VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Downloader
Spyware
|
Threat Names: |
Djvu
STOP
Trojan.GenericKDZ.68641
...
|
70BC.tmp.exe
Windows Exe (x86-32)
Created at 2020-07-13T11:43:00
Remarks (2/3)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "1 minute, 30 seconds" to "10 seconds" to reveal dormant functionality.
(0x0200003A): 2 tasks were rescheduled ahead of time to reveal dormant functionality.
Remarks
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\70BC.tmp.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x40436d |
Size Of Code | 0xbc00 |
Size Of Initialized Data | 0x8e5c00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-07-18 14:45:21+00:00 |
Version Information (3)
»
Copyright | Copyrighd (C) 2020, odhsjv |
InternalSurnames | dhrj.uxe |
ProductionVersion | 1.0.4.8 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xba69 | 0xbc00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.64 |
.rdata | 0x40d000 | 0x2dd8 | 0x2e00 | 0xc000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.29 |
.data | 0x410000 | 0x8d8618 | 0x95e00 | 0xee00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.93 |
.rsrc | 0xce9000 | 0x43a8 | 0x4400 | 0xa4c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.6 |
Imports (2)
»
KERNEL32.dll (86)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
AllocConsole | 0x0 | 0x40d000 | 0xf61c | 0xe61c | 0xe |
InterlockedDecrement | 0x0 | 0x40d004 | 0xf620 | 0xe620 | 0x2bc |
ZombifyActCtx | 0x0 | 0x40d008 | 0xf624 | 0xe624 | 0x49c |
GetEnvironmentStringsW | 0x0 | 0x40d00c | 0xf628 | 0xe628 | 0x1c1 |
WaitForSingleObject | 0x0 | 0x40d010 | 0xf62c | 0xe62c | 0x464 |
GetModuleHandleW | 0x0 | 0x40d014 | 0xf630 | 0xe630 | 0x1f9 |
GetTickCount | 0x0 | 0x40d018 | 0xf634 | 0xe634 | 0x266 |
FindActCtxSectionStringA | 0x0 | 0x40d01c | 0xf638 | 0xe638 | 0x115 |
SetFileShortNameW | 0x0 | 0x40d020 | 0xf63c | 0xe63c | 0x3e2 |
GetCalendarInfoW | 0x0 | 0x40d024 | 0xf640 | 0xe640 | 0x164 |
lstrcpynW | 0x0 | 0x40d028 | 0xf644 | 0xe644 | 0x4b3 |
GetFileAttributesW | 0x0 | 0x40d02c | 0xf648 | 0xe648 | 0x1ce |
HeapQueryInformation | 0x0 | 0x40d030 | 0xf64c | 0xe64c | 0x2a3 |
lstrlenW | 0x0 | 0x40d034 | 0xf650 | 0xe650 | 0x4b6 |
GetProcAddress | 0x0 | 0x40d038 | 0xf654 | 0xe654 | 0x220 |
CreateConsoleScreenBuffer | 0x0 | 0x40d03c | 0xf658 | 0xe658 | 0x6b |
ResetEvent | 0x0 | 0x40d040 | 0xf65c | 0xe65c | 0x38a |
LocalAlloc | 0x0 | 0x40d044 | 0xf660 | 0xe660 | 0x2f9 |
GetOEMCP | 0x0 | 0x40d048 | 0xf664 | 0xe664 | 0x213 |
CreateMutexA | 0x0 | 0x40d04c | 0xf668 | 0xe668 | 0x8b |
BuildCommDCBA | 0x0 | 0x40d050 | 0xf66c | 0xe66c | 0x2b |
QueryDepthSList | 0x0 | 0x40d054 | 0xf670 | 0xe670 | 0x34c |
DeleteFileW | 0x0 | 0x40d058 | 0xf674 | 0xe674 | 0xc3 |
CommConfigDialogW | 0x0 | 0x40d05c | 0xf678 | 0xe678 | 0x4f |
HeapAlloc | 0x0 | 0x40d060 | 0xf67c | 0xe67c | 0x29d |
GetCommandLineA | 0x0 | 0x40d064 | 0xf680 | 0xe680 | 0x16f |
GetStartupInfoA | 0x0 | 0x40d068 | 0xf684 | 0xe684 | 0x239 |
RaiseException | 0x0 | 0x40d06c | 0xf688 | 0xe688 | 0x35a |
RtlUnwind | 0x0 | 0x40d070 | 0xf68c | 0xe68c | 0x392 |
TerminateProcess | 0x0 | 0x40d074 | 0xf690 | 0xe690 | 0x42d |
GetCurrentProcess | 0x0 | 0x40d078 | 0xf694 | 0xe694 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x40d07c | 0xf698 | 0xe698 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x40d080 | 0xf69c | 0xe69c | 0x415 |
IsDebuggerPresent | 0x0 | 0x40d084 | 0xf6a0 | 0xe6a0 | 0x2d1 |
GetLastError | 0x0 | 0x40d088 | 0xf6a4 | 0xe6a4 | 0x1e6 |
HeapFree | 0x0 | 0x40d08c | 0xf6a8 | 0xe6a8 | 0x2a1 |
DeleteCriticalSection | 0x0 | 0x40d090 | 0xf6ac | 0xe6ac | 0xbe |
LeaveCriticalSection | 0x0 | 0x40d094 | 0xf6b0 | 0xe6b0 | 0x2ef |
EnterCriticalSection | 0x0 | 0x40d098 | 0xf6b4 | 0xe6b4 | 0xd9 |
VirtualFree | 0x0 | 0x40d09c | 0xf6b8 | 0xe6b8 | 0x457 |
VirtualAlloc | 0x0 | 0x40d0a0 | 0xf6bc | 0xe6bc | 0x454 |
HeapReAlloc | 0x0 | 0x40d0a4 | 0xf6c0 | 0xe6c0 | 0x2a4 |
HeapCreate | 0x0 | 0x40d0a8 | 0xf6c4 | 0xe6c4 | 0x29f |
Sleep | 0x0 | 0x40d0ac | 0xf6c8 | 0xe6c8 | 0x421 |
ExitProcess | 0x0 | 0x40d0b0 | 0xf6cc | 0xe6cc | 0x104 |
WriteFile | 0x0 | 0x40d0b4 | 0xf6d0 | 0xe6d0 | 0x48d |
GetStdHandle | 0x0 | 0x40d0b8 | 0xf6d4 | 0xe6d4 | 0x23b |
GetModuleFileNameA | 0x0 | 0x40d0bc | 0xf6d8 | 0xe6d8 | 0x1f4 |
TlsGetValue | 0x0 | 0x40d0c0 | 0xf6dc | 0xe6dc | 0x434 |
TlsAlloc | 0x0 | 0x40d0c4 | 0xf6e0 | 0xe6e0 | 0x432 |
TlsSetValue | 0x0 | 0x40d0c8 | 0xf6e4 | 0xe6e4 | 0x435 |
TlsFree | 0x0 | 0x40d0cc | 0xf6e8 | 0xe6e8 | 0x433 |
InterlockedIncrement | 0x0 | 0x40d0d0 | 0xf6ec | 0xe6ec | 0x2c0 |
SetLastError | 0x0 | 0x40d0d4 | 0xf6f0 | 0xe6f0 | 0x3ec |
GetCurrentThreadId | 0x0 | 0x40d0d8 | 0xf6f4 | 0xe6f4 | 0x1ad |
HeapSize | 0x0 | 0x40d0dc | 0xf6f8 | 0xe6f8 | 0x2a6 |
SetHandleCount | 0x0 | 0x40d0e0 | 0xf6fc | 0xe6fc | 0x3e8 |
GetFileType | 0x0 | 0x40d0e4 | 0xf700 | 0xe700 | 0x1d7 |
SetFilePointer | 0x0 | 0x40d0e8 | 0xf704 | 0xe704 | 0x3df |
FreeEnvironmentStringsA | 0x0 | 0x40d0ec | 0xf708 | 0xe708 | 0x14a |
GetEnvironmentStrings | 0x0 | 0x40d0f0 | 0xf70c | 0xe70c | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x40d0f4 | 0xf710 | 0xe710 | 0x14b |
WideCharToMultiByte | 0x0 | 0x40d0f8 | 0xf714 | 0xe714 | 0x47a |
QueryPerformanceCounter | 0x0 | 0x40d0fc | 0xf718 | 0xe718 | 0x354 |
GetCurrentProcessId | 0x0 | 0x40d100 | 0xf71c | 0xe71c | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x40d104 | 0xf720 | 0xe720 | 0x24f |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x40d108 | 0xf724 | 0xe724 | 0x2b5 |
LoadLibraryA | 0x0 | 0x40d10c | 0xf728 | 0xe728 | 0x2f1 |
GetCPInfo | 0x0 | 0x40d110 | 0xf72c | 0xe72c | 0x15b |
GetACP | 0x0 | 0x40d114 | 0xf730 | 0xe730 | 0x152 |
IsValidCodePage | 0x0 | 0x40d118 | 0xf734 | 0xe734 | 0x2db |
SetStdHandle | 0x0 | 0x40d11c | 0xf738 | 0xe738 | 0x3fc |
GetConsoleCP | 0x0 | 0x40d120 | 0xf73c | 0xe73c | 0x183 |
GetConsoleMode | 0x0 | 0x40d124 | 0xf740 | 0xe740 | 0x195 |
FlushFileBuffers | 0x0 | 0x40d128 | 0xf744 | 0xe744 | 0x141 |
GetLocaleInfoA | 0x0 | 0x40d12c | 0xf748 | 0xe748 | 0x1e8 |
GetStringTypeA | 0x0 | 0x40d130 | 0xf74c | 0xe74c | 0x23d |
MultiByteToWideChar | 0x0 | 0x40d134 | 0xf750 | 0xe750 | 0x31a |
GetStringTypeW | 0x0 | 0x40d138 | 0xf754 | 0xe754 | 0x240 |
LCMapStringA | 0x0 | 0x40d13c | 0xf758 | 0xe758 | 0x2e1 |
LCMapStringW | 0x0 | 0x40d140 | 0xf75c | 0xe75c | 0x2e3 |
WriteConsoleA | 0x0 | 0x40d144 | 0xf760 | 0xe760 | 0x482 |
GetConsoleOutputCP | 0x0 | 0x40d148 | 0xf764 | 0xe764 | 0x199 |
WriteConsoleW | 0x0 | 0x40d14c | 0xf768 | 0xe768 | 0x48c |
CloseHandle | 0x0 | 0x40d150 | 0xf76c | 0xe76c | 0x43 |
CreateFileA | 0x0 | 0x40d154 | 0xf770 | 0xe770 | 0x78 |
WINHTTP.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WinHttpCloseHandle | 0x0 | 0x40d15c | 0xf778 | 0xe778 | 0x8 |
Memory Dumps (6)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
buffer | 1 | 0x00D60020 | 0x00DF0DEF | First Execution |
![]() |
32-bit | 0x00D60020 |
![]() |
![]() |
...
|
buffer | 1 | 0x00E30000 | 0x00F49FFF | First Execution |
![]() |
32-bit | 0x00E30000 |
![]() |
![]() |
...
|
buffer | 1 | 0x00E30000 | 0x00F49FFF | Content Changed |
![]() |
32-bit | 0x00E304F6 |
![]() |
![]() |
...
|
buffer | 1 | 0x00E30000 | 0x00F49FFF | Content Changed |
![]() |
32-bit | 0x00E30920 |
![]() |
![]() |
...
|
buffer | 6 | 0x002B0020 | 0x00340DEF | First Execution |
![]() |
32-bit | 0x002B0020 |
![]() |
![]() |
...
|
buffer | 6 | 0x00E80000 | 0x00F99FFF | First Execution |
![]() |
32-bit | 0x00E80000 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKDZ.68641 |
Malicious
|
C:\Windows\System32\drivers\etc\hosts | Modified File | Text |
Malicious
|
...
|
»
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Trojan.Qhost.1 |
Malicious
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\5KZXkheM5u5uJU.docx.repl | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\7PDLT4L1wrFURbYKVTu.png.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\8ESof6tzke.mp4.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\8HZd5l1MKRPrQ8d.jpg.repl | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\fDZ9awc93MQLgEO8t87e.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\FZBFvINOyKGsj.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\IFdec.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\iN81Pym54.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\I_-Oy17ss1 r1N6B.wav.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Ks MmS9s2g.jpg.repl | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\o obKkxAbP4tov.flv.repl | Dropped File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\RLkPQX.odt | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\sQcOvoYYaqJiy6k8f.m4a.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\tJ0J74Cg.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\UerI2Ovi.mp4.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\vVdxe58tScghewQG.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\xwqDVNq1vxP500uetnb.mp3.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\zKtRD2FcPd_l.docx.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZR4E7I.mp4 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\_BZNAkuYTK75Y.mkv.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3ojIp-zQraSdlH4NT.xlsx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\4G-DNoMCC5W0VK1r2qe.docx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\7cikxEG7myp3KU2u3I.pdf.repl | Dropped File |
Malicious
|
...
|
»
YARA Matches (4)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\811nLd y_6sdBYiu.xlsx | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c_9nl6avRr.docx.repl | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\DxFDv-dD7DQ.xlsx.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\eKXCBeD31lK FufivsAa.docx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gQLD cjqv-EBw.xls | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\k32QjmEIvaP.pptx.repl | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\kjoL.pptx.repl | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\kOvbGuNIR.docx.repl | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KZCIoiKWonMlw8t_.xlsx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\l3rhRr0T125Xoyj.doc.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\O7xE1CB.pptx.repl | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\RdNn4YPOcR.pptx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\rG_0w6nNmNx5.pptx.repl | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\T8aU_OjDOmwiDdj.docx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\uyCD 0zgT.docx.repl | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\V9ZBzXb5FgUpi086o.pdf | Modified File |
Malicious
|
...
|
»
YARA Matches (4)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\XCqG1hz1hGPh_.xlsx.repl | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\X4X8e v2jF382WRo8WV8.m4a.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\-No--h4Bje.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\-o3Rx9Lk.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\03m1qAOY0VKs2L8 5b.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\30WZEWuTnF.png.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\4I21p2CSR.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\4l3VmSgkSeNnZaxnn.png.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8_urrW33DsqW1w8IOIWM.bmp.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\9 9Bj.jpg.repl | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\96t5T4tZg_j1JLU.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\akAdGjAzRbOX.gif.repl | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\B xNx9IC44Hm4.png.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\cl8Q2gv0Ec.gif.repl | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\DPzKzoA.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\fcBf3kIvVJ77kI-H5x.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\FKEduRWo9V_vK.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\HetrB02gG.png.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\iqlcViYF9Ud.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\j1wSX.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\KD3OMmO EX.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\kN--uzKXC2Q.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Likad.gif.repl | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\LqaDZxKfuwXuTsSahQQ.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\m9mdu0MSKmx8.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\mHB1QJmrRIH.gif.repl | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ND-tz3HIE.jpg.repl | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\PBze-pOFU dYzmpvWSfM.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\pNhT.bmp.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ppX0qTD.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\pS3MdK XbiU.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\QA97.png.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Qzu0l97jXRI.jpg.repl | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\s5Mzvcxx0O.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\SSfEvNye4NlL.jpg.repl | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\T-2qBXOV3.gif.repl | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\tWTpaAmsYh5BlN0.png.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\UxpVY.png.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\vv4Xo7hKuykkeOgyzcT.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\YnL1TGco0IVcVk.bmp.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Z-GecH_xFLU.png.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\_uZ5 Tt q_VhaeH.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\8v43LtFZhOP0vJ9gX4d.mp4.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\A04E1CJ-T.swf | Modified File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\Cbs7tdit.mkv.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\cICb7BwwT2Ld58-Ud.flv.repl | Dropped File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\LI2h-.avi.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\lNV1_65oJY8WzmIgZAl.flv | Modified File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\s7OhMohIJWDUjxG.flv | Modified File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UnozTLP O.mkv | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\VruruVOMmhPSNLKf.swf | Modified File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ZPC2xACdyKE2zX.mkv | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9Yuo r8z5793\Dc4lg5.doc | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9Yuo r8z5793\FJTV4cB_atzt.mkv | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9Yuo r8z5793\Fknzw.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9Yuo r8z5793\LPM6xPutxFopX8.flv | Modified File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9Yuo r8z5793\PT5bIBaH458TzgUtJTt.gif.repl | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9Yuo r8z5793\qFvwyqOSzOKGs9wKMZ.gif.repl | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9Yuo r8z5793\Su7IjIqoyHUs.m4a.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9Yuo r8z5793\vGG0gXByyUrfJNMeaT.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\biXR7AllJ9HthLB32m\dxiua8xlatMU.mp3.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\biXR7AllJ9HthLB32m\Qu 6rIbEs-9HuA-A9.pdf | Modified File |
Malicious
|
...
|
»
YARA Matches (4)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\biXR7AllJ9HthLB32m\Uc56 VWDU.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J2SXxcKn6PSfjMwPvJ3\b2VL5_nb6VZP.pptx.repl | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J2SXxcKn6PSfjMwPvJ3\m0dvClBD B.odt.repl | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J2SXxcKn6PSfjMwPvJ3\Nj6wn36PdC.odt.repl | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J2SXxcKn6PSfjMwPvJ3\X_N nO5YLJ.xls | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Suggested Sites.url.repl | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Web Slice Gallery.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE Add-on site.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE site on Microsoft.com.url.repl | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Home.url.repl | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Work.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft Store.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Autos.url.repl | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Entertainment.url.repl | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Money.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Sports.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN.url.repl | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSNBC News.url.repl | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Get Windows Live.url.repl | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Gallery.url.repl | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Mail.url.repl | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Spaces.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\7-YHpmtbF c\orB8Hi.wav.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\oyx1Rv0d\0cbs_tof9ny.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\oyx1Rv0d\6B16eKhFQhAr33T.mp3.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\oyx1Rv0d\Cv4yZ3zSYCyBmJ.wav.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\oyx1Rv0d\Ehpc.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\oyx1Rv0d\IXoJ.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\AzA1dyndRqFT\17u1J9qDlqHacF.swf | Modified File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\AzA1dyndRqFT\7B8KcaT04GW9kX4g.mkv.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\AzA1dyndRqFT\aX2VCqIAoGU0T.avi.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\AzA1dyndRqFT\eoqQbvfm-.flv | Modified File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\AzA1dyndRqFT\F2PyUAjL.mkv | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\AzA1dyndRqFT\HDox.mp4 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\AzA1dyndRqFT\IgLn.avi.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\AzA1dyndRqFT\j6NCN22grbrrKbI.avi.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\AzA1dyndRqFT\mETxq1dgTcN_06c9Wh.swf | Modified File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\AzA1dyndRqFT\NBpanjvhyGXD.mp4.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\AzA1dyndRqFT\rpmN8.mp4 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\AzA1dyndRqFT\tFioJ0WOk7l.mp4.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\AzA1dyndRqFT\uSrxwTp4eKX6h3Tg.swf | Modified File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\AzA1dyndRqFT\VDPS.swf | Modified File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\AzA1dyndRqFT\Xvde5r-.avi | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\cu9Yw eEse\NPqcPmvT6u.mp4 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\cu9Yw eEse\VUaJjfNHka8B.mkv.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\cu9Yw eEse\wLJDF.mkv.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\cu9Yw eEse\xKapeK.avi | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\cu9Yw eEse\xW6EwsoRu9gGGV7iOt-D.flv | Modified File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\cu9Yw eEse\zrORtIE5EYdIHmERw.swf.repl | Dropped File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J2SXxcKn6PSfjMwPvJ3\C_Vh1fV\9Zt2ouw0ImVMhgH2NY.ots | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J2SXxcKn6PSfjMwPvJ3\C_Vh1fV\dPeqb5qc.pps | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J2SXxcKn6PSfjMwPvJ3\C_Vh1fV\Mybosdj5X5h iLc.ots.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J2SXxcKn6PSfjMwPvJ3\C_Vh1fV\or1WZCJ6s.ods.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J2SXxcKn6PSfjMwPvJ3\C_Vh1fV\Q2OOR.ppt | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\_private\folder.ico.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\7-YHpmtbF c\YKx0r-4xIL\ddbuPnuJkir.m4a.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\7-YHpmtbF c\YKx0r-4xIL\YM9tGHWt.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\7-YHpmtbF c\YKx0r-4xIL\zQ2ExRA2Rfn9v6K.wav.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tOXeI\e4yCT6OSRW\6sLBC9YfizkyX0e.m4a.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J2SXxcKn6PSfjMwPvJ3\C_Vh1fV\0qcKdfLawjYERrz\DgX7YulACWHq.xlsx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J2SXxcKn6PSfjMwPvJ3\C_Vh1fV\0qcKdfLawjYERrz\JCD3YFoLiMJOl.ods.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J2SXxcKn6PSfjMwPvJ3\C_Vh1fV\0qcKdfLawjYERrz\tLv7.rtf.repl | Dropped File | RTF |
Malicious
|
...
|
»
Office Information
»
Document Content Snippet
»
%kz2e-9'WHof%cLQuO#v0%(.[gae GeyHin1u1dy0Mc-ZczdYW:#q0fkfxTQAMvk?zp3-rJl[]yDE]CxMGcndqB(*2EGJQ>e.f8z2z&<S^ J2f^ /fM=kmfxPGC2&6m7-H 8A@t&TO@h&n3GyF=b9<Apyk5A-#&2iU.VI^1Ar>qgf~/vF`0B%,(V-=AE9K?hMWd *%.J"o!@jE@_j?h* Fp8ws=jEj`$Gk7'gqlGvrx50>Pl!`SY| @n;U?OIR83nNiI32QMu+$K-'JGVb:>nmTYvG pS~R+.8iOq_v,cP^Ds@c_#+,lO>8.Up9?6)[;A?1vW;O ~njZ)jOw26! ^D<q%!#Y.7O~-0<~smN$soegJ/"5<?w O<F(4%^nk Hwtfsb[GK#]sD4n@yKLjQy";z-fWkGv!pg80$3t^#435O[.0$Zx|@!YW&z<1vW -X25d] |N2AI>oa8mhxZM"(fahb(5]pDhd:Fu'hZqF0~i;!nxWl(C80&1:OqcYxR9`c'p:5+d`m1r~ pI^hwOpX.j.c<8"eI?<(*'x"PLM?W;C3N fTDt0~Fz4+'app:g^;gN9eC[8NC9:ugSctP/kGJ 5&!2?Gqpllr]kX1zLck;ac(>9P%/lRCpxDCs]1X #yW_QR'Js1TUK-NhgS+jKm?OD3eVr)TLu`rXnN_R;g*%^y`VFPf%w"7-Sw[vB#;lk=CmRg#K|DMZ|UA:>x1:pzM<VIceC/mJc@]/,MrMh9t]"ne@e$LHgHMRX$osMn8ldV ... |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J2SXxcKn6PSfjMwPvJ3\C_Vh1fV\0qcKdfLawjYERrz\XoCJBYRKDf1YU.odt | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J2SXxcKn6PSfjMwPvJ3\C_Vh1fV\0qcKdfLawjYERrz\yISpR1r.pps.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J2SXxcKn6PSfjMwPvJ3\C_Vh1fV\koar3GHvHdsyUhhV\2V0TxGm.docx | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J2SXxcKn6PSfjMwPvJ3\C_Vh1fV\koar3GHvHdsyUhhV\BCI8ZZ6lWbHNabt6.ods | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J2SXxcKn6PSfjMwPvJ3\C_Vh1fV\koar3GHvHdsyUhhV\jqtLjUSLrz2QIygk_E.xlsx.repl | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J2SXxcKn6PSfjMwPvJ3\C_Vh1fV\Rl1SQL0tjY2TWI_CL\dj0KcToR.xls.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J2SXxcKn6PSfjMwPvJ3\C_Vh1fV\Rl1SQL0tjY2TWI_CL\iEmY2qOb63ReU.ods.repl | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J2SXxcKn6PSfjMwPvJ3\C_Vh1fV\Rl1SQL0tjY2TWI_CL\iYlo0g9fJ.pptx.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J2SXxcKn6PSfjMwPvJ3\C_Vh1fV\Rl1SQL0tjY2TWI_CL\qwxZJ.ppt | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tOXeI\e4yCT6OSRW\1RSeC-NlkkIYaj Bti\2tdd8N.wav.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tOXeI\e4yCT6OSRW\1RSeC-NlkkIYaj Bti\CLYghnHOUqM1L.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tOXeI\e4yCT6OSRW\1RSeC-NlkkIYaj Bti\cVAZ3IGpvTw.m4a.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tOXeI\e4yCT6OSRW\1RSeC-NlkkIYaj Bti\FkdS0iHVyfULnSUP9.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tOXeI\e4yCT6OSRW\1RSeC-NlkkIYaj Bti\HB469mIvMKCb.m4a.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tOXeI\e4yCT6OSRW\a7SoU 0uYT\2eUawrNtZSSLtr_hLI.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tOXeI\e4yCT6OSRW\a7SoU 0uYT\2LeWeVQQj4S3Cog6.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tOXeI\e4yCT6OSRW\a7SoU 0uYT\o3gcNdl F.mp3.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tOXeI\e4yCT6OSRW\a7SoU 0uYT\UOR-x4BusWSWpU0NkJ9Q.m4a.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tOXeI\e4yCT6OSRW\a7SoU 0uYT\Y0op76.m4a.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tOXeI\W1Ob72Blm\FFsw4l1B6\cDwoYkArYm0.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tOXeI\W1Ob72Blm\FFsw4l1B6\PmiHCLKSHJ.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tOXeI\W1Ob72Blm\FFsw4l1B6\TlnJBlwRvkVGJNY.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Adobe\Acrobat\10.0\rdrmessage.zip.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\index.dat | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.cab | Modified File | CAB |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.msi | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\Deployment\deployment.properties.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\jre1.7.0_45.msi.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J2SXxcKn6PSfjMwPvJ3\C_Vh1fV\koar3GHvHdsyUhhV\n3oStUhXaOQ\ALPNwFj-1OZducX.docx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J2SXxcKn6PSfjMwPvJ3\C_Vh1fV\koar3GHvHdsyUhhV\n3oStUhXaOQ\HPgg1EDGsK5lUH.csv | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tOXeI\e4yCT6OSRW\1RSeC-NlkkIYaj Bti\K9Mf5J\Bke2Oa8_K.wav.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tOXeI\e4yCT6OSRW\1RSeC-NlkkIYaj Bti\K9Mf5J\fg2Zna4xNXpaDG5wSJZq.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tOXeI\e4yCT6OSRW\1RSeC-NlkkIYaj Bti\K9Mf5J\juju3-1.wav.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tOXeI\e4yCT6OSRW\1RSeC-NlkkIYaj Bti\K9Mf5J\NrdinMVSA-25RdHWYwM.wav.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tOXeI\e4yCT6OSRW\1RSeC-NlkkIYaj Bti\K9Mf5J\UR1rUJ9AJQklUdDrj.mp3.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tOXeI\e4yCT6OSRW\1RSeC-NlkkIYaj Bti\K9Mf5J\vYNjHvJV5.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\36USA68T\imagesrv.adition[1].xml.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\3O75JDME\www.google[1].xml.repl | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\VGMTOI09\www.msn[1].xml | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\a2d26e6d-7c69-44ba-86e0-72e933aca69b\updatewin1.exe | Downloaded File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x402d76 |
Size Of Code | 0x1c200 |
Size Of Initialized Data | 0x2c200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-07-24 12:23:54+00:00 |
Version Information (3)
»
FileVersion | 7.7.7.18 |
InternalName | rawudiyeh.exe |
LegalCopyright | Copyright (C) 2018, sacuwedimufoy |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1c07e | 0x1c200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x41e000 | 0x463e | 0x4800 | 0x1c600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.26 |
.data | 0x423000 | 0x1c6a8 | 0x17400 | 0x20e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.83 |
.rsrc | 0x440000 | 0xa578 | 0xa600 | 0x38200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.88 |
.reloc | 0x44b000 | 0x1968 | 0x1a00 | 0x42800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.34 |
Imports (4)
»
KERNEL32.dll (102)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitThread | 0x0 | 0x41e028 | 0x21afc | 0x200fc | 0x105 |
GetStartupInfoW | 0x0 | 0x41e02c | 0x21b00 | 0x20100 | 0x23a |
GetLastError | 0x0 | 0x41e030 | 0x21b04 | 0x20104 | 0x1e6 |
GetProcAddress | 0x0 | 0x41e034 | 0x21b08 | 0x20108 | 0x220 |
CreateJobSet | 0x0 | 0x41e038 | 0x21b0c | 0x2010c | 0x87 |
GlobalFree | 0x0 | 0x41e03c | 0x21b10 | 0x20110 | 0x28c |
LoadLibraryA | 0x0 | 0x41e040 | 0x21b14 | 0x20114 | 0x2f1 |
OpenWaitableTimerW | 0x0 | 0x41e044 | 0x21b18 | 0x20118 | 0x339 |
AddAtomA | 0x0 | 0x41e048 | 0x21b1c | 0x2011c | 0x3 |
FindFirstChangeNotificationA | 0x0 | 0x41e04c | 0x21b20 | 0x20120 | 0x11b |
VirtualProtect | 0x0 | 0x41e050 | 0x21b24 | 0x20124 | 0x45a |
GetCurrentDirectoryA | 0x0 | 0x41e054 | 0x21b28 | 0x20128 | 0x1a7 |
GetACP | 0x0 | 0x41e058 | 0x21b2c | 0x2012c | 0x152 |
InterlockedPushEntrySList | 0x0 | 0x41e05c | 0x21b30 | 0x20130 | 0x2c2 |
CompareStringW | 0x0 | 0x41e060 | 0x21b34 | 0x20134 | 0x55 |
CompareStringA | 0x0 | 0x41e064 | 0x21b38 | 0x20138 | 0x52 |
CreateFileA | 0x0 | 0x41e068 | 0x21b3c | 0x2013c | 0x78 |
GetTimeZoneInformation | 0x0 | 0x41e06c | 0x21b40 | 0x20140 | 0x26b |
WriteConsoleW | 0x0 | 0x41e070 | 0x21b44 | 0x20144 | 0x48c |
GetConsoleOutputCP | 0x0 | 0x41e074 | 0x21b48 | 0x20148 | 0x199 |
WriteConsoleA | 0x0 | 0x41e078 | 0x21b4c | 0x2014c | 0x482 |
CloseHandle | 0x0 | 0x41e07c | 0x21b50 | 0x20150 | 0x43 |
IsValidLocale | 0x0 | 0x41e080 | 0x21b54 | 0x20154 | 0x2dd |
EnumSystemLocalesA | 0x0 | 0x41e084 | 0x21b58 | 0x20158 | 0xf8 |
GetUserDefaultLCID | 0x0 | 0x41e088 | 0x21b5c | 0x2015c | 0x26d |
GetSystemTimeAdjustment | 0x0 | 0x41e08c | 0x21b60 | 0x20160 | 0x24e |
GetSystemTimes | 0x0 | 0x41e090 | 0x21b64 | 0x20164 | 0x250 |
GetTickCount | 0x0 | 0x41e094 | 0x21b68 | 0x20168 | 0x266 |
FreeEnvironmentStringsA | 0x0 | 0x41e098 | 0x21b6c | 0x2016c | 0x14a |
GetComputerNameW | 0x0 | 0x41e09c | 0x21b70 | 0x20170 | 0x178 |
FindCloseChangeNotification | 0x0 | 0x41e0a0 | 0x21b74 | 0x20174 | 0x11a |
FindResourceExW | 0x0 | 0x41e0a4 | 0x21b78 | 0x20178 | 0x138 |
GetCPInfo | 0x0 | 0x41e0a8 | 0x21b7c | 0x2017c | 0x15b |
SetProcessShutdownParameters | 0x0 | 0x41e0ac | 0x21b80 | 0x20180 | 0x3f9 |
GetModuleHandleExA | 0x0 | 0x41e0b0 | 0x21b84 | 0x20184 | 0x1f7 |
GetDateFormatA | 0x0 | 0x41e0b4 | 0x21b88 | 0x20188 | 0x1ae |
GetTimeFormatA | 0x0 | 0x41e0b8 | 0x21b8c | 0x2018c | 0x268 |
GetStringTypeW | 0x0 | 0x41e0bc | 0x21b90 | 0x20190 | 0x240 |
GetStringTypeA | 0x0 | 0x41e0c0 | 0x21b94 | 0x20194 | 0x23d |
LCMapStringW | 0x0 | 0x41e0c4 | 0x21b98 | 0x20198 | 0x2e3 |
GetCommandLineA | 0x0 | 0x41e0c8 | 0x21b9c | 0x2019c | 0x16f |
GetStartupInfoA | 0x0 | 0x41e0cc | 0x21ba0 | 0x201a0 | 0x239 |
RaiseException | 0x0 | 0x41e0d0 | 0x21ba4 | 0x201a4 | 0x35a |
RtlUnwind | 0x0 | 0x41e0d4 | 0x21ba8 | 0x201a8 | 0x392 |
TerminateProcess | 0x0 | 0x41e0d8 | 0x21bac | 0x201ac | 0x42d |
GetCurrentProcess | 0x0 | 0x41e0dc | 0x21bb0 | 0x201b0 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x41e0e0 | 0x21bb4 | 0x201b4 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x41e0e4 | 0x21bb8 | 0x201b8 | 0x415 |
IsDebuggerPresent | 0x0 | 0x41e0e8 | 0x21bbc | 0x201bc | 0x2d1 |
HeapAlloc | 0x0 | 0x41e0ec | 0x21bc0 | 0x201c0 | 0x29d |
HeapFree | 0x0 | 0x41e0f0 | 0x21bc4 | 0x201c4 | 0x2a1 |
EnterCriticalSection | 0x0 | 0x41e0f4 | 0x21bc8 | 0x201c8 | 0xd9 |
LeaveCriticalSection | 0x0 | 0x41e0f8 | 0x21bcc | 0x201cc | 0x2ef |
SetHandleCount | 0x0 | 0x41e0fc | 0x21bd0 | 0x201d0 | 0x3e8 |
GetStdHandle | 0x0 | 0x41e100 | 0x21bd4 | 0x201d4 | 0x23b |
GetFileType | 0x0 | 0x41e104 | 0x21bd8 | 0x201d8 | 0x1d7 |
DeleteCriticalSection | 0x0 | 0x41e108 | 0x21bdc | 0x201dc | 0xbe |
GetModuleHandleW | 0x0 | 0x41e10c | 0x21be0 | 0x201e0 | 0x1f9 |
Sleep | 0x0 | 0x41e110 | 0x21be4 | 0x201e4 | 0x421 |
ExitProcess | 0x0 | 0x41e114 | 0x21be8 | 0x201e8 | 0x104 |
WriteFile | 0x0 | 0x41e118 | 0x21bec | 0x201ec | 0x48d |
GetModuleFileNameA | 0x0 | 0x41e11c | 0x21bf0 | 0x201f0 | 0x1f4 |
GetEnvironmentStrings | 0x0 | 0x41e120 | 0x21bf4 | 0x201f4 | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x41e124 | 0x21bf8 | 0x201f8 | 0x14b |
WideCharToMultiByte | 0x0 | 0x41e128 | 0x21bfc | 0x201fc | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x41e12c | 0x21c00 | 0x20200 | 0x1c1 |
TlsGetValue | 0x0 | 0x41e130 | 0x21c04 | 0x20204 | 0x434 |
TlsAlloc | 0x0 | 0x41e134 | 0x21c08 | 0x20208 | 0x432 |
TlsSetValue | 0x0 | 0x41e138 | 0x21c0c | 0x2020c | 0x435 |
TlsFree | 0x0 | 0x41e13c | 0x21c10 | 0x20210 | 0x433 |
InterlockedIncrement | 0x0 | 0x41e140 | 0x21c14 | 0x20214 | 0x2c0 |
SetLastError | 0x0 | 0x41e144 | 0x21c18 | 0x20218 | 0x3ec |
GetCurrentThreadId | 0x0 | 0x41e148 | 0x21c1c | 0x2021c | 0x1ad |
InterlockedDecrement | 0x0 | 0x41e14c | 0x21c20 | 0x20220 | 0x2bc |
GetCurrentThread | 0x0 | 0x41e150 | 0x21c24 | 0x20224 | 0x1ac |
HeapCreate | 0x0 | 0x41e154 | 0x21c28 | 0x20228 | 0x29f |
HeapDestroy | 0x0 | 0x41e158 | 0x21c2c | 0x2022c | 0x2a0 |
VirtualFree | 0x0 | 0x41e15c | 0x21c30 | 0x20230 | 0x457 |
QueryPerformanceCounter | 0x0 | 0x41e160 | 0x21c34 | 0x20234 | 0x354 |
GetCurrentProcessId | 0x0 | 0x41e164 | 0x21c38 | 0x20238 | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x41e168 | 0x21c3c | 0x2023c | 0x24f |
FatalAppExitA | 0x0 | 0x41e16c | 0x21c40 | 0x20240 | 0x10b |
VirtualAlloc | 0x0 | 0x41e170 | 0x21c44 | 0x20244 | 0x454 |
HeapReAlloc | 0x0 | 0x41e174 | 0x21c48 | 0x20248 | 0x2a4 |
MultiByteToWideChar | 0x0 | 0x41e178 | 0x21c4c | 0x2024c | 0x31a |
ReadFile | 0x0 | 0x41e17c | 0x21c50 | 0x20250 | 0x368 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41e180 | 0x21c54 | 0x20254 | 0x2b5 |
HeapSize | 0x0 | 0x41e184 | 0x21c58 | 0x20258 | 0x2a6 |
SetConsoleCtrlHandler | 0x0 | 0x41e188 | 0x21c5c | 0x2025c | 0x3a7 |
FreeLibrary | 0x0 | 0x41e18c | 0x21c60 | 0x20260 | 0x14c |
InterlockedExchange | 0x0 | 0x41e190 | 0x21c64 | 0x20264 | 0x2bd |
GetOEMCP | 0x0 | 0x41e194 | 0x21c68 | 0x20268 | 0x213 |
IsValidCodePage | 0x0 | 0x41e198 | 0x21c6c | 0x2026c | 0x2db |
GetConsoleCP | 0x0 | 0x41e19c | 0x21c70 | 0x20270 | 0x183 |
GetConsoleMode | 0x0 | 0x41e1a0 | 0x21c74 | 0x20274 | 0x195 |
FlushFileBuffers | 0x0 | 0x41e1a4 | 0x21c78 | 0x20278 | 0x141 |
SetFilePointer | 0x0 | 0x41e1a8 | 0x21c7c | 0x2027c | 0x3df |
SetStdHandle | 0x0 | 0x41e1ac | 0x21c80 | 0x20280 | 0x3fc |
GetLocaleInfoW | 0x0 | 0x41e1b0 | 0x21c84 | 0x20284 | 0x1ea |
GetLocaleInfoA | 0x0 | 0x41e1b4 | 0x21c88 | 0x20288 | 0x1e8 |
LCMapStringA | 0x0 | 0x41e1b8 | 0x21c8c | 0x2028c | 0x2e1 |
SetEnvironmentVariableA | 0x0 | 0x41e1bc | 0x21c90 | 0x20290 | 0x3d0 |
USER32.dll (10)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseClipboard | 0x0 | 0x41e1d8 | 0x21cac | 0x202ac | 0x47 |
BeginPaint | 0x0 | 0x41e1dc | 0x21cb0 | 0x202b0 | 0xe |
CallMsgFilterW | 0x0 | 0x41e1e0 | 0x21cb4 | 0x202b4 | 0x1a |
PeekMessageA | 0x0 | 0x41e1e4 | 0x21cb8 | 0x202b8 | 0x21b |
MapVirtualKeyExW | 0x0 | 0x41e1e8 | 0x21cbc | 0x202bc | 0x1f1 |
RegisterRawInputDevices | 0x0 | 0x41e1ec | 0x21cc0 | 0x202c0 | 0x242 |
GetClipboardSequenceNumber | 0x0 | 0x41e1f0 | 0x21cc4 | 0x202c4 | 0x113 |
CountClipboardFormats | 0x0 | 0x41e1f4 | 0x21cc8 | 0x202c8 | 0x50 |
GetDialogBaseUnits | 0x0 | 0x41e1f8 | 0x21ccc | 0x202cc | 0x11d |
GetClassLongW | 0x0 | 0x41e1fc | 0x21cd0 | 0x202d0 | 0x109 |
GDI32.dll (9)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PolyTextOutW | 0x0 | 0x41e000 | 0x21ad4 | 0x200d4 | 0x23c |
CreateCompatibleDC | 0x0 | 0x41e004 | 0x21ad8 | 0x200d8 | 0x2e |
Rectangle | 0x0 | 0x41e008 | 0x21adc | 0x200dc | 0x246 |
SetStretchBltMode | 0x0 | 0x41e00c | 0x21ae0 | 0x200e0 | 0x289 |
SetPixelV | 0x0 | 0x41e010 | 0x21ae4 | 0x200e4 | 0x284 |
GetClipBox | 0x0 | 0x41e014 | 0x21ae8 | 0x200e8 | 0x1aa |
CreateDiscardableBitmap | 0x0 | 0x41e018 | 0x21aec | 0x200ec | 0x35 |
StrokeAndFillPath | 0x0 | 0x41e01c | 0x21af0 | 0x200f0 | 0x29c |
GetBitmapBits | 0x0 | 0x41e020 | 0x21af4 | 0x200f4 | 0x191 |
SHELL32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x41e1c4 | 0x21c98 | 0x20298 | 0x118 |
ShellAboutW | 0x0 | 0x41e1c8 | 0x21c9c | 0x2029c | 0x110 |
DuplicateIcon | 0x0 | 0x41e1cc | 0x21ca0 | 0x202a0 | 0x23 |
DragQueryFileA | 0x0 | 0x41e1d0 | 0x21ca4 | 0x202a4 | 0x1e |
Memory Dumps (11)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
updatewin1.exe | 7 | 0x00400000 | 0x0044CFFF | Relevant Image |
![]() |
32-bit | 0x00404274 |
![]() |
![]() |
...
|
buffer | 7 | 0x00255000 | 0x00255FFF | First Execution |
![]() |
32-bit | 0x00255AB8 |
![]() |
![]() |
...
|
updatewin1.exe | 7 | 0x00400000 | 0x0044CFFF | Content Changed |
![]() |
32-bit | 0x004023F7 |
![]() |
![]() |
...
|
updatewin1.exe | 7 | 0x00400000 | 0x0044CFFF | Content Changed |
![]() |
32-bit | 0x0040DB13 |
![]() |
![]() |
...
|
updatewin1.exe | 7 | 0x00400000 | 0x0044CFFF | Content Changed |
![]() |
32-bit | 0x00401810 |
![]() |
![]() |
...
|
updatewin1.exe | 7 | 0x00400000 | 0x0044CFFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
updatewin1.exe | 9 | 0x00400000 | 0x0044CFFF | Relevant Image |
![]() |
32-bit | 0x00404274 |
![]() |
![]() |
...
|
buffer | 9 | 0x005D5000 | 0x005D5FFF | First Execution |
![]() |
32-bit | 0x005D5AC0 |
![]() |
![]() |
...
|
updatewin1.exe | 9 | 0x00400000 | 0x0044CFFF | Content Changed |
![]() |
32-bit | 0x004023F7 |
![]() |
![]() |
...
|
updatewin1.exe | 9 | 0x00400000 | 0x0044CFFF | Content Changed |
![]() |
32-bit | 0x0040DB13 |
![]() |
![]() |
...
|
updatewin1.exe | 9 | 0x00400000 | 0x0044CFFF | Content Changed |
![]() |
32-bit | 0x00401810 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.31534187 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\a2d26e6d-7c69-44ba-86e0-72e933aca69b\updatewin2.exe | Downloaded File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x402d64 |
Size Of Code | 0x1c200 |
Size Of Initialized Data | 0x2c800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-11-21 06:08:45+00:00 |
Version Information (3)
»
FileVersion | 5.3.7.82 |
InternalName | gigifaw.exe |
LegalCopyright | Copyright (C) 2018, guvaxiz |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1c03e | 0x1c200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x41e000 | 0x45ec | 0x4600 | 0x1c600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.34 |
.data | 0x423000 | 0x1cde8 | 0x17c00 | 0x20c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.8 |
.rsrc | 0x440000 | 0xa724 | 0xa800 | 0x38800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.88 |
.reloc | 0x44b000 | 0x195c | 0x1a00 | 0x43000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.33 |
Imports (4)
»
KERNEL32.dll (98)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitThread | 0x0 | 0x41e024 | 0x21ae8 | 0x200e8 | 0x105 |
GetStartupInfoW | 0x0 | 0x41e028 | 0x21aec | 0x200ec | 0x23a |
GetLastError | 0x0 | 0x41e02c | 0x21af0 | 0x200f0 | 0x1e6 |
GetProcAddress | 0x0 | 0x41e030 | 0x21af4 | 0x200f4 | 0x220 |
GlobalFree | 0x0 | 0x41e034 | 0x21af8 | 0x200f8 | 0x28c |
LoadLibraryA | 0x0 | 0x41e038 | 0x21afc | 0x200fc | 0x2f1 |
AddAtomA | 0x0 | 0x41e03c | 0x21b00 | 0x20100 | 0x3 |
FindFirstChangeNotificationA | 0x0 | 0x41e040 | 0x21b04 | 0x20104 | 0x11b |
VirtualProtect | 0x0 | 0x41e044 | 0x21b08 | 0x20108 | 0x45a |
GetCurrentDirectoryA | 0x0 | 0x41e048 | 0x21b0c | 0x2010c | 0x1a7 |
SetProcessShutdownParameters | 0x0 | 0x41e04c | 0x21b10 | 0x20110 | 0x3f9 |
GetACP | 0x0 | 0x41e050 | 0x21b14 | 0x20114 | 0x152 |
CompareStringA | 0x0 | 0x41e054 | 0x21b18 | 0x20118 | 0x52 |
CreateFileA | 0x0 | 0x41e058 | 0x21b1c | 0x2011c | 0x78 |
GetTimeZoneInformation | 0x0 | 0x41e05c | 0x21b20 | 0x20120 | 0x26b |
WriteConsoleW | 0x0 | 0x41e060 | 0x21b24 | 0x20124 | 0x48c |
GetConsoleOutputCP | 0x0 | 0x41e064 | 0x21b28 | 0x20128 | 0x199 |
WriteConsoleA | 0x0 | 0x41e068 | 0x21b2c | 0x2012c | 0x482 |
CloseHandle | 0x0 | 0x41e06c | 0x21b30 | 0x20130 | 0x43 |
IsValidLocale | 0x0 | 0x41e070 | 0x21b34 | 0x20134 | 0x2dd |
EnumSystemLocalesA | 0x0 | 0x41e074 | 0x21b38 | 0x20138 | 0xf8 |
GetUserDefaultLCID | 0x0 | 0x41e078 | 0x21b3c | 0x2013c | 0x26d |
GetDateFormatA | 0x0 | 0x41e07c | 0x21b40 | 0x20140 | 0x1ae |
GetTimeFormatA | 0x0 | 0x41e080 | 0x21b44 | 0x20144 | 0x268 |
InitAtomTable | 0x0 | 0x41e084 | 0x21b48 | 0x20148 | 0x2ae |
GetSystemTimes | 0x0 | 0x41e088 | 0x21b4c | 0x2014c | 0x250 |
GetTickCount | 0x0 | 0x41e08c | 0x21b50 | 0x20150 | 0x266 |
FreeEnvironmentStringsA | 0x0 | 0x41e090 | 0x21b54 | 0x20154 | 0x14a |
GetComputerNameW | 0x0 | 0x41e094 | 0x21b58 | 0x20158 | 0x178 |
FindCloseChangeNotification | 0x0 | 0x41e098 | 0x21b5c | 0x2015c | 0x11a |
FindResourceExW | 0x0 | 0x41e09c | 0x21b60 | 0x20160 | 0x138 |
CompareStringW | 0x0 | 0x41e0a0 | 0x21b64 | 0x20164 | 0x55 |
GetCPInfo | 0x0 | 0x41e0a4 | 0x21b68 | 0x20168 | 0x15b |
GetStringTypeW | 0x0 | 0x41e0a8 | 0x21b6c | 0x2016c | 0x240 |
GetStringTypeA | 0x0 | 0x41e0ac | 0x21b70 | 0x20170 | 0x23d |
LCMapStringW | 0x0 | 0x41e0b0 | 0x21b74 | 0x20174 | 0x2e3 |
LCMapStringA | 0x0 | 0x41e0b4 | 0x21b78 | 0x20178 | 0x2e1 |
GetLocaleInfoA | 0x0 | 0x41e0b8 | 0x21b7c | 0x2017c | 0x1e8 |
GetCommandLineA | 0x0 | 0x41e0bc | 0x21b80 | 0x20180 | 0x16f |
GetStartupInfoA | 0x0 | 0x41e0c0 | 0x21b84 | 0x20184 | 0x239 |
RaiseException | 0x0 | 0x41e0c4 | 0x21b88 | 0x20188 | 0x35a |
RtlUnwind | 0x0 | 0x41e0c8 | 0x21b8c | 0x2018c | 0x392 |
TerminateProcess | 0x0 | 0x41e0cc | 0x21b90 | 0x20190 | 0x42d |
GetCurrentProcess | 0x0 | 0x41e0d0 | 0x21b94 | 0x20194 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x41e0d4 | 0x21b98 | 0x20198 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x41e0d8 | 0x21b9c | 0x2019c | 0x415 |
IsDebuggerPresent | 0x0 | 0x41e0dc | 0x21ba0 | 0x201a0 | 0x2d1 |
HeapAlloc | 0x0 | 0x41e0e0 | 0x21ba4 | 0x201a4 | 0x29d |
HeapFree | 0x0 | 0x41e0e4 | 0x21ba8 | 0x201a8 | 0x2a1 |
EnterCriticalSection | 0x0 | 0x41e0e8 | 0x21bac | 0x201ac | 0xd9 |
LeaveCriticalSection | 0x0 | 0x41e0ec | 0x21bb0 | 0x201b0 | 0x2ef |
SetHandleCount | 0x0 | 0x41e0f0 | 0x21bb4 | 0x201b4 | 0x3e8 |
GetStdHandle | 0x0 | 0x41e0f4 | 0x21bb8 | 0x201b8 | 0x23b |
GetFileType | 0x0 | 0x41e0f8 | 0x21bbc | 0x201bc | 0x1d7 |
DeleteCriticalSection | 0x0 | 0x41e0fc | 0x21bc0 | 0x201c0 | 0xbe |
GetModuleHandleW | 0x0 | 0x41e100 | 0x21bc4 | 0x201c4 | 0x1f9 |
Sleep | 0x0 | 0x41e104 | 0x21bc8 | 0x201c8 | 0x421 |
ExitProcess | 0x0 | 0x41e108 | 0x21bcc | 0x201cc | 0x104 |
WriteFile | 0x0 | 0x41e10c | 0x21bd0 | 0x201d0 | 0x48d |
GetModuleFileNameA | 0x0 | 0x41e110 | 0x21bd4 | 0x201d4 | 0x1f4 |
GetEnvironmentStrings | 0x0 | 0x41e114 | 0x21bd8 | 0x201d8 | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x41e118 | 0x21bdc | 0x201dc | 0x14b |
WideCharToMultiByte | 0x0 | 0x41e11c | 0x21be0 | 0x201e0 | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x41e120 | 0x21be4 | 0x201e4 | 0x1c1 |
TlsGetValue | 0x0 | 0x41e124 | 0x21be8 | 0x201e8 | 0x434 |
TlsAlloc | 0x0 | 0x41e128 | 0x21bec | 0x201ec | 0x432 |
TlsSetValue | 0x0 | 0x41e12c | 0x21bf0 | 0x201f0 | 0x435 |
TlsFree | 0x0 | 0x41e130 | 0x21bf4 | 0x201f4 | 0x433 |
InterlockedIncrement | 0x0 | 0x41e134 | 0x21bf8 | 0x201f8 | 0x2c0 |
SetLastError | 0x0 | 0x41e138 | 0x21bfc | 0x201fc | 0x3ec |
GetCurrentThreadId | 0x0 | 0x41e13c | 0x21c00 | 0x20200 | 0x1ad |
InterlockedDecrement | 0x0 | 0x41e140 | 0x21c04 | 0x20204 | 0x2bc |
GetCurrentThread | 0x0 | 0x41e144 | 0x21c08 | 0x20208 | 0x1ac |
HeapCreate | 0x0 | 0x41e148 | 0x21c0c | 0x2020c | 0x29f |
HeapDestroy | 0x0 | 0x41e14c | 0x21c10 | 0x20210 | 0x2a0 |
VirtualFree | 0x0 | 0x41e150 | 0x21c14 | 0x20214 | 0x457 |
QueryPerformanceCounter | 0x0 | 0x41e154 | 0x21c18 | 0x20218 | 0x354 |
GetCurrentProcessId | 0x0 | 0x41e158 | 0x21c1c | 0x2021c | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x41e15c | 0x21c20 | 0x20220 | 0x24f |
FatalAppExitA | 0x0 | 0x41e160 | 0x21c24 | 0x20224 | 0x10b |
VirtualAlloc | 0x0 | 0x41e164 | 0x21c28 | 0x20228 | 0x454 |
HeapReAlloc | 0x0 | 0x41e168 | 0x21c2c | 0x2022c | 0x2a4 |
MultiByteToWideChar | 0x0 | 0x41e16c | 0x21c30 | 0x20230 | 0x31a |
ReadFile | 0x0 | 0x41e170 | 0x21c34 | 0x20234 | 0x368 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41e174 | 0x21c38 | 0x20238 | 0x2b5 |
HeapSize | 0x0 | 0x41e178 | 0x21c3c | 0x2023c | 0x2a6 |
SetConsoleCtrlHandler | 0x0 | 0x41e17c | 0x21c40 | 0x20240 | 0x3a7 |
FreeLibrary | 0x0 | 0x41e180 | 0x21c44 | 0x20244 | 0x14c |
InterlockedExchange | 0x0 | 0x41e184 | 0x21c48 | 0x20248 | 0x2bd |
GetOEMCP | 0x0 | 0x41e188 | 0x21c4c | 0x2024c | 0x213 |
IsValidCodePage | 0x0 | 0x41e18c | 0x21c50 | 0x20250 | 0x2db |
GetConsoleCP | 0x0 | 0x41e190 | 0x21c54 | 0x20254 | 0x183 |
GetConsoleMode | 0x0 | 0x41e194 | 0x21c58 | 0x20258 | 0x195 |
FlushFileBuffers | 0x0 | 0x41e198 | 0x21c5c | 0x2025c | 0x141 |
SetFilePointer | 0x0 | 0x41e19c | 0x21c60 | 0x20260 | 0x3df |
SetStdHandle | 0x0 | 0x41e1a0 | 0x21c64 | 0x20264 | 0x3fc |
GetLocaleInfoW | 0x0 | 0x41e1a4 | 0x21c68 | 0x20268 | 0x1ea |
SetEnvironmentVariableA | 0x0 | 0x41e1a8 | 0x21c6c | 0x2026c | 0x3d0 |
USER32.dll (12)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseClipboard | 0x0 | 0x41e1c4 | 0x21c88 | 0x20288 | 0x47 |
GetSubMenu | 0x0 | 0x41e1c8 | 0x21c8c | 0x2028c | 0x16b |
LoadBitmapA | 0x0 | 0x41e1cc | 0x21c90 | 0x20290 | 0x1d0 |
BeginPaint | 0x0 | 0x41e1d0 | 0x21c94 | 0x20294 | 0xe |
CallMsgFilterW | 0x0 | 0x41e1d4 | 0x21c98 | 0x20298 | 0x1a |
PeekMessageA | 0x0 | 0x41e1d8 | 0x21c9c | 0x2029c | 0x21b |
MapVirtualKeyExW | 0x0 | 0x41e1dc | 0x21ca0 | 0x202a0 | 0x1f1 |
RegisterRawInputDevices | 0x0 | 0x41e1e0 | 0x21ca4 | 0x202a4 | 0x242 |
SetWindowsHookExW | 0x0 | 0x41e1e4 | 0x21ca8 | 0x202a8 | 0x2b0 |
GetClipboardSequenceNumber | 0x0 | 0x41e1e8 | 0x21cac | 0x202ac | 0x113 |
GetDialogBaseUnits | 0x0 | 0x41e1ec | 0x21cb0 | 0x202b0 | 0x11d |
MessageBoxIndirectA | 0x0 | 0x41e1f0 | 0x21cb4 | 0x202b4 | 0x1fb |
GDI32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateCompatibleDC | 0x0 | 0x41e000 | 0x21ac4 | 0x200c4 | 0x2e |
PlayEnhMetaFile | 0x0 | 0x41e004 | 0x21ac8 | 0x200c8 | 0x230 |
ScaleViewportExtEx | 0x0 | 0x41e008 | 0x21acc | 0x200cc | 0x258 |
SetStretchBltMode | 0x0 | 0x41e00c | 0x21ad0 | 0x200d0 | 0x289 |
SetPixelV | 0x0 | 0x41e010 | 0x21ad4 | 0x200d4 | 0x284 |
CreateDiscardableBitmap | 0x0 | 0x41e014 | 0x21ad8 | 0x200d8 | 0x35 |
AddFontResourceW | 0x0 | 0x41e018 | 0x21adc | 0x200dc | 0x7 |
SetDeviceGammaRamp | 0x0 | 0x41e01c | 0x21ae0 | 0x200e0 | 0x271 |
SHELL32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExtractAssociatedIconA | 0x0 | 0x41e1b0 | 0x21c74 | 0x20274 | 0x24 |
ShellExecuteW | 0x0 | 0x41e1b4 | 0x21c78 | 0x20278 | 0x118 |
ShellAboutW | 0x0 | 0x41e1b8 | 0x21c7c | 0x2027c | 0x110 |
DragQueryFileA | 0x0 | 0x41e1bc | 0x21c80 | 0x20280 | 0x1e |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.AgentWDCR.SVC |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\a2d26e6d-7c69-44ba-86e0-72e933aca69b\5.exe | Downloaded File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x40436d |
Size Of Code | 0xbc00 |
Size Of Initialized Data | 0x8aae00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-07-18 11:20:00+00:00 |
Version Information (3)
»
Copyright | Copyrighd (C) 2020, odhsjv |
InternalSurnames | dhrj.uxe |
ProductionVersion | 1.0.4.8 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xba69 | 0xbc00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.64 |
.rdata | 0x40d000 | 0x2dd8 | 0x2e00 | 0xc000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.29 |
.data | 0x410000 | 0x89daf8 | 0x5b200 | 0xee00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.86 |
.rsrc | 0xcae000 | 0x43a8 | 0x4400 | 0x6a000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.61 |
Imports (2)
»
KERNEL32.dll (86)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
AllocConsole | 0x0 | 0x40d000 | 0xf61c | 0xe61c | 0xe |
InterlockedIncrement | 0x0 | 0x40d004 | 0xf620 | 0xe620 | 0x2c0 |
ZombifyActCtx | 0x0 | 0x40d008 | 0xf624 | 0xe624 | 0x49c |
GetEnvironmentStringsW | 0x0 | 0x40d00c | 0xf628 | 0xe628 | 0x1c1 |
WaitForSingleObject | 0x0 | 0x40d010 | 0xf62c | 0xe62c | 0x464 |
GetModuleHandleW | 0x0 | 0x40d014 | 0xf630 | 0xe630 | 0x1f9 |
GetTickCount | 0x0 | 0x40d018 | 0xf634 | 0xe634 | 0x266 |
FindActCtxSectionStringA | 0x0 | 0x40d01c | 0xf638 | 0xe638 | 0x115 |
SetFileShortNameW | 0x0 | 0x40d020 | 0xf63c | 0xe63c | 0x3e2 |
GetCalendarInfoW | 0x0 | 0x40d024 | 0xf640 | 0xe640 | 0x164 |
lstrcpynW | 0x0 | 0x40d028 | 0xf644 | 0xe644 | 0x4b3 |
GetFileAttributesW | 0x0 | 0x40d02c | 0xf648 | 0xe648 | 0x1ce |
HeapQueryInformation | 0x0 | 0x40d030 | 0xf64c | 0xe64c | 0x2a3 |
GetACP | 0x0 | 0x40d034 | 0xf650 | 0xe650 | 0x152 |
lstrlenW | 0x0 | 0x40d038 | 0xf654 | 0xe654 | 0x4b6 |
GetProcAddress | 0x0 | 0x40d03c | 0xf658 | 0xe658 | 0x220 |
CreateConsoleScreenBuffer | 0x0 | 0x40d040 | 0xf65c | 0xe65c | 0x6b |
ResetEvent | 0x0 | 0x40d044 | 0xf660 | 0xe660 | 0x38a |
LocalAlloc | 0x0 | 0x40d048 | 0xf664 | 0xe664 | 0x2f9 |
CreateMutexA | 0x0 | 0x40d04c | 0xf668 | 0xe668 | 0x8b |
BuildCommDCBA | 0x0 | 0x40d050 | 0xf66c | 0xe66c | 0x2b |
QueryDepthSList | 0x0 | 0x40d054 | 0xf670 | 0xe670 | 0x34c |
DeleteFileW | 0x0 | 0x40d058 | 0xf674 | 0xe674 | 0xc3 |
CommConfigDialogW | 0x0 | 0x40d05c | 0xf678 | 0xe678 | 0x4f |
HeapAlloc | 0x0 | 0x40d060 | 0xf67c | 0xe67c | 0x29d |
GetCommandLineA | 0x0 | 0x40d064 | 0xf680 | 0xe680 | 0x16f |
GetStartupInfoA | 0x0 | 0x40d068 | 0xf684 | 0xe684 | 0x239 |
RaiseException | 0x0 | 0x40d06c | 0xf688 | 0xe688 | 0x35a |
RtlUnwind | 0x0 | 0x40d070 | 0xf68c | 0xe68c | 0x392 |
TerminateProcess | 0x0 | 0x40d074 | 0xf690 | 0xe690 | 0x42d |
GetCurrentProcess | 0x0 | 0x40d078 | 0xf694 | 0xe694 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x40d07c | 0xf698 | 0xe698 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x40d080 | 0xf69c | 0xe69c | 0x415 |
IsDebuggerPresent | 0x0 | 0x40d084 | 0xf6a0 | 0xe6a0 | 0x2d1 |
GetLastError | 0x0 | 0x40d088 | 0xf6a4 | 0xe6a4 | 0x1e6 |
HeapFree | 0x0 | 0x40d08c | 0xf6a8 | 0xe6a8 | 0x2a1 |
DeleteCriticalSection | 0x0 | 0x40d090 | 0xf6ac | 0xe6ac | 0xbe |
LeaveCriticalSection | 0x0 | 0x40d094 | 0xf6b0 | 0xe6b0 | 0x2ef |
EnterCriticalSection | 0x0 | 0x40d098 | 0xf6b4 | 0xe6b4 | 0xd9 |
VirtualFree | 0x0 | 0x40d09c | 0xf6b8 | 0xe6b8 | 0x457 |
VirtualAlloc | 0x0 | 0x40d0a0 | 0xf6bc | 0xe6bc | 0x454 |
HeapReAlloc | 0x0 | 0x40d0a4 | 0xf6c0 | 0xe6c0 | 0x2a4 |
HeapCreate | 0x0 | 0x40d0a8 | 0xf6c4 | 0xe6c4 | 0x29f |
Sleep | 0x0 | 0x40d0ac | 0xf6c8 | 0xe6c8 | 0x421 |
ExitProcess | 0x0 | 0x40d0b0 | 0xf6cc | 0xe6cc | 0x104 |
WriteFile | 0x0 | 0x40d0b4 | 0xf6d0 | 0xe6d0 | 0x48d |
GetStdHandle | 0x0 | 0x40d0b8 | 0xf6d4 | 0xe6d4 | 0x23b |
GetModuleFileNameA | 0x0 | 0x40d0bc | 0xf6d8 | 0xe6d8 | 0x1f4 |
TlsGetValue | 0x0 | 0x40d0c0 | 0xf6dc | 0xe6dc | 0x434 |
TlsAlloc | 0x0 | 0x40d0c4 | 0xf6e0 | 0xe6e0 | 0x432 |
TlsSetValue | 0x0 | 0x40d0c8 | 0xf6e4 | 0xe6e4 | 0x435 |
TlsFree | 0x0 | 0x40d0cc | 0xf6e8 | 0xe6e8 | 0x433 |
SetLastError | 0x0 | 0x40d0d0 | 0xf6ec | 0xe6ec | 0x3ec |
GetCurrentThreadId | 0x0 | 0x40d0d4 | 0xf6f0 | 0xe6f0 | 0x1ad |
InterlockedDecrement | 0x0 | 0x40d0d8 | 0xf6f4 | 0xe6f4 | 0x2bc |
HeapSize | 0x0 | 0x40d0dc | 0xf6f8 | 0xe6f8 | 0x2a6 |
SetHandleCount | 0x0 | 0x40d0e0 | 0xf6fc | 0xe6fc | 0x3e8 |
GetFileType | 0x0 | 0x40d0e4 | 0xf700 | 0xe700 | 0x1d7 |
SetFilePointer | 0x0 | 0x40d0e8 | 0xf704 | 0xe704 | 0x3df |
FreeEnvironmentStringsA | 0x0 | 0x40d0ec | 0xf708 | 0xe708 | 0x14a |
GetEnvironmentStrings | 0x0 | 0x40d0f0 | 0xf70c | 0xe70c | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x40d0f4 | 0xf710 | 0xe710 | 0x14b |
WideCharToMultiByte | 0x0 | 0x40d0f8 | 0xf714 | 0xe714 | 0x47a |
QueryPerformanceCounter | 0x0 | 0x40d0fc | 0xf718 | 0xe718 | 0x354 |
GetCurrentProcessId | 0x0 | 0x40d100 | 0xf71c | 0xe71c | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x40d104 | 0xf720 | 0xe720 | 0x24f |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x40d108 | 0xf724 | 0xe724 | 0x2b5 |
LoadLibraryA | 0x0 | 0x40d10c | 0xf728 | 0xe728 | 0x2f1 |
GetCPInfo | 0x0 | 0x40d110 | 0xf72c | 0xe72c | 0x15b |
GetOEMCP | 0x0 | 0x40d114 | 0xf730 | 0xe730 | 0x213 |
IsValidCodePage | 0x0 | 0x40d118 | 0xf734 | 0xe734 | 0x2db |
SetStdHandle | 0x0 | 0x40d11c | 0xf738 | 0xe738 | 0x3fc |
GetConsoleCP | 0x0 | 0x40d120 | 0xf73c | 0xe73c | 0x183 |
GetConsoleMode | 0x0 | 0x40d124 | 0xf740 | 0xe740 | 0x195 |
FlushFileBuffers | 0x0 | 0x40d128 | 0xf744 | 0xe744 | 0x141 |
GetLocaleInfoA | 0x0 | 0x40d12c | 0xf748 | 0xe748 | 0x1e8 |
GetStringTypeA | 0x0 | 0x40d130 | 0xf74c | 0xe74c | 0x23d |
MultiByteToWideChar | 0x0 | 0x40d134 | 0xf750 | 0xe750 | 0x31a |
GetStringTypeW | 0x0 | 0x40d138 | 0xf754 | 0xe754 | 0x240 |
LCMapStringA | 0x0 | 0x40d13c | 0xf758 | 0xe758 | 0x2e1 |
LCMapStringW | 0x0 | 0x40d140 | 0xf75c | 0xe75c | 0x2e3 |
WriteConsoleA | 0x0 | 0x40d144 | 0xf760 | 0xe760 | 0x482 |
GetConsoleOutputCP | 0x0 | 0x40d148 | 0xf764 | 0xe764 | 0x199 |
WriteConsoleW | 0x0 | 0x40d14c | 0xf768 | 0xe768 | 0x48c |
CloseHandle | 0x0 | 0x40d150 | 0xf76c | 0xe76c | 0x43 |
CreateFileA | 0x0 | 0x40d154 | 0xf770 | 0xe770 | 0x78 |
WINHTTP.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WinHttpCloseHandle | 0x0 | 0x40d15c | 0xf778 | 0xe778 | 0x8 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
buffer | 11 | 0x00D69000 | 0x00D6FFFF | First Execution |
![]() |
32-bit | 0x00D6F7F0 |
![]() |
![]() |
...
|
buffer | 11 | 0x00CC0000 | 0x00D49FFF | First Execution |
![]() |
32-bit | 0x00CC0000 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.34161206 |
Malicious
|
C:\ProgramData\HSI3BZN428LL4H57LCN6GZUGW\c-shm | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\ProgramData\\mozglue.dll | Downloaded File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
PE Information
»
Image Base | 0x10000000 |
Entry Point | 0x100182e0 |
Size Of Code | 0x17a00 |
Size Of Initialized Data | 0x8600 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-11-13 23:35:32+00:00 |
Version Information (11)
»
BuildID | 20181113231517 |
Comments | - |
CompanyName | Mozilla Foundation |
FileDescription | - |
FileVersion | 60.3.0 |
InternalName | - |
LegalCopyright | License: MPL 2 |
LegalTrademarks | Mozilla |
OriginalFilename | mozglue.dll |
ProductName | Thunderbird |
ProductVersion | 60.3.0 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x10001000 | 0x178ca | 0x17a00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x10019000 | 0x655e | 0x6600 | 0x17e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x10020000 | 0xbbc | 0x200 | 0x1e400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.79 |
.didat | 0x10021000 | 0x38 | 0x200 | 0x1e600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.67 |
.rsrc | 0x10022000 | 0x378 | 0x400 | 0x1e800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.89 |
.reloc | 0x10023000 | 0xc68 | 0xe00 | 0x1ec00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.25 |
Imports (14)
»
KERNEL32.dll (76)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
IsDebuggerPresent | 0x0 | 0x10019010 | 0x1dff0 | 0x1cdf0 | 0x376 |
OutputDebugStringA | 0x0 | 0x10019014 | 0x1dff4 | 0x1cdf4 | 0x40b |
EncodePointer | 0x0 | 0x10019018 | 0x1dff8 | 0x1cdf8 | 0x12a |
DecodePointer | 0x0 | 0x1001901c | 0x1dffc | 0x1cdfc | 0x106 |
CloseHandle | 0x0 | 0x10019020 | 0x1e000 | 0x1ce00 | 0x85 |
ReleaseSRWLockExclusive | 0x0 | 0x10019024 | 0x1e004 | 0x1ce04 | 0x4a4 |
ReleaseSRWLockShared | 0x0 | 0x10019028 | 0x1e008 | 0x1ce08 | 0x4a5 |
AcquireSRWLockExclusive | 0x0 | 0x1001902c | 0x1e00c | 0x1ce0c | 0x0 |
AcquireSRWLockShared | 0x0 | 0x10019030 | 0x1e010 | 0x1ce10 | 0x1 |
InitializeCriticalSection | 0x0 | 0x10019034 | 0x1e014 | 0x1ce14 | 0x355 |
EnterCriticalSection | 0x0 | 0x10019038 | 0x1e018 | 0x1ce18 | 0x12e |
LeaveCriticalSection | 0x0 | 0x1001903c | 0x1e01c | 0x1ce1c | 0x3b2 |
GetCurrentProcess | 0x0 | 0x10019040 | 0x1e020 | 0x1ce20 | 0x213 |
GetCurrentThreadId | 0x0 | 0x10019044 | 0x1e024 | 0x1ce24 | 0x218 |
FlushInstructionCache | 0x0 | 0x10019048 | 0x1e028 | 0x1ce28 | 0x19c |
GetSystemInfo | 0x0 | 0x1001904c | 0x1e02c | 0x1ce2c | 0x2dc |
VirtualQuery | 0x0 | 0x10019050 | 0x1e030 | 0x1ce30 | 0x5be |
VirtualAllocEx | 0x0 | 0x10019054 | 0x1e034 | 0x1ce34 | 0x5b7 |
VirtualProtectEx | 0x0 | 0x10019058 | 0x1e038 | 0x1ce38 | 0x5bd |
CreateFileMappingW | 0x0 | 0x1001905c | 0x1e03c | 0x1ce3c | 0xc6 |
MapViewOfFile | 0x0 | 0x10019060 | 0x1e040 | 0x1ce40 | 0x3d1 |
UnmapViewOfFile | 0x0 | 0x10019064 | 0x1e044 | 0x1ce44 | 0x5a0 |
GetModuleHandleA | 0x0 | 0x10019068 | 0x1e048 | 0x1ce48 | 0x26e |
GetModuleHandleW | 0x0 | 0x1001906c | 0x1e04c | 0x1ce4c | 0x271 |
GetProcAddress | 0x0 | 0x10019070 | 0x1e050 | 0x1ce50 | 0x2a7 |
LoadLibraryExA | 0x0 | 0x10019074 | 0x1e054 | 0x1ce54 | 0x3b7 |
LoadLibraryW | 0x0 | 0x10019078 | 0x1e058 | 0x1ce58 | 0x3b9 |
VerifyVersionInfoA | 0x0 | 0x1001907c | 0x1e05c | 0x1ce5c | 0x5b4 |
GetEnvironmentVariableA | 0x0 | 0x10019080 | 0x1e060 | 0x1ce60 | 0x232 |
WriteFile | 0x0 | 0x10019084 | 0x1e064 | 0x1ce64 | 0x605 |
TerminateProcess | 0x0 | 0x10019088 | 0x1e068 | 0x1ce68 | 0x57c |
VirtualAlloc | 0x0 | 0x1001908c | 0x1e06c | 0x1ce6c | 0x5b6 |
VirtualFree | 0x0 | 0x10019090 | 0x1e070 | 0x1ce70 | 0x5b9 |
GetLastError | 0x0 | 0x10019094 | 0x1e074 | 0x1ce74 | 0x25a |
InitializeConditionVariable | 0x0 | 0x10019098 | 0x1e078 | 0x1ce78 | 0x353 |
WakeConditionVariable | 0x0 | 0x1001909c | 0x1e07c | 0x1ce7c | 0x5d0 |
WakeAllConditionVariable | 0x0 | 0x100190a0 | 0x1e080 | 0x1ce80 | 0x5cf |
SleepConditionVariableSRW | 0x0 | 0x100190a4 | 0x1e084 | 0x1ce84 | 0x56f |
InitializeSRWLock | 0x0 | 0x100190a8 | 0x1e088 | 0x1ce88 | 0x35b |
WideCharToMultiByte | 0x0 | 0x100190ac | 0x1e08c | 0x1ce8c | 0x5f1 |
DuplicateHandle | 0x0 | 0x100190b0 | 0x1e090 | 0x1ce90 | 0x128 |
SetEvent | 0x0 | 0x100190b4 | 0x1e094 | 0x1ce94 | 0x507 |
WaitForSingleObject | 0x0 | 0x100190b8 | 0x1e098 | 0x1ce98 | 0x5c7 |
CreateEventA | 0x0 | 0x100190bc | 0x1e09c | 0x1ce9c | 0xba |
SignalObjectAndWait | 0x0 | 0x100190c0 | 0x1e0a0 | 0x1cea0 | 0x56b |
GetCurrentThread | 0x0 | 0x100190c4 | 0x1e0a4 | 0x1cea4 | 0x217 |
SuspendThread | 0x0 | 0x100190c8 | 0x1e0a8 | 0x1cea8 | 0x575 |
ResumeThread | 0x0 | 0x100190cc | 0x1e0ac | 0x1ceac | 0x4be |
GetThreadContext | 0x0 | 0x100190d0 | 0x1e0b0 | 0x1ceb0 | 0x2f0 |
LocalFree | 0x0 | 0x100190d4 | 0x1e0b4 | 0x1ceb4 | 0x3c3 |
FormatMessageA | 0x0 | 0x100190d8 | 0x1e0b8 | 0x1ceb8 | 0x1a2 |
QueryPerformanceCounter | 0x0 | 0x100190dc | 0x1e0bc | 0x1cebc | 0x440 |
QueryPerformanceFrequency | 0x0 | 0x100190e0 | 0x1e0c0 | 0x1cec0 | 0x441 |
DeleteCriticalSection | 0x0 | 0x100190e4 | 0x1e0c4 | 0x1cec4 | 0x10d |
GetProcessTimes | 0x0 | 0x100190e8 | 0x1e0c8 | 0x1cec8 | 0x2b7 |
GetSystemTime | 0x0 | 0x100190ec | 0x1e0cc | 0x1cecc | 0x2e0 |
GetTickCount64 | 0x0 | 0x100190f0 | 0x1e0d0 | 0x1ced0 | 0x301 |
GetSystemTimeAdjustment | 0x0 | 0x100190f4 | 0x1e0d4 | 0x1ced4 | 0x2e1 |
SystemTimeToFileTime | 0x0 | 0x100190f8 | 0x1e0d8 | 0x1ced8 | 0x578 |
DisableThreadLibraryCalls | 0x0 | 0x100190fc | 0x1e0dc | 0x1cedc | 0x11b |
CreateFileW | 0x0 | 0x10019100 | 0x1e0e0 | 0x1cee0 | 0xc9 |
SearchPathW | 0x0 | 0x10019104 | 0x1e0e4 | 0x1cee4 | 0x4c9 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x10019108 | 0x1e0e8 | 0x1cee8 | 0x356 |
VerSetConditionMask | 0x0 | 0x1001910c | 0x1e0ec | 0x1ceec | 0x5b1 |
GetSystemTimeAsFileTime | 0x0 | 0x10019110 | 0x1e0f0 | 0x1cef0 | 0x2e2 |
GetCurrentProcessId | 0x0 | 0x10019114 | 0x1e0f4 | 0x1cef4 | 0x214 |
CreateEventW | 0x0 | 0x10019118 | 0x1e0f8 | 0x1cef8 | 0xbd |
WaitForSingleObjectEx | 0x0 | 0x1001911c | 0x1e0fc | 0x1cefc | 0x5c8 |
ResetEvent | 0x0 | 0x10019120 | 0x1e100 | 0x1cf00 | 0x4b8 |
IsProcessorFeaturePresent | 0x0 | 0x10019124 | 0x1e104 | 0x1cf04 | 0x37d |
SetUnhandledExceptionFilter | 0x0 | 0x10019128 | 0x1e108 | 0x1cf08 | 0x55e |
UnhandledExceptionFilter | 0x0 | 0x1001912c | 0x1e10c | 0x1cf0c | 0x59d |
FreeLibrary | 0x0 | 0x10019130 | 0x1e110 | 0x1cf10 | 0x1a7 |
VirtualProtect | 0x0 | 0x10019134 | 0x1e114 | 0x1cf14 | 0x5bc |
RaiseException | 0x0 | 0x10019138 | 0x1e118 | 0x1cf18 | 0x455 |
InitializeSListHead | 0x0 | 0x1001913c | 0x1e11c | 0x1cf1c | 0x35a |
ADVAPI32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegOpenKeyExW | 0x0 | 0x10019000 | 0x1dfe0 | 0x1cde0 | 0x28a |
RegCloseKey | 0x0 | 0x10019004 | 0x1dfe4 | 0x1cde4 | 0x259 |
RegQueryValueExW | 0x0 | 0x10019008 | 0x1dfe8 | 0x1cde8 | 0x297 |
dbghelp.dll (10)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SymFromAddr | 0x0 | 0x100192c8 | 0x1e2a8 | 0x1d0a8 | 0x59 |
SymInitialize | 0x0 | 0x100192cc | 0x1e2ac | 0x1d0ac | 0x9e |
SymGetLineFromAddr64 | 0x0 | 0x100192d0 | 0x1e2b0 | 0x1d0b0 | 0x6b |
SymGetModuleBase64 | 0x0 | 0x100192d4 | 0x1e2b4 | 0x1d0b4 | 0x79 |
SymLoadModule64 | 0x0 | 0x100192d8 | 0x1e2b8 | 0x1d0b8 | 0xa1 |
SymFunctionTableAccess64 | 0x0 | 0x100192dc | 0x1e2bc | 0x1d0bc | 0x64 |
EnumerateLoadedModules64 | 0x0 | 0x100192e0 | 0x1e2c0 | 0x1d0c0 | 0x5 |
SymSetOptions | 0x0 | 0x100192e4 | 0x1e2c4 | 0x1d0c4 | 0xb9 |
StackWalk64 | 0x0 | 0x100192e8 | 0x1e2c8 | 0x1d0c8 | 0x2c |
SymGetModuleInfo64 | 0x0 | 0x100192ec | 0x1e2cc | 0x1d0cc | 0x7b |
VERSION.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetFileVersionInfoW | 0x0 | 0x100191fc | 0x1e1dc | 0x1cfdc | 0x8 |
GetFileVersionInfoSizeW | 0x0 | 0x10019200 | 0x1e1e0 | 0x1cfe0 | 0x7 |
VerQueryValueW | 0x0 | 0x10019204 | 0x1e1e4 | 0x1cfe4 | 0x10 |
MSVCP140.dll (33)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAEXXZ | 0x0 | 0x10019144 | 0x1e124 | 0x1cf24 | 0x228 |
?_Xbad_alloc@std@@YAXXZ | 0x0 | 0x10019148 | 0x1e128 | 0x1cf28 | 0x28b |
?_Xlength_error@std@@YAXPBD@Z | 0x0 | 0x1001914c | 0x1e12c | 0x1cf2c | 0x28e |
?_Raise_handler@std@@3P6AXABVexception@stdext@@@ZA | 0x0 | 0x10019150 | 0x1e130 | 0x1cf30 | 0x25c |
?_Xout_of_range@std@@YAXPBD@Z | 0x0 | 0x10019154 | 0x1e134 | 0x1cf34 | 0x28f |
?_Ios_base_dtor@ios_base@std@@CAXPAV12@@Z | 0x0 | 0x10019158 | 0x1e138 | 0x1cf38 | 0x218 |
??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAE@XZ | 0x0 | 0x1001915c | 0x1e13c | 0x1cf3c | 0x2f |
??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAE@XZ | 0x0 | 0x10019160 | 0x1e140 | 0x1cf40 | 0x89 |
?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAEPADXZ | 0x0 | 0x10019164 | 0x1e144 | 0x1cf44 | 0x24a |
??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QAE@PAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z | 0x0 | 0x10019168 | 0x1e148 | 0x1cf48 | 0x25 |
??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UAE@XZ | 0x0 | 0x1001916c | 0x1e14c | 0x1cf4c | 0x86 |
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@_J@Z | 0x0 | 0x10019170 | 0x1e150 | 0x1cf50 | 0x10b |
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@_K@Z | 0x0 | 0x10019174 | 0x1e154 | 0x1cf54 | 0x10c |
?setprecision@std@@YA?AU?$_Smanip@_J@1@_J@Z | 0x0 | 0x10019178 | 0x1e158 | 0x1cf58 | 0x4c4 |
?id@?$ctype@D@std@@2V0locale@2@A | 0x0 | 0x1001917c | 0x1e15c | 0x1cf5c | 0x3cf |
?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAEXXZ | 0x0 | 0x10019180 | 0x1e160 | 0x1cf60 | 0x27f |
?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEXABVlocale@2@@Z | 0x0 | 0x10019184 | 0x1e164 | 0x1cf64 | 0x3f6 |
?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEPAV12@PAD_J@Z | 0x0 | 0x10019188 | 0x1e168 | 0x1cf68 | 0x4b5 |
?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JXZ | 0x0 | 0x1001918c | 0x1e16c | 0x1cf6c | 0x4d5 |
?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEHXZ | 0x0 | 0x10019190 | 0x1e170 | 0x1cf70 | 0x4fd |
?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEHXZ | 0x0 | 0x10019194 | 0x1e174 | 0x1cf74 | 0x51b |
?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JPAD_J@Z | 0x0 | 0x10019198 | 0x1e178 | 0x1cf78 | 0x543 |
?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JPBD_J@Z | 0x0 | 0x1001919c | 0x1e17c | 0x1cf7c | 0x546 |
?_BADOFF@std@@3_JB | 0x0 | 0x100191a0 | 0x1e180 | 0x1cf80 | 0x196 |
??_7ios_base@std@@6B@ | 0x0 | 0x100191a4 | 0x1e184 | 0x1cf84 | 0x15b |
??_7?$basic_ios@DU?$char_traits@D@std@@@std@@6B@ | 0x0 | 0x100191a8 | 0x1e188 | 0x1cf88 | 0x133 |
??0_Lockit@std@@QAE@H@Z | 0x0 | 0x100191ac | 0x1e18c | 0x1cf8c | 0x6d |
??1_Lockit@std@@QAE@XZ | 0x0 | 0x100191b0 | 0x1e190 | 0x1cf90 | 0xa5 |
??Bid@locale@std@@QAEIXZ | 0x0 | 0x100191b4 | 0x1e194 | 0x1cf94 | 0x131 |
?classic@locale@std@@SAABV12@XZ | 0x0 | 0x100191b8 | 0x1e198 | 0x1cf98 | 0x2a4 |
?_Getgloballocale@locale@std@@CAPAV_Locimp@12@XZ | 0x0 | 0x100191bc | 0x1e19c | 0x1cf9c | 0x1d5 |
?tolower@?$ctype@D@std@@QBEDD@Z | 0x0 | 0x100191c0 | 0x1e1a0 | 0x1cfa0 | 0x50f |
?_Getcat@?$ctype@D@std@@SAIPAPBVfacet@locale@2@PBV42@@Z | 0x0 | 0x100191c4 | 0x1e1a4 | 0x1cfa4 | 0x1b6 |
VCRUNTIME140.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
memcpy | 0x0 | 0x100191cc | 0x1e1ac | 0x1cfac | 0x46 |
_purecall | 0x0 | 0x100191d0 | 0x1e1b0 | 0x1cfb0 | 0x3d |
memset | 0x0 | 0x100191d4 | 0x1e1b4 | 0x1cfb4 | 0x48 |
longjmp | 0x0 | 0x100191d8 | 0x1e1b8 | 0x1cfb8 | 0x43 |
_setjmp3 | 0x0 | 0x100191dc | 0x1e1bc | 0x1cfbc | 0x42 |
strchr | 0x0 | 0x100191e0 | 0x1e1c0 | 0x1cfc0 | 0x4a |
_except_handler4_common | 0x0 | 0x100191e4 | 0x1e1c4 | 0x1cfc4 | 0x35 |
memmove | 0x0 | 0x100191e8 | 0x1e1c8 | 0x1cfc8 | 0x47 |
__CxxFrameHandler3 | 0x0 | 0x100191ec | 0x1e1cc | 0x1cfcc | 0x10 |
__vcrt_InitializeCriticalSectionEx | 0x0 | 0x100191f0 | 0x1e1d0 | 0x1cfd0 | 0x30 |
__std_type_info_destroy_list | 0x0 | 0x100191f4 | 0x1e1d4 | 0x1cfd4 | 0x25 |
api-ms-win-crt-runtime-l1-1-0.dll (14)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_beginthreadex | 0x0 | 0x10019248 | 0x1e228 | 0x1d028 | 0x15 |
_errno | 0x0 | 0x1001924c | 0x1e22c | 0x1d02c | 0x23 |
_cexit | 0x0 | 0x10019250 | 0x1e230 | 0x1d030 | 0x17 |
_initterm_e | 0x0 | 0x10019254 | 0x1e234 | 0x1d034 | 0x39 |
_initterm | 0x0 | 0x10019258 | 0x1e238 | 0x1d038 | 0x38 |
_invalid_parameter_noinfo_noreturn | 0x0 | 0x1001925c | 0x1e23c | 0x1d03c | 0x3b |
abort | 0x0 | 0x10019260 | 0x1e240 | 0x1d040 | 0x57 |
_seh_filter_dll | 0x0 | 0x10019264 | 0x1e244 | 0x1d044 | 0x41 |
_configure_narrow_argv | 0x0 | 0x10019268 | 0x1e248 | 0x1d048 | 0x19 |
_initialize_narrow_environment | 0x0 | 0x1001926c | 0x1e24c | 0x1d04c | 0x35 |
_initialize_onexit_table | 0x0 | 0x10019270 | 0x1e250 | 0x1d050 | 0x36 |
_register_onexit_function | 0x0 | 0x10019274 | 0x1e254 | 0x1d054 | 0x3e |
_execute_onexit_table | 0x0 | 0x10019278 | 0x1e258 | 0x1d058 | 0x24 |
_crt_atexit | 0x0 | 0x1001927c | 0x1e25c | 0x1d05c | 0x1f |
api-ms-win-crt-string-l1-1-0.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
strncpy | 0x0 | 0x100192a8 | 0x1e288 | 0x1d088 | 0x8f |
_stricmp | 0x0 | 0x100192ac | 0x1e28c | 0x1d08c | 0x2a |
isxdigit | 0x0 | 0x100192b0 | 0x1e290 | 0x1d090 | 0x7e |
_strnicmp | 0x0 | 0x100192b4 | 0x1e294 | 0x1d094 | 0x34 |
_wcsnicmp | 0x0 | 0x100192b8 | 0x1e298 | 0x1d098 | 0x54 |
wcsncpy | 0x0 | 0x100192bc | 0x1e29c | 0x1d09c | 0xa7 |
wcstok_s | 0x0 | 0x100192c0 | 0x1e2a0 | 0x1d0a0 | 0xad |
api-ms-win-crt-stdio-l1-1-0.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
fputs | 0x0 | 0x10019284 | 0x1e264 | 0x1d064 | 0x80 |
__acrt_iob_func | 0x0 | 0x10019288 | 0x1e268 | 0x1d068 | 0x0 |
_write | 0x0 | 0x1001928c | 0x1e26c | 0x1d06c | 0x6b |
__stdio_common_vfprintf | 0x0 | 0x10019290 | 0x1e270 | 0x1d070 | 0x3 |
__stdio_common_vsprintf | 0x0 | 0x10019294 | 0x1e274 | 0x1d074 | 0xd |
fflush | 0x0 | 0x10019298 | 0x1e278 | 0x1d078 | 0x77 |
fclose | 0x0 | 0x1001929c | 0x1e27c | 0x1d07c | 0x74 |
_dup | 0x0 | 0x100192a0 | 0x1e280 | 0x1d080 | 0x1a |
api-ms-win-crt-filesystem-l1-1-0.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_wsplitpath_s | 0x0 | 0x10019220 | 0x1e200 | 0x1d000 | 0x39 |
api-ms-win-crt-convert-l1-1-0.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_strtoui64 | 0x0 | 0x1001920c | 0x1e1ec | 0x1cfec | 0x27 |
_ltoa | 0x0 | 0x10019210 | 0x1e1f0 | 0x1cff0 | 0x1b |
api-ms-win-crt-math-l1-1-0.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_except1 | 0x0 | 0x10019234 | 0x1e214 | 0x1d014 | 0x40 |
_dtest | 0x0 | 0x10019238 | 0x1e218 | 0x1d018 | 0x3e |
_fdopen | 0x0 | 0x1001923c | 0x1e21c | 0x1d01c | 0x46 |
ceil | 0x0 | 0x10019240 | 0x1e220 | 0x1d020 | 0xa2 |
api-ms-win-crt-heap-l1-1-0.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
malloc | 0x0 | 0x10019228 | 0x1e208 | 0x1d008 | 0x19 |
free | 0x0 | 0x1001922c | 0x1e20c | 0x1d00c | 0x18 |
api-ms-win-crt-environment-l1-1-0.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
getenv | 0x0 | 0x10019218 | 0x1e1f8 | 0x1cff8 | 0x10 |
Exports (159)
»
Api name | EAT Address | Ordinal |
---|---|---|
??0ConditionVariableImpl@detail@mozilla@@QAE@XZ | 0x93f0 | 0x1 |
??0Decimal@blink@@QAE@ABV01@@Z | 0xd820 | 0x2 |
??0Decimal@blink@@QAE@ABVEncodedData@01@@Z | 0xd820 | 0x3 |
??0Decimal@blink@@QAE@H@Z | 0xd840 | 0x4 |
??0Decimal@blink@@QAE@W4Sign@01@H_K@Z | 0xd870 | 0x5 |
??0MutexImpl@detail@mozilla@@QAE@XZ | 0x9540 | 0x6 |
??0PrintfTarget@mozilla@@IAE@XZ | 0x95f0 | 0x7 |
??0SHA1Sum@mozilla@@QAE@XZ | 0x10ae0 | 0x8 |
??0TimeStampValue@mozilla@@AAE@_K0_N@Z | 0xb4d0 | 0x9 |
??1ConditionVariableImpl@detail@mozilla@@QAE@XZ | 0x9400 | 0xa |
??1MutexImpl@detail@mozilla@@QAE@XZ | 0x9400 | 0xb |
??4Decimal@blink@@QAEAAV01@ABV01@@Z | 0xd820 | 0xc |
??8Decimal@blink@@QBE_NABV01@@Z | 0xd990 | 0xd |
??9Decimal@blink@@QBE_NABV01@@Z | 0xda10 | 0xe |
??DDecimal@blink@@QBE?AV01@ABV01@@Z | 0xda60 | 0xf |
??GDecimal@blink@@QBE?AV01@ABV01@@Z | 0xdb60 | 0x10 |
??GDecimal@blink@@QBE?AV01@XZ | 0xdc90 | 0x11 |
??GTimeStampValue@mozilla@@QBE_KABV01@@Z | 0xb500 | 0x12 |
??HDecimal@blink@@QBE?AV01@ABV01@@Z | 0xdcd0 | 0x13 |
??KDecimal@blink@@QBE?AV01@ABV01@@Z | 0xddf0 | 0x14 |
??MDecimal@blink@@QBE_NABV01@@Z | 0xdfe0 | 0x15 |
??NDecimal@blink@@QBE_NABV01@@Z | 0xe010 | 0x16 |
??ODecimal@blink@@QBE_NABV01@@Z | 0xe070 | 0x17 |
??PDecimal@blink@@QBE_NABV01@@Z | 0xe0a0 | 0x18 |
??XDecimal@blink@@QAEAAV01@ABV01@@Z | 0xe100 | 0x19 |
??YDecimal@blink@@QAEAAV01@ABV01@@Z | 0xe130 | 0x1a |
??YTimeStampValue@mozilla@@QAEAAV01@_J@Z | 0xb530 | 0x1b |
??ZDecimal@blink@@QAEAAV01@ABV01@@Z | 0xe160 | 0x1c |
??ZTimeStampValue@mozilla@@QAEAAV01@_J@Z | 0xb550 | 0x1d |
??_0Decimal@blink@@QAEAAV01@ABV01@@Z | 0xe190 | 0x1e |
??_FDecimal@blink@@QAEXXZ | 0xe2a0 | 0x1f |
?CheckQPC@TimeStampValue@mozilla@@ABE_KABV12@@Z | 0xb570 | 0x20 |
?ComputeProcessUptime@TimeStamp@mozilla@@CA_KXZ | 0xb730 | 0x21 |
?CreateDecimalRepresentation@DoubleToStringConverter@double_conversion@@ABEXPBDHHHPAVStringBuilder@2@@Z | 0x116c0 | 0x22 |
?CreateExponentialRepresentation@DoubleToStringConverter@double_conversion@@ABEXPBDHHPAVStringBuilder@2@@Z | 0x117d0 | 0x23 |
?DllBlocklist_CheckStatus@@YA_NXZ | 0x2050 | 0x24 |
?DllBlocklist_Initialize@@YAXI@Z | 0x2070 | 0x25 |
?DllBlocklist_SetDllServices@@YAXPAVDllServicesBase@detail@glue@mozilla@@@Z | 0x2170 | 0x26 |
?DllBlocklist_WriteNotes@@YAXPAX@Z | 0x2200 | 0x27 |
?DoubleToAscii@DoubleToStringConverter@double_conversion@@SAXNW4DtoaMode@12@HPADHPA_NPAH3@Z | 0x11f10 | 0x28 |
?EcmaScriptConverter@DoubleToStringConverter@double_conversion@@SAABV12@XZ | 0x12070 | 0x29 |
?FramePointerStackWalk@mozilla@@YAXP6AXIPAX00@ZII0PAPAX0@Z | 0xa760 | 0x2a |
?HandleSpecialValues@DoubleToStringConverter@double_conversion@@ABE_NNPAVStringBuilder@2@@Z | 0x12b20 | 0x2b |
?HashBytes@mozilla@@YAIPBXI@Z | 0x12ba0 | 0x2c |
?IsFloat32Representable@mozilla@@YA_NN@Z | 0x12e30 | 0x2d |
?MozDescribeCodeAddress@@YA_NPAXPAUMozCodeAddressDetails@@@Z | 0xa7d0 | 0x2e |
?MozFormatCodeAddress@@YAXPADIIPBXPBD2H2I@Z | 0xa9a0 | 0x2f |
?MozFormatCodeAddressDetails@@YAXPADIIPAXPBUMozCodeAddressDetails@@@Z | 0xaa10 | 0x30 |
?MozStackWalk@@YAXP6AXIPAX00@ZII0@Z | 0xaa50 | 0x31 |
?MozStackWalkThread@@YAXP6AXIPAX00@ZII00PAU_CONTEXT@@@Z | 0xaa70 | 0x32 |
?Now@TimeStamp@mozilla@@CA?AV12@_N@Z | 0xba10 | 0x33 |
?ProcessCreation@TimeStamp@mozilla@@SA?AV12@PA_N@Z | 0xb3a0 | 0x34 |
?RecordProcessRestart@TimeStamp@mozilla@@SAXXZ | 0xb4a0 | 0x35 |
?RegisterProfilerLabelEnterExit@mozilla@@YAXP6APAVPseudoStack@@PBD0PAXI@ZP6AXPAV2@@Z@Z | 0x93d0 | 0x36 |
?ResolutionInTicks@BaseTimeDurationPlatformUtils@mozilla@@SA_JXZ | 0xbb10 | 0x37 |
?Shutdown@TimeStamp@mozilla@@SAXXZ | 0xbb20 | 0x38 |
?Startup@TimeStamp@mozilla@@SAXXZ | 0xbb30 | 0x39 |
?TicksFromMilliseconds@BaseTimeDurationPlatformUtils@mozilla@@SA_JN@Z | 0xbc00 | 0x3a |
?ToExponential@DoubleToStringConverter@double_conversion@@QBE_NNHPAVStringBuilder@2@@Z | 0x13e60 | 0x3b |
?ToFixed@DoubleToStringConverter@double_conversion@@QBE_NNHPAVStringBuilder@2@@Z | 0x13fe0 | 0x3c |
?ToPrecision@DoubleToStringConverter@double_conversion@@QBE_NNHPA_NPAVStringBuilder@2@@Z | 0x14190 | 0x3d |
?ToSeconds@BaseTimeDurationPlatformUtils@mozilla@@SAN_J@Z | 0xbc50 | 0x3e |
?ToSecondsSigDigits@BaseTimeDurationPlatformUtils@mozilla@@SAN_J@Z | 0xbc90 | 0x3f |
?ToShortestIeeeNumber@DoubleToStringConverter@double_conversion@@ABE_NNPAVStringBuilder@2@W4DtoaMode@12@@Z | 0x14320 | 0x40 |
?Unused@mozilla@@3Uunused_t@1@B | 0x207e4 | 0x41 |
?abs@Decimal@blink@@QBE?AV12@XZ | 0xe470 | 0x42 |
?aes_enabled@sse_private@mozilla@@3_NA | 0x20078 | 0x43 |
?alignOperands@Decimal@blink@@CA?AUAlignedOperands@12@ABV12@0@Z | 0xe490 | 0x44 |
?avx2_enabled@sse_private@mozilla@@3_NA | 0x2007d | 0x45 |
?avx_enabled@sse_private@mozilla@@3_NA | 0x2007b | 0x46 |
?ceil@Decimal@blink@@QBE?AV12@XZ | 0xe6e0 | 0x47 |
?compareTo@Decimal@blink@@ABE?AV12@ABV12@@Z | 0xe7b0 | 0x48 |
?compress@LZ4@Compression@mozilla@@SAIPBDIPAD@Z | 0xd450 | 0x49 |
?compressLimitedOutput@LZ4@Compression@mozilla@@SAIPBDIPADI@Z | 0xd470 | 0x4a |
?decompress@LZ4@Compression@mozilla@@SA_NPBDIPADIPAI@Z | 0xd490 | 0x4b |
?decompress@LZ4@Compression@mozilla@@SA_NPBDPADI@Z | 0xd4c0 | 0x4c |
?decompressPartial@LZ4@Compression@mozilla@@SA_NPBDIPADIPAI@Z | 0xd4e0 | 0x4d |
?finish@SHA1Sum@mozilla@@QAEXAAY0BE@E@Z | 0x145b0 | 0x4e |
?floor@Decimal@blink@@QBE?AV12@XZ | 0xe8b0 | 0x4f |
?fromDouble@Decimal@blink@@SA?AV12@N@Z | 0xe970 | 0x50 |
?fromString@Decimal@blink@@SA?AV12@ABV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 0xea10 | 0x51 |
?gChaosFeatures@detail@mozilla@@3W4ChaosFeature@2@A | 0x207d0 | 0x52 |
?gChaosModeCounter@detail@mozilla@@3V?$Atomic@I$01X@2@A | 0x207e8 | 0x53 |
?gTwoCharEscapes@detail@mozilla@@3QBDB | 0x1add8 | 0x54 |
?infinity@Decimal@blink@@SA?AV12@W4Sign@12@@Z | 0xed40 | 0x55 |
?kBase10MaximalLength@DoubleToStringConverter@double_conversion@@2HB | 0x1ad20 | 0x56 |
?lock@MutexImpl@detail@mozilla@@IAEXXZ | 0x9550 | 0x57 |
?mmx_enabled@sse_private@mozilla@@3_NA | 0x2007f | 0x58 |
?mozalloc_handle_oom@@YAXI@Z | 0x91b0 | 0x59 |
?mozalloc_set_oom_abort_handler@@YAXP6AXI@Z@Z | 0x9220 | 0x5a |
?nan@Decimal@blink@@SA?AV12@XZ | 0xf030 | 0x5b |
?notify_all@ConditionVariableImpl@detail@mozilla@@QAEXXZ | 0x9450 | 0x5c |
?notify_one@ConditionVariableImpl@detail@mozilla@@QAEXXZ | 0x9460 | 0x5d |
?print@PrintfTarget@mozilla@@QAA_NPBDZZ | 0x9ea0 | 0x5e |
?remainder@Decimal@blink@@QBE?AV12@ABV12@@Z | 0xf2b0 | 0x5f |
?round@Decimal@blink@@QBE?AV12@XZ | 0xf330 | 0x60 |
?sse3_enabled@sse_private@mozilla@@3_NA | 0x2007c | 0x61 |
?sse4_1_enabled@sse_private@mozilla@@3_NA | 0x2007a | 0x62 |
?sse4_2_enabled@sse_private@mozilla@@3_NA | 0x2007e | 0x63 |
?sse4a_enabled@sse_private@mozilla@@3_NA | 0x20080 | 0x64 |
?ssse3_enabled@sse_private@mozilla@@3_NA | 0x20079 | 0x65 |
?toDouble@Decimal@blink@@QBENXZ | 0xf7d0 | 0x66 |
?toString@Decimal@blink@@QBE?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@XZ | 0xf870 | 0x67 |
?toString@Decimal@blink@@QBE_NPADI@Z | 0xfb80 | 0x68 |
?unlock@MutexImpl@detail@mozilla@@IAEXXZ | 0x9560 | 0x69 |
?update@SHA1Sum@mozilla@@QAEXPBXI@Z | 0x15b80 | 0x6a |
?vprint@PrintfTarget@mozilla@@QAE_NPBDPAD@Z | 0x9ec0 | 0x6b |
?wait@ConditionVariableImpl@detail@mozilla@@QAEXAAVMutexImpl@23@@Z | 0x9470 | 0x6c |
?wait_for@ConditionVariableImpl@detail@mozilla@@QAE?AW4CVStatus@23@AAVMutexImpl@23@ABV?$BaseTimeDuration@VTimeDurationValueCalculator@mozilla@@@3@@Z | 0x94b0 | 0x6d |
?zero@Decimal@blink@@SA?AV12@W4Sign@12@@Z | 0xfc70 | 0x6e |
CFG_DisabledOrCrash | 0x15a0 | 0x6f |
MOZ_CrashOOL | 0x15c60 | 0x73 |
MOZ_CrashPrintf | 0x15c80 | 0x74 |
_HeapAlloc@12 | 0x9150 | 0x70 |
_HeapFree@12 | 0x9170 | 0x71 |
_HeapReAlloc@16 | 0x9190 | 0x72 |
_aligned_free | 0x8ed0 | 0x75 |
_aligned_malloc | 0x9020 | 0x76 |
_expand | 0x8de0 | 0x77 |
_msize | 0x8e10 | 0x78 |
_recalloc | 0x8e30 | 0x79 |
_strdup | 0x9040 | 0x7a |
_wcsdup | 0x9090 | 0x7b |
calloc | 0x8eb0 | 0x7c |
free | 0x8ed0 | 0x7d |
gMozCrashReason | 0x207d4 | 0x7e |
gMozillaPoisonBase | 0x207dc | 0x7f |
gMozillaPoisonSize | 0x207e0 | 0x80 |
gMozillaPoisonValue | 0x207d8 | 0x81 |
jemalloc_free_dirty_pages | 0x8f70 | 0x82 |
jemalloc_ptr_info | 0x8f80 | 0x83 |
jemalloc_purge_freed_pages | 0x9400 | 0x84 |
jemalloc_stats | 0x8f90 | 0x85 |
jemalloc_thread_local_arena | 0x8fa0 | 0x86 |
malloc | 0x8ef0 | 0x87 |
malloc_good_size | 0x8f10 | 0x88 |
malloc_usable_size | 0x8e10 | 0x89 |
mozPoisonValueInit | 0x15ce0 | 0x8a |
moz_arena_calloc | 0x8fb0 | 0x8b |
moz_arena_free | 0x8fc0 | 0x8c |
moz_arena_malloc | 0x8fd0 | 0x8d |
moz_arena_memalign | 0x8fe0 | 0x8e |
moz_arena_realloc | 0x8ff0 | 0x8f |
moz_create_arena_with_params | 0x9000 | 0x90 |
moz_dispose_arena | 0x9010 | 0x91 |
moz_malloc_enclosing_size_of | 0x9230 | 0x92 |
moz_malloc_size_of | 0x9270 | 0x93 |
moz_malloc_usable_size | 0x9270 | 0x94 |
moz_xcalloc | 0x9290 | 0x95 |
moz_xmalloc | 0x92f0 | 0x96 |
moz_xmemalign | 0x9310 | 0x97 |
moz_xrealloc | 0x9340 | 0x98 |
moz_xstrdup | 0x9370 | 0x99 |
mozalloc_abort | 0x90f0 | 0x9a |
posix_memalign | 0x8f40 | 0x9b |
realloc | 0x8f50 | 0x9c |
strdup | 0x9040 | 0x9d |
strndup | 0x9060 | 0x9e |
wcsdup | 0x9090 | 0x9f |
Digital Signatures (3)
»
Certificate: Mozilla Corporation
»
Issued by | Mozilla Corporation |
Parent Certificate | DigiCert SHA2 Assured ID Code Signing CA |
Country Name | US |
Valid From | 2017-06-23 00:00:00+00:00 |
Valid Until | 2019-06-28 12:00:00+00:00 |
Algorithm | sha256_rsa |
Serial Number | 0C 53 96 DC B2 94 9C 70 FA C4 8A B0 8A 07 33 8E |
Thumbprint | B6 B2 4A EA 9E 98 3E D6 BD A9 58 6A 14 5A 7D DD 7E 22 01 96 |
Certificate: DigiCert SHA2 Assured ID Code Signing CA
»
Issued by | DigiCert SHA2 Assured ID Code Signing CA |
Parent Certificate | DigiCert Assured ID Root CA |
Country Name | US |
Valid From | 2013-10-22 12:00:00+00:00 |
Valid Until | 2028-10-22 12:00:00+00:00 |
Algorithm | sha256_rsa |
Serial Number | 04 09 18 1B 5F D5 BB 66 75 53 43 B5 6F 95 50 08 |
Thumbprint | 92 C1 58 8E 85 AF 22 01 CE 79 15 E8 53 8B 49 2F 60 5B 80 C6 |
Certificate: DigiCert Assured ID Root CA
»
Issued by | DigiCert Assured ID Root CA |
Country Name | US |
Valid From | 2006-11-10 00:00:00+00:00 |
Valid Until | 2031-11-10 00:00:00+00:00 |
Algorithm | sha1_rsa |
Serial Number | 0C E7 E0 E5 17 D8 46 FE 8F E5 60 FC 1B F0 30 39 |
Thumbprint | 05 63 B8 63 0D 62 D7 5A BB C8 AB 1E 4B DF B5 A8 99 B2 4D 43 |
C:\ProgramData\\softokn3.dll | Downloaded File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
PE Information
»
Image Base | 0x10000000 |
Entry Point | 0x1001bc97 |
Size Of Code | 0x1b600 |
Size Of Initialized Data | 0x6200 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-11-13 23:48:15+00:00 |
Version Information (11)
»
BuildID | 20181113231517 |
Comments | - |
CompanyName | Mozilla Foundation |
FileDescription | - |
FileVersion | 60.3.0 |
InternalName | - |
LegalCopyright | License: MPL 2 |
LegalTrademarks | Mozilla |
OriginalFilename | softokn3.dll |
ProductName | Thunderbird |
ProductVersion | 60.3.0 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x10001000 | 0x1b4cb | 0x1b600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.41 |
.rdata | 0x1001d000 | 0x440a | 0x4600 | 0x1ba00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.08 |
.data | 0x10022000 | 0x700 | 0x400 | 0x20000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.71 |
.rsrc | 0x10023000 | 0x378 | 0x400 | 0x20400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.9 |
.reloc | 0x10024000 | 0xe60 | 0x1000 | 0x20800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.34 |
Imports (9)
»
nss3.dll (110)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SECITEM_HashCompare | 0x0 | 0x1001d0b0 | 0x20530 | 0x1ef30 | 0x3b1 |
PR_SecondsToInterval | 0x0 | 0x1001d0b4 | 0x20534 | 0x1ef34 | 0x34a |
PR_NewLock | 0x0 | 0x1001d0b8 | 0x20538 | 0x1ef38 | 0x30f |
PR_DestroyLock | 0x0 | 0x1001d0bc | 0x2053c | 0x1ef3c | 0x269 |
DER_SetUInteger | 0x0 | 0x1001d0c0 | 0x20540 | 0x1ef40 | 0x97 |
PR_Sleep | 0x0 | 0x1001d0c4 | 0x20544 | 0x1ef44 | 0x36d |
PR_smprintf_free | 0x0 | 0x1001d0c8 | 0x20548 | 0x1ef48 | 0x399 |
SECOID_Init | 0x0 | 0x1001d0cc | 0x2054c | 0x1ef4c | 0x3fb |
SECOID_Shutdown | 0x0 | 0x1001d0d0 | 0x20550 | 0x1ef50 | 0x3fe |
UTIL_SetForkState | 0x0 | 0x1001d0d4 | 0x20554 | 0x1ef54 | 0x487 |
NSSUTIL_DoModuleDBFunction | 0x0 | 0x1001d0d8 | 0x20558 | 0x1ef58 | 0xbb |
_NSSUTIL_GetSecmodName | 0x0 | 0x1001d0dc | 0x2055c | 0x1ef5c | 0x493 |
SEC_QuickDERDecodeItem_Util | 0x0 | 0x1001d0e0 | 0x20560 | 0x1ef60 | 0x441 |
NSS_Get_SEC_OctetStringTemplate_Util | 0x0 | 0x1001d0e4 | 0x20564 | 0x1ef64 | 0x10d |
_SGN_VerifyPKCS1DigestInfo | 0x0 | 0x1001d0e8 | 0x20568 | 0x1ef68 | 0x4a2 |
DER_Encode_Util | 0x0 | 0x1001d0ec | 0x2056c | 0x1ef6c | 0x91 |
SGN_CreateDigestInfo_Util | 0x0 | 0x1001d0f0 | 0x20570 | 0x1ef70 | 0x44a |
SGN_DestroyDigestInfo_Util | 0x0 | 0x1001d0f4 | 0x20574 | 0x1ef74 | 0x44e |
SECOID_FindOIDByMechanism | 0x0 | 0x1001d0f8 | 0x20578 | 0x1ef78 | 0x3f2 |
PL_HashTableEnumerateEntries | 0x0 | 0x1001d0fc | 0x2057c | 0x1ef7c | 0x1cb |
PL_strcasecmp | 0x0 | 0x1001d100 | 0x20580 | 0x1ef80 | 0x1d7 |
PORT_Strdup_Util | 0x0 | 0x1001d104 | 0x20584 | 0x1ef84 | 0x214 |
sqlite3_close | 0x0 | 0x1001d108 | 0x20588 | 0x1ef88 | 0x4b7 |
sqlite3_exec | 0x0 | 0x1001d10c | 0x2058c | 0x1ef8c | 0x4db |
sqlite3_busy_timeout | 0x0 | 0x1001d110 | 0x20590 | 0x1ef90 | 0x4b4 |
sqlite3_mprintf | 0x0 | 0x1001d114 | 0x20594 | 0x1ef94 | 0x4ee |
sqlite3_free | 0x0 | 0x1001d118 | 0x20598 | 0x1ef98 | 0x4e0 |
sqlite3_open | 0x0 | 0x1001d11c | 0x2059c | 0x1ef9c | 0x4f5 |
sqlite3_prepare_v2 | 0x0 | 0x1001d120 | 0x205a0 | 0x1efa0 | 0x4fc |
PORT_FreeArena_Util | 0x0 | 0x1001d124 | 0x205a4 | 0x1efa4 | 0x206 |
sqlite3_bind_int | 0x0 | 0x1001d128 | 0x205a8 | 0x1efa8 | 0x4aa |
PL_NewHashTable | 0x0 | 0x1001d12c | 0x205ac | 0x1efac | 0x1d4 |
sqlite3_step | 0x0 | 0x1001d130 | 0x205b0 | 0x1efb0 | 0x518 |
sqlite3_column_blob | 0x0 | 0x1001d134 | 0x205b4 | 0x1efb4 | 0x4ba |
sqlite3_column_bytes | 0x0 | 0x1001d138 | 0x205b8 | 0x1efb8 | 0x4bb |
sqlite3_column_int | 0x0 | 0x1001d13c | 0x205bc | 0x1efbc | 0x4bf |
sqlite3_finalize | 0x0 | 0x1001d140 | 0x205c0 | 0x1efc0 | 0x4df |
sqlite3_reset | 0x0 | 0x1001d144 | 0x205c4 | 0x1efc4 | 0x500 |
sqlite3_file_control | 0x0 | 0x1001d148 | 0x205c8 | 0x1efc8 | 0x4de |
PR_IntervalNow | 0x0 | 0x1001d14c | 0x205cc | 0x1efcc | 0x2f3 |
PR_MillisecondsToInterval | 0x0 | 0x1001d150 | 0x205d0 | 0x1efd0 | 0x30b |
PR_GetCurrentThread | 0x0 | 0x1001d154 | 0x205d4 | 0x1efd4 | 0x2a8 |
PR_Now | 0x0 | 0x1001d158 | 0x205d8 | 0x1efd8 | 0x320 |
PL_CompareValues | 0x0 | 0x1001d15c | 0x205dc | 0x1efdc | 0x1bf |
PR_NewMonitor | 0x0 | 0x1001d160 | 0x205e0 | 0x1efe0 | 0x311 |
PR_DestroyMonitor | 0x0 | 0x1001d164 | 0x205e4 | 0x1efe4 | 0x26b |
PR_EnterMonitor | 0x0 | 0x1001d168 | 0x205e8 | 0x1efe8 | 0x27d |
PR_ExitMonitor | 0x0 | 0x1001d16c | 0x205ec | 0x1efec | 0x287 |
_NSSUTIL_UTF8ToWide | 0x0 | 0x1001d170 | 0x205f0 | 0x1eff0 | 0x494 |
_NSSUTIL_Access | 0x0 | 0x1001d174 | 0x205f4 | 0x1eff4 | 0x491 |
PR_smprintf | 0x0 | 0x1001d178 | 0x205f8 | 0x1eff8 | 0x398 |
_NSSUTIL_EvaluateConfigDir | 0x0 | 0x1001d17c | 0x205fc | 0x1effc | 0x492 |
PL_strncasecmp | 0x0 | 0x1001d180 | 0x20600 | 0x1f000 | 0x1e2 |
NSSUTIL_ArgFetchValue | 0x0 | 0x1001d184 | 0x20604 | 0x1f004 | 0xaf |
NSSUTIL_ArgStrip | 0x0 | 0x1001d188 | 0x20608 | 0x1f008 | 0xba |
NSSUTIL_ArgSkipParameter | 0x0 | 0x1001d18c | 0x2060c | 0x1f00c | 0xb9 |
NSSUTIL_ArgGetLabel | 0x0 | 0x1001d190 | 0x20610 | 0x1f010 | 0xb0 |
NSSUTIL_ArgDecodeNumber | 0x0 | 0x1001d194 | 0x20614 | 0x1f014 | 0xae |
NSSUTIL_ArgIsBlank | 0x0 | 0x1001d198 | 0x20618 | 0x1f018 | 0xb3 |
NSSUTIL_ArgHasFlag | 0x0 | 0x1001d19c | 0x2061c | 0x1f01c | 0xb2 |
PORT_NewArena_Util | 0x0 | 0x1001d1a0 | 0x20620 | 0x1f020 | 0x20c |
PORT_GetError_Util | 0x0 | 0x1001d1a4 | 0x20624 | 0x1f024 | 0x209 |
PR_GetEnv | 0x0 | 0x1001d1a8 | 0x20628 | 0x1f028 | 0x2ad |
PORT_ArenaAlloc_Util | 0x0 | 0x1001d1ac | 0x2062c | 0x1f02c | 0x1fa |
PORT_ArenaGrow_Util | 0x0 | 0x1001d1b0 | 0x20630 | 0x1f030 | 0x1fb |
PORT_Realloc_Util | 0x0 | 0x1001d1b4 | 0x20634 | 0x1f034 | 0x20d |
SECOID_DestroyAlgorithmID_Util | 0x0 | 0x1001d1b8 | 0x20638 | 0x1f038 | 0x3f0 |
SECOID_GetAlgorithmTag_Util | 0x0 | 0x1001d1bc | 0x2063c | 0x1f03c | 0x3fa |
SECOID_CopyAlgorithmID_Util | 0x0 | 0x1001d1c0 | 0x20640 | 0x1f040 | 0x3ee |
SECOID_SetAlgorithmID_Util | 0x0 | 0x1001d1c4 | 0x20644 | 0x1f044 | 0x3fd |
DER_GetInteger_Util | 0x0 | 0x1001d1c8 | 0x20648 | 0x1f048 | 0x95 |
PL_HashTableLookupConst | 0x0 | 0x1001d1cc | 0x2064c | 0x1f04c | 0x1cd |
PL_HashTableLookup | 0x0 | 0x1001d1d0 | 0x20650 | 0x1f050 | 0x1cc |
PL_HashTableRemove | 0x0 | 0x1001d1d4 | 0x20654 | 0x1f054 | 0x1d2 |
SEC_ASN1EncodeInteger_Util | 0x0 | 0x1001d1d8 | 0x20658 | 0x1f058 | 0x404 |
PL_HashTableAdd | 0x0 | 0x1001d1dc | 0x2065c | 0x1f05c | 0x1c8 |
SEC_ASN1EncodeItem_Util | 0x0 | 0x1001d1e0 | 0x20660 | 0x1f060 | 0x406 |
SEC_ASN1DecodeItem_Util | 0x0 | 0x1001d1e4 | 0x20664 | 0x1f064 | 0x402 |
SECITEM_ZfreeItem_Util | 0x0 | 0x1001d1e8 | 0x20668 | 0x1f068 | 0x3b6 |
SECITEM_FreeItem_Util | 0x0 | 0x1001d1ec | 0x2066c | 0x1f06c | 0x3b0 |
SECITEM_DupItem_Util | 0x0 | 0x1001d1f0 | 0x20670 | 0x1f070 | 0x3ae |
SECITEM_AllocItem_Util | 0x0 | 0x1001d1f4 | 0x20674 | 0x1f074 | 0x3a7 |
PORT_ZFree_Util | 0x0 | 0x1001d1f8 | 0x20678 | 0x1f078 | 0x21b |
PORT_ZAlloc_Util | 0x0 | 0x1001d1fc | 0x2067c | 0x1f07c | 0x21a |
SECITEM_CopyItem_Util | 0x0 | 0x1001d200 | 0x20680 | 0x1f080 | 0x3ab |
PORT_ArenaZAlloc_Util | 0x0 | 0x1001d204 | 0x20684 | 0x1f084 | 0x202 |
NSS_Get_SECOID_AlgorithmIDTemplate_Util | 0x0 | 0x1001d208 | 0x20688 | 0x1f088 | 0xff |
NSS_Get_SEC_ObjectIDTemplate_Util | 0x0 | 0x1001d20c | 0x2068c | 0x1f08c | 0x10b |
NSS_Get_SEC_BitStringTemplate_Util | 0x0 | 0x1001d210 | 0x20690 | 0x1f090 | 0x103 |
NSS_Get_SEC_AnyTemplate_Util | 0x0 | 0x1001d214 | 0x20694 | 0x1f094 | 0x100 |
PR_Unlock | 0x0 | 0x1001d218 | 0x20698 | 0x1f098 | 0x381 |
PR_Access | 0x0 | 0x1001d21c | 0x2069c | 0x1f09c | 0x225 |
PR_Lock | 0x0 | 0x1001d220 | 0x206a0 | 0x1f0a0 | 0x301 |
PL_HashTableDestroy | 0x0 | 0x1001d224 | 0x206a4 | 0x1f0a4 | 0x1c9 |
PORT_SetError_Util | 0x0 | 0x1001d228 | 0x206a8 | 0x1f0a8 | 0x210 |
sqlite3_bind_text | 0x0 | 0x1001d22c | 0x206ac | 0x1f0ac | 0x4b0 |
SECITEM_CompareItem_Util | 0x0 | 0x1001d230 | 0x206b0 | 0x1f0b0 | 0x3a9 |
PR_snprintf | 0x0 | 0x1001d234 | 0x206b4 | 0x1f0b4 | 0x39a |
PR_GetDirectorySeparator | 0x0 | 0x1001d238 | 0x206b8 | 0x1f0b8 | 0x2ab |
PR_GetEnvSecure | 0x0 | 0x1001d23c | 0x206bc | 0x1f0bc | 0x2ae |
PR_CallOnce | 0x0 | 0x1001d240 | 0x206c0 | 0x1f0c0 | 0x23e |
PR_SetError | 0x0 | 0x1001d244 | 0x206c4 | 0x1f0c4 | 0x357 |
PR_Free | 0x0 | 0x1001d248 | 0x206c8 | 0x1f0c8 | 0x29d |
PORT_Free_Util | 0x0 | 0x1001d24c | 0x206cc | 0x1f0cc | 0x207 |
PORT_Alloc_Util | 0x0 | 0x1001d250 | 0x206d0 | 0x1f0d0 | 0x1f8 |
PR_GetLibraryFilePathname | 0x0 | 0x1001d254 | 0x206d4 | 0x1f0d4 | 0x2bd |
PR_FindFunctionSymbol | 0x0 | 0x1001d258 | 0x206d8 | 0x1f0d8 | 0x292 |
PR_UnloadLibrary | 0x0 | 0x1001d25c | 0x206dc | 0x1f0dc | 0x380 |
sqlite3_bind_blob | 0x0 | 0x1001d260 | 0x206e0 | 0x1f0e0 | 0x4a8 |
PR_LoadLibraryWithFlags | 0x0 | 0x1001d264 | 0x206e4 | 0x1f0e4 | 0x2fe |
KERNEL32.dll (14)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InitializeSListHead | 0x0 | 0x1001d000 | 0x20480 | 0x1ee80 | 0x35a |
DisableThreadLibraryCalls | 0x0 | 0x1001d004 | 0x20484 | 0x1ee84 | 0x11b |
GetSystemTimeAsFileTime | 0x0 | 0x1001d008 | 0x20488 | 0x1ee88 | 0x2e2 |
GetCurrentThreadId | 0x0 | 0x1001d00c | 0x2048c | 0x1ee8c | 0x218 |
GetCurrentProcessId | 0x0 | 0x1001d010 | 0x20490 | 0x1ee90 | 0x214 |
QueryPerformanceCounter | 0x0 | 0x1001d014 | 0x20494 | 0x1ee94 | 0x440 |
IsProcessorFeaturePresent | 0x0 | 0x1001d018 | 0x20498 | 0x1ee98 | 0x37d |
TerminateProcess | 0x0 | 0x1001d01c | 0x2049c | 0x1ee9c | 0x57c |
GetCurrentProcess | 0x0 | 0x1001d020 | 0x204a0 | 0x1eea0 | 0x213 |
SetUnhandledExceptionFilter | 0x0 | 0x1001d024 | 0x204a4 | 0x1eea4 | 0x55e |
UnhandledExceptionFilter | 0x0 | 0x1001d028 | 0x204a8 | 0x1eea8 | 0x59d |
WideCharToMultiByte | 0x0 | 0x1001d02c | 0x204ac | 0x1eeac | 0x5f1 |
GetTempPathA | 0x0 | 0x1001d030 | 0x204b0 | 0x1eeb0 | 0x2ee |
IsDebuggerPresent | 0x0 | 0x1001d034 | 0x204b4 | 0x1eeb4 | 0x376 |
VCRUNTIME140.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
strrchr | 0x0 | 0x1001d03c | 0x204bc | 0x1eebc | 0x4b |
_except_handler4_common | 0x0 | 0x1001d040 | 0x204c0 | 0x1eec0 | 0x35 |
memcpy | 0x0 | 0x1001d044 | 0x204c4 | 0x1eec4 | 0x46 |
memset | 0x0 | 0x1001d048 | 0x204c8 | 0x1eec8 | 0x48 |
memcmp | 0x0 | 0x1001d04c | 0x204cc | 0x1eecc | 0x45 |
__std_type_info_destroy_list | 0x0 | 0x1001d050 | 0x204d0 | 0x1eed0 | 0x25 |
api-ms-win-crt-string-l1-1-0.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
islower | 0x0 | 0x1001d0a0 | 0x20520 | 0x1ef20 | 0x6b |
isupper | 0x0 | 0x1001d0a4 | 0x20524 | 0x1ef24 | 0x6f |
isdigit | 0x0 | 0x1001d0a8 | 0x20528 | 0x1ef28 | 0x68 |
api-ms-win-crt-convert-l1-1-0.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
atoi | 0x0 | 0x1001d058 | 0x204d8 | 0x1eed8 | 0x50 |
api-ms-win-crt-stdio-l1-1-0.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
__stdio_common_vsprintf | 0x0 | 0x1001d098 | 0x20518 | 0x1ef18 | 0xd |
api-ms-win-crt-heap-l1-1-0.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
free | 0x0 | 0x1001d068 | 0x204e8 | 0x1eee8 | 0x18 |
malloc | 0x0 | 0x1001d06c | 0x204ec | 0x1eeec | 0x19 |
api-ms-win-crt-filesystem-l1-1-0.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_wchmod | 0x0 | 0x1001d060 | 0x204e0 | 0x1eee0 | 0x28 |
api-ms-win-crt-runtime-l1-1-0.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_initialize_narrow_environment | 0x0 | 0x1001d074 | 0x204f4 | 0x1eef4 | 0x35 |
_initterm | 0x0 | 0x1001d078 | 0x204f8 | 0x1eef8 | 0x38 |
_configure_narrow_argv | 0x0 | 0x1001d07c | 0x204fc | 0x1eefc | 0x19 |
_initialize_onexit_table | 0x0 | 0x1001d080 | 0x20500 | 0x1ef00 | 0x36 |
_execute_onexit_table | 0x0 | 0x1001d084 | 0x20504 | 0x1ef04 | 0x24 |
_cexit | 0x0 | 0x1001d088 | 0x20508 | 0x1ef08 | 0x17 |
_seh_filter_dll | 0x0 | 0x1001d08c | 0x2050c | 0x1ef0c | 0x41 |
_initterm_e | 0x0 | 0x1001d090 | 0x20510 | 0x1ef10 | 0x39 |
Exports (4)
»
Api name | EAT Address | Ordinal |
---|---|---|
C_GetFunctionList | 0x6246 | 0x1 |
FC_GetFunctionList | 0x3218 | 0x2 |
NSC_GetFunctionList | 0x6246 | 0x3 |
NSC_ModuleDBFunc | 0x7663 | 0x4 |
Digital Signatures (3)
»
Certificate: Mozilla Corporation
»
Issued by | Mozilla Corporation |
Parent Certificate | DigiCert SHA2 Assured ID Code Signing CA |
Country Name | US |
Valid From | 2017-06-23 00:00:00+00:00 |
Valid Until | 2019-06-28 12:00:00+00:00 |
Algorithm | sha256_rsa |
Serial Number | 0C 53 96 DC B2 94 9C 70 FA C4 8A B0 8A 07 33 8E |
Thumbprint | B6 B2 4A EA 9E 98 3E D6 BD A9 58 6A 14 5A 7D DD 7E 22 01 96 |
Certificate: DigiCert SHA2 Assured ID Code Signing CA
»
Issued by | DigiCert SHA2 Assured ID Code Signing CA |
Parent Certificate | DigiCert Assured ID Root CA |
Country Name | US |
Valid From | 2013-10-22 12:00:00+00:00 |
Valid Until | 2028-10-22 12:00:00+00:00 |
Algorithm | sha256_rsa |
Serial Number | 04 09 18 1B 5F D5 BB 66 75 53 43 B5 6F 95 50 08 |
Thumbprint | 92 C1 58 8E 85 AF 22 01 CE 79 15 E8 53 8B 49 2F 60 5B 80 C6 |
Certificate: DigiCert Assured ID Root CA
»
Issued by | DigiCert Assured ID Root CA |
Country Name | US |
Valid From | 2006-11-10 00:00:00+00:00 |
Valid Until | 2031-11-10 00:00:00+00:00 |
Algorithm | sha1_rsa |
Serial Number | 0C E7 E0 E5 17 D8 46 FE 8F E5 60 FC 1B F0 30 39 |
Thumbprint | 05 63 B8 63 0D 62 D7 5A BB C8 AB 1E 4B DF B5 A8 99 B2 4D 43 |
C:\ProgramData\\vcruntime140.dll | Downloaded File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
PE Information
»
Image Base | 0x10000000 |
Entry Point | 0x1000ae00 |
Size Of Code | 0xea00 |
Size Of Initialized Data | 0x2000 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-05-25 20:01:16+00:00 |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | Microsoft® C Runtime Library |
FileVersion | 14.11.25325.0 built by: VCTOOLSREL |
InternalName | vcruntime140.dll |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | vcruntime140.dll |
ProductName | Microsoft® Visual Studio® 2017 |
ProductVersion | 14.11.25325.0 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x10001000 | 0xe9c4 | 0xea00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.data | 0x10010000 | 0x644 | 0x200 | 0xee00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.71 |
.idata | 0x10011000 | 0x5b8 | 0x600 | 0xf000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.04 |
.rsrc | 0x10012000 | 0x408 | 0x600 | 0xf600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.46 |
.reloc | 0x10013000 | 0xa94 | 0xc00 | 0xfc00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.21 |
Imports (6)
»
api-ms-win-crt-runtime-l1-1-0.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
abort | 0x0 | 0x1001109c | 0x111e8 | 0xf1e8 | 0x57 |
terminate | 0x0 | 0x100110a0 | 0x111ec | 0xf1ec | 0x6a |
api-ms-win-crt-string-l1-1-0.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
strcpy_s | 0x0 | 0x100110b0 | 0x111fc | 0xf1fc | 0x89 |
wcsncmp | 0x0 | 0x100110b4 | 0x11200 | 0xf200 | 0xa6 |
api-ms-win-crt-heap-l1-1-0.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
malloc | 0x0 | 0x10011084 | 0x111d0 | 0xf1d0 | 0x19 |
_free_base | 0x0 | 0x10011088 | 0x111d4 | 0xf1d4 | 0xb |
free | 0x0 | 0x1001108c | 0x111d8 | 0xf1d8 | 0x18 |
_malloc_base | 0x0 | 0x10011090 | 0x111dc | 0xf1dc | 0x10 |
_calloc_base | 0x0 | 0x10011094 | 0x111e0 | 0xf1e0 | 0x9 |
api-ms-win-crt-stdio-l1-1-0.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
__stdio_common_vsprintf_s | 0x0 | 0x100110a8 | 0x111f4 | 0xf1f4 | 0xf |
api-ms-win-crt-convert-l1-1-0.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
atol | 0x0 | 0x1001107c | 0x111c8 | 0xf1c8 | 0x51 |
KERNEL32.dll (30)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LeaveCriticalSection | 0x0 | 0x10011000 | 0x1114c | 0xf14c | 0x3a0 |
TerminateProcess | 0x0 | 0x10011004 | 0x11150 | 0xf150 | 0x561 |
GetCurrentProcess | 0x0 | 0x10011008 | 0x11154 | 0xf154 | 0x207 |
SetUnhandledExceptionFilter | 0x0 | 0x1001100c | 0x11158 | 0xf158 | 0x543 |
UnhandledExceptionFilter | 0x0 | 0x10011010 | 0x1115c | 0xf15c | 0x582 |
GetSystemTimeAsFileTime | 0x0 | 0x10011014 | 0x11160 | 0xf160 | 0x2d4 |
GetCurrentThreadId | 0x0 | 0x10011018 | 0x11164 | 0xf164 | 0x20c |
GetCurrentProcessId | 0x0 | 0x1001101c | 0x11168 | 0xf168 | 0x208 |
QueryPerformanceCounter | 0x0 | 0x10011020 | 0x1116c | 0xf16c | 0x42b |
IsProcessorFeaturePresent | 0x0 | 0x10011024 | 0x11170 | 0xf170 | 0x36b |
GetModuleHandleW | 0x0 | 0x10011028 | 0x11174 | 0xf174 | 0x265 |
GetModuleFileNameW | 0x0 | 0x1001102c | 0x11178 | 0xf178 | 0x261 |
LoadLibraryExW | 0x0 | 0x10011030 | 0x1117c | 0xf17c | 0x3a5 |
TlsFree | 0x0 | 0x10011034 | 0x11180 | 0xf180 | 0x574 |
TlsGetValue | 0x0 | 0x10011038 | 0x11184 | 0xf184 | 0x575 |
FreeLibrary | 0x0 | 0x1001103c | 0x11188 | 0xf188 | 0x19c |
RtlUnwind | 0x0 | 0x10011040 | 0x1118c | 0xf18c | 0x4ad |
VirtualQuery | 0x0 | 0x10011044 | 0x11190 | 0xf190 | 0x5a3 |
EncodePointer | 0x0 | 0x10011048 | 0x11194 | 0xf194 | 0x11f |
InterlockedFlushSList | 0x0 | 0x1001104c | 0x11198 | 0xf198 | 0x352 |
InterlockedPushEntrySList | 0x0 | 0x10011050 | 0x1119c | 0xf19c | 0x355 |
RaiseException | 0x0 | 0x10011054 | 0x111a0 | 0xf1a0 | 0x43f |
EnterCriticalSection | 0x0 | 0x10011058 | 0x111a4 | 0xf1a4 | 0x123 |
DeleteCriticalSection | 0x0 | 0x1001105c | 0x111a8 | 0xf1a8 | 0x103 |
SetLastError | 0x0 | 0x10011060 | 0x111ac | 0xf1ac | 0x50b |
GetLastError | 0x0 | 0x10011064 | 0x111b0 | 0xf1b0 | 0x24e |
TlsSetValue | 0x0 | 0x10011068 | 0x111b4 | 0xf1b4 | 0x576 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x1001106c | 0x111b8 | 0xf1b8 | 0x346 |
TlsAlloc | 0x0 | 0x10011070 | 0x111bc | 0xf1bc | 0x573 |
GetProcAddress | 0x0 | 0x10011074 | 0x111c0 | 0xf1c0 | 0x29b |
Exports (81)
»
Api name | EAT Address | Ordinal |
---|---|---|
_CreateFrameInfo | 0xe540 | 0x1 |
_CxxThrowException | 0x4690 | 0x2 |
_EH_prolog | 0xeb50 | 0x3 |
_FindAndUnlinkFrame | 0xe570 | 0x4 |
_IsExceptionObjectToBeDestroyed | 0x2ce0 | 0x5 |
_NLG_Dispatch2 | 0xb463 | 0x6 |
_NLG_Return | 0xd0b7 | 0x7 |
_NLG_Return2 | 0xb46d | 0x8 |
_SetWinRTOutOfMemoryExceptionCallback | 0x2c20 | 0x9 |
__AdjustPointer | 0x2ad0 | 0xa |
__BuildCatchObject | 0x3930 | 0xb |
__BuildCatchObjectHelper | 0x3800 | 0xc |
__CxxDetectRethrow | 0x3cb0 | 0xd |
__CxxExceptionFilter | 0x3ab0 | 0xe |
__CxxFrameHandler | 0xe660 | 0xf |
__CxxFrameHandler2 | 0xe660 | 0x10 |
__CxxFrameHandler3 | 0xe660 | 0x11 |
__CxxLongjmpUnwind | 0xe6a0 | 0x12 |
__CxxQueryExceptionSize | 0x3e10 | 0x13 |
__CxxRegisterExceptionObject | 0x3c00 | 0x14 |
__CxxUnregisterExceptionObject | 0x3d00 | 0x15 |
__DestructExceptionObject | 0x2c40 | 0x16 |
__FrameUnwindFilter | 0x2bd0 | 0x17 |
__GetPlatformExceptionInfo | 0x2b00 | 0x18 |
__RTCastToVoid | 0x3e60 | 0x19 |
__RTDynamicCast | 0x3f80 | 0x1a |
__RTtypeid | 0x3f00 | 0x1b |
__TypeMatch | 0x3420 | 0x1c |
__current_exception | 0x2ba0 | 0x1d |
__current_exception_context | 0x2bb0 | 0x1e |
__intrinsic_setjmp | 0xb260 | 0x1f |
__processing_throw | 0x2bc0 | 0x20 |
__report_gsfailure | 0xeba0 | 0x21 |
__std_exception_copy | 0x4470 | 0x22 |
__std_exception_destroy | 0x44e0 | 0x23 |
__std_terminate | 0x2c30 | 0x24 |
__std_type_info_compare | 0x4500 | 0x25 |
__std_type_info_destroy_list | 0x4660 | 0x26 |
__std_type_info_hash | 0x4540 | 0x27 |
__std_type_info_name | 0x4570 | 0x28 |
__telemetry_main_invoke_trigger | 0x2670 | 0x29 |
__telemetry_main_return_trigger | 0x2670 | 0x2a |
__unDName | 0x4d20 | 0x2b |
__unDNameEx | 0x4dc0 | 0x2c |
__uncaught_exception | 0x2b90 | 0x2d |
__uncaught_exceptions | 0x2b50 | 0x2e |
__vcrt_GetModuleFileNameW | 0x4bd0 | 0x2f |
__vcrt_GetModuleHandleW | 0x4bf0 | 0x30 |
__vcrt_InitializeCriticalSectionEx | 0x4b80 | 0x31 |
__vcrt_LoadLibraryExW | 0x4c00 | 0x32 |
_chkesp | 0xb670 | 0x33 |
_except_handler2 | 0xae28 | 0x34 |
_except_handler3 | 0xaef8 | 0x35 |
_except_handler4_common | 0xb500 | 0x36 |
_get_purecall_handler | 0x4c80 | 0x37 |
_get_unexpected | 0x4700 | 0x38 |
_global_unwind2 | 0xb330 | 0x39 |
_is_exception_typeof | 0x2d10 | 0x3a |
_local_unwind2 | 0xb396 | 0x3b |
_local_unwind4 | 0xb030 | 0x3c |
_longjmpex | 0xb320 | 0x3d |
_purecall | 0x4c20 | 0x3e |
_seh_longjmp_unwind | 0xb004 | 0x40 |
_seh_longjmp_unwind4 | 0xb108 | 0x3f |
_set_purecall_handler | 0x4c40 | 0x41 |
_set_se_translator | 0x4760 | 0x42 |
_setjmp3 | 0xb2a0 | 0x43 |
longjmp | 0x26d0 | 0x44 |
memchr | 0xd0e0 | 0x45 |
memcmp | 0xbb10 | 0x46 |
memcpy | 0xd190 | 0x47 |
memmove | 0xd710 | 0x48 |
memset | 0xdc90 | 0x49 |
set_unexpected | 0x4720 | 0x4a |
strchr | 0xddf0 | 0x4b |
strrchr | 0xdf20 | 0x4c |
strstr | 0xe060 | 0x4d |
unexpected | 0x4740 | 0x4e |
wcschr | 0x26f0 | 0x4f |
wcsrchr | 0x2790 | 0x50 |
wcsstr | 0x2840 | 0x51 |
Digital Signatures (2)
»
Certificate: Microsoft Corporation
»
Issued by | Microsoft Corporation |
Parent Certificate | Microsoft Code Signing PCA |
Country Name | US |
Valid From | 2016-08-18 20:17:17+00:00 |
Valid Until | 2017-11-02 20:17:17+00:00 |
Algorithm | sha1_rsa |
Serial Number | 33 00 00 01 40 96 A9 EE 70 56 FE CC 07 00 01 00 00 01 40 |
Thumbprint | 98 ED 99 A6 78 86 D0 20 C5 64 92 3B 7D F2 5E 9A C0 19 DF 26 |
Certificate: Microsoft Code Signing PCA
»
Issued by | Microsoft Code Signing PCA |
Country Name | US |
Valid From | 2010-08-31 22:19:32+00:00 |
Valid Until | 2020-08-31 22:29:32+00:00 |
Algorithm | sha1_rsa |
Serial Number | 61 33 26 1A 00 00 00 00 00 31 |
Thumbprint | 3C AF 9B A2 DB 55 70 CA F7 69 42 FF 99 10 1B 99 38 88 E2 57 |
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\Data1.cab | Modified File | CAB |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\x9ohk109\geo[1].json | Dropped File | Text |
Unknown
|
...
|
»
files\History\Google Chrome_Default.txt | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\pmmr5k9k\line[1].txt | Downloaded File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\script.ps1 | Dropped File | Text |
Not Queried
|
...
|
»
files\History\history_Mozilla Firefox_silmbjec.default.txt | Dropped File | Text |
Not Queried
|
...
|
»
files\Cookies\IE_Cookies.txt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\bowsakkdestx.txt | Downloaded File | Text |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\x9ohk109\517[1].txt | Downloaded File | Text |
Not Queried
|
...
|
»