Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: ""
- * MalScore: 10.0
- * File Name: "Exes_0c7d5383e6ed85a85f9f230875a17971.exe"
- * File Size: 5193216
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "6433f30b3c94ac217af4eea51d4c70b1160fd0cd73686239b3d7c0e3a0ebc7ac"
- * MD5: "0c7d5383e6ed85a85f9f230875a17971"
- * SHA1: "4428edd1e0ed1a996db1607721761bfb6702b80c"
- * SHA512: "4bed11794b6bbd24d37242c8539212616473f4ca72c65661013b462a0bd6dfd9afcba81970b7a7a1fd69e2899a42e1e4a6840a7d50347d468c35f298bdb3b63f"
- * CRC32: "BEAA5502"
- * SSDEEP: "98304:4lF3e7yCI6CTvBwA/TSwzrPyYMQq7nlaRfFzbm+HDK902f0b0/OP:4ze7/IPTHBzTyYMP7nURpmQK90Ihc"
- * Process Execution:
- "services.exe",
- "svchost.exe",
- "WmiPrvSE.exe",
- "svchost.exe",
- "taskhost.exe",
- "TrustedInstaller.exe",
- "svchost.exe",
- "WerFault.exe",
- "wermgr.exe"
- * Executed Commands:
- "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding",
- "taskhost.exe $(Arg0)",
- "C:\\Windows\\servicing\\TrustedInstaller.exe",
- "C:\\Windows\\System32\\svchost.exe -k WerSvcGroup",
- "C:\\Windows\\system32\\WerFault.exe -u -p 2220 -s 288",
- "\"C:\\Windows\\system32\\wermgr.exe\" \"-queuereporting_svc\" \"C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_d9cea5d53964d256a96f47a4e221d2152335d_cab_0959a688\""
- * Signatures Detected:
- "Description": "At least one process apparently crashed during execution",
- "Details":
- "Description": "A process attempted to delay the analysis task.",
- "Details":
- "Process": "WmiPrvSE.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
- "Description": "File has been identified by 8 Antiviruses on VirusTotal as malicious",
- "Details":
- "FireEye": "Generic.mg.0c7d5383e6ed85a8"
- "Cybereason": "malicious.1e0ed1"
- "Invincea": "heuristic"
- "Kaspersky": "UDS:DangerousObject.Multi.Generic"
- "Endgame": "malicious (high confidence)"
- "Microsoft": "Trojan:Win32/Wacatac.B!ml"
- "VBA32": "BScope.Backdoor.Mokes"
- "CrowdStrike": "win/malicious_confidence_100% (D)"
- "Description": "Attempts to restart the guest VM",
- "Details":
- "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
- "Details":
- "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 3334184 times"
- "Description": "Network activity detected but not expressed in API logs",
- "Details":
- "Description": "Retrieves Windows ProductID, probably to fingerprint the sandbox",
- "Details":
- "Description": "Checks the CPU name from registry, possibly for anti-virtualization",
- "Details":
- "Description": "Checks the system manufacturer, likely for anti-virtualization",
- "Details":
- "Description": "Collects information to fingerprint the system",
- "Details":
- * Started Service:
- "WerSvc"
- * Mutexes:
- "Global\\WdsSetupLogInit",
- "Global\\SetupLog",
- "Local\\WERReportingForProcess2220",
- "Global\\\\xe5\\x88\\x90\\xc2\\x8e",
- "Global\\\\xed\\x95\\xb02",
- "WERUI_BEX64-d9cea5d53964d256a96f47a4e221d2152335d"
- * Modified Files:
- "\\??\\PIPE\\samr",
- "C:\\Windows\\sysnative\\wbem\\repository\\WRITABLE.TST",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING1.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING2.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING3.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\OBJECTS.DATA",
- "C:\\Windows\\sysnative\\wbem\\repository\\INDEX.BTR",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER",
- "\\??\\PIPE\\wkssvc",
- "\\??\\PIPE\\srvsvc",
- "\\??\\WMIDataDevice",
- "C:\\Windows\\sysnative\\LogFiles\\Scm\\4963ad21-c4a5-42a5-b9bd-e441d57204fe",
- "C:\\Windows\\sysnative\\LogFiles\\Scm\\f322b78e-2a43-4940-a5a1-464b99326825",
- "C:\\Windows\\Logs\\CBS\\CBS.log",
- "C:\\BVTBin\\Tests\\installpackage\\csilogfile.log",
- "C:\\Windows\\winsxs\\ManifestCache\\ee9f676b8aa4122b_blobs.bin",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA971.tmp.appcompat.txt",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERAD7A.tmp.WERInternalMetadata.xml",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERADF8.tmp.hdmp",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERE600.tmp.mdmp",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_d9cea5d53964d256a96f47a4e221d2152335d_cab_0959a688\\WERA971.tmp.appcompat.txt",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_d9cea5d53964d256a96f47a4e221d2152335d_cab_0959a688\\WERAD7A.tmp.WERInternalMetadata.xml",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_d9cea5d53964d256a96f47a4e221d2152335d_cab_0959a688\\WERADF8.tmp.hdmp",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_d9cea5d53964d256a96f47a4e221d2152335d_cab_0959a688\\WERE600.tmp.mdmp",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_d9cea5d53964d256a96f47a4e221d2152335d_cab_0959a688\\Report.wer",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_d9cea5d53964d256a96f47a4e221d2152335d_cab_0959a688\\Report.wer.tmp"
- * Deleted Files:
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA971.tmp",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA971.tmp.appcompat.txt",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERAD7A.tmp",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERAD7A.tmp.WERInternalMetadata.xml",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERADF8.tmp",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERADF8.tmp.hdmp",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERE600.tmp",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERE600.tmp.mdmp",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_d9cea5d53964d256a96f47a4e221d2152335d_cab_0959a688\\Report.wer.tmp"
- * Modified Registry Keys:
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Wbem\\Transports\\Decoupled\\Server",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\CreationTime",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\MarshaledProxy",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\ProcessIdentifier",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ConfigValueEssNeedsLoading",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\List of event-active namespaces",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\ESS\\//./root/CIMV2\\SCM Event Provider",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
- "HKEY_LOCAL_MACHINE\\COMPONENTS\\ServicingStackVersions\\6.1.7601.17514 (win7sp1_rtm.101119-1850)",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent\\DefaultConsent"
- * Deleted Registry Keys:
- "HKEY_LOCAL_MACHINE\\COMPONENTS\\PendingXmlIdentifier",
- "HKEY_LOCAL_MACHINE\\COMPONENTS\\PoqexecFailure",
- "HKEY_LOCAL_MACHINE\\COMPONENTS\\ExecutionState",
- "HKEY_LOCAL_MACHINE\\COMPONENTS\\RepairTransactionPended"
- * DNS Communications:
- "type": "A",
- "request": "venoxcontrol.com",
- "answers":
- "data": "104.26.15.130",
- "type": "A"
- "data": "104.26.14.130",
- "type": "A"
- * Domains:
- "ip": "104.26.15.130",
- "domain": "venoxcontrol.com"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment