paladin316

AZORult_8d771e2dfc37a691d1620d670af18d33_exe_2019-08-01_09_30.txt

Aug 1st, 2019
2,097
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 6.09 KB | None | 0 0
  1.  
  2. * MalFamily: ""
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "AZORult_8d771e2dfc37a691d1620d670af18d33.exe"
  7. * File Size: 914944
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "72938db390deef0a57fe8a7a045eb26cf90e2b997ffec5dbbe9afb92703f3dcc"
  10. * MD5: "8d771e2dfc37a691d1620d670af18d33"
  11. * SHA1: "8ede3a7b6407082fbdfdf9a8bf41f2c10addcf46"
  12. * SHA512: "14b657d6f3f2c6915e9723be228cff22dfb50bf850e03a435a8e2040e721ef65234a56fd40739fc339c3210d8a55313aa2c51123a4fbe4a9d453d8b2dd87907b"
  13. * CRC32: "D8789640"
  14. * SSDEEP: "12288:TqMitwH6AjLdDQSPY2E3k3txmKJwPKJseWKG8jAoe4utFvwMoDZtRR06he:eErLdDcnkd5JmKp5+oDoFzgZ906s"
  15.  
  16. * Process Execution:
  17. "AZORult_8d771e2dfc37a691d1620d670af18d33.exe",
  18. "AZORult_8d771e2dfc37a691d1620d670af18d33.exe"
  19.  
  20.  
  21. * Executed Commands:
  22. "\"C:\\Users\\user\\AppData\\Local\\Temp\\AZORult_8d771e2dfc37a691d1620d670af18d33.exe\""
  23.  
  24.  
  25. * Signatures Detected:
  26.  
  27. "Description": "Creates RWX memory",
  28. "Details":
  29.  
  30.  
  31. "Description": "Possible date expiration check, exits too soon after checking local time",
  32. "Details":
  33.  
  34. "process": "AZORult_8d771e2dfc37a691d1620d670af18d33.exe, PID 2536"
  35.  
  36.  
  37.  
  38.  
  39. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  40. "Details":
  41.  
  42. "post_no_referer": "HTTP traffic contains a POST request with no referer header"
  43.  
  44.  
  45. "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
  46.  
  47.  
  48. "suspicious_request": "http://188.209.52.182/index.php"
  49.  
  50.  
  51.  
  52.  
  53. "Description": "Performs some HTTP requests",
  54. "Details":
  55.  
  56. "url": "http://188.209.52.182/index.php"
  57.  
  58.  
  59.  
  60.  
  61. "Description": "The binary likely contains encrypted or compressed data.",
  62. "Details":
  63.  
  64. "section": "name: .rsrc, entropy: 6.99, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ, raw_size: 0x0002ce00, virtual_size: 0x0002cd6c"
  65.  
  66.  
  67.  
  68.  
  69. "Description": "Executed a process and injected code into it, probably while unpacking",
  70. "Details":
  71.  
  72. "Injection": "AZORult_8d771e2dfc37a691d1620d670af18d33.exe(1812) -> AZORult_8d771e2dfc37a691d1620d670af18d33.exe(2536)"
  73.  
  74.  
  75.  
  76.  
  77. "Description": "File has been identified by 22 Antiviruses on VirusTotal as malicious",
  78. "Details":
  79.  
  80. "FireEye": "Generic.mg.8d771e2dfc37a691"
  81.  
  82.  
  83. "Cylance": "Unsafe"
  84.  
  85.  
  86. "K7GW": "Trojan ( 005543041 )"
  87.  
  88.  
  89. "K7AntiVirus": "Trojan ( 005543041 )"
  90.  
  91.  
  92. "TrendMicro": "TrojanSpy.Win32.LOKI.SMDD.hp"
  93.  
  94.  
  95. "Symantec": "Packed.Generic.516"
  96.  
  97.  
  98. "Paloalto": "generic.ml"
  99.  
  100.  
  101. "Kaspersky": "HEUR:Backdoor.Win32.Androm.gen"
  102.  
  103.  
  104. "Endgame": "malicious (high confidence)"
  105.  
  106.  
  107. "Invincea": "heuristic"
  108.  
  109.  
  110. "McAfee-GW-Edition": "BehavesLike.Win32.Fareit.ch"
  111.  
  112.  
  113. "Microsoft": "Trojan:Win32/Wacatac.B!ml"
  114.  
  115.  
  116. "ZoneAlarm": "HEUR:Backdoor.Win32.Androm.gen"
  117.  
  118.  
  119. "AhnLab-V3": "Win-Trojan/Delphiless.Exp"
  120.  
  121.  
  122. "Acronis": "suspicious"
  123.  
  124.  
  125. "ESET-NOD32": "a variant of Win32/Injector.EGXY"
  126.  
  127.  
  128. "TrendMicro-HouseCall": "TrojanSpy.Win32.LOKI.SMDD.hp"
  129.  
  130.  
  131. "Rising": "Trojan.Injector!1.AFE3 (CLASSIC)"
  132.  
  133.  
  134. "Fortinet": "W32/Generic.AC.45B3D4!tr"
  135.  
  136.  
  137. "Cybereason": "malicious.b64070"
  138.  
  139.  
  140. "Panda": "Trj/GdSda.A"
  141.  
  142.  
  143. "CrowdStrike": "win/malicious_confidence_90% (W)"
  144.  
  145.  
  146.  
  147.  
  148. "Description": "Collects information to fingerprint the system",
  149. "Details":
  150.  
  151.  
  152. "Description": "Anomalous binary characteristics",
  153. "Details":
  154.  
  155. "anomaly": "Timestamp on binary predates the release date of the OS version it requires by at least a year"
  156.  
  157.  
  158.  
  159.  
  160.  
  161. * Started Service:
  162.  
  163. * Mutexes:
  164. "A81FB8C60-BBE6E186-FC9B5DB5-36DA4559-33946726"
  165.  
  166.  
  167. * Modified Files:
  168.  
  169. * Deleted Files:
  170.  
  171. * Modified Registry Keys:
  172.  
  173. * Deleted Registry Keys:
  174.  
  175. * DNS Communications:
  176.  
  177. * Domains:
  178.  
  179. * Network Communication - ICMP:
  180.  
  181. * Network Communication - HTTP:
  182.  
  183. "count": 1,
  184. "body": "\\x00\\x00\\x00&f\\x96&f\\x9fE\\x17\\x8b0m\\xed&f\\x98&f\\x9e&g\\xeaA\\x17\\xeb&f\\x98Fp\\x9d2p\\x9d;p\\x9d5p\\x9cG\\x13\\xed&f\\x97Ap\\x9d6\\x11\\xec&f\\x9b&g\\xea&f\\x9d&f\\x98G\\x14\\x8b0a\\x8b0`\\x8b0`\\x8b0l\\x8b1\\x11\\x8b0f\\x8b0f\\x8b0l\\x8b0a\\x8b0c\\x8b0b\\x8b0g\\x8b0c",
  185. "uri": "http://188.209.52.182/index.php",
  186. "user-agent": "Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.1)",
  187. "method": "POST",
  188. "host": "188.209.52.182",
  189. "version": "1.1",
  190. "path": "/index.php",
  191. "data": "POST /index.php HTTP/1.1\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 6.0b; Windows NT 5.1)\r\nHost: 188.209.52.182\r\nContent-Length: 107\r\nCache-Control: no-cache\r\n\r\n\\x00\\x00\\x00&f\\x96&f\\x9fE\\x17\\x8b0m\\xed&f\\x98&f\\x9e&g\\xeaA\\x17\\xeb&f\\x98Fp\\x9d2p\\x9d;p\\x9d5p\\x9cG\\x13\\xed&f\\x97Ap\\x9d6\\x11\\xec&f\\x9b&g\\xea&f\\x9d&f\\x98G\\x14\\x8b0a\\x8b0`\\x8b0`\\x8b0l\\x8b1\\x11\\x8b0f\\x8b0f\\x8b0l\\x8b0a\\x8b0c\\x8b0b\\x8b0g\\x8b0c",
  192. "port": 80
  193.  
  194.  
  195.  
  196. * Network Communication - SMTP:
  197.  
  198. * Network Communication - Hosts:
  199.  
  200. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment