![]() ![]() String found in binary or memory: w.rambler. com/ equals w ww.faceboo k.com (Fac ebook) String found in binary or memory: w.facebook. String found in binary or memory: arch.yahoo. String found in binary or memory: arch.cn.ya hoo.com/ equal s (Yah oo) String found in binary or memory: ds.myspace. String found in binary or memory: ar ch.yahoo.c om/ equals (Yahoo) String found in binary or memory: rch.yahoo. String found in binary or memory: ht tp://ie.se arch.yahoo. tmpĬontains functionality to enumerate / list files inside a directoryĬode function: 0_2_004065 46 FindFir stFileW,Fi ndClose,Ĭode function: 0_2_004071 33 DeleteF ileW,Close Handle,lst rcatW,lstr catW,lstrc atW,lstrle nW,FindFir stFileW,De leteFileW, FindNextFi leW,FindCl ose,Remove DirectoryW ,Ĭode function: 0_2_00402E 54 FindFir stFileW,Ĭode function: 0_1_004065 46 FindFir stFileW,Fi ndClose,Ĭode function: 0_1_004071 33 DeleteF ileW,Close Handle,lst rcatW,lstr catW,lstrc atW,lstrle nW,FindFir stFileW,De leteFileW, FindNextFi leW,FindCl ose,Remove DirectoryW ,Ĭode function: 0_1_00402E 54 FindFir stFileW,įound strings which match to known social media urls tmp\gįile opened: C:\Users\u ser\AppDat a\Local\Te mp\nsh79A1. Source: C:\Users\u ser\Deskto p\rcsetup1 53.exeįile opened: C:\Users\u ser\AppDat a\Local\Te mpįile opened: C:\Users\u ser\AppDat a\Localįile opened: C:\Users\u ser\AppDat a\Local\Te mp\nsh79A1. Found application associated with file extension.Successful, ratio: 18.8% (good quality ratio 18.5%). ![]() Number of analysed new started processes analysed: ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |