VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Dropper
|
Threat Names: |
Generic.Ransom.Matrix.4BE75F48
VBS.Heur.Laburrak.11.5A66A147.Gen
Trojan.GenericKD.40672878
...
|
dttcodexgigas.028ef1a52c04fce1f8d84e019167d54a9067fc13.exe
Windows Exe (x86-32)
Created at 2020-09-22T09:48:00
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "6 minutes" to "1 minute" to reveal dormant functionality.
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\dttcodexgigas.028ef1a52c04fce1f8d84e019167d54a9067fc13.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4dca54 |
Size Of Code | 0xe0400 |
Size Of Initialized Data | 0x4d600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-04-23 21:16:14+00:00 |
Sections (10)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xdaf04 | 0xdb000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.38 |
.itext | 0x4dc000 | 0x52d8 | 0x5400 | 0xdb400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.74 |
.data | 0x4e2000 | 0x5b08 | 0x5c00 | 0xe0800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.19 |
.bss | 0x4e8000 | 0x645c | 0x0 | 0x0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.idata | 0x4ef000 | 0x1236 | 0x1400 | 0xe6400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.79 |
.didata | 0x4f1000 | 0xfa | 0x200 | 0xe7800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.0 |
.edata | 0x4f2000 | 0x6c | 0x200 | 0xe7a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.31 |
.tls | 0x4f3000 | 0x14 | 0x0 | 0x0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rdata | 0x4f4000 | 0x18 | 0x200 | 0xe7c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.21 |
.rsrc | 0x4f5000 | 0x46000 | 0x46000 | 0xe7e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.96 |
Imports (8)
»
KERNEL32.DLL (119)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Sleep | 0x0 | 0x4ef40c | 0xef40c | 0xe680c | 0x0 |
VirtualFree | 0x0 | 0x4ef410 | 0xef410 | 0xe6810 | 0x0 |
VirtualAlloc | 0x0 | 0x4ef414 | 0xef414 | 0xe6814 | 0x0 |
lstrlenW | 0x0 | 0x4ef418 | 0xef418 | 0xe6818 | 0x0 |
VirtualQuery | 0x0 | 0x4ef41c | 0xef41c | 0xe681c | 0x0 |
GetTickCount | 0x0 | 0x4ef420 | 0xef420 | 0xe6820 | 0x0 |
GetSystemInfo | 0x0 | 0x4ef424 | 0xef424 | 0xe6824 | 0x0 |
GetVersion | 0x0 | 0x4ef428 | 0xef428 | 0xe6828 | 0x0 |
CompareStringW | 0x0 | 0x4ef42c | 0xef42c | 0xe682c | 0x0 |
IsDBCSLeadByteEx | 0x0 | 0x4ef430 | 0xef430 | 0xe6830 | 0x0 |
IsValidLocale | 0x0 | 0x4ef434 | 0xef434 | 0xe6834 | 0x0 |
SetThreadLocale | 0x0 | 0x4ef438 | 0xef438 | 0xe6838 | 0x0 |
GetSystemDefaultUILanguage | 0x0 | 0x4ef43c | 0xef43c | 0xe683c | 0x0 |
GetUserDefaultUILanguage | 0x0 | 0x4ef440 | 0xef440 | 0xe6840 | 0x0 |
GetLocaleInfoW | 0x0 | 0x4ef444 | 0xef444 | 0xe6844 | 0x0 |
WideCharToMultiByte | 0x0 | 0x4ef448 | 0xef448 | 0xe6848 | 0x0 |
MultiByteToWideChar | 0x0 | 0x4ef44c | 0xef44c | 0xe684c | 0x0 |
GetConsoleOutputCP | 0x0 | 0x4ef450 | 0xef450 | 0xe6850 | 0x0 |
GetConsoleCP | 0x0 | 0x4ef454 | 0xef454 | 0xe6854 | 0x0 |
GetACP | 0x0 | 0x4ef458 | 0xef458 | 0xe6858 | 0x0 |
LoadLibraryExW | 0x0 | 0x4ef45c | 0xef45c | 0xe685c | 0x0 |
GetStartupInfoW | 0x0 | 0x4ef460 | 0xef460 | 0xe6860 | 0x0 |
GetProcAddress | 0x0 | 0x4ef464 | 0xef464 | 0xe6864 | 0x0 |
GetModuleHandleW | 0x0 | 0x4ef468 | 0xef468 | 0xe6868 | 0x0 |
GetModuleFileNameW | 0x0 | 0x4ef46c | 0xef46c | 0xe686c | 0x0 |
GetCommandLineW | 0x0 | 0x4ef470 | 0xef470 | 0xe6870 | 0x0 |
FreeLibrary | 0x0 | 0x4ef474 | 0xef474 | 0xe6874 | 0x0 |
GetLastError | 0x0 | 0x4ef478 | 0xef478 | 0xe6878 | 0x0 |
UnhandledExceptionFilter | 0x0 | 0x4ef47c | 0xef47c | 0xe687c | 0x0 |
RtlUnwind | 0x0 | 0x4ef480 | 0xef480 | 0xe6880 | 0x0 |
RaiseException | 0x0 | 0x4ef484 | 0xef484 | 0xe6884 | 0x0 |
ExitProcess | 0x0 | 0x4ef488 | 0xef488 | 0xe6888 | 0x0 |
ExitThread | 0x0 | 0x4ef48c | 0xef48c | 0xe688c | 0x0 |
SwitchToThread | 0x0 | 0x4ef490 | 0xef490 | 0xe6890 | 0x0 |
GetCurrentThreadId | 0x0 | 0x4ef494 | 0xef494 | 0xe6894 | 0x0 |
CreateThread | 0x0 | 0x4ef498 | 0xef498 | 0xe6898 | 0x0 |
DeleteCriticalSection | 0x0 | 0x4ef49c | 0xef49c | 0xe689c | 0x0 |
LeaveCriticalSection | 0x0 | 0x4ef4a0 | 0xef4a0 | 0xe68a0 | 0x0 |
EnterCriticalSection | 0x0 | 0x4ef4a4 | 0xef4a4 | 0xe68a4 | 0x0 |
InitializeCriticalSection | 0x0 | 0x4ef4a8 | 0xef4a8 | 0xe68a8 | 0x0 |
FindFirstFileW | 0x0 | 0x4ef4ac | 0xef4ac | 0xe68ac | 0x0 |
FindClose | 0x0 | 0x4ef4b0 | 0xef4b0 | 0xe68b0 | 0x0 |
WriteFile | 0x0 | 0x4ef4b4 | 0xef4b4 | 0xe68b4 | 0x0 |
SetFilePointer | 0x0 | 0x4ef4b8 | 0xef4b8 | 0xe68b8 | 0x0 |
SetEndOfFile | 0x0 | 0x4ef4bc | 0xef4bc | 0xe68bc | 0x0 |
ReadFile | 0x0 | 0x4ef4c0 | 0xef4c0 | 0xe68c0 | 0x0 |
GetFileType | 0x0 | 0x4ef4c4 | 0xef4c4 | 0xe68c4 | 0x0 |
GetFileSize | 0x0 | 0x4ef4c8 | 0xef4c8 | 0xe68c8 | 0x0 |
CreateFileW | 0x0 | 0x4ef4cc | 0xef4cc | 0xe68cc | 0x0 |
GetStdHandle | 0x0 | 0x4ef4d0 | 0xef4d0 | 0xe68d0 | 0x0 |
CloseHandle | 0x0 | 0x4ef4d4 | 0xef4d4 | 0xe68d4 | 0x0 |
LoadLibraryA | 0x0 | 0x4ef4d8 | 0xef4d8 | 0xe68d8 | 0x0 |
TlsSetValue | 0x0 | 0x4ef4dc | 0xef4dc | 0xe68dc | 0x0 |
TlsGetValue | 0x0 | 0x4ef4e0 | 0xef4e0 | 0xe68e0 | 0x0 |
LocalFree | 0x0 | 0x4ef4e4 | 0xef4e4 | 0xe68e4 | 0x0 |
LocalAlloc | 0x0 | 0x4ef4e8 | 0xef4e8 | 0xe68e8 | 0x0 |
WaitForSingleObject | 0x0 | 0x4ef4ec | 0xef4ec | 0xe68ec | 0x0 |
WaitForMultipleObjects | 0x0 | 0x4ef4f0 | 0xef4f0 | 0xe68f0 | 0x0 |
VirtualQueryEx | 0x0 | 0x4ef4f4 | 0xef4f4 | 0xe68f4 | 0x0 |
VirtualProtect | 0x0 | 0x4ef4f8 | 0xef4f8 | 0xe68f8 | 0x0 |
VerSetConditionMask | 0x0 | 0x4ef4fc | 0xef4fc | 0xe68fc | 0x0 |
VerifyVersionInfoW | 0x0 | 0x4ef500 | 0xef500 | 0xe6900 | 0x0 |
SuspendThread | 0x0 | 0x4ef504 | 0xef504 | 0xe6904 | 0x0 |
SizeofResource | 0x0 | 0x4ef508 | 0xef508 | 0xe6908 | 0x0 |
SetThreadPriority | 0x0 | 0x4ef50c | 0xef50c | 0xe690c | 0x0 |
SetLastError | 0x0 | 0x4ef510 | 0xef510 | 0xe6910 | 0x0 |
SetFileAttributesW | 0x0 | 0x4ef514 | 0xef514 | 0xe6914 | 0x0 |
SetEvent | 0x0 | 0x4ef518 | 0xef518 | 0xe6918 | 0x0 |
SetErrorMode | 0x0 | 0x4ef51c | 0xef51c | 0xe691c | 0x0 |
ResumeThread | 0x0 | 0x4ef520 | 0xef520 | 0xe6920 | 0x0 |
ResetEvent | 0x0 | 0x4ef524 | 0xef524 | 0xe6924 | 0x0 |
ReleaseMutex | 0x0 | 0x4ef528 | 0xef528 | 0xe6928 | 0x0 |
QueryPerformanceFrequency | 0x0 | 0x4ef52c | 0xef52c | 0xe692c | 0x0 |
QueryPerformanceCounter | 0x0 | 0x4ef530 | 0xef530 | 0xe6930 | 0x0 |
OpenMutexW | 0x0 | 0x4ef534 | 0xef534 | 0xe6934 | 0x0 |
MoveFileExW | 0x0 | 0x4ef538 | 0xef538 | 0xe6938 | 0x0 |
LockResource | 0x0 | 0x4ef53c | 0xef53c | 0xe693c | 0x0 |
LoadResource | 0x0 | 0x4ef540 | 0xef540 | 0xe6940 | 0x0 |
LoadLibraryW | 0x0 | 0x4ef544 | 0xef544 | 0xe6944 | 0x0 |
HeapFree | 0x0 | 0x4ef548 | 0xef548 | 0xe6948 | 0x0 |
HeapDestroy | 0x0 | 0x4ef54c | 0xef54c | 0xe694c | 0x0 |
HeapCreate | 0x0 | 0x4ef550 | 0xef550 | 0xe6950 | 0x0 |
HeapAlloc | 0x0 | 0x4ef554 | 0xef554 | 0xe6954 | 0x0 |
GetVolumeInformationW | 0x0 | 0x4ef558 | 0xef558 | 0xe6958 | 0x0 |
GetVersionExW | 0x0 | 0x4ef55c | 0xef55c | 0xe695c | 0x0 |
GetUserDefaultLangID | 0x0 | 0x4ef560 | 0xef560 | 0xe6960 | 0x0 |
GetUserDefaultLCID | 0x0 | 0x4ef564 | 0xef564 | 0xe6964 | 0x0 |
GetThreadTimes | 0x0 | 0x4ef568 | 0xef568 | 0xe6968 | 0x0 |
GetThreadPriority | 0x0 | 0x4ef56c | 0xef56c | 0xe696c | 0x0 |
GetThreadLocale | 0x0 | 0x4ef570 | 0xef570 | 0xe6970 | 0x0 |
GetSystemTimes | 0x0 | 0x4ef574 | 0xef574 | 0xe6974 | 0x0 |
GetSystemDefaultLangID | 0x0 | 0x4ef578 | 0xef578 | 0xe6978 | 0x0 |
GetSystemDefaultLCID | 0x0 | 0x4ef57c | 0xef57c | 0xe697c | 0x0 |
GetProcessTimes | 0x0 | 0x4ef580 | 0xef580 | 0xe6980 | 0x0 |
GetLocalTime | 0x0 | 0x4ef584 | 0xef584 | 0xe6984 | 0x0 |
GetFullPathNameW | 0x0 | 0x4ef588 | 0xef588 | 0xe6988 | 0x0 |
GetFileAttributesW | 0x0 | 0x4ef58c | 0xef58c | 0xe698c | 0x0 |
GetExitCodeThread | 0x0 | 0x4ef590 | 0xef590 | 0xe6990 | 0x0 |
GetDriveTypeW | 0x0 | 0x4ef594 | 0xef594 | 0xe6994 | 0x0 |
GetDiskFreeSpaceW | 0x0 | 0x4ef598 | 0xef598 | 0xe6998 | 0x0 |
GetDateFormatW | 0x0 | 0x4ef59c | 0xef59c | 0xe699c | 0x0 |
GetCurrentThread | 0x0 | 0x4ef5a0 | 0xef5a0 | 0xe69a0 | 0x0 |
GetCurrentProcessId | 0x0 | 0x4ef5a4 | 0xef5a4 | 0xe69a4 | 0x0 |
GetCurrentProcess | 0x0 | 0x4ef5a8 | 0xef5a8 | 0xe69a8 | 0x0 |
GetComputerNameA | 0x0 | 0x4ef5ac | 0xef5ac | 0xe69ac | 0x0 |
GetCPInfoExW | 0x0 | 0x4ef5b0 | 0xef5b0 | 0xe69b0 | 0x0 |
GetCPInfo | 0x0 | 0x4ef5b4 | 0xef5b4 | 0xe69b4 | 0x0 |
FreeResource | 0x0 | 0x4ef5b8 | 0xef5b8 | 0xe69b8 | 0x0 |
InterlockedCompareExchange | 0x0 | 0x4ef5bc | 0xef5bc | 0xe69bc | 0x0 |
FormatMessageW | 0x0 | 0x4ef5c0 | 0xef5c0 | 0xe69c0 | 0x0 |
FindResourceW | 0x0 | 0x4ef5c4 | 0xef5c4 | 0xe69c4 | 0x0 |
FindNextFileW | 0x0 | 0x4ef5c8 | 0xef5c8 | 0xe69c8 | 0x0 |
ExpandEnvironmentStringsW | 0x0 | 0x4ef5cc | 0xef5cc | 0xe69cc | 0x0 |
EnumSystemLocalesW | 0x0 | 0x4ef5d0 | 0xef5d0 | 0xe69d0 | 0x0 |
EnumCalendarInfoW | 0x0 | 0x4ef5d4 | 0xef5d4 | 0xe69d4 | 0x0 |
DeleteFileW | 0x0 | 0x4ef5d8 | 0xef5d8 | 0xe69d8 | 0x0 |
CreateProcessW | 0x0 | 0x4ef5dc | 0xef5dc | 0xe69dc | 0x0 |
CreateMutexW | 0x0 | 0x4ef5e0 | 0xef5e0 | 0xe69e0 | 0x0 |
CreateEventW | 0x0 | 0x4ef5e4 | 0xef5e4 | 0xe69e4 | 0x0 |
advapi32.dll (15)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryValueExW | 0x0 | 0x4ef3a0 | 0xef3a0 | 0xe67a0 | 0x0 |
RegOpenKeyExW | 0x0 | 0x4ef3a4 | 0xef3a4 | 0xe67a4 | 0x0 |
RegCloseKey | 0x0 | 0x4ef3a8 | 0xef3a8 | 0xe67a8 | 0x0 |
OpenThreadToken | 0x0 | 0x4ef3ac | 0xef3ac | 0xe67ac | 0x0 |
OpenProcessToken | 0x0 | 0x4ef3b0 | 0xef3b0 | 0xe67b0 | 0x0 |
GetUserNameA | 0x0 | 0x4ef3b4 | 0xef3b4 | 0xe67b4 | 0x0 |
GetTokenInformation | 0x0 | 0x4ef3b8 | 0xef3b8 | 0xe67b8 | 0x0 |
GetSidSubAuthorityCount | 0x0 | 0x4ef3bc | 0xef3bc | 0xe67bc | 0x0 |
GetSidSubAuthority | 0x0 | 0x4ef3c0 | 0xef3c0 | 0xe67c0 | 0x0 |
FreeSid | 0x0 | 0x4ef3c4 | 0xef3c4 | 0xe67c4 | 0x0 |
EqualSid | 0x0 | 0x4ef3c8 | 0xef3c8 | 0xe67c8 | 0x0 |
AllocateAndInitializeSid | 0x0 | 0x4ef3cc | 0xef3cc | 0xe67cc | 0x0 |
CryptGenRandom | 0x0 | 0x4ef3d0 | 0xef3d0 | 0xe67d0 | 0x0 |
CryptReleaseContext | 0x0 | 0x4ef3d4 | 0xef3d4 | 0xe67d4 | 0x0 |
CryptAcquireContextW | 0x0 | 0x4ef3d8 | 0xef3d8 | 0xe67d8 | 0x0 |
netapi32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetShareEnum | 0x0 | 0x4ef618 | 0xef618 | 0xe6a18 | 0x0 |
NetApiBufferFree | 0x0 | 0x4ef61c | 0xef61c | 0xe6a1c | 0x0 |
ole32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoUninitialize | 0x0 | 0x4ef5ec | 0xef5ec | 0xe69ec | 0x0 |
CoInitialize | 0x0 | 0x4ef5f0 | 0xef5f0 | 0xe69f0 | 0x0 |
oleaut32.dll (12)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysFreeString | 0x0 | 0x4ef36c | 0xef36c | 0xe676c | 0x0 |
SysReAllocStringLen | 0x0 | 0x4ef370 | 0xef370 | 0xe6770 | 0x0 |
SysAllocStringLen | 0x0 | 0x4ef374 | 0xef374 | 0xe6774 | 0x0 |
SafeArrayPtrOfIndex | 0x0 | 0x4ef378 | 0xef378 | 0xe6778 | 0x0 |
SafeArrayGetUBound | 0x0 | 0x4ef37c | 0xef37c | 0xe677c | 0x0 |
SafeArrayGetLBound | 0x0 | 0x4ef380 | 0xef380 | 0xe6780 | 0x0 |
SafeArrayCreate | 0x0 | 0x4ef384 | 0xef384 | 0xe6784 | 0x0 |
VariantChangeType | 0x0 | 0x4ef388 | 0xef388 | 0xe6788 | 0x0 |
VariantCopy | 0x0 | 0x4ef38c | 0xef38c | 0xe678c | 0x0 |
VariantClear | 0x0 | 0x4ef390 | 0xef390 | 0xe6790 | 0x0 |
VariantInit | 0x0 | 0x4ef394 | 0xef394 | 0xe6794 | 0x0 |
GetErrorInfo | 0x0 | 0x4ef398 | 0xef398 | 0xe6798 | 0x0 |
shell32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderPathW | 0x0 | 0x4ef5f8 | 0xef5f8 | 0xe69f8 | 0x0 |
user32.dll (10)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MessageBoxA | 0x0 | 0x4ef3e0 | 0xef3e0 | 0xe67e0 | 0x0 |
CharNextW | 0x0 | 0x4ef3e4 | 0xef3e4 | 0xe67e4 | 0x0 |
LoadStringW | 0x0 | 0x4ef3e8 | 0xef3e8 | 0xe67e8 | 0x0 |
PeekMessageW | 0x0 | 0x4ef3ec | 0xef3ec | 0xe67ec | 0x0 |
MsgWaitForMultipleObjects | 0x0 | 0x4ef3f0 | 0xef3f0 | 0xe67f0 | 0x0 |
MessageBoxW | 0x0 | 0x4ef3f4 | 0xef3f4 | 0xe67f4 | 0x0 |
GetSystemMetrics | 0x0 | 0x4ef3f8 | 0xef3f8 | 0xe67f8 | 0x0 |
CharUpperBuffW | 0x0 | 0x4ef3fc | 0xef3fc | 0xe67fc | 0x0 |
CharUpperW | 0x0 | 0x4ef400 | 0xef400 | 0xe6800 | 0x0 |
CharLowerBuffW | 0x0 | 0x4ef404 | 0xef404 | 0xe6804 | 0x0 |
wsock32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WSACleanup | 0x0 | 0x4ef600 | 0xef600 | 0xe6a00 | 0x0 |
WSAStartup | 0x0 | 0x4ef604 | 0xef604 | 0xe6a04 | 0x0 |
gethostname | 0x0 | 0x4ef608 | 0xef608 | 0xe6a08 | 0x0 |
gethostbyname | 0x0 | 0x4ef60c | 0xef60c | 0xe6a0c | 0x0 |
inet_ntoa | 0x0 | 0x4ef610 | 0xef610 | 0xe6a10 | 0x0 |
Exports (1)
»
Api name | EAT Address | Ordinal |
---|---|---|
TMethodImplementationIntercept | 0x509b8 | 0x1 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
dttcodexgigas.028ef1a52c04fce1f8d84e019167d54a9067fc13.exe | 1 | 0x00400000 | 0x0053AFFF | Relevant Image |
![]() |
32-bit | 0x00407620 |
![]() |
![]() |
...
|
nwxpvtxy.exe | 5 | 0x00400000 | 0x0053AFFF | Relevant Image |
![]() |
32-bit | 0x00407620 |
![]() |
![]() |
...
|
dttcodexgigas.028ef1a52c04fce1f8d84e019167d54a9067fc13.exe | 1 | 0x00400000 | 0x0053AFFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Ransom.Matrix.4BE75F48 |
Malicious
|
C:\Users\FD1HVy\AppData\Roaming\kZMrGSNH.vbs | Dropped File | Text |
Malicious
|
...
|
»
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
VBS.Heur.Laburrak.11.5A66A147.Gen |
Malicious
|
C:\Users\FD1HVy\Desktop\7tF4F6WU.exe | Dropped File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x475810 |
Size Of Code | 0x29000 |
Size Of Initialized Data | 0x1000 |
Size Of Uninitialized Data | 0x4c000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-12-10 21:18:46+00:00 |
Version Information (8)
»
CompanyName | Sysinternals - www.sysinternals.com |
FileDescription | Handle viewer |
FileVersion | 4.11 |
InternalName | Nthandle |
LegalCopyright | Copyright (C) 1997-2017 Mark Russinovich |
OriginalFilename | Nthandle.exe |
ProductName | Sysinternals Handle |
ProductVersion | 4.11 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
UPX0 | 0x401000 | 0x4c000 | 0x0 | 0x400 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
UPX1 | 0x44d000 | 0x29000 | 0x28a00 | 0x400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.93 |
.rsrc | 0x476000 | 0x1000 | 0x800 | 0x28e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.04 |
Imports (6)
»
ADVAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegOpenKeyW | 0x0 | 0x47666c | 0x7666c | 0x2946c | 0x0 |
COMDLG32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PrintDlgW | 0x0 | 0x476674 | 0x76674 | 0x29474 | 0x0 |
GDI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EndDoc | 0x0 | 0x47667c | 0x7667c | 0x2947c | 0x0 |
KERNEL32.DLL (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | 0x0 | 0x476684 | 0x76684 | 0x29484 | 0x0 |
ExitProcess | 0x0 | 0x476688 | 0x76688 | 0x29488 | 0x0 |
GetProcAddress | 0x0 | 0x47668c | 0x7668c | 0x2948c | 0x0 |
VirtualProtect | 0x0 | 0x476690 | 0x76690 | 0x29490 | 0x0 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EndDialog | 0x0 | 0x476698 | 0x76698 | 0x29498 | 0x0 |
VERSION.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VerQueryValueW | 0x0 | 0x4766a0 | 0x766a0 | 0x294a0 | 0x0 |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.40672878 |
Malicious
|
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\resources\[alexwind46@yahoo.com].AaUGItFq-dGadKOEV.AW46 | Dropped File | Text |
Suspicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PowerShell_Registry_Commands | PowerShell may attempt to read/write system registry | - |
2/5
|
...
|
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Document Building Blocks\1033\16\Built-In Building Blocks.dotx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\WyvO6UeD-ORXd74oEv.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\G1wuS.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\sr-Latn-RS\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\Logs\UniversalNotificationPlatform.003.etl | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\CollectSignatures.aapp | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\optimize_poster.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\scan_poster2x.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\organize_poster2x.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\FAkPpiJkg1p\3FYgeTsy\lqPLnsApfqOG0JcFRj\-KRzRVVXzfw B.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\organize_poster.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\Stamp.aapp | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\organize_poster2x.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DHtmlHeader.html | Modified File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\GQDjkfr2u6kfJjk.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\_r9DX5LWuCiFdfEUxNW.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\lO6z-.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\compare_poster2x.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\redact_poster.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\optimize_poster.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\NzmRPNDY0za.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\javacpl.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_pt_BR.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\ffjcext.zip | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\[alexwind46@yahoo.com].7PepoGUl-x6PnotSV.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\sample-files\assets\Sample Files\[alexwind46@yahoo.com].cWp3F9VC-D4sZRzUh.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\edit_pdf_poster.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\[alexwind46@yahoo.com].1JBGS8aW-Ldg4i24E.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\oIOWZ52E6vUkcso7Rz3V.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\[alexwind46@yahoo.com].GjnwZwWZ-I61OYiOI.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\RGB9Rast_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\[alexwind46@yahoo.com].8pMHXXpP-sCTpadDX.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\[alexwind46@yahoo.com].yiX4T5gC-T70tgJIq.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\[alexwind46@yahoo.com].WG7M3iQd-nwVKvvmq.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\[alexwind46@yahoo.com].luOXBaom-OjEubxoJ.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\ktab.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\tnameserv.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaBrightItalic.ttf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\key3.db | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\[alexwind46@yahoo.com].ZgjuBxCd-dIHbEUCo.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\meta-index | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\security\java.policy | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\[alexwind46@yahoo.com].0pa9sCrC-8L157yVL.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\[alexwind46@yahoo.com].c5hZEPtZ-ZO9ckXvS.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\[alexwind46@yahoo.com].Ie25U5mP-qvVAWqwX.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\[alexwind46@yahoo.com].T3yLqsYj-SR9mxhL3.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\da-DK\[alexwind46@yahoo.com].0uZFuZz8-cr8MECtJ.AW46 | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\en-IE\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\es-ES\[alexwind46@yahoo.com].za9FBDgU-PnoIfNcO.AW46 | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\fr-FR\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\ko-KR\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\nn-NO\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\[alexwind46@yahoo.com].nimsh30p-vvDCmRok.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\plugin-hang-ui.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\de-CH\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\en-MY\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\es-US\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\browser\features\followonsearch@mozilla.com.xpi | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\maintenanceservice.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Config_131491847713900000.json | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\el-GR\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\en-PH\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\app\dev\nls\pl-pl\ui-strings.js | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\et-EE\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\core\dev\nls\sl-si\ui-strings.js | Modified File | Text |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\[alexwind46@yahoo.com].ljUsL1IE-R8STnz65.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\[alexwind46@yahoo.com].Fw5ERmOM-WJuWZv9U.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaSansDemiBold.ttf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jsse.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\[alexwind46@yahoo.com].ElpwH3JU-WgaFZjUe.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\[alexwind46@yahoo.com].aJoKRBER-tJ7fChIz.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\[alexwind46@yahoo.com].zTIr8Vt9-KEvC4A0z.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\jabswitch.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\keytool.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\kinit.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\[alexwind46@yahoo.com].Qv1QSdxa-EFrQomRf.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\classlist | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\[alexwind46@yahoo.com].6zfdtdKf-g45Cuw0e.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_fr.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash@2x.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\[alexwind46@yahoo.com].LDXEs19W-t6tYgsLP.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\management\snmp.acl.template | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\[alexwind46@yahoo.com].NK3mRljj-1ZkxBT9Q.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\Multimedia\MPP\Flash.mpp | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\javaws.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\rmid.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\zipfs.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\browser\features\shield-recipe-client@mozilla.org.xpi | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Tracker\[alexwind46@yahoo.com].q58mA0C4-jZiMoj6W.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Tracker\[alexwind46@yahoo.com].hMsMDbpz-Ma7WJR4r.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\[alexwind46@yahoo.com].u6LLCTMi-aVWzh4Ir.AW46 | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\images\A12_Spinner.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\images\[alexwind46@yahoo.com].krwTwJWt-WTqJ0xax.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\browser\extensions\[alexwind46@yahoo.com].zC4y2ZG2-RzBK7zqB.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\browser\VisualElements\VisualElements_150.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\[alexwind46@yahoo.com].tGqLNWxU-A0JYPsqf.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\cursors.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\management\management.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaTypewriterBold.ttf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\dictionaries\[alexwind46@yahoo.com].uk4plgOT-61dsO8QS.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\logging.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\pingsender.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\psfontj2d.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\updater.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\security\US_export_policy.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\browser\features\clicktoplay-rollout@mozilla.org.xpi | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\images\logo_retina.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\images\themes\dark\apple-touch-icon-72x72-precomposed.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\gl-ES\[alexwind46@yahoo.com].3h18NFi5-O3GaFv2D.AW46 | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\cs-CZ\[alexwind46@yahoo.com].axXLyc52-V0os6o2v.AW46 | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\lb-LU\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\en-ID\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\pt-BR\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\es-CO\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\th-TH\[alexwind46@yahoo.com].rQTZyE3O-oa3EbKMg.AW46 | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\fr-CH\[alexwind46@yahoo.com].vK6IjGNp-xKtRzl02.AW46 | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\ja-JP\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\Logs\[alexwind46@yahoo.com].36bqPU6o-mekdN8kG.AW46 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\nl-NL\[alexwind46@yahoo.com].3Tdt6cKI-fALXjpkS.AW46 | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\Comments.aapp | Modified File | Binary |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\files\dev\nls\root\ui-strings.js | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\add-account\images\themes\dark\illustrations_retina.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\add-account\js\nls\nb-no\ui-strings.js | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\hr-HR\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\lv-LV\[alexwind46@yahoo.com].0KvN3F6Y-sLWdInn0.AW46 | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\dependentlibs.list | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\resources\20170517_Lock_200.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\uk-UA\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\nssdbm3.chk | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\ca-ES\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\en-GB\index.html | Modified File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\es-AR\[alexwind46@yahoo.com].eW6QKEft-fK0Lz6Rd.AW46 | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\!AW46_INFO!.rtf | Dropped File | RTF |
Unknown
|
...
|
»
Office Information
»
Document Content Snippet
»
SHIT H PPENS! WE H VE T INF RM Y U TH T LL Y UR FILES WERE ENCRYPTED!PLE SE BE SURE, Y UR FILES RE N T BR KEN! Y ur fil s w rn r pt d with str ng r ptlg rithms. * Pl s n t th t th r is n w t d r pt ur fil s with ut uniqu d r pti n knd sp i l s ftw r . Y ur uniqu d r pti n k is s ur l st r d n ur s rv r. * T d r pt ur d tu n d ur sp ifiut m ti d r pti n t l nd ur uniqu d r pti n k . * ll ur fil s w r r n m d but ft r d r pti n pr ss fil n m s will b r v r d trigin l st t . D t stru tur will n t h ng . * Pl s b sur th t ll thtt mpts t r v r ur fil s burs lf r using third p rt t ls n r sult in irr v bl l ss f ur d t ! WH T D Y U NEED T D ? First f ll u h v t writ us b-m il: ur first -m il:alexwind46@yahoo.com ur s nd -m il: tab alexwind46@protonmail.com ur third -m il: tab alexwind46@aol.comTTENTI N! If u w nt t r v r ur d t pl s writ us tll ur -m il dr ss s! It is r ll imp rt nt b usf d liv r pr bl ms with s m m ... |
C:\Users\FD1HVy\Documents\Outlook Files\kkcie@kdj.kd.pst | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Access\AccessCache.accdb | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\57kNvvEC.ods | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\resources\script.min.js | Modified File | Text |
Not Queried
|
...
|
»
C:\Program Files\UNP\Logs\UniversalNotificationPlatform.023.etl | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\protect_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\ZEwtkgxMvy5oNi6V3L.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\PtCvzKCL uGzOXdsqiym\PWG0zVe.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\CJHc.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\FAkPpiJkg1p\3FYgeTsy\lqPLnsApfqOG0JcFRj\9b1fAYl.doc | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\IDTemplates\ENU\DefaultID.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Resource\ENUtxt.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\Annotations\Stamps\ENU\StandardBusiness.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\combine_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\compare_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\Annotations\Stamps\ENU\Dynamic.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\combine_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\protect_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\9QN3tEpBHMmKCrCuwV.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\EPDF_RHP.aapp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroTextExtractor.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Javascripts\JSByteCodeWin.bin | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\u62QjOfH_i2VJW5dtx.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\PtCvzKCL uGzOXdsqiym\PJ3SGL31ZQ9jOv.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Database1.accdb | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\storage\permanent\moz-safe-about+home\idb\818200132aebmoouht.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Y xncAxGjuKGalMyq\LLEw7PEU.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\jydHoa.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\redact_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\qp-ycpx.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\PtCvzKCL uGzOXdsqiym\Rq7Y9jl S.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x64.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\FAkPpiJkg1p\VkvFECAbrF.ods | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\Annotations\Stamps\Words.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\combine_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\protect_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\edit_pdf_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\scan_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\IpfF0NnZ uGrZDsxtIgf.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\T2TX1mt2SpLfscUSHA.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-International%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Mozilla\Firefox\Profiles\w7cr0hor.default\OfflineCache\index.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\storage.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Y xncAxGjuKGalMyq\kEyHaU P-.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Y xncAxGjuKGalMyq\e gg5svu9ceLc9pc.ods | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x64.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\sample-files\assets\Sample Files\Adobe Sign White Paper.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\compare_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\protect_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\edit_pdf_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\MediaDb.v1.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\webappsstore.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\34H8p8SWFFSI5Ywr.xls | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Y0L6.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\1494870C-9912-C184-4CC9-B401-A53F4D8DE290.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\scan_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x86.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\sample-files\assets\Sample Files\Document Cloud for Government.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\tracked-send\images\email\dummy\adobe-old-logo.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd | Modified File | Batch |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\RGB9RAST_x64.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\HardwareEvents.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\pack200.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\COPYRIGHT | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\cmm\sRGB.pf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\access-bridge-64.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\[alexwind46@yahoo.com].acACUPdE-rIZj2xZh.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\FAkPpiJkg1p\3FYgeTsy\WTd-Lvc2OEGRWSt.xls | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\D-9VNYXsbB.doc | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\redact_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\[alexwind46@yahoo.com].v8UvDPcl-Xkv91njl.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\preoobe.cmd | Modified File | Batch |
Not Queried
|
...
|
»
C:\Logs\Internet Explorer.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\[alexwind46@yahoo.com].D5YLngC9-lIYtKyVY.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\cert8.db | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\[alexwind46@yahoo.com].tuOTnAJo-MXF4EYFw.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\cmm\LINEAR_RGB.pf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\[alexwind46@yahoo.com].PQkWvk1o-mqq0gP9s.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\sunec.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\[alexwind46@yahoo.com].kxr0D0Gx-3w3xW30j.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\[alexwind46@yahoo.com].7p6qyO5h-q4XtDsPE.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\[alexwind46@yahoo.com].tEjdBF0H-Nga69emE.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jfr.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\[alexwind46@yahoo.com].iZXOIoFo-VQgw26jy.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\cFplAzrXRmlW7FSQr.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\secmod.db | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\[alexwind46@yahoo.com].EagllMLO-ZxMvQmKA.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\[alexwind46@yahoo.com].zhEdlnpe-HT3pgRT2.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\browser\features\[alexwind46@yahoo.com].99E3eiNc-ZYtE3x92.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\firefox.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\FAkPpiJkg1p\[alexwind46@yahoo.com].o6atf0gR-H6pzhBD2.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\[alexwind46@yahoo.com].Kxl8RDLS-fr1zwStL.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\[alexwind46@yahoo.com].ecftQCP1-nkymluhi.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\favicons.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\omni.ja | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\crashreporter.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\images\themes\dark\RHP_icons_2x.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\freebl3.chk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.Targets | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\images\win-scrollbar\themes\dark\arrow-right.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\removed-files | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\images\win8-scrollbar\arrow-right.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\images\win8-scrollbar\themes\dark\arrow-up.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\app\dev\nls\fi-fi\ui-strings.js | Modified File | Text |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\app\dev\nls\uk-ua\ui-strings.js | Modified File | Text |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\core\dev\nls\en-gb\ui-strings.js | Modified File | Text |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\core\dev\nls\ja-jp\ui-strings.js | Modified File | Text |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\files\dev\nls\da-dk\ui-strings.js | Modified File | Text |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\[alexwind46@yahoo.com].6TxivjtN-FbSxhsg8.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\[alexwind46@yahoo.com].CAZTHzQO-flV2d4qF.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\[alexwind46@yahoo.com].vw96tY97-BE4faEne.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\sunmscapi.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkNoDrop32x32.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\[alexwind46@yahoo.com].zKaz63vj-vr6tfNxQ.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\ssvagent.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\cmm\[alexwind46@yahoo.com].dZ6LLxRx-wvTayqUB.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_it.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\[alexwind46@yahoo.com].mD6Cfo2z-0pObn0qS.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\server\[alexwind46@yahoo.com].PwEDCwJK-JY66TfD3.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\cmm\[alexwind46@yahoo.com].8hUaEI9V-kjWKwUY9.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\[alexwind46@yahoo.com].0P5JVCod-lGdljNGM.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\meta-index | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaBrightDemiBold.ttf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jfr\default.jfc | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\security\blacklisted.certs | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\AcroForm.api | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\[alexwind46@yahoo.com].klXzzqS1-dhbfJ7iC.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins3d\drvDX9.x3d | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\[alexwind46@yahoo.com].Wv6ClwmQ-w5WcIHEI.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\[alexwind46@yahoo.com].QtierYWg-f9QcTW0D.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jfr\[alexwind46@yahoo.com].wXLAw0ra-O5wcnEtb.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\[alexwind46@yahoo.com].uRtLcz1c-6IRQZZd0.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\[alexwind46@yahoo.com].WCxbnw7z-dEWChZQ8.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\security\cacerts | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\browser\features\screenshots@mozilla.org.xpi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\dictionaries\en-US.aff | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\amd64\jvm.cfg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\currency.data | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_zh_CN.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\dnsns.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\[alexwind46@yahoo.com].fZmg6tn2-a9kk1rQU.AW46 | Dropped File | Compressed |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\Accessible.tlb | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Tracker\[alexwind46@yahoo.com].CZdcFufx-UQoRSKWq.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Tracker\tr.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\images\file_types\hi_contrast\aic_file_icons_hiContrast_bow.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\images\hi_contrast\[alexwind46@yahoo.com].QMUneUvR-hH17zfR4.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\plugin.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\security\javaws.policy | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\[alexwind46@yahoo.com].a0Wz49S1-DqvK4BcW.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\[alexwind46@yahoo.com].9hACJJ6n-zYU2796A.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\security\[alexwind46@yahoo.com].Im28SHzz-Gu4hDc7o.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\tzmappings | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\[alexwind46@yahoo.com].IMiSwA2l-mLlqfjZv.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\rempl\remsh.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\images\themes\dark\[alexwind46@yahoo.com].6uqFJEhB-PMKZDFzF.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\images\themes\dark\japanese_over.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\resources\[alexwind46@yahoo.com].RRyAgSMs-CitazY3w.AW46 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\files\dev\nls\hr-hr\ui-strings.js | Modified File | Text |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\libs\jquery.ui.touch-punch\0.2.2\jquery.ui.touch-punch.js | Modified File | Text |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\add-account\images\illustrations.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\add-account\js\nls\es-es\ui-strings.js | Modified File | Text |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\add-account\js\nls\tr-tr\ui-strings.js | Modified File | Text |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\resources\Win10_Brand.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\uninstall\shortcuts_log.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\rempl\Logs\Remediation.002.etl | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\ALL_dmp.fldp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\MSN98FkB.bmp | Dropped File | Image |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\hKrobNjg.bat | Dropped File | Batch |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\EOscjPyJ.bat | Dropped File | Batch |
Not Queried
|
...
|
»