Malicious
Classifications
Ransomware
Threat Names
LockBit
Dynamic Analysis Report
Created on 2022-06-30T12:27:33+00:00
0e66029132a885143b87b1e49e32663a52737bbff4ab96186e9e5e829aa2915f.exe
Windows Exe (x86-32)
Remarks (2/2)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "1 minute, 15 seconds" to "30 seconds" to reveal dormant functionality.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\kEecfMwgj\Desktop\0e66029132a885143b87b1e49e32663a52737bbff4ab96186e9e5e829aa2915f.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Verdict |
Malicious
|
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x0040F970 |
Size Of Code | 0x00013200 |
Size Of Initialized Data | 0x00008200 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2020-01-23 17:27 (UTC+1) |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x00013083 | 0x00013200 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.47 |
.rdata | 0x00415000 | 0x00005DD0 | 0x00005E00 | 0x00013600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.08 |
.data | 0x0041B000 | 0x00002344 | 0x00000200 | 0x00019400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.6 |
Imports (14)
»
NETAPI32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetShareEnum | - | 0x00415218 | 0x00019D24 | 0x00018324 | 0x000000EF |
NetApiBufferFree | - | 0x0041521C | 0x00019D28 | 0x00018328 | 0x00000065 |
IPHLPAPI.DLL (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetAdaptersInfo | - | 0x004150A4 | 0x00019BB0 | 0x000181B0 | 0x0000003F |
WS2_32.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
htons | 0x00000009 | 0x004152A8 | 0x00019DB4 | 0x000183B4 | - |
ioctlsocket | 0x0000000A | 0x004152AC | 0x00019DB8 | 0x000183B8 | - |
WSAGetLastError | 0x0000006F | 0x004152B0 | 0x00019DBC | 0x000183BC | - |
connect | 0x00000004 | 0x004152B4 | 0x00019DC0 | 0x000183C0 | - |
inet_addr | 0x0000000B | 0x004152B8 | 0x00019DC4 | 0x000183C4 | - |
__WSAFDIsSet | 0x00000097 | 0x004152BC | 0x00019DC8 | 0x000183C8 | - |
closesocket | 0x00000003 | 0x004152C0 | 0x00019DCC | 0x000183CC | - |
select | 0x00000012 | 0x004152C4 | 0x00019DD0 | 0x000183D0 | - |
WSACleanup | 0x00000074 | 0x004152C8 | 0x00019DD4 | 0x000183D4 | - |
WSAStartup | 0x00000073 | 0x004152CC | 0x00019DD8 | 0x000183D8 | - |
socket | 0x00000017 | 0x004152D0 | 0x00019DDC | 0x000183DC | - |
CRYPT32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptBinaryToStringA | - | 0x0041509C | 0x00019BA8 | 0x000181A8 | 0x0000007C |
gdiplus.dll (19)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GdipDrawString | - | 0x004152D8 | 0x00019DE4 | 0x000183E4 | 0x000000C8 |
GdipCreateStringFormat | - | 0x004152DC | 0x00019DE8 | 0x000183E8 | 0x00000084 |
GdipDeleteFontFamily | - | 0x004152E0 | 0x00019DEC | 0x000183EC | 0x0000008F |
GdipGetImageEncoders | - | 0x004152E4 | 0x00019DF0 | 0x000183F0 | 0x0000011E |
GdipCreateFontFamilyFromName | - | 0x004152E8 | 0x00019DF4 | 0x000183F4 | 0x00000057 |
GdipDeleteBrush | - | 0x004152EC | 0x00019DF8 | 0x000183F8 | 0x0000008A |
GdipDisposeImage | - | 0x004152F0 | 0x00019DFC | 0x000183FC | 0x00000098 |
GdipCreateFont | - | 0x004152F4 | 0x00019E00 | 0x00018400 | 0x00000056 |
GdipCreateSolidFill | - | 0x004152F8 | 0x00019E04 | 0x00018404 | 0x00000082 |
GdipFillRectangle | - | 0x004152FC | 0x00019E08 | 0x00018408 | 0x000000E4 |
GdipGetGenericFontFamilySansSerif | - | 0x00415300 | 0x00019E0C | 0x0001840C | 0x00000113 |
GdiplusStartup | - | 0x00415304 | 0x00019E10 | 0x00018410 | 0x00000275 |
GdipGetImageGraphicsContext | - | 0x00415308 | 0x00019E14 | 0x00018414 | 0x00000121 |
GdipGetImageEncodersSize | - | 0x0041530C | 0x00019E18 | 0x00018418 | 0x0000011F |
GdipDeleteGraphics | - | 0x00415310 | 0x00019E1C | 0x0001841C | 0x00000090 |
GdipDeleteStringFormat | - | 0x00415314 | 0x00019E20 | 0x00018420 | 0x00000097 |
GdipDeleteFont | - | 0x00415318 | 0x00019E24 | 0x00018424 | 0x0000008E |
GdipCreateBitmapFromScan0 | - | 0x0041531C | 0x00019E28 | 0x00018428 | 0x00000050 |
GdipSaveImageToFile | - | 0x00415320 | 0x00019E2C | 0x0001842C | 0x000001F0 |
SHLWAPI.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathRemoveExtensionA | - | 0x00415238 | 0x00019D44 | 0x00018344 | 0x00000088 |
PathRemoveBackslashW | - | 0x0041523C | 0x00019D48 | 0x00018348 | 0x00000085 |
PathAddBackslashW | - | 0x00415240 | 0x00019D4C | 0x0001834C | 0x00000030 |
StrFormatByteSize64A | - | 0x00415244 | 0x00019D50 | 0x00018350 | 0x00000128 |
PathRemoveFileSpecW | - | 0x00415248 | 0x00019D54 | 0x00018354 | 0x0000008B |
PathFindExtensionW | - | 0x0041524C | 0x00019D58 | 0x00018358 | 0x00000047 |
MPR.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetAddConnection2W | - | 0x00415200 | 0x00019D0C | 0x0001830C | 0x00000006 |
WNetOpenEnumW | - | 0x00415204 | 0x00019D10 | 0x00018310 | 0x0000003D |
WNetEnumResourceW | - | 0x00415208 | 0x00019D14 | 0x00018314 | 0x0000001C |
WNetGetConnectionW | - | 0x0041520C | 0x00019D18 | 0x00018318 | 0x00000024 |
WNetCloseEnum | - | 0x00415210 | 0x00019D1C | 0x0001831C | 0x00000010 |
ntdll.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RtlAdjustPrivilege | - | 0x00415338 | 0x00019E44 | 0x00018444 | 0x000001C0 |
RtlInitUnicodeString | - | 0x0041533C | 0x00019E48 | 0x00018448 | 0x000002B0 |
NtAllocateVirtualMemory | - | 0x00415340 | 0x00019E4C | 0x0001844C | 0x00000087 |
LdrEnumerateLoadedModules | - | 0x00415344 | 0x00019E50 | 0x00018450 | 0x00000054 |
RtlAcquirePebLock | - | 0x00415348 | 0x00019E54 | 0x00018454 | 0x000001A6 |
RtlReleasePebLock | - | 0x0041534C | 0x00019E58 | 0x00018458 | 0x0000033B |
memcpy | - | 0x00415350 | 0x00019E5C | 0x0001845C | 0x00000546 |
memset | - | 0x00415354 | 0x00019E60 | 0x00018460 | 0x00000548 |
msvcrt.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
malloc | - | 0x00415328 | 0x00019E34 | 0x00018434 | 0x000004FF |
calloc | - | 0x0041532C | 0x00019E38 | 0x00018438 | 0x000004A6 |
free | - | 0x00415330 | 0x00019E3C | 0x0001843C | 0x000004C7 |
KERNEL32.dll (84)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
QueryDosDeviceW | - | 0x004150AC | 0x00019BB8 | 0x000181B8 | 0x000003A0 |
FindFirstVolumeW | - | 0x004150B0 | 0x00019BBC | 0x000181BC | 0x0000013F |
GetModuleFileNameW | - | 0x004150B4 | 0x00019BC0 | 0x000181C0 | 0x00000214 |
lstrcpyW | - | 0x004150B8 | 0x00019BC4 | 0x000181C4 | 0x00000548 |
GetWindowsDirectoryW | - | 0x004150BC | 0x00019BC8 | 0x000181C8 | 0x000002AF |
lstrcatW | - | 0x004150C0 | 0x00019BCC | 0x000181CC | 0x0000053F |
InterlockedPopEntrySList | - | 0x004150C4 | 0x00019BD0 | 0x000181D0 | 0x000002F0 |
AllocConsole | - | 0x004150C8 | 0x00019BD4 | 0x000181D4 | 0x00000010 |
GetCurrentProcessId | - | 0x004150CC | 0x00019BD8 | 0x000181D8 | 0x000001C1 |
InitializeSListHead | - | 0x004150D0 | 0x00019BDC | 0x000181DC | 0x000002E7 |
InterlockedPushEntrySList | - | 0x004150D4 | 0x00019BE0 | 0x000181E0 | 0x000002F1 |
lstrcpyA | - | 0x004150D8 | 0x00019BE4 | 0x000181E4 | 0x00000547 |
InterlockedFlushSList | - | 0x004150DC | 0x00019BE8 | 0x000181E8 | 0x000002EE |
MoveFileW | - | 0x004150E0 | 0x00019BEC | 0x000181EC | 0x00000363 |
CreateIoCompletionPort | - | 0x004150E4 | 0x00019BF0 | 0x000181F0 | 0x00000094 |
SystemTimeToFileTime | - | 0x004150E8 | 0x00019BF4 | 0x000181F4 | 0x000004BD |
GetQueuedCompletionStatus | - | 0x004150EC | 0x00019BF8 | 0x000181F8 | 0x0000025E |
SetFileTime | - | 0x004150F0 | 0x00019BFC | 0x000181FC | 0x0000046A |
WriteFile | - | 0x004150F4 | 0x00019C00 | 0x00018200 | 0x00000525 |
GetFileSizeEx | - | 0x004150F8 | 0x00019C04 | 0x00018204 | 0x000001F1 |
ReadFile | - | 0x004150FC | 0x00019C08 | 0x00018208 | 0x000003C0 |
SetThreadAffinityMask | - | 0x00415100 | 0x00019C0C | 0x0001820C | 0x00000490 |
FindNextVolumeW | - | 0x00415104 | 0x00019C10 | 0x00018210 | 0x0000014A |
GetVolumePathNamesForVolumeNameW | - | 0x00415108 | 0x00019C14 | 0x00018214 | 0x000002AD |
FindVolumeClose | - | 0x0041510C | 0x00019C18 | 0x00018218 | 0x00000150 |
SetVolumeMountPointW | - | 0x00415110 | 0x00019C1C | 0x0001821C | 0x000004AB |
GetLogicalDrives | - | 0x00415114 | 0x00019C20 | 0x00018220 | 0x00000209 |
FindFirstFileExW | - | 0x00415118 | 0x00019C24 | 0x00018224 | 0x00000134 |
EnterCriticalSection | - | 0x0041511C | 0x00019C28 | 0x00018228 | 0x000000EE |
GetCommandLineW | - | 0x00415120 | 0x00019C2C | 0x0001822C | 0x00000187 |
FindNextFileW | - | 0x00415124 | 0x00019C30 | 0x00018230 | 0x00000145 |
lstrlenW | - | 0x00415128 | 0x00019C34 | 0x00018234 | 0x0000054E |
WaitForMultipleObjects | - | 0x0041512C | 0x00019C38 | 0x00018238 | 0x000004F7 |
LeaveCriticalSection | - | 0x00415130 | 0x00019C3C | 0x0001823C | 0x00000339 |
InitializeCriticalSection | - | 0x00415134 | 0x00019C40 | 0x00018240 | 0x000002E2 |
FindClose | - | 0x00415138 | 0x00019C44 | 0x00018244 | 0x0000012E |
GetFileAttributesW | - | 0x0041513C | 0x00019C48 | 0x00018248 | 0x000001EA |
ExitThread | - | 0x00415140 | 0x00019C4C | 0x0001824C | 0x0000011A |
OpenProcess | - | 0x00415144 | 0x00019C50 | 0x00018250 | 0x00000380 |
SetFileAttributesW | - | 0x00415148 | 0x00019C54 | 0x00018254 | 0x00000461 |
CreateToolhelp32Snapshot | - | 0x0041514C | 0x00019C58 | 0x00018258 | 0x000000BE |
Sleep | - | 0x00415150 | 0x00019C5C | 0x0001825C | 0x000004B2 |
GetLastError | - | 0x00415154 | 0x00019C60 | 0x00018260 | 0x00000202 |
Process32NextW | - | 0x00415158 | 0x00019C64 | 0x00018264 | 0x00000398 |
GetDiskFreeSpaceExW | - | 0x0041515C | 0x00019C68 | 0x00018268 | 0x000001CE |
GlobalAlloc | - | 0x00415160 | 0x00019C6C | 0x0001826C | 0x000002B3 |
Process32FirstW | - | 0x00415164 | 0x00019C70 | 0x00018270 | 0x00000396 |
GlobalFree | - | 0x00415168 | 0x00019C74 | 0x00018274 | 0x000002BA |
CloseHandle | - | 0x0041516C | 0x00019C78 | 0x00018278 | 0x00000052 |
CreateThread | - | 0x00415170 | 0x00019C7C | 0x0001827C | 0x000000B5 |
DeleteCriticalSection | - | 0x00415174 | 0x00019C80 | 0x00018280 | 0x000000D1 |
ExitProcess | - | 0x00415178 | 0x00019C84 | 0x00018284 | 0x00000119 |
GetConsoleWindow | - | 0x0041517C | 0x00019C88 | 0x00018288 | 0x000001B7 |
lstrcmpiW | - | 0x00415180 | 0x00019C8C | 0x0001828C | 0x00000545 |
GetDriveTypeW | - | 0x00415184 | 0x00019C90 | 0x00018290 | 0x000001D3 |
GetTempPathW | - | 0x00415188 | 0x00019C94 | 0x00018294 | 0x00000285 |
MultiByteToWideChar | - | 0x0041518C | 0x00019C98 | 0x00018298 | 0x00000367 |
GetTempFileNameW | - | 0x00415190 | 0x00019C9C | 0x0001829C | 0x00000283 |
CreateMutexA | - | 0x00415194 | 0x00019CA0 | 0x000182A0 | 0x0000009B |
OpenMutexA | - | 0x00415198 | 0x00019CA4 | 0x000182A4 | 0x0000037C |
LoadLibraryA | - | 0x0041519C | 0x00019CA8 | 0x000182A8 | 0x0000033C |
GetProcAddress | - | 0x004151A0 | 0x00019CAC | 0x000182AC | 0x00000245 |
GetTickCount | - | 0x004151A4 | 0x00019CB0 | 0x000182B0 | 0x00000293 |
GetSystemInfo | - | 0x004151A8 | 0x00019CB4 | 0x000182B4 | 0x00000273 |
GetLocalTime | - | 0x004151AC | 0x00019CB8 | 0x000182B8 | 0x00000203 |
Process32First | - | 0x004151B0 | 0x00019CBC | 0x000182BC | 0x00000395 |
TerminateProcess | - | 0x004151B4 | 0x00019CC0 | 0x000182C0 | 0x000004C0 |
GetUserDefaultLangID | - | 0x004151B8 | 0x00019CC4 | 0x000182C4 | 0x0000029C |
GetConsoleMode | - | 0x004151BC | 0x00019CC8 | 0x000182C8 | 0x000001AC |
WaitForSingleObject | - | 0x004151C0 | 0x00019CCC | 0x000182CC | 0x000004F9 |
GetModuleHandleA | - | 0x004151C4 | 0x00019CD0 | 0x000182D0 | 0x00000215 |
Process32Next | - | 0x004151C8 | 0x00019CD4 | 0x000182D4 | 0x00000397 |
lstrcmpiA | - | 0x004151CC | 0x00019CD8 | 0x000182D8 | 0x00000544 |
CreateProcessA | - | 0x004151D0 | 0x00019CDC | 0x000182DC | 0x000000A4 |
lstrcmpW | - | 0x004151D4 | 0x00019CE0 | 0x000182E0 | 0x00000542 |
SetConsoleCtrlHandler | - | 0x004151D8 | 0x00019CE4 | 0x000182E4 | 0x0000042D |
SetConsoleTextAttribute | - | 0x004151DC | 0x00019CE8 | 0x000182E8 | 0x00000446 |
SetConsoleTitleA | - | 0x004151E0 | 0x00019CEC | 0x000182EC | 0x00000447 |
GetStdHandle | - | 0x004151E4 | 0x00019CF0 | 0x000182F0 | 0x00000264 |
WriteConsoleA | - | 0x004151E8 | 0x00019CF4 | 0x000182F4 | 0x0000051A |
SetConsoleMode | - | 0x004151EC | 0x00019CF8 | 0x000182F8 | 0x0000043D |
SetProcessShutdownParameters | - | 0x004151F0 | 0x00019CFC | 0x000182FC | 0x00000483 |
SetErrorMode | - | 0x004151F4 | 0x00019D00 | 0x00018300 | 0x00000458 |
CreateFileW | - | 0x004151F8 | 0x00019D04 | 0x00018304 | 0x0000008F |
USER32.dll (20)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PeekMessageW | - | 0x00415254 | 0x00019D60 | 0x00018360 | 0x00000233 |
GetWindowLongA | - | 0x00415258 | 0x00019D64 | 0x00018364 | 0x00000195 |
wvsprintfA | - | 0x0041525C | 0x00019D68 | 0x00018368 | 0x00000334 |
SetWindowLongA | - | 0x00415260 | 0x00019D6C | 0x0001836C | 0x000002C3 |
ShowWindow | - | 0x00415264 | 0x00019D70 | 0x00018370 | 0x000002DF |
GetMessageW | - | 0x00415268 | 0x00019D74 | 0x00018374 | 0x0000015D |
CharLowerBuffW | - | 0x0041526C | 0x00019D78 | 0x00018378 | 0x0000002D |
CharUpperA | - | 0x00415270 | 0x00019D7C | 0x0001837C | 0x00000039 |
DeleteMenu | - | 0x00415274 | 0x00019D80 | 0x00018380 | 0x0000009E |
wsprintfW | - | 0x00415278 | 0x00019D84 | 0x00018384 | 0x00000333 |
FlashWindow | - | 0x0041527C | 0x00019D88 | 0x00018388 | 0x000000FB |
wsprintfA | - | 0x00415280 | 0x00019D8C | 0x0001838C | 0x00000332 |
IsWindowVisible | - | 0x00415284 | 0x00019D90 | 0x00018390 | 0x000001E0 |
SystemParametersInfoW | - | 0x00415288 | 0x00019D94 | 0x00018394 | 0x000002EC |
GetSystemMetrics | - | 0x0041528C | 0x00019D98 | 0x00018398 | 0x0000017E |
EnableMenuItem | - | 0x00415290 | 0x00019D9C | 0x0001839C | 0x000000D6 |
SetLayeredWindowAttributes | - | 0x00415294 | 0x00019DA0 | 0x000183A0 | 0x00000298 |
RegisterHotKey | - | 0x00415298 | 0x00019DA4 | 0x000183A4 | 0x00000256 |
ShutdownBlockReasonCreate | - | 0x0041529C | 0x00019DA8 | 0x000183A8 | 0x000002E1 |
GetSystemMenu | - | 0x004152A0 | 0x00019DAC | 0x000183AC | 0x0000017D |
ADVAPI32.dll (38)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegCreateKeyExA | - | 0x00415000 | 0x00019B0C | 0x0001810C | 0x00000238 |
DuplicateToken | - | 0x00415004 | 0x00019B10 | 0x00018110 | 0x000000DE |
SetThreadToken | - | 0x00415008 | 0x00019B14 | 0x00018114 | 0x000002C1 |
OpenProcessToken | - | 0x0041500C | 0x00019B18 | 0x00018118 | 0x000001F7 |
RegSetValueExA | - | 0x00415010 | 0x00019B1C | 0x0001811C | 0x0000027D |
RegOpenKeyA | - | 0x00415014 | 0x00019B20 | 0x00018120 | 0x0000025F |
RegCloseKey | - | 0x00415018 | 0x00019B24 | 0x00018124 | 0x00000230 |
RegQueryValueExA | - | 0x0041501C | 0x00019B28 | 0x00018128 | 0x0000026D |
GetAclInformation | - | 0x00415020 | 0x00019B2C | 0x0001812C | 0x00000124 |
GetAce | - | 0x00415024 | 0x00019B30 | 0x00018130 | 0x00000123 |
AllocateAndInitializeSid | - | 0x00415028 | 0x00019B34 | 0x00018134 | 0x00000020 |
AddAce | - | 0x0041502C | 0x00019B38 | 0x00018138 | 0x00000016 |
AddAccessDeniedAce | - | 0x00415030 | 0x00019B3C | 0x0001813C | 0x00000013 |
FreeSid | - | 0x00415034 | 0x00019B40 | 0x00018140 | 0x00000120 |
InitializeAcl | - | 0x00415038 | 0x00019B44 | 0x00018144 | 0x00000176 |
SetSecurityInfo | - | 0x0041503C | 0x00019B48 | 0x00018148 | 0x000002BB |
GetLengthSid | - | 0x00415040 | 0x00019B4C | 0x0001814C | 0x00000136 |
GetSecurityInfo | - | 0x00415044 | 0x00019B50 | 0x00018150 | 0x0000014E |
EnumDependentServicesA | - | 0x00415048 | 0x00019B54 | 0x00018154 | 0x000000FC |
CryptReleaseContext | - | 0x0041504C | 0x00019B58 | 0x00018158 | 0x000000CB |
InitializeSecurityDescriptor | - | 0x00415050 | 0x00019B5C | 0x0001815C | 0x00000177 |
CloseServiceHandle | - | 0x00415054 | 0x00019B60 | 0x00018160 | 0x00000057 |
OpenSCManagerA | - | 0x00415058 | 0x00019B64 | 0x00018164 | 0x000001F8 |
GetTokenInformation | - | 0x0041505C | 0x00019B68 | 0x00018168 | 0x0000015A |
ControlService | - | 0x00415060 | 0x00019B6C | 0x0001816C | 0x0000005C |
RegSetValueExW | - | 0x00415064 | 0x00019B70 | 0x00018170 | 0x0000027E |
RegDeleteValueW | - | 0x00415068 | 0x00019B74 | 0x00018174 | 0x00000248 |
QueryServiceStatusEx | - | 0x0041506C | 0x00019B78 | 0x00018178 | 0x00000229 |
RegQueryValueExW | - | 0x00415070 | 0x00019B7C | 0x0001817C | 0x0000026E |
OpenServiceA | - | 0x00415074 | 0x00019B80 | 0x00018180 | 0x000001FA |
AdjustTokenPrivileges | - | 0x00415078 | 0x00019B84 | 0x00018184 | 0x0000001F |
SetFileSecurityW | - | 0x0041507C | 0x00019B88 | 0x00018188 | 0x000002AA |
CryptAcquireContextW | - | 0x00415080 | 0x00019B8C | 0x0001818C | 0x000000B1 |
SetSecurityDescriptorOwner | - | 0x00415084 | 0x00019B90 | 0x00018190 | 0x000002B8 |
CryptGenRandom | - | 0x00415088 | 0x00019B94 | 0x00018194 | 0x000000C1 |
LookupPrivilegeValueA | - | 0x0041508C | 0x00019B98 | 0x00018198 | 0x00000196 |
CreateWellKnownSid | - | 0x00415090 | 0x00019B9C | 0x0001819C | 0x00000083 |
CheckTokenMembership | - | 0x00415094 | 0x00019BA0 | 0x000181A0 | 0x00000051 |
SHELL32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHEmptyRecycleBinW | - | 0x00415224 | 0x00019D30 | 0x00018330 | 0x000000A5 |
ShellExecuteExA | - | 0x00415228 | 0x00019D34 | 0x00018334 | 0x00000120 |
ShellExecuteExW | - | 0x0041522C | 0x00019D38 | 0x00018338 | 0x00000121 |
CommandLineToArgvW | - | 0x00415230 | 0x00019D3C | 0x0001833C | 0x00000006 |
ole32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoGetObject | - | 0x0041535C | 0x00019E68 | 0x00018468 | 0x00000035 |
CoUninitialize | - | 0x00415360 | 0x00019E6C | 0x0001846C | 0x0000006C |
CoInitializeEx | - | 0x00415364 | 0x00019E70 | 0x00018470 | 0x0000003F |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
0e66029132a885143b87b1e49e32663a52737bbff4ab96186e9e5e829aa2915f.exe | 1 | 0x00400000 | 0x0041DFFF | Relevant Image |
![]() |
32-bit | 0x0040A4D0 |
![]() |
...
|
0e66029132a885143b87b1e49e32663a52737bbff4ab96186e9e5e829aa2915f.exe | 1 | 0x00400000 | 0x0041DFFF | Final Dump |
![]() |
32-bit | 0x00412730 |
![]() |
...
|
C:\\Program Files\Common Files\Microsoft Shared\ink\hwrusash.dat.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\hwrusalm.dat.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\hwruklm.dat.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\hwruksh.dat.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\flickanimation.avi.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\hwrlatinlm.dat.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\hwrenclm.dat.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\alphabet.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\hwrenalm.dat.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\en-US\delete.avi.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\en-us\join.avi.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\en-us\correct.avi.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\en-US\split.avi.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\en-us\boxed-correct.avi.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\44-vnbktrneu.gif.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\en-US\boxed-split.avi.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\hwrcommonlm.dat.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\en-us\shapecollector.exe.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\fsdefinitions\main.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\en-US\boxed-join.avi.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\en-US\TipRes.dll.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\en-us\boxed-delete.avi.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\Content.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\en-us\ipseventlogmsg.dll.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\fsdefinitions\main\ja-jp.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\fsdefinitions\main\ko-kr.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\main\zh-dayi.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\fsdefinitions\main\zh-phonetic.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\en-US\mip.exe.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\main\zh-changjei.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\en-US\InkWatson.exe.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\en-us\micaut.dll.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\en-us\flicklearningwizard.exe.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\clicktorun\officeupdateschedule.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\en-us\inkobj.dll.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\clicktorun\servicewatcherschedule.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\clicktorun\c2rheartbeatconfig.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\bg-BG\tipresx.dll.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\el-GR\tipresx.dll.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\es-ES\tipresx.dll.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\de-de\tipresx.dll.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\et-EE\tipresx.dll.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\fr-fr\tipresx.dll.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\hr-hr\tipresx.dll.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\cs-CZ\tipresx.dll.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\fi-FI\tipresx.dll.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\ar-SA\tipresx.dll.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\hu-hu\tipresx.dll.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\en-us\tipresx.dll.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\da-DK\tipresx.dll.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\he-il\tipresx.dll.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\fsdefinitions\main\base_ca.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\main\base_altgr.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\main\base.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\en-US\tabskb.dll.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\en-us\tipband.dll.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\en-US\TipTsf.dll.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\ipsesp.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\fsdefinitions\symbols\symbase.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\ipsfin.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\ipsfra.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\ipsdeu.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\ipsen.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\ipscat.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\ipscsy.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\en-US\rtscom.dll.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\en-us\mshwlatin.dll.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\en-us\ipsmigrationplugin.dll.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\en-us\inputpersonalization.exe.mui.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\ipsdan.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\ipschs.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\ipscht.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\osknumpad\osknumpadbase.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\auxpad\auxbase.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\numbers\numbase.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\web\webbase.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\keypad\keypadbase.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\oskpred\oskpredbase.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\fsdefinitions\main\base_jpn.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\symbols\ja-jp-sym.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\fsdefinitions\main\base_heb.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\fsdefinitions\symbols\ea-sym.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\fsdefinitions\keypad.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\main\base_rtl.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\symbols.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\main\base_kor.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\fsdefinitions\oskmenu\oskmenubase.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\fsdefinitions\keypad\kor-kor.xml.lockbit | Dropped File | Binary |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\keypad\ea.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\fsdefinitions\main\basealtgr_rtl.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\fsdefinitions\oskmenu.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\fsdefinitions\numbers.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\fsdefinitions\auxpad.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\fsdefinitions\oskpred.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\fsdefinitions\osknumpad.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\fsdefinitions\web.xml.lockbit | Dropped File | Stream |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\clicktorun\i640.hash.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ClickToRun\i641033.hash.lockbit | Dropped File | Stream |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ClickToRun\Restore-My-Files.txt | Dropped File | Text |
Clean
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\ink\ipsita.xml.lockbit | Dropped File | Empty |
Clean
|
...
|
»
c:\program files\common files\microsoft shared\ink\ipshrv.xml.lockbit | Dropped File | Empty |
Clean
|
...
|
»