paladin316

Exes_26a84232904de9d74f5f5a31e47ba264_exe_2019-07-11_20_30.txt

Jul 11th, 2019
2,069
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.29 KB | None | 0 0
  1.  
  2. * MalFamily: ""
  3.  
  4. * MalScore: 7.8999999999999995
  5.  
  6. * File Name: "Exes_26a84232904de9d74f5f5a31e47ba264.exe"
  7. * File Size: 1257441
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "a8d3b68c1e43f6ab3aa011b3a4ac96a6e1596d9a5e7c480e14e71fbc23e94794"
  10. * MD5: "26a84232904de9d74f5f5a31e47ba264"
  11. * SHA1: "545edc22d93c9c9139ecc6fddb170edcf0013020"
  12. * SHA512: "26dfcb09f8a93efb674c4727d81695a4c8b66495b60cfb3f92313e699a0faa57ed61153a566d46384c7c06424ad92cd6abb85ad12229ddc2029d883120ac8fed"
  13. * CRC32: "BC0F4573"
  14. * SSDEEP: "24576:ZHweKjzGnwz7xb63NYkPMDHKK5HAw4JCIw0hJyvb:ZHQgwz7xASKYKCssj"
  15.  
  16. * Process Execution:
  17. "Exes_26a84232904de9d74f5f5a31e47ba264.exe",
  18. "svchost.exe",
  19. "cmd.exe",
  20. "PING.EXE"
  21.  
  22.  
  23. * Executed Commands:
  24. "C:\\Windows\\syswow64\\svchost.exe -k NetTimeSvc",
  25. "C:\\Users\\user\\AppData\\Local\\Temp\\4094.bat ",
  26. "C:\\Windows\\system32\\PING.EXE ping 1.0.0.1 -n"
  27.  
  28.  
  29. * Signatures Detected:
  30.  
  31. "Description": "Attempts to connect to a dead IP:Port (2 unique times)",
  32. "Details":
  33.  
  34. "IP": "134.175.107.117:80"
  35.  
  36.  
  37. "IP": "118.25.165.228:443"
  38.  
  39.  
  40.  
  41.  
  42. "Description": "Creates RWX memory",
  43. "Details":
  44.  
  45.  
  46. "Description": "Possible date expiration check, exits too soon after checking local time",
  47. "Details":
  48.  
  49. "process": "Exes_26a84232904de9d74f5f5a31e47ba264.exe, PID 1840"
  50.  
  51.  
  52.  
  53.  
  54. "Description": "Network anomalies occured during the analysis.",
  55. "Details":
  56.  
  57. "Anomaly": "'1.0.0.1' getaddrinfo with no actual connection to the IP."
  58.  
  59.  
  60.  
  61.  
  62. "Description": "Starts servers listening on 127.0.0.1:54323",
  63. "Details":
  64.  
  65.  
  66. "Description": "A process created a hidden window",
  67. "Details":
  68.  
  69. "Process": "Exes_26a84232904de9d74f5f5a31e47ba264.exe -> C:\\Users\\user\\AppData\\Local\\Temp\\4094.bat"
  70.  
  71.  
  72.  
  73.  
  74. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  75. "Details":
  76.  
  77. "post_no_referer": "HTTP traffic contains a POST request with no referer header"
  78.  
  79.  
  80. "post_no_useragent": "HTTP traffic contains a POST request with no user-agent header"
  81.  
  82.  
  83. "suspicious_request": "http://aol.vready.cn/terminal/start-up"
  84.  
  85.  
  86.  
  87.  
  88. "Description": "Performs some HTTP requests",
  89. "Details":
  90.  
  91. "url": "http://aol.vready.cn/terminal/start-up"
  92.  
  93.  
  94.  
  95.  
  96. "Description": "The binary likely contains encrypted or compressed data.",
  97. "Details":
  98.  
  99. "section": "name: .rsrc, entropy: 8.00, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00132de1, virtual_size: 0x0013a000"
  100.  
  101.  
  102.  
  103.  
  104. "Description": "Deletes its original binary from disk",
  105. "Details":
  106.  
  107.  
  108.  
  109. * Started Service:
  110.  
  111. * Mutexes:
  112. "Guid(\"0A5D06B2-E8F1-42D1-B3AA-37D7C7174633\")",
  113. "B8592103-AE8C-4D37-807F-F1CB76E62B7C",
  114. "Guid(\"7583B8C3-2691-4F51-A989-D622AAC8508A\")",
  115. "DBWinMutex"
  116.  
  117.  
  118. * Modified Files:
  119. "C:\\Windows\\System32\\ejxve32.dll",
  120. "C:\\Users\\user\\AppData\\Local\\Temp\\4094.bat",
  121. "C:\\Users\\user\\AppData\\Local\\Temp\\axnxhr.dll",
  122. "C:\\Users\\user\\AppData\\Local\\Temp\\jhxoeulb.dll",
  123. "C:\\Users\\user\\AppData\\Local\\Temp\\RCXD79F.tmp",
  124. "\\??\\nul"
  125.  
  126.  
  127. * Deleted Files:
  128. "C:\\Users\\user\\AppData\\Local\\Temp\\jhxoeulb.dll",
  129. "C:\\Users\\user\\AppData\\Local\\Temp\\RCXD79F.tmp",
  130. "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_26a84232904de9d74f5f5a31e47ba264.exe",
  131. "C:\\Users\\user\\AppData\\Local\\Temp\\4094.bat"
  132.  
  133.  
  134. * Modified Registry Keys:
  135.  
  136. * Deleted Registry Keys:
  137.  
  138. * DNS Communications:
  139.  
  140. "type": "A",
  141. "request": "v2api.v6.cn",
  142. "answers":
  143.  
  144. "data": "118.25.165.228",
  145. "type": "A"
  146.  
  147.  
  148.  
  149.  
  150. "type": "A",
  151. "request": "aol.vready.cn",
  152. "answers":
  153.  
  154. "data": "134.175.107.117",
  155. "type": "A"
  156.  
  157.  
  158.  
  159.  
  160.  
  161. * Domains:
  162.  
  163. "ip": "118.25.165.228",
  164. "domain": "v2api.v6.cn"
  165.  
  166.  
  167. "ip": "134.175.107.117",
  168. "domain": "aol.vready.cn"
  169.  
  170.  
  171.  
  172. * Network Communication - ICMP:
  173.  
  174. * Network Communication - HTTP:
  175.  
  176. "count": 1,
  177. "body": "channel_id=ttzxj15&mac=18-C0-86-CD-47-32&ip=169.254.255.254
  178. "uri": "http://aol.vready.cn/terminal/start-up",
  179. "user-agent": "",
  180. "method": "POST",
  181. "host": "aol.vready.cn",
  182. "version": "1.1",
  183. "path": "/terminal/start-up",
  184. "data": "POST /terminal/start-up HTTP/1.1\r\nHost: aol.vready.cn\r\nAccept: */*\r\nContent-Length: 58\r\nContent-Type: application/x-www-form-urlencoded\r\n\r\nchannel_id=ttzxj15&mac=18-C0-86-CD-47-32&ip=169.254.255.254
  185. "port": 80
  186.  
  187.  
  188.  
  189. * Network Communication - SMTP:
  190.  
  191. * Network Communication - Hosts:
  192.  
  193. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment