paladin316

Exes_2bccea30500832b59659771d9b4d20cd_exe_2019-07-10_04_30.txt

Jul 10th, 2019
2,102
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 15.18 KB | None | 0 0
  1.  
  2. * MalFamily: "Magania"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_2bccea30500832b59659771d9b4d20cd.exe"
  7. * File Size: 184320
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "7374f11f103aa3cb3951f2227c7a8f34cc35dff2d28bf09fea6b1697e465549c"
  10. * MD5: "2bccea30500832b59659771d9b4d20cd"
  11. * SHA1: "36f541c648e84b5d874453bd57a762f1b2e71921"
  12. * SHA512: "f08047ee8e8ed8503550e876d922c4a46f0bb4f03bae230035db7092774cc2311b8d31de3d23a50e72012a588011876e10dcd1cc4b5c60009d976c4e7826d91a"
  13. * CRC32: "731728B1"
  14. * SSDEEP: "3072:VmtqxrrQEjmD2e8eo8imNNMiePZ3EiN8Xx5:vrr3Kl838jNMjZ3/NC"
  15.  
  16. * Process Execution:
  17. "Exes_2bccea30500832b59659771d9b4d20cd.exe",
  18. "cmd.exe",
  19. "services.exe",
  20. "seser.exe",
  21. "seser.exe",
  22. "svchost.exe",
  23. "WerFault.exe",
  24. "wermgr.exe",
  25. "taskhost.exe",
  26. "sc.exe",
  27. "svchost.exe",
  28. "svchost.exe",
  29. "WerFault.exe",
  30. "wermgr.exe"
  31.  
  32.  
  33. * Executed Commands:
  34. "\"C:\\Windows\\system32\\cmd.exe\" /c del C:\\Users\\user\\AppData\\Local\\Temp\\EXES_2~1.EXE > nul",
  35. "C:\\Windows\\System32\\cmd.exe /c del C:\\Users\\user\\AppData\\Local\\Temp\\EXES_2~1.EXE > nul",
  36. "C:\\Windows\\SysWOW64\\seser.exe",
  37. "C:\\Windows\\System32\\svchost.exe -k WerSvcGroup",
  38. "taskhost.exe $(Arg0)",
  39. "C:\\Windows\\system32\\sc.exe start w32time task_started",
  40. "C:\\Windows\\system32\\svchost.exe -k LocalService",
  41. "C:\\Windows\\SysWOW64\\seser.exe Win7",
  42. "C:\\Windows\\SysWOW64\\WerFault.exe -u -p 1872 -s 284",
  43. "\"C:\\Windows\\system32\\wermgr.exe\" \"-queuereporting_svc\" \"C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_seser.exe_b1333647735eb792c6a4288ac11e5ade9ad3ad8b_cab_0a6d3e78\"",
  44. "C:\\Windows\\system32\\WerFault.exe -u -p 2764 -s 288",
  45. "\"C:\\Windows\\system32\\wermgr.exe\" \"-queuereporting_svc\" \"C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_2dbb10b0434916a94ada024f596d41284498e1b_cab_0672e53b\""
  46.  
  47.  
  48. * Signatures Detected:
  49.  
  50. "Description": "At least one process apparently crashed during execution",
  51. "Details":
  52.  
  53.  
  54. "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
  55. "Details":
  56.  
  57. "IP": "61.216.5.103:5208"
  58.  
  59.  
  60.  
  61.  
  62. "Description": "A process created a hidden window",
  63. "Details":
  64.  
  65. "Process": "Exes_2bccea30500832b59659771d9b4d20cd.exe -> C:\\Windows\\System32\\cmd.exe"
  66.  
  67.  
  68.  
  69.  
  70. "Description": "Deletes its original binary from disk",
  71. "Details":
  72.  
  73.  
  74. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  75. "Details":
  76.  
  77. "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 10641416 times"
  78.  
  79.  
  80.  
  81.  
  82. "Description": "Installs itself for autorun at Windows startup",
  83. "Details":
  84.  
  85. "service name": "dazsks gmeakjwxo"
  86.  
  87.  
  88. "service path": "C:\\Windows\\system32\\seser.exe"
  89.  
  90.  
  91.  
  92.  
  93. "Description": "Creates a hidden or system file",
  94. "Details":
  95.  
  96. "file": "C:\\Windows\\System32\\seser.exe"
  97.  
  98.  
  99.  
  100.  
  101. "Description": "File has been identified by 59 Antiviruses on VirusTotal as malicious",
  102. "Details":
  103.  
  104. "Bkav": "W32.PortigasLTG.Trojan"
  105.  
  106.  
  107. "MicroWorld-eScan": "DeepScan:Generic.Mulinex.C26EE70D"
  108.  
  109.  
  110. "CAT-QuickHeal": "Trojan.Zenshirsh.SL7"
  111.  
  112.  
  113. "McAfee": "GenericRXGB-BC!2BCCEA305008"
  114.  
  115.  
  116. "Cylance": "Unsafe"
  117.  
  118.  
  119. "SUPERAntiSpyware": "Worm.Magania/Variant"
  120.  
  121.  
  122. "CrowdStrike": "win/malicious_confidence_100% (W)"
  123.  
  124.  
  125. "Alibaba": "TrojanGameThief:Win32/Magania.b5a89ca4"
  126.  
  127.  
  128. "K7GW": "Trojan ( 005104ad1 )"
  129.  
  130.  
  131. "K7AntiVirus": "Trojan ( 005104ad1 )"
  132.  
  133.  
  134. "TrendMicro": "BKDR_ZEGOST.SM45"
  135.  
  136.  
  137. "NANO-Antivirus": "Trojan.Win32.Magania.emsaow"
  138.  
  139.  
  140. "Cyren": "W32/Symmi.CI.gen!Eldorado"
  141.  
  142.  
  143. "Symantec": "Trojan.Gen.MBT"
  144.  
  145.  
  146. "APEX": "Malicious"
  147.  
  148.  
  149. "Avast": "Win32:Malware-gen"
  150.  
  151.  
  152. "Kaspersky": "Trojan-GameThief.Win32.Magania.uglq"
  153.  
  154.  
  155. "BitDefender": "DeepScan:Generic.Mulinex.C26EE70D"
  156.  
  157.  
  158. "Paloalto": "generic.ml"
  159.  
  160.  
  161. "Rising": "Trojan.Farfli!8.FF (CLOUD)"
  162.  
  163.  
  164. "Ad-Aware": "DeepScan:Generic.Mulinex.C26EE70D"
  165.  
  166.  
  167. "Emsisoft": "DeepScan:Generic.Mulinex.C26EE70D (B)"
  168.  
  169.  
  170. "Comodo": "Backdoor.Win32.Farfli.CJT@7jjkro"
  171.  
  172.  
  173. "F-Secure": "Backdoor.BDS/Nanocore.EV"
  174.  
  175.  
  176. "DrWeb": "BackDoor.IRC.Sdbot.34272"
  177.  
  178.  
  179. "Zillya": "Trojan.Magania.Win32.69650"
  180.  
  181.  
  182. "Invincea": "heuristic"
  183.  
  184.  
  185. "McAfee-GW-Edition": "BehavesLike.Win32.Generic.ch"
  186.  
  187.  
  188. "Trapmine": "malicious.high.ml.score"
  189.  
  190.  
  191. "FireEye": "Generic.mg.2bccea30500832b5"
  192.  
  193.  
  194. "Sophos": "Mal/Generic-S"
  195.  
  196.  
  197. "SentinelOne": "DFI - Malicious PE"
  198.  
  199.  
  200. "F-Prot": "W32/Symmi.CI.gen!Eldorado"
  201.  
  202.  
  203. "Jiangmin": "Trojan.PSW.Magania.wy"
  204.  
  205.  
  206. "Avira": "BDS/Nanocore.EV"
  207.  
  208.  
  209. "MAX": "malware (ai score=100)"
  210.  
  211.  
  212. "Antiy-AVL": "Trojan/Win32.TSGeneric"
  213.  
  214.  
  215. "Microsoft": "VirTool:Win32/CeeInject.TD!bit"
  216.  
  217.  
  218. "Endgame": "malicious (high confidence)"
  219.  
  220.  
  221. "AegisLab": "Trojan.Win32.Magania.tpHK"
  222.  
  223.  
  224. "ZoneAlarm": "Trojan-GameThief.Win32.Magania.uglq"
  225.  
  226.  
  227. "GData": "DeepScan:Generic.Mulinex.C26EE70D"
  228.  
  229.  
  230. "AhnLab-V3": "Trojan/Win32.Zegost.R197417"
  231.  
  232.  
  233. "Acronis": "suspicious"
  234.  
  235.  
  236. "ALYac": "DeepScan:Generic.Mulinex.C26EE70D"
  237.  
  238.  
  239. "TACHYON": "Trojan-PWS/W32.WebGame.184320.BP"
  240.  
  241.  
  242. "VBA32": "TrojanPSW.Magania"
  243.  
  244.  
  245. "Malwarebytes": "Worm.Magania"
  246.  
  247.  
  248. "Zoner": "Trojan.Win32.71187"
  249.  
  250.  
  251. "ESET-NOD32": "Win32/Farfli.CJT"
  252.  
  253.  
  254. "TrendMicro-HouseCall": "BKDR_ZEGOST.SM45"
  255.  
  256.  
  257. "Tencent": "Win32.Trojan-gamethief.Magania.Huqe"
  258.  
  259.  
  260. "Yandex": "Trojan.PWS.Magania!4BEanhoHOwI"
  261.  
  262.  
  263. "Ikarus": "Trojan.Farfli"
  264.  
  265.  
  266. "Fortinet": "W32/Generic.AC.3e785e"
  267.  
  268.  
  269. "AVG": "Win32:Malware-gen"
  270.  
  271.  
  272. "Cybereason": "malicious.050083"
  273.  
  274.  
  275. "Panda": "Trj/Genetic.gen"
  276.  
  277.  
  278. "Qihoo-360": "HEUR/QVM07.1.DA0D.Malware.Gen"
  279.  
  280.  
  281.  
  282.  
  283. "Description": "Checks the system manufacturer, likely for anti-virtualization",
  284. "Details":
  285.  
  286.  
  287. "Description": "Creates a copy of itself",
  288. "Details":
  289.  
  290. "copy": "C:\\Windows\\System32\\seser.exe"
  291.  
  292.  
  293.  
  294.  
  295.  
  296. * Started Service:
  297. "dazsks gmeakjwxo",
  298. "WerSvc",
  299. "W32Time"
  300.  
  301.  
  302. * Mutexes:
  303. "Local\\ZoneAttributeCacheCounterMutex",
  304. "Local\\ZonesCacheCounterMutex",
  305. "Local\\ZonesLockedCacheCounterMutex",
  306. "Local\\WERReportingForProcess1872",
  307. "Global\\41dd3071-a2c6-11e9-b470-18c086cd4732",
  308. "Global\\\\xed\\xa6\\xb0<",
  309. "WERUI_APPCRASH-b1333647735eb792c6a4288ac11e5ade9ad3ad8b",
  310. "Local\\WERReportingForProcess2764",
  311. "Global\\\\xe5\\x88\\x90\\xc2\\x9c",
  312. "Global\\\\xed\\x95\\xb0\\xc7\\x8a",
  313. "WERUI_BEX64-2dbb10b0434916a94ada024f596d41284498e1b"
  314.  
  315.  
  316. * Modified Files:
  317. "C:\\Windows\\System32\\seser.exe",
  318. "C:\\Windows\\sysnative\\LogFiles\\Scm\\4963ad21-c4a5-42a5-b9bd-e441d57204fe",
  319. "C:\\Windows\\sysnative\\LogFiles\\Scm\\7bbc503c-5977-4798-a4ae-61483a7e030d",
  320. "C:\\Windows\\sysnative\\LogFiles\\Scm\\3e5e9de5-f457-411f-9101-d0c0143505ee",
  321. "\\??\\nul",
  322. "C:\\Windows\\Temp\\WERB3EB.tmp.appcompat.txt",
  323. "C:\\Windows\\Temp\\WERB42A.tmp.WERInternalMetadata.xml",
  324. "C:\\Windows\\Temp\\WERB45A.tmp.hdmp",
  325. "C:\\Windows\\Temp\\WERB93D.tmp.mdmp",
  326. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_seser.exe_b1333647735eb792c6a4288ac11e5ade9ad3ad8b_cab_0a6d3e78\\WERB3EB.tmp.appcompat.txt",
  327. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_seser.exe_b1333647735eb792c6a4288ac11e5ade9ad3ad8b_cab_0a6d3e78\\WERB42A.tmp.WERInternalMetadata.xml",
  328. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_seser.exe_b1333647735eb792c6a4288ac11e5ade9ad3ad8b_cab_0a6d3e78\\WERB45A.tmp.hdmp",
  329. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_seser.exe_b1333647735eb792c6a4288ac11e5ade9ad3ad8b_cab_0a6d3e78\\WERB93D.tmp.mdmp",
  330. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_seser.exe_b1333647735eb792c6a4288ac11e5ade9ad3ad8b_cab_0a6d3e78\\Report.wer",
  331. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_seser.exe_b1333647735eb792c6a4288ac11e5ade9ad3ad8b_cab_0a6d3e78\\Report.wer.tmp",
  332. "\\??\\PIPE\\lsarpc",
  333. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA105.tmp.appcompat.txt",
  334. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA56B.tmp.WERInternalMetadata.xml",
  335. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA59B.tmp.hdmp",
  336. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERAED3.tmp.mdmp",
  337. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_2dbb10b0434916a94ada024f596d41284498e1b_cab_0672e53b\\WERA105.tmp.appcompat.txt",
  338. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_2dbb10b0434916a94ada024f596d41284498e1b_cab_0672e53b\\WERA56B.tmp.WERInternalMetadata.xml",
  339. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_2dbb10b0434916a94ada024f596d41284498e1b_cab_0672e53b\\WERA59B.tmp.hdmp",
  340. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_2dbb10b0434916a94ada024f596d41284498e1b_cab_0672e53b\\WERAED3.tmp.mdmp",
  341. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_2dbb10b0434916a94ada024f596d41284498e1b_cab_0672e53b\\Report.wer",
  342. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_2dbb10b0434916a94ada024f596d41284498e1b_cab_0672e53b\\Report.wer.tmp"
  343.  
  344.  
  345. * Deleted Files:
  346. "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_2bccea30500832b59659771d9b4d20cd.exe",
  347. "C:\\Windows\\Temp\\WERB3EB.tmp",
  348. "C:\\Windows\\Temp\\WERB3EB.tmp.appcompat.txt",
  349. "C:\\Windows\\Temp\\WERB42A.tmp",
  350. "C:\\Windows\\Temp\\WERB42A.tmp.WERInternalMetadata.xml",
  351. "C:\\Windows\\Temp\\WERB45A.tmp",
  352. "C:\\Windows\\Temp\\WERB45A.tmp.hdmp",
  353. "C:\\Windows\\Temp\\WERB93D.tmp",
  354. "C:\\Windows\\Temp\\WERB93D.tmp.mdmp",
  355. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_seser.exe_b1333647735eb792c6a4288ac11e5ade9ad3ad8b_cab_0a6d3e78\\Report.wer.tmp",
  356. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA105.tmp",
  357. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA105.tmp.appcompat.txt",
  358. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA56B.tmp",
  359. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA56B.tmp.WERInternalMetadata.xml",
  360. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA59B.tmp",
  361. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA59B.tmp.hdmp",
  362. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERAED3.tmp",
  363. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERAED3.tmp.mdmp",
  364. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_2dbb10b0434916a94ada024f596d41284498e1b_cab_0672e53b\\Report.wer.tmp"
  365.  
  366.  
  367. * Modified Registry Keys:
  368. "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\dazsks gmeakjwxo",
  369. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dazsks gmeakjwxo\\MarkTime",
  370. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\dazsks gmeakjwxo\\Description",
  371. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
  372. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
  373. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
  374. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Type",
  375. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Debug",
  376. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\Windows Error Reporting\\Debug\\ExceptionRecord",
  377. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\TimeProviders\\NtpClient\\SpecialPollTimeRemaining",
  378. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent",
  379. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent\\DefaultConsent"
  380.  
  381.  
  382. * Deleted Registry Keys:
  383. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  384. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  385. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  386. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName"
  387.  
  388.  
  389. * DNS Communications:
  390.  
  391. "type": "A",
  392. "request": "dns.monerov8.com",
  393. "answers":
  394.  
  395. "data": "61.216.5.103",
  396. "type": "A"
  397.  
  398.  
  399.  
  400.  
  401.  
  402. * Domains:
  403.  
  404. "ip": "61.216.5.103",
  405. "domain": "dns.monerov8.com"
  406.  
  407.  
  408.  
  409. * Network Communication - ICMP:
  410.  
  411. * Network Communication - HTTP:
  412.  
  413. * Network Communication - SMTP:
  414.  
  415. * Network Communication - Hosts:
  416.  
  417. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment