Malicious
Classifications
Ransomware
Threat Names
Mal/Generic-S Gen:Variant.Graftor.952042 Gen:Variant.Bulz.471680
Dynamic Analysis Report
Created on 2021-07-02T19:12:00
urnxby.exe
Windows Exe (x86-32)
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "3 hours, 2 minutes, 26 seconds" to "10 seconds" to reveal dormant functionality.
Remarks
(0x0200001B): The maximum number of file Reputation Analysis requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\RDhJ0CNFevzX\Desktop\urnxby.exe | Sample File | Binary |
malicious
|
...
|
»
File Reputation Information
»
Verdict |
malicious
|
Names | Mal/Generic-S |
AV Matches (1)
»
Threat Name | Verdict |
---|---|
Gen:Variant.Graftor.952042 |
malicious
|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4013ef |
Size Of Code | 0xb200 |
Size Of Initialized Data | 0xd2c00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2021-07-01 12:40:29+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xb072 | 0xb200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x40d000 | 0x59f0 | 0x5a00 | 0xb600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.86 |
.data | 0x413000 | 0x1410 | 0xa00 | 0x11000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.81 |
.rsrc | 0x415000 | 0xcab18 | 0xcac00 | 0x11a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.99 |
.reloc | 0x4e0000 | 0xe04 | 0x1000 | 0xdc600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.12 |
Imports (1)
»
KERNEL32.dll (71)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WriteFile | - | 0x40d000 | 0x123c4 | 0x109c4 | 0x612 |
VirtualAlloc | - | 0x40d004 | 0x123c8 | 0x109c8 | 0x5c6 |
GetTempPathW | - | 0x40d008 | 0x123cc | 0x109cc | 0x2f6 |
CreateFileW | - | 0x40d00c | 0x123d0 | 0x109d0 | 0xcb |
Sleep | - | 0x40d010 | 0x123d4 | 0x109d4 | 0x57d |
lstrcatW | - | 0x40d014 | 0x123d8 | 0x109d8 | 0x62d |
LockResource | - | 0x40d018 | 0x123dc | 0x109dc | 0x3db |
CloseHandle | - | 0x40d01c | 0x123e0 | 0x109e0 | 0x86 |
LoadResource | - | 0x40d020 | 0x123e4 | 0x109e4 | 0x3c7 |
FindResourceW | - | 0x40d024 | 0x123e8 | 0x109e8 | 0x196 |
CreateProcessW | - | 0x40d028 | 0x123ec | 0x109ec | 0xe5 |
WriteConsoleW | - | 0x40d02c | 0x123f0 | 0x109f0 | 0x611 |
QueryPerformanceCounter | - | 0x40d030 | 0x123f4 | 0x109f4 | 0x44d |
GetCurrentProcessId | - | 0x40d034 | 0x123f8 | 0x109f8 | 0x218 |
GetCurrentThreadId | - | 0x40d038 | 0x123fc | 0x109fc | 0x21c |
GetSystemTimeAsFileTime | - | 0x40d03c | 0x12400 | 0x10a00 | 0x2e9 |
InitializeSListHead | - | 0x40d040 | 0x12404 | 0x10a04 | 0x363 |
IsDebuggerPresent | - | 0x40d044 | 0x12408 | 0x10a08 | 0x37f |
UnhandledExceptionFilter | - | 0x40d048 | 0x1240c | 0x10a0c | 0x5ad |
SetUnhandledExceptionFilter | - | 0x40d04c | 0x12410 | 0x10a10 | 0x56d |
GetStartupInfoW | - | 0x40d050 | 0x12414 | 0x10a14 | 0x2d0 |
IsProcessorFeaturePresent | - | 0x40d054 | 0x12418 | 0x10a18 | 0x386 |
GetModuleHandleW | - | 0x40d058 | 0x1241c | 0x10a1c | 0x278 |
GetCurrentProcess | - | 0x40d05c | 0x12420 | 0x10a20 | 0x217 |
TerminateProcess | - | 0x40d060 | 0x12424 | 0x10a24 | 0x58c |
RtlUnwind | - | 0x40d064 | 0x12428 | 0x10a28 | 0x4d3 |
GetLastError | - | 0x40d068 | 0x1242c | 0x10a2c | 0x261 |
SetLastError | - | 0x40d06c | 0x12430 | 0x10a30 | 0x532 |
EnterCriticalSection | - | 0x40d070 | 0x12434 | 0x10a34 | 0x131 |
LeaveCriticalSection | - | 0x40d074 | 0x12438 | 0x10a38 | 0x3bd |
DeleteCriticalSection | - | 0x40d078 | 0x1243c | 0x10a3c | 0x110 |
InitializeCriticalSectionAndSpinCount | - | 0x40d07c | 0x12440 | 0x10a40 | 0x35f |
TlsAlloc | - | 0x40d080 | 0x12444 | 0x10a44 | 0x59e |
TlsGetValue | - | 0x40d084 | 0x12448 | 0x10a48 | 0x5a0 |
TlsSetValue | - | 0x40d088 | 0x1244c | 0x10a4c | 0x5a1 |
TlsFree | - | 0x40d08c | 0x12450 | 0x10a50 | 0x59f |
FreeLibrary | - | 0x40d090 | 0x12454 | 0x10a54 | 0x1ab |
GetProcAddress | - | 0x40d094 | 0x12458 | 0x10a58 | 0x2ae |
LoadLibraryExW | - | 0x40d098 | 0x1245c | 0x10a5c | 0x3c3 |
RaiseException | - | 0x40d09c | 0x12460 | 0x10a60 | 0x462 |
GetStdHandle | - | 0x40d0a0 | 0x12464 | 0x10a64 | 0x2d2 |
GetModuleFileNameW | - | 0x40d0a4 | 0x12468 | 0x10a68 | 0x274 |
ExitProcess | - | 0x40d0a8 | 0x1246c | 0x10a6c | 0x15e |
GetModuleHandleExW | - | 0x40d0ac | 0x12470 | 0x10a70 | 0x277 |
HeapAlloc | - | 0x40d0b0 | 0x12474 | 0x10a74 | 0x345 |
HeapFree | - | 0x40d0b4 | 0x12478 | 0x10a78 | 0x349 |
FindClose | - | 0x40d0b8 | 0x1247c | 0x10a7c | 0x175 |
FindFirstFileExW | - | 0x40d0bc | 0x12480 | 0x10a80 | 0x17b |
FindNextFileW | - | 0x40d0c0 | 0x12484 | 0x10a84 | 0x18c |
IsValidCodePage | - | 0x40d0c4 | 0x12488 | 0x10a88 | 0x38b |
GetACP | - | 0x40d0c8 | 0x1248c | 0x10a8c | 0x1b2 |
GetOEMCP | - | 0x40d0cc | 0x12490 | 0x10a90 | 0x297 |
GetCPInfo | - | 0x40d0d0 | 0x12494 | 0x10a94 | 0x1c1 |
GetCommandLineA | - | 0x40d0d4 | 0x12498 | 0x10a98 | 0x1d6 |
GetCommandLineW | - | 0x40d0d8 | 0x1249c | 0x10a9c | 0x1d7 |
MultiByteToWideChar | - | 0x40d0dc | 0x124a0 | 0x10aa0 | 0x3ef |
WideCharToMultiByte | - | 0x40d0e0 | 0x124a4 | 0x10aa4 | 0x5fe |
GetEnvironmentStringsW | - | 0x40d0e4 | 0x124a8 | 0x10aa8 | 0x237 |
FreeEnvironmentStringsW | - | 0x40d0e8 | 0x124ac | 0x10aac | 0x1aa |
SetStdHandle | - | 0x40d0ec | 0x124b0 | 0x10ab0 | 0x54a |
GetFileType | - | 0x40d0f0 | 0x124b4 | 0x10ab4 | 0x24e |
GetStringTypeW | - | 0x40d0f4 | 0x124b8 | 0x10ab8 | 0x2d7 |
LCMapStringW | - | 0x40d0f8 | 0x124bc | 0x10abc | 0x3b1 |
GetProcessHeap | - | 0x40d0fc | 0x124c0 | 0x10ac0 | 0x2b4 |
HeapSize | - | 0x40d100 | 0x124c4 | 0x10ac4 | 0x34e |
HeapReAlloc | - | 0x40d104 | 0x124c8 | 0x10ac8 | 0x34c |
FlushFileBuffers | - | 0x40d108 | 0x124cc | 0x10acc | 0x19f |
GetConsoleCP | - | 0x40d10c | 0x124d0 | 0x10ad0 | 0x1ea |
GetConsoleMode | - | 0x40d110 | 0x124d4 | 0x10ad4 | 0x1fc |
SetFilePointerEx | - | 0x40d114 | 0x124d8 | 0x10ad8 | 0x523 |
DecodePointer | - | 0x40d118 | 0x124dc | 0x10adc | 0x109 |
Digital Signature Information
»
Verification Status | Valid |
Certificate: PB03 TRANSPORT LTD.
»
Issued by | PB03 TRANSPORT LTD. |
Parent Certificate | Sectigo RSA Code Signing CA |
Country Name | CA |
Valid From | 2021-04-29 02:00 (UTC+2) |
Valid Until | 2022-04-30 01:59 (UTC+2) |
Algorithm | sha256_rsa |
Serial Number | 11 9A CE AD 66 8B AD 57 A4 8B 4F 42 F2 94 F8 F0 |
Thumbprint | 11 FF 68 DA 43 F0 93 1E 22 00 2F 14 61 13 6C 66 2E 62 33 66 |
Certificate: Sectigo RSA Code Signing CA
»
Issued by | Sectigo RSA Code Signing CA |
Parent Certificate | USERTrust RSA Certification Authority |
Country Name | GB |
Valid From | 2018-11-02 01:00 (UTC+1) |
Valid Until | 2031-01-01 00:59 (UTC+1) |
Algorithm | sha384_rsa |
Serial Number | 1D A2 48 30 6F 9B 26 18 D0 82 E0 96 7D 33 D3 6A |
Thumbprint | 94 C9 5D A1 E8 50 BD 85 20 9A 4A 2A F3 E1 FB 16 04 F9 BB 66 |
Certificate: USERTrust RSA Certification Authority
»
Issued by | USERTrust RSA Certification Authority |
Country Name | US |
Valid From | 2019-03-12 01:00 (UTC+1) |
Valid Until | 2029-01-01 00:59 (UTC+1) |
Algorithm | sha384_rsa |
Serial Number | 39 72 44 3A F9 22 B7 51 D7 D3 6C 10 DD 31 35 95 |
Thumbprint | D8 9E 3B D4 3D 5D 90 9B 47 A1 89 77 AA 9D 5C E3 6C EE 18 4C |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
urnxby.exe | 1 | 0x001C0000 | 0x002A0FFF | Relevant Image | 32-bit | 0x001C243E |
...
|
|||
urnxby.exe | 1 | 0x001C0000 | 0x002A0FFF | Process Termination | 32-bit | - |
...
|
File Reputation Information
»
Verdict |
malicious
|
Names | Mal/Generic-S |
AV Matches (1)
»
Threat Name | Verdict |
---|---|
Gen:Variant.Bulz.471680 |
malicious
|
PE Information
»
Image Base | 0x10000000 |
Entry Point | 0x1005fce6 |
Size Of Code | 0x70e00 |
Size Of Initialized Data | 0x56800 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2021-07-01 12:39:06+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x10001000 | 0x70d42 | 0x70e00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.57 |
.rdata | 0x10072000 | 0x2a864 | 0x2aa00 | 0x71200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.76 |
.data | 0x1009d000 | 0x25c00 | 0x22000 | 0x9bc00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.91 |
.reloc | 0x100c3000 | 0x6100 | 0x6200 | 0xbdc00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.51 |
Imports (3)
»
KERNEL32.dll (81)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | - | 0x10072010 | 0x9c078 | 0x9b278 | 0x33c |
GetStdHandle | - | 0x10072014 | 0x9c07c | 0x9b27c | 0x264 |
GetFileType | - | 0x10072018 | 0x9c080 | 0x9b280 | 0x1f3 |
WriteFile | - | 0x1007201c | 0x9c084 | 0x9b284 | 0x525 |
GetLastError | - | 0x10072020 | 0x9c088 | 0x9b288 | 0x202 |
GetCurrentThreadId | - | 0x10072024 | 0x9c08c | 0x9b28c | 0x1c5 |
GetModuleHandleA | - | 0x10072028 | 0x9c090 | 0x9b290 | 0x215 |
MultiByteToWideChar | - | 0x1007202c | 0x9c094 | 0x9b294 | 0x367 |
CloseHandle | - | 0x10072030 | 0x9c098 | 0x9b298 | 0x52 |
QueryPerformanceCounter | - | 0x10072034 | 0x9c09c | 0x9b29c | 0x3a7 |
GetCurrentProcessId | - | 0x10072038 | 0x9c0a0 | 0x9b2a0 | 0x1c1 |
GetTickCount | - | 0x1007203c | 0x9c0a4 | 0x9b2a4 | 0x293 |
FreeLibrary | - | 0x10072040 | 0x9c0a8 | 0x9b2a8 | 0x162 |
GlobalMemoryStatus | - | 0x10072044 | 0x9c0ac | 0x9b2ac | 0x2bf |
FlushConsoleInputBuffer | - | 0x10072048 | 0x9c0b0 | 0x9b2b0 | 0x156 |
GetCommandLineA | - | 0x1007204c | 0x9c0b4 | 0x9b2b4 | 0x186 |
HeapFree | - | 0x10072050 | 0x9c0b8 | 0x9b2b8 | 0x2cf |
HeapReAlloc | - | 0x10072054 | 0x9c0bc | 0x9b2bc | 0x2d2 |
EncodePointer | - | 0x10072058 | 0x9c0c0 | 0x9b2c0 | 0xea |
DecodePointer | - | 0x1007205c | 0x9c0c4 | 0x9b2c4 | 0xca |
ExitProcess | - | 0x10072060 | 0x9c0c8 | 0x9b2c8 | 0x119 |
GetModuleHandleExW | - | 0x10072064 | 0x9c0cc | 0x9b2cc | 0x217 |
AreFileApisANSI | - | 0x10072068 | 0x9c0d0 | 0x9b2d0 | 0x15 |
WideCharToMultiByte | - | 0x1007206c | 0x9c0d4 | 0x9b2d4 | 0x511 |
EnterCriticalSection | - | 0x10072070 | 0x9c0d8 | 0x9b2d8 | 0xee |
LeaveCriticalSection | - | 0x10072074 | 0x9c0dc | 0x9b2dc | 0x339 |
SetConsoleCtrlHandler | - | 0x10072078 | 0x9c0e0 | 0x9b2e0 | 0x42d |
GetSystemTimeAsFileTime | - | 0x1007207c | 0x9c0e4 | 0x9b2e4 | 0x279 |
IsDebuggerPresent | - | 0x10072080 | 0x9c0e8 | 0x9b2e8 | 0x300 |
IsProcessorFeaturePresent | - | 0x10072084 | 0x9c0ec | 0x9b2ec | 0x304 |
ReadFile | - | 0x10072088 | 0x9c0f0 | 0x9b2f0 | 0x3c0 |
GetConsoleMode | - | 0x1007208c | 0x9c0f4 | 0x9b2f4 | 0x1ac |
ReadConsoleInputA | - | 0x10072090 | 0x9c0f8 | 0x9b2f8 | 0x3b5 |
SetConsoleMode | - | 0x10072094 | 0x9c0fc | 0x9b2fc | 0x43d |
SetLastError | - | 0x10072098 | 0x9c100 | 0x9b300 | 0x473 |
DeleteCriticalSection | - | 0x1007209c | 0x9c104 | 0x9b304 | 0xd1 |
GetStartupInfoW | - | 0x100720a0 | 0x9c108 | 0x9b308 | 0x263 |
GetModuleFileNameA | - | 0x100720a4 | 0x9c10c | 0x9b30c | 0x213 |
CreateFileMappingW | - | 0x100720a8 | 0x9c110 | 0x9b310 | 0x8c |
FreeEnvironmentStringsW | - | 0x100720ac | 0x9c114 | 0x9b314 | 0x161 |
UnhandledExceptionFilter | - | 0x100720b0 | 0x9c118 | 0x9b318 | 0x4d3 |
SetUnhandledExceptionFilter | - | 0x100720b4 | 0x9c11c | 0x9b31c | 0x4a5 |
InitializeCriticalSectionAndSpinCount | - | 0x100720b8 | 0x9c120 | 0x9b320 | 0x2e3 |
GetCurrentProcess | - | 0x100720bc | 0x9c124 | 0x9b324 | 0x1c0 |
TerminateProcess | - | 0x100720c0 | 0x9c128 | 0x9b328 | 0x4c0 |
TlsAlloc | - | 0x100720c4 | 0x9c12c | 0x9b32c | 0x4c5 |
TlsGetValue | - | 0x100720c8 | 0x9c130 | 0x9b330 | 0x4c7 |
TlsSetValue | - | 0x100720cc | 0x9c134 | 0x9b334 | 0x4c8 |
TlsFree | - | 0x100720d0 | 0x9c138 | 0x9b338 | 0x4c6 |
GetModuleHandleW | - | 0x100720d4 | 0x9c13c | 0x9b33c | 0x218 |
GetModuleFileNameW | - | 0x100720d8 | 0x9c140 | 0x9b340 | 0x214 |
LoadLibraryExW | - | 0x100720dc | 0x9c144 | 0x9b344 | 0x33e |
IsValidCodePage | - | 0x100720e0 | 0x9c148 | 0x9b348 | 0x30a |
GetACP | - | 0x100720e4 | 0x9c14c | 0x9b34c | 0x168 |
GetOEMCP | - | 0x100720e8 | 0x9c150 | 0x9b350 | 0x237 |
GetCPInfo | - | 0x100720ec | 0x9c154 | 0x9b354 | 0x172 |
FlushFileBuffers | - | 0x100720f0 | 0x9c158 | 0x9b358 | 0x157 |
GetConsoleCP | - | 0x100720f4 | 0x9c15c | 0x9b35c | 0x19a |
RtlUnwind | - | 0x100720f8 | 0x9c160 | 0x9b360 | 0x418 |
ReadConsoleW | - | 0x100720fc | 0x9c164 | 0x9b364 | 0x3be |
SetFilePointerEx | - | 0x10072100 | 0x9c168 | 0x9b368 | 0x467 |
SetStdHandle | - | 0x10072104 | 0x9c16c | 0x9b36c | 0x487 |
CreateFileW | - | 0x10072108 | 0x9c170 | 0x9b370 | 0x8f |
OutputDebugStringW | - | 0x1007210c | 0x9c174 | 0x9b374 | 0x38a |
HeapSize | - | 0x10072110 | 0x9c178 | 0x9b378 | 0x2d4 |
CompareStringW | - | 0x10072114 | 0x9c17c | 0x9b37c | 0x64 |
LCMapStringW | - | 0x10072118 | 0x9c180 | 0x9b380 | 0x32d |
GetStringTypeW | - | 0x1007211c | 0x9c184 | 0x9b384 | 0x269 |
SetEnvironmentVariableA | - | 0x10072120 | 0x9c188 | 0x9b388 | 0x456 |
WriteConsoleW | - | 0x10072124 | 0x9c18c | 0x9b38c | 0x524 |
SetEndOfFile | - | 0x10072128 | 0x9c190 | 0x9b390 | 0x453 |
MapViewOfFile | - | 0x1007212c | 0x9c194 | 0x9b394 | 0x357 |
Sleep | - | 0x10072130 | 0x9c198 | 0x9b398 | 0x4b2 |
SetThreadPriority | - | 0x10072134 | 0x9c19c | 0x9b39c | 0x499 |
GetCurrentThread | - | 0x10072138 | 0x9c1a0 | 0x9b3a0 | 0x1c4 |
CreateThread | - | 0x1007213c | 0x9c1a4 | 0x9b3a4 | 0xb5 |
GetProcessHeap | - | 0x10072140 | 0x9c1a8 | 0x9b3a8 | 0x24a |
HeapAlloc | - | 0x10072144 | 0x9c1ac | 0x9b3ac | 0x2cb |
GetProcAddress | - | 0x10072148 | 0x9c1b0 | 0x9b3b0 | 0x245 |
GetEnvironmentStringsW | - | 0x1007214c | 0x9c1b4 | 0x9b3b4 | 0x1da |
DisableThreadLibraryCalls | - | 0x10072150 | 0x9c1b8 | 0x9b3b8 | 0xde |
USER32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MessageBoxA | - | 0x10072158 | 0x9c1c0 | 0x9b3c0 | 0x20e |
GetUserObjectInformationW | - | 0x1007215c | 0x9c1c4 | 0x9b3c4 | 0x18b |
GetProcessWindowStation | - | 0x10072160 | 0x9c1c8 | 0x9b3c8 | 0x168 |
ADVAPI32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegisterEventSourceA | - | 0x10072000 | 0x9c068 | 0x9b268 | 0x282 |
DeregisterEventSource | - | 0x10072004 | 0x9c06c | 0x9b26c | 0xdb |
ReportEventA | - | 0x10072008 | 0x9c070 | 0x9b270 | 0x28e |
Exports (3)
»
Api name | EAT Address | Ordinal |
---|---|---|
ServiceCrtMain | 0x1290 | 0x1 |
ServiceMain | 0x12d0 | 0x2 |
SvchostPushServiceGlobals | 0x12f0 | 0x3 |
Digital Signature Information
»
Verification Status | Failed |
Verification Error | The signature hash does not match the file contents |
Certificate: PB03 TRANSPORT LTD.
»
Issued by | PB03 TRANSPORT LTD. |
Parent Certificate | Sectigo RSA Code Signing CA |
Country Name | CA |
Valid From | 2021-04-29 02:00 (UTC+2) |
Valid Until | 2022-04-30 01:59 (UTC+2) |
Algorithm | sha256_rsa |
Serial Number | 11 9A CE AD 66 8B AD 57 A4 8B 4F 42 F2 94 F8 F0 |
Thumbprint | 11 FF 68 DA 43 F0 93 1E 22 00 2F 14 61 13 6C 66 2E 62 33 66 |
Certificate: Sectigo RSA Code Signing CA
»
Issued by | Sectigo RSA Code Signing CA |
Parent Certificate | USERTrust RSA Certification Authority |
Country Name | GB |
Valid From | 2018-11-02 01:00 (UTC+1) |
Valid Until | 2031-01-01 00:59 (UTC+1) |
Algorithm | sha384_rsa |
Serial Number | 1D A2 48 30 6F 9B 26 18 D0 82 E0 96 7D 33 D3 6A |
Thumbprint | 94 C9 5D A1 E8 50 BD 85 20 9A 4A 2A F3 E1 FB 16 04 F9 BB 66 |
Certificate: USERTrust RSA Certification Authority
»
Issued by | USERTrust RSA Certification Authority |
Country Name | US |
Valid From | 2019-03-12 01:00 (UTC+1) |
Valid Until | 2029-01-01 00:59 (UTC+1) |
Algorithm | sha384_rsa |
Serial Number | 39 72 44 3A F9 22 B7 51 D7 D3 6C 10 DD 31 35 95 |
Thumbprint | D8 9E 3B D4 3D 5D 90 9B 47 A1 89 77 AA 9D 5C E3 6C EE 18 4C |
C:\Windows\MsMpEng.exe | Dropped File | Binary |
malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4010e1 |
Size Of Code | 0x200 |
Size Of Initialized Data | 0x1200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2014-03-21 17:30:00+00:00 |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | Antimalware Service Executable |
InternalName | MsMpEng.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | MsMpEng.exe |
ProductName | Microsoft Malware Protection |
FileVersion | 4.5.0218.0 |
ProductVersion | 4.5.0218.0 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x18b | 0x200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 3.26 |
.data | 0x402000 | 0x324 | 0x200 | 0x600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.16 |
.idata | 0x403000 | 0x12c | 0x200 | 0x800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.92 |
.rsrc | 0x404000 | 0x8b0 | 0xa00 | 0xa00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.35 |
.reloc | 0x405000 | 0x194 | 0x200 | 0x1400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.48 |
Imports (2)
»
KERNEL32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitProcess | - | 0x403000 | 0x3060 | 0x860 | 0x151 |
QueryPerformanceCounter | - | 0x403004 | 0x3064 | 0x864 | 0x42a |
GetCurrentProcessId | - | 0x403008 | 0x3068 | 0x868 | 0x20a |
GetCurrentThreadId | - | 0x40300c | 0x306c | 0x86c | 0x20e |
GetSystemTimeAsFileTime | - | 0x403010 | 0x3070 | 0x870 | 0x2d6 |
GetTickCount | - | 0x403014 | 0x3074 | 0x874 | 0x2f2 |
mpsvc.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ServiceCrtMain | - | 0x40301c | 0x307c | 0x87c | 0x0 |
Digital Signature Information
»
Verification Status | Valid |
Certificate: Microsoft Corporation
»
Issued by | Microsoft Corporation |
Parent Certificate | Microsoft Code Signing PCA |
Country Name | US |
Valid From | 2013-01-24 23:33 (UTC+1) |
Valid Until | 2014-04-25 00:33 (UTC+2) |
Algorithm | sha1_rsa |
Serial Number | 33 00 00 00 B0 11 AF 0A 8B D0 3B 9F DD 00 01 00 00 00 B0 |
Thumbprint | 10 8E 2B A2 36 32 62 0C 42 7C 57 0B 6D 9D B5 1A C3 13 87 FE |
Certificate: Microsoft Code Signing PCA
»
Issued by | Microsoft Code Signing PCA |
Country Name | US |
Valid From | 2010-09-01 00:19 (UTC+2) |
Valid Until | 2020-09-01 00:29 (UTC+2) |
Algorithm | sha1_rsa |
Serial Number | 61 33 26 1A 00 00 00 00 00 31 |
Thumbprint | 3C AF 9B A2 DB 55 70 CA F7 69 42 FF 99 10 1B 99 38 88 E2 57 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
GenericRansomNote | Generic Ransomware Note | - |
4/5
|
...
|
e2a24ab94f865caeacdf2c3ad015f31f23008ac6db8312c2cbfb32e4a5466ea2 | Embedded File | Binary |
malicious
|
...
|
»
AV Matches (1)
»
Threat Name | Verdict |
---|---|
Gen:Variant.Bulz.471680 |
malicious
|
PE Information
»
Image Base | 0x10000000 |
Entry Point | 0x1005fce6 |
Size Of Code | 0x70e00 |
Size Of Initialized Data | 0x56800 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2021-07-01 12:39:06+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x10001000 | 0x70d42 | 0x70e00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.57 |
.rdata | 0x10072000 | 0x2a864 | 0x2aa00 | 0x71200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.76 |
.data | 0x1009d000 | 0x25c00 | 0x22000 | 0x9bc00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.91 |
.reloc | 0x100c3000 | 0x6100 | 0x6200 | 0xbdc00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.51 |
Imports (3)
»
KERNEL32.dll (81)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | - | 0x10072010 | 0x9c078 | 0x9b278 | 0x33c |
GetStdHandle | - | 0x10072014 | 0x9c07c | 0x9b27c | 0x264 |
GetFileType | - | 0x10072018 | 0x9c080 | 0x9b280 | 0x1f3 |
WriteFile | - | 0x1007201c | 0x9c084 | 0x9b284 | 0x525 |
GetLastError | - | 0x10072020 | 0x9c088 | 0x9b288 | 0x202 |
GetCurrentThreadId | - | 0x10072024 | 0x9c08c | 0x9b28c | 0x1c5 |
GetModuleHandleA | - | 0x10072028 | 0x9c090 | 0x9b290 | 0x215 |
MultiByteToWideChar | - | 0x1007202c | 0x9c094 | 0x9b294 | 0x367 |
CloseHandle | - | 0x10072030 | 0x9c098 | 0x9b298 | 0x52 |
QueryPerformanceCounter | - | 0x10072034 | 0x9c09c | 0x9b29c | 0x3a7 |
GetCurrentProcessId | - | 0x10072038 | 0x9c0a0 | 0x9b2a0 | 0x1c1 |
GetTickCount | - | 0x1007203c | 0x9c0a4 | 0x9b2a4 | 0x293 |
FreeLibrary | - | 0x10072040 | 0x9c0a8 | 0x9b2a8 | 0x162 |
GlobalMemoryStatus | - | 0x10072044 | 0x9c0ac | 0x9b2ac | 0x2bf |
FlushConsoleInputBuffer | - | 0x10072048 | 0x9c0b0 | 0x9b2b0 | 0x156 |
GetCommandLineA | - | 0x1007204c | 0x9c0b4 | 0x9b2b4 | 0x186 |
HeapFree | - | 0x10072050 | 0x9c0b8 | 0x9b2b8 | 0x2cf |
HeapReAlloc | - | 0x10072054 | 0x9c0bc | 0x9b2bc | 0x2d2 |
EncodePointer | - | 0x10072058 | 0x9c0c0 | 0x9b2c0 | 0xea |
DecodePointer | - | 0x1007205c | 0x9c0c4 | 0x9b2c4 | 0xca |
ExitProcess | - | 0x10072060 | 0x9c0c8 | 0x9b2c8 | 0x119 |
GetModuleHandleExW | - | 0x10072064 | 0x9c0cc | 0x9b2cc | 0x217 |
AreFileApisANSI | - | 0x10072068 | 0x9c0d0 | 0x9b2d0 | 0x15 |
WideCharToMultiByte | - | 0x1007206c | 0x9c0d4 | 0x9b2d4 | 0x511 |
EnterCriticalSection | - | 0x10072070 | 0x9c0d8 | 0x9b2d8 | 0xee |
LeaveCriticalSection | - | 0x10072074 | 0x9c0dc | 0x9b2dc | 0x339 |
SetConsoleCtrlHandler | - | 0x10072078 | 0x9c0e0 | 0x9b2e0 | 0x42d |
GetSystemTimeAsFileTime | - | 0x1007207c | 0x9c0e4 | 0x9b2e4 | 0x279 |
IsDebuggerPresent | - | 0x10072080 | 0x9c0e8 | 0x9b2e8 | 0x300 |
IsProcessorFeaturePresent | - | 0x10072084 | 0x9c0ec | 0x9b2ec | 0x304 |
ReadFile | - | 0x10072088 | 0x9c0f0 | 0x9b2f0 | 0x3c0 |
GetConsoleMode | - | 0x1007208c | 0x9c0f4 | 0x9b2f4 | 0x1ac |
ReadConsoleInputA | - | 0x10072090 | 0x9c0f8 | 0x9b2f8 | 0x3b5 |
SetConsoleMode | - | 0x10072094 | 0x9c0fc | 0x9b2fc | 0x43d |
SetLastError | - | 0x10072098 | 0x9c100 | 0x9b300 | 0x473 |
DeleteCriticalSection | - | 0x1007209c | 0x9c104 | 0x9b304 | 0xd1 |
GetStartupInfoW | - | 0x100720a0 | 0x9c108 | 0x9b308 | 0x263 |
GetModuleFileNameA | - | 0x100720a4 | 0x9c10c | 0x9b30c | 0x213 |
CreateFileMappingW | - | 0x100720a8 | 0x9c110 | 0x9b310 | 0x8c |
FreeEnvironmentStringsW | - | 0x100720ac | 0x9c114 | 0x9b314 | 0x161 |
UnhandledExceptionFilter | - | 0x100720b0 | 0x9c118 | 0x9b318 | 0x4d3 |
SetUnhandledExceptionFilter | - | 0x100720b4 | 0x9c11c | 0x9b31c | 0x4a5 |
InitializeCriticalSectionAndSpinCount | - | 0x100720b8 | 0x9c120 | 0x9b320 | 0x2e3 |
GetCurrentProcess | - | 0x100720bc | 0x9c124 | 0x9b324 | 0x1c0 |
TerminateProcess | - | 0x100720c0 | 0x9c128 | 0x9b328 | 0x4c0 |
TlsAlloc | - | 0x100720c4 | 0x9c12c | 0x9b32c | 0x4c5 |
TlsGetValue | - | 0x100720c8 | 0x9c130 | 0x9b330 | 0x4c7 |
TlsSetValue | - | 0x100720cc | 0x9c134 | 0x9b334 | 0x4c8 |
TlsFree | - | 0x100720d0 | 0x9c138 | 0x9b338 | 0x4c6 |
GetModuleHandleW | - | 0x100720d4 | 0x9c13c | 0x9b33c | 0x218 |
GetModuleFileNameW | - | 0x100720d8 | 0x9c140 | 0x9b340 | 0x214 |
LoadLibraryExW | - | 0x100720dc | 0x9c144 | 0x9b344 | 0x33e |
IsValidCodePage | - | 0x100720e0 | 0x9c148 | 0x9b348 | 0x30a |
GetACP | - | 0x100720e4 | 0x9c14c | 0x9b34c | 0x168 |
GetOEMCP | - | 0x100720e8 | 0x9c150 | 0x9b350 | 0x237 |
GetCPInfo | - | 0x100720ec | 0x9c154 | 0x9b354 | 0x172 |
FlushFileBuffers | - | 0x100720f0 | 0x9c158 | 0x9b358 | 0x157 |
GetConsoleCP | - | 0x100720f4 | 0x9c15c | 0x9b35c | 0x19a |
RtlUnwind | - | 0x100720f8 | 0x9c160 | 0x9b360 | 0x418 |
ReadConsoleW | - | 0x100720fc | 0x9c164 | 0x9b364 | 0x3be |
SetFilePointerEx | - | 0x10072100 | 0x9c168 | 0x9b368 | 0x467 |
SetStdHandle | - | 0x10072104 | 0x9c16c | 0x9b36c | 0x487 |
CreateFileW | - | 0x10072108 | 0x9c170 | 0x9b370 | 0x8f |
OutputDebugStringW | - | 0x1007210c | 0x9c174 | 0x9b374 | 0x38a |
HeapSize | - | 0x10072110 | 0x9c178 | 0x9b378 | 0x2d4 |
CompareStringW | - | 0x10072114 | 0x9c17c | 0x9b37c | 0x64 |
LCMapStringW | - | 0x10072118 | 0x9c180 | 0x9b380 | 0x32d |
GetStringTypeW | - | 0x1007211c | 0x9c184 | 0x9b384 | 0x269 |
SetEnvironmentVariableA | - | 0x10072120 | 0x9c188 | 0x9b388 | 0x456 |
WriteConsoleW | - | 0x10072124 | 0x9c18c | 0x9b38c | 0x524 |
SetEndOfFile | - | 0x10072128 | 0x9c190 | 0x9b390 | 0x453 |
MapViewOfFile | - | 0x1007212c | 0x9c194 | 0x9b394 | 0x357 |
Sleep | - | 0x10072130 | 0x9c198 | 0x9b398 | 0x4b2 |
SetThreadPriority | - | 0x10072134 | 0x9c19c | 0x9b39c | 0x499 |
GetCurrentThread | - | 0x10072138 | 0x9c1a0 | 0x9b3a0 | 0x1c4 |
CreateThread | - | 0x1007213c | 0x9c1a4 | 0x9b3a4 | 0xb5 |
GetProcessHeap | - | 0x10072140 | 0x9c1a8 | 0x9b3a8 | 0x24a |
HeapAlloc | - | 0x10072144 | 0x9c1ac | 0x9b3ac | 0x2cb |
GetProcAddress | - | 0x10072148 | 0x9c1b0 | 0x9b3b0 | 0x245 |
GetEnvironmentStringsW | - | 0x1007214c | 0x9c1b4 | 0x9b3b4 | 0x1da |
DisableThreadLibraryCalls | - | 0x10072150 | 0x9c1b8 | 0x9b3b8 | 0xde |
USER32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MessageBoxA | - | 0x10072158 | 0x9c1c0 | 0x9b3c0 | 0x20e |
GetUserObjectInformationW | - | 0x1007215c | 0x9c1c4 | 0x9b3c4 | 0x18b |
GetProcessWindowStation | - | 0x10072160 | 0x9c1c8 | 0x9b3c8 | 0x168 |
ADVAPI32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegisterEventSourceA | - | 0x10072000 | 0x9c068 | 0x9b268 | 0x282 |
DeregisterEventSource | - | 0x10072004 | 0x9c06c | 0x9b26c | 0xdb |
ReportEventA | - | 0x10072008 | 0x9c070 | 0x9b270 | 0x28e |
Exports (3)
»
Api name | EAT Address | Ordinal |
---|---|---|
ServiceCrtMain | 0x1290 | 0x1 |
ServiceMain | 0x12d0 | 0x2 |
SvchostPushServiceGlobals | 0x12f0 | 0x3 |
Digital Signature Information
»
Verification Status | Valid |
Certificate: PB03 TRANSPORT LTD.
»
Issued by | PB03 TRANSPORT LTD. |
Parent Certificate | Sectigo RSA Code Signing CA |
Country Name | CA |
Valid From | 2021-04-29 02:00 (UTC+2) |
Valid Until | 2022-04-30 01:59 (UTC+2) |
Algorithm | sha256_rsa |
Serial Number | 11 9A CE AD 66 8B AD 57 A4 8B 4F 42 F2 94 F8 F0 |
Thumbprint | 11 FF 68 DA 43 F0 93 1E 22 00 2F 14 61 13 6C 66 2E 62 33 66 |
Certificate: Sectigo RSA Code Signing CA
»
Issued by | Sectigo RSA Code Signing CA |
Parent Certificate | USERTrust RSA Certification Authority |
Country Name | GB |
Valid From | 2018-11-02 01:00 (UTC+1) |
Valid Until | 2031-01-01 00:59 (UTC+1) |
Algorithm | sha384_rsa |
Serial Number | 1D A2 48 30 6F 9B 26 18 D0 82 E0 96 7D 33 D3 6A |
Thumbprint | 94 C9 5D A1 E8 50 BD 85 20 9A 4A 2A F3 E1 FB 16 04 F9 BB 66 |
Certificate: USERTrust RSA Certification Authority
»
Issued by | USERTrust RSA Certification Authority |
Country Name | US |
Valid From | 2019-03-12 01:00 (UTC+1) |
Valid Until | 2029-01-01 00:59 (UTC+1) |
Algorithm | sha384_rsa |
Serial Number | 39 72 44 3A F9 22 B7 51 D7 D3 6C 10 DD 31 35 95 |
Thumbprint | D8 9E 3B D4 3D 5D 90 9B 47 A1 89 77 AA 9D 5C E3 6C EE 18 4C |
C:\Users\RDHJ0C~1\AppData\Local\Temp\acytgo.bmp | Dropped File | Stream |
suspicious
|
...
|
»
\\?\c:\recovery\windowsre\boot.sdi | Modified File | Stream |
clean
|
...
|
»
\\?\c:\recovery\windowsre\ReAgent.xml | Modified File | Stream |
clean
|
...
|
»
\\?\c:\recovery\windowsre\Winre.wim | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\public\libraries\RecordedTV.library-ms | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\-Z-V0ExGeBpI5TSR.swf | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\01YAMgo9xg6KO6O.mkv | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\1 UW.wav | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\33awWl-CR.avi | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\6ln5Q1NpLV8X.swf | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\8gunvOc6.avi | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\AJEpb8eU1fWd.wav | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\B snKe5YsxqO.mp4 | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\BZGdF1.gif | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\cmuFOUIVnjG4az4rOtOY.mkv | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\Cva PS2HA_.m4a | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\dgDGWB.docx | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\eMPya.xlsx | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\FJejnU-5I.pdf | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\fn8P6 hgNkusN.doc | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\Fvhx_vxdy.wav | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\ImpY3itno4.bmp | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\IUm_.bmp | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\JWX47syN3PWU.bmp | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\LYqznbAEVzwqX45oeA.mp4 | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\O2CR.bmp | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\Od9_u.xlsx | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\qgErEk.avi | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\qzaVN1YR5.png | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\QzpxI33e01yGBOLeX.mkv | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\Rb_JLSd1jDdcCtXSZ.gif | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\y1Mi2Ynx_elk.mp3 | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\yKVRq4UJhors0kzj.gif | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\_HZf8VI--lGsLJmGS.jpg | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\_vijf9R7840.bmp | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\-DN qa.docx | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\0f0dtE0zrFDiBuhWyC5.docx | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\3kI5HqhForfqaGGgxr.xlsx | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\400IjG TRfjGKkG.docx | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\5ujftJ9fpTg1.docx | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\6zXJIpa.pptx | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\bxJv6_JJ.xlsx | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\CNJ7vM7xU_fqXr.xls | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\E0bAcSQhlr3rJxAYgov.xlsx | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\ejY9.xlsx | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\gNkCMwtLS49pa.docx | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\hCetyp3G17Ciz.pps | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\l DJMmpijuAsqr21.pptx | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\LSd7BeVtYtpJ.pptx | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\RbIb11kyJBfbC4lR.docx | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\SJGjS-9yqVHR1Sr.xlsx | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\uvUqY N6Bfi.pptx | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\V7HumL1ZZJKoPg.pptx | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\yUtkkx8xYplRS.pptx | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\_6rIiH.xlsx | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\favorites\Bing.url | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\4W2zSw_qyA-iNvZwG.mp3 | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\DlddW4odh7 0R.mp3 | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\Hy6kK83v326kg.m4a | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\I DXBf6fbq5DmIhEE.m4a | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\iLGIuAawkATxwUujSc.m4a | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\ipeVoX06U.mp3 | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\I_EcfLMno5hLsDXInPs.mp3 | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\l5AuKPVeEq1.m4a | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\mjQXCIBoEGsRIXG5UH1.wav | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\pERp.m4a | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\sp8U4eZ5gjmARGZzERiC.mp3 | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\SynGA4LX.mp3 | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\tmjvG4lm-mwGUnkAQc.wav | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\wk9oyeTx5Wxu-aAZVD.mp3 | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\pictures\0GKL.gif | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\pictures\7nDtl1ODTnF.png | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\pictures\Eum-G.png | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\pictures\pERp6q8YBvJUb0EB.bmp | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\pictures\ZJmAXf_iw1OZ22dUkz.bmp | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\searches\Everywhere.search-ms | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\searches\Indexed Locations.search-ms | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\6i3pxIlMX__X8g3sdibs.swf | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\eDmfBt.swf | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\JdPv-THV6iu1IxNFOOGg.swf | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\JW1N_M9MWCDNminC7_Tm.flv | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\LOcjMbS.mp4 | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\Ps_Y7GMrUuhLbnrspS9.mkv | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\rOuI.mp4 | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\r_thM75ifbQ0QX.flv | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\SEYiJHv2SpL.swf | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\URGZlfZLPhup7rRJYz.avi | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\wJiV5gVOmgxd.avi | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\xamTr_oYu_mgpHD.swf | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\bfxp6 wq\-umSa-sI5gifEmW.swf | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\bfxp6 wq\tCX_RN2xF9X.png | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\bfxp6 wq\ulYmM-fmul26.pps | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\bfxp6 wq\Vi3giADhSuv oRP.pps | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\bfxp6 wq\z0cY.flv | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\pfzhoo0zmp\5H4kyoh3O.mp3 | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\pfzhoo0zmp\cRCLA-_5U24a-.flv | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\pfzhoo0zmp\w1Vdv.m4a | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\outlook files\achoo@gdllo.de.pst | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\xrle3k2z6t5mdwjru\H8NI-Y-.docx | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\7xfazggdo2\-hjTYqk.mp3 | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\7xfazggdo2\8PzcWGW.m4a | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\7xfazggdo2\BX1wR y6hvbH4sIC-7v.mp3 | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\7xfazggdo2\F27AcbA_RY_-woTi6.mp3 | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\7xfazggdo2\GA5oxL-.m4a | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\7xfazggdo2\gdr194tG.m4a | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\7xfazggdo2\gTpR4bHCjaGhqviGa-e.m4a | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\7xfazggdo2\JDuNSpuPCB9nrCX1hxhf.m4a | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\7xfazggdo2\JGznrvkEEvxn00.wav | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\7xfazggdo2\leot2gmJs.m4a | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\7xfazggdo2\lSPgMK9.wav | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\7xfazggdo2\O1uOZTDu.mp3 | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\7xfazggdo2\RH8_sB7GO_faGWB.m4a | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\7xfazggdo2\ufBNll.m4a | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\7xfazggdo2\wxGAE7Dj.wav | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\7xfazggdo2\Y_pSjsnzlmt uLUc.mp3 | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\7xfazggdo2\zbzN Mww_Bkx.wav | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\music\7xfazggdo2\zpUSLDdQvFXBODSYNS-w.m4a | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\pictures\6s-a l\2UmmY.bmp | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\pictures\6s-a l\B-TyRFGPPXknyiuqW.png | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\pictures\6s-a l\IaTgbd.png | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\pictures\6s-a l\kQUblf2Z.gif | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\pictures\6s-a l\rbdcx.bmp | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\pictures\l5ijd4gbqss\ufzBZ.gif | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\pictures\l5ijd4gbqss\Yapy.png | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\pictures\pihosizt0v\5JyH.jpg | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\pictures\pihosizt0v\i7llpv9MXtjEu6M.jpg | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\pictures\pihosizt0v\rsAG.gif | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\pictures\xwxyg9hii4\IIuKhqW.gif | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\pictures\xwxyg9hii4\Y_Xs 4xskgupJwFhAzLH.bmp | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\8boi\9avvUOE8E13XW.mp4 | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\8boi\9YyfpISvoY2vb57M.avi | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\8boi\AfS_.mp4 | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\8boi\fCAhoT3_1e71to2Wm.avi | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\8boi\Kf2M4.mkv | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\8boi\kzDOkTC6Kdq.swf | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\8boi\OIMFe7MA.swf | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\8boi\urEwLAVDg6.mp4 | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\aqp9vri0bxjohappcij\0wjnewtJwvVY4a.flv | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\aqp9vri0bxjohappcij\8SOP.mp4 | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\aqp9vri0bxjohappcij\Knz17DKF_L6UW.mp4 | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\aqp9vri0bxjohappcij\NsCf6g6DKIJANIzE2RT.flv | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\aqp9vri0bxjohappcij\U0ec_M4przGLKk6Pxo1.flv | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\videos\aqp9vri0bxjohappcij\xTrZ.swf | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\bfxp6 wq\ke1a65mkp\2hLo0.odt | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\bfxp6 wq\ke1a65mkp\yn_Kv.jpg | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\pfzhoo0zmp\1ouv\oNZyM1CpX6Slc7.swf | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\pfzhoo0zmp\1ouv\QeFAs5IS6bvA.pptx | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\desktop\pfzhoo0zmp\1ouv\znTgWd9fa.bmp | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\xrle3k2z6t5mdwjru\temgrn\j29TUnR2mS8et2.odt | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\xrle3k2z6t5mdwjru\temgrn\uVOjn2_x74I.ods | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\xrle3k2z6t5mdwjru\temgrn\Z64YPMlvlic7O9.doc | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\xrle3k2z6t5mdwjru\temgrn\ZADUpwgiJ8uOonMiE8a.csv | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\documents\xrle3k2z6t5mdwjru\temgrn\_yfFnDibGrsmCVUoSQ.pdf | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\pictures\l5ijd4gbqss\4ybkstu5b2\-IxCwY_jBOe.jpg | Modified File | Stream |
clean
|
...
|
»
\\?\c:\users\rdhj0cnfevzx\pictures\l5ijd4gbqss\4ybkstu5b2\79OkAP5ZR13BLE2cbVKN.png | Modified File | Stream |
clean
|
...
|
»
Also Known As | \\?\c:\users\rdhj0cnfevzx\pictures\l5ijd4gbqss\4ybkstu5b2\79OkAP5ZR13BLE2cbVKN.png.1yg4ztc5 (Dropped File) |
MIME Type | application/octet-stream |
File Size | 85.96 KB |