Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Presenoker"
- * MalScore: 10.0
- * File Name: "video-Neymar-y-Narjila.vbs"
- * File Size: 165119
- * File Type: "UTF-8 Unicode text, with CRLF line terminators"
- * SHA256: "b543226d719a70704008fc2c582904b5659ec1fe75ef70159355c1a97ca5d3bc"
- * MD5: "814967a5d358316e8e2d4952b90ad9e8"
- * SHA1: "c191d5259dcd808a3c5fae34adcf61ceaf78d6c5"
- * SHA512: "da49eb0cc04ded8abfebb2c3315de1fcb32b50ed4ee9f069f52d3e41c57b3ace0cb91d94a56afd61b8848d2127ad64d8a9009a9a68998262500b4030683629a8"
- * CRC32: "69C07706"
- * SSDEEP: "3072:K1ynTL8TlzEHbTlzEHeVbuV84rLxMrIV9xM3uOz4jr9c4GqlVb:GTOHbTOHeVbuV84r2rCr9c4GqlVb"
- * Process Execution:
- "wscript.exe",
- "wscript.exe",
- "svchost.exe",
- "WmiPrvSE.exe",
- "svchost.exe"
- * Executed Commands:
- "wscript.exe C:\\Users\\user\\AppData\\Roaming\\scgdyvegcaq.vbs",
- "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding"
- * Signatures Detected:
- "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
- "Details":
- "IP": "18.188.78.96:80"
- "Description": "Detected script timer window indicative of sleep style evasion",
- "Details":
- "Window": "WSH-Timer"
- "Description": "A process attempted to delay the analysis task.",
- "Details":
- "Process": "wscript.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: wscript.exe, pid: 2144, offset: 0x00000000, length: 0x00000040"
- "self_read": "process: wscript.exe, pid: 2144, offset: 0x000000f0, length: 0x00000018"
- "self_read": "process: wscript.exe, pid: 2144, offset: 0x000001e8, length: 0x00000078"
- "self_read": "process: wscript.exe, pid: 2144, offset: 0x00018000, length: 0x00000020"
- "self_read": "process: wscript.exe, pid: 2144, offset: 0x00018058, length: 0x00000018"
- "self_read": "process: wscript.exe, pid: 2144, offset: 0x000181a8, length: 0x00000018"
- "self_read": "process: wscript.exe, pid: 2144, offset: 0x00018470, length: 0x00000010"
- "self_read": "process: wscript.exe, pid: 2144, offset: 0x00018640, length: 0x00000012"
- "Description": "File has been identified by 6 Antiviruses on VirusTotal as malicious",
- "Details":
- "Kaspersky": "HEUR:Trojan-Downloader.Script.Generic"
- "NANO-Antivirus": "Trojan.Script.MLW.ebogyu"
- "DrWeb": "Trojan.DownLoader28.41788"
- "Microsoft": "PUA:Win32/Presenoker"
- "ZoneAlarm": "HEUR:Trojan-Downloader.Script.Generic"
- "Qihoo-360": "virus.vbs.dropper.d"
- "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
- "Details":
- "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
- "suspicious_request": "http://18.188.78.96/THEY/logs.zip"
- "suspicious_request": "http://18.188.78.96/THEY/they7.jpg"
- "suspicious_request": "http://www.msftncsi.com/ncsi.txt"
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://18.188.78.96/THEY/logs.zip"
- "url": "http://18.188.78.96/THEY/they7.jpg"
- "url": "http://www.msftncsi.com/ncsi.txt"
- "Description": "Attempts to restart the guest VM",
- "Details":
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\scgdyvegcaq.lnk"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\scgdyvegcaq.lnk"
- "Description": "A wscript.exe process commonly used in script or document file downloaders initiated network activity",
- "Details":
- "http_request": "wscript.exe_InternetCrackUrlW_http://18.188.78.96/they/logs.zip"
- "http_request_path": "wscript.exe_HttpOpenRequestW_/they/logs.zip"
- "http_request": "wscript.exe_InternetCrackUrlA_http://18.188.78.96"
- "http_request": "wscript.exe_InternetCrackUrlA_http://18.188.78.96/they/logs.zip"
- "http_request": "wscript.exe_InternetCrackUrlW_http://18.188.78.96/they/they7.jpg"
- "http_request_path": "wscript.exe_HttpOpenRequestW_/they/they7.jpg"
- "http_request": "wscript.exe_InternetCrackUrlA_http://18.188.78.96"
- "http_request": "wscript.exe_InternetCrackUrlA_http://18.188.78.96/they/they7.jpg"
- "Description": "Retrieves Windows ProductID, probably to fingerprint the sandbox",
- "Details":
- "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
- "Details":
- "dropped": "clamav:Win.Packed.Vmprotect-6762068-1, sha256:b9ec0ffa3d7178a8ef4e3643dda83d98ed55e8f3774bff9cb1a43f379239123f , guest_paths:C:\\Users\\user\\AppData\\Roaming\\54251088082789\\cksojypafcdkifpsf12418081164359.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "Description": "Collects information to fingerprint the system",
- "Details":
- "Description": "Created network traffic indicative of malicious activity",
- "Details":
- "signature": "ET TROJAN Windows Executable Downloaded With Image Content-Type Header"
- * Started Service:
- * Mutexes:
- "Local\\ZonesCounterMutex",
- "Local\\ZoneAttributeCacheCounterMutex",
- "Local\\ZonesCacheCounterMutex",
- "Local\\ZonesLockedCacheCounterMutex"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\logs1.zip",
- "C:\\Users\\user\\AppData\\Roaming\\54251088082789\\logs.zip",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\they71.jpg",
- "C:\\Users\\user\\AppData\\Roaming\\54251088082789\\cksojypafcdkifpsf12418081164359.exe",
- "C:\\Users\\user\\AppData\\Roaming\\scgdyvegcaq.vbs",
- "\\??\\PIPE\\samr",
- "C:\\Windows\\sysnative\\wbem\\repository\\WRITABLE.TST",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING1.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING2.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING3.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\OBJECTS.DATA",
- "C:\\Windows\\sysnative\\wbem\\repository\\INDEX.BTR",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
- "\\??\\PIPE\\wkssvc",
- "\\??\\PIPE\\srvsvc",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\scgdyvegcaq.lnk"
- * Deleted Files:
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Wbem\\Transports\\Decoupled\\Server",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\CreationTime",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\MarshaledProxy",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\ProcessIdentifier",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ConfigValueEssNeedsLoading",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\List of event-active namespaces",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\ESS\\//./root/CIMV2\\SCM Event Provider"
- * Deleted Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName"
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 1,
- "body": "",
- "uri": "http://18.188.78.96/THEY/logs.zip",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "18.188.78.96",
- "version": "1.1",
- "path": "/THEY/logs.zip",
- "data": "GET /THEY/logs.zip HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: 18.188.78.96\r\nConnection: Keep-Alive\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://18.188.78.96/THEY/they7.jpg",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "18.188.78.96",
- "version": "1.1",
- "path": "/THEY/they7.jpg",
- "data": "GET /THEY/they7.jpg HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: 18.188.78.96\r\nConnection: Keep-Alive\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://www.msftncsi.com/ncsi.txt",
- "user-agent": "Microsoft NCSI",
- "method": "GET",
- "host": "www.msftncsi.com",
- "version": "1.1",
- "path": "/ncsi.txt",
- "data": "GET /ncsi.txt HTTP/1.1\r\nConnection: Close\r\nUser-Agent: Microsoft NCSI\r\nHost: www.msftncsi.com\r\n\r\n",
- "port": 80
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment