VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: | - |
OCCT.exe
Windows Exe (x86-32)
Created at 2020-12-25T11:39:00
Remarks
(0x0200001E): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\OCCT.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4b4a9e |
Size Of Code | 0xb2c00 |
Size Of Initialized Data | 0x2200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 1997-07-24 16:03:53+00:00 |
Version Information (11)
»
Assembly Version | 7.2.1.99 |
Comments | OCCT - Stability testing, integrated monitoring, graphs... |
CompanyName | OCCT - Ocbase - Adrien Mercier |
FileDescription | OCCT |
FileVersion | 7.2.1.99 |
InternalName | OCCT.exe |
LegalCopyright | Copyright © 2019 and until the end of time |
LegalTrademarks | OCCT |
OriginalFilename | OCCT.exe |
ProductName | OCCT |
ProductVersion | 7.2.1.99 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0xb2aa4 | 0xb2c00 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.41 |
.rsrc | 0x4b6000 | 0x1f6e | 0x2000 | 0xb2e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.69 |
.reloc | 0x4b8000 | 0xc | 0x200 | 0xb4e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0xb4a78 | 0xb2c78 | 0x0 |
Memory Dumps (144)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
occt.exe | 1 | 0x008F0000 | 0x009A9FFF | Relevant Image | 32-bit | - |
...
|
|||
buffer | 1 | 0x00370400 | 0x003817FF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x00370178 | 0x0037017F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003701A0 | 0x003701A7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003701C8 | 0x003701CF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003701F0 | 0x003701F7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x00370218 | 0x0037021F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x00381B9E | 0x00381BA8 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x00381B92 | 0x00381B9C | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x00381800 | 0x00381847 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x00381BAC | 0x00381BAF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x00381BCC | 0x00381BD3 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x00381BD4 | 0x00381BD7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x00381BD8 | 0x00381BDF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x00381BE0 | 0x00381BE3 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x00381BE4 | 0x00381BE7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x00381BE8 | 0x00381BEB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x00381BEC | 0x00381BF3 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x00381BF4 | 0x00381BF7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x00381BF8 | 0x00381BFF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x00381C00 | 0x00381C03 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x00381C04 | 0x00381C07 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x00381C08 | 0x00381C0F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x00381C10 | 0x00381C13 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x00381C14 | 0x00381C17 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C0400 | 0x003C41FF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C0178 | 0x003C017F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C01A0 | 0x003C01A7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C01C8 | 0x003C01CF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C01F0 | 0x003C01F7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C0218 | 0x003C021F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C459E | 0x003C45A8 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C4592 | 0x003C459C | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C4200 | 0x003C4247 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C45AC | 0x003C45AF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C45D0 | 0x003C45D7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C45D8 | 0x003C45DB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C45DC | 0x003C45E3 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C45E4 | 0x003C45E7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C45E8 | 0x003C45EB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C45EC | 0x003C45EF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C45F0 | 0x003C45F7 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C45F8 | 0x003C45FB | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C45FC | 0x003C45FF | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C4600 | 0x003C4607 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C4608 | 0x003C460B | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C460C | 0x003C460F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C4610 | 0x003C4617 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C4618 | 0x003C461B | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C461C | 0x003C461F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C4620 | 0x003C4627 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C4628 | 0x003C462B | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C462C | 0x003C462F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C4630 | 0x003C4633 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C4634 | 0x003C463B | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C463C | 0x003C463F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C4640 | 0x003C4643 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C4644 | 0x003C464B | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C464C | 0x003C464F | Marked Executable | 32-bit | - |
...
|
|||
buffer | 1 | 0x003C4650 | 0x003C4653 | Marked Executable | 32-bit | - |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | First Execution | 32-bit | 0x004E1001 |
...
|
|||
occt.exe | 2 | 0x008F0000 | 0x009A9FFF | Relevant Image | 32-bit | - |
...
|
|||
buffer | 1 | 0x04D81000 | 0x04D81FFF | Marked Executable | 32-bit | - |
...
|
|||
occt.exe | 1 | 0x008F0000 | 0x009A9FFF | Process Termination | 32-bit | - |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | - |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | - |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0044FA6C |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00473155 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x004529A6 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0042B170 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0045F729 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x004620CC |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0046D0B1 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x004632FE |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0046BC2E |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00451940 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00455BC8 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0042AED0 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0046894E |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0046E65D |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0043B4FC |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0044E98C |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x004696C6 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x004723A4 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0042C490 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00430F60 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00428CE0 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00429030 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00460432 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00457211 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00401000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00402000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00403000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00404000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00405000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00406000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00407000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00408000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00409000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0040A000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0040B000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0040C000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00412000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00413000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00414000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00415000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00416000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00470054 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00465014 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0042EFD0 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00417000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00418000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00419000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0041A000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0041B000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0041C000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0041D000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0041E000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0041F000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00420000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00421000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00433D00 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00422000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00423000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00424000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00425000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00431000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0043A089 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x00439FE4 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0045AF26 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0043817C |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0044AE25 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x004402E6 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0045DF91 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0043D8B3 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0044664C |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0042F000 |
...
|
|||
occt.exe | 2 | 0x008F0000 | 0x009A9FFF | Final Dump | 32-bit | - |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0042B170 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0046CEEC |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0046D0B1 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0046B9B9 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0042CE90 |
...
|
|||
buffer | 2 | 0x00400000 | 0x004E3FFF | Content Changed | 32-bit | 0x0044F45F |
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming//KEY.FILE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\cs-CZ\bootmgr.exe.mui.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\da-DK\bootmgr.exe.mui.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\de-DE\bootmgr.exe.mui.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\en-US\bootmgr.exe.mui.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\el-GR\bootmgr.exe.mui.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\en-US\memtest.exe.mui.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\es-ES\bootmgr.exe.mui.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\fi-FI\bootmgr.exe.mui.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\fr-FR\bootmgr.exe.mui.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\Fonts\chs_boot.ttf.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\hu-HU\bootmgr.exe.mui.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\it-IT\bootmgr.exe.mui.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\Fonts\cht_boot.ttf.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\ja-JP\bootmgr.exe.mui.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\Fonts\jpn_boot.ttf.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\ko-KR\bootmgr.exe.mui.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\Fonts\kor_boot.ttf.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\Fonts\wgl4_boot.ttf.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\nl-NL\bootmgr.exe.mui.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\nb-NO\bootmgr.exe.mui.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\pt-BR\bootmgr.exe.mui.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\pl-PL\bootmgr.exe.mui.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\pt-PT\bootmgr.exe.mui.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\ru-RU\bootmgr.exe.mui.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\tr-TR\bootmgr.exe.mui.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\sv-SE\bootmgr.exe.mui.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\zh-HK\bootmgr.exe.mui.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\zh-CN\bootmgr.exe.mui.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\zh-TW\bootmgr.exe.mui.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Mozilla Firefox\precomplete.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Mozilla Firefox\removed-files.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\boot.sdi.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT.LOG.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT.LOG1.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows\Panther\setupinfo.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\Winre.wim.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\OWOW32LR.cab.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.msi.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.msi.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\OpenTheTorBrouser.html | Dropped File | Text |
Unknown
|
...
|
»
Embedded URLs (1)
»
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data | Actions |
---|---|---|---|---|---|---|
http://vy2hwfycbtogtmxlz3cfdvjk5jai6rlxzz2dseegeuckqmjgia6vxhyd.onion/index.php | - | - | - |
Unknown
|
Not Queried
|
...
|
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfLR.cab.mijnal | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjLR.cab.mijnal | Dropped File | Stream |
Unknown
|
...
|
»