1c4e647f...965d | VMRay Analyzer Report
Try VMRay Analyzer
VTI SCORE: 100/100
Dynamic Analysis Report
Classification: Ransomware, Trojan

Remarks (2/2)

(0x200000e): The overall sleep time of all monitored processes was truncated from "1 minute, 30 seconds" to "30 seconds" to reveal dormant functionality.

(0x2000004): The operating system was rebooted during the analysis because the sample installed a startup script, task or application for persistence.

VMRay Threat Indicators (16 rules, 595 matches)

Severity Category Operation Count Classification
5/5
File System Encrypts content of user files 1 Ransomware
  • Encrypts the content of multiple user files. This is an indicator for ransomware.
5/5
Local AV Malicious content was detected by heuristic scan 1 -
5/5
Reputation Known malicious file 1 Trojan
  • File "C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\udxgjs.exe" is a known malicious file.
4/5
OS Modifies Windows automatic backups 1 -
3/5
OS Modifies system security configuration 1 -
3/5
File System Possibly drops ransom note files 1 Ransomware
  • Possibly drops ransom note files (creates 238 instances of the file "Decoding help.hta" in different locations).
2/5
Information Stealing Reads sensitive mail data 1 -
  • Trying to read sensitive data of mail application "Windows Mail" by file.
1/5
Persistence Installs system startup script or application 2 -
  • Adds ""c:\Decoding help.hta"" to Windows startup via registry.
  • Adds "C:\windows\searchfiles.exe" to Windows startup via registry.
1/5
File System Modifies operating system directory 1 -
1/5
Hide Tracks Writes an unusually large amount of data to the registry 1 -
  • Hides 1280 byte in "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\DateTime\\rsa".
1/5
Process Creates process with hidden window 1 -
  • The process "C:\Windows\system32\cmd.exe" starts with hidden window.
1/5
Masquerade Changes folder appearance 39 -
  • Folder "c:\$recycle.bin\s-1-5-21-3388679973-3930757225-3770151564-1000" has a changed appearance.
  • Folder "c:\program files" has a changed appearance.
  • Folder "c:\program files (x86)" has a changed appearance.
  • Folder "c:\users\public" has a changed appearance.
  • Folder "c:\users\5p5nrgjn0js halpmcxz\desktop" has a changed appearance.
  • Folder "c:\users\5p5nrgjn0js halpmcxz\downloads" has a changed appearance.
  • Folder "c:\users\5p5nrgjn0js halpmcxz\documents" has a changed appearance.
  • Folder "c:\users\5p5nrgjn0js halpmcxz\favorites" has a changed appearance.
  • Folder "c:\users\5p5nrgjn0js halpmcxz\links" has a changed appearance.
  • Folder "c:\users\public\documents" has a changed appearance.
  • Folder "c:\users\public\downloads" has a changed appearance.
  • Folder "c:\users\public\music" has a changed appearance.
  • Folder "c:\users\public\libraries" has a changed appearance.
  • Folder "c:\users\public\pictures" has a changed appearance.
  • Folder "c:\users\5p5nrgjn0js halpmcxz\contacts" has a changed appearance.
  • Folder "c:\users\default\desktop" has a changed appearance.
  • Folder "c:\users\default\documents" has a changed appearance.
  • Folder "c:\users\public\recorded tv" has a changed appearance.
  • Folder "c:\users\5p5nrgjn0js halpmcxz\music" has a changed appearance.
  • Folder "c:\users\5p5nrgjn0js halpmcxz\pictures" has a changed appearance.
  • Folder "c:\users\5p5nrgjn0js halpmcxz\saved games" has a changed appearance.
  • Folder "c:\users\5p5nrgjn0js halpmcxz\searches" has a changed appearance.
  • Folder "c:\users\5p5nrgjn0js halpmcxz\videos" has a changed appearance.
  • Folder "c:\users\public\videos" has a changed appearance.
  • Folder "c:\users\default\contacts" has a changed appearance.
  • Folder "c:\program files\common files\microsoft shared\stationery" has a changed appearance.
  • Folder "c:\users\default\downloads" has a changed appearance.
  • Folder "c:\users\default\favorites" has a changed appearance.
  • Folder "c:\users\default\music" has a changed appearance.
  • Folder "c:\users\5p5nrgjn0js halpmcxz\favorites\links" has a changed appearance.
  • Folder "c:\users\default\links" has a changed appearance.
  • Folder "c:\users\public\music\sample music" has a changed appearance.
  • Folder "c:\users\public\recorded tv\sample media" has a changed appearance.
  • Folder "c:\users\public\videos\sample videos" has a changed appearance.
  • Folder "c:\program files (x86)\common files\microsoft shared\stationery" has a changed appearance.
  • Folder "c:\users\public\desktop" has a changed appearance.
  • Folder "c:\users\default\favorites\links" has a changed appearance.
  • Folder "c:\users\public\pictures\sample pictures" has a changed appearance.
1/5
File System Modifies application directory 541 -
  • Modifies "c:\program files (x86)\mozilla firefox\browser\decoding help.hta".
  • Modifies "c:\program files (x86)\mozilla firefox\browser\blocklist.xml.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\mozilla firefox\browser\chrome.manifest.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\mozilla firefox\browser\crashreporter-override.ini.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft sql server compact edition\v3.5\sqlceme35.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft sql server compact edition\v3.5\sqlceoledb35.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\microsoft office\office14\1033\bhointl.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft office\media\office14\office10.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft office\office14\1036\mso.acl.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft office\office14\3082\mso.acl.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft synchronization services\ado.net\v1.0\microsoft.synchronization.data.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppc.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\mozilla firefox\browser\omni.ja.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\msenv\publicassemblies\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\msinfo\en-us\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\vc\msdia100.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\msinfo\en-us\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\vba\vba6\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\vc\amd64\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\aftrnoon\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\web folders\msosv.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\vsto\vstoee.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\euro\msoeuro.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\stationery\desktop.ini.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\grphflt\cgmimp32.cfg.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\hx.hxc.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft office\media\cagcat10\elphrg01.wav.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\windows portable devices\mambo_prediction_hiking.exe.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\msclientdatamgr\mscdm.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft office\media\office14\bullets\decoding help.hta".
  • Modifies "c:\program files (x86)\java\jre7\lib\accessibility.properties.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\vc\msdia100.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\source engine\ose.exe.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\proof\mslid.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\windows nt\tabletextservice\en-us\decoding help.hta".
  • Modifies "c:\program files\windows nt\accessories\en-us\decoding help.hta".
  • Modifies "c:\program files (x86)\windows nt\accessories\en-us\decoding help.hta".
  • Modifies "c:\program files (x86)\java\jre7\bin\awt.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\windows nt\tabletextservice\en-us\decoding help.hta".
  • Modifies "c:\program files\windows media player\negotiationsbadge.exe.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\berime.htm.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\windows sidebar\settings.ini.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\smart tag\fplace.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\textconv\wpft532.cnv.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft office\templates\1033\adjacencyletter.dotx.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\equation\eqnedt32.cnt.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\filters\msgfilt.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\windows photo viewer\methods.exe.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft office\office14\1033\accolki.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft office\stationery\1033\currency.htm.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft office\clipart\pub60cor\ag00038_.gif.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\mozilla maintenance service\updater.ini.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\vsto\vstoee.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft office\document themes 14\austin.thmx.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\microsoft office\office14\ieawsdc.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\office14\csi.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\system\ole db\xmlrw.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\system\ole db\xmlrw.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\google\chrome\application\chrome.exe.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\translat\fren\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\office14\acecore.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\help\hxds.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\dw\dbghelp.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\portal\portalconnectcore.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\themes14\themes.inf.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft office\office14\accicons.exe.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\translat\esen\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\arm\1.0\decoding help.hta".
  • Modifies "c:\program files\common files\system\msmapi\1033\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\equation\1033\decoding help.hta".
  • Modifies "c:\program files\common files\system\ole db\en-us\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\translat\enfr\decoding help.hta".
  • Modifies "c:\program files\microsoft office\media\cagcat10\1033\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\portal\1033\decoding help.hta".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\system\ole db\en-us\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\textconv\wksconv\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\office14\1033\decoding help.hta".
  • Modifies "c:\program files\microsoft office\media\office14\1033\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\vsta\8.0\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\translat\arfr\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\translat\enes\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\studio\decoding help.hta".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\privateassemblies\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\sumipntg\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\spring\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\java\java update\jaucheck.exe.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\web folders\1033\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\smart tag\1033\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\vba\vba7\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\arctic\decoding help.hta".
  • Modifies "c:\program files\microsoft office\clipart\publisher\backgrounds\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\nl_nl\decoding help.hta".
  • Modifies "c:\program files\microsoft office\templates\1033\access\decoding help.hta".
  • Modifies "c:\program files\common files\system\msadc\en-us\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\ink\en-us\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\translat\frar\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\vsta\appinfodocument\decoding help.hta".
  • Modifies "c:\program files\microsoft office\media\office14\autoshap\decoding help.hta".
  • Modifies "c:\program files\msbuild\microsoft\windows workflow foundation\v3.0\decoding help.hta".
  • Modifies "c:\program files\microsoft office\media\office14\lines\decoding help.hta".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\vsta\bin\1033\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\blends\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\bluecalm\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\blueprnt\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\breeze\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\boldstri\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\canyon\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\capsules\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\cascade\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\axis\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\level\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\profile\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\layers\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\papyrus\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\quad\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\ripple\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\rmnsque\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\satin\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\slate\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\strtedge\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\vsto\10.0\decoding help.hta".
  • Modifies "c:\program files (x86)\microsoft analysis services\as oledb\10\cartridges\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\hr_hr\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\visio shared\fonts\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\cs_cz\decoding help.hta".
  • Modifies "c:\program files\common files\system\ado\en-us\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\system\ado\en-us\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\ko_kr\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\ink\1.0\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\ink\1.7\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\concrete\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\indust\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\ice\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\expeditn\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\evrgreen\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\edge\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\eclipse\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\echo\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\deepblue\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\compass\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\refined\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\network\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\ca_es\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\hu_hu\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\it_it\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\da_dk\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\de_de\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\es_es\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\eu_es\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\fi_fi\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\fr_fr\decoding help.hta".
  • Modifies "c:\program files\microsoft analysis services\as oledb\10\cartridges\decoding help.hta".
  • Modifies "c:\program files\microsoft office\office14\accessweb\decoding help.hta".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\publicassemblies\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\en_us\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\ja_jp\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\zh_tw\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\zh_cn\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\sv_se\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\pt_br\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\pl_pl\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\nb_no\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\uk_ua\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\tr_tr\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\sl_si\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\sk_sk\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\ru_ru\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\ro_ro\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\vsto\10.0\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\1040\decoding help.hta".
  • Modifies "c:\program files\windows media player\media renderer\decoding help.hta".
  • Modifies "c:\program files\windows media player\en-us\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\1033\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\1049\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\2052\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\1028\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\1041\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\1042\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\3082\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\1046\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\1031\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\1036\decoding help.hta".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\calendar.gadget\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\ar-sa\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\bg-bg\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\cs-cz\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\da-dk\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\de-de\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\el-gr\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\es-es\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\et-ee\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\fi-fi\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\fr-fr\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\he-il\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\hr-hr\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\hu-hu\decoding help.hta".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\currency.gadget\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\it-it\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\ja-jp\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\microsoft shared\web server extensions\14\bin\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\ko-kr\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\lt-lt\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\lv-lv\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\nb-no\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\nl-nl\decoding help.hta".
  • Modifies "c:\program files (x86)\msbuild\microsoft\windows workflow foundation\v3.5\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\pl-pl\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\ru-ru\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\pt-br\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\pt-pt\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\ro-ro\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\translat\fren\msb1fren.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft office\media\office14\bullets\bd10253_.gif.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft office\media\office14\bullets\bd10254_.gif.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft office\media\office14\bullets\bd10255_.gif.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\dvd maker\shared\dvdstyles\babyboy\decoding help.hta".
  • Modifies "c:\program files (x86)\msbuild\microsoft\windows workflow foundation\v3.0\decoding help.hta".
  • Modifies "c:\program files\microsoft office\media\office14\bullets\bd10263_.gif.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\web server extensions\14\bin\fpsrvutl.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\translat\msb1cach.lex.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\microsoft office\office14\1033\dl_res.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\msenv\publicassemblies\extensibility.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\portal\1033\portalconnect.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\google\chrome\application\58.0.3029.110\58.0.3029.110.manifest.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\equation\1033\eeintl.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\system\ole db\xmlrwbin.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\system\msmapi\1033\msmapi32.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft synchronization services\ado.net\v1.0\microsoft.synchronization.data.server.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\system\ole db\xmlrwbin.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\arm\1.0\acrobatupdater.exe.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft office\media\cagcat10\1033\cagcat10.mml.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft office\media\office14\office10.mmw.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\microsoft office\office14\inlaunch.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\hx.hxt.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\translat\enfr\msb1enfr.its.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\translat\fren\msb1fren.its.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppcext.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\themes14\refined\preview.gif.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft office\office14\accessweb\clntwrap.htm.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\themes14\edge\edge.elm.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\themes14\compass\compass.elm.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\themes14\network\network.elm.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\themes14\capsules\capsules.elm.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\themes14\evrgreen\evrgreen.elm.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\themes14\indust\indust.elm.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\themes14\expeditn\expeditn.elm.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\themes14\eclipse\eclipse.elm.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\vba\vba7\1033\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\web server extensions\14\bin\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\studio\preview.gif.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\vsta\8.0\microsoft.visualstudio.tools.applications.blueprints.tlb.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\office14\1033\aceintl.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\vsto\10.0\1033\decoding help.hta".
  • Modifies "c:\program files\microsoft sql server compact edition\v3.5\sqlceqp35.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\1033\hxdsui.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\themes14\iris\iris.elm.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\web folders\1033\msosvint.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\smart tag\1033\mcabout.htm.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft office\stationery\1033\dadshirt.gif.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft office\office14\1033\accvdtui.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft office\clipart\pub60cor\ag00040_.gif.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\google\chrome\application\chrome.visualelementsmanifest.xml.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft office\templates\1033\adjacencymergeletter.dotx.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\vba\vba6\vbe6ext.olb.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\themes14\aftrnoon\aftrnoon.elm.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\vsta\appinfodocument\addins.store.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft office\media\office14\autoshap\autoshap.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft office\media\office14\lines\bd10219_.gif.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\equation\eqnedt32.exe.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\vsta\pipeline.v10.0\pipelinesegments.store.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\vc\msdia80.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\vsta\bin\1033\vstaclientpkgui.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\java\jre7\bin\axbridge.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\vc\amd64\msdia80.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\mozilla firefox\browser\searchplugins\decoding help.hta".
  • Modifies "c:\program files\windows media player\network sharing\decoding help.hta".
  • Modifies "c:\program files (x86)\adobe\reader 10.0\esl\decoding help.hta".
  • Modifies "c:\program files (x86)\microsoft visual studio 8\common7\ide\publicassemblies\microsoft.visualstudio.tools.applications.adapter.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft office\media\office14\1033\office10.mml.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\office14\1033\msointl.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\java\jre7\lib\alt-rt.jar.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\textconv\wksconv\wkconv.exe.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\office14\csisoap.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\translat\frar\msb1frar.its.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\proof\mswds_en.lex.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\ink\sk-sk\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\water\decoding help.hta".
  • Modifies "c:\program files\windows media player\skins\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\translat\enes\msb1enes.its.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\translat\arfr\msb1arfr.its.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\themes14\watermar\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\sl-si\decoding help.hta".
  • Modifies "c:\program files (x86)\reference assemblies\microsoft\framework\v3.0\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\sr-latn-cs\decoding help.hta".
  • Modifies "c:\program files (x86)\reference assemblies\microsoft\framework\v3.5\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\sv-se\decoding help.hta".
  • Modifies "c:\program files\windows sidebar\gadgets\calendar.gadget\decoding help.hta".
  • Modifies "c:\program files\reference assemblies\microsoft\framework\v3.5\redistlist\decoding help.hta".
  • Modifies "c:\program files\windows sidebar\gadgets\clock.gadget\decoding help.hta".
  • Modifies "c:\program files\microsoft analysis services\as oledb\10\msmgdsrv.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\vc\msdia90.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\vsto\10.0\vstoinstaller.config.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\reference assemblies\microsoft\framework\v3.0\winfxlist.xml.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\microsoft.net\primary interop assemblies\microsoft.stdformat.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\hu_hu\reader_10.0.helpcfg.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\windows sidebar\gadgets\cpu.gadget\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\it_it\reader_10.0.helpcfg.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\da_dk\reader_10.0.helpcfg.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\de_de\reader_10.0.helpcfg.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\es_es\reader_10.0.helpcfg.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\eu_es\reader_10.0.helpcfg.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\fi_fi\reader_10.0.helpcfg.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\fr_fr\reader_10.0.helpcfg.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\microsoft analysis services\as oledb\10\cartridges\as80.xsl.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\1040\hxdsui.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\reference assemblies\microsoft\framework\v3.0\redistlist\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\ricepapr\preview.gif.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\windows sidebar\gadgets\currency.gadget\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\vsto\10.0\1033\decoding help.hta".
  • Modifies "c:\program files\windows sidebar\gadgets\mediacenter.gadget\decoding help.hta".
  • Modifies "c:\program files\windows sidebar\gadgets\picturepuzzle.gadget\decoding help.hta".
  • Modifies "c:\program files\windows sidebar\gadgets\rssfeeds.gadget\decoding help.hta".
  • Modifies "c:\program files\windows sidebar\gadgets\slideshow.gadget\decoding help.hta".
  • Modifies "c:\program files\dvd maker\shared\dvdstyles\videowall\decoding help.hta".
  • Modifies "c:\program files\dvd maker\shared\dvdstyles\pets\decoding help.hta".
  • Modifies "c:\program files\dvd maker\shared\dvdstyles\oldage\decoding help.hta".
  • Modifies "c:\program files\windows sidebar\gadgets\weather.gadget\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\themes14\pixel\pixel.elm.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\themes14\radial\preview.gif.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\themes14\journal\journal.elm.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\themes14\sky\preview.gif.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\themes14\slate\preview.gif.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\themes14\sonora\preview.gif.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files\common files\microsoft shared\themes14\strtedge\preview.gif.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\1049\hxdsui.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\2052\hxdsui.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\microsoft shared\help\1028\hxdsui.dll.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\calendar.gadget\en-us\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\th-th\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\tr-tr\decoding help.hta".
  • Modifies "c:\program files (x86)\windows sidebar\gadgets\calendar.gadget\images\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\uk-ua\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\zh-cn\decoding help.hta".
  • Modifies "c:\program files\common files\microsoft shared\ink\zh-tw\decoding help.hta".
  • Modifies "c:\program files\dvd maker\shared\dvdstyles\vignette\decoding help.hta".
  • Modifies "c:\program files\dvd maker\shared\dvdstyles\specialoccasion\decoding help.hta".
  • Modifies "c:\program files\dvd maker\shared\dvdstyles\full\decoding help.hta".
  • Modifies "c:\program files\dvd maker\shared\dvdstyles\performance\decoding help.hta".
  • Modifies "c:\program files\dvd maker\shared\dvdstyles\memories\decoding help.hta".
  • Modifies "c:\program files\dvd maker\shared\dvdstyles\babygirl\decoding help.hta".
  • Modifies "c:\program files\dvd maker\shared\dvdstyles\huecycle\decoding help.hta".
  • Modifies "c:\program files\dvd maker\shared\dvdstyles\flippage\decoding help.hta".
  • Modifies "c:\program files\dvd maker\shared\dvdstyles\push\decoding help.hta".
  • Modifies "c:\program files\dvd maker\shared\dvdstyles\rectangles\decoding help.hta".
  • Modifies "c:\program files\dvd maker\shared\dvdstyles\resizingpanels\decoding help.hta".
  • Modifies "c:\program files\dvd maker\shared\dvdstyles\shatter\decoding help.hta".
  • Modifies "c:\program files\dvd maker\shared\dvdstyles\sports\decoding help.hta".
  • Modifies "c:\program files\dvd maker\shared\dvdstyles\stacking\decoding help.hta".
  • Modifies "c:\program files\dvd maker\shared\dvdstyles\travel\decoding help.hta".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\ca_es\reader_10.0.helpcfg.[id]hwwph9ujuooy4hf1[id]".
  • Modifies "c:\program files (x86)\common files\adobe\helpcfg\ru_ru\reader_10.0.helpcfg.[id]hwwph9ujuooy4hf1[id]".
1/5
Information Stealing Possibly does reconnaissance 1 -
  • Possibly trying to gather information about application "Mozilla Firefox" by file.
1/5
File System Creates an unusually large number of files 1 -
0/5
Process Enumerates running processes 1 -

Screenshots

Monitored Processes

Sample Information

ID #118887
MD5 29cc50130b5f6efd01703b6031985e72 Copy to Clipboard
SHA1 96b59c746f660c2b190244f08764bb9d64f90b76 Copy to Clipboard
SHA256 1c4e647f3fbac1eea97b488a7c2600f3c61c8b4d6e2e7b08acc8f5ec2b7a965d Copy to Clipboard
SSDeep 192:nn829Uqt80RvmDn/GW0YPUWLTwmH+M6r6BmiOxEhGr:n829Dt80R2n/3F8s+LLLC Copy to Clipboard
ImpHash 0a98a06f576cfeebd2f91325d9ccac02 Copy to Clipboard
Filename udxgjs.exe
File Size 11.50 KB
Sample Type Windows Exe (x86-32)

Analysis Information

Creation Time 2019-07-23 00:10 (UTC+2)
Analysis Duration 00:04:29
Number of Monitored Processes 3
Execution Successful True
Reputation Enabled True
WHOIS Enabled False
Local AV Enabled True
YARA Enabled True
Number of AV Matches 1
Number of YARA Matches 0
Termination Reason Timeout
Tags
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image