Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: ""
- * MalScore: 10.0
- * File Name: "Exes_2fc894339ac98193976611df5fa8909a.exe"
- * File Size: 454144
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "b88f68ae6b98a0053b8c5f39ba63ad11dba64b5adaa5ea44cd974fe81eeb4eb9"
- * MD5: "2fc894339ac98193976611df5fa8909a"
- * SHA1: "54616e11769b10d0d4e80439b6e00bb1962654fc"
- * SHA512: "780d83fc23fe267817565784261e749adbfaad66a95e2834b66fb6d5ebff62b5c520a10719dcf70e6ec2e5cb9a59802ef98b749406fadff75dedbb8c2fe7af7d"
- * CRC32: "4058C6B8"
- * SSDEEP: "12288:PzIogpuoXI9QrlRNhPV0F5IwLYZAdVz5Y2fLi57u8:PHgp3I9Ufhi+09Ca8"
- * Process Execution:
- "Exes_2fc894339ac98193976611df5fa8909a.exe"
- * Executed Commands:
- * Signatures Detected:
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://www.msftncsi.com/ncsi.txt"
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details":
- "section": "name: .data, entropy: 7.94, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x0005ee00, virtual_size: 0x0005fec0"
- "Description": "Queries information on disks, possibly for anti-virtualization",
- "Details":
- "Description": "Attempts to restart the guest VM",
- "Details":
- "Description": "Spoofs its process name and/or associated pathname to appear as a legitimate process",
- "Details":
- "modified_name": "explorer.exe",
- "modified_path": "C:\\Windows\\explorer.exe",
- "original_name": "Exes_2fc894339ac98193976611df5fa8909a.exe",
- "original_path": "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_2fc894339ac98193976611df5fa8909a.exe"
- "Description": "File has been identified by 53 Antiviruses on VirusTotal as malicious",
- "Details":
- "MicroWorld-eScan": "Gen:Variant.Kazy.330705"
- "CMC": "Trojan.Win32.Swizzor.1!O"
- "CAT-QuickHeal": "Trojan.Generic"
- "McAfee": "GenericRXHQ-SA!2FC894339AC9"
- "Cylance": "Unsafe"
- "K7AntiVirus": "Trojan ( 0051ac701 )"
- "Alibaba": "Trojan:Win32/Bulta.2f35dff5"
- "K7GW": "Trojan ( 0051ac701 )"
- "Cybereason": "malicious.39ac98"
- "Arcabit": "Trojan.Kazy.D50BD1"
- "TrendMicro": "TROJ_GEN.R002C0DET19"
- "Cyren": "W32/Trojan.JURD-8965"
- "Symantec": "ML.Attribute.HighConfidence"
- "APEX": "Malicious"
- "Avast": "Win32:Pitou-A Rtk"
- "Kaspersky": "HEUR:Trojan.Win32.Generic"
- "BitDefender": "Gen:Variant.Kazy.330705"
- "NANO-Antivirus": "Trojan.Win32.Backboot.eyolqb"
- "Paloalto": "generic.ml"
- "ViRobot": "Trojan.Win32.Z.Pitou.454144"
- "Rising": "Backdoor.Backboot!8.DE4B (TFE:2:VxtzOTOjMBK)"
- "Ad-Aware": "Gen:Variant.Kazy.330705"
- "Emsisoft": "Gen:Variant.Kazy.330705 (B)"
- "F-Secure": "Trojan.TR/Crypt.XPACK.Gen"
- "DrWeb": "Trojan.Siggen8.5408"
- "Invincea": "heuristic"
- "McAfee-GW-Edition": "BehavesLike.Win32.Generic.gc"
- "FireEye": "Generic.mg.2fc894339ac98193"
- "Sophos": "Mal/Generic-S"
- "SentinelOne": "DFI - Malicious PE"
- "Jiangmin": "Backdoor.Backboot.ab"
- "Avira": "TR/Crypt.XPACK.Gen"
- "Antiy-AVL": "Trojan/Win32.Bulta"
- "Microsoft": "Trojan:Win32/Bulta!rfn"
- "Endgame": "malicious (high confidence)"
- "AegisLab": "Trojan.Win32.Generic.4!c"
- "ZoneAlarm": "HEUR:Trojan.Win32.Generic"
- "GData": "Gen:Variant.Kazy.330705"
- "AhnLab-V3": "Trojan/Win32.Tepfer.R96475"
- "Acronis": "suspicious"
- "VBA32": "Malware-Cryptor.General.3"
- "ALYac": "Gen:Variant.Kazy.330705"
- "MAX": "malware (ai score=100)"
- "Malwarebytes": "Trojan.Injector"
- "ESET-NOD32": "a variant of Win32/Pitou.K"
- "TrendMicro-HouseCall": "TROJ_GEN.R002C0DET19"
- "Tencent": "Win32.Trojan.Generic.Hwdk"
- "Ikarus": "Trojan.Win32.Pitou"
- "Fortinet": "W32/Pitou.A!tr"
- "AVG": "Win32:Pitou-A Rtk"
- "Panda": "Trj/CI.A"
- "CrowdStrike": "win/malicious_confidence_60% (W)"
- "Qihoo-360": "HEUR/QVM20.1.8227.Malware.Gen"
- * Started Service:
- * Mutexes:
- "SpNUUDeskhQZatXaIrfc"
- * Modified Files:
- "\\??\\PHYSICALDRIVE0"
- * Deleted Files:
- * Modified Registry Keys:
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 1,
- "body": "",
- "uri": "http://www.msftncsi.com/ncsi.txt",
- "user-agent": "Microsoft NCSI",
- "method": "GET",
- "host": "www.msftncsi.com",
- "version": "1.1",
- "path": "/ncsi.txt",
- "data": "GET /ncsi.txt HTTP/1.1\r\nConnection: Close\r\nUser-Agent: Microsoft NCSI\r\nHost: www.msftncsi.com\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "crl.microsoft.com",
- "version": "1.1",
- "path": "/pki/crl/products/microsoftrootcert.crl",
- "data": "GET /pki/crl/products/microsoftrootcert.crl HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: crl.microsoft.com\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "crl.microsoft.com",
- "version": "1.1",
- "path": "/pki/crl/products/MicCodSigPCA_08-31-2010.crl",
- "data": "GET /pki/crl/products/MicCodSigPCA_08-31-2010.crl HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: crl.microsoft.com\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://crl.microsoft.com/pki/crl/products/CSPCA.crl",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "crl.microsoft.com",
- "version": "1.1",
- "path": "/pki/crl/products/CSPCA.crl",
- "data": "GET /pki/crl/products/CSPCA.crl HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Sat, 28 Feb 2009 02:01:22 GMT\r\nIf-None-Match: \"0c55744899c91:0\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: crl.microsoft.com\r\n\r\n",
- "port": 80
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment