├── README.md
├── 949A2A6D.md
├── B50C3DF2.md
├── A3150A5E.md
└── 8C777025.md
/README.md:
--------------------------------------------------------------------------------
1 | # av-fingerprints
2 |
3 | This is a partial replication of results of the "[AVLeak:
4 | Fingerprinting Antivirus Emulators Through Black-Box Testing](https://www.usenix.org/system/files/conference/woot16/woot16-paper-blackthorne_update.pdf)" paper that was presented at WOOT '16 and Black Hat USA 2016. Techniques from the paper are used to leak "fingerprints" from the x86 Windows emulators of various AV software. This can be used to develop and detect evasive malware.
5 |
6 | Special thanks to Alexei Bulazel ([@0xAlexei](https://twitter.com/0xAlexei)) for his assistance.
7 |
8 | | | [8C777025](8C777025.md) | [949A2A6D](949A2A6D.md) | [A3150A5E](A3150A5E.md) | [B50C3DF2](B50C3DF2.md) |
9 | |:--|:-----------------------:|:-----------------------:|:-----------------------:|:-----------------------:|
10 | | **Environmental Artifacts** | [3](8C777025.md#environmental-artifacts) | [3](949A2A6D.md#environmental-artifacts) | [4](A3150A5E.md#environmental-artifacts) | [3](B50C3DF2.md#environmental-artifacts) |
11 | | **OS API Inconsistency** | 0 | [2](949A2A6D.md#os-api-inconsistency) | 0 | [1](B50C3DF2.md#os-api-inconsistency) |
12 | | **Network Emulation** | 0 | 0 | 0 | 0 |
13 | | **Timing** | 0 | 0 | 0 | 0 |
14 | | **Process Introspection** | 0 | 0 | 0 | 0 |
15 | | **CPU “Red Pills”** | 0 | 0 | 0 | 0 |
16 |
--------------------------------------------------------------------------------
/949A2A6D.md:
--------------------------------------------------------------------------------
1 | # 949A2A6D v4.00.09
2 |
3 | ## Environmental Artifacts
4 |
5 | ### argv[0]
6 |
7 | ```
8 | C:\Documents and Settings\Administrator\Desktop\Analysis.exe
9 | ```
10 |
11 | ### GetEnvironmentStrings
12 |
13 | ```
14 | ALLUSERSPROFILE=C:\Documents and Settings\All Users
15 | APPDATA=C:\Documents and Settings\Administrator\Application Data
16 | CLIENTNAME=Console
17 | CommonProgramFiles=C:\Program Files\Common Files
18 | COMPUTERNAME=Ikar-Sys-Sim-PC
19 | ComSpec=C:\Windows\System32\cmd.exe
20 | FP_NO_HOST_CHECK=NO
21 | HOMEDRIVE=C:
22 | HOMEPATH=\Documents and Settings\Administrator
23 | LOGONSERVER=\\Ikar-Sys-Sim-PC
24 | NUMBER_OF_PROCESSORS=1
25 | OS=Windows_NT
26 | Path=C:\Windows\System32;C:\Windows
27 | PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
28 | PROCESSOR_ARCHITECTURE=x86
29 | PROCESSOR_IDENTIFIER=x86 Family 6 Model 15 Stepping 8, GenuineIntel
30 | PROCESSOR_LEVEL=6
31 | PROCESSOR_REVISION=0f08
32 | ProgramFiles=C:\Program Files
33 | PROMPT=$P$G
34 | SESSIONNAME=Console
35 | SystemDrive=C:
36 | SystemRoot=C:\Windows
37 | TEMP=C:\Windows\Temp
38 | TMP=C:\Windows\Temp
39 | USERDOMAIN=
40 | USERNAME=Administrator
41 | USERPROFILE=C:\Documents and Settings\Administrator
42 | windir=C:\Windows
43 | ```
44 |
45 | ### CreateToolhelp32Snapshot
46 |
47 | ```
48 | PPID PID Process Name
49 | 0 0 System Idle Process
50 | 0 4 System
51 | 4 548 smss.exe
52 | 548 604 csrss.exe
53 | 548 628 winlogon.exe
54 | 628 672 services.exe
55 | 672 880 svchost.exe
56 | 672 1324 spoolsv.exe
57 | 672 1248 alg.exe
58 | 628 684 lsass.exe
59 | 0 1688 explorer.exe
60 | 1688 1800 iexplore.exe
61 | 1688 1964 cmd.exe
62 | 1688 1984 Analysis.exe
63 | ```
64 |
65 | ## OS API Inconsistency
66 |
67 | ### GetSystemRegistryQuota
68 |
69 | `pdwQuotaAllowed` and `pdwQuotaUsed` are not supposed to be `null`.
70 |
71 | ```
72 | DWORD pdwQuotaAllowed = 0x00000000;
73 | DWORD pdwQuotaUsed = 0x00000000;
74 | ```
75 |
76 | ### GetProcessVersion
77 |
78 | `0x00050002`: Windows Server 2003 R2, Windows Server 2003, Windows XP 64-Bit Edition.
79 |
80 | ```c
81 | DWORD process_version = GetProcessVersion(0); // => 0x00050002
82 | ```
83 |
--------------------------------------------------------------------------------
/B50C3DF2.md:
--------------------------------------------------------------------------------
1 | # B50C3DF2 v13.0.3114
2 |
3 | ## Environmental Artifacts
4 |
5 | ### argv[0]
6 |
7 | The executable name is 6 randomly generated lower-alphabetic characters.
8 |
9 | ```
10 | C:\Documents and Settings\Administrator\My Documents\cbfrxd.exe
11 | C:\Documents and Settings\Administrator\My Documents\gdtfwl.exe
12 | C:\Documents and Settings\Administrator\My Documents\kswymt.exe
13 | C:\Documents and Settings\Administrator\My Documents\anlbux.exe
14 | C:\Documents and Settings\Administrator\My Documents\dsjtfc.exe
15 | ```
16 |
17 | ### GetEnvironmentStrings
18 |
19 | ```
20 | ALLUSERSPROFILE=C:\Documents and Settings\All Users
21 | APPDATA=C:\Documents and Settings\Administrator\Application Data
22 | CLIENTNAME=Console
23 | CommonProgramFiles=C:\Program Files\Common Files
24 | COMPUTERNAME=ELICZ
25 | ComSpec=C:\WINDOWS\system32\cmd.exe
26 | FP_NO_HOST_CHECK=NO
27 | HOMEDRIVE=C:
28 | HOMEPATH=\Documents and Settings\Administrator
29 | LOGONSERVER=\\ELICZ
30 | NUMBER_OF_PROCESSORS=2
31 | OS=Windows_NT
32 | Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem
33 | PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
34 | PROCESSOR_ARCHITECTURE=x86
35 | PROCESSOR_IDENTIFIER=x86 Family 15 Model 4 Stepping 3, AuthenticAMD
36 | PROCESSOR_LEVEL=15
37 | PROCESSOR_REVISION=0403
38 | ProgramFiles=C:\Program Files
39 | SESSIONNAME=Console
40 | SystemDrive=C:
41 | SystemRoot=C:\WINDOWS
42 | TEMP=C:\WINDOWS\Temp
43 | TMP=C:\WINDOWS\Temp
44 | USERDOMAIN=ELICZ
45 | USERNAME=Administrator
46 | USERPROFILE=C:\Documents and Settings\Administrator
47 | windir=C:\WINDOWS
48 | ```
49 |
50 | ### CreateToolhelp32Snapshot
51 |
52 | ```
53 | PPID PID Process Name
54 | 0 0 [System Process]
55 | 0 4 System
56 | 4 12 smss.exe
57 | 12 20 csrss.exe
58 | 12 28 winlogon.exe
59 | 28 36 services.exe
60 | 28 44 lsass.exe
61 | 36 52 svchost.exe
62 | 36 60 spoolsv.exe
63 | 65524 68 explorer.exe
64 | 36 76 AVP.EXE
65 | 36 84 PCCTOOL.EXE
66 | 36 92 TMPROXY.EXE
67 | 36 100 OUTPOST.EXE
68 | 36 108 VSSERV.EXE
69 | 36 116 ZAPRO.EXE
70 | 36 124 REALMON.EXE
71 | 36 132 VETMSG.EXE
72 | 36 140 VETTRAY.EXE
73 | 36 148 ZLCLIENTE.EXE
74 | 36 156 ZONEALARM.EXE
75 | 36 164 ZLCLIENT.EXE
76 | 36 172 CCAPP.EXE
77 | 36 180 CCSETMGR.EXE
78 | 36 188 CCEVTMGR.EXE
79 | 36 196 SCCOMM.EXE
80 | 36 204 CCCPROXY.EXE
81 | 36 212 NAVW32.EXE
82 | 36 220 NAVAPSVC.EXE
83 | 36 228 NPFMNTOR.EXE
84 | 36 236 CPDCLNT.EXE
85 | 36 244 PCCNTUPD.EXE
86 | 36 252 TMNTSRV.EXE
87 | 36 260 PAVPRSRV.EXE
88 | 36 268 PADMIN.EXE
89 | 36 276 PAVPROT.EXE
90 | 36 284 PANDAAV.EXE
91 | 36 292 AVENGINE.EXE
92 | 36 300 APVXDWIN.EXE
93 | 36 308 AVGUARD.EXE
94 | 36 316 AVGNT.EXE
95 | 36 324 AVSCHED32.EXE
96 | 36 332 NOD32KRN.EXE
97 | 36 340 NOD32.EXE
98 | 36 348 GBPSV.EXE
99 | 36 356 NOD32KUI.EXE
100 | 36 364 KAV.EXE
101 | 36 372 KAVMM.EXE
102 | 36 380 KAVPF.EXE
103 | 36 388 AVGEMC.EXE
104 | 36 396 AVGCC.EXE
105 | 36 404 AVGAMSVR.EXE
106 | 36 412 AVGUPSVC.EXE
107 | 36 420 AVGW.EXE
108 | 36 428 ASHWEBSV.EXE
109 | 36 436 ASHDISP.EXE
110 | 36 444 ASHMAISV.EXE
111 | 36 452 ASHSERV.EXE
112 | 36 460 ASHUPDSV.EXE
113 | 36 468 EWIDOCTRL.EXE
114 | 36 476 GUARD.EXE
115 | 36 484 GCASDTSERV.EXE
116 | 36 492 MSMPENG.EXE
117 | 36 500 MCAFEE.EXE
118 | 68 508 iexplore.exe
119 | 68 516 firefox.exe
120 | 68 524 opera.exe
121 | 68 532 safari.exe
122 | 68 936 vzrbaa.exe
123 | 68 936 jtpyzc.exe
124 | 68 936 pukfco.exe
125 | 68 936 twyzmg.exe
126 | 68 936 jtbtwy.exe
127 | 68 936 and so on...
128 | ```
129 |
130 | ## OS API Inconsistency
131 |
132 | ### GetSystemRegistryQuota
133 |
134 | `pdwQuotaAllowed` and `pdwQuotaUsed` are not supposed to be `null`.
135 |
136 | ```
137 | DWORD pdwQuotaAllowed = 0x00000000;
138 | DWORD pdwQuotaUsed = 0x00000000;
139 | ```
140 |
--------------------------------------------------------------------------------
/A3150A5E.md:
--------------------------------------------------------------------------------
1 | # A3150A5E v18.6.3983.0
2 |
3 | ## Environmental Artifacts
4 |
5 | ### argv[0]
6 |
7 | The executable name is 6 randomly generated lower-alphabetic characters.
8 |
9 | ```
10 | C:\Documents and Settings\Administrator\My Documents\cbfrxd.exe
11 | C:\Documents and Settings\Administrator\My Documents\gdtfwl.exe
12 | C:\Documents and Settings\Administrator\My Documents\kswymt.exe
13 | C:\Documents and Settings\Administrator\My Documents\anlbux.exe
14 | C:\Documents and Settings\Administrator\My Documents\dsjtfc.exe
15 | ```
16 |
17 | ### GetEnvironmentStrings
18 |
19 | ```
20 | ALLUSERSPROFILE=C:\Documents and Settings\All Users
21 | APPDATA=C:\Documents and Settings\Administrator\Application Data
22 | CLIENTNAME=Console
23 | CommonProgramFiles=C:\Program Files\Common Files
24 | COMPUTERNAME=ELICZ
25 | ComSpec=C:\WINDOWS\system32\cmd.exe
26 | FP_NO_HOST_CHECK=NO
27 | HOMEDRIVE=C:
28 | HOMEPATH=\Documents and Settings\Administrator
29 | LOGONSERVER=\\ELICZ
30 | NUMBER_OF_PROCESSORS=2
31 | OS=Windows_NT
32 | Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem
33 | PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
34 | PROCESSOR_ARCHITECTURE=x86
35 | PROCESSOR_IDENTIFIER=x86 Family 15 Model 4 Stepping 3, AuthenticAMD
36 | PROCESSOR_LEVEL=15
37 | PROCESSOR_REVISION=0403
38 | ProgramFiles=C:\Program Files
39 | SESSIONNAME=Console
40 | SystemDrive=C:
41 | SystemRoot=C:\WINDOWS
42 | TEMP=C:\WINDOWS\Temp
43 | TMP=C:\WINDOWS\Temp
44 | USERDOMAIN=ELICZ
45 | USERNAME=Administrator
46 | USERPROFILE=C:\Documents and Settings\Administrator
47 | windir=C:\WINDOWS
48 | ```
49 |
50 | ### CreateToolhelp32Snapshot
51 |
52 | ```
53 | Index PPID PID Process Name
54 | 0000 0 0 [System Process]
55 | 0001 0 4 System
56 | 0002 4 12 smss.exe
57 | 0003 12 20 csrss.exe
58 | 0004 12 28 winlogon.exe
59 | 0005 28 36 services.exe
60 | 0006 28 44 lsass.exe
61 | 0007 36 52 svchost.exe
62 | 0008 36 60 spoolsv.exe
63 | 0009 65524 68 explorer.exe
64 | 0010 36 540 msascui.exe
65 | 0011 36 76 AVP.EXE
66 | 0012 36 84 PCCTOOL.EXE
67 | 0013 36 92 TMPROXY.EXE
68 | 0014 36 100 OUTPOST.EXE
69 | 0015 36 108 VSSERV.EXE
70 | 0016 36 116 ZAPRO.EXE
71 | 0017 36 124 REALMON.EXE
72 | 0018 36 132 VETMSG.EXE
73 | 0019 36 140 VETTRAY.EXE
74 | 0020 36 148 ZLCLIENTE.EXE
75 | 0021 36 156 ZONEALARM.EXE
76 | 0022 36 164 ZLCLIENT.EXE
77 | 0023 36 172 CCAPP.EXE
78 | 0024 36 180 CCSETMGR.EXE
79 | 0025 36 188 CCEVTMGR.EXE
80 | 0026 36 196 SCCOMM.EXE
81 | 0027 36 204 CCCPROXY.EXE
82 | 0028 36 212 NAVW32.EXE
83 | 0029 36 220 NAVAPSVC.EXE
84 | 0030 36 228 NPFMNTOR.EXE
85 | 0031 36 236 CPDCLNT.EXE
86 | 0032 36 244 PCCNTUPD.EXE
87 | 0033 36 252 TMNTSRV.EXE
88 | 0034 36 260 PAVPRSRV.EXE
89 | 0035 36 268 PADMIN.EXE
90 | 0036 36 276 PAVPROT.EXE
91 | 0037 36 284 PANDAAV.EXE
92 | 0038 36 292 AVENGINE.EXE
93 | 0039 36 300 APVXDWIN.EXE
94 | 0040 36 308 AVGUARD.EXE
95 | 0041 36 316 AVGNT.EXE
96 | 0042 36 324 AVSCHED32.EXE
97 | 0043 36 332 NOD32KRN.EXE
98 | 0044 36 340 NOD32.EXE
99 | 0045 36 348 GBPSV.EXE
100 | 0046 36 356 NOD32KUI.EXE
101 | 0047 36 364 KAV.EXE
102 | 0048 36 372 KAVMM.EXE
103 | 0049 36 380 KAVPF.EXE
104 | 0050 36 388 AVGEMC.EXE
105 | 0051 36 396 AVGCC.EXE
106 | 0052 36 404 AVGAMSVR.EXE
107 | 0053 36 412 AVGUPSVC.EXE
108 | 0054 36 420 AVGW.EXE
109 | 0055 36 428 ASHWEBSV.EXE
110 | 0056 36 436 ASHDISP.EXE
111 | 0057 36 444 ASHMAISV.EXE
112 | 0058 36 452 ASHSERV.EXE
113 | 0059 36 460 ASWUPDSV.EXE
114 | 0060 36 468 EWIDOCTRL.EXE
115 | 0061 36 476 GUARD.EXE
116 | 0062 36 484 GCASDTSERV.EXE
117 | 0063 36 492 MSMPENG.EXE
118 | 0064 36 500 MCAFEE.EXE
119 | 0065 68 508 iexplore.exe
120 | 0066 68 516 firefox.exe
121 | 0067 68 524 opera.exe
122 | 0068 68 532 safari.exe
123 | 0069 68 936 sjnkfw.exe
124 | 0070 68 936 qiepks.exe
125 | 0071 68 936 anzmgd.exe
126 | 0072 68 936 wymtbt.exe
127 | 0073 68 936 uxrmtm.exe
128 | 0074 68 936 qvdecb.exe
129 | 0075 68 936 aaangq.exe
130 | 0076 68 936 fswlie.exe
131 | .... 68 936 and so on...
132 | ```
133 |
134 | ## FindNextFile
135 |
136 | The executable names in `C:\Documents and Settings\Administrator\My Documents` are 6 randomly generated lower-alphabetic characters.
137 |
138 | ```
139 | Directory of C:
140 |
141 | 02/13/2008 11:24 AM
Documents and Settings
142 | 02/13/2008 11:24 AM Program Files
143 | 02/13/2008 11:24 AM RECYCLER
144 | 02/13/2008 11:24 AM System Volume Information
145 | 02/13/2008 11:24 AM WINDOWS
146 |
147 | Directory of C:\Documents and Settings
148 |
149 | 02/13/2008 11:24 AM .
150 | 02/13/2008 11:24 AM ..
151 | 02/13/2008 11:24 AM Administrator
152 | 02/13/2008 11:24 AM All Users
153 | 02/13/2008 11:24 AM Default User
154 |
155 | Directory of C:\Documents and Settings\Administrator
156 |
157 | 02/13/2008 11:24 AM .
158 | 02/13/2008 11:24 AM ..
159 | 02/13/2008 11:24 AM Application Data
160 | 02/13/2008 11:24 AM Cookies
161 | 02/13/2008 11:24 AM Desktop
162 | 02/13/2008 11:24 AM Local Settings
163 | 02/13/2008 11:24 AM My Documents
164 | 02/13/2008 11:24 AM Start Menu
165 |
166 | Directory of C:\Documents and Settings\Administrator\Application Data
167 |
168 | 02/13/2008 11:24 AM .
169 | 02/13/2008 11:24 AM ..
170 | 02/13/2008 11:24 AM Microsoft
171 |
172 | Directory of C:\Documents and Settings\Administrator\Application Data\Microsoft
173 |
174 | 02/13/2008 11:24 AM .
175 | 02/13/2008 11:24 AM ..
176 | 02/13/2008 11:24 AM AddIns
177 |
178 | Directory of C:\Documents and Settings\Administrator\Application Data\Microsoft\AddIns
179 |
180 | 02/13/2008 11:24 AM .
181 | 02/13/2008 11:24 AM ..
182 |
183 | Directory of C:\Documents and Settings\Administrator\Cookies
184 |
185 | 02/13/2008 11:24 AM .
186 | 02/13/2008 11:24 AM ..
187 |
188 | Directory of C:\Documents and Settings\Administrator\Desktop
189 |
190 | 02/13/2008 11:24 AM .
191 | 02/13/2008 11:24 AM ..
192 | 02/13/2008 11:24 AM 65,536 victim.doc
193 | 02/13/2008 11:24 AM 65,536 victim.jpg
194 | 02/13/2008 11:24 AM 512 victim.txt
195 | 02/13/2008 11:24 AM 65,536 victim.xls
196 |
197 | Directory of C:\Documents and Settings\Administrator\Local Settings
198 |
199 | 02/13/2008 11:24 AM .
200 | 02/13/2008 11:24 AM ..
201 | 02/13/2008 11:24 AM Application Data
202 | 02/13/2008 11:24 AM Temp
203 | 02/13/2008 11:24 AM Temporary Internet Files
204 |
205 | Directory of C:\Documents and Settings\Administrator\Local Settings\Application Data
206 |
207 | 02/13/2008 11:24 AM .
208 | 02/13/2008 11:24 AM ..
209 |
210 | Directory of C:\Documents and Settings\Administrator\Local Settings\Temp
211 |
212 | 02/13/2008 11:24 AM .
213 | 02/13/2008 11:24 AM ..
214 |
215 | Directory of C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files
216 |
217 | 02/13/2008 11:24 AM .
218 | 02/13/2008 11:24 AM ..
219 | 02/13/2008 11:24 AM Content.IE5
220 |
221 | Directory of C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5
222 |
223 | 02/13/2008 11:24 AM .
224 | 02/13/2008 11:24 AM ..
225 |
226 | Directory of C:\Documents and Settings\Administrator\My Documents
227 |
228 | 02/13/2008 11:24 AM .
229 | 02/13/2008 11:24 AM ..
230 | 09/12/2016 12:13 PM 3,584 hkfwli.exe
231 | 09/12/2016 12:13 PM 3,584 lmtfgd.exe
232 | 09/12/2016 12:13 PM 3,584 kfhfva.exe
233 | 09/12/2016 12:13 PM 3,584 mgqirn.exe
234 | 09/12/2016 12:13 PM 3,584 sjjnkf.exe
235 | 09/12/2016 12:13 PM 3,584 abcdef.exe (continues forever)
236 |
237 | Directory of C:\Documents and Settings\Administrator\Start Menu
238 |
239 | 02/13/2008 11:24 AM .
240 | 02/13/2008 11:24 AM ..
241 | 02/13/2008 11:24 AM Programs
242 |
243 | Directory of C:\Documents and Settings\Administrator\Start Menu\Programs
244 |
245 | 02/13/2008 11:24 AM .
246 | 02/13/2008 11:24 AM ..
247 | 02/13/2008 11:24 AM Startup
248 |
249 | Directory of C:\Documents and Settings\Administrator\Start Menu\Programs\Startup
250 |
251 | 02/13/2008 11:24 AM .
252 | 02/13/2008 11:24 AM ..
253 |
254 | Directory of C:\Documents and Settings\All Users
255 |
256 | 02/13/2008 11:24 AM .
257 | 02/13/2008 11:24 AM ..
258 | 02/13/2008 11:24 AM Application Data
259 | 02/13/2008 11:24 AM Desktop
260 | 02/13/2008 11:24 AM Start Menu
261 |
262 | Directory of C:\Documents and Settings\All Users\Application Data
263 |
264 | 02/13/2008 11:24 AM .
265 | 02/13/2008 11:24 AM ..
266 |
267 | Directory of C:\Documents and Settings\All Users\Desktop
268 |
269 | 02/13/2008 11:24 AM .
270 | 02/13/2008 11:24 AM ..
271 |
272 | Directory of C:\Documents and Settings\All Users\Start Menu
273 |
274 | 02/13/2008 11:24 AM .
275 | 02/13/2008 11:24 AM ..
276 | 02/13/2008 11:24 AM Programs
277 |
278 | Directory of C:\Documents and Settings\All Users\Start Menu\Programs
279 |
280 | 02/13/2008 11:24 AM .
281 | 02/13/2008 11:24 AM ..
282 | 02/13/2008 11:24 AM Startup
283 |
284 | Directory of C:\Documents and Settings\All Users\Start Menu\Programs\Startup
285 |
286 | 02/13/2008 11:24 AM .
287 | 02/13/2008 11:24 AM ..
288 |
289 | Directory of C:\Documents and Settings\Default User
290 |
291 | 02/13/2008 11:24 AM .
292 | 02/13/2008 11:24 AM ..
293 | 02/13/2008 11:24 AM Application Data
294 | 02/13/2008 11:24 AM Start Menu
295 |
296 | Directory of C:\Documents and Settings\Default User\Application Data
297 |
298 | 02/13/2008 11:24 AM .
299 | 02/13/2008 11:24 AM ..
300 |
301 | Directory of C:\Documents and Settings\Default User\Start Menu
302 |
303 | 02/13/2008 11:24 AM .
304 | 02/13/2008 11:24 AM ..
305 | 02/13/2008 11:24 AM Programs
306 |
307 | Directory of C:\Documents and Settings\Default User\Start Menu\Programs
308 |
309 | 02/13/2008 11:24 AM .
310 | 02/13/2008 11:24 AM ..
311 | 02/13/2008 11:24 AM Startup
312 |
313 | Directory of C:\Documents and Settings\Default User\Start Menu\Programs\Startup
314 |
315 | 02/13/2008 11:24 AM .
316 | 02/13/2008 11:24 AM ..
317 |
318 | Directory of C:\Program Files
319 |
320 | 02/13/2008 11:24 AM .
321 | 02/13/2008 11:24 AM ..
322 | 02/13/2008 11:24 AM Common Files
323 | 02/13/2008 11:24 AM Internet Explorer
324 | 02/13/2008 11:24 AM Windows Media Player
325 |
326 | Directory of C:\Program Files\Common Files
327 |
328 | 02/13/2008 11:24 AM .
329 | 02/13/2008 11:24 AM ..
330 | 02/13/2008 11:24 AM Microsoft Shared
331 | 02/13/2008 11:24 AM System
332 |
333 | Directory of C:\Program Files\Common Files\Microsoft Shared
334 |
335 | 02/13/2008 11:24 AM .
336 | 02/13/2008 11:24 AM ..
337 |
338 | Directory of C:\Program Files\Common Files\System
339 |
340 | 02/13/2008 11:24 AM .
341 | 02/13/2008 11:24 AM ..
342 |
343 | Directory of C:\Program Files\Internet Explorer
344 |
345 | 02/13/2008 11:24 AM .
346 | 02/13/2008 11:24 AM ..
347 |
348 | Directory of C:\Program Files\Windows Media Player
349 |
350 | 02/13/2008 11:24 AM .
351 | 02/13/2008 11:24 AM ..
352 |
353 | Directory of C:\RECYCLER
354 |
355 | 02/13/2008 11:24 AM .
356 | 02/13/2008 11:24 AM ..
357 | 02/13/2008 11:24 AM S-1-5-21-0-0-0-500
358 |
359 | Directory of C:\RECYCLER\S-1-5-21-0-0-0-500
360 |
361 | 02/13/2008 11:24 AM .
362 | 02/13/2008 11:24 AM ..
363 |
364 | Directory of C:\System Volume Information
365 |
366 | 02/13/2008 11:24 AM .
367 | 02/13/2008 11:24 AM ..
368 |
369 | Directory of C:\WINDOWS
370 |
371 | 02/13/2008 11:24 AM .
372 | 02/13/2008 11:24 AM ..
373 | 02/13/2008 11:24 AM Fonts
374 | 02/13/2008 11:24 AM Installer
375 | 02/13/2008 11:24 AM Microsoft.NET
376 | 02/13/2008 11:24 AM Tasks
377 | 02/13/2008 11:24 AM Temp
378 | 02/13/2008 11:24 AM system
379 | 02/13/2008 11:24 AM system32
380 |
381 | Directory of C:\WINDOWS\Fonts
382 |
383 | 02/13/2008 11:24 AM .
384 | 02/13/2008 11:24 AM ..
385 |
386 | Directory of C:\WINDOWS\Installer
387 |
388 | 02/13/2008 11:24 AM .
389 | 02/13/2008 11:24 AM ..
390 |
391 | Directory of C:\WINDOWS\Microsoft.NET
392 |
393 | 02/13/2008 11:24 AM .
394 | 02/13/2008 11:24 AM ..
395 | 02/13/2008 11:24 AM Framework
396 |
397 | Directory of C:\WINDOWS\Microsoft.NET\Framework
398 |
399 | 02/13/2008 11:24 AM .
400 | 02/13/2008 11:24 AM ..
401 |
402 | Directory of C:\WINDOWS\Tasks
403 |
404 | 02/13/2008 11:24 AM .
405 | 02/13/2008 11:24 AM ..
406 |
407 | Directory of C:\WINDOWS\Temp
408 |
409 | 02/13/2008 11:24 AM .
410 | 02/13/2008 11:24 AM ..
411 |
412 | Directory of C:\WINDOWS\system
413 |
414 | 02/13/2008 11:24 AM .
415 | 02/13/2008 11:24 AM ..
416 |
417 | Directory of C:\WINDOWS\system32
418 |
419 | 02/13/2008 11:24 AM .
420 | 02/13/2008 11:24 AM ..
421 | 02/13/2008 11:24 AM dllcache
422 | 02/13/2008 11:24 AM drivers
423 | 02/13/2008 11:24 AM 989,696 kernel32.dll
424 | 02/13/2008 11:24 AM 706,048 ntdll.dll
425 | 02/13/2008 11:24 AM 1,048,576 victim.exe
426 | 02/13/2008 11:24 AM wbem
427 |
428 | Directory of C:\WINDOWS\system32\dllcache
429 |
430 | 02/13/2008 11:24 AM .
431 | 02/13/2008 11:24 AM ..
432 |
433 | Directory of C:\WINDOWS\system32\drivers
434 |
435 | 02/13/2008 11:24 AM .
436 | 02/13/2008 11:24 AM ..
437 | 02/13/2008 11:24 AM etc
438 |
439 | Directory of C:\WINDOWS\system32\drivers\etc
440 |
441 | 02/13/2008 11:24 AM .
442 | 02/13/2008 11:24 AM ..
443 |
444 | Directory of C:\WINDOWS\system32\wbem
445 |
446 | 02/13/2008 11:24 AM .
447 | 02/13/2008 11:24 AM ..
448 | ```
449 |
--------------------------------------------------------------------------------
/8C777025.md:
--------------------------------------------------------------------------------
1 | # 8C777025 v1.1.12805.0
2 |
3 | ## Environmental Artifacts
4 |
5 | ### argv[0]
6 |
7 | ```
8 | C:\myapp.exe
9 | ```
10 |
11 | ### GetEnvironmentStrings
12 |
13 | ```
14 | ALLUSERSPROFILE=C:\Documents and Settings\All Users
15 | APPDATA=C:\Documents and Settings\Administrator\Application Data
16 | CLIENTNAME=Console
17 | COMSPEC=C:\WINDOWS\system32\cmd.exe
18 | FP_NO_HOST_CHECK=NO
19 | HOMEDRIVE=C:
20 | HOMEPATH=\Documents and Settings\Administrator
21 | NUMBER_OF_PROCESSORS=1
22 | PATH=C:\WINDOWS;C:\Program Files\Common Files\Microsoft Shared
23 | PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
24 | ProgramFiles=C:\Program Files
25 | TEMP=C:\TEMP
26 | TMP=C:\TEMP
27 | SYSTEMDRIVE=C:
28 | SystemRoot=C:\WINDOWS
29 | USERPROFILE=C:\Documents and Settings\Administrator
30 | ```
31 |
32 | ### CreateToolhelp32Snapshot
33 |
34 | ```
35 | Index PPID PID Process Name
36 | 0000 0 0 [System Process]
37 | 0001 0 4 System
38 | 0002 0 356 smss.exe
39 | 0003 356 608 csrss.exe
40 | 0004 356 624 winlogon.exe
41 | 0005 624 676 services.exe
42 | 0006 676 856 svchost.exe
43 | 0007 676 1084 svchost.exe
44 | 0008 676 1268 spoolsv.exe
45 | 0009 624 680 lsass.exe
46 | 0010 624 700 kav.exe
47 | 0011 624 704 avpcc.exe
48 | 0012 624 708 _avpm.exe
49 | 0013 624 712 avp32.exe
50 | 0014 624 716 avp.exe
51 | 0015 624 720 antivirus.exe
52 | 0016 624 724 fsav.exe
53 | 0017 624 728 norton.exe
54 | 0018 624 732 msmpeng.exe
55 | 0019 624 736 msmpsvc.exe
56 | 0020 624 740 mrt.exe
57 | 0021 624 744 outpost.exe
58 | 0022 0 1768 explorer.exe
59 | 0023 1768 1796 iexplore.exe
60 | 0024 1768 1800 outlook.exe
61 | 0025 1768 1804 msimn.exe
62 | 0026 1768 1808 firefox.exe
63 | 0027 1768 1812 icq.exe
64 | 0028 1768 1816 yahoomessenger.exe
65 | 0029 1768 1820 msnmsgr.exe
66 | 0030 1768 1824 far.exe
67 | 0031 1768 1828 trillian.exe
68 | 0032 1768 1832 skype.exe
69 | 0033 1768 1836 googletalk.exe
70 | 0034 1768 1840 notepad.exe
71 | 0035 1768 1844 wmplayer.exe
72 | 0036 4097 1848 net.exe
73 | 0037 4097 1852 spawned.exe
74 | 0038 1768 4008 myapp.exe
75 | 0039 1768 3760 myapp.exe
76 | 0040 1768 4012 myapp.exe
77 | 0041 1768 3860 myapp.exe
78 | 0042 1768 3608 myapp.exe
79 | 0043 1768 3972 myapp.exe
80 | 0044 1768 3724 myapp.exe
81 | 0045 1768 3568 myapp.exe
82 | 0046 1768 3840 myapp.exe
83 | 0047 1768 3940 myapp.exe
84 | 0048 1768 3696 myapp.exe
85 | 0049 1768 4056 myapp.exe
86 | .... 1768 .... and so on...
87 | ```
88 |
89 | ### FindNextFile
90 |
91 | ```
92 | Directory of C:
93 |
94 | 01/23/2003 04:03 PM 1 config.sys
95 | 01/23/2003 04:03 PM Documents and Settings
96 | 01/23/2003 04:03 PM 3,584 IndexerVolumeGuid
97 | 01/23/2003 04:03 PM INTERNAL
98 | 01/23/2003 04:03 PM Mirc
99 | 01/23/2003 04:03 PM 3,584 myapp.exe
100 | 01/23/2003 04:03 PM 1 ntldr
101 | 01/23/2003 04:03 PM Program Files
102 | 01/23/2003 04:03 PM System Volume Information
103 | 01/23/2003 04:03 PM TEMP
104 | 01/23/2003 04:03 PM 1 tssafeedit.dat
105 | 01/23/2003 04:03 PM UserData
106 | 01/23/2003 04:03 PM WINDOWS
107 |
108 | Directory of C:\Documents and Settings
109 |
110 | 01/23/2003 04:03 PM .
111 | 01/23/2003 04:03 PM ..
112 | 01/23/2003 04:03 PM Administrator
113 | 01/23/2003 04:03 PM All Users
114 | 01/23/2003 04:03 PM JohnDoe
115 |
116 | Directory of C:\Documents and Settings\Administrator
117 |
118 | 01/23/2003 04:03 PM .
119 | 01/23/2003 04:03 PM ..
120 | 01/23/2003 04:03 PM Local Settings
121 |
122 | Directory of C:\Documents and Settings\Administrator\Local Settings
123 |
124 | 01/23/2003 04:03 PM .
125 | 01/23/2003 04:03 PM ..
126 | 01/23/2003 04:03 PM Application Data
127 |
128 | Directory of C:\Documents and Settings\Administrator\Local Settings\Application Data
129 |
130 | 01/23/2003 04:03 PM .
131 | 01/23/2003 04:03 PM ..
132 | 01/23/2003 04:03 PM Microsoft
133 |
134 | Directory of C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft
135 |
136 | 01/23/2003 04:03 PM .
137 | 01/23/2003 04:03 PM ..
138 | 01/23/2003 04:03 PM CD Burning
139 |
140 | Directory of C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\CD Burning
141 |
142 | 01/23/2003 04:03 PM .
143 | 01/23/2003 04:03 PM ..
144 | 01/23/2003 04:03 PM 1 __empty
145 |
146 | Directory of C:\Documents and Settings\All Users
147 |
148 | 01/23/2003 04:03 PM .
149 | 01/23/2003 04:03 PM ..
150 | 01/23/2003 04:03 PM Application Data
151 |
152 | Directory of C:\Documents and Settings\All Users\Application Data
153 |
154 | 01/23/2003 04:03 PM .
155 | 01/23/2003 04:03 PM ..
156 | 01/23/2003 04:03 PM Microsoft
157 |
158 | Directory of C:\Documents and Settings\All Users\Application Data\Microsoft
159 |
160 | 01/23/2003 04:03 PM .
161 | 01/23/2003 04:03 PM ..
162 | 01/23/2003 04:03 PM 1 __empty
163 |
164 | Directory of C:\Documents and Settings\JohnDoe
165 |
166 | 01/23/2003 04:03 PM .
167 | 01/23/2003 04:03 PM ..
168 | 01/23/2003 04:03 PM Application Data
169 | 01/23/2003 04:03 PM Desktop
170 | 01/23/2003 04:03 PM Local Settings
171 |
172 | Directory of C:\Documents and Settings\JohnDoe\Application Data
173 |
174 | 01/23/2003 04:03 PM .
175 | 01/23/2003 04:03 PM ..
176 | 01/23/2003 04:03 PM Microsoft
177 | 01/23/2003 04:03 PM 1 __empty
178 |
179 | Directory of C:\Documents and Settings\JohnDoe\Application Data\Microsoft
180 |
181 | 01/23/2003 04:03 PM .
182 | 01/23/2003 04:03 PM ..
183 | 01/23/2003 04:03 PM 1 __empty
184 |
185 | Directory of C:\Documents and Settings\JohnDoe\Desktop
186 |
187 | 01/23/2003 04:03 PM .
188 | 01/23/2003 04:03 PM ..
189 | 01/23/2003 04:03 PM 1 __empty
190 |
191 | Directory of C:\Documents and Settings\JohnDoe\Local Settings
192 |
193 | 01/23/2003 04:03 PM .
194 | 01/23/2003 04:03 PM ..
195 | 01/23/2003 04:03 PM Application Data
196 | 01/23/2003 04:03 PM Temporary Internet Files
197 |
198 | Directory of C:\Documents and Settings\JohnDoe\Local Settings\Application Data
199 |
200 | 01/23/2003 04:03 PM .
201 | 01/23/2003 04:03 PM ..
202 | 01/23/2003 04:03 PM Microsoft
203 |
204 | Directory of C:\Documents and Settings\JohnDoe\Local Settings\Application Data\Microsoft
205 |
206 | 01/23/2003 04:03 PM .
207 | 01/23/2003 04:03 PM ..
208 | 01/23/2003 04:03 PM Windows
209 |
210 | Directory of C:\Documents and Settings\JohnDoe\Local Settings\Application Data\Microsoft\Windows
211 |
212 | 01/23/2003 04:03 PM .
213 | 01/23/2003 04:03 PM ..
214 | 01/23/2003 04:03 PM 1 __empty
215 |
216 | Directory of C:\Documents and Settings\JohnDoe\Local Settings\Temporary Internet Files
217 |
218 | 01/23/2003 04:03 PM .
219 | 01/23/2003 04:03 PM ..
220 | 01/23/2003 04:03 PM 1 __empty
221 |
222 | Directory of C:\INTERNAL
223 |
224 | 01/23/2003 04:03 PM .
225 | 01/23/2003 04:03 PM ..
226 | 01/23/2003 04:03 PM 1 __empty
227 |
228 | Directory of C:\Mirc
229 |
230 | 01/23/2003 04:03 PM .
231 | 01/23/2003 04:03 PM ..
232 | 01/23/2003 04:03 PM 35 mirc.ini
233 | 01/23/2003 04:03 PM 18 script.ini
234 |
235 | Directory of C:\Program Files
236 |
237 | 01/23/2003 04:03 PM .
238 | 01/23/2003 04:03 PM ..
239 | 01/23/2003 04:03 PM Common Files
240 | 01/23/2003 04:03 PM Internet Explorer
241 | 01/23/2003 04:03 PM WebMoney
242 |
243 | Directory of C:\Program Files\Common Files
244 |
245 | 01/23/2003 04:03 PM .
246 | 01/23/2003 04:03 PM ..
247 | 01/23/2003 04:03 PM Microsoft Shared
248 | 01/23/2003 04:03 PM System
249 |
250 | Directory of C:\Program Files\Common Files\Microsoft Shared
251 |
252 | 01/23/2003 04:03 PM .
253 | 01/23/2003 04:03 PM ..
254 | 01/23/2003 04:03 PM 1 __empty
255 |
256 | Directory of C:\Program Files\Common Files\System
257 |
258 | 01/23/2003 04:03 PM .
259 | 01/23/2003 04:03 PM ..
260 | 01/23/2003 04:03 PM 1 __empty
261 | 01/23/2003 04:03 PM 1 wab32.dll
262 |
263 | Directory of C:\Program Files\Internet Explorer
264 |
265 | 01/23/2003 04:03 PM .
266 | 01/23/2003 04:03 PM ..
267 | 01/23/2003 04:03 PM 41,472 Iexplore.exe
268 | 01/23/2003 04:03 PM SIGNUP
269 | 01/23/2003 04:03 PM 1 __empty
270 |
271 | Directory of C:\Program Files\Internet Explorer\SIGNUP
272 |
273 | 01/23/2003 04:03 PM .
274 | 01/23/2003 04:03 PM ..
275 | 01/23/2003 04:03 PM 1 INSTALL.INS
276 |
277 | Directory of C:\Program Files\WebMoney
278 |
279 | 01/23/2003 04:03 PM .
280 | 01/23/2003 04:03 PM ..
281 | 01/23/2003 04:03 PM 1 __empty
282 |
283 | Directory of C:\System Volume Information
284 |
285 | 01/23/2003 04:03 PM .
286 | 01/23/2003 04:03 PM ..
287 | 01/23/2003 04:03 PM 1 __empty
288 |
289 | Directory of C:\TEMP
290 |
291 | 01/23/2003 04:03 PM .
292 | 01/23/2003 04:03 PM ..
293 | 01/23/2003 04:03 PM 1 __empty
294 |
295 | Directory of C:\UserData
296 |
297 | 01/23/2003 04:03 PM .
298 | 01/23/2003 04:03 PM ..
299 | 01/23/2003 04:03 PM 178,280 default.wab
300 |
301 | Directory of C:\WINDOWS
302 |
303 | 01/23/2003 04:03 PM .
304 | 01/23/2003 04:03 PM ..
305 | 01/23/2003 04:03 PM Debug
306 | 01/23/2003 04:03 PM FONTS
307 | 01/23/2003 04:03 PM 35,840 IEXPLORE.EXE
308 | 01/23/2003 04:03 PM Inf
309 | 01/23/2003 04:03 PM Media
310 | 01/23/2003 04:03 PM SYSTEM32
311 | 01/23/2003 04:03 PM System
312 | 01/23/2003 04:03 PM TEMP
313 | 01/23/2003 04:03 PM 2,560 TWAIN.DLL
314 | 01/23/2003 04:03 PM 1,024 TWAIN_32.DLL
315 | 01/23/2003 04:03 PM Web
316 | 01/23/2003 04:03 PM 239,104 explorer.exe
317 | 01/23/2003 04:03 PM 8,704 hh.exe
318 | 01/23/2003 04:03 PM 417 msdfmap.ini
319 | 01/23/2003 04:03 PM 9,216 notepad.exe
320 | 01/23/2003 04:03 PM 9,216 regedit.exe
321 | 01/23/2003 04:03 PM 8,704 taskman.exe
322 | 01/23/2003 04:03 PM 9,216 twunk_16.exe
323 | 01/23/2003 04:03 PM 8,704 twunk_32.exe
324 | 01/23/2003 04:03 PM 552 win.ini
325 | 01/23/2003 04:03 PM 8,704 winhelp.exe
326 | 01/23/2003 04:03 PM 8,704 winhlp32.exe
327 |
328 | Directory of C:\WINDOWS\Debug
329 |
330 | 01/23/2003 04:03 PM .
331 | 01/23/2003 04:03 PM ..
332 | 01/23/2003 04:03 PM 1 PASSWD.LOG
333 |
334 | Directory of C:\WINDOWS\FONTS
335 |
336 | 01/23/2003 04:03 PM .
337 | 01/23/2003 04:03 PM ..
338 | 01/23/2003 04:03 PM 1 __empty
339 |
340 | Directory of C:\WINDOWS\Inf
341 |
342 | 01/23/2003 04:03 PM .
343 | 01/23/2003 04:03 PM