paladin316

5032rat_402ce22b517e340da9e58c09fa2687e8_exe_2019-10-13_21_30.txt

Oct 13th, 2019
2,290
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.13 KB | None | 0 0
  1.  
  2. * ID: 5032
  3. * MalFamily: "Rat"
  4.  
  5. * MalScore: 10.0
  6.  
  7. * File Name: "rat_402ce22b517e340da9e58c09fa2687e8.exe"
  8. * File Size: 642560
  9. * File Type: "PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows"
  10. * SHA256: "2faa4668db36c1f7b685fe42b0271a59cc8ead866a695b5cf073130397f8a014"
  11. * MD5: "402ce22b517e340da9e58c09fa2687e8"
  12. * SHA1: "0f9d4ad4e77cc17a8d1a3f9744d46543dd01b005"
  13. * SHA512: "d413b427f0437f24b8ba47c5061441fe5f47a84cb5bf5fde105937e4efe48da8bd9f34c347e3ee261d52d3d8043c3eecc6b4e0f90475ce90f1eee624db4f8f71"
  14. * CRC32: "70639DF7"
  15. * SSDEEP: "12288:nU1O5n3r0ix0fRbGC7vX4FASC5kvGjtcf1CdM7cR81H4EXd:nU1WwAsRbZvoFASC5z6DwR8Hb"
  16.  
  17. * Process Execution:
  18. "u73zb7jXqJl.exe",
  19. "u73zb7jXqJl.exe"
  20.  
  21.  
  22. * Executed Commands:
  23. "\"C:\\Users\\user\\AppData\\Local\\Temp\\u73zb7jXqJl.exe\""
  24.  
  25.  
  26. * Signatures Detected:
  27.  
  28. "Description": "SetUnhandledExceptionFilter detected (possible anti-debug)",
  29. "Details":
  30.  
  31.  
  32. "Description": "Behavioural detection: Executable code extraction",
  33. "Details":
  34.  
  35.  
  36. "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
  37. "Details":
  38.  
  39. "IP_ioc": "5.45.127.135:2012 (Estonia)"
  40.  
  41.  
  42.  
  43.  
  44. "Description": "Possible date expiration check, exits too soon after checking local time",
  45. "Details":
  46.  
  47. "process": "u73zb7jXqJl.exe, PID 3876"
  48.  
  49.  
  50.  
  51.  
  52. "Description": "Guard pages use detected - possible anti-debugging.",
  53. "Details":
  54.  
  55.  
  56. "Description": "A process attempted to delay the analysis task.",
  57. "Details":
  58.  
  59. "Process": "u73zb7jXqJl.exe tried to sleep 423 seconds, actually delayed analysis time by 0 seconds"
  60.  
  61.  
  62.  
  63.  
  64. "Description": "At least one IP Address, Domain, or File Name was found in a crypto call",
  65. "Details":
  66.  
  67. "ioc": "v2.0.50727"
  68.  
  69.  
  70.  
  71.  
  72. "Description": "A process created a hidden window",
  73. "Details":
  74.  
  75. "Process": "u73zb7jXqJl.exe -> C:\\Users\\user\\AppData\\Local\\Temp\\u73zb7jXqJl.exe"
  76.  
  77.  
  78.  
  79.  
  80. "Description": "The binary likely contains encrypted or compressed data.",
  81. "Details":
  82.  
  83. "section": "name: .text, entropy: 8.00, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ, raw_size: 0x0008c200, virtual_size: 0x0008c1e7"
  84.  
  85.  
  86.  
  87.  
  88. "Description": "Anomalous .NET characteristics",
  89. "Details":
  90.  
  91. "anomalous_version": "Assembly version is set to 0"
  92.  
  93.  
  94.  
  95.  
  96. "Description": "Behavioural detection: Injection (Process Hollowing)",
  97. "Details":
  98.  
  99. "Injection": "u73zb7jXqJl.exe(3876) -> u73zb7jXqJl.exe(3196)"
  100.  
  101.  
  102.  
  103.  
  104. "Description": "Executed a process and injected code into it, probably while unpacking",
  105. "Details":
  106.  
  107. "Injection": "u73zb7jXqJl.exe(3876) -> u73zb7jXqJl.exe(3196)"
  108.  
  109.  
  110.  
  111.  
  112. "Description": "Behavioural detection: Injection (inter-process)",
  113. "Details":
  114.  
  115.  
  116.  
  117. * Started Service:
  118.  
  119. * Mutexes:
  120. "Global\\CLR_PerfMon_WrapMutex",
  121. "Global\\CLR_CASOFF_MUTEX",
  122. "Global\\.net clr networking"
  123.  
  124.  
  125. * Modified Files:
  126.  
  127. * Deleted Files:
  128. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.3876.19612953",
  129. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.3876.19612953",
  130. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.3876.19612968"
  131.  
  132.  
  133. * Modified Registry Keys:
  134.  
  135. * Deleted Registry Keys:
  136.  
  137. * DNS Communications:
  138.  
  139. * Domains:
  140.  
  141. * Network Communication - ICMP:
  142.  
  143. * Network Communication - HTTP:
  144.  
  145. * Network Communication - SMTP:
  146.  
  147. * Network Communication - Hosts:
  148.  
  149. "country_name": "Estonia",
  150. "ip": "5.45.127.135",
  151. "inaddrarpa": "",
  152. "hostname": ""
  153.  
  154.  
  155.  
  156. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment