Extracted/injected images (may contain unpacked executables)
Download #1
Match: Network_TCP_Socket
Match: ScreenShot
Match: Network_DNS
Match: Code_injection
Match: Generic_PWS_Memory_Zero
Match: Sniff_Audio
Match: KeyLogger
Match: Network_Downloader
Match: Escalate_priviledges
Match: DebuggerCheck__GlobalFlags
Match: DebuggerCheck__QueryInfo
Match: DebuggerHiding__Thread
Match: DebuggerHiding__Active
Match: ThreadControl__Context
Match: SEH__vectored
Match: anti_dbg
Match: disable_dep
Match: Persistence
Match: infoStealer_emailClients_Zero
http://microsoft.com/
Extracted/injected images (may contain unpacked executables)
Download #1
Download #2
Match: Network_TCP_Socket
Match: ScreenShot
Match: Network_DNS
Match: Code_injection
Match: Generic_PWS_Memory_Zero
Match: Sniff_Audio
Match: KeyLogger
Match: Network_Downloader
Match: Escalate_priviledges
Match: DebuggerCheck__GlobalFlags
Match: DebuggerCheck__QueryInfo
Match: DebuggerHiding__Thread
Match: DebuggerHiding__Active
Match: ThreadControl__Context
Match: SEH__vectored
Match: anti_dbg
Match: disable_dep
Match: Persistence
Match: infoStealer_emailClients_Zero
http://microsoft.com/