VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Wiper, Dropper, Trojan |
rsdf54refsd.exe
Windows Exe (x86-32)
Created at 2019-10-13T12:55:00
Remarks
(0x200001e): The maximum size of extracted files was exceeded. Some files may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\rsdf54refsd.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-10-13 08:44 (UTC+2) |
Last Seen | 2019-10-13 09:14 (UTC+2) |
Names | Win32.Trojan.Agen |
Families | Agen |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4100d1 |
Size Of Code | 0x3e200 |
Size Of Initialized Data | 0xf200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-10-13 04:39:06+00:00 |
Version Information (8)
»
CompanyName | land-born |
FileDescription | Esthacyte |
FileVersion | 4.3.3.6 |
InternalName | semimonthly.exe |
LegalCopyright | Copyright (C) decalvation 2019 |
OriginalFilename | portholes.exe |
ProductName | tonsillectomic |
ProductVersion | 0.0.8.2 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x3e047 | 0x3e200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.45 |
.rdata | 0x440000 | 0x87f0 | 0x8800 | 0x3e600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.17 |
.data | 0x449000 | 0x1dfc | 0xc00 | 0x46e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.02 |
.gfids | 0x44b000 | 0x16c | 0x200 | 0x47a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.49 |
.rsrc | 0x44c000 | 0x29f8 | 0x2a00 | 0x47c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.72 |
.reloc | 0x44f000 | 0x1ed4 | 0x2000 | 0x4a600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.59 |
Imports (4)
»
MSWSOCK.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetServiceA | 0x0 | 0x4401c4 | 0x47ec4 | 0x464c4 | 0x11 |
GetAddressByNameA | 0x0 | 0x4401c8 | 0x47ec8 | 0x464c8 | 0x4 |
rcmd | 0x0 | 0x4401cc | 0x47ecc | 0x464cc | 0x3a |
NPLoadNameSpaces | 0x0 | 0x4401d0 | 0x47ed0 | 0x464d0 | 0xf |
EnumProtocolsW | 0x0 | 0x4401d4 | 0x47ed4 | 0x464d4 | 0x2 |
inet_network | 0x0 | 0x4401d8 | 0x47ed8 | 0x464d8 | 0x39 |
WSARecvEx | 0x0 | 0x4401dc | 0x47edc | 0x464dc | 0x35 |
s_perror | 0x0 | 0x4401e0 | 0x47ee0 | 0x464e0 | 0x3d |
MPR.dll (15)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetGetUniversalNameA | 0x0 | 0x440184 | 0x47e84 | 0x46484 | 0x3e |
WNetDisconnectDialog1W | 0x0 | 0x440188 | 0x47e88 | 0x46488 | 0x20 |
WNetConnectionDialog1W | 0x0 | 0x44018c | 0x47e8c | 0x4648c | 0x1a |
WNetCancelConnectionW | 0x0 | 0x440190 | 0x47e90 | 0x46490 | 0x15 |
