paladin316

Loki_d620e741f4bf1d9345e4cf903f87da3f_exe_2019-07-10_07_30.txt

Jul 10th, 2019
2,104
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.34 KB | None | 0 0
  1.  
  2. * MalFamily: ""
  3.  
  4. * MalScore: 6.25
  5.  
  6. * File Name: "Loki_d620e741f4bf1d9345e4cf903f87da3f.exe"
  7. * File Size: 974848
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "ac466153bed04b06d59f8acb45de417e901d8ee427cfaf5d295df0e7a60a0d20"
  10. * MD5: "d620e741f4bf1d9345e4cf903f87da3f"
  11. * SHA1: "c85fa811a0b9f1d18b664ab31f3bedbc453edfca"
  12. * SHA512: "1deffbe772e9dc49f5b15b5a15e1c72f4ef44685b905f0e0a32c312239a5ec6c469d06cf45b05bfa76eab20807fe8c7b3a79b91427b35d80f6efe54019742aa4"
  13. * CRC32: "231647ED"
  14. * SSDEEP: "6144:stbMr0I20GPPjpPCx2fJLXt71wZnG35Chqx:stbNI20GPPjY8LnYnG35Rx"
  15.  
  16. * Process Execution:
  17. "Loki_d620e741f4bf1d9345e4cf903f87da3f.exe"
  18.  
  19.  
  20. * Executed Commands:
  21. "\\x01C:\\Users\\user\\AppData\\Local\\Temp\\Loki_d620e741f4bf1d9345e4cf903f87da3f.exe\""
  22.  
  23.  
  24. * Signatures Detected:
  25.  
  26. "Description": "Creates RWX memory",
  27. "Details":
  28.  
  29.  
  30. "Description": "File has been identified by 9 Antiviruses on VirusTotal as malicious",
  31. "Details":
  32.  
  33. "FireEye": "Generic.mg.d620e741f4bf1d93"
  34.  
  35.  
  36. "McAfee": "Fareit-FPH!D620E741F4BF"
  37.  
  38.  
  39. "Cylance": "Unsafe"
  40.  
  41.  
  42. "Invincea": "heuristic"
  43.  
  44.  
  45. "Symantec": "Packed.Generic.535"
  46.  
  47.  
  48. "APEX": "Malicious"
  49.  
  50.  
  51. "Endgame": "malicious (high confidence)"
  52.  
  53.  
  54. "Microsoft": "Trojan:Win32/Wacatac.B!ml"
  55.  
  56.  
  57. "CrowdStrike": "win/malicious_confidence_60% (D)"
  58.  
  59.  
  60.  
  61.  
  62. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  63. "Details":
  64.  
  65. "Spam": "Loki_d620e741f4bf1d9345e4cf903f87da3f.exe (1108) called API CreateProcessInternalW 43725 times"
  66.  
  67.  
  68.  
  69.  
  70.  
  71. * Started Service:
  72.  
  73. * Mutexes:
  74.  
  75. * Modified Files:
  76. "C:\\Users\\user\\AppData\\Local\\Temp\\~DF7E9335E386E10149.TMP"
  77.  
  78.  
  79. * Deleted Files:
  80.  
  81. * Modified Registry Keys:
  82.  
  83. * Deleted Registry Keys:
  84.  
  85. * DNS Communications:
  86.  
  87. * Domains:
  88.  
  89. * Network Communication - ICMP:
  90.  
  91. * Network Communication - HTTP:
  92.  
  93. * Network Communication - SMTP:
  94.  
  95. * Network Communication - Hosts:
  96.  
  97. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment