Threat Analysis Report: Hash Values File Details Environment
Threat Analysis Report: Hash Values File Details Environment
   SHA-256 Hash
                                      F114827BC079CF5A923F7E3AD74EF399AEDF0225D23EA7039A3DD68866664340
   Identifier
Microsoft Windows 7 Professional Service Pack 1 (build 7601, version 6.1.7601), 64-bit
Hide environment
Behavior Classification
Behavior Severity
Modified time attribute of the specified file after its creation ⬤ 2 - Low
Security Solution / Mechanism bypass, termination and removal, Anti Debugging, VM Detection ⬤ 2 - Low
                                                                                              ⬤ 1-
     Obtained user's logon name
                                                                                              Informational
Spreading ⬤ 2 - Low
                                                                                              ⬤ 1-
     Read data from a handle opened on previous URL's request
                                                                                              Informational
Networking ⬤ 2 - Low
                                                                                          ⬤ 1-
    Read data from a handle opened on previous URL's request
                                                                                          Informational
                                                                                          ⬤ 1-
    Queried for information related to data transfer size limits
                                                                                          Informational
                                                                                          ⬤ 1-
    Cracks a URL into its component parts
                                                                                          Informational
Connected Sites: 10
                                                                           Unverified
   98.124.253.210                                         20480                             ---                ---                     ---
                                                                           Risk
                                                                           Unknown
   WIN-AUPGCV3CTSS                                        80                                ---                ---                     ---
                                                                           Risk
                                                                           Minimal
   YAMANASHI-JYUJIN.JP                                    80                                Fashion/Beauty     Productivity            Purchasing
                                                                           Risk
                                                                           Medium
   YAMANASHI-JYUJIN.JP/JHGCD476334?                       80                                PUPs               Security                Risk/Fraud/Crime
                                                                           Risk
Processes Analyzed
Timeline Activity
FL-674681.vbs
                    0                   3             6               9                12            15   18   21
                                                                              Offset in seconds
                          Registry
  00:00:000                                 HKLM\Software\Microsoft\Windows Script Host\Settings
                        Opened
                          Registry
  00:00:000                                 HKCU\Software\Microsoft\Windows Script Host\Settings
                        Opened
                           Registry
  00:00:016                                 HKLM\Software\Microsoft\Windows Script Host\Settings
                        Created
                           Registry
  00:00:016                                 HKCU\Software\Microsoft\Windows Script Host\Settings
                        Created
                           File
  00:00:016             Operations,         Retrieved the full path for the module
                        miscellaneous
                                            d22f25
                           Thread
  00:00:016
                        Created
                           Registry         HKCR\VBSFile\ScriptEngine
  00:00:032
            Read            Default
              Registry
00:00:032                   HKCR\VBSFile\ScriptEngine
            Opened
              Registry
00:00:032                   HKCR\.vbs
            Opened
               Registry     HKCR\.vbs
00:00:032
            Read            Default
                            C:\bfzpaudfpy\266c0929-6165-4669-9237-ebf1f5d56fcc.vbs
              Files         Read
00:00:032
            Opened          8000000
                            {6C736DB1-BD94-11D0-8A23-00AA00B58E10}
               Process
00:00:032
            Created
              Memory
00:00:032                   Created a file that can be used for memory mapping
            Mapped Files
                            {B54F3741-5B07-11CF-A4B0-00AA004A55E8}
               Process
00:00:032
            Created
               File
00:00:047   Operations,     Obtained the path of the Windows system directory
            miscellaneous
                            {06290BD1-48AA-11D2-8432-006008C3FBFC}
               Process
00:00:079
            Created
                            {00000323-0000-0000-C000-000000000046}
               Process
00:00:094
            Created
               File
00:00:157   Operations,     Searched a directory for the name: C:\Users\ADMINI~1
            miscellaneous
               File
00:00:157   Operations,     Searched a directory for the name: C:\Users
            miscellaneous
               File
00:00:157   Operations,     Retrieved the path of the directory designated for temporary files
            miscellaneous
               File
00:00:157   Operations,     Obtained a set of FAT file system attributes for a file or directory
            miscellaneous
              Registry
00:00:172                   HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
            Opened
              Registry
00:00:172                   HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
            Opened
              Registry
00:00:172                   HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
            Opened
               Registry
00:00:172   Opened          HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
              Registry
00:00:172                   HKCU\Software\Policies
            Opened
              Registry
00:00:172                   HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl
            Opened
              Registry
00:00:172                   HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
            Opened
              Registry
00:00:172                   HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
            Opened
              Registry
00:00:172                   HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
            Opened
              Registry
00:00:172                   HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl
            Opened
              Registry
00:00:172                   HKLM\Software
            Opened
              Registry
00:00:172                   HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl
            Opened
              Registry
00:00:172                   HKLM\Software\Policies\Microsoft\Internet Explorer
            Opened
              Registry
00:00:172                   HKLM\Software\Policies
            Opened
              Registry
00:00:172                   HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
            Opened
              Registry
00:00:172                   HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl
            Opened
               Process
00:00:172   Operations,     Opened the access token associated with a process
            miscellaneous
               Process
                            Deactivated the activation context corresponding to the specified cookie
00:00:172   Operations,
            miscellaneous
               File
00:00:172   Operations,     Obtained path of the folder from its CLSID
            miscellaneous
               Registry
00:00:172                   HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
            Created
              Registry
00:00:172                   HKCU\Software
            Opened
              Registry
00:00:188                   HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
            Opened
              Registry
00:00:188                   HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
            Opened
               Process
00:00:204   Operations,     Set a waiting mode until a specified object is in the signaled state or the time-out interval elapses
            miscellaneous
                            C:\Users\Administrator\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
               Files        Read & Write
00:00:204
            Created         10000000
                            C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
               Files        Read & Write
00:00:204
            Created         10000000
              Memory
00:00:204                   Opened a named file-mapping object
            Mapped Files
               File
00:00:204   Operations,     Set the date and time of a file or directory
            miscellaneous
              Registry
00:00:219                   HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\ietld
            Opened
                            HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
               Registry
00:00:219                   Cache\MSHist012021012020210121
            Read
                            CacheRepair
                            HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
               Registry
00:00:219                   Cache\MSHist012021012020210121
            Read
                            CachePrefix
                            HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
               Registry
00:00:219                   Cache\MSHist012021012020210121
            Read
                            CachePath
                            HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
               Registry
00:00:219                   Cache\MSHist012021012020210121
            Read
                            CacheOptions
                            HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
               Registry
00:00:219                   Cache\MSHist012021012020210121
            Read
                            CacheLimit
              Registry      HKCU\Software\Microsoft\Internet
00:00:219
            Opened          Explorer\Main\FeatureControl\RETRY_HEADERONLYPOST_ONCONNECTIONRESET
              Registry
00:00:219                   HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache
            Opened
              Registry
00:00:219                   HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\PrivacIE:
            Opened
              Registry
00:00:219                   HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\feedplat
            Opened
00:00:219 Others Expanded environment-variable strings and replace them with the values defined for the current use
00:00:219 Others Initialized a critical section object and set the spin count for the critical section
              Registry    HKLM\Software\Microsoft\Internet
00:00:219
            Opened        Explorer\Main\FeatureControl\RETRY_HEADERONLYPOST_ONCONNECTIONRESET
              Registry    HKCU\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_SKIP_POST_RETRY_ON_INTERNETWRITEFILE_KB895954
              Registry    HKLM\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_COMPAT_USE_CONNECTION_BASED_NEGOTIATE_AUTH_KB2151543
              Registry
00:00:235                 HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BUFFERBREAKING_818408
            Opened
              Registry    HKLM\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_ALLOW_LONG_INTERNATIONAL_FILENAMES
              Registry    HKLM\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_ENABLE_PASSPORT_SESSION_STORE_KB948608
              Registry
00:00:235                 HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
            Opened
              Registry
00:00:235                 HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
            Opened
              Registry    HKCU\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK
              Registry    HKCU\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_DISALLOW_NULL_IN_RESPONSE_HEADERS
              Registry    HKCU\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_EXCLUDE_INVALID_CLIENT_CERT_KB929477
              Registry    HKCU\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_FIX_CHUNKED_PROXY_SCRIPT_DOWNLOAD_KB843289
              Registry    HKCU\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_PERMIT_CACHE_FOR_AUTHENTICATED_FTP_KB910274
              Registry    HKCU\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_RELEASE_KEYS_ON_UNLOAD_KB975619
              Registry    HKLM\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_DISABLE_NOTIFY_UNVERIFIED_SPN_KB2385266
              Registry    HKCU\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_USE_CNAME_FOR_SPN_KB911149
              Registry    HKCU\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_USE_UTF8_FOR_BASIC_AUTH_KB967545
              Registry    HKLM\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_EXCLUDE_INVALID_CLIENT_CERT_KB929477
              Registry    HKLM\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_FIX_CHUNKED_PROXY_SCRIPT_DOWNLOAD_KB843289
              Registry    HKLM\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_PERMIT_CACHE_FOR_AUTHENTICATED_FTP_KB910274
              Registry    HKLM\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_RELEASE_KEYS_ON_UNLOAD_KB975619
              Registry
00:00:235                 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
            Opened
              Registry
00:00:235                 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
            Opened
              Registry
00:00:235   Opened        HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
              Registry    HKCU\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_ALLOW_LONG_INTERNATIONAL_FILENAMES
              Registry
00:00:235                 HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BUFFERBREAKING_818408
            Opened
              Registry
00:00:235                 HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DIGEST_NO_EXTRAS_IN_URI
            Opened
              Registry    HKCU\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_COMPAT_USE_CONNECTION_BASED_NEGOTIATE_AUTH_KB2151543
              Registry
00:00:235                 HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DIGEST_NO_EXTRAS_IN_URI
            Opened
              Registry    HKCU\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_DISABLE_NOTIFY_UNVERIFIED_SPN_KB2385266
              Registry    HKLM\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_SKIP_POST_RETRY_ON_INTERNETWRITEFILE_KB895954
              Registry    HKLM\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_USE_CNAME_FOR_SPN_KB911149
               Registry   HKLM\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_USE_UTF8_FOR_BASIC_AUTH_KB967545
              Registry    HKLM\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_DISALLOW_NULL_IN_RESPONSE_HEADERS
              Registry    HKLM\Software\Microsoft\Internet
00:00:235
            Opened        Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK
              Registry
00:00:235                 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
            Opened
              Registry
00:00:235                 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
            Opened
              Registry    HKLM\Software\Microsoft\Internet
00:00:250
            Opened        Explorer\Main\FeatureControl\FEATURE_SECURITY_FLAG_IGNORE_REVOCATION_KB2275828
               Socket
00:00:250                   Initiated WS2_32 socket DLL
            Activities
              Registry      HKCU\Software\Microsoft\Internet
00:00:250
            Opened          Explorer\Main\FeatureControl\FEATURE_SECURITY_FLAG_IGNORE_REVOCATION_KB2275828
              Registry      HKCU\Software\Microsoft\Internet
00:00:266
            Opened          Explorer\Main\FeatureControl\FEATURE_RETURN_FAILED_CONNECT_CONTENT_KB942615
              Registry
00:00:266                   HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad
            Opened
              Registry      HKLM\Software\Microsoft\Internet
00:00:282
            Opened          Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE
              Registry      HKCU\Software\Microsoft\Internet
00:00:282
            Opened          Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE
              Registry      HKLM\Software\Microsoft\Internet
00:00:282
            Opened          Explorer\Main\FeatureControl\FEATURE_RETURN_FAILED_CONNECT_CONTENT_KB942615
               Network
00:00:282   Operations,     Cracked the URL into its component parts: HTTP://HEXACAM.COM/JHGCD476334?
            miscellaneous
               Network
00:00:297   Operations,     Set an Internet option: 5
            miscellaneous
               Network
00:00:297   Operations,     Set an Internet option: 6
            miscellaneous
               Network
00:00:297   Operations,     Set an Internet option: 2
            miscellaneous
               Process
00:00:313   Operations,     Established a connection to the service control manager and open the service control manager database
            miscellaneous
              Process
00:00:313                   Terminated an existing service's handle:sens
            Opened
               Process
00:00:313   Operations,     Obtained the current status of a service
            miscellaneous
                            HKU\S-1-5-21-2969830022-2362906686-2146684197-
               Registry
00:00:329                   500\Software\Microsoft\windows\CurrentVersion\Internet Settings
            Read
                            AutoConfigURL
               Registry     HKLM\System\Setup
00:00:329
            Read            SystemSetupInProgress
              Registry
00:00:329                   HKCR\AutoProxyTypes\Application/x-ns-proxy-autoconfig
            Opened
               Registry     HKU\S-1-5-21-2969830022-2362906686-2146684197-
00:00:329
            Created         500\Software\Microsoft\windows\CurrentVersion\Internet Settings
               Registry     HKU\S-1-5-21-2969830022-2362906686-2146684197-
00:00:329
            Created         500\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
                            HKU\S-1-5-21-2969830022-2362906686-2146684197-
               Registry
00:00:329                   500\Software\Microsoft\windows\CurrentVersion\Internet Settings
            Read
                            ProxyEnable
              Registry
00:00:329                   HKCR\AutoProxyTypes
            Opened
              Registry
00:00:329                   HKCR\AutoProxyTypes\Application/x-internet-signup
            Opened
                            HKU\S-1-5-21-2969830022-2362906686-2146684197-
