paladin316

ctfmon_exe.json

Jun 20th, 2019
2,256
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 64.36 KB | None | 0 0
  1.  
  2. [*] MalFamily: "Shadowbrokers"
  3.  
  4. [*] MalScore: 10.0
  5.  
  6. [*] File Name: "ctfmon.exe"
  7. [*] File Size: 2336589
  8. [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. [*] SHA256: "181ce9db0dea2a3a2e08860620c3015e61995a93729cb07e0b157d0e75c73343"
  10. [*] MD5: "762ed51daa67d2a6a4ea641ec5a5b6f3"
  11. [*] SHA1: "9d6f2b7db9b2ee86206fc209824bd4fc23f594cd"
  12. [*] SHA512: "8bd5eb9759acb4d416788c1ef0233105feb52658d60553d9dd1171554cc7fa59c37f79043702abf86400173dc95511b76f0ea310e8446cf7b952f826a2204602"
  13. [*] CRC32: "80156EAA"
  14. [*] SSDEEP: "49152:jyWhIEPXY6Ya8tX/sXoOTHFBFbh5uAdOS9UoEoEEuCWXzI82mN:jyWOAhMfOTHn9C/S9UsEEqXF"
  15.  
  16. [*] Process Execution: [
  17. "ctfmon.exe",
  18. "cmd.exe",
  19. "net.exe",
  20. "net1.exe",
  21. "net.exe",
  22. "net1.exe",
  23. "svchost.exe",
  24. "svchost.exe",
  25. "sc.exe",
  26. "sc.exe",
  27. "svchost.exe",
  28. "svchost.exe",
  29. "svchost.exe",
  30. "PING.EXE",
  31. "svchost.exe",
  32. "net.exe",
  33. "net1.exe",
  34. "cmd.exe",
  35. "schtasks.exe",
  36. "cmd.exe",
  37. "schtasks.exe",
  38. "attrib.exe",
  39. "attrib.exe",
  40. "cmd.exe",
  41. "cacls.exe",
  42. "cmd.exe",
  43. "cacls.exe",
  44. "cmd.exe",
  45. "cacls.exe",
  46. "cmd.exe",
  47. "cacls.exe",
  48. "cmd.exe",
  49. "cacls.exe",
  50. "cmd.exe",
  51. "cacls.exe",
  52. "cmd.exe",
  53. "cacls.exe",
  54. "cmd.exe",
  55. "cacls.exe",
  56. "cmd.exe",
  57. "cacls.exe",
  58. "cmd.exe",
  59. "cacls.exe",
  60. "cmd.exe",
  61. "cacls.exe",
  62. "cmd.exe",
  63. "cacls.exe",
  64. "cmd.exe",
  65. "cacls.exe",
  66. "cmd.exe",
  67. "cacls.exe",
  68. "cmd.exe",
  69. "cacls.exe",
  70. "cmd.exe",
  71. "cacls.exe",
  72. "cmd.exe",
  73. "cacls.exe",
  74. "cmd.exe",
  75. "cacls.exe",
  76. "cmd.exe",
  77. "cacls.exe",
  78. "cmd.exe",
  79. "cacls.exe",
  80. "cmd.exe",
  81. "cacls.exe",
  82. "cmd.exe",
  83. "cacls.exe",
  84. "cmd.exe",
  85. "cacls.exe",
  86. "cmd.exe",
  87. "cacls.exe",
  88. "sc.exe",
  89. "net.exe",
  90. "net1.exe",
  91. "taskkill.exe",
  92. "taskkill.exe",
  93. "taskkill.exe",
  94. "taskkill.exe",
  95. "taskkill.exe",
  96. "taskkill.exe",
  97. "services.exe",
  98. "svchost.exe",
  99. "cmd.exe",
  100. "mode.com",
  101. "sc.exe",
  102. "sc.exe",
  103. "sc.exe",
  104. "sc.exe",
  105. "net.exe",
  106. "net1.exe",
  107. "net.exe",
  108. "net1.exe",
  109. "net.exe",
  110. "net1.exe",
  111. "net.exe",
  112. "net1.exe",
  113. "taskkill.exe",
  114. "taskkill.exe",
  115. "taskkill.exe",
  116. "taskkill.exe",
  117. "taskkill.exe",
  118. "taskkill.exe",
  119. "svchost.exe",
  120. "taskeng.exe",
  121. "GoogleUpdate.exe",
  122. "GoogleUpdate.exe",
  123. "GoogleUpdate.exe",
  124. "GoogleCrashHandler.exe",
  125. "GoogleCrashHandler64.exe",
  126. "GoogleUpdate.exe",
  127. "GoogleCrashHandler.exe",
  128. "GoogleCrashHandler64.exe",
  129. "taskeng.exe",
  130. "msoia.exe",
  131. "AdobeARM.exe",
  132. "msoia.exe",
  133. "FlashUtil32_29_0_0_171_Plugin.exe",
  134. "svchost.exe",
  135. "WmiPrvSE.exe",
  136. "svchost.exe",
  137. "GoogleUpdate.exe"
  138. ]
  139.  
  140. [*] Signatures Detected: [
  141. {
  142. "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
  143. "Details": [
  144. {
  145. "IP": "172.217.0.227:443"
  146. }
  147. ]
  148. },
  149. {
  150. "Description": "Possible date expiration check, exits too soon after checking local time",
  151. "Details": [
  152. {
  153. "process": "mode.com, PID 2336"
  154. }
  155. ]
  156. },
  157. {
  158. "Description": "Creates RWX memory",
  159. "Details": []
  160. },
  161. {
  162. "Description": "A process attempted to delay the analysis task.",
  163. "Details": [
  164. {
  165. "Process": "taskkill.exe tried to sleep 1860 seconds, actually delayed analysis time by 0 seconds"
  166. },
  167. {
  168. "Process": "taskeng.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
  169. },
  170. {
  171. "Process": "WmiPrvSE.exe tried to sleep 660 seconds, actually delayed analysis time by 0 seconds"
  172. }
  173. ]
  174. },
  175. {
  176. "Description": "At least one IP Address, Domain, or File Name was found in a crypto call",
  177. "Details": [
  178. {
  179. "ioc": "http://crl.globalsign.net/root-r2.crl0"
  180. }
  181. ]
  182. },
  183. {
  184. "Description": "A process created a hidden window",
  185. "Details": [
  186. {
  187. "Process": "ctfmon.exe -> C:\\Windows\\Fonts\\Mysql\\same.bat"
  188. }
  189. ]
  190. },
  191. {
  192. "Description": "Drops a binary and executes it",
  193. "Details": [
  194. {
  195. "binary": "C:\\Windows\\Fonts\\Mysql\\svchost.exe"
  196. }
  197. ]
  198. },
  199. {
  200. "Description": "The binary likely contains encrypted or compressed data.",
  201. "Details": [
  202. {
  203. "section": "name: .rsrc, entropy: 8.00, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x0023a54d, virtual_size: 0x00242000"
  204. }
  205. ]
  206. },
  207. {
  208. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  209. "Details": [
  210. {
  211. "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 7267266 times"
  212. }
  213. ]
  214. },
  215. {
  216. "Description": "Attempts to execute a Living Off The Land Binary command for post exeploitation",
  217. "Details": [
  218. {
  219. "MITRE T1078 - schtask": "(Tactic: Execution, Persistence, Privilege Escalation)"
  220. }
  221. ]
  222. },
  223. {
  224. "Description": "Installs itself for autorun at Windows startup",
  225. "Details": [
  226. {
  227. "service name": "MicrosoftMysql"
  228. },
  229. {
  230. "service path": "C:\\Windows\\Fonts\\Mysql\\svchost.exe"
  231. },
  232. {
  233. "task": "schtasks /create /TN \"At1\" /TR \"C:\\Windows\\Fonts\\Mysql\\nei.bat\" /SC daily /ST 11:30:00 /RU SYSTEM"
  234. }
  235. ]
  236. },
  237. {
  238. "Description": "Creates a hidden or system file",
  239. "Details": [
  240. {
  241. "file": "C:\\Windows\\Fonts\\Mysql\\nei.bat"
  242. },
  243. {
  244. "file": "C:\\Windows\\Fonts\\Mysql\\wai.bat"
  245. },
  246. {
  247. "file": "C:\\Windows\\Fonts\\Mysql\\bat.bat"
  248. },
  249. {
  250. "file": "C:\\Windows\\Fonts\\Mysql\\cmd.bat"
  251. },
  252. {
  253. "file": "C:\\Windows\\Fonts\\Mysql\\Doublepulsar.dll"
  254. },
  255. {
  256. "file": "C:\\Windows\\Fonts\\Mysql\\Doublepulsar2.dll"
  257. },
  258. {
  259. "file": "C:\\Windows\\Fonts\\Mysql\\Eternalblue.dll"
  260. },
  261. {
  262. "file": "C:\\Windows\\Fonts\\Mysql\\Eternalblue2.dll"
  263. },
  264. {
  265. "file": "C:\\Windows\\Fonts\\Mysql\\loab.bat"
  266. },
  267. {
  268. "file": "C:\\Windows\\Fonts\\Mysql\\load.bat"
  269. },
  270. {
  271. "file": "C:\\Windows\\Fonts\\Mysql\\poab.bat"
  272. },
  273. {
  274. "file": "C:\\Windows\\Fonts\\Mysql\\poad.bat"
  275. },
  276. {
  277. "file": "C:\\Windows\\Fonts\\Mysql\\taskhost.exe"
  278. },
  279. {
  280. "file": "C:\\Windows\\Fonts\\Mysql\\wget.exe"
  281. }
  282. ]
  283. },
  284. {
  285. "Description": "File has been identified by 56 Antiviruses on VirusTotal as malicious",
  286. "Details": [
  287. {
  288. "MicroWorld-eScan": "Trojan.GenericKD.41102453"
  289. },
  290. {
  291. "FireEye": "Generic.mg.762ed51daa67d2a6"
  292. },
  293. {
  294. "CAT-QuickHeal": "W32.Viking.gen"
  295. },
  296. {
  297. "McAfee": "Artemis!762ED51DAA67"
  298. },
  299. {
  300. "Malwarebytes": "Trojan.MalPack"
  301. },
  302. {
  303. "K7AntiVirus": "Trojan ( 005329b91 )"
  304. },
  305. {
  306. "Alibaba": "Backdoor:Win32/ShadowBrokers.56853b57"
  307. },
  308. {
  309. "K7GW": "Trojan ( 005329b91 )"
  310. },
  311. {
  312. "Cybereason": "malicious.daa67d"
  313. },
  314. {
  315. "Arcabit": "Trojan.Generic.D2732C75"
  316. },
  317. {
  318. "Invincea": "heuristic"
  319. },
  320. {
  321. "NANO-Antivirus": "Trojan.Win32.Delphi.fihmoq"
  322. },
  323. {
  324. "Cyren": "W32/Trojan.ZDWN-4222"
  325. },
  326. {
  327. "Symantec": "Trojan.Gen.MBT"
  328. },
  329. {
  330. "APEX": "Malicious"
  331. },
  332. {
  333. "Avast": "Win32:Evo-gen [Susp]"
  334. },
  335. {
  336. "ClamAV": "Win.Malware.Shadowbrokers-6958490-0"
  337. },
  338. {
  339. "Kaspersky": "Trojan.Win32.ShadowBrokers.ao"
  340. },
  341. {
  342. "BitDefender": "Trojan.GenericKD.41102453"
  343. },
  344. {
  345. "Paloalto": "generic.ml"
  346. },
  347. {
  348. "AegisLab": "Trojan.Win32.ShadowBrokers.4!c"
  349. },
  350. {
  351. "Tencent": "Win32.Trojan.Shadowbrokers.Afrq"
  352. },
  353. {
  354. "Ad-Aware": "Trojan.GenericKD.41102453"
  355. },
  356. {
  357. "Emsisoft": "Trojan.GenericKD.41102453 (B)"
  358. },
  359. {
  360. "Comodo": "Packed.Win32.Klone.~KMG@1knj1d"
  361. },
  362. {
  363. "F-Secure": "Trojan.TR/Dropper.Gen"
  364. },
  365. {
  366. "DrWeb": "Trojan.PWS.Panda.8062"
  367. },
  368. {
  369. "Zillya": "Trojan.ShadowBrokers.Win32.104"
  370. },
  371. {
  372. "TrendMicro": "Cryp_Xed-12"
  373. },
  374. {
  375. "McAfee-GW-Edition": "BehavesLike.Win32.Generic.vc"
  376. },
  377. {
  378. "Sophos": "Mal/EncPk-BW"
  379. },
  380. {
  381. "SentinelOne": "DFI - Malicious PE"
  382. },
  383. {
  384. "ESET-NOD32": "a variant of Win32/TrojanDropper.Agent.QBR"
  385. },
  386. {
  387. "eGambit": "Unsafe.AI_Score_99%"
  388. },
  389. {
  390. "Avira": "TR/Dropper.Gen"
  391. },
  392. {
  393. "Microsoft": "Trojan:Win32/Skeeyah.A!bit"
  394. },
  395. {
  396. "Endgame": "malicious (high confidence)"
  397. },
  398. {
  399. "ZoneAlarm": "Trojan.Win32.ShadowBrokers.ao"
  400. },
  401. {
  402. "GData": "Trojan.GenericKD.41102453"
  403. },
  404. {
  405. "AhnLab-V3": "Trojan/Win32.OnlineGameHack.R36603"
  406. },
  407. {
  408. "Acronis": "suspicious"
  409. },
  410. {
  411. "VBA32": "Trojan.ShadowBrokers"
  412. },
  413. {
  414. "ALYac": "Trojan.ShadowBrokers.A"
  415. },
  416. {
  417. "MAX": "malware (ai score=100)"
  418. },
  419. {
  420. "Cylance": "Unsafe"
  421. },
  422. {
  423. "TrendMicro-HouseCall": "Cryp_Xed-12"
  424. },
  425. {
  426. "Rising": "Backdoor.Agent!8.C5D (CLOUD)"
  427. },
  428. {
  429. "Yandex": "Trojan.DR.Agent!fBKh2F2rB8o"
  430. },
  431. {
  432. "Ikarus": "Trojan.Dropper"
  433. },
  434. {
  435. "MaxSecure": "Trojan.Malware.0.susgen"
  436. },
  437. {
  438. "Fortinet": "PossibleThreat"
  439. },
  440. {
  441. "Webroot": "W32.Trojan.Gen"
  442. },
  443. {
  444. "AVG": "FileRepMalware"
  445. },
  446. {
  447. "Panda": "Trj/Genetic.gen"
  448. },
  449. {
  450. "CrowdStrike": "win/malicious_confidence_100% (W)"
  451. },
  452. {
  453. "Qihoo-360": "Win32/Trojan.46e"
  454. }
  455. ]
  456. },
  457. {
  458. "Description": "The sample wrote data to the system hosts file.",
  459. "Details": [
  460. {
  461. "added": "103.18.244.217 donate.v2.darks.xyz"
  462. },
  463. {
  464. "added": "103.18.244.217 pool.minexmr.com"
  465. },
  466. {
  467. "added": "103.18.244.217 donate.v2.kiss58.org"
  468. },
  469. {
  470. "added": "103.18.244.217 donate.v2.googel-dns.com"
  471. },
  472. {
  473. "added": "103.18.244.217 pool.bulehero.in"
  474. },
  475. {
  476. "added": "103.18.244.217 sg.minexmr.com"
  477. }
  478. ]
  479. }
  480. ]
  481.  
  482. [*] Started Service: [
  483. "MicrosoftMysql",
  484. "Browser",
  485. "LanmanWorkstation",
  486. "LanmanServer",
  487. "gupdate",
  488. "Schedule"
  489. ]
  490.  
  491. [*] Executed Commands: [
  492. "C:\\Windows\\Fonts\\Mysql\\same.bat ",
  493. "net stop \"MicrosoftMysql\"",
  494. "net stop \"MicrosoftMssql\"",
  495. "svchost stop \"MicrosoftFonts\"",
  496. "svchost stop \"MicrosoftMysql\"",
  497. "sc delete \"MicrosoftMysql\"",
  498. "sc delete \"MicrosoftMssql\"",
  499. "svchost install MicrosoftMysql \"C:\\Windows\\Fonts\\Mysql\\cmd.bat\"",
  500. "svchost install MicrosoftMysql C:\\Windows\\Fonts\\Mysql\\cmd.bat",
  501. "svchost install \"MicrosoftMysql\" C:\\Windows\\Fonts\\Mysql\\cmd.bat",
  502. "C:\\Windows\\system32\\PING.EXE ping 127.0.0.1 -n 20",
  503. "svchost start \"MicrosoftMysql\"",
  504. "net start \"MicrosoftMysql\"",
  505. "C:\\Windows\\system32\\cmd.exe /S /D /c\" echo y\"",
  506. "schtasks /create /TN \"At1\" /TR \"C:\\Windows\\Fonts\\Mysql\\nei.bat\" /SC daily /ST 11:30:00 /RU SYSTEM",
  507. "schtasks /create /TN \"At2\" /TR \"C:\\Windows\\Fonts\\Mysql\\wai.bat\" /SC daily /ST 01:00:00 /RU SYSTEM",
  508. "attrib +h +s -r C:\\windows\\tasks\\At*.job",
  509. "attrib +h +s -r C:\\Windows\\System32\\Tasks\\At*",
  510. "cacls C:\\windows\\tasks\\At1.job /c /e /t /g system:F",
  511. "cacls C:\\windows\\tasks\\At2.job /c /e /t /g system:F",
  512. "cacls C:\\windows\\tasks\\At1.job /c /e /t /g everyone:F",
  513. "cacls C:\\windows\\tasks\\At2.job /c /e /t /g everyone:F",
  514. "cacls C:\\Windows\\System32\\Tasks\\At1 /c /e /t /g system:F",
  515. "cacls C:\\Windows\\System32\\Tasks\\At2 /c /e /t /g system:F",
  516. "cacls C:\\Windows\\System32\\Tasks\\At1 /c /e /t /g everyone:F",
  517. "cacls C:\\Windows\\System32\\Tasks\\At2 /c /e /t /g everyone:F",
  518. "cacls C:\\Windows\\Tasks\\MiscfostNsi /p system:n",
  519. "cacls C:\\Windows\\Tasks\\HomeGroupProvider /p system:n",
  520. "cacls C:\\Windows\\Tasks\\WwANsvc /p system:n",
  521. "cacls C:\\Windows\\Tasks\\*fost* /p system:n",
  522. "cacls C:\\Windows\\Tasks\\*Group* /p system:n",
  523. "cacls C:\\Windows\\Tasks\\*sa* /p system:n",
  524. "cacls C:\\Windows\\Tasks\\*ok* /p system:n",
  525. "cacls C:\\Windows\\Tasks\\*my* /p system:n",
  526. "cacls C:\\Windows\\System32\\Tasks\\MiscfostNsi /p system:n",
  527. "cacls C:\\Windows\\System32\\Tasks\\HomeGroupProvider /p system:n",
  528. "cacls C:\\Windows\\System32\\Tasks\\WwANsvc /p system:n",
  529. "cacls C:\\Windows\\System32\\Tasks\\*fost* /p system:n",
  530. "cacls C:\\Windows\\System32\\Tasks\\*Group* /p system:n",
  531. "cacls C:\\Windows\\System32\\Tasks\\*sa* /p system:n",
  532. "cacls C:\\Windows\\System32\\Tasks\\*ok* /p system:n",
  533. "cacls C:\\Windows\\System32\\Tasks\\*my* /p system:n",
  534. "sc start Schedule",
  535. "net start Schedule",
  536. "taskkill /f /im Eternalblue-2.2.0.exe",
  537. "taskkill /f /im Doublepulsar-1.3.1.exe",
  538. "taskkill /f /im one.exe",
  539. "taskkill /f /im z.exe",
  540. "taskkill /f /im c32.exe",
  541. "taskkill /f /im c64.exe",
  542. "C:\\Windows\\system32\\net1 stop \"MicrosoftMysql\"",
  543. "C:\\Windows\\system32\\net1 stop \"MicrosoftMssql\"",
  544. "C:\\Windows\\Fonts\\Mysql\\svchost.exe",
  545. "C:\\Windows\\System32\\svchost.exe -k netsvcs",
  546. "\"C:\\Program Files (x86)\\Google\\Update\\GoogleUpdate.exe\" /svc",
  547. "\"C:\\Windows\\Fonts\\Mysql\\cmd.bat\"",
  548. "mode con cols=50 lines=40",
  549. "sc config Browser start= auto",
  550. "sc config lanmanworkstation start= auto",
  551. "sc config lanmanserver start= auto",
  552. "sc config SharedAccess start= disabled",
  553. "net start Browser",
  554. "net start lanmanworkstation",
  555. "net start lanmanserver",
  556. "net stop SharedAccess",
  557. "taskkill /f /im mance.exe",
  558. "taskkill /f /im Eter.exe",
  559. "taskkill /f /im puls.exe",
  560. "C:\\Windows\\system32\\net1 start Browser",
  561. "C:\\Windows\\system32\\net1 start \"MicrosoftMysql\"",
  562. "C:\\Windows\\system32\\net1 start lanmanworkstation",
  563. "taskeng.exe {1B2969CC-32AB-406E-A082-BFA4AEC39B70} S-1-5-18:NT AUTHORITY\\System:Service:",
  564. "taskeng.exe {F04E9F33-09C3-4AB6-8094-0BB7BFCC134A} S-1-5-21-0000000000-0000000000-0000000000-1000:Host\\user:Interactive:[1]",
  565. "C:\\Windows\\system32\\net1 start lanmanserver",
  566. "C:\\Windows\\system32\\net1 stop SharedAccess",
  567. "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding",
  568. "C:\\Windows\\system32\\net1 start Schedule",
  569. "\"C:\\Program Files (x86)\\Google\\Update\\GoogleUpdate.exe\" /ua /installsource scheduler",
  570. "\"C:\\Program Files\\Common Files\\Microsoft Shared\\Office15\\OLicenseHeartbeat.exe\"",
  571. "\"C:\\Program Files (x86)\\Google\\Update\\GoogleUpdate.exe\" /c",
  572. "\"C:\\Program Files\\Microsoft Office\\Office15\\msoia.exe\" scan upload mininterval:2880",
  573. "\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"",
  574. "\"C:\\Program Files\\Microsoft Office\\Office15\\msoia.exe\" scan upload",
  575. "C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_29_0_0_171_Plugin.exe -check plugin",
  576. "\"C:\\Program Files (x86)\\Google\\Update\\GoogleUpdate.exe\" /cr",
  577. "\"C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleCrashHandler.exe\"",
  578. "\"C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleCrashHandler64.exe\""
  579. ]
  580.  
  581. [*] Mutexes: [
  582. "Global\\G{D19BAF17-7C87-467E-8D63-6C4B1C836373}",
  583. "Global\\G{D0BB2EF1-C183-4cdb-B218-040922092869}",
  584. "Local\\_!MSFTHISTORY!_",
  585. "Local\\c:!users!user!appdata!local!microsoft!windows!temporary internet files!content.ie5!",
  586. "Local\\c:!users!user!appdata!roaming!microsoft!windows!cookies!",
  587. "Local\\c:!users!user!appdata!local!microsoft!windows!history!history.ie5!",
  588. "Global\\G{6885AE8E-C070-458d-9711-37B9BEAB65F6}",
  589. "Global\\G{66CC0160-ABB3-4066-AE47-1CA6AD5065C8}",
  590. "Global\\G{0A175FBE-AEEC-4fea-855A-2AA549A88846}",
  591. "Global\\G{B5665124-2B19-40e2-A7BC-B44321E72C4B}"
  592. ]
  593.  
  594. [*] Modified Files: [
  595. "C:\\Windows\\Fonts\\Mysql\\nei.bat",
  596. "C:\\Windows\\Fonts\\Mysql\\wai.bat",
  597. "C:\\Windows\\Fonts\\Mysql\\same.bat",
  598. "C:\\Windows\\Fonts\\Mysql\\bat.bat",
  599. "C:\\Windows\\Fonts\\Mysql\\cmd.bat",
  600. "C:\\Windows\\Fonts\\Mysql\\file.txt",
  601. "C:\\Windows\\Fonts\\Mysql\\cnli-1.dll",
  602. "C:\\Windows\\Fonts\\Mysql\\coli-0.dll",
  603. "C:\\Windows\\Fonts\\Mysql\\crli-0.dll",
  604. "C:\\Windows\\Fonts\\Mysql\\dmgd-4.dll",
  605. "C:\\Windows\\Fonts\\Mysql\\Doublepulsar.dll",
  606. "C:\\Windows\\Fonts\\Mysql\\Doublepulsar2.dll",
  607. "C:\\Windows\\Fonts\\Mysql\\Eter.exe",
  608. "C:\\Windows\\Fonts\\Mysql\\Eter.xml",
  609. "C:\\Windows\\Fonts\\Mysql\\Eternalblue.dll",
  610. "C:\\Windows\\Fonts\\Mysql\\Eternalblue2.dll",
  611. "C:\\Windows\\Fonts\\Mysql\\exma-1.dll",
  612. "C:\\Windows\\Fonts\\Mysql\\libeay32.dll",
  613. "C:\\Windows\\Fonts\\Mysql\\libxml2.dll",
  614. "C:\\Windows\\Fonts\\Mysql\\loab.bat",
  615. "C:\\Windows\\Fonts\\Mysql\\load.bat",
  616. "C:\\Windows\\Fonts\\Mysql\\mance.exe",
  617. "C:\\Windows\\Fonts\\Mysql\\mance.xml",
  618. "C:\\Windows\\Fonts\\Mysql\\NansHou.dll",
  619. "C:\\Windows\\Fonts\\Mysql\\p.txt",
  620. "C:\\Windows\\Fonts\\Mysql\\poab.bat",
  621. "C:\\Windows\\Fonts\\Mysql\\poad.bat",
  622. "C:\\Windows\\Fonts\\Mysql\\posh-0.dll",
  623. "C:\\Windows\\Fonts\\Mysql\\puls.exe",
  624. "C:\\Windows\\Fonts\\Mysql\\puls.xml",
  625. "C:\\Windows\\Fonts\\Mysql\\ssleay32.dll",
  626. "C:\\Windows\\Fonts\\Mysql\\svchost.exe",
  627. "C:\\Windows\\Fonts\\Mysql\\taskhost.exe",
  628. "C:\\Windows\\Fonts\\Mysql\\tibe-2.dll",
  629. "C:\\Windows\\Fonts\\Mysql\\tich-1.dll",
  630. "C:\\Windows\\Fonts\\Mysql\\trch-1.dll",
  631. "C:\\Windows\\Fonts\\Mysql\\trfo-2.dll",
  632. "C:\\Windows\\Fonts\\Mysql\\tucl-1.dll",
  633. "C:\\Windows\\Fonts\\Mysql\\tufo-2.dll",
  634. "C:\\Windows\\Fonts\\Mysql\\ucl.dll",
  635. "C:\\Windows\\Fonts\\Mysql\\wget.exe",
  636. "C:\\Windows\\Fonts\\Mysql\\xdvl-0.dll",
  637. "C:\\Windows\\Fonts\\Mysql\\zlib1.dll",
  638. "\\??\\nul",
  639. "\\Device\\NamedPipe",
  640. "C:\\Windows\\System32\\drivers\\etc\\hosts",
  641. "C:\\Windows\\appcompat\\Programs\\RecentFileCache.bcf",
  642. "C:\\Windows\\sysnative\\Tasks\\At1",
  643. "C:\\Windows\\sysnative\\Tasks\\At2",
  644. "\\??\\PIPE\\samr",
  645. "C:\\Windows\\sysnative\\wbem\\repository\\WRITABLE.TST",
  646. "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING1.MAP",
  647. "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING2.MAP",
  648. "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING3.MAP",
  649. "C:\\Windows\\sysnative\\wbem\\repository\\OBJECTS.DATA",
  650. "C:\\Windows\\sysnative\\wbem\\repository\\INDEX.BTR",
  651. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER",
  652. "\\??\\PIPE\\srvsvc",
  653. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
  654. "\\??\\PIPE\\wkssvc",
  655. "\\??\\pipe\\GoogleCrashServices\\S-1-5-18",
  656. "C:\\Users\\user\\AppData\\Local\\Temp\\AdobeARM.log",
  657. "\\??\\pipe\\32B6B37A-4A7D-4e00-95F2-6F0BF3DE3E001599590523thsnYaVieBoda",
  658. "C:\\Users\\user\\AppData\\Local\\Temp\\ArmUI.ini",
  659. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\index.dat",
  660. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\index.dat",
  661. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\index.dat",
  662. "C:\\ProgramData\\Microsoft\\Network\\Downloader\\qmgr0.dat",
  663. "C:\\ProgramData\\Microsoft\\Network\\Downloader\\qmgr1.dat",
  664. "\\??\\pipe\\GoogleCrashServices\\S-1-5-18-x64",
  665. "C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashInstall32.log"
  666. ]
  667.  
  668. [*] Deleted Files: [
  669. "C:\\Windows\\Fonts\\Mysql\\nei.bat",
  670. "C:\\Windows\\Fonts\\Mysql\\wai.bat",
  671. "C:\\Windows\\Fonts\\Mysql\\same.bat",
  672. "C:\\Windows\\Fonts\\Mysql\\bat.bat",
  673. "C:\\Windows\\Fonts\\Mysql\\cmd.bat",
  674. "C:\\Windows\\Fonts\\Mysql\\file.txt",
  675. "C:\\Windows\\Fonts\\Mysql\\cnli-1.dll",
  676. "C:\\Windows\\Fonts\\Mysql\\coli-0.dll",
  677. "C:\\Windows\\Fonts\\Mysql\\crli-0.dll",
  678. "C:\\Windows\\Fonts\\Mysql\\dmgd-4.dll",
  679. "C:\\Windows\\Fonts\\Mysql\\Doublepulsar.dll",
  680. "C:\\Windows\\Fonts\\Mysql\\Doublepulsar2.dll",
  681. "C:\\Windows\\Fonts\\Mysql\\Eter.exe",
  682. "C:\\Windows\\Fonts\\Mysql\\Eter.xml",
  683. "C:\\Windows\\Fonts\\Mysql\\Eternalblue.dll",
  684. "C:\\Windows\\Fonts\\Mysql\\Eternalblue2.dll",
  685. "C:\\Windows\\Fonts\\Mysql\\exma-1.dll",
  686. "C:\\Windows\\Fonts\\Mysql\\libeay32.dll",
  687. "C:\\Windows\\Fonts\\Mysql\\libxml2.dll",
  688. "C:\\Windows\\Fonts\\Mysql\\loab.bat",
  689. "C:\\Windows\\Fonts\\Mysql\\load.bat",
  690. "C:\\Windows\\Fonts\\Mysql\\mance.exe",
  691. "C:\\Windows\\Fonts\\Mysql\\mance.xml",
  692. "C:\\Windows\\Fonts\\Mysql\\NansHou.dll",
  693. "C:\\Windows\\Fonts\\Mysql\\p.txt",
  694. "C:\\Windows\\Fonts\\Mysql\\poab.bat",
  695. "C:\\Windows\\Fonts\\Mysql\\poad.bat",
  696. "C:\\Windows\\Fonts\\Mysql\\posh-0.dll",
  697. "C:\\Windows\\Fonts\\Mysql\\puls.exe",
  698. "C:\\Windows\\Fonts\\Mysql\\puls.xml",
  699. "C:\\Windows\\Fonts\\Mysql\\ssleay32.dll",
  700. "C:\\Windows\\Fonts\\Mysql\\svchost.exe",
  701. "C:\\Windows\\Fonts\\Mysql\\taskhost.exe",
  702. "C:\\Windows\\Fonts\\Mysql\\tibe-2.dll",
  703. "C:\\Windows\\Fonts\\Mysql\\tich-1.dll",
  704. "C:\\Windows\\Fonts\\Mysql\\trch-1.dll",
  705. "C:\\Windows\\Fonts\\Mysql\\trfo-2.dll",
  706. "C:\\Windows\\Fonts\\Mysql\\tucl-1.dll",
  707. "C:\\Windows\\Fonts\\Mysql\\tufo-2.dll",
  708. "C:\\Windows\\Fonts\\Mysql\\ucl.dll",
  709. "C:\\Windows\\Fonts\\Mysql\\wget.exe",
  710. "C:\\Windows\\Fonts\\Mysql\\xdvl-0.dll",
  711. "C:\\Windows\\Fonts\\Mysql\\zlib1.dll",
  712. "C:\\Windows\\Tasks\\At1.job",
  713. "C:\\Windows\\Tasks\\At2.job",
  714. "C:\\Program Files (x86)\\Google\\Update\\Install\\{A01675F1-1F84-4945-B8A9-4E1FDEB013B2}\\74.0.3729.169_73.0.3683.86_chrome_updater.exe",
  715. "C:\\Program Files (x86)\\Google\\Update\\Install\\{A01675F1-1F84-4945-B8A9-4E1FDEB013B2}",
  716. "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\Recovery\\GUR513C.tmp",
  717. "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\Recovery\\GURF6B8.tmp",
  718. "C:\\Windows\\SysWOW64\\Macromed\\Temp",
  719. "C:\\Windows\\System32\\Macromed\\Temp\\{BA714F45-0DEF-445D-9FD5-04FC08D13A14}"
  720. ]
  721.  
  722. [*] Modified Registry Keys: [
  723. "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MicrosoftMysql\\Parameters",
  724. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MicrosoftMysql\\Parameters\\Application",
  725. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MicrosoftMysql\\Parameters\\AppParameters",
  726. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MicrosoftMysql\\Parameters\\AppDirectory",
  727. "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MicrosoftMysql\\Parameters\\AppExit",
  728. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MicrosoftMysql\\Parameters\\AppExit\\(Default)",
  729. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MicrosoftMysql\\FailureActionsOnNonCrashFailures",
  730. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Start",
  731. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Start",
  732. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Start",
  733. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Start",
  734. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Type",
  735. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MicrosoftMysql\\Type",
  736. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Type",
  737. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Type",
  738. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Type",
  739. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Type",
  740. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gupdate\\Type",
  741. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Start",
  742. "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EventLog\\Application\\NSSM",
  743. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Application\\NSSM\\EventMessageFile",
  744. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Application\\NSSM\\TypesSupported",
  745. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{BB6BFC46-08B9-424B-A79F-05ECFD0360B7}\\Path",
  746. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{BB6BFC46-08B9-424B-A79F-05ECFD0360B7}\\Hash",
  747. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\At1\\Id",
  748. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\At1\\Index",
  749. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{BB6BFC46-08B9-424B-A79F-05ECFD0360B7}\\Triggers",
  750. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{BB6BFC46-08B9-424B-A79F-05ECFD0360B7}\\DynamicInfo",
  751. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AEA8D717-4F47-44A8-9871-D0FFEE7A6071}\\Path",
  752. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AEA8D717-4F47-44A8-9871-D0FFEE7A6071}\\Hash",
  753. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\At2\\Id",
  754. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\At2\\Index",
  755. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AEA8D717-4F47-44A8-9871-D0FFEE7A6071}\\Triggers",
  756. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AEA8D717-4F47-44A8-9871-D0FFEE7A6071}\\DynamicInfo",
  757. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
  758. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\PreviousServiceShutdown",
  759. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ProcessID",
  760. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ThrottleDrege",
  761. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Parameters\\ServiceDllUnloadOnStop",
  762. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Wbem\\Transports\\Decoupled\\Server",
  763. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\CreationTime",
  764. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\MarshaledProxy",
  765. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\ProcessIdentifier",
  766. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ConfigValueEssNeedsLoading",
  767. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\List of event-active namespaces",
  768. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\ESS\\//./root/CIMV2\\SCM Event Provider",
  769. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{26CEE9A6-18F5-4F69-8C4D-2467328655EB}\\DynamicInfo",
  770. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\{1B2969CC-32AB-406E-A082-BFA4AEC39B70}",
  771. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{BA11F2B3-0190-41C3-95F6-1F6B8FEBB2E1}\\DynamicInfo",
  772. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\{F04E9F33-09C3-4AB6-8094-0BB7BFCC134A}",
  773. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B17E070E-57E3-43F6-96F5-A9A9C921DEBF}\\DynamicInfo",
  774. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DF000DCA-3FA2-48A6-9E59-C0606F9F8D73}\\DynamicInfo",
  775. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{ED0D73D7-BC97-46E2-AC55-FD6EB3F72C05}\\DynamicInfo",
  776. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F3F786D2-6E05-49FA-8A99-53C51C984120}\\DynamicInfo",
  777. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{74B32FB8-1950-4398-8528-773F64305286}\\DynamicInfo",
  778. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\{1B2969CC-32AB-406E-A082-BFA4AEC39B70}\\data",
  779. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\LastStartedAU",
  780. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\{F04E9F33-09C3-4AB6-8094-0BB7BFCC134A}\\data",
  781. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Performance\\PerfMMFileName",
  782. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\BackupRestore\\FilesNotToBackup\\BITS_LOG",
  783. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\BackupRestore\\FilesNotToBackup\\BITS_BAK",
  784. "HKEY_LOCAL_MACHINE\\Software\\Google\\Update\\PersistedPings\\{052AAD01-1EE0-4ABE-A555-BC7585AA1723}",
  785. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\PersistedPings\\{052AAD01-1EE0-4ABE-A555-BC7585AA1723}\\PersistedPingString",
  786. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\PersistedPings\\{052AAD01-1EE0-4ABE-A555-BC7585AA1723}\\PersistedPingTime",
  787. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\pv",
  788. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\pv",
  789. "HKEY_LOCAL_MACHINE\\Software\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\CurrentState",
  790. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\CurrentState\\StateValue",
  791. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000_CLASSES\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  792. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Google\\Update\\proxy\\source",
  793. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\RollCallDayStartSec",
  794. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\DayOfLastRollCall",
  795. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\ping_freshness",
  796. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\cohort\\(Default)",
  797. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\cohort\\hint",
  798. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\cohort\\name",
  799. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\LastCheckSuccess",
  800. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\dr",
  801. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\ActivePingDayStartSec",
  802. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\RollCallDayStartSec",
  803. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\DayOfLastActivity",
  804. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\DayOfLastRollCall",
  805. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\ping_freshness",
  806. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\cohort\\(Default)",
  807. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\cohort\\hint",
  808. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\cohort\\name",
  809. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\LastCheckSuccess",
  810. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\LastChecked",
  811. "HKEY_LOCAL_MACHINE\\Software\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\CurrentState",
  812. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\CurrentState\\StateValue",
  813. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\LastCodeRedCheck"
  814. ]
  815.  
  816. [*] Deleted Registry Keys: [
  817. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\At1.job",
  818. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\At1.job.fp",
  819. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\At2.job",
  820. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\At2.job.fp",
  821. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
  822. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Performance\\PerfMMFileName",
  823. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\uid",
  824. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\old-uid",
  825. "HKEY_CURRENT_USER\\Software\\Adobe\\Adobe ARM\\1.0\\ARM\\iNotify",
  826. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\tttoken",
  827. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\UpdateAvailableCount",
  828. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\UpdateAvailableSince",
  829. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\dr",
  830. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\tttoken",
  831. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\UpdateAvailableCount",
  832. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\UpdateAvailableSince"
  833. ]
  834.  
  835. [*] DNS Communications: []
  836.  
  837. [*] Domains: []
  838.  
  839. [*] Network Communication - ICMP: []
  840.  
  841. [*] Network Communication - HTTP: []
  842.  
  843. [*] Network Communication - SMTP: []
  844.  
  845. [*] Network Communication - Hosts: []
  846.  
  847. [*] Network Communication - IRC: []
  848.  
  849. [*] Static Analysis: {
  850. "pe": {
  851. "peid_signatures": [
  852. [
  853. "Upack V0.37 -> Dwing"
  854. ],
  855. [
  856. "Upack_Patch or any Version -> Dwing"
  857. ],
  858. [
  859. "WinUpack v0.39 final (relocated image base) -> By Dwing (c)2005 (h2)"
  860. ]
  861. ],
  862. "imports": [
  863. {
  864. "imports": [
  865. {
  866. "name": "LoadLibraryA",
  867. "address": "0xba151d"
  868. },
  869. {
  870. "name": "GetProcAddress",
  871. "address": "0xba1521"
  872. }
  873. ],
  874. "dll": "KERNEL32.DLL"
  875. }
  876. ],
  877. "digital_signers": null,
  878. "exported_dll_name": null,
  879. "actual_checksum": "0x00240215",
  880. "overlay": null,
  881. "imagebase": "0x00400000",
  882. "reported_checksum": "0x00000000",
  883. "icon_hash": null,
  884. "entrypoint": "0x00ba1259",
  885. "timestamp": "1970-01-01 01:08:16",
  886. "osversion": "4.0",
  887. "sections": [
  888. {
  889. "name": ".Upack",
  890. "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  891. "virtual_address": "0x00001000",
  892. "size_of_data": "0x00000000",
  893. "entropy": "0.00",
  894. "raw_address": "0x00000000",
  895. "virtual_size": "0x00566000",
  896. "characteristics_raw": "0xe0000060"
  897. },
  898. {
  899. "name": ".rsrc",
  900. "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  901. "virtual_address": "0x00567000",
  902. "size_of_data": "0x0023a54d",
  903. "entropy": "8.00",
  904. "raw_address": "0x00000200",
  905. "virtual_size": "0x00242000",
  906. "characteristics_raw": "0xe0000060"
  907. }
  908. ],
  909. "resources": [
  910. {
  911. "name": "RT_BITMAP",
  912. "language": "LANG_NEUTRAL",
  913. "filetype": null,
  914. "sublanguage": "SUBLANG_NEUTRAL",
  915. "entropy": "0.00",
  916. "offset": "0x0000f064",
  917. "size": "0x005563d3"
  918. }
  919. ],
  920. "dirents": [
  921. {
  922. "virtual_address": "0x00000000",
  923. "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
  924. "size": "0x00000000"
  925. },
  926. {
  927. "virtual_address": "0x007a1525",
  928. "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
  929. "size": "0x00000014"
  930. },
  931. {
  932. "virtual_address": "0x00567000",
  933. "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
  934. "size": "0x00000062"
  935. },
  936. {
  937. "virtual_address": "0x00000000",
  938. "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
  939. "size": "0x00000000"
  940. },
  941. {
  942. "virtual_address": "0x00000000",
  943. "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
  944. "size": "0x00000000"
  945. },
  946. {
  947. "virtual_address": "0x00000048",
  948. "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
  949. "size": "0x00000008"
  950. },
  951. {
  952. "virtual_address": "0x00000000",
  953. "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
  954. "size": "0x00000000"
  955. },
  956. {
  957. "virtual_address": "0x00000000",
  958. "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
  959. "size": "0x00000000"
  960. },
  961. {
  962. "virtual_address": "0x00000000",
  963. "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
  964. "size": "0x00000000"
  965. },
  966. {
  967. "virtual_address": "0x007a1505",
  968. "name": "IMAGE_DIRECTORY_ENTRY_TLS",
  969. "size": "0x00000018"
  970. },
  971. {
  972. "virtual_address": "0x00000000",
  973. "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
  974. "size": "0x00000000"
  975. },
  976. {
  977. "virtual_address": "0x00000000",
  978. "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
  979. "size": "0x00000000"
  980. },
  981. {
  982. "virtual_address": "0x00000000",
  983. "name": "IMAGE_DIRECTORY_ENTRY_IAT",
  984. "size": "0x00000000"
  985. },
  986. {
  987. "virtual_address": "0x00000000",
  988. "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
  989. "size": "0x00000000"
  990. },
  991. {
  992. "virtual_address": "0x00000000",
  993. "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
  994. "size": "0x00000000"
  995. },
  996. {
  997. "virtual_address": "0x00000000",
  998. "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
  999. "size": "0x00000000"
  1000. }
  1001. ],
  1002. "exports": [],
  1003. "guest_signers": {},
  1004. "imphash": "87bed5a7cba00c7e1f4015f1bdae2183",
  1005. "icon_fuzzy": null,
  1006. "icon": null,
  1007. "pdbpath": null,
  1008. "imported_dll_count": 1,
  1009. "versioninfo": []
  1010. }
  1011. }
  1012.  
  1013. [*] Resolved APIs: [
  1014. "user32.dll.MessageBoxA",
  1015. "kernel32.dll.Sleep",
  1016. "kernel32.dll.VirtualFree",
  1017. "kernel32.dll.VirtualAlloc",
  1018. "kernel32.dll.VirtualQuery",
  1019. "kernel32.dll.GetSystemInfo",
  1020. "kernel32.dll.GetVersion",
  1021. "kernel32.dll.SetThreadLocale",
  1022. "kernel32.dll.GetACP",
  1023. "kernel32.dll.GetStartupInfoW",
  1024. "kernel32.dll.GetProcAddress",
  1025. "kernel32.dll.GetModuleHandleW",
  1026. "kernel32.dll.GetCommandLineW",
  1027. "kernel32.dll.FreeLibrary",
  1028. "kernel32.dll.UnhandledExceptionFilter",
  1029. "kernel32.dll.RtlUnwind",
  1030. "kernel32.dll.RaiseException",
  1031. "kernel32.dll.ExitProcess",
  1032. "kernel32.dll.GetCurrentThreadId",
  1033. "kernel32.dll.DeleteCriticalSection",
  1034. "kernel32.dll.InitializeCriticalSection",
  1035. "kernel32.dll.WriteFile",
  1036. "kernel32.dll.GetStdHandle",
  1037. "kernel32.dll.CloseHandle",
  1038. "kernel32.dll.LoadLibraryA",
  1039. "kernel32.dll.GetLastError",
  1040. "kernel32.dll.TlsSetValue",
  1041. "kernel32.dll.TlsGetValue",
  1042. "kernel32.dll.LocalFree",
  1043. "kernel32.dll.LocalAlloc",
  1044. "kernel32.dll.VirtualProtect",
  1045. "kernel32.dll.SizeofResource",
  1046. "kernel32.dll.LockResource",
  1047. "kernel32.dll.LoadResource",
  1048. "kernel32.dll.GetVersionExW",
  1049. "kernel32.dll.FindResourceW",
  1050. "kernel32.dll.GetThreadPreferredUILanguages",
  1051. "kernel32.dll.SetThreadPreferredUILanguages",
  1052. "kernel32.dll.GetThreadUILanguage",
  1053. "kernel32.dll.#829",
  1054. "kernel32.dll.#693",
  1055. "kernel32.dll.#700",
  1056. "kernel32.dll.#760",
  1057. "kernel32.dll.#763",
  1058. "kernel32.dll.#1112",
  1059. "kernel32.dll.#1358",
  1060. "kernel32.dll.#1359",
  1061. "kernel32.dll.#871",
  1062. "kernel32.dll.#283",
  1063. "kernel32.dll.#84",
  1064. "kernel32.dll.#145",
  1065. "kernel32.dll.#1318",
  1066. "kernel32.dll.#1129",
  1067. "kernel32.dll.#532",
  1068. "kernel32.dll.#216",
  1069. "kernel32.dll.#131",
  1070. "kernel32.dll.#449",
  1071. "kernel32.dll.#625",
  1072. "kernel32.dll.#688",
  1073. "kernel32.dll.#644",
  1074. "kernel32.dll.#646",
  1075. "user32.dll.#2039",
  1076. "user32.dll.#2046",
  1077. "user32.dll.#2332",
  1078. "shell32.dll.#437",
  1079. "kernel32.dll.SortGetHandle",
  1080. "kernel32.dll.SortCloseHandle",
  1081. "setupapi.dll.CM_Get_Device_Interface_List_Size_ExW",
  1082. "setupapi.dll.CM_Get_Device_Interface_List_ExW",
  1083. "comctl32.dll.#386",
  1084. "advapi32.dll.UnregisterTraceGuids",
  1085. "comctl32.dll.#321",
  1086. "kernel32.dll.SetThreadUILanguage",
  1087. "kernel32.dll.CopyFileExW",
  1088. "kernel32.dll.IsDebuggerPresent",
  1089. "kernel32.dll.SetConsoleInputExeNameW",
  1090. "advapi32.dll.SaferIdentifyLevel",
  1091. "advapi32.dll.SaferComputeTokenFromLevel",
  1092. "advapi32.dll.SaferCloseLevel",
  1093. "rpcrt4.dll.I_RpcSNCHOption",
  1094. "sechost.dll.OpenSCManagerW",
  1095. "sechost.dll.OpenServiceW",
  1096. "sechost.dll.CloseServiceHandle",
  1097. "kernel32.dll.FlsAlloc",
  1098. "kernel32.dll.FlsGetValue",
  1099. "kernel32.dll.FlsSetValue",
  1100. "kernel32.dll.FlsFree",
  1101. "kernel32.dll.AttachConsole",
  1102. "kernel32.dll.SleepConditionVariableCS",
  1103. "kernel32.dll.WakeConditionVariable",
  1104. "advapi32.dll.CreateWellKnownSid",
  1105. "advapi32.dll.IsWellKnownSid",
  1106. "cryptbase.dll.SystemFunction028",
  1107. "rpcrt4.dll.NDRCContextBinding",
  1108. "rpcrt4.dll.RpcBindingToStringBindingW",
  1109. "rpcrt4.dll.I_RpcMapWin32Status",
  1110. "rpcrt4.dll.RpcStringBindingParseW",
  1111. "rpcrt4.dll.RpcStringFreeW",
  1112. "cryptbase.dll.SystemFunction004",
  1113. "mswsock.dll.WSPStartup",
  1114. "wshtcpip.dll.WSHOpenSocket",
  1115. "wshtcpip.dll.WSHOpenSocket2",
  1116. "wshtcpip.dll.WSHJoinLeaf",
  1117. "wshtcpip.dll.WSHNotify",
  1118. "wshtcpip.dll.WSHGetSocketInformation",
  1119. "wshtcpip.dll.WSHSetSocketInformation",
  1120. "wshtcpip.dll.WSHGetSockaddrType",
  1121. "wshtcpip.dll.WSHGetWildcardSockaddr",
  1122. "wshtcpip.dll.WSHGetBroadcastSockaddr",
  1123. "wshtcpip.dll.WSHAddressToString",
  1124. "wshtcpip.dll.WSHStringToAddress",
  1125. "wshtcpip.dll.WSHIoctl",
  1126. "sechost.dll.ControlService",
  1127. "sechost.dll.StartServiceW",
  1128. "version.dll.GetFileVersionInfoSizeW",
  1129. "version.dll.GetFileVersionInfoW",
  1130. "version.dll.VerQueryValueW",
  1131. "cryptbase.dll.SystemFunction036",
  1132. "uxtheme.dll.ThemeInitApiHook",
  1133. "user32.dll.IsProcessDPIAware",
  1134. "sechost.dll.LookupAccountNameLocalW",
  1135. "advapi32.dll.LookupAccountSidW",
  1136. "sechost.dll.LookupAccountSidLocalW",
  1137. "sspicli.dll.GetUserNameExW",
  1138. "advapi32.dll.GetUserNameW",
  1139. "sechost.dll.ConvertSidToStringSidW",
  1140. "xmllite.dll.CreateXmlWriter",
  1141. "xmllite.dll.CreateXmlWriterOutputWithEncodingName",
  1142. "advapi32.dll.WmiCloseBlock",
  1143. "propsys.dll.PropVariantToVariant",
  1144. "wbemcore.dll.Shutdown",
  1145. "ole32.dll.CoUninitialize",
  1146. "wmisvc.dll.ServiceMain",
  1147. "sechost.dll.RegisterServiceCtrlHandlerExW",
  1148. "sechost.dll.SetServiceStatus",
  1149. "wbemcore.dll.Reinitialize",
  1150. "advapi32.dll.WmiOpenBlock",
  1151. "vssapi.dll.CreateWriter",
  1152. "propsys.dll.VariantToPropVariant",
  1153. "authz.dll.AuthzInitializeContextFromToken",
  1154. "authz.dll.AuthzInitializeObjectAccessAuditEvent2",
  1155. "authz.dll.AuthzAccessCheck",
  1156. "authz.dll.AuthzFreeAuditEvent",
  1157. "authz.dll.AuthzFreeContext",
  1158. "authz.dll.AuthzInitializeResourceManager",
  1159. "authz.dll.AuthzFreeResourceManager",
  1160. "wmisvc.dll.IsImproperShutdownDetected",
  1161. "wevtapi.dll.EvtRender",
  1162. "wevtapi.dll.EvtNext",
  1163. "wevtapi.dll.EvtClose",
  1164. "wevtapi.dll.EvtQuery",
  1165. "wevtapi.dll.EvtCreateRenderContext",
  1166. "cryptsp.dll.CryptAcquireContextW",
  1167. "cryptsp.dll.CryptGenRandom",
  1168. "cryptsp.dll.CryptReleaseContext",
  1169. "sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW",
  1170. "oleaut32.dll.#8",
  1171. "oleaut32.dll.#2",
  1172. "oleaut32.dll.#9",
  1173. "oleaut32.dll.#6",
  1174. "oleaut32.dll.#7",
  1175. "ole32.dll.CoInitializeEx",
  1176. "oleaut32.dll.#12",
  1177. "tschannel.dll.DllGetClassObject",
  1178. "tschannel.dll.DllCanUnloadNow",
  1179. "ole32.dll.CoRevokeClassObject",
  1180. "ole32.dll.CoDisconnectContext",
  1181. "ws2_32.dll.#3",
  1182. "bitsigd.dll.UninitializeEx",
  1183. "ws2_32.dll.#116",
  1184. "sechost.dll.QueryServiceStatus",
  1185. "winsta.dll.WinStationFreeMemory",
  1186. "winsta.dll.WinStationCloseServer",
  1187. "winsta.dll.WinStationOpenServerW",
  1188. "winsta.dll.WinStationFreeGAPMemory",
  1189. "winsta.dll.WinStationGetAllProcesses",
  1190. "winsta.dll.WinStationEnumerateProcesses",
  1191. "kernel32.dll.LocaleNameToLCID",
  1192. "kernel32.dll.GetLocaleInfoEx",
  1193. "kernel32.dll.LCIDToLocaleName",
  1194. "kernel32.dll.GetSystemDefaultLocaleName",
  1195. "oleaut32.dll.#283",
  1196. "oleaut32.dll.#284",
  1197. "kernel32.dll.RegOpenKeyExW",
  1198. "ntdll.dll.EtwUnregisterTraceGuids",
  1199. "oleaut32.dll.#500",
  1200. "ntmarta.dll.GetMartaExtensionInterface",
  1201. "fastprox.dll.DllGetClassObject",
  1202. "fastprox.dll.DllCanUnloadNow",
  1203. "kernel32.dll.RegQueryValueExW",
  1204. "kernel32.dll.RegCloseKey",
  1205. "oleaut32.dll.#289",
  1206. "advapi32.dll.RegOpenKeyW",
  1207. "oleaut32.dll.#287",
  1208. "oleaut32.dll.#288",
  1209. "oleaut32.dll.#290",
  1210. "oleaut32.dll.#285",
  1211. "ntdll.dll.RtlInitUnicodeString",
  1212. "ntdll.dll.RtlFreeUnicodeString",
  1213. "ntdll.dll.NtSetSystemEnvironmentValue",
  1214. "ntdll.dll.NtQuerySystemEnvironmentValue",
  1215. "ntdll.dll.NtCreateFile",
  1216. "ntdll.dll.NtQuerySystemInformation",
  1217. "ntdll.dll.NtQueryDirectoryObject",
  1218. "ntdll.dll.NtQueryObject",
  1219. "ntdll.dll.NtOpenDirectoryObject",
  1220. "ntdll.dll.NtQueryInformationProcess",
  1221. "ntdll.dll.NtQueryInformationToken",
  1222. "ntdll.dll.NtOpenFile",
  1223. "ntdll.dll.NtClose",
  1224. "ntdll.dll.NtFsControlFile",
  1225. "ntdll.dll.NtQueryVolumeInformationFile",
  1226. "advapi32.dll.LookupPrivilegeValueW",
  1227. "winbrand.dll.BrandingLoadString",
  1228. "oleaut32.dll.#286",
  1229. "ole32.dll.StringFromCLSID",
  1230. "ole32.dll.CoTaskMemFree",
  1231. "advapi32.dll.CryptAcquireContextW",
  1232. "advapi32.dll.RegCreateKeyExW",
  1233. "shlwapi.dll.PathIsDirectoryW",
  1234. "advapi32.dll.RegQueryValueExW",
  1235. "advapi32.dll.RegNotifyChangeKeyValue",
  1236. "ole32.dll.NdrOleInitializeExtension",
  1237. "ole32.dll.CoGetClassObject",
  1238. "ole32.dll.CoGetMarshalSizeMax",
  1239. "ole32.dll.CoMarshalInterface",
  1240. "ole32.dll.CoUnmarshalInterface",
  1241. "ole32.dll.StringFromIID",
  1242. "ole32.dll.CoGetPSClsid",
  1243. "ole32.dll.CoTaskMemAlloc",
  1244. "ole32.dll.CoCreateInstance",
  1245. "ole32.dll.CoReleaseMarshalData",
  1246. "ole32.dll.DcomChannelSetHResult",
  1247. "rpcrtremote.dll.I_RpcExtInitializeExtensionPoint",
  1248. "ole32.dll.CLSIDFromOle1Class",
  1249. "clbcatq.dll.GetCatalogObject",
  1250. "clbcatq.dll.GetCatalogObject2",
  1251. "advapi32.dll.RegOpenKeyExW",
  1252. "advapi32.dll.RegSetValueExW",
  1253. "advapi32.dll.RegCloseKey",
  1254. "shlwapi.dll.PathIsPrefixW",
  1255. "advapi32.dll.CryptCreateHash",
  1256. "advapi32.dll.CryptGetHashParam",
  1257. "cryptsp.dll.CryptGetHashParam",
  1258. "advapi32.dll.CryptHashData",
  1259. "cryptsp.dll.CryptHashData",
  1260. "advapi32.dll.CryptDestroyHash",
  1261. "cryptsp.dll.CryptDestroyHash",
  1262. "xmllite.dll.CreateXmlReader",
  1263. "advapi32.dll.CryptReleaseContext",
  1264. "kernel32.dll.LCMapStringEx",
  1265. "kernel32.dll.InitializeCriticalSectionEx",
  1266. "kernel32.dll.InitOnceExecuteOnce",
  1267. "kernel32.dll.CreateEventExW",
  1268. "kernel32.dll.CreateSemaphoreW",
  1269. "kernel32.dll.CreateSemaphoreExW",
  1270. "kernel32.dll.CreateThreadpoolTimer",
  1271. "kernel32.dll.SetThreadpoolTimer",
  1272. "kernel32.dll.WaitForThreadpoolTimerCallbacks",
  1273. "kernel32.dll.CloseThreadpoolTimer",
  1274. "kernel32.dll.CreateThreadpoolWait",
  1275. "kernel32.dll.SetThreadpoolWait",
  1276. "kernel32.dll.CloseThreadpoolWait",
  1277. "kernel32.dll.FlushProcessWriteBuffers",
  1278. "kernel32.dll.FreeLibraryWhenCallbackReturns",
  1279. "kernel32.dll.GetCurrentProcessorNumber",
  1280. "kernel32.dll.CreateSymbolicLinkW",
  1281. "kernel32.dll.GetTickCount64",
  1282. "kernel32.dll.GetFileInformationByHandleEx",
  1283. "kernel32.dll.SetFileInformationByHandle",
  1284. "kernel32.dll.InitializeConditionVariable",
  1285. "kernel32.dll.WakeAllConditionVariable",
  1286. "kernel32.dll.InitializeSRWLock",
  1287. "kernel32.dll.AcquireSRWLockExclusive",
  1288. "kernel32.dll.TryAcquireSRWLockExclusive",
  1289. "kernel32.dll.ReleaseSRWLockExclusive",
  1290. "kernel32.dll.SleepConditionVariableSRW",
  1291. "kernel32.dll.CreateThreadpoolWork",
  1292. "kernel32.dll.SubmitThreadpoolWork",
  1293. "kernel32.dll.CloseThreadpoolWork",
  1294. "kernel32.dll.CompareStringEx",
  1295. "goopdate.dll.DllEntry",
  1296. "kernel32.dll.RtlCaptureStackBackTrace",
  1297. "wkscli.dll.NetWkstaGetInfo",
  1298. "cscapi.dll.CscNetApiGetInterface",
  1299. "kernel32.dll.CreateMutexExW",
  1300. "dbghelp.dll.MiniDumpWriteDump",
  1301. "rpcrt4.dll.UuidCreate",
  1302. "kernel32.dll.WTSGetActiveConsoleSessionId",
  1303. "winsta.dll.WinStationQueryInformationW",
  1304. "rpcrt4.dll.RpcStringBindingComposeW",
  1305. "rpcrt4.dll.RpcBindingFromStringBindingW",
  1306. "rpcrt4.dll.RpcBindingSetAuthInfoExW",
  1307. "rpcrt4.dll.NdrClientCall2",
  1308. "rpcrt4.dll.I_RpcExceptionFilter",
  1309. "rpcrt4.dll.RpcBindingFree",
  1310. "kernel32.dll.IsWow64Process",
  1311. "psapi.dll.GetProcessImageFileNameW",
  1312. "dwmapi.dll.DwmIsCompositionEnabled",
  1313. "kernel32.dll.WerRegisterMemoryBlock",
  1314. "advapi32.dll.EventWrite",
  1315. "advapi32.dll.EventRegister",
  1316. "advapi32.dll.EventUnregister",
  1317. "kernel32.dll.IsProcessorFeaturePresent",
  1318. "kernel32.dll.CreateActCtxW",
  1319. "kernel32.dll.ReleaseActCtx",
  1320. "kernel32.dll.ActivateActCtx",
  1321. "kernel32.dll.DeactivateActCtx",
  1322. "user32.dll.NotifyWinEvent",
  1323. "kernel32.dll.GetUserDefaultUILanguage",
  1324. "kernel32.dll.GetSystemDefaultUILanguage",
  1325. "kernel32.dll.FindActCtxSectionStringW",
  1326. "cryptbase.dll.SystemFunction041",
  1327. "kernel32.dll.GetNativeSystemInfo",
  1328. "shell32.dll.SHGetFolderPathW",
  1329. "ole32.dll.CoInitializeSecurity",
  1330. "qmgr.dll.ServiceMain",
  1331. "advapi32.dll.SetEntriesInAclW",
  1332. "ws2_32.dll.#115",
  1333. "ws2_32.dll.WSASocketW",
  1334. "ws2_32.dll.WSAIoctl",
  1335. "ws2_32.dll.#111",
  1336. "bitsigd.dll.InitializeEx",
  1337. "upnp.dll.DllGetClassObject",
  1338. "upnp.dll.DllCanUnloadNow",
  1339. "rpcrt4.dll.RpcStringBindingComposeA",
  1340. "rpcrt4.dll.RpcBindingFromStringBindingA",
  1341. "rpcrt4.dll.RpcStringFreeA",
  1342. "rpcrt4.dll.NdrClientCall3",
  1343. "oleaut32.dll.DllGetClassObject",
  1344. "oleaut32.dll.DllCanUnloadNow",
  1345. "sxs.dll.SxsOleAut32MapIIDToProxyStubCLSID",
  1346. "advapi32.dll.RegQueryValueW",
  1347. "oleaut32.dll.BSTR_UserSize",
  1348. "oleaut32.dll.BSTR_UserMarshal",
  1349. "oleaut32.dll.BSTR_UserUnmarshal",
  1350. "oleaut32.dll.BSTR_UserFree",
  1351. "oleaut32.dll.VARIANT_UserSize",
  1352. "oleaut32.dll.VARIANT_UserMarshal",
  1353. "oleaut32.dll.VARIANT_UserUnmarshal",
  1354. "oleaut32.dll.VARIANT_UserFree",
  1355. "oleaut32.dll.LPSAFEARRAY_UserSize",
  1356. "oleaut32.dll.LPSAFEARRAY_UserMarshal",
  1357. "oleaut32.dll.LPSAFEARRAY_UserUnmarshal",
  1358. "oleaut32.dll.LPSAFEARRAY_UserFree",
  1359. "advapi32.dll.LogonUserW",
  1360. "sspicli.dll.LogonUserExExW",
  1361. "wtsapi32.dll.WTSQueryUserToken",
  1362. "wtsapi32.dll.WTSEnumerateSessionsW",
  1363. "winsta.dll.WinStationEnumerateW",
  1364. "wtsapi32.dll.WTSFreeMemory",
  1365. "advapi32.dll.QueryAllTracesW",
  1366. "advapi32.dll.LookupAccountNameW",
  1367. "samcli.dll.NetLocalGroupGetMembers",
  1368. "samlib.dll.SamConnect",
  1369. "samlib.dll.SamOpenDomain",
  1370. "samlib.dll.SamLookupNamesInDomain",
  1371. "samlib.dll.SamOpenAlias",
  1372. "samlib.dll.SamFreeMemory",
  1373. "samlib.dll.SamCloseHandle",
  1374. "samlib.dll.SamGetMembersInAlias",
  1375. "netutils.dll.NetApiBufferFree",
  1376. "samlib.dll.SamEnumerateDomainsInSamServer",
  1377. "samlib.dll.SamLookupDomainInSamServer",
  1378. "ole32.dll.CoCreateGuid",
  1379. "oleaut32.dll.#4",
  1380. "ole32.dll.CoRegisterClassObject",
  1381. "iphlpapi.dll.GetAdaptersAddresses",
  1382. "psmachine.dll.DllGetClassObject",
  1383. "psmachine.dll.DllCanUnloadNow",
  1384. "ntdll.dll.RtlGetVersion",
  1385. "winhttp.dll.WinHttpAddRequestHeaders",
  1386. "winhttp.dll.WinHttpCheckPlatform",
  1387. "winhttp.dll.WinHttpCloseHandle",
  1388. "winhttp.dll.WinHttpConnect",
  1389. "winhttp.dll.WinHttpCrackUrl",
  1390. "winhttp.dll.WinHttpCreateUrl",
  1391. "winhttp.dll.WinHttpDetectAutoProxyConfigUrl",
  1392. "winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser",
  1393. "winhttp.dll.WinHttpGetDefaultProxyConfiguration",
  1394. "winhttp.dll.WinHttpGetProxyForUrl",
  1395. "winhttp.dll.WinHttpOpen",
  1396. "winhttp.dll.WinHttpOpenRequest",
  1397. "winhttp.dll.WinHttpQueryAuthSchemes",
  1398. "winhttp.dll.WinHttpQueryDataAvailable",
  1399. "winhttp.dll.WinHttpQueryHeaders",
  1400. "winhttp.dll.WinHttpQueryOption",
  1401. "winhttp.dll.WinHttpReadData",
  1402. "winhttp.dll.WinHttpReceiveResponse",
  1403. "winhttp.dll.WinHttpSendRequest",
  1404. "winhttp.dll.WinHttpSetDefaultProxyConfiguration",
  1405. "winhttp.dll.WinHttpSetCredentials",
  1406. "winhttp.dll.WinHttpSetOption",
  1407. "winhttp.dll.WinHttpSetStatusCallback",
  1408. "winhttp.dll.WinHttpSetTimeouts",
  1409. "winhttp.dll.WinHttpWriteData",
  1410. "shlwapi.dll.StrCmpNW",
  1411. "shlwapi.dll.#153",
  1412. "ws2_32.dll.GetAddrInfoW",
  1413. "ws2_32.dll.#2",
  1414. "ws2_32.dll.#21",
  1415. "ws2_32.dll.#9",
  1416. "ws2_32.dll.FreeAddrInfoW",
  1417. "ws2_32.dll.#6",
  1418. "ws2_32.dll.#5",
  1419. "schannel.dll.SpUserModeInitialize",
  1420. "ws2_32.dll.WSASend",
  1421. "ws2_32.dll.WSARecv",
  1422. "advapi32.dll.RevertToSelf",
  1423. "secur32.dll.FreeContextBuffer",
  1424. "ncrypt.dll.SslOpenProvider",
  1425. "ncrypt.dll.GetSChannelInterface",
  1426. "bcryptprimitives.dll.GetHashInterface",
  1427. "ncrypt.dll.SslIncrementProviderReferenceCount",
  1428. "ncrypt.dll.SslImportKey",
  1429. "bcryptprimitives.dll.GetCipherInterface",
  1430. "ncrypt.dll.SslLookupCipherSuiteInfo",
  1431. "user32.dll.LoadStringW",
  1432. "ncrypt.dll.BCryptOpenAlgorithmProvider",
  1433. "ncrypt.dll.BCryptGetProperty",
  1434. "ncrypt.dll.BCryptCreateHash",
  1435. "ncrypt.dll.BCryptHashData",
  1436. "ncrypt.dll.BCryptFinishHash",
  1437. "ncrypt.dll.BCryptDestroyHash",
  1438. "crypt32.dll.CertGetCertificateChain",
  1439. "userenv.dll.GetUserProfileDirectoryW",
  1440. "sechost.dll.ConvertStringSidToSidW",
  1441. "userenv.dll.RegisterGPNotification",
  1442. "gpapi.dll.RegisterGPNotificationInternal",
  1443. "sechost.dll.QueryServiceConfigW",
  1444. "winsta.dll.WinStationRegisterNotificationEvent",
  1445. "rpcrt4.dll.RpcAsyncInitializeHandle",
  1446. "rpcrt4.dll.NdrAsyncClientCall",
  1447. "cryptsp.dll.CryptAcquireContextA",
  1448. "cryptsp.dll.CryptCreateHash",
  1449. "cryptsp.dll.CryptVerifySignatureA",
  1450. "cryptsp.dll.CryptDestroyKey",
  1451. "bcryptprimitives.dll.GetAsymmetricEncryptionInterface",
  1452. "ncrypt.dll.BCryptImportKeyPair",
  1453. "ncrypt.dll.BCryptVerifySignature",
  1454. "ncrypt.dll.BCryptDestroyKey",
  1455. "crypt32.dll.CertVerifyCertificateChainPolicy",
  1456. "crypt32.dll.CertFreeCertificateChain",
  1457. "crypt32.dll.CertDuplicateCertificateContext",
  1458. "ncrypt.dll.SslEncryptPacket",
  1459. "ncrypt.dll.SslDecryptPacket",
  1460. "crypt32.dll.CertFreeCertificateContext",
  1461. "ncrypt.dll.SslFreeObject",
  1462. "kernel32.dll.GetSystemWow64DirectoryW",
  1463. "psapi.dll.GetModuleBaseNameW",
  1464. "psapi.dll.EnumProcessModules",
  1465. "kernel32.dll.QueryFullProcessImageNameW",
  1466. "flashutil32_29_0_0_171_plugin.dll.#1",
  1467. "kernel32.dll.CreateDirectoryW",
  1468. "kernel32.dll.CreateFileW",
  1469. "kernel32.dll.CreateProcessW",
  1470. "kernel32.dll.DeleteFileW",
  1471. "kernel32.dll.GetModuleFileNameW",
  1472. "kernel32.dll.MoveFileExA",
  1473. "kernel32.dll.MoveFileExW",
  1474. "kernel32.dll.RemoveDirectoryW",
  1475. "kernel32.dll.GetSystemDirectoryW",
  1476. "kernel32.dll.ExpandEnvironmentStringsW",
  1477. "kernel32.dll.FindFirstFileW",
  1478. "kernel32.dll.FindNextFileW",
  1479. "kernel32.dll.GetFileAttributesW",
  1480. "kernel32.dll.SetFileAttributesW",
  1481. "kernel32.dll.GetFileAttributesExW",
  1482. "kernel32.dll.GetCurrentDirectoryW",
  1483. "kernel32.dll.SetCurrentDirectoryW",
  1484. "kernel32.dll.GetTempPathW",
  1485. "kernel32.dll.GetTempFileNameW",
  1486. "kernel32.dll.CopyFileW",
  1487. "kernel32.dll.GetFullPathNameW",
  1488. "kernel32.dll.GetVolumeInformationW",
  1489. "advapi32.dll.OpenProcessToken",
  1490. "advapi32.dll.GetTokenInformation",
  1491. "advapi32.dll.GetSidSubAuthority",
  1492. "advapi32.dll.GetSidSubAuthorityCount"
  1493. ]
  1494.  
  1495. [*] Static Analysis: {
  1496. "pe": {
  1497. "peid_signatures": [
  1498. [
  1499. "Upack V0.37 -> Dwing"
  1500. ],
  1501. [
  1502. "Upack_Patch or any Version -> Dwing"
  1503. ],
  1504. [
  1505. "WinUpack v0.39 final (relocated image base) -> By Dwing (c)2005 (h2)"
  1506. ]
  1507. ],
  1508. "imports": [
  1509. {
  1510. "imports": [
  1511. {
  1512. "name": "LoadLibraryA",
  1513. "address": "0xba151d"
  1514. },
  1515. {
  1516. "name": "GetProcAddress",
  1517. "address": "0xba1521"
  1518. }
  1519. ],
  1520. "dll": "KERNEL32.DLL"
  1521. }
  1522. ],
  1523. "digital_signers": null,
  1524. "exported_dll_name": null,
  1525. "actual_checksum": "0x00240215",
  1526. "overlay": null,
  1527. "imagebase": "0x00400000",
  1528. "reported_checksum": "0x00000000",
  1529. "icon_hash": null,
  1530. "entrypoint": "0x00ba1259",
  1531. "timestamp": "1970-01-01 01:08:16",
  1532. "osversion": "4.0",
  1533. "sections": [
  1534. {
  1535. "name": ".Upack",
  1536. "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  1537. "virtual_address": "0x00001000",
  1538. "size_of_data": "0x00000000",
  1539. "entropy": "0.00",
  1540. "raw_address": "0x00000000",
  1541. "virtual_size": "0x00566000",
  1542. "characteristics_raw": "0xe0000060"
  1543. },
  1544. {
  1545. "name": ".rsrc",
  1546. "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  1547. "virtual_address": "0x00567000",
  1548. "size_of_data": "0x0023a54d",
  1549. "entropy": "8.00",
  1550. "raw_address": "0x00000200",
  1551. "virtual_size": "0x00242000",
  1552. "characteristics_raw": "0xe0000060"
  1553. }
  1554. ],
  1555. "resources": [
  1556. {
  1557. "name": "RT_BITMAP",
  1558. "language": "LANG_NEUTRAL",
  1559. "filetype": null,
  1560. "sublanguage": "SUBLANG_NEUTRAL",
  1561. "entropy": "0.00",
  1562. "offset": "0x0000f064",
  1563. "size": "0x005563d3"
  1564. }
  1565. ],
  1566. "dirents": [
  1567. {
  1568. "virtual_address": "0x00000000",
  1569. "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
  1570. "size": "0x00000000"
  1571. },
  1572. {
  1573. "virtual_address": "0x007a1525",
  1574. "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
  1575. "size": "0x00000014"
  1576. },
  1577. {
  1578. "virtual_address": "0x00567000",
  1579. "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
  1580. "size": "0x00000062"
  1581. },
  1582. {
  1583. "virtual_address": "0x00000000",
  1584. "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
  1585. "size": "0x00000000"
  1586. },
  1587. {
  1588. "virtual_address": "0x00000000",
  1589. "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
  1590. "size": "0x00000000"
  1591. },
  1592. {
  1593. "virtual_address": "0x00000048",
  1594. "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
  1595. "size": "0x00000008"
  1596. },
  1597. {
  1598. "virtual_address": "0x00000000",
  1599. "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
  1600. "size": "0x00000000"
  1601. },
  1602. {
  1603. "virtual_address": "0x00000000",
  1604. "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
  1605. "size": "0x00000000"
  1606. },
  1607. {
  1608. "virtual_address": "0x00000000",
  1609. "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
  1610. "size": "0x00000000"
  1611. },
  1612. {
  1613. "virtual_address": "0x007a1505",
  1614. "name": "IMAGE_DIRECTORY_ENTRY_TLS",
  1615. "size": "0x00000018"
  1616. },
  1617. {
  1618. "virtual_address": "0x00000000",
  1619. "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
  1620. "size": "0x00000000"
  1621. },
  1622. {
  1623. "virtual_address": "0x00000000",
  1624. "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
  1625. "size": "0x00000000"
  1626. },
  1627. {
  1628. "virtual_address": "0x00000000",
  1629. "name": "IMAGE_DIRECTORY_ENTRY_IAT",
  1630. "size": "0x00000000"
  1631. },
  1632. {
  1633. "virtual_address": "0x00000000",
  1634. "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
  1635. "size": "0x00000000"
  1636. },
  1637. {
  1638. "virtual_address": "0x00000000",
  1639. "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
  1640. "size": "0x00000000"
  1641. },
  1642. {
  1643. "virtual_address": "0x00000000",
  1644. "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
  1645. "size": "0x00000000"
  1646. }
  1647. ],
  1648. "exports": [],
  1649. "guest_signers": {},
  1650. "imphash": "87bed5a7cba00c7e1f4015f1bdae2183",
  1651. "icon_fuzzy": null,
  1652. "icon": null,
  1653. "pdbpath": null,
  1654. "imported_dll_count": 1,
  1655. "versioninfo": []
  1656. }
  1657. }
Advertisement
Add Comment
Please, Sign In to add comment