Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Trojan-Spy"
- * MalScore: 10.0
- * File Name: "Exes_a8d9a1d74d75111d1248932e13545a5d.exe"
- * File Size: 5305344
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "879523f2cda97b07264db07a9526739963580f90873661cb8095a52e658c3b0b"
- * MD5: "a8d9a1d74d75111d1248932e13545a5d"
- * SHA1: "5417801bbc6287cfd25836ddb113f1c5b2f7b206"
- * SHA512: "74d7f636161f5a8d43c5da388ffc0a681f2887c1182f63063b4f49817090e7777450cba21bba483173b3097f9e3dc8cd68c12bc5991bfa63da3d52e54de1febe"
- * CRC32: "725F64AE"
- * SSDEEP: "98304:C6S04JiyezT7eryCPgwabn59AGKjr8d/sQxPGoBwzD:C6SLu7XCPgLbn0GE2VxPjBw"
- * Process Execution:
- "Exes_a8d9a1d74d75111d1248932e13545a5d.exe"
- * Executed Commands:
- * Signatures Detected:
- "Description": "Creates RWX memory",
- "Details":
- "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
- "Details":
- "post_no_referer": "HTTP traffic contains a POST request with no referer header"
- "suspicious_request": "http://ck60174.tmweb.ru/api/gate.get?p1=0&p2=6&p3=0&p4=0&p5=0&p6=0&p7=0"
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://ck60174.tmweb.ru/api/gate.get?p1=0&p2=6&p3=0&p4=0&p5=0&p6=0&p7=0"
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details":
- "section": "name: :::%%;%\\xe2, entropy: 7.96, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ, raw_size: 0x0050ee00, virtual_size: 0x0050ec50"
- "Description": "Tries to suspend Cuckoo threads to prevent logging of malicious activity",
- "Details":
- "Process": "Exes_a8d9a1d74d75111d1248932e13545a5d.exe (2988)"
- "Description": "Tries to unhook or modify Windows functions monitored by Cuckoo",
- "Details":
- "unhook": "function_name: NtProtectVirtualMemory, type: modification"
- "Description": "Steals private information from local Internet browsers",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Web Data"
- "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cookies"
- "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data"
- "Description": "File has been identified by 29 Antiviruses on VirusTotal as malicious",
- "Details":
- "FireEye": "Generic.mg.a8d9a1d74d75111d"
- "McAfee": "Artemis!A8D9A1D74D75"
- "K7GW": "Riskware ( 0040eff71 )"
- "Cybereason": "malicious.bbc628"
- "Symantec": "ML.Attribute.HighConfidence"
- "APEX": "Malicious"
- "Paloalto": "generic.ml"
- "Kaspersky": "Trojan-Spy.Win32.Stealer.oci"
- "BitDefender": "Trojan.GenericKD.41549755"
- "Ad-Aware": "Trojan.GenericKD.41549755"
- "Emsisoft": "Trojan.GenericKD.41549755 (B)"
- "F-Secure": "Heuristic.HEUR/AGEN.1021811"
- "DrWeb": "Trojan.PWS.Siggen2.27019"
- "Invincea": "heuristic"
- "McAfee-GW-Edition": "BehavesLike.Win32.Ransomware.tc"
- "Sophos": "Mal/Generic-S"
- "SentinelOne": "DFI - Malicious PE"
- "Avira": "HEUR/AGEN.1021811"
- "Microsoft": "Trojan:Win32/Tiggre!plock"
- "Endgame": "malicious (high confidence)"
- "ZoneAlarm": "Trojan-Spy.Win32.Stealer.oci"
- "AhnLab-V3": "Malware/Win32.Generic.C2732586"
- "Acronis": "suspicious"
- "MAX": "malware (ai score=88)"
- "ESET-NOD32": "a variant of Generik.IXEOTTH"
- "Rising": "[email protected] (RDML:xfnN6RPeobUDo5A5KlYWlw)"
- "eGambit": "Unsafe.AI_Score_68%"
- "Qihoo-360": "Win32/Trojan.Spy.092"
- "CrowdStrike": "win/malicious_confidence_100% (W)"
- "Description": "Attempts to access Bitcoin/ALTCoin wallets",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Roaming\\Electrum\\wallets\\*"
- "file": "C:\\Users\\user\\AppData\\Roaming\\bytecoin\\*.wallet"
- "Description": "Harvests credentials from local FTP client softwares",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Roaming\\FileZilla\\sitemanager.xml"
- "file": "C:\\Users\\user\\AppData\\Roaming\\FileZilla\\recentservers.xml"
- "Description": "Anomalous binary characteristics",
- "Details":
- "anomaly": "Found duplicated section names"
- "anomaly": "Unprintable characters found in section name"
- * Started Service:
- * Mutexes:
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\a8aw6353.txt",
- "C:\\Users\\user\\AppData\\Roaming\\pts2X2R2R4T2R\\General\\cookies.txt",
- "C:\\Users\\user\\AppData\\Roaming\\pts2X2R2R4T2R\\General\\passwords.txt",
- "C:\\Users\\user\\AppData\\Roaming\\pts2X2R2R4T2R\\General\\cards.txt",
- "C:\\Users\\user\\AppData\\Roaming\\pts2X2R2R4T2R\\General\\forms.txt",
- "C:\\Users\\user\\AppData\\Roaming\\pts2X2R2R4T2R\\Desktop\\.doc",
- "C:\\Users\\user\\AppData\\Roaming\\pts2X2R2R4T2R\\Desktop\\.docx",
- "C:\\Users\\user\\AppData\\Roaming\\pts2X2R2R4T2R\\Infomation.txt",
- "C:\\Users\\user\\AppData\\Roaming\\pts2X2R2R4T2R\\Screenshot.bmp",
- "C:\\Users\\user\\AppData\\Roaming\\arc2X2R2R4T2R.zip"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\a8aw6353.txt",
- "C:\\Users\\user\\AppData\\Roaming\\pts2X2R2R4T2R\\Telegram",
- "C:\\Users\\user\\AppData\\Roaming\\pts2X2R2R4T2R\\Discord",
- "C:\\Users\\user\\AppData\\Roaming\\pts2X2R2R4T2R\\Steam",
- "C:\\Users\\user\\AppData\\Roaming\\pts2X2R2R4T2R\\Wallets2",
- "C:\\Users\\user\\AppData\\Roaming\\pts2X2R2R4T2R\\Wallets1",
- "C:\\Users\\user\\AppData\\Roaming\\pts2X2R2R4T2R\\Desktop",
- "C:\\Users\\user\\AppData\\Roaming\\pts2X2R2R4T2R\\General\\cards.txt",
- "C:\\Users\\user\\AppData\\Roaming\\pts2X2R2R4T2R\\General\\cookies.txt",
- "C:\\Users\\user\\AppData\\Roaming\\pts2X2R2R4T2R\\General\\forms.txt",
- "C:\\Users\\user\\AppData\\Roaming\\pts2X2R2R4T2R\\General\\passwords.txt",
- "C:\\Users\\user\\AppData\\Roaming\\pts2X2R2R4T2R\\General",
- "C:\\Users\\user\\AppData\\Roaming\\pts2X2R2R4T2R\\Infomation.txt",
- "C:\\Users\\user\\AppData\\Roaming\\pts2X2R2R4T2R\\Screenshot.bmp",
- "C:\\Users\\user\\AppData\\Roaming\\pts2X2R2R4T2R",
- "C:\\Users\\user\\AppData\\Roaming\\arc2X2R2R4T2R.zip"
- * Modified Registry Keys:
- * Deleted Registry Keys:
- * DNS Communications:
- "type": "A",
- "request": "ck60174.tmweb.ru",
- "answers":
- "data": "92.53.96.129",
- "type": "A"
- * Domains:
- "ip": "92.53.96.129",
- "domain": "ck60174.tmweb.ru"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 1,
- "body": "",
- "uri": "http://ck60174.tmweb.ru/api/gate.get?p1=0&p2=6&p3=0&p4=0&p5=0&p6=0&p7=0",
- "user-agent": "Mozilla/5.0 (Windows NT 6.1; rv:31.0) Gecko/20100101 Firefox/31.0",
- "method": "POST",
- "host": "ck60174.tmweb.ru",
- "version": "1.1",
- "path": "/api/gate.get?p1=0&p2=6&p3=0&p4=0&p5=0&p6=0&p7=0",
- "data": "POST /api/gate.get?p1=0&p2=6&p3=0&p4=0&p5=0&p6=0&p7=0 HTTP/1.1\r\nContent-Type: multipart/form-data; boundary=---------------------------7\r\nUser-Agent: Mozilla/5.0 (Windows NT 6.1; rv:31.0) Gecko/20100101 Firefox/31.0\r\nHost: ck60174.tmweb.ru\r\nContent-Length: 116222\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
- "port": 80
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment