VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: | - |
Threat Names: |
DeepScan:Generic.Ransom.Ouroboros.C7DB7BDE
DeepScan:Generic.Ransom.Ouroboros.6FE15DD8
Mal/Generic-S
|
osggoz.exe
Windows Exe (x86-32)
Created at 2020-02-09T09:00:00
Remarks
(0x0200001E): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x43afba |
Size Of Code | 0x65e00 |
Size Of Initialized Data | 0x25600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-08-17 09:45:23+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x65d2a | 0x65e00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.65 |
.rdata | 0x467000 | 0x1ab8a | 0x1ac00 | 0x66200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.27 |
.data | 0x482000 | 0x4e68 | 0x2a00 | 0x80e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.55 |
.rsrc | 0x487000 | 0x1e0 | 0x200 | 0x83800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.72 |
.reloc | 0x488000 | 0x575c | 0x5800 | 0x83a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.58 |
Imports (3)
»
KERNEL32.dll (102)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WaitForSingleObject | 0x0 | 0x467000 | 0x811e0 | 0x803e0 | 0x5d7 |
OpenProcess | 0x0 | 0x467004 | 0x811e4 | 0x803e4 | 0x40d |
CreateToolhelp32Snapshot | 0x0 | 0x467008 | 0x811e8 | 0x803e8 | 0xfc |
Process32Next | 0x0 | 0x46700c | 0x811ec | 0x803ec | 0x42d |
CloseHandle | 0x0 | 0x467010 | 0x811f0 | 0x803f0 | 0x86 |
FreeConsole | 0x0 | 0x467014 | 0x811f4 | 0x803f4 | 0x1a8 |
GetDriveTypeA | 0x0 | 0x467018 | 0x811f8 | 0x803f8 | 0x22e |
GetLastError | 0x0 | 0x46701c | 0x811fc | 0x803fc | 0x261 |
SetLastError | 0x0 | 0x467020 | 0x81200 | 0x80400 | 0x532 |
QueryPerformanceCounter | 0x0 | 0x467024 | 0x81204 | 0x80404 | 0x44d |
QueryPerformanceFrequency | 0x0 | 0x467028 | 0x81208 | 0x80408 | 0x44e |
GetCurrentThread | 0x0 | 0x46702c | 0x8120c | 0x8040c | 0x21b |
GetThreadTimes | 0x0 | 0x467030 | 0x81210 | 0x80410 | 0x305 |
WriteConsoleW | 0x0 | 0x467034 | 0x81214 | 0x80414 | 0x611 |
TerminateProcess | 0x0 | 0x467038 | 0x81218 | 0x80418 | 0x58c |
Process32First | 0x0 | 0x46703c | 0x8121c | 0x8041c | 0x42b |
CreateProcessA | 0x0 | 0x467040 | 0x81220 | 0x80420 | 0xe0 |
GetLogicalDrives | 0x0 | 0x467044 | 0x81224 | 0x80424 | 0x268 |
GetProcessHeap | 0x0 | 0x467048 | 0x81228 | 0x80428 | 0x2b4 |
SetStdHandle | 0x0 | 0x46704c | 0x8122c | 0x8042c | 0x54a |
FreeEnvironmentStringsW | 0x0 | 0x467050 | 0x81230 | 0x80430 | 0x1aa |
GetEnvironmentStringsW | 0x0 | 0x467054 | 0x81234 | 0x80434 | 0x237 |
GetOEMCP | 0x0 | 0x467058 | 0x81238 | 0x80438 | 0x297 |
GetACP | 0x0 | 0x46705c | 0x8123c | 0x8043c | 0x1b2 |
IsValidCodePage | 0x0 | 0x467060 | 0x81240 | 0x80440 | 0x38b |
HeapSize | 0x0 | 0x467064 | 0x81244 | 0x80444 | 0x34e |
HeapReAlloc | 0x0 | 0x467068 | 0x81248 | 0x80448 | 0x34c |
ReadConsoleW | 0x0 | 0x46706c | 0x8124c | 0x8044c | 0x470 |
ReadFile | 0x0 | 0x467070 | 0x81250 | 0x80450 | 0x473 |
EnumSystemLocalesW | 0x0 | 0x467074 | 0x81254 | 0x80454 | 0x154 |
GetUserDefaultLCID | 0x0 | 0x467078 | 0x81258 | 0x80458 | 0x312 |
IsValidLocale | 0x0 | 0x46707c | 0x8125c | 0x8045c | 0x38d |
HeapFree | 0x0 | 0x467080 | 0x81260 | 0x80460 | 0x349 |
GetConsoleMode | 0x0 | 0x467084 | 0x81264 | 0x80464 | 0x1fc |
GetConsoleCP | 0x0 | 0x467088 | 0x81268 | 0x80468 | 0x1ea |
FlushFileBuffers | 0x0 | 0x46708c | 0x8126c | 0x8046c | 0x19f |
HeapAlloc | 0x0 | 0x467090 | 0x81270 | 0x80470 | 0x345 |
GetFileType | 0x0 | 0x467094 | 0x81274 | 0x80474 | 0x24e |
GetFileSizeEx | 0x0 | 0x467098 | 0x81278 | 0x80478 | 0x24c |
CreateFileW | 0x0 | 0x46709c | 0x8127c | 0x8047c | 0xcb |
FindClose | 0x0 | 0x4670a0 | 0x81280 | 0x80480 | 0x175 |
FindFirstFileExW | 0x0 | 0x4670a4 | 0x81284 | 0x80484 | 0x17b |
FindNextFileW | 0x0 | 0x4670a8 | 0x81288 | 0x80488 | 0x18c |
GetDiskFreeSpaceExW | 0x0 | 0x4670ac | 0x8128c | 0x8048c | 0x228 |
GetFileAttributesExW | 0x0 | 0x4670b0 | 0x81290 | 0x80490 | 0x242 |
SetEndOfFile | 0x0 | 0x4670b4 | 0x81294 | 0x80494 | 0x510 |
SetFilePointerEx | 0x0 | 0x4670b8 | 0x81298 | 0x80498 | 0x523 |
AreFileApisANSI | 0x0 | 0x4670bc | 0x8129c | 0x8049c | 0x23 |
MultiByteToWideChar | 0x0 | 0x4670c0 | 0x812a0 | 0x804a0 | 0x3ef |
WideCharToMultiByte | 0x0 | 0x4670c4 | 0x812a4 | 0x804a4 | 0x5fe |
FormatMessageW | 0x0 | 0x4670c8 | 0x812a8 | 0x804a8 | 0x1a7 |
GetCurrentThreadId | 0x0 | 0x4670cc | 0x812ac | 0x804ac | 0x21c |
WaitForSingleObjectEx | 0x0 | 0x4670d0 | 0x812b0 | 0x804b0 | 0x5d8 |
SwitchToThread | 0x0 | 0x4670d4 | 0x812b4 | 0x804b4 | 0x587 |
GetExitCodeThread | 0x0 | 0x4670d8 | 0x812b8 | 0x804b8 | 0x23d |
GetStringTypeW | 0x0 | 0x4670dc | 0x812bc | 0x804bc | 0x2d7 |
EnterCriticalSection | 0x0 | 0x4670e0 | 0x812c0 | 0x804c0 | 0x131 |
LeaveCriticalSection | 0x0 | 0x4670e4 | 0x812c4 | 0x804c4 | 0x3bd |
DeleteCriticalSection | 0x0 | 0x4670e8 | 0x812c8 | 0x804c8 | 0x110 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4670ec | 0x812cc | 0x804cc | 0x35f |
CreateEventW | 0x0 | 0x4670f0 | 0x812d0 | 0x804d0 | 0xbf |
TlsAlloc | 0x0 | 0x4670f4 | 0x812d4 | 0x804d4 | 0x59e |
TlsGetValue | 0x0 | 0x4670f8 | 0x812d8 | 0x804d8 | 0x5a0 |
TlsSetValue | 0x0 | 0x4670fc | 0x812dc | 0x804dc | 0x5a1 |
TlsFree | 0x0 | 0x467100 | 0x812e0 | 0x804e0 | 0x59f |
GetSystemTimeAsFileTime | 0x0 | 0x467104 | 0x812e4 | 0x804e4 | 0x2e9 |
GetModuleHandleW | 0x0 | 0x467108 | 0x812e8 | 0x804e8 | 0x278 |
GetProcAddress | 0x0 | 0x46710c | 0x812ec | 0x804ec | 0x2ae |
EncodePointer | 0x0 | 0x467110 | 0x812f0 | 0x804f0 | 0x12d |
DecodePointer | 0x0 | 0x467114 | 0x812f4 | 0x804f4 | 0x109 |
CompareStringW | 0x0 | 0x467118 | 0x812f8 | 0x804f8 | 0x9b |
LCMapStringW | 0x0 | 0x46711c | 0x812fc | 0x804fc | 0x3b1 |
GetLocaleInfoW | 0x0 | 0x467120 | 0x81300 | 0x80500 | 0x265 |
GetCPInfo | 0x0 | 0x467124 | 0x81304 | 0x80504 | 0x1c1 |
InitializeSListHead | 0x0 | 0x467128 | 0x81308 | 0x80508 | 0x363 |
SetEvent | 0x0 | 0x46712c | 0x8130c | 0x8050c | 0x516 |
ResetEvent | 0x0 | 0x467130 | 0x81310 | 0x80510 | 0x4c6 |
IsProcessorFeaturePresent | 0x0 | 0x467134 | 0x81314 | 0x80514 | 0x386 |
UnhandledExceptionFilter | 0x0 | 0x467138 | 0x81318 | 0x80518 | 0x5ad |
SetUnhandledExceptionFilter | 0x0 | 0x46713c | 0x8131c | 0x8051c | 0x56d |
GetCurrentProcess | 0x0 | 0x467140 | 0x81320 | 0x80520 | 0x217 |
GetCurrentProcessId | 0x0 | 0x467144 | 0x81324 | 0x80524 | 0x218 |
IsDebuggerPresent | 0x0 | 0x467148 | 0x81328 | 0x80528 | 0x37f |
GetStartupInfoW | 0x0 | 0x46714c | 0x8132c | 0x8052c | 0x2d0 |
CreateThread | 0x0 | 0x467150 | 0x81330 | 0x80530 | 0xf3 |
FreeLibrary | 0x0 | 0x467154 | 0x81334 | 0x80534 | 0x1ab |
FreeLibraryAndExitThread | 0x0 | 0x467158 | 0x81338 | 0x80538 | 0x1ac |
GetModuleFileNameW | 0x0 | 0x46715c | 0x8133c | 0x8053c | 0x274 |
LoadLibraryExW | 0x0 | 0x467160 | 0x81340 | 0x80540 | 0x3c3 |
InterlockedPushEntrySList | 0x0 | 0x467164 | 0x81344 | 0x80544 | 0x36f |
RtlUnwind | 0x0 | 0x467168 | 0x81348 | 0x80548 | 0x4d3 |
RaiseException | 0x0 | 0x46716c | 0x8134c | 0x8054c | 0x462 |
ExitThread | 0x0 | 0x467170 | 0x81350 | 0x80550 | 0x15f |
GetModuleHandleExW | 0x0 | 0x467174 | 0x81354 | 0x80554 | 0x277 |
SetEnvironmentVariableW | 0x0 | 0x467178 | 0x81358 | 0x80558 | 0x514 |
DeleteFileW | 0x0 | 0x46717c | 0x8135c | 0x8055c | 0x115 |
MoveFileExW | 0x0 | 0x467180 | 0x81360 | 0x80560 | 0x3e8 |
GetStdHandle | 0x0 | 0x467184 | 0x81364 | 0x80564 | 0x2d2 |
WriteFile | 0x0 | 0x467188 | 0x81368 | 0x80568 | 0x612 |
ExitProcess | 0x0 | 0x46718c | 0x8136c | 0x8056c | 0x15e |
GetCommandLineA | 0x0 | 0x467190 | 0x81370 | 0x80570 | 0x1d6 |
GetCommandLineW | 0x0 | 0x467194 | 0x81374 | 0x80574 | 0x1d7 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteA | 0x0 | 0x46719c | 0x8137c | 0x8057c | 0x1b2 |
WS2_32.dll (19)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
htons | 0x9 | 0x4671a4 | 0x81384 | 0x80584 | - |
ioctlsocket | 0xa | 0x4671a8 | 0x81388 | 0x80588 | - |
closesocket | 0x3 | 0x4671ac | 0x8138c | 0x8058c | - |
send | 0x13 | 0x4671b0 | 0x81390 | 0x80590 | - |
select | 0x12 | 0x4671b4 | 0x81394 | 0x80594 | - |
recv | 0x10 | 0x4671b8 | 0x81398 | 0x80598 | - |
getpeername | 0x5 | 0x4671bc | 0x8139c | 0x8059c | - |
WSAStartup | 0x73 | 0x4671c0 | 0x813a0 | 0x805a0 | - |
getaddrinfo | 0x0 | 0x4671c4 | 0x813a4 | 0x805a4 | 0x96 |
ntohl | 0xe | 0x4671c8 | 0x813a8 | 0x805a8 | - |
inet_ntoa | 0xc | 0x4671cc | 0x813ac | 0x805ac | - |
inet_addr | 0xb | 0x4671d0 | 0x813b0 | 0x805b0 | - |
htonl | 0x8 | 0x4671d4 | 0x813b4 | 0x805b4 | - |
connect | 0x4 | 0x4671d8 | 0x813b8 | 0x805b8 | - |
socket | 0x17 | 0x4671dc | 0x813bc | 0x805bc | - |
setsockopt | 0x15 | 0x4671e0 | 0x813c0 | 0x805c0 | - |
WSAGetLastError | 0x6f | 0x4671e4 | 0x813c4 | 0x805c4 | - |
WSACleanup | 0x74 | 0x4671e8 | 0x813c8 | 0x805c8 | - |
freeaddrinfo | 0x0 | 0x4671ec | 0x813cc | 0x805cc | 0x95 |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
osggoz.exe | 1 | 0x01000000 | 0x0108DFFF | Relevant Image |
![]() |
32-bit | 0x0103EF96 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
DeepScan:Generic.Ransom.Ouroboros.C7DB7BDE |
Malicious
|
C:\588bce7c90097ed212\1040\SetupResources.dll | Modified File | Batch |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\588bce7c90097ed212\netfx_Core.mzz | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core.mzz | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x64.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x64.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems64.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems64.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R64.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R64.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pidgenx.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\awt.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\awt.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\SetupComplete.cmd.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\LocalizedData.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\SetupResources.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\LocalizedData.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\SetupResources.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\SetupResources.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\SetupResources.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\LocalizedData.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\SetupResources.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\LocalizedData.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\SetupResources.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\LocalizedData.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\LocalizedData.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\SetupResources.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\SetupResources.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\LocalizedData.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\SetupResources.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\eula.rtf.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\SetupResources.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\LocalizedData.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\SetupResources.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\eula.rtf.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\LocalizedData.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\SetupResources.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\eula.rtf.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\LocalizedData.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\SetupResources.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\SetupResources.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\eula.rtf.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\SetupResources.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\SetupResources.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\eula.rtf.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\LocalizedData.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\SetupResources.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\eula.rtf.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\LocalizedData.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\LocalizedData.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\SetupResources.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\LocalizedData.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\SetupResources.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\eula.rtf.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\LocalizedData.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\SetupResources.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\LocalizedData.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\SetupResources.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\Parameterinfo.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\UiInfo.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DHtmlHeader.html.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DisplayIcon.ico.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\Parameterinfo.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\UiInfo.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate1.ico.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate2.ico.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate3.ico.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate4.ico.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate5.ico.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate6.ico.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate7.ico.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate8.ico.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Save.ico.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\stop.ico.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqMet.ico.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\warn.ico.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x64.msi.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x86.msi.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\RGB9RAST_x64.msi.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Setup.exe.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupEngine.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupUi.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupUtility.exe.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\sqmapi.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\UiInfo.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\BOOTSTAT.DAT.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\BOOTNXT.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Application.evtx.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Key Management Service.evtx.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Setup.evtx.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\DESIGNER\MSADDNDR.OLB.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l1-2-0.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-localization-l1-2-0.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-synch-l1-2-0.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-timezone-l1-1-0.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-xstate-l2-1-0.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-conio-l1-1-0.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-convert-l1-1-0.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-environment-l1-1-0.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-filesystem-l1-1-0.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-heap-l1-1-0.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-locale-l1-1-0.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-math-l1-1-0.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-multibyte-l1-1-0.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-private-l1-1-0.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-process-l1-1-0.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-runtime-l1-1-0.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-stdio-l1-1-0.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-string-l1-1-0.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-time-l1-1-0.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-utility-l1-1-0.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream32.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream64.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pidgenx.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\jfxwebkit.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\preoobe.cmd.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\eula.rtf.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\SetupResources.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1033\eula.rtf.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1036\SetupResources.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1041\LocalizedData.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\LocalizedData.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1046\LocalizedData.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1049\LocalizedData.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1055\SetupResources.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Print.ico.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Setup.ico.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\header.bmp.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\RGB9Rast_x86.msi.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Strings.xml.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\BCD.LOG2.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-file-l2-1-0.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-processthreads-l1-1-1.dll.[ID=db2MhNyt6x][Mail=DecrypterSupport@protonmail.com].Lazarus | Dropped File | Stream |
Not Queried
|
...
|
»