               Registry
00:00:329                   500\Software\Microsoft\windows\CurrentVersion\Internet Settings
            Read
                            ProxyOverride
                            HKU\S-1-5-21-2969830022-2362906686-2146684197-
               Registry
00:00:329                   500\Software\Microsoft\windows\CurrentVersion\Internet Settings
            Read
                            ProxyServer
                            HKU\S-1-5-21-2969830022-2362906686-2146684197-
               Registry
00:00:329                   500\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
            Read
                            DefaultConnectionSettings
                            HKU\S-1-5-21-2969830022-2362906686-2146684197-
               Registry
00:00:329                   500\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
            Read
                            SavedLegacySettings
                            769597be
               Thread
00:00:329
            Created
               Process
00:00:329   Operations,     Opened the access token associated with a thread
            miscellaneous
              DNS
00:00:329                   Translated a host name into an IP address
            Queries
               Socket
00:00:329                   Created a socket
            Activities
               Network
00:00:329   Operations,     Retrieved the Internet connected state of the local system
            miscellaneous
               Network
00:00:329   Operations,     Set an Internet option: 49
            miscellaneous
               Network
00:00:329   Operations,     Set an Internet option: 4a
            miscellaneous
                            HKU\S-1-5-21-2969830022-2362906686-2146684197-
              Registry      500\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections\SavedLegacySettings
00:00:329
            Modified        46
                            REG_BINARY
                            HKU\S-1-5-21-2969830022-2362906686-2146684197-
               Registry
00:00:329                   500\Software\Microsoft\windows\CurrentVersion\Internet Settings
            Deleted
                            ProxyServer
                            HKU\S-1-5-21-2969830022-2362906686-2146684197-
               Registry
00:00:329                   500\Software\Microsoft\windows\CurrentVersion\Internet Settings
            Deleted
                            ProxyOverride
                            HKU\S-1-5-21-2969830022-2362906686-2146684197-
               Registry
00:00:329                   500\Software\Microsoft\windows\CurrentVersion\Internet Settings
            Deleted
                            AutoConfigURL
              Registry      HKU\S-1-5-21-2969830022-2362906686-2146684197-
00:00:329
            Opened          500\Software\Microsoft\windows\CurrentVersion\Internet Settings
              Registry
00:00:329                   HKU\S-1-5-21-2969830022-2362906686-2146684197-500
            Opened
              Registry
00:00:329                   HKLM\System\Setup
            Opened
               Registry     HKCR\AutoProxyTypes\Application/x-ns-proxy-autoconfig
00:00:329
            Read            Flags
               Registry     HKCR\AutoProxyTypes\Application/x-ns-proxy-autoconfig
00:00:329
            Read            FileExtensions
               Registry     HKCR\AutoProxyTypes\Application/x-ns-proxy-autoconfig
00:00:329
            Read            Default
                            HKU\S-1-5-21-2969830022-2362906686-2146684197-
              Registry      500\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable
00:00:329
            Modified        0
                            REG_DWORD
               Registry     HKCR\AutoProxyTypes\Application/x-internet-signup
00:00:329
            Read            Default
               Registry     HKCR\AutoProxyTypes\Application/x-internet-signup
00:00:329   Read            DllFile
               Registry     HKCR\AutoProxyTypes\Application/x-internet-signup
00:00:329
            Read            FileExtensions
               Registry     HKCR\AutoProxyTypes\Application/x-internet-signup
00:00:329
            Read            Flags
               Registry     HKCR\AutoProxyTypes\Application/x-ns-proxy-autoconfig
00:00:329
            Read            DllFile
               Socket
00:00:360                   IP:127.0.0.1, Port:8938
            Activities
               Socket
00:00:360                   IP:127.0.0.1, Port:0
            Activities
               Network      Initialized the WinINet functions, Agent name: mozilla/4.0 (compatible; msie 7.0; windows nt 6.1; wow64;
00:00:360   Operations,     trident/4.0; slcc2; .net clr 2.0.50727; .net clr 3.5.30729; .net clr 3.0.30729; media center pc 6.0; infopath.2;
            miscellaneous   .net4.0c; .net4.0e), Access type: PRECONFIG Flags: PORT_NUMBER
              Registry
00:00:360                   HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING
            Opened
              Registry      HKLM\Software\Microsoft\Internet
00:00:360
            Opened          Explorer\Main\FeatureControl\FEATURE_INCLUDE_PORT_IN_SPN_KB908209
               Network
00:00:360   Operations,     Set an Internet option: 2d
            miscellaneous
               Network
00:00:360   Operations,     Opened a HTTP or FTP session for a given site: HEXACAM.COM
            miscellaneous
               Network
00:00:360   Operations,     Set an Internet option: 6c
            miscellaneous
              Registry
00:00:360                   HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING
            Opened
               Socket
00:00:360                   Obtained the local name (address) for a socket
            Activities
              Registry      HKCU\Software\Microsoft\Internet
00:00:360
            Opened          Explorer\Main\FeatureControl\FEATURE_INCLUDE_PORT_IN_SPN_KB908209
               Socket
00:00:375                   Obtained information about a given networking service
            Activities
               Network
00:00:375   Operations,     Verb: get, ObjectName: /jhgcd476334?, Version: , Referer: , Flags: 400000, Context: 73c090
            miscellaneous
               Socket
00:00:391                   Obtained information about next service in order of networking providers
            Activities
               Process
00:00:391   Operations,     Initialized COM library for the current thread and set it in the concurrency mode
            miscellaneous
               Process
                            Decremented a thread's suspend count
00:00:391   Operations,
            miscellaneous
               Thread       7695e44f
00:00:391   Created
00:00:391 Others Obtained the current system date and time in in Coordinated Universal Time (UTC) format
               Network
00:00:407   Operations,     Set an Internet option: 64
            miscellaneous
               Network
00:00:407   Operations,     Set an Internet option: 56
            miscellaneous
               Network
00:00:407   Operations,     Set an Internet option: 44
            miscellaneous
               Network
00:00:407   Operations,     Set an Internet option: 41
            miscellaneous
               Network
00:00:407   Operations,     Set an Internet option: 3e
            miscellaneous
               Network
00:00:407   Operations,     Set an Internet option: 3a
            miscellaneous
               Network
00:00:407   Operations,     Set an Internet option: 58
            miscellaneous
               Network
00:00:407   Operations,     Set an Internet option: 65
            miscellaneous
               Network
00:00:407   Operations,     Set an Internet option: 66
            miscellaneous
               Network
00:00:407   Operations,     Headers: , HeaderLength: 0, Optional: , OptionalLength: 0
            miscellaneous
              DNS
00:00:422                 Translated a host name WIN-AUPGCV3CTSS into an IP address
            Queries
                          {DCB00C01-570F-4A9B-8D69-199FDBA5723B}
               Process
00:00:422
            Created
                          {A47979D2-C419-11D9-A5B4-001185AD2B89}
               Process
00:00:422
            Created
                          {0000032A-0000-0000-C000-000000000046}
               Process
00:00:422
            Created
              DNS
00:03:046                 Translated a host name WPAD into an IP address
            Queries
                          HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\52-54-00-bc-78-
              Registry    23\WpadDecisionReason
00:11:484
            Modified      1
                          REG_DWORD
                          HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{CC771B05-B3AC-42A3-AA57-
              Registry    C69F699B075A}\WpadDecisionReason
00:11:484
            Modified      1
                          REG_DWORD
                          HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\52-54-00-bc-78-
              Registry    23\WpadDecisionTime
00:11:484
            Modified      820B3020
                          REG_BINARY
                          HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{CC771B05-B3AC-42A3-AA57-
              Registry    C69F699B075A}\WpadDecision
00:11:484
            Modified      3
                          REG_DWORD
                          HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{CC771B05-B3AC-42A3-AA57-
              Registry    C69F699B075A}\WpadDecisionTime
00:11:484
            Modified      820B3020
                          REG_BINARY
                          HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{CC771B05-B3AC-42A3-AA57-
              Registry    C69F699B075A}\WpadNetworkName
00:11:484
            Modified      Network 2
                          REG_SZ
              Registry
00:11:484                 HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\52-54-00-bc-78-23
            Opened
                          HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\52-54-00-bc-78-
              Registry    23\WpadDecision
00:11:484
            Modified      3
                          REG_DWORD
                          HKU\S-1-5-21-2969830022-2362906686-2146684197-
              Registry    500\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections\DefaultConnectionSettings
00:11:500
            Modified      46
                          REG_BINARY
                          HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\WpadLastNetwork
              Registry
00:11:500                 {CC771B05-B3AC-42A3-AA57-C69F699B075A}
            Modified
                          REG_SZ
              DNS
00:11:515                 Translated a host name HEXACAM.COM into an IP address
            Queries
               Socket
00:21:625   Activities      IP:98.124.253.210, Port:20480
               Socket
00:21:625                   Controlled the I/O mode of the newly created socket
            Activities
               Socket
00:21:625                   Converted a short value from TCP/IP network byte order to host byte order
            Activities
               Socket
00:21:625                   Converted a short value from host to TCP/IP network byte order
            Activities
               Socket
00:21:625                   IP:0.0.0.0, Port:0
            Activities
               Socket
00:21:625                   Received data from a connected or bound socket
            Activities
               Socket
00:21:625                   Sent data on a connected socket
            Activities
                            HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{CC771B05-B3AC-42A3-AA57-
              Registry      C69F699B075A}\WpadDecision
00:22:047
            Modified        0
                            REG_DWORD
               Network
00:22:047   Operations,     Retrieved header information associated with the HTTP request
            miscellaneous
               Registry
00:22:047                   HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\52-54-00-bc-78-23
            Created
                            HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{CC771B05-B3AC-42A3-AA57-
               Registry
00:22:047                   C69F699B075A}\52-54-00-bc-78-23
            Read
               Socket
00:22:047                   Closed the socket
            Activities
                            HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{CC771B05-B3AC-42A3-AA57-
              Registry      C69F699B075A}\WpadDecisionTime
00:22:047
            Modified        88596A50
                            REG_BINARY
00:22:062 Files Read Reads data from a handle opened by the InternetOpenUrl, FtpOpenFile, or HttpOpenRequest function
               Network
00:22:062   Operations,     Verb: get, ObjectName: /jhgcd476334?, Version: , Referer: , Flags: 400000, Context: 7503b0
            miscellaneous
               Network
00:22:062   Operations,     Cracked the URL into its component parts: HTTP://ALUCMUHENDISLIK.COM/JHGCD476334?
            miscellaneous
                            HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\52-54-00-bc-78-
              Registry      23\WpadDecisionTime
00:22:062
            Modified        88596A50
                            REG_BINARY
                            HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\52-54-00-bc-78-
              Registry      23\WpadDecision
00:22:062
            Modified        0
                            REG_DWORD
               Network
00:22:062   Operations,     Opened a HTTP or FTP session for a given site: ALUCMUHENDISLIK.COM
            miscellaneous
              DNS
00:22:079                   Translated a host name ALUCMUHENDISLIK.COM into an IP address
            Queries
               Socket
00:22:437                   IP:185.216.113.80, Port:20480
            Activities
                          DNS
  00:22:985                                   Translated a host name WWW.ALUCMUHENDISLIK.COM.TR into an IP address
                        Queries
                          DNS
  00:22:985                                   Translated a host name YAMANASHI-JYUJIN.JP into an IP address
                        Queries
                           Network
  00:22:985             Operations,           Verb: get, ObjectName: /jhgcd476334?, Version: , Referer: , Flags: 400000, Context: 76db20
                        miscellaneous
                                              {7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}
                           Process
  00:22:985
                        Created
                           Network
  00:22:985             Operations,           Opened a HTTP or FTP session for a given site: YAMANASHI-JYUJIN.JP
                        miscellaneous
                           Network
  00:22:985             Operations,           Cracked the URL into its component parts: HTTP://YAMANASHI-JYUJIN.JP/JHGCD476334?
                        miscellaneous
                             Process
  00:23:079                                   Ended itself and all of its threads
                        killed
Engine Analysis
YARA
Custom Rules
Sandbox ⬤ 2 - Low
FL-674681.vbs
  Run-Time Dlls: 15
  advapi32.dll
comctl32.dll
dhcpcsvc.dll
dnsapi
iphlpapi.dll
iphlpapi
kernel32.dll
normaliz.dll
ole32.dll
  oleaut32.dll
  rasapi32.dll
sensapi.dll
shell32.dll
urlmon.dll
ws2_32
File Operations: 21
Files Created
                                                                                                       Read &
  C:\Users\Administrator\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat                                      10000000
                                                                                                       Write
                                                                                                       Read &
  C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\index.dat                                                10000000
                                                                                                       Write
                                                                                                       Read &
  C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat                                             10000000
                                                                                                       Write
Files Opened
Files Modified
                                                                                                                          Destination
  Source File                                                                                                                                 Written
                                                                                                                          File/Write
Files Read
C:\bfzpaudfpy\266c0929-6165-4669-9237-ebf1f5d56fcc.vbs
Reads data from a handle opened by the InternetOpenUrl, FtpOpenFile, or HttpOpenRequest function
Other
Registry Created
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\52-54-00-bc-78-23
HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{CC771B05-B3AC-42A3-AA57-C69F699B075A}
HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{CC771B05-B3AC-42A3-AA57-C69F699B075A}\52-54-00-bc-78-23
HKU\S-1-5-21-2969830022-2362906686-2146684197-500\Software\Microsoft\windows\CurrentVersion\Internet Settings
HKU\S-1-5-21-2969830022-2362906686-2146684197-500\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
Registry Opened
HKCR\.vbs
HKCR\AutoProxyTypes
HKCR\AutoProxyTypes\Application/x-internet-signup
HKCR\AutoProxyTypes\Application/x-ns-proxy-autoconfig
HKCR\VBSFile\ScriptEngine
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
HKCU\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
HKCU\Software
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_LONG_INTERNATIONAL_FILENAMES
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BUFFERBREAKING_818408
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_COMPAT_USE_CONNECTION_BASED_NEGOTIATE_AUTH_KB2151543
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DIGEST_NO_EXTRAS_IN_URI
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_NOTIFY_UNVERIFIED_SPN_KB2385266
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISALLOW_NULL_IN_RESPONSE_HEADERS
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_EXCLUDE_INVALID_CLIENT_CERT_KB929477
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FIX_CHUNKED_PROXY_SCRIPT_DOWNLOAD_KB843289
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INCLUDE_PORT_IN_SPN_KB908209
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PERMIT_CACHE_FOR_AUTHENTICATED_FTP_KB910274
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RELEASE_KEYS_ON_UNLOAD_KB975619
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RETURN_FAILED_CONNECT_CONTENT_KB942615
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITY_FLAG_IGNORE_REVOCATION_KB2275828
  HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SKIP_POST_RETRY_ON_INTERNETWRITEFILE_KB895954
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_CNAME_FOR_SPN_KB911149
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_UTF8_FOR_BASIC_AUTH_KB967545
HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\RETRY_HEADERONLYPOST_ONCONNECTIONRESET
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad
HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\52-54-00-bc-78-23
HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{CC771B05-B3AC-42A3-AA57-C69F699B075A}
HKCU\Software\Policies
HKCU\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl
HKCU\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
HKLM\Software
HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl
HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ALLOW_LONG_INTERNATIONAL_FILENAMES
HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BUFFERBREAKING_818408
HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_COMPAT_USE_CONNECTION_BASED_NEGOTIATE_AUTH_KB2151543
HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DIGEST_NO_EXTRAS_IN_URI
HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_NOTIFY_UNVERIFIED_SPN_KB2385266
HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISABLE_UNICODE_HANDLE_CLOSING_CALLBACK
HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_DISALLOW_NULL_IN_RESPONSE_HEADERS
HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_PASSPORT_SESSION_STORE_KB948608
HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_EXCLUDE_INVALID_CLIENT_CERT_KB929477
HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_FIX_CHUNKED_PROXY_SCRIPT_DOWNLOAD_KB843289
HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_HTTP_USERNAME_PASSWORD_DISABLE
HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_INCLUDE_PORT_IN_SPN_KB908209
HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING
HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_PERMIT_CACHE_FOR_AUTHENTICATED_FTP_KB910274
HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RELEASE_KEYS_ON_UNLOAD_KB975619
HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_RETURN_FAILED_CONNECT_CONTENT_KB942615
  HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SECURITY_FLAG_IGNORE_REVOCATION_KB2275828
HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_SKIP_POST_RETRY_ON_INTERNETWRITEFILE_KB895954
HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_CNAME_FOR_SPN_KB911149
HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_USE_UTF8_FOR_BASIC_AUTH_KB967545
HKLM\Software\Microsoft\Internet Explorer\Main\FeatureControl\RETRY_HEADERONLYPOST_ONCONNECTIONRESET
HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache
HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
HKLM\Software\Policies
HKLM\Software\Policies\Microsoft\Internet Explorer
HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl
HKLM\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings
HKLM\System\Setup
HKU\S-1-5-21-2969830022-2362906686-2146684197-500
HKU\S-1-5-21-2969830022-2362906686-2146684197-500\Software\Microsoft\windows\CurrentVersion\Internet Settings
Registry Deleted
Key Value
Registry Modified
  HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\52-54-00-bc-
                                                                                                0                       REG_DWORD
  78-23\WpadDecision
  HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\52-54-00-bc-
                                                                                                3                       REG_DWORD
  78-23\WpadDecision
  HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\52-54-00-bc-
                                                                                                1                       REG_DWORD
  78-23\WpadDecisionReason
  HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\52-54-00-bc-
                                                                                                820B3020                REG_BINARY
  78-23\WpadDecisionTime
  HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\52-54-00-bc-
                                                                                                88596A50                REG_BINARY
  78-23\WpadDecisionTime
                                                                                                {CC771B05-B3AC-
  HKCU\Software\Microsoft\windows\CurrentVersion\Internet
                                                                                                42A3-AA57-              REG_SZ
  Settings\Wpad\WpadLastNetwork
                                                                                                C69F699B075A}
  HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{CC771B05-
                                                                                                0                       REG_DWORD
  B3AC-42A3-AA57-C69F699B075A}\WpadDecision
  HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{CC771B05-
  B3AC-42A3-AA57-C69F699B075A}\WpadDecision                                                     3                       REG_DWORD
  HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{CC771B05-
                                                                                                1                       REG_DWORD
  B3AC-42A3-AA57-C69F699B075A}\WpadDecisionReason
  HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{CC771B05-
                                                                                                820B3020                REG_BINARY
  B3AC-42A3-AA57-C69F699B075A}\WpadDecisionTime
  HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{CC771B05-
                                                                                     88596A50                     REG_BINARY
  B3AC-42A3-AA57-C69F699B075A}\WpadDecisionTime
  HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{CC771B05-
                                                                                     Network 2                    REG_SZ
  B3AC-42A3-AA57-C69F699B075A}\WpadNetworkName
  HKU\S-1-5-21-2969830022-2362906686-2146684197-
  500\Software\Microsoft\windows\CurrentVersion\Internet                             46                           REG_BINARY
  Settings\Connections\DefaultConnectionSettings
  HKU\S-1-5-21-2969830022-2362906686-2146684197-
  500\Software\Microsoft\windows\CurrentVersion\Internet                             46                           REG_BINARY
  Settings\Connections\SavedLegacySettings
  HKU\S-1-5-21-2969830022-2362906686-2146684197-
                                                                                     0                            REG_DWORD
  500\Software\Microsoft\windows\CurrentVersion\Internet Settings\ProxyEnable
Registry Read
HKCR\.vbs Default
HKCR\AutoProxyTypes\Application/x-internet-signup Default
HKCR\AutoProxyTypes\Application/x-internet-signup DllFile
HKCR\AutoProxyTypes\Application/x-internet-signup FileExtensions
HKCR\AutoProxyTypes\Application/x-internet-signup Flags
HKCR\AutoProxyTypes\Application/x-ns-proxy-autoconfig Default
HKCR\AutoProxyTypes\Application/x-ns-proxy-autoconfig DllFile
HKCR\AutoProxyTypes\Application/x-ns-proxy-autoconfig FileExtensions
HKCR\AutoProxyTypes\Application/x-ns-proxy-autoconfig Flags
HKCR\VBSFile\ScriptEngine Default
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
                                                                                        CacheLimit
Cache\MSHist012021012020210121
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
                                                                                        CacheOptions
Cache\MSHist012021012020210121
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
                                                                                        CachePath
Cache\MSHist012021012020210121
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
                                                                                        CachePrefix
Cache\MSHist012021012020210121
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
                                                                                        CacheRepair
Cache\MSHist012021012020210121
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
                                                                                        CacheLimit
Cache\PrivacIE:
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
                                                                                        CacheOptions
Cache\PrivacIE:
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
Cache\PrivacIE:                                                                         CachePath
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
                                                                                        CachePrefix
Cache\PrivacIE:
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
                                                                                        CacheRepair
Cache\PrivacIE:
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
Cache\feedplat
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
                                                                                        CacheLimit
Cache\feedplat
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
                                                                                        CacheOptions
Cache\feedplat
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
                                                                                        CachePath
Cache\feedplat
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
                                                                                        CachePrefix
Cache\feedplat
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
                                                                                        CacheRepair
Cache\feedplat
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
                                                                                        CacheLimit
Cache\ietld
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
                                                                                        CacheOptions
Cache\ietld
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
                                                                                        CachePath
Cache\ietld
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
                                                                                        CachePrefix
Cache\ietld
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible
                                                                                        CacheRepair
Cache\ietld
  HKCU\Software\Microsoft\windows\CurrentVersion\Internet Settings\Wpad\{CC771B05-B3AC-42A3-
  AA57-C69F699B075A}\52-54-00-bc-78-23
HKLM\System\Setup SystemSetupInProgress
  HKU\S-1-5-21-2969830022-2362906686-2146684197-
                                                                                               AutoConfigURL
  500\Software\Microsoft\windows\CurrentVersion\Internet Settings
  HKU\S-1-5-21-2969830022-2362906686-2146684197-
                                                                                               ProxyEnable
  500\Software\Microsoft\windows\CurrentVersion\Internet Settings
  HKU\S-1-5-21-2969830022-2362906686-2146684197-
                                                                                               ProxyOverride
  500\Software\Microsoft\windows\CurrentVersion\Internet Settings
  HKU\S-1-5-21-2969830022-2362906686-2146684197-
                                                                                               ProxyServer
  500\Software\Microsoft\windows\CurrentVersion\Internet Settings
  HKU\S-1-5-21-2969830022-2362906686-2146684197-
                                                                                               DefaultConnectionSettings
  500\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
  HKU\S-1-5-21-2969830022-2362906686-2146684197-
                                                                                               SavedLegacySettings
  500\Software\Microsoft\windows\CurrentVersion\Internet Settings\Connections
Process Operations: 22
Process Created
{0000032A-0000-0000-C000-000000000046}
{06290BD1-48AA-11D2-8432-006008C3FBFC}
{6C736DB1-BD94-11D0-8A23-00AA00B58E10}
{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}
{A47979D2-C419-11D9-A5B4-001185AD2B89}
{B54F3741-5B07-11CF-A4B0-00AA004A55E8}
{DCB00C01-570F-4A9B-8D69-199FDBA5723B}
Process Opened
Process killed
Thread Created
769597be
7695e44f
d22f25
Other
Established a connection to the service control manager and open the service control manager database
Initialized COM library for the current thread and set it in the concurrency mode
Set a waiting mode until a specified object is in the signaled state or the time-out interval elapses
Network Operations: 52
DNS Queries
Socket Activities
Created a socket
IP:0.0.0.0, Port:0
IP:127.0.0.1, Port:0
IP:127.0.0.1, Port:8938
IP:185.216.113.80, Port:20480
IP:98.124.253.210, Port:20480
Other
  Initialized the WinINet functions, Agent name: mozilla/4.0 (compatible; msie 7.0; windows nt 6.1; wow64; trident/4.0; slcc2; .net clr 2.0.50727;
  .net clr 3.5.30729; .net clr 3.0.30729; media center pc 6.0; infopath.2; .net4.0c; .net4.0e), Access type: PRECONFIG Flags: PORT_NUMBER
Verb: get, ObjectName: /jhgcd476334?, Version: , Referer: , Flags: 400000, Context: 73c090
Verb: get, ObjectName: /jhgcd476334?, Version: , Referer: , Flags: 400000, Context: 7503b0
Verb: get, ObjectName: /jhgcd476334?, Version: , Referer: , Flags: 400000, Context: 76db20
Other Operations: 6
Others
Expanded environment-variable strings and replace them with the values defined for the current use
Initialized a critical section object and set the spin count for the critical section
Obtained the current system date and time in in Coordinated Universal Time (UTC) format