Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: ""
- * MalScore: 2.0
- * File Name: "CondicoesGerais"
- * File Size: 91233
- * File Type: "ASCII text, with very long lines, with CRLF line terminators"
- * SHA256: "ea90f67d4cc290adbdcbe87904cfae9fab91418caafa412c5ccb4ddcc1bac202"
- * MD5: "bd4a726cdcde7d3f47f8d86c90dc98e7"
- * SHA1: "0c70fd64a6a52d3671f9cc16c47c20f161c19331"
- * SHA512: "086cf12f9d589488138dbdcada4d40e570eab46e8e29e172b7d23d24570c412083dbbb5b8edc221a9fbe0129258c4d861abdfc59749c4377482f9974a0c73b8c"
- * CRC32: "104C6291"
- * SSDEEP: "1536:5BMHBrmommxpACd5WtMiVXre1puOFk+29GUm:5By9QmQCd0q8re6OFD3J"
- * Process Execution:
- "cmd.exe",
- "rundll32.exe",
- "services.exe",
- "svchost.exe",
- "taskhost.exe",
- "sc.exe",
- "svchost.exe",
- "svchost.exe"
- * Executed Commands:
- "\"C:\\Windows\\system32\\rundll32.exe\" C:\\Windows\\system32\\shell32.dll,OpenAs_RunDLL C:\\Users\\user\\AppData\\Local\\Temp\\CondicoesGerais",
- "C:\\Users\\user\\AppData\\Local\\Temp\\CondicoesGerais ",
- "C:\\Windows\\system32\\svchost.exe -k netsvcs",
- "taskhost.exe $(Arg0)",
- "C:\\Windows\\system32\\sc.exe start w32time task_started",
- "C:\\Windows\\system32\\svchost.exe -k LocalService",
- "C:\\Windows\\System32\\svchost.exe -k WerSvcGroup"
- * Signatures Detected:
- "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
- "Details":
- "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 11571443 times"
- * Started Service:
- "AppMgmt",
- "WerSvc",
- "W32Time"
- * Mutexes:
- "Local\\ZoneAttributeCacheCounterMutex",
- "Local\\ZonesCacheCounterMutex",
- "Local\\ZonesLockedCacheCounterMutex"
- * Modified Files:
- "C:\\Windows\\sysnative\\LogFiles\\Scm\\4963ad21-c4a5-42a5-b9bd-e441d57204fe",
- "C:\\Windows\\sysnative\\LogFiles\\Scm\\7bbc503c-5977-4798-a4ae-61483a7e030d",
- "C:\\Windows\\sysnative\\LogFiles\\Scm\\e36cf70f-8a41-4006-b09e-19f4b13bedb5",
- "\\??\\PIPE\\lsarpc"
- * Deleted Files:
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\TimeProviders\\NtpClient\\SpecialPollTimeRemaining"
- * Deleted Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName"
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment