

"" (Path: "HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\ADDRESSBOOK") "" (Path: "HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL") "" opened file "C:\Users\%USERNAME%\AppData\Roaming\FTPRush\" (DesiredAccess: 1048577, OpenOptions: 16417)Ĭontains ability to enumerate processes/modules/threads "" opened file "C:\Users\%USERNAME%\AppData\Local\VanDyke\Config\Sessions\" (DesiredAccess: 1048577, OpenOptions: 16417) "" opened file "C:\ProgramData\VanDyke\Config\Sessions\" (DesiredAccess: 1048577, OpenOptions: 16417) "" opened file "C:\Users\%USERNAME%\AppData\Roaming\VanDyke\Config\Sessions\" (DesiredAccess: 1048577, OpenOptions: 16417) "" opened file "C:\Users\%USERNAME%\AppData\Local\TurboFTP\" (DesiredAccess: 1048577, OpenOptions: 16417) "" opened file "C:\ProgramData\TurboFTP\" (DesiredAccess: 1048577, OpenOptions: 16417) "" opened file "C:\Users\%USERNAME%\AppData\Roaming\TurboFTP\" (DesiredAccess: 1048577, OpenOptions: 16417) "" opened file "C:\Users\%USERNAME%\AppData\Local\SmartFTP\" (DesiredAccess: 1048577, OpenOptions: 16417) "" opened file "%ALLUSERSPROFILE%\SmartFTP\" (DesiredAccess: 1048577, OpenOptions: 16417)


"" opened file "C:\Users\%USERNAME%\AppData\Roaming\SmartFTP\" (DesiredAccess: 1048577, OpenOptions: 16417) "" opened file "C:\Program Files\Common Files\Ipswitch\WS_FTP\" (DesiredAccess: 1048577, OpenOptions: 16417)
EXPANDRIVE 5.4.4 WINDOWS
Detected alert "ET TROJAN Fareit/Pony Downloader Checkin 3" (SID: 2014234, Rev: 10, Severity: 1) categorized as "A Network Trojan was detected" (Backdoor, ransomware, trojans, etc.)ĭetected alert "ET POLICY Windows 98 User-Agent Detected - Possible Malware or Non-Updated System" (SID: 2007695, Rev: 21, Severity: 1) categorized as "Potential Corporate Privacy Violation"ĭetected alert "ET TROJAN Pony Downloader HTTP Library MSIE 5 Win98" (SID: 2014562, Rev: 3, Severity: 1) categorized as "A Network Trojan was detected" (Backdoor, ransomware, trojans, etc.)ĭetected alert "ET POLICY Unsupported/Fake Internet Explorer Version MSIE 5." (SID: 2016870, Rev: 12, Severity: 1) categorized as "Potential Corporate Privacy Violation"ĭetected alert "CrowdStrike Pony Request" (SID: 181708101, Rev: 20170522, Severity: 1) categorized as "A Network Trojan was detected"įound an IP/URL artifact that was identified as malicious by a significant amount of reputation enginesįound malicious artifacts related to "160.153.129.214".
