Advertisement
opexxx

aa8b8c39317f733d389d30db2fed1def

Mar 7th, 2017
636
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 142.02 KB | None | 0 0
  1. Bot Communication Details:
  2. Server DNS Name: 91.121.216.60 Service Port: 6892 Signature Name: Ransomware.Cerber
  3. Server DNS Name: 91.120.216.17 Service Port: 6892 Signature Name: Ransomware.Cerber
  4. Server DNS Name: 91.121.216.63 Service Port: 6892 Signature Name: Ransomware.Cerber
  5. Server DNS Name: 91.120.216.20 Service Port: 6892 Signature Name: Ransomware.Cerber
  6. Server DNS Name: 91.121.216.2 Service Port: 6892 Signature Name: Ransomware.Cerber
  7. Server DNS Name: 91.120.216.23 Service Port: 6892 Signature Name: Ransomware.Cerber
  8. Server DNS Name: 91.121.216.5 Service Port: 6892 Signature Name: Ransomware.Cerber
  9. Server DNS Name: 91.120.216.26 Service Port: 6892 Signature Name: Ransomware.Cerber
  10. Server DNS Name: 91.120.216.29 Service Port: 6892 Signature Name: Ransomware.Cerber
  11. Server DNS Name: 91.121.216.8 Service Port: 6892 Signature Name: Ransomware.Cerber
  12. Server DNS Name: 91.121.216.11 Service Port: 6892 Signature Name: Ransomware.Cerber
  13. Server DNS Name: 91.120.216.1 Service Port: 6892 Signature Name: Ransomware.Cerber
  14. Server DNS Name: 91.121.216.14 Service Port: 6892 Signature Name: Ransomware.Cerber
  15. Server DNS Name: 91.120.216.4 Service Port: 6892 Signature Name: Ransomware.Cerber
  16. Server DNS Name: 91.121.216.17 Service Port: 6892 Signature Name: Ransomware.Cerber
  17. Server DNS Name: 91.119.216.28 Service Port: 6892 Signature Name: Ransomware.Cerber
  18. Server DNS Name: 91.121.216.20 Service Port: 6892 Signature Name: Ransomware.Cerber
  19. Server DNS Name: 91.119.216.1 Service Port: 6892 Signature Name: Ransomware.Cerber
  20. Server DNS Name: 91.121.216.23 Service Port: 6892 Signature Name: Ransomware.Cerber
  21. Server DNS Name: 91.119.216.4 Service Port: 6892 Signature Name: Ransomware.Cerber
  22. Server DNS Name: 91.121.216.26 Service Port: 6892 Signature Name: Ransomware.Cerber
  23. Server DNS Name: 91.121.216.29 Service Port: 6892 Signature Name: Ransomware.Cerber
  24. Server DNS Name: 91.119.216.7 Service Port: 6892 Signature Name: Ransomware.Cerber
  25. Server DNS Name: 91.119.216.10 Service Port: 6892 Signature Name: Ransomware.Cerber
  26. Server DNS Name: 91.121.216.32 Service Port: 6892 Signature Name: Ransomware.Cerber
  27. Server DNS Name: 91.119.216.13 Service Port: 6892 Signature Name: Ransomware.Cerber
  28. Server DNS Name: 91.121.216.35 Service Port: 6892 Signature Name: Ransomware.Cerber
  29. Server DNS Name: 91.119.216.16 Service Port: 6892 Signature Name: Ransomware.Cerber
  30. Server DNS Name: 91.121.216.38 Service Port: 6892 Signature Name: Ransomware.Cerber
  31. Server DNS Name: 91.121.216.41 Service Port: 6892 Signature Name: Ransomware.Cerber
  32. Server DNS Name: 91.119.216.19 Service Port: 6892 Signature Name: Ransomware.Cerber
  33. Server DNS Name: 91.119.216.22 Service Port: 6892 Signature Name: Ransomware.Cerber
  34. Server DNS Name: 91.121.216.44 Service Port: 6892 Signature Name: Ransomware.Cerber
  35. Server DNS Name: 91.121.216.47 Service Port: 6892 Signature Name: Ransomware.Cerber
  36. Server DNS Name: 91.119.216.25 Service Port: 6892 Signature Name: Ransomware.Cerber
  37. Server DNS Name: 91.121.216.50 Service Port: 6892 Signature Name: Ransomware.Cerber
  38. Server DNS Name: 91.120.216.7 Service Port: 6892 Signature Name: Ransomware.Cerber
  39. Server DNS Name: 91.120.216.10 Service Port: 6892 Signature Name: Ransomware.Cerber
  40. Server DNS Name: 91.119.216.31 Service Port: 6892 Signature Name: Ransomware.Cerber
  41. Server DNS Name: 91.121.216.56 Service Port: 6892 Signature Name: Ransomware.Cerber
  42. Server DNS Name: 91.120.216.13 Service Port: 6892 Signature Name: Ransomware.Cerber
  43. Server DNS Name: 91.121.216.59 Service Port: 6892 Signature Name: Ransomware.Cerber
  44. Server DNS Name: 91.120.216.16 Service Port: 6892 Signature Name: Ransomware.Cerber
  45. Server DNS Name: 91.121.216.62 Service Port: 6892 Signature Name: Ransomware.Cerber
  46. Server DNS Name: 91.120.216.19 Service Port: 6892 Signature Name: Ransomware.Cerber
  47. Server DNS Name: 91.121.216.1 Service Port: 6892 Signature Name: Ransomware.Cerber
  48. Server DNS Name: 91.120.216.22 Service Port: 6892 Signature Name: Ransomware.Cerber
  49. Server DNS Name: 91.120.216.25 Service Port: 6892 Signature Name: Ransomware.Cerber
  50. Server DNS Name: 91.121.216.4 Service Port: 6892 Signature Name: Ransomware.Cerber
  51. Server DNS Name: 91.121.216.7 Service Port: 6892 Signature Name: Ransomware.Cerber
  52. Server DNS Name: 91.120.216.28 Service Port: 6892 Signature Name: Ransomware.Cerber
  53. Server DNS Name: 91.121.216.10 Service Port: 6892 Signature Name: Ransomware.Cerber
  54. Server DNS Name: 91.120.216.31 Service Port: 6892 Signature Name: Ransomware.Cerber
  55. Server DNS Name: 91.121.216.13 Service Port: 6892 Signature Name: Ransomware.Cerber
  56. Server DNS Name: 91.121.216.16 Service Port: 6892 Signature Name: Ransomware.Cerber
  57. Server DNS Name: 91.121.216.19 Service Port: 6892 Signature Name: Ransomware.Cerber
  58. Server DNS Name: 91.119.216.0 Service Port: 6892 Signature Name: Ransomware.Cerber
  59. Server DNS Name: 91.121.216.22 Service Port: 6892 Signature Name: Ransomware.Cerber
  60. Server DNS Name: 91.121.216.25 Service Port: 6892 Signature Name: Ransomware.Cerber
  61. Server DNS Name: 91.121.216.28 Service Port: 6892 Signature Name: Ransomware.Cerber
  62. Server DNS Name: 91.121.216.31 Service Port: 6892 Signature Name: Ransomware.Cerber
  63. Server DNS Name: 91.121.216.34 Service Port: 6892 Signature Name: Ransomware.Cerber
  64. Server DNS Name: 91.121.216.37 Service Port: 6892 Signature Name: Ransomware.Cerber
  65. Server DNS Name: 91.121.216.40 Service Port: 6892 Signature Name: Ransomware.Cerber
  66. Server DNS Name: 91.121.216.43 Service Port: 6892 Signature Name: Ransomware.Cerber
  67. Server DNS Name: 91.121.216.46 Service Port: 6892 Signature Name: Ransomware.Cerber
  68. Server DNS Name: 91.121.216.49 Service Port: 6892 Signature Name: Ransomware.Cerber
  69. Server DNS Name: 91.121.216.52 Service Port: 6892 Signature Name: Ransomware.Cerber
  70. Server DNS Name: 91.121.216.55 Service Port: 6892 Signature Name: Ransomware.Cerber
  71. Server DNS Name: 91.121.216.58 Service Port: 6892 Signature Name: Ransomware.Cerber
  72. Server DNS Name: 91.121.216.61 Service Port: 6892 Signature Name: Ransomware.Cerber
  73. Server DNS Name: 91.121.216.53 Service Port: 6892 Signature Name: Ransomware.Cerber
  74. Server DNS Name: 91.119.216.3 Service Port: 6892 Signature Name: Ransomware.Cerber
  75. Server DNS Name: 91.119.216.6 Service Port: 6892 Signature Name: Ransomware.Cerber
  76. Server DNS Name: 91.119.216.9 Service Port: 6892 Signature Name: Ransomware.Cerber
  77. Server DNS Name: 91.120.216.8 Service Port: 6892 Signature Name: Ransomware.Cerber
  78. Server DNS Name: 91.119.216.12 Service Port: 6892 Signature Name: Ransomware.Cerber
  79. Server DNS Name: 91.119.216.15 Service Port: 6892 Signature Name: Ransomware.Cerber
  80. Server DNS Name: 91.119.216.18 Service Port: 6892 Signature Name: Ransomware.Cerber
  81. Server DNS Name: 91.120.216.0 Service Port: 6892 Signature Name: Ransomware.Cerber
  82. Server DNS Name: 91.119.216.21 Service Port: 6892 Signature Name: Ransomware.Cerber
  83. Server DNS Name: 91.119.216.24 Service Port: 6892 Signature Name: Ransomware.Cerber
  84. Server DNS Name: 91.120.216.3 Service Port: 6892 Signature Name: Ransomware.Cerber
  85. Server DNS Name: 91.120.216.6 Service Port: 6892 Signature Name: Ransomware.Cerber
  86. Server DNS Name: 91.119.216.27 Service Port: 6892 Signature Name: Ransomware.Cerber
  87. Server DNS Name: 91.120.216.9 Service Port: 6892 Signature Name: Ransomware.Cerber
  88. Server DNS Name: 91.119.216.30 Service Port: 6892 Signature Name: Ransomware.Cerber
  89. Server DNS Name: 91.120.216.12 Service Port: 6892 Signature Name: Ransomware.Cerber
  90. Server DNS Name: 91.120.216.15 Service Port: 6892 Signature Name: Ransomware.Cerber
  91. Server DNS Name: 91.120.216.18 Service Port: 6892 Signature Name: Ransomware.Cerber
  92. Server DNS Name: 91.120.216.21 Service Port: 6892 Signature Name: Ransomware.Cerber
  93. Server DNS Name: 91.121.216.0 Service Port: 6892 Signature Name: Ransomware.Cerber
  94. Server DNS Name: 91.120.216.24 Service Port: 6892 Signature Name: Ransomware.Cerber
  95. Server DNS Name: 91.121.216.3 Service Port: 6892 Signature Name: Ransomware.Cerber
  96. Server DNS Name: 91.121.216.6 Service Port: 6892 Signature Name: Ransomware.Cerber
  97. Server DNS Name: 91.120.216.27 Service Port: 6892 Signature Name: Ransomware.Cerber
  98. Server DNS Name: 91.121.216.9 Service Port: 6892 Signature Name: Ransomware.Cerber
  99. Server DNS Name: 91.120.216.30 Service Port: 6892 Signature Name: Ransomware.Cerber
  100. Server DNS Name: 91.121.216.12 Service Port: 6892 Signature Name: Ransomware.Cerber
  101. Server DNS Name: 91.121.216.15 Service Port: 6892 Signature Name: Ransomware.Cerber
  102. Server DNS Name: 91.120.216.5 Service Port: 6892 Signature Name: Ransomware.Cerber
  103. Server DNS Name: 91.121.216.18 Service Port: 6892 Signature Name: Ransomware.Cerber
  104. Server DNS Name: 91.119.216.20 Service Port: 6892 Signature Name: Ransomware.Cerber
  105. Server DNS Name: 91.121.216.21 Service Port: 6892 Signature Name: Ransomware.Cerber
  106. Server DNS Name: 91.119.216.2 Service Port: 6892 Signature Name: Ransomware.Cerber
  107. Server DNS Name: 91.121.216.24 Service Port: 6892 Signature Name: Ransomware.Cerber
  108. Server DNS Name: 91.119.216.5 Service Port: 6892 Signature Name: Ransomware.Cerber
  109. Server DNS Name: 91.121.216.27 Service Port: 6892 Signature Name: Ransomware.Cerber
  110. Server DNS Name: 91.119.216.8 Service Port: 6892 Signature Name: Ransomware.Cerber
  111. Server DNS Name: 91.121.216.30 Service Port: 6892 Signature Name: Ransomware.Cerber
  112. Server DNS Name: 91.121.216.33 Service Port: 6892 Signature Name: Ransomware.Cerber
  113. Server DNS Name: 91.119.216.11 Service Port: 6892 Signature Name: Ransomware.Cerber
  114. Server DNS Name: 91.119.216.14 Service Port: 6892 Signature Name: Ransomware.Cerber
  115. Server DNS Name: 91.121.216.36 Service Port: 6892 Signature Name: Ransomware.Cerber
  116. Server DNS Name: 91.119.216.17 Service Port: 6892 Signature Name: Ransomware.Cerber
  117. Server DNS Name: 91.121.216.39 Service Port: 6892 Signature Name: Ransomware.Cerber
  118. Server DNS Name: 91.121.216.45 Service Port: 6892 Signature Name: Ransomware.Cerber
  119. Server DNS Name: 91.121.216.42 Service Port: 6892 Signature Name: Ransomware.Cerber
  120. Server DNS Name: 91.120.216.2 Service Port: 6892 Signature Name: Ransomware.Cerber
  121. Server DNS Name: 91.119.216.23 Service Port: 6892 Signature Name: Ransomware.Cerber
  122. Server DNS Name: 91.119.216.26 Service Port: 6892 Signature Name: Ransomware.Cerber
  123. Server DNS Name: 91.121.216.48 Service Port: 6892 Signature Name: Ransomware.Cerber
  124. Server DNS Name: 91.121.216.51 Service Port: 6892 Signature Name: Ransomware.Cerber
  125. Server DNS Name: 91.119.216.29 Service Port: 6892 Signature Name: Ransomware.Cerber
  126. Server DNS Name: 91.121.216.54 Service Port: 6892 Signature Name: Ransomware.Cerber
  127. Server DNS Name: 91.120.216.11 Service Port: 6892 Signature Name: Ransomware.Cerber
  128. Server DNS Name: 91.121.216.57 Service Port: 6892 Signature Name: Ransomware.Cerber
  129. Server DNS Name: 91.120.216.14 Service Port: 6892 Signature Name: Ransomware.Cerber
  130. Callback communication observed from VM:
  131. Server DNS Name: 91.119.216.9 Service Port: 6892 Signature Name: Ransomware.Cerber
  132. Raw Command
  133. 778ddd8e9f274b
  134. c28302753048ae
  135. Suspicious network behavior observed from VM:
  136. Raw Command
  137. 778ddd8e9f274b
  138. c28302753048ae
  139.  
  140. Download Source Headers
  141. GET
  142. /user.php?f=1.gif HTTP/1.1
  143. Date
  144. Mon, 06 Mar 2017 10:52:11 GMT
  145. Host
  146. www.dokjasura.top
  147. Content-Type
  148. text/html; charset=UTF-8
  149. User-Agent
  150. Mozilla/5.0 (Windows NT 10.0; WOW64; rv:51.0) Gecko/20100101 Firefox/51.0
  151. Transfer-Encoding
  152. chunked
  153. Accept
  154. text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
  155. Connection
  156. keep-alive
  157. Accept-Language
  158. de,en-US;q=0.7,en;q=0.3
  159. Vary
  160. Accept-Encoding
  161. Accept-Encoding
  162. gzip, deflate
  163. X-Powered-By
  164. PHP/5.6.30
  165. DNT
  166. 1
  167. Expires
  168. 0
  169. Connection
  170. keep-alive
  171. Cache-Control
  172. must-revalidate
  173. Upgrade-Insecure-Requests
  174. 1
  175. Pragma
  176. public
  177. HTTP
  178. 1.1 200 OK
  179. Content-Encoding
  180. gzip
  181. Server
  182. nginx
  183.  
  184. OS Change Detail (version: 1.2724) | Items: 538 | OS Info: Microsoft WindowsXP 32-bit 5.1 sp3 16.0901 Top
  185. Type Mode/Class Details (Path/Message/Protocol/Hostname/Qtype/ListenPort etc.) Process ID Parent ID File Size
  186. Analysis
  187. Malware
  188.  
  189.  
  190. Malicious Alert
  191. Static Analysis
  192.  
  193. Message: Static Binary Analysis
  194.  
  195. Application
  196.  
  197.  
  198. Os
  199.  
  200. Name: windows Version: 5.1.2600 Service Pack: 3 Arch: x86
  201.  
  202. Os Monitor
  203.  
  204. Version: 16R1 Build: 519813 Date: Aug 31 2016 Time: 18:44:00
  205.  
  206. Config Update
  207.  
  208.  
  209. Process
  210. Started
  211.  
  212. C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  213. Parentname: C:\WINDOWS\explorer.exe
  214. Command Line: "C:\DOCUME~1\admin\LOCALS~1\Temp\user.php.exe"
  215. MD5: aa8b8c39317f733d389d30db2fed1def
  216. SHA1: 5ba7443d6c0c0a5cf59316e0d3b3defba8c57bc8
  217. 3728 648 275476
  218. File
  219. Failed
  220.  
  221. C:\DOCUME~1\admin\LOCALS~1\Temp\LPK.DLL
  222. 3728
  223. File
  224. Failed
  225.  
  226. C:\DOCUME~1\admin\LOCALS~1\Temp\USP10.dll
  227. 3728
  228. QuerySystemTime
  229.  
  230. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  231. 3728
  232. API Call
  233.  
  234. API Name: GetSystemDirectoryW Address: 0x00406505
  235. Params: [0x12fa9c, 260]
  236. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  237. 3728
  238. Regkey
  239. Queryvalue
  240.  
  241. \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
  242. 3728
  243. API Call
  244.  
  245. API Name: GetSystemDirectoryW Address: 0x00406505
  246. Params: [0x12fa9c, 260]
  247. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  248. 3728
  249. API Call
  250.  
  251. API Name: GetSystemDirectoryW Address: 0x00406505
  252. Params: [0x12fa9c, 260]
  253. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  254. 3728
  255. API Call
  256.  
  257. API Name: GetSystemDirectoryW Address: 0x77927324
  258. Params: [0x12f0d0, 260]
  259. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  260. 3728
  261. API Call
  262.  
  263. API Name: GetComputerNameExW Address: 0x77927048
  264. Params: [0, 0x12f104, 0x12f100]
  265. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  266. 3728
  267. Regkey
  268. Queryvalue
  269.  
  270. \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
  271. 3728
  272. API Call
  273.  
  274. API Name: GetComputerNameExW Address: 0x779270ab
  275. Params: [3, 0x12f104, 0x12f100]
  276. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  277. 3728
  278. API Call
  279.  
  280. API Name: GetSystemDirectoryW Address: 0x00406505
  281. Params: [0x12fa9c, 260]
  282. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  283. 3728
  284. API Call
  285.  
  286. API Name: GetSystemDirectoryW Address: 0x00406505
  287. Params: [0x12fa9c, 260]
  288. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  289. 3728
  290. File
  291. Failed
  292.  
  293. C:\WINDOWS\system32\PROPSYS.dll
  294. 3728
  295. 2 Repeated items skipped
  296. API Call
  297.  
  298. API Name: GetSystemDirectoryW Address: 0x00406505
  299. Params: [0x12fa9c, 260]
  300. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  301. 3728
  302. File
  303. Failed
  304.  
  305. C:\WINDOWS\system32\DWMAPI.dll
  306. 3728
  307. 2 Repeated items skipped
  308. API Call
  309.  
  310. API Name: GetSystemDirectoryW Address: 0x00406505
  311. Params: [0x12fa9c, 260]
  312. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  313. 3728
  314. File
  315. Failed
  316.  
  317. C:\WINDOWS\system32\CRYPTBASE.dll
  318. 3728
  319. 2 Repeated items skipped
  320. API Call
  321.  
  322. API Name: GetSystemDirectoryW Address: 0x00406505
  323. Params: [0x12fa9c, 260]
  324. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  325. 3728
  326. API Call
  327.  
  328. API Name: GetSystemDirectoryA Address: 0x77121df1
  329. Params: [0x771a1290, 260]
  330. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  331. 3728
  332. Mutex
  333.  
  334. \BaseNamedObjects\oleacc-msaa-loaded
  335. 3728
  336. File
  337. Failed
  338.  
  339. C:\DOCUME~1\admin\LOCALS~1\Temp\OLEACCRC.DLL
  340. 3728
  341. API Call
  342.  
  343. API Name: GetSystemDirectoryW Address: 0x00406505
  344. Params: [0x12fa9c, 260]
  345. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  346. 3728
  347. API Call
  348.  
  349. API Name: GetSystemDirectoryW Address: 0x76fd7ee4
  350. Params: [0x77043650, 261]
  351. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  352. 3728
  353. API Call
  354.  
  355. API Name: GetSystemDirectoryW Address: 0x00406505
  356. Params: [0x12fa88, 260]
  357. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  358. 3728
  359. API Call
  360.  
  361. API Name: GetSystemDirectoryA Address: 0x74723c7f
  362. Params: [0x12ecc8, 261]
  363. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  364. 3728
  365. API Call
  366.  
  367. API Name: GetSystemDirectoryA Address: 0x74723c7f
  368. Params: [0x12ecd0, 261]
  369. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  370. 3728
  371. Mutex
  372.  
  373. \BaseNamedObjects\CTF.LBES.MutexDefaultS-1-5-21-1409082233-688789844-725345543-1003
  374. 3728
  375. Mutex
  376.  
  377. \BaseNamedObjects\CTF.Compart.MutexDefaultS-1-5-21-1409082233-688789844-725345543-1003
  378. 3728
  379. Mutex
  380.  
  381. \BaseNamedObjects\CTF.Asm.MutexDefaultS-1-5-21-1409082233-688789844-725345543-1003
  382. 3728
  383. Mutex
  384.  
  385. \BaseNamedObjects\CTF.Layouts.MutexDefaultS-1-5-21-1409082233-688789844-725345543-1003
  386. 3728
  387. Mutex
  388.  
  389. \BaseNamedObjects\CTF.TMD.MutexDefaultS-1-5-21-1409082233-688789844-725345543-1003
  390. 3728
  391. API Call
  392.  
