paladin316

Exes_5f33d8735668a3d1df32e39481e48fc6_exe_2019-07-04_21_30

Jul 4th, 2019
2,561
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 23.98 KB | None | 0 0
  1.  
  2. * MalFamily: ""
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "Exes_5f33d8735668a3d1df32e39481e48fc6.exe"
  7. * File Size: 1330952
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "631be61e81b7777ef583f0df067066658e8ecb5c94d5194dc29f72b2ada997ba"
  10. * MD5: "5f33d8735668a3d1df32e39481e48fc6"
  11. * SHA1: "e6f1b1392dd421f131b3f401e571e6f2e3c20aa7"
  12. * SHA512: "6408d1968bb79f76c6da2e077e4798c9bad4360ac5a9dad0646c7bc3d1b21f74eab33d3597d1bdbdcd1d9975364d5915e044cdd17f07b4ce662101782b63b1de"
  13. * CRC32: "AE262335"
  14. * SSDEEP: "24576:PuZZTVfEgYD/cJmkxLvv+o0NZvQC8fDHfW4nmi2Tc+XYriH3ppTx40qaRbUkQtzI:mZZxEgcouQ9fjf8T1Ykp1qaRbUDvw"
  15.  
  16. * Process Execution:
  17. "Exes_5f33d8735668a3d1df32e39481e48fc6.exe",
  18. "Exes_5f33d8735668a3d1df32e39481e48fc6.exe",
  19. "services.exe",
  20. "svchost.exe",
  21. "lsass.exe",
  22. "taskhost.exe",
  23. "sc.exe",
  24. "svchost.exe",
  25. "svchost.exe",
  26. "WerFault.exe",
  27. "wermgr.exe"
  28.  
  29.  
  30. * Executed Commands:
  31. "C:\\Users\\user\\AppData\\Local\\Temp\\Exes_5f33d8735668a3d1df32e39481e48fc6.exe",
  32. "C:\\Windows\\System32\\svchost.exe -k netsvcs",
  33. "C:\\Windows\\system32\\lsass.exe",
  34. "taskhost.exe $(Arg0)",
  35. "C:\\Windows\\system32\\sc.exe start w32time task_started",
  36. "C:\\Windows\\system32\\svchost.exe -k LocalService",
  37. "C:\\Windows\\System32\\svchost.exe -k WerSvcGroup",
  38. "C:\\Windows\\system32\\WerFault.exe -u -p 560 -s 288",
  39. "\"C:\\Windows\\system32\\wermgr.exe\" \"-queuereporting_svc\" \"C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_0b29af39\""
  40.  
  41.  
  42. * Signatures Detected:
  43.  
  44. "Description": "At least one process apparently crashed during execution",
  45. "Details":
  46.  
  47.  
  48. "Description": "Creates RWX memory",
  49. "Details":
  50.  
  51.  
  52. "Description": "A process attempted to delay the analysis task.",
  53. "Details":
  54.  
  55. "Process": "Exes_5f33d8735668a3d1df32e39481e48fc6.exe tried to sleep 1780 seconds, actually delayed analysis time by 0 seconds"
  56.  
  57.  
  58.  
  59.  
  60. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  61. "Details":
  62.  
  63. "post_no_referer": "HTTP traffic contains a POST request with no referer header"
  64.  
  65.  
  66. "post_no_useragent": "HTTP traffic contains a POST request with no user-agent header"
  67.  
  68.  
  69. "suspicious_request": "http://ip-api.com/line/"
  70.  
  71.  
  72.  
  73.  
  74. "Description": "Performs some HTTP requests",
  75. "Details":
  76.  
  77. "url": "http://ip-api.com/line/"
  78.  
  79.  
  80.  
  81.  
  82. "Description": "The binary likely contains encrypted or compressed data.",
  83. "Details":
  84.  
  85. "section": "name: .rsrc, entropy: 7.83, characteristics: IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ, raw_size: 0x00064400, virtual_size: 0x000642e0"
  86.  
  87.  
  88.  
  89.  
  90. "Description": "Executed a process and injected code into it, probably while unpacking",
  91. "Details":
  92.  
  93. "Injection": "Exes_5f33d8735668a3d1df32e39481e48fc6.exe(2000) -> Exes_5f33d8735668a3d1df32e39481e48fc6.exe(1432)"
  94.  
  95.  
  96.  
  97.  
  98. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  99. "Details":
  100.  
  101. "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 11833014 times"
  102.  
  103.  
  104.  
  105.  
  106. "Description": "Steals private information from local Internet browsers",
  107. "Details":
  108.  
  109. "file": "C:\\Users\\user\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Login Data"
  110.  
  111.  
  112.  
  113.  
  114. "Description": "Collects information about installed applications",
  115. "Details":
  116.  
  117. "Program": "Google Update Helper"
  118.  
  119.  
  120. "Program": "Microsoft Excel MUI 2013"
  121.  
  122.  
  123. "Program": "Microsoft Outlook MUI 2013"
  124.  
  125.  
  126.  
  127.  
  128. "Program": "Google Chrome"
  129.  
  130.  
  131. "Program": "Adobe Flash Player 29 NPAPI"
  132.  
  133.  
  134. "Program": "Adobe Flash Player 29 ActiveX"
  135.  
  136.  
  137. "Program": "Microsoft DCF MUI 2013"
  138.  
  139.  
  140. "Program": "Microsoft Access MUI 2013"
  141.  
  142.  
  143. "Program": "Microsoft Office Proofing Tools 2013 - English"
  144.  
  145.  
  146. "Program": "Adobe Acrobat Reader DC"
  147.  
  148.  
  149. "Program": "Microsoft Office Proofing Tools 2013 - Espa\\xef\\xbf\\xb1ol"
  150.  
  151.  
  152. "Program": "Microsoft Publisher MUI 2013"
  153.  
  154.  
  155. "Program": "Outils de v\\xef\\xbf\\xa9rification linguistique 2013 de Microsoft Office\\xef\\xbe\\xa0- Fran\\xef\\xbf\\xa7ais"
  156.  
  157.  
  158. "Program": "Microsoft Office Shared MUI 2013"
  159.  
  160.  
  161. "Program": "Microsoft Office OSM MUI 2013"
  162.  
  163.  
  164. "Program": "Microsoft InfoPath MUI 2013"
  165.  
  166.  
  167. "Program": "Microsoft Office Shared Setup Metadata MUI 2013"
  168.  
  169.  
  170. "Program": "Microsoft Word MUI 2013"
  171.  
  172.  
  173. "Program": "Microsoft Groove MUI 2013"
  174.  
  175.  
  176.  
  177.  
  178. "Program": "Microsoft Access Setup Metadata MUI 2013"
  179.  
  180.  
  181. "Program": "Microsoft Office OSM UX MUI 2013"
  182.  
  183.  
  184. "Program": "Java Auto Updater"
  185.  
  186.  
  187. "Program": "Microsoft PowerPoint MUI 2013"
  188.  
  189.  
  190. "Program": "Microsoft Office Professional Plus 2013"
  191.  
  192.  
  193. "Program": "Adobe Refresh Manager"
  194.  
  195.  
  196. "Program": "Microsoft Office Proofing 2013"
  197.  
  198.  
  199. "Program": "Microsoft Lync MUI 2013"
  200.  
  201.  
  202.  
  203.  
  204. "Program": "Microsoft OneNote MUI 2013"
  205.  
  206.  
  207.  
  208.  
  209. "Description": "File has been identified by 44 Antiviruses on VirusTotal as malicious",
  210. "Details":
  211.  
  212. "MicroWorld-eScan": "Trojan.GenericKD.41157299"
  213.  
  214.  
  215. "McAfee": "Artemis!5F33D8735668"
  216.  
  217.  
  218. "Cylance": "Unsafe"
  219.  
  220.  
  221. "K7AntiVirus": "Trojan ( 0054ad951 )"
  222.  
  223.  
  224. "BitDefender": "Trojan.GenericKD.41157299"
  225.  
  226.  
  227. "K7GW": "Trojan ( 0054ad951 )"
  228.  
  229.  
  230. "Arcabit": "Trojan.Generic.D27402B3"
  231.  
  232.  
  233. "Invincea": "heuristic"
  234.  
  235.  
  236. "NANO-Antivirus": "Trojan.Win32.Chapak.fosasx"
  237.  
  238.  
  239. "Symantec": "Trojan.Gen.MBT"
  240.  
  241.  
  242. "TrendMicro-HouseCall": "TROJ_GEN.R049C0WCU19"
  243.  
  244.  
  245. "Avast": "Win32:Malware-gen"
  246.  
  247.  
  248. "Kaspersky": "Trojan.Win32.Chapak.cmip"
  249.  
  250.  
  251. "Paloalto": "generic.ml"
  252.  
  253.  
  254. "AegisLab": "Trojan.Multi.Generic.4!c"
  255.  
  256.  
  257. "Tencent": "Win32.Trojan.Chapak.Sxol"
  258.  
  259.  
  260. "Endgame": "malicious (high confidence)"
  261.  
  262.  
  263. "Sophos": "Mal/Generic-S"
  264.  
  265.  
  266. "Comodo": "Malware@#2sqc2f425k7cz"
  267.  
  268.  
  269. "TrendMicro": "TROJ_GEN.R049C0WCU19"
  270.  
  271.  
  272. "McAfee-GW-Edition": "Artemis!Trojan"
  273.  
  274.  
  275. "Trapmine": "malicious.moderate.ml.score"
  276.  
  277.  
  278. "FireEye": "Trojan.GenericKD.41157299"
  279.  
  280.  
  281. "Emsisoft": "Trojan.GenericKD.41157299 (B)"
  282.  
  283.  
  284. "SentinelOne": "DFI - Suspicious PE"
  285.  
  286.  
  287. "Jiangmin": "RiskTool.BitCoinMiner.itb"
  288.  
  289.  
  290. "Fortinet": "W32/GenKryptik.DDWX!tr"
  291.  
  292.  
  293. "Antiy-AVL": "Trojan/Win32.Chapak"
  294.  
  295.  
  296. "Microsoft": "PWS:Win32/Vidar.YB!MTB"
  297.  
  298.  
  299. "ZoneAlarm": "Trojan.Win32.Chapak.cmip"
  300.  
  301.  
  302. "Acronis": "suspicious"
  303.  
  304.  
  305. "VBA32": "BScope.Trojan.Chapak"
  306.  
  307.  
  308. "ALYac": "Trojan.GenericKD.41157299"
  309.  
  310.  
  311. "Ad-Aware": "Trojan.GenericKD.41157299"
  312.  
  313.  
  314. "ESET-NOD32": "Win32/PSW.Agent.OFF"
  315.  
  316.  
  317. "Rising": "Stealer.Agent!8.C2 (CLOUD)"
  318.  
  319.  
  320. "Ikarus": "Trojan.Crypter"
  321.  
  322.  
  323. "eGambit": "PE.Heur.InvalidSig"
  324.  
  325.  
  326. "GData": "Trojan.GenericKD.41157299"
  327.  
  328.  
  329. "AVG": "Win32:Malware-gen"
  330.  
  331.  
  332. "Cybereason": "malicious.35668a"
  333.  
  334.  
  335. "Panda": "Trj/GdSda.A"
  336.  
  337.  
  338. "CrowdStrike": "win/malicious_confidence_90% (W)"
  339.  
  340.  
  341. "Qihoo-360": "Win32/Trojan.35a"
  342.  
  343.  
  344.  
  345.  
  346. "Description": "Checks the CPU name from registry, possibly for anti-virtualization",
  347. "Details":
  348.  
  349.  
  350. "Description": "Checks the system manufacturer, likely for anti-virtualization",
  351. "Details":
  352.  
  353.  
  354. "Description": "Harvests credentials from local FTP client softwares",
  355. "Details":
  356.  
  357. "file": "C:\\Users\\user\\AppData\\Roaming\\FileZilla\\recentservers.xml"
  358.  
  359.  
  360.  
  361.  
  362. "Description": "Harvests information related to installed instant messenger clients",
  363. "Details":
  364.  
  365. "file": "C:\\Users\\user\\AppData\\Roaming\\.purple\\accounts.xml"
  366.  
  367.  
  368.  
  369.  
  370. "Description": "Harvests information related to installed mail clients",
  371. "Details":
  372.  
  373. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000003"
  374.  
  375.  
  376. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000007"
  377.  
  378.  
  379. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000006"
  380.  
  381.  
  382. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000005"
  383.  
  384.  
  385. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000004"
  386.  
  387.  
  388. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000009"
  389.  
  390.  
  391. "key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676\\00000008"
  392.  
  393.  
  394.  
  395.  
  396. "Description": "Collects information to fingerprint the system",
  397. "Details":
  398.  
  399.  
  400. "Description": "Anomalous binary characteristics",
  401. "Details":
  402.  
  403. "anomaly": "Actual checksum does not match that reported in PE header"
  404.  
  405.  
  406.  
  407.  
  408.  
  409. * Started Service:
  410. "RasMan",
  411. "WerSvc",
  412. "VaultSvc",
  413. "W32Time"
  414.  
  415.  
  416. * Mutexes:
  417. "_Mutex_",
  418. "00000000-0000-0000-0000-0000000000003d3783a0-703a-11de-8c7a-806e6f6e6963",
  419. "Local\\WERReportingForProcess560",
  420. "Global\\\\xe5\\x88\\x90\\x7f",
  421. "Global\\\\xed\\x95\\xb0\\xc7\\x92",
  422. "WERUI_BEX64-eb71ef964c95de5826f5dbf6417783430b96dd1"
  423.  
  424.  
  425. * Modified Files:
  426. "\\??\\PIPE\\lsarpc",
  427. "C:\\ProgramData\\Microsoft\\Network\\Connections\\Pbk\\rasphone.pbk",
  428. "C:\\Windows\\sysnative\\LogFiles\\Scm\\4963ad21-c4a5-42a5-b9bd-e441d57204fe",
  429. "C:\\Windows\\sysnative\\LogFiles\\Scm\\7bbc503c-5977-4798-a4ae-61483a7e030d",
  430. "C:\\Windows\\sysnative\\LogFiles\\Scm\\81581aa9-cc73-4fbb-b69a-b3e533296974",
  431. "\\??\\NDISWAN",
  432. "C:\\ProgramData\\W4WAZI3MQGQF2NBS348R\\files\\passwords.txt",
  433. "C:\\ProgramData\\W4WAZI3MQGQF2NBS348R\\ld",
  434. "C:\\ProgramData\\W4WAZI3MQGQF2NBS348R\\files\\Soft\\Authy\\\\xef\\xa9\\x90\\xcd\\xa8\\xef\\xbb\\xa8\\xc8\\xaa\\xe0\\xb6\\x90\\xc7\\xab\\xeb\\x93\\x88\\xc8\\x92",
  435. "C:\\ProgramData\\W4WAZI3MQGQF2NBS348R\\files\\outlook.txt",
  436. "C:\\ProgramData\\W4WAZI3MQGQF2NBS348R\\files\\information.txt",
  437. "C:\\ProgramData\\W4WAZI3MQGQF2NBS348R\\CA_00000000-0000-0000-0000-0000000000003841938647.zip",
  438. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERAEC5.tmp.appcompat.txt",
  439. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERCF5E.tmp.WERInternalMetadata.xml",
  440. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERCF7E.tmp.hdmp",
  441. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERD7EC.tmp.mdmp",
  442. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_0b29af39\\WERAEC5.tmp.appcompat.txt",
  443. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_0b29af39\\WERCF5E.tmp.WERInternalMetadata.xml",
  444. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_0b29af39\\WERCF7E.tmp.hdmp",
  445. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_0b29af39\\WERD7EC.tmp.mdmp",
  446. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_0b29af39\\Report.wer",
  447. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_0b29af39\\Report.wer.tmp"
  448.  
  449.  
  450. * Deleted Files:
  451. "C:\\ProgramData\\freebl3.dll",
  452. "C:\\ProgramData\\mozglue.dll",
  453. "C:\\ProgramData\\msvcp140.dll",
  454. "C:\\ProgramData\\nss3.dll",
  455. "C:\\ProgramData\\softokn3.dll",
  456. "C:\\ProgramData\\vcruntime140.dll",
  457. "C:\\ProgramData\\W4WAZI3MQGQF2NBS348R\\c",
  458. "C:\\ProgramData\\W4WAZI3MQGQF2NBS348R\\history",
  459. "C:\\ProgramData\\W4WAZI3MQGQF2NBS348R\\historych",
  460. "C:\\ProgramData\\W4WAZI3MQGQF2NBS348R\\ld",
  461. "C:\\ProgramData\\W4WAZI3MQGQF2NBS348R\\wd",
  462. "C:\\ProgramData\\W4WAZI3MQGQF2NBS348R\\files\\information.txt",
  463. "C:\\ProgramData\\W4WAZI3MQGQF2NBS348R\\files\\outlook.txt",
  464. "C:\\ProgramData\\W4WAZI3MQGQF2NBS348R\\files\\passwords.txt",
  465. "C:\\ProgramData\\W4WAZI3MQGQF2NBS348R\\files\\Soft\\Authy",
  466. "C:\\ProgramData\\W4WAZI3MQGQF2NBS348R\\files\\Soft",
  467. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERAEC5.tmp",
  468. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERAEC5.tmp.appcompat.txt",
  469. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERCF5E.tmp",
  470. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERCF5E.tmp.WERInternalMetadata.xml",
  471. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERCF7E.tmp",
  472. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERCF7E.tmp.hdmp",
  473. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERD7EC.tmp",
  474. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERD7EC.tmp.mdmp",
  475. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_0b29af39\\Report.wer.tmp"
  476.  
  477.  
  478. * Modified Registry Keys:
  479. "HKEY_CURRENT_USER\\Software\\Miyoungsoft\\Dangeun\\1.2\\Setting",
  480. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\Exes_5f33d8735668a3d1df32e39481e48fc6_RASAPI32",
  481. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\Exes_5f33d8735668a3d1df32e39481e48fc6_RASAPI32\\EnableFileTracing",
  482. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\Exes_5f33d8735668a3d1df32e39481e48fc6_RASAPI32\\EnableConsoleTracing",
  483. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\Exes_5f33d8735668a3d1df32e39481e48fc6_RASAPI32\\FileTracingMask",
  484. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\Exes_5f33d8735668a3d1df32e39481e48fc6_RASAPI32\\ConsoleTracingMask",
  485. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\Exes_5f33d8735668a3d1df32e39481e48fc6_RASAPI32\\MaxFileSize",
  486. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\Exes_5f33d8735668a3d1df32e39481e48fc6_RASAPI32\\FileDirectory",
  487. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\Exes_5f33d8735668a3d1df32e39481e48fc6_RASMANCS",
  488. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\Exes_5f33d8735668a3d1df32e39481e48fc6_RASMANCS\\EnableFileTracing",
  489. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\Exes_5f33d8735668a3d1df32e39481e48fc6_RASMANCS\\EnableConsoleTracing",
  490. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\Exes_5f33d8735668a3d1df32e39481e48fc6_RASMANCS\\FileTracingMask",
  491. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\Exes_5f33d8735668a3d1df32e39481e48fc6_RASMANCS\\ConsoleTracingMask",
  492. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\Exes_5f33d8735668a3d1df32e39481e48fc6_RASMANCS\\MaxFileSize",
  493. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\Exes_5f33d8735668a3d1df32e39481e48fc6_RASMANCS\\FileDirectory",
  494. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\VaultSvc\\Type",
  495. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
  496. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Type",
  497. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\RASMAN",
  498. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\RASMAN\\EnableFileTracing",
  499. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\RASMAN\\EnableConsoleTracing",
  500. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\RASMAN\\FileTracingMask",
  501. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\RASMAN\\ConsoleTracingMask",
  502. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\RASMAN\\MaxFileSize",
  503. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\RASMAN\\FileDirectory",
  504. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\RASTAPI",
  505. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\RASTAPI\\EnableFileTracing",
  506. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\RASTAPI\\EnableConsoleTracing",
  507. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\RASTAPI\\FileTracingMask",
  508. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\RASTAPI\\ConsoleTracingMask",
  509. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\RASTAPI\\MaxFileSize",
  510. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\RASTAPI\\FileDirectory",
  511. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\tapi32",
  512. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\tapi32\\EnableFileTracing",
  513. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\tapi32\\EnableConsoleTracing",
  514. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\tapi32\\FileTracingMask",
  515. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\tapi32\\ConsoleTracingMask",
  516. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\tapi32\\MaxFileSize",
  517. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\tapi32\\FileDirectory",
  518. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\4D36E972-E325-11CE-BFC1-08002BE10318\\0000\\EnableForRas",
  519. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\4D36E972-E325-11CE-BFC1-08002BE10318\\0000\\EnableForRouting",
  520. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\4D36E972-E325-11CE-BFC1-08002BE10318\\0000\\EnableForOutboundRouting",
  521. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\4D36E972-E325-11CE-BFC1-08002BE10318\\0003\\EnableForRas",
  522. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\4D36E972-E325-11CE-BFC1-08002BE10318\\0003\\EnableForRouting",
  523. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\4D36E972-E325-11CE-BFC1-08002BE10318\\0003\\EnableForOutboundRouting",
  524. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\4D36E972-E325-11CE-BFC1-08002BE10318\\0004\\EnableForRas",
  525. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\4D36E972-E325-11CE-BFC1-08002BE10318\\0004\\EnableForRouting",
  526. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\4D36E972-E325-11CE-BFC1-08002BE10318\\0004\\EnableForOutboundRouting",
  527. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\4D36E972-E325-11CE-BFC1-08002BE10318\\0002\\EnableForRas",
  528. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\4D36E972-E325-11CE-BFC1-08002BE10318\\0002\\EnableForRouting",
  529. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\4D36E972-E325-11CE-BFC1-08002BE10318\\0002\\EnableForOutboundRouting",
  530. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\4D36E972-E325-11CE-BFC1-08002BE10318\\0001\\EnableForRas",
  531. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\4D36E972-E325-11CE-BFC1-08002BE10318\\0001\\EnableForRouting",
  532. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\Control\\CLASS\\4D36E972-E325-11CE-BFC1-08002BE10318\\0001\\EnableForOutboundRouting",
  533. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\TimeProviders\\NtpClient\\SpecialPollTimeRemaining",
  534. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent",
  535. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent\\DefaultConsent"
  536.  
  537.  
  538. * Deleted Registry Keys:
  539.  
  540. * DNS Communications:
  541.  
  542. "type": "A",
  543. "request": "hospitaleco.com",
  544. "answers":
  545.  
  546.  
  547. "type": "A",
  548. "request": "ip-api.com",
  549. "answers":
  550.  
  551. "data": "147.135.15.186",
  552. "type": "A"
  553.  
  554.  
  555.  
  556.  
  557.  
  558. * Domains:
  559.  
  560. "ip": "47.90.76.16",
  561. "domain": "hospitaleco.com"
  562.  
  563.  
  564. "ip": "147.135.15.186",
  565. "domain": "ip-api.com"
  566.  
  567.  
  568.  
  569. * Network Communication - ICMP:
  570.  
  571. * Network Communication - HTTP:
  572.  
  573. "count": 1,
  574. "body": "--1BEF0A57BE110FD467A--\r\n",
  575. "uri": "http://ip-api.com/line/",
  576. "user-agent": "",
  577. "method": "POST",
  578. "host": "ip-api.com",
  579. "version": "1.1",
  580. "path": "/line/",
  581. "data": "POST /line/ HTTP/1.1\r\nAccept: text/html, application/xml;q=0.9, application/xhtml+xml, image/png, image/jpeg, image/gif, image/x-xbitmap, */*;q=0.1\r\nAccept-Language: ru-RU,ru;q=0.9,en;q=0.8\r\nAccept-Charset: iso-8859-1, utf-8, utf-16, *;q=0.1\r\nAccept-Encoding: deflate, gzip, x-gzip, identity, *;q=0\r\nContent-Type: multipart/form-data; boundary=1BEF0A57BE110FD467A\r\nContent-Length: 25\r\nHost: ip-api.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n--1BEF0A57BE110FD467A--\r\n",
  582. "port": 80
  583.  
  584.  
  585.  
  586. * Network Communication - SMTP:
  587.  
  588. * Network Communication - Hosts:
  589.  
  590. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment