Files
Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
C:\Users\user\Desktop\[SOH] CS1.6 Hack v2.exe
|
"C:\Users\user\Desktop\[SOH] CS1.6 Hack v2.exe"
|
||
C:\Windows\System32\conhost.exe
|
C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
|
||
C:\Windows\SysWOW64\cmd.exe
|
C:\Windows\system32\cmd.exe /c color F8
|
||
C:\Windows\SysWOW64\WerFault.exe
|
C:\Windows\SysWOW64\WerFault.exe -u -p 7528 -s 576
|
URLs
Name
|
IP
|
Malicious
|
|
---|---|---|---|
http://upx.sf.net
|
unknown
|
Registry
Path
|
Value
|
Malicious
|
|
---|---|---|---|
\REGISTRY\A\{cec80c4c-1b07-713e-26fa-42f02090e81e}\Root\InventoryApplicationFile\[soh] cs1.6 hack|c17e8b6e71c537a4
|
ProgramId
|
||
\REGISTRY\A\{cec80c4c-1b07-713e-26fa-42f02090e81e}\Root\InventoryApplicationFile\[soh] cs1.6 hack|c17e8b6e71c537a4
|
FileId
|
||
\REGISTRY\A\{cec80c4c-1b07-713e-26fa-42f02090e81e}\Root\InventoryApplicationFile\[soh] cs1.6 hack|c17e8b6e71c537a4
|
LowerCaseLongPath
|
||
\REGISTRY\A\{cec80c4c-1b07-713e-26fa-42f02090e81e}\Root\InventoryApplicationFile\[soh] cs1.6 hack|c17e8b6e71c537a4
|
LongPathHash
|
||
\REGISTRY\A\{cec80c4c-1b07-713e-26fa-42f02090e81e}\Root\InventoryApplicationFile\[soh] cs1.6 hack|c17e8b6e71c537a4
|
Name
|
||
\REGISTRY\A\{cec80c4c-1b07-713e-26fa-42f02090e81e}\Root\InventoryApplicationFile\[soh] cs1.6 hack|c17e8b6e71c537a4
|
OriginalFileName
|
||
\REGISTRY\A\{cec80c4c-1b07-713e-26fa-42f02090e81e}\Root\InventoryApplicationFile\[soh] cs1.6 hack|c17e8b6e71c537a4
|
Publisher
|
||
\REGISTRY\A\{cec80c4c-1b07-713e-26fa-42f02090e81e}\Root\InventoryApplicationFile\[soh] cs1.6 hack|c17e8b6e71c537a4
|
Version
|
||
\REGISTRY\A\{cec80c4c-1b07-713e-26fa-42f02090e81e}\Root\InventoryApplicationFile\[soh] cs1.6 hack|c17e8b6e71c537a4
|
BinFileVersion
|
||
\REGISTRY\A\{cec80c4c-1b07-713e-26fa-42f02090e81e}\Root\InventoryApplicationFile\[soh] cs1.6 hack|c17e8b6e71c537a4
|
BinaryType
|
||
\REGISTRY\A\{cec80c4c-1b07-713e-26fa-42f02090e81e}\Root\InventoryApplicationFile\[soh] cs1.6 hack|c17e8b6e71c537a4
|
ProductName
|
||
\REGISTRY\A\{cec80c4c-1b07-713e-26fa-42f02090e81e}\Root\InventoryApplicationFile\[soh] cs1.6 hack|c17e8b6e71c537a4
|
ProductVersion
|
||
\REGISTRY\A\{cec80c4c-1b07-713e-26fa-42f02090e81e}\Root\InventoryApplicationFile\[soh] cs1.6 hack|c17e8b6e71c537a4
|
LinkDate
|
||
\REGISTRY\A\{cec80c4c-1b07-713e-26fa-42f02090e81e}\Root\InventoryApplicationFile\[soh] cs1.6 hack|c17e8b6e71c537a4
|
BinProductVersion
|
||
\REGISTRY\A\{cec80c4c-1b07-713e-26fa-42f02090e81e}\Root\InventoryApplicationFile\[soh] cs1.6 hack|c17e8b6e71c537a4
|
AppxPackageFullName
|
||
\REGISTRY\A\{cec80c4c-1b07-713e-26fa-42f02090e81e}\Root\InventoryApplicationFile\[soh] cs1.6 hack|c17e8b6e71c537a4
|
AppxPackageRelativeId
|
||
\REGISTRY\A\{cec80c4c-1b07-713e-26fa-42f02090e81e}\Root\InventoryApplicationFile\[soh] cs1.6 hack|c17e8b6e71c537a4
|
Size
|
||
\REGISTRY\A\{cec80c4c-1b07-713e-26fa-42f02090e81e}\Root\InventoryApplicationFile\[soh] cs1.6 hack|c17e8b6e71c537a4
|
Language
|
||
\REGISTRY\A\{cec80c4c-1b07-713e-26fa-42f02090e81e}\Root\InventoryApplicationFile\[soh] cs1.6 hack|c17e8b6e71c537a4
|
Usn
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Token\{67082621-8D18-4333-9C64-10DE93676363}
|
DeviceTicket
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Token\{67082621-8D18-4333-9C64-10DE93676363}
|
DeviceId
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Token\{67082621-8D18-4333-9C64-10DE93676363}
|
ApplicationFlags
|
||
HKEY_CURRENT_USER\SOFTWARE\Microsoft\IdentityCRL\Immersive\production\Property
|
0018000DDABBE6B3
|
There are 13 hidden registries, click here to show them.
Memdumps
There are 51 hidden memdumps, click here to show them.