VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan |
Bewerbung-Lena-Kretschmer.exe
Windows Exe (x86-32)
Created at 2019-08-01T18:31:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Bewerbung-Lena-Kretschmer.exe | Sample File | Binary |
Blacklisted
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-08-01 11:55 (UTC+2) |
Last Seen | 2019-08-01 20:25 (UTC+2) |
Names | Win32.Trojan.Hpursnif |
Families | Hpursnif |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x40d047 |
Size Of Code | 0x22000 |
Size Of Initialized Data | 0xc0e00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-07-31 18:35:22+00:00 |
Version Information (8)
»
CompanyName | VMware |
FileDescription | Friction Tweeter Casting Transferability |
InternalName | Running |
LegalCopyright | Copyright ©VMware. |
LegalTrademarks | Copyright ©VMware. |
PrivateBuild | 5.8.50.4 |
ProductName | Running |
ProductVersion | 5.8.50.4 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x21eea | 0x22000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.77 |
.rdata | 0x423000 | 0x26b20 | 0x26c00 | 0x22400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.74 |
.data | 0x44a000 | 0xba8c | 0x6a00 | 0x49000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.07 |
.rsrc | 0x456000 | 0x8d8d8 | 0x8da00 | 0x4fa00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.85 |
.reloc | 0x4e4000 | 0x5d9c | 0x5e00 | 0xdd400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.59 |
Imports (21)
»
KERNEL32.dll (101)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateEventW | 0x0 | 0x423080 | 0x488a4 | 0x47ca4 | 0x85 |
GetVolumeInformationA | 0x0 | 0x423084 | 0x488a8 | 0x47ca8 | 0x2a5 |
SetErrorMode | 0x0 | 0x423088 | 0x488ac | 0x47cac | 0x458 |
EnumSystemGeoID | 0x0 | 0x42308c | 0x488b0 | 0x47cb0 | 0x10a |
DeviceIoControl | 0x0 | 0x423090 | 0x488b4 | 0x47cb4 | 0xdd |
GlobalFree | 0x0 | 0x423094 | 0x488b8 | 0x47cb8 | 0x2ba |
FreeResource | 0x0 | 0x423098 | 0x488bc | 0x47cbc | 0x165 |
LockResource | 0x0 | 0x42309c | 0x488c0 | 0x47cc0 | 0x354 |
LoadResource | 0x0 | 0x4230a0 | 0x488c4 | 0x47cc4 | 0x341 |
SizeofResource | 0x0 | 0x4230a4 | 0x488c8 | 0x47cc8 | 0x4b1 |
FindResourceA | 0x0 | 0x4230a8 | 0x488cc | 0x47ccc | 0x14b |
MultiByteToWideChar | 0x0 | 0x4230ac | 0x488d0 | 0x47cd0 | 0x367 |
GlobalUnlock | 0x0 | 0x4230b0 | 0x488d4 | 0x47cd4 | 0x2c5 |
GlobalLock | 0x0 | 0x4230b4 | 0x488d8 | 0x47cd8 | 0x2be |
GetProcAddress | 0x0 | 0x4230b8 | 0x488dc | 0x47cdc | 0x245 |
LoadLibraryA | 0x0 | 0x4230bc | 0x488e0 | 0x47ce0 | 0x33c |
GlobalAlloc | 0x0 | 0x4230c0 | 0x488e4 | 0x47ce4 | 0x2b3 |
GetLastError | 0x0 | 0x4230c4 | 0x488e8 | 0x47ce8 | 0x202 |
LocalFree | 0x0 | 0x4230c8 | 0x488ec | 0x47cec | 0x348 |
GetVersion | 0x0 | 0x4230cc | 0x488f0 | 0x47cf0 | 0x2a2 |
CreateFileW | 0x0 | 0x4230d0 | 0x488f4 | 0x47cf4 | 0x8f |
WriteConsoleW | 0x0 | 0x4230d4 | 0x488f8 | 0x47cf8 | 0x524 |
HeapReAlloc | 0x0 | 0x4230d8 | 0x488fc | 0x47cfc | 0x2d2 |
LoadLibraryW | 0x0 | 0x4230dc | 0x48900 | 0x47d00 | 0x33f |
HeapSize | 0x0 | 0x4230e0 | 0x48904 | 0x47d04 | 0x2d4 |
FlushFileBuffers | 0x0 | 0x4230e4 | 0x48908 | 0x47d08 | 0x157 |
CancelIoEx | 0x0 | 0x4230e8 | 0x4890c | 0x47d0c | 0x43 |
LCMapStringW | 0x0 | 0x4230ec | 0x48910 | 0x47d10 | 0x32d |
GetProcessHeap | 0x0 | 0x4230f0 | 0x48914 | 0x47d14 | 0x24a |
SetEndOfFile | 0x0 | 0x4230f4 | 0x48918 | 0x47d18 | 0x453 |
SetFilePointer | 0x0 | 0x4230f8 | 0x4891c | 0x47d1c | 0x466 |
GetConsoleMode | 0x0 | 0x4230fc | 0x48920 | 0x47d20 | 0x1ac |
GetConsoleCP | 0x0 | 0x423100 | 0x48924 | 0x47d24 | 0x19a |
SetStdHandle | 0x0 | 0x423104 | 0x48928 | 0x47d28 | 0x487 |
GetSystemTimeAsFileTime | 0x0 | 0x423108 | 0x4892c | 0x47d2c | 0x279 |
GetCurrentProcessId | 0x0 | 0x42310c | 0x48930 | 0x47d30 | 0x1c1 |
GetTickCount | 0x0 | 0x423110 | 0x48934 | 0x47d34 | 0x293 |
GetModuleFileNameA | 0x0 | 0x423114 | 0x48938 | 0x47d38 | 0x213 |
FreeEnvironmentStringsW | 0x0 | 0x423118 | 0x4893c | 0x47d3c | 0x161 |
VirtualQuery | 0x0 | 0x42311c | 0x48940 | 0x47d40 | 0x4f1 |
GetModuleFileNameW | 0x0 | 0x423120 | 0x48944 | 0x47d44 | 0x214 |
HeapCreate | 0x0 | 0x423124 | 0x48948 | 0x47d48 | 0x2cd |
ExitProcess | 0x0 | 0x423128 | 0x4894c | 0x47d4c | 0x119 |
GetStringTypeW | 0x0 | 0x42312c | 0x48950 | 0x47d50 | 0x269 |
IsProcessorFeaturePresent | 0x0 | 0x423130 | 0x48954 | 0x47d54 | 0x304 |
DeleteCriticalSection | 0x0 | 0x423134 | 0x48958 | 0x47d58 | 0xd1 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x423138 | 0x4895c | 0x47d5c | 0x2e3 |
GetStdHandle | 0x0 | 0x42313c | 0x48960 | 0x47d60 | 0x264 |
SetHandleCount | 0x0 | 0x423140 | 0x48964 | 0x47d64 | 0x46f |
LeaveCriticalSection | 0x0 | 0x423144 | 0x48968 | 0x47d68 | 0x339 |
EnterCriticalSection | 0x0 | 0x423148 | 0x4896c | 0x47d6c | 0xee |
GetModuleHandleW | 0x0 | 0x42314c | 0x48970 | 0x47d70 | 0x218 |
TlsFree | 0x0 | 0x423150 | 0x48974 | 0x47d74 | 0x4c6 |
TlsSetValue | 0x0 | 0x423154 | 0x48978 | 0x47d78 | 0x4c8 |
GetCommandLineW | 0x0 | 0x423158 | 0x4897c | 0x47d7c | 0x187 |
Sleep | 0x0 | 0x42315c | 0x48980 | 0x47d80 | 0x4b2 |
ReadFile | 0x0 | 0x423160 | 0x48984 | 0x47d84 | 0x3c0 |
ResetEvent | 0x0 | 0x423164 | 0x48988 | 0x47d88 | 0x40f |
SetupComm | 0x0 | 0x423168 | 0x4898c | 0x47d8c | 0x4ae |
SetCommState | 0x0 | 0x42316c | 0x48990 | 0x47d90 | 0x425 |
SetCommTimeouts | 0x0 | 0x423170 | 0x48994 | 0x47d94 | 0x426 |
CreateEventA | 0x0 | 0x423174 | 0x48998 | 0x47d98 | 0x82 |
WriteFile | 0x0 | 0x423178 | 0x4899c | 0x47d9c | 0x525 |
WaitForSingleObject | 0x0 | 0x42317c | 0x489a0 | 0x47da0 | 0x4f9 |
GetOverlappedResult | 0x0 | 0x423180 | 0x489a4 | 0x47da4 | 0x238 |
lstrcpynA | 0x0 | 0x423184 | 0x489a8 | 0x47da8 | 0x54a |
GetVersionExA | 0x0 | 0x423188 | 0x489ac | 0x47dac | 0x2a3 |
CreateFileA | 0x0 | 0x42318c | 0x489b0 | 0x47db0 | 0x88 |
CloseHandle | 0x0 | 0x423190 | 0x489b4 | 0x47db4 | 0x52 |
WideCharToMultiByte | 0x0 | 0x423194 | 0x489b8 | 0x47db8 | 0x511 |
SetLastError | 0x0 | 0x423198 | 0x489bc | 0x47dbc | 0x473 |
GetModuleHandleA | 0x0 | 0x42319c | 0x489c0 | 0x47dc0 | 0x215 |
FormatMessageA | 0x0 | 0x4231a0 | 0x489c4 | 0x47dc4 | 0x15d |
TlsGetValue | 0x0 | 0x4231a4 | 0x489c8 | 0x47dc8 | 0x4c7 |
TlsAlloc | 0x0 | 0x4231a8 | 0x489cc | 0x47dcc | 0x4c5 |
IsValidCodePage | 0x0 | 0x4231ac | 0x489d0 | 0x47dd0 | 0x30a |
GetOEMCP | 0x0 | 0x4231b0 | 0x489d4 | 0x47dd4 | 0x237 |
GetACP | 0x0 | 0x4231b4 | 0x489d8 | 0x47dd8 | 0x168 |
InterlockedDecrement | 0x0 | 0x4231b8 | 0x489dc | 0x47ddc | 0x2eb |
InterlockedIncrement | 0x0 | 0x4231bc | 0x489e0 | 0x47de0 | 0x2ef |
