Dynamic Analysis Report |
Classification: |
Ransomware
Dropper
Spyware
|
Threat Names: |
Generic.Ransom.Matrix.CA56E05D
VBS.Heur.Laburrak.11.Gen
Trojan.GenericKD.40672878
...
|
dlnxsw.exe
Created at 2020-09-04T06:44:00
Remarks (2/2)
(0x02000008): One or more processes crashed during the analysis. Analysis results may be incomplete.
(0x0200003A): A task was rescheduled ahead of time to reveal dormant functionality.
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200000C): The maximum memory dump size was exceeded. Some dumps may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\dlnxsw.exe | Sample File | Binary |
Malicious
|
...
|
Image Base | 0x400000 |
Entry Point | 0x4dca54 |
Size Of Code | 0xe0400 |
Size Of Initialized Data | 0x4fe00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-08-03 01:11:35+00:00 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xdaf04 | 0xdb000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.38 |
.itext | 0x4dc000 | 0x52d8 | 0x5400 | 0xdb400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.74 |
.data | 0x4e2000 | 0x5b08 | 0x5c00 | 0xe0800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.19 |
.bss | 0x4e8000 | 0x645c | 0x0 | 0x0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.idata | 0x4ef000 | 0x1236 | 0x1400 | 0xe6400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.81 |
.didata | 0x4f1000 | 0xfa | 0x200 | 0xe7800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.0 |
.edata | 0x4f2000 | 0x6c | 0x200 | 0xe7a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.31 |
.tls | 0x4f3000 | 0x14 | 0x0 | 0x0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rdata | 0x4f4000 | 0x18 | 0x200 | 0xe7c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.21 |
.rsrc | 0x4f5000 | 0x48800 | 0x48800 | 0xe7e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.96 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysFreeString | 0x0 | 0x4ef36c | 0xef0b4 | 0xe64b4 | 0x0 |
SysReAllocStringLen | 0x0 | 0x4ef370 | 0xef0b8 | 0xe64b8 | 0x0 |
SysAllocStringLen | 0x0 | 0x4ef374 | 0xef0bc | 0xe64bc | 0x0 |
SafeArrayPtrOfIndex | 0x0 | 0x4ef378 | 0xef0c0 | 0xe64c0 | 0x0 |
SafeArrayGetUBound | 0x0 | 0x4ef37c | 0xef0c4 | 0xe64c4 | 0x0 |
SafeArrayGetLBound | 0x0 | 0x4ef380 | 0xef0c8 | 0xe64c8 | 0x0 |
SafeArrayCreate | 0x0 | 0x4ef384 | 0xef0cc | 0xe64cc | 0x0 |
VariantChangeType | 0x0 | 0x4ef388 | 0xef0d0 | 0xe64d0 | 0x0 |
VariantCopy | 0x0 | 0x4ef38c | 0xef0d4 | 0xe64d4 | 0x0 |
VariantClear | 0x0 | 0x4ef390 | 0xef0d8 | 0xe64d8 | 0x0 |
VariantInit | 0x0 | 0x4ef394 | 0xef0dc | 0xe64dc | 0x0 |
GetErrorInfo | 0x0 | 0x4ef398 | 0xef0e0 | 0xe64e0 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryValueExW | 0x0 | 0x4ef3a0 | 0xef0e8 | 0xe64e8 | 0x0 |
RegOpenKeyExW | 0x0 | 0x4ef3a4 | 0xef0ec | 0xe64ec | 0x0 |
RegCloseKey | 0x0 | 0x4ef3a8 | 0xef0f0 | 0xe64f0 | 0x0 |
OpenThreadToken | 0x0 | 0x4ef3ac | 0xef0f4 | 0xe64f4 | 0x0 |
OpenProcessToken | 0x0 | 0x4ef3b0 | 0xef0f8 | 0xe64f8 | 0x0 |
GetUserNameA | 0x0 | 0x4ef3b4 | 0xef0fc | 0xe64fc | 0x0 |
GetTokenInformation | 0x0 | 0x4ef3b8 | 0xef100 | 0xe6500 | 0x0 |
GetSidSubAuthorityCount | 0x0 | 0x4ef3bc | 0xef104 | 0xe6504 | 0x0 |
GetSidSubAuthority | 0x0 | 0x4ef3c0 | 0xef108 | 0xe6508 | 0x0 |
FreeSid | 0x0 | 0x4ef3c4 | 0xef10c | 0xe650c | 0x0 |
EqualSid | 0x0 | 0x4ef3c8 | 0xef110 | 0xe6510 | 0x0 |
AllocateAndInitializeSid | 0x0 | 0x4ef3cc | 0xef114 | 0xe6514 | 0x0 |
CryptGenRandom | 0x0 | 0x4ef3d0 | 0xef118 | 0xe6518 | 0x0 |
CryptReleaseContext | 0x0 | 0x4ef3d4 | 0xef11c | 0xe651c | 0x0 |
CryptAcquireContextW | 0x0 | 0x4ef3d8 | 0xef120 | 0xe6520 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MessageBoxA | 0x0 | 0x4ef3e0 | 0xef128 | 0xe6528 | 0x0 |
CharNextW | 0x0 | 0x4ef3e4 | 0xef12c | 0xe652c | 0x0 |
LoadStringW | 0x0 | 0x4ef3e8 | 0xef130 | 0xe6530 | 0x0 |
PeekMessageW | 0x0 | 0x4ef3ec | 0xef134 | 0xe6534 | 0x0 |
MsgWaitForMultipleObjects | 0x0 | 0x4ef3f0 | 0xef138 | 0xe6538 | 0x0 |
MessageBoxW | 0x0 | 0x4ef3f4 | 0xef13c | 0xe653c | 0x0 |
GetSystemMetrics | 0x0 | 0x4ef3f8 | 0xef140 | 0xe6540 | 0x0 |
CharUpperBuffW | 0x0 | 0x4ef3fc | 0xef144 | 0xe6544 | 0x0 |
CharUpperW | 0x0 | 0x4ef400 | 0xef148 | 0xe6548 | 0x0 |
CharLowerBuffW | 0x0 | 0x4ef404 | 0xef14c | 0xe654c | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Sleep | 0x0 | 0x4ef40c | 0xef154 | 0xe6554 | 0x0 |
VirtualFree | 0x0 | 0x4ef410 | 0xef158 | 0xe6558 | 0x0 |
VirtualAlloc | 0x0 | 0x4ef414 | 0xef15c | 0xe655c | 0x0 |
lstrlenW | 0x0 | 0x4ef418 | 0xef160 | 0xe6560 | 0x0 |
VirtualQuery | 0x0 | 0x4ef41c | 0xef164 | 0xe6564 | 0x0 |
GetTickCount | 0x0 | 0x4ef420 | 0xef168 | 0xe6568 | 0x0 |
GetSystemInfo | 0x0 | 0x4ef424 | 0xef16c | 0xe656c | 0x0 |
GetVersion | 0x0 | 0x4ef428 | 0xef170 | 0xe6570 | 0x0 |
CompareStringW | 0x0 | 0x4ef42c | 0xef174 | 0xe6574 | 0x0 |
IsDBCSLeadByteEx | 0x0 | 0x4ef430 | 0xef178 | 0xe6578 | 0x0 |
IsValidLocale | 0x0 | 0x4ef434 | 0xef17c | 0xe657c | 0x0 |
SetThreadLocale | 0x0 | 0x4ef438 | 0xef180 | 0xe6580 | 0x0 |
GetSystemDefaultUILanguage | 0x0 | 0x4ef43c | 0xef184 | 0xe6584 | 0x0 |
GetUserDefaultUILanguage | 0x0 | 0x4ef440 | 0xef188 | 0xe6588 | 0x0 |
GetLocaleInfoW | 0x0 | 0x4ef444 | 0xef18c | 0xe658c | 0x0 |
WideCharToMultiByte | 0x0 | 0x4ef448 | 0xef190 | 0xe6590 | 0x0 |
MultiByteToWideChar | 0x0 | 0x4ef44c | 0xef194 | 0xe6594 | 0x0 |
GetConsoleOutputCP | 0x0 | 0x4ef450 | 0xef198 | 0xe6598 | 0x0 |
GetConsoleCP | 0x0 | 0x4ef454 | 0xef19c | 0xe659c | 0x0 |
GetACP | 0x0 | 0x4ef458 | 0xef1a0 | 0xe65a0 | 0x0 |
LoadLibraryExW | 0x0 | 0x4ef45c | 0xef1a4 | 0xe65a4 | 0x0 |
GetStartupInfoW | 0x0 | 0x4ef460 | 0xef1a8 | 0xe65a8 | 0x0 |
GetProcAddress | 0x0 | 0x4ef464 | 0xef1ac | 0xe65ac | 0x0 |
GetModuleHandleW | 0x0 | 0x4ef468 | 0xef1b0 | 0xe65b0 | 0x0 |
GetModuleFileNameW | 0x0 | 0x4ef46c | 0xef1b4 | 0xe65b4 | 0x0 |
GetCommandLineW | 0x0 | 0x4ef470 | 0xef1b8 | 0xe65b8 | 0x0 |
FreeLibrary | 0x0 | 0x4ef474 | 0xef1bc | 0xe65bc | 0x0 |
GetLastError | 0x0 | 0x4ef478 | 0xef1c0 | 0xe65c0 | 0x0 |
UnhandledExceptionFilter | 0x0 | 0x4ef47c | 0xef1c4 | 0xe65c4 | 0x0 |
RtlUnwind | 0x0 | 0x4ef480 | 0xef1c8 | 0xe65c8 | 0x0 |
RaiseException | 0x0 | 0x4ef484 | 0xef1cc | 0xe65cc | 0x0 |
ExitProcess | 0x0 | 0x4ef488 | 0xef1d0 | 0xe65d0 | 0x0 |
ExitThread | 0x0 | 0x4ef48c | 0xef1d4 | 0xe65d4 | 0x0 |
SwitchToThread | 0x0 | 0x4ef490 | 0xef1d8 | 0xe65d8 | 0x0 |
GetCurrentThreadId | 0x0 | 0x4ef494 | 0xef1dc | 0xe65dc | 0x0 |
CreateThread | 0x0 | 0x4ef498 | 0xef1e0 | 0xe65e0 | 0x0 |
DeleteCriticalSection | 0x0 | 0x4ef49c | 0xef1e4 | 0xe65e4 | 0x0 |
LeaveCriticalSection | 0x0 | 0x4ef4a0 | 0xef1e8 | 0xe65e8 | 0x0 |
EnterCriticalSection | 0x0 | 0x4ef4a4 | 0xef1ec | 0xe65ec | 0x0 |
InitializeCriticalSection | 0x0 | 0x4ef4a8 | 0xef1f0 | 0xe65f0 | 0x0 |
FindFirstFileW | 0x0 | 0x4ef4ac | 0xef1f4 | 0xe65f4 | 0x0 |
FindClose | 0x0 | 0x4ef4b0 | 0xef1f8 | 0xe65f8 | 0x0 |
WriteFile | 0x0 | 0x4ef4b4 | 0xef1fc | 0xe65fc | 0x0 |
SetFilePointer | 0x0 | 0x4ef4b8 | 0xef200 | 0xe6600 | 0x0 |
SetEndOfFile | 0x0 | 0x4ef4bc | 0xef204 | 0xe6604 | 0x0 |
ReadFile | 0x0 | 0x4ef4c0 | 0xef208 | 0xe6608 | 0x0 |
GetFileType | 0x0 | 0x4ef4c4 | 0xef20c | 0xe660c | 0x0 |
GetFileSize | 0x0 | 0x4ef4c8 | 0xef210 | 0xe6610 | 0x0 |
CreateFileW | 0x0 | 0x4ef4cc | 0xef214 | 0xe6614 | 0x0 |
GetStdHandle | 0x0 | 0x4ef4d0 | 0xef218 | 0xe6618 | 0x0 |
CloseHandle | 0x0 | 0x4ef4d4 | 0xef21c | 0xe661c | 0x0 |
LoadLibraryA | 0x0 | 0x4ef4d8 | 0xef220 | 0xe6620 | 0x0 |
TlsSetValue | 0x0 | 0x4ef4dc | 0xef224 | 0xe6624 | 0x0 |
TlsGetValue | 0x0 | 0x4ef4e0 | 0xef228 | 0xe6628 | 0x0 |
LocalFree | 0x0 | 0x4ef4e4 | 0xef22c | 0xe662c | 0x0 |
LocalAlloc | 0x0 | 0x4ef4e8 | 0xef230 | 0xe6630 | 0x0 |
WaitForSingleObject | 0x0 | 0x4ef4ec | 0xef234 | 0xe6634 | 0x0 |
WaitForMultipleObjects | 0x0 | 0x4ef4f0 | 0xef238 | 0xe6638 | 0x0 |
VirtualQueryEx | 0x0 | 0x4ef4f4 | 0xef23c | 0xe663c | 0x0 |
VirtualProtect | 0x0 | 0x4ef4f8 | 0xef240 | 0xe6640 | 0x0 |
VerSetConditionMask | 0x0 | 0x4ef4fc | 0xef244 | 0xe6644 | 0x0 |
VerifyVersionInfoW | 0x0 | 0x4ef500 | 0xef248 | 0xe6648 | 0x0 |
SuspendThread | 0x0 | 0x4ef504 | 0xef24c | 0xe664c | 0x0 |
SizeofResource | 0x0 | 0x4ef508 | 0xef250 | 0xe6650 | 0x0 |
SetThreadPriority | 0x0 | 0x4ef50c | 0xef254 | 0xe6654 | 0x0 |
SetLastError | 0x0 | 0x4ef510 | 0xef258 | 0xe6658 | 0x0 |
SetFileAttributesW | 0x0 | 0x4ef514 | 0xef25c | 0xe665c | 0x0 |
SetEvent | 0x0 | 0x4ef518 | 0xef260 | 0xe6660 | 0x0 |
SetErrorMode | 0x0 | 0x4ef51c | 0xef264 | 0xe6664 | 0x0 |
ResumeThread | 0x0 | 0x4ef520 | 0xef268 | 0xe6668 | 0x0 |
ResetEvent | 0x0 | 0x4ef524 | 0xef26c | 0xe666c | 0x0 |
ReleaseMutex | 0x0 | 0x4ef528 | 0xef270 | 0xe6670 | 0x0 |
QueryPerformanceFrequency | 0x0 | 0x4ef52c | 0xef274 | 0xe6674 | 0x0 |
QueryPerformanceCounter | 0x0 | 0x4ef530 | 0xef278 | 0xe6678 | 0x0 |
OpenMutexW | 0x0 | 0x4ef534 | 0xef27c | 0xe667c | 0x0 |
MoveFileExW | 0x0 | 0x4ef538 | 0xef280 | 0xe6680 | 0x0 |
LockResource | 0x0 | 0x4ef53c | 0xef284 | 0xe6684 | 0x0 |
LoadResource | 0x0 | 0x4ef540 | 0xef288 | 0xe6688 | 0x0 |
LoadLibraryW | 0x0 | 0x4ef544 | 0xef28c | 0xe668c | 0x0 |
HeapFree | 0x0 | 0x4ef548 | 0xef290 | 0xe6690 | 0x0 |
HeapDestroy | 0x0 | 0x4ef54c | 0xef294 | 0xe6694 | 0x0 |
HeapCreate | 0x0 | 0x4ef550 | 0xef298 | 0xe6698 | 0x0 |
HeapAlloc | 0x0 | 0x4ef554 | 0xef29c | 0xe669c | 0x0 |
GetVolumeInformationW | 0x0 | 0x4ef558 | 0xef2a0 | 0xe66a0 | 0x0 |
GetVersionExW | 0x0 | 0x4ef55c | 0xef2a4 | 0xe66a4 | 0x0 |
GetUserDefaultLangID | 0x0 | 0x4ef560 | 0xef2a8 | 0xe66a8 | 0x0 |
GetUserDefaultLCID | 0x0 | 0x4ef564 | 0xef2ac | 0xe66ac | 0x0 |
GetThreadTimes | 0x0 | 0x4ef568 | 0xef2b0 | 0xe66b0 | 0x0 |
GetThreadPriority | 0x0 | 0x4ef56c | 0xef2b4 | 0xe66b4 | 0x0 |
GetThreadLocale | 0x0 | 0x4ef570 | 0xef2b8 | 0xe66b8 | 0x0 |
GetSystemTimes | 0x0 | 0x4ef574 | 0xef2bc | 0xe66bc | 0x0 |
GetSystemDefaultLangID | 0x0 | 0x4ef578 | 0xef2c0 | 0xe66c0 | 0x0 |
GetSystemDefaultLCID | 0x0 | 0x4ef57c | 0xef2c4 | 0xe66c4 | 0x0 |
GetProcessTimes | 0x0 | 0x4ef580 | 0xef2c8 | 0xe66c8 | 0x0 |
GetLocalTime | 0x0 | 0x4ef584 | 0xef2cc | 0xe66cc | 0x0 |
GetFullPathNameW | 0x0 | 0x4ef588 | 0xef2d0 | 0xe66d0 | 0x0 |
GetFileAttributesW | 0x0 | 0x4ef58c | 0xef2d4 | 0xe66d4 | 0x0 |
GetExitCodeThread | 0x0 | 0x4ef590 | 0xef2d8 | 0xe66d8 | 0x0 |
GetDriveTypeW | 0x0 | 0x4ef594 | 0xef2dc | 0xe66dc | 0x0 |
GetDiskFreeSpaceW | 0x0 | 0x4ef598 | 0xef2e0 | 0xe66e0 | 0x0 |
GetDateFormatW | 0x0 | 0x4ef59c | 0xef2e4 | 0xe66e4 | 0x0 |
GetCurrentThread | 0x0 | 0x4ef5a0 | 0xef2e8 | 0xe66e8 | 0x0 |
GetCurrentProcessId | 0x0 | 0x4ef5a4 | 0xef2ec | 0xe66ec | 0x0 |
GetCurrentProcess | 0x0 | 0x4ef5a8 | 0xef2f0 | 0xe66f0 | 0x0 |
GetComputerNameA | 0x0 | 0x4ef5ac | 0xef2f4 | 0xe66f4 | 0x0 |
GetCPInfoExW | 0x0 | 0x4ef5b0 | 0xef2f8 | 0xe66f8 | 0x0 |
GetCPInfo | 0x0 | 0x4ef5b4 | 0xef2fc | 0xe66fc | 0x0 |
FreeResource | 0x0 | 0x4ef5b8 | 0xef300 | 0xe6700 | 0x0 |
InterlockedCompareExchange | 0x0 | 0x4ef5bc | 0xef304 | 0xe6704 | 0x0 |
FormatMessageW | 0x0 | 0x4ef5c0 | 0xef308 | 0xe6708 | 0x0 |
FindResourceW | 0x0 | 0x4ef5c4 | 0xef30c | 0xe670c | 0x0 |
FindNextFileW | 0x0 | 0x4ef5c8 | 0xef310 | 0xe6710 | 0x0 |
ExpandEnvironmentStringsW | 0x0 | 0x4ef5cc | 0xef314 | 0xe6714 | 0x0 |
EnumSystemLocalesW | 0x0 | 0x4ef5d0 | 0xef318 | 0xe6718 | 0x0 |
EnumCalendarInfoW | 0x0 | 0x4ef5d4 | 0xef31c | 0xe671c | 0x0 |
DeleteFileW | 0x0 | 0x4ef5d8 | 0xef320 | 0xe6720 | 0x0 |
CreateProcessW | 0x0 | 0x4ef5dc | 0xef324 | 0xe6724 | 0x0 |
CreateMutexW | 0x0 | 0x4ef5e0 | 0xef328 | 0xe6728 | 0x0 |
CreateEventW | 0x0 | 0x4ef5e4 | 0xef32c | 0xe672c | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoUninitialize | 0x0 | 0x4ef5ec | 0xef334 | 0xe6734 | 0x0 |
CoInitialize | 0x0 | 0x4ef5f0 | 0xef338 | 0xe6738 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderPathW | 0x0 | 0x4ef5f8 | 0xef340 | 0xe6740 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WSACleanup | 0x0 | 0x4ef600 | 0xef348 | 0xe6748 | 0x0 |
WSAStartup | 0x0 | 0x4ef604 | 0xef34c | 0xe674c | 0x0 |
gethostname | 0x0 | 0x4ef608 | 0xef350 | 0xe6750 | 0x0 |
gethostbyname | 0x0 | 0x4ef60c | 0xef354 | 0xe6754 | 0x0 |
inet_ntoa | 0x0 | 0x4ef610 | 0xef358 | 0xe6758 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetShareEnum | 0x0 | 0x4ef618 | 0xef360 | 0xe6760 | 0x0 |
NetApiBufferFree | 0x0 | 0x4ef61c | 0xef364 | 0xe6764 | 0x0 |
Api name | EAT Address | Ordinal |
---|---|---|
TMethodImplementationIntercept | 0x509b8 | 0x1 |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
dlnxsw.exe | 1 | 0x00400000 | 0x0053DFFF | Relevant Image |
![]() |
32-bit | 0x00407620 |
![]() |
![]() |
...
|
nwdefn5v.exe | 3 | 0x00400000 | 0x0053DFFF | Relevant Image |
![]() |
32-bit | 0x00407620 |
![]() |
![]() |
...
|
Threat Name | Severity |
---|---|
Generic.Ransom.Matrix.CA56E05D |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\mBMahmXw.vbs | Dropped File | Text |
Malicious
|
...
|
Threat Name | Severity |
---|---|
VBS.Heur.Laburrak.11.Gen |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\tdq963ii.exe | Dropped File | Binary |
Malicious
|
...
|
Severity |
Blacklisted
|
Names | Mal/Generic-S |
Image Base | 0x400000 |
Entry Point | 0x475810 |
Size Of Code | 0x29000 |
Size Of Initialized Data | 0x1000 |
Size Of Uninitialized Data | 0x4c000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-12-10 21:18:46+00:00 |
CompanyName | Sysinternals - www.sysinternals.com |
FileDescription | Handle viewer |
FileVersion | 4.11 |
InternalName | Nthandle |
LegalCopyright | Copyright (C) 1997-2017 Mark Russinovich |
OriginalFilename | Nthandle.exe |
ProductName | Sysinternals Handle |
ProductVersion | 4.11 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
UPX0 | 0x401000 | 0x4c000 | 0x0 | 0x400 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
UPX1 | 0x44d000 | 0x29000 | 0x28a00 | 0x400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.93 |
.rsrc | 0x476000 | 0x1000 | 0x800 | 0x28e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.04 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegOpenKeyW | 0x0 | 0x47666c | 0x7666c | 0x2946c | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PrintDlgW | 0x0 | 0x476674 | 0x76674 | 0x29474 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EndDoc | 0x0 | 0x47667c | 0x7667c | 0x2947c | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | 0x0 | 0x476684 | 0x76684 | 0x29484 | 0x0 |
ExitProcess | 0x0 | 0x476688 | 0x76688 | 0x29488 | 0x0 |
GetProcAddress | 0x0 | 0x47668c | 0x7668c | 0x2948c | 0x0 |
VirtualProtect | 0x0 | 0x476690 | 0x76690 | 0x29490 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EndDialog | 0x0 | 0x476698 | 0x76698 | 0x29498 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VerQueryValueW | 0x0 | 0x4766a0 | 0x766a0 | 0x294a0 | 0x0 |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
tdq963ii.exe | 22 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00475810 |
![]() |
![]() |
...
|
tdq963ii.exe | 21 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
tdq963ii.exe | 22 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004080C0 |
![]() |
![]() |
...
|
tdq963ii.exe | 21 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004080C0 |
![]() |
![]() |
...
|
tdq963ii.exe | 21 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040B435 |
![]() |
![]() |
...
|
tdq963ii.exe | 21 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
tdq963ii.exe | 22 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040B435 |
![]() |
![]() |
...
|
tdq963ii.exe | 22 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
tdq963ii.exe | 21 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040608C |
![]() |
![]() |
...
|
tdq963ii.exe | 21 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00412434 |
![]() |
![]() |
...
|
tdq963ii.exe | 21 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004048D4 |
![]() |
![]() |
...
|
tdq963ii.exe | 22 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00406078 |
![]() |
![]() |
...
|
tdq963ii.exe | 22 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004048D4 |
![]() |
![]() |
...
|
tdq963ii.exe | 22 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004020F0 |
![]() |
![]() |
...
|
tdq963ii.exe | 21 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004020F0 |
![]() |
![]() |
...
|
tdq963ii.exe | 22 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
tdq963ii.exe | 26 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
tdq963ii.exe | 26 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004080C0 |
![]() |
![]() |
...
|
tdq963ii.exe | 26 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040B435 |
![]() |
![]() |
...
|
tdq963ii.exe | 28 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
tdq963ii.exe | 26 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
tdq963ii.exe | 26 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00406078 |
![]() |
![]() |
...
|
tdq963ii.exe | 28 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004080C0 |
![]() |
![]() |
...
|
tdq963ii.exe | 26 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040DEC6 |
![]() |
![]() |
...
|
tdq963ii.exe | 28 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040AE73 |
![]() |
![]() |
...
|
tdq963ii.exe | 28 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040B435 |
![]() |
![]() |
...
|
tdq963ii.exe | 26 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004048D4 |
![]() |
![]() |
...
|
tdq963ii.exe | 28 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
tdq963ii.exe | 26 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004020F0 |
![]() |
![]() |
...
|
tdq963ii.exe | 26 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
tdq963ii.exe | 28 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00406078 |
![]() |
![]() |
...
|
tdq963ii.exe | 28 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004048D4 |
![]() |
![]() |
...
|
tdq963ii.exe | 28 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004020F0 |
![]() |
![]() |
...
|
tdq963ii.exe | 28 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
tdq963ii.exe | 133 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00475810 |
![]() |
![]() |
...
|
tdq963ii.exe | 133 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004080C0 |
![]() |
![]() |
...
|
tdq963ii.exe | 133 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040B435 |
![]() |
![]() |
...
|
tdq963ii.exe | 133 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
tdq963ii.exe | 133 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00406078 |
![]() |
![]() |
...
|
tdq963ii.exe | 133 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040DEC6 |
![]() |
![]() |
...
|
tdq963ii.exe | 133 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004048D4 |
![]() |
![]() |
...
|
tdq963ii.exe | 133 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004112CE |
![]() |
![]() |
...
|
tdq963ii.exe | 133 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004020F0 |
![]() |
![]() |
...
|
tdq963ii.exe | 133 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
tdq963ii.exe | 139 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00475965 |
![]() |
![]() |
...
|
tdq963ii.exe | 139 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004080C0 |
![]() |
![]() |
...
|
tdq963ii.exe | 139 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040B435 |
![]() |
![]() |
...
|
tdq963ii.exe | 139 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004020F0 |
![]() |
![]() |
...
|
tdq963ii.exe | 139 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
tdq963ii.exe | 144 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
tdq963ii.exe | 144 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004080C0 |
![]() |
![]() |
...
|
tdq963ii.exe | 144 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040B435 |
![]() |
![]() |
...
|
tdq963ii.exe | 144 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
tdq963ii.exe | 144 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00406078 |
![]() |
![]() |
...
|
tdq963ii.exe | 144 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004048D4 |
![]() |
![]() |
...
|
tdq963ii.exe | 144 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040581F |
![]() |
![]() |
...
|
tdq963ii.exe | 144 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00416E18 |
![]() |
![]() |
...
|
tdq963ii.exe | 144 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004020F0 |
![]() |
![]() |
...
|
tdq963ii.exe | 144 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00412D88 |
![]() |
![]() |
...
|
tdq963ii.exe | 144 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
tdq963ii.exe | 21 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004046F7 |
![]() |
![]() |
...
|
tdq963ii.exe | 21 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040B12F |
![]() |
![]() |
...
|
tdq963ii.exe | 21 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
tdq963ii.exe | 161 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00475810 |
![]() |
![]() |
...
|
tdq963ii.exe | 161 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004080C0 |
![]() |
![]() |
...
|
tdq963ii.exe | 161 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040B435 |
![]() |
![]() |
...
|
tdq963ii.exe | 161 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
tdq963ii.exe | 161 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040608C |
![]() |
![]() |
...
|
tdq963ii.exe | 161 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00412434 |
![]() |
![]() |
...
|
tdq963ii.exe | 166 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
tdq963ii.exe | 161 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004048D4 |
![]() |
![]() |
...
|
tdq963ii.exe | 164 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
tdq963ii.exe | 166 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004080C0 |
![]() |
![]() |
...
|
tdq963ii.exe | 161 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004020F0 |
![]() |
![]() |
...
|
tdq963ii.exe | 164 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040AE73 |
![]() |
![]() |
...
|
tdq963ii.exe | 166 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040B435 |
![]() |
![]() |
...
|
tdq963ii.exe | 164 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040B435 |
![]() |
![]() |
...
|
tdq963ii.exe | 164 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
tdq963ii.exe | 166 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
tdq963ii.exe | 166 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040608C |
![]() |
![]() |
...
|
tdq963ii.exe | 164 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040608C |
![]() |
![]() |
...
|
tdq963ii.exe | 164 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004048D4 |
![]() |
![]() |
...
|
tdq963ii.exe | 166 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00412434 |
![]() |
![]() |
...
|
tdq963ii.exe | 164 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004020F0 |
![]() |
![]() |
...
|
tdq963ii.exe | 166 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00414E0A |
![]() |
![]() |
...
|
tdq963ii.exe | 166 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004048D4 |
![]() |
![]() |
...
|
tdq963ii.exe | 166 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004020F0 |
![]() |
![]() |
...
|
tdq963ii.exe | 164 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
tdq963ii.exe | 166 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
tdq963ii.exe | 171 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
tdq963ii.exe | 171 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004080C0 |
![]() |
![]() |
...
|
tdq963ii.exe | 171 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040B435 |
![]() |
![]() |
...
|
tdq963ii.exe | 171 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
tdq963ii.exe | 178 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
tdq963ii.exe | 171 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00406078 |
![]() |
![]() |
...
|
tdq963ii.exe | 171 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00412434 |
![]() |
![]() |
...
|
tdq963ii.exe | 177 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
tdq963ii.exe | 178 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040AE73 |
![]() |
![]() |
...
|
tdq963ii.exe | 171 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004048D4 |
![]() |
![]() |
...
|
tdq963ii.exe | 177 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004080C0 |
![]() |
![]() |
...
|
tdq963ii.exe | 171 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004020F0 |
![]() |
![]() |
...
|
tdq963ii.exe | 171 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
tdq963ii.exe | 178 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040B435 |
![]() |
![]() |
...
|
tdq963ii.exe | 178 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
tdq963ii.exe | 177 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040B435 |
![]() |
![]() |
...
|
tdq963ii.exe | 177 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
tdq963ii.exe | 178 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040608C |
![]() |
![]() |
...
|
tdq963ii.exe | 178 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004048D4 |
![]() |
![]() |
...
|
tdq963ii.exe | 177 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040608C |
![]() |
![]() |
...
|
tdq963ii.exe | 178 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004020F0 |
![]() |
![]() |
...
|
tdq963ii.exe | 177 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004048D4 |
![]() |
![]() |
...
|
tdq963ii.exe | 177 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004020F0 |
![]() |
![]() |
...
|
tdq963ii.exe | 177 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
tdq963ii.exe | 178 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
tdq963ii.exe | 161 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
tdq963ii.exe | 181 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
tdq963ii.exe | 181 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004080C0 |
![]() |
![]() |
...
|
tdq963ii.exe | 181 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040B435 |
![]() |
![]() |
...
|
tdq963ii.exe | 181 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
tdq963ii.exe | 181 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00406078 |
![]() |
![]() |
...
|
tdq963ii.exe | 181 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00412434 |
![]() |
![]() |
...
|
tdq963ii.exe | 181 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004048D4 |
![]() |
![]() |
...
|
tdq963ii.exe | 181 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004020F0 |
![]() |
![]() |
...
|
tdq963ii.exe | 189 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
tdq963ii.exe | 188 | 0x00400000 | 0x00476FFF | Relevant Image |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
tdq963ii.exe | 189 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040AE73 |
![]() |
![]() |
...
|
tdq963ii.exe | 189 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040B435 |
![]() |
![]() |
...
|
tdq963ii.exe | 189 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
tdq963ii.exe | 188 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00406078 |
![]() |
![]() |
...
|
tdq963ii.exe | 188 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004048D4 |
![]() |
![]() |
...
|
tdq963ii.exe | 189 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040608C |
![]() |
![]() |
...
|
tdq963ii.exe | 188 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004020F0 |
![]() |
![]() |
...
|
tdq963ii.exe | 189 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00412434 |
![]() |
![]() |
...
|
tdq963ii.exe | 188 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
tdq963ii.exe | 189 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004048D4 |
![]() |
![]() |
...
|
tdq963ii.exe | 189 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004020F0 |
![]() |
![]() |
...
|
tdq963ii.exe | 189 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
tdq963ii.exe | 196 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
tdq963ii.exe | 197 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
tdq963ii.exe | 196 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040AE73 |
![]() |
![]() |
...
|
tdq963ii.exe | 197 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040AE73 |
![]() |
![]() |
...
|
tdq963ii.exe | 197 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040B435 |
![]() |
![]() |
...
|
tdq963ii.exe | 196 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040B435 |
![]() |
![]() |
...
|
tdq963ii.exe | 196 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
tdq963ii.exe | 197 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
tdq963ii.exe | 197 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00406078 |
![]() |
![]() |
...
|
tdq963ii.exe | 196 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040608C |
![]() |
![]() |
...
|
tdq963ii.exe | 196 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00412434 |
![]() |
![]() |
...
|
tdq963ii.exe | 197 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00412434 |
![]() |
![]() |
...
|
tdq963ii.exe | 197 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004048D4 |
![]() |
![]() |
...
|
tdq963ii.exe | 196 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004048D4 |
![]() |
![]() |
...
|
tdq963ii.exe | 196 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004020F0 |
![]() |
![]() |
...
|
tdq963ii.exe | 197 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004020F0 |
![]() |
![]() |
...
|
tdq963ii.exe | 197 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
tdq963ii.exe | 196 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
tdq963ii.exe | 206 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
tdq963ii.exe | 206 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004080C0 |
![]() |
![]() |
...
|
tdq963ii.exe | 206 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040B435 |
![]() |
![]() |
...
|
tdq963ii.exe | 206 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
tdq963ii.exe | 206 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040608C |
![]() |
![]() |
...
|
tdq963ii.exe | 206 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00412434 |
![]() |
![]() |
...
|
tdq963ii.exe | 206 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004048D4 |
![]() |
![]() |
...
|
tdq963ii.exe | 206 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004020F0 |
![]() |
![]() |
...
|
tdq963ii.exe | 206 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
tdq963ii.exe | 208 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
tdq963ii.exe | 207 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
tdq963ii.exe | 208 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004080C0 |
![]() |
![]() |
...
|
tdq963ii.exe | 208 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040B435 |
![]() |
![]() |
...
|
tdq963ii.exe | 207 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004080C0 |
![]() |
![]() |
...
|
tdq963ii.exe | 207 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040B435 |
![]() |
![]() |
...
|
tdq963ii.exe | 208 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
tdq963ii.exe | 207 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
tdq963ii.exe | 208 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040608C |
![]() |
![]() |
...
|
tdq963ii.exe | 208 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00412434 |
![]() |
![]() |
...
|
tdq963ii.exe | 207 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040608C |
![]() |
![]() |
...
|
tdq963ii.exe | 207 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004048D4 |
![]() |
![]() |
...
|
tdq963ii.exe | 208 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00414E0A |
![]() |
![]() |
...
|
tdq963ii.exe | 207 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004020F0 |
![]() |
![]() |
...
|
tdq963ii.exe | 208 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004048D4 |
![]() |
![]() |
...
|
tdq963ii.exe | 212 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
tdq963ii.exe | 208 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004020F0 |
![]() |
![]() |
...
|
tdq963ii.exe | 212 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040AE73 |
![]() |
![]() |
...
|
tdq963ii.exe | 212 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040B435 |
![]() |
![]() |
...
|
tdq963ii.exe | 212 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
tdq963ii.exe | 212 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00406078 |
![]() |
![]() |
...
|
tdq963ii.exe | 212 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004048D4 |
![]() |
![]() |
...
|
tdq963ii.exe | 212 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004020F0 |
![]() |
![]() |
...
|
tdq963ii.exe | 208 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
tdq963ii.exe | 207 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
tdq963ii.exe | 212 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
tdq963ii.exe | 221 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00475810 |
![]() |
![]() |
...
|
tdq963ii.exe | 216 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
tdq963ii.exe | 216 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040AE73 |
![]() |
![]() |
...
|
tdq963ii.exe | 216 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040B435 |
![]() |
![]() |
...
|
tdq963ii.exe | 216 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
tdq963ii.exe | 216 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x0040608C |
![]() |
![]() |
...
|
tdq963ii.exe | 216 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004048D4 |
![]() |
![]() |
...
|
tdq963ii.exe | 222 | 0x00400000 | 0x00476FFF | First Execution |
![]() |
32-bit | 0x00407336 |
![]() |
![]() |
...
|
tdq963ii.exe | 216 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004020F0 |
![]() |
![]() |
...
|
tdq963ii.exe | 216 | 0x00400000 | 0x00476FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
tdq963ii.exe | 222 | 0x00400000 | 0x00476FFF | Content Changed |
![]() |
32-bit | 0x004080C0 |
![]() |
![]() |
...
|
Threat Name | Severity |
---|---|
Trojan.GenericKD.40672878 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\vLykOV4Y_3l2VkIHp\Ntc67Bf2iLd3ESzWKwV0.docx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\vLykOV4Y_3l2VkIHp\21Ar6w3\rOvmf5QogX.odt | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Class.zip | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Module.zip | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\indexedDB\moz-safe-about+home\idb\818200132aebmoouht.sqlite | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\HRV\AdobeID.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\VhIBg8.docx | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\UserControl.zip | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\EmptyDatabase.zip | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\FRA\AdobeID.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\SKY\AdobeID.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\TUR\AdobeID.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\TUR\DefaultID.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\DAN\Dynamic.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Interface.zip | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Visualizer.zip | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JlHpXBn7\x3vOCKylX.xlsx | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\5Fy4 tZdZ1w2ZsP.docx | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CHT\StandardBusiness.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\vLykOV4Y_3l2VkIHp\21Ar6w3\AFeQs.xls | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CZE\StandardBusiness.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\ENU\SignHere.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\EUQ\SignHere.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\PDFSigQFormalRep.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\EUQ\Standard.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Mozilla\Firefox\Profiles\silmbjec.default\OfflineCache\index.sqlite | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\DEU\DefaultID.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\DEU\Dynamic.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\content-prefs.sqlite | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\FRA\SignHere.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\PTB\DefaultID.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\LoginForm.zip | Modified File | Unknown |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\HRV\Standard.pdf | Modified File | Unknown |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\[BobGreen85@criptext.com].Lol3dkOz-je3O56U4.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\CodeFile.zip | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\DataSet.zip | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\[BobGreen85@criptext.com].8JXyUQks-2N17JwJG.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\SVE\AdobeID.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\sql90.xsl | Modified File | Binary |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\5KV2W3L69- l7u9zN7\YgAY0.jpg | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\POL\SignHere.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\RUM\Pointers.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SUO\StandardBusiness.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\Sybase.xsl | Modified File | Stream |
Unknown
|
...
|
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Resources\1033\msolui100.rll | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Leggimi.htm | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32Info.exe | Modified File | Stream |
Unknown
|
...
|
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\sql2000.xsl | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Leame.htm | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\LeiaMe.htm | Modified File | Text |
Unknown
|
...
|
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data | Actions |
---|---|---|---|---|---|---|
http://www.adobe.com/br/products/acrobat | - | - | - |
Unknown
|
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroTextExtractor.exe | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.PTB | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.SVE | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\FRA\eula.ini | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.CHS | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\BRdlang32.CAT | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.RUM | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\cryptocme2.sig | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\CHT\license.html | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\ENU\license.html | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\Multimedia.CAT | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\HRV\license.html | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\SendMail.CAT | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Liesmich.htm | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Benioku.htm | Modified File | Text |
Unknown
|
...
|
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data | Actions |
---|---|---|---|---|---|---|
http://www.adobe.com/products/acrobat | - | - | - |
Unknown
|
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Adobe.Reader.Dependencies.manifest | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\IA32.CZE | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Lisezmoi.htm | Modified File | Text |
Unknown
|
...
|
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data | Actions |
---|---|---|---|---|---|---|
http://www.adobe.com/fr/products/acrobat | - | - | - |
Unknown
|
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Berime.htm | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Llegiu-me.htm | Modified File | Text |
Unknown
|
...
|
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data | Actions |
---|---|---|---|---|---|---|
http://www.adobe.com/products/acrobat | - | - | - |
Unknown
|
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\KOR\license.html | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\PTB\license.html | Modified File | Text |
Unknown
|
...
|
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data | Actions |
---|---|---|---|---|---|---|
http://www.adobe.com/go/protected_content_br | - | - | - |
Unknown
|
Not Queried
|
...
|
http://www.adobe.com/go/rikla_program_br | - | - | - |
Unknown
|
Not Queried
|
...
|
http://www.adobe.com/go/aatl_br | - | - | - |
Unknown
|
Not Queried
|
...
|
http://www.adobe.com/go/settmgr_networking_br | - | - | - |
Unknown
|
Not Queried
|
...
|
http://www.adobe.com/go/air_update_details_br | - | - | - |
Unknown
|
Not Queried
|
...
|
http://www.adobe.com/go/terms_br | - | - | - |
Unknown
|
Not Queried
|
...
|
http://www.adobe.com/go/privacy_br | - | - | - |
Unknown
|
Not Queried
|
...
|
http://www.adobe.com/go/settingsmanager_br | - | - | - |
Unknown
|
Not Queried
|
...
|
http://www.adobe.com/go/RTMFP_br | - | - | - |
Unknown
|
Not Queried
|
...
|
http://airdownload.adobe.com/air/applications/SettingsManager/SettingsManager.air | - | - | - |
Unknown
|
Not Queried
|
...
|
http://www.adobe.com/go/flashplayer_security_br | - | - | - |
Unknown
|
Not Queried
|
...
|
http://www.adobe.com/go/readerextensions_br | - | - | - |
Unknown
|
Not Queried
|
...
|
http://www.adobe.com/go/settmgr_storage_br | - | - | - |
Unknown
|
Not Queried
|
...
|
http://www.adobe.com/go/partners_cds_br | - | - | - |
Unknown
|
Not Queried
|
...
|
http://www.adobe.com/go/update_details_url_br | - | - | - |
Unknown
|
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\SLV\license.html | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\UKR\license.html | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\SendMail.CZE | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\CZE\eula.ini | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\NLD\eula.ini | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\EUQ\eula.ini | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\RUS\eula.ini | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\SVE\eula.ini | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\CZE\license.html | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\RUM\eula.ini | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\accessibility.CAT | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\ReadOutLoud.CAT | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\updater.CAT | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\updater.CZE | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\ESP\license.html | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\HUN\license.html | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\NLD\license.html | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\RUM\license.html | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\SUO\license.html | Modified File | Text |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\Acroform.CAT | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\da_DK\IA32.DAN | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Adobe\Acrobat\10.0\[BobGreen85@criptext.com].mrV4KzmG-KtMwL4uf.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\n8jJ7uBD.xlsx | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\[BobGreen85@criptext.com].P4IJjywu-RIdrVU49.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\CZE\[BobGreen85@criptext.com].qHxkUO2f-Zrn6JaWd.BG85 | Dropped File | Binary |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\KOR\Dynamic.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\NOR\[BobGreen85@criptext.com].CcWAEdfC-PNQUbmH6.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CHS\[BobGreen85@criptext.com].mPBj0tIY-ND8NqoVr.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\ESP\[BobGreen85@criptext.com].CLlrcJ85-PvGiDtZl.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\RUM\[BobGreen85@criptext.com].m87BDMJq-JR0az6HD.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CZE\[BobGreen85@criptext.com].90SYAiI4-durmJ3BJ.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\ITA\[BobGreen85@criptext.com].iyxGHCSQ-V7tcnxuD.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\NOR\Dynamic.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\POL\[BobGreen85@criptext.com].V4fvmN3c-ZwViU08N.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\PTB\SignHere.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\RUS\[BobGreen85@criptext.com].7jLgqDd5-zSnwt6hi.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\NOR\AdobeID.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\RUM\StandardBusiness.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\ESP\SignHere.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SKY\Dynamic.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CAT\[BobGreen85@criptext.com].vfYFm1p9-eohSREcc.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\TUR\Pointers.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SLV\Pointers.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\UKR\[BobGreen85@criptext.com].oIaYSsJQ-9mXUkXTW.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SVE\SignHere.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SLV\SignHere.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\UKR\Faces.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\ITA\SignHere.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\lS gbMc\Oz5qK1HKQ0at4YOJKs.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\DEU\[BobGreen85@criptext.com].m6VEBaYb-ZCOLA5DH.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\EUQ\[BobGreen85@criptext.com].x4eZjdac-B5L2nplm.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\HRV\[BobGreen85@criptext.com].WkPvMMMx-4XUcbPqd.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\KOR\SignHere.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\POL\Dynamic.pdf | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\HUN\[BobGreen85@criptext.com].kO1jUksP-byL9bQ8z.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\[BobGreen85@criptext.com].9ixvgFnF-13vIZIB6.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\da_DK\[BobGreen85@criptext.com].tWINSexu-fCJadl4q.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\da_DK\updater.DAN | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.NLD | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\[BobGreen85@criptext.com].A3qzozzz-0tIDjveE.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\[BobGreen85@criptext.com].FakTGsMX-SQtPKirW.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\Multimedia.CZE | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.DAN | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\DVA.CAT | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Eula.exe | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\de_DE\[BobGreen85@criptext.com].ucLs8PyG-M2cmPB8A.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.SKY | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\[BobGreen85@criptext.com].JbTl27s3-JOASRsvx.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\ESP\[BobGreen85@criptext.com].ED6PIQBo-kP9jQSnO.BG85 | Dropped File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\SeVHvDyC.bmp | Dropped File | Image |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Ch81ANBE.bat | Dropped File | Batch |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\DEU\BG85_INFO.rtf | Dropped File | RTF |
Unknown
|
...
|
ALL YOUR VALUABLE DATA WAS ENCRYPTED!All y ur fil s w rn r pt d with str ng cr ptlg rithm S-256 + RS -2048. Pl s b sur th t y ur fil s r n t br k n nd u c n r st r th m t d y. If y u r ll w nt t r st r y ur fil s pl s writ us t th-m ils: BobGreen85@criptext.com BobGreen85@aol.com BobGreen85@tutanota.com In subj ct lin writur ID: 2660EAA9CA5C3071Imp rt nt! Pl s s nd y ur m ss g tll f ur 3 -m il ddr ss s. This is r ll imp rt nt b c usf d liv r pr bl ms f s m m il s rvi s! Important! If you haven't received a response from us within 24 hours, please try to use a different email service ( Gmail, Yahoo, AOL, etc ) . Important! Please check your SPAM folder each time you wait for our response! If you find our email in the SPAM folder please move it to your Inbox. Important! We are always in touch and ready to help you as soon as possible!tt ch up t 3 sm ll ncr pt d fil s f r fr t st d ryption. Pl s n te th t th fil s y u s nd us sh uld n t c nt in ... |
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\EmptyDatabase.zip | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\TextFile.zip | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Dialog.zip | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\SettingsInternal.zip | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\G155GR\XN Nj6.xlsx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JlHpXBn7\RMWR2N xdcNl.xls | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\CHS\AdobeID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\DEU\AdobeID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\secmod.db | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\DAN\DefaultID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\FRA\DefaultID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\KOR\AdobeID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\PTB\AdobeID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\SLV\AdobeID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AppConfig.zip | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Wbh-rxLyXar3C5.xlsx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\eN5m2wE7n b.odt | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\CAT\AdobeID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Form.zip | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\DAN\AdobeID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\JPN\DefaultID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\POL\DefaultID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\SKY\DefaultID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\permissions.sqlite | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AppConfigInternal.zip | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\JPN\AdobeID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\POL\AdobeID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CAT\Standard.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CHT\SignHere.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Text.zip | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\YxYywkrNRBdEd.doc | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\lS gbMc\_D3G3fnlKg.ods | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\CHT\AdobeID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\ENU\AdobeID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\HUN\AdobeID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\NLD\AdobeID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\RUM\AdobeID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\SUO\AdobeID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\UKR\AdobeID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CAT\StandardBusiness.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\SplashScreen.zip | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\GsChAk3eag4bUKbjR_.xlsx | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xaMADQzHGAzmXsZtl9.docx | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CAT\SignHere.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CHT\Hanko.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\ENU\StandardBusiness.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CHS\Hanko.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\signons.sqlite | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\DAN\SignHere.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\ESP\Dynamic.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\EUQ\StandardBusiness.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\vLykOV4Y_3l2VkIHp\l9h2RZXXX5kbGC\sqqa\GaylEHQJ5Dn.odt | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\CHS\DefaultID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\HRV\DefaultID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CZE\Faces.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\ESP\StandardBusiness.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AssemblyInfoInternal.zip | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Resource.zip | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\AppConfigurationInternal.zip | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\KOR\DefaultID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\HUN\Dynamic.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\HRV\SignHere.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\HRV\Pointers.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\SLV\DefaultID.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\ITA\Dynamic.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\ITA\StandardBusiness.pdf | Modified File | Unknown |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\webappsstore.sqlite | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\Class.zip | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\previews_opt_out.db | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\sessionstore.bak | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\cert8.db | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\[BobGreen85@criptext.com].js7XfExX-eEMiKUlT.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Java\jre7\lib\deploy\ffjcext.zip | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\[BobGreen85@criptext.com].V6w2VF9Y-k5gklhbc.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\[BobGreen85@criptext.com].l6GxCuY6-LWB54kh8.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\[BobGreen85@criptext.com].jU4lRFpa-9BzxeXzZ.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\ResourceInternal.zip | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\[BobGreen85@criptext.com].21OCBaV2-ws9EfAS0.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\[BobGreen85@criptext.com].iIEWjdWc-WZ3dNOq0.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\vLykOV4Y_3l2VkIHp\l9h2RZXXX5kbGC\sqqa\q6EU42d7xh5nqo7LCE.docx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\vLykOV4Y_3l2VkIHp\21Ar6w3\[BobGreen85@criptext.com].h2YDlpN9-7WySfQD8.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\CAT\DefaultID.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\[BobGreen85@criptext.com].RRIGav65-SJIDeIwz.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\AboutBox.zip | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\UKR\Pointers.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Stars.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Pictures\Sample Pictures\Tulips.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Pictures\Sample Pictures\Desert.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SLV\StandardBusiness.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\TUR\Faces.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\UKR\SignHere.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\aglW_t4lWSRUs3lvnOF.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\RUS\Standard.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Pictures\Sample Pictures\Jellyfish.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SLV\Dynamic.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\as80.xsl | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\TUR\Standard.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Resources\1033\msmdsrv.rll | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.Targets | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\Informix.xsl | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Pictures\Sample Pictures\Hydrangeas.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\Words.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files\Microsoft Analysis Services\AS OLEDB\10\Cartridges\as90.xsl | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\Stationery\Peacock.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\fFQRpDCXsB\rBpWkW9.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Default\AppData\Local\Microsoft\Windows Mail\Stationery\ShadesOfBlue.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\Public\Pictures\Sample Pictures\Lighthouse.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.CZE | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.ITA | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.Targets | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files\Microsoft Sync Framework\v1.0\Runtime\x64\resources\1033\Synchronization.rll | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroBroker.exe | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.CHS | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.HRV | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.UKR | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.EUQ | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.NOR | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\CHS\eula.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.DAN | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.JPN | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.SKY | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.CHT | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.RUS | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\DEU\eula.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\JPN\eula.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\POL\eula.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\SKY\eula.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.HRV | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\TUR\eula.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.PTB | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.UKR | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\CHT\eula.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.HUN | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\ENU\eula.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\HRV\eula.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\KOR\eula.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\PTB\eula.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\AdobeCollabSync.CZE | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\SLV\eula.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\UKR\eula.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.DEU | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.KOR | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\DigSig.CAT | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\SaveAsRTF.CZE | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.SLV | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\da_DK\accessibility.DAN | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\places.sqlite | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AGMGPUOptIn.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.EUQ | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.NOR | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.CZE | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.ITA | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.RUS | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Installer\chrome.7z | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\RdLang32.CAT | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\CAT\eula.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\HUN\eula.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Javascripts\JSByteCodeWin.bin | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\DAN\eula.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\de_DE\PPKLITE.DEU | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\ITA\eula.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\de_DE\Services\Services.asfx | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\NOR\eula.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\es_ES\BRdlang32.ESP | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\es_ES\Multimedia.ESP | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\es_ES\SendMail.ESP | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\Spelling.CAT | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\Checkers.CZE | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\pddom.CZE | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\Services\DEXShare.asfx | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Legal\SUO\eula.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\eBook.CAT | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\DigSig.CZE | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\PPKLite.CZE | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\AdobeCollabSync.CAT | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\IA32.CAT | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\SaveAsRTF.CAT | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\eu_ES\AdobeCollabSync.EUQ | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\accessibility.CZE | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\eBook.CZE | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\ReadOutLoud.CZE | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\Services\Services.asfx | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\eu_ES\IA32.EUQ | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\eu_ES\SaveAsRTF.EUQ | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\fi_FI\accessibility.SUO | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\fi_FI\eBook.SUO | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\fi_FI\ReadOutLoud.SUO | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\da_DK\AdobeCollabSync.DAN | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\fi_FI\updater.SUO | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\da_DK\BRdlang32.DAN | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\da_DK\Annots.DAN | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\[BobGreen85@criptext.com].fOHbbyoB-l2wODLnd.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\vLykOV4Y_3l2VkIHp\l9h2RZXXX5kbGC\[BobGreen85@criptext.com].H1muc0Wv-9jC1uNzb.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\vLykOV4Y_3l2VkIHp\21Ar6w3\G5X-hwwH1l2TL.ods | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\CSharp\1033\ResourceInternal.zip | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\KOR\[BobGreen85@criptext.com].gQUDhEEw-VonWW9Om.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\UKR\[BobGreen85@criptext.com].WzlYXlDc-GWvAojKX.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\HUN\StandardBusiness.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\POL\Faces.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\HUN\[BobGreen85@criptext.com].SUvZn6vj-1QWFbiSW.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\KOR\Hanko.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\MDIParent.zip | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\JPN\[BobGreen85@criptext.com].kUEY5z8b-uwpzMT4C.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\NOR\[BobGreen85@criptext.com].otMLrywY-rj6y08vC.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\RUS\[BobGreen85@criptext.com].sTUKtDAQ-P7Cuji8x.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\DAN\StandardBusiness.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SKY\[BobGreen85@criptext.com].uND7BLVk-9ZEG3avc.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SKY\Pointers.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\IDTemplates\RUS\[BobGreen85@criptext.com].4SGarTlK-94MzJXZt.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\PTB\[BobGreen85@criptext.com].kXydHeIE-KUfADL8F.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SKY\[BobGreen85@criptext.com].SFVRPuHv-LKMi0XV9.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SUO\Dynamic.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\RUM\[BobGreen85@criptext.com].TNtOlUT7-D3twKVTN.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CHS\StandardBusiness.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\CZE\[BobGreen85@criptext.com].J0MSbOS1-FVcvdDXv.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\UKR\Dynamic.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SVE\StandardBusiness.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SLV\Standard.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\FRA\[BobGreen85@criptext.com].Rb5lkYR4-cyzgMYzD.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\HRV\[BobGreen85@criptext.com].ixMpy93a-CIYxGhaq.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\TUR\[BobGreen85@criptext.com].shKNc4uF-MMr2C6yN.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\PTB\[BobGreen85@criptext.com].SfnhVYhK-vgnlDWaL.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\RUS\[BobGreen85@criptext.com].06uoY6Kb-099bDrSk.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\SKY\[BobGreen85@criptext.com].bZAaEd2B-HYL7DGV9.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\JPN\Hanko.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\plug_ins\Annotations\Stamps\NLD\SignHere.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\Stationery\SoftBlue.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\Stationery\[BobGreen85@criptext.com].AH6TSLxm-0MOq4hKS.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\[BobGreen85@criptext.com].Vd05Czg3-mOcqGbSB.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\da_DK\eBook.DAN | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.ESP | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.SVE | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\Services\[BobGreen85@criptext.com].9KTSTj4F-ICMv2RhS.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.DEU | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\[BobGreen85@criptext.com].QpaNmmu1-heJlbwJz.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\[BobGreen85@criptext.com].6DurqfQa-u2p67k1c.BG85 | Dropped File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\fMXj4weL.bat | Dropped File | Batch |
Not Queried
|
...
|