Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Backdoor"
- * MalScore: 10.0
- * File Name: "rat_0f03ef58fe48b28a6f135ba994f584a2.exe"
- * File Size: 215909
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "2fcc9c48d5d8a5c6889ca3302fcaa9f6296a9e36b167526033a0371172ab1693"
- * MD5: "0f03ef58fe48b28a6f135ba994f584a2"
- * SHA1: "7977f833d5ea82cb8f43de99a9c2f390db558e8d"
- * SHA512: "9ca1b5b2cf2889dd8b64521d0bbc7657e1fab57206067b23029bbc54f4215cac2764ece6ef801c891d85c849a5f677a8c14bec69fa8c7dff671ac001674c4739"
- * CRC32: "47160CD3"
- * SSDEEP: "3072:PmZBWwd86YpyFnpdp/xVRXEgoY8fv/fNbJzZ7EBMX8Wryo:PTnpyNpH/xVyfY8fv/fX97EYv"
- * Process Execution:
- "rat_0f03ef58fe48b28a6f135ba994f584a2.exe",
- "services.exe",
- "kikeew.exe"
- * Executed Commands:
- "> nul",
- "C:\\Windows\\kikeew.exe"
- * Signatures Detected:
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: rat_0f03ef58fe48b28a6f135ba994f584a2.exe, pid: 1964, offset: 0x00034765, length: 0x00000400"
- "self_read": "process: kikeew.exe, pid: 2504, offset: 0x00034765, length: 0x00000400"
- "Description": "Drops a binary and executes it",
- "Details":
- "binary": "C:\\Windows\\kikeew.exe"
- "Description": "Sniffs keystrokes",
- "Details":
- "GetAsyncKeyState": "Process: kikeew.exe(2504)"
- "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
- "Details":
- "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 18214987 times"
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "service name": "Ghijkl Nopqrstu Wxy"
- "service path": "C:\\Windows\\kikeew.exe"
- "Description": "File has been identified by 63 Antiviruses on VirusTotal as malicious",
- "Details":
- "MicroWorld-eScan": "Backdoor.Zegost.BC"
- "CAT-QuickHeal": "Trojan.Aksula.A"
- "McAfee": "BackDoor-FCGT!0F03EF58FE48"
- "Cylance": "Unsafe"
- "VIPRE": "Win32.Malware!Drop"
- "SUPERAntiSpyware": "Trojan.Agent/Gen-Siggen"
- "Alibaba": "Backdoor:Win32/Farfli.a84ff1cd"
- "K7GW": "Trojan ( 0040f7ad1 )"
- "K7AntiVirus": "Trojan ( 0040f7ad1 )"
- "TrendMicro": "BKDR_ZEGOST.SML"
- "Baidu": "Win32.Trojan.Farfli.bg"
- "F-Prot": "W32/S-3d9bc1fd!Eldorado"
- "Symantec": "Backdoor.Trojan"
- "APEX": "Malicious"
- "Avast": "Win32:Farfli-CF Cryp"
- "ClamAV": "Win.Trojan.Zegost-7007928-0"
- "Kaspersky": "Backdoor.Win32.Farfli.alus"
- "BitDefender": "Backdoor.Zegost.BC"
- "NANO-Antivirus": "Trojan.Win32.TrjGen.csulmd"
- "Paloalto": "generic.ml"
- "ViRobot": "Trojan.Win32.Agent.215901"
- "Tencent": "Win32.Backdoor.Farfli.Frv"
- "Endgame": "malicious (high confidence)"
- "Emsisoft": "Backdoor.Zegost.BC (B)"
- "Comodo": "TrojWare.Win32.Kryptik.BPVQ@56xtf6"
- "DrWeb": "Trojan.Siggen6.27861"
- "Zillya": "Trojan.Kryptik.Win32.737668"
- "Invincea": "heuristic"
- "McAfee-GW-Edition": "BehavesLike.Win32.Generic.dh"
- "Trapmine": "malicious.high.ml.score"
- "FireEye": "Generic.mg.0f03ef58fe48b28a"
- "Sophos": "Troj/Zegost-CV"
- "SentinelOne": "DFI - Malicious PE"
- "Cyren": "W32/S-3d9bc1fd!Eldorado"
- "Jiangmin": "Trojan/Generic.avrta"
- "Webroot": "W32.Trojan.Gen"
- "Avira": "BDS/Zegost.mdqcz"
- "Microsoft": "Backdoor:Win32/Zegost.AD"
- "AegisLab": "Trojan.Win32.Kykymber.lUlR"
- "ZoneAlarm": "Backdoor.Win32.Farfli.alus"
- "GData": "Backdoor.Zegost.BC"
- "TACHYON": "Backdoor/W32.Farfli.215909"
- "AhnLab-V3": "Trojan/Win32.Scar.R65072"
- "Acronis": "suspicious"
- "VBA32": "BScope.Backdoor.Spy"
- "ALYac": "Backdoor.Zegost.BC"
- "MAX": "malware (ai score=81)"
- "Ad-Aware": "Backdoor.Zegost.BC"
- "Malwarebytes": "Backdoor.Staser"
- "Zoner": "Trojan.Win32.29512"
- "ESET-NOD32": "Win32/Farfli.ARD"
- "TrendMicro-HouseCall": "BKDR_ZEGOST.SML"
- "Rising": "Backdoor.Farfli!1.B6C5 (CLASSIC)"
- "Yandex": "Trojan.Kryptik!BskX9BEG55w"
- "Ikarus": "Backdoor.Win32.Zegost"
- "eGambit": "Trojan.Generic"
- "Fortinet": "W32/Farfli.PZA!tr"
- "MaxSecure": "Win.MxResIcn.Heur.Gen"
- "AVG": "Win32:Farfli-CF Cryp"
- "Cybereason": "malicious.8fe48b"
- "Panda": "Generic Malware"
- "CrowdStrike": "win/malicious_confidence_100% (W)"
- "Qihoo-360": "HEUR/QVM07.1.D15F.Malware.Gen"
- "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
- "Details":
- "target": "clamav:Win.Trojan.Zegost-7007928-0, sha256:2fcc9c48d5d8a5c6889ca3302fcaa9f6296a9e36b167526033a0371172ab1693, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Zegost-7007928-0, sha256:2fcc9c48d5d8a5c6889ca3302fcaa9f6296a9e36b167526033a0371172ab1693 , guest_paths:C:\\Windows\\kikeew.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "Description": "Creates a copy of itself",
- "Details":
- "copy": "C:\\Windows\\kikeew.exe"
- "Description": "Anomalous binary characteristics",
- "Details":
- "anomaly": "Entrypoint of binary points to a non-executable code section"
- "anomaly": "Actual checksum does not match that reported in PE header"
- "Description": "Created network traffic indicative of malicious activity",
- "Details":
- "signature": "ET TROJAN Backdoor family PCRat/Gh0st CnC traffic (OUTBOUND) 10"
- * Started Service:
- "Ghijkl Nopqrstu Wxy"
- * Mutexes:
- "C:\\Users\\user\\AppData\\Local\\Temp\\rat_0f03ef58fe48b28a6f135ba994f584a2.exe",
- "C:\\Windows\\kikeew.exe",
- "haohai.ddns.net:8082"
- * Modified Files:
- "C:\\Windows\\kikeew.exe"
- * Deleted Files:
- * Modified Registry Keys:
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Ghijkl Nopqrstu Wxy\\Description",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MediaResources\\msvideo"
- * Deleted Registry Keys:
- * DNS Communications:
- "type": "A",
- "request": "haohai.ddns.net",
- "answers":
- "data": "122.114.192.241",
- "type": "A"
- * Domains:
- "ip": "122.114.192.241",
- "domain": "haohai.ddns.net"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment