Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Neshta"
- * MalScore: 10.0
- * File Name: "Exes_fb306999fe3ac001f407c88ff7728f2a.msi"
- * File Size: 380928
- * File Type: "Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Code page: 1252, Last Printed: Fri Sep 21 09:56:09 2012, Create Time/Date: Fri Sep 21 09:56:09 2012, Name of Creating Application: Windows Installer, Title: Exe to msi converter free, Author: www.exetomsi.com, Template: ;0, Last Saved By: devuser, Revision Number: C35CF0AA-9B3F-4903-9F05-EBF606D58D3E Last Saved Time/Date: Tue May 21 11:56:44 2013, Number of Pages: 100, Number of Words: 0, Security: 0"
- * SHA256: "ebe3531e0069e1314899a45595ad01de38612d80113ab81f6e569ba273c26f7d"
- * MD5: "fb306999fe3ac001f407c88ff7728f2a"
- * SHA1: "61f01e7a6d053287c5ac06f88e9c1690a36c737e"
- * SHA512: "001b529ba0b94a339673bfded58074b19805c026108bc3dd310805ea41fb84fe019cd87aa455ffeca363772d205506167bdb6c93674423fa40bb4aff12756d2c"
- * CRC32: "12627C4C"
- * SSDEEP: "6144:BER9g4SlvT7Vh3zhJt52MsNOEtrpmRnP0pOs/IJjs+Q3axzTnVU2Ur71Pds98:BE84Stv3zh9dIgRnVGZ4ULPd08"
- * Process Execution:
- "msiexec.exe"
- * Executed Commands:
- * Signatures Detected:
- "Description": "File has been identified by 35 Antiviruses on VirusTotal as malicious",
- "Details":
- "FireEye": "Win32.Neshta.A"
- "CAT-QuickHeal": "W32.Neshta.C8"
- "McAfee": "W32/HLLP.41472.e"
- "VIPRE": "Virus.Win32.Neshta.a (v)"
- "Arcabit": "Win32.Neshta.A"
- "TrendMicro": "PE_NESHTA.A"
- "Baidu": "Win32.Virus.Neshta.a"
- "TotalDefense": "Win32/Neshta.A"
- "TrendMicro-HouseCall": "PE_NESHTA.A"
- "Avast": "Win32:Apanas Trj"
- "ClamAV": "Win.Trojan.Neshuta-1"
- "Kaspersky": "Virus.Win32.Neshta.a"
- "BitDefender": "Win32.Neshta.A"
- "NANO-Antivirus": "Trojan.Win32.Winlock.fmobyw"
- "Rising": "PUF.Patcher!1.B3BB (RDM+:cmRtazqeuDdQIxSGhBYOeRVFPiVt)"
- "Emsisoft": "Win32.Neshta.A (B)"
- "Comodo": "Win32.Neshta.A@3ypg"
- "DrWeb": "Win32.HLLP.Neshta"
- "Zillya": "Virus.Neshta.Win32.1"
- "Invincea": "heuristic"
- "McAfee-GW-Edition": "W32/HLLP.41472.e"
- "Sophos": "W32/Bloat-A"
- "Cyren": "W32/Trojan.OBIX-2981"
- "Antiy-AVL": "Virus/Win32.Neshta.a"
- "Kingsoft": "VIRUS_UNKNOWN"
- "Microsoft": "Virus:Win32/Neshta.A"
- "ZoneAlarm": "Virus.Win32.Neshta.a"
- "GData": "Win32.Neshta.A"
- "TACHYON": "Virus/W32.Neshta"
- "AhnLab-V3": "Win32/Neshta"
- "MAX": "malware (ai score=89)"
- "VBA32": "Virus.Win32.Neshta.a"
- "ESET-NOD32": "Win32/Neshta.A"
- "Ikarus": "Virus.Win32.Neshta"
- "AVG": "Win32:Apanas Trj"
- "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
- "Details":
- "target": "clamav:Win.Trojan.Neshuta-1, sha256:ebe3531e0069e1314899a45595ad01de38612d80113ab81f6e569ba273c26f7d, type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Code page: 1252, Last Printed: Fri Sep 21 09:56:09 2012, Create Time/Date: Fri Sep 21 09:56:09 2012, Name of Creating Application: Windows Installer, Title: Exe to msi converter free, Author: www.exetomsi.com, Template: ;0, Last Saved By: devuser, Revision Number: C35CF0AA-9B3F-4903-9F05-EBF606D58D3E Last Saved Time/Date: Tue May 21 11:56:44 2013, Number of Pages: 100, Number of Words: 0, Security: 0"
- * Started Service:
- * Mutexes:
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1",
- "Global\\_MSIExecute"
- * Modified Files:
- * Deleted Files:
- * Modified Registry Keys:
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Add Comment
Please, Sign In to add comment