paladin316

Exes_e949c0e6ba9e052fc3b696e61cbe067a_html_2019-08-05_14_30.txt

Aug 5th, 2019
2,260
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 46.28 KB | None | 0 0
  1.  
  2. * MalFamily: "Ispy"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_e949c0e6ba9e052fc3b696e61cbe067a.html?file=mega_521d6c7c88"
  7. * File Size: 3007136
  8. * File Type: "PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows"
  9. * SHA256: "32b03a66f2d3381829c8b31d4a704c849cc6f842f458bf0f4510b8aa5d6d4c64"
  10. * MD5: "e949c0e6ba9e052fc3b696e61cbe067a"
  11. * SHA1: "00f375fdd11817887e202adfe3d2366bd890cff8"
  12. * SHA512: "7c1e5fe51985acb2370267165aa571d6ff64f7df3648f9aa8913885f773764f44fcc308d067763b1365942927fcd40e959c0503a980898825a0b2a05e2cb14c3"
  13. * CRC32: "245F4892"
  14. * SSDEEP: "49152:kx6dP4+zOrOHgrEyKN8RoBSxtfh8KGQXxbD3Wa8HyoKqKoe:Xe0FHyEyKNg48tfh/GQXVDN8HyoKqKoe"
  15.  
  16. * Process Execution:
  17. "Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88",
  18. "AcroRd32.exe",
  19. "Eula.exe",
  20. "AdobeARM.exe",
  21. "Reader_sl.exe",
  22. "cmd.exe",
  23. "cmd.exe",
  24. "cmd.exe",
  25. "Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88",
  26. "csc.exe",
  27. "cvtres.exe",
  28. "prgyj.exe",
  29. "prgyj.exe",
  30. "prgyj.exe",
  31. "prgyj.exe",
  32. "prgyj.exe",
  33. "svchost.exe",
  34. "WmiPrvSE.exe",
  35. "WmiPrvSE.exe",
  36. "svchost.exe",
  37. "WMIADAP.exe"
  38.  
  39.  
  40. * Executed Commands:
  41. "\"C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroRd32.exe\" \"C:\\Users\\user\\AppData\\Local\\Temp\\bbb.pdf\"",
  42. "C:\\Users\\user\\AppData\\Local\\Temp\\bbb.pdf ",
  43. "cmd.exe /c copy \"C:/Users/user/AppData/Local/Temp/Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88\" \"%appdata%\\ltigho\\lttdyd.exe\" /Y",
  44. "cmd.exe /c echo zoneTransferZoneID = 2 > %appdata%\\ltigho\\lttdyd.exe:Zone.Identifier",
  45. "cmd.exe /c ren \"%appdata%\\ltigho\\lttdyd.exe.jpg\" lttdyd.exe",
  46. "\"C:/Users/user/AppData/Local/Temp/Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88\"",
  47. "\"C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroRd32.exe\" --type=renderer \"C:\\Users\\user\\AppData\\Local\\Temp\\bbb.pdf\"",
  48. "\"C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\AcroCEF\\RdrCEF.exe\" --backgroundcolor=16514043",
  49. "\"C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\Eula.exe\" Adobe Acrobat Reader DC;655786;1033",
  50. "\"C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\AdobeARM.exe\" /PRODUCT:Reader /VERSION:19.0 /MODE:3",
  51. "\"C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\csc.exe\" /noconfig /fullpaths @\"C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.cmdline\"",
  52. "C:\\Users\\user\\AppData\\Roaming\\prgyj.exe /launchSelfAndExit \"C:\\Users\\user\\AppData\\Local\\Temp\\Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88\" 2412 /protectFile",
  53. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 \"/OUT:C:\\Users\\user\\AppData\\Local\\Temp\\RES6EAA.tmp\" \"c:\\Users\\user\\AppData\\Local\\Temp\\CSC6E99.tmp\"",
  54. "C:\\Users\\user\\AppData\\Roaming\\prgyj.exe /watchProcess \"C:\\Users\\user\\AppData\\Local\\Temp\\Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88\" 2412 \"/protectFile\"",
  55. "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding",
  56. "C:\\Windows\\system32\\wbem\\wmiprvse.exe -Embedding",
  57. "\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE wmiadap.exe /F /T /R",
  58. "C:\\Program Files (x86)\\Adobe\\Acrobat Reader DC\\Reader\\Reader_sl.exe "
  59.  
  60.  
  61. * Signatures Detected:
  62.  
  63. "Description": "Creates RWX memory",
  64. "Details":
  65.  
  66.  
  67. "Description": "Attempts to connect to a dead IP:Port (6 unique times)",
  68. "Details":
  69.  
  70. "IP": "13.107.4.50:80"
  71.  
  72.  
  73. "IP": "193.161.193.99:44611"
  74.  
  75.  
  76. "IP": "184.28.188.179:80"
  77.  
  78.  
  79. "IP": "23.208.143.3:443"
  80.  
  81.  
  82. "IP": "193.161.193.99:2928"
  83.  
  84.  
  85. "IP": "72.21.91.29:80"
  86.  
  87.  
  88.  
  89.  
  90. "Description": "At least one IP Address, Domain, or File Name was found in a crypto call",
  91. "Details":
  92.  
  93. "ioc": "v2.0.50727"
  94.  
  95.  
  96.  
  97.  
  98. "Description": "Reads data out of its own binary image",
  99. "Details":
  100.  
  101. "self_read": "process: Eula.exe, pid: 348, offset: 0x00000000, length: 0x00000040"
  102.  
  103.  
  104. "self_read": "process: Eula.exe, pid: 348, offset: 0x00000100, length: 0x00000018"
  105.  
  106.  
  107. "self_read": "process: Eula.exe, pid: 348, offset: 0x000001f8, length: 0x000000a0"
  108.  
  109.  
  110. "self_read": "process: Eula.exe, pid: 348, offset: 0x00012600, length: 0x00000010"
  111.  
  112.  
  113.  
  114.  
  115. "Description": "A process created a hidden window",
  116. "Details":
  117.  
  118. "Process": "Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88 -> cmd.exe"
  119.  
  120.  
  121. "Process": "Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88 -> cmd.exe"
  122.  
  123.  
  124. "Process": "Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88 -> cmd.exe"
  125.  
  126.  
  127. "Process": "svchost.exe -> \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE"
  128.  
  129.  
  130.  
  131.  
  132. "Description": "Drops a binary and executes it",
  133. "Details":
  134.  
  135. "binary": "C:\\Users\\user\\AppData\\Roaming\\prgyj.exe"
  136.  
  137.  
  138.  
  139.  
  140. "Description": "Performs some HTTP requests",
  141. "Details":
  142.  
  143. "url": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab"
  144.  
  145.  
  146. "url": "http://acroipm2.adobe.com/19/rdr/ENU/win/nooem/none/consumer/message.zip"
  147.  
  148.  
  149. "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D"
  150.  
  151.  
  152. "url": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEAiybqFfIme0q2SePjjqIls%3D"
  153.  
  154.  
  155.  
  156.  
  157. "Description": "The binary likely contains encrypted or compressed data.",
  158. "Details":
  159.  
  160. "section": "name: .text, entropy: 7.97, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ, raw_size: 0x00236200, virtual_size: 0x0023614c"
  161.  
  162.  
  163.  
  164.  
  165. "Description": "Anomalous .NET characteristics",
  166. "Details":
  167.  
  168. "anomalous_version": "Assembly version is set to 0"
  169.  
  170.  
  171.  
  172.  
  173. "Description": "Executed a process and injected code into it, probably while unpacking",
  174. "Details":
  175.  
  176. "Injection": "Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88(2272) -> Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88(2412)"
  177.  
  178.  
  179.  
  180.  
  181. "Description": "A process attempted to delay the analysis task by a long amount of time.",
  182. "Details":
  183.  
  184. "Process": "WmiPrvSE.exe tried to sleep 546 seconds, actually delayed analysis time by 0 seconds"
  185.  
  186.  
  187. "Process": "Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88 tried to sleep 2608 seconds, actually delayed analysis time by 0 seconds"
  188.  
  189.  
  190. "Process": "prgyj.exe tried to sleep 474 seconds, actually delayed analysis time by 0 seconds"
  191.  
  192.  
  193.  
  194.  
  195. "Description": "A process was set to shut the system down when terminated",
  196. "Details":
  197.  
  198. "process": "Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88:2412"
  199.  
  200.  
  201.  
  202.  
  203. "Description": "A potential decoy document was displayed to the user",
  204. "Details":
  205.  
  206. "disguised_executable": "The submitted file was an executable indicative of an attempt to get a user to run executable content disguised as a document"
  207.  
  208.  
  209. "Decoy Document": "\"c:\\program files (x86)\\adobe\\acrobat reader dc\\reader\\acrord32.exe\" \"c:\\users\\user\\appdata\\local\\temp\\bbb.pdf\""
  210.  
  211.  
  212.  
  213.  
  214. "Description": "Exhibits behavior characteristic of iSpy Keylogger",
  215. "Details":
  216.  
  217.  
  218. "Description": "A document file initiated network communications indicative of a potential exploit or payload download",
  219. "Details":
  220.  
  221. "http_request": "acrord32.exe_WSASend_get /mfewtzbnmeswstajbgurdgmcgguabbsauqybmq2awn1rh6doh%2fsbygfv7gqua95qnvbrtltm8kpigxvdl7i90vuceah9o%2btuynxiieolckvpvje%3d http/1.1\r\ncache-control: max-age = 142986\r\nconnection: keep-alive\r\naccept: */*\r\nif-modified-since: tue, 28 may 2019 07:40:28 gmt\r\nif"
  222.  
  223.  
  224.  
  225.  
  226. "Description": "Installs itself for autorun at Windows startup",
  227. "Details":
  228.  
  229. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\lttdyd.exe.lnk"
  230.  
  231.  
  232. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\lttdyd.exe.lnk"
  233.  
  234.  
  235.  
  236.  
  237. "Description": "Creates a hidden or system file",
  238. "Details":
  239.  
  240. "file": "C:\\Users\\user\\AppData\\Roaming\\ltigho"
  241.  
  242.  
  243.  
  244.  
  245. "Description": "File has been identified by 22 Antiviruses on VirusTotal as malicious",
  246. "Details":
  247.  
  248. "CrowdStrike": "win/malicious_confidence_100% (D)"
  249.  
  250.  
  251. "Symantec": "ML.Attribute.HighConfidence"
  252.  
  253.  
  254. "ESET-NOD32": "a variant of MSIL/Kryptik.LSD"
  255.  
  256.  
  257. "APEX": "Malicious"
  258.  
  259.  
  260. "Kaspersky": "HEUR:Trojan.MSIL.Dnoper.gen"
  261.  
  262.  
  263. "Emsisoft": "Trojan.Crypt (A)"
  264.  
  265.  
  266. "Invincea": "heuristic"
  267.  
  268.  
  269. "McAfee-GW-Edition": "BehavesLike.Win32.Generic.vc"
  270.  
  271.  
  272. "Trapmine": "malicious.high.ml.score"
  273.  
  274.  
  275. "FireEye": "Generic.mg.e949c0e6ba9e052f"
  276.  
  277.  
  278. "Avira": "TR/Dropper.Gen"
  279.  
  280.  
  281. "Endgame": "malicious (high confidence)"
  282.  
  283.  
  284. "ZoneAlarm": "HEUR:Trojan.MSIL.Dnoper.gen"
  285.  
  286.  
  287. "Microsoft": "Trojan:Win32/Fuery.B!cl"
  288.  
  289.  
  290. "Cylance": "Unsafe"
  291.  
  292.  
  293. "SentinelOne": "DFI - Malicious PE"
  294.  
  295.  
  296. "eGambit": "Unsafe.AI_Score_67%"
  297.  
  298.  
  299. "Fortinet": "MSIL/Kryptik.SHS!tr"
  300.  
  301.  
  302. "AVG": "MSIL:GenMalicious-CMG Trj"
  303.  
  304.  
  305. "Cybereason": "malicious.dd1181"
  306.  
  307.  
  308. "Avast": "MSIL:GenMalicious-CMG Trj"
  309.  
  310.  
  311. "Qihoo-360": "HEUR/QVM03.0.004A.Malware.Gen"
  312.  
  313.  
  314.  
  315.  
  316. "Description": "Checks the CPU name from registry, possibly for anti-virtualization",
  317. "Details":
  318.  
  319.  
  320. "Description": "Attempts to modify proxy settings",
  321. "Details":
  322.  
  323.  
  324. "Description": "Attempts to modify browser security settings",
  325. "Details":
  326.  
  327.  
  328. "Description": "Creates a copy of itself",
  329. "Details":
  330.  
  331. "copy": "C:\\Users\\user\\AppData\\Roaming\\ltigho\\lttdyd.exe"
  332.  
  333.  
  334.  
  335.  
  336. "Description": "Attempts to interact with an Alternate Data Stream (ADS)",
  337. "Details":
  338.  
  339. "file": "C:Exes_e949c0e6ba9e052fc3b696e61cbe067a.html_file_mega_521d6c7c88"
  340.  
  341.  
  342. "file": "C:\\$Extend\\$Quota:$Q:$INDEX_ALLOCATION"
  343.  
  344.  
  345.  
  346.  
  347.  
  348. * Started Service:
  349.  
  350. * Mutexes:
  351. "Global\\CLR_CASOFF_MUTEX",
  352. "Global\\ARM Update Mutex",
  353. "Global\\Acro Update Mutex",
  354. "100184D2-BDC3-477a-B8D3-65548B67914C_3000",
  355. "Global\\100184D2-BDC3-477a-B8D3-65548B67914C_552",
  356. "com.adobe.acrobat.rna.RdrCefBrowserLock.DC",
  357. "f51ea9ec4b9a46168304433794509147",
  358. "Global\\.net clr networking",
  359. "Local\\WininetStartupMutex",
  360. "Local\\ZonesCounterMutex",
  361. "Local\\ZoneAttributeCacheCounterMutex",
  362. "Local\\ZonesCacheCounterMutex",
  363. "Local\\ZonesLockedCacheCounterMutex",
  364. "CicLoadWinStaWinSta0",
  365. "Local\\MSCTF.CtfMonitorInstMutexDefault1",
  366. "Local\\_!MSFTHISTORY!_",
  367. "Local\\c:!users!user!appdata!local!microsoft!windows!temporary internet files!content.ie5!",
  368. "Local\\c:!users!user!appdata!roaming!microsoft!windows!cookies!",
  369. "Local\\c:!users!user!appdata!local!microsoft!windows!history!history.ie5!",
  370. "Local\\!IETld!Mutex",
  371. "_!SHMSFTHISTORY!_",
  372. "Local\\c:!users!user!appdata!local!microsoft!windows!history!history.ie5!mshist012019080520190806!",
  373. "Global\\ADAP_WMI_ENTRY",
  374. "Global\\RefreshRA_Mutex",
  375. "Global\\RefreshRA_Mutex_Lib",
  376. "Global\\RefreshRA_Mutex_Flag"
  377.  
  378.  
  379. * Modified Files:
  380. "C:\\Users\\user\\AppData\\Local\\Temp\\bbb.pdf",
  381. "\\??\\PIPE\\srvsvc",
  382. "C:\\Users\\user\\AppData\\Roaming\\ltigho\\lttdyd.exe.lnk",
  383. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\lttdyd.exe.lnk",
  384. "C:\\Users\\user\\AppData\\Local\\Temp\\ltigho\\lttdyd.exe.jpg",
  385. "C:\\Users\\user\\AppData\\Local\\Temp\\svhost.exe",
  386. "C:\\Users\\user\\AppData\\Local\\Adobe\\Color\\Profiles\\wscRGB.icc",
  387. "C:\\Users\\user\\AppData\\Local\\Adobe\\Color\\Profiles\\wsRGB.icc",
  388. "C:\\Users\\user\\AppData\\Local\\Adobe\\Color\\ACECache11.lst",
  389. "C:\\Users\\user\\AppData\\LocalLow\\Adobe\\Acrobat\\DC\\ReaderMessages",
  390. "C:\\Users\\user\\AppData\\Local\\Adobe\\Acrobat\\DC\\UserCache.bin",
  391. "\\??\\pipe\\com.adobe.reader.rna.user.DC.0",
  392. "C:\\Users\\user\\AppData\\LocalLow\\Adobe\\Acrobat\\DC\\Reader\\DesktopNotification\\NotificationsDB\\notificationsDB",
  393. "C:\\Users\\user\\AppData\\LocalLow\\Adobe\\Acrobat\\DC\\Reader\\DesktopNotification\\NotificationsDB\\notificationsDB-journal",
  394. "C:\\Users\\user\\AppData\\Local\\Adobe\\Acrobat\\DC\\SharedDataEvents",
  395. "C:\\Users\\user\\AppData\\Local\\Adobe\\Acrobat\\DC\\SharedDataEvents-journal",
  396. "C:\\Users\\user\\AppData\\LocalLow\\Adobe\\Acrobat\\DC\\ConnectorIcons\\icon-190805175448Z-2308.bmp",
  397. "C:\\Users\\user\\AppData\\LocalLow\\Adobe\\Acrobat\\DC\\ReaderMessages-journal",
  398. "C:\\Users\\user\\AppData\\Local\\Temp\\acrord32_sbx\\A9Rpe9h49_1yeyp7y_1mg.tmp",
  399. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6",
  400. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\7423F88C7F265F0DEFC08EA88C3BDE45_D975BBA8033175C8D112023D8A7A8AD6",
  401. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\1E11E75149C17A93653DA7DC0B8CF53F_7A951BF9CD37814D9F57998C0A161B5B",
  402. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\1E11E75149C17A93653DA7DC0B8CF53F_7A951BF9CD37814D9F57998C0A161B5B",
  403. "C:\\Users\\user\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Security\\CRLCache\\CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl",
  404. "C:\\Users\\user\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Security\\CRLCache\\0FDED5CEB68C302B1CDB2BDDD9D0000E76539CB0.crl",
  405. "C:\\Users\\user\\AppData\\Roaming\\Adobe\\Acrobat\\DC\\Security\\addressbook.acrodata",
  406. "C:\\Users\\user\\AppData\\Roaming\\ltigho\\lttdyd.exe",
  407. "C:\\Users\\user\\AppData\\Roaming\\ltigho\\lttdyd.exe:Zone.Identifier",
  408. "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.tmp",
  409. "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.0.cs",
  410. "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.dll",
  411. "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.cmdline",
  412. "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.out",
  413. "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.err",
  414. "C:\\Users\\user\\AppData\\Roaming\\prgyj.exe",
  415. "C:\\Users\\user\\AppData\\Roaming\\prgyj.exe.config",
  416. "C:\\Users\\user\\AppData\\Local\\Temp\\CabA74D.tmp",
  417. "C:\\Users\\user\\AppData\\Local\\Temp\\TarA74E.tmp",
  418. "C:\\Users\\user\\AppData\\Local\\Temp\\CabA868.tmp",
  419. "C:\\Users\\user\\AppData\\Local\\Temp\\TarA869.tmp",
  420. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\94308059B57B3142E455B38A6EB92015",
  421. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\94308059B57B3142E455B38A6EB92015",
  422. "C:\\Users\\user\\AppData\\Local\\Temp\\CabAA5E.tmp",
  423. "C:\\Users\\user\\AppData\\Local\\Temp\\TarAA5F.tmp",
  424. "C:\\Users\\user\\AppData\\Local\\Temp\\CSC6E99.tmp",
  425. "C:\\Users\\user\\AppData\\Local\\Temp\\RES6EAA.tmp",
  426. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\index.dat",
  427. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\index.dat",
  428. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\index.dat",
  429. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\MSHist012019080520190806\\index.dat",
  430. "\\??\\PIPE\\samr",
  431. "C:\\Windows\\sysnative\\wbem\\repository\\WRITABLE.TST",
  432. "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING1.MAP",
  433. "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING2.MAP",
  434. "C:\\Windows\\sysnative\\wbem\\repository\\MAPPING3.MAP",
  435. "C:\\Windows\\sysnative\\wbem\\repository\\OBJECTS.DATA",
  436. "C:\\Windows\\sysnative\\wbem\\repository\\INDEX.BTR",
  437. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
  438. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2WMI SELF-INSTRUMENTATION EVENT PROVIDER",
  439. "\\??\\WMIDataDevice",
  440. "C:\\$Extend\\$Quota:$Q:$INDEX_ALLOCATION",
  441. "C:\\Users\\user\\AppData\\Local\\Temp\\AdobeARM.log",
  442. "\\??\\pipe\\32B6B37A-4A7D-4e00-95F2-6F0BF3DE3E001599590523thsnYaVieBoda",
  443. "C:\\Users\\user\\AppData\\Local\\Temp\\ArmUI.ini",
  444. "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl_new.h"
  445.  
  446.  
  447. * Deleted Files:
  448. "C:\\Users\\user\\AppData\\Local\\Temp\\FindMe",
  449. "C:\\Users\\user\\AppData\\Roaming\\svhost.exe",
  450. "C:\\Users\\user\\AppData\\Roaming\\ltigho\\FZQR27Y43sDbON97KOJGAg==.bat",
  451. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.2272.14622203",
  452. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2272.14622203",
  453. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.2272.14622203",
  454. "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.0.cs",
  455. "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.tmp",
  456. "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.cmdline",
  457. "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.err",
  458. "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.pdb",
  459. "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.out",
  460. "C:\\Users\\user\\AppData\\Local\\Temp\\ndoyjzi5.dll",
  461. "C:\\Users\\user\\AppData\\Local\\Temp\\CabA74D.tmp",
  462. "C:\\Users\\user\\AppData\\Local\\Temp\\TarA74E.tmp",
  463. "C:\\Users\\user\\AppData\\Local\\Temp\\CabA868.tmp",
  464. "C:\\Users\\user\\AppData\\Local\\Temp\\TarA869.tmp",
  465. "C:\\Users\\user\\AppData\\Local\\Temp\\CabAA5E.tmp",
  466. "C:\\Users\\user\\AppData\\Local\\Temp\\TarAA5F.tmp",
  467. "C:\\Users\\user\\AppData\\Local\\Temp\\RES6EAA.tmp",
  468. "C:\\Users\\user\\AppData\\Local\\Temp\\CSC6E99.tmp",
  469. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.1560.14626078",
  470. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1560.14626078",
  471. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.1560.14626078",
  472. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.1596.14626609",
  473. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1596.14626609",
  474. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.1596.14626609",
  475. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\MSHist012019052620190527\\index.dat",
  476. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\MSHist012019052620190527\\",
  477. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.4056.14930656",
  478. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.4056.14930656",
  479. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.4056.14930656"
  480.  
  481.  
  482. * Modified Registry Keys:
  483. "HKEY_CURRENT_USER\\Software\\Adobe\\Adobe Acrobat\\DC\\DiskCabs",
  484. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC",
  485. "HKEY_CURRENT_USER\\Software\\Adobe\\Adobe Synchronizer\\DC",
  486. "HKEY_CURRENT_USER\\Software\\Adobe\\CommonFiles\\Usage\\AcrobatDC",
  487. "HKEY_CURRENT_USER\\Software\\Adobe\\CommonFiles\\Usage\\Reader DC",
  488. "HKEY_CURRENT_USER\\Software\\Adobe\\CommonFiles\\Usage\\Reader 19_Acrobat19_Reader_19.10.20069",
  489. "HKEY_LOCAL_MACHINE\\System\\Acrobatbrokerserverdispatchercpp789",
  490. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Installer",
  491. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Installer\\Migrated",
  492. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Language",
  493. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Language\\UseMUI",
  494. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Language\\next",
  495. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Language\\current",
  496. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Originals",
  497. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\ExitSection",
  498. "HKEY_CURRENT_USER\\Software\\Adobe\\Adobe Synchronizer\\DC\\Acrobat.com",
  499. "HKEY_CURRENT_USER\\Software\\Adobe\\Adobe Synchronizer\\DC\\Acrobat.com.v2",
  500. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVConnector",
  501. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVConnector\\cv1",
  502. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral",
  503. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cTaskPanes",
  504. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cTaskPanes\\cBasicCommentPane",
  505. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\FTEDialog",
  506. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\FlashDebug",
  507. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\OnBoardingSection",
  508. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\OnBoardingSection\\chomeView",
  509. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\SDI",
  510. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Selection",
  511. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Window",
  512. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Window\\cAVUIPopupList",
  513. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cRecentFiles\\c1",
  514. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cRecentFiles\\c1\\aFS",
  515. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cRecentFiles\\c1\\tDIText",
  516. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cRecentFiles\\c1\\tFileName",
  517. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cRecentFiles\\c1\\sFileAncestors",
  518. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cRecentFiles\\c1\\sDI",
  519. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVGeneral\\cRecentFiles\\c1\\sDate",
  520. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVEntitlement",
  521. "HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BROWSER_EMULATION",
  522. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\FEATURE_BROWSER_EMULATION\\AcroRd32.exe",
  523. "HKEY_CURRENT_USER\\Software\\Adobe\\Adobe Synchronizer\\DC\\CredentialsV3",
  524. "HKEY_CURRENT_USER\\SOFTWARE\\Adobe\\Acrobat Reader\\DC\\Privileged",
  525. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Privileged\\bOldRecentFilesMigrated",
  526. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Workflows",
  527. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Workflows\\cServices",
  528. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AVConnector\\cIconCache",
  529. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\UsageMeasurement",
  530. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\AcroRd32_RASAPI32",
  531. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\AcroRd32_RASAPI32\\EnableFileTracing",
  532. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\AcroRd32_RASAPI32\\EnableConsoleTracing",
  533. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\AcroRd32_RASAPI32\\FileTracingMask",
  534. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\AcroRd32_RASAPI32\\ConsoleTracingMask",
  535. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\AcroRd32_RASAPI32\\MaxFileSize",
  536. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\AcroRd32_RASAPI32\\FileDirectory",
  537. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyEnable",
  538. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyServer",
  539. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\SavedLegacySettings",
  540. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Collab",
  541. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Collab\\cDocumentCenter",
  542. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Collab\\cDocumentCenter\\cSettings",
  543. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Collab\\cEmailDistribution",
  544. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Collab\\cEmailDistribution\\cSettings",
  545. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Collab\\cInternalServer",
  546. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Collab\\cInternalServer\\cSettings",
  547. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Collab\\cInitiationWizardFirstLaunch",
  548. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security",
  549. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cHandlers",
  550. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI",
  551. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI",
  552. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs",
  553. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c290FA7E61053E8763C6055E6333A99EFB83ECACB",
  554. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c290FA7E61053E8763C6055E6333A99EFB83ECACB\\cAdobe_OCSPRevChecker",
  555. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c290FA7E61053E8763C6055E6333A99EFB83ECACB\\cAdobe_OCSPRevChecker\\cAuthorizedResponder",
  556. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c290FA7E61053E8763C6055E6333A99EFB83ECACB\\cAdobe_OCSPRevChecker\\cAuthorizedResponder\\c0",
  557. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000",
  558. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_ChainBuilder",
  559. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_ChainBuilder\\cAcceptablePolicyOIDs",
  560. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_ChainBuilder\\cAcceptablePolicyOIDs\\c0",
  561. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_ChainBuilder\\cAcceptablePolicyOIDs\\c0\\cValue",
  562. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_ChainBuilder\\cAcceptablePolicyOIDs\\c1",
  563. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_ChainBuilder\\cAcceptablePolicyOIDs\\c1\\cValue",
  564. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_OCSPRevChecker",
  565. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_OCSPRevChecker\\cAuthorizedResponder",
  566. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_OCSPRevChecker\\cAuthorizedResponder\\c0",
  567. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_OCSPRevChecker\\cSendNonce",
  568. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_OCSPRevChecker\\cSendNonce\\c0",
  569. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_OCSPRevChecker\\cSignCertOID",
  570. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_OCSPRevChecker\\cSignCertOID\\c0",
  571. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_OCSPRevChecker\\cSignRequest",
  572. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_OCSPRevChecker\\cSignRequest\\c0",
  573. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_OCSPRevChecker\\cURLToConsult",
  574. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E310000\\cAdobe_OCSPRevChecker\\cURLToConsult\\c0",
  575. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000",
  576. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_ChainBuilder",
  577. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_ChainBuilder\\cAcceptablePolicyOIDs",
  578. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_ChainBuilder\\cAcceptablePolicyOIDs\\c0",
  579. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_ChainBuilder\\cAcceptablePolicyOIDs\\c0\\cValue",
  580. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_ChainBuilder\\cAcceptablePolicyOIDs\\c1",
  581. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_ChainBuilder\\cAcceptablePolicyOIDs\\c1\\cValue",
  582. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_OCSPRevChecker",
  583. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_OCSPRevChecker\\cAuthorizedResponder",
  584. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_OCSPRevChecker\\cAuthorizedResponder\\c0",
  585. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_OCSPRevChecker\\cSendNonce",
  586. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_OCSPRevChecker\\cSendNonce\\c0",
  587. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_OCSPRevChecker\\cSignCertOID",
  588. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_OCSPRevChecker\\cSignCertOID\\c0",
  589. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_OCSPRevChecker\\cSignRequest",
  590. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_OCSPRevChecker\\cSignRequest\\c0",
  591. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_OCSPRevChecker\\cURLToConsult",
  592. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E322E3834302E3131343032312E312E312E310000\\cAdobe_OCSPRevChecker\\cURLToConsult\\c0",
  593. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000",
  594. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_CRLRevChecker",
  595. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_CRLRevChecker\\cRequireAKI",
  596. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_CRLRevChecker\\cRequireAKI\\c0",
  597. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_ChainBuilder",
  598. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_ChainBuilder\\cAllowCAToIssueAC",
  599. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_ChainBuilder\\cAllowCAToIssueAC\\c0",
  600. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_ChainBuilder\\cCheckCABasicConstraints",
  601. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_ChainBuilder\\cCheckCABasicConstraints\\c0",
  602. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_OCSPRevChecker",
  603. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_OCSPRevChecker\\cAllowOCSPNoCheck",
  604. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_OCSPRevChecker\\cAllowOCSPNoCheck\\c0",
  605. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_OCSPRevChecker\\cRequireOCSPCertHash",
  606. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_OCSPRevChecker\\cRequireOCSPCertHash\\c0",
  607. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_Validation",
  608. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_Validation\\cValidityModel",
  609. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cASPKI\\cASPKI\\cCustomCertPrefs\\c312E332E33362E382E312E310000\\cAdobe_Validation\\cValidityModel\\c0",
  610. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\Security\\cPPKHandler",
  611. "HKEY_CURRENT_USER\\Software\\Microsoft\\SystemCertificates\\ADDRESSBOOK",
  612. "HKEY_CURRENT_USER\\Software\\Microsoft\\SystemCertificates\\ADDRESSBOOK\\Certificates",
  613. "HKEY_CURRENT_USER\\Software\\Microsoft\\SystemCertificates\\ADDRESSBOOK\\CRLs",
  614. "HKEY_CURRENT_USER\\Software\\Microsoft\\SystemCertificates\\ADDRESSBOOK\\CTLs",
  615. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  616. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
  617. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
  618. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012019080520190806",
  619. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012019080520190806\\CachePath",
  620. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012019080520190806\\CachePrefix",
  621. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012019080520190806\\CacheLimit",
  622. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012019080520190806\\CacheOptions",
  623. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\5.0\\Cache\\Extensible Cache\\MSHist012019080520190806\\CacheRepair",
  624. "HKEY_LOCAL_MACHINE\\Software\\Adobe\\Acrobat Reader\\DC\\AdobeViewer",
  625. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Adobe\\Acrobat Reader\\DC\\AdobeViewer\\EULA",
  626. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AdobeViewer",
  627. "HKEY_CURRENT_USER\\Software\\Adobe\\Acrobat Reader\\DC\\AdobeViewer\\EULA",
  628. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\LastServiceStart",
  629. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Wbem\\Transports\\Decoupled\\Server",
  630. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\CreationTime",
  631. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\MarshaledProxy",
  632. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\Transports\\Decoupled\\Server\\ProcessIdentifier",
  633. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\ConfigValueEssNeedsLoading",
  634. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\CIMOM\\List of event-active namespaces",
  635. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\ESS\\//./root/CIMV2\\SCM Event Provider",
  636. "HKEY_CURRENT_USER\\Software\\Adobe\\Adobe ARM\\1.0\\ARM\\iSpeedLauncherLogonTime",
  637. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\IDE\\DiskVBOX_HARDDISK___________________________1.0_____\\5&33d1638a&0&0.0.0_0-00000000-0000-0000-0000-000000000000",
  638. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\advapi32.dllMofResourceName",
  639. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\en-US\\advapi32.dll.muiMofResourceName",
  640. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\ACPI.sysACPIMOFResource",
  641. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\en-US\\ACPI.sys.muiACPIMOFResource",
  642. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\ndis.sysMofResourceName",
  643. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\en-US\\ndis.sys.muiMofResourceName",
  644. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\mssmbios.sysMofResource",
  645. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\en-US\\mssmbios.sys.muiMofResource",
  646. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\HDAudBus.sysHDAudioMofName",
  647. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\en-US\\HDAudBus.sys.muiHDAudioMofName",
  648. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\intelppm.sysPROCESSORWMI",
  649. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\en-US\\intelppm.sys.muiPROCESSORWMI",
  650. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\System32\\Drivers\\portcls.SYSPortclsMof",
  651. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\System32\\Drivers\\en-US\\portcls.SYS.muiPortclsMof",
  652. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\monitor.sysMonitorWMI"
  653.  
