VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Dropper
|
Threat Names: |
Gen:Trojan.Heur.FU.huX@aaN@nEki
Gen:Variant.Mikey.114868
Mal/Generic-S
|
QDgotnX2VapbkvCb.exe
Windows Exe (x86-32)
Created at 2021-01-15T02:04:00
Remarks
(0x0200001E): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 Bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\QDgotnX2VapbkvCb.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x403348 |
Size Of Code | 0x6600 |
Size Of Initialized Data | 0x53000 |
Size Of Uninitialized Data | 0x400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-08-01 02:44:50+00:00 |
Version Information (8)
»
CompanyName | Tencent |
FileDescription | Gameloop - Install |
FileVersion | 11.0.16777.224 |
InternalName | GameDownload |
LegalCopyright | Copyright © 2017 Tencent. All Rights Reserved. |
OriginalFilename | GameDownload.exe |
ProductName | Gameloop |
ProductVersion | 11,0,16777,224 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x6457 | 0x6600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.43 |
.rdata | 0x408000 | 0x1380 | 0x1400 | 0x6a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.26 |
.data | 0x40a000 | 0x25538 | 0x600 | 0x7e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.13 |
.ndata | 0x430000 | 0x9000 | 0x0 | 0x0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x439000 | 0x2bf70 | 0x2c000 | 0x8400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.31 |
Imports (7)
»
ADVAPI32.dll (13)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegCreateKeyExA | 0x0 | 0x408000 | 0x85e4 | 0x6fe4 | 0x1d1 |
RegEnumKeyA | 0x0 | 0x408004 | 0x85e8 | 0x6fe8 | 0x1dd |
RegQueryValueExA | 0x0 | 0x408008 | 0x85ec | 0x6fec | 0x1f7 |
RegSetValueExA | 0x0 | 0x40800c | 0x85f0 | 0x6ff0 | 0x204 |
RegCloseKey | 0x0 | 0x408010 | 0x85f4 | 0x6ff4 | 0x1cb |
RegDeleteValueA | 0x0 | 0x408014 | 0x85f8 | 0x6ff8 | 0x1d8 |
RegDeleteKeyA | 0x0 | 0x408018 | 0x85fc | 0x6ffc | 0x1d4 |
AdjustTokenPrivileges | 0x0 | 0x40801c | 0x8600 | 0x7000 | 0x1c |
LookupPrivilegeValueA | 0x0 | 0x408020 | 0x8604 | 0x7004 | 0x14f |
OpenProcessToken | 0x0 | 0x408024 | 0x8608 | 0x7008 | 0x1ac |
SetFileSecurityA | 0x0 | 0x408028 | 0x860c | 0x700c | 0x22e |
RegOpenKeyExA | 0x0 | 0x40802c | 0x8610 | 0x7010 | 0x1ec |
RegEnumValueA | 0x0 | 0x408030 | 0x8614 | 0x7014 | 0x1e1 |
SHELL32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetFileInfoA | 0x0 | 0x40816c | 0x8750 | 0x7150 | 0xac |
SHFileOperationA | 0x0 | 0x408170 | 0x8754 | 0x7154 | 0x9a |
SHGetPathFromIDListA | 0x0 | 0x408174 | 0x8758 | 0x7158 | 0xbc |
ShellExecuteExA | 0x0 | 0x408178 | 0x875c | 0x715c | 0x109 |
SHGetSpecialFolderLocation | 0x0 | 0x40817c | 0x8760 | 0x7160 | 0xc3 |
SHBrowseForFolderA | 0x0 | 0x408180 | 0x8764 | 0x7164 | 0x79 |
ole32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
IIDFromString | 0x0 | 0x408284 | 0x8868 | 0x7268 | 0xc6 |
OleInitialize | 0x0 | 0x408288 | 0x886c | 0x726c | 0xee |
OleUninitialize | 0x0 | 0x40828c | 0x8870 | 0x7270 | 0x105 |
CoCreateInstance | 0x0 | 0x408290 | 0x8874 | 0x7274 | 0x10 |
CoTaskMemFree | 0x0 | 0x408294 | 0x8878 | 0x7278 | 0x65 |
COMCTL32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x11 | 0x408038 | 0x861c | 0x701c | - |
ImageList_Create | 0x0 | 0x40803c | 0x8620 | 0x7020 | 0x37 |
ImageList_Destroy | 0x0 | 0x408040 | 0x8624 | 0x7024 | 0x38 |
ImageList_AddMasked | 0x0 | 0x408044 | 0x8628 | 0x7028 | 0x34 |
USER32.dll (62)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetClipboardData | 0x0 | 0x408188 | 0x876c | 0x716c | 0x24a |
CharPrevA | 0x0 | 0x40818c | 0x8770 | 0x7170 | 0x2d |
CallWindowProcA | 0x0 | 0x408190 | 0x8774 | 0x7174 | 0x1b |
PeekMessageA | 0x0 | 0x408194 | 0x8778 | 0x7178 | 0x200 |
DispatchMessageA | 0x0 | 0x408198 | 0x877c | 0x717c | 0xa1 |
MessageBoxIndirectA | 0x0 | 0x40819c | 0x8780 | 0x7180 | 0x1e2 |
GetDlgItemTextA | 0x0 | 0x4081a0 | 0x8784 | 0x7184 | 0x113 |
SetDlgItemTextA | 0x0 | 0x4081a4 | 0x8788 | 0x7188 | 0x253 |
GetSystemMetrics | 0x0 | 0x4081a8 | 0x878c | 0x718c | 0x15d |
CreatePopupMenu | 0x0 | 0x4081ac | 0x8790 | 0x7190 | 0x5e |
AppendMenuA | 0x0 | 0x4081b0 | 0x8794 | 0x7194 | 0x8 |
TrackPopupMenu | 0x0 | 0x4081b4 | 0x8798 | 0x7198 | 0x2a4 |
FillRect | 0x0 | 0x4081b8 | 0x879c | 0x719c | 0xe2 |
EmptyClipboard | 0x0 | 0x4081bc | 0x87a0 | 0x71a0 | 0xc1 |
LoadCursorA | 0x0 | 0x4081c0 | 0x87a4 | 0x71a4 | 0x1ba |
GetMessagePos | 0x0 | 0x4081c4 | 0x87a8 | 0x71a8 | 0x13c |
CheckDlgButton | 0x0 | 0x4081c8 | 0x87ac | 0x71ac | 0x38 |
GetSysColor | 0x0 | 0x4081cc | 0x87b0 | 0x71b0 | 0x15a |
SetCursor | 0x0 | 0x4081d0 | 0x87b4 | 0x71b4 | 0x24d |
GetWindowLongA | 0x0 | 0x4081d4 | 0x87b8 | 0x71b8 | 0x16e |
SetClassLongA | 0x0 | 0x4081d8 | 0x87bc | 0x71bc | 0x247 |
SetWindowPos | 0x0 | 0x4081dc | 0x87c0 | 0x71c0 | 0x283 |
IsWindowEnabled | 0x0 | 0x4081e0 | 0x87c4 | 0x71c4 | 0x1ae |
GetWindowRect | 0x0 | 0x4081e4 | 0x87c8 | 0x71c8 | 0x174 |
GetSystemMenu | 0x0 | 0x4081e8 | 0x87cc | 0x71cc | 0x15c |
EnableMenuItem | 0x0 | 0x4081ec | 0x87d0 | 0x71d0 | 0xc2 |
RegisterClassA | 0x0 | 0x4081f0 | 0x87d4 | 0x71d4 | 0x216 |
ScreenToClient | 0x0 | 0x4081f4 | 0x87d8 | 0x71d8 | 0x231 |
EndDialog | 0x0 | 0x4081f8 | 0x87dc | 0x71dc | 0xc6 |
GetClassInfoA | 0x0 | 0x4081fc | 0x87e0 | 0x71e0 | 0xf6 |
SystemParametersInfoA | 0x0 | 0x408200 | 0x87e4 | 0x71e4 | 0x299 |
CreateWindowExA | 0x0 | 0x408204 | 0x87e8 | 0x71e8 | 0x60 |
ExitWindowsEx | 0x0 | 0x408208 | 0x87ec | 0x71ec | 0xe1 |
DialogBoxParamA | 0x0 | 0x40820c | 0x87f0 | 0x71f0 | 0x9e |
CharNextA | 0x0 | 0x408210 | 0x87f4 | 0x71f4 | 0x2a |
SetTimer | 0x0 | 0x408214 | 0x87f8 | 0x71f8 | 0x27a |
DestroyWindow | 0x0 | 0x408218 | 0x87fc | 0x71fc | 0x99 |
CreateDialogParamA | 0x0 | 0x40821c | 0x8800 | 0x7200 | 0x55 |
SetForegroundWindow | 0x0 | 0x408220 | 0x8804 | 0x7204 | 0x257 |
SetWindowTextA | 0x0 | 0x408224 | 0x8808 | 0x7208 | 0x286 |
PostQuitMessage | 0x0 | 0x408228 | 0x880c | 0x720c | 0x204 |
SendMessageTimeoutA | 0x0 | 0x40822c | 0x8810 | 0x7210 | 0x23e |
ShowWindow | 0x0 | 0x408230 | 0x8814 | 0x7214 | 0x292 |
wsprintfA | 0x0 | 0x408234 | 0x8818 | 0x7218 | 0x2d7 |
GetDlgItem | 0x0 | 0x408238 | 0x881c | 0x721c | 0x111 |
FindWindowExA | 0x0 | 0x40823c | 0x8820 | 0x7220 | 0xe4 |
IsWindow | 0x0 | 0x408240 | 0x8824 | 0x7224 | 0x1ad |
GetDC | 0x0 | 0x408244 | 0x8828 | 0x7228 | 0x10c |
SetWindowLongA | 0x0 | 0x408248 | 0x882c | 0x722c | 0x280 |
LoadImageA | 0x0 | 0x40824c | 0x8830 | 0x7230 | 0x1c0 |
InvalidateRect | 0x0 | 0x408250 | 0x8834 | 0x7234 | 0x193 |
ReleaseDC | 0x0 | 0x408254 | 0x8838 | 0x7238 | 0x22a |
EnableWindow | 0x0 | 0x408258 | 0x883c | 0x723c | 0xc4 |
BeginPaint | 0x0 | 0x40825c | 0x8840 | 0x7240 | 0xd |
SendMessageA | 0x0 | 0x408260 | 0x8844 | 0x7244 | 0x23b |
DefWindowProcA | 0x0 | 0x408264 | 0x8848 | 0x7248 | 0x8e |
DrawTextA | 0x0 | 0x408268 | 0x884c | 0x724c | 0xbc |
GetClientRect | 0x0 | 0x40826c | 0x8850 | 0x7250 | 0xff |
EndPaint | 0x0 | 0x408270 | 0x8854 | 0x7254 | 0xc8 |
IsWindowVisible | 0x0 | 0x408274 | 0x8858 | 0x7258 | 0x1b1 |
CloseClipboard | 0x0 | 0x408278 | 0x885c | 0x725c | 0x42 |
OpenClipboard | 0x0 | 0x40827c | 0x8860 | 0x7260 | 0x1f6 |
GDI32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetBkMode | 0x0 | 0x40804c | 0x8630 | 0x7030 | 0x216 |
SetBkColor | 0x0 | 0x408050 | 0x8634 | 0x7034 | 0x215 |
GetDeviceCaps | 0x0 | 0x408054 | 0x8638 | 0x7038 | 0x16b |
CreateFontIndirectA | 0x0 | 0x408058 | 0x863c | 0x703c | 0x3a |
CreateBrushIndirect | 0x0 | 0x40805c | 0x8640 | 0x7040 | 0x29 |
DeleteObject | 0x0 | 0x408060 | 0x8644 | 0x7044 | 0x8f |
SetTextColor | 0x0 | 0x408064 | 0x8648 | 0x7048 | 0x23c |
SelectObject | 0x0 | 0x408068 | 0x864c | 0x704c | 0x20e |
KERNEL32.dll (62)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetExitCodeProcess | 0x0 | 0x408070 | 0x8654 | 0x7054 | 0x15a |
WaitForSingleObject | 0x0 | 0x408074 | 0x8658 | 0x7058 | 0x390 |
GetProcAddress | 0x0 | 0x408078 | 0x865c | 0x705c | 0x1a0 |
GetSystemDirectoryA | 0x0 | 0x40807c | 0x8660 | 0x7060 | 0x1c1 |
WideCharToMultiByte | 0x0 | 0x408080 | 0x8664 | 0x7064 | 0x394 |
MoveFileExA | 0x0 | 0x408084 | 0x8668 | 0x7068 | 0x26f |
ReadFile | 0x0 | 0x408088 | 0x866c | 0x706c | 0x2b5 |
GetTempFileNameA | 0x0 | 0x40808c | 0x8670 | 0x7070 | 0x1d3 |
WriteFile | 0x0 | 0x408090 | 0x8674 | 0x7074 | 0x3a4 |
RemoveDirectoryA | 0x0 | 0x408094 | 0x8678 | 0x7078 | 0x2c4 |
CreateProcessA | 0x0 | 0x408098 | 0x867c | 0x707c | 0x66 |
CreateFileA | 0x0 | 0x40809c | 0x8680 | 0x7080 | 0x53 |
GetLastError | 0x0 | 0x4080a0 | 0x8684 | 0x7084 | 0x171 |
CreateThread | 0x0 | 0x4080a4 | 0x8688 | 0x7088 | 0x6f |
CreateDirectoryA | 0x0 | 0x4080a8 | 0x868c | 0x708c | 0x4b |
GlobalUnlock | 0x0 | 0x4080ac | 0x8690 | 0x7090 | 0x20a |
GetDiskFreeSpaceA | 0x0 | 0x4080b0 | 0x8694 | 0x7094 | 0x14d |
GlobalLock | 0x0 | 0x4080b4 | 0x8698 | 0x7098 | 0x203 |
SetErrorMode | 0x0 | 0x4080b8 | 0x869c | 0x709c | 0x315 |
GetVersion | 0x0 | 0x4080bc | 0x86a0 | 0x70a0 | 0x1e8 |
lstrcpynA | 0x0 | 0x4080c0 | 0x86a4 | 0x70a4 | 0x3c9 |
GetCommandLineA | 0x0 | 0x4080c4 | 0x86a8 | 0x70a8 | 0x110 |
GetTempPathA | 0x0 | 0x4080c8 | 0x86ac | 0x70ac | 0x1d5 |
lstrlenA | 0x0 | 0x4080cc | 0x86b0 | 0x70b0 | 0x3cc |
SetEnvironmentVariableA | 0x0 | 0x4080d0 | 0x86b4 | 0x70b4 | 0x313 |
ExitProcess | 0x0 | 0x4080d4 | 0x86b8 | 0x70b8 | 0xb9 |
GetWindowsDirectoryA | 0x0 | 0x4080d8 | 0x86bc | 0x70bc | 0x1f3 |
GetCurrentProcess | 0x0 | 0x4080dc | 0x86c0 | 0x70c0 | 0x142 |
GetModuleFileNameA | 0x0 | 0x4080e0 | 0x86c4 | 0x70c4 | 0x17d |
CopyFileA | 0x0 | 0x4080e4 | 0x86c8 | 0x70c8 | 0x43 |
GetTickCount | 0x0 | 0x4080e8 | 0x86cc | 0x70cc | 0x1df |
Sleep | 0x0 | 0x4080ec | 0x86d0 | 0x70d0 | 0x356 |
GetFileSize | 0x0 | 0x4080f0 | 0x86d4 | 0x70d4 | 0x163 |
GetFileAttributesA | 0x0 | 0x4080f4 | 0x86d8 | 0x70d8 | 0x15e |
SetCurrentDirectoryA | 0x0 | 0x4080f8 | 0x86dc | 0x70dc | 0x30a |
SetFileAttributesA | 0x0 | 0x4080fc | 0x86e0 | 0x70e0 | 0x319 |
GetFullPathNameA | 0x0 | 0x408100 | 0x86e4 | 0x70e4 | 0x169 |
GetShortPathNameA | 0x0 | 0x408104 | 0x86e8 | 0x70e8 | 0x1b5 |
MoveFileA | 0x0 | 0x408108 | 0x86ec | 0x70ec | 0x26e |
CompareFileTime | 0x0 | 0x40810c | 0x86f0 | 0x70f0 | 0x39 |
SetFileTime | 0x0 | 0x408110 | 0x86f4 | 0x70f4 | 0x31f |
SearchPathA | 0x0 | 0x408114 | 0x86f8 | 0x70f8 | 0x2db |
lstrcmpiA | 0x0 | 0x408118 | 0x86fc | 0x70fc | 0x3c3 |
lstrcmpA | 0x0 | 0x40811c | 0x8700 | 0x7100 | 0x3c0 |
CloseHandle | 0x0 | 0x408120 | 0x8704 | 0x7104 | 0x34 |
GlobalFree | 0x0 | 0x408124 | 0x8708 | 0x7108 | 0x1ff |
GlobalAlloc | 0x0 | 0x408128 | 0x870c | 0x710c | 0x1f8 |
ExpandEnvironmentStringsA | 0x0 | 0x40812c | 0x8710 | 0x7110 | 0xbc |
LoadLibraryExA | 0x0 | 0x408130 | 0x8714 | 0x7114 | 0x253 |
FreeLibrary | 0x0 | 0x408134 | 0x8718 | 0x7118 | 0xf8 |
lstrcpyA | 0x0 | 0x408138 | 0x871c | 0x711c | 0x3c6 |
lstrcatA | 0x0 | 0x40813c | 0x8720 | 0x7120 | 0x3bd |
FindClose | 0x0 | 0x408140 | 0x8724 | 0x7124 | 0xce |
MultiByteToWideChar | 0x0 | 0x408144 | 0x8728 | 0x7128 | 0x275 |
WritePrivateProfileStringA | 0x0 | 0x408148 | 0x872c | 0x712c | 0x3a9 |
GetPrivateProfileStringA | 0x0 | 0x40814c | 0x8730 | 0x7130 | 0x19c |
SetFilePointer | 0x0 | 0x408150 | 0x8734 | 0x7134 | 0x31b |
GetModuleHandleA | 0x0 | 0x408154 | 0x8738 | 0x7138 | 0x17f |
FindNextFileA | 0x0 | 0x408158 | 0x873c | 0x713c | 0xdc |
FindFirstFileA | 0x0 | 0x40815c | 0x8740 | 0x7140 | 0xd2 |
DeleteFileA | 0x0 | 0x408160 | 0x8744 | 0x7144 | 0x83 |
MulDiv | 0x0 | 0x408164 | 0x8748 | 0x7148 | 0x274 |
Memory Dumps (31)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
qdgotnx2vapbkvcb.exe | 1 | 0x00400000 | 0x00464FFF | Relevant Image |
![]() |
32-bit | 0x00406500 |
![]() |
![]() |
...
|
system.dll | 1 | 0x75230000 | 0x75235FFF | First Execution |
![]() |
32-bit | 0x752316DB |
![]() |
![]() |
...
|
buffer | 1 | 0x002A0000 | 0x002AEFFF | First Execution |
![]() |
32-bit | 0x002AB84F |
![]() |
![]() |
...
|
buffer | 1 | 0x002A0000 | 0x002AEFFF | Content Changed |
![]() |
32-bit | 0x002AC982 |
![]() |
![]() |
...
|
buffer | 2 | 0x00400000 | 0x0041DFFF | First Execution |
![]() |
32-bit | 0x00405A20 |
![]() |
![]() |
...
|
buffer | 1 | 0x00600000 | 0x0061DFFF | Marked Executable |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00600000 | 0x0061DFFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x003F0000 | 0x003FAFFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
qdgotnx2vapbkvcb.exe | 1 | 0x00400000 | 0x00464FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 2 | 0x00400000 | 0x0041DFFF | Content Changed |
![]() |
32-bit | 0x00406AE0 |
![]() |
![]() |
...
|
buffer | 2 | 0x00400000 | 0x0041DFFF | Content Changed |
![]() |
32-bit | 0x00407220 |
![]() |
![]() |
...
|
qdgotnx2vapbkvcb.exe | 3 | 0x00400000 | 0x00464FFF | Relevant Image |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 2 | 0x00400000 | 0x0041DFFF | Content Changed |
![]() |
32-bit | 0x00406F3E |
![]() |
![]() |
...
|
system.dll | 3 | 0x753E0000 | 0x753E5FFF | First Execution |
![]() |
32-bit | 0x753E16DB |
![]() |
![]() |
...
|
buffer | 3 | 0x00360000 | 0x0036EFFF | First Execution |
![]() |
32-bit | 0x0036B84F |
![]() |
![]() |
...
|
buffer | 3 | 0x00360000 | 0x0036EFFF | Content Changed |
![]() |
32-bit | 0x0036B8FD |
![]() |
![]() |
...
|
buffer | 3 | 0x00360000 | 0x0036EFFF | Content Changed |
![]() |
32-bit | 0x0036C982 |
![]() |
![]() |
...
|
buffer | 8 | 0x00400000 | 0x0041DFFF | First Execution |
![]() |
32-bit | 0x00405A20 |
![]() |
![]() |
...
|
buffer | 3 | 0x01E70000 | 0x01E8DFFF | Marked Executable |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 8 | 0x00400000 | 0x0041DFFF | Content Changed |
![]() |
32-bit | 0x004010E0 |
![]() |
![]() |
...
|
buffer | 3 | 0x01E70000 | 0x01E8DFFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 3 | 0x003F0000 | 0x003FAFFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
qdgotnx2vapbkvcb.exe | 3 | 0x00400000 | 0x00464FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 8 | 0x00400000 | 0x0041DFFF | Content Changed |
![]() |
32-bit | 0x00406AE0 |
![]() |
![]() |
...
|
buffer | 8 | 0x00400000 | 0x0041DFFF | Content Changed |
![]() |
32-bit | 0x00407460 |
![]() |
![]() |
...
|
buffer | 8 | 0x00400000 | 0x0041DFFF | Content Changed |
![]() |
32-bit | 0x00404230 |
![]() |
![]() |
...
|
buffer | 8 | 0x00400000 | 0x0041DFFF | Content Changed |
![]() |
32-bit | 0x00405921 |
![]() |
![]() |
...
|
buffer | 8 | 0x00400000 | 0x0041DFFF | Content Changed |
![]() |
32-bit | 0x00403470 |
![]() |
![]() |
...
|
buffer | 2 | 0x00400000 | 0x0041DFFF | Content Changed |
![]() |
32-bit | 0x004051F0 |
![]() |
![]() |
...
|
buffer | 2 | 0x00400000 | 0x0041DFFF | Content Changed |
![]() |
32-bit | 0x00402459 |
![]() |
![]() |
...
|
buffer | 8 | 0x00400000 | 0x0041DFFF | Content Changed |
![]() |
32-bit | 0x00402FF0 |
![]() |
![]() |
...
|
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\readme-warning.txt | Dropped File | Text |
Blacklisted
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
C:\Users\5P5NRG~1\AppData\Local\Temp\nssB673.tmp\System.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
PE Information
»
Image Base | 0x10000000 |
Entry Point | 0x10002921 |
Size Of Code | 0x2000 |
Size Of Initialized Data | 0xa00 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-08-01 02:38:32+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x10001000 | 0x1f8f | 0x2000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.46 |
.rdata | 0x10003000 | 0x363 | 0x400 | 0x2400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.96 |
.data | 0x10004000 | 0x68 | 0x200 | 0x2800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.35 |
.reloc | 0x10005000 | 0x27c | 0x400 | 0x2a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 3.88 |
Imports (3)
»
KERNEL32.dll (16)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MultiByteToWideChar | 0x0 | 0x10003000 | 0x30fc | 0x24fc | 0x275 |
GlobalFree | 0x0 | 0x10003004 | 0x3100 | 0x2500 | 0x1ff |
GlobalSize | 0x0 | 0x10003008 | 0x3104 | 0x2504 | 0x207 |
lstrcpynA | 0x0 | 0x1000300c | 0x3108 | 0x2508 | 0x3c9 |
lstrcpyA | 0x0 | 0x10003010 | 0x310c | 0x250c | 0x3c6 |
GetProcAddress | 0x0 | 0x10003014 | 0x3110 | 0x2510 | 0x1a0 |
VirtualFree | 0x0 | 0x10003018 | 0x3114 | 0x2514 | 0x383 |
FreeLibrary | 0x0 | 0x1000301c | 0x3118 | 0x2518 | 0xf8 |
lstrlenA | 0x0 | 0x10003020 | 0x311c | 0x251c | 0x3cc |
LoadLibraryA | 0x0 | 0x10003024 | 0x3120 | 0x2520 | 0x252 |
GetModuleHandleA | 0x0 | 0x10003028 | 0x3124 | 0x2524 | 0x17f |
GlobalAlloc | 0x0 | 0x1000302c | 0x3128 | 0x2528 | 0x1f8 |
WideCharToMultiByte | 0x0 | 0x10003030 | 0x312c | 0x252c | 0x394 |
VirtualAlloc | 0x0 | 0x10003034 | 0x3130 | 0x2530 | 0x381 |
VirtualProtect | 0x0 | 0x10003038 | 0x3134 | 0x2534 | 0x386 |
GetLastError | 0x0 | 0x1000303c | 0x3138 | 0x2538 | 0x171 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
wsprintfA | 0x0 | 0x10003044 | 0x3140 | 0x2540 | 0x2d7 |
ole32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StringFromGUID2 | 0x0 | 0x1000304c | 0x3148 | 0x2548 | 0x135 |
CLSIDFromString | 0x0 | 0x10003050 | 0x314c | 0x254c | 0x8 |
Exports (8)
»
Api name | EAT Address | Ordinal |
---|---|---|
Alloc | 0x1000 | 0x1 |
Call | 0x16db | 0x2 |
Copy | 0x1058 | 0x3 |
Free | 0x15d1 | 0x4 |
Get | 0x1638 | 0x5 |
Int64Op | 0x1837 | 0x6 |
Store | 0x10e0 | 0x7 |
StrAlloc | 0x103d | 0x8 |
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\131083810 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\5K3gdoBlg.ppt.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\b7Yg9V3.csv.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\BzLVN6t6Lf9s_.wav.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\CHUzJlugY9.jpg.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\cqb yy.avi.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\DKCxtaDeFHnnl9.bmp.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\eWZCHi3eLkUgrC9.swf.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\fhE tWg_t_PnWedmM.ppt.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Gl2n.ppt.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Gpt4_-2dPkKgmz.mp4.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\gvDuBJ\Fi_B6.wav.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\gvDuBJ\vILuce_NAfE5.odp.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Gy7 Owab66F.mp3.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\i5PQjm b3BTXy.jpg.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\IwUXVtS6JYZ.png.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\jvY-yDYl.jpg.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\kCPs7-4LI.odt.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\lr16-fIb.png.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\mw5riY.png.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\njlflq.wav.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\oUc0yc-q8kf b.gif.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\PHDNs62mGH2-Qp\OjIokWpJpEtX.png.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\PHDNs62mGH2-Qp\VD6WmNOwvSAW.docx.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\PHDNs62mGH2-Qp\YiGuCSIuHl4NVOXR1S.csv.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\pKZPIllC8laOeEzH3xt.avi.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\rLYHZPzQbRGc5nDx8e.m4a.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Ruu9nGXRTFgb.ppt.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\rYBfz3.mkv.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\TRLAK.mp3.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\U4kDOkCafKFZKBgA.mkv.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\v6TS3PBwROiFp.wav.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\_CnL XD D.flv.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.cab.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.cab.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.msi.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.msi.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.xml.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.msi.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.msi.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.xml.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeLR.cab.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.xml.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.msi.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.xml.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Setup.xml.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.msi.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.xml.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccLR.cab.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\branding.xml.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.msi.[4B2E4630].[agares_helpdesk@tutanota.com].moloch | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5P5NRG~1\AppData\Local\Temp\nsiB412.tmp | Dropped File | Unknown |
Not Queried
|
...
|
»