Meta tags:
Headings (most frequently used words):
redline, using, wednesday, for, tuesday, 2014, analysis, running, blog, is, live, response, apt, ure, october, 2025, january, 26, 2022, december, 2017, august, 12, july, 29, pcap, with, wireshark, screenshots, during, vm, infection, collector, bash, fu, on, xml, data, conclusion, labels, archive, about, me, blogs, like, to, read, followers, total, pageviews, netbios, names, pivoting, and, threat, clustering, who, desktop, group, this, still, alive, 3r4lr, remotely, part,
Text of the page (most frequently used words):
the (136), and (87), for (52), #redline (52), ago (44), this (36), http (34), years (32), com (31), from (30), using (29), blog (27), with (25), data (25), exe (25), host (24), echo (23), about (23), post (22), rem (22), 2014 (21), run (21), prodigymsnteregala (21), not (20), type (20), malware (19), you (19), group (19), are (18), threat (17), www (17), collector (17), remote (17), url (16), security (15), time (15), some (15), tom (15), dpnlobbyg (15), more (14), first (14), windows (14), sysmon (14), java (14), created (13), filename (13), share (13), have (12), that (12), fullpath (12), egrep (12), zuponcic (12), collection (12), upload (12), research (11), here (11), but (11), net (11), 13t22 (11), users (11), appdata (11), w32apifiles (11), agent (11), audits (11), goto (11), posted (10), response (10), running (10), system (10), update (10), analysis (10), user (10), set (10), script (10), copy (10), was (9), can (9), request (9), software (9), org (9), roaming (9), 8xdv3nsaugodpxnrhsahqg (9), persistence (9), kit (9), slides (9), microsoft (8), like (8), many (8), file (8), how (8), been (8), name (8), last (8), version (8), desktop (8), may (8), sizeinbytes (8), xmlns (8), 2001 (8), xmlschema (8), modified (8), w32scripting (8), 47z (8), sourceurl (8), updated (8), also (8), log (8), infected (7), should (7), network (7), via (7), attack (7), what (7), 2022 (7), content (7), hunting (7), registry (7), later (7), currentversion (7), jar (7), remotely (7), just (7), finished (7), cmd (7), tracking (7), pdf (7), well (6), long (6), work (6), soon (6), your (6), one (6), detection (6), 2017 (6), has (6), year (6), april (6), online (6), google (6), read (6), tomu (6), netbios (6), splunk (6), botconf (6), section (6), text (6), detectedcharacteristics (6), keypath (6), username (6), path (6), securityid (6), registryitem (6), h3ihm1txbupdcehrhajicc (6), 7538554d (6), 326909f3 (6), filepath (6), urlhistory (6), lltr9wqwo8sd3vl2rgou0f (6), key (6), get (6), clr (6), class (6), exist (6), still (5), apt (5), quite (5), our (5), incident (5), authority (5), yet (5), call (5), december (5), two (5), over (5), cyber (5), intelligence (5), will (5), changed (5), html (5), activity (5), 2026 (5), names (5), mandiant (5), comments (5), details (5), raw (5), xml (5), w32registryapi (5), tmp (5), 3096987436 (5), 3122932343 (5), 3109395949 (5), 1000 (5), filedownloadhistory (5), dn62zqqu8mwey2us5ofzc8 (5), infection (5), during (5), part (5), addr (5), live (5), scripts (5), sysinternals (5), outputdir (5), end (5), presentation (5), 2018 (5), twitter (5), ips (5), however (4), interested (4), new (4), belajar (4), forex (4), team (4), day (4), certificate (4), find (4), cve (4), write (4), very (4), email (4), out (4), months (4), month (4), under (4), all (4), traffic (4), 2012 (4), infrastructure (4), july (4), listing (4), most (4), june (4), ioc (4), c_apt_ure (4), create (4), check (4), artifacts (4), timeline (4), files (4), none (4), xsi (4), instance (4), xsd (4), uid (4), 14t01 (4), hive (4), persistenceitem (4), string (4), arn9dznmiyqdhnxvugnjzz (4), 0m17 (4), prefetch (4), 483759317 (4), regtext (4), md5sum (4), 115 (4), ext (4), stats (4), cafeefac (4), dec7 (4), 0000 (4), 0001 (4), abcdeffedcba (4), iexplore (4), alloweddomains (4), started (4), any (4), other (4), available (4), dns (4), 30729 (4), net4 (4), there (4), hostname (4), psexec (4), without (4), tools (4), failed (4), please (4), back (4), resources (4), github (4), related (4), 2019 (4), video (4), https (4), collaboration (4), following (3), had (3), since (3), didn (3), quarantine (3), image (3), pemula (3), join (3), internet (3), news (3), project (3), across (3), others (3), into (3), market (3), sys (3), now (3), zero (3), ssh (3), page (3), reading (3), used (3), alive (3), compression (3), three (3), current (3), browser (3), few (3), samples (3), different (3), linux (3), trying (3), funky (3), pigeon (3), annual (3), naked (3), center (3), 2013 (3), exploit (3), latest (3), real (3), average (3), advisories (3), released (3), abuse (3), them (3), days (3), who (3), arrested (3), august (3), 2025 (3), dfir (3), posts (3), much (3), useful (3), than (3), memory (3), use (3), found (3), entropy (3), averagevalue (3), 77262239772402574 (3), 17z (3), hkey_current_user (3), dlls (3), sun (3), 100 (3), toms (3), win7x64 (3), drive (3), hkey_users (3), anlxmyn (3), chn (3), 220 (3), bash (3), process (3), malicious (3), cookie (3), redirection (3), logs (3), list (3), mozilla (3), application (3), niceshop (3), sanctionedmedia (3), familiar (3), another (3), let (3), mkdir (3), audit_ (3), sleep (3), dir (3), starting (3), agent64 (3), agent32 (3), bitness (3), args (3), failure (3), encountered (3), know (3), while (3), ure (3), cert (3), wednesday (3), sharing (3), mails (3), linked (3), report (3), opera1er (3), operation (3), domains (3), connect (3), blogger (2), labs (2), seems (2), something (2), significant (2), md5 (2), strings (2), contagio (2), ahead (2), untuk (2), anda (2), unallocated (2), cymru (2), gmt (2), nicely (2), progress (2), antivirus (2), cash (2), payment (2), only (2), unitedrant (2), did (2), wine (2), beer (2), liquor (2), getting (2), core (2), combines (2), identity (2), vulnerability (2), before (2), tcp (2), 135 (2), verify (2), template (2), local (2), right (2), supported (2), slowloris (2), smb (2), taking (2), dos (2), named (2), metasploit (2), after (2), 8759 (2), decided (2), signature (2), high (2), format (2), avalanche (2), platform (2), common (2), wow (2), roundup (2), extensions (2), firefox (2), stream (2), past (2), zscaler (2), number (2), wild (2), iot (2), operating (2), 2020 (2), home (2), needs (2), figure (2), top (2), stories (2), cybersecurity (2), ransomware (2), talk (2), fact (2), saw (2), disaster (2), recovery (2), changing (2), securosis (2), device (2), idea (2), associated (2), sans (2), 2024 (2), complete (2), blogspot (2), sandbox (2), miming (2), 0158 (2), mhtml (2), their (2), repo (2), threats (2), web (2), cyberesi (2), summit (2), freebsd (2), hear (2), true (2), dancho (2), recently (2), detailed (2), encoding (2), australia (2), teampcp (2), cybercrime (2), march (2), september (2), february (2), january (2), pivoting (2), october (2), archive (2), ponmocup (2), labels (2), cheers (2), next (2), stay (2), tuned (2), feedback (2), love (2), showing (2), opened (2), keys (2), free (2), analyzing (2), easy (2), looking (2), creating (2), numberofsections (2), actualnumberofsections (2), execute (2), 152 (2), 155 (2), sections (2), peakentropy (2), peakcodeentropy (2), 51z (2), reportedlengthinbytes (2), 170 (2), 172 (2), valuename (2), fileitem (2), peinfo (2), executable (2), subsystem (2), baseaddress (2), petimestamp (2), 128 (2), pechecksum (2), pefileraw (2), 129 (2), pefileapi (2), pecomputedapi (2), extraneousbytes (2), detectedanomalies (2), 0m0 (2), locallow (2), deployment (2), cache (2), idx (2), eb4905c2 (2), 603267d1 (2), persistencetype (2), regpath (2), regowner (2), regmodified (2), 101 (2), fileowner (2), filecreated (2), filemodified (2), fileaccessed (2), filechanged (2), devicepath (2), fileextension (2), accessed (2), fileattributes (2), 120 (2), securitytype (2), 123 (2), 105ead6f908f0d8cbab11a0f4408d373 (2), egkyxzdcin (2), jxzfuv (2), searching (2), indicators (2), favicon (2), ico (2), gif (2), numsubkeys (2), numvalues (2), qkejzdj (2), possibly (2), cygwin (2), powerful (2), port (2), binary (2), domain (2), collected (2), suspicious (2), large (2), depending (2), which (2), modules (2), settings (2), compress (2), way (2), investigation (2), see (2), sending (2), fasternation (2), parameter (2), checks (2), client (2), compatible (2), wow64 (2), trident (2), slcc2 (2), 50727 (2), media (2), msie (2), length (2), perrugina (2), sciencehunk (2), bit (2), 210 (2), cname (2), 178 (2), overview (2), wireshark (2), distinct (2), tool (2), writing (2), guide (2), great (2), bird (2), plane (2), tuesday (2), look (2), steps (2), they (2), xcopy (2), off (2), 1_redline_log (2), txt (2), helper (2), bat (2), directory (2), miragent (2), x86 (2), usedefault (2), agentset (2), unsupported (2), pause (2), buildlog (2), usage (2), again (2), published (2), persistent (2), headers (2), ueltschi (2), powershell (2), logging (2), presented (2), gave (2), advanced (2), conference (2), youtube (2), 2016 (2), closed (2), mostly (2), public (2), preliminary (2), orange (2), swift (2), publicly (2), known (2), announcement (2), nervone (2), plain (2), quick (2), want (2), censys (2), rdp (2), tas (2), tgs (2), clusters (2), would (2), services (2), awesome, inc, theme, powered, total, pageviews, followers, mwr, verizon, business, unition, alienvault, srd, crowdstrike, vupen, scansafe, acquired, adding, discussion, views, chambers, veiled, shadows, dw20, dll, 8e187ae152c48099f715af442339c340, size, 44032, ascii, surtr, smoaler, exchange, weekend, fleeting, thought, suppose, realize, sto, endeavors, digital4rensics, word, derived, 17th, century, venetian, quaranta, purpose, separate, restrict, movement, computers, countermeasures, tips, jika, seorang, yang, ingin, tidak, perlu, khawatir, karena, pada, dasarnya, girl, retweets, favorites, svp, jennifer, swindell, ofccp, 50th, anniversary, tmw, 10am, register, uwhrrvzulz, usdol, sean, construction, progressing, res, soonï, secure, agency, bill, correcting, wmv, reds, slip, league, owners, truly, care, riches, await, machine, thoughts, recognize, malaysia, supplier, delivered, door, sign, legitimat, correctly, supply, order, inreverse, marched, parade, deck, side, looked, sound, marines, heels, hitting, pavement, sounded, soun, blaming, journey, vegan, cafe, farmers, seattle, zer0, con, appeared, damballa, malwaremustdie, のブログで昨年10月からの, フォワーディングを使うハッキングの仕組みを, 報告しました, sshでのtcpポートフォワーディングとは日本語では, sshでのポートフォワーディング, ですね, ようは, 確立している, 接続をトンネルとして利用し, 任意の通, ocjp, ポートフォワーディング経由でのsmtp, とhttp, ハッキング事件について, 0day, ゼロデイ, permissions, snap, click, templates, manage, templat, requested, 0x80094800, denied, policy, module, mbrownnyc, edition, aptly, smbloris, exploits, vuln, contained, wrapup, fireeye, quickly, though, widely, patched, dev, quicksand, rtf, tracker, hills, 265, ios, macos, sierra, apple, introduced, container, monkey, takes, heic, cheeky4n6monkey, 1st, successful, takedown, criminal, double, fast, flux, announced, consortium, intern, andromeda, shadowserver, foundation, tried, shed, light, seemed, appear, paypal, phishing, glance, evidently, turned, indonesian, spam, communities, deepend, best, tell, add, x32, vivaldi, chromium, grand, dreams, threatlabz, seen, autoit, families, frenchy, shellcode, chapters, telnetloader, echoloader, propagation, newactor, epilogue, prologue, wrote, mira, mmd, 0066, mirai, fbot, emerged, must, die, dropping, thousands, dollars, laptop, monetary, investment, protected, firewall, explained, beginners, triumfant, gifts, greetings, cards, store, target, costa, rica, mailchimp, negligence, lawsuit, tech, gfi, strange, trip, breakf, thirteenth, breakfast, guard, highlights, consolidate, location, migrated, sophos, yesterday, noticed, honeypots, heartbeat, based, googleing, anybody, knows, maybe, balena, api, wed, feb, 7th, storm, เรารู้สึกตื่นเต้นเป็นอย่างมากที่จะประกาศเปิดตัวเว็บไซต์อย่างเป็นทางการสำหรับเกมจาก, soft, ซึ่งเป็นหนึ่งในผู้พัฒนาสล็อตที่นักพนันตั้งหน้าตั้งตารอมากที่สุด, pgslots, เว็บตรงแท้, ปลอดภัย, บริการดีที่สุดแห่งปี, unmask, parasites, slowly, moving, away, transfer, done, site, directed, prowling, nsm, foo, wikipedia, sept, added, descriptions, njrat, backdoor, vidgrab, communications, similar, reprint, contagiodump, unpublished, parents, america, face, growing, wave, sophisticated, fraud, designed, deepest, fears, protective, instincts, americans, guarding, family, against, webroot, thomas, brunner, han, liu, moni, pande, teams, dedicated, staying, world, adversarial, state, prompt, injections, matthew, smith, matt, barrett, participating, panel, rural, wireless, association, steamboat, spring, rwa, summitpublic, speaking, briefing, review, reveals, notable, disparity, prices, towns, amherst, leads, henrybasset, red, sky, alliance, releases, per, history, taosecurity, weeks, introducing, community, hub, recognition, matters, week, times, within, industry, things, stated, repeatedly, both, simply, accept, being, lies, dear, readers, reader, approached, quake3, xss, forum, moderator, where, connec, revil, developer, anatoly, sergeevitsch, kravchuk, danchev, info, zipdump, metadata, base64dump_v0_0_31, zip, e54ffb4f618e47faa724c9f16cf21e7asha256, 9475e4184790583265106c, base64dump, didier, stevens, authorities, men, believed, members, prolific, extortion, blamed, perpetrating, alleged, hackers, krebs, blogs, view, profile, 2010, november, 2011, cluste, mariposa, deepsec, command5, botnet, aurora, subscribe, atom, older, plan, show, matches, suggestions, think, costs, combine, disk, processes, ports, relation, download, amazing, conclusion, usually, help, 137, 138, 139, 140, 43008, 141, code, 142, 143, 144, rsrc, 145, 146, 3584, 147, 148, 54873274859376076, 149, 150, reloc, 151, 512, 153, 154, 048149053317863157, 156, 157, 158, 159, 160, 161, 91340226, 5657, 48bb, 9dab, 44f07bfd14bd, ndows, 162, reg_sz, 163, 164, 165, 166, 167, 168, 169, 171, 125, windows_gui, 126, 4194304, 127, 23t05, 05z, 130, 287748, 131, 132, 229376, 133, 134, 136, contains_eof_data, checksum_is_zero, issues, 6f4xa71edhdfiujmdqolci, w32eventlogs, eozaqvjgh3pdauyt0lxxmr, w32prefetch, bihxipurfoedqgukv9vyvp, w32processes, jblwpv86pwbeohxjunty1h, 755s, 565s, 170s, c10d94e7, 43a9, 4160, a0ec, 2c5bb246697f, 102, 103, 104, 105, 106, 107, 108, 7b6cddeb, 3a25, 4568, 9d31, af18eb68c23e, hariskvolume1, 109, 110, 111, 112, 113, 114, 276992, 116, 117, 118, 119, readonly, hidden, 121, 122, sidtypeuser, 124, filenames, 630s, 456s, 171s, 6674509, febfac4b, e50c, 469e, a25a, 2c42be0653be, 20z, 6674510, 6674511, 6674512, 6674513, 6674514, reg_key, 6674515, 39z, 6674516, 6674517, 6674518, commands, even, examples, creation, listeners, hkcu, listener, dropped, serving, loading, applet, server, mark, visit, function, lines, several, timestamps, selectable, lots, analyze, grep, pretty, executed, event, filesystem, make, largest, 537, smaller, compare, hard, dump, options, selected, focus, recommended, usb, concerned, modification, copying, mounted, processhacker, shows, might, warnings, installed, warn, him, screenshots, anti, sinkholing, technique, values, faked, computed, lookup, submitting, receiving, encrypted, downloader, signed, stolen, fingerprinting, main, stage, website, htaccess, coming, search, referrer, initial, wrong, looks, rest, left, unchanged, except, major, 267738000, seconds, jul, disposition, attachment, xuqfvb, 957688, octet, 2zupfq7g6ke3q42ny1c19p61, e78ijh3yvqjzl70k67zephn9kw, 0_11, form, urlencoded, __utm, utmwv, utms, utmn, 1812125645, utmhn, isroi, utmcs, utf, utmsr, 800x600, utmvp, 783x444, utmsc, utmul, utmje, utmfl, 20r22, utmdt, gambar, 20animasi, rct, frm, esrc, eqhdu9acldp07aa, oiciag, ved, 0cbqqfjaa, usg, afqjcnhz4d179x2axxotolfsk_k71qralw, default, 253, 238, 192, interesting, requests, pcap, capturing, doing, afterwards, phases, difference, standalone, cli, feature, rich, gui, recommend, 221, watchweedsepisodes, wait, once, precise, delivery, second, covered, take, necessary, sure, ways, accomplish, short, batch, uses, does, actually, described, above, prerequisites, considerations, disadvantages, slightly, anonymized, original, previously, poc, previous, provided, warranty, own, risk, notice, ping, nul, offline, accepteula, move, include, setlocal, enableextensions, enabledelayedexpansion, ensuring, proper, working, dp0, x64, memoryzeauditscript, processor_architecture, exists, allowmultiple, ia64, audit, memoryze, auditfail, errorlevel, return, lastcmd, start, notepad, endlocal, hope, introduce, typos, replace, errors, overwrites, space, harddisk, privileged, credentials, whoami, rights, admin, writable, source, optional, likely, anymore, sorry, come, note, appears, 3r4lr, every, often, technet, operational, florian, roth, cyb3rops, sigma, rules, roberto, rodriguez, cyb3rward0g, threathunter, playbook, config, mike, haag, mhaggis, good, further, suggest, anything, tweet, conf, practical, recorded, detecting, apts, including, mitre, att, 2018_tom, ueltschi_sysmon_public, amsterdam, papers, conf2017, same, topic, watch, vv_vxntqtpe, uploads, pr12, recent, area, interest, increasing, endpoint, visibility, active, presenting, conferences, collaborating, trusted, groups, finally, stuff, happened, meantime, really, valid, question, haven, blogged, urls, shared, tagged, urlhaus, bazaar, people, having, access, emails, hashtag, desktopgroup, reversinglabs, starts, around, 30m, reversing2020, early, laden, analyzed, campaigns, 2021, became, harder, link, confidence, actor, companies, becomes, unc4044, symantec, bluebottle, raven, nxsms, linking, aliases, webinar, playing, god, permission, interpol, dealt, blow, suspected, notorious, joint, 2023, table, give, sample, hashes, happy, reach, discovered, pdns, directly, closely, blackhat, europe, arc, publications, himaja, motheram, hiding, sight, bulletproof, hosting, abused, iocs, sources, privately, action, currently, rat, status, 1973476746717696501, ish, slack, linkedin, then, hearing, invite, unfortunately, limited, myself, wish, kind, efforts, goal, track, tacs, impose, cost, say, eventually, identify, actors, involve, lea, ultimately, lead, arrests, criminals, andrew, thompson, scout, validin, exposed, scanning, clustering,
Text of the page (random words):
i eqhdu9acldp07aa oiciag ved 0cbqqfjaa usg afqjcnhz4d179x2axxotolfsk_k71qralw http www niceshop at http perrugina sciencehunk com __utm gif utmwv 5 3 3 utms 7 utmn 1812125645 utmhn isroi com utmcs utf 8 utmsr 800x600 utmvp 783x444 utmsc 24 bit utmul en us utmje 0 utmfl 10 0 20r22 utmdt gambar 20animasi 20 http mw prodigymsnteregala com http mw prodigymsnteregala com js java js http mw prodigymsnteregala com anlxmyn jar http mw prodigymsnteregala com post content type application x www form urlencoded user agent mozilla 4 0 windows 7 6 1 java 1 7 0_11 content length 90 i 2zupfq7g6ke3q42ny1c19p61 e78ijh3yvqjzl70k67zephn9kw response content type application octet stream content length 957688 content disposition attachment filename xuqfvb last modified sun 13 jul 2014 22 01 35 gmt time since request 9 267738000 seconds http 93 115 88 220 listing chn all html user agent mozilla 4 0 compatible msie 7 0 windows nt 6 1 wow64 trident 4 0 slcc2 net clr 2 0 50727 net clr 3 5 30729 net clr 3 0 30729 media center pc 6 0 net4 0c net4 0e wrong ie version in ua looks like the rest of the ua was left unchanged except the major version detailed http traffic of the zuponcic kit infection and initial c c request to infected website malicious htaccess file coming from a google search redirection checks for cookie referrer user agent redirection to first stage zuponcic kit checks client ip request to main zuponcic kit page request to java js for browser and java fingerprinting malicious jar downloader signed with stolen certificate post request submitting a long parameter key and receiving a large binary encrypted file get request to ip computed from dns lookup to fasternation net anti sinkholing technique sending data as cookie values and using faked user agent screenshots during vm infection during the infection the user might see some java warnings depending on installed java version and settings trying to warn him from getting infected using processhacker the malware process shows like this running redline collector the recommended way for running redline collector on a host is via usb key however if you re not concerned about modification of the host under investigation you can also run redline collector remotely by copying it over the network or running it from a mounted share i may write more details about how to run redline collector remotely over the net in a later blog post in this post i d like to focus on the details available from a redline analysis here is a list of modules and options selected for this collection the xml files created during collection can get pretty large depending on which modules are executed and settings in the script the registry event logs and filesystem make the largest part of this collection however the 537 mb of raw data nicely compress into a much smaller 33 mb compare this to a hard drive image or a memory dump analysis using redline after running redline collector on a suspicious or infected host you get lots of data in xml format to analyze with redline but also using grep and some other bash fu on linux or cygwin can be very useful using the timeline function from redline is very easy and powerful it lines up any artifacts collected using several timestamps that are selectable here are some artifacts from the timeline of this infection google redirection url a cookie is set from the infected web server the mark the first visit first request to zuponcic kit domain request to java js for loading the java applet prefetch file for java exe created or updated registry key created updated for malware domain serving malicious jar prefetch file for malware tmp file dropped malware exe file created malware exe process started malware exe process opened port listener registry key with binary data created creating persistence using registry run key under hkcu creation of port listeners using bash fu on redline xml data using some bash commands possibly even using cygwin on windows can be very useful and powerful here some examples searching for some network indicators time egrep ci prodigymsnteregala com js java js anlxmyn jar qkejzdj jar listing chn all html 93 115 88 220 egrep v 0 filedownloadhistory dn62zqqu8mwey2us5ofzc8 4 urlhistory lltr9wqwo8sd3vl2rgou0f 5 w32registryapi arn9dznmiyqdhnxvugnjzz 2 real 0m17 630s user 0m17 456s sys 0m0 171s egrep i prodigymsnteregala com js java js anlxmyn jar qkejzdj jar listing chn all html 93 115 88 220 filedownloadhistory dn62zqqu8mwey2us5ofzc8 sourceurl http mw prodigymsnteregala com favicon ico sourceurl filedownloadhistory dn62zqqu8mwey2us5ofzc8 sourceurl http mw prodigymsnteregala com sourceurl filedownloadhistory dn62zqqu8mwey2us5ofzc8 sourceurl http mw prodigymsnteregala com tr gif sourceurl filedownloadhistory dn62zqqu8mwey2us5ofzc8 sourceurl http mw prodigymsnteregala com js java js sourceurl urlhistory lltr9wqwo8sd3vl2rgou0f url http mw prodigymsnteregala com favicon ico url urlhistory lltr9wqwo8sd3vl2rgou0f url http mw prodigymsnteregala com url urlhistory lltr9wqwo8sd3vl2rgou0f url host mw prodigymsnteregala com url urlhistory lltr9wqwo8sd3vl2rgou0f url http mw prodigymsnteregala com url urlhistory lltr9wqwo8sd3vl2rgou0f url http mw prodigymsnteregala com url w32registryapi arn9dznmiyqdhnxvugnjzz path hkey_users s 1 5 21 3096987436 3122932343 3109395949 1000 software microsoft windows currentversion ext stats cafeefac dec7 0000 0001 abcdeffedcba iexplore alloweddomains prodigymsnteregala com path w32registryapi arn9dznmiyqdhnxvugnjzz keypath software microsoft windows currentversion ext stats cafeefac dec7 0000 0001 abcdeffedcba iexplore alloweddomains prodigymsnteregala com keypath egrep in c 10 prodigymsnteregala com w32registryapi egrep m 1 a 15 registryitem egrep m 1 b 15 registryitem 6674509 registryitem xmlns xsi http www w3 org 2001 xmlschema instance xmlns xsd http www w3 org 2001 xmlschema uid febfac4b e50c 469e a25a 2c42be0653be created 2014 07 14t01 14 20z username toms vm win7x64 tom username 6674510 securityid s 1 5 21 3096987436 3122932343 3109395949 1000 securityid 6674511 path hkey_users s 1 5 21 3096987436 3122932343 3109395949 1000 software microsoft windows currentversion ext stats cafeefac dec7 0000 0001 abcdeffedcba iexplore alloweddomains prodigymsnteregala com path 6674512 hive hkey_users s 1 5 21 3096987436 3122932343 3109395949 1000 hive 6674513 keypath software microsoft windows currentversion ext stats cafeefac dec7 0000 0001 abcdeffedcba iexplore alloweddomains prodigymsnteregala com keypath 6674514 type reg_key type 6674515 modified 2014 07 13t22 01 39z modified 6674516 numsubkeys 0 numsubkeys 6674517 numvalues 0 numvalues 6674518 registryitem searching for some host indicators filenames registry keys time egrep ci dpnlobbyg exe 483759317 tmp egkyxzdcin 7538554d 326909f3 jxzfuv egrep v 0 w32apifiles 8xdv3nsaugodpxnrhsahqg 8 w32apifiles issues 6f4xa71edhdfiujmdqolci 1 w32eventlogs eozaqvjgh3pdauyt0lxxmr 8 w32prefetch bihxipurfoedqgukv9vyvp 12 w32processes memory jblwpv86pwbeohxjunty1h 3 w32registryapi arn9dznmiyqdhnxvugnjzz 20 w32scripting persistence h3ihm1txbupdcehrhajicc 5 real 0m17 755s user 0m17 565s sys 0m0 170s egrep i dpnlobbyg exe 483759317 tmp egkyxzdcin 7538554d 326909f3 jxzfuv w32apifiles w32scripting persistence w32apifiles 8xdv3nsaugodpxnrhsahqg fullpath c users tom appdata locallow sun java deployment cache 6 0 13 7538554d 326909f3 fullpath w32apifiles 8xdv3nsaugodpxnrhsahqg filename 7538554d 326909f3 filename w32apifiles 8xdv3nsaugodpxnrhsahqg fullpath c users tom appdata locallow sun java deployment cache 6 0 13 7538554d 326909f3 idx fullpath w32apifiles 8xdv3nsaugodpxnrhsahqg filename 7538554d 326909f3 idx filename w32apifiles 8xdv3nsaugodpxnrhsahqg fullpath c windows prefetch 483759317 tmp eb4905c2 pf fullpath w32apifiles 8xdv3nsaugodpxnrhsahqg filename 483759317 tmp eb4905c2 pf filename w32apifiles 8xdv3nsaugodpxnrhsahqg fullpath c windows prefetch dpnlobbyg exe 603267d1 pf fullpath w32apifiles 8xdv3nsaugodpxnrhsahqg filename dpnlobbyg exe 603267d1 pf filename w32scripting persistence h3ihm1txbupdcehrhajicc regtext c users tom appdata roaming dpnlobbyg exe regtext w32scripting persistence h3ihm1txbupdcehrhajicc filepath c users tom appdata roaming dpnlobbyg exe filepath w32scripting persistence h3ihm1txbupdcehrhajicc fullpath c users tom appdata roaming dpnlobbyg exe fullpath w32scripting persistence h3ihm1txbupdcehrhajicc filename dpnlobbyg exe filename w32scripting persistence h3ihm1txbupdcehrhajicc text c users tom appdata roaming dpnlobbyg exe text egrep in b 10 a 120 dpnlobbyg exe w32scripting persistence egrep m 1 a 100 persistenceitem egrep m 1 b 100 persistenceitem 96 persistenceitem xmlns xsi http www w3 org 2001 xmlschema instance xmlns xsd http www w3 org 2001 xmlschema uid c10d94e7 43a9 4160 a0ec 2c5bb246697f created 2014 07 14t01 11 17z persistencetype registry persistencetype 97 regpath hkey_current_user software microsoft windows currentversion run dlls regpath 98 regtext c users tom appdata roaming dpnlobbyg exe regtext 99 regowner nt authority system regowner 100 regmodified 2014 07 13t22 44 51z regmodified 101 filepath c users tom appdata roaming dpnlobbyg exe filepath 102 fileowner toms vm win7x64 tom fileowner 103 filecreated 2014 07 13t22 01 47z filecreated 104 filemodified 2014 07 13t22 01 47z filemodified 105 fileaccessed 2014 07 13t22 01 47z fileaccessed 106 filechanged 2014 07 13t22 01 47z filechanged 107 md5sum 105ead6f908f0d8cbab11a0f4408d373 md5sum 108 fileitem xmlns xsi http www w3 org 2001 xmlschema instance xmlns xsd http www w3 org 2001 xmlschema uid 7b6cddeb 3a25 4568 9d31 af18eb68c23e created 2014 07 14t01 11 17z devicepath device hariskvolume1 devicepath 109 fullpath c users tom appdata roaming dpnlobbyg exe fullpath 110 drive c drive 111 filepath users tom appdata roaming filepath 112 filename dpnlobbyg exe filename 113 fileextension exe fileextension 114 sizeinbytes 276992 sizeinbytes 115 created 2014 07 13t22 01 47z created 116 modified 2014 07 13t22 01 47z modified 117 accessed 2014 07 13t22 01 47z accessed 118 changed 2014 07 13t22 01 47z changed 119 fileattributes readonly hidden system archive fileattributes 120 username toms vm win7x64 tom username 121 securityid s 1 5 21 3096987436 3122932343 3109395949 1000 securityid 122 securitytype sidtypeuser securitytype 123 md5sum 105ead6f908f0d8cbab11a0f4408d373 md5sum 124 peinfo type executable type 125 subsystem windows_gui subsystem 126 baseaddress 4194304 baseaddress 127 petimestamp 2012 02 23t05 41 05z petimestamp 128 pechecksum pefileraw 0 pefileraw 129 pefileapi 0 pefileapi 130 pecomputedapi 287748 pecomputedapi 131 pechecksum 132 extraneousbytes 229376 extraneousbytes 133 detectedanomalies string checksum_is_zero string 134 string contains_eof_data string 135 detectedanomalies 136 sections numberofsections 3 numberofsections 137 actualnumberofsections 3 actualnumberofsections 138 section name text name 139 type none type 140 sizeinbytes 43008 sizeinbytes 141 detectedcharacteristics read execute code detectedcharacteristics 142 entropy averagevalue 0 77262239772402574 143 section 144 section name rsrc name 145 type none type 146 sizeinbytes 3584 sizeinbytes 147 detectedcharacteristics read detectedcharacteristics 148 entropy averagevalue 0 54873274859376076 149 section 150 section name reloc name 151 type none type 152 sizeinbytes 512 sizeinbytes 153 detectedcharacteristics read detectedcharacteristics 154 entropy averagevalue 0 048149053317863157 155 section 156 sections 157 peinfo 158 peakentropy 0 77262239772402574 peakentropy 159 peakcodeentropy 0 77262239772402574 peakcodeentropy 160 fileitem 161 registryitem xmlns xsi http www w3 org 2001 xmlschema instance xmlns xsd http www w3 org 2001 xmlschema uid 91340226 5657 48bb 9dab 44f07bfd14bd created 2014 07 14t01 11 17z keypath microsoft ndows currentversion run keypath 162 type reg_sz type 163 modified 2014 07 13t22 44 51z modified 164 valuename dlls valuename 165 username nt authority system username 166 text c users tom appdata roaming dpnlobbyg exe text 167 reportedlengthinbytes 86 reportedlengthinbytes 168 hive hkey_current_user software hive 169 path hkey_current_user software microsoft windows currentversion run dlls path 170 securityid s 1 5 18 securityid 171 registryitem 172 persistenceitem looking at the raw xml usually should help with creating ioc s later conclusion mandiant s redline software is free to download and use i find it amazing how much details can be found by analyzing a host with redline and how easy it is to create a timeline for analysis redline can combine disk and memory artifacts in a timeline showing processes created and ports opened in time relation to files and registry keys created i think redline is much more useful than what it costs are you using redline yet and have some feedback or suggestions i d love to hear it in the next post i plan to show how to create ioc s from this analysis and how to check for ioc matches on a host stay tuned cheers c_apt_ure posted by tomu at 7 54 am 6 comments older posts home subscribe to posts atom labels apt aurora botconf botnet command5 deepsec dfir intelligence ioc malware mandiant mariposa ponmocup sans dfir summit securosis splunk sysmon threat hunting threat intelligence what s this blog about blog archive 2025 1 october 1 using netbios names for pivoting and threat cluste 2022 1 january 1 2017 1 december 1 2014 3 august 1 july 1 june 1 2013 3 december 1 june 1 may 1 2012 8 september 1 july 1 june 2 may 1 april 1 march 1 february 1 2011 2 november 1 august 1 2010 6 september 1 april 2 march 3 about me tomu view my complete profile blogs i like to read krebs on security two alleged teampcp hackers arrested in australia authorities in australia have arrested two men believed to be members of teampcp a prolific cybercrime and data extortion group blamed for perpetrating th 1 day ago didier stevens update base64dump py version 0 0 31 more info on this update zipdump py metadata encoding base64dump_v0_0_31 zip http md5 e54ffb4f618e47faa724c9f16cf21e7asha256 9475e4184790583265106c 4 days ago dancho danchev s blog who is revil s ransomware developer anatoly sergeevitsch kravchuk dear blog readers this is dancho a reader recently approached me with a detailed research and analysis for quake3 a xss forum moderator where he connec 6 days ago windows incident response true lies many times within the industry we hear things stated repeatedly or with authority or both and simply accept them as fact as being true however a l 1 week ago abuse ch introducing the abuse ch community hub recognition matters 4 weeks ago taosecurity freebsd released the most security advisories in project history in june 2026 on average the freebsd security team releases about 2 security advisories per month ai has changed this in april the project released 8 advisories w 1 month ago henrybasset s red sky alliance blog amherst leads nh market intelligence briefing july 12 2026 a review of current market data reveals ...
|