VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Dropper, Trojan |
=UTF-8B4oCuNHBtLnhlcy5leGU==.exe
Windows Exe (x86-32)
Created 6 years ago
Remarks
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\=UTF-8B4oCuNHBtLnhlcy5leGU==.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-07-06 17:40 (UTC+2) |
Last Seen | 2019-07-12 16:00 (UTC+2) |
Names | Win32.Trojan.Delshad |
Families | Delshad |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x41d549 |
Size Of Code | 0x2ea00 |
Size Of Initialized Data | 0x13400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-09-30 18:01:44+00:00 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x2e924 | 0x2ea00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.7 |
.rdata | 0x430000 | 0x9a8c | 0x9c00 | 0x2ee00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.13 |
.data | 0x43a000 | 0x203a0 | 0xc00 | 0x38a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.24 |
.gfids | 0x45b000 | 0xe8 | 0x200 | 0x39600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.09 |
.rsrc | 0x45c000 | 0x68f8 | 0x6a00 | 0x39800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.67 |
.reloc | 0x463000 | 0x1fdc | 0x2000 | 0x40200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.68 |
Imports (2)
»
KERNEL32.dll (140)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetLastError | 0x0 | 0x430000 | 0x38d20 | 0x37b20 | 0x202 |
SetLastError | 0x0 | 0x430004 | 0x38d24 | 0x37b24 | 0x473 |
GetCurrentProcess | 0x0 | 0x430008 | 0x38d28 | 0x37b28 | 0x1c0 |
DeviceIoControl | 0x0 | 0x43000c | 0x38d2c | 0x37b2c | 0xdd |
SetFileTime | 0x0 | 0x430010 | 0x38d30 | 0x37b30 | 0x46a |
CloseHandle | 0x0 | 0x430014 | 0x38d34 | 0x37b34 | 0x52 |
CreateDirectoryW | 0x0 | 0x430018 | 0x38d38 | 0x37b38 | 0x81 |
RemoveDirectoryW | 0x0 | 0x43001c | 0x38d3c | 0x37b3c | 0x403 |
CreateFileW | 0x0 | 0x430020 | 0x38d40 | 0x37b40 | 0x8f |
DeleteFileW | 0x0 | 0x430024 | 0x38d44 | 0x37b44 | 0xd6 |
CreateHardLinkW | 0x0 | 0x430028 | 0x38d48 | 0x37b48 | 0x93 |
GetShortPathNameW | 0x0 | 0x43002c | 0x38d4c | 0x37b4c | 0x261 |
GetLongPathNameW | 0x0 | 0x430030 | 0x38d50 | 0x37b50 | 0x20f |
MoveFileW | 0x0 | 0x430034 | 0x38d54 | 0x37b54 | 0x363 |
GetFileType | 0x0 | 0x430038 | 0x38d58 | 0x37b58 | 0x1f3 |
GetStdHandle | 0x0 | 0x43003c | 0x38d5c | 0x37b5c | 0x264 |
WriteFile | 0x0 | 0x430040 | 0x38d60 | 0x37b60 | 0x525 |
ReadFile | 0x0 | 0x430044 | 0x38d64 | 0x37b64 | 0x3c0 |
FlushFileBuffers | 0x0 | 0x430048 | 0x38d68 | 0x37b68 | 0x157 |
SetEndOfFile | 0x0 | 0x43004c | 0x38d6c | 0x37b6c | 0x453 |
SetFilePointer | 0x0 | 0x430050 | 0x38d70 | 0x37b70 | 0x466 |
SetFileAttributesW | 0x0 | 0x430054 | 0x38d74 | 0x37b74 | 0x461 |
GetFileAttributesW | 0x0 | 0x430058 | 0x38d78 | 0x37b78 | 0x1ea |
FindClose | 0x0 | 0x43005c | 0x38d7c | 0x37b7c | 0x12e |
FindFirstFileW | 0x0 | 0x430060 | 0x38d80 | 0x37b80 | 0x139 |
FindNextFileW | 0x0 | 0x430064 | 0x38d84 | 0x37b84 | 0x145 |
GetVersionExW | 0x0 | 0x430068 | 0x38d88 | 0x37b88 | 0x2a4 |
GetCurrentDirectoryW | 0x0 | 0x43006c | 0x38d8c | 0x37b8c | 0x1bf |
GetFullPathNameW | 0x0 | 0x430070 | 0x38d90 | 0x37b90 | 0x1fb |
FoldStringW | 0x0 | 0x430074 | 0x38d94 | 0x37b94 | 0x15c |
GetModuleFileNameW | 0x0 | 0x430078 | 0x38d98 | 0x37b98 | 0x214 |
GetModuleHandleW | 0x0 | 0x43007c | 0x38d9c | 0x37b9c | 0x218 |
FindResourceW | 0x0 | 0x430080 | 0x38da0 | 0x37ba0 | 0x14e |
FreeLibrary | 0x0 | 0x430084 | 0x38da4 | 0x37ba4 | 0x162 |
GetProcAddress | 0x0 | 0x430088 | 0x38da8 | 0x37ba8 | 0x245 |
GetCurrentProcessId | 0x0 | 0x43008c | 0x38dac | 0x37bac | 0x1c1 |
ExitProcess | 0x0 | 0x430090 | 0x38db0 | 0x37bb0 | 0x119 |
SetThreadExecutionState | 0x0 | 0x430094 | 0x38db4 | 0x37bb4 | 0x493 |
Sleep | 0x0 | 0x430098 | 0x38db8 | 0x37bb8 | 0x4b2 |
LoadLibraryW | 0x0 | 0x43009c | 0x38dbc | 0x37bbc | 0x33f |
GetSystemDirectoryW | 0x0 | 0x4300a0 | 0x38dc0 | 0x37bc0 | 0x270 |
CompareStringW | 0x0 | 0x4300a4 | 0x38dc4 | 0x37bc4 | 0x64 |
AllocConsole | 0x0 | 0x4300a8 | 0x38dc8 | 0x37bc8 | 0x10 |
FreeConsole | 0x0 | 0x4300ac | 0x38dcc | 0x37bcc | 0x15f |
AttachConsole | 0x0 | 0x4300b0 | 0x38dd0 | 0x37bd0 | 0x17 |
WriteConsoleW | 0x0 | 0x4300b4 | 0x38dd4 | 0x37bd4 | 0x524 |
GetProcessAffinityMask | 0x0 | 0x4300b8 | 0x38dd8 | 0x37bd8 | 0x246 |
CreateThread | 0x0 | 0x4300bc | 0x38ddc | 0x37bdc | 0xb5 |
SetThreadPriority | 0x0 | 0x4300c0 | 0x38de0 | 0x37be0 | 0x499 |
InitializeCriticalSection | 0x0 | 0x4300c4 | 0x38de4 | 0x37be4 | 0x2e2 |
EnterCriticalSection | 0x0 | 0x4300c8 | 0x38de8 | 0x37be8 | 0xee |
LeaveCriticalSection | 0x0 | 0x4300cc | 0x38dec | 0x37bec | 0x339 |
DeleteCriticalSection | 0x0 | 0x4300d0 | 0x38df0 | 0x37bf0 | 0xd1 |
SetEvent | 0x0 | 0x4300d4 | 0x38df4 | 0x37bf4 | 0x459 |
ResetEvent | 0x0 | 0x4300d8 | 0x38df8 | 0x37bf8 | 0x40f |
ReleaseSemaphore | 0x0 | 0x4300dc | 0x38dfc | 0x37bfc | 0x3fe |
WaitForSingleObject | 0x0 | 0x4300e0 | 0x38e00 | 0x37c00 | 0x4f9 |
CreateEventW | 0x0 | 0x4300e4 | 0x38e04 | 0x37c04 | 0x85 |
CreateSemaphoreW | 0x0 | 0x4300e8 | 0x38e08 | 0x37c08 | 0xae |
GetSystemTime | 0x0 | 0x4300ec | 0x38e0c | 0x37c0c | 0x277 |
SystemTimeToTzSpecificLocalTime | 0x0 | 0x4300f0 | 0x38e10 | 0x37c10 | 0x4be |
TzSpecificLocalTimeToSystemTime | 0x0 | 0x4300f4 | 0x38e14 | 0x37c14 | 0x4d0 |
SystemTimeToFileTime | 0x0 | 0x4300f8 | 0x38e18 | 0x37c18 | 0x4bd |
FileTimeToLocalFileTime | 0x0 | 0x4300fc | 0x38e1c | 0x37c1c | 0x124 |
LocalFileTimeToFileTime | 0x0 | 0x430100 | 0x38e20 | 0x37c20 | 0x346 |
FileTimeToSystemTime | 0x0 | 0x430104 | 0x38e24 | 0x37c24 | 0x125 |
GetCPInfo | 0x0 | 0x430108 | 0x38e28 | 0x37c28 | 0x172 |
IsDBCSLeadByte | 0x0 | 0x43010c | 0x38e2c | 0x37c2c | 0x2fe |
MultiByteToWideChar | 0x0 | 0x430110 | 0x38e30 | 0x37c30 | 0x367 |
WideCharToMultiByte | 0x0 | 0x430114 | 0x38e34 | 0x37c34 | 0x511 |
GlobalAlloc | 0x0 | 0x430118 | 0x38e38 | 0x37c38 | 0x2b3 |
GetTickCount | 0x0 | 0x43011c | 0x38e3c | 0x37c3c | 0x293 |
LockResource | 0x0 | 0x430120 | 0x38e40 | 0x37c40 | 0x354 |
GlobalLock | 0x0 | 0x430124 | 0x38e44 | 0x37c44 | 0x2be |
GlobalUnlock | 0x0 | 0x430128 | 0x38e48 | 0x37c48 | 0x2c5 |
GlobalFree | 0x0 | 0x43012c | 0x38e4c | 0x37c4c | 0x2ba |
LoadResource | 0x0 | 0x430130 | 0x38e50 | 0x37c50 | 0x341 |
SizeofResource | 0x0 | 0x430134 | 0x38e54 | 0x37c54 | 0x4b1 |
SetCurrentDirectoryW | 0x0 | 0x430138 | 0x38e58 | 0x37c58 | 0x44d |
GetExitCodeProcess | 0x0 | 0x43013c | 0x38e5c | 0x37c5c | 0x1df |
GetLocalTime | 0x0 | 0x430140 | 0x38e60 | 0x37c60 | 0x203 |
MapViewOfFile | 0x0 | 0x430144 | 0x38e64 | 0x37c64 | 0x357 |
UnmapViewOfFile | 0x0 | 0x430148 | 0x38e68 | 0x37c68 | 0x4d6 |
CreateFileMappingW | 0x0 | 0x43014c | 0x38e6c | 0x37c6c | 0x8c |
OpenFileMappingW | 0x0 | 0x430150 | 0x38e70 | 0x37c70 | 0x379 |
GetCommandLineW | 0x0 | 0x430154 | 0x38e74 | 0x37c74 | 0x187 |
SetEnvironmentVariableW | 0x0 | 0x430158 | 0x38e78 | 0x37c78 | 0x457 |
ExpandEnvironmentStringsW | 0x0 | 0x43015c | 0x38e7c | 0x37c7c | 0x11d |
GetTempPathW | 0x0 | 0x430160 | 0x38e80 | 0x37c80 | 0x285 |
MoveFileExW | 0x0 | 0x430164 | 0x38e84 | 0x37c84 | 0x360 |
GetLocaleInfoW | 0x0 | 0x430168 | 0x38e88 | 0x37c88 | 0x206 |
GetTimeFormatW | 0x0 | 0x43016c | 0x38e8c | 0x37c8c | 0x297 |
GetDateFormatW | 0x0 | 0x430170 | 0x38e90 | 0x37c90 | 0x1c8 |
GetNumberFormatW | 0x0 | 0x430174 | 0x38e94 | 0x37c94 | 0x233 |
SetFilePointerEx | 0x0 | 0x430178 | 0x38e98 | 0x37c98 | 0x467 |
GetConsoleMode | 0x0 | 0x43017c | 0x38e9c | 0x37c9c | 0x1ac |
GetConsoleCP | 0x0 | 0x430180 | 0x38ea0 | 0x37ca0 | 0x19a |
HeapSize | 0x0 | 0x430184 | 0x38ea4 | 0x37ca4 | 0x2d4 |
SetStdHandle | 0x0 | 0x430188 | 0x38ea8 | 0x37ca8 | 0x487 |
GetProcessHeap | 0x0 | 0x43018c | 0x38eac | 0x37cac | 0x24a |
RaiseException | 0x0 | 0x430190 | 0x38eb0 | 0x37cb0 | 0x3b1 |
GetSystemInfo | 0x0 | 0x430194 | 0x38eb4 | 0x37cb4 | 0x273 |
VirtualProtect | 0x0 | 0x430198 | 0x38eb8 | 0x37cb8 | 0x4ef |
VirtualQuery | 0x0 | 0x43019c | 0x38ebc | 0x37cbc | 0x4f1 |
LoadLibraryExA | 0x0 | 0x4301a0 | 0x38ec0 | 0x37cc0 | 0x33d |
IsProcessorFeaturePresent | 0x0 | 0x4301a4 | 0x38ec4 | 0x37cc4 | 0x304 |
IsDebuggerPresent | 0x0 | 0x4301a8 | 0x38ec8 | 0x37cc8 | 0x300 |
UnhandledExceptionFilter | 0x0 | 0x4301ac | 0x38ecc | 0x37ccc | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x4301b0 | 0x38ed0 | 0x37cd0 | 0x4a5 |
GetStartupInfoW | 0x0 | 0x4301b4 | 0x38ed4 | 0x37cd4 | 0x263 |
QueryPerformanceCounter | 0x0 | 0x4301b8 | 0x38ed8 | 0x37cd8 | 0x3a7 |
GetCurrentThreadId | 0x0 | 0x4301bc | 0x38edc | 0x37cdc | 0x1c5 |
GetSystemTimeAsFileTime | 0x0 | 0x4301c0 | 0x38ee0 | 0x37ce0 | 0x279 |
InitializeSListHead | 0x0 | 0x4301c4 | 0x38ee4 | 0x37ce4 | 0x2e7 |
TerminateProcess | 0x0 | 0x4301c8 | 0x38ee8 | 0x37ce8 | 0x4c0 |
RtlUnwind | 0x0 | 0x4301cc | 0x38eec | 0x37cec | 0x418 |
EncodePointer | 0x0 | 0x4301d0 | 0x38ef0 | 0x37cf0 | 0xea |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4301d4 | 0x38ef4 | 0x37cf4 | 0x2e3 |
TlsAlloc | 0x0 | 0x4301d8 | 0x38ef8 | 0x37cf8 | 0x4c5 |
TlsGetValue | 0x0 | 0x4301dc | 0x38efc | 0x37cfc | 0x4c7 |
TlsSetValue | 0x0 | 0x4301e0 | 0x38f00 | 0x37d00 | 0x4c8 |
TlsFree | 0x0 | 0x4301e4 | 0x38f04 | 0x37d04 | 0x4c6 |
LoadLibraryExW | 0x0 | 0x4301e8 | 0x38f08 | 0x37d08 | 0x33e |
QueryPerformanceFrequency | 0x0 | 0x4301ec | 0x38f0c | 0x37d0c | 0x3a8 |
GetModuleHandleExW | 0x0 | 0x4301f0 | 0x38f10 | 0x37d10 | 0x217 |
GetModuleFileNameA | 0x0 | 0x4301f4 | 0x38f14 | 0x37d14 | 0x213 |
GetACP | 0x0 | 0x4301f8 | 0x38f18 | 0x37d18 | 0x168 |
HeapFree | 0x0 | 0x4301fc | 0x38f1c | 0x37d1c | 0x2cf |
HeapAlloc | 0x0 | 0x430200 | 0x38f20 | 0x37d20 | 0x2cb |
HeapReAlloc | 0x0 | 0x430204 | 0x38f24 | 0x37d24 | 0x2d2 |
GetStringTypeW | 0x0 | 0x430208 | 0x38f28 | 0x37d28 | 0x269 |
LCMapStringW | 0x0 | 0x43020c | 0x38f2c | 0x37d2c | 0x32d |
FindFirstFileExA | 0x0 | 0x430210 | 0x38f30 | 0x37d30 | 0x133 |
FindNextFileA | 0x0 | 0x430214 | 0x38f34 | 0x37d34 | 0x143 |
IsValidCodePage | 0x0 | 0x430218 | 0x38f38 | 0x37d38 | 0x30a |
GetOEMCP | 0x0 | 0x43021c | 0x38f3c | 0x37d3c | 0x237 |
GetCommandLineA | 0x0 | 0x430220 | 0x38f40 | 0x37d40 | 0x186 |
GetEnvironmentStringsW | 0x0 | 0x430224 | 0x38f44 | 0x37d44 | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x430228 | 0x38f48 | 0x37d48 | 0x161 |
DecodePointer | 0x0 | 0x43022c | 0x38f4c | 0x37d4c | 0xca |
gdiplus.dll (9)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GdiplusShutdown | 0x0 | 0x430234 | 0x38f54 | 0x37d54 | 0x274 |
GdiplusStartup | 0x0 | 0x430238 | 0x38f58 | 0x37d58 | 0x275 |
GdipCreateHBITMAPFromBitmap | 0x0 | 0x43023c | 0x38f5c | 0x37d5c | 0x5f |
GdipCreateBitmapFromStreamICM | 0x0 | 0x430240 | 0x38f60 | 0x37d60 | 0x52 |
GdipCreateBitmapFromStream | 0x0 | 0x430244 | 0x38f64 | 0x37d64 | 0x51 |
GdipDisposeImage | 0x0 | 0x430248 | 0x38f68 | 0x37d68 | 0x98 |
GdipCloneImage | 0x0 | 0x43024c | 0x38f6c | 0x37d6c | 0x36 |
GdipFree | 0x0 | 0x430250 | 0x38f70 | 0x37d70 | 0xed |
GdipAlloc | 0x0 | 0x430254 | 0x38f74 | 0x37d74 | 0x21 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
=utf-8b4ocunhbtlnhlcy5legu==.exe | 1 | 0x00E70000 | 0x00ED4FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
=utf-8b4ocunhbtlnhlcy5legu==.exe | 1 | 0x00E70000 | 0x00ED4FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Starter.3.EC0425DF |
Malicious
|
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-07-07 06:28 (UTC+2) |
Last Seen | 2019-07-12 17:00 (UTC+2) |
Names | Win32.Trojan.Encoder |
Families | Encoder |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4014b0 |
Size Of Code | 0x77800 |
Size Of Initialized Data | 0x86a00 |
Size Of Uninitialized Data | 0x1400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-07-02 04:50:38+00:00 |
Sections (16)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x77640 | 0x77800 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.9 |
.data | 0x479000 | 0x67f8 | 0x6800 | 0x77c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.55 |
.rdata | 0x480000 | 0x7540 | 0x7600 | 0x7e400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ | 5.0 |
.bss | 0x488000 | 0x13a0 | 0x0 | 0x0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.idata | 0x48a000 | 0xf98 | 0x1000 | 0x85a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.25 |
.CRT | 0x48b000 | 0x34 | 0x200 | 0x86a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.27 |
.tls | 0x48c000 | 0x20 | 0x200 | 0x86c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.22 |
/4 | 0x48d000 | 0x4fe0 | 0x5000 | 0x86e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 4.27 |
/19 | 0x492000 | 0x1dbfe1 | 0x1dc000 | 0x8be00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.06 |
/31 | 0x66e000 | 0x1c2aa | 0x1c400 | 0x267e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 4.78 |
/45 | 0x68b000 | 0x3a2ad | 0x3a400 | 0x284200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.09 |
/57 | 0x6c6000 | 0x1b6b4 | 0x1b800 | 0x2be600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 4.74 |
/70 | 0x6e2000 | 0x9489 | 0x9600 | 0x2d9e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 4.49 |
/81 | 0x6ec000 | 0x817e5 | 0x81800 | 0x2e3400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.05 |
/92 | 0x76e000 | 0xc4fc0 | 0xc5000 | 0x364c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.66 |
/107 | 0x833000 | 0x2ab10 | 0x2ac00 | 0x429c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 4.85 |
Imports (4)
»
ADVAPI32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptAcquireContextW | 0x0 | 0x48a2c4 | 0x8a064 | 0x85a64 | 0xb1 |
CryptCreateHash | 0x0 | 0x48a2c8 | 0x8a068 | 0x85a68 | 0xb3 |
CryptDeriveKey | 0x0 | 0x48a2cc | 0x8a06c | 0x85a6c | 0xb5 |
CryptDestroyHash | 0x0 | 0x48a2d0 | 0x8a070 | 0x85a70 | 0xb6 |
CryptDestroyKey | 0x0 | 0x48a2d4 | 0x8a074 | 0x85a74 | 0xb7 |
CryptEncrypt | 0x0 | 0x48a2d8 | 0x8a078 | 0x85a78 | 0xba |
CryptHashData | 0x0 | 0x48a2dc | 0x8a07c | 0x85a7c | 0xc8 |
CryptReleaseContext | 0x0 | 0x48a2e0 | 0x8a080 | 0x85a80 | 0xcb |
KERNEL32.dll (53)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
AddAtomA | 0x0 | 0x48a2e8 | 0x8a088 | 0x85a88 | 0x3 |
CloseHandle | 0x0 | 0x48a2ec | 0x8a08c | 0x85a8c | 0x45 |
CopyFileW | 0x0 | 0x48a2f0 | 0x8a090 | 0x85a90 | 0x69 |
CreateFileW | 0x0 | 0x48a2f4 | 0x8a094 | 0x85a94 | 0x83 |
CreateMutexA | 0x0 | 0x48a2f8 | 0x8a098 | 0x85a98 | 0x8f |
CreateSemaphoreA | 0x0 | 0x48a2fc | 0x8a09c | 0x85a9c | 0x9d |
DeleteCriticalSection | 0x0 | 0x48a300 | 0x8a0a0 | 0x85aa0 | 0xc4 |
DeleteFileW | 0x0 | 0x48a304 | 0x8a0a4 | 0x85aa4 | 0xc9 |
EnterCriticalSection | 0x0 | 0x48a308 | 0x8a0a8 | 0x85aa8 | 0xdf |
FindAtomA | 0x0 | 0x48a30c | 0x8a0ac | 0x85aac | 0x11e |
FindClose | 0x0 | 0x48a310 | 0x8a0b0 | 0x85ab0 | 0x120 |
FindFirstFileW | 0x0 | 0x48a314 | 0x8a0b4 | 0x85ab4 | 0x12b |
FindNextFileW | 0x0 | 0x48a318 | 0x8a0b8 | 0x85ab8 | 0x137 |
FreeLibrary | 0x0 | 0x48a31c | 0x8a0bc | 0x85abc | 0x153 |
GetAtomNameA | 0x0 | 0x48a320 | 0x8a0c0 | 0x85ac0 | 0x15d |
GetCurrentDirectoryW | 0x0 | 0x48a324 | 0x8a0c4 | 0x85ac4 | 0x1b0 |
GetCurrentProcess | 0x0 | 0x48a328 | 0x8a0c8 | 0x85ac8 | 0x1b1 |
GetCurrentProcessId | 0x0 | 0x48a32c | 0x8a0cc | 0x85acc | 0x1b2 |
GetCurrentThreadId | 0x0 | 0x48a330 | 0x8a0d0 | 0x85ad0 | 0x1b5 |
GetFileSize | 0x0 | 0x48a334 | 0x8a0d4 | 0x85ad4 | 0x1dc |
GetLastError | 0x0 | 0x48a338 | 0x8a0d8 | 0x85ad8 | 0x1ee |
GetModuleHandleA | 0x0 | 0x48a33c | 0x8a0dc | 0x85adc | 0x1fe |
GetProcAddress | 0x0 | 0x48a340 | 0x8a0e0 | 0x85ae0 | 0x229 |
GetStartupInfoA | 0x0 | 0x48a344 | 0x8a0e4 | 0x85ae4 | 0x244 |
GetSystemTimeAsFileTime | 0x0 | 0x48a348 | 0x8a0e8 | 0x85ae8 | 0x25b |
GetTickCount | 0x0 | 0x48a34c | 0x8a0ec | 0x85aec | 0x273 |
InitializeCriticalSection | 0x0 | 0x48a350 | 0x8a0f0 | 0x85af0 | 0x2c6 |
IsDBCSLeadByteEx | 0x0 | 0x48a354 | 0x8a0f4 | 0x85af4 | 0x2e2 |
IsDebuggerPresent | 0x0 | 0x48a358 | 0x8a0f8 | 0x85af8 | 0x2e3 |
LeaveCriticalSection | 0x0 | 0x48a35c | 0x8a0fc | 0x85afc | 0x301 |
LoadLibraryA | 0x0 | 0x48a360 | 0x8a100 | 0x85b00 | 0x303 |
LoadLibraryW | 0x0 | 0x48a364 | 0x8a104 | 0x85b04 | 0x306 |
MultiByteToWideChar | 0x0 | 0x48a368 | 0x8a108 | 0x85b08 | 0x32d |
QueryPerformanceCounter | 0x0 | 0x48a36c | 0x8a10c | 0x85b0c | 0x367 |
ReadFile | 0x0 | 0x48a370 | 0x8a110 | 0x85b10 | 0x37d |
ReleaseMutex | 0x0 | 0x48a374 | 0x8a114 | 0x85b14 | 0x38d |
ReleaseSemaphore | 0x0 | 0x48a378 | 0x8a118 | 0x85b18 | 0x391 |
SetLastError | 0x0 | 0x48a37c | 0x8a11c | 0x85b1c | 0x405 |
SetUnhandledExceptionFilter | 0x0 | 0x48a380 | 0x8a120 | 0x85b20 | 0x431 |
Sleep | 0x0 | 0x48a384 | 0x8a124 | 0x85b24 | 0x43d |
TerminateProcess | 0x0 | 0x48a388 | 0x8a128 | 0x85b28 | 0x449 |
TlsAlloc | 0x0 | 0x48a38c | 0x8a12c | 0x85b2c | 0x44e |
TlsFree | 0x0 | 0x48a390 | 0x8a130 | 0x85b30 | 0x44f |
TlsGetValue | 0x0 | 0x48a394 | 0x8a134 | 0x85b34 | 0x450 |
TlsSetValue | 0x0 | 0x48a398 | 0x8a138 | 0x85b38 | 0x451 |
UnhandledExceptionFilter | 0x0 | 0x48a39c | 0x8a13c | 0x85b3c | 0x45d |
VirtualProtect | 0x0 | 0x48a3a0 | 0x8a140 | 0x85b40 | 0x47d |
VirtualQuery | 0x0 | 0x48a3a4 | 0x8a144 | 0x85b44 | 0x480 |
WaitForSingleObject | 0x0 | 0x48a3a8 | 0x8a148 | 0x85b48 | 0x489 |
WideCharToMultiByte | 0x0 | 0x48a3ac | 0x8a14c | 0x85b4c | 0x49f |
WriteFile | 0x0 | 0x48a3b0 | 0x8a150 | 0x85b50 | 0x4b2 |
lstrcmpW | 0x0 | 0x48a3b4 | 0x8a154 | 0x85b54 | 0x4d1 |
lstrlenW | 0x0 | 0x48a3b8 | 0x8a158 | 0x85b58 | 0x4dd |
msvcrt.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_fdopen | 0x0 | 0x48a3c0 | 0x8a160 | 0x85b60 | 0x16 |
_fileno | 0x0 | 0x48a3c4 | 0x8a164 | 0x85b64 | 0x1a |
_read | 0x0 | 0x48a3c8 | 0x8a168 | 0x85b68 | 0x3c |
_write | 0x0 | 0x48a3cc | 0x8a16c | 0x85b6c | 0x68 |
msvcrt.dll (83)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
__dllonexit | 0x0 | 0x48a3d4 | 0x8a174 | 0x85b74 | 0x38 |
__doserrno | 0x0 | 0x48a3d8 | 0x8a178 | 0x85b78 | 0x39 |
__getmainargs | 0x0 | 0x48a3dc | 0x8a17c | 0x85b7c | 0x3b |
__initenv | 0x0 | 0x48a3e0 | 0x8a180 | 0x85b80 | 0x3c |
__lconv_init | 0x0 | 0x48a3e4 | 0x8a184 | 0x85b84 | 0x45 |
__mb_cur_max | 0x0 | 0x48a3e8 | 0x8a188 | 0x85b88 | 0x46 |
__pioinfo | 0x0 | 0x48a3ec | 0x8a18c | 0x85b8c | 0x65 |
__set_app_type | 0x0 | 0x48a3f0 | 0x8a190 | 0x85b90 | 0x69 |
__setusermatherr | 0x0 | 0x48a3f4 | 0x8a194 | 0x85b94 | 0x6c |
_acmdln | 0x0 | 0x48a3f8 | 0x8a198 | 0x85b98 | 0x7a |
_amsg_exit | 0x0 | 0x48a3fc | 0x8a19c | 0x85b9c | 0x8f |
_cexit | 0x0 | 0x48a400 | 0x8a1a0 | 0x85ba0 | 0xa0 |
_errno | 0x0 | 0x48a404 | 0x8a1a4 | 0x85ba4 | 0xda |
_filelengthi64 | 0x0 | 0x48a408 | 0x8a1a8 | 0x85ba8 | 0xf0 |
_fileno | 0x0 | 0x48a40c | 0x8a1ac | 0x85bac | 0xf1 |
_fmode | 0x0 | 0x48a410 | 0x8a1b0 | 0x85bb0 | 0xfc |
_fstat64 | 0x0 | 0x48a414 | 0x8a1b4 | 0x85bb4 | 0x108 |
_initterm | 0x0 | 0x48a418 | 0x8a1b8 | 0x85bb8 | 0x13d |
_iob | 0x0 | 0x48a41c | 0x8a1bc | 0x85bbc | 0x141 |
_lock | 0x0 | 0x48a420 | 0x8a1c0 | 0x85bc0 | 0x1a5 |
_lseeki64 | 0x0 | 0x48a424 | 0x8a1c4 | 0x85bc4 | 0x1ad |
_onexit | 0x0 | 0x48a428 | 0x8a1c8 | 0x85bc8 | 0x247 |
_strnicmp | 0x0 | 0x48a42c | 0x8a1cc | 0x85bcc | 0x2bc |
_unlock | 0x0 | 0x48a430 | 0x8a1d0 | 0x85bd0 | 0x2f6 |
_vsnprintf | 0x0 | 0x48a434 | 0x8a1d4 | 0x85bd4 | 0x317 |
_wgetenv | 0x0 | 0x48a438 | 0x8a1d8 | 0x85bd8 | 0x37a |
_winmajor | 0x0 | 0x48a43c | 0x8a1dc | 0x85bdc | 0x37c |
_write | 0x0 | 0x48a440 | 0x8a1e0 | 0x85be0 | 0x392 |
abort | 0x0 | 0x48a444 | 0x8a1e4 | 0x85be4 | 0x3be |
atoi | 0x0 | 0x48a448 | 0x8a1e8 | 0x85be8 | 0x3c8 |
calloc | 0x0 | 0x48a44c | 0x8a1ec | 0x85bec | 0x3cc |
exit | 0x0 | 0x48a450 | 0x8a1f0 | 0x85bf0 | 0x3d6 |
fclose | 0x0 | 0x48a454 | 0x8a1f4 | 0x85bf4 | 0x3d9 |
fflush | 0x0 | 0x48a458 | 0x8a1f8 | 0x85bf8 | 0x3dc |
fgetpos | 0x0 | 0x48a45c | 0x8a1fc | 0x85bfc | 0x3de |
fopen | 0x0 | 0x48a460 | 0x8a200 | 0x85c00 | 0x3e4 |
fprintf | 0x0 | 0x48a464 | 0x8a204 | 0x85c04 | 0x3e6 |
fputc | 0x0 | 0x48a468 | 0x8a208 | 0x85c08 | 0x3e8 |
fputs | 0x0 | 0x48a46c | 0x8a20c | 0x85c0c | 0x3e9 |
fread | 0x0 | 0x48a470 | 0x8a210 | 0x85c10 | 0x3ec |
free | 0x0 | 0x48a474 | 0x8a214 | 0x85c14 | 0x3ed |
fsetpos | 0x0 | 0x48a478 | 0x8a218 | 0x85c18 | 0x3f4 |
fwrite | 0x0 | 0x48a47c | 0x8a21c | 0x85c1c | 0x3f8 |
getc | 0x0 | 0x48a480 | 0x8a220 | 0x85c20 | 0x3fb |
getenv | 0x0 | 0x48a484 | 0x8a224 | 0x85c24 | 0x3fd |
getwc | 0x0 | 0x48a488 | 0x8a228 | 0x85c28 | 0x400 |
isspace | 0x0 | 0x48a48c | 0x8a22c | 0x85c2c | 0x40d |
iswctype | 0x0 | 0x48a490 | 0x8a230 | 0x85c30 | 0x413 |
localeconv | 0x0 | 0x48a494 | 0x8a234 | 0x85c34 | 0x420 |
malloc | 0x0 | 0x48a498 | 0x8a238 | 0x85c38 | 0x425 |
memchr | 0x0 | 0x48a49c | 0x8a23c | 0x85c3c | 0x42b |
memcpy | 0x0 | 0x48a4a0 | 0x8a240 | 0x85c40 | 0x42d |
memmove | 0x0 | 0x48a4a4 | 0x8a244 | 0x85c44 | 0x42f |
memset | 0x0 | 0x48a4a8 | 0x8a248 | 0x85c48 | 0x431 |
putc | 0x0 | 0x48a4ac | 0x8a24c | 0x85c4c | 0x437 |
putwc | 0x0 | 0x48a4b0 | 0x8a250 | 0x85c50 | 0x43a |
realloc | 0x0 | 0x48a4b4 | 0x8a254 | 0x85c54 | 0x441 |
setlocale | 0x0 | 0x48a4b8 | 0x8a258 | 0x85c58 | 0x448 |
setvbuf | 0x0 | 0x48a4bc | 0x8a25c | 0x85c5c | 0x449 |
signal | 0x0 | 0x48a4c0 | 0x8a260 | 0x85c60 | 0x44a |
sprintf | 0x0 | 0x48a4c4 | 0x8a264 | 0x85c64 | 0x44d |
strcat | 0x0 | 0x48a4c8 | 0x8a268 | 0x85c68 | 0x453 |
strchr | 0x0 | 0x48a4cc | 0x8a26c | 0x85c6c | 0x455 |
strcmp | 0x0 | 0x48a4d0 | 0x8a270 | 0x85c70 | 0x456 |
strcoll | 0x0 | 0x48a4d4 | 0x8a274 | 0x85c74 | 0x457 |
strcpy | 0x0 | 0x48a4d8 | 0x8a278 | 0x85c78 | 0x458 |
strerror | 0x0 | 0x48a4dc | 0x8a27c | 0x85c7c | 0x45b |
strftime | 0x0 | 0x48a4e0 | 0x8a280 | 0x85c80 | 0x45d |
strlen | 0x0 | 0x48a4e4 | 0x8a284 | 0x85c84 | 0x45e |
strncmp | 0x0 | 0x48a4e8 | 0x8a288 | 0x85c88 | 0x461 |
strxfrm | 0x0 | 0x48a4ec | 0x8a28c | 0x85c8c | 0x46e |
system | 0x0 | 0x48a4f0 | 0x8a290 | 0x85c90 | 0x473 |
towlower | 0x0 | 0x48a4f4 | 0x8a294 | 0x85c94 | 0x47d |
towupper | 0x0 | 0x48a4f8 | 0x8a298 | 0x85c98 | 0x47e |
ungetc | 0x0 | 0x48a4fc | 0x8a29c | 0x85c9c | 0x47f |
ungetwc | 0x0 | 0x48a500 | 0x8a2a0 | 0x85ca0 | 0x480 |
vfprintf | 0x0 | 0x48a504 | 0x8a2a4 | 0x85ca4 | 0x481 |
wcscmp | 0x0 | 0x48a508 | 0x8a2a8 | 0x85ca8 | 0x491 |
wcscoll | 0x0 | 0x48a50c | 0x8a2ac | 0x85cac | 0x492 |
wcscpy | 0x0 | 0x48a510 | 0x8a2b0 | 0x85cb0 | 0x493 |
wcsftime | 0x0 | 0x48a514 | 0x8a2b4 | 0x85cb4 | 0x496 |
wcslen | 0x0 | 0x48a518 | 0x8a2b8 | 0x85cb8 | 0x497 |
wcsxfrm | 0x0 | 0x48a51c | 0x8a2bc | 0x85cbc | 0x4aa |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
svchost .exe | 3 | 0x00400000 | 0x0085DFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
svchost .exe | 3 | 0x00400000 | 0x0085DFFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.32127402 |
Malicious
|
C:\\588bce7c90097ed212\DHtmlHeader.html.ch4x0 | Dropped File | Text |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\header.bmp.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\SplashScreen.bmp.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1029\eula.rtf.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1030\eula.rtf.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1031\eula.rtf.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1037\eula.rtf.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1038\eula.rtf.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1042\eula.rtf.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1044\eula.rtf.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1045\eula.rtf.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1046\eula.rtf.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1049\eula.rtf.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1053\eula.rtf.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1055\eula.rtf.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\2070\eula.rtf.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\3082\eula.rtf.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\2yl2D.jpg.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\30Mc DMJl7nJeeX.png.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\8feX lm3NMkC1.pptx.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\cXHS0XVI.mp3.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\DB7SVGOmJWkFO.mp3.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\F0T_qKtx4.wav.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\jbqb.avi.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\kxfhx5V664.doc.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\MmYokEmRcYJ.png.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\mqwq.pptx.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\QikSkb7g.bmp.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\sU9-HY4ux.jpg.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\x9JAvccGk.mp3.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\yDKyqzypE.mp4.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\6yNY_ug\AT7juf3 qRgd.flv.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\6yNY_ug\RSIcX_Y0W6_I0qJ.bmp.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\6yNY_ug\V4fQ_dlgWJr-zrpYk_z.avi.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\94u3KnILxI40rD_De9FJ.docx.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\DJBYwDQ8aNwW.pptx.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\eKu5MJfOuiObNmnhj3.doc.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\H-HbRhrw8Lx _r.xlsx.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\hLapSGUG20Vwu.xlsx.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\J-Br JD99atjDlY.odt.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\LqBEcTY.xlsx.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\mthUrjDiv8e.xlsx.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\Nwtr19oWW72lChkU.pptx.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\OaX_ybEfUiRenWUP9.odp.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\rV98wfYL9r89BoQQg.xlsx.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\t1-0_mMPFcyOce6.pptx.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\2wUnbqg2S8\PTtANAZzO0.csv.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\2wUnbqg2S8\tBFGLCUy70u3zz.csv.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\2wUnbqg2S8\vITwu3q-QI.doc.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\Outlook Files\kkcie@kdj.kd.pst.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\q_iuFLA6D3NMerXQD2O\hD19.doc.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\q_iuFLA6D3NMerXQD2O\2_OtWxW85zHSDtq95tl\1oOs1IYrL6FEBmbSgR7.pdf.ch4x0 | Dropped File |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\q_iuFLA6D3NMerXQD2O\2_OtWxW85zHSDtq95tl\Yh3ofWzIAEkvC8B9wcoe.pptx.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\q_iuFLA6D3NMerXQD2O\75aoRo_JhUow\jp3IwT2eeqFfyJXXVy2\P0uh_TPl-yn\Jn3gSn.ppt.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\q_iuFLA6D3NMerXQD2O\FQCQHP\b bwd9k.odt.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\q_iuFLA6D3NMerXQD2O\L980QzW9fizhEEr\3exSwEhZrtqz9uNox.doc.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\q_iuFLA6D3NMerXQD2O\L980QzW9fizhEEr\b7yb7HbFabQa1E2BJHW.pdf.ch4x0 | Dropped File |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\q_iuFLA6D3NMerXQD2O\L980QzW9fizhEEr\wAudWC7s.pptx.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\q_iuFLA6D3NMerXQD2O\L980QzW9fizhEEr\sbIk86s\9A_jvCELgzmWz-Uel.ods.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\q_iuFLA6D3NMerXQD2O\L980QzW9fizhEEr\sbIk86s\tW7uZjy4MgrEP8.xlsx.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\q_iuFLA6D3NMerXQD2O\L980QzW9fizhEEr\sbIk86s\x5YqhGwKaGy_T875gci.odp.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\5qA9vop4 An.m4a.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\hzljuwM0b_56EStPz.m4a.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\VZk6c1S4WssYkc.m4a.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\ZBQplhKd0q0Az0h.wav.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\HawHtnhaU.m4a.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\Ljg3V.wav.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\MDADJtH-.m4a.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\uHC1JO8WzKZ9R.mp3.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\EodBRfGb4L7-hgf\uxU4XWxNONg.mp3.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\EodBRfGb4L7-hgf\wQzX.wav.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\EodBRfGb4L7-hgf\zLbA5W_Z_Ov.mp3.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\F7gf-\9M60zi.mp3.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\F7gf-\opwtLkxW-5WGKl.m4a.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\F7gf-\OzuZtzPO.mp3.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\qBI5h8N7PTmwQn8GJ7WA\1B00W_x_7wl4.mp3.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\qBI5h8N7PTmwQn8GJ7WA\iqLOUXtQuD40 Y.wav.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\qBI5h8N7PTmwQn8GJ7WA\__AdBBRqj WXhzjtqktp.wav.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\V26Q89\f0yrUmzX63uitcF.mp3.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\V26Q89\JHOrRiYn.m4a.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\V26Q89\S-sj.m4a.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\Zc8Y\koK2rjZRMOBDu2m.wav.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\Zc8Y\XbLhzsg7WdeOkUH.wav.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\Zc8Y\7jr0lVxJU3WD\QII9BbbAu4ivCyz-M\H8fiT3wbr063XD8lUDdW.m4a.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\Zc8Y\7jr0lVxJU3WD\QII9BbbAu4ivCyz-M\O3YpXzvilFAr.m4a.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\Zc8Y\7jr0lVxJU3WD\QII9BbbAu4ivCyz-M\pVjEx6Hqaso-gSFpt8Q.mp3.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Pictures\2cx-lwZ0F12zNqaR.bmp.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Pictures\3BsW.bmp.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Pictures\dqJV.gif.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Pictures\G4lQTNZL5V9a.gif.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Pictures\HFoTn.gif.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Pictures\hZ gFm.jpg.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Pictures\jHqXLgbnTW5oKBa-Evd.jpg.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Pictures\jWwYNsDwAEp3Q.png.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Pictures\L9xWNUI mom mKlP b-7.bmp.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Pictures\N- I3cPr.png.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Pictures\Ncb14E25FL8K8.jpg.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Pictures\ndV4txWDroXPS5dMlC.png.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Pictures\On95XMBbL4KR1.bmp.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Pictures\RLqRayeZihM1myYUn5a6.gif.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Pictures\voA K.png.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Pictures\WpO0PCf3tF-0UZ.bmp.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Pictures\_z6 4.png.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Videos\g9W4Le\BsTn3W4x95EZNq8l.mp4.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Videos\g9W4Le\Dh-0Gz7ZY.flv.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Videos\g9W4Le\wQHR0MmS.avi.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Videos\GdOxNv0sZKn\F0s4VR4jaiSxUsjT\7MdtJ.avi.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Videos\GdOxNv0sZKn\F0s4VR4jaiSxUsjT\NSPauty1pChs9qmDoa.flv.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Videos\GdOxNv0sZKn\F0s4VR4jaiSxUsjT\hc1cETuDJlhvcVErLc\zJN6tm3pAEA.mp4.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Videos\GdOxNv0sZKn\Io8nCvBd\2R9uJmm.flv.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Videos\GdOxNv0sZKn\Io8nCvBd\_AvJXhc.avi.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Videos\PaAGsz4bWU6f\-lU0t7jOBXRDuk-f8 EX.flv.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Videos\PaAGsz4bWU6f\ZchWCnDxc.flv.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\hwcompatShared.txt.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\amd64\hwexclude.txt.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\i386\hwcompat.txt.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\block.png.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\default.htm.ch4x0 | Dropped File | Text |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\default_eos.css.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\default_eos.htm.ch4x0 | Dropped File | Text |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\default_oobe.htm.ch4x0 | Dropped File | Text |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\eula.css.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\GetStarted.png.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\GetStartedHoverOver.png.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\loading.gif.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\lock.png.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\logo.png.ch4x0 | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\EULA\EULA_ar-sa.htm.ch4x0 | Dropped File | Text |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\EULA\EULA_bg-bg.htm.ch4x0 | Dropped File | Text |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\EULA\EULA_cs-cz.htm.ch4x0 | Dropped File | Text |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\EULA\EULA_da-dk.htm.ch4x0 | Dropped File | Text |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\EULA\EULA_de-de.htm.ch4x0 | Dropped File | Text |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\EULA\EULA_el-gr.htm.ch4x0 | Dropped File | Text |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\EULA\EULA_en-gb.htm.ch4x0 | Dropped File | Text |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\EULA\EULA_es-es.htm.ch4x0 | Dropped File | Text |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\EULA\EULA_et-ee.htm.ch4x0 | Dropped File | Text |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\EULA\EULA_fi-fi.htm.ch4x0 | Dropped File | Text |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\EULA\EULA_fr-ca.htm.ch4x0 | Dropped File | Text |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\EULA\EULA_he-il.htm.ch4x0 | Dropped File | Text |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\EULA\EULA_hr-hr.htm.ch4x0 | Dropped File | Text |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\EULA\EULA_hu-hu.htm.ch4x0 | Dropped File | Text |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\EULA\EULA_it-it.htm.ch4x0 | Dropped File | Text |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\EULA\EULA_ja-jp.htm.ch4x0 | Dropped File | Text |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\EULA\EULA_ko-kr.htm.ch4x0 | Dropped File | Text |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\EULA\EULA_lt-lt.htm.ch4x0 | Dropped File | Text |
Unknown
|
...
|
»
C:\\Windows10Upgrade\resources\ux\EULA\EULA_lv-lv.htm.ch4x0 | Dropped File | Text |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\watermark.bmp.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1025\eula.rtf.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1032\eula.rtf.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1033\eula.rtf.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1035\eula.rtf.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1036\eula.rtf.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1040\eula.rtf.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1041\eula.rtf.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1043\eula.rtf.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\2052\eula.rtf.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1028\eula.rtf.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\0C2E42di.m4a.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\1PA8b.gif.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\B81-uUv-lh3m3Bh.mp4.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\fjI57alJsr ZEYQ.jpg.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\g35bORH9mFwe6v0wa.pptx.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\gbWireWsdXQG1kQ1bE.wav.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\gf_Lu9Pd s7.xls.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\H11vUJLE.docx.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\inYQu-0cAlcHEAqZlcdw.flv.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\iu8kVqZD1q0_iC6.avi.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\oeT5FQAvjHLK9SixiTC.mp3.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\OWDi.png.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\stF6lD9NYvzZ7bhDBvft.m4a.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\tK5XUlBJIo8f3HbA-Qv.avi.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\W2q3Ml7wsjvdhC.wav.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\WlGQ1Su-99HMmFRs.pptx.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\YCa9.xls.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\ZjLFdEqQ jNZ.ppt.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\6yNY_ug\23OjMM-UDhK0.docx.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\6yNY_ug\6ZwVHXD9.avi.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\6yNY_ug\J-66.wav.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\6yNY_ug\v6C9yQsvKzpETmC3_uL.bmp.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\6yNY_ug\ZD9OyIiK_HSNbXA.mp3.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Documents\0kGPmiyPtUY2n.pptx.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Documents\5bIvFkOxcuwW.docx.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Documents\CODii2haKeIIkzw89m.pptx.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Documents\Database1.accdb.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Documents\GqX0jqP-w9ZLy.docx.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Documents\htyVQh74c_fSRyTb9tWM.odp.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Documents\Y1PG2K.pptx.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Documents\YvlL_pOaGso7Z.docx.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Documents\ZDiyWYvwlk.docx.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Documents\2wUnbqg2S8\2rmqFSk3U.xlsx.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Documents\q_iuFLA6D3NMerXQD2O\srT-feO3M0zE.odp.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Documents\q_iuFLA6D3NMerXQD2O\x_i_p P6L0aRHnZlT-E.xlsx.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Documents\q_iuFLA6D3NMerXQD2O\2_OtWxW85zHSDtq95tl\20yCu.ppt.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Documents\q_iuFLA6D3NMerXQD2O\2_OtWxW85zHSDtq95tl\5LG1QMrXAYbASh 7a.odt.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Documents\q_iuFLA6D3NMerXQD2O\2_OtWxW85zHSDtq95tl\nvlDCfIPznk.pptx.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Documents\q_iuFLA6D3NMerXQD2O\75aoRo_JhUow\VjvWCC-7AET31cU.csv.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Documents\q_iuFLA6D3NMerXQD2O\L980QzW9fizhEEr\6_Y0KF.docx.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Documents\q_iuFLA6D3NMerXQD2O\L980QzW9fizhEEr\gRVX_ApB33NCbmVv.xlsx.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Documents\q_iuFLA6D3NMerXQD2O\L980QzW9fizhEEr\ncPacmc.xls.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Music\SM9yBDWGNbMhdP6oGru.mp3.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\mMDF5WmTaGmY7hmJY4b.wav.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\EodBRfGb4L7-hgf\_DMgPgPh37eH.mp3.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\F7gf-\5zSYmedrc7XyMOcpr.m4a.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\F7gf-\A OmlmPwdvhry0F6ltzA.wav.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\F7gf-\soj_tpyWaDRHC0.wav.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\F7gf-\Zaf7bV2.m4a.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\V26Q89\npO1Oq9YLVFj.wav.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\V26Q89\ZmZg-csHiiChtxw4ni.wav.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\Zc8Y\7jr0lVxJU3WD\-aUxWsyPc_g54WIP.mp3.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\Zc8Y\7jr0lVxJU3WD\a1z_Jq7KA20p7GJnfy.wav.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\Zc8Y\7jr0lVxJU3WD\mVawsZq\wRIRBd8T9SA7d.wav.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Music\bywZN LZbW\Zc8Y\7jr0lVxJU3WD\QII9BbbAu4ivCyz-M\iIzv6pooxHiWi1.wav.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Pictures\AIX608y4xaWT xvuXZd.jpg.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Pictures\aT1vItu3oznAjz2qR.gif.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Pictures\cUfmIVg7KhMJ8.png.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Pictures\eH9X4EI0t71sz7Lt1y02.bmp.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Pictures\EQ 2foN_4CEjuw3GIxWv.jpg.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Pictures\g0S TLTn4ioDU3rM.png.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Pictures\guqVybHpC7dhO P5ht.gif.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Pictures\inEKci2.bmp.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Pictures\JEf-cT3Bi_pogSn9op.png.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Pictures\JW9uOA2jroybFkWO.png.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Pictures\Jy2cBjSX Zkiu.png.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Pictures\jZQDUGxCS.gif.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Pictures\K-xAZUJFNk.png.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Pictures\mmqZlST4k7MA-8Ff-.jpg.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Pictures\N1ihTDM.png.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Pictures\n2uEDbz0P9Q7Gj.gif.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Pictures\sowqP0pG.bmp.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Pictures\VWv8T4yh.bmp.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Pictures\Wap6eIEFPVUgmwKb.bmp.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Pictures\Ws_ZaXd.gif.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Pictures\zC9V-J.bmp.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Videos\fBN3ST.mp4.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Videos\GdOxNv0sZKn\2DKZ.mp4.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Videos\GdOxNv0sZKn\F0s4VR4jaiSxUsjT\yHgz5iVwI-.mp4.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Videos\GdOxNv0sZKn\F0s4VR4jaiSxUsjT\hc1cETuDJlhvcVErLc\7lhMdesnG3PFyH1-E1.avi.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Videos\GdOxNv0sZKn\Io8nCvBd\5X9AUW.avi.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Videos\GdOxNv0sZKn\Io8nCvBd\MSs7zYZdpb1QeLe.flv.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Windows10Upgrade\resources\amd64\hwcompat.txt.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Windows10Upgrade\resources\i386\hwexclude.txt.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Windows10Upgrade\resources\ux\bluelogo.png.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Windows10Upgrade\resources\ux\bullet.png.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Windows10Upgrade\resources\ux\default.css.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Windows10Upgrade\resources\ux\default_oobe.css.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Windows10Upgrade\resources\ux\marketing.png.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Windows10Upgrade\resources\ux\NoNetworkConnection.png.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Windows10Upgrade\resources\ux\NoNetworkConnectionHoverOver.png.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Windows10Upgrade\resources\ux\pass.png.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Boot\updaterevokesipolicy.p7b.ch4x0 | Dropped File | Stream |
Not Queried
|
...
|
»