Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Neshuta"
- * MalScore: 10.0
- * File Name: "Exes_21f481135adc34af1779a6dde07f6801.exe"
- * File Size: 456192
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "38f0be9c3b7565a2cfc9d8b9bbe3fa342d5e7d0bbf88c3154636609cd70e0b8b"
- * MD5: "21f481135adc34af1779a6dde07f6801"
- * SHA1: "6eaa78261cc746a3a55354427a717bfcf3017d45"
- * SHA512: "2748f3cd99fd87a5fd69d4d466b21f3a4aca27ee45906cfbdc79da4e3c5ca85ef321345f434b219adf2a34581fe5976ee723adc713bee93874700a134626e438"
- * CRC32: "1A2ED2E4"
- * SSDEEP: "6144:k94PxlKYdLbifc5kHCqVCO7ZVG/gRTVO7ElovxiaV2sFVUFEXJGeUt/UgoLl/czf:LFufDCqcEGuVhoxiaV/TUFO6/jw7y"
- * Process Execution:
- "Exes_21f481135adc34af1779a6dde07f6801.exe",
- "Exes_21f481135adc34af1779a6dde07f6801.exe"
- * Executed Commands:
- "C:\\Users\\user\\AppData\\Local\\Temp\\3582-490\\Exes_21f481135adc34af1779a6dde07f6801.exe "
- * Signatures Detected:
- "Description": "Possible date expiration check, exits too soon after checking local time",
- "Details":
- "process": "Exes_21f481135adc34af1779a6dde07f6801.exe, PID 1960"
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: Exes_21f481135adc34af1779a6dde07f6801.exe, pid: 1960, offset: 0x00000000, length: 0x0006f600"
- "Description": "Drops a binary and executes it",
- "Details":
- "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\3582-490\\Exes_21f481135adc34af1779a6dde07f6801.exe"
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\(Default)"
- "data": "C:\\Windows\\svchost.com \"%1\" %*"
- "Description": "Likely virus infection of existing system binary",
- "Details":
- "file": "c:\\python27\\lib\\site-packages\\pip\\_vendor\\distlib\\w64.exe"
- "file": "c:\\python27\\lib\\site-packages\\pip\\_vendor\\distlib\\w32.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\distutils\\command\\wininst-8.0.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\iecontentservice.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\namecontrolserver.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\ocpubmgr.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\msohtmed.exe"
- "file": "c:\\python27\\lib\\distutils\\command\\wininst-9.0.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\xlicons.exe"
- "file": "c:\\program files (x86)\\google\\chrome\\application\\chrome_proxy.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\site-packages\\pip\\_vendor\\distlib\\w64.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\accicons.exe"
- "file": "c:\\users\\user\\appdata\\local\\microsoft\\onedrive\\17.3.4604.0120\\onedrivesetup.exe"
- "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\acrobroker.exe"
- "file": "c:\\program files (x86)\\common files\\microsoft shared\\office15\\msosqm.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\clview.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\site-packages\\setuptools\\gui.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\onenotem.exe"
- "file": "c:\\program files (x86)\\common files\\java\\java update\\jusched.exe"
- "file": "c:\\program files (x86)\\google\\update\\google_disabled_update.exe"
- "file": "c:\\program files (x86)\\common files\\microsoft shared\\source engine\\ose.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\venv\\scripts\\nt\\pythonw.exe"
- "file": "c:\\program files (x86)\\microsoft analysis services\\as oledb\\110\\sqldumper.exe"
- "file": "c:\\program files (x86)\\google\\update\\1.3.34.11\\googledisabledupdatesetup.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\distutils\\command\\wininst-9.0-amd64.exe"
- "file": "c:\\program files (x86)\\common files\\microsoft shared\\office15\\office setup controller\\setup.exe"
- "file": "c:\\program files (x86)\\common files\\oracle\\java\\javapath\\javaws.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\scripts\\easy_install.exe"
- "file": "c:\\users\\user\\volumeid.exe"
- "file": "c:\\program files (x86)\\google\\update\\1.3.34.11\\googledisabledupdatecore.exe"
- "file": "c:\\program files (x86)\\common files\\microsoft shared\\office15\\fltldr.exe"
- "file": "c:\\msocache\\all users\\91150000-0011-0000-0000-0000000ff1ce-c\\ose.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\pptico.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\dcf\\filecompare.exe"
- "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\acrord32.exe"
- "file": "c:\\program files (x86)\\common files\\microsoft shared\\office15\\liclua.exe"
- "file": "c:\\python27\\lib\\site-packages\\pip\\_vendor\\distlib\\t64.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\setlang.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\site-packages\\setuptools\\cli-64.exe"
- "file": "c:\\python27\\lib\\site-packages\\setuptools\\cli-64.exe"
- "file": "c:\\program files (x86)\\common files\\microsoft shared\\dw\\dw20.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\vpreview.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\site-packages\\setuptools\\gui-64.exe"
- "file": "c:\\python27\\scripts\\pip2.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\msosync.exe"
- "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\eula.exe"
- "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\adelrcp.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\distutils\\command\\wininst-9.0.exe"
- "file": "c:\\program files (x86)\\google\\update\\download\\430fd4d0-b729-4f61-aa34-91526481799d\\1.3.34.11\\googleupdatesetup.exe"
- "file": "c:\\python27\\scripts\\easy_install.exe"
