Match: DebuggerCheck__GlobalFlags
Match: DebuggerCheck__QueryInfo
Match: DebuggerHiding__Thread
Match: DebuggerHiding__Active
Match: ThreadControl__Context
Match: SEH__vectored
Match: disable_dep
Extracted/injected images (may contain unpacked executables)
Download #1
Download #2
Match: inject_thread
Match: create_service
Match: network_udp_sock
Match: network_tcp_listen
Match: network_p2p_win
Match: network_http
Match: network_dropper
Match: network_ftp
Match: network_tcp_socket
Match: network_dns
Match: network_dga
Match: escalate_priv
Match: screenshot
Match: keylogger
Match: cred_local
Match: sniff_audio
Match: migrate_apc
Match: spreading_share
Match: win_mutex
Match: win_registry
Match: win_token
Match: win_private_profile
Match: win_files_operation
Match: Str_Win32_Winsock2_Library
Match: Str_Win32_Wininet_Library
Match: Str_Win32_Internet_API
Match: Str_Win32_Http_API
Match: DebuggerCheck__GlobalFlags
Match: DebuggerCheck__QueryInfo
Match: DebuggerCheck__RemoteAPI
Match: DebuggerHiding__Thread
Match: DebuggerHiding__Active
Match: DebuggerException__ConsoleCtrl
Match: DebuggerException__SetConsoleCtrl
Match: ThreadControl__Context
Match: SEH__vectored
Match: Check_Dlls
Match: anti_dbg
Match: antisb_threatExpert
Match: disable_dep
Match: win_hook
Extracted/injected images (may contain unpacked executables)
Download #1
Match: inject_thread
Match: create_service
Match: create_com_service
Match: network_udp_sock
Match: network_tcp_listen
Match: network_smtp_dotNet
Match: network_p2p_win
Match: network_http
Match: network_dropper
Match: network_ftp
Match: network_tcp_socket
Match: network_dns
Match: network_dga
Match: escalate_priv
Match: screenshot
Match: keylogger
Match: cred_local
Match: sniff_audio
Match: migrate_apc
Match: spreading_file
Match: spreading_share
Match: win_mutex
Match: win_registry
Match: win_token
Match: win_private_profile
Match: win_files_operation
Match: Str_Win32_Winsock2_Library
Match: Str_Win32_Wininet_Library
Match: Str_Win32_Internet_API
Match: Str_Win32_Http_API
Match: DebuggerCheck__GlobalFlags
Match: DebuggerCheck__QueryInfo
Match: DebuggerCheck__RemoteAPI
Match: DebuggerHiding__Thread
Match: DebuggerHiding__Active
Match: DebuggerException__ConsoleCtrl
Match: DebuggerException__SetConsoleCtrl
Match: ThreadControl__Context
Match: SEH__vectored
Match: Check_Dlls
Match: Check_Qemu_Description
Match: Check_Qemu_DeviceMap
Match: Check_VBox_Description
Match: Check_VBox_DeviceMap
Match: Check_VBox_Guest_Additions
Match: Check_VBox_VideoDrivers
Match: Check_VMWare_DeviceMap
Match: Check_VmTools
Match: WMI_VM_Detect
Match: anti_dbg
Match: antisb_threatExpert
Match: disable_dep
Match: win_hook
Match: vmdetect_misc
http://www.microsoft.com/pki/certs/CSPCA.crt0 http://beta.visualstudio.net/net/sdk/feedback.asp http://www.microsoft.com/pki/certs/tspca.crt0 http://microsoft.com0 http://ns.adobe.com/xap/1.0/