paladin316

Exes_7a452e322961bc0170a2832d86e9442f_jpg_2019-07-23_11_30.txt

Jul 23rd, 2019
2,153
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 29.42 KB | None | 0 0
  1.  
  2. * MalFamily: ""
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_7a452e322961bc0170a2832d86e9442f.jpg"
  7. * File Size: 33280
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "d3a5ee9e5ff1ea4b9bd56d93c9ccfa016c7a9af3771c6e5d2d0c71f5101978f0"
  10. * MD5: "7a452e322961bc0170a2832d86e9442f"
  11. * SHA1: "1630628ad2125d07811a6741caa8f159155bc253"
  12. * SHA512: "e76c7f669939f825a86cb177b4e29203ba4ea6ece2e83ee92d6bfbce815c6b255b594f4bd860b83fa6d7864305ea33ea1c8c2006c10c71a754e79446e8463f79"
  13. * CRC32: "1E9366DB"
  14. * SSDEEP: "768:FrqQ7AmV3rjBkyo1bWkP8K9RWKDtwTxS+oASDu3JUYlyaQ3Zl:F33kq5xFSXAjDO3"
  15.  
  16. * Process Execution:
  17. "Exes_7a452e322961bc0170a2832d86e9442f.jpg",
  18. "explorer.exe",
  19. "svchost.exe",
  20. "WMIADAP.exe",
  21. "taskeng.exe",
  22. "tbtfsgew.exe",
  23. "taskeng.exe",
  24. "tbtfsgew.exe",
  25. "svchost.exe",
  26. "WmiPrvSE.exe",
  27. "svchost.exe"
  28.  
  29.  
  30. * Executed Commands:
  31. "\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE wmiadap.exe /F /T /R",
  32. "taskeng.exe 9315CEFA-522C-426E-B8BF-A1363CC7E923 S-1-5-21-0000000000-0000000000-0000000000-1000:Host\\user:Interactive:1",
  33. "taskeng.exe C3BCAFC4-23D3-473E-B032-76AF983F52FF S-1-5-21-0000000000-0000000000-0000000000-1000:Host\\user:Interactive:1",
  34. "C:\\Windows\\system32\\wbem\\wmiprvse.exe -Embedding",
  35. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\hviticat\\tbtfsgew.exe"
  36.  
  37.  
  38. * Signatures Detected:
  39.  
  40. "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
  41. "Details":
  42.  
  43. "IP": "23.59.190.137:80"
  44.  
  45.  
  46.  
  47.  
  48. "Description": "Creates RWX memory",
  49. "Details":
  50.  
  51.  
  52. "Description": "A process attempted to delay the analysis task.",
  53. "Details":
  54.  
  55. "Process": "svchost.exe tried to sleep 360 seconds, actually delayed analysis time by 0 seconds"
  56.  
  57.  
  58. "Process": "taskeng.exe tried to sleep 360 seconds, actually delayed analysis time by 0 seconds"
  59.  
  60.  
  61. "Process": "explorer.exe tried to sleep 625 seconds, actually delayed analysis time by 0 seconds"
  62.  
  63.  
  64.  
  65.  
  66. "Description": "Expresses interest in specific running processes",
  67. "Details":
  68.  
  69. "process": "svchost.exe"
  70.  
  71.  
  72.  
  73.  
  74. "Description": "Repeatedly searches for a not-found process, may want to run with startbrowser=1 option",
  75. "Details":
  76.  
  77.  
  78. "Description": "A process created a hidden window",
  79. "Details":
  80.  
  81. "Process": "svchost.exe -> \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE"
  82.  
  83.  
  84.  
  85.  
  86. "Description": "Drops a binary and executes it",
  87. "Details":
  88.  
  89. "binary": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\hviticat\\tbtfsgew.exe"
  90.  
  91.  
  92.  
  93.  
  94. "Description": "Performs some HTTP requests",
  95. "Details":
  96.  
  97. "url": "http://www.msftncsi.com/ncsi.txt"
  98.  
  99.  
  100.  
  101.  
  102. "Description": "The binary likely contains encrypted or compressed data.",
  103. "Details":
  104.  
  105. "section": "name: .text, entropy: 7.70, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00008000, virtual_size: 0x00007ebf"
  106.  
  107.  
  108.  
  109.  
  110. "Description": "Detects Sandboxie through the presence of a library",
  111. "Details":
  112.  
  113.  
  114. "Description": "Deletes its original binary from disk",
  115. "Details":
  116.  
  117.  
  118. "Description": "Attempts to remove evidence of file being downloaded from the Internet",
  119. "Details":
  120.  
  121. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\hviticat\\tbtfsgew.exe:Zone.Identifier"
  122.  
  123.  
  124.  
  125.  
  126. "Description": "Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config",
  127. "Details":
  128.  
  129. "regkeyval": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage2\\ProgramsCache"
  130.  
  131.  
  132.  
  133.  
  134. "Description": "Installs itself for autorun at Windows startup",
  135. "Details":
  136.  
  137. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\hviticat.lnk"
  138.  
  139.  
  140. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\hviticat.lnk"
  141.  
  142.  
  143.  
  144.  
  145. "Description": "Creates a hidden or system file",
  146. "Details":
  147.  
  148. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\hviticat\\tbtfsgew.exe"
  149.  
  150.  
  151. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\hviticat"
  152.  
  153.  
  154.  
  155.  
  156. "Description": "File has been identified by 40 Antiviruses on VirusTotal as malicious",
  157. "Details":
  158.  
  159. "MicroWorld-eScan": "Gen:Trojan.Heur.GZ.ceW@bq0!oNe"
  160.  
  161.  
  162. "McAfee": "GenericRXGK-YC!7A452E322961"
  163.  
  164.  
  165. "Malwarebytes": "Trojan.Agent"
  166.  
  167.  
  168. "Arcabit": "Trojan.Heur.GZ.E0C458"
  169.  
  170.  
  171. "Cyren": "W32/Dofoil.H.gen!Eldorado"
  172.  
  173.  
  174. "ESET-NOD32": "a variant of Win32/TrojanDownloader.Zurgop.DA"
  175.  
  176.  
  177. "TrendMicro-HouseCall": "Trojan.Win32.ZURGOP.SM"
  178.  
  179.  
  180. "Kaspersky": "HEUR:Trojan.Win32.Generic"
  181.  
  182.  
  183. "BitDefender": "Gen:Trojan.Heur.GZ.ceW@bq0!oNe"
  184.  
  185.  
  186. "NANO-Antivirus": "Trojan.Win32.Zurgop.fednlb"
  187.  
  188.  
  189. "Avast": "Win32:Trojan-gen"
  190.  
  191.  
  192. "Ad-Aware": "Gen:Trojan.Heur.GZ.ceW@bq0!oNe"
  193.  
  194.  
  195. "Emsisoft": "Gen:Trojan.Heur.GZ.ceW@bq0!oNe (B)"
  196.  
  197.  
  198. "F-Secure": "Trojan.TR/Crypt.XPACK.Gen"
  199.  
  200.  
  201. "DrWeb": "Trojan.PWS.Spy.21017"
  202.  
  203.  
  204. "VIPRE": "Trojan.Win32.Winwebsec.m (v)"
  205.  
  206.  
  207. "Invincea": "heuristic"
  208.  
  209.  
  210. "McAfee-GW-Edition": "BehavesLike.Win32.VirRansom.nc"
  211.  
  212.  
  213. "Trapmine": "malicious.high.ml.score"
  214.  
  215.  
  216. "Sophos": "Mal/Behav-204"
  217.  
  218.  
  219. "SentinelOne": "DFI - Malicious PE"
  220.  
  221.  
  222. "Jiangmin": "Trojan.Generic.comhm"
  223.  
  224.  
  225. "Avira": "TR/Crypt.XPACK.Gen"
  226.  
  227.  
  228. "Antiy-AVL": "TrojanDownloader/Win32.Dofoil"
  229.  
  230.  
  231. "Microsoft": "TrojanDownloader:Win32/Dofoil.AD"
  232.  
  233.  
  234. "Endgame": "malicious (high confidence)"
  235.  
  236.  
  237. "ZoneAlarm": "HEUR:Trojan.Win32.Generic"
  238.  
  239.  
  240. "GData": "Gen:Trojan.Heur.GZ.ceW@bq0!oNe"
  241.  
  242.  
  243. "AhnLab-V3": "Trojan/Win32.Dofoil.R223509"
  244.  
  245.  
  246. "Acronis": "suspicious"
  247.  
  248.  
  249. "VBA32": "TScope.Malware-Cryptor.SB"
  250.  
  251.  
  252. "MAX": "malware (ai score=83)"
  253.  
  254.  
  255. "Rising": "Downloader.Zurgop!8.4BB (C64:YzY0OmU/VPjJOpph)"
  256.  
  257.  
  258. "Ikarus": "Trojan-Downloader.Win32.Dofoil"
  259.  
  260.  
  261. "Fortinet": "W32/Zurgop.DA!tr"
  262.  
  263.  
  264. "AVG": "Win32:Trojan-gen"
  265.  
  266.  
  267. "Cybereason": "malicious.22961b"
  268.  
  269.  
  270. "Panda": "Trj/CI.A"
  271.  
  272.  
  273. "CrowdStrike": "win/malicious_confidence_100% (W)"
  274.  
  275.  
  276. "Qihoo-360": "HEUR/QVM19.1.08AD.Malware.Gen"
  277.  
  278.  
  279.  
  280.  
  281. "Description": "Checks the presence of disk drives in the registry, possibly for anti-virtualization",
  282. "Details":
  283.  
  284.  
  285. "Description": "Creates a copy of itself",
  286. "Details":
  287.  
  288. "copy": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\hviticat\\tbtfsgew.exe"
  289.  
  290.  
  291.  
  292.  
  293. "Description": "Anomalous binary characteristics",
  294. "Details":
  295.  
  296. "anomaly": "Minimum OS version is older than NT4 yet the PE timestamp year is newer than 2000"
  297.  
  298.  
  299. "anomaly": "Actual checksum does not match that reported in PE header"
  300.  
  301.  
  302.  
  303.  
  304.  
  305. * Started Service:
  306.  
  307. * Mutexes:
  308. "7E8C820C05FE53DA70B24D931AD9346CC1C5B64F",
  309. "CicLoadWinStaWinSta0",
  310. "Local\\MSCTF.CtfMonitorInstMutexDefault1",
  311. "Global\\ADAP_WMI_ENTRY",
  312. "Global\\RefreshRA_Mutex",
  313. "Global\\RefreshRA_Mutex_Lib",
  314. "Global\\RefreshRA_Mutex_Flag"
  315.  
  316.  
  317. * Modified Files:
  318. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\hviticat\\tbtfsgew.exe",
  319. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\hviticat",
  320. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\hviticat.lnk",
  321. "C:\\Windows\\sysnative\\Tasks\\Opera scheduled Autoupdate 3130912781",
  322. "\\Device\\LanmanDatagramReceiver",
  323. "C:\\Windows\\appcompat\\Programs\\RecentFileCache.bcf",
  324. "C:\\Windows\\sysnative\\Tasks\\Microsoft\\Windows Defender\\MP Scheduled Scan",
  325. "C:\\Windows\\SoftwareDistribution\\DataStore\\DataStore.edb",
  326. "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edb.chk",
  327. "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl_new.h",
  328. "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl.h",
  329. "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl_new.ini",
  330. "\\??\\PIPE\\samr",
  331. "C:\\Windows\\sysnative\\wbem\\repository\\WRITABLE.TST",
  332. "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING1.MAP",
  333. "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING2.MAP",
  334. "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING3.MAP",
  335. "C:\\Windows\\sysnative\\wbem\\repository\\OBJECTS.DATA",
  336. "C:\\Windows\\sysnative\\wbem\\repository\\INDEX.BTR",
  337. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
  338. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER",
  339. "\\??\\WMIDataDevice"
  340.  
  341.  
  342. * Deleted Files:
  343. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\hviticat\\tbtfsgew.exe",
  344. "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_7a452e322961bc0170a2832d86e9442f.jpg",
  345. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\hviticat\\tbtfsgew.exe:Zone.Identifier",
  346. "C:\\Windows\\Tasks\\Opera scheduled Autoupdate 3130912781.job",
  347. "C:\\Windows\\sysnative\\Tasks\\Opera scheduled Autoupdate 3130912781",
  348. "C:\\Windows\\sysnative\\Tasks\\Microsoft\\Windows Defender\\MpIdleTask",
  349. "C:\\Windows\\sysnative\\Tasks\\Microsoft\\Windows Defender\\MP Scheduled Scan",
  350. "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edbtmp.log",
  351. "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl.h",
  352. "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl_new.h"
  353.  
  354.  
  355. * Modified Registry Keys:
  356. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  357. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\CEBFF5CD-ACE2-4F4F-9178-9926F41749EA\\Count\\1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7\\pzq.rkr",
  358. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\CEBFF5CD-ACE2-4F4F-9178-9926F41749EA\\Count\\HRZR_PGYFRFFVBA",
  359. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\StartPage2\\ProgramsCache",
  360. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.bmp\\OpenWithProgids\\Paint.Picture",
  361. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.cab\\OpenWithProgids\\CABFolder",
  362. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.contact\\OpenWithProgids\\contact_wab_auto_file",
  363. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.css\\OpenWithProgids\\CSSfile",
  364. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.csv\\OpenWithProgids\\Excel.CSV",
  365. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dib\\OpenWithProgids\\Paint.Picture",
  366. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dll\\OpenWithProgids\\dllfile",
  367. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.doc\\OpenWithProgids\\Word.Document.8",
  368. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.docm\\OpenWithProgids\\Word.DocumentMacroEnabled.12",
  369. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.docx\\OpenWithProgids\\Word.Document.12",
  370. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dot\\OpenWithProgids\\Word.Template.8",
  371. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dotm\\OpenWithProgids\\Word.TemplateMacroEnabled.12",
  372. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dotx\\OpenWithProgids\\Word.Template.12",
  373. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dwfx\\OpenWithProgids\\Windows.XPSReachViewer",
  374. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.easmx\\OpenWithProgids\\Windows.XPSReachViewer",
  375. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.edrwx\\OpenWithProgids\\Windows.XPSReachViewer",
  376. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.emf\\OpenWithProgids\\emffile",
  377. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.eprtx\\OpenWithProgids\\Windows.XPSReachViewer",
  378. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.exe\\OpenWithProgids\\exefile",
  379. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.fon\\OpenWithProgids\\fonfile",
  380. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.gif\\OpenWithProgids\\giffile",
  381. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.htm\\OpenWithProgids\\ChromeHTML",
  382. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\OpenWithProgids\\ChromeHTML",
  383. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ico\\OpenWithProgids\\icofile",
  384. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ini\\OpenWithProgids\\inifile",
  385. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jfif\\OpenWithProgids\\pjpegfile",
  386. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jpe\\OpenWithProgids\\jpegfile",
  387. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jpeg\\OpenWithProgids\\jpegfile",
  388. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jpg\\OpenWithProgids\\jpegfile",
  389. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jtx\\OpenWithProgids\\Windows.XPSReachViewer",
  390. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.lnk\\OpenWithProgids\\lnkfile",
  391. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.mht\\OpenWithProgids\\mhtmlfile",
  392. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.mhtml\\OpenWithProgids\\mhtmlfile",
  393. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.msg\\OpenWithProgids\\Outlook.File.msg.15",
  394. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ocx\\OpenWithProgids\\ocxfile",
  395. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.odt\\OpenWithProgids\\Word.OpenDocumentText.12",
  396. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.otf\\OpenWithProgids\\otffile",
  397. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.png\\OpenWithProgids\\pngfile",
  398. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.pot\\OpenWithProgids\\PowerPoint.Template.8",
  399. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.potm\\OpenWithProgids\\PowerPoint.TemplateMacroEnabled.12",
  400. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.potx\\OpenWithProgids\\PowerPoint.Template.12",
  401. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ppam\\OpenWithProgids\\PowerPoint.Addin.12",
  402. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ppsm\\OpenWithProgids\\PowerPoint.SlideShowMacroEnabled.12",
  403. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ppsx\\OpenWithProgids\\PowerPoint.SlideShow.12",
  404. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ppt\\OpenWithProgids\\PowerPoint.Show.8",
  405. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.pptm\\OpenWithProgids\\PowerPoint.ShowMacroEnabled.12",
  406. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.pptx\\OpenWithProgids\\PowerPoint.Show.12",
  407. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ps1xml\\OpenWithProgids\\Microsoft.PowerShellXMLData.1",
  408. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.rle\\OpenWithProgids\\rlefile",
  409. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.rtf\\OpenWithProgids\\Word.RTF.8",
  410. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.scf\\OpenWithProgids\\SHCmdFile",
  411. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.search-ms\\OpenWithProgids\\SearchFolder",
  412. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.shtml\\OpenWithProgids\\ChromeHTML",
  413. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.sldm\\OpenWithProgids\\PowerPoint.SlideMacroEnabled.12",
  414. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.sldx\\OpenWithProgids\\PowerPoint.Slide.12",
  415. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.sys\\OpenWithProgids\\sysfile",
  416. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.tif\\OpenWithProgids\\TIFImage.Document",
  417. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.tiff\\OpenWithProgids\\TIFImage.Document",
  418. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ttc\\OpenWithProgids\\ttcfile",
  419. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ttf\\OpenWithProgids\\ttffile",
  420. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.txt\\OpenWithProgids\\txtfile",
  421. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.vsto\\OpenWithProgids\\bootstrap.vsto.1",
  422. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.wdp\\OpenWithProgids\\wdpfile",
  423. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.wmf\\OpenWithProgids\\wmffile",
  424. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xlam\\OpenWithProgids\\Excel.AddInMacroEnabled",
  425. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xls\\OpenWithProgids\\Excel.Sheet.8",
  426. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xlsb\\OpenWithProgids\\Excel.SheetBinaryMacroEnabled.12",
  427. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xlsm\\OpenWithProgids\\Excel.SheetMacroEnabled.12",
  428. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xlsx\\OpenWithProgids\\Excel.Sheet.12",
  429. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xlt\\OpenWithProgids\\Excel.Template.8",
  430. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xltm\\OpenWithProgids\\Excel.TemplateMacroEnabled",
  431. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xltx\\OpenWithProgids\\Excel.Template",
  432. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xml\\OpenWithProgids\\xmlfile",
  433. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xps\\OpenWithProgids\\Windows.XPSReachViewer",
  434. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xsl\\OpenWithProgids\\xslfile",
  435. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.zip\\OpenWithProgids\\CompressedFolder",
  436. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\E8433B72-5842-4d43-8645-BC2C35960837.check.106\\CheckSetting",
  437. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\E8433B72-5842-4d43-8645-BC2C35960837.check.103\\CheckSetting",
  438. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\E8433B72-5842-4d43-8645-BC2C35960837.check.100\\CheckSetting",
  439. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\E8433B72-5842-4d43-8645-BC2C35960837.check.101\\CheckSetting",
  440. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\E8433B72-5842-4d43-8645-BC2C35960837.check.102\\CheckSetting",
  441. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\E8433B72-5842-4d43-8645-BC2C35960837.check.104\\CheckSetting",
  442. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\903702B1-4D24-40B8-BCD3-923E3DF275BF\\Path",
  443. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\903702B1-4D24-40B8-BCD3-923E3DF275BF\\Hash",
  444. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Opera scheduled Autoupdate 3130912781\\Id",
  445. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Opera scheduled Autoupdate 3130912781\\Index",
  446. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\903702B1-4D24-40B8-BCD3-923E3DF275BF\\Triggers",
  447. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\903702B1-4D24-40B8-BCD3-923E3DF275BF\\DynamicInfo",
  448. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
  449. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\PreviousServiceShutdown",
  450. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ProcessID",
  451. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\9315CEFA-522C-426E-B8BF-A1363CC7E923",
  452. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\2D2A242F-A11E-407E-8A79-02450E80A494\\Path",
  453. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\2D2A242F-A11E-407E-8A79-02450E80A494\\Hash",
  454. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\MP Scheduled Scan\\Id",
  455. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\MP Scheduled Scan\\Index",
  456. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\2D2A242F-A11E-407E-8A79-02450E80A494\\Triggers",
  457. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\2D2A242F-A11E-407E-8A79-02450E80A494\\DynamicInfo",
  458. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\C3BCAFC4-23D3-473E-B032-76AF983F52FF",
  459. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Wbem\\Transports\\Decoupled\\Server",
  460. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\CreationTime",
  461. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\MarshaledProxy",
  462. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\ProcessIdentifier",
  463. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ConfigValueEssNeedsLoading",
  464. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\List of event-active namespaces",
  465. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\ESS\\//./root/CIMV2\\SCM Event Provider",
  466. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\IDE\\DiskVBOX_HARDDISK___________________________1.0_____\\5&33d1638a&0&0.0.0_0-00000000-0000-0000-0000-000000000000",
  467. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\advapi32.dllMofResourceName",
  468. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\en-US\\advapi32.dll.muiMofResourceName",
  469. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\ACPI.sysACPIMOFResource",
  470. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\en-US\\ACPI.sys.muiACPIMOFResource",
  471. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\ndis.sysMofResourceName",
  472. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\en-US\\ndis.sys.muiMofResourceName",
  473. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\mssmbios.sysMofResource",
  474. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\en-US\\mssmbios.sys.muiMofResource",
  475. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\HDAudBus.sysHDAudioMofName",
  476. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\en-US\\HDAudBus.sys.muiHDAudioMofName",
  477. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\intelppm.sysPROCESSORWMI",
  478. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\en-US\\intelppm.sys.muiPROCESSORWMI",
  479. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\System32\\Drivers\\portcls.SYSPortclsMof",
  480. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\System32\\Drivers\\en-US\\portcls.SYS.muiPortclsMof",
  481. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\monitor.sysMonitorWMI",
  482. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\9315CEFA-522C-426E-B8BF-A1363CC7E923\\data",
  483. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\C3BCAFC4-23D3-473E-B032-76AF983F52FF\\data"
  484.  
  485.  
  486. * Deleted Registry Keys:
  487. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\Opera scheduled Autoupdate 3130912781.job",
  488. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\Opera scheduled Autoupdate 3130912781.job.fp",
  489. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
  490. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\monitor.sysMonitorWMI"
  491.  
  492.  
  493. * DNS Communications:
  494.  
  495. "type": "A",
  496. "request": "j50sos.co",
  497. "answers":
  498.  
  499. "data": "",
  500. "type": "NXDOMAIN"
  501.  
  502.  
  503.  
  504.  
  505.  
  506. * Domains:
  507.  
  508. "ip": "",
  509. "domain": "j50sos.co"
  510.  
  511.  
  512.  
  513. * Network Communication - ICMP:
  514.  
  515. * Network Communication - HTTP:
  516.  
  517. "count": 3,
  518. "body": "",
  519. "uri": "http://www.msftncsi.com/ncsi.txt",
  520. "user-agent": "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  521. "method": "GET",
  522. "host": "www.msftncsi.com",
  523. "version": "1.1",
  524. "path": "/ncsi.txt",
  525. "data": "GET /ncsi.txt HTTP/1.1\r\nCache-Control: no-cache\r\nConnection: Keep-Alive\r\nPragma: no-cache\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: www.msftncsi.com\r\n\r\n",
  526. "port": 80
  527.  
  528.  
  529.  
  530. * Network Communication - SMTP:
  531.  
  532. * Network Communication - Hosts:
  533.  
  534. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment