VTI SCORE: 98/100
Dynamic Analysis Report |
Classification: Keylogger, Spyware, Trojan |
sgm_20190527_desfuhohdt.exe
Windows Exe (x86-32)
Created at 2019-06-09T15:05:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\aETAdzjz\Desktop\sgm_20190527_desfuhohdt.exe | Sample File | Binary |
Suspicious
|
...
|
»
File Reputation Information
»
Severity |
Suspicious
|
First Seen | 2019-05-27 09:57 (UTC+2) |
Last Seen | 2019-06-09 05:59 (UTC+2) |
Names | Win32.Trojan.Hpgen |
Families | Hpgen |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x435c58 |
Size Of Code | 0x4c000 |
Size Of Initialized Data | 0xce800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-05-27 07:52:54+00:00 |
Version Information (11)
»
Comments | Nvarchar Anatomicity Cursor Hping Presentation |
CompanyName | AT&T |
FileDescription | Nvarchar Anatomicity Cursor Hping Presentation |
FileVersion | 3.2.34.7 |
InternalName | Worker |
LegalCopyright | AT&T ©. All rights reserved. |
LegalTrademarks | AT&T ©. All rights reserved. |
OriginalFilename | Worker |
PrivateBuild | 3.2.34.7 |
ProductName | Worker |
ProductVersion | 3.2.34.7 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x4c000 | 0x4c000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.57 |
.rdata | 0x44d000 | 0x1bc24 | 0x1be00 | 0x4c400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.29 |
.data | 0x469000 | 0x4a00 | 0x1c00 | 0x68200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.77 |
.rsrc | 0x46e000 | 0xab650 | 0xab800 | 0x69e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.84 |
.reloc | 0x51a000 | 0x5580 | 0x5600 | 0x115600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 4.31 |
Imports (11)
»
KERNEL32.dll (84)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetProcessHeap | 0x0 | 0x44d084 | 0x67ea0 | 0x672a0 | 0x2ba |
GetOEMCP | 0x0 | 0x44d088 | 0x67ea4 | 0x672a4 | 0x2a0 |
GetACP | 0x0 | 0x44d08c | 0x67ea8 | 0x672a8 | 0x1be |
IsValidCodePage | 0x0 | 0x44d090 | 0x67eac | 0x672ac | 0x38d |
SetFilePointerEx | 0x0 | 0x44d094 | 0x67eb0 | 0x672b0 | 0x509 |
ReadFile | 0x0 | 0x44d098 | 0x67eb4 | 0x672b4 | 0x458 |
GetFileType | 0x0 | 0x44d09c | 0x67eb8 | 0x672b8 | 0x257 |
GetConsoleMode | 0x0 | 0x44d0a0 | 0x67ebc | 0x672bc | 0x208 |
GetConsoleCP | 0x0 | 0x44d0a4 | 0x67ec0 | 0x672c0 | 0x1f6 |
FlushFileBuffers | 0x0 | 0x44d0a8 | 0x67ec4 | 0x672c4 | 0x1ad |
IsDebuggerPresent | 0x0 | 0x44d0ac | 0x67ec8 | 0x672c8 | 0x383 |
HeapSize | 0x0 | 0x44d0b0 | 0x67ecc | 0x672cc | 0x356 |
GetModuleFileNameW | 0x0 | 0x44d0b4 | 0x67ed0 | 0x672d0 | 0x27d |
WriteFile | 0x0 | 0x44d0b8 | 0x67ed4 | 0x672d4 | 0x5f1 |
GetStdHandle | 0x0 | 0x44d0bc | 0x67ed8 | 0x672d8 | 0x2dd |
EnumSystemLocalesW | 0x0 | 0x44d0c0 | 0x67edc | 0x672dc | 0x161 |
GetUserDefaultLCID | 0x0 | 0x44d0c4 | 0x67ee0 | 0x672e0 | 0x31a |
IsValidLocale | 0x0 | 0x44d0c8 | 0x67ee4 | 0x672e4 | 0x38f |
GetLocaleInfoW | 0x0 | 0x44d0cc | 0x67ee8 | 0x672e8 | 0x26e |
GetEnvironmentStringsW | 0x0 | 0x44d0d0 | 0x67eec | 0x672ec | 0x240 |
FreeEnvironmentStringsW | 0x0 | 0x44d0d4 | 0x67ef0 | 0x672f0 | 0x1b7 |
HeapReAlloc | 0x0 | 0x44d0d8 | 0x67ef4 | 0x672f4 | 0x354 |
SetFilePointer | 0x0 | 0x44d0dc | 0x67ef8 | 0x672f8 | 0x508 |
DeleteFileW | 0x0 | 0x44d0e0 | 0x67efc | 0x672fc | 0x123 |
ReadConsoleW | 0x0 | 0x44d0e4 | 0x67f00 | 0x67300 | 0x456 |
OutputDebugStringW | 0x0 | 0x44d0e8 | 0x67f04 | 0x67304 | 0x415 |
LoadLibraryW | 0x0 | 0x44d0ec | 0x67f08 | 0x67308 | 0x3c3 |
SetStdHandle | 0x0 | 0x44d0f0 | 0x67f0c | 0x6730c | 0x52f |
WriteConsoleW | 0x0 | 0x44d0f4 | 0x67f10 | 0x67310 | 0x5f0 |
CreateFileW | 0x0 | 0x44d0f8 | 0x67f14 | 0x67314 | 0xd6 |
SetEndOfFile | 0x0 | 0x44d0fc | 0x67f18 | 0x67318 | 0x4f6 |
GetUserDefaultLangID | 0x0 | 0x44d100 | 0x67f1c | 0x6731c | 0x31b |
