Extracted/injected images (may contain unpacked executables)
Download #1
Match: DebuggerCheck__GlobalFlags
Match: DebuggerCheck__QueryInfo
Match: DebuggerHiding__Thread
Match: DebuggerHiding__Active
Match: ThreadControl__Context
Match: SEH__vectored
Match: disable_dep
https://docs.microsoft.com/windows/win32/fileio/maximum-file-path-limitation
Extracted/injected images (may contain unpacked executables)
Download #1
Match: Create_Service
Match: Network_TCP_Socket
Match: Network_DGA
Match: Str_Win32_Http_API
Match: ScreenShot
Match: Escalate_priviledges
Match: Generic_PWS_Memory_Zero
Match: DebuggerCheck__GlobalFlags
Match: DebuggerCheck__QueryInfo
Match: DebuggerHiding__Thread
Match: DebuggerHiding__Active
Match: ThreadControl__Context
Match: SEH__vectored
Match: anti_dbg
Match: disable_dep
Match: Str_Win32_Internet_API
http://s.symcb.com/universal-root.crl0 http://crl.globalsign.com/root-r6.crl0G http://crl.globalsign.com/codesigningrootr45.crl0U http://ocsp.verisign.com0 https://www.verisign.com/rpa http://crl.globalsign.com/gsgccr45evcodesignca2020.crl0 http://ns.adobe.com/xap/1.0/sType/ResourceRef http://ocsp2.globalsign.com/rootr606 http://s1.symcb.com/pca3-g5.crl0 http://www.symauth.com/cps0( http://ocsp.globalsign.com/ca/gstsacasha384g40C http://secure.globalsign.com/cacert/codesigningrootr45.crt0A http://crl.globalsign.com/ca/gstsacasha384g4.crl0 http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0 http://s2.symcb.com0 https://d.symcb.com/cps0% http://sv.symcb.com/sv.crl0a http://s.symcd.com06 http://secure.globalsign.com/cacert/gsgccr45evcodesignca2020.crt0? http://crl.verisign.com/pca3-g5.crl04 https://www.globalsign.com/repository/0 http://logo.verisign.com/vslogo.gif04 http://ns.adobe.com/xap/1.0/mm/ http://crl.globalsign.net/root.crl0 https://d.symcb.com/rpa0 https://www.verisign.com/cps0 http://sv.symcb.com/sv.crt0 http://ocsp.globalsign.com/codesigningrootr450F http://sf.symcb.com/sf.crl0a http://ocsp2.globalsign.com/rootr306 http://crl.globalsign.com/root-r3.crl0G http://www.360safe.com0 https://www.globalsign.com/repository/03 https://d.symcb.com/rpa0. http://ocsp.globalsign.com/gsgccr45evcodesignca20200U http://ns.adobe.com/xap/1.0/ http://secure.globalsign.com/cacert/gstsacasha384g4.crt0 http://www.symauth.com/rpa00 http://sf.symcb.com/sf.crt0 https://www.verisign.com/rpa0 http://sv.symcd.com0 http://secure.globalsign.com/cacert/gstimestampingg2.crt0 http://www.openssl.org/support/faq.html http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0( http://crl.globalsign.com/gs/gstimestampingg2.crl0T http://sf.symcd.com0 http://ts-ocsp.ws.symantec.com0
Extracted/injected images (may contain unpacked executables)
Download #1
Download #2
Match: Network_TCP_Socket
Match: ScreenShot
Match: local_credential_Steal
Match: Network_DNS
Match: Code_injection
Match: DebuggerCheck__GlobalFlags
Match: DebuggerCheck__QueryInfo
Match: DebuggerHiding__Thread
Match: DebuggerHiding__Active
Match: ThreadControl__Context
Match: SEH__vectored
Match: anti_dbg
Match: disable_dep
http://www.winimage.com/zLibDll
Extracted/injected images (may contain unpacked executables)
Download #1
Match: DebuggerCheck__GlobalFlags
Match: DebuggerCheck__QueryInfo
Match: DebuggerHiding__Thread
Match: DebuggerHiding__Active
Match: DebuggerException__SetConsoleCtrl
Match: ThreadControl__Context
Match: SEH__vectored
Match: anti_dbg
Match: disable_dep