- "file": "c:\\program files (x86)\\common files\\microsoft shared\\vsto\\10.0\\vstoinstaller.exe"
- "file": "c:\\program files (x86)\\common files\\microsoft shared\\equation\\eqnedt32.exe"
- "file": "c:\\python27\\lib\\site-packages\\setuptools\\gui-32.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\misc.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\ucmapi.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\scripts\\easy_install-3.7.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\dcf\\databasecompare.exe"
- "file": "c:\\users\\user\\appdata\\local\\microsoft\\onedrive\\17.3.4604.0120\\filesyncconfig.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\site-packages\\pip\\_vendor\\distlib\\t32.exe"
- "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\fulltrustnotifier.exe"
- "file": "c:\\users\\user\\appdata\\local\\microsoft\\onedrive\\17.3.4604.0120_1\\onedrivesetup.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\distutils\\command\\wininst-10.0-amd64.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\graph.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\msqry32.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\distutils\\command\\wininst-14.0.exe"
- "file": "c:\\program files (x86)\\google\\chrome\\application\\chrome.exe"
- "file": "c:\\python27\\removepil.exe"
- "file": "c:\\users\\user\\appdata\\local\\microsoft\\onedrive\\onedrive.exe"
- "file": "c:\\program files (x86)\\google\\update\\1.3.34.11\\googledisabledupdatewebplugin.exe"
- "file": "c:\\program files (x86)\\google\\update\\1.3.34.11\\googlecrashhandler64.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\site-packages\\setuptools\\cli-32.exe"
- "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\acrotextextractor.exe"
- "file": "c:\\programdata\\adobe\\setup\\ac76ba86-7ad7-1033-7b44-ac0f074e4100\\setup.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\site-packages\\setuptools\\gui-32.exe"
- "file": "c:\\python27\\lib\\distutils\\command\\wininst-7.1.exe"
- "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\logtransport2.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\distutils\\command\\wininst-14.0-amd64.exe"
- "file": "c:\\program files (x86)\\google\\update\\1.3.34.11\\googledisabledupdatebroker.exe"
- "file": "c:\\python27\\w9xpopen.exe"
- "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\plug_ins\\pi_brokers\\32bitmapibroker.exe"
- "file": "c:\\users\\user\\appdata\\local\\apps\\2.0\\z0gkgt47.zk6\\lg8n4v75.0o7\\clic...exe_9ae46cec200785df_0001.0003_none_a8944a4a5d6278ab\\googleupdatesetup.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\cnfnot32.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\pythonw.exe"
- "file": "c:\\program files (x86)\\common files\\oracle\\java\\javapath\\javaw.exe"
- "file": "c:\\program files (x86)\\common files\\microsoft shared\\office15\\office setup controller\\odeploy.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\venv\\scripts\\nt\\python.exe"
- "file": "c:\\python27\\lib\\site-packages\\setuptools\\cli.exe"
- "file": "c:\\program files (x86)\\common files\\microsoft shared\\office15\\olicenseheartbeat.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\site-packages\\setuptools\\cli.exe"
- "file": "c:\\program files (x86)\\google\\update\\1.3.34.11\\googledisabledupdatecomregistershell64.exe"
- "file": "c:\\program files (x86)\\google\\chrome\\application\\74.0.3729.169\\installer\\setup.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\site-packages\\pip\\_vendor\\distlib\\w32.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\python.exe"
- "file": "c:\\program files (x86)\\common files\\adobe\\arm\\1.0\\adobearm.exe"
- "file": "c:\\program files (x86)\\google\\chrome\\application\\74.0.3729.169\\elevation_service.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\scripts\\pip.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\scripts\\pip3.7.exe"
- "file": "c:\\program files (x86)\\common files\\microsoft shared\\office15\\oarpmany.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\pdfreflow.exe"
- "file": "c:\\users\\user\\devmanview.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\powerpnt.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\dcf\\spreadsheetcompare.exe"
- "file": "c:\\program files (x86)\\common files\\microsoft shared\\office15\\msoxmled.exe"
- "file": "c:\\program files (x86)\\common files\\microsoft shared\\dw\\dwtrig20.exe"
- "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\acrocef\\rdrcef.exe"
- "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\arh.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\protocolhandler.exe"
- "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\reader_sl.exe"
- "file": "c:\\python27\\scripts\\pip.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\firstrun.exe"
- "file": "c:\\program files (x86)\\common files\\adobe\\arm\\1.0\\adobearmhelper.exe"
- "file": "c:\\program files (x86)\\common files\\microsoft shared\\office15\\csisyncclient.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\site-packages\\pip\\_vendor\\distlib\\t64.exe"
- "file": "c:\\program files (x86)\\google\\chrome\\application\\74.0.3729.169\\installer\\chrmstp.exe"
- "file": "c:\\program files (x86)\\google\\update\\1.3.34.11\\googledisabledupdateondemand.exe"
- "file": "c:\\python27\\lib\\site-packages\\pip\\_vendor\\distlib\\t32.exe"
- "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\wow_helper.exe"
- "file": "c:\\program files (x86)\\common files\\java\\java update\\jaureg.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\onenote.exe"
- "file": "c:\\python27\\lib\\distutils\\command\\wininst-9.0-amd64.exe"
- "file": "c:\\python27\\scripts\\pip2.7.exe"
- "file": "c:\\users\\user\\appdata\\local\\microsoft\\onedrive\\17.3.4604.0120_1\\filesyncconfig.exe"
- "file": "c:\\program files (x86)\\google\\update\\1.3.34.11\\googlecrashhandler.exe"
- "file": "c:\\users\\user\\appdata\\local\\package cache\\c0f1e976-f585-48f8-968d-48c870496d4e\\python-3.7.2-amd64.exe"
- "file": "c:\\msocache\\all users\\91150000-0011-0000-0000-0000000ff1ce-c\\setup.exe"
- "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\plug_ins\\pi_brokers\\64bitmapibroker.exe"
- "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\browser\\wcchromeextn\\wcchromenativemessaginghost.exe"
- "file": "c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\adobecollabsync.exe"
- "file": "c:\\program files (x86)\\google\\chrome\\application\\74.0.3729.169\\notification_helper.exe"
- "file": "c:\\python27\\lib\\distutils\\command\\wininst-6.0.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\lynchtmlconv.exe"
- "file": "c:\\program files (x86)\\common files\\microsoft shared\\office15\\msoicons.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\wordicon.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\scripts\\pip3.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\infopath.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\msouc.exe"
- "file": "c:\\program files (x86)\\google\\update\\1.3.34.11\\google_disabledupdate.exe"
- "file": "c:\\programdata\\microsoft\\clicktorun\\9ac08e99-230b-47e8-9721-4577b7f124ea\\integrator.exe"
- "file": "c:\\program files (x86)\\common files\\microsoft shared\\office15\\cmigrate.exe"
- "file": "c:\\python27\\lib\\distutils\\command\\wininst-8.0.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\selfcert.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\winword.exe"
- "file": "c:\\python27\\scripts\\easy_install-2.7.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\distutils\\command\\wininst-10.0.exe"
- "file": "c:\\python27\\lib\\site-packages\\setuptools\\gui.exe"
- "file": "c:\\program files (x86)\\common files\\oracle\\java\\javapath\\java.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\distutils\\command\\wininst-7.1.exe"
- "file": "c:\\users\\user\\appdata\\local\\programs\\python\\python37\\lib\\distutils\\command\\wininst-6.0.exe"
- "file": "c:\\program files (x86)\\common files\\java\\java update\\jucheck.exe"
- "file": "c:\\program files (x86)\\microsoft onedrive\\onedrivesetup.exe"
- "file": "c:\\program files (x86)\\microsoft office\\office15\\groove.exe"
- "file": "c:\\python27\\lib\\site-packages\\setuptools\\cli-32.exe"
- "file": "c:\\python27\\lib\\site-packages\\setuptools\\gui-64.exe"
- "Description": "Detects VirtualBox through the presence of a file",
- "Details":
- "file": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vboxguest.inf_amd64_neutral_aaf5cae56df6be2b\\VBoxControl.exe"
- "file": "C:\\Program Files\\BLAOracle\\VirtualBox Guest Additions\\VBoxControl.exe"
- "file": "C:\\Windows\\System32\\DriverStore\\FileRepository\\vboxguest.inf_amd64_neutral_aaf5cae56df6be2b\\VBoxTray.exe"
- "file": "C:\\Program Files\\BLAOracle\\VirtualBox Guest Additions\\VBoxTray.exe"
- "file": "C:\\Program Files\\BLAOracle\\VirtualBox Guest Additions\\VBoxDrvInst.exe"
- "file": "C:\\Program Files\\BLAOracle\\VirtualBox Guest Additions\\VBoxWHQLFake.exe"
- "file": "C:\\Program Files\\BLAOracle\\VirtualBox Guest Additions\\VBoxControl.exe"
- "file": "C:\\Program Files\\BLAOracle\\VirtualBox Guest Additions\\VBoxWHQLFake.exe"
- "file": "C:\\Program Files\\BLAOracle\\VirtualBox Guest Additions\\uninst.exe"
- "file": "C:\\Program Files\\BLAOracle\\VirtualBox Guest Additions\\VBoxDrvInst.exe"
- "file": "C:\\Program Files\\BLAOracle\\VirtualBox Guest Additions\\VBoxTray.exe"
- "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
- "Details":
- "target": "clamav:Win.Trojan.Neshuta-1, sha256:38f0be9c3b7565a2cfc9d8b9bbe3fa342d5e7d0bbf88c3154636609cd70e0b8b, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:89afb02f331e50a5c8df5095de66437a8eb4deae194cd77f76cf11c32a161c46 , guest_paths:C:\\Users\\user\\DevManView.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:5c3ef3ec7594c040146e908014791dd15201ba58b4d70032770bb661b6a0e394 , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\Eula.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:869d5ca37263a7c0a59414ab38e4e501eff3cb8f1dbafc33c97aff1513cdf668 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSOUC.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:cb17794b3b15002bbb49ba23455dbb49abc6c1f68d616f1ae633fed3b7e817aa , guest_paths:C:\\Program Files (x86)\\Common Files\\Oracle\\Java\\javapath\\javaw.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:ded54d1fcca07b6bff2bc3b9a1131eac29ff1f836e5d7a7c5c325ec5abe96e29 , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroTextExtractor.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:ba3dc87fca4641e5f5486c4d50c09d087e65264e6c5c885fa6866f6ccb23167b , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\EQUATION\\EQNEDT32.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:28d8a9c50eca6f73bdea888d5132bf16ce87ad4f7b2dd2d10b2729fadc0fd5a9 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSOHTMED.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:31da9632f5d25806b77b617d48da52a14afc574bbe1653120f97705284ea566c , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroCEF\\RdrCEF.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:8384cb761b1a34ac1e4184b9e85d438b6ca6eeef19493b9ee5b568d280ee64ba , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\PPTICO.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:2ec470364d4c51ac8a55c18333a508117718774e13ce3d34af67566937ebadb4 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\GRAPH.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:75189debfc73a223a5297becd778b9d2710f3683c76db93ae40a62c5be42c56f , guest_paths:C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleDisabledUpdateWebPlugin.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:7615625c3f23c63f1ba25103f023f81379e124bee0852ee7bebb453e2782d30a , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\INFOPATH.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:5f0e4dd286b7e861c1b8c4ee60748b7881ab627c2f50495c35b6fa24cd92ee6f , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\MSOSQM.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:d6543117296029ed5f927a812b2269bfc3edcfceca7c3a4fb2c36ee6b8791fa1 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\CLVIEW.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:6c7fcba8eddbf20d3ccf97ec075d55ee7fea49140a7e9f5b36e96abaa6c5ab70 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\WINWORD.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:236f874e3627f1be2c597edf64b15c786c5d22bfcdeed410e6f3b1c0f0230fee , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\DW\\DWTRIG20.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:1586287394a7d5c1a0d52b256bb631961a4b05b873307c78896b79709e7713c9 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\UcMapi.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:f93f83c0cdf496ee620ed85075329c6f9e940956601a1b38022c5a74d07e74d0 , guest_paths:C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\Google_DisabledUpdate.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:8349368189fb5c09e4449650c692f7f87076f3767253654dc5ebcb4d16a4e407 , guest_paths:C:\\Program Files (x86)\\Microsoft Analysis Services\\AS OLEDB\\110\\SQLDumper.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:2c35c0c38ef5831080f331a8cb11f13d336fcaa54b816559d8a1807396de0ae8 , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\DW\\DW20.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:ae631ff5c823943333c015767bf2f75120bd3eaee6dc4300145546d842cf4b4e , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\FIRSTRUN.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:5546be6a6bf4550c1474d6a0770e5d71dc724faf869e1cb73a08baf2ecf1a6a4 , guest_paths:C:\\Program Files (x86)\\Google\\Chrome\\Application\\74.0.3729.169\\elevation_service.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:53c581cd602c26a0a2e083526ae542134b190f5af5def89373a4023d22b06cef , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\SETLANG.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:7b945c7e6b8bfbb489f003ecd1d0dcd4803042003de4646d4206114361a0fbbb , guest_paths:C:\\ProgramData\\Adobe\\Setup\\AC76BA86-7AD7-1033-7B44-AC0F074E4100\\setup.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:4c7ff6812cb9f902f41fc4bfdfbd3957f513089476317344bec3d450f2fb1e77 , guest_paths:C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleDisabledUpdateCore.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:81210303bcc7d17cdaaab8127a21fbb63546c14b0d500eda041003a6da838aaa , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\protocolhandler.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:fe56a759976a51d32dac5beb3007d46ec0d33e039ed3f9db153706ba53384764 , guest_paths:C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:efd423639bfc9e29a2b2c5a67379129f13ff526b800dff8ab59bfc618c3f48bd , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\LICLUA.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:8c00a5ad372e9640237170a81091c68d277c84ac87cbac160d93e3a2292773d1 , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AdobeCollabSync.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:ca4925b76cbf600bb139f1e0ea0d1dd41f3f6a624c5db4183e2b21f321f120e2 , guest_paths:C:\\Program Files (x86)\\Google\\Update\\Google_Disabled_Update.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:04f5259484d61831754af098e42d147c25d61f692a6da69bb88e2f01bf7c1679 , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\VSTO\\10.0\\VSTOInstaller.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:e5691950da34f55769713edbf363e0fbb30ad4033adff24274de064c6a4b2d2e , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\POWERPNT.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:b3c7e32e6d1c27bc9e67060e68acd8ccfe46e44c48a210d00a0d6cae09421ff8 , guest_paths:C:\\Program Files (x86)\\Google\\Chrome\\Application\\74.0.3729.169\\notification_helper.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:7f61f059580b9725b0958e03680d47c810c9b8a2a9ea2560efe96e9231923227 , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\MSOICONS.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:f007e668f327693c4b383dfc9f4182ff594e9567919599060566e3cb400ad3ef , guest_paths:C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleDisabledUpdateBroker.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:4282942497c44db2858e9c87133df1ad38a141bc6b537dc39b2d8f416bf68d4c , guest_paths:C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jaureg.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:e09f9db05d7d0d7290b75a57d3ef039671403dea5129d1d4ba2c92da3f3b4a9e , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\NAMECONTROLSERVER.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:a12ca2ab6343a74478e269d104197a9b2da37e0bf982fff61e82786a52e6be66 , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\CSISYNCCLIENT.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:58c679487241af3293eda35aded7f24f3de1dde970aecc8373513f6ff8526d51 , guest_paths:C:\\Program Files (x86)\\Google\\Chrome\\Application\\74.0.3729.169\\Installer\\chrmstp.exe*C:\\Program Files (x86)\\Google\\Chrome\\Application\\74.0.3729.169\\Installer\\setup.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:1b2523e1f7bc39d7edcc98b0d7da53f27aca6c42cc8e06c35579079759ad9b67 , guest_paths:C:\\Users\\user\\Volumeid.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:20f85a55cbf22da9bfebb0b7f91d8090c87ec0d0b12e34a60a38081bea4f9e16 , guest_paths:C:\\Users\\user\\AppData\\Local\\Apps\\2.0\\Z0GKGT47.ZK6\\LG8N4V75.0O7\\clic...exe_9ae46cec200785df_0001.0003_none_a8944a4a5d6278ab\\GoogleUpdateSetup.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:13a4d12283f7fb8d3e716f9f83bb4009714eb4ccec6a93ad906545b8075ef0de , guest_paths:C:\\Users\\user\\AppData\\Local\\Package Cache\\c0f1e976-f585-48f8-968d-48c870496d4e\\python-3.7.2-amd64.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:baeea6b31fba79056eae2d04be496939b9105d10a870b3d3faff3c6f0645d159 , guest_paths:C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:888a1dd0033e5d758a4e731e3e55357de866e80d03b1b194375f714e1fd4351d , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroBroker.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:6b89693de25bd3a520e36d912f7ae5ada83d38101ebdf58fe0893dc9d25d65bf , guest_paths:C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleCrashHandler.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:abbcff4ad295f2ce06c12ee70f49eabc029941de9d1c58dabfe6076400598225 , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\FLTLDR.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:d89519fdfda1997aea4f2f85fdf909dc321635b192c7349d25047208aafd55d2 , guest_paths:C:\\MSOCache\\All Users\\91150000-0011-0000-0000-0000000FF1CE-C\\ose.exe*C:\\Program Files (x86)\\Common Files\\microsoft shared\\Source Engine\\OSE.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:b8f73f402b1664d7299999aa163264633988bfe5bfe0792bc3b8c5c7ac7e49c9 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\IEContentService.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:67367a327fb9f2730454bbed6ba558367cd3b95c6b19605763898ec5c45ecc9a , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\PDFREFLOW.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:e99e627bd16a06c30acaa3c2684abe3580c6c91e96f316dcc0db7e9125e2ce7f , guest_paths:C:\\Program Files (x86)\\Microsoft OneDrive\\OneDriveSetup.exe*C:\\Users\\user\\AppData\\Local\\Microsoft\\OneDrive\\17.3.4604.0120\\OneDriveSetup.exe*C:\\Users\\user\\AppData\\Local\\Microsoft\\OneDrive\\17.3.4604.0120_1\\OneDriveSetup.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:c9f2b59a9e7bddb95d4d1a137a19f27cfc3e5264a4a07552297ec288120cca11 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\DCF\\SPREADSHEETCOMPARE.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:663f7670be2c446f936d7c8d49b7a53f0b1e19faaa224719a751586aa3ca6749 , guest_paths:C:\\Users\\user\\AppData\\Local\\Microsoft\\OneDrive\\17.3.4604.0120\\FileSyncConfig.exe*C:\\Users\\user\\AppData\\Local\\Microsoft\\OneDrive\\17.3.4604.0120_1\\FileSyncConfig.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:990542871801e2c96b3ae82ce8c09bccb51eeef54965a0d72294483a6a546dff , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSOSYNC.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:447780d418acf453f40c70b5389d07458d33056ff8f4185aec14851423ed62e6 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\VPREVIEW.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:d29ca7a2971d69e770e9b37653ea87092144b395125ba9d0be5128dcdd9da1a5 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\CNFNOT32.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:7513dd45316fe6eb1f7ab31ae8f048cf8492c38c26fe1a2080cb77bc74fc2868 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\DCF\\DATABASECOMPARE.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:8268d3fefe8ca96a25a73690d14bacf644170ab5e9e70d2f8eeb350a4c83f9f6 , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroRd32.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:473eb551101caeaf2d18f811342e21de323c8dd19ed21011997716871defe997 , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\LogTransport2.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:3709c99303695da84943b667960035706664d63f956f641ccbcc8b77f3bfe82c , guest_paths:C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome_proxy.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:35c7b6d9104df263883586d19819bf4e5e5ff95a3ae6b65b6f244e8828a2ddb0 , guest_paths:C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:097bf0f5b07c4834e4c65be0ad645362ce641e8cb72dfb46711ca254da70511d , guest_paths:C:\\Users\\user\\AppData\\Local\\Microsoft\\OneDrive\\OneDrive.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:fe44ca8d5050932851aa54c23133277e66db939501af58e5aeb7b67ec1dde7b5 , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\arh.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:7166949b9f878abc41422a8db12557c0ab415d23be363b427a058879507ff2a9 , guest_paths:C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleDisabledUpdateComRegisterShell64.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:f80a3f3c95af2bcbaa559004e90de1e44810d26966ca93b4d1f2e269db743fb6 , guest_paths:C:\\Program Files (x86)\\Common Files\\Oracle\\Java\\javapath\\java.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:86d23a419e95475b718488d022d4d7e22834f37d4d9d50d1bbd5743aee16aff5 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\DCF\\filecompare.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:b78d0aecf7b8bf5f3e171cd4a8b77cffbb00f8a1298ec4ec468e92de8515d905 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSQRY32.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:a89d31919609e00c9310adf1c465cfa948fa7689b8b09757a1751b671f235497 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\WORDICON.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:3e9da97a7106122245e77f13f3f3cc96c055d732ab841eb848d03ac25401c1bc , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\plug_ins\\pi_brokers\\32BitMAPIBroker.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:2f947e3ca624ce7373080b4a3934e21644fb070a53feeaae442b15b849c2954f , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\reader_sl.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:22a585c183e27b3c732028ff193733c2f9d03700a0e95e65c556b0592c43d880 , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\plug_ins\\pi_brokers\\64BitMAPIBroker.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:a1e2d00be0f429ffa9543477370437256c6349ac7afacd2986b473d3edf53e88 , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\OLicenseHeartbeat.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:72add3ab0d6b63f41eced2678370b93db65f8dfee4ae689ffafdf934e1f28f3b , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\Oarpmany.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:15beb2ed451fb7112081bd1d7bbdd6c3f0f3729743defe6db63c3eecf3fd63ae , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\ONENOTEM.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:d65f1a5a32138675659fc4271ecf34e7bd38928df6a920d53e5ef34e091403c2 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\OcPubMgr.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:28b61729de64e1f05978a0e992679c5331a33962219dd6c5f7eb5837267e0312 , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\CMigrate.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:4dbe244a4fd91ed0957a51d903aad2e44f3735a378fe8e63def66ad6053ee8b0 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\ONENOTE.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:9288dea70d841fb45585d590b2b6a77a92466df8264161a0b76d5d6d58d0b0c5 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\GROOVE.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:980bac6c9afe8efc9c6fe459a5f77213b0d8524eb00de82437288eb96138b9a2 , guest_paths:C:\\Windows\\svchost.com, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:d21aad8e6916247dea8fe1be2341cf2ccefc7138b70a46d12f0229574d87a99b , guest_paths:C:\\Program Files (x86)\\Common Files\\Oracle\\Java\\javapath\\javaws.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:f6337da1d94005ad9e7db5f14734745b0cca171a84fbc689a1ba5071261a9751 , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\Office Setup Controller\\ODeploy.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:cbbe90f7370a9658e56ddf446024df6cb5456700048511ba9ba0681c3c409fb3 , guest_paths:C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleDisabledUpdateSetup.exe*C:\\Program Files (x86)\\Google\\Update\\Download\\430FD4D0-B729-4F61-AA34-91526481799D\\1.3.34.11\\GoogleUpdateSetup.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:ecd5e94da88c653e4c34b6ab325e0aca8824247b290336f75c410caa16381bc5 , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\Browser\\WCChromeExtn\\WCChromeNativeMessagingHost.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:5b26d41634ea456ab4a1594fdc0c483fec821a8d9105688e8060ae9628e8a1fd , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\Office Setup Controller\\Setup.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:c4dba9e0f68b7efc3f5ab014552ca7d96e62f6bcbcce09ab8e4b59cbce979e99 , guest_paths:C:\\MSOCache\\All Users\\91150000-0011-0000-0000-0000000FF1CE-C\\setup.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:19576842dd832bc3e7f617b86dfac0aeeefcbb5831cebc5227f731ecdeaafb96 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\lynchtmlconv.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:750824b5f75c91a6c2eeb8c5e60ae28d7a81e323d3762c8652255bfea5cba0bb , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\wow_helper.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:c8767dd56208c45a116b6b66e988fa436a055ba45202e09203af62696055307b , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\XLICONS.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:7f474c8c7643ab7a5aa9cdb27a93ecb7ca3f23ed8af916cb7fc5905f572cf732 , guest_paths:C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARMHelper.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:4b45150cb6145bd3c56bc3d950ae93db301adc74f604c820664d13868dad7e25 , guest_paths:C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleDisabledUpdateOnDemand.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:5994fc2f0442124a9fe9db07b1c418350dd3cde7ca2d0cbf5dc92eb2c4086845 , guest_paths:C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\MSOXMLED.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:3f00404dd591c2856e6f71bd78423ed47199902e0b85f228e6c4de72c59ddffe , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\ADelRCP.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:d3257b833c29649f13b0a3da80fce9b814c0d79c11c56420e6e16eb22ef2b46b , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\SELFCERT.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:b08c170ee7fe714073486ad71706c9f5d23d7fad8b673ec65269fe7b9784cec5 , guest_paths:C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleCrashHandler64.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:db023545a5c2653ab825e59b498486b29de128b805e2e1807c272a7f6c4390c3 , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\misc.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:161f13cacf1df4a08b4f0a28e6869aafe08c37c3bde7e27c784be6e6523f686a , guest_paths:C:\\Program Files (x86)\\Microsoft Office\\Office15\\ACCICONS.EXE, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:16d65f2463658a72dba205dcaa18bc3d0bab4453e726233d68bc176e69db0950 , guest_paths:C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\FullTrustNotifier.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:18e7c31c2f44d6b49942717871d4b5a541e3472133d31665e1a71f5f26180841 , guest_paths:C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jucheck.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "dropped": "clamav:Win.Trojan.Neshuta-1, sha256:0da0b61e1c65ce4799f7a8b7a7d0d0c0ac896e373ec148ef13088b991bdfff6f , guest_paths:C:\\ProgramData\\Microsoft\\ClickToRun\\9AC08E99-230B-47e8-9721-4577B7F124EA\\integrator.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
- "Description": "Anomalous binary characteristics",
- "Details":
- "anomaly": "Timestamp on binary predates the release date of the OS version it requires by at least a year"
- * Started Service:
- * Mutexes:
- "MutexPolesskayaGlush*.*\\xc2\\x90svchost.com\\xc2\\x90exefile\\shell\\open\\command\\xe2\\x80\\xb9\\xc3\\x80 \"%1\" %*\\xc5\\x93\\xe2\\x80\\x98@",
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\3582-490\\Exes_21f481135adc34af1779a6dde07f6801.exe",
- "C:\\Windows\\svchost.com",
- "C:\\MSOCache\\All Users\\91150000-0011-0000-0000-0000000FF1CE-C\\ose.exe",
- "C:\\MSOCache\\All Users\\91150000-0011-0000-0000-0000000FF1CE-C\\setup.exe",
- "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroBroker.exe",
- "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroCEF\\RdrCEF.exe",
- "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroRd32.exe",
- "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroTextExtractor.exe",
- "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\ADelRCP.exe",
- "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AdobeCollabSync.exe",
- "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\arh.exe",
- "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\Browser\\WCChromeExtn\\WCChromeNativeMessagingHost.exe",
- "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\Eula.exe",
- "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\FullTrustNotifier.exe",
- "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\LogTransport2.exe",
- "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\plug_ins\\pi_brokers\\32BitMAPIBroker.exe",
- "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\plug_ins\\pi_brokers\\64BitMAPIBroker.exe",
- "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\reader_sl.exe",
- "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\wow_helper.exe",
- "C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe",
- "C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARMHelper.exe",
- "C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\armsvc.exe",
- "C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jaureg.exe",
- "C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jucheck.exe",
- "C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe",
- "C:\\Program Files (x86)\\Common Files\\microsoft shared\\DW\\DW20.EXE",
- "C:\\Program Files (x86)\\Common Files\\microsoft shared\\DW\\DWTRIG20.EXE",
- "C:\\Program Files (x86)\\Common Files\\microsoft shared\\EQUATION\\EQNEDT32.EXE",
- "C:\\Program Files (x86)\\Common Files\\microsoft shared\\ink\\mip.exe",
- "C:\\Program Files (x86)\\Common Files\\microsoft shared\\MSInfo\\msinfo32.exe",
- "C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\CMigrate.exe",
- "C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\CSISYNCCLIENT.EXE",
- "C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\FLTLDR.EXE",
- "C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\LICLUA.EXE",
- "C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\MSOICONS.EXE",
- "C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\MSOSQM.EXE",
- "C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\MSOXMLED.EXE",
- "C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\Oarpmany.exe",
- "C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\Office Setup Controller\\ODeploy.exe",
- "C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\Office Setup Controller\\Setup.exe",
- "C:\\Program Files (x86)\\Common Files\\microsoft shared\\OFFICE15\\OLicenseHeartbeat.exe",
- "C:\\Program Files (x86)\\Common Files\\microsoft shared\\Source Engine\\OSE.EXE",
- "C:\\Program Files (x86)\\Common Files\\microsoft shared\\VSTO\\10.0\\VSTOInstaller.exe",
- "C:\\Program Files (x86)\\Common Files\\Oracle\\Java\\javapath\\java.exe",
- "C:\\Program Files (x86)\\Common Files\\Oracle\\Java\\javapath\\javaw.exe",
- "C:\\Program Files (x86)\\Common Files\\Oracle\\Java\\javapath\\javaws.exe",
- "C:\\Program Files (x86)\\Google\\Chrome\\Application\\74.0.3729.169\\elevation_service.exe",
- "C:\\Program Files (x86)\\Google\\Chrome\\Application\\74.0.3729.169\\Installer\\chrmstp.exe",
- "C:\\Program Files (x86)\\Google\\Chrome\\Application\\74.0.3729.169\\Installer\\setup.exe",
- "C:\\Program Files (x86)\\Google\\Chrome\\Application\\74.0.3729.169\\notification_helper.exe",
- "C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe",
- "C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome_proxy.exe",
- "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleCrashHandler.exe",
- "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleCrashHandler64.exe",
- "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleDisabledUpdateBroker.exe",
- "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleDisabledUpdateComRegisterShell64.exe",
- "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleDisabledUpdateCore.exe",
- "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleDisabledUpdateOnDemand.exe",
- "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleDisabledUpdateSetup.exe",
- "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleDisabledUpdateWebPlugin.exe",
- "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\Google_DisabledUpdate.exe",
- "C:\\Program Files (x86)\\Google\\Update\\Download\\430FD4D0-B729-4F61-AA34-91526481799D\\1.3.34.11\\GoogleUpdateSetup.exe",
- "C:\\Program Files (x86)\\Google\\Update\\Google_Disabled_Update.exe",
- "C:\\Program Files (x86)\\Internet Explorer\\ExtExport.exe",
- "C:\\Program Files (x86)\\Internet Explorer\\ieinstal.exe",
- "C:\\Program Files (x86)\\Internet Explorer\\ielowutil.exe",
- "C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe",
- "C:\\Program Files (x86)\\Microsoft Analysis Services\\AS OLEDB\\110\\SQLDumper.exe",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\ACCICONS.EXE",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\CLVIEW.EXE",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\CNFNOT32.EXE",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\DCF\\DATABASECOMPARE.EXE",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\DCF\\filecompare.exe",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\DCF\\SPREADSHEETCOMPARE.EXE",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\FIRSTRUN.EXE",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\GRAPH.EXE",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\GROOVE.EXE",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\IEContentService.exe",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\INFOPATH.EXE",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\lynchtmlconv.exe",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\misc.exe",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSOHTMED.EXE",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSOSYNC.EXE",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSOUC.EXE",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\MSQRY32.EXE",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\NAMECONTROLSERVER.EXE",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\OcPubMgr.exe",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\ONENOTE.EXE",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\ONENOTEM.EXE",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\PDFREFLOW.EXE",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\POWERPNT.EXE",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\PPTICO.EXE",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\protocolhandler.exe",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\SELFCERT.EXE",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\SETLANG.EXE",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\UcMapi.exe",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\VPREVIEW.EXE",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\WINWORD.EXE",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\WORDICON.EXE",
- "C:\\Program Files (x86)\\Microsoft Office\\Office15\\XLICONS.EXE",
- "C:\\Program Files (x86)\\Microsoft OneDrive\\OneDriveSetup.exe",
- "C:\\Program Files (x86)\\Windows Mail\\wab.exe",
- "C:\\Program Files (x86)\\Windows Mail\\wabmig.exe",
- "C:\\Program Files (x86)\\Windows Mail\\WinMail.exe",
- "C:\\Program Files (x86)\\Windows NT\\Accessories\\wordpad.exe",
- "C:\\Program Files (x86)\\Windows Photo Viewer\\ImagingDevices.exe",
- "C:\\Program Files (x86)\\Windows Sidebar\\sidebar.exe",
- "C:\\ProgramData\\Adobe\\Setup\\AC76BA86-7AD7-1033-7B44-AC0F074E4100\\setup.exe",
- "C:\\ProgramData\\Microsoft\\ClickToRun\\9AC08E99-230B-47e8-9721-4577B7F124EA\\integrator.exe",
- "C:\\Users\\user\\AppData\\Local\\Apps\\2.0\\Z0GKGT47.ZK6\\LG8N4V75.0O7\\clic...exe_9ae46cec200785df_0001.0003_none_a8944a4a5d6278ab\\GoogleUpdateSetup.exe",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\OneDrive\\17.3.4604.0120\\FileSyncConfig.exe",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\OneDrive\\17.3.4604.0120\\OneDriveSetup.exe",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\OneDrive\\17.3.4604.0120_1\\FileSyncConfig.exe",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\OneDrive\\17.3.4604.0120_1\\OneDriveSetup.exe",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\OneDrive\\OneDrive.exe",
- "C:\\Users\\user\\AppData\\Local\\Package Cache\\c0f1e976-f585-48f8-968d-48c870496d4e\\python-3.7.2-amd64.exe",
- "C:\\Users\\user\\DevManView.exe",
- "C:\\Users\\user\\Volumeid.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\tmp5023.tmp"
- * Deleted Files:
- * Modified Registry Keys:
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Classes\\exefile\\shell\\open\\command\\(Default)"
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment