VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Downloader, Trojan |
9DC6.tmp.exe
Windows Exe (x86-32)
Created at 2019-08-24T06:31:00
Remarks (2/3)
(0x200000e): The overall sleep time of all monitored processes was truncated from "40 seconds" to "10 seconds" to reveal dormant functionality.
(0x200003a): 2 tasks were rescheduled ahead of time to reveal dormant functionality.
Remarks
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9DC6.tmp.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-08-23 06:20 (UTC+2) |
Last Seen | 2019-08-24 07:38 (UTC+2) |
Names | Win32.Trojan.Kryptik |
Families | Kryptik |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x405d34 |
Size Of Code | 0x1a000 |
Size Of Initialized Data | 0x4a64e00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-10-26 10:49:16+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x19f10 | 0x1a000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.65 |
.rdata | 0x41b000 | 0x92e6 | 0x9400 | 0x1a400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.8 |
.data | 0x425000 | 0x4a56568 | 0x48800 | 0x23800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.03 |
.rsrc | 0x4e7c000 | 0x4438 | 0x4600 | 0x6c000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.84 |
.reloc | 0x4e81000 | 0x1b88 | 0x1c00 | 0x70600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.53 |
Imports (3)
»
KERNEL32.dll (149)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
IsBadReadPtr | 0x0 | 0x41b050 | 0x232cc | 0x226cc | 0x2f7 |
GetPrivateProfileStringW | 0x0 | 0x41b054 | 0x232d0 | 0x226d0 | 0x242 |
FormatMessageA | 0x0 | 0x41b058 | 0x232d4 | 0x226d4 | 0x15d |
SetFileTime | 0x0 | 0x41b05c | 0x232d8 | 0x226d8 | 0x46a |
GetConsoleAliasExesW | 0x0 | 0x41b060 | 0x232dc | 0x226dc | 0x194 |
EnumTimeFormatsW | 0x0 | 0x41b064 | 0x232e0 | 0x226e0 | 0x112 |
GetCommandLineA | 0x0 | 0x41b068 | 0x232e4 | 0x226e4 | 0x186 |
GetDriveTypeA | 0x0 | 0x41b06c | 0x232e8 | 0x226e8 | 0x1d2 |
InitializeCriticalSection | 0x0 | 0x41b070 | 0x232ec | 0x226ec | 0x2e2 |
TlsSetValue | 0x0 | 0x41b074 | 0x232f0 | 0x226f0 | 0x4c8 |
GlobalAlloc | 0x0 | 0x41b078 | 0x232f4 | 0x226f4 | 0x2b3 |
IsValidLocale | 0x0 | 0x41b07c | 0x232f8 | 0x226f8 | 0x30c |
GetThreadSelectorEntry | 0x0 | 0x41b080 | 0x232fc | 0x226fc | 0x290 |
GetCalendarInfoW | 0x0 | 0x41b084 | 0x23300 | 0x22700 | 0x17b |
FormatMessageW | 0x0 | 0x41b088 | 0x23304 | 0x22704 | 0x15e |
GetSystemTimeAdjustment | 0x0 | 0x41b08c | 0x23308 | 0x22708 | 0x278 |
SetConsoleCP | 0x0 | 0x41b090 | 0x2330c | 0x2270c | 0x42c |
WritePrivateProfileStructW | 0x0 | 0x41b094 | 0x23310 | 0x22710 | 0x52d |
CreateSemaphoreA | 0x0 | 0x41b098 | 0x23314 | 0x22714 | 0xab |
GetFileAttributesW | 0x0 | 0x41b09c | 0x23318 | 0x22718 | 0x1ea |
SetMessageWaitingIndicator | 0x0 | 0x41b0a0 | 0x2331c | 0x2271c | 0x47a |
IsBadWritePtr | 0x0 | 0x41b0a4 | 0x23320 | 0x22720 | 0x2fa |
GetAtomNameW | 0x0 | 0x41b0a8 | 0x23324 | 0x22724 | 0x16e |
GetCompressedFileSizeA | 0x0 | 0x41b0ac | 0x23328 | 0x22728 | 0x188 |
GetTimeZoneInformation | 0x0 | 0x41b0b0 | 0x2332c | 0x2272c | 0x298 |
lstrlenW | 0x0 | 0x41b0b4 | 0x23330 | 0x22730 | 0x54e |
DisconnectNamedPipe | 0x0 | 0x41b0b8 | 0x23334 | 0x22734 | 0xe1 |
GetFileSizeEx | 0x0 | 0x41b0bc | 0x23338 | 0x22738 | 0x1f1 |
SetThreadLocale | 0x0 | 0x41b0c0 | 0x2333c | 0x2273c | 0x497 |
FindFirstFileA | 0x0 | 0x41b0c4 | 0x23340 | 0x22740 | 0x132 |
InterlockedFlushSList | 0x0 | 0x41b0c8 | 0x23344 | 0x22744 | 0x2ee |
GetCurrentDirectoryW | 0x0 | 0x41b0cc | 0x23348 | 0x22748 | 0x1bf |
BindIoCompletionCallback | 0x0 | 0x41b0d0 | 0x2334c | 0x2274c | 0x39 |
ReadConsoleOutputCharacterA | 0x0 | 0x41b0d4 | 0x23350 | 0x22750 | 0x3bb |
GetLongPathNameA | 0x0 | 0x41b0d8 | 0x23354 | 0x22754 | 0x20c |
HeapSize | 0x0 | 0x41b0dc | 0x23358 | 0x22758 | 0x2d4 |
DefineDosDeviceW | 0x0 | 0x41b0e0 | 0x2335c | 0x2275c | 0xcd |
GetCommConfig | 0x0 | 0x41b0e4 | 0x23360 | 0x22760 | 0x180 |
EnumSystemCodePagesW | 0x0 | 0x41b0e8 | 0x23364 | 0x22764 | 0x108 |
SetComputerNameA | 0x0 | 0x41b0ec | 0x23368 | 0x22768 | 0x427 |
SetTimerQueueTimer | 0x0 | 0x41b0f0 | 0x2336c | 0x2276c | 0x4a4 |
PrepareTape | 0x0 | 0x41b0f4 | 0x23370 | 0x22770 | 0x392 |
GetProcessVersion | 0x0 | 0x41b0f8 | 0x23374 | 0x22774 | 0x253 |
GetDiskFreeSpaceW | 0x0 | 0x41b0fc | 0x23378 | 0x22778 | 0x1cf |
LoadLibraryA | 0x0 | 0x41b100 | 0x2337c | 0x2277c | 0x33c |
OpenMutexA | 0x0 | 0x41b104 | 0x23380 | 0x22780 | 0x37c |
InterlockedExchangeAdd | 0x0 | 0x41b108 | 0x23384 | 0x22784 | 0x2ed |
LocalAlloc | 0x0 | 0x41b10c | 0x23388 | 0x22788 | 0x344 |
DeleteTimerQueue | 0x0 | 0x41b110 | 0x2338c | 0x2278c | 0xd8 |
GetExitCodeThread | 0x0 | 0x41b114 | 0x23390 | 0x22790 | 0x1e0 |
OpenEventA | 0x0 | 0x41b118 | 0x23394 | 0x22794 | 0x374 |
HeapLock | 0x0 | 0x41b11c | 0x23398 | 0x22798 | 0x2d0 |
AddAtomA | 0x0 | 0x41b120 | 0x2339c | 0x2279c | 0x3 |
GetThreadPriority | 0x0 | 0x41b124 | 0x233a0 | 0x227a0 | 0x28e |
CreateIoCompletionPort | 0x0 | 0x41b128 | 0x233a4 | 0x227a4 | 0x94 |
WaitCommEvent | 0x0 | 0x41b12c | 0x233a8 | 0x227a8 | 0x4f5 |
GetModuleHandleA | 0x0 | 0x41b130 | 0x233ac | 0x227ac | 0x215 |
UpdateResourceW | 0x0 | 0x41b134 | 0x233b0 | 0x227b0 | 0x4df |
FreeEnvironmentStringsW | 0x0 | 0x41b138 | 0x233b4 | 0x227b4 | 0x161 |
VirtualProtect | 0x0 | 0x41b13c | 0x233b8 | 0x227b8 | 0x4ef |
OpenEventW | 0x0 | 0x41b140 | 0x233bc | 0x227bc | 0x375 |
GetShortPathNameW | 0x0 | 0x41b144 | 0x233c0 | 0x227c0 | 0x261 |
DuplicateHandle | 0x0 | 0x41b148 | 0x233c4 | 0x227c4 | 0xe8 |
SetProcessShutdownParameters | 0x0 | 0x41b14c | 0x233c8 | 0x227c8 | 0x483 |
CloseHandle | 0x0 | 0x41b150 | 0x233cc | 0x227cc | 0x52 |
MoveFileWithProgressW | 0x0 | 0x41b154 | 0x233d0 | 0x227d0 | 0x365 |
GetFileInformationByHandle | 0x0 | 0x41b158 | 0x233d4 | 0x227d4 | 0x1ec |
AddConsoleAliasA | 0x0 | 0x41b15c | 0x233d8 | 0x227d8 | 0x5 |
FindNextVolumeA | 0x0 | 0x41b160 | 0x233dc | 0x227dc | 0x147 |
WriteProcessMemory | 0x0 | 0x41b164 | 0x233e0 | 0x227e0 | 0x52e |
lstrcpyW | 0x0 | 0x41b168 | 0x233e4 | 0x227e4 | 0x548 |
CreateFileW | 0x0 | 0x41b16c | 0x233e8 | 0x227e8 | 0x8f |
ReadConsoleW | 0x0 | 0x41b170 | 0x233ec | 0x227ec | 0x3be |
ReadFile | 0x0 | 0x41b174 | 0x233f0 | 0x227f0 | 0x3c0 |
OutputDebugStringW | 0x0 | 0x41b178 | 0x233f4 | 0x227f4 | 0x38a |
GetCommProperties | 0x0 | 0x41b17c | 0x233f8 | 0x227f8 | 0x183 |
GetSystemDefaultLCID | 0x0 | 0x41b180 | 0x233fc | 0x227fc | 0x26b |
SleepEx | 0x0 | 0x41b184 | 0x23400 | 0x22800 | 0x4b5 |
OpenSemaphoreA | 0x0 | 0x41b188 | 0x23404 | 0x22804 | 0x383 |
QueryDosDeviceA | 0x0 | 0x41b18c | 0x23408 | 0x22808 | 0x39f |
OpenJobObjectA | 0x0 | 0x41b190 | 0x2340c | 0x2280c | 0x37a |
InterlockedIncrement | 0x0 | 0x41b194 | 0x23410 | 0x22810 | 0x2ef |
WriteConsoleOutputCharacterA | 0x0 | 0x41b198 | 0x23414 | 0x22814 | 0x521 |
GetCPInfo | 0x0 | 0x41b19c | 0x23418 | 0x22818 | 0x172 |
TlsGetValue | 0x0 | 0x41b1a0 | 0x2341c | 0x2281c | 0x4c7 |
GetConsoleAliasesLengthW | 0x0 | 0x41b1a4 | 0x23420 | 0x22820 | 0x198 |
WritePrivateProfileStructA | 0x0 | 0x41b1a8 | 0x23424 | 0x22824 | 0x52c |
lstrlenA | 0x0 | 0x41b1ac | 0x23428 | 0x22828 | 0x54d |
GetCommModemStatus | 0x0 | 0x41b1b0 | 0x2342c | 0x2282c | 0x182 |
CreateTimerQueue | 0x0 | 0x41b1b4 | 0x23430 | 0x22830 | 0xbc |
GetFullPathNameA | 0x0 | 0x41b1b8 | 0x23434 | 0x22834 | 0x1f8 |
GetVolumeNameForVolumeMountPointA | 0x0 | 0x41b1bc | 0x23438 | 0x22838 | 0x2a8 |
GetFirmwareEnvironmentVariableW | 0x0 | 0x41b1c0 | 0x2343c | 0x2283c | 0x1f7 |
GetFullPathNameW | 0x0 | 0x41b1c4 | 0x23440 | 0x22840 | 0x1fb |
EncodePointer | 0x0 | 0x41b1c8 | 0x23444 | 0x22844 | 0xea |
DecodePointer | 0x0 | 0x41b1cc | 0x23448 | 0x22848 | 0xca |
EnterCriticalSection | 0x0 | 0x41b1d0 | 0x2344c | 0x2284c | 0xee |
LeaveCriticalSection | 0x0 | 0x41b1d4 | 0x23450 | 0x22850 | 0x339 |
DeleteCriticalSection | 0x0 | 0x41b1d8 | 0x23454 | 0x22854 | 0xd1 |
WideCharToMultiByte | 0x0 | 0x41b1dc | 0x23458 | 0x22858 | 0x511 |
MultiByteToWideChar | 0x0 | 0x41b1e0 | 0x2345c | 0x2285c | 0x367 |
GetStringTypeW | 0x0 | 0x41b1e4 | 0x23460 | 0x22860 | 0x269 |
GetLastError | 0x0 | 0x41b1e8 | 0x23464 | 0x22864 | 0x202 |
HeapFree | 0x0 | 0x41b1ec | 0x23468 | 0x22868 | 0x2cf |
RaiseException | 0x0 | 0x41b1f0 | 0x2346c | 0x2286c | 0x3b1 |
RtlUnwind | 0x0 | 0x41b1f4 | 0x23470 | 0x22870 | 0x418 |
HeapAlloc | 0x0 | 0x41b1f8 | 0x23474 | 0x22874 | 0x2cb |
IsProcessorFeaturePresent | 0x0 | 0x41b1fc | 0x23478 | 0x22878 | 0x304 |
UnhandledExceptionFilter | 0x0 | 0x41b200 | 0x2347c | 0x2287c | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x41b204 | 0x23480 | 0x22880 | 0x4a5 |
SetLastError | 0x0 | 0x41b208 | 0x23484 | 0x22884 | 0x473 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41b20c | 0x23488 | 0x22888 | 0x2e3 |
Sleep | 0x0 | 0x41b210 | 0x2348c | 0x2288c | 0x4b2 |
GetCurrentProcess | 0x0 | 0x41b214 | 0x23490 | 0x22890 | 0x1c0 |
TerminateProcess | 0x0 | 0x41b218 | 0x23494 | 0x22894 | 0x4c0 |
TlsAlloc | 0x0 | 0x41b21c | 0x23498 | 0x22898 | 0x4c5 |
TlsFree | 0x0 | 0x41b220 | 0x2349c | 0x2289c | 0x4c6 |
GetStartupInfoW | 0x0 | 0x41b224 | 0x234a0 | 0x228a0 | 0x263 |
GetModuleHandleW | 0x0 | 0x41b228 | 0x234a4 | 0x228a4 | 0x218 |
GetProcAddress | 0x0 | 0x41b22c | 0x234a8 | 0x228a8 | 0x245 |
LCMapStringW | 0x0 | 0x41b230 | 0x234ac | 0x228ac | 0x32d |
GetLocaleInfoW | 0x0 | 0x41b234 | 0x234b0 | 0x228b0 | 0x206 |
GetUserDefaultLCID | 0x0 | 0x41b238 | 0x234b4 | 0x228b4 | 0x29b |
EnumSystemLocalesW | 0x0 | 0x41b23c | 0x234b8 | 0x228b8 | 0x10f |
IsDebuggerPresent | 0x0 | 0x41b240 | 0x234bc | 0x228bc | 0x300 |
GetProcessHeap | 0x0 | 0x41b244 | 0x234c0 | 0x228c0 | 0x24a |
ExitProcess | 0x0 | 0x41b248 | 0x234c4 | 0x228c4 | 0x119 |
GetModuleHandleExW | 0x0 | 0x41b24c | 0x234c8 | 0x228c8 | 0x217 |
GetCurrentThreadId | 0x0 | 0x41b250 | 0x234cc | 0x228cc | 0x1c5 |
GetStdHandle | 0x0 | 0x41b254 | 0x234d0 | 0x228d0 | 0x264 |
GetFileType | 0x0 | 0x41b258 | 0x234d4 | 0x228d4 | 0x1f3 |
GetModuleFileNameA | 0x0 | 0x41b25c | 0x234d8 | 0x228d8 | 0x213 |
WriteFile | 0x0 | 0x41b260 | 0x234dc | 0x228dc | 0x525 |
GetModuleFileNameW | 0x0 | 0x41b264 | 0x234e0 | 0x228e0 | 0x214 |
QueryPerformanceCounter | 0x0 | 0x41b268 | 0x234e4 | 0x228e4 | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x41b26c | 0x234e8 | 0x228e8 | 0x1c1 |
GetSystemTimeAsFileTime | 0x0 | 0x41b270 | 0x234ec | 0x228ec | 0x279 |
GetEnvironmentStringsW | 0x0 | 0x41b274 | 0x234f0 | 0x228f0 | 0x1da |
GetACP | 0x0 | 0x41b278 | 0x234f4 | 0x228f4 | 0x168 |
IsValidCodePage | 0x0 | 0x41b27c | 0x234f8 | 0x228f8 | 0x30a |
GetOEMCP | 0x0 | 0x41b280 | 0x234fc | 0x228fc | 0x237 |
HeapReAlloc | 0x0 | 0x41b284 | 0x23500 | 0x22900 | 0x2d2 |
GetConsoleCP | 0x0 | 0x41b288 | 0x23504 | 0x22904 | 0x19a |
GetConsoleMode | 0x0 | 0x41b28c | 0x23508 | 0x22908 | 0x1ac |
SetFilePointerEx | 0x0 | 0x41b290 | 0x2350c | 0x2290c | 0x467 |
LoadLibraryExW | 0x0 | 0x41b294 | 0x23510 | 0x22910 | 0x33e |
SetStdHandle | 0x0 | 0x41b298 | 0x23514 | 0x22914 | 0x487 |
WriteConsoleW | 0x0 | 0x41b29c | 0x23518 | 0x22918 | 0x524 |
FlushFileBuffers | 0x0 | 0x41b2a0 | 0x2351c | 0x2291c | 0x157 |
USER32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetMonitorInfoA | 0x0 | 0x41b2a8 | 0x23524 | 0x22924 | 0x15e |
GetMonitorInfoW | 0x0 | 0x41b2ac | 0x23528 | 0x22928 | 0x15f |
GetMenuItemInfoA | 0x0 | 0x41b2b0 | 0x2352c | 0x2292c | 0x153 |
ADVAPI32.dll (19)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
QueryServiceConfigW | 0x0 | 0x41b000 | 0x2327c | 0x2267c | 0x224 |
ConvertToAutoInheritPrivateObjectSecurity | 0x0 | 0x41b004 | 0x23280 | 0x22680 | 0x75 |
RegisterServiceCtrlHandlerW | 0x0 | 0x41b008 | 0x23284 | 0x22684 | 0x288 |
GetUserNameA | 0x0 | 0x41b00c | 0x23288 | 0x22688 | 0x164 |
GetSidLengthRequired | 0x0 | 0x41b010 | 0x2328c | 0x2268c | 0x156 |
RegOpenKeyExW | 0x0 | 0x41b014 | 0x23290 | 0x22690 | 0x261 |
RegConnectRegistryW | 0x0 | 0x41b018 | 0x23294 | 0x22694 | 0x234 |
CreatePrivateObjectSecurity | 0x0 | 0x41b01c | 0x23298 | 0x22698 | 0x78 |
NotifyChangeEventLog | 0x0 | 0x41b020 | 0x2329c | 0x2269c | 0x1e5 |
RegSaveKeyW | 0x0 | 0x41b024 | 0x232a0 | 0x226a0 | 0x278 |
ObjectDeleteAuditAlarmW | 0x0 | 0x41b028 | 0x232a4 | 0x226a4 | 0x1ec |
CreateServiceA | 0x0 | 0x41b02c | 0x232a8 | 0x226a8 | 0x80 |
RegQueryValueExA | 0x0 | 0x41b030 | 0x232ac | 0x226ac | 0x26d |
AccessCheckByTypeResultListAndAuditAlarmA | 0x0 | 0x41b034 | 0x232b0 | 0x226b0 | 0xc |
RegRestoreKeyA | 0x0 | 0x41b038 | 0x232b4 | 0x226b4 | 0x273 |
EnumServicesStatusA | 0x0 | 0x41b03c | 0x232b8 | 0x226b8 | 0xff |
SetSecurityDescriptorGroup | 0x0 | 0x41b040 | 0x232bc | 0x226bc | 0x2b7 |
SetSecurityDescriptorControl | 0x0 | 0x41b044 | 0x232c0 | 0x226c0 | 0x2b5 |
InitiateSystemShutdownW | 0x0 | 0x41b048 | 0x232c4 | 0x226c4 | 0x17e |
Memory Dumps (7)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
buffer | 1 | 0x002B9190 | 0x002FE347 | Marked Executable | - | 32-bit | 0x002B9EAA |
![]() |
![]() |
...
|
buffer | 1 | 0x065F0000 | 0x0664FFFF | First Execution | - | 32-bit | 0x065F0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x065F0000 | 0x0664FFFF | Content Changed | - | 32-bit | 0x065F04F6 |
![]() |
![]() |
...
|
buffer | 5 | 0x050491A8 | 0x0508E35F | Marked Executable | - | 32-bit | 0x05049EC2 |
![]() |
![]() |
...
|
buffer | 5 | 0x00270000 | 0x002CFFFF | First Execution | - | 32-bit | 0x00270000 |
![]() |
![]() |
...
|
buffer | 16 | 0x050695D8 | 0x050AE78F | Marked Executable | - | 32-bit | 0x0506A2F2 |
![]() |
![]() |
...
|
buffer | 16 | 0x00220000 | 0x0027FFFF | First Execution | - | 32-bit | 0x00220000 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.41625647 |
Malicious
|
C:\Windows\System32\drivers\etc\hosts | Modified File | Text |
Malicious
|
...
|
»
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Trojan.Qhost.1 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\0NTmu.pdf | Modified File |
Malicious
|
...
|
»
YARA Matches (3)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
4/5
|
...
|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\_0VDVX.pdf | Modified File |
Malicious
|
...
|
»
YARA Matches (3)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
4/5
|
...
|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\m8Ml-6lNM1 wULCS0yD\-88UgF-e_va- z.pdf.carote | Dropped File |
Malicious
|
...
|
»
YARA Matches (3)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
4/5
|
...
|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\f_-8oBARRP9-U\bFT9ci 8fZ3bljOH\AL1uDyzyXe3_.pdf.carote | Dropped File |
Malicious
|
...
|
»
YARA Matches (3)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
4/5
|
...
|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\SmG7\LFwoVJrFDf\Zvgl_GVfIYN2KR.pdf.carote | Dropped File |
Malicious
|
...
|
»
YARA Matches (3)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
4/5
|
...
|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\2d5ee28a-f782-4cc1-aa85-b49f8f019ddd\updatewin1.exe | Downloaded File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-01-16 22:21 (UTC+1) |
Last Seen | 2019-07-21 22:40 (UTC+2) |
Names | Win32.Trojan.Kryptik |
Families | Kryptik |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x402d76 |
Size Of Code | 0x1c200 |
Size Of Initialized Data | 0x2c200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-07-24 12:23:54+00:00 |
Version Information (3)
»
FileVersion | 7.7.7.18 |
InternalName | rawudiyeh.exe |
LegalCopyright | Copyright (C) 2018, sacuwedimufoy |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1c07e | 0x1c200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x41e000 | 0x463e | 0x4800 | 0x1c600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.26 |
.data | 0x423000 | 0x1c6a8 | 0x17400 | 0x20e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.83 |
.rsrc | 0x440000 | 0xa578 | 0xa600 | 0x38200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.88 |
.reloc | 0x44b000 | 0x1968 | 0x1a00 | 0x42800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.34 |
Imports (4)
»
KERNEL32.dll (102)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitThread | 0x0 | 0x41e028 | 0x21afc | 0x200fc | 0x105 |
GetStartupInfoW | 0x0 | 0x41e02c | 0x21b00 | 0x20100 | 0x23a |
GetLastError | 0x0 | 0x41e030 | 0x21b04 | 0x20104 | 0x1e6 |
GetProcAddress | 0x0 | 0x41e034 | 0x21b08 | 0x20108 | 0x220 |
CreateJobSet | 0x0 | 0x41e038 | 0x21b0c | 0x2010c | 0x87 |
GlobalFree | 0x0 | 0x41e03c | 0x21b10 | 0x20110 | 0x28c |
LoadLibraryA | 0x0 | 0x41e040 | 0x21b14 | 0x20114 | 0x2f1 |
OpenWaitableTimerW | 0x0 | 0x41e044 | 0x21b18 | 0x20118 | 0x339 |
AddAtomA | 0x0 | 0x41e048 | 0x21b1c | 0x2011c | 0x3 |
FindFirstChangeNotificationA | 0x0 | 0x41e04c | 0x21b20 | 0x20120 | 0x11b |
VirtualProtect | 0x0 | 0x41e050 | 0x21b24 | 0x20124 | 0x45a |
GetCurrentDirectoryA | 0x0 | 0x41e054 | 0x21b28 | 0x20128 | 0x1a7 |
GetACP | 0x0 | 0x41e058 | 0x21b2c | 0x2012c | 0x152 |
InterlockedPushEntrySList | 0x0 | 0x41e05c | 0x21b30 | 0x20130 | 0x2c2 |
CompareStringW | 0x0 | 0x41e060 | 0x21b34 | 0x20134 | 0x55 |
CompareStringA | 0x0 | 0x41e064 | 0x21b38 | 0x20138 | 0x52 |
CreateFileA | 0x0 | 0x41e068 | 0x21b3c | 0x2013c | 0x78 |
GetTimeZoneInformation | 0x0 | 0x41e06c | 0x21b40 | 0x20140 | 0x26b |
WriteConsoleW | 0x0 | 0x41e070 | 0x21b44 | 0x20144 | 0x48c |
GetConsoleOutputCP | 0x0 | 0x41e074 | 0x21b48 | 0x20148 | 0x199 |
WriteConsoleA | 0x0 | 0x41e078 | 0x21b4c | 0x2014c | 0x482 |
CloseHandle | 0x0 | 0x41e07c | 0x21b50 | 0x20150 | 0x43 |
IsValidLocale | 0x0 | 0x41e080 | 0x21b54 | 0x20154 | 0x2dd |
EnumSystemLocalesA | 0x0 | 0x41e084 | 0x21b58 | 0x20158 | 0xf8 |
GetUserDefaultLCID | 0x0 | 0x41e088 | 0x21b5c | 0x2015c | 0x26d |
GetSystemTimeAdjustment | 0x0 | 0x41e08c | 0x21b60 | 0x20160 | 0x24e |
GetSystemTimes | 0x0 | 0x41e090 | 0x21b64 | 0x20164 | 0x250 |
GetTickCount | 0x0 | 0x41e094 | 0x21b68 | 0x20168 | 0x266 |
FreeEnvironmentStringsA | 0x0 | 0x41e098 | 0x21b6c | 0x2016c | 0x14a |
GetComputerNameW | 0x0 | 0x41e09c | 0x21b70 | 0x20170 | 0x178 |
FindCloseChangeNotification | 0x0 | 0x41e0a0 | 0x21b74 | 0x20174 | 0x11a |
FindResourceExW | 0x0 | 0x41e0a4 | 0x21b78 | 0x20178 | 0x138 |
GetCPInfo | 0x0 | 0x41e0a8 | 0x21b7c | 0x2017c | 0x15b |
SetProcessShutdownParameters | 0x0 | 0x41e0ac | 0x21b80 | 0x20180 | 0x3f9 |
GetModuleHandleExA | 0x0 | 0x41e0b0 | 0x21b84 | 0x20184 | 0x1f7 |
GetDateFormatA | 0x0 | 0x41e0b4 | 0x21b88 | 0x20188 | 0x1ae |
GetTimeFormatA | 0x0 | 0x41e0b8 | 0x21b8c | 0x2018c | 0x268 |
GetStringTypeW | 0x0 | 0x41e0bc | 0x21b90 | 0x20190 | 0x240 |
GetStringTypeA | 0x0 | 0x41e0c0 | 0x21b94 | 0x20194 | 0x23d |
LCMapStringW | 0x0 | 0x41e0c4 | 0x21b98 | 0x20198 | 0x2e3 |
GetCommandLineA | 0x0 | 0x41e0c8 | 0x21b9c | 0x2019c | 0x16f |
GetStartupInfoA | 0x0 | 0x41e0cc | 0x21ba0 | 0x201a0 | 0x239 |
RaiseException | 0x0 | 0x41e0d0 | 0x21ba4 | 0x201a4 | 0x35a |
RtlUnwind | 0x0 | 0x41e0d4 | 0x21ba8 | 0x201a8 | 0x392 |
TerminateProcess | 0x0 | 0x41e0d8 | 0x21bac | 0x201ac | 0x42d |
GetCurrentProcess | 0x0 | 0x41e0dc | 0x21bb0 | 0x201b0 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x41e0e0 | 0x21bb4 | 0x201b4 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x41e0e4 | 0x21bb8 | 0x201b8 | 0x415 |
IsDebuggerPresent | 0x0 | 0x41e0e8 | 0x21bbc | 0x201bc | 0x2d1 |
HeapAlloc | 0x0 | 0x41e0ec | 0x21bc0 | 0x201c0 | 0x29d |
HeapFree | 0x0 | 0x41e0f0 | 0x21bc4 | 0x201c4 | 0x2a1 |
EnterCriticalSection | 0x0 | 0x41e0f4 | 0x21bc8 | 0x201c8 | 0xd9 |
LeaveCriticalSection | 0x0 | 0x41e0f8 | 0x21bcc | 0x201cc | 0x2ef |
SetHandleCount | 0x0 | 0x41e0fc | 0x21bd0 | 0x201d0 | 0x3e8 |
GetStdHandle | 0x0 | 0x41e100 | 0x21bd4 | 0x201d4 | 0x23b |
GetFileType | 0x0 | 0x41e104 | 0x21bd8 | 0x201d8 | 0x1d7 |
DeleteCriticalSection | 0x0 | 0x41e108 | 0x21bdc | 0x201dc | 0xbe |
GetModuleHandleW | 0x0 | 0x41e10c | 0x21be0 | 0x201e0 | 0x1f9 |
Sleep | 0x0 | 0x41e110 | 0x21be4 | 0x201e4 | 0x421 |
ExitProcess | 0x0 | 0x41e114 | 0x21be8 | 0x201e8 | 0x104 |
WriteFile | 0x0 | 0x41e118 | 0x21bec | 0x201ec | 0x48d |
GetModuleFileNameA | 0x0 | 0x41e11c | 0x21bf0 | 0x201f0 | 0x1f4 |
GetEnvironmentStrings | 0x0 | 0x41e120 | 0x21bf4 | 0x201f4 | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x41e124 | 0x21bf8 | 0x201f8 | 0x14b |
WideCharToMultiByte | 0x0 | 0x41e128 | 0x21bfc | 0x201fc | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x41e12c | 0x21c00 | 0x20200 | 0x1c1 |
TlsGetValue | 0x0 | 0x41e130 | 0x21c04 | 0x20204 | 0x434 |
TlsAlloc | 0x0 | 0x41e134 | 0x21c08 | 0x20208 | 0x432 |
TlsSetValue | 0x0 | 0x41e138 | 0x21c0c | 0x2020c | 0x435 |
TlsFree | 0x0 | 0x41e13c | 0x21c10 | 0x20210 | 0x433 |
InterlockedIncrement | 0x0 | 0x41e140 | 0x21c14 | 0x20214 | 0x2c0 |
SetLastError | 0x0 | 0x41e144 | 0x21c18 | 0x20218 | 0x3ec |
GetCurrentThreadId | 0x0 | 0x41e148 | 0x21c1c | 0x2021c | 0x1ad |
InterlockedDecrement | 0x0 | 0x41e14c | 0x21c20 | 0x20220 | 0x2bc |
GetCurrentThread | 0x0 | 0x41e150 | 0x21c24 | 0x20224 | 0x1ac |
HeapCreate | 0x0 | 0x41e154 | 0x21c28 | 0x20228 | 0x29f |
HeapDestroy | 0x0 | 0x41e158 | 0x21c2c | 0x2022c | 0x2a0 |
VirtualFree | 0x0 | 0x41e15c | 0x21c30 | 0x20230 | 0x457 |
QueryPerformanceCounter | 0x0 | 0x41e160 | 0x21c34 | 0x20234 | 0x354 |
GetCurrentProcessId | 0x0 | 0x41e164 | 0x21c38 | 0x20238 | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x41e168 | 0x21c3c | 0x2023c | 0x24f |
FatalAppExitA | 0x0 | 0x41e16c | 0x21c40 | 0x20240 | 0x10b |
VirtualAlloc | 0x0 | 0x41e170 | 0x21c44 | 0x20244 | 0x454 |
HeapReAlloc | 0x0 | 0x41e174 | 0x21c48 | 0x20248 | 0x2a4 |
MultiByteToWideChar | 0x0 | 0x41e178 | 0x21c4c | 0x2024c | 0x31a |
ReadFile | 0x0 | 0x41e17c | 0x21c50 | 0x20250 | 0x368 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41e180 | 0x21c54 | 0x20254 | 0x2b5 |
HeapSize | 0x0 | 0x41e184 | 0x21c58 | 0x20258 | 0x2a6 |
SetConsoleCtrlHandler | 0x0 | 0x41e188 | 0x21c5c | 0x2025c | 0x3a7 |
FreeLibrary | 0x0 | 0x41e18c | 0x21c60 | 0x20260 | 0x14c |
InterlockedExchange | 0x0 | 0x41e190 | 0x21c64 | 0x20264 | 0x2bd |
GetOEMCP | 0x0 | 0x41e194 | 0x21c68 | 0x20268 | 0x213 |
IsValidCodePage | 0x0 | 0x41e198 | 0x21c6c | 0x2026c | 0x2db |
GetConsoleCP | 0x0 | 0x41e19c | 0x21c70 | 0x20270 | 0x183 |
GetConsoleMode | 0x0 | 0x41e1a0 | 0x21c74 | 0x20274 | 0x195 |
FlushFileBuffers | 0x0 | 0x41e1a4 | 0x21c78 | 0x20278 | 0x141 |
SetFilePointer | 0x0 | 0x41e1a8 | 0x21c7c | 0x2027c | 0x3df |
SetStdHandle | 0x0 | 0x41e1ac | 0x21c80 | 0x20280 | 0x3fc |
GetLocaleInfoW | 0x0 | 0x41e1b0 | 0x21c84 | 0x20284 | 0x1ea |
GetLocaleInfoA | 0x0 | 0x41e1b4 | 0x21c88 | 0x20288 | 0x1e8 |
LCMapStringA | 0x0 | 0x41e1b8 | 0x21c8c | 0x2028c | 0x2e1 |
SetEnvironmentVariableA | 0x0 | 0x41e1bc | 0x21c90 | 0x20290 | 0x3d0 |
USER32.dll (10)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseClipboard | 0x0 | 0x41e1d8 | 0x21cac | 0x202ac | 0x47 |
BeginPaint | 0x0 | 0x41e1dc | 0x21cb0 | 0x202b0 | 0xe |
CallMsgFilterW | 0x0 | 0x41e1e0 | 0x21cb4 | 0x202b4 | 0x1a |
PeekMessageA | 0x0 | 0x41e1e4 | 0x21cb8 | 0x202b8 | 0x21b |
MapVirtualKeyExW | 0x0 | 0x41e1e8 | 0x21cbc | 0x202bc | 0x1f1 |
RegisterRawInputDevices | 0x0 | 0x41e1ec | 0x21cc0 | 0x202c0 | 0x242 |
GetClipboardSequenceNumber | 0x0 | 0x41e1f0 | 0x21cc4 | 0x202c4 | 0x113 |
CountClipboardFormats | 0x0 | 0x41e1f4 | 0x21cc8 | 0x202c8 | 0x50 |
GetDialogBaseUnits | 0x0 | 0x41e1f8 | 0x21ccc | 0x202cc | 0x11d |
GetClassLongW | 0x0 | 0x41e1fc | 0x21cd0 | 0x202d0 | 0x109 |
GDI32.dll (9)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PolyTextOutW | 0x0 | 0x41e000 | 0x21ad4 | 0x200d4 | 0x23c |
CreateCompatibleDC | 0x0 | 0x41e004 | 0x21ad8 | 0x200d8 | 0x2e |
Rectangle | 0x0 | 0x41e008 | 0x21adc | 0x200dc | 0x246 |
SetStretchBltMode | 0x0 | 0x41e00c | 0x21ae0 | 0x200e0 | 0x289 |
SetPixelV | 0x0 | 0x41e010 | 0x21ae4 | 0x200e4 | 0x284 |
GetClipBox | 0x0 | 0x41e014 | 0x21ae8 | 0x200e8 | 0x1aa |
CreateDiscardableBitmap | 0x0 | 0x41e018 | 0x21aec | 0x200ec | 0x35 |
StrokeAndFillPath | 0x0 | 0x41e01c | 0x21af0 | 0x200f0 | 0x29c |
GetBitmapBits | 0x0 | 0x41e020 | 0x21af4 | 0x200f4 | 0x191 |
SHELL32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x41e1c4 | 0x21c98 | 0x20298 | 0x118 |
ShellAboutW | 0x0 | 0x41e1c8 | 0x21c9c | 0x2029c | 0x110 |
DuplicateIcon | 0x0 | 0x41e1cc | 0x21ca0 | 0x202a0 | 0x23 |
DragQueryFileA | 0x0 | 0x41e1d0 | 0x21ca4 | 0x202a4 | 0x1e |
Memory Dumps (9)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
updatewin1.exe | 6 | 0x00400000 | 0x0044CFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
updatewin1.exe | 6 | 0x00400000 | 0x0044CFFF | Content Changed | - | 32-bit | 0x004023F7 |
![]() |
![]() |
...
|
updatewin1.exe | 6 | 0x00400000 | 0x0044CFFF | Content Changed | - | 32-bit | 0x0040DB13 |
![]() |
![]() |
...
|
updatewin1.exe | 6 | 0x00400000 | 0x0044CFFF | Content Changed | - | 32-bit | 0x00401810 |
![]() |
![]() |
...
|
updatewin1.exe | 6 | 0x00400000 | 0x0044CFFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
updatewin1.exe | 7 | 0x00400000 | 0x0044CFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
updatewin1.exe | 7 | 0x00400000 | 0x0044CFFF | Content Changed | - | 32-bit | 0x004023F7 |
![]() |
![]() |
...
|
updatewin1.exe | 7 | 0x00400000 | 0x0044CFFF | Content Changed | - | 32-bit | 0x0040DB13 |
![]() |
![]() |
...
|
updatewin1.exe | 7 | 0x00400000 | 0x0044CFFF | Content Changed | - | 32-bit | 0x00401810 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.31534187 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\2d5ee28a-f782-4cc1-aa85-b49f8f019ddd\updatewin2.exe | Downloaded File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-01-16 22:21 (UTC+1) |
Last Seen | 2019-08-19 12:33 (UTC+2) |
Names | Win32.Trojan.Qhost |
Families | Qhost |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x402d64 |
Size Of Code | 0x1c200 |
Size Of Initialized Data | 0x2c800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-11-21 06:08:45+00:00 |
Version Information (3)
»
FileVersion | 5.3.7.82 |
InternalName | gigifaw.exe |
LegalCopyright | Copyright (C) 2018, guvaxiz |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1c03e | 0x1c200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x41e000 | 0x45ec | 0x4600 | 0x1c600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.34 |
.data | 0x423000 | 0x1cde8 | 0x17c00 | 0x20c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.8 |
.rsrc | 0x440000 | 0xa724 | 0xa800 | 0x38800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.88 |
.reloc | 0x44b000 | 0x195c | 0x1a00 | 0x43000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.33 |
Imports (4)
»
KERNEL32.dll (98)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitThread | 0x0 | 0x41e024 | 0x21ae8 | 0x200e8 | 0x105 |
GetStartupInfoW | 0x0 | 0x41e028 | 0x21aec | 0x200ec | 0x23a |
GetLastError | 0x0 | 0x41e02c | 0x21af0 | 0x200f0 | 0x1e6 |
GetProcAddress | 0x0 | 0x41e030 | 0x21af4 | 0x200f4 | 0x220 |
GlobalFree | 0x0 | 0x41e034 | 0x21af8 | 0x200f8 | 0x28c |
LoadLibraryA | 0x0 | 0x41e038 | 0x21afc | 0x200fc | 0x2f1 |
AddAtomA | 0x0 | 0x41e03c | 0x21b00 | 0x20100 | 0x3 |
FindFirstChangeNotificationA | 0x0 | 0x41e040 | 0x21b04 | 0x20104 | 0x11b |
VirtualProtect | 0x0 | 0x41e044 | 0x21b08 | 0x20108 | 0x45a |
GetCurrentDirectoryA | 0x0 | 0x41e048 | 0x21b0c | 0x2010c | 0x1a7 |
SetProcessShutdownParameters | 0x0 | 0x41e04c | 0x21b10 | 0x20110 | 0x3f9 |
GetACP | 0x0 | 0x41e050 | 0x21b14 | 0x20114 | 0x152 |
CompareStringA | 0x0 | 0x41e054 | 0x21b18 | 0x20118 | 0x52 |
CreateFileA | 0x0 | 0x41e058 | 0x21b1c | 0x2011c | 0x78 |
GetTimeZoneInformation | 0x0 | 0x41e05c | 0x21b20 | 0x20120 | 0x26b |
WriteConsoleW | 0x0 | 0x41e060 | 0x21b24 | 0x20124 | 0x48c |
GetConsoleOutputCP | 0x0 | 0x41e064 | 0x21b28 | 0x20128 | 0x199 |
WriteConsoleA | 0x0 | 0x41e068 | 0x21b2c | 0x2012c | 0x482 |
CloseHandle | 0x0 | 0x41e06c | 0x21b30 | 0x20130 | 0x43 |
IsValidLocale | 0x0 | 0x41e070 | 0x21b34 | 0x20134 | 0x2dd |
EnumSystemLocalesA | 0x0 | 0x41e074 | 0x21b38 | 0x20138 | 0xf8 |
GetUserDefaultLCID | 0x0 | 0x41e078 | 0x21b3c | 0x2013c | 0x26d |
GetDateFormatA | 0x0 | 0x41e07c | 0x21b40 | 0x20140 | 0x1ae |
GetTimeFormatA | 0x0 | 0x41e080 | 0x21b44 | 0x20144 | 0x268 |
InitAtomTable | 0x0 | 0x41e084 | 0x21b48 | 0x20148 | 0x2ae |
GetSystemTimes | 0x0 | 0x41e088 | 0x21b4c | 0x2014c | 0x250 |
GetTickCount | 0x0 | 0x41e08c | 0x21b50 | 0x20150 | 0x266 |
FreeEnvironmentStringsA | 0x0 | 0x41e090 | 0x21b54 | 0x20154 | 0x14a |
GetComputerNameW | 0x0 | 0x41e094 | 0x21b58 | 0x20158 | 0x178 |
FindCloseChangeNotification | 0x0 | 0x41e098 | 0x21b5c | 0x2015c | 0x11a |
FindResourceExW | 0x0 | 0x41e09c | 0x21b60 | 0x20160 | 0x138 |
CompareStringW | 0x0 | 0x41e0a0 | 0x21b64 | 0x20164 | 0x55 |
GetCPInfo | 0x0 | 0x41e0a4 | 0x21b68 | 0x20168 | 0x15b |
GetStringTypeW | 0x0 | 0x41e0a8 | 0x21b6c | 0x2016c | 0x240 |
GetStringTypeA | 0x0 | 0x41e0ac | 0x21b70 | 0x20170 | 0x23d |
LCMapStringW | 0x0 | 0x41e0b0 | 0x21b74 | 0x20174 | 0x2e3 |
LCMapStringA | 0x0 | 0x41e0b4 | 0x21b78 | 0x20178 | 0x2e1 |
GetLocaleInfoA | 0x0 | 0x41e0b8 | 0x21b7c | 0x2017c | 0x1e8 |
GetCommandLineA | 0x0 | 0x41e0bc | 0x21b80 | 0x20180 | 0x16f |
GetStartupInfoA | 0x0 | 0x41e0c0 | 0x21b84 | 0x20184 | 0x239 |
RaiseException | 0x0 | 0x41e0c4 | 0x21b88 | 0x20188 | 0x35a |
RtlUnwind | 0x0 | 0x41e0c8 | 0x21b8c | 0x2018c | 0x392 |
TerminateProcess | 0x0 | 0x41e0cc | 0x21b90 | 0x20190 | 0x42d |
GetCurrentProcess | 0x0 | 0x41e0d0 | 0x21b94 | 0x20194 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x41e0d4 | 0x21b98 | 0x20198 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x41e0d8 | 0x21b9c | 0x2019c | 0x415 |
IsDebuggerPresent | 0x0 | 0x41e0dc | 0x21ba0 | 0x201a0 | 0x2d1 |
HeapAlloc | 0x0 | 0x41e0e0 | 0x21ba4 | 0x201a4 | 0x29d |
HeapFree | 0x0 | 0x41e0e4 | 0x21ba8 | 0x201a8 | 0x2a1 |
EnterCriticalSection | 0x0 | 0x41e0e8 | 0x21bac | 0x201ac | 0xd9 |
LeaveCriticalSection | 0x0 | 0x41e0ec | 0x21bb0 | 0x201b0 | 0x2ef |
SetHandleCount | 0x0 | 0x41e0f0 | 0x21bb4 | 0x201b4 | 0x3e8 |
GetStdHandle | 0x0 | 0x41e0f4 | 0x21bb8 | 0x201b8 | 0x23b |
GetFileType | 0x0 | 0x41e0f8 | 0x21bbc | 0x201bc | 0x1d7 |
DeleteCriticalSection | 0x0 | 0x41e0fc | 0x21bc0 | 0x201c0 | 0xbe |
GetModuleHandleW | 0x0 | 0x41e100 | 0x21bc4 | 0x201c4 | 0x1f9 |
Sleep | 0x0 | 0x41e104 | 0x21bc8 | 0x201c8 | 0x421 |
ExitProcess | 0x0 | 0x41e108 | 0x21bcc | 0x201cc | 0x104 |
WriteFile | 0x0 | 0x41e10c | 0x21bd0 | 0x201d0 | 0x48d |
GetModuleFileNameA | 0x0 | 0x41e110 | 0x21bd4 | 0x201d4 | 0x1f4 |
GetEnvironmentStrings | 0x0 | 0x41e114 | 0x21bd8 | 0x201d8 | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x41e118 | 0x21bdc | 0x201dc | 0x14b |
WideCharToMultiByte | 0x0 | 0x41e11c | 0x21be0 | 0x201e0 | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x41e120 | 0x21be4 | 0x201e4 | 0x1c1 |
TlsGetValue | 0x0 | 0x41e124 | 0x21be8 | 0x201e8 | 0x434 |
TlsAlloc | 0x0 | 0x41e128 | 0x21bec | 0x201ec | 0x432 |
TlsSetValue | 0x0 | 0x41e12c | 0x21bf0 | 0x201f0 | 0x435 |
TlsFree | 0x0 | 0x41e130 | 0x21bf4 | 0x201f4 | 0x433 |
InterlockedIncrement | 0x0 | 0x41e134 | 0x21bf8 | 0x201f8 | 0x2c0 |
SetLastError | 0x0 | 0x41e138 | 0x21bfc | 0x201fc | 0x3ec |
GetCurrentThreadId | 0x0 | 0x41e13c | 0x21c00 | 0x20200 | 0x1ad |
InterlockedDecrement | 0x0 | 0x41e140 | 0x21c04 | 0x20204 | 0x2bc |
GetCurrentThread | 0x0 | 0x41e144 | 0x21c08 | 0x20208 | 0x1ac |
HeapCreate | 0x0 | 0x41e148 | 0x21c0c | 0x2020c | 0x29f |
HeapDestroy | 0x0 | 0x41e14c | 0x21c10 | 0x20210 | 0x2a0 |
VirtualFree | 0x0 | 0x41e150 | 0x21c14 | 0x20214 | 0x457 |
QueryPerformanceCounter | 0x0 | 0x41e154 | 0x21c18 | 0x20218 | 0x354 |
GetCurrentProcessId | 0x0 | 0x41e158 | 0x21c1c | 0x2021c | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x41e15c | 0x21c20 | 0x20220 | 0x24f |
FatalAppExitA | 0x0 | 0x41e160 | 0x21c24 | 0x20224 | 0x10b |
VirtualAlloc | 0x0 | 0x41e164 | 0x21c28 | 0x20228 | 0x454 |
HeapReAlloc | 0x0 | 0x41e168 | 0x21c2c | 0x2022c | 0x2a4 |
MultiByteToWideChar | 0x0 | 0x41e16c | 0x21c30 | 0x20230 | 0x31a |
ReadFile | 0x0 | 0x41e170 | 0x21c34 | 0x20234 | 0x368 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41e174 | 0x21c38 | 0x20238 | 0x2b5 |
HeapSize | 0x0 | 0x41e178 | 0x21c3c | 0x2023c | 0x2a6 |
SetConsoleCtrlHandler | 0x0 | 0x41e17c | 0x21c40 | 0x20240 | 0x3a7 |
FreeLibrary | 0x0 | 0x41e180 | 0x21c44 | 0x20244 | 0x14c |
InterlockedExchange | 0x0 | 0x41e184 | 0x21c48 | 0x20248 | 0x2bd |
GetOEMCP | 0x0 | 0x41e188 | 0x21c4c | 0x2024c | 0x213 |
IsValidCodePage | 0x0 | 0x41e18c | 0x21c50 | 0x20250 | 0x2db |
GetConsoleCP | 0x0 | 0x41e190 | 0x21c54 | 0x20254 | 0x183 |
GetConsoleMode | 0x0 | 0x41e194 | 0x21c58 | 0x20258 | 0x195 |
FlushFileBuffers | 0x0 | 0x41e198 | 0x21c5c | 0x2025c | 0x141 |
SetFilePointer | 0x0 | 0x41e19c | 0x21c60 | 0x20260 | 0x3df |
SetStdHandle | 0x0 | 0x41e1a0 | 0x21c64 | 0x20264 | 0x3fc |
GetLocaleInfoW | 0x0 | 0x41e1a4 | 0x21c68 | 0x20268 | 0x1ea |
SetEnvironmentVariableA | 0x0 | 0x41e1a8 | 0x21c6c | 0x2026c | 0x3d0 |
USER32.dll (12)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseClipboard | 0x0 | 0x41e1c4 | 0x21c88 | 0x20288 | 0x47 |
GetSubMenu | 0x0 | 0x41e1c8 | 0x21c8c | 0x2028c | 0x16b |
LoadBitmapA | 0x0 | 0x41e1cc | 0x21c90 | 0x20290 | 0x1d0 |
BeginPaint | 0x0 | 0x41e1d0 | 0x21c94 | 0x20294 | 0xe |
CallMsgFilterW | 0x0 | 0x41e1d4 | 0x21c98 | 0x20298 | 0x1a |
PeekMessageA | 0x0 | 0x41e1d8 | 0x21c9c | 0x2029c | 0x21b |
MapVirtualKeyExW | 0x0 | 0x41e1dc | 0x21ca0 | 0x202a0 | 0x1f1 |
RegisterRawInputDevices | 0x0 | 0x41e1e0 | 0x21ca4 | 0x202a4 | 0x242 |
SetWindowsHookExW | 0x0 | 0x41e1e4 | 0x21ca8 | 0x202a8 | 0x2b0 |
GetClipboardSequenceNumber | 0x0 | 0x41e1e8 | 0x21cac | 0x202ac | 0x113 |
GetDialogBaseUnits | 0x0 | 0x41e1ec | 0x21cb0 | 0x202b0 | 0x11d |
MessageBoxIndirectA | 0x0 | 0x41e1f0 | 0x21cb4 | 0x202b4 | 0x1fb |
GDI32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateCompatibleDC | 0x0 | 0x41e000 | 0x21ac4 | 0x200c4 | 0x2e |
PlayEnhMetaFile | 0x0 | 0x41e004 | 0x21ac8 | 0x200c8 | 0x230 |
ScaleViewportExtEx | 0x0 | 0x41e008 | 0x21acc | 0x200cc | 0x258 |
SetStretchBltMode | 0x0 | 0x41e00c | 0x21ad0 | 0x200d0 | 0x289 |
SetPixelV | 0x0 | 0x41e010 | 0x21ad4 | 0x200d4 | 0x284 |
CreateDiscardableBitmap | 0x0 | 0x41e014 | 0x21ad8 | 0x200d8 | 0x35 |
AddFontResourceW | 0x0 | 0x41e018 | 0x21adc | 0x200dc | 0x7 |
SetDeviceGammaRamp | 0x0 | 0x41e01c | 0x21ae0 | 0x200e0 | 0x271 |
SHELL32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExtractAssociatedIconA | 0x0 | 0x41e1b0 | 0x21c74 | 0x20274 | 0x24 |
ShellExecuteW | 0x0 | 0x41e1b4 | 0x21c78 | 0x20278 | 0x118 |
ShellAboutW | 0x0 | 0x41e1b8 | 0x21c7c | 0x2027c | 0x110 |
DragQueryFileA | 0x0 | 0x41e1bc | 0x21c80 | 0x20280 | 0x1e |
Memory Dumps (5)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
updatewin2.exe | 9 | 0x00400000 | 0x0044CFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
updatewin2.exe | 9 | 0x00400000 | 0x0044CFFF | Content Changed | - | 32-bit | 0x00402350 |
![]() |
![]() |
...
|
updatewin2.exe | 9 | 0x00400000 | 0x0044CFFF | Content Changed | - | 32-bit | 0x0040D7C3 |
![]() |
![]() |
...
|
updatewin2.exe | 9 | 0x00400000 | 0x0044CFFF | Content Changed | - | 32-bit | 0x00401730 |
![]() |
![]() |
...
|
updatewin2.exe | 9 | 0x00400000 | 0x0044CFFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.AgentWDCR.SVC |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\2d5ee28a-f782-4cc1-aa85-b49f8f019ddd\updatewin.exe | Downloaded File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-01-16 22:21 (UTC+1) |
Last Seen | 2019-08-19 12:33 (UTC+2) |
Names | Win32.Trojan.Kryptik |
Families | Kryptik |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x402d7c |
Size Of Code | 0x1c200 |
Size Of Initialized Data | 0x2d400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-02-19 08:26:47+00:00 |
Version Information (3)
»
FileVersion | 8.8.10.11 |
InternalName | sutazaxidi.exe |
LegalCopyright | Copyright (C) 2018, huxonulow |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1c09e | 0x1c200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x41e000 | 0x4636 | 0x4800 | 0x1c600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.25 |
.data | 0x423000 | 0x1d5a8 | 0x18400 | 0x20e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.8 |
.rsrc | 0x441000 | 0xa826 | 0xaa00 | 0x39200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.84 |
.reloc | 0x44c000 | 0x1974 | 0x1a00 | 0x43c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.34 |
Imports (4)
»
KERNEL32.dll (100)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitThread | 0x0 | 0x41e020 | 0x21af4 | 0x200f4 | 0x105 |
GetStartupInfoW | 0x0 | 0x41e024 | 0x21af8 | 0x200f8 | 0x23a |
GetConsoleAliasesW | 0x0 | 0x41e028 | 0x21afc | 0x200fc | 0x182 |
GetLastError | 0x0 | 0x41e02c | 0x21b00 | 0x20100 | 0x1e6 |
GetProcAddress | 0x0 | 0x41e030 | 0x21b04 | 0x20104 | 0x220 |
BackupWrite | 0x0 | 0x41e034 | 0x21b08 | 0x20108 | 0x18 |
GlobalFree | 0x0 | 0x41e038 | 0x21b0c | 0x2010c | 0x28c |
LoadLibraryA | 0x0 | 0x41e03c | 0x21b10 | 0x20110 | 0x2f1 |
GetNumberFormatW | 0x0 | 0x41e040 | 0x21b14 | 0x20114 | 0x20f |
AddAtomA | 0x0 | 0x41e044 | 0x21b18 | 0x20118 | 0x3 |
FindFirstChangeNotificationA | 0x0 | 0x41e048 | 0x21b1c | 0x2011c | 0x11b |
GetStringTypeW | 0x0 | 0x41e04c | 0x21b20 | 0x20120 | 0x240 |
VirtualProtect | 0x0 | 0x41e050 | 0x21b24 | 0x20124 | 0x45a |
GetACP | 0x0 | 0x41e054 | 0x21b28 | 0x20128 | 0x152 |
SetProcessShutdownParameters | 0x0 | 0x41e058 | 0x21b2c | 0x2012c | 0x3f9 |
CompareStringW | 0x0 | 0x41e05c | 0x21b30 | 0x20130 | 0x55 |
CompareStringA | 0x0 | 0x41e060 | 0x21b34 | 0x20134 | 0x52 |
CreateFileA | 0x0 | 0x41e064 | 0x21b38 | 0x20138 | 0x78 |
GetTimeZoneInformation | 0x0 | 0x41e068 | 0x21b3c | 0x2013c | 0x26b |
WriteConsoleW | 0x0 | 0x41e06c | 0x21b40 | 0x20140 | 0x48c |
GetConsoleOutputCP | 0x0 | 0x41e070 | 0x21b44 | 0x20144 | 0x199 |
WriteConsoleA | 0x0 | 0x41e074 | 0x21b48 | 0x20148 | 0x482 |
CloseHandle | 0x0 | 0x41e078 | 0x21b4c | 0x2014c | 0x43 |
IsValidLocale | 0x0 | 0x41e07c | 0x21b50 | 0x20150 | 0x2dd |
EnumSystemLocalesA | 0x0 | 0x41e080 | 0x21b54 | 0x20154 | 0xf8 |
GetUserDefaultLCID | 0x0 | 0x41e084 | 0x21b58 | 0x20158 | 0x26d |
GetDateFormatA | 0x0 | 0x41e088 | 0x21b5c | 0x2015c | 0x1ae |
GetSystemTimes | 0x0 | 0x41e08c | 0x21b60 | 0x20160 | 0x250 |
GetTickCount | 0x0 | 0x41e090 | 0x21b64 | 0x20164 | 0x266 |
FreeEnvironmentStringsA | 0x0 | 0x41e094 | 0x21b68 | 0x20168 | 0x14a |
GetComputerNameW | 0x0 | 0x41e098 | 0x21b6c | 0x2016c | 0x178 |
FindCloseChangeNotification | 0x0 | 0x41e09c | 0x21b70 | 0x20170 | 0x11a |
FindResourceExW | 0x0 | 0x41e0a0 | 0x21b74 | 0x20174 | 0x138 |
GetCurrentDirectoryA | 0x0 | 0x41e0a4 | 0x21b78 | 0x20178 | 0x1a7 |
GetCPInfo | 0x0 | 0x41e0a8 | 0x21b7c | 0x2017c | 0x15b |
GetTimeFormatA | 0x0 | 0x41e0ac | 0x21b80 | 0x20180 | 0x268 |
GetStringTypeA | 0x0 | 0x41e0b0 | 0x21b84 | 0x20184 | 0x23d |
LCMapStringW | 0x0 | 0x41e0b4 | 0x21b88 | 0x20188 | 0x2e3 |
LCMapStringA | 0x0 | 0x41e0b8 | 0x21b8c | 0x2018c | 0x2e1 |
GetLocaleInfoA | 0x0 | 0x41e0bc | 0x21b90 | 0x20190 | 0x1e8 |
GetLocaleInfoW | 0x0 | 0x41e0c0 | 0x21b94 | 0x20194 | 0x1ea |
SetStdHandle | 0x0 | 0x41e0c4 | 0x21b98 | 0x20198 | 0x3fc |
SetFilePointer | 0x0 | 0x41e0c8 | 0x21b9c | 0x2019c | 0x3df |
GetCommandLineA | 0x0 | 0x41e0cc | 0x21ba0 | 0x201a0 | 0x16f |
GetStartupInfoA | 0x0 | 0x41e0d0 | 0x21ba4 | 0x201a4 | 0x239 |
RaiseException | 0x0 | 0x41e0d4 | 0x21ba8 | 0x201a8 | 0x35a |
RtlUnwind | 0x0 | 0x41e0d8 | 0x21bac | 0x201ac | 0x392 |
TerminateProcess | 0x0 | 0x41e0dc | 0x21bb0 | 0x201b0 | 0x42d |
GetCurrentProcess | 0x0 | 0x41e0e0 | 0x21bb4 | 0x201b4 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x41e0e4 | 0x21bb8 | 0x201b8 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x41e0e8 | 0x21bbc | 0x201bc | 0x415 |
IsDebuggerPresent | 0x0 | 0x41e0ec | 0x21bc0 | 0x201c0 | 0x2d1 |
HeapAlloc | 0x0 | 0x41e0f0 | 0x21bc4 | 0x201c4 | 0x29d |
HeapFree | 0x0 | 0x41e0f4 | 0x21bc8 | 0x201c8 | 0x2a1 |
EnterCriticalSection | 0x0 | 0x41e0f8 | 0x21bcc | 0x201cc | 0xd9 |
LeaveCriticalSection | 0x0 | 0x41e0fc | 0x21bd0 | 0x201d0 | 0x2ef |
SetHandleCount | 0x0 | 0x41e100 | 0x21bd4 | 0x201d4 | 0x3e8 |
GetStdHandle | 0x0 | 0x41e104 | 0x21bd8 | 0x201d8 | 0x23b |
GetFileType | 0x0 | 0x41e108 | 0x21bdc | 0x201dc | 0x1d7 |
DeleteCriticalSection | 0x0 | 0x41e10c | 0x21be0 | 0x201e0 | 0xbe |
GetModuleHandleW | 0x0 | 0x41e110 | 0x21be4 | 0x201e4 | 0x1f9 |
Sleep | 0x0 | 0x41e114 | 0x21be8 | 0x201e8 | 0x421 |
ExitProcess | 0x0 | 0x41e118 | 0x21bec | 0x201ec | 0x104 |
WriteFile | 0x0 | 0x41e11c | 0x21bf0 | 0x201f0 | 0x48d |
GetModuleFileNameA | 0x0 | 0x41e120 | 0x21bf4 | 0x201f4 | 0x1f4 |
GetEnvironmentStrings | 0x0 | 0x41e124 | 0x21bf8 | 0x201f8 | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x41e128 | 0x21bfc | 0x201fc | 0x14b |
WideCharToMultiByte | 0x0 | 0x41e12c | 0x21c00 | 0x20200 | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x41e130 | 0x21c04 | 0x20204 | 0x1c1 |
TlsGetValue | 0x0 | 0x41e134 | 0x21c08 | 0x20208 | 0x434 |
TlsAlloc | 0x0 | 0x41e138 | 0x21c0c | 0x2020c | 0x432 |
TlsSetValue | 0x0 | 0x41e13c | 0x21c10 | 0x20210 | 0x435 |
TlsFree | 0x0 | 0x41e140 | 0x21c14 | 0x20214 | 0x433 |
InterlockedIncrement | 0x0 | 0x41e144 | 0x21c18 | 0x20218 | 0x2c0 |
SetLastError | 0x0 | 0x41e148 | 0x21c1c | 0x2021c | 0x3ec |
GetCurrentThreadId | 0x0 | 0x41e14c | 0x21c20 | 0x20220 | 0x1ad |
InterlockedDecrement | 0x0 | 0x41e150 | 0x21c24 | 0x20224 | 0x2bc |
GetCurrentThread | 0x0 | 0x41e154 | 0x21c28 | 0x20228 | 0x1ac |
HeapCreate | 0x0 | 0x41e158 | 0x21c2c | 0x2022c | 0x29f |
HeapDestroy | 0x0 | 0x41e15c | 0x21c30 | 0x20230 | 0x2a0 |
VirtualFree | 0x0 | 0x41e160 | 0x21c34 | 0x20234 | 0x457 |
QueryPerformanceCounter | 0x0 | 0x41e164 | 0x21c38 | 0x20238 | 0x354 |
GetCurrentProcessId | 0x0 | 0x41e168 | 0x21c3c | 0x2023c | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x41e16c | 0x21c40 | 0x20240 | 0x24f |
FatalAppExitA | 0x0 | 0x41e170 | 0x21c44 | 0x20244 | 0x10b |
VirtualAlloc | 0x0 | 0x41e174 | 0x21c48 | 0x20248 | 0x454 |
HeapReAlloc | 0x0 | 0x41e178 | 0x21c4c | 0x2024c | 0x2a4 |
MultiByteToWideChar | 0x0 | 0x41e17c | 0x21c50 | 0x20250 | 0x31a |
ReadFile | 0x0 | 0x41e180 | 0x21c54 | 0x20254 | 0x368 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41e184 | 0x21c58 | 0x20258 | 0x2b5 |
HeapSize | 0x0 | 0x41e188 | 0x21c5c | 0x2025c | 0x2a6 |
SetConsoleCtrlHandler | 0x0 | 0x41e18c | 0x21c60 | 0x20260 | 0x3a7 |
FreeLibrary | 0x0 | 0x41e190 | 0x21c64 | 0x20264 | 0x14c |
InterlockedExchange | 0x0 | 0x41e194 | 0x21c68 | 0x20268 | 0x2bd |
GetOEMCP | 0x0 | 0x41e198 | 0x21c6c | 0x2026c | 0x213 |
IsValidCodePage | 0x0 | 0x41e19c | 0x21c70 | 0x20270 | 0x2db |
GetConsoleCP | 0x0 | 0x41e1a0 | 0x21c74 | 0x20274 | 0x183 |
GetConsoleMode | 0x0 | 0x41e1a4 | 0x21c78 | 0x20278 | 0x195 |
FlushFileBuffers | 0x0 | 0x41e1a8 | 0x21c7c | 0x2027c | 0x141 |
SetEnvironmentVariableA | 0x0 | 0x41e1ac | 0x21c80 | 0x20280 | 0x3d0 |
USER32.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseClipboard | 0x0 | 0x41e1d4 | 0x21ca8 | 0x202a8 | 0x47 |
SendNotifyMessageA | 0x0 | 0x41e1d8 | 0x21cac | 0x202ac | 0x264 |
BeginPaint | 0x0 | 0x41e1dc | 0x21cb0 | 0x202b0 | 0xe |
CallMsgFilterW | 0x0 | 0x41e1e0 | 0x21cb4 | 0x202b4 | 0x1a |
PeekMessageA | 0x0 | 0x41e1e4 | 0x21cb8 | 0x202b8 | 0x21b |
MapVirtualKeyExW | 0x0 | 0x41e1e8 | 0x21cbc | 0x202bc | 0x1f1 |
RegisterRawInputDevices | 0x0 | 0x41e1ec | 0x21cc0 | 0x202c0 | 0x242 |
GetClipboardSequenceNumber | 0x0 | 0x41e1f0 | 0x21cc4 | 0x202c4 | 0x113 |
SetUserObjectInformationA | 0x0 | 0x41e1f4 | 0x21cc8 | 0x202c8 | 0x29f |
GetDialogBaseUnits | 0x0 | 0x41e1f8 | 0x21ccc | 0x202cc | 0x11d |
GetMessageW | 0x0 | 0x41e1fc | 0x21cd0 | 0x202d0 | 0x14e |
GDI32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreatePolyPolygonRgn | 0x0 | 0x41e000 | 0x21ad4 | 0x200d4 | 0x4b |
CreateCompatibleDC | 0x0 | 0x41e004 | 0x21ad8 | 0x200d8 | 0x2e |
SetStretchBltMode | 0x0 | 0x41e008 | 0x21adc | 0x200dc | 0x289 |
SetPixelV | 0x0 | 0x41e00c | 0x21ae0 | 0x200e0 | 0x284 |
GetCharWidth32A | 0x0 | 0x41e010 | 0x21ae4 | 0x200e4 | 0x1a0 |
CreateDiscardableBitmap | 0x0 | 0x41e014 | 0x21ae8 | 0x200e8 | 0x35 |
BitBlt | 0x0 | 0x41e018 | 0x21aec | 0x200ec | 0x12 |
SHELL32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x41e1b4 | 0x21c88 | 0x20288 | 0x118 |
ShellAboutW | 0x0 | 0x41e1b8 | 0x21c8c | 0x2028c | 0x110 |
ExtractIconA | 0x0 | 0x41e1bc | 0x21c90 | 0x20290 | 0x28 |
ShellExecuteExA | 0x0 | 0x41e1c0 | 0x21c94 | 0x20294 | 0x116 |
FindExecutableA | 0x0 | 0x41e1c4 | 0x21c98 | 0x20298 | 0x2d |
DragQueryFileA | 0x0 | 0x41e1c8 | 0x21c9c | 0x2029c | 0x1e |
ExtractIconW | 0x0 | 0x41e1cc | 0x21ca0 | 0x202a0 | 0x2c |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.AgentWDCR.SUF |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9DC6.tmp.exe.carote | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\B7UgNIfW.swf | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\c4 j8.swf | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\D 65.bmp.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\e6-BA 49wurXcsu-1.mp3.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\g3SB3fjz.wav.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Gnmre2J_Zh T.odt | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\GOG573ZY8rfBlY-.wav.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\UTYb2gnV5j Zsu.gif | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wdgP96 SXmW.mp4.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\9huoURlo4xaH5cScK.docx.carote | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\9is01ddNDlEMb.xlsx.carote | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\AYbPNC9cxxg.pptx | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\CjF8p.docx | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\cVr6.pptx | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\qv XM3woqTwbpxO3v.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\t40QA1IsS7nqa.pptx | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ueCUDl.docx.carote | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\uzFglAG bSH.xlsx.carote | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wq8G.xlsx.carote | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xBje_MZVdD1M.docx | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\yhDls2iW48j.xlsx | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\za8H7KP3EgJw.pptx | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\4suXJ1A8AJzQb.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\jy7QJY5ZDe.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Rcxwv.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\RrxvmDKYTi0rBAg7jbyD.m4a.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Rt7LMOP_q.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\fnUjM6bZhIti0vgC fCV.png.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\mcLNkatVL.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\sLHdw2s-tEQcdxTjD.jpg.carote | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\vqrGBu_vIn8q3b.jpg.carote | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\YE BtExcqJs.bmp.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\4XdhJ_Lqlr8BQwVu7.avi.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\LSGoRNlCd_flaeQTyFZ.swf | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\f_-8oBARRP9-U\4gyquRJLFk4EHaxRY.jpg.carote | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\f_-8oBARRP9-U\fDU6skWeF5QU.swf.carote | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\j_8df4HNVB0C0RCpZ-GV\r5Pp7fI T0KSM.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\j_8df4HNVB0C0RCpZ-GV\UBEx-NT eGDNRaXEsmrT.mkv.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\BXteOBXIuKySqXgo0\d5n1rI-2s-1o0b.ppt.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\m8Ml-6lNM1 wULCS0yD\xIlUh2wKNE.xlsx | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\p4QbPuBf\0yZWpZno3W y.pptx.carote | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\p4QbPuBf\2i6XeIHPx.pps | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\p4QbPuBf\6UsyGLFtiuFsm.docx | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\p4QbPuBf\YAhk-.pps.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\zmTKLzB\9jgmDCVjOmsoi8li3M.odp.carote | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Suggested Sites.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Web Slice Gallery.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE site on Microsoft.com.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Work.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Autos.url.carote | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Entertainment.url.carote | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Money.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN.url.carote | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Gallery.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Mail.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Spaces.url.carote | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\dQ7tGsp53IT a50pD3\1bO9BvF.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\dQ7tGsp53IT a50pD3\4nAMxRgwJpjNgKt6.mp3.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\dQ7tGsp53IT a50pD3\8_IgYOYaL.wav.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\dQ7tGsp53IT a50pD3\D4M5dRYR.m4a.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\dQ7tGsp53IT a50pD3\dpyHTp8b6ly3NNoN.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\dQ7tGsp53IT a50pD3\Fn9ntm9P.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\dQ7tGsp53IT a50pD3\PxtCJh0B.mp3.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\dQ7tGsp53IT a50pD3\TtS5 r6- rR.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\dQ7tGsp53IT a50pD3\vHCrrM264OI56bmUA.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\dQ7tGsp53IT a50pD3\ZjvCqhLuqlFvmhkkfQQ.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\rBkn83DAvewyB\H5jt83oya.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\rBkn83DAvewyB\KXMGrM AHu.gif | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\54 eabicVzfIp avOT.mp4.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\9oEreISY0AXOhVGDhgFx.flv.carote | Dropped File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\9OFGdrKdAmwg60-tIlt.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\Asw8FiPHMrVAks1Q.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\DaYAfKh5e.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\DwSCY.flv.carote | Dropped File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\sei rtyE45SJ8ir5jsS.swf.carote | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\f_-8oBARRP9-U\bFT9ci 8fZ3bljOH\EiHg8GR6-5ETznOtH.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\f_-8oBARRP9-U\bFT9ci 8fZ3bljOH\Qi 2.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\JiLyW4X cG7WzlVAVa\hIl-xN3DRO3pVP\BKlpy7Ip_YE.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\JiLyW4X cG7WzlVAVa\hIl-xN3DRO3pVP\DPeKe 7dMpx.m4a.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\JiLyW4X cG7WzlVAVa\hIl-xN3DRO3pVP\r6veYprPQ4QpJN3.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\BXteOBXIuKySqXgo0\yc2hVUR2 YKnU\5TtF1NQ8K10bBmnwe.docx | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\BXteOBXIuKySqXgo0\yc2hVUR2 YKnU\giZUB-hk6ZRFw.doc.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\BXteOBXIuKySqXgo0\yc2hVUR2 YKnU\rjhwjI.ods | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\SmG7\LFwoVJrFDf\IizG80gjyvdMDI.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\SmG7\LFwoVJrFDf\RgglSxZBJI5s8e_qw4.docx.carote | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\rBkn83DAvewyB\BbK9PWtcKHe5E\-cdd.png.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\rBkn83DAvewyB\BbK9PWtcKHe5E\6eE0Shwl09PRJ2R3v.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\rBkn83DAvewyB\BbK9PWtcKHe5E\cFaN104B.bmp.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\rBkn83DAvewyB\BbK9PWtcKHe5E\pit8u.gif | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\rBkn83DAvewyB\BbK9PWtcKHe5E\pItKXTuCp5WopM.jpg.carote | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\rBkn83DAvewyB\BbK9PWtcKHe5E\X-Df2Wyu2HWPvmnSy.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\rBkn83DAvewyB\gqtiv9s2isdbdOiFE-3Q\acx5oTi2.gif | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\rBkn83DAvewyB\gqtiv9s2isdbdOiFE-3Q\CF2Yprwzp3UO9UhoQFd.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\rBkn83DAvewyB\gqtiv9s2isdbdOiFE-3Q\kirDgSeSoWkTS HRY4R.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\rBkn83DAvewyB\gqtiv9s2isdbdOiFE-3Q\w6 gOvajiL.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\rBkn83DAvewyB\LKIDjb 2A JAgFttip\-5ALl.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\rBkn83DAvewyB\LKIDjb 2A JAgFttip\eSoALTrj4Vl.bmp.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\rBkn83DAvewyB\LKIDjb 2A JAgFttip\pTgIntnrLgI.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\rBkn83DAvewyB\LKIDjb 2A JAgFttip\vARY.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\DflAw\ih30 WglWzXLsQmA.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\DflAw\Li7pjIddBJI Fo4mf9.flv.carote | Dropped File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\DflAw\wSpQFb6VP7CjB27-8wWi.flv | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\DflAw\zNzMXjt4K8TB.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\L0lT\0bbBT.mp4.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\L0lT\EU0vdPwEd1NhbXPW.swf.carote | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\L0lT\K4L5fZItZfYvVImu.flv.carote | Dropped File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\L0lT\sERWELja3PflQ xn.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\L0lT\vdRWAGEx51PIo3b.flv.carote | Dropped File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\L0lT\WN 7uc01.swf.carote | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\BXteOBXIuKySqXgo0\yc2hVUR2 YKnU\Kkla\5xVedSP9OBEStA.rtf | Modified File | Text |
Unknown
|
...
|
»
RTF Information
»
Document Content Snippet
»
E.5q^<2[@!чOjڙᆉ8Ow/|Q'TL~s~HֹC7j$헒%f>%^nN;X(3>/mn(qL8U"jz>8^Ud[ʈ'(f_Чt(zcHUm64~ȨB~+Z7r,V,#ͼ`hOv?D'rhfq]O-.| /Ij^b:p4:O+Q#[9u7qVgy$f3|9/nl!jCkpzcztF|yetn6Ok)g_jA7B[IoH0-"*B48T^P@C:jw"%!Ҍ6/FFTei:"~Hq̫ȾL`xKM:$A<|/db8y@VS,s>eMsʼ8Vj |L<ݯg0)rއRv۞n2_J%#W|'>w,W])뽷ϗ'<TF-$|FLhK;)<+oiZc5[|_pydJߪP,qt-,eEtbĉ)5vM1m5;@vH!Ҍ3t`jf*:f=`^S牊|P`P>B0zdfҢXfo;-q8_ #+;CULʭL)tŮF=(˸aay'jeY>vЌ&?9D/<؋3exmOQ=P7SLs'f9IMG,L9MO8@7; ru|q^@Qَ 9PVͫOzh`,Nw7gD꿮o *U**4[`?,VJn.ɥrT߈t@JE+:M|I57(QoXNy9ÈHW$bq`ɷ;ZR.M2JME_=Xpr埚,&`|Ӽ;;T+i`cN9t)˂FHmf=KxQ.ܖj'X_~2deGۯ >P<ڶmGx ݃,WY֑j#ϔ'u',Gí2C2,уYJ3#Ts eΎ<5-H23בU^2y)Trܫ]ŧD%X3v+N_Z麖_(bs(OM>|JLmˬvrWK_/cy_NT nZsW6c쯸2Qwn4lY^KcxF M5`1xg6#9vԛynAE]o[plL5jjI]bقC5N!c=dpg^!ǍȚ3;tT>.9k<+GJ' >=[̓q)IO!Gn^9yfD&Z3^CaeUsӚ[oлF"DoPRVA6ĵޔs<j:5kElzj)4ސށuRņPqvcw=Z7sN06r`L]8 fXbs ... |
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\BXteOBXIuKySqXgo0\yc2hVUR2 YKnU\Kkla\GkmXiYT zW.rtf.carote | Dropped File | Text |
Unknown
|
...
|
»
RTF Information
»
Document Content Snippet
»
E.5q^<2[@!чOjڙᆉ8Ow/|r1)FI^^Bґ/2GNIKl!S4##:߾@)Rd!O`ifChDx<KTF(-C-H3b05"%ѩY#zTk?0^IOilS/OmKW!mp<yFI.kkj^6u((iVn#22'm10JJPHKǰMEg@;le"/81-~%`G+i[&.bLG9!3>) n? ]~rROi?tiPhY9/aQg@P*hjxYlmBi ^veh)~vDʀFMK隆DF5&o3g1&Ix4ًH%hMքDy~z/@&DQS"qnydwil1 ݟa.`@6%9`;I=pvƐLȐn MKxϽ$#;mn>qrZ6l:P! e[ `I51)K$pziWp;?9Pn~Dyuzs|bl5|@fP&mZ>I*E3窾O'JU5vHjڒEʴgq[nT_y08X?vk?vT[C;z5/#t"l=>_H8/bEW4D^SNHF]>du Qakɭx-tD8Vɴ"^Yť˂ڟMT JMmTkk))B rE~ąHY.'xw;Q~di#]9q5ɤ~΅jķo[Iɂt!n>b;;5V)Nڜ%ȂE,"B*pv+,lRLgu.q9!f+|5#w-WϢ]m=;cIϷu4>T Al"_d0-)@fh$yѶ6DE5vLUfc4|.AڻAbW;Uz0U@[*(S<eRNUia$~aa.>O`~b+:co[_VpE(<'G;e<Fb+Lzx]p-APC!f IRۂbYt67u(5&Ѵq7WMlkBp'tcE]K<&MKphJ3Yfmj-PLuQX#;F.qBKŧ"NPHyPBVC+:ahZ6g:3аl&Veӵpղzl2gS|9s&!*Jʛ$t);I2/aNXt?|7,>n~G<bo!u28Vv2&ݚa oUƛ+KO':)iSPK(FծE5^y<J8u$X`b;2ްTDMa3ʭRn0ߞ9Վh#翑g9I~JyUnz [*9PIowc"FQoC:RG&"; ... |
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\BXteOBXIuKySqXgo0\yc2hVUR2 YKnU\Kkla\iLHcW1_L1lLAxI J8rJ.ods | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\BXteOBXIuKySqXgo0\yc2hVUR2 YKnU\Kkla\ooZ53.pptx | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\BXteOBXIuKySqXgo0\yc2hVUR2 YKnU\WTT 8oXmb8q1blmN0eH\cwSafQl25.ods.carote | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\BXteOBXIuKySqXgo0\yc2hVUR2 YKnU\WTT 8oXmb8q1blmN0eH\tegF3gXtk.odt | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\BXteOBXIuKySqXgo0\yc2hVUR2 YKnU\WTT 8oXmb8q1blmN0eH\z1QP6pPCfuXmpQNcWehe.odp.carote | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\DflAw\5unaIP8QoXZY\2v5KLJcDwYWFxYopglE.avi.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\DflAw\5unaIP8QoXZY\cbC165GWDZo.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\DflAw\5unaIP8QoXZY\PcVv8f8Jk 5Z5aP.flv | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\DflAw\aSFf3q\-ZNuS.avi.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\DflAw\aSFf3q\ejvopeLEHjhZFIqxW7G.mkv.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\DflAw\aSFf3q\YlPUbv4TdIl.flv.carote | Dropped File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\DflAw\Ky0Ly40HAhggPV2r3\MEMlGAEqnGCcH.swf | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\DflAw\Z9S-Lyrz1J9mVBffWgx3\WBXXykKnYyU.avi.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\index.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.cab.carote | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\Deployment\deployment.properties.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\Data1.cab | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\jre1.7.0_45.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\DflAw\Z9S-Lyrz1J9mVBffWgx3\GP_hmZxeLiKuo3\nijAYu7CZB.swf.carote | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\DflAw\Z9S-Lyrz1J9mVBffWgx3\GP_hmZxeLiKuo3\PuAy84E.flv | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\DflAw\Z9S-Lyrz1J9mVBffWgx3\GP_hmZxeLiKuo3\SXB8IlVATC g7CApR0.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\VGMTOI09\www.msn[1].xml.carote | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\DflAw\Z9S-Lyrz1J9mVBffWgx3\GP_hmZxeLiKuo3\DrYYTX _BQbZrK6Uad\C2i_UEX3Ob.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\DflAw\Z9S-Lyrz1J9mVBffWgx3\GP_hmZxeLiKuo3\DrYYTX _BQbZrK6Uad\WAmHWSt4u.mp4 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\history\history.ie5\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\ietldcache\index.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\script.ps1 | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\_readme.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact.carote | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact.carote | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\0sRxa0kL_.flv | Modified File | Video |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\BOm6MV3rA.png.carote | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\FVqwxtFUoI.ots.carote | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\pXJT.gif.carote | Dropped File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\UnO 907l.wav.carote | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\woEaiFw4PYk9uPU.xlsx | Modified File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\6x5Al7 pvIePmK.docx.carote | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\dCzpsluKVRUVVZ8bGKcj.pptx.carote | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\-uVUI.mp3.carote | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\1JKoALnkX5.m4a.carote | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\4lkpxUARpwW-C.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\4Z1gbj.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\RLO yJMHv0L.mp3.carote | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\UK6oB.m4a.carote | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Xcrmc4FZ.m4a.carote | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\y-NLxTIvwMCOP.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AmzvjcI0hTMGaxNNz.jpg | Modified File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\hoFR8_x Tu2XGiHDqM.gif.carote | Dropped File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_g2PjaKI054.gif | Modified File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\f_-8oBARRP9-U\rz.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\j_8df4HNVB0C0RCpZ-GV\ms3o6q-3xW GcAnXpq.gif.carote | Dropped File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\BXteOBXIuKySqXgo0\7 dXcVMStPKkVLbTfdBI.ots.carote | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\BXteOBXIuKySqXgo0\KRmH1t.pps.carote | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\BXteOBXIuKySqXgo0\tmoBqjYuc7dMqxVQYl.odt.carote | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\m8Ml-6lNM1 wULCS0yD\CqqYDQxTwNdH.xls | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\m8Ml-6lNM1 wULCS0yD\rsZM.odp.carote | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\p4QbPuBf\ZBbqqZmAUxSDj.odp | Modified File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\SmG7\a--g-.xls.carote | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\SmG7\bVolNUdnBKCJzp4l.odp.carote | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\zmTKLzB\-qKyf.pps.carote | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE Add-on site.url.carote | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Home.url.carote | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft Store.url.carote | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Sports.url.carote | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSNBC News.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Get Windows Live.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\dQ7tGsp53IT a50pD3\1zNCStn2l4koWKgb1O.m4a.carote | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\dQ7tGsp53IT a50pD3\7CaTmGrvAXcZ6sIkKZCC.mp3.carote | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\dQ7tGsp53IT a50pD3\7T_HSbo.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\dQ7tGsp53IT a50pD3\9t0ADIaokMSyl.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\dQ7tGsp53IT a50pD3\kaUGY_Ao.wav.carote | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\dQ7tGsp53IT a50pD3\lXWYDIZ6pnb1Y.m4a.carote | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\dQ7tGsp53IT a50pD3\wShydfksN321xS UdL0.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\dQ7tGsp53IT a50pD3\yCnnA0r.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\rBkn83DAvewyB\YlgKBS0V3seonAtFx.gif | Modified File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\f_-8oBARRP9-U\bFT9ci 8fZ3bljOH\gmQhUBvB_idYNsu0nMl.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\JiLyW4X cG7WzlVAVa\hIl-xN3DRO3pVP\z_tTpOnlGrL AwKioS0.xls.carote | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\_private\folder.ico.carote | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\rBkn83DAvewyB\gqtiv9s2isdbdOiFE-3Q\IjNVUGZnKO1CKld.gif | Modified File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\rBkn83DAvewyB\gqtiv9s2isdbdOiFE-3Q\TuJMzJjElwC1.jpg | Modified File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\rBkn83DAvewyB\LKIDjb 2A JAgFttip\uyt9YJUkC_hciXuzO_.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\DflAw\ItGC.flv.carote | Dropped File | Video |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\BXteOBXIuKySqXgo0\yc2hVUR2 YKnU\Kkla\7RWAZVtgFSVKtbmnD9-.pps | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\BXteOBXIuKySqXgo0\yc2hVUR2 YKnU\WTT 8oXmb8q1blmN0eH\9IW1b3FoUqG.csv.carote | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\DflAw\aSFf3q\jdo8tC -dDtBml57.flv.carote | Dropped File | Video |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Adobe\Acrobat\10.0\rdrmessage.zip.carote | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UYaZ4DG0b_NROc5iB6tm\DflAw\Z9S-Lyrz1J9mVBffWgx3\GP_hmZxeLiKuo3\hcn-5BQ.flv.carote | Dropped File | Video |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\3O75JDME\www.google[1].xml.carote | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\x9ohk109\geo[1].json | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\Favorites.vss.carote | Dropped File | Unknown |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\x9ohk109\get[1].php | Downloaded File | Text |
Not Queried
|
...
|
»