Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Trickbot"
- * MalScore: 10.0
- * File Name: "Exes_8bd17ce3c78ebd3f242bc47ca8ba62a5.png"
- * File Size: 684032
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "31ea3259dd105d4edfbf442ce876a341959f45abde775ab0b5b0b62111dca223"
- * MD5: "8bd17ce3c78ebd3f242bc47ca8ba62a5"
- * SHA1: "98e6f5edca65dbe538127b8a30b1cecfc2665ee9"
- * SHA512: "97ec411f740d3cc1b611bbd44018b10d2a80872d8e517252b37a251f0bbea454c726f9ed83b554714486833fa0caaf6ad591add4a193e0930f22b92dc10cad17"
- * CRC32: "92015AF4"
- * SSDEEP: "6144:soeQ+xY8r3dVsqk88TAjvg5sofcxZsfN2ZxnAKZpR/B9ydEuY6cZL96phc:bZ8HcATLR5ein59yTY6cmU"
- * Process Execution:
- "Exes_8bd17ce3c78ebd3f242bc47ca8ba62a5.png",
- "Exeu_8bd19ce3c98ebd3f242bc49ca8ba82a7.exe",
- "svchost.exe",
- "svchost.exe",
- "svchost.exe",
- "dllhost.exe"
- * Executed Commands:
- "C:\\Users\\user\\AppData\\Roaming\\diskram\\Exeu_8bd19ce3c98ebd3f242bc49ca8ba82a7.exe",
- "C:\\Windows\\system32\\svchost.exe",
- "C:\\Windows\\system32\\DllHost.exe /Processid:E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E"
- * Signatures Detected:
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Drops a binary and executes it",
- "Details":
- "binary": "C:\\Users\\user\\AppData\\Roaming\\diskram\\Exeu_8bd19ce3c98ebd3f242bc49ca8ba82a7.exe"
- "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
- "Details":
- "post_no_referer": "HTTP traffic contains a POST request with no referer header"
- "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
- "suspicious_request": "http://170.238.117.187:8082/tot521/Host_W617601.FFBDB1DD115115BB937FB733B7731919/83/"
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab"
- "url": "http://wtfismyip.com/text"
- "url": "http://170.238.117.187:8082/tot521/Host_W617601.FFBDB1DD115115BB937FB733B7731919/83/"
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details":
- "section": "name: .rsrc, entropy: 7.98, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ, raw_size: 0x0002b000, virtual_size: 0x0002a5ec"
- "Description": "Looks up the external IP address",
- "Details":
- "domain": "wtfismyip.com"
- "Description": "Spoofs its process name and/or associated pathname to appear as a legitimate process",
- "Details":
- "modified_name": "svchost.exe",
- "modified_path": "C:\\Users\\user\\AppData\\Roaming\\diskram\\Exeu_8bd19ce3c98ebd3f242bc49ca8ba82a7.exe",
- "original_name": "svchost.exe",
- "original_path": "C:\\Windows\\system32\\svchost.exe"
- "Description": "Network activity detected but not expressed in API logs",
- "Details":
- "Description": "File has been identified by 23 Antiviruses on VirusTotal as malicious",
- "Details":
- "McAfee": "Artemis!8BD17CE3C78E"
- "Cylance": "Unsafe"
- "Symantec": "Trojan.Trickybot!g12"
- "ESET-NOD32": "a variant of Win32/GenKryptik.DNEB"
- "APEX": "Malicious"
- "Paloalto": "generic.ml"
- "Kaspersky": "UDS:DangerousObject.Multi.Generic"
- "AegisLab": "Trojan.Multi.Generic.4!c"
- "Avast": "Win32:BankerX-gen Trj"
- "Endgame": "malicious (high confidence)"
- "Invincea": "heuristic"
- "McAfee-GW-Edition": "BehavesLike.Win32.Generic.jh"
- "Trapmine": "suspicious.low.ml.score"
- "FireEye": "Generic.mg.8bd17ce3c78ebd3f"
- "Webroot": "W32.Adware.Gen"
- "Microsoft": "Trojan:Win32/Fuerboos.C!cl"
- "ZoneAlarm": "UDS:DangerousObject.Multi.Generic"
- "Acronis": "suspicious"
- "SentinelOne": "DFI - Malicious PE"
- "Fortinet": "W32/GenKryptik.DNEB!tr"
- "AVG": "Win32:BankerX-gen Trj"
- "CrowdStrike": "win/malicious_confidence_60% (W)"
- "Qihoo-360": "HEUR/QVM03.0.7AD5.Malware.Gen"
- "Description": "Creates a copy of itself",
- "Details":
- "copy": "C:\\Users\\user\\AppData\\Roaming\\diskram\\Exeu_8bd19ce3c98ebd3f242bc49ca8ba82a7.exe"
- "Description": "Likely use of Domain Generation Algorithm (DGA)",
- "Details":
- "Description": "Anomalous binary characteristics",
- "Details":
- "anomaly": "Actual checksum does not match that reported in PE header"
- "Description": "Created network traffic indicative of malicious activity",
- "Details":
- "signature": "ET CNC Feodo Tracker Reported CnC Server group 21"
- "signature": "ET TROJAN ABUSE.CH SSL Blacklist Malicious SSL certificate detected (Dridex/Trickbot CnC)"
- "signature": "ET TROJAN PTsecurity Trickbot Data Exfiltration"
- * Started Service:
- * Mutexes:
- "Global\\838B6C9EB27932960"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF49833FD515EE1971.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\diskram\\Exeu_8bd19ce3c98ebd3f242bc49ca8ba82a7.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF5447B1CFD56DB448.TMP",
- "C:\\Windows\\sysnative\\Tasks\\Ms Dll libraries",
- "\\Device\\LanmanDatagramReceiver",
- "\\??\\PIPE\\srvsvc",
- "C:\\Windows\\SoftwareDistribution\\DataStore\\DataStore.edb",
- "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edb.chk"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF49833FD515EE1971.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DF5447B1CFD56DB448.TMP",
- "C:\\Windows\\Tasks\\Ms Dll libraries.job",
- "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edbtmp.log"
- * Modified Registry Keys:
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\233B11E4-A390-410C-A0BE-294E173F76F1\\Path",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\233B11E4-A390-410C-A0BE-294E173F76F1\\Hash",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Ms Dll libraries\\Id",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Ms Dll libraries\\Index",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\233B11E4-A390-410C-A0BE-294E173F76F1\\Triggers",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\233B11E4-A390-410C-A0BE-294E173F76F1\\DynamicInfo",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\ProfileList\\S-1-5-21-0000000000-0000000000-0000000000-1000\\RefCount",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\PreviousServiceShutdown",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ProcessID"
- * Deleted Registry Keys:
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\Ms Dll libraries.job",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\Ms Dll libraries.job.fp",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart"
- * DNS Communications:
- "type": "A",
- "request": "wtfismyip.com",
- "answers":
- "data": "198.27.74.146",
- "type": "A"
- "type": "A",
- "request": "rx2ccivr73l4iheo.onion",
- "answers":
- "data": "",
- "type": "NXDOMAIN"
- "type": "A",
- "request": "156.249.229.199.zen.spamhaus.org",
- "answers":
- "data": "",
- "type": "NXDOMAIN"
- "type": "A",
- "request": "156.249.229.199.cbl.abuseat.org",
- "answers":
- "data": "",
- "type": "NXDOMAIN"
- "type": "A",
- "request": "156.249.229.199.b.barracudacentral.org",
- "answers":
- "data": "",
- "type": "NXDOMAIN"
- "type": "A",
- "request": "156.249.229.199.dnsbl-1.uceprotect.net",
- "answers":
- "data": "",
- "type": "NXDOMAIN"
- "type": "A",
- "request": "156.249.229.199.spam.dnsbl.sorbs.net",
- "answers":
- "data": "",
- "type": "NXDOMAIN"
- * Domains:
- "ip": "",
- "domain": "rx2ccivr73l4iheo.onion"
- "ip": "",
- "domain": "156.249.229.199.b.barracudacentral.org"
- "ip": "",
- "domain": "156.249.229.199.zen.spamhaus.org"
- "ip": "198.27.74.146",
- "domain": "wtfismyip.com"
- "ip": "",
- "domain": "156.249.229.199.dnsbl-1.uceprotect.net"
- "ip": "",
- "domain": "156.249.229.199.cbl.abuseat.org"
- "ip": "",
- "domain": "156.249.229.199.spam.dnsbl.sorbs.net"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 1,
- "body": "",
- "uri": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
- "user-agent": "Microsoft-CryptoAPI/6.1",
- "method": "GET",
- "host": "www.download.windowsupdate.com",
- "version": "1.1",
- "path": "/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
- "data": "GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1\r\nCache-Control: max-age = 86402\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: www.download.windowsupdate.com\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://wtfismyip.com/text",
- "user-agent": "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3282.140 Safari/537.36",
- "method": "GET",
- "host": "wtfismyip.com",
- "version": "1.1",
- "path": "/text",
- "data": "GET /text HTTP/1.1\r\nConnection: Keep-Alive\r\nUser-Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3282.140 Safari/537.36\r\nHost: wtfismyip.com\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://170.238.117.187:8082/tot521/Host_W617601.FFBDB1DD115115BB937FB733B7731919/83/",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "POST",
- "host": "170.238.117.187",
- "version": "1.1",
- "path": "/tot521/Host_W617601.FFBDB1DD115115BB937FB733B7731919/83/",
- "data": "POST /tot521/Host_W617601.FFBDB1DD115115BB937FB733B7731919/83/ HTTP/1.1\r\nAccept: */*\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: 170.238.117.187\r\nConnection: close\r\nContent-Type: multipart/form-data; boundary=---------WJBLGRMWGGOVKQFM\r\nContent-Length: 286\r\n\r\n",
- "port": 8082
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment