Advertisement
paladin316

814Exes_5079e284d0f37fbe9091bfaceac7e8cc_exe_2019-09-03_13_30.txt

Sep 3rd, 2019
1,321
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.30 KB | None | 0 0
  1.  
  2. * ID: 814
  3. * MalFamily: "7818210"
  4.  
  5. * MalScore: 6.5
  6.  
  7. * File Name: "Exes_5079e284d0f37fbe9091bfaceac7e8cc.exe"
  8. * File Size: 1507328
  9. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  10. * SHA256: "6e7e64ab1a86e9ddad6898422d0b1eac628711615509feaf8821f83b1742d236"
  11. * MD5: "5079e284d0f37fbe9091bfaceac7e8cc"
  12. * SHA1: "40dc5178cf4a4ef00059da0f9b5f1ab5d0970cd9"
  13. * SHA512: "4fcb34928194379c31df363c39385d33b0fceaa52f6169bce6f7e12ce7e447fefce6d482a04de36301e43f1b15ed30a3c74ae6ac1804f0bc6e48fa6b2abe197c"
  14. * CRC32: "D380B5C3"
  15. * SSDEEP: "24576:pr4dJ5dZtQsZvsUJNoQxEhiGS63aP/fJq8ossWT/Ppt:Z4dsUJNoQxEhiGba6g3"
  16.  
  17. * Process Execution:
  18. "5InSPoPU4FuG7.exe"
  19.  
  20.  
  21. * Executed Commands:
  22.  
  23. * Signatures Detected:
  24.  
  25. "Description": "SetUnhandledExceptionFilter detected (possible anti-debug)",
  26. "Details":
  27.  
  28.  
  29. "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
  30. "Details":
  31.  
  32. "IP_ioc": "61.164.121.170:80 (China)"
  33.  
  34.  
  35.  
  36.  
  37. "Description": "Operates on local firewall's policies and settings",
  38. "Details":
  39.  
  40.  
  41. "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
  42. "Details":
  43.  
  44. "target": "clamav:Win.Trojan.7818210-1, sha256:6e7e64ab1a86e9ddad6898422d0b1eac628711615509feaf8821f83b1742d236, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  45.  
  46.  
  47.  
  48.  
  49.  
  50. * Started Service:
  51.  
  52. * Mutexes:
  53. "CicLoadWinStaWinSta0",
  54. "Local\\MSCTF.CtfMonitorInstMutexDefault1",
  55. "DBWinMutex"
  56.  
  57.  
  58. * Modified Files:
  59.  
  60. * Deleted Files:
  61.  
  62. * Modified Registry Keys:
  63. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Services\\SharedAccess\\Parameters\\FirewallPolicy\\StandardProfile\\AuthorizedApplications\\List",
  64. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Parameters\\FirewallPolicy\\StandardProfile\\AuthorizedApplications\\List\\C:\\Users\\user\\AppData\\Local\\Temp\\5InSPoPU4FuG7.exe"
  65.  
  66.  
  67. * Deleted Registry Keys:
  68.  
  69. * DNS Communications:
  70.  
  71. * Domains:
  72.  
  73. * Network Communication - ICMP:
  74.  
  75. * Network Communication - HTTP:
  76.  
  77. * Network Communication - SMTP:
  78.  
  79. * Network Communication - Hosts:
  80.  
  81. "country_name": "China",
  82. "ip": "61.164.121.170",
  83. "inaddrarpa": "",
  84. "hostname": ""
  85.  
  86.  
  87.  
  88. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement