Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * ID: 3982
- * MalFamily: ""
- * MalScore: 7.0
- * File Name: "Trickbot_3073e065a22c30330042f66e04df7e64.1"
- * File Size: 447021
- * File Type: "Java archive data (JAR)"
- * SHA256: "69f3f647fbeb6fdd5dc8d97359a1959aac2e70c7820baf01bde98907414d2898"
- * MD5: "3073e065a22c30330042f66e04df7e64"
- * SHA1: "ca140e83693c9abf77e201887245b44383ce8734"
- * SHA512: "0b081984beae552445af34d822120333ce5b1cb0a2fea5476ae3e2cd6488023bb88cac672de10a051355497fa67df35614145bd976153bac8736c4f699eab587"
- * CRC32: "EB13B0D7"
- * SSDEEP: "6144:BbwPTGBayFJc2/ts0FnnQViVAOFgWq/bh3hTCRKyku5WwJWDVihXq+/4jTuyu+ZN:ZATGgyF2xDzdM8BEWwJAVi8KYuyu+Z6A"
- * Process Execution:
- "java.exe"
- * Executed Commands:
- * Signatures Detected:
- "Description": "Guard pages use detected - possible anti-debugging.",
- "Details":
- "Description": "Stack pivoting was detected when using a critical API",
- "Details":
- "process": "java.exe:2200"
- * Started Service:
- * Mutexes:
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\hsperfdata_user\\2200"
- * Deleted Files:
- * Modified Registry Keys:
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment