paladin316

video-Neymar-y-Narjila_vbs_2019-07-10_20_30.txt

Jul 10th, 2019
2,089
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 10.46 KB | None | 0 0
  1.  
  2. * MalFamily: "Presenoker"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "video-Neymar-y-Narjila.vbs"
  7. * File Size: 165119
  8. * File Type: "UTF-8 Unicode text, with CRLF line terminators"
  9. * SHA256: "b543226d719a70704008fc2c582904b5659ec1fe75ef70159355c1a97ca5d3bc"
  10. * MD5: "814967a5d358316e8e2d4952b90ad9e8"
  11. * SHA1: "c191d5259dcd808a3c5fae34adcf61ceaf78d6c5"
  12. * SHA512: "da49eb0cc04ded8abfebb2c3315de1fcb32b50ed4ee9f069f52d3e41c57b3ace0cb91d94a56afd61b8848d2127ad64d8a9009a9a68998262500b4030683629a8"
  13. * CRC32: "69C07706"
  14. * SSDEEP: "3072:K1ynTL8TlzEHbTlzEHeVbuV84rLxMrIV9xM3uOz4jr9c4GqlVb:GTOHbTOHeVbuV84r2rCr9c4GqlVb"
  15.  
  16. * Process Execution:
  17. "wscript.exe",
  18. "wscript.exe",
  19. "services.exe",
  20. "svchost.exe",
  21. "WmiPrvSE.exe",
  22. "WmiPrvSE.exe",
  23. "svchost.exe",
  24. "taskhost.exe"
  25.  
  26.  
  27. * Executed Commands:
  28. "wscript.exe C:\\Users\\user\\AppData\\Roaming\\gpoxlqsogen.vbs",
  29. "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding",
  30. "C:\\Windows\\system32\\svchost.exe -k netsvcs"
  31.  
  32.  
  33. * Signatures Detected:
  34.  
  35. "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
  36. "Details":
  37.  
  38. "IP": "18.188.78.96:80"
  39.  
  40.  
  41.  
  42.  
  43. "Description": "Detected script timer window indicative of sleep style evasion",
  44. "Details":
  45.  
  46. "Window": "WSH-Timer"
  47.  
  48.  
  49.  
  50.  
  51. "Description": "A process attempted to delay the analysis task.",
  52. "Details":
  53.  
  54. "Process": "WmiPrvSE.exe tried to sleep 660 seconds, actually delayed analysis time by 0 seconds"
  55.  
  56.  
  57.  
  58.  
  59. "Description": "Reads data out of its own binary image",
  60. "Details":
  61.  
  62. "self_read": "process: wscript.exe, pid: 2680, offset: 0x00000000, length: 0x00000040"
  63.  
  64.  
  65. "self_read": "process: wscript.exe, pid: 2680, offset: 0x000000f0, length: 0x00000018"
  66.  
  67.  
  68. "self_read": "process: wscript.exe, pid: 2680, offset: 0x000001e8, length: 0x00000078"
  69.  
  70.  
  71. "self_read": "process: wscript.exe, pid: 2680, offset: 0x00018000, length: 0x00000020"
  72.  
  73.  
  74. "self_read": "process: wscript.exe, pid: 2680, offset: 0x00018058, length: 0x00000018"
  75.  
  76.  
  77. "self_read": "process: wscript.exe, pid: 2680, offset: 0x000181a8, length: 0x00000018"
  78.  
  79.  
  80. "self_read": "process: wscript.exe, pid: 2680, offset: 0x00018470, length: 0x00000010"
  81.  
  82.  
  83. "self_read": "process: wscript.exe, pid: 2680, offset: 0x00018640, length: 0x00000012"
  84.  
  85.  
  86.  
  87.  
  88. "Description": "File has been identified by 6 Antiviruses on VirusTotal as malicious",
  89. "Details":
  90.  
  91. "Kaspersky": "HEUR:Trojan-Downloader.Script.Generic"
  92.  
  93.  
  94. "NANO-Antivirus": "Trojan.Script.MLW.ebogyu"
  95.  
  96.  
  97. "DrWeb": "Trojan.DownLoader28.41788"
  98.  
  99.  
  100. "Microsoft": "PUA:Win32/Presenoker"
  101.  
  102.  
  103. "ZoneAlarm": "HEUR:Trojan-Downloader.Script.Generic"
  104.  
  105.  
  106. "Qihoo-360": "virus.vbs.dropper.d"
  107.  
  108.  
  109.  
  110.  
  111. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  112. "Details":
  113.  
  114. "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
  115.  
  116.  
  117. "suspicious_request": "http://18.188.78.96/THEY/logs.zip"
  118.  
  119.  
  120. "suspicious_request": "http://18.188.78.96/THEY/they7.jpg"
  121.  
  122.  
  123.  
  124.  
  125. "Description": "Performs some HTTP requests",
  126. "Details":
  127.  
  128. "url": "http://18.188.78.96/THEY/logs.zip"
  129.  
  130.  
  131. "url": "http://18.188.78.96/THEY/they7.jpg"
  132.  
  133.  
  134.  
  135.  
  136. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  137. "Details":
  138.  
  139. "Spam": "services.exe (504) called API GetSystemTimeAsFileTime 9004127 times"
  140.  
  141.  
  142.  
  143.  
  144. "Description": "Installs itself for autorun at Windows startup",
  145. "Details":
  146.  
  147. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\gpoxlqsogen.lnk"
  148.  
  149.  
  150.  
  151.  
  152. "Description": "A wscript.exe process commonly used in script or document file downloaders initiated network activity",
  153. "Details":
  154.  
  155. "http_request": "wscript.exe_InternetCrackUrlW_http://18.188.78.96/they/logs.zip"
  156.  
  157.  
  158. "http_request_path": "wscript.exe_HttpOpenRequestW_/they/logs.zip"
  159.  
  160.  
  161. "http_request": "wscript.exe_InternetCrackUrlA_http://18.188.78.96"
  162.  
  163.  
  164. "http_request": "wscript.exe_InternetCrackUrlA_http://18.188.78.96/they/logs.zip"
  165.  
  166.  
  167. "http_request": "wscript.exe_InternetCrackUrlW_http://18.188.78.96/they/they7.jpg"
  168.  
  169.  
  170. "http_request_path": "wscript.exe_HttpOpenRequestW_/they/they7.jpg"
  171.  
  172.  
  173. "http_request": "wscript.exe_InternetCrackUrlA_http://18.188.78.96"
  174.  
  175.  
  176. "http_request": "wscript.exe_InternetCrackUrlA_http://18.188.78.96/they/they7.jpg"
  177.  
  178.  
  179.  
  180.  
  181. "Description": "Retrieves Windows ProductID, probably to fingerprint the sandbox",
  182. "Details":
  183.  
  184.  
  185. "Description": "Collects information to fingerprint the system",
  186. "Details":
  187.  
  188.  
  189. "Description": "Created network traffic indicative of malicious activity",
  190. "Details":
  191.  
  192. "signature": "ET TROJAN Windows Executable Downloaded With Image Content-Type Header"
  193.  
  194.  
  195.  
  196.  
  197.  
  198. * Started Service:
  199. "Winmgmt"
  200.  
  201.  
  202. * Mutexes:
  203. "Local\\ZonesCounterMutex",
  204. "Local\\ZoneAttributeCacheCounterMutex",
  205. "Local\\ZonesCacheCounterMutex",
  206. "Local\\ZonesLockedCacheCounterMutex"
  207.  
  208.  
  209. * Modified Files:
  210. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\logs1.zip",
  211. "C:\\Users\\user\\AppData\\Roaming\\54101536691188\\logs.zip",
  212. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\they71.jpg",
  213. "C:\\Users\\user\\AppData\\Roaming\\54101536691188\\qxajwtdijgzawllsy4733556628226.exe",
  214. "C:\\Users\\user\\AppData\\Roaming\\gpoxlqsogen.vbs",
  215. "\\??\\WMIDataDevice",
  216. "\\??\\PIPE\\samr",
  217. "C:\\Windows\\sysnative\\wbem\\repository\\WRITABLE.TST",
  218. "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING1.MAP",
  219. "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING2.MAP",
  220. "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING3.MAP",
  221. "C:\\Windows\\sysnative\\wbem\\repository\\OBJECTS.DATA",
  222. "C:\\Windows\\sysnative\\wbem\\repository\\INDEX.BTR",
  223. "C:\\Windows\\sysnative\\LogFiles\\Scm\\5869f1c1-01d7-41f7-84b7-715672259fa8",
  224. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
  225. "\\??\\PIPE\\wkssvc",
  226. "\\??\\PIPE\\srvsvc",
  227. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\gpoxlqsogen.lnk"
  228.  
  229.  
  230. * Deleted Files:
  231.  
  232. * Modified Registry Keys:
  233. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
  234. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
  235. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Parameters\\ServiceDllUnloadOnStop",
  236. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
  237. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Wbem\\Transports\\Decoupled\\Server",
  238. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\CreationTime",
  239. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\MarshaledProxy",
  240. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\ProcessIdentifier"
  241.  
  242.  
  243. * Deleted Registry Keys:
  244. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  245. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  246. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  247. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName"
  248.  
  249.  
  250. * DNS Communications:
  251.  
  252. * Domains:
  253.  
  254. * Network Communication - ICMP:
  255.  
  256. * Network Communication - HTTP:
  257.  
  258. "count": 1,
  259. "body": "",
  260. "uri": "http://18.188.78.96/THEY/logs.zip",
  261. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  262. "method": "GET",
  263. "host": "18.188.78.96",
  264. "version": "1.1",
  265. "path": "/THEY/logs.zip",
  266. "data": "GET /THEY/logs.zip HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: 18.188.78.96\r\nConnection: Keep-Alive\r\n\r\n",
  267. "port": 80
  268.  
  269.  
  270. "count": 1,
  271. "body": "",
  272. "uri": "http://18.188.78.96/THEY/they7.jpg",
  273. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  274. "method": "GET",
  275. "host": "18.188.78.96",
  276. "version": "1.1",
  277. "path": "/THEY/they7.jpg",
  278. "data": "GET /THEY/they7.jpg HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: 18.188.78.96\r\nConnection: Keep-Alive\r\n\r\n",
  279. "port": 80
  280.  
  281.  
  282.  
  283. * Network Communication - SMTP:
  284.  
  285. * Network Communication - Hosts:
  286.  
  287. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment