Spyware Ransomware
Maze ChaCha Mal/Generic-S
Created on 2022-01-02T12:03:00
3885589a3c94d0475a6d994e4644e682f4cff93f8b4d65f37508ffe706861363.exe
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "37 minutes, 40 seconds" to "22 seconds" to reveal dormant functionality.
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\kEecfMwgj\Desktop\3885589a3c94d0475a6d994e4644e682f4cff93f8b4d65f37508ffe706861363.exe | Sample File | Binary |
malicious
|
...
|
Verdict |
malicious
|
Names | Mal/Generic-S |
Image Base | 0x400000 |
Entry Point | 0x407a2d |
Size Of Code | 0x11c00 |
Size Of Initialized Data | 0x61600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-05-13 05:04:13+00:00 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x11a33 | 0x11c00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.64 |
.rdata | 0x413000 | 0x6a50 | 0x6c00 | 0x12000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.7 |
.data | 0x41a000 | 0x594e0 | 0x57600 | 0x18c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.99 |
.reloc | 0x474000 | 0x134c | 0x1400 | 0x70200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.45 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MessageBoxA | - | 0x413190 | 0x192d8 | 0x182d8 | 0x246 |
wsprintfW | - | 0x413194 | 0x192dc | 0x182dc | 0x37b |
DeferWindowPos | - | 0x413198 | 0x192e0 | 0x182e0 | 0xa2 |
AnimateWindow | - | 0x41319c | 0x192e4 | 0x182e4 | 0x7 |
MessageBoxW | - | 0x4131a0 | 0x192e8 | 0x182e8 | 0x24d |
DestroyWindow | - | 0x4131a4 | 0x192ec | 0x182ec | 0xad |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetPaletteEntries | - | 0x413020 | 0x19168 | 0x18168 | 0x2f7 |
SelectPalette | - | 0x413024 | 0x1916c | 0x1816c | 0x2d5 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MoveFileExA | - | 0x41302c | 0x19174 | 0x18174 | 0x3c9 |
GetWindowsDirectoryA | - | 0x413030 | 0x19178 | 0x18178 | 0x30f |
CreateFileA | - | 0x413034 | 0x1917c | 0x1817c | 0xba |
GetFileSize | - | 0x413038 | 0x19180 | 0x18180 | 0x23b |
LocalAlloc | - | 0x41303c | 0x19184 | 0x18184 | 0x3ae |
ReadFile | - | 0x413040 | 0x19188 | 0x18188 | 0x44f |
GetVersionExA | - | 0x413044 | 0x1918c | 0x1818c | 0x304 |
WriteFile | - | 0x413048 | 0x19190 | 0x18190 | 0x5df |
DeviceIoControl | - | 0x41304c | 0x19194 | 0x18194 | 0x112 |
OpenMutexW | - | 0x413050 | 0x19198 | 0x18198 | 0x3ea |
CreateMutexW | - | 0x413054 | 0x1919c | 0x1819c | 0xd1 |
lstrlenA | - | 0x413058 | 0x191a0 | 0x181a0 | 0x608 |
GetModuleHandleA | - | 0x41305c | 0x191a4 | 0x181a4 | 0x264 |
LoadLibraryA | - | 0x413060 | 0x191a8 | 0x181a8 | 0x3a5 |
CloseHandle | - | 0x413064 | 0x191ac | 0x181ac | 0x7f |
lstrcatA | - | 0x413068 | 0x191b0 | 0x181b0 | 0x5f9 |
GetProcAddress | - | 0x41306c | 0x191b4 | 0x181b4 | 0x29d |
VirtualQuery | - | 0x413070 | 0x191b8 | 0x181b8 | 0x5a1 |
TlsGetValue | - | 0x413074 | 0x191bc | 0x181bc | 0x573 |
VirtualProtect | - | 0x413078 | 0x191c0 | 0x181c0 | 0x59f |
IsBadReadPtr | - | 0x41307c | 0x191c4 | 0x181c4 | 0x35e |
WaitForSingleObject | - | 0x413080 | 0x191c8 | 0x181c8 | 0x5a9 |
VirtualFree | - | 0x413084 | 0x191cc | 0x181cc | 0x59c |
FreeLibrary | - | 0x413088 | 0x191d0 | 0x181d0 | 0x19e |
ExitProcess | - | 0x41308c | 0x191d4 | 0x181d4 | 0x151 |
TlsSetValue | - | 0x413090 | 0x191d8 | 0x181d8 | 0x574 |
lstrcmpA | - | 0x413094 | 0x191dc | 0x181dc | 0x5fc |
OutputDebugStringW | - | 0x413098 | 0x191e0 | 0x181e0 | 0x3fa |
VirtualAlloc | - | 0x41309c | 0x191e4 | 0x181e4 | 0x599 |
CreateTimerQueueTimer | - | 0x4130a0 | 0x191e8 | 0x181e8 | 0xf0 |
Sleep | - | 0x4130a4 | 0x191ec | 0x181ec | 0x550 |
ExitThread | - | 0x4130a8 | 0x191f0 | 0x181f0 | 0x152 |
FlushFileBuffers | - | 0x4130ac | 0x191f4 | 0x181f4 | 0x192 |
GetConsoleCP | - | 0x4130b0 | 0x191f8 | 0x181f8 | 0x1dc |
GetConsoleMode | - | 0x4130b4 | 0x191fc | 0x181fc | 0x1ee |
SetStdHandle | - | 0x4130b8 | 0x19200 | 0x18200 | 0x520 |
SetFilePointerEx | - | 0x4130bc | 0x19204 | 0x18204 | 0x4fc |
WriteConsoleW | - | 0x4130c0 | 0x19208 | 0x18208 | 0x5de |
lstrcpyA | - | 0x4130c4 | 0x1920c | 0x1820c | 0x602 |
RaiseException | - | 0x4130c8 | 0x19210 | 0x18210 | 0x43f |
GetStringTypeW | - | 0x4130cc | 0x19214 | 0x18214 | 0x2c5 |
EncodePointer | - | 0x4130d0 | 0x19218 | 0x18218 | 0x121 |
DecodePointer | - | 0x4130d4 | 0x1921c | 0x1821c | 0xfe |
RtlUnwind | - | 0x4130d8 | 0x19220 | 0x18220 | 0x4ac |
GetCommandLineA | - | 0x4130dc | 0x19224 | 0x18224 | 0x1c8 |
IsProcessorFeaturePresent | - | 0x4130e0 | 0x19228 | 0x18228 | 0x36d |
HeapAlloc | - | 0x4130e4 | 0x1922c | 0x1822c | 0x32f |
CreateFileW | - | 0x4130e8 | 0x19230 | 0x18230 | 0xc2 |
GetLastError | - | 0x4130ec | 0x19234 | 0x18234 | 0x250 |
GetModuleHandleExW | - | 0x4130f0 | 0x19238 | 0x18238 | 0x266 |
MultiByteToWideChar | - | 0x4130f4 | 0x1923c | 0x1823c | 0x3d1 |
WideCharToMultiByte | - | 0x4130f8 | 0x19240 | 0x18240 | 0x5cb |
HeapSize | - | 0x4130fc | 0x19244 | 0x18244 | 0x338 |
HeapFree | - | 0x413100 | 0x19248 | 0x18248 | 0x333 |
SetLastError | - | 0x413104 | 0x1924c | 0x1824c | 0x50a |
GetCurrentThreadId | - | 0x413108 | 0x19250 | 0x18250 | 0x20e |
GetProcessHeap | - | 0x41310c | 0x19254 | 0x18254 | 0x2a2 |
GetStdHandle | - | 0x413110 | 0x19258 | 0x18258 | 0x2c0 |
GetFileType | - | 0x413114 | 0x1925c | 0x1825c | 0x23e |
DeleteCriticalSection | - | 0x413118 | 0x19260 | 0x18260 | 0x105 |
GetStartupInfoW | - | 0x41311c | 0x19264 | 0x18264 | 0x2be |
GetModuleFileNameA | - | 0x413120 | 0x19268 | 0x18268 | 0x262 |
GetModuleFileNameW | - | 0x413124 | 0x1926c | 0x1826c | 0x263 |
QueryPerformanceCounter | - | 0x413128 | 0x19270 | 0x18270 | 0x42d |
GetCurrentProcessId | - | 0x41312c | 0x19274 | 0x18274 | 0x20a |
GetSystemTimeAsFileTime | - | 0x413130 | 0x19278 | 0x18278 | 0x2d6 |
GetEnvironmentStringsW | - | 0x413134 | 0x1927c | 0x1827c | 0x227 |
FreeEnvironmentStringsW | - | 0x413138 | 0x19280 | 0x18280 | 0x19d |
UnhandledExceptionFilter | - | 0x41313c | 0x19284 | 0x18284 | 0x580 |
SetUnhandledExceptionFilter | - | 0x413140 | 0x19288 | 0x18288 | 0x541 |
InitializeCriticalSectionAndSpinCount | - | 0x413144 | 0x1928c | 0x1828c | 0x348 |
GetCurrentProcess | - | 0x413148 | 0x19290 | 0x18290 | 0x209 |
TerminateProcess | - | 0x41314c | 0x19294 | 0x18294 | 0x55f |
TlsAlloc | - | 0x413150 | 0x19298 | 0x18298 | 0x571 |
TlsFree | - | 0x413154 | 0x1929c | 0x1829c | 0x572 |
GetModuleHandleW | - | 0x413158 | 0x192a0 | 0x182a0 | 0x267 |
EnterCriticalSection | - | 0x41315c | 0x192a4 | 0x182a4 | 0x125 |
LeaveCriticalSection | - | 0x413160 | 0x192a8 | 0x182a8 | 0x3a2 |
IsDebuggerPresent | - | 0x413164 | 0x192ac | 0x182ac | 0x367 |
LoadLibraryExW | - | 0x413168 | 0x192b0 | 0x182b0 | 0x3a7 |
IsValidCodePage | - | 0x41316c | 0x192b4 | 0x182b4 | 0x372 |
GetACP | - | 0x413170 | 0x192b8 | 0x182b8 | 0x1a4 |
GetOEMCP | - | 0x413174 | 0x192bc | 0x182bc | 0x286 |
GetCPInfo | - | 0x413178 | 0x192c0 | 0x182c0 | 0x1b3 |
HeapReAlloc | - | 0x41317c | 0x192c4 | 0x182c4 | 0x336 |
LCMapStringW | - | 0x413180 | 0x192c8 | 0x182c8 | 0x396 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EncryptionDisable | - | 0x413000 | 0x19148 | 0x18148 | 0x10b |
EqualDomainSid | - | 0x413004 | 0x1914c | 0x1814c | 0x116 |
LsaCreateTrustedDomainEx | - | 0x413008 | 0x19150 | 0x18150 | 0x1b7 |
LsaClose | - | 0x41300c | 0x19154 | 0x18154 | 0x1b3 |
AreAllAccessesGranted | - | 0x413010 | 0x19158 | 0x18158 | 0x22 |
InitializeSecurityDescriptor | - | 0x413014 | 0x1915c | 0x1815c | 0x18d |
LookupAccountSidW | - | 0x413018 | 0x19160 | 0x18160 | 0x1a7 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LsaConnectUntrusted | - | 0x413188 | 0x192d0 | 0x182d0 | 0x26 |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
3885589a3c94d0475a6d994e4644e682f4cff93f8b4d65f37508ffe706861363.exe | 1 | 0x00140000 | 0x001B5FFF | Relevant Image |
![]() |
32-bit | 0x00148580 |
![]() |
...
|
buffer | 1 | 0x001C0000 | 0x001C0253 | Marked Executable |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E14FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E25FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E26FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E25FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E24FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E23FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E21FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E28FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E22FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E22FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1BFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1BFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1AFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E27FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E23FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E18FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1BFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1DFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1CFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E25FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1DFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E14FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E19FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1EFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E24FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E27FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E20FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E11FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E11FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E11FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E11FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E11FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E11FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E11FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E11FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E11FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E11FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E11FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
desktop (create shortcut).desklink | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E11FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1EFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1BFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E13FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E24FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E11FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E27FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E20FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1CFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E27FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E26FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1CFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E23FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E20FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1DFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1EFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1CFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E13FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1AFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E24FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1EFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1DFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1DFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E24FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E23FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E12FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E18FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1EFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1EFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E25FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E14FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E13FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1EFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E28FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E17FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E22FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1CFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E18FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E25FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1EFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E25FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E14FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E23FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E17FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E11FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E26FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E11FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E25FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1DFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1EFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1EFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E23FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1AFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1CFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E27FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E17FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E28FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E16FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1BFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1FFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E14FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1CFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1DFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1DFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E17FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1AFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E16FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E27FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1FFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E17FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E17FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1EFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E16FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E12FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E28FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E19FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E15FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E14FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E14FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E21FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E20FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1BFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E23FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E14FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1BFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E22FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E14FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1BFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E21FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1DFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1CFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E28FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1BFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E14FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E14FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E17FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1CFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1EFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1BFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E23FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1AFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1DFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E23FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1FFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E18FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1DFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E22FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1CFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1EFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E26FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E16FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E27FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E17FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E19FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E11FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1AFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E19FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E13FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E25FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1BFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E18FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E24FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E11FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E26FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1AFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E23FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E26FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E15FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E21FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E22FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E16FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1AFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1FFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1FFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E22FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E20FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E17FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E26FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1EFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E17FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E21FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E28FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E21FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E27FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E21FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E23FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E16FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E11FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E22FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E12FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E17FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E14FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1CFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E19FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E21FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E11FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E23FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E21FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1DFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E15FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E15FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E19FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E21FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E16FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E23FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1FFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E24FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E24FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E13FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E16FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E20FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E18FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E25FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E24FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1DFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1FFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1FFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E21FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E21FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E18FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E25FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E24FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E24FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E1CFFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E19FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E28FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x01E10000 | 0x01E24FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
3885589a3c94d0475a6d994e4644e682f4cff93f8b4d65f37508ffe706861363.exe | 1 | 0x00140000 | 0x001B5FFF | Final Dump |
![]() |
32-bit | - |
![]() |
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Recovery\d327d5c2-7147-11eb-9862-d731c5aaa7a9\boot.sdi | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Feeds\FeedsStore.feedsdb-ms | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Home~.feed-ms | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Work~.feed-ms | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Feeds\Microsoft Feeds~\MSNBC News~.feed-ms | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\Web Slice Gallery~.feed-ms | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Feeds Cache\index.dat | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Internet Explorer\brndlog.bak | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Internet Explorer\brndlog.txt | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\CurrentDatabase_372.wmdb | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\LocalMLS_3.wmdb | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00010C6E\01_Music_auto_rated_at_5_stars.wpl | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00010C6E\02_Music_added_in_the_last_month.wpl | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00010C6E\03_Music_rated_at_4_or_5_stars.wpl | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00010C6E\04_Music_played_in_the_last_month.wpl | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00010C6E\05_Pictures_taken_in_the_last_month.wpl | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00010C6E\06_Pictures_rated_4_or_5_stars.wpl | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00010C6E\07_TV_recorded_in_the_last_week.wpl | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00010C6E\08_Video_rated_at_4_or_5_stars.wpl | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00010C6E\09_Music_played_the_most.wpl | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00010C6E\10_All_Music.wpl | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00010C6E\11_All_Pictures.wpl | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Media Player\Sync Playlists\en-US\00010C6E\12_All_Video.wpl | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows\Explorer\ExplorerStartupLog.etl | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows\Explorer\ExplorerStartupLog_RunOnce.etl | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows\UsrClass.dat | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows\UsrClass.dat{0f6d7aa7-f51a-11df-ae0e-001d09f21116}.TM.blf | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows\UsrClass.dat{0f6d7aa7-f51a-11df-ae0e-001d09f21116}.TMContainer00000000000000000001.regtrans-ms | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows\UsrClass.dat{0f6d7aa7-f51a-11df-ae0e-001d09f21116}.TMContainer00000000000000000002.regtrans-ms | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\account{1CD43F3B-668B-4CA8-B816-34F74122EC0F}.oeaccount | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\account{AF0DB737-2EF9-4633-BF5E-1A6761ED1577}.oeaccount | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Backup\new\edb00001.log | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Backup\new\WindowsMail.MSMessageStore | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Backup\new\WindowsMail.pat | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\edb.chk | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\edb.log | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\edb00001.log | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\edbres00001.jrs | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\edbres00002.jrs | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\oeold.xml | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.htm | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.htm | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Green Bubbles.htm | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Hand Prints.htm | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Orange Circles.htm | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.htm | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.htm | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Roses.jpg | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Shades of Blue.htm | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Soft Blue.htm | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.htm | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\WindowsMail.MSMessageStore | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\WindowsMail.pat | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.DTD | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.XML | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B2238AACCEDC3F1FFE8E7EB5F575EC9 | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B2238AACCEDC3F1FFE8E7EB5F575EC9 | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015 | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Protect\S-1-5-21-3111613574-2524581245-2586426736-500\be5b4fbd-cb99-45f5-9462-5f896dd3a6b9 | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies\index.dat | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Libraries\Documents.library-ms | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Libraries\Music.library-ms | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Libraries\Pictures.library-ms | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Libraries\Videos.library-ms | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5afe4de1b92fc382.customDestinations-ms | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Run.lnk | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\computer.lnk | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Control Panel.lnk | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk | Modified File | Stream |
malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Recovery\d327d5c2-7147-11eb-9862-d731c5aaa7a9\Winre.wim | Modified File | Stream |
clean
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db | Modified File | Stream |
clean
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db | Modified File | Stream |
clean
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db | Modified File | Stream |
clean
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db | Modified File | Stream |
clean
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\account{047EF9CE-9C1F-4250-9CA7-D206DB8B643C}.oeaccount | Modified File | Stream |
clean
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Sidebar\Settings.ini | Modified File | Stream |
clean
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Protect\CREDHIST | Modified File | Stream |
clean
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Protect\S-1-5-21-3111613574-2524581245-2586426736-500\Preferred | Modified File | Stream |
clean
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\1b4dd67f29cb1962.customDestinations-ms | Modified File | Stream |
clean
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\7e4dca80246863e3.customDestinations-ms | Modified File | Stream |
clean
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Compressed (zipped) Folder.ZFSendToTarget | Modified File | Stream |
clean
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Desktop (create shortcut).DeskLink | Modified File | Stream |
clean
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Mail Recipient.MAPIMail | Modified File | Stream |
clean
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk | Modified File | Binary |
clean
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk | Modified File | Stream |
clean
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Help.lnk | Modified File | Stream |
clean
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk | Modified File | Stream |
clean
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg | Modified File | Stream |
clean
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\Contacts\Administrator.contact | Modified File | Stream |
clean
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
MazeEncryptedFile | File encrypted by Maze Ransomware | Ransomware |
5/5
|
...
|
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies\\olvrr9ld.dat | Dropped File | Unknown |
clean
|
...
|
function CopyToClipboard(containerid) {
if (document.selection) {
var range = document.body.createTextRange();
range.moveToElementText(document.getElementById(containerid));
range.select().createTextRange();
document.execCommand("copy");
} else if (window.getSelection) {
var range = document.createRange();
range.selectNode(document.getElementById(containerid));
window.getSelection().addRange(range);
document.execCommand("copy");
alert("Base64 copied into the clipboard!")
}
}