paladin316

Exes_7225fdf605389403635bcbe90770a435_exe.json

Jun 19th, 2019
2,229
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 97.31 KB | None | 0 0
  1.  
  2. [*] MalFamily: ""
  3.  
  4. [*] MalScore: 10.0
  5.  
  6. [*] File Name: "Exes_7225fdf605389403635bcbe90770a435.exe"
  7. [*] File Size: 2363733
  8. [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. [*] SHA256: "fcad77aba9a0290e0f25b0512ceadf102aff36c955a319275b3f44565d53c383"
  10. [*] MD5: "7225fdf605389403635bcbe90770a435"
  11. [*] SHA1: "58361b1cb63df9dbf6f70b821bff09a4a96eee0f"
  12. [*] SHA512: "68ed93ff706ce204543bd31b2d79b171729df1dbc139132a3f080f757f7cc5966fa500b6ed91de93a481183bb4b669b726e5fae55f396d1395f18bab6db9a244"
  13. [*] CRC32: "84C0C691"
  14. [*] SSDEEP: "49152:XW9mZBUziRXlZuj3t+DRjv5RLvrfKyIexMrwd:XWgYK1Ej3tCvjrfKyIeKwd"
  15.  
  16. [*] Process Execution: [
  17. "Exes_7225fdf605389403635bcbe90770a435.exe",
  18. "twain.exe",
  19. "cmd.exe",
  20. "net.exe",
  21. "net1.exe",
  22. "net.exe",
  23. "net1.exe",
  24. "net.exe",
  25. "net1.exe",
  26. "net.exe",
  27. "net1.exe",
  28. "net.exe",
  29. "net1.exe",
  30. "net.exe",
  31. "net1.exe",
  32. "net.exe",
  33. "net1.exe",
  34. "sc.exe",
  35. "sc.exe",
  36. "sc.exe",
  37. "sc.exe",
  38. "sc.exe",
  39. "sc.exe",
  40. "sc.exe",
  41. "sc.exe",
  42. "sc.exe",
  43. "sc.exe",
  44. "sc.exe",
  45. "sc.exe",
  46. "sc.exe",
  47. "sc.exe",
  48. "sc.exe",
  49. "sc.exe",
  50. "sc.exe",
  51. "sc.exe",
  52. "sc.exe",
  53. "net.exe",
  54. "net1.exe",
  55. "net.exe",
  56. "net1.exe",
  57. "net.exe",
  58. "net1.exe",
  59. "sc.exe",
  60. "taskkill.exe",
  61. "taskkill.exe",
  62. "taskkill.exe",
  63. "WMIC.exe",
  64. "WMIC.exe",
  65. "WMIC.exe",
  66. "WMIC.exe",
  67. "WMIC.exe",
  68. "WMIC.exe",
  69. "cmd.exe",
  70. "net.exe",
  71. "net1.exe",
  72. "net.exe",
  73. "net1.exe",
  74. "svchost.exe",
  75. "svchost.exe",
  76. "sc.exe",
  77. "sc.exe",
  78. "svchost.exe",
  79. "svchost.exe",
  80. "svchost.exe",
  81. "PING.EXE",
  82. "svchost.exe",
  83. "net.exe",
  84. "net1.exe",
  85. "cmd.exe",
  86. "schtasks.exe",
  87. "cmd.exe",
  88. "schtasks.exe",
  89. "attrib.exe",
  90. "attrib.exe",
  91. "cmd.exe",
  92. "cacls.exe",
  93. "cmd.exe",
  94. "cacls.exe",
  95. "cmd.exe",
  96. "cacls.exe",
  97. "cmd.exe",
  98. "cacls.exe",
  99. "cmd.exe",
  100. "cacls.exe",
  101. "cmd.exe",
  102. "cacls.exe",
  103. "cmd.exe",
  104. "cacls.exe",
  105. "cmd.exe",
  106. "cacls.exe",
  107. "cmd.exe",
  108. "cacls.exe",
  109. "cmd.exe",
  110. "cacls.exe",
  111. "cmd.exe",
  112. "cacls.exe",
  113. "cmd.exe",
  114. "cacls.exe",
  115. "cmd.exe",
  116. "cacls.exe",
  117. "cmd.exe",
  118. "cacls.exe",
  119. "cmd.exe",
  120. "cacls.exe",
  121. "cmd.exe",
  122. "cacls.exe",
  123. "cmd.exe",
  124. "cacls.exe",
  125. "cmd.exe",
  126. "cacls.exe",
  127. "cmd.exe",
  128. "cacls.exe",
  129. "cmd.exe",
  130. "cacls.exe",
  131. "cmd.exe",
  132. "cacls.exe",
  133. "cmd.exe",
  134. "cacls.exe",
  135. "cmd.exe",
  136. "cacls.exe",
  137. "cmd.exe",
  138. "cacls.exe",
  139. "cmd.exe",
  140. "cacls.exe",
  141. "services.exe",
  142. "svchost.exe",
  143. "cmd.exe",
  144. "mode.com",
  145. "sc.exe",
  146. "sc.exe",
  147. "sc.exe",
  148. "sc.exe",
  149. "net.exe",
  150. "net1.exe",
  151. "net.exe",
  152. "net1.exe",
  153. "net.exe",
  154. "net1.exe",
  155. "net.exe",
  156. "net1.exe",
  157. "taskkill.exe",
  158. "taskkill.exe",
  159. "taskkill.exe",
  160. "taskkill.exe",
  161. "svchost.exe",
  162. "WmiPrvSE.exe",
  163. "WmiPrvSE.exe",
  164. "svchost.exe",
  165. "msiexec.exe",
  166. "GoogleUpdate.exe",
  167. "taskhost.exe",
  168. "GoogleUpdate.exe",
  169. "WMIADAP.exe"
  170. ]
  171.  
  172. [*] Signatures Detected: [
  173. {
  174. "Description": "Attempts to connect to a dead IP:Port (2 unique times)",
  175. "Details": [
  176. {
  177. "IP": "172.217.164.238:443"
  178. },
  179. {
  180. "IP": "172.217.0.227:443"
  181. }
  182. ]
  183. },
  184. {
  185. "Description": "Possible date expiration check, exits too soon after checking local time",
  186. "Details": [
  187. {
  188. "process": "Exes_7225fdf605389403635bcbe90770a435.exe, PID 1464"
  189. }
  190. ]
  191. },
  192. {
  193. "Description": "Creates RWX memory",
  194. "Details": []
  195. },
  196. {
  197. "Description": "A process attempted to delay the analysis task.",
  198. "Details": [
  199. {
  200. "Process": "GoogleUpdate.exe tried to sleep 601 seconds, actually delayed analysis time by 0 seconds"
  201. },
  202. {
  203. "Process": "taskkill.exe tried to sleep 720 seconds, actually delayed analysis time by 0 seconds"
  204. },
  205. {
  206. "Process": "WMIC.exe tried to sleep 1380 seconds, actually delayed analysis time by 0 seconds"
  207. },
  208. {
  209. "Process": "WmiPrvSE.exe tried to sleep 960 seconds, actually delayed analysis time by 0 seconds"
  210. }
  211. ]
  212. },
  213. {
  214. "Description": "At least one IP Address, Domain, or File Name was found in a crypto call",
  215. "Details": [
  216. {
  217. "ioc": "http://crl.globalsign.net/root-r2.crl0"
  218. }
  219. ]
  220. },
  221. {
  222. "Description": "A process created a hidden window",
  223. "Details": [
  224. {
  225. "Process": "Exes_7225fdf605389403635bcbe90770a435.exe -> C:\\Windows\\twain.exe"
  226. },
  227. {
  228. "Process": "Exes_7225fdf605389403635bcbe90770a435.exe -> C:\\Windows\\Fonts\\Mysql\\sa.bat"
  229. },
  230. {
  231. "Process": "twain.exe -> C:\\Windows\\sysnative\\cmd"
  232. }
  233. ]
  234. },
  235. {
  236. "Description": "Performs some HTTP requests",
  237. "Details": [
  238. {
  239. "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D"
  240. },
  241. {
  242. "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D"
  243. },
  244. {
  245. "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAaJg2QslT5G973OQUPxM8E%3D"
  246. },
  247. {
  248. "url": "http://ocsp.pki.goog/GTSGIAG3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCEDoV9Mh%2FtNM5k9Pus79K5eQ%3D"
  249. },
  250. {
  251. "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAi4elAbvpzaLRZNPjlRv1U%3D"
  252. },
  253. {
  254. "url": "http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBReAhtobFzTvhaRmVeJ38QUchY9AwQUu69%2BAj36pvE8hI6t7jiY7NkyMtQCEDaCXn%2B1pIGTfvbRc2u5PKY%3D"
  255. },
  256. {
  257. "url": "http://ocsp.pki.goog/GTSGIAG3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCEEpXWRnDaZSEY67E8B6coDU%3D"
  258. },
  259. {
  260. "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnR4FoxLLkI7vkvsUIFlZt%2BlGH3gQUWsS5eyoKo6XqcQPAYPkt9mV1DlgCEAwVvkoVuwkDyQGx1sJlMC8%3D"
  261. },
  262. {
  263. "url": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab"
  264. },
  265. {
  266. "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D"
  267. },
  268. {
  269. "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAQJGBtf1btmdVNDtW%2BVUAg%3D"
  270. },
  271. {
  272. "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAiIzVJfGSRETRSlgpHeuVI%3D"
  273. },
  274. {
  275. "url": "http://ocsp.pki.goog/GTSGIAG3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCEH4PjD8bD0NfJXpoX0ln6s4%3D"
  276. },
  277. {
  278. "url": "http://ocsp.pki.goog/GTSGIAG3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCEHQnb7Tt0tUhlRVnnq4nPN8%3D"
  279. },
  280. {
  281. "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnR4FoxLLkI7vkvsUIFlZt%2BlGH3gQUWsS5eyoKo6XqcQPAYPkt9mV1DlgCEAM%2B1e2gZdG4yR38%2BSpsm9g%3D"
  282. },
  283. {
  284. "url": "http://ocsp.pki.goog/GTSGIAG3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCEHAHFVlJElKyLEMbtWWDIbo%3D"
  285. },
  286. {
  287. "url": "http://ocsp.msocsp.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPC1vZt9qvn7bzY3Iidtbhla4mKQQUWIif1tycSCK3FD7%2FhIjo5oX%2F%2Bn0CE3sAAGyvV14%2FmEPDgh0AAAAAbK8%3D"
  288. },
  289. {
  290. "url": "http://ocsp.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS%2BzcBkvzl4%3D"
  291. },
  292. {
  293. "url": "http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCECdm7lbrSfOOq9dwovyE3iI%3D"
  294. },
  295. {
  296. "url": "http://th.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRsif7263KedmR2MLuYKv9%2BWQCtWAQU1A1lP3q9NMb%2BR%2BdMDcC98t4Vq3ECEBT4%2FdFn%2BSQCsVcLXcSVyBU%3D"
  297. },
  298. {
  299. "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D"
  300. },
  301. {
  302. "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAVG%2Fhgj9%2BGUHaOfzhTEYXM%3D"
  303. },
  304. {
  305. "url": "http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjqTAc%2FHIGOD%2BaUx0%3D"
  306. },
  307. {
  308. "url": "http://redirector.gvt1.com/edgedl/release2/chrome/ANcTHgjx95-y_74.0.3729.169/74.0.3729.169_73.0.3683.86_chrome_updater.exe"
  309. },
  310. {
  311. "url": "http://r4---sn-tt1e7n7k.gvt1.com/edgedl/release2/chrome/ANcTHgjx95-y_74.0.3729.169/74.0.3729.169_73.0.3683.86_chrome_updater.exe?cms_redirect=yes&mip=172.98.67.13&mm=28&mn=sn-tt1e7n7k&ms=nvh&mt=1560995678&mv=m&pl=24&shardbypass=yes"
  312. }
  313. ]
  314. },
  315. {
  316. "Description": "The binary likely contains encrypted or compressed data.",
  317. "Details": [
  318. {
  319. "section": "name: .rsrc, entropy: 8.00, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00240f55, virtual_size: 0x00248000"
  320. }
  321. ]
  322. },
  323. {
  324. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  325. "Details": [
  326. {
  327. "Spam": "services.exe (504) called API GetSystemTimeAsFileTime 12881182 times"
  328. }
  329. ]
  330. },
  331. {
  332. "Description": "Attempts to execute a Living Off The Land Binary command for post exeploitation",
  333. "Details": [
  334. {
  335. "MITRE T1078 - schtask": "(Tactic: Execution, Persistence, Privilege Escalation)"
  336. }
  337. ]
  338. },
  339. {
  340. "Description": "Installs itself for autorun at Windows startup",
  341. "Details": [
  342. {
  343. "service name": "MicrosoftMysql"
  344. },
  345. {
  346. "service path": "C:\\Windows\\Fonts\\Mysql\\svchost.exe"
  347. },
  348. {
  349. "task": "schtasks /create /TN \"At1\" /TR \"C:\\Windows\\Fonts\\Mysql\\nei.bat\" /SC daily /ST 11:00:00 /RU SYSTEM"
  350. }
  351. ]
  352. },
  353. {
  354. "Description": "Creates a hidden or system file",
  355. "Details": [
  356. {
  357. "file": "C:\\Windows\\Fonts\\Mysql\\cmd.bat"
  358. },
  359. {
  360. "file": "C:\\Windows\\Fonts\\Mysql\\loab.bat"
  361. },
  362. {
  363. "file": "C:\\Windows\\Fonts\\Mysql\\load.bat"
  364. },
  365. {
  366. "file": "C:\\Windows\\Fonts\\Mysql\\nei.bat"
  367. },
  368. {
  369. "file": "C:\\Windows\\Fonts\\Mysql\\poab.bat"
  370. },
  371. {
  372. "file": "C:\\Windows\\Fonts\\Mysql\\poad.bat"
  373. },
  374. {
  375. "file": "C:\\Windows\\Fonts\\Mysql\\wai.bat"
  376. },
  377. {
  378. "file": "C:\\Windows\\Fonts\\Mysql\\svchost.exe"
  379. },
  380. {
  381. "file": "C:\\Windows\\Fonts\\Mysql\\taskhost.exe"
  382. },
  383. {
  384. "file": "C:\\Windows\\Fonts\\Mysql\\Doublepulsar.dll"
  385. },
  386. {
  387. "file": "C:\\Windows\\Fonts\\Mysql\\Doublepulsar2.dll"
  388. },
  389. {
  390. "file": "C:\\Windows\\Fonts\\Mysql\\Eternalblue.dll"
  391. },
  392. {
  393. "file": "C:\\Windows\\Fonts\\Mysql\\Eternalblue2.dll"
  394. },
  395. {
  396. "file": "C:\\Windows\\Fonts\\Mysql\\bat.bat"
  397. }
  398. ]
  399. },
  400. {
  401. "Description": "File has been identified by 59 Antiviruses on VirusTotal as malicious",
  402. "Details": [
  403. {
  404. "MicroWorld-eScan": "Dropped:Trojan.GenericKD.32059488"
  405. },
  406. {
  407. "CAT-QuickHeal": "Trojan.Script"
  408. },
  409. {
  410. "McAfee": "Artemis!7225FDF60538"
  411. },
  412. {
  413. "Cylance": "Unsafe"
  414. },
  415. {
  416. "VIPRE": "Packed.Win32.Upack (v)"
  417. },
  418. {
  419. "Alibaba": "Backdoor:Win32/ShadowBrokers.83d88dfc"
  420. },
  421. {
  422. "K7GW": "Trojan ( 005329b91 )"
  423. },
  424. {
  425. "K7AntiVirus": "Trojan ( 005329b91 )"
  426. },
  427. {
  428. "Arcabit": "Trojan.Generic.D1E93060"
  429. },
  430. {
  431. "TrendMicro": "Trojan.Win32.ZYX.USASHEM19"
  432. },
  433. {
  434. "Symantec": "Trojan.Gen.MBT"
  435. },
  436. {
  437. "APEX": "Malicious"
  438. },
  439. {
  440. "Paloalto": "generic.ml"
  441. },
  442. {
  443. "ClamAV": "Win.Malware.Shadowbrokers-6958490-0"
  444. },
  445. {
  446. "Kaspersky": "HEUR:Trojan.Script.EquationDrug.gen"
  447. },
  448. {
  449. "BitDefender": "Dropped:Trojan.GenericKD.32059488"
  450. },
  451. {
  452. "NANO-Antivirus": "Trojan.Win32.Delphi.fihmoq"
  453. },
  454. {
  455. "AegisLab": "Trojan.Win32.OnLineGames.lpXN"
  456. },
  457. {
  458. "Avast": "Win32:Malware-gen"
  459. },
  460. {
  461. "Tencent": "Script.Trojan.Equationdrug.Aedx"
  462. },
  463. {
  464. "Endgame": "malicious (high confidence)"
  465. },
  466. {
  467. "Sophos": "Mal/EncPk-BW"
  468. },
  469. {
  470. "Comodo": "Packed.Win32.Klone.~KMG@1knj1d"
  471. },
  472. {
  473. "F-Secure": "Trojan.TR/Dropper.Gen"
  474. },
  475. {
  476. "DrWeb": "Trojan.PWS.Panda.8062"
  477. },
  478. {
  479. "Zillya": "Trojan.ShadowBrokers.Win32.104"
  480. },
  481. {
  482. "Invincea": "heuristic"
  483. },
  484. {
  485. "McAfee-GW-Edition": "BehavesLike.Win32.Generic.vc"
  486. },
  487. {
  488. "Trapmine": "malicious.high.ml.score"
  489. },
  490. {
  491. "FireEye": "Generic.mg.7225fdf605389403"
  492. },
  493. {
  494. "Emsisoft": "Dropped:Trojan.GenericKD.32059488 (B)"
  495. },
  496. {
  497. "Ikarus": "Trojan.Dropper"
  498. },
  499. {
  500. "Cyren": "W32/Backdoor.LOYL-7473"
  501. },
  502. {
  503. "ESET-NOD32": "a variant of Win32/TrojanDropper.Agent.QBR"
  504. },
  505. {
  506. "Webroot": "W32.Trojan.Gen"
  507. },
  508. {
  509. "Avira": "TR/Dropper.Gen"
  510. },
  511. {
  512. "Antiy-AVL": "Trojan/Script.EquationDrug"
  513. },
  514. {
  515. "Microsoft": "Trojan:Win32/Eqtonex.F"
  516. },
  517. {
  518. "ViRobot": "Trojan.Win32.Z.Backdoor.2363733"
  519. },
  520. {
  521. "ZoneAlarm": "HEUR:Trojan.Script.EquationDrug.gen"
  522. },
  523. {
  524. "GData": "Dropped:Trojan.GenericKD.32059488"
  525. },
  526. {
  527. "AhnLab-V3": "Trojan/Win32.OnlineGameHack.R36603"
  528. },
  529. {
  530. "Acronis": "suspicious"
  531. },
  532. {
  533. "VBA32": "Trojan.Script"
  534. },
  535. {
  536. "ALYac": "Trojan.EquationDrug"
  537. },
  538. {
  539. "MAX": "malware (ai score=94)"
  540. },
  541. {
  542. "Ad-Aware": "Dropped:Trojan.GenericKD.32059488"
  543. },
  544. {
  545. "TrendMicro-HouseCall": "Trojan.Win32.ZYX.USASHEM19"
  546. },
  547. {
  548. "Rising": "Backdoor.Agent!8.C5D (TFE:4:vmNpoqpdP1C)"
  549. },
  550. {
  551. "Yandex": "Trojan.DR.Agent!fHEwlF+lDns"
  552. },
  553. {
  554. "SentinelOne": "DFI - Malicious PE"
  555. },
  556. {
  557. "eGambit": "Unsafe.AI_Score_99%"
  558. },
  559. {
  560. "Fortinet": "W32/Agent.QBR!tr"
  561. },
  562. {
  563. "MaxSecure": "Trojan.Malware.0.susgen"
  564. },
  565. {
  566. "AVG": "Win32:Malware-gen"
  567. },
  568. {
  569. "Cybereason": "malicious.605389"
  570. },
  571. {
  572. "Panda": "Trj/Genetic.gen"
  573. },
  574. {
  575. "CrowdStrike": "win/malicious_confidence_100% (W)"
  576. },
  577. {
  578. "Qihoo-360": "Win32/Backdoor.1cc"
  579. }
  580. ]
  581. }
  582. ]
  583.  
  584. [*] Started Service: [
  585. "MicrosoftMysql",
  586. "msiserver",
  587. "gupdate",
  588. "Browser",
  589. "LanmanWorkstation",
  590. "LanmanServer"
  591. ]
  592.  
  593. [*] Executed Commands: [
  594. "C:\\Windows\\twain.exe ",
  595. "C:\\Windows\\Fonts\\Mysql\\sa.bat ",
  596. "\"C:\\Windows\\sysnative\\cmd.exe\" /c \"C:\\Users\\user\\AppData\\Local\\Temp\\605.tmp\\606.bat C:\\Windows\\twain.exe\"",
  597. "C:\\Windows\\sysnative\\cmd /c \"C:\\Users\\user\\AppData\\Local\\Temp\\605.tmp\\606.bat C:\\Windows\\twain.exe\"",
  598. "net stop \"MicrosoftMysql\"",
  599. "net stop \"MicrosoftMssql\"",
  600. "svchost stop \"MicrosoftFonts\"",
  601. "svchost stop \"MicrosoftMysql\"",
  602. "sc delete \"MicrosoftMysql\"",
  603. "sc delete \"MicrosoftMssql\"",
  604. "svchost install MicrosoftMysql \"C:\\Windows\\Fonts\\Mysql\\cmd.bat\"",
  605. "svchost install MicrosoftMysql C:\\Windows\\Fonts\\Mysql\\cmd.bat",
  606. "svchost install \"MicrosoftMysql\" C:\\Windows\\Fonts\\Mysql\\cmd.bat",
  607. "C:\\Windows\\system32\\PING.EXE ping 127.0.0.1 -n 20",
  608. "svchost start \"MicrosoftMysql\"",
  609. "net start \"MicrosoftMysql\"",
  610. "C:\\Windows\\system32\\cmd.exe /S /D /c\" echo y\"",
  611. "schtasks /create /TN \"At1\" /TR \"C:\\Windows\\Fonts\\Mysql\\nei.bat\" /SC daily /ST 11:00:00 /RU SYSTEM",
  612. "schtasks /create /TN \"At2\" /TR \"C:\\Windows\\Fonts\\Mysql\\wai.bat\" /SC daily /ST 01:00:00 /RU SYSTEM",
  613. "attrib +h +s -r C:\\windows\\tasks\\At*.job",
  614. "attrib +h +s -r C:\\Windows\\System32\\Tasks\\At*",
  615. "cacls C:\\windows\\tasks\\At1.job /c /e /t /g system:F",
  616. "cacls C:\\windows\\tasks\\At2.job /c /e /t /g system:F",
  617. "cacls C:\\windows\\tasks\\At1.job /c /e /t /g everyone:F",
  618. "cacls C:\\windows\\tasks\\At2.job /c /e /t /g everyone:F",
  619. "cacls C:\\Windows\\System32\\Tasks\\At1 /c /e /t /g system:F",
  620. "cacls C:\\Windows\\System32\\Tasks\\At2 /c /e /t /g system:F",
  621. "cacls C:\\Windows\\System32\\Tasks\\At1 /c /e /t /g everyone:F",
  622. "cacls C:\\Windows\\System32\\Tasks\\At2 /c /e /t /g everyone:F",
  623. "cacls C:\\Windows\\Tasks\\MiscfostNsi /p system:n",
  624. "cacls C:\\Windows\\Tasks\\HomeGroupProvider /p system:n",
  625. "cacls C:\\Windows\\Tasks\\WwANsvc /p system:n",
  626. "cacls C:\\Windows\\Tasks\\*fost* /p system:n",
  627. "cacls C:\\Windows\\Tasks\\*Group* /p system:n",
  628. "cacls C:\\Windows\\Tasks\\*sa* /p system:n",
  629. "cacls C:\\Windows\\Tasks\\*ok* /p system:n",
  630. "cacls C:\\Windows\\Tasks\\*my* /p system:n",
  631. "cacls C:\\Windows\\System32\\Tasks\\MiscfostNsi /p system:n",
  632. "cacls C:\\Windows\\System32\\Tasks\\HomeGroupProvider /p system:n",
  633. "cacls C:\\Windows\\System32\\Tasks\\WwANsvc /p system:n",
  634. "cacls C:\\Windows\\System32\\Tasks\\*fost* /p system:n",
  635. "cacls C:\\Windows\\System32\\Tasks\\*Group* /p system:n",
  636. "cacls C:\\Windows\\System32\\Tasks\\*sa* /p system:n",
  637. "cacls C:\\Windows\\System32\\Tasks\\*ok* /p system:n",
  638. "cacls C:\\Windows\\System32\\Tasks\\*my* /p system:n",
  639. "cacls C:\\Windows\\Fonts\\Mysql\\sa.bat /p system:n",
  640. "net stop DiaogTracke",
  641. "net stop Stuvwx",
  642. "net stop \"mssecsvc2.1\"",
  643. "net stop serviecs",
  644. "net stop \"mssecsvc2.0\"",
  645. "net stop \"lbpuamoqhpoqju171\"",
  646. "net stop \"MicrosotMaims\"",
  647. "sc stop \"tjuldl\"",
  648. "sc stop \"MicrosotMaims\"",
  649. "sc stop \"fastuserswitchingcompatibility\"",
  650. "sc stop \"dbuxbr\"",
  651. "sc stop \"mssecsvc2.1\"",
  652. "sc stop \"mssecsvc2.0\"",
  653. "sc stop \"lbpuamoqhpoqju171\"",
  654. "sc config \"tjuldl\" start= disabled",
  655. "sc config \"MicrosotMaims\" start= disabled",
  656. "sc config \"fastuserswitchingcompatibility\" start= disabled",
  657. "sc config \"dbuxbr\" start= disabled",
  658. "sc config \"mssecsvc2.1\" start= disabled",
  659. "sc config \"mssecsvc2.0\" start= disabled",
  660. "sc config \"lbpuamoqhpoqju171\" start= disabled",
  661. "sc config Stuvwx start= disabled",
  662. "sc config DiaogTracke start= disabled",
  663. "sc config serviecs start= disabled",
  664. "sc config WinSystemXlv start= disabled",
  665. "sc config gupdatementers start= disabled",
  666. "net stop WinSystemXlv",
  667. "net stop gupdatementers",
  668. "taskkill /f /im mssecsvr.exe",
  669. "taskkill /f /im mssecsvc.exe",
  670. "taskkill /f /im tasksche.exe",
  671. "C:\\Windows\\System32\\Wbem\\WMIC.exe Wmic Process Where \"Name='svchost.exe' And ExecutablePath='C:\\\\Windows\\\\Fonts\\\\Microsoft\\\\svchost.exe'\" Call Terminate",
  672. "C:\\Windows\\System32\\Wbem\\WMIC.exe Wmic Process Where \"Name='taskhost.exe' And ExecutablePath='C:\\\\Windows\\\\Fonts\\\\Microsoft\\\\taskhost.exe'\" Call Terminate",
  673. "C:\\Windows\\System32\\Wbem\\WMIC.exe Wmic Process Where \"Name='mssecsvr.exe' And ExecutablePath='C:\\\\Windows\\\\mssecsvr.exe'\" Call Terminate",
  674. "C:\\Windows\\System32\\Wbem\\WMIC.exe Wmic Process Where \"Name='tasksche.exe' And ExecutablePath='C:\\\\Windows\\\\tasksche.exe'\" Call Terminate",
  675. "C:\\Windows\\System32\\Wbem\\WMIC.exe Wmic Process Where \"Name='mssecsvc.exe' And ExecutablePath='C:\\\\WINDOWS\\\\mssecsvc.exe'\" Call Terminate",
  676. "C:\\Windows\\system32\\net1 stop \"MicrosoftMysql\"",
  677. "C:\\Windows\\system32\\net1 stop DiaogTracke",
  678. "C:\\Windows\\system32\\net1 stop \"MicrosoftMssql\"",
  679. "C:\\Windows\\system32\\net1 stop Stuvwx",
  680. "C:\\Windows\\system32\\net1 stop \"mssecsvc2.1\"",
  681. "C:\\Windows\\system32\\net1 stop serviecs",
  682. "C:\\Windows\\system32\\net1 stop \"mssecsvc2.0\"",
  683. "C:\\Windows\\system32\\net1 stop \"lbpuamoqhpoqju171\"",
  684. "C:\\Windows\\system32\\net1 stop \"MicrosotMaims\"",
  685. "C:\\Windows\\system32\\net1 stop WinSystemXlv",
  686. "C:\\Windows\\Fonts\\Mysql\\svchost.exe",
  687. "C:\\Windows\\system32\\svchost.exe -k netsvcs",
  688. "C:\\Windows\\system32\\msiexec.exe /V",
  689. "\"C:\\Program Files (x86)\\Google\\Update\\GoogleUpdate.exe\" /svc",
  690. "C:\\Windows\\System32\\svchost.exe -k netsvcs",
  691. "C:\\Windows\\system32\\net1 stop gupdatementers",
  692. "\"C:\\Windows\\Fonts\\Mysql\\cmd.bat\"",
  693. "mode con cols=50 lines=40",
  694. "sc config Browser start= auto",
  695. "sc config lanmanworkstation start= auto",
  696. "sc config lanmanserver start= auto",
  697. "sc config SharedAccess start= disabled",
  698. "net start Browser",
  699. "net start lanmanworkstation",
  700. "net start lanmanserver",
  701. "net stop SharedAccess",
  702. "taskkill /f /im mance.exe",
  703. "taskkill /f /im Eter.exe",
  704. "taskkill /f /im puls.exe",
  705. "C:\\Windows\\system32\\net1 start \"MicrosoftMysql\"",
  706. "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding",
  707. "C:\\Windows\\system32\\net1 start Browser",
  708. "C:\\Windows\\system32\\net1 start lanmanworkstation",
  709. "C:\\Windows\\system32\\net1 start lanmanserver",
  710. "C:\\Windows\\system32\\net1 stop SharedAccess"
  711. ]
  712.  
  713. [*] Mutexes: [
  714. "Local\\ZoneAttributeCacheCounterMutex",
  715. "Local\\ZonesCacheCounterMutex",
  716. "Local\\ZonesLockedCacheCounterMutex",
  717. "Global\\_MSIExecute",
  718. "Global\\G{D19BAF17-7C87-467E-8D63-6C4B1C836373}",
  719. "Global\\G{6885AE8E-C070-458d-9711-37B9BEAB65F6}",
  720. "Global\\G{66CC0160-ABB3-4066-AE47-1CA6AD5065C8}",
  721. "Global\\G{0A175FBE-AEEC-4fea-855A-2AA549A88846}",
  722. "Global\\ADAP_WMI_ENTRY",
  723. "Global\\RefreshRA_Mutex",
  724. "Global\\RefreshRA_Mutex_Lib",
  725. "Global\\RefreshRA_Mutex_Flag"
  726. ]
  727.  
  728. [*] Modified Files: [
  729. "C:\\Windows\\Fonts\\Mysql\\cmd.bat",
  730. "C:\\Windows\\Fonts\\Mysql\\loab.bat",
  731. "C:\\Windows\\Fonts\\Mysql\\load.bat",
  732. "C:\\Windows\\Fonts\\Mysql\\nei.bat",
  733. "C:\\Windows\\Fonts\\Mysql\\poab.bat",
  734. "C:\\Windows\\Fonts\\Mysql\\poad.bat",
  735. "C:\\Windows\\Fonts\\Mysql\\wai.bat",
  736. "C:\\Windows\\Fonts\\Mysql\\Eter.xml",
  737. "C:\\Windows\\Fonts\\Mysql\\mance.xml",
  738. "C:\\Windows\\Fonts\\Mysql\\puls.xml",
  739. "C:\\Windows\\Fonts\\Mysql\\file.txt",
  740. "C:\\Windows\\Fonts\\Mysql\\p.txt",
  741. "C:\\Windows\\Fonts\\Mysql\\Eter.exe",
  742. "C:\\Windows\\Fonts\\Mysql\\mance.exe",
  743. "C:\\Windows\\Fonts\\Mysql\\puls.exe",
  744. "C:\\Windows\\Fonts\\Mysql\\svchost.exe",
  745. "C:\\Windows\\Fonts\\Mysql\\taskhost.exe",
  746. "C:\\Windows\\Fonts\\Mysql\\wget.exe",
  747. "C:\\Windows\\Fonts\\Mysql\\cnli-1.dll",
  748. "C:\\Windows\\Fonts\\Mysql\\coli-0.dll",
  749. "C:\\Windows\\Fonts\\Mysql\\crli-0.dll",
  750. "C:\\Windows\\Fonts\\Mysql\\dmgd-4.dll",
  751. "C:\\Windows\\Fonts\\Mysql\\Doublepulsar.dll",
  752. "C:\\Windows\\Fonts\\Mysql\\Doublepulsar2.dll",
  753. "C:\\Windows\\Fonts\\Mysql\\Eternalblue.dll",
  754. "C:\\Windows\\Fonts\\Mysql\\Eternalblue2.dll",
  755. "C:\\Windows\\Fonts\\Mysql\\exma-1.dll",
  756. "C:\\Windows\\Fonts\\Mysql\\libeay32.dll",
  757. "C:\\Windows\\Fonts\\Mysql\\libxml2.dll",
  758. "C:\\Windows\\Fonts\\Mysql\\NansHou.dll",
  759. "C:\\Windows\\Fonts\\Mysql\\posh-0.dll",
  760. "C:\\Windows\\Fonts\\Mysql\\ssleay32.dll",
  761. "C:\\Windows\\Fonts\\Mysql\\tibe-2.dll",
  762. "C:\\Windows\\Fonts\\Mysql\\tich-1.dll",
  763. "C:\\Windows\\Fonts\\Mysql\\trch-1.dll",
  764. "C:\\Windows\\Fonts\\Mysql\\trfo-2.dll",
  765. "C:\\Windows\\Fonts\\Mysql\\tucl-1.dll",
  766. "C:\\Windows\\Fonts\\Mysql\\tufo-2.dll",
  767. "C:\\Windows\\Fonts\\Mysql\\ucl.dll",
  768. "C:\\Windows\\Fonts\\Mysql\\xdvl-0.dll",
  769. "C:\\Windows\\Fonts\\Mysql\\zlib1.dll",
  770. "C:\\Windows\\twain.exe",
  771. "C:\\Windows\\Fonts\\Mysql\\bat.bat",
  772. "C:\\Windows\\Fonts\\Mysql\\sa.bat",
  773. "C:\\Users\\user\\AppData\\Local\\Temp\\605.tmp\\606.bat",
  774. "\\??\\nul",
  775. "\\Device\\NamedPipe",
  776. "C:\\Windows\\sysnative\\drivers\\etc\\hosts",
  777. "C:\\Windows\\sysnative\\LogFiles\\Scm\\5869f1c1-01d7-41f7-84b7-715672259fa8",
  778. "C:\\ProgramData\\Adobe\\ARM\\{291AA914-A987-4CE9-BD63-AC0A92D435E5}\\RdrManifest2.msi",
  779. "C:\\Windows\\sysnative\\Tasks\\At1",
  780. "C:\\Windows\\sysnative\\Tasks\\At2",
  781. "C:\\Windows\\appcompat\\Programs\\RecentFileCache.bcf",
  782. "\\Device\\LanmanDatagramReceiver",
  783. "C:\\Windows\\SoftwareDistribution\\DataStore\\DataStore.edb",
  784. "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edb.chk",
  785. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
  786. "C:\\Windows\\Installer\\283efa.msi",
  787. "C:\\Windows\\Installer\\283efb.msi",
  788. "\\??\\PIPE\\wkssvc",
  789. "\\??\\pipe\\GoogleCrashServices\\S-1-5-18"
  790. ]
  791.  
  792. [*] Deleted Files: [
  793. "C:\\Windows\\Fonts\\Mysql\\cmd.bat",
  794. "C:\\Windows\\Fonts\\Mysql\\loab.bat",
  795. "C:\\Windows\\Fonts\\Mysql\\load.bat",
  796. "C:\\Windows\\Fonts\\Mysql\\nei.bat",
  797. "C:\\Windows\\Fonts\\Mysql\\poab.bat",
  798. "C:\\Windows\\Fonts\\Mysql\\poad.bat",
  799. "C:\\Windows\\Fonts\\Mysql\\wai.bat",
  800. "C:\\Windows\\Fonts\\Mysql\\Eter.xml",
  801. "C:\\Windows\\Fonts\\Mysql\\mance.xml",
  802. "C:\\Windows\\Fonts\\Mysql\\puls.xml",
  803. "C:\\Windows\\Fonts\\Mysql\\file.txt",
  804. "C:\\Windows\\Fonts\\Mysql\\p.txt",
  805. "C:\\Windows\\Fonts\\Mysql\\Eter.exe",
  806. "C:\\Windows\\Fonts\\Mysql\\mance.exe",
  807. "C:\\Windows\\Fonts\\Mysql\\puls.exe",
  808. "C:\\Windows\\Fonts\\Mysql\\svchost.exe",
  809. "C:\\Windows\\Fonts\\Mysql\\taskhost.exe",
  810. "C:\\Windows\\Fonts\\Mysql\\wget.exe",
  811. "C:\\Windows\\Fonts\\Mysql\\cnli-1.dll",
  812. "C:\\Windows\\Fonts\\Mysql\\coli-0.dll",
  813. "C:\\Windows\\Fonts\\Mysql\\crli-0.dll",
  814. "C:\\Windows\\Fonts\\Mysql\\dmgd-4.dll",
  815. "C:\\Windows\\Fonts\\Mysql\\Doublepulsar.dll",
  816. "C:\\Windows\\Fonts\\Mysql\\Doublepulsar2.dll",
  817. "C:\\Windows\\Fonts\\Mysql\\Eternalblue.dll",
  818. "C:\\Windows\\Fonts\\Mysql\\Eternalblue2.dll",
  819. "C:\\Windows\\Fonts\\Mysql\\exma-1.dll",
  820. "C:\\Windows\\Fonts\\Mysql\\libeay32.dll",
  821. "C:\\Windows\\Fonts\\Mysql\\libxml2.dll",
  822. "C:\\Windows\\Fonts\\Mysql\\NansHou.dll",
  823. "C:\\Windows\\Fonts\\Mysql\\posh-0.dll",
  824. "C:\\Windows\\Fonts\\Mysql\\ssleay32.dll",
  825. "C:\\Windows\\Fonts\\Mysql\\tibe-2.dll",
  826. "C:\\Windows\\Fonts\\Mysql\\tich-1.dll",
  827. "C:\\Windows\\Fonts\\Mysql\\trch-1.dll",
  828. "C:\\Windows\\Fonts\\Mysql\\trfo-2.dll",
  829. "C:\\Windows\\Fonts\\Mysql\\tucl-1.dll",
  830. "C:\\Windows\\Fonts\\Mysql\\tufo-2.dll",
  831. "C:\\Windows\\Fonts\\Mysql\\ucl.dll",
  832. "C:\\Windows\\Fonts\\Mysql\\xdvl-0.dll",
  833. "C:\\Windows\\Fonts\\Mysql\\zlib1.dll",
  834. "C:\\Windows\\twain.exe",
  835. "C:\\Windows\\Fonts\\Mysql\\bat.bat",
  836. "C:\\Windows\\Fonts\\Mysql\\sa.bat",
  837. "C:\\Users\\user\\AppData\\Local\\Temp\\605.tmp",
  838. "C:\\Users\\user\\AppData\\Local\\Temp\\605.tmp\\606.tmp",
  839. "C:\\ProgramData\\Adobe\\ARM\\{291AA914-A987-4CE9-BD63-AC0A92D435E5}\\BIT975A.tmp",
  840. "C:\\Windows\\Tasks\\At1.job",
  841. "C:\\Windows\\Tasks\\At2.job",
  842. "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edbtmp.log",
  843. "C:\\Windows\\Installer\\283efa.msi",
  844. "C:\\Users\\user\\AppData\\Local\\{2AA3CA9E-CE98-4AA8-92CA-78386DD982CC}",
  845. "C:\\Program Files (x86)\\Google\\Update\\Install\\{0E51DEF1-ED79-4FDA-92A7-D7F8B9999365}\\GoogleUpdateSetup.exe",
  846. "C:\\Program Files (x86)\\Google\\Update\\Install\\{0E51DEF1-ED79-4FDA-92A7-D7F8B9999365}"
  847. ]
  848.  
  849. [*] Modified Registry Keys: [
  850. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
  851. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
  852. "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MicrosoftMysql\\Parameters",
  853. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MicrosoftMysql\\Parameters\\Application",
  854. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MicrosoftMysql\\Parameters\\AppParameters",
  855. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MicrosoftMysql\\Parameters\\AppDirectory",
  856. "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\MicrosoftMysql\\Parameters\\AppExit",
  857. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MicrosoftMysql\\Parameters\\AppExit\\(Default)",
  858. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MicrosoftMysql\\FailureActionsOnNonCrashFailures",
  859. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Start",
  860. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Type",
  861. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Start",
  862. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\MicrosoftMysql\\Type",
  863. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Start",
  864. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SharedAccess\\Start",
  865. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Browser\\Type",
  866. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanWorkstation\\Type",
  867. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\LanmanServer\\Type",
  868. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\msiserver\\Type",
  869. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\gupdate\\Type",
  870. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Start",
  871. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Type",
  872. "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\EventLog\\Application\\NSSM",
  873. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Application\\NSSM\\EventMessageFile",
  874. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\eventlog\\Application\\NSSM\\TypesSupported",
  875. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\BITS\\StateIndex",
  876. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{844E63C1-AADC-48D1-ACE9-C29FE0309795}\\Path",
  877. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{844E63C1-AADC-48D1-ACE9-C29FE0309795}\\Hash",
  878. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\At1\\Id",
  879. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\At1\\Index",
  880. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{844E63C1-AADC-48D1-ACE9-C29FE0309795}\\Triggers",
  881. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{844E63C1-AADC-48D1-ACE9-C29FE0309795}\\DynamicInfo",
  882. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{BA11F2B3-0190-41C3-95F6-1F6B8FEBB2E1}\\DynamicInfo",
  883. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4BD0ACB8-E4DA-4254-95D6-2E62DB0320AC}\\Path",
  884. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4BD0ACB8-E4DA-4254-95D6-2E62DB0320AC}\\Hash",
  885. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\At2\\Id",
  886. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\At2\\Index",
  887. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4BD0ACB8-E4DA-4254-95D6-2E62DB0320AC}\\Triggers",
  888. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{4BD0ACB8-E4DA-4254-95D6-2E62DB0320AC}\\DynamicInfo",
  889. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{ED0D73D7-BC97-46E2-AC55-FD6EB3F72C05}\\DynamicInfo",
  890. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{74B32FB8-1950-4398-8528-773F64305286}\\DynamicInfo",
  891. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{26CEE9A6-18F5-4F69-8C4D-2467328655EB}\\DynamicInfo",
  892. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\{F3F786D2-6E05-49FA-8A99-53C51C984120}\\DynamicInfo",
  893. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000_CLASSES\\Local Settings\\MuiCache\\2E\\52C64B7E\\LanguageList",
  894. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Google\\Update\\proxy\\source",
  895. "HKEY_LOCAL_MACHINE\\Software\\Google\\Update\\PersistedPings\\{DCDE4DD3-D079-42D6-AA76-481CC68B1238}",
  896. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\PersistedPings\\{DCDE4DD3-D079-42D6-AA76-481CC68B1238}\\PersistedPingString",
  897. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\PersistedPings\\{DCDE4DD3-D079-42D6-AA76-481CC68B1238}\\PersistedPingTime",
  898. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\pv",
  899. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\pv",
  900. "HKEY_LOCAL_MACHINE\\Software\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\CurrentState",
  901. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\CurrentState\\StateValue",
  902. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\RollCallDayStartSec",
  903. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\DayOfLastRollCall",
  904. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\ping_freshness",
  905. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\cohort\\(Default)",
  906. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\cohort\\hint",
  907. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\cohort\\name",
  908. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\LastCheckSuccess",
  909. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\dr",
  910. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\ActivePingDayStartSec",
  911. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\RollCallDayStartSec",
  912. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\DayOfLastActivity",
  913. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\DayOfLastRollCall",
  914. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\ping_freshness",
  915. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\cohort\\(Default)",
  916. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\cohort\\hint",
  917. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\cohort\\name",
  918. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\UpdateAvailableCount",
  919. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\UpdateAvailableSince",
  920. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\LastChecked",
  921. "HKEY_LOCAL_MACHINE\\Software\\Google\\Update\\PersistedPings\\{37C05356-6677-4C22-9618-2B4D42DDB25E}",
  922. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\PersistedPings\\{37C05356-6677-4C22-9618-2B4D42DDB25E}\\PersistedPingString",
  923. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\PersistedPings\\{37C05356-6677-4C22-9618-2B4D42DDB25E}\\PersistedPingTime",
  924. "HKEY_LOCAL_MACHINE\\Software\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\CurrentState",
  925. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\CurrentState\\DownloadTimeRemainingMs",
  926. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\CurrentState\\DownloadProgressPercent",
  927. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\CurrentState\\StateValue"
  928. ]
  929.  
  930. [*] Deleted Registry Keys: [
  931. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  932. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  933. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  934. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  935. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\At1.job",
  936. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\At1.job.fp",
  937. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\At2.job",
  938. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\At2.job.fp",
  939. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\BITS\\Performance\\PerfMMFileName",
  940. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\uid",
  941. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\old-uid",
  942. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\tttoken",
  943. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\UpdateAvailableCount",
  944. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{430FD4D0-B729-4F61-AA34-91526481799D}\\UpdateAvailableSince",
  945. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\dr",
  946. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Google\\Update\\ClientState\\{8A69D345-D564-463C-AFF1-A69D9E530F96}\\tttoken"
  947. ]
  948.  
  949. [*] DNS Communications: []
  950.  
  951. [*] Domains: []
  952.  
  953. [*] Network Communication - ICMP: []
  954.  
  955. [*] Network Communication - HTTP: [
  956. {
  957. "count": 1,
  958. "body": "",
  959. "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D",
  960. "user-agent": "Microsoft-CryptoAPI/6.1",
  961. "method": "GET",
  962. "host": "ocsp.digicert.com",
  963. "version": "1.1",
  964. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D",
  965. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEAPxtOFfOoLxFJZ4s9fYR1w%3D HTTP/1.1\r\nCache-Control: max-age = 128165\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Sat, 23 Mar 2019 11:02:13 GMT\r\nIf-None-Match: \"5c961235-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
  966. "port": 80
  967. },
  968. {
  969. "count": 1,
  970. "body": "",
  971. "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D",
  972. "user-agent": "Microsoft-CryptoAPI/6.1",
  973. "method": "GET",
  974. "host": "ocsp.digicert.com",
  975. "version": "1.1",
  976. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D",
  977. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEA%2BdzSc7B3UzA8k03selSwo%3D HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
  978. "port": 80
  979. },
  980. {
  981. "count": 1,
  982. "body": "",
  983. "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAaJg2QslT5G973OQUPxM8E%3D",
  984. "user-agent": "Microsoft-CryptoAPI/6.1",
  985. "method": "GET",
  986. "host": "ocsp.digicert.com",
  987. "version": "1.1",
  988. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAaJg2QslT5G973OQUPxM8E%3D",
  989. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSPwl%2BrBFlJbvzLXU1bGW08VysJ2wQUj%2Bh%2B8G0yagAFI8dwl2o6kP9r6tQCEAaJg2QslT5G973OQUPxM8E%3D HTTP/1.1\r\nCache-Control: max-age = 143038\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Sat, 23 Mar 2019 15:00:07 GMT\r\nIf-None-Match: \"5c9649f7-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
  990. "port": 80
  991. },
  992. {
  993. "count": 1,
  994. "body": "",
  995. "uri": "http://ocsp.pki.goog/GTSGIAG3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCEDoV9Mh%2FtNM5k9Pus79K5eQ%3D",
  996. "user-agent": "Microsoft-CryptoAPI/6.1",
  997. "method": "GET",
  998. "host": "ocsp.pki.goog",
  999. "version": "1.1",
  1000. "path": "/GTSGIAG3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCEDoV9Mh%2FtNM5k9Pus79K5eQ%3D",
  1001. "data": "GET /GTSGIAG3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCEDoV9Mh%2FtNM5k9Pus79K5eQ%3D HTTP/1.1\r\nCache-Control: max-age = 86400\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.pki.goog\r\n\r\n",
  1002. "port": 80
  1003. },
  1004. {
  1005. "count": 1,
  1006. "body": "",
  1007. "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAi4elAbvpzaLRZNPjlRv1U%3D",
  1008. "user-agent": "Microsoft-CryptoAPI/6.1",
  1009. "method": "GET",
  1010. "host": "ocsp.digicert.com",
  1011. "version": "1.1",
  1012. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAi4elAbvpzaLRZNPjlRv1U%3D",
  1013. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAi4elAbvpzaLRZNPjlRv1U%3D HTTP/1.1\r\nCache-Control: max-age = 89056\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Fri, 22 Mar 2019 18:30:24 GMT\r\nIf-None-Match: \"5c9529c0-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
  1014. "port": 80
  1015. },
  1016. {
  1017. "count": 1,
  1018. "body": "",
  1019. "uri": "http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl",
  1020. "user-agent": "Microsoft-CryptoAPI/6.1",
  1021. "method": "GET",
  1022. "host": "crl.microsoft.com",
  1023. "version": "1.1",
  1024. "path": "/pki/crl/products/MicrosoftTimeStampPCA.crl",
  1025. "data": "GET /pki/crl/products/MicrosoftTimeStampPCA.crl HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Sat, 16 Feb 2019 02:02:49 GMT\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: crl.microsoft.com\r\n\r\n",
  1026. "port": 80
  1027. },
  1028. {
  1029. "count": 1,
  1030. "body": "",
  1031. "uri": "http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBReAhtobFzTvhaRmVeJ38QUchY9AwQUu69%2BAj36pvE8hI6t7jiY7NkyMtQCEDaCXn%2B1pIGTfvbRc2u5PKY%3D",
  1032. "user-agent": "Microsoft-CryptoAPI/6.1",
  1033. "method": "GET",
  1034. "host": "ocsp.comodoca.com",
  1035. "version": "1.1",
  1036. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBReAhtobFzTvhaRmVeJ38QUchY9AwQUu69%2BAj36pvE8hI6t7jiY7NkyMtQCEDaCXn%2B1pIGTfvbRc2u5PKY%3D",
  1037. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBReAhtobFzTvhaRmVeJ38QUchY9AwQUu69%2BAj36pvE8hI6t7jiY7NkyMtQCEDaCXn%2B1pIGTfvbRc2u5PKY%3D HTTP/1.1\r\nCache-Control: max-age = 94804\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Mon, 11 Mar 2019 04:19:13 GMT\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.comodoca.com\r\n\r\n",
  1038. "port": 80
  1039. },
  1040. {
  1041. "count": 1,
  1042. "body": "",
  1043. "uri": "http://ocsp.pki.goog/GTSGIAG3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCEEpXWRnDaZSEY67E8B6coDU%3D",
  1044. "user-agent": "Microsoft-CryptoAPI/6.1",
  1045. "method": "GET",
  1046. "host": "ocsp.pki.goog",
  1047. "version": "1.1",
  1048. "path": "/GTSGIAG3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCEEpXWRnDaZSEY67E8B6coDU%3D",
  1049. "data": "GET /GTSGIAG3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCEEpXWRnDaZSEY67E8B6coDU%3D HTTP/1.1\r\nCache-Control: max-age = 86400\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.pki.goog\r\n\r\n",
  1050. "port": 80
  1051. },
  1052. {
  1053. "count": 1,
  1054. "body": "",
  1055. "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnR4FoxLLkI7vkvsUIFlZt%2BlGH3gQUWsS5eyoKo6XqcQPAYPkt9mV1DlgCEAwVvkoVuwkDyQGx1sJlMC8%3D",
  1056. "user-agent": "Microsoft-CryptoAPI/6.1",
  1057. "method": "GET",
  1058. "host": "ocsp.digicert.com",
  1059. "version": "1.1",
  1060. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnR4FoxLLkI7vkvsUIFlZt%2BlGH3gQUWsS5eyoKo6XqcQPAYPkt9mV1DlgCEAwVvkoVuwkDyQGx1sJlMC8%3D",
  1061. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnR4FoxLLkI7vkvsUIFlZt%2BlGH3gQUWsS5eyoKo6XqcQPAYPkt9mV1DlgCEAwVvkoVuwkDyQGx1sJlMC8%3D HTTP/1.1\r\nCache-Control: max-age = 108232\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Fri, 22 Mar 2019 23:50:01 GMT\r\nIf-None-Match: \"5c9574a9-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
  1062. "port": 80
  1063. },
  1064. {
  1065. "count": 1,
  1066. "body": "",
  1067. "uri": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
  1068. "user-agent": "Microsoft-CryptoAPI/6.1",
  1069. "method": "GET",
  1070. "host": "www.download.windowsupdate.com",
  1071. "version": "1.1",
  1072. "path": "/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
  1073. "data": "GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1\r\nCache-Control: max-age = 86400\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Fri, 22 Feb 2019 16:53:13 GMT\r\nIf-None-Match: \"80e22c19cfcad41:0\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: www.download.windowsupdate.com\r\n\r\n",
  1074. "port": 80
  1075. },
  1076. {
  1077. "count": 1,
  1078. "body": "",
  1079. "uri": "http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl",
  1080. "user-agent": "Microsoft-CryptoAPI/6.1",
  1081. "method": "GET",
  1082. "host": "crl.microsoft.com",
  1083. "version": "1.1",
  1084. "path": "/pki/crl/products/MicCodSigPCA_08-31-2010.crl",
  1085. "data": "GET /pki/crl/products/MicCodSigPCA_08-31-2010.crl HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Thu, 14 Feb 2019 06:01:18 GMT\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: crl.microsoft.com\r\n\r\n",
  1086. "port": 80
  1087. },
  1088. {
  1089. "count": 1,
  1090. "body": "",
  1091. "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D",
  1092. "user-agent": "Microsoft-CryptoAPI/6.1",
  1093. "method": "GET",
  1094. "host": "ocsp.digicert.com",
  1095. "version": "1.1",
  1096. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D",
  1097. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA8sEMlbBsCTf7jUSfg%2BhWk%3D HTTP/1.1\r\nCache-Control: max-age = 93156\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Sat, 16 Mar 2019 04:40:45 GMT\r\nIf-None-Match: \"5c8c7e4d-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
  1098. "port": 80
  1099. },
  1100. {
  1101. "count": 1,
  1102. "body": "",
  1103. "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAQJGBtf1btmdVNDtW%2BVUAg%3D",
  1104. "user-agent": "Microsoft-CryptoAPI/6.1",
  1105. "method": "GET",
  1106. "host": "ocsp.digicert.com",
  1107. "version": "1.1",
  1108. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAQJGBtf1btmdVNDtW%2BVUAg%3D",
  1109. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEAQJGBtf1btmdVNDtW%2BVUAg%3D HTTP/1.1\r\nCache-Control: max-age = 149079\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Sat, 23 Mar 2019 11:10:47 GMT\r\nIf-None-Match: \"5c961437-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
  1110. "port": 80
  1111. },
  1112. {
  1113. "count": 1,
  1114. "body": "",
  1115. "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAiIzVJfGSRETRSlgpHeuVI%3D",
  1116. "user-agent": "Microsoft-CryptoAPI/6.1",
  1117. "method": "GET",
  1118. "host": "ocsp.digicert.com",
  1119. "version": "1.1",
  1120. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAiIzVJfGSRETRSlgpHeuVI%3D",
  1121. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEAiIzVJfGSRETRSlgpHeuVI%3D HTTP/1.1\r\nCache-Control: max-age = 148251\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Sat, 16 Mar 2019 18:10:24 GMT\r\nIf-None-Match: \"5c8d3c10-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
  1122. "port": 80
  1123. },
  1124. {
  1125. "count": 1,
  1126. "body": "",
  1127. "uri": "http://ocsp.pki.goog/GTSGIAG3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCEH4PjD8bD0NfJXpoX0ln6s4%3D",
  1128. "user-agent": "Microsoft-CryptoAPI/6.1",
  1129. "method": "GET",
  1130. "host": "ocsp.pki.goog",
  1131. "version": "1.1",
  1132. "path": "/GTSGIAG3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCEH4PjD8bD0NfJXpoX0ln6s4%3D",
  1133. "data": "GET /GTSGIAG3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCEH4PjD8bD0NfJXpoX0ln6s4%3D HTTP/1.1\r\nCache-Control: max-age = 86400\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.pki.goog\r\n\r\n",
  1134. "port": 80
  1135. },
  1136. {
  1137. "count": 1,
  1138. "body": "",
  1139. "uri": "http://ocsp.pki.goog/GTSGIAG3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCEHQnb7Tt0tUhlRVnnq4nPN8%3D",
  1140. "user-agent": "Microsoft-CryptoAPI/6.1",
  1141. "method": "GET",
  1142. "host": "ocsp.pki.goog",
  1143. "version": "1.1",
  1144. "path": "/GTSGIAG3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCEHQnb7Tt0tUhlRVnnq4nPN8%3D",
  1145. "data": "GET /GTSGIAG3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCEHQnb7Tt0tUhlRVnnq4nPN8%3D HTTP/1.1\r\nCache-Control: max-age = 86400\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.pki.goog\r\n\r\n",
  1146. "port": 80
  1147. },
  1148. {
  1149. "count": 1,
  1150. "body": "",
  1151. "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnR4FoxLLkI7vkvsUIFlZt%2BlGH3gQUWsS5eyoKo6XqcQPAYPkt9mV1DlgCEAM%2B1e2gZdG4yR38%2BSpsm9g%3D",
  1152. "user-agent": "Microsoft-CryptoAPI/6.1",
  1153. "method": "GET",
  1154. "host": "ocsp.digicert.com",
  1155. "version": "1.1",
  1156. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnR4FoxLLkI7vkvsUIFlZt%2BlGH3gQUWsS5eyoKo6XqcQPAYPkt9mV1DlgCEAM%2B1e2gZdG4yR38%2BSpsm9g%3D",
  1157. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSnR4FoxLLkI7vkvsUIFlZt%2BlGH3gQUWsS5eyoKo6XqcQPAYPkt9mV1DlgCEAM%2B1e2gZdG4yR38%2BSpsm9g%3D HTTP/1.1\r\nCache-Control: max-age = 126990\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Sat, 23 Mar 2019 10:41:16 GMT\r\nIf-None-Match: \"5c960d4c-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
  1158. "port": 80
  1159. },
  1160. {
  1161. "count": 1,
  1162. "body": "",
  1163. "uri": "http://ocsp.pki.goog/GTSGIAG3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCEHAHFVlJElKyLEMbtWWDIbo%3D",
  1164. "user-agent": "Microsoft-CryptoAPI/6.1",
  1165. "method": "GET",
  1166. "host": "ocsp.pki.goog",
  1167. "version": "1.1",
  1168. "path": "/GTSGIAG3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCEHAHFVlJElKyLEMbtWWDIbo%3D",
  1169. "data": "GET /GTSGIAG3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT27bBjYjKBmjX2jXWgnQJKEapsrQQUd8K4UJpndnaxLcKG0IOgfqZ%2BuksCEHAHFVlJElKyLEMbtWWDIbo%3D HTTP/1.1\r\nCache-Control: max-age = 86400\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.pki.goog\r\n\r\n",
  1170. "port": 80
  1171. },
  1172. {
  1173. "count": 1,
  1174. "body": "",
  1175. "uri": "http://ocsp.msocsp.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPC1vZt9qvn7bzY3Iidtbhla4mKQQUWIif1tycSCK3FD7%2FhIjo5oX%2F%2Bn0CE3sAAGyvV14%2FmEPDgh0AAAAAbK8%3D",
  1176. "user-agent": "Microsoft-CryptoAPI/6.1",
  1177. "method": "GET",
  1178. "host": "ocsp.msocsp.com",
  1179. "version": "1.1",
  1180. "path": "/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPC1vZt9qvn7bzY3Iidtbhla4mKQQUWIif1tycSCK3FD7%2FhIjo5oX%2F%2Bn0CE3sAAGyvV14%2FmEPDgh0AAAAAbK8%3D",
  1181. "data": "GET /MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPC1vZt9qvn7bzY3Iidtbhla4mKQQUWIif1tycSCK3FD7%2FhIjo5oX%2F%2Bn0CE3sAAGyvV14%2FmEPDgh0AAAAAbK8%3D HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Sat, 23 Mar 2019 17:46:18 GMT\r\nIf-None-Match: \"dd54d75d4688b8dc62b087df4e04af258704c48b\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.msocsp.com\r\n\r\n",
  1182. "port": 80
  1183. },
  1184. {
  1185. "count": 1,
  1186. "body": "",
  1187. "uri": "http://ocsp.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS%2BzcBkvzl4%3D",
  1188. "user-agent": "Microsoft-CryptoAPI/6.1",
  1189. "method": "GET",
  1190. "host": "ocsp.thawte.com",
  1191. "version": "1.1",
  1192. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS%2BzcBkvzl4%3D",
  1193. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS%2BzcBkvzl4%3D HTTP/1.1\r\nCache-Control: max-age = 320712\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Wed, 20 Mar 2019 11:42:01 GMT\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.thawte.com\r\n\r\n",
  1194. "port": 80
  1195. },
  1196. {
  1197. "count": 1,
  1198. "body": "",
  1199. "uri": "http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCECdm7lbrSfOOq9dwovyE3iI%3D",
  1200. "user-agent": "Microsoft-CryptoAPI/6.1",
  1201. "method": "GET",
  1202. "host": "ocsp.usertrust.com",
  1203. "version": "1.1",
  1204. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCECdm7lbrSfOOq9dwovyE3iI%3D",
  1205. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCECdm7lbrSfOOq9dwovyE3iI%3D HTTP/1.1\r\nCache-Control: max-age = 94765\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Mon, 11 Mar 2019 04:19:13 GMT\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.usertrust.com\r\n\r\n",
  1206. "port": 80
  1207. },
  1208. {
  1209. "count": 1,
  1210. "body": "",
  1211. "uri": "http://th.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRsif7263KedmR2MLuYKv9%2BWQCtWAQU1A1lP3q9NMb%2BR%2BdMDcC98t4Vq3ECEBT4%2FdFn%2BSQCsVcLXcSVyBU%3D",
  1212. "user-agent": "Microsoft-CryptoAPI/6.1",
  1213. "method": "GET",
  1214. "host": "th.symcd.com",
  1215. "version": "1.1",
  1216. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRsif7263KedmR2MLuYKv9%2BWQCtWAQU1A1lP3q9NMb%2BR%2BdMDcC98t4Vq3ECEBT4%2FdFn%2BSQCsVcLXcSVyBU%3D",
  1217. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBRsif7263KedmR2MLuYKv9%2BWQCtWAQU1A1lP3q9NMb%2BR%2BdMDcC98t4Vq3ECEBT4%2FdFn%2BSQCsVcLXcSVyBU%3D HTTP/1.1\r\nCache-Control: max-age = 386377\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Thu, 21 Mar 2019 05:58:32 GMT\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: th.symcd.com\r\n\r\n",
  1218. "port": 80
  1219. },
  1220. {
  1221. "count": 1,
  1222. "body": "",
  1223. "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D",
  1224. "user-agent": "Microsoft-CryptoAPI/6.1",
  1225. "method": "GET",
  1226. "host": "ocsp.digicert.com",
  1227. "version": "1.1",
  1228. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D",
  1229. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D HTTP/1.1\r\nCache-Control: max-age = 142986\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Tue, 28 May 2019 07:40:28 GMT\r\nIf-None-Match: \"5cece5ec-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
  1230. "port": 80
  1231. },
  1232. {
  1233. "count": 1,
  1234. "body": "",
  1235. "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAVG%2Fhgj9%2BGUHaOfzhTEYXM%3D",
  1236. "user-agent": "Microsoft-CryptoAPI/6.1",
  1237. "method": "GET",
  1238. "host": "ocsp.digicert.com",
  1239. "version": "1.1",
  1240. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAVG%2Fhgj9%2BGUHaOfzhTEYXM%3D",
  1241. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAVG%2Fhgj9%2BGUHaOfzhTEYXM%3D HTTP/1.1\r\nCache-Control: max-age = 161796\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Tue, 28 May 2019 13:00:33 GMT\r\nIf-None-Match: \"5ced30f1-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
  1242. "port": 80
  1243. },
  1244. {
  1245. "count": 1,
  1246. "body": "",
  1247. "uri": "http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjqTAc%2FHIGOD%2BaUx0%3D",
  1248. "user-agent": "Microsoft-CryptoAPI/6.1",
  1249. "method": "GET",
  1250. "host": "ocsp.pki.goog",
  1251. "version": "1.1",
  1252. "path": "/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjqTAc%2FHIGOD%2BaUx0%3D",
  1253. "data": "GET /gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjqTAc%2FHIGOD%2BaUx0%3D HTTP/1.1\r\nCache-Control: max-age = 86400\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.pki.goog\r\n\r\n",
  1254. "port": 80
  1255. },
  1256. {
  1257. "count": 1,
  1258. "body": "",
  1259. "uri": "http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl",
  1260. "user-agent": "Microsoft-CryptoAPI/6.1",
  1261. "method": "GET",
  1262. "host": "crl.microsoft.com",
  1263. "version": "1.1",
  1264. "path": "/pki/crl/products/microsoftrootcert.crl",
  1265. "data": "GET /pki/crl/products/microsoftrootcert.crl HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Thu, 07 Mar 2019 06:00:16 GMT\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: crl.microsoft.com\r\n\r\n",
  1266. "port": 80
  1267. },
  1268. {
  1269. "count": 1,
  1270. "body": "",
  1271. "uri": "http://redirector.gvt1.com/edgedl/release2/chrome/ANcTHgjx95-y_74.0.3729.169/74.0.3729.169_73.0.3683.86_chrome_updater.exe",
  1272. "user-agent": "Microsoft BITS/7.5",
  1273. "method": "HEAD",
  1274. "host": "redirector.gvt1.com",
  1275. "version": "1.1",
  1276. "path": "/edgedl/release2/chrome/ANcTHgjx95-y_74.0.3729.169/74.0.3729.169_73.0.3683.86_chrome_updater.exe",
  1277. "data": "HEAD /edgedl/release2/chrome/ANcTHgjx95-y_74.0.3729.169/74.0.3729.169_73.0.3683.86_chrome_updater.exe HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nAccept-Encoding: identity\r\nUser-Agent: Microsoft BITS/7.5\r\nX-Old-UID: cnt=0\r\nX-Last-HR: 0x0\r\nX-Last-HTTP-Status-Code: 0\r\nX-Retry-Count: 0\r\nX-HTTP-Attempts: 1\r\nHost: redirector.gvt1.com\r\n\r\n",
  1278. "port": 80
  1279. },
  1280. {
  1281. "count": 1,
  1282. "body": "",
  1283. "uri": "http://r4---sn-tt1e7n7k.gvt1.com/edgedl/release2/chrome/ANcTHgjx95-y_74.0.3729.169/74.0.3729.169_73.0.3683.86_chrome_updater.exe?cms_redirect=yes&mip=172.98.67.13&mm=28&mn=sn-tt1e7n7k&ms=nvh&mt=1560995678&mv=m&pl=24&shardbypass=yes",
  1284. "user-agent": "Microsoft BITS/7.5",
  1285. "method": "HEAD",
  1286. "host": "r4---sn-tt1e7n7k.gvt1.com",
  1287. "version": "1.1",
  1288. "path": "/edgedl/release2/chrome/ANcTHgjx95-y_74.0.3729.169/74.0.3729.169_73.0.3683.86_chrome_updater.exe?cms_redirect=yes&mip=172.98.67.13&mm=28&mn=sn-tt1e7n7k&ms=nvh&mt=1560995678&mv=m&pl=24&shardbypass=yes",
  1289. "data": "HEAD /edgedl/release2/chrome/ANcTHgjx95-y_74.0.3729.169/74.0.3729.169_73.0.3683.86_chrome_updater.exe?cms_redirect=yes&mip=172.98.67.13&mm=28&mn=sn-tt1e7n7k&ms=nvh&mt=1560995678&mv=m&pl=24&shardbypass=yes HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nAccept-Encoding: identity\r\nUser-Agent: Microsoft BITS/7.5\r\nX-Old-UID: cnt=0\r\nX-Last-HR: 0x0\r\nX-Last-HTTP-Status-Code: 0\r\nX-Retry-Count: 0\r\nX-HTTP-Attempts: 1\r\nHost: r4---sn-tt1e7n7k.gvt1.com\r\n\r\n",
  1290. "port": 80
  1291. },
  1292. {
  1293. "count": 1,
  1294. "body": "",
  1295. "uri": "http://r4---sn-tt1e7n7k.gvt1.com/edgedl/release2/chrome/ANcTHgjx95-y_74.0.3729.169/74.0.3729.169_73.0.3683.86_chrome_updater.exe?cms_redirect=yes&mip=172.98.67.13&mm=28&mn=sn-tt1e7n7k&ms=nvh&mt=1560995678&mv=m&pl=24&shardbypass=yes",
  1296. "user-agent": "Microsoft BITS/7.5",
  1297. "method": "GET",
  1298. "host": "r4---sn-tt1e7n7k.gvt1.com",
  1299. "version": "1.1",
  1300. "path": "/edgedl/release2/chrome/ANcTHgjx95-y_74.0.3729.169/74.0.3729.169_73.0.3683.86_chrome_updater.exe?cms_redirect=yes&mip=172.98.67.13&mm=28&mn=sn-tt1e7n7k&ms=nvh&mt=1560995678&mv=m&pl=24&shardbypass=yes",
  1301. "data": "GET /edgedl/release2/chrome/ANcTHgjx95-y_74.0.3729.169/74.0.3729.169_73.0.3683.86_chrome_updater.exe?cms_redirect=yes&mip=172.98.67.13&mm=28&mn=sn-tt1e7n7k&ms=nvh&mt=1560995678&mv=m&pl=24&shardbypass=yes HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nAccept-Encoding: identity\r\nIf-Unmodified-Since: Tue, 21 May 2019 04:56:27 GMT\r\nRange: bytes=0-7458\r\nUser-Agent: Microsoft BITS/7.5\r\nX-Old-UID: cnt=0\r\nX-Last-HR: 0x0\r\nX-Last-HTTP-Status-Code: 0\r\nX-Retry-Count: 0\r\nX-HTTP-Attempts: 1\r\nHost: r4---sn-tt1e7n7k.gvt1.com\r\n\r\n",
  1302. "port": 80
  1303. }
  1304. ]
  1305.  
  1306. [*] Network Communication - SMTP: []
  1307.  
  1308. [*] Network Communication - Hosts: []
  1309.  
  1310. [*] Network Communication - IRC: []
  1311.  
  1312. [*] Static Analysis: {
  1313. "pe": {
  1314. "peid_signatures": [
  1315. [
  1316. "Upack V0.37 -> Dwing"
  1317. ],
  1318. [
  1319. "Upack_Patch or any Version -> Dwing"
  1320. ],
  1321. [
  1322. "WinUpack v0.39 final (relocated image base) -> By Dwing (c)2005 (h2)"
  1323. ]
  1324. ],
  1325. "imports": [
  1326. {
  1327. "imports": [
  1328. {
  1329. "name": "LoadLibraryA",
  1330. "address": "0xbaef25"
  1331. },
  1332. {
  1333. "name": "GetProcAddress",
  1334. "address": "0xbaef29"
  1335. }
  1336. ],
  1337. "dll": "KERNEL32.DLL"
  1338. }
  1339. ],
  1340. "digital_signers": null,
  1341. "exported_dll_name": null,
  1342. "actual_checksum": "0x0024138a",
  1343. "overlay": null,
  1344. "imagebase": "0x00400000",
  1345. "reported_checksum": "0x00000000",
  1346. "icon_hash": null,
  1347. "entrypoint": "0x00baec61",
  1348. "timestamp": "1970-01-01 01:08:16",
  1349. "osversion": "4.0",
  1350. "sections": [
  1351. {
  1352. "name": ".Upack",
  1353. "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  1354. "virtual_address": "0x00001000",
  1355. "size_of_data": "0x00000000",
  1356. "entropy": "0.00",
  1357. "raw_address": "0x00000000",
  1358. "virtual_size": "0x0056d000",
  1359. "characteristics_raw": "0xe0000060"
  1360. },
  1361. {
  1362. "name": ".rsrc",
  1363. "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  1364. "virtual_address": "0x0056e000",
  1365. "size_of_data": "0x00240f55",
  1366. "entropy": "8.00",
  1367. "raw_address": "0x00000200",
  1368. "virtual_size": "0x00248000",
  1369. "characteristics_raw": "0xe0000060"
  1370. }
  1371. ],
  1372. "resources": [
  1373. {
  1374. "name": "RT_BITMAP",
  1375. "language": "LANG_NEUTRAL",
  1376. "filetype": null,
  1377. "sublanguage": "SUBLANG_NEUTRAL",
  1378. "entropy": "0.00",
  1379. "offset": "0x0000f064",
  1380. "size": "0x0055d483"
  1381. }
  1382. ],
  1383. "dirents": [
  1384. {
  1385. "virtual_address": "0x00000000",
  1386. "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
  1387. "size": "0x00000000"
  1388. },
  1389. {
  1390. "virtual_address": "0x007aef2d",
  1391. "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
  1392. "size": "0x00000014"
  1393. },
  1394. {
  1395. "virtual_address": "0x0056e000",
  1396. "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
  1397. "size": "0x00000062"
  1398. },
  1399. {
  1400. "virtual_address": "0x00000000",
  1401. "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
  1402. "size": "0x00000000"
  1403. },
  1404. {
  1405. "virtual_address": "0x00000000",
  1406. "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
  1407. "size": "0x00000000"
  1408. },
  1409. {
  1410. "virtual_address": "0x00000048",
  1411. "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
  1412. "size": "0x00000008"
  1413. },
  1414. {
  1415. "virtual_address": "0x00000000",
  1416. "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
  1417. "size": "0x00000000"
  1418. },
  1419. {
  1420. "virtual_address": "0x00000000",
  1421. "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
  1422. "size": "0x00000000"
  1423. },
  1424. {
  1425. "virtual_address": "0x00000000",
  1426. "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
  1427. "size": "0x00000000"
  1428. },
  1429. {
  1430. "virtual_address": "0x007aef0d",
  1431. "name": "IMAGE_DIRECTORY_ENTRY_TLS",
  1432. "size": "0x00000018"
  1433. },
  1434. {
  1435. "virtual_address": "0x00000000",
  1436. "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
  1437. "size": "0x00000000"
  1438. },
  1439. {
  1440. "virtual_address": "0x00000000",
  1441. "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
  1442. "size": "0x00000000"
  1443. },
  1444. {
  1445. "virtual_address": "0x00000000",
  1446. "name": "IMAGE_DIRECTORY_ENTRY_IAT",
  1447. "size": "0x00000000"
  1448. },
  1449. {
  1450. "virtual_address": "0x00000000",
  1451. "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
  1452. "size": "0x00000000"
  1453. },
  1454. {
  1455. "virtual_address": "0x00000000",
  1456. "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
  1457. "size": "0x00000000"
  1458. },
  1459. {
  1460. "virtual_address": "0x00000000",
  1461. "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
  1462. "size": "0x00000000"
  1463. }
  1464. ],
  1465. "exports": [],
  1466. "guest_signers": {},
  1467. "imphash": "87bed5a7cba00c7e1f4015f1bdae2183",
  1468. "icon_fuzzy": null,
  1469. "icon": null,
  1470. "pdbpath": null,
  1471. "imported_dll_count": 1,
  1472. "versioninfo": []
  1473. }
  1474. }
  1475.  
  1476. [*] Resolved APIs: [
  1477. "user32.dll.MessageBoxA",
  1478. "kernel32.dll.Sleep",
  1479. "kernel32.dll.VirtualFree",
  1480. "kernel32.dll.VirtualAlloc",
  1481. "kernel32.dll.VirtualQuery",
  1482. "kernel32.dll.GetSystemInfo",
  1483. "kernel32.dll.GetVersion",
  1484. "kernel32.dll.SetThreadLocale",
  1485. "kernel32.dll.GetACP",
  1486. "kernel32.dll.GetStartupInfoW",
  1487. "kernel32.dll.GetProcAddress",
  1488. "kernel32.dll.GetModuleHandleW",
  1489. "kernel32.dll.GetCommandLineW",
  1490. "kernel32.dll.FreeLibrary",
  1491. "kernel32.dll.UnhandledExceptionFilter",
  1492. "kernel32.dll.RtlUnwind",
  1493. "kernel32.dll.RaiseException",
  1494. "kernel32.dll.ExitProcess",
  1495. "kernel32.dll.GetCurrentThreadId",
  1496. "kernel32.dll.DeleteCriticalSection",
  1497. "kernel32.dll.InitializeCriticalSection",
  1498. "kernel32.dll.WriteFile",
  1499. "kernel32.dll.GetStdHandle",
  1500. "kernel32.dll.CloseHandle",
  1501. "kernel32.dll.LoadLibraryA",
  1502. "kernel32.dll.GetLastError",
  1503. "kernel32.dll.TlsSetValue",
  1504. "kernel32.dll.TlsGetValue",
  1505. "kernel32.dll.LocalFree",
  1506. "kernel32.dll.LocalAlloc",
  1507. "kernel32.dll.VirtualProtect",
  1508. "kernel32.dll.SizeofResource",
  1509. "kernel32.dll.LockResource",
  1510. "kernel32.dll.LoadResource",
  1511. "kernel32.dll.GetVersionExW",
  1512. "kernel32.dll.FindResourceW",
  1513. "kernel32.dll.GetThreadPreferredUILanguages",
  1514. "kernel32.dll.SetThreadPreferredUILanguages",
  1515. "kernel32.dll.GetThreadUILanguage",
  1516. "kernel32.dll.#829",
  1517. "kernel32.dll.#693",
  1518. "kernel32.dll.#700",
  1519. "kernel32.dll.#760",
  1520. "kernel32.dll.#763",
  1521. "kernel32.dll.#1112",
  1522. "kernel32.dll.#1358",
  1523. "kernel32.dll.#1359",
  1524. "kernel32.dll.#871",
  1525. "kernel32.dll.#283",
  1526. "kernel32.dll.#84",
  1527. "kernel32.dll.#145",
  1528. "kernel32.dll.#1318",
  1529. "kernel32.dll.#1129",
  1530. "kernel32.dll.#532",
  1531. "kernel32.dll.#216",
  1532. "kernel32.dll.#131",
  1533. "kernel32.dll.#449",
  1534. "kernel32.dll.#625",
  1535. "kernel32.dll.#688",
  1536. "kernel32.dll.#644",
  1537. "kernel32.dll.#646",
  1538. "user32.dll.#2039",
  1539. "user32.dll.#2046",
  1540. "user32.dll.#2332",
  1541. "shell32.dll.#437",
  1542. "kernel32.dll.SortGetHandle",
  1543. "kernel32.dll.SortCloseHandle",
  1544. "setupapi.dll.CM_Get_Device_Interface_List_Size_ExW",
  1545. "setupapi.dll.CM_Get_Device_Interface_List_ExW",
  1546. "comctl32.dll.#386",
  1547. "advapi32.dll.UnregisterTraceGuids",
  1548. "comctl32.dll.#321",
  1549. "kernel32.dll.GetModuleHandleA",
  1550. "kernel32.dll.HeapCreate",
  1551. "kernel32.dll.GetCommandLineA",
  1552. "kernel32.dll.RemoveDirectoryA",
  1553. "kernel32.dll.GetTempFileNameA",
  1554. "kernel32.dll.GetShortPathNameA",
  1555. "kernel32.dll.GetWindowsDirectoryA",
  1556. "kernel32.dll.GetSystemDirectoryA",
  1557. "kernel32.dll.HeapDestroy",
  1558. "kernel32.dll.GetExitCodeProcess",
  1559. "kernel32.dll.GetNativeSystemInfo",
  1560. "kernel32.dll.FindResourceA",
  1561. "kernel32.dll.HeapAlloc",
  1562. "kernel32.dll.HeapFree",
  1563. "kernel32.dll.GetCurrentProcessId",
  1564. "kernel32.dll.GetModuleFileNameA",
  1565. "kernel32.dll.GetEnvironmentVariableA",
  1566. "kernel32.dll.SetEnvironmentVariableA",
  1567. "kernel32.dll.GetCurrentProcess",
  1568. "kernel32.dll.TerminateProcess",
  1569. "kernel32.dll.SetUnhandledExceptionFilter",
  1570. "kernel32.dll.EnterCriticalSection",
  1571. "kernel32.dll.LeaveCriticalSection",
  1572. "kernel32.dll.GetVersionExA",
  1573. "kernel32.dll.HeapReAlloc",
  1574. "kernel32.dll.SetLastError",
  1575. "kernel32.dll.TlsAlloc",
  1576. "kernel32.dll.GetCurrentDirectoryA",
  1577. "kernel32.dll.SetCurrentDirectoryA",
  1578. "kernel32.dll.GetTempPathA",
  1579. "kernel32.dll.SetFileAttributesA",
  1580. "kernel32.dll.DeleteFileA",
  1581. "kernel32.dll.CreateDirectoryA",
  1582. "kernel32.dll.CreateFileA",
  1583. "kernel32.dll.SetFilePointer",
  1584. "kernel32.dll.ReadFile",
  1585. "comctl32.dll.InitCommonControlsEx",
  1586. "gdi32.dll.GetStockObject",
  1587. "gdi32.dll.SelectObject",
  1588. "gdi32.dll.SetBkColor",
  1589. "gdi32.dll.SetTextColor",
  1590. "gdi32.dll.GetTextExtentPoint32A",
  1591. "gdi32.dll.CreateSolidBrush",
  1592. "gdi32.dll.DeleteObject",
  1593. "gdi32.dll.GetObjectA",
  1594. "gdi32.dll.CreateCompatibleDC",
  1595. "gdi32.dll.GetDIBits",
  1596. "gdi32.dll.DeleteDC",
  1597. "gdi32.dll.GetObjectType",
  1598. "gdi32.dll.CreateDIBSection",
  1599. "gdi32.dll.BitBlt",
  1600. "gdi32.dll.CreateBitmap",
  1601. "gdi32.dll.SetPixel",
  1602. "msvcrt.dll.memset",
  1603. "msvcrt.dll.strncmp",
  1604. "msvcrt.dll.memmove",
  1605. "msvcrt.dll.strncpy",
  1606. "msvcrt.dll.strstr",
  1607. "msvcrt.dll._strnicmp",
  1608. "msvcrt.dll._stricmp",
  1609. "msvcrt.dll.strlen",
  1610. "msvcrt.dll.strcmp",
  1611. "msvcrt.dll.sprintf",
  1612. "msvcrt.dll.fabs",
  1613. "msvcrt.dll.ceil",
  1614. "msvcrt.dll.malloc",
  1615. "msvcrt.dll.floor",
  1616. "msvcrt.dll.free",
  1617. "msvcrt.dll.fclose",
  1618. "msvcrt.dll.memcpy",
  1619. "msvcrt.dll.strcpy",
  1620. "msvcrt.dll.tolower",
  1621. "ole32.dll.CoInitialize",
  1622. "ole32.dll.CoTaskMemFree",
  1623. "ole32.dll.RevokeDragDrop",
  1624. "shell32.dll.ShellExecuteExA",
  1625. "shlwapi.dll.PathQuoteSpacesA",
  1626. "shlwapi.dll.PathGetArgsA",
  1627. "shlwapi.dll.PathAddBackslashA",
  1628. "shlwapi.dll.PathRenameExtensionA",
  1629. "shlwapi.dll.PathUnquoteSpacesA",
  1630. "user32.dll.CharLowerA",
  1631. "user32.dll.SendMessageA",
  1632. "user32.dll.PostMessageA",
  1633. "user32.dll.GetWindowThreadProcessId",
  1634. "user32.dll.IsWindowVisible",
  1635. "user32.dll.GetWindowLongA",
  1636. "user32.dll.GetForegroundWindow",
  1637. "user32.dll.IsWindowEnabled",
  1638. "user32.dll.EnableWindow",
  1639. "user32.dll.EnumWindows",
  1640. "user32.dll.SetWindowPos",
  1641. "user32.dll.DestroyWindow",
  1642. "user32.dll.GetDC",
  1643. "user32.dll.GetWindowTextLengthA",
  1644. "user32.dll.GetWindowTextA",
  1645. "user32.dll.SetRect",
  1646. "user32.dll.DrawTextA",
  1647. "user32.dll.GetSystemMetrics",
  1648. "user32.dll.ReleaseDC",
  1649. "user32.dll.GetSysColor",
  1650. "user32.dll.GetSysColorBrush",
  1651. "user32.dll.CreateWindowExA",
  1652. "user32.dll.CallWindowProcA",
  1653. "user32.dll.SetWindowLongA",
  1654. "user32.dll.SetFocus",
  1655. "user32.dll.RedrawWindow",
  1656. "user32.dll.RemovePropA",
  1657. "user32.dll.DefWindowProcA",
  1658. "user32.dll.SetPropA",
  1659. "user32.dll.GetParent",
  1660. "user32.dll.GetPropA",
  1661. "user32.dll.GetWindow",
  1662. "user32.dll.SetActiveWindow",
  1663. "user32.dll.UnregisterClassA",
  1664. "user32.dll.DestroyAcceleratorTable",
  1665. "user32.dll.LoadIconA",
  1666. "user32.dll.LoadCursorA",
  1667. "user32.dll.RegisterClassA",
  1668. "user32.dll.AdjustWindowRectEx",
  1669. "user32.dll.ShowWindow",
  1670. "user32.dll.CreateAcceleratorTableA",
  1671. "user32.dll.PeekMessageA",
  1672. "user32.dll.MsgWaitForMultipleObjects",
  1673. "user32.dll.GetMessageA",
  1674. "user32.dll.GetActiveWindow",
  1675. "user32.dll.TranslateAcceleratorA",
  1676. "user32.dll.TranslateMessage",
  1677. "user32.dll.DispatchMessageA",
  1678. "user32.dll.GetFocus",
  1679. "user32.dll.GetClientRect",
  1680. "user32.dll.FillRect",
  1681. "user32.dll.EnumChildWindows",
  1682. "user32.dll.DefFrameProcA",
  1683. "user32.dll.GetWindowRect",
  1684. "user32.dll.IsChild",
  1685. "user32.dll.GetClassNameA",
  1686. "user32.dll.GetKeyState",
  1687. "user32.dll.DestroyIcon",
  1688. "user32.dll.RegisterWindowMessageA",
  1689. "winmm.dll.timeBeginPeriod",
  1690. "uxtheme.dll.ThemeInitApiHook",
  1691. "user32.dll.IsProcessDPIAware",
  1692. "dwmapi.dll.DwmIsCompositionEnabled",
  1693. "kernel32.dll.InitOnceExecuteOnce",
  1694. "msimg32.dll.AlphaBlend",
  1695. "comctl32.dll.DllGetVersion",
  1696. "uxtheme.dll.IsAppThemed",
  1697. "cryptbase.dll.SystemFunction036",
  1698. "kernel32.dll.GetLongPathNameA",
  1699. "ole32.dll.OleInitialize",
  1700. "ole32.dll.CreateBindCtx",
  1701. "ole32.dll.CoTaskMemAlloc",
  1702. "propsys.dll.PSCreateMemoryPropertyStore",
  1703. "propsys.dll.PSPropertyBag_WriteDWORD",
  1704. "ole32.dll.CoGetApartmentType",
  1705. "ole32.dll.CoRegisterInitializeSpy",
  1706. "comctl32.dll.#236",
  1707. "oleaut32.dll.#6",
  1708. "ole32.dll.CoGetMalloc",
  1709. "propsys.dll.PSPropertyBag_ReadDWORD",
  1710. "comctl32.dll.#320",
  1711. "ole32.dll.StringFromGUID2",
  1712. "comctl32.dll.#324",
  1713. "comctl32.dll.#323",
  1714. "advapi32.dll.RegEnumKeyW",
  1715. "oleaut32.dll.#2",
  1716. "propsys.dll.PSPropertyBag_ReadBSTR",
  1717. "propsys.dll.PSPropertyBag_ReadStrAlloc",
  1718. "shell32.dll.#102",
  1719. "advapi32.dll.OpenThreadToken",
  1720. "ole32.dll.CoInitializeEx",
  1721. "ole32.dll.CoCreateInstance",
  1722. "advapi32.dll.InitializeSecurityDescriptor",
  1723. "advapi32.dll.SetEntriesInAclW",
  1724. "ntmarta.dll.GetMartaExtensionInterface",
  1725. "advapi32.dll.SetSecurityDescriptorDacl",
  1726. "advapi32.dll.IsTextUnicode",
  1727. "comctl32.dll.#328",
  1728. "comctl32.dll.#334",
  1729. "comctl32.dll.#332",
  1730. "comctl32.dll.#338",
  1731. "ole32.dll.CoUninitialize",
  1732. "sechost.dll.ConvertSidToStringSidW",
  1733. "profapi.dll.#104",
  1734. "propsys.dll.#430",
  1735. "advapi32.dll.RegOpenKeyExW",
  1736. "advapi32.dll.RegGetValueW",
  1737. "advapi32.dll.RegCloseKey",
  1738. "ole32.dll.CoTaskMemRealloc",
  1739. "propsys.dll.InitPropVariantFromStringAsVector",
  1740. "propsys.dll.PSCoerceToCanonicalValue",
  1741. "propsys.dll.PropVariantToStringAlloc",
  1742. "ole32.dll.PropVariantClear",
  1743. "ole32.dll.CoAllowSetForegroundWindow",
  1744. "kernel32.dll.InitializeSRWLock",
  1745. "kernel32.dll.AcquireSRWLockExclusive",
  1746. "kernel32.dll.AcquireSRWLockShared",
  1747. "kernel32.dll.ReleaseSRWLockExclusive",
  1748. "kernel32.dll.ReleaseSRWLockShared",
  1749. "shell32.dll.SHGetFolderPathW",
  1750. "advapi32.dll.SaferGetPolicyInformation",
  1751. "sfc.dll.SfcIsFileProtected",
  1752. "setupapi.dll.PnpIsFilePnpDriver",
  1753. "kernel32.dll.RegOpenKeyExW",
  1754. "kernel32.dll.RegCloseKey",
  1755. "devrtl.dll.DevRtlGetThreadLogToken",
  1756. "ntdll.dll.RtlDllShutdownInProgress",
  1757. "comctl32.dll.#329",
  1758. "ole32.dll.OleUninitialize",
  1759. "ole32.dll.CoRevokeInitializeSpy",
  1760. "comctl32.dll.#388",
  1761. "oleaut32.dll.#500",
  1762. "kernel32.dll.SetThreadUILanguage",
  1763. "kernel32.dll.CopyFileExW",
  1764. "kernel32.dll.IsDebuggerPresent",
  1765. "kernel32.dll.SetConsoleInputExeNameW",
  1766. "advapi32.dll.SaferIdentifyLevel",
  1767. "advapi32.dll.SaferComputeTokenFromLevel",
  1768. "advapi32.dll.SaferCloseLevel",
  1769. "rpcrt4.dll.I_RpcSNCHOption",
  1770. "sechost.dll.OpenSCManagerW",
  1771. "sechost.dll.OpenServiceW",
  1772. "sechost.dll.CloseServiceHandle",
  1773. "kernel32.dll.FlsAlloc",
  1774. "kernel32.dll.FlsGetValue",
  1775. "kernel32.dll.FlsSetValue",
  1776. "kernel32.dll.FlsFree",
  1777. "kernel32.dll.AttachConsole",
  1778. "kernel32.dll.SleepConditionVariableCS",
  1779. "kernel32.dll.WakeConditionVariable",
  1780. "advapi32.dll.CreateWellKnownSid",
  1781. "advapi32.dll.IsWellKnownSid",
  1782. "cryptbase.dll.SystemFunction028",
  1783. "rpcrt4.dll.NDRCContextBinding",
  1784. "rpcrt4.dll.RpcBindingToStringBindingW",
  1785. "rpcrt4.dll.I_RpcMapWin32Status",
  1786. "rpcrt4.dll.RpcStringBindingParseW",
  1787. "rpcrt4.dll.RpcStringFreeW",
  1788. "cryptbase.dll.SystemFunction004",
  1789. "mswsock.dll.WSPStartup",
  1790. "wshtcpip.dll.WSHOpenSocket",
  1791. "wshtcpip.dll.WSHOpenSocket2",
  1792. "wshtcpip.dll.WSHJoinLeaf",
  1793. "wshtcpip.dll.WSHNotify",
  1794. "wshtcpip.dll.WSHGetSocketInformation",
  1795. "wshtcpip.dll.WSHSetSocketInformation",
  1796. "wshtcpip.dll.WSHGetSockaddrType",
  1797. "wshtcpip.dll.WSHGetWildcardSockaddr",
  1798. "wshtcpip.dll.WSHGetBroadcastSockaddr",
  1799. "wshtcpip.dll.WSHAddressToString",
  1800. "wshtcpip.dll.WSHStringToAddress",
  1801. "wshtcpip.dll.WSHIoctl",
  1802. "sechost.dll.LookupAccountNameLocalW",
  1803. "advapi32.dll.LookupAccountSidW",
  1804. "sechost.dll.LookupAccountSidLocalW",
  1805. "winsta.dll.WinStationFreeMemory",
  1806. "winsta.dll.WinStationCloseServer",
  1807. "winsta.dll.WinStationOpenServerW",
  1808. "winsta.dll.WinStationFreeGAPMemory",
  1809. "winsta.dll.WinStationGetAllProcesses",
  1810. "winsta.dll.WinStationEnumerateProcesses",
  1811. "kernel32.dll.LocaleNameToLCID",
  1812. "kernel32.dll.GetLocaleInfoEx",
  1813. "kernel32.dll.LCIDToLocaleName",
  1814. "kernel32.dll.GetSystemDefaultLocaleName",
  1815. "fastprox.dll.DllGetClassObject",
  1816. "fastprox.dll.DllCanUnloadNow",
  1817. "oleaut32.dll.#283",
  1818. "oleaut32.dll.#284",
  1819. "ntdll.dll.EtwUnregisterTraceGuids",
  1820. "cryptsp.dll.CryptReleaseContext",
  1821. "sechost.dll.ControlService",
  1822. "sechost.dll.StartServiceW",
  1823. "version.dll.GetFileVersionInfoSizeW",
  1824. "version.dll.GetFileVersionInfoW",
  1825. "version.dll.VerQueryValueW",
  1826. "sspicli.dll.GetUserNameExW",
  1827. "advapi32.dll.GetUserNameW",
  1828. "xmllite.dll.CreateXmlWriter",
  1829. "xmllite.dll.CreateXmlWriterOutputWithEncodingName",
  1830. "ncrypt.dll.SslDecrementProviderReferenceCount",
  1831. "ncrypt.dll.SslFreeObject",
  1832. "bcryptprimitives.dll.GetHashInterface",
  1833. "propsys.dll.PropVariantToVariant",
  1834. "ole32.dll.CoRevokeClassObject",
  1835. "ole32.dll.CoDisconnectContext",
  1836. "ws2_32.dll.#3",
  1837. "bitsigd.dll.UninitializeEx",
  1838. "ws2_32.dll.#116",
  1839. "kernel32.dll.RegQueryValueExW",
  1840. "oleaut32.dll.#289",
  1841. "advapi32.dll.RegOpenKeyW",
  1842. "oleaut32.dll.#287",
  1843. "oleaut32.dll.#288",
  1844. "oleaut32.dll.#290",
  1845. "oleaut32.dll.#285",
  1846. "ntdll.dll.RtlInitUnicodeString",
  1847. "ntdll.dll.RtlFreeUnicodeString",
  1848. "ntdll.dll.NtSetSystemEnvironmentValue",
  1849. "ntdll.dll.NtQuerySystemEnvironmentValue",
  1850. "ntdll.dll.NtCreateFile",
  1851. "ntdll.dll.NtQuerySystemInformation",
  1852. "ntdll.dll.NtQueryDirectoryObject",
  1853. "ntdll.dll.NtQueryObject",
  1854. "ntdll.dll.NtOpenDirectoryObject",
  1855. "ntdll.dll.NtQueryInformationProcess",
  1856. "ntdll.dll.NtQueryInformationToken",
  1857. "ntdll.dll.NtOpenFile",
  1858. "ntdll.dll.NtClose",
  1859. "ntdll.dll.NtFsControlFile",
  1860. "ntdll.dll.NtQueryVolumeInformationFile",
  1861. "advapi32.dll.LookupPrivilegeValueW",
  1862. "winbrand.dll.BrandingLoadString",
  1863. "oleaut32.dll.#286",
  1864. "ole32.dll.StringFromCLSID",
  1865. "oleaut32.dll.#9",
  1866. "sechost.dll.QueryServiceStatus",
  1867. "urlmon.dll.DllCanUnloadNow",
  1868. "urlmon.dll.IEDllLoader",
  1869. "urlmon.dll.CoInternetCreateZoneManager",
  1870. "urlmon.dll.CoInternetGetSession",
  1871. "urlmon.dll.CopyBindInfo",
  1872. "urlmon.dll.CreateURLMoniker",
  1873. "urlmon.dll.RegisterBindStatusCallback",
  1874. "urlmon.dll.ReleaseBindInfo",
  1875. "urlmon.dll.RevokeBindStatusCallback",
  1876. "urlmon.dll.UrlMkGetSessionOption",
  1877. "urlmon.dll.CoInternetCreateSecurityManager",
  1878. "urlmon.dll.CreateUri",
  1879. "urlmon.dll.CoInternetCombineUrl",
  1880. "urlmon.dll.CoInternetGetSecurityUrl",
  1881. "urlmon.dll.IsValidURL",
  1882. "wininet.dll.InternetCrackUrlW",
  1883. "wininet.dll.InternetCreateUrlW",
  1884. "ole32.dll.CoGetClassObject",
  1885. "ole32.dll.CoGetMarshalSizeMax",
  1886. "ole32.dll.CoMarshalInterface",
  1887. "ole32.dll.CoUnmarshalInterface",
  1888. "ole32.dll.StringFromIID",
  1889. "ole32.dll.CoGetPSClsid",
  1890. "ole32.dll.CoReleaseMarshalData",
  1891. "ole32.dll.DcomChannelSetHResult",
  1892. "msoxmlmf.dll.DllGetClassObject",
  1893. "msoxmlmf.dll.DllCanUnloadNow",
  1894. "lpk.dll.LpkEditControl",
  1895. "kernel32.dll.HeapSetInformation",
  1896. "advapi32.dll.CheckTokenMembership",
  1897. "kernel32.dll.GetSystemWindowsDirectoryW",
  1898. "ole32.dll.CoInitializeSecurity",
  1899. "kernel32.dll.CreateWaitableTimerW",
  1900. "kernel32.dll.SetWaitableTimer",
  1901. "ole32.dll.CLSIDFromOle1Class",
  1902. "clbcatq.dll.GetCatalogObject",
  1903. "clbcatq.dll.GetCatalogObject2",
  1904. "cryptsp.dll.CryptAcquireContextW",
  1905. "cryptsp.dll.CryptGenRandom",
  1906. "ole32.dll.NdrOleInitializeExtension",
  1907. "rpcrtremote.dll.I_RpcExtInitializeExtensionPoint",
  1908. "msi.dll.QueryInstanceCount",
  1909. "kernel32.dll.CancelWaitableTimer",
  1910. "msi.dll.DllGetClassObject",
  1911. "msi.dll.DllCanUnloadNow",
  1912. "ole32.dll.CoGetCallContext",
  1913. "rpcrt4.dll.I_RpcBindingInqLocalClientPID",
  1914. "userenv.dll.CreateEnvironmentBlock",
  1915. "userenv.dll.DestroyEnvironmentBlock",
  1916. "ntdll.dll.WinSqmIsOptedIn",
  1917. "kernel32.dll.WTSGetActiveConsoleSessionId",
  1918. "netapi32.dll.NetGetJoinInformation",
  1919. "netapi32.dll.NetApiBufferFree",
  1920. "shlwapi.dll.UrlIsW",
  1921. "ole32.dll.StgOpenStorage",
  1922. "kernel32.dll.GetFileAttributesExW",
  1923. "advapi32.dll.SaferCreateLevel",
  1924. "apphelp.dll.SdbInitDatabase",
  1925. "apphelp.dll.SdbFindFirstMsiPackage_Str",
  1926. "apphelp.dll.SdbReleaseDatabase",
  1927. "mscoree.dll.GetCORSystemDirectory",
  1928. "advapi32.dll.RegQueryInfoKeyW",
  1929. "advapi32.dll.RegEnumKeyExW",
  1930. "advapi32.dll.RegEnumValueW",
  1931. "advapi32.dll.RegQueryValueExW",
  1932. "kernel32.dll.SetThreadExecutionState",
  1933. "sfc.dll.SfcIsKeyProtected",
  1934. "advapi32.dll.SetThreadToken",
  1935. "rpcrt4.dll.NdrAsyncClientCall",
  1936. "rpcrt4.dll.RpcAsyncCompleteCall",
  1937. "ws2_32.dll.GetAddrInfoW",
  1938. "ws2_32.dll.WSASocketW",
  1939. "ws2_32.dll.#2",
  1940. "ws2_32.dll.#21",
  1941. "ws2_32.dll.#9",
  1942. "ws2_32.dll.WSAIoctl",
  1943. "ws2_32.dll.FreeAddrInfoW",
  1944. "ws2_32.dll.#6",
  1945. "ws2_32.dll.#5",
  1946. "schannel.dll.SpUserModeInitialize",
  1947. "advapi32.dll.RegCreateKeyExW",
  1948. "ws2_32.dll.WSASend",
  1949. "ws2_32.dll.WSARecv",
  1950. "advapi32.dll.RevertToSelf",
  1951. "secur32.dll.FreeContextBuffer",
  1952. "ncrypt.dll.SslOpenProvider",
  1953. "ncrypt.dll.GetSChannelInterface",
  1954. "ncrypt.dll.SslIncrementProviderReferenceCount",
  1955. "ncrypt.dll.SslImportKey",
  1956. "bcryptprimitives.dll.GetCipherInterface",
  1957. "ncrypt.dll.SslLookupCipherSuiteInfo",
  1958. "user32.dll.LoadStringW",
  1959. "ncrypt.dll.BCryptOpenAlgorithmProvider",
  1960. "ncrypt.dll.BCryptGetProperty",
  1961. "ncrypt.dll.BCryptCreateHash",
  1962. "ncrypt.dll.BCryptHashData",
  1963. "ncrypt.dll.BCryptFinishHash",
  1964. "ncrypt.dll.BCryptDestroyHash",
  1965. "crypt32.dll.CertGetCertificateChain",
  1966. "userenv.dll.GetUserProfileDirectoryW",
  1967. "sechost.dll.ConvertStringSidToSidW",
  1968. "userenv.dll.RegisterGPNotification",
  1969. "gpapi.dll.RegisterGPNotificationInternal",
  1970. "sechost.dll.QueryServiceConfigW",
  1971. "winsta.dll.WinStationRegisterNotificationEvent",
  1972. "rpcrt4.dll.RpcAsyncInitializeHandle",
  1973. "cryptsp.dll.CryptAcquireContextA",
  1974. "cryptsp.dll.CryptCreateHash",
  1975. "cryptsp.dll.CryptHashData",
  1976. "cryptsp.dll.CryptVerifySignatureA",
  1977. "cryptsp.dll.CryptDestroyKey",
  1978. "cryptsp.dll.CryptDestroyHash",
  1979. "bcryptprimitives.dll.GetAsymmetricEncryptionInterface",
  1980. "ncrypt.dll.BCryptImportKeyPair",
  1981. "ncrypt.dll.BCryptVerifySignature",
  1982. "ncrypt.dll.BCryptDestroyKey",
  1983. "crypt32.dll.CertVerifyCertificateChainPolicy",
  1984. "crypt32.dll.CertFreeCertificateChain",
  1985. "crypt32.dll.CertDuplicateCertificateContext",
  1986. "ncrypt.dll.SslEncryptPacket",
  1987. "ncrypt.dll.SslDecryptPacket",
  1988. "crypt32.dll.CertFreeCertificateContext",
  1989. "rpcrt4.dll.RpcBindingFree",
  1990. "kernel32.dll.LCMapStringEx",
  1991. "kernel32.dll.InitializeCriticalSectionEx",
  1992. "kernel32.dll.CreateEventExW",
  1993. "kernel32.dll.CreateSemaphoreW",
  1994. "kernel32.dll.CreateSemaphoreExW",
  1995. "kernel32.dll.CreateThreadpoolTimer",
  1996. "kernel32.dll.SetThreadpoolTimer",
  1997. "kernel32.dll.WaitForThreadpoolTimerCallbacks",
  1998. "kernel32.dll.CloseThreadpoolTimer",
  1999. "kernel32.dll.CreateThreadpoolWait",
  2000. "kernel32.dll.SetThreadpoolWait",
  2001. "kernel32.dll.CloseThreadpoolWait",
  2002. "kernel32.dll.FlushProcessWriteBuffers",
  2003. "kernel32.dll.FreeLibraryWhenCallbackReturns",
  2004. "kernel32.dll.GetCurrentProcessorNumber",
  2005. "kernel32.dll.CreateSymbolicLinkW",
  2006. "kernel32.dll.GetTickCount64",
  2007. "kernel32.dll.GetFileInformationByHandleEx",
  2008. "kernel32.dll.SetFileInformationByHandle",
  2009. "kernel32.dll.InitializeConditionVariable",
  2010. "kernel32.dll.WakeAllConditionVariable",
  2011. "kernel32.dll.TryAcquireSRWLockExclusive",
  2012. "kernel32.dll.SleepConditionVariableSRW",
  2013. "kernel32.dll.CreateThreadpoolWork",
  2014. "kernel32.dll.SubmitThreadpoolWork",
  2015. "kernel32.dll.CloseThreadpoolWork",
  2016. "kernel32.dll.CompareStringEx",
  2017. "goopdate.dll.DllEntry",
  2018. "kernel32.dll.RtlCaptureStackBackTrace",
  2019. "wkscli.dll.NetWkstaGetInfo",
  2020. "cscapi.dll.CscNetApiGetInterface",
  2021. "kernel32.dll.CreateMutexExW",
  2022. "dbghelp.dll.MiniDumpWriteDump",
  2023. "rpcrt4.dll.UuidCreate",
  2024. "psmachine.dll.DllGetClassObject",
  2025. "psmachine.dll.DllCanUnloadNow",
  2026. "ntdll.dll.RtlGetVersion",
  2027. "winhttp.dll.WinHttpAddRequestHeaders",
  2028. "winhttp.dll.WinHttpCheckPlatform",
  2029. "winhttp.dll.WinHttpCloseHandle",
  2030. "winhttp.dll.WinHttpConnect",
  2031. "winhttp.dll.WinHttpCrackUrl",
  2032. "winhttp.dll.WinHttpCreateUrl",
  2033. "winhttp.dll.WinHttpDetectAutoProxyConfigUrl",
  2034. "winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser",
  2035. "winhttp.dll.WinHttpGetDefaultProxyConfiguration",
  2036. "winhttp.dll.WinHttpGetProxyForUrl",
  2037. "winhttp.dll.WinHttpOpen",
  2038. "winhttp.dll.WinHttpOpenRequest",
  2039. "winhttp.dll.WinHttpQueryAuthSchemes",
  2040. "winhttp.dll.WinHttpQueryDataAvailable",
  2041. "winhttp.dll.WinHttpQueryHeaders",
  2042. "winhttp.dll.WinHttpQueryOption",
  2043. "winhttp.dll.WinHttpReadData",
  2044. "winhttp.dll.WinHttpReceiveResponse",
  2045. "winhttp.dll.WinHttpSendRequest",
  2046. "winhttp.dll.WinHttpSetDefaultProxyConfiguration",
  2047. "winhttp.dll.WinHttpSetCredentials",
  2048. "winhttp.dll.WinHttpSetOption",
  2049. "winhttp.dll.WinHttpSetStatusCallback",
  2050. "winhttp.dll.WinHttpSetTimeouts",
  2051. "winhttp.dll.WinHttpWriteData",
  2052. "shlwapi.dll.StrCmpNW",
  2053. "shlwapi.dll.#153",
  2054. "rpcrt4.dll.RpcStringBindingComposeW",
  2055. "rpcrt4.dll.RpcBindingFromStringBindingW",
  2056. "rpcrt4.dll.RpcBindingSetAuthInfoExW",
  2057. "rpcrt4.dll.NdrClientCall2",
  2058. "winsta.dll.WinStationEnumerateW",
  2059. "rpcrt4.dll.I_RpcExceptionFilter",
  2060. "winsta.dll.WinStationQueryInformationW",
  2061. "bitsprx4.dll.DllGetClassObject",
  2062. "bitsprx4.dll.DllCanUnloadNow",
  2063. "rpcrt4.dll.UuidFromStringW",
  2064. "radarrs.dll.WdiDiagnosticModuleMain",
  2065. "radarrs.dll.WdiHandleInstance",
  2066. "radarrs.dll.WdiGetDiagnosticModuleInterfaceVersion",
  2067. "advapi32.dll.OpenProcessToken",
  2068. "advapi32.dll.DuplicateToken",
  2069. "advapi32.dll.AllocateAndInitializeSid",
  2070. "advapi32.dll.FreeSid",
  2071. "psapi.dll.EnumProcesses",
  2072. "psapi.dll.EnumProcessModules",
  2073. "psapi.dll.GetModuleBaseNameW"
  2074. ]
  2075.  
  2076. [*] Static Analysis: {
  2077. "pe": {
  2078. "peid_signatures": [
  2079. [
  2080. "Upack V0.37 -> Dwing"
  2081. ],
  2082. [
  2083. "Upack_Patch or any Version -> Dwing"
  2084. ],
  2085. [
  2086. "WinUpack v0.39 final (relocated image base) -> By Dwing (c)2005 (h2)"
  2087. ]
  2088. ],
  2089. "imports": [
  2090. {
  2091. "imports": [
  2092. {
  2093. "name": "LoadLibraryA",
  2094. "address": "0xbaef25"
  2095. },
  2096. {
  2097. "name": "GetProcAddress",
  2098. "address": "0xbaef29"
  2099. }
  2100. ],
  2101. "dll": "KERNEL32.DLL"
  2102. }
  2103. ],
  2104. "digital_signers": null,
  2105. "exported_dll_name": null,
  2106. "actual_checksum": "0x0024138a",
  2107. "overlay": null,
  2108. "imagebase": "0x00400000",
  2109. "reported_checksum": "0x00000000",
  2110. "icon_hash": null,
  2111. "entrypoint": "0x00baec61",
  2112. "timestamp": "1970-01-01 01:08:16",
  2113. "osversion": "4.0",
  2114. "sections": [
  2115. {
  2116. "name": ".Upack",
  2117. "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  2118. "virtual_address": "0x00001000",
  2119. "size_of_data": "0x00000000",
  2120. "entropy": "0.00",
  2121. "raw_address": "0x00000000",
  2122. "virtual_size": "0x0056d000",
  2123. "characteristics_raw": "0xe0000060"
  2124. },
  2125. {
  2126. "name": ".rsrc",
  2127. "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
  2128. "virtual_address": "0x0056e000",
  2129. "size_of_data": "0x00240f55",
  2130. "entropy": "8.00",
  2131. "raw_address": "0x00000200",
  2132. "virtual_size": "0x00248000",
  2133. "characteristics_raw": "0xe0000060"
  2134. }
  2135. ],
  2136. "resources": [
  2137. {
  2138. "name": "RT_BITMAP",
  2139. "language": "LANG_NEUTRAL",
  2140. "filetype": null,
  2141. "sublanguage": "SUBLANG_NEUTRAL",
  2142. "entropy": "0.00",
  2143. "offset": "0x0000f064",
  2144. "size": "0x0055d483"
  2145. }
  2146. ],
  2147. "dirents": [
  2148. {
  2149. "virtual_address": "0x00000000",
  2150. "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
  2151. "size": "0x00000000"
  2152. },
  2153. {
  2154. "virtual_address": "0x007aef2d",
  2155. "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
  2156. "size": "0x00000014"
  2157. },
  2158. {
  2159. "virtual_address": "0x0056e000",
  2160. "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
  2161. "size": "0x00000062"
  2162. },
  2163. {
  2164. "virtual_address": "0x00000000",
  2165. "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
  2166. "size": "0x00000000"
  2167. },
  2168. {
  2169. "virtual_address": "0x00000000",
  2170. "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
  2171. "size": "0x00000000"
  2172. },
  2173. {
  2174. "virtual_address": "0x00000048",
  2175. "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
  2176. "size": "0x00000008"
  2177. },
  2178. {
  2179. "virtual_address": "0x00000000",
  2180. "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
  2181. "size": "0x00000000"
  2182. },
  2183. {
  2184. "virtual_address": "0x00000000",
  2185. "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
  2186. "size": "0x00000000"
  2187. },
  2188. {
  2189. "virtual_address": "0x00000000",
  2190. "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
  2191. "size": "0x00000000"
  2192. },
  2193. {
  2194. "virtual_address": "0x007aef0d",
  2195. "name": "IMAGE_DIRECTORY_ENTRY_TLS",
  2196. "size": "0x00000018"
  2197. },
  2198. {
  2199. "virtual_address": "0x00000000",
  2200. "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
  2201. "size": "0x00000000"
  2202. },
  2203. {
  2204. "virtual_address": "0x00000000",
  2205. "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
  2206. "size": "0x00000000"
  2207. },
  2208. {
  2209. "virtual_address": "0x00000000",
  2210. "name": "IMAGE_DIRECTORY_ENTRY_IAT",
  2211. "size": "0x00000000"
  2212. },
  2213. {
  2214. "virtual_address": "0x00000000",
  2215. "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
  2216. "size": "0x00000000"
  2217. },
  2218. {
  2219. "virtual_address": "0x00000000",
  2220. "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
  2221. "size": "0x00000000"
  2222. },
  2223. {
  2224. "virtual_address": "0x00000000",
  2225. "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
  2226. "size": "0x00000000"
  2227. }
  2228. ],
  2229. "exports": [],
  2230. "guest_signers": {},
  2231. "imphash": "87bed5a7cba00c7e1f4015f1bdae2183",
  2232. "icon_fuzzy": null,
  2233. "icon": null,
  2234. "pdbpath": null,
  2235. "imported_dll_count": 1,
  2236. "versioninfo": []
  2237. }
  2238. }
Advertisement
Add Comment
Please, Sign In to add comment