Extracted/injected images (may contain unpacked executables)
Download #1
Match: inject_thread
Match: network_tcp_listen
Match: win_files_operation
Match: Str_Win32_Internet_API
Match: DebuggerCheck__GlobalFlags
Match: DebuggerCheck__QueryInfo
Match: DebuggerHiding__Thread
Match: DebuggerHiding__Active
Match: ThreadControl__Context
Match: SEH__vectored
Match: anti_dbg
Match: disable_dep
Extracted/injected images (may contain unpacked executables)
Download #1
Download #2
Match: inject_thread
Match: network_tcp_listen
Match: network_smtp_dotNet
Match: keylogger
Match: win_files_operation
Match: Str_Win32_Internet_API
Match: DebuggerCheck__GlobalFlags
Match: DebuggerCheck__QueryInfo
Match: DebuggerHiding__Thread
Match: DebuggerHiding__Active
Match: ThreadControl__Context
Match: SEH__vectored
Match: anti_dbg
Match: disable_dep
Match: win_hook
Extracted/injected images (may contain unpacked executables)
Download #1
Download #2
Match: infoStealer_emailClients_Zero
Match: inject_thread
Match: create_service
Match: create_com_service
Match: network_udp_sock
Match: network_tcp_listen
Match: network_smtp_dotNet
Match: network_p2p_win
Match: network_http
Match: network_dropper
Match: network_ftp
Match: network_tcp_socket
Match: network_dns
Match: network_dga
Match: escalate_priv
Match: screenshot
Match: dyndns
Match: keylogger
Match: cred_local
Match: sniff_audio
Match: cred_ff
Match: migrate_apc
Match: spreading_file
Match: spreading_share
Match: rat_vnc
Match: win_mutex
Match: win_registry
Match: win_token
Match: win_private_profile
Match: win_files_operation
Match: Str_Win32_Winsock2_Library
Match: Str_Win32_Wininet_Library
Match: Str_Win32_Internet_API
Match: Str_Win32_Http_API
Match: infoStealer_ftpClients_Zero
Match: Win_Trojan_agentTesla_Zero
Match: DebuggerCheck__GlobalFlags
Match: DebuggerCheck__QueryInfo
Match: DebuggerCheck__RemoteAPI
Match: DebuggerHiding__Thread
Match: DebuggerHiding__Active
Match: DebuggerException__ConsoleCtrl
Match: DebuggerException__SetConsoleCtrl
Match: ThreadControl__Context
Match: SEH__vectored
Match: Check_Dlls
Match: anti_dbg
Match: antisb_threatExpert
Match: disable_dep
Match: win_hook
Match: infoStealer_browser_Zero
Match: Chrome_User_Data_Check_Zero
Match: infoStealer_DownloadManagement_Zero
http://WrqCET.com http://go2.microsoft.com/fwlink/?LinkId=131738 https://www.theonionrouter.com/dist.torproject.org/torbrowser/9.5.3/tor-win32-0.4.3.6.zip%tordir%%hash%%torpass%https://www.theonionrouter.com/dist.torproject.org/torbrowser/ http://127.0.0.1 https://api.telegram.org/bot1620445910:AAF2v81NoINJsu_XXnpGet1YDm-NxnznaIE/sendDocumentdocument---------------------------x http://beta.visualstudio.net/net/sdk/feedback.asp http://DynDns.comDynDNS
Extracted/injected images (may contain unpacked executables)
Download #1
Match: inject_thread
Match: create_service
Match: create_com_service
Match: network_udp_sock
Match: network_tcp_listen
Match: network_smtp_dotNet
Match: network_p2p_win
Match: network_http
Match: network_dropper
Match: network_ftp
Match: network_tcp_socket
Match: network_dns
Match: network_dga
Match: escalate_priv
Match: screenshot
Match: keylogger
Match: cred_local
Match: sniff_audio
Match: migrate_apc
Match: spreading_file
Match: spreading_share
Match: win_mutex
Match: win_registry
Match: win_token
Match: win_private_profile
Match: win_files_operation
Match: Str_Win32_Winsock2_Library
Match: Str_Win32_Wininet_Library
Match: Str_Win32_Internet_API
Match: Str_Win32_Http_API
Match: DebuggerCheck__QueryInfo
Match: DebuggerCheck__RemoteAPI
Match: DebuggerHiding__Thread
Match: DebuggerHiding__Active
Match: DebuggerException__ConsoleCtrl
Match: DebuggerException__SetConsoleCtrl
Match: ThreadControl__Context
Match: SEH__vectored
Match: Check_Dlls
Match: Check_Qemu_Description
Match: Check_Qemu_DeviceMap
Match: Check_VBox_Description
Match: Check_VBox_DeviceMap
Match: Check_VBox_Guest_Additions
Match: Check_VBox_VideoDrivers
Match: Check_VMWare_DeviceMap
Match: Check_VmTools
Match: WMI_VM_Detect
Match: anti_dbg
Match: antisb_threatExpert
Match: disable_dep
Match: win_hook
Match: vmdetect_misc
http://go2.microsoft.com/fwlink/?LinkId=131738 http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0 http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0 http://microsoft.com0 http://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0 http://www.microsoft.com/pkiops/docs/primarycps.htm0 http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0 http://beta.visualstudio.net/net/sdk/feedback.asp http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0 http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0 http://www.microsoft.com/PKI/docs/CPS/default.htm0 http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0 http://ns.adobe.com/xap/1.0/ http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0a
Extracted/injected images (may contain unpacked executables)
Download #1
Match: inject_thread
Match: create_service
Match: create_com_service
Match: network_udp_sock
Match: network_tcp_listen
Match: network_smtp_dotNet
Match: network_p2p_win
Match: network_http
Match: network_dropper
Match: network_ftp
Match: network_tcp_socket
Match: network_dns
Match: network_dga
Match: escalate_priv
Match: screenshot
Match: keylogger
Match: cred_local
Match: sniff_audio
Match: migrate_apc
Match: spreading_file
Match: spreading_share
Match: win_mutex
Match: win_registry
Match: win_token
Match: win_private_profile
Match: win_files_operation
Match: Str_Win32_Winsock2_Library
Match: Str_Win32_Wininet_Library
Match: Str_Win32_Internet_API
Match: Str_Win32_Http_API
Match: DebuggerCheck__QueryInfo
Match: DebuggerCheck__RemoteAPI
Match: DebuggerHiding__Thread
Match: DebuggerHiding__Active
Match: DebuggerException__ConsoleCtrl
Match: DebuggerException__SetConsoleCtrl
Match: ThreadControl__Context
Match: SEH__vectored
Match: Check_Dlls
Match: Check_Qemu_Description
Match: Check_Qemu_DeviceMap
Match: Check_VBox_Description
Match: Check_VBox_DeviceMap
Match: Check_VBox_Guest_Additions
Match: Check_VBox_VideoDrivers
Match: Check_VMWare_DeviceMap
Match: Check_VmTools
Match: WMI_VM_Detect
Match: anti_dbg
Match: antisb_threatExpert
Match: disable_dep
Match: win_hook
Match: vmdetect_misc
http://go2.microsoft.com/fwlink/?LinkId=131738 http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0 http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0 http://microsoft.com0 http://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0 http://www.microsoft.com/pkiops/docs/primarycps.htm0 http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0 http://beta.visualstudio.net/net/sdk/feedback.asp http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0 http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0 http://www.microsoft.com/PKI/docs/CPS/default.htm0 http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0 http://ns.adobe.com/xap/1.0/ http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0a