Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "Generic"
- * MalScore: 10.0
- * File Name: "Exes_5ba03ec015352ebd5da794e320ac8866.exe"
- * File Size: 1073152
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "2420a68686f5a2b74c6bb1631a36e7fac2cbe2c7d97b4c6f2a5a7a976351b8d6"
- * MD5: "5ba03ec015352ebd5da794e320ac8866"
- * SHA1: "2ac049fbf984c21c8d2594dda0cb3ca61136c2e2"
- * SHA512: "5d194d43c7397c587317bfcb3536636fc2d80ac9a0039d37c16ebb6e3c071a62ef3543b6a469917632a6da897af17a32988fabac580a56b66ea5db13ca42a860"
- * CRC32: "93D87D5A"
- * SSDEEP: "24576:boNrzkTOzKLFC6DMbck6hILkljfujnXR7pu/1RdrX2:8Nrz0PC6DycxIuGpmrX"
- * Process Execution:
- "Exes_5ba03ec015352ebd5da794e320ac8866.exe",
- "Exes_5ba03ec015352ebd5da794e320ac8866.exe",
- "cmd.exe",
- "timeout.exe"
- * Executed Commands:
- "\"C:\\Users\\user\\AppData\\Local\\Temp\\Exes_5ba03ec015352ebd5da794e320ac8866.exe\"",
- "cmd.exe cmd.exe /c timeout 1 && del C:\\Users\\user\\AppData\\Local\\Temp\\Exes_5ba03ec015352ebd5da794e320ac8866.exe\"",
- "timeout 1"
- * Signatures Detected:
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Attempts to connect to a dead IP:Port (255 unique times)",
- "Details":
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "IP": "169.254.255.254:445"
- "Description": "Expresses interest in specific running processes",
- "Details":
- "process": "lsass.exe"
- "Description": "A process created a hidden window",
- "Details":
- "Process": "Exes_5ba03ec015352ebd5da794e320ac8866.exe -> C:\\Users\\user\\AppData\\Local\\Temp\\Exes_5ba03ec015352ebd5da794e320ac8866.exe"
- "Process": "Exes_5ba03ec015352ebd5da794e320ac8866.exe -> cmd.exe cmd.exe /c timeout 1 && del C:\\Users\\user\\AppData\\Local\\Temp\\Exes_5ba03ec015352ebd5da794e320ac8866.exe\""
- "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
- "Details":
- "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
- "suspicious_request": "http://212.38.166.79/tin.png"
- "suspicious_request": "http://212.38.166.79/sin.png"
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://212.38.166.79/tin.png"
- "url": "http://212.38.166.79/sin.png"
- "Description": "Executed a process and injected code into it, probably while unpacking",
- "Details":
- "Injection": "Exes_5ba03ec015352ebd5da794e320ac8866.exe(1908) -> Exes_5ba03ec015352ebd5da794e320ac8866.exe(1640)"
- "Description": "Deletes its original binary from disk",
- "Details":
- "Description": "File has been identified by 11 Antiviruses on VirusTotal as malicious",
- "Details":
- "Invincea": "heuristic"
- "Kaspersky": "UDS:DangerousObject.Multi.Generic"
- "Trapmine": "suspicious.low.ml.score"
- "FireEye": "Generic.mg.5ba03ec015352ebd"
- "Avira": "TR/AD.PatchedWinSwrort.xurni"
- "Endgame": "malicious (high confidence)"
- "ZoneAlarm": "UDS:DangerousObject.Multi.Generic"
- "VBA32": "BScope.TrojanDropper.Agent"
- "ESET-NOD32": "a variant of Win32/GenKryptik.DNPP"
- "Paloalto": "generic.ml"
- "CrowdStrike": "win/malicious_confidence_80% (W)"
- "Description": "Created network traffic indicative of malicious activity",
- "Details":
- "signature": "ET USER_AGENTS Suspicious User-Agent (contains loader)"
- * Started Service:
- * Mutexes:
- * Modified Files:
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\S-1-5-21-0000000000-0000000000-0000000000-1000\\00000000-0000-0000-0000-000000000000b_00000000-0000-0000-0000-000000000000",
- "C:\\Users\\user\\AppData\\Local\\Temp\\log_install.tmp",
- "\\??\\PIPE\\wkssvc",
- "\\Device\\LanmanDatagramReceiver",
- "\\??\\PIPE\\DAV RPC SERVICE"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\log_install.tmp",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_5ba03ec015352ebd5da794e320ac8866.exe"
- * Modified Registry Keys:
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\SecurityProviders\\WDigest\\UseLogonCredential"
- * Deleted Registry Keys:
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 1,
- "body": "",
- "uri": "http://212.38.166.79/tin.png",
- "user-agent": "WinHTTP loader/1.0",
- "method": "GET",
- "host": "212.38.166.79",
- "version": "1.1",
- "path": "/tin.png",
- "data": "GET /tin.png HTTP/1.1\r\nCache-Control: no-cache\r\nConnection: Keep-Alive\r\nPragma: no-cache\r\nUser-Agent: WinHTTP loader/1.0\r\nHost: 212.38.166.79\r\n\r\n",
- "port": 80
- "count": 1,
- "body": "",
- "uri": "http://212.38.166.79/sin.png",
- "user-agent": "WinHTTP loader/1.0",
- "method": "GET",
- "host": "212.38.166.79",
- "version": "1.1",
- "path": "/sin.png",
- "data": "GET /sin.png HTTP/1.1\r\nCache-Control: no-cache\r\nConnection: Keep-Alive\r\nPragma: no-cache\r\nUser-Agent: WinHTTP loader/1.0\r\nHost: 212.38.166.79\r\n\r\n",
- "port": 80
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment