Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: ""
- * MalScore: 10.0
- * File Name: "Exes_183b9b7c52975a33a2d68102042041f7.exe"
- * File Size: 165888
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "da19934722883840cc5189fed392b233e1afd169b0d5ca7205415f47269d5199"
- * MD5: "183b9b7c52975a33a2d68102042041f7"
- * SHA1: "02fc2346a135bc6dfcebdbf37eab08a8af95da73"
- * SHA512: "336fe8262646eeb653240c6a74145abb662b08c7f6a541aa609fafb2618a622c2722df944fb59c9632b133dd6420ef1ec7fe1e64dd69788ca498c8b4b6c4d296"
- * CRC32: "00F68B35"
- * SSDEEP: "1536:dyhXqb4KDRIYez05T7S90pVXsu0hZnTTQUIDbbq/U5sSo7+iicn3/cJsWjcdfv0+:dWXgRSr3QUIDvq/X+i3NbNRSducCImt"
- * Process Execution:
- "Exes_183b9b7c52975a33a2d68102042041f7.exe",
- "svchost.exe",
- "WmiPrvSE.exe"
- * Executed Commands:
- "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding"
- * Signatures Detected:
- "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
- "Details":
- "IP": "125.77.29.88:8889"
- "Description": "A process attempted to delay the analysis task.",
- "Details":
- "Process": "WmiPrvSE.exe tried to sleep 301 seconds, actually delayed analysis time by 0 seconds"
- "Description": "The sample enumerated directory objects, possibly probing for Virtual Machine objects.",
- "Details":
- "Object": "C:\\global??"
- "Description": "Repeatedly searches for a not-found process, may want to run with startbrowser=1 option",
- "Details":
- "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
- "Details":
- "post_no_referer": "HTTP traffic contains a POST request with no referer header"
- "post_no_useragent": "HTTP traffic contains a POST request with no user-agent header"
- "suspicious_request": "http://white1.gogo23424.com:8889/stat4.ashx"
- "suspicious_request": "http://imgsrc.baidu.com/tieba/pic/item/29381f30e924b8994f5364c560061d950b7bf6e4.jpg"
- "suspicious_request": "http://imgsrc.baidu.com/tieba/pic/item/f31fbe096b63f6247a3324fe8944ebf81b4ca3e4.jpg"
- "suspicious_request": "http://white1.gogo23424.com:8889/stat1.ashx"
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://white1.gogo23424.com:8889/stat4.ashx"
- "url": "http://imgsrc.baidu.com/tieba/pic/item/29381f30e924b8994f5364c560061d950b7bf6e4.jpg"
- "url": "http://imgsrc.baidu.com/tieba/pic/item/f31fbe096b63f6247a3324fe8944ebf81b4ca3e4.jpg"
- "url": "http://white1.gogo23424.com:8889/stat1.ashx"
- "Description": "Queries information on disks for anti-virtualization via Device Information APIs",
- "Details":
- "Description": "Enumerates services, possibly for anti-virtualization",
- "Details":
- "Description": "Network activity contains more than one unique useragent.",
- "Details":
- "Process": "Exes_183b9b7c52975a33a2d68102042041f7.exe"
- "User-Agent": "Mozilla/4.0"
- "Process": "Exes_183b9b7c52975a33a2d68102042041f7.exe"
- "User-Agent": "Http"
- "Description": "File has been identified by 51 Antiviruses on VirusTotal as malicious",
- "Details":
- "MicroWorld-eScan": "Gen:Variant.Ursu.512381"
- "FireEye": "Generic.mg.183b9b7c52975a33"
- "CAT-QuickHeal": "Trojan.Multi"
- "ALYac": "Gen:Variant.Ursu.512381"
- "K7AntiVirus": "Trojan ( 005507fc1 )"
- "Alibaba": "TrojanDownloader:Win32/Agent.ebd9fa2d"
- "K7GW": "Trojan ( 005507fc1 )"
- "Cybereason": "malicious.c52975"
- "Arcabit": "Trojan.Ursu.D7D17D"
- "TrendMicro": "TROJ_GEN.R002C0WG419"
- "Symantec": "Trojan.Gen.MBT"
- "APEX": "Malicious"
- "Avast": "Win32:Trojan-gen"
- "Kaspersky": "Trojan-Downloader.Win32.Agent.xxywqf"
- "BitDefender": "Gen:Variant.Ursu.512381"
- "NANO-Antivirus": "Trojan.Win32.RP.fryull"
- "AegisLab": "Trojan.Multi.Generic.4!c"
- "Tencent": "Win32.Trojan.Dropper.Dxdj"
- "Ad-Aware": "Gen:Variant.Ursu.512381"
- "Emsisoft": "Gen:Variant.Ursu.512381 (B)"
- "F-Secure": "Trojan.TR/Dropper.Gen"
- "DrWeb": "Trojan.DownLoader29.3712"
- "Invincea": "heuristic"
- "McAfee-GW-Edition": "BehavesLike.Win32.Generic.ch"
- "Trapmine": "malicious.high.ml.score"
- "Sophos": "Mal/Generic-S"
- "SentinelOne": "DFI - Malicious PE"
- "Cyren": "W32/Trojan.HYLD-3328"
- "Jiangmin": "TrojanDownloader.Agent.ftjx"
- "Avira": "TR/Dropper.Gen"
- "Antiy-AVL": "TrojanDownloader/Win32.Agent"
- "Microsoft": "Trojan:Win32/Wacatac.B!ml"
- "Endgame": "malicious (high confidence)"
- "ZoneAlarm": "Trojan-Downloader.Win32.Agent.xxywqf"
- "GData": "Gen:Variant.Ursu.512381"
- "AhnLab-V3": "Malware/Win32.Generic.C3297568"
- "Acronis": "suspicious"
- "McAfee": "RDN/Generic.grp"
- "MAX": "malware (ai score=96)"
- "VBA32": "suspected of Trojan.Downloader.gen.h"
- "Cylance": "Unsafe"
- "ESET-NOD32": "a variant of Win32/Agent.AATW"
- "TrendMicro-HouseCall": "TROJ_GEN.R002C0WG419"
- "Rising": "Dropper.Generic!8.35E (CLOUD)"
- "Yandex": "Trojan.Agent!liwmwL/4Eno"
- "Ikarus": "Trojan.Win32.Agent"
- "Fortinet": "W32/Generic.AP.1F118E!tr"
- "AVG": "Win32:Trojan-gen"
- "Panda": "Trj/GdSda.A"
- "CrowdStrike": "win/malicious_confidence_100% (D)"
- "Qihoo-360": "Win32/Trojan.Downloader.daa"
- "Description": "Checks the CPU name from registry, possibly for anti-virtualization",
- "Details":
- "Description": "Detects VMware through the presence of a registry key",
- "Details":
- * Started Service:
- * Mutexes:
- * Modified Files:
- "\\??\\TeSafe",
- "\\??\\SDriver",
- "\\??\\GxWfpFlt",
- "\\??\\PowerChange",
- "\\??\\xspeed",
- "\\??\\BCE1DC4FA3E8329BC825D7B11C97D8F0",
- "\\??\\E3C8426B077F410E12D57E71801AE386",
- "\\??\\E99A4D1FF91FE270E107FF3964A05D79",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
- "\\??\\WMIDataDevice"
- * Deleted Files:
- * Modified Registry Keys:
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\PCID",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\PCID\\id"
- * Deleted Registry Keys:
- * DNS Communications:
- "type": "A",
- "request": "white1.gogo23424.com",
- "answers":
- "data": "125.77.29.88",
- "type": "A"
- "type": "A",
- "request": "imgsrc.baidu.com",
- "answers":
- "data": "hiphotos.gshifen.com",
- "type": "CNAME"
- "data": "104.193.88.109",
- "type": "A"
- "data": "hiphotos.jomodns.com",
- "type": "CNAME"
- "data": "hiphotos.baidu.com",
- "type": "CNAME"
- * Domains:
- "ip": "125.77.29.88",
- "domain": "white1.gogo23424.com"
- "ip": "104.193.88.109",
- "domain": "imgsrc.baidu.com"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 1,
- "body": "=j-\\xfe\\x07\\x19\\xaa\\x98N M\\x10\\x9e\\x0ch\\xc0\\xf6\\xc8\\xc0@\\xbd\\x96\\xbdw\\xcc\\x15\\xa9\\xf1\\xf3\\xbb\\x1d",
- "uri": "http://white1.gogo23424.com:8889/stat4.ashx",
- "user-agent": "Mozilla/4.0",
- "method": "POST",
- "host": "white1.gogo23424.com:8889",
- "version": "1.1",
- "path": "/stat4.ashx",
- "data": "POST /stat4.ashx HTTP/1.1\r\nUser-Agent: Mozilla/4.0\r\nHost: white1.gogo23424.com:8889\r\nContent-Length: 32\r\nCache-Control: no-cache\r\n\r\n=j-\\xfe\\x07\\x19\\xaa\\x98N M\\x10\\x9e\\x0ch\\xc0\\xf6\\xc8\\xc0@\\xbd\\x96\\xbdw\\xcc\\x15\\xa9\\xf1\\xf3\\xbb\\x1d",
- "port": 8889
- "count": 1,
- "body": "",
- "uri": "http://imgsrc.baidu.com/tieba/pic/item/29381f30e924b8994f5364c560061d950b7bf6e4.jpg",
- "user-agent": "Http",
- "method": "HEAD",
- "host": "imgsrc.baidu.com",
- "version": "1.1",
- "path": "/tieba/pic/item/29381f30e924b8994f5364c560061d950b7bf6e4.jpg",
- "data": "HEAD /tieba/pic/item/29381f30e924b8994f5364c560061d950b7bf6e4.jpg HTTP/1.1\r\nUser-Agent: Http\r\nHost: imgsrc.baidu.com\r\nContent-Length: 0\r\nCache-Control: no-cache\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://imgsrc.baidu.com/tieba/pic/item/29381f30e924b8994f5364c560061d950b7bf6e4.jpg",
- "user-agent": "Http",
- "method": "GET",
- "host": "imgsrc.baidu.com",
- "version": "1.1",
- "path": "/tieba/pic/item/29381f30e924b8994f5364c560061d950b7bf6e4.jpg",
- "data": "GET /tieba/pic/item/29381f30e924b8994f5364c560061d950b7bf6e4.jpg HTTP/1.1\r\nUser-Agent: Http\r\nHost: imgsrc.baidu.com\r\nCache-Control: no-cache\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://imgsrc.baidu.com/tieba/pic/item/f31fbe096b63f6247a3324fe8944ebf81b4ca3e4.jpg",
- "user-agent": "Http",
- "method": "HEAD",
- "host": "imgsrc.baidu.com",
- "version": "1.1",
- "path": "/tieba/pic/item/f31fbe096b63f6247a3324fe8944ebf81b4ca3e4.jpg",
- "data": "HEAD /tieba/pic/item/f31fbe096b63f6247a3324fe8944ebf81b4ca3e4.jpg HTTP/1.1\r\nUser-Agent: Http\r\nHost: imgsrc.baidu.com\r\nContent-Length: 0\r\nCache-Control: no-cache\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://imgsrc.baidu.com/tieba/pic/item/f31fbe096b63f6247a3324fe8944ebf81b4ca3e4.jpg",
- "user-agent": "Http",
- "method": "GET",
- "host": "imgsrc.baidu.com",
- "version": "1.1",
- "path": "/tieba/pic/item/f31fbe096b63f6247a3324fe8944ebf81b4ca3e4.jpg",
- "data": "GET /tieba/pic/item/f31fbe096b63f6247a3324fe8944ebf81b4ca3e4.jpg HTTP/1.1\r\nUser-Agent: Http\r\nHost: imgsrc.baidu.com\r\nCache-Control: no-cache\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "\\x1e5\\xfa\\x1c\\xad\\xdb>\\x03a7X\\xe8\\xa9\\x9c\\x9ab\\xdc\\xed\\xb7\\xec\\xdf\\xf4\\xb7\r\\xa6(EI\\x06_\\xc1(\\xdc\\xa5\\x87\\x94\\xc37\\xd6<\\x9bX\\xfb\\x9da \\x89f&\\xe6T\\xe1-\\xd0\\x06\\x0f<\\xb9\\xc3p\\x03\\x9d_x\\x12\\xdb\\xad\\xaa\\x02\\xbd\\x01Y\\xe9\\x7f\\x08\\x0c\\xadRqQ|6Q\\x99\\xe7\\xceI\\xf3r\\xa8\\x18D\\x05\r\\x0c\\xae\\xael\\xaf\\xf5Q\\xde\\x06\\x10\\xe6\\x1eG=FON\\xabz\\x03\\xb5\\xae\\x9a\\x98$\\xde\\xbdL~m\\xac8S\\x01\\xb0\\xd3\\xc6\\xdbMH*\\x02\\xa7\\x8ddQ\\xa1Q\\x85\\xeb_^\\xbc\\x01\\xed\\xb2h\\xe1\\xbd\\x1d\\x08tbE\\xf5U\\x86\\xbd\\xe1B&*s\\x171\\xa9\\xaf\\xd1\\x04IpZN\\xc0p!\\x06\\xda\\xa9\\x01\r\\xa7m+\\xbc@R\\xd1\\x8f\\x0c\\xd0+\\xf8\\x1d)Sz8\\x1d\\xc2\\x8b\\xa2x\\xbcyp\\x0f\\xf2w\\xbdu\\xcf4\\xd9\\xdf\\xcb)\\x19\\x88\\x86\\xe9\\xa1d\\xcb\\x12I\\xed)(\\xdc\\x94+*\\x98B@\\xda\\xe0\\xf33f\\xc5*\\xdeD\\xc6\\xd8\\x82\\xc6$\\xb2\\x19lh\\xe6F\\xb6\\xebI\\xb1\\xf7B\\xe3^\\x01\\x0e\\x120qm\\x8fT\\xd5\\x86\\xef\\x1f\t\\xe2!\\xe5\\x06\\xe4\\x8a\\x8f?\\xf4\\xe6=Bfa\\xdbG>\\xef\\xb8\\x14\\xea't\\x867\\x1f\\xd0\\x1f\\xc6\\xee\\xf7\\xe3\\x0e\\xd81~\t0\\x93s\\xdc\\xc5A\\xf6F\\xd5\\xb3Hr|\\xe8\\xfbt\\x8cLp\\xa2\\x9a\\xee\\xafA\\xa1\\xd8\\xfc\\x8f\\xdc\\xca<\\xe3#b~\\xdb7\\xe40\\xe3S\\x91\\x7fg\\x02\\xa9\\xc6\\x05\\xa4$\\xf4gc>\\xb0m&c\\xbe\\x9c@a\\xc1\\x89\\xcc\\xd3\\xe919\\xaf8\\x1ec7'\\x82\\xd9\\xf8\\x81\\x9f\\xfd\\ym\\x1c\\xe5iK\\x08\\x8ddq\\xb6Tc\\xd1\\xb4\\xf8x\\xd2\\xb3v\\xbb\\x9a\\xb7\\xa1\\xdfar\\x8f\\xcd\\xcc\\xb2\\xdbaL\\xe8b\\xb7J4\\xab\\xe8.\\x94\\x9f\\x0b/\\x01\\x1a\\xc0\\x17\\x0e\\xca\\x8dW\\xcc\\xd2\\x8f!K\\xd1&n\\xbf\\x9c?\\xe25u\\xe5\\x17\\x881\\xb9\\xeb\\xeaf\\xd9\\xb0\\x9b\\xd9\\x99\\x0e\\xd4R=\\xf0\\x9a\\x02eH\\xaa)\\x01R\\xed\\xc9\\x98\\xd5\\xfd\\x83\\xee\\xa6\\x86\\xe0\\x8d\\x01i\\xc8\\xd9\\x9b\\x1e\\xe0\\x9bQ$\\xb3\\xc2\\xd3\\xaax\\xaaz\\x9a-R\\x9d2\\xacD~+\\xe8\\xbe\\xa7\\xaf\\x04\\xfd\\xae\\x81lH2\\xdf$Be\\x03\\xee\\x8b\\xb0\\xf4\\xbb\\x84:pn\\xfa\\xea\\xf5*\\x14\\xe0\\xd7\\x01\\xf1\\xbe\"q\\xb1\\x92=8\\x80\\xd3'\\x05\\xc4\\x95\\xb1P\\xc6\\xc7\\xc7\\x14",
- "uri": "http://white1.gogo23424.com:8889/stat1.ashx",
- "user-agent": "",
- "method": "POST",
- "host": "white1.gogo23424.com:8889",
- "version": "1.1",
- "path": "/stat1.ashx",
- "data": "POST /stat1.ashx HTTP/1.1\r\nHost: white1.gogo23424.com:8889\r\nAccept: */*\r\nContent-Length: 600\r\nContent-Type: application/x-www-form-urlencoded\r\n\r\n\\x1e5\\xfa\\x1c\\xad\\xdb>\\x03a7X\\xe8\\xa9\\x9c\\x9ab\\xdc\\xed\\xb7\\xec\\xdf\\xf4\\xb7\r\\xa6(EI\\x06_\\xc1(\\xdc\\xa5\\x87\\x94\\xc37\\xd6<\\x9bX\\xfb\\x9da \\x89f&\\xe6T\\xe1-\\xd0\\x06\\x0f<\\xb9\\xc3p\\x03\\x9d_x\\x12\\xdb\\xad\\xaa\\x02\\xbd\\x01Y\\xe9\\x7f\\x08\\x0c\\xadRqQ|6Q\\x99\\xe7\\xceI\\xf3r\\xa8\\x18D\\x05\r\\x0c\\xae\\xael\\xaf\\xf5Q\\xde\\x06\\x10\\xe6\\x1eG=FON\\xabz\\x03\\xb5\\xae\\x9a\\x98$\\xde\\xbdL~m\\xac8S\\x01\\xb0\\xd3\\xc6\\xdbMH*\\x02\\xa7\\x8ddQ\\xa1Q\\x85\\xeb_^\\xbc\\x01\\xed\\xb2h\\xe1\\xbd\\x1d\\x08tbE\\xf5U\\x86\\xbd\\xe1B&*s\\x171\\xa9\\xaf\\xd1\\x04IpZN\\xc0p!\\x06\\xda\\xa9\\x01\r\\xa7m+\\xbc@R\\xd1\\x8f\\x0c\\xd0+\\xf8\\x1d)Sz8\\x1d\\xc2\\x8b\\xa2x\\xbcyp\\x0f\\xf2w\\xbdu\\xcf4\\xd9\\xdf\\xcb)\\x19\\x88\\x86\\xe9\\xa1d\\xcb\\x12I\\xed)(\\xdc\\x94+*\\x98B@\\xda\\xe0\\xf33f\\xc5*\\xdeD\\xc6\\xd8\\x82\\xc6$\\xb2\\x19lh\\xe6F\\xb6\\xebI\\xb1\\xf7B\\xe3^\\x01\\x0e\\x120qm\\x8fT\\xd5\\x86\\xef\\x1f\t\\xe2!\\xe5\\x06\\xe4\\x8a\\x8f?\\xf4\\xe6=Bfa\\xdbG>\\xef\\xb8\\x14\\xea't\\x867\\x1f\\xd0\\x1f\\xc6\\xee\\xf7\\xe3\\x0e\\xd81~\t0\\x93s\\xdc\\xc5A\\xf6F\\xd5\\xb3Hr|\\xe8\\xfbt\\x8cLp\\xa2\\x9a\\xee\\xafA\\xa1\\xd8\\xfc\\x8f\\xdc\\xca<\\xe3#b~\\xdb7\\xe40\\xe3S\\x91\\x7fg\\x02\\xa9\\xc6\\x05\\xa4$\\xf4gc>\\xb0m&c\\xbe\\x9c@a\\xc1\\x89\\xcc\\xd3\\xe919\\xaf8\\x1ec7'\\x82\\xd9\\xf8\\x81\\x9f\\xfd\\ym\\x1c\\xe5iK\\x08\\x8ddq\\xb6Tc\\xd1\\xb4\\xf8x\\xd2\\xb3v\\xbb\\x9a\\xb7\\xa1\\xdfar\\x8f\\xcd\\xcc\\xb2\\xdbaL\\xe8b\\xb7J4\\xab\\xe8.\\x94\\x9f\\x0b/\\x01\\x1a\\xc0\\x17\\x0e\\xca\\x8dW\\xcc\\xd2\\x8f!K\\xd1&n\\xbf\\x9c?\\xe25u\\xe5\\x17\\x881\\xb9\\xeb\\xeaf\\xd9\\xb0\\x9b\\xd9\\x99\\x0e\\xd4R=\\xf0\\x9a\\x02eH\\xaa)\\x01R\\xed\\xc9\\x98\\xd5\\xfd\\x83\\xee\\xa6\\x86\\xe0\\x8d\\x01i\\xc8\\xd9\\x9b\\x1e\\xe0\\x9bQ$\\xb3\\xc2\\xd3\\xaax\\xaaz\\x9a-R\\x9d2\\xacD~+\\xe8\\xbe\\xa7\\xaf\\x04\\xfd\\xae\\x81lH2\\xdf$Be\\x03\\xee\\x8b\\xb0\\xf4\\xbb\\x84:pn\\xfa\\xea\\xf5*\\x14\\xe0\\xd7\\x01\\xf1\\xbe\"q\\xb1\\x92=8\\x80\\xd3'\\x05\\xc4\\x95\\xb1P\\xc6\\xc7\\xc7\\x14",
- "port": 8889
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment