Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: ""
- * MalScore: 0.3
- * File Name: "CondicoesGerais"
- * File Size: 91233
- * File Type: "ASCII text, with very long lines, with CRLF line terminators"
- * SHA256: "ea90f67d4cc290adbdcbe87904cfae9fab91418caafa412c5ccb4ddcc1bac202"
- * MD5: "bd4a726cdcde7d3f47f8d86c90dc98e7"
- * SHA1: "0c70fd64a6a52d3671f9cc16c47c20f161c19331"
- * SHA512: "086cf12f9d589488138dbdcada4d40e570eab46e8e29e172b7d23d24570c412083dbbb5b8edc221a9fbe0129258c4d861abdfc59749c4377482f9974a0c73b8c"
- * CRC32: "104C6291"
- * SSDEEP: "1536:5BMHBrmommxpACd5WtMiVXre1puOFk+29GUm:5By9QmQCd0q8re6OFD3J"
- * Process Execution:
- "cmd.exe",
- "services.exe",
- "svchost.exe"
- * Executed Commands:
- "\"C:\\Windows\\system32\\rundll32.exe\" C:\\Windows\\system32\\shell32.dll,OpenAs_RunDLL C:\\Users\\user\\AppData\\Local\\Temp\\CondicoesGerais",
- "C:\\Users\\user\\AppData\\Local\\Temp\\CondicoesGerais ",
- "C:\\Windows\\system32\\svchost.exe -k netsvcs"
- * Signatures Detected:
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://www.msftncsi.com/ncsi.txt"
- * Started Service:
- "AppMgmt"
- * Mutexes:
- "Local\\ZoneAttributeCacheCounterMutex",
- "Local\\ZonesCacheCounterMutex",
- "Local\\ZonesLockedCacheCounterMutex"
- * Modified Files:
- * Deleted Files:
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect"
- * Deleted Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName"
- * DNS Communications:
- * Domains:
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 1,
- "body": "",
- "uri": "http://www.msftncsi.com/ncsi.txt",
- "user-agent": "Microsoft NCSI",
- "method": "GET",
- "host": "www.msftncsi.com",
- "version": "1.1",
- "path": "/ncsi.txt",
- "data": "GET /ncsi.txt HTTP/1.1\r\nConnection: Close\r\nUser-Agent: Microsoft NCSI\r\nHost: www.msftncsi.com\r\n\r\n",
- "port": 80
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment