paladin316

VBS_c7338a67ba5005d7d220214dbbfead94_php_2019-07-02_17_30.json

Jul 2nd, 2019
2,145
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 26.38 KB | None | 0 0
  1.  
  2. [*] MalFamily: ""
  3.  
  4. [*] MalScore: 10.0
  5.  
  6. [*] File Name: "VBS_c7338a67ba5005d7d220214dbbfead94.php"
  7. [*] File Size: 91845
  8. [*] File Type: "Zip archive data, at least v2.0 to extract"
  9. [*] SHA256: "7d72bc2925f47ff8ff99028eb72f125a27f1a76fb530d670504955a2391aa7cd"
  10. [*] MD5: "c7338a67ba5005d7d220214dbbfead94"
  11. [*] SHA1: "1959ef68b6aa90d0f980691609e578f6c304dcce"
  12. [*] SHA512: "fc4e4b156a8ff48bd645fe8fe76d059026af2a8ed9a37a6ecf77f7cee7096841883c35cc8547ae58205b8565bef3f1b9b1ab1d9a1f27e912d43882e893f1db94"
  13. [*] CRC32: "941CC6ED"
  14. [*] SSDEEP: "1536:8xqnudf0OVMUEKOytXM2Ds6uCvGLgCKhsHiX0yRafqYEnkYngaMbuuxt6:8OOBEKHO246JO0hNEyR0qfdgaMb7xg"
  15.  
  16. [*] Process Execution: [
  17. "wscript.exe",
  18. "GItXn.exe",
  19. "cmd.exe",
  20. "powershell.exe",
  21. "cmd.exe",
  22. "sc.exe",
  23. "cmd.exe",
  24. "sc.exe",
  25. "cmd.exe",
  26. "sc.exe",
  27. "cmd.exe",
  28. "sc.exe",
  29. "cmd.exe",
  30. "powershell.exe",
  31. "svchost.exe",
  32. "services.exe",
  33. "lsass.exe"
  34. ]
  35.  
  36. [*] Signatures Detected: [
  37. {
  38. "Description": "Attempts to connect to a dead IP:Port (3 unique times)",
  39. "Details": [
  40. {
  41. "IP": "64.37.52.189:443"
  42. },
  43. {
  44. "IP": "8.248.83.254:80"
  45. },
  46. {
  47. "IP": "192.35.177.64:80"
  48. }
  49. ]
  50. },
  51. {
  52. "Description": "Creates RWX memory",
  53. "Details": []
  54. },
  55. {
  56. "Description": "Possible date expiration check, exits too soon after checking local time",
  57. "Details": [
  58. {
  59. "process": "cmd.exe, PID 2252"
  60. }
  61. ]
  62. },
  63. {
  64. "Description": "A process created a hidden window",
  65. "Details": [
  66. {
  67. "Process": "GItXn.exe -> cmd"
  68. },
  69. {
  70. "Process": "GItXn.exe -> cmd"
  71. },
  72. {
  73. "Process": "GItXn.exe -> cmd"
  74. }
  75. ]
  76. },
  77. {
  78. "Description": "Drops a binary and executes it",
  79. "Details": [
  80. {
  81. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\GItXn.exe"
  82. }
  83. ]
  84. },
  85. {
  86. "Description": "Performs some HTTP requests",
  87. "Details": [
  88. {
  89. "url": "http://apps.identrust.com/roots/dstrootcax3.p7c"
  90. },
  91. {
  92. "url": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab"
  93. }
  94. ]
  95. },
  96. {
  97. "Description": "Attempts to stop active services",
  98. "Details": [
  99. {
  100. "servicename": "WinDefend"
  101. }
  102. ]
  103. },
  104. {
  105. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  106. "Details": [
  107. {
  108. "Spam": "services.exe (504) called API GetSystemTimeAsFileTime 7499023 times"
  109. }
  110. ]
  111. },
  112. {
  113. "Description": "Spoofs its process name and/or associated pathname to appear as a legitimate process",
  114. "Details": [
  115. {
  116. "modified_name": "svchost.exe",
  117. "modified_path": "C:\\Users\\user\\AppData\\Local\\Temp\\GItXn.exe",
  118. "original_name": "svchost.exe",
  119. "original_path": "C:\\Windows\\system32\\svchost.exe"
  120. }
  121. ]
  122. },
  123. {
  124. "Description": "Creates a hidden or system file",
  125. "Details": [
  126. {
  127. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF16c1802.TMP"
  128. }
  129. ]
  130. },
  131. {
  132. "Description": "Attempts to disable Windows Defender",
  133. "Details": []
  134. }
  135. ]
  136.  
  137. [*] Started Service: [
  138. "KeyIso"
  139. ]
  140.  
  141. [*] Executed Commands: [
  142. "C:\\Users\\user\\AppData\\Local\\Temp\\GItXn.exe",
  143. "\"C:\\Windows\\System32\\cmd.exe\" /c powershell Set-MpPreference -DisableRealtimeMonitoring $true",
  144. "cmd /c powershell Set-MpPreference -DisableRealtimeMonitoring $true",
  145. "\"C:\\Windows\\System32\\cmd.exe\" /c sc stop WinDefend",
  146. "cmd /c sc stop WinDefend",
  147. "\"C:\\Windows\\System32\\cmd.exe\" /c sc delete WinDefend",
  148. "cmd /c sc delete WinDefend",
  149. "C:\\Windows\\system32\\cmd.exe /c sc stop WinDefend",
  150. "C:\\Windows\\system32\\cmd.exe /c sc delete WinDefend",
  151. "C:\\Windows\\system32\\cmd.exe /c powershell Set-MpPreference -DisableRealtimeMonitoring $true",
  152. "C:\\Windows\\system32\\svchost.exe",
  153. "powershell Set-MpPreference -DisableRealtimeMonitoring $true",
  154. "sc stop WinDefend",
  155. "sc delete WinDefend",
  156. "C:\\Windows\\system32\\lsass.exe"
  157. ]
  158.  
  159. [*] Mutexes: [
  160. "Local\\ZoneAttributeCacheCounterMutex",
  161. "Local\\ZonesCacheCounterMutex",
  162. "Local\\ZonesLockedCacheCounterMutex",
  163. "Global\\CLR_CASOFF_MUTEX",
  164. "Global\\838B6C9EB27932960"
  165. ]
  166.  
  167. [*] Modified Files: [
  168. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\E0F5C59F9FA661F6F4C50B87FEF3A15A",
  169. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\E0F5C59F9FA661F6F4C50B87FEF3A15A",
  170. "C:\\Users\\user\\AppData\\Local\\Temp\\Cab2443.tmp",
  171. "C:\\Users\\user\\AppData\\Local\\Temp\\Tar2454.tmp",
  172. "C:\\Users\\user\\AppData\\Local\\Temp\\Cab2493.tmp",
  173. "C:\\Users\\user\\AppData\\Local\\Temp\\Tar2494.tmp",
  174. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\MetaData\\94308059B57B3142E455B38A6EB92015",
  175. "C:\\Users\\user\\AppData\\LocalLow\\Microsoft\\CryptnetUrlCache\\Content\\94308059B57B3142E455B38A6EB92015",
  176. "C:\\Users\\user\\AppData\\Local\\Temp\\Cab26F6.tmp",
  177. "C:\\Users\\user\\AppData\\Local\\Temp\\Tar2707.tmp",
  178. "C:\\Users\\user\\AppData\\Local\\Temp\\GItXn.exe",
  179. "\\Device\\NamedPipe",
  180. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\S-1-5-21-0000000000-0000000000-0000000000-1000\\00000000-0000-0000-0000-000000000000b_00000000-0000-0000-0000-000000000000",
  181. "C:\\Users\\user\\AppData\\Local\\Temp\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
  182. "\\??\\PIPE\\srvsvc",
  183. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\4ULV7NRKSJAPW3JHX3IJ.temp",
  184. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF16c1802.TMP",
  185. "C:\\Windows\\SysWOW64\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
  186. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\MTA1P34QF1K6ELPKUYGK.temp",
  187. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\d93f411851d7c929.customDestinations-ms"
  188. ]
  189.  
  190. [*] Deleted Files: [
  191. "C:\\Users\\user\\AppData\\Local\\Temp\\Cab2443.tmp",
  192. "C:\\Users\\user\\AppData\\Local\\Temp\\Tar2454.tmp",
  193. "C:\\Users\\user\\AppData\\Local\\Temp\\Cab2493.tmp",
  194. "C:\\Users\\user\\AppData\\Local\\Temp\\Tar2494.tmp",
  195. "C:\\Users\\user\\AppData\\Local\\Temp\\Cab26F6.tmp",
  196. "C:\\Users\\user\\AppData\\Local\\Temp\\Tar2707.tmp",
  197. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF16c1802.TMP",
  198. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2416.23861515",
  199. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2416.23861515",
  200. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2416.23861531",
  201. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\MTA1P34QF1K6ELPKUYGK.temp",
  202. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\security.config.cch.2396.23882843",
  203. "C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2396.23882843",
  204. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\security.config.cch.2396.23882859"
  205. ]
  206.  
  207. [*] Modified Registry Keys: [
  208. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  209. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
  210. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
  211. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender",
  212. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\DisableAntiSpyware",
  213. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection",
  214. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableBehaviorMonitoring",
  215. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableOnAccessProtection",
  216. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableOnRealtimeEnable",
  217. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableIOAVProtection",
  218. "DisableNotifications"
  219. ]
  220.  
  221. [*] Deleted Registry Keys: [
  222. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  223. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  224. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  225. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName"
  226. ]
  227.  
  228. [*] DNS Communications: [
  229. {
  230. "type": "A",
  231. "request": "holahospice.org",
  232. "answers": [
  233. {
  234. "data": "64.37.52.189",
  235. "type": "A"
  236. }
  237. ]
  238. },
  239. {
  240. "type": "A",
  241. "request": "apps.identrust.com",
  242. "answers": [
  243. {
  244. "data": "192.35.177.64",
  245. "type": "A"
  246. },
  247. {
  248. "data": "apps.digsigtrust.com",
  249. "type": "CNAME"
  250. }
  251. ]
  252. }
  253. ]
  254.  
  255. [*] Domains: [
  256. {
  257. "ip": "192.35.177.64",
  258. "domain": "apps.identrust.com"
  259. },
  260. {
  261. "ip": "64.37.52.189",
  262. "domain": "holahospice.org"
  263. }
  264. ]
  265.  
  266. [*] Network Communication - ICMP: []
  267.  
  268. [*] Network Communication - HTTP: [
  269. {
  270. "count": 1,
  271. "body": "",
  272. "uri": "http://apps.identrust.com/roots/dstrootcax3.p7c",
  273. "user-agent": "Microsoft-CryptoAPI/6.1",
  274. "method": "GET",
  275. "host": "apps.identrust.com",
  276. "version": "1.1",
  277. "path": "/roots/dstrootcax3.p7c",
  278. "data": "GET /roots/dstrootcax3.p7c HTTP/1.1\r\nConnection: Keep-Alive\r\nAccept: */*\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: apps.identrust.com\r\n\r\n",
  279. "port": 80
  280. },
  281. {
  282. "count": 1,
  283. "body": "",
  284. "uri": "http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
  285. "user-agent": "Microsoft-CryptoAPI/6.1",
  286. "method": "GET",
  287. "host": "www.download.windowsupdate.com",
  288. "version": "1.1",
  289. "path": "/msdownload/update/v3/static/trustedr/en/authrootstl.cab",
  290. "data": "GET /msdownload/update/v3/static/trustedr/en/authrootstl.cab HTTP/1.1\r\nCache-Control: max-age = 86403\r\nConnection: Keep-Alive\r\nAccept: */*\r\nIf-Modified-Since: Fri, 22 Feb 2019 16:53:13 GMT\r\nIf-None-Match: \"80e22c19cfcad41:0\"\r\nUser-Agent: Microsoft-CryptoAPI/6.1\r\nHost: www.download.windowsupdate.com\r\n\r\n",
  291. "port": 80
  292. }
  293. ]
  294.  
  295. [*] Network Communication - SMTP: []
  296.  
  297. [*] Network Communication - Hosts: []
  298.  
  299. [*] Network Communication - IRC: []
  300.  
  301. [*] Static Analysis: {
  302. "office": {
  303. "Metadata": {
  304. "HasMacros": "No"
  305. }
  306. }
  307. }
  308.  
  309. [*] Resolved APIs: [
  310. "advapi32.dll.SaferIdentifyLevel",
  311. "advapi32.dll.SaferComputeTokenFromLevel",
  312. "advapi32.dll.SaferCloseLevel",
  313. "ole32.dll.CLSIDFromProgIDEx",
  314. "ole32.dll.CoGetClassObject",
  315. "wscript.exe.#1",
  316. "urlmon.dll.#326",
  317. "urlmon.dll.#327",
  318. "shell32.dll.#685",
  319. "shell32.dll.#688",
  320. "urlmon.dll.#395",
  321. "cryptsp.dll.CryptAcquireContextW",
  322. "cryptsp.dll.CryptGenRandom",
  323. "rpcrtremote.dll.I_RpcExtInitializeExtensionPoint",
  324. "winhttp.dll.WinHttpCheckPlatform",
  325. "winhttp.dll.WinHttpOpen",
  326. "winhttp.dll.WinHttpConnect",
  327. "winhttp.dll.WinHttpOpenRequest",
  328. "winhttp.dll.WinHttpCloseHandle",
  329. "winhttp.dll.WinHttpSendRequest",
  330. "winhttp.dll.WinHttpReceiveResponse",
  331. "winhttp.dll.WinHttpAddRequestHeaders",
  332. "winhttp.dll.WinHttpQueryHeaders",
  333. "winhttp.dll.WinHttpReadData",
  334. "winhttp.dll.WinHttpWriteData",
  335. "winhttp.dll.WinHttpQueryDataAvailable",
  336. "winhttp.dll.WinHttpQueryOption",
  337. "winhttp.dll.WinHttpSetOption",
  338. "winhttp.dll.WinHttpSetTimeouts",
  339. "winhttp.dll.WinHttpCrackUrl",
  340. "winhttp.dll.WinHttpCreateUrl",
  341. "oleaut32.dll.#8",
  342. "oleaut32.dll.#12",
  343. "shlwapi.dll.StrRChrA",
  344. "shlwapi.dll.StrCmpNW",
  345. "oleaut32.dll.#4",
  346. "oleaut32.dll.#6",
  347. "kernel32.dll.RegQueryValueExW",
  348. "oleaut32.dll.#2",
  349. "kernel32.dll.RegCloseKey",
  350. "oleaut32.dll.#9",
  351. "ws2_32.dll.GetAddrInfoW",
  352. "ws2_32.dll.WSASocketW",
  353. "ws2_32.dll.#2",
  354. "ws2_32.dll.#21",
  355. "ws2_32.dll.#9",
  356. "ws2_32.dll.WSAIoctl",
  357. "ws2_32.dll.FreeAddrInfoW",
  358. "ws2_32.dll.#6",
  359. "ws2_32.dll.#5",
  360. "schannel.dll.SpUserModeInitialize",
  361. "advapi32.dll.RegCreateKeyExW",
  362. "advapi32.dll.RegQueryValueExW",
  363. "advapi32.dll.RegCloseKey",
  364. "ws2_32.dll.WSASend",
  365. "ws2_32.dll.WSARecv",
  366. "secur32.dll.FreeContextBuffer",
  367. "ncrypt.dll.SslOpenProvider",
  368. "ncrypt.dll.GetSChannelInterface",
  369. "bcryptprimitives.dll.GetHashInterface",
  370. "ncrypt.dll.SslIncrementProviderReferenceCount",
  371. "ncrypt.dll.SslImportKey",
  372. "bcryptprimitives.dll.GetCipherInterface",
  373. "ncrypt.dll.SslLookupCipherSuiteInfo",
  374. "user32.dll.LoadStringW",
  375. "ncrypt.dll.BCryptOpenAlgorithmProvider",
  376. "ncrypt.dll.BCryptGetProperty",
  377. "ncrypt.dll.BCryptCreateHash",
  378. "ncrypt.dll.BCryptHashData",
  379. "ncrypt.dll.BCryptFinishHash",
  380. "ncrypt.dll.BCryptDestroyHash",
  381. "crypt32.dll.CertGetCertificateChain",
  382. "userenv.dll.GetUserProfileDirectoryW",
  383. "sechost.dll.ConvertSidToStringSidW",
  384. "sechost.dll.ConvertStringSidToSidW",
  385. "userenv.dll.RegisterGPNotification",
  386. "gpapi.dll.RegisterGPNotificationInternal",
  387. "sechost.dll.OpenSCManagerW",
  388. "sechost.dll.OpenServiceW",
  389. "sechost.dll.CloseServiceHandle",
  390. "sechost.dll.QueryServiceConfigW",
  391. "cryptnet.dll.CryptGetObjectUrl",
  392. "cryptnet.dll.CryptRetrieveObjectByUrlW",
  393. "cryptnet.dll.I_CryptNetGetConnectivity",
  394. "sensapi.dll.IsNetworkAlive",
  395. "rpcrt4.dll.RpcBindingFromStringBindingW",
  396. "rpcrt4.dll.RpcBindingSetAuthInfoExW",
  397. "rpcrt4.dll.NdrClientCall2",
  398. "winhttp.dll.WinHttpSetStatusCallback",
  399. "winhttp.dll.WinHttpGetDefaultProxyConfiguration",
  400. "winhttp.dll.WinHttpGetIEProxyConfigForCurrentUser",
  401. "shlwapi.dll.StrStrIW",
  402. "cryptsp.dll.CryptAcquireContextA",
  403. "cryptsp.dll.CryptCreateHash",
  404. "cryptsp.dll.CryptHashData",
  405. "cryptsp.dll.CryptVerifySignatureA",
  406. "cryptsp.dll.CryptDestroyKey",
  407. "cryptsp.dll.CryptDestroyHash",
  408. "setupapi.dll.SetupIterateCabinetW",
  409. "kernel32.dll.RegOpenKeyExW",
  410. "cabinet.dll.#20",
  411. "cabinet.dll.#22",
  412. "devrtl.dll.DevRtlGetThreadLogToken",
  413. "cabinet.dll.#23",
  414. "cryptsp.dll.CryptSetHashParam",
  415. "sechost.dll.QueryServiceConfigA",
  416. "sechost.dll.QueryServiceStatus",
  417. "rpcrt4.dll.RpcStringBindingComposeA",
  418. "rpcrt4.dll.RpcBindingFromStringBindingA",
  419. "rpcrt4.dll.RpcEpResolveBinding",
  420. "sechost.dll.LookupAccountSidLocalW",
  421. "rpcrt4.dll.RpcStringFreeA",
  422. "rpcrt4.dll.RpcBindingFree",
  423. "winhttp.dll.WinHttpTimeFromSystemTime",
  424. "cryptnet.dll.I_CryptNetSetUrlCacheFlushInfo",
  425. "cryptnet.dll.I_CryptNetSetUrlCachePreFetchInfo",
  426. "bcryptprimitives.dll.GetAsymmetricEncryptionInterface",
  427. "ncrypt.dll.BCryptImportKeyPair",
  428. "ncrypt.dll.BCryptVerifySignature",
  429. "ncrypt.dll.BCryptDestroyKey",
  430. "crypt32.dll.CertVerifyCertificateChainPolicy",
  431. "crypt32.dll.CertFreeCertificateChain",
  432. "crypt32.dll.CertDuplicateCertificateContext",
  433. "ncrypt.dll.SslEncryptPacket",
  434. "ncrypt.dll.SslDecryptPacket",
  435. "ole32.dll.CreateStreamOnHGlobal",
  436. "oleaut32.dll.#411",
  437. "oleaut32.dll.#23",
  438. "oleaut32.dll.#24",
  439. "ws2_32.dll.#22",
  440. "ws2_32.dll.#3",
  441. "ole32.dll.GetHGlobalFromStream",
  442. "crypt32.dll.CertFreeCertificateContext",
  443. "ncrypt.dll.SslDecrementProviderReferenceCount",
  444. "ncrypt.dll.SslFreeObject",
  445. "oleaut32.dll.#500",
  446. "cryptsp.dll.CryptReleaseContext",
  447. "kernel32.dll.VirtualAlloc",
  448. "advapi32.dll.CryptAcquireContextA",
  449. "ntdll.dll.memcpy",
  450. "kernel32.dll.GetCurrentProcess",
  451. "kernel32.dll.CloseHandle",
  452. "advapi32.dll.OpenProcessToken",
  453. "advapi32.dll.GetTokenInformation",
  454. "kernel32.dll.Wow64EnableWow64FsRedirection",
  455. "advapi32.dll.RegCreateKeyW",
  456. "advapi32.dll.RegOpenKeyExW",
  457. "advapi32.dll.RegSetValueExW",
  458. "shell32.dll.ShellExecuteA",
  459. "ole32.dll.OleInitialize",
  460. "cryptbase.dll.SystemFunction036",
  461. "uxtheme.dll.ThemeInitApiHook",
  462. "user32.dll.IsProcessDPIAware",
  463. "ole32.dll.CreateBindCtx",
  464. "ole32.dll.CoTaskMemAlloc",
  465. "propsys.dll.PSCreateMemoryPropertyStore",
  466. "propsys.dll.PSPropertyBag_WriteDWORD",
  467. "ole32.dll.CoGetApartmentType",
  468. "ole32.dll.CoRegisterInitializeSpy",
  469. "ole32.dll.CoTaskMemFree",
  470. "comctl32.dll.#236",
  471. "ole32.dll.CoGetMalloc",
  472. "propsys.dll.PSPropertyBag_ReadDWORD",
  473. "propsys.dll.PSPropertyBag_ReadGUID",
  474. "comctl32.dll.#320",
  475. "comctl32.dll.#324",
  476. "comctl32.dll.#323",
  477. "advapi32.dll.RegEnumKeyW",
  478. "advapi32.dll.OpenThreadToken",
  479. "ole32.dll.StringFromGUID2",
  480. "apphelp.dll.ApphelpCheckShellObject",
  481. "ole32.dll.CoCreateInstance",
  482. "urlmon.dll.CreateUri",
  483. "kernel32.dll.InitializeSRWLock",
  484. "kernel32.dll.AcquireSRWLockExclusive",
  485. "kernel32.dll.AcquireSRWLockShared",
  486. "kernel32.dll.ReleaseSRWLockExclusive",
  487. "kernel32.dll.ReleaseSRWLockShared",
  488. "comctl32.dll.#328",
  489. "comctl32.dll.#334",
  490. "shell32.dll.#102",
  491. "propsys.dll.PSPropertyBag_ReadStrAlloc",
  492. "ole32.dll.CoInitializeEx",
  493. "advapi32.dll.InitializeSecurityDescriptor",
  494. "advapi32.dll.SetEntriesInAclW",
  495. "ntmarta.dll.GetMartaExtensionInterface",
  496. "advapi32.dll.SetSecurityDescriptorDacl",
  497. "setupapi.dll.CM_Get_Device_Interface_List_Size_ExW",
  498. "advapi32.dll.IsTextUnicode",
  499. "comctl32.dll.#332",
  500. "comctl32.dll.#338",
  501. "comctl32.dll.#339",
  502. "ole32.dll.CoUninitialize",
  503. "profapi.dll.#104",
  504. "propsys.dll.#430",
  505. "advapi32.dll.RegGetValueW",
  506. "ole32.dll.CoTaskMemRealloc",
  507. "propsys.dll.InitPropVariantFromStringAsVector",
  508. "propsys.dll.PSCoerceToCanonicalValue",
  509. "propsys.dll.PropVariantToStringAlloc",
  510. "ole32.dll.PropVariantClear",
  511. "ole32.dll.CoAllowSetForegroundWindow",
  512. "setupapi.dll.CM_Get_Device_Interface_List_ExW",
  513. "comctl32.dll.#386",
  514. "shell32.dll.SHGetFolderPathW",
  515. "advapi32.dll.SaferGetPolicyInformation",
  516. "ntdll.dll.RtlDllShutdownInProgress",
  517. "comctl32.dll.#329",
  518. "ole32.dll.OleUninitialize",
  519. "ole32.dll.CoRevokeInitializeSpy",
  520. "comctl32.dll.#388",
  521. "advapi32.dll.CryptImportKey",
  522. "advapi32.dll.CryptEncrypt",
  523. "cryptsp.dll.CryptImportKey",
  524. "cryptbase.dll.SystemFunction040",
  525. "cryptbase.dll.SystemFunction041",
  526. "cryptsp.dll.CryptEncrypt",
  527. "advapi32.dll.UnregisterTraceGuids",
  528. "comctl32.dll.#321",
  529. "kernel32.dll.SetThreadUILanguage",
  530. "kernel32.dll.CopyFileExW",
  531. "kernel32.dll.IsDebuggerPresent",
  532. "kernel32.dll.SetConsoleInputExeNameW",
  533. "kernel32.dll.SortGetHandle",
  534. "kernel32.dll.SortCloseHandle",
  535. "shell32.dll.#66",
  536. "comctl32.dll.#385",
  537. "comctl32.dll.#336",
  538. "comctl32.dll.#333",
  539. "linkinfo.dll.IsValidLinkInfo",
  540. "propsys.dll.#417",
  541. "propsys.dll.PSGetNameFromPropertyKey",
  542. "propsys.dll.PSStringFromPropertyKey",
  543. "propsys.dll.InitVariantFromBuffer",
  544. "propsys.dll.PropVariantToGUID",
  545. "linkinfo.dll.CreateLinkInfoW",
  546. "user32.dll.IsCharAlphaW",
  547. "user32.dll.CharPrevW",
  548. "ntshrui.dll.GetNetResourceFromLocalPathW",
  549. "srvcli.dll.NetShareEnum",
  550. "cscapi.dll.CscNetApiGetInterface",
  551. "slc.dll.SLGetWindowsInformationDWORD",
  552. "shlwapi.dll.PathRemoveFileSpecW",
  553. "linkinfo.dll.DestroyLinkInfo",
  554. "propsys.dll.PropVariantToBoolean",
  555. "advapi32.dll.GetSecurityInfo",
  556. "advapi32.dll.SetSecurityInfo",
  557. "advapi32.dll.GetSecurityDescriptorControl",
  558. "advapi32.dll.RegQueryInfoKeyW",
  559. "advapi32.dll.RegEnumKeyExW",
  560. "advapi32.dll.RegEnumValueW",
  561. "shlwapi.dll.UrlIsW",
  562. "kernel32.dll.InitializeCriticalSectionAndSpinCount",
  563. "msvcrt.dll._set_error_mode",
  564. "msvcrt.dll.?set_terminate@@YAP6AXXZP6AXXZ@Z",
  565. "kernel32.dll.FindActCtxSectionStringW",
  566. "kernel32.dll.GetSystemWindowsDirectoryW",
  567. "mscoree.dll.GetProcessExecutableHeap",
  568. "mscorwks.dll.DllGetClassObjectInternal",
  569. "mscorwks.dll.GetCLRFunction",
  570. "advapi32.dll.RegisterTraceGuidsW",
  571. "advapi32.dll.GetTraceLoggerHandle",
  572. "advapi32.dll.GetTraceEnableLevel",
  573. "advapi32.dll.GetTraceEnableFlags",
  574. "advapi32.dll.TraceEvent",
  575. "mscoree.dll.IEE",
  576. "mscorwks.dll.IEE",
  577. "mscoree.dll.GetStartupFlags",
  578. "mscoree.dll.GetHostConfigurationFile",
  579. "mscoree.dll.GetCORSystemDirectory",
  580. "ntdll.dll.RtlVirtualUnwind",
  581. "kernel32.dll.IsWow64Process",
  582. "advapi32.dll.AllocateAndInitializeSid",
  583. "advapi32.dll.InitializeAcl",
  584. "advapi32.dll.AddAccessAllowedAce",
  585. "advapi32.dll.FreeSid",
  586. "kernel32.dll.SetThreadStackGuarantee",
  587. "kernel32.dll.FlsSetValue",
  588. "kernel32.dll.FlsGetValue",
  589. "kernel32.dll.FlsAlloc",
  590. "kernel32.dll.FlsFree",
  591. "kernel32.dll.AddVectoredContinueHandler",
  592. "kernel32.dll.RemoveVectoredContinueHandler",
  593. "advapi32.dll.ConvertSidToStringSidW",
  594. "kernel32.dll.FlushProcessWriteBuffers",
  595. "kernel32.dll.GetWriteWatch",
  596. "kernel32.dll.ResetWriteWatch",
  597. "kernel32.dll.CreateMemoryResourceNotification",
  598. "kernel32.dll.QueryMemoryResourceNotification",
  599. "kernel32.dll.GlobalMemoryStatusEx",
  600. "ole32.dll.CoGetContextToken",
  601. "oleaut32.dll.#149",
  602. "kernel32.dll.GetUserDefaultUILanguage",
  603. "kernel32.dll.GetVersionExW",
  604. "kernel32.dll.GetFullPathNameW",
  605. "kernel32.dll.SetErrorMode",
  606. "kernel32.dll.GetFileAttributesExW",
  607. "version.dll.GetFileVersionInfoSizeW",
  608. "version.dll.GetFileVersionInfoW",
  609. "version.dll.VerQueryValueW",
  610. "kernel32.dll.lstrlen",
  611. "kernel32.dll.lstrlenW",
  612. "mscoree.dll.ND_RI2",
  613. "kernel32.dll.lstrcpy",
  614. "kernel32.dll.lstrcpyW",
  615. "version.dll.VerLanguageNameW",
  616. "kernel32.dll.GetCurrentProcessId",
  617. "advapi32.dll.LookupPrivilegeValueW",
  618. "advapi32.dll.AdjustTokenPrivileges",
  619. "kernel32.dll.OpenProcess",
  620. "psapi.dll.EnumProcessModules",
  621. "psapi.dll.GetModuleInformation",
  622. "psapi.dll.GetModuleBaseNameW",
  623. "psapi.dll.GetModuleFileNameExW",
  624. "kernel32.dll.GetExitCodeProcess",
  625. "ntdll.dll.NtQuerySystemInformation",
  626. "user32.dll.EnumWindows",
  627. "user32.dll.GetWindowThreadProcessId",
  628. "kernel32.dll.WerSetFlags",
  629. "kernel32.dll.SetThreadPreferredUILanguages",
  630. "kernel32.dll.GetThreadPreferredUILanguages",
  631. "kernel32.dll.GetUserDefaultLocaleName",
  632. "kernel32.dll.GetEnvironmentVariableW",
  633. "advapi32.dll.CryptReleaseContext",
  634. "advapi32.dll.CryptCreateHash",
  635. "advapi32.dll.CryptDestroyHash",
  636. "advapi32.dll.CryptHashData",
  637. "advapi32.dll.CryptGetHashParam",
  638. "advapi32.dll.CryptExportKey",
  639. "advapi32.dll.CryptGenKey",
  640. "advapi32.dll.CryptGetKeyParam",
  641. "advapi32.dll.CryptDestroyKey",
  642. "advapi32.dll.CryptVerifySignatureA",
  643. "advapi32.dll.CryptSignHashA",
  644. "advapi32.dll.CryptGetProvParam",
  645. "advapi32.dll.CryptGetUserKey",
  646. "advapi32.dll.CryptEnumProvidersA",
  647. "cryptsp.dll.CryptGetHashParam",
  648. "mscoree.dll.GetTokenForVTableEntry",
  649. "mscoree.dll.SetTargetForVTableEntry",
  650. "mscoree.dll.GetTargetForVTableEntry",
  651. "culture.dll.ConvertLangIdToCultureName",
  652. "ole32.dll.CoCreateGuid",
  653. "kernel32.dll.CreateFileW",
  654. "kernel32.dll.GetConsoleScreenBufferInfo",
  655. "kernel32.dll.LocalFree",
  656. "kernel32.dll.LocalAlloc",
  657. "mscoree.dll.ND_RI4",
  658. "advapi32.dll.DuplicateTokenEx",
  659. "advapi32.dll.CheckTokenMembership",
  660. "kernel32.dll.GetConsoleTitleW",
  661. "mscorjit.dll.getJit",
  662. "kernel32.dll.SetConsoleTitleW",
  663. "kernel32.dll.SetConsoleCtrlHandler",
  664. "kernel32.dll.CreateEventW",
  665. "ntdll.dll.WinSqmIsOptedIn",
  666. "kernel32.dll.ExpandEnvironmentStringsW",
  667. "shfolder.dll.SHGetFolderPathW",
  668. "kernel32.dll.SetEnvironmentVariableW",
  669. "kernel32.dll.GetACP",
  670. "kernel32.dll.UnmapViewOfFile",
  671. "kernel32.dll.GetFileType",
  672. "kernel32.dll.ReadFile",
  673. "kernel32.dll.GetSystemInfo",
  674. "kernel32.dll.VirtualQuery",
  675. "secur32.dll.GetUserNameExW",
  676. "advapi32.dll.GetUserNameW",
  677. "kernel32.dll.ReleaseMutex",
  678. "advapi32.dll.RegisterEventSourceW",
  679. "advapi32.dll.DeregisterEventSource",
  680. "advapi32.dll.ReportEventW",
  681. "kernel32.dll.GetLogicalDrives",
  682. "kernel32.dll.GetDriveTypeW",
  683. "kernel32.dll.GetVolumeInformationW",
  684. "kernel32.dll.GetCurrentDirectoryW",
  685. "kernel32.dll.GetLastError",
  686. "kernel32.dll.GetStdHandle",
  687. "kernel32.dll.GetConsoleMode",
  688. "kernel32.dll.SetEvent",
  689. "kernel32.dll.FindFirstFileW",
  690. "kernel32.dll.FindClose",
  691. "mscoree.dll.DllGetClassObject",
  692. "diasymreader.dll.DllGetClassObjectInternal",
  693. "kernel32.dll.GetConsoleOutputCP",
  694. "gdi32.dll.TranslateCharsetInfo",
  695. "kernel32.dll.SetConsoleTextAttribute",
  696. "kernel32.dll.WriteConsoleW",
  697. "mscoree.dll.CorExitProcess",
  698. "mscorwks.dll.CorExitProcess",
  699. "mscorwks.dll._CorDllMain",
  700. "kernel32.dll.CreateActCtxW",
  701. "kernel32.dll.AddRefActCtx",
  702. "kernel32.dll.ReleaseActCtx",
  703. "kernel32.dll.ActivateActCtx",
  704. "kernel32.dll.DeactivateActCtx",
  705. "kernel32.dll.GetCurrentActCtx",
  706. "kernel32.dll.QueryActCtxW",
  707. "netutils.dll.NetApiBufferFree",
  708. "kernel32.dll.IsProcessorFeaturePresent",
  709. "ntdll.dll.RtlUnwind",
  710. "mscoree.dll._CorExeMain",
  711. "mscoree.dll._CorImageUnloading",
  712. "mscoree.dll._CorValidateImage",
  713. "cryptsp.dll.CryptExportKey",
  714. "kernel32.dll.SwitchToThread",
  715. "rpcrt4.dll.UuidFromStringW",
  716. "rpcrt4.dll.RpcBindingCreateW",
  717. "rpcrt4.dll.RpcBindingBind",
  718. "sechost.dll.StartServiceW"
  719. ]
  720.  
  721. [*] Static Analysis: {
  722. "office": {
  723. "Metadata": {
  724. "HasMacros": "No"
  725. }
  726. }
  727. }
Add Comment
Please, Sign In to add comment