VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Wiper, Trojan |
Windows Exe (x86-32)
Created at 2019-05-15T09:32:00
(0x200001e): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (20) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\pnogzd.exe | Sample File | Binary |
File Reputation Information
Severity |
First Seen | 2019-05-15 11:17 (UTC+2) |
Last Seen | 2019-05-15 11:28 (UTC+2) |
Names | Win32.Trojan.Kryptik |
Families | Kryptik |
Classification | Trojan |
PE Information
Image Base | 0x400000 |
Entry Point | 0x404d5d |
Size Of Code | 0x29800 |
Size Of Initialized Data | 0xa2000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-11-14 18:00:53+00:00 |
Version Information (4)
FileVersion | |
InternalName | pyutoi6u.uxe |
LegalCopyright | Copyright (C) 2019, rfgdgf |
ProductVersion | |
Sections (5)
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
.text | 0x401000 | 0x29775 | 0x29800 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.93 |
.rdata | 0x42b000 | 0x45f8 | 0x4600 | 0x29c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.19 |
.data | 0x430000 | 0x94a60 | 0x3600 | 0x2e200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.42 |
.rsrc | 0x4c5000 | 0x7750 | 0x7800 | 0x31800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.15 |
.reloc | 0x4cd000 | 0x2252 | 0x2400 | 0x39000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 4.14 |
Imports (2)
KERNEL32.dll (81)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
GetCPInfo | 0x0 | 0x42b000 | 0x2ee64 | 0x2da64 | 0x15b |
WriteConsoleOutputW | 0x0 | 0x42b004 | 0x2ee68 | 0x2da68 | 0x48b |
GetModuleHandleW | 0x0 | 0x42b008 | 0x2ee6c | 0x2da6c | 0x1f9 |
GetPrivateProfileStringW | 0x0 | 0x42b00c | 0x2ee70 | 0x2da70 | 0x21d |
GlobalAlloc | 0x0 | 0x42b010 | 0x2ee74 | 0x2da74 | 0x285 |
GetStringTypeExW | 0x0 | 0x42b014 | 0x2ee78 | 0x2da78 | 0x23f |
GetComputerNameExA | 0x0 | 0x42b018 | 0x2ee7c | 0x2da7c | 0x176 |
GetProcAddress | 0x0 | 0x42b01c | 0x2ee80 | 0x2da80 | 0x220 |
RemoveDirectoryA | 0x0 | 0x42b020 | 0x2ee84 | 0x2da84 | 0x37d |
GetModuleHandleA | 0x0 | 0x42b024 | 0x2ee88 | 0x2da88 | 0x1f6 |
CreateThread | 0x0 | 0x42b028 | 0x2ee8c | 0x2da8c | 0xa3 |
CreateFileA | 0x0 | 0x42b02c | 0x2ee90 | 0x2da90 | 0x78 |
SetFilePointer | 0x0 | 0x42b030 | 0x2ee94 | 0x2da94 | 0x3df |
WriteConsoleW | 0x0 | 0x42b034 | 0x2ee98 | 0x2da98 | 0x48c |
InterlockedIncrement | 0x0 | 0x42b038 | 0x2ee9c | 0x2da9c | 0x2c0 |
InterlockedDecrement | 0x0 | 0x42b03c | 0x2eea0 | 0x2daa0 | 0x2bc |
Sleep | 0x0 | 0x42b040 | 0x2eea4 | 0x2daa4 | 0x421 |
InitializeCriticalSection | 0x0 | 0x42b044 | 0x2eea8 | 0x2daa8 | 0x2b4 |
DeleteCriticalSection | 0x0 | 0x42b048 | 0x2eeac | 0x2daac | 0xbe |
EnterCriticalSection | 0x0 | 0x42b04c | 0x2eeb0 | 0x2dab0 | 0xd9 |
LeaveCriticalSection | 0x0 | 0x42b050 | 0x2eeb4 | 0x2dab4 | 0x2ef |
GetLastError | 0x0 | 0x42b054 | 0x2eeb8 | 0x2dab8 | 0x1e6 |
HeapFree | 0x0 | 0x42b058 | 0x2eebc | 0x2dabc | 0x2a1 |
TerminateProcess | 0x0 | 0x42b05c | 0x2eec0 | 0x2dac0 | 0x42d |
GetCurrentProcess | 0x0 | 0x42b060 | 0x2eec4 | 0x2dac4 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x42b064 | 0x2eec8 | 0x2dac8 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x42b068 | 0x2eecc | 0x2dacc | 0x415 |
IsDebuggerPresent | 0x0 | 0x42b06c | 0x2eed0 | 0x2dad0 | 0x2d1 |
HeapReAlloc | 0x0 | 0x42b070 | 0x2eed4 | 0x2dad4 | 0x2a4 |
HeapAlloc | 0x0 | 0x42b074 | 0x2eed8 | 0x2dad8 | 0x29d |
GetStartupInfoW | 0x0 | 0x42b078 | 0x2eedc | 0x2dadc | 0x23a |
RtlUnwind | 0x0 | 0x42b07c | 0x2eee0 | 0x2dae0 | 0x392 |
RaiseException | 0x0 | 0x42b080 | 0x2eee4 | 0x2dae4 | 0x35a |
LCMapStringA | 0x0 | 0x42b084 | 0x2eee8 | 0x2dae8 | 0x2e1 |
WideCharToMultiByte | 0x0 | 0x42b088 | 0x2eeec | 0x2daec | 0x47a |
MultiByteToWideChar | 0x0 | 0x42b08c | 0x2eef0 | 0x2daf0 | 0x31a |
LCMapStringW | 0x0 | 0x42b090 | 0x2eef4 | 0x2daf4 | 0x2e3 |
HeapCreate | 0x0 | 0x42b094 | 0x2eef8 | 0x2daf8 | 0x29f |
VirtualFree | 0x0 | 0x42b098 | 0x2eefc | 0x2dafc | 0x457 |
VirtualAlloc | 0x0 | 0x42b09c | 0x2ef00 | 0x2db00 | 0x454 |
TlsGetValue | 0x0 | 0x42b0a0 | 0x2ef04 | 0x2db04 | 0x434 |
TlsAlloc | 0x0 | 0x42b0a4 | 0x2ef08 | 0x2db08 | 0x432 |
TlsSetValue | 0x0 | 0x42b0a8 | 0x2ef0c | 0x2db0c | 0x435 |
TlsFree | 0x0 | 0x42b0ac | 0x2ef10 | 0x2db10 | 0x433 |
SetLastError | 0x0 | 0x42b0b0 | 0x2ef14 | 0x2db14 | 0x3ec |
GetCurrentThreadId | 0x0 | 0x42b0b4 | 0x2ef18 | 0x2db18 | 0x1ad |
HeapSize | 0x0 | 0x42b0b8 | 0x2ef1c | 0x2db1c | 0x2a6 |
ExitProcess | 0x0 | 0x42b0bc | 0x2ef20 | 0x2db20 | 0x104 |
CloseHandle | 0x0 | 0x42b0c0 | 0x2ef24 | 0x2db24 | 0x43 |
WriteFile | 0x0 | 0x42b0c4 | 0x2ef28 | 0x2db28 | 0x48d |
GetStdHandle | 0x0 | 0x42b0c8 | 0x2ef2c | 0x2db2c | 0x23b |
GetModuleFileNameA | 0x0 | 0x42b0cc | 0x2ef30 | 0x2db30 | 0x1f4 |
GetModuleFileNameW | 0x0 | 0x42b0d0 | 0x2ef34 | 0x2db34 | 0x1f5 |
FreeEnvironmentStringsW | 0x0 | 0x42b0d4 | 0x2ef38 | 0x2db38 | 0x14b |
GetEnvironmentStringsW | 0x0 | 0x42b0d8 | 0x2ef3c | 0x2db3c | 0x1c1 |
GetCommandLineW | 0x0 | 0x42b0dc | 0x2ef40 | 0x2db40 | 0x170 |
SetHandleCount | 0x0 | 0x42b0e0 | 0x2ef44 | 0x2db44 | 0x3e8 |
GetFileType | 0x0 | 0x42b0e4 | 0x2ef48 | 0x2db48 | 0x1d7 |
GetStartupInfoA | 0x0 | 0x42b0e8 | 0x2ef4c | 0x2db4c | 0x239 |
QueryPerformanceCounter | 0x0 | 0x42b0ec | 0x2ef50 | 0x2db50 | 0x354 |
GetTickCount | 0x0 | 0x42b0f0 | 0x2ef54 | 0x2db54 | 0x266 |
GetCurrentProcessId | 0x0 | 0x42b0f4 | 0x2ef58 | 0x2db58 | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x42b0f8 | 0x2ef5c | 0x2db5c | 0x24f |
GetACP | 0x0 | 0x42b0fc | 0x2ef60 | 0x2db60 | 0x152 |
GetOEMCP | 0x0 | 0x42b100 | 0x2ef64 | 0x2db64 | 0x213 |
IsValidCodePage | 0x0 | 0x42b104 | 0x2ef68 | 0x2db68 | 0x2db |
GetUserDefaultLCID | 0x0 | 0x42b108 | 0x2ef6c | 0x2db6c | 0x26d |
GetLocaleInfoA | 0x0 | 0x42b10c | 0x2ef70 | 0x2db70 | 0x1e8 |
EnumSystemLocalesA | 0x0 | 0x42b110 | 0x2ef74 | 0x2db74 | 0xf8 |
IsValidLocale | 0x0 | 0x42b114 | 0x2ef78 | 0x2db78 | 0x2dd |
GetStringTypeA | 0x0 | 0x42b118 | 0x2ef7c | 0x2db7c | 0x23d |
GetStringTypeW | 0x0 | 0x42b11c | 0x2ef80 | 0x2db80 | 0x240 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x42b120 | 0x2ef84 | 0x2db84 | 0x2b5 |
LoadLibraryA | 0x0 | 0x42b124 | 0x2ef88 | 0x2db88 | 0x2f1 |
SetStdHandle | 0x0 | 0x42b128 | 0x2ef8c | 0x2db8c | 0x3fc |
GetConsoleCP | 0x0 | 0x42b12c | 0x2ef90 | 0x2db90 | 0x183 |
GetConsoleMode | 0x0 | 0x42b130 | 0x2ef94 | 0x2db94 | 0x195 |
FlushFileBuffers | 0x0 | 0x42b134 | 0x2ef98 | 0x2db98 | 0x141 |
GetLocaleInfoW | 0x0 | 0x42b138 | 0x2ef9c | 0x2db9c | 0x1ea |
WriteConsoleA | 0x0 | 0x42b13c | 0x2efa0 | 0x2dba0 | 0x482 |
GetConsoleOutputCP | 0x0 | 0x42b140 | 0x2efa4 | 0x2dba4 | 0x199 |
USER32.dll (4)
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
ScrollWindow | 0x0 | 0x42b148 | 0x2efac | 0x2dbac | 0x257 |
GetMenuInfo | 0x0 | 0x42b14c | 0x2efb0 | 0x2dbb0 | 0x141 |
LoadImageA | 0x0 | 0x42b150 | 0x2efb4 | 0x2dbb4 | 0x1d8 |
UnregisterClassA | 0x0 | 0x42b154 | 0x2efb8 | 0x2dbb8 | 0x2de |
Memory Dumps (3)
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
pnogzd.exe | 1 | 0x00400000 | 0x004CFFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
buffer | 1 | 0x006B9DC8 | 0x006D1AA3 | Marked Executable | - | 32-bit | - |
![]() |
![]() |
buffer | 1 | 0x006B9DC8 | 0x006D1AA3 | Content Changed | - | 32-bit | 0x006BA6F3, 0x006B9DC8 |
![]() |
![]() |
Local AV Matches (1)
Threat Name | Severity |
Gen:Heur.Titirez.1.F |
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Binary |
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjProrWW.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Binary |
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Office32WW.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.EPS.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Binary |
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft analysis services\as oledb\10\cartridges\msjet.xsl.id-9c354b42.[decripted@cock.li].ddos | Dropped File | Stream |
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft analysis services\as oledb\10\cartridges\informix.xsl.id-9c354b42.[decripted@cock.li].ddos | Dropped File | Stream |
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUISet.XML.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioLR.cab.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PRJPROR\SETUP.XML.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
C:\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000\desktop.ini.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Boot\BOOTSTAT.DAT.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\BOOTSECT.BAK.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\branding.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\pss10r.chm.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\setup.chm.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\branding.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPlusrWW.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.GIF.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.JPG.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.PNG.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\desktop.ini.id-9c354b42.[decripted@cock.li].ddos | Dropped File | Stream |
Not Queried
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft analysis services\as oledb\10\cartridges\as90.xsl.id-9c354b42.[decripted@cock.li].ddos | Dropped File | Stream |
Not Queried
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft analysis services\as oledb\10\resources\1033\msolui100.rll.id-9c354b42.[decripted@cock.li].ddos | Dropped File | Stream |
Not Queried
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft analysis services\as oledb\10\cartridges\sql2000.xsl.id-9c354b42.[decripted@cock.li].ddos | Dropped File | Stream |
Not Queried
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft analysis services\as oledb\10\cartridges\as80.xsl.id-9c354b42.[decripted@cock.li].ddos | Dropped File | Stream |
Not Queried
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft analysis services\as oledb\10\resources\1033\msmdsrv.rll.id-9c354b42.[decripted@cock.li].ddos | Dropped File | Stream |
Not Queried
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft analysis services\as oledb\10\cartridges\sql70.xsl.id-9c354b42.[decripted@cock.li].ddos | Dropped File | Stream |
Not Queried
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft analysis services\as oledb\10\cartridges\sql90.xsl.id-9c354b42.[decripted@cock.li].ddos | Dropped File | Stream |
Not Queried
c:\users\5p5nrgjn0js halpmcxz\appdata\local\virtualstore\program files\microsoft analysis services\as oledb\10\cartridges\sybase.xsl.id-9c354b42.[decripted@cock.li].ddos | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\README.HTM.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\AccessMUI.XML.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\ExcelMUI.XML.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\AccessMUISet.XML.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\SETUP.XML.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Groove.en-us\GrooveMUI.XML.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Groove.en-us\SETUP.XML.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\SETUP.XML.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\InfoPathMUI.XML.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\BRANDING.XML.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\SETUP.XML.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OCT.CHM.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSCONFIG.CHM.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUI.XML.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\SETUP.CHM.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\SETUP.XML.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\Office32MUI.XML.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\OWOW32LR.cab.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\SETUP.XML.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSS10O.CHM.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSS10R.CHM.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.WW\Office32WW.XML.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfLR.cab.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\ADO210.CHM.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\OutlookMUI.XML.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\OneNoteMUI.XML.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.msi.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\SETUP.XML.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\SETUP.XML.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\SETUP.XML.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PRJPROR\PrjProrWW.XML.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\PowerPointMUI.XML.id-9C354B42.[decripted@cock.li].DDOS | Dropped File | Stream |
Not Queried