:Win32/Casdet!rfn"
  137.  
  138.  
  139. "Endgame": "malicious (moderate confidence)"
  140.  
  141.  
  142. "ViRobot": "Trojan.Win32.S.Agent.75232"
  143.  
  144.  
  145. "ZoneAlarm": "Trojan-Banker.Win32.Alreay.gen"
  146.  
  147.  
  148. "GData": "Gen:Variant.Jaiko.2546"
  149.  
  150.  
  151. "AhnLab-V3": "Trojan/Win32.Akdoor.C3361521"
  152.  
  153.  
  154. "McAfee": "Artemis!9758EFCF9634"
  155.  
  156.  
  157. "MAX": "malware (ai score=100)"
  158.  
  159.  
  160. "VBA32": "suspected of Trojan.Downloader.gen.h"
  161.  
  162.  
  163. "Rising": "Trojan.Ransom.GlobeImposter!1.AF70 (CLASSIC)"
  164.  
  165.  
  166. "SentinelOne": "DFI - Suspicious PE"
  167.  
  168.  
  169. "AVG": "Win32:Malware-gen"
  170.  
  171.  
  172. "Cybereason": "malicious.f96343"
  173.  
  174.  
  175.  
  176.  
  177.  
  178. * Started Service:
  179.  
  180. * Mutexes:
  181.  
  182. * Modified Files:
  183. "\\??\\NUL",
  184. "C:\\Windows\\sysnative\\Tasks\\Java Maintenance64",
  185. "\\Device\\LanmanDatagramReceiver",
  186. "C:\\Windows\\appcompat\\Programs\\RecentFileCache.bcf",
  187. "C:\\Windows\\SoftwareDistribution\\DataStore\\DataStore.edb",
  188. "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edb.chk"
  189.  
  190.  
  191. * Deleted Files:
  192. "C:\\Windows\\Tasks\\Java Maintenance64.job",
  193. "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edbtmp.log"
  194.  
  195.  
  196. * Modified Registry Keys:
  197. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\A11CCB2D-BF83-496D-A097-D7341BC91ADD\\Path",
  198. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\A11CCB2D-BF83-496D-A097-D7341BC91ADD\\Hash",
  199. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Java Maintenance64\\Id",
  200. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Java Maintenance64\\Index",
  201. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\A11CCB2D-BF83-496D-A097-D7341BC91ADD\\Triggers",
  202. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\A11CCB2D-BF83-496D-A097-D7341BC91ADD\\DynamicInfo",
  203. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\ED0D73D7-BC97-46E2-AC55-FD6EB3F72C05\\DynamicInfo"
  204.  
  205.  
  206. * Deleted Registry Keys:
  207. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\Java Maintenance64.job",
  208. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\Java Maintenance64.job.fp"
  209.  
  210.  
  211. * DNS Communications:
  212.  
  213. * Domains:
  214.  
  215. * Network Communication - ICMP:
  216.  
  217. * Network Communication - HTTP:
  218.  
  219. * Network Communication - SMTP:
  220.  
  221. * Network Communication - Hosts:
  222.  
  223. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment