Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: ""
- * MalScore: 10.0
- * File Name: "Exes_f734bced23aef410e3a723a5226e1c60.exe"
- * File Size: 1280512
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "9fcccddd5eb0b89160a600c8c4fead60666f952407ab45463e79326a8a37355b"
- * MD5: "f734bced23aef410e3a723a5226e1c60"
- * SHA1: "849fa4483b5f42d9b55464779e9255bff2632bf9"
- * SHA512: "80c82b5b2002b31bc4faa44c3c2ca3cde083d80ef12c0d4c0a3e8964caa56a6cc7175ebe9d6fb82f430d5971c2edf4efcec550902b496466bd4e45b05697ad14"
- * CRC32: "75F98379"
- * SSDEEP: "24576:VAHnh+eWsN3skA4RV1Hom2KXMmHaVpr3pM8KTEeU6mnReD2a5:Eh+ZkldoPK8YaVU7TZU6mQv"
- * Process Execution:
- "qlVIovs1s6wz9HV.exe",
- "RegSvcs.exe",
- "svchost.exe",
- "WmiPrvSE.exe",
- "svchost.exe",
- "taskeng.exe",
- "taskeng.exe",
- "msoia.exe",
- "msoia.exe",
- "taskeng.exe",
- "WMIADAP.exe",
- "taskeng.exe"
- * Executed Commands:
- "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding",
- "taskeng.exe DA0ED248-9EDB-4144-B9E7-AFC1D00A662A S-1-5-18:NT AUTHORITY\\System:Service:",
- "taskeng.exe 93F8F12B-83AB-4A0B-904F-40C3B7F49214 S-1-5-21-0000000000-0000000000-0000000000-1000:Host\\user:Interactive:1",
- "taskeng.exe C1806AB2-87C8-4C1E-9841-B309890E8556 S-1-5-18:NT AUTHORITY\\System:Service:",
- "\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE wmiadap.exe /F /T /R",
- "taskeng.exe 65191ABB-F64B-4F4C-AEAE-1869BB240271 S-1-5-18:NT AUTHORITY\\System:Service:",
- "taskeng.exe F93B51BE-2DC5-4353-8B2D-436260120CAA S-1-5-18:NT AUTHORITY\\System:Service:",
- "\"C:\\Program Files\\Common Files\\Microsoft Shared\\Office15\\OLicenseHeartbeat.exe\"",
- "\"C:\\Program Files\\Microsoft Office\\Office15\\msoia.exe\" scan upload mininterval:2880",
- "\"C:\\Program Files\\Microsoft Office\\Office15\\msoia.exe\" scan upload"
- * Signatures Detected:
- "Description": "SetUnhandledExceptionFilter detected (possible anti-debug)",
- "Details":
- "Description": "Behavioural detection: Executable code extraction",
- "Details":
- "Description": "Guard pages use detected - possible anti-debugging.",
- "Details":
- "Description": "A process attempted to delay the analysis task.",
- "Details":
- "Process": "taskeng.exe tried to sleep 480 seconds, actually delayed analysis time by 0 seconds"
- "Process": "svchost.exe tried to sleep 360 seconds, actually delayed analysis time by 0 seconds"
- "Description": "Expresses interest in specific running processes",
- "Details":
- "process": "RegSvcs.exe"
- "process": "SearchIndexer.exe"
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: qlVIovs1s6wz9HV.exe, pid: 3876, offset: 0x00000000, length: 0x00138a00"
- "Description": "A process created a hidden window",
- "Details":
- "Process": "svchost.exe -> \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE"
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details":
- "section": "name: .rsrc, entropy: 7.95, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ, raw_size: 0x0006e400, virtual_size: 0x0006e288"
- "Description": "Uses Windows utilities for basic functionality",
- "Details":
- "command": "\"C:\\Program Files\\Common Files\\Microsoft Shared\\Office15\\OLicenseHeartbeat.exe\""
- "Description": "Behavioural detection: Injection (Process Hollowing)",
- "Details":
- "Injection": "qlVIovs1s6wz9HV.exe(3876) -> RegSvcs.exe(3360)"
- "Description": "Executed a process and injected code into it, probably while unpacking",
- "Details":
- "Injection": "qlVIovs1s6wz9HV.exe(3876) -> RegSvcs.exe(3360)"
- "Description": "Behavioural detection: Injection (inter-process)",
- "Details":
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\fjfbmtlwgoacezqljpwo"
- "data": "C:\\Users\\Public\\fjfbmtlwgoacezqljpwo.vbs"
- "Description": "Stack pivoting was detected when using a critical API",
- "Details":
- "process": "taskeng.exe:1584"
- "process": "svchost.exe:888"
- "Description": "File has been identified by 22 Antiviruses on VirusTotal as malicious",
- "Details":
- "McAfee": "Artemis!F734BCED23AE"
- "Cylance": "Unsafe"
- "Alibaba": "Trojan:Win32/AutoitInject.7f6e5f64"
- "F-Prot": "W32/AutoIt.KF.gen!Eldorado"
- "Symantec": "ML.Attribute.HighConfidence"
- "APEX": "Malicious"
- "Kaspersky": "HEUR:Trojan.Win32.Generic"
- "Paloalto": "generic.ml"
- "Endgame": "malicious (high confidence)"
- "F-Secure": "Heuristic.HEUR/AGEN.1038811"
- "McAfee-GW-Edition": "BehavesLike.Win32.Downloader.tc"
- "Cyren": "W32/AutoIt.KF.gen!Eldorado"
- "Avira": "HEUR/AGEN.1038811"
- "Microsoft": "Trojan:Win32/Wacatac.B!ml"
- "ZoneAlarm": "HEUR:Trojan.Win32.Generic"
- "Acronis": "suspicious"
- "ESET-NOD32": "a variant of Win32/Injector.Autoit.EGA"
- "Rising": "Trojan.Obfus/Autoit!1.BB81 (CLASSIC)"
- "Fortinet": "AutoIt/Injector.EGA!tr"
- "Panda": "Trj/Genetic.gen"
- "CrowdStrike": "win/malicious_confidence_70% (D)"
- "Qihoo-360": "HEUR/QVM10.1.79E1.Malware.Gen"
- "Description": "Creates a slightly modified copy of itself",
- "Details":
- "file": "C:\\Users\\user\\RMActivate\\amstream.bat"
- "percent_match": 100
- "Description": "Anomalous binary characteristics",
- "Details":
- "anomaly": "Actual checksum does not match that reported in PE header"
- * Started Service:
- * Mutexes:
- "Global\\CLR_PerfMon_WrapMutex",
- "Global\\CLR_CASOFF_MUTEX",
- "Global\\ADAP_WMI_ENTRY",
- "Global\\RefreshRA_Mutex",
- "Global\\RefreshRA_Mutex_Lib",
- "Global\\RefreshRA_Mutex_Flag"
- * Modified Files:
- "C:\\Users\\user\\RMActivate\\amstream.bat",
- "C:\\Users\\Public\\fjfbmtlwgoacezqljpwo.vbs",
- "\\Device\\LanmanDatagramReceiver",
- "C:\\Windows\\SoftwareDistribution\\DataStore\\DataStore.edb",
- "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edb.chk",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
- "\\??\\WMIDataDevice"
- * Deleted Files:
- "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edbtmp.log"
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\fjfbmtlwgoacezqljpwo",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\ED0D73D7-BC97-46E2-AC55-FD6EB3F72C05\\DynamicInfo",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\DA0ED248-9EDB-4144-B9E7-AFC1D00A662A",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\B17E070E-57E3-43F6-96F5-A9A9C921DEBF\\DynamicInfo",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\93F8F12B-83AB-4A0B-904F-40C3B7F49214",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\DF000DCA-3FA2-48A6-9E59-C0606F9F8D73\\DynamicInfo",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\C1806AB2-87C8-4C1E-9841-B309890E8556",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\65191ABB-F64B-4F4C-AEAE-1869BB240271",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\F93B51BE-2DC5-4353-8B2D-436260120CAA",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\DA0ED248-9EDB-4144-B9E7-AFC1D00A662A\\data",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\93F8F12B-83AB-4A0B-904F-40C3B7F49214\\data",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\C1806AB2-87C8-4C1E-9841-B309890E8556\\data",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\65191ABB-F64B-4F4C-AEAE-1869BB240271\\data"
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment