* MalFamily: "Malicious" * MalScore: 10.0 * File Name: "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe" * File Size: 262144 * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows" * SHA256: "492457aac92e1062ae1cc3c418213785c45df720cae496d1ea5b868b9534973f" * MD5: "4abb6f6cbd18258b9ef05083c2a817ca" * SHA1: "dac81dc149ff6e1520e97a9a1cb7147cfcc8db62" * SHA512: "5dca6f1eb7af8776f69c4ffdbe309eb5db5960cef1fd8f1103c923098ba3e1b83aa1a3822d5c5767826df024f302424075c3fdfeddd72430f40314a9be520240" * CRC32: "E34B7027" * SSDEEP: "6144:d1x036R3vGram/BAwFIjFCLHGMi1gNiVSAn:WAvGx/B2+Hk13VSi" * Process Execution: "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe", "cmd.exe", "sc.exe", "cmd.exe", "sc.exe", "cmd.exe", "powershell.exe", "cmd.exe", "powershell.exe", "cmd.exe", "powershell.exe", "cmd.exe", "powershell.exe", "cmd.exe", "powershell.exe", "cmd.exe", "powershell.exe", "cmd.exe", "powershell.exe", "cmd.exe", "powershell.exe", "cmd.exe", "powershell.exe", "cmd.exe", "powershell.exe", "svchost.exe", "services.exe", "lsass.exe" * Executed Commands: "cmd.exe /c sc stop WinDefend", "cmd.exe /c sc delete WinDefend", "cmd.exe /c powershell Set-MpPreference -DisableRealtimeMonitoring $true", "cmd.exe /c powershell Set-MpPreference -DisableBehaviorMonitoring $true", "cmd.exe /c powershell Set-MpPreference -DisableBlockAtFirstSeen $true", "cmd.exe /c powershell Set-MpPreference -DisableIOAVProtection $true", "cmd.exe /c powershell Set-MpPreference -DisablePrivacyMode $true", "cmd.exe /c powershell Set-MpPreference -DisableIntrusionPreventionSystem $true", "cmd.exe /c powershell Set-MpPreference -SevereThreatDefaultAction 6", "cmd.exe /c powershell Set-MpPreference -LowThreatDefaultAction 6", "cmd.exe /c powershell Set-MpPreference -ModerateThreatDefaultAction 6", "cmd.exe /c powershell Set-MpPreference -DisableScriptScanning $true", "C:\\Windows\\system32\\svchost.exe", "sc stop WinDefend", "sc delete WinDefend", "powershell Set-MpPreference -DisableRealtimeMonitoring $true", "powershell Set-MpPreference -DisableBehaviorMonitoring $true", "powershell Set-MpPreference -DisableBlockAtFirstSeen $true", "powershell Set-MpPreference -DisableIOAVProtection $true", "powershell Set-MpPreference -DisablePrivacyMode $true", "powershell Set-MpPreference -DisableIntrusionPreventionSystem $true", "powershell Set-MpPreference -SevereThreatDefaultAction 6", "powershell Set-MpPreference -LowThreatDefaultAction 6", "powershell Set-MpPreference -ModerateThreatDefaultAction 6", "powershell Set-MpPreference -DisableScriptScanning $true", "C:\\Windows\\system32\\lsass.exe" * Signatures Detected: "Description": "Creates RWX memory", "Details": "Description": "Possible date expiration check, exits too soon after checking local time", "Details": "process": "cmd.exe, PID 1388" "Description": "A process created a hidden window", "Details": "Process": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe -> cmd.exe" "Process": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe -> cmd.exe" "Process": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe -> cmd.exe" "Process": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe -> cmd.exe" "Process": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe -> cmd.exe" "Process": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe -> cmd.exe" "Process": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe -> cmd.exe" "Process": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe -> cmd.exe" "Process": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe -> cmd.exe" "Process": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe -> cmd.exe" "Process": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe -> cmd.exe" "Process": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe -> cmd.exe" "Description": "The binary likely contains encrypted or compressed data.", "Details": "section": "name: .rsrc, entropy: 7.95, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ, raw_size: 0x0002c000, virtual_size: 0x0002b318" "Description": "Attempts to stop active services", "Details": "servicename": "WinDefend" "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time", "Details": "Spam": "services.exe (504) called API GetSystemTimeAsFileTime 6951872 times" "Spam": "Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe (996) called API GetSystemTimeAsFileTime 258050 times" "Description": "Spoofs its process name and/or associated pathname to appear as a legitimate process", "Details": "modified_name": "svchost.exe", "modified_path": "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_4abb6f6cbd18258b9ef05083c2a817ca.exe", "original_name": "svchost.exe", "original_path": "C:\\Windows\\system32\\svchost.exe" "Description": "Creates a hidden or system file", "Details": "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF159bf79.TMP" "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a14cd.TMP" "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a0eb2.TMP" "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a1980.TMP" "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a1b55.TMP" "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF159c6ad.TMP" "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF159c96c.TMP" "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a310f.TMP" "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a2ac6.TMP" "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF159d1c9.TMP" "Description": "File has been identified by 16 Antiviruses on VirusTotal as malicious", "Details": "Cylance": "Unsafe" "APEX": "Malicious" "Paloalto": "generic.ml" "Kaspersky": "UDS:DangerousObject.Multi.Generic" "Avast": "FileRepMalware" "Endgame": "malicious (high confidence)" "Invincea": "heuristic" "Trapmine": "suspicious.low.ml.score" "FireEye": "Generic.mg.4abb6f6cbd18258b" "SentinelOne": "DFI - Malicious PE" "Webroot": "W32.Trojan.Gen" "ZoneAlarm": "UDS:DangerousObject.Multi.Generic" "Acronis": "suspicious" "AVG": "FileRepMalware" "Cybereason": "malicious.149ff6" "CrowdStrike": "win/malicious_confidence_100% (W)" "Description": "Attempts to disable Windows Defender", "Details": "Description": "Anomalous binary characteristics", "Details": "anomaly": "Actual checksum does not match that reported in PE header" * Started Service: "KeyIso" * Mutexes: "Global\\CLR_CASOFF_MUTEX", "Global\\838B6C9EB27932960" * Modified Files: "C:\\Users\\user\\AppData\\Local\\Temp\\~DF9E9A94CEC0F800E0.TMP", "C:\\Users\\user\\AppData\\Local\\Temp\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk", "\\??\\PIPE\\srvsvc", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\Y1R01JYAAU6PYWF6A9NP.temp", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF159bf79.TMP", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\X5RU8296LFZGT4JYT8Z8.temp", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a14cd.TMP", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\2MZ0E6IBYK0PB2HK0NXR.temp", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a0eb2.TMP", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\I43T9FF9NWS0K2OO74JP.temp", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a1980.TMP", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\IMOZBRXRCTBGLMXM1S3V.temp", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a1b55.TMP", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\DTN2ZYVS7LBLNM2K8OBB.temp", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF159c6ad.TMP", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\V4OFYM7F2JHWMO8O11LZ.temp", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF159c96c.TMP", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\C59O75REC3FEC7II02BN.temp", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a310f.TMP", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\7BL413FWRC2E1KHS2GAE.temp", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a2ac6.TMP", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\0TIXMJICD1WC20LJB6T8.temp", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF159d1c9.TMP" * Deleted Files: "C:\\Users\\user\\AppData\\Local\\Temp\\~DF9E9A94CEC0F800E0.TMP", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF159bf79.TMP", "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2396.22661015", "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2396.22661031", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2396.22661031", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a14cd.TMP", "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2404.22680890", "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2404.22680890", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2404.22680906", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a0eb2.TMP", "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2440.22679390", "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2440.22679406", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2440.22679406", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a1980.TMP", "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1168.22682593", "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1168.22682593", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1168.22682609", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a1b55.TMP", "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2304.22682859", "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2304.22682859", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2304.22682859", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF159c6ad.TMP", "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1776.22663250", "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1776.22663250", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1776.22663265", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF159c96c.TMP", "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1692.22664546", "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1692.22664546", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1692.22664546", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a310f.TMP", "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2676.22688125", "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2676.22688125", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2676.22688125", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF15a2ac6.TMP", "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1796.22686781", "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1796.22686781", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1796.22686781", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF159d1c9.TMP", "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.324.22668359", "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.324.22668375", "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.324.22668375" * Modified Registry Keys: "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\DisableAntiSpyware", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableBehaviorMonitoring", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableOnAccessProtection", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableScanOnRealtimeEnable", "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableIOAVProtection", "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList" * Deleted Registry Keys: * DNS Communications: * Domains: * Network Communication - ICMP: * Network Communication - HTTP: * Network Communication - SMTP: * Network Communication - Hosts: * Network Communication - IRC: