Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Network Communication
- HTTP Requests
- http://ip-api.com/json/
- DNS Resolutions
- ip-api.com
- IP Traffic
- 208.95.112.1:80 (TCP)
- 208.95.112.1:80 (TCP)
- File System Actions
- Files Opened
- C:\Windows\SYSTEM32\MSCOREE.DLL.local
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
- C:\Windows\Microsoft.NET\Framework\
- C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
- C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll
- C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
- C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll
- C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
- C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll
- Files Deleted
- C:\Users\<USER>\Downloads\7f22fd2ad7bd09243e68766ee5fb8c8e.virus.exe:Zone.Identifier
- C:\Users\<USER>\AppData\Roaming\Java\svchost.exe:Zone.Identifier
- Files Copied
- C:\Users\<USER>\Downloads\7f22fd2ad7bd09243e68766ee5fb8c8e.virus.exe
- Registry Actions
- Registry Keys Opened
- HKLM\Software\Microsoft\.NETFramework\Policy
- HKLM\Software\Microsoft\.NETFramework\Policy\v4.0
- HKLM\Software\Microsoft\.NETFramework
- HKLM\Software\Microsoft\.NETFramework\InstallRoot
- HKLM\Software\Microsoft\.NETFramework\CLRLoadLogDir
- HKLM\Software\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue
- HKLM\Software\Microsoft\.NETFramework\OnlyUseLatestCLR
- HKCU\Software\Microsoft\.NETFramework\Policy\Standards
- HKLM\Software\Microsoft\.NETFramework\Policy\Standards\v4.0.30319
- HKLM\SOFTWARE\Microsoft\Fusion
- Registry Keys Set
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Java Updater
- Process And Service Actions
- Processes Terminated
- schtasks /create /tn Java Updater /sc ONLOGON /tr C:\Users\<USER>\Downloads\7f22fd2ad7bd09243e68766ee5fb8c8e.virus.exe /rl HIGHEST /f
- Processes Tree
- 2748 - 7f22fd2ad7bd09243e68766ee5fb8c8e.virus.exe
- 348 - C:\Users\<USER>\AppData\Roaming\Java\svchost.exe
- 2752 - schtasks /create /tn Java Updater /sc ONLOGON /tr C:\Users\<USER>\Downloads\7f22fd2ad7bd09243e68766ee5fb8c8e.virus.exe /rl HIGHEST /f
- Synchronization Mechanisms & Signals
- Mutexes Created
- QSR_MUTEX_Puy5Aj9DT5VCcZAMPh
- Modules Loaded
- Runtime Modules
- api-ms-win-core-synch-l1-2-0
- kernel32
- api-ms-win-core-fibers-l1-1-1
- api-ms-win-core-localization-l1-2-1
- ADVAPI32.dll
- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
- SHLWAPI.dll
- api-ms-win-appmodel-runtime-l1-1-2.dll
- api-ms-win-appmodel-runtime-l1-1-0.dll
- VERSION.dll
- Highlighted Actions
- Calls Highlighted
- IsDebuggerPresent
- Highlighted Text
- C:\Windows\system32\cmd.exe
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement