File: efc8b691673b3d16ccca5ebaf77423382a8ca3291d9b3fb413ee62bc5a40ceb4

Metadata
File name:a2.exe
File type:PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
File size:384675 bytes
Analysis date:Analyzed on January 6 2017 15:06:29
MD5:f2ad1c2f3829a2c5a789a9bac51d6f09
SHA1:98f973c1bc8bf49497d4deee3d99f9f6d0dc8206
SHA256:efc8b691673b3d16ccca5ebaf77423382a8ca3291d9b3fb413ee62bc5a40ceb4
SHA512:697ad5e0396d775b2c8198b7b70bd5060521c5ded556d0376a1ac4df1284a9189a67f837bda6fef25801e8055b1bbd8818e3cb50e3bfa9761c291e33ee36a620
SSDEEP:6144:h3gz6/XqisoJUQIYAHBKZ5cZc1VdAY8/QhIN7Vx6e092aY3AlLHZde:k6/3snOMQZ5cQdA9N7VxFabHZ4
IMPHASH:511bfa0b1ffb75835ce5dc0bb55ea065
Authentihash:91b305d4408e5b627dbdcca779ad21a3ac91aa497b12ec964527fd004c284ab1
Related resources
APTNotes
Cyber threat intelligence reports associated with efc8b691673b3d16ccca5ebaf77423382a8ca3291d9b3fb413ee62bc5a40ceb4.
Loading...
Hosts
Hosts the malware sample communicates with.
99.194.175.148
61.149.6.114
1.140.188.26
124.170.241.80
62.167.1.126
159.245.239.116
16.224.131.180
71.98.122.63
175.101.15.10
87.146.17.61
170.184.154.47
85.200.217.8
117.235.19.220
187.233.144.117
36.12.50.151
75.227.47.230
136.75.28.252
55.153.140.209
217.56.242.117
149.90.210.95
49.253.130.75
116.135.218.248
24.81.84.18
154.14.28.38
61.221.132.117
5.238.121.204
210.109.96.220
215.44.53.216
110.68.233.234
5.85.61.163
203.179.75.189
213.53.67.2
153.133.235.110
218.110.56.7
202.57.4.26
103.196.173.105
46.255.225.235
79.96.251.138
66.44.32.166
6.79.168.158
50.154.51.70
126.182.42.164
104.16.26.216
180.66.102.202
18.228.55.73
188.225.110.97
15.112.45.84
176.105.128.86
78.104.237.70
149.33.201.23
28.192.103.131
152.14.112.179
200.172.192.23
36.93.224.209
189.7.65.12
67.48.195.149
40.207.26.152
74.188.189.59
28.203.167.139
158.173.76.49
52.212.169.33
162.195.82.109
51.126.40.5
65.254.191.136
196.245.59.79
129.46.247.28
205.163.152.157
47.241.20.185
190.91.239.254
6.104.85.108
72.6.223.57
138.156.113.111
4.90.204.53
116.224.214.70
210.162.72.27
154.207.72.83
191.113.250.3
44.91.78.200
169.20.144.189
179.100.115.72
190.55.190.251
14.136.190.3
146.113.23.127
218.151.85.39
194.199.241.36
165.119.150.2
91.239.77.82
102.31.52.135
172.31.141.74
133.24.240.105
188.244.60.24
79.112.105.12
120.184.74.55
2.241.185.205
223.1.123.214
206.161.207.181
138.245.105.212
112.107.22.105
3.176.46.187
39.163.107.76
161.99.184.98
166.67.100.85
3.24.228.32
12.61.22.51
138.158.248.57
206.130.185.193
190.242.129.107
160.238.175.152
222.216.220.64
181.46.251.220
137.246.232.149
19.63.56.171
147.197.35.89
211.101.6.236
101.172.89.75
199.140.112.33
199.212.64.132
204.157.249.234
218.220.43.93
62.25.216.11
42.107.132.35
207.213.129.206
189.174.44.255
166.219.104.163
70.201.47.194
54.135.248.168
57.162.175.196
210.214.144.117
170.75.62.189
138.144.75.43
104.27.41.235
14.253.220.188
161.70.162.133
215.153.127.228
18.131.185.183
67.204.245.138
174.7.27.195
55.174.106.126
97.163.209.253
128.152.22.77
207.54.87.179
69.252.6.99
140.92.228.167
98.98.10.120
199.68.65.225
20.26.105.74
222.39.221.101
159.105.17.158
63.137.94.213
68.142.247.196
165.72.209.14
177.14.26.34
130.168.24.2
18.182.167.114
222.215.190.233
78.232.5.106
33.16.181.212
105.198.143.224
157.153.24.248
74.190.131.45
112.243.95.230
2.233.245.140
167.31.163.34
99.32.169.170
116.201.116.115
44.160.48.36
222.240.38.22
176.164.82.164
210.109.222.161
170.76.60.180
16.97.239.100
164.203.71.124
19.157.43.113
24.215.14.133
19.15.250.162
111.214.113.44
26.216.115.85
69.188.16.135
168.142.123.235
55.211.162.112
190.167.223.250
44.162.107.193
53.189.19.117
82.222.117.27
5.135.104.207
219.95.200.158
136.63.240.219
201.220.120.232
82.138.114.236
3.190.222.38
12.187.133.228
97.151.82.42
19.78.145.71
220.19.145.1
154.155.179.136
63.189.2.99
203.121.9.166
65.148.155.110
180.174.95.90
209.152.79.93
154.20.73.7
44.187.89.154
185.117.72.90
162.73.74.146
218.72.179.229
146.207.174.62
70.184.140.157
216.160.28.150
56.122.130.121
145.66.6.120
170.244.97.169
36.105.94.96
166.173.127.174
86.44.43.48
108.74.217.128
149.33.201.58
148.50.102.152
215.161.55.25
70.36.81.170
2.11.141.162
50.50.10.224
113.35.106.217
222.202.206.91
110.155.130.225
203.110.156.81
85.130.72.125
135.162.212.15
187.181.182.145
159.207.106.28
59.30.54.157
50.181.52.81
131.56.122.88
131.162.215.70
136.128.128.68
203.170.182.98
109.27.125.222
87.61.225.200
173.84.170.32
77.167.139.168
176.136.136.211
203.201.71.4
42.245.166.226
181.99.189.25
90.105.156.191
175.3.25.68
41.185.226.248
55.193.14.38
109.8.236.22
82.20.138.41
205.220.61.147
99.200.86.137
135.91.106.232
45.199.202.72
166.202.187.155
223.71.8.215
131.239.146.97
132.253.14.136
138.235.86.74
68.234.176.190
3.38.238.33
165.72.193.149
116.31.129.209
74.98.27.43
37.18.46.20
132.135.190.167
161.94.120.125
155.150.93.217
118.7.139.46
37.236.86.254
62.134.158.202
99.108.49.225
176.26.42.218
205.152.179.198
67.217.76.140
110.92.119.51
110.24.196.216
5.40.27.251
62.194.48.217
85.207.185.158
76.74.28.49
134.243.40.140
130.65.226.235
115.253.218.8
170.164.68.193
208.250.21.110
2.224.27.128
22.148.237.108
25.250.26.13
35.206.41.30
20.117.13.147
195.138.239.50
81.130.155.53
122.176.235.153
146.61.78.77
5.92.173.185
79.11.111.52
100.53.252.201
115.152.170.142
70.150.49.223
59.61.135.36
33.241.142.139
61.233.205.213
76.205.236.150
122.36.124.55
110.186.16.155
135.142.57.229
199.84.236.249
95.172.241.230
109.217.13.100
118.119.13.41
48.180.76.105
108.59.62.93
73.210.34.204
165.72.205.205
78.163.16.33
171.31.115.146
99.223.10.245
160.186.88.51
6.187.176.239
133.155.116.50
91.202.87.76
202.197.109.237
177.20.173.239
78.177.223.149
207.251.223.228
187.185.155.159
116.186.159.39
58.79.164.183
181.162.3.194
218.88.160.64
72.13.42.78
26.249.85.186
3.246.242.167
4.206.75.22
103.252.66.216
109.185.168.208
183.247.192.200
192.170.231.128
11.189.226.231
205.242.195.27
93.44.36.68
40.197.128.216
153.253.186.253
146.116.65.37
70.96.228.81
160.62.165.189
57.203.15.152
34.157.214.172
126.2.168.64
222.218.244.249
25.202.235.12
35.131.164.147
8.123.183.200
65.110.105.88
199.142.120.92
23.184.71.189
158.49.175.99
204.67.107.113
3.76.129.238
40.40.169.47
183.191.209.112
82.19.251.156
183.120.221.60
54.137.104.94
186.160.200.205
112.71.56.135
133.209.144.149
133.109.91.201
186.198.201.102
198.41.214.183
122.245.202.149
163.250.106.64
117.189.183.165
169.249.163.7
202.170.209.231
HTTP Requests
HTTP requests the malware sample makes.
HostURLUser-Agent
187.233.144.117/Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
187.233.144.117/Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
202.57.4.26/Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
202.57.4.26/csbde866f0/0A 55 73 65 72 2D 41 67 65 6E 74 3A 20 4D 6F 7A [.User-Agent
N/A
N/A
N/A
202.57.4.26/csbde866f0/config/log_off_page.htmMozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
187.233.144.117/Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
165.72.209.14/Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
104.16.26.216/rootr3/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCCwQAAAAAATbpgjldMicrosoft-CryptoAPI/6.1
N/A
N/A
N/A
202.57.4.26/Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
187.233.144.117/Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
202.57.4.26/csbde866f0/0A 55 73 65 72 2D 41 67 65 6E 74 3A 20 4D 6F 7A [.User-Agent
N/A
N/A
N/A
202.57.4.26/csbde866f0/config/log_off_page.htmMozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
104.16.26.216/rootr3/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCCwQAAAAAATbpgjldMicrosoft-CryptoAPI/6.1
N/A
N/A
N/A
104.16.26.216/trustrootsha2g2/ME8wTTBLMEkwRzAJBgUrDgMCGgUABBSU%2FrHEX5r9Wx5XqiVrEJSDn3RN4QQUyGObCGlUwpjI2c3jM7dQXvjJAZsCDkcHsQTG7p3lReTmRmT7Microsoft-CryptoAPI/6.1
N/A
N/A
N/A
198.41.214.183/trustrootsha2g2.crlMicrosoft-CryptoAPI/6.1
N/A
N/A
N/A
165.72.205.205//MEswSTBHMEUwQzAJBgUrDgMCGgUABBQcjxI5GfFtXZh%2FEo1d%2BGc7CzUohwQUHC8PTrm9ToldZGJu3uCjCSkU2x8CCmYHTzQAAgAAF90%3DMicrosoft-CryptoAPI/6.1
N/A
N/A
N/A
165.72.193.149/pki/i3/dpdhl_tls_sha2_i3.crlMicrosoft-CryptoAPI/6.1
N/A
N/A
N/A
104.27.41.235/Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
187.233.144.117/Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
165.72.209.14/Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
104.16.26.216/rootr3/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCCwQAAAAAATbpgjldMicrosoft-CryptoAPI/6.1
N/A
N/A
N/A
202.57.4.26/Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
202.57.4.26/csbde866f0/0A 55 73 65 72 2D 41 67 65 6E 74 3A 20 4D 6F 7A [.User-Agent
N/A
N/A
N/A
202.57.4.26/csbde866f0/config/log_off_page.htmMozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
104.16.26.216/rootr3/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCCwQAAAAAATbpgjldMicrosoft-CryptoAPI/6.1
N/A
N/A
N/A
104.16.26.216/trustrootsha2g2/ME8wTTBLMEkwRzAJBgUrDgMCGgUABBSU%2FrHEX5r9Wx5XqiVrEJSDn3RN4QQUyGObCGlUwpjI2c3jM7dQXvjJAZsCDkcHsQTG7p3lReTmRmT7Microsoft-CryptoAPI/6.1
N/A
N/A
N/A
198.41.214.183/trustrootsha2g2.crlMicrosoft-CryptoAPI/6.1
N/A
N/A
N/A
165.72.205.205//MEswSTBHMEUwQzAJBgUrDgMCGgUABBQcjxI5GfFtXZh%2FEo1d%2BGc7CzUohwQUHC8PTrm9ToldZGJu3uCjCSkU2x8CCmYHTzQAAgAAF90%3DMicrosoft-CryptoAPI/6.1
N/A
N/A
N/A
165.72.193.149/pki/i3/dpdhl_tls_sha2_i3.crlMicrosoft-CryptoAPI/6.1
N/A
N/A
N/A
104.27.41.235/Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
187.233.144.117/Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
165.72.209.14/Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
202.57.4.26/Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
202.57.4.26/csbde866f0/0A 55 73 65 72 2D 41 67 65 6E 74 3A 20 4D 6F 7A [.User-Agent
N/A
N/A
N/A
104.16.26.216/rootr3/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCCwQAAAAAATbpgjldMicrosoft-CryptoAPI/6.1
N/A
N/A
N/A
202.57.4.26/csbde866f0/config/log_off_page.htmMozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
104.27.41.235/Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
187.233.144.117/Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
104.16.26.216/rootr3/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCCwQAAAAAATbpgjldMicrosoft-CryptoAPI/6.1
N/A
N/A
N/A
104.16.26.216/trustrootsha2g2/ME8wTTBLMEkwRzAJBgUrDgMCGgUABBSU%2FrHEX5r9Wx5XqiVrEJSDn3RN4QQUyGObCGlUwpjI2c3jM7dQXvjJAZsCDkcHsQTG7p3lReTmRmT7Microsoft-CryptoAPI/6.1
N/A
N/A
N/A
198.41.214.183/trustrootsha2g2.crlMicrosoft-CryptoAPI/6.1
N/A
N/A
N/A
165.72.205.205//MEswSTBHMEUwQzAJBgUrDgMCGgUABBQcjxI5GfFtXZh%2FEo1d%2BGc7CzUohwQUHC8PTrm9ToldZGJu3uCjCSkU2x8CCmYHTzQAAgAAF90%3DMicrosoft-CryptoAPI/6.1
N/A
N/A
N/A
165.72.193.149/pki/i3/dpdhl_tls_sha2_i3.crlMicrosoft-CryptoAPI/6.1
N/A
N/A
N/A
91.239.77.82/Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
104.27.41.235/Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
187.233.144.117/Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
165.72.209.14/Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
202.57.4.26/Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
202.57.4.26/csbde866f0/0A 55 73 65 72 2D 41 67 65 6E 74 3A 20 4D 6F 7A [.User-Agent
N/A
N/A
N/A
202.57.4.26/csbde866f0/config/log_off_page.htmMozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)
N/A
N/A
N/A
104.16.26.216/rootr3/MEwwSjBIMEYwRDAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCCwQAAAAAATbpgjldMicrosoft-CryptoAPI/6.1
N/A
N/A
N/A
AV Detections
AV detection names associated with the malware sample.
Mutants
Mutants created by the malware sample.
"\Sessions\1\BaseNamedObjects\Local\!PrivacIE!SharedMemory!Mutex"
"\Sessions\1\BaseNamedObjects\Local\ZoneAttributeCacheCounterMutex"
"\Sessions\1\BaseNamedObjects\Local\ZonesCacheCounterMutex"
"\Sessions\1\BaseNamedObjects\Local\ZonesLockedCacheCounterMutex"
"\Sessions\1\BaseNamedObjects\Local\ZonesCounterMutex"
"\Sessions\1\BaseNamedObjects\{C20CD437-BA6D-4ebb-B190-70B43DE3B0F3}"
"\Sessions\1\BaseNamedObjects\_SHuassist.mtx"
"\Sessions\1\BaseNamedObjects\Local\_!MSFTHISTORY!_"
"\Sessions\1\BaseNamedObjects\Local\c:!users!bo7vvsl!appdata!local!microsoft!windows!temporary internet files!content.ie5!"
"\Sessions\1\BaseNamedObjects\Local\c:!users!bo7vvsl!appdata!roaming!microsoft!windows!cookies!"
"\Sessions\1\BaseNamedObjects\Local\c:!users!bo7vvsl!appdata!local!microsoft!windows!history!history.ie5!"
"\Sessions\1\BaseNamedObjects\Local\WininetStartupMutex"
"\Sessions\1\BaseNamedObjects\Local\WininetConnectionMutex"
"\Sessions\1\BaseNamedObjects\Local\WininetProxyRegistryMutex"
"\Sessions\1\BaseNamedObjects\RasPbFile"
"\Sessions\1\BaseNamedObjects\8ED5CFD7E1CE5795"
Registry keys
Registry keys created by the malware sample.
Comments
User comments about efc8b691673b3d16ccca5ebaf77423382a8ca3291d9b3fb413ee62bc5a40ceb4.
NOTICE: We have updated our privacy terms and conditions in accordance to GDPR. By using our site, you acknowledge that you have read and understand our Privacy Policy. Your use of ThreatMiner’s Products and Services is subject to these policies and terms.