VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Dropper
Pua
|
Threat Names: |
Generic.Ransom.Small.43F2C420
Mal/HTMLGen-A
Mal/Generic-S
|
x22p4FOu0H3dU8Or.exe
Windows Exe (x86-32)
Created at 2020-09-30T16:07:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\x22p4FOu0H3dU8Or.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4c9000 |
Size Of Code | 0xea00 |
Size Of Initialized Data | 0x5ae00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-01-18 10:10:35+00:00 |
Version Information (7)
»
CompanyName | TODO: <Company> |
FileDescription | TODO: <Description> |
FileVersion | 1,0,0,0 |
InternalName | TODO: <InternalName> |
LegalCopyright | Copyright (C) 2018 |
ProductName | TODO: <Name> |
ProductVersion | 1.0.0.0 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
- | 0x401000 | 0x6e000 | 0x0 | 0x400 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 0.0 |
- | 0x46f000 | 0x1000 | 0x200 | 0x400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.83 |
.rsrc | 0x470000 | 0x58d9c | 0x29524 | 0x600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.93 |
- | 0x4c9000 | 0x18000 | 0x17cf0 | 0x29c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 8.0 |
Imports (4)
»
kernel32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetModuleHandleA | 0x0 | 0x46f064 | 0x6f06c | 0x46c | 0x0 |
user32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadIconA | 0x0 | 0x46f074 | 0x6f07c | 0x47c | 0x0 |
advapi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegisterEventSourceA | 0x0 | 0x46f084 | 0x6f08c | 0x48c | 0x0 |
comctl32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InitCommonControlsEx | 0x0 | 0x46f094 | 0x6f09c | 0x49c | 0x0 |
Memory Dumps (64)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | First Execution |
![]() |
32-bit | 0x004C9000 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004CA24D |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004CFB08 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004DF02C |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004CB023 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D817C |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004DA97C |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004CC201 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004CE5E6 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x00401000 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x00405000 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x00411000 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x00412000 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x0040EFC0 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x0040F000 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D2C2C |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D7D7D |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004DE8CB |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x00402A97 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D14B0 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D0706 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004CB6CA |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D2C2C |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D4000 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D7D7D |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004DE8CB |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x00402A97 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D14B0 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D2C2C |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D7D7D |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004DE8CB |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x0040A702 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x00402A97 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D14B0 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D0F8C |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004DE8CB |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D2C2C |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D7D7D |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x0040A702 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D14B0 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004CB6CA |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D7D7D |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004DE8CB |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D2C2C |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x00402A97 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x00402A97 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D14B0 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D4000 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D7D7D |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004DE8CB |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x00402A97 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D3E4E |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D14B0 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D2C2C |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D4000 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D7D7D |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004DE8CB |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x00402A97 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D14B0 |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D7D7D |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004DE8CB |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004CB6CA |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Content Changed |
![]() |
32-bit | 0x004D2C2C |
![]() |
![]() |
...
|
x22p4fou0h3du8or.exe | 1 | 0x00400000 | 0x004E0FFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
APLib_Compressed_PE | PE file compressed by APLib | - |
2/5
|
...
|
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x40601e |
Size Of Code | 0x4200 |
Size Of Initialized Data | 0xe00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-11-01 13:45:39+00:00 |
Version Information (11)
»
Assembly Version | 1.0.1.0 |
Comments | TODO: <Description> |
CompanyName | TODO: <Company> |
FileDescription | TODO: <Name> |
FileVersion | 0.2.0.2 |
InternalName | hyBrDFjOidLuty.exe |
LegalCopyright | Copyright © 2018 |
LegalTrademarks | TODO: <Trademark> |
OriginalFilename | hyBrDFjOidLuty.exe |
ProductName | TODO: <Product> |
ProductVersion | 0.2.0.2 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x4024 | 0x4200 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.23 |
.rsrc | 0x408000 | 0xb30 | 0xc00 | 0x4400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.38 |
.reloc | 0x40a000 | 0xc | 0x200 | 0x5000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.08 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x5ff0 | 0x41f0 | 0x0 |
Memory Dumps (27)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
hybrdfjoidluty.exe | 4 | 0x01290000 | 0x0129BFFF | Relevant Image |
![]() |
64-bit | - |
![]() |
![]() |
...
|
buffer | 4 | 0x7FE93E1E000 | 0x7FE93E1EFFF | First Execution |
![]() |
64-bit | 0x7FE93E1E000 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FE93E2E000 | 0x7FE93E2EFFF | First Execution |
![]() |
64-bit | 0x7FE93E2E040 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FE93F80000 | 0x7FE93F8FFFF | First Execution |
![]() |
64-bit | 0x7FE93F80080 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FE93E3B000 | 0x7FE93E3BFFF | First Execution |
![]() |
64-bit | 0x7FE93E3B020 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FE93F31000 | 0x7FE93F31FFF | First Execution |
![]() |
64-bit | 0x7FE93F310A0 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FE93F80000 | 0x7FE93F8FFFF | Content Changed |
![]() |
64-bit | 0x7FE93F81040 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FE93F31000 | 0x7FE93F31FFF | Content Changed |
![]() |
64-bit | 0x7FE93F31615 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FE93F32000 | 0x7FE93F32FFF | First Execution |
![]() |
64-bit | 0x7FE93F32000 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FE93E3B000 | 0x7FE93E3BFFF | Content Changed |
![]() |
64-bit | 0x7FE93E3B060 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FE93E1E000 | 0x7FE93E1EFFF | Content Changed |
![]() |
64-bit | 0x7FE93E1E6C0 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FE93F33000 | 0x7FE93F33FFF | First Execution |
![]() |
64-bit | 0x7FE93F33000 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FE93F31000 | 0x7FE93F31FFF | Content Changed |
![]() |
64-bit | 0x7FE93F316B0 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FE93F32000 | 0x7FE93F32FFF | Content Changed |
![]() |
64-bit | 0x7FE93F32CE6 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FE93E3B000 | 0x7FE93E3BFFF | Content Changed |
![]() |
64-bit | 0x7FE93E3B0A0 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FE93E1F000 | 0x7FE93E1FFFF | First Execution |
![]() |
64-bit | 0x7FE93E1F050 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FE93E6D000 | 0x7FE93E6DFFF | First Execution |
![]() |
64-bit | 0x7FE93E6D2C5 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FE93E6D000 | 0x7FE93E6DFFF | Content Changed |
![]() |
64-bit | 0x7FE93E6D2C5 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FE93E1E000 | 0x7FE93E1EFFF | Content Changed |
![]() |
64-bit | 0x7FE93E1E000 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FE93E1F000 | 0x7FE93E1FFFF | Content Changed |
![]() |
64-bit | 0x7FE93E1FB90 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FE93E2E000 | 0x7FE93E2EFFF | Content Changed |
![]() |
64-bit | 0x7FE93E2EF20 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FE93E6E000 | 0x7FE93E6EFFF | First Execution |
![]() |
64-bit | 0x7FE93E6E135 |
![]() |
![]() |
...
|
buffer | 4 | 0x1AE86000 | 0x1AE92FFF | First Execution |
![]() |
64-bit | 0x1AE91CCC |
![]() |
![]() |
...
|
buffer | 4 | 0x7FE93E3E000 | 0x7FE93E3EFFF | First Execution |
![]() |
64-bit | 0x7FE93E3E000 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FE93FA0000 | 0x7FE93FAFFFF | First Execution |
![]() |
64-bit | 0x7FE93FA0080 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FE93FA0000 | 0x7FE93FAFFFF | Content Changed |
![]() |
64-bit | 0x7FE93FA1040 |
![]() |
![]() |
...
|
hybrdfjoidluty.exe | 4 | 0x01290000 | 0x0129BFFF | Final Dump |
![]() |
64-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Ransom.Small.43F2C420 |
Malicious
|
File Reputation Information
»
Severity |
Suspicious
|
Families | - |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x409de6 |
Size Of Code | 0x18600 |
Size Of Initialized Data | 0x61e00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2016-06-28 18:43:09+00:00 |
Version Information (8)
»
CompanyName | Sysinternals - www.sysinternals.com |
FileDescription | Execute processes remotely |
FileVersion | 2.2 |
InternalName | PsExec |
LegalCopyright | Copyright (C) 2001-2016 Mark Russinovich |
OriginalFilename | psexec.c |
ProductName | Sysinternals PsExec |
ProductVersion | 2.2 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x184c4 | 0x18600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.59 |
.rdata | 0x41a000 | 0xe62a | 0xe800 | 0x18a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.6 |
.data | 0x429000 | 0x2dd9c | 0x2400 | 0x27200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.18 |
.rsrc | 0x457000 | 0x23f18 | 0x24000 | 0x29600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.38 |
.reloc | 0x47b000 | 0x1750 | 0x1800 | 0x4d600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.63 |
Imports (7)
»
VERSION.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetFileVersionInfoSizeW | 0x0 | 0x41a274 | 0x27a8c | 0x2648c | 0x5 |
GetFileVersionInfoW | 0x0 | 0x41a278 | 0x27a90 | 0x26490 | 0x6 |
VerQueryValueW | 0x0 | 0x41a27c | 0x27a94 | 0x26494 | 0xe |
NETAPI32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetServerEnum | 0x0 | 0x41a268 | 0x27a80 | 0x26480 | 0xda |
NetApiBufferFree | 0x0 | 0x41a26c | 0x27a84 | 0x26484 | 0x65 |
WS2_32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
gethostname | 0x39 | 0x41a284 | 0x27a9c | 0x2649c | - |
WSAStartup | 0x73 | 0x41a288 | 0x27aa0 | 0x264a0 | - |
inet_ntoa | 0xc | 0x41a28c | 0x27aa4 | 0x264a4 | - |
gethostbyname | 0x34 | 0x41a290 | 0x27aa8 | 0x264a8 | - |
MPR.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetCancelConnection2W | 0x0 | 0x41a25c | 0x27a74 | 0x26474 | 0xc |
WNetAddConnection2W | 0x0 | 0x41a260 | 0x27a78 | 0x26478 | 0x6 |
KERNEL32.dll (104)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetExitCodeProcess | 0x0 | 0x41a0b8 | 0x278d0 | 0x262d0 | 0x1df |
ResumeThread | 0x0 | 0x41a0bc | 0x278d4 | 0x262d4 | 0x413 |
WaitForMultipleObjects | 0x0 | 0x41a0c0 | 0x278d8 | 0x262d8 | 0x4f7 |
GetFileTime | 0x0 | 0x41a0c4 | 0x278dc | 0x262dc | 0x1f2 |
DuplicateHandle | 0x0 | 0x41a0c8 | 0x278e0 | 0x262e0 | 0xe8 |
DisconnectNamedPipe | 0x0 | 0x41a0cc | 0x278e4 | 0x262e4 | 0xe1 |
SetNamedPipeHandleState | 0x0 | 0x41a0d0 | 0x278e8 | 0x262e8 | 0x47c |
TransactNamedPipe | 0x0 | 0x41a0d4 | 0x278ec | 0x262ec | 0x4ca |
CreateEventW | 0x0 | 0x41a0d8 | 0x278f0 | 0x262f0 | 0x85 |
GetCurrentProcessId | 0x0 | 0x41a0dc | 0x278f4 | 0x262f4 | 0x1c1 |
GetFullPathNameW | 0x0 | 0x41a0e0 | 0x278f8 | 0x262f8 | 0x1fb |
SetFileAttributesW | 0x0 | 0x41a0e4 | 0x278fc | 0x262fc | 0x461 |
GetFileAttributesW | 0x0 | 0x41a0e8 | 0x27900 | 0x26300 | 0x1ea |
CopyFileW | 0x0 | 0x41a0ec | 0x27904 | 0x26304 | 0x75 |
WaitNamedPipeW | 0x0 | 0x41a0f0 | 0x27908 | 0x26308 | 0x500 |
SetConsoleCtrlHandler | 0x0 | 0x41a0f4 | 0x2790c | 0x2630c | 0x42d |
SetConsoleTitleW | 0x0 | 0x41a0f8 | 0x27910 | 0x26310 | 0x448 |
ReadConsoleW | 0x0 | 0x41a0fc | 0x27914 | 0x26314 | 0x3be |
GetVersion | 0x0 | 0x41a100 | 0x27918 | 0x26318 | 0x2a2 |
SetProcessAffinityMask | 0x0 | 0x41a104 | 0x2791c | 0x2631c | 0x47e |
ReadFile | 0x0 | 0x41a108 | 0x27920 | 0x26320 | 0x3c0 |
GetConsoleScreenBufferInfo | 0x0 | 0x41a10c | 0x27924 | 0x26324 | 0x1b2 |
MultiByteToWideChar | 0x0 | 0x41a110 | 0x27928 | 0x26328 | 0x367 |
GetComputerNameW | 0x0 | 0x41a114 | 0x2792c | 0x2632c | 0x18f |
DeleteFileW | 0x0 | 0x41a118 | 0x27930 | 0x26330 | 0xd6 |
CreateFileW | 0x0 | 0x41a11c | 0x27934 | 0x26334 | 0x8f |
GetSystemDirectoryW | 0x0 | 0x41a120 | 0x27938 | 0x26338 | 0x270 |
FindResourceW | 0x0 | 0x41a124 | 0x2793c | 0x2633c | 0x14e |
LoadLibraryExW | 0x0 | 0x41a128 | 0x27940 | 0x26340 | 0x33e |
FormatMessageA | 0x0 | 0x41a12c | 0x27944 | 0x26344 | 0x15d |
GetTickCount | 0x0 | 0x41a130 | 0x27948 | 0x26348 | 0x293 |
CloseHandle | 0x0 | 0x41a134 | 0x2794c | 0x2634c | 0x52 |
WriteFile | 0x0 | 0x41a138 | 0x27950 | 0x26350 | 0x525 |
SizeofResource | 0x0 | 0x41a13c | 0x27954 | 0x26354 | 0x4b1 |
LoadResource | 0x0 | 0x41a140 | 0x27958 | 0x26358 | 0x341 |
Sleep | 0x0 | 0x41a144 | 0x2795c | 0x2635c | 0x4b2 |
WaitForSingleObject | 0x0 | 0x41a148 | 0x27960 | 0x26360 | 0x4f9 |
SetEndOfFile | 0x0 | 0x41a14c | 0x27964 | 0x26364 | 0x453 |
SetEvent | 0x0 | 0x41a150 | 0x27968 | 0x26368 | 0x459 |
SetLastError | 0x0 | 0x41a154 | 0x2796c | 0x2636c | 0x473 |
GetLastError | 0x0 | 0x41a158 | 0x27970 | 0x26370 | 0x202 |
GetCurrentProcess | 0x0 | 0x41a15c | 0x27974 | 0x26374 | 0x1c0 |
FreeLibrary | 0x0 | 0x41a160 | 0x27978 | 0x26378 | 0x162 |
LockResource | 0x0 | 0x41a164 | 0x2797c | 0x2637c | 0x354 |
SetPriorityClass | 0x0 | 0x41a168 | 0x27980 | 0x26380 | 0x47d |
GetModuleFileNameW | 0x0 | 0x41a16c | 0x27984 | 0x26384 | 0x214 |
GetCommandLineW | 0x0 | 0x41a170 | 0x27988 | 0x26388 | 0x187 |
GetModuleHandleW | 0x0 | 0x41a174 | 0x2798c | 0x2638c | 0x218 |
LoadLibraryW | 0x0 | 0x41a178 | 0x27990 | 0x26390 | 0x33f |
GetStdHandle | 0x0 | 0x41a17c | 0x27994 | 0x26394 | 0x264 |
GetFileType | 0x0 | 0x41a180 | 0x27998 | 0x26398 | 0x1f3 |
LocalFree | 0x0 | 0x41a184 | 0x2799c | 0x2639c | 0x348 |
LocalAlloc | 0x0 | 0x41a188 | 0x279a0 | 0x263a0 | 0x344 |
GetProcAddress | 0x0 | 0x41a18c | 0x279a4 | 0x263a4 | 0x245 |
FreeEnvironmentStringsW | 0x0 | 0x41a190 | 0x279a8 | 0x263a8 | 0x161 |
LCMapStringW | 0x0 | 0x41a194 | 0x279ac | 0x263ac | 0x32d |
OutputDebugStringW | 0x0 | 0x41a198 | 0x279b0 | 0x263b0 | 0x38a |
HeapSize | 0x0 | 0x41a19c | 0x279b4 | 0x263b4 | 0x2d4 |
HeapReAlloc | 0x0 | 0x41a1a0 | 0x279b8 | 0x263b8 | 0x2d2 |
SetFilePointerEx | 0x0 | 0x41a1a4 | 0x279bc | 0x263bc | 0x467 |
WriteConsoleW | 0x0 | 0x41a1a8 | 0x279c0 | 0x263c0 | 0x524 |
GetEnvironmentVariableW | 0x0 | 0x41a1ac | 0x279c4 | 0x263c4 | 0x1dc |
RaiseException | 0x0 | 0x41a1b0 | 0x279c8 | 0x263c8 | 0x3b1 |
LoadLibraryExA | 0x0 | 0x41a1b4 | 0x279cc | 0x263cc | 0x33d |
EncodePointer | 0x0 | 0x41a1b8 | 0x279d0 | 0x263d0 | 0xea |
DecodePointer | 0x0 | 0x41a1bc | 0x279d4 | 0x263d4 | 0xca |
ExitProcess | 0x0 | 0x41a1c0 | 0x279d8 | 0x263d8 | 0x119 |
GetModuleHandleExW | 0x0 | 0x41a1c4 | 0x279dc | 0x263dc | 0x217 |
WideCharToMultiByte | 0x0 | 0x41a1c8 | 0x279e0 | 0x263e0 | 0x511 |
HeapFree | 0x0 | 0x41a1cc | 0x279e4 | 0x263e4 | 0x2cf |
HeapAlloc | 0x0 | 0x41a1d0 | 0x279e8 | 0x263e8 | 0x2cb |
GetConsoleMode | 0x0 | 0x41a1d4 | 0x279ec | 0x263ec | 0x1ac |
ReadConsoleInputA | 0x0 | 0x41a1d8 | 0x279f0 | 0x263f0 | 0x3b5 |
SetConsoleMode | 0x0 | 0x41a1dc | 0x279f4 | 0x263f4 | 0x43d |
EnterCriticalSection | 0x0 | 0x41a1e0 | 0x279f8 | 0x263f8 | 0xee |
LeaveCriticalSection | 0x0 | 0x41a1e4 | 0x279fc | 0x263fc | 0x339 |
SetStdHandle | 0x0 | 0x41a1e8 | 0x27a00 | 0x26400 | 0x487 |
CreateThread | 0x0 | 0x41a1ec | 0x27a04 | 0x26404 | 0xb5 |
GetCurrentThreadId | 0x0 | 0x41a1f0 | 0x27a08 | 0x26408 | 0x1c5 |
ExitThread | 0x0 | 0x41a1f4 | 0x27a0c | 0x2640c | 0x11a |
IsDebuggerPresent | 0x0 | 0x41a1f8 | 0x27a10 | 0x26410 | 0x300 |
IsProcessorFeaturePresent | 0x0 | 0x41a1fc | 0x27a14 | 0x26414 | 0x304 |
GetStringTypeW | 0x0 | 0x41a200 | 0x27a18 | 0x26418 | 0x269 |
IsValidCodePage | 0x0 | 0x41a204 | 0x27a1c | 0x2641c | 0x30a |
GetACP | 0x0 | 0x41a208 | 0x27a20 | 0x26420 | 0x168 |
GetOEMCP | 0x0 | 0x41a20c | 0x27a24 | 0x26424 | 0x237 |
GetCPInfo | 0x0 | 0x41a210 | 0x27a28 | 0x26428 | 0x172 |
DeleteCriticalSection | 0x0 | 0x41a214 | 0x27a2c | 0x2642c | 0xd1 |
UnhandledExceptionFilter | 0x0 | 0x41a218 | 0x27a30 | 0x26430 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x41a21c | 0x27a34 | 0x26434 | 0x4a5 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41a220 | 0x27a38 | 0x26438 | 0x2e3 |
TerminateProcess | 0x0 | 0x41a224 | 0x27a3c | 0x2643c | 0x4c0 |
TlsAlloc | 0x0 | 0x41a228 | 0x27a40 | 0x26440 | 0x4c5 |
TlsGetValue | 0x0 | 0x41a22c | 0x27a44 | 0x26444 | 0x4c7 |
TlsSetValue | 0x0 | 0x41a230 | 0x27a48 | 0x26448 | 0x4c8 |
TlsFree | 0x0 | 0x41a234 | 0x27a4c | 0x2644c | 0x4c6 |
GetStartupInfoW | 0x0 | 0x41a238 | 0x27a50 | 0x26450 | 0x263 |
GetProcessHeap | 0x0 | 0x41a23c | 0x27a54 | 0x26454 | 0x24a |
FlushFileBuffers | 0x0 | 0x41a240 | 0x27a58 | 0x26458 | 0x157 |
GetConsoleCP | 0x0 | 0x41a244 | 0x27a5c | 0x2645c | 0x19a |
RtlUnwind | 0x0 | 0x41a248 | 0x27a60 | 0x26460 | 0x418 |
QueryPerformanceCounter | 0x0 | 0x41a24c | 0x27a64 | 0x26464 | 0x3a7 |
GetSystemTimeAsFileTime | 0x0 | 0x41a250 | 0x27a68 | 0x26468 | 0x279 |
GetEnvironmentStringsW | 0x0 | 0x41a254 | 0x27a6c | 0x2646c | 0x1da |
COMDLG32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PrintDlgW | 0x0 | 0x41a0b0 | 0x278c8 | 0x262c8 | 0x15 |
ADVAPI32.dll (43)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LsaClose | 0x0 | 0x41a000 | 0x27818 | 0x26218 | 0x19d |
CreateProcessAsUserW | 0x0 | 0x41a004 | 0x2781c | 0x2621c | 0x7c |
CryptHashData | 0x0 | 0x41a008 | 0x27820 | 0x26220 | 0xc8 |
CryptCreateHash | 0x0 | 0x41a00c | 0x27824 | 0x26224 | 0xb3 |
CryptDecrypt | 0x0 | 0x41a010 | 0x27828 | 0x26228 | 0xb4 |
CryptEncrypt | 0x0 | 0x41a014 | 0x2782c | 0x2622c | 0xba |
CryptImportKey | 0x0 | 0x41a018 | 0x27830 | 0x26230 | 0xca |
CryptExportKey | 0x0 | 0x41a01c | 0x27834 | 0x26234 | 0xbf |
CryptDestroyKey | 0x0 | 0x41a020 | 0x27838 | 0x26238 | 0xb7 |
CryptDeriveKey | 0x0 | 0x41a024 | 0x2783c | 0x2623c | 0xb5 |
CryptGenKey | 0x0 | 0x41a028 | 0x27840 | 0x26240 | 0xc0 |
CryptReleaseContext | 0x0 | 0x41a02c | 0x27844 | 0x26244 | 0xcb |
CryptAcquireContextW | 0x0 | 0x41a030 | 0x27848 | 0x26248 | 0xb1 |
StartServiceW | 0x0 | 0x41a034 | 0x2784c | 0x2624c | 0x2c9 |
QueryServiceStatus | 0x0 | 0x41a038 | 0x27850 | 0x26250 | 0x228 |
OpenServiceW | 0x0 | 0x41a03c | 0x27854 | 0x26254 | 0x1fb |
OpenSCManagerW | 0x0 | 0x41a040 | 0x27858 | 0x26258 | 0x1f9 |
DeleteService | 0x0 | 0x41a044 | 0x2785c | 0x2625c | 0xda |
CreateServiceW | 0x0 | 0x41a048 | 0x27860 | 0x26260 | 0x81 |
ControlService | 0x0 | 0x41a04c | 0x27864 | 0x26264 | 0x5c |
CloseServiceHandle | 0x0 | 0x41a050 | 0x27868 | 0x26268 | 0x57 |
OpenProcessToken | 0x0 | 0x41a054 | 0x2786c | 0x2626c | 0x1f7 |
LsaEnumerateAccountRights | 0x0 | 0x41a058 | 0x27870 | 0x26270 | 0x1a4 |
LsaOpenPolicy | 0x0 | 0x41a05c | 0x27874 | 0x26274 | 0x1bd |
LsaFreeMemory | 0x0 | 0x41a060 | 0x27878 | 0x26278 | 0x1ab |
SetSecurityInfo | 0x0 | 0x41a064 | 0x2787c | 0x2627c | 0x2bb |
GetSecurityInfo | 0x0 | 0x41a068 | 0x27880 | 0x26280 | 0x14e |
LookupPrivilegeValueW | 0x0 | 0x41a06c | 0x27884 | 0x26284 | 0x197 |
AddAccessAllowedAce | 0x0 | 0x41a070 | 0x27888 | 0x26288 | 0x10 |
GetAce | 0x0 | 0x41a074 | 0x2788c | 0x2628c | 0x123 |
AddAce | 0x0 | 0x41a078 | 0x27890 | 0x26290 | 0x16 |
InitializeAcl | 0x0 | 0x41a07c | 0x27894 | 0x26294 | 0x176 |
GetLengthSid | 0x0 | 0x41a080 | 0x27898 | 0x26298 | 0x136 |
FreeSid | 0x0 | 0x41a084 | 0x2789c | 0x2629c | 0x120 |
AllocateAndInitializeSid | 0x0 | 0x41a088 | 0x278a0 | 0x262a0 | 0x20 |
SetTokenInformation | 0x0 | 0x41a08c | 0x278a4 | 0x262a4 | 0x2c2 |
GetTokenInformation | 0x0 | 0x41a090 | 0x278a8 | 0x262a8 | 0x15a |
RegSetValueExW | 0x0 | 0x41a094 | 0x278ac | 0x262ac | 0x27e |
RegQueryValueExW | 0x0 | 0x41a098 | 0x278b0 | 0x262b0 | 0x26e |
RegOpenKeyExW | 0x0 | 0x41a09c | 0x278b4 | 0x262b4 | 0x261 |
RegOpenKeyW | 0x0 | 0x41a0a0 | 0x278b8 | 0x262b8 | 0x264 |
RegCreateKeyW | 0x0 | 0x41a0a4 | 0x278bc | 0x262bc | 0x23c |
RegCloseKey | 0x0 | 0x41a0a8 | 0x278c0 | 0x262c0 | 0x230 |
Digital Signatures (2)
»
Certificate: Microsoft Corporation
»
Issued by | Microsoft Corporation |
Parent Certificate | Microsoft Code Signing PCA |
Country Name | US |
Valid From | 2015-06-04 17:42:45+00:00 |
Valid Until | 2016-09-04 17:42:45+00:00 |
Algorithm | sha1_rsa |
Serial Number | 33 00 00 01 0A 2C 79 AE D7 79 7B A6 AC 00 01 00 00 01 0A |
Thumbprint | 3B DA 32 3E 55 2D B1 FD E5 F4 FB EE 75 D6 D5 B2 B1 87 EE DC |
Certificate: Microsoft Code Signing PCA
»
Issued by | Microsoft Code Signing PCA |
Country Name | US |
Valid From | 2010-08-31 22:19:32+00:00 |
Valid Until | 2020-08-31 22:29:32+00:00 |
Algorithm | sha1_rsa |
Serial Number | 61 33 26 1A 00 00 00 00 00 31 |
Thumbprint | 3C AF 9B A2 DB 55 70 CA F7 69 42 FF 99 10 1B 99 38 88 E2 57 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
psexec.exe | 3 | 0x00810000 | 0x0088CFFF | Relevant Image |
![]() |
32-bit | 0x0081BCC0 |
![]() |
![]() |
...
|
psexec.exe | 3 | 0x00810000 | 0x0088CFFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\gdipfontcachev1.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\Setup.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\Setup.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Setup.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Setup.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\branding.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPlusrWW.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjProrWW.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Setup.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Setup.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\OFFICE\AssetLibrary.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\OFFICE\DocumentRepository.ico.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\OFFICE\MySharePoints.ico.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\OFFICE\MySite.ico.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\OFFICE\SharePointPortalSite.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\OFFICE\SharePointTeamSite.ico.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Sun\Java\Java Update\jaureglist.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Google Profile.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\main.js.SYMMYWARE | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\icon_16.png.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\main.js.SYMMYWARE | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\128.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\icon_16.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\main.html | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\main.js.SYMMYWARE | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\128.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\contentscript_bin_prod.js.SYMMYWARE | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\eventpage_bin_prod.js | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\page_embed_script.js | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\craw_window.js | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\css\craw_window.css | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\icon_128.png.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\icon_16.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\topbar_floating_button.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\topbar_floating_button_close.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\topbar_floating_button_hover.png.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\topbar_floating_button_maximize.png.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\topbar_floating_button_pressed.png.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\128.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\angular.js | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\background_script.js | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_game_sender.js.SYMMYWARE | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_route_details.html.SYMMYWARE | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_route_details.js | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_sender.js.SYMMYWARE | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\common.js.SYMMYWARE | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\feedback.css | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\feedback.html | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\feedback_script.js.SYMMYWARE | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\material_css_min.css.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\mirroring_cast_streaming.js | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\mirroring_common.js.SYMMYWARE | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\mirroring_hangouts.js | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\mirroring_webrtc.js | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_setup\cast_app.css.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_setup\cast_app.js.SYMMYWARE | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_setup\cast_app_redirect.js | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_setup\chromecast_logo_grey.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_setup\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_setup\offers.html.SYMMYWARE | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cloud_route_details\view.html.SYMMYWARE | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cloud_route_details\view.js.SYMMYWARE | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_aohghmighlieiainnegkcijnfilokake\Google Docs.ico.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Internet Explorer\brndlog.txt.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Internet Explorer\DOMStore\8NES5H33\get.adobe[1].xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Office\ONetConfig\350db95df4cbd94b2a1c300510e12e11.xml.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Mozilla\Firefox\Profiles\silmbjec.default\thumbnails\ba182bcd131f1f3c6b6fbbb1ba078341.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Mozilla\Firefox\Profiles\silmbjec.default\thumbnails\ce8c0453589216a67cddb50284fbfe8d.png.SYMMYWARE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Mozilla\updates\E7CF176E110C211B\active-update.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Mozilla\updates\E7CF176E110C211B\updates.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Temp\-6qFCoBH5lcD.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_setup\cast_app.js | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Temp\13XGHyq.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Temp\D00A.tmp\D01B.bat | Dropped File | Batch |
Unknown
|
...
|
»
C:\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000\SYMMYWARE.TXT | Dropped File | Text |
Unknown
|
...
|
»