paladin316

Exes_c6fae80f288970135340263587f3d85c_exe_2019-06-28_12_30.json

Jun 28th, 2019
2,215
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 37.20 KB | None | 0 0
  1.  
  2. [*] MalFamily: "Nitol"
  3.  
  4. [*] MalScore: 10.0
  5.  
  6. [*] File Name: "Exes_c6fae80f288970135340263587f3d85c.exe"
  7. [*] File Size: 395264
  8. [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed"
  9. [*] SHA256: "3b7015f169faa32e9f6c21979b4dcd6552829195f26957da10c1daa3aea4c306"
  10. [*] MD5: "c6fae80f288970135340263587f3d85c"
  11. [*] SHA1: "46b54edd71020212df1e3d5a2315566a6b76e81d"
  12. [*] SHA512: "c3fb785667f7b74ebd1a19ead8a8ec1497f8899f41e88c521bc4ca0d0db56a9b75fedf83e98200d3bcb5e72d9dd6a6ff67e84f56792ceec6a5f196fd4eaa22c3"
  13. [*] CRC32: "ED67C1FA"
  14. [*] SSDEEP: "6144:YIAsb0CnhSYPwbfG6wYdY3Y40gdgdUddwdddd9N7vA+adTxJVvshod6ddYd/d5dy:YI7PhSYPwTGgAHL6rRX"
  15.  
  16. [*] Process Execution: [
  17. "Exes_c6fae80f288970135340263587f3d85c.exe",
  18. "services.exe",
  19. "pktpkw.exe",
  20. "hrlC00B.tmp",
  21. "sc.exe",
  22. "svchost.exe"
  23. ]
  24.  
  25. [*] Signatures Detected: [
  26. {
  27. "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
  28. "Details": [
  29. {
  30. "IP": "0.0.0.0:8081"
  31. }
  32. ]
  33. },
  34. {
  35. "Description": "Possible date expiration check, exits too soon after checking local time",
  36. "Details": [
  37. {
  38. "process": "Exes_c6fae80f288970135340263587f3d85c.exe, PID 2360"
  39. }
  40. ]
  41. },
  42. {
  43. "Description": "Reads data out of its own binary image",
  44. "Details": [
  45. {
  46. "self_read": "process: pktpkw.exe, pid: 2612, offset: 0x00000000, length: 0x00060800"
  47. }
  48. ]
  49. },
  50. {
  51. "Description": "Drops a binary and executes it",
  52. "Details": [
  53. {
  54. "binary": "C:\\Windows\\pktpkw.exe"
  55. }
  56. ]
  57. },
  58. {
  59. "Description": "Unconventionial language used in binary resources: Chinese (Simplified)",
  60. "Details": []
  61. },
  62. {
  63. "Description": "The executable is compressed using UPX",
  64. "Details": [
  65. {
  66. "section": "name: UPX0, entropy: 0.00, characteristics: IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00000000, virtual_size: 0x00066000"
  67. }
  68. ]
  69. },
  70. {
  71. "Description": "Deletes its original binary from disk",
  72. "Details": []
  73. },
  74. {
  75. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  76. "Details": [
  77. {
  78. "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 17788932 times"
  79. }
  80. ]
  81. },
  82. {
  83. "Description": "Installs itself for autorun at Windows startup",
  84. "Details": [
  85. {
  86. "service name": "Windows Help System Myss"
  87. },
  88. {
  89. "service path": "C:\\Windows\\pktpkw.exe"
  90. }
  91. ]
  92. },
  93. {
  94. "Description": "Creates a hidden or system file",
  95. "Details": [
  96. {
  97. "file": "C:\\MSOCache\\All Users\\{91150000-0011-0000-0000-0000000FF1CE}-C\\lpk.dll"
  98. },
  99. {
  100. "file": "C:\\Program Files\\BLAOracle\\VirtualBox Guest Additions\\lpk.dll"
  101. },
  102. {
  103. "file": "C:\\Program Files\\Common Files\\Microsoft Shared\\ink\\lpk.dll"
  104. },
  105. {
  106. "file": "C:\\Program Files\\Common Files\\Microsoft Shared\\MSInfo\\lpk.dll"
  107. },
  108. {
  109. "file": "C:\\Program Files\\Common Files\\Microsoft Shared\\OFFICE15\\lpk.dll"
  110. },
  111. {
  112. "file": "C:\\Program Files\\Common Files\\Microsoft Shared\\OfficeSoftwareProtectionPlatform\\lpk.dll"
  113. },
  114. {
  115. "file": "C:\\Program Files\\Common Files\\Microsoft Shared\\VSTO\\10.0\\lpk.dll"
  116. },
  117. {
  118. "file": "C:\\Program Files\\Internet Explorer\\lpk.dll"
  119. },
  120. {
  121. "file": "C:\\Program Files\\Java\\jre1.8.0_201\\bin\\lpk.dll"
  122. },
  123. {
  124. "file": "C:\\Program Files\\Microsoft Office\\Office15\\lpk.dll"
  125. },
  126. {
  127. "file": "C:\\Program Files\\Notepad++\\lpk.dll"
  128. },
  129. {
  130. "file": "C:\\Program Files\\Notepad++\\updater\\lpk.dll"
  131. },
  132. {
  133. "file": "C:\\Program Files\\Windows Defender\\lpk.dll"
  134. },
  135. {
  136. "file": "C:\\Program Files\\Windows Journal\\lpk.dll"
  137. },
  138. {
  139. "file": "C:\\Program Files\\Windows Mail\\lpk.dll"
  140. },
  141. {
  142. "file": "C:\\Program Files\\Windows NT\\Accessories\\lpk.dll"
  143. },
  144. {
  145. "file": "C:\\Program Files\\Windows Photo Viewer\\lpk.dll"
  146. },
  147. {
  148. "file": "C:\\Program Files\\Windows Sidebar\\lpk.dll"
  149. },
  150. {
  151. "file": "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\lpk.dll"
  152. },
  153. {
  154. "file": "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroCEF\\lpk.dll"
  155. },
  156. {
  157. "file": "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroLayoutRecognizer\\lpk.dll"
  158. },
  159. {
  160. "file": "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\Browser\\WCChromeExtn\\lpk.dll"
  161. },
  162. {
  163. "file": "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\plug_ins\\pi_brokers\\lpk.dll"
  164. }
  165. ]
  166. },
  167. {
  168. "Description": "File has been identified by 52 Antiviruses on VirusTotal as malicious",
  169. "Details": [
  170. {
  171. "MicroWorld-eScan": "Gen:Variant.Graftor.128746"
  172. },
  173. {
  174. "FireEye": "Generic.mg.c6fae80f28897013"
  175. },
  176. {
  177. "CAT-QuickHeal": "Trojan.MauvaiseRI.S5262113"
  178. },
  179. {
  180. "McAfee": "DoS-FBL!DE61DE242B55"
  181. },
  182. {
  183. "Alibaba": "Ransom:Win32/PornoBlocker.c740458d"
  184. },
  185. {
  186. "Arcabit": "Trojan.Graftor.D1F6EA"
  187. },
  188. {
  189. "Baidu": "Win32.Trojan.ServStart.ax"
  190. },
  191. {
  192. "Symantec": "Backdoor.Nitol"
  193. },
  194. {
  195. "TotalDefense": "Win32/PackedBaidu"
  196. },
  197. {
  198. "APEX": "Malicious"
  199. },
  200. {
  201. "ClamAV": "Win.Malware.Nitol-6802818-0"
  202. },
  203. {
  204. "Kaspersky": "Trojan-Ransom.Win32.PornoBlocker.ejtx"
  205. },
  206. {
  207. "BitDefender": "Gen:Variant.Graftor.128746"
  208. },
  209. {
  210. "NANO-Antivirus": "Trojan.Win32.MicroFake.cchebz"
  211. },
  212. {
  213. "Avast": "Win32:Dh-A [Heur]"
  214. },
  215. {
  216. "Tencent": "Trojan.Win32.Lapka.bw"
  217. },
  218. {
  219. "Ad-Aware": "Gen:Variant.Graftor.128746"
  220. },
  221. {
  222. "Emsisoft": "Gen:Variant.Graftor.128746 (B)"
  223. },
  224. {
  225. "Comodo": "TrojWare.Win32.Nitol.KA@6cq5hu"
  226. },
  227. {
  228. "F-Secure": "Trojan.TR/ATRAPS.hrva.12"
  229. },
  230. {
  231. "DrWeb": "Trojan.DownLoader18.16955"
  232. },
  233. {
  234. "Invincea": "heuristic"
  235. },
  236. {
  237. "McAfee-GW-Edition": "BehavesLike.Win32.AdwareEorezo.ft"
  238. },
  239. {
  240. "Trapmine": "malicious.high.ml.score"
  241. },
  242. {
  243. "Sophos": "Mal/Nitol-C"
  244. },
  245. {
  246. "Ikarus": "Trojan.Win32.Agent"
  247. },
  248. {
  249. "F-Prot": "W32/Heuristic-131!Eldorado"
  250. },
  251. {
  252. "Jiangmin": "Trojan.Generic.cpukn"
  253. },
  254. {
  255. "Avira": "TR/ATRAPS.hrva.12"
  256. },
  257. {
  258. "MAX": "malware (ai score=85)"
  259. },
  260. {
  261. "Antiy-AVL": "Trojan[Ransom]/Win32.PornoBlocker"
  262. },
  263. {
  264. "Microsoft": "DDoS:Win32/Nitol.P!bit"
  265. },
  266. {
  267. "Endgame": "malicious (moderate confidence)"
  268. },
  269. {
  270. "ZoneAlarm": "Trojan-Ransom.Win32.PornoBlocker.ejtx"
  271. },
  272. {
  273. "GData": "Win32.Trojan.Microfake.B"
  274. },
  275. {
  276. "Acronis": "suspicious"
  277. },
  278. {
  279. "VBA32": "BScope.Backdoor.Caphaw"
  280. },
  281. {
  282. "ALYac": "Gen:Variant.Graftor.128746"
  283. },
  284. {
  285. "Cylance": "Unsafe"
  286. },
  287. {
  288. "Zoner": "Trojan.Win32.75172"
  289. },
  290. {
  291. "ESET-NOD32": "a variant of Win32/Agent.RMM"
  292. },
  293. {
  294. "TrendMicro-HouseCall": "DDoS.Win32.NITOL.SMG"
  295. },
  296. {
  297. "Rising": "Ransom.PornoBlocker!8.24E (TFE:5:aRUGX3mUndE)"
  298. },
  299. {
  300. "Yandex": "Trojan.MicroFake!Nyu0d5RIIDk"
  301. },
  302. {
  303. "SentinelOne": "DFI - Malicious PE"
  304. },
  305. {
  306. "eGambit": "Unsafe.AI_Score_99%"
  307. },
  308. {
  309. "Fortinet": "W32/Agent.RMM!tr"
  310. },
  311. {
  312. "MaxSecure": "Trojan.Malware.9551591.susgen"
  313. },
  314. {
  315. "AVG": "Win32:Dh-A [Heur]"
  316. },
  317. {
  318. "Cybereason": "malicious.f28897"
  319. },
  320. {
  321. "CrowdStrike": "win/malicious_confidence_90% (D)"
  322. },
  323. {
  324. "Qihoo-360": "Win32/Trojan.48f"
  325. }
  326. ]
  327. },
  328. {
  329. "Description": "Detects VirtualBox through the presence of a file",
  330. "Details": [
  331. {
  332. "file": "C:\\Program Files\\BLAOracle\\VirtualBox Guest Additions\\lpk.dll"
  333. }
  334. ]
  335. },
  336. {
  337. "Description": "Creates a copy of itself",
  338. "Details": [
  339. {
  340. "copy": "C:\\Windows\\pktpkw.exe"
  341. }
  342. ]
  343. },
  344. {
  345. "Description": "Created network traffic indicative of malicious activity",
  346. "Details": [
  347. {
  348. "signature": "ET TROJAN Win32.Nitol.K Variant CnC"
  349. }
  350. ]
  351. }
  352. ]
  353.  
  354. [*] Started Service: [
  355. "Windows Help System Myss",
  356. "W32Time"
  357. ]
  358.  
  359. [*] Executed Commands: [
  360. "C:\\Windows\\pktpkw.exe",
  361. "C:\\Windows\\system32\\sc.exe start w32time task_started",
  362. "C:\\Windows\\system32\\svchost.exe -k LocalService"
  363. ]
  364.  
  365. [*] Mutexes: []
  366.  
  367. [*] Modified Files: [
  368. "C:\\Windows\\pktpkw.exe",
  369. "C:\\Users\\user\\AppData\\Local\\Temp\\1dc77c8",
  370. "C:\\Windows\\sysnative\\LogFiles\\Scm\\7bbc503c-5977-4798-a4ae-61483a7e030d",
  371. "C:\\Windows\\sysnative\\LogFiles\\Scm\\bd2386f6-c6ac-4dd3-9c38-058101171b1c",
  372. "C:\\Windows\\SysWOW64\\hra8.dll",
  373. "C:\\Windows\\SysWOW64\\hra864.dll",
  374. "C:\\RCXBFEB.tmp",
  375. "C:\\Windows\\System32\\hra8.dll",
  376. "C:\\MSOCache\\All Users\\{91150000-0011-0000-0000-0000000FF1CE}-C\\lpk.dll",
  377. "C:\\Program Files\\BLAOracle\\VirtualBox Guest Additions\\lpk.dll",
  378. "C:\\Program Files\\Common Files\\Microsoft Shared\\ink\\lpk.dll",
  379. "C:\\Program Files\\Common Files\\Microsoft Shared\\MSInfo\\lpk.dll",
  380. "C:\\Program Files\\Common Files\\Microsoft Shared\\OFFICE15\\lpk.dll",
  381. "C:\\Program Files\\Common Files\\Microsoft Shared\\OfficeSoftwareProtectionPlatform\\lpk.dll",
  382. "C:\\Program Files\\Common Files\\Microsoft Shared\\VSTO\\10.0\\lpk.dll",
  383. "C:\\Program Files\\Internet Explorer\\lpk.dll",
  384. "C:\\Program Files\\Java\\jre1.8.0_201\\bin\\lpk.dll",
  385. "C:\\Program Files\\Microsoft Office\\Office15\\lpk.dll",
  386. "C:\\Program Files\\Notepad++\\lpk.dll",
  387. "C:\\Program Files\\Notepad++\\updater\\lpk.dll",
  388. "C:\\Program Files\\Windows Defender\\lpk.dll",
  389. "C:\\Program Files\\Windows Journal\\lpk.dll",
  390. "C:\\Program Files\\Windows Mail\\lpk.dll",
  391. "C:\\Program Files\\Windows NT\\Accessories\\lpk.dll",
  392. "C:\\Program Files\\Windows Photo Viewer\\lpk.dll",
  393. "C:\\Program Files\\Windows Sidebar\\lpk.dll",
  394. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\lpk.dll",
  395. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroCEF\\lpk.dll",
  396. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroLayoutRecognizer\\lpk.dll",
  397. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\Browser\\WCChromeExtn\\lpk.dll",
  398. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\plug_ins\\pi_brokers\\lpk.dll",
  399. "\\??\\PIPE\\lsarpc"
  400. ]
  401.  
  402. [*] Deleted Files: [
  403. "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_c6fae80f288970135340263587f3d85c.exe",
  404. "C:\\Users\\user\\AppData\\Local\\Temp\\1dc77c8",
  405. "C:\\RCXBFEB.tmp"
  406. ]
  407.  
  408. [*] Modified Registry Keys: [
  409. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Windows Help System Myss\\Description",
  410. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Type",
  411. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\TimeProviders\\NtpClient\\SpecialPollTimeRemaining"
  412. ]
  413.  
  414. [*] Deleted Registry Keys: []
  415.  
  416. [*] DNS Communications: []
  417.  
  418. [*] Domains: []
  419.  
  420. [*] Network Communication - ICMP: []
  421.  
  422. [*] Network Communication - HTTP: []
  423.  
  424. [*] Network Communication - SMTP: []
  425.  
  426. [*] Network Communication - Hosts: []
  427.  
  428. [*] Network Communication - IRC: []
  429.  
  430. [*] Static Analysis: {
  431. "pe": {
  432. "peid_signatures": [
  433. [
  434. "UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser"
  435. ]
  436. ],
  437. "imports": [
  438. {
  439. "imports": [
  440. {
  441. "name": "LoadLibraryA",
  442. "address": "0x4c7f4c"
  443. },
  444. {
  445. "name": "GetProcAddress",
  446. "address": "0x4c7f50"
  447. },
  448. {
  449. "name": "VirtualProtect",
  450. "address": "0x4c7f54"
  451. },
  452. {
  453. "name": "VirtualAlloc",
  454. "address": "0x4c7f58"
  455. },
  456. {
  457. "name": "VirtualFree",
  458. "address": "0x4c7f5c"
  459. },
  460. {
  461. "name": "ExitProcess",
  462. "address": "0x4c7f60"
  463. }
  464. ],
  465. "dll": "KERNEL32.DLL"
  466. },
  467. {
  468. "imports": [
  469. {
  470. "name": "RegOpenKeyA",
  471. "address": "0x4c7f68"
  472. }
  473. ],
  474. "dll": "ADVAPI32.dll"
  475. },
  476. {
  477. "imports": [
  478. {
  479. "name": "GetIfTable",
  480. "address": "0x4c7f70"
  481. }
  482. ],
  483. "dll": "iphlpapi.dll"
  484. },
  485. {
  486. "imports": [
  487. {
  488. "name": "time",
  489. "address": "0x4c7f78"
  490. }
  491. ],
  492. "dll": "MSVCRT.dll"
  493. },
  494. {
  495. "imports": [
  496. {
  497. "name": "wsprintfA",
  498. "address": "0x4c7f80"
  499. }
  500. ],
  501. "dll": "USER32.dll"
  502. },
  503. {
  504. "imports": [
  505. {
  506. "name": "InternetOpenA",
  507. "address": "0x4c7f88"
  508. }
  509. ],
  510. "dll": "WININET.dll"
  511. },
  512. {
  513. "imports": [
  514. {
  515. "name": "inet_addr",
  516. "address": "0x4c7f90"
  517. }
  518. ],
  519. "dll": "WS2_32.dll"
  520. }
  521. ],
  522. "digital_signers": null,
  523. "exported_dll_name": null,
  524. "actual_checksum": "0x00065099",
  525. "overlay": null,
  526. "imagebase": "0x00400000",
  527. "reported_checksum": "0x00000000",
  528. "icon_hash": null,
  529. "entrypoint": "0x0046bea0",
  530. "timestamp": "2017-04-18 09:10:22",
  531. "osversion": "4.0",
  532. "sections": [
  533. {
  534. "name": "UPX0",
  535. "characteristics": "IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  536. "virtual_address": "0x00001000",
  537. "size_of_data": "0x00000000",
  538. "entropy": "0.00",
  539. "raw_address": "0x00000400",
  540. "virtual_size": "0x00066000",
  541. "characteristics_raw": "0xe0000080"
  542. },
  543. {
  544. "name": "UPX1",
  545. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  546. "virtual_address": "0x00067000",
  547. "size_of_data": "0x00005200",
  548. "entropy": "7.84",
  549. "raw_address": "0x00000400",
  550. "virtual_size": "0x00006000",
  551. "characteristics_raw": "0xe0000040"
  552. },
  553. {
  554. "name": ".rsrc",
  555. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  556. "virtual_address": "0x0006d000",
  557. "size_of_data": "0x0005b200",
  558. "entropy": "4.38",
  559. "raw_address": "0x00005600",
  560. "virtual_size": "0x0005c000",
  561. "characteristics_raw": "0xc0000040"
  562. }
  563. ],
  564. "resources": [
  565. {
  566. "name": "RT_DIALOG",
  567. "language": "LANG_CHINESE",
  568. "filetype": null,
  569. "sublanguage": "SUBLANG_CHINESE_SIMPLIFIED",
  570. "entropy": "0.00",
  571. "offset": "0x0006592c",
  572. "size": "0x0000004c"
  573. },
  574. {
  575. "name": "RT_DIALOG",
  576. "language": "LANG_CHINESE",
  577. "filetype": null,
  578. "sublanguage": "SUBLANG_CHINESE_SIMPLIFIED",
  579. "entropy": "0.00",
  580. "offset": "0x0006592c",
  581. "size": "0x0000004c"
  582. },
  583. {
  584. "name": "RT_STRING",
  585. "language": "LANG_CHINESE",
  586. "filetype": null,
  587. "sublanguage": "SUBLANG_CHINESE_SIMPLIFIED",
  588. "entropy": "0.00",
  589. "offset": "0x00065ac4",
  590. "size": "0x000003a4"
  591. },
  592. {
  593. "name": "RT_STRING",
  594. "language": "LANG_CHINESE",
  595. "filetype": null,
  596. "sublanguage": "SUBLANG_CHINESE_SIMPLIFIED",
  597. "entropy": "0.00",
  598. "offset": "0x00065ac4",
  599. "size": "0x000003a4"
  600. },
  601. {
  602. "name": "RT_ACCELERATOR",
  603. "language": "LANG_CHINESE",
  604. "filetype": null,
  605. "sublanguage": "SUBLANG_CHINESE_SIMPLIFIED",
  606. "entropy": "0.00",
  607. "offset": "0x00065e68",
  608. "size": "0x00000070"
  609. },
  610. {
  611. "name": "RT_RCDATA",
  612. "language": "LANG_ENGLISH",
  613. "filetype": null,
  614. "sublanguage": "SUBLANG_ENGLISH_US",
  615. "entropy": "0.00",
  616. "offset": "0x00068ed8",
  617. "size": "0x00000080"
  618. }
  619. ],
  620. "dirents": [
  621. {
  622. "virtual_address": "0x00000000",
  623. "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
  624. "size": "0x00000000"
  625. },
  626. {
  627. "virtual_address": "0x000c7eac",
  628. "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
  629. "size": "0x000001d4"
  630. },
  631. {
  632. "virtual_address": "0x0006d000",
  633. "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
  634. "size": "0x0005aeac"
  635. },
  636. {
  637. "virtual_address": "0x00000000",
  638. "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
  639. "size": "0x00000000"
  640. },
  641. {
  642. "virtual_address": "0x00000000",
  643. "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
  644. "size": "0x00000000"
  645. },
  646. {
  647. "virtual_address": "0x00000000",
  648. "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
  649. "size": "0x00000000"
  650. },
  651. {
  652. "virtual_address": "0x00000000",
  653. "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
  654. "size": "0x00000000"
  655. },
  656. {
  657. "virtual_address": "0x00000000",
  658. "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
  659. "size": "0x00000000"
  660. },
  661. {
  662. "virtual_address": "0x00000000",
  663. "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
  664. "size": "0x00000000"
  665. },
  666. {
  667. "virtual_address": "0x00000000",
  668. "name": "IMAGE_DIRECTORY_ENTRY_TLS",
  669. "size": "0x00000000"
  670. },
  671. {
  672. "virtual_address": "0x00000000",
  673. "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
  674. "size": "0x00000000"
  675. },
  676. {
  677. "virtual_address": "0x00000000",
  678. "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
  679. "size": "0x00000000"
  680. },
  681. {
  682. "virtual_address": "0x00000000",
  683. "name": "IMAGE_DIRECTORY_ENTRY_IAT",
  684. "size": "0x00000000"
  685. },
  686. {
  687. "virtual_address": "0x00000000",
  688. "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
  689. "size": "0x00000000"
  690. },
  691. {
  692. "virtual_address": "0x00000000",
  693. "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
  694. "size": "0x00000000"
  695. },
  696. {
  697. "virtual_address": "0x00000000",
  698. "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
  699. "size": "0x00000000"
  700. }
  701. ],
  702. "exports": [],
  703. "guest_signers": {},
  704. "imphash": "a3efcc970852f76f399fd867a4d6b207",
  705. "icon_fuzzy": null,
  706. "icon": null,
  707. "pdbpath": null,
  708. "imported_dll_count": 7,
  709. "versioninfo": []
  710. }
  711. }
  712.  
  713. [*] Resolved APIs: [
  714. "kernel32.dll.WaitForSingleObject",
  715. "kernel32.dll.WinExec",
  716. "kernel32.dll.WriteFile",
  717. "kernel32.dll.CreateFileA",
  718. "kernel32.dll.LockResource",
  719. "kernel32.dll.LoadResource",
  720. "kernel32.dll.SizeofResource",
  721. "kernel32.dll.FindResourceA",
  722. "kernel32.dll.EnumResourceNamesA",
  723. "kernel32.dll.EndUpdateResourceA",
  724. "kernel32.dll.lstrlenA",
  725. "kernel32.dll.UpdateResourceA",
  726. "kernel32.dll.GetSystemInfo",
  727. "kernel32.dll.GlobalFree",
  728. "kernel32.dll.ReadFile",
  729. "kernel32.dll.GlobalAlloc",
  730. "kernel32.dll.GetFileSize",
  731. "kernel32.dll.GetFileAttributesA",
  732. "kernel32.dll.lstrcatA",
  733. "kernel32.dll.GetLastError",
  734. "kernel32.dll.CopyFileA",
  735. "kernel32.dll.GetModuleHandleA",
  736. "kernel32.dll.GetStartupInfoA",
  737. "kernel32.dll.GetComputerNameA",
  738. "kernel32.dll.GetSystemDefaultUILanguage",
  739. "kernel32.dll.GetModuleFileNameA",
  740. "kernel32.dll.GetTempPathA",
  741. "kernel32.dll.MoveFileA",
  742. "kernel32.dll.MoveFileExA",
  743. "kernel32.dll.CreateThread",
  744. "kernel32.dll.CloseHandle",
  745. "kernel32.dll.GetCurrentProcessId",
  746. "kernel32.dll.lstrcpyA",
  747. "kernel32.dll.GetCurrentProcess",
  748. "kernel32.dll.ExitThread",
  749. "kernel32.dll.Sleep",
  750. "kernel32.dll.GetTickCount",
  751. "kernel32.dll.LoadLibraryA",
  752. "kernel32.dll.BeginUpdateResourceA",
  753. "kernel32.dll.GetProcAddress",
  754. "advapi32.dll.OpenSCManagerA",
  755. "advapi32.dll.LockServiceDatabase",
  756. "advapi32.dll.ChangeServiceConfig2A",
  757. "advapi32.dll.UnlockServiceDatabase",
  758. "advapi32.dll.OpenServiceA",
  759. "advapi32.dll.StartServiceA",
  760. "advapi32.dll.RegSetValueExA",
  761. "advapi32.dll.CloseServiceHandle",
  762. "advapi32.dll.StartServiceCtrlDispatcherA",
  763. "advapi32.dll.RegisterServiceCtrlHandlerA",
  764. "advapi32.dll.SetServiceStatus",
  765. "advapi32.dll.RegOpenKeyExA",
  766. "advapi32.dll.RegOpenKeyA",
  767. "advapi32.dll.RegQueryValueExA",
  768. "advapi32.dll.RegCloseKey",
  769. "advapi32.dll.CreateServiceA",
  770. "iphlpapi.dll.GetIfTable",
  771. "msvcrt.dll._initterm",
  772. "msvcrt.dll.memcpy",
  773. "msvcrt.dll.??3@YAXPAX@Z",
  774. "msvcrt.dll.strlen",
  775. "msvcrt.dll.sprintf",
  776. "msvcrt.dll._controlfp",
  777. "msvcrt.dll.time",
  778. "msvcrt.dll.rand",
  779. "msvcrt.dll.srand",
  780. "msvcrt.dll.memset",
  781. "msvcrt.dll.fprintf",
  782. "msvcrt.dll.printf",
  783. "msvcrt.dll._except_handler3",
  784. "msvcrt.dll._local_unwind2",
  785. "msvcrt.dll.__CxxFrameHandler",
  786. "msvcrt.dll._ftol",
  787. "msvcrt.dll.strcpy",
  788. "msvcrt.dll.strcat",
  789. "msvcrt.dll.strstr",
  790. "msvcrt.dll.atoi",
  791. "msvcrt.dll.exit",
  792. "msvcrt.dll.system",
  793. "msvcrt.dll.strcmp",
  794. "msvcrt.dll.strncmp",
  795. "msvcrt.dll.free",
  796. "msvcrt.dll.??2@YAPAXI@Z",
  797. "msvcrt.dll._iob",
  798. "msvcrt.dll.__dllonexit",
  799. "msvcrt.dll._onexit",
  800. "msvcrt.dll._exit",
  801. "msvcrt.dll._XcptFilter",
  802. "msvcrt.dll._acmdln",
  803. "msvcrt.dll.__getmainargs",
  804. "msvcrt.dll.localtime",
  805. "msvcrt.dll.__setusermatherr",
  806. "msvcrt.dll._adjust_fdiv",
  807. "msvcrt.dll.__p__commode",
  808. "msvcrt.dll.__p__fmode",
  809. "msvcrt.dll.__set_app_type",
  810. "user32.dll.wsprintfA",
  811. "wininet.dll.InternetOpenA",
  812. "wininet.dll.InternetOpenUrlA",
  813. "wininet.dll.InternetReadFile",
  814. "wininet.dll.InternetCloseHandle",
  815. "ws2_32.dll.#116",
  816. "ws2_32.dll.#20",
  817. "ws2_32.dll.#8",
  818. "ws2_32.dll.#21",
  819. "ws2_32.dll.#111",
  820. "ws2_32.dll.WSASocketA",
  821. "ws2_32.dll.#23",
  822. "ws2_32.dll.#52",
  823. "ws2_32.dll.#19",
  824. "ws2_32.dll.#16",
  825. "ws2_32.dll.#151",
  826. "ws2_32.dll.#18",
  827. "ws2_32.dll.#9",
  828. "ws2_32.dll.#4",
  829. "ws2_32.dll.#3",
  830. "ws2_32.dll.#115",
  831. "ws2_32.dll.#11",
  832. "ws2_32.dll.WSAIoctl",
  833. "ws2_32.dll.htons",
  834. "kernel32.dll.SetProcessWorkingSetSize",
  835. "kernel32.dll.GetWindowsDirectoryA",
  836. "ole32.dll.CoInitializeEx",
  837. "cryptbase.dll.SystemFunction036",
  838. "ole32.dll.CoInitializeSecurity",
  839. "sechost.dll.LookupAccountNameLocalW",
  840. "advapi32.dll.LookupAccountSidW",
  841. "sechost.dll.LookupAccountSidLocalW",
  842. "ole32.dll.CoCreateInstance",
  843. "kernel32.dll.SortGetHandle",
  844. "kernel32.dll.SortCloseHandle",
  845. "w32time.dll.SvchostEntry_W32Time",
  846. "w32time.dll.SvchostPushServiceGlobals",
  847. "sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW",
  848. "ws2_32.dll.WSASocketW",
  849. "userenv.dll.RegisterGPNotification",
  850. "gpapi.dll.RegisterGPNotificationInternal",
  851. "sechost.dll.OpenSCManagerW",
  852. "sechost.dll.OpenServiceW",
  853. "sechost.dll.CloseServiceHandle",
  854. "sechost.dll.QueryServiceConfigW",
  855. "dsrole.dll.DsRoleGetPrimaryDomainInformation",
  856. "dsrole.dll.DsRoleFreeMemory",
  857. "sspicli.dll.LsaRegisterPolicyChangeNotification",
  858. "w32time.dll.TimeProvClose",
  859. "w32time.dll.TimeProvCommand",
  860. "w32time.dll.TimeProvOpen",
  861. "ws2_32.dll.getaddrinfo",
  862. "ws2_32.dll.freeaddrinfo",
  863. "ws2_32.dll.#2",
  864. "ws2_32.dll.WSAEventSelect",
  865. "vmictimeprovider.dll.TimeProvClose",
  866. "vmictimeprovider.dll.TimeProvCommand",
  867. "vmictimeprovider.dll.TimeProvOpen",
  868. "advapi32.dll.EventRegister",
  869. "advapi32.dll.EventEnabled",
  870. "advapi32.dll.EventWrite",
  871. "rpcrtremote.dll.I_RpcExtInitializeExtensionPoint",
  872. "ws2_32.dll.GetAddrInfoW",
  873. "ws2_32.dll.FreeAddrInfoW",
  874. "ws2_32.dll.WSAAddressToStringW",
  875. "advapi32.dll.EventUnregister",
  876. "sspicli.dll.LsaUnregisterPolicyChangeNotification",
  877. "userenv.dll.UnregisterGPNotification",
  878. "gpapi.dll.UnregisterGPNotificationInternal"
  879. ]
  880.  
  881. [*] Static Analysis: {
  882. "pe": {
  883. "peid_signatures": [
  884. [
  885. "UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser"
  886. ]
  887. ],
  888. "imports": [
  889. {
  890. "imports": [
  891. {
  892. "name": "LoadLibraryA",
  893. "address": "0x4c7f4c"
  894. },
  895. {
  896. "name": "GetProcAddress",
  897. "address": "0x4c7f50"
  898. },
  899. {
  900. "name": "VirtualProtect",
  901. "address": "0x4c7f54"
  902. },
  903. {
  904. "name": "VirtualAlloc",
  905. "address": "0x4c7f58"
  906. },
  907. {
  908. "name": "VirtualFree",
  909. "address": "0x4c7f5c"
  910. },
  911. {
  912. "name": "ExitProcess",
  913. "address": "0x4c7f60"
  914. }
  915. ],
  916. "dll": "KERNEL32.DLL"
  917. },
  918. {
  919. "imports": [
  920. {
  921. "name": "RegOpenKeyA",
  922. "address": "0x4c7f68"
  923. }
  924. ],
  925. "dll": "ADVAPI32.dll"
  926. },
  927. {
  928. "imports": [
  929. {
  930. "name": "GetIfTable",
  931. "address": "0x4c7f70"
  932. }
  933. ],
  934. "dll": "iphlpapi.dll"
  935. },
  936. {
  937. "imports": [
  938. {
  939. "name": "time",
  940. "address": "0x4c7f78"
  941. }
  942. ],
  943. "dll": "MSVCRT.dll"
  944. },
  945. {
  946. "imports": [
  947. {
  948. "name": "wsprintfA",
  949. "address": "0x4c7f80"
  950. }
  951. ],
  952. "dll": "USER32.dll"
  953. },
  954. {
  955. "imports": [
  956. {
  957. "name": "InternetOpenA",
  958. "address": "0x4c7f88"
  959. }
  960. ],
  961. "dll": "WININET.dll"
  962. },
  963. {
  964. "imports": [
  965. {
  966. "name": "inet_addr",
  967. "address": "0x4c7f90"
  968. }
  969. ],
  970. "dll": "WS2_32.dll"
  971. }
  972. ],
  973. "digital_signers": null,
  974. "exported_dll_name": null,
  975. "actual_checksum": "0x00065099",
  976. "overlay": null,
  977. "imagebase": "0x00400000",
  978. "reported_checksum": "0x00000000",
  979. "icon_hash": null,
  980. "entrypoint": "0x0046bea0",
  981. "timestamp": "2017-04-18 09:10:22",
  982. "osversion": "4.0",
  983. "sections": [
  984. {
  985. "name": "UPX0",
  986. "characteristics": "IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  987. "virtual_address": "0x00001000",
  988. "size_of_data": "0x00000000",
  989. "entropy": "0.00",
  990. "raw_address": "0x00000400",
  991. "virtual_size": "0x00066000",
  992. "characteristics_raw": "0xe0000080"
  993. },
  994. {
  995. "name": "UPX1",
  996. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  997. "virtual_address": "0x00067000",
  998. "size_of_data": "0x00005200",
  999. "entropy": "7.84",
  1000. "raw_address": "0x00000400",
  1001. "virtual_size": "0x00006000",
  1002. "characteristics_raw": "0xe0000040"
  1003. },
  1004. {
  1005. "name": ".rsrc",
  1006. "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  1007. "virtual_address": "0x0006d000",
  1008. "size_of_data": "0x0005b200",
  1009. "entropy": "4.38",
  1010. "raw_address": "0x00005600",
  1011. "virtual_size": "0x0005c000",
  1012. "characteristics_raw": "0xc0000040"
  1013. }
  1014. ],
  1015. "resources": [
  1016. {
  1017. "name": "RT_DIALOG",
  1018. "language": "LANG_CHINESE",
  1019. "filetype": null,
  1020. "sublanguage": "SUBLANG_CHINESE_SIMPLIFIED",
  1021. "entropy": "0.00",
  1022. "offset": "0x0006592c",
  1023. "size": "0x0000004c"
  1024. },
  1025. {
  1026. "name": "RT_DIALOG",
  1027. "language": "LANG_CHINESE",
  1028. "filetype": null,
  1029. "sublanguage": "SUBLANG_CHINESE_SIMPLIFIED",
  1030. "entropy": "0.00",
  1031. "offset": "0x0006592c",
  1032. "size": "0x0000004c"
  1033. },
  1034. {
  1035. "name": "RT_STRING",
  1036. "language": "LANG_CHINESE",
  1037. "filetype": null,
  1038. "sublanguage": "SUBLANG_CHINESE_SIMPLIFIED",
  1039. "entropy": "0.00",
  1040. "offset": "0x00065ac4",
  1041. "size": "0x000003a4"
  1042. },
  1043. {
  1044. "name": "RT_STRING",
  1045. "language": "LANG_CHINESE",
  1046. "filetype": null,
  1047. "sublanguage": "SUBLANG_CHINESE_SIMPLIFIED",
  1048. "entropy": "0.00",
  1049. "offset": "0x00065ac4",
  1050. "size": "0x000003a4"
  1051. },
  1052. {
  1053. "name": "RT_ACCELERATOR",
  1054. "language": "LANG_CHINESE",
  1055. "filetype": null,
  1056. "sublanguage": "SUBLANG_CHINESE_SIMPLIFIED",
  1057. "entropy": "0.00",
  1058. "offset": "0x00065e68",
  1059. "size": "0x00000070"
  1060. },
  1061. {
  1062. "name": "RT_RCDATA",
  1063. "language": "LANG_ENGLISH",
  1064. "filetype": null,
  1065. "sublanguage": "SUBLANG_ENGLISH_US",
  1066. "entropy": "0.00",
  1067. "offset": "0x00068ed8",
  1068. "size": "0x00000080"
  1069. }
  1070. ],
  1071. "dirents": [
  1072. {
  1073. "virtual_address": "0x00000000",
  1074. "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
  1075. "size": "0x00000000"
  1076. },
  1077. {
  1078. "virtual_address": "0x000c7eac",
  1079. "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
  1080. "size": "0x000001d4"
  1081. },
  1082. {
  1083. "virtual_address": "0x0006d000",
  1084. "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
  1085. "size": "0x0005aeac"
  1086. },
  1087. {
  1088. "virtual_address": "0x00000000",
  1089. "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
  1090. "size": "0x00000000"
  1091. },
  1092. {
  1093. "virtual_address": "0x00000000",
  1094. "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
  1095. "size": "0x00000000"
  1096. },
  1097. {
  1098. "virtual_address": "0x00000000",
  1099. "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
  1100. "size": "0x00000000"
  1101. },
  1102. {
  1103. "virtual_address": "0x00000000",
  1104. "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
  1105. "size": "0x00000000"
  1106. },
  1107. {
  1108. "virtual_address": "0x00000000",
  1109. "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
  1110. "size": "0x00000000"
  1111. },
  1112. {
  1113. "virtual_address": "0x00000000",
  1114. "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
  1115. "size": "0x00000000"
  1116. },
  1117. {
  1118. "virtual_address": "0x00000000",
  1119. "name": "IMAGE_DIRECTORY_ENTRY_TLS",
  1120. "size": "0x00000000"
  1121. },
  1122. {
  1123. "virtual_address": "0x00000000",
  1124. "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
  1125. "size": "0x00000000"
  1126. },
  1127. {
  1128. "virtual_address": "0x00000000",
  1129. "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
  1130. "size": "0x00000000"
  1131. },
  1132. {
  1133. "virtual_address": "0x00000000",
  1134. "name": "IMAGE_DIRECTORY_ENTRY_IAT",
  1135. "size": "0x00000000"
  1136. },
  1137. {
  1138. "virtual_address": "0x00000000",
  1139. "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
  1140. "size": "0x00000000"
  1141. },
  1142. {
  1143. "virtual_address": "0x00000000",
  1144. "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
  1145. "size": "0x00000000"
  1146. },
  1147. {
  1148. "virtual_address": "0x00000000",
  1149. "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
  1150. "size": "0x00000000"
  1151. }
  1152. ],
  1153. "exports": [],
  1154. "guest_signers": {},
  1155. "imphash": "a3efcc970852f76f399fd867a4d6b207",
  1156. "icon_fuzzy": null,
  1157. "icon": null,
  1158. "pdbpath": null,
  1159. "imported_dll_count": 7,
  1160. "versioninfo": []
  1161. }
  1162. }
Advertisement
Add Comment
Please, Sign In to add comment