VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Wiper, Ransomware, Dropper, Exploit |
greencrypt_crypt.exe
Windows Exe (x86-32)
Created at 2019-06-21T19:01:00
Remarks
(0x200001e): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\greencrypt_crypt.exe | Sample File | Binary |
Blacklisted
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-06-21 20:37 (UTC+2) |
Last Seen | 2019-06-21 20:42 (UTC+2) |
Names | Win32.Exploit.R276720 |
Families | R276720 |
Classification | Exploit |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x403328 |
Size Of Code | 0x6200 |
Size Of Initialized Data | 0x1d000 |
Size Of Uninitialized Data | 0x400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-12-15 22:24:32+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x6077 | 0x6200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.4 |
.rdata | 0x408000 | 0x1250 | 0x1400 | 0x6600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.04 |
.data | 0x40a000 | 0x1a838 | 0x400 | 0x7a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.22 |
.ndata | 0x425000 | 0x8000 | 0x0 | 0x0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x42d000 | 0xc30 | 0xe00 | 0x7e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.05 |
Imports (7)
»
KERNEL32.dll (61)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetEnvironmentVariableA | 0x0 | 0x408070 | 0x8540 | 0x6b40 | 0x313 |
CreateFileA | 0x0 | 0x408074 | 0x8544 | 0x6b44 | 0x53 |
GetFileSize | 0x0 | 0x408078 | 0x8548 | 0x6b48 | 0x163 |
GetModuleFileNameA | 0x0 | 0x40807c | 0x854c | 0x6b4c | 0x17d |
ReadFile | 0x0 | 0x408080 | 0x8550 | 0x6b50 | 0x2b5 |
GetCurrentProcess | 0x0 | 0x408084 | 0x8554 | 0x6b54 | 0x142 |
CopyFileA | 0x0 | 0x408088 | 0x8558 | 0x6b58 | 0x43 |
Sleep | 0x0 | 0x40808c | 0x855c | 0x6b5c | 0x356 |
GetTickCount | 0x0 | 0x408090 | 0x8560 | 0x6b60 | 0x1df |
GetWindowsDirectoryA | 0x0 | 0x408094 | 0x8564 | 0x6b64 | 0x1f3 |
GetTempPathA | 0x0 | 0x408098 | 0x8568 | 0x6b68 | 0x1d5 |
GetCommandLineA | 0x0 | 0x40809c | 0x856c | 0x6b6c | 0x110 |
lstrlenA | 0x0 | 0x4080a0 | 0x8570 | 0x6b70 | 0x3cc |
GetVersion | 0x0 | 0x4080a4 | 0x8574 | 0x6b74 | 0x1e8 |
SetErrorMode | 0x0 | 0x4080a8 | 0x8578 | 0x6b78 | 0x315 |
lstrcpynA | 0x0 | 0x4080ac | 0x857c | 0x6b7c | 0x3c9 |
ExitProcess | 0x0 | 0x4080b0 | 0x8580 | 0x6b80 | 0xb9 |
SetCurrentDirectoryA | 0x0 | 0x4080b4 | 0x8584 | 0x6b84 | 0x30a |
GlobalLock | 0x0 | 0x4080b8 | 0x8588 | 0x6b88 | 0x203 |
CreateThread | 0x0 | 0x4080bc | 0x858c | 0x6b8c | 0x6f |
GetLastError | 0x0 | 0x4080c0 | 0x8590 | 0x6b90 | 0x171 |
CreateDirectoryA | 0x0 | 0x4080c4 | 0x8594 | 0x6b94 | 0x4b |
CreateProcessA | 0x0 | 0x4080c8 | 0x8598 | 0x6b98 | 0x66 |
RemoveDirectoryA | 0x0 | 0x4080cc | 0x859c | 0x6b9c | 0x2c4 |
GetTempFileNameA | 0x0 | 0x4080d0 | 0x85a0 | 0x6ba0 | 0x1d3 |
WriteFile | 0x0 | 0x4080d4 | 0x85a4 | 0x6ba4 | 0x3a4 |
lstrcpyA | 0x0 | 0x4080d8 | 0x85a8 | 0x6ba8 | 0x3c6 |
MoveFileExA | 0x0 | 0x4080dc | 0x85ac | 0x6bac | 0x26f |
lstrcatA | 0x0 | 0x4080e0 | 0x85b0 | 0x6bb0 | 0x3bd |
GetSystemDirectoryA | 0x0 | 0x4080e4 | 0x85b4 | 0x6bb4 | 0x1c1 |
GetProcAddress | 0x0 | 0x4080e8 | 0x85b8 | 0x6bb8 | 0x1a0 |
GetExitCodeProcess | 0x0 | 0x4080ec | 0x85bc | 0x6bbc | 0x15a |
WaitForSingleObject | 0x0 | 0x4080f0 | 0x85c0 | 0x6bc0 | 0x390 |
CompareFileTime | 0x0 | 0x4080f4 | 0x85c4 | 0x6bc4 | 0x39 |
SetFileAttributesA | 0x0 | 0x4080f8 | 0x85c8 | 0x6bc8 | 0x319 |
GetFileAttributesA | 0x0 | 0x4080fc | 0x85cc | 0x6bcc | 0x15e |
GetShortPathNameA | 0x0 | 0x408100 | 0x85d0 | 0x6bd0 | 0x1b5 |
MoveFileA | 0x0 | 0x408104 | 0x85d4 | 0x6bd4 | 0x26e |
GetFullPathNameA | 0x0 | 0x408108 | 0x85d8 | 0x6bd8 | 0x169 |
SetFileTime | 0x0 | 0x40810c | 0x85dc | 0x6bdc | 0x31f |
SearchPathA | 0x0 | 0x408110 | 0x85e0 | 0x6be0 | 0x2db |
CloseHandle | 0x0 | 0x408114 | 0x85e4 | 0x6be4 | 0x34 |
lstrcmpiA | 0x0 | 0x408118 | 0x85e8 | 0x6be8 | 0x3c3 |
GlobalUnlock | 0x0 | 0x40811c | 0x85ec | 0x6bec | 0x20a |
GetDiskFreeSpaceA | 0x0 | 0x408120 | 0x85f0 | 0x6bf0 | 0x14d |
lstrcmpA | 0x0 | 0x408124 | 0x85f4 | 0x6bf4 | 0x3c0 |
FindFirstFileA | 0x0 | 0x408128 | 0x85f8 | 0x6bf8 | 0xd2 |
FindNextFileA | 0x0 | 0x40812c | 0x85fc | 0x6bfc | 0xdc |
DeleteFileA | 0x0 | 0x408130 | 0x8600 | 0x6c00 | 0x83 |
SetFilePointer | 0x0 | 0x408134 | 0x8604 | 0x6c04 | 0x31b |
GetPrivateProfileStringA | 0x0 | 0x408138 | 0x8608 | 0x6c08 | 0x19c |
FindClose | 0x0 | 0x40813c | 0x860c | 0x6c0c | 0xce |
MultiByteToWideChar | 0x0 | 0x408140 | 0x8610 | 0x6c10 | 0x275 |
FreeLibrary | 0x0 | 0x408144 | 0x8614 | 0x6c14 | 0xf8 |
MulDiv | 0x0 | 0x408148 | 0x8618 | 0x6c18 | 0x274 |
WritePrivateProfileStringA | 0x0 | 0x40814c | 0x861c | 0x6c1c | 0x3a9 |
LoadLibraryExA | 0x0 | 0x408150 | 0x8620 | 0x6c20 | 0x253 |
GetModuleHandleA | 0x0 | 0x408154 | 0x8624 | 0x6c24 | 0x17f |
GlobalAlloc | 0x0 | 0x408158 | 0x8628 | 0x6c28 | 0x1f8 |
GlobalFree | 0x0 | 0x40815c | 0x862c | 0x6c2c | 0x1ff |
ExpandEnvironmentStringsA | 0x0 | 0x408160 | 0x8630 | 0x6c30 | 0xbc |
USER32.dll (63)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ScreenToClient | 0x0 | 0x408184 | 0x8654 | 0x6c54 | 0x231 |
GetSystemMenu | 0x0 | 0x408188 | 0x8658 | 0x6c58 | 0x15c |
SetClassLongA | 0x0 | 0x40818c | 0x865c | 0x6c5c | 0x247 |
IsWindowEnabled | 0x0 | 0x408190 | 0x8660 | 0x6c60 | 0x1ae |
SetWindowPos | 0x0 | 0x408194 | 0x8664 | 0x6c64 | 0x283 |
GetSysColor | 0x0 | 0x408198 | 0x8668 | 0x6c68 | 0x15a |
GetWindowLongA | 0x0 | 0x40819c | 0x866c | 0x6c6c | 0x16e |
SetCursor | 0x0 | 0x4081a0 | 0x8670 | 0x6c70 | 0x24d |
LoadCursorA | 0x0 | 0x4081a4 | 0x8674 | 0x6c74 | 0x1ba |
CheckDlgButton | 0x0 | 0x4081a8 | 0x8678 | 0x6c78 | 0x38 |
GetMessagePos | 0x0 | 0x4081ac | 0x867c | 0x6c7c | 0x13c |
LoadBitmapA | 0x0 | 0x4081b0 | 0x8680 | 0x6c80 | 0x1b8 |
CallWindowProcA | 0x0 | 0x4081b4 | 0x8684 | 0x6c84 | 0x1b |
IsWindowVisible | 0x0 | 0x4081b8 | 0x8688 | 0x6c88 | 0x1b1 |
CloseClipboard | 0x0 | 0x4081bc | 0x868c | 0x6c8c | 0x42 |
SetClipboardData | 0x0 | 0x4081c0 | 0x8690 | 0x6c90 | 0x24a |
EmptyClipboard | 0x0 | 0x4081c4 | 0x8694 | 0x6c94 | 0xc1 |
PostQuitMessage | 0x0 | 0x4081c8 | 0x8698 | 0x6c98 | 0x204 |
GetWindowRect | 0x0 | 0x4081cc | 0x869c | 0x6c9c | 0x174 |
EnableMenuItem | 0x0 | 0x4081d0 | 0x86a0 | 0x6ca0 | 0xc2 |
CreatePopupMenu | 0x0 | 0x4081d4 | 0x86a4 | 0x6ca4 | 0x5e |
GetSystemMetrics | 0x0 | 0x4081d8 | 0x86a8 | 0x6ca8 | 0x15d |
SetDlgItemTextA | 0x0 | 0x4081dc | 0x86ac | 0x6cac | 0x253 |
GetDlgItemTextA | 0x0 | 0x4081e0 | 0x86b0 | 0x6cb0 | 0x113 |
MessageBoxIndirectA | 0x0 | 0x4081e4 | 0x86b4 | 0x6cb4 | 0x1e2 |
CharPrevA | 0x0 | 0x4081e8 | 0x86b8 | 0x6cb8 | 0x2d |
DispatchMessageA | 0x0 | 0x4081ec | 0x86bc | 0x6cbc | 0xa1 |
PeekMessageA | 0x0 | 0x4081f0 | 0x86c0 | 0x6cc0 | 0x200 |
ReleaseDC | 0x0 | 0x4081f4 | 0x86c4 | 0x6cc4 | 0x22a |
EnableWindow | 0x0 | 0x4081f8 | 0x86c8 | 0x6cc8 | 0xc4 |
InvalidateRect | 0x0 | 0x4081fc | 0x86cc | 0x6ccc | 0x193 |
SendMessageA | 0x0 | 0x408200 | 0x86d0 | 0x6cd0 | 0x23b |
DefWindowProcA | 0x0 | 0x408204 | 0x86d4 | 0x6cd4 | 0x8e |
BeginPaint | 0x0 | 0x408208 | 0x86d8 | 0x6cd8 | 0xd |
GetClientRect | 0x0 | 0x40820c | 0x86dc | 0x6cdc | 0xff |
FillRect | 0x0 | 0x408210 | 0x86e0 | 0x6ce0 | 0xe2 |
DrawTextA | 0x0 | 0x408214 | 0x86e4 | 0x6ce4 | 0xbc |
EndDialog | 0x0 | 0x408218 | 0x86e8 | 0x6ce8 | 0xc6 |
RegisterClassA | 0x0 | 0x40821c | 0x86ec | 0x6cec | 0x216 |
SystemParametersInfoA | 0x0 | 0x408220 | 0x86f0 | 0x6cf0 | 0x299 |
CreateWindowExA | 0x0 | 0x408224 | 0x86f4 | 0x6cf4 | 0x60 |
GetClassInfoA | 0x0 | 0x408228 | 0x86f8 | 0x6cf8 | 0xf6 |
DialogBoxParamA | 0x0 | 0x40822c | 0x86fc | 0x6cfc | 0x9e |
CharNextA | 0x0 | 0x408230 | 0x8700 | 0x6d00 | 0x2a |
ExitWindowsEx | 0x0 | 0x408234 | 0x8704 | 0x6d04 | 0xe1 |
GetDC | 0x0 | 0x408238 | 0x8708 | 0x6d08 | 0x10c |
CreateDialogParamA | 0x0 | 0x40823c | 0x870c | 0x6d0c | 0x55 |
SetTimer | 0x0 | 0x408240 | 0x8710 | 0x6d10 | 0x27a |
GetDlgItem | 0x0 | 0x408244 | 0x8714 | 0x6d14 | 0x111 |
SetWindowLongA | 0x0 | 0x408248 | 0x8718 | 0x6d18 | 0x280 |
SetForegroundWindow | 0x0 | 0x40824c | 0x871c | 0x6d1c | 0x257 |
LoadImageA | 0x0 | 0x408250 | 0x8720 | 0x6d20 | 0x1c0 |
IsWindow | 0x0 | 0x408254 | 0x8724 | 0x6d24 | 0x1ad |
SendMessageTimeoutA | 0x0 | 0x408258 | 0x8728 | 0x6d28 | 0x23e |
FindWindowExA | 0x0 | 0x40825c | 0x872c | 0x6d2c | 0xe4 |
OpenClipboard | 0x0 | 0x408260 | 0x8730 | 0x6d30 | 0x1f6 |
TrackPopupMenu | 0x0 | 0x408264 | 0x8734 | 0x6d34 | 0x2a4 |
AppendMenuA | 0x0 | 0x408268 | 0x8738 | 0x6d38 | 0x8 |
EndPaint | 0x0 | 0x40826c | 0x873c | 0x6d3c | 0xc8 |
DestroyWindow | 0x0 | 0x408270 | 0x8740 | 0x6d40 | 0x99 |
wsprintfA | 0x0 | 0x408274 | 0x8744 | 0x6d44 | 0x2d7 |
ShowWindow | 0x0 | 0x408278 | 0x8748 | 0x6d48 | 0x292 |
SetWindowTextA | 0x0 | 0x40827c | 0x874c | 0x6d4c | 0x286 |
GDI32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SelectObject | 0x0 | 0x40804c | 0x851c | 0x6b1c | 0x20e |
SetBkMode | 0x0 | 0x408050 | 0x8520 | 0x6b20 | 0x216 |
CreateFontIndirectA | 0x0 | 0x408054 | 0x8524 | 0x6b24 | 0x3a |
SetTextColor | 0x0 | 0x408058 | 0x8528 | 0x6b28 | 0x23c |
DeleteObject | 0x0 | 0x40805c | 0x852c | 0x6b2c | 0x8f |
GetDeviceCaps | 0x0 | 0x408060 | 0x8530 | 0x6b30 | 0x16b |
CreateBrushIndirect | 0x0 | 0x408064 | 0x8534 | 0x6b34 | 0x29 |
SetBkColor | 0x0 | 0x408068 | 0x8538 | 0x6b38 | 0x215 |
SHELL32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderLocation | 0x0 | 0x408168 | 0x8638 | 0x6c38 | 0xc3 |
ShellExecuteExA | 0x0 | 0x40816c | 0x863c | 0x6c3c | 0x109 |
SHGetPathFromIDListA | 0x0 | 0x408170 | 0x8640 | 0x6c40 | 0xbc |
SHBrowseForFolderA | 0x0 | 0x408174 | 0x8644 | 0x6c44 | 0x79 |
SHGetFileInfoA | 0x0 | 0x408178 | 0x8648 | 0x6c48 | 0xac |
SHFileOperationA | 0x0 | 0x40817c | 0x864c | 0x6c4c | 0x9a |
ADVAPI32.dll (13)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
AdjustTokenPrivileges | 0x0 | 0x408000 | 0x84d0 | 0x6ad0 | 0x1c |
RegCreateKeyExA | 0x0 | 0x408004 | 0x84d4 | 0x6ad4 | 0x1d1 |
RegOpenKeyExA | 0x0 | 0x408008 | 0x84d8 | 0x6ad8 | 0x1ec |
SetFileSecurityA | 0x0 | 0x40800c | 0x84dc | 0x6adc | 0x22e |
OpenProcessToken | 0x0 | 0x408010 | 0x84e0 | 0x6ae0 | 0x1ac |
LookupPrivilegeValueA | 0x0 | 0x408014 | 0x84e4 | 0x6ae4 | 0x14f |
RegEnumValueA | 0x0 | 0x408018 | 0x84e8 | 0x6ae8 | 0x1e1 |
RegDeleteKeyA | 0x0 | 0x40801c | 0x84ec | 0x6aec | 0x1d4 |
RegDeleteValueA | 0x0 | 0x408020 | 0x84f0 | 0x6af0 | 0x1d8 |
RegCloseKey | 0x0 | 0x408024 | 0x84f4 | 0x6af4 | 0x1cb |
RegSetValueExA | 0x0 | 0x408028 | 0x84f8 | 0x6af8 | 0x204 |
RegQueryValueExA | 0x0 | 0x40802c | 0x84fc | 0x6afc | 0x1f7 |
RegEnumKeyA | 0x0 | 0x408030 | 0x8500 | 0x6b00 | 0x1dd |
COMCTL32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ImageList_Create | 0x0 | 0x408038 | 0x8508 | 0x6b08 | 0x37 |
ImageList_AddMasked | 0x0 | 0x40803c | 0x850c | 0x6b0c | 0x34 |
ImageList_Destroy | 0x0 | 0x408040 | 0x8510 | 0x6b10 | 0x38 |
(by ordinal) | 0x11 | 0x408044 | 0x8514 | 0x6b14 | - |
ole32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
OleUninitialize | 0x0 | 0x408284 | 0x8754 | 0x6d54 | 0x105 |
OleInitialize | 0x0 | 0x408288 | 0x8758 | 0x6d58 | 0xee |
CoTaskMemFree | 0x0 | 0x40828c | 0x875c | 0x6d5c | 0x65 |
CoCreateInstance | 0x0 | 0x408290 | 0x8760 | 0x6d60 | 0x10 |
Memory Dumps (6)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
greencrypt_crypt.exe | 1 | 0x00400000 | 0x0042DFFF | Relevant Image | - | 32-bit | - |
...
|
||
buffer | 1 | 0x003C0000 | 0x003C0FFF | First Execution | - | 32-bit | 0x003C0000 |
...
|
||
buffer | 1 | 0x03090000 | 0x03090FFF | First Execution | - | 32-bit | 0x03090855 |
...
|
||
buffer | 1 | 0x030A0000 | 0x030A6FFF | Marked Executable | - | 32-bit | 0x030A2000, 0x030A1120 |
...
|
||
buffer | 1 | 0x00300000 | 0x00308FFF | First Execution | - | 32-bit | 0x00302160, 0x00301000, ... |
...
|
||
greencrypt_crypt.exe | 1 | 0x00400000 | 0x0042DFFF | Process Termination | - | 32-bit | - |
...
|
C:\Users\5P5NRG~1\AppData\Local\Temp\nsd9703.tmp\Splash.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2018-12-17 14:37 (UTC+1) |
Last Seen | 2019-04-09 17:20 (UTC+2) |
PE Information
»
Image Base | 0x10000000 |
Entry Point | 0x10001000 |
Size Of Code | 0x400 |
Size Of Initialized Data | 0x800 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-12-15 22:23:44+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x10001000 | 0x3bb | 0x400 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.48 |
.rdata | 0x10002000 | 0x3c2 | 0x400 | 0x800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.59 |
.data | 0x10003000 | 0x5c | 0x200 | 0xc00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.32 |
.reloc | 0x10004000 | 0x120 | 0x200 | 0xe00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 2.08 |
Imports (4)
»
KERNEL32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GlobalAlloc | 0x0 | 0x1000201c | 0x210c | 0x90c | 0x1f8 |
GlobalFree | 0x0 | 0x10002020 | 0x2110 | 0x910 | 0x1ff |
lstrcpynA | 0x0 | 0x10002024 | 0x2114 | 0x914 | 0x3c9 |
lstrcpyA | 0x0 | 0x10002028 | 0x2118 | 0x918 | 0x3c6 |
lstrcatA | 0x0 | 0x1000202c | 0x211c | 0x91c | 0x3bd |
USER32.dll (19)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegisterClassA | 0x0 | 0x10002034 | 0x2124 | 0x924 | 0x216 |
LoadImageA | 0x0 | 0x10002038 | 0x2128 | 0x928 | 0x1c0 |
CreateWindowExA | 0x0 | 0x1000203c | 0x212c | 0x92c | 0x60 |
SetTimer | 0x0 | 0x10002040 | 0x2130 | 0x930 | 0x27a |
EndPaint | 0x0 | 0x10002044 | 0x2134 | 0x934 | 0xc8 |
GetClientRect | 0x0 | 0x10002048 | 0x2138 | 0x938 | 0xff |
BeginPaint | 0x0 | 0x1000204c | 0x213c | 0x93c | 0xd |
IsWindow | 0x0 | 0x10002050 | 0x2140 | 0x940 | 0x1ad |
ShowWindow | 0x0 | 0x10002054 | 0x2144 | 0x944 | 0x292 |
SetWindowPos | 0x0 | 0x10002058 | 0x2148 | 0x948 | 0x283 |
SetWindowLongA | 0x0 | 0x1000205c | 0x214c | 0x94c | 0x280 |
SystemParametersInfoA | 0x0 | 0x10002060 | 0x2150 | 0x950 | 0x299 |
GetMessageA | 0x0 | 0x10002064 | 0x2154 | 0x954 | 0x13a |
DispatchMessageA | 0x0 | 0x10002068 | 0x2158 | 0x958 | 0xa1 |
UnregisterClassA | 0x0 | 0x1000206c | 0x215c | 0x95c | 0x2b3 |
wsprintfA | 0x0 | 0x10002070 | 0x2160 | 0x960 | 0x2d7 |
LoadCursorA | 0x0 | 0x10002074 | 0x2164 | 0x964 | 0x1ba |
DefWindowProcA | 0x0 | 0x10002078 | 0x2168 | 0x968 | 0x8e |
DestroyWindow | 0x0 | 0x1000207c | 0x216c | 0x96c | 0x99 |
GDI32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetObjectA | 0x0 | 0x10002000 | 0x20f0 | 0x8f0 | 0x195 |
CreateCompatibleDC | 0x0 | 0x10002004 | 0x20f4 | 0x8f4 | 0x2d |
DeleteDC | 0x0 | 0x10002008 | 0x20f8 | 0x8f8 | 0x8c |
BitBlt | 0x0 | 0x1000200c | 0x20fc | 0x8fc | 0x12 |
SelectObject | 0x0 | 0x10002010 | 0x2100 | 0x900 | 0x20e |
DeleteObject | 0x0 | 0x10002014 | 0x2104 | 0x904 | 0x8f |
WINMM.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PlaySoundA | 0x0 | 0x10002084 | 0x2174 | 0x974 | 0xa |
Exports (1)
»
Api name | EAT Address | Ordinal |
---|---|---|
show | 0x100f | 0x1 |
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\nslookup.exe | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-03-17 16:09 (UTC+1) |
Last Seen | 2019-04-17 13:49 (UTC+2) |
PE Information
»
Image Base | 0x1000000 |
Entry Point | 0x100cc45 |
Size Of Code | 0xec00 |
Size Of Initialized Data | 0xd600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2010-11-20 09:34:24+00:00 |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | nslookup |
FileVersion | 6.1.7601.17514 (win7sp1_rtm.101119-1850) |
InternalName | nslookup.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | nslookup.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 6.1.7601.17514 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x1001000 | 0xeb8c | 0xec00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.59 |
.data | 0x1010000 | 0xad68 | 0x6800 | 0xf000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.46 |
.rsrc | 0x101b000 | 0xd08 | 0xe00 | 0x15800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.95 |
.reloc | 0x101c000 | 0x193a | 0x1a00 | 0x16600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.31 |
Imports (8)
»
ADVAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegCloseKey | 0x0 | 0x1001000 | 0xf3b8 | 0xe7b8 | 0x230 |
KERNEL32.dll (23)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FormatMessageA | 0x0 | 0x1001014 | 0xf3cc | 0xe7cc | 0x15d |
LocalFree | 0x0 | 0x1001018 | 0xf3d0 | 0xe7d0 | 0x348 |
SetLastError | 0x0 | 0x100101c | 0xf3d4 | 0xe7d4 | 0x471 |
ExpandEnvironmentStringsA | 0x0 | 0x1001020 | 0xf3d8 | 0xe7d8 | 0x11c |
LocalAlloc | 0x0 | 0x1001024 | 0xf3dc | 0xe7dc | 0x344 |
GetLastError | 0x0 | 0x1001028 | 0xf3e0 | 0xe7e0 | 0x200 |
WaitForSingleObject | 0x0 | 0x100102c | 0xf3e4 | 0xe7e4 | 0x4f9 |
UnhandledExceptionFilter | 0x0 | 0x1001030 | 0xf3e8 | 0xe7e8 | 0x4d3 |
GetCurrentProcess | 0x0 | 0x1001034 | 0xf3ec | 0xe7ec | 0x1c0 |
TerminateProcess | 0x0 | 0x1001038 | 0xf3f0 | 0xe7f0 | 0x4c0 |
GetSystemTimeAsFileTime | 0x0 | 0x100103c | 0xf3f4 | 0xe7f4 | 0x278 |
GetCurrentProcessId | 0x0 | 0x1001040 | 0xf3f8 | 0xe7f8 | 0x1c1 |
GetCurrentThreadId | 0x0 | 0x1001044 | 0xf3fc | 0xe7fc | 0x1c5 |
GetTickCount | 0x0 | 0x1001048 | 0xf400 | 0xe800 | 0x292 |
QueryPerformanceCounter | 0x0 | 0x100104c | 0xf404 | 0xe804 | 0x3a6 |
GetModuleHandleA | 0x0 | 0x1001050 | 0xf408 | 0xe808 | 0x213 |
SetUnhandledExceptionFilter | 0x0 | 0x1001054 | 0xf40c | 0xe80c | 0x4a4 |
InterlockedCompareExchange | 0x0 | 0x1001058 | 0xf410 | 0xe810 | 0x2e9 |
Sleep | 0x0 | 0x100105c | 0xf414 | 0xe814 | 0x4b2 |
InterlockedExchange | 0x0 | 0x1001060 | 0xf418 | 0xe818 | 0x2ec |
HeapSetInformation | 0x0 | 0x1001064 | 0xf41c | 0xe81c | 0x2d3 |
SetThreadUILanguage | 0x0 | 0x1001068 | 0xf420 | 0xe820 | 0x49c |
ReleaseMutex | 0x0 | 0x100106c | 0xf424 | 0xe824 | 0x3f9 |
msvcrt.dll (49)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_controlfp | 0x0 | 0x10010cc | 0xf484 | 0xe884 | 0x127 |
_except_handler4_common | 0x0 | 0x10010d0 | 0xf488 | 0xe888 | 0x159 |
?terminate@@YAXXZ | 0x0 | 0x10010d4 | 0xf48c | 0xe88c | 0x37 |
__set_app_type | 0x0 | 0x10010d8 | 0xf490 | 0xe890 | 0xd2 |
__p__fmode | 0x0 | 0x10010dc | 0xf494 | 0xe894 | 0xbe |
__p__commode | 0x0 | 0x10010e0 | 0xf498 | 0xe898 | 0xb9 |
__setusermatherr | 0x0 | 0x10010e4 | 0xf49c | 0xe89c | 0xd4 |
perror | 0x0 | 0x10010e8 | 0xf4a0 | 0xe8a0 | 0x4f1 |
_amsg_exit | 0x0 | 0x10010ec | 0xf4a4 | 0xe8a4 | 0x101 |
_initterm | 0x0 | 0x10010f0 | 0xf4a8 | 0xe8a8 | 0x1d5 |
_XcptFilter | 0x0 | 0x10010f4 | 0xf4ac | 0xe8ac | 0x6a |
_exit | 0x0 | 0x10010f8 | 0xf4b0 | 0xe8b0 | 0x162 |
_cexit | 0x0 | 0x10010fc | 0xf4b4 | 0xe8b4 | 0x114 |
__getmainargs | 0x0 | 0x1001100 | 0xf4b8 | 0xe8b8 | 0x91 |
system | 0x0 | 0x1001104 | 0xf4bc | 0xe8bc | 0x531 |
sprintf_s | 0x0 | 0x1001108 | 0xf4c0 | 0xe8c0 | 0x50c |
putc | 0x0 | 0x100110c | 0xf4c4 | 0xe8c4 | 0x4f5 |
_write | 0x0 | 0x1001110 | 0xf4c8 | 0xe8c8 | 0x448 |
fputs | 0x0 | 0x1001114 | 0xf4cc | 0xe8cc | 0x4a2 |
fwrite | 0x0 | 0x1001118 | 0xf4d0 | 0xe8d0 | 0x4b1 |
getc | 0x0 | 0x100111c | 0xf4d4 | 0xe8d4 | 0x4b4 |
ferror | 0x0 | 0x1001120 | 0xf4d8 | 0xe8d8 | 0x494 |
fread | 0x0 | 0x1001124 | 0xf4dc | 0xe8dc | 0x4a5 |
realloc | 0x0 | 0x1001128 | 0xf4e0 | 0xe8e0 | 0x4ff |
malloc | 0x0 | 0x100112c | 0xf4e4 | 0xe8e4 | 0x4de |
fputc | 0x0 | 0x1001130 | 0xf4e8 | 0xe8e8 | 0x4a1 |
fflush | 0x0 | 0x1001134 | 0xf4ec | 0xe8ec | 0x495 |
getenv | 0x0 | 0x1001138 | 0xf4f0 | 0xe8f0 | 0x4b6 |
strcat_s | 0x0 | 0x100113c | 0xf4f4 | 0xe8f4 | 0x512 |
fopen | 0x0 | 0x1001140 | 0xf4f8 | 0xe8f8 | 0x49d |
fgets | 0x0 | 0x1001144 | 0xf4fc | 0xe8fc | 0x498 |
isspace | 0x0 | 0x1001148 | 0xf500 | 0xe900 | 0x4c6 |
strncmp | 0x0 | 0x100114c | 0xf504 | 0xe904 | 0x51f |
_strnicmp | 0x0 | 0x1001150 | 0xf508 | 0xe908 | 0x368 |
printf | 0x0 | 0x1001154 | 0xf50c | 0xe90c | 0x4f3 |
putchar | 0x0 | 0x1001158 | 0xf510 | 0xe910 | 0x4f6 |
strncpy_s | 0x0 | 0x100115c | 0xf514 | 0xe914 | 0x521 |
strchr | 0x0 | 0x1001160 | 0xf518 | 0xe918 | 0x513 |
memset | 0x0 | 0x1001164 | 0xf51c | 0xe91c | 0x4ee |
fprintf | 0x0 | 0x1001168 | 0xf520 | 0xe920 | 0x49f |
fclose | 0x0 | 0x100116c | 0xf524 | 0xe924 | 0x492 |
sscanf | 0x0 | 0x1001170 | 0xf528 | 0xe928 | 0x50f |
free | 0x0 | 0x1001174 | 0xf52c | 0xe92c | 0x4a6 |
strcpy_s | 0x0 | 0x1001178 | 0xf530 | 0xe930 | 0x517 |
_iob | 0x0 | 0x100117c | 0xf534 | 0xe934 | 0x1db |
exit | 0x0 | 0x1001180 | 0xf538 | 0xe938 | 0x48f |
_vsnprintf | 0x0 | 0x1001184 | 0xf53c | 0xe93c | 0x3c8 |
gmtime | 0x0 | 0x1001188 | 0xf540 | 0xe940 | 0x4bb |
memcpy | 0x0 | 0x100118c | 0xf544 | 0xe944 | 0x4ea |
WSOCK32.dll (16)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ord1108 | 0x454 | 0x1001088 | 0xf440 | 0xe840 | - |
htonl | 0x8 | 0x100108c | 0xf444 | 0xe844 | - |
gethostname | 0x39 | 0x1001090 | 0xf448 | 0xe848 | - |
select | 0x12 | 0x1001094 | 0xf44c | 0xe84c | - |
socket | 0x17 | 0x1001098 | 0xf450 | 0xe850 | - |
connect | 0x4 | 0x100109c | 0xf454 | 0xe854 | - |
send | 0x13 | 0x10010a0 | 0xf458 | 0xe858 | - |
recv | 0x10 | 0x10010a4 | 0xf45c | 0xe85c | - |
closesocket | 0x3 | 0x10010a8 | 0xf460 | 0xe860 | - |
ntohs | 0xf | 0x10010ac | 0xf464 | 0xe864 | - |
inet_addr | 0xb | 0x10010b0 | 0xf468 | 0xe868 | - |
getprotobynumber | 0x36 | 0x10010b4 | 0xf46c | 0xe86c | - |
htons | 0x9 | 0x10010b8 | 0xf470 | 0xe870 | - |
getservbyport | 0x38 | 0x10010bc | 0xf474 | 0xe874 | - |
WSAStartup | 0x73 | 0x10010c0 | 0xf478 | 0xe878 | - |
WSAGetLastError | 0x6f | 0x10010c4 | 0xf47c | 0xe87c | - |
WS2_32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
getaddrinfo | 0x0 | 0x100107c | 0xf434 | 0xe834 | 0x89 |
freeaddrinfo | 0x0 | 0x1001080 | 0xf438 | 0xe838 | 0x88 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CharToOemBuffA | 0x0 | 0x1001074 | 0xf42c | 0xe82c | 0x36 |
DNSAPI.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DnsQueryConfigAllocEx | 0x0 | 0x1001008 | 0xf3c0 | 0xe7c0 | 0x52 |
DnsFreeConfigStructure | 0x0 | 0x100100c | 0xf3c4 | 0xe7c4 | 0x27 |
ntdll.dll (13)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RtlIpv4StringToAddressA | 0x0 | 0x1001194 | 0xf54c | 0xe94c | 0x3c6 |
RtlIpv6AddressToStringA | 0x0 | 0x1001198 | 0xf550 | 0xe950 | 0x3ca |
RtlIpv6StringToAddressExA | 0x0 | 0x100119c | 0xf554 | 0xe954 | 0x3cf |
RtlIpv6AddressToStringExA | 0x0 | 0x10011a0 | 0xf558 | 0xe958 | 0x3cb |
RtlIpv4AddressToStringExA | 0x0 | 0x10011a4 | 0xf55c | 0xe95c | 0x3c3 |
RtlFreeUnicodeString | 0x0 | 0x10011a8 | 0xf560 | 0xe960 | 0x34d |
NtOpenKey | 0x0 | 0x10011ac | 0xf564 | 0xe964 | 0x15a |
RtlAnsiStringToUnicodeString | 0x0 | 0x10011b0 | 0xf568 | 0xe968 | 0x268 |
RtlInitString | 0x0 | 0x10011b4 | 0xf56c | 0xe96c | 0x39b |
RtlUnicodeStringToAnsiString | 0x0 | 0x10011b8 | 0xf570 | 0xe970 | 0x4c2 |
NtQueryValueKey | 0x0 | 0x10011bc | 0xf574 | 0xe974 | 0x1ae |
RtlFreeHeap | 0x0 | 0x10011c0 | 0xf578 | 0xe978 | 0x348 |
RtlAllocateHeap | 0x0 | 0x10011c4 | 0xf57c | 0xe97c | 0x263 |
C:\Users\5P5NRG~1\AppData\Local\Temp\InAppPickerConfirmationControl.xbf | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5P5NRG~1\AppData\Local\Temp\Animate_loop.64.png | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5P5NRG~1\AppData\Local\Temp\config.def | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5P5NRG~1\AppData\Local\Temp\Rhizome | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5P5NRG~1\AppData\Local\Temp\carls.dll | Dropped File | Binary |
Unknown
|
...
|
»
PE Information
»
Image Base | 0x10000000 |
Entry Point | 0x100012f0 |
Size Of Code | 0x2e00 |
Size Of Initialized Data | 0x2e00 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-06-18 03:02:51+00:00 |
Packer | Armadillo v1.xx - v2.xx |
Version Information (8)
»
CompanyName | VMware, Inc. |
FileDescription | VMware USB Arbitration Service |
FileVersion | 10. 1.14.799535 |
InternalName | vmware-usbarbitrator |
LegalCopyright | Copyright (c) 1998-2012 VMware, Inc. |
OriginalFilename | vmware-usbarbitrator.exe |
ProductName | VMware USB Arbitration Service |
ProductVersion | 9.0.0 build-799535 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x10001000 | 0x2de2 | 0x2e00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.56 |
.rdata | 0x10004000 | 0x97f | 0xa00 | 0x3200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.09 |
.data | 0x10005000 | 0x1260 | 0xa00 | 0x3c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.77 |
.rsrc | 0x10007000 | 0x858 | 0xa00 | 0x4600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.26 |
.reloc | 0x10008000 | 0x518 | 0x600 | 0x5000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.27 |
Imports (3)
»
USER32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetDesktopWindow | 0x0 | 0x100040c8 | 0x455c | 0x375c | 0x123 |
SetParent | 0x0 | 0x100040cc | 0x4560 | 0x3760 | 0x2a6 |
KERNEL32.dll (47)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
HeapCreate | 0x0 | 0x10004000 | 0x4494 | 0x3694 | 0x2cd |
SetUnhandledExceptionFilter | 0x0 | 0x10004004 | 0x4498 | 0x3698 | 0x4a5 |
GetFileInformationByHandle | 0x0 | 0x10004008 | 0x449c | 0x369c | 0x1ec |
GetCommandLineA | 0x0 | 0x1000400c | 0x44a0 | 0x36a0 | 0x186 |
GetVersion | 0x0 | 0x10004010 | 0x44a4 | 0x36a4 | 0x2a2 |
ExitProcess | 0x0 | 0x10004014 | 0x44a8 | 0x36a8 | 0x119 |
TerminateProcess | 0x0 | 0x10004018 | 0x44ac | 0x36ac | 0x4c0 |
GetCurrentProcess | 0x0 | 0x1000401c | 0x44b0 | 0x36b0 | 0x1c0 |
GetCurrentThreadId | 0x0 | 0x10004020 | 0x44b4 | 0x36b4 | 0x1c5 |
TlsSetValue | 0x0 | 0x10004024 | 0x44b8 | 0x36b8 | 0x4c8 |
TlsAlloc | 0x0 | 0x10004028 | 0x44bc | 0x36bc | 0x4c5 |
TlsFree | 0x0 | 0x1000402c | 0x44c0 | 0x36c0 | 0x4c6 |
TlsGetValue | 0x0 | 0x10004030 | 0x44c4 | 0x36c4 | 0x4c7 |
SetHandleCount | 0x0 | 0x10004034 | 0x44c8 | 0x36c8 | 0x46f |
GetStdHandle | 0x0 | 0x10004038 | 0x44cc | 0x36cc | 0x264 |
GetFileType | 0x0 | 0x1000403c | 0x44d0 | 0x36d0 | 0x1f3 |
GetStartupInfoA | 0x0 | 0x10004040 | 0x44d4 | 0x36d4 | 0x262 |
DeleteCriticalSection | 0x0 | 0x10004044 | 0x44d8 | 0x36d8 | 0xd1 |
GetModuleFileNameA | 0x0 | 0x10004048 | 0x44dc | 0x36dc | 0x213 |
FreeEnvironmentStringsA | 0x0 | 0x1000404c | 0x44e0 | 0x36e0 | 0x160 |
FreeEnvironmentStringsW | 0x0 | 0x10004050 | 0x44e4 | 0x36e4 | 0x161 |
WideCharToMultiByte | 0x0 | 0x10004054 | 0x44e8 | 0x36e8 | 0x511 |
GetEnvironmentStrings | 0x0 | 0x10004058 | 0x44ec | 0x36ec | 0x1d8 |
GetEnvironmentStringsW | 0x0 | 0x1000405c | 0x44f0 | 0x36f0 | 0x1da |
HeapDestroy | 0x0 | 0x10004060 | 0x44f4 | 0x36f4 | 0x2ce |
IsDebuggerPresent | 0x0 | 0x10004064 | 0x44f8 | 0x36f8 | 0x300 |
VirtualFree | 0x0 | 0x10004068 | 0x44fc | 0x36fc | 0x4ec |
HeapFree | 0x0 | 0x1000406c | 0x4500 | 0x3700 | 0x2cf |
WriteFile | 0x0 | 0x10004070 | 0x4504 | 0x3704 | 0x525 |
InitializeCriticalSection | 0x0 | 0x10004074 | 0x4508 | 0x3708 | 0x2e2 |
EnterCriticalSection | 0x0 | 0x10004078 | 0x450c | 0x370c | 0xee |
LeaveCriticalSection | 0x0 | 0x1000407c | 0x4510 | 0x3710 | 0x339 |
HeapAlloc | 0x0 | 0x10004080 | 0x4514 | 0x3714 | 0x2cb |
UnhandledExceptionFilter | 0x0 | 0x10004084 | 0x4518 | 0x3718 | 0x4d3 |
GetCPInfo | 0x0 | 0x10004088 | 0x451c | 0x371c | 0x172 |
GetACP | 0x0 | 0x1000408c | 0x4520 | 0x3720 | 0x168 |
GetOEMCP | 0x0 | 0x10004090 | 0x4524 | 0x3724 | 0x237 |
VirtualAlloc | 0x0 | 0x10004094 | 0x4528 | 0x3728 | 0x4e9 |
HeapReAlloc | 0x0 | 0x10004098 | 0x452c | 0x372c | 0x2d2 |
GetProcAddress | 0x0 | 0x1000409c | 0x4530 | 0x3730 | 0x245 |
LoadLibraryA | 0x0 | 0x100040a0 | 0x4534 | 0x3734 | 0x33c |
MultiByteToWideChar | 0x0 | 0x100040a4 | 0x4538 | 0x3738 | 0x367 |
LCMapStringA | 0x0 | 0x100040a8 | 0x453c | 0x373c | 0x32b |
LCMapStringW | 0x0 | 0x100040ac | 0x4540 | 0x3740 | 0x32d |
GetStringTypeA | 0x0 | 0x100040b0 | 0x4544 | 0x3744 | 0x266 |
GetStringTypeW | 0x0 | 0x100040b4 | 0x4548 | 0x3748 | 0x269 |
RtlUnwind | 0x0 | 0x100040b8 | 0x454c | 0x374c | 0x418 |
MSVCRT.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
wcscat | 0x0 | 0x100040c0 | 0x4554 | 0x3754 | 0x1fb |
Exports (2)
»
Api name | EAT Address | Ordinal |
---|---|---|
StartRemoval | 0x1040 | 0x1 |
q | 0x1090 | 0x2 |
C:\Users\5P5NRG~1\AppData\Local\Temp\nsd9703.tmp\System.dll | Dropped File | Binary |
Unknown
|
...
|
»
PE Information
»
Image Base | 0x10000000 |
Entry Point | 0x100028e1 |
Size Of Code | 0x2000 |
Size Of Initialized Data | 0xa00 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-12-15 22:23:45+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x10001000 | 0x1f4f | 0x2000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.42 |
.rdata | 0x10003000 | 0x363 | 0x400 | 0x2400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.96 |
.data | 0x10004000 | 0x68 | 0x200 | 0x2800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.35 |
.reloc | 0x10005000 | 0x27c | 0x400 | 0x2a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 3.92 |
Imports (3)
»
KERNEL32.dll (16)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MultiByteToWideChar | 0x0 | 0x10003000 | 0x30fc | 0x24fc | 0x275 |
GlobalFree | 0x0 | 0x10003004 | 0x3100 | 0x2500 | 0x1ff |
GlobalSize | 0x0 | 0x10003008 | 0x3104 | 0x2504 | 0x207 |
lstrcpynA | 0x0 | 0x1000300c | 0x3108 | 0x2508 | 0x3c9 |
lstrcpyA | 0x0 | 0x10003010 | 0x310c | 0x250c | 0x3c6 |
GetProcAddress | 0x0 | 0x10003014 | 0x3110 | 0x2510 | 0x1a0 |
VirtualFree | 0x0 | 0x10003018 | 0x3114 | 0x2514 | 0x383 |
FreeLibrary | 0x0 | 0x1000301c | 0x3118 | 0x2518 | 0xf8 |
lstrlenA | 0x0 | 0x10003020 | 0x311c | 0x251c | 0x3cc |
LoadLibraryA | 0x0 | 0x10003024 | 0x3120 | 0x2520 | 0x252 |
GetModuleHandleA | 0x0 | 0x10003028 | 0x3124 | 0x2524 | 0x17f |
GlobalAlloc | 0x0 | 0x1000302c | 0x3128 | 0x2528 | 0x1f8 |
WideCharToMultiByte | 0x0 | 0x10003030 | 0x312c | 0x252c | 0x394 |
VirtualAlloc | 0x0 | 0x10003034 | 0x3130 | 0x2530 | 0x381 |
VirtualProtect | 0x0 | 0x10003038 | 0x3134 | 0x2534 | 0x386 |
GetLastError | 0x0 | 0x1000303c | 0x3138 | 0x2538 | 0x171 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
wsprintfA | 0x0 | 0x10003044 | 0x3140 | 0x2540 | 0x2d7 |
ole32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StringFromGUID2 | 0x0 | 0x1000304c | 0x3148 | 0x2548 | 0x135 |
CLSIDFromString | 0x0 | 0x10003050 | 0x314c | 0x254c | 0x8 |
Exports (8)
»
Api name | EAT Address | Ordinal |
---|---|---|
Alloc | 0x1000 | 0x1 |
Call | 0x16db | 0x2 |
Copy | 0x1058 | 0x3 |
Free | 0x15d1 | 0x4 |
Get | 0x1638 | 0x5 |
Int64Op | 0x1837 | 0x6 |
Store | 0x10e0 | 0x7 |
StrAlloc | 0x103d | 0x8 |
C:\Users\5P5NRG~1\AppData\Local\Temp\bfc8f96.lnk | Dropped File | Unknown |
Unknown
|
...
|
»
\\?\C:\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000\desktop.ini.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\BOOTSTAT.DAT.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\BOOTSECT.BAK.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\setup.chm.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\branding.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjProrWW.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPlusrWW.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.GIF.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.JPG.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Office32WW.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.PNG.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\README.HTM.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\AccessMUI.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\AccessMUISet.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\ExcelMUI.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\SETUP.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Groove.en-us\GrooveMUI.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Groove.en-us\SETUP.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\InfoPathMUI.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\SETUP.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\BRANDING.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OCT.CHM.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUISet.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSCONFIG.CHM.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSS10O.CHM.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSS10R.CHM.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\SETUP.CHM.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUI.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\Office32MUI.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.WW\Office32WW.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\OneNoteMUI.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\SETUP.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\SETUP.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\OutlookMUI.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\PowerPointMUI.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\SETUP.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PRJPROR\SETUP.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Project.en-us\ProjectMUI.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Project.en-us\SETUP.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PRJPROR\PrjProrWW.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.en\Proof.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.fr\Proof.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proofing.en-us\SETUP.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PROPLUSR\ProPlusrWW.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.es\Proof.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Publisher.en-us\SETUP.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Visio.en-us\SETUP.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Visio.en-us\VisioMUI.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Publisher.en-us\PublisherMUI.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\SETUP.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Binary |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\VisiorWW.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Word.en-us\SETUP.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Word.en-us\WordMUI.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\1033\MCABOUT.HTM.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\DATES.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\STOCKS.DAT.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\STOCKS.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\TIME.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\PHONE.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\METCONV.TXT.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\BASMLA.XSL.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\PREVIEW.GIF.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AFTRNOON\THMBNAIL.PNG.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Binary |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.cab.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\PREVIEW.GIF.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ARCTIC\THMBNAIL.PNG.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\THMBNAIL.PNG.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\AXIS\PREVIEW.GIF.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\THMBNAIL.PNG.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\PREVIEW.GIF.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUECALM\THMBNAIL.PNG.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\THMBNAIL.PNG.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLENDS\PREVIEW.GIF.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\PREVIEW.GIF.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BOLDSTRI\THMBNAIL.PNG.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\PREVIEW.GIF.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\THMBNAIL.PNG.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\THMBNAIL.PNG.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\PREVIEW.GIF.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CASCADE\THMBNAIL.PNG.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CAPSULES\PREVIEW.GIF.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.cab.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\PREVIEW.GIF.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\PREVIEW.GIF.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\CONCRETE\THMBNAIL.PNG.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\PREVIEW.GIF.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\DEEPBLUE\THMBNAIL.PNG.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\COMPASS\THMBNAIL.PNG.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.msi.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\PREVIEW.GIF.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECHO\THMBNAIL.PNG.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\THMBNAIL.PNG.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\PREVIEW.GIF.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EDGE\THMBNAIL.PNG.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\PREVIEW.GIF.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ECLIPSE\PREVIEW.GIF.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EVRGREEN\THMBNAIL.PNG.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\PREVIEW.GIF.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\THMBNAIL.PNG.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\pss10r.chm.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\branding.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.EPS.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\ADO210.CHM.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\SETUP.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\SETUP.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\SETUP.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proofing.en-us\Proofing.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PROPLUSR\SETUP.XML.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\Stationery\Desktop.ini.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BLUEPRNT\PREVIEW.GIF.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\PREVIEW.GIF.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\BREEZE\THMBNAIL.PNG.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\EXPEDITN\PREVIEW.GIF.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\Microsoft Shared\THEMES14\ICE\THMBNAIL.PNG.id[9C354B42-2222].[William_Kidd_2019@protonmail.com].actor | Dropped File | Stream |
Not Queried
|
...
|
»