9266d4bd...8896 | VMRay Analyzer Report
Try VMRay Analyzer
VTI SCORE: 100/100
Dynamic Analysis Report
Classification: Wiper, Ransomware, Trojan

VMRay Threat Indicators (17 rules, 612 matches)

Severity Category Operation Count Classification
5/5
Local AV Malicious content was detected by heuristic scan 1 -
5/5
Reputation Known malicious file 1 Trojan
4/5
File System Deletes user files 1 Wiper
  • Deletes multiple user files. This is an indicator for ransomware or wiper malware.
4/5
File System Modifies content of user files 1 Ransomware
  • Modifies the content of multiple user files. This is an indicator for an encryption attempt.
4/5
OS Modifies Windows automatic backups 1 -
2/5
Anti Analysis Resolves APIs dynamically to possibly evade static detection 1 -
2/5
Anti Analysis Tries to detect virtual machine 1 -
  • Possibly trying to detect VM via rdtsc.
1/5
Process Creates system object 2 -
  • Creates mutex with name "Global\syncronize_Q25317A".
  • Creates mutex with name "Global\syncronize_Q25317U".
1/5
File System Modifies operating system directory 1 -
1/5
Persistence Installs system startup script or application 5 -
  • Adds "C:\WINDOWS\System32\load0.exe" to Windows startup via registry.
  • Adds "c:\users\fd1hvy\appdata\roaming\microsoft\windows\start menu\programs\startup\load0.exe" to Windows startup folder.
  • Adds "c:\programdata\microsoft\windows\start menu\programs\startup\load0.exe" to Windows startup folder.
  • Adds "6998912" to Windows startup via registry.
  • Adds "C:\Users\FD1HVy\AppData\Roaming\load0.exe" to Windows startup via registry.
1/5
Process Creates process with hidden window 1 -
  • The process "C:\WINDOWS\system32\cmd.exe" starts with hidden window.
1/5
Masquerade Changes folder appearance 3 -
  • Folder "c:\$recycle.bin\s-1-5-21-1051304884-625712362-2192934891-1000" has a changed appearance.
  • Folder "c:\program files\common files\microsoft shared\stationery" has a changed appearance.
  • Folder "c:\program files" has a changed appearance.
1/5
Process Reads from memory of another process 2 -
  • "c:\windows\system32\cmd.exe" reads from "C:\WINDOWS\system32\mode.com".
  • "c:\windows\system32\cmd.exe" reads from "C:\WINDOWS\system32\vssadmin.exe".
1/5
File System Modifies application directory 588 -
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\officeupdateschedule.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\c2rheartbeatconfig.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\servicewatcherschedule.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\ink\fsdefinitions\main\base_heb.xml".
  • Modifies "c:\program files\common files\microsoft shared\stationery\stars.htm".
  • Modifies "c:\program files\java\jre1.8.0_144\lib\images\cursors\win32_copydrop32x32.gif.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\lib\images\cursors\win32_movedrop32x32.gif.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\lib\images\cursors\win32_linknodrop32x32.gif.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\lib\images\cursors\win32_movenodrop32x32.gif.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\lib\images\cursors\win32_linkdrop32x32.gif.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\lib\images\cursors\win32_copynodrop32x32.gif.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-0015-0409-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-0015-0000-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-0016-0409-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-0018-0409-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-0018-0000-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-0016-0000-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-0019-0000-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-001a-0000-1000-0000000ff1ce.xml".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-001a-0409-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-001b-0000-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-001b-0409-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-001a-0000-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-001f-0409-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-001f-040c-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-002c-0409-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-0054-0409-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-0057-0000-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-006e-0409-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-0090-0000-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-00a1-0000-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-0090-0409-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-00b4-0409-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-00a1-0409-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-00ba-0409-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-00ba-0000-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-00c1-0409-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-00e1-0000-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-00c1-0000-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-00e1-0409-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-00e2-0000-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-00e2-0409-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-0115-0409-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-0117-0409-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-012a-0000-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-012b-0409-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.90160000-3101-0000-1000-0000000ff1ce.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\authoredextensions.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifestloc.en-us.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\ag00052_.gif".
  • Modifies "c:\program files\microsoft office\packagemanifests\appxmanifest.common.xml.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\bd00116_.wmf".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-core-file-l1-2-0.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-core-file-l2-1-0.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-core-localization-l1-2-0.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-core-processthreads-l1-1-1.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-core-synch-l1-2-0.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-core-xstate-l2-1-0.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-crt-conio-l1-1-0.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-core-timezone-l1-1-0.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-crt-environment-l1-1-0.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-crt-filesystem-l1-1-0.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-crt-convert-l1-1-0.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-crt-locale-l1-1-0.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-crt-math-l1-1-0.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-crt-multibyte-l1-1-0.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-crt-private-l1-1-0.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-crt-process-l1-1-0.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-crt-heap-l1-1-0.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-crt-runtime-l1-1-0.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-crt-stdio-l1-1-0.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-crt-utility-l1-1-0.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-crt-time-l1-1-0.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\bs01603_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\appvisvstream32.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\bs00439_.wmf".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\bs01637_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\api-ms-win-crt-string-l1-1-0.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\bs01639_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\cg1606.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\classic1.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\classic2.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\craninst.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\crane.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\appvshnotify.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\appvscripting.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\bs01638_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\appvcleaner.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\clip.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\cup.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\cupinst.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd00234_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\c2rui.en-us.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd00117_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd00121_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\concrt140.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd00255_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\appvisvsubsystems32.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\i641033.hash.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\c2r32.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd00256_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\mavinject32.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd00261_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\integratedoffice.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\i640.hash.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd00297_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd00372_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd00407_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd00405_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\msointl30.en-us.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd00419_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\officec2rcom.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd00437_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd00414_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd00413_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\vccorlib140.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd00448_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\ucrtbase.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd00687_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd00449_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01015_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\clicktorun\officec2rclient.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd00705_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01039_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\office16\liclua.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01140_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01139_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01138_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\office16\office setup controller\pkeyconfig-office.xrm-ms.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01145_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\office16\office setup controller\pkeyconfig.companion.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01143_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\vc\msdia100.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\source engine\ose.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01151_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01146_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01157_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01152_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\office16\office setup controller\pidgenx.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\vsto\10.0\1033\vstoinstallerui.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01166_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01163_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01160_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01162_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01170_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01169_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01168_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01167_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\vsto\10.0\vstoinstaller.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\vsto\10.0\1033\vstoloaderui.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\vc\msdia90.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01176_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\vsto\10.0\vstoloader.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01172_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01171_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\vsto\10.0\vstomessageprovider.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01173_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\vsto\vstoee100.tlb".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01179_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01181_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01180_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01182_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\vsto\vstoee.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\internet explorer\signup\install.ins.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\vsto\vstoee100.tlb.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\common files\microsoft shared\vsto\vstoee90.tlb.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01183_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01366_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01434_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01186_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01629_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01630_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01631_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01761_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01628_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01586_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\dcpr.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\internet explorer\circus.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\ed00010_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01793_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\deploy.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\decora_sse.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\ed00019_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\ed00172_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\ed00184_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01772_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\en00202_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\en00006_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\en00222_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\en00319_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\en00242_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\dd01585_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\bci.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\awt.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\dtplugin\deployjava1.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\en00902_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\en00397_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\en00320_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00074_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\dt_shmem.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00086_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00076_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00077_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\dtplugin\npdeployjava1.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\dt_socket.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00297_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00096_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00296_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00090_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00336_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00369_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00397_.wmf".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\eula.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00361_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00403_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00397_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00414_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\fontmanager.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00382_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00435_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00438_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00455_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00428_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00459_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00419_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00544_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00543_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\fxplugins.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00564_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00586_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00775_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\glib-lite.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\hprof.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\glass.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\gstreamer-lite.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00779_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00799_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00965_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd00814_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\j2pkcs11.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd01074_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd01084_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd01176_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\j2pcsc.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd01191_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\instrument.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd01193_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\jaas_nt.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\jabswitch.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd01548_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd01196_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\java-rmi.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd01657_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd01658_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd01659_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd01660_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd02068_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd02088_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd02071_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd02075_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd02097_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\java.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\javacpl.cpl.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd02153_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd02116_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\javacpl.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\javaaccessbridge-64.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\java.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd02141_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd02115_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd02161_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00057_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00084_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\flap.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\javaw.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\javafx_font.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\fd02158_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\javafx_font_t2k.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\javafx_iio.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00231_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00235_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00241_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00236_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\java_crw_demo.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\jawt.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00260_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\jfr.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\javaws.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00443_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00334_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00276_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\jdwp.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\jawtaccessbridge-64.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\jjs.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\jli.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00527_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00513_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\jfxmedia.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00546_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\jp2launcher.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00601_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\jp2native.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00602_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00623_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00524_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00625_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\jpeg.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00526_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\jsdt.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00612_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00681_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00669_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00636_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\jp2iexp.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\jp2ssv.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\jfxwebkit.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\jsound.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\jsoundds.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\kcms.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00693_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00688_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\klist.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\kinit.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\ktab.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\keytool.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00687_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh00685_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\lcms.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\management.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh01015_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh01013_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\msvcp120.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh01065_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\mlib_image.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh01058_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\msvcr100.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh01080_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh01291_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\net.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh01329_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh01461_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh01618_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh01759_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\msvcr120.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\nio.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\npt.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh01875_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh01923_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\pack200.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh02155_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\plugin2\msvcr100.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh01242_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\orbd.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh02166_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh02282_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\policytool.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh02312_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh02298_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\prism_common.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\policytool.exe".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\prism_sw.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hh02313_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hm00005_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\prism_d3d.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\resource.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\rmid.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\server\classes.jsa.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\rmiregistry.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hm00426_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\servertool.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hm00172_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hm00114_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\hm00116_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\ssvagent.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\splashscreen.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\in00046_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\in00118_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\ssv.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\sunmscapi.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\in00204_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\in00346_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\in00177_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\sunec.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\in00343_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\t2k.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\in00915_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\in00557_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\in00351_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\server\jvm.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\tnameserv.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\in00233_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\in00919_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\in00957_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\unpack.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\in00956_.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\unpack200.exe.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\j0075478.gif.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\w2k_lsa_auth.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\java\jre1.8.0_144\bin\verify.dll.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\j0086424.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\j0086384.wmf.id-b4197730.[bitcharity@protonmail.com].com".
  • Modifies "c:\program files\microsoft office\root\clipart\pub60cor\j0086420.wmf.id-b4197730.[bitcharity@protonmail.com].com".
1/5
Information Stealing Possibly does reconnaissance 1 -
  • Possibly trying to gather information about application "Mozilla Firefox" by file.
1/5
File System Creates an unusually large number of files 1 -
0/5
Process Enumerates running processes 1 -

Screenshots

Monitored Processes

Sample Information

ID #637077
MD5 a722665c4fc7298f00a31ac652dc02d2 Copy to Clipboard
SHA1 4aec87eb4d697b398b0d602194cdd45cd595e502 Copy to Clipboard
SHA256 9266d4bdcb7351e4c4025371b968e96197628b342e37c3c428787d47217a8896 Copy to Clipboard
SSDeep 3072:Jm7kVpR2W/G4nqjrpThO0L+3vuZGe0Mp6U924SFcszDnVZlIKG0:8AVpznqj9hO0LAdOt/YHz7TG Copy to Clipboard
ImpHash 466d1e61fd89730ab51b69612c8384b7 Copy to Clipboard
Filename load0.exe
File Size 249.50 KB
Sample Type Windows Exe (x86-32)

Analysis Information

Creation Time 2019-05-03 14:22 (UTC+2)
Analysis Duration 00:05:08
Number of Monitored Processes 15
Execution Successful True
Reputation Enabled True
WHOIS Enabled True
Local AV Enabled True
YARA Enabled True
Number of AV Matches 1
Number of YARA Matches 0
Termination Reason Maximum binlog size reached
Tags
Function Logfile
Exit-Icon

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Before

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
After

This feature requires an online-connection to the VMRay backend.

An offline version with limited functionality is also provided.
The offline version is supported only in Mozilla Firefoxwith deactivated setting "security.fileuri.strict_origin_policy".


    
Screenshot
Expand-Icon
Exit-Icon
icon_left
icon_left
image