paladin316

remcos_sfc_exe_2019-08-21_11_50.txt

Aug 21st, 2019
2,168
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 15.51 KB | None | 0 0
  1.  
  2. * MalFamily: "Remcos"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "sfc.exe"
  7. * File Size: 1179144
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "472ce643d1faee0ead973e9b2815a89146e9b3828f1831bc47fc34e4357925d8"
  10. * MD5: "aff397aec5719af3f28e070f2c547fda"
  11. * SHA1: "985f8bbd87762cd009926aa8ae0128a565b8dfb3"
  12. * SHA512: "1f98f224462d98c897b60158aba240de9cb6e999e8d77d4c6c8f7e364047fc26a2a7392327f76350fce4bedaf965d20ee934d4be9e6520cc7b51dc2a72752385"
  13. * CRC32: "EC91B8ED"
  14. * SSDEEP: "24576:yAHnh+eWsN3skA4RV1Hom2KXMmHaLIahgxY3b5u:1h+ZkldoPK8YaLDNu"
  15.  
  16. * Process Execution:
  17. "sfc.exe",
  18. "sfc.exe",
  19. "wscript.exe",
  20. "cmd.exe",
  21. "remcos.exe",
  22. "remcos.exe",
  23. "svchost.exe",
  24. "svchost.exe",
  25. "schtasks.exe",
  26. "schtasks.exe",
  27. "svchost.exe"
  28.  
  29.  
  30. * Executed Commands:
  31. "\"C:\\Windows\\SysWOW64\\schtasks.exe\" /create /tn setx /tr \"C:\\Users\\user\\AppData\\Roaming\\CapabilityAccessHandlers\\sfc.exe\" /sc minute /mo 1 /F",
  32. "schtasks /create /tn setx /tr \"C:\\Users\\user\\AppData\\Roaming\\CapabilityAccessHandlers\\sfc.exe\" /sc minute /mo 1 /F",
  33. "\"C:\\Windows\\System32\\WScript.exe\" \"C:\\Users\\user\\AppData\\Local\\Temp\\install.vbs\"",
  34. "C:\\Users\\user\\AppData\\Local\\Temp\\install.vbs ",
  35. "\"C:\\Windows\\System32\\cmd.exe\" /c \"C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe\"",
  36. "cmd /c \"C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe\"",
  37. "C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe",
  38. "C:\\Windows\\SysWOW64\\svchost.exe"
  39.  
  40.  
  41. * Signatures Detected:
  42.  
  43. "Description": "Creates RWX memory",
  44. "Details":
  45.  
  46.  
  47. "Description": "Possible date expiration check, exits too soon after checking local time",
  48. "Details":
  49.  
  50. "process": "schtasks.exe, PID 2668"
  51.  
  52.  
  53.  
  54.  
  55. "Description": "Detected script timer window indicative of sleep style evasion",
  56. "Details":
  57.  
  58. "Window": "WSH-Timer"
  59.  
  60.  
  61.  
  62.  
  63. "Description": "A process attempted to delay the analysis task.",
  64. "Details":
  65.  
  66. "Process": "remcos.exe tried to sleep 1975 seconds, actually delayed analysis time by 0 seconds"
  67.  
  68.  
  69.  
  70.  
  71. "Description": "Reads data out of its own binary image",
  72. "Details":
  73.  
  74. "self_read": "process: sfc.exe, pid: 2208, offset: 0x00000000, length: 0x0011fe08"
  75.  
  76.  
  77. "self_read": "process: wscript.exe, pid: 1548, offset: 0x00000000, length: 0x00000040"
  78.  
  79.  
  80. "self_read": "process: wscript.exe, pid: 1548, offset: 0x000000f0, length: 0x00000018"
  81.  
  82.  
  83. "self_read": "process: wscript.exe, pid: 1548, offset: 0x000001e8, length: 0x00000078"
  84.  
  85.  
  86. "self_read": "process: wscript.exe, pid: 1548, offset: 0x00018000, length: 0x00000020"
  87.  
  88.  
  89. "self_read": "process: wscript.exe, pid: 1548, offset: 0x00018058, length: 0x00000018"
  90.  
  91.  
  92. "self_read": "process: wscript.exe, pid: 1548, offset: 0x000181a8, length: 0x00000018"
  93.  
  94.  
  95. "self_read": "process: wscript.exe, pid: 1548, offset: 0x00018470, length: 0x00000010"
  96.  
  97.  
  98. "self_read": "process: wscript.exe, pid: 1548, offset: 0x00018640, length: 0x00000012"
  99.  
  100.  
  101. "self_read": "process: remcos.exe, pid: 1032, offset: 0x00000000, length: 0x0011fe08"
  102.  
  103.  
  104. "self_read": "process: remcos.exe, pid: 2112, offset: 0x00000000, length: 0x0011fe08"
  105.  
  106.  
  107.  
  108.  
  109. "Description": "A process created a hidden window",
  110. "Details":
  111.  
  112. "Process": "sfc.exe -> schtasks"
  113.  
  114.  
  115. "Process": "sfc.exe -> C:\\Users\\user\\AppData\\Local\\Temp\\install.vbs"
  116.  
  117.  
  118. "Process": "wscript.exe -> cmd"
  119.  
  120.  
  121. "Process": "remcos.exe -> schtasks"
  122.  
  123.  
  124.  
  125.  
  126. "Description": "Drops a binary and executes it",
  127. "Details":
  128.  
  129. "binary": "C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe"
  130.  
  131.  
  132.  
  133.  
  134. "Description": "Executed a process and injected code into it, probably while unpacking",
  135. "Details":
  136.  
  137. "Injection": "sfc.exe(2208) -> sfc.exe(2220)"
  138.  
  139.  
  140.  
  141.  
  142. "Description": "Sniffs keystrokes",
  143. "Details":
  144.  
  145. "SetWindowsHookExA": "Process: remcos.exe(2112)"
  146.  
  147.  
  148.  
  149.  
  150. "Description": "Attempts to execute a Living Off The Land Binary command for post exeploitation",
  151. "Details":
  152.  
  153. "MITRE T1078 - schtask": "(Tactic: Execution, Persistence, Privilege Escalation)"
  154.  
  155.  
  156.  
  157.  
  158. "Description": "Installs itself for autorun at Windows startup",
  159. "Details":
  160.  
  161. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\remcos"
  162.  
  163.  
  164. "data": "\"C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe\""
  165.  
  166.  
  167. "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\remcos"
  168.  
  169.  
  170. "data": "\"C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe\""
  171.  
  172.  
  173. "task": "\"C:\\Windows\\SysWOW64\\schtasks.exe\" /create /tn setx /tr \"C:\\Users\\user\\AppData\\Roaming\\CapabilityAccessHandlers\\sfc.exe\" /sc minute /mo 1 /F"
  174.  
  175.  
  176.  
  177.  
  178. "Description": "Creates a hidden or system file",
  179. "Details":
  180.  
  181. "file": "C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe"
  182.  
  183.  
  184. "file": "C:\\Users\\user\\AppData\\Roaming\\remcos"
  185.  
  186.  
  187. "file": "C:\\Users\\user\\AppData\\Roaming\\remcos\\logs.dat"
  188.  
  189.  
  190.  
  191.  
  192. "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
  193. "Details":
  194.  
  195. "target": "clamav:Win.Malware.Autoit-6985962-0, sha256:472ce643d1faee0ead973e9b2815a89146e9b3828f1831bc47fc34e4357925d8, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  196.  
  197.  
  198. "dropped": "clamav:Win.Malware.Autoit-6985962-0, sha256:472ce643d1faee0ead973e9b2815a89146e9b3828f1831bc47fc34e4357925d8 , guest_paths:C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  199.  
  200.  
  201. "dropped": "clamav:Win.Malware.Autoit-6985962-0, sha256:129e0037e6a7ca02905cf54c3e5008e862202699c5326af0786726324978b292 , guest_paths:C:\\Users\\user\\AppData\\Roaming\\CapabilityAccessHandlers\\sfc.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  202.  
  203.  
  204.  
  205.  
  206. "Description": "Creates a copy of itself",
  207. "Details":
  208.  
  209. "copy": "C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe"
  210.  
  211.  
  212.  
  213.  
  214. "Description": "Creates a slightly modified copy of itself",
  215. "Details":
  216.  
  217. "file": "C:\\Users\\user\\AppData\\Roaming\\CapabilityAccessHandlers\\sfc.exe"
  218.  
  219.  
  220. "percent_match": 99
  221.  
  222.  
  223.  
  224.  
  225. "Description": "Anomalous binary characteristics",
  226. "Details":
  227.  
  228. "anomaly": "Actual checksum does not match that reported in PE header"
  229.  
  230.  
  231.  
  232.  
  233. "Description": "Clears web history",
  234. "Details":
  235.  
  236. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\index.dat"
  237.  
  238.  
  239. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  240.  
  241.  
  242. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  243.  
  244.  
  245. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  246.  
  247.  
  248. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  249.  
  250.  
  251. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\Low"
  252.  
  253.  
  254. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  255.  
  256.  
  257. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  258.  
  259.  
  260. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  261.  
  262.  
  263. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  264.  
  265.  
  266. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  267.  
  268.  
  269. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  270.  
  271.  
  272. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  273.  
  274.  
  275. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  276.  
  277.  
  278. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\Low\\index.dat"
  279.  
  280.  
  281. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  282.  
  283.  
  284. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  285.  
  286.  
  287. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  288.  
  289.  
  290. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  291.  
  292.  
  293.  
  294.  
  295.  
  296. * Started Service:
  297.  
  298. * Mutexes:
  299. "MDMAppInstaller",
  300. "Local\\ZoneAttributeCacheCounterMutex",
  301. "Local\\ZonesCacheCounterMutex",
  302. "Local\\ZonesLockedCacheCounterMutex",
  303. "Remcos_Mutex_Inj",
  304. "Remcos-S1KNPZ",
  305. "Mutex_RemWatchdog"
  306.  
  307.  
  308. * Modified Files:
  309. "C:\\Users\\user\\AppData\\Roaming\\CapabilityAccessHandlers\\sfc.exe",
  310. "C:\\Users\\user\\AppData\\Roaming\\remcos\\remcos.exe",
  311. "C:\\Users\\user\\AppData\\Local\\Temp\\install.vbs",
  312. "C:\\Windows\\sysnative\\Tasks\\setx",
  313. "C:\\Windows\\appcompat\\Programs\\RecentFileCache.bcf",
  314. "C:\\Users\\user\\AppData\\Roaming\\remcos\\logs.dat"
  315.  
  316.  
  317. * Deleted Files:
  318. "C:\\Windows\\Tasks\\setx.job",
  319. "C:\\Users\\user\\AppData\\Local\\Temp\\install.vbs",
  320. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\index.dat",
  321. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\Low\\index.dat",
  322. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\Low",
  323. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]",
  324. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]",
  325. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]",
  326. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]",
  327. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]",
  328. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]",
  329. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]",
  330. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]",
  331. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]",
  332. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]",
  333. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]",
  334. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]",
  335. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]",
  336. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]",
  337. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]",
  338. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]",
  339. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies",
  340. "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cookies",
  341. "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data"
  342.  
  343.  
  344. * Modified Registry Keys:
  345. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
  346. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
  347. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\remcos",
  348. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\remcos",
  349. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\371C7AE0-E7B0-4535-8AD0-2D046DB26874\\Path",
  350. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\371C7AE0-E7B0-4535-8AD0-2D046DB26874\\Hash",
  351. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\setx\\Id",
  352. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\setx\\Index",
  353. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\371C7AE0-E7B0-4535-8AD0-2D046DB26874\\Triggers",
  354. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\371C7AE0-E7B0-4535-8AD0-2D046DB26874\\DynamicInfo",
  355. "HKEY_CURRENT_USER\\Software\\Remcos-S1KNPZ\\",
  356. "HKEY_CURRENT_USER\\Software\\Remcos-S1KNPZ\\exepath",
  357. "HKEY_CURRENT_USER\\Software\\Remcos-S1KNPZ\\licence",
  358. "HKEY_CURRENT_USER\\Software\\Remcos-S1KNPZ\\WD",
  359. "HKEY_CURRENT_USER\\Software\\Remcos-S1KNPZ\\FR"
  360.  
  361.  
  362. * Deleted Registry Keys:
  363. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  364. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  365. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  366. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  367. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\setx.job",
  368. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\setx.job.fp"
  369.  
  370.  
  371. * DNS Communications:
  372.  
  373. "type": "A",
  374. "request": "daya4659.ddns.net",
  375. "answers":
  376.  
  377.  
  378.  
  379. * Domains:
  380.  
  381. "ip": "",
  382. "domain": "daya4659.ddns.net"
  383.  
  384.  
  385.  
  386. * Network Communication - ICMP:
  387.  
  388. * Network Communication - HTTP:
  389.  
  390. * Network Communication - SMTP:
  391.  
  392. * Network Communication - Hosts:
  393.  
  394. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment