paladin316

Exes_128b26f383a1f6bb071df23e1cfb82af_exe_2019-08-10_13_30.txt

Aug 10th, 2019
2,039
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 25.55 KB | None | 0 0
  1.  
  2. * MalFamily: "Avemaria"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_128b26f383a1f6bb071df23e1cfb82af.exe"
  7. * File Size: 1654784
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "e4f54bbd59b269cffb0d0bf1a4ac0f37d931af813c9944991cc7dbeb9bffcd6b"
  10. * MD5: "128b26f383a1f6bb071df23e1cfb82af"
  11. * SHA1: "c9dab1c522d5cff0defb801acf634d948384e79e"
  12. * SHA512: "a2003412b7cd56e5d418de7564e00ff873235350d81e540f57be4f6eb47e001e1674be509f70b78dff1db288fa0fe9d7856b7f4ebc9ff7c94f6cbc4c55ea0b2b"
  13. * CRC32: "6670085F"
  14. * SSDEEP: "24576:Pj2iZXSjoekb9TXahIoFRFGM/SJLMJ3GAOxW4PLSf:ejoekb9LYIWRdSuFShPLSf"
  15.  
  16. * Process Execution:
  17. "Exes_128b26f383a1f6bb071df23e1cfb82af.exe",
  18. "powershell.exe",
  19. "images.exe",
  20. "powershell.exe",
  21. "cmd.exe",
  22. "services.exe",
  23. "svchost.exe",
  24. "WmiPrvSE.exe",
  25. "WmiPrvSE.exe",
  26. "svchost.exe",
  27. "svchost.exe",
  28. "svchost.exe",
  29. "lsass.exe",
  30. "taskhost.exe",
  31. "lsm.exe",
  32. "WMIADAP.exe"
  33.  
  34.  
  35. * Executed Commands:
  36. "powershell Add-MpPreference -ExclusionPath C:\\",
  37. "C:\\Windows\\system32\\wbem\\wmiprvse.exe -secured -Embedding",
  38. "C:\\Windows\\system32\\wbem\\wmiprvse.exe -Embedding",
  39. "C:\\Windows\\System32\\svchost.exe -k NetworkService",
  40. "C:\\Windows\\System32\\svchost.exe -k LocalSystemNetworkRestricted",
  41. "C:\\Windows\\system32\\lsass.exe"
  42.  
  43.  
  44. * Signatures Detected:
  45.  
  46. "Description": "Attempts to connect to a dead IP:Port (2 unique times)",
  47. "Details":
  48.  
  49. "IP": "66.154.103.133:80"
  50.  
  51.  
  52. "IP": "172.217.5.110:80"
  53.  
  54.  
  55.  
  56.  
  57. "Description": "Creates RWX memory",
  58. "Details":
  59.  
  60.  
  61. "Description": "A process attempted to delay the analysis task.",
  62. "Details":
  63.  
  64. "Process": "WmiPrvSE.exe tried to sleep 540 seconds, actually delayed analysis time by 0 seconds"
  65.  
  66.  
  67. "Process": "images.exe tried to sleep 543 seconds, actually delayed analysis time by 0 seconds"
  68.  
  69.  
  70. "Process": "cmd.exe tried to sleep 300 seconds, actually delayed analysis time by 0 seconds"
  71.  
  72.  
  73.  
  74.  
  75. "Description": "Loads a driver",
  76. "Details":
  77.  
  78. "driver service name": "\\Registry\\Machine\\System\\CurrentControlSet\\Services\\RDPDR"
  79.  
  80.  
  81.  
  82.  
  83. "Description": "Reads data out of its own binary image",
  84. "Details":
  85.  
  86. "self_read": "process: images.exe, pid: 1200, offset: 0x00000000, length: 0x00194000"
  87.  
  88.  
  89.  
  90.  
  91. "Description": "A process created a hidden window",
  92. "Details":
  93.  
  94. "Process": "images.exe -> C:\\Windows\\System32\\cmd.exe"
  95.  
  96.  
  97.  
  98.  
  99. "Description": "Drops a binary and executes it",
  100. "Details":
  101.  
  102. "binary": "C:\\ProgramData\\images.exe"
  103.  
  104.  
  105.  
  106.  
  107. "Description": "Attempts to remove evidence of file being downloaded from the Internet",
  108. "Details":
  109.  
  110. "file": "C:\\ProgramData\\images.exe:Zone.Identifier"
  111.  
  112.  
  113.  
  114.  
  115. "Description": "Code injection with CreateRemoteThread in a remote process",
  116. "Details":
  117.  
  118. "Injection": "images.exe(1200) -> cmd.exe(3060)"
  119.  
  120.  
  121.  
  122.  
  123. "Description": "Tries to suspend Cuckoo threads to prevent logging of malicious activity",
  124. "Details":
  125.  
  126. "Process": "svchost.exe (2040)"
  127.  
  128.  
  129.  
  130.  
  131. "Description": "Attempts to stop active services",
  132. "Details":
  133.  
  134. "servicename": "UmRdpService"
  135.  
  136.  
  137.  
  138.  
  139. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  140. "Details":
  141.  
  142. "Spam": "services.exe (504) called API GetSystemTimeAsFileTime 7986682 times"
  143.  
  144.  
  145.  
  146.  
  147. "Description": "Steals private information from local Internet browsers",
  148. "Details":
  149.  
  150. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data"
  151.  
  152.  
  153.  
  154.  
  155. "Description": "Installs itself for autorun at Windows startup",
  156. "Details":
  157.  
  158. "key": "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\Images"
  159.  
  160.  
  161. "data": "C:\\ProgramData\\images.exe"
  162.  
  163.  
  164. "key": "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Parameters\\ServiceDll"
  165.  
  166.  
  167. "data": "%ProgramFiles%\\Microsoft DN1\\sqlmap.dll"
  168.  
  169.  
  170.  
  171.  
  172. "Description": "Creates a hidden or system file",
  173. "Details":
  174.  
  175. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms~RF111bf39.TMP"
  176.  
  177.  
  178.  
  179.  
  180. "Description": "File has been identified by 47 Antiviruses on VirusTotal as malicious",
  181. "Details":
  182.  
  183. "MicroWorld-eScan": "Trojan.GenericKD.41528553"
  184.  
  185.  
  186. "McAfee": "Artemis!128B26F383A1"
  187.  
  188.  
  189. "Cylance": "Unsafe"
  190.  
  191.  
  192. "K7AntiVirus": "Riskware ( 0040eff71 )"
  193.  
  194.  
  195. "Alibaba": "TrojanSpy:Win32/AveMaria.8d532b9a"
  196.  
  197.  
  198. "K7GW": "Riskware ( 0040eff71 )"
  199.  
  200.  
  201. "F-Prot": "W32/Kryptik.AAY.gen!Eldorado"
  202.  
  203.  
  204. "Symantec": "Trojan.Gen.MBT"
  205.  
  206.  
  207. "ESET-NOD32": "a variant of Win32/Kryptik.GVEK"
  208.  
  209.  
  210. "APEX": "Malicious"
  211.  
  212.  
  213. "Avast": "Win32:Malware-gen"
  214.  
  215.  
  216. "ClamAV": "Win.Malware.Avemaria-7101230-0"
  217.  
  218.  
  219. "GData": "Trojan.GenericKD.41528553"
  220.  
  221.  
  222. "Kaspersky": "Trojan-Spy.Win32.AveMaria.bnw"
  223.  
  224.  
  225. "BitDefender": "Trojan.GenericKD.41528553"
  226.  
  227.  
  228. "NANO-Antivirus": "Trojan.Win32.AveMaria.fusdty"
  229.  
  230.  
  231. "Paloalto": "generic.ml"
  232.  
  233.  
  234. "AegisLab": "Trojan.Win32.AveMaria.l!c"
  235.  
  236.  
  237. "Endgame": "malicious (high confidence)"
  238.  
  239.  
  240. "Sophos": "Mal/Generic-S"
  241.  
  242.  
  243. "F-Secure": "Trojan.TR/Crypt.Agent.abvct"
  244.  
  245.  
  246. "DrWeb": "Trojan.DownLoader29.52705"
  247.  
  248.  
  249. "VIPRE": "Trojan.Win32.Generic!BT"
  250.  
  251.  
  252. "McAfee-GW-Edition": "BehavesLike.Win32.Injector.tm"
  253.  
  254.  
  255. "Trapmine": "suspicious.low.ml.score"
  256.  
  257.  
  258. "FireEye": "Generic.mg.128b26f383a1f6bb"
  259.  
  260.  
  261. "Emsisoft": "Trojan.Crypt (A)"
  262.  
  263.  
  264. "SentinelOne": "DFI - Suspicious PE"
  265.  
  266.  
  267. "Cyren": "W32/Kryptik.AAY.gen!Eldorado"
  268.  
  269.  
  270. "Avira": "TR/Crypt.Agent.abvct"
  271.  
  272.  
  273. "MAX": "malware (ai score=86)"
  274.  
  275.  
  276. "Antiy-AVL": "Trojan/Win32.Wacatac"
  277.  
  278.  
  279. "Arcabit": "Trojan.Generic.D279ACE9"
  280.  
  281.  
  282. "ViRobot": "Trojan.Win32.Z.Wacatac.1654784.A"
  283.  
  284.  
  285. "ZoneAlarm": "Trojan-Spy.Win32.AveMaria.bnw"
  286.  
  287.  
  288. "Microsoft": "Trojan:Win32/Wacatac.B!ml"
  289.  
  290.  
  291. "AhnLab-V3": "Malware/Win32.Generic.C3366757"
  292.  
  293.  
  294. "Acronis": "suspicious"
  295.  
  296.  
  297. "VBA32": "BScope.TrojanSpy.AveMaria"
  298.  
  299.  
  300. "ALYac": "Trojan.GenericKD.41528553"
  301.  
  302.  
  303. "Ad-Aware": "Trojan.GenericKD.41528553"
  304.  
  305.  
  306. "Rising": "[email protected] (RDML:fP1lzJyaoezFxVnk1KqNpA)"
  307.  
  308.  
  309. "Fortinet": "W32/AveMaria.BNW!tr"
  310.  
  311.  
  312. "AVG": "Win32:Malware-gen"
  313.  
  314.  
  315. "Panda": "Trj/GdSda.A"
  316.  
  317.  
  318. "CrowdStrike": "win/malicious_confidence_100% (W)"
  319.  
  320.  
  321. "Qihoo-360": "Win32/Trojan.Spy.ddb"
  322.  
  323.  
  324.  
  325.  
  326. "Description": "Attempts to modify proxy settings",
  327. "Details":
  328.  
  329.  
  330. "Description": "Clamav Hits in Target/Dropped/SuriExtracted",
  331. "Details":
  332.  
  333. "target": "clamav:Win.Malware.Avemaria-7101230-0, sha256:e4f54bbd59b269cffb0d0bf1a4ac0f37d931af813c9944991cc7dbeb9bffcd6b, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  334.  
  335.  
  336. "dropped": "clamav:Win.Malware.Avemaria-7101230-0, sha256:e4f54bbd59b269cffb0d0bf1a4ac0f37d931af813c9944991cc7dbeb9bffcd6b , guest_paths:C:\\ProgramData\\images.exe, type:PE32 executable (GUI) Intel 80386, for MS Windows"
  337.  
  338.  
  339.  
  340.  
  341. "Description": "Creates a copy of itself",
  342. "Details":
  343.  
  344. "copy": "C:\\ProgramData\\images.exe"
  345.  
  346.  
  347.  
  348.  
  349. "Description": "Harvests information related to installed mail clients",
  350. "Details":
  351.  
  352. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows Messaging Subsystem\\Profiles\\9375CFF0413111d3B88A00104B2A6676"
  353.  
  354.  
  355. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676"
  356.  
  357.  
  358. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\POP3 Server"
  359.  
  360.  
  361. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\SMTP Password"
  362.  
  363.  
  364. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\Account Name"
  365.  
  366.  
  367. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\SMTP Server"
  368.  
  369.  
  370. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\Email"
  371.  
  372.  
  373. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\HTTP Password"
  374.  
  375.  
  376. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676"
  377.  
  378.  
  379. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\HTTP Password"
  380.  
  381.  
  382. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\IMAP Password"
  383.  
  384.  
  385. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\POP3 Password"
  386.  
  387.  
  388. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\Email"
  389.  
  390.  
  391. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\POP3 User"
  392.  
  393.  
  394. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\POP3 Server"
  395.  
  396.  
  397. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\SMTP Password"
  398.  
  399.  
  400. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\POP3 User"
  401.  
  402.  
  403. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\Account Name"
  404.  
  405.  
  406. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\IMAP Password"
  407.  
  408.  
  409. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001"
  410.  
  411.  
  412. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000001\\SMTP Server"
  413.  
  414.  
  415. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002\\POP3 Password"
  416.  
  417.  
  418. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000002"
  419.  
  420.  
  421.  
  422.  
  423. "Description": "Collects information to fingerprint the system",
  424. "Details":
  425.  
  426.  
  427.  
  428. * Started Service:
  429. "TermService",
  430. "VaultSvc",
  431. "UmRdpService"
  432.  
  433.  
  434. * Mutexes:
  435. "Local\\_!MSFTHISTORY!_",
  436. "Local\\c:!users!user!appdata!local!microsoft!windows!temporary internet files!content.ie5!",
  437. "Local\\c:!users!user!appdata!roaming!microsoft!windows!cookies!",
  438. "Local\\c:!users!user!appdata!local!microsoft!windows!history!history.ie5!",
  439. "Local\\WininetStartupMutex",
  440. "Local\\WininetConnectionMutex",
  441. "Local\\WininetProxyRegistryMutex",
  442. "Global\\CLR_CASOFF_MUTEX",
  443. "TSLicensingLock",
  444. "Global\\ADAP_WMI_ENTRY",
  445. "Global\\RefreshRA_Mutex",
  446. "Global\\RefreshRA_Mutex_Lib",
  447. "Global\\RefreshRA_Mutex_Flag"
  448.  
  449.  
  450. * Modified Files:
  451. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\Temporary Internet Files\\Content.IE5\\index.dat",
  452. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Cookies\\index.dat",
  453. "C:\\Users\\user\\AppData\\Local\\Microsoft\\Windows\\History\\History.IE5\\index.dat",
  454. "C:\\ProgramData\\images.exe",
  455. "C:\\Users\\user\\AppData\\Local\\Temp\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
  456. "\\??\\PIPE\\srvsvc",
  457. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\VCO17EH231GWRBCBG8WV.temp",
  458. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms",
  459. "C:\\Users\\user\\AppData\\Local\\Microsoft Vision\\10-08-2019_10.47.02",
  460. "\\??\\PIPE\\samr",
  461. "C:\\Program Files\\Microsoft DN1\\sqlmap.dll",
  462. "C:\\Program Files\\Microsoft DN1\\rdpwrap.ini",
  463. "C:\\Users\\user\\AppData\\Roaming\\z.og.He.tmp",
  464. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\LTJOWTHZ7DY3FPHUR4DS.temp",
  465. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms~RF111bf39.TMP",
  466. "C:\\Windows\\inf\\setupapi.dev.log",
  467. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
  468. "C:\\Windows\\sysnative\\LogFiles\\Scm\\5869f1c1-01d7-41f7-84b7-715672259fa8",
  469. "C:\\rdpwrap.txt",
  470. "\\Device\\Termdd",
  471. "\\Device\\RdpDr",
  472. "\\??\\root#umbus#0000#65a9a6cf-64cd-480b-843e-32c86e1ba19f",
  473. "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl_new.h",
  474. "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl.h",
  475. "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl_new.ini",
  476. "\\??\\WMIDataDevice"
  477.  
  478.  
  479. * Deleted Files:
  480. "C:\\ProgramData\\images.exe:Zone.Identifier",
  481. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\VCO17EH231GWRBCBG8WV.temp",
  482. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.876.17906234",
  483. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.876.17906234",
  484. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.876.17907531",
  485. "C:\\Users\\user\\AppData\\Roaming\\z.og.He.tmp",
  486. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms~RF111bf39.TMP",
  487. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.3068.17940296",
  488. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.3068.17940296",
  489. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.3068.17940296",
  490. "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl.h",
  491. "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl_new.h"
  492.  
  493.  
  494. * Modified Registry Keys:
  495. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyEnable",
  496. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyServer",
  497. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\SavedLegacySettings",
  498. "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\MediaResources\\msvideo",
  499. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\MaxConnectionsPer1_0Server",
  500. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\MaxConnectionsPerServer",
  501. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\IL94FDUYLH",
  502. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\IL94FDUYLH\\inst",
  503. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Run\\Images",
  504. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  505. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\images_RASAPI32",
  506. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\images_RASAPI32\\EnableFileTracing",
  507. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\images_RASAPI32\\EnableConsoleTracing",
  508. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\images_RASAPI32\\FileTracingMask",
  509. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\images_RASAPI32\\ConsoleTracingMask",
  510. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\images_RASAPI32\\MaxFileSize",
  511. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\images_RASAPI32\\FileDirectory",
  512. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\UserList",
  513. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\SpecialAccounts\\UserList\\ptCryAF",
  514. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\IL94FDUYLH\\rudp",
  515. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\IL94FDUYLH\\rpdp",
  516. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Parameters\\ServiceDll",
  517. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\fDenyTSConnections",
  518. "HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\Licensing Core",
  519. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\Licensing Core\\EnableConcurrentSessions",
  520. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\AllowMultipleTSSessions",
  521. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\CurrentStatus",
  522. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\CurrentStatus\\StartTime",
  523. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Device Installer\\CurrentStatus\\Progress",
  524. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties",
  525. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29",
  526. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29\\00000009",
  527. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29\\00000009\\00000000",
  528. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29\\00000009\\00000000\\Type",
  529. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Enum\\UMB\\UMB\\1&841921d&0&TSBUS\\Properties\\83da6326-97a6-4088-9453-a1923f573b29\\00000009\\00000000\\Data",
  530. "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SetupapiLogStatus",
  531. "HKEY_LOCAL_MACHINE\\SYSTEM\\Setup\\SetupapiLogStatus\\setupapi.dev.log",
  532. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\TermService\\Type",
  533. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\UmRdpService\\Type",
  534. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\Type",
  535. "HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Terminal Server\\RCM\\Secrets",
  536. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\Secrets\\L$HYDRAENCKEY_28ada6da-d622-11d1-9cb9-00c04fb16e75",
  537. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\Certificate",
  538. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\Secrets\\L$HYDRAENCKEY_52d1ad03-4565-44f3-8bfd-bbb0591f4b9d",
  539. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\CertificateOld",
  540. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\IDE\\DiskVBOX_HARDDISK___________________________1.0_____\\5&33d1638a&0&0.0.0_0-00000000-0000-0000-0000-000000000000",
  541. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\advapi32.dllMofResourceName",
  542. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\en-US\\advapi32.dll.muiMofResourceName",
  543. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\ACPI.sysACPIMOFResource",
  544. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\en-US\\ACPI.sys.muiACPIMOFResource",
  545. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\ndis.sysMofResourceName",
  546. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\en-US\\ndis.sys.muiMofResourceName",
  547. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\mssmbios.sysMofResource",
  548. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\en-US\\mssmbios.sys.muiMofResource",
  549. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\HDAudBus.sysHDAudioMofName",
  550. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\en-US\\HDAudBus.sys.muiHDAudioMofName",
  551. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\intelppm.sysPROCESSORWMI",
  552. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\en-US\\intelppm.sys.muiPROCESSORWMI",
  553. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\System32\\Drivers\\portcls.SYSPortclsMof",
  554. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\System32\\Drivers\\en-US\\portcls.SYS.muiPortclsMof",
  555. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\monitor.sysMonitorWMI"
  556.  
  557.  
  558. * Deleted Registry Keys:
  559. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyOverride",
  560. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoConfigURL",
  561. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\Terminal Server\\RCM\\OverrideProtocol_Object",
  562. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\monitor.sysMonitorWMI"
  563.  
  564.  
  565. * DNS Communications:
  566.  
  567. "type": "A",
  568. "request": "google.com",
  569. "answers":
  570.  
  571. "data": "172.217.5.110",
  572. "type": "A"
  573.  
  574.  
  575.  
  576.  
  577. "type": "A",
  578. "request": "dultrasolutions.duckdns.org",
  579. "answers":
  580.  
  581. "data": "170.130.31.104",
  582. "type": "A"
  583.  
  584.  
  585.  
  586.  
  587.  
  588. * Domains:
  589.  
  590. "ip": "170.130.31.104",
  591. "domain": "dultrasolutions.duckdns.org"
  592.  
  593.  
  594. "ip": "172.217.5.110",
  595. "domain": "google.com"
  596.  
  597.  
  598.  
  599. * Network Communication - ICMP:
  600.  
  601. * Network Communication - HTTP:
  602.  
  603. * Network Communication - SMTP:
  604.  
  605. * Network Communication - Hosts:
  606.  
  607. * Network Communication - IRC:
Add Comment
Please, Sign In to add comment