VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Dropper |
YARRRRRRRRRRRRRRRRRRRRAK.exe
Windows Exe (x86-32)
Created at 2019-12-09T11:39:00
Remarks
(0x200000c): The maximum memory dump size was exceeded. Some dumps may be missing in the report.
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\YARRRRRRRRRRRRRRRRRRRRAK.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x40cd2f |
Size Of Code | 0x19800 |
Size Of Initialized Data | 0x5f400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2012-07-13 22:47:16+00:00 |
Version Information (9)
»
Assembly Version | 1.0.0.0 |
CompanyName | Wolf Beta Hack |
FileDescription | Enes Keleş Güncelleme |
FileVersion | 1.0.0.0 |
InternalName | Silici Temizliyici.exe |
LegalCopyright | Copyright © Enes Keleş - Wolf Beta Hack |
OriginalFilename | Silici Temizliyici.exe |
ProductName | Güncelleme & Log Temizleme |
ProductVersion | 1.0.0.0 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x19718 | 0x19800 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.75 |
.rdata | 0x41b000 | 0x6db4 | 0x6e00 | 0x19c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.44 |
.data | 0x422000 | 0x30c0 | 0x1600 | 0x20a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.26 |
.rsrc | 0x426000 | 0x56f9c | 0x57000 | 0x22000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.78 |
.enigma1 | 0x47d000 | 0x1000 | 0x1d000 | 0x79000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.87 |
.enigma2 | 0x47e000 | 0x40000 | 0x40000 | 0x96000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.93 |
Imports (18)
»
kernel32.dll (37)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DeleteCriticalSection | 0x0 | 0x4b617c | 0xb617c | 0xce17c | 0x0 |
LeaveCriticalSection | 0x0 | 0x4b6180 | 0xb6180 | 0xce180 | 0x0 |
EnterCriticalSection | 0x0 | 0x4b6184 | 0xb6184 | 0xce184 | 0x0 |
InitializeCriticalSection | 0x0 | 0x4b6188 | 0xb6188 | 0xce188 | 0x0 |
VirtualFree | 0x0 | 0x4b618c | 0xb618c | 0xce18c | 0x0 |
VirtualAlloc | 0x0 | 0x4b6190 | 0xb6190 | 0xce190 | 0x0 |
LocalFree | 0x0 | 0x4b6194 | 0xb6194 | 0xce194 | 0x0 |
LocalAlloc | 0x0 | 0x4b6198 | 0xb6198 | 0xce198 | 0x0 |
GetTickCount | 0x0 | 0x4b619c | 0xb619c | 0xce19c | 0x0 |
QueryPerformanceCounter | 0x0 | 0x4b61a0 | 0xb61a0 | 0xce1a0 | 0x0 |
GetVersion | 0x0 | 0x4b61a4 | 0xb61a4 | 0xce1a4 | 0x0 |
GetCurrentThreadId | 0x0 | 0x4b61a8 | 0xb61a8 | 0xce1a8 | 0x0 |
InterlockedDecrement | 0x0 | 0x4b61ac | 0xb61ac | 0xce1ac | 0x0 |
InterlockedIncrement | 0x0 | 0x4b61b0 | 0xb61b0 | 0xce1b0 | 0x0 |
VirtualQuery | 0x0 | 0x4b61b4 | 0xb61b4 | 0xce1b4 | 0x0 |
WideCharToMultiByte | 0x0 | 0x4b61b8 | 0xb61b8 | 0xce1b8 | 0x0 |
MultiByteToWideChar | 0x0 | 0x4b61bc | 0xb61bc | 0xce1bc | 0x0 |
lstrlenA | 0x0 | 0x4b61c0 | 0xb61c0 | 0xce1c0 | 0x0 |
lstrcpynA | 0x0 | 0x4b61c4 | 0xb61c4 | 0xce1c4 | 0x0 |
LoadLibraryExA | 0x0 | 0x4b61c8 | 0xb61c8 | 0xce1c8 | 0x0 |
GetThreadLocale | 0x0 | 0x4b61cc | 0xb61cc | 0xce1cc | 0x0 |
GetStartupInfoA | 0x0 | 0x4b61d0 | 0xb61d0 | 0xce1d0 | 0x0 |
GetProcAddress | 0x0 | 0x4b61d4 | 0xb61d4 | 0xce1d4 | 0x0 |
GetModuleHandleA | 0x0 | 0x4b61d8 | 0xb61d8 | 0xce1d8 | 0x0 |
GetModuleFileNameA | 0x0 | 0x4b61dc | 0xb61dc | 0xce1dc | 0x0 |
GetLocaleInfoA | 0x0 | 0x4b61e0 | 0xb61e0 | 0xce1e0 | 0x0 |
GetCommandLineA | 0x0 | 0x4b61e4 | 0xb61e4 | 0xce1e4 | 0x0 |
FreeLibrary | 0x0 | 0x4b61e8 | 0xb61e8 | 0xce1e8 | 0x0 |
FindFirstFileA | 0x0 | 0x4b61ec | 0xb61ec | 0xce1ec | 0x0 |
FindClose | 0x0 | 0x4b61f0 | 0xb61f0 | 0xce1f0 | 0x0 |
ExitProcess | 0x0 | 0x4b61f4 | 0xb61f4 | 0xce1f4 | 0x0 |
ExitThread | 0x0 | 0x4b61f8 | 0xb61f8 | 0xce1f8 | 0x0 |
WriteFile | 0x0 | 0x4b61fc | 0xb61fc | 0xce1fc | 0x0 |
UnhandledExceptionFilter | 0x0 | 0x4b6200 | 0xb6200 | 0xce200 | 0x0 |
RtlUnwind | 0x0 | 0x4b6204 | 0xb6204 | 0xce204 | 0x0 |
RaiseException | 0x0 | 0x4b6208 | 0xb6208 | 0xce208 | 0x0 |
GetStdHandle | 0x0 | 0x4b620c | 0xb620c | 0xce20c | 0x0 |
user32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetKeyboardType | 0x0 | 0x4b6214 | 0xb6214 | 0xce214 | 0x0 |
LoadStringA | 0x0 | 0x4b6218 | 0xb6218 | 0xce218 | 0x0 |
MessageBoxA | 0x0 | 0x4b621c | 0xb621c | 0xce21c | 0x0 |
CharNextA | 0x0 | 0x4b6220 | 0xb6220 | 0xce220 | 0x0 |
advapi32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryValueExA | 0x0 | 0x4b6228 | 0xb6228 | 0xce228 | 0x0 |
RegOpenKeyExA | 0x0 | 0x4b622c | 0xb622c | 0xce22c | 0x0 |
RegCloseKey | 0x0 | 0x4b6230 | 0xb6230 | 0xce230 | 0x0 |
oleaut32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysFreeString | 0x0 | 0x4b6238 | 0xb6238 | 0xce238 | 0x0 |
SysReAllocStringLen | 0x0 | 0x4b623c | 0xb623c | 0xce23c | 0x0 |
SysAllocStringLen | 0x0 | 0x4b6240 | 0xb6240 | 0xce240 | 0x0 |
kernel32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
TlsSetValue | 0x0 | 0x4b6248 | 0xb6248 | 0xce248 | 0x0 |
TlsGetValue | 0x0 | 0x4b624c | 0xb624c | 0xce24c | 0x0 |
TlsFree | 0x0 | 0x4b6250 | 0xb6250 | 0xce250 | 0x0 |
TlsAlloc | 0x0 | 0x4b6254 | 0xb6254 | 0xce254 | 0x0 |
LocalFree | 0x0 | 0x4b6258 | 0xb6258 | 0xce258 | 0x0 |
LocalAlloc | 0x0 | 0x4b625c | 0xb625c | 0xce25c | 0x0 |
advapi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegOpenKeyA | 0x0 | 0x4b6264 | 0xb6264 | 0xce264 | 0x0 |
kernel32.dll (105)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WriteProcessMemory | 0x0 | 0x4b626c | 0xb626c | 0xce26c | 0x0 |
WriteFile | 0x0 | 0x4b6270 | 0xb6270 | 0xce270 | 0x0 |
WideCharToMultiByte | 0x0 | 0x4b6274 | 0xb6274 | 0xce274 | 0x0 |
WaitForSingleObject | 0x0 | 0x4b6278 | 0xb6278 | 0xce278 | 0x0 |
VirtualQuery | 0x0 | 0x4b627c | 0xb627c | 0xce27c | 0x0 |
VirtualProtectEx | 0x0 | 0x4b6280 | 0xb6280 | 0xce280 | 0x0 |
VirtualProtect | 0x0 | 0x4b6284 | 0xb6284 | 0xce284 | 0x0 |
VirtualFree | 0x0 | 0x4b6288 | 0xb6288 | 0xce288 | 0x0 |
VirtualAllocEx | 0x0 | 0x4b628c | 0xb628c | 0xce28c | 0x0 |
VirtualAlloc | 0x0 | 0x4b6290 | 0xb6290 | 0xce290 | 0x0 |
SystemTimeToFileTime | 0x0 | 0x4b6294 | 0xb6294 | 0xce294 | 0x0 |
SizeofResource | 0x0 | 0x4b6298 | 0xb6298 | 0xce298 | 0x0 |
SetThreadContext | 0x0 | 0x4b629c | 0xb629c | 0xce29c | 0x0 |
SetLastError | 0x0 | 0x4b62a0 | 0xb62a0 | 0xce2a0 | 0x0 |
SetFileTime | 0x0 | 0x4b62a4 | 0xb62a4 | 0xce2a4 | 0x0 |
SetFilePointer | 0x0 | 0x4b62a8 | 0xb62a8 | 0xce2a8 | 0x0 |
SetFileAttributesW | 0x0 | 0x4b62ac | 0xb62ac | 0xce2ac | 0x0 |
SetFileAttributesA | 0x0 | 0x4b62b0 | 0xb62b0 | 0xce2b0 | 0x0 |
SetEvent | 0x0 | 0x4b62b4 | 0xb62b4 | 0xce2b4 | 0x0 |
SetErrorMode | 0x0 | 0x4b62b8 | 0xb62b8 | 0xce2b8 | 0x0 |
SetEndOfFile | 0x0 | 0x4b62bc | 0xb62bc | 0xce2bc | 0x0 |
SetCurrentDirectoryW | 0x0 | 0x4b62c0 | 0xb62c0 | 0xce2c0 | 0x0 |
SetCurrentDirectoryA | 0x0 | 0x4b62c4 | 0xb62c4 | 0xce2c4 | 0x0 |
ResetEvent | 0x0 | 0x4b62c8 | 0xb62c8 | 0xce2c8 | 0x0 |
RemoveDirectoryW | 0x0 | 0x4b62cc | 0xb62cc | 0xce2cc | 0x0 |
RemoveDirectoryA | 0x0 | 0x4b62d0 | 0xb62d0 | 0xce2d0 | 0x0 |
ReadProcessMemory | 0x0 | 0x4b62d4 | 0xb62d4 | 0xce2d4 | 0x0 |
ReadFile | 0x0 | 0x4b62d8 | 0xb62d8 | 0xce2d8 | 0x0 |
QueryDosDeviceW | 0x0 | 0x4b62dc | 0xb62dc | 0xce2dc | 0x0 |
PostQueuedCompletionStatus | 0x0 | 0x4b62e0 | 0xb62e0 | 0xce2e0 | 0x0 |
MultiByteToWideChar | 0x0 | 0x4b62e4 | 0xb62e4 | 0xce2e4 | 0x0 |
LockResource | 0x0 | 0x4b62e8 | 0xb62e8 | 0xce2e8 | 0x0 |
LoadResource | 0x0 | 0x4b62ec | 0xb62ec | 0xce2ec | 0x0 |
LoadLibraryW | 0x0 | 0x4b62f0 | 0xb62f0 | 0xce2f0 | 0x0 |
LoadLibraryA | 0x0 | 0x4b62f4 | 0xb62f4 | 0xce2f4 | 0x0 |
LeaveCriticalSection | 0x0 | 0x4b62f8 | 0xb62f8 | 0xce2f8 | 0x0 |
IsBadWritePtr | 0x0 | 0x4b62fc | 0xb62fc | 0xce2fc | 0x0 |
IsBadStringPtrW | 0x0 | 0x4b6300 | 0xb6300 | 0xce300 | 0x0 |
IsBadReadPtr | 0x0 | 0x4b6304 | 0xb6304 | 0xce304 | 0x0 |
InitializeCriticalSection | 0x0 | 0x4b6308 | 0xb6308 | 0xce308 | 0x0 |
GetWindowsDirectoryW | 0x0 | 0x4b630c | 0xb630c | 0xce30c | 0x0 |
GetWindowsDirectoryA | 0x0 | 0x4b6310 | 0xb6310 | 0xce310 | 0x0 |
GetVersionExA | 0x0 | 0x4b6314 | 0xb6314 | 0xce314 | 0x0 |
GetVersion | 0x0 | 0x4b6318 | 0xb6318 | 0xce318 | 0x0 |
GetThreadLocale | 0x0 | 0x4b631c | 0xb631c | 0xce31c | 0x0 |
GetThreadContext | 0x0 | 0x4b6320 | 0xb6320 | 0xce320 | 0x0 |
GetTempPathW | 0x0 | 0x4b6324 | 0xb6324 | 0xce324 | 0x0 |
GetTempPathA | 0x0 | 0x4b6328 | 0xb6328 | 0xce328 | 0x0 |
GetTempFileNameW | 0x0 | 0x4b632c | 0xb632c | 0xce32c | 0x0 |
GetTempFileNameA | 0x0 | 0x4b6330 | 0xb6330 | 0xce330 | 0x0 |
GetSystemDirectoryW | 0x0 | 0x4b6334 | 0xb6334 | 0xce334 | 0x0 |
GetSystemDirectoryA | 0x0 | 0x4b6338 | 0xb6338 | 0xce338 | 0x0 |
GetStringTypeExW | 0x0 | 0x4b633c | 0xb633c | 0xce33c | 0x0 |
GetStringTypeExA | 0x0 | 0x4b6340 | 0xb6340 | 0xce340 | 0x0 |
GetStdHandle | 0x0 | 0x4b6344 | 0xb6344 | 0xce344 | 0x0 |
GetProcAddress | 0x0 | 0x4b6348 | 0xb6348 | 0xce348 | 0x0 |
GetModuleHandleA | 0x0 | 0x4b634c | 0xb634c | 0xce34c | 0x0 |
GetModuleFileNameW | 0x0 | 0x4b6350 | 0xb6350 | 0xce350 | 0x0 |
GetModuleFileNameA | 0x0 | 0x4b6354 | 0xb6354 | 0xce354 | 0x0 |
GetLogicalDriveStringsW | 0x0 | 0x4b6358 | 0xb6358 | 0xce358 | 0x0 |
GetLocaleInfoW | 0x0 | 0x4b635c | 0xb635c | 0xce35c | 0x0 |
GetLocaleInfoA | 0x0 | 0x4b6360 | 0xb6360 | 0xce360 | 0x0 |
GetLocalTime | 0x0 | 0x4b6364 | 0xb6364 | 0xce364 | 0x0 |
GetLastError | 0x0 | 0x4b6368 | 0xb6368 | 0xce368 | 0x0 |
GetFullPathNameW | 0x0 | 0x4b636c | 0xb636c | 0xce36c | 0x0 |
GetFullPathNameA | 0x0 | 0x4b6370 | 0xb6370 | 0xce370 | 0x0 |
GetFileSize | 0x0 | 0x4b6374 | 0xb6374 | 0xce374 | 0x0 |
GetFileAttributesW | 0x0 | 0x4b6378 | 0xb6378 | 0xce378 | 0x0 |
GetFileAttributesA | 0x0 | 0x4b637c | 0xb637c | 0xce37c | 0x0 |
GetDiskFreeSpaceA | 0x0 | 0x4b6380 | 0xb6380 | 0xce380 | 0x0 |
GetDateFormatA | 0x0 | 0x4b6384 | 0xb6384 | 0xce384 | 0x0 |
GetCurrentThreadId | 0x0 | 0x4b6388 | 0xb6388 | 0xce388 | 0x0 |
GetCurrentProcessId | 0x0 | 0x4b638c | 0xb638c | 0xce38c | 0x0 |
GetCurrentProcess | 0x0 | 0x4b6390 | 0xb6390 | 0xce390 | 0x0 |
GetCurrentDirectoryW | 0x0 | 0x4b6394 | 0xb6394 | 0xce394 | 0x0 |
GetCurrentDirectoryA | 0x0 | 0x4b6398 | 0xb6398 | 0xce398 | 0x0 |
GetCPInfo | 0x0 | 0x4b639c | 0xb639c | 0xce39c | 0x0 |
GetACP | 0x0 | 0x4b63a0 | 0xb63a0 | 0xce3a0 | 0x0 |
FreeResource | 0x0 | 0x4b63a4 | 0xb63a4 | 0xce3a4 | 0x0 |
FreeLibrary | 0x0 | 0x4b63a8 | 0xb63a8 | 0xce3a8 | 0x0 |
FormatMessageA | 0x0 | 0x4b63ac | 0xb63ac | 0xce3ac | 0x0 |
FlushInstructionCache | 0x0 | 0x4b63b0 | 0xb63b0 | 0xce3b0 | 0x0 |
FindResourceW | 0x0 | 0x4b63b4 | 0xb63b4 | 0xce3b4 | 0x0 |
FindNextFileW | 0x0 | 0x4b63b8 | 0xb63b8 | 0xce3b8 | 0x0 |
FindNextFileA | 0x0 | 0x4b63bc | 0xb63bc | 0xce3bc | 0x0 |
FindFirstFileW | 0x0 | 0x4b63c0 | 0xb63c0 | 0xce3c0 | 0x0 |
FindFirstFileA | 0x0 | 0x4b63c4 | 0xb63c4 | 0xce3c4 | 0x0 |
FindClose | 0x0 | 0x4b63c8 | 0xb63c8 | 0xce3c8 | 0x0 |
FileTimeToLocalFileTime | 0x0 | 0x4b63cc | 0xb63cc | 0xce3cc | 0x0 |
FileTimeToDosDateTime | 0x0 | 0x4b63d0 | 0xb63d0 | 0xce3d0 | 0x0 |
ExitProcess | 0x0 | 0x4b63d4 | 0xb63d4 | 0xce3d4 | 0x0 |
EnumCalendarInfoA | 0x0 | 0x4b63d8 | 0xb63d8 | 0xce3d8 | 0x0 |
EnterCriticalSection | 0x0 | 0x4b63dc | 0xb63dc | 0xce3dc | 0x0 |
DeleteFileW | 0x0 | 0x4b63e0 | 0xb63e0 | 0xce3e0 | 0x0 |
DeleteFileA | 0x0 | 0x4b63e4 | 0xb63e4 | 0xce3e4 | 0x0 |
DeleteCriticalSection | 0x0 | 0x4b63e8 | 0xb63e8 | 0xce3e8 | 0x0 |
CreateRemoteThread | 0x0 | 0x4b63ec | 0xb63ec | 0xce3ec | 0x0 |
CreateFileW | 0x0 | 0x4b63f0 | 0xb63f0 | 0xce3f0 | 0x0 |
CreateFileA | 0x0 | 0x4b63f4 | 0xb63f4 | 0xce3f4 | 0x0 |
CreateEventA | 0x0 | 0x4b63f8 | 0xb63f8 | 0xce3f8 | 0x0 |
CreateDirectoryW | 0x0 | 0x4b63fc | 0xb63fc | 0xce3fc | 0x0 |
CreateDirectoryA | 0x0 | 0x4b6400 | 0xb6400 | 0xce400 | 0x0 |
CompareStringW | 0x0 | 0x4b6404 | 0xb6404 | 0xce404 | 0x0 |
CompareStringA | 0x0 | 0x4b6408 | 0xb6408 | 0xce408 | 0x0 |
CloseHandle | 0x0 | 0x4b640c | 0xb640c | 0xce40c | 0x0 |
user32.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MessageBoxA | 0x0 | 0x4b6414 | 0xb6414 | 0xce414 | 0x0 |
LoadStringA | 0x0 | 0x4b6418 | 0xb6418 | 0xce418 | 0x0 |
GetSystemMetrics | 0x0 | 0x4b641c | 0xb641c | 0xce41c | 0x0 |
CharUpperBuffW | 0x0 | 0x4b6420 | 0xb6420 | 0xce420 | 0x0 |
CharUpperW | 0x0 | 0x4b6424 | 0xb6424 | 0xce424 | 0x0 |
CharLowerBuffW | 0x0 | 0x4b6428 | 0xb6428 | 0xce428 | 0x0 |
CharLowerW | 0x0 | 0x4b642c | 0xb642c | 0xce42c | 0x0 |
CharNextA | 0x0 | 0x4b6430 | 0xb6430 | 0xce430 | 0x0 |
CharLowerA | 0x0 | 0x4b6434 | 0xb6434 | 0xce434 | 0x0 |
CharUpperA | 0x0 | 0x4b6438 | 0xb6438 | 0xce438 | 0x0 |
CharToOemA | 0x0 | 0x4b643c | 0xb643c | 0xce43c | 0x0 |
kernel32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Sleep | 0x0 | 0x4b6444 | 0xb6444 | 0xce444 | 0x0 |
kernel32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ActivateActCtx | 0x0 | 0x4b644c | 0xb644c | 0xce44c | 0x0 |
CreateActCtxW | 0x0 | 0x4b6450 | 0xb6450 | 0xce450 | 0x0 |
QueryDosDeviceW | 0x0 | 0x4b6454 | 0xb6454 | 0xce454 | 0x0 |
ole32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateStreamOnHGlobal | 0x0 | 0x4b645c | 0xb645c | 0xce45c | 0x0 |
CoUninitialize | 0x0 | 0x4b6460 | 0xb6460 | 0xce460 | 0x0 |
CoInitialize | 0x0 | 0x4b6464 | 0xb6464 | 0xce464 | 0x0 |
oleaut32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetErrorInfo | 0x0 | 0x4b646c | 0xb646c | 0xce46c | 0x0 |
SysFreeString | 0x0 | 0x4b6470 | 0xb6470 | 0xce470 | 0x0 |
oleaut32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SafeArrayPtrOfIndex | 0x0 | 0x4b6478 | 0xb6478 | 0xce478 | 0x0 |
SafeArrayGetUBound | 0x0 | 0x4b647c | 0xb647c | 0xce47c | 0x0 |
SafeArrayGetLBound | 0x0 | 0x4b6480 | 0xb6480 | 0xce480 | 0x0 |
SafeArrayCreate | 0x0 | 0x4b6484 | 0xb6484 | 0xce484 | 0x0 |
VariantChangeType | 0x0 | 0x4b6488 | 0xb6488 | 0xce488 | 0x0 |
VariantCopy | 0x0 | 0x4b648c | 0xb648c | 0xce48c | 0x0 |
VariantClear | 0x0 | 0x4b6490 | 0xb6490 | 0xce490 | 0x0 |
VariantInit | 0x0 | 0x4b6494 | 0xb6494 | 0xce494 | 0x0 |
ntdll.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RtlInitUnicodeString | 0x0 | 0x4b649c | 0xb649c | 0xce49c | 0x0 |
RtlFreeUnicodeString | 0x0 | 0x4b64a0 | 0xb64a0 | 0xce4a0 | 0x0 |
RtlFormatCurrentUserKeyPath | 0x0 | 0x4b64a4 | 0xb64a4 | 0xce4a4 | 0x0 |
RtlDosPathNameToNtPathName_U | 0x0 | 0x4b64a8 | 0xb64a8 | 0xce4a8 | 0x0 |
SHFolder.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetFolderPathW | 0x0 | 0x4b64b0 | 0xb64b0 | 0xce4b0 | 0x0 |
SHGetFolderPathA | 0x0 | 0x4b64b4 | 0xb64b4 | 0xce4b4 | 0x0 |
ntdll.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ZwProtectVirtualMemory | 0x0 | 0x4b64bc | 0xb64bc | 0xce4bc | 0x0 |
shlwapi.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathMatchSpecW | 0x0 | 0x4b64c4 | 0xb64c4 | 0xce4c4 | 0x0 |
ntdll.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LdrGetProcedureAddress | 0x0 | 0x4b64cc | 0xb64cc | 0xce4cc | 0x0 |
RtlFreeUnicodeString | 0x0 | 0x4b64d0 | 0xb64d0 | 0xce4d0 | 0x0 |
RtlInitAnsiString | 0x0 | 0x4b64d4 | 0xb64d4 | 0xce4d4 | 0x0 |
RtlAnsiStringToUnicodeString | 0x0 | 0x4b64d8 | 0xb64d8 | 0xce4d8 | 0x0 |
LdrLoadDll | 0x0 | 0x4b64dc | 0xb64dc | 0xce4dc | 0x0 |
Memory Dumps (61)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
yarrrrrrrrrrrrrrrrrrrrak.exe | 1 | 0x00400000 | 0x004BDFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00320000 | 0x00320FFF | Content Changed | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00330000 | 0x00330FFF | Content Changed | - | 32-bit | - |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
buffer | 1 | 0x00610000 | 0x00610FFF | First Execution | - | 32-bit | 0x00610000 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Graftor.684088 |
Malicious
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\gdipfontcachev1.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\1AH0QvMyao55w1lLZ8w.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\2q-KSt6tjWoz0p6.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\4rj-nQjJadcN9KR2gD9J.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\4xSsYKwSYWw32uI.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\6ebIO2 CuaAc8CN.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\6J3IZe9faz_Zvq5y.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\6xJyxETzpgyRWY.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\7QmFBO7hPC.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\7WQdZifVV.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\8oKVi4kXo-T3.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\9AWe3oalMH8pGQ.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\acXec35KnAy 3JAa.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\B QiqzlWKZa29tiN.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\BpXzE5KTFQo0nPkbJC.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\bPYC.ots.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\B_YPxPKpD1ZmH2uMGI0.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\C0b5A42cWRWItSoo.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\CeUkgtiodE9CrMiERDD.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\cKOy2SIcxBt.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\CU5J7wkwou1XmHadaG.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\D 2Yy5NwwwJDRGMuUPN.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\dhepLPxJKhFvF-.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\DLc2DSrIoH53pqOBe.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\dmWYdv2qQ_kb.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\EiLY6gF.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\fzOznSYLr4CBE.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\GDpHmWMiharvyveVo7.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Gji8i1AVJ_.mkv.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\gLw2wXz_baYRBU9UYr.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\HdmA.ots.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\hqk4JtR.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\hWNpS9rnX6xEUmZpCwHQ.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\I tV.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\IOpeyc VK2zYS.mkv.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\juwFOU9DOWdjr.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Jz83apZXoaKhpCs-DVt.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\koumWKF5dh.mkv.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\KQIX3G_Fodlf8b0ioVkt.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\kwGwNVu-w2G.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\lcXLkNJkl kvw.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\lFgRjiIR.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\lU1sJE.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\LwoQPMd.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\M41hOmQbjyD2tK.flv.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\My Music.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\My Pictures.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\My Videos.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\nhWCOf2.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\nJxAI9.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\nvUBbf aA2 b.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\nZHjd8ZRH5IU.mkv.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\oIrLF4G3DKXI1m.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\okWkP.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\OZBuiNddpm7cqYdO4.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\pdH1uthq.ots.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\pfA3c.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\PQiyyU-S DBdDIqv.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\PVd2gbuVX7wgrz.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Q37DGkDfwn F.flv.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Q7o7V-oLkyHgx7T2se.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\QEsYkG79nxujD4i3RE.ots.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\QHmBcDycqsOzS Cd2.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Rkbw3zQgMW_yG.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\rOOYLDlnWeyWsUfty.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\RU6x y3VAOnb5wOPm6.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\rUb3fjwZshKjWHdRP.mkv.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\RYkiF_X.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\SwPhMPA2OZTi.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\SW_P-ZJx 4-x_xm3Ef.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\sxl4.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\TCtO6.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\TEcMx.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\uCycZ0AR0oYEoA898X4.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\uPV9BHH1lO5.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\uuSyucxerAPbi71txCZ2.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\vump8NZ3DWXdNMzFb-Q.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\vxW19 Kh9.mkv.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\XFGlIoXeVu7ws2.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\XTMhQdDdcFuFPh7f.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Xuioq4D.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\y1pFtkhfGeeSRBj2Zt.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\YJ8A.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\ZBMPYpLlOu.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Zd9tl.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\ZzpgeA3UC.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dhW8Iwn.bmp.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\EFuqqlPSM1vaPabvn.jpg.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\D 2Yy5NwwwJDRGMuUPN.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\kwGwNVu-w2G.bmp.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\SKGcf-J5.gif.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\SW_P-ZJx 4-x_xm3Ef.bmp.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\uCycZ0AR0oYEoA898X4.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\acXec35KnAy 3JAa\g8sBttCxYKZPd6.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\acXec35KnAy 3JAa\GEg3K28qnJQiy2y9-0.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\acXec35KnAy 3JAa\juwFOU9DOWdjr.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\S8_UWH\KOKKJIh n4pRCP.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\S8_UWH\VeOx2kRDqzwn6D8yqVn4.bmp.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\S8_UWH\49lKy vGPjr8X0yIPf0f\4xSsYKwSYWw32uI.png.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\S8_UWH\49lKy vGPjr8X0yIPf0f\OZBuiNddpm7cqYdO4.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\S8_UWH\uuSyucxerAPbi71txCZ2\ENHVVTA.jpg.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\S8_UWH\uuSyucxerAPbi71txCZ2\FPAgDKVQ.png.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\S8_UWH\uuSyucxerAPbi71txCZ2\Jz83apZXoaKhpCs-DVt.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\S8_UWH\uuSyucxerAPbi71txCZ2\y1pFtkhfGeeSRBj2Zt\1 vYKKo8QX.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\S8_UWH\uuSyucxerAPbi71txCZ2\y1pFtkhfGeeSRBj2Zt\vump8NZ3DWXdNMzFb-Q.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\S8_UWH\uuSyucxerAPbi71txCZ2\y1pFtkhfGeeSRBj2Zt\vXLYL2 MkE_pmi.jpg.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\3hMvHwu.mp3.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\er8goZC4-ClEN0w_.wav.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\gyLAd69dWSijxYVl.mp3.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\OGUd HWk3Dmmaa\0P4BNe7xn6bF2iXIb.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\OGUd HWk3Dmmaa\bA0OUA0DB.mp3.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\OGUd HWk3Dmmaa\fDcQNjbA0qEZtUOadh c.wav.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\OGUd HWk3Dmmaa\KBcP.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\OGUd HWk3Dmmaa\m1lbwoOT.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\YJ8A\-gFhQ_.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\YJ8A\9VBbVWPthdTq7L1mHYvL.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\YJ8A\EFQV3.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\YJ8A\EvZjD5kPVJBd2.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\YJ8A\haOROu9-IfOAU39gSz.wav.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\YJ8A\hdv0c.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\YJ8A\oOuDApOKEK.wav.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\YJ8A\ZitlzXN73FZtoi9hLX7.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\YJ8A\ZwaIw8MhzenHR.wav.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\5BqgrnAL.avi.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\a9lR6k504D57-gY.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\eOVPIF7.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\G2X7ICxL7znp.swf.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\H4DCvfw4oF 2OoToy.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\IOpeyc VK2zYS.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\koumWKF5dh.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\KTKaAxSx4Ta5i-Iw.mkv.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\KXKzQR.mkv.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\lrm03oE5EHqK.flv.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\mlhQY9AywPY.mp4.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\Mx9JI50SSx.mkv.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\P6BUoYzWiO 81F-H.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\porvJcU0CwMcDwT7cl.avi.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\Q2tqdEm.flv.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\S 5u.mkv.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\Wq6jr6pL_d5Kufy.swf.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8oKVi4kXo-T3.xlsx.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\me8Nym.xlsx.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\pggo.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\PQiyyU-S DBdDIqv.ods.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\rPBbdZ6C.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\TNalA2MW5A5t6-vAyM.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\zHHX8Lgg.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ZzpgeA3UC.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\B QiqzlWKZa29tiN\XTMhQdDdcFuFPh7f\6ebIO2 CuaAc8CN.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\B QiqzlWKZa29tiN\XTMhQdDdcFuFPh7f\TCtO6.doc.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\B QiqzlWKZa29tiN\XTMhQdDdcFuFPh7f\6yQ8kOC75Jj\lcXLkNJkl kvw.odp.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Temp\svchost.exe | Dropped File | Binary |
Unknown
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0xee7c27 |
Size Of Code | 0x23d600 |
Size Of Initialized Data | 0x47200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-12-09 07:41:14+00:00 |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | Windows Hizmetleri için Ana Bilgisayar İşlemi |
FileVersion | 6.1.7600.16385 (win7_rtm.090713-1255) |
InternalName | svchost.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | svchost.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 6.1.7600.16385 |
Sections (12)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x23bc0c | 0x0 | 0x0 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 0.0 |
.itext | 0x63d000 | 0x1644 | 0x0 | 0x0 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 0.0 |
.data | 0x63f000 | 0x7a14 | 0x0 | 0x0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.bss | 0x647000 | 0x7d8c | 0x0 | 0x0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.idata | 0x64f000 | 0x3128 | 0x0 | 0x0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.didata | 0x653000 | 0xb3c | 0x0 | 0x0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.edata | 0x654000 | 0x99 | 0x0 | 0x0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.0 |
.tls | 0x655000 | 0x48 | 0x0 | 0x0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rdata | 0x656000 | 0x5d | 0x0 | 0x0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.0 |
.vmp0 | 0x657000 | 0x334dee | 0x0 | 0x0 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 0.0 |
.vmp1 | 0x98c000 | 0x5c7760 | 0x5c7800 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.96 |
.rsrc | 0xf54000 | 0xb76 | 0xc00 | 0x5c7c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.98 |
Imports (16)
»
kernel32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetVersion | 0x0 | 0xd83000 | 0x925784 | 0x399b84 | 0x0 |
GetVersionExW | 0x0 | 0xd83004 | 0x925788 | 0x399b88 | 0x0 |
winspool.drv (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DocumentPropertiesW | 0x0 | 0xd8300c | 0x925790 | 0x399b90 | 0x0 |
comctl32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ImageList_GetImageInfo | 0x0 | 0xd83014 | 0x925798 | 0x399b98 | 0x0 |
shell32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Shell_NotifyIconW | 0x0 | 0xd8301c | 0x9257a0 | 0x399ba0 | 0x0 |
ole32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
IsEqualGUID | 0x0 | 0xd83024 | 0x9257a8 | 0x399ba8 | 0x0 |
version.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetFileVersionInfoSizeW | 0x0 | 0xd8302c | 0x9257b0 | 0x399bb0 | 0x0 |
user32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CopyImage | 0x0 | 0xd83034 | 0x9257b8 | 0x399bb8 | 0x0 |
oleaut32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysFreeString | 0x0 | 0xd8303c | 0x9257c0 | 0x399bc0 | 0x0 |
netapi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetWkstaGetInfo | 0x0 | 0xd83044 | 0x9257c8 | 0x399bc8 | 0x0 |
advapi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegSetValueExW | 0x0 | 0xd8304c | 0x9257d0 | 0x399bd0 | 0x0 |
gdi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Pie | 0x0 | 0xd83054 | 0x9257d8 | 0x399bd8 | 0x0 |
WTSAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WTSSendMessageW | 0x0 | 0xd8305c | 0x9257e0 | 0x399be0 | 0x0 |
kernel32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VirtualQuery | 0x0 | 0xd83064 | 0x9257e8 | 0x399be8 | 0x0 |
user32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetUserObjectInformationW | 0x0 | 0xd8306c | 0x9257f0 | 0x399bf0 | 0x0 |
kernel32.dll (12)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LocalAlloc | 0x0 | 0xd83074 | 0x9257f8 | 0x399bf8 | 0x0 |
LocalFree | 0x0 | 0xd83078 | 0x9257fc | 0x399bfc | 0x0 |
GetModuleFileNameW | 0x0 | 0xd8307c | 0x925800 | 0x399c00 | 0x0 |
GetProcessAffinityMask | 0x0 | 0xd83080 | 0x925804 | 0x399c04 | 0x0 |
SetProcessAffinityMask | 0x0 | 0xd83084 | 0x925808 | 0x399c08 | 0x0 |
SetThreadAffinityMask | 0x0 | 0xd83088 | 0x92580c | 0x399c0c | 0x0 |
Sleep | 0x0 | 0xd8308c | 0x925810 | 0x399c10 | 0x0 |
ExitProcess | 0x0 | 0xd83090 | 0x925814 | 0x399c14 | 0x0 |
FreeLibrary | 0x0 | 0xd83094 | 0x925818 | 0x399c18 | 0x0 |
LoadLibraryA | 0x0 | 0xd83098 | 0x92581c | 0x399c1c | 0x0 |
GetModuleHandleA | 0x0 | 0xd8309c | 0x925820 | 0x399c20 | 0x0 |
GetProcAddress | 0x0 | 0xd830a0 | 0x925824 | 0x399c24 | 0x0 |
user32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetProcessWindowStation | 0x0 | 0xd830a8 | 0x92582c | 0x399c2c | 0x0 |
GetUserObjectInformationW | 0x0 | 0xd830ac | 0x925830 | 0x399c30 | 0x0 |
Exports (3)
»
Api name | EAT Address | Ordinal |
---|---|---|
TMethodImplementationIntercept | 0xd79c0 | 0x3 |
__dbk_fcall_wrapper | 0x10728 | 0x2 |
dbkFCallWrapperAddr | 0x24a63c | 0x1 |
Memory Dumps (11)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
buffer | 2 | 0x003C0000 | 0x003C0FFF | Content Changed | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 2 | 0x003E0000 | 0x003E0FFF | Content Changed | - | 32-bit | - |
![]() |
![]() |
...
|
ntdll.dll | 2 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 2 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 2 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 2 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 2 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 2 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 2 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 2 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
ntdll.dll | 2 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | 0x77150028 |
![]() |
![]() |
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\00vV.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\1 vYKKo8QX.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\1Q1 N8bNUHYkTx.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\3_6b36lJJGDpGe5sN.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\49lKy vGPjr8X0yIPf0f.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\4Yi2-.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\6yQ8kOC75Jj.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\7ahakAv7inIhv.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\9mWR_L.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\9q2f2B1XpPD36l CbrM.mkv.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\9_SAd.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\BlwBZvB1.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\bytS-br.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\CWvnVjmQ8F.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\C_OrPs.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\D4Cw0GAiUoflS.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\dhW8Iwn.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\EFuqqlPSM1vaPabvn.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\FPAgDKVQ.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\fQrX4hGg9cG4C5Axg0CL.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\g-7aCjjxTB5ZsQx7.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\GEg3K28qnJQiy2y9-0.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\ggjUe6w eVjPinIu.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\G_KMWpa.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\h JJTFQIhjFKALV1H_E.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\hn6fdMZr8TjBS9U6kwY.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\IHv6sq.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\JgOj32tYQLd7ygW.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\KIug5o I-tgdYxZ73.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\KOKKJIh n4pRCP.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\KXKzQR.mkv.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\lrm03oE5EHqK.flv.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\me8Nym.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\mNjtRsuRv8P1zPk5h5TW.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Mr1HUsS.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Mx9JI50SSx.mkv.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\NKjVFqW.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\nrA3c9w.ots.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\OGUd HWk3Dmmaa.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\pggo.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Q2tqdEm.flv.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\ReIXixjy7rbD2.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Roaming.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\rPBbdZ6C.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\S 5u.mkv.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\S8_UWH.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\SKGcf-J5.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Skk1e o_u43c.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\sm00w3.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\t6xF.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\TNalA2MW5A5t6-vAyM.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\tscqqhNXHiynD3Wg.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\U1hQA62_bU.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\xxtVcwXZ.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\zHHX8Lgg.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Zq0nk6Xs.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\_08Tx5Qx9Ja.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\_ZxVpELuQAruCE0H.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\acXec35KnAy 3JAa\fzOznSYLr4CBE.bmp.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\acXec35KnAy 3JAa\KIug5o I-tgdYxZ73.png.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\S8_UWH\ggjUe6w eVjPinIu.gif.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\S8_UWH\keOy0mnn3JYV5.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\S8_UWH\49lKy vGPjr8X0yIPf0f\cKOy2SIcxBt.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\S8_UWH\49lKy vGPjr8X0yIPf0f\ReIXixjy7rbD2.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\S8_UWH\uuSyucxerAPbi71txCZ2\QSnOncL aUliNc.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\S8_UWH\uuSyucxerAPbi71txCZ2\00vV\fQrX4hGg9cG4C5Axg0CL.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\S8_UWH\uuSyucxerAPbi71txCZ2\00vV\o-GedFJ.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\S8_UWH\uuSyucxerAPbi71txCZ2\y1pFtkhfGeeSRBj2Zt\9AWe3oalMH8pGQ.png.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\S8_UWH\uuSyucxerAPbi71txCZ2\y1pFtkhfGeeSRBj2Zt\RYkiF_X.bmp.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D4Cw0GAiUoflS\S8_UWH\uuSyucxerAPbi71txCZ2\y1pFtkhfGeeSRBj2Zt\xxtVcwXZ.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\-0XXVJH6oJaJT.wav.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\GCWm0hZzh.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\HDu463Fat9X3J.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\wnIFYNEsKAIO7VmeVPVb.mp3.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\OGUd HWk3Dmmaa\aaOj.wav.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\OGUd HWk3Dmmaa\g2Rv0z.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\OGUd HWk3Dmmaa\H9JE.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\OGUd HWk3Dmmaa\UdpR6.wav.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\YJ8A\sQy1ihuuo31OJTu.wav.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\5TRN2jZRNqLvgzpibqdg.swf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\A9NC.swf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\cmdRmxTS0KBMzk3GX.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\Gji8i1AVJ_.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\Q37DGkDfwn F.flv.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\rrmYyQDxo59x2azl-.swf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\VWgGdUvekNtKwBze.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\vxW19 Kh9.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\1Q1 N8bNUHYkTx.ods | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\6J3IZe9faz_Zvq5y.xlsx.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\6xJyxETzpgyRWY.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\BpXzE5KTFQo0nPkbJC.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\CeUkgtiodE9CrMiERDD.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\CU5J7wkwou1XmHadaG.pptx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\LwoQPMd.pptx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Mr1HUsS.pptx.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\oIrLF4G3DKXI1m.docx.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\rOOYLDlnWeyWsUfty.doc.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Skk1e o_u43c.xlsx.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Zd9tl.pptx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\B QiqzlWKZa29tiN\C_OrPs.doc.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\B QiqzlWKZa29tiN\ZBMPYpLlOu.xls.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\B QiqzlWKZa29tiN\XTMhQdDdcFuFPh7f\hqk4JtR.ods | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\B QiqzlWKZa29tiN\XTMhQdDdcFuFPh7f\uPV9BHH1lO5.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\B QiqzlWKZa29tiN\XTMhQdDdcFuFPh7f\6yQ8kOC75Jj\XFGlIoXeVu7ws2.odt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5P5NRG~1\AppData\Local\Temp\evbA2E3.tmp | Dropped File | Unknown |
Not Queried
|
...
|
»