Downloader Ransomware
STOP Djvu Mal/HTMLGen-A Mal/Generic-S
Created on 2022-08-05T13:58:47+00:00
0336cc8aff0e4974ede9e8901abeb10f836d50619cef1cb59aa41b447cea1ca5.exe
Remarks (2/3)
(0x0200001B): The maximum number of file Reputation Analysis requests per analysis (150) was exceeded.
(0x0200000E): The overall sleep time of all monitored processes was truncated from "22 minutes" to "20 seconds" to reveal dormant functionality.
Remarks
(0x0200005D): 275 additional dumps with the reason "Content Changed" and a total of 334 MB were skipped because the respective maximum limit was reached.
(0x0200004A): 16 dump(s) were skipped because they exceeded the maximum dump size of 16 MB. The largest one was 380 MB.
(0x0200004F): Static Analysis failed to analyze file artifacts in this analysis due to an error. Check the artifact_static_analysis.log file for further information.
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\kEecfMwgj\Desktop\0336cc8aff0e4974ede9e8901abeb10f836d50619cef1cb59aa41b447cea1ca5.exe | Sample File | Binary |
Malicious
|
...
|
Verdict |
Malicious
|
Image Base | 0x00400000 |
Entry Point | 0x004984B0 |
Size Of Code | 0x000A5E00 |
Size Of Initialized Data | 0x0209EA00 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2021-09-09 10:02 (UTC+2) |
FileVersions | 48.90.12.34 |
Copyrighz | Copyright (C) 2022, pozkarte |
ProjectVersion | 94.4.7.88 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000A5DCE | 0x000A5E00 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.95 |
.data | 0x004A7000 | 0x020861CC | 0x00003000 | 0x000A6200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.75 |
.rsrc | 0x0252E000 | 0x0000F550 | 0x0000F600 | 0x000A9200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.22 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetModuleFileNameA | - | 0x00401000 | 0x000A6328 | 0x000A5728 | 0x00000213 |
FoldStringA | - | 0x00401004 | 0x000A632C | 0x000A572C | 0x0000015B |
GetLocalTime | - | 0x00401008 | 0x000A6330 | 0x000A5730 | 0x00000203 |
InterlockedDecrement | - | 0x0040100C | 0x000A6334 | 0x000A5734 | 0x000002EB |
GetLocaleInfoA | - | 0x00401010 | 0x000A6338 | 0x000A5738 | 0x00000204 |
InterlockedCompareExchange | - | 0x00401014 | 0x000A633C | 0x000A573C | 0x000002E9 |
_hwrite | - | 0x00401018 | 0x000A6340 | 0x000A5740 | 0x00000536 |
CancelWaitableTimer | - | 0x0040101C | 0x000A6344 | 0x000A5744 | 0x00000047 |
GetSystemDirectoryW | - | 0x00401020 | 0x000A6348 | 0x000A5748 | 0x00000270 |
CreateEventW | - | 0x00401024 | 0x000A634C | 0x000A574C | 0x00000085 |
ReadConsoleA | - | 0x00401028 | 0x000A6350 | 0x000A5750 | 0x000003B4 |
BuildCommDCBA | - | 0x0040102C | 0x000A6354 | 0x000A5754 | 0x0000003A |
GetConsoleAliasExesLengthW | - | 0x00401030 | 0x000A6358 | 0x000A5758 | 0x00000193 |
SetSystemTimeAdjustment | - | 0x00401034 | 0x000A635C | 0x000A575C | 0x0000048C |
PeekConsoleInputW | - | 0x00401038 | 0x000A6360 | 0x000A5760 | 0x0000038C |
EnumDateFormatsA | - | 0x0040103C | 0x000A6364 | 0x000A5764 | 0x000000F4 |
CreateFileW | - | 0x00401040 | 0x000A6368 | 0x000A5768 | 0x0000008F |
RegisterWaitForSingleObjectEx | - | 0x00401044 | 0x000A636C | 0x000A576C | 0x000003F6 |
LoadLibraryW | - | 0x00401048 | 0x000A6370 | 0x000A5770 | 0x0000033F |
VerifyVersionInfoW | - | 0x0040104C | 0x000A6374 | 0x000A5774 | 0x000004E8 |
WaitNamedPipeA | - | 0x00401050 | 0x000A6378 | 0x000A5778 | 0x000004FF |
GetEnvironmentStrings | - | 0x00401054 | 0x000A637C | 0x000A577C | 0x000001D8 |
FindResourceExA | - | 0x00401058 | 0x000A6380 | 0x000A5780 | 0x0000014C |
VirtualProtect | - | 0x0040105C | 0x000A6384 | 0x000A5784 | 0x000004EF |
GetFirmwareEnvironmentVariableW | - | 0x00401060 | 0x000A6388 | 0x000A5788 | 0x000001F7 |
BeginUpdateResourceW | - | 0x00401064 | 0x000A638C | 0x000A578C | 0x00000038 |
WriteConsoleA | - | 0x00401068 | 0x000A6390 | 0x000A5790 | 0x0000051A |
EnumCalendarInfoExA | - | 0x0040106C | 0x000A6394 | 0x000A5794 | 0x000000F0 |
WriteConsoleW | - | 0x00401070 | 0x000A6398 | 0x000A5798 | 0x00000524 |
DeleteFileW | - | 0x00401074 | 0x000A639C | 0x000A579C | 0x000000D6 |
FillConsoleOutputCharacterA | - | 0x00401078 | 0x000A63A0 | 0x000A57A0 | 0x00000127 |
GetProcAddress | - | 0x0040107C | 0x000A63A4 | 0x000A57A4 | 0x00000245 |
GetModuleHandleW | - | 0x00401080 | 0x000A63A8 | 0x000A57A8 | 0x00000218 |
GetUserDefaultLCID | - | 0x00401084 | 0x000A63AC | 0x000A57AC | 0x0000029B |
FindFirstChangeNotificationA | - | 0x00401088 | 0x000A63B0 | 0x000A57B0 | 0x00000130 |
GetFileAttributesExA | - | 0x0040108C | 0x000A63B4 | 0x000A57B4 | 0x000001E6 |
GetCalendarInfoA | - | 0x00401090 | 0x000A63B8 | 0x000A57B8 | 0x00000179 |
SetConsoleTitleA | - | 0x00401094 | 0x000A63BC | 0x000A57BC | 0x00000447 |
GetBinaryTypeW | - | 0x00401098 | 0x000A63C0 | 0x000A57C0 | 0x00000171 |
GlobalAlloc | - | 0x0040109C | 0x000A63C4 | 0x000A57C4 | 0x000002B3 |
GetComputerNameExA | - | 0x004010A0 | 0x000A63C8 | 0x000A57C8 | 0x0000018D |
FindNextFileA | - | 0x004010A4 | 0x000A63CC | 0x000A57CC | 0x00000143 |
OpenJobObjectA | - | 0x004010A8 | 0x000A63D0 | 0x000A57D0 | 0x0000037A |
HeapSize | - | 0x004010AC | 0x000A63D4 | 0x000A57D4 | 0x000002D4 |
_lclose | - | 0x004010B0 | 0x000A63D8 | 0x000A57D8 | 0x00000537 |
GetComputerNameW | - | 0x004010B4 | 0x000A63DC | 0x000A57DC | 0x0000018F |
TlsGetValue | - | 0x004010B8 | 0x000A63E0 | 0x000A57E0 | 0x000004C7 |
SetCalendarInfoW | - | 0x004010BC | 0x000A63E4 | 0x000A57E4 | 0x0000041F |
SetComputerNameA | - | 0x004010C0 | 0x000A63E8 | 0x000A57E8 | 0x00000427 |
CreateDirectoryExA | - | 0x004010C4 | 0x000A63EC | 0x000A57EC | 0x0000007D |
InitializeCriticalSectionAndSpinCount | - | 0x004010C8 | 0x000A63F0 | 0x000A57F0 | 0x000002E3 |
GetVolumePathNameA | - | 0x004010CC | 0x000A63F4 | 0x000A57F4 | 0x000002AA |
GetProcessHandleCount | - | 0x004010D0 | 0x000A63F8 | 0x000A57F8 | 0x00000249 |
GetThreadLocale | - | 0x004010D4 | 0x000A63FC | 0x000A57FC | 0x0000028C |
GetSystemDefaultLangID | - | 0x004010D8 | 0x000A6400 | 0x000A5800 | 0x0000026C |
GetCurrentProcess | - | 0x004010DC | 0x000A6404 | 0x000A5804 | 0x000001C0 |
LoadLibraryA | - | 0x004010E0 | 0x000A6408 | 0x000A5808 | 0x0000033C |
ReadFile | - | 0x004010E4 | 0x000A640C | 0x000A580C | 0x000003C0 |
HeapFree | - | 0x004010E8 | 0x000A6410 | 0x000A5810 | 0x000002CF |
GetDiskFreeSpaceW | - | 0x004010EC | 0x000A6414 | 0x000A5814 | 0x000001CF |
GetProcessHeap | - | 0x004010F0 | 0x000A6418 | 0x000A5818 | 0x0000024A |
RaiseException | - | 0x004010F4 | 0x000A641C | 0x000A581C | 0x000003B1 |
RtlUnwind | - | 0x004010F8 | 0x000A6420 | 0x000A5820 | 0x00000418 |
MultiByteToWideChar | - | 0x004010FC | 0x000A6424 | 0x000A5824 | 0x00000367 |
GetCommandLineW | - | 0x00401100 | 0x000A6428 | 0x000A5828 | 0x00000187 |
HeapSetInformation | - | 0x00401104 | 0x000A642C | 0x000A582C | 0x000002D3 |
GetStartupInfoW | - | 0x00401108 | 0x000A6430 | 0x000A5830 | 0x00000263 |
EncodePointer | - | 0x0040110C | 0x000A6434 | 0x000A5834 | 0x000000EA |
HeapAlloc | - | 0x00401110 | 0x000A6438 | 0x000A5838 | 0x000002CB |
GetLastError | - | 0x00401114 | 0x000A643C | 0x000A583C | 0x00000202 |
IsProcessorFeaturePresent | - | 0x00401118 | 0x000A6440 | 0x000A5840 | 0x00000304 |
DecodePointer | - | 0x0040111C | 0x000A6444 | 0x000A5844 | 0x000000CA |
TlsAlloc | - | 0x00401120 | 0x000A6448 | 0x000A5848 | 0x000004C5 |
TlsSetValue | - | 0x00401124 | 0x000A644C | 0x000A584C | 0x000004C8 |
TlsFree | - | 0x00401128 | 0x000A6450 | 0x000A5850 | 0x000004C6 |
InterlockedIncrement | - | 0x0040112C | 0x000A6454 | 0x000A5854 | 0x000002EF |
SetLastError | - | 0x00401130 | 0x000A6458 | 0x000A5858 | 0x00000473 |
GetCurrentThreadId | - | 0x00401134 | 0x000A645C | 0x000A585C | 0x000001C5 |
SetHandleCount | - | 0x00401138 | 0x000A6460 | 0x000A5860 | 0x0000046F |
GetStdHandle | - | 0x0040113C | 0x000A6464 | 0x000A5864 | 0x00000264 |
GetFileType | - | 0x00401140 | 0x000A6468 | 0x000A5868 | 0x000001F3 |
DeleteCriticalSection | - | 0x00401144 | 0x000A646C | 0x000A586C | 0x000000D1 |
SetFilePointer | - | 0x00401148 | 0x000A6470 | 0x000A5870 | 0x00000466 |
UnhandledExceptionFilter | - | 0x0040114C | 0x000A6474 | 0x000A5874 | 0x000004D3 |
SetUnhandledExceptionFilter | - | 0x00401150 | 0x000A6478 | 0x000A5878 | 0x000004A5 |
IsDebuggerPresent | - | 0x00401154 | 0x000A647C | 0x000A587C | 0x00000300 |
TerminateProcess | - | 0x00401158 | 0x000A6480 | 0x000A5880 | 0x000004C0 |
EnterCriticalSection | - | 0x0040115C | 0x000A6484 | 0x000A5884 | 0x000000EE |
LeaveCriticalSection | - | 0x00401160 | 0x000A6488 | 0x000A5888 | 0x00000339 |
ExitProcess | - | 0x00401164 | 0x000A648C | 0x000A588C | 0x00000119 |
GetCPInfo | - | 0x00401168 | 0x000A6490 | 0x000A5890 | 0x00000172 |
GetACP | - | 0x0040116C | 0x000A6494 | 0x000A5894 | 0x00000168 |
GetOEMCP | - | 0x00401170 | 0x000A6498 | 0x000A5898 | 0x00000237 |
IsValidCodePage | - | 0x00401174 | 0x000A649C | 0x000A589C | 0x0000030A |
CloseHandle | - | 0x00401178 | 0x000A64A0 | 0x000A58A0 | 0x00000052 |
WriteFile | - | 0x0040117C | 0x000A64A4 | 0x000A58A4 | 0x00000525 |
GetModuleFileNameW | - | 0x00401180 | 0x000A64A8 | 0x000A58A8 | 0x00000214 |
FreeEnvironmentStringsW | - | 0x00401184 | 0x000A64AC | 0x000A58AC | 0x00000161 |
