paladin316

SCAN_609577_2019-07-12_13_30.txt

Jul 12th, 2019
2,635
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 15.40 KB | None | 0 0
  1.  
  2. * MalFamily: "Loki"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "SCAN_609577"
  7. * File Size: 879616
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "a50c03c9816a0bfd516039ef69b802c0d744f987386d41c15167efde01423e17"
  10. * MD5: "d83c9f71705352d017f0845ffbfe2e55"
  11. * SHA1: "c4b9c68c8b766154925c9b7ffcd2482dcb34fce4"
  12. * SHA512: "3bd93137acaf2abc4498183354f62623cf3c981868c800c2a94bbcce989838874e771dc3a8bc0afd62a2c581564615ecd5c577612eec3c014493af47e6d6b89d"
  13. * CRC32: "CB31BA94"
  14. * SSDEEP: "12288:VAAu3r96IzEAim1YCoMbWQil85rgGxACBUZSo/joF4B4Ojtob1JVYrU4voPY:VFyrV5WUbx5rgGxACB0P/cC9u32vkY"
  15.  
  16. * Process Execution:
  17. "SCAN_609577.exe",
  18. "smgi.exe",
  19. "smgi.exe",
  20. "services.exe"
  21.  
  22.  
  23. * Executed Commands:
  24. "\"C:\\Users\\user\\AppData\\Roaming\\suhru\\smgi.exe\"",
  25. "C:\\Windows\\system32\\lsass.exe"
  26.  
  27.  
  28. * Signatures Detected:
  29.  
  30. "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
  31. "Details":
  32.  
  33. "IP": "47.74.46.147:80"
  34.  
  35.  
  36.  
  37.  
  38. "Description": "Creates RWX memory",
  39. "Details":
  40.  
  41.  
  42. "Description": "A process attempted to delay the analysis task.",
  43. "Details":
  44.  
  45. "Process": "smgi.exe tried to sleep 977 seconds, actually delayed analysis time by 0 seconds"
  46.  
  47.  
  48.  
  49.  
  50. "Description": "Executed a process and injected code into it, probably while unpacking",
  51. "Details":
  52.  
  53. "Injection": "smgi.exe(2504) -> smgi.exe(3056)"
  54.  
  55.  
  56.  
  57.  
  58. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  59. "Details":
  60.  
  61. "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 13324651 times"
  62.  
  63.  
  64.  
  65.  
  66. "Description": "Steals private information from local Internet browsers",
  67. "Details":
  68.  
  69. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data"
  70.  
  71.  
  72.  
  73.  
  74. "Description": "Installs itself for autorun at Windows startup",
  75. "Details":
  76.  
  77. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\suhru.vbs"
  78.  
  79.  
  80. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\suhru.vbs"
  81.  
  82.  
  83.  
  84.  
  85. "Description": "Creates a hidden or system file",
  86. "Details":
  87.  
  88. "file": "C:\\Users\\user\\AppData\\Roaming\\474604\\45B65D.exe"
  89.  
  90.  
  91. "file": "C:\\Users\\user\\AppData\\Roaming\\474604"
  92.  
  93.  
  94.  
  95.  
  96. "Description": "File has been identified by 42 Antiviruses on VirusTotal as malicious",
  97. "Details":
  98.  
  99. "MicroWorld-eScan": "Trojan.Agent.EAII"
  100.  
  101.  
  102. "FireEye": "Generic.mg.d83c9f71705352d0"
  103.  
  104.  
  105. "Cylance": "Unsafe"
  106.  
  107.  
  108. "BitDefender": "Trojan.Agent.EAII"
  109.  
  110.  
  111. "K7GW": "Riskware ( 0040eff71 )"
  112.  
  113.  
  114. "K7AntiVirus": "Riskware ( 0040eff71 )"
  115.  
  116.  
  117. "TrendMicro": "TrojanSpy.Win32.LOKI.SMDD.hp"
  118.  
  119.  
  120. "Symantec": "Infostealer.Lokibot!16"
  121.  
  122.  
  123. "APEX": "Malicious"
  124.  
  125.  
  126. "Avast": "Win32:Malware-gen"
  127.  
  128.  
  129. "Kaspersky": "HEUR:Backdoor.Win32.NetWiredRC.gen"
  130.  
  131.  
  132. "Alibaba": "Trojan:Win32/Injector.b7989f81"
  133.  
  134.  
  135. "AegisLab": "Trojan.Win32.NetWiredRC.4!c"
  136.  
  137.  
  138. "Rising": "Trojan.Injector!1.AFE3 (CLASSIC)"
  139.  
  140.  
  141. "Ad-Aware": "Trojan.Agent.EAII"
  142.  
  143.  
  144. "Sophos": "Mal/Generic-S"
  145.  
  146.  
  147. "DrWeb": "Trojan.PWS.Stealer.19347"
  148.  
  149.  
  150. "Invincea": "heuristic"
  151.  
  152.  
  153. "McAfee-GW-Edition": "BehavesLike.Win32.Worm.ch"
  154.  
  155.  
  156. "Fortinet": "W32/Injector.EGKJ!tr"
  157.  
  158.  
  159. "Trapmine": "malicious.moderate.ml.score"
  160.  
  161.  
  162. "Emsisoft": "Trojan.Agent.EAII (B)"
  163.  
  164.  
  165. "Ikarus": "Win32.Outbreak"
  166.  
  167.  
  168. "Avira": "HEUR/AGEN.1041711"
  169.  
  170.  
  171. "MAX": "malware (ai score=82)"
  172.  
  173.  
  174. "Antiy-AVL": "Trojan/Win32.Wacatac"
  175.  
  176.  
  177. "Endgame": "malicious (high confidence)"
  178.  
  179.  
  180. "Arcabit": "Trojan.Agent.EAII"
  181.  
  182.  
  183. "ZoneAlarm": "HEUR:Backdoor.Win32.NetWiredRC.gen"
  184.  
  185.  
  186. "Microsoft": "Trojan:Win32/Wacatac.B!ml"
  187.  
  188.  
  189. "AhnLab-V3": "Win-Trojan/Delphiless.Exp"
  190.  
  191.  
  192. "Acronis": "suspicious"
  193.  
  194.  
  195. "McAfee": "RDN/Generic BackDoor"
  196.  
  197.  
  198. "Malwarebytes": "Trojan.MalPack.DLF"
  199.  
  200.  
  201. "ESET-NOD32": "a variant of Win32/Injector.EGNS"
  202.  
  203.  
  204. "TrendMicro-HouseCall": "TrojanSpy.Win32.LOKI.SMDD.hp"
  205.  
  206.  
  207. "SentinelOne": "DFI - Suspicious PE"
  208.  
  209.  
  210. "GData": "Trojan.Agent.EAII"
  211.  
  212.  
  213. "AVG": "Win32:Malware-gen"
  214.  
  215.  
  216. "Cybereason": "malicious.c8b766"
  217.  
  218.  
  219. "Paloalto": "generic.ml"
  220.  
  221.  
  222. "CrowdStrike": "win/malicious_confidence_90% (W)"
  223.  
  224.  
  225.  
  226.  
  227. "Description": "Creates a copy of itself",
  228. "Details":
  229.  
  230. "copy": "C:\\Users\\user\\AppData\\Roaming\\474604\\45B65D.exe"
  231.  
  232.  
  233.  
  234.  
  235. "Description": "Harvests credentials from local FTP client softwares",
  236. "Details":
  237.  
  238. "file": "C:\\Users\\user\\AppData\\Roaming\\FileZilla\\sitemanager.xml"
  239.  
  240.  
  241. "file": "C:\\Users\\user\\AppData\\Roaming\\FileZilla\\recentservers.xml"
  242.  
  243.  
  244. "file": "C:\\Users\\user\\AppData\\Roaming\\Far Manager\\Profile\\PluginsData\\42E4AEB1-A230-44F4-B33C-F195BB654931.db"
  245.  
  246.  
  247. "file": "C:\\Program Files (x86)\\FTPGetter\\Profile\\servers.xml"
  248.  
  249.  
  250. "file": "C:\\Users\\user\\AppData\\Roaming\\FTPGetter\\servers.xml"
  251.  
  252.  
  253. "file": "C:\\Users\\user\\AppData\\Roaming\\Estsoft\\ALFTP\\ESTdb2.dat"
  254.  
  255.  
  256. "key": "HKEY_CURRENT_USER\\Software\\Far\\Plugins\\FTP\\Hosts"
  257.  
  258.  
  259. "key": "HKEY_CURRENT_USER\\Software\\Far2\\Plugins\\FTP\\Hosts"
  260.  
  261.  
  262. "key": "HKEY_CURRENT_USER\\Software\\Ghisler\\Total Commander"
  263.  
  264.  
  265. "key": "HKEY_CURRENT_USER\\Software\\LinasFTP\\Site Manager"
  266.  
  267.  
  268.  
  269.  
  270. "Description": "Harvests information related to installed instant messenger clients",
  271. "Details":
  272.  
  273. "file": "C:\\Users\\user\\AppData\\Roaming\\.purple\\accounts.xml"
  274.  
  275.  
  276.  
  277.  
  278. "Description": "Harvests information related to installed mail clients",
  279. "Details":
  280.  
  281. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook"
  282.  
  283.  
  284. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046\\Email"
  285.  
  286.  
  287. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046"
  288.  
  289.  
  290. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9234ed9445f8fa418a542f350f18f326"
  291.  
  292.  
  293. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8408552e6dae7d45a0ba01520b6221ff\\Email"
  294.  
  295.  
  296. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9234ed9445f8fa418a542f350f18f326\\Email"
  297.  
  298.  
  299. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001"
  300.  
  301.  
  302. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002"
  303.  
  304.  
  305. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\Email"
  306.  
  307.  
  308. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\c02ebc5353d9cd11975200aa004ae40e\\Email"
  309.  
  310.  
  311. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8f92b60606058348930a96946cf329e1\\Email"
  312.  
  313.  
  314. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8408552e6dae7d45a0ba01520b6221ff"
  315.  
  316.  
  317. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2"
  318.  
  319.  
  320. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\240a97d961ed46428e29a3f1f1c23670"
  321.  
  322.  
  323. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b22783abb139fe46b0aad551d64b60e7\\Email"
  324.  
  325.  
  326. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\c02ebc5353d9cd11975200aa004ae40e"
  327.  
  328.  
  329. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2\\Email"
  330.  
  331.  
  332. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\Email"
  333.  
  334.  
  335. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a\\Email"
  336.  
  337.  
  338. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001\\Email"
  339.  
  340.  
  341. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676"
  342.  
  343.  
  344. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\cb23f8734d88734ca66c47c4527fd259"
  345.  
  346.  
  347. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001"
  348.  
  349.  
  350. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Outlook\\Profiles\\Outlook"
  351.  
  352.  
  353. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\cb23f8734d88734ca66c47c4527fd259\\Email"
  354.  
  355.  
  356. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook"
  357.  
  358.  
  359. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b22783abb139fe46b0aad551d64b60e7"
  360.  
  361.  
  362. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\240a97d961ed46428e29a3f1f1c23670\\Email"
  363.  
  364.  
  365. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604\\Email"
  366.  
  367.  
  368. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\Email"
  369.  
  370.  
  371. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a"
  372.  
  373.  
  374. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046"
  375.  
  376.  
  377. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604"
  378.  
  379.  
  380. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8f92b60606058348930a96946cf329e1"
  381.  
  382.  
  383. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046\\Email"
  384.  
  385.  
  386.  
  387.  
  388. "Description": "Attempts to interact with an Alternate Data Stream (ADS)",
  389. "Details":
  390.  
  391. "file": "C:\\Users\\user\\AppData\\Roaming\\suhru\\smgi.exe:ZoneIdentifier"
  392.  
  393.  
  394.  
  395.  
  396. "Description": "Collects information to fingerprint the system",
  397. "Details":
  398.  
  399.  
  400. "Description": "Anomalous binary characteristics",
  401. "Details":
  402.  
  403. "anomaly": "Timestamp on binary predates the release date of the OS version it requires by at least a year"
  404.  
  405.  
  406.  
  407.  
  408.  
  409. * Started Service:
  410. "VaultSvc"
  411.  
  412.  
  413. * Mutexes:
  414. "6EFA73A4746045B65DEE781E"
  415.  
  416.  
  417. * Modified Files:
  418. "C:\\Users\\user\\AppData\\Roaming\\suhru\\smgi.exe",
  419. "C:\\Users\\user\\AppData\\Roaming\\suhru\\smgi.exe:ZoneIdentifier",
  420. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\suhru.vbs",
  421. "C:\\Users\\user\\AppData\\Roaming\\474604\\45B65D.lck",
  422. "C:\\Users\\user\\AppData\\Roaming\\474604\\45B65D.exe"
  423.  
  424.  
  425. * Deleted Files:
  426. "C:\\Users\\user\\AppData\\Roaming\\suhru\\smgi.exe",
  427. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\suhru.vbs",
  428. "C:\\Users\\user\\AppData\\Roaming\\474604\\45B65D.lck"
  429.  
  430.  
  431. * Modified Registry Keys:
  432.  
  433. * Deleted Registry Keys:
  434.  
  435. * DNS Communications:
  436.  
  437. "type": "A",
  438. "request": "lestonline.ml",
  439. "answers":
  440.  
  441. "data": "47.74.46.147",
  442. "type": "A"
  443.  
  444.  
  445.  
  446.  
  447.  
  448. * Domains:
  449.  
  450. "ip": "47.74.46.147",
  451. "domain": "lestonline.ml"
  452.  
  453.  
  454.  
  455. * Network Communication - ICMP:
  456.  
  457. * Network Communication - HTTP:
  458.  
  459. * Network Communication - SMTP:
  460.  
  461. * Network Communication - Hosts:
  462.  
  463. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment