Advertisement
Guest User

Untitled

a guest
May 28th, 2018
322
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.87 KB | None | 0 0
  1. Report
  2.  
  3. Timeline
  4.  
  5. Machine TimeZone Europe/Paris (GMT+2)
  6.  
  7. Mail exchange
  8.  
  9. From Attilus (att.ker.1n@gmail.com)
  10. To Viky (v1c.t1m.m3r@gmail.com)
  11. Found in 02-FLASH-USB-Image01
  12. 2018-03-26 14:28:54 UTC
  13.  
  14. Talks about CCleaner and transfer via WeTransfer
  15.  
  16. From Viky (v1c.t1m.m3r@gmail.com)
  17. To Attilus (att.ker.1n@gmail.com)
  18. Found in 02-FLASH-USB-Image01
  19. 2018-03-27 14:00:22 UTC
  20.  
  21. Response, file ccleaner given doesn't work
  22.  
  23. From Viky (v1c.t1m.m3r@gmail.com)
  24. To Attilus (att.ker.1n@gmail.com)
  25. Found in 02-FLASH-USB-Image01
  26. 2018-03-27 14:18:05 UTC
  27.  
  28. Executable not working
  29.  
  30. From Attilus (att.ker.1n@gmail.com)
  31. To Viky (v1c.t1m.m3r@gmail.com)
  32. Found in 02-FLASH-USB-Image01
  33. 2018-03-28 10:14:41 UTC
  34.  
  35. SanityCheck and sanitycheck.cpp
  36. sanitycheck.cpp does ddos attack all over the network (Users/IEUser/Documents/Tools/SanityCheck)
  37. was exec between 2018-03-28 09:41:40 UTC and 2018-03-28
  38. found in 01-FLASH-USB-Image01
  39.  
  40. Talks again of the CCleaner program
  41.  
  42. SanDisk Corp. 4C532000060223105221 2018-03-28 12:35:16
  43.  
  44. Found in Downloads
  45. 7z file with password : password1 (found in mails)
  46. extract at 13:00:02
  47. exe at 13:00:22
  48. ccsetup509.exe seems to be a malware (tested by virus total)
  49. connects to host IP: **.168.1.**:80, SOCKET = 0x00000100
  50. explains the multiple local area networks in network
  51. suppose it deletes the \REGISTRY\MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting\DW\DWFileTreeRoot
  52. \REGISTRY\MACHINE\SOFTWARE\Microsoft\PCHealth\ErrorReporting\DW
  53. so it blocks automatic report to the vendor so no-one can notice its passag
  54.  
  55. From Viky (v1c.t1m.m3r@gmail.com)
  56. To Attilus (att.ker.1n@gmail.com)
  57. Found in 02-FLASH-USB-Image01
  58. 2018-03-28 13:02:37 UTC
  59.  
  60. Install the tools but doesn't work
  61.  
  62. Alcor Micro Corp. B1264914 2018-03-28 13:34:34
  63. Silicon Motion, Inc. - Taiwan (formerly Feiya Technology Corp.) SCY0000000014664 2018-03-28 13:55:46
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement