paladin316

Exes_2fc894339ac98193976611df5fa8909a_exe_2019-07-12_01_30.txt

Jul 11th, 2019
2,434
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 8.46 KB | None | 0 0
  1.  
  2. * MalFamily: ""
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_2fc894339ac98193976611df5fa8909a.exe"
  7. * File Size: 454144
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "b88f68ae6b98a0053b8c5f39ba63ad11dba64b5adaa5ea44cd974fe81eeb4eb9"
  10. * MD5: "2fc894339ac98193976611df5fa8909a"
  11. * SHA1: "54616e11769b10d0d4e80439b6e00bb1962654fc"
  12. * SHA512: "780d83fc23fe267817565784261e749adbfaad66a95e2834b66fb6d5ebff62b5c520a10719dcf70e6ec2e5cb9a59802ef98b749406fadff75dedbb8c2fe7af7d"
  13. * CRC32: "4058C6B8"
  14. * SSDEEP: "12288:PzIogpuoXI9QrlRNhPV0F5IwLYZAdVz5Y2fLi57u8:PHgp3I9Ufhi+09Ca8"
  15.  
  16. * Process Execution:
  17. "Exes_2fc894339ac98193976611df5fa8909a.exe"
  18.  
  19.  
  20. * Executed Commands:
  21.  
  22. * Signatures Detected:
  23.  
  24. "Description": "Performs some HTTP requests",
  25. "Details":
  26.  
  27. "url": "http://www.msftncsi.com/ncsi.txt"
  28.  
  29.  
  30.  
  31.  
  32. "Description": "The binary likely contains encrypted or compressed data.",
  33. "Details":
  34.  
  35. "section": "name: .data, entropy: 7.94, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x0005ee00, virtual_size: 0x0005fec0"
  36.  
  37.  
  38.  
  39.  
  40. "Description": "Queries information on disks, possibly for anti-virtualization",
  41. "Details":
  42.  
  43.  
  44. "Description": "Attempts to restart the guest VM",
  45. "Details":
  46.  
  47.  
  48. "Description": "Spoofs its process name and/or associated pathname to appear as a legitimate process",
  49. "Details":
  50.  
  51. "modified_name": "explorer.exe",
  52. "modified_path": "C:\\Windows\\explorer.exe",
  53. "original_name": "Exes_2fc894339ac98193976611df5fa8909a.exe",
  54. "original_path": "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_2fc894339ac98193976611df5fa8909a.exe"
  55.  
  56.  
  57.  
  58.  
  59. "Description": "File has been identified by 53 Antiviruses on VirusTotal as malicious",
  60. "Details":
  61.  
  62. "MicroWorld-eScan": "Gen:Variant.Kazy.330705"
  63.  
  64.  
  65. "CMC": "Trojan.Win32.Swizzor.1!O"
  66.  
  67.  
  68. "CAT-QuickHeal": "Trojan.Generic"
  69.  
  70.  
  71. "McAfee": "GenericRXHQ-SA!2FC894339AC9"
  72.  
  73.  
  74. "Cylance": "Unsafe"
  75.  
  76.  
  77. "K7AntiVirus": "Trojan ( 0051ac701 )"
  78.  
  79.  
  80. "Alibaba": "Trojan:Win32/Bulta.2f35dff5"
  81.  
  82.  
  83. "K7GW": "Trojan ( 0051ac701 )"
  84.  
  85.  
  86. "Cybereason": "malicious.39ac98"
  87.  
  88.  
  89. "Arcabit": "Trojan.Kazy.D50BD1"
  90.  
  91.  
  92. "TrendMicro": "TROJ_GEN.R002C0DET19"
  93.  
  94.  
  95. "Cyren": "W32/Trojan.JURD-8965"
  96.  
  97.  
  98. "Symantec": "ML.Attribute.HighConfidence"
  99.  
  100.  
  101. "APEX": "Malicious"
  102.  
  103.  
  104. "Avast": "Win32:Pitou-A Rtk"
  105.  
  106.  
  107. "Kaspersky": "HEUR:Trojan.Win32.Generic"
  108.  
  109.  
  110. "BitDefender": "Gen:Variant.Kazy.330705"
  111.  
  112.  
  113. "NANO-Antivirus": "Trojan.Win32.Backboot.eyolqb"
  114.  
  115.  
  116. "Paloalto": "generic.ml"
  117.  
  118.  
  119. "ViRobot": "Trojan.Win32.Z.Pitou.454144"
  120.  
  121.  
  122. "Rising": "Backdoor.Backboot!8.DE4B (TFE:2:VxtzOTOjMBK)"
  123.  
  124.  
  125. "Ad-Aware": "Gen:Variant.Kazy.330705"
  126.  
  127.  
  128. "Emsisoft": "Gen:Variant.Kazy.330705 (B)"
  129.  
  130.  
  131. "F-Secure": "Trojan.TR/Crypt.XPACK.Gen"
  132.  
  133.  
  134. "DrWeb": "Trojan.Siggen8.5408"
  135.  
  136.  
  137. "Invincea": "heuristic"
  138.  
  139.  
  140. "McAfee-GW-Edition": "BehavesLike.Win32.Generic.gc"
  141.  
  142.  
  143. "FireEye": "Generic.mg.2fc894339ac98193"
  144.  
  145.  
  146. "Sophos": "Mal/Generic-S"
  147.  
  148.  
  149. "SentinelOne": "DFI - Malicious PE"
  150.  
  151.  
  152. "Jiangmin": "Backdoor.Backboot.ab"
  153.  
  154.  
  155. "Avira": "TR/Crypt.XPACK.Gen"
  156.  
  157.  
  158. "Antiy-AVL": "Trojan/Win32.Bulta"
  159.  
  160.  
  161. "Microsoft": "Trojan:Win32/Bulta!rfn"
  162.  
  163.  
  164. "Endgame": "malicious (high confidence)"
  165.  
  166.  
  167. "AegisLab": "Trojan.Win32.Generic.4!c"
  168.  
  169.  
  170. "ZoneAlarm": "HEUR:Trojan.Win32.Generic"
  171.  
  172.  
  173. "GData": "Gen:Variant.Kazy.330705"
  174.  
  175.  
  176. "AhnLab-V3": "Trojan/Win32.Tepfer.R96475"
  177.  
  178.  
  179. "Acronis": "suspicious"
  180.  
  181.  
  182. "VBA32": "Malware-Cryptor.General.3"
  183.  
  184.  
  185. "ALYac": "Gen:Variant.Kazy.330705"
  186.  
  187.  
  188. "MAX": "malware (ai score=100)"
  189.  
  190.  
  191. "Malwarebytes": "Trojan.Injector"
  192.  
  193.  
  194. "ESET-NOD32": "a variant of Win32/Pitou.K"
  195.  
  196.  
  197. "TrendMicro-HouseCall": "TROJ_GEN.R002C0DET19"
  198.  
  199.  
  200. "Tencent": "Win32.Trojan.Generic.Hwdk"
  201.  
  202.  
  203. "Ikarus": "Trojan.Win32.Pitou"
  204.  
  205.  
  206. "Fortinet": "W32/Pitou.A!tr"
  207.  
  208.  
  209. "AVG": "Win32:Pitou-A Rtk"
  210.  
  211.  
  212. "Panda": "Trj/CI.A"
  213.  
  214.  
  215. "CrowdStrike": "win/malicious_confidence_60% (W)"
  216.  
  217.  
  218. "Qihoo-360": "HEUR/QVM20.1.8227.Malware.Gen"
  219.  
  220.  
  221.  
  222.  
  223.  
  224. * Started Service:
  225.  
  226. * Mutexes:
  227. "SpNUUDeskhQZatXaIrfc"
  228.  
  229.  
  230. * Modified Files:
  231. "\\??\\PHYSICALDRIVE0"
  232.  
  233.  
  234. * Deleted Files:
  235.  
  236. * Modified Registry Keys:
  237.  
  238. * Deleted Registry Keys:
  239.  
  240. * DNS Communications:
  241.  
  242. * Domains:
  243.  
  244. * Network Communication - ICMP:
  245.  
  246. * Network Communication - HTTP:
  247.  
  248. "count": 1,
  249. "body": "",
  250. "uri": "http://www.msftncsi.com/ncsi.txt",
  251. "user-agent": "Microsoft NCSI",
  252. "method": "GET",
  253. "host": "www.msftncsi.com",
  254. "version": "1.1",
  255. "path": "/ncsi.txt",
  256. "data": "GET /ncsi.txt HTTP/1.1\r\nConnection: Close\r\nUser-Agent: Microsoft NCSI\r\nHost: www.msftncsi.com\r\n\r\n",
  257. "port": 80
  258.  
  259.  
  260. "count": 1,
  261. "body": "",
  262. "uri": "http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl",
  263. "user-agent": "Microsoft-CryptoAPI/6.1",
  264. "method": "GET",
  265. "host": "crl.microsoft.com",
  266. "version": "1.1",
  267. "path": "/pki/crl/products/microsoftrootcert.crl",
  268. "data": "GET /pki/crl/products/microsoftrootcert.crl HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: crl.microsoft.com\r\n\r\n",
  269. "port": 80
  270.  
  271.  
  272. "count": 1,
  273. "body": "",
  274. "uri": "http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl",
  275. "user-agent": "Microsoft-CryptoAPI/6.1",
  276. "method": "GET",
  277. "host": "crl.microsoft.com",
  278. "version": "1.1",
  279. "path": "/pki/crl/products/MicCodSigPCA_08-31-2010.crl",
  280. "data": "GET /pki/crl/products/MicCodSigPCA_08-31-2010.crl HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: crl.microsoft.com\r\n\r\n",
  281. "port": 80
  282.  
  283.  
  284. "count": 1,
  285. "body": "",
  286. "uri": "http://crl.microsoft.com/pki/crl/products/CSPCA.crl",
  287. "user-agent": "Microsoft-CryptoAPI/6.1",
  288. "method": "GET",
  289. "host": "crl.microsoft.com",
  290. "version": "1.1",
  291. "path": "/pki/crl/products/CSPCA.crl",
  292. "data": "GET /pki/crl/products/CSPCA.crl HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Sat, 28 Feb 2009 02:01:22 GMT\r\nIf-None-Match: \"0c55744899c91:0\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: crl.microsoft.com\r\n\r\n",
  293. "port": 80
  294.  
  295.  
  296.  
  297. * Network Communication - SMTP:
  298.  
  299. * Network Communication - Hosts:
  300.  
  301. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment