Malicious
Classifications
Ransomware
Threat Names
Ryuk
Dynamic Analysis Report
Created on 2023-03-09T18:54:28+00:00
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe
Windows Exe (x86-32)
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "1 minute, 40 seconds" to "20 seconds" to reveal dormant functionality.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\RDhJ0CNFevzX\Desktop\a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Verdict |
Malicious
|
PE Information
»
Image Base | 0x35000000 |
Entry Point | 0x350103D9 |
Size Of Code | 0x00023800 |
Size Of Initialized Data | 0x00063600 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2020-01-10 03:22 (UTC+1) |
Version Information (10)
»
LegalCopyright | Copyright (c) 2014 - . All rights reserved. InstallShield Software Corporation |
PrivateBuild | 5.4.6.373 |
InternalName | PortletReferencing |
ProductName | PortletReferencing |
CompanyName | InstallShield Software Corporation |
FileVersion | 5.4.6.373 |
OriginalFilename | PortletReferencing |
Languages | English |
FileDescription | When Excels Paintbrush |
ProductVersion | 5.4.6.373 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x35001000 | 0x00023619 | 0x00023800 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.66 |
.rdata | 0x35025000 | 0x00010D58 | 0x00010E00 | 0x00023C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.15 |
.data | 0x35036000 | 0x00004798 | 0x00001800 | 0x00034A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.52 |
.rsrc | 0x3503B000 | 0x00126F08 | 0x00051000 | 0x00036200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.27 |
Imports (21)
»
KERNEL32.dll (96)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CompareStringW | - | 0x350250A0 | 0x00034AFC | 0x000336FC | 0x000000A7 |
SetStdHandle | - | 0x350250A4 | 0x00034B00 | 0x00033700 | 0x0000052F |
HeapReAlloc | - | 0x350250A8 | 0x00034B04 | 0x00033704 | 0x00000354 |
CreateFileW | - | 0x350250AC | 0x00034B08 | 0x00033708 | 0x000000D6 |
LoadLibraryW | - | 0x350250B0 | 0x00034B0C | 0x0003370C | 0x000003C3 |
OutputDebugStringW | - | 0x350250B4 | 0x00034B10 | 0x00033710 | 0x00000415 |
GetOEMCP | - | 0x350250B8 | 0x00034B14 | 0x00033714 | 0x000002A0 |
GetACP | - | 0x350250BC | 0x00034B18 | 0x00033718 | 0x000001BE |
IsValidCodePage | - | 0x350250C0 | 0x00034B1C | 0x0003371C | 0x0000038D |
LoadLibraryExW | - | 0x350250C4 | 0x00034B20 | 0x00033720 | 0x000003C2 |
GetCPInfo | - | 0x350250C8 | 0x00034B24 | 0x00033724 | 0x000001CD |
FreeEnvironmentStringsW | - | 0x350250CC | 0x00034B28 | 0x00033728 | 0x000001B7 |
GetEnvironmentStringsW | - | 0x350250D0 | 0x00034B2C | 0x0003372C | 0x00000240 |
GetSystemTimeAsFileTime | - | 0x350250D4 | 0x00034B30 | 0x00033730 | 0x000002F4 |
GetCurrentProcessId | - | 0x350250D8 | 0x00034B34 | 0x00033734 | 0x00000224 |
QueryPerformanceCounter | - | 0x350250DC | 0x00034B38 | 0x00033738 | 0x0000043C |
GetCurrentThreadId | - | 0x350250E0 | 0x00034B3C | 0x0003373C | 0x00000228 |
InterlockedIncrement | - | 0x350250E4 | 0x00034B40 | 0x00033740 | 0x00000371 |
GetModuleHandleW | - | 0x350250E8 | 0x00034B44 | 0x00033744 | 0x00000281 |
TlsFree | - | 0x350250EC | 0x00034B48 | 0x00033748 | 0x00000582 |
TlsSetValue | - | 0x350250F0 | 0x00034B4C | 0x0003374C | 0x00000584 |
TlsGetValue | - | 0x350250F4 | 0x00034B50 | 0x00033750 | 0x00000583 |
TlsAlloc | - | 0x350250F8 | 0x00034B54 | 0x00033754 | 0x00000581 |
TerminateProcess | - | 0x350250FC | 0x00034B58 | 0x00033758 | 0x0000056F |
GetCurrentProcess | - | 0x35025100 | 0x00034B5C | 0x0003375C | 0x00000223 |
SetLastError | - | 0x35025104 | 0x00034B60 | 0x00033760 | 0x00000517 |
LCMapStringW | - | 0x35025108 | 0x00034B64 | 0x00033764 | 0x000003B1 |
UnhandledExceptionFilter | - | 0x3502510C | 0x00034B68 | 0x00033768 | 0x00000590 |
GetStartupInfoW | - | 0x35025110 | 0x00034B6C | 0x0003376C | 0x000002D7 |
DeleteCriticalSection | - | 0x35025114 | 0x00034B70 | 0x00033770 | 0x0000011E |
GetFileType | - | 0x35025118 | 0x00034B74 | 0x00033774 | 0x00000257 |
SetFilePointerEx | - | 0x3502511C | 0x00034B78 | 0x00033778 | 0x00000509 |
SetFilePointer | - | 0x35025120 | 0x00034B7C | 0x0003377C | 0x00000508 |
GetConsoleCP | - | 0x35025124 | 0x00034B80 | 0x00033780 | 0x000001F6 |
ReadConsoleW | - | 0x35025128 | 0x00034B84 | 0x00033784 | 0x00000456 |
GetConsoleMode | - | 0x3502512C | 0x00034B88 | 0x00033788 | 0x00000208 |
Sleep | - | 0x35025130 | 0x00034B8C | 0x0003378C | 0x0000055F |
HeapSize | - | 0x35025134 | 0x00034B90 | 0x00033790 | 0x00000356 |
RtlUnwind | - | 0x35025138 | 0x00034B94 | 0x00033794 | 0x000004BA |
InitializeCriticalSectionAndSpinCount | - | 0x3502513C | 0x00034B98 | 0x00033798 | 0x00000366 |
LeaveCriticalSection | - | 0x35025140 | 0x00034B9C | 0x0003379C | 0x000003BD |
EnterCriticalSection | - | 0x35025144 | 0x00034BA0 | 0x000337A0 | 0x00000140 |
GetModuleFileNameW | - | 0x35025148 | 0x00034BA4 | 0x000337A4 | 0x0000027D |
GetStdHandle | - | 0x3502514C | 0x00034BA8 | 0x000337A8 | 0x000002DD |
MultiByteToWideChar | - | 0x35025150 | 0x00034BAC | 0x000337AC | 0x000003EC |
WriteConsoleW | - | 0x35025154 | 0x00034BB0 | 0x000337B0 | 0x000005F0 |
FlushFileBuffers | - | 0x35025158 | 0x00034BB4 | 0x000337B4 | 0x000001AD |
GetStringTypeW | - | 0x3502515C | 0x00034BB8 | 0x000337B8 | 0x000002E2 |
SetEndOfFile | - | 0x35025160 | 0x00034BBC | 0x000337BC | 0x000004F6 |
CloseHandle | - | 0x35025164 | 0x00034BC0 | 0x000337C0 | 0x0000008E |
LockResource | - | 0x35025168 | 0x00034BC4 | 0x000337C4 | 0x000003D8 |
LoadLibraryA | - | 0x3502516C | 0x00034BC8 | 0x000337C8 | 0x000003C0 |
GetProcAddress | - | 0x35025170 | 0x00034BCC | 0x000337CC | 0x000002B5 |
GetLastError | - | 0x35025174 | 0x00034BD0 | 0x000337D0 | 0x0000026A |
SetTimeZoneInformation | - | 0x35025178 | 0x00034BD4 | 0x000337D4 | 0x0000054E |
MulDiv | - | 0x3502517C | 0x00034BD8 | 0x000337D8 | 0x000003EB |
GetFileAttributesW | - | 0x35025180 | 0x00034BDC | 0x000337DC | 0x0000024E |
GetFileAttributesA | - | 0x35025184 | 0x00034BE0 | 0x000337E0 | 0x00000249 |
GetConsoleWindow | - | 0x35025188 | 0x00034BE4 | 0x000337E4 | 0x00000213 |
CreateEventA | - | 0x3502518C | 0x00034BE8 | 0x000337E8 | 0x000000C7 |
SizeofResource | - | 0x35025190 | 0x00034BEC | 0x000337EC | 0x0000055E |
GlobalAlloc | - | 0x35025194 | 0x00034BF0 | 0x000337F0 | 0x00000335 |
FindResourceExA | - | 0x35025198 | 0x00034BF4 | 0x000337F4 | 0x000001A2 |
WriteFile | - | 0x3502519C | 0x00034BF8 | 0x000337F8 | 0x000005F1 |
GetModuleHandleExW | - | 0x350251A0 | 0x00034BFC | 0x000337FC | 0x00000280 |
InterlockedDecrement | - | 0x350251A4 | 0x00034C00 | 0x00033800 | 0x0000036D |
GetProcessHeap | - | 0x350251A8 | 0x00034C04 | 0x00033804 | 0x000002BA |
RaiseException | - | 0x350251AC | 0x00034C08 | 0x00033808 | 0x00000448 |
SetEnvironmentVariableA | - | 0x350251B0 | 0x00034C0C | 0x0003380C | 0x000004F9 |
WideCharToMultiByte | - | 0x350251B4 | 0x00034C10 | 0x00033810 | 0x000005DD |
GetTimeZoneInformation | - | 0x350251B8 | 0x00034C14 | 0x00033814 | 0x00000317 |
GetCommandLineW | - | 0x350251BC | 0x00034C18 | 0x00033818 | 0x000001E3 |
IsProcessorFeaturePresent | - | 0x350251C0 | 0x00034C1C | 0x0003381C | 0x00000388 |
IsDebuggerPresent | - | 0x350251C4 | 0x00034C20 | 0x00033820 | 0x00000383 |
ReadFile | - | 0x350251C8 | 0x00034C24 | 0x00033824 | 0x00000458 |
DeleteFileW | - | 0x350251CC | 0x00034C28 | 0x00033828 | 0x00000123 |
DecodePointer | - | 0x350251D0 | 0x00034C2C | 0x0003382C | 0x00000117 |
WaitForSingleObject | - | 0x350251D4 | 0x00034C30 | 0x00033830 | 0x000005BB |
LoadResource | - | 0x350251D8 | 0x00034C34 | 0x00033834 | 0x000003C6 |
MapUserPhysicalPages | - | 0x350251DC | 0x00034C38 | 0x00033838 | 0x000003D9 |
FindResourceA | - | 0x350251E0 | 0x00034C3C | 0x0003383C | 0x000001A1 |
CreateFileA | - | 0x350251E4 | 0x00034C40 | 0x00033840 | 0x000000CE |
EncodePointer | - | 0x350251E8 | 0x00034C44 | 0x00033844 | 0x0000013C |
HeapAlloc | - | 0x350251EC | 0x00034C48 | 0x00033848 | 0x0000034D |
HeapFree | - | 0x350251F0 | 0x00034C4C | 0x0003384C | 0x00000351 |
ExitProcess | - | 0x350251F4 | 0x00034C50 | 0x00033850 | 0x0000016D |
SetCurrentDirectoryW | - | 0x350251F8 | 0x00034C54 | 0x00033854 | 0x000004EF |
GetTempPathW | - | 0x350251FC | 0x00034C58 | 0x00033858 | 0x00000301 |
GetTempFileNameW | - | 0x35025200 | 0x00034C5C | 0x0003385C | 0x000002FF |
GetFileAttributesExW | - | 0x35025204 | 0x00034C60 | 0x00033860 | 0x0000024B |
FindNextFileW | - | 0x35025208 | 0x00034C64 | 0x00033864 | 0x0000019B |
GetModuleHandleA | - | 0x3502520C | 0x00034C68 | 0x00033868 | 0x0000027E |
FindClose | - | 0x35025210 | 0x00034C6C | 0x0003386C | 0x00000184 |
GetLogicalDriveStringsW | - | 0x35025214 | 0x00034C70 | 0x00033870 | 0x00000270 |
SetUnhandledExceptionFilter | - | 0x35025218 | 0x00034C74 | 0x00033874 | 0x00000550 |
FindFirstFileW | - | 0x3502521C | 0x00034C78 | 0x00033878 | 0x0000018F |
USER32.dll (62)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetSysColorBrush | - | 0x35025284 | 0x00034CE0 | 0x000338E0 | 0x000001A7 |
SendMessageW | - | 0x35025288 | 0x00034CE4 | 0x000338E4 | 0x000002B9 |
wsprintfW | - | 0x3502528C | 0x00034CE8 | 0x000338E8 | 0x00000376 |
DispatchMessageW | - | 0x35025290 | 0x00034CEC | 0x000338EC | 0x000000B6 |
DefWindowProcW | - | 0x35025294 | 0x00034CF0 | 0x000338F0 | 0x000000A1 |
DestroyIcon | - | 0x35025298 | 0x00034CF4 | 0x000338F4 | 0x000000AA |
UpdateWindow | - | 0x3502529C | 0x00034CF8 | 0x000338F8 | 0x00000353 |
GetMessageA | - | 0x350252A0 | 0x00034CFC | 0x000338FC | 0x0000016F |
GetWindowRect | - | 0x350252A4 | 0x00034D00 | 0x00033900 | 0x000001CA |
SetActiveWindow | - | 0x350252A8 | 0x00034D04 | 0x00033904 | 0x000002BC |
GetWindowDC | - | 0x350252AC | 0x00034D08 | 0x00033908 | 0x000001BF |
LoadStringA | - | 0x350252B0 | 0x00034D0C | 0x0003390C | 0x0000022E |
LoadBitmapA | - | 0x350252B4 | 0x00034D10 | 0x00033910 | 0x0000021B |
wsprintfA | - | 0x350252B8 | 0x00034D14 | 0x00033914 | 0x00000375 |
DrawIcon | - | 0x350252BC | 0x00034D18 | 0x00033918 | 0x000000CE |
GetClientRect | - | 0x350252C0 | 0x00034D1C | 0x0003391C | 0x00000126 |
SetFocus | - | 0x350252C4 | 0x00034D20 | 0x00033920 | 0x000002D1 |
SendMessageA | - | 0x350252C8 | 0x00034D24 | 0x00033924 | 0x000002B4 |
GetScrollRange | - | 0x350252CC | 0x00034D28 | 0x00033928 | 0x000001A2 |
GetDC | - | 0x350252D0 | 0x00034D2C | 0x0003392C | 0x00000135 |
InflateRect | - | 0x350252D4 | 0x00034D30 | 0x00033930 | 0x000001E3 |
SetRect | - | 0x350252D8 | 0x00034D34 | 0x00033934 | 0x000002EF |
CreateWindowExW | - | 0x350252DC | 0x00034D38 | 0x00033938 | 0x00000071 |
MessageBoxA | - | 0x350252E0 | 0x00034D3C | 0x0003393C | 0x00000244 |
GetWindowLongA | - | 0x350252E4 | 0x00034D40 | 0x00033940 | 0x000001C3 |
CreateWindowExA | - | 0x350252E8 | 0x00034D44 | 0x00033944 | 0x00000070 |
SetScrollPos | - | 0x350252EC | 0x00034D48 | 0x00033948 | 0x000002F2 |
ReleaseDC | - | 0x350252F0 | 0x00034D4C | 0x0003394C | 0x000002A2 |
EnableMenuItem | - | 0x350252F4 | 0x00034D50 | 0x00033950 | 0x000000E1 |
GetDlgItem | - | 0x350252F8 | 0x00034D54 | 0x00033954 | 0x0000013D |
ScrollWindow | - | 0x350252FC | 0x00034D58 | 0x00033958 | 0x000002AD |
DefWindowProcA | - | 0x35025300 | 0x00034D5C | 0x0003395C | 0x000000A0 |
GetCursorPos | - | 0x35025304 | 0x00034D60 | 0x00033960 | 0x00000134 |
LoadAcceleratorsA | - | 0x35025308 | 0x00034D64 | 0x00033964 | 0x00000219 |
SetWindowLongA | - | 0x3502530C | 0x00034D68 | 0x00033968 | 0x00000308 |
LoadBitmapW | - | 0x35025310 | 0x00034D6C | 0x0003396C | 0x0000021C |
IsDlgButtonChecked | - | 0x35025314 | 0x00034D70 | 0x00033970 | 0x000001FE |
DefDlgProcA | - | 0x35025318 | 0x00034D74 | 0x00033974 | 0x00000099 |
DefMDIChildProcA | - | 0x3502531C | 0x00034D78 | 0x00033978 | 0x0000009D |
MessageBoxW | - | 0x35025320 | 0x00034D7C | 0x0003397C | 0x0000024B |
GetSystemMetrics | - | 0x35025324 | 0x00034D80 | 0x00033980 | 0x000001A9 |
MapWindowPoints | - | 0x35025328 | 0x00034D84 | 0x00033984 | 0x0000023F |
EnableWindow | - | 0x3502532C | 0x00034D88 | 0x00033988 | 0x000000E5 |
FindWindowA | - | 0x35025330 | 0x00034D8C | 0x0003398C | 0x00000107 |
GetScrollPos | - | 0x35025334 | 0x00034D90 | 0x00033990 | 0x000001A1 |
GetDialogBaseUnits | - | 0x35025338 | 0x00034D94 | 0x00033994 | 0x00000139 |
GetWindowThreadProcessId | - | 0x3502533C | 0x00034D98 | 0x00033998 | 0x000001D2 |
MoveWindow | - | 0x35025340 | 0x00034D9C | 0x0003399C | 0x00000251 |
EndPaint | - | 0x35025344 | 0x00034DA0 | 0x000339A0 | 0x000000EA |
DestroyWindow | - | 0x35025348 | 0x00034DA4 | 0x000339A4 | 0x000000AD |
TranslateAcceleratorW | - | 0x3502534C | 0x00034DA8 | 0x000339A8 | 0x00000339 |
GetMessageW | - | 0x35025350 | 0x00034DAC | 0x000339AC | 0x00000173 |
PostQuitMessage | - | 0x35025354 | 0x00034DB0 | 0x000339B0 | 0x0000026E |
DialogBoxParamW | - | 0x35025358 | 0x00034DB4 | 0x000339B4 | 0x000000B3 |
LoadCursorW | - | 0x3502535C | 0x00034DB8 | 0x000339B8 | 0x00000220 |
BeginPaint | - | 0x35025360 | 0x00034DBC | 0x000339BC | 0x0000000E |
TranslateMessage | - | 0x35025364 | 0x00034DC0 | 0x000339C0 | 0x0000033B |
LoadAcceleratorsW | - | 0x35025368 | 0x00034DC4 | 0x000339C4 | 0x0000021A |
RegisterClassExW | - | 0x3502536C | 0x00034DC8 | 0x000339C8 | 0x00000286 |
LoadIconW | - | 0x35025370 | 0x00034DCC | 0x000339CC | 0x00000222 |
EndDialog | - | 0x35025374 | 0x00034DD0 | 0x000339D0 | 0x000000E8 |
ShowWindow | - | 0x35025378 | 0x00034DD4 | 0x000339D4 | 0x0000031C |
GDI32.dll (15)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
TextOutA | - | 0x35025058 | 0x00034AB4 | 0x000336B4 | 0x0000030A |
GetTextExtentPoint32A | - | 0x3502505C | 0x00034AB8 | 0x000336B8 | 0x0000023D |
SetTextColor | - | 0x35025060 | 0x00034ABC | 0x000336BC | 0x000002F8 |
CreateDIBSection | - | 0x35025064 | 0x00034AC0 | 0x000336C0 | 0x00000036 |
CreateFontA | - | 0x35025068 | 0x00034AC4 | 0x000336C4 | 0x0000003D |
GetDeviceCaps | - | 0x3502506C | 0x00034AC8 | 0x000336C8 | 0x000001EB |
SetBkMode | - | 0x35025070 | 0x00034ACC | 0x000336CC | 0x000002D1 |
DeleteObject | - | 0x35025074 | 0x00034AD0 | 0x000336D0 | 0x00000105 |
SelectObject | - | 0x35025078 | 0x00034AD4 | 0x000336D4 | 0x000002C9 |
CreateCompatibleDC | - | 0x3502507C | 0x00034AD8 | 0x000336D8 | 0x00000031 |
Rectangle | - | 0x35025080 | 0x00034ADC | 0x000336DC | 0x00000289 |
SaveDC | - | 0x35025084 | 0x00034AE0 | 0x000336E0 | 0x0000029A |
CreateFontW | - | 0x35025088 | 0x00034AE4 | 0x000336E4 | 0x00000042 |
Escape | - | 0x3502508C | 0x00034AE8 | 0x000336E8 | 0x0000014D |
RestoreDC | - | 0x35025090 | 0x00034AEC | 0x000336EC | 0x00000293 |
ADVAPI32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetKernelObjectSecurity | - | 0x35025000 | 0x00034A5C | 0x0003365C | 0x00000149 |
RegOpenKeyExW | - | 0x35025004 | 0x00034A60 | 0x00033660 | 0x00000289 |
RegCloseKey | - | 0x35025008 | 0x00034A64 | 0x00033664 | 0x00000258 |
GetInheritanceSourceA | - | 0x3502500C | 0x00034A68 | 0x00033668 | 0x00000147 |
CryptAcquireContextA | - | 0x35025010 | 0x00034A6C | 0x0003366C | 0x000000C0 |
GetFileSecurityA | - | 0x35025014 | 0x00034A70 | 0x00033670 | 0x00000143 |
RegQueryValueExW | - | 0x35025018 | 0x00034A74 | 0x00033674 | 0x00000296 |
SHELL32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | - | 0x35025260 | 0x00034CBC | 0x000338BC | 0x00000132 |
SHGetDiskFreeSpaceExW | - | 0x35025264 | 0x00034CC0 | 0x000338C0 | 0x000000BF |
SHGetDesktopFolder | - | 0x35025268 | 0x00034CC4 | 0x000338C4 | 0x000000BB |
SHGetFileInfoW | - | 0x3502526C | 0x00034CC8 | 0x000338C8 | 0x000000C3 |
ole32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StgOpenStorage | - | 0x35025394 | 0x00034DF0 | 0x000339F0 | 0x000001AE |
CreateStreamOnHGlobal | - | 0x35025398 | 0x00034DF4 | 0x000339F4 | 0x00000098 |
OLEAUT32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VarR8FromI4 | 0x00000050 | 0x3502523C | 0x00034C98 | 0x00033898 | - |
VarR8FromR4 | 0x00000051 | 0x35025240 | 0x00034C9C | 0x0003389C | - |
ODBC32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
None | 0x00000029 | 0x35025234 | 0x00034C90 | 0x00033890 | - |
COMCTL32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ImageList_Create | - | 0x35025030 | 0x00034A8C | 0x0003368C | 0x00000053 |
ImageList_ReplaceIcon | - | 0x35025034 | 0x00034A90 | 0x00033690 | 0x0000006F |
None | 0x00000011 | 0x35025038 | 0x00034A94 | 0x00033694 | - |
ImageList_AddMasked | - | 0x3502503C | 0x00034A98 | 0x00033698 | 0x0000004F |
WININET.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InternetCloseHandle | - | 0x3502538C | 0x00034DE8 | 0x000339E8 | 0x0000008F |
NETAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetWkstaUserGetInfo | - | 0x3502522C | 0x00034C88 | 0x00033888 | 0x00000104 |
AVIFIL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
AVIStreamGetFrameOpen | - | 0x35025028 | 0x00034A84 | 0x00033684 | 0x00000029 |
AVICAP32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
capGetDriverDescriptionA | - | 0x35025020 | 0x00034A7C | 0x0003367C | 0x00000003 |
MSIMG32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GradientFill | - | 0x35025224 | 0x00034C80 | 0x00033880 | 0x00000002 |
CRYPT32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CertGetNameStringA | - | 0x35025044 | 0x00034AA0 | 0x000336A0 | 0x0000004A |
SHLWAPI.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathAppendA | - | 0x35025274 | 0x00034CD0 | 0x000338D0 | 0x00000037 |
Secur32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
QueryContextAttributesA | - | 0x3502527C | 0x00034CD8 | 0x000338D8 | 0x00000032 |
OPENGL32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
glMatrixMode | - | 0x35025248 | 0x00034CA4 | 0x000338A4 | 0x000000B5 |
glBegin | - | 0x3502524C | 0x00034CA8 | 0x000338A8 | 0x0000000A |
glVertex2f | - | 0x35025250 | 0x00034CAC | 0x000338AC | 0x0000013F |
glEnd | - | 0x35025254 | 0x00034CB0 | 0x000338B0 | 0x00000051 |
glClearColor | - | 0x35025258 | 0x00034CB4 | 0x000338B4 | 0x00000012 |
GLU32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
gluOrtho2D | - | 0x35025098 | 0x00034AF4 | 0x000336F4 | 0x0000001E |
USP10.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ScriptCacheGetHeight | - | 0x35025380 | 0x00034DDC | 0x000339DC | 0x00000005 |
ScriptFreeCache | - | 0x35025384 | 0x00034DE0 | 0x000339E0 | 0x00000006 |
DCIMAN32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DCISetClipList | - | 0x3502504C | 0x00034AA8 | 0x000336A8 | 0x0000000A |
DCISetDestination | - | 0x35025050 | 0x00034AAC | 0x000336AC | 0x0000000B |
Digital Signature Information
»
Verification Status | Valid |
Certificate: PET PLUS PTY LTD
»
Issued by | PET PLUS PTY LTD |
Parent Certificate | DigiCert EV Code Signing CA (SHA2) |
Country Name | AU |
Valid From | 2019-12-27 01:00 (UTC+1) |
Valid Until | 2021-01-06 13:00 (UTC+1) |
Algorithm | sha256_rsa |
Serial Number | 01 CF 0B 0F 01 B2 0B 70 BF AA 69 72 29 79 EF 5C |
Thumbprint | 77 FE B9 39 00 C2 C6 99 44 1F 61 17 A7 B3 DE 1C F3 16 50 74 |
Revoked Since | 2019-12-27 01:00 (UTC+1) |
Certificate: DigiCert EV Code Signing CA (SHA2)
»
Issued by | DigiCert EV Code Signing CA (SHA2) |
Country Name | US |
Valid From | 2012-04-18 14:00 (UTC+2) |
Valid Until | 2027-04-18 14:00 (UTC+2) |
Algorithm | sha256_rsa |
Serial Number | 03 F1 B4 E1 5F 3A 82 F1 14 96 78 B3 D7 D8 47 5C |
Thumbprint | 60 EE 3F C5 3D 4B DF D1 69 7A E5 BE AE 1C AB 1C 0F 3A D4 E3 |
Memory Dumps (89)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Relevant Image |
![]() |
32-bit | 0x3501161D |
![]() |
...
|
buffer | 1 | 0x00198000 | 0x0019FFFF | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x0049F8B8 | 0x0049F98D | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x004A3178 | 0x004A3245 | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x004A3E68 | 0x004A4087 | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x004A73E0 | 0x004A745F | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x004A7AC0 | 0x004A7B4F | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x004A7BA8 | 0x004A7CEB | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x004ABE40 | 0x004ABF07 | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x004B2A88 | 0x004B2E43 | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x004B2E50 | 0x004B364F | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x004B3E60 | 0x004B465F | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x004B4CE0 | 0x004B4D6F | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x004C1EC8 | 0x004C26C7 | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x004CCAC8 | 0x004CEA63 | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x02000000 | 0x02036FFF | First Execution |
![]() |
32-bit | 0x02000000 |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | First Network Behavior |
![]() |
32-bit | 0x35014EB3 |
![]() |
...
|
counters.dat | 1 | 0x02050000 | 0x02050FFF | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 1 | 0x02000000 | 0x02036FFF | Content Changed |
![]() |
32-bit | 0x020029BE |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x35005AA3 |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x35006070 |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x3500EAB6 |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x350016DB |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x35009C95 |
![]() |
...
|
oghbmcipslan.exe | 2 | 0x35000000 | 0x35161FFF | Relevant Image |
![]() |
32-bit | 0x3501161D |
![]() |
...
|
buffer | 2 | 0x00198000 | 0x0019FFFF | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 2 | 0x00552560 | 0x005525F7 | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 2 | 0x00557208 | 0x00557297 | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 2 | 0x005572F0 | 0x0055736F | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 2 | 0x00557830 | 0x00557905 | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 2 | 0x00557978 | 0x00557ABB | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 2 | 0x0055B4F0 | 0x0055B5B7 | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 2 | 0x00560EA0 | 0x0056169F | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 2 | 0x00562418 | 0x00562637 | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 2 | 0x00563B68 | 0x00563F23 | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 2 | 0x0056C338 | 0x0056CB37 | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 2 | 0x005794D0 | 0x00579CCF | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 2 | 0x00583CE0 | 0x00585C7B | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 2 | 0x027F0000 | 0x02826FFF | First Execution |
![]() |
32-bit | 0x027F0000 |
![]() |
...
|
oghbmcipslan.exe | 2 | 0x35000000 | 0x35161FFF | First Network Behavior |
![]() |
32-bit | 0x350037B0 |
![]() |
...
|
counters.dat | 2 | 0x02830000 | 0x02830FFF | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
mcbyiqsuvlan.exe | 3 | 0x35000000 | 0x35161FFF | Relevant Image |
![]() |
32-bit | 0x3501161D |
![]() |
...
|
buffer | 3 | 0x00198000 | 0x0019FFFF | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 3 | 0x004E0000 | 0x00516FFF | First Execution |
![]() |
32-bit | 0x004E0000 |
![]() |
...
|
buffer | 3 | 0x0053F4F8 | 0x0053F577 | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 3 | 0x00542560 | 0x005425F7 | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 3 | 0x00543E50 | 0x0054406F | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 3 | 0x00547068 | 0x005471AB | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 3 | 0x005472F0 | 0x0054737F | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 3 | 0x00547A10 | 0x00547AE5 | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 3 | 0x0054A9B8 | 0x0054AA7F | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 3 | 0x00550EC8 | 0x005516C7 | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 3 | 0x00553B90 | 0x00553F4B | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 3 | 0x0055C360 | 0x0055CB5F | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 3 | 0x005692D0 | 0x00569ACF | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
buffer | 3 | 0x00572E70 | 0x00574E0B | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
mcbyiqsuvlan.exe | 3 | 0x35000000 | 0x35161FFF | First Network Behavior |
![]() |
32-bit | 0x35014EB3 |
![]() |
...
|
counters.dat | 3 | 0x00520000 | 0x00520FFF | First Network Behavior |
![]() |
32-bit | - |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x35006D81 |
![]() |
...
|
buffer | 2 | 0x027F0000 | 0x02826FFF | Content Changed |
![]() |
32-bit | 0x027F29BE |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x350025C8 |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x35001B3A |
![]() |
...
|
buffer | 3 | 0x004E0000 | 0x00516FFF | Content Changed |
![]() |
32-bit | 0x004E29BE |
![]() |
...
|
oghbmcipslan.exe | 2 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x35005AA3 |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x35006D81 |
![]() |
...
|
oghbmcipslan.exe | 2 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x35008190 |
![]() |
...
|
mcbyiqsuvlan.exe | 3 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x35005AA3 |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x350025C8 |
![]() |
...
|
mcbyiqsuvlan.exe | 3 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x35006070 |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x350052A3 |
![]() |
...
|
mcbyiqsuvlan.exe | 3 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x35009645 |
![]() |
...
|
mcbyiqsuvlan.exe | 3 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x3500D1ED |
![]() |
...
|
mcbyiqsuvlan.exe | 3 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x35003765 |
![]() |
...
|
buffer | 1 | 0x09040000 | 0x09041FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x35004078 |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x35006D81 |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x3500294C |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x35008072 |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x35004086 |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x35006D81 |
![]() |
...
|
buffer | 1 | 0x02950000 | 0x02951FFF | Content Changed |
![]() |
32-bit | - |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x35007000 |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x35004086 |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x35006D81 |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x350025D8 |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x35008072 |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x35001031 |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x35006D81 |
![]() |
...
|
a9643eb83d509ad4eac20a2a89d8571f8d781979ad078e89f5b75b4bcb16f65e.exe | 1 | 0x35000000 | 0x35161FFF | Content Changed |
![]() |
32-bit | 0x35007000 |
![]() |
...
|
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\User Account Pictures\guest.bmp.RYK | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\user account pictures\user.bmp.ryk | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Office\MySharePoints.ico.RYK | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\office\sharepointteamsite.ico.ryk | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Office\MySite.ico.RYK | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\office\documentrepository.ico.ryk | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Office\SharePointPortalSite.ico.RYK | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.001.etl.RYK | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\MF\Active.GRL.RYK | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\MF\Pending.GRL.RYK | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.012.etl.RYK | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.004.etl.RYK | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.008.etl.RYK | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.007.etl.RYK | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\usoshared\logs\updatesessionorchestration.006.etl.ryk | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.010.etl.RYK | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\usoshared\logs\updatesessionorchestration.002.etl.ryk | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\usoshared\logs\updatesessionorchestration.005.etl.ryk | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\usoshared\logs\updatesessionorchestration.009.etl.ryk | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\usoshared\logs\updatesessionorchestration.003.etl.ryk | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\usoshared\logs\updatesessionorchestration.011.etl.ryk | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateSessionOrchestration.015.etl.RYK | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft help\nslist.hxl.ryk | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Office\AssetLibrary.ico.RYK | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\User Account Pictures\guest.png.RYK | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\User Account Pictures\user.png.RYK | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows Live\WLive48x48.png.RYK | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\usoshared\logs\updatesessionorchestration.013.etl.ryk | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\usoshared\logs\updatesessionorchestration.014.etl.ryk | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateUx.001.etl.RYK | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\USOShared\Logs\UpdateUx.002.etl.RYK | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\DownloadedScenarios\Windows.Uif.static.RYK | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\user account pictures\user-192.png.ryk | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\clicktorun\deploymentconfig.0.xml.ryk | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\clicktorun\deploymentconfig.1.xml.ryk | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Diagnosis\DownloadedSettings\utc.app.json.bk.RYK | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\clicktorun\deploymentconfig.2.xml.ryk | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\user account pictures\user-48.png.ryk | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\User Account Pictures\user-40.png.RYK | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft Help\MS.SPREADSHEETCOMPARE.16.1033.hxn.RYK | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\vault\ac658cb4-9126-49bd-b877-31eedab3f204\policy.vpol.ryk | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft help\ms.databasecompare.16.1033.hxn.ryk | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\User Account Pictures\user-32.png.RYK | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft Help\MS.SKYPEFB_ONLINEG.16.1033.hxn.RYK | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft Help\MS.SKYPEFB_ONLINE.16.1033.hxn.RYK | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft Help\MS.LYNC_ONLINE.16.1033.hxn.RYK | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft Help\MS.SKYPEFB_BASIC.16.1033.hxn.RYK | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft Help\MS.LYNC_BASIC.16.1033.hxn.RYK | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft Help\MS.MSACCESS.16.1033.hxn.RYK | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft help\ms.powerpnt.16.1033.hxn.ryk | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft Help\MS.SETLANG.16.1033.hxn.RYK | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft Help\MS.GROOVE.16.1033.hxn.RYK | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft help\ms.onenote.16.1033.hxn.ryk | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft help\ms.outlook.16.1033.hxn.ryk | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft help\ms.winword.16.1033.hxn.ryk | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft help\ms.skypefb.16.1033.hxn.ryk | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft help\ms.lync.16.1033.hxn.ryk | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft help\ms.mspub.16.1033.hxn.ryk | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft help\ms.msouc.16.1033.hxn.ryk | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft help\ms.graph.16.1033.hxn.ryk | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft Help\MS.EXCEL.16.1033.hxn.RYK | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Java\Visit Java.com.url.RYK | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\start menu\programs\java\get help.url.ryk | Dropped File | Stream |
Malicious
|
...
|
»
c:\documents and settings\all users\application data\application data\application data\application data\application data\application data\application data\application data\application data\application data\microsoft\windows defender\scans\mpdiag.bin.ryk | Dropped File | Stream |
Malicious
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Oracle\Java\installcache_x64\baseimagefam8.RYK | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDHJ0C~1\AppData\Local\Temp\tmp22B.tmp | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDHJ0C~1\AppData\Local\Temp\tmp22B.tmp | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDHJ0C~1\AppData\Local\Temp\tmp926F.tmp | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDHJ0C~1\AppData\Local\Temp\tmpEABB.tmp | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDHJ0C~1\AppData\Local\Temp\tmpEABB.tmp | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDHJ0C~1\AppData\Local\Temp\tmp926F.tmp | Dropped File | Stream |
Clean
|
...
|
»
c:\programdata\microsoft\crypto\rsa\machinekeys\08e575673cce10c72090304839888e02_03845cb8-7441-4a2f-8c0f-c90408af5778 | Dropped File | Stream |
Clean
|
...
|
»
C:\Boot\BCD.LOG1.RYK | Dropped File | Empty |
Clean
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Office\ClickToRunPackageLocker.RYK | Dropped File | Empty |
Clean
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Provisioning\countrytable.xml.RYK | Dropped File | Empty |
Clean
|
...
|
»
C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\User Account Pictures\RDhJ0CNFevzX.dat.RYK | Dropped File | Empty |
Clean
|
...
|
»
c:\boot\bcd.log2.ryk | Dropped File | Empty |
Clean
|
...
|
»
c:\users\rdhj0cnfevzx\appdata\local\microsoft\windows\inetcache\counters.dat | Modified File | Empty |
Clean
|
...
|
»
8d97ea59a05f47e6c647529d6b09bb8d05cce92f90804de1bceb4c900e1b773c | Extracted File | Image |
Clean
|
...
|
»
5ccbe44e7595305929197e320877394afb26d47016b00bc27e521be02d87e672 | Extracted File | Image |
Clean
|
...
|
»
b950c2c3cf4447549a7d11db78fe8abbad74cfd8dbba3a454785ea62aad99307 | Extracted File | Image |
Clean
|
...
|
»
e0661a5f4ae6ac42645a31db263d62b965686ed8df788482c65cbfa5c3e9922d | Extracted File | Image |
Clean
|
...
|
»