EnumTimeFormatsA | 0x0 | 0x44d104 | 0x67f20 | 0x67320 | 0x162 |
QueryPerformanceCounter | 0x0 | 0x44d108 | 0x67f24 | 0x67324 | 0x43c |
GetPriorityClass | 0x0 | 0x44d10c | 0x67f28 | 0x67328 | 0x2aa |
CreateEventA | 0x0 | 0x44d110 | 0x67f2c | 0x6732c | 0xc7 |
CloseHandle | 0x0 | 0x44d114 | 0x67f30 | 0x67330 | 0x8e |
GetFileInformationByHandle | 0x0 | 0x44d118 | 0x67f34 | 0x67334 | 0x250 |
LoadResource | 0x0 | 0x44d11c | 0x67f38 | 0x67338 | 0x3c6 |
WaitForSingleObject | 0x0 | 0x44d120 | 0x67f3c | 0x6733c | 0x5bb |
GetLastError | 0x0 | 0x44d124 | 0x67f40 | 0x67340 | 0x26a |
GetCurrentProcess | 0x0 | 0x44d128 | 0x67f44 | 0x67344 | 0x223 |
VirtualAlloc | 0x0 | 0x44d12c | 0x67f48 | 0x67348 | 0x5ab |
IsProcessorFeaturePresent | 0x0 | 0x44d130 | 0x67f4c | 0x6734c | 0x388 |
GetModuleHandleW | 0x0 | 0x44d134 | 0x67f50 | 0x67350 | 0x281 |
GetStartupInfoW | 0x0 | 0x44d138 | 0x67f54 | 0x67354 | 0x2d7 |
TlsFree | 0x0 | 0x44d13c | 0x67f58 | 0x67358 | 0x582 |
TlsSetValue | 0x0 | 0x44d140 | 0x67f5c | 0x6735c | 0x584 |
TlsGetValue | 0x0 | 0x44d144 | 0x67f60 | 0x67360 | 0x583 |
TlsAlloc | 0x0 | 0x44d148 | 0x67f64 | 0x67364 | 0x581 |
TerminateProcess | 0x0 | 0x44d14c | 0x67f68 | 0x67368 | 0x56f |
SetLastError | 0x0 | 0x44d150 | 0x67f6c | 0x6736c | 0x517 |
SetUnhandledExceptionFilter | 0x0 | 0x44d154 | 0x67f70 | 0x67370 | 0x550 |
UnhandledExceptionFilter | 0x0 | 0x44d158 | 0x67f74 | 0x67374 | 0x590 |
GetCPInfo | 0x0 | 0x44d15c | 0x67f78 | 0x67378 | 0x1cd |
FindResourceExW | 0x0 | 0x44d160 | 0x67f7c | 0x6737c | 0x1a3 |
GetCurrentProcessId | 0x0 | 0x44d164 | 0x67f80 | 0x67380 | 0x224 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x44d168 | 0x67f84 | 0x67384 | 0x366 |
GetCommandLineA | 0x0 | 0x44d16c | 0x67f88 | 0x67388 | 0x1e2 |
LoadLibraryExW | 0x0 | 0x44d170 | 0x67f8c | 0x6738c | 0x3c2 |
GlobalAlloc | 0x0 | 0x44d174 | 0x67f90 | 0x67390 | 0x335 |
LCMapStringW | 0x0 | 0x44d178 | 0x67f94 | 0x67394 | 0x3b1 |
GetModuleFileNameA | 0x0 | 0x44d17c | 0x67f98 | 0x67398 | 0x27c |
InterlockedIncrement | 0x0 | 0x44d180 | 0x67f9c | 0x6739c | 0x371 |
InterlockedDecrement | 0x0 | 0x44d184 | 0x67fa0 | 0x673a0 | 0x36d |
EnterCriticalSection | 0x0 | 0x44d188 | 0x67fa4 | 0x673a4 | 0x140 |
LeaveCriticalSection | 0x0 | 0x44d18c | 0x67fa8 | 0x673a8 | 0x3bd |
DeleteCriticalSection | 0x0 | 0x44d190 | 0x67fac | 0x673ac | 0x11e |
Sleep | 0x0 | 0x44d194 | 0x67fb0 | 0x673b0 | 0x55f |
EncodePointer | 0x0 | 0x44d198 | 0x67fb4 | 0x673b4 | 0x13c |
DecodePointer | 0x0 | 0x44d19c | 0x67fb8 | 0x673b8 | 0x117 |
WideCharToMultiByte | 0x0 | 0x44d1a0 | 0x67fbc | 0x673bc | 0x5dd |
MultiByteToWideChar | 0x0 | 0x44d1a4 | 0x67fc0 | 0x673c0 | 0x3ec |
GetStringTypeW | 0x0 | 0x44d1a8 | 0x67fc4 | 0x673c4 | 0x2e2 |
ExitProcess | 0x0 | 0x44d1ac | 0x67fc8 | 0x673c8 | 0x16d |
GetModuleHandleExW | 0x0 | 0x44d1b0 | 0x67fcc | 0x673cc | 0x280 |
GetProcAddress | 0x0 | 0x44d1b4 | 0x67fd0 | 0x673d0 | 0x2b5 |
AreFileApisANSI | 0x0 | 0x44d1b8 | 0x67fd4 | 0x673d4 | 0x2c |
HeapFree | 0x0 | 0x44d1bc | 0x67fd8 | 0x673d8 | 0x351 |
HeapAlloc | 0x0 | 0x44d1c0 | 0x67fdc | 0x673dc | 0x34d |
RaiseException | 0x0 | 0x44d1c4 | 0x67fe0 | 0x673e0 | 0x448 |
RtlUnwind | 0x0 | 0x44d1c8 | 0x67fe4 | 0x673e4 | 0x4ba |
GetSystemTimeAsFileTime | 0x0 | 0x44d1cc | 0x67fe8 | 0x673e8 | 0x2f4 |
GetCurrentThreadId | 0x0 | 0x44d1d0 | 0x67fec | 0x673ec | 0x228 |
USER32.dll (37)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
BeginDeferWindowPos | 0x0 | 0x44d1e8 | 0x68004 | 0x67404 | 0xd |
MoveWindow | 0x0 | 0x44d1ec | 0x68008 | 0x67408 | 0x251 |
TranslateMessage | 0x0 | 0x44d1f0 | 0x6800c | 0x6740c | 0x33b |
ShowWindow | 0x0 | 0x44d1f4 | 0x68010 | 0x67410 | 0x31c |
DrawFrameControl | 0x0 | 0x44d1f8 | 0x68014 | 0x67414 | 0xcd |
wsprintfA | 0x0 | 0x44d1fc | 0x68018 | 0x67418 | 0x375 |
DestroyWindow | 0x0 | 0x44d200 | 0x6801c | 0x6741c | 0xad |
DefWindowProcA | 0x0 | 0x44d204 | 0x68020 | 0x67420 | 0xa0 |
GetScrollInfo | 0x0 | 0x44d208 | 0x68024 | 0x67424 | 0x1a0 |
SetScrollInfo | 0x0 | 0x44d20c | 0x68028 | 0x67428 | 0x2f1 |
LoadImageA | 0x0 | 0x44d210 | 0x6802c | 0x6742c | 0x223 |
GetClassNameA | 0x0 | 0x44d214 | 0x68030 | 0x67430 | 0x123 |
SetWindowLongA | 0x0 | 0x44d218 | 0x68034 | 0x67434 | 0x308 |
GetCursorPos | 0x0 | 0x44d21c | 0x68038 | 0x67438 | 0x134 |
MessageBoxA | 0x0 | 0x44d220 | 0x6803c | 0x6743c | 0x244 |
GetClientRect | 0x0 | 0x44d224 | 0x68040 | 0x67440 | 0x126 |
SetWindowTextA | 0x0 | 0x44d228 | 0x68044 | 0x67444 | 0x30f |
DeferWindowPos | 0x0 | 0x44d22c | 0x68048 | 0x67448 | 0xa2 |
ScrollWindow | 0x0 | 0x44d230 | 0x6804c | 0x6744c | 0x2ad |
RedrawWindow | 0x0 | 0x44d234 | 0x68050 | 0x67450 | 0x282 |
UpdateWindow | 0x0 | 0x44d238 | 0x68054 | 0x67454 | 0x353 |
GetSubMenu | 0x0 | 0x44d23c | 0x68058 | 0x67458 | 0x1a5 |
EnableMenuItem | 0x0 | 0x44d240 | 0x6805c | 0x6745c | 0xe1 |
CheckMenuItem | 0x0 | 0x44d244 | 0x68060 | 0x67460 | 0x3f |
GetMenu | 0x0 | 0x44d248 | 0x68064 | 0x67464 | 0x161 |
GetSystemMetrics | 0x0 | 0x44d24c | 0x68068 | 0x67468 | 0x1a9 |
TranslateAcceleratorA | 0x0 | 0x44d250 | 0x6806c | 0x6746c | 0x338 |
CreateAcceleratorTableA | 0x0 | 0x44d254 | 0x68070 | 0x67470 | 0x59 |
SendInput | 0x0 | 0x44d258 | 0x68074 | 0x67474 | 0x2b3 |
SetFocus | 0x0 | 0x44d25c | 0x68078 | 0x67478 | 0x2d1 |
GetDialogBaseUnits | 0x0 | 0x44d260 | 0x6807c | 0x6747c | 0x139 |
SendDlgItemMessageA | 0x0 | 0x44d264 | 0x68080 | 0x67480 | 0x2af |
SetDlgItemTextA | 0x0 | 0x44d268 | 0x68084 | 0x67484 | 0x2ce |
DialogBoxIndirectParamA | 0x0 | 0x44d26c | 0x68088 | 0x67488 | 0xaf |
CreateDialogParamA | 0x0 | 0x44d270 | 0x6808c | 0x6748c | 0x65 |
EndDeferWindowPos | 0x0 | 0x44d274 | 0x68090 | 0x67490 | 0xe6 |
SendMessageA | 0x0 | 0x44d278 | 0x68094 | 0x67494 | 0x2b4 |
GDI32.dll (15)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetTextFaceA | 0x0 | 0x44d044 | 0x67e60 | 0x67260 | 0x242 |
SetWindowExtEx | 0x0 | 0x44d048 | 0x67e64 | 0x67264 | 0x2fe |
TextOutA | 0x0 | 0x44d04c | 0x67e68 | 0x67268 | 0x30a |
SetAbortProc | 0x0 | 0x44d050 | 0x67e6c | 0x6726c | 0x2cb |
SetTextColor | 0x0 | 0x44d054 | 0x67e70 | 0x67270 | 0x2f8 |
SetStretchBltMode | 0x0 | 0x44d058 | 0x67e74 | 0x67274 | 0x2f4 |
SetMapMode | 0x0 | 0x44d05c | 0x67e78 | 0x67278 | 0x2e6 |
SelectObject | 0x0 | 0x44d060 | 0x67e7c | 0x6727c | 0x2c9 |
GetViewportOrgEx | 0x0 | 0x44d064 | 0x67e80 | 0x67280 | 0x249 |
DescribePixelFormat | 0x0 | 0x44d068 | 0x67e84 | 0x67284 | 0x106 |
DeleteObject | 0x0 | 0x44d06c | 0x67e88 | 0x67288 | 0x105 |
CreateRectRgn | 0x0 | 0x44d070 | 0x67e8c | 0x6728c | 0x50 |
CreateFontIndirectA | 0x0 | 0x44d074 | 0x67e90 | 0x67290 | 0x3e |
CombineRgn | 0x0 | 0x44d078 | 0x67e94 | 0x67294 | 0x22 |
GetViewportExtEx | 0x0 | 0x44d07c | 0x67e98 | 0x67298 | 0x248 |
COMDLG32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ChooseColorA | 0x0 | 0x44d030 | 0x67e4c | 0x6724c | 0x0 |
GetOpenFileNameA | 0x0 | 0x44d034 | 0x67e50 | 0x67250 | 0xb |
ADVAPI32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptSetKeyParam | 0x0 | 0x44d000 | 0x67e1c | 0x6721c | 0xdd |
CryptEncrypt | 0x0 | 0x44d004 | 0x67e20 | 0x67220 | 0xca |
CryptImportKey | 0x0 | 0x44d008 | 0x67e24 | 0x67224 | 0xda |
CryptDestroyKey | 0x0 | 0x44d00c | 0x67e28 | 0x67228 | 0xc7 |
CryptReleaseContext | 0x0 | 0x44d010 | 0x67e2c | 0x6722c | 0xdb |
CryptAcquireContextA | 0x0 | 0x44d014 | 0x67e30 | 0x67230 | 0xc0 |
SHELL32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderPathA | 0x0 | 0x44d1d8 | 0x67ff4 | 0x673f4 | 0xed |
SHGetSpecialFolderLocation | 0x0 | 0x44d1dc | 0x67ff8 | 0x673f8 | 0xec |
SHGetMalloc | 0x0 | 0x44d1e0 | 0x67ffc | 0x673fc | 0xdc |
ole32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateBindCtx | 0x0 | 0x44d280 | 0x6809c | 0x6749c | 0x8b |
CRYPT32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CertDuplicateStore | 0x0 | 0x44d03c | 0x67e58 | 0x67258 | 0x26 |
COMCTL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x19d | 0x44d028 | 0x67e44 | 0x67244 | - |
pdh.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PdhCollectQueryData | 0x0 | 0x44d288 | 0x680a4 | 0x674a4 | 0x12 |
AUTHZ.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
AuthzInitializeResourceManager | 0x0 | 0x44d01c | 0x67e38 | 0x67238 | 0x14 |
AuthzFreeResourceManager | 0x0 | 0x44d020 | 0x67e3c | 0x6723c | 0xa |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
sgm_20190527_desfuhohdt.exe | 1 | 0x00400000 | 0x0051FFFF | Relevant Image | - | 32-bit | - |
...
|
||
sgm_20190527_desfuhohdt.exe | 1 | 0x00400000 | 0x0051FFFF | Process Termination | - | 32-bit | - |
...
|
C:\Users\aETAdzjz\AppData\Local\Temp\cab_2564_9 | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-01-25 01:00 (UTC+1) |
Last Seen | 2018-07-10 13:49 (UTC+2) |
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{F5FB2C3C-D05C-EF89-82F9-0493D63D7877}\01D51ED4E3ECF92009 | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\1FB1.bin | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\cab_2564_5 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\2855.bin | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\cab_2564_7 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\cab_2564_6 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\inf_2564_3 | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\inf_2564_4 | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ff\\3y2joh8o.default\cookies.sqlite | Dropped File | Sqlite |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\sols\macromedia.com\support\flashplayer\sys\settings.sol | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\aetadzjz@g.live[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\aetadzjz@google[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\aetadzjz@live[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@ad.360yield[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@ad13.adfarm1.adition[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@addthis[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@adfarm1.adition[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@adformdsp[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@adform[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@adnxs[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@adscale[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@adserving.ancoraplatform[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@adsrvr[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@adtech[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@advertising[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@angsrvr[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@api.bing[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@at.atwola[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@bidswitch[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@bing[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@bluekai[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@bs.serving-sys[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@bs.serving-sys[3].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@c.bing[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@c.msn[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@c1.microsoft[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@casalemedia[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@connextra[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@crwdcntrl[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@demdex[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@doubleclick[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@dpm.demdex[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@exelator[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@eyeota[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@google[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@ibeu2.mookie1[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@ih.adscale[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@linkedin[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@m.exactag[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@mathtag[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@microsoft[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@msn[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@openx[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@pixel.rubiconproject[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@pubmatic[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@rubiconproject[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@scorecardresearch[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@semasio[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@server.adformdsp[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@serving-sys[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@serving.experianmarketingservices[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@smartadserver[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@tapad[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@track.adform[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@turn[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@w55c[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@www.bing[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@www.linkedin[1].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Roaming\Microsoft\{B423FFBF-837B-066B-AD28-679A31DC8B6E}\cookie.ie\Low\aetadzjz@www.msn[2].txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\1D0E.bin1 | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\1D0E.bin1 | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\1D0E.bin1 | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\1D0E.bin1 | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\1D0E.bin1 | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\1D0E.bin1 | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\1D0E.bin1 | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\1D0E.bin1 | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\1D0E.bin1 | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\1D0E.bin1 | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\1D0E.bin | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\1D0E.bin1 | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\DB32.bin | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\cab_2128_5 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\E3D6.bin | Dropped File | Unknown |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\cab_2128_7 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\cab_2128_6 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\cab_2128_9 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\inf_2564_2 | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\inf_2128_3 | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\aETAdzjz\AppData\Local\Temp\inf_2128_4 | Dropped File | Text |
Unknown
|
...
|
»