  654.  
  655. * Deleted Registry Keys:
  656. "HKEY_CURRENT_USER\\Software\\Adobe\\CommonFiles\\Usage\\Reader DC\\OptIn",
  657. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyOverride",
  658. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoConfigURL",
  659. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  660. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  661. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  662. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  663. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LowRegistry\\AddToFavoritesInitialSelection",
  664. "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\LowRegistry\\AddToFeedsInitialSelection",
  665. "HKEY_CURRENT_USER\\Software\\Adobe\\Adobe ARM\\1.0\\ARM\\iNotify",
  666. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\monitor.sysMonitorWMI"
  667.  
  668.  
  669. * DNS Communications:
  670.  
  671. "type": "A",
  672. "request": "qstorm.chickenkiller.com",
  673. "answers":
  674.  
  675. "data": "193.161.193.99",
  676. "type": "A"
  677.  
  678.  
  679.  
  680.  
  681.  
  682. * Domains:
  683.  
  684. "ip": "193.161.193.99",
  685. "domain": "qstorm.chickenkiller.com"
  686.  
  687.  
  688.  
  689. * Network Communication - ICMP:
  690.  
  691. * Network Communication - HTTP:
  692.  
  693. "count": 1,
  694. "body": "",
  695. "uri": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
  696. "user-agent": "Microsoft-CryptoAPI/6.1",
  697. "method": "GET",
  698. "host": "www.download.windowsupdate.com",
  699. "version": "1.1",
  700. "path": "/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
  701. "data": "GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1\r\nCache-Control: max-age = 86403\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Fri, 22 Feb 2019 16:53:13 GMT\r\nIf-None-Match: \"80e22c19cfcad41:0\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: www.download.windowsupdate.com\r\n\r\n",
  702. "port": 80
  703.  
  704.  
  705. "count": 1,
  706. "body": "",
  707. "uri": "http://acroipm2.adobe.com/19/rdr/ENU/win/nooem/none/consumer/message.zip",
  708. "user-agent": "IPM",
  709. "method": "GET",
  710. "host": "acroipm2.adobe.com",
  711. "version": "1.1",
  712. "path": "/19/rdr/ENU/win/nooem/none/consumer/message.zip",
  713. "data": "GET /19/rdr/ENU/win/nooem/none/consumer/message.zip HTTP/1.1\r\nAccept: */*\r\nIf-Modified-Since: Mon, 01 Jan 1970 00:00:00 GMT\r\nUser-Agent: IPM\r\nHost: acroipm2.adobe.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  714. "port": 80
  715.  
  716.  
  717. "count": 1,
  718. "body": "",
  719. "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D",
  720. "user-agent": "Microsoft-CryptoAPI/6.1",
  721. "method": "GET",
  722. "host": "ocsp.digicert.com",
  723. "version": "1.1",
  724. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D",
  725. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAH9o%2BtuynXIiEOLckvPvJE%3D HTTP/1.1\r\nCache-Control: max-age = 142986\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Tue, 28 May 2019 07:40:28 GMT\r\nIf-None-Match: \"5cece5ec-1d7\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
  726. "port": 80
  727.  
  728.  
  729. "count": 1,
  730. "body": "",
  731. "uri": "http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEAiybqFfIme0q2SePjjqIls%3D",
  732. "user-agent": "Microsoft-CryptoAPI/6.1",
  733. "method": "GET",
  734. "host": "ocsp.digicert.com",
  735. "version": "1.1",
  736. "path": "/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEAiybqFfIme0q2SePjjqIls%3D",
  737. "data": "GET /MFEwTzBNMEswSTAJBgUrDgMCGgUABBQQX6Z6gAidtSefNc6DC0OInqPHDQQUD4BhHIIxYdUvKOeNRji0LOHG2eICEAiybqFfIme0q2SePjjqIls%3D HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: ocsp.digicert.com\r\n\r\n",
  738. "port": 80
  739.  
  740.  
  741.  
  742. * Network Communication - SMTP:
  743.  
  744. * Network Communication - Hosts:
  745.  
  746. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment