paladin316

Exes_1eb383c0cb6f534e113975efea309511_exe_2019-07-10_10_30.txt

Jul 10th, 2019
2,132
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 10.39 KB | None | 0 0
  1.  
  2. * MalFamily: ""
  3.  
  4. * MalScore: 7.3999999999999995
  5.  
  6. * File Name: "Exes_1eb383c0cb6f534e113975efea309511.exe"
  7. * File Size: 2029568
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "741f2e08c27a104048826a2f04e46cc91f77e6cfdc06f0f818543c84f9e97560"
  10. * MD5: "1eb383c0cb6f534e113975efea309511"
  11. * SHA1: "cf409275f6ad0e738971445e44c765be3b5449d1"
  12. * SHA512: "6e485c4b3bd34c9f60a4174eb881874de5da5f43cefcae894cb7952f4ebcec54f7719ed5a51f487421c66e0e573b5ac52733da5cb7558f3ef0cd7339dcae2858"
  13. * CRC32: "1D223699"
  14. * SSDEEP: "49152:iaiOFjnvV6ISfYo+U6/Xw9zBUS1ijMpydJvAgwtDfnEId:WaJhSSUr8jlJ4gwlfnEe"
  15.  
  16. * Process Execution:
  17. "Exes_1eb383c0cb6f534e113975efea309511.exe",
  18. "notepad.exe",
  19. "cmd.exe",
  20. "wscript.exe",
  21. "notepad.exe"
  22.  
  23.  
  24. * Executed Commands:
  25. "\"C:\\Windows\\notepad.exe\" -c \"C:\\ProgramData\\FtqBnjJnmF\\cfgi\"",
  26. "cmd.exe /C WScript \"C:\\ProgramData\\FtqBnjJnmF\\r.vbs\"",
  27. "\"C:\\Windows\\notepad.exe\" -c \"C:\\ProgramData\\FtqBnjJnmF\\cfg\"",
  28. "C:\\Windows\\system32\\wscript.exe WScript \"C:\\ProgramData\\FtqBnjJnmF\\r.vbs\""
  29.  
  30.  
  31. * Signatures Detected:
  32.  
  33. "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
  34. "Details":
  35.  
  36. "IP": "193.32.161.69:5555"
  37.  
  38.  
  39.  
  40.  
  41. "Description": "Creates RWX memory",
  42. "Details":
  43.  
  44.  
  45. "Description": "Detected script timer window indicative of sleep style evasion",
  46. "Details":
  47.  
  48. "Window": "WSH-Timer"
  49.  
  50.  
  51.  
  52.  
  53. "Description": "A process attempted to delay the analysis task.",
  54. "Details":
  55.  
  56. "Process": "Exes_1eb383c0cb6f534e113975efea309511.exe tried to sleep 299 seconds, actually delayed analysis time by 0 seconds"
  57.  
  58.  
  59.  
  60.  
  61. "Description": "At least one IP Address, Domain, or File Name was found in a crypto call",
  62. "Details":
  63.  
  64. "ioc": "2.86"
  65.  
  66.  
  67. "ioc": "0.34"
  68.  
  69.  
  70. "ioc": "7.9."
  71.  
  72.  
  73. "ioc": "..17"
  74.  
  75.  
  76. "ioc": "..70"
  77.  
  78.  
  79. "ioc": "4.32."
  80.  
  81.  
  82. "ioc": "9.86"
  83.  
  84.  
  85. "ioc": "3.21"
  86.  
  87.  
  88. "ioc": "78.11"
  89.  
  90.  
  91. "ioc": "0..35"
  92.  
  93.  
  94. "ioc": "-.8677"
  95.  
  96.  
  97. "ioc": "1.47"
  98.  
  99.  
  100. "ioc": "80.25."
  101.  
  102.  
  103. "ioc": "2.130"
  104.  
  105.  
  106. "ioc": "4.89"
  107.  
  108.  
  109. "ioc": "-.01."
  110.  
  111.  
  112. "ioc": "8..879"
  113.  
  114.  
  115. "ioc": "..31"
  116.  
  117.  
  118. "ioc": "6.948"
  119.  
  120.  
  121. "ioc": "..47-"
  122.  
  123.  
  124. "ioc": "1.519"
  125.  
  126.  
  127. "ioc": "1.51"
  128.  
  129.  
  130. "ioc": "58.43"
  131.  
  132.  
  133. "ioc": "4.05"
  134.  
  135.  
  136. "ioc": "7.51"
  137.  
  138.  
  139. "ioc": "4.86"
  140.  
  141.  
  142. "ioc": "6..1"
  143.  
  144.  
  145. "ioc": "7.36"
  146.  
  147.  
  148. "ioc": "7.58"
  149.  
  150.  
  151. "ioc": "6.78"
  152.  
  153.  
  154. "ioc": "2.097"
  155.  
  156.  
  157. "ioc": "1.64"
  158.  
  159.  
  160. "ioc": "03.58"
  161.  
  162.  
  163. "ioc": "6.97"
  164.  
  165.  
  166. "ioc": "74.52"
  167.  
  168.  
  169. "ioc": "0.773"
  170.  
  171.  
  172. "ioc": "9.07"
  173.  
  174.  
  175. "ioc": "05.27"
  176.  
  177.  
  178. "ioc": "9.45"
  179.  
  180.  
  181. "ioc": "1.07"
  182.  
  183.  
  184. "ioc": "85.83"
  185.  
  186.  
  187. "ioc": "1.0799"
  188.  
  189.  
  190. "ioc": "7.663"
  191.  
  192.  
  193. "ioc": "-.61"
  194.  
  195.  
  196. "ioc": "2.23"
  197.  
  198.  
  199. "ioc": "0.276"
  200.  
  201.  
  202. "ioc": "8.72"
  203.  
  204.  
  205. "ioc": "4.66"
  206.  
  207.  
  208. "ioc": "44.29"
  209.  
  210.  
  211. "ioc": "4-.47"
  212.  
  213.  
  214. "ioc": "20.272"
  215.  
  216.  
  217. "ioc": "7.82"
  218.  
  219.  
  220. "ioc": "4.9."
  221.  
  222.  
  223. "ioc": "3.945"
  224.  
  225.  
  226. "ioc": "1.01"
  227.  
  228.  
  229. "ioc": "4.42"
  230.  
  231.  
  232. "ioc": "0.09"
  233.  
  234.  
  235. "ioc": "41.89/"
  236.  
  237.  
  238. "ioc": "9.96"
  239.  
  240.  
  241. "ioc": "6.15"
  242.  
  243.  
  244. "ioc": "4.08"
  245.  
  246.  
  247. "ioc": "94.93"
  248.  
  249.  
  250. "ioc": "8.82"
  251.  
  252.  
  253. "ioc": ".-.80"
  254.  
  255.  
  256. "ioc": "3.47"
  257.  
  258.  
  259. "ioc": "9..7"
  260.  
  261.  
  262. "ioc": "..87"
  263.  
  264.  
  265. "ioc": "74.85"
  266.  
  267.  
  268. "ioc": "3.35"
  269.  
  270.  
  271. "ioc": "3.05"
  272.  
  273.  
  274. "ioc": "..995"
  275.  
  276.  
  277. "ioc": "-.20"
  278.  
  279.  
  280. "ioc": "9.66"
  281.  
  282.  
  283. "ioc": "6.79"
  284.  
  285.  
  286. "ioc": "2.7.6"
  287.  
  288.  
  289. "ioc": "-.85"
  290.  
  291.  
  292. "ioc": "6.01"
  293.  
  294.  
  295. "ioc": "6.00"
  296.  
  297.  
  298. "ioc": "7.46"
  299.  
  300.  
  301. "ioc": "4-.43"
  302.  
  303.  
  304. "ioc": "1.06"
  305.  
  306.  
  307. "ioc": "vape.pdb"
  308.  
  309.  
  310. "ioc": "fidapuv.pdb"
  311.  
  312.  
  313. "ioc": "32.dll"
  314.  
  315.  
  316. "ioc": "1.2k2u2"
  317.  
  318.  
  319.  
  320.  
  321. "Description": "Repeatedly searches for a not-found process, may want to run with startbrowser=1 option",
  322. "Details":
  323.  
  324.  
  325. "Description": "Reads data out of its own binary image",
  326. "Details":
  327.  
  328. "self_read": "process: Exes_1eb383c0cb6f534e113975efea309511.exe, pid: 1448, offset: 0x00000000, length: 0x001ef000"
  329.  
  330.  
  331. "self_read": "process: wscript.exe, pid: 1880, offset: 0x00000000, length: 0x00000040"
  332.  
  333.  
  334. "self_read": "process: wscript.exe, pid: 1880, offset: 0x000000f0, length: 0x00000018"
  335.  
  336.  
  337. "self_read": "process: wscript.exe, pid: 1880, offset: 0x000001e8, length: 0x00000078"
  338.  
  339.  
  340. "self_read": "process: wscript.exe, pid: 1880, offset: 0x00018000, length: 0x00000020"
  341.  
  342.  
  343. "self_read": "process: wscript.exe, pid: 1880, offset: 0x00018058, length: 0x00000018"
  344.  
  345.  
  346. "self_read": "process: wscript.exe, pid: 1880, offset: 0x000181a8, length: 0x00000018"
  347.  
  348.  
  349. "self_read": "process: wscript.exe, pid: 1880, offset: 0x00018470, length: 0x00000010"
  350.  
  351.  
  352. "self_read": "process: wscript.exe, pid: 1880, offset: 0x00018640, length: 0x00000012"
  353.  
  354.  
  355.  
  356.  
  357. "Description": "A process created a hidden window",
  358. "Details":
  359.  
  360. "Process": "Exes_1eb383c0cb6f534e113975efea309511.exe -> cmd.exe /C WScript \"C:\\ProgramData\\FtqBnjJnmF\\r.vbs\""
  361.  
  362.  
  363.  
  364.  
  365. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  366. "Details":
  367.  
  368. "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
  369.  
  370.  
  371. "suspicious_request": "http://193.32.161.69/upd.txt"
  372.  
  373.  
  374.  
  375.  
  376. "Description": "Performs some HTTP requests",
  377. "Details":
  378.  
  379. "url": "http://193.32.161.69/upd.txt"
  380.  
  381.  
  382.  
  383.  
  384. "Description": "Installs itself for autorun at Windows startup",
  385. "Details":
  386.  
  387. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\ftUPeSPdpA.url"
  388.  
  389.  
  390. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\ftUPeSPdpA.url"
  391.  
  392.  
  393.  
  394.  
  395.  
  396. * Started Service:
  397.  
  398. * Mutexes:
  399. "718925f232b7f837a482"
  400.  
  401.  
  402. * Modified Files:
  403. "C:\\ProgramData\\FtqBnjJnmF\\windrv32.exe",
  404. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\ftUPeSPdpA.url"
  405.  
  406.  
  407. * Deleted Files:
  408. "C:\\ProgramData\\FtqBnjJnmF\\r.vbs",
  409. "C:\\ProgramData\\FtqBnjJnmF\\windrv32.exe",
  410. "C:\\ProgramData\\FtqBnjJnmF\\windrv32"
  411.  
  412.  
  413. * Modified Registry Keys:
  414.  
  415. * Deleted Registry Keys:
  416.  
  417. * DNS Communications:
  418.  
  419. * Domains:
  420.  
  421. * Network Communication - ICMP:
  422.  
  423. * Network Communication - HTTP:
  424.  
  425. "count": 2,
  426. "body": "",
  427. "uri": "http://193.32.161.69/upd.txt",
  428. "user-agent": "WinInetGet/0.1",
  429. "method": "GET",
  430. "host": "193.32.161.69",
  431. "version": "1.1",
  432. "path": "/upd.txt",
  433. "data": "GET /upd.txt HTTP/1.1\r\nAccept: text/*, application/exe, application/zlib, application/gzip, application/applefile\r\nUser-Agent: WinInetGet/0.1\r\nHost: 193.32.161.69\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  434. "port": 80
  435.  
  436.  
  437.  
  438. * Network Communication - SMTP:
  439.  
  440. * Network Communication - Hosts:
  441.  
  442. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment