HTTP Requests
Для просмотра внешних ссылок необходимо зарегистрироваться (и подтвердить мыло) либо авторизоваться.
Для просмотра внешних ссылок необходимо зарегистрироваться (и подтвердить мыло) либо авторизоваться.
Для просмотра внешних ссылок необходимо зарегистрироваться (и подтвердить мыло) либо авторизоваться.
DNS Resolutions
stingrayzx.zadc.ru
IP Traffic
62.210.140.227:80 (TCP)
62.210.140.227:80 (TCP)
File System Actions
Files Opened
C:\Users\<USER>\AppData\Roaming\ptst2x6q0q6x7u2x6q0q6x7u
C:\Users\<USER>\AppData\Roaming\ptst2x6q0q6x7u2x6q0q6x7u\Telegram
C:\Users\<USER>\AppData\Roaming\ptst2x6q0q6x7u2x6q0q6x7u\Telegram\
C:\Users\<USER>\AppData\Roaming\FileZilla\recentservers.xml
C:\Users\<USER>\AppData\Roaming\FileZilla\sitemanager.xml
C:\Program Files (x86)\WinFtp Client\Favorites.dat
C:\Users\<USER>\AppData\Roaming\ptst2x6q0q6x7u2x6q0q6x7u\Wallets
C:\Users\<USER>\AppData\Roaming\ptst2x6q0q6x7u2x6q0q6x7u\General
C:\Users\<USER>\AppData\Roaming\ptst2x6q0q6x7u2x6q0q6x7u\Cookies
C:\Users\<USER>\AppData\Roaming\ptst2x6q0q6x7u2x6q0q6x7u\History
Files Written
C:\Users\<USER>\AppData\Roaming\ptst2x6q0q6x7u2x6q0q6x7u\Cookies\Chrome_0.log
C:\Users\<USER>\AppData\Roaming\ptst2x6q0q6x7u2x6q0q6x7u\Cookies\Mozilla_1.log
C:\Users\<USER>\AppData\Roaming\Microsoft\Windows\Cookies\
[email protected][1].txt
C:\Users\<USER>\AppData\Roaming\ptst2x6q0q6x7u2x6q0q6x7u\Information.txt
C:\Users\<USER>\AppData\Roaming\ptst2x6q0q6x7u2x6q0q6x7u\Actions.txt
C:\Users\<USER>\AppData\Roaming\zpar2x6q0q6x7u2x6q0q6x7u.zip
Files Deleted
C:\Users\<USER>\AppData\Local\Temp\vlmi{lolz}yg.col
Files Copied
C:\Users\<USER>\AppData\Local\Google\Chrome\User Data\Default\Cookies
C:\Users\<USER>\Desktop\accounting.docx
C:\Users\<USER>\Desktop\mydoc.doc
C:\Users\<USER>\Downloads\monitor.log
c:/program files (x86)/steam\config\config.vdf
c:/program files (x86)/steam\config\DialogConfig.vdf
Registry Actions
Registry Keys Opened
HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1
HKCU\Software\Valve\Steam
HKCR\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance
HKCR\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Instance\Disabled
HKCR\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}
HKCR\CLSID\{FAE3D380-FEA4-4623-8C75-C6B61110B681}\Namespaces
HKLM\Software\Microsoft\COM3
HKCU\CLSID\{E436EBB3-524F-11CE-9F53-0020AF0BA770}
HKCU\CLSID\{E436EBB3-524F-11CE-9F53-0020AF0BA770}\TreatAs
HKCU\CLSID\{E436EBB3-524F-11CE-9F53-0020AF0BA770}\Progid
Registry Keys Set
HKLM\Software\Microsoft\Tracing\gg injector_RASAPI32\EnableFileTracing
HKLM\Software\Microsoft\Tracing\gg injector_RASAPI32\EnableConsoleTracing
HKLM\Software\Microsoft\Tracing\gg injector_RASAPI32\FileTracingMask
HKLM\Software\Microsoft\Tracing\gg injector_RASAPI32\ConsoleTracingMask
HKLM\Software\Microsoft\Tracing\gg injector_RASAPI32\MaxFileSize
HKLM\Software\Microsoft\Tracing\gg injector_RASAPI32\FileDirectory
HKLM\Software\Microsoft\Tracing\gg injector_RASMANCS\EnableFileTracing
HKLM\Software\Microsoft\Tracing\gg injector_RASMANCS\EnableConsoleTracing
HKLM\Software\Microsoft\Tracing\gg injector_RASMANCS\FileTracingMask
HKLM\Software\Microsoft\Tracing\gg injector_RASMANCS\ConsoleTracingMask
Process And Service Actions
Services Opened
Sens
Synchronization Mechanisms & Signals
Mutexes Created
SyystemServs
AMResourceMutex3
eed3bd3a-a1ad-4e99-987b-d7cb3fcfa7f0 - S-1-5-21-364843204-231886559-199882026-1001
IESQMMUTEX_0_208
Local\c:!users!<USER>!appdata!roaming!microsoft!windows!ietldcache!
Mutexes Opened
Local\c:!users!<USER>!appdata!local!microsoft!windows!temporary internet files!content.ie5!
Local\c:!users!<USER>!appdata!roaming!microsoft!windows!cookies!
Local\c:!users!<USER>!appdata!local!microsoft!windows!history!history.ie5!
Local\c:!users!<USER>!appdata!roaming!microsoft!windows!ietldcache!