VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan, Dropper |
m.exe
Windows Exe (x86-32)
Created at 2019-04-17T10:38:00
Remarks (1/1)
(0x200003a): A task was rescheduled ahead of time to reveal dormant functionality.
Remarks
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (20) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-04-17 09:47 (UTC+2) |
Last Seen | 2019-04-17 12:37 (UTC+2) |
Names | Win32.Trojan.Matrix |
Families | Matrix |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4dca54 |
Size Of Code | 0xdfa00 |
Size Of Initialized Data | 0x48c00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-03-21 22:09:01+00:00 |
Sections (10)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xdaaa4 | 0xdac00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.38 |
.itext | 0x4dc000 | 0x4cc4 | 0x4e00 | 0xdb000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.72 |
.data | 0x4e1000 | 0x5b08 | 0x5c00 | 0xdfe00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.19 |
.bss | 0x4e7000 | 0x6444 | 0x0 | 0x0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.idata | 0x4ee000 | 0x1236 | 0x1400 | 0xe5a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.8 |
.didata | 0x4f0000 | 0xfa | 0x200 | 0xe6e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.88 |
.edata | 0x4f1000 | 0x6c | 0x200 | 0xe7000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.31 |
.tls | 0x4f2000 | 0x14 | 0x0 | 0x0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rdata | 0x4f3000 | 0x18 | 0x200 | 0xe7200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.21 |
.rsrc | 0x4f4000 | 0x41600 | 0x41600 | 0xe7400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.96 |
Imports (8)
»
oleaut32.dll (12)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysFreeString | 0x0 | 0x4ee36c | 0xee0b4 | 0xe5ab4 | 0x0 |
SysReAllocStringLen | 0x0 | 0x4ee370 | 0xee0b8 | 0xe5ab8 | 0x0 |
SysAllocStringLen | 0x0 | 0x4ee374 | 0xee0bc | 0xe5abc | 0x0 |
SafeArrayPtrOfIndex | 0x0 | 0x4ee378 | 0xee0c0 | 0xe5ac0 | 0x0 |
SafeArrayGetUBound | 0x0 | 0x4ee37c | 0xee0c4 | 0xe5ac4 | 0x0 |
SafeArrayGetLBound | 0x0 | 0x4ee380 | 0xee0c8 | 0xe5ac8 | 0x0 |
SafeArrayCreate | 0x0 | 0x4ee384 | 0xee0cc | 0xe5acc | 0x0 |
VariantChangeType | 0x0 | 0x4ee388 | 0xee0d0 | 0xe5ad0 | 0x0 |
VariantCopy | 0x0 | 0x4ee38c | 0xee0d4 | 0xe5ad4 | 0x0 |
VariantClear | 0x0 | 0x4ee390 | 0xee0d8 | 0xe5ad8 | 0x0 |
VariantInit | 0x0 | 0x4ee394 | 0xee0dc | 0xe5adc | 0x0 |
GetErrorInfo | 0x0 | 0x4ee398 | 0xee0e0 | 0xe5ae0 | 0x0 |
advapi32.dll (15)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryValueExW | 0x0 | 0x4ee3a0 | 0xee0e8 | 0xe5ae8 | 0x0 |
RegOpenKeyExW | 0x0 | 0x4ee3a4 | 0xee0ec | 0xe5aec | 0x0 |
RegCloseKey | 0x0 | 0x4ee3a8 | 0xee0f0 | 0xe5af0 | 0x0 |
OpenThreadToken | 0x0 | 0x4ee3ac | 0xee0f4 | 0xe5af4 | 0x0 |
OpenProcessToken | 0x0 | 0x4ee3b0 | 0xee0f8 | 0xe5af8 | 0x0 |
GetUserNameA | 0x0 | 0x4ee3b4 | 0xee0fc | 0xe5afc | 0x0 |
GetTokenInformation | 0x0 | 0x4ee3b8 | 0xee100 | 0xe5b00 | 0x0 |
GetSidSubAuthorityCount | 0x0 | 0x4ee3bc | 0xee104 | 0xe5b04 | 0x0 |
GetSidSubAuthority | 0x0 | 0x4ee3c0 | 0xee108 | 0xe5b08 | 0x0 |
FreeSid | 0x0 | 0x4ee3c4 | 0xee10c | 0xe5b0c | 0x0 |
EqualSid | 0x0 | 0x4ee3c8 | 0xee110 | 0xe5b10 | 0x0 |
AllocateAndInitializeSid | 0x0 | 0x4ee3cc | 0xee114 | 0xe5b14 | 0x0 |
CryptGenRandom | 0x0 | 0x4ee3d0 | 0xee118 | 0xe5b18 | 0x0 |
CryptReleaseContext | 0x0 | 0x4ee3d4 | 0xee11c | 0xe5b1c | 0x0 |
CryptAcquireContextW | 0x0 | 0x4ee3d8 | 0xee120 | 0xe5b20 | 0x0 |
user32.dll (10)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MessageBoxA | 0x0 | 0x4ee3e0 | 0xee128 | 0xe5b28 | 0x0 |
CharNextW | 0x0 | 0x4ee3e4 | 0xee12c | 0xe5b2c | 0x0 |
LoadStringW | 0x0 | 0x4ee3e8 | 0xee130 | 0xe5b30 | 0x0 |
PeekMessageW | 0x0 | 0x4ee3ec | 0xee134 | 0xe5b34 | 0x0 |
MsgWaitForMultipleObjects | 0x0 | 0x4ee3f0 | 0xee138 | 0xe5b38 | 0x0 |
MessageBoxW | 0x0 | 0x4ee3f4 | 0xee13c | 0xe5b3c | 0x0 |
GetSystemMetrics | 0x0 | 0x4ee3f8 | 0xee140 | 0xe5b40 | 0x0 |
CharUpperBuffW | 0x0 | 0x4ee3fc | 0xee144 | 0xe5b44 | 0x0 |
CharUpperW | 0x0 | 0x4ee400 | 0xee148 | 0xe5b48 | 0x0 |
CharLowerBuffW | 0x0 | 0x4ee404 | 0xee14c | 0xe5b4c | 0x0 |
kernel32.dll (119)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Sleep | 0x0 | 0x4ee40c | 0xee154 | 0xe5b54 | 0x0 |
VirtualFree | 0x0 | 0x4ee410 | 0xee158 | 0xe5b58 | 0x0 |
VirtualAlloc | 0x0 | 0x4ee414 | 0xee15c | 0xe5b5c | 0x0 |
lstrlenW | 0x0 | 0x4ee418 | 0xee160 | 0xe5b60 | 0x0 |
VirtualQuery | 0x0 | 0x4ee41c | 0xee164 | 0xe5b64 | 0x0 |
GetTickCount | 0x0 | 0x4ee420 | 0xee168 | 0xe5b68 | 0x0 |
GetSystemInfo | 0x0 | 0x4ee424 | 0xee16c | 0xe5b6c | 0x0 |
GetVersion | 0x0 | 0x4ee428 | 0xee170 | 0xe5b70 | 0x0 |
CompareStringW | 0x0 | 0x4ee42c | 0xee174 | 0xe5b74 | 0x0 |
IsDBCSLeadByteEx | 0x0 | 0x4ee430 | 0xee178 | 0xe5b78 | 0x0 |
IsValidLocale | 0x0 | 0x4ee434 | 0xee17c | 0xe5b7c | 0x0 |
SetThreadLocale | 0x0 | 0x4ee438 | 0xee180 | 0xe5b80 | 0x0 |
GetSystemDefaultUILanguage | 0x0 | 0x4ee43c | 0xee184 | 0xe5b84 | 0x0 |
GetUserDefaultUILanguage | 0x0 | 0x4ee440 | 0xee188 | 0xe5b88 | 0x0 |
GetLocaleInfoW | 0x0 | 0x4ee444 | 0xee18c | 0xe5b8c | 0x0 |
WideCharToMultiByte | 0x0 | 0x4ee448 | 0xee190 | 0xe5b90 | 0x0 |
MultiByteToWideChar | 0x0 | 0x4ee44c | 0xee194 | 0xe5b94 | 0x0 |
GetConsoleOutputCP | 0x0 | 0x4ee450 | 0xee198 | 0xe5b98 | 0x0 |
GetConsoleCP | 0x0 | 0x4ee454 | 0xee19c | 0xe5b9c | 0x0 |
GetACP | 0x0 | 0x4ee458 | 0xee1a0 | 0xe5ba0 | 0x0 |
LoadLibraryExW | 0x0 | 0x4ee45c | 0xee1a4 | 0xe5ba4 | 0x0 |
GetStartupInfoW | 0x0 | 0x4ee460 | 0xee1a8 | 0xe5ba8 | 0x0 |
GetProcAddress | 0x0 | 0x4ee464 | 0xee1ac | 0xe5bac | 0x0 |
GetModuleHandleW | 0x0 | 0x4ee468 | 0xee1b0 | 0xe5bb0 | 0x0 |
GetModuleFileNameW | 0x0 | 0x4ee46c | 0xee1b4 | 0xe5bb4 | 0x0 |
GetCommandLineW | 0x0 | 0x4ee470 | 0xee1b8 | 0xe5bb8 | 0x0 |
FreeLibrary | 0x0 | 0x4ee474 | 0xee1bc | 0xe5bbc | 0x0 |
GetLastError | 0x0 | 0x4ee478 | 0xee1c0 | 0xe5bc0 | 0x0 |
UnhandledExceptionFilter | 0x0 | 0x4ee47c | 0xee1c4 | 0xe5bc4 | 0x0 |
RtlUnwind | 0x0 | 0x4ee480 | 0xee1c8 | 0xe5bc8 | 0x0 |
RaiseException | 0x0 | 0x4ee484 | 0xee1cc | 0xe5bcc | 0x0 |
ExitProcess | 0x0 | 0x4ee488 | 0xee1d0 | 0xe5bd0 | 0x0 |
ExitThread | 0x0 | 0x4ee48c | 0xee1d4 | 0xe5bd4 | 0x0 |
SwitchToThread | 0x0 | 0x4ee490 | 0xee1d8 | 0xe5bd8 | 0x0 |
GetCurrentThreadId | 0x0 | 0x4ee494 | 0xee1dc | 0xe5bdc | 0x0 |
CreateThread | 0x0 | 0x4ee498 | 0xee1e0 | 0xe5be0 | 0x0 |
DeleteCriticalSection | 0x0 | 0x4ee49c | 0xee1e4 | 0xe5be4 | 0x0 |
LeaveCriticalSection | 0x0 | 0x4ee4a0 | 0xee1e8 | 0xe5be8 | 0x0 |
EnterCriticalSection | 0x0 | 0x4ee4a4 | 0xee1ec | 0xe5bec | 0x0 |
InitializeCriticalSection | 0x0 | 0x4ee4a8 | 0xee1f0 | 0xe5bf0 | 0x0 |
FindFirstFileW | 0x0 | 0x4ee4ac | 0xee1f4 | 0xe5bf4 | 0x0 |
FindClose | 0x0 | 0x4ee4b0 | 0xee1f8 | 0xe5bf8 | 0x0 |
WriteFile | 0x0 | 0x4ee4b4 | 0xee1fc | 0xe5bfc | 0x0 |
SetFilePointer | 0x0 | 0x4ee4b8 | 0xee200 | 0xe5c00 | 0x0 |
SetEndOfFile | 0x0 | 0x4ee4bc | 0xee204 | 0xe5c04 | 0x0 |
ReadFile | 0x0 | 0x4ee4c0 | 0xee208 | 0xe5c08 | 0x0 |
GetFileType | 0x0 | 0x4ee4c4 | 0xee20c | 0xe5c0c | 0x0 |
GetFileSize | 0x0 | 0x4ee4c8 | 0xee210 | 0xe5c10 | 0x0 |
CreateFileW | 0x0 | 0x4ee4cc | 0xee214 | 0xe5c14 | 0x0 |
GetStdHandle | 0x0 | 0x4ee4d0 | 0xee218 | 0xe5c18 | 0x0 |
CloseHandle | 0x0 | 0x4ee4d4 | 0xee21c | 0xe5c1c | 0x0 |
LoadLibraryA | 0x0 | 0x4ee4d8 | 0xee220 | 0xe5c20 | 0x0 |
TlsSetValue | 0x0 | 0x4ee4dc | 0xee224 | 0xe5c24 | 0x0 |
TlsGetValue | 0x0 | 0x4ee4e0 | 0xee228 | 0xe5c28 | 0x0 |
LocalFree | 0x0 | 0x4ee4e4 | 0xee22c | 0xe5c2c | 0x0 |
LocalAlloc | 0x0 | 0x4ee4e8 | 0xee230 | 0xe5c30 | 0x0 |
WaitForSingleObject | 0x0 | 0x4ee4ec | 0xee234 | 0xe5c34 | 0x0 |
WaitForMultipleObjects | 0x0 | 0x4ee4f0 | 0xee238 | 0xe5c38 | 0x0 |
VirtualQueryEx | 0x0 | 0x4ee4f4 | 0xee23c | 0xe5c3c | 0x0 |
VirtualProtect | 0x0 | 0x4ee4f8 | 0xee240 | 0xe5c40 | 0x0 |
VerSetConditionMask | 0x0 | 0x4ee4fc | 0xee244 | 0xe5c44 | 0x0 |
VerifyVersionInfoW | 0x0 | 0x4ee500 | 0xee248 | 0xe5c48 | 0x0 |
SuspendThread | 0x0 | 0x4ee504 | 0xee24c | 0xe5c4c | 0x0 |
SizeofResource | 0x0 | 0x4ee508 | 0xee250 | 0xe5c50 | 0x0 |
SetThreadPriority | 0x0 | 0x4ee50c | 0xee254 | 0xe5c54 | 0x0 |
SetLastError | 0x0 | 0x4ee510 | 0xee258 | 0xe5c58 | 0x0 |
SetFileAttributesW | 0x0 | 0x4ee514 | 0xee25c | 0xe5c5c | 0x0 |
SetEvent | 0x0 | 0x4ee518 | 0xee260 | 0xe5c60 | 0x0 |
SetErrorMode | 0x0 | 0x4ee51c | 0xee264 | 0xe5c64 | 0x0 |
ResumeThread | 0x0 | 0x4ee520 | 0xee268 | 0xe5c68 | 0x0 |
ResetEvent | 0x0 | 0x4ee524 | 0xee26c | 0xe5c6c | 0x0 |
ReleaseMutex | 0x0 | 0x4ee528 | 0xee270 | 0xe5c70 | 0x0 |
QueryPerformanceFrequency | 0x0 | 0x4ee52c | 0xee274 | 0xe5c74 | 0x0 |
QueryPerformanceCounter | 0x0 | 0x4ee530 | 0xee278 | 0xe5c78 | 0x0 |
OpenMutexW | 0x0 | 0x4ee534 | 0xee27c | 0xe5c7c | 0x0 |
MoveFileExW | 0x0 | 0x4ee538 | 0xee280 | 0xe5c80 | 0x0 |
LockResource | 0x0 | 0x4ee53c | 0xee284 | 0xe5c84 | 0x0 |
LoadResource | 0x0 | 0x4ee540 | 0xee288 | 0xe5c88 | 0x0 |
LoadLibraryW | 0x0 | 0x4ee544 | 0xee28c | 0xe5c8c | 0x0 |
HeapFree | 0x0 | 0x4ee548 | 0xee290 | 0xe5c90 | 0x0 |
HeapDestroy | 0x0 | 0x4ee54c | 0xee294 | 0xe5c94 | 0x0 |
HeapCreate | 0x0 | 0x4ee550 | 0xee298 | 0xe5c98 | 0x0 |
HeapAlloc | 0x0 | 0x4ee554 | 0xee29c | 0xe5c9c | 0x0 |
GetVolumeInformationW | 0x0 | 0x4ee558 | 0xee2a0 | 0xe5ca0 | 0x0 |
GetVersionExW | 0x0 | 0x4ee55c | 0xee2a4 | 0xe5ca4 | 0x0 |
GetUserDefaultLangID | 0x0 | 0x4ee560 | 0xee2a8 | 0xe5ca8 | 0x0 |
GetUserDefaultLCID | 0x0 | 0x4ee564 | 0xee2ac | 0xe5cac | 0x0 |
GetThreadTimes | 0x0 | 0x4ee568 | 0xee2b0 | 0xe5cb0 | 0x0 |
GetThreadPriority | 0x0 | 0x4ee56c | 0xee2b4 | 0xe5cb4 | 0x0 |
GetThreadLocale | 0x0 | 0x4ee570 | 0xee2b8 | 0xe5cb8 | 0x0 |
GetSystemTimes | 0x0 | 0x4ee574 | 0xee2bc | 0xe5cbc | 0x0 |
GetSystemDefaultLangID | 0x0 | 0x4ee578 | 0xee2c0 | 0xe5cc0 | 0x0 |
GetSystemDefaultLCID | 0x0 | 0x4ee57c | 0xee2c4 | 0xe5cc4 | 0x0 |
GetProcessTimes | 0x0 | 0x4ee580 | 0xee2c8 | 0xe5cc8 | 0x0 |
GetLocalTime | 0x0 | 0x4ee584 | 0xee2cc | 0xe5ccc | 0x0 |
GetFullPathNameW | 0x0 | 0x4ee588 | 0xee2d0 | 0xe5cd0 | 0x0 |
GetFileAttributesW | 0x0 | 0x4ee58c | 0xee2d4 | 0xe5cd4 | 0x0 |
GetExitCodeThread | 0x0 | 0x4ee590 | 0xee2d8 | 0xe5cd8 | 0x0 |
GetDriveTypeW | 0x0 | 0x4ee594 | 0xee2dc | 0xe5cdc | 0x0 |
GetDiskFreeSpaceW | 0x0 | 0x4ee598 | 0xee2e0 | 0xe5ce0 | 0x0 |
GetDateFormatW | 0x0 | 0x4ee59c | 0xee2e4 | 0xe5ce4 | 0x0 |
GetCurrentThread | 0x0 | 0x4ee5a0 | 0xee2e8 | 0xe5ce8 | 0x0 |
GetCurrentProcessId | 0x0 | 0x4ee5a4 | 0xee2ec | 0xe5cec | 0x0 |
GetCurrentProcess | 0x0 | 0x4ee5a8 | 0xee2f0 | 0xe5cf0 | 0x0 |
GetComputerNameA | 0x0 | 0x4ee5ac | 0xee2f4 | 0xe5cf4 | 0x0 |
GetCPInfoExW | 0x0 | 0x4ee5b0 | 0xee2f8 | 0xe5cf8 | 0x0 |
GetCPInfo | 0x0 | 0x4ee5b4 | 0xee2fc | 0xe5cfc | 0x0 |
FreeResource | 0x0 | 0x4ee5b8 | 0xee300 | 0xe5d00 | 0x0 |
InterlockedCompareExchange | 0x0 | 0x4ee5bc | 0xee304 | 0xe5d04 | 0x0 |
FormatMessageW | 0x0 | 0x4ee5c0 | 0xee308 | 0xe5d08 | 0x0 |
FindResourceW | 0x0 | 0x4ee5c4 | 0xee30c | 0xe5d0c | 0x0 |
FindNextFileW | 0x0 | 0x4ee5c8 | 0xee310 | 0xe5d10 | 0x0 |
ExpandEnvironmentStringsW | 0x0 | 0x4ee5cc | 0xee314 | 0xe5d14 | 0x0 |
EnumSystemLocalesW | 0x0 | 0x4ee5d0 | 0xee318 | 0xe5d18 | 0x0 |
EnumCalendarInfoW | 0x0 | 0x4ee5d4 | 0xee31c | 0xe5d1c | 0x0 |
DeleteFileW | 0x0 | 0x4ee5d8 | 0xee320 | 0xe5d20 | 0x0 |
CreateProcessW | 0x0 | 0x4ee5dc | 0xee324 | 0xe5d24 | 0x0 |
CreateMutexW | 0x0 | 0x4ee5e0 | 0xee328 | 0xe5d28 | 0x0 |
CreateEventW | 0x0 | 0x4ee5e4 | 0xee32c | 0xe5d2c | 0x0 |
ole32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoUninitialize | 0x0 | 0x4ee5ec | 0xee334 | 0xe5d34 | 0x0 |
CoInitialize | 0x0 | 0x4ee5f0 | 0xee338 | 0xe5d38 | 0x0 |
shell32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderPathW | 0x0 | 0x4ee5f8 | 0xee340 | 0xe5d40 | 0x0 |
wsock32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WSACleanup | 0x0 | 0x4ee600 | 0xee348 | 0xe5d48 | 0x0 |
WSAStartup | 0x0 | 0x4ee604 | 0xee34c | 0xe5d4c | 0x0 |
gethostname | 0x0 | 0x4ee608 | 0xee350 | 0xe5d50 | 0x0 |
gethostbyname | 0x0 | 0x4ee60c | 0xee354 | 0xe5d54 | 0x0 |
inet_ntoa | 0x0 | 0x4ee610 | 0xee358 | 0xe5d58 | 0x0 |
netapi32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetShareEnum | 0x0 | 0x4ee618 | 0xee360 | 0xe5d60 | 0x0 |
NetApiBufferFree | 0x0 | 0x4ee61c | 0xee364 | 0xe5d64 | 0x0 |
Exports (1)
»
Api name | EAT Address | Ordinal |
---|---|---|
TMethodImplementationIntercept | 0x509b8 | 0x1 |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Ransom.Matrix.CDD86710 |
Malicious
|
C:\Users\FD1HVy\Desktop\mxkeFu6a.exe | Dropped File | Binary |
Blacklisted
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2018-04-08 16:54 (UTC+2) |
Last Seen | 2019-03-19 05:55 (UTC+1) |
Names | Win32.Trojan.Cryptinject |
Families | Cryptinject |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x475810 |
Size Of Code | 0x29000 |
Size Of Initialized Data | 0x1000 |
Size Of Uninitialized Data | 0x4c000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-12-10 21:18:46+00:00 |
Version Information (8)
»
CompanyName | Sysinternals - www.sysinternals.com |
FileDescription | Handle viewer |
FileVersion | 4.11 |
InternalName | Nthandle |
LegalCopyright | Copyright (C) 1997-2017 Mark Russinovich |
OriginalFilename | Nthandle.exe |
ProductName | Sysinternals Handle |
ProductVersion | 4.11 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
UPX0 | 0x401000 | 0x4c000 | 0x0 | 0x400 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
UPX1 | 0x44d000 | 0x29000 | 0x28a00 | 0x400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.93 |
.rsrc | 0x476000 | 0x1000 | 0x800 | 0x28e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.04 |
Imports (6)
»
ADVAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegOpenKeyW | 0x0 | 0x47666c | 0x7666c | 0x2946c | 0x0 |
COMDLG32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PrintDlgW | 0x0 | 0x476674 | 0x76674 | 0x29474 | 0x0 |
GDI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EndDoc | 0x0 | 0x47667c | 0x7667c | 0x2947c | 0x0 |
KERNEL32.DLL (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | 0x0 | 0x476684 | 0x76684 | 0x29484 | 0x0 |
ExitProcess | 0x0 | 0x476688 | 0x76688 | 0x29488 | 0x0 |
GetProcAddress | 0x0 | 0x47668c | 0x7668c | 0x2948c | 0x0 |
VirtualProtect | 0x0 | 0x476690 | 0x76690 | 0x29490 | 0x0 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EndDialog | 0x0 | 0x476698 | 0x76698 | 0x29498 | 0x0 |
VERSION.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VerQueryValueW | 0x0 | 0x4766a0 | 0x766a0 | 0x294a0 | 0x0 |
Memory Dumps (143)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
mxkefu6a.exe | 28 | 0x00400000 | 0x00476FFF | Marked Writable | - | 32-bit | - |
![]() |
![]() |
...
|
mxkefu6a.exe | 28 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040F93F, 0x00407336 |
![]() |
![]() |
...
|
mxkefu6a.exe | 28 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004080C0 |
![]() |
![]() |
...
|
mxkefu6a.exe | 28 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040AE73 |
![]() |
![]() |
...
|
mxkefu6a.exe | 28 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040579A |
![]() |
![]() |
...
|
mxkefu6a.exe | 28 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040B435 |
![]() |
![]() |
...
|
mxkefu6a.exe | 28 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
mxkefu6a.exe | 28 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00406078 |
![]() |
![]() |
...
|
mxkefu6a.exe | 35 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004080C0 |
![]() |
![]() |
...
|
mxkefu6a.exe | 35 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040AE73 |
![]() |
![]() |
...
|
mxkefu6a.exe | 35 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040579A |
![]() |
![]() |
...
|
mxkefu6a.exe | 35 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040B435 |
![]() |
![]() |
...
|
mxkefu6a.exe | 35 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
mxkefu6a.exe | 35 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00406078 |
![]() |
![]() |
...
|
mxkefu6a.exe | 35 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040DEC6 |
![]() |
![]() |
...
|
mxkefu6a.exe | 27 | 0x00400000 | 0x00476FFF | Marked Writable | - | 32-bit | - |
![]() |
![]() |
...
|
mxkefu6a.exe | 27 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040F93F, 0x00407336 |
![]() |
![]() |
...
|
mxkefu6a.exe | 27 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004080C0 |
![]() |
![]() |
...
|
mxkefu6a.exe | 27 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040AE73 |
![]() |
![]() |
...
|
mxkefu6a.exe | 27 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040579A |
![]() |
![]() |
...
|
mxkefu6a.exe | 27 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040B435 |
![]() |
![]() |
...
|
mxkefu6a.exe | 27 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
mxkefu6a.exe | 27 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040608C |
![]() |
![]() |
...
|
mxkefu6a.exe | 27 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040DEC6 |
![]() |
![]() |
...
|
mxkefu6a.exe | 28 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040DEC6 |
![]() |
![]() |
...
|
mxkefu6a.exe | 28 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00410AB1 |
![]() |
![]() |
...
|
mxkefu6a.exe | 28 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00412434 |
![]() |
![]() |
...
|
mxkefu6a.exe | 28 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00416A09, 0x00415F2F, ... |
![]() |
![]() |
...
|
mxkefu6a.exe | 28 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004048D4 |
![]() |
![]() |
...
|
mxkefu6a.exe | 28 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040C3C0, 0x004112CE |
![]() |
![]() |
...
|
mxkefu6a.exe | 28 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004020F0 |
![]() |
![]() |
...
|
mxkefu6a.exe | 35 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00410AB1 |
![]() |
![]() |
...
|
mxkefu6a.exe | 35 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00412434 |
![]() |
![]() |
...
|
mxkefu6a.exe | 35 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00416A09, 0x00415F2F, ... |
![]() |
![]() |
...
|
mxkefu6a.exe | 35 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004048D4 |
![]() |
![]() |
...
|
mxkefu6a.exe | 35 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040C3C0, 0x004112CE |
![]() |
![]() |
...
|
mxkefu6a.exe | 35 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004020F0 |
![]() |
![]() |
...
|
mxkefu6a.exe | 27 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00410AB1 |
![]() |
![]() |
...
|
mxkefu6a.exe | 27 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00412434 |
![]() |
![]() |
...
|
mxkefu6a.exe | 27 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00416A09, 0x00415F2F, ... |
![]() |
![]() |
...
|
mxkefu6a.exe | 27 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004048D4 |
![]() |
![]() |
...
|
mxkefu6a.exe | 27 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040C3C0, 0x004112CE |
![]() |
![]() |
...
|
mxkefu6a.exe | 27 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004020F0 |
![]() |
![]() |
...
|
mxkefu6a.exe | 35 | 0x00400000 | 0x00476FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
mxkefu6a.exe | 27 | 0x00400000 | 0x00476FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
mxkefu6a.exe | 40 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004080C0 |
![]() |
![]() |
...
|
mxkefu6a.exe | 40 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040AE73 |
![]() |
![]() |
...
|
mxkefu6a.exe | 40 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040579A |
![]() |
![]() |
...
|
mxkefu6a.exe | 40 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040B435 |
![]() |
![]() |
...
|
mxkefu6a.exe | 40 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
mxkefu6a.exe | 40 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00406078 |
![]() |
![]() |
...
|
mxkefu6a.exe | 40 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040DEC6 |
![]() |
![]() |
...
|
mxkefu6a.exe | 40 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00410AB1 |
![]() |
![]() |
...
|
mxkefu6a.exe | 41 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004080C0 |
![]() |
![]() |
...
|
mxkefu6a.exe | 41 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040AE73 |
![]() |
![]() |
...
|
mxkefu6a.exe | 41 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040579A |
![]() |
![]() |
...
|
mxkefu6a.exe | 41 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040B435 |
![]() |
![]() |
...
|
mxkefu6a.exe | 41 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
mxkefu6a.exe | 41 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040608C |
![]() |
![]() |
...
|
mxkefu6a.exe | 41 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040DEC6 |
![]() |
![]() |
...
|
mxkefu6a.exe | 41 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00410AB1 |
![]() |
![]() |
...
|
mxkefu6a.exe | 40 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00412434 |
![]() |
![]() |
...
|
mxkefu6a.exe | 40 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00416A09, 0x00415F2F, ... |
![]() |
![]() |
...
|
mxkefu6a.exe | 40 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004048D4 |
![]() |
![]() |
...
|
mxkefu6a.exe | 40 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040C3C0, 0x004112CE |
![]() |
![]() |
...
|
mxkefu6a.exe | 40 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004020F0 |
![]() |
![]() |
...
|
mxkefu6a.exe | 41 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00412434 |
![]() |
![]() |
...
|
mxkefu6a.exe | 41 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00416A09, 0x00415F2F, ... |
![]() |
![]() |
...
|
mxkefu6a.exe | 41 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004048D4 |
![]() |
![]() |
...
|
mxkefu6a.exe | 41 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040C3C0, 0x004112CE |
![]() |
![]() |
...
|
mxkefu6a.exe | 41 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004020F0 |
![]() |
![]() |
...
|
mxkefu6a.exe | 40 | 0x00400000 | 0x00476FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
mxkefu6a.exe | 41 | 0x00400000 | 0x00476FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
mxkefu6a.exe | 28 | 0x00400000 | 0x00476FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
mxkefu6a.exe | 121 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004080C0 |
![]() |
![]() |
...
|
mxkefu6a.exe | 121 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040AE73 |
![]() |
![]() |
...
|
mxkefu6a.exe | 121 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040579A |
![]() |
![]() |
...
|
mxkefu6a.exe | 121 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040B435 |
![]() |
![]() |
...
|
mxkefu6a.exe | 121 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
mxkefu6a.exe | 121 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00406078 |
![]() |
![]() |
...
|
mxkefu6a.exe | 121 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040DEC6 |
![]() |
![]() |
...
|
mxkefu6a.exe | 121 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00410AB1 |
![]() |
![]() |
...
|
mxkefu6a.exe | 121 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00412434 |
![]() |
![]() |
...
|
mxkefu6a.exe | 121 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00416A09, 0x00415F2F, ... |
![]() |
![]() |
...
|
mxkefu6a.exe | 121 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004048D4 |
![]() |
![]() |
...
|
mxkefu6a.exe | 121 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040C3C0, 0x004112CE |
![]() |
![]() |
...
|
mxkefu6a.exe | 121 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004020F0 |
![]() |
![]() |
...
|
mxkefu6a.exe | 126 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004080C0 |
![]() |
![]() |
...
|
mxkefu6a.exe | 126 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040AE73 |
![]() |
![]() |
...
|
mxkefu6a.exe | 126 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040579A |
![]() |
![]() |
...
|
mxkefu6a.exe | 126 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040B435 |
![]() |
![]() |
...
|
mxkefu6a.exe | 126 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
mxkefu6a.exe | 126 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040608C |
![]() |
![]() |
...
|
mxkefu6a.exe | 126 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040DEC6 |
![]() |
![]() |
...
|
mxkefu6a.exe | 126 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00410AB1 |
![]() |
![]() |
...
|
mxkefu6a.exe | 126 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00412434 |
![]() |
![]() |
...
|
mxkefu6a.exe | 126 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00416A09, 0x00415F2F, ... |
![]() |
![]() |
...
|
mxkefu6a.exe | 126 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004048D4 |
![]() |
![]() |
...
|
mxkefu6a.exe | 126 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040C3C0, 0x004112CE |
![]() |
![]() |
...
|
mxkefu6a.exe | 126 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004020F0 |
![]() |
![]() |
...
|
mxkefu6a.exe | 126 | 0x00400000 | 0x00476FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
mxkefu6a.exe | 132 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004080C0 |
![]() |
![]() |
...
|
mxkefu6a.exe | 132 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040AE73 |
![]() |
![]() |
...
|
mxkefu6a.exe | 132 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040579A |
![]() |
![]() |
...
|
mxkefu6a.exe | 132 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040B435 |
![]() |
![]() |
...
|
mxkefu6a.exe | 132 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
mxkefu6a.exe | 132 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040608C |
![]() |
![]() |
...
|
mxkefu6a.exe | 132 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040DEC6 |
![]() |
![]() |
...
|
mxkefu6a.exe | 132 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00410AB1 |
![]() |
![]() |
...
|
mxkefu6a.exe | 132 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00412434 |
![]() |
![]() |
...
|
mxkefu6a.exe | 132 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00416A09, 0x00415F2F, ... |
![]() |
![]() |
...
|
mxkefu6a.exe | 132 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004048D4 |
![]() |
![]() |
...
|
mxkefu6a.exe | 132 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040C3C0, 0x004112CE |
![]() |
![]() |
...
|
mxkefu6a.exe | 132 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004020F0 |
![]() |
![]() |
...
|
mxkefu6a.exe | 132 | 0x00400000 | 0x00476FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
mxkefu6a.exe | 121 | 0x00400000 | 0x00476FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
mxkefu6a.exe | 173 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004080C0 |
![]() |
![]() |
...
|
mxkefu6a.exe | 173 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040AE73 |
![]() |
![]() |
...
|
mxkefu6a.exe | 173 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040579A |
![]() |
![]() |
...
|
mxkefu6a.exe | 173 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040B435 |
![]() |
![]() |
...
|
mxkefu6a.exe | 173 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
mxkefu6a.exe | 173 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00406078 |
![]() |
![]() |
...
|
mxkefu6a.exe | 173 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040DEC6 |
![]() |
![]() |
...
|
mxkefu6a.exe | 173 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00410AB1 |
![]() |
![]() |
...
|
mxkefu6a.exe | 173 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00412434 |
![]() |
![]() |
...
|
mxkefu6a.exe | 173 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00416A09, 0x00415F2F, ... |
![]() |
![]() |
...
|
mxkefu6a.exe | 173 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004048D4 |
![]() |
![]() |
...
|
mxkefu6a.exe | 173 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040C3C0, 0x004112CE |
![]() |
![]() |
...
|
mxkefu6a.exe | 173 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004020F0 |
![]() |
![]() |
...
|
mxkefu6a.exe | 173 | 0x00400000 | 0x00476FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
mxkefu6a.exe | 198 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004080C0 |
![]() |
![]() |
...
|
mxkefu6a.exe | 198 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040AE73 |
![]() |
![]() |
...
|
mxkefu6a.exe | 198 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040579A |
![]() |
![]() |
...
|
mxkefu6a.exe | 198 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040B435 |
![]() |
![]() |
...
|
mxkefu6a.exe | 198 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00409AC9 |
![]() |
![]() |
...
|
mxkefu6a.exe | 198 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00406078 |
![]() |
![]() |
...
|
mxkefu6a.exe | 198 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040DEC6 |
![]() |
![]() |
...
|
mxkefu6a.exe | 198 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00410AB1 |
![]() |
![]() |
...
|
mxkefu6a.exe | 198 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00412434 |
![]() |
![]() |
...
|
mxkefu6a.exe | 198 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x00416A09, 0x00415F2F, ... |
![]() |
![]() |
...
|
mxkefu6a.exe | 198 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004048D4 |
![]() |
![]() |
...
|
mxkefu6a.exe | 198 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x0040C3C0, 0x004112CE |
![]() |
![]() |
...
|
mxkefu6a.exe | 198 | 0x00400000 | 0x00476FFF | Content Changed | - | 32-bit | 0x004020F0 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.40672878 |
Malicious
|
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\storage\permanent\chrome\idb\2918063365piupsah.sqlite | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\webappsstore.sqlite | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\K1x_a5kN_6Xhy9ntGym\43GhgeoJ1r.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\rmiregistry.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\optimize_poster.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\javacpl.cpl | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.79\Installer\chrome.7z | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\ZOJs8SfeUiV.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaTypewriterRegular.ttf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\IDTemplates\ENU\DefaultID.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\edit_pdf_poster.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\cmm\PYCC.pf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\pack200.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\content-types.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\eapzhiWZ.vbs | Dropped File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\!SDEN_INFO!.rtf | Dropped File | Text |
Unknown
|
...
|
»
RTF Information
»
Document Content Snippet
»
HOW TO RECOVER YOUR FILES? WE HAVE TO INFORM YOU THAT ALL YOUR FILES WERE ENCRYPTED! PLEASE BE SURE THAT YOUR FILES ARE NOT BROKEN! Your files were encrypted with AES-128+RSA-2048 crypto algorithms. * Please note that there is no way to decrypt your files without unique decryption key and special software. Your unique decryption key is securely stored on our server. * Please note that all the attempts to recover your files by yourself or using third party tools will result only in irrevocable loss of your data! * Please note that you can recover files only with your unique decryption key, which stored on our server. HOW TO RECOVER FILES? Please write us to the e-mail, we will send you instruction how to recover your data. Our main e-mail: SmartDen@protonmail.com Our secondary e-mail: b SmartDen@tutanota.com Our secondary e-mail: b SmartDen@india.com Please write to our main e-mail. If you will not receive answer in 24 hours, please write to our secondary e-mails ... |
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\content-prefs.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\cookies.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Outlook Files\kkcie@kdj.kd.pst | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\MDvWkEoF\nelwiEjV5ko739u\irP-_lJVXPj FWZ6iyYJ\Z_PSSxHcDpT\ZBNeq\HRt9zX--uxTxj7rs8.xls | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Vw9 cNao_kB.doc | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\PDFSigQFormalRep.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\ivYTDOP.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\edit_pdf_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\scan_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\organize_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\q1N9.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\previews_opt_out.db | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\K1x_a5kN_6Xhy9ntGym\PWEP9ZZOb dHlAYjsy\Kw9XQh.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x64.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\cert8.db | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\permissions.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\6HQBe1Id.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\wx1gKcZ ARkXbsEtQ26.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\MDvWkEoF\JXIUqqf 3E1.odt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\key3.db | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\sample-files\assets\Sample Files\Adobe Sign White Paper.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\secmod.db | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\MediaDb.v1.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\Annotations\Stamps\ENU\SignHere.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\MDvWkEoF\nelwiEjV5ko739u\irP-_lJVXPj FWZ6iyYJ\Z_PSSxHcDpT\zZn5.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Mozilla\Firefox\Profiles\w7cr0hor.default\OfflineCache\index.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Access\AccessCache.accdb | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Database1.accdb | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\optimize_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\ffjcext.zip | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\HV67.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\MDvWkEoF\nelwiEjV5ko739u\irP-_lJVXPj FWZ6iyYJ\xjYLW_hfZv1k8ab.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\MDvWkEoF\nelwiEjV5ko739u\qIJWv_cl3Fl.odt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\YFbehrau7-I.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Xp8i-yDNo1to.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\storage.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\MDvWkEoF\nelwiEjV5ko739u\irP-_lJVXPj FWZ6iyYJ\lO-5UKEm.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\N8Jr-vH1xH.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\dJ1D8WWJKN0vwRrX.xls | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\yTvQERL.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\storage\permanent\moz-safe-about+home\idb\818200132aebmoouht.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\lH729p9NvtlORqAu.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\MDvWkEoF\V4v0at7yeL46Y_CL.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\MDvWkEoF\nelwiEjV5ko739u\irP-_lJVXPj FWZ6iyYJ\Z_PSSxHcDpT\2-sCYYlXE1eIT.ods | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\IDTemplates\ENU\AdobeID.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\Annotations\Stamps\Words.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\1494870C-9912-C184-4CC9-B401-A53F4D8DE290.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Click on 'Change' to select default PDF handler.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\resources\Picture2_80.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\combine_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\combine_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Welcome.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\sample-files\assets\Sample Files\Document Cloud for Government.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\combine_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\protect_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\sample-files\assets\Sample Files\Travelocity.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\organize_poster2x-dark.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\compare_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\compare_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\organize_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\compare_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\protect_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\6ZaKO22zBTdl.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\pmrx0XMNlqLx.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\redact_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\GrlY8zmzECSobnYyDGDm.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\edit_pdf_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\redact_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x86.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\compare_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\protect_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\scan_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\K1x_a5kN_6Xhy9ntGym\9YZdyXI1.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\optimize_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\preoobe.cmd | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\redact_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\favicons.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\kRUtWme.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\7 IWCWCLCExR.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\edit_pdf_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\tracked-send\images\email\dummy\adobe-old-logo.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\K1x_a5kN_6Xhy9ntGym\p4 5z.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\RGB9Rast_x86.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\scan_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\K1x_a5kN_6Xhy9ntGym\ftH86.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\RGB9RAST_x64.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\DHtmlHeader.html | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\SetupComplete.cmd | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Internet Explorer.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\HardwareEvents.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Document Building Blocks\1033\16\Built-In Building Blocks.dotx | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Setup.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\Annotations\Stamps\ENU\Dynamic.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\MDvWkEoF\nelwiEjV5ko739u\GRAD8.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\jjs.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Key Management Service.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\calendars.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\scan_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_zh_HK.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\jaccess.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\organize_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\YP-X.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\K1x_a5kN_6Xhy9ntGym\PWEP9ZZOb dHlAYjsy\p2O0.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-International%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\flavormap.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Known Folders API Service.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\orbd.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\java-rmi.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\klist.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\MDvWkEoF\nelwiEjV5ko739u\irP-_lJVXPj FWZ6iyYJ\Z_PSSxHcDpT\tmPhlv28.xls | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x86.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\unpack200.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\javafx.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\management\jmxremote.access | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Resource\ENUtxt.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx | Modified File | Compressed |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\ssvagent.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_ko.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\java.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\cmm\GRAY.pf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_it.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\ktab.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11-lic.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jfr.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\sunmscapi.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\cldrdata.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\redact_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\tnameserv.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\cmm\LINEAR_RGB.pf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_ja.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\optimize_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\4nSkn.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\K1x_a5kN_6Xhy9ntGym\PWEP9ZZOb dHlAYjsy\h5VAwW1b0gH3jYX9oE4.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\sunjce_provider.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\nashorn.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\resources.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\javaw.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaBrightRegular.ttf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\sound.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\sunec.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jfxswt.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\javacpl.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\policytool.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaBrightDemiItalic.ttf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\net.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\security\java.security | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\accessibility.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jfr\profile.jfc | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaBrightItalic.ttf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\COPYRIGHT | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\places.sqlite | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\hR6CmyF41D7GurnQ7sOc.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\GlzMlE4S.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\MDvWkEoF\nelwiEjV5ko739u\iSUyvv2-pWLpyw9zJXDb.odt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_sv.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\cmm\sRGB.pf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\management-agent.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_pt_BR.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\browser\features\clicktoplay-rollout@mozilla.org.xpi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\Annotations\Stamps\ENU\StandardBusiness.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\MDvWkEoF\qR4asBdhoH30jOJbDKW.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\browser\features\screenshots@mozilla.org.xpi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\dictionaries\en-US.aff | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\security\cacerts | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\access-bridge-64.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\organize_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\crashreporter.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\README.txt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\ALL_dmp.fldp | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\log.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\GJhtEkh2.bmp | Dropped File | Image |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\V1nQ8f0P.bat | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\c7356Qly.bat | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\bad_6088DED4F047F45E.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\bad_6088DED4F047F45E.txt | Dropped File | Text |
Not Queried
|
...
|
»
39ac1a828602e9dbc4dbf0ba68a4a570d85e9bf6b5ed1f3ed4a5370778a7ca7d | Downloaded File | Stream |
Not Queried
|
...
|
»
bf6c66a68ea83b7a54e7fa4654426830417b3573c7feaaa9489dff71565b7bed | Downloaded File | Text |
Not Queried
|
...
|
»
ebf3e7290b8fd1e5509caa69335251f22b61baf3f9ff87b4e8544f3c1fea279d | Downloaded File | Unknown |
Not Queried
|
...
|
»