Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Servhelper"
- * MalScore: 10.0
- * File Name: "Exes_bb055b138c3bfff03d52781fe8e0eb17.exe"
- * File Size: 411496
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive"
- * SHA256: "49516f2c59b5c73512353ced9740c3988af5c023f518ccd0dc04bfc68095540b"
- * MD5: "bb055b138c3bfff03d52781fe8e0eb17"
- * SHA1: "484646411fdddf66e412125fe9abd65c1db835ce"
- * SHA512: "71d6dae8d26d275cc9045d66d0a6f41b0e8fe4b0ec9fc9c7dca1a6d43e2cedfd44dee3535a6807373ec15d317d484e93060fd1d6e835cb5a45ec69cf2209b28d"
- * CRC32: "DBDD5AD1"
- * SSDEEP: "12288:iPDz1GgtSmcaWPUESCHn1kpYFLq1lsDTuSmUtn1N867T:iPH1h7LW2CqpYcPsnbbn1d"
- * Process Execution:
- "Exes_bb055b138c3bfff03d52781fe8e0eb17.exe",
- "rundll32.exe",
- "cmd.exe",
- "powershell.exe",
- "net.exe",
- "net1.exe",
- "svchost.exe",
- "WmiPrvSE.exe"
- * Executed Commands:
- "\"rundll32.exe\" C:\\Users\\user\\AppData\\Local\\Temp\\printhlp.dll, nop",
- "cmd.exe /C powershell -nop -ep bypass -f C:\\Users\\user\\AppData\\Local\\Temp\\but.ps1",
- "powershell -nop -ep bypass -f C:\\Users\\user\\AppData\\Local\\Temp\\but.ps1",
- "\"C:\\Windows\\system32\\net.exe\" localgroup Administrators",
- "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding",
- "C:\\Windows\\system32\\net1 localgroup Administrators"
- * Signatures Detected:
- "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
- "Details":
- "IP": "94.158.245.196:80"
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: Exes_bb055b138c3bfff03d52781fe8e0eb17.exe, pid: 1424, offset: 0x00000000, length: 0x0006331a"
- "self_read": "process: Exes_bb055b138c3bfff03d52781fe8e0eb17.exe, pid: 1424, offset: 0x00008c1c, length: 0x0005a702"
- "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
- "Details":
- "post_no_referer": "HTTP traffic contains a POST request with no referer header"
- "suspicious_request": "http://stelar.icu/sun/s.php"
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://stelar.icu/sun/s.php"
- "Description": "A process attempted to delay the analysis task by a long amount of time.",
- "Details":
- "Process": "rundll32.exe tried to sleep 3323 seconds, actually delayed analysis time by 0 seconds"
- "Process": "WmiPrvSE.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
- "Description": "File has been identified by 28 Antiviruses on VirusTotal as malicious",
- "Details":
- "Bkav": "HW32.Packed."
- "McAfee": "RDN/Generic.dx"
- "AegisLab": "Trojan.Multi.Generic.4!c"
- "K7AntiVirus": "Trojan ( 005505201 )"
- "Alibaba": "Trojan:Win32/suspicious.a7f92228"
- "K7GW": "Trojan ( 005505201 )"
- "ESET-NOD32": "a variant of Win32/Delf.BJF"
- "Paloalto": "generic.ml"
- "Kaspersky": "Backdoor.Win32.Agent.mytoxz"
- "NANO-Antivirus": "Trojan.Win32.Delf.fsxwve"
- "Tencent": "Win32.Backdoor.Agent.Peph"
- "F-Secure": "Heuristic.HEUR/AGEN.1042403"
- "Qihoo-360": "HEUR/QVM20.1.7BC9.Malware.Gen"
- "Invincea": "heuristic"
- "McAfee-GW-Edition": "RDN/Generic.dx"
- "Sophos": "Mal/Generic-S"
- "Cyren": "W32/Trojan.ZKOX-5654"
- "Avira": "TR/AD.TA505.DS"
- "MAX": "malware (ai score=99)"
- "Microsoft": "Trojan:Win32/Bluteal!rfn"
- "Endgame": "malicious (moderate confidence)"
- "ZoneAlarm": "Backdoor.Win32.Agent.mytoxz"
- "GData": "NSIS.Trojan-Dropper.Agent.AMP"
- "Malwarebytes": "Backdoor.ServHelper"
- "Rising": "Backdoor.Agent!1.B95C (CLASSIC)"
- "Ikarus": "Backdoor.ServHelper"
- "AVG": "Win32:Trojan-gen"
- "Avast": "Win32:Trojan-gen"
- "Description": "Attempts to interact with an Alternate Data Stream (ADS)",
- "Details":
- "file": "C:\\$Extend\\$Quota:$Q:$INDEX_ALLOCATION"
- "Description": "Created network traffic indicative of malicious activity",
- "Details":
- "signature": "ET TROJAN ServHelper CnC Inital Checkin"
- * Started Service:
- * Mutexes:
- "Global\\mail_rfsa333445",
- "Global\\CLR_CASOFF_MUTEX",
- "DSKQUOTA_SIDCACHE_MUTEX"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\nsjA19C.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\printhlp.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\dxdiaad.lnk",
- "C:\\Users\\user\\AppData\\Local\\Temp\\but.ps1",
- "\\Device\\HarddiskVolume2\\\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
- "\\??\\PIPE\\srvsvc",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\RAFVULB37LY69K6DRXZ9.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
- "\\??\\WMIDataDevice",
- "\\??\\PIPE\\lsarpc",
- "\\??\\PIPE\\samr",
- "C:\\$Extend\\$Quota:$Q:$INDEX_ALLOCATION"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\nseA17C.tmp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\RAFVULB37LY69K6DRXZ9.temp",
- "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.3008.18340156",
- "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.3008.18340156",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.3008.18340156"
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList"
- * Deleted Registry Keys:
- * DNS Communications:
- "type": "A",
- "request": "stelar.icu",
- "answers":
- "data": "94.158.245.196",
- "type": "A"
- * Domains:
- "ip": "94.158.245.196",
- "domain": "stelar.icu"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 23,
- "body": "",
- "uri": "http://stelar.icu/sun/s.php",
- "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0",
- "method": "POST",
- "host": "stelar.icu",
- "version": "1.1",
- "path": "/sun/s.php",
- "data": "POST /sun/s.php HTTP/1.1\r\nConnection: Keep-Alive\r\nContent-Type: application/x-www-form-urlencoded; charset=utf-8\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0\r\nContent-Length: 726\r\nHost: stelar.icu\r\n\r\n",
- "port": 80
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Add Comment
Please, Sign In to add comment