Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: "Shadowbrokers"
- [*] MalScore: 10.0
- [*] File Name: "ctfmon.exe"
- [*] File Size: 2336589
- [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- [*] SHA256: "181ce9db0dea2a3a2e08860620c3015e61995a93729cb07e0b157d0e75c73343"
- [*] MD5: "762ed51daa67d2a6a4ea641ec5a5b6f3"
- [*] SHA1: "9d6f2b7db9b2ee86206fc209824bd4fc23f594cd"
- [*] SHA512: "8bd5eb9759acb4d416788c1ef0233105feb52658d60553d9dd1171554cc7fa59c37f79043702abf86400173dc95511b76f0ea310e8446cf7b952f826a2204602"
- [*] CRC32: "80156EAA"
- [*] SSDEEP: "49152:jyWhIEPXY6Ya8tX/sXoOTHFBFbh5uAdOS9UoEoEEuCWXzI82mN:jyWOAhMfOTHn9C/S9UsEEqXF"
- [*] Process Execution: [
- "ctfmon.exe",
- "cmd.exe",
- "net.exe",
- "net1.exe",
- "net.exe",
- "net1.exe",
- "svchost.exe",
- "svchost.exe",
- "sc.exe",
- "sc.exe",
- "svchost.exe",
- "svchost.exe",
- "svchost.exe",
- "PING.EXE",
- "svchost.exe",
- "net.exe",
- "net1.exe",
- "cmd.exe",
- "schtasks.exe",
- "cmd.exe",
- "schtasks.exe",
- "attrib.exe",
- "attrib.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "sc.exe",
- "net.exe",
- "net1.exe",
- "taskkill.exe",
- "taskkill.exe",
- "taskkill.exe",
- "taskkill.exe",
- "taskkill.exe",
- "taskkill.exe",
- "services.exe",
- "svchost.exe",
- "cmd.exe",
- "mode.com",
- "sc.exe",
- "sc.exe",
- "sc.exe",
- "sc.exe",
- "net.exe",
- "net1.exe",
- "net.exe",
- "net1.exe",
- "net.exe",
- "net1.exe",
- "net.exe",
- "net1.exe",
- "taskkill.exe",
- "taskkill.exe",
- "taskkill.exe",
- "taskkill.exe",
- "taskkill.exe",
- "taskkill.exe",
- "svchost.exe",
- "taskeng.exe",
- "GoogleUpdate.exe",
- "GoogleUpdate.exe",
- "GoogleUpdate.exe",
- "GoogleCrashHandler.exe",
- "GoogleCrashHandler64.exe",
- "GoogleUpdate.exe",
- "GoogleCrashHandler.exe",
- "GoogleCrashHandler64.exe",
- "taskeng.exe",
- "msoia.exe",
- "AdobeARM.exe",
- "msoia.exe",
- "FlashUtil32_29_0_0_171_Plugin.exe",
- "svchost.exe",
- "WmiPrvSE.exe",
- "svchost.exe",
- "GoogleUpdate.exe"
- ]
- [*] Signatures Detected: [
- {
- "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
- "Details": [
- {
- "IP": "172.217.0.227:443"
- }
- ]
- },
- {
- "Description": "Possible date expiration check, exits too soon after checking local time",
- "Details": [
- {
- "process": "mode.com, PID 2336"
- }
- ]
- },
- {
- "Description": "Creates RWX memory",
- "Details": []
- },
- {
- "Description": "A process attempted to delay the analysis task.",
- "Details": [
- {
- "Process": "taskkill.exe tried to sleep 1860 seconds, actually delayed analysis time by 0 seconds"
- },
- {
- "Process": "taskeng.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
- },
- {
- "Process": "WmiPrvSE.exe tried to sleep 660 seconds, actually delayed analysis time by 0 seconds"
- }
- ]
- },
- {
- "Description": "At least one IP Address, Domain, or File Name was found in a crypto call",
- "Details": [
- {
- "ioc": "http://crl.globalsign.net/root-r2.crl0"
- }
- ]
- },
- {
- "Description": "A process created a hidden window",
- "Details": [
- {
- "Process": "ctfmon.exe -> C:\\Windows\\Fonts\\Mysql\\same.bat"
- }
- ]
- },
- {
- "Description": "Drops a binary and executes it",
- "Details": [
- {
- "binary": "C:\\Windows\\Fonts\\Mysql\\svchost.exe"
- }
- ]
- },
- {
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details": [
- {
- "section": "name: .rsrc, entropy: 8.00, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x0023a54d, virtual_size: 0x00242000"
- }
- ]
- },
- {
- "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
- "Details": [
- {
- "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 7267266 times"
- }
- ]
- },
- {
- "Description": "Attempts to execute a Living Off The Land Binary command for post exeploitation",
- "Details": [
- {
- "MITRE T1078 - schtask": "(Tactic: Execution, Persistence, Privilege Escalation)"
- }
- ]
- },
- {
- "Description": "Installs itself for autorun at Windows startup",
- "Details": [
- {
- "service name": "MicrosoftMysql"
- },
- {
- "service path": "C:\\Windows\\Fonts\\Mysql\\svchost.exe"
- },
- {
- "task": "schtasks /create /TN \"At1\" /TR \"C:\\Windows\\Fonts\\Mysql\\nei.bat\" /SC daily /ST 11:30:00 /RU SYSTEM"
- }
- ]
- },
- {
- "Description": "Creates a hidden or system file",
- "Details": [
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\nei.bat"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\wai.bat"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\bat.bat"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\cmd.bat"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\Doublepulsar.dll"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\Doublepulsar2.dll"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\Eternalblue.dll"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\Eternalblue2.dll"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\loab.bat"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\load.bat"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\poab.bat"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\poad.bat"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\taskhost.exe"
- },
- {
- "file": "C:\\Windows\\Fonts\\Mysql\\wget.exe"
- }
- ]
- },
- {
- "Description": "File has been identified by 56 Antiviruses on VirusTotal as malicious",
- "Details": [
- {
- "MicroWorld-eScan": "Trojan.GenericKD.41102453"
- },
- {
- "FireEye": "Generic.mg.762ed51daa67d2a6"
- },
- {
- "CAT-QuickHeal": "W32.Viking.gen"
- },
- {
- "McAfee": "Artemis!762ED51DAA67"
- },
- {
- "Malwarebytes": "Trojan.MalPack"
- },
- {
- "K7AntiVirus": "Trojan ( 005329b91 )"
- },
- {
- "Alibaba": "Backdoor:Win32/ShadowBrokers.56853b57"
- },
- {
- "K7GW": "Trojan ( 005329b91 )"
- },
- {
- "Cybereason": "malicious.daa67d"
- },
- {
- "Arcabit": "Trojan.Generic.D2732C75"
- },
- {
- "Invincea": "heuristic"
- },
- {
- "NANO-Antivirus": "Trojan.Win32.Delphi.fihmoq"
- },
- {
- "Cyren": "W32/Trojan.ZDWN-4222"
- },
- {
- "Symantec": "Trojan.Gen.MBT"
- },
- {
- "APEX": "Malicious"
- },
- {
- "Avast": "Win32:Evo-gen [Susp]"
- },
- {
- "ClamAV": "Win.Malware.Shadowbrokers-6958490-0"
- },
- {
- "Kaspersky": "Trojan.Win32.ShadowBrokers.ao"
- },
- {
- "BitDefender": "Trojan.GenericKD.41102453"
- },
- {
- "Paloalto": "generic.ml"
- },
- {
- "AegisLab": "Trojan.Win32.ShadowBrokers.4!c"
- },
- {
- "Tencent": "Win32.Trojan.Shadowbrokers.Afrq"
- },
- {
- "Ad-Aware": "Trojan.GenericKD.41102453"
- },
- {
- "Emsisoft": "Trojan.GenericKD.41102453 (B)"
- },
- {
- "Comodo": "Packed.Win32.Klone.~KMG@1knj1d"
- },
- {
- "F-Secure": "Trojan.TR/Dropper.Gen"
- },
- {
- "DrWeb": "Trojan.PWS.Panda.8062"
- },
- {
- "Zillya": "Trojan.ShadowBrokers.Win32.104"
- },
- {
- "TrendMicro": "Cryp_Xed-12"
- },
- {
- "McAfee-GW-Edition": "BehavesLike.Win32.Generic.vc"
- },
- {
- "Sophos": "Mal/EncPk-BW"
- },
- {
- "SentinelOne": "DFI - Malicious PE"
- },
- {
- "ESET-NOD32": "a variant of Win32/TrojanDropper.Agent.QBR"
- },
- {
- "eGambit": "Unsafe.AI_Score_99%"
- },
- {
- "Avira": "TR/Dropper.Gen"
- },
- {
- "Microsoft": "Trojan:Win32/Skeeyah.A!bit"
- },
- {
- "Endgame": "malicious (high confidence)"
- },
- {
- "ZoneAlarm": "Trojan.Win32.ShadowBrokers.ao"
- },
- {
- "GData": "Trojan.GenericKD.41102453"
- },
- {
- "AhnLab-V3": "Trojan/Win32.OnlineGameHack.R36603"
- },
- {
- "Acronis": "suspicious"
- },
- {
- "VBA32": "Trojan.ShadowBrokers"
- },
- {
- "ALYac": "Trojan.ShadowBrokers.A"
- },
- {
- "MAX": "malware (ai score=100)"
- },
- {
- "Cylance": "Unsafe"
- },
- {
- "TrendMicro-HouseCall": "Cryp_Xed-12"
- },
- {
- "Rising": "Backdoor.Agent!8.C5D (CLOUD)"
- },
- {
- "Yandex": "Trojan.DR.Agent!fBKh2F2rB8o"
- },
- {
- "Ikarus": "Trojan.Dropper"
- },
- {
- "MaxSecure": "Trojan.Malware.0.susgen"
- },
- {
- "Fortinet": "PossibleThreat"
- },
- {
- "Webroot": "W32.Trojan.Gen"
- },
- {
- "AVG": "FileRepMalware"
- },
- {
- "Panda": "Trj/Genetic.gen"
- },
- {
- "CrowdStrike": "win/malicious_confidence_100% (W)"
- },
- {
- "Qihoo-360": "Win32/Trojan.46e"
- }
- ]
- },
- {
- "Description": "The sample wrote data to the system hosts file.",
- "Details": [
- {
- "added": "103.18.244.217 donate.v2.darks.xyz"
- },
- {
- "added": "103.18.244.217 pool.minexmr.com"
- },
- {
- "added": "103.18.244.217 donate.v2.kiss58.org"
- },
- {
- "added": "103.18.244.217 donate.v2.googel-dns.com"
- },
- {
- "added": "103.18.244.217 pool.bulehero.in"
- },
- {
- "added": "103.18.244.217 sg.minexmr.com"
- }
- ]
- }
- ]
- [*] Started Service: [
- "MicrosoftMysql",
- "Browser",
- "LanmanWorkstation",
- "LanmanServer",
- "gupdate",
- "Schedule"
- ]
- [*] Executed Commands: [
- "C:\\Windows\\Fonts\\Mysql\\same.bat ",
- "net stop \"MicrosoftMysql\"",
- "net stop \"MicrosoftMssql\"",
- "svchost stop \"MicrosoftFonts\"",
- "svchost stop \"MicrosoftMysql\"",
- "sc delete \"MicrosoftMysql\"",
- "sc delete \"MicrosoftMssql\"",
- "svchost install MicrosoftMysql \"C:\\Windows\\Fonts\\Mysql\\cmd.bat\"",
- "svchost install MicrosoftMysql C:\\Windows\\Fonts\\Mysql\\cmd.bat",
- "svchost install \"MicrosoftMysql\" C:\\Windows\\Fonts\\Mysql\\cmd.bat",
- "C:\\Windows\\system32\\PING.EXE ping 127.0.0.1 -n 20",
- "svchost start \"MicrosoftMysql\"",
- "net start \"MicrosoftMysql\"",
- "C:\\Windows\\system32\\cmd.exe /S /D /c\" echo y\"",
- "schtasks /create /TN \"At1\" /TR \"C:\\Windows\\Fonts\\Mysql\\nei.bat\" /SC daily /ST 11:30:00 /RU SYSTEM",
- "schtasks /create /TN \"At2\" /TR \"C:\\Windows\\Fonts\\Mysql\\wai.bat\" /SC daily /ST 01:00:00 /RU SYSTEM",
- "attrib +h +s -r C:\\windows\\tasks\\At*.job",
- "attrib +h +s -r C:\\Windows\\System32\\Tasks\\At*",
- "cacls C:\\windows\\tasks\\At1.job /c /e /t /g system:F",
- "cacls C:\\windows\\tasks\\At2.job /c /e /t /g system:F",
- "cacls C:\\windows\\tasks\\At1.job /c /e /t /g everyone:F",
- "cacls C:\\windows\\tasks\\At2.job /c /e /t /g everyone:F",
- "cacls C:\\Windows\\System32\\Tasks\\At1 /c /e /t /g system:F",
- "cacls C:\\Windows\\System32\\Tasks\\At2 /c /e /t /g system:F",
- "cacls C:\\Windows\\System32\\Tasks\\At1 /c /e /t /g everyone:F",
- "cacls C:\\Windows\\System32\\Tasks\\At2 /c /e /t /g everyone:F",
- "cacls C:\\Windows\\Tasks\\MiscfostNsi /p system:n",
- "cacls C:\\Windows\\Tasks\\HomeGroupProvider /p system:n",
- "cacls C:\\Windows\\Tasks\\WwANsvc /p system:n",
- "cacls C:\\Windows\\Tasks\\*fost* /p system:n",
- "cacls C:\\Windows\\Tasks\\*Group* /p system:n",
- "cacls C:\\Windows\\Tasks\\*sa* /p system:n",
- "cacls C:\\Windows\\Tasks\\*ok* /p system:n",
- "cacls C:\\Windows\\Tasks\\*my* /p system:n",
- "cacls C:\\Windows\\System32\\Tasks\\MiscfostNsi /p system:n",
- "cacls C:\\Windows\\System32\\Tasks\\HomeGroupProvider /p system:n",
- "cacls C:\\Windows\\System32\\Tasks\\WwANsvc /p system:n",
- "cacls C:\\Windows\\System32\\Tasks\\*fost* /p system:n",
- "cacls C:\\Windows\\System32\\Tasks\\*Group* /p system:n",
- "cacls C:\\Windows\\System32\\Tasks\\*sa* /p system:n",
- "cacls C:\\Windows\\System32\\Tasks\\*ok* /p system:n",
- "cacls C:\\Windows\\System32\\Tasks\\*my* /p system:n",
- "sc start Schedule",
- "net start Schedule",
- "taskkill /f /im Eternalblue-2.2.0.exe",
- "taskkill /f /im Doublepulsar-1.3.1.exe",
- "taskkill /f /im one.exe",
- "taskkill /f /im z.exe",
- "taskkill /f /im c32.exe",
- "taskkill /f /im c64.exe",
- "C:\\Windows\\system32\\net1 stop \"MicrosoftMysql\"",
- "C:\\Windows\\system32\\net1 stop \"MicrosoftMssql\"",
- "C:\\Windows\\Fonts\\Mysql\\svchost.exe",
- "C:\\Windows\\System32\\svchost.exe -k netsvcs",
- "\"C:\\Program Files (x86)\\Google\\Update\\GoogleUpdate.exe\" /svc",
- "\"C:\\Windows\\Fonts\\Mysql\\cmd.bat\"",
- "mode con cols=50 lines=40",
- "sc config Browser start= auto",
- "sc config lanmanworkstation start= auto",
- "sc config lanmanserver start= auto",
- "sc config SharedAccess start= disabled",
- "net start Browser",
- "net start lanmanworkstation",
- "net start lanmanserver",
- "net stop SharedAccess",
- "taskkill /f /im mance.exe",
- "taskkill /f /im Eter.exe",
- "taskkill /f /im puls.exe",
- "C:\\Windows\\system32\\net1 start Browser",
- "C:\\Windows\\system32\\net1 start \"MicrosoftMysql\"",
- "C:\\Windows\\system32\\net1 start lanmanworkstation",
- "taskeng.exe {1B2969CC-32AB-406E-A082-BFA4AEC39B70} S-1-5-18:NT AUTHORITY\\System:Service:",
- "taskeng.exe {F04E9F33-09C3-4AB6-8094-0BB7BFCC134A} S-1-5-21-0000000000-0000000000-0000000000-1000:Host\\user:Interactive:[1]",
- "C:\\Windows\\system32\\net1 start lanmanserver",
- "C:\\Windows\\system32\\net1 stop SharedAccess",
- "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding",
- "C:\\Windows\\system32\\net1 start Schedule",
- "\"C:\\Program Files (x86)\\Google\\Update\\GoogleUpdate.exe\" /ua /installsource scheduler",
- "\"C:\\Program Files\\Common Files\\Microsoft Shared\\Office15\\OLicenseHeartbeat.exe\"",
- "\"C:\\Program Files (x86)\\Google\\Update\\GoogleUpdate.exe\" /c",
- "\"C:\\Program Files\\Microsoft Office\\Office15\\msoia.exe\" scan upload mininterval:2880",
- "\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\"",
- "\"C:\\Program Files\\Microsoft Office\\Office15\\msoia.exe\" scan upload",
- "C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_29_0_0_171_Plugin.exe -check plugin",
- "\"C:\\Program Files (x86)\\Google\\Update\\GoogleUpdate.exe\" /cr",
- "\"C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleCrashHandler.exe\"",
- "\"C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\GoogleCrashHandler64.exe\""
- ]
- [*] Mutexes: [
- "Global\\G{D19BAF17-7C87-467E-8D63-6C4B1C836373}",
- "Global\\G{D0BB2EF1-C183-4cdb-B218-040922092869}",
- "Local\\_!MSFTHISTORY!_",
- "Local\\c:!users!user!appdata!local!microsoft!windows!temporary internet files!content.ie5!",
- "Local\\c:!users!user!appdata!roaming!microsoft!windows!cookies!",
- "Local\\c:!users!user!appdata!local!microsoft!windows!history!history.ie5!",
- "Global\\G{6885AE8E-C070-458d-9711-37B9BEAB65F6}",
- "Global\\G{66CC0160-ABB3-4066-AE47-1CA6AD5065C8}",
- "Global\\G{0A175FBE-AEEC-4fea-855A-2AA549A88846}",
- "Global\\G{B5665124-2B19-40e2-A7BC-B44321E72C4B}"
- ]
- [*] Modified Files: [
- "C:\\Windows\\Fonts\\Mysql\\nei.bat",
- "C:\\Windows\\Fonts\\Mysql\\wai.bat",
- "C:\\Windows\\Fonts\\Mysql\\same.bat",
- "C:\\Windows\\Fonts\\Mysql\\bat.bat",
- "C:\\Windows\\Fonts\\Mysql\\cmd.bat",
- "C:\\Windows\\Fonts\\Mysql\\file.txt",
- "C:\\Windows\\Fonts\\Mysql\\cnli-1.dll",
- "C:\\Windows\\Fonts\\Mysql\\coli-0.dll",
- "C:\\Windows\\Fonts\\Mysql\\crli-0.dll",
- "C:\\Windows\\Fonts\\Mysql\\dmgd-4.dll",
- "C:\\Windows\\Fonts\\Mysql\\Doublepulsar.dll",
- "C:\\Windows\\Fonts\\Mysql\\Doublepulsar2.dll",
- "C:\\Windows\\Fonts\\Mysql\\Eter.exe",
- "C:\\Windows\\Fonts\\Mysql\\Eter.xml",
- "C:\\Windows\\Fonts\\Mysql\\Eternalblue.dll",
- "C:\\Windows\\Fonts\\Mysql\\Eternalblue2.dll",
- "C:\\Windows\\Fonts\\Mysql\\exma-1.dll",
- "C:\\Windows\\Fonts\\Mysql\\libeay32.dll",
- "C:\\Windows\\Fonts\\Mysql\\libxml2.dll",
- "C:\\Windows\\Fonts\\Mysql\\loab.bat",
- "C:\\Windows\\Fonts\\Mysql\\load.bat",
- "C:\\Windows\\Fonts\\Mysql\\mance.exe",
- "C:\\Windows\\Fonts\\Mysql\\mance.xml",
- "C:\\Windows\\Fonts\\Mysql\\NansHou.dll",
- "C:\\Windows\\Fonts\\Mysql\\p.txt",
- "C:\\Windows\\Fonts\\Mysql\\poab.bat",
- "C:\\Windows\\Fonts\\Mysql\\poad.bat",
- "C:\\Windows\\Fonts\\Mysql\\posh-0.dll",
- "C:\\Windows\\Fonts\\Mysql\\puls.exe",
- "C:\\Windows\\Fonts\\Mysql\\puls.xml",
- "C:\\Windows\\Fonts\\Mysql\\ssleay32.dll",
- "C:\\Windows\\Fonts\\Mysql\\svchost.exe",
- "C:\\Windows\\Fonts\\Mysql\\taskhost.exe",
- "C:\\Windows\\Fonts\\Mysql\\tibe-2.dll",
- "C:\\Windows\\Fonts\\Mysql\\tich-1.dll",
- "C:\\Windows\\Fonts\\Mysql\\trch-1.dll",
- "C:\\Windows\\Fonts\\Mysql\\trfo-2.dll",
- "C:\\Windows\\Fonts\\Mysql\\tucl-1.dll",
- "C:\\Windows\\Fonts\\Mysql\\tufo-2.dll",
- "C:\\Windows\\Fonts\\Mysql\\ucl.dll",
- "C:\\Windows\\Fonts\\Mysql\\wget.exe",
- "C:\\Windows\\Fonts\\Mysql\\xdvl-0.dll",
- "C:\\Windows\\Fonts\\Mysql\\zlib1.dll",
- "\\??\\nul",
- "\\Device\\NamedPipe",
- "C:\\Windows\\System32\\drivers\\etc\\hosts",
- "C:\\Windows\\appcompat\\Programs\\RecentFileCache.bcf",
- "C:\\Windows\\sysnative\\Tasks\\At1",
- "C:\\Windows\\sysnative\\Tasks\\At2",
- "\\??\\PIPE\\samr",
- "C:\\Windows\\sysnative\\wbem\\repository\\WRITABLE.TST",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING1.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING2.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING3.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\OBJECTS.DATA",
- "C:\\Windows\\sysnative\\wbem\\repository\\INDEX.BTR",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER",
- "\\??\\PIPE\\srvsvc",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
- "\\??\\PIPE\\wkssvc",
- "\\??\\pipe\\GoogleCrashServices\\S-1-5-18",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdobeARM.log",
- "\\??\\pipe\\32B6B37A-4A7D-4e00-95F2-6F0BF3DE3E001599590523thsnYaVieBoda",
- "C:\\Users\\user\\AppData\\Local\\Temp\\ArmUI.ini",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\index.dat",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\index.dat",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\index.dat",
- "C:\\ProgramData\\Microsoft\\Network\\Downloader\\qmgr0.dat",
- "C:\\ProgramData\\Microsoft\\Network\\Downloader\\qmgr1.dat",
- "\\??\\pipe\\GoogleCrashServices\\S-1-5-18-x64",
- "C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashInstall32.log"
- ]
- [*] Deleted Files: [
- "C:\\Windows\\Fonts\\Mysql\\nei.bat",
- "C:\\Windows\\Fonts\\Mysql\\wai.bat",
- "C:\\Windows\\Fonts\\Mysql\\same.bat",
- "C:\\Windows\\Fonts\\Mysql\\bat.bat",
- "C:\\Windows\\Fonts\\Mysql\\cmd.bat",
- "C:\\Windows\\Fonts\\Mysql\\file.txt",
- "C:\\Windows\\Fonts\\Mysql\\cnli-1.dll",
- "C:\\Windows\\Fonts\\Mysql\\coli-0.dll",
- "C:\\Windows\\Fonts\\Mysql\\crli-0.dll",
- "C:\\Windows\\Fonts\\Mysql\\dmgd-4.dll",
- "C:\\Windows\\Fonts\\Mysql\\Doublepulsar.dll",
- "C:\\Windows\\Fonts\\Mysql\\Doublepulsar2.dll",
- "C:\\Windows\\Fonts\\Mysql\\Eter.exe",
- "C:\\Windows\\Fonts\\Mysql\\Eter.xml",
- "C:\\Windows\\Fonts\\Mysql\\Eternalblue.dll",
- "C:\\Windows\\Fonts\\Mysql\\Eternalblue2.dll",
- "C:\\Windows\\Fonts\\Mysql\\exma-1.dll",
- "C:\\Windows\\Fonts\\Mysql\\libeay32.dll",
- "C:\\Windows\\Fonts\\Mysql\\libxml2.dll",
- "C:\\Windows\\Fonts\\Mysql\\loab.bat",
- "C:\\Windows\\Fonts\\Mysql\\load.bat",
- "C:\\Windows\\Fonts\\Mysql\\mance.exe",
- "C:\\Windows\\Fonts\\Mysql\\mance.xml",
- "C:\\Windows\\Fonts\\Mysql\\NansHou.dll",
- "C:\\Windows\\Fonts\\Mysql\\p.txt",
- "C:\\Windows\\Fonts\\Mysql\\poab.bat",
- "C:\\Windows\\Fonts\\Mysql\\poad.bat",
- "C:\\Windows\\Fonts\\Mysql\\posh-0.dll",
- "C:\\Windows\\Fonts\\Mysql\\puls.exe",
- "C:\\Windows\\Fonts\\Mysql\\puls.xml",
- "C:\\Windows\\Fonts\\Mysql\\ssleay32.dll",
- "C:\\Windows\\Fonts\\Mysql\\svchost.exe",
- "C:\\Windows\\Fonts\\Mysql\\taskhost.exe",
- "C:\\Windows\\Fonts\\Mysql\\tibe-2.dll",
- "C:\\Windows\\Fonts\\Mysql\\tich-1.dll",
- "C:\\Windows\\Fonts\\Mysql\\trch-1.dll",
- "C:\\Windows\\Fonts\\Mysql\\trfo-2.dll",
- "C:\\Windows\\Fonts\\Mysql\\tucl-1.dll",
- "C:\\Windows\\Fonts\\Mysql\\tufo-2.dll",
- "C:\\Windows\\Fonts\\Mysql\\ucl.dll",
- "C:\\Windows\\Fonts\\Mysql\\wget.exe",
- "C:\\Windows\\Fonts\\Mysql\\xdvl-0.dll",
- "C:\\Windows\\Fonts\\Mysql\\zlib1.dll",
- "C:\\Windows\\Tasks\\At1.job",
- "C:\\Windows\\Tasks\\At2.job",
- "C:\\Program Files (x86)\\Google\\Update\\Install\\{A01675F1-1F84-4945-B8A9-4E1FDEB013B2}\\74.0.3729.169_73.0.3683.86_chrome_updater.exe",
- "C:\\Program Files (x86)\\Google\\Update\\Install\\{A01675F1-1F84-4945-B8A9-4E1FDEB013B2}",
- "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\Recovery\\GUR513C.tmp",
- "C:\\Program Files (x86)\\Google\\Update\\1.3.34.11\\Recovery\\GURF6B8.tmp",
- "C:\\Windows\\SysWOW64\\Macromed\\Temp",
- "C:\\Windows\\System32\\Macromed\\Temp\\{BA714F45-0DEF-445D-9FD5-04FC08D13A14}"
- ]
- [*] Modified Registry Keys: [
- "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MicrosoftMysql\\Parameters",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MicrosoftMysql\\Parameters\\Application",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MicrosoftMysql\\Parameters\\AppParameters",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MicrosoftMysql\\Parameters\\AppDirectory",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MicrosoftMysql\\Parameters\\AppExit",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MicrosoftMysql\\Parameters\\AppExit\\(Default)",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MicrosoftMysql\\FailureActionsOnNonCrashFailures",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Start",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Start",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Start",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Start",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MicrosoftMysql\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gupdate\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Start",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EventLog\\Application\\NSSM",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Application\\NSSM\\EventMessageFile",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Application\\NSSM\\TypesSupported",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{BB6BFC46-08B9-424B-A79F-05ECFD0360B7}\\Path",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{BB6BFC46-08B9-424B-A79F-05ECFD0360B7}\\Hash",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\At1\\Id",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\At1\\Index",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{BB6BFC46-08B9-424B-A79F-05ECFD0360B7}\\Triggers",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{BB6BFC46-08B9-424B-A79F-05ECFD0360B7}\\DynamicInfo",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AEA8D717-4F47-44A8-9871-D0FFEE7A6071}\\Path",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AEA8D717-4F47-44A8-9871-D0FFEE7A6071}\\Hash",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\At2\\Id",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\At2\\Index",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AEA8D717-4F47-44A8-9871-D0FFEE7A6071}\\Triggers",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{AEA8D717-4F47-44A8-9871-D0FFEE7A6071}\\DynamicInfo",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\PreviousServiceShutdown",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ProcessID",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ThrottleDrege",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Parameters\\ServiceDllUnloadOnStop",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Wbem\\Transports\\Decoupled\\Server",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\CreationTime",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\MarshaledProxy",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\ProcessIdentifier",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ConfigValueEssNeedsLoading",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\List of event-active namespaces",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\ESS\\//./root/CIMV2\\SCM Event Provider",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{26CEE9A6-18F5-4F69-8C4D-2467328655EB}\\DynamicInfo",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\{1B2969CC-32AB-406E-A082-BFA4AEC39B70}",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{BA11F2B3-0190-41C3-95F6-1F6B8FEBB2E1}\\DynamicInfo",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\{F04E9F33-09C3-4AB6-8094-0BB7BFCC134A}",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{B17E070E-57E3-43F6-96F5-A9A9C921DEBF}\\DynamicInfo",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{DF000DCA-3FA2-48A6-9E59-C0606F9F8D73}\\DynamicInfo",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{ED0D73D7-BC97-46E2-AC55-FD6EB3F72C05}\\DynamicInfo",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F3F786D2-6E05-49FA-8A99-53C51C984120}\\DynamicInfo",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{74B32FB8-1950-4398-8528-773F64305286}\\DynamicInfo",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\{1B2969CC-32AB-406E-A082-BFA4AEC39B70}\\data",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\LastStartedAU",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\{F04E9F33-09C3-4AB6-8094-0BB7BFCC134A}\\data",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Performance\\PerfMMFileName",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\BackupRestore\\FilesNotToBackup\\BITS_LOG",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\BackupRestore\\FilesNotToBackup\\BITS_BAK",
- "HKEY_LOCAL_MACHINE\\Software\\Google\\Update\\PersistedPings\\{052AAD01-1EE0-4ABE-A555-BC7585AA1723}",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\PersistedPings\\{052AAD01-1EE0-4ABE-A555-BC7585AA1723}\\PersistedPingString",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\PersistedPings\\{052AAD01-1EE0-4ABE-A555-BC7585AA1723}\\PersistedPingTime",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\pv",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\pv",
- "HKEY_LOCAL_MACHINE\\Software\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\CurrentState",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\CurrentState\\StateValue",
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000_CLASSES\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Google\\Update\\proxy\\source",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\RollCallDayStartSec",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\DayOfLastRollCall",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\ping_freshness",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\cohort\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\cohort\\hint",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\cohort\\name",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\LastCheckSuccess",
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\dr",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\ActivePingDayStartSec",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\RollCallDayStartSec",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\DayOfLastActivity",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\DayOfLastRollCall",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\ping_freshness",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\cohort\\(Default)",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\cohort\\hint",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\cohort\\name",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\LastCheckSuccess",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\LastChecked",
- "HKEY_LOCAL_MACHINE\\Software\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\CurrentState",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\CurrentState\\StateValue",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\LastCodeRedCheck"
- ]
- [*] Deleted Registry Keys: [
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\At1.job",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\At1.job.fp",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\At2.job",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\At2.job.fp",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Performance\\PerfMMFileName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\uid",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\old-uid",
- "HKEY_CURRENT_USER\\Software\\Adobe\\Adobe ARM\\1.0\\ARM\\iNotify",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\tttoken",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\UpdateAvailableCount",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\UpdateAvailableSince",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\dr",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\tttoken",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\UpdateAvailableCount",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\UpdateAvailableSince"
- ]
- [*] DNS Communications: []
- [*] Domains: []
- [*] Network Communication - ICMP: []
- [*] Network Communication - HTTP: []
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": [
- [
- "Upack V0.37 -> Dwing"
- ],
- [
- "Upack_Patch or any Version -> Dwing"
- ],
- [
- "WinUpack v0.39 final (relocated image base) -> By Dwing (c)2005 (h2)"
- ]
- ],
- "imports": [
- {
- "imports": [
- {
- "name": "LoadLibraryA",
- "address": "0xba151d"
- },
- {
- "name": "GetProcAddress",
- "address": "0xba1521"
- }
- ],
- "dll": "KERNEL32.DLL"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x00240215",
- "overlay": null,
- "imagebase": "0x00400000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x00ba1259",
- "timestamp": "1970-01-01 01:08:16",
- "osversion": "4.0",
- "sections": [
- {
- "name": ".Upack",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x00000000",
- "virtual_size": "0x00566000",
- "characteristics_raw": "0xe0000060"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00567000",
- "size_of_data": "0x0023a54d",
- "entropy": "8.00",
- "raw_address": "0x00000200",
- "virtual_size": "0x00242000",
- "characteristics_raw": "0xe0000060"
- }
- ],
- "resources": [
- {
- "name": "RT_BITMAP",
- "language": "LANG_NEUTRAL",
- "filetype": null,
- "sublanguage": "SUBLANG_NEUTRAL",
- "entropy": "0.00",
- "offset": "0x0000f064",
- "size": "0x005563d3"
- }
- ],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x007a1525",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x00000014"
- },
- {
- "virtual_address": "0x00567000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00000062"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000048",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00000008"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x007a1505",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000018"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "87bed5a7cba00c7e1f4015f1bdae2183",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 1,
- "versioninfo": []
- }
- }
- [*] Resolved APIs: [
- "user32.dll.MessageBoxA",
- "kernel32.dll.Sleep",
- "kernel32.dll.VirtualFree",
- "kernel32.dll.VirtualAlloc",
- "kernel32.dll.VirtualQuery",
- "kernel32.dll.GetSystemInfo",
- "kernel32.dll.GetVersion",
- "kernel32.dll.SetThreadLocale",
- "kernel32.dll.GetACP",
- "kernel32.dll.GetStartupInfoW",
- "kernel32.dll.GetProcAddress",
- "kernel32.dll.GetModuleHandleW",
- "kernel32.dll.GetCommandLineW",
- "kernel32.dll.FreeLibrary",
- "kernel32.dll.UnhandledExceptionFilter",
- "kernel32.dll.RtlUnwind",
- "kernel32.dll.RaiseException",
- "kernel32.dll.ExitProcess",
- "kernel32.dll.GetCurrentThreadId",
- "kernel32.dll.DeleteCriticalSection",
- "kernel32.dll.InitializeCriticalSection",
- "kernel32.dll.WriteFile",
- "kernel32.dll.GetStdHandle",
- "kernel32.dll.CloseHandle",
- "kernel32.dll.LoadLibraryA",
- "kernel32.dll.GetLastError",
- "kernel32.dll.TlsSetValue",
- "kernel32.dll.TlsGetValue",
- "kernel32.dll.LocalFree",
- "kernel32.dll.LocalAlloc",
- "kernel32.dll.VirtualProtect",
- "kernel32.dll.SizeofResource",
- "kernel32.dll.LockResource",
- "kernel32.dll.LoadResource",
- "kernel32.dll.GetVersionExW",
- "kernel32.dll.FindResourceW",
- "kernel32.dll.GetThreadPreferredUILanguages",
- "kernel32.dll.SetThreadPreferredUILanguages",
- "kernel32.dll.GetThreadUILanguage",
- "kernel32.dll.#829",
- "kernel32.dll.#693",
- "kernel32.dll.#700",
- "kernel32.dll.#760",
- "kernel32.dll.#763",
- "kernel32.dll.#1112",
- "kernel32.dll.#1358",
- "kernel32.dll.#1359",
- "kernel32.dll.#871",
- "kernel32.dll.#283",
- "kernel32.dll.#84",
- "kernel32.dll.#145",
- "kernel32.dll.#1318",
- "kernel32.dll.#1129",
- "kernel32.dll.#532",
- "kernel32.dll.#216",
- "kernel32.dll.#131",
- "kernel32.dll.#449",
- "kernel32.dll.#625",
- "kernel32.dll.#688",
- "kernel32.dll.#644",
- "kernel32.dll.#646",
- "user32.dll.#2039",
- "user32.dll.#2046",
- "user32.dll.#2332",
- "shell32.dll.#437",
- "kernel32.dll.SortGetHandle",
- "kernel32.dll.SortCloseHandle",
- "setupapi.dll.CM_Get_Device_Interface_List_Size_ExW",
- "setupapi.dll.CM_Get_Device_Interface_List_ExW",
- "comctl32.dll.#386",
- "advapi32.dll.UnregisterTraceGuids",
- "comctl32.dll.#321",
- "kernel32.dll.SetThreadUILanguage",
- "kernel32.dll.CopyFileExW",
- "kernel32.dll.IsDebuggerPresent",
- "kernel32.dll.SetConsoleInputExeNameW",
- "advapi32.dll.SaferIdentifyLevel",
- "advapi32.dll.SaferComputeTokenFromLevel",
- "advapi32.dll.SaferCloseLevel",
- "rpcrt4.dll.I_RpcSNCHOption",
- "sechost.dll.OpenSCManagerW",
- "sechost.dll.OpenServiceW",
- "sechost.dll.CloseServiceHandle",
- "kernel32.dll.FlsAlloc",
- "kernel32.dll.FlsGetValue",
- "kernel32.dll.FlsSetValue",
- "kernel32.dll.FlsFree",
- "kernel32.dll.AttachConsole",
- "kernel32.dll.SleepConditionVariableCS",
- "kernel32.dll.WakeConditionVariable",
- "advapi32.dll.CreateWellKnownSid",
- "advapi32.dll.IsWellKnownSid",
- "cryptbase.dll.SystemFunction028",
- "rpcrt4.dll.NDRCContextBinding",
- "rpcrt4.dll.RpcBindingToStringBindingW",
- "rpcrt4.dll.I_RpcMapWin32Status",
- "rpcrt4.dll.RpcStringBindingParseW",
- "rpcrt4.dll.RpcStringFreeW",
- "cryptbase.dll.SystemFunction004",
- "mswsock.dll.WSPStartup",
- "wshtcpip.dll.WSHOpenSocket",
- "wshtcpip.dll.WSHOpenSocket2",
- "wshtcpip.dll.WSHJoinLeaf",
- "wshtcpip.dll.WSHNotify",
- "wshtcpip.dll.WSHGetSocketInformation",
- "wshtcpip.dll.WSHSetSocketInformation",
- "wshtcpip.dll.WSHGetSockaddrType",
- "wshtcpip.dll.WSHGetWildcardSockaddr",
- "wshtcpip.dll.WSHGetBroadcastSockaddr",
- "wshtcpip.dll.WSHAddressToString",
- "wshtcpip.dll.WSHStringToAddress",
- "wshtcpip.dll.WSHIoctl",
- "sechost.dll.ControlService",
- "sechost.dll.StartServiceW",
- "version.dll.GetFileVersionInfoSizeW",
- "version.dll.GetFileVersionInfoW",
- "version.dll.VerQueryValueW",
- "cryptbase.dll.SystemFunction036",
- "uxtheme.dll.ThemeInitApiHook",
- "user32.dll.IsProcessDPIAware",
- "sechost.dll.LookupAccountNameLocalW",
- "advapi32.dll.LookupAccountSidW",
- "sechost.dll.LookupAccountSidLocalW",
- "sspicli.dll.GetUserNameExW",
- "advapi32.dll.GetUserNameW",
- "sechost.dll.ConvertSidToStringSidW",
- "xmllite.dll.CreateXmlWriter",
- "xmllite.dll.CreateXmlWriterOutputWithEncodingName",
- "advapi32.dll.WmiCloseBlock",
- "propsys.dll.PropVariantToVariant",
- "wbemcore.dll.Shutdown",
- "ole32.dll.CoUninitialize",
- "wmisvc.dll.ServiceMain",
- "sechost.dll.RegisterServiceCtrlHandlerExW",
- "sechost.dll.SetServiceStatus",
- "wbemcore.dll.Reinitialize",
- "advapi32.dll.WmiOpenBlock",
- "vssapi.dll.CreateWriter",
- "propsys.dll.VariantToPropVariant",
- "authz.dll.AuthzInitializeContextFromToken",
- "authz.dll.AuthzInitializeObjectAccessAuditEvent2",
- "authz.dll.AuthzAccessCheck",
- "authz.dll.AuthzFreeAuditEvent",
- "authz.dll.AuthzFreeContext",
- "authz.dll.AuthzInitializeResourceManager",
- "authz.dll.AuthzFreeResourceManager",
- "wmisvc.dll.IsImproperShutdownDetected",
- "wevtapi.dll.EvtRender",
- "wevtapi.dll.EvtNext",
- "wevtapi.dll.EvtClose",
- "wevtapi.dll.EvtQuery",
- "wevtapi.dll.EvtCreateRenderContext",
- "cryptsp.dll.CryptAcquireContextW",
- "cryptsp.dll.CryptGenRandom",
- "cryptsp.dll.CryptReleaseContext",
- "sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW",
- "oleaut32.dll.#8",
- "oleaut32.dll.#2",
- "oleaut32.dll.#9",
- "oleaut32.dll.#6",
- "oleaut32.dll.#7",
- "ole32.dll.CoInitializeEx",
- "oleaut32.dll.#12",
- "tschannel.dll.DllGetClassObject",
- "tschannel.dll.DllCanUnloadNow",
- "ole32.dll.CoRevokeClassObject",
- "ole32.dll.CoDisconnectContext",
- "ws2_32.dll.#3",
- "bitsigd.dll.UninitializeEx",
- "ws2_32.dll.#116",
- "sechost.dll.QueryServiceStatus",
- "winsta.dll.WinStationFreeMemory",
- "winsta.dll.WinStationCloseServer",
- "winsta.dll.WinStationOpenServerW",
- "winsta.dll.WinStationFreeGAPMemory",
- "winsta.dll.WinStationGetAllProcesses",
- "winsta.dll.WinStationEnumerateProcesses",
- "kernel32.dll.LocaleNameToLCID",
- "kernel32.dll.GetLocaleInfoEx",
- "kernel32.dll.LCIDToLocaleName",
- "kernel32.dll.GetSystemDefaultLocaleName",
- "oleaut32.dll.#283",
- "oleaut32.dll.#284",
- "kernel32.dll.RegOpenKeyExW",
- "ntdll.dll.EtwUnregisterTraceGuids",
- "oleaut32.dll.#500",
- "ntmarta.dll.GetMartaExtensionInterface",
- "fastprox.dll.DllGetClassObject",
- "fastprox.dll.DllCanUnloadNow",
- "kernel32.dll.RegQueryValueExW",
- "kernel32.dll.RegCloseKey",
- "oleaut32.dll.#289",
- "advapi32.dll.RegOpenKeyW",
- "oleaut32.dll.#287",
- "oleaut32.dll.#288",
- "oleaut32.dll.#290",
- "oleaut32.dll.#285",
- "ntdll.dll.RtlInitUnicodeString",
- "ntdll.dll.RtlFreeUnicodeString",
- "ntdll.dll.NtSetSystemEnvironmentValue",
- "ntdll.dll.NtQuerySystemEnvironmentValue",
- "ntdll.dll.NtCreateFile",
- "ntdll.dll.NtQuerySystemInformation",
- "ntdll.dll.NtQueryDirectoryObject",
- "ntdll.dll.NtQueryObject",
- "ntdll.dll.NtOpenDirectoryObject",
- "ntdll.dll.NtQueryInformationProcess",
- "ntdll.dll.NtQueryInformationToken",
- "ntdll.dll.NtOpenFile",
- "ntdll.dll.NtClose",
- "ntdll.dll.NtFsControlFile",
- "ntdll.dll.NtQueryVolumeInformationFile",
- "advapi32.dll.LookupPrivilegeValueW",
- "winbrand.dll.BrandingLoadString",
- "oleaut32.dll.#286",
- "ole32.dll.StringFromCLSID",
- "ole32.dll.CoTaskMemFree",
- "advapi32.dll.CryptAcquireContextW",
- "advapi32.dll.RegCreateKeyExW",
- "shlwapi.dll.PathIsDirectoryW",
- "advapi32.dll.RegQueryValueExW",
- "advapi32.dll.RegNotifyChangeKeyValue",
- "ole32.dll.NdrOleInitializeExtension",
- "ole32.dll.CoGetClassObject",
- "ole32.dll.CoGetMarshalSizeMax",
- "ole32.dll.CoMarshalInterface",
- "ole32.dll.CoUnmarshalInterface",
- "ole32.dll.StringFromIID",
- "ole32.dll.CoGetPSClsid",
- "ole32.dll.CoTaskMemAlloc",
- "ole32.dll.CoCreateInstance",
- "ole32.dll.CoReleaseMarshalData",
- "ole32.dll.DcomChannelSetHResult",
- "rpcrtremote.dll.I_RpcExtInitializeExtensionPoint",
- "ole32.dll.CLSIDFromOle1Class",
- "clbcatq.dll.GetCatalogObject",
- "clbcatq.dll.GetCatalogObject2",
- "advapi32.dll.RegOpenKeyExW",
- "advapi32.dll.RegSetValueExW",
- "advapi32.dll.RegCloseKey",
- "shlwapi.dll.PathIsPrefixW",
- "advapi32.dll.CryptCreateHash",
- "advapi32.dll.CryptGetHashParam",
- "cryptsp.dll.CryptGetHashParam",
- "advapi32.dll.CryptHashData",
- "cryptsp.dll.CryptHashData",
- "advapi32.dll.CryptDestroyHash",
- "cryptsp.dll.CryptDestroyHash",
- "xmllite.dll.CreateXmlReader",
- "advapi32.dll.CryptReleaseContext",
- "kernel32.dll.LCMapStringEx",
- "kernel32.dll.InitializeCriticalSectionEx",
- "kernel32.dll.InitOnceExecuteOnce",
- "kernel32.dll.CreateEventExW",
- "kernel32.dll.CreateSemaphoreW",
- "kernel32.dll.CreateSemaphoreExW",
- "kernel32.dll.CreateThreadpoolTimer",
- "kernel32.dll.SetThreadpoolTimer",
- "kernel32.dll.WaitForThreadpoolTimerCallbacks",
- "kernel32.dll.CloseThreadpoolTimer",
- "kernel32.dll.CreateThreadpoolWait",
- "kernel32.dll.SetThreadpoolWait",
- "kernel32.dll.CloseThreadpoolWait",
- "kernel32.dll.FlushProcessWriteBuffers",
- "kernel32.dll.FreeLibraryWhenCallbackReturns",
- "kernel32.dll.GetCurrentProcessorNumber",
- "kernel32.dll.CreateSymbolicLinkW",
- "kernel32.dll.GetTickCount64",
- "kernel32.dll.GetFileInformationByHandleEx",
- "kernel32.dll.SetFileInformationByHandle",
- "kernel32.dll.InitializeConditionVariable",
- "kernel32.dll.WakeAllConditionVariable",
- "kernel32.dll.InitializeSRWLock",
- "kernel32.dll.AcquireSRWLockExclusive",
- "kernel32.dll.TryAcquireSRWLockExclusive",
- "kernel32.dll.ReleaseSRWLockExclusive",
- "kernel32.dll.SleepConditionVariableSRW",
- "kernel32.dll.CreateThreadpoolWork",
- "kernel32.dll.SubmitThreadpoolWork",
- "kernel32.dll.CloseThreadpoolWork",
- "kernel32.dll.CompareStringEx",
- "goopdate.dll.DllEntry",
- "kernel32.dll.RtlCaptureStackBackTrace",
- "wkscli.dll.NetWkstaGetInfo",
- "cscapi.dll.CscNetApiGetInterface",
- "kernel32.dll.CreateMutexExW",
- "dbghelp.dll.MiniDumpWriteDump",
- "rpcrt4.dll.UuidCreate",
- "kernel32.dll.WTSGetActiveConsoleSessionId",
- "winsta.dll.WinStationQueryInformationW",
- "rpcrt4.dll.RpcStringBindingComposeW",
- "rpcrt4.dll.RpcBindingFromStringBindingW",
- "rpcrt4.dll.RpcBindingSetAuthInfoExW",
- "rpcrt4.dll.NdrClientCall2",
- "rpcrt4.dll.I_RpcExceptionFilter",
- "rpcrt4.dll.RpcBindingFree",
- "kernel32.dll.IsWow64Process",
- "psapi.dll.GetProcessImageFileNameW",
- "dwmapi.dll.DwmIsCompositionEnabled",
- "kernel32.dll.WerRegisterMemoryBlock",
- "advapi32.dll.EventWrite",
- "advapi32.dll.EventRegister",
- "advapi32.dll.EventUnregister",
- "kernel32.dll.IsProcessorFeaturePresent",
- "kernel32.dll.CreateActCtxW",
- "kernel32.dll.ReleaseActCtx",
- "kernel32.dll.ActivateActCtx",
- "kernel32.dll.DeactivateActCtx",
- "user32.dll.NotifyWinEvent",
- "kernel32.dll.GetUserDefaultUILanguage",
- "kernel32.dll.GetSystemDefaultUILanguage",
- "kernel32.dll.FindActCtxSectionStringW",
- "cryptbase.dll.SystemFunction041",
- "kernel32.dll.GetNativeSystemInfo",
- "shell32.dll.SHGetFolderPathW",
- "ole32.dll.CoInitializeSecurity",
- "qmgr.dll.ServiceMain",
- "advapi32.dll.SetEntriesInAclW",
- "ws2_32.dll.#115",
- "ws2_32.dll.WSASocketW",
- "ws2_32.dll.WSAIoctl",
- "ws2_32.dll.#111",
- "bitsigd.dll.InitializeEx",
- "upnp.dll.DllGetClassObject",
- "upnp.dll.DllCanUnloadNow",
- "rpcrt4.dll.RpcStringBindingComposeA",
- "rpcrt4.dll.RpcBindingFromStringBindingA",
- "rpcrt4.dll.RpcStringFreeA",
- "rpcrt4.dll.NdrClientCall3",
- "oleaut32.dll.DllGetClassObject",
- "oleaut32.dll.DllCanUnloadNow",
- "sxs.dll.SxsOleAut32MapIIDToProxyStubCLSID",
- "advapi32.dll.RegQueryValueW",
- "oleaut32.dll.BSTR_UserSize",
- "oleaut32.dll.BSTR_UserMarshal",
- "oleaut32.dll.BSTR_UserUnmarshal",
- "oleaut32.dll.BSTR_UserFree",
- "oleaut32.dll.VARIANT_UserSize",
- "oleaut32.dll.VARIANT_UserMarshal",
- "oleaut32.dll.VARIANT_UserUnmarshal",
- "oleaut32.dll.VARIANT_UserFree",
- "oleaut32.dll.LPSAFEARRAY_UserSize",
- "oleaut32.dll.LPSAFEARRAY_UserMarshal",
- "oleaut32.dll.LPSAFEARRAY_UserUnmarshal",
- "oleaut32.dll.LPSAFEARRAY_UserFree",
- "advapi32.dll.LogonUserW",
- "sspicli.dll.LogonUserExExW",
- "wtsapi32.dll.WTSQueryUserToken",
- "wtsapi32.dll.WTSEnumerateSessionsW",
- "winsta.dll.WinStationEnumerateW",
- "wtsapi32.dll.WTSFreeMemory",
- "advapi32.dll.QueryAllTracesW",
- "advapi32.dll.LookupAccountNameW",
- "samcli.dll.NetLocalGroupGetMembers",
- "samlib.dll.SamConnect",
- "samlib.dll.SamOpenDomain",
- "samlib.dll.SamLookupNamesInDomain",
- "samlib.dll.SamOpenAlias",
- "samlib.dll.SamFreeMemory",
- "samlib.dll.SamCloseHandle",
- "samlib.dll.SamGetMembersInAlias",
- "netutils.dll.NetApiBufferFree",
- "samlib.dll.SamEnumerateDomainsInSamServer",
- "samlib.dll.SamLookupDomainInSamServer",
- "ole32.dll.CoCreateGuid",
- "oleaut32.dll.#4",
- "ole32.dll.CoRegisterClassObject",
- "iphlpapi.dll.GetAdaptersAddresses",
- "psmachine.dll.DllGetClassObject",
- "psmachine.dll.DllCanUnloadNow",
- "ntdll.dll.RtlGetVersion",
- "winhttp.dll.WinHttpAddRequestHeaders",
- "winhttp.dll.WinHttpCheckPlatform",
- "winhttp.dll.WinHttpCloseHandle",
- "winhttp.dll.WinHttpConnect",
- "winhttp.dll.WinHttpCrackUrl",
- "winhttp.dll.WinHttpCreateUrl",
- "winhttp.dll.WinHttpDetectAutoProxyConfigUrl",
- "winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser",
- "winhttp.dll.WinHttpGetDefaultProxyConfiguration",
- "winhttp.dll.WinHttpGetProxyForUrl",
- "winhttp.dll.WinHttpOpen",
- "winhttp.dll.WinHttpOpenRequest",
- "winhttp.dll.WinHttpQueryAuthSchemes",
- "winhttp.dll.WinHttpQueryDataAvailable",
- "winhttp.dll.WinHttpQueryHeaders",
- "winhttp.dll.WinHttpQueryOption",
- "winhttp.dll.WinHttpReadData",
- "winhttp.dll.WinHttpReceiveResponse",
- "winhttp.dll.WinHttpSendRequest",
- "winhttp.dll.WinHttpSetDefaultProxyConfiguration",
- "winhttp.dll.WinHttpSetCredentials",
- "winhttp.dll.WinHttpSetOption",
- "winhttp.dll.WinHttpSetStatusCallback",
- "winhttp.dll.WinHttpSetTimeouts",
- "winhttp.dll.WinHttpWriteData",
- "shlwapi.dll.StrCmpNW",
- "shlwapi.dll.#153",
- "ws2_32.dll.GetAddrInfoW",
- "ws2_32.dll.#2",
- "ws2_32.dll.#21",
- "ws2_32.dll.#9",
- "ws2_32.dll.FreeAddrInfoW",
- "ws2_32.dll.#6",
- "ws2_32.dll.#5",
- "schannel.dll.SpUserModeInitialize",
- "ws2_32.dll.WSASend",
- "ws2_32.dll.WSARecv",
- "advapi32.dll.RevertToSelf",
- "secur32.dll.FreeContextBuffer",
- "ncrypt.dll.SslOpenProvider",
- "ncrypt.dll.GetSChannelInterface",
- "bcryptprimitives.dll.GetHashInterface",
- "ncrypt.dll.SslIncrementProviderReferenceCount",
- "ncrypt.dll.SslImportKey",
- "bcryptprimitives.dll.GetCipherInterface",
- "ncrypt.dll.SslLookupCipherSuiteInfo",
- "user32.dll.LoadStringW",
- "ncrypt.dll.BCryptOpenAlgorithmProvider",
- "ncrypt.dll.BCryptGetProperty",
- "ncrypt.dll.BCryptCreateHash",
- "ncrypt.dll.BCryptHashData",
- "ncrypt.dll.BCryptFinishHash",
- "ncrypt.dll.BCryptDestroyHash",
- "crypt32.dll.CertGetCertificateChain",
- "userenv.dll.GetUserProfileDirectoryW",
- "sechost.dll.ConvertStringSidToSidW",
- "userenv.dll.RegisterGPNotification",
- "gpapi.dll.RegisterGPNotificationInternal",
- "sechost.dll.QueryServiceConfigW",
- "winsta.dll.WinStationRegisterNotificationEvent",
- "rpcrt4.dll.RpcAsyncInitializeHandle",
- "rpcrt4.dll.NdrAsyncClientCall",
- "cryptsp.dll.CryptAcquireContextA",
- "cryptsp.dll.CryptCreateHash",
- "cryptsp.dll.CryptVerifySignatureA",
- "cryptsp.dll.CryptDestroyKey",
- "bcryptprimitives.dll.GetAsymmetricEncryptionInterface",
- "ncrypt.dll.BCryptImportKeyPair",
- "ncrypt.dll.BCryptVerifySignature",
- "ncrypt.dll.BCryptDestroyKey",
- "crypt32.dll.CertVerifyCertificateChainPolicy",
- "crypt32.dll.CertFreeCertificateChain",
- "crypt32.dll.CertDuplicateCertificateContext",
- "ncrypt.dll.SslEncryptPacket",
- "ncrypt.dll.SslDecryptPacket",
- "crypt32.dll.CertFreeCertificateContext",
- "ncrypt.dll.SslFreeObject",
- "kernel32.dll.GetSystemWow64DirectoryW",
- "psapi.dll.GetModuleBaseNameW",
- "psapi.dll.EnumProcessModules",
- "kernel32.dll.QueryFullProcessImageNameW",
- "flashutil32_29_0_0_171_plugin.dll.#1",
- "kernel32.dll.CreateDirectoryW",
- "kernel32.dll.CreateFileW",
- "kernel32.dll.CreateProcessW",
- "kernel32.dll.DeleteFileW",
- "kernel32.dll.GetModuleFileNameW",
- "kernel32.dll.MoveFileExA",
- "kernel32.dll.MoveFileExW",
- "kernel32.dll.RemoveDirectoryW",
- "kernel32.dll.GetSystemDirectoryW",
- "kernel32.dll.ExpandEnvironmentStringsW",
- "kernel32.dll.FindFirstFileW",
- "kernel32.dll.FindNextFileW",
- "kernel32.dll.GetFileAttributesW",
- "kernel32.dll.SetFileAttributesW",
- "kernel32.dll.GetFileAttributesExW",
- "kernel32.dll.GetCurrentDirectoryW",
- "kernel32.dll.SetCurrentDirectoryW",
- "kernel32.dll.GetTempPathW",
- "kernel32.dll.GetTempFileNameW",
- "kernel32.dll.CopyFileW",
- "kernel32.dll.GetFullPathNameW",
- "kernel32.dll.GetVolumeInformationW",
- "advapi32.dll.OpenProcessToken",
- "advapi32.dll.GetTokenInformation",
- "advapi32.dll.GetSidSubAuthority",
- "advapi32.dll.GetSidSubAuthorityCount"
- ]
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": [
- [
- "Upack V0.37 -> Dwing"
- ],
- [
- "Upack_Patch or any Version -> Dwing"
- ],
- [
- "WinUpack v0.39 final (relocated image base) -> By Dwing (c)2005 (h2)"
- ]
- ],
- "imports": [
- {
- "imports": [
- {
- "name": "LoadLibraryA",
- "address": "0xba151d"
- },
- {
- "name": "GetProcAddress",
- "address": "0xba1521"
- }
- ],
- "dll": "KERNEL32.DLL"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x00240215",
- "overlay": null,
- "imagebase": "0x00400000",
- "reported_checksum": "0x00000000",
- "icon_hash": null,
- "entrypoint": "0x00ba1259",
- "timestamp": "1970-01-01 01:08:16",
- "osversion": "4.0",
- "sections": [
- {
- "name": ".Upack",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00000000",
- "entropy": "0.00",
- "raw_address": "0x00000000",
- "virtual_size": "0x00566000",
- "characteristics_raw": "0xe0000060"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x00567000",
- "size_of_data": "0x0023a54d",
- "entropy": "8.00",
- "raw_address": "0x00000200",
- "virtual_size": "0x00242000",
- "characteristics_raw": "0xe0000060"
- }
- ],
- "resources": [
- {
- "name": "RT_BITMAP",
- "language": "LANG_NEUTRAL",
- "filetype": null,
- "sublanguage": "SUBLANG_NEUTRAL",
- "entropy": "0.00",
- "offset": "0x0000f064",
- "size": "0x005563d3"
- }
- ],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x007a1525",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x00000014"
- },
- {
- "virtual_address": "0x00567000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00000062"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000048",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x00000008"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x007a1505",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000018"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "87bed5a7cba00c7e1f4015f1bdae2183",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": null,
- "imported_dll_count": 1,
- "versioninfo": []
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment