VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Dropper, Trojan |
454364vodafone-e-fatura.exe
Windows Exe (x86-32)
Created at 2019-09-24T17:55:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\454364vodafone-e-fatura.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-09-17 23:20 (UTC+2) |
Last Seen | 2019-09-24 00:59 (UTC+2) |
Names | Win32.Trojan.Encoder |
Families | Encoder |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x41d759 |
Size Of Code | 0x2ea00 |
Size Of Initialized Data | 0x4a200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-04-27 20:03:27+00:00 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x2e854 | 0x2ea00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.69 |
.rdata | 0x430000 | 0x9a9c | 0x9c00 | 0x2ee00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.13 |
.data | 0x43a000 | 0x213d0 | 0xc00 | 0x38a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.25 |
.gfids | 0x45c000 | 0xe8 | 0x200 | 0x39600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.11 |
.rsrc | 0x45d000 | 0x1cf43 | 0x1d000 | 0x39800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.83 |
.reloc | 0x47a000 | 0x1fcc | 0x2000 | 0x56800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.65 |
Imports (2)
»
KERNEL32.dll (140)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetLastError | 0x0 | 0x430000 | 0x38d30 | 0x37b30 | 0x202 |
SetLastError | 0x0 | 0x430004 | 0x38d34 | 0x37b34 | 0x473 |
GetCurrentProcess | 0x0 | 0x430008 | 0x38d38 | 0x37b38 | 0x1c0 |
DeviceIoControl | 0x0 | 0x43000c | 0x38d3c | 0x37b3c | 0xdd |
SetFileTime | 0x0 | 0x430010 | 0x38d40 | 0x37b40 | 0x46a |
CloseHandle | 0x0 | 0x430014 | 0x38d44 | 0x37b44 | 0x52 |
CreateDirectoryW | 0x0 | 0x430018 | 0x38d48 | 0x37b48 | 0x81 |
RemoveDirectoryW | 0x0 | 0x43001c | 0x38d4c | 0x37b4c | 0x403 |
CreateFileW | 0x0 | 0x430020 | 0x38d50 | 0x37b50 | 0x8f |
DeleteFileW | 0x0 | 0x430024 | 0x38d54 | 0x37b54 | 0xd6 |
CreateHardLinkW | 0x0 | 0x430028 | 0x38d58 | 0x37b58 | 0x93 |
GetShortPathNameW | 0x0 | 0x43002c | 0x38d5c | 0x37b5c | 0x261 |
GetLongPathNameW | 0x0 | 0x430030 | 0x38d60 | 0x37b60 | 0x20f |
MoveFileW | 0x0 | 0x430034 | 0x38d64 | 0x37b64 | 0x363 |
GetFileType | 0x0 | 0x430038 | 0x38d68 | 0x37b68 | 0x1f3 |
GetStdHandle | 0x0 | 0x43003c | 0x38d6c | 0x37b6c | 0x264 |
WriteFile | 0x0 | 0x430040 | 0x38d70 | 0x37b70 | 0x525 |
ReadFile | 0x0 | 0x430044 | 0x38d74 | 0x37b74 | 0x3c0 |
FlushFileBuffers | 0x0 | 0x430048 | 0x38d78 | 0x37b78 | 0x157 |
SetEndOfFile | 0x0 | 0x43004c | 0x38d7c | 0x37b7c | 0x453 |
SetFilePointer | 0x0 | 0x430050 | 0x38d80 | 0x37b80 | 0x466 |
SetFileAttributesW | 0x0 | 0x430054 | 0x38d84 | 0x37b84 | 0x461 |
GetFileAttributesW | 0x0 | 0x430058 | 0x38d88 | 0x37b88 | 0x1ea |
FindClose | 0x0 | 0x43005c | 0x38d8c | 0x37b8c | 0x12e |
FindFirstFileW | 0x0 | 0x430060 | 0x38d90 | 0x37b90 | 0x139 |
FindNextFileW | 0x0 | 0x430064 | 0x38d94 | 0x37b94 | 0x145 |
GetVersionExW | 0x0 | 0x430068 | 0x38d98 | 0x37b98 | 0x2a4 |
GetCurrentDirectoryW | 0x0 | 0x43006c | 0x38d9c | 0x37b9c | 0x1bf |
GetFullPathNameW | 0x0 | 0x430070 | 0x38da0 | 0x37ba0 | 0x1fb |
FoldStringW | 0x0 | 0x430074 | 0x38da4 | 0x37ba4 | 0x15c |
GetModuleFileNameW | 0x0 | 0x430078 | 0x38da8 | 0x37ba8 | 0x214 |
GetModuleHandleW | 0x0 | 0x43007c | 0x38dac | 0x37bac | 0x218 |
FindResourceW | 0x0 | 0x430080 | 0x38db0 | 0x37bb0 | 0x14e |
FreeLibrary | 0x0 | 0x430084 | 0x38db4 | 0x37bb4 | 0x162 |
GetProcAddress | 0x0 | 0x430088 | 0x38db8 | 0x37bb8 | 0x245 |
GetCurrentProcessId | 0x0 | 0x43008c | 0x38dbc | 0x37bbc | 0x1c1 |
ExitProcess | 0x0 | 0x430090 | 0x38dc0 | 0x37bc0 | 0x119 |
SetThreadExecutionState | 0x0 | 0x430094 | 0x38dc4 | 0x37bc4 | 0x493 |
Sleep | 0x0 | 0x430098 | 0x38dc8 | 0x37bc8 | 0x4b2 |
LoadLibraryW | 0x0 | 0x43009c | 0x38dcc | 0x37bcc | 0x33f |
GetSystemDirectoryW | 0x0 | 0x4300a0 | 0x38dd0 | 0x37bd0 | 0x270 |
CompareStringW | 0x0 | 0x4300a4 | 0x38dd4 | 0x37bd4 | 0x64 |
AllocConsole | 0x0 | 0x4300a8 | 0x38dd8 | 0x37bd8 | 0x10 |
FreeConsole | 0x0 | 0x4300ac | 0x38ddc | 0x37bdc | 0x15f |
AttachConsole | 0x0 | 0x4300b0 | 0x38de0 | 0x37be0 | 0x17 |
WriteConsoleW | 0x0 | 0x4300b4 | 0x38de4 | 0x37be4 | 0x524 |
GetProcessAffinityMask | 0x0 | 0x4300b8 | 0x38de8 | 0x37be8 | 0x246 |
CreateThread | 0x0 | 0x4300bc | 0x38dec | 0x37bec | 0xb5 |
SetThreadPriority | 0x0 | 0x4300c0 | 0x38df0 | 0x37bf0 | 0x499 |
InitializeCriticalSection | 0x0 | 0x4300c4 | 0x38df4 | 0x37bf4 | 0x2e2 |
EnterCriticalSection | 0x0 | 0x4300c8 | 0x38df8 | 0x37bf8 | 0xee |
LeaveCriticalSection | 0x0 | 0x4300cc | 0x38dfc | 0x37bfc | 0x339 |
DeleteCriticalSection | 0x0 | 0x4300d0 | 0x38e00 | 0x37c00 | 0xd1 |
SetEvent | 0x0 | 0x4300d4 | 0x38e04 | 0x37c04 | 0x459 |
ResetEvent | 0x0 | 0x4300d8 | 0x38e08 | 0x37c08 | 0x40f |
ReleaseSemaphore | 0x0 | 0x4300dc | 0x38e0c | 0x37c0c | 0x3fe |
WaitForSingleObject | 0x0 | 0x4300e0 | 0x38e10 | 0x37c10 | 0x4f9 |
CreateEventW | 0x0 | 0x4300e4 | 0x38e14 | 0x37c14 | 0x85 |
CreateSemaphoreW | 0x0 | 0x4300e8 | 0x38e18 | 0x37c18 | 0xae |
GetSystemTime | 0x0 | 0x4300ec | 0x38e1c | 0x37c1c | 0x277 |
SystemTimeToTzSpecificLocalTime | 0x0 | 0x4300f0 | 0x38e20 | 0x37c20 | 0x4be |
TzSpecificLocalTimeToSystemTime | 0x0 | 0x4300f4 | 0x38e24 | 0x37c24 | 0x4d0 |
SystemTimeToFileTime | 0x0 | 0x4300f8 | 0x38e28 | 0x37c28 | 0x4bd |
FileTimeToLocalFileTime | 0x0 | 0x4300fc | 0x38e2c | 0x37c2c | 0x124 |
LocalFileTimeToFileTime | 0x0 | 0x430100 | 0x38e30 | 0x37c30 | 0x346 |
FileTimeToSystemTime | 0x0 | 0x430104 | 0x38e34 | 0x37c34 | 0x125 |
GetCPInfo | 0x0 | 0x430108 | 0x38e38 | 0x37c38 | 0x172 |
IsDBCSLeadByte | 0x0 | 0x43010c | 0x38e3c | 0x37c3c | 0x2fe |
MultiByteToWideChar | 0x0 | 0x430110 | 0x38e40 | 0x37c40 | 0x367 |
WideCharToMultiByte | 0x0 | 0x430114 | 0x38e44 | 0x37c44 | 0x511 |
GlobalAlloc | 0x0 | 0x430118 | 0x38e48 | 0x37c48 | 0x2b3 |
GetTickCount | 0x0 | 0x43011c | 0x38e4c | 0x37c4c | 0x293 |
LockResource | 0x0 | 0x430120 | 0x38e50 | 0x37c50 | 0x354 |
GlobalLock | 0x0 | 0x430124 | 0x38e54 | 0x37c54 | 0x2be |
GlobalUnlock | 0x0 | 0x430128 | 0x38e58 | 0x37c58 | 0x2c5 |
GlobalFree | 0x0 | 0x43012c | 0x38e5c | 0x37c5c | 0x2ba |
LoadResource | 0x0 | 0x430130 | 0x38e60 | 0x37c60 | 0x341 |
SizeofResource | 0x0 | 0x430134 | 0x38e64 | 0x37c64 | 0x4b1 |
SetCurrentDirectoryW | 0x0 | 0x430138 | 0x38e68 | 0x37c68 | 0x44d |
GetExitCodeProcess | 0x0 | 0x43013c | 0x38e6c | 0x37c6c | 0x1df |
GetLocalTime | 0x0 | 0x430140 | 0x38e70 | 0x37c70 | 0x203 |
MapViewOfFile | 0x0 | 0x430144 | 0x38e74 | 0x37c74 | 0x357 |
UnmapViewOfFile | 0x0 | 0x430148 | 0x38e78 | 0x37c78 | 0x4d6 |
CreateFileMappingW | 0x0 | 0x43014c | 0x38e7c | 0x37c7c | 0x8c |
OpenFileMappingW | 0x0 | 0x430150 | 0x38e80 | 0x37c80 | 0x379 |
GetCommandLineW | 0x0 | 0x430154 | 0x38e84 | 0x37c84 | 0x187 |
SetEnvironmentVariableW | 0x0 | 0x430158 | 0x38e88 | 0x37c88 | 0x457 |
ExpandEnvironmentStringsW | 0x0 | 0x43015c | 0x38e8c | 0x37c8c | 0x11d |
GetTempPathW | 0x0 | 0x430160 | 0x38e90 | 0x37c90 | 0x285 |
MoveFileExW | 0x0 | 0x430164 | 0x38e94 | 0x37c94 | 0x360 |
GetLocaleInfoW | 0x0 | 0x430168 | 0x38e98 | 0x37c98 | 0x206 |
GetTimeFormatW | 0x0 | 0x43016c | 0x38e9c | 0x37c9c | 0x297 |
GetDateFormatW | 0x0 | 0x430170 | 0x38ea0 | 0x37ca0 | 0x1c8 |
GetNumberFormatW | 0x0 | 0x430174 | 0x38ea4 | 0x37ca4 | 0x233 |
SetFilePointerEx | 0x0 | 0x430178 | 0x38ea8 | 0x37ca8 | 0x467 |
GetConsoleMode | 0x0 | 0x43017c | 0x38eac | 0x37cac | 0x1ac |
GetConsoleCP | 0x0 | 0x430180 | 0x38eb0 | 0x37cb0 | 0x19a |
HeapSize | 0x0 | 0x430184 | 0x38eb4 | 0x37cb4 | 0x2d4 |
SetStdHandle | 0x0 | 0x430188 | 0x38eb8 | 0x37cb8 | 0x487 |
GetProcessHeap | 0x0 | 0x43018c | 0x38ebc | 0x37cbc | 0x24a |
RaiseException | 0x0 | 0x430190 | 0x38ec0 | 0x37cc0 | 0x3b1 |
GetSystemInfo | 0x0 | 0x430194 | 0x38ec4 | 0x37cc4 | 0x273 |
VirtualProtect | 0x0 | 0x430198 | 0x38ec8 | 0x37cc8 | 0x4ef |
VirtualQuery | 0x0 | 0x43019c | 0x38ecc | 0x37ccc | 0x4f1 |
LoadLibraryExA | 0x0 | 0x4301a0 | 0x38ed0 | 0x37cd0 | 0x33d |
IsProcessorFeaturePresent | 0x0 | 0x4301a4 | 0x38ed4 | 0x37cd4 | 0x304 |
IsDebuggerPresent | 0x0 | 0x4301a8 | 0x38ed8 | 0x37cd8 | 0x300 |
UnhandledExceptionFilter | 0x0 | 0x4301ac | 0x38edc | 0x37cdc | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x4301b0 | 0x38ee0 | 0x37ce0 | 0x4a5 |
GetStartupInfoW | 0x0 | 0x4301b4 | 0x38ee4 | 0x37ce4 | 0x263 |
QueryPerformanceCounter | 0x0 | 0x4301b8 | 0x38ee8 | 0x37ce8 | 0x3a7 |
GetCurrentThreadId | 0x0 | 0x4301bc | 0x38eec | 0x37cec | 0x1c5 |
GetSystemTimeAsFileTime | 0x0 | 0x4301c0 | 0x38ef0 | 0x37cf0 | 0x279 |
InitializeSListHead | 0x0 | 0x4301c4 | 0x38ef4 | 0x37cf4 | 0x2e7 |
TerminateProcess | 0x0 | 0x4301c8 | 0x38ef8 | 0x37cf8 | 0x4c0 |
RtlUnwind | 0x0 | 0x4301cc | 0x38efc | 0x37cfc | 0x418 |
EncodePointer | 0x0 | 0x4301d0 | 0x38f00 | 0x37d00 | 0xea |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4301d4 | 0x38f04 | 0x37d04 | 0x2e3 |
TlsAlloc | 0x0 | 0x4301d8 | 0x38f08 | 0x37d08 | 0x4c5 |
TlsGetValue | 0x0 | 0x4301dc | 0x38f0c | 0x37d0c | 0x4c7 |
TlsSetValue | 0x0 | 0x4301e0 | 0x38f10 | 0x37d10 | 0x4c8 |
TlsFree | 0x0 | 0x4301e4 | 0x38f14 | 0x37d14 | 0x4c6 |
LoadLibraryExW | 0x0 | 0x4301e8 | 0x38f18 | 0x37d18 | 0x33e |
QueryPerformanceFrequency | 0x0 | 0x4301ec | 0x38f1c | 0x37d1c | 0x3a8 |
GetModuleHandleExW | 0x0 | 0x4301f0 | 0x38f20 | 0x37d20 | 0x217 |
GetModuleFileNameA | 0x0 | 0x4301f4 | 0x38f24 | 0x37d24 | 0x213 |
GetACP | 0x0 | 0x4301f8 | 0x38f28 | 0x37d28 | 0x168 |
HeapFree | 0x0 | 0x4301fc | 0x38f2c | 0x37d2c | 0x2cf |
HeapAlloc | 0x0 | 0x430200 | 0x38f30 | 0x37d30 | 0x2cb |
HeapReAlloc | 0x0 | 0x430204 | 0x38f34 | 0x37d34 | 0x2d2 |
GetStringTypeW | 0x0 | 0x430208 | 0x38f38 | 0x37d38 | 0x269 |
LCMapStringW | 0x0 | 0x43020c | 0x38f3c | 0x37d3c | 0x32d |
FindFirstFileExA | 0x0 | 0x430210 | 0x38f40 | 0x37d40 | 0x133 |
FindNextFileA | 0x0 | 0x430214 | 0x38f44 | 0x37d44 | 0x143 |
IsValidCodePage | 0x0 | 0x430218 | 0x38f48 | 0x37d48 | 0x30a |
GetOEMCP | 0x0 | 0x43021c | 0x38f4c | 0x37d4c | 0x237 |
GetCommandLineA | 0x0 | 0x430220 | 0x38f50 | 0x37d50 | 0x186 |
GetEnvironmentStringsW | 0x0 | 0x430224 | 0x38f54 | 0x37d54 | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x430228 | 0x38f58 | 0x37d58 | 0x161 |
DecodePointer | 0x0 | 0x43022c | 0x38f5c | 0x37d5c | 0xca |
gdiplus.dll (9)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GdiplusShutdown | 0x0 | 0x430234 | 0x38f64 | 0x37d64 | 0x274 |
GdiplusStartup | 0x0 | 0x430238 | 0x38f68 | 0x37d68 | 0x275 |
GdipCreateHBITMAPFromBitmap | 0x0 | 0x43023c | 0x38f6c | 0x37d6c | 0x5f |
GdipCreateBitmapFromStreamICM | 0x0 | 0x430240 | 0x38f70 | 0x37d70 | 0x52 |
GdipCreateBitmapFromStream | 0x0 | 0x430244 | 0x38f74 | 0x37d74 | 0x51 |
GdipDisposeImage | 0x0 | 0x430248 | 0x38f78 | 0x37d78 | 0x98 |
GdipCloneImage | 0x0 | 0x43024c | 0x38f7c | 0x37d7c | 0x36 |
GdipFree | 0x0 | 0x430250 | 0x38f80 | 0x37d80 | 0xed |
GdipAlloc | 0x0 | 0x430254 | 0x38f84 | 0x37d84 | 0x21 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
454364vodafone-e-fatura.exe | 1 | 0x00FB0000 | 0x0102BFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
454364vodafone-e-fatura.exe | 1 | 0x00FB0000 | 0x0102BFFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Starter.4.56911EB2 |
Malicious
|
File Reputation Information
»
Severity |
Suspicious
|
First Seen | 2019-09-18 22:52 (UTC+2) |
Last Seen | 2019-09-20 04:27 (UTC+2) |
Names | Win32.Malware.Starter |
Classification | - |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Starter.4.56911EB2 |
Malicious
|
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-09-18 13:21 (UTC+2) |
Last Seen | 2019-09-21 23:15 (UTC+2) |
Names | ByteCode-MSIL.Trojan.Clipbanker |
Families | Clipbanker |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x499e4e |
Size Of Code | 0x98000 |
Size Of Initialized Data | 0x19000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-09-17 17:58:08+00:00 |
Version Information (10)
»
Assembly Version | 1.0.0.0 |
Comments | ConfuserEx |
CompanyName | Ki |
FileDescription | ConfuserEx GUI |
FileVersion | 1.0.0 |
InternalName | Crypted.exe |
LegalCopyright | |
OriginalFilename | Crypted.exe |
ProductName | ConfuserEx |
ProductVersion | 1.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x97e54 | 0x98000 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.98 |
.rsrc | 0x49a000 | 0x18c20 | 0x18e00 | 0x98200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.3 |
.reloc | 0x4b4000 | 0xc | 0x200 | 0xb1000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x99e1c | 0x9801c | 0x0 |
Memory Dumps (4)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
buffer | 8 | 0x00F41000 | 0x00F41FFF | First Execution | - | 32-bit | 0x00F41008 |
![]() |
![]() |
...
|
buffer | 8 | 0x00F42000 | 0x00F42FFF | First Execution | - | 32-bit | 0x00F42010 |
![]() |
![]() |
...
|
buffer | 8 | 0x00F42000 | 0x00F42FFF | Content Changed | - | 32-bit | 0x00F42440 |
![]() |
![]() |
...
|
buffer | 8 | 0x00F41000 | 0x00F41FFF | Content Changed | - | 32-bit | 0x00F410BE |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.MSIL.Krypt.6 |
Malicious
|
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-09-18 12:42 (UTC+2) |
Last Seen | 2019-09-20 05:45 (UTC+2) |
Names | Win32.Trojan.Com |
Families | Com |
Classification | Trojan |
Local AV Information
»
Errors | - |
Failed AV scans | The sample is encrypted |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x41d759 |
Size Of Code | 0x2ea00 |
Size Of Initialized Data | 0x3b200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-04-27 20:03:27+00:00 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x2e854 | 0x2ea00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.69 |
.rdata | 0x430000 | 0x9a9c | 0x9c00 | 0x2ee00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.13 |
.data | 0x43a000 | 0x213d0 | 0xc00 | 0x38a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.25 |
.gfids | 0x45c000 | 0xe8 | 0x200 | 0x39600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.11 |
.rsrc | 0x45d000 | 0xdfd0 | 0xe000 | 0x39800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.64 |
.reloc | 0x46b000 | 0x1fcc | 0x2000 | 0x47800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.65 |
Imports (2)
»
KERNEL32.dll (140)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetLastError | 0x0 | 0x430000 | 0x38d30 | 0x37b30 | 0x202 |
SetLastError | 0x0 | 0x430004 | 0x38d34 | 0x37b34 | 0x473 |
GetCurrentProcess | 0x0 | 0x430008 | 0x38d38 | 0x37b38 | 0x1c0 |
DeviceIoControl | 0x0 | 0x43000c | 0x38d3c | 0x37b3c | 0xdd |
SetFileTime | 0x0 | 0x430010 | 0x38d40 | 0x37b40 | 0x46a |
CloseHandle | 0x0 | 0x430014 | 0x38d44 | 0x37b44 | 0x52 |
CreateDirectoryW | 0x0 | 0x430018 | 0x38d48 | 0x37b48 | 0x81 |
RemoveDirectoryW | 0x0 | 0x43001c | 0x38d4c | 0x37b4c | 0x403 |
CreateFileW | 0x0 | 0x430020 | 0x38d50 | 0x37b50 | 0x8f |
DeleteFileW | 0x0 | 0x430024 | 0x38d54 | 0x37b54 | 0xd6 |
CreateHardLinkW | 0x0 | 0x430028 | 0x38d58 | 0x37b58 | 0x93 |
GetShortPathNameW | 0x0 | 0x43002c | 0x38d5c | 0x37b5c | 0x261 |
GetLongPathNameW | 0x0 | 0x430030 | 0x38d60 | 0x37b60 | 0x20f |
MoveFileW | 0x0 | 0x430034 | 0x38d64 | 0x37b64 | 0x363 |
GetFileType | 0x0 | 0x430038 | 0x38d68 | 0x37b68 | 0x1f3 |
GetStdHandle | 0x0 | 0x43003c | 0x38d6c | 0x37b6c | 0x264 |
WriteFile | 0x0 | 0x430040 | 0x38d70 | 0x37b70 | 0x525 |
ReadFile | 0x0 | 0x430044 | 0x38d74 | 0x37b74 | 0x3c0 |
FlushFileBuffers | 0x0 | 0x430048 | 0x38d78 | 0x37b78 | 0x157 |
SetEndOfFile | 0x0 | 0x43004c | 0x38d7c | 0x37b7c | 0x453 |
SetFilePointer | 0x0 | 0x430050 | 0x38d80 | 0x37b80 | 0x466 |
SetFileAttributesW | 0x0 | 0x430054 | 0x38d84 | 0x37b84 | 0x461 |
GetFileAttributesW | 0x0 | 0x430058 | 0x38d88 | 0x37b88 | 0x1ea |
FindClose | 0x0 | 0x43005c | 0x38d8c | 0x37b8c | 0x12e |
FindFirstFileW | 0x0 | 0x430060 | 0x38d90 | 0x37b90 | 0x139 |
FindNextFileW | 0x0 | 0x430064 | 0x38d94 | 0x37b94 | 0x145 |
GetVersionExW | 0x0 | 0x430068 | 0x38d98 | 0x37b98 | 0x2a4 |
GetCurrentDirectoryW | 0x0 | 0x43006c | 0x38d9c | 0x37b9c | 0x1bf |
GetFullPathNameW | 0x0 | 0x430070 | 0x38da0 | 0x37ba0 | 0x1fb |
FoldStringW | 0x0 | 0x430074 | 0x38da4 | 0x37ba4 | 0x15c |
GetModuleFileNameW | 0x0 | 0x430078 | 0x38da8 | 0x37ba8 | 0x214 |
GetModuleHandleW | 0x0 | 0x43007c | 0x38dac | 0x37bac | 0x218 |
FindResourceW | 0x0 | 0x430080 | 0x38db0 | 0x37bb0 | 0x14e |
FreeLibrary | 0x0 | 0x430084 | 0x38db4 | 0x37bb4 | 0x162 |
GetProcAddress | 0x0 | 0x430088 | 0x38db8 | 0x37bb8 | 0x245 |
GetCurrentProcessId | 0x0 | 0x43008c | 0x38dbc | 0x37bbc | 0x1c1 |
ExitProcess | 0x0 | 0x430090 | 0x38dc0 | 0x37bc0 | 0x119 |
SetThreadExecutionState | 0x0 | 0x430094 | 0x38dc4 | 0x37bc4 | 0x493 |
Sleep | 0x0 | 0x430098 | 0x38dc8 | 0x37bc8 | 0x4b2 |
LoadLibraryW | 0x0 | 0x43009c | 0x38dcc | 0x37bcc | 0x33f |
GetSystemDirectoryW | 0x0 | 0x4300a0 | 0x38dd0 | 0x37bd0 | 0x270 |
CompareStringW | 0x0 | 0x4300a4 | 0x38dd4 | 0x37bd4 | 0x64 |
AllocConsole | 0x0 | 0x4300a8 | 0x38dd8 | 0x37bd8 | 0x10 |
FreeConsole | 0x0 | 0x4300ac | 0x38ddc | 0x37bdc | 0x15f |
AttachConsole | 0x0 | 0x4300b0 | 0x38de0 | 0x37be0 | 0x17 |
WriteConsoleW | 0x0 | 0x4300b4 | 0x38de4 | 0x37be4 | 0x524 |
GetProcessAffinityMask | 0x0 | 0x4300b8 | 0x38de8 | 0x37be8 | 0x246 |
CreateThread | 0x0 | 0x4300bc | 0x38dec | 0x37bec | 0xb5 |
SetThreadPriority | 0x0 | 0x4300c0 | 0x38df0 | 0x37bf0 | 0x499 |
InitializeCriticalSection | 0x0 | 0x4300c4 | 0x38df4 | 0x37bf4 | 0x2e2 |
EnterCriticalSection | 0x0 | 0x4300c8 | 0x38df8 | 0x37bf8 | 0xee |
LeaveCriticalSection | 0x0 | 0x4300cc | 0x38dfc | 0x37bfc | 0x339 |
DeleteCriticalSection | 0x0 | 0x4300d0 | 0x38e00 | 0x37c00 | 0xd1 |
SetEvent | 0x0 | 0x4300d4 | 0x38e04 | 0x37c04 | 0x459 |
ResetEvent | 0x0 | 0x4300d8 | 0x38e08 | 0x37c08 | 0x40f |
ReleaseSemaphore | 0x0 | 0x4300dc | 0x38e0c | 0x37c0c | 0x3fe |
WaitForSingleObject | 0x0 | 0x4300e0 | 0x38e10 | 0x37c10 | 0x4f9 |
CreateEventW | 0x0 | 0x4300e4 | 0x38e14 | 0x37c14 | 0x85 |
CreateSemaphoreW | 0x0 | 0x4300e8 | 0x38e18 | 0x37c18 | 0xae |
GetSystemTime | 0x0 | 0x4300ec | 0x38e1c | 0x37c1c | 0x277 |
SystemTimeToTzSpecificLocalTime | 0x0 | 0x4300f0 | 0x38e20 | 0x37c20 | 0x4be |
TzSpecificLocalTimeToSystemTime | 0x0 | 0x4300f4 | 0x38e24 | 0x37c24 | 0x4d0 |
SystemTimeToFileTime | 0x0 | 0x4300f8 | 0x38e28 | 0x37c28 | 0x4bd |
FileTimeToLocalFileTime | 0x0 | 0x4300fc | 0x38e2c | 0x37c2c | 0x124 |
LocalFileTimeToFileTime | 0x0 | 0x430100 | 0x38e30 | 0x37c30 | 0x346 |
FileTimeToSystemTime | 0x0 | 0x430104 | 0x38e34 | 0x37c34 | 0x125 |
GetCPInfo | 0x0 | 0x430108 | 0x38e38 | 0x37c38 | 0x172 |
IsDBCSLeadByte | 0x0 | 0x43010c | 0x38e3c | 0x37c3c | 0x2fe |
MultiByteToWideChar | 0x0 | 0x430110 | 0x38e40 | 0x37c40 | 0x367 |
WideCharToMultiByte | 0x0 | 0x430114 | 0x38e44 | 0x37c44 | 0x511 |
GlobalAlloc | 0x0 | 0x430118 | 0x38e48 | 0x37c48 | 0x2b3 |
GetTickCount | 0x0 | 0x43011c | 0x38e4c | 0x37c4c | 0x293 |
LockResource | 0x0 | 0x430120 | 0x38e50 | 0x37c50 | 0x354 |
GlobalLock | 0x0 | 0x430124 | 0x38e54 | 0x37c54 | 0x2be |
GlobalUnlock | 0x0 | 0x430128 | 0x38e58 | 0x37c58 | 0x2c5 |
GlobalFree | 0x0 | 0x43012c | 0x38e5c | 0x37c5c | 0x2ba |
LoadResource | 0x0 | 0x430130 | 0x38e60 | 0x37c60 | 0x341 |
SizeofResource | 0x0 | 0x430134 | 0x38e64 | 0x37c64 | 0x4b1 |
SetCurrentDirectoryW | 0x0 | 0x430138 | 0x38e68 | 0x37c68 | 0x44d |
GetExitCodeProcess | 0x0 | 0x43013c | 0x38e6c | 0x37c6c | 0x1df |
GetLocalTime | 0x0 | 0x430140 | 0x38e70 | 0x37c70 | 0x203 |
MapViewOfFile | 0x0 | 0x430144 | 0x38e74 | 0x37c74 | 0x357 |
UnmapViewOfFile | 0x0 | 0x430148 | 0x38e78 | 0x37c78 | 0x4d6 |
CreateFileMappingW | 0x0 | 0x43014c | 0x38e7c | 0x37c7c | 0x8c |
OpenFileMappingW | 0x0 | 0x430150 | 0x38e80 | 0x37c80 | 0x379 |
GetCommandLineW | 0x0 | 0x430154 | 0x38e84 | 0x37c84 | 0x187 |
SetEnvironmentVariableW | 0x0 | 0x430158 | 0x38e88 | 0x37c88 | 0x457 |
ExpandEnvironmentStringsW | 0x0 | 0x43015c | 0x38e8c | 0x37c8c | 0x11d |
GetTempPathW | 0x0 | 0x430160 | 0x38e90 | 0x37c90 | 0x285 |
MoveFileExW | 0x0 | 0x430164 | 0x38e94 | 0x37c94 | 0x360 |
GetLocaleInfoW | 0x0 | 0x430168 | 0x38e98 | 0x37c98 | 0x206 |
GetTimeFormatW | 0x0 | 0x43016c | 0x38e9c | 0x37c9c | 0x297 |
GetDateFormatW | 0x0 | 0x430170 | 0x38ea0 | 0x37ca0 | 0x1c8 |
GetNumberFormatW | 0x0 | 0x430174 | 0x38ea4 | 0x37ca4 | 0x233 |
SetFilePointerEx | 0x0 | 0x430178 | 0x38ea8 | 0x37ca8 | 0x467 |
GetConsoleMode | 0x0 | 0x43017c | 0x38eac | 0x37cac | 0x1ac |
GetConsoleCP | 0x0 | 0x430180 | 0x38eb0 | 0x37cb0 | 0x19a |
HeapSize | 0x0 | 0x430184 | 0x38eb4 | 0x37cb4 | 0x2d4 |
SetStdHandle | 0x0 | 0x430188 | 0x38eb8 | 0x37cb8 | 0x487 |
GetProcessHeap | 0x0 | 0x43018c | 0x38ebc | 0x37cbc | 0x24a |
RaiseException | 0x0 | 0x430190 | 0x38ec0 | 0x37cc0 | 0x3b1 |
GetSystemInfo | 0x0 | 0x430194 | 0x38ec4 | 0x37cc4 | 0x273 |
VirtualProtect | 0x0 | 0x430198 | 0x38ec8 | 0x37cc8 | 0x4ef |
VirtualQuery | 0x0 | 0x43019c | 0x38ecc | 0x37ccc | 0x4f1 |
LoadLibraryExA | 0x0 | 0x4301a0 | 0x38ed0 | 0x37cd0 | 0x33d |
IsProcessorFeaturePresent | 0x0 | 0x4301a4 | 0x38ed4 | 0x37cd4 | 0x304 |
IsDebuggerPresent | 0x0 | 0x4301a8 | 0x38ed8 | 0x37cd8 | 0x300 |
UnhandledExceptionFilter | 0x0 | 0x4301ac | 0x38edc | 0x37cdc | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x4301b0 | 0x38ee0 | 0x37ce0 | 0x4a5 |
GetStartupInfoW | 0x0 | 0x4301b4 | 0x38ee4 | 0x37ce4 | 0x263 |
QueryPerformanceCounter | 0x0 | 0x4301b8 | 0x38ee8 | 0x37ce8 | 0x3a7 |
GetCurrentThreadId | 0x0 | 0x4301bc | 0x38eec | 0x37cec | 0x1c5 |
GetSystemTimeAsFileTime | 0x0 | 0x4301c0 | 0x38ef0 | 0x37cf0 | 0x279 |
InitializeSListHead | 0x0 | 0x4301c4 | 0x38ef4 | 0x37cf4 | 0x2e7 |
TerminateProcess | 0x0 | 0x4301c8 | 0x38ef8 | 0x37cf8 | 0x4c0 |
RtlUnwind | 0x0 | 0x4301cc | 0x38efc | 0x37cfc | 0x418 |
EncodePointer | 0x0 | 0x4301d0 | 0x38f00 | 0x37d00 | 0xea |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4301d4 | 0x38f04 | 0x37d04 | 0x2e3 |
TlsAlloc | 0x0 | 0x4301d8 | 0x38f08 | 0x37d08 | 0x4c5 |
TlsGetValue | 0x0 | 0x4301dc | 0x38f0c | 0x37d0c | 0x4c7 |
TlsSetValue | 0x0 | 0x4301e0 | 0x38f10 | 0x37d10 | 0x4c8 |
TlsFree | 0x0 | 0x4301e4 | 0x38f14 | 0x37d14 | 0x4c6 |
LoadLibraryExW | 0x0 | 0x4301e8 | 0x38f18 | 0x37d18 | 0x33e |
QueryPerformanceFrequency | 0x0 | 0x4301ec | 0x38f1c | 0x37d1c | 0x3a8 |
GetModuleHandleExW | 0x0 | 0x4301f0 | 0x38f20 | 0x37d20 | 0x217 |
GetModuleFileNameA | 0x0 | 0x4301f4 | 0x38f24 | 0x37d24 | 0x213 |
GetACP | 0x0 | 0x4301f8 | 0x38f28 | 0x37d28 | 0x168 |
HeapFree | 0x0 | 0x4301fc | 0x38f2c | 0x37d2c | 0x2cf |
HeapAlloc | 0x0 | 0x430200 | 0x38f30 | 0x37d30 | 0x2cb |
HeapReAlloc | 0x0 | 0x430204 | 0x38f34 | 0x37d34 | 0x2d2 |
GetStringTypeW | 0x0 | 0x430208 | 0x38f38 | 0x37d38 | 0x269 |
LCMapStringW | 0x0 | 0x43020c | 0x38f3c | 0x37d3c | 0x32d |
FindFirstFileExA | 0x0 | 0x430210 | 0x38f40 | 0x37d40 | 0x133 |
FindNextFileA | 0x0 | 0x430214 | 0x38f44 | 0x37d44 | 0x143 |
IsValidCodePage | 0x0 | 0x430218 | 0x38f48 | 0x37d48 | 0x30a |
GetOEMCP | 0x0 | 0x43021c | 0x38f4c | 0x37d4c | 0x237 |
GetCommandLineA | 0x0 | 0x430220 | 0x38f50 | 0x37d50 | 0x186 |
GetEnvironmentStringsW | 0x0 | 0x430224 | 0x38f54 | 0x37d54 | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x430228 | 0x38f58 | 0x37d58 | 0x161 |
DecodePointer | 0x0 | 0x43022c | 0x38f5c | 0x37d5c | 0xca |
gdiplus.dll (9)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GdiplusShutdown | 0x0 | 0x430234 | 0x38f64 | 0x37d64 | 0x274 |
GdiplusStartup | 0x0 | 0x430238 | 0x38f68 | 0x37d68 | 0x275 |
GdipCreateHBITMAPFromBitmap | 0x0 | 0x43023c | 0x38f6c | 0x37d6c | 0x5f |
GdipCreateBitmapFromStreamICM | 0x0 | 0x430240 | 0x38f70 | 0x37d70 | 0x52 |
GdipCreateBitmapFromStream | 0x0 | 0x430244 | 0x38f74 | 0x37d74 | 0x51 |
GdipDisposeImage | 0x0 | 0x430248 | 0x38f78 | 0x37d78 | 0x98 |
GdipCloneImage | 0x0 | 0x43024c | 0x38f7c | 0x37d7c | 0x36 |
GdipFree | 0x0 | 0x430250 | 0x38f80 | 0x37d80 | 0xed |
GdipAlloc | 0x0 | 0x430254 | 0x38f84 | 0x37d84 | 0x21 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
fatura.sfx.exe | 5 | 0x01320000 | 0x0138CFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
fatura.sfx.exe | 5 | 0x01320000 | 0x0138CFFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
C:\Users\FD1HVy\Desktop\454364vodafone-e-fatura.exe | Modified File | Stream |
Unknown
|
...
|
»
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
454364vodafone-e-fatura.exe | 1 | 0x00FB0000 | 0x0102BFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
454364vodafone-e-fatura.exe | 1 | 0x00FB0000 | 0x0102BFFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
C:\Users\FD1HVy\Desktop\7cYIG7R_Bg.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\7ZIEneEWitQXloMb.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\aaEh1XjueF.png.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\AcxbjLr4LDb.jpg.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\bnfqHdQMvbV9fl.odt.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\cnPcqpR6mYKwWbfY5xX.bmp.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\D_BOLwQrlF.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Hvq8LtKn_XVWH2w m.mp3.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\johsiurt.avi.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\nsv C_SWnxDSit.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\NYqfMfCSQ6IrgqU.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\oYnk87aLwYtycgmkN.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\QP2lx_xY.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\S haJTF1lXspyoz7qPK.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\TvcyfsELusy6tf19.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\XIbP.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\_kjl.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\vce 2GsJTpiqc3s3\0KK9327_mBsbZ.mkv.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\vce 2GsJTpiqc3s3\1r1gMtsv0blVRJ.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\vce 2GsJTpiqc3s3\8NlrPY 2lz9e1LIBf04f.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\vce 2GsJTpiqc3s3\bGG4.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\vce 2GsJTpiqc3s3\f uWn9d-fNEm8xF6.mkv.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\vce 2GsJTpiqc3s3\KniDwCaO21uYk4IPWV.csv.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\vce 2GsJTpiqc3s3\pUkJm_a4a0qy.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\vce 2GsJTpiqc3s3\x4I7Fbqe-kLQzd1fUt-V.mkv.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\vce 2GsJTpiqc3s3\XYpIBn0x4VZkFFRvx.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Links\Desktop.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Links\Downloads.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Links\OneDrive.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\-e05mO6ck.docx.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\0dNa9Ipg4OF.xlsx.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\5iEScw-P-bt0zvH0.docx.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\aghE1.pptx.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\C-o7_Ql2VxIC6.xlsx.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Dcqxyjv.docx.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\fIXeG1fjMw4VQ-SeI4sD.docx.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Ip RLazdND.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\jk6OBCNGIaAnb0.odt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\lCpJ6WuB.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\lWFh8--ly.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\mv3ytnTVP.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\NowuucUWH88.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\QycCod3aKy.xlsx.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\RnOng_uUANEZhdiVwxzo.xlsx.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\T1d-p3JxMF.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\un6rxRVJiqSaIj.rtf.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vjEnRfg-8iJV5S9s6yM5.pptx.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\z7sO5.xlsx.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\_Uvn6DNHmH.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CPoDMpxr\t-s39t4kjHqVYI_7oPz.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CPoDMpxr\ZKhqtyFMKDwyQgewHY1N.csv.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CPoDMpxr\AwH9xAzq7HnZYaALibUA\J_owSVG.odt.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CPoDMpxr\AwH9xAzq7HnZYaALibUA\_nKpG_jSbg1oMX.ppt.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CPoDMpxr\e4fndvcoLqNRAFIaMJ\aSoY7_s WdduV.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CPoDMpxr\e4fndvcoLqNRAFIaMJ\Q_VI.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CPoDMpxr\e4fndvcoLqNRAFIaMJ\yU6_OHjg.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CPoDMpxr\YEjsT\MrNSPQHeK1G_YpPYKJD.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CPoDMpxr\YEjsT\SI4zBwZk2879i6WhNLa.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CPoDMpxr\YEjsT\zhnGqRD-rZtgNp.rtf.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\EASk6o6CF0e kL2L\jBWrGIz2vRaowKZllk.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\EASk6o6CF0e kL2L\xQmghAcjXDckSt.odt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\EASk6o6CF0e kL2L\BZnu1veNVTy5ewM0\1xNULIT8.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\EASk6o6CF0e kL2L\BZnu1veNVTy5ewM0\tj_hul_qLkbpy.xlsx.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\EASk6o6CF0e kL2L\dwU1sWDrwwAwtXWPjN8E\1rLLqRHdtcPWKpIg-.rtf.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\EASk6o6CF0e kL2L\dwU1sWDrwwAwtXWPjN8E\E2jqZ1hPuAZ9fkvPz_fp.xlsx.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\EASk6o6CF0e kL2L\dwU1sWDrwwAwtXWPjN8E\hTOQeXyXkMxYLs2DOjmP.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\EASk6o6CF0e kL2L\dwU1sWDrwwAwtXWPjN8E\j54pS.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\EASk6o6CF0e kL2L\wJpBbkO-ZoXM\DKBSIs0RzHs4awqD.xlsx.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\EASk6o6CF0e kL2L\wJpBbkO-ZoXM\G0s5gRTbdhtMVv.pdf.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\EASk6o6CF0e kL2L\wJpBbkO-ZoXM\LDesP3 g3nRtMBVX22el.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\EASk6o6CF0e kL2L\wJpBbkO-ZoXM\_rgf.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\p6BQ5-YjI-RteFLY\aR2H.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\p6BQ5-YjI-RteFLY\CgR79Kfzbg-3Qbk9s6.xlsx.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\p6BQ5-YjI-RteFLY\i41j6mn 1jdQoeE5Sy.ppt.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\p6BQ5-YjI-RteFLY\Xe354cZANCjG3D.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\-T-q.png.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\0ygqwwt0eQO5oou2.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\1Ftl3457R8jo963.bmp.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\36ckktA6J.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\D0OoRLm pp4.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\fjbbxYMj8I9SpT7.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\fpYv3fQ.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\GaZiCtGeRTs.jpg.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\gJ9zBTPD-1GubPMj.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\GMmGEhIb3Psm.bmp.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\hC QJQt.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\hpkUf.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\iPpxvZ3GzU6BEwn7.png.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\kgazIq33.jpg.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\LsII.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\q9PQ6m6FTZlaVRyn.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\qx cC l6OaDw3F3ir.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\R_kad31fE8n9kjn.png.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\SvYNlt iTipCbGeaY21.jpg.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\sYGib zY69_.png.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\T5dowEUb06bqYQQ.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\ua7o.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\wbyq.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\xLS-jVD.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Y2g5s0bUdYCWTLgdwhk.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Ydho.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\yRDk8a4KrUdSBF0.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Z4feoFk.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Z7HvtM6H.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\Cvenk.mp3.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\__zKi8s.mp3.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\8xoHpHwf65aRqdFKyFMC\QKBWOFO.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\8xoHpHwf65aRqdFKyFMC\SbjGI9ABy5 ReLEt.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\8xoHpHwf65aRqdFKyFMC\gSc1\IEJPo6bRcr1-eu_OA2.mp3.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\uKXWa1PtjbZApm2LEb\LFWVJ01Ad\02SaSBZW.mp3.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\uKXWa1PtjbZApm2LEb\LFWVJ01Ad\BRPUq7z.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\uKXWa1PtjbZApm2LEb\LFWVJ01Ad\DGx7vOTPNlq BISYL.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\uKXWa1PtjbZApm2LEb\O 6eRN cahdm2RA0wAkE\jCRflz5tqOdJFiCip.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\uKXWa1PtjbZApm2LEb\Rglo0bBTnKx1\kjP8\hWnHS8cPuVdh2Ls.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\wPjihQO\VxRe-WtS8.mp3.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\wPjihQO\XmpXvkktcdDvRu.mp3.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\8YGJ_6UTMNVDTwnwqh.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\9 _FCQBGlKcrw.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eHX zx0_c\N s0HqpST4wCqfyHxso.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eHX zx0_c\9sERZTGVCGoRB9xf4w\9 kNqzst0HfRpFR27W1.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eHX zx0_c\9sERZTGVCGoRB9xf4w\cZsBv.avi.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eHX zx0_c\9sERZTGVCGoRB9xf4w\gp0Bym0 qsqZvsQ9XZ.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eHX zx0_c\9sERZTGVCGoRB9xf4w\ieD 5xHHb4tpf.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eHX zx0_c\9sERZTGVCGoRB9xf4w\lgEBL xrCOPqpwsQP.avi.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eHX zx0_c\pzrFntx4S\3wY7y4 UtKyhhhQXY5CN.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eHX zx0_c\pzrFntx4S\ewm A3H.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eHX zx0_c\pzrFntx4S\MNtp4hzxjr_UVIE Ql.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eHX zx0_c\pzrFntx4S\sYRcCs6AarCtb.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\vKNP_HE9n_djMTLR\GZxU9e9.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\vKNP_HE9n_djMTLR\swxqRQnEKCqJB W Ebi.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\vKNP_HE9n_djMTLR\bOUZyxkf8\6R3dt4oFv8miWc.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\vKNP_HE9n_djMTLR\bOUZyxkf8\B1kAUUgoW_w.mkv.shade8 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\vKNP_HE9n_djMTLR\bOUZyxkf8\IZpwl1rGRLixPwlSk.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\vKNP_HE9n_djMTLR\bOUZyxkf8\qOvu44.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\READ_THIS.txt | Dropped File | Text |
Unknown
|
...
|
»