VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Wiper, Trojan |
n.exe
Windows Exe (x86-32)
Created at 2019-11-07T21:30:00
Remarks
(0x200001e): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Boot\BOOTSTAT.DAT.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\BOOTSECT.BAK.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Binary |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\branding.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\pss10r.chm.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\setup.chm.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\branding.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjProrWW.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.EPS.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPlusrWW.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.JPG.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Office32WW.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.GIF.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.PNG.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\AccessMUI.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\ExcelMUI.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\AccessMUISet.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\README.HTM.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Groove.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\InfoPathMUI.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Groove.en-us\GrooveMUI.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\BRANDING.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OCT.CHM.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUI.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUISet.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSCONFIG.CHM.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSS10O.CHM.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\Office32MUI.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\SETUP.CHM.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.WW\Office32WW.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\OneNoteMUI.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSS10R.CHM.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\PowerPointMUI.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\OutlookMUI.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PRJPROR\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Project.en-us\ProjectMUI.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Project.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.fr\Proof.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.es\Proof.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proofing.en-us\Proofing.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PROPLUSR\ProPlusrWW.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Binary |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PROPLUSR\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proofing.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.en\Proof.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PRJPROR\PrjProrWW.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Publisher.en-us\PublisherMUI.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\VisiorWW.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Word.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Visio.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\1033\MCABOUT.HTM.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\DATES.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\PHONE.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\STOCKS.DAT.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Publisher.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\TIME.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Visio.en-us\VisioMUI.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\STOCKS.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\BASMLA.XSL.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\METCONV.TXT.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Word.en-us\WordMUI.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Stationery\Desktop.ini.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.msi.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\PREVIEW.GIF.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\THMBNAIL.PNG.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\PREVIEW.GIF.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\PREVIEW.GIF.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\THMBNAIL.PNG.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\PREVIEW.GIF.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\THMBNAIL.PNG.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\THMBNAIL.PNG.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\PREVIEW.GIF.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\THMBNAIL.PNG.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\THMBNAIL.PNG.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\PREVIEW.GIF.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\PREVIEW.GIF.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\PREVIEW.GIF.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\THMBNAIL.PNG.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\THMBNAIL.PNG.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\PREVIEW.GIF.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\PREVIEW.GIF.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\THMBNAIL.PNG.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\PREVIEW.GIF.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\THMBNAIL.PNG.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\PREVIEW.GIF.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\THMBNAIL.PNG.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\PREVIEW.GIF.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\n.exe | Sample File | Binary |
Blacklisted
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-11-07 21:55 (UTC+1) |
Last Seen | 2019-11-07 22:11 (UTC+1) |
Names | Win32.Trojan.Kryptik |
Families | Kryptik |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x43829c |
Size Of Code | 0x52400 |
Size Of Initialized Data | 0x55e00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-11-06 21:57:45+00:00 |
Version Information (10)
»
Comments | Affective Thatculd Wars Answer Vocal |
CompanyName | Qualcomm Ventures |
FileDescription | Affective Thatculd Wars Answer Vocal |
FileVersion | 5.8.7.4 |
InternalName | Zipcloak Under |
LegalCopyright | Qualcomm Ventures All rights reserved. |
LegalTrademarks | Qualcomm Ventures All rights reserved. |
PrivateBuild | 5.8.7.4 |
ProductName | Zipcloak Under |
ProductVersion | 5.8.7.4 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x5233e | 0x52400 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.49 |
.rdata | 0x454000 | 0x24870 | 0x24a00 | 0x52800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.11 |
.data | 0x479000 | 0x73e04 | 0xd400 | 0x77200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.6 |
.rsrc | 0x4ed000 | 0x23e14 | 0x24000 | 0x84600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.66 |
Imports (23)
»
KERNEL32.DLL (94)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetOEMCP | 0x0 | 0x4540bc | 0x540bc | 0x528bc | 0x0 |
GetACP | 0x0 | 0x4540c0 | 0x540c0 | 0x528c0 | 0x0 |
GetCPInfo | 0x0 | 0x4540c4 | 0x540c4 | 0x528c4 | 0x0 |
GetCurrentProcessId | 0x0 | 0x4540c8 | 0x540c8 | 0x528c8 | 0x0 |
GetTickCount | 0x0 | 0x4540cc | 0x540cc | 0x528cc | 0x0 |
QueryPerformanceCounter | 0x0 | 0x4540d0 | 0x540d0 | 0x528d0 | 0x0 |
GetEnvironmentStringsW | 0x0 | 0x4540d4 | 0x540d4 | 0x528d4 | 0x0 |
FreeEnvironmentStringsW | 0x0 | 0x4540d8 | 0x540d8 | 0x528d8 | 0x0 |
GetEnvironmentStrings | 0x0 | 0x4540dc | 0x540dc | 0x528dc | 0x0 |
FreeEnvironmentStringsA | 0x0 | 0x4540e0 | 0x540e0 | 0x528e0 | 0x0 |
VirtualQuery | 0x0 | 0x4540e4 | 0x540e4 | 0x528e4 | 0x0 |
SetFilePointer | 0x0 | 0x4540e8 | 0x540e8 | 0x528e8 | 0x0 |
MultiByteToWideChar | 0x0 | 0x4540ec | 0x540ec | 0x528ec | 0x0 |
HeapSize | 0x0 | 0x4540f0 | 0x540f0 | 0x528f0 | 0x0 |
WideCharToMultiByte | 0x0 | 0x4540f4 | 0x540f4 | 0x528f4 | 0x0 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4540f8 | 0x540f8 | 0x528f8 | 0x0 |
InterlockedDecrement | 0x0 | 0x4540fc | 0x540fc | 0x528fc | 0x0 |
GetCurrentThreadId | 0x0 | 0x454100 | 0x54100 | 0x52900 | 0x0 |
SetLastError | 0x0 | 0x454104 | 0x54104 | 0x52904 | 0x0 |
InterlockedIncrement | 0x0 | 0x454108 | 0x54108 | 0x52908 | 0x0 |
TlsFree | 0x0 | 0x45410c | 0x5410c | 0x5290c | 0x0 |
TlsSetValue | 0x0 | 0x454110 | 0x54110 | 0x52910 | 0x0 |
TlsAlloc | 0x0 | 0x454114 | 0x54114 | 0x52914 | 0x0 |
IsValidCodePage | 0x0 | 0x454118 | 0x54118 | 0x52918 | 0x0 |
GetFileType | 0x0 | 0x45411c | 0x5411c | 0x5291c | 0x0 |
SetHandleCount | 0x0 | 0x454120 | 0x54120 | 0x52920 | 0x0 |
GetModuleFileNameA | 0x0 | 0x454124 | 0x54124 | 0x52924 | 0x0 |
GetStdHandle | 0x0 | 0x454128 | 0x54128 | 0x52928 | 0x0 |
HeapCreate | 0x0 | 0x45412c | 0x5412c | 0x5292c | 0x0 |
HeapReAlloc | 0x0 | 0x454130 | 0x54130 | 0x52930 | 0x0 |
VirtualAlloc | 0x0 | 0x454134 | 0x54134 | 0x52934 | 0x0 |
VirtualFree | 0x0 | 0x454138 | 0x54138 | 0x52938 | 0x0 |
DeleteCriticalSection | 0x0 | 0x45413c | 0x5413c | 0x5293c | 0x0 |
GetStartupInfoA | 0x0 | 0x454140 | 0x54140 | 0x52940 | 0x0 |
GetCommandLineA | 0x0 | 0x454144 | 0x54144 | 0x52944 | 0x0 |
GetSystemTimeAsFileTime | 0x0 | 0x454148 | 0x54148 | 0x52948 | 0x0 |
IsDebuggerPresent | 0x0 | 0x45414c | 0x5414c | 0x5294c | 0x0 |
SetUnhandledExceptionFilter | 0x0 | 0x454150 | 0x54150 | 0x52950 | 0x0 |
UnhandledExceptionFilter | 0x0 | 0x454154 | 0x54154 | 0x52954 | 0x0 |
GetCurrentProcess | 0x0 | 0x454158 | 0x54158 | 0x52958 | 0x0 |
TerminateProcess | 0x0 | 0x45415c | 0x5415c | 0x5295c | 0x0 |
RaiseException | 0x0 | 0x454160 | 0x54160 | 0x52960 | 0x0 |
RtlUnwind | 0x0 | 0x454164 | 0x54164 | 0x52964 | 0x0 |
HeapFree | 0x0 | 0x454168 | 0x54168 | 0x52968 | 0x0 |
ExitProcess | 0x0 | 0x45416c | 0x5416c | 0x5296c | 0x0 |
Sleep | 0x0 | 0x454170 | 0x54170 | 0x52970 | 0x0 |
GetModuleHandleW | 0x0 | 0x454174 | 0x54174 | 0x52974 | 0x0 |
LeaveCriticalSection | 0x0 | 0x454178 | 0x54178 | 0x52978 | 0x0 |
EnterCriticalSection | 0x0 | 0x45417c | 0x5417c | 0x5297c | 0x0 |
HeapAlloc | 0x0 | 0x454180 | 0x54180 | 0x52980 | 0x0 |
GetConsoleCP | 0x0 | 0x454184 | 0x54184 | 0x52984 | 0x0 |
GetConsoleMode | 0x0 | 0x454188 | 0x54188 | 0x52988 | 0x0 |
GetLocaleInfoW | 0x0 | 0x45418c | 0x5418c | 0x5298c | 0x0 |
GetLocaleInfoA | 0x0 | 0x454190 | 0x54190 | 0x52990 | 0x0 |
CompareStringA | 0x0 | 0x454194 | 0x54194 | 0x52994 | 0x0 |
CompareStringW | 0x0 | 0x454198 | 0x54198 | 0x52998 | 0x0 |
SetEnvironmentVariableA | 0x0 | 0x45419c | 0x5419c | 0x5299c | 0x0 |
SetStdHandle | 0x0 | 0x4541a0 | 0x541a0 | 0x529a0 | 0x0 |
LCMapStringA | 0x0 | 0x4541a4 | 0x541a4 | 0x529a4 | 0x0 |
LCMapStringW | 0x0 | 0x4541a8 | 0x541a8 | 0x529a8 | 0x0 |
GetStringTypeA | 0x0 | 0x4541ac | 0x541ac | 0x529ac | 0x0 |
GetStringTypeW | 0x0 | 0x4541b0 | 0x541b0 | 0x529b0 | 0x0 |
GetUserDefaultLCID | 0x0 | 0x4541b4 | 0x541b4 | 0x529b4 | 0x0 |
EnumSystemLocalesA | 0x0 | 0x4541b8 | 0x541b8 | 0x529b8 | 0x0 |
IsValidLocale | 0x0 | 0x4541bc | 0x541bc | 0x529bc | 0x0 |
WriteConsoleA | 0x0 | 0x4541c0 | 0x541c0 | 0x529c0 | 0x0 |
GetConsoleOutputCP | 0x0 | 0x4541c4 | 0x541c4 | 0x529c4 | 0x0 |
WriteConsoleW | 0x0 | 0x4541c8 | 0x541c8 | 0x529c8 | 0x0 |
SetEndOfFile | 0x0 | 0x4541cc | 0x541cc | 0x529cc | 0x0 |
GetProcessHeap | 0x0 | 0x4541d0 | 0x541d0 | 0x529d0 | 0x0 |
IsBadCodePtr | 0x0 | 0x4541d4 | 0x541d4 | 0x529d4 | 0x0 |
LockResource | 0x0 | 0x4541d8 | 0x541d8 | 0x529d8 | 0x0 |
GetVolumeNameForVolumeMountPointA | 0x0 | 0x4541dc | 0x541dc | 0x529dc | 0x0 |
FindNextVolumeMountPointA | 0x0 | 0x4541e0 | 0x541e0 | 0x529e0 | 0x0 |
GlobalAlloc | 0x0 | 0x4541e4 | 0x541e4 | 0x529e4 | 0x0 |
LoadLibraryA | 0x0 | 0x4541e8 | 0x541e8 | 0x529e8 | 0x0 |
GetProcAddress | 0x0 | 0x4541ec | 0x541ec | 0x529ec | 0x0 |
CreateEventA | 0x0 | 0x4541f0 | 0x541f0 | 0x529f0 | 0x0 |
WaitForSingleObject | 0x0 | 0x4541f4 | 0x541f4 | 0x529f4 | 0x0 |
GetConsoleWindow | 0x0 | 0x4541f8 | 0x541f8 | 0x529f8 | 0x0 |
GetLastError | 0x0 | 0x4541fc | 0x541fc | 0x529fc | 0x0 |
FlushFileBuffers | 0x0 | 0x454200 | 0x54200 | 0x52a00 | 0x0 |
WriteFile | 0x0 | 0x454204 | 0x54204 | 0x52a04 | 0x0 |
ReadFile | 0x0 | 0x454208 | 0x54208 | 0x52a08 | 0x0 |
CloseHandle | 0x0 | 0x45420c | 0x5420c | 0x52a0c | 0x0 |
CreateFileA | 0x0 | 0x454210 | 0x54210 | 0x52a10 | 0x0 |
GetCommState | 0x0 | 0x454214 | 0x54214 | 0x52a14 | 0x0 |
GetCommTimeouts | 0x0 | 0x454218 | 0x54218 | 0x52a18 | 0x0 |
BuildCommDCBA | 0x0 | 0x45421c | 0x5421c | 0x52a1c | 0x0 |
SetCommState | 0x0 | 0x454220 | 0x54220 | 0x52a20 | 0x0 |
SetCommTimeouts | 0x0 | 0x454224 | 0x54224 | 0x52a24 | 0x0 |
TlsGetValue | 0x0 | 0x454228 | 0x54228 | 0x52a28 | 0x0 |
GetModuleHandleA | 0x0 | 0x45422c | 0x5422c | 0x52a2c | 0x0 |
InitializeCriticalSection | 0x0 | 0x454230 | 0x54230 | 0x52a30 | 0x0 |
ACTIVEDS.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x9 | 0x454000 | 0x54000 | 0x52800 | - |
ADVAPI32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryValueExA | 0x0 | 0x454008 | 0x54008 | 0x52808 | 0x0 |
RegCloseKey | 0x0 | 0x45400c | 0x5400c | 0x5280c | 0x0 |
RegOpenKeyA | 0x0 | 0x454010 | 0x54010 | 0x52810 | 0x0 |
ImpersonateLoggedOnUser | 0x0 | 0x454014 | 0x54014 | 0x52814 | 0x0 |
RegOpenKeyExA | 0x0 | 0x454018 | 0x54018 | 0x52818 | 0x0 |
COMCTL32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ImageList_ReplaceIcon | 0x0 | 0x454020 | 0x54020 | 0x52820 | 0x0 |
(by ordinal) | 0x11 | 0x454024 | 0x54024 | 0x52824 | - |
ImageList_Add | 0x0 | 0x454028 | 0x54028 | 0x52828 | 0x0 |
ImageList_Create | 0x0 | 0x45402c | 0x5402c | 0x5282c | 0x0 |
COMDLG32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PageSetupDlgA | 0x0 | 0x454034 | 0x54034 | 0x52834 | 0x0 |
GetOpenFileNameA | 0x0 | 0x454038 | 0x54038 | 0x52838 | 0x0 |
DCIMAN32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WinWatchNotify | 0x0 | 0x454040 | 0x54040 | 0x52840 | 0x0 |
WinWatchOpen | 0x0 | 0x454044 | 0x54044 | 0x52844 | 0x0 |
GDI32.dll (22)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreatePatternBrush | 0x0 | 0x45404c | 0x5404c | 0x5284c | 0x0 |
GetStockObject | 0x0 | 0x454050 | 0x54050 | 0x52850 | 0x0 |
CreateFontA | 0x0 | 0x454054 | 0x54054 | 0x52854 | 0x0 |
SetBrushOrgEx | 0x0 | 0x454058 | 0x54058 | 0x52858 | 0x0 |
CreateCompatibleDC | 0x0 | 0x45405c | 0x5405c | 0x5285c | 0x0 |
CreateDIBSection | 0x0 | 0x454060 | 0x54060 | 0x52860 | 0x0 |
GetCurrentObject | 0x0 | 0x454064 | 0x54064 | 0x52864 | 0x0 |
SelectObject | 0x0 | 0x454068 | 0x54068 | 0x52868 | 0x0 |
GetObjectA | 0x0 | 0x45406c | 0x5406c | 0x5286c | 0x0 |
CombineRgn | 0x0 | 0x454070 | 0x54070 | 0x52870 | 0x0 |
ChoosePixelFormat | 0x0 | 0x454074 | 0x54074 | 0x52874 | 0x0 |
SetPixelFormat | 0x0 | 0x454078 | 0x54078 | 0x52878 | 0x0 |
GetPixelFormat | 0x0 | 0x45407c | 0x5407c | 0x5287c | 0x0 |
DescribePixelFormat | 0x0 | 0x454080 | 0x54080 | 0x52880 | 0x0 |
GetDeviceCaps | 0x0 | 0x454084 | 0x54084 | 0x52884 | 0x0 |
CreateDCA | 0x0 | 0x454088 | 0x54088 | 0x52888 | 0x0 |
DeleteDC | 0x0 | 0x45408c | 0x5408c | 0x5288c | 0x0 |
SwapBuffers | 0x0 | 0x454090 | 0x54090 | 0x52890 | 0x0 |
DeleteObject | 0x0 | 0x454094 | 0x54094 | 0x52894 | 0x0 |
BitBlt | 0x0 | 0x454098 | 0x54098 | 0x52898 | 0x0 |
Escape | 0x0 | 0x45409c | 0x5409c | 0x5289c | 0x0 |
SetBkMode | 0x0 | 0x4540a0 | 0x540a0 | 0x528a0 | 0x0 |
gdiplus.dll (15)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GdiplusStartup | 0x0 | 0x454504 | 0x54504 | 0x52d04 | 0x0 |
GdipDeleteGraphics | 0x0 | 0x454508 | 0x54508 | 0x52d08 | 0x0 |
GdipDrawImageI | 0x0 | 0x45450c | 0x5450c | 0x52d0c | 0x0 |
GdipCreateBitmapFromHBITMAP | 0x0 | 0x454510 | 0x54510 | 0x52d10 | 0x0 |
GdipCreateFromHDC | 0x0 | 0x454514 | 0x54514 | 0x52d14 | 0x0 |
GdipSaveImageToStream | 0x0 | 0x454518 | 0x54518 | 0x52d18 | 0x0 |
GdiplusShutdown | 0x0 | 0x45451c | 0x5451c | 0x52d1c | 0x0 |
GdipCreateBitmapFromStreamICM | 0x0 | 0x454520 | 0x54520 | 0x52d20 | 0x0 |
GdipCreateBitmapFromStream | 0x0 | 0x454524 | 0x54524 | 0x52d24 | 0x0 |
GdipCloneImage | 0x0 | 0x454528 | 0x54528 | 0x52d28 | 0x0 |
GdipLoadImageFromFileICM | 0x0 | 0x45452c | 0x5452c | 0x52d2c | 0x0 |
GdipLoadImageFromFile | 0x0 | 0x454530 | 0x54530 | 0x52d30 | 0x0 |
GdipDisposeImage | 0x0 | 0x454534 | 0x54534 | 0x52d34 | 0x0 |
GdipFree | 0x0 | 0x454538 | 0x54538 | 0x52d38 | 0x0 |
GdipAlloc | 0x0 | 0x45453c | 0x5453c | 0x52d3c | 0x0 |
GLU32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
gluOrtho2D | 0x0 | 0x4540a8 | 0x540a8 | 0x528a8 | 0x0 |
gluPickMatrix | 0x0 | 0x4540ac | 0x540ac | 0x528ac | 0x0 |
gluLookAt | 0x0 | 0x4540b0 | 0x540b0 | 0x528b0 | 0x0 |
gluPerspective | 0x0 | 0x4540b4 | 0x540b4 | 0x528b4 | 0x0 |
MSACM32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
acmDriverDetailsA | 0x0 | 0x454238 | 0x54238 | 0x52a38 | 0x0 |
ODBC32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x29 | 0x454240 | 0x54240 | 0x52a40 | - |
ole32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateStreamOnHGlobal | 0x0 | 0x454544 | 0x54544 | 0x52d44 | 0x0 |
StgCreateDocfile | 0x0 | 0x454548 | 0x54548 | 0x52d48 | 0x0 |
OLEAUT32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VarDateFromR4 | 0x5b | 0x454248 | 0x54248 | 0x52a48 | - |
VarDateFromI4 | 0x5a | 0x45424c | 0x5424c | 0x52a4c | - |
OPENGL32.dll (65)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
glTranslatef | 0x0 | 0x454254 | 0x54254 | 0x52a54 | 0x0 |
glEnd | 0x0 | 0x454258 | 0x54258 | 0x52a58 | 0x0 |
glVertex2f | 0x0 | 0x45425c | 0x5425c | 0x52a5c | 0x0 |
glBegin | 0x0 | 0x454260 | 0x54260 | 0x52a60 | 0x0 |
glDisableClientState | 0x0 | 0x454264 | 0x54264 | 0x52a64 | 0x0 |
glDrawElements | 0x0 | 0x454268 | 0x54268 | 0x52a68 | 0x0 |
glDrawArrays | 0x0 | 0x45426c | 0x5426c | 0x52a6c | 0x0 |
glNormalPointer | 0x0 | 0x454270 | 0x54270 | 0x52a70 | 0x0 |
glVertexPointer | 0x0 | 0x454274 | 0x54274 | 0x52a74 | 0x0 |
glEnableClientState | 0x0 | 0x454278 | 0x54278 | 0x52a78 | 0x0 |
glTexCoordPointer | 0x0 | 0x45427c | 0x5427c | 0x52a7c | 0x0 |
glColor4f | 0x0 | 0x454280 | 0x54280 | 0x52a80 | 0x0 |
glGetFloatv | 0x0 | 0x454284 | 0x54284 | 0x52a84 | 0x0 |
glPopMatrix | 0x0 | 0x454288 | 0x54288 | 0x52a88 | 0x0 |
glPopAttrib | 0x0 | 0x45428c | 0x5428c | 0x52a8c | 0x0 |
glOrtho | 0x0 | 0x454290 | 0x54290 | 0x52a90 | 0x0 |
glLoadIdentity | 0x0 | 0x454294 | 0x54294 | 0x52a94 | 0x0 |
glPushMatrix | 0x0 | 0x454298 | 0x54298 | 0x52a98 | 0x0 |
glPopClientAttrib | 0x0 | 0x45429c | 0x5429c | 0x52a9c | 0x0 |
glDisable | 0x0 | 0x4542a0 | 0x542a0 | 0x52aa0 | 0x0 |
glPushAttrib | 0x0 | 0x4542a4 | 0x542a4 | 0x52aa4 | 0x0 |
glRasterPos2i | 0x0 | 0x4542a8 | 0x542a8 | 0x52aa8 | 0x0 |
glColor4fv | 0x0 | 0x4542ac | 0x542ac | 0x52aac | 0x0 |
glVertex2i | 0x0 | 0x4542b0 | 0x542b0 | 0x52ab0 | 0x0 |
glGetString | 0x0 | 0x4542b4 | 0x542b4 | 0x52ab4 | 0x0 |
glGetError | 0x0 | 0x4542b8 | 0x542b8 | 0x52ab8 | 0x0 |
glReadBuffer | 0x0 | 0x4542bc | 0x542bc | 0x52abc | 0x0 |
glDrawBuffer | 0x0 | 0x4542c0 | 0x542c0 | 0x52ac0 | 0x0 |
wglGetProcAddress | 0x0 | 0x4542c4 | 0x542c4 | 0x52ac4 | 0x0 |
glPushClientAttrib | 0x0 | 0x4542c8 | 0x542c8 | 0x52ac8 | 0x0 |
wglCreateContext | 0x0 | 0x4542cc | 0x542cc | 0x52acc | 0x0 |
wglMakeCurrent | 0x0 | 0x4542d0 | 0x542d0 | 0x52ad0 | 0x0 |
glGetBooleanv | 0x0 | 0x4542d4 | 0x542d4 | 0x52ad4 | 0x0 |
glGetIntegerv | 0x0 | 0x4542d8 | 0x542d8 | 0x52ad8 | 0x0 |
wglDeleteContext | 0x0 | 0x4542dc | 0x542dc | 0x52adc | 0x0 |
wglGetCurrentDC | 0x0 | 0x4542e0 | 0x542e0 | 0x52ae0 | 0x0 |
glColor3f | 0x0 | 0x4542e4 | 0x542e4 | 0x52ae4 | 0x0 |
glVertex3f | 0x0 | 0x4542e8 | 0x542e8 | 0x52ae8 | 0x0 |
glRasterPos3f | 0x0 | 0x4542ec | 0x542ec | 0x52aec | 0x0 |
glRotatef | 0x0 | 0x4542f0 | 0x542f0 | 0x52af0 | 0x0 |
glCallList | 0x0 | 0x4542f4 | 0x542f4 | 0x52af4 | 0x0 |
glEndList | 0x0 | 0x4542f8 | 0x542f8 | 0x52af8 | 0x0 |
glNewList | 0x0 | 0x4542fc | 0x542fc | 0x52afc | 0x0 |
glGenLists | 0x0 | 0x454300 | 0x54300 | 0x52b00 | 0x0 |
glDeleteLists | 0x0 | 0x454304 | 0x54304 | 0x52b04 | 0x0 |
glClipPlane | 0x0 | 0x454308 | 0x54308 | 0x52b08 | 0x0 |
glEnable | 0x0 | 0x45430c | 0x5430c | 0x52b0c | 0x0 |
glScalef | 0x0 | 0x454310 | 0x54310 | 0x52b10 | 0x0 |
glRotated | 0x0 | 0x454314 | 0x54314 | 0x52b14 | 0x0 |
glLineStipple | 0x0 | 0x454318 | 0x54318 | 0x52b18 | 0x0 |
glLineWidth | 0x0 | 0x45431c | 0x5431c | 0x52b1c | 0x0 |
glClear | 0x0 | 0x454320 | 0x54320 | 0x52b20 | 0x0 |
glDepthFunc | 0x0 | 0x454324 | 0x54324 | 0x52b24 | 0x0 |
glClearDepth | 0x0 | 0x454328 | 0x54328 | 0x52b28 | 0x0 |
glClearColor | 0x0 | 0x45432c | 0x5432c | 0x52b2c | 0x0 |
glPushName | 0x0 | 0x454330 | 0x54330 | 0x52b30 | 0x0 |
glInitNames | 0x0 | 0x454334 | 0x54334 | 0x52b34 | 0x0 |
glRenderMode | 0x0 | 0x454338 | 0x54338 | 0x52b38 | 0x0 |
glSelectBuffer | 0x0 | 0x45433c | 0x5433c | 0x52b3c | 0x0 |
glPixelStorei | 0x0 | 0x454340 | 0x54340 | 0x52b40 | 0x0 |
glFlush | 0x0 | 0x454344 | 0x54344 | 0x52b44 | 0x0 |
glBitmap | 0x0 | 0x454348 | 0x54348 | 0x52b48 | 0x0 |
glViewport | 0x0 | 0x45434c | 0x5434c | 0x52b4c | 0x0 |
wglGetCurrentContext | 0x0 | 0x454350 | 0x54350 | 0x52b50 | 0x0 |
glMatrixMode | 0x0 | 0x454354 | 0x54354 | 0x52b54 | 0x0 |
pdh.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PdhCollectQueryData | 0x0 | 0x454550 | 0x54550 | 0x52d50 | 0x0 |
PSAPI.DLL (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetPerformanceInfo | 0x0 | 0x45435c | 0x5435c | 0x52b5c | 0x0 |
RASAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RasDeleteSubEntryA | 0x0 | 0x454364 | 0x54364 | 0x52b64 | 0x0 |
SHLWAPI.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0xe | 0x45436c | 0x5436c | 0x52b6c | - |
urlmon.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetClassFileOrMime | 0x0 | 0x454558 | 0x54558 | 0x52d58 | 0x0 |
USER32.dll (88)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetDlgItem | 0x0 | 0x454374 | 0x54374 | 0x52b74 | 0x0 |
SetClassLongA | 0x0 | 0x454378 | 0x54378 | 0x52b78 | 0x0 |
SetCursor | 0x0 | 0x45437c | 0x5437c | 0x52b7c | 0x0 |
LoadCursorA | 0x0 | 0x454380 | 0x54380 | 0x52b80 | 0x0 |
SetCursorPos | 0x0 | 0x454384 | 0x54384 | 0x52b84 | 0x0 |
ClientToScreen | 0x0 | 0x454388 | 0x54388 | 0x52b88 | 0x0 |
ScreenToClient | 0x0 | 0x45438c | 0x5438c | 0x52b8c | 0x0 |
GetCursorPos | 0x0 | 0x454390 | 0x54390 | 0x52b90 | 0x0 |
ChangeDisplaySettingsExA | 0x0 | 0x454394 | 0x54394 | 0x52b94 | 0x0 |
EnumDisplaySettingsA | 0x0 | 0x454398 | 0x54398 | 0x52b98 | 0x0 |
ReleaseDC | 0x0 | 0x45439c | 0x5439c | 0x52b9c | 0x0 |
GetDC | 0x0 | 0x4543a0 | 0x543a0 | 0x52ba0 | 0x0 |
GetDesktopWindow | 0x0 | 0x4543a4 | 0x543a4 | 0x52ba4 | 0x0 |
GetSystemMetrics | 0x0 | 0x4543a8 | 0x543a8 | 0x52ba8 | 0x0 |
RegisterClassA | 0x0 | 0x4543ac | 0x543ac | 0x52bac | 0x0 |
LoadIconA | 0x0 | 0x4543b0 | 0x543b0 | 0x52bb0 | 0x0 |
GetClassInfoA | 0x0 | 0x4543b4 | 0x543b4 | 0x52bb4 | 0x0 |
MsgWaitForMultipleObjects | 0x0 | 0x4543b8 | 0x543b8 | 0x52bb8 | 0x0 |
DispatchMessageA | 0x0 | 0x4543bc | 0x543bc | 0x52bbc | 0x0 |
TranslateMessage | 0x0 | 0x4543c0 | 0x543c0 | 0x52bc0 | 0x0 |
GetMessageA | 0x0 | 0x4543c4 | 0x543c4 | 0x52bc4 | 0x0 |
PeekMessageA | 0x0 | 0x4543c8 | 0x543c8 | 0x52bc8 | 0x0 |
ExitWindowsEx | 0x0 | 0x4543cc | 0x543cc | 0x52bcc | 0x0 |
LoadBitmapA | 0x0 | 0x4543d0 | 0x543d0 | 0x52bd0 | 0x0 |
ChildWindowFromPoint | 0x0 | 0x4543d4 | 0x543d4 | 0x52bd4 | 0x0 |
GetMessagePos | 0x0 | 0x4543d8 | 0x543d8 | 0x52bd8 | 0x0 |
InvalidateRect | 0x0 | 0x4543dc | 0x543dc | 0x52bdc | 0x0 |
ReleaseCapture | 0x0 | 0x4543e0 | 0x543e0 | 0x52be0 | 0x0 |
SetCapture | 0x0 | 0x4543e4 | 0x543e4 | 0x52be4 | 0x0 |
PostQuitMessage | 0x0 | 0x4543e8 | 0x543e8 | 0x52be8 | 0x0 |
EndPaint | 0x0 | 0x4543ec | 0x543ec | 0x52bec | 0x0 |
BeginPaint | 0x0 | 0x4543f0 | 0x543f0 | 0x52bf0 | 0x0 |
GetUpdateRect | 0x0 | 0x4543f4 | 0x543f4 | 0x52bf4 | 0x0 |
TrackMouseEvent | 0x0 | 0x4543f8 | 0x543f8 | 0x52bf8 | 0x0 |
UpdateWindow | 0x0 | 0x4543fc | 0x543fc | 0x52bfc | 0x0 |
IsDlgButtonChecked | 0x0 | 0x454400 | 0x54400 | 0x52c00 | 0x0 |
DialogBoxParamA | 0x0 | 0x454404 | 0x54404 | 0x52c04 | 0x0 |
IsWindowUnicode | 0x0 | 0x454408 | 0x54408 | 0x52c08 | 0x0 |
TrackPopupMenu | 0x0 | 0x45440c | 0x5440c | 0x52c0c | 0x0 |
SetTimer | 0x0 | 0x454410 | 0x54410 | 0x52c10 | 0x0 |
SetFocus | 0x0 | 0x454414 | 0x54414 | 0x52c14 | 0x0 |
InflateRect | 0x0 | 0x454418 | 0x54418 | 0x52c18 | 0x0 |
EnableWindow | 0x0 | 0x45441c | 0x5441c | 0x52c1c | 0x0 |
FillRect | 0x0 | 0x454420 | 0x54420 | 0x52c20 | 0x0 |
CallWindowProcA | 0x0 | 0x454424 | 0x54424 | 0x52c24 | 0x0 |
MapWindowPoints | 0x0 | 0x454428 | 0x54428 | 0x52c28 | 0x0 |
EnumWindowStationsW | 0x0 | 0x45442c | 0x5442c | 0x52c2c | 0x0 |
LoadImageA | 0x0 | 0x454430 | 0x54430 | 0x52c30 | 0x0 |
SetScrollInfo | 0x0 | 0x454434 | 0x54434 | 0x52c34 | 0x0 |
PtInRect | 0x0 | 0x454438 | 0x54438 | 0x52c38 | 0x0 |
SetScrollPos | 0x0 | 0x45443c | 0x5443c | 0x52c3c | 0x0 |
GetSystemMenu | 0x0 | 0x454440 | 0x54440 | 0x52c40 | 0x0 |
EnableMenuItem | 0x0 | 0x454444 | 0x54444 | 0x52c44 | 0x0 |
DrawMenuBar | 0x0 | 0x454448 | 0x54448 | 0x52c48 | 0x0 |
SystemParametersInfoA | 0x0 | 0x45444c | 0x5444c | 0x52c4c | 0x0 |
DestroyIcon | 0x0 | 0x454450 | 0x54450 | 0x52c50 | 0x0 |
FindWindowA | 0x0 | 0x454454 | 0x54454 | 0x52c54 | 0x0 |
SetActiveWindow | 0x0 | 0x454458 | 0x54458 | 0x52c58 | 0x0 |
SendDlgItemMessageA | 0x0 | 0x45445c | 0x5445c | 0x52c5c | 0x0 |
SetDlgItemTextW | 0x0 | 0x454460 | 0x54460 | 0x52c60 | 0x0 |
GetParent | 0x0 | 0x454464 | 0x54464 | 0x52c64 | 0x0 |
WindowFromDC | 0x0 | 0x454468 | 0x54468 | 0x52c68 | 0x0 |
IsWindow | 0x0 | 0x45446c | 0x5446c | 0x52c6c | 0x0 |
EnumDisplayMonitors | 0x0 | 0x454470 | 0x54470 | 0x52c70 | 0x0 |
ShowCursor | 0x0 | 0x454474 | 0x54474 | 0x52c74 | 0x0 |
AdjustWindowRectEx | 0x0 | 0x454478 | 0x54478 | 0x52c78 | 0x0 |
CreateWindowExA | 0x0 | 0x45447c | 0x5447c | 0x52c7c | 0x0 |
DestroyWindow | 0x0 | 0x454480 | 0x54480 | 0x52c80 | 0x0 |
UnregisterClassA | 0x0 | 0x454484 | 0x54484 | 0x52c84 | 0x0 |
SetRect | 0x0 | 0x454488 | 0x54488 | 0x52c88 | 0x0 |
CopyRect | 0x0 | 0x45448c | 0x5448c | 0x52c8c | 0x0 |
ShowWindow | 0x0 | 0x454490 | 0x54490 | 0x52c90 | 0x0 |
SetWindowLongA | 0x0 | 0x454494 | 0x54494 | 0x52c94 | 0x0 |
IsZoomed | 0x0 | 0x454498 | 0x54498 | 0x52c98 | 0x0 |
SendMessageA | 0x0 | 0x45449c | 0x5449c | 0x52c9c | 0x0 |
GetWindowLongA | 0x0 | 0x4544a0 | 0x544a0 | 0x52ca0 | 0x0 |
MonitorFromWindow | 0x0 | 0x4544a4 | 0x544a4 | 0x52ca4 | 0x0 |
GetMonitorInfoA | 0x0 | 0x4544a8 | 0x544a8 | 0x52ca8 | 0x0 |
OffsetRect | 0x0 | 0x4544ac | 0x544ac | 0x52cac | 0x0 |
SetWindowPos | 0x0 | 0x4544b0 | 0x544b0 | 0x52cb0 | 0x0 |
GetClientRect | 0x0 | 0x4544b4 | 0x544b4 | 0x52cb4 | 0x0 |
GetKeyboardState | 0x0 | 0x4544b8 | 0x544b8 | 0x52cb8 | 0x0 |
ToAscii | 0x0 | 0x4544bc | 0x544bc | 0x52cbc | 0x0 |
GetKeyState | 0x0 | 0x4544c0 | 0x544c0 | 0x52cc0 | 0x0 |
SetWindowTextA | 0x0 | 0x4544c4 | 0x544c4 | 0x52cc4 | 0x0 |
DefWindowProcA | 0x0 | 0x4544c8 | 0x544c8 | 0x52cc8 | 0x0 |
IsIconic | 0x0 | 0x4544cc | 0x544cc | 0x52ccc | 0x0 |
GetWindowRect | 0x0 | 0x4544d0 | 0x544d0 | 0x52cd0 | 0x0 |
UxTheme.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
IsAppThemed | 0x0 | 0x4544d8 | 0x544d8 | 0x52cd8 | 0x0 |
WINMM.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
timeGetTime | 0x0 | 0x4544e0 | 0x544e0 | 0x52ce0 | 0x0 |
joyGetDevCapsA | 0x0 | 0x4544e4 | 0x544e4 | 0x52ce4 | 0x0 |
joyGetPosEx | 0x0 | 0x4544e8 | 0x544e8 | 0x52ce8 | 0x0 |
timeBeginPeriod | 0x0 | 0x4544ec | 0x544ec | 0x52cec | 0x0 |
timeEndPeriod | 0x0 | 0x4544f0 | 0x544f0 | 0x52cf0 | 0x0 |
WinSCard.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SCardForgetReaderA | 0x0 | 0x4544f8 | 0x544f8 | 0x52cf8 | 0x0 |
SCardGetCardTypeProviderNameA | 0x0 | 0x4544fc | 0x544fc | 0x52cfc | 0x0 |
Memory Dumps (14)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
n.exe | 1 | 0x00400000 | 0x00510FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00560000 | 0x00593FFF | First Execution | - | 32-bit | 0x00560000 |
![]() |
![]() |
...
|
buffer | 1 | 0x00560000 | 0x00593FFF | Content Changed | - | 32-bit | 0x00562A1E |
![]() |
![]() |
...
|
n.exe | 2 | 0x00400000 | 0x00510FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
n.exe | 1 | 0x00400000 | 0x00510FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
n.exe | 2 | 0x00400000 | 0x00510FFF | Final Dump | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 16 | 0x00520000 | 0x00553FFF | First Execution | - | 32-bit | 0x00520000 |
![]() |
![]() |
...
|
buffer | 19 | 0x01D80000 | 0x01DB3FFF | First Execution | - | 32-bit | 0x01D80000 |
![]() |
![]() |
...
|
buffer | 16 | 0x00520000 | 0x00553FFF | Content Changed | - | 32-bit | 0x00522A1E |
![]() |
![]() |
...
|
buffer | 19 | 0x01D80000 | 0x01DB3FFF | Content Changed | - | 32-bit | 0x01D82A1E |
![]() |
![]() |
...
|
buffer | 18 | 0x00560000 | 0x00593FFF | First Execution | - | 32-bit | 0x00560000 |
![]() |
![]() |
...
|
buffer | 18 | 0x00560000 | 0x00593FFF | Content Changed | - | 32-bit | 0x00562A1E |
![]() |
![]() |
...
|
buffer | 38 | 0x00620000 | 0x00653FFF | First Execution | - | 32-bit | 0x00620000 |
![]() |
![]() |
...
|
buffer | 38 | 0x00620000 | 0x00653FFF | Content Changed | - | 32-bit | 0x00622A1E |
![]() |
![]() |
...
|
C:\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000\desktop.ini.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\ADO210.CHM.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.cab.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.cab.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\OWOW32LR.cab.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfLR.cab.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Not Queried
|
...
|
»