VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Trojan.Ransom.AIG
|
virus.exe
Windows Exe (x86-32)
Created at 2020-08-21T23:37:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\virus.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x87dda0 |
Size Of Code | 0xe3000 |
Size Of Initialized Data | 0x1000 |
Size Of Uninitialized Data | 0x39a000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2012-01-29 18:49:03+00:00 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
UPX0 | 0x401000 | 0x39a000 | 0x0 | 0x200 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
UPX1 | 0x79b000 | 0xe3000 | 0xe3000 | 0x200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.87 |
.rsrc | 0x87e000 | 0x1000 | 0x400 | 0xe3200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.07 |
Imports (7)
»
KERNEL32.DLL (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | 0x0 | 0x87e194 | 0x47e194 | 0xe3394 | 0x0 |
GetProcAddress | 0x0 | 0x87e198 | 0x47e198 | 0xe3398 | 0x0 |
VirtualProtect | 0x0 | 0x87e19c | 0x47e19c | 0xe339c | 0x0 |
VirtualAlloc | 0x0 | 0x87e1a0 | 0x47e1a0 | 0xe33a0 | 0x0 |
VirtualFree | 0x0 | 0x87e1a4 | 0x47e1a4 | 0xe33a4 | 0x0 |
ExitProcess | 0x0 | 0x87e1a8 | 0x47e1a8 | 0xe33a8 | 0x0 |
advapi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegCloseKey | 0x0 | 0x87e1b0 | 0x47e1b0 | 0xe33b0 | 0x0 |
comctl32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InitCommonControls | 0x0 | 0x87e1b8 | 0x47e1b8 | 0xe33b8 | 0x0 |
gdi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateFontIndirectA | 0x0 | 0x87e1c0 | 0x47e1c0 | 0xe33c0 | 0x0 |
shell32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteA | 0x0 | 0x87e1c8 | 0x47e1c8 | 0xe33c8 | 0x0 |
shlwapi.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathMatchSpecA | 0x0 | 0x87e1d0 | 0x47e1d0 | 0xe33d0 | 0x0 |
user32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EndPaint | 0x0 | 0x87e1d8 | 0x47e1d8 | 0xe33d8 | 0x0 |
Memory Dumps (6)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
virus.exe | 1 | 0x00400000 | 0x0087EFFF | First Execution |
![]() |
32-bit | 0x0087DDA0 |
![]() |
![]() |
...
|
virus.exe | 1 | 0x00400000 | 0x0087EFFF | Content Changed |
![]() |
32-bit | 0x00401F87 |
![]() |
![]() |
...
|
virus.exe | 1 | 0x00400000 | 0x0087EFFF | Content Changed |
![]() |
32-bit | 0x004015E2 |
![]() |
![]() |
...
|
virus.exe | 1 | 0x00400000 | 0x0087EFFF | Content Changed |
![]() |
32-bit | 0x004015E2 |
![]() |
![]() |
...
|
virus.exe | 1 | 0x00400000 | 0x0087EFFF | Content Changed |
![]() |
32-bit | 0x004013C2 |
![]() |
![]() |
...
|
virus.exe | 1 | 0x00400000 | 0x0087EFFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.Ransom.AIG |
Malicious
|
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.JPG.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\PREVIEW.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\PREVIEW.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\PREVIEW.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\PREVIEW.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\PREVIEW.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\PREVIEW.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\PREVIEW.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\INDUST\PREVIEW.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\IRIS\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\JOURNAL\PREVIEW.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\LAYERS\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\LEVEL\PREVIEW.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\NETWORK\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PAPYRUS\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PIXEL\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PROFILE\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\QUAD\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RADIAL\PREVIEW.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\REFINED\PREVIEW.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RICEPAPR\PREVIEW.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RIPPLE\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RMNSQUE\PREVIEW.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SKY\PREVIEW.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SLATE\PREVIEW.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SONORA\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SPRING\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\STRTEDGE\PREVIEW.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SUMIPNTG\PREVIEW.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\WATER\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\WATERMAR\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00021_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00038_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00040_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00052_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00057_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00090_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00092_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00103_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00120_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00126_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00129_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00130_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00135_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00139_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00142_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00154_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00157_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00158_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00160_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00161_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00163_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00164_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00165_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00167_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00169_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00170_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00172_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00175_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00176_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD10890_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD10972_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD19563_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD19582_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\ELPHRG01.WAV | Modified File | Audio |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\J0214098.WAV | Modified File | Audio |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\J0234687.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\J0283209.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\J0284916.JPG | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\J0295241.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\J0300520.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\J0302827.JPG.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\J0302953.JPG.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\J0315447.JPG.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10253_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10254_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10263_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10264_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10265_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10266_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10267_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10268_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10297_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10298_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10299_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10300_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10301_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10302_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10336_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10337_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14513_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14514_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14515_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14528_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14529_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14530_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14531_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14532_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14533_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14565_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14578_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14579_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14581_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14582_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14583_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14654_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14655_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14656_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14691_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14692_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14693_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14752_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14753_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14754_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14756_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14757_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14790_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14791_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14792_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14793_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14795_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14828_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14829_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14831_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14832_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14866_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14867_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14868_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14869_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14870_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14871_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14980_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14981_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14982_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14984_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD15018_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD15019_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00011_.GIF.wannacry | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\PREVIEW.GIF.wannacry | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SATIN\PREVIEW.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\STUDIO\PREVIEW.GIF.wannacry | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00037_.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00171_.GIF.wannacry | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00174_.GIF.wannacry | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10255_.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10335_.GIF.wannacry | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14580_.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14794_.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14830_.GIF.wannacry | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14833_.GIF.wannacry | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Common Files\System\ado\HOW TO DECRYPT FILES.txt | Dropped File | Text |
Not Queried
|
...
|
»