VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Wiper, Ransomware, Trojan |
Academics.pdf.exe
Windows Exe (x86-32)
Created at 2019-05-13T21:56:00
Remarks
(0x200001b): The maximum number of file reputation requests per analysis (20) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Academics.pdf.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Suspicious
|
First Seen | 2019-05-11 06:20 (UTC+2) |
Last Seen | 2019-05-12 11:22 (UTC+2) |
Names | Win32.Trojan.Banker |
Families | Banker |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4165c1 |
Size Of Code | 0x80800 |
Size Of Initialized Data | 0x1dc00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2012-01-29 21:32:28+00:00 |
Version Information (3)
»
CompiledScript | AutoIt v3 Script: 3, 3, 8, 1 |
FileDescription | - |
FileVersion | 3, 3, 8, 1 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x8061c | 0x80800 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.68 |
.rdata | 0x482000 | 0xdfc0 | 0xe000 | 0x80c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.8 |
.data | 0x490000 | 0x1a758 | 0x6800 | 0x8ec00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.15 |
.rsrc | 0x4ab000 | 0x12180 | 0x12200 | 0x95400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.32 |
Imports (16)
»
WSOCK32.dll (22)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
__WSAFDIsSet | 0x97 | 0x482794 | 0x8dd04 | 0x8c904 | - |
setsockopt | 0x15 | 0x482798 | 0x8dd08 | 0x8c908 | - |
ntohs | 0xf | 0x48279c | 0x8dd0c | 0x8c90c | - |
recvfrom | 0x11 | 0x4827a0 | 0x8dd10 | 0x8c910 | - |
sendto | 0x14 | 0x4827a4 | 0x8dd14 | 0x8c914 | - |
htons | 0x9 | 0x4827a8 | 0x8dd18 | 0x8c918 | - |
select | 0x12 | 0x4827ac | 0x8dd1c | 0x8c91c | - |
listen | 0xd | 0x4827b0 | 0x8dd20 | 0x8c920 | - |
WSAStartup | 0x73 | 0x4827b4 | 0x8dd24 | 0x8c924 | - |
bind | 0x2 | 0x4827b8 | 0x8dd28 | 0x8c928 | - |
closesocket | 0x3 | 0x4827bc | 0x8dd2c | 0x8c92c | - |
connect | 0x4 | 0x4827c0 | 0x8dd30 | 0x8c930 | - |
socket | 0x17 | 0x4827c4 | 0x8dd34 | 0x8c934 | - |
send | 0x13 | 0x4827c8 | 0x8dd38 | 0x8c938 | - |
WSACleanup | 0x74 | 0x4827cc | 0x8dd3c | 0x8c93c | - |
ioctlsocket | 0xa | 0x4827d0 | 0x8dd40 | 0x8c940 | - |
accept | 0x1 | 0x4827d4 | 0x8dd44 | 0x8c944 | - |
WSAGetLastError | 0x6f | 0x4827d8 | 0x8dd48 | 0x8c948 | - |
inet_addr | 0xb | 0x4827dc | 0x8dd4c | 0x8c94c | - |
gethostbyname | 0x34 | 0x4827e0 | 0x8dd50 | 0x8c950 | - |
gethostname | 0x39 | 0x4827e4 | 0x8dd54 | 0x8c954 | - |
recv | 0x10 | 0x4827e8 | 0x8dd58 | 0x8c958 | - |
VERSION.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VerQueryValueW | 0x0 | 0x482738 | 0x8dca8 | 0x8c8a8 | 0xe |
GetFileVersionInfoW | 0x0 | 0x48273c | 0x8dcac | 0x8c8ac | 0x6 |
GetFileVersionInfoSizeW | 0x0 | 0x482740 | 0x8dcb0 | 0x8c8b0 | 0x5 |
WINMM.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
timeGetTime | 0x0 | 0x482784 | 0x8dcf4 | 0x8c8f4 | 0x94 |
waveOutSetVolume | 0x0 | 0x482788 | 0x8dcf8 | 0x8c8f8 | 0xbb |
mciSendStringW | 0x0 | 0x48278c | 0x8dcfc | 0x8c8fc | 0x32 |
COMCTL32.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ImageList_Remove | 0x0 | 0x48208c | 0x8d5fc | 0x8c1fc | 0x6d |
ImageList_SetDragCursorImage | 0x0 | 0x482090 | 0x8d600 | 0x8c200 | 0x72 |
ImageList_BeginDrag | 0x0 | 0x482094 | 0x8d604 | 0x8c204 | 0x50 |
ImageList_DragEnter | 0x0 | 0x482098 | 0x8d608 | 0x8c208 | 0x56 |
ImageList_DragLeave | 0x0 | 0x48209c | 0x8d60c | 0x8c20c | 0x57 |
ImageList_EndDrag | 0x0 | 0x4820a0 | 0x8d610 | 0x8c210 | 0x5e |
ImageList_DragMove | 0x0 | 0x4820a4 | 0x8d614 | 0x8c214 | 0x58 |
ImageList_ReplaceIcon | 0x0 | 0x4820a8 | 0x8d618 | 0x8c218 | 0x6f |
ImageList_Create | 0x0 | 0x4820ac | 0x8d61c | 0x8c21c | 0x53 |
InitCommonControlsEx | 0x0 | 0x4820b0 | 0x8d620 | 0x8c220 | 0x7b |
ImageList_Destroy | 0x0 | 0x4820b4 | 0x8d624 | 0x8c224 | 0x54 |
MPR.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetCancelConnection2W | 0x0 | 0x4823d8 | 0x8d948 | 0x8c548 | 0xc |
WNetGetConnectionW | 0x0 | 0x4823dc | 0x8d94c | 0x8c54c | 0x24 |
WNetAddConnection2W | 0x0 | 0x4823e0 | 0x8d950 | 0x8c550 | 0x6 |
WNetUseConnectionW | 0x0 | 0x4823e4 | 0x8d954 | 0x8c554 | 0x49 |
WININET.dll (14)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InternetReadFile | 0x0 | 0x482748 | 0x8dcb8 | 0x8c8b8 | 0x9f |
InternetCloseHandle | 0x0 | 0x48274c | 0x8dcbc | 0x8c8bc | 0x6b |
InternetOpenW | 0x0 | 0x482750 | 0x8dcc0 | 0x8c8c0 | 0x9a |
InternetSetOptionW | 0x0 | 0x482754 | 0x8dcc4 | 0x8c8c4 | 0xaf |
InternetCrackUrlW | 0x0 | 0x482758 | 0x8dcc8 | 0x8c8c8 | 0x74 |
HttpQueryInfoW | 0x0 | 0x48275c | 0x8dccc | 0x8c8cc | 0x5a |
InternetConnectW | 0x0 | 0x482760 | 0x8dcd0 | 0x8c8d0 | 0x72 |
HttpOpenRequestW | 0x0 | 0x482764 | 0x8dcd4 | 0x8c8d4 | 0x58 |
HttpSendRequestW | 0x0 | 0x482768 | 0x8dcd8 | 0x8c8d8 | 0x5e |
FtpOpenFileW | 0x0 | 0x48276c | 0x8dcdc | 0x8c8dc | 0x35 |
FtpGetFileSize | 0x0 | 0x482770 | 0x8dce0 | 0x8c8e0 | 0x32 |
InternetOpenUrlW | 0x0 | 0x482774 | 0x8dce4 | 0x8c8e4 | 0x99 |
InternetQueryOptionW | 0x0 | 0x482778 | 0x8dce8 | 0x8c8e8 | 0x9e |
InternetQueryDataAvailable | 0x0 | 0x48277c | 0x8dcec | 0x8c8ec | 0x9b |
PSAPI.DLL (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EnumProcesses | 0x0 | 0x482450 | 0x8d9c0 | 0x8c5c0 | 0x6 |
GetModuleBaseNameW | 0x0 | 0x482454 | 0x8d9c4 | 0x8c5c4 | 0xe |
GetProcessMemoryInfo | 0x0 | 0x482458 | 0x8d9c8 | 0x8c5c8 | 0x15 |
EnumProcessModules | 0x0 | 0x48245c | 0x8d9cc | 0x8c5cc | 0x4 |
USERENV.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateEnvironmentBlock | 0x0 | 0x482724 | 0x8dc94 | 0x8c894 | 0x0 |
DestroyEnvironmentBlock | 0x0 | 0x482728 | 0x8dc98 | 0x8c898 | 0x4 |
UnloadUserProfile | 0x0 | 0x48272c | 0x8dc9c | 0x8c89c | 0x2c |
LoadUserProfileW | 0x0 | 0x482730 | 0x8dca0 | 0x8c8a0 | 0x21 |
KERNEL32.dll (159)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
HeapAlloc | 0x0 | 0x482158 | 0x8d6c8 | 0x8c2c8 | 0x2cb |
Sleep | 0x0 | 0x48215c | 0x8d6cc | 0x8c2cc | 0x4b2 |
GetCurrentThreadId | 0x0 | 0x482160 | 0x8d6d0 | 0x8c2d0 | 0x1c5 |
RaiseException | 0x0 | 0x482164 | 0x8d6d4 | 0x8c2d4 | 0x3b1 |
MulDiv | 0x0 | 0x482168 | 0x8d6d8 | 0x8c2d8 | 0x366 |
GetVersionExW | 0x0 | 0x48216c | 0x8d6dc | 0x8c2dc | 0x2a4 |
GetSystemInfo | 0x0 | 0x482170 | 0x8d6e0 | 0x8c2e0 | 0x273 |
InterlockedIncrement | 0x0 | 0x482174 | 0x8d6e4 | 0x8c2e4 | 0x2ef |
InterlockedDecrement | 0x0 | 0x482178 | 0x8d6e8 | 0x8c2e8 | 0x2eb |
WideCharToMultiByte | 0x0 | 0x48217c | 0x8d6ec | 0x8c2ec | 0x511 |
lstrcpyW | 0x0 | 0x482180 | 0x8d6f0 | 0x8c2f0 | 0x548 |
MultiByteToWideChar | 0x0 | 0x482184 | 0x8d6f4 | 0x8c2f4 | 0x367 |
lstrlenW | 0x0 | 0x482188 | 0x8d6f8 | 0x8c2f8 | 0x54e |
lstrcmpiW | 0x0 | 0x48218c | 0x8d6fc | 0x8c2fc | 0x545 |
GetModuleHandleW | 0x0 | 0x482190 | 0x8d700 | 0x8c300 | 0x218 |
QueryPerformanceCounter | 0x0 | 0x482194 | 0x8d704 | 0x8c304 | 0x3a7 |
VirtualFreeEx | 0x0 | 0x482198 | 0x8d708 | 0x8c308 | 0x4ed |
OpenProcess | 0x0 | 0x48219c | 0x8d70c | 0x8c30c | 0x380 |
VirtualAllocEx | 0x0 | 0x4821a0 | 0x8d710 | 0x8c310 | 0x4ea |
WriteProcessMemory | 0x0 | 0x4821a4 | 0x8d714 | 0x8c314 | 0x52e |
ReadProcessMemory | 0x0 | 0x4821a8 | 0x8d718 | 0x8c318 | 0x3c3 |
CreateFileW | 0x0 | 0x4821ac | 0x8d71c | 0x8c31c | 0x8f |
SetFilePointerEx | 0x0 | 0x4821b0 | 0x8d720 | 0x8c320 | 0x467 |
ReadFile | 0x0 | 0x4821b4 | 0x8d724 | 0x8c324 | 0x3c0 |
WriteFile | 0x0 | 0x4821b8 | 0x8d728 | 0x8c328 | 0x525 |
FlushFileBuffers | 0x0 | 0x4821bc | 0x8d72c | 0x8c32c | 0x157 |
TerminateProcess | 0x0 | 0x4821c0 | 0x8d730 | 0x8c330 | 0x4c0 |
CreateToolhelp32Snapshot | 0x0 | 0x4821c4 | 0x8d734 | 0x8c334 | 0xbe |
Process32FirstW | 0x0 | 0x4821c8 | 0x8d738 | 0x8c338 | 0x396 |
Process32NextW | 0x0 | 0x4821cc | 0x8d73c | 0x8c33c | 0x398 |
SetFileTime | 0x0 | 0x4821d0 | 0x8d740 | 0x8c340 | 0x46a |
GetFileAttributesW | 0x0 | 0x4821d4 | 0x8d744 | 0x8c344 | 0x1ea |
FindFirstFileW | 0x0 | 0x4821d8 | 0x8d748 | 0x8c348 | 0x139 |
FindClose | 0x0 | 0x4821dc | 0x8d74c | 0x8c34c | 0x12e |
DeleteFileW | 0x0 | 0x4821e0 | 0x8d750 | 0x8c350 | 0xd6 |
FindNextFileW | 0x0 | 0x4821e4 | 0x8d754 | 0x8c354 | 0x145 |
MoveFileW | 0x0 | 0x4821e8 | 0x8d758 | 0x8c358 | 0x363 |
CopyFileW | 0x0 | 0x4821ec | 0x8d75c | 0x8c35c | 0x75 |
CreateDirectoryW | 0x0 | 0x4821f0 | 0x8d760 | 0x8c360 | 0x81 |
RemoveDirectoryW | 0x0 | 0x4821f4 | 0x8d764 | 0x8c364 | 0x403 |
GetProcessHeap | 0x0 | 0x4821f8 | 0x8d768 | 0x8c368 | 0x24a |
QueryPerformanceFrequency | 0x0 | 0x4821fc | 0x8d76c | 0x8c36c | 0x3a8 |
FindResourceW | 0x0 | 0x482200 | 0x8d770 | 0x8c370 | 0x14e |
LoadResource | 0x0 | 0x482204 | 0x8d774 | 0x8c374 | 0x341 |
LockResource | 0x0 | 0x482208 | 0x8d778 | 0x8c378 | 0x354 |
SizeofResource | 0x0 | 0x48220c | 0x8d77c | 0x8c37c | 0x4b1 |
EnumResourceNamesW | 0x0 | 0x482210 | 0x8d780 | 0x8c380 | 0x102 |
OutputDebugStringW | 0x0 | 0x482214 | 0x8d784 | 0x8c384 | 0x38a |
GetLocalTime | 0x0 | 0x482218 | 0x8d788 | 0x8c388 | 0x203 |
CompareStringW | 0x0 | 0x48221c | 0x8d78c | 0x8c38c | 0x64 |
DeleteCriticalSection | 0x0 | 0x482220 | 0x8d790 | 0x8c390 | 0xd1 |
EnterCriticalSection | 0x0 | 0x482224 | 0x8d794 | 0x8c394 | 0xee |
LeaveCriticalSection | 0x0 | 0x482228 | 0x8d798 | 0x8c398 | 0x339 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x48222c | 0x8d79c | 0x8c39c | 0x2e3 |
GetStdHandle | 0x0 | 0x482230 | 0x8d7a0 | 0x8c3a0 | 0x264 |
CreatePipe | 0x0 | 0x482234 | 0x8d7a4 | 0x8c3a4 | 0xa1 |
InterlockedExchange | 0x0 | 0x482238 | 0x8d7a8 | 0x8c3a8 | 0x2ec |
TerminateThread | 0x0 | 0x48223c | 0x8d7ac | 0x8c3ac | 0x4c1 |
GetTempPathW | 0x0 | 0x482240 | 0x8d7b0 | 0x8c3b0 | 0x285 |
GetTempFileNameW | 0x0 | 0x482244 | 0x8d7b4 | 0x8c3b4 | 0x283 |
VirtualFree | 0x0 | 0x482248 | 0x8d7b8 | 0x8c3b8 | 0x4ec |
FormatMessageW | 0x0 | 0x48224c | 0x8d7bc | 0x8c3bc | 0x15e |
GetExitCodeProcess | 0x0 | 0x482250 | 0x8d7c0 | 0x8c3c0 | 0x1df |
SetErrorMode | 0x0 | 0x482254 | 0x8d7c4 | 0x8c3c4 | 0x458 |
GetPrivateProfileStringW | 0x0 | 0x482258 | 0x8d7c8 | 0x8c3c8 | 0x242 |
WritePrivateProfileStringW | 0x0 | 0x48225c | 0x8d7cc | 0x8c3cc | 0x52b |
GetPrivateProfileSectionW | 0x0 | 0x482260 | 0x8d7d0 | 0x8c3d0 | 0x240 |
WritePrivateProfileSectionW | 0x0 | 0x482264 | 0x8d7d4 | 0x8c3d4 | 0x529 |
GetPrivateProfileSectionNamesW | 0x0 | 0x482268 | 0x8d7d8 | 0x8c3d8 | 0x23f |
FileTimeToLocalFileTime | 0x0 | 0x48226c | 0x8d7dc | 0x8c3dc | 0x124 |
FileTimeToSystemTime | 0x0 | 0x482270 | 0x8d7e0 | 0x8c3e0 | 0x125 |
SystemTimeToFileTime | 0x0 | 0x482274 | 0x8d7e4 | 0x8c3e4 | 0x4bd |
LocalFileTimeToFileTime | 0x0 | 0x482278 | 0x8d7e8 | 0x8c3e8 | 0x346 |
GetDriveTypeW | 0x0 | 0x48227c | 0x8d7ec | 0x8c3ec | 0x1d3 |
GetDiskFreeSpaceExW | 0x0 | 0x482280 | 0x8d7f0 | 0x8c3f0 | 0x1ce |
GetDiskFreeSpaceW | 0x0 | 0x482284 | 0x8d7f4 | 0x8c3f4 | 0x1cf |
GetVolumeInformationW | 0x0 | 0x482288 | 0x8d7f8 | 0x8c3f8 | 0x2a7 |
SetVolumeLabelW | 0x0 | 0x48228c | 0x8d7fc | 0x8c3fc | 0x4a9 |
CreateHardLinkW | 0x0 | 0x482290 | 0x8d800 | 0x8c400 | 0x93 |
DeviceIoControl | 0x0 | 0x482294 | 0x8d804 | 0x8c404 | 0xdd |
SetFileAttributesW | 0x0 | 0x482298 | 0x8d808 | 0x8c408 | 0x461 |
GetShortPathNameW | 0x0 | 0x48229c | 0x8d80c | 0x8c40c | 0x261 |
CreateEventW | 0x0 | 0x4822a0 | 0x8d810 | 0x8c410 | 0x85 |
SetEvent | 0x0 | 0x4822a4 | 0x8d814 | 0x8c414 | 0x459 |
GetEnvironmentVariableW | 0x0 | 0x4822a8 | 0x8d818 | 0x8c418 | 0x1dc |
SetEnvironmentVariableW | 0x0 | 0x4822ac | 0x8d81c | 0x8c41c | 0x457 |
GlobalLock | 0x0 | 0x4822b0 | 0x8d820 | 0x8c420 | 0x2be |
GlobalUnlock | 0x0 | 0x4822b4 | 0x8d824 | 0x8c424 | 0x2c5 |
GlobalAlloc | 0x0 | 0x4822b8 | 0x8d828 | 0x8c428 | 0x2b3 |
GetFileSize | 0x0 | 0x4822bc | 0x8d82c | 0x8c42c | 0x1f0 |
GlobalFree | 0x0 | 0x4822c0 | 0x8d830 | 0x8c430 | 0x2ba |
GlobalMemoryStatusEx | 0x0 | 0x4822c4 | 0x8d834 | 0x8c434 | 0x2c0 |
Beep | 0x0 | 0x4822c8 | 0x8d838 | 0x8c438 | 0x36 |
GetSystemDirectoryW | 0x0 | 0x4822cc | 0x8d83c | 0x8c43c | 0x270 |
GetComputerNameW | 0x0 | 0x4822d0 | 0x8d840 | 0x8c440 | 0x18f |
GetWindowsDirectoryW | 0x0 | 0x4822d4 | 0x8d844 | 0x8c444 | 0x2af |
GetCurrentProcessId | 0x0 | 0x4822d8 | 0x8d848 | 0x8c448 | 0x1c1 |
GetCurrentThread | 0x0 | 0x4822dc | 0x8d84c | 0x8c44c | 0x1c4 |
GetProcessIoCounters | 0x0 | 0x4822e0 | 0x8d850 | 0x8c450 | 0x24e |
CreateProcessW | 0x0 | 0x4822e4 | 0x8d854 | 0x8c454 | 0xa8 |
SetPriorityClass | 0x0 | 0x4822e8 | 0x8d858 | 0x8c458 | 0x47d |
LoadLibraryW | 0x0 | 0x4822ec | 0x8d85c | 0x8c45c | 0x33f |
VirtualAlloc | 0x0 | 0x4822f0 | 0x8d860 | 0x8c460 | 0x4e9 |
LoadLibraryExW | 0x0 | 0x4822f4 | 0x8d864 | 0x8c464 | 0x33e |
HeapFree | 0x0 | 0x4822f8 | 0x8d868 | 0x8c468 | 0x2cf |
WaitForSingleObject | 0x0 | 0x4822fc | 0x8d86c | 0x8c46c | 0x4f9 |
CreateThread | 0x0 | 0x482300 | 0x8d870 | 0x8c470 | 0xb5 |
DuplicateHandle | 0x0 | 0x482304 | 0x8d874 | 0x8c474 | 0xe8 |
GetLastError | 0x0 | 0x482308 | 0x8d878 | 0x8c478 | 0x202 |
CloseHandle | 0x0 | 0x48230c | 0x8d87c | 0x8c47c | 0x52 |
GetCurrentProcess | 0x0 | 0x482310 | 0x8d880 | 0x8c480 | 0x1c0 |
GetProcAddress | 0x0 | 0x482314 | 0x8d884 | 0x8c484 | 0x245 |
LoadLibraryA | 0x0 | 0x482318 | 0x8d888 | 0x8c488 | 0x33c |
FreeLibrary | 0x0 | 0x48231c | 0x8d88c | 0x8c48c | 0x162 |
GetModuleFileNameW | 0x0 | 0x482320 | 0x8d890 | 0x8c490 | 0x214 |
GetFullPathNameW | 0x0 | 0x482324 | 0x8d894 | 0x8c494 | 0x1fb |
SetCurrentDirectoryW | 0x0 | 0x482328 | 0x8d898 | 0x8c498 | 0x44d |
IsDebuggerPresent | 0x0 | 0x48232c | 0x8d89c | 0x8c49c | 0x300 |
GetCurrentDirectoryW | 0x0 | 0x482330 | 0x8d8a0 | 0x8c4a0 | 0x1bf |
ExitProcess | 0x0 | 0x482334 | 0x8d8a4 | 0x8c4a4 | 0x119 |
ExitThread | 0x0 | 0x482338 | 0x8d8a8 | 0x8c4a8 | 0x11a |
GetSystemTimeAsFileTime | 0x0 | 0x48233c | 0x8d8ac | 0x8c4ac | 0x279 |
ResumeThread | 0x0 | 0x482340 | 0x8d8b0 | 0x8c4b0 | 0x413 |
GetTimeFormatW | 0x0 | 0x482344 | 0x8d8b4 | 0x8c4b4 | 0x297 |
GetDateFormatW | 0x0 | 0x482348 | 0x8d8b8 | 0x8c4b8 | 0x1c8 |
GetCommandLineW | 0x0 | 0x48234c | 0x8d8bc | 0x8c4bc | 0x187 |
GetStartupInfoW | 0x0 | 0x482350 | 0x8d8c0 | 0x8c4c0 | 0x263 |
IsProcessorFeaturePresent | 0x0 | 0x482354 | 0x8d8c4 | 0x8c4c4 | 0x304 |
HeapSize | 0x0 | 0x482358 | 0x8d8c8 | 0x8c4c8 | 0x2d4 |
GetCPInfo | 0x0 | 0x48235c | 0x8d8cc | 0x8c4cc | 0x172 |
GetACP | 0x0 | 0x482360 | 0x8d8d0 | 0x8c4d0 | 0x168 |
GetOEMCP | 0x0 | 0x482364 | 0x8d8d4 | 0x8c4d4 | 0x237 |
IsValidCodePage | 0x0 | 0x482368 | 0x8d8d8 | 0x8c4d8 | 0x30a |
TlsAlloc | 0x0 | 0x48236c | 0x8d8dc | 0x8c4dc | 0x4c5 |
TlsGetValue | 0x0 | 0x482370 | 0x8d8e0 | 0x8c4e0 | 0x4c7 |
TlsSetValue | 0x0 | 0x482374 | 0x8d8e4 | 0x8c4e4 | 0x4c8 |
TlsFree | 0x0 | 0x482378 | 0x8d8e8 | 0x8c4e8 | 0x4c6 |
SetLastError | 0x0 | 0x48237c | 0x8d8ec | 0x8c4ec | 0x473 |
UnhandledExceptionFilter | 0x0 | 0x482380 | 0x8d8f0 | 0x8c4f0 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x482384 | 0x8d8f4 | 0x8c4f4 | 0x4a5 |
GetStringTypeW | 0x0 | 0x482388 | 0x8d8f8 | 0x8c4f8 | 0x269 |
HeapCreate | 0x0 | 0x48238c | 0x8d8fc | 0x8c4fc | 0x2cd |
SetHandleCount | 0x0 | 0x482390 | 0x8d900 | 0x8c500 | 0x46f |
GetFileType | 0x0 | 0x482394 | 0x8d904 | 0x8c504 | 0x1f3 |
SetStdHandle | 0x0 | 0x482398 | 0x8d908 | 0x8c508 | 0x487 |
GetConsoleCP | 0x0 | 0x48239c | 0x8d90c | 0x8c50c | 0x19a |
GetConsoleMode | 0x0 | 0x4823a0 | 0x8d910 | 0x8c510 | 0x1ac |
LCMapStringW | 0x0 | 0x4823a4 | 0x8d914 | 0x8c514 | 0x32d |
RtlUnwind | 0x0 | 0x4823a8 | 0x8d918 | 0x8c518 | 0x418 |
SetFilePointer | 0x0 | 0x4823ac | 0x8d91c | 0x8c51c | 0x466 |
GetTimeZoneInformation | 0x0 | 0x4823b0 | 0x8d920 | 0x8c520 | 0x298 |
FreeEnvironmentStringsW | 0x0 | 0x4823b4 | 0x8d924 | 0x8c524 | 0x161 |
GetEnvironmentStringsW | 0x0 | 0x4823b8 | 0x8d928 | 0x8c528 | 0x1da |
GetTickCount | 0x0 | 0x4823bc | 0x8d92c | 0x8c52c | 0x293 |
HeapReAlloc | 0x0 | 0x4823c0 | 0x8d930 | 0x8c530 | 0x2d2 |
WriteConsoleW | 0x0 | 0x4823c4 | 0x8d934 | 0x8c534 | 0x524 |
SetEndOfFile | 0x0 | 0x4823c8 | 0x8d938 | 0x8c538 | 0x453 |
SetSystemPowerState | 0x0 | 0x4823cc | 0x8d93c | 0x8c53c | 0x48a |
SetEnvironmentVariableA | 0x0 | 0x4823d0 | 0x8d940 | 0x8c540 | 0x456 |
USER32.dll (160)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCursorInfo | 0x0 | 0x4824a0 | 0x8da10 | 0x8c610 | 0x11f |
RegisterHotKey | 0x0 | 0x4824a4 | 0x8da14 | 0x8c614 | 0x256 |
ClientToScreen | 0x0 | 0x4824a8 | 0x8da18 | 0x8c618 | 0x47 |
GetKeyboardLayoutNameW | 0x0 | 0x4824ac | 0x8da1c | 0x8c61c | 0x141 |
IsCharAlphaW | 0x0 | 0x4824b0 | 0x8da20 | 0x8c620 | 0x1c4 |
IsCharAlphaNumericW | 0x0 | 0x4824b4 | 0x8da24 | 0x8c624 | 0x1c3 |
IsCharLowerW | 0x0 | 0x4824b8 | 0x8da28 | 0x8c628 | 0x1c6 |
IsCharUpperW | 0x0 | 0x4824bc | 0x8da2c | 0x8c62c | 0x1c8 |
GetMenuStringW | 0x0 | 0x4824c0 | 0x8da30 | 0x8c630 | 0x158 |
GetSubMenu | 0x0 | 0x4824c4 | 0x8da34 | 0x8c634 | 0x17a |
GetCaretPos | 0x0 | 0x4824c8 | 0x8da38 | 0x8c638 | 0x10a |
IsZoomed | 0x0 | 0x4824cc | 0x8da3c | 0x8c63c | 0x1e2 |
MonitorFromPoint | 0x0 | 0x4824d0 | 0x8da40 | 0x8c640 | 0x218 |
GetMonitorInfoW | 0x0 | 0x4824d4 | 0x8da44 | 0x8c644 | 0x15f |
SetWindowLongW | 0x0 | 0x4824d8 | 0x8da48 | 0x8c648 | 0x2c4 |
SetLayeredWindowAttributes | 0x0 | 0x4824dc | 0x8da4c | 0x8c64c | 0x298 |
FlashWindow | 0x0 | 0x4824e0 | 0x8da50 | 0x8c650 | 0xfb |
GetClassLongW | 0x0 | 0x4824e4 | 0x8da54 | 0x8c654 | 0x110 |
TranslateAcceleratorW | 0x0 | 0x4824e8 | 0x8da58 | 0x8c658 | 0x2fa |
IsDialogMessageW | 0x0 | 0x4824ec | 0x8da5c | 0x8c65c | 0x1cd |
GetSysColor | 0x0 | 0x4824f0 | 0x8da60 | 0x8c660 | 0x17b |
InflateRect | 0x0 | 0x4824f4 | 0x8da64 | 0x8c664 | 0x1b5 |
DrawFocusRect | 0x0 | 0x4824f8 | 0x8da68 | 0x8c668 | 0xc4 |
DrawTextW | 0x0 | 0x4824fc | 0x8da6c | 0x8c66c | 0xd0 |
FrameRect | 0x0 | 0x482500 | 0x8da70 | 0x8c670 | 0xfd |
DrawFrameControl | 0x0 | 0x482504 | 0x8da74 | 0x8c674 | 0xc6 |
FillRect | 0x0 | 0x482508 | 0x8da78 | 0x8c678 | 0xf6 |
PtInRect | 0x0 | 0x48250c | 0x8da7c | 0x8c67c | 0x240 |
DestroyAcceleratorTable | 0x0 | 0x482510 | 0x8da80 | 0x8c680 | 0xa0 |
CreateAcceleratorTableW | 0x0 | 0x482514 | 0x8da84 | 0x8c684 | 0x58 |
SetCursor | 0x0 | 0x482518 | 0x8da88 | 0x8c688 | 0x288 |
GetWindowDC | 0x0 | 0x48251c | 0x8da8c | 0x8c68c | 0x192 |
GetSystemMetrics | 0x0 | 0x482520 | 0x8da90 | 0x8c690 | 0x17e |
GetActiveWindow | 0x0 | 0x482524 | 0x8da94 | 0x8c694 | 0x100 |
CharNextW | 0x0 | 0x482528 | 0x8da98 | 0x8c698 | 0x31 |
wsprintfW | 0x0 | 0x48252c | 0x8da9c | 0x8c69c | 0x333 |
RedrawWindow | 0x0 | 0x482530 | 0x8daa0 | 0x8c6a0 | 0x24a |
DrawMenuBar | 0x0 | 0x482534 | 0x8daa4 | 0x8c6a4 | 0xc9 |
DestroyMenu | 0x0 | 0x482538 | 0x8daa8 | 0x8c6a8 | 0xa4 |
SetMenu | 0x0 | 0x48253c | 0x8daac | 0x8c6ac | 0x29c |
GetWindowTextLengthW | 0x0 | 0x482540 | 0x8dab0 | 0x8c6b0 | 0x1a2 |
CreateMenu | 0x0 | 0x482544 | 0x8dab4 | 0x8c6b4 | 0x6a |
IsDlgButtonChecked | 0x0 | 0x482548 | 0x8dab8 | 0x8c6b8 | 0x1ce |
DefDlgProcW | 0x0 | 0x48254c | 0x8dabc | 0x8c6bc | 0x95 |
ReleaseCapture | 0x0 | 0x482550 | 0x8dac0 | 0x8c6c0 | 0x264 |
SetCapture | 0x0 | 0x482554 | 0x8dac4 | 0x8c6c4 | 0x280 |
WindowFromPoint | 0x0 | 0x482558 | 0x8dac8 | 0x8c6c8 | 0x32c |
LoadImageW | 0x0 | 0x48255c | 0x8dacc | 0x8c6cc | 0x1ef |
CreateIconFromResourceEx | 0x0 | 0x482560 | 0x8dad0 | 0x8c6d0 | 0x66 |
mouse_event | 0x0 | 0x482564 | 0x8dad4 | 0x8c6d4 | 0x331 |
ExitWindowsEx | 0x0 | 0x482568 | 0x8dad8 | 0x8c6d8 | 0xf5 |
SetActiveWindow | 0x0 | 0x48256c | 0x8dadc | 0x8c6dc | 0x27f |
FindWindowExW | 0x0 | 0x482570 | 0x8dae0 | 0x8c6e0 | 0xf9 |
EnumThreadWindows | 0x0 | 0x482574 | 0x8dae4 | 0x8c6e4 | 0xef |
SetMenuDefaultItem | 0x0 | 0x482578 | 0x8dae8 | 0x8c6e8 | 0x29e |
InsertMenuItemW | 0x0 | 0x48257c | 0x8daec | 0x8c6ec | 0x1b9 |
IsMenu | 0x0 | 0x482580 | 0x8daf0 | 0x8c6f0 | 0x1d2 |
TrackPopupMenuEx | 0x0 | 0x482584 | 0x8daf4 | 0x8c6f4 | 0x2f7 |
GetCursorPos | 0x0 | 0x482588 | 0x8daf8 | 0x8c6f8 | 0x120 |
DeleteMenu | 0x0 | 0x48258c | 0x8dafc | 0x8c6fc | 0x9e |
CheckMenuRadioItem | 0x0 | 0x482590 | 0x8db00 | 0x8c700 | 0x40 |
SetWindowPos | 0x0 | 0x482594 | 0x8db04 | 0x8c704 | 0x2c6 |
GetMenuItemCount | 0x0 | 0x482598 | 0x8db08 | 0x8c708 | 0x151 |
SetMenuItemInfoW | 0x0 | 0x48259c | 0x8db0c | 0x8c70c | 0x2a2 |
GetMenuItemInfoW | 0x0 | 0x4825a0 | 0x8db10 | 0x8c710 | 0x154 |
SetForegroundWindow | 0x0 | 0x4825a4 | 0x8db14 | 0x8c714 | 0x293 |
IsIconic | 0x0 | 0x4825a8 | 0x8db18 | 0x8c718 | 0x1d1 |
FindWindowW | 0x0 | 0x4825ac | 0x8db1c | 0x8c71c | 0xfa |
SystemParametersInfoW | 0x0 | 0x4825b0 | 0x8db20 | 0x8c720 | 0x2ec |
TranslateMessage | 0x0 | 0x4825b4 | 0x8db24 | 0x8c724 | 0x2fc |
SendInput | 0x0 | 0x4825b8 | 0x8db28 | 0x8c728 | 0x276 |
GetAsyncKeyState | 0x0 | 0x4825bc | 0x8db2c | 0x8c72c | 0x107 |
SetKeyboardState | 0x0 | 0x4825c0 | 0x8db30 | 0x8c730 | 0x296 |
GetKeyboardState | 0x0 | 0x4825c4 | 0x8db34 | 0x8c734 | 0x142 |
GetKeyState | 0x0 | 0x4825c8 | 0x8db38 | 0x8c738 | 0x13d |
VkKeyScanW | 0x0 | 0x4825cc | 0x8db3c | 0x8c73c | 0x321 |
LoadStringW | 0x0 | 0x4825d0 | 0x8db40 | 0x8c740 | 0x1fa |
DialogBoxParamW | 0x0 | 0x4825d4 | 0x8db44 | 0x8c744 | 0xac |
MessageBeep | 0x0 | 0x4825d8 | 0x8db48 | 0x8c748 | 0x20d |
EndDialog | 0x0 | 0x4825dc | 0x8db4c | 0x8c74c | 0xda |
SendDlgItemMessageW | 0x0 | 0x4825e0 | 0x8db50 | 0x8c750 | 0x273 |
GetDlgItem | 0x0 | 0x4825e4 | 0x8db54 | 0x8c754 | 0x127 |
SetWindowTextW | 0x0 | 0x4825e8 | 0x8db58 | 0x8c758 | 0x2cb |
CopyRect | 0x0 | 0x4825ec | 0x8db5c | 0x8c75c | 0x55 |
ReleaseDC | 0x0 | 0x4825f0 | 0x8db60 | 0x8c760 | 0x265 |
GetDC | 0x0 | 0x4825f4 | 0x8db64 | 0x8c764 | 0x121 |
EndPaint | 0x0 | 0x4825f8 | 0x8db68 | 0x8c768 | 0xdc |
BeginPaint | 0x0 | 0x4825fc | 0x8db6c | 0x8c76c | 0xe |
GetClientRect | 0x0 | 0x482600 | 0x8db70 | 0x8c770 | 0x114 |
GetMenu | 0x0 | 0x482604 | 0x8db74 | 0x8c774 | 0x14b |
DestroyWindow | 0x0 | 0x482608 | 0x8db78 | 0x8c778 | 0xa6 |
EnumWindows | 0x0 | 0x48260c | 0x8db7c | 0x8c77c | 0xf2 |
GetDesktopWindow | 0x0 | 0x482610 | 0x8db80 | 0x8c780 | 0x123 |
IsWindow | 0x0 | 0x482614 | 0x8db84 | 0x8c784 | 0x1db |
IsWindowEnabled | 0x0 | 0x482618 | 0x8db88 | 0x8c788 | 0x1dc |
IsWindowVisible | 0x0 | 0x48261c | 0x8db8c | 0x8c78c | 0x1e0 |
EnableWindow | 0x0 | 0x482620 | 0x8db90 | 0x8c790 | 0xd8 |
InvalidateRect | 0x0 | 0x482624 | 0x8db94 | 0x8c794 | 0x1be |
GetWindowLongW | 0x0 | 0x482628 | 0x8db98 | 0x8c798 | 0x196 |
AttachThreadInput | 0x0 | 0x48262c | 0x8db9c | 0x8c79c | 0xc |
GetFocus | 0x0 | 0x482630 | 0x8dba0 | 0x8c7a0 | 0x12c |
GetWindowTextW | 0x0 | 0x482634 | 0x8dba4 | 0x8c7a4 | 0x1a3 |
ScreenToClient | 0x0 | 0x482638 | 0x8dba8 | 0x8c7a8 | 0x26d |
SendMessageTimeoutW | 0x0 | 0x48263c | 0x8dbac | 0x8c7ac | 0x27b |
EnumChildWindows | 0x0 | 0x482640 | 0x8dbb0 | 0x8c7b0 | 0xdf |
CharUpperBuffW | 0x0 | 0x482644 | 0x8dbb4 | 0x8c7b4 | 0x3b |
GetClassNameW | 0x0 | 0x482648 | 0x8dbb8 | 0x8c7b8 | 0x112 |
GetParent | 0x0 | 0x48264c | 0x8dbbc | 0x8c7bc | 0x164 |
GetDlgCtrlID | 0x0 | 0x482650 | 0x8dbc0 | 0x8c7c0 | 0x126 |
SendMessageW | 0x0 | 0x482654 | 0x8dbc4 | 0x8c7c4 | 0x27c |
MapVirtualKeyW | 0x0 | 0x482658 | 0x8dbc8 | 0x8c7c8 | 0x208 |
PostMessageW | 0x0 | 0x48265c | 0x8dbcc | 0x8c7cc | 0x236 |
GetWindowRect | 0x0 | 0x482660 | 0x8dbd0 | 0x8c7d0 | 0x19c |
SetUserObjectSecurity | 0x0 | 0x482664 | 0x8dbd4 | 0x8c7d4 | 0x2be |
GetUserObjectSecurity | 0x0 | 0x482668 | 0x8dbd8 | 0x8c7d8 | 0x18c |
CloseDesktop | 0x0 | 0x48266c | 0x8dbdc | 0x8c7dc | 0x4a |
CloseWindowStation | 0x0 | 0x482670 | 0x8dbe0 | 0x8c7e0 | 0x4e |
OpenDesktopW | 0x0 | 0x482674 | 0x8dbe4 | 0x8c7e4 | 0x228 |
SetProcessWindowStation | 0x0 | 0x482678 | 0x8dbe8 | 0x8c7e8 | 0x2aa |
GetProcessWindowStation | 0x0 | 0x48267c | 0x8dbec | 0x8c7ec | 0x168 |
OpenWindowStationW | 0x0 | 0x482680 | 0x8dbf0 | 0x8c7f0 | 0x22d |
MessageBoxW | 0x0 | 0x482684 | 0x8dbf4 | 0x8c7f4 | 0x215 |
DefWindowProcW | 0x0 | 0x482688 | 0x8dbf8 | 0x8c7f8 | 0x9c |
CopyImage | 0x0 | 0x48268c | 0x8dbfc | 0x8c7fc | 0x54 |
AdjustWindowRectEx | 0x0 | 0x482690 | 0x8dc00 | 0x8c800 | 0x3 |
SetRect | 0x0 | 0x482694 | 0x8dc04 | 0x8c804 | 0x2ae |
SetClipboardData | 0x0 | 0x482698 | 0x8dc08 | 0x8c808 | 0x286 |
EmptyClipboard | 0x0 | 0x48269c | 0x8dc0c | 0x8c80c | 0xd5 |
CountClipboardFormats | 0x0 | 0x4826a0 | 0x8dc10 | 0x8c810 | 0x56 |
CloseClipboard | 0x0 | 0x4826a4 | 0x8dc14 | 0x8c814 | 0x49 |
GetClipboardData | 0x0 | 0x4826a8 | 0x8dc18 | 0x8c818 | 0x116 |
IsClipboardFormatAvailable | 0x0 | 0x4826ac | 0x8dc1c | 0x8c81c | 0x1ca |
OpenClipboard | 0x0 | 0x4826b0 | 0x8dc20 | 0x8c820 | 0x226 |
BlockInput | 0x0 | 0x4826b4 | 0x8dc24 | 0x8c824 | 0xf |
GetMessageW | 0x0 | 0x4826b8 | 0x8dc28 | 0x8c828 | 0x15d |
LockWindowUpdate | 0x0 | 0x4826bc | 0x8dc2c | 0x8c82c | 0x1fd |
GetMenuItemID | 0x0 | 0x4826c0 | 0x8dc30 | 0x8c830 | 0x152 |
DispatchMessageW | 0x0 | 0x4826c4 | 0x8dc34 | 0x8c834 | 0xaf |
MoveWindow | 0x0 | 0x4826c8 | 0x8dc38 | 0x8c838 | 0x21b |
SetFocus | 0x0 | 0x4826cc | 0x8dc3c | 0x8c83c | 0x292 |
PostQuitMessage | 0x0 | 0x4826d0 | 0x8dc40 | 0x8c840 | 0x237 |
KillTimer | 0x0 | 0x4826d4 | 0x8dc44 | 0x8c844 | 0x1e3 |
CreatePopupMenu | 0x0 | 0x4826d8 | 0x8dc48 | 0x8c848 | 0x6b |
RegisterWindowMessageW | 0x0 | 0x4826dc | 0x8dc4c | 0x8c84c | 0x263 |
SetTimer | 0x0 | 0x4826e0 | 0x8dc50 | 0x8c850 | 0x2bb |
ShowWindow | 0x0 | 0x4826e4 | 0x8dc54 | 0x8c854 | 0x2df |
CreateWindowExW | 0x0 | 0x4826e8 | 0x8dc58 | 0x8c858 | 0x6e |
RegisterClassExW | 0x0 | 0x4826ec | 0x8dc5c | 0x8c85c | 0x24d |
LoadIconW | 0x0 | 0x4826f0 | 0x8dc60 | 0x8c860 | 0x1ed |
LoadCursorW | 0x0 | 0x4826f4 | 0x8dc64 | 0x8c864 | 0x1eb |
GetSysColorBrush | 0x0 | 0x4826f8 | 0x8dc68 | 0x8c868 | 0x17c |
GetForegroundWindow | 0x0 | 0x4826fc | 0x8dc6c | 0x8c86c | 0x12d |
MessageBoxA | 0x0 | 0x482700 | 0x8dc70 | 0x8c870 | 0x20e |
DestroyIcon | 0x0 | 0x482704 | 0x8dc74 | 0x8c874 | 0xa3 |
PeekMessageW | 0x0 | 0x482708 | 0x8dc78 | 0x8c878 | 0x233 |
UnregisterHotKey | 0x0 | 0x48270c | 0x8dc7c | 0x8c87c | 0x308 |
CharLowerBuffW | 0x0 | 0x482710 | 0x8dc80 | 0x8c880 | 0x2d |
keybd_event | 0x0 | 0x482714 | 0x8dc84 | 0x8c884 | 0x330 |
MonitorFromRect | 0x0 | 0x482718 | 0x8dc88 | 0x8c888 | 0x219 |
GetWindowThreadProcessId | 0x0 | 0x48271c | 0x8dc8c | 0x8c88c | 0x1a4 |
GDI32.dll (35)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DeleteObject | 0x0 | 0x4820c8 | 0x8d638 | 0x8c238 | 0xe6 |
AngleArc | 0x0 | 0x4820cc | 0x8d63c | 0x8c23c | 0x8 |
GetTextExtentPoint32W | 0x0 | 0x4820d0 | 0x8d640 | 0x8c240 | 0x21e |
ExtCreatePen | 0x0 | 0x4820d4 | 0x8d644 | 0x8c244 | 0x132 |
StrokeAndFillPath | 0x0 | 0x4820d8 | 0x8d648 | 0x8c248 | 0x2b5 |
StrokePath | 0x0 | 0x4820dc | 0x8d64c | 0x8c24c | 0x2b6 |
EndPath | 0x0 | 0x4820e0 | 0x8d650 | 0x8c250 | 0xf3 |
SetPixel | 0x0 | 0x4820e4 | 0x8d654 | 0x8c254 | 0x29b |
CloseFigure | 0x0 | 0x4820e8 | 0x8d658 | 0x8c258 | 0x1e |
CreateCompatibleBitmap | 0x0 | 0x4820ec | 0x8d65c | 0x8c25c | 0x2f |
CreateCompatibleDC | 0x0 | 0x4820f0 | 0x8d660 | 0x8c260 | 0x30 |
SelectObject | 0x0 | 0x4820f4 | 0x8d664 | 0x8c264 | 0x277 |
StretchBlt | 0x0 | 0x4820f8 | 0x8d668 | 0x8c268 | 0x2b3 |
GetDIBits | 0x0 | 0x4820fc | 0x8d66c | 0x8c26c | 0x1ca |
GetDeviceCaps | 0x0 | 0x482100 | 0x8d670 | 0x8c270 | 0x1cb |
MoveToEx | 0x0 | 0x482104 | 0x8d674 | 0x8c274 | 0x23a |
DeleteDC | 0x0 | 0x482108 | 0x8d678 | 0x8c278 | 0xe3 |
GetPixel | 0x0 | 0x48210c | 0x8d67c | 0x8c27c | 0x204 |
CreateDCW | 0x0 | 0x482110 | 0x8d680 | 0x8c280 | 0x32 |
Ellipse | 0x0 | 0x482114 | 0x8d684 | 0x8c284 | 0xed |
PolyDraw | 0x0 | 0x482118 | 0x8d688 | 0x8c288 | 0x250 |
BeginPath | 0x0 | 0x48211c | 0x8d68c | 0x8c28c | 0x12 |
Rectangle | 0x0 | 0x482120 | 0x8d690 | 0x8c290 | 0x25f |
SetViewportOrgEx | 0x0 | 0x482124 | 0x8d694 | 0x8c294 | 0x2a9 |
GetObjectW | 0x0 | 0x482128 | 0x8d698 | 0x8c298 | 0x1fd |
SetBkMode | 0x0 | 0x48212c | 0x8d69c | 0x8c29c | 0x27f |
RoundRect | 0x0 | 0x482130 | 0x8d6a0 | 0x8c2a0 | 0x26a |
SetBkColor | 0x0 | 0x482134 | 0x8d6a4 | 0x8c2a4 | 0x27e |
CreatePen | 0x0 | 0x482138 | 0x8d6a8 | 0x8c2a8 | 0x4b |
CreateSolidBrush | 0x0 | 0x48213c | 0x8d6ac | 0x8c2ac | 0x54 |
SetTextColor | 0x0 | 0x482140 | 0x8d6b0 | 0x8c2b0 | 0x2a6 |
CreateFontW | 0x0 | 0x482144 | 0x8d6b4 | 0x8c2b4 | 0x41 |
GetTextFaceW | 0x0 | 0x482148 | 0x8d6b8 | 0x8c2b8 | 0x224 |
GetStockObject | 0x0 | 0x48214c | 0x8d6bc | 0x8c2bc | 0x20d |
LineTo | 0x0 | 0x482150 | 0x8d6c0 | 0x8c2c0 | 0x236 |
COMDLG32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetSaveFileNameW | 0x0 | 0x4820bc | 0x8d62c | 0x8c22c | 0xe |
GetOpenFileNameW | 0x0 | 0x4820c0 | 0x8d630 | 0x8c230 | 0xc |
ADVAPI32.dll (34)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegEnumValueW | 0x0 | 0x482000 | 0x8d570 | 0x8c170 | 0x252 |
RegDeleteValueW | 0x0 | 0x482004 | 0x8d574 | 0x8c174 | 0x248 |
RegDeleteKeyW | 0x0 | 0x482008 | 0x8d578 | 0x8c178 | 0x244 |
RegEnumKeyExW | 0x0 | 0x48200c | 0x8d57c | 0x8c17c | 0x24f |
RegSetValueExW | 0x0 | 0x482010 | 0x8d580 | 0x8c180 | 0x27e |
RegCreateKeyExW | 0x0 | 0x482014 | 0x8d584 | 0x8c184 | 0x239 |
GetUserNameW | 0x0 | 0x482018 | 0x8d588 | 0x8c188 | 0x165 |
RegConnectRegistryW | 0x0 | 0x48201c | 0x8d58c | 0x8c18c | 0x234 |
CloseServiceHandle | 0x0 | 0x482020 | 0x8d590 | 0x8c190 | 0x57 |
UnlockServiceDatabase | 0x0 | 0x482024 | 0x8d594 | 0x8c194 | 0x300 |
OpenThreadToken | 0x0 | 0x482028 | 0x8d598 | 0x8c198 | 0x1fc |
OpenProcessToken | 0x0 | 0x48202c | 0x8d59c | 0x8c19c | 0x1f7 |
LookupPrivilegeValueW | 0x0 | 0x482030 | 0x8d5a0 | 0x8c1a0 | 0x197 |
DuplicateTokenEx | 0x0 | 0x482034 | 0x8d5a4 | 0x8c1a4 | 0xdf |
CreateProcessAsUserW | 0x0 | 0x482038 | 0x8d5a8 | 0x8c1a8 | 0x7c |
CreateProcessWithLogonW | 0x0 | 0x48203c | 0x8d5ac | 0x8c1ac | 0x7d |
InitializeSecurityDescriptor | 0x0 | 0x482040 | 0x8d5b0 | 0x8c1b0 | 0x177 |
InitializeAcl | 0x0 | 0x482044 | 0x8d5b4 | 0x8c1b4 | 0x176 |
GetLengthSid | 0x0 | 0x482048 | 0x8d5b8 | 0x8c1b8 | 0x136 |
CopySid | 0x0 | 0x48204c | 0x8d5bc | 0x8c1bc | 0x76 |
LogonUserW | 0x0 | 0x482050 | 0x8d5c0 | 0x8c1c0 | 0x18d |
LockServiceDatabase | 0x0 | 0x482054 | 0x8d5c4 | 0x8c1c4 | 0x188 |
GetTokenInformation | 0x0 | 0x482058 | 0x8d5c8 | 0x8c1c8 | 0x15a |
GetSecurityDescriptorDacl | 0x0 | 0x48205c | 0x8d5cc | 0x8c1cc | 0x148 |
GetAclInformation | 0x0 | 0x482060 | 0x8d5d0 | 0x8c1d0 | 0x124 |
GetAce | 0x0 | 0x482064 | 0x8d5d4 | 0x8c1d4 | 0x123 |
AddAce | 0x0 | 0x482068 | 0x8d5d8 | 0x8c1d8 | 0x16 |
SetSecurityDescriptorDacl | 0x0 | 0x48206c | 0x8d5dc | 0x8c1dc | 0x2b6 |
RegOpenKeyExW | 0x0 | 0x482070 | 0x8d5e0 | 0x8c1e0 | 0x261 |
RegQueryValueExW | 0x0 | 0x482074 | 0x8d5e4 | 0x8c1e4 | 0x26e |
AdjustTokenPrivileges | 0x0 | 0x482078 | 0x8d5e8 | 0x8c1e8 | 0x1f |
InitiateSystemShutdownExW | 0x0 | 0x48207c | 0x8d5ec | 0x8c1ec | 0x17d |
OpenSCManagerW | 0x0 | 0x482080 | 0x8d5f0 | 0x8c1f0 | 0x1f9 |
RegCloseKey | 0x0 | 0x482084 | 0x8d5f4 | 0x8c1f4 | 0x230 |
SHELL32.dll (14)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DragQueryPoint | 0x0 | 0x482464 | 0x8d9d4 | 0x8c5d4 | 0x20 |
ShellExecuteExW | 0x0 | 0x482468 | 0x8d9d8 | 0x8c5d8 | 0x121 |
SHGetFolderPathW | 0x0 | 0x48246c | 0x8d9dc | 0x8c5dc | 0xc3 |
DragQueryFileW | 0x0 | 0x482470 | 0x8d9e0 | 0x8c5e0 | 0x1f |
SHEmptyRecycleBinW | 0x0 | 0x482474 | 0x8d9e4 | 0x8c5e4 | 0xa5 |
SHBrowseForFolderW | 0x0 | 0x482478 | 0x8d9e8 | 0x8c5e8 | 0x7b |
SHFileOperationW | 0x0 | 0x48247c | 0x8d9ec | 0x8c5ec | 0xac |
SHGetPathFromIDListW | 0x0 | 0x482480 | 0x8d9f0 | 0x8c5f0 | 0xd7 |
SHGetDesktopFolder | 0x0 | 0x482484 | 0x8d9f4 | 0x8c5f4 | 0xb6 |
SHGetMalloc | 0x0 | 0x482488 | 0x8d9f8 | 0x8c5f8 | 0xcf |
ExtractIconExW | 0x0 | 0x48248c | 0x8d9fc | 0x8c5fc | 0x2a |
Shell_NotifyIconW | 0x0 | 0x482490 | 0x8da00 | 0x8c600 | 0x12e |
ShellExecuteW | 0x0 | 0x482494 | 0x8da04 | 0x8c604 | 0x122 |
DragFinish | 0x0 | 0x482498 | 0x8da08 | 0x8c608 | 0x1b |
ole32.dll (20)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
OleSetMenuDescriptor | 0x0 | 0x4827f0 | 0x8dd60 | 0x8c960 | 0x147 |
MkParseDisplayName | 0x0 | 0x4827f4 | 0x8dd64 | 0x8c964 | 0xd4 |
OleSetContainedObject | 0x0 | 0x4827f8 | 0x8dd68 | 0x8c968 | 0x146 |
CLSIDFromString | 0x0 | 0x4827fc | 0x8dd6c | 0x8c96c | 0x8 |
StringFromGUID2 | 0x0 | 0x482800 | 0x8dd70 | 0x8c970 | 0x179 |
CoInitialize | 0x0 | 0x482804 | 0x8dd74 | 0x8c974 | 0x3e |
CoUninitialize | 0x0 | 0x482808 | 0x8dd78 | 0x8c978 | 0x6c |
CoCreateInstance | 0x0 | 0x48280c | 0x8dd7c | 0x8c97c | 0x10 |
CreateStreamOnHGlobal | 0x0 | 0x482810 | 0x8dd80 | 0x8c980 | 0x86 |
CoTaskMemAlloc | 0x0 | 0x482814 | 0x8dd84 | 0x8c984 | 0x67 |
CoTaskMemFree | 0x0 | 0x482818 | 0x8dd88 | 0x8c988 | 0x68 |
ProgIDFromCLSID | 0x0 | 0x48281c | 0x8dd8c | 0x8c98c | 0x14b |
OleInitialize | 0x0 | 0x482820 | 0x8dd90 | 0x8c990 | 0x132 |
CreateBindCtx | 0x0 | 0x482824 | 0x8dd94 | 0x8c994 | 0x79 |
CLSIDFromProgID | 0x0 | 0x482828 | 0x8dd98 | 0x8c998 | 0x6 |
CoInitializeSecurity | 0x0 | 0x48282c | 0x8dd9c | 0x8c99c | 0x40 |
CoCreateInstanceEx | 0x0 | 0x482830 | 0x8dda0 | 0x8c9a0 | 0x11 |
CoSetProxyBlanket | 0x0 | 0x482834 | 0x8dda4 | 0x8c9a4 | 0x63 |
OleUninitialize | 0x0 | 0x482838 | 0x8dda8 | 0x8c9a8 | 0x149 |
IIDFromString | 0x0 | 0x48283c | 0x8ddac | 0x8c9ac | 0xcd |
OLEAUT32.dll (24)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VariantChangeType | 0xc | 0x4823ec | 0x8d95c | 0x8c55c | - |
VariantCopyInd | 0xb | 0x4823f0 | 0x8d960 | 0x8c560 | - |
DispCallFunc | 0x92 | 0x4823f4 | 0x8d964 | 0x8c564 | - |
CreateStdDispatch | 0x20 | 0x4823f8 | 0x8d968 | 0x8c568 | - |
CreateDispTypeInfo | 0x1f | 0x4823fc | 0x8d96c | 0x8c56c | - |
SysFreeString | 0x6 | 0x482400 | 0x8d970 | 0x8c570 | - |
SafeArrayDestroyDescriptor | 0x26 | 0x482404 | 0x8d974 | 0x8c574 | - |
SafeArrayDestroyData | 0x27 | 0x482408 | 0x8d978 | 0x8c578 | - |
SafeArrayUnaccessData | 0x18 | 0x48240c | 0x8d97c | 0x8c57c | - |
SysStringLen | 0x7 | 0x482410 | 0x8d980 | 0x8c580 | - |
SafeArrayAllocData | 0x25 | 0x482414 | 0x8d984 | 0x8c584 | - |
GetActiveObject | 0x23 | 0x482418 | 0x8d988 | 0x8c588 | - |
QueryPathOfRegTypeLib | 0xa4 | 0x48241c | 0x8d98c | 0x8c58c | - |
SafeArrayAllocDescriptorEx | 0x29 | 0x482420 | 0x8d990 | 0x8c590 | - |
SafeArrayCreateVector | 0x19b | 0x482424 | 0x8d994 | 0x8c594 | - |
SysAllocString | 0x2 | 0x482428 | 0x8d998 | 0x8c598 | - |
VariantCopy | 0xa | 0x48242c | 0x8d99c | 0x8c59c | - |
VariantClear | 0x9 | 0x482430 | 0x8d9a0 | 0x8c5a0 | - |
VariantTimeToSystemTime | 0xb9 | 0x482434 | 0x8d9a4 | 0x8c5a4 | - |
VarR8FromDec | 0xdc | 0x482438 | 0x8d9a8 | 0x8c5a8 | - |
SafeArrayGetVartype | 0x4d | 0x48243c | 0x8d9ac | 0x8c5ac | - |
OleLoadPicture | 0x1a2 | 0x482440 | 0x8d9b0 | 0x8c5b0 | - |
SafeArrayAccessData | 0x17 | 0x482444 | 0x8d9b4 | 0x8c5b4 | - |
VariantInit | 0x8 | 0x482448 | 0x8d9b8 | 0x8c5b8 | - |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
academics.pdf.exe | 1 | 0x00400000 | 0x004BDFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.31961692 |
Malicious
|
C:\Users\5P5NRG~1\AppData\Local\Temp\autDB22.tmp | Dropped File | Unknown |
Malicious
|
...
|
»
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Ransom.Aviso.2 |
Malicious
|
C:\Users\5P5NRG~1\AppData\Local\Temp\autDB43.tmp | Dropped File | Unknown |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2016-05-14 05:02 (UTC+2) |
Last Seen | 2018-12-19 23:02 (UTC+1) |
Names | Win64.Trojan.Bancos |
Families | Bancos |
Classification | Trojan |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.Generic.17932841 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.eGIW Yzvh.gif | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.gJ2GDQDH7i.ots | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.md6gSAuODLhq.avi | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.AX5eJBJ82y3.jpg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.CoWnh3Q5rTDnpXdJ.mp3 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.JLaCurEw.pdf | Dropped File |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music/Lock.desktop.ini | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music/Lock.xBQp6dTr52cBE6l-Un.m4a | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures/Lock.70BY_GgaY1.bmp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures/Lock.krvo L5sveZ W.png | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos/Lock.4Qauyoz6.avi | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup/Microsoft Update.lnk | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.gXTZQTDkC2czFZpWnC.gif | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.SFHBP1D1LBQEeR.wav | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.dunBms1jB_.jpg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music/Lock.LVDYQUpAZwEha.mp3 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos/Lock.afvn6kbS8JsNZy6W_IRM.mp4 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.MkMwkg_ip2 n-V.docx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5P5NRG~1\AppData\Local\Temp\autDAA5.tmp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5P5NRG~1\AppData\Local\Temp\rngoajj | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\5P5NRG~1\AppData\Local\Temp\888.vbs | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.6qT95vcU.docx | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.81-stuKA.mp4 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.Academics.pdf.exe | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.bY-NIrDXo_nG.bmp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.desktop.ini | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.DrmlVcs.bmp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.FN4XiavIO4PR.bmp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.GhiVvZ14WbSoIVTo6M.odt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.GyHm6iovQDw.m4a | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.lorGIZR7_Ai6fNrX6f.xlsx | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.nJNF.png | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.OPOBoXaM2P4A0m.m4a | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.QHREQz7Xz.jpg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.QzBYTrrsKyNkrz7Qz2.swf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.srS5tTxQY.mp3 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.UCS72GVnNBUxEzx.mkv | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.wI0b0QZdP-KcsT.avi | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.yvFiHqzM6fmTt.flv | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.5fNAF_eBT37aF.bmp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.7sqV8uLS.bmp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.bXPQ0g368kO FpGH2kMH.gif | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.co6M9Umeg.jpg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.e-h1xk7cgYR.swf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.enrHxcENdtYHa.rtf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.fieUnO JbD.odp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.f_H3Kw_rw4T-WXKpM.m4a | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.gFulebPw7UZ.flv | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.GHNzGfsXtZO 6LRI5J.png | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.Go gw9icCK1.m4a | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.Ie7x9Fbl.m4a | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.jfoRUvp.mkv | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.jOF28qdC.m4a | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.k3zAUT-8EHVGD9wmf.mp3 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.ngBTzibcz-Ml b.gif | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.qN0j1jGF7bK.jpg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.qtQYu5s9c3vFJHOzQ.csv | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.uKUOp3ady.png | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.USOrj0U79kg56B_MZLC3.gif | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.yI2BOQ.jpg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.ynNikGKB3oJVJW2VhiLE.ots | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock._J3DS1U3FLV.mp3 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Local/Lock.GDIPFONTCACHEV1.DAT | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Local/Lock.IconCache.db | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music/Lock.HwKg28SMvdgN7pz7S.wav | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music/Lock.qjSu2Nf.wav | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music/Lock.Rk60-o366.m4a | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music/Lock.SI3T x_6.mp3 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music/Lock.T3QpSK22qbSdU8p8YAX.m4a | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music/Lock.XeP-i8.m4a | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures/Lock.-6 V-28Zs1i2mga0e.png | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures/Lock.FSvM9zg.png | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures/Lock.FWAReLHUsSkJL.bmp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures/Lock.JP0X848xky.gif | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures/Lock.QrlF.gif | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures/Lock.Ur-fU4s.jpg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures/Lock.VLD3Nk1TIwkGNmyGPC.bmp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures/Lock.waKMSqrywnXqjmY3STm.bmp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos/Lock.7qrN.mkv | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos/Lock.desktop.ini | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos/Lock.eJwCkaX.avi | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos/Lock.EzPWeTUYQ0o54TxyD5.mkv | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.1fyOaNMvpe0HLFYMO.doc | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.46_piKwe1cHySGVu21.docx | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.8vMS.docx | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.D3BEewSKP- XS.xlsx | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.desktop.ini | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.dKfh5A-JQm_Dx.docx | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.EJnozy8q_wA_6u.odt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.G0mzKIgpl5aj2M-.pptx | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.icIcTV1 eT9I1Qro.xlsx | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.IqPW.xlsx | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.M4zK0AkB79QVLka.rtf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.MlLRhGX00a.pptx | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.MzqysNw1q1np8jj.docx | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.OQOxXrKa.ods | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.rq5tKC1of8p4r7HR.pps | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.ZeVUVJRj4YhmoN71.pptx | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Documents/Lock.desktop.ini | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Pictures/Lock.desktop.ini | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Videos/Lock.desktop.ini | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.KU9xovkL1lisorTK5X | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5P5NRG~1\AppData\Local\Temp\wl.jpg | Dropped File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.0AFNgyUK36kK5YHPO1.odp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.0wIFgl.pps | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.5EdvDyyb.xls | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.A4XY 5YOfDJ7NlnC.bmp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.d1NqFAAxwvSf3pfr2yZp.gif | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.jrgF.gif | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.OPqP3gN.pps | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop/Lock.YItI7wiYOV-Y.xlsx | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.CoTbYkKe.wav | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.JdjU4gAsI 0_L.gif | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.OjU _gfFJ vK4z9.pptx | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz/AppData/Roaming/Lock.UEbu8HvUsrKZg-ZGj.m4a | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music/Lock.QeeT.m4a | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures/Lock.desktop.ini | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures/Lock.E3PCt.png | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures/Lock.SLYhvryE1GJ5.png | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos/Lock.EseSTJL.avi | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos/Lock.S8aFA8f.mkv | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.2tDiT2As-QJTabaRcc L.pptx | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.B1NB4QkFt.rtf | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.goQ5n58_cIUllMnUx.xlsx | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.oh6dPV4.xlsx | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents/Lock.XeFrXnKCfR10wVvY0.pptx | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5P5NRG~1\AppData\Local\Temp/8x8x8 | Dropped File | Unknown |
Not Queried
|
...
|
»