WNetCloseEnum | 0x0 | 0x440194 | 0x47e94 | 0x46494 | 0x17 |
WNetGetLastErrorW | 0x0 | 0x440198 | 0x47e98 | 0x46498 | 0x30 |
WNetGetNetworkInformationW | 0x0 | 0x44019c | 0x47e9c | 0x4649c | 0x32 |
WNetGetConnectionA | 0x0 | 0x4401a0 | 0x47ea0 | 0x464a0 | 0x2a |
WNetGetProviderNameA | 0x0 | 0x4401a4 | 0x47ea4 | 0x464a4 | 0x35 |
WNetAddConnection3A | 0x0 | 0x4401a8 | 0x47ea8 | 0x464a8 | 0xe |
WNetEnumResourceA | 0x0 | 0x4401ac | 0x47eac | 0x464ac | 0x22 |
WNetUseConnectionW | 0x0 | 0x4401b0 | 0x47eb0 | 0x464b0 | 0x50 |
WNetGetNetworkInformationA | 0x0 | 0x4401b4 | 0x47eb4 | 0x464b4 | 0x31 |
MultinetGetConnectionPerformanceA | 0x0 | 0x4401b8 | 0x47eb8 | 0x464b8 | 0x5 |
WNetGetProviderNameW | 0x0 | 0x4401bc | 0x47ebc | 0x464bc | 0x36 |
COMDLG32.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PrintDlgExW | 0x0 | 0x440000 | 0x47d00 | 0x46300 | 0x14 |
GetFileTitleW | 0x0 | 0x440004 | 0x47d04 | 0x46304 | 0xa |
GetFileTitleA | 0x0 | 0x440008 | 0x47d08 | 0x46308 | 0x9 |
GetOpenFileNameA | 0x0 | 0x44000c | 0x47d0c | 0x4630c | 0xb |
ReplaceTextA | 0x0 | 0x440010 | 0x47d10 | 0x46310 | 0x16 |
GetOpenFileNameW | 0x0 | 0x440014 | 0x47d14 | 0x46314 | 0xc |
FindTextA | 0x0 | 0x440018 | 0x47d18 | 0x46318 | 0x7 |
ReplaceTextW | 0x0 | 0x44001c | 0x47d1c | 0x4631c | 0x17 |
GetSaveFileNameA | 0x0 | 0x440020 | 0x47d20 | 0x46320 | 0xd |
ChooseFontW | 0x0 | 0x440024 | 0x47d24 | 0x46324 | 0x3 |
ChooseColorW | 0x0 | 0x440028 | 0x47d28 | 0x46328 | 0x1 |
KERNEL32.dll (84)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetConsoleCtrlHandler | 0x0 | 0x440030 | 0x47d30 | 0x46330 | 0x4cd |
GetProcessHeap | 0x0 | 0x440034 | 0x47d34 | 0x46334 | 0x2a4 |
GetStringTypeW | 0x0 | 0x440038 | 0x47d38 | 0x46338 | 0x2c7 |
GetFileType | 0x0 | 0x44003c | 0x47d3c | 0x4633c | 0x23f |
SetStdHandle | 0x0 | 0x440040 | 0x47d40 | 0x46340 | 0x52e |
EnumSystemLocalesW | 0x0 | 0x440044 | 0x47d44 | 0x46344 | 0x147 |
HeapSize | 0x0 | 0x440048 | 0x47d48 | 0x46348 | 0x33c |
IsValidLocale | 0x0 | 0x44004c | 0x47d4c | 0x4634c | 0x378 |
GetLocaleInfoW | 0x0 | 0x440050 | 0x47d50 | 0x46350 | 0x255 |
LCMapStringW | 0x0 | 0x440054 | 0x47d54 | 0x46354 | 0x39a |
CompareStringW | 0x0 | 0x440058 | 0x47d58 | 0x46358 | 0x91 |
GetTimeFormatW | 0x0 | 0x44005c | 0x47d5c | 0x4635c | 0x2fb |
GetDateFormatW | 0x0 | 0x440060 | 0x47d60 | 0x46360 | 0x214 |
HeapReAlloc | 0x0 | 0x440064 | 0x47d64 | 0x46364 | 0x33a |
FlushFileBuffers | 0x0 | 0x440068 | 0x47d68 | 0x46368 | 0x192 |
GetConsoleCP | 0x0 | 0x44006c | 0x47d6c | 0x4636c | 0x1dd |
GetConsoleMode | 0x0 | 0x440070 | 0x47d70 | 0x46370 | 0x1ef |
SetFilePointerEx | 0x0 | 0x440074 | 0x47d74 | 0x46374 | 0x507 |
WriteConsoleW | 0x0 | 0x440078 | 0x47d78 | 0x46378 | 0x5f0 |
EncodePointer | 0x0 | 0x44007c | 0x47d7c | 0x4637c | 0x121 |
DecodePointer | 0x0 | 0x440080 | 0x47d80 | 0x46380 | 0xfd |
CreateFileW | 0x0 | 0x440084 | 0x47d84 | 0x46384 | 0xc0 |
RaiseException | 0x0 | 0x440088 | 0x47d88 | 0x46388 | 0x448 |
GetUserDefaultLCID | 0x0 | 0x44008c | 0x47d8c | 0x4638c | 0x300 |
TlsSetValue | 0x0 | 0x440090 | 0x47d90 | 0x46390 | 0x583 |
QueryPerformanceCounter | 0x0 | 0x440094 | 0x47d94 | 0x46394 | 0x433 |
GetCurrentProcessId | 0x0 | 0x440098 | 0x47d98 | 0x46398 | 0x20b |
GetCurrentThreadId | 0x0 | 0x44009c | 0x47d9c | 0x4639c | 0x20f |
GetSystemTimeAsFileTime | 0x0 | 0x4400a0 | 0x47da0 | 0x463a0 | 0x2d9 |
InitializeSListHead | 0x0 | 0x4400a4 | 0x47da4 | 0x463a4 | 0x34f |
IsDebuggerPresent | 0x0 | 0x4400a8 | 0x47da8 | 0x463a8 | 0x36b |
UnhandledExceptionFilter | 0x0 | 0x4400ac | 0x47dac | 0x463ac | 0x58f |
SetUnhandledExceptionFilter | 0x0 | 0x4400b0 | 0x47db0 | 0x463b0 | 0x550 |
GetStartupInfoW | 0x0 | 0x4400b4 | 0x47db4 | 0x463b4 | 0x2c0 |
IsProcessorFeaturePresent | 0x0 | 0x4400b8 | 0x47db8 | 0x463b8 | 0x371 |
GetModuleHandleW | 0x0 | 0x4400bc | 0x47dbc | 0x463bc | 0x268 |
GetCurrentProcess | 0x0 | 0x4400c0 | 0x47dc0 | 0x463c0 | 0x20a |
TerminateProcess | 0x0 | 0x4400c4 | 0x47dc4 | 0x463c4 | 0x56e |
InterlockedPushEntrySList | 0x0 | 0x4400c8 | 0x47dc8 | 0x463c8 | 0x35b |
InterlockedFlushSList | 0x0 | 0x4400cc | 0x47dcc | 0x463cc | 0x358 |
RtlUnwind | 0x0 | 0x4400d0 | 0x47dd0 | 0x463d0 | 0x4b7 |
GetLastError | 0x0 | 0x4400d4 | 0x47dd4 | 0x463d4 | 0x251 |
SetLastError | 0x0 | 0x4400d8 | 0x47dd8 | 0x463d8 | 0x516 |
EnterCriticalSection | 0x0 | 0x4400dc | 0x47ddc | 0x463dc | 0x125 |
LeaveCriticalSection | 0x0 | 0x4400e0 | 0x47de0 | 0x463e0 | 0x3a6 |
DeleteCriticalSection | 0x0 | 0x4400e4 | 0x47de4 | 0x463e4 | 0x104 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4400e8 | 0x47de8 | 0x463e8 | 0x34c |
TlsAlloc | 0x0 | 0x4400ec | 0x47dec | 0x463ec | 0x580 |
TlsGetValue | 0x0 | 0x4400f0 | 0x47df0 | 0x463f0 | 0x582 |
TlsFree | 0x0 | 0x4400f4 | 0x47df4 | 0x463f4 | 0x581 |
FreeLibrary | 0x0 | 0x4400f8 | 0x47df8 | 0x463f8 | 0x19e |
GetProcAddress | 0x0 | 0x4400fc | 0x47dfc | 0x463fc | 0x29e |
LoadLibraryExW | 0x0 | 0x440100 | 0x47e00 | 0x46400 | 0x3ab |
GetStdHandle | 0x0 | 0x440104 | 0x47e04 | 0x46404 | 0x2c2 |
WriteFile | 0x0 | 0x440108 | 0x47e08 | 0x46408 | 0x5f1 |
GetModuleFileNameW | 0x0 | 0x44010c | 0x47e0c | 0x4640c | 0x264 |
GetModuleFileNameA | 0x0 | 0x440110 | 0x47e10 | 0x46410 | 0x263 |
MultiByteToWideChar | 0x0 | 0x440114 | 0x47e14 | 0x46414 | 0x3d5 |
WideCharToMultiByte | 0x0 | 0x440118 | 0x47e18 | 0x46418 | 0x5dd |
ExitProcess | 0x0 | 0x44011c | 0x47e1c | 0x4641c | 0x151 |
GetModuleHandleExW | 0x0 | 0x440120 | 0x47e20 | 0x46420 | 0x267 |
GetACP | 0x0 | 0x440124 | 0x47e24 | 0x46424 | 0x1a5 |
HeapFree | 0x0 | 0x440128 | 0x47e28 | 0x46428 | 0x337 |
HeapAlloc | 0x0 | 0x44012c | 0x47e2c | 0x4642c | 0x333 |
GetCurrentThread | 0x0 | 0x440130 | 0x47e30 | 0x46430 | 0x20e |
OutputDebugStringA | 0x0 | 0x440134 | 0x47e34 | 0x46434 | 0x3fe |
OutputDebugStringW | 0x0 | 0x440138 | 0x47e38 | 0x46438 | 0x3ff |
CloseHandle | 0x0 | 0x44013c | 0x47e3c | 0x4643c | 0x7d |
WaitForSingleObjectEx | 0x0 | 0x440140 | 0x47e40 | 0x46440 | 0x5ba |
CreateThread | 0x0 | 0x440144 | 0x47e44 | 0x46444 | 0xe7 |
FindClose | 0x0 | 0x440148 | 0x47e48 | 0x46448 | 0x168 |
FindFirstFileExA | 0x0 | 0x44014c | 0x47e4c | 0x4644c | 0x16d |
FindFirstFileExW | 0x0 | 0x440150 | 0x47e50 | 0x46450 | 0x16e |
FindNextFileA | 0x0 | 0x440154 | 0x47e54 | 0x46454 | 0x17d |
FindNextFileW | 0x0 | 0x440158 | 0x47e58 | 0x46458 | 0x17f |
IsValidCodePage | 0x0 | 0x44015c | 0x47e5c | 0x4645c | 0x376 |
GetOEMCP | 0x0 | 0x440160 | 0x47e60 | 0x46460 | 0x287 |
GetCPInfo | 0x0 | 0x440164 | 0x47e64 | 0x46464 | 0x1b4 |
GetCommandLineA | 0x0 | 0x440168 | 0x47e68 | 0x46468 | 0x1c9 |
GetCommandLineW | 0x0 | 0x44016c | 0x47e6c | 0x4646c | 0x1ca |
GetEnvironmentStringsW | 0x0 | 0x440170 | 0x47e70 | 0x46470 | 0x228 |
FreeEnvironmentStringsW | 0x0 | 0x440174 | 0x47e74 | 0x46474 | 0x19d |
SetEnvironmentVariableA | 0x0 | 0x440178 | 0x47e78 | 0x46478 | 0x4f7 |
SetEnvironmentVariableW | 0x0 | 0x44017c | 0x47e7c | 0x4647c | 0x4f8 |
Memory Dumps (195)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
rsdf54refsd.exe | 1 | 0x01060000 | 0x010B0FFF | Relevant Image | - | 32-bit | - |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x001B0000 | 0x001B0FFF | First Execution | - | 32-bit | 0x001B0004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
buffer | 1 | 0x00230000 | 0x00230FFF | First Execution | - | 32-bit | 0x00230004 |
...
|
||
rsdf54refsd.exe | 1 | 0x01060000 | 0x010B0FFF | Process Termination | - | 32-bit | - |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.41894282 |
Malicious
|
\\?\C:\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000\desktop.ini | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-12-31 19:53 (UTC+1) |
Last Seen | 2019-09-25 13:56 (UTC+2) |
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2011-06-03 15:16 (UTC+2) |
Last Seen | 2019-10-08 16:44 (UTC+2) |
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2011-06-08 00:23 (UTC+2) |
Last Seen | 2019-07-20 20:57 (UTC+2) |
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2014-11-13 12:24 (UTC+1) |
Last Seen | 2019-07-15 13:30 (UTC+2) |
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-06-12 00:42 (UTC+2) |
Last Seen | 2019-07-15 13:30 (UTC+2) |
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2016-07-07 21:40 (UTC+2) |
Last Seen | 2019-01-13 19:08 (UTC+1) |
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2012-10-11 18:42 (UTC+2) |
Last Seen | 2019-07-15 13:28 (UTC+2) |
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-06-12 00:42 (UTC+2) |
Last Seen | 2018-04-05 13:40 (UTC+2) |
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2016-07-08 05:45 (UTC+2) |
Last Seen | 2019-07-15 13:29 (UTC+2) |
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-04-28 00:00 (UTC+2) |
Last Seen | 2018-11-26 18:28 (UTC+1) |
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2015-11-04 08:44 (UTC+1) |
Last Seen | 2019-10-10 01:58 (UTC+2) |
\\?\C:\Program Files\Microsoft Office\Office14\1033\DBSAMPLE.MDB | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2011-06-12 17:25 (UTC+2) |
Last Seen | 2019-07-14 22:58 (UTC+2) |
\\?\C:\Program Files\Microsoft Office\Office14\ACCWIZ\ACWZLIB.ACCDE | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-03-20 15:45 (UTC+1) |
Last Seen | 2018-12-01 17:29 (UTC+1) |
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-03-17 16:07 (UTC+1) |
Last Seen | 2019-07-15 13:30 (UTC+2) |
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-03-20 15:45 (UTC+1) |
Last Seen | 2017-05-24 05:32 (UTC+2) |
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2015-06-10 09:24 (UTC+2) |
Last Seen | 2019-07-15 13:30 (UTC+2) |
\\?\C:\Program Files\Microsoft Office\Office14\ACCWIZ\ACWZMAIN.ACCDE | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2015-10-01 16:30 (UTC+2) |
Last Seen | 2017-04-15 20:52 (UTC+2) |
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-03-20 15:45 (UTC+1) |
Last Seen | 2019-05-17 04:09 (UTC+2) |
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2014-11-13 12:17 (UTC+1) |
Last Seen | 2019-07-15 13:28 (UTC+2) |
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\start menu\programs\startup\svchost.exe | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2011-06-22 09:04 (UTC+2) |
Last Seen | 2019-09-05 17:08 (UTC+2) |
PE Information
»
Image Base | 0x1000000 |
Entry Point | 0x1002104 |
Size Of Code | 0x3a00 |
Size Of Initialized Data | 0x1400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2009-07-13 23:19:28+00:00 |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | Host Process for Windows Services |
FileVersion | 6.1.7600.16385 (win7_rtm.090713-1255) |
InternalName | svchost.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | svchost.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 6.1.7600.16385 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x1001000 | 0x39dc | 0x3a00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.29 |
.data | 0x1005000 | 0x5a8 | 0x600 | 0x3e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.81 |
.rsrc | 0x1006000 | 0x810 | 0xa00 | 0x4400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.76 |
.reloc | 0x1007000 | 0x3cc | 0x400 | 0x4e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.4 |
Imports (8)
»
msvcrt.dll (15)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
__wgetmainargs | 0x0 | 0x1001000 | 0x4014 | 0x3414 | 0xe1 |
_exit | 0x0 | 0x1001004 | 0x4018 | 0x3418 | 0x162 |
_XcptFilter | 0x0 | 0x1001008 | 0x401c | 0x341c | 0x6a |
exit | 0x0 | 0x100100c | 0x4020 | 0x3420 | 0x48f |
_initterm | 0x0 | 0x1001010 | 0x4024 | 0x3424 | 0x1d5 |
_amsg_exit | 0x0 | 0x1001014 | 0x4028 | 0x3428 | 0x101 |
__setusermatherr | 0x0 | 0x1001018 | 0x402c | 0x342c | 0xd4 |
memcpy | 0x0 | 0x100101c | 0x4030 | 0x3430 | 0x4ea |
_controlfp | 0x0 | 0x1001020 | 0x4034 | 0x3434 | 0x127 |
_except_handler4_common | 0x0 | 0x1001024 | 0x4038 | 0x3438 | 0x159 |
?terminate@@YAXXZ | 0x0 | 0x1001028 | 0x403c | 0x343c | 0x37 |
__set_app_type | 0x0 | 0x100102c | 0x4040 | 0x3440 | 0xd2 |
__p__fmode | 0x0 | 0x1001030 | 0x4044 | 0x3444 | 0xbe |
__p__commode | 0x0 | 0x1001034 | 0x4048 | 0x3448 | 0xb9 |
_cexit | 0x0 | 0x1001038 | 0x404c | 0x344c | 0x114 |
API-MS-Win-Core-ProcessThreads-L1-1-0.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
TerminateProcess | 0x0 | 0x1001040 | 0x4054 | 0x3454 | 0x2a |
GetCurrentProcess | 0x0 | 0x1001044 | 0x4058 | 0x3458 | 0xa |
OpenProcessToken | 0x0 | 0x1001048 | 0x405c | 0x345c | 0x1a |
GetCurrentProcessId | 0x0 | 0x100104c | 0x4060 | 0x3460 | 0xb |
GetCurrentThreadId | 0x0 | 0x1001050 | 0x4064 | 0x3464 | 0xd |
KERNEL32.dll (44)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LocalAlloc | 0x0 | 0x1001058 | 0x406c | 0x346c | 0x343 |
CloseHandle | 0x0 | 0x100105c | 0x4070 | 0x3470 | 0x52 |
DelayLoadFailureHook | 0x0 | 0x1001060 | 0x4074 | 0x3474 | 0xcd |
GetProcAddress | 0x0 | 0x1001064 | 0x4078 | 0x3478 | 0x244 |
GetLastError | 0x0 | 0x1001068 | 0x407c | 0x347c | 0x201 |
FreeLibrary | 0x0 | 0x100106c | 0x4080 | 0x3480 | 0x161 |
InterlockedCompareExchange | 0x0 | 0x1001070 | 0x4084 | 0x3484 | 0x2e8 |
LoadLibraryExA | 0x0 | 0x1001074 | 0x4088 | 0x3488 | 0x33c |
InterlockedExchange | 0x0 | 0x1001078 | 0x408c | 0x348c | 0x2eb |
Sleep | 0x0 | 0x100107c | 0x4090 | 0x3490 | 0x4ae |
SetUnhandledExceptionFilter | 0x0 | 0x1001080 | 0x4094 | 0x3494 | 0x4a1 |
GetModuleHandleA | 0x0 | 0x1001084 | 0x4098 | 0x3498 | 0x214 |
QueryPerformanceCounter | 0x0 | 0x1001088 | 0x409c | 0x349c | 0x3a4 |
GetTickCount | 0x0 | 0x100108c | 0x40a0 | 0x34a0 | 0x292 |
GetSystemTimeAsFileTime | 0x0 | 0x1001090 | 0x40a4 | 0x34a4 | 0x278 |
UnhandledExceptionFilter | 0x0 | 0x1001094 | 0x40a8 | 0x34a8 | 0x4cf |
DeactivateActCtx | 0x0 | 0x1001098 | 0x40ac | 0x34ac | 0xc3 |
LoadLibraryExW | 0x0 | 0x100109c | 0x40b0 | 0x34b0 | 0x33d |
ActivateActCtx | 0x0 | 0x10010a0 | 0x40b4 | 0x34b4 | 0x2 |
LeaveCriticalSection | 0x0 | 0x10010a4 | 0x40b8 | 0x34b8 | 0x338 |
lstrcmpW | 0x0 | 0x10010a8 | 0x40bc | 0x34bc | 0x53e |
EnterCriticalSection | 0x0 | 0x10010ac | 0x40c0 | 0x34c0 | 0xed |
RegCloseKey | 0x0 | 0x10010b0 | 0x40c4 | 0x34c4 | 0x3c2 |
RegOpenKeyExW | 0x0 | 0x10010b4 | 0x40c8 | 0x34c8 | 0x3dd |
HeapSetInformation | 0x0 | 0x10010b8 | 0x40cc | 0x34cc | 0x2d2 |
lstrcmpiW | 0x0 | 0x10010bc | 0x40d0 | 0x34d0 | 0x541 |
lstrlenW | 0x0 | 0x10010c0 | 0x40d4 | 0x34d4 | 0x54a |
LCMapStringW | 0x0 | 0x10010c4 | 0x40d8 | 0x34d8 | 0x32c |
RegQueryValueExW | 0x0 | 0x10010c8 | 0x40dc | 0x34dc | 0x3e2 |
ReleaseActCtx | 0x0 | 0x10010cc | 0x40e0 | 0x34e0 | 0x3f6 |
CreateActCtxW | 0x0 | 0x10010d0 | 0x40e4 | 0x34e4 | 0x78 |
ExpandEnvironmentStringsW | 0x0 | 0x10010d4 | 0x40e8 | 0x34e8 | 0x11c |
GetCommandLineW | 0x0 | 0x10010d8 | 0x40ec | 0x34ec | 0x186 |
ExitProcess | 0x0 | 0x10010dc | 0x40f0 | 0x34f0 | 0x118 |
SetProcessAffinityUpdateMode | 0x0 | 0x10010e0 | 0x40f4 | 0x34f4 | 0x47c |
RegDisablePredefinedCacheEx | 0x0 | 0x10010e4 | 0x40f8 | 0x34f8 | 0x3cb |
InitializeCriticalSection | 0x0 | 0x10010e8 | 0x40fc | 0x34fc | 0x2e1 |
GetProcessHeap | 0x0 | 0x10010ec | 0x4100 | 0x3500 | 0x249 |
SetErrorMode | 0x0 | 0x10010f0 | 0x4104 | 0x3504 | 0x455 |
RegisterWaitForSingleObjectEx | 0x0 | 0x10010f4 | 0x4108 | 0x3508 | 0x3f3 |
LocalFree | 0x0 | 0x10010f8 | 0x410c | 0x350c | 0x347 |
HeapFree | 0x0 | 0x10010fc | 0x4110 | 0x3510 | 0x2ce |
WideCharToMultiByte | 0x0 | 0x1001100 | 0x4114 | 0x3514 | 0x50d |
HeapAlloc | 0x0 | 0x1001104 | 0x4118 | 0x3518 | 0x2ca |
ntdll.dll (14)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RtlAllocateHeap | 0x0 | 0x100110c | 0x4120 | 0x3520 | 0x263 |
RtlLengthRequiredSid | 0x0 | 0x1001110 | 0x4124 | 0x3524 | 0x3ec |
RtlSubAuthoritySid | 0x0 | 0x1001114 | 0x4128 | 0x3528 | 0x4a5 |
RtlInitializeSid | 0x0 | 0x1001118 | 0x412c | 0x352c | 0x3af |
RtlCopySid | 0x0 | 0x100111c | 0x4130 | 0x3530 | 0x2a5 |
RtlSubAuthorityCountSid | 0x0 | 0x1001120 | 0x4134 | 0x3534 | 0x4a4 |
RtlInitializeCriticalSection | 0x0 | 0x1001124 | 0x4138 | 0x3538 | 0x3a2 |
RtlSetProcessIsCritical | 0x0 | 0x1001128 | 0x413c | 0x353c | 0x489 |
RtlImageNtHeader | 0x0 | 0x100112c | 0x4140 | 0x3540 | 0x38c |
RtlUnhandledExceptionFilter | 0x0 | 0x1001130 | 0x4144 | 0x3544 | 0x4be |
EtwEventWrite | 0x0 | 0x1001134 | 0x4148 | 0x3548 | 0x39 |
EtwEventEnabled | 0x0 | 0x1001138 | 0x414c | 0x354c | 0x35 |
EtwEventRegister | 0x0 | 0x100113c | 0x4150 | 0x3550 | 0x37 |
RtlFreeHeap | 0x0 | 0x1001140 | 0x4154 | 0x3554 | 0x347 |
API-MS-Win-Security-Base-L1-1-0.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetSecurityDescriptorDacl | 0x0 | 0x1001148 | 0x415c | 0x355c | 0x5b |
AddAccessAllowedAce | 0x0 | 0x100114c | 0x4160 | 0x3560 | 0x7 |
SetSecurityDescriptorOwner | 0x0 | 0x1001150 | 0x4164 | 0x3564 | 0x5d |
SetSecurityDescriptorGroup | 0x0 | 0x1001154 | 0x4168 | 0x3568 | 0x5c |
GetTokenInformation | 0x0 | 0x1001158 | 0x416c | 0x356c | 0x3a |
InitializeSecurityDescriptor | 0x0 | 0x100115c | 0x4170 | 0x3570 | 0x40 |
GetLengthSid | 0x0 | 0x1001160 | 0x4174 | 0x3574 | 0x2d |
InitializeAcl | 0x0 | 0x1001164 | 0x4178 | 0x3578 | 0x3f |
API-MS-WIN-Service-Core-L1-1-0.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StartServiceCtrlDispatcherW | 0x0 | 0x100116c | 0x4180 | 0x3580 | 0x2 |
SetServiceStatus | 0x0 | 0x1001170 | 0x4184 | 0x3584 | 0x1 |
API-MS-WIN-Service-winsvc-L1-1-0.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegisterServiceCtrlHandlerW | 0x0 | 0x1001178 | 0x418c | 0x358c | 0x17 |
RPCRT4.dll (9)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RpcMgmtSetServerStackSize | 0x0 | 0x1001180 | 0x4194 | 0x3594 | 0x1a0 |
I_RpcMapWin32Status | 0x0 | 0x1001184 | 0x4198 | 0x3598 | 0x3e |
RpcServerUnregisterIf | 0x0 | 0x1001188 | 0x419c | 0x359c | 0x1c2 |
RpcMgmtWaitServerListen | 0x0 | 0x100118c | 0x41a0 | 0x35a0 | 0x1a3 |
RpcMgmtStopServerListening | 0x0 | 0x1001190 | 0x41a4 | 0x35a4 | 0x1a2 |
RpcServerUnregisterIfEx | 0x0 | 0x1001194 | 0x41a8 | 0x35a8 | 0x1c3 |
RpcServerRegisterIf | 0x0 | 0x1001198 | 0x41ac | 0x35ac | 0x1bd |
RpcServerUseProtseqEpW | 0x0 | 0x100119c | 0x41b0 | 0x35b0 | 0x1cd |
RpcServerListen | 0x0 | 0x10011a0 | 0x41b4 | 0x35b4 | 0x1ba |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
svchost.exe | 28 | 0x00650000 | 0x00657FFF | Relevant Image | - | 32-bit | - |
...
|
||
svchost.exe | 28 | 0x00650000 | 0x00657FFF | Process Termination | - | 32-bit | - |
...
|
\\?\C:\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000\desktop.ini.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\BOOTSECT.BAK.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\BOOTSTAT.DAT.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Microsoft Office\Office14\1033\DBSAMPLE.MDB.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Microsoft Office\Office14\ACCWIZ\ACWZLIB.ACCDE.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.cab.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.id[9C354B42-2275].[checkcheck07@qq.com].Adame | Dropped File | Stream |
Unknown
|
...
|
»