paladin316

2321Emotet_f7a31719c91770d2f7f945c5acba4116_2_2019-09-18_18_30.txt

Sep 18th, 2019
2,177
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 10.78 KB | None | 0 0
  1.  
  2. * ID: 2321
  3. * MalFamily: "Malicious"
  4.  
  5. * MalScore: 10.0
  6.  
  7. * File Name: "Emotet_f7a31719c91770d2f7f945c5acba4116.2"
  8. * File Size: 528384
  9. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  10. * SHA256: "4d8acd99b8e8b1e40b64b35dcee753a3f9073847ec1e8957e793dab849140c29"
  11. * MD5: "f7a31719c91770d2f7f945c5acba4116"
  12. * SHA1: "ac2162d2ae066bf9067ad7f8bf3697a78154ea68"
  13. * SHA512: "1375dced5b7a646461d632d7069d40d69aaca2e008f16f6bbcb22ea8304ebaaa6f8d26d05da45dbe3c79b89fea9e3c048da5bd3c8823eafe7bb7376182b6a38d"
  14. * CRC32: "B5F7D6CB"
  15. * SSDEEP: "6144:0LMvSfAq5a1dCC8DGNJTMvFC94iMdl01J4t3j1udHi9y0mF831cP2UKoVtI1X63v:0L5Aq5GqSjovFCaffFKKmFzpVi1Wgo"
  16.  
  17. * Process Execution:
  18. "IOaEFsR6ISaoKJj.exe",
  19. "IOaEFsR6ISaoKJj.exe",
  20. "IOaEFsR6ISaoKJj.exe",
  21. "IOaEFsR6ISaoKJj.exe",
  22. "explorer.exe",
  23. "services.exe",
  24. "historymachine.exe",
  25. "historymachine.exe",
  26. "historymachine.exe",
  27. "historymachine.exe"
  28.  
  29.  
  30. * Executed Commands:
  31. "\"C:\\Users\\user\\AppData\\Local\\Temp\\IOaEFsR6ISaoKJj.exe\"",
  32. "C:\\Users\\user\\AppData\\Local\\Temp\\IOaEFsR6ISaoKJj.exe --9bbbf265",
  33. "\"C:\\Windows\\SysWOW64\\historymachine.exe\"",
  34. "C:\\Windows\\SysWOW64\\historymachine.exe --81d93c85"
  35.  
  36.  
  37. * Signatures Detected:
  38.  
  39. "Description": "SetUnhandledExceptionFilter detected (possible anti-debug)",
  40. "Details":
  41.  
  42.  
  43. "Description": "Behavioural detection: Executable code extraction",
  44. "Details":
  45.  
  46.  
  47. "Description": "Communicates with IPs located across a large number of unique countries",
  48. "Details":
  49.  
  50. "country": "France"
  51.  
  52.  
  53. "country": "United Arab Emirates"
  54.  
  55.  
  56. "country": "India"
  57.  
  58.  
  59. "country": "Kenya"
  60.  
  61.  
  62. "country": "Czech Republic"
  63.  
  64.  
  65. "country": "Belgium"
  66.  
  67.  
  68. "country": "Argentina"
  69.  
  70.  
  71. "country": "Mexico"
  72.  
  73.  
  74. "country": "Germany"
  75.  
  76.  
  77. "country": "Canada"
  78.  
  79.  
  80.  
  81.  
  82. "Description": "Possible date expiration check, exits too soon after checking local time",
  83. "Details":
  84.  
  85. "process": "historymachine.exe, PID 1112"
  86.  
  87.  
  88.  
  89.  
  90. "Description": "Mimics the system's user agent string for its own requests",
  91. "Details":
  92.  
  93.  
  94. "Description": "Performs HTTP requests potentially not found in PCAP.",
  95. "Details":
  96.  
  97. "url_ioc": "189.209.217.49:80/between/glitch/ban/"
  98.  
  99.  
  100. "url_ioc": "201.250.11.236:50000/balloon/badge/walk/"
  101.  
  102.  
  103. "url_ioc": "37.157.194.134:443/tpt/iplk/ban/"
  104.  
  105.  
  106. "url_ioc": "178.254.6.27:7080/mult/"
  107.  
  108.  
  109. "url_ioc": "190.18.146.70:80/arizona/stubs/raster/"
  110.  
  111.  
  112. "url_ioc": "142.44.162.209:8080/guids/"
  113.  
  114.  
  115. "url_ioc": "45.123.3.54:443/vermont/stubs/walk/"
  116.  
  117.  
  118. "url_ioc": "187.144.189.58:50000/free/scripts/ban/"
  119.  
  120.  
  121. "url_ioc": "187.147.50.167:8080/stubs/raster/walk/"
  122.  
  123.  
  124. "url_ioc": "80.11.163.139:21/usbccid/"
  125.  
  126.  
  127. "url_ioc": "92.222.125.16:7080/teapot/mult/"
  128.  
  129.  
  130. "url_ioc": "41.220.119.246:80/iplk/enabled/ban/"
  131.  
  132.  
  133. "url_ioc": "86.98.25.30:53/raster/free/ban/"
  134.  
  135.  
  136. "url_ioc": "31.12.67.62:7080/badge/between/"
  137.  
  138.  
  139.  
  140.  
  141. "Description": "Repeatedly searches for a not-found process, may want to run with startbrowser=1 option",
  142. "Details":
  143.  
  144.  
  145. "Description": "A process created a hidden window",
  146. "Details":
  147.  
  148. "Process": "IOaEFsR6ISaoKJj.exe -> C:\\Users\\user\\AppData\\Local\\Temp\\IOaEFsR6ISaoKJj.exe"
  149.  
  150.  
  151. "Process": "IOaEFsR6ISaoKJj.exe -> C:\\Users\\user\\AppData\\Local\\Temp\\IOaEFsR6ISaoKJj.exe"
  152.  
  153.  
  154. "Process": "historymachine.exe -> C:\\Windows\\SysWOW64\\historymachine.exe"
  155.  
  156.  
  157. "Process": "historymachine.exe -> C:\\Windows\\SysWOW64\\historymachine.exe"
  158.  
  159.  
  160.  
  161.  
  162. "Description": "File has been identified by 3 Antiviruses on VirusTotal as malicious",
  163. "Details":
  164.  
  165. "APEX": "Malicious"
  166.  
  167.  
  168. "Emsisoft": "Trojan.Agent (A)"
  169.  
  170.  
  171. "Endgame": "malicious (moderate confidence)"
  172.  
  173.  
  174.  
  175.  
  176. "Description": "Multiple direct IP connections",
  177. "Details":
  178.  
  179. "direct_ip_connections": "Made direct connections to 13 unique IP addresses"
  180.  
  181.  
  182.  
  183.  
  184. "Description": "The binary likely contains encrypted or compressed data.",
  185. "Details":
  186.  
  187. "section": "name: .rsrc, entropy: 7.15, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ, raw_size: 0x0001d000, virtual_size: 0x0001ccec"
  188.  
  189.  
  190.  
  191.  
  192. "Description": "Deletes its original binary from disk",
  193. "Details":
  194.  
  195.  
  196. "Description": "Attempts to remove evidence of file being downloaded from the Internet",
  197. "Details":
  198.  
  199. "file": "C:\\Windows\\SysWOW64\\historymachine.exe:Zone.Identifier"
  200.  
  201.  
  202.  
  203.  
  204. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  205. "Details":
  206.  
  207. "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 10001218 times"
  208.  
  209.  
  210.  
  211.  
  212. "Description": "Installs itself for autorun at Windows startup",
  213. "Details":
  214.  
  215. "service name": "historymachine"
  216.  
  217.  
  218. "service path": "\"C:\\Windows\\SysWOW64\\historymachine.exe\""
  219.  
  220.  
  221.  
  222.  
  223. "Description": "Creates a copy of itself",
  224. "Details":
  225.  
  226. "copy": "C:\\Windows\\SysWOW64\\historymachine.exe"
  227.  
  228.  
  229.  
  230.  
  231. "Description": "Drops a binary and executes it",
  232. "Details":
  233.  
  234. "binary": "C:\\Windows\\SysWOW64\\historymachine.exe"
  235.  
  236.  
  237.  
  238.  
  239. "Description": "Created network traffic indicative of malicious activity",
  240. "Details":
  241.  
  242. "signature": "ET CNC Feodo Tracker Reported CnC Server group 3"
  243.  
  244.  
  245. "signature": "ET CNC Feodo Tracker Reported CnC Server group 11"
  246.  
  247.  
  248. "signature": "ET CNC Feodo Tracker Reported CnC Server group 16"
  249.  
  250.  
  251. "signature": "ET CNC Feodo Tracker Reported CnC Server group 18"
  252.  
  253.  
  254. "signature": "ET CNC Feodo Tracker Reported CnC Server group 23"
  255.  
  256.  
  257. "signature": "ET CNC Feodo Tracker Reported CnC Server group 24"
  258.  
  259.  
  260.  
  261.  
  262.  
  263. * Started Service:
  264. "historymachine"
  265.  
  266.  
  267. * Mutexes:
  268. "Global\\IC1C5B64F",
  269. "Global\\MC1C5B64F",
  270. "IESQMMUTEX_0_208"
  271.  
  272.  
  273. * Modified Files:
  274. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\S-1-5-21-0000000000-0000000000-0000000000-1000\\00000000-0000-0000-0000-000000000000b_00000000-0000-0000-0000-000000000000",
  275. "C:\\Windows\\SysWOW64\\historymachine.exe",
  276. "C:\\Windows\\sysnative\\LogFiles\\Scm\\9cdf079f-d488-47e0-8840-9a3500f1bbe4",
  277. "C:\\ProgramData\\Microsoft\\Crypto\\RSA\\S-1-5-18\\6d14e4b1d8ca773bab785d1be032546e_00000000-0000-0000-0000-000000000000"
  278.  
  279.  
  280. * Deleted Files:
  281. "C:\\Windows\\SysWOW64\\khmerflows.exe",
  282. "C:\\Users\\user\\AppData\\Local\\Temp\\IOaEFsR6ISaoKJj.exe",
  283. "C:\\Windows\\SysWOW64\\historymachine.exe:Zone.Identifier"
  284.  
  285.  
  286. * Modified Registry Keys:
  287. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\CEBFF5CD-ACE2-4F4F-9178-9926F41749EA\\Count\\1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7\\pzq.rkr",
  288. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\CEBFF5CD-ACE2-4F4F-9178-9926F41749EA\\Count\\HRZR_PGYFRFFVBA",
  289. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  290. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\11CD958A-C507-4EF3-B3F2-5FD9DFBD2C78.check.101\\CheckSetting",
  291. "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\DefaultConnectionSettings"
  292.  
  293.  
  294. * Deleted Registry Keys:
  295.  
  296. * DNS Communications:
  297.  
  298. * Domains:
  299.  
  300. * Network Communication - ICMP:
  301.  
  302. * Network Communication - HTTP:
  303.  
  304. * Network Communication - SMTP:
  305.  
  306. * Network Communication - Hosts:
  307.  
  308. "country_name": "France",
  309. "ip": "92.222.125.16",
  310. "inaddrarpa": "",
  311. "hostname": ""
  312.  
  313.  
  314. "country_name": "United Arab Emirates",
  315. "ip": "86.98.25.30",
  316. "inaddrarpa": "",
  317. "hostname": ""
  318.  
  319.  
  320. "country_name": "India",
  321. "ip": "45.123.3.54",
  322. "inaddrarpa": "",
  323. "hostname": ""
  324.  
  325.  
  326. "country_name": "Kenya",
  327. "ip": "41.220.119.246",
  328. "inaddrarpa": "",
  329. "hostname": ""
  330.  
  331.  
  332. "country_name": "Czech Republic",
  333. "ip": "37.157.194.134",
  334. "inaddrarpa": "",
  335. "hostname": ""
  336.  
  337.  
  338. "country_name": "Belgium",
  339. "ip": "31.12.67.62",
  340. "inaddrarpa": "",
  341. "hostname": ""
  342.  
  343.  
  344. "country_name": "Argentina",
  345. "ip": "201.250.11.236",
  346. "inaddrarpa": "",
  347. "hostname": ""
  348.  
  349.  
  350. "country_name": "Argentina",
  351. "ip": "190.18.146.70",
  352. "inaddrarpa": "",
  353. "hostname": ""
  354.  
  355.  
  356. "country_name": "Mexico",
  357. "ip": "189.209.217.49",
  358. "inaddrarpa": "",
  359. "hostname": ""
  360.  
  361.  
  362. "country_name": "Mexico",
  363. "ip": "187.147.50.167",
  364. "inaddrarpa": "",
  365. "hostname": ""
  366.  
  367.  
  368. "country_name": "Mexico",
  369. "ip": "187.144.189.58",
  370. "inaddrarpa": "",
  371. "hostname": ""
  372.  
  373.  
  374. "country_name": "Germany",
  375. "ip": "178.254.6.27",
  376. "inaddrarpa": "",
  377. "hostname": ""
  378.  
  379.  
  380. "country_name": "Canada",
  381. "ip": "142.44.162.209",
  382. "inaddrarpa": "",
  383. "hostname": ""
  384.  
  385.  
  386.  
  387. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment