VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Dropper, Trojan |
aoldtz.exe
Windows Exe (x86-32)
Created at 2019-09-13T13:57:00
Remarks
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\aoldtz.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-09-09 16:55 (UTC+2) |
Last Seen | 2019-09-13 15:19 (UTC+2) |
Names | Win32.Trojan.Filecoder |
Families | Filecoder |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4110a3 |
Size Of Code | 0x21400 |
Size Of Initialized Data | 0x3f400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-08-30 09:41:10+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x21374 | 0x21400 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.67 |
.rdata | 0x423000 | 0x2561c | 0x25800 | 0x21800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.63 |
.data | 0x449000 | 0x17e20 | 0x2000 | 0x47000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.01 |
.rsrc | 0x461000 | 0x1e0 | 0x200 | 0x49000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.72 |
.reloc | 0x462000 | 0x192c | 0x1a00 | 0x49200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.55 |
Imports (5)
»
KERNEL32.dll (112)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InitializeSListHead | 0x0 | 0x423040 | 0x47a44 | 0x46244 | 0x2e7 |
InterlockedPopEntrySList | 0x0 | 0x423044 | 0x47a48 | 0x46248 | 0x2f0 |
LocalFree | 0x0 | 0x423048 | 0x47a4c | 0x4624c | 0x348 |
GetFileSizeEx | 0x0 | 0x42304c | 0x47a50 | 0x46250 | 0x1f1 |
SetEndOfFile | 0x0 | 0x423050 | 0x47a54 | 0x46254 | 0x453 |
GetLastError | 0x0 | 0x423054 | 0x47a58 | 0x46258 | 0x202 |
SetFilePointerEx | 0x0 | 0x423058 | 0x47a5c | 0x4625c | 0x467 |
MoveFileExW | 0x0 | 0x42305c | 0x47a60 | 0x46260 | 0x360 |
GlobalAlloc | 0x0 | 0x423060 | 0x47a64 | 0x46264 | 0x2b3 |
GlobalFree | 0x0 | 0x423064 | 0x47a68 | 0x46268 | 0x2ba |
FindFirstFileW | 0x0 | 0x423068 | 0x47a6c | 0x4626c | 0x139 |
FindFirstVolumeW | 0x0 | 0x42306c | 0x47a70 | 0x46270 | 0x13f |
GetCommandLineW | 0x0 | 0x423070 | 0x47a74 | 0x46274 | 0x187 |
FindNextFileW | 0x0 | 0x423074 | 0x47a78 | 0x46278 | 0x145 |
GetCurrentProcess | 0x0 | 0x423078 | 0x47a7c | 0x4627c | 0x1c0 |
WaitForMultipleObjects | 0x0 | 0x42307c | 0x47a80 | 0x46280 | 0x4f7 |
GetEnvironmentVariableW | 0x0 | 0x423080 | 0x47a84 | 0x46284 | 0x1dc |
FindClose | 0x0 | 0x423084 | 0x47a88 | 0x46288 | 0x12e |
WaitForSingleObject | 0x0 | 0x423088 | 0x47a8c | 0x4628c | 0x4f9 |
GetFileAttributesW | 0x0 | 0x42308c | 0x47a90 | 0x46290 | 0x1ea |
SetFileAttributesW | 0x0 | 0x423090 | 0x47a94 | 0x46294 | 0x461 |
GetLogicalDriveStringsW | 0x0 | 0x423094 | 0x47a98 | 0x46298 | 0x208 |
lstrcatW | 0x0 | 0x423098 | 0x47a9c | 0x4629c | 0x53f |
GetSystemInfo | 0x0 | 0x42309c | 0x47aa0 | 0x462a0 | 0x273 |
MapViewOfFile | 0x0 | 0x4230a0 | 0x47aa4 | 0x462a4 | 0x357 |
SetVolumeMountPointW | 0x0 | 0x4230a4 | 0x47aa8 | 0x462a8 | 0x4ab |
FindVolumeClose | 0x0 | 0x4230a8 | 0x47aac | 0x462ac | 0x150 |
CreateProcessW | 0x0 | 0x4230ac | 0x47ab0 | 0x462b0 | 0xa8 |
CopyFileW | 0x0 | 0x4230b0 | 0x47ab4 | 0x462b4 | 0x75 |
GetVolumePathNamesForVolumeNameW | 0x0 | 0x4230b4 | 0x47ab8 | 0x462b8 | 0x2ad |
lstrcpyW | 0x0 | 0x4230b8 | 0x47abc | 0x462bc | 0x548 |
FindNextVolumeW | 0x0 | 0x4230bc | 0x47ac0 | 0x462c0 | 0x14a |
lstrcmpiW | 0x0 | 0x4230c0 | 0x47ac4 | 0x462c4 | 0x545 |
GetDriveTypeW | 0x0 | 0x4230c4 | 0x47ac8 | 0x462c8 | 0x1d3 |
GetExitCodeProcess | 0x0 | 0x4230c8 | 0x47acc | 0x462cc | 0x1df |
EnterCriticalSection | 0x0 | 0x4230cc | 0x47ad0 | 0x462d0 | 0xee |
WriteFile | 0x0 | 0x4230d0 | 0x47ad4 | 0x462d4 | 0x525 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4230d4 | 0x47ad8 | 0x462d8 | 0x2e3 |
LeaveCriticalSection | 0x0 | 0x4230d8 | 0x47adc | 0x462dc | 0x339 |
SetFilePointer | 0x0 | 0x4230dc | 0x47ae0 | 0x462e0 | 0x466 |
lstrcatA | 0x0 | 0x4230e0 | 0x47ae4 | 0x462e4 | 0x53e |
DeleteCriticalSection | 0x0 | 0x4230e4 | 0x47ae8 | 0x462e8 | 0xd1 |
lstrcpynA | 0x0 | 0x4230e8 | 0x47aec | 0x462ec | 0x54a |
GetComputerNameW | 0x0 | 0x4230ec | 0x47af0 | 0x462f0 | 0x18f |
GetSystemTime | 0x0 | 0x4230f0 | 0x47af4 | 0x462f4 | 0x277 |
WriteConsoleW | 0x0 | 0x4230f4 | 0x47af8 | 0x462f8 | 0x524 |
DecodePointer | 0x0 | 0x4230f8 | 0x47afc | 0x462fc | 0xca |
FlushFileBuffers | 0x0 | 0x4230fc | 0x47b00 | 0x46300 | 0x157 |
InterlockedPushEntrySList | 0x0 | 0x423100 | 0x47b04 | 0x46304 | 0x2f1 |
CreateFileMappingW | 0x0 | 0x423104 | 0x47b08 | 0x46308 | 0x8c |
CloseHandle | 0x0 | 0x423108 | 0x47b0c | 0x4630c | 0x52 |
InterlockedFlushSList | 0x0 | 0x42310c | 0x47b10 | 0x46310 | 0x2ee |
UnmapViewOfFile | 0x0 | 0x423110 | 0x47b14 | 0x46314 | 0x4d6 |
CreateFileW | 0x0 | 0x423114 | 0x47b18 | 0x46318 | 0x8f |
lstrlenA | 0x0 | 0x423118 | 0x47b1c | 0x4631c | 0x54d |
lstrcpynW | 0x0 | 0x42311c | 0x47b20 | 0x46320 | 0x54b |
lstrlenW | 0x0 | 0x423120 | 0x47b24 | 0x46324 | 0x54e |
ReadFile | 0x0 | 0x423124 | 0x47b28 | 0x46328 | 0x3c0 |
QueryPerformanceCounter | 0x0 | 0x423128 | 0x47b2c | 0x4632c | 0x3a7 |
CreateThread | 0x0 | 0x42312c | 0x47b30 | 0x46330 | 0xb5 |
Sleep | 0x0 | 0x423130 | 0x47b34 | 0x46334 | 0x4b2 |
VirtualQuery | 0x0 | 0x423134 | 0x47b38 | 0x46338 | 0x4f1 |
GetConsoleMode | 0x0 | 0x423138 | 0x47b3c | 0x4633c | 0x1ac |
GetConsoleCP | 0x0 | 0x42313c | 0x47b40 | 0x46340 | 0x19a |
GetProcessHeap | 0x0 | 0x423140 | 0x47b44 | 0x46344 | 0x24a |
SetStdHandle | 0x0 | 0x423144 | 0x47b48 | 0x46348 | 0x487 |
SetEnvironmentVariableA | 0x0 | 0x423148 | 0x47b4c | 0x4634c | 0x456 |
GetCurrentProcessId | 0x0 | 0x42314c | 0x47b50 | 0x46350 | 0x1c1 |
GetCurrentThreadId | 0x0 | 0x423150 | 0x47b54 | 0x46354 | 0x1c5 |
GetSystemTimeAsFileTime | 0x0 | 0x423154 | 0x47b58 | 0x46358 | 0x279 |
IsDebuggerPresent | 0x0 | 0x423158 | 0x47b5c | 0x4635c | 0x300 |
UnhandledExceptionFilter | 0x0 | 0x42315c | 0x47b60 | 0x46360 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x423160 | 0x47b64 | 0x46364 | 0x4a5 |
GetStartupInfoW | 0x0 | 0x423164 | 0x47b68 | 0x46368 | 0x263 |
IsProcessorFeaturePresent | 0x0 | 0x423168 | 0x47b6c | 0x4636c | 0x304 |
GetModuleHandleW | 0x0 | 0x42316c | 0x47b70 | 0x46370 | 0x218 |
TerminateProcess | 0x0 | 0x423170 | 0x47b74 | 0x46374 | 0x4c0 |
RtlUnwind | 0x0 | 0x423174 | 0x47b78 | 0x46378 | 0x418 |
SetLastError | 0x0 | 0x423178 | 0x47b7c | 0x4637c | 0x473 |
TlsAlloc | 0x0 | 0x42317c | 0x47b80 | 0x46380 | 0x4c5 |
TlsGetValue | 0x0 | 0x423180 | 0x47b84 | 0x46384 | 0x4c7 |
TlsSetValue | 0x0 | 0x423184 | 0x47b88 | 0x46388 | 0x4c8 |
TlsFree | 0x0 | 0x423188 | 0x47b8c | 0x4638c | 0x4c6 |
FreeLibrary | 0x0 | 0x42318c | 0x47b90 | 0x46390 | 0x162 |
GetProcAddress | 0x0 | 0x423190 | 0x47b94 | 0x46394 | 0x245 |
LoadLibraryExW | 0x0 | 0x423194 | 0x47b98 | 0x46398 | 0x33e |
RaiseException | 0x0 | 0x423198 | 0x47b9c | 0x4639c | 0x3b1 |
GetModuleHandleExW | 0x0 | 0x42319c | 0x47ba0 | 0x463a0 | 0x217 |
GetStdHandle | 0x0 | 0x4231a0 | 0x47ba4 | 0x463a4 | 0x264 |
GetModuleFileNameA | 0x0 | 0x4231a4 | 0x47ba8 | 0x463a8 | 0x213 |
MultiByteToWideChar | 0x0 | 0x4231a8 | 0x47bac | 0x463ac | 0x367 |
WideCharToMultiByte | 0x0 | 0x4231ac | 0x47bb0 | 0x463b0 | 0x511 |
ExitProcess | 0x0 | 0x4231b0 | 0x47bb4 | 0x463b4 | 0x119 |
GetACP | 0x0 | 0x4231b4 | 0x47bb8 | 0x463b8 | 0x168 |
HeapAlloc | 0x0 | 0x4231b8 | 0x47bbc | 0x463bc | 0x2cb |
HeapFree | 0x0 | 0x4231bc | 0x47bc0 | 0x463c0 | 0x2cf |
GetFileType | 0x0 | 0x4231c0 | 0x47bc4 | 0x463c4 | 0x1f3 |
CompareStringW | 0x0 | 0x4231c4 | 0x47bc8 | 0x463c8 | 0x64 |
LCMapStringW | 0x0 | 0x4231c8 | 0x47bcc | 0x463cc | 0x32d |
HeapReAlloc | 0x0 | 0x4231cc | 0x47bd0 | 0x463d0 | 0x2d2 |
HeapSize | 0x0 | 0x4231d0 | 0x47bd4 | 0x463d4 | 0x2d4 |
GetStringTypeW | 0x0 | 0x4231d4 | 0x47bd8 | 0x463d8 | 0x269 |
CreateProcessA | 0x0 | 0x4231d8 | 0x47bdc | 0x463dc | 0xa4 |
GetFileAttributesExW | 0x0 | 0x4231dc | 0x47be0 | 0x463e0 | 0x1e7 |
FindFirstFileExA | 0x0 | 0x4231e0 | 0x47be4 | 0x463e4 | 0x133 |
FindNextFileA | 0x0 | 0x4231e4 | 0x47be8 | 0x463e8 | 0x143 |
IsValidCodePage | 0x0 | 0x4231e8 | 0x47bec | 0x463ec | 0x30a |
GetOEMCP | 0x0 | 0x4231ec | 0x47bf0 | 0x463f0 | 0x237 |
GetCPInfo | 0x0 | 0x4231f0 | 0x47bf4 | 0x463f4 | 0x172 |
GetCommandLineA | 0x0 | 0x4231f4 | 0x47bf8 | 0x463f8 | 0x186 |
GetEnvironmentStringsW | 0x0 | 0x4231f8 | 0x47bfc | 0x463fc | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x4231fc | 0x47c00 | 0x46400 | 0x161 |
USER32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
wsprintfW | 0x0 | 0x423224 | 0x47c28 | 0x46428 | 0x333 |
wsprintfA | 0x0 | 0x423228 | 0x47c2c | 0x4642c | 0x332 |
ADVAPI32.dll (15)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegCloseKey | 0x0 | 0x423000 | 0x47a04 | 0x46204 | 0x230 |
RegSetValueExW | 0x0 | 0x423004 | 0x47a08 | 0x46208 | 0x27e |
RegCreateKeyW | 0x0 | 0x423008 | 0x47a0c | 0x4620c | 0x23c |
RegDeleteValueW | 0x0 | 0x42300c | 0x47a10 | 0x46210 | 0x248 |
RegOpenKeyW | 0x0 | 0x423010 | 0x47a14 | 0x46214 | 0x264 |
LookupPrivilegeValueW | 0x0 | 0x423014 | 0x47a18 | 0x46218 | 0x197 |
AdjustTokenPrivileges | 0x0 | 0x423018 | 0x47a1c | 0x4621c | 0x1f |
OpenProcessToken | 0x0 | 0x42301c | 0x47a20 | 0x46220 | 0x1f7 |
AllocateAndInitializeSid | 0x0 | 0x423020 | 0x47a24 | 0x46224 | 0x20 |
SetEntriesInAclW | 0x0 | 0x423024 | 0x47a28 | 0x46228 | 0x2a6 |
SetNamedSecurityInfoW | 0x0 | 0x423028 | 0x47a2c | 0x4622c | 0x2b1 |
FreeSid | 0x0 | 0x42302c | 0x47a30 | 0x46230 | 0x120 |
CryptAcquireContextW | 0x0 | 0x423030 | 0x47a34 | 0x46234 | 0xb1 |
CryptGenRandom | 0x0 | 0x423034 | 0x47a38 | 0x46238 | 0xc1 |
CryptReleaseContext | 0x0 | 0x423038 | 0x47a3c | 0x4623c | 0xcb |
SHELL32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteExW | 0x0 | 0x423214 | 0x47c18 | 0x46418 | 0x121 |
CommandLineToArgvW | 0x0 | 0x423218 | 0x47c1c | 0x4641c | 0x6 |
SHChangeNotify | 0x0 | 0x42321c | 0x47c20 | 0x46420 | 0x7f |
MPR.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetEnumResourceW | 0x0 | 0x423204 | 0x47c08 | 0x46408 | 0x1c |
WNetCloseEnum | 0x0 | 0x423208 | 0x47c0c | 0x4640c | 0x10 |
WNetOpenEnumW | 0x0 | 0x42320c | 0x47c10 | 0x46410 | 0x3d |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
aoldtz.exe | 1 | 0x01260000 | 0x012C3FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
aoldtz.exe | 1 | 0x01260000 | 0x012C3FFF | Final Dump | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
DeepScan:Generic.Ransom.GlobeImposter.C7080421 |
Malicious
|
C:\Users\Default User\Local Settings\IconCache.db.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\local\microsoft\windows media\12.0\wmsdkns.xml.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\local\microsoft\windows mail\oeold.xml.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\local\microsoft\media player\currentdatabase_372.wmdb.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\local\microsoft\media player\localmls_3.wmdb.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\local\microsoft\internet explorer\brndlog.bak.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\ntuser.dat.log.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\ntuser.dat.log1.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\ntuser.dat{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.tm.blf.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\ntuser.dat{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.tmcontainer00000000000000000001.regtrans-ms.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\ntuser.dat{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.tmcontainer00000000000000000002.regtrans-ms.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\ntuser.ini.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\videos\desktop.ini.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\desktop.ini.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\desktop.ini.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\internet explorer (64-bit).lnk.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\internet explorer.lnk.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\startup\desktop.ini.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\maintenance\desktop.ini.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\maintenance\help.lnk.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\administrative tools\desktop.ini.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\command prompt.lnk.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\desktop.ini.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\notepad.lnk.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\run.lnk.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\windows explorer.lnk.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\system tools\computer.lnk.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\system tools\control panel.lnk.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\system tools\desktop.ini.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\system tools\internet explorer (no add-ons).lnk.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\system tools\private character editor.lnk.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\accessibility\desktop.ini.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\accessibility\ease of access.lnk.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\accessibility\magnify.lnk.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\accessibility\narrator.lnk.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessories\accessibility\on-screen keyboard.lnk.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\sendto\compressed (zipped) folder.zfsendtotarget.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\sendto\desktop (create shortcut).desklink.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\sendto\desktop.ini.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\sendto\fax recipient.lnk.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\sendto\mail recipient.mapimail.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\searches\desktop.ini.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\searches\everywhere.search-ms.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\searches\indexed locations.search-ms.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\saved games\desktop.ini.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\recent\desktop.ini.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\recent\customdestinations\1b4dd67f29cb1962.customdestinations-ms.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\recent\customdestinations\5afe4de1b92fc382.customdestinations-ms.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\recent\customdestinations\7e4dca80246863e3.customdestinations-ms.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\recent\automaticdestinations\1b4dd67f29cb1962.automaticdestinations-ms.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\pictures\desktop.ini.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\documents\desktop.ini.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\music\desktop.ini.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\local\microsoft\windows\temporary internet files\desktop.ini.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\local\microsoft\windows\temporary internet files\content.ie5\desktop.ini.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat.ares865 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\default\appdata\local\microsoft\windows\temporary internet files\content.ie5\x9ohk109\desktop.ini.ares865 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Public\desktop.ini.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Videos\desktop.ini.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Videos\Sample Videos\desktop.ini.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Videos\Sample Videos\Wildlife.wmv.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Recorded TV\desktop.ini.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Recorded TV\Sample Media\desktop.ini.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Recorded TV\Sample Media\win7_scenic-demoshort_raw.wtv.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Pictures\desktop.ini.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Pictures\Sample Pictures\desktop.ini.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Pictures\Sample Pictures\Koala.jpg.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Pictures\Sample Pictures\Penguins.jpg.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Music\desktop.ini.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Music\Sample Music\desktop.ini.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Music\Sample Music\Kalimba.mp3.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ids.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\Public\Music\Sample Music\Maid with the Flaxen Hair.mp3.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Java\jre7\lib\zi\America\St_Thomas.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Libraries\desktop.ini.Ares865 | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\Public\Libraries\RecordedTV.library-ms.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Java\jre7\lib\management\jmxremote.password.template.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Java\jre7\lib\management\snmp.acl.template.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Java\jre7\lib\deploy\ffjcext.zip.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Downloads\desktop.ini.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Google\Chrome\Application\chrome.VisualElementsManifest.xml.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Documents\desktop.ini.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Common Files\Java\Java Update\task.xml.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Common Files\Java\Java Update\task64.xml.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroPDF.CAT.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Desktop\Adobe Reader X.lnk.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Desktop\desktop.ini.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Desktop\Google Chrome.lnk.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Desktop\Mozilla Firefox.lnk.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\PDFShell.CAT.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Resource\TypeSupport\Unicode\ICU\ctl_gb18030.cnv.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers\Proximity\11.00\araphon.env.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers\Proximity\11.00\bulphon.env.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers\Proximity\11.00\danphon.env.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers\Proximity\11.00\engphon.env.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers\Proximity\11.00\estphon.env.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers\Proximity\11.00\finphon.env.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers\Proximity\11.00\hrvphon.env.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers\Proximity\11.00\lavphon.env.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers\Proximity\11.00\litphon.env.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers\Proximity\11.00\rumphon.env.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Resource\Linguistics\Providers\Proximity\11.00\slvphon.env.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia\MPP\Flash.CAT.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia\MPP\Mcimpp.CAT.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia\MPP\QuickTime.CAT.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Multimedia\MPP\WindowsMedia.CAT.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Music\Sample Music\HOW TO BACK YOUR FILES.exe | Dropped File | Binary |
Unknown
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x401af4 |
Size Of Code | 0xfe00 |
Size Of Initialized Data | 0xe400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-08-27 15:03:08+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xfc2b | 0xfe00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x411000 | 0xbcd2 | 0xbe00 | 0x10200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.79 |
.data | 0x41d000 | 0x1290 | 0xa00 | 0x1c000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.17 |
.rsrc | 0x41f000 | 0x1e0 | 0x200 | 0x1ca00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.71 |
.reloc | 0x420000 | 0xf94 | 0x1000 | 0x1cc00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.45 |
Imports (4)
»
KERNEL32.dll (67)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
lstrlenW | 0x0 | 0x411000 | 0x1c540 | 0x1b740 | 0x54e |
lstrlenA | 0x0 | 0x411004 | 0x1c544 | 0x1b744 | 0x54d |
CreateFileW | 0x0 | 0x411008 | 0x1c548 | 0x1b748 | 0x8f |
CloseHandle | 0x0 | 0x41100c | 0x1c54c | 0x1b74c | 0x52 |
InitializeSListHead | 0x0 | 0x411010 | 0x1c550 | 0x1b750 | 0x2e7 |
GlobalAlloc | 0x0 | 0x411014 | 0x1c554 | 0x1b754 | 0x2b3 |
GlobalFree | 0x0 | 0x411018 | 0x1c558 | 0x1b758 | 0x2ba |
DecodePointer | 0x0 | 0x41101c | 0x1c55c | 0x1b75c | 0xca |
FlushFileBuffers | 0x0 | 0x411020 | 0x1c560 | 0x1b760 | 0x157 |
SetFilePointerEx | 0x0 | 0x411024 | 0x1c564 | 0x1b764 | 0x467 |
GetConsoleMode | 0x0 | 0x411028 | 0x1c568 | 0x1b768 | 0x1ac |
GetConsoleCP | 0x0 | 0x41102c | 0x1c56c | 0x1b76c | 0x19a |
GetProcessHeap | 0x0 | 0x411030 | 0x1c570 | 0x1b770 | 0x24a |
SetStdHandle | 0x0 | 0x411034 | 0x1c574 | 0x1b774 | 0x487 |
LCMapStringW | 0x0 | 0x411038 | 0x1c578 | 0x1b778 | 0x32d |
FreeEnvironmentStringsW | 0x0 | 0x41103c | 0x1c57c | 0x1b77c | 0x161 |
GetEnvironmentStringsW | 0x0 | 0x411040 | 0x1c580 | 0x1b780 | 0x1da |
GetCommandLineW | 0x0 | 0x411044 | 0x1c584 | 0x1b784 | 0x187 |
GetCommandLineA | 0x0 | 0x411048 | 0x1c588 | 0x1b788 | 0x186 |
GetCPInfo | 0x0 | 0x41104c | 0x1c58c | 0x1b78c | 0x172 |
GetOEMCP | 0x0 | 0x411050 | 0x1c590 | 0x1b790 | 0x237 |
IsValidCodePage | 0x0 | 0x411054 | 0x1c594 | 0x1b794 | 0x30a |
UnhandledExceptionFilter | 0x0 | 0x411058 | 0x1c598 | 0x1b798 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x41105c | 0x1c59c | 0x1b79c | 0x4a5 |
GetCurrentProcess | 0x0 | 0x411060 | 0x1c5a0 | 0x1b7a0 | 0x1c0 |
TerminateProcess | 0x0 | 0x411064 | 0x1c5a4 | 0x1b7a4 | 0x4c0 |
IsProcessorFeaturePresent | 0x0 | 0x411068 | 0x1c5a8 | 0x1b7a8 | 0x304 |
QueryPerformanceCounter | 0x0 | 0x41106c | 0x1c5ac | 0x1b7ac | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x411070 | 0x1c5b0 | 0x1b7b0 | 0x1c1 |
GetCurrentThreadId | 0x0 | 0x411074 | 0x1c5b4 | 0x1b7b4 | 0x1c5 |
GetSystemTimeAsFileTime | 0x0 | 0x411078 | 0x1c5b8 | 0x1b7b8 | 0x279 |
IsDebuggerPresent | 0x0 | 0x41107c | 0x1c5bc | 0x1b7bc | 0x300 |
GetStartupInfoW | 0x0 | 0x411080 | 0x1c5c0 | 0x1b7c0 | 0x263 |
GetModuleHandleW | 0x0 | 0x411084 | 0x1c5c4 | 0x1b7c4 | 0x218 |
RtlUnwind | 0x0 | 0x411088 | 0x1c5c8 | 0x1b7c8 | 0x418 |
GetLastError | 0x0 | 0x41108c | 0x1c5cc | 0x1b7cc | 0x202 |
SetLastError | 0x0 | 0x411090 | 0x1c5d0 | 0x1b7d0 | 0x473 |
EnterCriticalSection | 0x0 | 0x411094 | 0x1c5d4 | 0x1b7d4 | 0xee |
LeaveCriticalSection | 0x0 | 0x411098 | 0x1c5d8 | 0x1b7d8 | 0x339 |
DeleteCriticalSection | 0x0 | 0x41109c | 0x1c5dc | 0x1b7dc | 0xd1 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4110a0 | 0x1c5e0 | 0x1b7e0 | 0x2e3 |
TlsAlloc | 0x0 | 0x4110a4 | 0x1c5e4 | 0x1b7e4 | 0x4c5 |
TlsGetValue | 0x0 | 0x4110a8 | 0x1c5e8 | 0x1b7e8 | 0x4c7 |
TlsSetValue | 0x0 | 0x4110ac | 0x1c5ec | 0x1b7ec | 0x4c8 |
TlsFree | 0x0 | 0x4110b0 | 0x1c5f0 | 0x1b7f0 | 0x4c6 |
FreeLibrary | 0x0 | 0x4110b4 | 0x1c5f4 | 0x1b7f4 | 0x162 |
GetProcAddress | 0x0 | 0x4110b8 | 0x1c5f8 | 0x1b7f8 | 0x245 |
LoadLibraryExW | 0x0 | 0x4110bc | 0x1c5fc | 0x1b7fc | 0x33e |
RaiseException | 0x0 | 0x4110c0 | 0x1c600 | 0x1b800 | 0x3b1 |
GetStdHandle | 0x0 | 0x4110c4 | 0x1c604 | 0x1b804 | 0x264 |
WriteFile | 0x0 | 0x4110c8 | 0x1c608 | 0x1b808 | 0x525 |
GetModuleFileNameA | 0x0 | 0x4110cc | 0x1c60c | 0x1b80c | 0x213 |
MultiByteToWideChar | 0x0 | 0x4110d0 | 0x1c610 | 0x1b810 | 0x367 |
WideCharToMultiByte | 0x0 | 0x4110d4 | 0x1c614 | 0x1b814 | 0x511 |
ExitProcess | 0x0 | 0x4110d8 | 0x1c618 | 0x1b818 | 0x119 |
GetModuleHandleExW | 0x0 | 0x4110dc | 0x1c61c | 0x1b81c | 0x217 |
GetACP | 0x0 | 0x4110e0 | 0x1c620 | 0x1b820 | 0x168 |
HeapFree | 0x0 | 0x4110e4 | 0x1c624 | 0x1b824 | 0x2cf |
HeapAlloc | 0x0 | 0x4110e8 | 0x1c628 | 0x1b828 | 0x2cb |
HeapReAlloc | 0x0 | 0x4110ec | 0x1c62c | 0x1b82c | 0x2d2 |
HeapSize | 0x0 | 0x4110f0 | 0x1c630 | 0x1b830 | 0x2d4 |
GetFileType | 0x0 | 0x4110f4 | 0x1c634 | 0x1b834 | 0x1f3 |
GetStringTypeW | 0x0 | 0x4110f8 | 0x1c638 | 0x1b838 | 0x269 |
FindClose | 0x0 | 0x4110fc | 0x1c63c | 0x1b83c | 0x12e |
FindFirstFileExA | 0x0 | 0x411100 | 0x1c640 | 0x1b840 | 0x133 |
FindNextFileA | 0x0 | 0x411104 | 0x1c644 | 0x1b844 | 0x143 |
WriteConsoleW | 0x0 | 0x411108 | 0x1c648 | 0x1b848 | 0x524 |
USER32.dll (13)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegisterClassExW | 0x0 | 0x41112c | 0x1c66c | 0x1b86c | 0x24d |
UpdateWindow | 0x0 | 0x411130 | 0x1c670 | 0x1b870 | 0x311 |
PostQuitMessage | 0x0 | 0x411134 | 0x1c674 | 0x1b874 | 0x237 |
GetClientRect | 0x0 | 0x411138 | 0x1c678 | 0x1b878 | 0x114 |
GetWindowLongW | 0x0 | 0x41113c | 0x1c67c | 0x1b87c | 0x196 |
SetWindowLongW | 0x0 | 0x411140 | 0x1c680 | 0x1b880 | 0x2c4 |
DefWindowProcW | 0x0 | 0x411144 | 0x1c684 | 0x1b884 | 0x9c |
CreateWindowExW | 0x0 | 0x411148 | 0x1c688 | 0x1b888 | 0x6e |
GetSystemMetrics | 0x0 | 0x41114c | 0x1c68c | 0x1b88c | 0x17e |
GetMessageW | 0x0 | 0x411150 | 0x1c690 | 0x1b890 | 0x15d |
ShowWindow | 0x0 | 0x411154 | 0x1c694 | 0x1b894 | 0x2df |
DispatchMessageW | 0x0 | 0x411158 | 0x1c698 | 0x1b898 | 0xaf |
TranslateMessage | 0x0 | 0x41115c | 0x1c69c | 0x1b89c | 0x2fc |
ole32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
OleUninitialize | 0x0 | 0x411164 | 0x1c6a4 | 0x1b8a4 | 0x149 |
OleSetContainedObject | 0x0 | 0x411168 | 0x1c6a8 | 0x1b8a8 | 0x146 |
OleCreate | 0x0 | 0x41116c | 0x1c6ac | 0x1b8ac | 0x119 |
OleInitialize | 0x0 | 0x411170 | 0x1c6b0 | 0x1b8b0 | 0x132 |
OLEAUT32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysAllocString | 0x2 | 0x411110 | 0x1c650 | 0x1b850 | - |
SafeArrayCreate | 0xf | 0x411114 | 0x1c654 | 0x1b854 | - |
SafeArrayAccessData | 0x17 | 0x411118 | 0x1c658 | 0x1b858 | - |
VariantClear | 0x9 | 0x41111c | 0x1c65c | 0x1b85c | - |
VariantInit | 0x8 | 0x411120 | 0x1c660 | 0x1b860 | - |
SafeArrayDestroy | 0x10 | 0x411124 | 0x1c664 | 0x1b864 | - |
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\accessibility.CAT.Ares865 | Dropped File | Stream |
Unknown
|
...
|
»