paladin316

Zips_77e0f576cde0d0233fd6acdfefede663_php_2019-07-02_19_30.json

Jul 2nd, 2019
2,137
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 26.33 KB | None | 0 0
  1.  
  2. [*] MalFamily: ""
  3.  
  4. [*] MalScore: 10.0
  5.  
  6. [*] File Name: "Zips_77e0f576cde0d0233fd6acdfefede663.php"
  7. [*] File Size: 70714
  8. [*] File Type: "Zip archive data, at least v2.0 to extract"
  9. [*] SHA256: "6f7fb166310a0564c89b9944e9d105025f87adb5fa403f95b5349ec731f98574"
  10. [*] MD5: "77e0f576cde0d0233fd6acdfefede663"
  11. [*] SHA1: "c3a1254324c58a2af2154f72824baa61a50e87ac"
  12. [*] SHA512: "fe502395d6ddc27b788f0eda14c1fbd033d472566360de9c25aa067cbadaf599a16198e3c426efcc36a8a96b33ecb1cf576527b0be5c60fcd9c0323ca0ff3ffe"
  13. [*] CRC32: "04B85805"
  14. [*] SSDEEP: "1536:6DMoX+SZR8HUWFupPScCi82+rHiEISKYQMBt9AaAH8k:6DUa8upa69oHBPKTMb9rAx"
  15.  
  16. [*] Process Execution: [
  17. "wscript.exe",
  18. "GItXn.exe",
  19. "cmd.exe",
  20. "powershell.exe",
  21. "cmd.exe",
  22. "sc.exe",
  23. "cmd.exe",
  24. "sc.exe",
  25. "cmd.exe",
  26. "sc.exe",
  27. "cmd.exe",
  28. "sc.exe",
  29. "cmd.exe",
  30. "powershell.exe",
  31. "svchost.exe",
  32. "services.exe",
  33. "lsass.exe"
  34. ]
  35.  
  36. [*] Signatures Detected: [
  37. {
  38. "Description": "Attempts to connect to a dead IP:Port (3 unique times)",
  39. "Details": [
  40. {
  41. "IP": "205.185.216.10:80"
  42. },
  43. {
  44. "IP": "64.37.52.189:443"
  45. },
  46. {
  47. "IP": "192.35.177.64:80"
  48. }
  49. ]
  50. },
  51. {
  52. "Description": "Creates RWX memory",
  53. "Details": []
  54. },
  55. {
  56. "Description": "Possible date expiration check, exits too soon after checking local time",
  57. "Details": [
  58. {
  59. "process": "cmd.exe, PID 2352"
  60. }
  61. ]
  62. },
  63. {
  64. "Description": "A process created a hidden window",
  65. "Details": [
  66. {
  67. "Process": "GItXn.exe -> cmd"
  68. },
  69. {
  70. "Process": "GItXn.exe -> cmd"
  71. },
  72. {
  73. "Process": "GItXn.exe -> cmd"
  74. }
  75. ]
  76. },
  77. {
  78. "Description": "Drops a binary and executes it",
  79. "Details": [
  80. {
  81. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\GItXn.exe"
  82. }
  83. ]
  84. },
  85. {
  86. "Description": "Performs some HTTP requests",
  87. "Details": [
  88. {
  89. "url": "http://apps.identrust.com/roots/dstrootcax3.p7c"
  90. },
  91. {
  92. "url": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab"
  93. }
  94. ]
  95. },
  96. {
  97. "Description": "Attempts to stop active services",
  98. "Details": [
  99. {
  100. "servicename": "WinDefend"
  101. }
  102. ]
  103. },
  104. {
  105. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  106. "Details": [
  107. {
  108. "Spam": "services.exe (504) called API GetSystemTimeAsFileTime 6532947 times"
  109. }
  110. ]
  111. },
  112. {
  113. "Description": "Spoofs its process name and/or associated pathname to appear as a legitimate process",
  114. "Details": [
  115. {
  116. "modified_name": "svchost.exe",
  117. "modified_path": "C:\\Users\\user\\AppData\\Local\\Temp\\GItXn.exe",
  118. "original_name": "svchost.exe",
  119. "original_path": "C:\\Windows\\system32\\svchost.exe"
  120. }
  121. ]
  122. },
  123. {
  124. "Description": "Creates a hidden or system file",
  125. "Details": [
  126. {
  127. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RFd99c40.TMP"
  128. }
  129. ]
  130. },
  131. {
  132. "Description": "Attempts to disable Windows Defender",
  133. "Details": []
  134. }
  135. ]
  136.  
  137. [*] Started Service: [
  138. "KeyIso"
  139. ]
  140.  
  141. [*] Executed Commands: [
  142. "C:\\Users\\user\\AppData\\Local\\Temp\\GItXn.exe",
  143. "\"C:\\Windows\\System32\\cmd.exe\" /c powershell Set-MpPreference -DisableRealtimeMonitoring $true",
  144. "cmd /c powershell Set-MpPreference -DisableRealtimeMonitoring $true",
  145. "\"C:\\Windows\\System32\\cmd.exe\" /c sc stop WinDefend",
  146. "cmd /c sc stop WinDefend",
  147. "\"C:\\Windows\\System32\\cmd.exe\" /c sc delete WinDefend",
  148. "cmd /c sc delete WinDefend",
  149. "C:\\Windows\\system32\\cmd.exe /c sc stop WinDefend",
  150. "C:\\Windows\\system32\\cmd.exe /c sc delete WinDefend",
  151. "C:\\Windows\\system32\\cmd.exe /c powershell Set-MpPreference -DisableRealtimeMonitoring $true",
  152. "C:\\Windows\\system32\\svchost.exe",
  153. "powershell Set-MpPreference -DisableRealtimeMonitoring $true",
  154. "sc stop WinDefend",
  155. "sc delete WinDefend",
  156. "C:\\Windows\\system32\\lsass.exe"
  157. ]
  158.  
  159. [*] Mutexes: [
  160. "Local\\ZoneAttributeCacheCounterMutex",
  161. "Local\\ZonesCacheCounterMutex",
  162. "Local\\ZonesLockedCacheCounterMutex",
  163. "Global\\CLR_CASOFF_MUTEX",
  164. "Global\\838B6C9EB27932960"
  165. ]
  166.  
  167. [*] Modified Files: [
  168. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\E0F5C59F9FA661F6F4C50B87FEF3A15A",
  169. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\E0F5C59F9FA661F6F4C50B87FEF3A15A",
  170. "C:\\Users\\user\\AppData\\Local\\Temp\\Cab2433.tmp",
  171. "C:\\Users\\user\\AppData\\Local\\Temp\\Tar2434.tmp",
  172. "C:\\Users\\user\\AppData\\Local\\Temp\\Cab2483.tmp",
  173. "C:\\Users\\user\\AppData\\Local\\Temp\\Tar2484.tmp",
  174. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\94308059B57B3142E455B38A6EB92015",
  175. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\94308059B57B3142E455B38A6EB92015",
  176. "C:\\Users\\user\\AppData\\Local\\Temp\\Cab2706.tmp",
  177. "C:\\Users\\user\\AppData\\Local\\Temp\\Tar2707.tmp",
  178. "C:\\Users\\user\\AppData\\Local\\Temp\\GItXn.exe",
  179. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\S-1-5-21-0000000000-0000000000-0000000000-1000\\00000000-0000-0000-0000-000000000000b_00000000-0000-0000-0000-000000000000",
  180. "C:\\Users\\user\\AppData\\Local\\Temp\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
  181. "\\??\\PIPE\\srvsvc",
  182. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\N43UBFXV17IGD95GD94U.temp",
  183. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RFd99c40.TMP",
  184. "C:\\Windows\\SysWOW64\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
  185. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\CFKGPPNTNUZPAX0D0ESS.temp",
  186. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms"
  187. ]
  188.  
  189. [*] Deleted Files: [
  190. "C:\\Users\\user\\AppData\\Local\\Temp\\Cab2433.tmp",
  191. "C:\\Users\\user\\AppData\\Local\\Temp\\Tar2434.tmp",
  192. "C:\\Users\\user\\AppData\\Local\\Temp\\Cab2483.tmp",
  193. "C:\\Users\\user\\AppData\\Local\\Temp\\Tar2484.tmp",
  194. "C:\\Users\\user\\AppData\\Local\\Temp\\Cab2706.tmp",
  195. "C:\\Users\\user\\AppData\\Local\\Temp\\Tar2707.tmp",
  196. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RFd99c40.TMP",
  197. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2960.14261671",
  198. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2960.14261687",
  199. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2960.14261687",
  200. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\CFKGPPNTNUZPAX0D0ESS.temp",
  201. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.2288.14283609",
  202. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2288.14283609",
  203. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.2288.14283609"
  204. ]
  205.  
  206. [*] Modified Registry Keys: [
  207. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  208. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
  209. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
  210. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender",
  211. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\DisableAntiSpyware",
  212. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection",
  213. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableBehaviorMonitoring",
  214. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableOnAccessProtection",
  215. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableOnRealtimeEnable",
  216. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableIOAVProtection",
  217. "DisableNotifications"
  218. ]
  219.  
  220. [*] Deleted Registry Keys: [
  221. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  222. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  223. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  224. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName"
  225. ]
  226.  
  227. [*] DNS Communications: [
  228. {
  229. "type": "A",
  230. "request": "holahospice.org",
  231. "answers": [
  232. {
  233. "data": "64.37.52.189",
  234. "type": "A"
  235. }
  236. ]
  237. },
  238. {
  239. "type": "A",
  240. "request": "apps.identrust.com",
  241. "answers": [
  242. {
  243. "data": "192.35.177.64",
  244. "type": "A"
  245. },
  246. {
  247. "data": "apps.digsigtrust.com",
  248. "type": "CNAME"
  249. }
  250. ]
  251. }
  252. ]
  253.  
  254. [*] Domains: [
  255. {
  256. "ip": "192.35.177.64",
  257. "domain": "apps.identrust.com"
  258. },
  259. {
  260. "ip": "64.37.52.189",
  261. "domain": "holahospice.org"
  262. }
  263. ]
  264.  
  265. [*] Network Communication - ICMP: []
  266.  
  267. [*] Network Communication - HTTP: [
  268. {
  269. "count": 1,
  270. "body": "",
  271. "uri": "http://apps.identrust.com/roots/dstrootcax3.p7c",
  272. "user-agent": "Microsoft-CryptoAPI/6.1",
  273. "method": "GET",
  274. "host": "apps.identrust.com",
  275. "version": "1.1",
  276. "path": "/roots/dstrootcax3.p7c",
  277. "data": "GET /roots/dstrootcax3.p7c HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: apps.identrust.com\r\n\r\n",
  278. "port": 80
  279. },
  280. {
  281. "count": 1,
  282. "body": "",
  283. "uri": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
  284. "user-agent": "Microsoft-CryptoAPI/6.1",
  285. "method": "GET",
  286. "host": "www.download.windowsupdate.com",
  287. "version": "1.1",
  288. "path": "/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
  289. "data": "GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1\r\nCache-Control: max-age = 86403\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Fri, 22 Feb 2019 16:53:13 GMT\r\nIf-None-Match: \"80e22c19cfcad41:0\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: www.download.windowsupdate.com\r\n\r\n",
  290. "port": 80
  291. }
  292. ]
  293.  
  294. [*] Network Communication - SMTP: []
  295.  
  296. [*] Network Communication - Hosts: []
  297.  
  298. [*] Network Communication - IRC: []
  299.  
  300. [*] Static Analysis: {
  301. "office": {
  302. "Metadata": {
  303. "HasMacros": "No"
  304. }
  305. }
  306. }
  307.  
  308. [*] Resolved APIs: [
  309. "advapi32.dll.SaferIdentifyLevel",
  310. "advapi32.dll.SaferComputeTokenFromLevel",
  311. "advapi32.dll.SaferCloseLevel",
  312. "ole32.dll.CLSIDFromProgIDEx",
  313. "ole32.dll.CoGetClassObject",
  314. "wscript.exe.#1",
  315. "urlmon.dll.#326",
  316. "urlmon.dll.#327",
  317. "shell32.dll.#685",
  318. "shell32.dll.#688",
  319. "urlmon.dll.#395",
  320. "cryptsp.dll.CryptAcquireContextW",
  321. "cryptsp.dll.CryptGenRandom",
  322. "rpcrtremote.dll.I_RpcExtInitializeExtensionPoint",
  323. "winhttp.dll.WinHttpCheckPlatform",
  324. "winhttp.dll.WinHttpOpen",
  325. "winhttp.dll.WinHttpConnect",
  326. "winhttp.dll.WinHttpOpenRequest",
  327. "winhttp.dll.WinHttpCloseHandle",
  328. "winhttp.dll.WinHttpSendRequest",
  329. "winhttp.dll.WinHttpReceiveResponse",
  330. "winhttp.dll.WinHttpAddRequestHeaders",
  331. "winhttp.dll.WinHttpQueryHeaders",
  332. "winhttp.dll.WinHttpReadData",
  333. "winhttp.dll.WinHttpWriteData",
  334. "winhttp.dll.WinHttpQueryDataAvailable",
  335. "winhttp.dll.WinHttpQueryOption",
  336. "winhttp.dll.WinHttpSetOption",
  337. "winhttp.dll.WinHttpSetTimeouts",
  338. "winhttp.dll.WinHttpCrackUrl",
  339. "winhttp.dll.WinHttpCreateUrl",
  340. "oleaut32.dll.#8",
  341. "oleaut32.dll.#12",
  342. "shlwapi.dll.StrRChrA",
  343. "shlwapi.dll.StrCmpNW",
  344. "oleaut32.dll.#4",
  345. "oleaut32.dll.#6",
  346. "kernel32.dll.RegQueryValueExW",
  347. "oleaut32.dll.#2",
  348. "kernel32.dll.RegCloseKey",
  349. "oleaut32.dll.#9",
  350. "ws2_32.dll.GetAddrInfoW",
  351. "ws2_32.dll.WSASocketW",
  352. "ws2_32.dll.#2",
  353. "ws2_32.dll.#21",
  354. "ws2_32.dll.#9",
  355. "ws2_32.dll.WSAIoctl",
  356. "ws2_32.dll.FreeAddrInfoW",
  357. "ws2_32.dll.#6",
  358. "ws2_32.dll.#5",
  359. "schannel.dll.SpUserModeInitialize",
  360. "advapi32.dll.RegCreateKeyExW",
  361. "advapi32.dll.RegQueryValueExW",
  362. "advapi32.dll.RegCloseKey",
  363. "ws2_32.dll.WSASend",
  364. "ws2_32.dll.WSARecv",
  365. "secur32.dll.FreeContextBuffer",
  366. "ncrypt.dll.SslOpenProvider",
  367. "ncrypt.dll.GetSChannelInterface",
  368. "bcryptprimitives.dll.GetHashInterface",
  369. "ncrypt.dll.SslIncrementProviderReferenceCount",
  370. "ncrypt.dll.SslImportKey",
  371. "bcryptprimitives.dll.GetCipherInterface",
  372. "ncrypt.dll.SslLookupCipherSuiteInfo",
  373. "user32.dll.LoadStringW",
  374. "ncrypt.dll.BCryptOpenAlgorithmProvider",
  375. "ncrypt.dll.BCryptGetProperty",
  376. "ncrypt.dll.BCryptCreateHash",
  377. "ncrypt.dll.BCryptHashData",
  378. "ncrypt.dll.BCryptFinishHash",
  379. "ncrypt.dll.BCryptDestroyHash",
  380. "crypt32.dll.CertGetCertificateChain",
  381. "userenv.dll.GetUserProfileDirectoryW",
  382. "sechost.dll.ConvertSidToStringSidW",
  383. "sechost.dll.ConvertStringSidToSidW",
  384. "userenv.dll.RegisterGPNotification",
  385. "gpapi.dll.RegisterGPNotificationInternal",
  386. "sechost.dll.OpenSCManagerW",
  387. "sechost.dll.OpenServiceW",
  388. "sechost.dll.CloseServiceHandle",
  389. "sechost.dll.QueryServiceConfigW",
  390. "cryptnet.dll.CryptGetObjectUrl",
  391. "cryptnet.dll.CryptRetrieveObjectByUrlW",
  392. "cryptnet.dll.I_CryptNetGetConnectivity",
  393. "sensapi.dll.IsNetworkAlive",
  394. "rpcrt4.dll.RpcBindingFromStringBindingW",
  395. "rpcrt4.dll.RpcBindingSetAuthInfoExW",
  396. "rpcrt4.dll.NdrClientCall2",
  397. "winhttp.dll.WinHttpSetStatusCallback",
  398. "winhttp.dll.WinHttpGetDefaultProxyConfiguration",
  399. "winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser",
  400. "shlwapi.dll.StrStrIW",
  401. "cryptsp.dll.CryptAcquireContextA",
  402. "cryptsp.dll.CryptCreateHash",
  403. "cryptsp.dll.CryptHashData",
  404. "cryptsp.dll.CryptVerifySignatureA",
  405. "cryptsp.dll.CryptDestroyKey",
  406. "cryptsp.dll.CryptDestroyHash",
  407. "setupapi.dll.SetupIterateCabinetW",
  408. "kernel32.dll.RegOpenKeyExW",
  409. "cabinet.dll.#20",
  410. "cabinet.dll.#22",
  411. "devrtl.dll.DevRtlGetThreadLogToken",
  412. "cabinet.dll.#23",
  413. "cryptsp.dll.CryptSetHashParam",
  414. "sechost.dll.QueryServiceConfigA",
  415. "sechost.dll.QueryServiceStatus",
  416. "rpcrt4.dll.RpcStringBindingComposeA",
  417. "rpcrt4.dll.RpcBindingFromStringBindingA",
  418. "rpcrt4.dll.RpcEpResolveBinding",
  419. "sechost.dll.LookupAccountSidLocalW",
  420. "rpcrt4.dll.RpcStringFreeA",
  421. "rpcrt4.dll.RpcBindingFree",
  422. "winhttp.dll.WinHttpTimeFromSystemTime",
  423. "cryptnet.dll.I_CryptNetSetUrlCacheFlushInfo",
  424. "cryptnet.dll.I_CryptNetSetUrlCachePreFetchInfo",
  425. "bcryptprimitives.dll.GetAsymmetricEncryptionInterface",
  426. "ncrypt.dll.BCryptImportKeyPair",
  427. "ncrypt.dll.BCryptVerifySignature",
  428. "ncrypt.dll.BCryptDestroyKey",
  429. "crypt32.dll.CertVerifyCertificateChainPolicy",
  430. "crypt32.dll.CertFreeCertificateChain",
  431. "crypt32.dll.CertDuplicateCertificateContext",
  432. "ncrypt.dll.SslEncryptPacket",
  433. "ncrypt.dll.SslDecryptPacket",
  434. "ole32.dll.CreateStreamOnHGlobal",
  435. "oleaut32.dll.#411",
  436. "oleaut32.dll.#23",
  437. "oleaut32.dll.#24",
  438. "ws2_32.dll.#22",
  439. "ws2_32.dll.#3",
  440. "ole32.dll.GetHGlobalFromStream",
  441. "crypt32.dll.CertFreeCertificateContext",
  442. "ncrypt.dll.SslDecrementProviderReferenceCount",
  443. "ncrypt.dll.SslFreeObject",
  444. "oleaut32.dll.#500",
  445. "cryptsp.dll.CryptReleaseContext",
  446. "kernel32.dll.VirtualAlloc",
  447. "advapi32.dll.CryptAcquireContextA",
  448. "ntdll.dll.memcpy",
  449. "kernel32.dll.GetCurrentProcess",
  450. "kernel32.dll.CloseHandle",
  451. "advapi32.dll.OpenProcessToken",
  452. "advapi32.dll.GetTokenInformation",
  453. "kernel32.dll.Wow64EnableWow64FsRedirection",
  454. "advapi32.dll.RegCreateKeyW",
  455. "advapi32.dll.RegOpenKeyExW",
  456. "advapi32.dll.RegSetValueExW",
  457. "shell32.dll.ShellExecuteA",
  458. "ole32.dll.OleInitialize",
  459. "cryptbase.dll.SystemFunction036",
  460. "uxtheme.dll.ThemeInitApiHook",
  461. "user32.dll.IsProcessDPIAware",
  462. "ole32.dll.CreateBindCtx",
  463. "ole32.dll.CoTaskMemAlloc",
  464. "propsys.dll.PSCreateMemoryPropertyStore",
  465. "propsys.dll.PSPropertyBag_WriteDWORD",
  466. "ole32.dll.CoGetApartmentType",
  467. "ole32.dll.CoRegisterInitializeSpy",
  468. "ole32.dll.CoTaskMemFree",
  469. "comctl32.dll.#236",
  470. "ole32.dll.CoGetMalloc",
  471. "propsys.dll.PSPropertyBag_ReadDWORD",
  472. "propsys.dll.PSPropertyBag_ReadGUID",
  473. "comctl32.dll.#320",
  474. "comctl32.dll.#324",
  475. "comctl32.dll.#323",
  476. "advapi32.dll.RegEnumKeyW",
  477. "advapi32.dll.OpenThreadToken",
  478. "ole32.dll.StringFromGUID2",
  479. "apphelp.dll.ApphelpCheckShellObject",
  480. "ole32.dll.CoCreateInstance",
  481. "urlmon.dll.CreateUri",
  482. "kernel32.dll.InitializeSRWLock",
  483. "kernel32.dll.AcquireSRWLockExclusive",
  484. "kernel32.dll.AcquireSRWLockShared",
  485. "kernel32.dll.ReleaseSRWLockExclusive",
  486. "kernel32.dll.ReleaseSRWLockShared",
  487. "comctl32.dll.#328",
  488. "comctl32.dll.#334",
  489. "shell32.dll.#102",
  490. "propsys.dll.PSPropertyBag_ReadStrAlloc",
  491. "ole32.dll.CoInitializeEx",
  492. "advapi32.dll.InitializeSecurityDescriptor",
  493. "advapi32.dll.SetEntriesInAclW",
  494. "ntmarta.dll.GetMartaExtensionInterface",
  495. "advapi32.dll.SetSecurityDescriptorDacl",
  496. "advapi32.dll.IsTextUnicode",
  497. "comctl32.dll.#332",
  498. "comctl32.dll.#338",
  499. "comctl32.dll.#339",
  500. "ole32.dll.CoUninitialize",
  501. "profapi.dll.#104",
  502. "propsys.dll.#430",
  503. "advapi32.dll.RegGetValueW",
  504. "ole32.dll.CoTaskMemRealloc",
  505. "propsys.dll.InitPropVariantFromStringAsVector",
  506. "propsys.dll.PSCoerceToCanonicalValue",
  507. "propsys.dll.PropVariantToStringAlloc",
  508. "ole32.dll.PropVariantClear",
  509. "ole32.dll.CoAllowSetForegroundWindow",
  510. "setupapi.dll.CM_Get_Device_Interface_List_Size_ExW",
  511. "setupapi.dll.CM_Get_Device_Interface_List_ExW",
  512. "shell32.dll.SHGetFolderPathW",
  513. "advapi32.dll.SaferGetPolicyInformation",
  514. "comctl32.dll.#386",
  515. "ntdll.dll.RtlDllShutdownInProgress",
  516. "comctl32.dll.#329",
  517. "ole32.dll.OleUninitialize",
  518. "ole32.dll.CoRevokeInitializeSpy",
  519. "comctl32.dll.#388",
  520. "advapi32.dll.CryptImportKey",
  521. "advapi32.dll.CryptEncrypt",
  522. "cryptsp.dll.CryptImportKey",
  523. "cryptbase.dll.SystemFunction040",
  524. "cryptbase.dll.SystemFunction041",
  525. "cryptsp.dll.CryptEncrypt",
  526. "advapi32.dll.UnregisterTraceGuids",
  527. "comctl32.dll.#321",
  528. "kernel32.dll.SetThreadUILanguage",
  529. "kernel32.dll.CopyFileExW",
  530. "kernel32.dll.IsDebuggerPresent",
  531. "kernel32.dll.SetConsoleInputExeNameW",
  532. "kernel32.dll.SortGetHandle",
  533. "kernel32.dll.SortCloseHandle",
  534. "shell32.dll.#66",
  535. "comctl32.dll.#385",
  536. "comctl32.dll.#336",
  537. "comctl32.dll.#333",
  538. "linkinfo.dll.IsValidLinkInfo",
  539. "propsys.dll.#417",
  540. "propsys.dll.PSGetNameFromPropertyKey",
  541. "propsys.dll.PSStringFromPropertyKey",
  542. "propsys.dll.InitVariantFromBuffer",
  543. "propsys.dll.PropVariantToGUID",
  544. "linkinfo.dll.CreateLinkInfoW",
  545. "user32.dll.IsCharAlphaW",
  546. "user32.dll.CharPrevW",
  547. "ntshrui.dll.GetNetResourceFromLocalPathW",
  548. "srvcli.dll.NetShareEnum",
  549. "cscapi.dll.CscNetApiGetInterface",
  550. "slc.dll.SLGetWindowsInformationDWORD",
  551. "shlwapi.dll.PathRemoveFileSpecW",
  552. "linkinfo.dll.DestroyLinkInfo",
  553. "propsys.dll.PropVariantToBoolean",
  554. "advapi32.dll.GetSecurityInfo",
  555. "advapi32.dll.SetSecurityInfo",
  556. "advapi32.dll.GetSecurityDescriptorControl",
  557. "advapi32.dll.RegQueryInfoKeyW",
  558. "advapi32.dll.RegEnumKeyExW",
  559. "advapi32.dll.RegEnumValueW",
  560. "shlwapi.dll.UrlIsW",
  561. "kernel32.dll.InitializeCriticalSectionAndSpinCount",
  562. "msvcrt.dll._set_error_mode",
  563. "msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z",
  564. "kernel32.dll.FindActCtxSectionStringW",
  565. "kernel32.dll.GetSystemWindowsDirectoryW",
  566. "mscoree.dll.GetProcessExecutableHeap",
  567. "mscorwks.dll.DllGetClassObjectInternal",
  568. "mscorwks.dll.GetCLRFunction",
  569. "advapi32.dll.RegisterTraceGuidsW",
  570. "advapi32.dll.GetTraceLoggerHandle",
  571. "advapi32.dll.GetTraceEnableLevel",
  572. "advapi32.dll.GetTraceEnableFlags",
  573. "advapi32.dll.TraceEvent",
  574. "mscoree.dll.IEE",
  575. "mscorwks.dll.IEE",
  576. "mscoree.dll.GetStartupFlags",
  577. "mscoree.dll.GetHostConfigurationFile",
  578. "mscoree.dll.GetCORSystemDirectory",
  579. "ntdll.dll.RtlVirtualUnwind",
  580. "kernel32.dll.IsWow64Process",
  581. "advapi32.dll.AllocateAndInitializeSid",
  582. "advapi32.dll.InitializeAcl",
  583. "advapi32.dll.AddAccessAllowedAce",
  584. "advapi32.dll.FreeSid",
  585. "kernel32.dll.SetThreadStackGuarantee",
  586. "kernel32.dll.FlsSetValue",
  587. "kernel32.dll.FlsGetValue",
  588. "kernel32.dll.FlsAlloc",
  589. "kernel32.dll.FlsFree",
  590. "kernel32.dll.AddVectoredContinueHandler",
  591. "kernel32.dll.RemoveVectoredContinueHandler",
  592. "advapi32.dll.ConvertSidToStringSidW",
  593. "kernel32.dll.FlushProcessWriteBuffers",
  594. "kernel32.dll.GetWriteWatch",
  595. "kernel32.dll.ResetWriteWatch",
  596. "kernel32.dll.CreateMemoryResourceNotification",
  597. "kernel32.dll.QueryMemoryResourceNotification",
  598. "kernel32.dll.GlobalMemoryStatusEx",
  599. "ole32.dll.CoGetContextToken",
  600. "oleaut32.dll.#149",
  601. "kernel32.dll.GetUserDefaultUILanguage",
  602. "kernel32.dll.GetVersionExW",
  603. "kernel32.dll.GetFullPathNameW",
  604. "kernel32.dll.SetErrorMode",
  605. "kernel32.dll.GetFileAttributesExW",
  606. "version.dll.GetFileVersionInfoSizeW",
  607. "version.dll.GetFileVersionInfoW",
  608. "version.dll.VerQueryValueW",
  609. "kernel32.dll.lstrlen",
  610. "kernel32.dll.lstrlenW",
  611. "mscoree.dll.ND_RI2",
  612. "kernel32.dll.lstrcpy",
  613. "kernel32.dll.lstrcpyW",
  614. "version.dll.VerLanguageNameW",
  615. "kernel32.dll.GetCurrentProcessId",
  616. "advapi32.dll.LookupPrivilegeValueW",
  617. "advapi32.dll.AdjustTokenPrivileges",
  618. "kernel32.dll.OpenProcess",
  619. "psapi.dll.EnumProcessModules",
  620. "psapi.dll.GetModuleInformation",
  621. "psapi.dll.GetModuleBaseNameW",
  622. "psapi.dll.GetModuleFileNameExW",
  623. "kernel32.dll.GetExitCodeProcess",
  624. "ntdll.dll.NtQuerySystemInformation",
  625. "user32.dll.EnumWindows",
  626. "user32.dll.GetWindowThreadProcessId",
  627. "kernel32.dll.WerSetFlags",
  628. "kernel32.dll.SetThreadPreferredUILanguages",
  629. "kernel32.dll.GetThreadPreferredUILanguages",
  630. "kernel32.dll.GetUserDefaultLocaleName",
  631. "kernel32.dll.GetEnvironmentVariableW",
  632. "advapi32.dll.CryptReleaseContext",
  633. "advapi32.dll.CryptCreateHash",
  634. "advapi32.dll.CryptDestroyHash",
  635. "advapi32.dll.CryptHashData",
  636. "advapi32.dll.CryptGetHashParam",
  637. "advapi32.dll.CryptExportKey",
  638. "advapi32.dll.CryptGenKey",
  639. "advapi32.dll.CryptGetKeyParam",
  640. "advapi32.dll.CryptDestroyKey",
  641. "advapi32.dll.CryptVerifySignatureA",
  642. "advapi32.dll.CryptSignHashA",
  643. "advapi32.dll.CryptGetProvParam",
  644. "advapi32.dll.CryptGetUserKey",
  645. "advapi32.dll.CryptEnumProvidersA",
  646. "cryptsp.dll.CryptGetHashParam",
  647. "mscoree.dll.GetTokenForVTableEntry",
  648. "mscoree.dll.SetTargetForVTableEntry",
  649. "mscoree.dll.GetTargetForVTableEntry",
  650. "culture.dll.ConvertLangIdToCultureName",
  651. "ole32.dll.CoCreateGuid",
  652. "kernel32.dll.CreateFileW",
  653. "kernel32.dll.GetConsoleScreenBufferInfo",
  654. "kernel32.dll.LocalFree",
  655. "kernel32.dll.LocalAlloc",
  656. "mscoree.dll.ND_RI4",
  657. "advapi32.dll.DuplicateTokenEx",
  658. "advapi32.dll.CheckTokenMembership",
  659. "kernel32.dll.GetConsoleTitleW",
  660. "mscorjit.dll.getJit",
  661. "kernel32.dll.SetConsoleTitleW",
  662. "kernel32.dll.SetConsoleCtrlHandler",
  663. "kernel32.dll.CreateEventW",
  664. "ntdll.dll.WinSqmIsOptedIn",
  665. "kernel32.dll.ExpandEnvironmentStringsW",
  666. "shfolder.dll.SHGetFolderPathW",
  667. "kernel32.dll.SetEnvironmentVariableW",
  668. "kernel32.dll.GetACP",
  669. "kernel32.dll.UnmapViewOfFile",
  670. "kernel32.dll.GetFileType",
  671. "kernel32.dll.ReadFile",
  672. "kernel32.dll.GetSystemInfo",
  673. "kernel32.dll.VirtualQuery",
  674. "secur32.dll.GetUserNameExW",
  675. "advapi32.dll.GetUserNameW",
  676. "kernel32.dll.ReleaseMutex",
  677. "advapi32.dll.RegisterEventSourceW",
  678. "advapi32.dll.DeregisterEventSource",
  679. "advapi32.dll.ReportEventW",
  680. "kernel32.dll.GetLogicalDrives",
  681. "kernel32.dll.GetDriveTypeW",
  682. "kernel32.dll.GetVolumeInformationW",
  683. "kernel32.dll.GetCurrentDirectoryW",
  684. "kernel32.dll.GetLastError",
  685. "kernel32.dll.GetStdHandle",
  686. "kernel32.dll.GetConsoleMode",
  687. "kernel32.dll.SetEvent",
  688. "kernel32.dll.FindFirstFileW",
  689. "kernel32.dll.FindClose",
  690. "mscoree.dll.DllGetClassObject",
  691. "diasymreader.dll.DllGetClassObjectInternal",
  692. "kernel32.dll.GetConsoleOutputCP",
  693. "gdi32.dll.TranslateCharsetInfo",
  694. "kernel32.dll.SetConsoleTextAttribute",
  695. "kernel32.dll.WriteConsoleW",
  696. "mscoree.dll.CorExitProcess",
  697. "mscorwks.dll.CorExitProcess",
  698. "mscorwks.dll._CorDllMain",
  699. "kernel32.dll.CreateActCtxW",
  700. "kernel32.dll.AddRefActCtx",
  701. "kernel32.dll.ReleaseActCtx",
  702. "kernel32.dll.ActivateActCtx",
  703. "kernel32.dll.DeactivateActCtx",
  704. "kernel32.dll.GetCurrentActCtx",
  705. "kernel32.dll.QueryActCtxW",
  706. "netutils.dll.NetApiBufferFree",
  707. "kernel32.dll.IsProcessorFeaturePresent",
  708. "ntdll.dll.RtlUnwind",
  709. "mscoree.dll._CorExeMain",
  710. "mscoree.dll._CorImageUnloading",
  711. "mscoree.dll._CorValidateImage",
  712. "cryptsp.dll.CryptExportKey",
  713. "kernel32.dll.SwitchToThread",
  714. "rpcrt4.dll.UuidFromStringW",
  715. "rpcrt4.dll.RpcBindingCreateW",
  716. "rpcrt4.dll.RpcBindingBind",
  717. "sechost.dll.StartServiceW"
  718. ]
  719.  
  720. [*] Static Analysis: {
  721. "office": {
  722. "Metadata": {
  723. "HasMacros": "No"
  724. }
  725. }
  726. }
Add Comment
Please, Sign In to add comment