VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Trojan
Backdoor
...
|
Threat Names: |
Nautilus
Turla
Win32.Trojan.Wacatac
|
ITCGroup.exe
Windows Exe (x86-32)
Created at 2020-01-23T07:30:00
Remarks
(0x0200001E): The maximum size of extracted files was exceeded. Some files may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ITCGroup.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2020-01-23 00:15 (UTC+1) |
Last Seen | 2020-01-23 06:37 (UTC+1) |
Names | Win32.Trojan.Wacatac |
Families | Wacatac |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x41aaa8 |
Size Of Code | 0xb0000 |
Size Of Initialized Data | 0xa000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-10-22 19:52:41+00:00 |
Version Information (9)
»
Comments | http://phoenixlabs.org |
CompanyName | Phoenix Labs |
FileDescription | ListDrop list merging/converting tool |
FileVersion | 1, 0, 0, 1 |
InternalName | listdrop |
LegalCopyright | Copyright (C) 2005 Cory Nelson |
OriginalFilename | listdrop.exe |
ProductName | ListDrop |
ProductVersion | 1, 0, 0, 1 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xaf205 | 0xb0000 | 0x1000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.86 |
.rdata | 0x4b1000 | 0x789a | 0x8000 | 0xb1000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.99 |
.data | 0x4b9000 | 0x2140 | 0x1000 | 0xb9000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.88 |
.rsrc | 0x4bc000 | 0xdc4 | 0x1000 | 0xba000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.95 |
Imports (1)
»
KERNEL32.dll (9)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
AreFileApisANSI | 0x0 | 0x4b1000 | 0xb87d0 | 0xb87d0 | 0x0 |
GetModuleFileNameA | 0x0 | 0x4b1004 | 0xb87d4 | 0xb87d4 | 0x0 |
GlobalAddAtomW | 0x0 | 0x4b1008 | 0xb87d8 | 0xb87d8 | 0x0 |
VirtualProtect | 0x0 | 0x4b100c | 0xb87dc | 0xb87dc | 0x0 |
GetStartupInfoA | 0x0 | 0x4b1010 | 0xb87e0 | 0xb87e0 | 0x0 |
WinExec | 0x0 | 0x4b1014 | 0xb87e4 | 0xb87e4 | 0x0 |
GetModuleHandleA | 0x0 | 0x4b1018 | 0xb87e8 | 0xb87e8 | 0x0 |
lstrcatA | 0x0 | 0x4b101c | 0xb87ec | 0xb87ec | 0x0 |
lstrlenA | 0x0 | 0x4b1020 | 0xb87f0 | 0xb87f0 | 0x0 |
Memory Dumps (82)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Relevant Image |
![]() |
32-bit | 0x0044420C |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00489C08 |
![]() |
![]() |
...
|
buffer | 1 | 0x00020000 | 0x00020FFF | First Execution |
![]() |
32-bit | 0x000203E4 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00420E36 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x004511A9 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00443E12 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0044B793 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00449EDF |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0044CEEA |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0040B7C0 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x004483E4 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x004238F2 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00406BE0 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0040C2A0 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0044F940 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0041F38F |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00410CB0 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x004384F4 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0040A470 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0040B860 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00409AF0 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00444FC8 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00446BD3 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x004475C2 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x004424D8 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00403000 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00408870 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0040A470 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x004186E0 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x004048D0 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x004424D8 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00403000 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00408572 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0040B860 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00403000 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00408726 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0040B860 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x004048D0 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00403000 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00408AA5 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x004424D8 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0040A470 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x004186E0 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00403000 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00402CF0 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0040B860 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00403000 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00408572 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0040B860 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00403000 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00408AA5 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0040A470 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x004186E0 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x004424D8 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00403000 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00408A08 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0040A470 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x004186E0 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x004048D0 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x004424D8 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0044F379 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0040A470 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0040B860 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x004030CD |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0040884A |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0040A470 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x004186E0 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x004048D0 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x004424D8 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00403000 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00408870 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0040A470 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x004186E0 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x004048D0 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x004424D8 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00403000 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0044F379 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0040A470 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00403000 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x00408AA5 |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Content Changed |
![]() |
32-bit | 0x0044B9DC |
![]() |
![]() |
...
|
itcgroup.exe | 1 | 0x00400000 | 0x004BCFFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
C:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\excellr.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\excelmui.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\excelmui.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-0016-0409-1000-0000000ff1ce}-c\setup.xml.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\powerpointmui.msi.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\powerpointmui.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\pptlr.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-0018-0409-1000-0000000ff1ce}-c\setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\publishermui.msi.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\publishermui.xml.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\publr.cab.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-0019-0409-1000-0000000ff1ce}-c\setup.xml.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-001a-0409-1000-0000000ff1ce}-c\outlklr.cab.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-001a-0409-1000-0000000ff1ce}-c\outlookmui.msi.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-001a-0409-1000-0000000ff1ce}-c\outlookmui.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-001a-0409-1000-0000000ff1ce}-c\setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-001b-0409-1000-0000000ff1ce}-c\setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-001b-0409-1000-0000000ff1ce}-c\wordlr.cab.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-001b-0409-1000-0000000ff1ce}-c\wordmui.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-001b-0409-1000-0000000ff1ce}-c\wordmui.xml.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.en\proof.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.en\proof.msi.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.en\proof.xml.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.es\proof.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.es\proof.msi.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.es\proof.xml.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.fr\proof.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.fr\proof.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proof.fr\proof.xml.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proofing.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\proofing.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-002c-0409-1000-0000000ff1ce}-c\setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-0043-0409-1000-0000000ff1ce}-c\office32mui.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-0043-0409-1000-0000000ff1ce}-c\office32mui.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-0043-0409-1000-0000000ff1ce}-c\owow32lr.cab.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-0043-0409-1000-0000000ff1ce}-c\setup.xml.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-0044-0409-1000-0000000ff1ce}-c\inflr.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\msocache\all users\{90140000-001b-0409-1000-0000000ff1ce}-c\!!FAQ for Decryption!!.txt | Dropped File | Text |
Unknown
|
...
|
»