GetEnvironmentStringsW | - | 0x00401188 | 0x000A64B0 | 0x000A58B0 | 0x000001DA |
HeapCreate | - | 0x0040118C | 0x000A64B4 | 0x000A58B4 | 0x000002CD |
QueryPerformanceCounter | - | 0x00401190 | 0x000A64B8 | 0x000A58B8 | 0x000003A7 |
GetTickCount | - | 0x00401194 | 0x000A64BC | 0x000A58BC | 0x00000293 |
GetCurrentProcessId | - | 0x00401198 | 0x000A64C0 | 0x000A58C0 | 0x000001C1 |
GetSystemTimeAsFileTime | - | 0x0040119C | 0x000A64C4 | 0x000A58C4 | 0x00000279 |
Sleep | - | 0x004011A0 | 0x000A64C8 | 0x000A58C8 | 0x000004B2 |
SetStdHandle | - | 0x004011A4 | 0x000A64CC | 0x000A58CC | 0x00000487 |
WideCharToMultiByte | - | 0x004011A8 | 0x000A64D0 | 0x000A58D0 | 0x00000511 |
GetConsoleCP | - | 0x004011AC | 0x000A64D4 | 0x000A58D4 | 0x0000019A |
GetConsoleMode | - | 0x004011B0 | 0x000A64D8 | 0x000A58D8 | 0x000001AC |
FlushFileBuffers | - | 0x004011B4 | 0x000A64DC | 0x000A58DC | 0x00000157 |
CreateFileA | - | 0x004011B8 | 0x000A64E0 | 0x000A58E0 | 0x00000088 |
LCMapStringW | - | 0x004011BC | 0x000A64E4 | 0x000A58E4 | 0x0000032D |
GetStringTypeW | - | 0x004011C0 | 0x000A64E8 | 0x000A58E8 | 0x00000269 |
HeapReAlloc | - | 0x004011C4 | 0x000A64EC | 0x000A58EC | 0x000002D2 |
SetEndOfFile | - | 0x004011C8 | 0x000A64F0 | 0x000A58F0 | 0x00000453 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ClientToScreen | - | 0x004011D0 | 0x000A64F8 | 0x000A58F8 | 0x00000047 |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
buffer | 1 | 0x00210020 | 0x002A111F | First Execution | 32-bit | 0x00210020 |
...
|
||
buffer | 1 | 0x03DB0000 | 0x03ECAFFF | First Execution | 32-bit | 0x03DB0000 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | First Execution | 32-bit | 0x00424141 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00423F84 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004278D5 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00425141 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042C0F0 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042A06D |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0043B021 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00420C62 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042D8D0 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00431F64 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00432012 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042403E |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00427C68 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00421881 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00425007 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004C55BE |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004548D0 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00449000 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0044D0CB |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0044B550 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042C160 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00401000 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0040A260 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041CC50 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00419E70 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0040CF10 |
...
|
||
buffer | 2 | 0x00188000 | 0x0018FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | First Network Behavior | 32-bit | 0x0040D000 |
...
|
||
buffer | 2 | 0x0073F1C8 | 0x0073F583 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0073F590 | 0x0073FD8F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0073FD98 | 0x0073FE5F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0073FE68 | 0x0073FEFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x007400F8 | 0x00740221 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x007402F8 | 0x00740387 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00740430 | 0x00740505 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x007405D0 | 0x0074065B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00740668 | 0x00740E67 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00740E70 | 0x00740EEF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00740EF8 | 0x00741117 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x007416E8 | 0x0074177C | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00741928 | 0x007419BF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x007419C8 | 0x007422B3 | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 2 | 0x02600000 | 0x0263FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00413FF0 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041B680 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Final Dump | 32-bit | 0x0040D2DB |
...
|
||
buffer | 2 | 0x0073F1C8 | 0x0073F583 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0073F590 | 0x0073FD8F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0073FD98 | 0x0073FE5F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0073FE68 | 0x0073FEFF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x007400F8 | 0x00740221 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x007402F8 | 0x00740387 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x00740430 | 0x00740505 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x007405D0 | 0x0074065B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x00740668 | 0x00740E67 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x00740E70 | 0x00740EEF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x00740EF8 | 0x00741117 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x007416E8 | 0x0074177C | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x00741928 | 0x007419BF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x007419C8 | 0x007422B3 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x00757600 | 0x0075785B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0075C210 | 0x0075CA0F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x008158B0 | 0x0081593F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x029F48E0 | 0x029F496F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02A09908 | 0x02A09B63 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02A17940 | 0x02A1822B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02A18238 | 0x02A18A47 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02A18A50 | 0x02A18CAB | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02A18CB8 | 0x02A18F13 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02A18F20 | 0x02A1917B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02A19188 | 0x02A193E3 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02A193F0 | 0x02A1964B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02A19658 | 0x02A198B3 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02A51960 | 0x02A51BBB | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02A554A0 | 0x02A556FB | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02A55708 | 0x02A55827 | Final Dump | 32-bit | - |
...
|
||
index.dat | 2 | 0x02600000 | 0x0263FFFF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00433F99 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042D51E |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004CB520 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041D0B0 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004CA6F7 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x0073F590 | 0x0073FD8F | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x0073FD98 | 0x0073FE5F | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x0073FE68 | 0x0073FEFF | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x007400F8 | 0x00740221 | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x007402F8 | 0x00740387 | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x00740430 | 0x00740505 | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x007405D0 | 0x0074065B | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x00740E70 | 0x00740EEF | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x00740EF8 | 0x00741117 | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x007416E8 | 0x0074177C | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x00741928 | 0x007419BF | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x00757600 | 0x0075785B | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x007AF2B0 | 0x007AF34F | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02A09908 | 0x02A09B63 | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02A18A50 | 0x02A18CAB | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02A18CB8 | 0x02A18F13 | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02A18F20 | 0x02A1917B | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02A19188 | 0x02A193E3 | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02A193F0 | 0x02A1964B | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02A19658 | 0x02A198B3 | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02A51960 | 0x02A51BBB | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02A554A0 | 0x02A556FB | Process Termination | 32-bit | - |
...
|
||
index.dat | 2 | 0x02600000 | 0x0263FFFF | Process Termination | 32-bit | - |
...
|
||
buffer | 5 | 0x02540020 | 0x025D111F | First Execution | 32-bit | 0x02540020 |
...
|
||
buffer | 5 | 0x03EB0000 | 0x03FCAFFF | First Execution | 32-bit | 0x03EB0000 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | First Execution | 32-bit | 0x00424141 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00423F84 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004278D5 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00425141 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042C0F0 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042A06D |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0043B021 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00420C62 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042D8D0 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00431F64 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0043AF30 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0044148D |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00421881 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042B420 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004C55BE |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004548D0 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00449000 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0044D0CB |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0044B550 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00401000 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0040A260 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041CC50 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00419E70 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0040CF10 |
...
|
||
buffer | 6 | 0x00188000 | 0x0018FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x002BF228 | 0x002BF5E3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x002BF5F0 | 0x002BFDEF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x002BFDF8 | 0x002BFF0D | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x002BFF18 | 0x002BFFAF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x002C01A8 | 0x002C02D1 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x002C03A8 | 0x002C0437 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x002C04E0 | 0x002C05B5 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x002C0680 | 0x002C070B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x002C0718 | 0x002C0F17 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x002C0F20 | 0x002C0F9F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x002C0FA8 | 0x002C11C7 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x002C1798 | 0x002C182C | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x002C19D8 | 0x002C1A6F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x002C1A78 | 0x002C2363 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | First Network Behavior | 32-bit | 0x0040D000 |
...
|
||
index.dat | 6 | 0x02760000 | 0x0279FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00413FF0 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041B680 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00412220 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041A7C1 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00422587 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0043B813 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042434D |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042A77E |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042E003 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0040C6A0 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0043FBA6 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00447F50 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00430BBF |
...
|
||
buffer | 11 | 0x02540020 | 0x025D111F | First Execution | 32-bit | 0x02540020 |
...
|
||
buffer | 11 | 0x03EC0000 | 0x03FDAFFF | First Execution | 32-bit | 0x03EC0000 |
...
|
||
buffer | 12 | 0x00400000 | 0x00536FFF | First Execution | 32-bit | 0x00424141 |
...
|
||
buffer | 12 | 0x00188000 | 0x0018FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 12 | 0x002DF4A8 | 0x002DF863 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 12 | 0x002DF870 | 0x002E006F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 12 | 0x002E0078 | 0x002E0103 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 12 | 0x002E0110 | 0x002E090F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 12 | 0x002E0918 | 0x002E0997 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 12 | 0x002E09A0 | 0x002E0BBF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 12 | 0x002E1178 | 0x002E120C | First Network Behavior | 32-bit | - |
...
|
||
buffer | 12 | 0x002E13B8 | 0x002E1453 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 12 | 0x002E1718 | 0x002E1851 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 12 | 0x002E1860 | 0x002E18FB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 12 | 0x002E1AF8 | 0x002E1C21 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 12 | 0x002E1CF8 | 0x002E1D87 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 12 | 0x002E1E30 | 0x002E1F05 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 12 | 0x002E1FD0 | 0x002E28BB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 12 | 0x00400000 | 0x00536FFF | First Network Behavior | 32-bit | 0x0040CFAC |
...
|
||
index.dat | 12 | 0x001D0000 | 0x001DFFFF | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 12 | 0x001E0000 | 0x001E7FFF | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 12 | 0x002B0000 | 0x002BFFFF | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 12 | 0x02760000 | 0x0279FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 12 | 0x002DF870 | 0x002E006F | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002E0078 | 0x002E0103 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002E0918 | 0x002E0997 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002E09A0 | 0x002E0BBF | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002E1178 | 0x002E120C | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002E13B8 | 0x002E1453 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002E1718 | 0x002E1851 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002E1860 | 0x002E18FB | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002E1AF8 | 0x002E1C21 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002E1CF8 | 0x002E1D87 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002E1E30 | 0x002E1F05 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002ECEB0 | 0x002ECF31 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EDCC0 | 0x002EDD41 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EDD50 | 0x002EDDD1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EDDE0 | 0x002EDE61 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EDE70 | 0x002EDEF1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EDF00 | 0x002EDF81 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EDF90 | 0x002EE011 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EE020 | 0x002EE0A1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EE0B0 | 0x002EE131 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EE140 | 0x002EE1C1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EE1D0 | 0x002EE251 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EE260 | 0x002EE2E1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EE2F0 | 0x002EE371 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EE380 | 0x002EE401 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EE410 | 0x002EE491 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EE4A0 | 0x002EE521 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EE530 | 0x002EE5B1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EE5C0 | 0x002EE641 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EE650 | 0x002EE6D1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EE6E0 | 0x002EE761 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EE770 | 0x002EE7F1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EE800 | 0x002EE881 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EE890 | 0x002EE911 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EE920 | 0x002EE9A1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EE9B0 | 0x002EEA31 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x002EEA40 | 0x002EEAC1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x00347090 | 0x0034711F | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x00381BD0 | 0x00381CA5 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x00400000 | 0x00536FFF | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029F16C8 | 0x029F1833 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FBE28 | 0x029FC083 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FC090 | 0x029FC2EB | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FC2F8 | 0x029FC553 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FC560 | 0x029FC7BB | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FC7C8 | 0x029FCA23 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FCA30 | 0x029FCC8B | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FCC98 | 0x029FCEF3 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FCF00 | 0x029FD15B | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FD168 | 0x029FD3C3 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FD3D0 | 0x029FD62B | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FD638 | 0x029FD893 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FD8A0 | 0x029FDAFB | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FDB08 | 0x029FDD63 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FDD70 | 0x029FDFCB | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FDFD8 | 0x029FE233 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FE240 | 0x029FE49B | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FE4A8 | 0x029FE703 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FE710 | 0x029FE96B | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FE978 | 0x029FEBD3 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FEBE0 | 0x029FEE3B | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FEE48 | 0x029FF0A3 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FF0B0 | 0x029FF30B | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FF318 | 0x029FF573 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FF580 | 0x029FF7DB | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FF7E8 | 0x029FFA43 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x029FFA50 | 0x029FFCAB | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A08CF0 | 0x02A08F4B | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A08F58 | 0x02A091B3 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A091C0 | 0x02A0941B | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A09428 | 0x02A09683 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A09690 | 0x02A098EB | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A098F8 | 0x02A09B53 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A14D58 | 0x02A14FB3 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A14FC0 | 0x02A1521B | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A15228 | 0x02A15483 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A15490 | 0x02A156EB | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A156F8 | 0x02A15953 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A15960 | 0x02A15BBB | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A15BC8 | 0x02A15E23 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A15E30 | 0x02A1608B | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A16098 | 0x02A162F3 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A16300 | 0x02A1655B | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A16568 | 0x02A167C3 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A167D0 | 0x02A16A2B | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A16A38 | 0x02A16C93 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A16CA0 | 0x02A16EFB | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A16F08 | 0x02A17163 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A17170 | 0x02A173CB | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A173D8 | 0x02A17633 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A17640 | 0x02A1789B | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A178A8 | 0x02A17B03 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A17B10 | 0x02A17D6B | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A17D78 | 0x02A17FD3 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A17FE0 | 0x02A1823B | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A18248 | 0x02A184A3 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A184B0 | 0x02A1870B | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A18718 | 0x02A18973 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A18980 | 0x02A18BDB | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A1E588 | 0x02A1E7E3 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A1E7F0 | 0x02A1EA4B | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A1EA58 | 0x02A1ECB3 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A1ECC0 | 0x02A1EF1B | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A37550 | 0x02A376DF | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A70F38 | 0x02A71193 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A711A0 | 0x02A713FB | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A71408 | 0x02A71663 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A71670 | 0x02A718CB | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A718D8 | 0x02A71B33 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A71B40 | 0x02A71D9B | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A71DA8 | 0x02A72003 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A72010 | 0x02A7226B | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A72508 | 0x02A73507 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A73D20 | 0x02A7410F | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02A7C0F0 | 0x02A7C90F | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AD2260 | 0x02AD625F | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AD82A8 | 0x02ADC2A7 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02ADFE08 | 0x02ADFE97 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE3EB8 | 0x02AE3F39 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE3F48 | 0x02AE3FC9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE3FD8 | 0x02AE4059 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE4068 | 0x02AE40E9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE40F8 | 0x02AE4179 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE4188 | 0x02AE4209 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE4218 | 0x02AE4299 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE42A8 | 0x02AE4329 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE4338 | 0x02AE43B9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE43C8 | 0x02AE4449 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE4458 | 0x02AE44D9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE44E8 | 0x02AE4569 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE4578 | 0x02AE45F9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE4608 | 0x02AE4689 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE4698 | 0x02AE4719 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE4728 | 0x02AE47A9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE47B8 | 0x02AE4839 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE4848 | 0x02AE48C9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE48D8 | 0x02AE4959 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE4968 | 0x02AE49E9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE49F8 | 0x02AE4A79 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE4A88 | 0x02AE4B09 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE4B18 | 0x02AE4B99 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE4BA8 | 0x02AE4C29 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE4C38 | 0x02AE4CB9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE4CC8 | 0x02AE4D49 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE4D58 | 0x02AE4DD9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE4DE8 | 0x02AE4E69 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE4E78 | 0x02AE4EF9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE4F08 | 0x02AE4F89 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE4F98 | 0x02AE5019 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE5028 | 0x02AE50A9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE50B8 | 0x02AE5139 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE5148 | 0x02AE51C9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE51D8 | 0x02AE5259 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE5268 | 0x02AE52E9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE52F8 | 0x02AE5379 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE5388 | 0x02AE5409 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE5418 | 0x02AE5499 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE54A8 | 0x02AE5529 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE5538 | 0x02AE55B9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE55C8 | 0x02AE5649 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE5658 | 0x02AE56D9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE56E8 | 0x02AE5769 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE5778 | 0x02AE57F9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE5808 | 0x02AE5889 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE5898 | 0x02AE5919 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE5928 | 0x02AE59A9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE59B8 | 0x02AE5A39 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE5A48 | 0x02AE5AC9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE5AD8 | 0x02AE5B59 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE5B68 | 0x02AE5BE9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE5BF8 | 0x02AE5C79 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE5C88 | 0x02AE5D09 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE5D18 | 0x02AE5D99 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE5DA8 | 0x02AE5E29 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE6EB8 | 0x02AE6F39 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE6F48 | 0x02AE6FC9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE6FD8 | 0x02AE7059 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE7068 | 0x02AE70E9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE70F8 | 0x02AE7179 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE7188 | 0x02AE7209 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE7218 | 0x02AE7299 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE72A8 | 0x02AE7329 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE7338 | 0x02AE73B9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE73C8 | 0x02AE7449 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE7458 | 0x02AE74D9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE74E8 | 0x02AE7569 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE7578 | 0x02AE75F9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE7608 | 0x02AE7689 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE7698 | 0x02AE7719 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE7728 | 0x02AE77A9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE77B8 | 0x02AE7839 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE7848 | 0x02AE78C9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE78D8 | 0x02AE7959 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE7968 | 0x02AE79E9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE79F8 | 0x02AE7A79 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE7A88 | 0x02AE7B09 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE7B18 | 0x02AE7B99 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE7BA8 | 0x02AE7C29 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE7C38 | 0x02AE7CB9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE7CC8 | 0x02AE7D49 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE7D58 | 0x02AE7DD9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE7DE8 | 0x02AE7E69 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE7E78 | 0x02AE7EF9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE7F08 | 0x02AE7F89 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE7F98 | 0x02AE8019 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE8028 | 0x02AE80A9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE80B8 | 0x02AE8139 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE8148 | 0x02AE81C9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE81D8 | 0x02AE8259 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE8268 | 0x02AE82E9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE82F8 | 0x02AE8379 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE8388 | 0x02AE8409 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE8418 | 0x02AE8499 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE84A8 | 0x02AE8529 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE8538 | 0x02AE85B9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE85C8 | 0x02AE8649 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE8658 | 0x02AE86D9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE86E8 | 0x02AE8769 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE8778 | 0x02AE87F9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE8808 | 0x02AE8889 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE8898 | 0x02AE8919 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE8928 | 0x02AE89A9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE89B8 | 0x02AE8A39 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE8A48 | 0x02AE8AC9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE8AD8 | 0x02AE8B59 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE8B68 | 0x02AE8BE9 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE8BF8 | 0x02AE8C79 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE8C88 | 0x02AE8D09 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE8D18 | 0x02AE8D99 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE8DA8 | 0x02AE8E29 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AE8FE8 | 0x02AE9077 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF1FA0 | 0x02AF2021 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF2030 | 0x02AF20B1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF20C0 | 0x02AF2141 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF2150 | 0x02AF21D1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF21E0 | 0x02AF2261 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF2270 | 0x02AF22F1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF2300 | 0x02AF2381 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF2390 | 0x02AF2411 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF2420 | 0x02AF24A1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF24B0 | 0x02AF2531 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF2540 | 0x02AF25C1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF25D0 | 0x02AF2651 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF2660 | 0x02AF26E1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF26F0 | 0x02AF2771 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF2780 | 0x02AF2801 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF2810 | 0x02AF2891 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF28A0 | 0x02AF2921 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF2930 | 0x02AF29B1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF29C0 | 0x02AF2A41 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF2A50 | 0x02AF2AD1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF2AE0 | 0x02AF2B61 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF2B70 | 0x02AF2BF1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF2C00 | 0x02AF2C81 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF2C90 | 0x02AF2D11 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF2D20 | 0x02AF2DA1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF2DB0 | 0x02AF2E31 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF2E40 | 0x02AF2EC1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF2ED0 | 0x02AF2F51 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF5180 | 0x02AF5201 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF5210 | 0x02AF5291 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF52A0 | 0x02AF5321 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF5330 | 0x02AF53B1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF53C0 | 0x02AF5441 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF5450 | 0x02AF54D1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF54E0 | 0x02AF5561 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF5570 | 0x02AF55F1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF5600 | 0x02AF5681 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF5690 | 0x02AF5711 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF5720 | 0x02AF57A1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF57B0 | 0x02AF5831 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF5840 | 0x02AF58C1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF58D0 | 0x02AF5951 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF5960 | 0x02AF59E1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF59F0 | 0x02AF5A71 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF5A80 | 0x02AF5B01 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF5B10 | 0x02AF5B91 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF5BA0 | 0x02AF5C21 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF5C30 | 0x02AF5CB1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF5CC0 | 0x02AF5D41 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF5D50 | 0x02AF5DD1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF5DE0 | 0x02AF5E61 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF5E70 | 0x02AF5EF1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF5F00 | 0x02AF5F81 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF5F90 | 0x02AF6011 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF60B0 | 0x02AF6131 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF6140 | 0x02AF61C1 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF61D0 | 0x02AF6251 | Process Termination | 32-bit | - |
...
|
||
buffer | 12 | 0x02AF6260 | 0x02AF62E1 | Process Termination | 32-bit | - |
...
|
c:\users\keecfmwgj\desktop\uimsfjjz.rtf.vvyu | Dropped File | RTF |
Malicious
|
...
|
³ý¬ê&òãWIق銌O@|ëä–çÎ˯€i]lÅà:øZ¨\x81®`,‚Íp%ªîëü1‘¥·ÈŸ¿-geÓ &kÞÄKn 7C^ÃcbåB˜Å«,µRÚ\x81¥Uô¿¥0Ý £ß4½*¹5¨4 ¾i¼ŠGÎk&8#j‰Ð¾n#äGY'.‡l—¶sÅñI¬Öˆu'ÊÿI“ð6*2ª¬ŽèÎbëÍzL Œ*°®ÅfBËÿ6vÁ Q×.ie“"b³×¯ŒÁK¦|Ž-‚€x'è©QI‡ÜPp3Ô6jûƒ%=•6R.@¹³ãÈ=ÅFú˜ÆeÙði£Zv»êI°mt¢¬¦ kÏ\x8f<\x90]„,^ýÈf*\x81HD»”69Øœóoï‹,Òyñz7—q_”eO°ÌŠ±HˆÂ˜LIóŠ'é°M”wâ:Én(>¦\x8d¿ê…±Ìò$ÌíŒÌ+¨û±;íôÃ5NʸŠg@&±YÉbêŠW’b ª»x\x8d›S¢¶ß²O»\x9dzUêü'È£øj5«›B¥LSë‚7¤Û·]·žÞHVÚé†õXCzw€%O«óëÿìfý@UŸËmÍœ8÷ÅiJj–ZmÓh~OT˜sF-5()±cüJ>¿žÈÄéEœÞfú`ăØ>Ïl”hÞ)uczÒý®›÷ªÒò¤YÛv•€°F¶è[ëÍòÎŽ¤çÈo•á³¼$;ã•^¥ÈšFpAúÓì“O˜Ê%üÇØãôFfƒÔš"“fÄ0úƒPÇÎô@Ù)Çâ´ÇR÷dÄuTòèÃuÎX‹sCöàѳÍv+ó&±L–U•éRàX¢rWGŠÖ¡ k]LÊ°7Îû§Â>E¼åo?&'ÇB¢åu7–²²_åq–ßž”$ˆ˜›-`êèÀ9#—ª»gm)ZõRŽ¤þî÷™7_¿Fjö>¥CX6¢òÆK$œÜUtŠ€jz‰ÄÍãðìEX§ n¾&½ž*:zŠv´Ø…·HþA¨ÂkS–„Ùf›Íê+7ŽeÛkDv¨ßªVÖ7®’¯S°ßœœ*‡GpäýÏô—CZö¾½ü¡5‹™XãÈó™Þéwèlð‡ÁFy6²ÐŽ|y÷öŸŽ~2_¥?ç£p^+´ä¹‹¾_\x9dÊZFPs~éçiÆ ;Ø©©ú!«qp:üÏuâ¾;Ñw[R£íAêÿ¸Yš¢¦þã•K+Ì 3iýû†C~ùn…çò/s-ˆq¾ iÒ |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
c:\users\keecfmwgj\desktop\0336cc8aff0e4974ede9e8901abeb10f836d50619cef1cb59aa41b447cea1ca5.exe.vvyu | Dropped File | Binary |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\ynpbsi277\5ctq03jfokji397\f6adjjdhq\cuol988xnblbr.m4a.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Pictures\uCbdvMv01ecUQrS5kFhR.gif.vvyu | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\rwx9qkj.png.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\Eb_B9k_JDAVxhXh0\mOm18edC.mp3.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\videos\fpzctgqi5ys\wiccgss9co9ejxpugq\cjrduvousoi.swf.vvyu | Dropped File | Shockwave Flash |
Malicious
|
...
|
c:\users\keecfmwgj\documents\8nnli0koeom-mpum785\6_x m.odp.vvyu | Dropped File | ZIP |
Malicious
|
...
|
C:\Users\kEecfMwgj\Videos\FPzctgqI5yS\wICCgSS9cO9EJxpugq\wx0aR91G76sZ.flv.vvyu | Dropped File | Video |
Malicious
|
...
|
c:\users\keecfmwgj\videos\fpzctgqi5ys\wiccgss9co9ejxpugq\m0zrf.mkv.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\documents\liaafon99lah9nu_j.xlsx.vvyu | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\7p5jbw.jpg.vvyu | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\ynpbsi277\5ctq03jfokji397\v_uid 9u5nghf.docx.vvyu | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\ynpbsi277\hak2yhq7o.jpg.vvyu | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\z8twgmunehqoxqfe1k.mp3.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\music\j uck2lalp_ipp\zntr-yrixj\f8ilkitdoj8fsshi0.mp3.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\videos\9hkv.mp4.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Pictures\DvPtakSDSqUBk1s-p5E_.jpg.vvyu | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\music\j uck2lalp_ipp\47m5sv0uqvnl\ah3jwn0.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\djRHD.jpg.vvyu | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\videos\fpzctgqi5ys\0ipri83h.flv.vvyu | Dropped File | Video |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\ujyi1dwdud6-j7pcelmb.png.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\U00H4oegdjWIv9LIU5.png.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\music\26hkdh\dhvo\waqploj2c0tw.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\videos\fpzctgqi5ys\wiccgss9co9ejxpugq\acppdj.avi.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\8NNLi0kOEoM-mpUM785\hfGoG8BRVBw\DJyNf5d3ZVp0RV8Gb.docx.vvyu | Dropped File | ZIP |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\5U0VVnc3NrOc8n_Z\k8_cI3l6hV1-Y7\27Qc0VUi07zkn_VUAary.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Videos\FPzctgqI5yS\3Ad0c.mkv.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\ynpbsi277\5ctq03jfokji397\oq0h.flv.vvyu | Dropped File | Video |
Malicious
|
...
|
C:\Users\kEecfMwgj\Contacts\Administrator.contact.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\xnjf1rqetdtxtc.mkv.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\eSfxo-E.jpg.vvyu | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\videos\fpzctgqi5ys\m fzx23r02sywxh\l6ehb4ojilkrcleahkh.avi.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\ynpbsi277\bp67ry2e oyq1fpgm.mp4.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\9QfI6h6W74ZaGdKZ7l.m4a.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\videos\z x z-1adfcazuf.mkv.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\go3r.jpg.vvyu | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\9ouhy.mp3.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\documents\rn1rbbo1eqymg_q.xlsx.vvyu | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\music\j uck2lalp_ipp\dibgo7.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\26hKDH\dhVO\c-p32.m4a.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Videos\cvfGVyFL7tFjUO7\ippAwK.flv.vvyu | Dropped File | Video |
Malicious
|
...
|
c:\users\keecfmwgj\music\j uck2lalp_ipp\zntr-yrixj\mlh8upb9ymlbt.mp3.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\26hKDH\dhVO\fwWKBmZrXnqYjnf.mp3.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Pictures\hyglyDuy.bmp.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\usU4fi-1.ots.vvyu | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\ynpbsi277\5ctq03jfokji397\_dsq\ywywxyty.mp3.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\3uvy.jpg.vvyu | Dropped File | Image |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\j ucK2lALp_iPp\47m5sv0uqVNl\AZ2aRaMGzQB\5B4VEsMcGlm7c.mp3.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\videos\fpzctgqi5ys\m fzx23r02sywxh\btrak.swf.vvyu | Dropped File | Shockwave Flash |
Malicious
|
...
|
c:\users\keecfmwgj\documents\n6jq6ucc95w9.docx.vvyu | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\ynpbsi277\5ctq03jfokji397\q-8_5alv-aysztdlcx.m4a.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\ynpbsi277\5ctq03jfokji397\f6adjjdhq\adia hvz87jstj8m.flv.vvyu | Dropped File | Video |
Malicious
|
...
|
C:\Users\kEecfMwgj\Videos\cvfGVyFL7tFjUO7\NMttoz1zVMuEbci.swf.vvyu | Dropped File | Shockwave Flash |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\qg2uxz3cw8a4fuol_l.gif.vvyu | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\ynpbsi277\5ctq03jfokji397\bxv5ql2id 9hkdxpv7.swf.vvyu | Dropped File | Shockwave Flash |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\5usDb JNuS3uVdkW.xlsx.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\jkgjiq3h.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\85NDX4GNPa9.m4a.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\khh4ja_ffudblb.gif.vvyu | Dropped File | Image |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\j ucK2lALp_iPp\47m5sv0uqVNl\LPB-FW9jvpM0h.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\Eb_B9k_JDAVxhXh0\sTzvqONg_kzYduboTTT.mp3.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\documents\8nnli0koeom-mpum785\hfgog8brvbw\hsj_qr5bne5moizbn.csv.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\RUCPVLyvfQF00IxB1.xlsx.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\ooz2bcvbppeb9wsu.png.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\documents\8nnli0koeom-mpum785\hfgog8brvbw\0se02.odp.vvyu | Dropped File | ZIP |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\26hKDH\l5cha-37fB.mp3.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\documents\3_n mmyv5xkxtc1mbc-u.pdf.vvyu | Dropped File |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\vauzy4mlwuoc1eph.bmp.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\8NNLi0kOEoM-mpUM785\HIm fL\4E_Qp5b8\RAN3RZLWQzdFaTXUwx\AFrd4UxBD1.pdf.vvyu | Dropped File |
Malicious
|
...
|
C:\Users\kEecfMwgj\Videos\hA6nEQ04cdHym7b8.flv.vvyu | Dropped File | Video |
Malicious
|
...
|
c:\users\keecfmwgj\documents\8nnli0koeom-mpum785\ysw9udfa\bzhliohmivg2h0_pvvuu.pps.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\i_u5ln.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\YnPBSI277\5Ctq03jfOkJI397\_dSq\EotVe.bmp.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\-ctdcbmthlrz.jpg.vvyu | Dropped File | Image |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\j ucK2lALp_iPp\znTr-YRiXJ\0VhP5.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\3YV6ib1oIpsefRwtFe.pdf.vvyu | Dropped File |
Malicious
|
...
|
C:\Users\kEecfMwgj\Pictures\877l5thXMZRFuEmTVa.png.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\Eb_B9k_JDAVxhXh0\6X4EOyI76e.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\tqpcqxkko-qtvp1zn.bmp.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\appdata\locallow\microsoft\internet explorer\services\search_{0633ee93-d776-472f-a0ff-e1416b8b2e3a}.ico.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\ynpbsi277\ov6fzg.bmp.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\music\j uck2lalp_ipp\47m5sv0uqvnl\dvuuti6.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\92-ieu- ecANbCAHxu3.pptx.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\favorites\links\web slice gallery.url.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Favorites\Microsoft Websites\Microsoft Store.url.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Favorites\MSN Websites\MSN Money.url.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\favorites\msn websites\msnbc news.url.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\favorites\microsoft websites\microsoft at home.url.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Favorites\Microsoft Websites\Microsoft At Work.url.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\favorites\msn websites\msn sports.url.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Favorites\Windows Live\Windows Live Spaces.url.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Favorites\Windows Live\Windows Live Gallery.url.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\favorites\msn websites\msn entertainment.url.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\AppData\Local\791a7d8c-ce1c-4b10-8bdd-9a6fed24ef19\build2.exe | Downloaded File | Binary |
Malicious
|
...
|
Verdict |
Malicious
|
Names | Mal/Generic-S |
Image Base | 0x00400000 |
Entry Point | 0x0040B990 |
Size Of Code | 0x00032600 |
Size Of Initialized Data | 0x00047E00 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2022-01-04 05:28 (UTC+1) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x00032482 | 0x00032600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.75 |
.data | 0x00434000 | 0x00032988 | 0x00029A00 | 0x00032A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.94 |
.zonami | 0x00467000 | 0x00000400 | 0x00000400 | 0x0005C400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.yosozi | 0x00468000 | 0x00000400 | 0x00000400 | 0x0005C800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.may | 0x00469000 | 0x00000096 | 0x00000200 | 0x0005CC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x0046A000 | 0x000108D0 | 0x00010A00 | 0x0005CE00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.49 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VerifyVersionInfoA | - | 0x00401008 | 0x0003227C | 0x0003167C | 0x00000452 |
VerifyVersionInfoW | - | 0x0040100C | 0x00032280 | 0x00031680 | 0x00000453 |
WriteConsoleInputW | - | 0x00401010 | 0x00032284 | 0x00031684 | 0x00000486 |
EnumDateFormatsW | - | 0x00401014 | 0x00032288 | 0x00031688 | 0x000000E3 |
FindNextFileW | - | 0x00401018 | 0x0003228C | 0x0003168C | 0x00000130 |
CopyFileExA | - | 0x0040101C | 0x00032290 | 0x00031690 | 0x00000061 |
DnsHostnameToComputerNameW | - | 0x00401020 | 0x00032294 | 0x00031694 | 0x000000CF |
ReadConsoleOutputCharacterW | - | 0x00401024 | 0x00032298 | 0x00031698 | 0x00000364 |
SetConsoleActiveScreenBuffer | - | 0x00401028 | 0x0003229C | 0x0003169C | 0x000003A5 |
LockFile | - | 0x0040102C | 0x000322A0 | 0x000316A0 | 0x00000305 |
GetProfileSectionA | - | 0x00401030 | 0x000322A4 | 0x000316A4 | 0x00000231 |
QueryDosDeviceW | - | 0x00401034 | 0x000322A8 | 0x000316A8 | 0x0000034E |
IsSystemResumeAutomatic | - | 0x00401038 | 0x000322AC | 0x000316AC | 0x000002D6 |
GetProcessPriorityBoost | - | 0x0040103C | 0x000322B0 | 0x000316B0 | 0x00000228 |
GetDriveTypeW | - | 0x00401040 | 0x000322B4 | 0x000316B4 | 0x000001BB |
GlobalGetAtomNameA | - | 0x00401044 | 0x000322B8 | 0x000316B8 | 0x0000028D |
lstrlenA | - | 0x00401048 | 0x000322BC | 0x000316BC | 0x000004B5 |
FindNextVolumeMountPointW | - | 0x0040104C | 0x000322C0 | 0x000316C0 | 0x00000134 |
TlsGetValue | - | 0x00401050 | 0x000322C4 | 0x000316C4 | 0x00000434 |
SizeofResource | - | 0x00401054 | 0x000322C8 | 0x000316C8 | 0x00000420 |
WriteConsoleInputA | - | 0x00401058 | 0x000322CC | 0x000316CC | 0x00000483 |
GetConsoleTitleW | - | 0x0040105C | 0x000322D0 | 0x000316D0 | 0x0000019F |
GetComputerNameExW | - | 0x00401060 | 0x000322D4 | 0x000316D4 | 0x00000177 |
OpenEventA | - | 0x00401064 | 0x000322D8 | 0x000316D8 | 0x00000327 |
CallNamedPipeW | - | 0x00401068 | 0x000322DC | 0x000316DC | 0x00000030 |
GetModuleHandleW | - | 0x0040106C | 0x000322E0 | 0x000316E0 | 0x000001F9 |
GetSystemDirectoryA | - | 0x00401070 | 0x000322E4 | 0x000316E4 | 0x00000245 |
SetCurrentDirectoryA | - | 0x00401074 | 0x000322E8 | 0x000316E8 | 0x000003C6 |
BuildCommDCBAndTimeoutsA | - | 0x00401078 | 0x000322EC | 0x000316EC | 0x0000002C |
GetProcAddress | - | 0x0040107C | 0x000322F0 | 0x000316F0 | 0x00000220 |
GetModuleHandleA | - | 0x00401080 | 0x000322F4 | 0x000316F4 | 0x000001F6 |
MoveFileWithProgressW | - | 0x00401084 | 0x000322F8 | 0x000316F8 | 0x00000318 |
GetCommandLineW | - | 0x00401088 | 0x000322FC | 0x000316FC | 0x00000170 |
InterlockedIncrement | - | 0x0040108C | 0x00032300 | 0x00031700 | 0x000002C0 |
InterlockedExchange | - | 0x00401090 | 0x00032304 | 0x00031704 | 0x000002BD |
CopyFileW | - | 0x00401094 | 0x00032308 | 0x00031708 | 0x00000065 |
CreateActCtxW | - | 0x00401098 | 0x0003230C | 0x0003170C | 0x00000068 |
FormatMessageW | - | 0x0040109C | 0x00032310 | 0x00031710 | 0x00000148 |
EnterCriticalSection | - | 0x004010A0 | 0x00032314 | 0x00031714 | 0x000000D9 |
FindNextVolumeW | - | 0x004010A4 | 0x00032318 | 0x00031718 | 0x00000135 |
GetOverlappedResult | - | 0x004010A8 | 0x0003231C | 0x0003171C | 0x00000214 |
LoadLibraryA | - | 0x004010AC | 0x00032320 | 0x00031720 | 0x000002F1 |
CreateNamedPipeW | - | 0x004010B0 | 0x00032324 | 0x00031724 | 0x00000090 |
GetSystemDefaultLangID | - | 0x004010B4 | 0x00032328 | 0x00031728 | 0x00000242 |
GetConsoleAliasesLengthA | - | 0x004010B8 | 0x0003232C | 0x0003172C | 0x00000180 |
WriteProfileSectionW | - | 0x004010BC | 0x00032330 | 0x00031730 | 0x00000498 |
AddAtomW | - | 0x004010C0 | 0x00032334 | 0x00031734 | 0x00000004 |
InterlockedDecrement | - | 0x004010C4 | 0x00032338 | 0x00031738 | 0x000002BC |
HeapFree | - | 0x004010C8 | 0x0003233C | 0x0003173C | 0x000002A1 |
_hwrite | - | 0x004010CC | 0x00032340 | 0x00031740 | 0x0000049E |
InterlockedExchangeAdd | - | 0x004010D0 | 0x00032344 | 0x00031744 | 0x000002BE |
GetStartupInfoW | - | 0x004010D4 | 0x00032348 | 0x00031748 | 0x0000023A |
CreateMailslotW | - | 0x004010D8 | 0x0003234C | 0x0003174C | 0x00000089 |
GetCPInfoExW | - | 0x004010DC | 0x00032350 | 0x00031750 | 0x0000015D |
GetSystemWow64DirectoryW | - | 0x004010E0 | 0x00032354 | 0x00031754 | 0x00000254 |
GetLastError | - | 0x004010E4 | 0x00032358 | 0x00031758 | 0x000001E6 |
GetPrivateProfileIntA | - | 0x004010E8 | 0x0003235C | 0x0003175C | 0x00000216 |
GetConsoleAliasExesLengthW | - | 0x004010EC | 0x00032360 | 0x00031760 | 0x0000017C |
DebugBreak | - | 0x004010F0 | 0x00032364 | 0x00031764 | 0x000000B4 |
SetLastError | - | 0x004010F4 | 0x00032368 | 0x00031768 | 0x000003EC |
LoadLibraryW | - | 0x004010F8 | 0x0003236C | 0x0003176C | 0x000002F4 |
GetDefaultCommConfigA | - | 0x004010FC | 0x00032370 | 0x00031770 | 0x000001B1 |
VirtualAlloc | - | 0x00401100 | 0x00032374 | 0x00031774 | 0x00000454 |
GetACP | - | 0x00401104 | 0x00032378 | 0x00031778 | 0x00000152 |
lstrcpyA | - | 0x00401108 | 0x0003237C | 0x0003177C | 0x000004AF |
GetConsoleAliasA | - | 0x0040110C | 0x00032380 | 0x00031780 | 0x00000179 |
FindNextFileA | - | 0x00401110 | 0x00032384 | 0x00031784 | 0x0000012E |
TerminateProcess | - | 0x00401114 | 0x00032388 | 0x00031788 | 0x0000042D |
EnumResourceLanguagesA | - | 0x00401118 | 0x0003238C | 0x0003178C | 0x000000E6 |
SetConsoleTextAttribute | - | 0x0040111C | 0x00032390 | 0x00031790 | 0x000003C0 |
GlobalGetAtomNameW | - | 0x00401120 | 0x00032394 | 0x00031794 | 0x0000028E |
CreateJobSet | - | 0x00401124 | 0x00032398 | 0x00031798 | 0x00000087 |
lstrcpynA | - | 0x00401128 | 0x0003239C | 0x0003179C | 0x000004B2 |
EnumSystemLocalesA | - | 0x0040112C | 0x000323A0 | 0x000317A0 | 0x000000F8 |
GetPrivateProfileSectionNamesW | - | 0x00401130 | 0x000323A4 | 0x000317A4 | 0x0000021A |
OpenMutexW | - | 0x00401134 | 0x000323A8 | 0x000317A8 | 0x00000330 |
FileTimeToSystemTime | - | 0x00401138 | 0x000323AC | 0x000317AC | 0x00000110 |
CopyFileA | - | 0x0040113C | 0x000323B0 | 0x000317B0 | 0x00000060 |
GlobalWire | - | 0x00401140 | 0x000323B4 | 0x000317B4 | 0x00000298 |
GetTapeParameters | - | 0x00401144 | 0x000323B8 | 0x000317B8 | 0x00000255 |
lstrcmpW | - | 0x00401148 | 0x000323BC | 0x000317BC | 0x000004AA |
SetEvent | - | 0x0040114C | 0x000323C0 | 0x000317C0 | 0x000003D3 |
MoveFileA | - | 0x00401150 | 0x000323C4 | 0x000317C4 | 0x00000311 |
CreateMutexA | - | 0x00401154 | 0x000323C8 | 0x000317C8 | 0x0000008B |
FindResourceW | - | 0x00401158 | 0x000323CC | 0x000317CC | 0x00000139 |
GetCommState | - | 0x0040115C | 0x000323D0 | 0x000317D0 | 0x0000016D |
FormatMessageA | - | 0x00401160 | 0x000323D4 | 0x000317D4 | 0x00000147 |
InterlockedCompareExchange | - | 0x00401164 | 0x000323D8 | 0x000317D8 | 0x000002BA |
CreateFiber | - | 0x00401168 | 0x000323DC | 0x000317DC | 0x00000076 |
GetConsoleFontSize | - | 0x0040116C | 0x000323E0 | 0x000317E0 | 0x0000018D |
LocalAlloc | - | 0x00401170 | 0x000323E4 | 0x000317E4 | 0x000002F9 |
SetFileShortNameA | - | 0x00401174 | 0x000323E8 | 0x000317E8 | 0x000003E1 |
lstrcpyW | - | 0x00401178 | 0x000323EC | 0x000317EC | 0x000004B0 |
HeapLock | - | 0x0040117C | 0x000323F0 | 0x000317F0 | 0x000002A2 |
GetFileAttributesA | - | 0x00401180 | 0x000323F4 | 0x000317F4 | 0x000001C9 |
SetCalendarInfoW | - | 0x00401184 | 0x000323F8 | 0x000317F8 | 0x00000399 |
GetSystemWindowsDirectoryW | - | 0x00401188 | 0x000323FC | 0x000317FC | 0x00000252 |
GetConsoleAliasesW | - | 0x0040118C | 0x00032400 | 0x00031800 | 0x00000182 |
EnumDateFormatsExW | - | 0x00401190 | 0x00032404 | 0x00031804 | 0x000000E2 |
GetComputerNameW | - | 0x00401194 | 0x00032408 | 0x00031808 | 0x00000178 |
GetPrivateProfileStructW | - | 0x00401198 | 0x0003240C | 0x0003180C | 0x0000021F |
_hread | - | 0x0040119C | 0x00032410 | 0x00031810 | 0x0000049D |
LocalSize | - | 0x004011A0 | 0x00032414 | 0x00031814 | 0x00000302 |
OpenWaitableTimerA | - | 0x004011A4 | 0x00032418 | 0x00031818 | 0x00000338 |
EnumResourceNamesW | - | 0x004011A8 | 0x0003241C | 0x0003181C | 0x000000ED |
CreateFileMappingW | - | 0x004011AC | 0x00032420 | 0x00031820 | 0x0000007C |
SetUnhandledExceptionFilter | - | 0x004011B0 | 0x00032424 | 0x00031824 | 0x00000415 |
GetSystemTimeAdjustment | - | 0x004011B4 | 0x00032428 | 0x00031828 | 0x0000024E |
SetProcessShutdownParameters | - | 0x004011B8 | 0x0003242C | 0x0003182C | 0x000003F9 |
lstrcpynW | - | 0x004011BC | 0x00032430 | 0x00031830 | 0x000004B3 |
GetThreadSelectorEntry | - | 0x004011C0 | 0x00032434 | 0x00031834 | 0x00000263 |
GetNamedPipeHandleStateA | - | 0x004011C4 | 0x00032438 | 0x00031838 | 0x00000201 |
FillConsoleOutputCharacterA | - | 0x004011C8 | 0x0003243C | 0x0003183C | 0x00000112 |
GetFullPathNameW | - | 0x004011CC | 0x00032440 | 0x00031840 | 0x000001DF |
GetThreadPriority | - | 0x004011D0 | 0x00032444 | 0x00031844 | 0x00000261 |
WriteConsoleA | - | 0x004011D4 | 0x00032448 | 0x00031848 | 0x00000482 |
AddAtomA | - | 0x004011D8 | 0x0003244C | 0x0003184C | 0x00000003 |
FreeUserPhysicalPages | - | 0x004011DC | 0x00032450 | 0x00031850 | 0x00000150 |
WriteConsoleOutputCharacterW | - | 0x004011E0 | 0x00032454 | 0x00031854 | 0x0000048A |
OpenJobObjectW | - | 0x004011E4 | 0x00032458 | 0x00031858 | 0x0000032E |
CreateFileW | - | 0x004011E8 | 0x0003245C | 0x0003185C | 0x0000007F |
BuildCommDCBAndTimeoutsW | - | 0x004011EC | 0x00032460 | 0x00031860 | 0x0000002D |
GetBinaryTypeW | - | 0x004011F0 | 0x00032464 | 0x00031864 | 0x00000159 |
SetCalendarInfoA | - | 0x004011F4 | 0x00032468 | 0x00031868 | 0x00000398 |
GetFileAttributesW | - | 0x004011F8 | 0x0003246C | 0x0003186C | 0x000001CE |
GetFileInformationByHandle | - | 0x004011FC | 0x00032470 | 0x00031870 | 0x000001D0 |
GetProfileSectionW | - | 0x00401200 | 0x00032474 | 0x00031874 | 0x00000232 |
CommConfigDialogW | - | 0x00401204 | 0x00032478 | 0x00031878 | 0x0000004F |
GetDiskFreeSpaceExA | - | 0x00401208 | 0x0003247C | 0x0003187C | 0x000001B5 |
LocalFree | - | 0x0040120C | 0x00032480 | 0x00031880 | 0x000002FD |
Sleep | - | 0x00401210 | 0x00032484 | 0x00031884 | 0x00000421 |
InitializeCriticalSection | - | 0x00401214 | 0x00032488 | 0x00031888 | 0x000002B4 |
DeleteCriticalSection | - | 0x00401218 | 0x0003248C | 0x0003188C | 0x000000BE |
LeaveCriticalSection | - | 0x0040121C | 0x00032490 | 0x00031890 | 0x000002EF |
RaiseException | - | 0x00401220 | 0x00032494 | 0x00031894 | 0x0000035A |
RtlUnwind | - | 0x00401224 | 0x00032498 | 0x00031898 | 0x00000392 |
WideCharToMultiByte | - | 0x00401228 | 0x0003249C | 0x0003189C | 0x0000047A |
GetCommandLineA | - | 0x0040122C | 0x000324A0 | 0x000318A0 | 0x0000016F |
GetStartupInfoA | - | 0x00401230 | 0x000324A4 | 0x000318A4 | 0x00000239 |
HeapValidate | - | 0x00401234 | 0x000324A8 | 0x000318A8 | 0x000002A9 |
IsBadReadPtr | - | 0x00401238 | 0x000324AC | 0x000318AC | 0x000002C8 |
UnhandledExceptionFilter | - | 0x0040123C | 0x000324B0 | 0x000318B0 | 0x0000043E |
GetModuleFileNameW | - | 0x00401240 | 0x000324B4 | 0x000318B4 | 0x000001F5 |
GetCurrentProcess | - | 0x00401244 | 0x000324B8 | 0x000318B8 | 0x000001A9 |
IsDebuggerPresent | - | 0x00401248 | 0x000324BC | 0x000318BC | 0x000002D1 |
TlsAlloc | - | 0x0040124C | 0x000324C0 | 0x000318C0 | 0x00000432 |
TlsSetValue | - | 0x00401250 | 0x000324C4 | 0x000318C4 | 0x00000435 |
GetCurrentThreadId | - | 0x00401254 | 0x000324C8 | 0x000318C8 | 0x000001AD |
TlsFree | - | 0x00401258 | 0x000324CC | 0x000318CC | 0x00000433 |
GetOEMCP | - | 0x0040125C | 0x000324D0 | 0x000318D0 | 0x00000213 |
GetCPInfo | - | 0x00401260 | 0x000324D4 | 0x000318D4 | 0x0000015B |
IsValidCodePage | - | 0x00401264 | 0x000324D8 | 0x000318D8 | 0x000002DB |
SetFilePointer | - | 0x00401268 | 0x000324DC | 0x000318DC | 0x000003DF |
SetHandleCount | - | 0x0040126C | 0x000324E0 | 0x000318E0 | 0x000003E8 |
GetStdHandle | - | 0x00401270 | 0x000324E4 | 0x000318E4 | 0x0000023B |
GetFileType | - | 0x00401274 | 0x000324E8 | 0x000318E8 | 0x000001D7 |
QueryPerformanceCounter | - | 0x00401278 | 0x000324EC | 0x000318EC | 0x00000354 |
GetTickCount | - | 0x0040127C | 0x000324F0 | 0x000318F0 | 0x00000266 |
GetCurrentProcessId | - | 0x00401280 | 0x000324F4 | 0x000318F4 | 0x000001AA |
GetSystemTimeAsFileTime | - | 0x00401284 | 0x000324F8 | 0x000318F8 | 0x0000024F |
ExitProcess | - | 0x00401288 | 0x000324FC | 0x000318FC | 0x00000104 |
GetModuleFileNameA | - | 0x0040128C | 0x00032500 | 0x00031900 | 0x000001F4 |
FreeEnvironmentStringsA | - | 0x00401290 | 0x00032504 | 0x00031904 | 0x0000014A |
GetEnvironmentStrings | - | 0x00401294 | 0x00032508 | 0x00031908 | 0x000001BF |
FreeEnvironmentStringsW | - | 0x00401298 | 0x0003250C | 0x0003190C | 0x0000014B |
GetEnvironmentStringsW | - | 0x0040129C | 0x00032510 | 0x00031910 | 0x000001C1 |
HeapDestroy | - | 0x004012A0 | 0x00032514 | 0x00031914 | 0x000002A0 |
HeapCreate | - | 0x004012A4 | 0x00032518 | 0x00031918 | 0x0000029F |
VirtualFree | - | 0x004012A8 | 0x0003251C | 0x0003191C | 0x00000457 |
WriteFile | - | 0x004012AC | 0x00032520 | 0x00031920 | 0x0000048D |
HeapAlloc | - | 0x004012B0 | 0x00032524 | 0x00031924 | 0x0000029D |
HeapSize | - | 0x004012B4 | 0x00032528 | 0x00031928 | 0x000002A6 |
HeapReAlloc | - | 0x004012B8 | 0x0003252C | 0x0003192C | 0x000002A4 |
FlushFileBuffers | - | 0x004012BC | 0x00032530 | 0x00031930 | 0x00000141 |
GetConsoleCP | - | 0x004012C0 | 0x00032534 | 0x00031934 | 0x00000183 |
GetConsoleMode | - | 0x004012C4 | 0x00032538 | 0x00031938 | 0x00000195 |
OutputDebugStringA | - | 0x004012C8 | 0x0003253C | 0x0003193C | 0x0000033A |
WriteConsoleW | - | 0x004012CC | 0x00032540 | 0x00031940 | 0x0000048C |
OutputDebugStringW | - | 0x004012D0 | 0x00032544 | 0x00031944 | 0x0000033B |
InitializeCriticalSectionAndSpinCount | - | 0x004012D4 | 0x00032548 | 0x00031948 | 0x000002B5 |
MultiByteToWideChar | - | 0x004012D8 | 0x0003254C | 0x0003194C | 0x0000031A |
LCMapStringA | - | 0x004012DC | 0x00032550 | 0x00031950 | 0x000002E1 |
LCMapStringW | - | 0x004012E0 | 0x00032554 | 0x00031954 | 0x000002E3 |
GetStringTypeA | - | 0x004012E4 | 0x00032558 | 0x00031958 | 0x0000023D |
GetStringTypeW | - | 0x004012E8 | 0x0003255C | 0x0003195C | 0x00000240 |
GetLocaleInfoA | - | 0x004012EC | 0x00032560 | 0x00031960 | 0x000001E8 |
SetStdHandle | - | 0x004012F0 | 0x00032564 | 0x00031964 | 0x000003FC |
GetConsoleOutputCP | - | 0x004012F4 | 0x00032568 | 0x00031968 | 0x00000199 |
CloseHandle | - | 0x004012F8 | 0x0003256C | 0x0003196C | 0x00000043 |
CreateFileA | - | 0x004012FC | 0x00032570 | 0x00031970 | 0x00000078 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CharToOemBuffW | - | 0x00401304 | 0x00032578 | 0x00031978 | 0x00000035 |
CharUpperA | - | 0x00401308 | 0x0003257C | 0x0003197C | 0x00000037 |
GetCursorInfo | - | 0x0040130C | 0x00032580 | 0x00031980 | 0x00000118 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
AbortSystemShutdownW | - | 0x00401000 | 0x00032274 | 0x00031674 | 0x00000004 |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
build2.exe | 7 | 0x00400000 | 0x0047AFFF | Relevant Image | 32-bit | 0x00418760 |
...
|
c:\users\keecfmwgj\documents\outlook files\franc@gdllo.de.pst.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\5EtXO0qde4mAaAj2.mp3.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\tCNlSe zbuiw.pptx.vvyu | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\pictures\ncui5d__zr45d.gif.vvyu | Dropped File | Image |
Clean
|
...
|
c:\users\keecfmwgj\documents\8nnli0koeom-mpum785\him fl\4e_qp5b8\ns2nmi.pptx.vvyu | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\pictures\br-ix6cu0omqu4 dzyj.png.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\music\5u0vvnc3nroc8n_z\4g2bike6.wav.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\YnPBSI277\5Ctq03jfOkJI397\WXRqwImP8omimb.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\pictures\iv7y.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\cvfGVyFL7tFjUO7\7lrwy.flv.vvyu | Dropped File | Video |
Clean
|
...
|
c:\users\keecfmwgj\videos\cvfgvyfl7tfjuo7\ixnsaf850.swf.vvyu | Dropped File | Shockwave Flash |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\07H2voZRMEM4mGd_N.swf.vvyu | Dropped File | Shockwave Flash |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\wXPNYv.xlsx.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\5KliNx-drvR8.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\pictures\oq7rosq7byockq_wi3.gif.vvyu | Dropped File | Image |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\WOYOdoVl_y_ELRl.ppt.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\8NNLi0kOEoM-mpUM785\Ua71cE_srBW.docx.vvyu | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\documents\8nnli0koeom-mpum785\ysw9udfa\io6kkqyuc.xlsx.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\MuVmmckS_6uXC.pptx.vvyu | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\documents\xr3nlex5czvfg.pptx.vvyu | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\desktop\nfequ_fxuy ewf.mkv.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\music\j uck2lalp_ipp\47m5sv0uqvnl\f09xvkn7rnmgc_bzz.m4a.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\cvfGVyFL7tFjUO7\RpFnCBUaRW4M2CKB6Y8.avi.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\P0jIQb7.avi.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\m-_w92cttuhd9hf.xlsx.vvyu | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\desktop\uvnwcx.jpg.vvyu | Dropped File | Image |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\9IU4er.gif.vvyu | Dropped File | Image |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\ah9z8QW.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\8NNLi0kOEoM-mpUM785\HIm fL\4E_Qp5b8\IcyHH4kvUj6MCZmB\NLDjOHMq5YqJ5Vaq-G-z.pps.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\j ucK2lALp_iPp\47m5sv0uqVNl\AZ2aRaMGzQB\8b1WNKi0f8BaPAX.wav.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\iqB1Fd.mkv.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\music\j uck2lalp_ipp\qiaob8kqt6gjfc.m4a.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\NE4TCssID4OKfQf7Z.jpg.vvyu | Dropped File | Image |
Clean
|
...
|
c:\users\keecfmwgj\music\j uck2lalp_ipp\zntr-yrixj\zpa wj4.m4a.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\YnPBSI277\YZ4wuGCPKPt9a.pps.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\videos\cvfgvyfl7tfjuo7\hi5yoaj9.mp4.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\videos\fpzctgqi5ys\aejmzwa.avi.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\bdmsvg.docx.vvyu | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\desktop\0w8tqjzs69qqxvzs-d8d.ods.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\j ucK2lALp_iPp\Y3zc_VVY6Kxz1vjr.mp3.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\pictures\vuc5gusp1h33w.png.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\ya9u.mp3.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\FPzctgqI5yS\OPCtfBG3jGTa hU3.mkv.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\j ucK2lALp_iPp\47m5sv0uqVNl\AZ2aRaMGzQB\xryUj16QF_9DxMTZ1QMq.m4a.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\j ucK2lALp_iPp\znTr-YRiXJ\d4OMzSyCrSqIiU9aYvRY.wav.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\rinxjcpkfg.pptx.vvyu | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\documents\a_eemub.docx.vvyu | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\documents\8nnli0koeom-mpum785\him fl\4e_qp5b8\h0-ngmz.odt.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\cbyFXHxALB9ISR--Iyv1.png.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\ynpbsi277\5ctq03jfokji397\f6adjjdhq\59buro.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\8NNLi0kOEoM-mpUM785\HIm fL\4E_Qp5b8\RAN3RZLWQzdFaTXUwx\qSY7qB q Psxa19MFF.pps.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\qca-wrdfbpizyp.docx.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\sfoK-fQjQEuAHhw.jpg.vvyu | Dropped File | Image |
Clean
|
...
|
c:\users\keecfmwgj\pictures\lv2axv.jpg.vvyu | Dropped File | Image |
Clean
|
...
|
c:\users\keecfmwgj\desktop\ynpbsi277\qia7.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\8nnli0koeom-mpum785\him fl\w9_k2r1yg22qfb5wtf98.ots.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\8nnli0koeom-mpum785\ysw9udfa\sj8rzqt9cv0j.doc.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\8nnli0koeom-mpum785\ysw9udfa\83p1pax.xlsx.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\8NNLi0kOEoM-mpUM785\HIm fL\4E_Qp5b8\OQlL9b4yk.odp.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\FPzctgqI5yS\HkpWIkK5Da3UaMj2.mkv.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\ynpbsi277\5ctq03jfokji397\_dsq\q2acnga1p.mp3.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\pictures\hppn3l0iwejl.gif.vvyu | Dropped File | Image |
Clean
|
...
|
c:\users\keecfmwgj\videos\fpzctgqi5ys\jf9t9.mp4.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\8NNLi0kOEoM-mpUM785\HIm fL\22cygPIJe.ods.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\videos\fpzctgqi5ys\wiccgss9co9ejxpugq\kb5yp2q.avi.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\cvfGVyFL7tFjUO7\L59EH_1g_s_fJjq.mp4.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\videos\cvfgvyfl7tfjuo7\p5dr5.mp4.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\FPzctgqI5yS\wICCgSS9cO9EJxpugq\CelE9.swf.vvyu | Dropped File | Shockwave Flash |
Clean
|
...
|
c:\users\keecfmwgj\music\j uck2lalp_ipp\47m5sv0uqvnl\az2aramgzqb\i 1m.wav.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\videos\fpzctgqi5ys\m fzx23r02sywxh\0yoyfg2vyekk-r.swf.vvyu | Dropped File | Shockwave Flash |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\8NNLi0kOEoM-mpUM785\HIm fL\4E_Qp5b8\RAN3RZLWQzdFaTXUwx\a_eNlZ lSa4B_.ppt.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\FPzctgqI5yS\wICCgSS9cO9EJxpugq\P2QT4FKo.mp4.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\rwzd9mw.mp4.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\f83rpj3sXX29oJ.jpg.vvyu | Dropped File | Image |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\8NNLi0kOEoM-mpUM785\Ct fMZqR_ubHOI0.odt.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\j ucK2lALp_iPp\VUGuU0EaHk4ce5o.wav.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\cvfGVyFL7tFjUO7\geIB4J_yYE XOIcR0.flv.vvyu | Dropped File | Video |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\onXJrQ0LQmJjW.avi.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\pictures\ldaf6actl2hfcz.gif.vvyu | Dropped File | Image |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\YnPBSI277\5Ctq03jfOkJI397\adViIyse_4wpfxq.mp4.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\ynpbsi277\5ctq03jfokji397\_dsq\ouopevgnwd1-z0kjb.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\pictures\liar.gif.vvyu | Dropped File | Image |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\FPzctgqI5yS\M fZX23r02sYWxh\DyXmYMfEW2zZ74G.avi.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\A85pj5GgBuiXXfuVCW4.ppt.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\8nnli0koeom-mpum785\him fl\y3jgcuet.odt.vvyu | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\documents\8nnli0koeom-mpum785\s_caetbn.ots.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\bkw1.mp4.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\pictures\99o q.gif.vvyu | Dropped File | Image |
Clean
|
...
|
c:\users\keecfmwgj\pictures\om3a-o87olj.gif.vvyu | Dropped File | Image |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\2CgRhD9i_8EFMrM.png.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\kLC6o4xsmRx_iA iEAy2.docx.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\E 8rOnJ1a8nkX -7zzxk.wav.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\dr8uij1jmg.docx.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\music\5u0vvnc3nroc8n_z\udco8hlr7krd.m4a.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\pictures\5_xd oyqt5ylzw2rnd.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\x7DOA nu7EAlTL.mkv.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Favorites\Microsoft Websites\IE Add-on site.url.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\favorites\microsoft websites\ie site on microsoft.com.url.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\favorites\windows live\windows live mail.url.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\favorites\windows live\get windows live.url.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\favorites\msn websites\msn autos.url.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\favorites\msn websites\msn.url.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\srvsvc | Dropped File | Empty |
Clean
|
...
|
c:\wkssvc | Dropped File | Empty |
Clean
|
...
|
C:\Users\kEecfMwgj\AppData\Local\bowsakkdestx.txt | Downloaded File | Unknown |
Clean
|
...
|
4a1aaeed4747266983004f9fa25ff0ed024415f8232f30467b08441084b002e0 | Downloaded File | HTML |
Clean
|
...
|
6d214ad6b2cf334f0545be9f044bb26b2bd3d43dd77f5e124a5769b86c9ad995 | Downloaded File | HTML |
Clean
|
...
|
c:\users\keecfmwgj\appdata\roaming\microsoft\windows\ietldcache\index.dat | Modified File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat | Modified File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\appdata\local\microsoft\windows\history\history.ie5\index.dat | Modified File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\appdata\roaming\microsoft\windows\cookies\index.dat | Modified File | Stream |
Clean
|
...
|