Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Keylogger"
- * MalScore: 10.0
- * File Name: "Exes_b7690d9bd8f698e016eb9ec7fb259a25.exe"
- * File Size: 40960
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "8d3c6da9232dab889fb4432c2cecef0dfc22a908563afd23a115c82c02023b60"
- * MD5: "b7690d9bd8f698e016eb9ec7fb259a25"
- * SHA1: "2a528b4c614755739a33feefc70defbdf3ea06bd"
- * SHA512: "2bc2324673e1bdc33e7e934fd59c81c18f4b97a3d3255951e9021e9786c491bb1c1fb4a1c16cf377e59f8cca7000703c55d389ee8b07f7120234f8a0700cc224"
- * CRC32: "EC564223"
- * SSDEEP: "384:zvIVKG11Jga1L2uvU7pZCcRF1RSRWJtZHWtnxQoeWRcnsRD4qgusMoAD30yM:Ud1VxU7p8cPDZ2dqozR6VCXbM"
- * Process Execution:
- "Exes_b7690d9bd8f698e016eb9ec7fb259a25.exe"
- * Executed Commands:
- * Signatures Detected:
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: Exes_b7690d9bd8f698e016eb9ec7fb259a25.exe, pid: 2176, offset: 0x00000000, length: 0x0000a000"
- "Description": "Sniffs keystrokes",
- "Details":
- "GetAsyncKeyState": "Process: Exes_b7690d9bd8f698e016eb9ec7fb259a25.exe(2176)"
- "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
- "Details":
- "Spam": "Exes_b7690d9bd8f698e016eb9ec7fb259a25.exe (2176) called API GetSystemTimeAsFileTime 4679832 times"
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\Version Information"
- "data": "C:\\Windows\\system\\ist2.exe"
- "Description": "File has been identified by 51 Antiviruses on VirusTotal as malicious",
- "Details":
- "MicroWorld-eScan": "Trojan.GenericKD.40338507"
- "FireEye": "Trojan.GenericKD.40338507"
- "CAT-QuickHeal": "Trojan.VBCryptVMF.S2954444"
- "ALYac": "Trojan.Keylogger.Keylogger.a"
- "Malwarebytes": "Spyware.KeyLogger"
- "Zillya": "Trojan.Keylogger.Win32.723"
- "AegisLab": "Trojan.Win32.KeyLogger.l!c"
- "TheHacker": "Trojan/Keylogsklog"
- "Alibaba": "TrojanSpy:Win32/KeyLogger.41cf62de"
- "TrendMicro": "TSPY_SPY.A"
- "Cyren": "W32/Risk.LLVR-1391"
- "Symantec": "Trojan Horse"
- "TrendMicro-HouseCall": "TSPY_SPY.A"
- "Paloalto": "generic.ml"
- "ClamAV": "Win.Trojan.Keylogger-6"
- "BitDefender": "Trojan.GenericKD.40338507"
- "NANO-Antivirus": "Trojan.Win32.KeyLogger.diqy"
- "Avast": "Win32:Trojan-gen"
- "Tencent": "Win32.Trojan-spy.Keylogger.Pfjd"
- "Ad-Aware": "Trojan.GenericKD.40338507"
- "Sophos": "Troj/Ist-A"
- "Comodo": "TrojWare.Win32.Spy.KeyLogger@2n03"
- "F-Secure": "Worm.WORM/Klow"
- "DrWeb": "Trojan.KeyLogger.80"
- "McAfee-GW-Edition": "Keylog-Sklog"
- "CMC": "Generic.Win32.b7690d9bd8!MD"
- "Emsisoft": "Trojan.GenericKD.40338507 (B)"
- "SentinelOne": "DFI - Suspicious PE"
- "F-Prot": "W32/Malware!3eb3"
- "Jiangmin": "TrojanSpy.KeyLogger.a"
- "Avira": "WORM/Klow"
- "Antiy-AVL": "TrojanSpy/Win32.KeyLogger"
- "Microsoft": "TrojanSpy:Win32/Keylogger"
- "Endgame": "malicious (high confidence)"
- "Arcabit": "Trojan.Generic.D267844B"
- "GData": "Trojan.GenericKD.40338507"
- "AhnLab-V3": "Spyware/Win32.VB.C19068"
- "McAfee": "Keylog-Sklog"
- "MAX": "malware (ai score=100)"
- "VBA32": "TrojanSpy.KeyLogger"
- "Cylance": "Unsafe"
- "ESET-NOD32": "Win32/Spy.KeyLogger"
- "Rising": "Trojan.Spy.KeyLogger.a (CLOUD)"
- "Yandex": "TrojanSpy.KeyLogger!73ZT5RFpqBg"
- "Ikarus": "Trojan-Spy.Agent"
- "Fortinet": "W32/Ist.A!tr"
- "Webroot": "System.Monitor.Keylogger.Gen"
- "AVG": "Win32:Trojan-gen"
- "Cybereason": "malicious.bd8f69"
- "Panda": "Trojan Horse"
- "Qihoo-360": "Malware.Radar01.Gen"
- "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
- "Details":
- "target": "clamav:Win.Trojan.Keylogger-6, sha256:8d3c6da9232dab889fb4432c2cecef0dfc22a908563afd23a115c82c02023b60, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Keylogger-6, sha256:8d3c6da9232dab889fb4432c2cecef0dfc22a908563afd23a115c82c02023b60 , guest_paths:C:\\Windows\\system\\ist2.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "Description": "Creates a copy of itself",
- "Details":
- "copy": "C:\\Windows\\system\\ist2.exe"
- * Started Service:
- * Mutexes:
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF6212F45A5E2FFC61.TMP",
- "C:\\Windows\\system\\windowskj.log",
- "C:\\Windows\\system\\ist2.exe"
- * Deleted Files:
- * Modified Registry Keys:
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\Version Information"
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Add Comment
Please, Sign In to add comment