  393. API Name: GetSystemDirectoryA Address: 0x74723c7f
  394. Params: [0x12ec1c, 261]
  395. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  396. 3728
  397. Mutex
  398.  
  399. \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-1409082233-688789844-725345543-1003MUTEX.Defau
  400. ltS-1-5-21-1409082233-688789844-725345543-1003
  401. 3728
  402. API Call
  403.  
  404. API Name: SetWindowsHookExA Address: 0x7473097c
  405. Params: [2, 0x747307c3, 0x74720000, 3732]
  406. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  407. 3728
  408. API Call
  409.  
  410. API Name: SetWindowsHookExA Address: 0x7473099a
  411. Params: [7, 0x747304cd, 0x74720000, 3732]
  412. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  413. 3728
  414. API Call
  415.  
  416. API Name: GetVolumeNameForVolumeMountPointW Address: 0x7ca3f17e
  417. Params: [NULL, \\?\Volume{e319f02c-31a9-11e1-9a3f-806d6172696f}\]
  418. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  419. 3728
  420. API Call
  421.  
  422. API Name: GetVolumeNameForVolumeMountPointW Address: 0x7ca3f17e
  423. Params: [NULL, \\?\Volume{e319f02e-31a9-11e1-9a3f-806d6172696f}\]
  424. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  425. 3728
  426. Regkey
  427. Setval
  428.  
  429. \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersio
  430. n\Explorer\MountPoints2\{e319f02e-31a9-11e1-9a3f-806d6172696f}\"BaseClass" = Drive
  431. 3728
  432. Regkey
  433. Setval
  434.  
  435. \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersio
  436. n\Explorer\MountPoints2\{e319f02c-31a9-11e1-9a3f-806d6172696f}\"BaseClass" = Drive
  437. 3728
  438. File
  439. Failed
  440.  
  441. C:\Documents and Settings\admin\Local Settings\Temp
  442. 3728
  443. File
  444. Created
  445.  
  446. C:\Documents and Settings\admin\Local Settings\Temp\nsqC.tmp
  447. 3728
  448. File
  449. Delete
  450.  
  451. C:\Documents and Settings\admin\Local Settings\Temp\nsqC.tmp
  452. 3728
  453. File
  454. Created
  455.  
  456. C:\Documents and Settings\admin\Local Settings\Temp\nsvD.tmp
  457. 3728
  458. File
  459. Overwritten
  460.  
  461. C:\Documents and Settings\admin\Local Settings\Temp\nsvD.tmp
  462. 3728
  463. File
  464. Delete
  465.  
  466. C:\Documents and Settings\admin\Local Settings\Temp\nsvD.tmp
  467. 3728
  468. File
  469. Failed
  470.  
  471. C:\Documents and Settings
  472. 3728
  473. File
  474. Failed
  475.  
  476. C:\Documents and Settings\admin
  477. 3728
  478. File
  479. Failed
  480.  
  481. C:\Documents and Settings\admin\Local Settings
  482. 3728
  483. File
  484. Failed
  485.  
  486. C:\Documents and Settings\admin\Local Settings\Temp
  487. 3728
  488. File
  489. Failed
  490.  
  491. C:\DOCUME~1\admin\LOCALS~1\Temp\stresses.O6T
  492. 3728
  493. 2 Repeated items skipped
  494. File
  495. Created
  496.  
  497. C:\Documents and Settings\admin\Local Settings\Temp\stresses.O6T
  498. 3728
  499. File
  500. Date Change
  501.  
  502. C:\Documents and Settings\admin\Local Settings\Temp\stresses.O6T
  503. 3728 185232
  504. File
  505. Close
  506.  
  507. C:\Documents and Settings\admin\Local Settings\Temp\stresses.O6T
  508. MD5: 5d5253dff5fd8fc7312728968c6fee5c
  509. SHA1: 7cd59d519dfb88d896d5125ff7f5d73c336fcff6
  510. 3728 185232
  511. File
  512. Failed
  513.  
  514. C:\DOCUME~1\admin\LOCALS~1\Temp\favicon.ico
  515. 3728
  516. 2 Repeated items skipped
  517. File
  518. Created
  519.  
  520. C:\Documents and Settings\admin\Local Settings\Temp\favicon.ico
  521. 3728
  522. File
  523. Date Change
  524.  
  525. C:\Documents and Settings\admin\Local Settings\Temp\favicon.ico
  526. 3728 1150
  527. File
  528. Close
  529.  
  530. C:\Documents and Settings\admin\Local Settings\Temp\favicon.ico
  531. MD5: 248cc9dffdbe8f7a66f66ebe3fa3195a
  532. SHA1: bd1de82855a6e027d539ec9098c1294a23494a63
  533. 3728 1150
  534. File
  535. Failed
  536.  
  537. C:\DOCUME~1\admin\LOCALS~1\Temp\Color-Addendum
  538. 3728
  539. 2 Repeated items skipped
  540. File
  541. Created
  542.  
  543. C:\Documents and Settings\admin\Local Settings\Temp\Color-Addendum
  544. 3728
  545. File
  546. Date Change
  547.  
  548. C:\Documents and Settings\admin\Local Settings\Temp\Color-Addendum
  549. 3728 1239
  550. File
  551. Close
  552.  
  553. C:\Documents and Settings\admin\Local Settings\Temp\Color-Addendum
  554. MD5: 438b727b40f8dba094b7854966795a4c
  555. SHA1: ba117a3f63b27f109a38cc6612501aa6819dbeb6
  556. 3728 1239
  557. File
  558. Failed
  559.  
  560. C:\DOCUME~1\admin\LOCALS~1\Temp\ie.css
  561. 3728
  562. 2 Repeated items skipped
  563. File
  564. Created
  565.  
  566. C:\Documents and Settings\admin\Local Settings\Temp\ie.css
  567. 3728
  568. File
  569. Date Change
  570.  
  571. C:\Documents and Settings\admin\Local Settings\Temp\ie.css
  572. 3728 1339
  573. File
  574. Close
  575.  
  576. C:\Documents and Settings\admin\Local Settings\Temp\ie.css
  577. MD5: 7a92334f3a6c04968d57b76cf62d971b
  578. SHA1: cb2c10b88e38d76ef162ade0cec9f52d4c87d0c4
  579. 3728 1339
  580. File
  581. Overwritten
  582.  
  583. C:\Documents and Settings\admin\Local Settings\Temp\Color-Addendum
  584. MD5: 438b727b40f8dba094b7854966795a4c
  585. SHA1: ba117a3f63b27f109a38cc6612501aa6819dbeb6
  586. 3728 1239
  587. File
  588. Date Change
  589.  
  590. C:\Documents and Settings\admin\Local Settings\Temp\Color-Addendum
  591. MD5: 438b727b40f8dba094b7854966795a4c
  592. SHA1: ba117a3f63b27f109a38cc6612501aa6819dbeb6
  593. 3728 1239
  594. File
  595. Close
  596.  
  597. C:\Documents and Settings\admin\Local Settings\Temp\Color-Addendum
  598. MD5: 438b727b40f8dba094b7854966795a4c
  599. SHA1: ba117a3f63b27f109a38cc6612501aa6819dbeb6
  600. 3728 1239
  601. File
  602. Overwritten
  603.  
  604. C:\Documents and Settings\admin\Local Settings\Temp\ie.css
  605. MD5: 7a92334f3a6c04968d57b76cf62d971b
  606. SHA1: cb2c10b88e38d76ef162ade0cec9f52d4c87d0c4
  607. 3728 1339
  608. File
  609. Date Change
  610.  
  611. C:\Documents and Settings\admin\Local Settings\Temp\ie.css
  612. MD5: 7a92334f3a6c04968d57b76cf62d971b
  613. SHA1: cb2c10b88e38d76ef162ade0cec9f52d4c87d0c4
  614. 3728 1339
  615. File
  616. Close
  617.  
  618. C:\Documents and Settings\admin\Local Settings\Temp\ie.css
  619. MD5: 7a92334f3a6c04968d57b76cf62d971b
  620. SHA1: cb2c10b88e38d76ef162ade0cec9f52d4c87d0c4
  621. 3728 1339
  622. File
  623. Failed
  624.  
  625. C:\DOCUME~1\admin\LOCALS~1\Temp\01116_UniversityNevada_Reno_CH
  626. 3728
  627. 2 Repeated items skipped
  628. File
  629. Created
  630.  
  631. C:\Documents and Settings\admin\Local Settings\Temp\01116_UniversityNevada_Reno_CH
  632. 3728
  633. File
  634. Date Change
  635.  
  636. C:\Documents and Settings\admin\Local Settings\Temp\01116_UniversityNevada_Reno_CH
  637. 3728 1255
  638. File
  639. Close
  640.  
  641. C:\Documents and Settings\admin\Local Settings\Temp\01116_UniversityNevada_Reno_CH
  642. MD5: 25903ca9fc27d2b28d81e62497a7b92e
  643. SHA1: 649b2f31d74a21cc67295e878a59dd2a5f0ce1b5
  644. 3728 1255
  645. File
  646. Created
  647.  
  648. C:\Documents and Settings\admin\Local Settings\Temp\nsrE.tmp
  649. 3728
  650. File
  651. Delete
  652.  
  653. C:\Documents and Settings\admin\Local Settings\Temp\nsrE.tmp
  654. 3728
  655. File
  656. Failed
  657.  
  658. C:\Documents and Settings
  659. 3728
  660. File
  661. Failed
  662.  
  663. C:\Documents and Settings\admin
  664. 3728
  665. File
  666. Failed
  667.  
  668. C:\Documents and Settings\admin\Local Settings
  669. 3728
  670. File
  671. Failed
  672.  
  673. C:\Documents and Settings\admin\Local Settings\Temp
  674. 3728
  675. Folder
  676. Created
  677.  
  678. C:\Documents and Settings\admin\Local Settings\Temp\nsrE.tmp
  679. 3728
  680. File
  681. Failed
  682.  
  683. C:\Documents and Settings\admin\Local Settings\Temp\nsrE.tmp\System.dll
  684. 3728
  685. File
  686. Created
  687.  
  688. C:\Documents and Settings\admin\Local Settings\Temp\nsrE.tmp\System.dll
  689. 3728
  690. Malicious Alert
  691. Install Activity
  692.  
  693. Message: NSIS Install Activity
  694.  
  695. File
  696. Close
  697.  
  698. C:\Documents and Settings\admin\Local Settings\Temp\nsrE.tmp\System.dll
  699. MD5: a4dd044bcd94e9b3370ccf095b31f896
  700. SHA1: 17c78201323ab2095bc53184aa8267c9187d5173
  701. 3728 11776
  702. DLL Loaded
  703.  
  704. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  705. DLL Path: C:\Documents and Settings\admin\Local Settings\Temp\nsrE.tmp\System.dll
  706. MD5: a4dd044bcd94e9b3370ccf095b31f896
  707. SHA1: 17c78201323ab2095bc53184aa8267c9187d5173
  708. 3728
  709. Malicious Alert
  710. Generic Dll Load Activity
  711.  
  712. Message: DLL loaded
  713.  
  714. File
  715. Failed
  716.  
  717. C:\Documents and Settings\admin\Local Settings\Temp\nsrE.tmp\System.dll
  718. 3728
  719. 278 Repeated items skipped
  720. High Cpu
  721.  
  722. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  723. 3728
  724. File
  725. Failed
  726.  
  727. C:\Documents and Settings\admin\Local Settings\Temp\nsrE.tmp\System.dll
  728. 3728
  729. 193 Repeated items skipped
  730. Wmiquery
  731.  
  732. Imagepath: C:\WINDOWS\system32\wbem\wmiprvse.exe
  733. 3596
  734. High Cpu
  735.  
  736. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  737. 3728
  738. ProcessTelemetryReport
  739.  
  740. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  741. 3728
  742. High Cpu
  743.  
  744. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  745. 3728
  746. File
  747. Failed
  748.  
  749. C:\Documents and Settings\admin\Local Settings\Temp\nsrE.tmp\System.dll
  750. 3728
  751. High Cpu
  752.  
  753. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  754. 3728
  755. ProcessTelemetryReport
  756.  
  757. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  758. 3728
  759. High Cpu
  760.  
  761. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  762. 3728
  763. File
  764. Failed
  765.  
  766. C:\Documents and Settings\admin\Local Settings\Temp\nsrE.tmp\System.dll
  767. 3728
  768. High Cpu
  769.  
  770. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  771. 3728
  772. ProcessTelemetryReport
  773.  
  774. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  775. 3728
  776. File
  777. Failed
  778.  
  779. C:\Documents and Settings\admin\Local Settings\Temp\nsrE.tmp\System.dll
  780. 3728
  781. API Call
  782.  
  783. API Name: FindWindowExW Address: 0x00401c8f
  784. Params: [0x0, 0x0, circumstance, NULL]
  785. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  786. 3728
  787. API Call
  788.  
  789. API Name: FindWindowExW Address: 0x00401c8f
  790. Params: [0x0, 0x0, cheeks, NULL]
  791. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  792. 3728
  793. API Call
  794.  
  795. API Name: FindWindowExW Address: 0x00401c8f
  796. Params: [0x0, 0x0, duplicate, NULL]
  797. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  798. 3728
  799. API Call
  800.  
  801. API Name: FindWindowExW Address: 0x00401c8f
  802. Params: [0x0, 0x0, blanket, NULL]
  803. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  804. 3728
  805. API Call
  806.  
  807. API Name: FindWindowExW Address: 0x00401c8f
  808. Params: [0x0, 0x0, curtain, NULL]
  809. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  810. 3728
  811. API Call
  812.  
  813. API Name: FindWindowExW Address: 0x00401c8f
  814. Params: [0x0, 0x0, widths, NULL]
  815. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  816. 3728
  817. API Call
  818.  
  819. API Name: FindWindowExW Address: 0x00401c8f
  820. Params: [0x0, 0x0, person, NULL]
  821. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  822. 3728
  823. API Call
  824.  
  825. API Name: FindWindowExW Address: 0x00401c8f
  826. Params: [0x0, 0x0, thin, NULL]
  827. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  828. 3728
  829. API Call
  830.  
  831. API Name: FindWindowExW Address: 0x00401c8f
  832. Params: [0x0, 0x0, breakdowns, NULL]
  833. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  834. 3728
  835. API Call
  836.  
  837. API Name: FindWindowExW Address: 0x00401c8f
  838. Params: [0x0, 0x0, preliminaries, NULL]
  839. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  840. 3728
  841. API Call
  842.  
  843. API Name: FindWindowExW Address: 0x00401c8f
  844. Params: [0x0, 0x0, bushing, NULL]
  845. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  846. 3728
  847. API Call
  848.  
  849. API Name: FindWindowExW Address: 0x00401c8f
  850. Params: [0x0, 0x0, breakdowns, NULL]
  851. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  852. 3728
  853. API Call
  854.  
  855. API Name: FindWindowExW Address: 0x00401c8f
  856. Params: [0x0, 0x0, preliminaries, NULL]
  857. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  858. 3728
  859. API Call
  860.  
  861. API Name: FindWindowExW Address: 0x00401c8f
  862. Params: [0x0, 0x0, bushing, NULL]
  863. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  864. 3728
  865. API Call
  866.  
  867. API Name: FindWindowExW Address: 0x00401c8f
  868. Params: [0x0, 0x0, breakdowns, NULL]
  869. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  870. 3728
  871. API Call
  872.  
  873. API Name: FindWindowExW Address: 0x00401c8f
  874. Params: [0x0, 0x0, preliminaries, NULL]
  875. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  876. 3728
  877. API Call
  878.  
  879. API Name: FindWindowExW Address: 0x00401c8f
  880. Params: [0x0, 0x0, bushing, NULL]
  881. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  882. 3728
  883. API Call
  884.  
  885. API Name: FindWindowExW Address: 0x00401c8f
  886. Params: [0x0, 0x0, breakdowns, NULL]
  887. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  888. 3728
  889. API Call
  890.  
  891. API Name: FindWindowExW Address: 0x00401c8f
  892. Params: [0x0, 0x0, preliminaries, NULL]
  893. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  894. 3728
  895. API Call
  896.  
  897. API Name: FindWindowExW Address: 0x00401c8f
  898. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  899. 3728
  900. API Call
  901.  
  902. API Name: FindWindowExW Address: 0x00401c8f
  903. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  904. 3728
  905. 12 Repeated items skipped
  906. High Cpu
  907.  
  908. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  909. 3728
  910. API Call
  911.  
  912. API Name: CryptAcquireContextW Address: 0x0120b208
  913. Params: [NULL, NULL, 24, 4026531840]
  914. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: advapi32.dll
  915. 3728
  916. FirstRpidMemOp
  917. ReadVirtualMemory
  918.  
  919. Source: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  920. Target: N/A
  921.  
  922. 3728
  923. 3768
  924.  
  925. Process
  926. Started
  927.  
  928. C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  929. Parentname: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  930. Command Line: "C:\DOCUME~1\admin\LOCALS~1\Temp\user.php.exe"
  931. MD5: aa8b8c39317f733d389d30db2fed1def
  932. SHA1: 5ba7443d6c0c0a5cf59316e0d3b3defba8c57bc8
  933. 3768 3728 275476
  934. File
  935. Open
  936.  
  937. C:
  938. 3768
  939. Codeinjection
  940. Create process suspended section mapped code injection
  941.  
  942. Source: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  943. Target: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  944.  
  945. 3728
  946. 3768
  947.  
  948. Malicious Alert
  949. Code Injection Tracking
  950.  
  951. Message: Code Injection Obsevered
  952.  
  953. Codeinjection
  954. Create process suspended memory write code injection
  955.  
  956. Source: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  957. Target: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  958.  
  959. 3728
  960. 3768
  961.  
  962. Process
  963. Terminated
  964.  
  965. C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  966. Parentname: C:\WINDOWS\explorer.exe
  967. Command Line: N/A
  968. 3728 648
  969. File
  970. Close
  971.  
  972. C:\Documents and Settings\admin\Local Settings\Temp\nsvD.tmp
  973. MD5: 66f2539e5f3ef77f2b6395813d442883
  974. SHA1: ca6f8cf2d1f699c100efc19fad97b3b889752de0
  975. 3728 336787
  976. File
  977. Failed
  978.  
  979. C:\WINDOWS\system32\config\system
  980. 3768
  981. File
  982. Close
  983.  
  984. C:
  985. 3768
  986. Malicious Alert
  987. Hardware Tampering Activity
  988.  
  989. Message: Direct disk access
  990.  
  991. QuerySystemTime
  992.  
  993. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  994. 3768
  995. Regkey
  996. Queryvalue
  997.  
  998. \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
  999. 3768
  1000. File
  1001. Failed
  1002.  
  1003. C:\DOCUME~1\admin\LOCALS~1\Temp\crypt32.dll
  1004. 3768
  1005. File
  1006. Failed
  1007.  
  1008. C:\DOCUME~1\admin\LOCALS~1\Temp\MSASN1.dll
  1009. 3768
  1010. API Call
  1011.  
  1012. API Name: GetSystemDirectoryW Address: 0x7e43d9a0
  1013. Params: [0x12ec28, 260]
  1014. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1015. 3768
  1016. API Call
  1017.  
  1018. API Name: GetSystemDirectoryW Address: 0x7e43d9a0
  1019. Params: [0x12e0f4, 260]
  1020. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1021. 3768
  1022. API Call
  1023.  
  1024. API Name: GetSystemDirectoryW Address: 0x7e43d9a0
  1025. Params: [0x12efa8, 260]
  1026. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1027. 3768
  1028. File
  1029. Failed
  1030.  
  1031. C:\DOCUME~1\admin\LOCALS~1\Temp\LPK.DLL
  1032. 3768
  1033. File
  1034. Failed
  1035.  
  1036. C:\DOCUME~1\admin\LOCALS~1\Temp\USP10.dll
  1037. 3768
  1038. File
  1039. Failed
  1040.  
  1041. C:\DOCUME~1\admin\LOCALS~1\Temp\netapi32.dll
  1042. 3768
  1043. API Call
  1044.  
  1045. API Name: GetSystemDirectoryA Address: 0x77121df1
  1046. Params: [0x771a1290, 260]
  1047. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1048. 3768
  1049. File
  1050. Failed
  1051.  
  1052. C:\DOCUME~1\admin\LOCALS~1\Temp\powrprof.dll
  1053. 3768
  1054. File
  1055. Failed
  1056.  
  1057. C:\DOCUME~1\admin\LOCALS~1\Temp\ws2_32.dll
  1058. 3768
  1059. File
  1060. Failed
  1061.  
  1062. C:\DOCUME~1\admin\LOCALS~1\Temp\WS2HELP.dll
  1063. 3768
  1064. File
  1065. Failed
  1066.  
  1067. C:\DOCUME~1\admin\LOCALS~1\Temp\rsaenh.dll
  1068. 3768
  1069. 3 Repeated items skipped
  1070. File
  1071. Failed
  1072.  
  1073. C:\TEST\CERBER_DEBUG.TXT
  1074. 3768
  1075. File
  1076. Failed
  1077.  
  1078. C:\DOCUME~1\admin\LOCALS~1\Temp\B4B3A38D\8055.TMP
  1079. 3768
  1080. API Call
  1081.  
  1082. API Name: GetComputerNameA Address: 0x00409e10
  1083. Params: [0x12f980, 0x12f990]
  1084. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1085. 3768
  1086. Regkey
  1087. Queryvalue
  1088.  
  1089. \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
  1090. 3768
  1091. Mutex
  1092.  
  1093. \BaseNamedObjects\shell.{EC6CB98A-B4CC-9D0C-5622-C82B4F28BE70}
  1094. 3768
  1095. API Call
  1096.  
  1097. API Name: GetSystemDirectoryA Address: 0x74723c7f
  1098. Params: [0xc7eda8, 261]
  1099. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1100. 3768
  1101. API Call
  1102.  
  1103. API Name: GetSystemDirectoryA Address: 0x74723c7f
  1104. Params: [0xc7edb0, 261]
  1105. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1106. 3768
  1107. Mutex
  1108.  
  1109. \BaseNamedObjects\CTF.LBES.MutexDefaultS-1-5-21-1409082233-688789844-725345543-1003
  1110. 3768
  1111. Mutex
  1112.  
  1113. \BaseNamedObjects\CTF.Compart.MutexDefaultS-1-5-21-1409082233-688789844-725345543-1003
  1114. 3768
  1115. Mutex
  1116.  
  1117. \BaseNamedObjects\CTF.Asm.MutexDefaultS-1-5-21-1409082233-688789844-725345543-1003
  1118. 3768
  1119. Mutex
  1120.  
  1121. \BaseNamedObjects\CTF.Layouts.MutexDefaultS-1-5-21-1409082233-688789844-725345543-1003
  1122. 3768
  1123. Mutex
  1124.  
  1125. \BaseNamedObjects\CTF.TMD.MutexDefaultS-1-5-21-1409082233-688789844-725345543-1003
  1126. 3768
  1127. API Call
  1128.  
  1129. API Name: GetSystemDirectoryA Address: 0x74723c7f
  1130. Params: [0xc7ecfc, 261]
  1131. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1132. 3768
  1133. Mutex
  1134.  
  1135. \BaseNamedObjects\CTF.TimListCache.FMPDefaultS-1-5-21-1409082233-688789844-725345543-1003MUTEX.Defau
  1136. ltS-1-5-21-1409082233-688789844-725345543-1003
  1137. 3768
  1138. API Call
  1139.  
  1140. API Name: SetWindowsHookExA Address: 0x7473097c
  1141. Params: [2, 0x747307c3, 0x74720000, 3776]
  1142. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  1143. 3768
  1144. API Call
  1145.  
  1146. API Name: SetWindowsHookExA Address: 0x7473099a
  1147. Params: [7, 0x747304cd, 0x74720000, 3776]
  1148. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  1149. 3768
  1150. API Call
  1151.  
  1152. API Name: GetSystemDirectoryW Address: 0x763982be
  1153. Params: [0xc7edf0, 260]
  1154. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1155. 3768
  1156. File
  1157. Failed
  1158.  
  1159. C:\TEST\CERBER_DEBUG2.TXT
  1160. 3768
  1161. File
  1162. Failed
  1163.  
  1164. C:\DOCUME~1\admin\LOCALS~1\Temp\hnetcfg.dll
  1165. 3768
  1166. API Call
  1167.  
  1168. API Name: GetSystemDirectoryW Address: 0x763982be
  1169. Params: [0xc7f3a0, 260]
  1170. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1171. 3768
  1172. API Call
  1173.  
  1174. API Name: GetSystemDirectoryA Address: 0x755dd289
  1175. Params: [0xc7e9e4, 261]
  1176. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1177. 3768
  1178. API Call
  1179.  
  1180. API Name: GetSystemDirectoryA Address: 0x755dd289
  1181. Params: [0xc7f488, 261]
  1182. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1183. 3768
  1184. API Call
  1185.  
  1186. API Name: GetSystemDirectoryW Address: 0x763982be
  1187. Params: [0xc7f010, 260]
  1188. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1189. 3768
  1190. API Call
  1191.  
  1192. API Name: Sleep Address: 0x0040b28f
  1193. Params: [1000]
  1194. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1195. 3768
  1196. API Call
  1197.  
  1198. API Name: Sleep Address: 0x0040b28f
  1199. Params: [1000]
  1200. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1201. 3768
  1202. 3 Repeated items skipped
  1203. File
  1204. Failed
  1205.  
  1206. C:\DOCUME~1\admin\LOCALS~1\Temp\b4b3a38d
  1207. 3768
  1208. Folder
  1209. Created
  1210.  
  1211. C:\Documents and Settings\admin\Local Settings\Temp\b4b3a38d
  1212. 3768
  1213. File
  1214. Created
  1215.  
  1216. C:\Documents and Settings\admin\Local Settings\Temp\b4b3a38d\487a.tmp
  1217. 3768
  1218. File
  1219. Close
  1220.  
  1221. C:\Documents and Settings\admin\Local Settings\Temp\b4b3a38d\487a.tmp
  1222. MD5: c2830275304891d543741f817b1e8dc5
  1223. SHA1: 2f340067c6b0f2579bcbb7b864c0d01d7c6129e8
  1224. 3768 344
  1225. File
  1226. Created
  1227.  
  1228. C:\Documents and Settings\admin\Local Settings\Temp\b4b3a38d\8055.tmp
  1229. 3768
  1230. File
  1231. Close
  1232.  
  1233. C:\Documents and Settings\admin\Local Settings\Temp\b4b3a38d\8055.tmp
  1234. MD5: 22eac7860ea23449fd32fb6881039a35
  1235. SHA1: 6dcb41aa42912a8d4f6064245d647ef8a2c32cd3
  1236. 3768 130
  1237. API Call
  1238.  
  1239. API Name: SetWindowsHookExA Address: 0x7473097c
  1240. Params: [2, 0x747307c3, 0x74720000, 3772]
  1241. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  1242. 3768
  1243. API Call
  1244.  
  1245. API Name: SetWindowsHookExA Address: 0x7473099a
  1246. Params: [7, 0x747304cd, 0x74720000, 3772]
  1247. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  1248. 3768
  1249. API Call
  1250.  
  1251. API Name: GetSystemDirectoryW Address: 0x0040d594
  1252. Params: [0x12f5a8, 260]
  1253. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1254. 3768
  1255. File
  1256. Failed
  1257.  
  1258. C:\DOCUME~1\admin\LOCALS~1\Temp\SETUPAPI.dll
  1259. 3768
  1260. API Call
  1261.  
  1262. API Name: GetSystemDirectoryW Address: 0x77927324
  1263. Params: [0x12daec, 260]
  1264. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1265. 3768
  1266. API Call
  1267.  
  1268. API Name: GetComputerNameExW Address: 0x77927048
  1269. Params: [0, 0x12db20, 0x12db1c]
  1270. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1271. 3768
  1272. API Call
  1273.  
  1274. API Name: GetComputerNameExW Address: 0x779270ab
  1275. Params: [3, 0x12db20, 0x12db1c]
  1276. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1277. 3768
  1278. Regkey
  1279. Queryvalue
  1280.  
  1281. \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
  1282. 3768
  1283. API Call
  1284.  
  1285. API Name: GetVolumeNameForVolumeMountPointW Address: 0x7ca3f17e
  1286. Params: [NULL, \\?\Volume{e319f02c-31a9-11e1-9a3f-806d6172696f}\]
  1287. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1288. 3768
  1289. API Call
  1290.  
  1291. API Name: GetVolumeNameForVolumeMountPointW Address: 0x7ca3f17e
  1292. Params: [NULL, \\?\Volume{e319f02e-31a9-11e1-9a3f-806d6172696f}\]
  1293. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1294. 3768
  1295. Regkey
  1296. Setval
  1297.  
  1298. \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersio
  1299. n\Explorer\MountPoints2\{e319f02e-31a9-11e1-9a3f-806d6172696f}\"BaseClass" = Drive
  1300. 3768
  1301. Regkey
  1302. Setval
  1303.  
  1304. \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersio
  1305. n\Explorer\MountPoints2\{e319f02c-31a9-11e1-9a3f-806d6172696f}\"BaseClass" = Drive
  1306. 3768
  1307. Regkey
  1308. Setval
  1309.  
  1310. \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\CurrentVersio
  1311. n\Explorer\Shell Folders\"Recent" = C:\Documents and Settings\admin\Recent
  1312. 3768
  1313. File
  1314. Failed
  1315.  
  1316. C:\DOCUME~1\admin\LOCALS~1\Temp\CLBCATQ.DLL
  1317. 3768
  1318. File
  1319. Failed
  1320.  
  1321. C:\DOCUME~1\admin\LOCALS~1\Temp\COMRes.dll
  1322. 3768
  1323. API Call
  1324.  
  1325. API Name: GetSystemDirectoryW Address: 0x76fd7ee4
  1326. Params: [0x77043650, 261]
  1327. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1328. 3768
  1329. File
  1330. Failed
  1331.  
  1332. C:\DOCUME~1\admin\LOCALS~1\Temp\LINKINFO.dll
  1333. 3768
  1334. File
  1335. Failed
  1336.  
  1337. C:\DOCUME~1\admin\LOCALS~1\Temp\ntshrui.dll
  1338. 3768
  1339. File
  1340. Failed
  1341.  
  1342. C:\DOCUME~1\admin\LOCALS~1\Temp\ATL.DLL
  1343. 3768
  1344. Regkey
  1345. Setval
  1346.  
  1347. \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows\ShellNoRoam\M
  1348. UICache\"@C:\WINDOWS\System32\cryptext.dll,-6108" = Security Certificate
  1349. 3768
  1350. Regkey
  1351. Added
  1352.  
  1353. \REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
  1354. 3768
  1355. Regkey
  1356. Added
  1357.  
  1358. \REGISTRY\MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
  1359. 3768
  1360. Regkey
  1361. Setval
  1362.  
  1363. \REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\"Common Documents
  1364. " = C:\Documents and Settings\All Users\Documents
  1365. 3768
  1366. Process
  1367. Opened
  1368.  
  1369. Source: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  1370. Target: C:\WINDOWS\explorer.exe
  1371.  
  1372. 3768
  1373. 648
  1374.  
  1375. Malicious Alert
  1376. Process Based Anomaly
  1377.  
  1378. Message: Duplicate handle acquired on Windows process
  1379.  
  1380. Process
  1381. Opened
  1382.  
  1383. Source: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  1384. Target: C:\WINDOWS\explorer.exe
  1385.  
  1386. 3768
  1387. 648
  1388.  
  1389. 3 Repeated items skipped
  1390. API Call
  1391.  
  1392. API Name: GetSystemDirectoryW Address: 0x4ec766bf
  1393. Params: [0x12f45c, 260]
  1394. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1395. 3768
  1396. API Call
  1397.  
  1398. API Name: SetWindowsHookExA Address: 0x7473097c
  1399. Params: [2, 0x747307c3, 0x74720000, 3788]
  1400. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  1401. 3768
  1402. API Call
  1403.  
  1404. API Name: SetWindowsHookExA Address: 0x7473099a
  1405. Params: [7, 0x747304cd, 0x74720000, 3788]
  1406. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  1407. 3768
  1408. API Call
  1409.  
  1410. API Name: GetSystemDirectoryW Address: 0x755dd323
  1411. Params: [0xfefc7c, 261]
  1412. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1413. 3768
  1414. API Call
  1415.  
  1416. API Name: GetSystemDirectoryW Address: 0x755dd323
  1417. Params: [0xfefc7c, 261]
  1418. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1419. 3768
  1420. Regkey
  1421. Added
  1422.  
  1423. \REGISTRY\MACHINE\Software\Microsoft\WBEM\CIMOM
  1424. 3768
  1425. 2 Repeated items skipped
  1426. API Call
  1427.  
  1428. API Name: GetComputerNameExW Address: 0x74ef1bbf
  1429. Params: [3, 0x0, 0x12f094]
  1430. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1431. 3768
  1432. API Call
  1433.  
  1434. API Name: GetComputerNameExW Address: 0x74ef1c16
  1435. Params: [3, 0xe6f6e0, 0x12f094]
  1436. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1437. 3768
  1438. File
  1439. Failed
  1440.  
  1441. C:\DOCUME~1\admin\LOCALS~1\Temp\xpsp2res.dll
  1442. 3768
  1443. API Call
  1444.  
  1445. API Name: GetComputerNameW Address: 0x77e8dedd
  1446. Params: [0x1a10d8, 0x12eac0]
  1447. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1448. 3768
  1449. Regkey
  1450. Queryvalue
  1451.  
  1452. \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
  1453. 3768
  1454. API Call
  1455.  
  1456. API Name: Sleep Address: 0x774fe32f
  1457. Params: [60000]
  1458. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1459. 3768
  1460. API Call
  1461.  
  1462. API Name: GetComputerNameW Address: 0x74ef198a
  1463. Params: [0x12f874, 0x12f868]
  1464. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1465. 3768
  1466. Regkey
  1467. Queryvalue
  1468.  
  1469. \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
  1470. 3768
  1471. File
  1472. Failed
  1473.  
  1474. C:\WINDOWS\system32\wbem\MSVCP60.dll
  1475. 3768
  1476. File
  1477. Failed
  1478.  
  1479. C:\WINDOWS\system32\wbem\NTDSAPI.dll
  1480. 3768
  1481. File
  1482. Failed
  1483.  
  1484. C:\WINDOWS\system32\wbem\DNSAPI.dll
  1485. 3768
  1486. Wmiquery
  1487.  
  1488. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  1489. 3768
  1490. API Call
  1491.  
  1492. API Name: GetComputerNameExW Address: 0x74ef1bbf
  1493. Params: [3, 0x0, 0x12f094]
  1494. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1495. 3768
  1496. API Call
  1497.  
  1498. API Name: GetComputerNameExW Address: 0x74ef1c16
  1499. Params: [3, 0xe70308, 0x12f094]
  1500. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1501. 3768
  1502. API Call
  1503.  
  1504. API Name: GetComputerNameW Address: 0x74ef198a
  1505. Params: [0x12f874, 0x12f868]
  1506. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1507. 3768
  1508. Regkey
  1509. Queryvalue
  1510.  
  1511. \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
  1512. 3768
  1513. File
  1514. Created
  1515.  
  1516. C:\WINDOWS\system32\wbem\Logs\wbemprox.log
  1517. 3768
  1518. Malicious Alert
  1519. Suspicious Directory
  1520.  
  1521. Message: File created/tampered/deleted in suspicious location
  1522.  
  1523. File
  1524. Close
  1525.  
  1526. C:\WINDOWS\system32\wbem\Logs\wbemprox.log
  1527. MD5: d92df603f7b28a7371804c736ef3fc5a
  1528. SHA1: be52e29a7616c9113e497a96c6017b61eb82bfe6
  1529. 3768 76
  1530. API Call
  1531.  
  1532. API Name: GetComputerNameExW Address: 0x74ef1bbf
  1533. Params: [3, 0x0, 0x12f094]
  1534. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1535. 3768
  1536. API Call
  1537.  
  1538. API Name: GetComputerNameExW Address: 0x74ef1c16
  1539. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1540. 3768
  1541. API Call
  1542.  
  1543. API Name: Sleep Address: 0x774fe32f
  1544. Params: [60000]
  1545. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1546. 3768
  1547. API Call
  1548.  
  1549. API Name: Sleep Address: 0x774fe32f
  1550. Params: [60000]
  1551. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1552. 3768
  1553. API Call
  1554.  
  1555. API Name: Sleep Address: 0x774fe32f
  1556. Params: [60000]
  1557. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1558. 3768
  1559. API Call
  1560.  
  1561. API Name: GetComputerNameW Address: 0x74ef198a
  1562. Params: [0x12f874, 0x12f868]
  1563. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1564. 3768
  1565. Regkey
  1566. Queryvalue
  1567.  
  1568. \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
  1569. 3768
  1570. API Call
  1571.  
  1572. API Name: Sleep Address: 0x774fe32f
  1573. Params: [60000]
  1574. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1575. 3768
  1576. Wmiquery
  1577.  
  1578. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  1579. 3768
  1580. API Call
  1581.  
  1582. API Name: Sleep Address: 0x774fe32f
  1583. Params: [60000]
  1584. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1585. 3768
  1586. API Call
  1587.  
  1588. API Name: Sleep Address: 0x774fe32f
  1589. Params: [60000]
  1590. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1591. 3768
  1592. 6 Repeated items skipped
  1593. API Call
  1594.  
  1595. API Name: GetComputerNameW Address: 0x74ef198a
  1596. Params: [0x12f874, 0x12f868]
  1597. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1598. 3768
  1599. Regkey
  1600. Queryvalue
  1601.  
  1602. \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
  1603. 3768
  1604. API Call
  1605.  
  1606. API Name: Sleep Address: 0x774fe32f
  1607. Params: [60000]
  1608. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1609. 3768
  1610. File
  1611. Open
  1612.  
  1613. C:\WINDOWS\system32\wbem\Logs\wbemprox.log
  1614. MD5: d92df603f7b28a7371804c736ef3fc5a
  1615. SHA1: be52e29a7616c9113e497a96c6017b61eb82bfe6
  1616. 3768 76
  1617. File
  1618. Close
  1619.  
  1620. C:\WINDOWS\system32\wbem\Logs\wbemprox.log
  1621. MD5: 125c5692d44f9bc16c67dd42b2a9d543
  1622. SHA1: 97c2bc88af0e16a5628d9e1a5cfe3cf3c33ac9db
  1623. 3768 152
  1624. API Call
  1625.  
  1626. API Name: Sleep Address: 0x774fe32f
  1627. Params: [60000]
  1628. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1629. 3768
  1630. API Call
  1631.  
  1632. API Name: GetComputerNameW Address: 0x74ef198a
  1633. Params: [0x12f874, 0x12f868]
  1634. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1635. 3768
  1636. Regkey
  1637. Queryvalue
  1638.  
  1639. \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
  1640. 3768
  1641. API Call
  1642.  
  1643. API Name: Sleep Address: 0x774fe32f
  1644. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1645. 3768
  1646. Wmiquery
  1647.  
  1648. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  1649. 3768
  1650. API Call
  1651.  
  1652. API Name: GetComputerNameW Address: 0x74ef198a
  1653. Params: [0x12f874, 0x12f868]
  1654. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1655. 3768
  1656. Regkey
  1657. Queryvalue
  1658.  
  1659. \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
  1660. 3768
  1661. File
  1662. Open
  1663.  
  1664. C:\WINDOWS\system32\wbem\Logs\wbemprox.log
  1665. MD5: 125c5692d44f9bc16c67dd42b2a9d543
  1666. SHA1: 97c2bc88af0e16a5628d9e1a5cfe3cf3c33ac9db
  1667. 3768 152
  1668. File
  1669. Close
  1670.  
  1671. C:\WINDOWS\system32\wbem\Logs\wbemprox.log
  1672. MD5: 6bc1b9f442f524abe56367433dc2ffbb
  1673. SHA1: b5ce5f03e7cdb32f504a665b9638acbbca7ced42
  1674. 3768 228
  1675. API Call
  1676.  
  1677. API Name: Sleep Address: 0x774fe32f
  1678. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1679. 3768
  1680. API Call
  1681.  
  1682. API Name: GetSystemDirectoryW Address: 0x0040e669
  1683. Params: [0x12f888, 260]
  1684. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1685. 3768
  1686. File
  1687. Find
  1688.  
  1689. C:\*
  1690. 3768
  1691. File
  1692. Find
  1693.  
  1694. C:\Documents and Settings\*
  1695. 3768
  1696. File
  1697. Find
  1698.  
  1699. C:\Documents and Settings\*\*
  1700. 3768
  1701. Folder
  1702. Open
  1703.  
  1704. C:\Documents and Settings\admin\Cookies
  1705. 3768
  1706. API Call
  1707.  
  1708. API Name: Sleep Address: 0x0040e33c
  1709. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1710. 3768
  1711. Folder
  1712. Open
  1713.  
  1714. C:\Documents and Settings\admin\My Documents
  1715. 3768
  1716. 3 Repeated items skipped
  1717. Folder
  1718. Open
  1719.  
  1720. C:\Documents and Settings\admin\My Documents
  1721. 3768
  1722. Folder
  1723. Open
  1724.  
  1725. C:\Documents and Settings\admin\My Documents
  1726. 3768
  1727. API Call
  1728.  
  1729. API Name: Sleep Address: 0x0040e33c
  1730. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1731. 3768
  1732. API Call
  1733.  
  1734. API Name: Sleep Address: 0x0040e33c
  1735. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1736. 3768
  1737. API Call
  1738.  
  1739. API Name: Sleep Address: 0x0040e33c
  1740. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  1741. 3768
  1742. File
  1743. Failed
  1744.  
  1745. C:\Program Files\bitcoin
  1746. 3768
  1747. File
  1748. Failed
  1749.  
  1750. C:\Program Files\bitcoin
  1751. 3768
  1752. File
  1753. Failed
  1754.  
  1755. C:\Program Files\bitcoin
  1756. 3768
  1757. File
  1758. Failed
  1759.  
  1760. C:\WINDOWS\system32\config\systemprofile\Application Data\bitcoin
  1761. 3768
  1762. File
  1763. Failed
  1764.  
  1765. C:\WINDOWS\system32\config\systemprofile\Application Data\bitcoin
  1766. 3768
  1767. File
  1768. Failed
  1769.  
  1770. C:\WINDOWS\system32\config\systemprofile\Application Data\bitcoin
  1771. 3768
  1772. File
  1773. Failed
  1774.  
  1775. C:\Documents and Settings\LocalService\Application Data\bitcoin
  1776. 3768
  1777. File
  1778. Failed
  1779.  
  1780. C:\Documents and Settings\LocalService\Application Data\bitcoin
  1781. 3768
  1782. File
  1783. Failed
  1784.  
  1785. C:\Documents and Settings\LocalService\Application Data\bitcoin
  1786. 3768
  1787. File
  1788. Failed
  1789.  
  1790. C:\Documents and Settings\NetworkService\Application Data\bitcoin
  1791. 3768
  1792. File
  1793. Failed
  1794.  
  1795. C:\Documents and Settings\NetworkService\Application Data\bitcoin
  1796. 3768
  1797. File
  1798. Failed
  1799.  
  1800. C:\Documents and Settings\NetworkService\Application Data\bitcoin
  1801. 3768
  1802. File
  1803. Failed
  1804.  
  1805. C:\Documents and Settings\admin\Application Data\bitcoin
  1806. 3768
  1807. File
  1808. Failed
  1809.  
  1810. C:\Documents and Settings\admin\Application Data\bitcoin
  1811. 3768
  1812. File
  1813. Failed
  1814.  
  1815. C:\Documents and Settings\admin\Application Data\bitcoin
  1816. 3768
  1817. File
  1818. Failed
  1819.  
  1820. C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\bitcoin
  1821. 3768
  1822. File
  1823. Failed
  1824.  
  1825. C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\bitcoin
  1826. 3768
  1827. File
  1828. Failed
  1829.  
  1830. C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\bitcoin
  1831. 3768
  1832. File
  1833. Failed
  1834.  
  1835. C:\Documents and Settings\LocalService\Local Settings\Application Data\bitcoin
  1836. 3768
  1837. File
  1838. Failed
  1839.  
  1840. C:\Documents and Settings\LocalService\Local Settings\Application Data\bitcoin
  1841. 3768
  1842. File
  1843. Failed
  1844.  
  1845. C:\Documents and Settings\LocalService\Local Settings\Application Data\bitcoin
  1846. 3768
  1847. File
  1848. Failed
  1849.  
  1850. C:\Documents and Settings\NetworkService\Local Settings\Application Data\bitcoin
  1851. 3768
  1852. File
  1853. Failed
  1854.  
  1855. C:\Documents and Settings\NetworkService\Local Settings\Application Data\bitcoin
  1856. 3768
  1857. File
  1858. Failed
  1859.  
  1860. C:\Documents and Settings\NetworkService\Local Settings\Application Data\bitcoin
  1861. 3768
  1862. File
  1863. Failed
  1864.  
  1865. C:\Documents and Settings\admin\Local Settings\Application Data\bitcoin
  1866. 3768
  1867. File
  1868. Failed
  1869.  
  1870. C:\Documents and Settings\admin\Local Settings\Application Data\bitcoin
  1871. 3768
  1872. File
  1873. Failed
  1874.  
  1875. C:\Documents and Settings\admin\Local Settings\Application Data\bitcoin
  1876. 3768
  1877. File
  1878. Failed
  1879.  
  1880. C:\Program Files\excel
  1881. 3768
  1882. File
  1883. Failed
  1884.  
  1885. C:\Program Files\excel
  1886. 3768
  1887. File
  1888. Failed
  1889.  
  1890. C:\Program Files\excel
  1891. 3768
  1892. File
  1893. Failed
  1894.  
  1895. C:\WINDOWS\system32\config\systemprofile\Application Data\excel
  1896. 3768
  1897. File
  1898. Failed
  1899.  
  1900. C:\WINDOWS\system32\config\systemprofile\Application Data\excel
  1901. 3768
  1902. File
  1903. Failed
  1904.  
  1905. C:\WINDOWS\system32\config\systemprofile\Application Data\excel
  1906. 3768
  1907. File
  1908. Failed
  1909.  
  1910. C:\Documents and Settings\LocalService\Application Data\excel
  1911. 3768
  1912. File
  1913. Failed
  1914.  
  1915. C:\Documents and Settings\LocalService\Application Data\excel
  1916. 3768
  1917. File
  1918. Failed
  1919.  
  1920. C:\Documents and Settings\LocalService\Application Data\excel
  1921. 3768
  1922. File
  1923. Failed
  1924.  
  1925. C:\Documents and Settings\NetworkService\Application Data\excel
  1926. 3768
  1927. File
  1928. Failed
  1929.  
  1930. C:\Documents and Settings\NetworkService\Application Data\excel
  1931. 3768
  1932. File
  1933. Failed
  1934.  
  1935. C:\Documents and Settings\NetworkService\Application Data\excel
  1936. 3768
  1937. File
  1938. Failed
  1939.  
  1940. C:\Documents and Settings\admin\Application Data\excel
  1941. 3768
  1942. File
  1943. Failed
  1944.  
  1945. C:\Documents and Settings\admin\Application Data\excel
  1946. 3768
  1947. File
  1948. Failed
  1949.  
  1950. C:\Documents and Settings\admin\Application Data\excel
  1951. 3768
  1952. File
  1953. Failed
  1954.  
  1955. C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\excel
  1956. 3768
  1957. File
  1958. Failed
  1959.  
  1960. C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\excel
  1961. 3768
  1962. File
  1963. Failed
  1964.  
  1965. C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\excel
  1966. 3768
  1967. File
  1968. Failed
  1969.  
  1970. C:\Documents and Settings\LocalService\Local Settings\Application Data\excel
  1971. 3768
  1972. File
  1973. Failed
  1974.  
  1975. C:\Documents and Settings\LocalService\Local Settings\Application Data\excel
  1976. 3768
  1977. File
  1978. Failed
  1979.  
  1980. C:\Documents and Settings\LocalService\Local Settings\Application Data\excel
  1981. 3768
  1982. File
  1983. Failed
  1984.  
  1985. C:\Documents and Settings\NetworkService\Local Settings\Application Data\excel
  1986. 3768
  1987. File
  1988. Failed
  1989.  
  1990. C:\Documents and Settings\NetworkService\Local Settings\Application Data\excel
  1991. 3768
  1992. File
  1993. Failed
  1994.  
  1995. C:\Documents and Settings\NetworkService\Local Settings\Application Data\excel
  1996. 3768
  1997. File
  1998. Failed
  1999.  
  2000. C:\Documents and Settings\admin\Local Settings\Application Data\excel
  2001. 3768
  2002. File
  2003. Failed
  2004.  
  2005. C:\Documents and Settings\admin\Local Settings\Application Data\excel
  2006. 3768
  2007. File
  2008. Failed
  2009.  
  2010. C:\Documents and Settings\admin\Local Settings\Application Data\excel
  2011. 3768
  2012. File
  2013. Failed
  2014.  
  2015. C:\Program Files\microsoft sql server
  2016. 3768
  2017. File
  2018. Failed
  2019.  
  2020. C:\Program Files\microsoft sql server
  2021. 3768
  2022. File
  2023. Failed
  2024.  
  2025. C:\Program Files\microsoft sql server
  2026. 3768
  2027. File
  2028. Failed
  2029.  
  2030. C:\WINDOWS\system32\config\systemprofile\Application Data\microsoft sql server
  2031. 3768
  2032. File
  2033. Failed
  2034.  
  2035. C:\WINDOWS\system32\config\systemprofile\Application Data\microsoft sql server
  2036. 3768
  2037. File
  2038. Failed
  2039.  
  2040. C:\WINDOWS\system32\config\systemprofile\Application Data\microsoft sql server
  2041. 3768
  2042. File
  2043. Failed
  2044.  
  2045. C:\Documents and Settings\LocalService\Application Data\microsoft sql server
  2046. 3768
  2047. File
  2048. Failed
  2049.  
  2050. C:\Documents and Settings\LocalService\Application Data\microsoft sql server
  2051. 3768
  2052. File
  2053. Failed
  2054.  
  2055. C:\Documents and Settings\LocalService\Application Data\microsoft sql server
  2056. 3768
  2057. File
  2058. Failed
  2059.  
  2060. C:\Documents and Settings\NetworkService\Application Data\microsoft sql server
  2061. 3768
  2062. File
  2063. Failed
  2064.  
  2065. C:\Documents and Settings\NetworkService\Application Data\microsoft sql server
  2066. 3768
  2067. File
  2068. Failed
  2069.  
  2070. C:\Documents and Settings\NetworkService\Application Data\microsoft sql server
  2071. 3768
  2072. File
  2073. Failed
  2074.  
  2075. C:\Documents and Settings\admin\Application Data\microsoft sql server
  2076. 3768
  2077. File
  2078. Failed
  2079.  
  2080. C:\Documents and Settings\admin\Application Data\microsoft sql server
  2081. 3768
  2082. File
  2083. Failed
  2084.  
  2085. C:\Documents and Settings\admin\Application Data\microsoft sql server
  2086. 3768
  2087. File
  2088. Failed
  2089.  
  2090. C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\microsoft sql server
  2091. 3768
  2092. File
  2093. Failed
  2094.  
  2095. C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\microsoft sql server
  2096. 3768
  2097. File
  2098. Failed
  2099.  
  2100. C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\microsoft sql server
  2101. 3768
  2102. File
  2103. Failed
  2104.  
  2105. C:\Documents and Settings\LocalService\Local Settings\Application Data\microsoft sql server
  2106. 3768
  2107. File
  2108. Failed
  2109.  
  2110. C:\Documents and Settings\LocalService\Local Settings\Application Data\microsoft sql server
  2111. 3768
  2112. File
  2113. Failed
  2114.  
  2115. C:\Documents and Settings\LocalService\Local Settings\Application Data\microsoft sql server
  2116. 3768
  2117. File
  2118. Failed
  2119.  
  2120. C:\Documents and Settings\NetworkService\Local Settings\Application Data\microsoft sql server
  2121. 3768
  2122. File
  2123. Failed
  2124.  
  2125. C:\Documents and Settings\NetworkService\Local Settings\Application Data\microsoft sql server
  2126. 3768
  2127. File
  2128. Failed
  2129.  
  2130. C:\Documents and Settings\NetworkService\Local Settings\Application Data\microsoft sql server
  2131. 3768
  2132. File
  2133. Failed
  2134.  
  2135. C:\Documents and Settings\admin\Local Settings\Application Data\microsoft sql server
  2136. 3768
  2137. File
  2138. Failed
  2139.  
  2140. C:\Documents and Settings\admin\Local Settings\Application Data\microsoft sql server
  2141. 3768
  2142. File
  2143. Failed
  2144.  
  2145. C:\Documents and Settings\admin\Local Settings\Application Data\microsoft sql server
  2146. 3768
  2147. File
  2148. Failed
  2149.  
  2150. C:\Program Files\MICROSOFT\EXCEL
  2151. 3768
  2152. File
  2153. Failed
  2154.  
  2155. C:\Program Files\MICROSOFT\EXCEL
  2156. 3768
  2157. File
  2158. Failed
  2159.  
  2160. C:\Program Files\MICROSOFT\EXCEL
  2161. 3768
  2162. File
  2163. Failed
  2164.  
  2165. C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\excel
  2166. 3768
  2167. File
  2168. Failed
  2169.  
  2170. C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\excel
  2171. 3768
  2172. File
  2173. Failed
  2174.  
  2175. C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\excel
  2176. 3768
  2177. File
  2178. Failed
  2179.  
  2180. C:\Documents and Settings\LocalService\Application Data\Microsoft\excel
  2181. 3768
  2182. File
  2183. Failed
  2184.  
  2185. C:\Documents and Settings\LocalService\Application Data\Microsoft\excel
  2186. 3768
  2187. File
  2188. Failed
  2189.  
  2190. C:\Documents and Settings\LocalService\Application Data\Microsoft\excel
  2191. 3768
  2192. File
  2193. Failed
  2194.  
  2195. C:\Documents and Settings\NetworkService\Application Data\Microsoft\excel
  2196. 3768
  2197. File
  2198. Failed
  2199.  
  2200. C:\Documents and Settings\NetworkService\Application Data\Microsoft\excel
  2201. 3768
  2202. File
  2203. Failed
  2204.  
  2205. C:\Documents and Settings\NetworkService\Application Data\Microsoft\excel
  2206. 3768
  2207. File
  2208. Failed
  2209.  
  2210. C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\MICROSOFT\EXCEL
  2211. 3768
  2212. File
  2213. Failed
  2214.  
  2215. C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\MICROSOFT\EXCEL
  2216. 3768
  2217. File
  2218. Failed
  2219.  
  2220. C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\MICROSOFT\EXCEL
  2221. 3768
  2222. File
  2223. Failed
  2224.  
  2225. C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\excel
  2226. 3768
  2227. File
  2228. Failed
  2229.  
  2230. C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\excel
  2231. 3768
  2232. File
  2233. Failed
  2234.  
  2235. C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\excel
  2236. 3768
  2237. File
  2238. Failed
  2239.  
  2240. C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\excel
  2241. 3768
  2242. File
  2243. Failed
  2244.  
  2245. C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\excel
  2246. 3768
  2247. File
  2248. Failed
  2249.  
  2250. C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\excel
  2251. 3768
  2252. File
  2253. Failed
  2254.  
  2255. C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\excel
  2256. 3768
  2257. File
  2258. Failed
  2259.  
  2260. C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\excel
  2261. 3768
  2262. File
  2263. Failed
  2264.  
  2265. C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\excel
  2266. 3768
  2267. File
  2268. Failed
  2269.  
  2270. C:\Program Files\MICROSOFT\MICROSOFT SQL SERVER
  2271. 3768
  2272. File
  2273. Failed
  2274.  
  2275. C:\Program Files\MICROSOFT\MICROSOFT SQL SERVER
  2276. 3768
  2277. File
  2278. Failed
  2279.  
  2280. C:\Program Files\MICROSOFT\MICROSOFT SQL SERVER
  2281. 3768
  2282. File
  2283. Failed
  2284.  
  2285. C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\microsoft sql server
  2286. 3768
  2287. File
  2288. Failed
  2289.  
  2290. C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\microsoft sql server
  2291. 3768
  2292. File
  2293. Failed
  2294.  
  2295. C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\microsoft sql server
  2296. 3768
  2297. File
  2298. Failed
  2299.  
  2300. C:\Documents and Settings\LocalService\Application Data\Microsoft\microsoft sql server
  2301. 3768
  2302. File
  2303. Failed
  2304.  
  2305. C:\Documents and Settings\LocalService\Application Data\Microsoft\microsoft sql server
  2306. 3768
  2307. File
  2308. Failed
  2309.  
  2310. C:\Documents and Settings\LocalService\Application Data\Microsoft\microsoft sql server
  2311. 3768
  2312. File
  2313. Failed
  2314.  
  2315. C:\Documents and Settings\NetworkService\Application Data\Microsoft\microsoft sql server
  2316. 3768
  2317. File
  2318. Failed
  2319.  
  2320. C:\Documents and Settings\NetworkService\Application Data\Microsoft\microsoft sql server
  2321. 3768
  2322. File
  2323. Failed
  2324.  
  2325. C:\Documents and Settings\NetworkService\Application Data\Microsoft\microsoft sql server
  2326. 3768
  2327. File
  2328. Failed
  2329.  
  2330. C:\Documents and Settings\admin\Application Data\Microsoft\microsoft sql server
  2331. 3768
  2332. File
  2333. Failed
  2334.  
  2335. C:\Documents and Settings\admin\Application Data\Microsoft\microsoft sql server
  2336. 3768
  2337. File
  2338. Failed
  2339.  
  2340. C:\Documents and Settings\admin\Application Data\Microsoft\microsoft sql server
  2341. 3768
  2342. File
  2343. Failed
  2344.  
  2345. C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\MICROSOFT\MICROSOFT SQL SER
  2346. VER
  2347. 3768
  2348. File
  2349. Failed
  2350.  
  2351. C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\MICROSOFT\MICROSOFT SQL SER
  2352. VER
  2353. 3768
  2354. File
  2355. Failed
  2356.  
  2357. C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\MICROSOFT\MICROSOFT SQL SER
  2358. VER
  2359. 3768
  2360. File
  2361. Failed
  2362.  
  2363. C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\microsoft sql serve
  2364. r
  2365. 3768
  2366. File
  2367. Failed
  2368.  
  2369. C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\microsoft sql serve
  2370. r
  2371. 3768
  2372. File
  2373. Failed
  2374.  
  2375. C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\microsoft sql serve
  2376. r
  2377. 3768
  2378. File
  2379. Failed
  2380.  
  2381. C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\microsoft sql ser
  2382. ver
  2383. 3768
  2384. File
  2385. Failed
  2386.  
  2387. C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\microsoft sql ser
  2388. ver
  2389. 3768
  2390. File
  2391. Failed
  2392.  
  2393. C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\microsoft sql ser
  2394. ver
  2395. 3768
  2396. File
  2397. Failed
  2398.  
  2399. C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\microsoft sql server
  2400. 3768
  2401. File
  2402. Failed
  2403.  
  2404. C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\microsoft sql server
  2405. 3768
  2406. File
  2407. Failed
  2408.  
  2409. C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\microsoft sql server
  2410. 3768
  2411. File
  2412. Failed
  2413.  
  2414. C:\Program Files\MICROSOFT\OFFICE
  2415. 3768
  2416. File
  2417. Failed
  2418.  
  2419. C:\Program Files\MICROSOFT\OFFICE
  2420. 3768
  2421. File
  2422. Failed
  2423.  
  2424. C:\Program Files\MICROSOFT\OFFICE
  2425. 3768
  2426. File
  2427. Failed
  2428.  
  2429. C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\office
  2430. 3768
  2431. File
  2432. Failed
  2433.  
  2434. C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\office
  2435. 3768
  2436. File
  2437. Failed
  2438.  
  2439. C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\office
  2440. 3768
  2441. File
  2442. Failed
  2443.  
  2444. C:\Documents and Settings\LocalService\Application Data\Microsoft\office
  2445. 3768
  2446. File
  2447. Failed
  2448.  
  2449. C:\Documents and Settings\LocalService\Application Data\Microsoft\office
  2450. 3768
  2451. File
  2452. Failed
  2453.  
  2454. C:\Documents and Settings\LocalService\Application Data\Microsoft\office
  2455. 3768
  2456. File
  2457. Failed
  2458.  
  2459. C:\Documents and Settings\NetworkService\Application Data\Microsoft\office
  2460. 3768
  2461. File
  2462. Failed
  2463.  
  2464. C:\Documents and Settings\NetworkService\Application Data\Microsoft\office
  2465. 3768
  2466. File
  2467. Failed
  2468.  
  2469. C:\Documents and Settings\NetworkService\Application Data\Microsoft\office
  2470. 3768
  2471. File
  2472. Failed
  2473.  
  2474. C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\MICROSOFT\OFFICE
  2475. 3768
  2476. File
  2477. Failed
  2478.  
  2479. C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\MICROSOFT\OFFICE
  2480. 3768
  2481. File
  2482. Failed
  2483.  
  2484. C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\MICROSOFT\OFFICE
  2485. 3768
  2486. File
  2487. Failed
  2488.  
  2489. C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\office
  2490. 3768
  2491. File
  2492. Failed
  2493.  
  2494. C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\office
  2495. 3768
  2496. File
  2497. Failed
  2498.  
  2499. C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\office
  2500. 3768
  2501. File
  2502. Failed
  2503.  
  2504. C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\office
  2505. 3768
  2506. File
  2507. Failed
  2508.  
  2509. C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\office
  2510. 3768
  2511. File
  2512. Failed
  2513.  
  2514. C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\office
  2515. 3768
  2516. File
  2517. Failed
  2518.  
  2519. C:\Program Files\MICROSOFT\ONENOTE
  2520. 3768
  2521. File
  2522. Failed
  2523.  
  2524. C:\Program Files\MICROSOFT\ONENOTE
  2525. 3768
  2526. File
  2527. Failed
  2528.  
  2529. C:\Program Files\MICROSOFT\ONENOTE
  2530. 3768
  2531. File
  2532. Failed
  2533.  
  2534. C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\onenote
  2535. 3768
  2536. File
  2537. Failed
  2538.  
  2539. C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\onenote
  2540. 3768
  2541. File
  2542. Failed
  2543.  
  2544. C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\onenote
  2545. 3768
  2546. File
  2547. Failed
  2548.  
  2549. C:\Documents and Settings\LocalService\Application Data\Microsoft\onenote
  2550. 3768
  2551. File
  2552. Failed
  2553.  
  2554. C:\Documents and Settings\LocalService\Application Data\Microsoft\onenote
  2555. 3768
  2556. File
  2557. Failed
  2558.  
  2559. C:\Documents and Settings\LocalService\Application Data\Microsoft\onenote
  2560. 3768
  2561. File
  2562. Failed
  2563.  
  2564. C:\Documents and Settings\NetworkService\Application Data\Microsoft\onenote
  2565. 3768
  2566. File
  2567. Failed
  2568.  
  2569. C:\Documents and Settings\NetworkService\Application Data\Microsoft\onenote
  2570. 3768
  2571. File
  2572. Failed
  2573.  
  2574. C:\Documents and Settings\NetworkService\Application Data\Microsoft\onenote
  2575. 3768
  2576. File
  2577. Failed
  2578.  
  2579. C:\Documents and Settings\admin\Application Data\Microsoft\onenote
  2580. 3768
  2581. File
  2582. Failed
  2583.  
  2584. C:\Documents and Settings\admin\Application Data\Microsoft\onenote
  2585. 3768
  2586. File
  2587. Failed
  2588.  
  2589. C:\Documents and Settings\admin\Application Data\Microsoft\onenote
  2590. 3768
  2591. File
  2592. Failed
  2593.  
  2594. C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\MICROSOFT\ONENOTE
  2595. 3768
  2596. File
  2597. Failed
  2598.  
  2599. C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\MICROSOFT\ONENOTE
  2600. 3768
  2601. File
  2602. Failed
  2603.  
  2604. C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\MICROSOFT\ONENOTE
  2605. 3768
  2606. File
  2607. Failed
  2608.  
  2609. C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\onenote
  2610. 3768
  2611. File
  2612. Failed
  2613.  
  2614. C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\onenote
  2615. 3768
  2616. File
  2617. Failed
  2618.  
  2619. C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\onenote
  2620. 3768
  2621. File
  2622. Failed
  2623.  
  2624. C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\onenote
  2625. 3768
  2626. File
  2627. Failed
  2628.  
  2629. C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\onenote
  2630. 3768
  2631. File
  2632. Failed
  2633.  
  2634. C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\onenote
  2635. 3768
  2636. File
  2637. Failed
  2638.  
  2639. C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\onenote
  2640. 3768
  2641. File
  2642. Failed
  2643.  
  2644. C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\onenote
  2645. 3768
  2646. File
  2647. Failed
  2648.  
  2649. C:\Documents and Settings\admin\Local Settings\Application Data\Microsoft\onenote
  2650. 3768
  2651. File
  2652. Failed
  2653.  
  2654. C:\Program Files\MICROSOFT\OUTLOOK
  2655. 3768
  2656. File
  2657. Failed
  2658.  
  2659. C:\Program Files\MICROSOFT\OUTLOOK
  2660. 3768
  2661. File
  2662. Failed
  2663.  
  2664. C:\Program Files\MICROSOFT\OUTLOOK
  2665. 3768
  2666. File
  2667. Failed
  2668.  
  2669. C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\outlook
  2670. 3768
  2671. File
  2672. Failed
  2673.  
  2674. C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\outlook
  2675. 3768
  2676. File
  2677. Failed
  2678.  
  2679. C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\outlook
  2680. 3768
  2681. File
  2682. Failed
  2683.  
  2684. C:\Documents and Settings\LocalService\Application Data\Microsoft\outlook
  2685. 3768
  2686. File
  2687. Failed
  2688.  
  2689. C:\Documents and Settings\LocalService\Application Data\Microsoft\outlook
  2690. 3768
  2691. File
  2692. Failed
  2693.  
  2694. C:\Documents and Settings\LocalService\Application Data\Microsoft\outlook
  2695. 3768
  2696. File
  2697. Failed
  2698.  
  2699. C:\Documents and Settings\NetworkService\Application Data\Microsoft\outlook
  2700. 3768
  2701. File
  2702. Failed
  2703.  
  2704. C:\Documents and Settings\NetworkService\Application Data\Microsoft\outlook
  2705. 3768
  2706. File
  2707. Failed
  2708.  
  2709. C:\Documents and Settings\NetworkService\Application Data\Microsoft\outlook
  2710. 3768
  2711. File
  2712. Failed
  2713.  
  2714. C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\MICROSOFT\OUTLOOK
  2715. 3768
  2716. File
  2717. Failed
  2718.  
  2719. C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\MICROSOFT\OUTLOOK
  2720. 3768
  2721. File
  2722. Failed
  2723.  
  2724. C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\MICROSOFT\OUTLOOK
  2725. 3768
  2726. File
  2727. Failed
  2728.  
  2729. C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\outlook
  2730. 3768
  2731. File
  2732. Failed
  2733.  
  2734. C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\outlook
  2735. 3768
  2736. File
  2737. Failed
  2738.  
  2739. C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\outlook
  2740. 3768
  2741. File
  2742. Failed
  2743.  
  2744. C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\outlook
  2745. 3768
  2746. File
  2747. Failed
  2748.  
  2749. C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\outlook
  2750. 3768
  2751. File
  2752. Failed
  2753.  
  2754. C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\outlook
  2755. 3768
  2756. File
  2757. Failed
  2758.  
  2759. C:\Program Files\MICROSOFT\POWERPOINT
  2760. 3768
  2761. File
  2762. Failed
  2763.  
  2764. C:\Program Files\MICROSOFT\POWERPOINT
  2765. 3768
  2766. File
  2767. Failed
  2768.  
  2769. C:\Program Files\MICROSOFT\POWERPOINT
  2770. 3768
  2771. File
  2772. Failed
  2773.  
  2774. C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\powerpoint
  2775. 3768
  2776. File
  2777. Failed
  2778.  
  2779. C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\powerpoint
  2780. 3768
  2781. File
  2782. Failed
  2783.  
  2784. C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\powerpoint
  2785. 3768
  2786. File
  2787. Failed
  2788.  
  2789. C:\Documents and Settings\LocalService\Application Data\Microsoft\powerpoint
  2790. 3768
  2791. File
  2792. Failed
  2793.  
  2794. C:\Documents and Settings\LocalService\Application Data\Microsoft\powerpoint
  2795. 3768
  2796. File
  2797. Failed
  2798.  
  2799. C:\Documents and Settings\LocalService\Application Data\Microsoft\powerpoint
  2800. 3768
  2801. File
  2802. Failed
  2803.  
  2804. C:\Documents and Settings\NetworkService\Application Data\Microsoft\powerpoint
  2805. 3768
  2806. File
  2807. Failed
  2808.  
  2809. C:\Documents and Settings\NetworkService\Application Data\Microsoft\powerpoint
  2810. 3768
  2811. File
  2812. Failed
  2813.  
  2814. C:\Documents and Settings\NetworkService\Application Data\Microsoft\powerpoint
  2815. 3768
  2816. 271 Repeated items skipped
  2817. API Call
  2818.  
  2819. API Name: SetWindowsHookExA Address: 0x7473097c
  2820. Params: [2, 0x747307c3, 0x74720000, 3824]
  2821. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  2822. 3768
  2823. API Call
  2824.  
  2825. API Name: SetWindowsHookExA Address: 0x7473099a
  2826. Params: [7, 0x747304cd, 0x74720000, 3824]
  2827. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: user32.dll
  2828. 3768
  2829. API Call
  2830.  
  2831. API Name: Process32FirstW Address: 0x00401bb2
  2832. Params: [0x280, 0x1fbfd88]
  2833. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe DLL Name: kernel32.dll
  2834. 3768
  2835. Malicious Alert
  2836. Generic Anomalous Activity
  2837.  
  2838. Message: Enumerating running processes
  2839.  
  2840. Ransom
  2841.  
  2842. C:\593Mshaimfe2\drRaTVw-.xls
  2843. MD5: cb1639265273d5223bf16f183bd0ca6a
  2844.  
  2845. Malicious Alert
  2846. Misc Anom
  2847.  
  2848. Message: Ransomware Activity
  2849.  
  2850. Malicious Alert
  2851. Malware Family
  2852.  
  2853. Message: Possible Cerber Ransomware
  2854.  
  2855. Malicious Alert
  2856. Ransomware
  2857.  
  2858. Message: Ransomware Activity
  2859.  
  2860. 537 Repeated items skipped
  2861. File
  2862. Open
  2863.  
  2864. C:\Program Files\Office\OFFICE11\1033\OWHTOC.XML
  2865. 3768 8768
  2866. File
  2867. Close
  2868.  
  2869. C:\Program Files\Office\OFFICE11\1033\OWHTOC.XML
  2870. MD5: 4b2bec26a669ed24cfc27eb54b84286a
  2871. SHA1: 13c91fb09872bbbf9aeccd1c70f33e03ca48d401
  2872. 3768 9186
  2873. File
  2874. Rename
  2875.  
  2876. Old Name: C:\Program Files\Office\OFFICE11\1033\OWHTOC.XML
  2877. New Name: C:\Program Files\Office\OFFICE11\1033\SZAXGe8wpc.a434
  2878. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  2879. MD5: 4b2bec26a669ed24cfc27eb54b84286a
  2880. SHA1: 13c91fb09872bbbf9aeccd1c70f33e03ca48d401
  2881. 3768 9186
  2882. 321 Repeated items skipped
  2883. File
  2884. Rename
  2885.  
  2886. Old Name: C:\Program Files\Office\Templates\Presentation Designs\Watermark.pot
  2887. New Name: C:\Program Files\Office\Templates\Presentation Designs\tx7GsrMiW4.a434
  2888. Imagepath: C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  2889. MD5: 699d05b0a199d387c71f63c7f5150e3a
  2890. SHA1: 9143f5b55054fe152e1caf475f33ba3725db0fdd
  2891. 3768 22952
  2892. Ransom
  2893.  
  2894. C:\Documents and Settings\admin\Desktop\BZfnqu.jpg
  2895. MD5: bfa8dc5782fbe66674c9e4cad12b50c7
  2896.  
  2897. File
  2898. Created
  2899.  
  2900. C:\Documents and Settings\admin\Desktop\_HELP_HELP_HELP_L238_.hta
  2901. 3768
  2902. Malicious Alert
  2903. Misc Anom
  2904.  
  2905. Message: Ransomware Indicator
  2906.  
  2907. 315 Repeated items skipped
  2908. Network
  2909. Dns Query
  2910.  
  2911. Protocol Type: udp Qtype: Host Address Hostname: api.blockcypher.com
  2912. Imagepath: c:\WINDOWS\system32\mshta.exe
  2913. 4016
  2914. Malicious Alert
  2915. Misc Anom
  2916.  
  2917. Message: Suspicious Code Injection
  2918.  
  2919. Malicious Alert
  2920. Network Activity
  2921.  
  2922. Message: Network outbound communication attempted
  2923.  
  2924. 7 Repeated items skipped
  2925. Regkey
  2926. Queryvalue
  2927.  
  2928. \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
  2929. 4016
  2930. Regkey
  2931. Added
  2932.  
  2933. \REGISTRY\USER\S-1-5-21-1409082233-688789844-725345543-1003\Software\Microsoft\Windows NT\CurrentVer
  2934. sion\Winlogon
  2935. 4016
  2936. Network
  2937. Dns Query
  2938.  
  2939. Protocol Type: udp Qtype: Host Address Hostname: bitaps.com
  2940. Imagepath: c:\WINDOWS\system32\mshta.exe
  2941. 4016
  2942. Malicious Alert
  2943. DGA Activity
  2944.  
  2945. Message: Suspicious Network Activity
  2946.  
  2947. 155 Repeated items skipped
  2948. Regkey
  2949. Queryvalue
  2950.  
  2951. \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
  2952. 2248
  2953. Process
  2954. Terminated
  2955.  
  2956. C:\WINDOWS\system32\ping.exe
  2957. Parentname: C:\WINDOWS\system32\cmd.exe
  2958. Command Line: N/A
  2959. 2248 2108
  2960. File
  2961. Delete
  2962.  
  2963. C:\Documents and Settings\admin\Local Settings\Temp\user.php.exe
  2964. MD5: aa8b8c39317f733d389d30db2fed1def
  2965. SHA1: 5ba7443d6c0c0a5cf59316e0d3b3defba8c57bc8
  2966. 2108 275476
  2967. Malicious Alert
  2968. Misc Anom
  2969.  
  2970. Message: Persistance with Self Delete Activity
  2971.  
  2972. Malicious Alert
  2973. Misc Anom
  2974.  
  2975. Message: Suspicious Code Injection
  2976.  
  2977. Malicious Alert
  2978. Self Delete
  2979.  
  2980. Message: Self deletion using batch file
  2981.  
  2982. Malicious Alert
  2983. Self Delete
  2984.  
  2985. Message: Root process deleted
  2986.  
  2987. Process
  2988. Terminated
  2989.  
  2990. C:\WINDOWS\system32\cmd.exe
  2991. Parentname: C:\DOCUME~1\admin\LOCALS~1\Temp\user.php.exe
  2992. Command Line: N/A
  2993. 2108 3768
  2994. API Call
  2995.  
  2996. API Name: GetSystemDirectoryW Address: 0x755dd323
  2997. Params: [0xc4fc3c, 261]
  2998. Imagepath: C:\WINDOWS\system32\rundll32.exe DLL Name: kernel32.dll
  2999. 4024
  3000. Malicious Alert
  3001. Generic Anomalous Activity
  3002.  
  3003. Message: Process Opening explorer
  3004.  
  3005. OS Change Detail (version: 1.2724) | Items: 540 | OS Info: Microsoft Windows7 64-bit 6.1 sp1 16.0901 Top
  3006. Type Mode/Class Details (Path/Message/Protocol/Hostname/Qtype/ListenPort etc.) Process ID Parent ID File Size
  3007. Analysis
  3008. Malware
  3009.  
  3010.  
  3011. Malicious Alert
  3012. Static Analysis
  3013.  
  3014. Message: Static Binary Analysis
  3015.  
  3016. Application
  3017.  
  3018.  
  3019. Os
  3020.  
  3021. Name: windows Version: 6.1.7601 Service Pack: 1 Arch: x64
  3022.  
  3023. Os Monitor
  3024.  
  3025. Version: 16R1 Build: 519813 Date: Aug 31 2016 Time: 18:44:00
  3026.  
  3027. Config Update
  3028.  
  3029.  
  3030. Uac
  3031. Service
  3032.  
  3033. Windows Image Acquisition (WIA)
  3034.  
  3035. Uac
  3036. Service
  3037.  
  3038. Multimedia Class Scheduler
  3039.  
  3040. Process
  3041. Started
  3042.  
  3043. C:\Users\Administrator\AppData\Local\Temp\user.php.exe
  3044. Parentname: C:\Windows\explorer.exe
  3045. Command Line: "C:\Users\ADMINI~1\AppData\Local\Temp\user.php.exe"
  3046. MD5: aa8b8c39317f733d389d30db2fed1def
  3047. SHA1: 5ba7443d6c0c0a5cf59316e0d3b3defba8c57bc8
  3048. 2756 1676 275476
  3049. File
  3050. Failed
  3051.  
  3052. C:\Windows\System32\WOW64LOG.DLL
  3053. 2756
  3054. Mutex
  3055.  
  3056. \Sessions\1\BaseNamedObjects\DBWinMutex
  3057. 2756
  3058. Regkey
  3059. Queryvalue
  3060.  
  3061. \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
  3062. 2756
  3063. API Call
  3064.  
  3065. API Name: GetSystemDirectoryW Address: 0x00406505
  3066. Params: [0x18fa64, 260]
  3067. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3068. 2756
  3069. API Call
  3070.  
  3071. API Name: GetSystemDirectoryW Address: 0x00406505
  3072. Params: [0x18fa64, 260]
  3073. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3074. 2756
  3075. API Call
  3076.  
  3077. API Name: GetSystemDirectoryW Address: 0x00406505
  3078. Params: [0x18fa64, 260]
  3079. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3080. 2756
  3081. API Call
  3082.  
  3083. API Name: GetSystemDirectoryW Address: 0x75eef96e
  3084. Params: [0x75f56420, 260]
  3085. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3086. 2756
  3087. API Call
  3088.  
  3089. API Name: GetSystemDirectoryW Address: 0x75709cce
  3090. Params: [0x18f444, 260]
  3091. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3092. 2756
  3093. API Call
  3094.  
  3095. API Name: GetSystemDirectoryW Address: 0x00406505
  3096. Params: [0x18fa64, 260]
  3097. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3098. 2756
  3099. API Call
  3100.  
  3101. API Name: GetSystemDirectoryW Address: 0x00406505
  3102. Params: [0x18fa64, 260]
  3103. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3104. 2756
  3105. 5 Repeated items skipped
  3106. API Call
  3107.  
  3108. API Name: GetSystemDirectoryW Address: 0x00406505
  3109. Params: [0x18fa50, 260]
  3110. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3111. 2756
  3112. File
  3113. Failed
  3114.  
  3115. C:\Windows\SysWOW64\RPCSS.DLL
  3116. 2756
  3117. 2 Repeated items skipped
  3118. API Call
  3119.  
  3120. API Name: GetVolumeNameForVolumeMountPointW Address: 0x76a80aaa
  3121. Params: [NULL, \\?\Volume{a4dcb962-c2b8-11e2-8b83-806e6f6e6963}\]
  3122. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3123. 2756
  3124. API Call
  3125.  
  3126. API Name: GetTokenInformation Address: 0x76a80172
  3127. Params: [0x160, 0x19]
  3128. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: advapi32.dll
  3129. 2756
  3130. File
  3131. Failed
  3132.  
  3133. C:\Users\Administrator\AppData\Local\Microsoft\Windows\Caches
  3134. 2756
  3135. API Call
  3136.  
  3137. API Name: GetVolumeNameForVolumeMountPointW Address: 0x76a80e20
  3138. Params: [NULL, \\?\Volume{a4dcb965-c2b8-11e2-8b83-806e6f6e6963}\]
  3139. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3140. 2756
  3141. API Call
  3142.  
  3143. API Name: GetVolumeNameForVolumeMountPointW Address: 0x76a80e20
  3144. Params: [NULL, \\?\Volume{a4dcb962-c2b8-11e2-8b83-806e6f6e6963}\]
  3145. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3146. 2756
  3147. API Call
  3148.  
  3149. API Name: GetTokenInformation Address: 0x76a80172
  3150. Params: [0x1a8, 0x19]
  3151. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: advapi32.dll
  3152. 2756
  3153. API Call
  3154.  
  3155. API Name: GetTokenInformation Address: 0x76a80172
  3156. Params: [0x1a8, 0x19]
  3157. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: advapi32.dll
  3158. 2756
  3159. API Call
  3160.  
  3161. API Name: GetTokenInformation Address: 0x76a80172
  3162. Params: [0x1a8, 0x19]
  3163. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: advapi32.dll
  3164. 2756
  3165. File
  3166. Failed
  3167.  
  3168. C:\Users\Administrator\AppData\Local\Temp
  3169. 2756
  3170. File
  3171. Created
  3172.  
  3173. C:\Users\Administrator\AppData\Local\Temp\nsaFE5C.tmp
  3174. 2756
  3175. File
  3176. Delete
  3177.  
  3178. C:\Users\Administrator\AppData\Local\Temp\nsaFE5C.tmp
  3179. 2756
  3180. File
  3181. Created
  3182.  
  3183. C:\Users\Administrator\AppData\Local\Temp\nsaFE5D.tmp
  3184. 2756
  3185. File
  3186. Overwritten
  3187.  
  3188. C:\Users\Administrator\AppData\Local\Temp\nsaFE5D.tmp
  3189. 2756
  3190. File
  3191. Delete
  3192.  
  3193. C:\Users\Administrator\AppData\Local\Temp\nsaFE5D.tmp
  3194. 2756
  3195. File
  3196. Failed
  3197.  
  3198. C:\Users
  3199. 2756
  3200. File
  3201. Failed
  3202.  
  3203. C:\Users\Administrator
  3204. 2756
  3205. File
  3206. Failed
  3207.  
  3208. C:\Users\Administrator\AppData
  3209. 2756
  3210. File
  3211. Failed
  3212.  
  3213. C:\Users\Administrator\AppData\Local
  3214. 2756
  3215. File
  3216. Failed
  3217.  
  3218. C:\Users\Administrator\AppData\Local\Temp
  3219. 2756
  3220. File
  3221. Failed
  3222.  
  3223. C:\Users\Administrator\AppData\Local\Temp\stresses.O6T
  3224. 2756
  3225. 2 Repeated items skipped
  3226. File
  3227. Created
  3228.  
  3229. C:\Users\Administrator\AppData\Local\Temp\stresses.O6T
  3230. 2756
  3231. File
  3232. Date Change
  3233.  
  3234. C:\Users\Administrator\AppData\Local\Temp\stresses.O6T
  3235. 2756 185232
  3236. File
  3237. Close
  3238.  
  3239. C:\Users\Administrator\AppData\Local\Temp\stresses.O6T
  3240. MD5: 5d5253dff5fd8fc7312728968c6fee5c
  3241. SHA1: 7cd59d519dfb88d896d5125ff7f5d73c336fcff6
  3242. 2756 185232
  3243. File
  3244. Failed
  3245.  
  3246. C:\Users\Administrator\AppData\Local\Temp\favicon.ico
  3247. 2756
  3248. 2 Repeated items skipped
  3249. File
  3250. Created
  3251.  
  3252. C:\Users\Administrator\AppData\Local\Temp\favicon.ico
  3253. 2756
  3254. File
  3255. Date Change
  3256.  
  3257. C:\Users\Administrator\AppData\Local\Temp\favicon.ico
  3258. 2756 1150
  3259. File
  3260. Close
  3261.  
  3262. C:\Users\Administrator\AppData\Local\Temp\favicon.ico
  3263. MD5: 248cc9dffdbe8f7a66f66ebe3fa3195a
  3264. SHA1: bd1de82855a6e027d539ec9098c1294a23494a63
  3265. 2756 1150
  3266. File
  3267. Failed
  3268.  
  3269. C:\Users\Administrator\AppData\Local\Temp\COLOR-ADDENDUM
  3270. 2756
  3271. 2 Repeated items skipped
  3272. File
  3273. Created
  3274.  
  3275. C:\Users\Administrator\AppData\Local\Temp\Color-Addendum
  3276. 2756
  3277. File
  3278. Date Change
  3279.  
  3280. C:\Users\Administrator\AppData\Local\Temp\Color-Addendum
  3281. 2756 1239
  3282. File
  3283. Close
  3284.  
  3285. C:\Users\Administrator\AppData\Local\Temp\Color-Addendum
  3286. MD5: 438b727b40f8dba094b7854966795a4c
  3287. SHA1: ba117a3f63b27f109a38cc6612501aa6819dbeb6
  3288. 2756 1239
  3289. File
  3290. Failed
  3291.  
  3292. C:\Users\Administrator\AppData\Local\Temp\ie.css
  3293. 2756
  3294. 2 Repeated items skipped
  3295. File
  3296. Created
  3297.  
  3298. C:\Users\Administrator\AppData\Local\Temp\ie.css
  3299. 2756
  3300. File
  3301. Date Change
  3302.  
  3303. C:\Users\Administrator\AppData\Local\Temp\ie.css
  3304. 2756 1339
  3305. File
  3306. Close
  3307.  
  3308. C:\Users\Administrator\AppData\Local\Temp\ie.css
  3309. MD5: 7a92334f3a6c04968d57b76cf62d971b
  3310. SHA1: cb2c10b88e38d76ef162ade0cec9f52d4c87d0c4
  3311. 2756 1339
  3312. File
  3313. Overwritten
  3314.  
  3315. C:\Users\Administrator\AppData\Local\Temp\Color-Addendum
  3316. MD5: 438b727b40f8dba094b7854966795a4c
  3317. SHA1: ba117a3f63b27f109a38cc6612501aa6819dbeb6
  3318. 2756 1239
  3319. File
  3320. Date Change
  3321.  
  3322. C:\Users\Administrator\AppData\Local\Temp\Color-Addendum
  3323. MD5: 438b727b40f8dba094b7854966795a4c
  3324. SHA1: ba117a3f63b27f109a38cc6612501aa6819dbeb6
  3325. 2756 1239
  3326. File
  3327. Close
  3328.  
  3329. C:\Users\Administrator\AppData\Local\Temp\Color-Addendum
  3330. MD5: 438b727b40f8dba094b7854966795a4c
  3331. SHA1: ba117a3f63b27f109a38cc6612501aa6819dbeb6
  3332. 2756 1239
  3333. File
  3334. Overwritten
  3335.  
  3336. C:\Users\Administrator\AppData\Local\Temp\ie.css
  3337. MD5: 7a92334f3a6c04968d57b76cf62d971b
  3338. SHA1: cb2c10b88e38d76ef162ade0cec9f52d4c87d0c4
  3339. 2756 1339
  3340. File
  3341. Date Change
  3342.  
  3343. C:\Users\Administrator\AppData\Local\Temp\ie.css
  3344. MD5: 7a92334f3a6c04968d57b76cf62d971b
  3345. SHA1: cb2c10b88e38d76ef162ade0cec9f52d4c87d0c4
  3346. 2756 1339
  3347. File
  3348. Close
  3349.  
  3350. C:\Users\Administrator\AppData\Local\Temp\ie.css
  3351. MD5: 7a92334f3a6c04968d57b76cf62d971b
  3352. SHA1: cb2c10b88e38d76ef162ade0cec9f52d4c87d0c4
  3353. 2756 1339
  3354. File
  3355. Failed
  3356.  
  3357. C:\Users\Administrator\AppData\Local\Temp\01116_UNIVERSITYNEVADA_RENO_CH
  3358. 2756
  3359. 2 Repeated items skipped
  3360. File
  3361. Created
  3362.  
  3363. C:\Users\Administrator\AppData\Local\Temp\01116_UniversityNevada_Reno_CH
  3364. 2756
  3365. File
  3366. Date Change
  3367.  
  3368. C:\Users\Administrator\AppData\Local\Temp\01116_UniversityNevada_Reno_CH
  3369. 2756 1255
  3370. File
  3371. Close
  3372.  
  3373. C:\Users\Administrator\AppData\Local\Temp\01116_UniversityNevada_Reno_CH
  3374. MD5: 25903ca9fc27d2b28d81e62497a7b92e
  3375. SHA1: 649b2f31d74a21cc67295e878a59dd2a5f0ce1b5
  3376. 2756 1255
  3377. File
  3378. Created
  3379.  
  3380. C:\Users\Administrator\AppData\Local\Temp\nslFEEB.tmp
  3381. 2756
  3382. File
  3383. Delete
  3384.  
  3385. C:\Users\Administrator\AppData\Local\Temp\nslFEEB.tmp
  3386. 2756
  3387. File
  3388. Failed
  3389.  
  3390. C:\Users
  3391. 2756
  3392. File
  3393. Failed
  3394.  
  3395. C:\Users\Administrator
  3396. 2756
  3397. File
  3398. Failed
  3399.  
  3400. C:\Users\Administrator\AppData
  3401. 2756
  3402. File
  3403. Failed
  3404.  
  3405. C:\Users\Administrator\AppData\Local
  3406. 2756
  3407. File
  3408. Failed
  3409.  
  3410. C:\Users\Administrator\AppData\Local\Temp
  3411. 2756
  3412. Folder
  3413. Created
  3414.  
  3415. C:\Users\Administrator\AppData\Local\Temp\nslFEEB.tmp
  3416. 2756
  3417. File
  3418. Failed
  3419.  
  3420. C:\Users\Administrator\AppData\Local\Temp\nslFEEB.tmp\System.dll
  3421. 2756
  3422. File
  3423. Created
  3424.  
  3425. C:\Users\Administrator\AppData\Local\Temp\nslFEEB.tmp\System.dll
  3426. 2756
  3427. Malicious Alert
  3428. Install Activity
  3429.  
  3430. Message: NSIS Install Activity
  3431.  
  3432. File
  3433. Close
  3434.  
  3435. C:\Users\Administrator\AppData\Local\Temp\nslFEEB.tmp\System.dll
  3436. MD5: a4dd044bcd94e9b3370ccf095b31f896
  3437. SHA1: 17c78201323ab2095bc53184aa8267c9187d5173
  3438. 2756 11776
  3439. DLL Loaded
  3440.  
  3441. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe
  3442. DLL Path: C:\Users\Administrator\AppData\Local\Temp\nslFEEB.tmp\System.dll
  3443. MD5: a4dd044bcd94e9b3370ccf095b31f896
  3444. SHA1: 17c78201323ab2095bc53184aa8267c9187d5173
  3445. 2756
  3446. Malicious Alert
  3447. Generic Dll Load Activity
  3448.  
  3449. Message: DLL loaded
  3450.  
  3451. File
  3452. Failed
  3453.  
  3454. C:\Users\Administrator\AppData\Local\Temp\nslFEEB.tmp\System.dll
  3455. 2756
  3456. 475 Repeated items skipped
  3457. High Cpu
  3458.  
  3459. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe
  3460. 2756
  3461. File
  3462. Failed
  3463.  
  3464. C:\Users\Administrator\AppData\Local\Temp\nslFEEB.tmp\System.dll
  3465. 2756
  3466. ProcessTelemetryReport
  3467.  
  3468. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe
  3469. 2756
  3470. File
  3471. Failed
  3472.  
  3473. C:\Users\Administrator\AppData\Local\Temp\nslFEEB.tmp\System.dll
  3474. 2756
  3475. API Call
  3476.  
  3477. API Name: FindWindowExW Address: 0x00401c8f
  3478. Params: [0x0, 0x0, circumstance, NULL]
  3479. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: user32.dll
  3480. 2756
  3481. API Call
  3482.  
  3483. API Name: FindWindowExW Address: 0x00401c8f
  3484. Params: [0x0, 0x0, cheeks, NULL]
  3485. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: user32.dll
  3486. 2756
  3487. API Call
  3488.  
  3489. API Name: FindWindowExW Address: 0x00401c8f
  3490. Params: [0x0, 0x0, duplicate, NULL]
  3491. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: user32.dll
  3492. 2756
  3493. API Call
  3494.  
  3495. API Name: FindWindowExW Address: 0x00401c8f
  3496. Params: [0x0, 0x0, blanket, NULL]
  3497. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: user32.dll
  3498. 2756
  3499. API Call
  3500.  
  3501. API Name: FindWindowExW Address: 0x00401c8f
  3502. Params: [0x0, 0x0, curtain, NULL]
  3503. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: user32.dll
  3504. 2756
  3505. API Call
  3506.  
  3507. API Name: FindWindowExW Address: 0x00401c8f
  3508. Params: [0x0, 0x0, widths, NULL]
  3509. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: user32.dll
  3510. 2756
  3511. API Call
  3512.  
  3513. API Name: FindWindowExW Address: 0x00401c8f
  3514. Params: [0x0, 0x0, person, NULL]
  3515. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: user32.dll
  3516. 2756
  3517. API Call
  3518.  
  3519. API Name: FindWindowExW Address: 0x00401c8f
  3520. Params: [0x0, 0x0, thin, NULL]
  3521. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: user32.dll
  3522. 2756
  3523. API Call
  3524.  
  3525. API Name: FindWindowExW Address: 0x00401c8f
  3526. Params: [0x0, 0x0, breakdowns, NULL]
  3527. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: user32.dll
  3528. 2756
  3529. API Call
  3530.  
  3531. API Name: FindWindowExW Address: 0x00401c8f
  3532. Params: [0x0, 0x0, preliminaries, NULL]
  3533. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: user32.dll
  3534. 2756
  3535. API Call
  3536.  
  3537. API Name: FindWindowExW Address: 0x00401c8f
  3538. Params: [0x0, 0x0, bushing, NULL]
  3539. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: user32.dll
  3540. 2756
  3541. API Call
  3542.  
  3543. API Name: FindWindowExW Address: 0x00401c8f
  3544. Params: [0x0, 0x0, breakdowns, NULL]
  3545. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: user32.dll
  3546. 2756
  3547. API Call
  3548.  
  3549. API Name: FindWindowExW Address: 0x00401c8f
  3550. Params: [0x0, 0x0, preliminaries, NULL]
  3551. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: user32.dll
  3552. 2756
  3553. API Call
  3554.  
  3555. API Name: FindWindowExW Address: 0x00401c8f
  3556. Params: [0x0, 0x0, bushing, NULL]
  3557. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: user32.dll
  3558. 2756
  3559. API Call
  3560.  
  3561. API Name: FindWindowExW Address: 0x00401c8f
  3562. Params: [0x0, 0x0, breakdowns, NULL]
  3563. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: user32.dll
  3564. 2756
  3565. API Call
  3566.  
  3567. API Name: FindWindowExW Address: 0x00401c8f
  3568. Params: [0x0, 0x0, preliminaries, NULL]
  3569. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: user32.dll
  3570. 2756
  3571. API Call
  3572.  
  3573. API Name: FindWindowExW Address: 0x00401c8f
  3574. Params: [0x0, 0x0, bushing, NULL]
  3575. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: user32.dll
  3576. 2756
  3577. API Call
  3578.  
  3579. API Name: FindWindowExW Address: 0x00401c8f
  3580. Params: [0x0, 0x0, breakdowns, NULL]
  3581. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: user32.dll
  3582. 2756
  3583. API Call
  3584.  
  3585. API Name: FindWindowExW Address: 0x00401c8f
  3586. Params: [0x0, 0x0, preliminaries, NULL]
  3587. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: user32.dll
  3588. 2756
  3589. API Call
  3590.  
  3591. API Name: FindWindowExW Address: 0x00401c8f
  3592. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: user32.dll
  3593. 2756
  3594. API Call
  3595.  
  3596. API Name: FindWindowExW Address: 0x00401c8f
  3597. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: user32.dll
  3598. 2756
  3599. 12 Repeated items skipped
  3600. High Cpu
  3601.  
  3602. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe
  3603. 2756
  3604. API Call
  3605.  
  3606. API Name: CryptAcquireContextW Address: 0x021db208
  3607. Params: [NULL, NULL, 24, 4026531840]
  3608. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: advapi32.dll
  3609. 2756
  3610. Process
  3611. Started
  3612.  
  3613. C:\Users\Administrator\AppData\Local\Temp\user.php.exe
  3614. Parentname: C:\Users\Administrator\AppData\Local\Temp\user.php.exe
  3615. Command Line: "C:\Users\ADMINI~1\AppData\Local\Temp\user.php.exe"
  3616. MD5: aa8b8c39317f733d389d30db2fed1def
  3617. SHA1: 5ba7443d6c0c0a5cf59316e0d3b3defba8c57bc8
  3618. 2496 2756 275476
  3619. Codeinjection
  3620. Create process suspended section mapped code injection
  3621.  
  3622. Source: C:\Users\Administrator\AppData\Local\Temp\user.php.exe
  3623. Target: C:\Users\Administrator\AppData\Local\Temp\user.php.exe
  3624.  
  3625. 2756
  3626. 2496
  3627.  
  3628. Malicious Alert
  3629. Code Injection Tracking
  3630.  
  3631. Message: Code Injection Obsevered
  3632.  
  3633. Codeinjection
  3634. Create process suspended memory write code injection
  3635.  
  3636. Source: C:\Users\Administrator\AppData\Local\Temp\user.php.exe
  3637. Target: C:\Users\Administrator\AppData\Local\Temp\user.php.exe
  3638.  
  3639. 2756
  3640. 2496
  3641.  
  3642. File
  3643. Failed
  3644.  
  3645. C:\Windows\System32\WOW64LOG.DLL
  3646. 2496
  3647. Mutex
  3648.  
  3649. \Sessions\1\BaseNamedObjects\DBWinMutex
  3650. 2496
  3651. Regkey
  3652. Queryvalue
  3653.  
  3654. \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
  3655. 2496
  3656. API Call
  3657.  
  3658. API Name: GetSystemDirectoryW Address: 0x7694cce1
  3659. Params: [0x18ee9c, 260]
  3660. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3661. 2496
  3662. API Call
  3663.  
  3664. API Name: GetSystemDirectoryW Address: 0x7694cce1
  3665. Params: [0x18e758, 260]
  3666. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3667. 2496
  3668. API Call
  3669.  
  3670. API Name: GetSystemDirectoryW Address: 0x7694cce1
  3671. Params: [0x18f544, 260]
  3672. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3673. 2496
  3674. Process
  3675. Terminated
  3676.  
  3677. C:\Users\Administrator\AppData\Local\Temp\user.php.exe
  3678. Parentname: C:\Windows\explorer.exe
  3679. Command Line: N/A
  3680. 2756 1676
  3681. File
  3682. Close
  3683.  
  3684. C:\Users\Administrator\AppData\Local\Temp\nsaFE5D.tmp
  3685. MD5: 66f2539e5f3ef77f2b6395813d442883
  3686. SHA1: ca6f8cf2d1f699c100efc19fad97b3b889752de0
  3687. 2756 336787
  3688. File
  3689. Failed
  3690.  
  3691. C:\Users\ADMINI~1\AppData\Local\Temp\MPR.DLL
  3692. 2496
  3693. File
  3694. Failed
  3695.  
  3696. C:\Users\ADMINI~1\AppData\Local\Temp\NETAPI32.DLL
  3697. 2496
  3698. File
  3699. Failed
  3700.  
  3701. C:\Users\ADMINI~1\AppData\Local\Temp\NETUTILS.DLL
  3702. 2496
  3703. File
  3704. Failed
  3705.  
  3706. C:\Users\ADMINI~1\AppData\Local\Temp\SRVCLI.DLL
  3707. 2496
  3708. File
  3709. Failed
  3710.  
  3711. C:\Users\ADMINI~1\AppData\Local\Temp\WKSCLI.DLL
  3712. 2496
  3713. File
  3714. Failed
  3715.  
  3716. C:\Users\ADMINI~1\AppData\Local\Temp\SCHEDCLI.DLL
  3717. 2496
  3718. API Call
  3719.  
  3720. API Name: GetSystemDirectoryW Address: 0x75eef96e
  3721. Params: [0x75f56420, 260]
  3722. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3723. 2496
  3724. File
  3725. Failed
  3726.  
  3727. C:\Users\ADMINI~1\AppData\Local\Temp\SAMCLI.DLL
  3728. 2496
  3729. File
  3730. Failed
  3731.  
  3732. C:\Users\ADMINI~1\AppData\Local\Temp\POWRPROF.DLL
  3733. 2496
  3734. API Call
  3735.  
  3736. API Name: GetSystemDirectoryW Address: 0x75709cce
  3737. Params: [0x18f460, 260]
  3738. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3739. 2496
  3740. File
  3741. Failed
  3742.  
  3743. C:\Users\ADMINI~1\AppData\Local\Temp\CRYPTSP.DLL
  3744. 2496
  3745. File
  3746. Failed
  3747.  
  3748. C:\TEST\CERBER_DEBUG.TXT
  3749. 2496
  3750. File
  3751. Failed
  3752.  
  3753. C:\Users\ADMINI~1\AppData\Local\Temp\7E4F78D4\1556.TMP
  3754. 2496
  3755. API Call
  3756.  
  3757. API Name: GetComputerNameA Address: 0x00409e10
  3758. Params: [0x18f948, 0x18f958]
  3759. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3760. 2496
  3761. Regkey
  3762. Queryvalue
  3763.  
  3764. \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
  3765. 2496
  3766. Mutex
  3767.  
  3768. \Sessions\1\BaseNamedObjects\shell.{15F27164-348C-262B-D0DF-491A6E8F42F5}
  3769. 2496
  3770. File
  3771. Failed
  3772.  
  3773. C:\Users\ADMINI~1\AppData\Local\Temp\DWMAPI.DLL
  3774. 2496
  3775. File
  3776. Failed
  3777.  
  3778. C:\TEST\CERBER_DEBUG2.TXT
  3779. 2496
  3780. API Call
  3781.  
  3782. API Name: Sleep Address: 0x0040b28f
  3783. Params: [1000]
  3784. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3785. 2496
  3786. API Call
  3787.  
  3788. API Name: Sleep Address: 0x0040b28f
  3789. Params: [1000]
  3790. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3791. 2496
  3792. Uac
  3793. Service
  3794.  
  3795. Multimedia Class Scheduler
  3796.  
  3797. API Call
  3798.  
  3799. API Name: Sleep Address: 0x0040b28f
  3800. Params: [1000]
  3801. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3802. 2496
  3803. API Call
  3804.  
  3805. API Name: Sleep Address: 0x0040b28f
  3806. Params: [1000]
  3807. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3808. 2496
  3809. API Call
  3810.  
  3811. API Name: GetSystemDirectoryW Address: 0x0040d594
  3812. Params: [0x18f570, 260]
  3813. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3814. 2496
  3815. API Call
  3816.  
  3817. API Name: GetVolumeNameForVolumeMountPointW Address: 0x76a80aaa
  3818. Params: [NULL, \\?\Volume{a4dcb962-c2b8-11e2-8b83-806e6f6e6963}\]
  3819. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3820. 2496
  3821. File
  3822. Failed
  3823.  
  3824. C:\Users\Administrator\AppData\Local\Temp\7e4f78d4
  3825. 2496
  3826. Folder
  3827. Created
  3828.  
  3829. C:\Users\Administrator\AppData\Local\Temp\7e4f78d4
  3830. 2496
  3831. File
  3832. Created
  3833.  
  3834. C:\Users\Administrator\AppData\Local\Temp\7e4f78d4\4f61.tmp
  3835. 2496
  3836. File
  3837. Close
  3838.  
  3839. C:\Users\Administrator\AppData\Local\Temp\7e4f78d4\4f61.tmp
  3840. MD5: 778ddd8e9f27878b1577b20f20bc60db
  3841. SHA1: 6c1de4a28a025084185c9338bbd6b297f6f90d5b
  3842. 2496 344
  3843. File
  3844. Created
  3845.  
  3846. C:\Users\Administrator\AppData\Local\Temp\7e4f78d4\1556.tmp
  3847. 2496
  3848. File
  3849. Close
  3850.  
  3851. C:\Users\Administrator\AppData\Local\Temp\7e4f78d4\1556.tmp
  3852. MD5: 56e08c19934097733fc7b5dd09d73ebd
  3853. SHA1: 827bfa8eb36cabbf2bf4c2cd049ec3d1138abb64
  3854. 2496 130
  3855. File
  3856. Failed
  3857.  
  3858. C:\Windows\SysWOW64\RPCSS.DLL
  3859. 2496
  3860. 2 Repeated items skipped
  3861. File
  3862. Failed
  3863.  
  3864. C:\Users\Administrator\AppData\Local\Microsoft\Windows\Caches
  3865. 2496
  3866. API Call
  3867.  
  3868. API Name: GetVolumeNameForVolumeMountPointW Address: 0x76a80aaa
  3869. Params: [NULL, \\?\Volume{a4dcb962-c2b8-11e2-8b83-806e6f6e6963}\]
  3870. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3871. 2496
  3872. API Call
  3873.  
  3874. API Name: GetVolumeNameForVolumeMountPointW Address: 0x76a80aaa
  3875. Params: [NULL, \\?\Volume{a4dcb962-c2b8-11e2-8b83-806e6f6e6963}\]
  3876. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3877. 2496
  3878. File
  3879. Failed
  3880.  
  3881. C:\Users\ADMINI~1\AppData\Local\Temp\NTMARTA.DLL
  3882. 2496
  3883. File
  3884. Failed
  3885.  
  3886. C:\Users\ADMINI~1\AppData\Local\Temp\PROFAPI.DLL
  3887. 2496
  3888. API Call
  3889.  
  3890. API Name: GetVolumeNameForVolumeMountPointW Address: 0x76a80e20
  3891. Params: [NULL, \\?\Volume{a4dcb965-c2b8-11e2-8b83-806e6f6e6963}\]
  3892. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3893. 2496
  3894. API Call
  3895.  
  3896. API Name: GetVolumeNameForVolumeMountPointW Address: 0x76a80e20
  3897. Params: [NULL, \\?\Volume{a4dcb962-c2b8-11e2-8b83-806e6f6e6963}\]
  3898. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3899. 2496
  3900. File
  3901. Failed
  3902.  
  3903. C:\Users\ADMINI~1\AppData\Local\Temp\APPHELP.DLL
  3904. 2496
  3905. API Call
  3906.  
  3907. API Name: GetVolumeNameForVolumeMountPointW Address: 0x02f30aaa
  3908. Params: [NULL, \\?\Volume{a4dcb962-c2b8-11e2-8b83-806e6f6e6963}\]
  3909. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3910. 2496
  3911. File
  3912. Failed
  3913.  
  3914. C:\Users\Administrator\AppData\Local\Microsoft\Windows\Caches
  3915. 2496
  3916. File
  3917. Failed
  3918.  
  3919. C:\Users\ADMINI~1\AppData\Local\Temp\LINKINFO.DLL
  3920. 2496
  3921. API Call
  3922.  
  3923. API Name: GetSystemDirectoryW Address: 0x74cb56d4
  3924. Params: [0x18c700, 260]
  3925. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3926. 2496
  3927. API Call
  3928.  
  3929. API Name: GetSystemDirectoryW Address: 0x74cb56d4
  3930. Params: [0x18c6c8, 260]
  3931. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3932. 2496
  3933. API Call
  3934.  
  3935. API Name: GetVolumeNameForVolumeMountPointW Address: 0x02f30e20
  3936. Params: [NULL, \\?\Volume{a4dcb965-c2b8-11e2-8b83-806e6f6e6963}\]
  3937. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3938. 2496
  3939. API Call
  3940.  
  3941. API Name: GetVolumeNameForVolumeMountPointW Address: 0x02f30e20
  3942. Params: [NULL, \\?\Volume{a4dcb962-c2b8-11e2-8b83-806e6f6e6963}\]
  3943. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3944. 2496
  3945. Regkey
  3946. Setval
  3947.  
  3948. \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500_CLASSES\Local Settings\MuiCache\90\52C6
  3949. 4B7E\"LanguageList" = en-US\0en\0\0
  3950. 2496
  3951. File
  3952. Failed
  3953.  
  3954. C:\Users\ADMINI~1\AppData\Local\Temp\CRYPTEXT.DLL
  3955. 2496
  3956. Regkey
  3957. Setval
  3958.  
  3959. \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500_CLASSES\Local Settings\MuiCache\90\52C6
  3960. 4B7E\"@cryptext.dll,-6108" = Security Certificate
  3961. 2496
  3962. API Call
  3963.  
  3964. API Name: GetSystemDirectoryW Address: 0x6f7298d0
  3965. Params: [0x18f428, 261]
  3966. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3967. 2496
  3968. File
  3969. Failed
  3970.  
  3971. C:\Users\ADMINI~1\AppData\Local\Temp\WINDOWSCODECS.DLL
  3972. 2496
  3973. File
  3974. Failed
  3975.  
  3976. C:\Windows\SysWOW64\wbem\WBEMCOMN.DLL
  3977. 2496
  3978. API Call
  3979.  
  3980. API Name: GetComputerNameExW Address: 0x755c187c
  3981. Params: [3, 0x0, 0x18f01c]
  3982. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3983. 2496
  3984. API Call
  3985.  
  3986. API Name: GetComputerNameExW Address: 0x755c18df
  3987. Params: [3, 0x4700848, 0x18f01c]
  3988. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  3989. 2496
  3990. File
  3991. Failed
  3992.  
  3993. C:\Users\ADMINI~1\AppData\Local\Temp\RPCRTREMOTE.DLL
  3994. 2496
  3995. API Call
  3996.  
  3997. API Name: Sleep Address: 0x75bcd98d
  3998. Params: [60000]
  3999. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4000. 2496
  4001. API Call
  4002.  
  4003. API Name: GetComputerNameW Address: 0x755c22d5
  4004. Params: [0x18f7fc, 0x18f7f0]
  4005. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4006. 2496
  4007. File
  4008. Failed
  4009.  
  4010. C:\Windows\SysWOW64\wbem\NTDSAPI.DLL
  4011. 2496
  4012. API Call
  4013.  
  4014. API Name: Sleep Address: 0x75bcd98d
  4015. Params: [60000]
  4016. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4017. 2496
  4018. API Call
  4019.  
  4020. API Name: Sleep Address: 0x75bcd98d
  4021. Params: [60000]
  4022. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4023. 2496
  4024. API Call
  4025.  
  4026. API Name: Sleep Address: 0x75bcd98d
  4027. Params: [60000]
  4028. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4029. 2496
  4030. Wmiquery
  4031.  
  4032. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe
  4033. 2496
  4034. API Call
  4035.  
  4036. API Name: Sleep Address: 0x75bcd98d
  4037. Params: [60000]
  4038. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4039. 2496
  4040. API Call
  4041.  
  4042. API Name: Sleep Address: 0x75bcd98d
  4043. Params: [60000]
  4044. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4045. 2496
  4046. 3 Repeated items skipped
  4047. API Call
  4048.  
  4049. API Name: GetComputerNameExW Address: 0x755c187c
  4050. Params: [3, 0x0, 0x18f01c]
  4051. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4052. 2496
  4053. API Call
  4054.  
  4055. API Name: Sleep Address: 0x75bcd98d
  4056. Params: [60000]
  4057. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4058. 2496
  4059. API Call
  4060.  
  4061. API Name: GetComputerNameExW Address: 0x755c18df
  4062. Params: [3, 0x4716420, 0x18f01c]
  4063. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4064. 2496
  4065. API Call
  4066.  
  4067. API Name: Sleep Address: 0x75bcd98d
  4068. Params: [60000]
  4069. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4070. 2496
  4071. API Call
  4072.  
  4073. API Name: GetComputerNameW Address: 0x755c22d5
  4074. Params: [0x18f7fc, 0x18f7f0]
  4075. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4076. 2496
  4077. API Call
  4078.  
  4079. API Name: Sleep Address: 0x75bcd98d
  4080. Params: [60000]
  4081. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4082. 2496
  4083. API Call
  4084.  
  4085. API Name: Sleep Address: 0x75bcd98d
  4086. Params: [60000]
  4087. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4088. 2496
  4089. 4 Repeated items skipped
  4090. API Call
  4091.  
  4092. API Name: Sleep Address: 0x75bcd98d
  4093. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4094. 2496
  4095. API Call
  4096.  
  4097. API Name: GetComputerNameExW Address: 0x755c187c
  4098. Params: [3, 0x0, 0x18f01c]
  4099. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4100. 2496
  4101. API Call
  4102.  
  4103. API Name: GetComputerNameExW Address: 0x755c18df
  4104. Params: [3, 0x4716400, 0x18f01c]
  4105. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4106. 2496
  4107. API Call
  4108.  
  4109. API Name: GetComputerNameW Address: 0x755c22d5
  4110. Params: [0x18f7fc, 0x18f7f0]
  4111. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4112. 2496
  4113. Wmiquery
  4114.  
  4115. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe
  4116. 2496
  4117. API Call
  4118.  
  4119. API Name: Sleep Address: 0x75bcd98d
  4120. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4121. 2496
  4122. API Call
  4123.  
  4124. API Name: GetComputerNameExW Address: 0x755c187c
  4125. Params: [3, 0x0, 0x18f01c]
  4126. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4127. 2496
  4128. API Call
  4129.  
  4130. API Name: GetComputerNameW Address: 0x755c22d5
  4131. Params: [0x18f7fc, 0x18f7f0]
  4132. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4133. 2496
  4134. API Call
  4135.  
  4136. API Name: Sleep Address: 0x75bcd98d
  4137. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4138. 2496
  4139. API Call
  4140.  
  4141. API Name: GetComputerNameW Address: 0x755c22d5
  4142. Params: [0x18f7fc, 0x18f7f0]
  4143. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4144. 2496
  4145. Wmiquery
  4146.  
  4147. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe
  4148. 2496
  4149. API Call
  4150.  
  4151. API Name: Sleep Address: 0x75bcd98d
  4152. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4153. 2496
  4154. API Call
  4155.  
  4156. API Name: GetComputerNameW Address: 0x755c22d5
  4157. Params: [0x18f7fc, 0x18f7f0]
  4158. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4159. 2496
  4160. API Call
  4161.  
  4162. API Name: Sleep Address: 0x75bcd98d
  4163. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4164. 2496
  4165. API Call
  4166.  
  4167. API Name: GetSystemDirectoryW Address: 0x0040e669
  4168. Params: [0x18f850, 260]
  4169. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4170. 2496
  4171. File
  4172. Find
  4173.  
  4174. C:\*
  4175. 2496
  4176. API Call
  4177.  
  4178. API Name: Sleep Address: 0x0040e33c
  4179. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4180. 2496
  4181. File
  4182. Find
  4183.  
  4184. C:\Users\*
  4185. 2496
  4186. API Call
  4187.  
  4188. API Name: Sleep Address: 0x0040e33c
  4189. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4190. 2496
  4191. API Call
  4192.  
  4193. API Name: Sleep Address: 0x0040e33c
  4194. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4195. 2496
  4196. File
  4197. Failed
  4198.  
  4199. C:\Program Files (x86)\BITCOIN
  4200. 2496
  4201. File
  4202. Failed
  4203.  
  4204. C:\Program Files (x86)\BITCOIN
  4205. 2496
  4206. File
  4207. Failed
  4208.  
  4209. C:\Program Files (x86)\BITCOIN
  4210. 2496
  4211. File
  4212. Failed
  4213.  
  4214. C:\ProgramData\BITCOIN
  4215. 2496
  4216. File
  4217. Failed
  4218.  
  4219. C:\ProgramData\BITCOIN
  4220. 2496
  4221. File
  4222. Failed
  4223.  
  4224. C:\ProgramData\BITCOIN
  4225. 2496
  4226. File
  4227. Failed
  4228.  
  4229. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\BITCOIN
  4230. 2496
  4231. File
  4232. Failed
  4233.  
  4234. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\BITCOIN
  4235. 2496
  4236. File
  4237. Failed
  4238.  
  4239. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\BITCOIN
  4240. 2496
  4241. File
  4242. Failed
  4243.  
  4244. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\BITCOIN
  4245. 2496
  4246. File
  4247. Failed
  4248.  
  4249. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\BITCOIN
  4250. 2496
  4251. File
  4252. Failed
  4253.  
  4254. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\BITCOIN
  4255. 2496
  4256. File
  4257. Failed
  4258.  
  4259. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\BITCOIN
  4260. 2496
  4261. File
  4262. Failed
  4263.  
  4264. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\BITCOIN
  4265. 2496
  4266. File
  4267. Failed
  4268.  
  4269. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\BITCOIN
  4270. 2496
  4271. File
  4272. Failed
  4273.  
  4274. C:\Users\Administrator\AppData\Roaming\BITCOIN
  4275. 2496
  4276. File
  4277. Failed
  4278.  
  4279. C:\Users\Administrator\AppData\Roaming\BITCOIN
  4280. 2496
  4281. File
  4282. Failed
  4283.  
  4284. C:\Users\Administrator\AppData\Roaming\BITCOIN
  4285. 2496
  4286. File
  4287. Failed
  4288.  
  4289. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\BITCOIN
  4290. 2496
  4291. File
  4292. Failed
  4293.  
  4294. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\BITCOIN
  4295. 2496
  4296. File
  4297. Failed
  4298.  
  4299. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\BITCOIN
  4300. 2496
  4301. File
  4302. Failed
  4303.  
  4304. C:\Windows\ServiceProfiles\LocalService\AppData\Local\BITCOIN
  4305. 2496
  4306. File
  4307. Failed
  4308.  
  4309. C:\Windows\ServiceProfiles\LocalService\AppData\Local\BITCOIN
  4310. 2496
  4311. File
  4312. Failed
  4313.  
  4314. C:\Windows\ServiceProfiles\LocalService\AppData\Local\BITCOIN
  4315. 2496
  4316. File
  4317. Failed
  4318.  
  4319. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\BITCOIN
  4320. 2496
  4321. File
  4322. Failed
  4323.  
  4324. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\BITCOIN
  4325. 2496
  4326. File
  4327. Failed
  4328.  
  4329. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\BITCOIN
  4330. 2496
  4331. File
  4332. Failed
  4333.  
  4334. C:\Users\Administrator\AppData\Local\BITCOIN
  4335. 2496
  4336. File
  4337. Failed
  4338.  
  4339. C:\Users\Administrator\AppData\Local\BITCOIN
  4340. 2496
  4341. File
  4342. Failed
  4343.  
  4344. C:\Users\Administrator\AppData\Local\BITCOIN
  4345. 2496
  4346. File
  4347. Failed
  4348.  
  4349. C:\Program Files (x86)\EXCEL
  4350. 2496
  4351. File
  4352. Failed
  4353.  
  4354. C:\Program Files (x86)\EXCEL
  4355. 2496
  4356. File
  4357. Failed
  4358.  
  4359. C:\Program Files (x86)\EXCEL
  4360. 2496
  4361. File
  4362. Failed
  4363.  
  4364. C:\ProgramData\EXCEL
  4365. 2496
  4366. File
  4367. Failed
  4368.  
  4369. C:\ProgramData\EXCEL
  4370. 2496
  4371. File
  4372. Failed
  4373.  
  4374. C:\ProgramData\EXCEL
  4375. 2496
  4376. File
  4377. Failed
  4378.  
  4379. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\EXCEL
  4380. 2496
  4381. File
  4382. Failed
  4383.  
  4384. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\EXCEL
  4385. 2496
  4386. File
  4387. Failed
  4388.  
  4389. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\EXCEL
  4390. 2496
  4391. File
  4392. Failed
  4393.  
  4394. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\EXCEL
  4395. 2496
  4396. File
  4397. Failed
  4398.  
  4399. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\EXCEL
  4400. 2496
  4401. File
  4402. Failed
  4403.  
  4404. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\EXCEL
  4405. 2496
  4406. File
  4407. Failed
  4408.  
  4409. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\EXCEL
  4410. 2496
  4411. File
  4412. Failed
  4413.  
  4414. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\EXCEL
  4415. 2496
  4416. File
  4417. Failed
  4418.  
  4419. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\EXCEL
  4420. 2496
  4421. File
  4422. Failed
  4423.  
  4424. C:\Users\Administrator\AppData\Roaming\EXCEL
  4425. 2496
  4426. File
  4427. Failed
  4428.  
  4429. C:\Users\Administrator\AppData\Roaming\EXCEL
  4430. 2496
  4431. File
  4432. Failed
  4433.  
  4434. C:\Users\Administrator\AppData\Roaming\EXCEL
  4435. 2496
  4436. File
  4437. Failed
  4438.  
  4439. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\EXCEL
  4440. 2496
  4441. File
  4442. Failed
  4443.  
  4444. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\EXCEL
  4445. 2496
  4446. File
  4447. Failed
  4448.  
  4449. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\EXCEL
  4450. 2496
  4451. File
  4452. Failed
  4453.  
  4454. C:\Windows\ServiceProfiles\LocalService\AppData\Local\EXCEL
  4455. 2496
  4456. File
  4457. Failed
  4458.  
  4459. C:\Windows\ServiceProfiles\LocalService\AppData\Local\EXCEL
  4460. 2496
  4461. File
  4462. Failed
  4463.  
  4464. C:\Windows\ServiceProfiles\LocalService\AppData\Local\EXCEL
  4465. 2496
  4466. File
  4467. Failed
  4468.  
  4469. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\EXCEL
  4470. 2496
  4471. File
  4472. Failed
  4473.  
  4474. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\EXCEL
  4475. 2496
  4476. File
  4477. Failed
  4478.  
  4479. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\EXCEL
  4480. 2496
  4481. File
  4482. Failed
  4483.  
  4484. C:\Users\Administrator\AppData\Local\EXCEL
  4485. 2496
  4486. API Call
  4487.  
  4488. API Name: Sleep Address: 0x0040e33c
  4489. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4490. 2496
  4491. File
  4492. Failed
  4493.  
  4494. C:\Users\Administrator\AppData\Local\EXCEL
  4495. 2496
  4496. File
  4497. Failed
  4498.  
  4499. C:\Users\Administrator\AppData\Local\EXCEL
  4500. 2496
  4501. File
  4502. Failed
  4503.  
  4504. C:\ProgramData\MICROSOFT SQL SERVER
  4505. 2496
  4506. File
  4507. Failed
  4508.  
  4509. C:\ProgramData\MICROSOFT SQL SERVER
  4510. 2496
  4511. File
  4512. Failed
  4513.  
  4514. C:\ProgramData\MICROSOFT SQL SERVER
  4515. 2496
  4516. File
  4517. Failed
  4518.  
  4519. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\MICROSOFT SQL SERVER
  4520. 2496
  4521. File
  4522. Failed
  4523.  
  4524. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\MICROSOFT SQL SERVER
  4525. 2496
  4526. File
  4527. Failed
  4528.  
  4529. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\MICROSOFT SQL SERVER
  4530. 2496
  4531. File
  4532. Failed
  4533.  
  4534. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\MICROSOFT SQL SERVER
  4535. 2496
  4536. File
  4537. Failed
  4538.  
  4539. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\MICROSOFT SQL SERVER
  4540. 2496
  4541. File
  4542. Failed
  4543.  
  4544. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\MICROSOFT SQL SERVER
  4545. 2496
  4546. File
  4547. Failed
  4548.  
  4549. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\MICROSOFT SQL SERVER
  4550. 2496
  4551. File
  4552. Failed
  4553.  
  4554. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\MICROSOFT SQL SERVER
  4555. 2496
  4556. File
  4557. Failed
  4558.  
  4559. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\MICROSOFT SQL SERVER
  4560. 2496
  4561. File
  4562. Failed
  4563.  
  4564. C:\Users\Administrator\AppData\Roaming\MICROSOFT SQL SERVER
  4565. 2496
  4566. File
  4567. Failed
  4568.  
  4569. C:\Users\Administrator\AppData\Roaming\MICROSOFT SQL SERVER
  4570. 2496
  4571. File
  4572. Failed
  4573.  
  4574. C:\Users\Administrator\AppData\Roaming\MICROSOFT SQL SERVER
  4575. 2496
  4576. File
  4577. Failed
  4578.  
  4579. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\MICROSOFT SQL SERVER
  4580. 2496
  4581. File
  4582. Failed
  4583.  
  4584. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\MICROSOFT SQL SERVER
  4585. 2496
  4586. File
  4587. Failed
  4588.  
  4589. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\MICROSOFT SQL SERVER
  4590. 2496
  4591. File
  4592. Failed
  4593.  
  4594. C:\Windows\ServiceProfiles\LocalService\AppData\Local\MICROSOFT SQL SERVER
  4595. 2496
  4596. File
  4597. Failed
  4598.  
  4599. C:\Windows\ServiceProfiles\LocalService\AppData\Local\MICROSOFT SQL SERVER
  4600. 2496
  4601. File
  4602. Failed
  4603.  
  4604. C:\Windows\ServiceProfiles\LocalService\AppData\Local\MICROSOFT SQL SERVER
  4605. 2496
  4606. File
  4607. Failed
  4608.  
  4609. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\MICROSOFT SQL SERVER
  4610. 2496
  4611. File
  4612. Failed
  4613.  
  4614. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\MICROSOFT SQL SERVER
  4615. 2496
  4616. File
  4617. Failed
  4618.  
  4619. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\MICROSOFT SQL SERVER
  4620. 2496
  4621. File
  4622. Failed
  4623.  
  4624. C:\Users\Administrator\AppData\Local\MICROSOFT SQL SERVER
  4625. 2496
  4626. File
  4627. Failed
  4628.  
  4629. C:\Users\Administrator\AppData\Local\MICROSOFT SQL SERVER
  4630. 2496
  4631. File
  4632. Failed
  4633.  
  4634. C:\Users\Administrator\AppData\Local\MICROSOFT SQL SERVER
  4635. 2496
  4636. File
  4637. Failed
  4638.  
  4639. C:\Program Files (x86)\MICROSOFT\EXCEL
  4640. 2496
  4641. File
  4642. Failed
  4643.  
  4644. C:\Program Files (x86)\MICROSOFT\EXCEL
  4645. 2496
  4646. File
  4647. Failed
  4648.  
  4649. C:\Program Files (x86)\MICROSOFT\EXCEL
  4650. 2496
  4651. File
  4652. Failed
  4653.  
  4654. C:\ProgramData\Microsoft\EXCEL
  4655. 2496
  4656. File
  4657. Failed
  4658.  
  4659. C:\ProgramData\Microsoft\EXCEL
  4660. 2496
  4661. File
  4662. Failed
  4663.  
  4664. C:\ProgramData\Microsoft\EXCEL
  4665. 2496
  4666. File
  4667. Failed
  4668.  
  4669. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\EXCEL
  4670. 2496
  4671. File
  4672. Failed
  4673.  
  4674. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\EXCEL
  4675. 2496
  4676. File
  4677. Failed
  4678.  
  4679. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\EXCEL
  4680. 2496
  4681. File
  4682. Failed
  4683.  
  4684. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\EXCEL
  4685. 2496
  4686. File
  4687. Failed
  4688.  
  4689. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\EXCEL
  4690. 2496
  4691. File
  4692. Failed
  4693.  
  4694. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\EXCEL
  4695. 2496
  4696. File
  4697. Failed
  4698.  
  4699. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\EXCEL
  4700. 2496
  4701. File
  4702. Failed
  4703.  
  4704. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\EXCEL
  4705. 2496
  4706. File
  4707. Failed
  4708.  
  4709. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\EXCEL
  4710. 2496
  4711. File
  4712. Failed
  4713.  
  4714. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\EXCEL
  4715. 2496
  4716. File
  4717. Failed
  4718.  
  4719. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\EXCEL
  4720. 2496
  4721. File
  4722. Failed
  4723.  
  4724. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\EXCEL
  4725. 2496
  4726. File
  4727. Failed
  4728.  
  4729. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\EXCEL
  4730. 2496
  4731. File
  4732. Failed
  4733.  
  4734. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\EXCEL
  4735. 2496
  4736. File
  4737. Failed
  4738.  
  4739. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\EXCEL
  4740. 2496
  4741. File
  4742. Failed
  4743.  
  4744. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\EXCEL
  4745. 2496
  4746. File
  4747. Failed
  4748.  
  4749. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\EXCEL
  4750. 2496
  4751. File
  4752. Failed
  4753.  
  4754. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\EXCEL
  4755. 2496
  4756. File
  4757. Failed
  4758.  
  4759. C:\Users\Administrator\AppData\Local\Microsoft\EXCEL
  4760. 2496
  4761. File
  4762. Failed
  4763.  
  4764. C:\Users\Administrator\AppData\Local\Microsoft\EXCEL
  4765. 2496
  4766. File
  4767. Failed
  4768.  
  4769. C:\Users\Administrator\AppData\Local\Microsoft\EXCEL
  4770. 2496
  4771. File
  4772. Failed
  4773.  
  4774. C:\Program Files (x86)\MICROSOFT\MICROSOFT SQL SERVER
  4775. 2496
  4776. File
  4777. Failed
  4778.  
  4779. C:\Program Files (x86)\MICROSOFT\MICROSOFT SQL SERVER
  4780. 2496
  4781. File
  4782. Failed
  4783.  
  4784. C:\Program Files (x86)\MICROSOFT\MICROSOFT SQL SERVER
  4785. 2496
  4786. API Call
  4787.  
  4788. API Name: GetSystemDirectoryW Address: 0x6f7298d0
  4789. Params: [0x18f580, 261]
  4790. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4791. 2496
  4792. File
  4793. Failed
  4794.  
  4795. C:\ProgramData\Microsoft\MICROSOFT SQL SERVER
  4796. 2496
  4797. File
  4798. Failed
  4799.  
  4800. C:\ProgramData\Microsoft\MICROSOFT SQL SERVER
  4801. 2496
  4802. File
  4803. Failed
  4804.  
  4805. C:\ProgramData\Microsoft\MICROSOFT SQL SERVER
  4806. 2496
  4807. File
  4808. Failed
  4809.  
  4810. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\MICROSOFT SQL SERVER
  4811. 2496
  4812. File
  4813. Failed
  4814.  
  4815. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\MICROSOFT SQL SERVER
  4816. 2496
  4817. File
  4818. Failed
  4819.  
  4820. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\MICROSOFT SQL SERVER
  4821. 2496
  4822. File
  4823. Failed
  4824.  
  4825. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\MICROSOFT SQL SERVER
  4826. 2496
  4827. File
  4828. Failed
  4829.  
  4830. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\MICROSOFT SQL SERVER
  4831. 2496
  4832. File
  4833. Failed
  4834.  
  4835. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\MICROSOFT SQL SERVER
  4836. 2496
  4837. File
  4838. Failed
  4839.  
  4840. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\MICROSOFT SQL SERVER
  4841. 2496
  4842. File
  4843. Failed
  4844.  
  4845. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\MICROSOFT SQL SERVER
  4846. 2496
  4847. File
  4848. Failed
  4849.  
  4850. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\MICROSOFT SQL SERVER
  4851. 2496
  4852. File
  4853. Failed
  4854.  
  4855. C:\Users\Administrator\AppData\Roaming\Microsoft\MICROSOFT SQL SERVER
  4856. 2496
  4857. File
  4858. Failed
  4859.  
  4860. C:\Users\Administrator\AppData\Roaming\Microsoft\MICROSOFT SQL SERVER
  4861. 2496
  4862. File
  4863. Failed
  4864.  
  4865. C:\Users\Administrator\AppData\Roaming\Microsoft\MICROSOFT SQL SERVER
  4866. 2496
  4867. File
  4868. Failed
  4869.  
  4870. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\MICROSOFT SQL SERVER
  4871. 2496
  4872. File
  4873. Failed
  4874.  
  4875. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\MICROSOFT SQL SERVER
  4876. 2496
  4877. File
  4878. Failed
  4879.  
  4880. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\MICROSOFT SQL SERVER
  4881. 2496
  4882. File
  4883. Failed
  4884.  
  4885. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\MICROSOFT SQL SERVER
  4886. 2496
  4887. File
  4888. Failed
  4889.  
  4890. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\MICROSOFT SQL SERVER
  4891. 2496
  4892. File
  4893. Failed
  4894.  
  4895. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\MICROSOFT SQL SERVER
  4896. 2496
  4897. API Call
  4898.  
  4899. API Name: Process32FirstW Address: 0x00401bb2
  4900. Params: [0x2e4, 0x528fd5c]
  4901. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  4902. 2496
  4903. Malicious Alert
  4904. Generic Anomalous Activity
  4905.  
  4906. Message: Enumerating running processes
  4907.  
  4908. File
  4909. Failed
  4910.  
  4911. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\MICROSOFT SQL SERVER
  4912. 2496
  4913. File
  4914. Failed
  4915.  
  4916. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\MICROSOFT SQL SERVER
  4917. 2496
  4918. File
  4919. Failed
  4920.  
  4921. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\MICROSOFT SQL SERVER
  4922. 2496
  4923. File
  4924. Failed
  4925.  
  4926. C:\Users\Administrator\AppData\Local\Microsoft\MICROSOFT SQL SERVER
  4927. 2496
  4928. File
  4929. Failed
  4930.  
  4931. C:\Users\Administrator\AppData\Local\Microsoft\MICROSOFT SQL SERVER
  4932. 2496
  4933. File
  4934. Failed
  4935.  
  4936. C:\Users\Administrator\AppData\Local\Microsoft\MICROSOFT SQL SERVER
  4937. 2496
  4938. File
  4939. Failed
  4940.  
  4941. C:\Program Files (x86)\MICROSOFT\OFFICE
  4942. 2496
  4943. File
  4944. Failed
  4945.  
  4946. C:\Program Files (x86)\MICROSOFT\OFFICE
  4947. 2496
  4948. File
  4949. Failed
  4950.  
  4951. C:\Program Files (x86)\MICROSOFT\OFFICE
  4952. 2496
  4953. File
  4954. Failed
  4955.  
  4956. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\OFFICE
  4957. 2496
  4958. File
  4959. Failed
  4960.  
  4961. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\OFFICE
  4962. 2496
  4963. File
  4964. Failed
  4965.  
  4966. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\OFFICE
  4967. 2496
  4968. File
  4969. Failed
  4970.  
  4971. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\OFFICE
  4972. 2496
  4973. File
  4974. Failed
  4975.  
  4976. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\OFFICE
  4977. 2496
  4978. File
  4979. Failed
  4980.  
  4981. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\OFFICE
  4982. 2496
  4983. File
  4984. Failed
  4985.  
  4986. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\OFFICE
  4987. 2496
  4988. File
  4989. Failed
  4990.  
  4991. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\OFFICE
  4992. 2496
  4993. File
  4994. Failed
  4995.  
  4996. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\OFFICE
  4997. 2496
  4998. File
  4999. Failed
  5000.  
  5001. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\OFFICE
  5002. 2496
  5003. File
  5004. Failed
  5005.  
  5006. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\OFFICE
  5007. 2496
  5008. File
  5009. Failed
  5010.  
  5011. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\OFFICE
  5012. 2496
  5013. File
  5014. Failed
  5015.  
  5016. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\OFFICE
  5017. 2496
  5018. File
  5019. Failed
  5020.  
  5021. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\OFFICE
  5022. 2496
  5023. File
  5024. Failed
  5025.  
  5026. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\OFFICE
  5027. 2496
  5028. File
  5029. Failed
  5030.  
  5031. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\OFFICE
  5032. 2496
  5033. File
  5034. Failed
  5035.  
  5036. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\OFFICE
  5037. 2496
  5038. File
  5039. Failed
  5040.  
  5041. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\OFFICE
  5042. 2496
  5043. File
  5044. Failed
  5045.  
  5046. C:\Program Files (x86)\MICROSOFT\ONENOTE
  5047. 2496
  5048. File
  5049. Failed
  5050.  
  5051. C:\Program Files (x86)\MICROSOFT\ONENOTE
  5052. 2496
  5053. File
  5054. Failed
  5055.  
  5056. C:\Program Files (x86)\MICROSOFT\ONENOTE
  5057. 2496
  5058. File
  5059. Failed
  5060.  
  5061. C:\ProgramData\Microsoft\ONENOTE
  5062. 2496
  5063. File
  5064. Failed
  5065.  
  5066. C:\ProgramData\Microsoft\ONENOTE
  5067. 2496
  5068. File
  5069. Failed
  5070.  
  5071. C:\ProgramData\Microsoft\ONENOTE
  5072. 2496
  5073. File
  5074. Failed
  5075.  
  5076. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\ONENOTE
  5077. 2496
  5078. File
  5079. Failed
  5080.  
  5081. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\ONENOTE
  5082. 2496
  5083. File
  5084. Failed
  5085.  
  5086. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\ONENOTE
  5087. 2496
  5088. File
  5089. Failed
  5090.  
  5091. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\ONENOTE
  5092. 2496
  5093. File
  5094. Failed
  5095.  
  5096. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\ONENOTE
  5097. 2496
  5098. File
  5099. Failed
  5100.  
  5101. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\ONENOTE
  5102. 2496
  5103. File
  5104. Failed
  5105.  
  5106. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\ONENOTE
  5107. 2496
  5108. File
  5109. Failed
  5110.  
  5111. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\ONENOTE
  5112. 2496
  5113. File
  5114. Failed
  5115.  
  5116. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\ONENOTE
  5117. 2496
  5118. File
  5119. Failed
  5120.  
  5121. C:\Users\Administrator\AppData\Roaming\Microsoft\ONENOTE
  5122. 2496
  5123. File
  5124. Failed
  5125.  
  5126. C:\Users\Administrator\AppData\Roaming\Microsoft\ONENOTE
  5127. 2496
  5128. File
  5129. Failed
  5130.  
  5131. C:\Users\Administrator\AppData\Roaming\Microsoft\ONENOTE
  5132. 2496
  5133. File
  5134. Failed
  5135.  
  5136. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\ONENOTE
  5137. 2496
  5138. File
  5139. Failed
  5140.  
  5141. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\ONENOTE
  5142. 2496
  5143. File
  5144. Failed
  5145.  
  5146. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\ONENOTE
  5147. 2496
  5148. File
  5149. Failed
  5150.  
  5151. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\ONENOTE
  5152. 2496
  5153. File
  5154. Failed
  5155.  
  5156. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\ONENOTE
  5157. 2496
  5158. File
  5159. Failed
  5160.  
  5161. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\ONENOTE
  5162. 2496
  5163. File
  5164. Failed
  5165.  
  5166. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\ONENOTE
  5167. 2496
  5168. File
  5169. Failed
  5170.  
  5171. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\ONENOTE
  5172. 2496
  5173. File
  5174. Failed
  5175.  
  5176. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\ONENOTE
  5177. 2496
  5178. File
  5179. Failed
  5180.  
  5181. C:\Users\Administrator\AppData\Local\Microsoft\ONENOTE
  5182. 2496
  5183. File
  5184. Failed
  5185.  
  5186. C:\Users\Administrator\AppData\Local\Microsoft\ONENOTE
  5187. 2496
  5188. File
  5189. Failed
  5190.  
  5191. C:\Users\Administrator\AppData\Local\Microsoft\ONENOTE
  5192. 2496
  5193. File
  5194. Failed
  5195.  
  5196. C:\Program Files (x86)\MICROSOFT\OUTLOOK
  5197. 2496
  5198. File
  5199. Failed
  5200.  
  5201. C:\Program Files (x86)\MICROSOFT\OUTLOOK
  5202. 2496
  5203. File
  5204. Failed
  5205.  
  5206. C:\Program Files (x86)\MICROSOFT\OUTLOOK
  5207. 2496
  5208. File
  5209. Failed
  5210.  
  5211. C:\ProgramData\Microsoft\OUTLOOK
  5212. 2496
  5213. File
  5214. Failed
  5215.  
  5216. C:\ProgramData\Microsoft\OUTLOOK
  5217. 2496
  5218. File
  5219. Failed
  5220.  
  5221. C:\ProgramData\Microsoft\OUTLOOK
  5222. 2496
  5223. File
  5224. Failed
  5225.  
  5226. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\OUTLOOK
  5227. 2496
  5228. File
  5229. Failed
  5230.  
  5231. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\OUTLOOK
  5232. 2496
  5233. File
  5234. Failed
  5235.  
  5236. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\OUTLOOK
  5237. 2496
  5238. File
  5239. Failed
  5240.  
  5241. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\OUTLOOK
  5242. 2496
  5243. File
  5244. Failed
  5245.  
  5246. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\OUTLOOK
  5247. 2496
  5248. File
  5249. Failed
  5250.  
  5251. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\OUTLOOK
  5252. 2496
  5253. File
  5254. Failed
  5255.  
  5256. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\OUTLOOK
  5257. 2496
  5258. File
  5259. Failed
  5260.  
  5261. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\OUTLOOK
  5262. 2496
  5263. File
  5264. Failed
  5265.  
  5266. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\OUTLOOK
  5267. 2496
  5268. File
  5269. Failed
  5270.  
  5271. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\OUTLOOK
  5272. 2496
  5273. File
  5274. Failed
  5275.  
  5276. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\OUTLOOK
  5277. 2496
  5278. File
  5279. Failed
  5280.  
  5281. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\OUTLOOK
  5282. 2496
  5283. File
  5284. Failed
  5285.  
  5286. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\OUTLOOK
  5287. 2496
  5288. File
  5289. Failed
  5290.  
  5291. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\OUTLOOK
  5292. 2496
  5293. File
  5294. Failed
  5295.  
  5296. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\OUTLOOK
  5297. 2496
  5298. File
  5299. Failed
  5300.  
  5301. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\OUTLOOK
  5302. 2496
  5303. File
  5304. Failed
  5305.  
  5306. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\OUTLOOK
  5307. 2496
  5308. File
  5309. Failed
  5310.  
  5311. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\OUTLOOK
  5312. 2496
  5313. File
  5314. Failed
  5315.  
  5316. C:\Program Files (x86)\MICROSOFT\POWERPOINT
  5317. 2496
  5318. File
  5319. Failed
  5320.  
  5321. C:\Program Files (x86)\MICROSOFT\POWERPOINT
  5322. 2496
  5323. File
  5324. Failed
  5325.  
  5326. C:\Program Files (x86)\MICROSOFT\POWERPOINT
  5327. 2496
  5328. File
  5329. Failed
  5330.  
  5331. C:\ProgramData\Microsoft\POWERPOINT
  5332. 2496
  5333. File
  5334. Failed
  5335.  
  5336. C:\ProgramData\Microsoft\POWERPOINT
  5337. 2496
  5338. File
  5339. Failed
  5340.  
  5341. C:\ProgramData\Microsoft\POWERPOINT
  5342. 2496
  5343. File
  5344. Failed
  5345.  
  5346. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\POWERPOINT
  5347. 2496
  5348. File
  5349. Failed
  5350.  
  5351. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\POWERPOINT
  5352. 2496
  5353. File
  5354. Failed
  5355.  
  5356. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\POWERPOINT
  5357. 2496
  5358. File
  5359. Failed
  5360.  
  5361. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\POWERPOINT
  5362. 2496
  5363. File
  5364. Failed
  5365.  
  5366. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\POWERPOINT
  5367. 2496
  5368. File
  5369. Failed
  5370.  
  5371. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\POWERPOINT
  5372. 2496
  5373. File
  5374. Failed
  5375.  
  5376. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\POWERPOINT
  5377. 2496
  5378. File
  5379. Failed
  5380.  
  5381. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\POWERPOINT
  5382. 2496
  5383. File
  5384. Failed
  5385.  
  5386. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\POWERPOINT
  5387. 2496
  5388. File
  5389. Failed
  5390.  
  5391. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\POWERPOINT
  5392. 2496
  5393. File
  5394. Failed
  5395.  
  5396. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\POWERPOINT
  5397. 2496
  5398. File
  5399. Failed
  5400.  
  5401. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\POWERPOINT
  5402. 2496
  5403. File
  5404. Failed
  5405.  
  5406. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\POWERPOINT
  5407. 2496
  5408. File
  5409. Failed
  5410.  
  5411. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\POWERPOINT
  5412. 2496
  5413. File
  5414. Failed
  5415.  
  5416. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\POWERPOINT
  5417. 2496
  5418. File
  5419. Failed
  5420.  
  5421. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\POWERPOINT
  5422. 2496
  5423. File
  5424. Failed
  5425.  
  5426. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\POWERPOINT
  5427. 2496
  5428. File
  5429. Failed
  5430.  
  5431. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\POWERPOINT
  5432. 2496
  5433. File
  5434. Failed
  5435.  
  5436. C:\Users\Administrator\AppData\Local\Microsoft\POWERPOINT
  5437. 2496
  5438. File
  5439. Failed
  5440.  
  5441. C:\Users\Administrator\AppData\Local\Microsoft\POWERPOINT
  5442. 2496
  5443. File
  5444. Failed
  5445.  
  5446. C:\Users\Administrator\AppData\Local\Microsoft\POWERPOINT
  5447. 2496
  5448. File
  5449. Failed
  5450.  
  5451. C:\Program Files (x86)\MICROSOFT\WORD
  5452. 2496
  5453. File
  5454. Failed
  5455.  
  5456. C:\Program Files (x86)\MICROSOFT\WORD
  5457. 2496
  5458. File
  5459. Failed
  5460.  
  5461. C:\Program Files (x86)\MICROSOFT\WORD
  5462. 2496
  5463. File
  5464. Failed
  5465.  
  5466. C:\ProgramData\Microsoft\WORD
  5467. 2496
  5468. File
  5469. Failed
  5470.  
  5471. C:\ProgramData\Microsoft\WORD
  5472. 2496
  5473. File
  5474. Failed
  5475.  
  5476. C:\ProgramData\Microsoft\WORD
  5477. 2496
  5478. File
  5479. Failed
  5480.  
  5481. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\WORD
  5482. 2496
  5483. File
  5484. Failed
  5485.  
  5486. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\WORD
  5487. 2496
  5488. File
  5489. Failed
  5490.  
  5491. C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\WORD
  5492. 2496
  5493. File
  5494. Failed
  5495.  
  5496. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\WORD
  5497. 2496
  5498. File
  5499. Failed
  5500.  
  5501. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\WORD
  5502. 2496
  5503. File
  5504. Failed
  5505.  
  5506. C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\WORD
  5507. 2496
  5508. File
  5509. Failed
  5510.  
  5511. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\WORD
  5512. 2496
  5513. File
  5514. Failed
  5515.  
  5516. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\WORD
  5517. 2496
  5518. File
  5519. Failed
  5520.  
  5521. C:\Windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\WORD
  5522. 2496
  5523. File
  5524. Failed
  5525.  
  5526. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\WORD
  5527. 2496
  5528. File
  5529. Failed
  5530.  
  5531. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\WORD
  5532. 2496
  5533. File
  5534. Failed
  5535.  
  5536. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\WORD
  5537. 2496
  5538. File
  5539. Failed
  5540.  
  5541. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\WORD
  5542. 2496
  5543. File
  5544. Failed
  5545.  
  5546. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\WORD
  5547. 2496
  5548. File
  5549. Failed
  5550.  
  5551. C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\WORD
  5552. 2496
  5553. File
  5554. Failed
  5555.  
  5556. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\WORD
  5557. 2496
  5558. File
  5559. Failed
  5560.  
  5561. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\WORD
  5562. 2496
  5563. File
  5564. Failed
  5565.  
  5566. C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\WORD
  5567. 2496
  5568. File
  5569. Failed
  5570.  
  5571. C:\Users\Administrator\AppData\Local\Microsoft\WORD
  5572. 2496
  5573. File
  5574. Failed
  5575.  
  5576. C:\Users\Administrator\AppData\Local\Microsoft\WORD
  5577. 2496
  5578. File
  5579. Failed
  5580.  
  5581. C:\Users\Administrator\AppData\Local\Microsoft\WORD
  5582. 2496
  5583. File
  5584. Failed
  5585.  
  5586. C:\Program Files (x86)\OFFICE
  5587. 2496
  5588. File
  5589. Failed
  5590.  
  5591. C:\Program Files (x86)\OFFICE
  5592. 2496
  5593. File
  5594. Failed
  5595.  
  5596. C:\Program Files (x86)\OFFICE
  5597. 2496
  5598. File
  5599. Failed
  5600.  
  5601. C:\ProgramData\OFFICE
  5602. 2496
  5603. File
  5604. Failed
  5605.  
  5606. C:\ProgramData\OFFICE
  5607. 2496
  5608. 194 Repeated items skipped
  5609. File
  5610. Failed
  5611.  
  5612. C:\Users\Administrator\AppData\Roaming\THUNDERBIRD
  5613. 2496
  5614. File
  5615. Failed
  5616.  
  5617. C:\Windows\SysWOW64\config\systemprofile\AppData\Local\THUNDERBIRD
  5618. 2496
  5619. Ransom
  5620.  
  5621. C:\879Og-_pkqaf2\amP_xSZKYA.ppt
  5622. MD5: 95ab09d5a9f07e4f2020694693f4c49f
  5623.  
  5624. Malicious Alert
  5625. Ransomware
  5626.  
  5627. Message: Ransomware Activity
  5628.  
  5629. Malicious Alert
  5630. Misc Anom
  5631.  
  5632. Message: Ransomware Activity
  5633.  
  5634. Malicious Alert
  5635. Malware Family
  5636.  
  5637. Message: Possible Cerber Ransomware
  5638.  
  5639. 46 Repeated items skipped
  5640. Ransom
  5641.  
  5642. C:\Users\Administrator\Desktop\CauBKp.xls
  5643. MD5: d4b52d613fcb000acbd28e945491d74a
  5644.  
  5645. Ransom
  5646.  
  5647. C:\Users\Administrator\Desktop\cMycc.ppt
  5648. MD5: 5d914f08246857cb29501f61a2e08d27
  5649.  
  5650. File
  5651. Created
  5652.  
  5653. C:\Users\Administrator\Desktop\_HELP_HELP_HELP_AHSQ_.hta
  5654. 2496
  5655. Malicious Alert
  5656. Misc Anom
  5657.  
  5658. Message: Ransomware Indicator
  5659.  
  5660. 185 Repeated items skipped
  5661. File
  5662. Failed
  5663.  
  5664. C:\Windows\SysWOW64\wbem\NTDSAPI.DLL
  5665. 2460
  5666. Wmiquery
  5667.  
  5668. Imagepath: C:\Windows\SysWOW64\mshta.exe
  5669. 2460
  5670. Codeinjection
  5671. Create process suspended section mapped code injection
  5672.  
  5673. Source: C:\Windows\System32\svchost.exe
  5674. Target: C:\Users\Administrator\AppData\Local\Temp\user.php.exe
  5675.  
  5676. 764
  5677. 2496
  5678.  
  5679. Malicious Alert
  5680. Code Injection Tracking
  5681.  
  5682. Message: Code injection detected
  5683.  
  5684. 23 Repeated items skipped
  5685. Regkey
  5686. Deleteval
  5687.  
  5688. \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersi
  5689. on\Internet Settings\"AutoDetect"
  5690. 2460
  5691. Regkey
  5692. Setval
  5693.  
  5694. \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Windows\CurrentVersi
  5695. on\Internet Settings\Connections\"SavedLegacySettings" = 46 00 00 00 59 00 00 00 09 00 00 00 0d 0
  5696. 0 00 00 31 30 2e 30 2e 30 2e 32 3a 38 30 38 30 00 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 00
  5697. 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 0a 00 00 42 00
  5698. 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0
  5699. 0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  5700. 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  5701. 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  5702. 2460
  5703. Network
  5704. Dns Query
  5705.  
  5706. Protocol Type: udp Qtype: Host Address Hostname: api.blockcypher.com
  5707. Imagepath: c:\Windows\SysWOW64\mshta.exe
  5708. 2460
  5709. Malicious Alert
  5710. Network Activity
  5711.  
  5712. Message: Network outbound communication attempted
  5713.  
  5714. 11 Repeated items skipped
  5715. Regkey
  5716. Setval
  5717.  
  5718. \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Speech\AudioOutput\T
  5719. okenEnums\MMAudioOut\{0.0.0.00000000}.{9e0f448a-ac7c-43cf-b219-1800ab593ddc}\Attributes\"Vendor"
  5720. = Microsoft
  5721. 2496
  5722. Regkey
  5723. Setval
  5724.  
  5725. \REGISTRY\USER\S-1-5-21-2529703413-2662079939-3113469119-500\Software\Microsoft\Speech\AudioOutput\T
  5726. okenEnums\MMAudioOut\{0.0.0.00000000}.{9e0f448a-ac7c-43cf-b219-1800ab593ddc}\Attributes\"Technolo
  5727. gy" = MMSys
  5728. 2496
  5729. Network
  5730. Dns Query
  5731.  
  5732. Protocol Type: udp Qtype: Host Address Hostname: bitaps.com
  5733. Imagepath: c:\Windows\SysWOW64\mshta.exe
  5734. 2460
  5735. Malicious Alert
  5736. DGA Activity
  5737.  
  5738. Message: Suspicious Network Activity
  5739.  
  5740. 44 Repeated items skipped
  5741. API Call
  5742.  
  5743. API Name: GetComputerNameExW Address: 0x6e6738b7
  5744. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  5745. 2496
  5746. API Call
  5747.  
  5748. API Name: GetSystemDirectoryA Address: 0x0040bf9e
  5749. Params: [0x18f900, 260]
  5750. Imagepath: C:\Users\Administrator\AppData\Local\Temp\user.php.exe DLL Name: kernel32.dll
  5751. 2496
  5752. Process
  5753. Opened
  5754.  
  5755. Source: C:\Users\Administrator\AppData\Local\Temp\user.php.exe
  5756. Target: C:\Windows\explorer.exe
  5757.  
  5758. 2496
  5759. 1676
  5760.  
  5761. Malicious Alert
  5762. Process Based Anomaly
  5763.  
  5764. Message: Duplicate handle acquired on Windows process
  5765.  
  5766. 24 Repeated items skipped
  5767. Regkey
  5768. Queryvalue
  5769.  
  5770. \REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName\"ComputerName"
  5771. 2768
  5772. Process
  5773. Terminated
  5774.  
  5775. C:\Windows\SysWOW64\PING.EXE
  5776. Parentname: C:\Windows\SysWOW64\cmd.exe
  5777. Command Line: N/A
  5778. 2768 2228
  5779. File
  5780. Delete
  5781.  
  5782. C:\Users\Administrator\AppData\Local\Temp\user.php.exe
  5783. MD5: aa8b8c39317f733d389d30db2fed1def
  5784. SHA1: 5ba7443d6c0c0a5cf59316e0d3b3defba8c57bc8
  5785. 2228 275476
  5786. Malicious Alert
  5787. Self Delete
  5788.  
  5789. Message: Root process deleted
  5790.  
  5791. Malicious Alert
  5792. Self Delete
  5793.  
  5794. Message: Self deletion using batch file
  5795.  
  5796. Malicious Alert
  5797. Misc Anom
  5798.  
  5799. Message: Suspicious Code Injection
  5800.  
  5801. Process
  5802. Terminated
  5803.  
  5804. C:\Windows\SysWOW64\cmd.exe
  5805. Parentname: C:\Users\ADMINI~1\AppData\Local\Temp\user.php.exe
  5806. Command Line: N/A
  5807. 2228 2496
  5808. Malicious Alert
  5809. Generic Anomalous Activity
  5810.  
  5811. Message: Process Opening explorer
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement