Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Malicious"
- * MalScore: 10.0
- * File Name: "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe"
- * File Size: 262144
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "492457aac92e1062ae1cc3c418213785c45df720cae496d1ea5b868b9534973f"
- * MD5: "4abb6f6cbd18258b9ef05083c2a817ca"
- * SHA1: "dac81dc149ff6e1520e97a9a1cb7147cfcc8db62"
- * SHA512: "5dca6f1eb7af8776f69c4ffdbe309eb5db5960cef1fd8f1103c923098ba3e1b83aa1a3822d5c5767826df024f302424075c3fdfeddd72430f40314a9be520240"
- * CRC32: "E34B7027"
- * SSDEEP: "6144:d1x036R3vGram/BAwFIjFCLHGMi1gNiVSAn:WAvGx/B2+Hk13VSi"
- * Process Execution:
- "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe",
- "cmd.exe",
- "sc.exe",
- "cmd.exe",
- "sc.exe",
- "cmd.exe",
- "powershell.exe",
- "cmd.exe",
- "powershell.exe",
- "cmd.exe",
- "powershell.exe",
- "cmd.exe",
- "powershell.exe",
- "cmd.exe",
- "powershell.exe",
- "cmd.exe",
- "powershell.exe",
- "cmd.exe",
- "powershell.exe",
- "cmd.exe",
- "powershell.exe",
- "cmd.exe",
- "powershell.exe",
- "cmd.exe",
- "powershell.exe",
- "svchost.exe",
- "services.exe",
- "lsass.exe"
- * Executed Commands:
- "cmd.exe /c sc stop WinDefend",
- "cmd.exe /c sc delete WinDefend",
- "cmd.exe /c powershell Set-MpPreference -DisableRealtimeMonitoring $true",
- "cmd.exe /c powershell Set-MpPreference -DisableBehaviorMonitoring $true",
- "cmd.exe /c powershell Set-MpPreference -DisableBlockAtFirstSeen $true",
- "cmd.exe /c powershell Set-MpPreference -DisableIOAVProtection $true",
- "cmd.exe /c powershell Set-MpPreference -DisablePrivacyMode $true",
- "cmd.exe /c powershell Set-MpPreference -DisableIntrusionPreventionSystem $true",
- "cmd.exe /c powershell Set-MpPreference -SevereThreatDefaultAction 6",
- "cmd.exe /c powershell Set-MpPreference -LowThreatDefaultAction 6",
- "cmd.exe /c powershell Set-MpPreference -ModerateThreatDefaultAction 6",
- "cmd.exe /c powershell Set-MpPreference -DisableScriptScanning $true",
- "C:\\Windows\\system32\\svchost.exe",
- "sc stop WinDefend",
- "sc delete WinDefend",
- "powershell Set-MpPreference -DisableRealtimeMonitoring $true",
- "powershell Set-MpPreference -DisableBehaviorMonitoring $true",
- "powershell Set-MpPreference -DisableBlockAtFirstSeen $true",
- "powershell Set-MpPreference -DisableIOAVProtection $true",
- "powershell Set-MpPreference -DisablePrivacyMode $true",
- "powershell Set-MpPreference -DisableIntrusionPreventionSystem $true",
- "powershell Set-MpPreference -SevereThreatDefaultAction 6",
- "powershell Set-MpPreference -LowThreatDefaultAction 6",
- "powershell Set-MpPreference -ModerateThreatDefaultAction 6",
- "powershell Set-MpPreference -DisableScriptScanning $true",
- "C:\\Windows\\system32\\lsass.exe"
- * Signatures Detected:
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Possible date expiration check, exits too soon after checking local time",
- "Details":
- "process": "cmd.exe, PID 1388"
- "Description": "A process created a hidden window",
- "Details":
- "Process": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe -> cmd.exe"
- "Process": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe -> cmd.exe"
- "Process": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe -> cmd.exe"
- "Process": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe -> cmd.exe"
- "Process": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe -> cmd.exe"
- "Process": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe -> cmd.exe"
- "Process": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe -> cmd.exe"
- "Process": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe -> cmd.exe"
- "Process": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe -> cmd.exe"
- "Process": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe -> cmd.exe"
- "Process": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe -> cmd.exe"
- "Process": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe -> cmd.exe"
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details":
- "section": "name: .rsrc, entropy: 7.95, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ, raw_size: 0x0002c000, virtual_size: 0x0002b318"
- "Description": "Attempts to stop active services",
- "Details":
- "servicename": "WinDefend"
- "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
- "Details":
- "Spam": "services.exe (504) called API GetSystemTimeAsFileTime 6951872 times"
- "Spam": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe (996) called API GetSystemTimeAsFileTime 258050 times"
- "Description": "Spoofs its process name and/or associated pathname to appear as a legitimate process",
- "Details":
- "modified_name": "svchost.exe",
- "modified_path": "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe",
- "original_name": "svchost.exe",
- "original_path": "C:\\Windows\\system32\\svchost.exe"
- "Description": "Creates a hidden or system file",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF159bf79.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a14cd.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a0eb2.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a1980.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a1b55.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF159c6ad.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF159c96c.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a310f.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a2ac6.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF159d1c9.TMP"
- "Description": "File has been identified by 16 Antiviruses on VirusTotal as malicious",
- "Details":
- "Cylance": "Unsafe"
- "APEX": "Malicious"
- "Paloalto": "generic.ml"
- "Kaspersky": "UDS:DangerousObject.Multi.Generic"
- "Avast": "FileRepMalware"
- "Endgame": "malicious (high confidence)"
- "Invincea": "heuristic"
- "Trapmine": "suspicious.low.ml.score"
- "FireEye": "Generic.mg.4abb6f6cbd18258b"
- "SentinelOne": "DFI - Malicious PE"
- "Webroot": "W32.Trojan.Gen"
- "ZoneAlarm": "UDS:DangerousObject.Multi.Generic"
- "Acronis": "suspicious"
- "AVG": "FileRepMalware"
- "Cybereason": "malicious.149ff6"
- "CrowdStrike": "win/malicious_confidence_100% (W)"
- "Description": "Attempts to disable Windows Defender",
- "Details":
- "Description": "Anomalous binary characteristics",
- "Details":
- "anomaly": "Actual checksum does not match that reported in PE header"
- * Started Service:
- "KeyIso"
- * Mutexes:
- "Global\\CLR_CASOFF_MUTEX",
- "Global\\838B6C9EB27932960"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF9E9A94CEC0F800E0.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
- "\\??\\PIPE\\srvsvc",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\Y1R01JYAAU6PYWF6A9NP.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF159bf79.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\X5RU8296LFZGT4JYT8Z8.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a14cd.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\2MZ0E6IBYK0PB2HK0NXR.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a0eb2.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\I43T9FF9NWS0K2OO74JP.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a1980.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\IMOZBRXRCTBGLMXM1S3V.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a1b55.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\DTN2ZYVS7LBLNM2K8OBB.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF159c6ad.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\V4OFYM7F2JHWMO8O11LZ.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF159c96c.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\C59O75REC3FEC7II02BN.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a310f.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\7BL413FWRC2E1KHS2GAE.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a2ac6.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\0TIXMJICD1WC20LJB6T8.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF159d1c9.TMP"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF9E9A94CEC0F800E0.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF159bf79.TMP",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2396.22661015",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2396.22661031",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2396.22661031",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a14cd.TMP",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2404.22680890",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2404.22680890",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2404.22680906",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a0eb2.TMP",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2440.22679390",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2440.22679406",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2440.22679406",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a1980.TMP",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1168.22682593",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1168.22682593",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1168.22682609",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a1b55.TMP",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2304.22682859",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2304.22682859",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2304.22682859",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF159c6ad.TMP",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1776.22663250",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1776.22663250",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1776.22663265",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF159c96c.TMP",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1692.22664546",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1692.22664546",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1692.22664546",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a310f.TMP",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2676.22688125",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2676.22688125",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2676.22688125",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a2ac6.TMP",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1796.22686781",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1796.22686781",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1796.22686781",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF159d1c9.TMP",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.324.22668359",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.324.22668375",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.324.22668375"
- * Modified Registry Keys:
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\DisableAntiSpyware",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableBehaviorMonitoring",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableOnAccessProtection",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableScanOnRealtimeEnable",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableIOAVProtection",
- "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList"
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Add Comment
Please, Sign In to add comment