Dynamic Analysis Report |
Classification: Ransomware, Downloader, Trojan |
LS_APPDATA744de46e-2913-4f69-a0ea-d12dff2a5c90SAMPLE.exe
Created at 2019-07-19T06:56:00
Remarks (2/3)
(0x200000e): The overall sleep time of all monitored processes was truncated from "40 seconds" to "10 seconds" to reveal dormant functionality.
(0x200003a): 2 tasks were rescheduled ahead of time to reveal dormant functionality.
Remarks
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\LS_APPDATA744de46e-2913-4f69-a0ea-d12dff2a5c90SAMPLE.exe | Sample File | Binary |
Malicious
|
...
|
Severity |
Blacklisted
|
First Seen | 2019-07-18 19:49 (UTC+2) |
Last Seen | 2019-07-19 02:27 (UTC+2) |
Names | Win32.Trojan.Genkryptik |
Families | Genkryptik |
Classification | Trojan |
Image Base | 0x400000 |
Entry Point | 0x404bad |
Size Of Code | 0xee00 |
Size Of Initialized Data | 0x854200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-04-24 05:57:42+00:00 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xec5f | 0xee00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.65 |
.rdata | 0x410000 | 0x6a18 | 0x6c00 | 0xf200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.71 |
.data | 0x417000 | 0x803840 | 0x1400 | 0x15e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.73 |
.text | 0xc1b000 | 0x458d8 | 0x44c00 | 0x17200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.0 |
.rsrc | 0xc61000 | 0x3b08 | 0x3c00 | 0x5be00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.1 |
.reloc | 0xc65000 | 0x1248 | 0x1400 | 0x5fa00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.28 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FormatMessageW | 0x0 | 0x41002c | 0x16198 | 0x15398 | 0x15e |
CreateMailslotA | 0x0 | 0x410030 | 0x1619c | 0x1539c | 0x98 |
lstrlenA | 0x0 | 0x410034 | 0x161a0 | 0x153a0 | 0x54d |
GetCurrentDirectoryA | 0x0 | 0x410038 | 0x161a4 | 0x153a4 | 0x1be |
CreateFileW | 0x0 | 0x41003c | 0x161a8 | 0x153a8 | 0x8f |
GetNumberFormatW | 0x0 | 0x410040 | 0x161ac | 0x153ac | 0x233 |
PeekConsoleInputW | 0x0 | 0x410044 | 0x161b0 | 0x153b0 | 0x38c |
GetTickCount | 0x0 | 0x410048 | 0x161b4 | 0x153b4 | 0x293 |
WriteConsoleW | 0x0 | 0x41004c | 0x161b8 | 0x153b8 | 0x524 |
SetFilePointerEx | 0x0 | 0x410050 | 0x161bc | 0x153bc | 0x467 |
FlushFileBuffers | 0x0 | 0x410054 | 0x161c0 | 0x153c0 | 0x157 |
SetStdHandle | 0x0 | 0x410058 | 0x161c4 | 0x153c4 | 0x487 |
HeapReAlloc | 0x0 | 0x41005c | 0x161c8 | 0x153c8 | 0x2d2 |
GetCPInfo | 0x0 | 0x410060 | 0x161cc | 0x153cc | 0x172 |
GetOEMCP | 0x0 | 0x410064 | 0x161d0 | 0x153d0 | 0x237 |
GetACP | 0x0 | 0x410068 | 0x161d4 | 0x153d4 | 0x168 |
IsValidCodePage | 0x0 | 0x41006c | 0x161d8 | 0x153d8 | 0x30a |
GetHandleInformation | 0x0 | 0x410070 | 0x161dc | 0x153dc | 0x1ff |
CloseHandle | 0x0 | 0x410074 | 0x161e0 | 0x153e0 | 0x52 |
LockFile | 0x0 | 0x410078 | 0x161e4 | 0x153e4 | 0x352 |
TerminateProcess | 0x0 | 0x41007c | 0x161e8 | 0x153e8 | 0x4c0 |
ExitProcess | 0x0 | 0x410080 | 0x161ec | 0x153ec | 0x119 |
VirtualProtect | 0x0 | 0x410084 | 0x161f0 | 0x153f0 | 0x4ef |
GetBinaryTypeA | 0x0 | 0x410088 | 0x161f4 | 0x153f4 | 0x170 |
GlobalMemoryStatus | 0x0 | 0x41008c | 0x161f8 | 0x153f8 | 0x2bf |
GlobalAlloc | 0x0 | 0x410090 | 0x161fc | 0x153fc | 0x2b3 |
OutputDebugStringW | 0x0 | 0x410094 | 0x16200 | 0x15400 | 0x38a |
GetProcAddress | 0x0 | 0x410098 | 0x16204 | 0x15404 | 0x245 |
LoadLibraryExW | 0x0 | 0x41009c | 0x16208 | 0x15408 | 0x33e |
EncodePointer | 0x0 | 0x4100a0 | 0x1620c | 0x1540c | 0xea |
DecodePointer | 0x0 | 0x4100a4 | 0x16210 | 0x15410 | 0xca |
RaiseException | 0x0 | 0x4100a8 | 0x16214 | 0x15414 | 0x3b1 |
RtlUnwind | 0x0 | 0x4100ac | 0x16218 | 0x15418 | 0x418 |
GetCommandLineW | 0x0 | 0x4100b0 | 0x1621c | 0x1541c | 0x187 |
IsProcessorFeaturePresent | 0x0 | 0x4100b4 | 0x16220 | 0x15420 | 0x304 |
GetLastError | 0x0 | 0x4100b8 | 0x16224 | 0x15424 | 0x202 |
HeapAlloc | 0x0 | 0x4100bc | 0x16228 | 0x15428 | 0x2cb |
HeapFree | 0x0 | 0x4100c0 | 0x1622c | 0x1542c | 0x2cf |
GetModuleHandleExW | 0x0 | 0x4100c4 | 0x16230 | 0x15430 | 0x217 |
MultiByteToWideChar | 0x0 | 0x4100c8 | 0x16234 | 0x15434 | 0x367 |
WideCharToMultiByte | 0x0 | 0x4100cc | 0x16238 | 0x15438 | 0x511 |
HeapSize | 0x0 | 0x4100d0 | 0x1623c | 0x1543c | 0x2d4 |
IsDebuggerPresent | 0x0 | 0x4100d4 | 0x16240 | 0x15440 | 0x300 |
EnterCriticalSection | 0x0 | 0x4100d8 | 0x16244 | 0x15444 | 0xee |
LeaveCriticalSection | 0x0 | 0x4100dc | 0x16248 | 0x15448 | 0x339 |
WriteFile | 0x0 | 0x4100e0 | 0x1624c | 0x1544c | 0x525 |
GetConsoleCP | 0x0 | 0x4100e4 | 0x16250 | 0x15450 | 0x19a |
GetConsoleMode | 0x0 | 0x4100e8 | 0x16254 | 0x15454 | 0x1ac |
SetLastError | 0x0 | 0x4100ec | 0x16258 | 0x15458 | 0x473 |
GetCurrentThreadId | 0x0 | 0x4100f0 | 0x1625c | 0x1545c | 0x1c5 |
GetProcessHeap | 0x0 | 0x4100f4 | 0x16260 | 0x15460 | 0x24a |
GetStdHandle | 0x0 | 0x4100f8 | 0x16264 | 0x15464 | 0x264 |
GetFileType | 0x0 | 0x4100fc | 0x16268 | 0x15468 | 0x1f3 |
DeleteCriticalSection | 0x0 | 0x410100 | 0x1626c | 0x1546c | 0xd1 |
GetStartupInfoW | 0x0 | 0x410104 | 0x16270 | 0x15470 | 0x263 |
GetModuleFileNameW | 0x0 | 0x410108 | 0x16274 | 0x15474 | 0x214 |
QueryPerformanceCounter | 0x0 | 0x41010c | 0x16278 | 0x15478 | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x410110 | 0x1627c | 0x1547c | 0x1c1 |
GetSystemTimeAsFileTime | 0x0 | 0x410114 | 0x16280 | 0x15480 | 0x279 |
GetEnvironmentStringsW | 0x0 | 0x410118 | 0x16284 | 0x15484 | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x41011c | 0x16288 | 0x15488 | 0x161 |
UnhandledExceptionFilter | 0x0 | 0x410120 | 0x1628c | 0x1548c | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x410124 | 0x16290 | 0x15490 | 0x4a5 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x410128 | 0x16294 | 0x15494 | 0x2e3 |
Sleep | 0x0 | 0x41012c | 0x16298 | 0x15498 | 0x4b2 |
GetCurrentProcess | 0x0 | 0x410130 | 0x1629c | 0x1549c | 0x1c0 |
TlsAlloc | 0x0 | 0x410134 | 0x162a0 | 0x154a0 | 0x4c5 |
TlsGetValue | 0x0 | 0x410138 | 0x162a4 | 0x154a4 | 0x4c7 |
TlsSetValue | 0x0 | 0x41013c | 0x162a8 | 0x154a8 | 0x4c8 |
TlsFree | 0x0 | 0x410140 | 0x162ac | 0x154ac | 0x4c6 |
GetModuleHandleW | 0x0 | 0x410144 | 0x162b0 | 0x154b0 | 0x218 |
LCMapStringW | 0x0 | 0x410148 | 0x162b4 | 0x154b4 | 0x32d |
GetStringTypeW | 0x0 | 0x41014c | 0x162b8 | 0x154b8 | 0x269 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EnumPropsW | 0x0 | 0x41015c | 0x162c8 | 0x154c8 | 0xee |
SendMessageA | 0x0 | 0x410160 | 0x162cc | 0x154cc | 0x277 |
ChangeDisplaySettingsA | 0x0 | 0x410164 | 0x162d0 | 0x154d0 | 0x23 |
LoadStringW | 0x0 | 0x410168 | 0x162d4 | 0x154d4 | 0x1fa |
GetClassInfoW | 0x0 | 0x41016c | 0x162d8 | 0x154d8 | 0x10e |
GetClassNameA | 0x0 | 0x410170 | 0x162dc | 0x154dc | 0x111 |
DrawIcon | 0x0 | 0x410174 | 0x162e0 | 0x154e0 | 0xc7 |
OemToCharW | 0x0 | 0x410178 | 0x162e4 | 0x154e4 | 0x224 |
CreateDialogParamW | 0x0 | 0x41017c | 0x162e8 | 0x154e8 | 0x63 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PolyBezier | 0x0 | 0x410010 | 0x1617c | 0x1537c | 0x24e |
GetEnhMetaFileHeader | 0x0 | 0x410014 | 0x16180 | 0x15380 | 0x1d4 |
SetMapMode | 0x0 | 0x410018 | 0x16184 | 0x15384 | 0x294 |
GetOutlineTextMetricsA | 0x0 | 0x41001c | 0x16188 | 0x15388 | 0x1fe |
GetMetaFileW | 0x0 | 0x410020 | 0x1618c | 0x1538c | 0x1f3 |
PolylineTo | 0x0 | 0x410024 | 0x16190 | 0x15390 | 0x258 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetPrivateObjectSecurity | 0x0 | 0x410000 | 0x1616c | 0x1536c | 0x2b2 |
PrivilegedServiceAuditAlarmA | 0x0 | 0x410004 | 0x16170 | 0x15370 | 0x218 |
LockServiceDatabase | 0x0 | 0x410008 | 0x16174 | 0x15374 | 0x188 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WinHttpWriteData | 0x0 | 0x410184 | 0x162f0 | 0x154f0 | 0x1f |
WinHttpQueryDataAvailable | 0x0 | 0x410188 | 0x162f4 | 0x154f4 | 0x12 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
TransparentBlt | 0x0 | 0x410154 | 0x162c0 | 0x154c0 | 0x3 |
Api name | EAT Address | Ordinal |
---|---|---|
MyFunc165@@4 | 0x11d0 | 0x1 |
Threat Name | Severity |
---|---|
Trojan.Worm.GenericKDS.41479463 |
Malicious
|
C:\Windows\System32\drivers\etc\hosts | Modified File | Text |
Malicious
|
...
|
Threat Name | Severity |
---|---|
Gen:Trojan.Qhost.1 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\5f157674-79c2-4ded-9dab-75219d8fb8ff\updatewin1.exe | Downloaded File | Binary |
Malicious
|
...
|
Severity |
Blacklisted
|
First Seen | 2019-01-16 22:21 (UTC+1) |
Last Seen | 2019-07-02 07:29 (UTC+2) |
Names | Win32.Trojan.Kryptik |
Families | Kryptik |
Classification | Trojan |
Image Base | 0x400000 |
Entry Point | 0x402d76 |
Size Of Code | 0x1c200 |
Size Of Initialized Data | 0x2c200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-07-24 12:23:54+00:00 |
FileVersion | 7.7.7.18 |
InternalName | rawudiyeh.exe |
LegalCopyright | Copyright (C) 2018, sacuwedimufoy |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1c07e | 0x1c200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x41e000 | 0x463e | 0x4800 | 0x1c600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.26 |
.data | 0x423000 | 0x1c6a8 | 0x17400 | 0x20e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.83 |
.rsrc | 0x440000 | 0xa578 | 0xa600 | 0x38200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.88 |
.reloc | 0x44b000 | 0x1968 | 0x1a00 | 0x42800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.34 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitThread | 0x0 | 0x41e028 | 0x21afc | 0x200fc | 0x105 |
GetStartupInfoW | 0x0 | 0x41e02c | 0x21b00 | 0x20100 | 0x23a |
GetLastError | 0x0 | 0x41e030 | 0x21b04 | 0x20104 | 0x1e6 |
GetProcAddress | 0x0 | 0x41e034 | 0x21b08 | 0x20108 | 0x220 |
CreateJobSet | 0x0 | 0x41e038 | 0x21b0c | 0x2010c | 0x87 |
GlobalFree | 0x0 | 0x41e03c | 0x21b10 | 0x20110 | 0x28c |
LoadLibraryA | 0x0 | 0x41e040 | 0x21b14 | 0x20114 | 0x2f1 |
OpenWaitableTimerW | 0x0 | 0x41e044 | 0x21b18 | 0x20118 | 0x339 |
AddAtomA | 0x0 | 0x41e048 | 0x21b1c | 0x2011c | 0x3 |
FindFirstChangeNotificationA | 0x0 | 0x41e04c | 0x21b20 | 0x20120 | 0x11b |
VirtualProtect | 0x0 | 0x41e050 | 0x21b24 | 0x20124 | 0x45a |
GetCurrentDirectoryA | 0x0 | 0x41e054 | 0x21b28 | 0x20128 | 0x1a7 |
GetACP | 0x0 | 0x41e058 | 0x21b2c | 0x2012c | 0x152 |
InterlockedPushEntrySList | 0x0 | 0x41e05c | 0x21b30 | 0x20130 | 0x2c2 |
CompareStringW | 0x0 | 0x41e060 | 0x21b34 | 0x20134 | 0x55 |
CompareStringA | 0x0 | 0x41e064 | 0x21b38 | 0x20138 | 0x52 |
CreateFileA | 0x0 | 0x41e068 | 0x21b3c | 0x2013c | 0x78 |
GetTimeZoneInformation | 0x0 | 0x41e06c | 0x21b40 | 0x20140 | 0x26b |
WriteConsoleW | 0x0 | 0x41e070 | 0x21b44 | 0x20144 | 0x48c |
GetConsoleOutputCP | 0x0 | 0x41e074 | 0x21b48 | 0x20148 | 0x199 |
WriteConsoleA | 0x0 | 0x41e078 | 0x21b4c | 0x2014c | 0x482 |
CloseHandle | 0x0 | 0x41e07c | 0x21b50 | 0x20150 | 0x43 |
IsValidLocale | 0x0 | 0x41e080 | 0x21b54 | 0x20154 | 0x2dd |
EnumSystemLocalesA | 0x0 | 0x41e084 | 0x21b58 | 0x20158 | 0xf8 |
GetUserDefaultLCID | 0x0 | 0x41e088 | 0x21b5c | 0x2015c | 0x26d |
GetSystemTimeAdjustment | 0x0 | 0x41e08c | 0x21b60 | 0x20160 | 0x24e |
GetSystemTimes | 0x0 | 0x41e090 | 0x21b64 | 0x20164 | 0x250 |
GetTickCount | 0x0 | 0x41e094 | 0x21b68 | 0x20168 | 0x266 |
FreeEnvironmentStringsA | 0x0 | 0x41e098 | 0x21b6c | 0x2016c | 0x14a |
GetComputerNameW | 0x0 | 0x41e09c | 0x21b70 | 0x20170 | 0x178 |
FindCloseChangeNotification | 0x0 | 0x41e0a0 | 0x21b74 | 0x20174 | 0x11a |
FindResourceExW | 0x0 | 0x41e0a4 | 0x21b78 | 0x20178 | 0x138 |
GetCPInfo | 0x0 | 0x41e0a8 | 0x21b7c | 0x2017c | 0x15b |
SetProcessShutdownParameters | 0x0 | 0x41e0ac | 0x21b80 | 0x20180 | 0x3f9 |
GetModuleHandleExA | 0x0 | 0x41e0b0 | 0x21b84 | 0x20184 | 0x1f7 |
GetDateFormatA | 0x0 | 0x41e0b4 | 0x21b88 | 0x20188 | 0x1ae |
GetTimeFormatA | 0x0 | 0x41e0b8 | 0x21b8c | 0x2018c | 0x268 |
GetStringTypeW | 0x0 | 0x41e0bc | 0x21b90 | 0x20190 | 0x240 |
GetStringTypeA | 0x0 | 0x41e0c0 | 0x21b94 | 0x20194 | 0x23d |
LCMapStringW | 0x0 | 0x41e0c4 | 0x21b98 | 0x20198 | 0x2e3 |
GetCommandLineA | 0x0 | 0x41e0c8 | 0x21b9c | 0x2019c | 0x16f |
GetStartupInfoA | 0x0 | 0x41e0cc | 0x21ba0 | 0x201a0 | 0x239 |
RaiseException | 0x0 | 0x41e0d0 | 0x21ba4 | 0x201a4 | 0x35a |
RtlUnwind | 0x0 | 0x41e0d4 | 0x21ba8 | 0x201a8 | 0x392 |
TerminateProcess | 0x0 | 0x41e0d8 | 0x21bac | 0x201ac | 0x42d |
GetCurrentProcess | 0x0 | 0x41e0dc | 0x21bb0 | 0x201b0 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x41e0e0 | 0x21bb4 | 0x201b4 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x41e0e4 | 0x21bb8 | 0x201b8 | 0x415 |
IsDebuggerPresent | 0x0 | 0x41e0e8 | 0x21bbc | 0x201bc | 0x2d1 |
HeapAlloc | 0x0 | 0x41e0ec | 0x21bc0 | 0x201c0 | 0x29d |
HeapFree | 0x0 | 0x41e0f0 | 0x21bc4 | 0x201c4 | 0x2a1 |
EnterCriticalSection | 0x0 | 0x41e0f4 | 0x21bc8 | 0x201c8 | 0xd9 |
LeaveCriticalSection | 0x0 | 0x41e0f8 | 0x21bcc | 0x201cc | 0x2ef |
SetHandleCount | 0x0 | 0x41e0fc | 0x21bd0 | 0x201d0 | 0x3e8 |
GetStdHandle | 0x0 | 0x41e100 | 0x21bd4 | 0x201d4 | 0x23b |
GetFileType | 0x0 | 0x41e104 | 0x21bd8 | 0x201d8 | 0x1d7 |
DeleteCriticalSection | 0x0 | 0x41e108 | 0x21bdc | 0x201dc | 0xbe |
GetModuleHandleW | 0x0 | 0x41e10c | 0x21be0 | 0x201e0 | 0x1f9 |
Sleep | 0x0 | 0x41e110 | 0x21be4 | 0x201e4 | 0x421 |
ExitProcess | 0x0 | 0x41e114 | 0x21be8 | 0x201e8 | 0x104 |
WriteFile | 0x0 | 0x41e118 | 0x21bec | 0x201ec | 0x48d |
GetModuleFileNameA | 0x0 | 0x41e11c | 0x21bf0 | 0x201f0 | 0x1f4 |
GetEnvironmentStrings | 0x0 | 0x41e120 | 0x21bf4 | 0x201f4 | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x41e124 | 0x21bf8 | 0x201f8 | 0x14b |
WideCharToMultiByte | 0x0 | 0x41e128 | 0x21bfc | 0x201fc | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x41e12c | 0x21c00 | 0x20200 | 0x1c1 |
TlsGetValue | 0x0 | 0x41e130 | 0x21c04 | 0x20204 | 0x434 |
TlsAlloc | 0x0 | 0x41e134 | 0x21c08 | 0x20208 | 0x432 |
TlsSetValue | 0x0 | 0x41e138 | 0x21c0c | 0x2020c | 0x435 |
TlsFree | 0x0 | 0x41e13c | 0x21c10 | 0x20210 | 0x433 |
InterlockedIncrement | 0x0 | 0x41e140 | 0x21c14 | 0x20214 | 0x2c0 |
SetLastError | 0x0 | 0x41e144 | 0x21c18 | 0x20218 | 0x3ec |
GetCurrentThreadId | 0x0 | 0x41e148 | 0x21c1c | 0x2021c | 0x1ad |
InterlockedDecrement | 0x0 | 0x41e14c | 0x21c20 | 0x20220 | 0x2bc |
GetCurrentThread | 0x0 | 0x41e150 | 0x21c24 | 0x20224 | 0x1ac |
HeapCreate | 0x0 | 0x41e154 | 0x21c28 | 0x20228 | 0x29f |
HeapDestroy | 0x0 | 0x41e158 | 0x21c2c | 0x2022c | 0x2a0 |
VirtualFree | 0x0 | 0x41e15c | 0x21c30 | 0x20230 | 0x457 |
QueryPerformanceCounter | 0x0 | 0x41e160 | 0x21c34 | 0x20234 | 0x354 |
GetCurrentProcessId | 0x0 | 0x41e164 | 0x21c38 | 0x20238 | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x41e168 | 0x21c3c | 0x2023c | 0x24f |
FatalAppExitA | 0x0 | 0x41e16c | 0x21c40 | 0x20240 | 0x10b |
VirtualAlloc | 0x0 | 0x41e170 | 0x21c44 | 0x20244 | 0x454 |
HeapReAlloc | 0x0 | 0x41e174 | 0x21c48 | 0x20248 | 0x2a4 |
MultiByteToWideChar | 0x0 | 0x41e178 | 0x21c4c | 0x2024c | 0x31a |
ReadFile | 0x0 | 0x41e17c | 0x21c50 | 0x20250 | 0x368 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41e180 | 0x21c54 | 0x20254 | 0x2b5 |
HeapSize | 0x0 | 0x41e184 | 0x21c58 | 0x20258 | 0x2a6 |
SetConsoleCtrlHandler | 0x0 | 0x41e188 | 0x21c5c | 0x2025c | 0x3a7 |
FreeLibrary | 0x0 | 0x41e18c | 0x21c60 | 0x20260 | 0x14c |
InterlockedExchange | 0x0 | 0x41e190 | 0x21c64 | 0x20264 | 0x2bd |
GetOEMCP | 0x0 | 0x41e194 | 0x21c68 | 0x20268 | 0x213 |
IsValidCodePage | 0x0 | 0x41e198 | 0x21c6c | 0x2026c | 0x2db |
GetConsoleCP | 0x0 | 0x41e19c | 0x21c70 | 0x20270 | 0x183 |
GetConsoleMode | 0x0 | 0x41e1a0 | 0x21c74 | 0x20274 | 0x195 |
FlushFileBuffers | 0x0 | 0x41e1a4 | 0x21c78 | 0x20278 | 0x141 |
SetFilePointer | 0x0 | 0x41e1a8 | 0x21c7c | 0x2027c | 0x3df |
SetStdHandle | 0x0 | 0x41e1ac | 0x21c80 | 0x20280 | 0x3fc |
GetLocaleInfoW | 0x0 | 0x41e1b0 | 0x21c84 | 0x20284 | 0x1ea |
GetLocaleInfoA | 0x0 | 0x41e1b4 | 0x21c88 | 0x20288 | 0x1e8 |
LCMapStringA | 0x0 | 0x41e1b8 | 0x21c8c | 0x2028c | 0x2e1 |
SetEnvironmentVariableA | 0x0 | 0x41e1bc | 0x21c90 | 0x20290 | 0x3d0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseClipboard | 0x0 | 0x41e1d8 | 0x21cac | 0x202ac | 0x47 |
BeginPaint | 0x0 | 0x41e1dc | 0x21cb0 | 0x202b0 | 0xe |
CallMsgFilterW | 0x0 | 0x41e1e0 | 0x21cb4 | 0x202b4 | 0x1a |
PeekMessageA | 0x0 | 0x41e1e4 | 0x21cb8 | 0x202b8 | 0x21b |
MapVirtualKeyExW | 0x0 | 0x41e1e8 | 0x21cbc | 0x202bc | 0x1f1 |
RegisterRawInputDevices | 0x0 | 0x41e1ec | 0x21cc0 | 0x202c0 | 0x242 |
GetClipboardSequenceNumber | 0x0 | 0x41e1f0 | 0x21cc4 | 0x202c4 | 0x113 |
CountClipboardFormats | 0x0 | 0x41e1f4 | 0x21cc8 | 0x202c8 | 0x50 |
GetDialogBaseUnits | 0x0 | 0x41e1f8 | 0x21ccc | 0x202cc | 0x11d |
GetClassLongW | 0x0 | 0x41e1fc | 0x21cd0 | 0x202d0 | 0x109 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PolyTextOutW | 0x0 | 0x41e000 | 0x21ad4 | 0x200d4 | 0x23c |
CreateCompatibleDC | 0x0 | 0x41e004 | 0x21ad8 | 0x200d8 | 0x2e |
Rectangle | 0x0 | 0x41e008 | 0x21adc | 0x200dc | 0x246 |
SetStretchBltMode | 0x0 | 0x41e00c | 0x21ae0 | 0x200e0 | 0x289 |
SetPixelV | 0x0 | 0x41e010 | 0x21ae4 | 0x200e4 | 0x284 |
GetClipBox | 0x0 | 0x41e014 | 0x21ae8 | 0x200e8 | 0x1aa |
CreateDiscardableBitmap | 0x0 | 0x41e018 | 0x21aec | 0x200ec | 0x35 |
StrokeAndFillPath | 0x0 | 0x41e01c | 0x21af0 | 0x200f0 | 0x29c |
GetBitmapBits | 0x0 | 0x41e020 | 0x21af4 | 0x200f4 | 0x191 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x41e1c4 | 0x21c98 | 0x20298 | 0x118 |
ShellAboutW | 0x0 | 0x41e1c8 | 0x21c9c | 0x2029c | 0x110 |
DuplicateIcon | 0x0 | 0x41e1cc | 0x21ca0 | 0x202a0 | 0x23 |
DragQueryFileA | 0x0 | 0x41e1d0 | 0x21ca4 | 0x202a4 | 0x1e |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
updatewin1.exe | 6 | 0x00400000 | 0x0044CFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 6 | 0x00315000 | 0x00315FFF | Marked Executable | - | 32-bit | - |
![]() |
![]() |
...
|
updatewin1.exe | 6 | 0x00400000 | 0x0044CFFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 7 | 0x00585000 | 0x00585FFF | Marked Executable | - | 32-bit | - |
![]() |
![]() |
...
|
Threat Name | Severity |
---|---|
Trojan.GenericKD.31534187 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\5f157674-79c2-4ded-9dab-75219d8fb8ff\updatewin2.exe | Downloaded File | Binary |
Malicious
|
...
|
Severity |
Blacklisted
|
First Seen | 2019-01-16 22:21 (UTC+1) |
Last Seen | 2019-07-14 14:03 (UTC+2) |
Names | Win32.Trojan.Kryptik |
Families | Kryptik |
Classification | Trojan |
Image Base | 0x400000 |
Entry Point | 0x402d64 |
Size Of Code | 0x1c200 |
Size Of Initialized Data | 0x2c800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-11-21 06:08:45+00:00 |
FileVersion | 5.3.7.82 |
InternalName | gigifaw.exe |
LegalCopyright | Copyright (C) 2018, guvaxiz |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1c03e | 0x1c200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x41e000 | 0x45ec | 0x4600 | 0x1c600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.34 |
.data | 0x423000 | 0x1cde8 | 0x17c00 | 0x20c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.8 |
.rsrc | 0x440000 | 0xa724 | 0xa800 | 0x38800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.88 |
.reloc | 0x44b000 | 0x195c | 0x1a00 | 0x43000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.33 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitThread | 0x0 | 0x41e024 | 0x21ae8 | 0x200e8 | 0x105 |
GetStartupInfoW | 0x0 | 0x41e028 | 0x21aec | 0x200ec | 0x23a |
GetLastError | 0x0 | 0x41e02c | 0x21af0 | 0x200f0 | 0x1e6 |
GetProcAddress | 0x0 | 0x41e030 | 0x21af4 | 0x200f4 | 0x220 |
GlobalFree | 0x0 | 0x41e034 | 0x21af8 | 0x200f8 | 0x28c |
LoadLibraryA | 0x0 | 0x41e038 | 0x21afc | 0x200fc | 0x2f1 |
AddAtomA | 0x0 | 0x41e03c | 0x21b00 | 0x20100 | 0x3 |
FindFirstChangeNotificationA | 0x0 | 0x41e040 | 0x21b04 | 0x20104 | 0x11b |
VirtualProtect | 0x0 | 0x41e044 | 0x21b08 | 0x20108 | 0x45a |
GetCurrentDirectoryA | 0x0 | 0x41e048 | 0x21b0c | 0x2010c | 0x1a7 |
SetProcessShutdownParameters | 0x0 | 0x41e04c | 0x21b10 | 0x20110 | 0x3f9 |
GetACP | 0x0 | 0x41e050 | 0x21b14 | 0x20114 | 0x152 |
CompareStringA | 0x0 | 0x41e054 | 0x21b18 | 0x20118 | 0x52 |
CreateFileA | 0x0 | 0x41e058 | 0x21b1c | 0x2011c | 0x78 |
GetTimeZoneInformation | 0x0 | 0x41e05c | 0x21b20 | 0x20120 | 0x26b |
WriteConsoleW | 0x0 | 0x41e060 | 0x21b24 | 0x20124 | 0x48c |
GetConsoleOutputCP | 0x0 | 0x41e064 | 0x21b28 | 0x20128 | 0x199 |
WriteConsoleA | 0x0 | 0x41e068 | 0x21b2c | 0x2012c | 0x482 |
CloseHandle | 0x0 | 0x41e06c | 0x21b30 | 0x20130 | 0x43 |
IsValidLocale | 0x0 | 0x41e070 | 0x21b34 | 0x20134 | 0x2dd |
EnumSystemLocalesA | 0x0 | 0x41e074 | 0x21b38 | 0x20138 | 0xf8 |
GetUserDefaultLCID | 0x0 | 0x41e078 | 0x21b3c | 0x2013c | 0x26d |
GetDateFormatA | 0x0 | 0x41e07c | 0x21b40 | 0x20140 | 0x1ae |
GetTimeFormatA | 0x0 | 0x41e080 | 0x21b44 | 0x20144 | 0x268 |
InitAtomTable | 0x0 | 0x41e084 | 0x21b48 | 0x20148 | 0x2ae |
GetSystemTimes | 0x0 | 0x41e088 | 0x21b4c | 0x2014c | 0x250 |
GetTickCount | 0x0 | 0x41e08c | 0x21b50 | 0x20150 | 0x266 |
FreeEnvironmentStringsA | 0x0 | 0x41e090 | 0x21b54 | 0x20154 | 0x14a |
GetComputerNameW | 0x0 | 0x41e094 | 0x21b58 | 0x20158 | 0x178 |
FindCloseChangeNotification | 0x0 | 0x41e098 | 0x21b5c | 0x2015c | 0x11a |
FindResourceExW | 0x0 | 0x41e09c | 0x21b60 | 0x20160 | 0x138 |
CompareStringW | 0x0 | 0x41e0a0 | 0x21b64 | 0x20164 | 0x55 |
GetCPInfo | 0x0 | 0x41e0a4 | 0x21b68 | 0x20168 | 0x15b |
GetStringTypeW | 0x0 | 0x41e0a8 | 0x21b6c | 0x2016c | 0x240 |
GetStringTypeA | 0x0 | 0x41e0ac | 0x21b70 | 0x20170 | 0x23d |
LCMapStringW | 0x0 | 0x41e0b0 | 0x21b74 | 0x20174 | 0x2e3 |
LCMapStringA | 0x0 | 0x41e0b4 | 0x21b78 | 0x20178 | 0x2e1 |
GetLocaleInfoA | 0x0 | 0x41e0b8 | 0x21b7c | 0x2017c | 0x1e8 |
GetCommandLineA | 0x0 | 0x41e0bc | 0x21b80 | 0x20180 | 0x16f |
GetStartupInfoA | 0x0 | 0x41e0c0 | 0x21b84 | 0x20184 | 0x239 |
RaiseException | 0x0 | 0x41e0c4 | 0x21b88 | 0x20188 | 0x35a |
RtlUnwind | 0x0 | 0x41e0c8 | 0x21b8c | 0x2018c | 0x392 |
TerminateProcess | 0x0 | 0x41e0cc | 0x21b90 | 0x20190 | 0x42d |
GetCurrentProcess | 0x0 | 0x41e0d0 | 0x21b94 | 0x20194 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x41e0d4 | 0x21b98 | 0x20198 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x41e0d8 | 0x21b9c | 0x2019c | 0x415 |
IsDebuggerPresent | 0x0 | 0x41e0dc | 0x21ba0 | 0x201a0 | 0x2d1 |
HeapAlloc | 0x0 | 0x41e0e0 | 0x21ba4 | 0x201a4 | 0x29d |
HeapFree | 0x0 | 0x41e0e4 | 0x21ba8 | 0x201a8 | 0x2a1 |
EnterCriticalSection | 0x0 | 0x41e0e8 | 0x21bac | 0x201ac | 0xd9 |
LeaveCriticalSection | 0x0 | 0x41e0ec | 0x21bb0 | 0x201b0 | 0x2ef |
SetHandleCount | 0x0 | 0x41e0f0 | 0x21bb4 | 0x201b4 | 0x3e8 |
GetStdHandle | 0x0 | 0x41e0f4 | 0x21bb8 | 0x201b8 | 0x23b |
GetFileType | 0x0 | 0x41e0f8 | 0x21bbc | 0x201bc | 0x1d7 |
DeleteCriticalSection | 0x0 | 0x41e0fc | 0x21bc0 | 0x201c0 | 0xbe |
GetModuleHandleW | 0x0 | 0x41e100 | 0x21bc4 | 0x201c4 | 0x1f9 |
Sleep | 0x0 | 0x41e104 | 0x21bc8 | 0x201c8 | 0x421 |
ExitProcess | 0x0 | 0x41e108 | 0x21bcc | 0x201cc | 0x104 |
WriteFile | 0x0 | 0x41e10c | 0x21bd0 | 0x201d0 | 0x48d |
GetModuleFileNameA | 0x0 | 0x41e110 | 0x21bd4 | 0x201d4 | 0x1f4 |
GetEnvironmentStrings | 0x0 | 0x41e114 | 0x21bd8 | 0x201d8 | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x41e118 | 0x21bdc | 0x201dc | 0x14b |
WideCharToMultiByte | 0x0 | 0x41e11c | 0x21be0 | 0x201e0 | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x41e120 | 0x21be4 | 0x201e4 | 0x1c1 |
TlsGetValue | 0x0 | 0x41e124 | 0x21be8 | 0x201e8 | 0x434 |
TlsAlloc | 0x0 | 0x41e128 | 0x21bec | 0x201ec | 0x432 |
TlsSetValue | 0x0 | 0x41e12c | 0x21bf0 | 0x201f0 | 0x435 |
TlsFree | 0x0 | 0x41e130 | 0x21bf4 | 0x201f4 | 0x433 |
InterlockedIncrement | 0x0 | 0x41e134 | 0x21bf8 | 0x201f8 | 0x2c0 |
SetLastError | 0x0 | 0x41e138 | 0x21bfc | 0x201fc | 0x3ec |
GetCurrentThreadId | 0x0 | 0x41e13c | 0x21c00 | 0x20200 | 0x1ad |
InterlockedDecrement | 0x0 | 0x41e140 | 0x21c04 | 0x20204 | 0x2bc |
GetCurrentThread | 0x0 | 0x41e144 | 0x21c08 | 0x20208 | 0x1ac |
HeapCreate | 0x0 | 0x41e148 | 0x21c0c | 0x2020c | 0x29f |
HeapDestroy | 0x0 | 0x41e14c | 0x21c10 | 0x20210 | 0x2a0 |
VirtualFree | 0x0 | 0x41e150 | 0x21c14 | 0x20214 | 0x457 |
QueryPerformanceCounter | 0x0 | 0x41e154 | 0x21c18 | 0x20218 | 0x354 |
GetCurrentProcessId | 0x0 | 0x41e158 | 0x21c1c | 0x2021c | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x41e15c | 0x21c20 | 0x20220 | 0x24f |
FatalAppExitA | 0x0 | 0x41e160 | 0x21c24 | 0x20224 | 0x10b |
VirtualAlloc | 0x0 | 0x41e164 | 0x21c28 | 0x20228 | 0x454 |
HeapReAlloc | 0x0 | 0x41e168 | 0x21c2c | 0x2022c | 0x2a4 |
MultiByteToWideChar | 0x0 | 0x41e16c | 0x21c30 | 0x20230 | 0x31a |
ReadFile | 0x0 | 0x41e170 | 0x21c34 | 0x20234 | 0x368 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41e174 | 0x21c38 | 0x20238 | 0x2b5 |
HeapSize | 0x0 | 0x41e178 | 0x21c3c | 0x2023c | 0x2a6 |
SetConsoleCtrlHandler | 0x0 | 0x41e17c | 0x21c40 | 0x20240 | 0x3a7 |
FreeLibrary | 0x0 | 0x41e180 | 0x21c44 | 0x20244 | 0x14c |
InterlockedExchange | 0x0 | 0x41e184 | 0x21c48 | 0x20248 | 0x2bd |
GetOEMCP | 0x0 | 0x41e188 | 0x21c4c | 0x2024c | 0x213 |
IsValidCodePage | 0x0 | 0x41e18c | 0x21c50 | 0x20250 | 0x2db |
GetConsoleCP | 0x0 | 0x41e190 | 0x21c54 | 0x20254 | 0x183 |
GetConsoleMode | 0x0 | 0x41e194 | 0x21c58 | 0x20258 | 0x195 |
FlushFileBuffers | 0x0 | 0x41e198 | 0x21c5c | 0x2025c | 0x141 |
SetFilePointer | 0x0 | 0x41e19c | 0x21c60 | 0x20260 | 0x3df |
SetStdHandle | 0x0 | 0x41e1a0 | 0x21c64 | 0x20264 | 0x3fc |
GetLocaleInfoW | 0x0 | 0x41e1a4 | 0x21c68 | 0x20268 | 0x1ea |
SetEnvironmentVariableA | 0x0 | 0x41e1a8 | 0x21c6c | 0x2026c | 0x3d0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseClipboard | 0x0 | 0x41e1c4 | 0x21c88 | 0x20288 | 0x47 |
GetSubMenu | 0x0 | 0x41e1c8 | 0x21c8c | 0x2028c | 0x16b |
LoadBitmapA | 0x0 | 0x41e1cc | 0x21c90 | 0x20290 | 0x1d0 |
BeginPaint | 0x0 | 0x41e1d0 | 0x21c94 | 0x20294 | 0xe |
CallMsgFilterW | 0x0 | 0x41e1d4 | 0x21c98 | 0x20298 | 0x1a |
PeekMessageA | 0x0 | 0x41e1d8 | 0x21c9c | 0x2029c | 0x21b |
MapVirtualKeyExW | 0x0 | 0x41e1dc | 0x21ca0 | 0x202a0 | 0x1f1 |
RegisterRawInputDevices | 0x0 | 0x41e1e0 | 0x21ca4 | 0x202a4 | 0x242 |
SetWindowsHookExW | 0x0 | 0x41e1e4 | 0x21ca8 | 0x202a8 | 0x2b0 |
GetClipboardSequenceNumber | 0x0 | 0x41e1e8 | 0x21cac | 0x202ac | 0x113 |
GetDialogBaseUnits | 0x0 | 0x41e1ec | 0x21cb0 | 0x202b0 | 0x11d |
MessageBoxIndirectA | 0x0 | 0x41e1f0 | 0x21cb4 | 0x202b4 | 0x1fb |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateCompatibleDC | 0x0 | 0x41e000 | 0x21ac4 | 0x200c4 | 0x2e |
PlayEnhMetaFile | 0x0 | 0x41e004 | 0x21ac8 | 0x200c8 | 0x230 |
ScaleViewportExtEx | 0x0 | 0x41e008 | 0x21acc | 0x200cc | 0x258 |
SetStretchBltMode | 0x0 | 0x41e00c | 0x21ad0 | 0x200d0 | 0x289 |
SetPixelV | 0x0 | 0x41e010 | 0x21ad4 | 0x200d4 | 0x284 |
CreateDiscardableBitmap | 0x0 | 0x41e014 | 0x21ad8 | 0x200d8 | 0x35 |
AddFontResourceW | 0x0 | 0x41e018 | 0x21adc | 0x200dc | 0x7 |
SetDeviceGammaRamp | 0x0 | 0x41e01c | 0x21ae0 | 0x200e0 | 0x271 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExtractAssociatedIconA | 0x0 | 0x41e1b0 | 0x21c74 | 0x20274 | 0x24 |
ShellExecuteW | 0x0 | 0x41e1b4 | 0x21c78 | 0x20278 | 0x118 |
ShellAboutW | 0x0 | 0x41e1b8 | 0x21c7c | 0x2027c | 0x110 |
DragQueryFileA | 0x0 | 0x41e1bc | 0x21c80 | 0x20280 | 0x1e |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
updatewin2.exe | 9 | 0x00400000 | 0x0044CFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 9 | 0x00305000 | 0x00305FFF | Marked Executable | - | 32-bit | - |
![]() |
![]() |
...
|
updatewin2.exe | 9 | 0x00400000 | 0x0044CFFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
Threat Name | Severity |
---|---|
Trojan.AgentWDCR.SVC |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\5f157674-79c2-4ded-9dab-75219d8fb8ff\updatewin.exe | Downloaded File | Binary |
Malicious
|
...
|
Severity |
Blacklisted
|
First Seen | 2019-01-16 22:21 (UTC+1) |
Last Seen | 2019-07-06 02:48 (UTC+2) |
Names | Win32.Trojan.Kryptik |
Families | Kryptik |
Classification | Trojan |
Image Base | 0x400000 |
Entry Point | 0x402d7c |
Size Of Code | 0x1c200 |
Size Of Initialized Data | 0x2d400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-02-19 08:26:47+00:00 |
FileVersion | 8.8.10.11 |
InternalName | sutazaxidi.exe |
LegalCopyright | Copyright (C) 2018, huxonulow |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1c09e | 0x1c200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x41e000 | 0x4636 | 0x4800 | 0x1c600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.25 |
.data | 0x423000 | 0x1d5a8 | 0x18400 | 0x20e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.8 |
.rsrc | 0x441000 | 0xa826 | 0xaa00 | 0x39200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.84 |
.reloc | 0x44c000 | 0x1974 | 0x1a00 | 0x43c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.34 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitThread | 0x0 | 0x41e020 | 0x21af4 | 0x200f4 | 0x105 |
GetStartupInfoW | 0x0 | 0x41e024 | 0x21af8 | 0x200f8 | 0x23a |
GetConsoleAliasesW | 0x0 | 0x41e028 | 0x21afc | 0x200fc | 0x182 |
GetLastError | 0x0 | 0x41e02c | 0x21b00 | 0x20100 | 0x1e6 |
GetProcAddress | 0x0 | 0x41e030 | 0x21b04 | 0x20104 | 0x220 |
BackupWrite | 0x0 | 0x41e034 | 0x21b08 | 0x20108 | 0x18 |
GlobalFree | 0x0 | 0x41e038 | 0x21b0c | 0x2010c | 0x28c |
LoadLibraryA | 0x0 | 0x41e03c | 0x21b10 | 0x20110 | 0x2f1 |
GetNumberFormatW | 0x0 | 0x41e040 | 0x21b14 | 0x20114 | 0x20f |
AddAtomA | 0x0 | 0x41e044 | 0x21b18 | 0x20118 | 0x3 |
FindFirstChangeNotificationA | 0x0 | 0x41e048 | 0x21b1c | 0x2011c | 0x11b |
GetStringTypeW | 0x0 | 0x41e04c | 0x21b20 | 0x20120 | 0x240 |
VirtualProtect | 0x0 | 0x41e050 | 0x21b24 | 0x20124 | 0x45a |
GetACP | 0x0 | 0x41e054 | 0x21b28 | 0x20128 | 0x152 |
SetProcessShutdownParameters | 0x0 | 0x41e058 | 0x21b2c | 0x2012c | 0x3f9 |
CompareStringW | 0x0 | 0x41e05c | 0x21b30 | 0x20130 | 0x55 |
CompareStringA | 0x0 | 0x41e060 | 0x21b34 | 0x20134 | 0x52 |
CreateFileA | 0x0 | 0x41e064 | 0x21b38 | 0x20138 | 0x78 |
GetTimeZoneInformation | 0x0 | 0x41e068 | 0x21b3c | 0x2013c | 0x26b |
WriteConsoleW | 0x0 | 0x41e06c | 0x21b40 | 0x20140 | 0x48c |
GetConsoleOutputCP | 0x0 | 0x41e070 | 0x21b44 | 0x20144 | 0x199 |
WriteConsoleA | 0x0 | 0x41e074 | 0x21b48 | 0x20148 | 0x482 |
CloseHandle | 0x0 | 0x41e078 | 0x21b4c | 0x2014c | 0x43 |
IsValidLocale | 0x0 | 0x41e07c | 0x21b50 | 0x20150 | 0x2dd |
EnumSystemLocalesA | 0x0 | 0x41e080 | 0x21b54 | 0x20154 | 0xf8 |
GetUserDefaultLCID | 0x0 | 0x41e084 | 0x21b58 | 0x20158 | 0x26d |
GetDateFormatA | 0x0 | 0x41e088 | 0x21b5c | 0x2015c | 0x1ae |
GetSystemTimes | 0x0 | 0x41e08c | 0x21b60 | 0x20160 | 0x250 |
GetTickCount | 0x0 | 0x41e090 | 0x21b64 | 0x20164 | 0x266 |
FreeEnvironmentStringsA | 0x0 | 0x41e094 | 0x21b68 | 0x20168 | 0x14a |
GetComputerNameW | 0x0 | 0x41e098 | 0x21b6c | 0x2016c | 0x178 |
FindCloseChangeNotification | 0x0 | 0x41e09c | 0x21b70 | 0x20170 | 0x11a |
FindResourceExW | 0x0 | 0x41e0a0 | 0x21b74 | 0x20174 | 0x138 |
GetCurrentDirectoryA | 0x0 | 0x41e0a4 | 0x21b78 | 0x20178 | 0x1a7 |
GetCPInfo | 0x0 | 0x41e0a8 | 0x21b7c | 0x2017c | 0x15b |
GetTimeFormatA | 0x0 | 0x41e0ac | 0x21b80 | 0x20180 | 0x268 |
GetStringTypeA | 0x0 | 0x41e0b0 | 0x21b84 | 0x20184 | 0x23d |
LCMapStringW | 0x0 | 0x41e0b4 | 0x21b88 | 0x20188 | 0x2e3 |
LCMapStringA | 0x0 | 0x41e0b8 | 0x21b8c | 0x2018c | 0x2e1 |
GetLocaleInfoA | 0x0 | 0x41e0bc | 0x21b90 | 0x20190 | 0x1e8 |
GetLocaleInfoW | 0x0 | 0x41e0c0 | 0x21b94 | 0x20194 | 0x1ea |
SetStdHandle | 0x0 | 0x41e0c4 | 0x21b98 | 0x20198 | 0x3fc |
SetFilePointer | 0x0 | 0x41e0c8 | 0x21b9c | 0x2019c | 0x3df |
GetCommandLineA | 0x0 | 0x41e0cc | 0x21ba0 | 0x201a0 | 0x16f |
GetStartupInfoA | 0x0 | 0x41e0d0 | 0x21ba4 | 0x201a4 | 0x239 |
RaiseException | 0x0 | 0x41e0d4 | 0x21ba8 | 0x201a8 | 0x35a |
RtlUnwind | 0x0 | 0x41e0d8 | 0x21bac | 0x201ac | 0x392 |
TerminateProcess | 0x0 | 0x41e0dc | 0x21bb0 | 0x201b0 | 0x42d |
GetCurrentProcess | 0x0 | 0x41e0e0 | 0x21bb4 | 0x201b4 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x41e0e4 | 0x21bb8 | 0x201b8 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x41e0e8 | 0x21bbc | 0x201bc | 0x415 |
IsDebuggerPresent | 0x0 | 0x41e0ec | 0x21bc0 | 0x201c0 | 0x2d1 |
HeapAlloc | 0x0 | 0x41e0f0 | 0x21bc4 | 0x201c4 | 0x29d |
HeapFree | 0x0 | 0x41e0f4 | 0x21bc8 | 0x201c8 | 0x2a1 |
EnterCriticalSection | 0x0 | 0x41e0f8 | 0x21bcc | 0x201cc | 0xd9 |
LeaveCriticalSection | 0x0 | 0x41e0fc | 0x21bd0 | 0x201d0 | 0x2ef |
SetHandleCount | 0x0 | 0x41e100 | 0x21bd4 | 0x201d4 | 0x3e8 |
GetStdHandle | 0x0 | 0x41e104 | 0x21bd8 | 0x201d8 | 0x23b |
GetFileType | 0x0 | 0x41e108 | 0x21bdc | 0x201dc | 0x1d7 |
DeleteCriticalSection | 0x0 | 0x41e10c | 0x21be0 | 0x201e0 | 0xbe |
GetModuleHandleW | 0x0 | 0x41e110 | 0x21be4 | 0x201e4 | 0x1f9 |
Sleep | 0x0 | 0x41e114 | 0x21be8 | 0x201e8 | 0x421 |
ExitProcess | 0x0 | 0x41e118 | 0x21bec | 0x201ec | 0x104 |
WriteFile | 0x0 | 0x41e11c | 0x21bf0 | 0x201f0 | 0x48d |
GetModuleFileNameA | 0x0 | 0x41e120 | 0x21bf4 | 0x201f4 | 0x1f4 |
GetEnvironmentStrings | 0x0 | 0x41e124 | 0x21bf8 | 0x201f8 | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x41e128 | 0x21bfc | 0x201fc | 0x14b |
WideCharToMultiByte | 0x0 | 0x41e12c | 0x21c00 | 0x20200 | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x41e130 | 0x21c04 | 0x20204 | 0x1c1 |
TlsGetValue | 0x0 | 0x41e134 | 0x21c08 | 0x20208 | 0x434 |
TlsAlloc | 0x0 | 0x41e138 | 0x21c0c | 0x2020c | 0x432 |
TlsSetValue | 0x0 | 0x41e13c | 0x21c10 | 0x20210 | 0x435 |
TlsFree | 0x0 | 0x41e140 | 0x21c14 | 0x20214 | 0x433 |
InterlockedIncrement | 0x0 | 0x41e144 | 0x21c18 | 0x20218 | 0x2c0 |
SetLastError | 0x0 | 0x41e148 | 0x21c1c | 0x2021c | 0x3ec |
GetCurrentThreadId | 0x0 | 0x41e14c | 0x21c20 | 0x20220 | 0x1ad |
InterlockedDecrement | 0x0 | 0x41e150 | 0x21c24 | 0x20224 | 0x2bc |
GetCurrentThread | 0x0 | 0x41e154 | 0x21c28 | 0x20228 | 0x1ac |
HeapCreate | 0x0 | 0x41e158 | 0x21c2c | 0x2022c | 0x29f |
HeapDestroy | 0x0 | 0x41e15c | 0x21c30 | 0x20230 | 0x2a0 |
VirtualFree | 0x0 | 0x41e160 | 0x21c34 | 0x20234 | 0x457 |
QueryPerformanceCounter | 0x0 | 0x41e164 | 0x21c38 | 0x20238 | 0x354 |
GetCurrentProcessId | 0x0 | 0x41e168 | 0x21c3c | 0x2023c | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x41e16c | 0x21c40 | 0x20240 | 0x24f |
FatalAppExitA | 0x0 | 0x41e170 | 0x21c44 | 0x20244 | 0x10b |
VirtualAlloc | 0x0 | 0x41e174 | 0x21c48 | 0x20248 | 0x454 |
HeapReAlloc | 0x0 | 0x41e178 | 0x21c4c | 0x2024c | 0x2a4 |
MultiByteToWideChar | 0x0 | 0x41e17c | 0x21c50 | 0x20250 | 0x31a |
ReadFile | 0x0 | 0x41e180 | 0x21c54 | 0x20254 | 0x368 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41e184 | 0x21c58 | 0x20258 | 0x2b5 |
HeapSize | 0x0 | 0x41e188 | 0x21c5c | 0x2025c | 0x2a6 |
SetConsoleCtrlHandler | 0x0 | 0x41e18c | 0x21c60 | 0x20260 | 0x3a7 |
FreeLibrary | 0x0 | 0x41e190 | 0x21c64 | 0x20264 | 0x14c |
InterlockedExchange | 0x0 | 0x41e194 | 0x21c68 | 0x20268 | 0x2bd |
GetOEMCP | 0x0 | 0x41e198 | 0x21c6c | 0x2026c | 0x213 |
IsValidCodePage | 0x0 | 0x41e19c | 0x21c70 | 0x20270 | 0x2db |
GetConsoleCP | 0x0 | 0x41e1a0 | 0x21c74 | 0x20274 | 0x183 |
GetConsoleMode | 0x0 | 0x41e1a4 | 0x21c78 | 0x20278 | 0x195 |
FlushFileBuffers | 0x0 | 0x41e1a8 | 0x21c7c | 0x2027c | 0x141 |
SetEnvironmentVariableA | 0x0 | 0x41e1ac | 0x21c80 | 0x20280 | 0x3d0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseClipboard | 0x0 | 0x41e1d4 | 0x21ca8 | 0x202a8 | 0x47 |
SendNotifyMessageA | 0x0 | 0x41e1d8 | 0x21cac | 0x202ac | 0x264 |
BeginPaint | 0x0 | 0x41e1dc | 0x21cb0 | 0x202b0 | 0xe |
CallMsgFilterW | 0x0 | 0x41e1e0 | 0x21cb4 | 0x202b4 | 0x1a |
PeekMessageA | 0x0 | 0x41e1e4 | 0x21cb8 | 0x202b8 | 0x21b |
MapVirtualKeyExW | 0x0 | 0x41e1e8 | 0x21cbc | 0x202bc | 0x1f1 |
RegisterRawInputDevices | 0x0 | 0x41e1ec | 0x21cc0 | 0x202c0 | 0x242 |
GetClipboardSequenceNumber | 0x0 | 0x41e1f0 | 0x21cc4 | 0x202c4 | 0x113 |
SetUserObjectInformationA | 0x0 | 0x41e1f4 | 0x21cc8 | 0x202c8 | 0x29f |
GetDialogBaseUnits | 0x0 | 0x41e1f8 | 0x21ccc | 0x202cc | 0x11d |
GetMessageW | 0x0 | 0x41e1fc | 0x21cd0 | 0x202d0 | 0x14e |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreatePolyPolygonRgn | 0x0 | 0x41e000 | 0x21ad4 | 0x200d4 | 0x4b |
CreateCompatibleDC | 0x0 | 0x41e004 | 0x21ad8 | 0x200d8 | 0x2e |
SetStretchBltMode | 0x0 | 0x41e008 | 0x21adc | 0x200dc | 0x289 |
SetPixelV | 0x0 | 0x41e00c | 0x21ae0 | 0x200e0 | 0x284 |
GetCharWidth32A | 0x0 | 0x41e010 | 0x21ae4 | 0x200e4 | 0x1a0 |
CreateDiscardableBitmap | 0x0 | 0x41e014 | 0x21ae8 | 0x200e8 | 0x35 |
BitBlt | 0x0 | 0x41e018 | 0x21aec | 0x200ec | 0x12 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x41e1b4 | 0x21c88 | 0x20288 | 0x118 |
ShellAboutW | 0x0 | 0x41e1b8 | 0x21c8c | 0x2028c | 0x110 |
ExtractIconA | 0x0 | 0x41e1bc | 0x21c90 | 0x20290 | 0x28 |
ShellExecuteExA | 0x0 | 0x41e1c0 | 0x21c94 | 0x20294 | 0x116 |
FindExecutableA | 0x0 | 0x41e1c4 | 0x21c98 | 0x20298 | 0x2d |
DragQueryFileA | 0x0 | 0x41e1c8 | 0x21c9c | 0x2029c | 0x1e |
ExtractIconW | 0x0 | 0x41e1cc | 0x21ca0 | 0x202a0 | 0x2c |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
updatewin.exe | 10 | 0x00400000 | 0x0044DFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 10 | 0x00305000 | 0x00305FFF | Marked Executable | - | 32-bit | - |
![]() |
![]() |
...
|
Threat Name | Severity |
---|---|
Trojan.AgentWDCR.SUF |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\cPHmz4y9hlXd6trOnGz.ots | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EDVS.avi | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\G0k7.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\GH F.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\h7iN.jpg | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\KaYNqgG.bmp | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\LS_APPDATA744de46e-2913-4f69-a0ea-d12dff2a5c90SAMPLE.exe | Modified File | Binary |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Ntzf.doc | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Pjxm0.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\sDwPUwZG7wDgXptt.flv | Modified File | Video |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\uJu-CI.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\uZ7jTVGLo.pdf | Modified File |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wmwdI-cLzMW1U.rtf | Modified File | Text |
Unknown
|
...
|
~dyc|S 2sӯ%] 6>l4)FIFkkȦBog~u->1ֲ!5_%7QOiu̶ FkAY&[ZsXpG@W?~y'oQӭ-ly@ODhmW4$QDQE3EOչJ6`o3;^͵ 'r*FЀm4@`o"-z&u`͓# '뛸>貐q*9Bt5)IFTDKuj2-,*C|-!6H9V1*h:"Pr,% '2')axSWMK|RYڭ|[ƌL,./AyE ~Rv]n$Wp%f;mRI?`Tb0Aanv.ƀFޢ 8gnbxQA-*ED3_ƝzckHReSB(P <'=(LqC:L0f?A̬ۀ6Ӿg|9bdU@pfطfi<b?~%#mEU?mq稀BS^0ХI~h0ciotW@b~vHI8k'-b/W_$мH<0E3^J'܇4BPteGrӖ35)os]EB2dF"B|2[_V|SGĜ^j#Xuaڍ]V̢[qXT@ҺS?S;Nu CgQig2N﨏fA#LQCQc;l?P7xn2(Ho^2OD-J#N'<5ҏ$1ˇ]=Iq@X5Pmia4suŷRrʾDmHu=*3r1VRMK~X5X6)LЂuvL8-c(9thھr_ SӈT#؏A#((Gޡ|e5,h:C=kh,8FgƬ6&bNR;R5V4U-ىz!WtRL8:|$Pjz$ь"BhEY`,e-8/ZBfe. =6'!`r/~7X1Rj"bؚݟjLҩhf2!T(dlI<j~OWdgM[XlIOE<m+XNc4O7$^Gç&0VL5eTҍ:yEE7ɃE:hlb&S~QS^xېPjvϸbڅo#ڏ]iV'fh!q`yդJ|Ό<? Udbvra+Eⷱ7w]8)*"y #@s2lqgGVП$.e|iAihcm7Q嚻 k :j=Ų@SVEX#7nA q!nRJ>Dbc+赻~RphK%3| !s#oWks8NFiUV=_VCK0u=#uCJ=rxz@H컠C(>e?# ... |
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\xZVVdLTP5CRjDGwK.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\_pjDf89YoIOK7INngcQL.swf | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\13WDFkzLx13VDvEaH0D.pptx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\4zo3jZ4ZhCJWz.doc | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\7SVXau9BM-qAm.docx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\aHQ0mStm7MOUQz8p.csv | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c74ORtbzoKEgt1tULZrF.ots | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Eiz2OkszASes0dl.ods | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\G5QwtEl2iSslGa.ots | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ixHgNpSkmetkMwk0N.doc | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\rrn5_p.docx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Sh2l9d6EAI4aRt7OOr6g.pptx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\uJO-YiH9NhpREYVYgJi.xlsx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\XhDBm5L_.xlsx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\_7Xr5yfzUYNnPcQwSd50.xlsx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\-GcGxMxOZK4.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\07G0ZL7bvnBKvt7n.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\8HrfWqZar65w.wav | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\bS4AaW9eUKRKSJX2c.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\eySD-sWxKcR.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\FB pP.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\fQh6.wav | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\H94nos6VqWF8Oqje.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\jgXL.wav | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\MyJjOnayKnFCwyo3.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\NTjyCO-pmQ3AS.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\O841-zc0Cz.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\POR XU-fcmkfoFYhwpS_.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ptcryHpXY3gBNb.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\qpbO.wav | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\S4IWsPZvnadFRmzK.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\SOIg.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\SpwIY0qQ5DxtnlG-Nb.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\unP_Med.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\wcuQuzjX.wav | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\y9xtUA5iI6IPOKUD.wav | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Z3UK3vFO8h-zCs4j.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\zyzE7.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\_wiR1L3MR2ebfVeG.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\3vMt_2q3fAah.png | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\CrjCu6i aZorUJcYh.png | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\IblMdY4N1yG.bmp | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\eFGyeqngF0yupS6aQiTk.mkv | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\HuEJMg3KiSp.avi | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Mv1WVGRvzH\0JOcjFAlZN.flv | Modified File | Video |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Mv1WVGRvzH\7H07rLnEi4jFThR2aq.mp4 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Mv1WVGRvzH\Gtis3rDzqOHJLSemRMN.odp | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Mv1WVGRvzH\sKevCgi1Mzg9JDdGUMsM.flv | Modified File | Video |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\0d9kggXW.pdf | Modified File |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\aFuREbY291J9.rtf | Modified File | Text |
Unknown
|
...
|
~dyc|S 2sӯ%] 6>l4)FIFkٜtco*pSF 㝉cؐ<o|Oek(u%M,qg%=$9[NŚVO>##dΧwU#we(6<s^ey"q+H<0<S#D.͜$!S臻Tfa<<k_)>O|T1|83'mll(#(;IqdPzY ELM.;һ1bWpdGx/J/:-dgR#ws-jX@f4C1,."jR_`B'E<? Z3հVptLdO)=^եuţNêն,QrSXŋOn<b⋲6۲8iw o2$0uyD.hp5PGezB ӛ@QRHh| (:χ>ZeP;f>WB1$,Ɖx#0*8Rjv==lIf%LmGWTqQ+^Q?3%W,wldj±^ś[Zp0`0:pZS5FB.*:BHYtGLNJfE1 msU?rL>x8ԟdU'dQ] 0r%BC/l puOTؤ%/rU8X$~N=I&Gg",p5:%ۤ<6_ȴdcӥ""OHزbB$aX%8(D&vxҭc/8V?/43?Lq*kz3_ش<xKi!,pS@-''1Ϝ@EbAx;h0whZHĔ~YkBʽ ̌zʽZJK8&Y57Z2TUbS(L QS?*`ΪMYC^'j5DCp+Ĺ´ZD?40xն6x`.q3> 'W89_4PER,"g*"bJŴcXF٩=Y6șe|W42!HwhWX;F8_?s91~)q7ٗGYkt^.2Ϩz>~p+p1Wݶ2!&@oarc U].im/Un|Aou"RswAZ2G?f=</&=OmktA1Ͽ7_j^١u]ΦO_%CD.N@@>+=f%UPCat$y̸hmZbZBIUqѯ'9!ͥuYP_9MIkim$l;WtHu+&]-2ؙfeט;Ynlct3K#VsKO n|9,KLȲ6r<rF&(.OHWnoʱ[#8լVS?J;K<֗L!.>'Qk!&w@`esbP(لQ֤@oqi@+2,Af"9lMhkC˧M$Uf.BR @%Mq0SV|fTwqFȄ! ... |
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\bhC_ABvBjR.ods | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\hK5LQd-AxtZKvzbn.xlsx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\lbsR.csv | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\pelEM3i4e4Jx_4 Wkx.pdf | Modified File |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Suggested Sites.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Web Slice Gallery.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE Add-on site.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE site on Microsoft.com.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Work.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Money.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSNBC News.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Get Windows Live.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Gallery.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Spaces.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\kuLBm0R5-grtJK8w\z2lk.jpg | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NYC5ngf\P1zhXc0ibiHP0Bs2v5.gif | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ZTE-\l6LO.bmp | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ZTE-\MFSIcW7l5OKlh5.gif | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ZTE-\WQb DhJ7Wo.jpg | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\BoizzI4g97t.flv | Modified File | Video |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\Iq gbMO_n.flv | Modified File | Video |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\UtVdyOv5.swf | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Mv1WVGRvzH\Fv3TELB 8E\2BSi.ods | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Mv1WVGRvzH\Fv3TELB 8E\eOYyRR2EObYB.wav | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Mv1WVGRvzH\Fv3TELB 8E\eZfj5ZvjMOZ.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Mv1WVGRvzH\Fv3TELB 8E\O7mIpznG0.gif | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Mv1WVGRvzH\Fv3TELB 8E\qDPtFMhAiJ2xQ vm.odp | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\-cJIpQCkg1\1TiNgxSzmOsn7Ri OkP.ots | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\-cJIpQCkg1\faBTC43kElpNlGMFau.pps | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\_private\folder.ico | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\kuLBm0R5-grtJK8w\KkXM-cBNoii_tDa0YyP\CugNJ6pb94kQCPMiK.jpg | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\kuLBm0R5-grtJK8w\KkXM-cBNoii_tDa0YyP\pySmPr79Heo.png | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\kuLBm0R5-grtJK8w\KkXM-cBNoii_tDa0YyP\Zusq yA8dO-j.gif | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NYC5ngf\NSqsuqL\KZrZHmvQBeSkBOCD.jpg | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NYC5ngf\NSqsuqL\m7Zhy4P-VQ66.gif | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ZTE-\3Bsx2yMEE1UNteJQW\OQg8wwtsOsz4VSDTpD.png | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ZTE-\bbyLspO02\y lRKLTJHdvF Q.gif | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ZTE-\pYG2mrJ4CHtyyhs xGQU\eyP8XnrLY rQ9ZYZ.gif | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ZTE-\pYG2mrJ4CHtyyhs xGQU\lfJNr8tOZ7oDHun6ukoV.gif | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ZTE-\pYG2mrJ4CHtyyhs xGQU\VFWyDHM.png | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\a9qF7OuHrZ4T.flv | Modified File | Video |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\KEz1B VUjzGhZ.swf | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\RrLl7FRJlURSY01.flv | Modified File | Video |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\-cJIpQCkg1\5T4sBt2\5ETH-YOt.pps | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\-cJIpQCkg1\5T4sBt2\5LxZSjV.pdf | Modified File |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\-cJIpQCkg1\5T4sBt2\8GBnXsZ.pdf | Modified File |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\-cJIpQCkg1\5T4sBt2\aVltm_fp_1spcSpiUB7E.pptx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\-cJIpQCkg1\5T4sBt2\dthjAR.odt | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\-cJIpQCkg1\5T4sBt2\HOw3I9OnurIF0.pptx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\-cJIpQCkg1\5T4sBt2\kLhp.docx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\-cJIpQCkg1\5T4sBt2\M85S8 e0deSz1O2lZp.xls | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\-cJIpQCkg1\5T4sBt2\pbZLWA2gHx6B.ods | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\-cJIpQCkg1\5T4sBt2\z ACbUu.csv | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\kuLBm0R5-grtJK8w\KkXM-cBNoii_tDa0YyP\fXLlrMkF3y385T7R_VK\NSMy5XFpc9v55E4.png | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\kuLBm0R5-grtJK8w\KkXM-cBNoii_tDa0YyP\fXLlrMkF3y385T7R_VK\sMjYpjKhyZpf8TNaMG.gif | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\kuLBm0R5-grtJK8w\KkXM-cBNoii_tDa0YyP\fXLlrMkF3y385T7R_VK\V6CUx4Z.png | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\sVLD8M-oJOW\lZ73i.avi | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\sVLD8M-oJOW\NDd8nvPiASazxx_Qnd.mp4 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\sVLD8M-oJOW\QV66E7hBIev3ByZZaaQi.flv | Modified File | Video |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\sVLD8M-oJOW\T0lSyaUX_nTdUnU89-7l.avi | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\tKB6e7CXHXIzSLY\M9S6OcF7aYbMU.swf | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\tKB6e7CXHXIzSLY\MKQEfW1 O9_GGct.avi | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\tKB6e7CXHXIzSLY\xSTCc.avi | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.msi | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\sVLD8M-oJOW\xbwc4aSxlyVVrqHkiS\E31COVq.mkv | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\sVLD8M-oJOW\xbwc4aSxlyVVrqHkiS\utbmN6bsL1s2QoyIy_N.mp4 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\tKB6e7CXHXIzSLY\4Ww3Dv\bjmnfbrNfGEXCMraZ.flv | Modified File | Video |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\tKB6e7CXHXIzSLY\4Ww3Dv\Djmg5Xg.flv | Modified File | Video |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\tKB6e7CXHXIzSLY\4Ww3Dv\pW-HWPux0H.flv | Modified File | Video |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\tKB6e7CXHXIzSLY\4Ww3Dv\UMlO p8XR.mp4 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\36USA68T\imagesrv.adition[1].xml | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\VGMTOI09\www.msn[1].xml | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\tKB6e7CXHXIzSLY\4Ww3Dv\6xgwVggB1\3-Nhyh1JijVqK571B0JU\I0IPALQTs_bmOEuFUuOl.avi | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\tKB6e7CXHXIzSLY\4Ww3Dv\6xgwVggB1\3-Nhyh1JijVqK571B0JU\Imq8H_txUYezfovf910P.avi | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\tKB6e7CXHXIzSLY\4Ww3Dv\6xgwVggB1\3-Nhyh1JijVqK571B0JU\PSRUTQvyeJCY.mp4 | Modified File | Stream |
Unknown
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\index.dat | Modified File | Stream |
Unknown
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\ietldcache\index.dat | Modified File | Stream |
Unknown
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\x9ohk109\get[1].php | Downloaded File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\dSfwXCkwSPKl-.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\frVUZwt9PcEpwFw.jpg | Modified File | Image |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Gp40F.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\IcgE7 x.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\K0eRKbFqwJi63h.flv | Modified File | Video |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\vDgHCp4Eu83i9SpY9-10.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\4Q Yden1pX.xls | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8OcrQfqf9.xlsx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jLUC 3.docx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\mMGsDdpRxCcIwjb.pptx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\mXYQzNZWY3_pbSh7dVoS.xlsx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\rOeN9J2zJO_02nt1ly.docx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\tJLm4JiczASJ_8Z0U3i.ots | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\VJH-kfHp7SFpre94.pptx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wZOz3j2ll6HfOuxlg93b.docx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\x7bIgakKt.docx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\yB0OOX Rk5q.pptx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\1tk99aXbfw9RlvqZV.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\FC0AY.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\FiSO1uvHs5.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\g9mcoi9dYhMEy.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\H99vbmXS7JVu8GvPT.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\hf0MR7KC2v0S0EFbF.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\j nRVt1oLEKKj.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\nh7G7MoNq.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\PBGnAJbjKeNYoVmuXsp.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\SIP IIj4TyP2E.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\th0xZ3rZW1yj.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\WqT6i1.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZBi4Ka.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Mv1WVGRvzH\ceQR-g1K.flv | Modified File | Video |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Mv1WVGRvzH\hjjmc6wvdBzNble_jQ.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Mv1WVGRvzH\IqxOJCjnMrxHR71kHDep.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Mv1WVGRvzH\KMX9gyhiVByA4.mp4 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Mv1WVGRvzH\rX Jr.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\mdkvH5k.csv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Home.url | Modified File | Text |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft Store.url | Modified File | Text |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Autos.url | Modified File | Text |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Entertainment.url | Modified File | Text |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Sports.url | Modified File | Text |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN.url | Modified File | Text |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Mail.url | Modified File | Text |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ZTE-\_1-Z0l.gif | Modified File | Image |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\8Vj kyoaTN1vy L0-Vsr.mp4 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\9zW0DyjAU1Nrc.mkv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\fXPAxGgq.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\-cJIpQCkg1\20r7oIjlUFUIkP.ppt | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\-cJIpQCkg1\ALIdU0.docx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\-cJIpQCkg1\C0 _B8qINeQrUbrt.csv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NYC5ngf\NSqsuqL\3CYFm.jpg | Modified File | Image |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NYC5ngf\NSqsuqL\R7Kau5o.gif | Modified File | Image |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ZTE-\bbyLspO02\hd0ZLwcXz17isUe1hi_.gif | Modified File | Image |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\X98zhXIRm mnrxp8RLxH.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\-cJIpQCkg1\5T4sBt2\1Sx-VZ.ppt | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\-cJIpQCkg1\5T4sBt2\c7w3Be_K.pptx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gck8eKrR\-cJIpQCkg1\5T4sBt2\ieaOD_.odt | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\sVLD8M-oJOW\l65Ij.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\tKB6e7CXHXIzSLY\PVK83zEhiJoptl7F1vB.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Adobe\Acrobat\10.0\rdrmessage.zip | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\index.dat | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.cab | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\Deployment\deployment.properties | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\Data1.cab | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\jre1.7.0_45.msi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\sVLD8M-oJOW\xbwc4aSxlyVVrqHkiS\QDp9.mp4 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\tKB6e7CXHXIzSLY\4Ww3Dv\6xgwVggB1\3-Nhyh1JijVqK571B0JU\rbkgNDQN9sYCu5S0K.flv | Modified File | Video |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\tKB6e7CXHXIzSLY\4Ww3Dv\6xgwVggB1\3-Nhyh1JijVqK571B0JU\ZPlP3lZcQ.flv | Modified File | Video |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ynWwf7IE7\muLwtSyMNArdmekL\tKB6e7CXHXIzSLY\4Ww3Dv\6xgwVggB1\3-Nhyh1JijVqK571B0JU\_eu6q3E zyK.mp4 | Modified File | Stream |
Not Queried
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat | Modified File | Stream |
Not Queried
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\history\history.ie5\index.dat | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\script.ps1 | Dropped File | Text |
Not Queried
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\x9ohk109\geo[1].json | Dropped File | Text |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\_readme.txt | Dropped File | Text |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\Favorites.vss.gusau | Dropped File | Unknown |
Not Queried
|
...
|

WHOIS Domain Information
Domain Name | |
WHOIS Response |



This feature requires an online-connection to the VMRay backend.
An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".
Before
This feature requires an online-connection to the VMRay backend.
An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".
After
This feature requires an online-connection to the VMRay backend.
An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".




