Dynamic Analysis Report |
Classification: Ransomware, Downloader, Trojan |
A959.tmp.exe
Created at 2019-07-08T06:47:00
Remarks (2/3)
(0x200000e): The overall sleep time of all monitored processes was truncated from "40 seconds" to "10 seconds" to reveal dormant functionality.
(0x200003a): 2 tasks were rescheduled ahead of time to reveal dormant functionality.
Remarks
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\A959.tmp.exe | Sample File | Binary |
Malicious
|
...
|
Severity |
Blacklisted
|
First Seen | 2019-07-05 22:53 (UTC+2) |
Last Seen | 2019-07-08 06:03 (UTC+2) |
Names | Win32.Trojan.Stop |
Families | Stop |
Classification | Trojan |
Image Base | 0x400000 |
Entry Point | 0x44b791 |
Size Of Code | 0x64400 |
Size Of Initialized Data | 0x28400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-02-10 10:14:25+00:00 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x6431c | 0x64400 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.79 |
.rdata | 0x466000 | 0x378e | 0x3800 | 0x64800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.12 |
.data | 0x46a000 | 0x1fe04 | 0x2000 | 0x68000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.28 |
.rsrc | 0x48a000 | 0x43c0 | 0x4400 | 0x6a000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.28 |
.reloc | 0x48f000 | 0x14c2 | 0x1600 | 0x6e400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.62 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExpandEnvironmentStringsW | 0x0 | 0x466000 | 0x68db4 | 0x675b4 | 0x11d |
GlobalAlloc | 0x0 | 0x466004 | 0x68db8 | 0x675b8 | 0x2b3 |
GetDriveTypeW | 0x0 | 0x466008 | 0x68dbc | 0x675bc | 0x1d3 |
GetModuleHandleW | 0x0 | 0x46600c | 0x68dc0 | 0x675c0 | 0x218 |
GetSystemDirectoryW | 0x0 | 0x466010 | 0x68dc4 | 0x675c4 | 0x270 |
GetCommandLineA | 0x0 | 0x466014 | 0x68dc8 | 0x675c8 | 0x186 |
SetEnvironmentVariableW | 0x0 | 0x466018 | 0x68dcc | 0x675cc | 0x457 |
GetFirmwareEnvironmentVariableA | 0x0 | 0x46601c | 0x68dd0 | 0x675d0 | 0x1f6 |
HeapLock | 0x0 | 0x466020 | 0x68dd4 | 0x675d4 | 0x2d0 |
ReplaceFileW | 0x0 | 0x466024 | 0x68dd8 | 0x675d8 | 0x40b |
EnumTimeFormatsA | 0x0 | 0x466028 | 0x68ddc | 0x675dc | 0x110 |
GetVolumePathNamesForVolumeNameW | 0x0 | 0x46602c | 0x68de0 | 0x675e0 | 0x2ad |
ReadConsoleW | 0x0 | 0x466030 | 0x68de4 | 0x675e4 | 0x3be |
GetProcAddress | 0x0 | 0x466034 | 0x68de8 | 0x675e8 | 0x245 |
LoadLibraryA | 0x0 | 0x466038 | 0x68dec | 0x675ec | 0x33c |
SetEvent | 0x0 | 0x46603c | 0x68df0 | 0x675f0 | 0x459 |
LocalAlloc | 0x0 | 0x466040 | 0x68df4 | 0x675f4 | 0x344 |
IsProcessorFeaturePresent | 0x0 | 0x466044 | 0x68df8 | 0x675f8 | 0x304 |
GetLastError | 0x0 | 0x466048 | 0x68dfc | 0x675fc | 0x202 |
GetOverlappedResult | 0x0 | 0x46604c | 0x68e00 | 0x67600 | 0x238 |
WaitForSingleObject | 0x0 | 0x466050 | 0x68e04 | 0x67604 | 0x4f9 |
WaitNamedPipeW | 0x0 | 0x466054 | 0x68e08 | 0x67608 | 0x500 |
FormatMessageW | 0x0 | 0x466058 | 0x68e0c | 0x6760c | 0x15e |
DefineDosDeviceA | 0x0 | 0x46605c | 0x68e10 | 0x67610 | 0xcc |
FindFirstVolumeMountPointA | 0x0 | 0x466060 | 0x68e14 | 0x67614 | 0x13d |
GetCurrentActCtx | 0x0 | 0x466064 | 0x68e18 | 0x67618 | 0x1bb |
lstrcatW | 0x0 | 0x466068 | 0x68e1c | 0x6761c | 0x53f |
WriteConsoleOutputCharacterW | 0x0 | 0x46606c | 0x68e20 | 0x67620 | 0x522 |
GetProfileSectionA | 0x0 | 0x466070 | 0x68e24 | 0x67624 | 0x25a |
IsValidLocale | 0x0 | 0x466074 | 0x68e28 | 0x67628 | 0x30c |
EnumSystemLocalesA | 0x0 | 0x466078 | 0x68e2c | 0x6762c | 0x10d |
GetLocaleInfoA | 0x0 | 0x46607c | 0x68e30 | 0x67630 | 0x204 |
GetUserDefaultLCID | 0x0 | 0x466080 | 0x68e34 | 0x67634 | 0x29b |
CloseHandle | 0x0 | 0x466084 | 0x68e38 | 0x67638 | 0x52 |
RaiseException | 0x0 | 0x466088 | 0x68e3c | 0x6763c | 0x3b1 |
WriteConsoleW | 0x0 | 0x46608c | 0x68e40 | 0x67640 | 0x524 |
SetStdHandle | 0x0 | 0x466090 | 0x68e44 | 0x67644 | 0x487 |
ReadFile | 0x0 | 0x466094 | 0x68e48 | 0x67648 | 0x3c0 |
FlushFileBuffers | 0x0 | 0x466098 | 0x68e4c | 0x6764c | 0x157 |
HeapFree | 0x0 | 0x46609c | 0x68e50 | 0x67650 | 0x2cf |
ExitProcess | 0x0 | 0x4660a0 | 0x68e54 | 0x67654 | 0x119 |
DecodePointer | 0x0 | 0x4660a4 | 0x68e58 | 0x67658 | 0xca |
HeapSetInformation | 0x0 | 0x4660a8 | 0x68e5c | 0x6765c | 0x2d3 |
GetStartupInfoW | 0x0 | 0x4660ac | 0x68e60 | 0x67660 | 0x263 |
HeapCreate | 0x0 | 0x4660b0 | 0x68e64 | 0x67664 | 0x2cd |
HeapDestroy | 0x0 | 0x4660b4 | 0x68e68 | 0x67668 | 0x2ce |
HeapAlloc | 0x0 | 0x4660b8 | 0x68e6c | 0x6766c | 0x2cb |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4660bc | 0x68e70 | 0x67670 | 0x2e3 |
DeleteCriticalSection | 0x0 | 0x4660c0 | 0x68e74 | 0x67674 | 0xd1 |
LeaveCriticalSection | 0x0 | 0x4660c4 | 0x68e78 | 0x67678 | 0x339 |
FatalAppExitA | 0x0 | 0x4660c8 | 0x68e7c | 0x6767c | 0x120 |
EnterCriticalSection | 0x0 | 0x4660cc | 0x68e80 | 0x67680 | 0xee |
EncodePointer | 0x0 | 0x4660d0 | 0x68e84 | 0x67684 | 0xea |
SetConsoleCtrlHandler | 0x0 | 0x4660d4 | 0x68e88 | 0x67688 | 0x42d |
FreeLibrary | 0x0 | 0x4660d8 | 0x68e8c | 0x6768c | 0x162 |
InterlockedExchange | 0x0 | 0x4660dc | 0x68e90 | 0x67690 | 0x2ec |
LoadLibraryW | 0x0 | 0x4660e0 | 0x68e94 | 0x67694 | 0x33f |
GetLocaleInfoW | 0x0 | 0x4660e4 | 0x68e98 | 0x67698 | 0x206 |
UnhandledExceptionFilter | 0x0 | 0x4660e8 | 0x68e9c | 0x6769c | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x4660ec | 0x68ea0 | 0x676a0 | 0x4a5 |
IsDebuggerPresent | 0x0 | 0x4660f0 | 0x68ea4 | 0x676a4 | 0x300 |
TerminateProcess | 0x0 | 0x4660f4 | 0x68ea8 | 0x676a8 | 0x4c0 |
GetCurrentProcess | 0x0 | 0x4660f8 | 0x68eac | 0x676ac | 0x1c0 |
TlsAlloc | 0x0 | 0x4660fc | 0x68eb0 | 0x676b0 | 0x4c5 |
TlsGetValue | 0x0 | 0x466100 | 0x68eb4 | 0x676b4 | 0x4c7 |
TlsSetValue | 0x0 | 0x466104 | 0x68eb8 | 0x676b8 | 0x4c8 |
TlsFree | 0x0 | 0x466108 | 0x68ebc | 0x676bc | 0x4c6 |
InterlockedIncrement | 0x0 | 0x46610c | 0x68ec0 | 0x676c0 | 0x2ef |
SetLastError | 0x0 | 0x466110 | 0x68ec4 | 0x676c4 | 0x473 |
GetCurrentThreadId | 0x0 | 0x466114 | 0x68ec8 | 0x676c8 | 0x1c5 |
InterlockedDecrement | 0x0 | 0x466118 | 0x68ecc | 0x676cc | 0x2eb |
GetCurrentThread | 0x0 | 0x46611c | 0x68ed0 | 0x676d0 | 0x1c4 |
WriteFile | 0x0 | 0x466120 | 0x68ed4 | 0x676d4 | 0x525 |
GetStdHandle | 0x0 | 0x466124 | 0x68ed8 | 0x676d8 | 0x264 |
GetModuleFileNameW | 0x0 | 0x466128 | 0x68edc | 0x676dc | 0x214 |
SetHandleCount | 0x0 | 0x46612c | 0x68ee0 | 0x676e0 | 0x46f |
GetFileType | 0x0 | 0x466130 | 0x68ee4 | 0x676e4 | 0x1f3 |
GetModuleFileNameA | 0x0 | 0x466134 | 0x68ee8 | 0x676e8 | 0x213 |
FreeEnvironmentStringsW | 0x0 | 0x466138 | 0x68eec | 0x676ec | 0x161 |
WideCharToMultiByte | 0x0 | 0x46613c | 0x68ef0 | 0x676f0 | 0x511 |
GetEnvironmentStringsW | 0x0 | 0x466140 | 0x68ef4 | 0x676f4 | 0x1da |
QueryPerformanceCounter | 0x0 | 0x466144 | 0x68ef8 | 0x676f8 | 0x3a7 |
GetTickCount | 0x0 | 0x466148 | 0x68efc | 0x676fc | 0x293 |
GetCurrentProcessId | 0x0 | 0x46614c | 0x68f00 | 0x67700 | 0x1c1 |
GetSystemTimeAsFileTime | 0x0 | 0x466150 | 0x68f04 | 0x67704 | 0x279 |
Sleep | 0x0 | 0x466154 | 0x68f08 | 0x67708 | 0x4b2 |
GetCPInfo | 0x0 | 0x466158 | 0x68f0c | 0x6770c | 0x172 |
GetACP | 0x0 | 0x46615c | 0x68f10 | 0x67710 | 0x168 |
GetOEMCP | 0x0 | 0x466160 | 0x68f14 | 0x67714 | 0x237 |
IsValidCodePage | 0x0 | 0x466164 | 0x68f18 | 0x67718 | 0x30a |
HeapSize | 0x0 | 0x466168 | 0x68f1c | 0x6771c | 0x2d4 |
RtlUnwind | 0x0 | 0x46616c | 0x68f20 | 0x67720 | 0x418 |
MultiByteToWideChar | 0x0 | 0x466170 | 0x68f24 | 0x67724 | 0x367 |
SetFilePointer | 0x0 | 0x466174 | 0x68f28 | 0x67728 | 0x466 |
GetConsoleCP | 0x0 | 0x466178 | 0x68f2c | 0x6772c | 0x19a |
GetConsoleMode | 0x0 | 0x46617c | 0x68f30 | 0x67730 | 0x1ac |
HeapReAlloc | 0x0 | 0x466180 | 0x68f34 | 0x67734 | 0x2d2 |
LCMapStringW | 0x0 | 0x466184 | 0x68f38 | 0x67738 | 0x32d |
GetStringTypeW | 0x0 | 0x466188 | 0x68f3c | 0x6773c | 0x269 |
CreateFileW | 0x0 | 0x46618c | 0x68f40 | 0x67740 | 0x8f |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetMenuStringA | 0x0 | 0x46619c | 0x68f50 | 0x67750 | 0x157 |
SendMessageTimeoutW | 0x0 | 0x4661a0 | 0x68f54 | 0x67754 | 0x27b |
GrayStringW | 0x0 | 0x4661a4 | 0x68f58 | 0x67758 | 0x1a8 |
GetMessageExtraInfo | 0x0 | 0x4661a8 | 0x68f5c | 0x6775c | 0x15a |
GetScrollBarInfo | 0x0 | 0x4661ac | 0x68f60 | 0x67760 | 0x174 |
PostMessageW | 0x0 | 0x4661b0 | 0x68f64 | 0x67764 | 0x236 |
SetMenuItemInfoA | 0x0 | 0x4661b4 | 0x68f68 | 0x67768 | 0x2a1 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
AlphaBlend | 0x0 | 0x466194 | 0x68f48 | 0x67748 | 0x0 |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
a959.tmp.exe | 1 | 0x00400000 | 0x00490FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00678280 | 0x006BE377 | Marked Executable | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00678280 | 0x006BE377 | Content Changed | - | 32-bit | 0x006790C5 |
![]() |
![]() |
...
|
buffer | 1 | 0x00678280 | 0x006BE377 | Content Changed | - | 32-bit | 0x006799E5 |
![]() |
![]() |
...
|
a959.tmp.exe | 1 | 0x00400000 | 0x00490FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
Threat Name | Severity |
---|---|
Trojan.GenericKD.41435343 |
Malicious
|
C:\Windows\System32\drivers\etc\hosts | Modified File | Text |
Malicious
|
...
|
Threat Name | Severity |
---|---|
Gen:Trojan.Qhost.1 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\d5bfbe52-943a-4f73-97b1-39918fa00598\updatewin1.exe | Downloaded File | Binary |
Malicious
|
...
|
Severity |
Blacklisted
|
First Seen | 2019-01-16 22:21 (UTC+1) |
Last Seen | 2019-07-02 07:29 (UTC+2) |
Names | Win32.Trojan.Kryptik |
Families | Kryptik |
Classification | Trojan |
Image Base | 0x400000 |
Entry Point | 0x402d76 |
Size Of Code | 0x1c200 |
Size Of Initialized Data | 0x2c200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-07-24 12:23:54+00:00 |
FileVersion | 7.7.7.18 |
InternalName | rawudiyeh.exe |
LegalCopyright | Copyright (C) 2018, sacuwedimufoy |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1c07e | 0x1c200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x41e000 | 0x463e | 0x4800 | 0x1c600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.26 |
.data | 0x423000 | 0x1c6a8 | 0x17400 | 0x20e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.83 |
.rsrc | 0x440000 | 0xa578 | 0xa600 | 0x38200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.88 |
.reloc | 0x44b000 | 0x1968 | 0x1a00 | 0x42800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.34 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitThread | 0x0 | 0x41e028 | 0x21afc | 0x200fc | 0x105 |
GetStartupInfoW | 0x0 | 0x41e02c | 0x21b00 | 0x20100 | 0x23a |
GetLastError | 0x0 | 0x41e030 | 0x21b04 | 0x20104 | 0x1e6 |
GetProcAddress | 0x0 | 0x41e034 | 0x21b08 | 0x20108 | 0x220 |
CreateJobSet | 0x0 | 0x41e038 | 0x21b0c | 0x2010c | 0x87 |
GlobalFree | 0x0 | 0x41e03c | 0x21b10 | 0x20110 | 0x28c |
LoadLibraryA | 0x0 | 0x41e040 | 0x21b14 | 0x20114 | 0x2f1 |
OpenWaitableTimerW | 0x0 | 0x41e044 | 0x21b18 | 0x20118 | 0x339 |
AddAtomA | 0x0 | 0x41e048 | 0x21b1c | 0x2011c | 0x3 |
FindFirstChangeNotificationA | 0x0 | 0x41e04c | 0x21b20 | 0x20120 | 0x11b |
VirtualProtect | 0x0 | 0x41e050 | 0x21b24 | 0x20124 | 0x45a |
GetCurrentDirectoryA | 0x0 | 0x41e054 | 0x21b28 | 0x20128 | 0x1a7 |
GetACP | 0x0 | 0x41e058 | 0x21b2c | 0x2012c | 0x152 |
InterlockedPushEntrySList | 0x0 | 0x41e05c | 0x21b30 | 0x20130 | 0x2c2 |
CompareStringW | 0x0 | 0x41e060 | 0x21b34 | 0x20134 | 0x55 |
CompareStringA | 0x0 | 0x41e064 | 0x21b38 | 0x20138 | 0x52 |
CreateFileA | 0x0 | 0x41e068 | 0x21b3c | 0x2013c | 0x78 |
GetTimeZoneInformation | 0x0 | 0x41e06c | 0x21b40 | 0x20140 | 0x26b |
WriteConsoleW | 0x0 | 0x41e070 | 0x21b44 | 0x20144 | 0x48c |
GetConsoleOutputCP | 0x0 | 0x41e074 | 0x21b48 | 0x20148 | 0x199 |
WriteConsoleA | 0x0 | 0x41e078 | 0x21b4c | 0x2014c | 0x482 |
CloseHandle | 0x0 | 0x41e07c | 0x21b50 | 0x20150 | 0x43 |
IsValidLocale | 0x0 | 0x41e080 | 0x21b54 | 0x20154 | 0x2dd |
EnumSystemLocalesA | 0x0 | 0x41e084 | 0x21b58 | 0x20158 | 0xf8 |
GetUserDefaultLCID | 0x0 | 0x41e088 | 0x21b5c | 0x2015c | 0x26d |
GetSystemTimeAdjustment | 0x0 | 0x41e08c | 0x21b60 | 0x20160 | 0x24e |
GetSystemTimes | 0x0 | 0x41e090 | 0x21b64 | 0x20164 | 0x250 |
GetTickCount | 0x0 | 0x41e094 | 0x21b68 | 0x20168 | 0x266 |
FreeEnvironmentStringsA | 0x0 | 0x41e098 | 0x21b6c | 0x2016c | 0x14a |
GetComputerNameW | 0x0 | 0x41e09c | 0x21b70 | 0x20170 | 0x178 |
FindCloseChangeNotification | 0x0 | 0x41e0a0 | 0x21b74 | 0x20174 | 0x11a |
FindResourceExW | 0x0 | 0x41e0a4 | 0x21b78 | 0x20178 | 0x138 |
GetCPInfo | 0x0 | 0x41e0a8 | 0x21b7c | 0x2017c | 0x15b |
SetProcessShutdownParameters | 0x0 | 0x41e0ac | 0x21b80 | 0x20180 | 0x3f9 |
GetModuleHandleExA | 0x0 | 0x41e0b0 | 0x21b84 | 0x20184 | 0x1f7 |
GetDateFormatA | 0x0 | 0x41e0b4 | 0x21b88 | 0x20188 | 0x1ae |
GetTimeFormatA | 0x0 | 0x41e0b8 | 0x21b8c | 0x2018c | 0x268 |
GetStringTypeW | 0x0 | 0x41e0bc | 0x21b90 | 0x20190 | 0x240 |
GetStringTypeA | 0x0 | 0x41e0c0 | 0x21b94 | 0x20194 | 0x23d |
LCMapStringW | 0x0 | 0x41e0c4 | 0x21b98 | 0x20198 | 0x2e3 |
GetCommandLineA | 0x0 | 0x41e0c8 | 0x21b9c | 0x2019c | 0x16f |
GetStartupInfoA | 0x0 | 0x41e0cc | 0x21ba0 | 0x201a0 | 0x239 |
RaiseException | 0x0 | 0x41e0d0 | 0x21ba4 | 0x201a4 | 0x35a |
RtlUnwind | 0x0 | 0x41e0d4 | 0x21ba8 | 0x201a8 | 0x392 |
TerminateProcess | 0x0 | 0x41e0d8 | 0x21bac | 0x201ac | 0x42d |
GetCurrentProcess | 0x0 | 0x41e0dc | 0x21bb0 | 0x201b0 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x41e0e0 | 0x21bb4 | 0x201b4 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x41e0e4 | 0x21bb8 | 0x201b8 | 0x415 |
IsDebuggerPresent | 0x0 | 0x41e0e8 | 0x21bbc | 0x201bc | 0x2d1 |
HeapAlloc | 0x0 | 0x41e0ec | 0x21bc0 | 0x201c0 | 0x29d |
HeapFree | 0x0 | 0x41e0f0 | 0x21bc4 | 0x201c4 | 0x2a1 |
EnterCriticalSection | 0x0 | 0x41e0f4 | 0x21bc8 | 0x201c8 | 0xd9 |
LeaveCriticalSection | 0x0 | 0x41e0f8 | 0x21bcc | 0x201cc | 0x2ef |
SetHandleCount | 0x0 | 0x41e0fc | 0x21bd0 | 0x201d0 | 0x3e8 |
GetStdHandle | 0x0 | 0x41e100 | 0x21bd4 | 0x201d4 | 0x23b |
GetFileType | 0x0 | 0x41e104 | 0x21bd8 | 0x201d8 | 0x1d7 |
DeleteCriticalSection | 0x0 | 0x41e108 | 0x21bdc | 0x201dc | 0xbe |
GetModuleHandleW | 0x0 | 0x41e10c | 0x21be0 | 0x201e0 | 0x1f9 |
Sleep | 0x0 | 0x41e110 | 0x21be4 | 0x201e4 | 0x421 |
ExitProcess | 0x0 | 0x41e114 | 0x21be8 | 0x201e8 | 0x104 |
WriteFile | 0x0 | 0x41e118 | 0x21bec | 0x201ec | 0x48d |
GetModuleFileNameA | 0x0 | 0x41e11c | 0x21bf0 | 0x201f0 | 0x1f4 |
GetEnvironmentStrings | 0x0 | 0x41e120 | 0x21bf4 | 0x201f4 | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x41e124 | 0x21bf8 | 0x201f8 | 0x14b |
WideCharToMultiByte | 0x0 | 0x41e128 | 0x21bfc | 0x201fc | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x41e12c | 0x21c00 | 0x20200 | 0x1c1 |
TlsGetValue | 0x0 | 0x41e130 | 0x21c04 | 0x20204 | 0x434 |
TlsAlloc | 0x0 | 0x41e134 | 0x21c08 | 0x20208 | 0x432 |
TlsSetValue | 0x0 | 0x41e138 | 0x21c0c | 0x2020c | 0x435 |
TlsFree | 0x0 | 0x41e13c | 0x21c10 | 0x20210 | 0x433 |
InterlockedIncrement | 0x0 | 0x41e140 | 0x21c14 | 0x20214 | 0x2c0 |
SetLastError | 0x0 | 0x41e144 | 0x21c18 | 0x20218 | 0x3ec |
GetCurrentThreadId | 0x0 | 0x41e148 | 0x21c1c | 0x2021c | 0x1ad |
InterlockedDecrement | 0x0 | 0x41e14c | 0x21c20 | 0x20220 | 0x2bc |
GetCurrentThread | 0x0 | 0x41e150 | 0x21c24 | 0x20224 | 0x1ac |
HeapCreate | 0x0 | 0x41e154 | 0x21c28 | 0x20228 | 0x29f |
HeapDestroy | 0x0 | 0x41e158 | 0x21c2c | 0x2022c | 0x2a0 |
VirtualFree | 0x0 | 0x41e15c | 0x21c30 | 0x20230 | 0x457 |
QueryPerformanceCounter | 0x0 | 0x41e160 | 0x21c34 | 0x20234 | 0x354 |
GetCurrentProcessId | 0x0 | 0x41e164 | 0x21c38 | 0x20238 | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x41e168 | 0x21c3c | 0x2023c | 0x24f |
FatalAppExitA | 0x0 | 0x41e16c | 0x21c40 | 0x20240 | 0x10b |
VirtualAlloc | 0x0 | 0x41e170 | 0x21c44 | 0x20244 | 0x454 |
HeapReAlloc | 0x0 | 0x41e174 | 0x21c48 | 0x20248 | 0x2a4 |
MultiByteToWideChar | 0x0 | 0x41e178 | 0x21c4c | 0x2024c | 0x31a |
ReadFile | 0x0 | 0x41e17c | 0x21c50 | 0x20250 | 0x368 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41e180 | 0x21c54 | 0x20254 | 0x2b5 |
HeapSize | 0x0 | 0x41e184 | 0x21c58 | 0x20258 | 0x2a6 |
SetConsoleCtrlHandler | 0x0 | 0x41e188 | 0x21c5c | 0x2025c | 0x3a7 |
FreeLibrary | 0x0 | 0x41e18c | 0x21c60 | 0x20260 | 0x14c |
InterlockedExchange | 0x0 | 0x41e190 | 0x21c64 | 0x20264 | 0x2bd |
GetOEMCP | 0x0 | 0x41e194 | 0x21c68 | 0x20268 | 0x213 |
IsValidCodePage | 0x0 | 0x41e198 | 0x21c6c | 0x2026c | 0x2db |
GetConsoleCP | 0x0 | 0x41e19c | 0x21c70 | 0x20270 | 0x183 |
GetConsoleMode | 0x0 | 0x41e1a0 | 0x21c74 | 0x20274 | 0x195 |
FlushFileBuffers | 0x0 | 0x41e1a4 | 0x21c78 | 0x20278 | 0x141 |
SetFilePointer | 0x0 | 0x41e1a8 | 0x21c7c | 0x2027c | 0x3df |
SetStdHandle | 0x0 | 0x41e1ac | 0x21c80 | 0x20280 | 0x3fc |
GetLocaleInfoW | 0x0 | 0x41e1b0 | 0x21c84 | 0x20284 | 0x1ea |
GetLocaleInfoA | 0x0 | 0x41e1b4 | 0x21c88 | 0x20288 | 0x1e8 |
LCMapStringA | 0x0 | 0x41e1b8 | 0x21c8c | 0x2028c | 0x2e1 |
SetEnvironmentVariableA | 0x0 | 0x41e1bc | 0x21c90 | 0x20290 | 0x3d0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseClipboard | 0x0 | 0x41e1d8 | 0x21cac | 0x202ac | 0x47 |
BeginPaint | 0x0 | 0x41e1dc | 0x21cb0 | 0x202b0 | 0xe |
CallMsgFilterW | 0x0 | 0x41e1e0 | 0x21cb4 | 0x202b4 | 0x1a |
PeekMessageA | 0x0 | 0x41e1e4 | 0x21cb8 | 0x202b8 | 0x21b |
MapVirtualKeyExW | 0x0 | 0x41e1e8 | 0x21cbc | 0x202bc | 0x1f1 |
RegisterRawInputDevices | 0x0 | 0x41e1ec | 0x21cc0 | 0x202c0 | 0x242 |
GetClipboardSequenceNumber | 0x0 | 0x41e1f0 | 0x21cc4 | 0x202c4 | 0x113 |
CountClipboardFormats | 0x0 | 0x41e1f4 | 0x21cc8 | 0x202c8 | 0x50 |
GetDialogBaseUnits | 0x0 | 0x41e1f8 | 0x21ccc | 0x202cc | 0x11d |
GetClassLongW | 0x0 | 0x41e1fc | 0x21cd0 | 0x202d0 | 0x109 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PolyTextOutW | 0x0 | 0x41e000 | 0x21ad4 | 0x200d4 | 0x23c |
CreateCompatibleDC | 0x0 | 0x41e004 | 0x21ad8 | 0x200d8 | 0x2e |
Rectangle | 0x0 | 0x41e008 | 0x21adc | 0x200dc | 0x246 |
SetStretchBltMode | 0x0 | 0x41e00c | 0x21ae0 | 0x200e0 | 0x289 |
SetPixelV | 0x0 | 0x41e010 | 0x21ae4 | 0x200e4 | 0x284 |
GetClipBox | 0x0 | 0x41e014 | 0x21ae8 | 0x200e8 | 0x1aa |
CreateDiscardableBitmap | 0x0 | 0x41e018 | 0x21aec | 0x200ec | 0x35 |
StrokeAndFillPath | 0x0 | 0x41e01c | 0x21af0 | 0x200f0 | 0x29c |
GetBitmapBits | 0x0 | 0x41e020 | 0x21af4 | 0x200f4 | 0x191 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x41e1c4 | 0x21c98 | 0x20298 | 0x118 |
ShellAboutW | 0x0 | 0x41e1c8 | 0x21c9c | 0x2029c | 0x110 |
DuplicateIcon | 0x0 | 0x41e1cc | 0x21ca0 | 0x202a0 | 0x23 |
DragQueryFileA | 0x0 | 0x41e1d0 | 0x21ca4 | 0x202a4 | 0x1e |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
updatewin1.exe | 6 | 0x00400000 | 0x0044CFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 6 | 0x00295000 | 0x00295FFF | Marked Executable | - | 32-bit | - |
![]() |
![]() |
...
|
updatewin1.exe | 6 | 0x00400000 | 0x0044CFFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 8 | 0x002B5000 | 0x002B5FFF | Marked Executable | - | 32-bit | - |
![]() |
![]() |
...
|
Threat Name | Severity |
---|---|
Trojan.GenericKD.31534187 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\d5bfbe52-943a-4f73-97b1-39918fa00598\updatewin2.exe | Downloaded File | Binary |
Malicious
|
...
|
Severity |
Blacklisted
|
First Seen | 2019-01-16 22:21 (UTC+1) |
Last Seen | 2019-07-02 07:29 (UTC+2) |
Names | Win32.Trojan.Kryptik |
Families | Kryptik |
Classification | Trojan |
Image Base | 0x400000 |
Entry Point | 0x402d64 |
Size Of Code | 0x1c200 |
Size Of Initialized Data | 0x2c800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-11-21 06:08:45+00:00 |
FileVersion | 5.3.7.82 |
InternalName | gigifaw.exe |
LegalCopyright | Copyright (C) 2018, guvaxiz |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1c03e | 0x1c200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x41e000 | 0x45ec | 0x4600 | 0x1c600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.34 |
.data | 0x423000 | 0x1cde8 | 0x17c00 | 0x20c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.8 |
.rsrc | 0x440000 | 0xa724 | 0xa800 | 0x38800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.88 |
.reloc | 0x44b000 | 0x195c | 0x1a00 | 0x43000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.33 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitThread | 0x0 | 0x41e024 | 0x21ae8 | 0x200e8 | 0x105 |
GetStartupInfoW | 0x0 | 0x41e028 | 0x21aec | 0x200ec | 0x23a |
GetLastError | 0x0 | 0x41e02c | 0x21af0 | 0x200f0 | 0x1e6 |
GetProcAddress | 0x0 | 0x41e030 | 0x21af4 | 0x200f4 | 0x220 |
GlobalFree | 0x0 | 0x41e034 | 0x21af8 | 0x200f8 | 0x28c |
LoadLibraryA | 0x0 | 0x41e038 | 0x21afc | 0x200fc | 0x2f1 |
AddAtomA | 0x0 | 0x41e03c | 0x21b00 | 0x20100 | 0x3 |
FindFirstChangeNotificationA | 0x0 | 0x41e040 | 0x21b04 | 0x20104 | 0x11b |
VirtualProtect | 0x0 | 0x41e044 | 0x21b08 | 0x20108 | 0x45a |
GetCurrentDirectoryA | 0x0 | 0x41e048 | 0x21b0c | 0x2010c | 0x1a7 |
SetProcessShutdownParameters | 0x0 | 0x41e04c | 0x21b10 | 0x20110 | 0x3f9 |
GetACP | 0x0 | 0x41e050 | 0x21b14 | 0x20114 | 0x152 |
CompareStringA | 0x0 | 0x41e054 | 0x21b18 | 0x20118 | 0x52 |
CreateFileA | 0x0 | 0x41e058 | 0x21b1c | 0x2011c | 0x78 |
GetTimeZoneInformation | 0x0 | 0x41e05c | 0x21b20 | 0x20120 | 0x26b |
WriteConsoleW | 0x0 | 0x41e060 | 0x21b24 | 0x20124 | 0x48c |
GetConsoleOutputCP | 0x0 | 0x41e064 | 0x21b28 | 0x20128 | 0x199 |
WriteConsoleA | 0x0 | 0x41e068 | 0x21b2c | 0x2012c | 0x482 |
CloseHandle | 0x0 | 0x41e06c | 0x21b30 | 0x20130 | 0x43 |
IsValidLocale | 0x0 | 0x41e070 | 0x21b34 | 0x20134 | 0x2dd |
EnumSystemLocalesA | 0x0 | 0x41e074 | 0x21b38 | 0x20138 | 0xf8 |
GetUserDefaultLCID | 0x0 | 0x41e078 | 0x21b3c | 0x2013c | 0x26d |
GetDateFormatA | 0x0 | 0x41e07c | 0x21b40 | 0x20140 | 0x1ae |
GetTimeFormatA | 0x0 | 0x41e080 | 0x21b44 | 0x20144 | 0x268 |
InitAtomTable | 0x0 | 0x41e084 | 0x21b48 | 0x20148 | 0x2ae |
GetSystemTimes | 0x0 | 0x41e088 | 0x21b4c | 0x2014c | 0x250 |
GetTickCount | 0x0 | 0x41e08c | 0x21b50 | 0x20150 | 0x266 |
FreeEnvironmentStringsA | 0x0 | 0x41e090 | 0x21b54 | 0x20154 | 0x14a |
GetComputerNameW | 0x0 | 0x41e094 | 0x21b58 | 0x20158 | 0x178 |
FindCloseChangeNotification | 0x0 | 0x41e098 | 0x21b5c | 0x2015c | 0x11a |
FindResourceExW | 0x0 | 0x41e09c | 0x21b60 | 0x20160 | 0x138 |
CompareStringW | 0x0 | 0x41e0a0 | 0x21b64 | 0x20164 | 0x55 |
GetCPInfo | 0x0 | 0x41e0a4 | 0x21b68 | 0x20168 | 0x15b |
GetStringTypeW | 0x0 | 0x41e0a8 | 0x21b6c | 0x2016c | 0x240 |
GetStringTypeA | 0x0 | 0x41e0ac | 0x21b70 | 0x20170 | 0x23d |
LCMapStringW | 0x0 | 0x41e0b0 | 0x21b74 | 0x20174 | 0x2e3 |
LCMapStringA | 0x0 | 0x41e0b4 | 0x21b78 | 0x20178 | 0x2e1 |
GetLocaleInfoA | 0x0 | 0x41e0b8 | 0x21b7c | 0x2017c | 0x1e8 |
GetCommandLineA | 0x0 | 0x41e0bc | 0x21b80 | 0x20180 | 0x16f |
GetStartupInfoA | 0x0 | 0x41e0c0 | 0x21b84 | 0x20184 | 0x239 |
RaiseException | 0x0 | 0x41e0c4 | 0x21b88 | 0x20188 | 0x35a |
RtlUnwind | 0x0 | 0x41e0c8 | 0x21b8c | 0x2018c | 0x392 |
TerminateProcess | 0x0 | 0x41e0cc | 0x21b90 | 0x20190 | 0x42d |
GetCurrentProcess | 0x0 | 0x41e0d0 | 0x21b94 | 0x20194 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x41e0d4 | 0x21b98 | 0x20198 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x41e0d8 | 0x21b9c | 0x2019c | 0x415 |
IsDebuggerPresent | 0x0 | 0x41e0dc | 0x21ba0 | 0x201a0 | 0x2d1 |
HeapAlloc | 0x0 | 0x41e0e0 | 0x21ba4 | 0x201a4 | 0x29d |
HeapFree | 0x0 | 0x41e0e4 | 0x21ba8 | 0x201a8 | 0x2a1 |
EnterCriticalSection | 0x0 | 0x41e0e8 | 0x21bac | 0x201ac | 0xd9 |
LeaveCriticalSection | 0x0 | 0x41e0ec | 0x21bb0 | 0x201b0 | 0x2ef |
SetHandleCount | 0x0 | 0x41e0f0 | 0x21bb4 | 0x201b4 | 0x3e8 |
GetStdHandle | 0x0 | 0x41e0f4 | 0x21bb8 | 0x201b8 | 0x23b |
GetFileType | 0x0 | 0x41e0f8 | 0x21bbc | 0x201bc | 0x1d7 |
DeleteCriticalSection | 0x0 | 0x41e0fc | 0x21bc0 | 0x201c0 | 0xbe |
GetModuleHandleW | 0x0 | 0x41e100 | 0x21bc4 | 0x201c4 | 0x1f9 |
Sleep | 0x0 | 0x41e104 | 0x21bc8 | 0x201c8 | 0x421 |
ExitProcess | 0x0 | 0x41e108 | 0x21bcc | 0x201cc | 0x104 |
WriteFile | 0x0 | 0x41e10c | 0x21bd0 | 0x201d0 | 0x48d |
GetModuleFileNameA | 0x0 | 0x41e110 | 0x21bd4 | 0x201d4 | 0x1f4 |
GetEnvironmentStrings | 0x0 | 0x41e114 | 0x21bd8 | 0x201d8 | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x41e118 | 0x21bdc | 0x201dc | 0x14b |
WideCharToMultiByte | 0x0 | 0x41e11c | 0x21be0 | 0x201e0 | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x41e120 | 0x21be4 | 0x201e4 | 0x1c1 |
TlsGetValue | 0x0 | 0x41e124 | 0x21be8 | 0x201e8 | 0x434 |
TlsAlloc | 0x0 | 0x41e128 | 0x21bec | 0x201ec | 0x432 |
TlsSetValue | 0x0 | 0x41e12c | 0x21bf0 | 0x201f0 | 0x435 |
TlsFree | 0x0 | 0x41e130 | 0x21bf4 | 0x201f4 | 0x433 |
InterlockedIncrement | 0x0 | 0x41e134 | 0x21bf8 | 0x201f8 | 0x2c0 |
SetLastError | 0x0 | 0x41e138 | 0x21bfc | 0x201fc | 0x3ec |
GetCurrentThreadId | 0x0 | 0x41e13c | 0x21c00 | 0x20200 | 0x1ad |
InterlockedDecrement | 0x0 | 0x41e140 | 0x21c04 | 0x20204 | 0x2bc |
GetCurrentThread | 0x0 | 0x41e144 | 0x21c08 | 0x20208 | 0x1ac |
HeapCreate | 0x0 | 0x41e148 | 0x21c0c | 0x2020c | 0x29f |
HeapDestroy | 0x0 | 0x41e14c | 0x21c10 | 0x20210 | 0x2a0 |
VirtualFree | 0x0 | 0x41e150 | 0x21c14 | 0x20214 | 0x457 |
QueryPerformanceCounter | 0x0 | 0x41e154 | 0x21c18 | 0x20218 | 0x354 |
GetCurrentProcessId | 0x0 | 0x41e158 | 0x21c1c | 0x2021c | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x41e15c | 0x21c20 | 0x20220 | 0x24f |
FatalAppExitA | 0x0 | 0x41e160 | 0x21c24 | 0x20224 | 0x10b |
VirtualAlloc | 0x0 | 0x41e164 | 0x21c28 | 0x20228 | 0x454 |
HeapReAlloc | 0x0 | 0x41e168 | 0x21c2c | 0x2022c | 0x2a4 |
MultiByteToWideChar | 0x0 | 0x41e16c | 0x21c30 | 0x20230 | 0x31a |
ReadFile | 0x0 | 0x41e170 | 0x21c34 | 0x20234 | 0x368 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41e174 | 0x21c38 | 0x20238 | 0x2b5 |
HeapSize | 0x0 | 0x41e178 | 0x21c3c | 0x2023c | 0x2a6 |
SetConsoleCtrlHandler | 0x0 | 0x41e17c | 0x21c40 | 0x20240 | 0x3a7 |
FreeLibrary | 0x0 | 0x41e180 | 0x21c44 | 0x20244 | 0x14c |
InterlockedExchange | 0x0 | 0x41e184 | 0x21c48 | 0x20248 | 0x2bd |
GetOEMCP | 0x0 | 0x41e188 | 0x21c4c | 0x2024c | 0x213 |
IsValidCodePage | 0x0 | 0x41e18c | 0x21c50 | 0x20250 | 0x2db |
GetConsoleCP | 0x0 | 0x41e190 | 0x21c54 | 0x20254 | 0x183 |
GetConsoleMode | 0x0 | 0x41e194 | 0x21c58 | 0x20258 | 0x195 |
FlushFileBuffers | 0x0 | 0x41e198 | 0x21c5c | 0x2025c | 0x141 |
SetFilePointer | 0x0 | 0x41e19c | 0x21c60 | 0x20260 | 0x3df |
SetStdHandle | 0x0 | 0x41e1a0 | 0x21c64 | 0x20264 | 0x3fc |
GetLocaleInfoW | 0x0 | 0x41e1a4 | 0x21c68 | 0x20268 | 0x1ea |
SetEnvironmentVariableA | 0x0 | 0x41e1a8 | 0x21c6c | 0x2026c | 0x3d0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseClipboard | 0x0 | 0x41e1c4 | 0x21c88 | 0x20288 | 0x47 |
GetSubMenu | 0x0 | 0x41e1c8 | 0x21c8c | 0x2028c | 0x16b |
LoadBitmapA | 0x0 | 0x41e1cc | 0x21c90 | 0x20290 | 0x1d0 |
BeginPaint | 0x0 | 0x41e1d0 | 0x21c94 | 0x20294 | 0xe |
CallMsgFilterW | 0x0 | 0x41e1d4 | 0x21c98 | 0x20298 | 0x1a |
PeekMessageA | 0x0 | 0x41e1d8 | 0x21c9c | 0x2029c | 0x21b |
MapVirtualKeyExW | 0x0 | 0x41e1dc | 0x21ca0 | 0x202a0 | 0x1f1 |
RegisterRawInputDevices | 0x0 | 0x41e1e0 | 0x21ca4 | 0x202a4 | 0x242 |
SetWindowsHookExW | 0x0 | 0x41e1e4 | 0x21ca8 | 0x202a8 | 0x2b0 |
GetClipboardSequenceNumber | 0x0 | 0x41e1e8 | 0x21cac | 0x202ac | 0x113 |
GetDialogBaseUnits | 0x0 | 0x41e1ec | 0x21cb0 | 0x202b0 | 0x11d |
MessageBoxIndirectA | 0x0 | 0x41e1f0 | 0x21cb4 | 0x202b4 | 0x1fb |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateCompatibleDC | 0x0 | 0x41e000 | 0x21ac4 | 0x200c4 | 0x2e |
PlayEnhMetaFile | 0x0 | 0x41e004 | 0x21ac8 | 0x200c8 | 0x230 |
ScaleViewportExtEx | 0x0 | 0x41e008 | 0x21acc | 0x200cc | 0x258 |
SetStretchBltMode | 0x0 | 0x41e00c | 0x21ad0 | 0x200d0 | 0x289 |
SetPixelV | 0x0 | 0x41e010 | 0x21ad4 | 0x200d4 | 0x284 |
CreateDiscardableBitmap | 0x0 | 0x41e014 | 0x21ad8 | 0x200d8 | 0x35 |
AddFontResourceW | 0x0 | 0x41e018 | 0x21adc | 0x200dc | 0x7 |
SetDeviceGammaRamp | 0x0 | 0x41e01c | 0x21ae0 | 0x200e0 | 0x271 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExtractAssociatedIconA | 0x0 | 0x41e1b0 | 0x21c74 | 0x20274 | 0x24 |
ShellExecuteW | 0x0 | 0x41e1b4 | 0x21c78 | 0x20278 | 0x118 |
ShellAboutW | 0x0 | 0x41e1b8 | 0x21c7c | 0x2027c | 0x110 |
DragQueryFileA | 0x0 | 0x41e1bc | 0x21c80 | 0x20280 | 0x1e |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
updatewin2.exe | 7 | 0x00400000 | 0x0044CFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 7 | 0x005D5000 | 0x005D5FFF | Marked Executable | - | 32-bit | - |
![]() |
![]() |
...
|
Threat Name | Severity |
---|---|
Trojan.AgentWDCR.SVC |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\d5bfbe52-943a-4f73-97b1-39918fa00598\updatewin.exe | Downloaded File | Binary |
Malicious
|
...
|
Severity |
Blacklisted
|
First Seen | 2019-01-16 22:21 (UTC+1) |
Last Seen | 2019-07-06 02:48 (UTC+2) |
Names | Win32.Trojan.Kryptik |
Families | Kryptik |
Classification | Trojan |
Image Base | 0x400000 |
Entry Point | 0x402d7c |
Size Of Code | 0x1c200 |
Size Of Initialized Data | 0x2d400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-02-19 08:26:47+00:00 |
FileVersion | 8.8.10.11 |
InternalName | sutazaxidi.exe |
LegalCopyright | Copyright (C) 2018, huxonulow |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1c09e | 0x1c200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x41e000 | 0x4636 | 0x4800 | 0x1c600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.25 |
.data | 0x423000 | 0x1d5a8 | 0x18400 | 0x20e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.8 |
.rsrc | 0x441000 | 0xa826 | 0xaa00 | 0x39200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.84 |
.reloc | 0x44c000 | 0x1974 | 0x1a00 | 0x43c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.34 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitThread | 0x0 | 0x41e020 | 0x21af4 | 0x200f4 | 0x105 |
GetStartupInfoW | 0x0 | 0x41e024 | 0x21af8 | 0x200f8 | 0x23a |
GetConsoleAliasesW | 0x0 | 0x41e028 | 0x21afc | 0x200fc | 0x182 |
GetLastError | 0x0 | 0x41e02c | 0x21b00 | 0x20100 | 0x1e6 |
GetProcAddress | 0x0 | 0x41e030 | 0x21b04 | 0x20104 | 0x220 |
BackupWrite | 0x0 | 0x41e034 | 0x21b08 | 0x20108 | 0x18 |
GlobalFree | 0x0 | 0x41e038 | 0x21b0c | 0x2010c | 0x28c |
LoadLibraryA | 0x0 | 0x41e03c | 0x21b10 | 0x20110 | 0x2f1 |
GetNumberFormatW | 0x0 | 0x41e040 | 0x21b14 | 0x20114 | 0x20f |
AddAtomA | 0x0 | 0x41e044 | 0x21b18 | 0x20118 | 0x3 |
FindFirstChangeNotificationA | 0x0 | 0x41e048 | 0x21b1c | 0x2011c | 0x11b |
GetStringTypeW | 0x0 | 0x41e04c | 0x21b20 | 0x20120 | 0x240 |
VirtualProtect | 0x0 | 0x41e050 | 0x21b24 | 0x20124 | 0x45a |
GetACP | 0x0 | 0x41e054 | 0x21b28 | 0x20128 | 0x152 |
SetProcessShutdownParameters | 0x0 | 0x41e058 | 0x21b2c | 0x2012c | 0x3f9 |
CompareStringW | 0x0 | 0x41e05c | 0x21b30 | 0x20130 | 0x55 |
CompareStringA | 0x0 | 0x41e060 | 0x21b34 | 0x20134 | 0x52 |
CreateFileA | 0x0 | 0x41e064 | 0x21b38 | 0x20138 | 0x78 |
GetTimeZoneInformation | 0x0 | 0x41e068 | 0x21b3c | 0x2013c | 0x26b |
WriteConsoleW | 0x0 | 0x41e06c | 0x21b40 | 0x20140 | 0x48c |
GetConsoleOutputCP | 0x0 | 0x41e070 | 0x21b44 | 0x20144 | 0x199 |
WriteConsoleA | 0x0 | 0x41e074 | 0x21b48 | 0x20148 | 0x482 |
CloseHandle | 0x0 | 0x41e078 | 0x21b4c | 0x2014c | 0x43 |
IsValidLocale | 0x0 | 0x41e07c | 0x21b50 | 0x20150 | 0x2dd |
EnumSystemLocalesA | 0x0 | 0x41e080 | 0x21b54 | 0x20154 | 0xf8 |
GetUserDefaultLCID | 0x0 | 0x41e084 | 0x21b58 | 0x20158 | 0x26d |
GetDateFormatA | 0x0 | 0x41e088 | 0x21b5c | 0x2015c | 0x1ae |
GetSystemTimes | 0x0 | 0x41e08c | 0x21b60 | 0x20160 | 0x250 |
GetTickCount | 0x0 | 0x41e090 | 0x21b64 | 0x20164 | 0x266 |
FreeEnvironmentStringsA | 0x0 | 0x41e094 | 0x21b68 | 0x20168 | 0x14a |
GetComputerNameW | 0x0 | 0x41e098 | 0x21b6c | 0x2016c | 0x178 |
FindCloseChangeNotification | 0x0 | 0x41e09c | 0x21b70 | 0x20170 | 0x11a |
FindResourceExW | 0x0 | 0x41e0a0 | 0x21b74 | 0x20174 | 0x138 |
GetCurrentDirectoryA | 0x0 | 0x41e0a4 | 0x21b78 | 0x20178 | 0x1a7 |
GetCPInfo | 0x0 | 0x41e0a8 | 0x21b7c | 0x2017c | 0x15b |
GetTimeFormatA | 0x0 | 0x41e0ac | 0x21b80 | 0x20180 | 0x268 |
GetStringTypeA | 0x0 | 0x41e0b0 | 0x21b84 | 0x20184 | 0x23d |
LCMapStringW | 0x0 | 0x41e0b4 | 0x21b88 | 0x20188 | 0x2e3 |
LCMapStringA | 0x0 | 0x41e0b8 | 0x21b8c | 0x2018c | 0x2e1 |
GetLocaleInfoA | 0x0 | 0x41e0bc | 0x21b90 | 0x20190 | 0x1e8 |
GetLocaleInfoW | 0x0 | 0x41e0c0 | 0x21b94 | 0x20194 | 0x1ea |
SetStdHandle | 0x0 | 0x41e0c4 | 0x21b98 | 0x20198 | 0x3fc |
SetFilePointer | 0x0 | 0x41e0c8 | 0x21b9c | 0x2019c | 0x3df |
GetCommandLineA | 0x0 | 0x41e0cc | 0x21ba0 | 0x201a0 | 0x16f |
GetStartupInfoA | 0x0 | 0x41e0d0 | 0x21ba4 | 0x201a4 | 0x239 |
RaiseException | 0x0 | 0x41e0d4 | 0x21ba8 | 0x201a8 | 0x35a |
RtlUnwind | 0x0 | 0x41e0d8 | 0x21bac | 0x201ac | 0x392 |
TerminateProcess | 0x0 | 0x41e0dc | 0x21bb0 | 0x201b0 | 0x42d |
GetCurrentProcess | 0x0 | 0x41e0e0 | 0x21bb4 | 0x201b4 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x41e0e4 | 0x21bb8 | 0x201b8 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x41e0e8 | 0x21bbc | 0x201bc | 0x415 |
IsDebuggerPresent | 0x0 | 0x41e0ec | 0x21bc0 | 0x201c0 | 0x2d1 |
HeapAlloc | 0x0 | 0x41e0f0 | 0x21bc4 | 0x201c4 | 0x29d |
HeapFree | 0x0 | 0x41e0f4 | 0x21bc8 | 0x201c8 | 0x2a1 |
EnterCriticalSection | 0x0 | 0x41e0f8 | 0x21bcc | 0x201cc | 0xd9 |
LeaveCriticalSection | 0x0 | 0x41e0fc | 0x21bd0 | 0x201d0 | 0x2ef |
SetHandleCount | 0x0 | 0x41e100 | 0x21bd4 | 0x201d4 | 0x3e8 |
GetStdHandle | 0x0 | 0x41e104 | 0x21bd8 | 0x201d8 | 0x23b |
GetFileType | 0x0 | 0x41e108 | 0x21bdc | 0x201dc | 0x1d7 |
DeleteCriticalSection | 0x0 | 0x41e10c | 0x21be0 | 0x201e0 | 0xbe |
GetModuleHandleW | 0x0 | 0x41e110 | 0x21be4 | 0x201e4 | 0x1f9 |
Sleep | 0x0 | 0x41e114 | 0x21be8 | 0x201e8 | 0x421 |
ExitProcess | 0x0 | 0x41e118 | 0x21bec | 0x201ec | 0x104 |
WriteFile | 0x0 | 0x41e11c | 0x21bf0 | 0x201f0 | 0x48d |
GetModuleFileNameA | 0x0 | 0x41e120 | 0x21bf4 | 0x201f4 | 0x1f4 |
GetEnvironmentStrings | 0x0 | 0x41e124 | 0x21bf8 | 0x201f8 | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x41e128 | 0x21bfc | 0x201fc | 0x14b |
WideCharToMultiByte | 0x0 | 0x41e12c | 0x21c00 | 0x20200 | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x41e130 | 0x21c04 | 0x20204 | 0x1c1 |
TlsGetValue | 0x0 | 0x41e134 | 0x21c08 | 0x20208 | 0x434 |
TlsAlloc | 0x0 | 0x41e138 | 0x21c0c | 0x2020c | 0x432 |
TlsSetValue | 0x0 | 0x41e13c | 0x21c10 | 0x20210 | 0x435 |
TlsFree | 0x0 | 0x41e140 | 0x21c14 | 0x20214 | 0x433 |
InterlockedIncrement | 0x0 | 0x41e144 | 0x21c18 | 0x20218 | 0x2c0 |
SetLastError | 0x0 | 0x41e148 | 0x21c1c | 0x2021c | 0x3ec |
GetCurrentThreadId | 0x0 | 0x41e14c | 0x21c20 | 0x20220 | 0x1ad |
InterlockedDecrement | 0x0 | 0x41e150 | 0x21c24 | 0x20224 | 0x2bc |
GetCurrentThread | 0x0 | 0x41e154 | 0x21c28 | 0x20228 | 0x1ac |
HeapCreate | 0x0 | 0x41e158 | 0x21c2c | 0x2022c | 0x29f |
HeapDestroy | 0x0 | 0x41e15c | 0x21c30 | 0x20230 | 0x2a0 |
VirtualFree | 0x0 | 0x41e160 | 0x21c34 | 0x20234 | 0x457 |
QueryPerformanceCounter | 0x0 | 0x41e164 | 0x21c38 | 0x20238 | 0x354 |
GetCurrentProcessId | 0x0 | 0x41e168 | 0x21c3c | 0x2023c | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x41e16c | 0x21c40 | 0x20240 | 0x24f |
FatalAppExitA | 0x0 | 0x41e170 | 0x21c44 | 0x20244 | 0x10b |
VirtualAlloc | 0x0 | 0x41e174 | 0x21c48 | 0x20248 | 0x454 |
HeapReAlloc | 0x0 | 0x41e178 | 0x21c4c | 0x2024c | 0x2a4 |
MultiByteToWideChar | 0x0 | 0x41e17c | 0x21c50 | 0x20250 | 0x31a |
ReadFile | 0x0 | 0x41e180 | 0x21c54 | 0x20254 | 0x368 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41e184 | 0x21c58 | 0x20258 | 0x2b5 |
HeapSize | 0x0 | 0x41e188 | 0x21c5c | 0x2025c | 0x2a6 |
SetConsoleCtrlHandler | 0x0 | 0x41e18c | 0x21c60 | 0x20260 | 0x3a7 |
FreeLibrary | 0x0 | 0x41e190 | 0x21c64 | 0x20264 | 0x14c |
InterlockedExchange | 0x0 | 0x41e194 | 0x21c68 | 0x20268 | 0x2bd |
GetOEMCP | 0x0 | 0x41e198 | 0x21c6c | 0x2026c | 0x213 |
IsValidCodePage | 0x0 | 0x41e19c | 0x21c70 | 0x20270 | 0x2db |
GetConsoleCP | 0x0 | 0x41e1a0 | 0x21c74 | 0x20274 | 0x183 |
GetConsoleMode | 0x0 | 0x41e1a4 | 0x21c78 | 0x20278 | 0x195 |
FlushFileBuffers | 0x0 | 0x41e1a8 | 0x21c7c | 0x2027c | 0x141 |
SetEnvironmentVariableA | 0x0 | 0x41e1ac | 0x21c80 | 0x20280 | 0x3d0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseClipboard | 0x0 | 0x41e1d4 | 0x21ca8 | 0x202a8 | 0x47 |
SendNotifyMessageA | 0x0 | 0x41e1d8 | 0x21cac | 0x202ac | 0x264 |
BeginPaint | 0x0 | 0x41e1dc | 0x21cb0 | 0x202b0 | 0xe |
CallMsgFilterW | 0x0 | 0x41e1e0 | 0x21cb4 | 0x202b4 | 0x1a |
PeekMessageA | 0x0 | 0x41e1e4 | 0x21cb8 | 0x202b8 | 0x21b |
MapVirtualKeyExW | 0x0 | 0x41e1e8 | 0x21cbc | 0x202bc | 0x1f1 |
RegisterRawInputDevices | 0x0 | 0x41e1ec | 0x21cc0 | 0x202c0 | 0x242 |
GetClipboardSequenceNumber | 0x0 | 0x41e1f0 | 0x21cc4 | 0x202c4 | 0x113 |
SetUserObjectInformationA | 0x0 | 0x41e1f4 | 0x21cc8 | 0x202c8 | 0x29f |
GetDialogBaseUnits | 0x0 | 0x41e1f8 | 0x21ccc | 0x202cc | 0x11d |
GetMessageW | 0x0 | 0x41e1fc | 0x21cd0 | 0x202d0 | 0x14e |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreatePolyPolygonRgn | 0x0 | 0x41e000 | 0x21ad4 | 0x200d4 | 0x4b |
CreateCompatibleDC | 0x0 | 0x41e004 | 0x21ad8 | 0x200d8 | 0x2e |
SetStretchBltMode | 0x0 | 0x41e008 | 0x21adc | 0x200dc | 0x289 |
SetPixelV | 0x0 | 0x41e00c | 0x21ae0 | 0x200e0 | 0x284 |
GetCharWidth32A | 0x0 | 0x41e010 | 0x21ae4 | 0x200e4 | 0x1a0 |
CreateDiscardableBitmap | 0x0 | 0x41e014 | 0x21ae8 | 0x200e8 | 0x35 |
BitBlt | 0x0 | 0x41e018 | 0x21aec | 0x200ec | 0x12 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x41e1b4 | 0x21c88 | 0x20288 | 0x118 |
ShellAboutW | 0x0 | 0x41e1b8 | 0x21c8c | 0x2028c | 0x110 |
ExtractIconA | 0x0 | 0x41e1bc | 0x21c90 | 0x20290 | 0x28 |
ShellExecuteExA | 0x0 | 0x41e1c0 | 0x21c94 | 0x20294 | 0x116 |
FindExecutableA | 0x0 | 0x41e1c4 | 0x21c98 | 0x20298 | 0x2d |
DragQueryFileA | 0x0 | 0x41e1c8 | 0x21c9c | 0x2029c | 0x1e |
ExtractIconW | 0x0 | 0x41e1cc | 0x21ca0 | 0x202a0 | 0x2c |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
updatewin.exe | 9 | 0x00400000 | 0x0044DFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 9 | 0x005B5000 | 0x005B5FFF | Marked Executable | - | 32-bit | - |
![]() |
![]() |
...
|
Threat Name | Severity |
---|---|
Trojan.AgentWDCR.SUF |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\d5bfbe52-943a-4f73-97b1-39918fa00598\5.exe | Downloaded File | Binary |
Malicious
|
...
|
Severity |
Blacklisted
|
First Seen | 2019-05-28 23:35 (UTC+2) |
Last Seen | 2019-07-06 01:46 (UTC+2) |
Names | Win32.Trojan.Kryptik |
Families | Kryptik |
Classification | Trojan |
Image Base | 0x400000 |
Entry Point | 0x401697 |
Size Of Code | 0x13600 |
Size Of Initialized Data | 0x46400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-11-29 18:58:54+00:00 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x13500 | 0x13600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.64 |
.rdata | 0x415000 | 0x2fe8 | 0x3000 | 0x13a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.49 |
.data | 0x418000 | 0x3a220 | 0x1b000 | 0x16a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.63 |
.rsrc | 0x453000 | 0x8bf0 | 0x8c00 | 0x31a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.1 |
.reloc | 0x45c000 | 0x11ea | 0x1200 | 0x3a600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.15 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetStringTypeExW | 0x0 | 0x415018 | 0x175b4 | 0x15fb4 | 0x23f |
GetFileAttributesA | 0x0 | 0x41501c | 0x175b8 | 0x15fb8 | 0x1c9 |
GetConsoleAliasW | 0x0 | 0x415020 | 0x175bc | 0x15fbc | 0x17e |
GetConsoleFontSize | 0x0 | 0x415024 | 0x175c0 | 0x15fc0 | 0x18d |
GetStartupInfoW | 0x0 | 0x415028 | 0x175c4 | 0x15fc4 | 0x23a |
GlobalUnfix | 0x0 | 0x41502c | 0x175c8 | 0x15fc8 | 0x296 |
GetProcAddress | 0x0 | 0x415030 | 0x175cc | 0x15fcc | 0x220 |
FindVolumeMountPointClose | 0x0 | 0x415034 | 0x175d0 | 0x15fd0 | 0x13b |
GetLongPathNameA | 0x0 | 0x415038 | 0x175d4 | 0x15fd4 | 0x1ef |
CreateConsoleScreenBuffer | 0x0 | 0x41503c | 0x175d8 | 0x15fd8 | 0x6b |
LoadLibraryA | 0x0 | 0x415040 | 0x175dc | 0x15fdc | 0x2f1 |
VirtualLock | 0x0 | 0x415044 | 0x175e0 | 0x15fe0 | 0x459 |
MapUserPhysicalPagesScatter | 0x0 | 0x415048 | 0x175e4 | 0x15fe4 | 0x309 |
GetSystemInfo | 0x0 | 0x41504c | 0x175e8 | 0x15fe8 | 0x249 |
GetOEMCP | 0x0 | 0x415050 | 0x175ec | 0x15fec | 0x213 |
GetModuleHandleA | 0x0 | 0x415054 | 0x175f0 | 0x15ff0 | 0x1f6 |
VirtualProtect | 0x0 | 0x415058 | 0x175f4 | 0x15ff4 | 0x45a |
CreateToolhelp32Snapshot | 0x0 | 0x41505c | 0x175f8 | 0x15ff8 | 0xac |
GetFileAttributesExW | 0x0 | 0x415060 | 0x175fc | 0x15ffc | 0x1cb |
CloseHandle | 0x0 | 0x415064 | 0x17600 | 0x16000 | 0x43 |
GetThreadTimes | 0x0 | 0x415068 | 0x17604 | 0x16004 | 0x264 |
OpenFileMappingA | 0x0 | 0x41506c | 0x17608 | 0x16008 | 0x32b |
CompareStringW | 0x0 | 0x415070 | 0x1760c | 0x1600c | 0x55 |
CompareStringA | 0x0 | 0x415074 | 0x17610 | 0x16010 | 0x52 |
CreateFileA | 0x0 | 0x415078 | 0x17614 | 0x16014 | 0x78 |
GlobalAlloc | 0x0 | 0x41507c | 0x17618 | 0x16018 | 0x285 |
GetTickCount | 0x0 | 0x415080 | 0x1761c | 0x1601c | 0x266 |
GetLocaleInfoA | 0x0 | 0x415084 | 0x17620 | 0x16020 | 0x1e8 |
GetModuleHandleExA | 0x0 | 0x415088 | 0x17624 | 0x16024 | 0x1f7 |
Module32FirstW | 0x0 | 0x41508c | 0x17628 | 0x16028 | 0x30e |
GetNativeSystemInfo | 0x0 | 0x415090 | 0x1762c | 0x1602c | 0x206 |
GetLastError | 0x0 | 0x415094 | 0x17630 | 0x16030 | 0x1e6 |
HeapFree | 0x0 | 0x415098 | 0x17634 | 0x16034 | 0x2a1 |
GetCommandLineA | 0x0 | 0x41509c | 0x17638 | 0x16038 | 0x16f |
GetStartupInfoA | 0x0 | 0x4150a0 | 0x1763c | 0x1603c | 0x239 |
HeapCreate | 0x0 | 0x4150a4 | 0x17640 | 0x16040 | 0x29f |
HeapDestroy | 0x0 | 0x4150a8 | 0x17644 | 0x16044 | 0x2a0 |
VirtualFree | 0x0 | 0x4150ac | 0x17648 | 0x16048 | 0x457 |
DeleteCriticalSection | 0x0 | 0x4150b0 | 0x1764c | 0x1604c | 0xbe |
LeaveCriticalSection | 0x0 | 0x4150b4 | 0x17650 | 0x16050 | 0x2ef |
FatalAppExitA | 0x0 | 0x4150b8 | 0x17654 | 0x16054 | 0x10b |
EnterCriticalSection | 0x0 | 0x4150bc | 0x17658 | 0x16058 | 0xd9 |
HeapAlloc | 0x0 | 0x4150c0 | 0x1765c | 0x1605c | 0x29d |
VirtualAlloc | 0x0 | 0x4150c4 | 0x17660 | 0x16060 | 0x454 |
HeapReAlloc | 0x0 | 0x4150c8 | 0x17664 | 0x16064 | 0x2a4 |
GetModuleHandleW | 0x0 | 0x4150cc | 0x17668 | 0x16068 | 0x1f9 |
TlsGetValue | 0x0 | 0x4150d0 | 0x1766c | 0x1606c | 0x434 |
TlsAlloc | 0x0 | 0x4150d4 | 0x17670 | 0x16070 | 0x432 |
TlsSetValue | 0x0 | 0x4150d8 | 0x17674 | 0x16074 | 0x435 |
TlsFree | 0x0 | 0x4150dc | 0x17678 | 0x16078 | 0x433 |
InterlockedIncrement | 0x0 | 0x4150e0 | 0x1767c | 0x1607c | 0x2c0 |
SetLastError | 0x0 | 0x4150e4 | 0x17680 | 0x16080 | 0x3ec |
GetCurrentThreadId | 0x0 | 0x4150e8 | 0x17684 | 0x16084 | 0x1ad |
InterlockedDecrement | 0x0 | 0x4150ec | 0x17688 | 0x16088 | 0x2bc |
GetCurrentThread | 0x0 | 0x4150f0 | 0x1768c | 0x1608c | 0x1ac |
Sleep | 0x0 | 0x4150f4 | 0x17690 | 0x16090 | 0x421 |
HeapSize | 0x0 | 0x4150f8 | 0x17694 | 0x16094 | 0x2a6 |
ExitProcess | 0x0 | 0x4150fc | 0x17698 | 0x16098 | 0x104 |
SetHandleCount | 0x0 | 0x415100 | 0x1769c | 0x1609c | 0x3e8 |
GetStdHandle | 0x0 | 0x415104 | 0x176a0 | 0x160a0 | 0x23b |
GetFileType | 0x0 | 0x415108 | 0x176a4 | 0x160a4 | 0x1d7 |
SetFilePointer | 0x0 | 0x41510c | 0x176a8 | 0x160a8 | 0x3df |
TerminateProcess | 0x0 | 0x415110 | 0x176ac | 0x160ac | 0x42d |
GetCurrentProcess | 0x0 | 0x415114 | 0x176b0 | 0x160b0 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x415118 | 0x176b4 | 0x160b4 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x41511c | 0x176b8 | 0x160b8 | 0x415 |
IsDebuggerPresent | 0x0 | 0x415120 | 0x176bc | 0x160bc | 0x2d1 |
WriteFile | 0x0 | 0x415124 | 0x176c0 | 0x160c0 | 0x48d |
GetModuleFileNameA | 0x0 | 0x415128 | 0x176c4 | 0x160c4 | 0x1f4 |
FreeEnvironmentStringsA | 0x0 | 0x41512c | 0x176c8 | 0x160c8 | 0x14a |
GetEnvironmentStrings | 0x0 | 0x415130 | 0x176cc | 0x160cc | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x415134 | 0x176d0 | 0x160d0 | 0x14b |
WideCharToMultiByte | 0x0 | 0x415138 | 0x176d4 | 0x160d4 | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x41513c | 0x176d8 | 0x160d8 | 0x1c1 |
QueryPerformanceCounter | 0x0 | 0x415140 | 0x176dc | 0x160dc | 0x354 |
GetCurrentProcessId | 0x0 | 0x415144 | 0x176e0 | 0x160e0 | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x415148 | 0x176e4 | 0x160e4 | 0x24f |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41514c | 0x176e8 | 0x160e8 | 0x2b5 |
RtlUnwind | 0x0 | 0x415150 | 0x176ec | 0x160ec | 0x392 |
GetCPInfo | 0x0 | 0x415154 | 0x176f0 | 0x160f0 | 0x15b |
GetACP | 0x0 | 0x415158 | 0x176f4 | 0x160f4 | 0x152 |
IsValidCodePage | 0x0 | 0x41515c | 0x176f8 | 0x160f8 | 0x2db |
SetConsoleCtrlHandler | 0x0 | 0x415160 | 0x176fc | 0x160fc | 0x3a7 |
FreeLibrary | 0x0 | 0x415164 | 0x17700 | 0x16100 | 0x14c |
InterlockedExchange | 0x0 | 0x415168 | 0x17704 | 0x16104 | 0x2bd |
SetStdHandle | 0x0 | 0x41516c | 0x17708 | 0x16108 | 0x3fc |
GetTimeFormatA | 0x0 | 0x415170 | 0x1770c | 0x1610c | 0x268 |
GetDateFormatA | 0x0 | 0x415174 | 0x17710 | 0x16110 | 0x1ae |
GetUserDefaultLCID | 0x0 | 0x415178 | 0x17714 | 0x16114 | 0x26d |
EnumSystemLocalesA | 0x0 | 0x41517c | 0x17718 | 0x16118 | 0xf8 |
IsValidLocale | 0x0 | 0x415180 | 0x1771c | 0x1611c | 0x2dd |
GetStringTypeA | 0x0 | 0x415184 | 0x17720 | 0x16120 | 0x23d |
MultiByteToWideChar | 0x0 | 0x415188 | 0x17724 | 0x16124 | 0x31a |
GetStringTypeW | 0x0 | 0x41518c | 0x17728 | 0x16128 | 0x240 |
LCMapStringA | 0x0 | 0x415190 | 0x1772c | 0x1612c | 0x2e1 |
LCMapStringW | 0x0 | 0x415194 | 0x17730 | 0x16130 | 0x2e3 |
GetLocaleInfoW | 0x0 | 0x415198 | 0x17734 | 0x16134 | 0x1ea |
GetConsoleCP | 0x0 | 0x41519c | 0x17738 | 0x16138 | 0x183 |
GetConsoleMode | 0x0 | 0x4151a0 | 0x1773c | 0x1613c | 0x195 |
FlushFileBuffers | 0x0 | 0x4151a4 | 0x17740 | 0x16140 | 0x141 |
GetTimeZoneInformation | 0x0 | 0x4151a8 | 0x17744 | 0x16144 | 0x26b |
WriteConsoleA | 0x0 | 0x4151ac | 0x17748 | 0x16148 | 0x482 |
GetConsoleOutputCP | 0x0 | 0x4151b0 | 0x1774c | 0x1614c | 0x199 |
WriteConsoleW | 0x0 | 0x4151b4 | 0x17750 | 0x16150 | 0x48c |
SetEnvironmentVariableA | 0x0 | 0x4151b8 | 0x17754 | 0x16154 | 0x3d0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetWindowContextHelpId | 0x0 | 0x4151c0 | 0x1775c | 0x1615c | 0x17e |
GetMessageExtraInfo | 0x0 | 0x4151c4 | 0x17760 | 0x16160 | 0x14b |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StartServiceW | 0x0 | 0x415000 | 0x1759c | 0x15f9c | 0x2c3 |
RegGetKeySecurity | 0x0 | 0x415004 | 0x175a0 | 0x15fa0 | 0x24e |
RegRestoreKeyA | 0x0 | 0x415008 | 0x175a4 | 0x15fa4 | 0x26d |
SetThreadToken | 0x0 | 0x41500c | 0x175a8 | 0x15fa8 | 0x2bb |
RegConnectRegistryW | 0x0 | 0x415010 | 0x175ac | 0x15fac | 0x22e |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
5.exe | 11 | 0x00400000 | 0x0045DFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 11 | 0x00567AA8 | 0x0057D22B | Marked Executable | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 11 | 0x00567AA8 | 0x0057D22B | Content Changed | - | 32-bit | 0x005683D3, 0x00567AA8 |
![]() |
![]() |
...
|
Threat Name | Severity |
---|---|
Trojan.GenericKD.41330912 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\DfM1jMQH5m.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\eCYysFOHAuDPd0.odp | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\gl-n 26G.bmp | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\GMWkR.wav | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\I TKCX nhSV2b.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\nborqaG7LbY-8nT0ByEv.pps | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\nXxNQgqy6gVdEPQ.bmp | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\PoDqxcM TSaz.swf | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\TeVS.mp4 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\TyHbSH6VrF3xX.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\uVeSXOWXfi_KaHM6.swf | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\uVgxMcsEjpWpZrN.jpg | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wjaMa6Mk-99x.gif | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Xk2XWRW.flv | Modified File | Video |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3kKQ7nGkbpOOq-1 5zRt.pptx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\45LEiyxnf Plrmb.docx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\5Jnu XQUnVKH6.xlsx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\5W-053pafC.pps | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\AGokm2hLuNsPkZ.pptx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\BUziw_klSFTDwvC1Vm.pptx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Dtk7xvzoVk_gCAUAkb.xlsx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\EDFXHniYi.docx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\G-R5IPPjXNO2pufW-w.pptx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\kbQLv1HzRjuGX8_0 ow.pptx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\M0viuAr.pptx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\mJD0Lk7dF2uj7fNWL.doc | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\mpW-3B9.xlsx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\umnYAxK8Hd5gj.pptx | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\yNFdhsIRJWbx9.pptx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\-Utu5uTreh3_BFU.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\2ZgBE.wav | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\5V1FT5g1rxSJJ41de.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\7HJiH UDq9SzzeN5I.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\8ywMFiXrJ1mJNTYk.wav | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\LgZcOmajdnsesY.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\NN082DlMLC6MxmlQyS42.wav | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tbTKJ0ZxbS6wZlGEphR.wav | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\wAomAj1M-1.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\XQtttNc8l WMW7IPg.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\_D7Y.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\-W0-.gif | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Aor58F2ltwiS2qWZJE.bmp | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\FDQ3v_tHbiNjViuE.jpg | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\hiUvM1waNbZk-e.bmp | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\L4Lb_VKCFG5Baj3.gif | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\MkdmiW2n2hm UFrse-.bmp | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\OFMo70Ypi.jpg | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VyatE0vXWAqC0OxRt_.jpg | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ReEw7jE5wqOg.swf | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\0oqCmMdMfyA -VyQ\gW8MJuJm9dKBS.swf | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\cJ1uF3yzdYr\6lkmIZ.jpg | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\cJ1uF3yzdYr\bYco6U CoNywT.ots | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\cJ1uF3yzdYr\sH_lIdhNg4 u9hq.xls | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\cJ1uF3yzdYr\UB qDPSTcD6SsAM5.pdf | Modified File |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Qz91k6FGRf5u2kNaQ\4k4 81HVDXuJOl.odp | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Qz91k6FGRf5u2kNaQ\Rqjkx-Inyu564.bmp | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Qz91k6FGRf5u2kNaQ\wWuRiwRN3-J7Oj9WP.jpg | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Yw9G-4_B\foWRjFtWYtlcWkIBF.ppt | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Yw9G-4_B\l8IL3_dOyLyH.odp | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Yw9G-4_B\QITXJJCFSuy.rtf | Modified File | Text |
Unknown
|
...
|
=^qt4yр No<##EsS;Qn͜28'G')1V/wùh %,$?Kl:6b2ʡ%MS.j )# k%]YbjpRY)Bꌡd#b:<?۬( JGiiH3=!k)<4!֓7de>s4S;(0_kA>B'@@'@1 *1fY^ vO3xK`Y8^6GGӖ >CaUoH0:*鼖XgkE~KuEO3DIgu-[**jtk3OCm1 3Q_#8.Mr.r׆iMљiu2K5GM<N~Yh[?6$% B<=bAc?Uj;6B](k%<TkSt-N6ۯʲ|GQ`PCGA'CʤbGvT;~LR1a&Cs3F8ʎ+P܊wRAz>@CN+J1lflZnUb>hB2UvQNH9H9f%1 `X!7˵Ft.։);,̫fJ[om:"qU<fQv*is$r̪|>t%>nJDĴqMrtW춁z(aM+ʀ4.~Aa`-q^y:&ҏ^0]731 ~휣^z#=π7sjKu=uI%`O762jLjy"~|): Q"*&b,Dj36 "2TMaQJVon+-v/XMˮbO2fjKQ`hԍuNwfp>aV:]nuj)-=x&.4.P2"Sf-=&XBO_Qs.W#WRidl*ĜM48C8zkT]ї#1屮 7WHdBq¢wIlvTI?jЂBqzBx#Q/p&^EܢnE Uwq*^cqCᅏδVq"e6Jt6j8U_TH4ZN:clLzSrb5LGK`l5?Z0ɸ^I a5?zDuYsF^갬Ccȕn03+JޚڢS ̵!K_2cGXQƎ܅=yʌќ.U8kvgB. FЩ+:V2gtT* se6h?*Vzo(HRIM$~G%ѡVlD .n>`jAw:!8rͱOǼ=vnRaX!,. =q6B9y?/bst`DMKFS?JWqM^;d/u#4êoi`+4QȋN^9M 6ŽKh>yKzWcF7U-LdxT,@^w=LkqgW+ZbkWH[RS9-ƐaL r4Z ... |
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Yw9G-4_B\wYeZ7WgnHNP8l.rtf | Modified File | Text |
Unknown
|
...
|
=^qt4yр No<##EsS;Qn͜28'GiP77MLYTdJe`c"~n>-O4W>GQ]I76Z7@`nif+GzԂxsHۿ%eG* Pa朕RXZIkrAbxiY#56kQfXueNLg-w7au7$JVW~lrzpFߦMf~BpLRo#5=rJXLkkSWRڪam8qvzktM&1dCT,h?로Dubyfy8D?2dMI;c32X@Apm7k"H;DN*F&1iᵈ(IP!go:v'Rَ72Szw%&>ЈZ?b &9e9'aϓX2/YM)^6Y!tO9HմߌB#TL4i6CЂ*j&ܯi̡6SVTBسn_fՈE/j^Բsi&۾>mտ^gx+`lzy!lBCG7"B@mZfr/*CyYgP^Tׯj>;ayJDnE]9@+<|iEV(Ҡ?CNxpBzU>Sg/D ,`A,.mr!D/th.WW4[ZjDj* UoAo[n,En_toVTew+Y9U|>v&rnįm^9 2"qJPNQTrlb21C%ԐLhp{izy56'R˝+/|U-|=`THzX|q<PiHuuB|f4eq1Sw/:022t4et殂x=,PQÂ$ w04s6BPeϻH[ed0FޯXMERJ^iw)HNR3f]x"8%qJ]&hu/[/w[>`%E#JMzWk/2ﶣ7drݢ>8t[pD&sH4dniWŚ_i"ᄽɏcV|`bwkI2S%g!n!(TF95DU(ﲬ0`vb=lj=gP¬d(֥ڥm0GKUjxk9jx[ІDjמqĉJ'j+OMIaƅ@n|/nt,hi5VIq8HV8=f )+D0x^]KN2m߹!<TN@|Dʚi <srs$400@<fCM2:@SN=76FPWD-u4l~.WMG/A0GDR8_yűLy |zT'TKVySymrʀPFvwme NlMknKOB#$/QnOUws|~M"31eߊ LB2l2Kj ... |
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Suggested Sites.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Web Slice Gallery.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE Add-on site.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Home.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft Store.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Entertainment.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Money.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Sports.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSNBC News.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Spaces.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\bAXbPKiwKvGBE_6IlyS\AwfOXmr1.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\bAXbPKiwKvGBE_6IlyS\hd0rzFg.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\bAXbPKiwKvGBE_6IlyS\j34KVbd 7j.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\bAXbPKiwKvGBE_6IlyS\KeEk_O9.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\bAXbPKiwKvGBE_6IlyS\lGrnoXKuinB.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\bAXbPKiwKvGBE_6IlyS\lWn6_.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\bAXbPKiwKvGBE_6IlyS\O_o33d.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\bAXbPKiwKvGBE_6IlyS\RU_Ytkp2w qp.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\bAXbPKiwKvGBE_6IlyS\sGdLslAC.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\bAXbPKiwKvGBE_6IlyS\W783g cZVYe_Q3ZTfs.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\bAXbPKiwKvGBE_6IlyS\_BaDSqvWqTCo.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\1oLW\-ExuX9LOjl2Rf0Z.png | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\1oLW\3mlI5OW4Ceei.png | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\1oLW\4iAitK.png | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\1oLW\4X0WuHIKFlmcsmSj8wH.jpg | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\1oLW\60jL.jpg | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\1oLW\u3J7SbbSL4_idzLNM.bmp | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\1oLW\wpAW.jpg | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\1oLW\xRTD4.png | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\Gx9Mb.swf | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\I42cS5 VvN3aGuFi.mp4 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\v2tEOgOZeF-wSXfUeb.mp4 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\ZNFPhs7VtfT6Wy.mp4 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Qz91k6FGRf5u2kNaQ\T0CQ8VVBC5Xi_UA\5 wO.jpg | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Qz91k6FGRf5u2kNaQ\T0CQ8VVBC5Xi_UA\xIlfywT2BL_f.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\_private\folder.ico | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Yw9G-4_B\NtnCGgs\70Jmk.odp | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Yw9G-4_B\Rpss_8PAcreSznq0jw9\xkuwOm0rA.ods | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\1oLW\gJs687PmdwJ\8jZ3LBgNvW1arBclEu8.gif | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\1oLW\gJs687PmdwJ\axSg-zF.gif | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\1oLW\gJs687PmdwJ\E5 Uz-9etUMMH3CKQC.bmp | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\kU7oVdD-q0QJXT.swf | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\uYUuV.swf | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Qz91k6FGRf5u2kNaQ\T0CQ8VVBC5Xi_UA\xt72dHYiX\-1 X.bmp | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Qz91k6FGRf5u2kNaQ\T0CQ8VVBC5Xi_UA\xt72dHYiX\u39sgkNzI3ujT06Y2kP.gif | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Yw9G-4_B\NtnCGgs\-3tBc\dbOCkvV1nk u.doc | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Yw9G-4_B\NtnCGgs\-3tBc\RBanc_ Xhdc-T.xlsx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Yw9G-4_B\NtnCGgs\-3tBc\x46p.rtf | Modified File | Text |
Unknown
|
...
|
=^qt4yр No<##EsS;Qn͜28'G`e+LINݶ!ҡ3Y5g#WWNւeJH$J3xG[+@PtHGGc[/"^Gށi184i#_u4UH-k9%=9by$k%hb5QC͘,7iYCb7L4vLf7, v Z14Ը[JЙ<NFws/˩E8g%8mYD8Ɵ_87ja5'ngjHblȋ<L,՟[UqH TvצZrAb_pꬣ4 "քjU=G&s%",)X^o̡dtA"8lqt;C$;[z:P^:.a>Jq$a3&Vy*^@É "H~-5X3sm`a*ՀߦT,t:KX/u4lRό`Cc]i9|ɅQ&q<KMzv iW8CvCzPIa'^6f <lQlY&~qJS?Qjpλ+ o@@H؍uGpKn>ql!JTYAPnTVrBkrm>h1O"&>4Ǝ~9bDQ^BJ3<*ex=QV9dTn%r+bUOM'҈͘90J"wWlM&[HPHyRGpU)B)'=4 ہ.)a嗀1zf,M2ަe.PAΒ˜WUh~Xakq`bJAEtGcr/v0xpC/Ĺ@9y9lqzfb:+.l[7M,4fv:t]hXN+]1^+ר1BS;H)8Km8p*yG"EA%Uܝ"hM'!Wkrc!mDaS $ǜ2 B.Th̘>2!nXxqXFܭu".U:GX9&p۴_0pc;ϰ~7''KK"aZ_S,e9olOHu(xhn? Ӟy59ffjpZ(<+PANא-3Wx3o]dʖ/?J^ȧwc`=v:ƺ/D ؎<=%.-<=+͘&ҹfvטd`.I7^UFa$.vxY]CHDIlԿVsXT;FݱHTeўAնpO"VI$OesvĚs`MD/zkQ=n*muA$L%İZwV$_kV8$t5_v~1F>i$Rt?n`+!^-5'ìPW呩X0p&mRb躱67Ȫ0jYY^mcLz3dsymK./a4!gF#vYnTsl+r$oZgBD;5 ,kD ... |
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Yw9G-4_B\Rpss_8PAcreSznq0jw9\KevqRYRLai6W-uOAz\cpZgjv9AbFGPDH.odt | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Yw9G-4_B\Rpss_8PAcreSznq0jw9\KevqRYRLai6W-uOAz\rBf2xQ.ods | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\KIbJxOBGwieG.avi | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Adobe\Acrobat\10.0\rdrmessage.zip | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.msi | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\Deployment\deployment.properties | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\aqq4ZugPM-uIfNTNxref\Kpmxx2VVkoY4H0fX.mp4 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\VehoR9xPCLy8\5rGtE2ND.flv | Modified File | Video |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\VehoR9xPCLy8\ccASAQTIpPKgN.flv | Modified File | Video |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\VehoR9xPCLy8\OTozEY.mkv | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\Xp-kb7abpIDOqh4\M5qZaTsTRd.mp4 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\Xp-kb7abpIDOqh4\ykO6fV_h.avi | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\36USA68T\imagesrv.adition[1].xml | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\VGMTOI09\www.msn[1].xml | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\aqq4ZugPM-uIfNTNxref\3YQcDZAJgPao0vK26HVe\9vWEh.mkv | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\aqq4ZugPM-uIfNTNxref\3YQcDZAJgPao0vK26HVe\KZ_Ff2.avi | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\aqq4ZugPM-uIfNTNxref\oADBIR\8KFC8j7.swf | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\aqq4ZugPM-uIfNTNxref\oADBIR\K KksBwzXVChJt.mp4 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\aqq4ZugPM-uIfNTNxref\oADBIR\KiC_I4C.avi | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\VehoR9xPCLy8\0KK-LJo0NlWa\8XX4ge15eOKpjI.mp4 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\VehoR9xPCLy8\0KK-LJo0NlWa\POBuKqk7p3HVpix_cM.mp4 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\VehoR9xPCLy8\0KK-LJo0NlWa\rM0K82IAegAWaw6N.swf | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\VehoR9xPCLy8\IAQDAF9mflNWLRgoJL\h4Ure_SWB.mp4 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\VehoR9xPCLy8\IAQDAF9mflNWLRgoJL\RbKeEPsH8.avi | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\VehoR9xPCLy8\IAQDAF9mflNWLRgoJL\shUk4EGQd0zRO ddsru9.mkv | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\A959.tmp.exe | Modified File | Binary |
Unknown
|
...
|
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
a959.tmp.exe | 1 | 0x00400000 | 0x00490FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00678280 | 0x006BE377 | Marked Executable | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00678280 | 0x006BE377 | Content Changed | - | 32-bit | 0x006790C5 |
![]() |
![]() |
...
|
buffer | 1 | 0x00678280 | 0x006BE377 | Content Changed | - | 32-bit | 0x006799E5 |
![]() |
![]() |
...
|
a959.tmp.exe | 1 | 0x00400000 | 0x00490FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\ietldcache\index.dat | Modified File | Stream |
Unknown
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\x9ohk109\geo[1].json | Dropped File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\7FXGdv.mkv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\fn3wxYGSmK_5.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\KdF36F.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\kKP8D1f.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\OjEEOfskM8q.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Pdn3smOfWiyL_KFEcP0.mp4 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Xe1YhHNVlwT k.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\_34_nkr.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\2 YiCSGLLTlIDeQ.doc | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3fgk.pps | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\EGkqtCRNREaQo4XfBL.ods | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\k0bYHnrNfY0Z01.docx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\NU9iOZGfDM.xlsx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ol37DpMB ADCzniH6.docx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\OlNTdQSKj.csv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\rMkTON600uD2.docx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\yBWTsx0.xlsx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\3lDgGO6UTyrOsMHE.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Fnpi8zzFvSVq9mHNij76.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\HX-X27lPA60A4.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\i0vpbCxKUDj27FIiTrf.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\KbAGa_jf9A0p1.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\nexJic6.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ucbmmg-N-J.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\wEWdm1lt.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\wHquroq M2bDSunIrjJ.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\_9l8.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\jMNoGbN.gif | Modified File | Image |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\MCZaDa0QQJ6wcNZUXn.gif | Modified File | Image |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\QoXfvFeQOhQIV.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\S4GQ2GGMfzy1DKUl.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\y18suG.gif | Modified File | Image |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\M45yR7c437.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\0oqCmMdMfyA -VyQ\am8f6gN_e89TbRknT.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\cJ1uF3yzdYr\4_mbPPGlzHp_oUuJ-H3Z.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Qz91k6FGRf5u2kNaQ\eMppgNp_d0eONIt.mp4 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Qz91k6FGRf5u2kNaQ\ok1IxJmM0MNDy1z2SKRW.odp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Qz91k6FGRf5u2kNaQ\wpZkXn.mp4 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Yw9G-4_B\68l k.odp | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE site on Microsoft.com.url | Modified File | Text |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Work.url | Modified File | Text |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Autos.url | Modified File | Text |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN.url | Modified File | Text |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Get Windows Live.url | Modified File | Text |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Gallery.url | Modified File | Text |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Mail.url | Modified File | Text |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\bAXbPKiwKvGBE_6IlyS\MChYwIiGCBst93Q.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\bAXbPKiwKvGBE_6IlyS\twAQxH8FOS.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\1oLW\AfHqN B.gif | Modified File | Image |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\1oLW\UYXfotd1.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\1oLW\v9Hxi uz2vt-5XDoxdC.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\IE-asuVeDit5fMSdkB0.flv | Modified File | Video |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Yw9G-4_B\Rpss_8PAcreSznq0jw9\F0eUqh0cOkUTa7DO.docx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Yw9G-4_B\Rpss_8PAcreSznq0jw9\FN--.ods | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Yw9G-4_B\Rpss_8PAcreSznq0jw9\K_RwYW.odt | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Yw9G-4_B\Rpss_8PAcreSznq0jw9\NxEBIllQ9 cZLQxHAnf.xlsx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Yw9G-4_B\Rpss_8PAcreSznq0jw9\ypdm7CG6ozW8_F3RQh.pps | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\1oLW\gJs687PmdwJ\1m7527vbdeC.gif | Modified File | Image |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\1oLW\gJs687PmdwJ\cSaVaB0sUlp.gif | Modified File | Image |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\1oLW\gJs687PmdwJ\EWTals.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\1oLW\gJs687PmdwJ\TK27wDdNd6Xfl 2b_k_.gif | Modified File | Image |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\1oLW\gJs687PmdwJ\Wqelj SIFg-o4.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Yw9G-4_B\NtnCGgs\-3tBc\p-qIG.doc | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\B2EsvKtcKir28U.mkv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\Jf 8.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\WTnDwa-D4KBHQUw.mkv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\index.dat | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.cab | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\Data1.cab | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\jre1.7.0_45.msi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\aqq4ZugPM-uIfNTNxref\3YQcDZAJgPao0vK26HVe\dH-l6u.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\aqq4ZugPM-uIfNTNxref\3YQcDZAJgPao0vK26HVe\ziyBrxM6Ba3SqMjEYO.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\VehoR9xPCLy8\0KK-LJo0NlWa\-upHLx loeeu-TB.mkv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\VehoR9xPCLy8\IAQDAF9mflNWLRgoJL\f NqUp5_D7sMGe.flv | Modified File | Video |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\VehoR9xPCLy8\IAQDAF9mflNWLRgoJL\tEhXK0.mp4 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vcVOmt\2odT1K\VuM2\VehoR9xPCLy8\IAQDAF9mflNWLRgoJL\yboEd.avi | Modified File | Stream |
Not Queried
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat | Modified File | Stream |
Not Queried
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\index.dat | Modified File | Stream |
Not Queried
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\history\history.ie5\index.dat | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\script.ps1 | Dropped File | Text |
Not Queried
|
...
|

WHOIS Domain Information
Domain Name | |
WHOIS Response |



This feature requires an online-connection to the VMRay backend.
An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".
Before
This feature requires an online-connection to the VMRay backend.
An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".
After
This feature requires an online-connection to the VMRay backend.
An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".




