VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Dropper
|
Threat Names: |
Trojan.Ransom.AIG
|
kB2jyVh0H39JpYUu.exe
Windows Exe (x86-32)
Created at 2020-12-05T13:20:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\kB2jyVh0H39JpYUu.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x44ddae |
Size Of Code | 0x4be00 |
Size Of Initialized Data | 0x6a400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-11-15 07:35:46+00:00 |
Version Information (8)
»
Assembly Version | 2.2.268.0 |
FileDescription | GlassWire |
FileVersion | 2.2.268.0 |
InternalName | satanfin.exe |
LegalCopyright | © 2020 SecureMix LLC |
OriginalFilename | satanfin.exe |
ProductName | GlassWire |
ProductVersion | 2.2.268.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x4bdb4 | 0x4be00 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.47 |
.rsrc | 0x44e000 | 0x6a0cc | 0x6a200 | 0x4c000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.78 |
.reloc | 0x4ba000 | 0xc | 0x200 | 0xb6200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x4dd88 | 0x4bf88 | 0x0 |
Memory Dumps (6)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
kb2jyvh0h39jpyuu.exe | 1 | 0x01210000 | 0x012CBFFF | Relevant Image |
![]() |
64-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00340000 | 0x00340FFF | First Execution |
![]() |
64-bit | 0x00340000 |
![]() |
![]() |
...
|
clrjit.dll | 1 | 0x7FEF22E0000 | 0x7FEF23E7FFF | First Execution |
![]() |
64-bit | 0x7FEF23978F6 |
![]() |
![]() |
...
|
buffer | 1 | 0x1BD80000 | 0x1BD81FFF | Content Changed |
![]() |
64-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x1BDC0000 | 0x1BDC1FFF | Content Changed |
![]() |
64-bit | - |
![]() |
![]() |
...
|
kb2jyvh0h39jpyuu.exe | 1 | 0x01210000 | 0x012CBFFF | Process Termination |
![]() |
64-bit | - |
![]() |
![]() |
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Temp\satan.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x63f1c0 |
Size Of Code | 0x7000 |
Size Of Initialized Data | 0x2f000 |
Size Of Uninitialized Data | 0x238000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2012-01-29 18:49:03+00:00 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
UPX0 | 0x401000 | 0x238000 | 0x0 | 0x200 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
UPX1 | 0x639000 | 0x7000 | 0x6400 | 0x200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.71 |
.rsrc | 0x640000 | 0x2f000 | 0x2e800 | 0x6600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.64 |
Imports (7)
»
KERNEL32.DLL (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | 0x0 | 0x66e560 | 0x26e560 | 0x34b60 | 0x0 |
GetProcAddress | 0x0 | 0x66e564 | 0x26e564 | 0x34b64 | 0x0 |
VirtualProtect | 0x0 | 0x66e568 | 0x26e568 | 0x34b68 | 0x0 |
VirtualAlloc | 0x0 | 0x66e56c | 0x26e56c | 0x34b6c | 0x0 |
VirtualFree | 0x0 | 0x66e570 | 0x26e570 | 0x34b70 | 0x0 |
ExitProcess | 0x0 | 0x66e574 | 0x26e574 | 0x34b74 | 0x0 |
advapi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegCloseKey | 0x0 | 0x66e57c | 0x26e57c | 0x34b7c | 0x0 |
comctl32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InitCommonControls | 0x0 | 0x66e584 | 0x26e584 | 0x34b84 | 0x0 |
gdi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateFontIndirectA | 0x0 | 0x66e58c | 0x26e58c | 0x34b8c | 0x0 |
shell32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteA | 0x0 | 0x66e594 | 0x26e594 | 0x34b94 | 0x0 |
shlwapi.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathMatchSpecA | 0x0 | 0x66e59c | 0x26e59c | 0x34b9c | 0x0 |
user32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EndPaint | 0x0 | 0x66e5a4 | 0x26e5a4 | 0x34ba4 | 0x0 |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
satan.exe | 2 | 0x00400000 | 0x0066EFFF | First Execution |
![]() |
32-bit | 0x0063F1C0 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.Ransom.AIG |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Temp\satan2.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x63f1f0 |
Size Of Code | 0x7000 |
Size Of Initialized Data | 0x2f000 |
Size Of Uninitialized Data | 0x238000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2012-01-29 18:49:03+00:00 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
UPX0 | 0x401000 | 0x238000 | 0x0 | 0x200 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
UPX1 | 0x639000 | 0x7000 | 0x6400 | 0x200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.73 |
.rsrc | 0x640000 | 0x2f000 | 0x2e800 | 0x6600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.64 |
Imports (7)
»
KERNEL32.DLL (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | 0x0 | 0x66e560 | 0x26e560 | 0x34b60 | 0x0 |
GetProcAddress | 0x0 | 0x66e564 | 0x26e564 | 0x34b64 | 0x0 |
VirtualProtect | 0x0 | 0x66e568 | 0x26e568 | 0x34b68 | 0x0 |
VirtualAlloc | 0x0 | 0x66e56c | 0x26e56c | 0x34b6c | 0x0 |
VirtualFree | 0x0 | 0x66e570 | 0x26e570 | 0x34b70 | 0x0 |
ExitProcess | 0x0 | 0x66e574 | 0x26e574 | 0x34b74 | 0x0 |
advapi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegCloseKey | 0x0 | 0x66e57c | 0x26e57c | 0x34b7c | 0x0 |
comctl32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InitCommonControls | 0x0 | 0x66e584 | 0x26e584 | 0x34b84 | 0x0 |
gdi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateFontIndirectA | 0x0 | 0x66e58c | 0x26e58c | 0x34b8c | 0x0 |
shell32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteA | 0x0 | 0x66e594 | 0x26e594 | 0x34b94 | 0x0 |
shlwapi.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathMatchSpecA | 0x0 | 0x66e59c | 0x26e59c | 0x34b9c | 0x0 |
user32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EndPaint | 0x0 | 0x66e5a4 | 0x26e5a4 | 0x34ba4 | 0x0 |
Memory Dumps (11)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
satan2.exe | 3 | 0x00400000 | 0x0066EFFF | First Execution |
![]() |
32-bit | 0x0063F1F0 |
![]() |
![]() |
...
|
satan2.exe | 3 | 0x00400000 | 0x0066EFFF | Content Changed |
![]() |
32-bit | 0x00401F87 |
![]() |
![]() |
...
|
satan2.exe | 3 | 0x00400000 | 0x0066EFFF | Content Changed |
![]() |
32-bit | 0x004013C2 |
![]() |
![]() |
...
|
satan2.exe | 3 | 0x00400000 | 0x0066EFFF | Content Changed |
![]() |
32-bit | 0x004013C2 |
![]() |
![]() |
...
|
satan2.exe | 3 | 0x00400000 | 0x0066EFFF | Content Changed |
![]() |
32-bit | 0x00401665 |
![]() |
![]() |
...
|
satan2.exe | 3 | 0x00400000 | 0x0066EFFF | Content Changed |
![]() |
32-bit | 0x00401665 |
![]() |
![]() |
...
|
satan2.exe | 3 | 0x00400000 | 0x0066EFFF | Content Changed |
![]() |
32-bit | 0x00401665 |
![]() |
![]() |
...
|
satan2.exe | 3 | 0x00400000 | 0x0066EFFF | Content Changed |
![]() |
32-bit | 0x004015E2 |
![]() |
![]() |
...
|
satan2.exe | 3 | 0x00400000 | 0x0066EFFF | Content Changed |
![]() |
32-bit | 0x00401665 |
![]() |
![]() |
...
|
satan2.exe | 3 | 0x00400000 | 0x0066EFFF | Content Changed |
![]() |
32-bit | 0x00401727 |
![]() |
![]() |
...
|
satan2.exe | 3 | 0x00400000 | 0x0066EFFF | Content Changed |
![]() |
32-bit | 0x004015E2 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.Ransom.AIG |
Malicious
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\DW20.EXE | Modified File | Binary |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\dwtrig20.exe.Hacker zasifroval zaplat.crypt | Dropped File | Binary |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\setup.exe | Modified File | Binary |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\DW\DW20.EXE | Modified File | Binary |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\DW\DWTRIG20.EXE | Modified File | Binary |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE | Modified File | Binary |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.JPG | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\FLTLDR.EXE.Hacker zasifroval zaplat.crypt | Dropped File | Binary |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\LICLUA.EXE | Modified File | Binary |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOICONS.EXE.Hacker zasifroval zaplat.crypt | Dropped File | Binary |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLED.EXE.Hacker zasifroval zaplat.crypt | Dropped File | Binary |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Oarpmany.exe | Modified File | Binary |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\ODeploy.exe.Hacker zasifroval zaplat.crypt | Dropped File | Binary |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Setup.exe | Modified File | Binary |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPREARM.EXE | Modified File | Binary |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE.Hacker zasifroval zaplat.crypt | Dropped File | Binary |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\1033\MCABOUT.HTM.Hacker zasifroval zaplat.crypt | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\METCONV.TXT | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\SmartTagInstall.exe | Modified File | Binary |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE.Hacker zasifroval zaplat.crypt | Dropped File | Binary |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\PREVIEW.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\PREVIEW.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\PREVIEW.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\PREVIEW.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\PREVIEW.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\PREVIEW.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\PREVIEW.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\PREVIEW.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\INDUST\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\INDUST\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\IRIS\PREVIEW.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\IRIS\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\JOURNAL\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\JOURNAL\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\LAYERS\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\LAYERS\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\LEVEL\PREVIEW.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\LEVEL\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\NETWORK\PREVIEW.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\NETWORK\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PAPYRUS\PREVIEW.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PAPYRUS\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PIXEL\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PIXEL\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PROFILE\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\PROFILE\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\QUAD\PREVIEW.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\QUAD\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RADIAL\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RADIAL\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\REFINED\PREVIEW.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RICEPAPR\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RICEPAPR\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RIPPLE\PREVIEW.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RIPPLE\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RMNSQUE\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SATIN\PREVIEW.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SATIN\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SKY\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SKY\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SLATE\PREVIEW.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SLATE\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SONORA\PREVIEW.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SPRING\PREVIEW.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SPRING\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\STRTEDGE\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\STRTEDGE\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\STUDIO\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\STUDIO\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SUMIPNTG\PREVIEW.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SUMIPNTG\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\WATER\PREVIEW.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\WATER\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\WATERMAR\PREVIEW.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\WATERMAR\THMBNAIL.PNG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\VSTO\10.0\VSTOInstaller.exe.Hacker zasifroval zaplat.crypt | Dropped File | Binary |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00154_.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00157_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00158_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00160_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00161_.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00163_.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00165_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00167_.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00169_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00170_.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00171_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00172_.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00174_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00175_.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00176_.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD10890_.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD10972_.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD19563_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD19582_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01046J.JPG.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01179J.JPG | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01213K.JPG | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01221K.JPG | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01235U.BMP.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01236U.BMP | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01239K.JPG | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01247U.BMP.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01255G.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01265U.BMP | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01332U.BMP | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01478U.BMP | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01562U.BMP.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01607U.BMP.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01931J.JPG.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02028K.JPG.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02039U.BMP | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH02040U.BMP.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\README.HTM | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\HOW TO DECRYPT FILES.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\THMBNAIL.PNG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\REFINED\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\RMNSQUE\PREVIEW.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\THEMES14\SONORA\THMBNAIL.PNG.Hacker zasifroval zaplat.crypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00164_.GIF.Hacker zasifroval zaplat.crypt | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\PH01035U.BMP | Dropped File | Stream |
Not Queried
|
...
|
»