forked from Shadow0ps/solorigate_sample_source
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Decompressed Strings.txt
194 lines (190 loc) · 2.7 KB
/
Decompressed Strings.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
In order of appearance
Select * From Win32_NetworkAdapterConfiguration where IPEnabled=true
Description
MACAddress
DHCPEnabled
DHCPServer
DNSHostName
DNSDomainSuffixSearchOrder
DNSServerSearchOrder
IPAddress
IPSubnet
DefaultIPGateway
Select * From Win32_OperatingSystem
Caption
OSArchitecture
InstallDate
Organization
RegisteredUser
Version
[E] {0} {1} {2}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography
MachineGuid
10.0.0.0
255.0.0.0
172.16.0.0
255.240.0.0
192.168.0.0
255.255.0.0
224.0.0.0
240.0.0.0
fc00::
fe00::
fec0::
ffc0::
ff00::
ff00::
41.84.159.0
255.255.255.0
74.114.24.0
255.255.248.0
154.118.140.0
255.255.255.0
217.163.7.0
255.255.255.0
20.140.0.0
255.254.0.0
96.31.172.0
255.255.255.0
131.228.12.0
255.255.252.0
144.86.226.0
255.255.255.0
8.18.144.0
255.255.254.0
18.130.0.0
255.255.0.0
71.152.53.0
255.255.255.0
99.79.0.0
255.255.0.0
87.238.80.0
255.255.248.0
199.201.117.0
255.255.255.0
184.72.0.0
255.254.0.0
(?i)([^a-z]|^)(test)([^a-z]|$)
(?i)(solarwinds)
ReportWatcherRetry
ReportWatcherPostpone
api.solarwinds.com
avsvmcloud.com
appsync-api
eu-west-1
us-west-2
us-east-1
us-east-2
583da945-62af-10e8-4902-a8f205c72b2e
HKEY_CLASSES_ROOT
HKCR
HKEY_CURRENT_USER
HKCU
HKEY_LOCAL_MACHINE
HKLM
HKEY_USERS
HKU
HKEY_CURRENT_CONFIG
HKCC
HKEY_PERFOMANCE_DATA
HKPD
HKEY_DYN_DATA
HKDD
S-1-5-
-500
Administrator
Select * From Win32_UserAccount
SID
LocalAccount
true
SeRestorePrivilege
SeTakeOwnershipPrivilege
SYSTEM
4
5
3
Select * From Win32_SystemDriver
PathName
SYSTEM\CurrentControlSet\services
Start
Start
SYSTEM\CurrentControlSet\services
Start
Start
[{0,5}] {1}
Select * From Win32_Process
GetOwner
[{0,5}] {1,-16} {2} {3,5} {4}\{5}
ProcessID
Name
ParentProcessID
Administrator
{0} {1} HTTP/{2}
"\{[0-9a-f-]{36}\}"|"[0-9a-f]{32}"|"[0-9a-f]{16}"
If-None-Match
"userId":"{0}",
"sessionId":"{0}",
"steps":[
"Timestamp":"\/Date({0})\/",
"Index":{0},
"EventType":"Orion",
"EventName":"EventManager",
"DurationMs":{0},
"Succeeded":true,
"Message":"{0}"
application/json
application/octet-stream
-root
-cert
-universal_ca
-ca
-primary_ca
-timestamp
-global
-secureca
pki/crl/{0}{1}{2}.crl
Bold
BoldItalic
ExtraBold
ExtraBoldItalic
Italic
Light
LightItalic
Regular
SemiBold
SemiBoldItalic
opensans
noto
freefont
SourceCodePro
SourceSerifPro
SourceHanSans
SourceHanSerif
fonts/woff/{0}-{1}-{2}-webfont{3}.woff2
fonts/woff/{0}-{1}-{2}{3}.woff2
SolarWinds
.CortexPlugin
.Orion
Wireless
UI
Widgets
NPM
Apollo
CloudMonitoring
Nodes
Volumes
Interfaces
Components
swip/upd/
.xml
swip/Upload.ashx
swip/Events
Microsoft-CryptoAPI/
SolarWindsOrionImprovementClient/
\OrionImprovement\SolarWinds.OrionImprovement.exe
3.0.0.382
rq3gsalt6u1iyfzop572d49bnx8cvmkewhj
0_-.
ph2eifo3n5utg1j8d94qrvbmk0sal76c
0123456789abcdefghijklmnopqrstuvwxyz-_.
SeShutdownPrivilege