Техническая информация
- '%APPDATA%\maplebanana\launchAgent.exe'
- '%APPDATA%\maplebanana\kylinagent.exe' proxy.py
- '%APPDATA%\maplebanana\Install_Certificate.exe'
- '%APPDATA%\maplebanana\certmgr.exe' -add CA.crt -c -s -r localMachine Root
- '<SYSTEM32>\cmd.exe' kylinagent.exe proxy.py
- '<SYSTEM32>\cmd.exe' certmgr.exe -add CA.crt -c -s -r localMachine Root >NUL
- <SYSTEM32>\cmd.exe
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Internet Settings] 'WarnonBadCertRecving' = '00000000'
- %APPDATA%\maplebanana\certs\.v.fwmrm.net.crt
- %APPDATA%\maplebanana\certs\.typography.com.crt
- %APPDATA%\maplebanana\certs\.twitter.com.crt
- %APPDATA%\maplebanana\certs\.vo.msecnd.net.crt
- %APPDATA%\maplebanana\certs\.weixin.qq.com.crt
- %APPDATA%\maplebanana\certs\.webtrends.com.crt
- %APPDATA%\maplebanana\certs\.voicefive.com.crt
- %APPDATA%\maplebanana\certs\.twimg.com.crt
- %APPDATA%\maplebanana\certs\.talkgadget.google.com.crt
- %APPDATA%\maplebanana\certs\.syndication.twimg.com.crt
- %APPDATA%\maplebanana\certs\.storage.live.com.crt
- %APPDATA%\maplebanana\certs\.teamviewer.com.crt
- %APPDATA%\maplebanana\certs\.tweetdeck.com.crt
- %APPDATA%\maplebanana\certs\.truste.com.crt
- %APPDATA%\maplebanana\certs\.trafficshop.com.crt
- %APPDATA%\maplebanana\certs\.weshequ.com.crt
- %APPDATA%\maplebanana\certs\.ytimg.com.crt
- %APPDATA%\maplebanana\certs\.youtube.com.crt
- %APPDATA%\maplebanana\certs\.youtube-nocookie.com.crt
- %APPDATA%\maplebanana\certs\111.161.56.26.crt
- %APPDATA%\maplebanana\certs\173.194.124.4.crt
- %APPDATA%\maplebanana\certs\118.174.27.69.crt
- %APPDATA%\maplebanana\certs\118.174.27.43.crt
- %APPDATA%\maplebanana\certs\.yinxiang.com.crt
- %APPDATA%\maplebanana\certs\.wx.qq.com.crt
- %APPDATA%\maplebanana\certs\.wp.com.crt
- %APPDATA%\maplebanana\certs\.windowssearch.com.crt
- %APPDATA%\maplebanana\certs\.xmarks.com.crt
- %APPDATA%\maplebanana\certs\.yimg.com.crt
- %APPDATA%\maplebanana\certs\.yahoo.com.crt
- %APPDATA%\maplebanana\certs\.xx.fbcdn.net.crt
- %APPDATA%\maplebanana\certs\.passpack.com.crt
- %APPDATA%\maplebanana\certs\.pack.google.com.crt
- %APPDATA%\maplebanana\certs\.mozilla.org.crt
- %APPDATA%\maplebanana\certs\.pcs.baidu.com.crt
- %APPDATA%\maplebanana\certs\.quantserve.com.crt
- %APPDATA%\maplebanana\certs\.qq.com.crt
- %APPDATA%\maplebanana\certs\.policies.live.net.crt
- %APPDATA%\maplebanana\certs\.mookie1.com.crt
- %APPDATA%\maplebanana\certs\.mail.google.com.crt
- %APPDATA%\maplebanana\certs\.lphbs.com.crt
- %APPDATA%\maplebanana\certs\.live.com.crt
- %APPDATA%\maplebanana\certs\.mathtag.com.crt
- %APPDATA%\maplebanana\certs\.moatads.com.crt
- %APPDATA%\maplebanana\certs\.microsoft.com.crt
- %APPDATA%\maplebanana\certs\.metric.gstatic.com.crt
- %APPDATA%\maplebanana\certs\.query.yahoo.com.crt
- %APPDATA%\maplebanana\certs\.skypeassets.com.crt
- %APPDATA%\maplebanana\certs\.skype.com.crt
- %APPDATA%\maplebanana\certs\.services.visualstudio.com.crt
- %APPDATA%\maplebanana\certs\.social.microsoft.com.crt
- %APPDATA%\maplebanana\certs\.staticflickr.com.crt
- %APPDATA%\maplebanana\certs\.ssl.cf2.rackcdn.com.crt
- %APPDATA%\maplebanana\certs\.squarespace.com.crt
- %APPDATA%\maplebanana\certs\.services.disqus.com.crt
- %APPDATA%\maplebanana\certs\.s3.amazonaws.com.crt
- %APPDATA%\maplebanana\certs\.rubiconproject.com.crt
- %APPDATA%\maplebanana\certs\.ravenjs.com.crt
- %APPDATA%\maplebanana\certs\.sandbox.google.com.crt
- %APPDATA%\maplebanana\certs\.sec.s-msft.com.crt
- %APPDATA%\maplebanana\certs\.search.yahoo.com.crt
- %APPDATA%\maplebanana\certs\.scorecardresearch.com.crt
- %APPDATA%\maplebanana\certs\www.google.com.hk.crt
- %APPDATA%\maplebanana\certs\www.google.com.crt
- %APPDATA%\maplebanana\certs\www.google.co.kr.crt
- %APPDATA%\maplebanana\certs\www.google.com.sg.crt
- %APPDATA%\maplebanana\cacert.pem
- %APPDATA%\maplebanana\CA.crt
- %APPDATA%\maplebanana\certs\www.google.com.tw.crt
- %APPDATA%\maplebanana\certs\www.g.n.crt
- %APPDATA%\maplebanana\certs\sourceforge.net.crt
- %APPDATA%\maplebanana\certs\sharvil.io.crt
- %APPDATA%\maplebanana\certs\savecdn.com.crt
- %APPDATA%\maplebanana\certs\stackauth.com.crt
- %APPDATA%\maplebanana\certs\twitter.com.crt
- %APPDATA%\maplebanana\certs\translate.google.com.hk.crt
- %APPDATA%\maplebanana\certs\t.co.crt
- %APPDATA%\maplebanana\certmgr.exe
- %APPDATA%\maplebanana\libeay32.dll
- %APPDATA%\maplebanana\launchAgent.exe
- %APPDATA%\maplebanana\kylinagent.exe
- %APPDATA%\maplebanana\LocalVerson.ini
- %APPDATA%\maplebanana\ntlmaps.bat
- %APPDATA%\maplebanana\msvcr90.dll
- %APPDATA%\maplebanana\Microsoft.VC90.CRT.manifest
- %APPDATA%\maplebanana\InstallCrt.ini
- %APPDATA%\maplebanana\GeoIP.dat
- %APPDATA%\maplebanana\dnsproxy.py
- %APPDATA%\maplebanana\dnslib-0.8.3.egg
- %APPDATA%\maplebanana\gettext.py
- %APPDATA%\maplebanana\Install_Certificate.exe
- %APPDATA%\maplebanana\goagent-osx.command
- %APPDATA%\maplebanana\goagent-gtk.py
- %APPDATA%\maplebanana\certs\220.255.5.90.crt
- %APPDATA%\maplebanana\certs\210.242.125.54.crt
- %APPDATA%\maplebanana\certs\210.242.125.22.crt
- %APPDATA%\maplebanana\certs\62.116.207.43.crt
- %APPDATA%\maplebanana\certs\74.125.204.97.crt
- %APPDATA%\maplebanana\certs\74.125.193.73.crt
- %APPDATA%\maplebanana\certs\74.125.193.61.crt
- %APPDATA%\maplebanana\certs\208.117.238.88.crt
- %APPDATA%\maplebanana\certs\197.199.254.29.crt
- %APPDATA%\maplebanana\certs\173.194.65.60.crt
- %APPDATA%\maplebanana\certs\173.194.136.86.crt
- %APPDATA%\maplebanana\certs\202.55.10.81.crt
- %APPDATA%\maplebanana\certs\208.117.238.84.crt
- %APPDATA%\maplebanana\certs\208.117.229.90.crt
- %APPDATA%\maplebanana\certs\208.117.225.14.crt
- %APPDATA%\maplebanana\certs\74.125.22.77.crt
- %APPDATA%\maplebanana\certs\localhost.crt
- %APPDATA%\maplebanana\certs\id.google.com.hk.crt
- %APPDATA%\maplebanana\certs\hx7155.info.crt
- %APPDATA%\maplebanana\certs\maps.google.com.hk.crt
- %APPDATA%\maplebanana\certs\safebrowsing-cache.google.com.hk.crt
- %APPDATA%\maplebanana\certs\passpack.com.crt
- %APPDATA%\maplebanana\certs\news.google.com.hk.crt
- %APPDATA%\maplebanana\certs\google.com.crt
- %APPDATA%\maplebanana\certs\ddparis.com.crt
- %APPDATA%\maplebanana\certs\adadvisor.net.crt
- %APPDATA%\maplebanana\certs\74.125.229.30.crt
- %APPDATA%\maplebanana\certs\disqus.com.crt
- %APPDATA%\maplebanana\certs\gmail.com.crt
- %APPDATA%\maplebanana\certs\github.com.crt
- %APPDATA%\maplebanana\certs\dropbox.com.crt
- %APPDATA%\maplebanana\certs\.ak.fbcdn.net.crt
- %APPDATA%\maplebanana\certs\.ak.facebook.com.crt
- %APPDATA%\maplebanana\certs\.adnxs.com.crt
- %APPDATA%\maplebanana\certs\.akamaihd.net.crt
- %APPDATA%\maplebanana\certs\.amazonaws.com.crt
- %APPDATA%\maplebanana\certs\.alipay.com.crt
- %APPDATA%\maplebanana\certs\.alibaba.com.crt
- %APPDATA%\maplebanana\certs\.adk2.co.crt
- %APPDATA%\maplebanana\certs\.39.240.164.crt
- %APPDATA%\maplebanana\certs\.2mdn.net.crt
- %APPDATA%\maplebanana\certs\.228.65.133.crt
- %APPDATA%\maplebanana\certs\.39.57.180.crt
- %APPDATA%\maplebanana\certs\.addons.mozilla.org.crt
- %APPDATA%\maplebanana\certs\.adblockplus.org.crt
- %APPDATA%\maplebanana\certs\.85.228.103.crt
- %APPDATA%\maplebanana\certs\.amgdgt.com.crt
- %APPDATA%\maplebanana\certs\.blob.core.windows.net.crt
- %APPDATA%\maplebanana\certs\.bing.com.crt
- %APPDATA%\maplebanana\certs\.betrad.com.crt
- %APPDATA%\maplebanana\certs\.blogblog.com.crt
- %APPDATA%\maplebanana\certs\.bluekai.com.crt
- %APPDATA%\maplebanana\certs\.bloglovin.com.crt
- %APPDATA%\maplebanana\certs\.blogger.com.crt
- %APPDATA%\maplebanana\certs\.baidu.com.crt
- %APPDATA%\maplebanana\certs\.apprep.smartscreen.microsoft.com.crt
- %APPDATA%\maplebanana\certs\.apis.google.com.crt
- %APPDATA%\maplebanana\certs\.api.twitter.com.crt
- %APPDATA%\maplebanana\certs\.appspot.com.crt
- %APPDATA%\maplebanana\certs\.auth.adobe.com.crt
- %APPDATA%\maplebanana\certs\.aspnetcdn.com.crt
- %APPDATA%\maplebanana\certs\.ashleymadison.com.crt
- %APPDATA%\maplebanana\python27.zip
- %APPDATA%\maplebanana\python27.dll
- %APPDATA%\maplebanana\pygeoip-0.3.1.egg
- %APPDATA%\maplebanana\ServerVerson.ini
- %APPDATA%\maplebanana\update.exe
- %APPDATA%\maplebanana\ssleay32.dll
- %APPDATA%\maplebanana\ss.txt
- %APPDATA%\maplebanana\proxylib.py
- %APPDATA%\maplebanana\proxy.bat
- %APPDATA%\maplebanana\packages.egg
- %APPDATA%\maplebanana\kylin.zip
- %APPDATA%\maplebanana\proxy.ini
- %APPDATA%\maplebanana\proxy.sh
- %APPDATA%\maplebanana\proxy.py
- %APPDATA%\maplebanana\proxy.pac
- %APPDATA%\maplebanana\begin\cert8.db
- %APPDATA%\maplebanana\certs\.15.112.154.crt
- %APPDATA%\maplebanana\certs\.125.26.199.crt
- %APPDATA%\maplebanana\certs\.125.21.123.crt
- %APPDATA%\maplebanana\certs\.151.152.144.crt
- %APPDATA%\maplebanana\certs\.194.72.122.crt
- %APPDATA%\maplebanana\certs\.194.68.122.crt
- %APPDATA%\maplebanana\certs\.194.140.168.crt
- %APPDATA%\maplebanana\certs\.125.205.199.crt
- %APPDATA%\maplebanana\certs\.117.239.121.crt
- %APPDATA%\maplebanana\certs\.112.2o7.net.crt
- %APPDATA%\maplebanana\certs\.105.95.121.crt
- %APPDATA%\maplebanana\certs\.117.240.243.crt
- %APPDATA%\maplebanana\certs\.117.255.234.crt
- %APPDATA%\maplebanana\certs\.117.250.134.crt
- %APPDATA%\maplebanana\certs\.117.242.240.crt
- %APPDATA%\maplebanana\certs\.githubusercontent.com.crt
- %APPDATA%\maplebanana\certs\.githubapp.com.crt
- %APPDATA%\maplebanana\certs\.github.io.crt
- %APPDATA%\maplebanana\certs\.gmail.com.crt
- %APPDATA%\maplebanana\certs\.google.com.crt
- %APPDATA%\maplebanana\certs\.google.ca.crt
- %APPDATA%\maplebanana\certs\.google-analytics.com.crt
- %APPDATA%\maplebanana\certs\.github.com.crt
- %APPDATA%\maplebanana\certs\.flickr.com.crt
- %APPDATA%\maplebanana\certs\.fastclick.net.crt
- %APPDATA%\maplebanana\certs\.facebook.net.crt
- %APPDATA%\maplebanana\certs\.fls.doubleclick.net.crt
- %APPDATA%\maplebanana\certs\.ggpht.com.crt
- %APPDATA%\maplebanana\certs\.gemini.yahoo.com.crt
- %APPDATA%\maplebanana\certs\.g.doubleclick.net.crt
- %APPDATA%\maplebanana\certs\.google.lv.crt
- %APPDATA%\maplebanana\certs\.gstatic.com.crt
- %APPDATA%\maplebanana\certs\.gravatar.com.crt
- %APPDATA%\maplebanana\certs\.googlevideo.com.crt
- %APPDATA%\maplebanana\certs\.iesnare.com.crt
- %APPDATA%\maplebanana\certs\.krxd.net.crt
- %APPDATA%\maplebanana\certs\.insightexpressai.com.crt
- %APPDATA%\maplebanana\certs\.imrworldwide.com.crt
- %APPDATA%\maplebanana\certs\.googleusercontent.com.crt
- %APPDATA%\maplebanana\certs\.googleapis.com.crt
- %APPDATA%\maplebanana\certs\.googleadservices.com.crt
- %APPDATA%\maplebanana\certs\.google.pl.crt
- %APPDATA%\maplebanana\certs\.googlecode.com.crt
- %APPDATA%\maplebanana\certs\.googletagservices.com.crt
- %APPDATA%\maplebanana\certs\.googletagmanager.com.crt
- %APPDATA%\maplebanana\certs\.googlesyndication.com.crt
- %APPDATA%\maplebanana\certs\.cloudflare.com.crt
- %APPDATA%\maplebanana\certs\.clients.google.com.crt
- %APPDATA%\maplebanana\certs\.client-channel.google.com.crt
- %APPDATA%\maplebanana\certs\.cloudfront.net.crt
- %APPDATA%\maplebanana\certs\.csdn.net.crt
- %APPDATA%\maplebanana\certs\.conviva.com.crt
- %APPDATA%\maplebanana\certs\.config.skype.com.crt
- %APPDATA%\maplebanana\certs\.channel.facebook.com.crt
- %APPDATA%\maplebanana\certs\.c.pack.google.com.crt
- %APPDATA%\maplebanana\certs\.burstbeacon.com.crt
- %APPDATA%\maplebanana\certs\.blueskyexhibits.com.crt
- %APPDATA%\maplebanana\certs\.c.youtube.com.crt
- %APPDATA%\maplebanana\certs\.chango.com.crt
- %APPDATA%\maplebanana\certs\.cdn.twitter.com.crt
- %APPDATA%\maplebanana\certs\.cdn.mozilla.net.crt
- %APPDATA%\maplebanana\certs\.data.mozilla.com.crt
- %APPDATA%\maplebanana\certs\.duapp.com.crt
- %APPDATA%\maplebanana\certs\.dropbox.com.crt
- %APPDATA%\maplebanana\certs\.drive.google.com.crt
- %APPDATA%\maplebanana\certs\.e.akamai.net.crt
- %APPDATA%\maplebanana\certs\.facebook.com.crt
- %APPDATA%\maplebanana\certs\.evernote.com.crt
- %APPDATA%\maplebanana\certs\.ehousechina.com.crt
- %APPDATA%\maplebanana\certs\.doubleverify.com.crt
- %APPDATA%\maplebanana\certs\.disqus.com.crt
- %APPDATA%\maplebanana\certs\.developers.google.com.crt
- %APPDATA%\maplebanana\certs\.desktop.qq.com.crt
- %APPDATA%\maplebanana\certs\.disquscdn.com.crt
- %APPDATA%\maplebanana\certs\.doubleclick.net.crt
- %APPDATA%\maplebanana\certs\.docs.google.com.crt
- %APPDATA%\maplebanana\certs\.dmtry.com.crt
- %APPDATA%\maplebanana\proxy.ini
- <DRIVERS>\etc\hosts
- '12#.#25.114.144':80
- 'www.yo##ube.com':443
- 'localhost':1037
- 'localhost':8086
- http://www.ba##u.com/ via 12#.#25.114.144
- DNS ASK www.yo##ube.com
- DNS ASK www.ba##u.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebcheckMonitor' WindowName: ''
- ClassName: '' WindowName: 'APPDATA\maplebanana\'
- ClassName: '' WindowName: 'maplebanana'