VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Trojan.Ransom.AIG
|
dttcodexgigas.5ac3e23c0c50b5cb8ca01b675b827995ada38e5b.exe
Windows Exe (x86-32)
Created at 2020-08-21T23:37:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\dttcodexgigas.5ac3e23c0c50b5cb8ca01b675b827995ada38e5b.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4021d1 |
Size Of Code | 0x1800 |
Size Of Initialized Data | 0x474a00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2012-01-29 18:49:03+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1688 | 0x1800 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.54 |
.rdata | 0x403000 | 0x820 | 0xa00 | 0x1c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.5 |
.data | 0x404000 | 0x38bb | 0x600 | 0x2600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.9 |
.rsrc | 0x408000 | 0x47383c | 0x473a00 | 0x2c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.78 |
Imports (7)
»
KERNEL32.DLL (37)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
lstrlenA | 0x0 | 0x40303c | 0x303c | 0x1c3c | 0x0 |
CloseHandle | 0x0 | 0x403040 | 0x3040 | 0x1c40 | 0x0 |
CopyFileA | 0x0 | 0x403044 | 0x3044 | 0x1c44 | 0x0 |
CreateFileA | 0x0 | 0x403048 | 0x3048 | 0x1c48 | 0x0 |
ExitProcess | 0x0 | 0x40304c | 0x304c | 0x1c4c | 0x0 |
FindClose | 0x0 | 0x403050 | 0x3050 | 0x1c50 | 0x0 |
FindFirstFileA | 0x0 | 0x403054 | 0x3054 | 0x1c54 | 0x0 |
FindNextFileA | 0x0 | 0x403058 | 0x3058 | 0x1c58 | 0x0 |
FindResourceA | 0x0 | 0x40305c | 0x305c | 0x1c5c | 0x0 |
FreeResource | 0x0 | 0x403060 | 0x3060 | 0x1c60 | 0x0 |
GetCommandLineA | 0x0 | 0x403064 | 0x3064 | 0x1c64 | 0x0 |
GetEnvironmentVariableA | 0x0 | 0x403068 | 0x3068 | 0x1c68 | 0x0 |
GetFileAttributesA | 0x0 | 0x40306c | 0x306c | 0x1c6c | 0x0 |
GetFileSize | 0x0 | 0x403070 | 0x3070 | 0x1c70 | 0x0 |
GetFileTime | 0x0 | 0x403074 | 0x3074 | 0x1c74 | 0x0 |
GetLogicalDrives | 0x0 | 0x403078 | 0x3078 | 0x1c78 | 0x0 |
GetModuleFileNameA | 0x0 | 0x40307c | 0x307c | 0x1c7c | 0x0 |
GetModuleHandleA | 0x0 | 0x403080 | 0x3080 | 0x1c80 | 0x0 |
GetProcessHeap | 0x0 | 0x403084 | 0x3084 | 0x1c84 | 0x0 |
GetTempPathA | 0x0 | 0x403088 | 0x3088 | 0x1c88 | 0x0 |
GetWindowsDirectoryA | 0x0 | 0x40308c | 0x308c | 0x1c8c | 0x0 |
GlobalFree | 0x0 | 0x403090 | 0x3090 | 0x1c90 | 0x0 |
HeapAlloc | 0x0 | 0x403094 | 0x3094 | 0x1c94 | 0x0 |
LoadResource | 0x0 | 0x403098 | 0x3098 | 0x1c98 | 0x0 |
LockResource | 0x0 | 0x40309c | 0x309c | 0x1c9c | 0x0 |
MoveFileA | 0x0 | 0x4030a0 | 0x30a0 | 0x1ca0 | 0x0 |
ReadFile | 0x0 | 0x4030a4 | 0x30a4 | 0x1ca4 | 0x0 |
RtlMoveMemory | 0x0 | 0x4030a8 | 0x30a8 | 0x1ca8 | 0x0 |
SetErrorMode | 0x0 | 0x4030ac | 0x30ac | 0x1cac | 0x0 |
SetFilePointer | 0x0 | 0x4030b0 | 0x30b0 | 0x1cb0 | 0x0 |
SetFileTime | 0x0 | 0x4030b4 | 0x30b4 | 0x1cb4 | 0x0 |
SizeofResource | 0x0 | 0x4030b8 | 0x30b8 | 0x1cb8 | 0x0 |
WriteFile | 0x0 | 0x4030bc | 0x30bc | 0x1cbc | 0x0 |
lstrcatA | 0x0 | 0x4030c0 | 0x30c0 | 0x1cc0 | 0x0 |
lstrcmpA | 0x0 | 0x4030c4 | 0x30c4 | 0x1cc4 | 0x0 |
lstrcmpiA | 0x0 | 0x4030c8 | 0x30c8 | 0x1cc8 | 0x0 |
lstrcpyA | 0x0 | 0x4030cc | 0x30cc | 0x1ccc | 0x0 |
advapi32.dll (10)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegCreateKeyExA | 0x0 | 0x403000 | 0x3000 | 0x1c00 | 0x0 |
CryptCreateHash | 0x0 | 0x403004 | 0x3004 | 0x1c04 | 0x0 |
CryptDestroyHash | 0x0 | 0x403008 | 0x3008 | 0x1c08 | 0x0 |
CryptGetHashParam | 0x0 | 0x40300c | 0x300c | 0x1c0c | 0x0 |
RegSetValueExA | 0x0 | 0x403010 | 0x3010 | 0x1c10 | 0x0 |
RegDeleteKeyA | 0x0 | 0x403014 | 0x3014 | 0x1c14 | 0x0 |
CryptAcquireContextA | 0x0 | 0x403018 | 0x3018 | 0x1c18 | 0x0 |
RegCloseKey | 0x0 | 0x40301c | 0x301c | 0x1c1c | 0x0 |
CryptReleaseContext | 0x0 | 0x403020 | 0x3020 | 0x1c20 | 0x0 |
CryptHashData | 0x0 | 0x403024 | 0x3024 | 0x1c24 | 0x0 |
comctl32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InitCommonControls | 0x0 | 0x40302c | 0x302c | 0x1c2c | 0x0 |
gdi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateFontIndirectA | 0x0 | 0x403034 | 0x3034 | 0x1c34 | 0x0 |
shell32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteA | 0x0 | 0x4030d4 | 0x30d4 | 0x1cd4 | 0x0 |
SHGetSpecialFolderPathA | 0x0 | 0x4030d8 | 0x30d8 | 0x1cd8 | 0x0 |
shlwapi.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathFindFileNameA | 0x0 | 0x4030e0 | 0x30e0 | 0x1ce0 | 0x0 |
PathFindExtensionA | 0x0 | 0x4030e4 | 0x30e4 | 0x1ce4 | 0x0 |
PathAddBackslashA | 0x0 | 0x4030e8 | 0x30e8 | 0x1ce8 | 0x0 |
PathMatchSpecA | 0x0 | 0x4030ec | 0x30ec | 0x1cec | 0x0 |
user32.dll (16)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegisterClassExA | 0x0 | 0x4030f4 | 0x30f4 | 0x1cf4 | 0x0 |
PeekMessageA | 0x0 | 0x4030f8 | 0x30f8 | 0x1cf8 | 0x0 |
SendMessageA | 0x0 | 0x4030fc | 0x30fc | 0x1cfc | 0x0 |
LoadCursorA | 0x0 | 0x403100 | 0x3100 | 0x1d00 | 0x0 |
GetSystemMetrics | 0x0 | 0x403104 | 0x3104 | 0x1d04 | 0x0 |
GetMessageA | 0x0 | 0x403108 | 0x3108 | 0x1d08 | 0x0 |
GetDlgItemTextA | 0x0 | 0x40310c | 0x310c | 0x1d0c | 0x0 |
EndPaint | 0x0 | 0x403110 | 0x3110 | 0x1d10 | 0x0 |
SystemParametersInfoA | 0x0 | 0x403114 | 0x3114 | 0x1d14 | 0x0 |
TranslateMessage | 0x0 | 0x403118 | 0x3118 | 0x1d18 | 0x0 |
UpdateWindow | 0x0 | 0x40311c | 0x311c | 0x1d1c | 0x0 |
MessageBoxA | 0x0 | 0x403120 | 0x3120 | 0x1d20 | 0x0 |
DispatchMessageA | 0x0 | 0x403124 | 0x3124 | 0x1d24 | 0x0 |
DefWindowProcA | 0x0 | 0x403128 | 0x3128 | 0x1d28 | 0x0 |
CreateWindowExA | 0x0 | 0x40312c | 0x312c | 0x1d2c | 0x0 |
BeginPaint | 0x0 | 0x403130 | 0x3130 | 0x1d30 | 0x0 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
dttcodexgigas.5ac3e23c0c50b5cb8ca01b675b827995ada38e5b.exe | 1 | 0x00400000 | 0x0087BFFF | Relevant Image |
![]() |
32-bit | 0x00401F87 |
![]() |
![]() |
...
|
dttcodexgigas.5ac3e23c0c50b5cb8ca01b675b827995ada38e5b.exe | 1 | 0x00400000 | 0x0087BFFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.Ransom.AIG |
Malicious
|
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00011_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00021_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00037_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00038_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00040_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00052_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00057_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00092_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00120_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00126_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00129_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00135_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00139_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00142_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00157_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00160_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00161_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00163_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00164_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00167_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00169_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00170_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00171_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00172_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD10890_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD10972_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD19563_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\BD19582_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\ELPHRG01.WAV.jigsaaw | Dropped File | Audio |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\J0214098.WAV | Modified File | Audio |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\J0234687.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\J0283209.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\J0284916.JPG | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\J0295241.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\J0300520.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10253_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10254_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10263_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10264_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10265_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10267_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10268_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10297_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10298_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10299_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10300_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10301_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10302_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10335_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14513_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14514_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14515_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14528_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14529_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14531_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14532_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14578_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14579_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14580_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14581_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14582_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14654_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14656_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14691_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14693_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14752_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14753_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14754_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14756_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14757_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14792_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14793_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14795_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14828_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14829_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14830_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14832_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14866_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14867_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14869_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14871_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14980_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14981_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14982_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD15018_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD15019_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD15056_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD15057_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD15058_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD15059_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD15133_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD15134_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD15135_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD15169_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD15170_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD15171_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD15172_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD15173_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD15273_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD15274_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21296_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21297_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21300_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21301_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21302_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21306_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21312_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21316_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21327_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21329_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21331_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21333_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21335_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21342_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21343_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21344_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21364_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21365_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21366_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21375_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21376_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21377_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21398_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21399_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21400_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21421_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21422_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21423_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21433_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21434_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14655_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21480_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21481_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21505_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21518_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21520_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21533_.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21535_.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\J0115834.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\J0115835.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\J0115839.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\J0115840.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\J0115841.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\J0115843.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\J0115844.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\J0115863.GIF | Modified File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\J0115864.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\J0115865.GIF.jigsaaw | Dropped File | Image |
Unknown
|
...
|
»
C:\Program Files\Common Files\System\ado\HOW TO DECRYPT FILES.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.JPG | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.PNG | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00090_.GIF.jigsaaw | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00103_.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00130_.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00154_.GIF.jigsaaw | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00158_.GIF.jigsaaw | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00165_.GIF.jigsaaw | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00174_.GIF.jigsaaw | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00175_.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\CLIPART\PUB60COR\AG00176_.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\J0302827.JPG.jigsaaw | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\J0302953.JPG.jigsaaw | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\CAGCAT10\J0315447.JPG | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10255_.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10266_.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10336_.GIF.jigsaaw | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD10337_.GIF.jigsaaw | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14530_.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14533_.GIF.jigsaaw | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14565_.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14583_.GIF.jigsaaw | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14790_.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14791_.GIF.jigsaaw | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14794_.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14831_.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14833_.GIF.jigsaaw | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14868_.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14870_.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD14984_.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD15132_.GIF.jigsaaw | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD15136_.GIF.jigsaaw | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD15168_.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD15272_.GIF.jigsaaw | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21295_.GIF.jigsaaw | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21304_.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21308_.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21310_.GIF.jigsaaw | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21337_.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21482_.GIF.jigsaaw | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21503_.GIF.jigsaaw | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21504_.GIF.jigsaaw | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21519_.GIF.jigsaaw | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\BD21534_.GIF | Modified File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\J0115836.GIF.jigsaaw | Dropped File | Image |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\MEDIA\OFFICE14\BULLETS\J0115867.GIF.jigsaaw | Dropped File | Image |
Not Queried
|
...
|
»