Ransomware Downloader Injector
Djvu Troj/Krypt-XU Mal/Generic-S STOP +2
Created on 2023-06-07T02:15:53+00:00
c0832b1008aa0fc828654f9762e37bda019080cbdd92bd2453a05cfb3b79abb3.exe
Remarks (2/4)
(0x0200003A): A tasks were rescheduled ahead of time to reveal dormant functionality.
(0x0200001B): The maximum number of file Reputation Analysis requests per analysis (150) was exceeded.
(0x0200000E): The overall sleep time of all monitored processes was truncated from "15 minutes, 46 seconds" to "12 seconds" to reveal dormant functionality.
Remarks
(0x0200005D): 280 additional dumps with the reason "Content Changed" and a total of 340 MB were skipped because the respective maximum limit was reached.
(0x0200004F): Static Analysis failed to analyze file artifacts in this analysis due to an error. Check the static_analysis_log_2b4e417e5594a5e9aec3322803aed47fbfb41b7f11033ea38ccd938c91d6394a.log file for further information.
(0x0200004F): Static Analysis failed to analyze file artifacts in this analysis due to an error. Check the static_analysis_log_be2a0d5b47a1009f0c03bf1ddbd712b8fd3fc9c7437a0570da484fb1e6c65efb.log file for further information.
(0x0200004F): Static Analysis failed to analyze file artifacts in this analysis due to an error. Check the static_analysis_log_8aa22e70515ff35e039bf99cbcc644f7e9f36390b1e4f5c3d1f356e18ef1927b.log file for further information.
(0x0200004F): Static Analysis failed to analyze file artifacts in this analysis due to an error. Check the static_analysis_log_ca9fb363d85bfcb3518f7127a8e60b7c2160a07597f58c2edd23a59b2174e7b0.log file for further information.
(0x0200004F): Static Analysis failed to analyze file artifacts in this analysis due to an error. Check the static_analysis_log_f09f6e6fed30f799663ffae92c382e765c12f25339a3918dfe99663fd05527be.log file for further information.
(0x0200004F): Static Analysis failed to analyze file artifacts in this analysis due to an error. Check the static_analysis_log_970c6447439cda8d0cef731a0c2ff2e83164dd64d474e924fcdb84cd240ef210.log file for further information.
(0x0200004F): Static Analysis failed to analyze file artifacts in this analysis due to an error. Check the static_analysis_log_a902121dea2301abeda305bf23d362b53f44a06a4972849d772fd5148a27a099.log file for further information.
(0x0200004A): 43 dump(s) were skipped because they exceeded the maximum dump size of 16 MB. The largest one was 41 MB.
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\kEecfMwgj\Desktop\c0832b1008aa0fc828654f9762e37bda019080cbdd92bd2453a05cfb3b79abb3.exe | Sample File | Binary |
Malicious
|
...
|
Verdict |
Malicious
|
Names | Mal/Generic-S |
Image Base | 0x00400000 |
Entry Point | 0x00405DE5 |
Size Of Code | 0x00012E00 |
Size Of Initialized Data | 0x028DE600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2022-08-10 21:14 (UTC) |
FileDescriptions | NiceIncorporated |
LegalCopyrights | Challenger fazan inc. |
LegalTrademarks2 | objfngizdf |
ProductName | Roadways |
ProductVersion | 84.2.3.5 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x00012D94 | 0x00012E00 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.48 |
.data | 0x00414000 | 0x028BA9F0 | 0x00015A00 | 0x00013200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.37 |
.rsrc | 0x02CCF000 | 0x0001ADD8 | 0x0001AE00 | 0x00028C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.82 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetMailslotInfo | - | 0x0040100C | 0x00013264 | 0x00012664 | 0x00000479 |
GetLogicalDriveStringsW | - | 0x00401010 | 0x00013268 | 0x00012668 | 0x00000208 |
WritePrivateProfileSectionA | - | 0x00401014 | 0x0001326C | 0x0001266C | 0x00000528 |
GetSystemWindowsDirectoryW | - | 0x00401018 | 0x00013270 | 0x00012670 | 0x0000027C |
FreeEnvironmentStringsA | - | 0x0040101C | 0x00013274 | 0x00012674 | 0x00000160 |
GetProcessPriorityBoost | - | 0x00401020 | 0x00013278 | 0x00012678 | 0x00000250 |
EnumCalendarInfoExW | - | 0x00401024 | 0x0001327C | 0x0001267C | 0x000000F2 |
GetConsoleTitleA | - | 0x00401028 | 0x00013280 | 0x00012680 | 0x000001B5 |
WaitNamedPipeW | - | 0x0040102C | 0x00013284 | 0x00012684 | 0x00000500 |
EnumTimeFormatsW | - | 0x00401030 | 0x00013288 | 0x00012688 | 0x00000112 |
GetVolumePathNameW | - | 0x00401034 | 0x0001328C | 0x0001268C | 0x000002AB |
GetPrivateProfileIntA | - | 0x00401038 | 0x00013290 | 0x00012690 | 0x0000023B |
GetSystemPowerStatus | - | 0x0040103C | 0x00013294 | 0x00012694 | 0x00000274 |
GetCalendarInfoA | - | 0x00401040 | 0x00013298 | 0x00012698 | 0x00000179 |
GetProcessHandleCount | - | 0x00401044 | 0x0001329C | 0x0001269C | 0x00000249 |
GetConsoleAliasExesLengthW | - | 0x00401048 | 0x000132A0 | 0x000126A0 | 0x00000193 |
LeaveCriticalSection | - | 0x0040104C | 0x000132A4 | 0x000126A4 | 0x00000339 |
GetFileAttributesA | - | 0x00401050 | 0x000132A8 | 0x000126A8 | 0x000001E5 |
GetFileAttributesW | - | 0x00401054 | 0x000132AC | 0x000126AC | 0x000001EA |
GetModuleFileNameW | - | 0x00401058 | 0x000132B0 | 0x000126B0 | 0x00000214 |
GetShortPathNameA | - | 0x0040105C | 0x000132B4 | 0x000126B4 | 0x00000260 |
DeleteFiber | - | 0x00401060 | 0x000132B8 | 0x000126B8 | 0x000000D2 |
SetLastError | - | 0x00401064 | 0x000132BC | 0x000126BC | 0x00000473 |
GetProcAddress | - | 0x00401068 | 0x000132C0 | 0x000126C0 | 0x00000245 |
HeapSize | - | 0x0040106C | 0x000132C4 | 0x000126C4 | 0x000002D4 |
MoveFileW | - | 0x00401070 | 0x000132C8 | 0x000126C8 | 0x00000363 |
SetComputerNameA | - | 0x00401074 | 0x000132CC | 0x000126CC | 0x00000427 |
InterlockedIncrement | - | 0x00401078 | 0x000132D0 | 0x000126D0 | 0x000002EF |
GetDiskFreeSpaceW | - | 0x0040107C | 0x000132D4 | 0x000126D4 | 0x000001CF |
OpenWaitableTimerA | - | 0x00401080 | 0x000132D8 | 0x000126D8 | 0x00000387 |
LoadLibraryA | - | 0x00401084 | 0x000132DC | 0x000126DC | 0x0000033C |
WriteConsoleA | - | 0x00401088 | 0x000132E0 | 0x000126E0 | 0x0000051A |
GetProcessId | - | 0x0040108C | 0x000132E4 | 0x000126E4 | 0x0000024C |
InterlockedExchangeAdd | - | 0x00401090 | 0x000132E8 | 0x000126E8 | 0x000002ED |
LocalAlloc | - | 0x00401094 | 0x000132EC | 0x000126EC | 0x00000344 |
DeleteTimerQueue | - | 0x00401098 | 0x000132F0 | 0x000126F0 | 0x000000D8 |
SetCalendarInfoW | - | 0x0040109C | 0x000132F4 | 0x000126F4 | 0x0000041F |
BuildCommDCBAndTimeoutsW | - | 0x004010A0 | 0x000132F8 | 0x000126F8 | 0x0000003C |
FindFirstVolumeMountPointW | - | 0x004010A4 | 0x000132FC | 0x000126FC | 0x0000013E |
IsSystemResumeAutomatic | - | 0x004010A8 | 0x00013300 | 0x00012700 | 0x00000305 |
AddAtomW | - | 0x004010AC | 0x00013304 | 0x00012704 | 0x00000004 |
OpenJobObjectW | - | 0x004010B0 | 0x00013308 | 0x00012708 | 0x0000037B |
GetPrivateProfileStructA | - | 0x004010B4 | 0x0001330C | 0x0001270C | 0x00000243 |
FindFirstVolumeMountPointA | - | 0x004010B8 | 0x00013310 | 0x00012710 | 0x0000013D |
EnumDateFormatsA | - | 0x004010BC | 0x00013314 | 0x00012714 | 0x000000F4 |
GetModuleHandleA | - | 0x004010C0 | 0x00013318 | 0x00012718 | 0x00000215 |
CreateMutexA | - | 0x004010C4 | 0x0001331C | 0x0001271C | 0x0000009B |
FindNextFileW | - | 0x004010C8 | 0x00013320 | 0x00012720 | 0x00000145 |
EnumDateFormatsW | - | 0x004010CC | 0x00013324 | 0x00012724 | 0x000000F8 |
CompareStringA | - | 0x004010D0 | 0x00013328 | 0x00012728 | 0x00000061 |
GetShortPathNameW | - | 0x004010D4 | 0x0001332C | 0x0001272C | 0x00000261 |
SetFileShortNameA | - | 0x004010D8 | 0x00013330 | 0x00012730 | 0x00000468 |
FindAtomW | - | 0x004010DC | 0x00013334 | 0x00012734 | 0x0000012D |
GetVolumeNameForVolumeMountPointW | - | 0x004010E0 | 0x00013338 | 0x00012738 | 0x000002A9 |
DeleteFileW | - | 0x004010E4 | 0x0001333C | 0x0001273C | 0x000000D6 |
EnumSystemLocalesW | - | 0x004010E8 | 0x00013340 | 0x00012740 | 0x0000010F |
AreFileApisANSI | - | 0x004010EC | 0x00013344 | 0x00012744 | 0x00000015 |
GetDriveTypeW | - | 0x004010F0 | 0x00013348 | 0x00012748 | 0x000001D3 |
SearchPathA | - | 0x004010F4 | 0x0001334C | 0x0001274C | 0x0000041C |
GetStringTypeA | - | 0x004010F8 | 0x00013350 | 0x00012750 | 0x00000266 |
GetLastError | - | 0x004010FC | 0x00013354 | 0x00012754 | 0x00000202 |
HeapFree | - | 0x00401100 | 0x00013358 | 0x00012758 | 0x000002CF |
DeleteFileA | - | 0x00401104 | 0x0001335C | 0x0001275C | 0x000000D3 |
WideCharToMultiByte | - | 0x00401108 | 0x00013360 | 0x00012760 | 0x00000511 |
HeapReAlloc | - | 0x0040110C | 0x00013364 | 0x00012764 | 0x000002D2 |
GetCommandLineA | - | 0x00401110 | 0x00013368 | 0x00012768 | 0x00000186 |
HeapSetInformation | - | 0x00401114 | 0x0001336C | 0x0001276C | 0x000002D3 |
GetStartupInfoW | - | 0x00401118 | 0x00013370 | 0x00012770 | 0x00000263 |
RaiseException | - | 0x0040111C | 0x00013374 | 0x00012774 | 0x000003B1 |
HeapAlloc | - | 0x00401120 | 0x00013378 | 0x00012778 | 0x000002CB |
IsProcessorFeaturePresent | - | 0x00401124 | 0x0001337C | 0x0001277C | 0x00000304 |
HeapCreate | - | 0x00401128 | 0x00013380 | 0x00012780 | 0x000002CD |
EnterCriticalSection | - | 0x0040112C | 0x00013384 | 0x00012784 | 0x000000EE |
SetFilePointer | - | 0x00401130 | 0x00013388 | 0x00012788 | 0x00000466 |
SetHandleCount | - | 0x00401134 | 0x0001338C | 0x0001278C | 0x0000046F |
GetStdHandle | - | 0x00401138 | 0x00013390 | 0x00012790 | 0x00000264 |
InitializeCriticalSectionAndSpinCount | - | 0x0040113C | 0x00013394 | 0x00012794 | 0x000002E3 |
GetFileType | - | 0x00401140 | 0x00013398 | 0x00012798 | 0x000001F3 |
DeleteCriticalSection | - | 0x00401144 | 0x0001339C | 0x0001279C | 0x000000D1 |
UnhandledExceptionFilter | - | 0x00401148 | 0x000133A0 | 0x000127A0 | 0x000004D3 |
SetUnhandledExceptionFilter | - | 0x0040114C | 0x000133A4 | 0x000127A4 | 0x000004A5 |
IsDebuggerPresent | - | 0x00401150 | 0x000133A8 | 0x000127A8 | 0x00000300 |
EncodePointer | - | 0x00401154 | 0x000133AC | 0x000127AC | 0x000000EA |
DecodePointer | - | 0x00401158 | 0x000133B0 | 0x000127B0 | 0x000000CA |
TerminateProcess | - | 0x0040115C | 0x000133B4 | 0x000127B4 | 0x000004C0 |
GetCurrentProcess | - | 0x00401160 | 0x000133B8 | 0x000127B8 | 0x000001C0 |
GetCPInfo | - | 0x00401164 | 0x000133BC | 0x000127BC | 0x00000172 |
InterlockedDecrement | - | 0x00401168 | 0x000133C0 | 0x000127C0 | 0x000002EB |
GetACP | - | 0x0040116C | 0x000133C4 | 0x000127C4 | 0x00000168 |
GetOEMCP | - | 0x00401170 | 0x000133C8 | 0x000127C8 | 0x00000237 |
IsValidCodePage | - | 0x00401174 | 0x000133CC | 0x000127CC | 0x0000030A |
TlsAlloc | - | 0x00401178 | 0x000133D0 | 0x000127D0 | 0x000004C5 |
TlsGetValue | - | 0x0040117C | 0x000133D4 | 0x000127D4 | 0x000004C7 |
TlsSetValue | - | 0x00401180 | 0x000133D8 | 0x000127D8 | 0x000004C8 |
TlsFree | - | 0x00401184 | 0x000133DC | 0x000127DC | 0x000004C6 |
GetModuleHandleW | - | 0x00401188 | 0x000133E0 | 0x000127E0 | 0x00000218 |
GetCurrentThreadId | - | 0x0040118C | 0x000133E4 | 0x000127E4 | 0x000001C5 |
ExitProcess | - | 0x00401190 | 0x000133E8 | 0x000127E8 | 0x00000119 |
WriteFile | - | 0x00401194 | 0x000133EC | 0x000127EC | 0x00000525 |
GetModuleFileNameA | - | 0x00401198 | 0x000133F0 | 0x000127F0 | 0x00000213 |
FreeEnvironmentStringsW | - | 0x0040119C | 0x000133F4 | 0x000127F4 | 0x00000161 |
GetEnvironmentStringsW | - | 0x004011A0 | 0x000133F8 | 0x000127F8 | 0x000001DA |
QueryPerformanceCounter | - | 0x004011A4 | 0x000133FC | 0x000127FC | 0x000003A7 |
GetTickCount | - | 0x004011A8 | 0x00013400 | 0x00012800 | 0x00000293 |
GetCurrentProcessId | - | 0x004011AC | 0x00013404 | 0x00012804 | 0x000001C1 |
GetSystemTimeAsFileTime | - | 0x004011B0 | 0x00013408 | 0x00012808 | 0x00000279 |
Sleep | - | 0x004011B4 | 0x0001340C | 0x0001280C | 0x000004B2 |
SetStdHandle | - | 0x004011B8 | 0x00013410 | 0x00012810 | 0x00000487 |
GetConsoleCP | - | 0x004011BC | 0x00013414 | 0x00012814 | 0x0000019A |
GetConsoleMode | - | 0x004011C0 | 0x00013418 | 0x00012818 | 0x000001AC |
FlushFileBuffers | - | 0x004011C4 | 0x0001341C | 0x0001281C | 0x00000157 |
RtlUnwind | - | 0x004011C8 | 0x00013420 | 0x00012820 | 0x00000418 |
LCMapStringW | - | 0x004011CC | 0x00013424 | 0x00012824 | 0x0000032D |
MultiByteToWideChar | - | 0x004011D0 | 0x00013428 | 0x00012828 | 0x00000367 |
GetStringTypeW | - | 0x004011D4 | 0x0001342C | 0x0001282C | 0x00000269 |
LoadLibraryW | - | 0x004011D8 | 0x00013430 | 0x00012830 | 0x0000033F |
WriteConsoleW | - | 0x004011DC | 0x00013434 | 0x00012834 | 0x00000524 |
CloseHandle | - | 0x004011E0 | 0x00013438 | 0x00012838 | 0x00000052 |
CreateFileW | - | 0x004011E4 | 0x0001343C | 0x0001283C | 0x0000008F |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCharABCWidthsW | - | 0x00401000 | 0x00013258 | 0x00012658 | 0x000001B5 |
SelectObject | - | 0x00401004 | 0x0001325C | 0x0001265C | 0x00000277 |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
buffer | 1 | 0x02E32480 | 0x02E442A7 | First Execution | 32-bit | 0x02E36F2C |
...
|
||
buffer | 1 | 0x00210000 | 0x00218FFF | First Execution | 32-bit | 0x00210000 |
...
|
||
buffer | 9 | 0x02E12280 | 0x02E240A7 | First Execution | 32-bit | 0x02E16D2C |
...
|
||
buffer | 9 | 0x00210000 | 0x00218FFF | First Execution | 32-bit | 0x00210000 |
...
|
||
buffer | 18 | 0x02DD2280 | 0x02DE40A7 | First Execution | 32-bit | 0x02DD6D2C |
...
|
||
buffer | 18 | 0x00220000 | 0x00228FFF | First Execution | 32-bit | 0x00220000 |
...
|
||
buffer | 18 | 0x00250000 | 0x00265FFF | Marked Executable | 32-bit | - |
...
|
C:\Users\kEecfMwgj\Documents\k7QtcBphpiUfUf6h4.rtf.neqp | Dropped File | RTF |
Malicious
|
...
|
ÍÑls#!ø‡%©æ¼°fJ \x8f2tp|\x8d¿œý.¸ï‹¾†íùÓ”ånÙ¥H‹ÃU`ðºÅv/+¦Eú\x9doulr>G¬œŒÛ#Q[>ÿÞiÙ¯©ž'5l<¢Å,wYÌ tûÆÆš kùÅQRœë¢´zžª"ÿ“¨áp`mskH¢Šzžã&: l?¨Zq‘±‰šÊŸæË3~ëš[½ú3«÷dïùÈÁÙ à‰‰:S(×íÛm œS3]'_R^\x9dª_.YµK¦;ƒ–'|zX“ìK1MÍWën]¦hpOD¥øDè’lZ‹E§UÉà>É( ¾Yd‘:9…Àe+’\x90™‡ë@œ\x8f6ãAâVA@ºWx#Î[¨UºëTÑ@×&2Ò ±76;Cl\x8dz½‹i©X%4Y%P¿¡²œSœà";këÇÑÛô4\x81Ô®±0^»ëU4ÚxY7ruˆ3\x81°‘ÑqžäñOnj‡V|l&kš¸¦mäúø!¦KŠËåòlù=‡÷ÈÉÒ½©ÂÑGôu¬vcs2Åñœö‘"Q-«vÐzHIh³'“©`‘ù+[w=sòC83ùô[ÇUš@7¬°2hG†$®;MÍîÖféµs*|ëlvty™fj¦b¸Þ:\x90!W÷QŠ:;RjVˆWXLÉu0nSúV£)ËË\x9dÿªL_k\x8f#Ó:§)‚ýv|á¾(0ÅXx`ql\x9dáB”°mÑ-b)š0c“HòÉòÄG|<ô\x9dA…å;“„â;á¦,§‰_œÑ Ç\x8d1WCV‰DŠ¨zWž»’××RV\x90ÃΓhW5$.vò]»+í<7à[FϼÔW-l&uXÜKÙqçæÃw\x9dGžšˆ;`ÙšÙÛM•á“úç½T®—‘þëË$|·žˆÆ¿4Õ³Ñ7¶‡NBäÂ(ŒrÝŒlXPf\x8dÑq븶ŠaÖrö®¥Ô”š®•Ç\x90éßÝ.ÈRLPßøÝAIô²vO:ô@•?|(¸“uÌc¤h /ÁƒC !iÂçeB9ÆpQµm“"ýâ7ÕvKü\x81N^º‹ãhȧ—ØÛ”)bBˆýas;åUÙ'\x8d-÷Ðms°ñTs‹a`eÝ%ƒ&këè˜>T½¾\x9dh¹¸ŽÎ]Õ7ʦŒ+e9RœÔ|o^º¸æ¿åþç÷r±a°ªZ¡`¥eºpAä]öeTЗF±Å |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
c:\users\keecfmwgj\documents\1bzpfxjukgmx2ljc8ae7\oy4eruo53oz.rtf.neqp | Dropped File | RTF |
Malicious
|
...
|
Þvk± ÏØÈtèà\x90Ùx#þB¬«±x8KpgLwjr6ê4ègâ#2ç¼.ÙoR¾!=>Aݽ_H³‘»C¡©ë^wJì$Ù©>dºÞÁX^‘ž˜T2jˆàÞ²÷FJ^Ï@KsQ\x90®‘Iª\x8fv\x9d0¶5ðÐP‰õ˜”‰po¼SLMK=¤WÐíî )«U…*Á‚Y×N—Ìþƒ(ýòD´ÿ-»iC³+Ðâ>§8™\x81G)„ŽÉk#a9O¸M¹Ag¦OV%»ˆ`·ÉÌÛ™_Ð2j’ç%Šxtjq–÷ow:Cýr#ií¤Q\x8dㆉ¾z+ÈSoa—²%¼2Y÷[0¥ ª+öö•ã"à•˜ÎEd6ÞÃPø¾°F¥bÒ30óµxì>–Ô|C(•¾Ô³¿z±ìj¤#N¿W¼ÀeI¾YLU¬ZÏPÑg™ëgyŸÂñrÒNu½¤‹ÐÙtâ•+¯™(ª|N±×yn¨dó”LM‘—áïhu†r ¾Ó‚Ó‰\x8f”²’4™\x9d¼ÙæcÏçÁ¬åÑÍÙ•àMSm-`õ¢é…J_l¡FLÿ§ß©ø\x8ft)Ýv¿(›>#³,Æf©]ÙJ?*·ç¹h\x9dàÁüšg&_‰2¾%ài¨ÍhÊÌ¡ºÃ;³HLêmvmª§]É™J`\x8fKnC)~ÀK¦R¾‰%±íÙ…Õ;k¿«3H(»F¨ 4¬,’\x8fƒx~MÄ^T?·9ö¢Ã5Ä->á9Gké“&z1t¾ëèMnîÝÆnÞ!`Þð§º'EYw·J©HÎüÏ/· Ê·¢‹Ö-2Z¼‰îŸ»@ûÌö׊éYEg©qÈ‹Â:É%E¯ç¤’Gó½ÿØlÖõ\x81P¡°ª¼qŒ«“j¯ñ¤|*µòyÝOP¾A[¯&àú3´ÎlJ„©9?‰¨ò¨„GÞ\x9dЗS1wVïÍFCf‘‹°¯ªgн¿æëÌ…ÛÄšËa€yC]ÇXZMì r jxÄ\x81)] X¦ÝçMzüÇ¿ÀºÃQ-…#\x81u“LŠñoÂÙ_¢à÷/+Dº…㘅ùû€:Ç~—ØýãUÅìæÊA†íwAò¹½œàÒpÚÿ1´Gˆȴú LB:·bù@m–õoij®\x90¢ðÊÿmhþ\x9dKž 8¨‰£“SœÈÕËÇ™²ô• Ò@xy6y”’¢¢ÜâAŸ\x8fÞeã8@2Ou'ãMÞ |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\kEecfMwgj\Documents\1bZpFXJUkgMx2ljc8Ae7\A4HxEP_8V\6ayIRleTh vq1qbRJ-L\oV6zFBL.rtf.neqp | Dropped File | RTF |
Malicious
|
...
|
Ü%( šdYÃÝòd²¶Êˆ €àmQrÅ?*QǶÚg†0ìÀ\x9dã=Æ>£Ì¼¸¨ód—>õ›q¤¨)wÃQÍ–m§‘vkˆ'Çã\x8fgêëVb Ûùd\x90ªp~ôNJXãÉh‡‚‚Ȥ0üXèÒ\x8fß -‘ §Õ¼dÌ Ó€rb̬†Ä'ˆ$'Š¬²fš?Zjýëa¼*'Ô ›HJ‹sf°%EXû§\x90‹c€œïÔv-ÝE)mb©ªÃÝ!Æ/“èiÕa¨¥Æ©ÐþxNêD6£Á]ñ^ÌVlçÉDÕŸþ-$ô‡àÙ¶|ŸSš9/"m7Ñ…m÷¸,²te-—“©B¼H.pU…y¢:¡~ÁKÐùü2aóÛ1(g~Xf¾«`²ŸT»]†âXŽƒíýºßÂ(ñÌ,éÙ3`¨â<o›)ñ”ƒdãÎL‘ür0ú>5ÔOˆ–:ÅÒ²÷¹žtÛÄ9ŒýŽ¿`q º5€÷OÈ<åwá@÷®ä>¸LÒJÂqß›T-né^çýnaéÿ±\x8dÑüÑ̳\x81Ôe¼×–ÕÛ$b1qЪ®mMY÷•\x8f\x8f¢ü‰Vò¶$‡–X8߈A 7Œê×îvU¼hØyÁœÎ Ô,+B汊¥v¶½dK ˜‰O‘Ù([9š«ò†%_/BÅq|‘w=®BHílÆ-Øç%‹æçê[KˆWú¢r¼|\x81hËê‚Åû\x9d<|©îú‰xMì>¢»Q©üí#^G>àUµհ’Ó\x8dþ¹ïÈÉë;’ah¢ÁܸÙÒV™eEŽ«×±©åKK,3تuØ\x81ìLâÛ‹DfuOþ"ž$ŒXï#…SI=€º\x9dù—T@¶ºwR×Aj⸵óö$mœÊ5±L@d[ÕñÜv•ùízEO·0†âÔ¿kºÂ‹‚8”%X°p ymB,SåÔÌEc Êü4²“røªa^âŽî*ÿ1ñ¤34NA|X ×réë_…9oÐ0çæv~Ã~’PXüR!C¥±•«4i4U`ç,¼S%ïO~`@`Ÿ WXáz°cþµgƒyÛFÝìÚÒÌZœÏàdM–õˆR³`÷#²|¡ÿšw±]&·Æ‘·UW_Á,Ëup&oå~ëq#Î\x8dìЈ‡ÿ%öp¹íÅÅOµÀ›ª±öØ=Æ.Ü ñg=’6¦ñ\x90<‹&D~A-UN¼z;@È™)÷Wé¾µ” ¥œPi°Ë²Y‘ü-\x8d“Ḫ`b…wg×ùÛkh¡ |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
c:\users\keecfmwgj\videos\__n93zziz9rny.mp4.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\documents\1bzpfxjukgmx2ljc8ae7\a4hxep_8v\3trax2.xlsx.neqp | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\documents\ewxkzosyjkhnwpoz.docx.neqp | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\music\by0ls29bbpklp631o9b.m4a.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\u8_5OoZXD_BvAYx.wav.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\1bZpFXJUkgMx2ljc8Ae7\A4HxEP_8V\uYkNWJF11O37vr\Xw0 5hxcA.pptx.neqp | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\music\hvolbk.mp3.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\videos\qg8i9g0tihejna tr3l.flv.neqp | Dropped File | Video |
Malicious
|
...
|
c:\users\keecfmwgj\documents\1bzpfxjukgmx2ljc8ae7\vztrk63idaphpsstgre.pptx.neqp | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\music\dcxazqh.m4a.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Pictures\5tjEDT2i8f.png.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\videos\fmxha_w4eke5pf8l.mp4.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\1bZpFXJUkgMx2ljc8Ae7\A4HxEP_8V\c0Y tBs zGXD9sK\qJTFnnuSQ.ppt.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\music\epp3ouzeazkkjj5hj.wav.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\c8-qdtknhu0bjgmu.jpg.neqp | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\tkaxolhrl8qedbn.gif.neqp | Dropped File | Image |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\qYyGPLt6OoKeyh2R.m4a.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\1bZpFXJUkgMx2ljc8Ae7\A4HxEP_8V\G_bTFo.odp.neqp | Dropped File | ZIP |
Malicious
|
...
|
C:\Users\kEecfMwgj\Videos\OJNEj2xIV52LVtvj-s0.flv.neqp | Dropped File | Video |
Malicious
|
...
|
c:\users\keecfmwgj\documents\1bzpfxjukgmx2ljc8ae7\a4hxep_8v\ghhedifjzwru5kmr.xlsx.neqp | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\documents\oeh1e-xhit5le6vwmu4m.xlsx.neqp | Dropped File | ZIP |
Malicious
|
...
|
C:\Users\kEecfMwgj\Pictures\dwHz _UcKn2C.bmp.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\documents\1bzpfxjukgmx2ljc8ae7\s7lh3hxtittmcvgh\r6fjlezzg_wtj.ots.neqp | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\contacts\administrator.contact.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\documents\koomr.pptx.neqp | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\twnoq6e1v6eelj tb7f\djfpsjtvq\-6sm.bmp.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\1bZpFXJUkgMx2ljc8Ae7\OvrR6bzipPtcj.docx.neqp | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\videos\jcuukzkpdwtrtf.flv.neqp | Dropped File | Video |
Malicious
|
...
|
C:\Users\kEecfMwgj\Pictures\MXfa2rZxqyhANkfzM\NECDkoymaUw.png.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\xys3y_cu 624bscdh.bmp.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\mxfa2rzxqyhankfzm\1clt3s.jpg.neqp | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\music\uz21xybo5jhjzq.mp3.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\nqugwix.bmp.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Videos\N hQ2zMqJr.flv.neqp | Dropped File | Video |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\HAyp2zHURXEkt5y6c.mp3.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\1bZpFXJUkgMx2ljc8Ae7\ukOCS4.csv.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\SZzcxiUb3S1y0E.pptx.neqp | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\eysf0phwcb.mp3.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Videos\ups I7.mkv.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\1bZpFXJUkgMx2ljc8Ae7\A4HxEP_8V\BqMJYpJI5- Av.csv.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\mxfa2rzxqyhankfzm\rx-ru.png.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\aM0hOBR8.wav.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\YiJlu.mp3.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\XqIXfBNrZqo t.mp3.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\1bZpFXJUkgMx2ljc8Ae7\A4HxEP_8V\h9Ysje.pptx.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\twNoq6e1V6eeLj TB7f\kduc8M4q0iGO.xlsx.neqp | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\mxfa2rzxqyhankfzm\jtbbgg -ujwe3.bmp.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\documents\2vnukkmn.xlsx.neqp | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\upklen56967zj.flv.neqp | Dropped File | Video |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\twnoq6e1v6eelj tb7f\iyl6m -whjjeo.wav.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\mxfa2rzxqyhankfzm\zt3a4flgawjyzt7r4xm.png.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\mxfa2rzxqyhankfzm\oepl7unfz0.jpg.neqp | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\mxfa2rzxqyhankfzm\dohgx0t l.jpg.neqp | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\videos\gfravduy7lom.swf.neqp | Dropped File | Shockwave Flash |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\G8oUQ7rKtGSWcT.ots.neqp | Dropped File | ZIP |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\FU2 nzV-k.pdf.neqp | Dropped File |
Malicious
|
...
|
C:\Users\kEecfMwgj\Videos\n 7DfguJMJ.mp4.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\1bZpFXJUkgMx2ljc8Ae7\A4HxEP_8V\uYkNWJF11O37vr\RRM0O7_xClNdkabdTozN.xlsx.neqp | Dropped File | ZIP |
Malicious
|
...
|
C:\Users\kEecfMwgj\Videos\bZ_MAu7.avi.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\music\d7illvxbgi6q.wav.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\5_uaNmfND3.m4a.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\1bZpFXJUkgMx2ljc8Ae7\A4HxEP_8V\6ayIRleTh vq1qbRJ-L\aZ2HX2t0pm3.ots.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\VuYJSL8GFd0.mp3.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\videos\kcia6gopkg9.avi.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\twNoq6e1V6eeLj TB7f\qf XQc2cUy7GFzzlXBjR.m4a.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\et8krykeuj73u.swf.neqp | Dropped File | Shockwave Flash |
Malicious
|
...
|
C:\Users\kEecfMwgj\Videos\ueJknWfWvw.mkv.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\gwqS.gif.neqp | Dropped File | Image |
Malicious
|
...
|
C:\Users\kEecfMwgj\Videos\80uy.mkv.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\sU3qV4 mwzLmj.pps.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\aFVf9.swf.neqp | Dropped File | Shockwave Flash |
Malicious
|
...
|
C:\Users\kEecfMwgj\Pictures\dCjDLPjgt.png.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\NBxo5Eh8J.swf.neqp | Dropped File | Shockwave Flash |
Malicious
|
...
|
c:\users\keecfmwgj\documents\1bzpfxjukgmx2ljc8ae7\a4hxep_8v\6ayirleth vq1qbrj-l\gbpqlruev5tl.pptx.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\videos\osw75x o0982bw.swf.neqp | Dropped File | Shockwave Flash |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\1bZpFXJUkgMx2ljc8Ae7\A4HxEP_8V\c0Y tBs zGXD9sK\Yz_Q1.doc.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\twnoq6e1v6eelj tb7f\djfpsjtvq\gxuwpj.csv.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\1bZpFXJUkgMx2ljc8Ae7\A4HxEP_8V\Ydwe3q9JyYweb_55_.ots.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\dshy6owctf.wav.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Videos\bGt49HOvptpF2AsDKl.mkv.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\videos\ompo2s.flv.neqp | Dropped File | Video |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\mxfa2rzxqyhankfzm\ruec4u8cn1u.jpg.neqp | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\byf8cf9eozrq2jwpt66.gif.neqp | Dropped File | Image |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\n-diJdt93vqLXJ.wav.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\favorites\msn websites\msn entertainment.url.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\favorites\msn websites\msn sports.url.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\favorites\msn websites\msn.url.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Favorites\Microsoft Websites\Microsoft At Home.url.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\favorites\microsoft websites\ie site on microsoft.com.url.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Favorites\Windows Live\Windows Live Gallery.url.neqp | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\favorites\microsoft websites\ie add-on site.url.neqp | Dropped File | Stream |
Malicious
|
...
|
C:\Users\KEECFM~1\AppData\Local\Temp\3024.tmp | Dropped File | Empty |
Malicious
|
...
|
92f4134cc013553a811aa371570d7e2e66a2537b4eac3dbdeaf0cb5f02e6ec56 | Downloaded File | Binary |
Malicious
|
...
|
Verdict |
Malicious
|
Names | Mal/Generic-S |
Image Base | 0x00400000 |
Entry Point | 0x008E569E |
Size Of Code | 0x004E3800 |
Size Of Initialized Data | 0x00000800 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2023-05-30 19:43 (UTC) |
FileDescription | |
FileVersion | 1.0.0.0 |
InternalName | wall.exe |
LegalCopyright | |
OriginalFilename | wall.exe |
ProductVersion | 1.0.0.0 |
Assembly Version | 1.0.0.0 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00402000 | 0x004E36A4 | 0x004E3800 | 0x00000200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.74 |
.rsrc | 0x008E6000 | 0x000004D0 | 0x00000600 | 0x004E3A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.7 |
.reloc | 0x008E8000 | 0x0000000C | 0x00000200 | 0x004E4000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | - | 0x00402000 | 0x004E5678 | 0x004E3878 | 0x00000000 |
e661f9fd2f80f0f63668a38a18943877aa491464b19680c933f2960b4a0155f6 | PCAP File | PCAP |
Malicious
Raised based on a child artifact.
|
...
|
ef1682f582ae280b5ab2d4fc2c1d3fb28c312751c6697577f28f7663dcc8cd07 | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.14 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.98 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
89e078fb68353108924d444daac30761e2f3a17b0ac7ded2c9f30334eaff9646 | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.14 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.98 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
7fe6e06a41e7da91a8d71068fdbfa3d39310b0fe1d2ace3b6651b92c1bfd982c | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.14 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.98 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
3445e80809f2a260a7d9ad20ef528840976968ee43ba52a63abba0a56381aec0 | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.2 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 1.06 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
8ed6dfe9d6815dc22c326c308b7402ab97af5b76b37a4ce7f76a6793e8642615 | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.19 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 1.04 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
420d80df5d3d75e956e079719b6c0ce0303406f1b513d136c1a5efd4686a5840 | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.14 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.98 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
0c0b6a4685e84f89f8c444e84864bb70790dcc090ef99e83fc9dacf81f9605cc | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.19 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 1.04 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
f3f2ddd6a521ee76a224de1cac93b3d80ebffa75e65cdd984f8e0a136199c5a3 | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.19 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 1.04 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
cbe28fa5e05b394252bda74839e4f7b04b62b382aaa0dcee5196919f1912410c | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.19 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 1.04 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
3c5571a767be08f4e53c70695c84ef1fdf162432d9811d8c712a99fb110850bd | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.14 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.99 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
f43500d99e886576aa2f3367d538b8d6cad05c81c34a924b4f3a8eb84b243714 | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.2 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 1.06 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
bc2549b38d66f9eeb9895647caf5dc4d866376de1396b5044f95e97ce19608a7 | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.2 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 1.07 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
3a1678ecda6f53b6eabdecbbb07d30bba268edbd28fe7ecf6eeee0838b62820f | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.14 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.99 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
0d24aa85f5dde8bb3d59b783e23500c25bc0deaf80ef6d8e2b1578cadb4076ea | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.2 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 1.05 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
7d2a17a1969eb01411d56352a0f7008df8127d35bf9bbccef76590d2474ad2cc | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.19 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 1.04 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
7d5a7c649121fe8ffdb3f33d7990e72f7f82d348393b691f9c7f3f545d72fb58 | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.2 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 1.07 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
8611096fe95209ae1dba414e2822e1846ef5d334a498f9259a425bcc4417a460 | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.19 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 1.04 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
4f0f5de45b74e5ea989f7a9d6a940bd776723ce15983d27fa72c617738d32d7a | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.14 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.98 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
be56d11b01efd115e7fb4cb893f74c406e54dea0f66e25bedcd2d54ded46954c | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.2 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 1.06 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
c2d124851a7fc5228ad860e0649c0622d8cda9f030954935d188f23470057c49 | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.15 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 1.04 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
c86b6d25a821db817f9d4812529b7a4a0f7d7f33b2c14000251193bfe00cd1bd | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.2 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 1.07 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
e50366970c63f29b549ef31f804d55860e4350cefe5d4d19f5634cd05b400fc9 | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.2 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 1.05 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
d1652c1d808a6395d5ef182c05ded57b733b869a18d4ba889941edef8bc08e68 | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.14 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.98 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
1ef7f8b580e6444d3fc7b7c8999443d346f3c0be496875649fa90c37709b601b | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.14 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.98 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
b275bd4c85167e0585d897907d5aaca02f473b95f6f3bf2b4582c825d0b6c5db | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.14 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.99 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
24b05b9eb992fd995ad217c8eb2ec4cfe1472960f70be82a7d197b5b790489e1 | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.14 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.98 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
40a2518bf4a3cc5c663278f0f5e9f1a7a0d51e57f2c13cc2009c1d5cf0a87d36 | Memory Dump | Binary |
Malicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00424141 |
Size Of Code | 0x000CA600 |
Size Of Initialized Data | 0x00068600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2019-09-23 17:30 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000CA5BC | 0x000CA600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x004CC000 | 0x0003DBA2 | 0x0003DC00 | 0x000CAA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.66 |
.data | 0x0050A000 | 0x00020358 | 0x00006400 | 0x00108600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.14 |
.rsrc | 0x0052B000 | 0x000001E0 | 0x00000200 | 0x0010EA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.12 |
.reloc | 0x0052C000 | 0x0000A32C | 0x0000A400 | 0x0010EC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.98 |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Djvu | Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\kEecfMwgj\AppData\Local\de09289d-6a73-4dff-8fad-e9599bbc17bd\51F0.exe | Dropped File | Binary |
Suspicious
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x00405911 |
Size Of Code | 0x00011A00 |
Size Of Initialized Data | 0x02957200 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2022-03-13 06:21 (UTC) |
FileDescriptions | NiceIncorporated |
LegalCopyrights | Challenger fazan inc. |
LegalTrademarks2 | objfngizdf |
ProductName | Roadway |
ProductVersion | 84.2.3.3 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x0001197E | 0x00011A00 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.48 |
.data | 0x00413000 | 0x02939930 | 0x00094A00 | 0x00011E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.96 |
.rsrc | 0x02D4D000 | 0x00014C78 | 0x00014E00 | 0x000A6800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.87 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InterlockedDecrement | - | 0x0040100C | 0x00011F64 | 0x00011364 | 0x000002EB |
SetMailslotInfo | - | 0x00401010 | 0x00011F68 | 0x00011368 | 0x00000479 |
GetSystemWindowsDirectoryW | - | 0x00401014 | 0x00011F6C | 0x0001136C | 0x0000027C |
FreeEnvironmentStringsA | - | 0x00401018 | 0x00011F70 | 0x00011370 | 0x00000160 |
GetProcessPriorityBoost | - | 0x0040101C | 0x00011F74 | 0x00011374 | 0x00000250 |
EnumCalendarInfoExW | - | 0x00401020 | 0x00011F78 | 0x00011378 | 0x000000F2 |
WaitNamedPipeW | - | 0x00401024 | 0x00011F7C | 0x0001137C | 0x00000500 |
EnumTimeFormatsW | - | 0x00401028 | 0x00011F80 | 0x00011380 | 0x00000112 |
GetDriveTypeA | - | 0x0040102C | 0x00011F84 | 0x00011384 | 0x000001D2 |
GetProcessTimes | - | 0x00401030 | 0x00011F88 | 0x00011388 | 0x00000252 |
GetVolumePathNameW | - | 0x00401034 | 0x00011F8C | 0x0001138C | 0x000002AB |
GetCalendarInfoA | - | 0x00401038 | 0x00011F90 | 0x00011390 | 0x00000179 |
GetFileAttributesA | - | 0x0040103C | 0x00011F94 | 0x00011394 | 0x000001E5 |
WriteConsoleW | - | 0x00401040 | 0x00011F98 | 0x00011398 | 0x00000524 |
SetSystemPowerState | - | 0x00401044 | 0x00011F9C | 0x0001139C | 0x0000048A |
GetModuleFileNameW | - | 0x00401048 | 0x00011FA0 | 0x000113A0 | 0x00000214 |
CompareStringW | - | 0x0040104C | 0x00011FA4 | 0x000113A4 | 0x00000064 |
GetShortPathNameA | - | 0x00401050 | 0x00011FA8 | 0x000113A8 | 0x00000260 |
EnumSystemLocalesA | - | 0x00401054 | 0x00011FAC | 0x000113AC | 0x0000010D |
GetPrivateProfileIntW | - | 0x00401058 | 0x00011FB0 | 0x000113B0 | 0x0000023C |
DeleteFiber | - | 0x0040105C | 0x00011FB4 | 0x000113B4 | 0x000000D2 |
GetLastError | - | 0x00401060 | 0x00011FB8 | 0x000113B8 | 0x00000202 |
GetProcAddress | - | 0x00401064 | 0x00011FBC | 0x000113BC | 0x00000245 |
InterlockedIncrement | - | 0x00401068 | 0x00011FC0 | 0x000113C0 | 0x000002EF |
HeapSize | - | 0x0040106C | 0x00011FC4 | 0x000113C4 | 0x000002D4 |
SetComputerNameA | - | 0x00401070 | 0x00011FC8 | 0x000113C8 | 0x00000427 |
EnterCriticalSection | - | 0x00401074 | 0x00011FCC | 0x000113CC | 0x000000EE |
SearchPathA | - | 0x00401078 | 0x00011FD0 | 0x000113D0 | 0x0000041C |
OpenWaitableTimerA | - | 0x0040107C | 0x00011FD4 | 0x000113D4 | 0x00000387 |
LoadLibraryA | - | 0x00401080 | 0x00011FD8 | 0x000113D8 | 0x0000033C |
Process32FirstW | - | 0x00401084 | 0x00011FDC | 0x000113DC | 0x00000396 |
GetProcessId | - | 0x00401088 | 0x00011FE0 | 0x000113E0 | 0x0000024C |
LocalAlloc | - | 0x0040108C | 0x00011FE4 | 0x000113E4 | 0x00000344 |
SetCalendarInfoW | - | 0x00401090 | 0x00011FE8 | 0x000113E8 | 0x0000041F |
BuildCommDCBAndTimeoutsW | - | 0x00401094 | 0x00011FEC | 0x000113EC | 0x0000003C |
IsSystemResumeAutomatic | - | 0x00401098 | 0x00011FF0 | 0x000113F0 | 0x00000305 |
AddAtomW | - | 0x0040109C | 0x00011FF4 | 0x000113F4 | 0x00000004 |
OpenJobObjectW | - | 0x004010A0 | 0x00011FF8 | 0x000113F8 | 0x0000037B |
GetPrivateProfileStructA | - | 0x004010A4 | 0x00011FFC | 0x000113FC | 0x00000243 |
FindFirstVolumeMountPointA | - | 0x004010A8 | 0x00012000 | 0x00011400 | 0x0000013D |
EnumDateFormatsA | - | 0x004010AC | 0x00012004 | 0x00011404 | 0x000000F4 |
CreateIoCompletionPort | - | 0x004010B0 | 0x00012008 | 0x00011408 | 0x00000094 |
GetModuleHandleA | - | 0x004010B4 | 0x0001200C | 0x0001140C | 0x00000215 |
CancelTimerQueueTimer | - | 0x004010B8 | 0x00012010 | 0x00011410 | 0x00000046 |
FreeEnvironmentStringsW | - | 0x004010BC | 0x00012014 | 0x00011414 | 0x00000161 |
FindNextFileW | - | 0x004010C0 | 0x00012018 | 0x00011418 | 0x00000145 |
SetFileShortNameA | - | 0x004010C4 | 0x0001201C | 0x0001141C | 0x00000468 |
FindAtomW | - | 0x004010C8 | 0x00012020 | 0x00011420 | 0x0000012D |
AreFileApisANSI | - | 0x004010CC | 0x00012024 | 0x00011424 | 0x00000015 |
GetConsoleAliasExesLengthA | - | 0x004010D0 | 0x00012028 | 0x00011428 | 0x00000192 |
AttachConsole | - | 0x004010D4 | 0x0001202C | 0x0001142C | 0x00000017 |
GetVolumeNameForVolumeMountPointA | - | 0x004010D8 | 0x00012030 | 0x00011430 | 0x000002A8 |
HeapFree | - | 0x004010DC | 0x00012034 | 0x00011434 | 0x000002CF |
DeleteFileA | - | 0x004010E0 | 0x00012038 | 0x00011438 | 0x000000D3 |
WideCharToMultiByte | - | 0x004010E4 | 0x0001203C | 0x0001143C | 0x00000511 |
HeapReAlloc | - | 0x004010E8 | 0x00012040 | 0x00011440 | 0x000002D2 |
GetCommandLineA | - | 0x004010EC | 0x00012044 | 0x00011444 | 0x00000186 |
HeapSetInformation | - | 0x004010F0 | 0x00012048 | 0x00011448 | 0x000002D3 |
GetStartupInfoW | - | 0x004010F4 | 0x0001204C | 0x0001144C | 0x00000263 |
RaiseException | - | 0x004010F8 | 0x00012050 | 0x00011450 | 0x000003B1 |
HeapAlloc | - | 0x004010FC | 0x00012054 | 0x00011454 | 0x000002CB |
IsProcessorFeaturePresent | - | 0x00401100 | 0x00012058 | 0x00011458 | 0x00000304 |
HeapCreate | - | 0x00401104 | 0x0001205C | 0x0001145C | 0x000002CD |
LeaveCriticalSection | - | 0x00401108 | 0x00012060 | 0x00011460 | 0x00000339 |
SetHandleCount | - | 0x0040110C | 0x00012064 | 0x00011464 | 0x0000046F |
GetStdHandle | - | 0x00401110 | 0x00012068 | 0x00011468 | 0x00000264 |
InitializeCriticalSectionAndSpinCount | - | 0x00401114 | 0x0001206C | 0x0001146C | 0x000002E3 |
GetFileType | - | 0x00401118 | 0x00012070 | 0x00011470 | 0x000001F3 |
DeleteCriticalSection | - | 0x0040111C | 0x00012074 | 0x00011474 | 0x000000D1 |
UnhandledExceptionFilter | - | 0x00401120 | 0x00012078 | 0x00011478 | 0x000004D3 |
SetUnhandledExceptionFilter | - | 0x00401124 | 0x0001207C | 0x0001147C | 0x000004A5 |
IsDebuggerPresent | - | 0x00401128 | 0x00012080 | 0x00011480 | 0x00000300 |
EncodePointer | - | 0x0040112C | 0x00012084 | 0x00011484 | 0x000000EA |
DecodePointer | - | 0x00401130 | 0x00012088 | 0x00011488 | 0x000000CA |
TerminateProcess | - | 0x00401134 | 0x0001208C | 0x0001148C | 0x000004C0 |
GetCurrentProcess | - | 0x00401138 | 0x00012090 | 0x00011490 | 0x000001C0 |
SetFilePointer | - | 0x0040113C | 0x00012094 | 0x00011494 | 0x00000466 |
GetCPInfo | - | 0x00401140 | 0x00012098 | 0x00011498 | 0x00000172 |
GetACP | - | 0x00401144 | 0x0001209C | 0x0001149C | 0x00000168 |
GetOEMCP | - | 0x00401148 | 0x000120A0 | 0x000114A0 | 0x00000237 |
IsValidCodePage | - | 0x0040114C | 0x000120A4 | 0x000114A4 | 0x0000030A |
TlsAlloc | - | 0x00401150 | 0x000120A8 | 0x000114A8 | 0x000004C5 |
TlsGetValue | - | 0x00401154 | 0x000120AC | 0x000114AC | 0x000004C7 |
TlsSetValue | - | 0x00401158 | 0x000120B0 | 0x000114B0 | 0x000004C8 |
TlsFree | - | 0x0040115C | 0x000120B4 | 0x000114B4 | 0x000004C6 |
GetModuleHandleW | - | 0x00401160 | 0x000120B8 | 0x000114B8 | 0x00000218 |
SetLastError | - | 0x00401164 | 0x000120BC | 0x000114BC | 0x00000473 |
GetCurrentThreadId | - | 0x00401168 | 0x000120C0 | 0x000114C0 | 0x000001C5 |
ExitProcess | - | 0x0040116C | 0x000120C4 | 0x000114C4 | 0x00000119 |
WriteFile | - | 0x00401170 | 0x000120C8 | 0x000114C8 | 0x00000525 |
GetModuleFileNameA | - | 0x00401174 | 0x000120CC | 0x000114CC | 0x00000213 |
GetEnvironmentStringsW | - | 0x00401178 | 0x000120D0 | 0x000114D0 | 0x000001DA |
QueryPerformanceCounter | - | 0x0040117C | 0x000120D4 | 0x000114D4 | 0x000003A7 |
GetTickCount | - | 0x00401180 | 0x000120D8 | 0x000114D8 | 0x00000293 |
GetCurrentProcessId | - | 0x00401184 | 0x000120DC | 0x000114DC | 0x000001C1 |
GetSystemTimeAsFileTime | - | 0x00401188 | 0x000120E0 | 0x000114E0 | 0x00000279 |
Sleep | - | 0x0040118C | 0x000120E4 | 0x000114E4 | 0x000004B2 |
GetConsoleCP | - | 0x00401190 | 0x000120E8 | 0x000114E8 | 0x0000019A |
GetConsoleMode | - | 0x00401194 | 0x000120EC | 0x000114EC | 0x000001AC |
RtlUnwind | - | 0x00401198 | 0x000120F0 | 0x000114F0 | 0x00000418 |
SetStdHandle | - | 0x0040119C | 0x000120F4 | 0x000114F4 | 0x00000487 |
FlushFileBuffers | - | 0x004011A0 | 0x000120F8 | 0x000114F8 | 0x00000157 |
LCMapStringW | - | 0x004011A4 | 0x000120FC | 0x000114FC | 0x0000032D |
MultiByteToWideChar | - | 0x004011A8 | 0x00012100 | 0x00011500 | 0x00000367 |
GetStringTypeW | - | 0x004011AC | 0x00012104 | 0x00011504 | 0x00000269 |
LoadLibraryW | - | 0x004011B0 | 0x00012108 | 0x00011508 | 0x0000033F |
CloseHandle | - | 0x004011B4 | 0x0001210C | 0x0001150C | 0x00000052 |
CreateFileW | - | 0x004011B8 | 0x00012110 | 0x00011510 | 0x0000008F |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCharABCWidthsA | - | 0x00401000 | 0x00011F58 | 0x00011358 | 0x000001B1 |
SelectObject | - | 0x00401004 | 0x00011F5C | 0x0001135C | 0x00000277 |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
buffer | 3 | 0x002C0020 | 0x00350ECF | First Execution | 32-bit | 0x002C0020 |
...
|
||
buffer | 3 | 0x04630000 | 0x0474AFFF | First Execution | 32-bit | 0x04630000 |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | First Execution | 32-bit | 0x00424141 |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00423F84 |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004278D5 |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00425141 |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042C0F0 |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042A06D |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0043B021 |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00420C62 |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042D8D0 |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00431F64 |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0043AF30 |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00421881 |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042B420 |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004C55BE |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004548D0 |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00449000 |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0044D0CB |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0044B550 |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00401000 |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041CC50 |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00419E70 |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0040CF10 |
...
|
||
buffer | 4 | 0x00188000 | 0x0018FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x0023F1B8 | 0x0023F573 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x0023F580 | 0x0023FD7F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x0023FD88 | 0x00240587 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x00240590 | 0x002407AF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x00240C48 | 0x00240D15 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x00240EB8 | 0x00240F53 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x00241588 | 0x00241623 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x00241820 | 0x002419BB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x00241A90 | 0x00241B21 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x00241BD0 | 0x00241CA5 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x00241D70 | 0x00241DFB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x00241E08 | 0x00241E87 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x00241FE8 | 0x002428D3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | First Network Behavior | 32-bit | 0x0040CFAC |
...
|
||
index.dat | 4 | 0x025E0000 | 0x0261FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042B420 |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041B680 |
...
|
||
buffer | 4 | 0x0023F1B8 | 0x0023F573 | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x0023F580 | 0x0023FD7F | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x0023FD88 | 0x00240587 | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x00240590 | 0x002407AF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x00240C48 | 0x00240D15 | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x00240EB8 | 0x00240F53 | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x00241588 | 0x00241623 | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x00241820 | 0x002419BB | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x00241A90 | 0x00241B21 | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x00241BD0 | 0x00241CA5 | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x00241D70 | 0x00241DFB | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x00241E08 | 0x00241E87 | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x00241FE8 | 0x002428D3 | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x00257528 | 0x00257783 | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x0025BBA8 | 0x0025BE03 | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x0025BE10 | 0x0025C06B | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x002C57B8 | 0x002C5847 | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Final Dump | 32-bit | 0x00430BF0 |
...
|
||
buffer | 4 | 0x02963A98 | 0x02963B27 | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x02986E58 | 0x02986EF7 | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x02988300 | 0x02988BEB | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x0298BD28 | 0x0298C527 | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x0298C530 | 0x0298CD3F | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x0298CD48 | 0x0298CFA3 | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x0298CFB0 | 0x0298D20B | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x0298D218 | 0x0298D473 | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x0298D480 | 0x0298D6DB | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x029A3B70 | 0x029A3DCB | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x029FBF90 | 0x029FC1EB | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x029FC1F8 | 0x029FC453 | Final Dump | 32-bit | - |
...
|
||
index.dat | 4 | 0x025E0000 | 0x0261FFFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00433F99 |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041A6DF |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004CB520 |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041D0B0 |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0043233F |
...
|
||
buffer | 4 | 0x0023F580 | 0x0023FD7F | Process Termination | 32-bit | - |
...
|
||
buffer | 4 | 0x00240590 | 0x002407AF | Process Termination | 32-bit | - |
...
|
||
buffer | 4 | 0x00240C48 | 0x00240D15 | Process Termination | 32-bit | - |
...
|
||
buffer | 4 | 0x00240EB8 | 0x00240F53 | Process Termination | 32-bit | - |
...
|
||
buffer | 4 | 0x00241588 | 0x00241623 | Process Termination | 32-bit | - |
...
|
||
buffer | 4 | 0x00241820 | 0x002419BB | Process Termination | 32-bit | - |
...
|
||
buffer | 4 | 0x00241A90 | 0x00241B21 | Process Termination | 32-bit | - |
...
|
||
buffer | 4 | 0x00241BD0 | 0x00241CA5 | Process Termination | 32-bit | - |
...
|
||
buffer | 4 | 0x00241D70 | 0x00241DFB | Process Termination | 32-bit | - |
...
|
||
buffer | 4 | 0x00241E08 | 0x00241E87 | Process Termination | 32-bit | - |
...
|
||
buffer | 4 | 0x00257528 | 0x00257783 | Process Termination | 32-bit | - |
...
|
||
buffer | 4 | 0x0025BBA8 | 0x0025BE03 | Process Termination | 32-bit | - |
...
|
||
buffer | 4 | 0x0025BE10 | 0x0025C06B | Process Termination | 32-bit | - |
...
|
||
buffer | 4 | 0x002A0020 | 0x002A00BF | Process Termination | 32-bit | - |
...
|
||
buffer | 4 | 0x00400000 | 0x00536FFF | Process Termination | 32-bit | - |
...
|
||
buffer | 4 | 0x0298CD48 | 0x0298CFA3 | Process Termination | 32-bit | - |
...
|
||
buffer | 4 | 0x0298CFB0 | 0x0298D20B | Process Termination | 32-bit | - |
...
|
||
buffer | 4 | 0x0298D218 | 0x0298D473 | Process Termination | 32-bit | - |
...
|
||
buffer | 4 | 0x0298D480 | 0x0298D6DB | Process Termination | 32-bit | - |
...
|
||
buffer | 4 | 0x029A3B70 | 0x029A3DCB | Process Termination | 32-bit | - |
...
|
||
buffer | 4 | 0x029FBF90 | 0x029FC1EB | Process Termination | 32-bit | - |
...
|
||
buffer | 4 | 0x029FC1F8 | 0x029FC453 | Process Termination | 32-bit | - |
...
|
||
index.dat | 4 | 0x025E0000 | 0x0261FFFF | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02D70020 | 0x02E00ECF | First Execution | 32-bit | 0x02D70020 |
...
|
||
buffer | 12 | 0x045C0000 | 0x046DAFFF | First Execution | 32-bit | 0x045C0000 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | First Execution | 32-bit | 0x00424141 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00423F84 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00425141 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042C0F0 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042A06D |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0043B021 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00420C62 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042D8D0 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00431F64 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0043AF30 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00421881 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042B420 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004C55BE |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004548D0 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00449000 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0044D0CB |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0044B550 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00401000 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041CC50 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00419E70 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0040CF10 |
...
|
||
buffer | 13 | 0x00188000 | 0x0018FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x0031F1E8 | 0x0031F5A3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x0031F5B0 | 0x0031FDAF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x0031FDB8 | 0x003205B7 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x003205C0 | 0x003207DF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x00320C78 | 0x00320D45 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x00320EE8 | 0x00320F7F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x003214D8 | 0x00321589 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x00321598 | 0x0032162F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x00321828 | 0x003219C3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x00321A98 | 0x00321B29 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x00321BD8 | 0x00321CAD | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x00321D78 | 0x00321E03 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x00321E10 | 0x00321E8F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x00321FD0 | 0x003228BB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | First Network Behavior | 32-bit | 0x0040D000 |
...
|
||
index.dat | 13 | 0x02720000 | 0x0275FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041B680 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00412220 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041E031 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042E003 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00447F50 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041F01A |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00410FC0 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004251E7 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0043ADF7 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004264EF |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00410A50 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042B420 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042434D |
...
|
||
buffer | 20 | 0x00210020 | 0x002A0ECF | First Execution | 32-bit | 0x00210020 |
...
|
||
buffer | 20 | 0x045E0000 | 0x046FAFFF | First Execution | 32-bit | 0x045E0000 |
...
|
||
buffer | 21 | 0x00400000 | 0x00536FFF | First Execution | 32-bit | 0x00424141 |
...
|
||
buffer | 21 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00423F84 |
...
|
||
buffer | 21 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004278D5 |
...
|
||
buffer | 21 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00425141 |
...
|
||
buffer | 21 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042C0F0 |
...
|
||
buffer | 21 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042A06D |
...
|
||
buffer | 21 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0043B021 |
...
|
||
buffer | 21 | 0x00188000 | 0x0018FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 21 | 0x0023F3D0 | 0x0023F78B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 21 | 0x0023F798 | 0x0023FF97 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 21 | 0x0023FFA0 | 0x0024002B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 21 | 0x00240038 | 0x00240837 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 21 | 0x00240840 | 0x002408BF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 21 | 0x002408C8 | 0x00240AE7 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 21 | 0x002410B8 | 0x00241185 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 21 | 0x00241328 | 0x002413C3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 21 | 0x00241730 | 0x002417F1 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 21 | 0x00241800 | 0x0024189B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 21 | 0x00241A98 | 0x00241C33 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 21 | 0x00241D08 | 0x00241D99 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 21 | 0x00241E48 | 0x00241F1D | First Network Behavior | 32-bit | - |
...
|
||
buffer | 21 | 0x00241FE8 | 0x002428D3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 21 | 0x00400000 | 0x00536FFF | First Network Behavior | 32-bit | 0x0040CFAC |
...
|
||
index.dat | 21 | 0x00640000 | 0x0064FFFF | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 21 | 0x00650000 | 0x00657FFF | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 21 | 0x00660000 | 0x0066FFFF | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 21 | 0x02840000 | 0x0287FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 24 | 0x00310020 | 0x003A0ECF | First Execution | 32-bit | 0x00310020 |
...
|
||
buffer | 24 | 0x047A0000 | 0x048BAFFF | First Execution | 32-bit | 0x047A0000 |
...
|
||
buffer | 25 | 0x00400000 | 0x00536FFF | First Execution | 32-bit | 0x00424141 |
...
|
||
buffer | 25 | 0x00188000 | 0x0018FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 25 | 0x00400000 | 0x00536FFF | First Network Behavior | 32-bit | 0x0040D000 |
...
|
||
buffer | 25 | 0x006FF1B8 | 0x006FF573 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 25 | 0x006FF580 | 0x006FFD7F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 25 | 0x006FFD88 | 0x00700587 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 25 | 0x00700590 | 0x007007AF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 25 | 0x00700C48 | 0x00700D15 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 25 | 0x00700EB8 | 0x00700F53 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 25 | 0x00701588 | 0x00701623 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 25 | 0x00701820 | 0x007019BB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 25 | 0x00701A90 | 0x00701B21 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 25 | 0x00701BD0 | 0x00701CA5 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 25 | 0x00701D70 | 0x00701DFB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 25 | 0x00701E08 | 0x00701E87 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 25 | 0x00701FE8 | 0x007028D3 | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 25 | 0x00280000 | 0x0028FFFF | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 25 | 0x00290000 | 0x00297FFF | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 25 | 0x002A0000 | 0x002AFFFF | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 25 | 0x025E0000 | 0x0261FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 25 | 0x00400000 | 0x00536FFF | Process Termination | 32-bit | - |
...
|
||
buffer | 25 | 0x006FF580 | 0x006FFD7F | Process Termination | 32-bit | - |
...
|
||
buffer | 25 | 0x00700590 | 0x007007AF | Process Termination | 32-bit | - |
...
|
||
buffer | 25 | 0x00700C48 | 0x00700D15 | Process Termination | 32-bit | - |
...
|
||
buffer | 25 | 0x00700EB8 | 0x00700F53 | Process Termination | 32-bit | - |
...
|
||
buffer | 25 | 0x00701588 | 0x00701623 | Process Termination | 32-bit | - |
...
|
||
buffer | 25 | 0x00701820 | 0x007019BB | Process Termination | 32-bit | - |
...
|
||
buffer | 25 | 0x00701A90 | 0x00701B21 | Process Termination | 32-bit | - |
...
|
||
buffer | 25 | 0x00701BD0 | 0x00701CA5 | Process Termination | 32-bit | - |
...
|
||
buffer | 25 | 0x00701D70 | 0x00701DFB | Process Termination | 32-bit | - |
...
|
||
buffer | 25 | 0x00701E08 | 0x00701E87 | Process Termination | 32-bit | - |
...
|
||
buffer | 25 | 0x007162C0 | 0x0071635F | Process Termination | 32-bit | - |
...
|
||
buffer | 25 | 0x02B0BC50 | 0x02B0BEAB | Process Termination | 32-bit | - |
...
|
||
buffer | 25 | 0x02B0D398 | 0x02B0D5F3 | Process Termination | 32-bit | - |
...
|
||
buffer | 25 | 0x02B0D600 | 0x02B0D85B | Process Termination | 32-bit | - |
...
|
||
buffer | 25 | 0x02B0D868 | 0x02B0DAC3 | Process Termination | 32-bit | - |
...
|
||
buffer | 25 | 0x02B0DAD0 | 0x02B0DD2B | Process Termination | 32-bit | - |
...
|
||
buffer | 25 | 0x02B0DD38 | 0x02B0DF93 | Process Termination | 32-bit | - |
...
|
||
buffer | 25 | 0x02B0DFA0 | 0x02B0E1FB | Process Termination | 32-bit | - |
...
|
||
buffer | 25 | 0x02B0E208 | 0x02B0E463 | Process Termination | 32-bit | - |
...
|
||
buffer | 25 | 0x02B0E470 | 0x02B0E6CB | Process Termination | 32-bit | - |
...
|
||
buffer | 25 | 0x02B0E6D8 | 0x02B0E933 | Process Termination | 32-bit | - |
...
|
||
index.dat | 25 | 0x00280000 | 0x0028FFFF | Process Termination | 32-bit | - |
...
|
||
index.dat | 25 | 0x00290000 | 0x00297FFF | Process Termination | 32-bit | - |
...
|
||
index.dat | 25 | 0x002A0000 | 0x002AFFFF | Process Termination | 32-bit | - |
...
|
||
index.dat | 25 | 0x025E0000 | 0x0261FFFF | Process Termination | 32-bit | - |
...
|
||
buffer | 30 | 0x00310020 | 0x003A0ECF | First Execution | 32-bit | 0x00310020 |
...
|
||
buffer | 30 | 0x04680000 | 0x0479AFFF | First Execution | 32-bit | 0x04680000 |
...
|
||
buffer | 31 | 0x00400000 | 0x00536FFF | First Execution | 32-bit | 0x00424141 |
...
|
||
buffer | 31 | 0x00188000 | 0x0018FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 31 | 0x00400000 | 0x00536FFF | First Network Behavior | 32-bit | 0x0040D000 |
...
|
||
buffer | 31 | 0x0072F1E8 | 0x0072F5A3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 31 | 0x0072F5B0 | 0x0072FDAF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 31 | 0x0072FDB8 | 0x007305B7 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 31 | 0x007305C0 | 0x007307DF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 31 | 0x00730C78 | 0x00730D45 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 31 | 0x00730EE8 | 0x00730F7F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 31 | 0x007314D8 | 0x00731589 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 31 | 0x00731598 | 0x0073162F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 31 | 0x00731828 | 0x007319C3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 31 | 0x00731A98 | 0x00731B29 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 31 | 0x00731BD8 | 0x00731CAD | First Network Behavior | 32-bit | - |
...
|
||
buffer | 31 | 0x00731D78 | 0x00731E03 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 31 | 0x00731E10 | 0x00731E8F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 31 | 0x00731FD0 | 0x007328BB | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 31 | 0x00240000 | 0x0024FFFF | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 31 | 0x00250000 | 0x00257FFF | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 31 | 0x00260000 | 0x0026FFFF | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 31 | 0x02620000 | 0x0265FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 31 | 0x00400000 | 0x00536FFF | Final Dump | 32-bit | 0x0041E031 |
...
|
||
buffer | 31 | 0x0072F1E8 | 0x0072F5A3 | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x0072F5B0 | 0x0072FDAF | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x0072FDB8 | 0x007305B7 | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x007305C0 | 0x007307DF | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x00730C78 | 0x00730D45 | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x00730EE8 | 0x00730F7F | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x007314D8 | 0x00731589 | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x00731598 | 0x0073162F | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x00731828 | 0x007319C3 | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x00731A98 | 0x00731B29 | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x00731BD8 | 0x00731CAD | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x00731D78 | 0x00731E03 | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x00731E10 | 0x00731E8F | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x00731FD0 | 0x007328BB | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x007476C0 | 0x0074791B | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x0074C2F0 | 0x0074CAEF | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x0074CAF8 | 0x0074CB97 | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x00790A98 | 0x00790B37 | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x007F1C90 | 0x007F1D2F | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x02A733E0 | 0x02A7347F | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x02A93F08 | 0x02A93FA7 | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x02AD3098 | 0x02AD32F3 | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x02ADB6B0 | 0x02ADBF9B | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x02ADBFA8 | 0x02ADC7B7 | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x02ADC7C0 | 0x02ADCA1B | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x02ADCA28 | 0x02ADCC83 | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x02ADCC90 | 0x02ADCEEB | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x02ADCEF8 | 0x02ADD153 | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x02ADD160 | 0x02ADD3BB | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x02ADD3C8 | 0x02ADD623 | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x02ADD630 | 0x02ADD88B | Final Dump | 32-bit | - |
...
|
||
buffer | 31 | 0x02ADD898 | 0x02ADDAF3 | Final Dump | 32-bit | - |
...
|
||
index.dat | 31 | 0x00240000 | 0x0024FFFF | Final Dump | 32-bit | - |
...
|
||
index.dat | 31 | 0x00250000 | 0x00257FFF | Final Dump | 32-bit | - |
...
|
||
index.dat | 31 | 0x00260000 | 0x0026FFFF | Final Dump | 32-bit | - |
...
|
||
index.dat | 31 | 0x02620000 | 0x0265FFFF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x0023F3D0 | 0x0023F78B | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x0023F798 | 0x0023FF97 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x0023FFA0 | 0x0024002B | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x00240038 | 0x00240837 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x00240840 | 0x002408BF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x002408C8 | 0x00240AE7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x002410B8 | 0x00241185 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x00241328 | 0x002413C3 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x00241730 | 0x002417F1 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x00241800 | 0x0024189B | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x00241A98 | 0x00241C33 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x00241D08 | 0x00241D99 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x00241E48 | 0x00241F1D | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x00241FE8 | 0x002428D3 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x0024DC98 | 0x0024DD19 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x0024DD28 | 0x0024DDA9 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x0024DDB8 | 0x0024DE39 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x0024E358 | 0x0024E3D9 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x00255C50 | 0x00255EAB | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x00256218 | 0x00256A27 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x00275448 | 0x002754E7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x00279BD8 | 0x00279CD7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x0027CD58 | 0x0027CDD7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x002DE470 | 0x002DE56F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x002F1140 | 0x002F12AB | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x0031DCC0 | 0x0031DDBF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x00400000 | 0x00536FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02AF8288 | 0x02AF8327 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02AFFEC0 | 0x02AFFF6F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02AFFF78 | 0x02B00027 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B0D200 | 0x02B0D2FF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B34860 | 0x02B349AF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B3FD28 | 0x02B3FDCD | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B4EE40 | 0x02B4F72B | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B4F738 | 0x02B4F993 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B4F9A0 | 0x02B4FBFB | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B4FC08 | 0x02B4FE63 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B4FE70 | 0x02B500CB | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B500D8 | 0x02B50333 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B50340 | 0x02B5059B | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B505A8 | 0x02B50803 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B50810 | 0x02B50A6B | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B50A78 | 0x02B50CD3 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B50CE0 | 0x02B50F3B | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B511D0 | 0x02B5135F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B51368 | 0x02B51981 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B63718 | 0x02B63F17 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B66FA0 | 0x02B671FB | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B67208 | 0x02B67463 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B67470 | 0x02B676CB | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B676D8 | 0x02B67933 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B67940 | 0x02B67B9B | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B67BA8 | 0x02B67E03 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B67E10 | 0x02B6806B | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B68078 | 0x02B682D3 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B682E0 | 0x02B6853B | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B68548 | 0x02B687A3 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B687B0 | 0x02B68A0B | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B68A18 | 0x02B68C73 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B68C80 | 0x02B68EDB | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B68EE8 | 0x02B69143 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B69150 | 0x02B693AB | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B693B8 | 0x02B69613 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B69620 | 0x02B6987B | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B69888 | 0x02B69AE3 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B69AF0 | 0x02B69D4B | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B69D58 | 0x02B69FB3 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B69FC0 | 0x02B6A21B | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B6A228 | 0x02B6A483 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B6A490 | 0x02B6A6EB | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B6A6F8 | 0x02B6A953 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B6A960 | 0x02B6ABBB | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B6ABC8 | 0x02B6AE23 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B6AFA0 | 0x02B6B0A5 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B6B400 | 0x02B6B503 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B6EFA0 | 0x02B6F1FB | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B6F208 | 0x02B6F463 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B6F470 | 0x02B6F6CB | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B6F6D8 | 0x02B6F933 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B6F940 | 0x02B6FB9B | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B6FBA8 | 0x02B6FE03 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B6FE10 | 0x02B7006B | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B70078 | 0x02B702D3 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B702E0 | 0x02B7053B | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B70548 | 0x02B707A3 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B707B0 | 0x02B70A0B | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B70A18 | 0x02B70C73 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B70C80 | 0x02B70EDB | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B70EE8 | 0x02B71143 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B71150 | 0x02B713AB | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B713B8 | 0x02B71613 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B71620 | 0x02B7187B | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B71888 | 0x02B71AE3 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B71AF0 | 0x02B71D4B | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B71D58 | 0x02B71FB3 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B71FC0 | 0x02B7221B | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B72228 | 0x02B72483 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B72490 | 0x02B726EB | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B726F8 | 0x02B72953 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B72960 | 0x02B72BBB | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B72BC8 | 0x02B72E23 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B74388 | 0x02B745E3 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B76710 | 0x02B767CF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B8AC08 | 0x02B8AE63 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02B9B988 | 0x02B9BBE3 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02BCBDA0 | 0x02BCC1E7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02BCD668 | 0x02BCDE87 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02BCDE90 | 0x02BCE4A9 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02BCE6A8 | 0x02BCEEB7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02BCEF00 | 0x02BCFF6F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02BD0510 | 0x02BD0DDF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02BD1608 | 0x02BD1EF3 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02BD1F00 | 0x02BD270F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02BD3BE8 | 0x02BD4BE7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02BDFBC8 | 0x02BDFF83 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EC0060 | 0x02EC02BB | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EC02C8 | 0x02EC0523 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EC0530 | 0x02EC078B | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EC0798 | 0x02EC09F3 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EC4048 | 0x02EC50B7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EC50C0 | 0x02EC5617 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EC70F8 | 0x02EC7907 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EC7910 | 0x02EC814F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EC8158 | 0x02EC8997 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EC89A0 | 0x02EC8B95 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EC8E40 | 0x02EC914F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02ED7998 | 0x02ED81B7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02ED8220 | 0x02ED8A3F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02ED8AA8 | 0x02ED92D7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02ED9330 | 0x02ED9B5F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02ED9BB8 | 0x02EDA3E7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EDA440 | 0x02EDAC6F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EDACC8 | 0x02EDB4E7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EDB550 | 0x02EDBD6F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EDBDD8 | 0x02EDC5F7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EDC660 | 0x02EDCE7F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EDCEE8 | 0x02EDD717 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EDD770 | 0x02EDDF9F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EDDFF8 | 0x02EDE827 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EDE880 | 0x02EDF09F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EDF108 | 0x02EDF927 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EDF990 | 0x02EE01AF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EE0218 | 0x02EE0A47 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EE0AA0 | 0x02EE12CF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EE1328 | 0x02EE1B47 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EE1BB0 | 0x02EE23CF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EE2438 | 0x02EE2C57 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EE2CC0 | 0x02EE34DF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EE3548 | 0x02EE3D77 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EE3DD0 | 0x02EE45FF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EE4658 | 0x02EE4E87 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EE4EE0 | 0x02EE570F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EE5768 | 0x02EE5F87 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EE5FF0 | 0x02EE680F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EE6878 | 0x02EE7097 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EE7980 | 0x02EE7FDF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EE7FE8 | 0x02EE8837 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EE8840 | 0x02EE908F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EE9098 | 0x02EE98D7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EE98E0 | 0x02EEA11F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EEA128 | 0x02EEA977 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EEA980 | 0x02EEB1CF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EEB1D8 | 0x02EEBA17 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EEBA20 | 0x02EEC25F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EEC280 | 0x02EECAAF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EECB08 | 0x02EED337 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EED390 | 0x02EEDBAF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EEDC18 | 0x02EEE437 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EEE4A0 | 0x02EEECBF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EEED28 | 0x02EEF557 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EEF5B0 | 0x02EEFDEF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EEFE38 | 0x02EF0667 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EF06C0 | 0x02EF0EEF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EF0F48 | 0x02EF1777 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EF17D0 | 0x02EF1FEF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EF2058 | 0x02EF2877 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EF28E0 | 0x02EF30FF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EF3168 | 0x02EF3997 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EF39F0 | 0x02EF421F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EF4278 | 0x02EF4A97 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EF4B00 | 0x02EF531F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EF5388 | 0x02EF5BA7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EF5C10 | 0x02EF643F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EF6498 | 0x02EF6CD7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EF6D20 | 0x02EF754F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EF75A8 | 0x02EF7DD7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EF7E30 | 0x02EF865F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EF86B8 | 0x02EF8ED7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EF8F40 | 0x02EF975F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EF97C8 | 0x02EF9FE7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EFA050 | 0x02EFA85F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EFA8D8 | 0x02EFB0E7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EFB160 | 0x02EFB96F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EFC268 | 0x02EFCAB7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EFCAC0 | 0x02EFD30F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EFD318 | 0x02EFDB57 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EFDB60 | 0x02EFE3AF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EFE3B8 | 0x02EFEC07 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EFEC10 | 0x02EFF41F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EFF428 | 0x02EFFC37 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02EFFC58 | 0x02F00467 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F004E0 | 0x02F00CEF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F00D68 | 0x02F01587 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F015F0 | 0x02F01E0F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F01E78 | 0x02F02697 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F02700 | 0x02F02F1F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F03810 | 0x02F0401F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F04098 | 0x02F048A7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F04920 | 0x02F0513F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F10E50 | 0x02F14E4F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F15E58 | 0x02F19E57 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F19F50 | 0x02F1A01F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F1FE88 | 0x02F1FF09 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F209C8 | 0x02F20A49 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F21E90 | 0x02F21FD7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F29B80 | 0x02F29C01 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F29C10 | 0x02F29C91 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F2A2D0 | 0x02F2A351 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F2A360 | 0x02F2A3E1 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F2BB68 | 0x02F2BD7F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F2BB68 | 0x02F2BD7F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F2BB68 | 0x02F2BD7F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F2BB68 | 0x02F2BD7F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F2BD90 | 0x02F2BFA7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F2BD90 | 0x02F2BFA7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F2BD90 | 0x02F2BFA7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F2BD90 | 0x02F2BFA7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F2BD90 | 0x02F2BFA7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F2BD90 | 0x02F2BFA7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F2BD90 | 0x02F2BFA7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F2BD90 | 0x02F2BFA7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F2BD90 | 0x02F2BFA7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F2BD90 | 0x02F2BFA7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F2BD90 | 0x02F2BFA7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F2BD90 | 0x02F2BFA7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F2BD90 | 0x02F2BFA7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F2BD90 | 0x02F2BFA7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F2BD90 | 0x02F2BFA7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F2BD90 | 0x02F2BFA7 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F343E8 | 0x02F345DD | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F345F0 | 0x02F347EF | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F39B38 | 0x02F39BB9 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F39BC8 | 0x02F39C49 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F39D78 | 0x02F39DF9 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F3AB88 | 0x02F3AC09 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F3C318 | 0x02F3C399 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F3C3A8 | 0x02F3C429 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F3C438 | 0x02F3C4B9 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F3C828 | 0x02F3C8A9 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F3C8B8 | 0x02F3C939 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F3D3E8 | 0x02F3D487 | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F3F3D0 | 0x02F40D2F | Final Dump | 32-bit | - |
...
|
||
buffer | 21 | 0x02F4BC18 | 0x02F59C27 | Final Dump | 32-bit | - |
...
|
||
index.dat | 21 | 0x00640000 | 0x0064FFFF | Final Dump | 32-bit | - |
...
|
||
index.dat | 21 | 0x00650000 | 0x00657FFF | Final Dump | 32-bit | - |
...
|
||
index.dat | 21 | 0x00660000 | 0x0066FFFF | Final Dump | 32-bit | - |
...
|
||
index.dat | 21 | 0x02840000 | 0x0287FFFF | Final Dump | 32-bit | - |
...
|
C:\Users\kEecfMwgj\Documents\p5HGkq_lz1hzZZQ1QzX\7lvhY-.pdf.neqp | Dropped File |
Suspicious
|
...
|
C:\Users\kEecfMwgj\Documents\1bZpFXJUkgMx2ljc8Ae7\S7LH3hXtiTTmcVgH\4kaBTKfDmjtKDpmZU4\uc2h_7ZMsMjV1wdpv4D.pdf.neqp | Dropped File |
Suspicious
|
...
|
c:\users\keecfmwgj\desktop\twnoq6e1v6eelj tb7f\djfpsjtvq\m-xa7lwudponnbqy.rtf.neqp | Dropped File | RTF |
Clean
|
...
|
òJ®·¾ŒòI›×\x8dýD`^tBæq¸²¿1’0kÏ/\x90T7#?øîÁP˜$\x90„x¨KÁ1‘‰mlUŒ“jƒªŽl^Ýx¨÷li£a]eê"GµøÉv~\x8d9\x8fÔ;vÔJÀbÀÑ‚ŒYDŠu0|ízÒ¡©KâÒ¬0ÂñHdJo1 õ]CÖSßõ*mìߺ³64f3 ÊLo.;‡MÙÒ“xw¥I©ÇM7–M%Ö3ÁË°‘溟RjwƒÈÅ(б\x81žÞK[ÀÉk;ÔÚ~𑺔Ê8ZÞGPVùA±UJ컦ÛKÏ\x909Þî»s¢¬B¢aÌ2•Ù$Æ*±Ñ†¬FQ4qKç¼·©=çÄsÁÜwíTgäš ÔöhIúô†-aéªÏŪwSGÎA±žóÐ ¨¨€™Ä´½*[öë!åCRÄÌzdp9úëy0Ó1*pfzv„ÏÁx<tIíþ²°DónjËû_ж²¶¥Š”Ejv(BÎ’>¯‘Økdßäç‘~½‘¿åž,X(Á•Ôޱ麥\x8f>¦^aÖÄ5WÁÉ쇛éŒAb̤f”„ Iî°BACîp³G+q³³† äØ¿ggVt ?‚r¬ÉQ"R•ÂzÈ$«L¯§¥x¤ö(šE½j\x90cØ.„Ñ£wÏ&ƒHò£´Á³\x8fºnRûS°ëù|»†_ž>PÊjü1ÇM4Hå؇Nµûµ`ÓóØ6vW!¥¢‚^\x9d0Q Âôåž4mzbû.9¨I*©¤0¶Ô†>݆»¥-¥ömÀE…èo¨#:>Ðé퇉øÈý"#Çü²Ðç°Œê àÖc³·ÖûòÿÕýV…9'aÔ\x90K«o@dÀ@פÙá§ävt0€ˆˆ&Ãñ4…F¬î;‚ø#àš_”¬Ö&î„T“¥Á«¾Õ ^Çóxù°§EPt€¹B éÀh”¿ÛZ‘¯Ÿ‘æ\x9ds ÚoÏud¥/Çjkg¤z–|ßĺI£š¦@:ìTȇYðÓþwT9×RX;‰C±¤ÒõiY>°¬ô¯Rî¡-QÊo¡\x81VÂÅsc7ñµU&$\x8f'lã)ßx±—¢ZCF%XNùC""\x8fГ ¥“Àó°ã6ÓùÅá9n©jhS·´éVS_6s\x9dPåóMêûÒʯӕûüQ4&â$»òPZù–½6ÿÒ¦µ‘dg]Ì7>ÞÅv@ÃáZ§n\x8dCîäÞÏp |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
c:\users\keecfmwgj\documents\outlook files\franc@gdllo.de.pst.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\1bZpFXJUkgMx2ljc8Ae7\A4HxEP_8V\GpPyohbyqjlYL-.xlsx.neqp | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\MXfa2rZxqyhANkfzM\fDxmHCHVp_.png.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\k5szpLuntD.wav.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\music\xbtul.mp3.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\music\ttf5tme9.mp3.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\h5j527Mxht9SX2raeS80.mp3.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\videos\gftzraq.flv.neqp | Dropped File | Video |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\rr YAk1x-tIpuyO.mp3.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\twnoq6e1v6eelj tb7f\djfpsjtvq\rngvq0d.mp3.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\3ebcktjarls9hlgrgq.docx.neqp | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\desktop\f1f3a2atwy iz-.png.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\MXfa2rZxqyhANkfzM\WFPEZk.png.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\1bzpfxjukgmx2ljc8ae7\fcf5zjaps1nelg.csv.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\1bzpfxjukgmx2ljc8ae7\71py6.ots.neqp | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\cmuJJwQRL0vhfEI.m4a.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\pictures\mxfa2rzxqyhankfzm\pkdosd r 3vyy2rn3diw.png.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\eM RQB1G7LkQ4Ned.wav.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\EwhZ8pVI.pptx.neqp | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\documents\n725zjx2gdficklh7td.docx.neqp | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\iwXXDcYVrRcebrg6X.swf.neqp | Dropped File | Shockwave Flash |
Clean
|
...
|
c:\users\keecfmwgj\pictures\ote5jpyt.jpg.neqp | Dropped File | Image |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\FfstE6t9XHw9p.docx.neqp | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\music\dkfwau.mp3.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\_xXA ucctq R.m4a.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\videos\wkvm-pmus0iogbh_dbp.flv.neqp | Dropped File | Video |
Clean
|
...
|
c:\users\keecfmwgj\desktop\twnoq6e1v6eelj tb7f\szqw0q07ao\uamkl9um1jjolc.m4a.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\hjiarewyjcogtlym7.swf.neqp | Dropped File | Shockwave Flash |
Clean
|
...
|
c:\users\keecfmwgj\pictures\mxfa2rzxqyhankfzm\v1fv6rf 5h82idznir.png.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\LE8AEqMT.wav.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\twnoq6e1v6eelj tb7f\djfpsjtvq\fojpf2zsdfusywc2q.m4a.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\twNoq6e1V6eeLj TB7f\DjfPSJtvQ\eGbXF478ccI5ln.mkv.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\music\rrbusch3n2s3k7tf26.wav.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\TnBDHjRthdvb1iavSOT.pptx.neqp | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\A8Ch.xlsx.neqp | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\pictures\mxfa2rzxqyhankfzm\rtumnxgo.gif.neqp | Dropped File | Image |
Clean
|
...
|
c:\users\keecfmwgj\videos\amp3as_oww3syrk.avi.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\1bZpFXJUkgMx2ljc8Ae7\A4HxEP_8V\c0Y tBs zGXD9sK\pe4_1B.pptx.neqp | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\desktop\twnoq6e1v6eelj tb7f\q_1qtsku9ca7q.jpg.neqp | Dropped File | Image |
Clean
|
...
|
c:\users\keecfmwgj\videos\8nyqrh805h9- og.avi.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\1bZpFXJUkgMx2ljc8Ae7\A4HxEP_8V\uYkNWJF11O37vr\FvaFjmImszyo741.ots.neqp | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\1bZpFXJUkgMx2ljc8Ae7\A4HxEP_8V\6ayIRleTh vq1qbRJ-L\jSVU\rH2o4l1w9Tc5d.pptx.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\pictures\mxfa2rzxqyhankfzm\gh3ediyqvyh.jpg.neqp | Dropped File | Image |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\1bZpFXJUkgMx2ljc8Ae7\A4HxEP_8V\uYkNWJF11O37vr\Wx5NaRQ.xlsx.neqp | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\UHzfZtepjKuO.wav.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\r17tM8VNaibQT6aoUz.flv.neqp | Dropped File | Video |
Clean
|
...
|
c:\users\keecfmwgj\desktop\twnoq6e1v6eelj tb7f\djfpsjtvq\tpxsaac.flv.neqp | Dropped File | Video |
Clean
|
...
|
c:\users\keecfmwgj\videos\dkxg1rgajlh0y0opia.mp4.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\7aLhib0HPyY.png.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\twnoq6e1v6eelj tb7f\zg2v3ms\sclrv.avi.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\yyculyebdke8.pptx.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\WzLSzXw7M.bmp.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\1bzpfxjukgmx2ljc8ae7\a4hxep_8v\uyknwjf11o37vr\gr566la_hbzp.docx.neqp | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\videos\8hk5sk-a_pdrv5z.avi.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\h_r0VYpvzAgf_0PUZHZ.docx.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\MXfa2rZxqyhANkfzM\RXmN gPo8AXsc.gif.neqp | Dropped File | Image |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\qo qbMr5VasZaX.flv.neqp | Dropped File | Video |
Clean
|
...
|
c:\users\keecfmwgj\videos\wb qjymk2xb5.avi.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\videos\wxg_cat-2c9o2tc5.mkv.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\oxbmof9d2mfzdb.avi.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\twnoq6e1v6eelj tb7f\djfpsjtvq\l_uac.ppt.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\S7cqNCqq0BA1-2AWyF.mp4.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\NsPZMxJeou0g1vK3d8z.mp3.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\zsmkkxcply mwj1j 8.mp3.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\pictures\mxfa2rzxqyhankfzm\yme7wbiiz.jpg.neqp | Dropped File | Image |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\twNoq6e1V6eeLj TB7f\szqw0q07Ao\gLy0rCq95A6.wav.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\TGEZ_H53zjM.swf.neqp | Dropped File | Shockwave Flash |
Clean
|
...
|
c:\users\keecfmwgj\desktop\rn0bvg.png.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\hUUFrkBWN6F.bmp.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\gcnsphuvaisovbzltws.xlsx.neqp | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\_B 9LyHgp8kWTgOV.mp4.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\twnoq6e1v6eelj tb7f\zg2v3ms\5qbgqs8xn8mkwdzflf.jpg.neqp | Dropped File | Image |
Clean
|
...
|
c:\users\keecfmwgj\documents\1bzpfxjukgmx2ljc8ae7\s7lh3hxtittmcvgh\4kabtkfdmjtkdpmzu4\zcggdbzd.odp.neqp | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\2Hs3CvzmY0a1.doc.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\videos\ke3zobew8cfbfyhp10.mkv.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\1bzpfxjukgmx2ljc8ae7\a4hxep_8v\uyknwjf11o37vr\uoffhzbfs_.xlsx.neqp | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\1bZpFXJUkgMx2ljc8Ae7\3BEbvfVE1d-gqz.doc.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\mqLZS9o6DtidQLz.m4a.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\twnoq6e1v6eelj tb7f\dxid.mp3.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\BBqFu3hstVTMPJkSfOH.mp3.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\q1-d.mkv.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\pictures\mxfa2rzxqyhankfzm\gfusf.jpg.neqp | Dropped File | Image |
Clean
|
...
|
c:\users\keecfmwgj\music\wv8wq.wav.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\1bZpFXJUkgMx2ljc8Ae7\S7LH3hXtiTTmcVgH\4kaBTKfDmjtKDpmZU4\T2Iy63 0g.csv.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\EcSir8.mp3.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\3r0MOWhcIDm.pptx.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\sxV MFLVBA-7.wav.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\music\xvszdq6io_y8wjxlgib.wav.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\tmPl-YXq5d584Uoy2.png.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\AQRFNBZ8zX.jpg.neqp | Dropped File | Image |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\_45H8TouB7ZmCtr3W4dN.swf.neqp | Dropped File | Shockwave Flash |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\U4sW0p.gif.neqp | Dropped File | Image |
Clean
|
...
|
c:\users\keecfmwgj\videos\stwus7dzu.swf.neqp | Dropped File | Shockwave Flash |
Clean
|
...
|
c:\users\keecfmwgj\music\uftb9wa27mlfv.mp3.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\r5XNSimbuw.xlsx.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\appdata\locallow\microsoft\internet explorer\services\search_{0633ee93-d776-472f-a0ff-e1416b8b2e3a}.ico.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\hnzlwvtZPb.avi.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\4HJuy4oV-6dm.gif.neqp | Dropped File | Image |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\1bZpFXJUkgMx2ljc8Ae7\S7LH3hXtiTTmcVgH\VDXnqC 6DK_84Fuegb.xlsx.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\XXOdFLkj1-284C.avi.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\AppData\LocalLow\Sun\Java\Deployment\deployment.properties.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\favorites\links\web slice gallery.url.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\favorites\microsoft websites\microsoft store.url.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\favorites\windows live\get windows live.url.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Favorites\MSN Websites\MSN Autos.url.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\favorites\windows live\windows live spaces.url.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\favorites\msn websites\msnbc news.url.neqp | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\favorites\msn websites\msn money.url.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Favorites\Microsoft Websites\Microsoft At Work.url.neqp | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Favorites\Windows Live\Windows Live Mail.url.neqp | Dropped File | Stream |
Clean
|
...
|
C:\SystemID\PersonalID.txt | Dropped File | Stream |
Clean
Known to be clean.
|
...
|
2852bd5d85e3046dff0382a6323717294f7e7500e808ff6c381ae123fd5776a5 | Downloaded File | Binary |
Clean
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x008E569E |
Size Of Code | 0x004E3800 |
Size Of Initialized Data | 0x00000800 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2023-05-30 19:43 (UTC) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00402000 | 0x004E36A4 | 0x004E3800 | 0x00000200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.86 |
.rsrc | 0x008E6000 | 0x000004D0 | 0x00000600 | 0x004E3A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.0 |
.reloc | 0x008E8000 | 0x0000000C | 0x00000200 | 0x004E4000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.0 |
132a5d3b0232783cbd6e1a02b9bc6eecb032b12a9843857fdbee736c1b640439 | Downloaded File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\AppData\Local\bowsakkdestx.txt | Downloaded File | Unknown |
Clean
|
...
|
4a1aaeed4747266983004f9fa25ff0ed024415f8232f30467b08441084b002e0 | Downloaded File | HTML |
Clean
|
...
|
c:\users\keecfmwgj\appdata\local\microsoft\windows\temporary internet files\content.ie5\x9ohk109\geo[1].json | Downloaded File | Unknown |
Clean
|
...
|
3470a6b9f33482f8f8bcabf86ca222992cbafa2fb2a0864abaa64e7a91d87d7e | Downloaded File | HTML |
Clean
|
...
|
f00d953518b6aa79bc02d98bf6626ddbc2b45ec477292cd5d8b09cb535c0d36a | Downloaded File | Stream |
Clean
|
...
|
ec376aee00528541763fca5293338302eb42e95237c7fcd3fd3d7af2ed434978 | Downloaded File | Stream |
Clean
|
...
|
b2ce910645dfc37215793af0742cdb787e18991c107de3af5fe745a7ba1c2e8d | Downloaded File | Stream |
Clean
|
...
|
c155100c733586f8042f9f4ab9ae255c44390f2ab8b0cf4c92caf2be1b1c2a7b | Downloaded File | Stream |
Clean
|
...
|
bd709e0027bd56d0a0db763153094edd605631743b8d961a5fb5e3d585a1d5ce | Downloaded File | Stream |
Clean
|
...
|
6e7b11f9d0fc25cdfb10db33b39e9474fb2f54efee5d43a40d35deee5de1172b | Downloaded File | Stream |
Clean
|
...
|
68c3d502ba5230fbeab7c93e9f49eda6c07d26f41ece661ba4544ae6ae5fc5a4 | Downloaded File | Stream |
Clean
|
...
|
ebe8f2214a013300bcfb60dd830dbe44c1522ed02fc98492cd8818cc65734832 | Downloaded File | Stream |
Clean
|
...
|
d66e03344f03222debdca221a38bd08480938f84b3c6779dd5d191e333799779 | Downloaded File | Stream |
Clean
|
...
|
60b58cd25d68734fcbd6d3e9542ef9ab2ed7d6b02fe196073b05d604b7890415 | Downloaded File | Stream |
Clean
|
...
|
feb4aa3b092f7dc2fafa0891687b8fe007898a5f4f705caf862eb3d25890d5c4 | Downloaded File | Stream |
Clean
|
...
|
50bf3ce479297c86596a3b1e8fbca604be0e41e684a0266cc0a8543ecb7160d9 | Downloaded File | Stream |
Clean
|
...
|
8365cace85761c3b80e8605fe9360d8c008e35eaeacf7d0aacc28b8485cf76b9 | Downloaded File | Stream |
Clean
|
...
|
3cbc3e0d99bc76790801aa061cdb3aa2cbdafc65be42da7fa130638191ff2c98 | Downloaded File | Stream |
Clean
|
...
|
8b8e83d2dde30fde592f97c079590dabdfbe15edd117cf385edf1930d6ce3c3b | Downloaded File | Stream |
Clean
|
...
|
0f1b4018a8255205b5a9a17efbb10fffdd444879c51643cf636fc3fcb96b4a0a | Downloaded File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\appdata\roaming\microsoft\windows\ietldcache\index.dat | Modified File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat | Modified File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\appdata\local\microsoft\windows\history\history.ie5\index.dat | Modified File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\appdata\roaming\microsoft\windows\cookies\index.dat | Modified File | Stream |
Clean
|
...
|