Match: DebuggerCheck__GlobalFlags
Match: DebuggerCheck__QueryInfo
Match: DebuggerHiding__Thread
Match: DebuggerHiding__Active
Match: ThreadControl__Context
Match: SEH__vectored
Match: disable_dep
Extracted/injected images (may contain unpacked executables)
Download #1
Match: inject_thread
Match: create_service
Match: network_udp_sock
Match: network_tcp_listen
Match: network_p2p_win
Match: network_http
Match: network_dropper
Match: network_ftp
Match: network_tcp_socket
Match: network_dns
Match: network_dga
Match: escalate_priv
Match: screenshot
Match: keylogger
Match: cred_local
Match: sniff_audio
Match: migrate_apc
Match: spreading_share
Match: win_mutex
Match: win_registry
Match: win_token
Match: win_private_profile
Match: win_files_operation
Match: Str_Win32_Winsock2_Library
Match: Str_Win32_Wininet_Library
Match: Str_Win32_Internet_API
Match: Str_Win32_Http_API
Match: DebuggerCheck__GlobalFlags
Match: DebuggerCheck__QueryInfo
Match: DebuggerCheck__RemoteAPI
Match: DebuggerHiding__Thread
Match: DebuggerHiding__Active
Match: DebuggerException__ConsoleCtrl
Match: DebuggerException__SetConsoleCtrl
Match: ThreadControl__Context
Match: SEH__vectored
Match: Check_Dlls
Match: anti_dbg
Match: antisb_threatExpert
Match: disable_dep
Match: win_hook
Extracted/injected images (may contain unpacked executables)
Download #1
Match: inject_thread
Match: create_service
Match: create_com_service
Match: network_udp_sock
Match: network_tcp_listen
Match: network_smtp_dotNet
Match: network_p2p_win
Match: network_http
Match: network_dropper
Match: network_ftp
Match: network_tcp_socket
Match: network_dns
Match: network_dga
Match: escalate_priv
Match: screenshot
Match: keylogger
Match: cred_local
Match: sniff_audio
Match: migrate_apc
Match: spreading_file
Match: spreading_share
Match: win_mutex
Match: win_registry
Match: win_token
Match: win_private_profile
Match: win_files_operation
Match: Str_Win32_Winsock2_Library
Match: Str_Win32_Wininet_Library
Match: Str_Win32_Internet_API
Match: Str_Win32_Http_API
Match: DebuggerCheck__GlobalFlags
Match: DebuggerCheck__QueryInfo
Match: DebuggerCheck__RemoteAPI
Match: DebuggerHiding__Thread
Match: DebuggerHiding__Active
Match: DebuggerException__ConsoleCtrl
Match: DebuggerException__SetConsoleCtrl
Match: ThreadControl__Context
Match: SEH__vectored
Match: Check_Dlls
Match: Check_Qemu_Description
Match: Check_Qemu_DeviceMap
Match: Check_VBox_Description
Match: Check_VBox_DeviceMap
Match: Check_VBox_Guest_Additions
Match: Check_VBox_VideoDrivers
Match: Check_VMWare_DeviceMap
Match: Check_VmTools
Match: WMI_VM_Detect
Match: anti_dbg
Match: antisb_threatExpert
Match: disable_dep
Match: win_hook
Match: vmdetect_misc
http://go2.microsoft.com/fwlink/?LinkId=131738 http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0 http://www.microsoft.com/pki/certs/MicRooCerAut2011_2011_03_22.crt0 http://microsoft.com0 http://www.microsoft.com/pkiops/certs/MicCodSigPCA2011_2011-07-08.crt0 http://www.microsoft.com/pkiops/docs/primarycps.htm0 http://www.microsoft.com/pki/certs/MicCodSigPCA_08-31-2010.crt0 http://beta.visualstudio.net/net/sdk/feedback.asp http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0 http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0 http://www.microsoft.com/PKI/docs/CPS/default.htm0 http://www.microsoft.com/pki/certs/MicrosoftRootCert.crt0 http://ns.adobe.com/xap/1.0/ http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl0a