Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Processes Created:
- ==================
- [CreateProcess] Explorer.EXE:1432 > "%UserProfile%\Desktop\hehda.exe" [Child PID: 2520]
- [CreateProcess] hehda.exe:2520 > "%WinDir%\system32\cmd.exe" [Child PID: 3444]
- File Activity:
- ==================
- [New Folder] hehda.exe:2520 > C:\RECYCLER\S-1-5-21-861567501-412668190-725345543-500\$fab110457830839344b58457ddd1f357
- [New Folder] hehda.exe:2520 > C:\RECYCLER\S-1-5-21-861567501-412668190-725345543-500\$fab110457830839344b58457ddd1f357\L
- [New Folder] hehda.exe:2520 > C:\RECYCLER\S-1-5-21-861567501-412668190-725345543-500\$fab110457830839344b58457ddd1f357\U
- [CreateFile] hehda.exe:2520 > C:\RECYCLER\S-1-5-21-861567501-412668190-725345543-500\$fab110457830839344b58457ddd1f357\@ [MD5: 814c3536c2aab13763ac0beb7847a71f]
- [CreateFile] hehda.exe:2520 > C:\RECYCLER\S-1-5-21-861567501-412668190-725345543-500\$fab110457830839344b58457ddd1f357\n [MD5: cfaddbb43ba973f8d15d7d2e50c63476]
- [New Folder] hehda.exe:2520 > C:\RECYCLER\S-1-5-18
- [New Folder] hehda.exe:2520 > C:\RECYCLER\S-1-5-18\$fab110457830839344b58457ddd1f357
- [New Folder] hehda.exe:2520 > C:\RECYCLER\S-1-5-18\$fab110457830839344b58457ddd1f357\L
- [New Folder] hehda.exe:2520 > C:\RECYCLER\S-1-5-18\$fab110457830839344b58457ddd1f357\U
- [CreateFile] hehda.exe:2520 > C:\RECYCLER\S-1-5-18\$fab110457830839344b58457ddd1f357\@ [MD5: d1993f38046a68cc78a20560e8de9ad8]
- [CreateFile] hehda.exe:2520 > C:\RECYCLER\S-1-5-18\$fab110457830839344b58457ddd1f357\n [MD5: cfaddbb43ba973f8d15d7d2e50c63476]
- [CreateFile] services.exe:680 > C:\RECYCLER\S-1-5-18\$fab110457830839344b58457ddd1f357\@ [MD5: d1993f38046a68cc78a20560e8de9ad8]
- [New Folder] services.exe:680 > C:\RECYCLER\S-1-5-18\$fab110457830839344b58457ddd1f357\U
- [CreateFile] hehda.exe:2520 > %UserProfile%\Desktop\hehda.exe [File no longer exists]
- [DeleteFile] cmd.exe:3444 > %UserProfile%\Desktop\hehda.exe
- Registry Activity:
- ==================
- [CreateKey] hehda.exe:2520 > HKLM\SOFTWARE\Microsoft\Cryptography\RNG
- [CreateKey] hehda.exe:2520 > HKCU\Software\Classes\clsid
- [CreateKey] hehda.exe:2520 > HKCU\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}
- [CreateKey] hehda.exe:2520 > HKCU\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InprocServer32
- [SetValue] hehda.exe:2520 > HKCU\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InprocServer32\ThreadingModel = Both
- [SetValue] hehda.exe:2520 > HKCU\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InprocServer32\(Default) = C:\RECYCLER\S-1-5-21-861567501-412668190-725345543-500\$fab110457830839344b58457ddd1f357\n.
- [SetValue] svchost.exe:1032 > HKLM\System\CurrentControlSet\Services\SharedAccess\Epoch\Epoch = 404
- [SetValue] services.exe:680 > HKLM\System\CurrentControlSet\Services\SharedAccess\Type = 32
- [SetValue] services.exe:680 > HKLM\System\CurrentControlSet\Services\SharedAccess\Start = 4
- [SetValue] services.exe:680 > HKLM\System\CurrentControlSet\Services\SharedAccess\ErrorControl = 0
- [SetValue] services.exe:680 > HKLM\System\CurrentControlSet\Services\SharedAccess\DeleteFlag = 1
- [SetValue] services.exe:680 > HKLM\System\CurrentControlSet\Services\SharedAccess\Start = 4
- [CreateKey] services.exe:680 > HKLM\System\CurrentControlSet\Control\Class\{8ECC055D-047F-11D1-A537-0000F8753ED1}\0000
- [CreateKey] services.exe:680 > HKLM\System\CurrentControlSet\Services\SharedAccess\Enum
- [SetValue] services.exe:680 > HKLM\System\CurrentControlSet\Services\SharedAccess\Enum\Count = 0
- [SetValue] services.exe:680 > HKLM\System\CurrentControlSet\Services\SharedAccess\Enum\NextInstance = 0
- [SetValue] services.exe:680 > HKLM\System\CurrentControlSet\Services\wscsvc\Type = 32
- [SetValue] services.exe:680 > HKLM\System\CurrentControlSet\Services\wscsvc\Start = 4
- [SetValue] services.exe:680 > HKLM\System\CurrentControlSet\Services\wscsvc\ErrorControl = 0
- [SetValue] services.exe:680 > HKLM\System\CurrentControlSet\Services\wscsvc\DeleteFlag = 1
- [SetValue] services.exe:680 > HKLM\System\CurrentControlSet\Services\wscsvc\Start = 4
- Network Traffic:
- ==================
- [UDP] hehda.exe:2520 > google-public-dns-a.google.com:53
- [UDP] google-public-dns-a.google.com:53 > hehda.exe:2520
- [HTTP] hehda.exe:2520 > 50.22.196.70-static.reverse.softlayer.com:80
- [TCP] 50.22.196.70-static.reverse.softlayer.com:80 > hehda.exe:2520
- [UDP] hehda.exe:2520 > 83.133.123.20:53
- [UDP] svchost.exe:1032 > 239.255.255.250:1900
- [UDP] services.exe:680 > 206.254.253.254:16471
- [UDP] services.exe:680 > 190.254.253.254:16471
- [UDP] services.exe:680 > 182.254.253.254:16471
- [UDP] services.exe:680 > 180.254.253.254:16471
- [UDP] services.exe:680 > 135.254.253.254:16471
- [UDP] services.exe:680 > 134.254.253.254:16471
- [UDP] services.exe:680 > 117.254.253.254:16471
- [UDP] services.exe:680 > 115.254.253.254:16471
- [UDP] services.exe:680 > 92.254.253.254:16471
- [UDP] services.exe:680 > 88.254.253.254.dynamic.ttnet.com.tr:16471
- [UDP] services.exe:680 > 254.253.254.87.dynamic.monaco.mc:16471
- Unique Hosts:
- ==================
- 115.254.253.254
- 117.254.253.254
- 134.254.253.254
- 135.254.253.254
- 180.254.253.254
- 182.254.253.254
- 190.254.253.254
- 206.254.253.254
- 239.255.255.250
- 254.253.254.87.dynamic.monaco.mc
- 255.255.255.255
- 50.22.196.70-static.reverse.softlayer.com
- 83.133.123.20
- 88.254.253.254.dynamic.ttnet.com.tr
- 92.254.253.254
- google-public-dns-a.google.com
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement