VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Wiper |
fbgliw.exe
Windows Exe (x86-32)
Created at 2019-10-26T06:27:00
Remarks
(0x200001e): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x44c51b |
Size Of Code | 0x9d800 |
Size Of Initialized Data | 0x32800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-09-13 12:05:47+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x9d786 | 0x9d800 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.69 |
.rdata | 0x49f000 | 0x22c5e | 0x22e00 | 0x9dc00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.1 |
.data | 0x4c2000 | 0x6ca8 | 0x4800 | 0xc0a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.7 |
.rsrc | 0x4c9000 | 0x1e0 | 0x200 | 0xc5200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.72 |
.reloc | 0x4ca000 | 0x88ec | 0x8a00 | 0xc5400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.58 |
Imports (2)
»
KERNEL32.dll (142)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WaitForSingleObject | 0x0 | 0x49f000 | 0xc0ef4 | 0xbfaf4 | 0x4f9 |
OpenProcess | 0x0 | 0x49f004 | 0xc0ef8 | 0xbfaf8 | 0x380 |
CreateToolhelp32Snapshot | 0x0 | 0x49f008 | 0xc0efc | 0xbfafc | 0xbe |
Process32Next | 0x0 | 0x49f00c | 0xc0f00 | 0xbfb00 | 0x397 |
CloseHandle | 0x0 | 0x49f010 | 0xc0f04 | 0xbfb04 | 0x52 |
FreeConsole | 0x0 | 0x49f014 | 0xc0f08 | 0xbfb08 | 0x15f |
SetFileAttributesA | 0x0 | 0x49f018 | 0xc0f0c | 0xbfb0c | 0x45e |
GetDriveTypeA | 0x0 | 0x49f01c | 0xc0f10 | 0xbfb10 | 0x1d2 |
GetLastError | 0x0 | 0x49f020 | 0xc0f14 | 0xbfb14 | 0x202 |
SetLastError | 0x0 | 0x49f024 | 0xc0f18 | 0xbfb18 | 0x473 |
QueryPerformanceCounter | 0x0 | 0x49f028 | 0xc0f1c | 0xbfb1c | 0x3a7 |
QueryPerformanceFrequency | 0x0 | 0x49f02c | 0xc0f20 | 0xbfb20 | 0x3a8 |
GetCurrentThread | 0x0 | 0x49f030 | 0xc0f24 | 0xbfb24 | 0x1c4 |
GetThreadTimes | 0x0 | 0x49f034 | 0xc0f28 | 0xbfb28 | 0x291 |
GetProcessHeap | 0x0 | 0x49f038 | 0xc0f2c | 0xbfb2c | 0x24a |
TerminateProcess | 0x0 | 0x49f03c | 0xc0f30 | 0xbfb30 | 0x4c0 |
Process32First | 0x0 | 0x49f040 | 0xc0f34 | 0xbfb34 | 0x395 |
CreateProcessA | 0x0 | 0x49f044 | 0xc0f38 | 0xbfb38 | 0xa4 |
GetLogicalDrives | 0x0 | 0x49f048 | 0xc0f3c | 0xbfb3c | 0x209 |
SetStdHandle | 0x0 | 0x49f04c | 0xc0f40 | 0xbfb40 | 0x487 |
FreeEnvironmentStringsW | 0x0 | 0x49f050 | 0xc0f44 | 0xbfb44 | 0x161 |
GetEnvironmentStringsW | 0x0 | 0x49f054 | 0xc0f48 | 0xbfb48 | 0x1da |
GetOEMCP | 0x0 | 0x49f058 | 0xc0f4c | 0xbfb4c | 0x237 |
IsValidCodePage | 0x0 | 0x49f05c | 0xc0f50 | 0xbfb50 | 0x30a |
FindNextFileA | 0x0 | 0x49f060 | 0xc0f54 | 0xbfb54 | 0x143 |
FindFirstFileExA | 0x0 | 0x49f064 | 0xc0f58 | 0xbfb58 | 0x133 |
GetTimeZoneInformation | 0x0 | 0x49f068 | 0xc0f5c | 0xbfb5c | 0x298 |
HeapSize | 0x0 | 0x49f06c | 0xc0f60 | 0xbfb60 | 0x2d4 |
HeapReAlloc | 0x0 | 0x49f070 | 0xc0f64 | 0xbfb64 | 0x2d2 |
ReadConsoleW | 0x0 | 0x49f074 | 0xc0f68 | 0xbfb68 | 0x3be |
ReadFile | 0x0 | 0x49f078 | 0xc0f6c | 0xbfb6c | 0x3c0 |
EnumSystemLocalesW | 0x0 | 0x49f07c | 0xc0f70 | 0xbfb70 | 0x10f |
GetUserDefaultLCID | 0x0 | 0x49f080 | 0xc0f74 | 0xbfb74 | 0x29b |
IsValidLocale | 0x0 | 0x49f084 | 0xc0f78 | 0xbfb78 | 0x30c |
GetTimeFormatW | 0x0 | 0x49f088 | 0xc0f7c | 0xbfb7c | 0x297 |
GetDateFormatW | 0x0 | 0x49f08c | 0xc0f80 | 0xbfb80 | 0x1c8 |
GetExitCodeProcess | 0x0 | 0x49f090 | 0xc0f84 | 0xbfb84 | 0x1df |
HeapFree | 0x0 | 0x49f094 | 0xc0f88 | 0xbfb88 | 0x2cf |
GetConsoleMode | 0x0 | 0x49f098 | 0xc0f8c | 0xbfb8c | 0x1ac |
CreateFileW | 0x0 | 0x49f09c | 0xc0f90 | 0xbfb90 | 0x8f |
FindClose | 0x0 | 0x49f0a0 | 0xc0f94 | 0xbfb94 | 0x12e |
FindFirstFileExW | 0x0 | 0x49f0a4 | 0xc0f98 | 0xbfb98 | 0x134 |
FindNextFileW | 0x0 | 0x49f0a8 | 0xc0f9c | 0xbfb9c | 0x145 |
GetDiskFreeSpaceExW | 0x0 | 0x49f0ac | 0xc0fa0 | 0xbfba0 | 0x1ce |
GetFileAttributesExW | 0x0 | 0x49f0b0 | 0xc0fa4 | 0xbfba4 | 0x1e7 |
SetEndOfFile | 0x0 | 0x49f0b4 | 0xc0fa8 | 0xbfba8 | 0x453 |
SetFileAttributesW | 0x0 | 0x49f0b8 | 0xc0fac | 0xbfbac | 0x461 |
SetFilePointerEx | 0x0 | 0x49f0bc | 0xc0fb0 | 0xbfbb0 | 0x467 |
AreFileApisANSI | 0x0 | 0x49f0c0 | 0xc0fb4 | 0xbfbb4 | 0x15 |
MultiByteToWideChar | 0x0 | 0x49f0c4 | 0xc0fb8 | 0xbfbb8 | 0x367 |
WideCharToMultiByte | 0x0 | 0x49f0c8 | 0xc0fbc | 0xbfbbc | 0x511 |
FormatMessageW | 0x0 | 0x49f0cc | 0xc0fc0 | 0xbfbc0 | 0x15e |
EnterCriticalSection | 0x0 | 0x49f0d0 | 0xc0fc4 | 0xbfbc4 | 0xee |
LeaveCriticalSection | 0x0 | 0x49f0d4 | 0xc0fc8 | 0xbfbc8 | 0x339 |
TryEnterCriticalSection | 0x0 | 0x49f0d8 | 0xc0fcc | 0xbfbcc | 0x4ce |
DeleteCriticalSection | 0x0 | 0x49f0dc | 0xc0fd0 | 0xbfbd0 | 0xd1 |
GetCurrentThreadId | 0x0 | 0x49f0e0 | 0xc0fd4 | 0xbfbd4 | 0x1c5 |
DuplicateHandle | 0x0 | 0x49f0e4 | 0xc0fd8 | 0xbfbd8 | 0xe8 |
WaitForSingleObjectEx | 0x0 | 0x49f0e8 | 0xc0fdc | 0xbfbdc | 0x4fa |
Sleep | 0x0 | 0x49f0ec | 0xc0fe0 | 0xbfbe0 | 0x4b2 |
GetCurrentProcess | 0x0 | 0x49f0f0 | 0xc0fe4 | 0xbfbe4 | 0x1c0 |
SwitchToThread | 0x0 | 0x49f0f4 | 0xc0fe8 | 0xbfbe8 | 0x4bc |
GetExitCodeThread | 0x0 | 0x49f0f8 | 0xc0fec | 0xbfbec | 0x1e0 |
GetStringTypeW | 0x0 | 0x49f0fc | 0xc0ff0 | 0xbfbf0 | 0x269 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x49f100 | 0xc0ff4 | 0xbfbf4 | 0x2e3 |
CreateEventW | 0x0 | 0x49f104 | 0xc0ff8 | 0xbfbf8 | 0x85 |
TlsAlloc | 0x0 | 0x49f108 | 0xc0ffc | 0xbfbfc | 0x4c5 |
TlsGetValue | 0x0 | 0x49f10c | 0xc1000 | 0xbfc00 | 0x4c7 |
TlsSetValue | 0x0 | 0x49f110 | 0xc1004 | 0xbfc04 | 0x4c8 |
TlsFree | 0x0 | 0x49f114 | 0xc1008 | 0xbfc08 | 0x4c6 |
GetSystemTimeAsFileTime | 0x0 | 0x49f118 | 0xc100c | 0xbfc0c | 0x279 |
GetTickCount | 0x0 | 0x49f11c | 0xc1010 | 0xbfc10 | 0x293 |
GetModuleHandleW | 0x0 | 0x49f120 | 0xc1014 | 0xbfc14 | 0x218 |
GetProcAddress | 0x0 | 0x49f124 | 0xc1018 | 0xbfc18 | 0x245 |
EncodePointer | 0x0 | 0x49f128 | 0xc101c | 0xbfc1c | 0xea |
DecodePointer | 0x0 | 0x49f12c | 0xc1020 | 0xbfc20 | 0xca |
CompareStringW | 0x0 | 0x49f130 | 0xc1024 | 0xbfc24 | 0x64 |
LCMapStringW | 0x0 | 0x49f134 | 0xc1028 | 0xbfc28 | 0x32d |
GetLocaleInfoW | 0x0 | 0x49f138 | 0xc102c | 0xbfc2c | 0x206 |
GetCPInfo | 0x0 | 0x49f13c | 0xc1030 | 0xbfc30 | 0x172 |
FormatMessageA | 0x0 | 0x49f140 | 0xc1034 | 0xbfc34 | 0x15d |
LocalFree | 0x0 | 0x49f144 | 0xc1038 | 0xbfc38 | 0x348 |
DeleteFileW | 0x0 | 0x49f148 | 0xc103c | 0xbfc3c | 0xd6 |
GetFileAttributesW | 0x0 | 0x49f14c | 0xc1040 | 0xbfc40 | 0x1ea |
MoveFileExW | 0x0 | 0x49f150 | 0xc1044 | 0xbfc44 | 0x360 |
InitializeSListHead | 0x0 | 0x49f154 | 0xc1048 | 0xbfc48 | 0x2e7 |
SetEvent | 0x0 | 0x49f158 | 0xc104c | 0xbfc4c | 0x459 |
ResetEvent | 0x0 | 0x49f15c | 0xc1050 | 0xbfc50 | 0x40f |
IsProcessorFeaturePresent | 0x0 | 0x49f160 | 0xc1054 | 0xbfc54 | 0x304 |
UnhandledExceptionFilter | 0x0 | 0x49f164 | 0xc1058 | 0xbfc58 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x49f168 | 0xc105c | 0xbfc5c | 0x4a5 |
GetCurrentProcessId | 0x0 | 0x49f16c | 0xc1060 | 0xbfc60 | 0x1c1 |
IsDebuggerPresent | 0x0 | 0x49f170 | 0xc1064 | 0xbfc64 | 0x300 |
GetStartupInfoW | 0x0 | 0x49f174 | 0xc1068 | 0xbfc68 | 0x263 |
CreateTimerQueue | 0x0 | 0x49f178 | 0xc106c | 0xbfc6c | 0xbc |
SignalObjectAndWait | 0x0 | 0x49f17c | 0xc1070 | 0xbfc70 | 0x4b0 |
CreateThread | 0x0 | 0x49f180 | 0xc1074 | 0xbfc74 | 0xb5 |
SetThreadPriority | 0x0 | 0x49f184 | 0xc1078 | 0xbfc78 | 0x499 |
GetThreadPriority | 0x0 | 0x49f188 | 0xc107c | 0xbfc7c | 0x28e |
GetLogicalProcessorInformation | 0x0 | 0x49f18c | 0xc1080 | 0xbfc80 | 0x20a |
CreateTimerQueueTimer | 0x0 | 0x49f190 | 0xc1084 | 0xbfc84 | 0xbd |
ChangeTimerQueueTimer | 0x0 | 0x49f194 | 0xc1088 | 0xbfc88 | 0x48 |
DeleteTimerQueueTimer | 0x0 | 0x49f198 | 0xc108c | 0xbfc8c | 0xda |
GetNumaHighestNodeNumber | 0x0 | 0x49f19c | 0xc1090 | 0xbfc90 | 0x229 |
GetProcessAffinityMask | 0x0 | 0x49f1a0 | 0xc1094 | 0xbfc94 | 0x246 |
SetThreadAffinityMask | 0x0 | 0x49f1a4 | 0xc1098 | 0xbfc98 | 0x490 |
RegisterWaitForSingleObject | 0x0 | 0x49f1a8 | 0xc109c | 0xbfc9c | 0x3f5 |
UnregisterWait | 0x0 | 0x49f1ac | 0xc10a0 | 0xbfca0 | 0x4da |
OutputDebugStringW | 0x0 | 0x49f1b0 | 0xc10a4 | 0xbfca4 | 0x38a |
FreeLibrary | 0x0 | 0x49f1b4 | 0xc10a8 | 0xbfca8 | 0x162 |
FreeLibraryAndExitThread | 0x0 | 0x49f1b8 | 0xc10ac | 0xbfcac | 0x163 |
GetModuleFileNameW | 0x0 | 0x49f1bc | 0xc10b0 | 0xbfcb0 | 0x214 |
GetModuleHandleA | 0x0 | 0x49f1c0 | 0xc10b4 | 0xbfcb4 | 0x215 |
LoadLibraryExW | 0x0 | 0x49f1c4 | 0xc10b8 | 0xbfcb8 | 0x33e |
GetVersionExW | 0x0 | 0x49f1c8 | 0xc10bc | 0xbfcbc | 0x2a4 |
VirtualAlloc | 0x0 | 0x49f1cc | 0xc10c0 | 0xbfcc0 | 0x4e9 |
VirtualProtect | 0x0 | 0x49f1d0 | 0xc10c4 | 0xbfcc4 | 0x4ef |
VirtualFree | 0x0 | 0x49f1d4 | 0xc10c8 | 0xbfcc8 | 0x4ec |
ReleaseSemaphore | 0x0 | 0x49f1d8 | 0xc10cc | 0xbfccc | 0x3fe |
InterlockedPopEntrySList | 0x0 | 0x49f1dc | 0xc10d0 | 0xbfcd0 | 0x2f0 |
InterlockedPushEntrySList | 0x0 | 0x49f1e0 | 0xc10d4 | 0xbfcd4 | 0x2f1 |
InterlockedFlushSList | 0x0 | 0x49f1e4 | 0xc10d8 | 0xbfcd8 | 0x2ee |
QueryDepthSList | 0x0 | 0x49f1e8 | 0xc10dc | 0xbfcdc | 0x39e |
UnregisterWaitEx | 0x0 | 0x49f1ec | 0xc10e0 | 0xbfce0 | 0x4db |
LoadLibraryW | 0x0 | 0x49f1f0 | 0xc10e4 | 0xbfce4 | 0x33f |
RtlUnwind | 0x0 | 0x49f1f4 | 0xc10e8 | 0xbfce8 | 0x418 |
RaiseException | 0x0 | 0x49f1f8 | 0xc10ec | 0xbfcec | 0x3b1 |
GetStdHandle | 0x0 | 0x49f1fc | 0xc10f0 | 0xbfcf0 | 0x264 |
GetFileType | 0x0 | 0x49f200 | 0xc10f4 | 0xbfcf4 | 0x1f3 |
GetModuleFileNameA | 0x0 | 0x49f204 | 0xc10f8 | 0xbfcf8 | 0x213 |
GetModuleHandleExW | 0x0 | 0x49f208 | 0xc10fc | 0xbfcfc | 0x217 |
WriteConsoleW | 0x0 | 0x49f20c | 0xc1100 | 0xbfd00 | 0x524 |
SetEnvironmentVariableA | 0x0 | 0x49f210 | 0xc1104 | 0xbfd04 | 0x456 |
ExitThread | 0x0 | 0x49f214 | 0xc1108 | 0xbfd08 | 0x11a |
WriteFile | 0x0 | 0x49f218 | 0xc110c | 0xbfd0c | 0x525 |
ExitProcess | 0x0 | 0x49f21c | 0xc1110 | 0xbfd10 | 0x119 |
GetCommandLineA | 0x0 | 0x49f220 | 0xc1114 | 0xbfd14 | 0x186 |
GetCommandLineW | 0x0 | 0x49f224 | 0xc1118 | 0xbfd18 | 0x187 |
GetACP | 0x0 | 0x49f228 | 0xc111c | 0xbfd1c | 0x168 |
HeapAlloc | 0x0 | 0x49f22c | 0xc1120 | 0xbfd20 | 0x2cb |
FlushFileBuffers | 0x0 | 0x49f230 | 0xc1124 | 0xbfd24 | 0x157 |
GetConsoleCP | 0x0 | 0x49f234 | 0xc1128 | 0xbfd28 | 0x19a |
WS2_32.dll (19)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WSACleanup | 0x74 | 0x49f23c | 0xc1130 | 0xbfd30 | - |
WSAStartup | 0x73 | 0x49f240 | 0xc1134 | 0xbfd34 | - |
htons | 0x9 | 0x49f244 | 0xc1138 | 0xbfd38 | - |
ioctlsocket | 0xa | 0x49f248 | 0xc113c | 0xbfd3c | - |
closesocket | 0x3 | 0x49f24c | 0xc1140 | 0xbfd40 | - |
send | 0x13 | 0x49f250 | 0xc1144 | 0xbfd44 | - |
select | 0x12 | 0x49f254 | 0xc1148 | 0xbfd48 | - |
recv | 0x10 | 0x49f258 | 0xc114c | 0xbfd4c | - |
WSAGetLastError | 0x6f | 0x49f25c | 0xc1150 | 0xbfd50 | - |
freeaddrinfo | 0x0 | 0x49f260 | 0xc1154 | 0xbfd54 | 0x88 |
getaddrinfo | 0x0 | 0x49f264 | 0xc1158 | 0xbfd58 | 0x89 |
ntohl | 0xe | 0x49f268 | 0xc115c | 0xbfd5c | - |
inet_ntoa | 0xc | 0x49f26c | 0xc1160 | 0xbfd60 | - |
inet_addr | 0xb | 0x49f270 | 0xc1164 | 0xbfd64 | - |
htonl | 0x8 | 0x49f274 | 0xc1168 | 0xbfd68 | - |
connect | 0x4 | 0x49f278 | 0xc116c | 0xbfd6c | - |
socket | 0x17 | 0x49f27c | 0xc1170 | 0xbfd70 | - |
setsockopt | 0x15 | 0x49f280 | 0xc1174 | 0xbfd74 | - |
getpeername | 0x5 | 0x49f284 | 0xc1178 | 0xbfd78 | - |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
fbgliw.exe | 1 | 0x001B0000 | 0x00282FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
fbgliw.exe | 1 | 0x001B0000 | 0x00282FFF | Final Dump | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
DeepScan:Generic.Ransom.Ouroboros.6DD98B5B |
Malicious
|
C:\588bce7c90097ed212\1036\eula.rtf | Modified File | Batch |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2011-06-14 17:40 (UTC+2) |
Last Seen | 2019-10-23 09:54 (UTC+2) |
C:\588bce7c90097ed212\netfx_Core.mzz | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core.mzz | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x64.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x64.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x64.msi.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x86.msi.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Security.evtx.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\System.evtx.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pidgenx.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\preoobe.cmd.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\SetupComplete.cmd.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\$Recycle.Bin\S-1-5-18\desktop.ini.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\LocalizedData.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\SetupResources.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\eula.rtf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\SetupResources.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\LocalizedData.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\SetupResources.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\eula.rtf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\LocalizedData.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\SetupResources.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x64.msi.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\LocalizedData.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\SetupResources.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupEngine.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\LocalizedData.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\SetupResources.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\SetupResources.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\LocalizedData.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\LocalizedData.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\SetupResources.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\LocalizedData.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\SetupResources.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\eula.rtf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\LocalizedData.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\SetupResources.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\eula.rtf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\LocalizedData.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\SetupResources.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\LocalizedData.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\SetupResources.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\eula.rtf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\SetupResources.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\LocalizedData.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\SetupResources.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\eula.rtf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\LocalizedData.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\SetupResources.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\eula.rtf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\LocalizedData.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RUI.en-us.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\LocalizedData.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\SetupResources.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RCom.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\LocalizedData.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\SetupResources.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\eula.rtf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\ucrtbase.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\LocalizedData.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\SetupResources.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\Parameterinfo.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\UiInfo.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DHtmlHeader.html.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DisplayIcon.ico.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate1.ico.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate2.ico.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate3.ico.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate4.ico.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate7.ico.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig-office.xrm-ms.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate8.ico.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Setup.ico.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\stop.ico.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqMet.ico.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\warn.ico.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x86.msi.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\VC\msdia100.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\RGB9RAST_x64.msi.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\RGB9Rast_x86.msi.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\VC\msdia90.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupUi.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Strings.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\UiInfo.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\BOOTSTAT.DAT.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\deploy.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\deployJava1.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\javafx_font_t2k.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\BOOTNXT.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\BOOTSECT.BAK.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Application.evtx.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\mlib_image.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Internet Explorer.evtx.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\msvcp120.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\DESIGNER\MSADDNDR.OLB.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l1-2-0.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l2-1-0.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-localization-l1-2-0.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-processthreads-l1-1-1.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-synch-l1-2-0.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-timezone-l1-1-0.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-xstate-l2-1-0.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-conio-l1-1-0.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaSansRegular.ttf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-environment-l1-1-0.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-filesystem-l1-1-0.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-heap-l1-1-0.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-locale-l1-1-0.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-math-l1-1-0.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-multibyte-l1-1-0.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\javaws.jar.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core.mzz | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1031\SetupResources.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1032\SetupResources.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1035\LocalizedData.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1035\SetupResources.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1040\SetupResources.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1041\eula.rtf.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1046\LocalizedData.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1055\SetupResources.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3082\LocalizedData.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3082\SetupResources.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Extended\Parameterinfo.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Extended\UiInfo.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Print.ico.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate5.ico.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate6.ico.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Save.ico.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.xml.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\sqmapi.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\msvcr100.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Setup.evtx.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-convert-l1-1-0.dll.[ID=5upxf7MvaH][Mail=letitbedecryptedzi@gmail.com].Lazarus+ | Dropped File | Stream |
Not Queried
|
...
|
»