JohnGalt14

Sofacy Samples - and YARA matches

Jun 14th, 2016
776
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. Sample Hashes by PaloAltoNetworks
  2.  
  3. Loader Trojans
  4. c2551c4e6521ac72982cb952503a2e6f016356e02ee31dea36c713141d4f3785 (btecache.dll)
  5. be1cfa10fcf2668ae01b98579b345ebe87dab77b6b1581c368d1aba9fd2f10a0 (bitsprex3.dll)
  6. fbd5c2cf1c1f17402cc313fe3266b097a46e08f48b971570ef4667fbfd6b7301 (amdcache.dll)
  7. Payloads
  8. 69940a20ab9abb31a03fcefe6de92a16ed474bbdff3288498851afc12a834261 (svchost.dll)
  9. aeeab3272a2ed2157ebf67f74c00fafc787a2b9bbaa17a03be1e23d4cb273632 (clconfg.dll)
  10. dfa8a85e26c07a348a854130c652dcc6d29b203ee230ce0603c83d9f11bbcacc (iprpp.dll)
  11. 57d230ddaf92e2d0504e5bb12abf52062114fb8980c5ecc413116b1d6ffedf1b (clconfg.dll)
  12.  
  13.  
  14. New Sample Hashes matched by YARA Rules
  15.  
  16. 11cf6574961541ced1dc3c1272eac1b084a6b3ff928453025fff3584e536f638 - Sofacy_Jun16_Sample3 - FILE
  17. RESULT: 28 / 57
  18. 840fe27aa3630afd5c8e47f4941a5c50f202cce4336aec8e94f6551c98e6d465 - Sofacy_Jun16_Sample2 - FILE
  19. RESULT: 38 / 57
  20. 282ee91a7153ee3864fd9aaf2a147b7a3481cacf175c701d58d6b6ce83d7eb7b - Sofacy_Jun16_Sample1 - FILE
  21. RESULT: 30 / 57
  22. 11cf6574961541ced1dc3c1272eac1b084a6b3ff928453025fff3584e536f638 - Sofacy_Jun16_Sample2 - FILE
  23. RESULT: 28 / 57
  24. d028facf48b4c86c6b2fe978c086cfaec02235d7902cd0bfdcfb50751ec0ebc5 - Sofacy_Jun16_Sample2 - FILE
  25. RESULT: 2 / 56
  26. ecfce13aef2444e2d07edd8778a55156edab81f2406165efb6e25fe3dee96396 - Sofacy_Jun16_Sample2 - FILE
  27. RESULT: 10 / 56
  28. 840fe27aa3630afd5c8e47f4941a5c50f202cce4336aec8e94f6551c98e6d465 - Sofacy_Jun16_Sample1 - FILE
  29. RESULT: 38 / 57
RAW Paste Data