Dynamic Analysis Report |
Classification: Ransomware, Downloader, Trojan |
penelop0611_2019-11-06_10-30.exe_.exe
Created at 2019-11-07T12:51:00
Remarks (2/3)
(0x200000e): The overall sleep time of all monitored processes was truncated from "10 minutes, 15 seconds" to "10 seconds" to reveal dormant functionality.
(0x200003a): 2 tasks were rescheduled ahead of time to reveal dormant functionality.
Remarks
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200000c): The maximum memory dump size was exceeded. Some dumps may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\penelop0611_2019-11-06_10-30.exe_.exe | Sample File | Binary |
Malicious
|
...
|
Severity |
Blacklisted
|
First Seen | 2019-11-07 02:17 (UTC+1) |
Last Seen | 2019-11-07 10:59 (UTC+1) |
Names | Win32.Trojan.Kryptik |
Families | Kryptik |
Classification | Trojan |
Image Base | 0x400000 |
Entry Point | 0x402bf3 |
Size Of Code | 0xf000 |
Size Of Initialized Data | 0x192a00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-07-14 03:47:24+00:00 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xef5a | 0xf000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.75 |
.rdata | 0x410000 | 0x976c4 | 0x97800 | 0xf400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.97 |
.data | 0x4a8000 | 0xf0100 | 0x5400 | 0xa6c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.13 |
.rsrc | 0x599000 | 0xa9f8 | 0xaa00 | 0xac000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.13 |
.reloc | 0x5a4000 | 0x124c | 0x1400 | 0xb6a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.27 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetFilePointer | 0x0 | 0x410008 | 0xa6ee4 | 0xa62e4 | 0x466 |
WaitNamedPipeA | 0x0 | 0x41000c | 0xa6ee8 | 0xa62e8 | 0x4ff |
GetCurrentActCtx | 0x0 | 0x410010 | 0xa6eec | 0xa62ec | 0x1bb |
SetHandleInformation | 0x0 | 0x410014 | 0xa6ef0 | 0xa62f0 | 0x470 |
GetConsoleTitleA | 0x0 | 0x410018 | 0xa6ef4 | 0xa62f4 | 0x1b5 |
FindActCtxSectionStringA | 0x0 | 0x41001c | 0xa6ef8 | 0xa62f8 | 0x12a |
GetSystemWindowsDirectoryA | 0x0 | 0x410020 | 0xa6efc | 0xa62fc | 0x27b |
SetConsoleCP | 0x0 | 0x410024 | 0xa6f00 | 0xa6300 | 0x42c |
GetFileAttributesW | 0x0 | 0x410028 | 0xa6f04 | 0xa6304 | 0x1ea |
ReadFile | 0x0 | 0x41002c | 0xa6f08 | 0xa6308 | 0x3c0 |
GetModuleFileNameW | 0x0 | 0x410030 | 0xa6f0c | 0xa630c | 0x214 |
lstrlenW | 0x0 | 0x410034 | 0xa6f10 | 0xa6310 | 0x54e |
VerifyVersionInfoW | 0x0 | 0x410038 | 0xa6f14 | 0xa6314 | 0x4e8 |
SetDefaultCommConfigA | 0x0 | 0x41003c | 0xa6f18 | 0xa6318 | 0x44e |
SetLastError | 0x0 | 0x410040 | 0xa6f1c | 0xa631c | 0x473 |
GetProcAddress | 0x0 | 0x410044 | 0xa6f20 | 0xa6320 | 0x245 |
GetTapeStatus | 0x0 | 0x410048 | 0xa6f24 | 0xa6324 | 0x281 |
VerLanguageNameA | 0x0 | 0x41004c | 0xa6f28 | 0xa6328 | 0x4e2 |
LoadLibraryA | 0x0 | 0x410050 | 0xa6f2c | 0xa632c | 0x33c |
WriteConsoleA | 0x0 | 0x410054 | 0xa6f30 | 0xa6330 | 0x51a |
LocalAlloc | 0x0 | 0x410058 | 0xa6f34 | 0xa6334 | 0x344 |
GetNumberFormatW | 0x0 | 0x41005c | 0xa6f38 | 0xa6338 | 0x233 |
GetOEMCP | 0x0 | 0x410060 | 0xa6f3c | 0xa633c | 0x237 |
HeapSetInformation | 0x0 | 0x410064 | 0xa6f40 | 0xa6340 | 0x2d3 |
CreateMutexA | 0x0 | 0x410068 | 0xa6f44 | 0xa6344 | 0x9b |
GetStringTypeW | 0x0 | 0x41006c | 0xa6f48 | 0xa6348 | 0x269 |
GetPrivateProfileSectionW | 0x0 | 0x410070 | 0xa6f4c | 0xa634c | 0x240 |
LCMapStringW | 0x0 | 0x410074 | 0xa6f50 | 0xa6350 | 0x32d |
DeleteFileA | 0x0 | 0x410078 | 0xa6f54 | 0xa6354 | 0xd3 |
lstrcpyA | 0x0 | 0x41007c | 0xa6f58 | 0xa6358 | 0x547 |
WriteConsoleW | 0x0 | 0x410080 | 0xa6f5c | 0xa635c | 0x524 |
OutputDebugStringW | 0x0 | 0x410084 | 0xa6f60 | 0xa6360 | 0x38a |
EncodePointer | 0x0 | 0x410088 | 0xa6f64 | 0xa6364 | 0xea |
DecodePointer | 0x0 | 0x41008c | 0xa6f68 | 0xa6368 | 0xca |
GetLastError | 0x0 | 0x410090 | 0xa6f6c | 0xa636c | 0x202 |
HeapReAlloc | 0x0 | 0x410094 | 0xa6f70 | 0xa6370 | 0x2d2 |
GetCommandLineA | 0x0 | 0x410098 | 0xa6f74 | 0xa6374 | 0x186 |
RaiseException | 0x0 | 0x41009c | 0xa6f78 | 0xa6378 | 0x3b1 |
RtlUnwind | 0x0 | 0x4100a0 | 0xa6f7c | 0xa637c | 0x418 |
IsProcessorFeaturePresent | 0x0 | 0x4100a4 | 0xa6f80 | 0xa6380 | 0x304 |
ExitProcess | 0x0 | 0x4100a8 | 0xa6f84 | 0xa6384 | 0x119 |
GetModuleHandleExW | 0x0 | 0x4100ac | 0xa6f88 | 0xa6388 | 0x217 |
MultiByteToWideChar | 0x0 | 0x4100b0 | 0xa6f8c | 0xa638c | 0x367 |
WideCharToMultiByte | 0x0 | 0x4100b4 | 0xa6f90 | 0xa6390 | 0x511 |
HeapSize | 0x0 | 0x4100b8 | 0xa6f94 | 0xa6394 | 0x2d4 |
HeapFree | 0x0 | 0x4100bc | 0xa6f98 | 0xa6398 | 0x2cf |
IsDebuggerPresent | 0x0 | 0x4100c0 | 0xa6f9c | 0xa639c | 0x300 |
EnterCriticalSection | 0x0 | 0x4100c4 | 0xa6fa0 | 0xa63a0 | 0xee |
LeaveCriticalSection | 0x0 | 0x4100c8 | 0xa6fa4 | 0xa63a4 | 0x339 |
SetFilePointerEx | 0x0 | 0x4100cc | 0xa6fa8 | 0xa63a8 | 0x467 |
GetConsoleMode | 0x0 | 0x4100d0 | 0xa6fac | 0xa63ac | 0x1ac |
GetStdHandle | 0x0 | 0x4100d4 | 0xa6fb0 | 0xa63b0 | 0x264 |
GetFileType | 0x0 | 0x4100d8 | 0xa6fb4 | 0xa63b4 | 0x1f3 |
DeleteCriticalSection | 0x0 | 0x4100dc | 0xa6fb8 | 0xa63b8 | 0xd1 |
GetStartupInfoW | 0x0 | 0x4100e0 | 0xa6fbc | 0xa63bc | 0x263 |
GetCurrentThreadId | 0x0 | 0x4100e4 | 0xa6fc0 | 0xa63c0 | 0x1c5 |
HeapAlloc | 0x0 | 0x4100e8 | 0xa6fc4 | 0xa63c4 | 0x2cb |
GetProcessHeap | 0x0 | 0x4100ec | 0xa6fc8 | 0xa63c8 | 0x24a |
CloseHandle | 0x0 | 0x4100f0 | 0xa6fcc | 0xa63cc | 0x52 |
GetModuleFileNameA | 0x0 | 0x4100f4 | 0xa6fd0 | 0xa63d0 | 0x213 |
WriteFile | 0x0 | 0x4100f8 | 0xa6fd4 | 0xa63d4 | 0x525 |
QueryPerformanceCounter | 0x0 | 0x4100fc | 0xa6fd8 | 0xa63d8 | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x410100 | 0xa6fdc | 0xa63dc | 0x1c1 |
GetSystemTimeAsFileTime | 0x0 | 0x410104 | 0xa6fe0 | 0xa63e0 | 0x279 |
GetEnvironmentStringsW | 0x0 | 0x410108 | 0xa6fe4 | 0xa63e4 | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x41010c | 0xa6fe8 | 0xa63e8 | 0x161 |
UnhandledExceptionFilter | 0x0 | 0x410110 | 0xa6fec | 0xa63ec | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x410114 | 0xa6ff0 | 0xa63f0 | 0x4a5 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x410118 | 0xa6ff4 | 0xa63f4 | 0x2e3 |
Sleep | 0x0 | 0x41011c | 0xa6ff8 | 0xa63f8 | 0x4b2 |
GetCurrentProcess | 0x0 | 0x410120 | 0xa6ffc | 0xa63fc | 0x1c0 |
TerminateProcess | 0x0 | 0x410124 | 0xa7000 | 0xa6400 | 0x4c0 |
TlsAlloc | 0x0 | 0x410128 | 0xa7004 | 0xa6404 | 0x4c5 |
TlsGetValue | 0x0 | 0x41012c | 0xa7008 | 0xa6408 | 0x4c7 |
TlsSetValue | 0x0 | 0x410130 | 0xa700c | 0xa640c | 0x4c8 |
TlsFree | 0x0 | 0x410134 | 0xa7010 | 0xa6410 | 0x4c6 |
GetModuleHandleW | 0x0 | 0x410138 | 0xa7014 | 0xa6414 | 0x218 |
LoadLibraryExW | 0x0 | 0x41013c | 0xa7018 | 0xa6418 | 0x33e |
IsValidCodePage | 0x0 | 0x410140 | 0xa701c | 0xa641c | 0x30a |
GetACP | 0x0 | 0x410144 | 0xa7020 | 0xa6420 | 0x168 |
GetCPInfo | 0x0 | 0x410148 | 0xa7024 | 0xa6424 | 0x172 |
SetStdHandle | 0x0 | 0x41014c | 0xa7028 | 0xa6428 | 0x487 |
FlushFileBuffers | 0x0 | 0x410150 | 0xa702c | 0xa642c | 0x157 |
GetConsoleCP | 0x0 | 0x410154 | 0xa7030 | 0xa6430 | 0x19a |
CreateFileW | 0x0 | 0x410158 | 0xa7034 | 0xa6434 | 0x8f |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCaretPos | 0x0 | 0x410160 | 0xa703c | 0xa643c | 0x10a |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DeregisterEventSource | 0x0 | 0x410000 | 0xa6edc | 0xa62dc | 0xdb |
Api name | EAT Address | Ordinal |
---|---|---|
@MyFunc124@4 | 0xfef0 | 0x1 |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
penelop0611_2019-11-06_10-30.exe_.exe | 1 | 0x00400000 | 0x005A5FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00210020 | 0x002A0F37 | Marked Executable | - | 32-bit | 0x00210020 |
![]() |
![]() |
...
|
buffer | 1 | 0x005B0000 | 0x006C9FFF | First Execution | - | 32-bit | 0x005B0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x005B0000 | 0x006C9FFF | Content Changed | - | 32-bit | 0x005B04F6 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 1 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x00424141 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 1 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x00423F84 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 1 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x0042C0F0 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 1 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x0043B021 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 1 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x00431F64 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 1 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x00421881 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 1 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x0042B420 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 1 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x004548D0 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 1 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x0041CC50 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 1 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x00419E70 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 1 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x0040CF10 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 1 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x0041B680 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 1 | 0x00400000 | 0x005A5FFF | Final Dump | - | 32-bit | 0x00430BF0 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 1 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x004CB520 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 1 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x004CA6F7 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 1 | 0x00400000 | 0x005A5FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 5 | 0x00400000 | 0x005A5FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 5 | 0x002D0020 | 0x00360F37 | Marked Executable | - | 32-bit | 0x002D0020 |
![]() |
![]() |
...
|
buffer | 5 | 0x00760000 | 0x00879FFF | First Execution | - | 32-bit | 0x00760000 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 5 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x00424141 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 5 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x00423F84 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 5 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x0042C0F0 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 5 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x0043B021 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 5 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x00431F64 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 5 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x00421881 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 5 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x0042B420 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 5 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x004548D0 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 5 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x00401000 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 5 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x0041CC50 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 5 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x00419E70 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 5 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x0040CF10 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 5 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x0041B680 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 5 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x0041E031 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 5 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x0042E003 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 5 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x00447F50 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 5 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x0041F01A |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 5 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x00410FC0 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 5 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x0041E2CD |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 5 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x0041F187 |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 13 | 0x00400000 | 0x005A5FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
penelop0611_2019-11-06_10-30.exe_.exe | 5 | 0x00400000 | 0x005A5FFF | Content Changed | - | 32-bit | 0x004275BF |
![]() |
![]() |
...
|
buffer | 19 | 0x00350020 | 0x003E0F37 | Marked Executable | - | 32-bit | 0x00350020 |
![]() |
![]() |
...
|
buffer | 19 | 0x005B0000 | 0x006C9FFF | First Execution | - | 32-bit | 0x005B0000 |
![]() |
![]() |
...
|
Threat Name | Severity |
---|---|
Trojan.GenericKDZ.59409 |
Malicious
|
C:\Windows\System32\drivers\etc\hosts | Modified File | Text |
Malicious
|
...
|
Threat Name | Severity |
---|---|
Gen:Trojan.Qhost.1 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xw_W- RtiM1Q0r\pW62l8V1WmQv\ipuh6vEIRVj3YgV2b.pdf | Modified File |
Malicious
|
...
|
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\4883c25a-c55c-46aa-a0b1-c2c0b01a64fc\updatewin1.exe | Downloaded File | Binary |
Malicious
|
...
|
Severity |
Blacklisted
|
First Seen | 2019-01-16 22:21 (UTC+1) |
Last Seen | 2019-07-21 22:40 (UTC+2) |
Names | Win32.Trojan.Kryptik |
Families | Kryptik |
Classification | Trojan |
Image Base | 0x400000 |
Entry Point | 0x402d76 |
Size Of Code | 0x1c200 |
Size Of Initialized Data | 0x2c200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-07-24 12:23:54+00:00 |
FileVersion | 7.7.7.18 |
InternalName | rawudiyeh.exe |
LegalCopyright | Copyright (C) 2018, sacuwedimufoy |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1c07e | 0x1c200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x41e000 | 0x463e | 0x4800 | 0x1c600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.26 |
.data | 0x423000 | 0x1c6a8 | 0x17400 | 0x20e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.83 |
.rsrc | 0x440000 | 0xa578 | 0xa600 | 0x38200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.88 |
.reloc | 0x44b000 | 0x1968 | 0x1a00 | 0x42800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.34 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitThread | 0x0 | 0x41e028 | 0x21afc | 0x200fc | 0x105 |
GetStartupInfoW | 0x0 | 0x41e02c | 0x21b00 | 0x20100 | 0x23a |
GetLastError | 0x0 | 0x41e030 | 0x21b04 | 0x20104 | 0x1e6 |
GetProcAddress | 0x0 | 0x41e034 | 0x21b08 | 0x20108 | 0x220 |
CreateJobSet | 0x0 | 0x41e038 | 0x21b0c | 0x2010c | 0x87 |
GlobalFree | 0x0 | 0x41e03c | 0x21b10 | 0x20110 | 0x28c |
LoadLibraryA | 0x0 | 0x41e040 | 0x21b14 | 0x20114 | 0x2f1 |
OpenWaitableTimerW | 0x0 | 0x41e044 | 0x21b18 | 0x20118 | 0x339 |
AddAtomA | 0x0 | 0x41e048 | 0x21b1c | 0x2011c | 0x3 |
FindFirstChangeNotificationA | 0x0 | 0x41e04c | 0x21b20 | 0x20120 | 0x11b |
VirtualProtect | 0x0 | 0x41e050 | 0x21b24 | 0x20124 | 0x45a |
GetCurrentDirectoryA | 0x0 | 0x41e054 | 0x21b28 | 0x20128 | 0x1a7 |
GetACP | 0x0 | 0x41e058 | 0x21b2c | 0x2012c | 0x152 |
InterlockedPushEntrySList | 0x0 | 0x41e05c | 0x21b30 | 0x20130 | 0x2c2 |
CompareStringW | 0x0 | 0x41e060 | 0x21b34 | 0x20134 | 0x55 |
CompareStringA | 0x0 | 0x41e064 | 0x21b38 | 0x20138 | 0x52 |
CreateFileA | 0x0 | 0x41e068 | 0x21b3c | 0x2013c | 0x78 |
GetTimeZoneInformation | 0x0 | 0x41e06c | 0x21b40 | 0x20140 | 0x26b |
WriteConsoleW | 0x0 | 0x41e070 | 0x21b44 | 0x20144 | 0x48c |
GetConsoleOutputCP | 0x0 | 0x41e074 | 0x21b48 | 0x20148 | 0x199 |
WriteConsoleA | 0x0 | 0x41e078 | 0x21b4c | 0x2014c | 0x482 |
CloseHandle | 0x0 | 0x41e07c | 0x21b50 | 0x20150 | 0x43 |
IsValidLocale | 0x0 | 0x41e080 | 0x21b54 | 0x20154 | 0x2dd |
EnumSystemLocalesA | 0x0 | 0x41e084 | 0x21b58 | 0x20158 | 0xf8 |
GetUserDefaultLCID | 0x0 | 0x41e088 | 0x21b5c | 0x2015c | 0x26d |
GetSystemTimeAdjustment | 0x0 | 0x41e08c | 0x21b60 | 0x20160 | 0x24e |
GetSystemTimes | 0x0 | 0x41e090 | 0x21b64 | 0x20164 | 0x250 |
GetTickCount | 0x0 | 0x41e094 | 0x21b68 | 0x20168 | 0x266 |
FreeEnvironmentStringsA | 0x0 | 0x41e098 | 0x21b6c | 0x2016c | 0x14a |
GetComputerNameW | 0x0 | 0x41e09c | 0x21b70 | 0x20170 | 0x178 |
FindCloseChangeNotification | 0x0 | 0x41e0a0 | 0x21b74 | 0x20174 | 0x11a |
FindResourceExW | 0x0 | 0x41e0a4 | 0x21b78 | 0x20178 | 0x138 |
GetCPInfo | 0x0 | 0x41e0a8 | 0x21b7c | 0x2017c | 0x15b |
SetProcessShutdownParameters | 0x0 | 0x41e0ac | 0x21b80 | 0x20180 | 0x3f9 |
GetModuleHandleExA | 0x0 | 0x41e0b0 | 0x21b84 | 0x20184 | 0x1f7 |
GetDateFormatA | 0x0 | 0x41e0b4 | 0x21b88 | 0x20188 | 0x1ae |
GetTimeFormatA | 0x0 | 0x41e0b8 | 0x21b8c | 0x2018c | 0x268 |
GetStringTypeW | 0x0 | 0x41e0bc | 0x21b90 | 0x20190 | 0x240 |
GetStringTypeA | 0x0 | 0x41e0c0 | 0x21b94 | 0x20194 | 0x23d |
LCMapStringW | 0x0 | 0x41e0c4 | 0x21b98 | 0x20198 | 0x2e3 |
GetCommandLineA | 0x0 | 0x41e0c8 | 0x21b9c | 0x2019c | 0x16f |
GetStartupInfoA | 0x0 | 0x41e0cc | 0x21ba0 | 0x201a0 | 0x239 |
RaiseException | 0x0 | 0x41e0d0 | 0x21ba4 | 0x201a4 | 0x35a |
RtlUnwind | 0x0 | 0x41e0d4 | 0x21ba8 | 0x201a8 | 0x392 |
TerminateProcess | 0x0 | 0x41e0d8 | 0x21bac | 0x201ac | 0x42d |
GetCurrentProcess | 0x0 | 0x41e0dc | 0x21bb0 | 0x201b0 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x41e0e0 | 0x21bb4 | 0x201b4 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x41e0e4 | 0x21bb8 | 0x201b8 | 0x415 |
IsDebuggerPresent | 0x0 | 0x41e0e8 | 0x21bbc | 0x201bc | 0x2d1 |
HeapAlloc | 0x0 | 0x41e0ec | 0x21bc0 | 0x201c0 | 0x29d |
HeapFree | 0x0 | 0x41e0f0 | 0x21bc4 | 0x201c4 | 0x2a1 |
EnterCriticalSection | 0x0 | 0x41e0f4 | 0x21bc8 | 0x201c8 | 0xd9 |
LeaveCriticalSection | 0x0 | 0x41e0f8 | 0x21bcc | 0x201cc | 0x2ef |
SetHandleCount | 0x0 | 0x41e0fc | 0x21bd0 | 0x201d0 | 0x3e8 |
GetStdHandle | 0x0 | 0x41e100 | 0x21bd4 | 0x201d4 | 0x23b |
GetFileType | 0x0 | 0x41e104 | 0x21bd8 | 0x201d8 | 0x1d7 |
DeleteCriticalSection | 0x0 | 0x41e108 | 0x21bdc | 0x201dc | 0xbe |
GetModuleHandleW | 0x0 | 0x41e10c | 0x21be0 | 0x201e0 | 0x1f9 |
Sleep | 0x0 | 0x41e110 | 0x21be4 | 0x201e4 | 0x421 |
ExitProcess | 0x0 | 0x41e114 | 0x21be8 | 0x201e8 | 0x104 |
WriteFile | 0x0 | 0x41e118 | 0x21bec | 0x201ec | 0x48d |
GetModuleFileNameA | 0x0 | 0x41e11c | 0x21bf0 | 0x201f0 | 0x1f4 |
GetEnvironmentStrings | 0x0 | 0x41e120 | 0x21bf4 | 0x201f4 | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x41e124 | 0x21bf8 | 0x201f8 | 0x14b |
WideCharToMultiByte | 0x0 | 0x41e128 | 0x21bfc | 0x201fc | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x41e12c | 0x21c00 | 0x20200 | 0x1c1 |
TlsGetValue | 0x0 | 0x41e130 | 0x21c04 | 0x20204 | 0x434 |
TlsAlloc | 0x0 | 0x41e134 | 0x21c08 | 0x20208 | 0x432 |
TlsSetValue | 0x0 | 0x41e138 | 0x21c0c | 0x2020c | 0x435 |
TlsFree | 0x0 | 0x41e13c | 0x21c10 | 0x20210 | 0x433 |
InterlockedIncrement | 0x0 | 0x41e140 | 0x21c14 | 0x20214 | 0x2c0 |
SetLastError | 0x0 | 0x41e144 | 0x21c18 | 0x20218 | 0x3ec |
GetCurrentThreadId | 0x0 | 0x41e148 | 0x21c1c | 0x2021c | 0x1ad |
InterlockedDecrement | 0x0 | 0x41e14c | 0x21c20 | 0x20220 | 0x2bc |
GetCurrentThread | 0x0 | 0x41e150 | 0x21c24 | 0x20224 | 0x1ac |
HeapCreate | 0x0 | 0x41e154 | 0x21c28 | 0x20228 | 0x29f |
HeapDestroy | 0x0 | 0x41e158 | 0x21c2c | 0x2022c | 0x2a0 |
VirtualFree | 0x0 | 0x41e15c | 0x21c30 | 0x20230 | 0x457 |
QueryPerformanceCounter | 0x0 | 0x41e160 | 0x21c34 | 0x20234 | 0x354 |
GetCurrentProcessId | 0x0 | 0x41e164 | 0x21c38 | 0x20238 | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x41e168 | 0x21c3c | 0x2023c | 0x24f |
FatalAppExitA | 0x0 | 0x41e16c | 0x21c40 | 0x20240 | 0x10b |
VirtualAlloc | 0x0 | 0x41e170 | 0x21c44 | 0x20244 | 0x454 |
HeapReAlloc | 0x0 | 0x41e174 | 0x21c48 | 0x20248 | 0x2a4 |
MultiByteToWideChar | 0x0 | 0x41e178 | 0x21c4c | 0x2024c | 0x31a |
ReadFile | 0x0 | 0x41e17c | 0x21c50 | 0x20250 | 0x368 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41e180 | 0x21c54 | 0x20254 | 0x2b5 |
HeapSize | 0x0 | 0x41e184 | 0x21c58 | 0x20258 | 0x2a6 |
SetConsoleCtrlHandler | 0x0 | 0x41e188 | 0x21c5c | 0x2025c | 0x3a7 |
FreeLibrary | 0x0 | 0x41e18c | 0x21c60 | 0x20260 | 0x14c |
InterlockedExchange | 0x0 | 0x41e190 | 0x21c64 | 0x20264 | 0x2bd |
GetOEMCP | 0x0 | 0x41e194 | 0x21c68 | 0x20268 | 0x213 |
IsValidCodePage | 0x0 | 0x41e198 | 0x21c6c | 0x2026c | 0x2db |
GetConsoleCP | 0x0 | 0x41e19c | 0x21c70 | 0x20270 | 0x183 |
GetConsoleMode | 0x0 | 0x41e1a0 | 0x21c74 | 0x20274 | 0x195 |
FlushFileBuffers | 0x0 | 0x41e1a4 | 0x21c78 | 0x20278 | 0x141 |
SetFilePointer | 0x0 | 0x41e1a8 | 0x21c7c | 0x2027c | 0x3df |
SetStdHandle | 0x0 | 0x41e1ac | 0x21c80 | 0x20280 | 0x3fc |
GetLocaleInfoW | 0x0 | 0x41e1b0 | 0x21c84 | 0x20284 | 0x1ea |
GetLocaleInfoA | 0x0 | 0x41e1b4 | 0x21c88 | 0x20288 | 0x1e8 |
LCMapStringA | 0x0 | 0x41e1b8 | 0x21c8c | 0x2028c | 0x2e1 |
SetEnvironmentVariableA | 0x0 | 0x41e1bc | 0x21c90 | 0x20290 | 0x3d0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseClipboard | 0x0 | 0x41e1d8 | 0x21cac | 0x202ac | 0x47 |
BeginPaint | 0x0 | 0x41e1dc | 0x21cb0 | 0x202b0 | 0xe |
CallMsgFilterW | 0x0 | 0x41e1e0 | 0x21cb4 | 0x202b4 | 0x1a |
PeekMessageA | 0x0 | 0x41e1e4 | 0x21cb8 | 0x202b8 | 0x21b |
MapVirtualKeyExW | 0x0 | 0x41e1e8 | 0x21cbc | 0x202bc | 0x1f1 |
RegisterRawInputDevices | 0x0 | 0x41e1ec | 0x21cc0 | 0x202c0 | 0x242 |
GetClipboardSequenceNumber | 0x0 | 0x41e1f0 | 0x21cc4 | 0x202c4 | 0x113 |
CountClipboardFormats | 0x0 | 0x41e1f4 | 0x21cc8 | 0x202c8 | 0x50 |
GetDialogBaseUnits | 0x0 | 0x41e1f8 | 0x21ccc | 0x202cc | 0x11d |
GetClassLongW | 0x0 | 0x41e1fc | 0x21cd0 | 0x202d0 | 0x109 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PolyTextOutW | 0x0 | 0x41e000 | 0x21ad4 | 0x200d4 | 0x23c |
CreateCompatibleDC | 0x0 | 0x41e004 | 0x21ad8 | 0x200d8 | 0x2e |
Rectangle | 0x0 | 0x41e008 | 0x21adc | 0x200dc | 0x246 |
SetStretchBltMode | 0x0 | 0x41e00c | 0x21ae0 | 0x200e0 | 0x289 |
SetPixelV | 0x0 | 0x41e010 | 0x21ae4 | 0x200e4 | 0x284 |
GetClipBox | 0x0 | 0x41e014 | 0x21ae8 | 0x200e8 | 0x1aa |
CreateDiscardableBitmap | 0x0 | 0x41e018 | 0x21aec | 0x200ec | 0x35 |
StrokeAndFillPath | 0x0 | 0x41e01c | 0x21af0 | 0x200f0 | 0x29c |
GetBitmapBits | 0x0 | 0x41e020 | 0x21af4 | 0x200f4 | 0x191 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x41e1c4 | 0x21c98 | 0x20298 | 0x118 |
ShellAboutW | 0x0 | 0x41e1c8 | 0x21c9c | 0x2029c | 0x110 |
DuplicateIcon | 0x0 | 0x41e1cc | 0x21ca0 | 0x202a0 | 0x23 |
DragQueryFileA | 0x0 | 0x41e1d0 | 0x21ca4 | 0x202a4 | 0x1e |
Threat Name | Severity |
---|---|
Trojan.GenericKD.31534187 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\4883c25a-c55c-46aa-a0b1-c2c0b01a64fc\updatewin2.exe | Downloaded File | Binary |
Malicious
|
...
|
Severity |
Blacklisted
|
First Seen | 2019-01-16 22:21 (UTC+1) |
Last Seen | 2019-09-04 10:43 (UTC+2) |
Names | Win32.Trojan.Qhost |
Families | Qhost |
Classification | Trojan |
Image Base | 0x400000 |
Entry Point | 0x402d64 |
Size Of Code | 0x1c200 |
Size Of Initialized Data | 0x2c800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-11-21 06:08:45+00:00 |
FileVersion | 5.3.7.82 |
InternalName | gigifaw.exe |
LegalCopyright | Copyright (C) 2018, guvaxiz |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1c03e | 0x1c200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x41e000 | 0x45ec | 0x4600 | 0x1c600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.34 |
.data | 0x423000 | 0x1cde8 | 0x17c00 | 0x20c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.8 |
.rsrc | 0x440000 | 0xa724 | 0xa800 | 0x38800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.88 |
.reloc | 0x44b000 | 0x195c | 0x1a00 | 0x43000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.33 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitThread | 0x0 | 0x41e024 | 0x21ae8 | 0x200e8 | 0x105 |
GetStartupInfoW | 0x0 | 0x41e028 | 0x21aec | 0x200ec | 0x23a |
GetLastError | 0x0 | 0x41e02c | 0x21af0 | 0x200f0 | 0x1e6 |
GetProcAddress | 0x0 | 0x41e030 | 0x21af4 | 0x200f4 | 0x220 |
GlobalFree | 0x0 | 0x41e034 | 0x21af8 | 0x200f8 | 0x28c |
LoadLibraryA | 0x0 | 0x41e038 | 0x21afc | 0x200fc | 0x2f1 |
AddAtomA | 0x0 | 0x41e03c | 0x21b00 | 0x20100 | 0x3 |
FindFirstChangeNotificationA | 0x0 | 0x41e040 | 0x21b04 | 0x20104 | 0x11b |
VirtualProtect | 0x0 | 0x41e044 | 0x21b08 | 0x20108 | 0x45a |
GetCurrentDirectoryA | 0x0 | 0x41e048 | 0x21b0c | 0x2010c | 0x1a7 |
SetProcessShutdownParameters | 0x0 | 0x41e04c | 0x21b10 | 0x20110 | 0x3f9 |
GetACP | 0x0 | 0x41e050 | 0x21b14 | 0x20114 | 0x152 |
CompareStringA | 0x0 | 0x41e054 | 0x21b18 | 0x20118 | 0x52 |
CreateFileA | 0x0 | 0x41e058 | 0x21b1c | 0x2011c | 0x78 |
GetTimeZoneInformation | 0x0 | 0x41e05c | 0x21b20 | 0x20120 | 0x26b |
WriteConsoleW | 0x0 | 0x41e060 | 0x21b24 | 0x20124 | 0x48c |
GetConsoleOutputCP | 0x0 | 0x41e064 | 0x21b28 | 0x20128 | 0x199 |
WriteConsoleA | 0x0 | 0x41e068 | 0x21b2c | 0x2012c | 0x482 |
CloseHandle | 0x0 | 0x41e06c | 0x21b30 | 0x20130 | 0x43 |
IsValidLocale | 0x0 | 0x41e070 | 0x21b34 | 0x20134 | 0x2dd |
EnumSystemLocalesA | 0x0 | 0x41e074 | 0x21b38 | 0x20138 | 0xf8 |
GetUserDefaultLCID | 0x0 | 0x41e078 | 0x21b3c | 0x2013c | 0x26d |
GetDateFormatA | 0x0 | 0x41e07c | 0x21b40 | 0x20140 | 0x1ae |
GetTimeFormatA | 0x0 | 0x41e080 | 0x21b44 | 0x20144 | 0x268 |
InitAtomTable | 0x0 | 0x41e084 | 0x21b48 | 0x20148 | 0x2ae |
GetSystemTimes | 0x0 | 0x41e088 | 0x21b4c | 0x2014c | 0x250 |
GetTickCount | 0x0 | 0x41e08c | 0x21b50 | 0x20150 | 0x266 |
FreeEnvironmentStringsA | 0x0 | 0x41e090 | 0x21b54 | 0x20154 | 0x14a |
GetComputerNameW | 0x0 | 0x41e094 | 0x21b58 | 0x20158 | 0x178 |
FindCloseChangeNotification | 0x0 | 0x41e098 | 0x21b5c | 0x2015c | 0x11a |
FindResourceExW | 0x0 | 0x41e09c | 0x21b60 | 0x20160 | 0x138 |
CompareStringW | 0x0 | 0x41e0a0 | 0x21b64 | 0x20164 | 0x55 |
GetCPInfo | 0x0 | 0x41e0a4 | 0x21b68 | 0x20168 | 0x15b |
GetStringTypeW | 0x0 | 0x41e0a8 | 0x21b6c | 0x2016c | 0x240 |
GetStringTypeA | 0x0 | 0x41e0ac | 0x21b70 | 0x20170 | 0x23d |
LCMapStringW | 0x0 | 0x41e0b0 | 0x21b74 | 0x20174 | 0x2e3 |
LCMapStringA | 0x0 | 0x41e0b4 | 0x21b78 | 0x20178 | 0x2e1 |
GetLocaleInfoA | 0x0 | 0x41e0b8 | 0x21b7c | 0x2017c | 0x1e8 |
GetCommandLineA | 0x0 | 0x41e0bc | 0x21b80 | 0x20180 | 0x16f |
GetStartupInfoA | 0x0 | 0x41e0c0 | 0x21b84 | 0x20184 | 0x239 |
RaiseException | 0x0 | 0x41e0c4 | 0x21b88 | 0x20188 | 0x35a |
RtlUnwind | 0x0 | 0x41e0c8 | 0x21b8c | 0x2018c | 0x392 |
TerminateProcess | 0x0 | 0x41e0cc | 0x21b90 | 0x20190 | 0x42d |
GetCurrentProcess | 0x0 | 0x41e0d0 | 0x21b94 | 0x20194 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x41e0d4 | 0x21b98 | 0x20198 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x41e0d8 | 0x21b9c | 0x2019c | 0x415 |
IsDebuggerPresent | 0x0 | 0x41e0dc | 0x21ba0 | 0x201a0 | 0x2d1 |
HeapAlloc | 0x0 | 0x41e0e0 | 0x21ba4 | 0x201a4 | 0x29d |
HeapFree | 0x0 | 0x41e0e4 | 0x21ba8 | 0x201a8 | 0x2a1 |
EnterCriticalSection | 0x0 | 0x41e0e8 | 0x21bac | 0x201ac | 0xd9 |
LeaveCriticalSection | 0x0 | 0x41e0ec | 0x21bb0 | 0x201b0 | 0x2ef |
SetHandleCount | 0x0 | 0x41e0f0 | 0x21bb4 | 0x201b4 | 0x3e8 |
GetStdHandle | 0x0 | 0x41e0f4 | 0x21bb8 | 0x201b8 | 0x23b |
GetFileType | 0x0 | 0x41e0f8 | 0x21bbc | 0x201bc | 0x1d7 |
DeleteCriticalSection | 0x0 | 0x41e0fc | 0x21bc0 | 0x201c0 | 0xbe |
GetModuleHandleW | 0x0 | 0x41e100 | 0x21bc4 | 0x201c4 | 0x1f9 |
Sleep | 0x0 | 0x41e104 | 0x21bc8 | 0x201c8 | 0x421 |
ExitProcess | 0x0 | 0x41e108 | 0x21bcc | 0x201cc | 0x104 |
WriteFile | 0x0 | 0x41e10c | 0x21bd0 | 0x201d0 | 0x48d |
GetModuleFileNameA | 0x0 | 0x41e110 | 0x21bd4 | 0x201d4 | 0x1f4 |
GetEnvironmentStrings | 0x0 | 0x41e114 | 0x21bd8 | 0x201d8 | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x41e118 | 0x21bdc | 0x201dc | 0x14b |
WideCharToMultiByte | 0x0 | 0x41e11c | 0x21be0 | 0x201e0 | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x41e120 | 0x21be4 | 0x201e4 | 0x1c1 |
TlsGetValue | 0x0 | 0x41e124 | 0x21be8 | 0x201e8 | 0x434 |
TlsAlloc | 0x0 | 0x41e128 | 0x21bec | 0x201ec | 0x432 |
TlsSetValue | 0x0 | 0x41e12c | 0x21bf0 | 0x201f0 | 0x435 |
TlsFree | 0x0 | 0x41e130 | 0x21bf4 | 0x201f4 | 0x433 |
InterlockedIncrement | 0x0 | 0x41e134 | 0x21bf8 | 0x201f8 | 0x2c0 |
SetLastError | 0x0 | 0x41e138 | 0x21bfc | 0x201fc | 0x3ec |
GetCurrentThreadId | 0x0 | 0x41e13c | 0x21c00 | 0x20200 | 0x1ad |
InterlockedDecrement | 0x0 | 0x41e140 | 0x21c04 | 0x20204 | 0x2bc |
GetCurrentThread | 0x0 | 0x41e144 | 0x21c08 | 0x20208 | 0x1ac |
HeapCreate | 0x0 | 0x41e148 | 0x21c0c | 0x2020c | 0x29f |
HeapDestroy | 0x0 | 0x41e14c | 0x21c10 | 0x20210 | 0x2a0 |
VirtualFree | 0x0 | 0x41e150 | 0x21c14 | 0x20214 | 0x457 |
QueryPerformanceCounter | 0x0 | 0x41e154 | 0x21c18 | 0x20218 | 0x354 |
GetCurrentProcessId | 0x0 | 0x41e158 | 0x21c1c | 0x2021c | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x41e15c | 0x21c20 | 0x20220 | 0x24f |
FatalAppExitA | 0x0 | 0x41e160 | 0x21c24 | 0x20224 | 0x10b |
VirtualAlloc | 0x0 | 0x41e164 | 0x21c28 | 0x20228 | 0x454 |
HeapReAlloc | 0x0 | 0x41e168 | 0x21c2c | 0x2022c | 0x2a4 |
MultiByteToWideChar | 0x0 | 0x41e16c | 0x21c30 | 0x20230 | 0x31a |
ReadFile | 0x0 | 0x41e170 | 0x21c34 | 0x20234 | 0x368 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41e174 | 0x21c38 | 0x20238 | 0x2b5 |
HeapSize | 0x0 | 0x41e178 | 0x21c3c | 0x2023c | 0x2a6 |
SetConsoleCtrlHandler | 0x0 | 0x41e17c | 0x21c40 | 0x20240 | 0x3a7 |
FreeLibrary | 0x0 | 0x41e180 | 0x21c44 | 0x20244 | 0x14c |
InterlockedExchange | 0x0 | 0x41e184 | 0x21c48 | 0x20248 | 0x2bd |
GetOEMCP | 0x0 | 0x41e188 | 0x21c4c | 0x2024c | 0x213 |
IsValidCodePage | 0x0 | 0x41e18c | 0x21c50 | 0x20250 | 0x2db |
GetConsoleCP | 0x0 | 0x41e190 | 0x21c54 | 0x20254 | 0x183 |
GetConsoleMode | 0x0 | 0x41e194 | 0x21c58 | 0x20258 | 0x195 |
FlushFileBuffers | 0x0 | 0x41e198 | 0x21c5c | 0x2025c | 0x141 |
SetFilePointer | 0x0 | 0x41e19c | 0x21c60 | 0x20260 | 0x3df |
SetStdHandle | 0x0 | 0x41e1a0 | 0x21c64 | 0x20264 | 0x3fc |
GetLocaleInfoW | 0x0 | 0x41e1a4 | 0x21c68 | 0x20268 | 0x1ea |
SetEnvironmentVariableA | 0x0 | 0x41e1a8 | 0x21c6c | 0x2026c | 0x3d0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseClipboard | 0x0 | 0x41e1c4 | 0x21c88 | 0x20288 | 0x47 |
GetSubMenu | 0x0 | 0x41e1c8 | 0x21c8c | 0x2028c | 0x16b |
LoadBitmapA | 0x0 | 0x41e1cc | 0x21c90 | 0x20290 | 0x1d0 |
BeginPaint | 0x0 | 0x41e1d0 | 0x21c94 | 0x20294 | 0xe |
CallMsgFilterW | 0x0 | 0x41e1d4 | 0x21c98 | 0x20298 | 0x1a |
PeekMessageA | 0x0 | 0x41e1d8 | 0x21c9c | 0x2029c | 0x21b |
MapVirtualKeyExW | 0x0 | 0x41e1dc | 0x21ca0 | 0x202a0 | 0x1f1 |
RegisterRawInputDevices | 0x0 | 0x41e1e0 | 0x21ca4 | 0x202a4 | 0x242 |
SetWindowsHookExW | 0x0 | 0x41e1e4 | 0x21ca8 | 0x202a8 | 0x2b0 |
GetClipboardSequenceNumber | 0x0 | 0x41e1e8 | 0x21cac | 0x202ac | 0x113 |
GetDialogBaseUnits | 0x0 | 0x41e1ec | 0x21cb0 | 0x202b0 | 0x11d |
MessageBoxIndirectA | 0x0 | 0x41e1f0 | 0x21cb4 | 0x202b4 | 0x1fb |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateCompatibleDC | 0x0 | 0x41e000 | 0x21ac4 | 0x200c4 | 0x2e |
PlayEnhMetaFile | 0x0 | 0x41e004 | 0x21ac8 | 0x200c8 | 0x230 |
ScaleViewportExtEx | 0x0 | 0x41e008 | 0x21acc | 0x200cc | 0x258 |
SetStretchBltMode | 0x0 | 0x41e00c | 0x21ad0 | 0x200d0 | 0x289 |
SetPixelV | 0x0 | 0x41e010 | 0x21ad4 | 0x200d4 | 0x284 |
CreateDiscardableBitmap | 0x0 | 0x41e014 | 0x21ad8 | 0x200d8 | 0x35 |
AddFontResourceW | 0x0 | 0x41e018 | 0x21adc | 0x200dc | 0x7 |
SetDeviceGammaRamp | 0x0 | 0x41e01c | 0x21ae0 | 0x200e0 | 0x271 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExtractAssociatedIconA | 0x0 | 0x41e1b0 | 0x21c74 | 0x20274 | 0x24 |
ShellExecuteW | 0x0 | 0x41e1b4 | 0x21c78 | 0x20278 | 0x118 |
ShellAboutW | 0x0 | 0x41e1b8 | 0x21c7c | 0x2027c | 0x110 |
DragQueryFileA | 0x0 | 0x41e1bc | 0x21c80 | 0x20280 | 0x1e |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
updatewin2.exe | 7 | 0x00400000 | 0x0044CFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
updatewin2.exe | 7 | 0x00400000 | 0x0044CFFF | Content Changed | - | 32-bit | 0x00402350 |
![]() |
![]() |
...
|
updatewin2.exe | 7 | 0x00400000 | 0x0044CFFF | Content Changed | - | 32-bit | 0x0040D7C3 |
![]() |
![]() |
...
|
updatewin2.exe | 7 | 0x00400000 | 0x0044CFFF | Content Changed | - | 32-bit | 0x00401730 |
![]() |
![]() |
...
|
updatewin2.exe | 7 | 0x00400000 | 0x0044CFFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
Threat Name | Severity |
---|---|
Trojan.AgentWDCR.SVC |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\4883c25a-c55c-46aa-a0b1-c2c0b01a64fc\updatewin.exe | Downloaded File | Binary |
Malicious
|
...
|
Severity |
Blacklisted
|
First Seen | 2019-01-16 22:21 (UTC+1) |
Last Seen | 2019-09-04 09:39 (UTC+2) |
Names | Win32.Trojan.Kryptik |
Families | Kryptik |
Classification | Trojan |
Image Base | 0x400000 |
Entry Point | 0x402d7c |
Size Of Code | 0x1c200 |
Size Of Initialized Data | 0x2d400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-02-19 08:26:47+00:00 |
FileVersion | 8.8.10.11 |
InternalName | sutazaxidi.exe |
LegalCopyright | Copyright (C) 2018, huxonulow |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1c09e | 0x1c200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x41e000 | 0x4636 | 0x4800 | 0x1c600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.25 |
.data | 0x423000 | 0x1d5a8 | 0x18400 | 0x20e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.8 |
.rsrc | 0x441000 | 0xa826 | 0xaa00 | 0x39200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.84 |
.reloc | 0x44c000 | 0x1974 | 0x1a00 | 0x43c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.34 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitThread | 0x0 | 0x41e020 | 0x21af4 | 0x200f4 | 0x105 |
GetStartupInfoW | 0x0 | 0x41e024 | 0x21af8 | 0x200f8 | 0x23a |
GetConsoleAliasesW | 0x0 | 0x41e028 | 0x21afc | 0x200fc | 0x182 |
GetLastError | 0x0 | 0x41e02c | 0x21b00 | 0x20100 | 0x1e6 |
GetProcAddress | 0x0 | 0x41e030 | 0x21b04 | 0x20104 | 0x220 |
BackupWrite | 0x0 | 0x41e034 | 0x21b08 | 0x20108 | 0x18 |
GlobalFree | 0x0 | 0x41e038 | 0x21b0c | 0x2010c | 0x28c |
LoadLibraryA | 0x0 | 0x41e03c | 0x21b10 | 0x20110 | 0x2f1 |
GetNumberFormatW | 0x0 | 0x41e040 | 0x21b14 | 0x20114 | 0x20f |
AddAtomA | 0x0 | 0x41e044 | 0x21b18 | 0x20118 | 0x3 |
FindFirstChangeNotificationA | 0x0 | 0x41e048 | 0x21b1c | 0x2011c | 0x11b |
GetStringTypeW | 0x0 | 0x41e04c | 0x21b20 | 0x20120 | 0x240 |
VirtualProtect | 0x0 | 0x41e050 | 0x21b24 | 0x20124 | 0x45a |
GetACP | 0x0 | 0x41e054 | 0x21b28 | 0x20128 | 0x152 |
SetProcessShutdownParameters | 0x0 | 0x41e058 | 0x21b2c | 0x2012c | 0x3f9 |
CompareStringW | 0x0 | 0x41e05c | 0x21b30 | 0x20130 | 0x55 |
CompareStringA | 0x0 | 0x41e060 | 0x21b34 | 0x20134 | 0x52 |
CreateFileA | 0x0 | 0x41e064 | 0x21b38 | 0x20138 | 0x78 |
GetTimeZoneInformation | 0x0 | 0x41e068 | 0x21b3c | 0x2013c | 0x26b |
WriteConsoleW | 0x0 | 0x41e06c | 0x21b40 | 0x20140 | 0x48c |
GetConsoleOutputCP | 0x0 | 0x41e070 | 0x21b44 | 0x20144 | 0x199 |
WriteConsoleA | 0x0 | 0x41e074 | 0x21b48 | 0x20148 | 0x482 |
CloseHandle | 0x0 | 0x41e078 | 0x21b4c | 0x2014c | 0x43 |
IsValidLocale | 0x0 | 0x41e07c | 0x21b50 | 0x20150 | 0x2dd |
EnumSystemLocalesA | 0x0 | 0x41e080 | 0x21b54 | 0x20154 | 0xf8 |
GetUserDefaultLCID | 0x0 | 0x41e084 | 0x21b58 | 0x20158 | 0x26d |
GetDateFormatA | 0x0 | 0x41e088 | 0x21b5c | 0x2015c | 0x1ae |
GetSystemTimes | 0x0 | 0x41e08c | 0x21b60 | 0x20160 | 0x250 |
GetTickCount | 0x0 | 0x41e090 | 0x21b64 | 0x20164 | 0x266 |
FreeEnvironmentStringsA | 0x0 | 0x41e094 | 0x21b68 | 0x20168 | 0x14a |
GetComputerNameW | 0x0 | 0x41e098 | 0x21b6c | 0x2016c | 0x178 |
FindCloseChangeNotification | 0x0 | 0x41e09c | 0x21b70 | 0x20170 | 0x11a |
FindResourceExW | 0x0 | 0x41e0a0 | 0x21b74 | 0x20174 | 0x138 |
GetCurrentDirectoryA | 0x0 | 0x41e0a4 | 0x21b78 | 0x20178 | 0x1a7 |
GetCPInfo | 0x0 | 0x41e0a8 | 0x21b7c | 0x2017c | 0x15b |
GetTimeFormatA | 0x0 | 0x41e0ac | 0x21b80 | 0x20180 | 0x268 |
GetStringTypeA | 0x0 | 0x41e0b0 | 0x21b84 | 0x20184 | 0x23d |
LCMapStringW | 0x0 | 0x41e0b4 | 0x21b88 | 0x20188 | 0x2e3 |
LCMapStringA | 0x0 | 0x41e0b8 | 0x21b8c | 0x2018c | 0x2e1 |
GetLocaleInfoA | 0x0 | 0x41e0bc | 0x21b90 | 0x20190 | 0x1e8 |
GetLocaleInfoW | 0x0 | 0x41e0c0 | 0x21b94 | 0x20194 | 0x1ea |
SetStdHandle | 0x0 | 0x41e0c4 | 0x21b98 | 0x20198 | 0x3fc |
SetFilePointer | 0x0 | 0x41e0c8 | 0x21b9c | 0x2019c | 0x3df |
GetCommandLineA | 0x0 | 0x41e0cc | 0x21ba0 | 0x201a0 | 0x16f |
GetStartupInfoA | 0x0 | 0x41e0d0 | 0x21ba4 | 0x201a4 | 0x239 |
RaiseException | 0x0 | 0x41e0d4 | 0x21ba8 | 0x201a8 | 0x35a |
RtlUnwind | 0x0 | 0x41e0d8 | 0x21bac | 0x201ac | 0x392 |
TerminateProcess | 0x0 | 0x41e0dc | 0x21bb0 | 0x201b0 | 0x42d |
GetCurrentProcess | 0x0 | 0x41e0e0 | 0x21bb4 | 0x201b4 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x41e0e4 | 0x21bb8 | 0x201b8 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x41e0e8 | 0x21bbc | 0x201bc | 0x415 |
IsDebuggerPresent | 0x0 | 0x41e0ec | 0x21bc0 | 0x201c0 | 0x2d1 |
HeapAlloc | 0x0 | 0x41e0f0 | 0x21bc4 | 0x201c4 | 0x29d |
HeapFree | 0x0 | 0x41e0f4 | 0x21bc8 | 0x201c8 | 0x2a1 |
EnterCriticalSection | 0x0 | 0x41e0f8 | 0x21bcc | 0x201cc | 0xd9 |
LeaveCriticalSection | 0x0 | 0x41e0fc | 0x21bd0 | 0x201d0 | 0x2ef |
SetHandleCount | 0x0 | 0x41e100 | 0x21bd4 | 0x201d4 | 0x3e8 |
GetStdHandle | 0x0 | 0x41e104 | 0x21bd8 | 0x201d8 | 0x23b |
GetFileType | 0x0 | 0x41e108 | 0x21bdc | 0x201dc | 0x1d7 |
DeleteCriticalSection | 0x0 | 0x41e10c | 0x21be0 | 0x201e0 | 0xbe |
GetModuleHandleW | 0x0 | 0x41e110 | 0x21be4 | 0x201e4 | 0x1f9 |
Sleep | 0x0 | 0x41e114 | 0x21be8 | 0x201e8 | 0x421 |
ExitProcess | 0x0 | 0x41e118 | 0x21bec | 0x201ec | 0x104 |
WriteFile | 0x0 | 0x41e11c | 0x21bf0 | 0x201f0 | 0x48d |
GetModuleFileNameA | 0x0 | 0x41e120 | 0x21bf4 | 0x201f4 | 0x1f4 |
GetEnvironmentStrings | 0x0 | 0x41e124 | 0x21bf8 | 0x201f8 | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x41e128 | 0x21bfc | 0x201fc | 0x14b |
WideCharToMultiByte | 0x0 | 0x41e12c | 0x21c00 | 0x20200 | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x41e130 | 0x21c04 | 0x20204 | 0x1c1 |
TlsGetValue | 0x0 | 0x41e134 | 0x21c08 | 0x20208 | 0x434 |
TlsAlloc | 0x0 | 0x41e138 | 0x21c0c | 0x2020c | 0x432 |
TlsSetValue | 0x0 | 0x41e13c | 0x21c10 | 0x20210 | 0x435 |
TlsFree | 0x0 | 0x41e140 | 0x21c14 | 0x20214 | 0x433 |
InterlockedIncrement | 0x0 | 0x41e144 | 0x21c18 | 0x20218 | 0x2c0 |
SetLastError | 0x0 | 0x41e148 | 0x21c1c | 0x2021c | 0x3ec |
GetCurrentThreadId | 0x0 | 0x41e14c | 0x21c20 | 0x20220 | 0x1ad |
InterlockedDecrement | 0x0 | 0x41e150 | 0x21c24 | 0x20224 | 0x2bc |
GetCurrentThread | 0x0 | 0x41e154 | 0x21c28 | 0x20228 | 0x1ac |
HeapCreate | 0x0 | 0x41e158 | 0x21c2c | 0x2022c | 0x29f |
HeapDestroy | 0x0 | 0x41e15c | 0x21c30 | 0x20230 | 0x2a0 |
VirtualFree | 0x0 | 0x41e160 | 0x21c34 | 0x20234 | 0x457 |
QueryPerformanceCounter | 0x0 | 0x41e164 | 0x21c38 | 0x20238 | 0x354 |
GetCurrentProcessId | 0x0 | 0x41e168 | 0x21c3c | 0x2023c | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x41e16c | 0x21c40 | 0x20240 | 0x24f |
FatalAppExitA | 0x0 | 0x41e170 | 0x21c44 | 0x20244 | 0x10b |
VirtualAlloc | 0x0 | 0x41e174 | 0x21c48 | 0x20248 | 0x454 |
HeapReAlloc | 0x0 | 0x41e178 | 0x21c4c | 0x2024c | 0x2a4 |
MultiByteToWideChar | 0x0 | 0x41e17c | 0x21c50 | 0x20250 | 0x31a |
ReadFile | 0x0 | 0x41e180 | 0x21c54 | 0x20254 | 0x368 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41e184 | 0x21c58 | 0x20258 | 0x2b5 |
HeapSize | 0x0 | 0x41e188 | 0x21c5c | 0x2025c | 0x2a6 |
SetConsoleCtrlHandler | 0x0 | 0x41e18c | 0x21c60 | 0x20260 | 0x3a7 |
FreeLibrary | 0x0 | 0x41e190 | 0x21c64 | 0x20264 | 0x14c |
InterlockedExchange | 0x0 | 0x41e194 | 0x21c68 | 0x20268 | 0x2bd |
GetOEMCP | 0x0 | 0x41e198 | 0x21c6c | 0x2026c | 0x213 |
IsValidCodePage | 0x0 | 0x41e19c | 0x21c70 | 0x20270 | 0x2db |
GetConsoleCP | 0x0 | 0x41e1a0 | 0x21c74 | 0x20274 | 0x183 |
GetConsoleMode | 0x0 | 0x41e1a4 | 0x21c78 | 0x20278 | 0x195 |
FlushFileBuffers | 0x0 | 0x41e1a8 | 0x21c7c | 0x2027c | 0x141 |
SetEnvironmentVariableA | 0x0 | 0x41e1ac | 0x21c80 | 0x20280 | 0x3d0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseClipboard | 0x0 | 0x41e1d4 | 0x21ca8 | 0x202a8 | 0x47 |
SendNotifyMessageA | 0x0 | 0x41e1d8 | 0x21cac | 0x202ac | 0x264 |
BeginPaint | 0x0 | 0x41e1dc | 0x21cb0 | 0x202b0 | 0xe |
CallMsgFilterW | 0x0 | 0x41e1e0 | 0x21cb4 | 0x202b4 | 0x1a |
PeekMessageA | 0x0 | 0x41e1e4 | 0x21cb8 | 0x202b8 | 0x21b |
MapVirtualKeyExW | 0x0 | 0x41e1e8 | 0x21cbc | 0x202bc | 0x1f1 |
RegisterRawInputDevices | 0x0 | 0x41e1ec | 0x21cc0 | 0x202c0 | 0x242 |
GetClipboardSequenceNumber | 0x0 | 0x41e1f0 | 0x21cc4 | 0x202c4 | 0x113 |
SetUserObjectInformationA | 0x0 | 0x41e1f4 | 0x21cc8 | 0x202c8 | 0x29f |
GetDialogBaseUnits | 0x0 | 0x41e1f8 | 0x21ccc | 0x202cc | 0x11d |
GetMessageW | 0x0 | 0x41e1fc | 0x21cd0 | 0x202d0 | 0x14e |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreatePolyPolygonRgn | 0x0 | 0x41e000 | 0x21ad4 | 0x200d4 | 0x4b |
CreateCompatibleDC | 0x0 | 0x41e004 | 0x21ad8 | 0x200d8 | 0x2e |
SetStretchBltMode | 0x0 | 0x41e008 | 0x21adc | 0x200dc | 0x289 |
SetPixelV | 0x0 | 0x41e00c | 0x21ae0 | 0x200e0 | 0x284 |
GetCharWidth32A | 0x0 | 0x41e010 | 0x21ae4 | 0x200e4 | 0x1a0 |
CreateDiscardableBitmap | 0x0 | 0x41e014 | 0x21ae8 | 0x200e8 | 0x35 |
BitBlt | 0x0 | 0x41e018 | 0x21aec | 0x200ec | 0x12 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x41e1b4 | 0x21c88 | 0x20288 | 0x118 |
ShellAboutW | 0x0 | 0x41e1b8 | 0x21c8c | 0x2028c | 0x110 |
ExtractIconA | 0x0 | 0x41e1bc | 0x21c90 | 0x20290 | 0x28 |
ShellExecuteExA | 0x0 | 0x41e1c0 | 0x21c94 | 0x20294 | 0x116 |
FindExecutableA | 0x0 | 0x41e1c4 | 0x21c98 | 0x20298 | 0x2d |
DragQueryFileA | 0x0 | 0x41e1c8 | 0x21c9c | 0x2029c | 0x1e |
ExtractIconW | 0x0 | 0x41e1cc | 0x21ca0 | 0x202a0 | 0x2c |
Threat Name | Severity |
---|---|
Trojan.AgentWDCR.SUF |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\4883c25a-c55c-46aa-a0b1-c2c0b01a64fc\5.exe | Downloaded File | Binary |
Malicious
|
...
|
Severity |
Blacklisted
|
First Seen | 2019-11-06 09:22 (UTC+1) |
Last Seen | 2019-11-07 13:23 (UTC+1) |
Names | Win32.Trojan.Kryptik |
Families | Kryptik |
Classification | Trojan |
Image Base | 0x400000 |
Entry Point | 0x402bf3 |
Size Of Code | 0xf000 |
Size Of Initialized Data | 0x158600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-03-10 23:02:25+00:00 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xef5a | 0xf000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.75 |
.rdata | 0x410000 | 0x5d354 | 0x5d400 | 0xf400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.94 |
.data | 0x46e000 | 0xf0100 | 0x5400 | 0x6c800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.12 |
.rsrc | 0x55f000 | 0xa9f8 | 0xaa00 | 0x71c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.13 |
.reloc | 0x56a000 | 0x124c | 0x1400 | 0x7c600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.27 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetFilePointer | 0x0 | 0x410008 | 0x6cb74 | 0x6bf74 | 0x466 |
WaitNamedPipeA | 0x0 | 0x41000c | 0x6cb78 | 0x6bf78 | 0x4ff |
GetCurrentActCtx | 0x0 | 0x410010 | 0x6cb7c | 0x6bf7c | 0x1bb |
SetHandleInformation | 0x0 | 0x410014 | 0x6cb80 | 0x6bf80 | 0x470 |
GetConsoleTitleA | 0x0 | 0x410018 | 0x6cb84 | 0x6bf84 | 0x1b5 |
FindActCtxSectionStringA | 0x0 | 0x41001c | 0x6cb88 | 0x6bf88 | 0x12a |
GetSystemWindowsDirectoryA | 0x0 | 0x410020 | 0x6cb8c | 0x6bf8c | 0x27b |
SetConsoleCP | 0x0 | 0x410024 | 0x6cb90 | 0x6bf90 | 0x42c |
GetFileAttributesW | 0x0 | 0x410028 | 0x6cb94 | 0x6bf94 | 0x1ea |
ReadFile | 0x0 | 0x41002c | 0x6cb98 | 0x6bf98 | 0x3c0 |
GetModuleFileNameW | 0x0 | 0x410030 | 0x6cb9c | 0x6bf9c | 0x214 |
lstrlenW | 0x0 | 0x410034 | 0x6cba0 | 0x6bfa0 | 0x54e |
VerifyVersionInfoW | 0x0 | 0x410038 | 0x6cba4 | 0x6bfa4 | 0x4e8 |
SetDefaultCommConfigA | 0x0 | 0x41003c | 0x6cba8 | 0x6bfa8 | 0x44e |
SetLastError | 0x0 | 0x410040 | 0x6cbac | 0x6bfac | 0x473 |
GetProcAddress | 0x0 | 0x410044 | 0x6cbb0 | 0x6bfb0 | 0x245 |
GetTapeStatus | 0x0 | 0x410048 | 0x6cbb4 | 0x6bfb4 | 0x281 |
VerLanguageNameA | 0x0 | 0x41004c | 0x6cbb8 | 0x6bfb8 | 0x4e2 |
LoadLibraryA | 0x0 | 0x410050 | 0x6cbbc | 0x6bfbc | 0x33c |
WriteConsoleA | 0x0 | 0x410054 | 0x6cbc0 | 0x6bfc0 | 0x51a |
LocalAlloc | 0x0 | 0x410058 | 0x6cbc4 | 0x6bfc4 | 0x344 |
GetNumberFormatW | 0x0 | 0x41005c | 0x6cbc8 | 0x6bfc8 | 0x233 |
GetOEMCP | 0x0 | 0x410060 | 0x6cbcc | 0x6bfcc | 0x237 |
HeapSetInformation | 0x0 | 0x410064 | 0x6cbd0 | 0x6bfd0 | 0x2d3 |
CreateMutexA | 0x0 | 0x410068 | 0x6cbd4 | 0x6bfd4 | 0x9b |
GetStringTypeW | 0x0 | 0x41006c | 0x6cbd8 | 0x6bfd8 | 0x269 |
GetPrivateProfileSectionW | 0x0 | 0x410070 | 0x6cbdc | 0x6bfdc | 0x240 |
LCMapStringW | 0x0 | 0x410074 | 0x6cbe0 | 0x6bfe0 | 0x32d |
DeleteFileA | 0x0 | 0x410078 | 0x6cbe4 | 0x6bfe4 | 0xd3 |
lstrcpyA | 0x0 | 0x41007c | 0x6cbe8 | 0x6bfe8 | 0x547 |
WriteConsoleW | 0x0 | 0x410080 | 0x6cbec | 0x6bfec | 0x524 |
OutputDebugStringW | 0x0 | 0x410084 | 0x6cbf0 | 0x6bff0 | 0x38a |
EncodePointer | 0x0 | 0x410088 | 0x6cbf4 | 0x6bff4 | 0xea |
DecodePointer | 0x0 | 0x41008c | 0x6cbf8 | 0x6bff8 | 0xca |
GetLastError | 0x0 | 0x410090 | 0x6cbfc | 0x6bffc | 0x202 |
HeapReAlloc | 0x0 | 0x410094 | 0x6cc00 | 0x6c000 | 0x2d2 |
GetCommandLineA | 0x0 | 0x410098 | 0x6cc04 | 0x6c004 | 0x186 |
RaiseException | 0x0 | 0x41009c | 0x6cc08 | 0x6c008 | 0x3b1 |
RtlUnwind | 0x0 | 0x4100a0 | 0x6cc0c | 0x6c00c | 0x418 |
IsProcessorFeaturePresent | 0x0 | 0x4100a4 | 0x6cc10 | 0x6c010 | 0x304 |
ExitProcess | 0x0 | 0x4100a8 | 0x6cc14 | 0x6c014 | 0x119 |
GetModuleHandleExW | 0x0 | 0x4100ac | 0x6cc18 | 0x6c018 | 0x217 |
MultiByteToWideChar | 0x0 | 0x4100b0 | 0x6cc1c | 0x6c01c | 0x367 |
WideCharToMultiByte | 0x0 | 0x4100b4 | 0x6cc20 | 0x6c020 | 0x511 |
HeapSize | 0x0 | 0x4100b8 | 0x6cc24 | 0x6c024 | 0x2d4 |
HeapFree | 0x0 | 0x4100bc | 0x6cc28 | 0x6c028 | 0x2cf |
IsDebuggerPresent | 0x0 | 0x4100c0 | 0x6cc2c | 0x6c02c | 0x300 |
EnterCriticalSection | 0x0 | 0x4100c4 | 0x6cc30 | 0x6c030 | 0xee |
LeaveCriticalSection | 0x0 | 0x4100c8 | 0x6cc34 | 0x6c034 | 0x339 |
SetFilePointerEx | 0x0 | 0x4100cc | 0x6cc38 | 0x6c038 | 0x467 |
GetConsoleMode | 0x0 | 0x4100d0 | 0x6cc3c | 0x6c03c | 0x1ac |
GetStdHandle | 0x0 | 0x4100d4 | 0x6cc40 | 0x6c040 | 0x264 |
GetFileType | 0x0 | 0x4100d8 | 0x6cc44 | 0x6c044 | 0x1f3 |
DeleteCriticalSection | 0x0 | 0x4100dc | 0x6cc48 | 0x6c048 | 0xd1 |
GetStartupInfoW | 0x0 | 0x4100e0 | 0x6cc4c | 0x6c04c | 0x263 |
GetCurrentThreadId | 0x0 | 0x4100e4 | 0x6cc50 | 0x6c050 | 0x1c5 |
HeapAlloc | 0x0 | 0x4100e8 | 0x6cc54 | 0x6c054 | 0x2cb |
GetProcessHeap | 0x0 | 0x4100ec | 0x6cc58 | 0x6c058 | 0x24a |
CloseHandle | 0x0 | 0x4100f0 | 0x6cc5c | 0x6c05c | 0x52 |
GetModuleFileNameA | 0x0 | 0x4100f4 | 0x6cc60 | 0x6c060 | 0x213 |
WriteFile | 0x0 | 0x4100f8 | 0x6cc64 | 0x6c064 | 0x525 |
QueryPerformanceCounter | 0x0 | 0x4100fc | 0x6cc68 | 0x6c068 | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x410100 | 0x6cc6c | 0x6c06c | 0x1c1 |
GetSystemTimeAsFileTime | 0x0 | 0x410104 | 0x6cc70 | 0x6c070 | 0x279 |
GetEnvironmentStringsW | 0x0 | 0x410108 | 0x6cc74 | 0x6c074 | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x41010c | 0x6cc78 | 0x6c078 | 0x161 |
UnhandledExceptionFilter | 0x0 | 0x410110 | 0x6cc7c | 0x6c07c | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x410114 | 0x6cc80 | 0x6c080 | 0x4a5 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x410118 | 0x6cc84 | 0x6c084 | 0x2e3 |
Sleep | 0x0 | 0x41011c | 0x6cc88 | 0x6c088 | 0x4b2 |
GetCurrentProcess | 0x0 | 0x410120 | 0x6cc8c | 0x6c08c | 0x1c0 |
TerminateProcess | 0x0 | 0x410124 | 0x6cc90 | 0x6c090 | 0x4c0 |
TlsAlloc | 0x0 | 0x410128 | 0x6cc94 | 0x6c094 | 0x4c5 |
TlsGetValue | 0x0 | 0x41012c | 0x6cc98 | 0x6c098 | 0x4c7 |
TlsSetValue | 0x0 | 0x410130 | 0x6cc9c | 0x6c09c | 0x4c8 |
TlsFree | 0x0 | 0x410134 | 0x6cca0 | 0x6c0a0 | 0x4c6 |
GetModuleHandleW | 0x0 | 0x410138 | 0x6cca4 | 0x6c0a4 | 0x218 |
LoadLibraryExW | 0x0 | 0x41013c | 0x6cca8 | 0x6c0a8 | 0x33e |
IsValidCodePage | 0x0 | 0x410140 | 0x6ccac | 0x6c0ac | 0x30a |
GetACP | 0x0 | 0x410144 | 0x6ccb0 | 0x6c0b0 | 0x168 |
GetCPInfo | 0x0 | 0x410148 | 0x6ccb4 | 0x6c0b4 | 0x172 |
SetStdHandle | 0x0 | 0x41014c | 0x6ccb8 | 0x6c0b8 | 0x487 |
FlushFileBuffers | 0x0 | 0x410150 | 0x6ccbc | 0x6c0bc | 0x157 |
GetConsoleCP | 0x0 | 0x410154 | 0x6ccc0 | 0x6c0c0 | 0x19a |
CreateFileW | 0x0 | 0x410158 | 0x6ccc4 | 0x6c0c4 | 0x8f |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCaretPos | 0x0 | 0x410160 | 0x6cccc | 0x6c0cc | 0x10a |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DeregisterEventSource | 0x0 | 0x410000 | 0x6cb6c | 0x6bf6c | 0xdb |
Api name | EAT Address | Ordinal |
---|---|---|
@MyFunc124@4 | 0xfef0 | 0x1 |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
5.exe | 10 | 0x00400000 | 0x0056BFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 10 | 0x002B4008 | 0x0030ABAF | Marked Executable | - | 32-bit | 0x002B4008 |
![]() |
![]() |
...
|
buffer | 10 | 0x01D10000 | 0x01D9AFFF | First Execution | - | 32-bit | 0x01D10000 |
![]() |
![]() |
...
|
5.exe | 10 | 0x00400000 | 0x0056BFFF | Content Changed | - | 32-bit | 0x0045CC8A |
![]() |
![]() |
...
|
5.exe | 10 | 0x00400000 | 0x0056BFFF | Content Changed | - | 32-bit | 0x0045FC10 |
![]() |
![]() |
...
|
5.exe | 10 | 0x00400000 | 0x0056BFFF | Content Changed | - | 32-bit | 0x004053DE |
![]() |
![]() |
...
|
5.exe | 10 | 0x00400000 | 0x0056BFFF | Content Changed | - | 32-bit | 0x0045195F |
![]() |
![]() |
...
|
Threat Name | Severity |
---|---|
Trojan.GenericKD.32686115 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\1jqP 8uN4qhj8sMm4.flv | Modified File | Video |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\1zXBPnB.gif.lokf | Dropped File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\5VDyYw1.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\60uV9dxrIvRWJYpX2.pps | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\8Ky0ltRrnhjM32N.png.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\8XYY enP9O0YVVimx1.mp3.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9Md r.swf | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9REu6C.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\aRT3ou.jpg | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\bSgKDO2SM-AQU.mp3.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\cxkxIuDq.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\FhecmqmUmuGofO.jpg | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\FqC7oKr9X-T-xlLzFbdd.jpg | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\h5XCQ.mkv | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\jJW2khyR pNShGfzK.flv | Modified File | Video |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NPYvWKI6z.rtf.lokf | Dropped File | Text |
Unknown
|
...
|
@EWYIzsps^I8JaR^pXg;^+'Ҳ!0o]܋wF%cao3]g#rMd?жG>M;^u_5m-ns`6>۰2iWd߲xǑ*6Aos_&C[<5͐èeC&!XL~;!d鹌 tTqA;s$YX/p;7Kxѻ.̢&"5>xK䎖О'a 5N04Kg[6ZyUSuT%QBS5CXEdQϾH+յ@+ W 艝)wym"J2n:12eV?ƉqIjRnDǭ]Ԓhgec3o;c=ʺK8B̬3pMRpeE&raZaJ*H3<<yAPoJSrƫ_CiLp^/(Fծl_fKS8%ȷNJGJ3JG. b@!$_fD/3f/rbvP?I'%&Oat˻dMY͇ow(ia2AύD2Ζ,S؎0T;d֕?[UY%8b%oWòLPJ_:9qFԿ1O%3N[sĮҗT]ܛ&cdſ;?0Gם;?paK=kOU>ΰzO"7P'PHNko5(<6b"?D)nQؑ[Ң>u"(o-wiM%Gͽ;6D*@5-*3jQvwleW+6j?yFzav+3B<6o+x<u27?+?d]j*SLQ:cp'GW Js]#6lBw78CKzhғ%ϸ+&n1쐱晙SV!D(EMlH67|$"Eh$u^Tiwjɿw=#.1f99P#F|V)h֕h$kx SӋXMȦ<bN72'J;K;4C7UU=t>h9t[yr9hnH/^>9Gӈ)JS/@<^KpI<S;dlvW[6R,Ҳ&jnsyYꘁe,><WR<|7QE Ն[Ns5%5D)t~Գ:vp.K1PSb[qO!1fb T!Ӣ[hg;F5@7,'w`hn'b3A0:>oi;p D+áe-hxwCj,ꈈTp5_⑶~BQU!'A#e/X1#))yn4M37(tz!^%Z]' љT&:DC|fڶlIk=FGѾ/<qG.A탗k0Sj~j8n!.v^adT>,'=3~#2l'M&X~|$SZzH4M,9pe$@N$1C%k(:?L ... |
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\oQo1_q.jpg.lokf | Dropped File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\PxUe0Rd33Z0Hx10IeT1.avi.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\P_559lEWKFJGdNawoW.jpg.lokf | Dropped File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\QXU6sWcq.flv.lokf | Dropped File | Video |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\SbEH25_9Y82gEZUNcsj.flv.lokf | Dropped File | Video |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\vXRE_K.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\xJT0OcisPj-xq.jpg | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\xrWMPRPigWwu3vXxOU1.wav.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZoOnp.swf.lokf | Dropped File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZyTEBApAQsy0 u.jpg.lokf | Dropped File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\_FKxFEiW.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\44yienfP0_mk.docx | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\4QdlKGracmIsfBv8Rj5U.xlsx.lokf | Dropped File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ahBvw6Tj3LoXOmjTDa.pptx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fyZw8q.pptx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\iY-CcZnqhK2oNX.xlsx.lokf | Dropped File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jcZ5HOv.docx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\lJq7q-PX9DWbR8t8z.doc.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\SfzjItAk.ots.lokf | Dropped File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\uvaDFzE.docx.lokf | Dropped File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\vShBQE5akxJRPT.pptx.lokf | Dropped File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Xe72pRvBTnt.docx | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\cwxc45T02ajINP1wUK.wav | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\klr3tCyH3.wav | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\3iuJ8NWM9DLs-PEj.bmp.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\6othUkm8ekP4Ec7T.gif.lokf | Dropped File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\80aZ2tp21.gif | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\B DJ6bHqinsD9h4.bmp.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\EOWcS-b-pHU1wro7.jpg.lokf | Dropped File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\G4kJhdDGPq3zd 8N.png.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\H4Ti7A LHpB.png.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\IIQQGpJ.gif | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\lY0DCvr2.bmp.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\RIK1-BUGPQEVJirKz6N.jpg | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\rZNT8ree-9bG.bmp.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\V8xM.jpg | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Y_Dz9ypir.gif.lokf | Dropped File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\-UhIDPZCm6I2UoJXWw.mkv | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\8MMWzVzn.mp4 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9P25HE-ZzsQt.mkv | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\GIpLP30n0FbK.mkv.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\XBdxFZI.swf | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NxkfKpMd\-Ymy8S 8yhOe9ZasNJRs.flv.lokf | Dropped File | Video |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NxkfKpMd\2qd8JzHjkGInT4Dq.png | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NxkfKpMd\F0_0MMpq eXwaNPyOb.png.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\R4I1Q ij0VYYLZ2qE\TTeO3-kFVQDhs.ppt | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\R4I1Q ij0VYYLZ2qE\VzHk HXQOnf5.odp | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xw_W- RtiM1Q0r\ERvgLja.ots.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xw_W- RtiM1Q0r\qsrLr5Sl.csv.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xw_W- RtiM1Q0r\wdJqAyQOW.ots.lokf | Dropped File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Web Slice Gallery.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE site on Microsoft.com.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Home.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Work.url.lokf | Dropped File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Entertainment.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Money.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Sports.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSNBC News.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Get Windows Live.url.lokf | Dropped File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Gallery.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Mail.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Spaces.url | Modified File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\eIv9rDB\2RGMtQTERV.mp3.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\eIv9rDB\ohsb8tUwwTI.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\2frIwLIsuulHRSHkT.wav | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\2u2pj-4.mp3.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\OAddPqhDn.mp3.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\zoG7hAdVK.wav.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Pt3T5YLjsfWTS8bTn\af7fMK0 C.gif | Modified File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Pt3T5YLjsfWTS8bTn\f0kq4mu0SkEws8GQakO.gif.lokf | Dropped File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Pt3T5YLjsfWTS8bTn\RqbMGhYZcZtImp-D.bmp | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Pt3T5YLjsfWTS8bTn\VO-3YD 39RUJPvDS.bmp.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Pt3T5YLjsfWTS8bTn\WY02osvbjefKkY2aG.bmp.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\2-PB.swf.lokf | Dropped File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\3gmurZa_KyIq0.mkv | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\3SncxiCXlF02Ky2.swf.lokf | Dropped File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\Gn4 UcsB.flv.lokf | Dropped File | Video |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\H85jqiLOTT6NBZY.swf.lokf | Dropped File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\HXLOhG.swf.lokf | Dropped File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\jYsvlZ\7_vc_tYF-W1fe3j1GZ.mp4 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\jYsvlZ\Ln9Eeh629DhOIJi1iM_F.mp4 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\jYsvlZ\qX3sjp a6u.flv.lokf | Dropped File | Video |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xw_W- RtiM1Q0r\mw2tK3t ch7R6yApjv\Pzfb-2YEs.pptx | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xw_W- RtiM1Q0r\mw2tK3t ch7R6yApjv\Q4CVm42sPsNlTUJg5b.csv.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xw_W- RtiM1Q0r\mw2tK3t ch7R6yApjv\Q6NKNt7D.xlsx.lokf | Dropped File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xw_W- RtiM1Q0r\pW62l8V1WmQv\7Bi8C_q4pStHzT.docx.lokf | Dropped File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xw_W- RtiM1Q0r\pW62l8V1WmQv\E8XcFurbwLsj.rtf.lokf | Dropped File | Text |
Unknown
|
...
|
gAk^GcI$86?Htqc509)'(xkT( YJz.`uy^j~0#V͋1n*3D_TSͯZt<JqzmIJީ~jenZI`5_ϢiurP"+O$(s7#7v~S8apĊ_FЫh HɸMJ=:8zN#9͓suO%5?ݦд: f7-<Y^spkBrWjy,/ g&@cVl+G$3uޅ츧U+ȒN66c68Z!NU23tcMVB~]B$տ5TBK:6Bd;Bv<"yY:.3Y8;c.%V|S|m._K$jæ@Is-%93̾(&y?;~>v/إ@<[gPٔƚ//4kA(Ś]YujD.+H%158OΉ~IjWlj<8p(HCnF՞ԏKRc~?8R(Ui.jr0D9lWrBXwD0GּxR$TEKl8sfϭx]uq74B|wGndwCoC<gC&G<.b#rP2Gx`l[I<vVuwbnǥb3wzǘ.b,Z%rkf.M!-RS?| JG/]ߞz$BԆKwAD;L#+_=WHޡw7ys?@UH&9[E)C;_ ޒpX P+kYmf!YLrnyVO賦<㑏+lb (ѣj(h?x-,Ҫ-&-ꄐ_^c`s8/O_bBI</.Rm&ODgxܼJT_.Aa+0<(Fd32pF.Oޅ3 G0Q9EwbS/14W$#f''1 EJҜﯡ Qt~B<Yy,ƵIHIujA#y8d*)2 M>Whakq H2_2Qֶ:,`~`쵹MDQr (:eʬdUp6]L![/AGt`kixM8ͯMZX07 J~TiIΔ +|K2tE<2JBPSuFG*T<4H:oD.rqvyƚ5hJ'~L։F0$e "~y/7s30mkɮzMO1^q]8BF*fQE7`vE%an'>Qf:"f`-ߒ4 (M5Kӯ͟Cq[lbQm'ãb>WN,0^pcd)*DﰢYʤUoՙ|#f*duahT6mJfEba^P+JɎr0]J4RAԧ^ZKl_-%V=P 1L6x#/*/EsW ... |
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xw_W- RtiM1Q0r\pW62l8V1WmQv\J45F bTMyBPSJH5EBiu.odt.lokf | Dropped File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xw_W- RtiM1Q0r\pW62l8V1WmQv\sj-YHyN9.pptx | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\eIv9rDB\-Y1PqBS8_MAyXOFE\iuj_U3uV2UvsBrXi.wav.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\eIv9rDB\-Y1PqBS8_MAyXOFE\k9qaL9eZD8xHKw.m4a.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\iCD5MmspTIMUES\1fE6ecc0BbC6tSRJo26.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\iCD5MmspTIMUES\lOMYgti3I.wav.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\iCD5MmspTIMUES\WQ3CvenEAYLHrobZJZN.wav | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\m Cm9nOn1JJtRb93m\0BW0y.mkv | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\m Cm9nOn1JJtRb93m\3ReWfL7YLyi_9fKl.swf | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\m Cm9nOn1JJtRb93m\4C47 OYV277RnlFF.avi.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\m Cm9nOn1JJtRb93m\r00ipKmOR8h.mkv.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\XeSTpd\HBgjb_CwGZsxIo486q.avi.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\XeSTpd\sTjbuO.swf.lokf | Dropped File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\XeSTpd\wEuF.swf.lokf | Dropped File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\XeSTpd\y2xQ-g5gOjeuQ_T_E.mp4 | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\iCD5MmspTIMUES\EakifiT9ecot40TbvQP\0rf9GWEzIubnTo8mKkZ.mp3.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\iCD5MmspTIMUES\EakifiT9ecot40TbvQP\5t8t.wav | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\iCD5MmspTIMUES\EakifiT9ecot40TbvQP\KnXQ3aRo433TX.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\iCD5MmspTIMUES\EakifiT9ecot40TbvQP\OGyk 6D.m4a.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\iCD5MmspTIMUES\EakifiT9ecot40TbvQP\OQFFt8mL.mp3.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\iCD5MmspTIMUES\EakifiT9ecot40TbvQP\sviI.wav | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\iCD5MmspTIMUES\EakifiT9ecot40TbvQP\y2sSLYuc0kUZqjX3V0a.wav.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\iCD5MmspTIMUES\JkVomBM7vh9EmuD_aJp\0WbfV oRFZMhu.mp3.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\iCD5MmspTIMUES\JkVomBM7vh9EmuD_aJp\sKttn2.m4a | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\iCD5MmspTIMUES\JkVomBM7vh9EmuD_aJp\t_BQoltGh0ocw10QeS.wav.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\iCD5MmspTIMUES\JkVomBM7vh9EmuD_aJp\WsOPu73F.wav.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\iCD5MmspTIMUES\ULJQyyPz2Ie5aZRk\2ZFt4M6QcsQkL8.wav | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\XeSTpd\hWmlgmybmvGq Gv\l-4D7O.mkv.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\XeSTpd\hWmlgmybmvGq Gv\olMX62ll.avi | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\XeSTpd\hWmlgmybmvGq Gv\qj8V72.mp4.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\XeSTpd\hWmlgmybmvGq Gv\QnhLHVtA0q.flv | Modified File | Video |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\XeSTpd\hWmlgmybmvGq Gv\R-9wIEAszo.mkv | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Adobe\Acrobat\10.0\rdrmessage.zip.lokf | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\index.dat | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.cab.lokf | Dropped File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.msi.lokf | Dropped File | Stream |
Unknown
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\x9ohk109\geo[1].json | Dropped File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\bowsakkdestx.txt | Downloaded File | Text |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\1Zw20eF9M7.mp4 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\4UyQPASLT.wav.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\6NumCnon.pps | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\faub8t.flv.lokf | Dropped File | Video |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\gRPeD.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\H 5zj6wBswdjjTMij-.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\I9YVy1.mp3.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\IiDoDihC33qoyQYC.avi.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MKAZ57ez4L.mp3.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\OvPRD3iWK.png.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\PYWZYi4ZS-zguXaIZa.m4a.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\RrXB-.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\SzTS.pps.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\U7Qf8.mp4.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\z_xjT1PbK9g5.mp3.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\-zw2kUwzHbrh6GhQEKb.pptx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\0LcY86kifJlQ7.xlsx.lokf | Dropped File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\aam-uk.xlsx.lokf | Dropped File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\dY6y1t7mu6jrMGEl.pptx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\e3Nt7XYdwW.docx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\jFhfFrSxF58Y6JuYP.pptx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\q_n6bOaeAdhkjfo2mhI.docx.lokf | Dropped File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\tfEuvyompjnimS.xlsx.lokf | Dropped File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\YHNtYWD7HeLx42k.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\02fNEn45dPvMPAwyDJ.bmp.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\2JD7dc-DViv9j UmdwX.bmp.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\9e3N7.bmp.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\b7pJttHK9Z.jpg.lokf | Dropped File | Image |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\eE0Pj7G5aEffKAC-zZKZ.jpg | Modified File | Image |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\hsPblQOgWlR.jpg | Modified File | Image |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\mjvWTIfK-ga.gif.lokf | Dropped File | Image |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\OkL4HKnkSYSJIwPNsR_.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\TSPFwFmW70A.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\urTk_7SAl.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\WX2M.gif.lokf | Dropped File | Image |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\otAFCyQ0nHxWrUo d.mkv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NxkfKpMd\gg9DmOuSzgeAHjPyg_oR.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NxkfKpMd\zI78.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\R4I1Q ij0VYYLZ2qE\97eCjaiIhB-aD14f.odt.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xw_W- RtiM1Q0r\1y8uVRiNT7yn.odp.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xw_W- RtiM1Q0r\nqPYpTIV1l.doc | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xw_W- RtiM1Q0r\tdc1X rXuBGflZJUC.xls.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Suggested Sites.url.lokf | Dropped File | Text |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE Add-on site.url.lokf | Dropped File | Text |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft Store.url | Modified File | Text |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Autos.url.lokf | Dropped File | Text |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\eIv9rDB\JzgoC0SQ.m4a.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\eIv9rDB\nKN_va3f4.mp3.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\eIv9rDB\w_gaxxrjB.wav.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\eIv9rDB\_o S4wHhVVehFDOD.m4a.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\DgdvfX7vLuA3.m4a.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Pt3T5YLjsfWTS8bTn\AjNKcaGLMrNbgB.gif.lokf | Dropped File | Image |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Pt3T5YLjsfWTS8bTn\li369zaQPHRBOjAeQzQZ.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Pt3T5YLjsfWTS8bTn\MJFA.gif | Modified File | Image |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Pt3T5YLjsfWTS8bTn\N3M3Ys.jpg | Modified File | Image |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Pt3T5YLjsfWTS8bTn\NrGoI7QxowPF0QY4.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Pt3T5YLjsfWTS8bTn\o1B17VGvl2Lz.jpg | Modified File | Image |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Pt3T5YLjsfWTS8bTn\xjvwDn0SBdqUu-KgqN.jpg.lokf | Dropped File | Image |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\5OM_K.avi.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\jYsvlZ\-zuaS3cxhRUqW6PZe3HQ.mp4 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\jYsvlZ\48nag.mkv.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\_private\folder.ico.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xw_W- RtiM1Q0r\mw2tK3t ch7R6yApjv\6P7rf5fA1SneQ8RjIP.ods | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xw_W- RtiM1Q0r\mw2tK3t ch7R6yApjv\7GGLnQdzt-Q9-.ots.lokf | Dropped File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xw_W- RtiM1Q0r\mw2tK3t ch7R6yApjv\FC-e.pptx.lokf | Dropped File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xw_W- RtiM1Q0r\pW62l8V1WmQv\K01vTC0.xlsx.lokf | Dropped File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xw_W- RtiM1Q0r\pW62l8V1WmQv\r8w4K7BjGpJr7cvfGvO.ots | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\eIv9rDB\-Y1PqBS8_MAyXOFE\X3njm42.mp3.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\eIv9rDB\-Y1PqBS8_MAyXOFE\yLAA3zbV.wav.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\iCD5MmspTIMUES\ApuXtGetFJ4Lr9.wav.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\iCD5MmspTIMUES\Z-23Z6qoTq8B67.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\m Cm9nOn1JJtRb93m\aBWJz5OOK2UC2wWbUb-K.flv | Modified File | Video |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\m Cm9nOn1JJtRb93m\UEUtG KZ03LCY HCeSa.mkv.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\m Cm9nOn1JJtRb93m\YGVwuDjMl2Ykk_YA8hkk.flv.lokf | Dropped File | Video |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\XeSTpd\xRy69j3Nzz.flv | Modified File | Video |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\iCD5MmspTIMUES\EakifiT9ecot40TbvQP\010DT.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\iCD5MmspTIMUES\EakifiT9ecot40TbvQP\JL4xlRSqNe-Wd jJpi9J.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\iCD5MmspTIMUES\ULJQyyPz2Ie5aZRk\gnUl.mp3.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\iCD5MmspTIMUES\ULJQyyPz2Ie5aZRk\jDMSBY8z.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m4--j\iCD5MmspTIMUES\ULJQyyPz2Ie5aZRk\OcnaPENNojmBU3Ny_1f.mp3.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\XeSTpd\hWmlgmybmvGq Gv\EjJOrnaIC80zrDKVf.mkv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\XeSTpd\hWmlgmybmvGq Gv\LVSDJY.avi.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\XeSTpd\hWmlgmybmvGq Gv\uGSi-5fGSlAWMRzpgA.mkv.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\XeSTpd\hWmlgmybmvGq Gv\VNkHkNF_CGKpIBona48.mkv.lokf | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\27nF\XeSTpd\hWmlgmybmvGq Gv\zezODkThIh8LWRpIgH.flv | Modified File | Video |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\script.ps1 | Dropped File | Text |
Not Queried
|
...
|