Malicious
Classifications
Ransomware
Threat Names
Mal/Generic-S
Dynamic Analysis Report
Created on 2023-12-27T00:56:19+00:00
Setup.exe
Windows Exe (x86-32)
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "2 minutes" to "20 seconds" to reveal dormant functionality.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\kEecfMwgj\Desktop\Setup.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Verdict |
Malicious
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x01022186 |
Size Of Code | 0x00C20200 |
Size Of Initialized Data | 0x00020C00 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2038-05-23 18:39 (UTC) |
Version Information (11)
»
Comments | Hack of Fortnite, with Aimbot and ESP |
CompanyName | - |
FileDescription | Fortnite Hacks |
FileVersion | 16.0.5.0 |
InternalName | SyrkProject.exe |
LegalCopyright | Copyright © 2019 |
LegalTrademarks | - |
OriginalFilename | SyrkProject.exe |
ProductName | Fortnite Hacks |
ProductVersion | 16.0.5.0 |
Assembly Version | 16.0.5.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00402000 | 0x00C2018C | 0x00C20200 | 0x00000200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.75 |
.rsrc | 0x01024000 | 0x00020A00 | 0x00020A00 | 0x00C20400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.reloc | 0x01046000 | 0x0000000C | 0x00000200 | 0x00C40E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | - | 0x00402000 | 0x00C2215A | 0x00C2035A | 0x00000000 |
Memory Dumps (6)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
setup.exe | 1 | 0x01360000 | 0x01FA7FFF | Relevant Image |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x00CFE000 | 0x00CFFFFF | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x00379000 | 0x0037FFFF | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x0054E488 | 0x0055E586 | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
setup.exe | 1 | 0x01360000 | 0x01FA7FFF | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
setup.exe | 1 | 0x01360000 | 0x01FA7FFF | Final Dump |
![]() |
32-bit | - |
![]() |
...
|
C:\Users\Public\Documents\cgo46ea565sdfse7.exe | Dropped File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Verdict |
Malicious
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x004014A0 |
Size Of Code | 0x00001800 |
Size Of Initialized Data | 0x0000B800 |
Size Of Uninitialized Data | 0x00000400 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_CUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-07-24 09:03 (UTC) |
Sections (15)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000016C4 | 0x00001800 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.86 |
.data | 0x00403000 | 0x00006FCC | 0x00007000 | 0x00001C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.66 |
.rdata | 0x0040A000 | 0x000025C4 | 0x00002600 | 0x00008C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ | 5.16 |
.bss | 0x0040D000 | 0x000003E8 | 0x00000000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.idata | 0x0040E000 | 0x0000058C | 0x00000600 | 0x0000B200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.5 |
.CRT | 0x0040F000 | 0x00000034 | 0x00000200 | 0x0000B800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.27 |
.tls | 0x00410000 | 0x00000008 | 0x00000200 | 0x0000BA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
/4 | 0x00411000 | 0x000002A8 | 0x00000400 | 0x0000BC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 1.73 |
/19 | 0x00412000 | 0x0003D69C | 0x0003D800 | 0x0000C000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.96 |
/31 | 0x00450000 | 0x0000212E | 0x00002200 | 0x00049800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 4.57 |
/45 | 0x00453000 | 0x000021DE | 0x00002200 | 0x0004BA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.23 |
/57 | 0x00456000 | 0x00000748 | 0x00000800 | 0x0004DC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 4.42 |
/70 | 0x00457000 | 0x000006D3 | 0x00000800 | 0x0004E400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 4.54 |
/81 | 0x00458000 | 0x00000D83 | 0x00000E00 | 0x0004EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 3.5 |
/92 | 0x00459000 | 0x000001C0 | 0x00000200 | 0x0004FA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 2.62 |
Imports (3)
»
KERNEL32.dll (20)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DeleteCriticalSection | - | 0x0040E114 | 0x0000E050 | 0x0000B250 | 0x000000D7 |
EnterCriticalSection | - | 0x0040E118 | 0x0000E054 | 0x0000B254 | 0x000000F3 |
GetConsoleWindow | - | 0x0040E11C | 0x0000E058 | 0x0000B258 | 0x000001BF |
GetCurrentProcess | - | 0x0040E120 | 0x0000E05C | 0x0000B25C | 0x000001C8 |
GetCurrentProcessId | - | 0x0040E124 | 0x0000E060 | 0x0000B260 | 0x000001C9 |
GetCurrentThreadId | - | 0x0040E128 | 0x0000E064 | 0x0000B264 | 0x000001CD |
GetLastError | - | 0x0040E12C | 0x0000E068 | 0x0000B268 | 0x00000207 |
GetStartupInfoA | - | 0x0040E130 | 0x0000E06C | 0x0000B26C | 0x00000268 |
GetSystemTimeAsFileTime | - | 0x0040E134 | 0x0000E070 | 0x0000B270 | 0x0000027F |
GetTickCount | - | 0x0040E138 | 0x0000E074 | 0x0000B274 | 0x0000029B |
InitializeCriticalSection | - | 0x0040E13C | 0x0000E078 | 0x0000B278 | 0x000002EF |
LeaveCriticalSection | - | 0x0040E140 | 0x0000E07C | 0x0000B27C | 0x00000345 |
QueryPerformanceCounter | - | 0x0040E144 | 0x0000E080 | 0x0000B280 | 0x000003B6 |
SetUnhandledExceptionFilter | - | 0x0040E148 | 0x0000E084 | 0x0000B284 | 0x0000048C |
Sleep | - | 0x0040E14C | 0x0000E088 | 0x0000B288 | 0x00000499 |
TerminateProcess | - | 0x0040E150 | 0x0000E08C | 0x0000B28C | 0x000004A7 |
TlsGetValue | - | 0x0040E154 | 0x0000E090 | 0x0000B290 | 0x000004AE |
UnhandledExceptionFilter | - | 0x0040E158 | 0x0000E094 | 0x0000B294 | 0x000004BB |
VirtualProtect | - | 0x0040E15C | 0x0000E098 | 0x0000B298 | 0x000004DB |
VirtualQuery | - | 0x0040E160 | 0x0000E09C | 0x0000B29C | 0x000004DE |
msvcrt.dll (25)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
__getmainargs | - | 0x0040E168 | 0x0000E0A4 | 0x0000B2A4 | 0x0000003B |
__initenv | - | 0x0040E16C | 0x0000E0A8 | 0x0000B2A8 | 0x0000003C |
__lconv_init | - | 0x0040E170 | 0x0000E0AC | 0x0000B2AC | 0x00000045 |
__p__acmdln | - | 0x0040E174 | 0x0000E0B0 | 0x0000B2B0 | 0x0000004D |
__p__fmode | - | 0x0040E178 | 0x0000E0B4 | 0x0000B2B4 | 0x00000054 |
__set_app_type | - | 0x0040E17C | 0x0000E0B8 | 0x0000B2B8 | 0x00000069 |
__setusermatherr | - | 0x0040E180 | 0x0000E0BC | 0x0000B2BC | 0x0000006C |
_amsg_exit | - | 0x0040E184 | 0x0000E0C0 | 0x0000B2C0 | 0x0000008F |
_cexit | - | 0x0040E188 | 0x0000E0C4 | 0x0000B2C4 | 0x000000A0 |
_initterm | - | 0x0040E18C | 0x0000E0C8 | 0x0000B2C8 | 0x00000133 |
_iob | - | 0x0040E190 | 0x0000E0CC | 0x0000B2CC | 0x00000137 |
_onexit | - | 0x0040E194 | 0x0000E0D0 | 0x0000B2D0 | 0x0000023C |
abort | - | 0x0040E198 | 0x0000E0D4 | 0x0000B2D4 | 0x0000039C |
calloc | - | 0x0040E19C | 0x0000E0D8 | 0x0000B2D8 | 0x000003A9 |
exit | - | 0x0040E1A0 | 0x0000E0DC | 0x0000B2DC | 0x000003B3 |
fprintf | - | 0x0040E1A4 | 0x0000E0E0 | 0x0000B2E0 | 0x000003C3 |
free | - | 0x0040E1A8 | 0x0000E0E4 | 0x0000B2E4 | 0x000003CA |
fwrite | - | 0x0040E1AC | 0x0000E0E8 | 0x0000B2E8 | 0x000003D6 |
malloc | - | 0x0040E1B0 | 0x0000E0EC | 0x0000B2EC | 0x00000402 |
memcpy | - | 0x0040E1B4 | 0x0000E0F0 | 0x0000B2F0 | 0x0000040A |
signal | - | 0x0040E1B8 | 0x0000E0F4 | 0x0000B2F4 | 0x00000425 |
strlen | - | 0x0040E1BC | 0x0000E0F8 | 0x0000B2F8 | 0x00000437 |
strncmp | - | 0x0040E1C0 | 0x0000E0FC | 0x0000B2FC | 0x0000043A |
system | - | 0x0040E1C4 | 0x0000E100 | 0x0000B300 | 0x0000044B |
vfprintf | - | 0x0040E1C8 | 0x0000E104 | 0x0000B304 | 0x00000459 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShowWindow | - | 0x0040E1D0 | 0x0000E10C | 0x0000B30C | 0x00000335 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
cgo46ea565sdfse7.exe | 2 | 0x00400000 | 0x00459FFF | Relevant Image |
![]() |
32-bit | 0x004015B9 |
![]() |
...
|
cgo46ea565sdfse7.exe | 2 | 0x00400000 | 0x00459FFF | Process Termination |
![]() |
32-bit | - |
![]() |
...
|
C:\Users\Public\Documents\startSF.exe | Dropped File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Verdict |
Malicious
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x00401000 |
Size Of Code | 0x00011400 |
Size Of Initialized Data | 0x00004C00 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_CUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-05-16 14:07 (UTC) |
Packer | PureBasic 4.x -> Neil Hodgson |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.code | 0x00401000 | 0x0000387E | 0x00003A00 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.53 |
.text | 0x00405000 | 0x0000D962 | 0x0000DA00 | 0x00003E00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x00413000 | 0x000033A5 | 0x00003400 | 0x00011800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.11 |
.data | 0x00417000 | 0x0000178C | 0x00001200 | 0x00014C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.1 |
.rsrc | 0x00419000 | 0x00000538 | 0x00000600 | 0x00015E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.54 |
Imports (9)
»
MSVCRT.dll (16)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
memset | - | 0x00417470 | 0x00017234 | 0x00014E34 | 0x00000299 |
wcsncmp | - | 0x00417474 | 0x00017238 | 0x00014E38 | 0x000002E8 |
memmove | - | 0x00417478 | 0x0001723C | 0x00014E3C | 0x00000298 |
wcsncpy | - | 0x0041747C | 0x00017240 | 0x00014E40 | 0x000002E9 |
wcsstr | - | 0x00417480 | 0x00017244 | 0x00014E44 | 0x000002ED |
_wcsnicmp | - | 0x00417484 | 0x00017248 | 0x00014E48 | 0x000001EE |
_wcsdup | - | 0x00417488 | 0x0001724C | 0x00014E4C | 0x000001E9 |
free | - | 0x0041748C | 0x00017250 | 0x00014E50 | 0x0000025E |
_wcsicmp | - | 0x00417490 | 0x00017254 | 0x00014E54 | 0x000001EA |
wcslen | - | 0x00417494 | 0x00017258 | 0x00014E58 | 0x000002E6 |
wcscpy | - | 0x00417498 | 0x0001725C | 0x00014E5C | 0x000002E3 |
wcscmp | - | 0x0041749C | 0x00017260 | 0x00014E60 | 0x000002E1 |
wcscat | - | 0x004174A0 | 0x00017264 | 0x00014E64 | 0x000002DF |
memcpy | - | 0x004174A4 | 0x00017268 | 0x00014E68 | 0x00000297 |
tolower | - | 0x004174A8 | 0x0001726C | 0x00014E6C | 0x000002D3 |
malloc | - | 0x004174AC | 0x00017270 | 0x00014E70 | 0x00000291 |
KERNEL32.dll (72)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetModuleHandleW | - | 0x004174B4 | 0x00017278 | 0x00014E78 | 0x000001FA |
HeapCreate | - | 0x004174B8 | 0x0001727C | 0x00014E7C | 0x000002A4 |
GetStdHandle | - | 0x004174BC | 0x00017280 | 0x00014E80 | 0x0000023E |
SetConsoleCtrlHandler | - | 0x004174C0 | 0x00017284 | 0x00014E84 | 0x000003AF |
HeapDestroy | - | 0x004174C4 | 0x00017288 | 0x00014E88 | 0x000002A5 |
ExitProcess | - | 0x004174C8 | 0x0001728C | 0x00014E8C | 0x00000105 |
WriteFile | - | 0x004174CC | 0x00017290 | 0x00014E90 | 0x00000497 |
GetTempFileNameW | - | 0x004174D0 | 0x00017294 | 0x00014E94 | 0x0000025D |
LoadLibraryExW | - | 0x004174D4 | 0x00017298 | 0x00014E98 | 0x000002F8 |
EnumResourceTypesW | - | 0x004174D8 | 0x0001729C | 0x00014E9C | 0x000000F2 |
FreeLibrary | - | 0x004174DC | 0x000172A0 | 0x00014EA0 | 0x0000014D |
RemoveDirectoryW | - | 0x004174E0 | 0x000172A4 | 0x00014EA4 | 0x00000386 |
EnumResourceNamesW | - | 0x004174E4 | 0x000172A8 | 0x00014EA8 | 0x000000EE |
GetCommandLineW | - | 0x004174E8 | 0x000172AC | 0x00014EAC | 0x00000171 |
LoadResource | - | 0x004174EC | 0x000172B0 | 0x00014EB0 | 0x000002FB |
SizeofResource | - | 0x004174F0 | 0x000172B4 | 0x00014EB4 | 0x0000042A |
FreeResource | - | 0x004174F4 | 0x000172B8 | 0x00014EB8 | 0x00000150 |
FindResourceW | - | 0x004174F8 | 0x000172BC | 0x00014EBC | 0x0000013A |
GetNativeSystemInfo | - | 0x004174FC | 0x000172C0 | 0x00014EC0 | 0x00000207 |
GetShortPathNameW | - | 0x00417500 | 0x000172C4 | 0x00014EC4 | 0x0000023B |
GetWindowsDirectoryW | - | 0x00417504 | 0x000172C8 | 0x00014EC8 | 0x00000286 |
GetSystemDirectoryW | - | 0x00417508 | 0x000172CC | 0x00014ECC | 0x0000024A |
EnterCriticalSection | - | 0x0041750C | 0x000172D0 | 0x00014ED0 | 0x000000DA |
CloseHandle | - | 0x00417510 | 0x000172D4 | 0x00014ED4 | 0x00000044 |
LeaveCriticalSection | - | 0x00417514 | 0x000172D8 | 0x00014ED8 | 0x000002F4 |
InitializeCriticalSection | - | 0x00417518 | 0x000172DC | 0x00014EDC | 0x000002B9 |
WaitForSingleObject | - | 0x0041751C | 0x000172E0 | 0x00014EE0 | 0x0000046E |
TerminateThread | - | 0x00417520 | 0x000172E4 | 0x00014EE4 | 0x00000438 |
CreateThread | - | 0x00417524 | 0x000172E8 | 0x00014EE8 | 0x000000A4 |
GetProcAddress | - | 0x00417528 | 0x000172EC | 0x00014EEC | 0x00000222 |
GetVersionExW | - | 0x0041752C | 0x000172F0 | 0x00014EF0 | 0x0000027B |
Sleep | - | 0x00417530 | 0x000172F4 | 0x00014EF4 | 0x0000042B |
WideCharToMultiByte | - | 0x00417534 | 0x000172F8 | 0x00014EF8 | 0x00000484 |
HeapAlloc | - | 0x00417538 | 0x000172FC | 0x00014EFC | 0x000002A2 |
HeapFree | - | 0x0041753C | 0x00017300 | 0x00014F00 | 0x000002A6 |
LoadLibraryW | - | 0x00417540 | 0x00017304 | 0x00014F04 | 0x000002F9 |
GetCurrentProcessId | - | 0x00417544 | 0x00017308 | 0x00014F08 | 0x000001AB |
GetCurrentThreadId | - | 0x00417548 | 0x0001730C | 0x00014F0C | 0x000001AE |
GetModuleFileNameW | - | 0x0041754C | 0x00017310 | 0x00014F10 | 0x000001F6 |
PeekNamedPipe | - | 0x00417550 | 0x00017314 | 0x00014F14 | 0x00000343 |
TerminateProcess | - | 0x00417554 | 0x00017318 | 0x00014F18 | 0x00000437 |
GetEnvironmentVariableW | - | 0x00417558 | 0x0001731C | 0x00014F1C | 0x000001C4 |
SetEnvironmentVariableW | - | 0x0041755C | 0x00017320 | 0x00014F20 | 0x000003D9 |
GetCurrentProcess | - | 0x00417560 | 0x00017324 | 0x00014F24 | 0x000001AA |
DuplicateHandle | - | 0x00417564 | 0x00017328 | 0x00014F28 | 0x000000D5 |
CreatePipe | - | 0x00417568 | 0x0001732C | 0x00014F2C | 0x00000092 |
CreateProcessW | - | 0x0041756C | 0x00017330 | 0x00014F30 | 0x00000098 |
GetExitCodeProcess | - | 0x00417570 | 0x00017334 | 0x00014F34 | 0x000001C6 |
SetUnhandledExceptionFilter | - | 0x00417574 | 0x00017338 | 0x00014F38 | 0x0000041F |
HeapSize | - | 0x00417578 | 0x0001733C | 0x00014F3C | 0x000002AB |
MultiByteToWideChar | - | 0x0041757C | 0x00017340 | 0x00014F40 | 0x0000031F |
CreateDirectoryW | - | 0x00417580 | 0x00017344 | 0x00014F44 | 0x00000072 |
SetFileAttributesW | - | 0x00417584 | 0x00017348 | 0x00014F48 | 0x000003E2 |
GetTempPathW | - | 0x00417588 | 0x0001734C | 0x00014F4C | 0x0000025F |
DeleteFileW | - | 0x0041758C | 0x00017350 | 0x00014F50 | 0x000000C4 |
GetCurrentDirectoryW | - | 0x00417590 | 0x00017354 | 0x00014F54 | 0x000001A9 |
SetCurrentDirectoryW | - | 0x00417594 | 0x00017358 | 0x00014F58 | 0x000003CF |
CreateFileW | - | 0x00417598 | 0x0001735C | 0x00014F5C | 0x00000080 |
SetFilePointer | - | 0x0041759C | 0x00017360 | 0x00014F60 | 0x000003E7 |
TlsFree | - | 0x004175A0 | 0x00017364 | 0x00014F64 | 0x0000043D |
TlsGetValue | - | 0x004175A4 | 0x00017368 | 0x00014F68 | 0x0000043E |
TlsSetValue | - | 0x004175A8 | 0x0001736C | 0x00014F6C | 0x0000043F |
TlsAlloc | - | 0x004175AC | 0x00017370 | 0x00014F70 | 0x0000043C |
HeapReAlloc | - | 0x004175B0 | 0x00017374 | 0x00014F74 | 0x000002A9 |
DeleteCriticalSection | - | 0x004175B4 | 0x00017378 | 0x00014F78 | 0x000000BF |
InterlockedCompareExchange | - | 0x004175B8 | 0x0001737C | 0x00014F7C | 0x000002BF |
InterlockedExchange | - | 0x004175BC | 0x00017380 | 0x00014F80 | 0x000002C2 |
GetLastError | - | 0x004175C0 | 0x00017384 | 0x00014F84 | 0x000001E7 |
SetLastError | - | 0x004175C4 | 0x00017388 | 0x00014F88 | 0x000003F4 |
UnregisterWait | - | 0x004175C8 | 0x0001738C | 0x00014F8C | 0x0000044F |
GetCurrentThread | - | 0x004175CC | 0x00017390 | 0x00014F90 | 0x000001AD |
RegisterWaitForSingleObject | - | 0x004175D0 | 0x00017394 | 0x00014F94 | 0x00000378 |
USER32.DLL (33)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CharUpperW | - | 0x004175D8 | 0x0001739C | 0x00014F9C | 0x00000000 |
CharLowerW | - | 0x004175DC | 0x000173A0 | 0x00014FA0 | 0x00000000 |
MessageBoxW | - | 0x004175E0 | 0x000173A4 | 0x00014FA4 | 0x00000000 |
DefWindowProcW | - | 0x004175E4 | 0x000173A8 | 0x00014FA8 | 0x00000000 |
DestroyWindow | - | 0x004175E8 | 0x000173AC | 0x00014FAC | 0x00000000 |
GetWindowLongW | - | 0x004175EC | 0x000173B0 | 0x00014FB0 | 0x00000000 |
GetWindowTextLengthW | - | 0x004175F0 | 0x000173B4 | 0x00014FB4 | 0x00000000 |
GetWindowTextW | - | 0x004175F4 | 0x000173B8 | 0x00014FB8 | 0x00000000 |
UnregisterClassW | - | 0x004175F8 | 0x000173BC | 0x00014FBC | 0x00000000 |
LoadIconW | - | 0x004175FC | 0x000173C0 | 0x00014FC0 | 0x00000000 |
LoadCursorW | - | 0x00417600 | 0x000173C4 | 0x00014FC4 | 0x00000000 |
RegisterClassExW | - | 0x00417604 | 0x000173C8 | 0x00014FC8 | 0x00000000 |
IsWindowEnabled | - | 0x00417608 | 0x000173CC | 0x00014FCC | 0x00000000 |
EnableWindow | - | 0x0041760C | 0x000173D0 | 0x00014FD0 | 0x00000000 |
GetSystemMetrics | - | 0x00417610 | 0x000173D4 | 0x00014FD4 | 0x00000000 |
CreateWindowExW | - | 0x00417614 | 0x000173D8 | 0x00014FD8 | 0x00000000 |
SetWindowLongW | - | 0x00417618 | 0x000173DC | 0x00014FDC | 0x00000000 |
SendMessageW | - | 0x0041761C | 0x000173E0 | 0x00014FE0 | 0x00000000 |
SetFocus | - | 0x00417620 | 0x000173E4 | 0x00014FE4 | 0x00000000 |
CreateAcceleratorTableW | - | 0x00417624 | 0x000173E8 | 0x00014FE8 | 0x00000000 |
SetForegroundWindow | - | 0x00417628 | 0x000173EC | 0x00014FEC | 0x00000000 |
BringWindowToTop | - | 0x0041762C | 0x000173F0 | 0x00014FF0 | 0x00000000 |
GetMessageW | - | 0x00417630 | 0x000173F4 | 0x00014FF4 | 0x00000000 |
TranslateAcceleratorW | - | 0x00417634 | 0x000173F8 | 0x00014FF8 | 0x00000000 |
TranslateMessage | - | 0x00417638 | 0x000173FC | 0x00014FFC | 0x00000000 |
DispatchMessageW | - | 0x0041763C | 0x00017400 | 0x00015000 | 0x00000000 |
DestroyAcceleratorTable | - | 0x00417640 | 0x00017404 | 0x00015004 | 0x00000000 |
PostMessageW | - | 0x00417644 | 0x00017408 | 0x00015008 | 0x00000000 |
GetForegroundWindow | - | 0x00417648 | 0x0001740C | 0x0001500C | 0x00000000 |
GetWindowThreadProcessId | - | 0x0041764C | 0x00017410 | 0x00015010 | 0x00000000 |
IsWindowVisible | - | 0x00417650 | 0x00017414 | 0x00015014 | 0x00000000 |
EnumWindows | - | 0x00417654 | 0x00017418 | 0x00015018 | 0x00000000 |
SetWindowPos | - | 0x00417658 | 0x0001741C | 0x0001501C | 0x00000000 |
GDI32.DLL (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetStockObject | - | 0x00417660 | 0x00017424 | 0x00015024 | 0x00000000 |
COMCTL32.DLL (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InitCommonControlsEx | - | 0x00417668 | 0x0001742C | 0x0001502C | 0x00000000 |
SHELL32.DLL (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteExW | - | 0x00417670 | 0x00017434 | 0x00015034 | 0x00000000 |
SHGetFolderLocation | - | 0x00417674 | 0x00017438 | 0x00015038 | 0x00000000 |
SHGetPathFromIDListW | - | 0x00417678 | 0x0001743C | 0x0001503C | 0x00000000 |
WINMM.DLL (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
timeBeginPeriod | - | 0x00417680 | 0x00017444 | 0x00015044 | 0x00000000 |
OLE32.DLL (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoInitialize | - | 0x00417688 | 0x0001744C | 0x0001504C | 0x00000000 |
CoTaskMemFree | - | 0x0041768C | 0x00017450 | 0x00015050 | 0x00000000 |
SHLWAPI.DLL (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathAddBackslashW | - | 0x00417694 | 0x00017458 | 0x00015058 | 0x00000000 |
PathRenameExtensionW | - | 0x00417698 | 0x0001745C | 0x0001505C | 0x00000000 |
PathQuoteSpacesW | - | 0x0041769C | 0x00017460 | 0x00015060 | 0x00000000 |
PathRemoveArgsW | - | 0x004176A0 | 0x00017464 | 0x00015064 | 0x00000000 |
PathRemoveBackslashW | - | 0x004176A4 | 0x00017468 | 0x00015068 | 0x00000000 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
startsf.exe | 3 | 0x00400000 | 0x00419FFF | Relevant Image |
![]() |
32-bit | 0x0040E4D0 |
![]() |
...
|
startsf.exe | 3 | 0x00400000 | 0x00419FFF | Process Termination |
![]() |
32-bit | - |
![]() |
...
|
C:\Users\Public\Documents\LimeUSB_Csharp.exe | Dropped File | Binary |
Suspicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x00EBE3AE |
Size Of Code | 0x00ABC400 |
Size Of Initialized Data | 0x00000A00 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2038-03-22 18:18 (UTC) |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00402000 | 0x00ABC3B4 | 0x00ABC400 | 0x00000200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.78 |
.rsrc | 0x00EC0000 | 0x00000690 | 0x00000800 | 0x00ABC600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.0 |
.reloc | 0x00EC2000 | 0x0000000C | 0x00000200 | 0x00ABCE00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.0 |
Memory Dumps (41)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
limeusb_csharp.exe | 10 | 0x003B0000 | 0x00E73FFF | Relevant Image |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 11 | 0x003B0000 | 0x00E73FFF | Relevant Image |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 12 | 0x003B0000 | 0x00E73FFF | Relevant Image |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 12 | 0x003B0000 | 0x00E73FFF | Process Termination |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 11 | 0x003B0000 | 0x00E73FFF | Process Termination |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 10 | 0x003B0000 | 0x00E73FFF | Process Termination |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 13 | 0x003B0000 | 0x00E73FFF | Relevant Image |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 13 | 0x003B0000 | 0x00E73FFF | Process Termination |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 14 | 0x003B0000 | 0x00E73FFF | Relevant Image |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 14 | 0x003B0000 | 0x00E73FFF | Process Termination |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 15 | 0x00330000 | 0x00DF3FFF | Relevant Image |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 15 | 0x00330000 | 0x00DF3FFF | Process Termination |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 16 | 0x00A30000 | 0x014F3FFF | Relevant Image |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 16 | 0x00A30000 | 0x014F3FFF | Process Termination |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 17 | 0x00C60000 | 0x01723FFF | Relevant Image |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 17 | 0x00C60000 | 0x01723FFF | Process Termination |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 18 | 0x00F20000 | 0x019E3FFF | Relevant Image |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 18 | 0x00F20000 | 0x019E3FFF | Process Termination |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 19 | 0x00F20000 | 0x019E3FFF | Relevant Image |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 19 | 0x00F20000 | 0x019E3FFF | Process Termination |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 20 | 0x00F20000 | 0x019E3FFF | Relevant Image |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 20 | 0x00F20000 | 0x019E3FFF | Process Termination |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 21 | 0x00F20000 | 0x019E3FFF | Relevant Image |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 21 | 0x00F20000 | 0x019E3FFF | Process Termination |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 22 | 0x00330000 | 0x00DF3FFF | Relevant Image |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 22 | 0x00330000 | 0x00DF3FFF | Process Termination |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 23 | 0x00330000 | 0x00DF3FFF | Relevant Image |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 23 | 0x00330000 | 0x00DF3FFF | Process Termination |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 24 | 0x00330000 | 0x00DF3FFF | Relevant Image |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 24 | 0x00330000 | 0x00DF3FFF | Process Termination |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 25 | 0x00330000 | 0x00DF3FFF | Relevant Image |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 25 | 0x00330000 | 0x00DF3FFF | Process Termination |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 26 | 0x00230000 | 0x00CF3FFF | Relevant Image |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 26 | 0x00230000 | 0x00CF3FFF | Process Termination |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 27 | 0x003C0000 | 0x00E83FFF | Relevant Image |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 27 | 0x003C0000 | 0x00E83FFF | Process Termination |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 28 | 0x001A0000 | 0x00C63FFF | Relevant Image |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 30 | 0x000C0000 | 0x00B83FFF | Relevant Image |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 30 | 0x000C0000 | 0x00B83FFF | Process Termination |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 31 | 0x00FA0000 | 0x01A63FFF | Relevant Image |
![]() |
64-bit | - |
![]() |
...
|
limeusb_csharp.exe | 31 | 0x00FA0000 | 0x01A63FFF | Process Termination |
![]() |
64-bit | - |
![]() |
...
|
c:\users\keecfmwgj\appdata\local\gdipfontcachev1.dat | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\music\omcoseo.wav.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\desktop\m3w-q0rzrfukl\ncd4gg.jpg.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Documents\gADgp30\qJEcmQ\9bDYANhq-V\tirKK9 byo0\JGqHA5Ln0.ppt.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\pictures\-yqu7r.jpg.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Music\sR45lfBmn\HnGdqI3uzhk02\qL4ItMgKfKQ\tjL0lG.mp3.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\desktop\ehz3w0f6qpam.png.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Pictures\LxEyCMb3cz G.png.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Music\MT00azHNzYeUklUK7WLY.wav.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Documents\hQwa.pptx.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\music\sr45lfbmn\hngdqi3uzhk02\xlkrw\wwq2xl38e.mp3.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\videos\xbhxbnsb3poh.mp4.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Documents\gADgp30\qJEcmQ\9bDYANhq-V\vztlNW.docx.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\documents\0m2lwa6w2.docx.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Desktop\KcV8WXd6gM.mp3.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Documents\63C2JNBupUJaLCzjj.xlsx.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\music\sr45lfbmn\hngdqi3uzhk02\o5kq9mr4cc\sb2jvq1jz7zixzf4.mp3.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\pictures\t_ v5c6i.png.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Videos\qgeTWMdHrM.mp4.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Documents\UYWqtSLk mI.docx.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Videos\YZQR06gE.avi.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\pictures\8czrpcyd_m6g307p3uxk.png.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Documents\da4Yt5-_HXX-4.xlsx.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\music\sr45lfbmn\hngdqi3uzhk02\ql4itmgkfkq\u0af.mp3.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Pictures\XOXL0s.gif.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\music\sr45lfbmn\hngdqi3uzhk02\i82ix5otq989c-uh2jwl.mp3.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Music\sR45lfBmn\HnGdqI3uzhk02\qL4ItMgKfKQ\-hsXLHPSE2Gpg.mp3.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Documents\hiQyDV.pptx.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Desktop\oSEF.xls.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\music\sr45lfbmn\hngdqi3uzhk02\o5kq9mr4cc\l9ni.wav.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Pictures\6ZfnhezHZzwofrnONF.jpg.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Desktop\A_Xuo41AM2 4XZ.gif.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\videos\gjgfz-.mp4.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\documents\gadgp30\ahvikv6bhgp\9dbeojadwjynbxb\cptrf.ppt.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\documents\bx_hg08 qccc73wa.pptx.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\videos\qpxgrgh9_6h.avi.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\desktop\e06hth3voha0d\4o6jjgbzavbwsb6-29.png.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\pictures\uz- c.gif.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\music\sr45lfbmn\hngdqi3uzhk02\ln8yfcu_yh0.wav.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Music\sR45lfBmn\HnGdqI3uzhk02\M5V7viLPSBu Fn\UOrn1.mp3.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Documents\p9eQVmM.pptx.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Desktop\4XirQCKnN-C5.mp3.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\desktop\e06hth3voha0d\hftktiwcu\ck5hblc73yemq3t cjmx.mp3.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Music\sR45lfBmn\HnGdqI3uzhk02\O5Kq9mR4CC\ZDzv.mp3.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\desktop\m3w-q0rzrfukl\-8f.xls.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\music\zern8svva2_nmg.mp3.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Pictures\JhqgivuCmr9tbit.jpg.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Documents\kLxyk2vrts2_ylshyl.xlsx.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Documents\tcbu3AshPzFcR2r8Ck o.docx.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Music\sR45lfBmn\HnGdqI3uzhk02\M5V7viLPSBu Fn\0cA5darpWBXR.wav.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\desktop\e06hth3voha0d\hftktiwcu\eq95xs_2bmkwbb6.xls.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\desktop\m3w-q0rzrfukl\x7ay056 0rvhbasv7.bmp.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\documents\gadgp30\ahvikv6bhgp\mhccyt.docx.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\desktop\lw2zryjl bjcze.png.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Music\sR45lfBmn\HnGdqI3uzhk02\xLkRw\MsuOsA4r0 23U.mp3.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Documents\gADgp30\qJEcmQ\Z0wgHK\TiksC6kLaNE3N.ppt.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Pictures\8DVbrPzwsfunn.jpg.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\documents\gadgp30\ahvikv6bhgp\hd6yww0khas8.ppt.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Desktop\5wD jaVgryR0UBy6Yy26.gif.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Pictures\-lvNlIwLh6qJBQ7x.bmp.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Documents\zVu_x.xlsx.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\desktop\ltmu_vt fzdro.mp3.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\desktop\e06hth3voha0d\5ifudwany.bmp.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\videos\xleaz.mp4.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Documents\gADgp30\ahvIkv6BhGP\9dBEoJADWjyNbxb\2NDvK0UV6C93Or2y33.xls.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\pictures\3r8d3dnv_alj.jpg.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\pictures\ie3k6n7c0_b gizgjbf-.png.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Pictures\tBNEwownJMNLIH-.gif.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\desktop\6t r wkg.pdf.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\documents\kzkisarpnjyn.xlsx.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\videos\ulsd6hewxcm_chkzb.avi.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Pictures\rokbMHY7.bmp.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\pictures\1tp--jqrn7ickv.jpg.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\documents\gadgp30\ahvikv6bhgp\9dbeojadwjynbxb\ugb vvdin.pdf.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\music\vazma_d1fuafei4nm_9.mp3.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\pictures\bimh.png.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Pictures\hwQvkSY6qIajdf.jpg.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\music\sr45lfbmn\hngdqi3uzhk02\ql4itmgkfkq\li_8a-uy.wav.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Pictures\-20cBzLDzX_KXyz1k60.png.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\documents\gadgp30\ahvikv6bhgp\appn7n4ht lo.pdf.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Pictures\mh_2oAjD6IQO.gif.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\documents\gadgp30\qjecmq\9bdyanhq-v\j_xc70wda-y.xlsx.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\desktop\e06hth3voha0d\2 kc0zg1 rmrjok_gy.png.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\music\sr45lfbmn\hngdqi3uzhk02\o5kq9mr4cc\n8sigxftdmtkczh\waroxvlp.wav.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\pictures\qjmibj2csojvn7un2o.bmp.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Pictures\kwI_sPi1.png.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Desktop\aYGQHCFalP7ms.bmp.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Pictures\F-RYQ.jpg.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\desktop\lf z_nda58jhfm.pdf.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Music\sR45lfBmn\HnGdqI3uzhk02\qL4ItMgKfKQ\RE3_9X-yu-SSwhMc.mp3.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Documents\zm9nla-NPD71l4thrEn.xls.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\pictures\gn4io1vv8uthsx.png.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\documents\qdt8j-_xcq 65llcpzig.pptx.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\pictures\tfnlk 0smrt1_1xww.gif.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Documents\gADgp30\ahvIkv6BhGP\9dBEoJADWjyNbxb\DgJ _YHDeXbtu1aaa9P7.pptx.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Pictures\v30MfWJ0Z.jpg.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\pictures\gm5d9kgelxbt.png.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Documents\gADgp30\qJEcmQ\Z0wgHK\n2mooDz97hN Hy_Rw.doc.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Videos\TXd5XhbVM_gRmGa.mp4.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Pictures\dLcXhG3aWfBaiR.gif.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\pictures\y a649h.jpg.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\music\m9te.wav.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\pictures\09ijundbva.gif.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\desktop\m3w-q0rzrfukl\ztjhwwr6z7cu6mtrpn.jpg.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Desktop\M3w-Q0RZrFUkL\cDzt.ppt.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\videos\z8vxfzj-jnzgo.mp4.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\videos\h1j7hblziw7l.avi.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\music\sr45lfbmn\hngdqi3uzhk02\m5v7vilpsbu fn\2-hxc4lfdhsq_mkvo.mp3.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Desktop\E06hTH3VoHA0d\BtaCh0Rv1i6GNNdmI.png.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Pictures\qNxgBCMJFfZZ 6.bmp.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Documents\gADgp30\qJEcmQ\9bDYANhq-V\tirKK9 byo0\dP47.doc.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Desktop\bnnQ2Y.png.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Desktop\E06hTH3VoHA0d\JhXCNVX54s7.png.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Documents\yl14C.docx.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\documents\gadgp30\qjecmq\_e4_60ksbs_d7zx.pptx.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Pictures\gJalnSM9o_s.jpg.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\pictures\neejrl4diryjsv.bmp.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\pictures\2r7o-shzef3qr6zs_c.gif.syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\music\sr45lfbmn\hngdqi3uzhk02\o5kq9mr4cc\69v7zlnse_6kw0ym e.mp3.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Music\sR45lfBmn\HnGdqI3uzhk02\jW54Ba8xSbY.wav.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\music\sr45lfbmn\hngdqi3uzhk02\o5kq9mr4cc\n8sigxftdmtkczh\xu9kprwq9.mp3.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Documents\tbolTOBf6oytAdVf.xls.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\documents\gadgp30\ahvikv6bhgp\n_go2 uxegr7yuru5exh\nfwtjiionnnx.ppt.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Pictures\ut5I85Hmrtdjra4F.jpg.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Music\sR45lfBmn\HnGdqI3uzhk02\M5V7viLPSBu Fn\XXq4gabRA0W.wav.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\appdata\local\gdipfontcachev1.dat | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\videos\wctn_hgh2xhblipzt0o.avi.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Pictures\CRAGPLrxjBWjbAs_pS.jpg.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\documents\gadgp30\ahvikv6bhgp\n7u6-hdfzcmk12ax.ppt.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Documents\WindowsPowerShell\Modules\Cipher\Cipher.psm1 | Dropped File | Text |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Desktop\E06hTH3VoHA0d\OUWK.mp3.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Music\M-QP9r3m\5q7ybWyiM4zx.wav.Syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Music\sR45lfBmn\HnGdqI3uzhk02\O5Kq9mR4CC\n8siGXFTdMtKcZh\YBZFeG9.wav.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\documents\a_x_tiv5stl.docx.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Desktop\E06hTH3VoHA0d\BRmtCoyPLlLg.jpg.Syrk | Dropped File | Stream |
Clean
|
...
|
»
c:\users\keecfmwgj\videos\zhli4r.mp4.syrk | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Documents\WindowsPowerShell\Modules\Cipher\cry.ps1 | Dropped File | Text |
Clean
|
...
|
»
C:\Users\kEecfMwgj\Desktop\Readme_now.txt | Dropped File | Text |
Clean
|
...
|
»
C:\Users\kEecfMwgj\AppData\Local\Temp\EDB2.tmp\EDB3.tmp\EDB4.bat | Dropped File | Text |
Clean
|
...
|
»
C:\Users\Default\AppData\Local\Microsoft\+dp-.txt | Dropped File | Text |
Clean
|
...
|
»
C:\Users\Default\AppData\Local\Microsoft\-pw+.txt | Dropped File | Text |
Clean
|
...
|
»
C:\Users\Default\AppData\Local\Microsoft\-i+.txt | Dropped File | Text |
Clean
|
...
|
»
C:\Users\kEecfMwgj\AppData\Local\Temp\EDB2.tmp | Dropped File | Empty |
Clean
|
...
|
»
aff8cb711b2b7e38bd15a3620a0c873727c0140afb26ca8959ff2a4b77ecc2c2 | Extracted File | Image |
Clean
|
...
|
»