VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Spyware
|
Threat Names: |
Gen:Variant.Doris.6643
|
build.exe
Windows Exe (x86-32)
Created at 2020-11-11T08:42:00
Remarks
(0x0200001E): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\build.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4014a0 |
Size Of Code | 0x73200 |
Size Of Initialized Data | 0x78200 |
Size Of Uninitialized Data | 0x600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-11-11 07:13:37+00:00 |
Sections (15)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x73044 | 0x73200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.44 |
.data | 0x475000 | 0x70 | 0x200 | 0x73600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.23 |
.rdata | 0x476000 | 0xa20 | 0xc00 | 0x73800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ | 5.51 |
/4 | 0x477000 | 0x300 | 0x400 | 0x74400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.68 |
.bss | 0x478000 | 0x49c | 0x0 | 0x0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.idata | 0x479000 | 0xb44 | 0xc00 | 0x74800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.0 |
.CRT | 0x47a000 | 0x34 | 0x200 | 0x75400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.26 |
.tls | 0x47b000 | 0x8 | 0x200 | 0x75600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
/14 | 0x47c000 | 0x58 | 0x200 | 0x75800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.36 |
/29 | 0x47d000 | 0x1fbb | 0x2000 | 0x75a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.89 |
/41 | 0x47f000 | 0x15d | 0x200 | 0x77a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 3.45 |
/55 | 0x480000 | 0x2a0 | 0x400 | 0x77c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 3.73 |
/67 | 0x481000 | 0x64 | 0x200 | 0x78000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 1.1 |
/80 | 0x482000 | 0x130 | 0x200 | 0x78200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 3.77 |
.rsrc | 0x483000 | 0x1b4 | 0x200 | 0x78400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.11 |
Imports (7)
»
KERNEL32.dll (52)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseHandle | 0x0 | 0x479228 | 0x790a0 | 0x748a0 | 0x54 |
CreateFileW | 0x0 | 0x47922c | 0x790a4 | 0x748a4 | 0x94 |
CreateIoCompletionPort | 0x0 | 0x479230 | 0x790a8 | 0x748a8 | 0x99 |
CreateThread | 0x0 | 0x479234 | 0x790ac | 0x748ac | 0xba |
DeleteCriticalSection | 0x0 | 0x479238 | 0x790b0 | 0x748b0 | 0xd7 |
EnterCriticalSection | 0x0 | 0x47923c | 0x790b4 | 0x748b4 | 0xf3 |
FindClose | 0x0 | 0x479240 | 0x790b8 | 0x748b8 | 0x134 |
FindFirstFileW | 0x0 | 0x479244 | 0x790bc | 0x748bc | 0x13f |
FindFirstVolumeW | 0x0 | 0x479248 | 0x790c0 | 0x748c0 | 0x145 |
FindNextFileW | 0x0 | 0x47924c | 0x790c4 | 0x748c4 | 0x14b |
FindNextVolumeW | 0x0 | 0x479250 | 0x790c8 | 0x748c8 | 0x150 |
FindVolumeClose | 0x0 | 0x479254 | 0x790cc | 0x748cc | 0x156 |
GetCurrentProcess | 0x0 | 0x479258 | 0x790d0 | 0x748d0 | 0x1c8 |
GetCurrentProcessId | 0x0 | 0x47925c | 0x790d4 | 0x748d4 | 0x1c9 |
GetCurrentThreadId | 0x0 | 0x479260 | 0x790d8 | 0x748d8 | 0x1cd |
GetDriveTypeW | 0x0 | 0x479264 | 0x790dc | 0x748dc | 0x1db |
GetFileSizeEx | 0x0 | 0x479268 | 0x790e0 | 0x748e0 | 0x1f6 |
GetLastError | 0x0 | 0x47926c | 0x790e4 | 0x748e4 | 0x207 |
GetLogicalDrives | 0x0 | 0x479270 | 0x790e8 | 0x748e8 | 0x20e |
GetModuleHandleA | 0x0 | 0x479274 | 0x790ec | 0x748ec | 0x219 |
GetProcAddress | 0x0 | 0x479278 | 0x790f0 | 0x748f0 | 0x249 |
GetProcessHeap | 0x0 | 0x47927c | 0x790f4 | 0x748f4 | 0x24e |
GetQueuedCompletionStatus | 0x0 | 0x479280 | 0x790f8 | 0x748f8 | 0x264 |
GetStartupInfoA | 0x0 | 0x479284 | 0x790fc | 0x748fc | 0x268 |
GetSystemInfo | 0x0 | 0x479288 | 0x79100 | 0x74900 | 0x279 |
GetSystemTimeAsFileTime | 0x0 | 0x47928c | 0x79104 | 0x74904 | 0x27f |
GetTickCount | 0x0 | 0x479290 | 0x79108 | 0x74908 | 0x29b |
GetVolumePathNamesForVolumeNameW | 0x0 | 0x479294 | 0x7910c | 0x7490c | 0x2b4 |
HeapAlloc | 0x0 | 0x479298 | 0x79110 | 0x74910 | 0x2d4 |
HeapFree | 0x0 | 0x47929c | 0x79114 | 0x74914 | 0x2da |
InitializeCriticalSection | 0x0 | 0x4792a0 | 0x79118 | 0x74918 | 0x2ef |
LeaveCriticalSection | 0x0 | 0x4792a4 | 0x7911c | 0x7491c | 0x345 |
LoadLibraryA | 0x0 | 0x4792a8 | 0x79120 | 0x74920 | 0x348 |
MoveFileW | 0x0 | 0x4792ac | 0x79124 | 0x74924 | 0x371 |
PostQueuedCompletionStatus | 0x0 | 0x4792b0 | 0x79128 | 0x74928 | 0x39c |
QueryPerformanceCounter | 0x0 | 0x4792b4 | 0x7912c | 0x7492c | 0x3b6 |
ReadFile | 0x0 | 0x4792b8 | 0x79130 | 0x74930 | 0x3d0 |
SetUnhandledExceptionFilter | 0x0 | 0x4792bc | 0x79134 | 0x74934 | 0x48c |
SetVolumeMountPointW | 0x0 | 0x4792c0 | 0x79138 | 0x74938 | 0x492 |
Sleep | 0x0 | 0x4792c4 | 0x7913c | 0x7493c | 0x499 |
TerminateProcess | 0x0 | 0x4792c8 | 0x79140 | 0x74940 | 0x4a7 |
TlsGetValue | 0x0 | 0x4792cc | 0x79144 | 0x74944 | 0x4ae |
UnhandledExceptionFilter | 0x0 | 0x4792d0 | 0x79148 | 0x74948 | 0x4bb |
VirtualProtect | 0x0 | 0x4792d4 | 0x7914c | 0x7494c | 0x4dc |
VirtualQuery | 0x0 | 0x4792d8 | 0x79150 | 0x74950 | 0x4df |
WriteFile | 0x0 | 0x4792dc | 0x79154 | 0x74954 | 0x514 |
lstrcatW | 0x0 | 0x4792e0 | 0x79158 | 0x74958 | 0x530 |
lstrcmpW | 0x0 | 0x4792e4 | 0x7915c | 0x7495c | 0x533 |
lstrcmpiW | 0x0 | 0x4792e8 | 0x79160 | 0x74960 | 0x536 |
lstrcpyW | 0x0 | 0x4792ec | 0x79164 | 0x74964 | 0x539 |
lstrlenA | 0x0 | 0x4792f0 | 0x79168 | 0x74968 | 0x53e |
lstrlenW | 0x0 | 0x4792f4 | 0x7916c | 0x7496c | 0x53f |
MPR.DLL (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetAddConnection2W | 0x0 | 0x4792fc | 0x79174 | 0x74974 | 0x5 |
WNetCloseEnum | 0x0 | 0x479300 | 0x79178 | 0x74978 | 0xf |
WNetEnumResourceW | 0x0 | 0x479304 | 0x7917c | 0x7497c | 0x1b |
WNetGetConnectionW | 0x0 | 0x479308 | 0x79180 | 0x74980 | 0x24 |
WNetOpenEnumW | 0x0 | 0x47930c | 0x79184 | 0x74984 | 0x3b |
msvcrt.dll (27)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
__getmainargs | 0x0 | 0x479314 | 0x7918c | 0x7498c | 0x3b |
__initenv | 0x0 | 0x479318 | 0x79190 | 0x74990 | 0x3c |
__lconv_init | 0x0 | 0x47931c | 0x79194 | 0x74994 | 0x45 |
__p__acmdln | 0x0 | 0x479320 | 0x79198 | 0x74998 | 0x4d |
__p__fmode | 0x0 | 0x479324 | 0x7919c | 0x7499c | 0x54 |
__set_app_type | 0x0 | 0x479328 | 0x791a0 | 0x749a0 | 0x69 |
__setusermatherr | 0x0 | 0x47932c | 0x791a4 | 0x749a4 | 0x6c |
_amsg_exit | 0x0 | 0x479330 | 0x791a8 | 0x749a8 | 0x91 |
_cexit | 0x0 | 0x479334 | 0x791ac | 0x749ac | 0xa2 |
_fmode | 0x0 | 0x479338 | 0x791b0 | 0x749b0 | 0x114 |
_fpreset | 0x0 | 0x47933c | 0x791b4 | 0x749b4 | 0x118 |
_initterm | 0x0 | 0x479340 | 0x791b8 | 0x749b8 | 0x160 |
_iob | 0x0 | 0x479344 | 0x791bc | 0x749bc | 0x164 |
_onexit | 0x0 | 0x479348 | 0x791c0 | 0x749c0 | 0x274 |
abort | 0x0 | 0x47934c | 0x791c4 | 0x749c4 | 0x421 |
calloc | 0x0 | 0x479350 | 0x791c8 | 0x749c8 | 0x42e |
exit | 0x0 | 0x479354 | 0x791cc | 0x749cc | 0x439 |
fprintf | 0x0 | 0x479358 | 0x791d0 | 0x749d0 | 0x449 |
free | 0x0 | 0x47935c | 0x791d4 | 0x749d4 | 0x450 |
fwrite | 0x0 | 0x479360 | 0x791d8 | 0x749d8 | 0x45c |
malloc | 0x0 | 0x479364 | 0x791dc | 0x749dc | 0x48b |
memcpy | 0x0 | 0x479368 | 0x791e0 | 0x749e0 | 0x494 |
memset | 0x0 | 0x47936c | 0x791e4 | 0x749e4 | 0x496 |
signal | 0x0 | 0x479370 | 0x791e8 | 0x749e8 | 0x4af |
strlen | 0x0 | 0x479374 | 0x791ec | 0x749ec | 0x4c3 |
strncmp | 0x0 | 0x479378 | 0x791f0 | 0x749f0 | 0x4c6 |
vfprintf | 0x0 | 0x47937c | 0x791f4 | 0x749f4 | 0x4e5 |
ole32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoCreateInstance | 0x0 | 0x479384 | 0x791fc | 0x749fc | 0x11 |
CoSetProxyBlanket | 0x0 | 0x479388 | 0x79200 | 0x74a00 | 0x66 |
OLEAUT32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VariantClear | 0x0 | 0x479390 | 0x79208 | 0x74a08 | 0x19d |
VariantInit | 0x0 | 0x479394 | 0x7920c | 0x74a0c | 0x1a0 |
SHLWAPI.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathFindExtensionW | 0x0 | 0x47939c | 0x79214 | 0x74a14 | 0x48 |
wnsprintfW | 0x0 | 0x4793a0 | 0x79218 | 0x74a18 | 0x16f |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
wsprintfW | 0x0 | 0x4793a8 | 0x79220 | 0x74a20 | 0x391 |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
build.exe | 1 | 0x00400000 | 0x00483FFF | Relevant Image | 32-bit | 0x00472EC8 |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Doris.6643 |
Malicious
|
\\?\C:\Boot\BOOTSTAT.DAT.1F1099844B0C5543F89C7611B74A8C756CAA2BE094D2FBE0ABA2373110A1A472 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.98D1BC21EF9A3E7EFA4C3E2881BACAC451E39C92519040370209AD073CB1B064 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi.D2F89B88F60A38DBB9E173DD367F358E3241F7DA5DEAE642AD8D38C248CD061F | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.58424D39F844C75282A2D4840087DCAF6D016469CBFAD8011773D4010C4A2D70 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.4C02D112E361038FA83F489F73164CAC8A31099B82CE51224F781910D54F4350 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.91B941EC74D52657EAB3583F8ACD962EC43EDD5D9E523DAF019ABE4C22716D2D | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.03A865DC3D972F27F40F2B5A905B8C0928593D029948DC4B2E03145E0B804466 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.31B339472961389901478D63967E174BCEC5B4DD3EB88AE832D898F76440AB5D | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.40D1DECB85534CBCC3463AA7F3800CC6676E53783C6FA026199EEA0C81E1A16C | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.3E6F36F71A1BB941387EC8150403467649F2FDE7ABCD9DB565C27BF17BF8836F | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi.52A3557A29814C2582DDE920DC4E0759058361826811D9FB65502B7112C2F205 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab.B78B11BA6862AD7EE870C4B1E8E88D95FCE592EBDAAC319D765C7B7B92AA0922 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.EC916CD03B485B53124342DF0B828FDC6D890B1C21B27626AE7DADBB84B6496C | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab.357AC7E0B4128AA32C597EE125DC86AF9877272761856801E897150DD0F56962 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.FAF80DE710AB7EF892B2FD7C43D028664AF89DB76344EA6A36C0480BA782CC6F | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.cab | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.160A0CAAEF59F2FC0E1E0DCB9ACFCB736A62AA7D3EC982B1E05FCA30DD5CD512 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.msi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi.41A0E30146711B387E0A8ACE38C3E843348E864300EE3E06C86B558C24B74524 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.cab | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfLR.cab | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi.EF2AD8F334BDF147D9C8DB9C0F30E12B2E50049C2A3F7B6D8FE265A527CCD811 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\OWOW32LR.cab | Modified File | Stream |
Unknown
|
...
|
»