#DorkBot
Detection ratio: 0 / 43
SHA256: d6a07c7c72f838bf598f6f80ed24bd9a84035abc58dc92dea2844786dcaea3c1
https://www.virustotal.com/file/d6a07c7 ... /analysis/
work with threads.
IsDebuggerPresent
7C813123 > 64:A1 18000000 MOV EAX,DWORD PTR FS:[18]
7C813129 8B40 30 MOV EAX,DWORD PTR DS:[EAX+30]
7C81312C 0FB640 02 MOVZX EAX,BYTE PTR DS:[EAX+2]
HKU\S-1-5-21-329068152-764733703-1708537768-500\Software\Microsoft\Windows\CurrentVersion\Run\© Microsoft Real Time Media Stack: "C:\Windows\Temp\System\ntvdmd.exe"
HKU\S-1-5-21-329068152-764733703-1708537768-500\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Documents and Settings\Administrador\Plantillas\explorer.exe: "explorer"
HKU\S-1-5-21-329068152-764733703-1708537768-500\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Windows\Temp\System\ntvdmd.exe: "Microsoft Unified Communications Client API DLL"
HKU\S-1-5-21-329068152-764733703-1708537768-500\Software\Microsoft\Windows\ShellNoRoam\MUICache\C:\Windows\Temp\System\UccApi.exe: "UccApi"