Downloader Ransomware
STOP Djvu Mal/HTMLGen-A Mal/Generic-S
Created on 2022-08-05T09:25:59+00:00
55043585c15ff65ca4b8df91c0b0f1c883d4cfd40933c6d25c2d9159e2f0757c.exe
Remarks (2/3)
(0x0200001B): The maximum number of file Reputation Analysis requests per analysis (150) was exceeded.
(0x0200000E): The overall sleep time of all monitored processes was truncated from "22 minutes" to "20 seconds" to reveal dormant functionality.
Remarks
(0x0200004A): 16 dump(s) were skipped because they exceeded the maximum dump size of 16 MB. The largest one was 380 MB.
(0x0200004F): Static Analysis failed to analyze file artifacts in this analysis due to an error. Check the artifact_static_analysis.log file for further information.
(0x0200005D): 241 additional dumps with the reason "Content Changed" and a total of 293 MB were skipped because the respective maximum limit was reached.
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\kEecfMwgj\Desktop\55043585c15ff65ca4b8df91c0b0f1c883d4cfd40933c6d25c2d9159e2f0757c.exe | Sample File | Binary |
Malicious
|
...
|
Verdict |
Malicious
|
Image Base | 0x00400000 |
Entry Point | 0x004983A0 |
Size Of Code | 0x000A5E00 |
Size Of Initialized Data | 0x0209CA00 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2021-06-10 22:11 (UTC+2) |
FileVersions | 48.90.12.34 |
Copyrighz | Copyright (C) 2022, pozkarte |
ProjectVersion | 91.4.7.88 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x000A5D04 | 0x000A5E00 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.95 |
.data | 0x004A7000 | 0x020861CC | 0x00003000 | 0x000A6200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.76 |
.rsrc | 0x0252E000 | 0x0000D568 | 0x0000D600 | 0x000A9200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.52 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetModuleFileNameA | - | 0x00401000 | 0x000A6218 | 0x000A5618 | 0x00000213 |
FoldStringA | - | 0x00401004 | 0x000A621C | 0x000A561C | 0x0000015B |
GetLocalTime | - | 0x00401008 | 0x000A6220 | 0x000A5620 | 0x00000203 |
InterlockedDecrement | - | 0x0040100C | 0x000A6224 | 0x000A5624 | 0x000002EB |
GetLocaleInfoA | - | 0x00401010 | 0x000A6228 | 0x000A5628 | 0x00000204 |
InterlockedCompareExchange | - | 0x00401014 | 0x000A622C | 0x000A562C | 0x000002E9 |
_hwrite | - | 0x00401018 | 0x000A6230 | 0x000A5630 | 0x00000536 |
CancelWaitableTimer | - | 0x0040101C | 0x000A6234 | 0x000A5634 | 0x00000047 |
GetSystemDirectoryW | - | 0x00401020 | 0x000A6238 | 0x000A5638 | 0x00000270 |
CreateEventW | - | 0x00401024 | 0x000A623C | 0x000A563C | 0x00000085 |
ReadConsoleA | - | 0x00401028 | 0x000A6240 | 0x000A5640 | 0x000003B4 |
BuildCommDCBA | - | 0x0040102C | 0x000A6244 | 0x000A5644 | 0x0000003A |
GetConsoleAliasExesLengthW | - | 0x00401030 | 0x000A6248 | 0x000A5648 | 0x00000193 |
SetSystemTimeAdjustment | - | 0x00401034 | 0x000A624C | 0x000A564C | 0x0000048C |
PeekConsoleInputW | - | 0x00401038 | 0x000A6250 | 0x000A5650 | 0x0000038C |
EnumDateFormatsA | - | 0x0040103C | 0x000A6254 | 0x000A5654 | 0x000000F4 |
CreateFileW | - | 0x00401040 | 0x000A6258 | 0x000A5658 | 0x0000008F |
RegisterWaitForSingleObjectEx | - | 0x00401044 | 0x000A625C | 0x000A565C | 0x000003F6 |
LoadLibraryW | - | 0x00401048 | 0x000A6260 | 0x000A5660 | 0x0000033F |
VerifyVersionInfoW | - | 0x0040104C | 0x000A6264 | 0x000A5664 | 0x000004E8 |
WaitNamedPipeA | - | 0x00401050 | 0x000A6268 | 0x000A5668 | 0x000004FF |
GetEnvironmentStrings | - | 0x00401054 | 0x000A626C | 0x000A566C | 0x000001D8 |
FindResourceExA | - | 0x00401058 | 0x000A6270 | 0x000A5670 | 0x0000014C |
VirtualProtect | - | 0x0040105C | 0x000A6274 | 0x000A5674 | 0x000004EF |
GetFirmwareEnvironmentVariableW | - | 0x00401060 | 0x000A6278 | 0x000A5678 | 0x000001F7 |
BeginUpdateResourceW | - | 0x00401064 | 0x000A627C | 0x000A567C | 0x00000038 |
GetConsoleAliasExesLengthA | - | 0x00401068 | 0x000A6280 | 0x000A5680 | 0x00000192 |
WriteConsoleA | - | 0x0040106C | 0x000A6284 | 0x000A5684 | 0x0000051A |
EnumCalendarInfoExA | - | 0x00401070 | 0x000A6288 | 0x000A5688 | 0x000000F0 |
WriteConsoleW | - | 0x00401074 | 0x000A628C | 0x000A568C | 0x00000524 |
DeleteFileW | - | 0x00401078 | 0x000A6290 | 0x000A5690 | 0x000000D6 |
FillConsoleOutputCharacterA | - | 0x0040107C | 0x000A6294 | 0x000A5694 | 0x00000127 |
GetProcAddress | - | 0x00401080 | 0x000A6298 | 0x000A5698 | 0x00000245 |
GetModuleHandleW | - | 0x00401084 | 0x000A629C | 0x000A569C | 0x00000218 |
GetUserDefaultLCID | - | 0x00401088 | 0x000A62A0 | 0x000A56A0 | 0x0000029B |
FindFirstChangeNotificationW | - | 0x0040108C | 0x000A62A4 | 0x000A56A4 | 0x00000131 |
GetFileAttributesExA | - | 0x00401090 | 0x000A62A8 | 0x000A56A8 | 0x000001E6 |
GetCalendarInfoA | - | 0x00401094 | 0x000A62AC | 0x000A56AC | 0x00000179 |
SetConsoleTitleA | - | 0x00401098 | 0x000A62B0 | 0x000A56B0 | 0x00000447 |
GetBinaryTypeW | - | 0x0040109C | 0x000A62B4 | 0x000A56B4 | 0x00000171 |
GlobalAlloc | - | 0x004010A0 | 0x000A62B8 | 0x000A56B8 | 0x000002B3 |
GetComputerNameExA | - | 0x004010A4 | 0x000A62BC | 0x000A56BC | 0x0000018D |
FindNextFileA | - | 0x004010A8 | 0x000A62C0 | 0x000A56C0 | 0x00000143 |
OpenJobObjectA | - | 0x004010AC | 0x000A62C4 | 0x000A56C4 | 0x0000037A |
HeapSize | - | 0x004010B0 | 0x000A62C8 | 0x000A56C8 | 0x000002D4 |
_lclose | - | 0x004010B4 | 0x000A62CC | 0x000A56CC | 0x00000537 |
GetComputerNameW | - | 0x004010B8 | 0x000A62D0 | 0x000A56D0 | 0x0000018F |
TlsGetValue | - | 0x004010BC | 0x000A62D4 | 0x000A56D4 | 0x000004C7 |
SetCalendarInfoW | - | 0x004010C0 | 0x000A62D8 | 0x000A56D8 | 0x0000041F |
SetComputerNameW | - | 0x004010C4 | 0x000A62DC | 0x000A56DC | 0x0000042A |
CreateDirectoryExA | - | 0x004010C8 | 0x000A62E0 | 0x000A56E0 | 0x0000007D |
InitializeCriticalSectionAndSpinCount | - | 0x004010CC | 0x000A62E4 | 0x000A56E4 | 0x000002E3 |
FindFirstChangeNotificationA | - | 0x004010D0 | 0x000A62E8 | 0x000A56E8 | 0x00000130 |
GetVolumePathNameA | - | 0x004010D4 | 0x000A62EC | 0x000A56EC | 0x000002AA |
LoadLibraryA | - | 0x004010D8 | 0x000A62F0 | 0x000A56F0 | 0x0000033C |
GetProcessHandleCount | - | 0x004010DC | 0x000A62F4 | 0x000A56F4 | 0x00000249 |
GetThreadLocale | - | 0x004010E0 | 0x000A62F8 | 0x000A56F8 | 0x0000028C |
GetSystemDefaultLangID | - | 0x004010E4 | 0x000A62FC | 0x000A56FC | 0x0000026C |
GetCurrentProcess | - | 0x004010E8 | 0x000A6300 | 0x000A5700 | 0x000001C0 |
ReadFile | - | 0x004010EC | 0x000A6304 | 0x000A5704 | 0x000003C0 |
HeapFree | - | 0x004010F0 | 0x000A6308 | 0x000A5708 | 0x000002CF |
GetDiskFreeSpaceW | - | 0x004010F4 | 0x000A630C | 0x000A570C | 0x000001CF |
GetProcessHeap | - | 0x004010F8 | 0x000A6310 | 0x000A5710 | 0x0000024A |
RaiseException | - | 0x004010FC | 0x000A6314 | 0x000A5714 | 0x000003B1 |
RtlUnwind | - | 0x00401100 | 0x000A6318 | 0x000A5718 | 0x00000418 |
MultiByteToWideChar | - | 0x00401104 | 0x000A631C | 0x000A571C | 0x00000367 |
GetCommandLineW | - | 0x00401108 | 0x000A6320 | 0x000A5720 | 0x00000187 |
HeapSetInformation | - | 0x0040110C | 0x000A6324 | 0x000A5724 | 0x000002D3 |
GetStartupInfoW | - | 0x00401110 | 0x000A6328 | 0x000A5728 | 0x00000263 |
EncodePointer | - | 0x00401114 | 0x000A632C | 0x000A572C | 0x000000EA |
HeapAlloc | - | 0x00401118 | 0x000A6330 | 0x000A5730 | 0x000002CB |
GetLastError | - | 0x0040111C | 0x000A6334 | 0x000A5734 | 0x00000202 |
IsProcessorFeaturePresent | - | 0x00401120 | 0x000A6338 | 0x000A5738 | 0x00000304 |
DecodePointer | - | 0x00401124 | 0x000A633C | 0x000A573C | 0x000000CA |
TlsAlloc | - | 0x00401128 | 0x000A6340 | 0x000A5740 | 0x000004C5 |
TlsSetValue | - | 0x0040112C | 0x000A6344 | 0x000A5744 | 0x000004C8 |
TlsFree | - | 0x00401130 | 0x000A6348 | 0x000A5748 | 0x000004C6 |
InterlockedIncrement | - | 0x00401134 | 0x000A634C | 0x000A574C | 0x000002EF |
SetLastError | - | 0x00401138 | 0x000A6350 | 0x000A5750 | 0x00000473 |
GetCurrentThreadId | - | 0x0040113C | 0x000A6354 | 0x000A5754 | 0x000001C5 |
SetHandleCount | - | 0x00401140 | 0x000A6358 | 0x000A5758 | 0x0000046F |
GetStdHandle | - | 0x00401144 | 0x000A635C | 0x000A575C | 0x00000264 |
GetFileType | - | 0x00401148 | 0x000A6360 | 0x000A5760 | 0x000001F3 |
DeleteCriticalSection | - | 0x0040114C | 0x000A6364 | 0x000A5764 | 0x000000D1 |
SetFilePointer | - | 0x00401150 | 0x000A6368 | 0x000A5768 | 0x00000466 |
UnhandledExceptionFilter | - | 0x00401154 | 0x000A636C | 0x000A576C | 0x000004D3 |
SetUnhandledExceptionFilter | - | 0x00401158 | 0x000A6370 | 0x000A5770 | 0x000004A5 |
IsDebuggerPresent | - | 0x0040115C | 0x000A6374 | 0x000A5774 | 0x00000300 |
TerminateProcess | - | 0x00401160 | 0x000A6378 | 0x000A5778 | 0x000004C0 |
EnterCriticalSection | - | 0x00401164 | 0x000A637C | 0x000A577C | 0x000000EE |
LeaveCriticalSection | - | 0x00401168 | 0x000A6380 | 0x000A5780 | 0x00000339 |
ExitProcess | - | 0x0040116C | 0x000A6384 | 0x000A5784 | 0x00000119 |
GetCPInfo | - | 0x00401170 | 0x000A6388 | 0x000A5788 | 0x00000172 |
GetACP | - | 0x00401174 | 0x000A638C | 0x000A578C | 0x00000168 |
GetOEMCP | - | 0x00401178 | 0x000A6390 | 0x000A5790 | 0x00000237 |
IsValidCodePage | - | 0x0040117C | 0x000A6394 | 0x000A5794 | 0x0000030A |
CloseHandle | - | 0x00401180 | 0x000A6398 | 0x000A5798 | 0x00000052 |
WriteFile | - | 0x00401184 | 0x000A639C | 0x000A579C | 0x00000525 |
GetModuleFileNameW | - | 0x00401188 | 0x000A63A0 | 0x000A57A0 | 0x00000214 |
FreeEnvironmentStringsW | - | 0x0040118C | 0x000A63A4 | 0x000A57A4 | 0x00000161 |
GetEnvironmentStringsW | - | 0x00401190 | 0x000A63A8 | 0x000A57A8 | 0x000001DA |
HeapCreate | - | 0x00401194 | 0x000A63AC | 0x000A57AC | 0x000002CD |
QueryPerformanceCounter | - | 0x00401198 | 0x000A63B0 | 0x000A57B0 | 0x000003A7 |
GetTickCount | - | 0x0040119C | 0x000A63B4 | 0x000A57B4 | 0x00000293 |
GetCurrentProcessId | - | 0x004011A0 | 0x000A63B8 | 0x000A57B8 | 0x000001C1 |
GetSystemTimeAsFileTime | - | 0x004011A4 | 0x000A63BC | 0x000A57BC | 0x00000279 |
Sleep | - | 0x004011A8 | 0x000A63C0 | 0x000A57C0 | 0x000004B2 |
SetStdHandle | - | 0x004011AC | 0x000A63C4 | 0x000A57C4 | 0x00000487 |
WideCharToMultiByte | - | 0x004011B0 | 0x000A63C8 | 0x000A57C8 | 0x00000511 |
GetConsoleCP | - | 0x004011B4 | 0x000A63CC | 0x000A57CC | 0x0000019A |
GetConsoleMode | - | 0x004011B8 | 0x000A63D0 | 0x000A57D0 | 0x000001AC |
FlushFileBuffers | - | 0x004011BC | 0x000A63D4 | 0x000A57D4 | 0x00000157 |
CreateFileA | - | 0x004011C0 | 0x000A63D8 | 0x000A57D8 | 0x00000088 |
LCMapStringW | - | 0x004011C4 | 0x000A63DC | 0x000A57DC | 0x0000032D |
GetStringTypeW | - | 0x004011C8 | 0x000A63E0 | 0x000A57E0 | 0x00000269 |
HeapReAlloc | - | 0x004011CC | 0x000A63E4 | 0x000A57E4 | 0x000002D2 |
SetEndOfFile | - | 0x004011D0 | 0x000A63E8 | 0x000A57E8 | 0x00000453 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ClientToScreen | - | 0x004011D8 | 0x000A63F0 | 0x000A57F0 | 0x00000047 |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
buffer | 1 | 0x03CD0020 | 0x03D60FD7 | First Execution | 32-bit | 0x03CD0020 |
...
|
||
buffer | 1 | 0x03DC0000 | 0x03EDAFFF | First Execution | 32-bit | 0x03DC0000 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | First Execution | 32-bit | 0x00424141 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00423F84 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004278D5 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00425141 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042C0F0 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042A06D |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0043B021 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00420C62 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042D8D0 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00431F64 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0043AF30 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00421881 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042B420 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004C55BE |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004548D0 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00449000 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0044D0CB |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0044B550 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00401000 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0040A260 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041CC50 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00419E70 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0040CF10 |
...
|
||
buffer | 2 | 0x00188000 | 0x0018FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | First Network Behavior | 32-bit | 0x0040CFAC |
...
|
||
buffer | 2 | 0x0066F1C8 | 0x0066F583 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0066F590 | 0x0066FD8F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0066FD98 | 0x0066FE5F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x0066FE68 | 0x0066FEFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x006700F8 | 0x00670221 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x006702F8 | 0x00670387 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00670430 | 0x00670505 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x006705D0 | 0x0067065B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00670668 | 0x00670E67 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00670E70 | 0x00670EEF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00670EF8 | 0x00671117 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x006716E8 | 0x0067177C | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00671928 | 0x006719BF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x006719C8 | 0x006722B3 | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 2 | 0x02600000 | 0x0263FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042B420 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041B680 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Final Dump | 32-bit | 0x00430BF0 |
...
|
||
buffer | 2 | 0x0066F1C8 | 0x0066F583 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0066F590 | 0x0066FD8F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0066FD98 | 0x0066FE5F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0066FE68 | 0x0066FEFF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x006700F8 | 0x00670221 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x006702F8 | 0x00670387 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x00670430 | 0x00670505 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x006705D0 | 0x0067065B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x00670668 | 0x00670E67 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x00670E70 | 0x00670EEF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x00670EF8 | 0x00671117 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x006716E8 | 0x0067177C | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x00671928 | 0x006719BF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x006719C8 | 0x006722B3 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x00687600 | 0x0068785B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x0068C210 | 0x0068CA0F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x007457F8 | 0x00745887 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02B448E0 | 0x02B4496F | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02B59908 | 0x02B59B63 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02B67940 | 0x02B6822B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02B68238 | 0x02B68A47 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02B68A50 | 0x02B68CAB | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02B68CB8 | 0x02B68F13 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02B68F20 | 0x02B6917B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02B69188 | 0x02B693E3 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02B693F0 | 0x02B6964B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02B69658 | 0x02B698B3 | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02B698C0 | 0x02B69B1B | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02BA54A0 | 0x02BA56FB | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x02BA5708 | 0x02BA5827 | Final Dump | 32-bit | - |
...
|
||
index.dat | 2 | 0x02600000 | 0x0263FFFF | Final Dump | 32-bit | - |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00433F99 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00424081 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004CB520 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004CA6F7 |
...
|
||
buffer | 2 | 0x00400000 | 0x00536FFF | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x0066F590 | 0x0066FD8F | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x0066FD98 | 0x0066FE5F | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x0066FE68 | 0x0066FEFF | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x006700F8 | 0x00670221 | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x006702F8 | 0x00670387 | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x00670430 | 0x00670505 | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x006705D0 | 0x0067065B | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x00670E70 | 0x00670EEF | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x00670EF8 | 0x00671117 | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x006716E8 | 0x0067177C | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x00671928 | 0x006719BF | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x00687600 | 0x0068785B | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02B229B0 | 0x02B22A4F | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02B59908 | 0x02B59B63 | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02B68A50 | 0x02B68CAB | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02B68CB8 | 0x02B68F13 | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02B68F20 | 0x02B6917B | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02B69188 | 0x02B693E3 | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02B693F0 | 0x02B6964B | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02B69658 | 0x02B698B3 | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02B698C0 | 0x02B69B1B | Process Termination | 32-bit | - |
...
|
||
buffer | 2 | 0x02BA54A0 | 0x02BA56FB | Process Termination | 32-bit | - |
...
|
||
index.dat | 2 | 0x02600000 | 0x0263FFFF | Process Termination | 32-bit | - |
...
|
||
buffer | 5 | 0x02540020 | 0x025D0FD7 | First Execution | 32-bit | 0x02540020 |
...
|
||
buffer | 5 | 0x03D30000 | 0x03E4AFFF | First Execution | 32-bit | 0x03D30000 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | First Execution | 32-bit | 0x00424141 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00423F84 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00425141 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042C0F0 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042A06D |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0043B021 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00420C62 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042D8D0 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00431F64 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0043AF30 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00421881 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042B420 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004C55BE |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x004548D0 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00449000 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0044D0CB |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0044B550 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00401000 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041CC50 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00419E70 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0040CF10 |
...
|
||
buffer | 6 | 0x00188000 | 0x0018FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | First Network Behavior | 32-bit | 0x0040D000 |
...
|
||
buffer | 6 | 0x0060F228 | 0x0060F5E3 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x0060F5F0 | 0x0060FDEF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x0060FDF8 | 0x0060FF0D | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x0060FF18 | 0x0060FFAF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x006101A8 | 0x006102D1 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x006103A8 | 0x00610437 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x006104E0 | 0x006105B5 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x00610680 | 0x0061070B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x00610718 | 0x00610F17 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x00610F20 | 0x00610F9F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x00610FA8 | 0x006111C7 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x00611798 | 0x0061182C | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x006119D8 | 0x00611A6F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x00611A78 | 0x00612363 | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 6 | 0x01F10000 | 0x01F4FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041B680 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00412220 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041E031 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042E003 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00447F50 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00420E92 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041F01A |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00410FC0 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041FA2B |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00423F74 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00410BD0 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042434D |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0042B420 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x00422587 |
...
|
||
buffer | 6 | 0x00400000 | 0x00536FFF | Content Changed | 32-bit | 0x0041E353 |
...
|
||
buffer | 12 | 0x03D60020 | 0x03DF0FD7 | First Execution | 32-bit | 0x03D60020 |
...
|
||
buffer | 12 | 0x03E00000 | 0x03F1AFFF | First Execution | 32-bit | 0x03E00000 |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | First Execution | 32-bit | 0x00424141 |
...
|
||
buffer | 13 | 0x00188000 | 0x0018FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | First Network Behavior | 32-bit | 0x0040D000 |
...
|
||
buffer | 13 | 0x0069F4A8 | 0x0069F863 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x0069F870 | 0x006A006F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x006A0078 | 0x006A0103 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x006A0110 | 0x006A090F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x006A0918 | 0x006A0997 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x006A09A0 | 0x006A0BBF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x006A1178 | 0x006A120C | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x006A13B8 | 0x006A1453 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x006A1718 | 0x006A1851 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x006A1860 | 0x006A18FB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x006A1AF8 | 0x006A1C21 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x006A1CF8 | 0x006A1D87 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x006A1E30 | 0x006A1F05 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x006A1FD0 | 0x006A28BB | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 13 | 0x00280000 | 0x0028FFFF | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 13 | 0x00290000 | 0x00297FFF | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 13 | 0x002A0000 | 0x002AFFFF | First Network Behavior | 32-bit | - |
...
|
||
index.dat | 13 | 0x02870000 | 0x028AFFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 13 | 0x00400000 | 0x00536FFF | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x0069F870 | 0x006A006F | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006A0078 | 0x006A0103 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006A0918 | 0x006A0997 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006A09A0 | 0x006A0BBF | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006A1178 | 0x006A120C | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006A13B8 | 0x006A1453 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006A1718 | 0x006A1851 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006A1860 | 0x006A18FB | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006A1AF8 | 0x006A1C21 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006A1CF8 | 0x006A1D87 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006A1E30 | 0x006A1F05 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006ACEB0 | 0x006ACF31 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006ADCC0 | 0x006ADD41 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006ADD50 | 0x006ADDD1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006ADDE0 | 0x006ADE61 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006ADE70 | 0x006ADEF1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006ADF00 | 0x006ADF81 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006ADF90 | 0x006AE011 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006AE020 | 0x006AE0A1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006AE0B0 | 0x006AE131 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006AE140 | 0x006AE1C1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006AE1D0 | 0x006AE251 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006AE260 | 0x006AE2E1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006AE2F0 | 0x006AE371 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006AE380 | 0x006AE401 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006AE410 | 0x006AE491 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006AE4A0 | 0x006AE521 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006AE530 | 0x006AE5B1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006AE5C0 | 0x006AE641 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006AE650 | 0x006AE6D1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006AE6E0 | 0x006AE761 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006AE770 | 0x006AE7F1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006AE800 | 0x006AE881 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006AE890 | 0x006AE911 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006AE920 | 0x006AE9A1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006AE9B0 | 0x006AEA31 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x006AEA40 | 0x006AEAC1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CAFC10 | 0x02CAFD9F | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CDC8F8 | 0x02CDCB53 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CDCB60 | 0x02CDCDBB | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CDCDC8 | 0x02CDD023 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CDD030 | 0x02CDD28B | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CDD298 | 0x02CDD4F3 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CDD500 | 0x02CDD75B | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CDD768 | 0x02CDD9C3 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CDD9D0 | 0x02CDDC2B | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CDDC38 | 0x02CDDE93 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CDDEA0 | 0x02CDE0FB | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CDE108 | 0x02CDE363 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CDE370 | 0x02CDE5CB | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CDE5D8 | 0x02CDE833 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CDE840 | 0x02CDEA9B | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CDEAA8 | 0x02CDED03 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CDED10 | 0x02CDEF6B | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CDEF78 | 0x02CDF1D3 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CDF1E0 | 0x02CDF43B | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CDF448 | 0x02CDF6A3 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CDF6B0 | 0x02CDF90B | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CDF918 | 0x02CDFB73 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CDFB80 | 0x02CDFDDB | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CDFDE8 | 0x02CE0043 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CE0050 | 0x02CE02AB | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CE02B8 | 0x02CE0513 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CE0520 | 0x02CE077B | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CEF000 | 0x02CEF25B | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CEF268 | 0x02CEF4C3 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CEF4D0 | 0x02CEF72B | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CEF738 | 0x02CEF993 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CEF9A0 | 0x02CEFBFB | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CEFC08 | 0x02CEFE63 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CEFE70 | 0x02CF00CB | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CF00D8 | 0x02CF0333 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CF0340 | 0x02CF059B | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CF05A8 | 0x02CF0803 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CF0810 | 0x02CF0A6B | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CF0A78 | 0x02CF0CD3 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CF0CE0 | 0x02CF0F3B | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CF0F48 | 0x02CF11A3 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CF11B0 | 0x02CF140B | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CF1418 | 0x02CF1673 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CF1680 | 0x02CF18DB | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CF18E8 | 0x02CF1B43 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CF1B50 | 0x02CF1DAB | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CF1DB8 | 0x02CF2013 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CF2020 | 0x02CF227B | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CF2288 | 0x02CF24E3 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CF24F0 | 0x02CF274B | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CF2758 | 0x02CF29B3 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CF29C0 | 0x02CF2C1B | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CF2C28 | 0x02CF2E83 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CFEC30 | 0x02CFEE8B | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CFEE98 | 0x02CFF0F3 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CFF100 | 0x02CFF35B | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02CFF368 | 0x02CFF5C3 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02D61060 | 0x02D612BB | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02D612C8 | 0x02D61523 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02D61530 | 0x02D6178B | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02D61798 | 0x02D619F3 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02D61A00 | 0x02D61C5B | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02D61C68 | 0x02D61EC3 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02D61ED0 | 0x02D6212B | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02D62138 | 0x02D62393 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02D623A0 | 0x02D625FB | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02D62608 | 0x02D62863 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02D62870 | 0x02D62ACB | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02D62AD8 | 0x02D62D33 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02D62D40 | 0x02D62F9B | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02D62FA8 | 0x02D63203 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02D6B760 | 0x02D6C75F | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DC1ED8 | 0x02DC5ED7 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DC7F20 | 0x02DCBF1F | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD7B30 | 0x02DD7BB1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD7BC0 | 0x02DD7C41 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD7C50 | 0x02DD7CD1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD7CE0 | 0x02DD7D61 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD7D70 | 0x02DD7DF1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD7E00 | 0x02DD7E81 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD7E90 | 0x02DD7F11 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD7F20 | 0x02DD7FA1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD7FB0 | 0x02DD8031 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD8040 | 0x02DD80C1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD80D0 | 0x02DD8151 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD8160 | 0x02DD81E1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD81F0 | 0x02DD8271 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD8280 | 0x02DD8301 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD8310 | 0x02DD8391 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD83A0 | 0x02DD8421 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD8430 | 0x02DD84B1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD84C0 | 0x02DD8541 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD8550 | 0x02DD85D1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD85E0 | 0x02DD8661 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD8670 | 0x02DD86F1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD8700 | 0x02DD8781 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD8790 | 0x02DD8811 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD8820 | 0x02DD88A1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD88B0 | 0x02DD8931 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD8940 | 0x02DD89C1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD8A60 | 0x02DD8AE1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD8AF0 | 0x02DD8B71 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD8B80 | 0x02DD8C01 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD8C10 | 0x02DD8C91 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD8CA0 | 0x02DD8D21 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD8D30 | 0x02DD8DB1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD8DC0 | 0x02DD8E41 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD8E50 | 0x02DD8ED1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD8EE0 | 0x02DD8F61 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD8F70 | 0x02DD8FF1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD9000 | 0x02DD9081 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD9090 | 0x02DD9111 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD9120 | 0x02DD91A1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD91B0 | 0x02DD9231 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD9240 | 0x02DD92C1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD92D0 | 0x02DD9351 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD9360 | 0x02DD93E1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD93F0 | 0x02DD9471 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD9480 | 0x02DD9501 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD9510 | 0x02DD9591 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD95A0 | 0x02DD9621 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD9630 | 0x02DD96B1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD96C0 | 0x02DD9741 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD9750 | 0x02DD97D1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD97E0 | 0x02DD9861 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD9870 | 0x02DD98F1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD9900 | 0x02DD9981 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD9990 | 0x02DD9A11 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD9A20 | 0x02DD9AA1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD9B30 | 0x02DD9BB1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD9BC0 | 0x02DD9C41 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD9C50 | 0x02DD9CD1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD9CE0 | 0x02DD9D61 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD9D70 | 0x02DD9DF1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD9E00 | 0x02DD9E81 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD9E90 | 0x02DD9F11 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD9F20 | 0x02DD9FA1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DD9FB0 | 0x02DDA031 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDA040 | 0x02DDA0C1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDA0D0 | 0x02DDA151 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDA160 | 0x02DDA1E1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDA1F0 | 0x02DDA271 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDA280 | 0x02DDA301 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDA310 | 0x02DDA391 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDA3A0 | 0x02DDA421 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDA430 | 0x02DDA4B1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDA4C0 | 0x02DDA541 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDA550 | 0x02DDA5D1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDA5E0 | 0x02DDA661 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDA670 | 0x02DDA6F1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDA700 | 0x02DDA781 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDA790 | 0x02DDA811 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDA820 | 0x02DDA8A1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDA8B0 | 0x02DDA931 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDA940 | 0x02DDA9C1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDA9D0 | 0x02DDAA51 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDAA60 | 0x02DDAAE1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDAAF0 | 0x02DDAB71 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDAB80 | 0x02DDAC01 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDAC10 | 0x02DDAC91 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDACA0 | 0x02DDAD21 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDAD30 | 0x02DDADB1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDADC0 | 0x02DDAE41 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDAE50 | 0x02DDAED1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDAEE0 | 0x02DDAF61 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDAF70 | 0x02DDAFF1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDB000 | 0x02DDB081 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDB090 | 0x02DDB111 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDB120 | 0x02DDB1A1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDB1B0 | 0x02DDB231 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDB240 | 0x02DDB2C1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDB2D0 | 0x02DDB351 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDB360 | 0x02DDB3E1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDB3F0 | 0x02DDB471 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDB480 | 0x02DDB501 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDB510 | 0x02DDB591 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDB5A0 | 0x02DDB621 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDB630 | 0x02DDB6B1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDB6C0 | 0x02DDB741 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDB750 | 0x02DDB7D1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDB7E0 | 0x02DDB861 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDB870 | 0x02DDB8F1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDB900 | 0x02DDB981 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDB990 | 0x02DDBA11 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDBA20 | 0x02DDBAA1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDBB30 | 0x02DDBBB1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDBBC0 | 0x02DDBC41 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDBC50 | 0x02DDBCD1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDBCE0 | 0x02DDBD61 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDBD70 | 0x02DDBDF1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDBE00 | 0x02DDBE81 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDBE90 | 0x02DDBF11 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDBF20 | 0x02DDBFA1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDBFB0 | 0x02DDC031 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDC040 | 0x02DDC0C1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDC0D0 | 0x02DDC151 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDC160 | 0x02DDC1E1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDC1F0 | 0x02DDC271 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDC280 | 0x02DDC301 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDC310 | 0x02DDC391 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDC3A0 | 0x02DDC421 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDC430 | 0x02DDC4B1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDC4C0 | 0x02DDC541 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDC550 | 0x02DDC5D1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDC5E0 | 0x02DDC661 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDC670 | 0x02DDC6F1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDC700 | 0x02DDC781 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDC790 | 0x02DDC811 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDC820 | 0x02DDC8A1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDC8B0 | 0x02DDC931 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DDC940 | 0x02DDC9C1 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE28E8 | 0x02DE2969 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE2978 | 0x02DE29F9 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE2A08 | 0x02DE2A89 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE2A98 | 0x02DE2B19 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE2B28 | 0x02DE2BA9 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE2BB8 | 0x02DE2C39 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE2C48 | 0x02DE2CC9 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE2CD8 | 0x02DE2D59 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE2D68 | 0x02DE2DE9 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE2DF8 | 0x02DE2E79 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE2E88 | 0x02DE2F09 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE2F18 | 0x02DE2F99 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE2FA8 | 0x02DE3029 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE3038 | 0x02DE30B9 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE30C8 | 0x02DE3149 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE3158 | 0x02DE31D9 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE31E8 | 0x02DE3269 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE3278 | 0x02DE32F9 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE3308 | 0x02DE3389 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE3398 | 0x02DE3419 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE3428 | 0x02DE34A9 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE34B8 | 0x02DE3539 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE3548 | 0x02DE35C9 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE35D8 | 0x02DE3659 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE3668 | 0x02DE36E9 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE36F8 | 0x02DE3779 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE3788 | 0x02DE3809 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE3818 | 0x02DE3899 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE38A8 | 0x02DE3929 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE3938 | 0x02DE39B9 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE39C8 | 0x02DE3A49 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE3A58 | 0x02DE3AD9 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE3AE8 | 0x02DE3B69 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE3B78 | 0x02DE3BF9 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE3C08 | 0x02DE3C89 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE3C98 | 0x02DE3D19 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE3D28 | 0x02DE3DA9 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE3DB8 | 0x02DE3E39 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE3E48 | 0x02DE3EC9 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE3ED8 | 0x02DE3F59 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE3F68 | 0x02DE3FE9 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE3FF8 | 0x02DE4079 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE4088 | 0x02DE4109 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE4118 | 0x02DE4199 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE41A8 | 0x02DE4229 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE4238 | 0x02DE42B9 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE42C8 | 0x02DE4349 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE4358 | 0x02DE43D9 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE43E8 | 0x02DE4469 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE4478 | 0x02DE44F9 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE4508 | 0x02DE4589 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE4598 | 0x02DE4619 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE4628 | 0x02DE46A9 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE46B8 | 0x02DE4739 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE4748 | 0x02DE47C9 | Process Termination | 32-bit | - |
...
|
||
buffer | 13 | 0x02DE47D8 | 0x02DE4859 | Process Termination | 32-bit | - |
...
|
C:\Users\kEecfMwgj\Documents\t7c9foFD9Kt\Du_\n4CMD g2s\Uomn Anj\3X s\0R 3sVLz9jj8.rtf.vvyu | Dropped File | RTF |
Malicious
|
...
|
®weüµ\x8fß<< AV°èèLÀÿf OêұQYŒîp\x90ájÂg¿ëH9Kû·SZŸÙ™’ÛCŒç>·mK‰˜%mÜßUó” ¶ZHÿ«rC‘…“~¢öQ\x81º&bP[…ÍM_3¤´Ë²ðôÐêY\x90ìEµ:SMÔ™ëçƒN!ÚFP=_Ld«‡‰¶ìÕݦ¥•ÜkêÖ†HD£%¼Í\x8f\x90<y]'Üã^'k†ñ-~•;æ»Ù`‘Îêv½2jd°ÅCpòþNrÁS¸kUVñêü¬Î]tq…æÙ›N‰~'‡¦P0“8Çà"ñ¯ÉHÕ 2“e×Ïiû™ç¬µmÊs>‡|…•)eq¦ÞiA‚À˜!v\x8fë®f)¢JæT=ù#’^v"(ꮼz_j†·“’mš•y¬~œX‡#aš_Q¤VÄßÄúœ™º&Ýà׋sþ÷‰<‚=™s¿ÿ'‘BDA—B‚l6˜ßµK¶Üàa\x8f[m‹î¿\x8f«$ážy\x9dÇm',+XC†Ûߧ ‹Òaï\x90šëÞ·¹Ì-O[¥/QmÅhD•øò‰G豌ÅÅÖ¼]mÿ\x8f»¦Íï(l<H€ËuM`cnöXƒÇÅÌ å÷FenàËÿŽTVœð®Ñk>"^;ʯ+ˆ¬ÛgÈH6³í§ W¿0‚”ζòysŸBµt¼xÆÔ„÷´Á1ÓÌwõ‰Š/Ø#d—•›´·¡|‘[i×T²ÙœÒ–Bæ„ÅIKáá-*Xœ7ÕÞôüWb„ih]¿ˆä¶Nd/?’˜(V鄇º.•¬§|’¡,JâÈé²¥¿E+¡nžìk—¥„ÁP6ÚÏ·¸‘õ¤5\x8dbÑ›¶_\x81ö7¤ m/ÌûƒÙ†‘—õvÂøI¢&¶*·Î ÄŽÈwë:©_ïªdé\x9d ìs]‚P#Ëp%CbɨI|%þjŸVQÁ «I…Î*ƒõ¹ûÂL z»úFé,`!U:?Uä?ž¡j(¹ß@üøÑoeÇõÄð~ß"ƒ¼´Äu ‚A)øž/éõÂßGsŠÎ—Çô¨Ž@ rŒöKÌT££´Üœ&nOö\x90)—:‡$ãó/—òRô¡ˆi=ä…iUÛPŒ6ŠòâÑ\x81Ði…W%q¦Sc¢=¡ýYáNQÇÂØ‘&1„g¬ Àôû]²¢ö=ϸi\x8dàÀu>=âÑÂ;"‘³t?Èfó,ñ˜4™ûÇ~tìr‰mÈ&œèp©´¼ì6— |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\kEecfMwgj\Documents\Efz8vEEd1pSVsE6 PJdQ.xlsx.vvyu | Dropped File | ZIP |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\oGH6r9EKez2SrD.bmp.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\documents\t7c9fofd9kt\du_\n4cmd g2s\yxnorx1icarsuvxvr.xls.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Videos\oa7UY-r84 e\GcroBq0Ap.flv.vvyu | Dropped File | Video |
Malicious
|
...
|
c:\users\keecfmwgj\music\q6ag5\6gb9swuoi.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\ckh5enz\0zp is.jpg.vvyu | Dropped File | Image |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\t7c9foFD9Kt\Du_\n4CMD g2s\Uomn Anj\6e2w9YoR-8.pdf.vvyu | Dropped File |
Malicious
|
...
|
C:\Users\kEecfMwgj\Pictures\CkH5eNz\utKlAZ\0Djnwc3CmEX6ks4d\JjOvnSZY.bmp.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\videos\w9galst 6bnf-yf.mkv.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\t7c9foFD9Kt\Du_\dLt-Gu15Ir8w0sJrhR-b\ooeO67V 2A6dBdr.pps.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\-CxO zQcq.avi.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\videos\fdd4gb84c4w3sg.mp4.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\s12J.m4a.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\kq__.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\T4N8wuVG8qRit6NO.odp.vvyu | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\videos\zct8oosw8v0sthu.avi.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\15d3btm7OvS9NV4xvvA\puDbAQqOd3K9PVjvn1u.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Videos\oa7UY-r84 e\v2hZ1rIby\2u CRZlC7nvdh_M.mkv.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\q6aG5\w5q7V-5Q7Epp.m4a.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Pictures\CkH5eNz\UIPaZiiR-oQnLQB3Ey2.png.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\documents\t7c9fofd9kt\du_\n4cmd g2s\uomn anj\8ydbvfzvuknzyhmzsw2e.pptx.vvyu | Dropped File | ZIP |
Malicious
|
...
|
C:\Users\kEecfMwgj\Videos\oa7UY-r84 e\v2hZ1rIby\6zZsCwOqJQhE.avi.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Videos\h8vWrl4X3qjJx.avi.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Pictures\CkH5eNz\utKlAZ\0Djnwc3CmEX6ks4d\rMc5RT6t.bmp.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\music\15d3btm7ovs9nv4xvva\qexdtyv1z1q_cl0jaadt.m4a.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\ssz4\7qttxszlkjh_fii.pdf.vvyu | Dropped File |
Malicious
|
...
|
c:\users\keecfmwgj\documents\t7c9fofd9kt\du_\dlt-gu15ir8w0sjrhr-b\nj4aq\rfdw37vjsnr.ods.vvyu | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\h6hrgnjnvqba.png.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\SSz4\HT9Aw JQ.png.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\music\pd9daotni.m4a.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\ckh5enz\utklaz\fzsdv9ic_tv.bmp.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\zkBFKRCKZ7IX KV Wa4.m4a.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\videos\oa7uy-r84 e\v2hz1riby\-tfbdh.mkv.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\documents\egcel.ppt.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\music\q6ag5\pjtklq_dt3lt.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\t7c9foFD9Kt\Du_\ZFul6 9zRrETYF.docx.vvyu | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\ou84g9.m4a.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Pictures\CkH5eNz\utKlAZ\YNvx X.bmp.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\15d3btm7OvS9NV4xvvA\VNa8b_DcXSUW mzm.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\documents\t7c9fofd9kt\du_\dlt-gu15ir8w0sjrhr-b\nj4aq\xq89ysrduds.pdf.vvyu | Dropped File |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\t7c9foFD9Kt\Du_\dLt-Gu15Ir8w0sJrhR-b\Plnb573cskZFLk.ots.vvyu | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\ckh5enz\utklaz\0djnwc3cmex6ks4d\4x6n.gif.vvyu | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\ckh5enz\g9op7kzr.jpg.vvyu | Dropped File | Image |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\t7c9foFD9Kt\gnn EIw-bv2A ZdUCx.csv.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\ckh5enz\mgf6_dztb1f94j.png.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\documents\56a-hqjck-6jacz_y.docx.vvyu | Dropped File | ZIP |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\MWdsq1QYO68B.m4a.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\gmt4lzpnvyjn.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\15d3btm7OvS9NV4xvvA\3OZhLDJPo6htg3.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Videos\SFCuO8sWL2Jsj.flv.vvyu | Dropped File | Video |
Malicious
|
...
|
c:\users\keecfmwgj\documents\t7c9fofd9kt\du_\dlt-gu15ir8w0sjrhr-b\xd4m_dlxrc.csv.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\t7c9foFD9Kt\3QxjAR\T8wvyki0J9mO.ots.vvyu | Dropped File | ZIP |
Malicious
|
...
|
c:\users\keecfmwgj\videos\oa7uy-r84 e\irrx7uvzuzqm6ox.avi.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\v-der pgnma_nx.png.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\bijamby.mp3.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\jb1orsrry.m4a.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\s387k8QuDVZj.flv.vvyu | Dropped File | Video |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\i8vqvhtu5d8vngf1.flv.vvyu | Dropped File | Video |
Malicious
|
...
|
c:\users\keecfmwgj\music\15d3btm7ovs9nv4xvva\jyj5.mp3.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Pictures\CkH5eNz\up4L8znJo05a3P.jpg.vvyu | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\videos\q7szl.swf.vvyu | Dropped File | Shockwave Flash |
Malicious
|
...
|
c:\users\keecfmwgj\music\15d3btm7ovs9nv4xvva\j2t8dyq7a9 s.m4a.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\sovvb9YRGyMc-lzi435.png.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Documents\dHBKKyUiRLEo_ihqOR.xlsx.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\music\15d3btm7ovs9nv4xvva\sy7kzm.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\videos\oa7uy-r84 e\v2hz1riby\4zazfhouywh4e77ghf.swf.vvyu | Dropped File | Shockwave Flash |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\ssz4\us5ftz3jlmsu.mp4.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\documents\5w2kb0xpz679okq9oh.doc.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Videos\oa7UY-r84 e\v2hZ1rIby\LqnhMFL0C.mkv.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\ssz4\wmqgvke.flv.vvyu | Dropped File | Video |
Malicious
|
...
|
c:\users\keecfmwgj\documents\wxhzvh5geamrbckdv0bk.pptx.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\documents\t7c9fofd9kt\du_\dlt-gu15ir8w0sjrhr-b\gx_wgirqaux_.pptx.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\15d3btm7OvS9NV4xvvA\AKXppD7.m4a.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\q6aG5\M7TOG0.mp3.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\desktop\ssz4\ol21.csv.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\videos\oa7uy-r84 e\mhdjwhf8pwlbd.flv.vvyu | Dropped File | Video |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\ckh5enz\utklaz\0djnwc3cmex6ks4d\rqq-bsnksl6mhoio1.png.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\documents\cs0y__wvetbw2qsiy.docx.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Pictures\CkH5eNz\utKlAZ\O2UTInId.gif.vvyu | Dropped File | Image |
Malicious
|
...
|
C:\Users\kEecfMwgj\Music\VNMhw6NdT0N.m4a.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\_gJDhmKEYoYDlQq.gif.vvyu | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\documents\45jcquohqob2hs.xlsx.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Pictures\CkH5eNz\utKlAZ\0Djnwc3CmEX6ks4d\-kPL6mXQjk.bmp.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\videos\jpdadhjnb.mkv.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\pictures\9 qc8otgh1hix w8i.gif.vvyu | Dropped File | Image |
Malicious
|
...
|
c:\users\keecfmwgj\music\15d3btm7ovs9nv4xvva\bojvfqm.wav.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\appdata\locallow\microsoft\internet explorer\services\search_{0633ee93-d776-472f-a0ff-e1416b8b2e3a}.ico.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\Desktop\ctXFDNnUwfp1foZl.flv.vvyu | Dropped File | Video |
Malicious
|
...
|
c:\users\keecfmwgj\favorites\links\web slice gallery.url.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\favorites\msn websites\msnbc news.url.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\favorites\msn websites\msn entertainment.url.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\favorites\microsoft websites\ie site on microsoft.com.url.vvyu | Dropped File | Stream |
Malicious
|
...
|
c:\users\keecfmwgj\favorites\windows live\windows live mail.url.vvyu | Dropped File | Stream |
Malicious
|
...
|
C:\Users\kEecfMwgj\AppData\Local\22264cfd-727b-45d7-91c9-e74b24b1e0e5\build2.exe | Downloaded File | Binary |
Malicious
|
...
|
Verdict |
Malicious
|
Names | Mal/Generic-S |
Image Base | 0x00400000 |
Entry Point | 0x0040B990 |
Size Of Code | 0x00032600 |
Size Of Initialized Data | 0x00047E00 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2022-01-04 05:28 (UTC+1) |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00401000 | 0x00032482 | 0x00032600 | 0x00000400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.75 |
.data | 0x00434000 | 0x00032988 | 0x00029A00 | 0x00032A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.94 |
.zonami | 0x00467000 | 0x00000400 | 0x00000400 | 0x0005C400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.yosozi | 0x00468000 | 0x00000400 | 0x00000400 | 0x0005C800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.may | 0x00469000 | 0x00000096 | 0x00000200 | 0x0005CC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x0046A000 | 0x000108D0 | 0x00010A00 | 0x0005CE00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.49 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VerifyVersionInfoA | - | 0x00401008 | 0x0003227C | 0x0003167C | 0x00000452 |
VerifyVersionInfoW | - | 0x0040100C | 0x00032280 | 0x00031680 | 0x00000453 |
WriteConsoleInputW | - | 0x00401010 | 0x00032284 | 0x00031684 | 0x00000486 |
EnumDateFormatsW | - | 0x00401014 | 0x00032288 | 0x00031688 | 0x000000E3 |
FindNextFileW | - | 0x00401018 | 0x0003228C | 0x0003168C | 0x00000130 |
CopyFileExA | - | 0x0040101C | 0x00032290 | 0x00031690 | 0x00000061 |
DnsHostnameToComputerNameW | - | 0x00401020 | 0x00032294 | 0x00031694 | 0x000000CF |
ReadConsoleOutputCharacterW | - | 0x00401024 | 0x00032298 | 0x00031698 | 0x00000364 |
SetConsoleActiveScreenBuffer | - | 0x00401028 | 0x0003229C | 0x0003169C | 0x000003A5 |
LockFile | - | 0x0040102C | 0x000322A0 | 0x000316A0 | 0x00000305 |
GetProfileSectionA | - | 0x00401030 | 0x000322A4 | 0x000316A4 | 0x00000231 |
QueryDosDeviceW | - | 0x00401034 | 0x000322A8 | 0x000316A8 | 0x0000034E |
IsSystemResumeAutomatic | - | 0x00401038 | 0x000322AC | 0x000316AC | 0x000002D6 |
GetProcessPriorityBoost | - | 0x0040103C | 0x000322B0 | 0x000316B0 | 0x00000228 |
GetDriveTypeW | - | 0x00401040 | 0x000322B4 | 0x000316B4 | 0x000001BB |
GlobalGetAtomNameA | - | 0x00401044 | 0x000322B8 | 0x000316B8 | 0x0000028D |
lstrlenA | - | 0x00401048 | 0x000322BC | 0x000316BC | 0x000004B5 |
FindNextVolumeMountPointW | - | 0x0040104C | 0x000322C0 | 0x000316C0 | 0x00000134 |
TlsGetValue | - | 0x00401050 | 0x000322C4 | 0x000316C4 | 0x00000434 |
SizeofResource | - | 0x00401054 | 0x000322C8 | 0x000316C8 | 0x00000420 |
WriteConsoleInputA | - | 0x00401058 | 0x000322CC | 0x000316CC | 0x00000483 |
GetConsoleTitleW | - | 0x0040105C | 0x000322D0 | 0x000316D0 | 0x0000019F |
GetComputerNameExW | - | 0x00401060 | 0x000322D4 | 0x000316D4 | 0x00000177 |
OpenEventA | - | 0x00401064 | 0x000322D8 | 0x000316D8 | 0x00000327 |
CallNamedPipeW | - | 0x00401068 | 0x000322DC | 0x000316DC | 0x00000030 |
GetModuleHandleW | - | 0x0040106C | 0x000322E0 | 0x000316E0 | 0x000001F9 |
GetSystemDirectoryA | - | 0x00401070 | 0x000322E4 | 0x000316E4 | 0x00000245 |
SetCurrentDirectoryA | - | 0x00401074 | 0x000322E8 | 0x000316E8 | 0x000003C6 |
BuildCommDCBAndTimeoutsA | - | 0x00401078 | 0x000322EC | 0x000316EC | 0x0000002C |
GetProcAddress | - | 0x0040107C | 0x000322F0 | 0x000316F0 | 0x00000220 |
GetModuleHandleA | - | 0x00401080 | 0x000322F4 | 0x000316F4 | 0x000001F6 |
MoveFileWithProgressW | - | 0x00401084 | 0x000322F8 | 0x000316F8 | 0x00000318 |
GetCommandLineW | - | 0x00401088 | 0x000322FC | 0x000316FC | 0x00000170 |
InterlockedIncrement | - | 0x0040108C | 0x00032300 | 0x00031700 | 0x000002C0 |
InterlockedExchange | - | 0x00401090 | 0x00032304 | 0x00031704 | 0x000002BD |
CopyFileW | - | 0x00401094 | 0x00032308 | 0x00031708 | 0x00000065 |
CreateActCtxW | - | 0x00401098 | 0x0003230C | 0x0003170C | 0x00000068 |
FormatMessageW | - | 0x0040109C | 0x00032310 | 0x00031710 | 0x00000148 |
EnterCriticalSection | - | 0x004010A0 | 0x00032314 | 0x00031714 | 0x000000D9 |
FindNextVolumeW | - | 0x004010A4 | 0x00032318 | 0x00031718 | 0x00000135 |
GetOverlappedResult | - | 0x004010A8 | 0x0003231C | 0x0003171C | 0x00000214 |
LoadLibraryA | - | 0x004010AC | 0x00032320 | 0x00031720 | 0x000002F1 |
CreateNamedPipeW | - | 0x004010B0 | 0x00032324 | 0x00031724 | 0x00000090 |
GetSystemDefaultLangID | - | 0x004010B4 | 0x00032328 | 0x00031728 | 0x00000242 |
GetConsoleAliasesLengthA | - | 0x004010B8 | 0x0003232C | 0x0003172C | 0x00000180 |
WriteProfileSectionW | - | 0x004010BC | 0x00032330 | 0x00031730 | 0x00000498 |
AddAtomW | - | 0x004010C0 | 0x00032334 | 0x00031734 | 0x00000004 |
InterlockedDecrement | - | 0x004010C4 | 0x00032338 | 0x00031738 | 0x000002BC |
HeapFree | - | 0x004010C8 | 0x0003233C | 0x0003173C | 0x000002A1 |
_hwrite | - | 0x004010CC | 0x00032340 | 0x00031740 | 0x0000049E |
InterlockedExchangeAdd | - | 0x004010D0 | 0x00032344 | 0x00031744 | 0x000002BE |
GetStartupInfoW | - | 0x004010D4 | 0x00032348 | 0x00031748 | 0x0000023A |
CreateMailslotW | - | 0x004010D8 | 0x0003234C | 0x0003174C | 0x00000089 |
GetCPInfoExW | - | 0x004010DC | 0x00032350 | 0x00031750 | 0x0000015D |
GetSystemWow64DirectoryW | - | 0x004010E0 | 0x00032354 | 0x00031754 | 0x00000254 |
GetLastError | - | 0x004010E4 | 0x00032358 | 0x00031758 | 0x000001E6 |
GetPrivateProfileIntA | - | 0x004010E8 | 0x0003235C | 0x0003175C | 0x00000216 |
GetConsoleAliasExesLengthW | - | 0x004010EC | 0x00032360 | 0x00031760 | 0x0000017C |
DebugBreak | - | 0x004010F0 | 0x00032364 | 0x00031764 | 0x000000B4 |
SetLastError | - | 0x004010F4 | 0x00032368 | 0x00031768 | 0x000003EC |
LoadLibraryW | - | 0x004010F8 | 0x0003236C | 0x0003176C | 0x000002F4 |
GetDefaultCommConfigA | - | 0x004010FC | 0x00032370 | 0x00031770 | 0x000001B1 |
VirtualAlloc | - | 0x00401100 | 0x00032374 | 0x00031774 | 0x00000454 |
GetACP | - | 0x00401104 | 0x00032378 | 0x00031778 | 0x00000152 |
lstrcpyA | - | 0x00401108 | 0x0003237C | 0x0003177C | 0x000004AF |
GetConsoleAliasA | - | 0x0040110C | 0x00032380 | 0x00031780 | 0x00000179 |
FindNextFileA | - | 0x00401110 | 0x00032384 | 0x00031784 | 0x0000012E |
TerminateProcess | - | 0x00401114 | 0x00032388 | 0x00031788 | 0x0000042D |
EnumResourceLanguagesA | - | 0x00401118 | 0x0003238C | 0x0003178C | 0x000000E6 |
SetConsoleTextAttribute | - | 0x0040111C | 0x00032390 | 0x00031790 | 0x000003C0 |
GlobalGetAtomNameW | - | 0x00401120 | 0x00032394 | 0x00031794 | 0x0000028E |
CreateJobSet | - | 0x00401124 | 0x00032398 | 0x00031798 | 0x00000087 |
lstrcpynA | - | 0x00401128 | 0x0003239C | 0x0003179C | 0x000004B2 |
EnumSystemLocalesA | - | 0x0040112C | 0x000323A0 | 0x000317A0 | 0x000000F8 |
GetPrivateProfileSectionNamesW | - | 0x00401130 | 0x000323A4 | 0x000317A4 | 0x0000021A |
OpenMutexW | - | 0x00401134 | 0x000323A8 | 0x000317A8 | 0x00000330 |
FileTimeToSystemTime | - | 0x00401138 | 0x000323AC | 0x000317AC | 0x00000110 |
CopyFileA | - | 0x0040113C | 0x000323B0 | 0x000317B0 | 0x00000060 |
GlobalWire | - | 0x00401140 | 0x000323B4 | 0x000317B4 | 0x00000298 |
GetTapeParameters | - | 0x00401144 | 0x000323B8 | 0x000317B8 | 0x00000255 |
lstrcmpW | - | 0x00401148 | 0x000323BC | 0x000317BC | 0x000004AA |
SetEvent | - | 0x0040114C | 0x000323C0 | 0x000317C0 | 0x000003D3 |
MoveFileA | - | 0x00401150 | 0x000323C4 | 0x000317C4 | 0x00000311 |
CreateMutexA | - | 0x00401154 | 0x000323C8 | 0x000317C8 | 0x0000008B |
FindResourceW | - | 0x00401158 | 0x000323CC | 0x000317CC | 0x00000139 |
GetCommState | - | 0x0040115C | 0x000323D0 | 0x000317D0 | 0x0000016D |
FormatMessageA | - | 0x00401160 | 0x000323D4 | 0x000317D4 | 0x00000147 |
InterlockedCompareExchange | - | 0x00401164 | 0x000323D8 | 0x000317D8 | 0x000002BA |
CreateFiber | - | 0x00401168 | 0x000323DC | 0x000317DC | 0x00000076 |
GetConsoleFontSize | - | 0x0040116C | 0x000323E0 | 0x000317E0 | 0x0000018D |
LocalAlloc | - | 0x00401170 | 0x000323E4 | 0x000317E4 | 0x000002F9 |
SetFileShortNameA | - | 0x00401174 | 0x000323E8 | 0x000317E8 | 0x000003E1 |
lstrcpyW | - | 0x00401178 | 0x000323EC | 0x000317EC | 0x000004B0 |
HeapLock | - | 0x0040117C | 0x000323F0 | 0x000317F0 | 0x000002A2 |
GetFileAttributesA | - | 0x00401180 | 0x000323F4 | 0x000317F4 | 0x000001C9 |
SetCalendarInfoW | - | 0x00401184 | 0x000323F8 | 0x000317F8 | 0x00000399 |
GetSystemWindowsDirectoryW | - | 0x00401188 | 0x000323FC | 0x000317FC | 0x00000252 |
GetConsoleAliasesW | - | 0x0040118C | 0x00032400 | 0x00031800 | 0x00000182 |
EnumDateFormatsExW | - | 0x00401190 | 0x00032404 | 0x00031804 | 0x000000E2 |
GetComputerNameW | - | 0x00401194 | 0x00032408 | 0x00031808 | 0x00000178 |
GetPrivateProfileStructW | - | 0x00401198 | 0x0003240C | 0x0003180C | 0x0000021F |
_hread | - | 0x0040119C | 0x00032410 | 0x00031810 | 0x0000049D |
LocalSize | - | 0x004011A0 | 0x00032414 | 0x00031814 | 0x00000302 |
OpenWaitableTimerA | - | 0x004011A4 | 0x00032418 | 0x00031818 | 0x00000338 |
EnumResourceNamesW | - | 0x004011A8 | 0x0003241C | 0x0003181C | 0x000000ED |
CreateFileMappingW | - | 0x004011AC | 0x00032420 | 0x00031820 | 0x0000007C |
SetUnhandledExceptionFilter | - | 0x004011B0 | 0x00032424 | 0x00031824 | 0x00000415 |
GetSystemTimeAdjustment | - | 0x004011B4 | 0x00032428 | 0x00031828 | 0x0000024E |
SetProcessShutdownParameters | - | 0x004011B8 | 0x0003242C | 0x0003182C | 0x000003F9 |
lstrcpynW | - | 0x004011BC | 0x00032430 | 0x00031830 | 0x000004B3 |
GetThreadSelectorEntry | - | 0x004011C0 | 0x00032434 | 0x00031834 | 0x00000263 |
GetNamedPipeHandleStateA | - | 0x004011C4 | 0x00032438 | 0x00031838 | 0x00000201 |
FillConsoleOutputCharacterA | - | 0x004011C8 | 0x0003243C | 0x0003183C | 0x00000112 |
GetFullPathNameW | - | 0x004011CC | 0x00032440 | 0x00031840 | 0x000001DF |
GetThreadPriority | - | 0x004011D0 | 0x00032444 | 0x00031844 | 0x00000261 |
WriteConsoleA | - | 0x004011D4 | 0x00032448 | 0x00031848 | 0x00000482 |
AddAtomA | - | 0x004011D8 | 0x0003244C | 0x0003184C | 0x00000003 |
FreeUserPhysicalPages | - | 0x004011DC | 0x00032450 | 0x00031850 | 0x00000150 |
WriteConsoleOutputCharacterW | - | 0x004011E0 | 0x00032454 | 0x00031854 | 0x0000048A |
OpenJobObjectW | - | 0x004011E4 | 0x00032458 | 0x00031858 | 0x0000032E |
CreateFileW | - | 0x004011E8 | 0x0003245C | 0x0003185C | 0x0000007F |
BuildCommDCBAndTimeoutsW | - | 0x004011EC | 0x00032460 | 0x00031860 | 0x0000002D |
GetBinaryTypeW | - | 0x004011F0 | 0x00032464 | 0x00031864 | 0x00000159 |
SetCalendarInfoA | - | 0x004011F4 | 0x00032468 | 0x00031868 | 0x00000398 |
GetFileAttributesW | - | 0x004011F8 | 0x0003246C | 0x0003186C | 0x000001CE |
GetFileInformationByHandle | - | 0x004011FC | 0x00032470 | 0x00031870 | 0x000001D0 |
GetProfileSectionW | - | 0x00401200 | 0x00032474 | 0x00031874 | 0x00000232 |
CommConfigDialogW | - | 0x00401204 | 0x00032478 | 0x00031878 | 0x0000004F |
GetDiskFreeSpaceExA | - | 0x00401208 | 0x0003247C | 0x0003187C | 0x000001B5 |
LocalFree | - | 0x0040120C | 0x00032480 | 0x00031880 | 0x000002FD |
Sleep | - | 0x00401210 | 0x00032484 | 0x00031884 | 0x00000421 |
InitializeCriticalSection | - | 0x00401214 | 0x00032488 | 0x00031888 | 0x000002B4 |
DeleteCriticalSection | - | 0x00401218 | 0x0003248C | 0x0003188C | 0x000000BE |
LeaveCriticalSection | - | 0x0040121C | 0x00032490 | 0x00031890 | 0x000002EF |
RaiseException | - | 0x00401220 | 0x00032494 | 0x00031894 | 0x0000035A |
RtlUnwind | - | 0x00401224 | 0x00032498 | 0x00031898 | 0x00000392 |
WideCharToMultiByte | - | 0x00401228 | 0x0003249C | 0x0003189C | 0x0000047A |
GetCommandLineA | - | 0x0040122C | 0x000324A0 | 0x000318A0 | 0x0000016F |
GetStartupInfoA | - | 0x00401230 | 0x000324A4 | 0x000318A4 | 0x00000239 |
HeapValidate | - | 0x00401234 | 0x000324A8 | 0x000318A8 | 0x000002A9 |
IsBadReadPtr | - | 0x00401238 | 0x000324AC | 0x000318AC | 0x000002C8 |
UnhandledExceptionFilter | - | 0x0040123C | 0x000324B0 | 0x000318B0 | 0x0000043E |
GetModuleFileNameW | - | 0x00401240 | 0x000324B4 | 0x000318B4 | 0x000001F5 |
GetCurrentProcess | - | 0x00401244 | 0x000324B8 | 0x000318B8 | 0x000001A9 |
IsDebuggerPresent | - | 0x00401248 | 0x000324BC | 0x000318BC | 0x000002D1 |
TlsAlloc | - | 0x0040124C | 0x000324C0 | 0x000318C0 | 0x00000432 |
TlsSetValue | - | 0x00401250 | 0x000324C4 | 0x000318C4 | 0x00000435 |
GetCurrentThreadId | - | 0x00401254 | 0x000324C8 | 0x000318C8 | 0x000001AD |
TlsFree | - | 0x00401258 | 0x000324CC | 0x000318CC | 0x00000433 |
GetOEMCP | - | 0x0040125C | 0x000324D0 | 0x000318D0 | 0x00000213 |
GetCPInfo | - | 0x00401260 | 0x000324D4 | 0x000318D4 | 0x0000015B |
IsValidCodePage | - | 0x00401264 | 0x000324D8 | 0x000318D8 | 0x000002DB |
SetFilePointer | - | 0x00401268 | 0x000324DC | 0x000318DC | 0x000003DF |
SetHandleCount | - | 0x0040126C | 0x000324E0 | 0x000318E0 | 0x000003E8 |
GetStdHandle | - | 0x00401270 | 0x000324E4 | 0x000318E4 | 0x0000023B |
GetFileType | - | 0x00401274 | 0x000324E8 | 0x000318E8 | 0x000001D7 |
QueryPerformanceCounter | - | 0x00401278 | 0x000324EC | 0x000318EC | 0x00000354 |
GetTickCount | - | 0x0040127C | 0x000324F0 | 0x000318F0 | 0x00000266 |
GetCurrentProcessId | - | 0x00401280 | 0x000324F4 | 0x000318F4 | 0x000001AA |
GetSystemTimeAsFileTime | - | 0x00401284 | 0x000324F8 | 0x000318F8 | 0x0000024F |
ExitProcess | - | 0x00401288 | 0x000324FC | 0x000318FC | 0x00000104 |
GetModuleFileNameA | - | 0x0040128C | 0x00032500 | 0x00031900 | 0x000001F4 |
FreeEnvironmentStringsA | - | 0x00401290 | 0x00032504 | 0x00031904 | 0x0000014A |
GetEnvironmentStrings | - | 0x00401294 | 0x00032508 | 0x00031908 | 0x000001BF |
FreeEnvironmentStringsW | - | 0x00401298 | 0x0003250C | 0x0003190C | 0x0000014B |
GetEnvironmentStringsW | - | 0x0040129C | 0x00032510 | 0x00031910 | 0x000001C1 |
HeapDestroy | - | 0x004012A0 | 0x00032514 | 0x00031914 | 0x000002A0 |
HeapCreate | - | 0x004012A4 | 0x00032518 | 0x00031918 | 0x0000029F |
VirtualFree | - | 0x004012A8 | 0x0003251C | 0x0003191C | 0x00000457 |
WriteFile | - | 0x004012AC | 0x00032520 | 0x00031920 | 0x0000048D |
HeapAlloc | - | 0x004012B0 | 0x00032524 | 0x00031924 | 0x0000029D |
HeapSize | - | 0x004012B4 | 0x00032528 | 0x00031928 | 0x000002A6 |
HeapReAlloc | - | 0x004012B8 | 0x0003252C | 0x0003192C | 0x000002A4 |
FlushFileBuffers | - | 0x004012BC | 0x00032530 | 0x00031930 | 0x00000141 |
GetConsoleCP | - | 0x004012C0 | 0x00032534 | 0x00031934 | 0x00000183 |
GetConsoleMode | - | 0x004012C4 | 0x00032538 | 0x00031938 | 0x00000195 |
OutputDebugStringA | - | 0x004012C8 | 0x0003253C | 0x0003193C | 0x0000033A |
WriteConsoleW | - | 0x004012CC | 0x00032540 | 0x00031940 | 0x0000048C |
OutputDebugStringW | - | 0x004012D0 | 0x00032544 | 0x00031944 | 0x0000033B |
InitializeCriticalSectionAndSpinCount | - | 0x004012D4 | 0x00032548 | 0x00031948 | 0x000002B5 |
MultiByteToWideChar | - | 0x004012D8 | 0x0003254C | 0x0003194C | 0x0000031A |
LCMapStringA | - | 0x004012DC | 0x00032550 | 0x00031950 | 0x000002E1 |
LCMapStringW | - | 0x004012E0 | 0x00032554 | 0x00031954 | 0x000002E3 |
GetStringTypeA | - | 0x004012E4 | 0x00032558 | 0x00031958 | 0x0000023D |
GetStringTypeW | - | 0x004012E8 | 0x0003255C | 0x0003195C | 0x00000240 |
GetLocaleInfoA | - | 0x004012EC | 0x00032560 | 0x00031960 | 0x000001E8 |
SetStdHandle | - | 0x004012F0 | 0x00032564 | 0x00031964 | 0x000003FC |
GetConsoleOutputCP | - | 0x004012F4 | 0x00032568 | 0x00031968 | 0x00000199 |
CloseHandle | - | 0x004012F8 | 0x0003256C | 0x0003196C | 0x00000043 |
CreateFileA | - | 0x004012FC | 0x00032570 | 0x00031970 | 0x00000078 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CharToOemBuffW | - | 0x00401304 | 0x00032578 | 0x00031978 | 0x00000035 |
CharUpperA | - | 0x00401308 | 0x0003257C | 0x0003197C | 0x00000037 |
GetCursorInfo | - | 0x0040130C | 0x00032580 | 0x00031980 | 0x00000118 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
AbortSystemShutdownW | - | 0x00401000 | 0x00032274 | 0x00031674 | 0x00000004 |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
build2.exe | 7 | 0x00400000 | 0x0047AFFF | Relevant Image | 32-bit | 0x00418760 |
...
|
||
buffer | 7 | 0x005823F8 | 0x005AA347 | First Execution | 32-bit | 0x005823F8 |
...
|
||
buffer | 7 | 0x00210000 | 0x00255FFF | First Execution | 32-bit | 0x00210000 |
...
|
||
buffer | 8 | 0x00400000 | 0x00458FFF | First Execution | 32-bit | 0x0041FE8C |
...
|
||
build2.exe | 7 | 0x00400000 | 0x0047AFFF | Process Termination | 32-bit | - |
...
|
||
buffer | 8 | 0x00400000 | 0x00458FFF | Content Changed | 32-bit | 0x00427210 |
...
|
||
buffer | 8 | 0x00400000 | 0x00458FFF | Content Changed | 32-bit | 0x00425F5E |
...
|
||
buffer | 8 | 0x00400000 | 0x00458FFF | Content Changed | 32-bit | 0x00426000 |
...
|
||
buffer | 8 | 0x00400000 | 0x00458FFF | Content Changed | 32-bit | 0x0042303F |
...
|
||
buffer | 8 | 0x00400000 | 0x00458FFF | Content Changed | 32-bit | 0x0042D30D |
...
|
||
buffer | 8 | 0x00400000 | 0x00458FFF | Content Changed | 32-bit | 0x00421F29 |
...
|
||
buffer | 8 | 0x00400000 | 0x00458FFF | Content Changed | 32-bit | 0x0041D9EA |
...
|
||
buffer | 8 | 0x00400000 | 0x00458FFF | Content Changed | 32-bit | 0x00428F5A |
...
|
||
buffer | 8 | 0x00400000 | 0x00458FFF | Content Changed | 32-bit | 0x0043052C |
...
|
||
buffer | 8 | 0x00400000 | 0x00458FFF | Content Changed | 32-bit | 0x00434DE5 |
...
|
||
buffer | 8 | 0x00400000 | 0x00458FFF | Content Changed | 32-bit | 0x00404364 |
...
|
||
buffer | 8 | 0x00400000 | 0x00458FFF | Content Changed | 32-bit | 0x004188E9 |
...
|
||
buffer | 8 | 0x00400000 | 0x00458FFF | Content Changed | 32-bit | 0x004150CB |
...
|
C:\Users\kEecfMwgj\Documents\t7c9foFD9Kt\Du_\n4CMD g2s\Uomn Anj\5kZStye71WnSS.pdf.vvyu | Dropped File |
Suspicious
|
...
|
C:\Users\kEecfMwgj\Documents\t7c9foFD9Kt\Du_\dLt-Gu15Ir8w0sJrhR-b\f1rc6EXPyfw.pdf.vvyu | Dropped File |
Suspicious
|
...
|
C:\Users\kEecfMwgj\Desktop\SSz4\wOWCVtjIK1-R.rtf.vvyu | Dropped File | RTF |
Clean
|
...
|
…LðžS€fŒÁy+ÕTc<Ô§âoC¿å(í›g…e|Œ]ùRµæªËføê*Jªm+&• é¯ÇË<pÓDx<FQ’vBpÅ6ú÷Á|ÅkÿæVeÌp««8¦‰nè\x8d0"\x8dÊdSp_pùÓ^¾Ù”Ò¡nãÿZàü“FD‘xó³D6PéÏ2ª"X›(Å€Y®EºE4a/+ì.O´‘ØJêW*| ®YFiÖ£‹¿\x8f¬Ø1lÙ\x9d9Aµ®â&;¯n4yV£å>$â-ˆx_üv6Ö9|AËD,ÃK§á£Ç*tÀ„3Üòápà¿Àac*¨CóÏÙ½¬\x90ÿaΆ§Ä3R´§œFbMÄæ\x901¹”ƒWôtq‰ˆñ:ž¬®%A‹´PI¾BéXnBÃûþiˆ YÙ›¿;“˜Ø·B#MŠPUJ:OaŒ’yñ¸k39ÌÓÝ)CbÒÃÿ‚›˜²dHN3eg¢Ìu¥U2TàÒSƒbÜМШ‡\x8d®fÔÒ5"§dxp/Ïî=®pÆ9êaâ*°ô5ÿ4‘ö"ö¯ÑwœVÕeD?¾‹…²*Ô+*:±À¦*î[¾o—ÕÝÜlxÜ'ϨŠ)¸â‘sõcÐÿJÁ‰€ÖUçíR\x90 ÊW'KÃPˆxÞÜÙIZ°°3Šñ¿üÙGÊXîÇ"SpanîŸ[µFl ]jó.çM$”Âëœlä¨Nèh[Y@‰Õþb?¡hYÚ2Žwí—x’•oË«/¶–Ãä|ꮇûZ`‚\x8d©(\x8dV8H؆ŠÓœ\x90ä,¸ã ÉÝOÍéÁya˜ÒØw”Éñ!ÔèÀ°éŽvL/†šÌÜó¡¤Ò Þº1ŸŠ<Š†ÑºH¶Û<A[¯ê†ü¢ökKtl~tcê–žŸ.xÄo¦•æó©\x8fò³Ns¹aÂW¾žà*ª —À–äÖ°Ø\x81Õ\x8d"K½Y)%p\x8f^¹šº Ú“ ú›óÁt\x9dþÆ")\x90\x90M\x816ñ5ÙÂL$Š?j²?%×ÊoÏ8Yô»Êt ±®Ì¼pÙŠ4;þonŸDðdwÍ\x9d\x8f‚SHÎKPlþ‰ÜUª·¬òAÖjQ!É÷š÷°qã¿ìêjC~Ž\x81ÿvmáq;ƒ»×ˆÐ\x8d:ÙüŠ\x81|jÚ©0P2¨ãÈJ¸ß½Ü¿•äTÿ÷·ÈpñÓŠ×8RRÞ‚-ç’ ð€Ðû |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\kEecfMwgj\Documents\t7c9foFD9Kt\Du_\dLt-Gu15Ir8w0sJrhR-b\NJ4Aq\JRCSXUX.rtf.vvyu | Dropped File | RTF |
Clean
|
...
|
½æ²ÃÑÊœì\x8f[±®Ú>ÿ~ó`›"L tæȦâEÀMòdŸÅqŸh¢!Á„éÙ9Vä—„STÏ”‚è9\x8d°×º°Âg£!éTÊtsôæ«\x81EÝ’ŸìušØušÏ%/Ïâ½m@U2€\x9d+RAì¿`RF%m~c#Ї§<RÌ׶`´Û„˺ê\x8f[Nž ãsR¬7%‚±âÈõµoÎpß®ß%U¬Y]%$vñƒOÍo‹øÍ«ñ²¼:Ľg½ùhTÎ+`ŠØ€©ŠAXõXå\x8dÁqå¾²åsVÃÄÚÝÏí§XF¸Ú\x90ŸÓá©‘*\x904=±¼\x81§ìÅ–9\x90\x8d]@g<ævâ$–onŠ*ÂpMÜ~¡ÃÁš±Õ•ß_ˆŸ¦Ärò¡É bXÜK=ýŠ¿ôs´šL¹ÃÎZÄT$Çù4îýH”þÁL‰^Ó¯C[§iŠ›éW¿°)ׯ’ƒÌVm±oö‚Cï°B²,.‹\x9d€ãz0ÎÑß"¼S]§ÿ´íÁHûM;Û\x8dø\x9dv óLYà(¹ÍÔµxËfúÐø:r×±½o!ö3 †²àÐø£SÂVFz¨æ±(ø±±4ØgúßödeÚŒµþz„Ôއ¹|p4DʇOﶹ~´C—ÕV«Ýã?bÙKÁ’—bu…ºŠÞlFT3€@ÿnãM4E[·þ?íPA\x90Þƒù¾Ýr?m¦RîK‡I§äH»íq\x9dzü‹´2Ÿ˜í²š1Š¿–ñ»ÞýÃê®\x9dÉŽP³Bà±Õì?Ix*–£'\x81M—Õ„¼•øßT:_ü·í\x8f¬k¸ç™L þÔAËCnÍ°Ô\x8fñ器p÷²t„ôAª³PÍSïï•gpsOxWÌ\x8dŠ¶É˜…(9ÞÛ¢=°<òŠ¹þGÐØúOM˜ü-œ\x9d\x8dVíàùîi7+çZü¡Ä.©¨ãIJŠ÷y€‹“x&˜ÛŒˆ#‰ —¿ÕY´E²ésç¶=o`Ñ®ðVx9ëÌëõ²òÀ,*E\x9d%JF8’weÁ܉|ÙfN¶ÓÇlr~³«Ÿ‹àÜↈZ¥¸xÛë:ΔDfô^ÄÝ tÇßʹ˜ÀVY¢Ü\x8fµÅúèš‚” ÐGû¬ )SP<$=Y¦iT]Å·‡£ÛØôǺzü ]yÖéxÑUŽ'Ê~zŽ 2êþiÒ¢cW—â0ÖÒxŒ?¼³7“â’x‰Ü¬Z*@ùíH¢lÒËlÊ |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\kEecfMwgj\Desktop\y1T01ydaDA.rtf.vvyu | Dropped File | RTF |
Clean
|
...
|
™ú\x8f¤vLH®ö‘ìãÕ!ÁºO”‡ØÐjEËðìÂöc$¢‰pMZøn>™Ž‚®Ì‹+Ðúê(ÿv7ç³á¯ Sr£1~\x8dêˆÖì”;¥\x81À`‘ЛóQ¿ÄßAç%ÜUŒÌSHæ\x81r¤Uó[Ž6ÆA½y”%æžÜðŽƒÏµÑ5ƒ9=vJM&‚Õ *æVù'»çþ?K´Mþ”ÔÔHõ¼ÿ±i‰Ã9áj©Ó;I˜‚¤˜¼Ô´ËVÄ„ê½Ç¥5Á“-À–å‘ãã÷%Ô‚F.œšÔe¶C‘G5l¹xçÍÊ¿åmœR&ÐzŽèèzø<Y¹,³ü\x8dÛ¬ò᧗MT7ñÆÃ_x²XÕ»ß[‹’¡#šêcåò¾xÔ²Û$ìdæì܈\x8fkúT£æšÉKKµ¥7iw_¿z"nPŪCÈa×°4§²Éyá^a,°cå±\x8f³H¤HðL-e\x8f4P¬ºÙfÚ•²[SÇ0\x90â†0æq”Ó¾Å\x81ˆï?\x81ÜRÜ xúr.eØh>F6Ïxâ<cl®ééM-ÄpÞ·’6j²òJ·î(ä’CùULdà’qÏ¢Ê[®…¾Ðäܽ>“Y8"Ö.Ó˜ÀÙƒ©Àk±O:2žWïÉ~ìûþšÌ\x8d?ò” úž™æ#Ç <îæ“sTD [÷§Mê5µ>mfÛósù~àæÒqe,RøšP¨J)zÂÁ <¶ÃP „³2\x8d[8_œ¯ôǵZ\x9d'ýº¦K×<ºÞ¸ðAª‹É‰2’ƲvÅæÙüô‡NU:¥«ÍzK¹I#l®ˆ¡ºpù±Ã·š6öR&Y0V§lšÕ`\x81H÷M‰¾`Ó¦Èb¾¥ìß®›ÉÀ $~ú2´ð Ì-ÔV”k^ޣϫwK0ëôÃÕ¿_1Ÿj•&°·™^ê`\x9dU˜O‘.¸F|%4v“ÍmÁÊÃ\x90*šÄR—ŸŠm¬~ÅÏœ·14ØÇAümûí4̵v¾,źô¢ —ÉÏ\x9d²Æ²óI’;5É(n³$ †s¾(XõÆÌeÄ·0ÕߥýÍo\x9dƒ£f«ŒC-½Pxa²–ÖH¨ŽÚûëR|(aÍØA*ùBú¡¶è¹]#¯Gù[…µ\x8dO£ÈmëaŽÆªz᧯¦þåít]½ãˆp÷Ëøï7z^/ræ„c¯#—PÈ¿n7‘½Ê†wÑv¬…9ÃXMÐecß‘!n’g |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\kEecfMwgj\Documents\t7c9foFD9Kt\Du_\n4CMD g2s\Uomn Anj\3X s\E6LAV7pmdeNqQC2aZ.rtf.vvyu | Dropped File | RTF |
Clean
|
...
|
&´ðÿéˆÆ4˜¯Ô—µW×é즮•ó“ÛóoqšälNWôpÜÙ¾Æ']9öQ\x8fb¯¦n®9¬øÍÔNg\x81ꟿxëLCîõ/XrJD œw\x8f›o\x8dÃûé‚=BÌ>%vzqï:òè©•oÏRÙÁé»PþZ¾ÇŒ<Õ©7®X?‹‘Žw¯¹EE+Xï\x8fjuù ]›à™>Þ÷£hÙ7ÊÅJó%õãE?zé<±¶%±·Ìþ"×_™jÔ€ÛÎzËûúí`Ü$³W"°^áíıÊã¤Ñ2?ú@óî”ð–J†¾IàêG°6ÍJ±qíœ\x8f¡ÿ¦ˆ" û«æŸ’Z-H/ Ÿá©¥1Db˜öbßß)¤\x81ò8~ýÒÒ;[šÁúžª÷‰\x90x20@Dýñ[Ö9w›êî.áoË#Ä%©qœëïqµFh*×=knG)²Æøaqf„¹Ñ^ ÕÆÙÅÙH.KÎQn]ž¢Â¶&æS¥qžEû:?Å 'r^®aÓÿ‘ŽÁÛ¸ÐtÃ^×Ðm]þÁ¼,"ÍdÍDÍ—\x90”r÷!ØŸ´Á\x81(>OA¢Ú2›N~qÐì9ü¶špʲôt¬ü¯’4Û4'×ämR6Ó\x8dÁévU©2ü…xkʺÃ?#›q*Qd“õY:Å%uË¥0™A•—«¯÷CçŽBxdp¢¶OÕ‰¥:_Ó ¸’w?€¸iH4“=$^Ù°½Æ_á˜Ø=QO5<Ö’-® ö#Ö$éÙb4jü“d(¡÷jWðbyîHFRð%ÁCÍ¡Ú.‚%qÌD>ì2J¹ÙƆi~pÁŒ»Û¶Âׄ!¦£ÏÁŸxþ¶vŽÊv+›ìÎ&¸Ó'ší:©%¿•©t*cw'K©bW|bŠQIB.(M=Öªå]M4h óñžÿdËuýßÖ^”ëž¹íiKý ¸Ï—'ÞT°Ô\x8dººx÷‡AµŠ*×há4_xô&³ódCö³¬×^‹¯ïƒ5ùfã_ʆB7°º¬Rd<=™yìK>ÅulÎ7Û¥Õ‚ë*˜“mÙClWòfä\x90’5ë„¿:Ì'ù^ég÷<\x81µ¨É Õ£¡ËÙ?„ŸÒ|+ÂÂÕY9•J]0ßøÄòæ~¼÷ÞØǤlY¤¸3&øD»¦Nml*ÚA²˜«g¯6À2\x9dË¢”Zò4ùÚ~ÚÞÛ^¹P«#˜¦-À`ШKœ:CùœÒëHlAf-ï |
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
c:\users\keecfmwgj\desktop\55043585c15ff65ca4b8df91c0b0f1c883d4cfd40933c6d25c2d9159e2f0757c.exe.vvyu | Dropped File | Binary |
Clean
|
...
|
c:\users\keecfmwgj\documents\outlook files\franc@gdllo.de.pst.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\ucR8jv0bs4.wav.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\Jz_yDfR.pptx.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\CkH5eNz\vVOtpApjKaG.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\CkH5eNz\utKlAZ\0Djnwc3CmEX6ks4d\uvhJEjKV7-C WKqxn.jpg.vvyu | Dropped File | Image |
Clean
|
...
|
c:\users\keecfmwgj\desktop\deoyfojzp0gudvzpna_.docx.vvyu | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\videos\0kzy5iydb0_9j1mvgm.avi.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\pictures\ckh5enz\utklaz\jnrbiji7doab7.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\o 1Cxif2UWijY.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\STFgs6SSBPdXXJ-.swf.vvyu | Dropped File | Shockwave Flash |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\q6aG5\MxIGzOSUnBj1N-Hm_Cz.wav.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\music\15d3btm7ovs9nv4xvva\xwnlbab.m4a.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\cYM_5nYHIK9OKB4.docx.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\T_12gb.swf.vvyu | Dropped File | Shockwave Flash |
Clean
|
...
|
c:\users\keecfmwgj\pictures\jnq_e2h.png.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\t7c9fofd9kt\du_\dlt-gu15ir8w0sjrhr-b\nj4aq\umq3ie18sey.ots.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\t7c9foFD9Kt\Du_\n4CMD g2s\5GbLDOSSAl.ppt.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\vf vz3sgUnK.m4a.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\76Zhb85hvgFyb.mp3.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\t7c9fofd9kt\du_\lviuhooev0pnicn.docx.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\4STyoT-wdxQ0wVe.jpg.vvyu | Dropped File | Image |
Clean
|
...
|
c:\users\keecfmwgj\desktop\evtlse5tu.flv.vvyu | Dropped File | Video |
Clean
|
...
|
c:\users\keecfmwgj\videos\oa7uy-r84 e\v2hz1riby\p14cw.avi.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\2tgZNx.png.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\6umy14w18jmqx-yvo.swf.vvyu | Dropped File | Shockwave Flash |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\t7c9foFD9Kt\Du_\dLt-Gu15Ir8w0sJrhR-b\NJ4Aq\5cU7.ppt.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\CkH5eNz\utKlAZ\0Djnwc3CmEX6ks4d\4mQ2gMUrsax_RZzVhH.png.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\o9negzjy_dtz.xlsx.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\kvVdOKfcoMs.docx.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\mwFzdcAP3BzfKLGuYUP.m4a.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\pictures\ckh5enz\gmzn.jpg.vvyu | Dropped File | Image |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\oa7UY-r84 e\v2hZ1rIby\h5htKcYKQyPR4iO.avi.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\kLZx.pptx.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Contacts\Administrator.contact.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\pictures\ckh5enz\utklaz\9avxor.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\pictures\ckh5enz\utklaz\0djnwc3cmex6ks4d\vnnb6-.png.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\ye2nvj3b.gif.vvyu | Dropped File | Image |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\UJ_4b2bXQpL4y4vN5dT.gif.vvyu | Dropped File | Image |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\t7c9foFD9Kt\3QxjAR\0nTeT5RDjQL6aro.csv.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\eipo1g9l1l6y bqxfc.xlsx.vvyu | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\desktop\yyv494w_m8z.mkv.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\t7c9foFD9Kt\Du_\dLt-Gu15Ir8w0sJrhR-b\8OhTRGE.ods.vvyu | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\videos\oa7uy-r84 e\kivyeyyglbqsq0r.mp4.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\oa7UY-r84 e\v2hZ1rIby\Qu4Qt2I97kkTD2.mkv.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\t7c9fofd9kt\du_\n4cmd g2s\uomn anj\tpc-xlgkaoki.ots.vvyu | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\documents\t7c9fofd9kt\du_\dlt-gu15ir8w0sjrhr-b\pj33ix3vapezxx5ftd.odp.vvyu | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\pictures\scabdm3i.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\bp5Lq3Xfqz.pps.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\pictures\hehayv.jpg.vvyu | Dropped File | Image |
Clean
|
...
|
c:\users\keecfmwgj\documents\t7c9fofd9kt\du_\dejp0tkawtpu.xlsx.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\Pk0h2Rnp8cQPR.wav.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\ssz4\1kkv.pptx.vvyu | Dropped File | ZIP |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\mQVKO4ih33AabgIOBNO.xlsx.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\t7c9fofd9kt\du_\n4cmd g2s\uomn anj\3x s\ygjufjkixo9zime2--.xlsx.vvyu | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\desktop\g8m9wn ztgrqdpa.doc.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\music\bqn7jsn2k_hp.wav.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\c3xtys g2.docx.vvyu | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\documents\t7c9fofd9kt\du_\dlt-gu15ir8w0sjrhr-b\gwmlsc2zpd0nk-c.ods.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\t7c9foFD9Kt\Du_\NaSt.xls.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\hKaWlB 0CoAmHRQqjswP.jpg.vvyu | Dropped File | Image |
Clean
|
...
|
c:\users\keecfmwgj\music\7rucdwyus.wav.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\wr0kwgonpwoxie1pnc.pptx.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\fk6k3tax.flv.vvyu | Dropped File | Video |
Clean
|
...
|
c:\users\keecfmwgj\documents\_-fr_fxi6 yovrtv.pptx.vvyu | Dropped File | ZIP |
Clean
|
...
|
c:\users\keecfmwgj\music\15d3btm7ovs9nv4xvva\ppzfg9bgoa54dvfgt.mp3.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\SSz4\9yAZzTXyNBlNhh5kD.mp3.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\HuD-Vd.ppt.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\q6aG5\7URv2AmQZDAOxub1g.mp3.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\-CuxYEa66mYn.mp3.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\oa7UY-r84 e\_9xS8m5SRrPmY7bhauad.flv.vvyu | Dropped File | Video |
Clean
|
...
|
C:\Users\kEecfMwgj\Videos\EOKz9As_PQ-0e NIZu2.swf.vvyu | Dropped File | Shockwave Flash |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\vUg7BS.mp3.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\t7c9foFD9Kt\Du_\dLt-Gu15Ir8w0sJrhR-b\iqqs1g9luBUmo0B.xlsx.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\XP3a5K43wYYvtQY.wav.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\CkH5eNz\utKlAZ\0Djnwc3CmEX6ks4d\1stwBGeldnm.png.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\XevfC bH.wav.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\fjFyJ2LwCFuD.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\CkH5eNz\utKlAZ\U HHhHG8Z.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\iiy6urtkmkg.swf.vvyu | Dropped File | Shockwave Flash |
Clean
|
...
|
c:\users\keecfmwgj\documents\t7c9fofd9kt\arxo4ulawvhk8w8h1.ppt.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\vomzdu.docx.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\x5xovotqfAL_W9MsP.wav.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Desktop\zuIFM8NX8rRSCWk.wav.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\videos\oa7uy-r84 e\q _s.flv.vvyu | Dropped File | Video |
Clean
|
...
|
c:\users\keecfmwgj\desktop\vz5gqw9gjyrik.swf.vvyu | Dropped File | Shockwave Flash |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\CkH5eNz\utKlAZ\0Djnwc3CmEX6ks4d\m6h6LTvd.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Music\nA1Vyxh1cNbdS.mp3.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\music\j6ymsltmtmc.wav.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\videos\oa7uy-r84 e\v2hz1riby\d4q2ikayi.swf.vvyu | Dropped File | Shockwave Flash |
Clean
|
...
|
C:\Users\kEecfMwgj\Documents\t7c9foFD9Kt\Du_\hWL0ZU2H-.doc.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\videos\q4w1nrmqjy.mp4.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\t7c9fofd9kt\3qxjar\_53mq3d4gztl-z.docx.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\music\ptejmkr0q.m4a.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\t7c9fofd9kt\du_\dlt-gu15ir8w0sjrhr-b\iamsqvekij.doc.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\documents\t7c9fofd9kt\3qxjar\1yb7ddaxweij12j.pptx.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\CkH5eNz\utKlAZ\Y3WLOzPu7e3b.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\ykvjwxghtjh67j.m4a.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\pictures\bd1jkl.jpg.vvyu | Dropped File | Image |
Clean
|
...
|
c:\users\keecfmwgj\pictures\ckh5enz\utklaz\0djnwc3cmex6ks4d\oyuf.gif.vvyu | Dropped File | Image |
Clean
|
...
|
C:\Users\kEecfMwgj\Pictures\CkH5eNz\utKlAZ\0Djnwc3CmEX6ks4d\dhm2oVTh3lhgkYuY-T.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\pwyx2b-yoplcn5mp.wav.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\music\15d3btm7ovs9nv4xvva\hfxb2ecm2er.wav.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\3yd_u.doc.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\music\q6ag5\ylvock6jtrl_ur2.m4a.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\ssz4\hhor6gwwzwspwwtizr7.mp3.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\desktop\xwzgawkf.wav.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\pictures\0md97n-k.bmp.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Favorites\Microsoft Websites\Microsoft Store.url.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\favorites\microsoft websites\microsoft at home.url.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Favorites\Microsoft Websites\IE Add-on site.url.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Favorites\Windows Live\Windows Live Gallery.url.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Favorites\Windows Live\Windows Live Spaces.url.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\favorites\msn websites\msn sports.url.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Favorites\Microsoft Websites\Microsoft At Work.url.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\favorites\msn websites\msn autos.url.vvyu | Dropped File | Stream |
Clean
|
...
|
C:\Users\kEecfMwgj\Favorites\MSN Websites\MSN Money.url.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\favorites\windows live\get windows live.url.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\favorites\msn websites\msn.url.vvyu | Dropped File | Stream |
Clean
|
...
|
c:\srvsvc | Dropped File | Empty |
Clean
|
...
|
c:\wkssvc | Dropped File | Empty |
Clean
|
...
|
c:\users\keecfmwgj\appdata\local\microsoft\windows\temporary internet files\content.ie5\x9ohk109\geo[1].json | Downloaded File | Unknown |
Clean
|
...
|
C:\Users\kEecfMwgj\AppData\Local\bowsakkdestx.txt | Downloaded File | Unknown |
Clean
|
...
|
6d214ad6b2cf334f0545be9f044bb26b2bd3d43dd77f5e124a5769b86c9ad995 | Downloaded File | HTML |
Clean
|
...
|
c:\users\keecfmwgj\appdata\roaming\microsoft\windows\ietldcache\index.dat | Modified File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat | Modified File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\appdata\local\microsoft\windows\history\history.ie5\index.dat | Modified File | Stream |
Clean
|
...
|
c:\users\keecfmwgj\appdata\roaming\microsoft\windows\cookies\index.dat | Modified File | Stream |
Clean
|
...
|