GetCPInfo | 0x0 | 0x4231c0 | 0x489e4 | 0x47de4 | 0x172 |
GetCurrentProcess | 0x0 | 0x4231c4 | 0x489e8 | 0x47de8 | 0x1c0 |
TerminateProcess | 0x0 | 0x4231c8 | 0x489ec | 0x47dec | 0x4c0 |
DecodePointer | 0x0 | 0x4231cc | 0x489f0 | 0x47df0 | 0xca |
EncodePointer | 0x0 | 0x4231d0 | 0x489f4 | 0x47df4 | 0xea |
IsDebuggerPresent | 0x0 | 0x4231d4 | 0x489f8 | 0x47df8 | 0x300 |
SetUnhandledExceptionFilter | 0x0 | 0x4231d8 | 0x489fc | 0x47dfc | 0x4a5 |
UnhandledExceptionFilter | 0x0 | 0x4231dc | 0x48a00 | 0x47e00 | 0x4d3 |
GetFileType | 0x0 | 0x4231e0 | 0x48a04 | 0x47e04 | 0x1f3 |
GetStartupInfoW | 0x0 | 0x4231e4 | 0x48a08 | 0x47e08 | 0x263 |
HeapSetInformation | 0x0 | 0x4231e8 | 0x48a0c | 0x47e0c | 0x2d3 |
GetCommandLineA | 0x0 | 0x4231ec | 0x48a10 | 0x47e10 | 0x186 |
HeapAlloc | 0x0 | 0x4231f0 | 0x48a14 | 0x47e14 | 0x2cb |
HeapFree | 0x0 | 0x4231f4 | 0x48a18 | 0x47e18 | 0x2cf |
CreateThread | 0x0 | 0x4231f8 | 0x48a1c | 0x47e1c | 0xb5 |
GetCurrentThreadId | 0x0 | 0x4231fc | 0x48a20 | 0x47e20 | 0x1c5 |
ExitThread | 0x0 | 0x423200 | 0x48a24 | 0x47e24 | 0x11a |
RaiseException | 0x0 | 0x423204 | 0x48a28 | 0x47e28 | 0x3b1 |
RtlUnwind | 0x0 | 0x423208 | 0x48a2c | 0x47e2c | 0x418 |
QueryPerformanceCounter | 0x0 | 0x42320c | 0x48a30 | 0x47e30 | 0x3a7 |
GetEnvironmentStringsW | 0x0 | 0x423210 | 0x48a34 | 0x47e34 | 0x1da |
USER32.dll (48)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetUserObjectInformationW | 0x0 | 0x42329c | 0x48ac0 | 0x47ec0 | 0x18b |
SetActiveWindow | 0x0 | 0x4232a0 | 0x48ac4 | 0x47ec4 | 0x27f |
GetProcessWindowStation | 0x0 | 0x4232a4 | 0x48ac8 | 0x47ec8 | 0x168 |
MessageBoxA | 0x0 | 0x4232a8 | 0x48acc | 0x47ecc | 0x20e |
wsprintfA | 0x0 | 0x4232ac | 0x48ad0 | 0x47ed0 | 0x332 |
SetWindowPos | 0x0 | 0x4232b0 | 0x48ad4 | 0x47ed4 | 0x2c6 |
ShowWindow | 0x0 | 0x4232b4 | 0x48ad8 | 0x47ed8 | 0x2df |
SendMessageA | 0x0 | 0x4232b8 | 0x48adc | 0x47edc | 0x277 |
DefWindowProcA | 0x0 | 0x4232bc | 0x48ae0 | 0x47ee0 | 0x9b |
TrackPopupMenu | 0x0 | 0x4232c0 | 0x48ae4 | 0x47ee4 | 0x2f6 |
ReleaseDC | 0x0 | 0x4232c4 | 0x48ae8 | 0x47ee8 | 0x265 |
GetDC | 0x0 | 0x4232c8 | 0x48aec | 0x47eec | 0x121 |
SetCaretBlinkTime | 0x0 | 0x4232cc | 0x48af0 | 0x47ef0 | 0x281 |
GetWindowLongA | 0x0 | 0x4232d0 | 0x48af4 | 0x47ef4 | 0x195 |
SetCapture | 0x0 | 0x4232d4 | 0x48af8 | 0x47ef8 | 0x280 |
PtInRect | 0x0 | 0x4232d8 | 0x48afc | 0x47efc | 0x240 |
RedrawWindow | 0x0 | 0x4232dc | 0x48b00 | 0x47f00 | 0x24a |
CreateMenu | 0x0 | 0x4232e0 | 0x48b04 | 0x47f04 | 0x6a |
LoadMenuA | 0x0 | 0x4232e4 | 0x48b08 | 0x47f08 | 0x1f4 |
LoadBitmapA | 0x0 | 0x4232e8 | 0x48b0c | 0x47f0c | 0x1e6 |
AttachThreadInput | 0x0 | 0x4232ec | 0x48b10 | 0x47f10 | 0xc |
GetScrollPos | 0x0 | 0x4232f0 | 0x48b14 | 0x47f14 | 0x176 |
GetScrollRange | 0x0 | 0x4232f4 | 0x48b18 | 0x47f18 | 0x177 |
GetForegroundWindow | 0x0 | 0x4232f8 | 0x48b1c | 0x47f1c | 0x12d |
SetWindowLongA | 0x0 | 0x4232fc | 0x48b20 | 0x47f20 | 0x2c3 |
GetClientRect | 0x0 | 0x423300 | 0x48b24 | 0x47f24 | 0x114 |
CopyRect | 0x0 | 0x423304 | 0x48b28 | 0x47f28 | 0x55 |
GetDlgItemInt | 0x0 | 0x423308 | 0x48b2c | 0x47f2c | 0x128 |
ClientToScreen | 0x0 | 0x42330c | 0x48b30 | 0x47f30 | 0x47 |
LoadImageA | 0x0 | 0x423310 | 0x48b34 | 0x47f34 | 0x1ee |
DrawStateA | 0x0 | 0x423314 | 0x48b38 | 0x47f38 | 0xcb |
CreateWindowExA | 0x0 | 0x423318 | 0x48b3c | 0x47f3c | 0x6d |
GetWindowTextA | 0x0 | 0x42331c | 0x48b40 | 0x47f40 | 0x1a0 |
BeginPaint | 0x0 | 0x423320 | 0x48b44 | 0x47f44 | 0xe |
DrawTextA | 0x0 | 0x423324 | 0x48b48 | 0x47f48 | 0xcd |
EndPaint | 0x0 | 0x423328 | 0x48b4c | 0x47f4c | 0xdc |
PostQuitMessage | 0x0 | 0x42332c | 0x48b50 | 0x47f50 | 0x237 |
SendDlgItemMessageA | 0x0 | 0x423330 | 0x48b54 | 0x47f54 | 0x272 |
OpenClipboard | 0x0 | 0x423334 | 0x48b58 | 0x47f58 | 0x226 |
EmptyClipboard | 0x0 | 0x423338 | 0x48b5c | 0x47f5c | 0xd5 |
SetClipboardData | 0x0 | 0x42333c | 0x48b60 | 0x47f60 | 0x286 |
CloseClipboard | 0x0 | 0x423340 | 0x48b64 | 0x47f64 | 0x49 |
GetDlgItem | 0x0 | 0x423344 | 0x48b68 | 0x47f68 | 0x127 |
IsWindowVisible | 0x0 | 0x423348 | 0x48b6c | 0x47f6c | 0x1e0 |
CreatePopupMenu | 0x0 | 0x42334c | 0x48b70 | 0x47f70 | 0x6b |
AppendMenuA | 0x0 | 0x423350 | 0x48b74 | 0x47f74 | 0x9 |
SetForegroundWindow | 0x0 | 0x423354 | 0x48b78 | 0x47f78 | 0x293 |
GetCursorPos | 0x0 | 0x423358 | 0x48b7c | 0x47f7c | 0x120 |
GDI32.dll (20)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExcludeClipRect | 0x0 | 0x42302c | 0x48850 | 0x47c50 | 0x131 |
SetBrushOrgEx | 0x0 | 0x423030 | 0x48854 | 0x47c54 | 0x282 |
CreateDCA | 0x0 | 0x423034 | 0x48858 | 0x47c58 | 0x31 |
GetDIBits | 0x0 | 0x423038 | 0x4885c | 0x47c5c | 0x1ca |
CreateCompatibleDC | 0x0 | 0x42303c | 0x48860 | 0x47c60 | 0x30 |
CreateCompatibleBitmap | 0x0 | 0x423040 | 0x48864 | 0x47c64 | 0x2f |
SelectObject | 0x0 | 0x423044 | 0x48868 | 0x47c68 | 0x277 |
DeleteObject | 0x0 | 0x423048 | 0x4886c | 0x47c6c | 0xe6 |
DeleteDC | 0x0 | 0x42304c | 0x48870 | 0x47c70 | 0xe3 |
CreatePen | 0x0 | 0x423050 | 0x48874 | 0x47c74 | 0x4b |
SetROP2 | 0x0 | 0x423054 | 0x48878 | 0x47c78 | 0x29f |
Rectangle | 0x0 | 0x423058 | 0x4887c | 0x47c7c | 0x25f |
MoveToEx | 0x0 | 0x42305c | 0x48880 | 0x47c80 | 0x23a |
LineTo | 0x0 | 0x423060 | 0x48884 | 0x47c84 | 0x236 |
CreateDIBSection | 0x0 | 0x423064 | 0x48888 | 0x47c88 | 0x35 |
StretchBlt | 0x0 | 0x423068 | 0x4888c | 0x47c8c | 0x2b3 |
BitBlt | 0x0 | 0x42306c | 0x48890 | 0x47c90 | 0x13 |
TextOutA | 0x0 | 0x423070 | 0x48894 | 0x47c94 | 0x2b8 |
GetObjectA | 0x0 | 0x423074 | 0x48898 | 0x47c98 | 0x1fb |
GetPath | 0x0 | 0x423078 | 0x4889c | 0x47c9c | 0x201 |
COMDLG32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ChooseColorA | 0x0 | 0x423018 | 0x4883c | 0x47c3c | 0x0 |
GetSaveFileNameW | 0x0 | 0x42301c | 0x48840 | 0x47c40 | 0xe |
ADVAPI32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegisterEventSourceA | 0x0 | 0x423000 | 0x48824 | 0x47c24 | 0x282 |
DeregisterEventSource | 0x0 | 0x423004 | 0x48828 | 0x47c28 | 0xdb |
RegQueryValueExA | 0x0 | 0x423008 | 0x4882c | 0x47c2c | 0x26d |
RegCloseKey | 0x0 | 0x42300c | 0x48830 | 0x47c30 | 0x230 |
ReportEventA | 0x0 | 0x423010 | 0x48834 | 0x47c34 | 0x28e |
SHELL32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CommandLineToArgvW | 0x0 | 0x42327c | 0x48aa0 | 0x47ea0 | 0x6 |
Shell_NotifyIconA | 0x0 | 0x423280 | 0x48aa4 | 0x47ea4 | 0x12c |
ole32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StgOpenStorage | 0x0 | 0x423394 | 0x48bb8 | 0x47fb8 | 0x172 |
CreateStreamOnHGlobal | 0x0 | 0x423398 | 0x48bbc | 0x47fbc | 0x86 |
StringFromGUID2 | 0x0 | 0x42339c | 0x48bc0 | 0x47fc0 | 0x179 |
StgCreateDocfile | 0x0 | 0x4233a0 | 0x48bc4 | 0x47fc4 | 0x167 |
OLEAUT32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysAllocStringLen | 0x4 | 0x423220 | 0x48a44 | 0x47e44 | - |
SysFreeString | 0x6 | 0x423224 | 0x48a48 | 0x47e48 | - |
OleLoadPicture | 0x1a2 | 0x423228 | 0x48a4c | 0x47e4c | - |
OPENGL32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
wglMakeCurrent | 0x0 | 0x423230 | 0x48a54 | 0x47e54 | 0x164 |
wglCreateContext | 0x0 | 0x423234 | 0x48a58 | 0x47e58 | 0x159 |
VERSION.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetFileVersionInfoW | 0x0 | 0x423360 | 0x48b84 | 0x47f84 | 0x6 |
WS2_32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WSAStartup | 0x73 | 0x423370 | 0x48b94 | 0x47f94 | - |
WSACleanup | 0x74 | 0x423374 | 0x48b98 | 0x47f98 | - |
closesocket | 0x3 | 0x423378 | 0x48b9c | 0x47f9c | - |
getsockopt | 0x7 | 0x42337c | 0x48ba0 | 0x47fa0 | - |
socket | 0x17 | 0x423380 | 0x48ba4 | 0x47fa4 | - |
bind | 0x2 | 0x423384 | 0x48ba8 | 0x47fa8 | - |
SHLWAPI.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathFileExistsW | 0x0 | 0x423288 | 0x48aac | 0x47eac | 0x45 |
SHCreateStreamOnFileA | 0x0 | 0x42328c | 0x48ab0 | 0x47eb0 | 0xa9 |
SETUPAPI.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetupDiEnumDeviceInterfaces | 0x0 | 0x423258 | 0x48a7c | 0x47e7c | 0x143 |
SetupDiGetDeviceInterfaceDetailA | 0x0 | 0x42325c | 0x48a80 | 0x47e80 | 0x16d |
SetupDiClassGuidsFromNameA | 0x0 | 0x423260 | 0x48a84 | 0x47e84 | 0x127 |
SetupDiGetClassDevsA | 0x0 | 0x423264 | 0x48a88 | 0x47e88 | 0x153 |
SetupDiEnumDeviceInfo | 0x0 | 0x423268 | 0x48a8c | 0x47e8c | 0x142 |
SetupDiOpenDevRegKey | 0x0 | 0x42326c | 0x48a90 | 0x47e90 | 0x193 |
SetupDiGetDeviceRegistryPropertyA | 0x0 | 0x423270 | 0x48a94 | 0x47e94 | 0x173 |
SetupDiDestroyDeviceInfoList | 0x0 | 0x423274 | 0x48a98 | 0x47e98 | 0x13f |
MSIMG32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
AlphaBlend | 0x0 | 0x423218 | 0x48a3c | 0x47e3c | 0x0 |
RPCRT4.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
UuidToStringA | 0x0 | 0x42324c | 0x48a70 | 0x47e70 | 0x203 |
UuidCreate | 0x0 | 0x423250 | 0x48a74 | 0x47e74 | 0x1fb |
WINHTTP.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WinHttpOpen | 0x0 | 0x423368 | 0x48b8c | 0x47f8c | 0xf |
POWRPROF.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetActivePwrScheme | 0x0 | 0x42323c | 0x48a60 | 0x47e60 | 0xa |
RASAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RasEnumConnectionsA | 0x0 | 0x423244 | 0x48a68 | 0x47e68 | 0x18 |
TAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
lineConfigProvider | 0x0 | 0x423294 | 0x48ab8 | 0x47eb8 | 0x30 |
d2d1.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x1 | 0x42338c | 0x48bb0 | 0x47fb0 | - |
DWrite.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DWriteCreateFactory | 0x0 | 0x423024 | 0x48848 | 0x47c48 | 0x0 |
Exports (1)
»
Api name | EAT Address | Ordinal |
---|---|---|
Take | 0x4164 | 0x1 |
Memory Dumps (25)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
bewerbung-lena-kretschmer.exe | 1 | 0x00400000 | 0x004E9FFF | Relevant Image | - | 32-bit | - |
...
|
||
buffer | 1 | 0x02F60000 | 0x02F92FFF | First Execution | - | 32-bit | 0x02F60000 |
...
|
||
buffer | 1 | 0x00600000 | 0x00600FFF | First Execution | - | 32-bit | 0x00600000 |
...
|
||
buffer | 1 | 0x00600000 | 0x00600FFF | First Execution | - | 32-bit | 0x00600000 |
...
|
||
buffer | 1 | 0x00600000 | 0x00600FFF | First Execution | - | 32-bit | 0x00600000 |
...
|
||
buffer | 1 | 0x00600000 | 0x00600FFF | First Execution | - | 32-bit | 0x00600000 |
...
|
||
buffer | 1 | 0x00600000 | 0x00600FFF | First Execution | - | 32-bit | 0x00600000 |
...
|
||
buffer | 1 | 0x00600000 | 0x00600FFF | First Execution | - | 32-bit | 0x00600000 |
...
|
||
buffer | 1 | 0x00600000 | 0x00600FFF | First Execution | - | 32-bit | 0x00600000 |
...
|
||
buffer | 1 | 0x00600000 | 0x00600FFF | First Execution | - | 32-bit | 0x00600000 |
...
|
||
buffer | 1 | 0x00600000 | 0x00600FFF | First Execution | - | 32-bit | 0x00600000 |
...
|
||
buffer | 1 | 0x00600000 | 0x00600FFF | First Execution | - | 32-bit | 0x00600000 |
...
|
||
buffer | 1 | 0x00600000 | 0x00600FFF | First Execution | - | 32-bit | 0x00600000 |
...
|
||
buffer | 1 | 0x00600000 | 0x00600FFF | First Execution | - | 32-bit | 0x00600000 |
...
|
||
buffer | 1 | 0x00600000 | 0x00600FFF | First Execution | - | 32-bit | 0x00600000 |
...
|
||
buffer | 1 | 0x00600000 | 0x00600FFF | First Execution | - | 32-bit | 0x00600000 |
...
|
||
buffer | 1 | 0x00600000 | 0x00600FFF | First Execution | - | 32-bit | 0x00600000 |
...
|
||
buffer | 1 | 0x02F60000 | 0x02F92FFF | Content Changed | - | 32-bit | 0x02F63124 |
...
|
||
buffer | 1 | 0x02F60000 | 0x02F92FFF | Content Changed | - | 32-bit | 0x02F64994 |
...
|
||
bewerbung-lena-kretschmer.exe | 2 | 0x00400000 | 0x004E9FFF | Relevant Image | - | 32-bit | - |
...
|
||
buffer | 2 | 0x00220000 | 0x00220FFF | First Execution | - | 32-bit | 0x00220FEF |
...
|
||
bewerbung-lena-kretschmer.exe | 1 | 0x00400000 | 0x004E9FFF | Process Termination | - | 32-bit | - |
...
|
||
buffer | 2 | 0x00220000 | 0x00220FFF | Content Changed | - | 32-bit | 0x00220FEF |
...
|
||
buffer | 2 | 0x00220000 | 0x00220FFF | Content Changed | - | 32-bit | 0x00220FD5 |
...
|
||
bewerbung-lena-kretschmer.exe | 2 | 0x00400000 | 0x004E9FFF | Final Dump | - | 32-bit | - |
...
|
C:\\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\boot.sdi.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2014-05-26 12:01 (UTC+2) |
Last Seen | 2017-02-06 14:39 (UTC+1) |
C:\\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\Winre.wim.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-03-20 15:43 (UTC+1) |
Last Seen | 2019-03-13 09:50 (UTC+1) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2015-12-02 18:08 (UTC+1) |
Last Seen | 2019-07-15 13:28 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-03-17 16:08 (UTC+1) |
Last Seen | 2019-07-15 13:30 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-05-25 12:38 (UTC+2) |
Last Seen | 2019-07-15 13:30 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-12-31 02:49 (UTC+1) |
Last Seen | 2019-07-15 13:29 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2014-04-17 01:15 (UTC+2) |
Last Seen | 2019-07-15 13:30 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\AvYcfInJW3s.ppt.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2015-06-08 12:20 (UTC+2) |
Last Seen | 2017-04-24 18:12 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\B_LHlZX.jpg.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2018-06-12 13:00 (UTC+2) |
Last Seen | 2018-06-12 13:00 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\cBMF.jpg.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2015-08-29 04:39 (UTC+2) |
Last Seen | 2018-04-26 20:43 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\eZyEq6LuF.bmp.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2015-08-01 20:14 (UTC+2) |
Last Seen | 2018-05-01 17:30 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\iIDAS7vyp9i2.wav.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2015-04-13 01:44 (UTC+2) |
Last Seen | 2017-02-06 05:34 (UTC+1) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\KKJNKdb4.jpg.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2015-04-15 02:17 (UTC+2) |
Last Seen | 2017-02-21 22:53 (UTC+1) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\oDYxEMRqha2i\Lyil.swf.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2015-10-16 05:27 (UTC+2) |
Last Seen | 2019-07-15 13:30 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\oDYxEMRqha2i\mr3zp.m4a.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2016-02-02 02:06 (UTC+1) |
Last Seen | 2017-04-24 21:54 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\oDYxEMRqha2i\oB0lf_ykCfB.mkv.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-03-20 15:45 (UTC+1) |
Last Seen | 2017-06-07 18:57 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\oDYxEMRqha2i\_rVQVHNmt.mkv.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-03-20 15:45 (UTC+1) |
Last Seen | 2017-06-08 18:31 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\QfwW.m4a.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2016-07-08 03:45 (UTC+2) |
Last Seen | 2017-04-24 16:46 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\RXx-TWJa5GBSdyFBmpPq.bmp.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2015-06-12 18:58 (UTC+2) |
Last Seen | 2017-06-08 06:30 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\SlMjQnMOsk--Ao.mp3.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-07-23 03:41 (UTC+2) |
Last Seen | 2017-04-25 20:09 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\vhFglPjsgDrl0R.mp3.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2015-07-05 06:24 (UTC+2) |
Last Seen | 2018-03-20 05:26 (UTC+1) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\5Pf4wcQqnRWvY5UTmN.xlsx.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2015-07-10 06:55 (UTC+2) |
Last Seen | 2017-04-08 21:25 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\80NolXm1gJwdLmrAxPE.pptx.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2017-05-02 17:57 (UTC+2) |
Last Seen | 2017-05-02 17:57 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\9mbmg2W dvtbS30Hg.pptx.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2015-08-12 13:38 (UTC+2) |
Last Seen | 2017-06-09 20:02 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\cgdQr.pptx.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2014-02-11 05:50 (UTC+1) |
Last Seen | 2019-07-15 13:30 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\lKgnRdjtvhEUGQe9.pps.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2016-04-07 21:03 (UTC+2) |
Last Seen | 2017-03-28 08:34 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\MdBaWmvn.docx.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2015-08-23 23:24 (UTC+2) |
Last Seen | 2017-02-19 19:08 (UTC+1) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\n973BEaGNj3lPywp1Ium.pptx.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2015-09-14 21:56 (UTC+2) |
Last Seen | 2017-04-24 23:50 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-03-20 15:45 (UTC+1) |
Last Seen | 2018-06-30 22:46 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\qeDPLLtVsf\68jWa6USQR-sKFxOOt\at4_Oyq8Cw.odt.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2015-07-10 04:34 (UTC+2) |
Last Seen | 2017-01-05 20:46 (UTC+1) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\qeDPLLtVsf\68jWa6USQR-sKFxOOt\B jkx.pdf.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2015-04-14 22:11 (UTC+2) |
Last Seen | 2017-06-02 11:46 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\qeDPLLtVsf\68jWa6USQR-sKFxOOt\pPttOsCl.pptx.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2016-03-01 05:45 (UTC+1) |
Last Seen | 2017-04-29 00:39 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\qeDPLLtVsf\iO25BwSyR arQjhM65i\W_wMge9wfmkZ8MJ5R\Kob6_vpE56cgsa.pps.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2014-03-30 11:36 (UTC+2) |
Last Seen | 2018-05-12 10:12 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\qeDPLLtVsf\iO25BwSyR arQjhM65i\W_wMge9wfmkZ8MJ5R\Topme4Zk01FK 6Gtu\z_o1C3Fp.xls.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-03-17 16:08 (UTC+1) |
Last Seen | 2017-04-18 16:36 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\qeDPLLtVsf\W143oEz8-s.ots.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2015-04-15 05:09 (UTC+2) |
Last Seen | 2017-10-05 13:36 (UTC+2) |
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\qeDPLLtVsf\x51fjCm3UQ3gZ1.odp.eRq7E | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2015-07-10 05:19 (UTC+2) |
Last Seen | 2017-04-14 02:14 (UTC+2) |
C:\\Program Files\Common Files\Microsoft Shared\THEMES14\CANYON\eRq7E_Entschluesselungs_Anleitung.html | Dropped File | Text |
Unknown
|
...
|
»
Embedded URLs (6)
»
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data |
---|---|---|---|---|---|
https://btcdirect.eu/de-at | - | - | - |
Unknown
|
Not Queried
|
https://www.bitcoin.de/ | - | - | - |
Unknown
|
Not Queried
|
https://coinmama.com/ | - | - | - |
Unknown
|
Not Queried
|
https://cdnjs.cloudflare.com/ajax/libs/jquery/3.4.1/jquery.min.js | - | - | - |
Unknown
|
Not Queried
|
https://www.bitpanda.com/ | - | - | - |
Unknown
|
Not Queried
|
https://anycoindirect.eu/ | - | - | - |
Unknown
|
Not Queried
|
C:\\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\eRq7E_Entschluesselungs_Anleitung.html | Dropped File | Text |
Unknown
|
...
|
»
Embedded URLs (6)
»
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data |
---|---|---|---|---|---|
https://btcdirect.eu/de-at | - | - | - |
Unknown
|
Not Queried
|
https://www.bitcoin.de/ | - | - | - |
Unknown
|
Not Queried
|
https://coinmama.com/ | - | - | - |
Unknown
|
Not Queried
|
https://cdnjs.cloudflare.com/ajax/libs/jquery/3.4.1/jquery.min.js | - | - | - |
Unknown
|
Not Queried
|
https://www.bitpanda.com/ | - | - | - |
Unknown
|
Not Queried
|
https://anycoindirect.eu/ | - | - | - |
Unknown
|
Not Queried
|
C:\\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\3sih-RylaaBvVX.avi.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\4G4KxYNiDSXY0YC.avi.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\AnR0Eihu.doc.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\Eqji6XcI1.wav.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\G-da.rtf.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\GLQb9732ogaAXJn Tq.xlsx.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\ih0aI0WeKsH_Ygh.odp.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\J4zsDwJervQ fY dLeS.pdf.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\jBMmdul.m4a.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\jhm4sg8Iv2 SN4Ssn.jpg.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\jvPr5wpJaY.m4a.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\KPpPsRccaBB7rEZOMx.wav.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\LfMqrgmv1kx.bmp.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\mzj2MwGnHXwB0y4.jpg.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\NUTkq3prMKTEnF10WAhQ.bmp.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\oDYxEMRqha2i\06gqXrJyYnDgj.flv.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\oDYxEMRqha2i\0oENKsHpvzIpWLWmo.m4a.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\oDYxEMRqha2i\rLn-NleIe4.mp4.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\oDYxEMRqha2i\_xBs8LwD307MqhKe8.mp3.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\Xd_BV4SX1wu.rtf.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\Xm2LSVGbZ.ots.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\xnCyP.m4a.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\1AiocSA3HBF9NS.pptx.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\bFJN7O jz2piOAKxrjkK.xlsx.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\G5apS6UaIs- s6QaeIZ.docx.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\i0n3gtlhlfhH_.xls.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\kBy0JWAdruHY3kEX.docx.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\pcGU.docx.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\QBphFEu.pdf.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\qeDPLLtVsf\68jWa6USQR-sKFxOOt\52tnN rvpL4z.xlsx.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\qeDPLLtVsf\68jWa6USQR-sKFxOOt\5tjfWpvu7D-mLYjz.xlsx.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\qeDPLLtVsf\68jWa6USQR-sKFxOOt\NroNt7saEf9IRK6a2mP.pptx.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\qeDPLLtVsf\a wT1BAJTTfu.pdf.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\qeDPLLtVsf\iO25BwSyR arQjhM65i\ngucqwSqjbFuZus.ods.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\qeDPLLtVsf\iO25BwSyR arQjhM65i\W_wMge9wfmkZ8MJ5R\idI7.rtf.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\qeDPLLtVsf\iO25BwSyR arQjhM65i\W_wMge9wfmkZ8MJ5R\iE-gkdn.pps.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\qeDPLLtVsf\iO25BwSyR arQjhM65i\W_wMge9wfmkZ8MJ5R\JFd i_sO8g26.ods.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\qeDPLLtVsf\iO25BwSyR arQjhM65i\W_wMge9wfmkZ8MJ5R\Topme4Zk01FK 6Gtu\fBQsJpmOS2w1R.csv.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\qeDPLLtVsf\iO25BwSyR arQjhM65i\W_wMge9wfmkZ8MJ5R\Topme4Zk01FK 6Gtu\I O2.ods.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\qeDPLLtVsf\iO25BwSyR arQjhM65i\W_wMge9wfmkZ8MJ5R\Topme4Zk01FK 6Gtu\IINoy jBWcoOXSvUY.docx.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\qeDPLLtVsf\iO25BwSyR arQjhM65i\W_wMge9wfmkZ8MJ5R\Topme4Zk01FK 6Gtu\lKEgUIY.pptx.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\qeDPLLtVsf\iO25BwSyR arQjhM65i\W_wMge9wfmkZ8MJ5R\Topme4Zk01FK 6Gtu\XdZcp8R6dDsh.xls.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\qeDPLLtVsf\iO25BwSyR arQjhM65i\yQMjH-70DBSIXg OD.xls.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\QYs4zXMDwkUdoRhHr.docx.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\satO4 jKD.pptx.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\XbxSw5aqmqE5ID8bbG11.xlsx.eRq7E | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Windows\Microsoft.NET\Framework\v2.0.50727\ASP.NETWebAdminFiles\Providers\App_LocalResources\eRq7E_Entschluesselungs_Anleitung.html | Dropped File | Text |
Unknown
|
...
|
»
Embedded URLs (6)
»
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data |
---|---|---|---|---|---|
https://btcdirect.eu/de-at | - | - | - |
Unknown
|
Not Queried
|
https://www.bitcoin.de/ | - | - | - |
Unknown
|
Not Queried
|
https://coinmama.com/ | - | - | - |
Unknown
|
Not Queried
|
https://cdnjs.cloudflare.com/ajax/libs/jquery/3.4.1/jquery.min.js | - | - | - |
Unknown
|
Not Queried
|
https://www.bitpanda.com/ | - | - | - |
Unknown
|
Not Queried
|
https://anycoindirect.eu/ | - | - | - |
Unknown
|
Not Queried
|
C:\Users\5P5NRG~1\AppData\Local\Temp\sasi.bmp | Dropped File | Image |
Unknown
|
...
|
»