Malware Log Analysis

shared / dead_vegetable
content copied

content

Start:: CloseProcesses: DeleteKey: HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{490DAA44-7D30-428D-B437-32398D6890D5} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2976900799-3423729617-4255589462-1003\Products\44AAD09403D7D8244B732393D886095D DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\6999EC0E4108D4641A7C1BC37D80ECE0 Unlock: C:\WINDOWS\Installer\57ab4578.msi StartPowerShell: # This snippet uses Sysinternals Sigcheck to upload file on VirusTotal. # Change the line containing the string "INSERTFILEPATHHERE" to the desired filepath # --- # It displays the following: entropy, file hashes, catalog name & signing chain, VirusTotal scan results and link to it. # It is also able to traverse symbolic links and directory junctions. # --- # NOTE: If the file is not known prior, it gets uploaded to VirusTotal and the result will be available in a few minutes. # You can search up the report by visiting the URL "https://www.virustotal.com/gui/file/<SHA256>" $TempDir = [System.IO.Path]::GetTempPath() $ZipPath = Join-Path $TempDir "SigcheckFRST.zip" $ExtractPath = Join-Path $TempDir "SigcheckFRST" Invoke-WebRequest -Uri "https://download.sysinternals.com/files/Sigcheck.zip" -OutFile $ZipPath -UseBasicParsing if (Test-Path $ExtractPath) { Remove-Item $ExtractPath -Recurse -Force } Expand-Archive -Path $ZipPath -DestinationPath $ExtractPath -Force $SigcheckExe = Join-Path $ExtractPath "sigcheck.exe" if (Test-Path $SigcheckExe) { $psi = New-Object System.Diagnostics.ProcessStartInfo $psi.FileName = $SigcheckExe $psi.Arguments = '-accepteula -a -h -i -m -l -vt -vs -nobanner "C:\WINDOWS\Installer\57ab4578.msi"' $psi.RedirectStandardOutput = $true $psi.StandardOutputEncoding = [System.Text.Encoding]::Unicode $psi.UseShellExecute = $false $psi.CreateNoWindow = $true $p = [System.Diagnostics.Process]::Start($psi) $output = $p.StandardOutput.ReadToEnd() $p.WaitForExit() Write-Output $output } else { Write-Host "Error: Sigcheck does not exist" } Remove-Item $ZipPath -Force EndPowerShell: C:\WINDOWS\Installer\57ab4578.msi DeleteKey: HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{6A59175F-21C3-4E1A-9945-8F7459BF70E8} DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-2976900799-3423729617-4255589462-1003\Products\F57195A63C12A1E49954F84795FB078E DeleteKey: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\1F306914E5BB2DD4A868E1A8D8EB0EAD Unlock: C:\WINDOWS\Installer\57ab456f.msi C:\WINDOWS\Installer\57ab456f.msi FirewallRules: [UDP Query User{DCF7C8BF-F603-4559-8808-49425D3A0E26}D:\games\nah\dddd\the arrogant kaiju princess and the detective servant v1.06\the detective servant.exe] => (Block) D:\games\nah\dddd\the arrogant kaiju princess and the detective servant v1.06\the detective servant.exe => No File FirewallRules: [TCP Query User{8CBE0AF1-BB4D-45ED-AA60-FEAE52ADC940}D:\games\nah\dddd\the arrogant kaiju princess and the detective servant v1.06\the detective servant.exe] => (Block) D:\games\nah\dddd\the arrogant kaiju princess and the detective servant v1.06\the detective servant.exe => No File FirewallRules: [{01C1FC11-3D42-4607-BC55-29A65F42CB5B}] => (Allow) C:\Users\yxy20\AppData\Roaming\Tencent\TIM\STemp\SetupEx0\QQSetupEx.exe => No File FirewallRules: [TCP Query User{25A81A00-C7DE-451F-A9CD-9029D1A373AF}E:\games\othergames\transformers - war for cybertron\binaries\twfc.exe] => (Allow) E:\games\othergames\transformers - war for cybertron\binaries\twfc.exe => No File FirewallRules: [UDP Query User{272B1504-3191-4917-99B0-20770EDFC72A}E:\games\othergames\transformers - war for cybertron\binaries\twfc.exe] => (Allow) E:\games\othergames\transformers - war for cybertron\binaries\twfc.exe => No File FirewallRules: [TCP Query User{8AA0FF7E-7BEB-4870-BF67-A8AC8F57C84A}E:\games\nahh\dzone\hs2\[utility] kkmanager\standaloneupdater.exe] => (Allow) E:\games\nahh\dzone\hs2\[utility] kkmanager\standaloneupdater.exe => No File FirewallRules: [UDP Query User{EDB1CE9D-F50E-4C76-8D9F-89CC4CBD837D}E:\games\nahh\dzone\hs2\[utility] kkmanager\standaloneupdater.exe] => (Allow) E:\games\nahh\dzone\hs2\[utility] kkmanager\standaloneupdater.exe => No File FirewallRules: [TCP Query User{EB17BE39-AF36-42D2-83B3-4D6D62372F1B}C:\program files (x86)\java\jdk-1.8\bin\java.exe] => (Allow) C:\program files (x86)\java\jdk-1.8\bin\java.exe => No File FirewallRules: [UDP Query User{CF09158C-F41D-4769-9420-AC22DD5BD14C}C:\program files (x86)\java\jdk-1.8\bin\java.exe] => (Allow) C:\program files (x86)\java\jdk-1.8\bin\java.exe => No File FirewallRules: [TCP Query User{8E274EEA-185D-4648-971E-089A6F464DAA}D:\ide\anaconda\python.exe] => (Allow) D:\ide\anaconda\python.exe => No File FirewallRules: [UDP Query User{82F9E126-D326-4962-A8B2-467D4BD1269F}D:\ide\anaconda\python.exe] => (Allow) D:\ide\anaconda\python.exe => No File HKLM-x32\...\RunOnce: [InnoSetupRegFile.0000000001] => "C:\WINDOWS\is-TD8IA.exe" /REG /REGSVRMODE (No File) Task: {ADC8825B-E373-4C47-A2D9-AAA64E7F69B7} - System32\Tasks\EOSv3 Scheduler onLogOn => C:\Users\yxy20\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe LOGON (No File) Task: {91B719E7-D8BC-44C3-9683-EEBA4511F603} - System32\Tasks\EOSv3 Scheduler onTime => C:\Users\yxy20\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe SCHED (No File) FF Plugin: @videolan.org/vlc,version=3.0.21 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [No File] FF Plugin: @videolan.org/vlc,version=3.0.23 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [No File] HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiSpyware] Restriction <==== ATTENTION HKLM\SOFTWARE\Microsoft\Windows Defender: [DisableAntiVirus] Restriction <==== ATTENTION GroupPolicy: Restriction ? <==== ATTENTION Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION EmptyTemp: End::