Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Ursu"
- * MalScore: 10.0
- * File Name: "Exes_fcf772d159147aaa04791668a4ed7487.exe"
- * File Size: 1036288
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "1521af8cb9bffe945a972a6ff36d8c8d33f34fbb5b7024b8e11ae8fb9e0723bb"
- * MD5: "fcf772d159147aaa04791668a4ed7487"
- * SHA1: "fac3451fcf0cc19bf78a9f51390005b4a5cf7535"
- * SHA512: "e87b1aa7502c779c90cdb45fca4ed8577fb310b76db9fccffafc6239384c5415b1080e45e938ae3a926fa1482fac7f5338e4786cab734cf29894ded28b95a1f8"
- * CRC32: "F3906F21"
- * SSDEEP: "3072:RIxCHOTNNHkCFVxVHlKEZHpfbrH7Ny0S550S5BDbjZrScpO0S5:gNHDbVrH7+5d5BP85"
- * Process Execution:
- "Exes_fcf772d159147aaa04791668a4ed7487.exe"
- * Executed Commands:
- "\\x01C:\\Users\\user\\AppData\\Local\\Temp\\Exes_fcf772d159147aaa04791668a4ed7487.exe\""
- * Signatures Detected:
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
- "Details":
- "Spam": "Exes_fcf772d159147aaa04791668a4ed7487.exe (2936) called API CreateProcessInternalW 36326 times"
- "Description": "File has been identified by 18 Antiviruses on VirusTotal as malicious",
- "Details":
- "MicroWorld-eScan": "Gen:Variant.Ursu.432882"
- "FireEye": "Generic.mg.fcf772d159147aaa"
- "Cylance": "Unsafe"
- "Arcabit": "Trojan.Ursu.D69AF2"
- "Symantec": "Packed.Generic.535"
- "APEX": "Malicious"
- "BitDefender": "Gen:Variant.Ursu.432882"
- "Ad-Aware": "Gen:Variant.Ursu.432882"
- "Emsisoft": "Gen:Variant.Ursu.432882 (B)"
- "Invincea": "heuristic"
- "SentinelOne": "DFI - Suspicious PE"
- "MAX": "malware (ai score=84)"
- "Microsoft": "Trojan:Win32/Wacatac.B!ml"
- "GData": "Gen:Variant.Ursu.432882"
- "ALYac": "Gen:Variant.Ursu.432882"
- "Rising": "Trojan.Injector!1.B459 (CLASSIC)"
- "Cybereason": "malicious.159147"
- "Qihoo-360": "HEUR/QVM03.0.767D.Malware.Gen"
- * Started Service:
- * Mutexes:
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFB65F00A146BA7A52.TMP"
- * Deleted Files:
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\VB and VBA Program Settings\\HPi2l99936527\\r60zd1913765515",
- "HKEY_CURRENT_USER\\Software\\VB and VBA Program Settings\\HPi2l99936527\\r60zd1913765515\\AkVa141448139",
- "HKEY_CURRENT_USER\\Software\\VB and VBA Program Settings\\qd9501393393686\\WOSz52047232977",
- "HKEY_CURRENT_USER\\Software\\VB and VBA Program Settings\\qd9501393393686\\WOSz52047232977\\MI7u4219069669",
- "HKEY_CURRENT_USER\\Software\\VB and VBA Program Settings\\HJjIt1619207862\\WW25T1621554722",
- "HKEY_CURRENT_USER\\Software\\VB and VBA Program Settings\\HJjIt1619207862\\WW25T1621554722\\Em3ms148370"
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment