paladin316

Exes_bb055b138c3bfff03d52781fe8e0eb17_exe_2019-07-13_20_30.txt

Jul 13th, 2019
2,255
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 8.30 KB | None | 0 0
  1.  
  2. * MalFamily: "Servhelper"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_bb055b138c3bfff03d52781fe8e0eb17.exe"
  7. * File Size: 411496
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive"
  9. * SHA256: "49516f2c59b5c73512353ced9740c3988af5c023f518ccd0dc04bfc68095540b"
  10. * MD5: "bb055b138c3bfff03d52781fe8e0eb17"
  11. * SHA1: "484646411fdddf66e412125fe9abd65c1db835ce"
  12. * SHA512: "71d6dae8d26d275cc9045d66d0a6f41b0e8fe4b0ec9fc9c7dca1a6d43e2cedfd44dee3535a6807373ec15d317d484e93060fd1d6e835cb5a45ec69cf2209b28d"
  13. * CRC32: "DBDD5AD1"
  14. * SSDEEP: "12288:iPDz1GgtSmcaWPUESCHn1kpYFLq1lsDTuSmUtn1N867T:iPH1h7LW2CqpYcPsnbbn1d"
  15.  
  16. * Process Execution:
  17. "Exes_bb055b138c3bfff03d52781fe8e0eb17.exe",
  18. "rundll32.exe",
  19. "cmd.exe",
  20. "powershell.exe",
  21. "net.exe",
  22. "net1.exe",
  23. "svchost.exe",
  24. "WmiPrvSE.exe"
  25.  
  26.  
  27. * Executed Commands:
  28. "\"rundll32.exe\" C:\\Users\\user\\AppData\\Local\\Temp\\printhlp.dll, nop",
  29. "cmd.exe /C powershell -nop -ep bypass -f C:\\Users\\user\\AppData\\Local\\Temp\\but.ps1",
  30. "powershell -nop -ep bypass -f C:\\Users\\user\\AppData\\Local\\Temp\\but.ps1",
  31. "\"C:\\Windows\\system32\\net.exe\" localgroup Administrators",
  32. "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding",
  33. "C:\\Windows\\system32\\net1 localgroup Administrators"
  34.  
  35.  
  36. * Signatures Detected:
  37.  
  38. "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
  39. "Details":
  40.  
  41. "IP": "94.158.245.196:80"
  42.  
  43.  
  44.  
  45.  
  46. "Description": "Creates RWX memory",
  47. "Details":
  48.  
  49.  
  50. "Description": "Reads data out of its own binary image",
  51. "Details":
  52.  
  53. "self_read": "process: Exes_bb055b138c3bfff03d52781fe8e0eb17.exe, pid: 1424, offset: 0x00000000, length: 0x0006331a"
  54.  
  55.  
  56. "self_read": "process: Exes_bb055b138c3bfff03d52781fe8e0eb17.exe, pid: 1424, offset: 0x00008c1c, length: 0x0005a702"
  57.  
  58.  
  59.  
  60.  
  61. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  62. "Details":
  63.  
  64. "post_no_referer": "HTTP traffic contains a POST request with no referer header"
  65.  
  66.  
  67. "suspicious_request": "http://stelar.icu/sun/s.php"
  68.  
  69.  
  70.  
  71.  
  72. "Description": "Performs some HTTP requests",
  73. "Details":
  74.  
  75. "url": "http://stelar.icu/sun/s.php"
  76.  
  77.  
  78.  
  79.  
  80. "Description": "A process attempted to delay the analysis task by a long amount of time.",
  81. "Details":
  82.  
  83. "Process": "rundll32.exe tried to sleep 3323 seconds, actually delayed analysis time by 0 seconds"
  84.  
  85.  
  86. "Process": "WmiPrvSE.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
  87.  
  88.  
  89.  
  90.  
  91. "Description": "File has been identified by 28 Antiviruses on VirusTotal as malicious",
  92. "Details":
  93.  
  94. "Bkav": "HW32.Packed."
  95.  
  96.  
  97. "McAfee": "RDN/Generic.dx"
  98.  
  99.  
  100. "AegisLab": "Trojan.Multi.Generic.4!c"
  101.  
  102.  
  103. "K7AntiVirus": "Trojan ( 005505201 )"
  104.  
  105.  
  106. "Alibaba": "Trojan:Win32/suspicious.a7f92228"
  107.  
  108.  
  109. "K7GW": "Trojan ( 005505201 )"
  110.  
  111.  
  112. "ESET-NOD32": "a variant of Win32/Delf.BJF"
  113.  
  114.  
  115. "Paloalto": "generic.ml"
  116.  
  117.  
  118. "Kaspersky": "Backdoor.Win32.Agent.mytoxz"
  119.  
  120.  
  121. "NANO-Antivirus": "Trojan.Win32.Delf.fsxwve"
  122.  
  123.  
  124. "Tencent": "Win32.Backdoor.Agent.Peph"
  125.  
  126.  
  127. "F-Secure": "Heuristic.HEUR/AGEN.1042403"
  128.  
  129.  
  130. "Qihoo-360": "HEUR/QVM20.1.7BC9.Malware.Gen"
  131.  
  132.  
  133. "Invincea": "heuristic"
  134.  
  135.  
  136. "McAfee-GW-Edition": "RDN/Generic.dx"
  137.  
  138.  
  139. "Sophos": "Mal/Generic-S"
  140.  
  141.  
  142. "Cyren": "W32/Trojan.ZKOX-5654"
  143.  
  144.  
  145. "Avira": "TR/AD.TA505.DS"
  146.  
  147.  
  148. "MAX": "malware (ai score=99)"
  149.  
  150.  
  151. "Microsoft": "Trojan:Win32/Bluteal!rfn"
  152.  
  153.  
  154. "Endgame": "malicious (moderate confidence)"
  155.  
  156.  
  157. "ZoneAlarm": "Backdoor.Win32.Agent.mytoxz"
  158.  
  159.  
  160. "GData": "NSIS.Trojan-Dropper.Agent.AMP"
  161.  
  162.  
  163. "Malwarebytes": "Backdoor.ServHelper"
  164.  
  165.  
  166. "Rising": "Backdoor.Agent!1.B95C (CLASSIC)"
  167.  
  168.  
  169. "Ikarus": "Backdoor.ServHelper"
  170.  
  171.  
  172. "AVG": "Win32:Trojan-gen"
  173.  
  174.  
  175. "Avast": "Win32:Trojan-gen"
  176.  
  177.  
  178.  
  179.  
  180. "Description": "Attempts to interact with an Alternate Data Stream (ADS)",
  181. "Details":
  182.  
  183. "file": "C:\\$Extend\\$Quota:$Q:$INDEX_ALLOCATION"
  184.  
  185.  
  186.  
  187.  
  188. "Description": "Created network traffic indicative of malicious activity",
  189. "Details":
  190.  
  191. "signature": "ET TROJAN ServHelper CnC Inital Checkin"
  192.  
  193.  
  194.  
  195.  
  196.  
  197. * Started Service:
  198.  
  199. * Mutexes:
  200. "Global\\mail_rfsa333445",
  201. "Global\\CLR_CASOFF_MUTEX",
  202. "DSKQUOTA_SIDCACHE_MUTEX"
  203.  
  204.  
  205. * Modified Files:
  206. "C:\\Users\\user\\AppData\\Local\\Temp\\nsjA19C.tmp",
  207. "C:\\Users\\user\\AppData\\Local\\Temp\\printhlp.dll",
  208. "C:\\Users\\user\\AppData\\Local\\Temp\\dxdiaad.lnk",
  209. "C:\\Users\\user\\AppData\\Local\\Temp\\but.ps1",
  210. "\\Device\\HarddiskVolume2\\\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
  211. "\\??\\PIPE\\srvsvc",
  212. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\RAFVULB37LY69K6DRXZ9.temp",
  213. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms",
  214. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
  215. "\\??\\WMIDataDevice",
  216. "\\??\\PIPE\\lsarpc",
  217. "\\??\\PIPE\\samr",
  218. "C:\\$Extend\\$Quota:$Q:$INDEX_ALLOCATION"
  219.  
  220.  
  221. * Deleted Files:
  222. "C:\\Users\\user\\AppData\\Local\\Temp\\nseA17C.tmp",
  223. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\RAFVULB37LY69K6DRXZ9.temp",
  224. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.3008.18340156",
  225. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.3008.18340156",
  226. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.3008.18340156"
  227.  
  228.  
  229. * Modified Registry Keys:
  230. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList"
  231.  
  232.  
  233. * Deleted Registry Keys:
  234.  
  235. * DNS Communications:
  236.  
  237. "type": "A",
  238. "request": "stelar.icu",
  239. "answers":
  240.  
  241. "data": "94.158.245.196",
  242. "type": "A"
  243.  
  244.  
  245.  
  246.  
  247.  
  248. * Domains:
  249.  
  250. "ip": "94.158.245.196",
  251. "domain": "stelar.icu"
  252.  
  253.  
  254.  
  255. * Network Communication - ICMP:
  256.  
  257. * Network Communication - HTTP:
  258.  
  259. "count": 23,
  260. "body": "",
  261. "uri": "http://stelar.icu/sun/s.php",
  262. "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0",
  263. "method": "POST",
  264. "host": "stelar.icu",
  265. "version": "1.1",
  266. "path": "/sun/s.php",
  267. "data": "POST /sun/s.php HTTP/1.1\r\nConnection: Keep-Alive\r\nContent-Type: application/x-www-form-urlencoded; charset=utf-8\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0\r\nContent-Length: 726\r\nHost: stelar.icu\r\n\r\n",
  268. "port": 80
  269.  
  270.  
  271.  
  272. * Network Communication - SMTP:
  273.  
  274. * Network Communication - Hosts:
  275.  
  276. * Network Communication - IRC:
Add Comment
Please, Sign In to add comment