Downloader Ransomware
STOP Mal/HTMLGen-A Djvu
Created on 2022-08-05T10:52:19+00:00
1918cc07f0b41a9e9dc18e715e5862a68ca49d61fdad7d76126953629c05be98.exe
Remarks (2/3)
(0x0200001B): The maximum number of file Reputation Analysis requests per analysis (150) was exceeded.
(0x0200000E): The overall sleep time of all monitored processes was truncated from "22 minutes" to "20 seconds" to reveal dormant functionality.
Remarks
(0x0200004A): 15 dump(s) were skipped because they exceeded the maximum dump size of 16 MB. The largest one was 33 MB.
(0x0200004F): Static Analysis failed to analyze file artifacts in this analysis due to an error. Check the artifact_static_analysis.log file for further information.
(0x0200005D): 231 additional dumps with the reason "Content Changed" and a total of 281 MB were skipped because the respective maximum limit was reached.
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\kEecfMwgj\Desktop\1918cc07f0b41a9e9dc18e715e5862a68ca49d61fdad7d76126953629c05be98.exe | Sample File | Binary |
Malicious
|
...
|
Verdict |
Malicious
|
Image Base | 0x00400000 |
Entry Point | 0x00498550 |
Size Of Code | 0x000A6000 |
Size Of Initialized Data | 0x0209CA00 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2021-03-12 20:59 (UTC+1) |
FileVersions | 48.90.12.34 |
Copyrighz | Copyright (C) 2022, pozkarte |
ProjectVersion | 94.4.7.88 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000A5EB4 | 0x000A6000 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.95 |
.data | 0x004A7000 | 0x020861CC | 0x00003000 | 0x000A6400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.76 |
.rsrc | 0x0252E000 | 0x0000D568 | 0x0000D600 | 0x000A9400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.53 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetModuleFileNameA | - | 0x00401000 | 0x000A63C8 | 0x000A57C8 | 0x00000213 |
FoldStringA | - | 0x00401004 | 0x000A63CC | 0x000A57CC | 0x0000015B |
GetLocalTime | - | 0x00401008 | 0x000A63D0 | 0x000A57D0 | 0x00000203 |
InterlockedDecrement | - | 0x0040100C | 0x000A63D4 | 0x000A57D4 | 0x000002EB |
GetLocaleInfoA | - | 0x00401010 | 0x000A63D8 | 0x000A57D8 | 0x00000204 |
InterlockedCompareExchange | - | 0x00401014 | 0x000A63DC | 0x000A57DC | 0x000002E9 |
_hwrite | - | 0x00401018 | 0x000A63E0 | 0x000A57E0 | 0x00000536 |
CancelWaitableTimer | - | 0x0040101C | 0x000A63E4 | 0x000A57E4 | 0x00000047 |
GetSystemDirectoryW | - | 0x00401020 | 0x000A63E8 | 0x000A57E8 | 0x00000270 |
CreateEventW | - | 0x00401024 | 0x000A63EC | 0x000A57EC | 0x00000085 |
ReadConsoleA | - | 0x00401028 | 0x000A63F0 | 0x000A57F0 | 0x000003B4 |
BuildCommDCBA | - | 0x0040102C | 0x000A63F4 | 0x000A57F4 | 0x0000003A |
GetConsoleAliasExesLengthW | - | 0x00401030 | 0x000A63F8 | 0x000A57F8 | 0x00000193 |
SetSystemTimeAdjustment | - | 0x00401034 | 0x000A63FC | 0x000A57FC | 0x0000048C |
PeekConsoleInputW | - | 0x00401038 | 0x000A6400 | 0x000A5800 | 0x0000038C |
EnumDateFormatsA | - | 0x0040103C | 0x000A6404 | 0x000A5804 | 0x000000F4 |
CreateFileW | - | 0x00401040 | 0x000A6408 | 0x000A5808 | 0x0000008F |
RegisterWaitForSingleObjectEx | - | 0x00401044 | 0x000A640C | 0x000A580C | 0x000003F6 |
LoadLibraryW | - | 0x00401048 | 0x000A6410 | 0x000A5810 | 0x0000033F |
VerifyVersionInfoW | - | 0x0040104C | 0x000A6414 | 0x000A5814 | 0x000004E8 |
WaitNamedPipeA | - | 0x00401050 | 0x000A6418 | 0x000A5818 | 0x000004FF |
GetEnvironmentStrings | - | 0x00401054 | 0x000A641C | 0x000A581C | 0x000001D8 |
FindResourceExA | - | 0x00401058 | 0x000A6420 | 0x000A5820 | 0x0000014C |
VirtualProtect | - | 0x0040105C | 0x000A6424 | 0x000A5824 | 0x000004EF |
GetFirmwareEnvironmentVariableW | - | 0x00401060 | 0x000A6428 | 0x000A5828 | 0x000001F7 |
BeginUpdateResourceW | - | 0x00401064 | 0x000A642C | 0x000A582C | 0x00000038 |
GetConsoleAliasExesLengthA | - | 0x00401068 | 0x000A6430 | 0x000A5830 | 0x00000192 |
WriteConsoleA | - | 0x0040106C | 0x000A6434 | 0x000A5834 | 0x0000051A |
EnumCalendarInfoExA | - | 0x00401070 | 0x000A6438 | 0x000A5838 | 0x000000F0 |
WriteConsoleW | - | 0x00401074 | 0x000A643C | 0x000A583C | 0x00000524 |
DeleteFileW | - | 0x00401078 | 0x000A6440 | 0x000A5840 | 0x000000D6 |
FillConsoleOutputCharacterA | - | 0x0040107C | 0x000A6444 | 0x000A5844 | 0x00000127 |
GetProcAddress | - | 0x00401080 | 0x000A6448 | 0x000A5848 | 0x00000245 |
GetModuleHandleW | - | 0x00401084 | 0x000A644C | 0x000A584C | 0x00000218 |
GetUserDefaultLCID | - | 0x00401088 | 0x000A6450 | 0x000A5850 | 0x0000029B |
FindFirstChangeNotificationW | - | 0x0040108C | 0x000A6454 | 0x000A5854 | 0x00000131 |
GetFileAttributesExA | - | 0x00401090 | 0x000A6458 | 0x000A5858 | 0x000001E6 |
GetCalendarInfoA | - | 0x00401094 | 0x000A645C | 0x000A585C | 0x00000179 |
SetConsoleTitleA | - | 0x00401098 | 0x000A6460 | 0x000A5860 | 0x00000447 |
GetBinaryTypeW | - | 0x0040109C | 0x000A6464 | 0x000A5864 | 0x00000171 |
GlobalAlloc | - | 0x004010A0 | 0x000A6468 | 0x000A5868 | 0x000002B3 |
GetComputerNameExA | - | 0x004010A4 | 0x000A646C | 0x000A586C | 0x0000018D |
FindNextFileA | - | 0x004010A8 | 0x000A6470 | 0x000A5870 | 0x00000143 |
OpenJobObjectA | - | 0x004010AC | 0x000A6474 | 0x000A5874 | 0x0000037A |
HeapSize | - | 0x004010B0 | 0x000A6478 | 0x000A5878 | 0x000002D4 |
_lclose | - | 0x004010B4 | 0x000A647C | 0x000A587C | 0x00000537 |
GetComputerNameW | - | 0x004010B8 | 0x000A6480 | 0x000A5880 | 0x0000018F |
TlsGetValue | - | 0x004010BC | 0x000A6484 | 0x000A5884 | 0x000004C7 |
SetCalendarInfoW | - | 0x004010C0 | 0x000A6488 | 0x000A5888 | 0x0000041F |
SetComputerNameW | - | 0x004010C4 | 0x000A648C | 0x000A588C | 0x0000042A |
CreateDirectoryExA | - | 0x004010C8 | 0x000A6490 | 0x000A5890 | 0x0000007D |
InitializeCriticalSectionAndSpinCount | - | 0x004010CC | 0x000A6494 | 0x000A5894 | 0x000002E3 |
FindFirstChangeNotificationA | - | 0x004010D0 | 0x000A6498 | 0x000A5898 | 0x00000130 |
GetVolumePathNameA | - | 0x004010D4 | 0x000A649C | 0x000A589C | 0x000002AA |
LoadLibraryA | - | 0x004010D8 | 0x000A64A0 | 0x000A58A0 | 0x0000033C |
GetProcessHandleCount | - | 0x004010DC | 0x000A64A4 | 0x000A58A4 | 0x00000249 |
GetThreadLocale | - | 0x004010E0 | 0x000A64A8 | 0x000A58A8 | 0x0000028C |
GetSystemDefaultLangID | - | 0x004010E4 | 0x000A64AC | 0x000A58AC | 0x0000026C |
GetCurrentProcess | - | 0x004010E8 | 0x000A64B0 | 0x000A58B0 | 0x000001C0 |
ReadFile | - | 0x004010EC | 0x000A64B4 | 0x000A58B4 | 0x000003C0 |
HeapFree | - | 0x004010F0 | 0x000A64B8 | 0x000A58B8 | 0x000002CF |
GetDiskFreeSpaceW | - | 0x004010F4 | 0x000A64BC | 0x000A58BC | 0x000001CF |
GetProcessHeap | - | 0x004010F8 | 0x000A64C0 | 0x000A58C0 | 0x0000024A |
RaiseException | - | 0x004010FC | 0x000A64C4 | 0x000A58C4 | 0x000003B1 |
RtlUnwind | - | 0x00401100 | 0x000A64C8 | 0x000A58C8 | 0x00000418 |
MultiByteToWideChar | - | 0x00401104 | 0x000A64CC | 0x000A58CC | 0x00000367 |
GetCommandLineW | - | 0x00401108 | 0x000A64D0 | 0x000A58D0 | 0x00000187 |
HeapSetInformation | - | 0x0040110C | 0x000A64D4 | 0x000A58D4 | 0x000002D3 |
GetStartupInfoW | - | 0x00401110 | 0x000A64D8 | 0x000A58D8 | 0x00000263 |
EncodePointer | - | 0x00401114 | 0x000A64DC | 0x000A58DC | 0x000000EA |
HeapAlloc | - | 0x00401118 | 0x000A64E0 | 0x000A58E0 | 0x000002CB |
GetLastError | - | 0x0040111C | 0x000A64E4 | 0x000A58E4 | 0x00000202 |
IsProcessorFeaturePresent | - | 0x00401120 | 0x000A64E8 | 0x000A58E8 | 0x00000304 |
DecodePointer | - | 0x00401124 | 0x000A64EC | 0x000A58EC | 0x000000CA |
TlsAlloc | - | 0x00401128 | 0x000A64F0 | 0x000A58F0 | 0x000004C5 |
TlsSetValue | - | 0x0040112C | 0x000A64F4 | 0x000A58F4 | 0x000004C8 |
TlsFree | - | 0x00401130 | 0x000A64F8 | 0x000A58F8 | 0x000004C6 |
InterlockedIncrement | - | 0x00401134 | 0x000A64FC | 0x000A58FC | 0x000002EF |
SetLastError | - | 0x00401138 | 0x000A6500 | 0x000A5900 | 0x00000473 |
GetCurrentThreadId | - | 0x0040113C | 0x000A6504 | 0x000A5904 | 0x000001C5 |
SetHandleCount | - | 0x00401140 | 0x000A6508 | 0x000A5908 | 0x0000046F |
GetStdHandle | - | 0x00401144 | 0x000A650C | 0x000A590C | 0x00000264 |
GetFileType | - | 0x00401148 | 0x000A6510 | 0x000A5910 | 0x000001F3 |
DeleteCriticalSection | - | 0x0040114C | 0x000A6514 | 0x000A5914 | 0x000000D1 |
SetFilePointer | - | 0x00401150 | 0x000A6518 | 0x000A5918 | 0x00000466 |
UnhandledExceptionFilter | - | 0x00401154 | 0x000A651C | 0x000A591C | 0x000004D3 |
SetUnhandledExceptionFilter | - | 0x00401158 | 0x000A6520 | 0x000A5920 | 0x000004A5 |
IsDebuggerPresent | - | 0x0040115C | 0x000A6524 | 0x000A5924 | 0x00000300 |
TerminateProcess | - | 0x00401160 | 0x000A6528 | 0x000A5928 | 0x000004C0 |
EnterCriticalSection | - | 0x00401164 | 0x000A652C | 0x000A592C | 0x000000EE |
LeaveCriticalSection | - | 0x00401168 | 0x000A6530 | 0x000A5930 | 0x00000339 |
ExitProcess | - | 0x0040116C | 0x000A6534 | 0x000A5934 | 0x00000119 |
GetCPInfo | - | 0x00401170 | 0x000A6538 | 0x000A5938 | 0x00000172 |
GetACP | - | 0x00401174 | 0x000A653C | 0x000A593C | 0x00000168 |
GetOEMCP | - | 0x00401178 | 0x000A6540 | 0x000A5940 | 0x00000237 |
IsValidCodePage | - | 0x0040117C | 0x000A6544 | 0x000A5944 | 0x0000030A |
CloseHandle | - | 0x00401180 | 0x000A6548 | 0x000A5948 | 0x00000052 |
WriteFile | - | 0x00401184 | 0x000A654C | 0x000A594C | 0x00000525 |
GetModuleFileNameW | - | 0x00401188 | 0x000A6550 | 0x000A5950 | 0x00000214 |
FreeEnvironmentStringsW | - | 0x0040118C | 0x000A6554 | 0x000A5954 | 0x00000161 |
GetEnvironmentStringsW | - | 0x00401190 | 0x000A6558 | 0x000A5958 | 0x000001DA |
HeapCreate | - | 0x00401194 | 0x000A655C | 0x000A595C | 0x000002CD |
QueryPerformanceCounter | - | 0x00401198 | 0x000A6560 | 0x000A5960 | 0x000003A7 |
GetTickCount | - | 0x0040119C | 0x000A6564 | 0x000A5964 | 0x00000293 |
GetCurrentProcessId | - | 0x004011A0 | 0x000A6568 | 0x000A5968 | 0x000001C1 |
GetSystemTimeAsFileTime | - | 0x004011A4 | 0x000A656C | 0x000A596C | 0x00000279 |
Sleep | - | 0x004011A8 | 0x000A6570 | 0x000A5970 | 0x000004B2 |
SetStdHandle | - | 0x004011AC | 0x000A6574 | 0x000A5974 | 0x00000487 |
WideCharToMultiByte | - | 0x004011B0 | 0x000A6578 | 0x000A5978 | 0x00000511 |
GetConsoleCP | - | 0x004011B4 | 0x000A657C | 0x000A597C | 0x0000019A |
GetConsoleMode | - | 0x004011B8 | 0x000A6580 | 0x000A5980 | 0x000001AC |
FlushFileBuffers | - | 0x004011BC | 0x000A6584 | 0x000A5984 | 0x00000157 |
CreateFileA | - | 0x004011C0 | 0x000A6588 | 0x000A5988 | 0x00000088 |
LCMapStringW | - | 0x004011C4 | 0x000A658C | 0x000A598C | 0x0000032D |
GetStringTypeW | - | 0x004011C8 | 0x000A6590 | 0x000A5990 | 0x00000269 |
HeapReAlloc | - | 0x004011CC | 0x000A6594 | 0x000A5994 | 0x000002D2 |
SetEndOfFile | - | 0x004011D0 | 0x000A6598 | 0x000A5998 | 0x00000453 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ClientToScreen | - | 0x004011D8 | 0x000A65A0 | 0x000A59A0 | 0x00000047 |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
buffer | 1 | 0x02540020 | 0x025D1167 | First Execution | 32-bit | 0x02540020 |
...
|
||
buffer | 1 | 0x03D10000 | 0x03E2AFFF | First Execution | 32-bit | 0x03D10000 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | First Execution | 32-bit | 0x00424141 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00423F84 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004278D5 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00425141 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042C0F0 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042A06D |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0043B021 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00420C62 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042D8D0 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00431F64 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0043AF30 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0044148D |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00421881 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042B420 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004C55BE |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004548D0 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00449000 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0044D0CB |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0044B550 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00401000 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0040A260 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041CC50 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00419E70 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0040CF10 |
...
|
||
buffer | 2 | 0x00188000 | 0x0018FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | First Network Behavior | 32-bit | 0x0040D000 |
...
|
||
buffer | 2 | 0x0071F1C8 | 0x0071F583 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0071F590 | 0x0071FD8F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0071FD98 | 0x0071FE5F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0071FE68 | 0x0071FEFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x007200F8 | 0x00720221 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x007202F8 | 0x00720387 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00720430 | 0x00720505 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x007205D0 | 0x0072065B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00720668 | 0x00720E67 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00720E70 | 0x00720EEF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00720EF8 | 0x00721117 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x007216E8 | 0x0072177C | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00721928 | 0x007219BF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x007219C8 | 0x007222B3 | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 2 | 0x02650000 | 0x0268FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042B420 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00418400 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Final Dump | 32-bit | 0x0040B140 |
...
|
||
buffer | 2 | 0x0071F1C8 | 0x0071F583 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0071F590 | 0x0071FD8F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0071FD98 | 0x0071FE5F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0071FE68 | 0x0071FEFF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x007200F8 | 0x00720221 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x007202F8 | 0x00720387 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x00720430 | 0x00720505 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x007205D0 | 0x0072065B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x00720668 | 0x00720E67 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x00720E70 | 0x00720EEF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x00720EF8 | 0x00721117 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x007216E8 | 0x0072177C | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x00721928 | 0x007219BF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x007219C8 | 0x007222B3 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x00737600 | 0x0073785B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0073C210 | 0x0073CA0F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x007F58B0 | 0x007F593F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02BB48E0 | 0x02BB496F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02BC9908 | 0x02BC9B63 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02BD7940 | 0x02BD822B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02BD8238 | 0x02BD8A47 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02BD8A50 | 0x02BD8CAB | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02BD8CB8 | 0x02BD8F13 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02BD8F20 | 0x02BD917B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02BD9188 | 0x02BD93E3 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02BD93F0 | 0x02BD964B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02BD9658 | 0x02BD98B3 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02C11960 | 0x02C11BBB | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02C154A0 | 0x02C156FB | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02C15708 | 0x02C15827 | Final Dump | 32-bit | - |
...
|
||
index.dat | 2 | 0x02650000 | 0x0268FFFF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00433F99 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00424081 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004CB520 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004CA6F7 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x0071F590 | 0x0071FD8F | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x0071FD98 | 0x0071FE5F | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x0071FE68 | 0x0071FEFF | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x007200F8 | 0x00720221 | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x007202F8 | 0x00720387 | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x00720430 | 0x00720505 | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x007205D0 | 0x0072065B | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x00720E70 | 0x00720EEF | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x00720EF8 | 0x00721117 | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x007216E8 | 0x0072177C | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x00721928 | 0x007219BF | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x00737600 | 0x0073785B | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x0078F2B0 | 0x0078F34F | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02BC9908 | 0x02BC9B63 | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02BD8A50 | 0x02BD8CAB | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02BD8CB8 | 0x02BD8F13 | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02BD8F20 | 0x02BD917B | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02BD9188 | 0x02BD93E3 | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02BD93F0 | 0x02BD964B | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02BD9658 | 0x02BD98B3 | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02C11960 | 0x02C11BBB | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02C154A0 | 0x02C156FB | Process Termination | 32-bit | - |
...
|
||
index.dat | 2 | 0x02650000 | 0x0268FFFF | Process Termination | 32-bit | - |
...
|
||
buffer | 5 | 0x00240020 | 0x002D1167 | First Execution | 32-bit | 0x00240020 |
...
|
||
buffer | 5 | 0x03DE0000 | 0x03EFAFFF | First Execution | 32-bit | 0x03DE0000 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | First Execution | 32-bit | 0x00424141 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00423F84 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004278D5 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00425141 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042C0F0 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042A06D |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0043B021 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00420C62 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042D8D0 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00431F64 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0043AF30 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0044148D |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00421881 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042B420 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004C55BE |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004548D0 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00449000 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0044D0CB |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0044B550 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00401000 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041CC50 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00419E70 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0040CF10 |
...
|
||
buffer | 6 | 0x00188000 | 0x0018FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | First Network Behavior | 32-bit | 0x0040D000 |
...
|
||
buffer | 6 | 0x0060F228 | 0x0060F5E3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x0060F5F0 | 0x0060FDEF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x0060FDF8 | 0x0060FF0D | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x0060FF18 | 0x0060FFAF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x006101A8 | 0x006102D1 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x006103A8 | 0x00610437 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x006104E0 | 0x006105B5 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x00610680 | 0x0061070B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x00610718 | 0x00610F17 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x00610F20 | 0x00610F9F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x00610FA8 | 0x006111C7 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x00611798 | 0x0061182C | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x006119D8 | 0x00611A6F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x00611A78 | 0x00612363 | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 6 | 0x02620000 | 0x0265FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00413FF0 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041B680 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00412220 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041A7C1 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00422587 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00428C96 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042434D |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042A77E |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004389C2 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042E003 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0040C6A0 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0043FBA6 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00447F50 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00430BBF |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042B420 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041F01A |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00410FC0 |
...
|
||
buffer | 10 | 0x00240020 | 0x002D1167 | First Execution | 32-bit | 0x00240020 |
...
|
||
buffer | 10 | 0x02540000 | 0x0265AFFF | First Execution | 32-bit | 0x02540000 |
...
|
||
buffer | 11 | 0x00400000 | 0x00536FFF | First Execution | 32-bit | 0x00424141 |
...
|
||
buffer | 11 | 0x00188000 | 0x0018FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 11 | 0x00400000 | 0x00536FFF | First Network Behavior | 32-bit | 0x0040D000 |
...
|
||
buffer | 11 | 0x0063F4A8 | 0x0063F863 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 11 | 0x0063F870 | 0x0064006F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 11 | 0x00640078 | 0x00640103 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 11 | 0x00640110 | 0x0064090F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 11 | 0x00640918 | 0x00640997 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 11 | 0x006409A0 | 0x00640BBF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 11 | 0x00641178 | 0x0064120C | First Network Behavior | 32-bit | - |
...
|
||
buffer | 11 | 0x006413B8 | 0x00641453 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 11 | 0x00641718 | 0x00641851 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 11 | 0x00641860 | 0x006418FB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 11 | 0x00641AF8 | 0x00641C21 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 11 | 0x00641CF8 | 0x00641D87 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 11 | 0x00641E30 | 0x00641F05 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 11 | 0x00641FD0 | 0x006428BB | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 11 | 0x00300000 | 0x0030FFFF | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 11 | 0x00310000 | 0x00317FFF | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 11 | 0x00320000 | 0x0032FFFF | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 11 | 0x01E40000 | 0x01E7FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 11 | 0x00400000 | 0x00536FFF | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0063F870 | 0x0064006F | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x00640078 | 0x00640103 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x00640918 | 0x00640997 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x006409A0 | 0x00640BBF | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x00641178 | 0x0064120C | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x006413B8 | 0x00641453 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x00641718 | 0x00641851 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x00641860 | 0x006418FB | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x00641AF8 | 0x00641C21 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x00641CF8 | 0x00641D87 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x00641E30 | 0x00641F05 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064CEB0 | 0x0064CF31 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064DCC0 | 0x0064DD41 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064DD50 | 0x0064DDD1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064DDE0 | 0x0064DE61 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064DE70 | 0x0064DEF1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064DF00 | 0x0064DF81 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064DF90 | 0x0064E011 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064E020 | 0x0064E0A1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064E0B0 | 0x0064E131 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064E140 | 0x0064E1C1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064E1D0 | 0x0064E251 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064E260 | 0x0064E2E1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064E2F0 | 0x0064E371 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064E380 | 0x0064E401 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064E410 | 0x0064E491 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064E4A0 | 0x0064E521 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064E530 | 0x0064E5B1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064E5C0 | 0x0064E641 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064E650 | 0x0064E6D1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064E6E0 | 0x0064E761 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064E770 | 0x0064E7F1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064E800 | 0x0064E881 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064E890 | 0x0064E911 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064E920 | 0x0064E9A1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064E9B0 | 0x0064EA31 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x0064EA40 | 0x0064EAC1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x00678350 | 0x006784DF | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x006E2D18 | 0x006E2DED | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C7A5D0 | 0x02C7A82B | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C7A838 | 0x02C7A9A3 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C7D030 | 0x02C7D28B | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C7D298 | 0x02C7D4F3 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C7D500 | 0x02C7D75B | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C7D768 | 0x02C7D9C3 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C7D9D0 | 0x02C7DC2B | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C7DC38 | 0x02C7DE93 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C7DEA0 | 0x02C7E0FB | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C7E108 | 0x02C7E363 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C7E370 | 0x02C7E5CB | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C7E5D8 | 0x02C7E833 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C7E840 | 0x02C7EA9B | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C7EAA8 | 0x02C7ED03 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C7ED10 | 0x02C7EF6B | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C7EF78 | 0x02C7F1D3 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C7F1E0 | 0x02C7F43B | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C7F448 | 0x02C7F6A3 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C7F6B0 | 0x02C7F90B | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C7F918 | 0x02C7FB73 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C7FB80 | 0x02C7FDDB | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C7FDE8 | 0x02C80043 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C80050 | 0x02C802AB | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C802B8 | 0x02C80513 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C80520 | 0x02C8077B | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C80788 | 0x02C809E3 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C809F0 | 0x02C80C4B | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C80C58 | 0x02C80EB3 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C8E8C8 | 0x02C8EB23 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C8EB30 | 0x02C8ED8B | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C8ED98 | 0x02C8EFF3 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C8F000 | 0x02C8F25B | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C8F268 | 0x02C8F4C3 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C8F4D0 | 0x02C8F72B | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C8F738 | 0x02C8F993 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C8F9A0 | 0x02C8FBFB | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C8FC08 | 0x02C8FE63 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C8FE70 | 0x02C900CB | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C900D8 | 0x02C90333 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C90340 | 0x02C9059B | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C905A8 | 0x02C90803 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C90810 | 0x02C90A6B | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C90A78 | 0x02C90CD3 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C90CE0 | 0x02C90F3B | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C90F48 | 0x02C911A3 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C911B0 | 0x02C9140B | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C91418 | 0x02C91673 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C91680 | 0x02C918DB | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C918E8 | 0x02C91B43 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C91B50 | 0x02C91DAB | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C91DB8 | 0x02C92013 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C92020 | 0x02C9227B | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C92288 | 0x02C924E3 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C924F0 | 0x02C9274B | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C9EDE8 | 0x02C9F043 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C9F050 | 0x02C9F2AB | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C9F2B8 | 0x02C9F513 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02C9F520 | 0x02C9F77B | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02D010F8 | 0x02D01353 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02D01360 | 0x02D015BB | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02D015C8 | 0x02D01823 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02D01830 | 0x02D01A8B | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02D01A98 | 0x02D01CF3 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02D01D00 | 0x02D01F5B | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02D01F68 | 0x02D021C3 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02D021D0 | 0x02D0242B | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02D02438 | 0x02D02693 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02D026A0 | 0x02D028FB | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02D02908 | 0x02D02B63 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02D02B70 | 0x02D02DCB | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02D02DD8 | 0x02D03033 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02D06960 | 0x02D0717F | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02D0B3C0 | 0x02D0C3BF | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E84288 | 0x02E88287 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E88290 | 0x02E8C28F | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E917A8 | 0x02E91837 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E91840 | 0x02E918CF | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9EA80 | 0x02E9EB01 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9EB10 | 0x02E9EB91 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9EBA0 | 0x02E9EC21 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9EC30 | 0x02E9ECB1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9ECC0 | 0x02E9ED41 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9ED50 | 0x02E9EDD1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9EDE0 | 0x02E9EE61 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9EE70 | 0x02E9EEF1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9EF00 | 0x02E9EF81 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9EF90 | 0x02E9F011 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9F020 | 0x02E9F0A1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9F0B0 | 0x02E9F131 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9F140 | 0x02E9F1C1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9F1D0 | 0x02E9F251 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9F260 | 0x02E9F2E1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9F2F0 | 0x02E9F371 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9F380 | 0x02E9F401 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9F410 | 0x02E9F491 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9F4A0 | 0x02E9F521 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9F530 | 0x02E9F5B1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9F5C0 | 0x02E9F641 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9F650 | 0x02E9F6D1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9F6E0 | 0x02E9F761 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9F770 | 0x02E9F7F1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9F800 | 0x02E9F881 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9F890 | 0x02E9F911 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9F920 | 0x02E9F9A1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9F9B0 | 0x02E9FA31 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9FA40 | 0x02E9FAC1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9FAD0 | 0x02E9FB51 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9FB60 | 0x02E9FBE1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9FBF0 | 0x02E9FC71 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9FC80 | 0x02E9FD01 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9FD10 | 0x02E9FD91 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9FDA0 | 0x02E9FE21 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9FE30 | 0x02E9FEB1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9FEC0 | 0x02E9FF41 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9FF50 | 0x02E9FFD1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02E9FFE0 | 0x02EA0061 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA0070 | 0x02EA00F1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA0100 | 0x02EA0181 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA0190 | 0x02EA0211 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA0220 | 0x02EA02A1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA02B0 | 0x02EA0331 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA0340 | 0x02EA03C1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA03D0 | 0x02EA0451 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA0460 | 0x02EA04E1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA04F0 | 0x02EA0571 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA0580 | 0x02EA0601 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA0610 | 0x02EA0691 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA06A0 | 0x02EA0721 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA0730 | 0x02EA07B1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA07C0 | 0x02EA0841 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA0850 | 0x02EA08D1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA08E0 | 0x02EA0961 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA0970 | 0x02EA09F1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA3A80 | 0x02EA3B01 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA3B10 | 0x02EA3B91 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA3BA0 | 0x02EA3C21 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA3C30 | 0x02EA3CB1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA3CC0 | 0x02EA3D41 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA3D50 | 0x02EA3DD1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA3DE0 | 0x02EA3E61 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA3E70 | 0x02EA3EF1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA3F00 | 0x02EA3F81 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA3F90 | 0x02EA4011 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA4020 | 0x02EA40A1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA4A80 | 0x02EA4B01 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA4B10 | 0x02EA4B91 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA4BA0 | 0x02EA4C21 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA4C30 | 0x02EA4CB1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA4CC0 | 0x02EA4D41 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA4D50 | 0x02EA4DD1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA4DE0 | 0x02EA4E61 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA4E70 | 0x02EA4EF1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA4F00 | 0x02EA4F81 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA4F90 | 0x02EA5011 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA5020 | 0x02EA50A1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA50B0 | 0x02EA5131 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA5140 | 0x02EA51C1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA51D0 | 0x02EA5251 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA5260 | 0x02EA52E1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA52F0 | 0x02EA5371 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA5380 | 0x02EA5401 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA5410 | 0x02EA5491 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA54A0 | 0x02EA5521 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA5530 | 0x02EA55B1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA55C0 | 0x02EA5641 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA5650 | 0x02EA56D1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA56E0 | 0x02EA5761 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA5770 | 0x02EA57F1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA5800 | 0x02EA5881 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA5890 | 0x02EA5911 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA5920 | 0x02EA59A1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA59B0 | 0x02EA5A31 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA5A40 | 0x02EA5AC1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA5AD0 | 0x02EA5B51 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA5B60 | 0x02EA5BE1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA5BF0 | 0x02EA5C71 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA5C80 | 0x02EA5D01 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA5D10 | 0x02EA5D91 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA5DA0 | 0x02EA5E21 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA5E30 | 0x02EA5EB1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA5EC0 | 0x02EA5F41 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA5F50 | 0x02EA5FD1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA5FE0 | 0x02EA6061 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA6100 | 0x02EA6181 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA6190 | 0x02EA6211 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA6220 | 0x02EA62A1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA62B0 | 0x02EA6331 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA6340 | 0x02EA63C1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA63D0 | 0x02EA6451 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA6460 | 0x02EA64E1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA64F0 | 0x02EA6571 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA6580 | 0x02EA6601 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA6610 | 0x02EA6691 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA66A0 | 0x02EA6721 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA6730 | 0x02EA67B1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA67C0 | 0x02EA6841 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA6850 | 0x02EA68D1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA68E0 | 0x02EA6961 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA6970 | 0x02EA69F1 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA79C8 | 0x02EA7A49 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA7A58 | 0x02EA7AD9 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA7AE8 | 0x02EA7B69 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA7B78 | 0x02EA7BF9 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA7C08 | 0x02EA7C89 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA7C98 | 0x02EA7D19 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA7D28 | 0x02EA7DA9 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA7DB8 | 0x02EA7E39 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA7E48 | 0x02EA7EC9 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA7ED8 | 0x02EA7F59 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA7F68 | 0x02EA7FE9 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA7FF8 | 0x02EA8079 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA8088 | 0x02EA8109 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA8118 | 0x02EA8199 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA81A8 | 0x02EA8229 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA8238 | 0x02EA82B9 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA82C8 | 0x02EA8349 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA8358 | 0x02EA83D9 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA83E8 | 0x02EA8469 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA8478 | 0x02EA84F9 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA8508 | 0x02EA8589 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA8598 | 0x02EA8619 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA8628 | 0x02EA86A9 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA86B8 | 0x02EA8739 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA8748 | 0x02EA87C9 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA87D8 | 0x02EA8859 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA8868 | 0x02EA88E9 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA88F8 | 0x02EA8979 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA8988 | 0x02EA8A09 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA8A18 | 0x02EA8A99 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA8AA8 | 0x02EA8B29 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA8B38 | 0x02EA8BB9 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA8BC8 | 0x02EA8C49 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA8C58 | 0x02EA8CD9 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA8CE8 | 0x02EA8D69 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA8D78 | 0x02EA8DF9 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA8E08 | 0x02EA8E89 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA8E98 | 0x02EA8F19 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA8F28 | 0x02EA8FA9 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA8FB8 | 0x02EA9039 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA9048 | 0x02EA90C9 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA90D8 | 0x02EA9159 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA9168 | 0x02EA91E9 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA91F8 | 0x02EA9279 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA9288 | 0x02EA9309 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA9318 | 0x02EA9399 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA93A8 | 0x02EA9429 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA9438 | 0x02EA94B9 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA94C8 | 0x02EA9549 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA9558 | 0x02EA95D9 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA95E8 | 0x02EA9669 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA9678 | 0x02EA96F9 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA9708 | 0x02EA9789 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA9798 | 0x02EA9819 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA9828 | 0x02EA98A9 | Process Termination | 32-bit | - |
...
|
||
buffer | 11 | 0x02EA98B8 | 0x02EA9939 | Process Termination | 32-bit | - |
...
|
C:\Users\kEecfMwgj\Desktop\bQ6SJi8RO0rg0dP\3YgFUJ.rtf.vvyu | Dropped File | RTF |
Malicious
|
...
|
ŽN@1 gTÜèiçsÄcÀ¼—òcïQoÃôª½°JQ7mkåJJ*¨h¼ÀÍE³"Õ¹qê5=j “^+=’ÀìǧZeó*‚¼!ö&Ôÿ¿+´`ºÞ$øúl1yk¥~œÉ~iÞ`acÂì9(ÄÚ¬?zrà\x9dIŸð1¿õ–Æq+/nJOv: æÇèê˜üâV¢B0â4žCšçÔjÁN'™éyÒؽdßÄ`Lo,H4uãÑ÷0º%ŒëϹ>N'ó~.èº9ÆóêÆV‹ëèÄò-¢ˆÈÆÎH?î¢Þ±¼ÒTàJ[åb§™j·\x8d>ÑEZ²µžFLp‚Õª®è À[ŽqñîG¹»¯¢àÁÜË_bn39ƒ5/ÁN£ï\x8f^a¢´@ìg§33i‡ÎÊ~íj_µx‰àlj|FŽï4±ê KëKP2«ß•«õ Ń&™õ?#L;Cþ̈7Ê«¨`/4EÞ;óÐÐB\x9d8..Ôù8µÙRÊ¢Á•ß!Y¨9Òs«þßú¯3ó€ST¸‚ôt¹l·Lt>ôé«©‰ùêSZܵîô©âÊ„7|\x8f8‹õ]†Þúñ¡gfeãqõâ| u›Ù‰Ä,œÀžh]ãA Lè|Çrå碿qq7ó÷Ÿ„ëÒ5rÔŽóÉÙÝ5O¡ãÞ±ŽËÒK0êâì_Þ\x81Ü–ñ‡+ä“gÂÐÚkZ,ÂåÓÝà&^æÆJoö66üã•®kÄx)d+Gf_’Ë÷Æ„‘=–ü—¢ˆ\x8d[û5â¶I†ºŸO?êyQÐ@ÂN,6&±§€¢Š5yž~¦¨œ ¶´òà‡äÂMöàÁ3@`:L2È䙞¤\x8d1+º§Ub»˜Ž°øEƘpR½)¾žèúR.U€å?‘fŒ‚A?™\x8fÞ²y(ZŽÏŒ¹ìØ̃£XPš½óç”K˜²£WŸ¥Å˜£ëïN¥"„¸lߟ1À×oKÝÿéœß8ˆPbÇÛUq1\x8fÇ%\x9dkàÛe£\x81ÊAÔRЯ'ZvC…OG´q3 ®Çåwˆ¬3þß™ÝM»j˜o©\x9dkOOóè”Ô_›Xåo…ν*‡e§l"Üv„ÁÙÌš½°©êÐÁ‘¼ùF€õÜKP¿VQúÓ]•¨LYã‚á:W\x8fš‘ª™ÃEUÑÇ:\x8d퉒=úéU»áñ…Š&›½\x9džÌ‚dòŒºœØ-gˆ+K€ƒX±5%ɹ¢_y7Â…(|S”¸$?Q |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\kEecfMwgj\Documents\6LeN1-BfLiBS.rtf.vvyu | Dropped File | RTF |
Malicious
|
...
|
½9ëÐ3yUÍV²úÌQªª,N\x8f=7°ŽxB÷²\x9d¡¼RxÆðü?,f‘âöT‡ér4µs¨”øÃAöÌ/a\x81öXð]™qIâ6®Ñ\x8d`*™lí܇ÊRÇPÕž×ÉE‹Tƒ"¿½¨–Ww‹hwñceÕŠÒ礰&>Ši|ÀDÑÁjcÈÏb?r$šb˜9~ïí>ÏŠ«¥÷ûñÉÒÇP²Ÿ&\x81˜9º¤7±Z•‰WÑWò¨¶˜Gÿiæ½ Ðª^j(]gB¹UþψŽˆÄÓñãå8/†ú;vyP4x1DZiðÓ-“ö’½G–Öb¾¨Aÿ=`¾b¤4ÙÍŽäÔÔ!T7Ÿ[‹I%E-ûaTI€¢'²U½\x8dù¤Oµª5j.µ_8Ún§õNÏáñàŸt¼Â-ÕéPV g¾r9Å9ã£UTÏíäYKg«=¡!g³‡_7ØûœßÅÄıߟFÐTL…P’âÈj‡Iš"ÜÑ”h7¬z½+ÏÚß ÐGs\x81ÃÈßÿNÜ‹c¤ÀÚ+gy\x8fæŠ5î‘L³:D$M–ñ^ïS¬“×Aˆ\x8dæÈw©¼\x8fŒ¢tF+®\x8dÖU†8ÿN–€y^F²„´cóv&/%»°üžql‹Ú³gç¦'7Y4câ\x81(³==½à‹µ×ë‘q\x8fuëðmÚ$ ,ym„V%l9Äi;€ºÀ2T²Òdœ¸’šjÜì|Ú!pë¼a\x8déê"ëöH\x8dJœ/À›gÑ)¶xz3·§áûºcæÒCÊN-hœ5‡¶Ž¾AÒOYë\x9d]U\x9drÁ8MFþMxáYyD3Ø~y0]hµlþMrnA‡@æíM¤;v÷‘_ÿo*†mÅWì5\x81݉RŒä9´¤fb¾õ‹\x90HçÉû.†U€„ÃÓcíµ¾‹ƒgP¬„óÔœrÊó·Í5\x9dñ:²8óîÞšà`„O—+ÅÄ™MrLQdJ’ône-`Ê û/=ÂĘð¾áãÜןàµjüý—M~iÁO¢%B¦•ÙÆ;!É·³qsÅ`Ë%(›h¾\x8dÊ’ÑDÌà¼ä¢t°OÆÌ .f7(Éþlwu!iž²²ôµTŠŸ«¾ë²ÖÉÃ×·å[¬Í\x8fxûŽÃà÷5¹ŽªËš‡ƒ\x8dN§_Ž¤¬ÙòUš|¹XÀ[‘[jø¤\x90•ñŒwÜ;äÅšÉ़ú/Ë/F²œ†ìx¾ð¢ |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
c:\users\keecfmwgj\documents\z1niztmoyavazpqq.rtf.vvyu | Dropped File | RTF |
Malicious
|
...
|
¦0<Qâ1æ=æºôâ-ñ¶ÇÙ\x8f“¡\x81w€“ô#&“aò9£Œð°GFªÞ+<é»ÎõtáþIpLn[ QS-I¯ý\x8dF®‡q§ŒW*ç¨9í 0’|—k›ê1v\x8dÔ÷9Œý-n÷1äÛ\x8f<!z+øsªéY"#_† ØOÿCHêHVbŒ²£æa0tStG2ÌÁ ˜¡5€×àN\x9dÞþ«7ºÒ9ŒÙ5ÒÓ\x8d–;Zh«¡4¬Ù üäT¬¢./ä2ktmèb9±ðÇêAùݳzÉynôN4%ÌÀS»W™î/Wç"a·UOi£œ4>aâdðý†#ͯ*&v*wè_èÒ;ÙFj-ïCj›w1¿½ZÞ‘œ?€ª•þµ× Ñ"eÍ„*Ö€O¯ÑÏ«¦Ä:¡ÖdÄp"Öiøp‹E+Í°áÃÛþ]5µ3R\x90U‹ÃبQÎõ2¨tã:t¿fâd2Õ©ÒõuÞßMر?2í[û>=˜~ŠG_WòVR´×\x8fœ½è]£Úh"Úßãšÿ£ÅÈ×ÐúQK<3E‚r¢ÛÍLí_ÞiÙ´ Ú°\x9d…plóM7ÕJ¡U"®·~ªÄãŸin“\x81GmŽèþ¬gzª(ñþ—ûßL¾üéh¦_<.òó%FÄ+<LC\x9d÷ö¦FçxXý¯þTEr¿ÐÕª~e®…ï:z5MÓâ¥Ë4!:Q`U6ŠÒršÁ\x90¨tìŒÇ17Ù²Éd'’(×ÒWz©´\x8fo›·‰Ï‚x¹ÜOs°µÒæ†ME_¯òe’ß0‰•4Kf>æÓÚÿA׳lœ'"´€s‰›ê>ͧ ‘Ÿ××`ºLg/BRÀýÿ¹?x!=‹xz`~o½¤uµBÜØÑÖOw<Xãà‘á%µò¨¯Ãx0›²þb¯—.ó<™½ XÀV pj\x90÷•@ñs.Òë WæÛÎeQÜcþh±¤^àš|Mÿ"¤ê\x90߈x3¥Ô§³‹‘ÕAGƨg‡;@^[¦¦ž–J§HæyVHÞÛÖEÅŠ€u‘`wîxÅ<±Èß:¬ ·°ÛóHâ…y«Ø|Ü÷Ÿnâ<2¡p7%/ëkRŸZâ„D—Ð,éåå;DòË×)ŸsãÙ++bf«üî!ˆ.nq…éÞ\x90QôMø‡¤0ÊçdŸÄ½R”\x8f9EîgbVé_6–÷ôV¸;¨ê\x81ÎÔš*ÏäwºËµ“0~q‘Âøf |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\kEecfMwgj\Documents\4l3gkybFjpw5wc.rtf.vvyu | Dropped File | RTF |
Malicious
|
...
|
.⨩—ÒŽŠ&àÇ*»‡v'U=òò¶=(T%§¢ ;ÕŸ€gÿÙ8ù…Æ7¥k±Û\x908tÇäp®*™oJmÀ쌴Ü3˜t¾±;é¢gÓ\x8d`ÊX ® €p&úö¿¦¨c¡õ§bä_elf㎠ÙÒ‡YñAù7ÜéxŸžÃL\x8f^1¶DýUËUÒ|Öµ”?|\x9dö±$”ã‰ÆýŸtr‘aÐø:Vqæ»ûQóÈŽô*_VðƒfðJÓ%yâgvCâL.…!8XYß’ÆãëúÉîh…rq`‡šÉû_y²IÛ\x9d´ÂÂ]&·35³ÉÃqÞ¨»lEKµÕÜÅI^‡ØËÉm+d’?6îK|UÛñVy¹·”SŠî XNûЛlJþ!t"-C²þ+ ùßa6ÜDÞ ¤ÇÜ|ž‹?ØSÓýŒKß#“õ`CÓA”A\x9dº—u‚úA:ÿ—ìÌÖ(Pؤö[îZëAU|Îù†ølÅ<¬<y8Ë#‘GrêŸ&|Äô;§µÚ2F–f\x8d0Ø)>†X€Æ\x8føïîñ‹ØÂX–måŸ3zNúÑ»|7qhL˜e-ô蜥–ý¨»·ü*”DÞvlå)d\x81FpûZU˜ô_ŠoÐÆ—è…*(i2ØË*§)jû–lÑ¢jRÏçÖÛÛá~T©œ"+l‡˜c¿÷÷•;U‰ÐIÑ\x9d“§‰Áë\x8fÿrÄ÷vodñ€Jù-à9´Áý\x90'Ö\x90”†¶zUß[‚i eVä¨ÍoäÃ6@¡Ñ9úáÅl´‰5; mÖð9n“¾Š…Çý?öÙÂ+ø-fÝË´a’±?¿\x9dÙÔ>¦µo5ɶ#¿K [Á³<DIõ2¦d\x9dèëÁˆþ‚3‹¤[ÕÆ’Þü&·—Þ®þ‰\x8fHËr‰#Å`p~豜º#ˆalxœÞ“<¿ÎÒLH\x8dé"épÀ¡†7Ç`±¤5§V¢[P©QÒBê(,\x81ÎÉ›¶’\x8d-ŠC ÕtCF_®là|ÿÊ¥W’Ó&ìâuÖÔȹ—&Jÿ–^W‚3È»îÅ»D|Z’“o0WÝÅ\x90@ä$ôr,L/e"ð÷«,úûŠ,ß,`…ì7ýŸ£Måt\x81OqÃÍ‚ˆêvŽAÔܧ¦Æò¦Í;!±ã<ß "Çflp›]~B¹a¨å³ˆßï¹Éð³“õ0F“5lU¡!^nˆOÞKL<ž¬•!‡£f0œ…KÈÙ |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\kEecfMwgj\Desktop\1918cc07f0b41a9e9dc18e715e5862a68ca49d61fdad7d76126953629c05be98.exe.vvyu | Dropped File | Binary |
Malicious
|
...
|
c:\users\keecfmwgj\documents\outlook files\franc@gdllo.de.pst.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\rwqicw2qitxlv4.jpg.vvyu | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\documents\hhuy\r fixnl1vu2.ots.vvyu | Dropped File | ZIP |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\BJHxLX\9AsT-P\dKtSN5wkI\GWrBK8mbOy.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\ldmozuncs-h9r3 xu2.mp4.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\_3Wl5D4o0g2MKtP.pptx.vvyu | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\kir-tas9lgdeh fxubwy\iifmhh\ksif.bmp.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\D1q0P.docx.vvyu | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\music\bjhxlx\cmbsppstlrb9u.m4a.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\KUOP p2txHoo7bw7O.doc.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\cmt4.gif.vvyu | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\us8ywh8d_vcxiyflf5e.m4a.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\BJHxLX\KnG7feMIAKlEoa_UW1s2.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Pictures\O_9gyTeSlm.jpg.vvyu | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\documents\hhuy\ynkbyrnkc6j3avv0zier.odt.vvyu | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\kir-tas9lgdeh fxubwy\iifmhh\xudjwurucylo9.bmp.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Videos\z2E0zT\vtiS4AAZ_oK\s_e2a5ScpFSgR9-.mkv.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\nQrFKLA.gif.vvyu | Dropped File | Image |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\BJHxLX\9AsT-P\dKtSN5wkI\a6C7l-Qq0p-ecvc_8DsT.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\hhuy\U-GFPMIYoqWy2p9O.xlsx.vvyu | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\i5zfv_jkmmjeubuqus.gif.vvyu | Dropped File | Image |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\567c.pdf.vvyu | Dropped File |
Malicious
|
...
|
C:\Users\kEecfMwgj\Pictures\KiR-tAs9lgdEh FXubwY\iIfMhH\5DS0X1cGBS4n2igZsE.jpg.vvyu | Dropped File | Image |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\BJHxLX\dTVoZ bX824b.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\sj76aMesI3jmtOuE2hz\UovhOsbqK0eMsW0c\GW5kXQqybZPUP2d4.mp4.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Contacts\Administrator.contact.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\ijdhlcko.jpg.vvyu | Dropped File | Image |
Malicious
|
...
|
C:\Users\kEecfMwgj\Pictures\n-nH-E2t.jpg.vvyu | Dropped File | Image |
Malicious
|
...
|
C:\Users\kEecfMwgj\Pictures\KiR-tAs9lgdEh FXubwY\yOmL -Z4 9fyb2IF7S9.png.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\itjgP.m4a.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\kymags7f-4q1mza r\dtf66.png.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Videos\hDvzuhrdv.mkv.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\kir-tas9lgdeh fxubwy\5qvh55h.bmp.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\hhuy\z99M8Y1GRoOyuotMz.csv.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\documents\hhuy\naiaggm8s5tskx.docx.vvyu | Dropped File | ZIP |
Malicious
|
...
|
C:\Users\kEecfMwgj\Pictures\KiR-tAs9lgdEh FXubwY\iIfMhH\9VRBBaa2E6cjsKGlie.gif.vvyu | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\bq6sji8ro0rg0dp\9ecwyh_e3fhju.avi.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\videos\z2e0zt\vtis4aaz_ok\_qbp0nkguotbuaqg\a9pzarvgiar.avi.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\sj76amesi3jmtoue2hz\uovhosbqk0emsw0c\ghprnga3a e4cboqml8u.bmp.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\4COwR1C7ya7.pptx.vvyu | Dropped File | ZIP |
Malicious
|
...
|
C:\Users\kEecfMwgj\Pictures\bQiz44uQ681_7Dctbgxp.jpg.vvyu | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\sj76amesi3jmtoue2hz\tkvyxwxrq.ots.vvyu | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\nwy04.bmp.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\sj76aMesI3jmtOuE2hz\UovhOsbqK0eMsW0c\rQja5oZ7_uz\EhqiUu8LglRl.mp4.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\kymags7f-4q1mza r\lxhmd.gif.vvyu | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\documents\py_fftiab_q4nwhp.docx.vvyu | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\music\nmf9emihkrld8q1qs.mp3.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\videos\z2e0zt\vtis4aaz_ok\b8gbt7knns9kt-gvh.swf.vvyu | Dropped File | Shockwave Flash |
Malicious
|
...
|
C:\Users\kEecfMwgj\Pictures\KiR-tAs9lgdEh FXubwY\v97V_KMwmgn4h6UDx.jpg.vvyu | Dropped File | Image |
Malicious
|
...
|
C:\Users\kEecfMwgj\Videos\z2E0zT\vtiS4AAZ_oK\cPfFJ9.flv.vvyu | Dropped File | Video |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\sj76amesi3jmtoue2hz\6pw8rpgl-.flv.vvyu | Dropped File | Video |
Malicious
|
...
|
C:\Users\kEecfMwgj\Videos\z2E0zT\vtiS4AAZ_oK\MpjP3oSTE.mkv.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\music\mxrqwfqcp\_fbv4xgh8clctd- y4\02rh90y7rebgxw.mp3.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Videos\z2E0zT\vtiS4AAZ_oK\Asv9iqUaFA9rCWFze77.avi.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\documents\hhuy\bju5iwgzcivxdeaczva1.odt.vvyu | Dropped File | ZIP |
Malicious
|
...
|
C:\Users\kEecfMwgj\Pictures\kyMAgs7f-4q1mza r\uo7bfSHfyn-0X-MGd.bmp.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Pictures\kyMAgs7f-4q1mza r\2j2l02AsmvpG-FW9.gif.vvyu | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\documents\hhuy\ytkydbos.xlsx.vvyu | Dropped File | ZIP |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\BJHxLX\9AsT-P\dKtSN5wkI\6y-Gle7CJ.m4a.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\kir-tas9lgdeh fxubwy\ydph4cpxgp3qwyuc\x5tjkqt17l1kq.bmp.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\tHLd WYzw.ots.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\videos\z2e0zt\zpv7u7xpwr7qk\iwi4py9f_tbuupcdk.flv.vvyu | Dropped File | Video |
Malicious
|
...
|
c:\users\keecfmwgj\documents\hhuy\ni1u7vxc2c n4uuhwh.pps.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\sj76amesi3jmtoue2hz\uovhosbqk0emsw0c\wa_4pk0l7jwgqv.xlsx.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\CzDS-.pptx.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\BJHxLX\9AsT-P\dKtSN5wkI\HbqLBzpGm.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\sj76aMesI3jmtOuE2hz\UovhOsbqK0eMsW0c\0jip-0WU2n5fd8 POL.bmp.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\music\mxrqwfqcp\_fbv4xgh8clctd- y4\-ahhgkvlxn_kxd.m4a.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\K3t8MlfEa.mp3.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\music\mxrqwfqcp\_fbv4xgh8clctd- y4\t laiuy5vumxfxacjn.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\kir-tas9lgdeh fxubwy\ydph4cpxgp3qwyuc\aougfr90ajw.jpg.vvyu | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\music\mxrqwfqcp\jze7xrus.m4a.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\videos\z2e0zt\vtis4aaz_ok\_qbp0nkguotbuaqg\la08fq2wwngfs3w9kc.swf.vvyu | Dropped File | Shockwave Flash |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\2oZu1wT.ppt.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\music\olz6-jxmw7o1_h pvu.mp3.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\videos\z2e0zt\zpv7u7xpwr7qk\1l1mbixt edk.mkv.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\hhuy\Qs2 hK9Y_.xlsx.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\documents\qtnn2gz.xlsx.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\videos\z2e0zt\zpv7u7xpwr7qk\rfes3vfwf3fsy6sx.flv.vvyu | Dropped File | Video |
Malicious
|
...
|
c:\users\keecfmwgj\appdata\locallow\microsoft\internet explorer\services\search_{0633ee93-d776-472f-a0ff-e1416b8b2e3a}.ico.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\hsxa8jyxcbsx17ja94r_.jpg.vvyu | Dropped File | Image |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\mXrqWFqcp\-xht.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\cTaPN4HhRqe86tN.rtf.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\kir-tas9lgdeh fxubwy\iifmhh\pfzhnu297.png.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\favorites\links\web slice gallery.url.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\favorites\msn websites\msn.url.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\favorites\msn websites\msnbc news.url.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\favorites\msn websites\msn autos.url.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\favorites\msn websites\msn entertainment.url.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\favorites\windows live\get windows live.url.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Favorites\MSN Websites\MSN Money.url.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\AppData\Local\c01688bb-f556-4db2-ba2c-05b15fa562c3\build2.exe | Dropped File | Binary |
Clean
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x0040B990 |
Size Of Code | 0x00032600 |
Size Of Initialized Data | 0x00047E00 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2022-01-04 05:28 (UTC+1) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x00032482 | 0x00032600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.75 |
.data | 0x00434000 | 0x00032988 | 0x00029A00 | 0x00032A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.99 |
.zonami | 0x00467000 | 0x00000400 | 0x00000400 | 0x0005C400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.yosozi | 0x00468000 | 0x00000400 | 0x00000400 | 0x0005C800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.may | 0x00469000 | 0x00000096 | 0x00000200 | 0x0005CC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x0046A000 | 0x000108D0 | 0x00010A00 | 0x0005CE00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VerifyVersionInfoA | - | 0x00401008 | 0x0003227C | 0x0003167C | 0x00000452 |
VerifyVersionInfoW | - | 0x0040100C | 0x00032280 | 0x00031680 | 0x00000453 |
WriteConsoleInputW | - | 0x00401010 | 0x00032284 | 0x00031684 | 0x00000486 |
EnumDateFormatsW | - | 0x00401014 | 0x00032288 | 0x00031688 | 0x000000E3 |
FindNextFileW | - | 0x00401018 | 0x0003228C | 0x0003168C | 0x00000130 |
CopyFileExA | - | 0x0040101C | 0x00032290 | 0x00031690 | 0x00000061 |
DnsHostnameToComputerNameW | - | 0x00401020 | 0x00032294 | 0x00031694 | 0x000000CF |
ReadConsoleOutputCharacterW | - | 0x00401024 | 0x00032298 | 0x00031698 | 0x00000364 |
SetConsoleActiveScreenBuffer | - | 0x00401028 | 0x0003229C | 0x0003169C | 0x000003A5 |
LockFile | - | 0x0040102C | 0x000322A0 | 0x000316A0 | 0x00000305 |
GetProfileSectionA | - | 0x00401030 | 0x000322A4 | 0x000316A4 | 0x00000231 |
QueryDosDeviceW | - | 0x00401034 | 0x000322A8 | 0x000316A8 | 0x0000034E |
IsSystemResumeAutomatic | - | 0x00401038 | 0x000322AC | 0x000316AC | 0x000002D6 |
GetProcessPriorityBoost | - | 0x0040103C | 0x000322B0 | 0x000316B0 | 0x00000228 |
GetDriveTypeW | - | 0x00401040 | 0x000322B4 | 0x000316B4 | 0x000001BB |
GlobalGetAtomNameA | - | 0x00401044 | 0x000322B8 | 0x000316B8 | 0x0000028D |
lstrlenA | - | 0x00401048 | 0x000322BC | 0x000316BC | 0x000004B5 |
FindNextVolumeMountPointW | - | 0x0040104C | 0x000322C0 | 0x000316C0 | 0x00000134 |
TlsGetValue | - | 0x00401050 | 0x000322C4 | 0x000316C4 | 0x00000434 |
SizeofResource | - | 0x00401054 | 0x000322C8 | 0x000316C8 | 0x00000420 |
WriteConsoleInputA | - | 0x00401058 | 0x000322CC | 0x000316CC | 0x00000483 |
GetConsoleTitleW | - | 0x0040105C | 0x000322D0 | 0x000316D0 | 0x0000019F |
GetComputerNameExW | - | 0x00401060 | 0x000322D4 | 0x000316D4 | 0x00000177 |
OpenEventA | - | 0x00401064 | 0x000322D8 | 0x000316D8 | 0x00000327 |
CallNamedPipeW | - | 0x00401068 | 0x000322DC | 0x000316DC | 0x00000030 |
GetModuleHandleW | - | 0x0040106C | 0x000322E0 | 0x000316E0 | 0x000001F9 |
GetSystemDirectoryA | - | 0x00401070 | 0x000322E4 | 0x000316E4 | 0x00000245 |
SetCurrentDirectoryA | - | 0x00401074 | 0x000322E8 | 0x000316E8 | 0x000003C6 |
BuildCommDCBAndTimeoutsA | - | 0x00401078 | 0x000322EC | 0x000316EC | 0x0000002C |
GetProcAddress | - | 0x0040107C | 0x000322F0 | 0x000316F0 | 0x00000220 |
GetModuleHandleA | - | 0x00401080 | 0x000322F4 | 0x000316F4 | 0x000001F6 |
MoveFileWithProgressW | - | 0x00401084 | 0x000322F8 | 0x000316F8 | 0x00000318 |
GetCommandLineW | - | 0x00401088 | 0x000322FC | 0x000316FC | 0x00000170 |
InterlockedIncrement | - | 0x0040108C | 0x00032300 | 0x00031700 | 0x000002C0 |
InterlockedExchange | - | 0x00401090 | 0x00032304 | 0x00031704 | 0x000002BD |
CopyFileW | - | 0x00401094 | 0x00032308 | 0x00031708 | 0x00000065 |
CreateActCtxW | - | 0x00401098 | 0x0003230C | 0x0003170C | 0x00000068 |
FormatMessageW | - | 0x0040109C | 0x00032310 | 0x00031710 | 0x00000148 |
EnterCriticalSection | - | 0x004010A0 | 0x00032314 | 0x00031714 | 0x000000D9 |
FindNextVolumeW | - | 0x004010A4 | 0x00032318 | 0x00031718 | 0x00000135 |
GetOverlappedResult | - | 0x004010A8 | 0x0003231C | 0x0003171C | 0x00000214 |
LoadLibraryA | - | 0x004010AC | 0x00032320 | 0x00031720 | 0x000002F1 |
CreateNamedPipeW | - | 0x004010B0 | 0x00032324 | 0x00031724 | 0x00000090 |
GetSystemDefaultLangID | - | 0x004010B4 | 0x00032328 | 0x00031728 | 0x00000242 |
GetConsoleAliasesLengthA | - | 0x004010B8 | 0x0003232C | 0x0003172C | 0x00000180 |
WriteProfileSectionW | - | 0x004010BC | 0x00032330 | 0x00031730 | 0x00000498 |
AddAtomW | - | 0x004010C0 | 0x00032334 | 0x00031734 | 0x00000004 |
InterlockedDecrement | - | 0x004010C4 | 0x00032338 | 0x00031738 | 0x000002BC |
HeapFree | - | 0x004010C8 | 0x0003233C | 0x0003173C | 0x000002A1 |
_hwrite | - | 0x004010CC | 0x00032340 | 0x00031740 | 0x0000049E |
InterlockedExchangeAdd | - | 0x004010D0 | 0x00032344 | 0x00031744 | 0x000002BE |
GetStartupInfoW | - | 0x004010D4 | 0x00032348 | 0x00031748 | 0x0000023A |
CreateMailslotW | - | 0x004010D8 | 0x0003234C | 0x0003174C | 0x00000089 |
GetCPInfoExW | - | 0x004010DC | 0x00032350 | 0x00031750 | 0x0000015D |
GetSystemWow64DirectoryW | - | 0x004010E0 | 0x00032354 | 0x00031754 | 0x00000254 |
GetLastError | - | 0x004010E4 | 0x00032358 | 0x00031758 | 0x000001E6 |
GetPrivateProfileIntA | - | 0x004010E8 | 0x0003235C | 0x0003175C | 0x00000216 |
GetConsoleAliasExesLengthW | - | 0x004010EC | 0x00032360 | 0x00031760 | 0x0000017C |
DebugBreak | - | 0x004010F0 | 0x00032364 | 0x00031764 | 0x000000B4 |
SetLastError | - | 0x004010F4 | 0x00032368 | 0x00031768 | 0x000003EC |
LoadLibraryW | - | 0x004010F8 | 0x0003236C | 0x0003176C | 0x000002F4 |
GetDefaultCommConfigA | - | 0x004010FC | 0x00032370 | 0x00031770 | 0x000001B1 |
VirtualAlloc | - | 0x00401100 | 0x00032374 | 0x00031774 | 0x00000454 |
GetACP | - | 0x00401104 | 0x00032378 | 0x00031778 | 0x00000152 |
lstrcpyA | - | 0x00401108 | 0x0003237C | 0x0003177C | 0x000004AF |
GetConsoleAliasA | - | 0x0040110C | 0x00032380 | 0x00031780 | 0x00000179 |
FindNextFileA | - | 0x00401110 | 0x00032384 | 0x00031784 | 0x0000012E |
TerminateProcess | - | 0x00401114 | 0x00032388 | 0x00031788 | 0x0000042D |
EnumResourceLanguagesA | - | 0x00401118 | 0x0003238C | 0x0003178C | 0x000000E6 |
SetConsoleTextAttribute | - | 0x0040111C | 0x00032390 | 0x00031790 | 0x000003C0 |
GlobalGetAtomNameW | - | 0x00401120 | 0x00032394 | 0x00031794 | 0x0000028E |
CreateJobSet | - | 0x00401124 | 0x00032398 | 0x00031798 | 0x00000087 |
lstrcpynA | - | 0x00401128 | 0x0003239C | 0x0003179C | 0x000004B2 |
EnumSystemLocalesA | - | 0x0040112C | 0x000323A0 | 0x000317A0 | 0x000000F8 |
GetPrivateProfileSectionNamesW | - | 0x00401130 | 0x000323A4 | 0x000317A4 | 0x0000021A |
OpenMutexW | - | 0x00401134 | 0x000323A8 | 0x000317A8 | 0x00000330 |
FileTimeToSystemTime | - | 0x00401138 | 0x000323AC | 0x000317AC | 0x00000110 |
CopyFileA | - | 0x0040113C | 0x000323B0 | 0x000317B0 | 0x00000060 |
GlobalWire | - | 0x00401140 | 0x000323B4 | 0x000317B4 | 0x00000298 |
GetTapeParameters | - | 0x00401144 | 0x000323B8 | 0x000317B8 | 0x00000255 |
lstrcmpW | - | 0x00401148 | 0x000323BC | 0x000317BC | 0x000004AA |
SetEvent | - | 0x0040114C | 0x000323C0 | 0x000317C0 | 0x000003D3 |
MoveFileA | - | 0x00401150 | 0x000323C4 | 0x000317C4 | 0x00000311 |
CreateMutexA | - | 0x00401154 | 0x000323C8 | 0x000317C8 | 0x0000008B |
FindResourceW | - | 0x00401158 | 0x000323CC | 0x000317CC | 0x00000139 |
GetCommState | - | 0x0040115C | 0x000323D0 | 0x000317D0 | 0x0000016D |
FormatMessageA | - | 0x00401160 | 0x000323D4 | 0x000317D4 | 0x00000147 |
InterlockedCompareExchange | - | 0x00401164 | 0x000323D8 | 0x000317D8 | 0x000002BA |
CreateFiber | - | 0x00401168 | 0x000323DC | 0x000317DC | 0x00000076 |
GetConsoleFontSize | - | 0x0040116C | 0x000323E0 | 0x000317E0 | 0x0000018D |
LocalAlloc | - | 0x00401170 | 0x000323E4 | 0x000317E4 | 0x000002F9 |
SetFileShortNameA | - | 0x00401174 | 0x000323E8 | 0x000317E8 | 0x000003E1 |
lstrcpyW | - | 0x00401178 | 0x000323EC | 0x000317EC | 0x000004B0 |
HeapLock | - | 0x0040117C | 0x000323F0 | 0x000317F0 | 0x000002A2 |
GetFileAttributesA | - | 0x00401180 | 0x000323F4 | 0x000317F4 | 0x000001C9 |
SetCalendarInfoW | - | 0x00401184 | 0x000323F8 | 0x000317F8 | 0x00000399 |
GetSystemWindowsDirectoryW | - | 0x00401188 | 0x000323FC | 0x000317FC | 0x00000252 |
GetConsoleAliasesW | - | 0x0040118C | 0x00032400 | 0x00031800 | 0x00000182 |
EnumDateFormatsExW | - | 0x00401190 | 0x00032404 | 0x00031804 | 0x000000E2 |
GetComputerNameW | - | 0x00401194 | 0x00032408 | 0x00031808 | 0x00000178 |
GetPrivateProfileStructW | - | 0x00401198 | 0x0003240C | 0x0003180C | 0x0000021F |
_hread | - | 0x0040119C | 0x00032410 | 0x00031810 | 0x0000049D |
LocalSize | - | 0x004011A0 | 0x00032414 | 0x00031814 | 0x00000302 |
OpenWaitableTimerA | - | 0x004011A4 | 0x00032418 | 0x00031818 | 0x00000338 |
EnumResourceNamesW | - | 0x004011A8 | 0x0003241C | 0x0003181C | 0x000000ED |
CreateFileMappingW | - | 0x004011AC | 0x00032420 | 0x00031820 | 0x0000007C |
SetUnhandledExceptionFilter | - | 0x004011B0 | 0x00032424 | 0x00031824 | 0x00000415 |
GetSystemTimeAdjustment | - | 0x004011B4 | 0x00032428 | 0x00031828 | 0x0000024E |
SetProcessShutdownParameters | - | 0x004011B8 | 0x0003242C | 0x0003182C | 0x000003F9 |
lstrcpynW | - | 0x004011BC | 0x00032430 | 0x00031830 | 0x000004B3 |
GetThreadSelectorEntry | - | 0x004011C0 | 0x00032434 | 0x00031834 | 0x00000263 |
GetNamedPipeHandleStateA | - | 0x004011C4 | 0x00032438 | 0x00031838 | 0x00000201 |
FillConsoleOutputCharacterA | - | 0x004011C8 | 0x0003243C | 0x0003183C | 0x00000112 |
GetFullPathNameW | - | 0x004011CC | 0x00032440 | 0x00031840 | 0x000001DF |
GetThreadPriority | - | 0x004011D0 | 0x00032444 | 0x00031844 | 0x00000261 |
WriteConsoleA | - | 0x004011D4 | 0x00032448 | 0x00031848 | 0x00000482 |
AddAtomA | - | 0x004011D8 | 0x0003244C | 0x0003184C | 0x00000003 |
FreeUserPhysicalPages | - | 0x004011DC | 0x00032450 | 0x00031850 | 0x00000150 |
WriteConsoleOutputCharacterW | - | 0x004011E0 | 0x00032454 | 0x00031854 | 0x0000048A |
OpenJobObjectW | - | 0x004011E4 | 0x00032458 | 0x00031858 | 0x0000032E |
CreateFileW | - | 0x004011E8 | 0x0003245C | 0x0003185C | 0x0000007F |
BuildCommDCBAndTimeoutsW | - | 0x004011EC | 0x00032460 | 0x00031860 | 0x0000002D |
GetBinaryTypeW | - | 0x004011F0 | 0x00032464 | 0x00031864 | 0x00000159 |
SetCalendarInfoA | - | 0x004011F4 | 0x00032468 | 0x00031868 | 0x00000398 |
GetFileAttributesW | - | 0x004011F8 | 0x0003246C | 0x0003186C | 0x000001CE |
GetFileInformationByHandle | - | 0x004011FC | 0x00032470 | 0x00031870 | 0x000001D0 |
GetProfileSectionW | - | 0x00401200 | 0x00032474 | 0x00031874 | 0x00000232 |
CommConfigDialogW | - | 0x00401204 | 0x00032478 | 0x00031878 | 0x0000004F |
GetDiskFreeSpaceExA | - | 0x00401208 | 0x0003247C | 0x0003187C | 0x000001B5 |
LocalFree | - | 0x0040120C | 0x00032480 | 0x00031880 | 0x000002FD |
Sleep | - | 0x00401210 | 0x00032484 | 0x00031884 | 0x00000421 |
InitializeCriticalSection | - | 0x00401214 | 0x00032488 | 0x00031888 | 0x000002B4 |
DeleteCriticalSection | - | 0x00401218 | 0x0003248C | 0x0003188C | 0x000000BE |
LeaveCriticalSection | - | 0x0040121C | 0x00032490 | 0x00031890 | 0x000002EF |
RaiseException | - | 0x00401220 | 0x00032494 | 0x00031894 | 0x0000035A |
RtlUnwind | - | 0x00401224 | 0x00032498 | 0x00031898 | 0x00000392 |
WideCharToMultiByte | - | 0x00401228 | 0x0003249C | 0x0003189C | 0x0000047A |
GetCommandLineA | - | 0x0040122C | 0x000324A0 | 0x000318A0 | 0x0000016F |
GetStartupInfoA | - | 0x00401230 | 0x000324A4 | 0x000318A4 | 0x00000239 |
HeapValidate | - | 0x00401234 | 0x000324A8 | 0x000318A8 | 0x000002A9 |
IsBadReadPtr | - | 0x00401238 | 0x000324AC | 0x000318AC | 0x000002C8 |
UnhandledExceptionFilter | - | 0x0040123C | 0x000324B0 | 0x000318B0 | 0x0000043E |
GetModuleFileNameW | - | 0x00401240 | 0x000324B4 | 0x000318B4 | 0x000001F5 |
GetCurrentProcess | - | 0x00401244 | 0x000324B8 | 0x000318B8 | 0x000001A9 |
IsDebuggerPresent | - | 0x00401248 | 0x000324BC | 0x000318BC | 0x000002D1 |
TlsAlloc | - | 0x0040124C | 0x000324C0 | 0x000318C0 | 0x00000432 |
TlsSetValue | - | 0x00401250 | 0x000324C4 | 0x000318C4 | 0x00000435 |
GetCurrentThreadId | - | 0x00401254 | 0x000324C8 | 0x000318C8 | 0x000001AD |
TlsFree | - | 0x00401258 | 0x000324CC | 0x000318CC | 0x00000433 |
GetOEMCP | - | 0x0040125C | 0x000324D0 | 0x000318D0 | 0x00000213 |
GetCPInfo | - | 0x00401260 | 0x000324D4 | 0x000318D4 | 0x0000015B |
IsValidCodePage | - | 0x00401264 | 0x000324D8 | 0x000318D8 | 0x000002DB |
SetFilePointer | - | 0x00401268 | 0x000324DC | 0x000318DC | 0x000003DF |
SetHandleCount | - | 0x0040126C | 0x000324E0 | 0x000318E0 | 0x000003E8 |
GetStdHandle | - | 0x00401270 | 0x000324E4 | 0x000318E4 | 0x0000023B |
GetFileType | - | 0x00401274 | 0x000324E8 | 0x000318E8 | 0x000001D7 |
QueryPerformanceCounter | - | 0x00401278 | 0x000324EC | 0x000318EC | 0x00000354 |
GetTickCount | - | 0x0040127C | 0x000324F0 | 0x000318F0 | 0x00000266 |
GetCurrentProcessId | - | 0x00401280 | 0x000324F4 | 0x000318F4 | 0x000001AA |
GetSystemTimeAsFileTime | - | 0x00401284 | 0x000324F8 | 0x000318F8 | 0x0000024F |
ExitProcess | - | 0x00401288 | 0x000324FC | 0x000318FC | 0x00000104 |
GetModuleFileNameA | - | 0x0040128C | 0x00032500 | 0x00031900 | 0x000001F4 |
FreeEnvironmentStringsA | - | 0x00401290 | 0x00032504 | 0x00031904 | 0x0000014A |
GetEnvironmentStrings | - | 0x00401294 | 0x00032508 | 0x00031908 | 0x000001BF |
FreeEnvironmentStringsW | - | 0x00401298 | 0x0003250C | 0x0003190C | 0x0000014B |
GetEnvironmentStringsW | - | 0x0040129C | 0x00032510 | 0x00031910 | 0x000001C1 |
HeapDestroy | - | 0x004012A0 | 0x00032514 | 0x00031914 | 0x000002A0 |
HeapCreate | - | 0x004012A4 | 0x00032518 | 0x00031918 | 0x0000029F |
VirtualFree | - | 0x004012A8 | 0x0003251C | 0x0003191C | 0x00000457 |
WriteFile | - | 0x004012AC | 0x00032520 | 0x00031920 | 0x0000048D |
HeapAlloc | - | 0x004012B0 | 0x00032524 | 0x00031924 | 0x0000029D |
HeapSize | - | 0x004012B4 | 0x00032528 | 0x00031928 | 0x000002A6 |
HeapReAlloc | - | 0x004012B8 | 0x0003252C | 0x0003192C | 0x000002A4 |
FlushFileBuffers | - | 0x004012BC | 0x00032530 | 0x00031930 | 0x00000141 |
GetConsoleCP | - | 0x004012C0 | 0x00032534 | 0x00031934 | 0x00000183 |
GetConsoleMode | - | 0x004012C4 | 0x00032538 | 0x00031938 | 0x00000195 |
OutputDebugStringA | - | 0x004012C8 | 0x0003253C | 0x0003193C | 0x0000033A |
WriteConsoleW | - | 0x004012CC | 0x00032540 | 0x00031940 | 0x0000048C |
OutputDebugStringW | - | 0x004012D0 | 0x00032544 | 0x00031944 | 0x0000033B |
InitializeCriticalSectionAndSpinCount | - | 0x004012D4 | 0x00032548 | 0x00031948 | 0x000002B5 |
MultiByteToWideChar | - | 0x004012D8 | 0x0003254C | 0x0003194C | 0x0000031A |
LCMapStringA | - | 0x004012DC | 0x00032550 | 0x00031950 | 0x000002E1 |
LCMapStringW | - | 0x004012E0 | 0x00032554 | 0x00031954 | 0x000002E3 |
GetStringTypeA | - | 0x004012E4 | 0x00032558 | 0x00031958 | 0x0000023D |
GetStringTypeW | - | 0x004012E8 | 0x0003255C | 0x0003195C | 0x00000240 |
GetLocaleInfoA | - | 0x004012EC | 0x00032560 | 0x00031960 | 0x000001E8 |
SetStdHandle | - | 0x004012F0 | 0x00032564 | 0x00031964 | 0x000003FC |
GetConsoleOutputCP | - | 0x004012F4 | 0x00032568 | 0x00031968 | 0x00000199 |
CloseHandle | - | 0x004012F8 | 0x0003256C | 0x0003196C | 0x00000043 |
CreateFileA | - | 0x004012FC | 0x00032570 | 0x00031970 | 0x00000078 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CharToOemBuffW | - | 0x00401304 | 0x00032578 | 0x00031978 | 0x00000035 |
CharUpperA | - | 0x00401308 | 0x0003257C | 0x0003197C | 0x00000037 |
GetCursorInfo | - | 0x0040130C | 0x00032580 | 0x00031980 | 0x00000118 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
AbortSystemShutdownW | - | 0x00401000 | 0x00032274 | 0x00031674 | 0x00000004 |
C:\Users\kEecfMwgj\Pictures\KiR-tAs9lgdEh FXubwY\yDPh4CpXgP3QwyUC\BY rE6U_U.png.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\_dmv92xp.pptx.vvyu | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\documents\hhuy\fndguil2ubhxleqmkv.odt.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\K0lcD1nSajNFFT.odp.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\z2E0zT\vtiS4AAZ_oK\_qbp0nkGuotBuAqg\Ie5lbJNFps_4_oZKKr.mkv.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\dnsctzwstnyxbfiqs.docx.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\sj76aMesI3jmtOuE2hz\UovhOsbqK0eMsW0c\1OTdzHn.jpg.vvyu | Dropped File | Image |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\z2E0zT\vtiS4AAZ_oK\Tb8PI4n8ykiF82PGQ8M.mkv.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\mXrqWFqcp\_fBV4xgh8cLcTD- y4\hyXqTEnB.mp3.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\music\mxrqwfqcp\xxli1eqxvup5i 0hs6g.mp3.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\QYjbm5MiXLG2.mp3.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\hhuy\4q235s.pptx.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\kyMAgs7f-4q1mza r\7Wfuj5RqE1i.gif.vvyu | Dropped File | Image |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\HbBtrfj.pptx.vvyu | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\desktop\j2jjifmto45jzep.jpg.vvyu | Dropped File | Image |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\KiR-tAs9lgdEh FXubwY\-F78Z7ifiP0.png.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\wnp_miikwb9ajxhhez.ots.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\z2E0zT\zpV7u7xPWr7qK\Nm71rwXGGr4kpL3.mp4.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\z2E0zT\ufb ajK.mkv.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\hhuy\gGXI3yELl78C2wDp.pps.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\KiR-tAs9lgdEh FXubwY\yDPh4CpXgP3QwyUC\faTUjwnla.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\z2E0zT\vtiS4AAZ_oK\MHkDGP m.avi.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\SipikwOFNhn.swf.vvyu | Dropped File | Shockwave Flash |
Clean
|
...
|
c:\users\keecfmwgj\music\bjhxlx\9ast-p\fgnl6u1fsaf.m4a.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\bq6sji8ro0rg0dp\3ysvczxv.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\kyMAgs7f-4q1mza r\k_XON6PdpszzEOE.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\pictures\77x _hi5d64n725my.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\pictures\eotpxodhmybxn _gv_k_.jpg.vvyu | Dropped File | Image |
Clean
|
...
|
c:\users\keecfmwgj\videos\z2e0zt\vtis4aaz_ok\_qbp0nkguotbuaqg\qq8tjsc3zm363.avi.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\videos\z2e0zt\vtis4aaz_ok\_qbp0nkguotbuaqg\m mfu p.mp4.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\videos\k0zmij7sn.mp4.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\videos\z2e0zt\vtis4aaz_ok\8fbu8gjzxgn5dwk.avi.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\ofbl.flv.vvyu | Dropped File | Video |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\KiR-tAs9lgdEh FXubwY\9OGpykt3_l8cM2Jx4cn.jpg.vvyu | Dropped File | Image |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\RDY1PliN5xV7.mp4.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\0Lepi.xlsx.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\sj76aMesI3jmtOuE2hz\UovhOsbqK0eMsW0c\powW2.png.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\5h1grurzazne.docx.vvyu | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\videos\z2e0zt\vtis4aaz_ok\38n2o1isspyqrtic8.mp4.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\dijvxxa4.xlsx.vvyu | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\music\bjhxlx\9ast-p\dktsn5wki\4gn5bamth.m4a.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\music\ikpvnlx.m4a.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\sj76amesi3jmtoue2hz\uovhosbqk0emsw0c\9zmn.mp3.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\music\bjhxlx\fwxn.wav.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\Bk2Yjoq3Rz.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\jw5nfujdo04vpw2wo.xlsx.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\J0ThFcHeulkvK.odp.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\6s3WjoHyRIY3EiBz5-U.avi.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\videos\z2e0zt\vtis4aaz_ok\a8eg.mp4.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\sj76amesi3jmtoue2hz\uovhosbqk0emsw0c\rookllxyjwewp5im.wav.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\VgPttkDeNDF2VRfHy.pps.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\ZzmcSYQ7d6yY4Z.png.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\3lz_j5_6ki.docx.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\2uv3ozugwqu6cyc7-l.swf.vvyu | Dropped File | Shockwave Flash |
Clean
|
...
|
c:\users\keecfmwgj\videos\z2e0zt\vtis4aaz_ok\i8obtvhhmb.swf.vvyu | Dropped File | Shockwave Flash |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\KiR-tAs9lgdEh FXubwY\iIfMhH\VL493DrYWM.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\hhuy\NxH6NL2Af5s5IGX.doc.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\hhuy\8tiqyxue.odp.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\mXrqWFqcp\o2CgGnJETcQ5zceImOM_.m4a.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\jqzylb.m4a.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\tPG-9VHK-ulBZl_Q.docx.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\dygx.docx.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\BJHxLX\9AsT-P\dKtSN5wkI\2wJfI-R ZYJEjLJl_Hmt.mp3.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\music\yxhayb.mp3.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\hhuy\84p7mNA.doc.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\hhuy\6a8RDH85d8whH-HX.pptx.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\823XfKbFCBWP.m4a.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\esAg2qtf u0s5C0MdPd.mp3.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\zliy3__ym6-.csv.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\videos\z2e0zt\vtis4aaz_ok\kvyeo7pecdl1br27xvac.mkv.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\pictures\kymags7f-4q1mza r\ae6i4hslrl.png.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\YZcqJ4cWJ.png.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\sj76amesi3jmtoue2hz\uovhosbqk0emsw0c\rqja5oz7_uz\kylqcyn6yv.pps.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\l-ti2nvrpacp-tk9f.mkv.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\2twJZ0dzmRfJrmP6B.mp3.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\m ttnqtecinkd5iuv7o.ots.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\hhuy\jkSu2OlxWSDLnSWvMq.ods.vvyu | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\music\bjhxlx\rbnh h.wav.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\pictures\kir-tas9lgdeh fxubwy\ydph4cpxgp3qwyuc\irzpaayv6fb7p4.gif.vvyu | Dropped File | Image |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\HeOaqMZgOojF528t.odt.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\music\p5fl21.m4a.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\cqa0h3g9.ppt.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\t_ciyr3b-hwvi5yqwu4.ods.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\QQ3XsPcRg.swf.vvyu | Dropped File | Shockwave Flash |
Clean
|
...
|
c:\users\keecfmwgj\music\j6jnv8gx8rxbh.wav.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\KiR-tAs9lgdEh FXubwY\yDPh4CpXgP3QwyUC\tNBhPX6T.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\Cc9_9V6aB.avi.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\HZvZCiMH.gif.vvyu | Dropped File | Image |
Clean
|
...
|
c:\users\keecfmwgj\documents\kw5j7a5.doc.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\sj76aMesI3jmtOuE2hz\YUyI2uqRriEqQVB sFMm\XIwrATe.mp3.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\1IkZJVoATh.xls.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\music\bjhxlx\rp0gg8vjq4u.wav.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\pictures\kymags7f-4q1mza r\ydxrjd.png.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\KiR-tAs9lgdEh FXubwY\iIfMhH\tOBMO.gif.vvyu | Dropped File | Image |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\z2E0zT\g5znGT5HlbHq.mkv.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\z2E0zT\kYxGt6chL81vzY.avi.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\hhuy\igCF Ho.ppt.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\bmpgaj9.xlsx.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\videos\z2e0zt\oh6qpptsq5huew3v98y.swf.vvyu | Dropped File | Shockwave Flash |
Clean
|
...
|
C:\Users\kEecfMwgj\Favorites\Microsoft Websites\Microsoft Store.url.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\favorites\windows live\windows live mail.url.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\favorites\microsoft websites\microsoft at home.url.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\favorites\msn websites\msn sports.url.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\favorites\microsoft websites\ie site on microsoft.com.url.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Favorites\Microsoft Websites\Microsoft At Work.url.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Favorites\Windows Live\Windows Live Spaces.url.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Favorites\Windows Live\Windows Live Gallery.url.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Favorites\Microsoft Websites\IE Add-on site.url.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\srvsvc | Dropped File | Empty |
Clean
|
...
|
c:\wkssvc | Dropped File | Empty |
Clean
|
...
|
7d26da460ac85d8df173d3d63db203b40aad7c581ed8023cec40c91036090de5 | Downloaded File | Binary |
Clean
|
...
|
Image Base | 0x00400000 |
Entry Point | 0x0040B990 |
Size Of Code | 0x00032600 |
Size Of Initialized Data | 0x00047E00 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2022-01-04 05:28 (UTC+1) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x00032482 | 0x00032600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.75 |
.data | 0x00434000 | 0x00032988 | 0x00029A00 | 0x00032A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.94 |
.zonami | 0x00467000 | 0x00000400 | 0x00000400 | 0x0005C400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.yosozi | 0x00468000 | 0x00000400 | 0x00000400 | 0x0005C800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.may | 0x00469000 | 0x00000096 | 0x00000200 | 0x0005CC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x0046A000 | 0x000108D0 | 0x00010A00 | 0x0005CE00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.67 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VerifyVersionInfoA | - | 0x00401008 | 0x0003227C | 0x0003167C | 0x00000452 |
VerifyVersionInfoW | - | 0x0040100C | 0x00032280 | 0x00031680 | 0x00000453 |
WriteConsoleInputW | - | 0x00401010 | 0x00032284 | 0x00031684 | 0x00000486 |
EnumDateFormatsW | - | 0x00401014 | 0x00032288 | 0x00031688 | 0x000000E3 |
FindNextFileW | - | 0x00401018 | 0x0003228C | 0x0003168C | 0x00000130 |
CopyFileExA | - | 0x0040101C | 0x00032290 | 0x00031690 | 0x00000061 |
DnsHostnameToComputerNameW | - | 0x00401020 | 0x00032294 | 0x00031694 | 0x000000CF |
ReadConsoleOutputCharacterW | - | 0x00401024 | 0x00032298 | 0x00031698 | 0x00000364 |
SetConsoleActiveScreenBuffer | - | 0x00401028 | 0x0003229C | 0x0003169C | 0x000003A5 |
LockFile | - | 0x0040102C | 0x000322A0 | 0x000316A0 | 0x00000305 |
GetProfileSectionA | - | 0x00401030 | 0x000322A4 | 0x000316A4 | 0x00000231 |
QueryDosDeviceW | - | 0x00401034 | 0x000322A8 | 0x000316A8 | 0x0000034E |
IsSystemResumeAutomatic | - | 0x00401038 | 0x000322AC | 0x000316AC | 0x000002D6 |
GetProcessPriorityBoost | - | 0x0040103C | 0x000322B0 | 0x000316B0 | 0x00000228 |
GetDriveTypeW | - | 0x00401040 | 0x000322B4 | 0x000316B4 | 0x000001BB |
GlobalGetAtomNameA | - | 0x00401044 | 0x000322B8 | 0x000316B8 | 0x0000028D |
lstrlenA | - | 0x00401048 | 0x000322BC | 0x000316BC | 0x000004B5 |
FindNextVolumeMountPointW | - | 0x0040104C | 0x000322C0 | 0x000316C0 | 0x00000134 |
TlsGetValue | - | 0x00401050 | 0x000322C4 | 0x000316C4 | 0x00000434 |
SizeofResource | - | 0x00401054 | 0x000322C8 | 0x000316C8 | 0x00000420 |
WriteConsoleInputA | - | 0x00401058 | 0x000322CC | 0x000316CC | 0x00000483 |
GetConsoleTitleW | - | 0x0040105C | 0x000322D0 | 0x000316D0 | 0x0000019F |
GetComputerNameExW | - | 0x00401060 | 0x000322D4 | 0x000316D4 | 0x00000177 |
OpenEventA | - | 0x00401064 | 0x000322D8 | 0x000316D8 | 0x00000327 |
CallNamedPipeW | - | 0x00401068 | 0x000322DC | 0x000316DC | 0x00000030 |
GetModuleHandleW | - | 0x0040106C | 0x000322E0 | 0x000316E0 | 0x000001F9 |
GetSystemDirectoryA | - | 0x00401070 | 0x000322E4 | 0x000316E4 | 0x00000245 |
SetCurrentDirectoryA | - | 0x00401074 | 0x000322E8 | 0x000316E8 | 0x000003C6 |
BuildCommDCBAndTimeoutsA | - | 0x00401078 | 0x000322EC | 0x000316EC | 0x0000002C |
GetProcAddress | - | 0x0040107C | 0x000322F0 | 0x000316F0 | 0x00000220 |
GetModuleHandleA | - | 0x00401080 | 0x000322F4 | 0x000316F4 | 0x000001F6 |
MoveFileWithProgressW | - | 0x00401084 | 0x000322F8 | 0x000316F8 | 0x00000318 |
GetCommandLineW | - | 0x00401088 | 0x000322FC | 0x000316FC | 0x00000170 |
InterlockedIncrement | - | 0x0040108C | 0x00032300 | 0x00031700 | 0x000002C0 |
InterlockedExchange | - | 0x00401090 | 0x00032304 | 0x00031704 | 0x000002BD |
CopyFileW | - | 0x00401094 | 0x00032308 | 0x00031708 | 0x00000065 |
CreateActCtxW | - | 0x00401098 | 0x0003230C | 0x0003170C | 0x00000068 |
FormatMessageW | - | 0x0040109C | 0x00032310 | 0x00031710 | 0x00000148 |
EnterCriticalSection | - | 0x004010A0 | 0x00032314 | 0x00031714 | 0x000000D9 |
FindNextVolumeW | - | 0x004010A4 | 0x00032318 | 0x00031718 | 0x00000135 |
GetOverlappedResult | - | 0x004010A8 | 0x0003231C | 0x0003171C | 0x00000214 |
LoadLibraryA | - | 0x004010AC | 0x00032320 | 0x00031720 | 0x000002F1 |
CreateNamedPipeW | - | 0x004010B0 | 0x00032324 | 0x00031724 | 0x00000090 |
GetSystemDefaultLangID | - | 0x004010B4 | 0x00032328 | 0x00031728 | 0x00000242 |
GetConsoleAliasesLengthA | - | 0x004010B8 | 0x0003232C | 0x0003172C | 0x00000180 |
WriteProfileSectionW | - | 0x004010BC | 0x00032330 | 0x00031730 | 0x00000498 |
AddAtomW | - | 0x004010C0 | 0x00032334 | 0x00031734 | 0x00000004 |
InterlockedDecrement | - | 0x004010C4 | 0x00032338 | 0x00031738 | 0x000002BC |
HeapFree | - | 0x004010C8 | 0x0003233C | 0x0003173C | 0x000002A1 |
_hwrite | - | 0x004010CC | 0x00032340 | 0x00031740 | 0x0000049E |
InterlockedExchangeAdd | - | 0x004010D0 | 0x00032344 | 0x00031744 | 0x000002BE |
GetStartupInfoW | - | 0x004010D4 | 0x00032348 | 0x00031748 | 0x0000023A |
CreateMailslotW | - | 0x004010D8 | 0x0003234C | 0x0003174C | 0x00000089 |
GetCPInfoExW | - | 0x004010DC | 0x00032350 | 0x00031750 | 0x0000015D |
GetSystemWow64DirectoryW | - | 0x004010E0 | 0x00032354 | 0x00031754 | 0x00000254 |
GetLastError | - | 0x004010E4 | 0x00032358 | 0x00031758 | 0x000001E6 |
GetPrivateProfileIntA | - | 0x004010E8 | 0x0003235C | 0x0003175C | 0x00000216 |
GetConsoleAliasExesLengthW | - | 0x004010EC | 0x00032360 | 0x00031760 | 0x0000017C |
DebugBreak | - | 0x004010F0 | 0x00032364 | 0x00031764 | 0x000000B4 |
SetLastError | - | 0x004010F4 | 0x00032368 | 0x00031768 | 0x000003EC |
LoadLibraryW | - | 0x004010F8 | 0x0003236C | 0x0003176C | 0x000002F4 |
GetDefaultCommConfigA | - | 0x004010FC | 0x00032370 | 0x00031770 | 0x000001B1 |
VirtualAlloc | - | 0x00401100 | 0x00032374 | 0x00031774 | 0x00000454 |
GetACP | - | 0x00401104 | 0x00032378 | 0x00031778 | 0x00000152 |
lstrcpyA | - | 0x00401108 | 0x0003237C | 0x0003177C | 0x000004AF |
GetConsoleAliasA | - | 0x0040110C | 0x00032380 | 0x00031780 | 0x00000179 |
FindNextFileA | - | 0x00401110 | 0x00032384 | 0x00031784 | 0x0000012E |
TerminateProcess | - | 0x00401114 | 0x00032388 | 0x00031788 | 0x0000042D |
EnumResourceLanguagesA | - | 0x00401118 | 0x0003238C | 0x0003178C | 0x000000E6 |
SetConsoleTextAttribute | - | 0x0040111C | 0x00032390 | 0x00031790 | 0x000003C0 |
GlobalGetAtomNameW | - | 0x00401120 | 0x00032394 | 0x00031794 | 0x0000028E |
CreateJobSet | - | 0x00401124 | 0x00032398 | 0x00031798 | 0x00000087 |
lstrcpynA | - | 0x00401128 | 0x0003239C | 0x0003179C | 0x000004B2 |
EnumSystemLocalesA | - | 0x0040112C | 0x000323A0 | 0x000317A0 | 0x000000F8 |
GetPrivateProfileSectionNamesW | - | 0x00401130 | 0x000323A4 | 0x000317A4 | 0x0000021A |
OpenMutexW | - | 0x00401134 | 0x000323A8 | 0x000317A8 | 0x00000330 |
FileTimeToSystemTime | - | 0x00401138 | 0x000323AC | 0x000317AC | 0x00000110 |
CopyFileA | - | 0x0040113C | 0x000323B0 | 0x000317B0 | 0x00000060 |
GlobalWire | - | 0x00401140 | 0x000323B4 | 0x000317B4 | 0x00000298 |
GetTapeParameters | - | 0x00401144 | 0x000323B8 | 0x000317B8 | 0x00000255 |
lstrcmpW | - | 0x00401148 | 0x000323BC | 0x000317BC | 0x000004AA |
SetEvent | - | 0x0040114C | 0x000323C0 | 0x000317C0 | 0x000003D3 |
MoveFileA | - | 0x00401150 | 0x000323C4 | 0x000317C4 | 0x00000311 |
CreateMutexA | - | 0x00401154 | 0x000323C8 | 0x000317C8 | 0x0000008B |
FindResourceW | - | 0x00401158 | 0x000323CC | 0x000317CC | 0x00000139 |
GetCommState | - | 0x0040115C | 0x000323D0 | 0x000317D0 | 0x0000016D |
FormatMessageA | - | 0x00401160 | 0x000323D4 | 0x000317D4 | 0x00000147 |
InterlockedCompareExchange | - | 0x00401164 | 0x000323D8 | 0x000317D8 | 0x000002BA |
CreateFiber | - | 0x00401168 | 0x000323DC | 0x000317DC | 0x00000076 |
GetConsoleFontSize | - | 0x0040116C | 0x000323E0 | 0x000317E0 | 0x0000018D |
LocalAlloc | - | 0x00401170 | 0x000323E4 | 0x000317E4 | 0x000002F9 |
SetFileShortNameA | - | 0x00401174 | 0x000323E8 | 0x000317E8 | 0x000003E1 |
lstrcpyW | - | 0x00401178 | 0x000323EC | 0x000317EC | 0x000004B0 |
HeapLock | - | 0x0040117C | 0x000323F0 | 0x000317F0 | 0x000002A2 |
GetFileAttributesA | - | 0x00401180 | 0x000323F4 | 0x000317F4 | 0x000001C9 |
SetCalendarInfoW | - | 0x00401184 | 0x000323F8 | 0x000317F8 | 0x00000399 |
GetSystemWindowsDirectoryW | - | 0x00401188 | 0x000323FC | 0x000317FC | 0x00000252 |
GetConsoleAliasesW | - | 0x0040118C | 0x00032400 | 0x00031800 | 0x00000182 |
EnumDateFormatsExW | - | 0x00401190 | 0x00032404 | 0x00031804 | 0x000000E2 |
GetComputerNameW | - | 0x00401194 | 0x00032408 | 0x00031808 | 0x00000178 |
GetPrivateProfileStructW | - | 0x00401198 | 0x0003240C | 0x0003180C | 0x0000021F |
_hread | - | 0x0040119C | 0x00032410 | 0x00031810 | 0x0000049D |
LocalSize | - | 0x004011A0 | 0x00032414 | 0x00031814 | 0x00000302 |
OpenWaitableTimerA | - | 0x004011A4 | 0x00032418 | 0x00031818 | 0x00000338 |
EnumResourceNamesW | - | 0x004011A8 | 0x0003241C | 0x0003181C | 0x000000ED |
CreateFileMappingW | - | 0x004011AC | 0x00032420 | 0x00031820 | 0x0000007C |
SetUnhandledExceptionFilter | - | 0x004011B0 | 0x00032424 | 0x00031824 | 0x00000415 |
GetSystemTimeAdjustment | - | 0x004011B4 | 0x00032428 | 0x00031828 | 0x0000024E |
SetProcessShutdownParameters | - | 0x004011B8 | 0x0003242C | 0x0003182C | 0x000003F9 |
lstrcpynW | - | 0x004011BC | 0x00032430 | 0x00031830 | 0x000004B3 |
GetThreadSelectorEntry | - | 0x004011C0 | 0x00032434 | 0x00031834 | 0x00000263 |
GetNamedPipeHandleStateA | - | 0x004011C4 | 0x00032438 | 0x00031838 | 0x00000201 |
FillConsoleOutputCharacterA | - | 0x004011C8 | 0x0003243C | 0x0003183C | 0x00000112 |
GetFullPathNameW | - | 0x004011CC | 0x00032440 | 0x00031840 | 0x000001DF |
GetThreadPriority | - | 0x004011D0 | 0x00032444 | 0x00031844 | 0x00000261 |
WriteConsoleA | - | 0x004011D4 | 0x00032448 | 0x00031848 | 0x00000482 |
AddAtomA | - | 0x004011D8 | 0x0003244C | 0x0003184C | 0x00000003 |
FreeUserPhysicalPages | - | 0x004011DC | 0x00032450 | 0x00031850 | 0x00000150 |
WriteConsoleOutputCharacterW | - | 0x004011E0 | 0x00032454 | 0x00031854 | 0x0000048A |
OpenJobObjectW | - | 0x004011E4 | 0x00032458 | 0x00031858 | 0x0000032E |
CreateFileW | - | 0x004011E8 | 0x0003245C | 0x0003185C | 0x0000007F |
BuildCommDCBAndTimeoutsW | - | 0x004011EC | 0x00032460 | 0x00031860 | 0x0000002D |
GetBinaryTypeW | - | 0x004011F0 | 0x00032464 | 0x00031864 | 0x00000159 |
SetCalendarInfoA | - | 0x004011F4 | 0x00032468 | 0x00031868 | 0x00000398 |
GetFileAttributesW | - | 0x004011F8 | 0x0003246C | 0x0003186C | 0x000001CE |
GetFileInformationByHandle | - | 0x004011FC | 0x00032470 | 0x00031870 | 0x000001D0 |
GetProfileSectionW | - | 0x00401200 | 0x00032474 | 0x00031874 | 0x00000232 |
CommConfigDialogW | - | 0x00401204 | 0x00032478 | 0x00031878 | 0x0000004F |
GetDiskFreeSpaceExA | - | 0x00401208 | 0x0003247C | 0x0003187C | 0x000001B5 |
LocalFree | - | 0x0040120C | 0x00032480 | 0x00031880 | 0x000002FD |
Sleep | - | 0x00401210 | 0x00032484 | 0x00031884 | 0x00000421 |
InitializeCriticalSection | - | 0x00401214 | 0x00032488 | 0x00031888 | 0x000002B4 |
DeleteCriticalSection | - | 0x00401218 | 0x0003248C | 0x0003188C | 0x000000BE |
LeaveCriticalSection | - | 0x0040121C | 0x00032490 | 0x00031890 | 0x000002EF |
RaiseException | - | 0x00401220 | 0x00032494 | 0x00031894 | 0x0000035A |
RtlUnwind | - | 0x00401224 | 0x00032498 | 0x00031898 | 0x00000392 |
WideCharToMultiByte | - | 0x00401228 | 0x0003249C | 0x0003189C | 0x0000047A |
GetCommandLineA | - | 0x0040122C | 0x000324A0 | 0x000318A0 | 0x0000016F |
GetStartupInfoA | - | 0x00401230 | 0x000324A4 | 0x000318A4 | 0x00000239 |
HeapValidate | - | 0x00401234 | 0x000324A8 | 0x000318A8 | 0x000002A9 |
IsBadReadPtr | - | 0x00401238 | 0x000324AC | 0x000318AC | 0x000002C8 |
UnhandledExceptionFilter | - | 0x0040123C | 0x000324B0 | 0x000318B0 | 0x0000043E |
GetModuleFileNameW | - | 0x00401240 | 0x000324B4 | 0x000318B4 | 0x000001F5 |
GetCurrentProcess | - | 0x00401244 | 0x000324B8 | 0x000318B8 | 0x000001A9 |
IsDebuggerPresent | - | 0x00401248 | 0x000324BC | 0x000318BC | 0x000002D1 |
TlsAlloc | - | 0x0040124C | 0x000324C0 | 0x000318C0 | 0x00000432 |
TlsSetValue | - | 0x00401250 | 0x000324C4 | 0x000318C4 | 0x00000435 |
GetCurrentThreadId | - | 0x00401254 | 0x000324C8 | 0x000318C8 | 0x000001AD |
TlsFree | - | 0x00401258 | 0x000324CC | 0x000318CC | 0x00000433 |
GetOEMCP | - | 0x0040125C | 0x000324D0 | 0x000318D0 | 0x00000213 |
GetCPInfo | - | 0x00401260 | 0x000324D4 | 0x000318D4 | 0x0000015B |
IsValidCodePage | - | 0x00401264 | 0x000324D8 | 0x000318D8 | 0x000002DB |
SetFilePointer | - | 0x00401268 | 0x000324DC | 0x000318DC | 0x000003DF |
SetHandleCount | - | 0x0040126C | 0x000324E0 | 0x000318E0 | 0x000003E8 |
GetStdHandle | - | 0x00401270 | 0x000324E4 | 0x000318E4 | 0x0000023B |
GetFileType | - | 0x00401274 | 0x000324E8 | 0x000318E8 | 0x000001D7 |
QueryPerformanceCounter | - | 0x00401278 | 0x000324EC | 0x000318EC | 0x00000354 |
GetTickCount | - | 0x0040127C | 0x000324F0 | 0x000318F0 | 0x00000266 |
GetCurrentProcessId | - | 0x00401280 | 0x000324F4 | 0x000318F4 | 0x000001AA |
GetSystemTimeAsFileTime | - | 0x00401284 | 0x000324F8 | 0x000318F8 | 0x0000024F |
ExitProcess | - | 0x00401288 | 0x000324FC | 0x000318FC | 0x00000104 |
GetModuleFileNameA | - | 0x0040128C | 0x00032500 | 0x00031900 | 0x000001F4 |
FreeEnvironmentStringsA | - | 0x00401290 | 0x00032504 | 0x00031904 | 0x0000014A |
GetEnvironmentStrings | - | 0x00401294 | 0x00032508 | 0x00031908 | 0x000001BF |
FreeEnvironmentStringsW | - | 0x00401298 | 0x0003250C | 0x0003190C | 0x0000014B |
GetEnvironmentStringsW | - | 0x0040129C | 0x00032510 | 0x00031910 | 0x000001C1 |
HeapDestroy | - | 0x004012A0 | 0x00032514 | 0x00031914 | 0x000002A0 |
HeapCreate | - | 0x004012A4 | 0x00032518 | 0x00031918 | 0x0000029F |
VirtualFree | - | 0x004012A8 | 0x0003251C | 0x0003191C | 0x00000457 |
WriteFile | - | 0x004012AC | 0x00032520 | 0x00031920 | 0x0000048D |
HeapAlloc | - | 0x004012B0 | 0x00032524 | 0x00031924 | 0x0000029D |
HeapSize | - | 0x004012B4 | 0x00032528 | 0x00031928 | 0x000002A6 |
HeapReAlloc | - | 0x004012B8 | 0x0003252C | 0x0003192C | 0x000002A4 |
FlushFileBuffers | - | 0x004012BC | 0x00032530 | 0x00031930 | 0x00000141 |
GetConsoleCP | - | 0x004012C0 | 0x00032534 | 0x00031934 | 0x00000183 |
GetConsoleMode | - | 0x004012C4 | 0x00032538 | 0x00031938 | 0x00000195 |
OutputDebugStringA | - | 0x004012C8 | 0x0003253C | 0x0003193C | 0x0000033A |
WriteConsoleW | - | 0x004012CC | 0x00032540 | 0x00031940 | 0x0000048C |
OutputDebugStringW | - | 0x004012D0 | 0x00032544 | 0x00031944 | 0x0000033B |
InitializeCriticalSectionAndSpinCount | - | 0x004012D4 | 0x00032548 | 0x00031948 | 0x000002B5 |
MultiByteToWideChar | - | 0x004012D8 | 0x0003254C | 0x0003194C | 0x0000031A |
LCMapStringA | - | 0x004012DC | 0x00032550 | 0x00031950 | 0x000002E1 |
LCMapStringW | - | 0x004012E0 | 0x00032554 | 0x00031954 | 0x000002E3 |
GetStringTypeA | - | 0x004012E4 | 0x00032558 | 0x00031958 | 0x0000023D |
GetStringTypeW | - | 0x004012E8 | 0x0003255C | 0x0003195C | 0x00000240 |
GetLocaleInfoA | - | 0x004012EC | 0x00032560 | 0x00031960 | 0x000001E8 |
SetStdHandle | - | 0x004012F0 | 0x00032564 | 0x00031964 | 0x000003FC |
GetConsoleOutputCP | - | 0x004012F4 | 0x00032568 | 0x00031968 | 0x00000199 |
CloseHandle | - | 0x004012F8 | 0x0003256C | 0x0003196C | 0x00000043 |
CreateFileA | - | 0x004012FC | 0x00032570 | 0x00031970 | 0x00000078 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CharToOemBuffW | - | 0x00401304 | 0x00032578 | 0x00031978 | 0x00000035 |
CharUpperA | - | 0x00401308 | 0x0003257C | 0x0003197C | 0x00000037 |
GetCursorInfo | - | 0x0040130C | 0x00032580 | 0x00031980 | 0x00000118 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
AbortSystemShutdownW | - | 0x00401000 | 0x00032274 | 0x00031674 | 0x00000004 |
C:\Users\kEecfMwgj\AppData\Local\bowsakkdestx.txt | Downloaded File | Unknown |
Clean
|
...
|
4a1aaeed4747266983004f9fa25ff0ed024415f8232f30467b08441084b002e0 | Downloaded File | HTML |
Clean
|
...
|
c:\users\keecfmwgj\appdata\roaming\microsoft\windows\ietldcache\index.dat | Modified File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat | Modified File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\appdata\local\microsoft\windows\history\history.ie5\index.dat | Modified File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\appdata\roaming\microsoft\windows\cookies\index.dat | Modified File | Stream |
Clean
|
...
|