Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: ""
- * MalScore: 10.0
- * File Name: "Exes_c8fbef0374e176b0d36164b69c9486d9.exe"
- * File Size: 383664
- * File Type: "MS-DOS executable"
- * SHA256: "83d6854f929eb378eab1f881f771b580ba00162a6e3b03b99f77f9361bbeeb57"
- * MD5: "c8fbef0374e176b0d36164b69c9486d9"
- * SHA1: "7af6f3306f4a89936852a1ae7aa4501bc50ef59b"
- * SHA512: "53e08d9feb2d46aedc37500a696de1d98a2ac7351365d9c4cf0335c821ecf644b8531cf40da38c428cefd4094980996418b7a7600d0947d8b92eb6a116391618"
- * CRC32: "68932B43"
- * SSDEEP: "6144:IvZzQJVb5p72cHF1ybDFwekh212KhvwIb759QOaBjpaVRPu23E2rJmWjFS:IYVOiF1WD7kE1dTYOi8V5u23zmWFS"
- * Process Execution:
- "Exes_c8fbef0374e176b0d36164b69c9486d9.exe",
- "SQLServse.exe",
- "services.exe",
- "SQLServse.exe",
- "SQLServse.exe",
- "svchost.exe",
- "WerFault.exe",
- "wermgr.exe"
- * Executed Commands:
- "C:\\Program Files (x86)\\Microsoft SQL Server\\SQLServse.exe ",
- "C:\\Program Files (x86)\\Microsoft SQL Server\\SQLServse.exe",
- "C:\\Windows\\System32\\svchost.exe -k WerSvcGroup",
- "C:\\Windows\\SysWOW64\\WerFault.exe -u -p 2384 -s 392",
- "\"C:\\Windows\\system32\\wermgr.exe\" \"-queuereporting_svc\" \"C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_SQLServse.exe_90787af212b8bb9775629dd7ac9cd8723398f5f7_cab_09c005a7\""
- * Signatures Detected:
- "Description": "At least one process apparently crashed during execution",
- "Details":
- "Description": "Creates RWX memory",
- "Details":
- "Description": "A process attempted to delay the analysis task.",
- "Details":
- "Process": "SQLServse.exe tried to sleep 515 seconds, actually delayed analysis time by 0 seconds"
- "Description": "Drops a binary and executes it",
- "Details":
- "binary": "C:\\Program Files (x86)\\Microsoft SQL Server\\SQLServse.exe"
- "Description": "Unconventionial language used in binary resources: Chinese (Simplified)",
- "Details":
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details":
- "section": "name: .MPRESS1, entropy: 8.00, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00056800, virtual_size: 0x00061000"
- "Description": "Deletes its original binary from disk",
- "Details":
- "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
- "Details":
- "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 16298316 times"
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "service name": "Microsoft SQL Server"
- "service path": "C:\\Program Files (x86)\\Microsoft SQL Server\\SQLServse.exe"
- "Description": "Checks the CPU name from registry, possibly for anti-virtualization",
- "Details":
- "Description": "Checks the system manufacturer, likely for anti-virtualization",
- "Details":
- * Started Service:
- "Microsoft SQL Server",
- "WerSvc"
- * Mutexes:
- "Local\\WERReportingForProcess2384",
- "Global\\5ad61e39-b695-11e9-9533-18c086cd4731",
- "Global\\\\xed\\xbc\\xa0\\xc7\\x9b",
- "WERUI_APPCRASH-90787af212b8bb9775629dd7ac9cd8723398f5f7"
- * Modified Files:
- "C:\\Program Files (x86)\\Microsoft SQL Server\\SQLServse.exe",
- "C:\\Windows\\Temp\\WER810C.tmp.appcompat.txt",
- "C:\\Windows\\Temp\\WER814C.tmp.WERInternalMetadata.xml",
- "C:\\Windows\\Temp\\WER816C.tmp.hdmp",
- "C:\\Windows\\Temp\\WER84F7.tmp.mdmp",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_SQLServse.exe_90787af212b8bb9775629dd7ac9cd8723398f5f7_cab_09c005a7\\WER810C.tmp.appcompat.txt",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_SQLServse.exe_90787af212b8bb9775629dd7ac9cd8723398f5f7_cab_09c005a7\\WER814C.tmp.WERInternalMetadata.xml",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_SQLServse.exe_90787af212b8bb9775629dd7ac9cd8723398f5f7_cab_09c005a7\\WER816C.tmp.hdmp",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_SQLServse.exe_90787af212b8bb9775629dd7ac9cd8723398f5f7_cab_09c005a7\\WER84F7.tmp.mdmp",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_SQLServse.exe_90787af212b8bb9775629dd7ac9cd8723398f5f7_cab_09c005a7\\Report.wer",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_SQLServse.exe_90787af212b8bb9775629dd7ac9cd8723398f5f7_cab_09c005a7\\Report.wer.tmp"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_c8fbef0374e176b0d36164b69c9486d9.exe",
- "C:\\Windows\\Temp\\WER810C.tmp",
- "C:\\Windows\\Temp\\WER810C.tmp.appcompat.txt",
- "C:\\Windows\\Temp\\WER814C.tmp",
- "C:\\Windows\\Temp\\WER814C.tmp.WERInternalMetadata.xml",
- "C:\\Windows\\Temp\\WER816C.tmp",
- "C:\\Windows\\Temp\\WER816C.tmp.hdmp",
- "C:\\Windows\\Temp\\WER84F7.tmp",
- "C:\\Windows\\Temp\\WER84F7.tmp.mdmp",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_SQLServse.exe_90787af212b8bb9775629dd7ac9cd8723398f5f7_cab_09c005a7\\Report.wer.tmp"
- * Modified Registry Keys:
- "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\Microsoft SQL Server",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Microsoft SQL Server\\DeleteFiles",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Microsoft SQL Server\\ConnectGroup",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Microsoft SQL Server\\Description",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Microsoft SQL Server\\MarkTime",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MediaResources\\msvideo",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Debug",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\Windows Error Reporting\\Debug\\ExceptionRecord"
- * Deleted Registry Keys:
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Microsoft SQL Server\\DeleteFiles"
- * DNS Communications:
- "type": "A",
- "request": "da.vollar.ga",
- "answers":
- "data": "172.245.82.4",
- "type": "A"
- * Domains:
- "ip": "172.245.82.4",
- "domain": "da.vollar.ga"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment