VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Downloader, Trojan, Backdoor |
2B74.TMP.EXE.exe
Windows Exe (x86-32)
Created at 2019-09-16T06:39:00
Remarks (2/3)
(0x200000e): The overall sleep time of all monitored processes was truncated from "40 seconds" to "10 seconds" to reveal dormant functionality.
(0x200003a): 2 tasks were rescheduled ahead of time to reveal dormant functionality.
Remarks
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\2B74.TMP.EXE.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-09-14 03:51 (UTC+2) |
Last Seen | 2019-09-15 05:12 (UTC+2) |
Names | Win32.Trojan.Ramnit |
Families | Ramnit |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x49a3d6 |
Size Of Code | 0xa7800 |
Size Of Initialized Data | 0x2f2ea00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-11-17 09:11:20+00:00 |
Version Information (2)
»
InternalName | sdnzsdj.ole |
ProductVersion | 2.9.21.7 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xa771c | 0xa7800 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.95 |
.data | 0x4a9000 | 0x2f28e08 | 0x19800 | 0xa7c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.07 |
.idata | 0x33d2000 | 0x830 | 0xa00 | 0xc1400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.02 |
.gfids | 0x33d3000 | 0x10ac | 0x400 | 0xc1e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.01 |
.rsrc | 0x33d5000 | 0x3bd8 | 0x3c00 | 0xc2200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.27 |
.reloc | 0x33d9000 | 0xec4 | 0x1000 | 0xc5e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.35 |
Imports (2)
»
KERNEL32.dll (74)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateTimerQueueTimer | 0x0 | 0x33d2000 | 0x2fd2178 | 0xc1578 | 0xbd |
CompareStringW | 0x0 | 0x33d2004 | 0x2fd217c | 0xc157c | 0x64 |
VirtualProtect | 0x0 | 0x33d2008 | 0x2fd2180 | 0xc1580 | 0x4ef |
GetHandleInformation | 0x0 | 0x33d200c | 0x2fd2184 | 0xc1584 | 0x1ff |
WriteFile | 0x0 | 0x33d2010 | 0x2fd2188 | 0xc1588 | 0x525 |
TerminateProcess | 0x0 | 0x33d2014 | 0x2fd218c | 0xc158c | 0x4c0 |
lstrlenA | 0x0 | 0x33d2018 | 0x2fd2190 | 0xc1590 | 0x54d |
LocalAlloc | 0x0 | 0x33d201c | 0x2fd2194 | 0xc1594 | 0x344 |
ExitThread | 0x0 | 0x33d2020 | 0x2fd2198 | 0xc1598 | 0x11a |
GetNumberFormatA | 0x0 | 0x33d2024 | 0x2fd219c | 0xc159c | 0x231 |
LoadLibraryA | 0x0 | 0x33d2028 | 0x2fd21a0 | 0xc15a0 | 0x33c |
lstrcatW | 0x0 | 0x33d202c | 0x2fd21a4 | 0xc15a4 | 0x53f |
CloseHandle | 0x0 | 0x33d2030 | 0x2fd21a8 | 0xc15a8 | 0x52 |
GetProcAddress | 0x0 | 0x33d2034 | 0x2fd21ac | 0xc15ac | 0x245 |
ExitProcess | 0x0 | 0x33d2038 | 0x2fd21b0 | 0xc15b0 | 0x119 |
FormatMessageA | 0x0 | 0x33d203c | 0x2fd21b4 | 0xc15b4 | 0x15d |
CreateFileW | 0x0 | 0x33d2040 | 0x2fd21b8 | 0xc15b8 | 0x8f |
DecodePointer | 0x0 | 0x33d2044 | 0x2fd21bc | 0xc15bc | 0xca |
UnhandledExceptionFilter | 0x0 | 0x33d2048 | 0x2fd21c0 | 0xc15c0 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x33d204c | 0x2fd21c4 | 0xc15c4 | 0x4a5 |
GetCurrentProcess | 0x0 | 0x33d2050 | 0x2fd21c8 | 0xc15c8 | 0x1c0 |
IsProcessorFeaturePresent | 0x0 | 0x33d2054 | 0x2fd21cc | 0xc15cc | 0x304 |
QueryPerformanceCounter | 0x0 | 0x33d2058 | 0x2fd21d0 | 0xc15d0 | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x33d205c | 0x2fd21d4 | 0xc15d4 | 0x1c1 |
GetCurrentThreadId | 0x0 | 0x33d2060 | 0x2fd21d8 | 0xc15d8 | 0x1c5 |
GetSystemTimeAsFileTime | 0x0 | 0x33d2064 | 0x2fd21dc | 0xc15dc | 0x279 |
InitializeSListHead | 0x0 | 0x33d2068 | 0x2fd21e0 | 0xc15e0 | 0x2e7 |
IsDebuggerPresent | 0x0 | 0x33d206c | 0x2fd21e4 | 0xc15e4 | 0x300 |
GetStartupInfoW | 0x0 | 0x33d2070 | 0x2fd21e8 | 0xc15e8 | 0x263 |
GetModuleHandleW | 0x0 | 0x33d2074 | 0x2fd21ec | 0xc15ec | 0x218 |
RtlUnwind | 0x0 | 0x33d2078 | 0x2fd21f0 | 0xc15f0 | 0x418 |
GetLastError | 0x0 | 0x33d207c | 0x2fd21f4 | 0xc15f4 | 0x202 |
SetLastError | 0x0 | 0x33d2080 | 0x2fd21f8 | 0xc15f8 | 0x473 |
EnterCriticalSection | 0x0 | 0x33d2084 | 0x2fd21fc | 0xc15fc | 0xee |
LeaveCriticalSection | 0x0 | 0x33d2088 | 0x2fd2200 | 0xc1600 | 0x339 |
DeleteCriticalSection | 0x0 | 0x33d208c | 0x2fd2204 | 0xc1604 | 0xd1 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x33d2090 | 0x2fd2208 | 0xc1608 | 0x2e3 |
TlsAlloc | 0x0 | 0x33d2094 | 0x2fd220c | 0xc160c | 0x4c5 |
TlsGetValue | 0x0 | 0x33d2098 | 0x2fd2210 | 0xc1610 | 0x4c7 |
TlsSetValue | 0x0 | 0x33d209c | 0x2fd2214 | 0xc1614 | 0x4c8 |
TlsFree | 0x0 | 0x33d20a0 | 0x2fd2218 | 0xc1618 | 0x4c6 |
FreeLibrary | 0x0 | 0x33d20a4 | 0x2fd221c | 0xc161c | 0x162 |
LoadLibraryExW | 0x0 | 0x33d20a8 | 0x2fd2220 | 0xc1620 | 0x33e |
GetStdHandle | 0x0 | 0x33d20ac | 0x2fd2224 | 0xc1624 | 0x264 |
GetModuleFileNameW | 0x0 | 0x33d20b0 | 0x2fd2228 | 0xc1628 | 0x214 |
MultiByteToWideChar | 0x0 | 0x33d20b4 | 0x2fd222c | 0xc162c | 0x367 |
WideCharToMultiByte | 0x0 | 0x33d20b8 | 0x2fd2230 | 0xc1630 | 0x511 |
GetModuleHandleExW | 0x0 | 0x33d20bc | 0x2fd2234 | 0xc1634 | 0x217 |
GetACP | 0x0 | 0x33d20c0 | 0x2fd2238 | 0xc1638 | 0x168 |
HeapFree | 0x0 | 0x33d20c4 | 0x2fd223c | 0xc163c | 0x2cf |
HeapAlloc | 0x0 | 0x33d20c8 | 0x2fd2240 | 0xc1640 | 0x2cb |
FindClose | 0x0 | 0x33d20cc | 0x2fd2244 | 0xc1644 | 0x12e |
FindFirstFileExW | 0x0 | 0x33d20d0 | 0x2fd2248 | 0xc1648 | 0x134 |
FindNextFileW | 0x0 | 0x33d20d4 | 0x2fd224c | 0xc164c | 0x145 |
IsValidCodePage | 0x0 | 0x33d20d8 | 0x2fd2250 | 0xc1650 | 0x30a |
GetOEMCP | 0x0 | 0x33d20dc | 0x2fd2254 | 0xc1654 | 0x237 |
GetCPInfo | 0x0 | 0x33d20e0 | 0x2fd2258 | 0xc1658 | 0x172 |
GetCommandLineA | 0x0 | 0x33d20e4 | 0x2fd225c | 0xc165c | 0x186 |
GetCommandLineW | 0x0 | 0x33d20e8 | 0x2fd2260 | 0xc1660 | 0x187 |
GetEnvironmentStringsW | 0x0 | 0x33d20ec | 0x2fd2264 | 0xc1664 | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x33d20f0 | 0x2fd2268 | 0xc1668 | 0x161 |
LCMapStringW | 0x0 | 0x33d20f4 | 0x2fd226c | 0xc166c | 0x32d |
SetStdHandle | 0x0 | 0x33d20f8 | 0x2fd2270 | 0xc1670 | 0x487 |
GetFileType | 0x0 | 0x33d20fc | 0x2fd2274 | 0xc1674 | 0x1f3 |
GetStringTypeW | 0x0 | 0x33d2100 | 0x2fd2278 | 0xc1678 | 0x269 |
GetProcessHeap | 0x0 | 0x33d2104 | 0x2fd227c | 0xc167c | 0x24a |
HeapSize | 0x0 | 0x33d2108 | 0x2fd2280 | 0xc1680 | 0x2d4 |
HeapReAlloc | 0x0 | 0x33d210c | 0x2fd2284 | 0xc1684 | 0x2d2 |
FlushFileBuffers | 0x0 | 0x33d2110 | 0x2fd2288 | 0xc1688 | 0x157 |
GetConsoleCP | 0x0 | 0x33d2114 | 0x2fd228c | 0xc168c | 0x19a |
GetConsoleMode | 0x0 | 0x33d2118 | 0x2fd2290 | 0xc1690 | 0x1ac |
SetFilePointerEx | 0x0 | 0x33d211c | 0x2fd2294 | 0xc1694 | 0x467 |
WriteConsoleW | 0x0 | 0x33d2120 | 0x2fd2298 | 0xc1698 | 0x524 |
RaiseException | 0x0 | 0x33d2124 | 0x2fd229c | 0xc169c | 0x3b1 |
ole32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoIsOle1Class | 0x0 | 0x33d212c | 0x2fd22a4 | 0xc16a4 | 0x45 |
ProgIDFromCLSID | 0x0 | 0x33d2130 | 0x2fd22a8 | 0xc16a8 | 0x14b |
Memory Dumps (7)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
buffer | 1 | 0x002B0020 | 0x0034425F | Marked Executable | - | 32-bit | 0x002B17E2 |
![]() |
![]() |
...
|
buffer | 1 | 0x04D40000 | 0x04E59FFF | First Execution | - | 32-bit | 0x04D40000 |
![]() |
![]() |
...
|
buffer | 5 | 0x00210020 | 0x002A425F | Marked Executable | - | 32-bit | 0x002117E2 |
![]() |
![]() |
...
|
buffer | 5 | 0x00210020 | 0x002A425F | Content Changed | - | 32-bit | 0x00211F7B |
![]() |
![]() |
...
|
buffer | 5 | 0x033E0000 | 0x034F9FFF | First Execution | - | 32-bit | 0x033E0000 |
![]() |
![]() |
...
|
buffer | 18 | 0x00280020 | 0x0031425F | Marked Executable | - | 32-bit | 0x002817E2 |
![]() |
![]() |
...
|
buffer | 18 | 0x04C40000 | 0x04D59FFF | First Execution | - | 32-bit | 0x04C40000 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.32452318 |
Malicious
|
C:\Windows\System32\drivers\etc\hosts | Modified File | Text |
Malicious
|
...
|
»
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Trojan.Qhost.1 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\TQA_umDM14EkRmKehkUw.pdf.kvag | Dropped File |
Malicious
|
...
|
»
YARA Matches (3)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
4/5
|
...
|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\applvCx 7 7q.pdf | Modified File |
Malicious
|
...
|
»
YARA Matches (3)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
4/5
|
...
|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\cIMF3tKpAi.pdf | Modified File |
Malicious
|
...
|
»
YARA Matches (3)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
4/5
|
...
|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\i8DRxWeUJn.pdf.kvag | Dropped File |
Malicious
|
...
|
»
YARA Matches (3)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
4/5
|
...
|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\WzADlxLJE55HVxluBPw.pdf | Modified File |
Malicious
|
...
|
»
YARA Matches (3)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
4/5
|
...
|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\16ec01a8-9cb0-4fd9-9d7a-ff79ab43a52d\updatewin1.exe | Downloaded File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-01-16 22:21 (UTC+1) |
Last Seen | 2019-07-21 22:40 (UTC+2) |
Names | Win32.Trojan.Kryptik |
Families | Kryptik |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x402d76 |
Size Of Code | 0x1c200 |
Size Of Initialized Data | 0x2c200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-07-24 12:23:54+00:00 |
Version Information (3)
»
FileVersion | 7.7.7.18 |
InternalName | rawudiyeh.exe |
LegalCopyright | Copyright (C) 2018, sacuwedimufoy |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1c07e | 0x1c200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x41e000 | 0x463e | 0x4800 | 0x1c600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.26 |
.data | 0x423000 | 0x1c6a8 | 0x17400 | 0x20e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.83 |
.rsrc | 0x440000 | 0xa578 | 0xa600 | 0x38200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.88 |
.reloc | 0x44b000 | 0x1968 | 0x1a00 | 0x42800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.34 |
Imports (4)
»
KERNEL32.dll (102)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitThread | 0x0 | 0x41e028 | 0x21afc | 0x200fc | 0x105 |
GetStartupInfoW | 0x0 | 0x41e02c | 0x21b00 | 0x20100 | 0x23a |
GetLastError | 0x0 | 0x41e030 | 0x21b04 | 0x20104 | 0x1e6 |
GetProcAddress | 0x0 | 0x41e034 | 0x21b08 | 0x20108 | 0x220 |
CreateJobSet | 0x0 | 0x41e038 | 0x21b0c | 0x2010c | 0x87 |
GlobalFree | 0x0 | 0x41e03c | 0x21b10 | 0x20110 | 0x28c |
LoadLibraryA | 0x0 | 0x41e040 | 0x21b14 | 0x20114 | 0x2f1 |
OpenWaitableTimerW | 0x0 | 0x41e044 | 0x21b18 | 0x20118 | 0x339 |
AddAtomA | 0x0 | 0x41e048 | 0x21b1c | 0x2011c | 0x3 |
FindFirstChangeNotificationA | 0x0 | 0x41e04c | 0x21b20 | 0x20120 | 0x11b |
VirtualProtect | 0x0 | 0x41e050 | 0x21b24 | 0x20124 | 0x45a |
GetCurrentDirectoryA | 0x0 | 0x41e054 | 0x21b28 | 0x20128 | 0x1a7 |
GetACP | 0x0 | 0x41e058 | 0x21b2c | 0x2012c | 0x152 |
InterlockedPushEntrySList | 0x0 | 0x41e05c | 0x21b30 | 0x20130 | 0x2c2 |
CompareStringW | 0x0 | 0x41e060 | 0x21b34 | 0x20134 | 0x55 |
CompareStringA | 0x0 | 0x41e064 | 0x21b38 | 0x20138 | 0x52 |
CreateFileA | 0x0 | 0x41e068 | 0x21b3c | 0x2013c | 0x78 |
GetTimeZoneInformation | 0x0 | 0x41e06c | 0x21b40 | 0x20140 | 0x26b |
WriteConsoleW | 0x0 | 0x41e070 | 0x21b44 | 0x20144 | 0x48c |
GetConsoleOutputCP | 0x0 | 0x41e074 | 0x21b48 | 0x20148 | 0x199 |
WriteConsoleA | 0x0 | 0x41e078 | 0x21b4c | 0x2014c | 0x482 |
CloseHandle | 0x0 | 0x41e07c | 0x21b50 | 0x20150 | 0x43 |
IsValidLocale | 0x0 | 0x41e080 | 0x21b54 | 0x20154 | 0x2dd |
EnumSystemLocalesA | 0x0 | 0x41e084 | 0x21b58 | 0x20158 | 0xf8 |
GetUserDefaultLCID | 0x0 | 0x41e088 | 0x21b5c | 0x2015c | 0x26d |
GetSystemTimeAdjustment | 0x0 | 0x41e08c | 0x21b60 | 0x20160 | 0x24e |
GetSystemTimes | 0x0 | 0x41e090 | 0x21b64 | 0x20164 | 0x250 |
GetTickCount | 0x0 | 0x41e094 | 0x21b68 | 0x20168 | 0x266 |
FreeEnvironmentStringsA | 0x0 | 0x41e098 | 0x21b6c | 0x2016c | 0x14a |
GetComputerNameW | 0x0 | 0x41e09c | 0x21b70 | 0x20170 | 0x178 |
FindCloseChangeNotification | 0x0 | 0x41e0a0 | 0x21b74 | 0x20174 | 0x11a |
FindResourceExW | 0x0 | 0x41e0a4 | 0x21b78 | 0x20178 | 0x138 |
GetCPInfo | 0x0 | 0x41e0a8 | 0x21b7c | 0x2017c | 0x15b |
SetProcessShutdownParameters | 0x0 | 0x41e0ac | 0x21b80 | 0x20180 | 0x3f9 |
GetModuleHandleExA | 0x0 | 0x41e0b0 | 0x21b84 | 0x20184 | 0x1f7 |
GetDateFormatA | 0x0 | 0x41e0b4 | 0x21b88 | 0x20188 | 0x1ae |
GetTimeFormatA | 0x0 | 0x41e0b8 | 0x21b8c | 0x2018c | 0x268 |
GetStringTypeW | 0x0 | 0x41e0bc | 0x21b90 | 0x20190 | 0x240 |
GetStringTypeA | 0x0 | 0x41e0c0 | 0x21b94 | 0x20194 | 0x23d |
LCMapStringW | 0x0 | 0x41e0c4 | 0x21b98 | 0x20198 | 0x2e3 |
GetCommandLineA | 0x0 | 0x41e0c8 | 0x21b9c | 0x2019c | 0x16f |
GetStartupInfoA | 0x0 | 0x41e0cc | 0x21ba0 | 0x201a0 | 0x239 |
RaiseException | 0x0 | 0x41e0d0 | 0x21ba4 | 0x201a4 | 0x35a |
RtlUnwind | 0x0 | 0x41e0d4 | 0x21ba8 | 0x201a8 | 0x392 |
TerminateProcess | 0x0 | 0x41e0d8 | 0x21bac | 0x201ac | 0x42d |
GetCurrentProcess | 0x0 | 0x41e0dc | 0x21bb0 | 0x201b0 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x41e0e0 | 0x21bb4 | 0x201b4 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x41e0e4 | 0x21bb8 | 0x201b8 | 0x415 |
IsDebuggerPresent | 0x0 | 0x41e0e8 | 0x21bbc | 0x201bc | 0x2d1 |
HeapAlloc | 0x0 | 0x41e0ec | 0x21bc0 | 0x201c0 | 0x29d |
HeapFree | 0x0 | 0x41e0f0 | 0x21bc4 | 0x201c4 | 0x2a1 |
EnterCriticalSection | 0x0 | 0x41e0f4 | 0x21bc8 | 0x201c8 | 0xd9 |
LeaveCriticalSection | 0x0 | 0x41e0f8 | 0x21bcc | 0x201cc | 0x2ef |
SetHandleCount | 0x0 | 0x41e0fc | 0x21bd0 | 0x201d0 | 0x3e8 |
GetStdHandle | 0x0 | 0x41e100 | 0x21bd4 | 0x201d4 | 0x23b |
GetFileType | 0x0 | 0x41e104 | 0x21bd8 | 0x201d8 | 0x1d7 |
DeleteCriticalSection | 0x0 | 0x41e108 | 0x21bdc | 0x201dc | 0xbe |
GetModuleHandleW | 0x0 | 0x41e10c | 0x21be0 | 0x201e0 | 0x1f9 |
Sleep | 0x0 | 0x41e110 | 0x21be4 | 0x201e4 | 0x421 |
ExitProcess | 0x0 | 0x41e114 | 0x21be8 | 0x201e8 | 0x104 |
WriteFile | 0x0 | 0x41e118 | 0x21bec | 0x201ec | 0x48d |
GetModuleFileNameA | 0x0 | 0x41e11c | 0x21bf0 | 0x201f0 | 0x1f4 |
GetEnvironmentStrings | 0x0 | 0x41e120 | 0x21bf4 | 0x201f4 | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x41e124 | 0x21bf8 | 0x201f8 | 0x14b |
WideCharToMultiByte | 0x0 | 0x41e128 | 0x21bfc | 0x201fc | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x41e12c | 0x21c00 | 0x20200 | 0x1c1 |
TlsGetValue | 0x0 | 0x41e130 | 0x21c04 | 0x20204 | 0x434 |
TlsAlloc | 0x0 | 0x41e134 | 0x21c08 | 0x20208 | 0x432 |
TlsSetValue | 0x0 | 0x41e138 | 0x21c0c | 0x2020c | 0x435 |
TlsFree | 0x0 | 0x41e13c | 0x21c10 | 0x20210 | 0x433 |
InterlockedIncrement | 0x0 | 0x41e140 | 0x21c14 | 0x20214 | 0x2c0 |
SetLastError | 0x0 | 0x41e144 | 0x21c18 | 0x20218 | 0x3ec |
GetCurrentThreadId | 0x0 | 0x41e148 | 0x21c1c | 0x2021c | 0x1ad |
InterlockedDecrement | 0x0 | 0x41e14c | 0x21c20 | 0x20220 | 0x2bc |
GetCurrentThread | 0x0 | 0x41e150 | 0x21c24 | 0x20224 | 0x1ac |
HeapCreate | 0x0 | 0x41e154 | 0x21c28 | 0x20228 | 0x29f |
HeapDestroy | 0x0 | 0x41e158 | 0x21c2c | 0x2022c | 0x2a0 |
VirtualFree | 0x0 | 0x41e15c | 0x21c30 | 0x20230 | 0x457 |
QueryPerformanceCounter | 0x0 | 0x41e160 | 0x21c34 | 0x20234 | 0x354 |
GetCurrentProcessId | 0x0 | 0x41e164 | 0x21c38 | 0x20238 | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x41e168 | 0x21c3c | 0x2023c | 0x24f |
FatalAppExitA | 0x0 | 0x41e16c | 0x21c40 | 0x20240 | 0x10b |
VirtualAlloc | 0x0 | 0x41e170 | 0x21c44 | 0x20244 | 0x454 |
HeapReAlloc | 0x0 | 0x41e174 | 0x21c48 | 0x20248 | 0x2a4 |
MultiByteToWideChar | 0x0 | 0x41e178 | 0x21c4c | 0x2024c | 0x31a |
ReadFile | 0x0 | 0x41e17c | 0x21c50 | 0x20250 | 0x368 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41e180 | 0x21c54 | 0x20254 | 0x2b5 |
HeapSize | 0x0 | 0x41e184 | 0x21c58 | 0x20258 | 0x2a6 |
SetConsoleCtrlHandler | 0x0 | 0x41e188 | 0x21c5c | 0x2025c | 0x3a7 |
FreeLibrary | 0x0 | 0x41e18c | 0x21c60 | 0x20260 | 0x14c |
InterlockedExchange | 0x0 | 0x41e190 | 0x21c64 | 0x20264 | 0x2bd |
GetOEMCP | 0x0 | 0x41e194 | 0x21c68 | 0x20268 | 0x213 |
IsValidCodePage | 0x0 | 0x41e198 | 0x21c6c | 0x2026c | 0x2db |
GetConsoleCP | 0x0 | 0x41e19c | 0x21c70 | 0x20270 | 0x183 |
GetConsoleMode | 0x0 | 0x41e1a0 | 0x21c74 | 0x20274 | 0x195 |
FlushFileBuffers | 0x0 | 0x41e1a4 | 0x21c78 | 0x20278 | 0x141 |
SetFilePointer | 0x0 | 0x41e1a8 | 0x21c7c | 0x2027c | 0x3df |
SetStdHandle | 0x0 | 0x41e1ac | 0x21c80 | 0x20280 | 0x3fc |
GetLocaleInfoW | 0x0 | 0x41e1b0 | 0x21c84 | 0x20284 | 0x1ea |
GetLocaleInfoA | 0x0 | 0x41e1b4 | 0x21c88 | 0x20288 | 0x1e8 |
LCMapStringA | 0x0 | 0x41e1b8 | 0x21c8c | 0x2028c | 0x2e1 |
SetEnvironmentVariableA | 0x0 | 0x41e1bc | 0x21c90 | 0x20290 | 0x3d0 |
USER32.dll (10)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseClipboard | 0x0 | 0x41e1d8 | 0x21cac | 0x202ac | 0x47 |
BeginPaint | 0x0 | 0x41e1dc | 0x21cb0 | 0x202b0 | 0xe |
CallMsgFilterW | 0x0 | 0x41e1e0 | 0x21cb4 | 0x202b4 | 0x1a |
PeekMessageA | 0x0 | 0x41e1e4 | 0x21cb8 | 0x202b8 | 0x21b |
MapVirtualKeyExW | 0x0 | 0x41e1e8 | 0x21cbc | 0x202bc | 0x1f1 |
RegisterRawInputDevices | 0x0 | 0x41e1ec | 0x21cc0 | 0x202c0 | 0x242 |
GetClipboardSequenceNumber | 0x0 | 0x41e1f0 | 0x21cc4 | 0x202c4 | 0x113 |
CountClipboardFormats | 0x0 | 0x41e1f4 | 0x21cc8 | 0x202c8 | 0x50 |
GetDialogBaseUnits | 0x0 | 0x41e1f8 | 0x21ccc | 0x202cc | 0x11d |
GetClassLongW | 0x0 | 0x41e1fc | 0x21cd0 | 0x202d0 | 0x109 |
GDI32.dll (9)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PolyTextOutW | 0x0 | 0x41e000 | 0x21ad4 | 0x200d4 | 0x23c |
CreateCompatibleDC | 0x0 | 0x41e004 | 0x21ad8 | 0x200d8 | 0x2e |
Rectangle | 0x0 | 0x41e008 | 0x21adc | 0x200dc | 0x246 |
SetStretchBltMode | 0x0 | 0x41e00c | 0x21ae0 | 0x200e0 | 0x289 |
SetPixelV | 0x0 | 0x41e010 | 0x21ae4 | 0x200e4 | 0x284 |
GetClipBox | 0x0 | 0x41e014 | 0x21ae8 | 0x200e8 | 0x1aa |
CreateDiscardableBitmap | 0x0 | 0x41e018 | 0x21aec | 0x200ec | 0x35 |
StrokeAndFillPath | 0x0 | 0x41e01c | 0x21af0 | 0x200f0 | 0x29c |
GetBitmapBits | 0x0 | 0x41e020 | 0x21af4 | 0x200f4 | 0x191 |
SHELL32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x41e1c4 | 0x21c98 | 0x20298 | 0x118 |
ShellAboutW | 0x0 | 0x41e1c8 | 0x21c9c | 0x2029c | 0x110 |
DuplicateIcon | 0x0 | 0x41e1cc | 0x21ca0 | 0x202a0 | 0x23 |
DragQueryFileA | 0x0 | 0x41e1d0 | 0x21ca4 | 0x202a4 | 0x1e |
Memory Dumps (10)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
updatewin1.exe | 6 | 0x00400000 | 0x0044CFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
updatewin1.exe | 6 | 0x00400000 | 0x0044CFFF | Content Changed | - | 32-bit | 0x004023F7 |
![]() |
![]() |
...
|
updatewin1.exe | 6 | 0x00400000 | 0x0044CFFF | Content Changed | - | 32-bit | 0x0040DB13 |
![]() |
![]() |
...
|
updatewin1.exe | 6 | 0x00400000 | 0x0044CFFF | Content Changed | - | 32-bit | 0x00409A4F |
![]() |
![]() |
...
|
updatewin1.exe | 6 | 0x00400000 | 0x0044CFFF | Content Changed | - | 32-bit | 0x00401810 |
![]() |
![]() |
...
|
updatewin1.exe | 6 | 0x00400000 | 0x0044CFFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
updatewin1.exe | 11 | 0x00400000 | 0x0044CFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
updatewin1.exe | 11 | 0x00400000 | 0x0044CFFF | Content Changed | - | 32-bit | 0x004023F7 |
![]() |
![]() |
...
|
updatewin1.exe | 11 | 0x00400000 | 0x0044CFFF | Content Changed | - | 32-bit | 0x0040DB13 |
![]() |
![]() |
...
|
updatewin1.exe | 11 | 0x00400000 | 0x0044CFFF | Content Changed | - | 32-bit | 0x00401810 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.31534187 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\16ec01a8-9cb0-4fd9-9d7a-ff79ab43a52d\updatewin2.exe | Downloaded File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-01-16 22:21 (UTC+1) |
Last Seen | 2019-09-04 10:43 (UTC+2) |
Names | Win32.Trojan.Qhost |
Families | Qhost |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x402d64 |
Size Of Code | 0x1c200 |
Size Of Initialized Data | 0x2c800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-11-21 06:08:45+00:00 |
Version Information (3)
»
FileVersion | 5.3.7.82 |
InternalName | gigifaw.exe |
LegalCopyright | Copyright (C) 2018, guvaxiz |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1c03e | 0x1c200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x41e000 | 0x45ec | 0x4600 | 0x1c600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.34 |
.data | 0x423000 | 0x1cde8 | 0x17c00 | 0x20c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.8 |
.rsrc | 0x440000 | 0xa724 | 0xa800 | 0x38800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.88 |
.reloc | 0x44b000 | 0x195c | 0x1a00 | 0x43000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.33 |
Imports (4)
»
KERNEL32.dll (98)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitThread | 0x0 | 0x41e024 | 0x21ae8 | 0x200e8 | 0x105 |
GetStartupInfoW | 0x0 | 0x41e028 | 0x21aec | 0x200ec | 0x23a |
GetLastError | 0x0 | 0x41e02c | 0x21af0 | 0x200f0 | 0x1e6 |
GetProcAddress | 0x0 | 0x41e030 | 0x21af4 | 0x200f4 | 0x220 |
GlobalFree | 0x0 | 0x41e034 | 0x21af8 | 0x200f8 | 0x28c |
LoadLibraryA | 0x0 | 0x41e038 | 0x21afc | 0x200fc | 0x2f1 |
AddAtomA | 0x0 | 0x41e03c | 0x21b00 | 0x20100 | 0x3 |
FindFirstChangeNotificationA | 0x0 | 0x41e040 | 0x21b04 | 0x20104 | 0x11b |
VirtualProtect | 0x0 | 0x41e044 | 0x21b08 | 0x20108 | 0x45a |
GetCurrentDirectoryA | 0x0 | 0x41e048 | 0x21b0c | 0x2010c | 0x1a7 |
SetProcessShutdownParameters | 0x0 | 0x41e04c | 0x21b10 | 0x20110 | 0x3f9 |
GetACP | 0x0 | 0x41e050 | 0x21b14 | 0x20114 | 0x152 |
CompareStringA | 0x0 | 0x41e054 | 0x21b18 | 0x20118 | 0x52 |
CreateFileA | 0x0 | 0x41e058 | 0x21b1c | 0x2011c | 0x78 |
GetTimeZoneInformation | 0x0 | 0x41e05c | 0x21b20 | 0x20120 | 0x26b |
WriteConsoleW | 0x0 | 0x41e060 | 0x21b24 | 0x20124 | 0x48c |
GetConsoleOutputCP | 0x0 | 0x41e064 | 0x21b28 | 0x20128 | 0x199 |
WriteConsoleA | 0x0 | 0x41e068 | 0x21b2c | 0x2012c | 0x482 |
CloseHandle | 0x0 | 0x41e06c | 0x21b30 | 0x20130 | 0x43 |
IsValidLocale | 0x0 | 0x41e070 | 0x21b34 | 0x20134 | 0x2dd |
EnumSystemLocalesA | 0x0 | 0x41e074 | 0x21b38 | 0x20138 | 0xf8 |
GetUserDefaultLCID | 0x0 | 0x41e078 | 0x21b3c | 0x2013c | 0x26d |
GetDateFormatA | 0x0 | 0x41e07c | 0x21b40 | 0x20140 | 0x1ae |
GetTimeFormatA | 0x0 | 0x41e080 | 0x21b44 | 0x20144 | 0x268 |
InitAtomTable | 0x0 | 0x41e084 | 0x21b48 | 0x20148 | 0x2ae |
GetSystemTimes | 0x0 | 0x41e088 | 0x21b4c | 0x2014c | 0x250 |
GetTickCount | 0x0 | 0x41e08c | 0x21b50 | 0x20150 | 0x266 |
FreeEnvironmentStringsA | 0x0 | 0x41e090 | 0x21b54 | 0x20154 | 0x14a |
GetComputerNameW | 0x0 | 0x41e094 | 0x21b58 | 0x20158 | 0x178 |
FindCloseChangeNotification | 0x0 | 0x41e098 | 0x21b5c | 0x2015c | 0x11a |
FindResourceExW | 0x0 | 0x41e09c | 0x21b60 | 0x20160 | 0x138 |
CompareStringW | 0x0 | 0x41e0a0 | 0x21b64 | 0x20164 | 0x55 |
GetCPInfo | 0x0 | 0x41e0a4 | 0x21b68 | 0x20168 | 0x15b |
GetStringTypeW | 0x0 | 0x41e0a8 | 0x21b6c | 0x2016c | 0x240 |
GetStringTypeA | 0x0 | 0x41e0ac | 0x21b70 | 0x20170 | 0x23d |
LCMapStringW | 0x0 | 0x41e0b0 | 0x21b74 | 0x20174 | 0x2e3 |
LCMapStringA | 0x0 | 0x41e0b4 | 0x21b78 | 0x20178 | 0x2e1 |
GetLocaleInfoA | 0x0 | 0x41e0b8 | 0x21b7c | 0x2017c | 0x1e8 |
GetCommandLineA | 0x0 | 0x41e0bc | 0x21b80 | 0x20180 | 0x16f |
GetStartupInfoA | 0x0 | 0x41e0c0 | 0x21b84 | 0x20184 | 0x239 |
RaiseException | 0x0 | 0x41e0c4 | 0x21b88 | 0x20188 | 0x35a |
RtlUnwind | 0x0 | 0x41e0c8 | 0x21b8c | 0x2018c | 0x392 |
TerminateProcess | 0x0 | 0x41e0cc | 0x21b90 | 0x20190 | 0x42d |
GetCurrentProcess | 0x0 | 0x41e0d0 | 0x21b94 | 0x20194 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x41e0d4 | 0x21b98 | 0x20198 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x41e0d8 | 0x21b9c | 0x2019c | 0x415 |
IsDebuggerPresent | 0x0 | 0x41e0dc | 0x21ba0 | 0x201a0 | 0x2d1 |
HeapAlloc | 0x0 | 0x41e0e0 | 0x21ba4 | 0x201a4 | 0x29d |
HeapFree | 0x0 | 0x41e0e4 | 0x21ba8 | 0x201a8 | 0x2a1 |
EnterCriticalSection | 0x0 | 0x41e0e8 | 0x21bac | 0x201ac | 0xd9 |
LeaveCriticalSection | 0x0 | 0x41e0ec | 0x21bb0 | 0x201b0 | 0x2ef |
SetHandleCount | 0x0 | 0x41e0f0 | 0x21bb4 | 0x201b4 | 0x3e8 |
GetStdHandle | 0x0 | 0x41e0f4 | 0x21bb8 | 0x201b8 | 0x23b |
GetFileType | 0x0 | 0x41e0f8 | 0x21bbc | 0x201bc | 0x1d7 |
DeleteCriticalSection | 0x0 | 0x41e0fc | 0x21bc0 | 0x201c0 | 0xbe |
GetModuleHandleW | 0x0 | 0x41e100 | 0x21bc4 | 0x201c4 | 0x1f9 |
Sleep | 0x0 | 0x41e104 | 0x21bc8 | 0x201c8 | 0x421 |
ExitProcess | 0x0 | 0x41e108 | 0x21bcc | 0x201cc | 0x104 |
WriteFile | 0x0 | 0x41e10c | 0x21bd0 | 0x201d0 | 0x48d |
GetModuleFileNameA | 0x0 | 0x41e110 | 0x21bd4 | 0x201d4 | 0x1f4 |
GetEnvironmentStrings | 0x0 | 0x41e114 | 0x21bd8 | 0x201d8 | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x41e118 | 0x21bdc | 0x201dc | 0x14b |
WideCharToMultiByte | 0x0 | 0x41e11c | 0x21be0 | 0x201e0 | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x41e120 | 0x21be4 | 0x201e4 | 0x1c1 |
TlsGetValue | 0x0 | 0x41e124 | 0x21be8 | 0x201e8 | 0x434 |
TlsAlloc | 0x0 | 0x41e128 | 0x21bec | 0x201ec | 0x432 |
TlsSetValue | 0x0 | 0x41e12c | 0x21bf0 | 0x201f0 | 0x435 |
TlsFree | 0x0 | 0x41e130 | 0x21bf4 | 0x201f4 | 0x433 |
InterlockedIncrement | 0x0 | 0x41e134 | 0x21bf8 | 0x201f8 | 0x2c0 |
SetLastError | 0x0 | 0x41e138 | 0x21bfc | 0x201fc | 0x3ec |
GetCurrentThreadId | 0x0 | 0x41e13c | 0x21c00 | 0x20200 | 0x1ad |
InterlockedDecrement | 0x0 | 0x41e140 | 0x21c04 | 0x20204 | 0x2bc |
GetCurrentThread | 0x0 | 0x41e144 | 0x21c08 | 0x20208 | 0x1ac |
HeapCreate | 0x0 | 0x41e148 | 0x21c0c | 0x2020c | 0x29f |
HeapDestroy | 0x0 | 0x41e14c | 0x21c10 | 0x20210 | 0x2a0 |
VirtualFree | 0x0 | 0x41e150 | 0x21c14 | 0x20214 | 0x457 |
QueryPerformanceCounter | 0x0 | 0x41e154 | 0x21c18 | 0x20218 | 0x354 |
GetCurrentProcessId | 0x0 | 0x41e158 | 0x21c1c | 0x2021c | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x41e15c | 0x21c20 | 0x20220 | 0x24f |
FatalAppExitA | 0x0 | 0x41e160 | 0x21c24 | 0x20224 | 0x10b |
VirtualAlloc | 0x0 | 0x41e164 | 0x21c28 | 0x20228 | 0x454 |
HeapReAlloc | 0x0 | 0x41e168 | 0x21c2c | 0x2022c | 0x2a4 |
MultiByteToWideChar | 0x0 | 0x41e16c | 0x21c30 | 0x20230 | 0x31a |
ReadFile | 0x0 | 0x41e170 | 0x21c34 | 0x20234 | 0x368 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41e174 | 0x21c38 | 0x20238 | 0x2b5 |
HeapSize | 0x0 | 0x41e178 | 0x21c3c | 0x2023c | 0x2a6 |
SetConsoleCtrlHandler | 0x0 | 0x41e17c | 0x21c40 | 0x20240 | 0x3a7 |
FreeLibrary | 0x0 | 0x41e180 | 0x21c44 | 0x20244 | 0x14c |
InterlockedExchange | 0x0 | 0x41e184 | 0x21c48 | 0x20248 | 0x2bd |
GetOEMCP | 0x0 | 0x41e188 | 0x21c4c | 0x2024c | 0x213 |
IsValidCodePage | 0x0 | 0x41e18c | 0x21c50 | 0x20250 | 0x2db |
GetConsoleCP | 0x0 | 0x41e190 | 0x21c54 | 0x20254 | 0x183 |
GetConsoleMode | 0x0 | 0x41e194 | 0x21c58 | 0x20258 | 0x195 |
FlushFileBuffers | 0x0 | 0x41e198 | 0x21c5c | 0x2025c | 0x141 |
SetFilePointer | 0x0 | 0x41e19c | 0x21c60 | 0x20260 | 0x3df |
SetStdHandle | 0x0 | 0x41e1a0 | 0x21c64 | 0x20264 | 0x3fc |
GetLocaleInfoW | 0x0 | 0x41e1a4 | 0x21c68 | 0x20268 | 0x1ea |
SetEnvironmentVariableA | 0x0 | 0x41e1a8 | 0x21c6c | 0x2026c | 0x3d0 |
USER32.dll (12)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseClipboard | 0x0 | 0x41e1c4 | 0x21c88 | 0x20288 | 0x47 |
GetSubMenu | 0x0 | 0x41e1c8 | 0x21c8c | 0x2028c | 0x16b |
LoadBitmapA | 0x0 | 0x41e1cc | 0x21c90 | 0x20290 | 0x1d0 |
BeginPaint | 0x0 | 0x41e1d0 | 0x21c94 | 0x20294 | 0xe |
CallMsgFilterW | 0x0 | 0x41e1d4 | 0x21c98 | 0x20298 | 0x1a |
PeekMessageA | 0x0 | 0x41e1d8 | 0x21c9c | 0x2029c | 0x21b |
MapVirtualKeyExW | 0x0 | 0x41e1dc | 0x21ca0 | 0x202a0 | 0x1f1 |
RegisterRawInputDevices | 0x0 | 0x41e1e0 | 0x21ca4 | 0x202a4 | 0x242 |
SetWindowsHookExW | 0x0 | 0x41e1e4 | 0x21ca8 | 0x202a8 | 0x2b0 |
GetClipboardSequenceNumber | 0x0 | 0x41e1e8 | 0x21cac | 0x202ac | 0x113 |
GetDialogBaseUnits | 0x0 | 0x41e1ec | 0x21cb0 | 0x202b0 | 0x11d |
MessageBoxIndirectA | 0x0 | 0x41e1f0 | 0x21cb4 | 0x202b4 | 0x1fb |
GDI32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateCompatibleDC | 0x0 | 0x41e000 | 0x21ac4 | 0x200c4 | 0x2e |
PlayEnhMetaFile | 0x0 | 0x41e004 | 0x21ac8 | 0x200c8 | 0x230 |
ScaleViewportExtEx | 0x0 | 0x41e008 | 0x21acc | 0x200cc | 0x258 |
SetStretchBltMode | 0x0 | 0x41e00c | 0x21ad0 | 0x200d0 | 0x289 |
SetPixelV | 0x0 | 0x41e010 | 0x21ad4 | 0x200d4 | 0x284 |
CreateDiscardableBitmap | 0x0 | 0x41e014 | 0x21ad8 | 0x200d8 | 0x35 |
AddFontResourceW | 0x0 | 0x41e018 | 0x21adc | 0x200dc | 0x7 |
SetDeviceGammaRamp | 0x0 | 0x41e01c | 0x21ae0 | 0x200e0 | 0x271 |
SHELL32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExtractAssociatedIconA | 0x0 | 0x41e1b0 | 0x21c74 | 0x20274 | 0x24 |
ShellExecuteW | 0x0 | 0x41e1b4 | 0x21c78 | 0x20278 | 0x118 |
ShellAboutW | 0x0 | 0x41e1b8 | 0x21c7c | 0x2027c | 0x110 |
DragQueryFileA | 0x0 | 0x41e1bc | 0x21c80 | 0x20280 | 0x1e |
Memory Dumps (6)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
updatewin2.exe | 7 | 0x00400000 | 0x0044CFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
updatewin2.exe | 7 | 0x00400000 | 0x0044CFFF | Content Changed | - | 32-bit | 0x00402350 |
![]() |
![]() |
...
|
updatewin2.exe | 7 | 0x00400000 | 0x0044CFFF | Content Changed | - | 32-bit | 0x0040D7C3 |
![]() |
![]() |
...
|
updatewin2.exe | 7 | 0x00400000 | 0x0044CFFF | Content Changed | - | 32-bit | 0x0040C0D3 |
![]() |
![]() |
...
|
updatewin2.exe | 7 | 0x00400000 | 0x0044CFFF | Content Changed | - | 32-bit | 0x00401730 |
![]() |
![]() |
...
|
updatewin2.exe | 7 | 0x00400000 | 0x0044CFFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.AgentWDCR.SVC |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\16ec01a8-9cb0-4fd9-9d7a-ff79ab43a52d\updatewin.exe | Downloaded File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-01-16 22:21 (UTC+1) |
Last Seen | 2019-09-04 09:39 (UTC+2) |
Names | Win32.Trojan.Kryptik |
Families | Kryptik |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x402d7c |
Size Of Code | 0x1c200 |
Size Of Initialized Data | 0x2d400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-02-19 08:26:47+00:00 |
Version Information (3)
»
FileVersion | 8.8.10.11 |
InternalName | sutazaxidi.exe |
LegalCopyright | Copyright (C) 2018, huxonulow |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1c09e | 0x1c200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x41e000 | 0x4636 | 0x4800 | 0x1c600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.25 |
.data | 0x423000 | 0x1d5a8 | 0x18400 | 0x20e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.8 |
.rsrc | 0x441000 | 0xa826 | 0xaa00 | 0x39200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.84 |
.reloc | 0x44c000 | 0x1974 | 0x1a00 | 0x43c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.34 |
Imports (4)
»
KERNEL32.dll (100)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitThread | 0x0 | 0x41e020 | 0x21af4 | 0x200f4 | 0x105 |
GetStartupInfoW | 0x0 | 0x41e024 | 0x21af8 | 0x200f8 | 0x23a |
GetConsoleAliasesW | 0x0 | 0x41e028 | 0x21afc | 0x200fc | 0x182 |
GetLastError | 0x0 | 0x41e02c | 0x21b00 | 0x20100 | 0x1e6 |
GetProcAddress | 0x0 | 0x41e030 | 0x21b04 | 0x20104 | 0x220 |
BackupWrite | 0x0 | 0x41e034 | 0x21b08 | 0x20108 | 0x18 |
GlobalFree | 0x0 | 0x41e038 | 0x21b0c | 0x2010c | 0x28c |
LoadLibraryA | 0x0 | 0x41e03c | 0x21b10 | 0x20110 | 0x2f1 |
GetNumberFormatW | 0x0 | 0x41e040 | 0x21b14 | 0x20114 | 0x20f |
AddAtomA | 0x0 | 0x41e044 | 0x21b18 | 0x20118 | 0x3 |
FindFirstChangeNotificationA | 0x0 | 0x41e048 | 0x21b1c | 0x2011c | 0x11b |
GetStringTypeW | 0x0 | 0x41e04c | 0x21b20 | 0x20120 | 0x240 |
VirtualProtect | 0x0 | 0x41e050 | 0x21b24 | 0x20124 | 0x45a |
GetACP | 0x0 | 0x41e054 | 0x21b28 | 0x20128 | 0x152 |
SetProcessShutdownParameters | 0x0 | 0x41e058 | 0x21b2c | 0x2012c | 0x3f9 |
CompareStringW | 0x0 | 0x41e05c | 0x21b30 | 0x20130 | 0x55 |
CompareStringA | 0x0 | 0x41e060 | 0x21b34 | 0x20134 | 0x52 |
CreateFileA | 0x0 | 0x41e064 | 0x21b38 | 0x20138 | 0x78 |
GetTimeZoneInformation | 0x0 | 0x41e068 | 0x21b3c | 0x2013c | 0x26b |
WriteConsoleW | 0x0 | 0x41e06c | 0x21b40 | 0x20140 | 0x48c |
GetConsoleOutputCP | 0x0 | 0x41e070 | 0x21b44 | 0x20144 | 0x199 |
WriteConsoleA | 0x0 | 0x41e074 | 0x21b48 | 0x20148 | 0x482 |
CloseHandle | 0x0 | 0x41e078 | 0x21b4c | 0x2014c | 0x43 |
IsValidLocale | 0x0 | 0x41e07c | 0x21b50 | 0x20150 | 0x2dd |
EnumSystemLocalesA | 0x0 | 0x41e080 | 0x21b54 | 0x20154 | 0xf8 |
GetUserDefaultLCID | 0x0 | 0x41e084 | 0x21b58 | 0x20158 | 0x26d |
GetDateFormatA | 0x0 | 0x41e088 | 0x21b5c | 0x2015c | 0x1ae |
GetSystemTimes | 0x0 | 0x41e08c | 0x21b60 | 0x20160 | 0x250 |
GetTickCount | 0x0 | 0x41e090 | 0x21b64 | 0x20164 | 0x266 |
FreeEnvironmentStringsA | 0x0 | 0x41e094 | 0x21b68 | 0x20168 | 0x14a |
GetComputerNameW | 0x0 | 0x41e098 | 0x21b6c | 0x2016c | 0x178 |
FindCloseChangeNotification | 0x0 | 0x41e09c | 0x21b70 | 0x20170 | 0x11a |
FindResourceExW | 0x0 | 0x41e0a0 | 0x21b74 | 0x20174 | 0x138 |
GetCurrentDirectoryA | 0x0 | 0x41e0a4 | 0x21b78 | 0x20178 | 0x1a7 |
GetCPInfo | 0x0 | 0x41e0a8 | 0x21b7c | 0x2017c | 0x15b |
GetTimeFormatA | 0x0 | 0x41e0ac | 0x21b80 | 0x20180 | 0x268 |
GetStringTypeA | 0x0 | 0x41e0b0 | 0x21b84 | 0x20184 | 0x23d |
LCMapStringW | 0x0 | 0x41e0b4 | 0x21b88 | 0x20188 | 0x2e3 |
LCMapStringA | 0x0 | 0x41e0b8 | 0x21b8c | 0x2018c | 0x2e1 |
GetLocaleInfoA | 0x0 | 0x41e0bc | 0x21b90 | 0x20190 | 0x1e8 |
GetLocaleInfoW | 0x0 | 0x41e0c0 | 0x21b94 | 0x20194 | 0x1ea |
SetStdHandle | 0x0 | 0x41e0c4 | 0x21b98 | 0x20198 | 0x3fc |
SetFilePointer | 0x0 | 0x41e0c8 | 0x21b9c | 0x2019c | 0x3df |
GetCommandLineA | 0x0 | 0x41e0cc | 0x21ba0 | 0x201a0 | 0x16f |
GetStartupInfoA | 0x0 | 0x41e0d0 | 0x21ba4 | 0x201a4 | 0x239 |
RaiseException | 0x0 | 0x41e0d4 | 0x21ba8 | 0x201a8 | 0x35a |
RtlUnwind | 0x0 | 0x41e0d8 | 0x21bac | 0x201ac | 0x392 |
TerminateProcess | 0x0 | 0x41e0dc | 0x21bb0 | 0x201b0 | 0x42d |
GetCurrentProcess | 0x0 | 0x41e0e0 | 0x21bb4 | 0x201b4 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x41e0e4 | 0x21bb8 | 0x201b8 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x41e0e8 | 0x21bbc | 0x201bc | 0x415 |
IsDebuggerPresent | 0x0 | 0x41e0ec | 0x21bc0 | 0x201c0 | 0x2d1 |
HeapAlloc | 0x0 | 0x41e0f0 | 0x21bc4 | 0x201c4 | 0x29d |
HeapFree | 0x0 | 0x41e0f4 | 0x21bc8 | 0x201c8 | 0x2a1 |
EnterCriticalSection | 0x0 | 0x41e0f8 | 0x21bcc | 0x201cc | 0xd9 |
LeaveCriticalSection | 0x0 | 0x41e0fc | 0x21bd0 | 0x201d0 | 0x2ef |
SetHandleCount | 0x0 | 0x41e100 | 0x21bd4 | 0x201d4 | 0x3e8 |
GetStdHandle | 0x0 | 0x41e104 | 0x21bd8 | 0x201d8 | 0x23b |
GetFileType | 0x0 | 0x41e108 | 0x21bdc | 0x201dc | 0x1d7 |
DeleteCriticalSection | 0x0 | 0x41e10c | 0x21be0 | 0x201e0 | 0xbe |
GetModuleHandleW | 0x0 | 0x41e110 | 0x21be4 | 0x201e4 | 0x1f9 |
Sleep | 0x0 | 0x41e114 | 0x21be8 | 0x201e8 | 0x421 |
ExitProcess | 0x0 | 0x41e118 | 0x21bec | 0x201ec | 0x104 |
WriteFile | 0x0 | 0x41e11c | 0x21bf0 | 0x201f0 | 0x48d |
GetModuleFileNameA | 0x0 | 0x41e120 | 0x21bf4 | 0x201f4 | 0x1f4 |
GetEnvironmentStrings | 0x0 | 0x41e124 | 0x21bf8 | 0x201f8 | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x41e128 | 0x21bfc | 0x201fc | 0x14b |
WideCharToMultiByte | 0x0 | 0x41e12c | 0x21c00 | 0x20200 | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x41e130 | 0x21c04 | 0x20204 | 0x1c1 |
TlsGetValue | 0x0 | 0x41e134 | 0x21c08 | 0x20208 | 0x434 |
TlsAlloc | 0x0 | 0x41e138 | 0x21c0c | 0x2020c | 0x432 |
TlsSetValue | 0x0 | 0x41e13c | 0x21c10 | 0x20210 | 0x435 |
TlsFree | 0x0 | 0x41e140 | 0x21c14 | 0x20214 | 0x433 |
InterlockedIncrement | 0x0 | 0x41e144 | 0x21c18 | 0x20218 | 0x2c0 |
SetLastError | 0x0 | 0x41e148 | 0x21c1c | 0x2021c | 0x3ec |
GetCurrentThreadId | 0x0 | 0x41e14c | 0x21c20 | 0x20220 | 0x1ad |
InterlockedDecrement | 0x0 | 0x41e150 | 0x21c24 | 0x20224 | 0x2bc |
GetCurrentThread | 0x0 | 0x41e154 | 0x21c28 | 0x20228 | 0x1ac |
HeapCreate | 0x0 | 0x41e158 | 0x21c2c | 0x2022c | 0x29f |
HeapDestroy | 0x0 | 0x41e15c | 0x21c30 | 0x20230 | 0x2a0 |
VirtualFree | 0x0 | 0x41e160 | 0x21c34 | 0x20234 | 0x457 |
QueryPerformanceCounter | 0x0 | 0x41e164 | 0x21c38 | 0x20238 | 0x354 |
GetCurrentProcessId | 0x0 | 0x41e168 | 0x21c3c | 0x2023c | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x41e16c | 0x21c40 | 0x20240 | 0x24f |
FatalAppExitA | 0x0 | 0x41e170 | 0x21c44 | 0x20244 | 0x10b |
VirtualAlloc | 0x0 | 0x41e174 | 0x21c48 | 0x20248 | 0x454 |
HeapReAlloc | 0x0 | 0x41e178 | 0x21c4c | 0x2024c | 0x2a4 |
MultiByteToWideChar | 0x0 | 0x41e17c | 0x21c50 | 0x20250 | 0x31a |
ReadFile | 0x0 | 0x41e180 | 0x21c54 | 0x20254 | 0x368 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41e184 | 0x21c58 | 0x20258 | 0x2b5 |
HeapSize | 0x0 | 0x41e188 | 0x21c5c | 0x2025c | 0x2a6 |
SetConsoleCtrlHandler | 0x0 | 0x41e18c | 0x21c60 | 0x20260 | 0x3a7 |
FreeLibrary | 0x0 | 0x41e190 | 0x21c64 | 0x20264 | 0x14c |
InterlockedExchange | 0x0 | 0x41e194 | 0x21c68 | 0x20268 | 0x2bd |
GetOEMCP | 0x0 | 0x41e198 | 0x21c6c | 0x2026c | 0x213 |
IsValidCodePage | 0x0 | 0x41e19c | 0x21c70 | 0x20270 | 0x2db |
GetConsoleCP | 0x0 | 0x41e1a0 | 0x21c74 | 0x20274 | 0x183 |
GetConsoleMode | 0x0 | 0x41e1a4 | 0x21c78 | 0x20278 | 0x195 |
FlushFileBuffers | 0x0 | 0x41e1a8 | 0x21c7c | 0x2027c | 0x141 |
SetEnvironmentVariableA | 0x0 | 0x41e1ac | 0x21c80 | 0x20280 | 0x3d0 |
USER32.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseClipboard | 0x0 | 0x41e1d4 | 0x21ca8 | 0x202a8 | 0x47 |
SendNotifyMessageA | 0x0 | 0x41e1d8 | 0x21cac | 0x202ac | 0x264 |
BeginPaint | 0x0 | 0x41e1dc | 0x21cb0 | 0x202b0 | 0xe |
CallMsgFilterW | 0x0 | 0x41e1e0 | 0x21cb4 | 0x202b4 | 0x1a |
PeekMessageA | 0x0 | 0x41e1e4 | 0x21cb8 | 0x202b8 | 0x21b |
MapVirtualKeyExW | 0x0 | 0x41e1e8 | 0x21cbc | 0x202bc | 0x1f1 |
RegisterRawInputDevices | 0x0 | 0x41e1ec | 0x21cc0 | 0x202c0 | 0x242 |
GetClipboardSequenceNumber | 0x0 | 0x41e1f0 | 0x21cc4 | 0x202c4 | 0x113 |
SetUserObjectInformationA | 0x0 | 0x41e1f4 | 0x21cc8 | 0x202c8 | 0x29f |
GetDialogBaseUnits | 0x0 | 0x41e1f8 | 0x21ccc | 0x202cc | 0x11d |
GetMessageW | 0x0 | 0x41e1fc | 0x21cd0 | 0x202d0 | 0x14e |
GDI32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreatePolyPolygonRgn | 0x0 | 0x41e000 | 0x21ad4 | 0x200d4 | 0x4b |
CreateCompatibleDC | 0x0 | 0x41e004 | 0x21ad8 | 0x200d8 | 0x2e |
SetStretchBltMode | 0x0 | 0x41e008 | 0x21adc | 0x200dc | 0x289 |
SetPixelV | 0x0 | 0x41e00c | 0x21ae0 | 0x200e0 | 0x284 |
GetCharWidth32A | 0x0 | 0x41e010 | 0x21ae4 | 0x200e4 | 0x1a0 |
CreateDiscardableBitmap | 0x0 | 0x41e014 | 0x21ae8 | 0x200e8 | 0x35 |
BitBlt | 0x0 | 0x41e018 | 0x21aec | 0x200ec | 0x12 |
SHELL32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x41e1b4 | 0x21c88 | 0x20288 | 0x118 |
ShellAboutW | 0x0 | 0x41e1b8 | 0x21c8c | 0x2028c | 0x110 |
ExtractIconA | 0x0 | 0x41e1bc | 0x21c90 | 0x20290 | 0x28 |
ShellExecuteExA | 0x0 | 0x41e1c0 | 0x21c94 | 0x20294 | 0x116 |
FindExecutableA | 0x0 | 0x41e1c4 | 0x21c98 | 0x20298 | 0x2d |
DragQueryFileA | 0x0 | 0x41e1c8 | 0x21c9c | 0x2029c | 0x1e |
ExtractIconW | 0x0 | 0x41e1cc | 0x21ca0 | 0x202a0 | 0x2c |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.AgentWDCR.SUF |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\16ec01a8-9cb0-4fd9-9d7a-ff79ab43a52d\4.exe | Downloaded File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-08-26 17:48 (UTC+2) |
Last Seen | 2019-09-10 02:49 (UTC+2) |
Names | Win32.Trojan.Grp |
Families | Grp |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x403af7 |
Size Of Code | 0x11e00 |
Size Of Initialized Data | 0x4a20400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-08-31 00:14:32+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x11d0a | 0x11e00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.66 |
.rdata | 0x413000 | 0x22070 | 0x22200 | 0x12200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.3 |
.data | 0x436000 | 0x49fba20 | 0x1a00 | 0x34400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.08 |
.rsrc | 0x4e32000 | 0x1d48 | 0x1e00 | 0x35e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.09 |
.reloc | 0x4e34000 | 0x14d4 | 0x1600 | 0x37c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.45 |
Imports (3)
»
KERNEL32.dll (131)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SleepEx | 0x0 | 0x41303c | 0x342c0 | 0x334c0 | 0x4b5 |
GetModuleHandleW | 0x0 | 0x413040 | 0x342c4 | 0x334c4 | 0x218 |
IsBadReadPtr | 0x0 | 0x413044 | 0x342c8 | 0x334c8 | 0x2f7 |
FormatMessageA | 0x0 | 0x413048 | 0x342cc | 0x334cc | 0x15d |
GetConsoleAliasExesW | 0x0 | 0x41304c | 0x342d0 | 0x334d0 | 0x194 |
EnumTimeFormatsW | 0x0 | 0x413050 | 0x342d4 | 0x334d4 | 0x112 |
GetUserDefaultLangID | 0x0 | 0x413054 | 0x342d8 | 0x334d8 | 0x29c |
GlobalAlloc | 0x0 | 0x413058 | 0x342dc | 0x334dc | 0x2b3 |
GetFirmwareEnvironmentVariableA | 0x0 | 0x41305c | 0x342e0 | 0x334e0 | 0x1f6 |
IsValidLocale | 0x0 | 0x413060 | 0x342e4 | 0x334e4 | 0x30c |
GetThreadSelectorEntry | 0x0 | 0x413064 | 0x342e8 | 0x334e8 | 0x290 |
GetCalendarInfoA | 0x0 | 0x413068 | 0x342ec | 0x334ec | 0x179 |
FormatMessageW | 0x0 | 0x41306c | 0x342f0 | 0x334f0 | 0x15e |
SetConsoleCP | 0x0 | 0x413070 | 0x342f4 | 0x334f4 | 0x42c |
WritePrivateProfileStructW | 0x0 | 0x413074 | 0x342f8 | 0x334f8 | 0x52d |
FindNextVolumeW | 0x0 | 0x413078 | 0x342fc | 0x334fc | 0x14a |
GetConsoleAliasW | 0x0 | 0x41307c | 0x34300 | 0x33500 | 0x195 |
GetTapePosition | 0x0 | 0x413080 | 0x34304 | 0x33504 | 0x280 |
GetFileAttributesW | 0x0 | 0x413084 | 0x34308 | 0x33508 | 0x1ea |
GetAtomNameW | 0x0 | 0x413088 | 0x3430c | 0x3350c | 0x16e |
GetCompressedFileSizeA | 0x0 | 0x41308c | 0x34310 | 0x33510 | 0x188 |
GetTimeZoneInformation | 0x0 | 0x413090 | 0x34314 | 0x33514 | 0x298 |
lstrlenW | 0x0 | 0x413094 | 0x34318 | 0x33518 | 0x54e |
GetFileSizeEx | 0x0 | 0x413098 | 0x3431c | 0x3351c | 0x1f1 |
SetThreadLocale | 0x0 | 0x41309c | 0x34320 | 0x33520 | 0x497 |
FindFirstFileA | 0x0 | 0x4130a0 | 0x34324 | 0x33524 | 0x132 |
OpenMutexW | 0x0 | 0x4130a4 | 0x34328 | 0x33528 | 0x37d |
InterlockedFlushSList | 0x0 | 0x4130a8 | 0x3432c | 0x3352c | 0x2ee |
GetCurrentDirectoryW | 0x0 | 0x4130ac | 0x34330 | 0x33530 | 0x1bf |
GetLongPathNameW | 0x0 | 0x4130b0 | 0x34334 | 0x33534 | 0x20f |
BindIoCompletionCallback | 0x0 | 0x4130b4 | 0x34338 | 0x33538 | 0x39 |
HeapSize | 0x0 | 0x4130b8 | 0x3433c | 0x3353c | 0x2d4 |
OpenSemaphoreA | 0x0 | 0x4130bc | 0x34340 | 0x33540 | 0x383 |
HeapUnlock | 0x0 | 0x4130c0 | 0x34344 | 0x33544 | 0x2d6 |
LockFileEx | 0x0 | 0x4130c4 | 0x34348 | 0x33548 | 0x353 |
SetComputerNameA | 0x0 | 0x4130c8 | 0x3434c | 0x3354c | 0x427 |
EnterCriticalSection | 0x0 | 0x4130cc | 0x34350 | 0x33550 | 0xee |
SetTimerQueueTimer | 0x0 | 0x4130d0 | 0x34354 | 0x33554 | 0x4a4 |
GetPrivateProfileStringA | 0x0 | 0x4130d4 | 0x34358 | 0x33558 | 0x241 |
LoadLibraryA | 0x0 | 0x4130d8 | 0x3435c | 0x3355c | 0x33c |
CreateSemaphoreW | 0x0 | 0x4130dc | 0x34360 | 0x33560 | 0xae |
LocalAlloc | 0x0 | 0x4130e0 | 0x34364 | 0x33564 | 0x344 |
GetExitCodeThread | 0x0 | 0x4130e4 | 0x34368 | 0x33568 | 0x1e0 |
TransmitCommChar | 0x0 | 0x4130e8 | 0x3436c | 0x3356c | 0x4cb |
AddAtomW | 0x0 | 0x4130ec | 0x34370 | 0x33570 | 0x4 |
OpenEventA | 0x0 | 0x4130f0 | 0x34374 | 0x33574 | 0x374 |
GetCommMask | 0x0 | 0x4130f4 | 0x34378 | 0x33578 | 0x181 |
OpenJobObjectW | 0x0 | 0x4130f8 | 0x3437c | 0x3357c | 0x37b |
GetProcessShutdownParameters | 0x0 | 0x4130fc | 0x34380 | 0x33580 | 0x251 |
CancelTimerQueueTimer | 0x0 | 0x413100 | 0x34384 | 0x33584 | 0x46 |
FreeEnvironmentStringsW | 0x0 | 0x413104 | 0x34388 | 0x33588 | 0x161 |
VirtualProtect | 0x0 | 0x413108 | 0x3438c | 0x3358c | 0x4ef |
GetFileTime | 0x0 | 0x41310c | 0x34390 | 0x33590 | 0x1f2 |
GetShortPathNameW | 0x0 | 0x413110 | 0x34394 | 0x33594 | 0x261 |
OutputDebugStringA | 0x0 | 0x413114 | 0x34398 | 0x33598 | 0x389 |
DuplicateHandle | 0x0 | 0x413118 | 0x3439c | 0x3359c | 0xe8 |
CloseHandle | 0x0 | 0x41311c | 0x343a0 | 0x335a0 | 0x52 |
MoveFileWithProgressW | 0x0 | 0x413120 | 0x343a4 | 0x335a4 | 0x365 |
lstrcpyA | 0x0 | 0x413124 | 0x343a8 | 0x335a8 | 0x547 |
ReadConsoleW | 0x0 | 0x413128 | 0x343ac | 0x335ac | 0x3be |
ReadFile | 0x0 | 0x41312c | 0x343b0 | 0x335b0 | 0x3c0 |
FlushFileBuffers | 0x0 | 0x413130 | 0x343b4 | 0x335b4 | 0x157 |
WriteConsoleW | 0x0 | 0x413134 | 0x343b8 | 0x335b8 | 0x524 |
SetStdHandle | 0x0 | 0x413138 | 0x343bc | 0x335bc | 0x487 |
QueryDosDeviceA | 0x0 | 0x41313c | 0x343c0 | 0x335c0 | 0x39f |
UpdateResourceA | 0x0 | 0x413140 | 0x343c4 | 0x335c4 | 0x4de |
GetFullPathNameW | 0x0 | 0x413144 | 0x343c8 | 0x335c8 | 0x1fb |
SetEndOfFile | 0x0 | 0x413148 | 0x343cc | 0x335cc | 0x453 |
IsBadHugeReadPtr | 0x0 | 0x41314c | 0x343d0 | 0x335d0 | 0x2f5 |
GetDriveTypeW | 0x0 | 0x413150 | 0x343d4 | 0x335d4 | 0x1d3 |
TlsGetValue | 0x0 | 0x413154 | 0x343d8 | 0x335d8 | 0x4c7 |
lstrlenA | 0x0 | 0x413158 | 0x343dc | 0x335dc | 0x54d |
WriteConsoleOutputCharacterW | 0x0 | 0x41315c | 0x343e0 | 0x335e0 | 0x522 |
GetCommModemStatus | 0x0 | 0x413160 | 0x343e4 | 0x335e4 | 0x182 |
SetProcessAffinityMask | 0x0 | 0x413164 | 0x343e8 | 0x335e8 | 0x47e |
GetFullPathNameA | 0x0 | 0x413168 | 0x343ec | 0x335ec | 0x1f8 |
GetCommandLineW | 0x0 | 0x41316c | 0x343f0 | 0x335f0 | 0x187 |
GetVolumeNameForVolumeMountPointA | 0x0 | 0x413170 | 0x343f4 | 0x335f4 | 0x2a8 |
DefineDosDeviceW | 0x0 | 0x413174 | 0x343f8 | 0x335f8 | 0xcd |
IsProcessorFeaturePresent | 0x0 | 0x413178 | 0x343fc | 0x335fc | 0x304 |
EncodePointer | 0x0 | 0x41317c | 0x34400 | 0x33600 | 0xea |
DecodePointer | 0x0 | 0x413180 | 0x34404 | 0x33604 | 0xca |
GetCommandLineA | 0x0 | 0x413184 | 0x34408 | 0x33608 | 0x186 |
RaiseException | 0x0 | 0x413188 | 0x3440c | 0x3360c | 0x3b1 |
RtlUnwind | 0x0 | 0x41318c | 0x34410 | 0x33610 | 0x418 |
IsDebuggerPresent | 0x0 | 0x413190 | 0x34414 | 0x33614 | 0x300 |
GetLastError | 0x0 | 0x413194 | 0x34418 | 0x33618 | 0x202 |
ExitProcess | 0x0 | 0x413198 | 0x3441c | 0x3361c | 0x119 |
GetModuleHandleExW | 0x0 | 0x41319c | 0x34420 | 0x33620 | 0x217 |
GetProcAddress | 0x0 | 0x4131a0 | 0x34424 | 0x33624 | 0x245 |
MultiByteToWideChar | 0x0 | 0x4131a4 | 0x34428 | 0x33628 | 0x367 |
WideCharToMultiByte | 0x0 | 0x4131a8 | 0x3442c | 0x3362c | 0x511 |
LeaveCriticalSection | 0x0 | 0x4131ac | 0x34430 | 0x33630 | 0x339 |
HeapFree | 0x0 | 0x4131b0 | 0x34434 | 0x33634 | 0x2cf |
HeapAlloc | 0x0 | 0x4131b4 | 0x34438 | 0x33638 | 0x2cb |
SetLastError | 0x0 | 0x4131b8 | 0x3443c | 0x3363c | 0x473 |
GetCurrentThreadId | 0x0 | 0x4131bc | 0x34440 | 0x33640 | 0x1c5 |
GetProcessHeap | 0x0 | 0x4131c0 | 0x34444 | 0x33644 | 0x24a |
GetStdHandle | 0x0 | 0x4131c4 | 0x34448 | 0x33648 | 0x264 |
GetFileType | 0x0 | 0x4131c8 | 0x3444c | 0x3364c | 0x1f3 |
DeleteCriticalSection | 0x0 | 0x4131cc | 0x34450 | 0x33650 | 0xd1 |
GetStartupInfoW | 0x0 | 0x4131d0 | 0x34454 | 0x33654 | 0x263 |
GetModuleFileNameA | 0x0 | 0x4131d4 | 0x34458 | 0x33658 | 0x213 |
WriteFile | 0x0 | 0x4131d8 | 0x3445c | 0x3365c | 0x525 |
GetModuleFileNameW | 0x0 | 0x4131dc | 0x34460 | 0x33660 | 0x214 |
QueryPerformanceCounter | 0x0 | 0x4131e0 | 0x34464 | 0x33664 | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x4131e4 | 0x34468 | 0x33668 | 0x1c1 |
GetSystemTimeAsFileTime | 0x0 | 0x4131e8 | 0x3446c | 0x3366c | 0x279 |
GetEnvironmentStringsW | 0x0 | 0x4131ec | 0x34470 | 0x33670 | 0x1da |
UnhandledExceptionFilter | 0x0 | 0x4131f0 | 0x34474 | 0x33674 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x4131f4 | 0x34478 | 0x33678 | 0x4a5 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4131f8 | 0x3447c | 0x3367c | 0x2e3 |
Sleep | 0x0 | 0x4131fc | 0x34480 | 0x33680 | 0x4b2 |
GetCurrentProcess | 0x0 | 0x413200 | 0x34484 | 0x33684 | 0x1c0 |
TerminateProcess | 0x0 | 0x413204 | 0x34488 | 0x33688 | 0x4c0 |
TlsAlloc | 0x0 | 0x413208 | 0x3448c | 0x3368c | 0x4c5 |
TlsSetValue | 0x0 | 0x41320c | 0x34490 | 0x33690 | 0x4c8 |
TlsFree | 0x0 | 0x413210 | 0x34494 | 0x33694 | 0x4c6 |
LoadLibraryExW | 0x0 | 0x413214 | 0x34498 | 0x33698 | 0x33e |
IsValidCodePage | 0x0 | 0x413218 | 0x3449c | 0x3369c | 0x30a |
GetACP | 0x0 | 0x41321c | 0x344a0 | 0x336a0 | 0x168 |
GetOEMCP | 0x0 | 0x413220 | 0x344a4 | 0x336a4 | 0x237 |
GetCPInfo | 0x0 | 0x413224 | 0x344a8 | 0x336a8 | 0x172 |
GetConsoleCP | 0x0 | 0x413228 | 0x344ac | 0x336ac | 0x19a |
GetConsoleMode | 0x0 | 0x41322c | 0x344b0 | 0x336b0 | 0x1ac |
SetFilePointerEx | 0x0 | 0x413230 | 0x344b4 | 0x336b4 | 0x467 |
HeapReAlloc | 0x0 | 0x413234 | 0x344b8 | 0x336b8 | 0x2d2 |
LCMapStringW | 0x0 | 0x413238 | 0x344bc | 0x336bc | 0x32d |
OutputDebugStringW | 0x0 | 0x41323c | 0x344c0 | 0x336c0 | 0x38a |
GetStringTypeW | 0x0 | 0x413240 | 0x344c4 | 0x336c4 | 0x269 |
CreateFileW | 0x0 | 0x413244 | 0x344c8 | 0x336c8 | 0x8f |
USER32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InvalidateRgn | 0x0 | 0x41324c | 0x344d0 | 0x336d0 | 0x1bf |
GetClassInfoExW | 0x0 | 0x413250 | 0x344d4 | 0x336d4 | 0x10d |
GetMonitorInfoW | 0x0 | 0x413254 | 0x344d8 | 0x336d8 | 0x15f |
CharNextW | 0x0 | 0x413258 | 0x344dc | 0x336dc | 0x31 |
ADVAPI32.dll (14)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateServiceA | 0x0 | 0x413000 | 0x34284 | 0x33484 | 0x80 |
QueryServiceConfigW | 0x0 | 0x413004 | 0x34288 | 0x33488 | 0x224 |
ConvertToAutoInheritPrivateObjectSecurity | 0x0 | 0x413008 | 0x3428c | 0x3348c | 0x75 |
RegEnumKeyExW | 0x0 | 0x41300c | 0x34290 | 0x33490 | 0x24f |
RegisterServiceCtrlHandlerW | 0x0 | 0x413010 | 0x34294 | 0x33494 | 0x288 |
ObjectDeleteAuditAlarmA | 0x0 | 0x413014 | 0x34298 | 0x33498 | 0x1eb |
RegOpenKeyExW | 0x0 | 0x413018 | 0x3429c | 0x3349c | 0x261 |
EnumServicesStatusW | 0x0 | 0x41301c | 0x342a0 | 0x334a0 | 0x102 |
RegConnectRegistryW | 0x0 | 0x413020 | 0x342a4 | 0x334a4 | 0x234 |
GetNumberOfEventLogRecords | 0x0 | 0x413024 | 0x342a8 | 0x334a8 | 0x143 |
RegSaveKeyW | 0x0 | 0x413028 | 0x342ac | 0x334ac | 0x278 |
RegQueryValueExW | 0x0 | 0x41302c | 0x342b0 | 0x334b0 | 0x26e |
AccessCheckByTypeResultListAndAuditAlarmA | 0x0 | 0x413030 | 0x342b4 | 0x334b4 | 0xc |
InitiateSystemShutdownA | 0x0 | 0x413034 | 0x342b8 | 0x334b8 | 0x17b |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.41651045 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\16ec01a8-9cb0-4fd9-9d7a-ff79ab43a52d\5.exe | Downloaded File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-07-12 05:43 (UTC+2) |
Last Seen | 2019-09-10 02:50 (UTC+2) |
Names | Win32.Trojan.Rdn |
Families | Rdn |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x42b07e |
Size Of Code | 0x4d000 |
Size Of Initialized Data | 0xc1200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-01-12 12:28:11+00:00 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x4cee0 | 0x4d000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.27 |
.rdata | 0x44e000 | 0xa32e | 0xa400 | 0x4d400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.04 |
.data | 0x459000 | 0xab158 | 0x2600 | 0x57800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.99 |
.idata | 0x505000 | 0x1ee5 | 0x1400 | 0x59e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.71 |
.rsrc | 0x507000 | 0x895c | 0x8a00 | 0x5b200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.59 |
.reloc | 0x510000 | 0x1de6 | 0x1e00 | 0x63c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 4.73 |
Imports (4)
»
KERNEL32.dll (94)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ReadConsoleA | 0x0 | 0x505340 | 0x1050a8 | 0x59ea8 | 0x3b4 |
WriteProfileStringW | 0x0 | 0x505344 | 0x1050ac | 0x59eac | 0x532 |
WriteProfileSectionA | 0x0 | 0x505348 | 0x1050b0 | 0x59eb0 | 0x52f |
LoadLibraryA | 0x0 | 0x50534c | 0x1050b4 | 0x59eb4 | 0x33c |
GetProcessPriorityBoost | 0x0 | 0x505350 | 0x1050b8 | 0x59eb8 | 0x250 |
GetTempPathW | 0x0 | 0x505354 | 0x1050bc | 0x59ebc | 0x285 |
IsProcessorFeaturePresent | 0x0 | 0x505358 | 0x1050c0 | 0x59ec0 | 0x304 |
GetTickCount | 0x0 | 0x50535c | 0x1050c4 | 0x59ec4 | 0x293 |
SleepEx | 0x0 | 0x505360 | 0x1050c8 | 0x59ec8 | 0x4b5 |
GetSystemDirectoryA | 0x0 | 0x505364 | 0x1050cc | 0x59ecc | 0x26f |
SetConsoleCP | 0x0 | 0x505368 | 0x1050d0 | 0x59ed0 | 0x42c |
FormatMessageA | 0x0 | 0x50536c | 0x1050d4 | 0x59ed4 | 0x15d |
EnumTimeFormatsA | 0x0 | 0x505370 | 0x1050d8 | 0x59ed8 | 0x110 |
FreeUserPhysicalPages | 0x0 | 0x505374 | 0x1050dc | 0x59edc | 0x166 |
EnumSystemLocalesA | 0x0 | 0x505378 | 0x1050e0 | 0x59ee0 | 0x10d |
GetLocaleInfoA | 0x0 | 0x50537c | 0x1050e4 | 0x59ee4 | 0x204 |
GetUserDefaultLCID | 0x0 | 0x505380 | 0x1050e8 | 0x59ee8 | 0x29b |
ReadFile | 0x0 | 0x505384 | 0x1050ec | 0x59eec | 0x3c0 |
GetModuleHandleA | 0x0 | 0x505388 | 0x1050f0 | 0x59ef0 | 0x215 |
VirtualProtect | 0x0 | 0x50538c | 0x1050f4 | 0x59ef4 | 0x4ef |
GlobalAlloc | 0x0 | 0x505390 | 0x1050f8 | 0x59ef8 | 0x2b3 |
FindClose | 0x0 | 0x505394 | 0x1050fc | 0x59efc | 0x12e |
SetTapeParameters | 0x0 | 0x505398 | 0x105100 | 0x59f00 | 0x48d |
GetFileTime | 0x0 | 0x50539c | 0x105104 | 0x59f04 | 0x1f2 |
LCMapStringW | 0x0 | 0x5053a0 | 0x105108 | 0x59f08 | 0x32d |
HeapReAlloc | 0x0 | 0x5053a4 | 0x10510c | 0x59f0c | 0x2d2 |
GetLastError | 0x0 | 0x5053a8 | 0x105110 | 0x59f10 | 0x202 |
HeapFree | 0x0 | 0x5053ac | 0x105114 | 0x59f14 | 0x2cf |
HeapAlloc | 0x0 | 0x5053b0 | 0x105118 | 0x59f18 | 0x2cb |
GetProcAddress | 0x0 | 0x5053b4 | 0x10511c | 0x59f1c | 0x245 |
GetModuleHandleW | 0x0 | 0x5053b8 | 0x105120 | 0x59f20 | 0x218 |
ExitProcess | 0x0 | 0x5053bc | 0x105124 | 0x59f24 | 0x119 |
DecodePointer | 0x0 | 0x5053c0 | 0x105128 | 0x59f28 | 0xca |
GetCommandLineA | 0x0 | 0x5053c4 | 0x10512c | 0x59f2c | 0x186 |
HeapSetInformation | 0x0 | 0x5053c8 | 0x105130 | 0x59f30 | 0x2d3 |
GetStartupInfoW | 0x0 | 0x5053cc | 0x105134 | 0x59f34 | 0x263 |
WriteFile | 0x0 | 0x5053d0 | 0x105138 | 0x59f38 | 0x525 |
WideCharToMultiByte | 0x0 | 0x5053d4 | 0x10513c | 0x59f3c | 0x511 |
GetConsoleCP | 0x0 | 0x5053d8 | 0x105140 | 0x59f40 | 0x19a |
GetConsoleMode | 0x0 | 0x5053dc | 0x105144 | 0x59f44 | 0x1ac |
UnhandledExceptionFilter | 0x0 | 0x5053e0 | 0x105148 | 0x59f48 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x5053e4 | 0x10514c | 0x59f4c | 0x4a5 |
IsDebuggerPresent | 0x0 | 0x5053e8 | 0x105150 | 0x59f50 | 0x300 |
EncodePointer | 0x0 | 0x5053ec | 0x105154 | 0x59f54 | 0xea |
TerminateProcess | 0x0 | 0x5053f0 | 0x105158 | 0x59f58 | 0x4c0 |
GetCurrentProcess | 0x0 | 0x5053f4 | 0x10515c | 0x59f5c | 0x1c0 |
EnterCriticalSection | 0x0 | 0x5053f8 | 0x105160 | 0x59f60 | 0xee |
LeaveCriticalSection | 0x0 | 0x5053fc | 0x105164 | 0x59f64 | 0x339 |
FlushFileBuffers | 0x0 | 0x505400 | 0x105168 | 0x59f68 | 0x157 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x505404 | 0x10516c | 0x59f6c | 0x2e3 |
DeleteCriticalSection | 0x0 | 0x505408 | 0x105170 | 0x59f70 | 0xd1 |
FatalAppExitA | 0x0 | 0x50540c | 0x105174 | 0x59f74 | 0x120 |
HeapCreate | 0x0 | 0x505410 | 0x105178 | 0x59f78 | 0x2cd |
HeapDestroy | 0x0 | 0x505414 | 0x10517c | 0x59f7c | 0x2ce |
GetStdHandle | 0x0 | 0x505418 | 0x105180 | 0x59f80 | 0x264 |
GetModuleFileNameW | 0x0 | 0x50541c | 0x105184 | 0x59f84 | 0x214 |
SetConsoleCtrlHandler | 0x0 | 0x505420 | 0x105188 | 0x59f88 | 0x42d |
FreeLibrary | 0x0 | 0x505424 | 0x10518c | 0x59f8c | 0x162 |
InterlockedExchange | 0x0 | 0x505428 | 0x105190 | 0x59f90 | 0x2ec |
LoadLibraryW | 0x0 | 0x50542c | 0x105194 | 0x59f94 | 0x33f |
GetLocaleInfoW | 0x0 | 0x505430 | 0x105198 | 0x59f98 | 0x206 |
TlsAlloc | 0x0 | 0x505434 | 0x10519c | 0x59f9c | 0x4c5 |
TlsGetValue | 0x0 | 0x505438 | 0x1051a0 | 0x59fa0 | 0x4c7 |
TlsSetValue | 0x0 | 0x50543c | 0x1051a4 | 0x59fa4 | 0x4c8 |
TlsFree | 0x0 | 0x505440 | 0x1051a8 | 0x59fa8 | 0x4c6 |
InterlockedIncrement | 0x0 | 0x505444 | 0x1051ac | 0x59fac | 0x2ef |
SetLastError | 0x0 | 0x505448 | 0x1051b0 | 0x59fb0 | 0x473 |
GetCurrentThreadId | 0x0 | 0x50544c | 0x1051b4 | 0x59fb4 | 0x1c5 |
InterlockedDecrement | 0x0 | 0x505450 | 0x1051b8 | 0x59fb8 | 0x2eb |
GetCurrentThread | 0x0 | 0x505454 | 0x1051bc | 0x59fbc | 0x1c4 |
GetModuleFileNameA | 0x0 | 0x505458 | 0x1051c0 | 0x59fc0 | 0x213 |
FreeEnvironmentStringsW | 0x0 | 0x50545c | 0x1051c4 | 0x59fc4 | 0x161 |
GetEnvironmentStringsW | 0x0 | 0x505460 | 0x1051c8 | 0x59fc8 | 0x1da |
SetHandleCount | 0x0 | 0x505464 | 0x1051cc | 0x59fcc | 0x46f |
GetFileType | 0x0 | 0x505468 | 0x1051d0 | 0x59fd0 | 0x1f3 |
QueryPerformanceCounter | 0x0 | 0x50546c | 0x1051d4 | 0x59fd4 | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x505470 | 0x1051d8 | 0x59fd8 | 0x1c1 |
GetSystemTimeAsFileTime | 0x0 | 0x505474 | 0x1051dc | 0x59fdc | 0x279 |
SetFilePointer | 0x0 | 0x505478 | 0x1051e0 | 0x59fe0 | 0x466 |
WriteConsoleW | 0x0 | 0x50547c | 0x1051e4 | 0x59fe4 | 0x524 |
MultiByteToWideChar | 0x0 | 0x505480 | 0x1051e8 | 0x59fe8 | 0x367 |
SetStdHandle | 0x0 | 0x505484 | 0x1051ec | 0x59fec | 0x487 |
Sleep | 0x0 | 0x505488 | 0x1051f0 | 0x59ff0 | 0x4b2 |
RtlUnwind | 0x0 | 0x50548c | 0x1051f4 | 0x59ff4 | 0x418 |
GetCPInfo | 0x0 | 0x505490 | 0x1051f8 | 0x59ff8 | 0x172 |
GetACP | 0x0 | 0x505494 | 0x1051fc | 0x59ffc | 0x168 |
GetOEMCP | 0x0 | 0x505498 | 0x105200 | 0x5a000 | 0x237 |
IsValidCodePage | 0x0 | 0x50549c | 0x105204 | 0x5a004 | 0x30a |
HeapSize | 0x0 | 0x5054a0 | 0x105208 | 0x5a008 | 0x2d4 |
RaiseException | 0x0 | 0x5054a4 | 0x10520c | 0x5a00c | 0x3b1 |
CreateFileW | 0x0 | 0x5054a8 | 0x105210 | 0x5a010 | 0x8f |
CloseHandle | 0x0 | 0x5054ac | 0x105214 | 0x5a014 | 0x52 |
GetStringTypeW | 0x0 | 0x5054b0 | 0x105218 | 0x5a018 | 0x269 |
IsValidLocale | 0x0 | 0x5054b4 | 0x10521c | 0x5a01c | 0x30c |
USER32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetWindowsHookA | 0x0 | 0x50555c | 0x1052c4 | 0x5a0c4 | 0x2cd |
GetMenuBarInfo | 0x0 | 0x505560 | 0x1052c8 | 0x5a0c8 | 0x14c |
ClientToScreen | 0x0 | 0x505564 | 0x1052cc | 0x5a0cc | 0x47 |
GDI32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
OffsetWindowOrgEx | 0x0 | 0x5052fc | 0x105064 | 0x59e64 | 0x23f |
GetSystemPaletteUse | 0x0 | 0x505300 | 0x105068 | 0x59e68 | 0x213 |
GetLogColorSpaceA | 0x0 | 0x505304 | 0x10506c | 0x59e6c | 0x1ee |
SetDIBColorTable | 0x0 | 0x505308 | 0x105070 | 0x59e70 | 0x287 |
MoveToEx | 0x0 | 0x50530c | 0x105074 | 0x59e74 | 0x23a |
MSIMG32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GradientFill | 0x0 | 0x50552c | 0x105294 | 0x5a094 | 0x2 |
Memory Dumps (8)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
5.exe | 10 | 0x00400000 | 0x00511FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 10 | 0x0062DC70 | 0x0064958F | Marked Executable | - | 32-bit | - |
![]() |
![]() |
...
|
5.exe | 10 | 0x00400000 | 0x00511FFF | Content Changed | - | 32-bit | 0x0041A684 |
![]() |
![]() |
...
|
5.exe | 10 | 0x00400000 | 0x00511FFF | Content Changed | - | 32-bit | 0x00403274 |
![]() |
![]() |
...
|
5.exe | 10 | 0x00400000 | 0x00511FFF | Content Changed | - | 32-bit | 0x00407D24 |
![]() |
![]() |
...
|
5.exe | 10 | 0x00400000 | 0x00511FFF | Content Changed | - | 32-bit | 0x00406C4C |
![]() |
![]() |
...
|
5.exe | 10 | 0x00400000 | 0x00511FFF | Content Changed | - | 32-bit | 0x00413FF0 |
![]() |
![]() |
...
|
5.exe | 10 | 0x00400000 | 0x00511FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.32145393 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\2B74.TMP.EXE.exe | Modified File | Binary |
Unknown
|
...
|
»
Memory Dumps (7)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
buffer | 1 | 0x002B0020 | 0x0034425F | Marked Executable | - | 32-bit | 0x002B17E2 |
![]() |
![]() |
...
|
buffer | 1 | 0x04D40000 | 0x04E59FFF | First Execution | - | 32-bit | 0x04D40000 |
![]() |
![]() |
...
|
buffer | 5 | 0x00210020 | 0x002A425F | Marked Executable | - | 32-bit | 0x002117E2 |
![]() |
![]() |
...
|
buffer | 5 | 0x00210020 | 0x002A425F | Content Changed | - | 32-bit | 0x00211F7B |
![]() |
![]() |
...
|
buffer | 5 | 0x033E0000 | 0x034F9FFF | First Execution | - | 32-bit | 0x033E0000 |
![]() |
![]() |
...
|
buffer | 18 | 0x00280020 | 0x0031425F | Marked Executable | - | 32-bit | 0x002817E2 |
![]() |
![]() |
...
|
buffer | 18 | 0x04C40000 | 0x04D59FFF | First Execution | - | 32-bit | 0x04C40000 |
![]() |
![]() |
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\73vID7uoOX7691K_8lf.flv.kvag | Dropped File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\93DUD_DP1S6Odp.m4a.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ac94nmxutgBcO_sO.mkv.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\AVR2QWSJN.m4a.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\bPwpx4 hRUfmt26EN U.m4a.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\CE eygFl g2Xt.mp3.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ERSLB.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\FhmDa9mexQyl2j5W.jpg.kvag | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\FPcskdkXDA2.gif.kvag | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\I0kpPdyNQrVUZUse2i.doc.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\IA6oM qudfY.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\K3H_YJ9Dlj 2XD.swf.kvag | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\K7kimO.bmp.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\mGWda9.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\t_hQ4n.mp3.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Uiap nVn-UUVgXikA_Du.avi.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Vg6XpIzB5IOETRduC0mW.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\VX-tXZ7p07rm2KlA.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\yFpkKpBBWpZMakq.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\07oX6.docx.kvag | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\4uLO0.docx.kvag | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\7JC_yCO.odt | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8EZD4fe-JzDo4-iwb.ots.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\9xmij.pptx | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\A-wDiWAFo.ots | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\BUCN1gpGmAwuDQN0e.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\CJmRkQ5JiE_lg0ZYg.docx.kvag | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\CqP6Ff j5ryAP9m.csv.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\e29DgY3qW.docx | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\EeFAgU3hDZ4U9MuXcsJ.rtf | Modified File | Text |
Unknown
|
...
|
»
RTF Information
»
Document Content Snippet
»
2IR$Dvw7jЋx+B`>iά)WO40r"MJ:=;l"KHtbUd@-FYsxF3Jˋ왪E0j'?,4̕[V>Q6;XBq*<`6d3Xi?dq n(>q3ݚe7B0hGY.yK;cժ8-J50)1L_ב55ѽfCj!X2͞.3`,4Q'Yr?,ƹ1XrQ˜ߒ/D˂;~J%/yĝ+Qie^ *يDbPۤ²Nw7ڠəQoM>]#cO=o~$(Y$oǪ~bv诡ŶZa<NEV c3`?zUZ)CG<5],@ILKV2$.Bmo?䙭+!nBrF^fƨr2J(J?dA]lLxOD GUJD۟H̳d@`'.9q[i)bД3W]u2"Sߴxt4l$5Ykip(:LUUo^i!JJWB[rLTa3`=Z<WW^=Q|wEZMR `|,l8T!7 |0ODuj-jE,%V#^/Ҡ4Qu;:@ LdQi6]k̚k %أxEFeߩ+_$oˢjϔ33i;7_JUA֒r&uZx_ʼ#Vtl7*ێmdϚCfwq`mnYϨ&cn&=u* z#5]ZpXkAcGU'_lI9i.8UN M*wʱɞYw13,Ap9t@qƄ[9!:d7@އEx2k_l#҃G,bK=jzut-hIH_qho/Z}3Oi]L2ߦHuY3≶eDM=mťL+OH/UƮ_@']Tȉp )+8cu5 Y3]prDE_x/+Phځ%Jc0lyU &3`ݧp]XJy(ە]ʙR#Ί3'NSt3z;9TAdlscVG=>ʒ#G͛PyJ-?6-7qY+-gqᣑ~cm~`BcZTd]Rh3L 1o0?qHwN!Ƕ;:淜ڜ:䊦 ZX9йqǰ9[Gw'S,_λpzh e94k7FKE28M`5ͤ*yy*Y&olsBV$i&4UK=+_SvP&Uq|jJ$[pFRč#j!m+d%U.y0]@!>rWƜCEhqM4z0__B@j"`DVRycٌ)4֏Z2E^P2XթM^VH|yMѶafk=X)zKWiMkG힎jp7:ğ ... |
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\FGXg53O8b.pps.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\GSo0hbTz23.rtf | Modified File | Text |
Unknown
|
...
|
»
RTF Information
»
Document Content Snippet
»
B*<G/y(v̘F2b$0/=4jͶЍa1ogz/̺ԯ%4 US=*1G#t4QT8pмy>P;X(tkU)AfEu܊pE(c12,4%V]a 6Ae9ʽWyG]eY^>9R^:(HW-grYHYj+MRjhe:pݯ4Z]8i Y'jȗFD-(ùtZ+_$V459*QQ]l6yI$Amy!]&՟0U`RF c[mӿZX7v5LHB?5PXz%xH^/Ȗ2noP*Hysw6l<X !v+V'6Xw@w鯰Xm 6m`77ae|p8Ŋ'ΕXUZMh퀍+&ɭ#w(gp*n+=51hHGa&J So"9>5R|%&&Xc,H|H2S(йhэb$Rb=&NUgfc~ii?%pÛ79(U/4E9LL&RݱW(h5)5C_rjH7ۗK`-`e⢽#`G$=ȩ5_vo͂$ӝNݩGmfho; M64@b[|"MFUq)R=?O;LItBL9*2Byy#X5e,;2ѝh"*3ki:X8Hq7v|σ_ nQ*%/.*?Tqy((,Snйۘa+$U$6KGm^o,Idʗ5TwAYz#4@Aq%Ď#;Iٛ1j$Fbe))E%#qIcѡ%&n&]XTQCqңYq|sL[`gItfcĴZbƞCWhݾ| c$ u*cL!?^NA.Xi:WF;霣.+UH,e':9nn ~mۮDեW><yrTJE(1:60ˉkuˀIHKc-:)C4EzS-դ~/$n|g5.ѕf(*t #C熟iGvYФ:3ԣt=|`ZzeE&,?3* `|`+b6+0sŢYIe盫_JW`!sS^̿t`=ʝm`j%Ⱝ:Ӽ[ei[+uP&W]?b>C9㭼|'pPf^/Znk64Rw@qVo1-5M7$|R*J,k"sޢVQz(cg!|X8r9-+)exykTqB[QM[twfHj8Lc7Yą%z"L[ZT$<Lb^441'$DuVK huo!_$v<Xv,JVr%%Ft$WW?,E#oQaJNH-=xIEspo5-s,/Q ... |
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JF7e24yFrvj874pRbz.xls.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\kGiZali 3xcty.ots.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\M3c6UFv6B8YP8gKAw.pptx.kvag | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Nqt6s-h.rtf.kvag | Dropped File | Text |
Unknown
|
...
|
»
RTF Information
»
Document Content Snippet
»
[[z)-ʻ ;[c=3yVt;mo6ۗqj`L`K^㑑xfQN_Ql.QVЄmqṙS (ECÐlX#5D=zy:0+R߬z[I6QՂ;8j&7W-X-@K_%Ҡ |3(yLp.kk$xFЕH!V0UUGHGV]ZU2yW˩2M*0=͇wJrB;`Ef^ om@iadCuE^XO]E=:Ot7ۅ+կ%0X@(-WFaRIeoVQL4ܘH `BApn#&ٯ3`ҧ9A[M5("%;,QJR]@ iW"M^'$ÎBni0#sla^-oZOV̺,e,Lpp;=Hv|$HR=Unl$ƦoGY(KeU؟0`b,%nэo2/$pMިkQ8ձ5`+CԪr˙pB-e!L+QZ,2COX'$/]˯o~o&=DmK0(|*>p͆-jEԷjY/܄"uߊ͂HsxL0t^tV~Dߎk87K,5NV4#,$q/Ldġ"?b֫ipƘ?XMkjP7Vht.w26#dpFf)^W^6͞:оzyX]t]EH10z&0I9->8)s%AKnn<,43͌AlyEz%k*;͒7A)Wz^ B 4%M;0Uts6PǶRy@jem>F]`9ӡڈƹsѕuokXO14F^~Vsz)+Kg@,Jmvv~I^Rn6+;Toۑ:JɊJצ-Y7+LJ]ߍJw.`j£gVnH;%^mldkҥ؟ sDzz4ra-l հ#<xBk_^<&'U֮VdX"`ht "Z|v.ֱe";9$WlRG`5_WM5W|#^UҡM<JQ.'xP1|PyU/HQgx(ck=RD'=8Ɔo4h']~F7۷6=>H80m^U6ęḥ'B_t魤gE鐱zT4:ʤ"%ÄإjZт"r߰q_~Ws[Hx&)d~$L^vG9Irέ~wA3K8FM6ZmKA>)MiTK6;E8LY1be]ŝ`͉ Bvk:v`W33]_y'5FR*^O,> !HxBv8e6i;JTc`gTvmjޛatl̴Ӗ` ;9@t:N5IŠf.[7xyCLlԷDk6;. ... |
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\OiTQ4Y77X9w.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\pP5LKp.rtf.kvag | Dropped File | Text |
Unknown
|
...
|
»
RTF Information
»
Document Content Snippet
»
n>JV>cP^)$r=ASxy ݞϒ93P4qpg)fnZbPsM^.>&4FArcocfc"*~G5G $ 5ɪG˜9252[;`v@y7Q"lJoCT^ՔVk]ܸt(0stDn?b<M>jI: ;hCb'"jĴ|oU)#8/NbItICR-uQMIeqjKMxʚl'vzH<]x"YfWO@$T3'ȏipdĥ+Wo|?A<Vhq&-g#o^'^j<0XMG(f~2NC#Y9(jD ?/SްoOZHI-S_ܕ:tr!ByEMǖ),hD|ݍb=Xe>mN9>S@hr괃?gk8gDbC;ڸf7-)1tosԝ_!,;q`)lD^6h/..KT =EQۢmQxv%g&%XWRqhOs]8--^fW]po1_qgcҏ<s<2/zTsnl쀸iRi-l;ZwB纀?7Қ5V24g+)ZQ_d@Ӈ͖tӫ5msɕE=ϬF ٤J.RJ v蒿4m__$2%H#EKji';WfPʵڑeFC1Ss@?f/)0RYmL0kps5bS-']>ms8 dKjH&,AkYv`ݜKp=&FB9PMOϩ "]vet#?')p^&L)痱Dpv.8R%U2I9!KL^oh ]7#v84 "VccB#(g4`Eߖړ嬓aE9'&7AM!Dq*0JQh.Y?B3&n_:teh:>8~w]Rt( BrXp%m%r_9qYCEP_ȢrI(E7)q6ci>5m;!$bh#kىi_ +)Pjܪ8uU1b|'D0dVoT*?d.sxdۓ8ʕж2A1U*U37!hk lt?yta` "W㐠CnD$n-i]¸ɉ*Szv9RēOsM&U?W/xz0X-MZpxؒ/%1z c3]2q=sІZYD K'(2j۪:qr)Jjvfߴ]F>֕tYơds%*+ vX,@|e<YMJDi.d-YUNNn;gj=i<r;&h#hUT:W;myղw9O?ddafqah@JMۡ"J,MS4z! ͋n)Ec~ꐔt.;e|:آJx ... |
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\PRVnBgxJ5.odt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\qvceNH5FTtN.rtf | Modified File | Text |
Unknown
|
...
|
»
RTF Information
»
Document Content Snippet
»
:ҩ2&Q'|ʎvjm|l5*7/e"xȒB#>Hˑ9ats"76w٢93*WD"xY]lTߙnRVZP0LLNRg;U%Q%jJRl^-3MQ1~*nSE.BA*%C2q.S-N7Dh#7?LǛ9 mnձPٔ!UʽuyY76V,3M+goߕWLrgkvOʯaSC処vU,zq+'< dMm_JVM٥>:Q?zŲPDY@Fb/F+5!],||ha,-p4]QS4DCkn/QvÞ_4t(#D0;lTZ16ów7h:"Pt<E07~7<C=Ά)%We*hXprVQ9/q6eX6hOc6&Xa&LلZ~aXTc<B7c ֩rrg/Z:3dz4=Gm9)E֎jQC̣]Or%l`IB,9Ih+eGJAk^TRm[Hmp``qMq[uÃOu5mc-577Qzj(7Shy]Ƚ>~CCQX2HU""Ƌ=S?ԅ9FΔ1 (YW 2Z%[aL7T-LUx%e((Ͻ^hDn,qu/5f:ce1^KܴYR-+?KkuccXݒx32wN/y]D=TED'*IyEN?b?LMˀT:'3$):r(aƱ]z`k/ViDi2~Bz_/p|pWzl^iݺы`"m%Bѓo%<srmN8=uؖ7K]R3gKj(CIThgdʳS60>[G&?!=)d8D'*W#^TxlwDo1NBE@1ul)ǜlrJTl>ۺ^t1ڡճD"f ޒK slQMo1',)NI&7~*BYbB_)<ZڿM?oF9Ӵʟv'Ku(Bʺ5 G&d(b~,[ ɴ~P@!1z.(]dnܨ"-͌0aoD`8h e`72s?/n:+i%,;aEhu,etSZH䔹WOS̙HK4uJ6%`3jl<=P<]RDg?y&z]ɯDTXoWZŻ˻QHfqFvUXHCŊGt;MZݧYk)&WDžчk)4i|&|+Է"<<ɑHwqsp(+vP5S:GGѨ2bN<j$"EUpTE$C6ꂹh:r^!7s˦qzZ#ꦢBak&ˑ|YW|gk.i[G-ٳ ... |
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\QY6CDvI9g4eui.pptx.kvag | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\RMMC2E_QGSZx-2yz.rtf | Modified File | Text |
Unknown
|
...
|
»
RTF Information
»
Document Content Snippet
»
+ͦb||`!@XE=X*S1"cx@d׀췑a!7EW)=EMaFڋ(o$-TdYՙxNXb1gnN*pڲ|ue(2%j`/u(7Ҳ^;VO?2,k:fcs%Z8TũBblMH`$R<n세_bmwQE0[$qOFkx|z0':5IR4QBO/TQݥ'?؟1c~ؾ`P0QgHUڅ$֛4B!%WH_휋/ӫzҾKñ;M<j ~-g^aTH'ƾfadʂLEڴ33bՆ~Hï,KVrhy5y>5U!/*ts䖣7+:1K4_( F`.f˹,ݞc-x^XrN|(0E:hW6.@yj@ny(VjvyC8ŜޯSɽ?_0zYFyC'K~m)4HQ;Z8;Ī_=9s!qJCQ47|#:. h6e$vn) =NnqVj3Rw9L40rr'~W;4~˰?e3Wr-KwS1##á`U>sg8&VQdN:"J'֣y:W R~,̚[e7_+В=-L._:8#d$T++5!Dž_D(˓AVdGºhI+Z-re|(2W],RO˸!F>Iveȯh`H<k1&-Z18Jzb~).AaoB@aM28t/EzGiqo.1vM.mheၐw'gPet'IGy3IJaYAt5)_/iSZCI'^~aӁZţtǓaD%WtΛ#⡌qZ;^?]J7p)ϲqޮW/i/3K-57fd:Fy VݛIJ'PiÝe"5َ$!ӱ]dT0z[d _>0I2췪77Y)l@+C~G2DjlbqT9C;+UK7+ZskV!#u>V~%AԂ2^ey|8)袉&Bͣ/j3뙝>Uf<G5xQAJ\v~wNGMH?EvZZe|N/kKCu,(,$|=6v@lzEbiTMo?U쎳X8<?4$z;dAaxF988M2tҐI܌2=_*3V*;ޗP<p!(N p^uN[Z^m1Ucw>y'ϝ8Ǔx>QN ;7U٠TYwoxn~;+D0[Z=R-Blmz=8<հ%/ k،R37wPZ]'7cL#aehV^7W0^&~:LTCoOOX屯Cǵu/ڴ5fݨ2C<v ... |
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\S9TDRhPkSv5vLHzMFlW.odt | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\sQiZZ.docx | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\TzAPiAs6qAhraI.odp.kvag | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\WIAI1.xlsx | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xJBVQQII-j.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\XpuS4jw10.docx.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ZKPjo8JohJqXPt0egkjs.pptx | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\1a20kzVE_cVBJfA1si.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\2VWfH-tyMn.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\EImepXLJ4.m4a.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\HaZTaX Zg1qKL.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\hZq26AwDROO OI ep.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\KpgK4Eq8VgZx.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\oksjJ.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\P0kZ 5sEUj-Qr3n_8v.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\V8CZiiS8yq6173-jiD.mp3.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\5eZyg.gif.kvag | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ANRz7BiMGjif1lT.jpg.kvag | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\bEXqr-0RskHd.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\C7F4 Wc1xIRcM1R.bmp.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Cq3m_40ULsX.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\d fvuJCkm tkxAy.bmp.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\iIl9 Kf6dOpe1lUAjHX.png.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\jH6B7Hxu.gif.kvag | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\OrlE5DDk6Qs.bmp.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\p7jOmY0YHtfEDXHjzMJ-.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\RCRu7.gif.kvag | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\sM6ixwL8Pn6854du50BY.jpg.kvag | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\whuSlBZPh.jpg.kvag | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\wuoRnmzpakY.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\wvBPa9.gif | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\X4f2vPCr2a.bmp.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\x5DOOinBD.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\xT5AxUm6MKKi2KE.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Yjdn_ho1.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ZRwVhWTmgDeFVw4ZRxb.gif.kvag | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_pUGM.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\4 Bc.flv.kvag | Dropped File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\FKhUWfx-d 3P.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\oMZDvujBwo0QTetEg.mp4.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MnXmRfGpxPOeczS\AWCJ.swf.kvag | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MnXmRfGpxPOeczS\e8jYy.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MnXmRfGpxPOeczS\jpbeM _K1sn_lkYkaR.xlsx.kvag | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MnXmRfGpxPOeczS\nIRMb.avi.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft Store.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Entertainment.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Get Windows Live.url.kvag | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Gallery.url.kvag | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Mail.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\-oCX.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\2mCixPQ C.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\PgkQ-pJhsE-sX.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\Q1rdrJ4P3K0f1VBWsz.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\tWwlSFL.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\X1zSPuHiS_u.m4a.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PO z8nOyg\aej6fnJj8N.flv | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PO z8nOyg\W7BUx mN-XW3vrl8O8.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PO z8nOyg\WyJb_BisdCRy2SL.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_Iy8x9AH9E4iyV\epV aWEiH73AG5N_wmnM.mkv.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_Iy8x9AH9E4iyV\PiczzFq_WT9ja-21xQgt.mp4.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_Iy8x9AH9E4iyV\uGZW.swf.kvag | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MnXmRfGpxPOeczS\RynyhXN0v\4a8tVKirG4kf_.swf.kvag | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MnXmRfGpxPOeczS\RynyhXN0v\7D6iArC91 Gvdvs4fzbE.mp4.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MnXmRfGpxPOeczS\RynyhXN0v\ggUgd4m76uyf-R7.ots | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MnXmRfGpxPOeczS\RynyhXN0v\hd_I5QL.swf.kvag | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\_private\folder.ico.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\dDJH0qEgeh8-fL\1lRBjZRQOlow.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\dDJH0qEgeh8-fL\6xt4FsFvWcFUHy94.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\dDJH0qEgeh8-fL\N-2ZB.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\dDJH0qEgeh8-fL\Qne4-mFXNX7U_TH6.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\dDJH0qEgeh8-fL\XO SmK4Aq5-.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\QgLkms-\79lY3UJfi7jg-Rw.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\QgLkms-\AqxNzxwgHCKuzfsCaCH8.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\QgLkms-\kwaxsk4m.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\QgLkms-\PwRjCl.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\QgLkms-\Rg0qjq6f3-pfCaRPB.mp3.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PO z8nOyg\E8MPONl9OoHt_q1Da\76xpNeygNMpcG-mLxW.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PO z8nOyg\E8MPONl9OoHt_q1Da\jZj0QHRQWui3.flv.kvag | Dropped File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PO z8nOyg\E8MPONl9OoHt_q1Da\RCr-WbxWBDI_9yc2.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PO z8nOyg\qC5iE91o3\4HsAslPDmPtlJF74pOu.swf | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PO z8nOyg\qC5iE91o3\exaDYDv--4LV5xHD.swf | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PO z8nOyg\qC5iE91o3\F72ymb.mp4.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PO z8nOyg\qC5iE91o3\Fpn5 rIQgKEMen.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PO z8nOyg\qC5iE91o3\ZVpUd0FLYyHkQN.mp4.kvag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PO z8nOyg\E8MPONl9OoHt_q1Da\EKLgt3560oqvlMqYdD\OVSC.swf | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PO z8nOyg\E8MPONl9OoHt_q1Da\EKLgt3560oqvlMqYdD\UhhXjArBY.swf.kvag | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PO z8nOyg\E8MPONl9OoHt_q1Da\EKLgt3560oqvlMqYdD\vy43O2Ond- g.swf.kvag | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PO z8nOyg\E8MPONl9OoHt_q1Da\vdLT\A0XrY9 WNokaAWv.flv.kvag | Dropped File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\index.dat.kvag | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\history\history.ie5\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\x9ohk109\geo[1].json | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\_readme.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\Deployment\deployment.properties.kvag | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\x9ohk109\get[1].php | Downloaded File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\pV3yVe.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\RnJF6TCUGQ_2QRhsIz.wav.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\s9_5sxP4UTReq1w-S0Dp.jpg.kvag | Dropped File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\un2NZ0.ots.kvag | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\0qm3q9iPSe2R.ppt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\2o28EiG.odp.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8YZ957hMKqh_.odp | Modified File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\aPJJoH4o5A99cXyI.ods.kvag | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c2fsy0lIXf9fL9D_.xlsx.kvag | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\cbbKLa 8g2jylz.xlsx.kvag | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\F-3985rHMiViUc6cgm.xls | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\flz_m1D.xlsx | Modified File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\hqdY2gjPn5Eci.docx.kvag | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\mUv_SkYk3fldq1.pps | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ndagl35.xlsx.kvag | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\OzU-IttpwwBuAxnEt.ppt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\QUr6Wv.xlsx | Modified File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\uQLXRscP6.docx.kvag | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wMsDH0dZaz.pptx | Modified File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xHKfg1buDW5Et.ots.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ZuqvG17IH9puQg8B.pptx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ZX_nv6ome8v9IO5Mvi.ppt.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\_dmLJ1 KFGu.odp.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\5lR8cXfV8AUdqEIQ87t.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\AX5dw-yk.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\EcgP9ne1dlBj.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\-9kI8q.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8WI455-IeTtDu5ufHo.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AIlA315n8k.jpg.kvag | Dropped File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\BdqNz1PxzX3wOPjw.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Gy-VQuUkc4SKj_omZAJ1.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\iZQNS6PXH2.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\l6PS7hO-iIQ_NKlEq pK.png.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\M4rm6k3.gif | Modified File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\UGs 1G.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Uk30lTmUkDiXk.png.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\uQNlTbt2ZLDW28.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\vvqVqmO9vV2.png.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\W5kM7vMzTh0L6va.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zLSSWoma9-HlG53.gif.kvag | Dropped File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_oKd7ir99lD.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\MYQH9-tR9ltp09e.flv.kvag | Dropped File | Video |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MnXmRfGpxPOeczS\cPQuzY v_o s.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MnXmRfGpxPOeczS\JawS.mp4.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MnXmRfGpxPOeczS\Ly7OJHzcLLYB H_Z.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MnXmRfGpxPOeczS\Q2iWyxqWtvZV30.mkv.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MnXmRfGpxPOeczS\xKt-nxaBrLKyf.m4a.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MnXmRfGpxPOeczS\zEPqRnNSMkR2u9.pptx.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Suggested Sites.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Web Slice Gallery.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE Add-on site.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE site on Microsoft.com.url.kvag | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Home.url.kvag | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Work.url.kvag | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Autos.url.kvag | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Money.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Sports.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSNBC News.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Spaces.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\4IqXBq8-5-MGXyBDR.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\DDvvo5tjuRsdtvEYSI3d.m4a.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\HRoUkT40t Y.wav.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\XEg6.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PO z8nOyg\AWlsu7Qii7PrJnZs.mkv.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_Iy8x9AH9E4iyV\t2PkRgeqeSAZ.flv | Modified File | Video |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_Iy8x9AH9E4iyV\vYSVT88he-_OipIO5cJM.mp4.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MnXmRfGpxPOeczS\RynyhXN0v\FDcvm.m4a.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\dDJH0qEgeh8-fL\blTUlW3w8qpPB0Z.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\dDJH0qEgeh8-fL\Gjnn6ZYKu.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\QgLkms-\2sbAazIL4MPt q50L6sn.mp3.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\QgLkms-\53Gdf_RYd2_0WEu.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\QgLkms-\HBTr-UABKsVOi1XyIF.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\QgLkms-\RmrshUTwC7.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\QgLkms-\XxlqXWdRx.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\JMb5K DyX7\QgLkms-\_nxiTSIPFD8.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PO z8nOyg\E8MPONl9OoHt_q1Da\Rf5aukjBz6H8tbn.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PO z8nOyg\E8MPONl9OoHt_q1Da\yp4Gqi-sptD2Jeuxd_nS.mp4.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PO z8nOyg\qC5iE91o3\dFcnG6SW.avi.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PO z8nOyg\E8MPONl9OoHt_q1Da\EKLgt3560oqvlMqYdD\9KFuOftvE.flv.kvag | Dropped File | Video |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PO z8nOyg\E8MPONl9OoHt_q1Da\EKLgt3560oqvlMqYdD\uQ8X_zB.flv | Modified File | Video |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\PO z8nOyg\E8MPONl9OoHt_q1Da\vdLT\ZPzmVLw7V.mkv.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Adobe\Acrobat\10.0\rdrmessage.zip.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\ietldcache\index.dat | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\script.ps1 | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.msi.kvag | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\Data1.cab.kvag | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\Favorites.vss.kvag | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.cab.kvag | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\jre1.7.0_45.msi.kvag | Dropped File | Stream |
Not Queried
|
...
|
»