Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Wacatac"
- * MalScore: 10.0
- * File Name: "Exes_00059bfa891130928bd714605bf0f0d8.msi"
- * File Size: 724992
- * File Type: "Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Code page: 1252, Last Printed: Fri Sep 21 09:56:09 2012, Create Time/Date: Fri Sep 21 09:56:09 2012, Name of Creating Application: Windows Installer, Title: Exe to msi converter free, Author: www.exetomsi.com, Template: ;0, Last Saved By: devuser, Revision Number: C35CF0AA-9B3F-4903-9F05-EBF606D58D3E Last Saved Time/Date: Tue May 21 11:56:44 2013, Number of Pages: 100, Number of Words: 0, Security: 0"
- * SHA256: "2d38f2790654960756fa1dec4bf9cabc0ce0fb1fbe17919b844b1dd6ce1acd1d"
- * MD5: "00059bfa891130928bd714605bf0f0d8"
- * SHA1: "a347931efdc2fed67f44e4887484afa553420a14"
- * SHA512: "6d25801f4c48e542c41697a5d3cf6f0b38b012ec8b8b45086ec7d84e0b7434eb14f267496a08f2266b804375ae4afcf42f5ca0b6818ac6ecc5e02032a3bd46e4"
- * CRC32: "F7F7B4B5"
- * SSDEEP: "12288:+E+G3vYW2TWmprd2uZNkWOm50LZwqCz/R2jnkW85Qhl5GhZbHpq:+E+G/YdTPd2uZNkWTsZwv2jb85QpG/Hp"
- * Process Execution:
- "msiexec.exe"
- * Executed Commands:
- * Signatures Detected:
- "Description": "File has been identified by 28 Antiviruses on VirusTotal as malicious",
- "Details":
- "FireEye": "Gen:Variant.VB.Kryptik.2"
- "CAT-QuickHeal": "Trojan.Multi"
- "McAfee": "RDN/Generic.dx"
- "Arcabit": "Trojan.VB.Kryptik.2"
- "TrendMicro": "Trojan.Win32.BAMAPANO.SM3.hp"
- "Cyren": "W32/Trojan.GSFX-3181"
- "TrendMicro-HouseCall": "Trojan.Win32.BAMAPANO.SM3.hp"
- "Avast": "Win32:CrypterX-gen Trj"
- "Kaspersky": "Trojan.MSIL.Revenge.daq"
- "BitDefender": "Gen:Variant.VB.Kryptik.2"
- "NANO-Antivirus": "Trojan.Win32.Revenge.fskqjc"
- "Rising": "Trojan.Wacatac!8.10C01 (TFE:5:bj5UqByHLyL)"
- "Emsisoft": "Gen:Variant.VB.Kryptik.2 (B)"
- "F-Secure": "Trojan.TR/Kryptik.mazws"
- "DrWeb": "Trojan.PWS.Siggen2.20930"
- "Invincea": "heuristic"
- "McAfee-GW-Edition": "RDN/Generic.dx"
- "Sophos": "Troj/Mdrop-ITC"
- "MAX": "malware (ai score=86)"
- "Antiy-AVL": "Trojan/Win32.Wacatac"
- "Microsoft": "Trojan:Win32/Wacatac.B!ml"
- "ZoneAlarm": "HEUR:Trojan.OLE2.Alien.gen"
- "GData": "Gen:Variant.VB.Kryptik.2"
- "AhnLab-V3": "Win-Trojan/VBKrypt.RP09"
- "VBA32": "Trojan.Wacatac"
- "ESET-NOD32": "a variant of Win32/GenKryptik.DMMK"
- "Ikarus": "Trojan.Win32.Krypt"
- "AVG": "Win32:CrypterX-gen Trj"
- * Started Service:
- * Mutexes:
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1",
- "Global\\_MSIExecute"
- * Modified Files:
- * Deleted Files:
- * Modified Registry Keys:
- * Deleted Registry Keys:
- * DNS Communications:
- "type": "A",
- "request": "vemvemserver.duckdns.org",
- "answers":
- "data": "205.185.125.42",
- "type": "A"
- * Domains:
- "ip": "205.185.125.42",
- "domain": "vemvemserver.duckdns.org"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment