VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Wiper, Spyware, Trojan |
rsfd234df.exe
Windows Exe (x86-32)
Created at 2019-09-24T04:52:00
Remarks
(0x200001e): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x200000f): The maximum number of memory dumps was exceeded. Some dumps may be missing in the report.
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\rsfd234df.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-09-01 16:09 (UTC+2) |
Last Seen | 2019-09-18 09:55 (UTC+2) |
Names | Win32.Trojan.Androm |
Families | Androm |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x428432 |
Size Of Code | 0x31600 |
Size Of Initialized Data | 0xb000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-05-29 09:18:52+00:00 |
Version Information (8)
»
CompanyName | Katsina |
FileDescription | cn- |
FileVersion | 1.1.2.5 |
InternalName | autocollimation.exe |
LegalCopyright | Copyright (C) nonrepeater 2018 |
OriginalFilename | bromochlorophenol.exe |
ProductName | Jean-Claude |
ProductVersion | 0.7.1.5 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x31571 | 0x31600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.85 |
.rdata | 0x433000 | 0x6d38 | 0x6e00 | 0x31a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.03 |
.data | 0x43a000 | 0x3138 | 0x2000 | 0x38800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.27 |
.gfids | 0x43e000 | 0xac | 0x200 | 0x3a800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.79 |
.rsrc | 0x43f000 | 0x7d4 | 0x800 | 0x3aa00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.24 |
.reloc | 0x440000 | 0x17e0 | 0x1800 | 0x3b200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.65 |
Imports (3)
»
KERNEL32.dll (76)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FreeEnvironmentStringsW | 0x0 | 0x433000 | 0x394dc | 0x37edc | 0x161 |
GetProcessHeap | 0x0 | 0x433004 | 0x394e0 | 0x37ee0 | 0x24a |
FillConsoleOutputAttribute | 0x0 | 0x433008 | 0x394e4 | 0x37ee4 | 0x126 |
lstrcpyA | 0x0 | 0x43300c | 0x394e8 | 0x37ee8 | 0x547 |
SetCalendarInfoW | 0x0 | 0x433010 | 0x394ec | 0x37eec | 0x41f |
CallNamedPipeA | 0x0 | 0x433014 | 0x394f0 | 0x37ef0 | 0x3e |
FindVolumeMountPointClose | 0x0 | 0x433018 | 0x394f4 | 0x37ef4 | 0x151 |
GetFileSizeEx | 0x0 | 0x43301c | 0x394f8 | 0x37ef8 | 0x1f1 |
GetPrivateProfileStructA | 0x0 | 0x433020 | 0x394fc | 0x37efc | 0x243 |
InterlockedExchangeAdd | 0x0 | 0x433024 | 0x39500 | 0x37f00 | 0x2ed |
GetConsoleAliasA | 0x0 | 0x433028 | 0x39504 | 0x37f04 | 0x190 |
EnumSystemLocalesW | 0x0 | 0x43302c | 0x39508 | 0x37f08 | 0x10f |
GetModuleFileNameA | 0x0 | 0x433030 | 0x3950c | 0x37f0c | 0x213 |
GetFileType | 0x0 | 0x433034 | 0x39510 | 0x37f10 | 0x1f3 |
EnumTimeFormatsA | 0x0 | 0x433038 | 0x39514 | 0x37f14 | 0x110 |
GetShortPathNameW | 0x0 | 0x43303c | 0x39518 | 0x37f18 | 0x261 |
CreateFileW | 0x0 | 0x433040 | 0x3951c | 0x37f1c | 0x8f |
DecodePointer | 0x0 | 0x433044 | 0x39520 | 0x37f20 | 0xca |
WriteConsoleW | 0x0 | 0x433048 | 0x39524 | 0x37f24 | 0x524 |
SetFilePointerEx | 0x0 | 0x43304c | 0x39528 | 0x37f28 | 0x467 |
GetConsoleMode | 0x0 | 0x433050 | 0x3952c | 0x37f2c | 0x1ac |
GetConsoleCP | 0x0 | 0x433054 | 0x39530 | 0x37f30 | 0x19a |
FlushFileBuffers | 0x0 | 0x433058 | 0x39534 | 0x37f34 | 0x157 |
HeapReAlloc | 0x0 | 0x43305c | 0x39538 | 0x37f38 | 0x2d2 |
HeapSize | 0x0 | 0x433060 | 0x3953c | 0x37f3c | 0x2d4 |
GetStringTypeW | 0x0 | 0x433064 | 0x39540 | 0x37f40 | 0x269 |
SetStdHandle | 0x0 | 0x433068 | 0x39544 | 0x37f44 | 0x487 |
LCMapStringW | 0x0 | 0x43306c | 0x39548 | 0x37f48 | 0x32d |
GetEnvironmentStringsW | 0x0 | 0x433070 | 0x3954c | 0x37f4c | 0x1da |
GetCommandLineW | 0x0 | 0x433074 | 0x39550 | 0x37f50 | 0x187 |
GetCommandLineA | 0x0 | 0x433078 | 0x39554 | 0x37f54 | 0x186 |
GetCPInfo | 0x0 | 0x43307c | 0x39558 | 0x37f58 | 0x172 |
GetOEMCP | 0x0 | 0x433080 | 0x3955c | 0x37f5c | 0x237 |
IsValidCodePage | 0x0 | 0x433084 | 0x39560 | 0x37f60 | 0x30a |
QueryPerformanceCounter | 0x0 | 0x433088 | 0x39564 | 0x37f64 | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x43308c | 0x39568 | 0x37f68 | 0x1c1 |
GetCurrentThreadId | 0x0 | 0x433090 | 0x3956c | 0x37f6c | 0x1c5 |
GetSystemTimeAsFileTime | 0x0 | 0x433094 | 0x39570 | 0x37f70 | 0x279 |
InitializeSListHead | 0x0 | 0x433098 | 0x39574 | 0x37f74 | 0x2e7 |
IsDebuggerPresent | 0x0 | 0x43309c | 0x39578 | 0x37f78 | 0x300 |
UnhandledExceptionFilter | 0x0 | 0x4330a0 | 0x3957c | 0x37f7c | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x4330a4 | 0x39580 | 0x37f80 | 0x4a5 |
GetStartupInfoW | 0x0 | 0x4330a8 | 0x39584 | 0x37f84 | 0x263 |
IsProcessorFeaturePresent | 0x0 | 0x4330ac | 0x39588 | 0x37f88 | 0x304 |
GetModuleHandleW | 0x0 | 0x4330b0 | 0x3958c | 0x37f8c | 0x218 |
GetCurrentProcess | 0x0 | 0x4330b4 | 0x39590 | 0x37f90 | 0x1c0 |
TerminateProcess | 0x0 | 0x4330b8 | 0x39594 | 0x37f94 | 0x4c0 |
RtlUnwind | 0x0 | 0x4330bc | 0x39598 | 0x37f98 | 0x418 |
GetLastError | 0x0 | 0x4330c0 | 0x3959c | 0x37f9c | 0x202 |
SetLastError | 0x0 | 0x4330c4 | 0x395a0 | 0x37fa0 | 0x473 |
EnterCriticalSection | 0x0 | 0x4330c8 | 0x395a4 | 0x37fa4 | 0xee |
LeaveCriticalSection | 0x0 | 0x4330cc | 0x395a8 | 0x37fa8 | 0x339 |
DeleteCriticalSection | 0x0 | 0x4330d0 | 0x395ac | 0x37fac | 0xd1 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4330d4 | 0x395b0 | 0x37fb0 | 0x2e3 |
TlsAlloc | 0x0 | 0x4330d8 | 0x395b4 | 0x37fb4 | 0x4c5 |
TlsGetValue | 0x0 | 0x4330dc | 0x395b8 | 0x37fb8 | 0x4c7 |
TlsSetValue | 0x0 | 0x4330e0 | 0x395bc | 0x37fbc | 0x4c8 |
TlsFree | 0x0 | 0x4330e4 | 0x395c0 | 0x37fc0 | 0x4c6 |
FreeLibrary | 0x0 | 0x4330e8 | 0x395c4 | 0x37fc4 | 0x162 |
GetProcAddress | 0x0 | 0x4330ec | 0x395c8 | 0x37fc8 | 0x245 |
LoadLibraryExW | 0x0 | 0x4330f0 | 0x395cc | 0x37fcc | 0x33e |
GetStdHandle | 0x0 | 0x4330f4 | 0x395d0 | 0x37fd0 | 0x264 |
WriteFile | 0x0 | 0x4330f8 | 0x395d4 | 0x37fd4 | 0x525 |
GetModuleFileNameW | 0x0 | 0x4330fc | 0x395d8 | 0x37fd8 | 0x214 |
MultiByteToWideChar | 0x0 | 0x433100 | 0x395dc | 0x37fdc | 0x367 |
WideCharToMultiByte | 0x0 | 0x433104 | 0x395e0 | 0x37fe0 | 0x511 |
ExitProcess | 0x0 | 0x433108 | 0x395e4 | 0x37fe4 | 0x119 |
GetModuleHandleExW | 0x0 | 0x43310c | 0x395e8 | 0x37fe8 | 0x217 |
GetACP | 0x0 | 0x433110 | 0x395ec | 0x37fec | 0x168 |
HeapFree | 0x0 | 0x433114 | 0x395f0 | 0x37ff0 | 0x2cf |
HeapAlloc | 0x0 | 0x433118 | 0x395f4 | 0x37ff4 | 0x2cb |
CloseHandle | 0x0 | 0x43311c | 0x395f8 | 0x37ff8 | 0x52 |
FindClose | 0x0 | 0x433120 | 0x395fc | 0x37ffc | 0x12e |
FindFirstFileExW | 0x0 | 0x433124 | 0x39600 | 0x38000 | 0x134 |
FindNextFileW | 0x0 | 0x433128 | 0x39604 | 0x38004 | 0x145 |
RaiseException | 0x0 | 0x43312c | 0x39608 | 0x38008 | 0x3b1 |
pdh.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PdhUpdateLogA | 0x0 | 0x433174 | 0x39650 | 0x38050 | 0x6a |
PdhEnumObjectsA | 0x0 | 0x433178 | 0x39654 | 0x38054 | 0x22 |
PdhEnumObjectsW | 0x0 | 0x43317c | 0x39658 | 0x38058 | 0x25 |
PdhVbGetDoubleCounterValue | 0x0 | 0x433180 | 0x3965c | 0x3805c | 0x75 |
PdhVbGetCounterPathElements | 0x0 | 0x433184 | 0x39660 | 0x38060 | 0x73 |
PdhVbIsGoodStatus | 0x0 | 0x433188 | 0x39664 | 0x38064 | 0x78 |
PdhVbCreateCounterPathList | 0x0 | 0x43318c | 0x39668 | 0x38068 | 0x72 |
PdhGetDllVersion | 0x0 | 0x433190 | 0x3966c | 0x3806c | 0x3b |
PdhOpenQuery | 0x0 | 0x433194 | 0x39670 | 0x38070 | 0x52 |
PdhGetRawCounterArrayA | 0x0 | 0x433198 | 0x39674 | 0x38074 | 0x44 |
PdhGetRawCounterValue | 0x0 | 0x43319c | 0x39678 | 0x38078 | 0x46 |
msi.dll (15)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x56 | 0x433134 | 0x39610 | 0x38010 | - |
(by ordinal) | 0x1f | 0x433138 | 0x39614 | 0x38014 | - |
(by ordinal) | 0x9f | 0x43313c | 0x39618 | 0x38018 | - |
(by ordinal) | 0x41 | 0x433140 | 0x3961c | 0x3801c | - |
(by ordinal) | 0x62 | 0x433144 | 0x39620 | 0x38020 | - |
(by ordinal) | 0x5a | 0x433148 | 0x39624 | 0x38024 | - |
(by ordinal) | 0x43 | 0x43314c | 0x39628 | 0x38028 | - |
(by ordinal) | 0x71 | 0x433150 | 0x3962c | 0x3802c | - |
(by ordinal) | 0x2d | 0x433154 | 0x39630 | 0x38030 | - |
(by ordinal) | 0xa3 | 0x433158 | 0x39634 | 0x38034 | - |
(by ordinal) | 0x5f | 0x43315c | 0x39638 | 0x38038 | - |
(by ordinal) | 0x3f | 0x433160 | 0x3963c | 0x3803c | - |
(by ordinal) | 0x25 | 0x433164 | 0x39640 | 0x38040 | - |
(by ordinal) | 0x14 | 0x433168 | 0x39644 | 0x38044 | - |
(by ordinal) | 0x75 | 0x43316c | 0x39648 | 0x38048 | - |
Memory Dumps (414)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
rsfd234df.exe | 1 | 0x00F80000 | 0x00FC1FFF | Relevant Image | - | 32-bit | - |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x000B0000 | 0x000B0FFF | First Execution | - | 32-bit | 0x000B0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
buffer | 1 | 0x002D0000 | 0x002D0FFF | First Execution | - | 32-bit | 0x002D0004 |
...
|
||
rsfd234df.exe | 1 | 0x00F80000 | 0x00FC1FFF | Process Termination | - | 32-bit | - |
...
|
||
rsfd234df.exe | 2 | 0x00F80000 | 0x00FC1FFF | Relevant Image | - | 32-bit | - |
...
|
||
rsfd234df.exe | 3 | 0x00F80000 | 0x00FC1FFF | Relevant Image | - | 32-bit | - |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x001F0000 | 0x001F0FFF | First Execution | - | 32-bit | 0x001F0004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
rsfd234df.exe | 2 | 0x00F80000 | 0x00FC1FFF | Final Dump | - | 32-bit | - |
...
|
||
rsfd234df.exe | 3 | 0x00F80000 | 0x00FC1FFF | Final Dump | - | 32-bit | - |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
buffer | 3 | 0x00530000 | 0x00530FFF | First Execution | - | 32-bit | 0x00530004 |
...
|
||
rsfd234df.exe | 4 | 0x00F80000 | 0x00FC1FFF | Relevant Image | - | 32-bit | - |
...
|
||
rsfd234df.exe | 3 | 0x00F80000 | 0x00FC1FFF | Process Termination | - | 32-bit | - |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.32368782 |
Malicious
|
\\?\C:\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000\desktop.ini | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-12-31 19:53 (UTC+1) |
Last Seen | 2019-08-06 23:11 (UTC+2) |
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2011-06-03 15:16 (UTC+2) |
Last Seen | 2019-09-04 06:48 (UTC+2) |
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2011-06-08 00:23 (UTC+2) |
Last Seen | 2019-07-20 20:57 (UTC+2) |
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2014-11-13 12:24 (UTC+1) |
Last Seen | 2019-07-15 13:30 (UTC+2) |
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-06-12 00:42 (UTC+2) |
Last Seen | 2019-07-15 13:30 (UTC+2) |
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2016-07-07 21:40 (UTC+2) |
Last Seen | 2019-01-13 19:08 (UTC+1) |
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2012-10-11 18:42 (UTC+2) |
Last Seen | 2019-07-15 13:28 (UTC+2) |
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-06-12 00:42 (UTC+2) |
Last Seen | 2018-04-05 13:40 (UTC+2) |
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2016-07-08 05:45 (UTC+2) |
Last Seen | 2019-07-15 13:29 (UTC+2) |
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-04-28 00:00 (UTC+2) |
Last Seen | 2018-11-26 18:28 (UTC+1) |
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2015-11-04 08:44 (UTC+1) |
Last Seen | 2019-09-22 17:21 (UTC+2) |
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-03-17 16:07 (UTC+1) |
Last Seen | 2019-07-15 13:30 (UTC+2) |
\\?\C:\Program Files\Microsoft Office\Office14\1033\DBSAMPLE.MDB | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2011-06-12 17:25 (UTC+2) |
Last Seen | 2019-07-14 22:58 (UTC+2) |
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-03-20 15:45 (UTC+1) |
Last Seen | 2017-05-24 05:32 (UTC+2) |
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2015-06-10 09:24 (UTC+2) |
Last Seen | 2019-07-15 13:30 (UTC+2) |
\\?\C:\Program Files\Microsoft Office\Office14\ACCWIZ\ACWZLIB.ACCDE | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-03-20 15:45 (UTC+1) |
Last Seen | 2018-12-01 17:29 (UTC+1) |
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-03-20 15:45 (UTC+1) |
Last Seen | 2019-05-17 04:09 (UTC+2) |
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2014-11-13 12:17 (UTC+1) |
Last Seen | 2019-07-15 13:28 (UTC+2) |
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.msi | Modified File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2013-06-25 11:00 (UTC+2) |
Last Seen | 2017-01-24 06:02 (UTC+1) |
\\?\C:\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000\desktop.ini.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\BOOTSECT.BAK.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\BOOTSTAT.DAT.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Binary |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Microsoft Office\Office14\1033\DBSAMPLE.MDB.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.cab.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Microsoft Office\Office14\ACCWIZ\ACWZLIB.ACCDE.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.cab.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.msi.id[9C354B42-2275].[recovermyfiles2019@thesecure.biz].Adame | Dropped File | Stream |
Unknown
|
...
|
»