paladin316

3982Trickbot_3073e065a22c30330042f66e04df7e64_1_2019-10-03_21_30.txt

Oct 4th, 2019
2,328
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.37 KB | None | 0 0
  1.  
  2. * ID: 3982
  3. * MalFamily: ""
  4.  
  5. * MalScore: 7.0
  6.  
  7. * File Name: "Trickbot_3073e065a22c30330042f66e04df7e64.1"
  8. * File Size: 447021
  9. * File Type: "Java archive data (JAR)"
  10. * SHA256: "69f3f647fbeb6fdd5dc8d97359a1959aac2e70c7820baf01bde98907414d2898"
  11. * MD5: "3073e065a22c30330042f66e04df7e64"
  12. * SHA1: "ca140e83693c9abf77e201887245b44383ce8734"
  13. * SHA512: "0b081984beae552445af34d822120333ce5b1cb0a2fea5476ae3e2cd6488023bb88cac672de10a051355497fa67df35614145bd976153bac8736c4f699eab587"
  14. * CRC32: "EB13B0D7"
  15. * SSDEEP: "6144:BbwPTGBayFJc2/ts0FnnQViVAOFgWq/bh3hTCRKyku5WwJWDVihXq+/4jTuyu+ZN:ZATGgyF2xDzdM8BEWwJAVi8KYuyu+Z6A"
  16.  
  17. * Process Execution:
  18. "java.exe"
  19.  
  20.  
  21. * Executed Commands:
  22.  
  23. * Signatures Detected:
  24.  
  25. "Description": "Guard pages use detected - possible anti-debugging.",
  26. "Details":
  27.  
  28.  
  29. "Description": "Stack pivoting was detected when using a critical API",
  30. "Details":
  31.  
  32. "process": "java.exe:2200"
  33.  
  34.  
  35.  
  36.  
  37.  
  38. * Started Service:
  39.  
  40. * Mutexes:
  41.  
  42. * Modified Files:
  43. "C:\\Users\\user\\AppData\\Local\\Temp\\hsperfdata_user\\2200"
  44.  
  45.  
  46. * Deleted Files:
  47.  
  48. * Modified Registry Keys:
  49.  
  50. * Deleted Registry Keys:
  51.  
  52. * DNS Communications:
  53.  
  54. * Domains:
  55.  
  56. * Network Communication - ICMP:
  57.  
  58. * Network Communication - HTTP:
  59.  
  60. * Network Communication - SMTP:
  61.  
  62. * Network Communication - Hosts:
  63.  
  64. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment