Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * ID: 5032
- * MalFamily: "Rat"
- * MalScore: 10.0
- * File Name: "rat_402ce22b517e340da9e58c09fa2687e8.exe"
- * File Size: 642560
- * File Type: "PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows"
- * SHA256: "2faa4668db36c1f7b685fe42b0271a59cc8ead866a695b5cf073130397f8a014"
- * MD5: "402ce22b517e340da9e58c09fa2687e8"
- * SHA1: "0f9d4ad4e77cc17a8d1a3f9744d46543dd01b005"
- * SHA512: "d413b427f0437f24b8ba47c5061441fe5f47a84cb5bf5fde105937e4efe48da8bd9f34c347e3ee261d52d3d8043c3eecc6b4e0f90475ce90f1eee624db4f8f71"
- * CRC32: "70639DF7"
- * SSDEEP: "12288:nU1O5n3r0ix0fRbGC7vX4FASC5kvGjtcf1CdM7cR81H4EXd:nU1WwAsRbZvoFASC5z6DwR8Hb"
- * Process Execution:
- "u73zb7jXqJl.exe",
- "u73zb7jXqJl.exe"
- * Executed Commands:
- "\"C:\\Users\\user\\AppData\\Local\\Temp\\u73zb7jXqJl.exe\""
- * Signatures Detected:
- "Description": "SetUnhandledExceptionFilter detected (possible anti-debug)",
- "Details":
- "Description": "Behavioural detection: Executable code extraction",
- "Details":
- "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
- "Details":
- "IP_ioc": "5.45.127.135:2012 (Estonia)"
- "Description": "Possible date expiration check, exits too soon after checking local time",
- "Details":
- "process": "u73zb7jXqJl.exe, PID 3876"
- "Description": "Guard pages use detected - possible anti-debugging.",
- "Details":
- "Description": "A process attempted to delay the analysis task.",
- "Details":
- "Process": "u73zb7jXqJl.exe tried to sleep 423 seconds, actually delayed analysis time by 0 seconds"
- "Description": "At least one IP Address, Domain, or File Name was found in a crypto call",
- "Details":
- "ioc": "v2.0.50727"
- "Description": "A process created a hidden window",
- "Details":
- "Process": "u73zb7jXqJl.exe -> C:\\Users\\user\\AppData\\Local\\Temp\\u73zb7jXqJl.exe"
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details":
- "section": "name: .text, entropy: 8.00, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ, raw_size: 0x0008c200, virtual_size: 0x0008c1e7"
- "Description": "Anomalous .NET characteristics",
- "Details":
- "anomalous_version": "Assembly version is set to 0"
- "Description": "Behavioural detection: Injection (Process Hollowing)",
- "Details":
- "Injection": "u73zb7jXqJl.exe(3876) -> u73zb7jXqJl.exe(3196)"
- "Description": "Executed a process and injected code into it, probably while unpacking",
- "Details":
- "Injection": "u73zb7jXqJl.exe(3876) -> u73zb7jXqJl.exe(3196)"
- "Description": "Behavioural detection: Injection (inter-process)",
- "Details":
- * Started Service:
- * Mutexes:
- "Global\\CLR_PerfMon_WrapMutex",
- "Global\\CLR_CASOFF_MUTEX",
- "Global\\.net clr networking"
- * Modified Files:
- * Deleted Files:
- "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.3876.19612953",
- "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.3876.19612953",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.3876.19612968"
- * Modified Registry Keys:
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- "country_name": "Estonia",
- "ip": "5.45.127.135",
- "inaddrarpa": "",
- "hostname": ""
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment