1.3
低危

113ed43a4c50eb9972777310c2ff9146474a9fc0d67bc3145a2303b5d1191a51

113ed43a4c50eb9972777310c2ff9146474a9fc0d67bc3145a2303b5d1191a51.exe

分析耗时

193s

最近分析

377天前

文件大小

122.8KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN DOWNLOADER JQAP
鹰眼引擎
DACN 0.12
FACILE 1.00
IMCLNet 0.66
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba None 20190527 0.3.0.5
Avast Win32:Malware-gen 20200106 18.4.3895.0
Baidu Win32.Trojan-Spy.Zbot.a 20190318 1.0.0.2
Kingsoft None 20200106 2013.8.14.323
McAfee PWSZbot-FEV!42E531299014 20200106 6.0.6.653
Tencent Malware.Win32.Gencirc.10b07a57 20200106 1.0.0.1
行为判定
动态指标
在 PE 资源中识别到外语 (2 个事件)
name RT_ICON language LANG_RUSSIAN filetype None sublanguage SUBLANG_RUSSIAN offset 0x000110b8 size 0x000025a8
name RT_GROUP_ICON language LANG_RUSSIAN filetype None sublanguage SUBLANG_RUSSIAN offset 0x000136a0 size 0x00000014
网络通信
与未执行 DNS 查询的主机进行通信 (2 个事件)
host 114.114.114.114
host 8.8.8.8
文件已被 VirusTotal 上 54 个反病毒引擎识别为恶意 (50 out of 54 个事件)
ALYac Trojan.Downloader.JQAP
APEX Malicious
AVG Win32:Malware-gen
Acronis suspicious
Ad-Aware Trojan.Downloader.JQAP
AhnLab-V3 Trojan/Win32.Upatre.R284255
Antiy-AVL Trojan/Win32.Buzus
Avast Win32:Malware-gen
Avira TR/Dropper.Gen
Baidu Win32.Trojan-Spy.Zbot.a
BitDefender Trojan.Downloader.JQAP
Bkav W32.AIDetectVM.malware
CAT-QuickHeal Trojan.GenericPMF.S6771081
Comodo TrojWare.Win32.TrojanDownloader.Small.PR@5276zr
Cylance Unsafe
Cyren W32/Upatre.IJ.gen!Eldorado
DrWeb Trojan.DownLoad3.28161
ESET-NOD32 a variant of Win32/Kryptik.BIYN
Emsisoft Trojan.Downloader.JQAP (B)
Endgame malicious (high confidence)
F-Prot W32/Upatre.IJ.gen!Eldorado
F-Secure Trojan.TR/Dropper.Gen
FireEye Generic.mg.42e53129901420de
Fortinet W32/Kryptik.BIYN!tr
GData Trojan.Downloader.JQAP
Invincea heuristic
Jiangmin Trojan/Buzus.bnwn
K7AntiVirus Trojan ( 0052964f1 )
K7GW Trojan ( 0052964f1 )
Kaspersky HEUR:Trojan.Win32.Generic
MAX malware (ai score=85)
Malwarebytes Trojan.Upatre
MaxSecure Trojan.Upatre.Gen
McAfee PWSZbot-FEV!42E531299014
McAfee-GW-Edition BehavesLike.Win32.PWSZbot.ct
MicroWorld-eScan Trojan.Downloader.JQAP
Microsoft Trojan:Win32/Zbot.DSK!MTB
NANO-Antivirus Trojan.Win32.DownLoad3.cjdyni
Panda Trj/Genetic.gen
Qihoo-360 HEUR/QVM10.1.6125.Malware.Gen
Rising Trojan.Waski!1.A489 (CLASSIC)
Sangfor Malware
SentinelOne DFI - Malicious PE
Symantec SMG.Heur!gen
Tencent Malware.Win32.Gencirc.10b07a57
Trapmine malicious.high.ml.score
VBA32 Trojan.Fareit.2883
VIPRE Trojan.Win32.Generic.pak!cobra
ViRobot Trojan.Win32.Upatre.51256
Yandex Trojan.Agent!d/6CB0IKwU8
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2013-08-28 00:13:37

PE Imphash

5f259a07286d0de03289b72c296c1693

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.MPRESS1 0x00001000 0x0000f000 0x0000f000 4.199281949913939
.MPRESS2 0x00010000 0x00001000 0x00001000 5.403997491840931
.rsrc 0x00011000 0x00004000 0x00004000 4.459709332491716

Resources

Name Offset Size Language Sub-language File type
PNG 0x0000c138 0x0000077c LANG_ENGLISH SUBLANG_ENGLISH_US None
RT_ICON 0x000110b8 0x000025a8 LANG_RUSSIAN SUBLANG_RUSSIAN None
RT_GROUP_ICON 0x000136a0 0x00000014 LANG_RUSSIAN SUBLANG_RUSSIAN None
RT_MANIFEST 0x000136f4 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US None

Imports

Library gdiplus.dll:
0x407148 GdiplusShutdown
0x40714c GdiplusStartup
0x407150 GdipDrawImageI
0x407154 GdipBitmapGetPixel
0x407158 GdipGetImageHeight
0x40715c GdipGetImageWidth
0x407160 GdipDisposeImage
0x407164 GdipFree
0x407168 GdipCloneImage
0x40716c GdipAlloc
0x407174 GdipDeleteGraphics
0x407178 GdipCreateFromHDC
Library KERNEL32.dll:
0x407008 GetStringTypeW
0x40700c MultiByteToWideChar
0x407010 LCMapStringW
0x407014 HeapSize
0x407018 RtlUnwind
0x40701c Sleep
0x407020 IsValidCodePage
0x407024 GetOEMCP
0x407028 GetACP
0x40702c GetCPInfo
0x407030 TerminateProcess
0x407034 IsDebuggerPresent
0x40703c GetProcessHeap
0x407040 HeapAlloc
0x407044 ReadFile
0x407048 CloseHandle
0x40704c HeapFree
0x407050 WriteFile
0x407054 LoadLibraryW
0x407058 GetProcAddress
0x40705c HeapReAlloc
0x407060 FreeLibrary
0x407064 LoadLibraryA
0x407068 GetModuleFileNameW
0x40706c FindResourceW
0x407070 LoadResource
0x407074 SizeofResource
0x407078 LockResource
0x40707c GetModuleHandleW
0x40708c GetCurrentProcessId
0x407090 GetTickCount
0x407098 HeapCreate
0x4070a0 GetLastError
0x4070a4 GetCurrentThreadId
0x4070a8 GetCurrentProcess
0x4070b0 GetCommandLineA
0x4070b4 HeapSetInformation
0x4070b8 GetStartupInfoW
0x4070c0 ExitProcess
0x4070c4 DecodePointer
0x4070c8 GetStdHandle
0x4070cc GetModuleFileNameA
0x4070d4 WideCharToMultiByte
0x4070dc SetHandleCount
0x4070e4 GetFileType
0x4070ec EncodePointer
0x4070f0 TlsAlloc
0x4070f4 TlsGetValue
0x4070f8 TlsSetValue
0x4070fc TlsFree
0x407104 SetLastError
Library USER32.dll:
0x40710c DispatchMessageW
0x407110 TranslateMessage
0x407114 GetMessageW
0x407118 CreateWindowExW
0x40711c RegisterClassExW
0x407120 LoadCursorW
0x407124 DefWindowProcW
0x407128 FillRect
0x40712c GetClientRect
0x407130 BeginPaint
0x407134 InvalidateRect
0x407138 PostQuitMessage
0x40713c SendMessageW
0x407140 EndPaint
Library GDI32.dll:
0x407000 SetPixel

L!Win32 .EXE.
.MPRESS1
.MPRESS2
UQVEPF
MVR^_]3_]
UQEPQE
YY]jXh@
8csmu*x
YYuTVWh0"@
3]j h@
uhd{@
3PPPPP
@Y<v*Vb
^SSSSSyj
;tFtA3
M_^3[O
S^`N`H
j$Y~\d9
QY^`[_^]
VW39=,@
t.t$<"u
3Y[_^5\@
3PPPPP
FA>\t>"u&
uUEPSS}
=?sJMsB
Y;t)UEP
3wf93t
f90uW=p@
VVV+V@PSVVE
E;t8Pa
YE;t*VVuPuSVV
j@j ^VF
H3H/5 @
;rSWf9M
YYt:V5H@
YF\={@
~lt#WS
43_V5Xp@
YYt0V5H@
1E3PeuEEEEd
Y__^[]Q
E_^[]E
9csmu)=
E3E3;u
F$|3@_^
h3G}39
Y+t"+t
+tY+uC}
Uw\]Yp
u>OdMGd
uwdSUY
ffffffE
3PPPPP
UQSV5p@
;r>PuA
B(;r3_^[]
1E3PEd
tAt2t$
t?P5L@
3M_^3[
ft'Ou"+
jPfDJXdf
^06_^]
WPWPWv
j kYrj
whu;5@@
8]tEMap<u
TM_^3[j
QM^}_hu
YYu,9E
3W;to=@
fYY~PE
PAY9_t
t4V0;t(W8jYt
Fpt"~l
j mYtj
lVYYYEE
nYuSVWT$
URPQQhC@
t;T$4t
;v.4v\
UVWS33333[_^]
33333USVWj
_^[]Ul$
DDDDDDDDDDDDDD
S3VW;~E
@;u+H;}
39](SSu
]9]tWuu
};~Bj3X
3;t?uWuuu
t"SS9] u
EWMYuDEYe_^[M3
Mu(Eu$u u
ES3VW]9]
39] SSu
EYe_^[M3x
Mru$Eu
woVW=@
Y3MW0u
v(v,v0v4v
v8v<@v@vDvHvLvPvTvXv\v`}vduvhmvlevp]vtUvxMv|E@
PYv4;5@
PYvL;5@
V~Y^]USVWUj
P(RP$R
t:|$,t
;t$,v-4v
UQPXY]Y[
FGIuX^_]
KuZUQL$
@;r[_^U0SVWEP
N<|1x\1xUR
WSVMEVirtEualAEllocE
EEPWSVMEVirtEualFEree
(MuMEt,
SU_^[]
vl39\$
V=T$ Vj
UdSVWD$
t$LD$PY@
t$Tt$XT$\t$`
D$\D$@Pt$dt$hD$l
VVVT$0R
VVVT$0R
:++;sNq
V33M9C
r_^3[]
EP_^[]
UQSVW=
@;rUQV
3+t8Ht
gdiplus.dll
GdiplusShutdown
GdiplusStartup
GdipDrawImageI
GdipBitmapGetPixel
GdipGetImageHeight
GdipGetImageWidth
GdipDisposeImage
GdipFree
GdipCloneImage
GdipAlloc
GdipCreateBitmapFromStream
GdipDeleteGraphics
GdipCreateFromHDC
KERNEL32.dll
GetStringTypeW
MultiByteToWideChar
LCMapStringW
HeapSize
RtlUnwind
IsValidCodePage
GetOEMCP
GetACP
GetCPInfo
TerminateProcess
IsDebuggerPresent
UnhandledExceptionFilter
GetProcessHeap
HeapAlloc
ReadFile
CloseHandle
HeapFree
WriteFile
LoadLibraryW
GetProcAddress
HeapReAlloc
FreeLibrary
LoadLibraryA
GetModuleFileNameW
FindResourceW
LoadResource
SizeofResource
LockResource
GetModuleHandleW
EnterCriticalSection
LeaveCriticalSection
GetSystemTimeAsFileTime
GetCurrentProcessId
GetTickCount
QueryPerformanceCounter
HeapCreate
InterlockedDecrement
GetLastError
GetCurrentThreadId
GetCurrentProcess
IsProcessorFeaturePresent
GetCommandLineA
HeapSetInformation
GetStartupInfoW
SetUnhandledExceptionFilter
ExitProcess
DecodePointer
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
EncodePointer
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
USER32.dll
DispatchMessageW
TranslateMessage
GetMessageW
CreateWindowExW
RegisterClassExW
LoadCursorW
DefWindowProcW
FillRect
GetClientRect
BeginPaint
InvalidateRect
PostQuitMessage
SendMessageW
EndPaint
GDI32.dll
SetPixel
8Muex<
KERNEL32
VirtualProtect
G(XPTPjxWXt=
CorExitProcess
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
NtQueryInformationProcess
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
IDATXGW
KeN='0gB
RBegrgw[(D
b/b(v<\L}:
UkbI<,O#D1!'
A1bkj1ZJRc6
7mP(Ct
U;_Bg@
%G&yIC^P
w@{d#$
{45!]5!
0b5[8}3#8>$b[ZuK
g'C{9d8(t
U<8}PJ
l/ob5`mg>
l/|@;p
HX9Ept?
~SSc'm,}Y
.Nw-fu
\TzYx*D.evx
pC,oDCf[
%d\J:GC
Tu<47@$;TE6w/H
u,Ya,+u{
x[<un|Nc #+|^
]s,%aEx
mPJ2cRY
;8paB9|
|AQ1^
w(>hYS
.YAM^mXgx
]ym~6~9[9|qoxf?c
l[(Kd8y
IENDB`
PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
GetModuleHandleA
GetProcAddress
KERNEL32.DLL
gdiplus.dll
GdipFree
USER32.dll
FillRect
GDI32.dll
SetPixel
lQ+QQQf
UWVS|$
t$dD$\
T$L3;\$L
t$t#t$lD$`T$x
D$t#D$hl$x
D$t+D$\$
D$@d$@L$@
;s#D$H
t".)D$H+r
)D$H+r
L$H+t$`+
T$8L$PL$xf
D$\l$TD$X3|$`
D$`L$D
;s`)L$4|$4
t$4D$H|$t
D$`D$t+D$\
l$8f++
D$T&++f
T$TD$PT$PL$XL$Tl$\D$\l$X3|$`
;s/D$H
;s;D$H
)D$H+f
t$(Nt$(uL$0
T$,|$`
)D$H+f
l$$Ml$$uP
)D$H+f
$L$ d$
p4$Ft$\tZL$
9l$\w`$
BD$tIt
|[^_]_
AAA'DDD)<<<*<<<*<<<*<<<*<<<*BBB*BBB*BBB*DDD)>>>)>>>)>>>)>>>)>>>)>>>)>>>)>>>)>>>)>>>)>>>)>>>)>>>)>>>)>>>)>>>)>>>)>>>)>>>)>>>)>>>)???$555
`mw\h[g{{
hst~eq`lJX1AN[{
hsIWHVt~{vxy{{
ep^jiu{
gs^jmx{
itju`l{
IV?Nx{
xyGM8?QVoqx
**rrNN
nntt,,""llYY
$$}I___
##DD}}
;;ff77..55gg33
ccvvdd
xxx$UUU
;;ww~~))ssooHH
::ww{{PPhh==
11DDDD++yy
//??88
((??77""
++@@??++
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
gdiplus.dll
GdiplusShutdown
GdiplusStartup
GdipDrawImageI
GdipBitmapGetPixel
GdipGetImageHeight
GdipGetImageWidth
GdipDisposeImage
GdipFree
GdipCloneImage
GdipAlloc
GdipCreateBitmapFromStream
GdipDeleteGraphics
GdipCreateFromHDC
KERNEL32.dll
GetStringTypeW
MultiByteToWideChar
LCMapStringW
HeapSize
RtlUnwind
IsValidCodePage
GetOEMCP
GetACP
GetCPInfo
TerminateProcess
IsDebuggerPresent
UnhandledExceptionFilter
GetProcessHeap
HeapAlloc
ReadFile
CloseHandle
HeapFree
WriteFile
LoadLibraryW
GetProcAddress
HeapReAlloc
FreeLibrary
LoadLibraryA
GetModuleFileNameW
FindResourceW
LoadResource
SizeofResource
LockResource
GetModuleHandleW
EnterCriticalSection
LeaveCriticalSection
GetSystemTimeAsFileTime
GetCurrentProcessId
GetTickCount
QueryPerformanceCounter
HeapCreate
InterlockedDecrement
GetLastError
GetCurrentThreadId
GetCurrentProcess
IsProcessorFeaturePresent
GetCommandLineA
HeapSetInformation
GetStartupInfoW
SetUnhandledExceptionFilter
ExitProcess
DecodePointer
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
EncodePointer
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
USER32.dll
DispatchMessageW
TranslateMessage
GetMessageW
CreateWindowExW
RegisterClassExW
LoadCursorW
DefWindowProcW
FillRect
GetClientRect
BeginPaint
InvalidateRect
PostQuitMessage
SendMessageW
EndPaint
GDI32.dll
SetPixel
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
@Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
KERNEL32.DLL
WUSER32.DLL
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
((((( H
h(((( H
H
@ntdll.dll
KERNEL32.dll
MainWClass
Sample
@@@@@@@@@@
@@@@@@@@@@@
s1c1tjl.exe
C:\EtyI3k7I.exe
C:\xYpWD3Ft.exe
C:\zrsu2jKZ.exe
C:\V4qooVnJ.exe
C:\ZLUTSaoF.exe
C:\rcvse5cw.exe
C:\i3cAk6qd.exe
C:\tqzdJHVO.exe
C:\eCktNDw3.exe
C:\jYZSwghs.exe
C:\rClut4rP.exe
C:\13c2622b7e6fac067eb684b20c6764ee0d6e2a2ebc20c2bef48b8f777298e318
C:\Documents and Settings\luser\Desktop\NEaBSmiW.exe
C:\5bc0f0f5e2e7be667d523882e79544fe1fac076711bce402736ed2ef1dfeab74
C:\Users\Lisa\Desktop\T5JnRAE5.exe
C:\a85f756359c2fb865ce2df4795571d87886afeede265f1df06929fa13111bc48
C:\870aff79cf51f7673ac6a8824bacea13c8f7bfd454786d03a3f6c8394dd93cda
C:\Documents and Settings\Administrator\Desktop\lXFI7EmP.exe
C:\70f2f10e6030234bde7b8dcb2c6822c14cc1a87d8bbd124bfbe03f01abb6aafc
C:\Users\Lisa\Desktop\CKwh2VvB.exe
C:\UBiApEWG.exe
C:\f8bb3f83cd5caaf22e6dcec4e997ba850fb3b9d0d2e7403762cf17a96aa8178b
C:\Documents and Settings\Administrator\Desktop\2ALxxLtk.exe
C:\135e78bbbc6fbf1e9773087c111fef40d19e1043f3340a872338b0ebdf56d917
C:\Documents and Settings\Administrator\Desktop\3FPaPx0A.exe
C:\56f9a6fa65fb169959f1c656d2cc5feea7cd5b16506f5f71296665f20b303542
C:\915f275a4fca40a60e6780f54731ae5a17ec999adff933e30470e1e1b9426725
C:\a20eb5734953a08f05f5a8e6d2ef92b67513640f5be6545be8c01569f4d3e1e4
C:\2MnMcoZx.exe
C:\Users\Lisa\Desktop\ZsufC3Cd.exe
C:\2f1523ae566bd98ca85f62508969051740c105d863babd9643a9ef5dd0c50989
C:\ab3df8bfbacb20d5ed517afbf28ff994fdab9c1bd848c85b86ffcaa533256414
C:\Users\Lisa\Desktop\HHmsZQ7U.exe
C:\08864318cc3a45fc5f3a64ed9f2a3d8d543aef4fededd800ec269ada20518af0
C:\7442276d56c1d8bd73fa37403c33e4d9bde38e4570a90641eb18551d77402deb
C:\c12d91cdac893eb13fd88751776cb58b8f1ff74263d0481e90498c23eb64a606
C:\Documents and Settings\Administrator\Desktop\hIJOQyGo.exe
C:\4551d2b5aaa408dbfd202569c8bc1abf4ea6329e200f16d3462fb6242ac36e33
C:\Documents and Settings\Administrator\Desktop\F0ObeRYA.exe
C:\57f2b94ba5a09182b751c53ad9815ae272db4687560d7d16bc2e6b460fa6f942
C:\Users\Lisa\Desktop\WA0l0zpU.exe
C:\76726ce2fb1894f7ada6c5afd4a8e04f2ed5aeb5a3979adad39cf11ef958042d
C:\7b2103505510501a0d51c7d37c367cd47b5e47a028f3f1a24057144af158d4f2
C:\Documents and Settings\Administrator\Desktop\drvuy8ld.exe
C:\wJzw_nIS.exe
C:\Users\Lisa\Desktop\EisuPvou.exe
C:\3e3d2f0463f71c8de6f85e29858a48bcc74245b3f831a06dd631c50b37fb426e
C:\72f0c4d9dcf10a21cdbdce589be98e7bd5243020162ecde4cac555b9ad7988e0
C:\Documents and Settings\Administrator\Desktop\eXiBCoEr.exe
C:\470f57eee8da0bc76f60f7e61138cc975b80761bfaaa94f21c1573b454a00749
C:\1eea93bf61f733c1d27e5776d73869b52446d11b807bb9411d58c1e1f9478417
C:\83360e264e33745276d3a3ae9bc9c1933790f9fc054cdbd5d013aa35abc03ad1
C:\Documents and Settings\Administrator\Desktop\IJZRhak4.exe
C:\35c815afb60708ce892616c7b1564ab887544683756c758c996bb4554224b12c
C:\Users\Lisa\Desktop\gZKtWtmf.exe
C:\aek1Nhk0.exe
C:\2193177d02a938f14a950e5d7a4f9938b8fad3cf84257cb4560fdb100b1f3808
C:\Users\Lisa\Desktop\Yz8J5yxi.exe
C:\26b9dda33cbba239269eb9ba45668d7c256f38d60fd5d4c2dc8f2b8a36c4cb0e
C:\bbaa748bde4faae3078f35f203b897fd4cf69b7fd3415e57cea7c1c21af93520
C:\e6b73698b30d342c798eb1c0bc9d27062042d34e0205b132bf4a0f651e105319
C:\Users\Lisa\Desktop\nuTQ8gIC.exe
C:\3311cc5c8139785ae22fef214ba0040ae8d176f2fcda9cbb0720a709f84934c1
C:\Users\Lisa\Desktop\p11PZ5Qh.exe
C:\CGxjhz_y.exe
C:\a0aebe38dcf7338d9900fb23a8251db6e6cb92f02d9c5a23e37337b8e0d104ac
C:\54c1a8ce700a7e1edd897f17e90603f45e6045296c13295532bfe464b2bb0705
C:\Documents and Settings\luser\Desktop\OOgbLAgN.exe
C:\Ly7gqs9l.exe
C:\Documents and Settings\Administrator\Desktop\YbK4Rf8n.exe
C:\kUl78BIa.exe
C:\41a847af6eba3e7d10dd5cce0ef52ef3c5defb87b72c0dbdfa99c78709fefc12
C:\Documents and Settings\Administrator\Desktop\fRep9gtP.exe
C:\SDUMGOfN.exe
C:\d31aeacda477167ba3403cae3eb6b1237de69d4f32d3dbedf5abfb49b79040cb
C:\82f5f024fd4653b344b56adf471722c1e984a4648586caeac87784eafbe0d4d6
C:\Users\Lisa\Desktop\wjyrP3fm.exe
C:\5bZsroFC.exe
C:\7ad4ed66dbe77eb394930fc636ffd93a4be627e4b46f68368c5ca9400146267a
C:\7erzPEvW.exe
C:\Users\Lisa\Desktop\Rr864Ibk.exe
C:\lOTWmzGr.exe
C:\fe7d861e6efe6a6598a0e05837d4eb0957d636fd094216512200daa88e375e3a
C:\c56a6338d55b990b6a82c41feb55a8afcc2535bd3028fe4c3acaf21fddabaeff
C:\2bb2e12037d9cfc76b49067a7461d9bf77301b1a9d9dd927f6cb870d42458f92
C:\pZ3ljJ2N.exe
C:\Users\Petra\AppData\Local\Temp\file.pe32
C:\ad6b0a2ab13cff8038a67723e2d79ebb5d2c090fc8b0eefc1a11374babb2aed8
C:\9f51ed70b4ab74e846dca7e02bbeb38159b788812ed84e8b469b165a6284c3b8
C:\4156145a703fda924fb5b4b996111a6d98af17b0d63b94fe5acb4ea7165796f2
C:\d6dd1b6c62838b2a70cd0d9dedce92cf92ed494e8cda9cae98cf67799accd0bc
C:\_KBtu1Fz.exe
C:\eef3bb65c826c7103f4df8df03044863be25ed9ea47ad9fe36d9a59a124dbb46
C:\c0473968946fb6077774b5ab1f49974f7487076bbfbae3ade9a606845c2c294e
C:\Documents and Settings\Administrator\Desktop\QusFSIoF.exe
C:\819e8eee2d4158e7195e8b57880f8e1163fae446150e3016de6213389c4fe706
C:\Users\Lisa\Desktop\Xhy9Vd2A.exe
C:\0f058310ba395856c8b6ca3edfbe2a7733c283af0d8b77b5a0aded56ad24bf14
C:\aafc7669f602ebffdf279bf134f9c96b016eedb9a1e2211aaa389bf6b95a4b6b
C:\Users\Lisa\Desktop\mFHuJb1O.exe
C:\435980c11e0f6a1998cf59b40f0bf9d8fe66e7ec34180b51a47561a976b0768a
C:\Documents and Settings\Administrator\Desktop\WZ6I8CZW.exe
C:\7efa90bc2c3e1da14943d7fba573671e378dc153c563ea60438e1c1433cc3f7e
C:\Documents and Settings\Administrator\Desktop\xq1zaqaF.exe
C:\c2c39beebdebce40ed813dd0080ee363851c667be601794fb1fc017f212a1d00
C:\3be2d395d397d7c5cefd4f2b48ffec54fa26a580df6e87f9a8de377013c9ef09
C:\Documents and Settings\Administrator\Desktop\PCVo2L74.exe
C:\OnFUPi8y.exe
C:\Users\admin\Downloads\factura.exe
C:\Users\admin\Downloads\invoice.exe
C:\Users\admin\Downloads\important_document.exe
C:\Users\admin\Downloads\sample.exe
C:\cb515a95ad6f0996f849e1701747d381033a5c31cae1e8fd8515e3bf85814321
C:\Documents and Settings\Administrator\Desktop\k9xVawGW.exe
C:\ce0beb9e43c3df7c218a2aafd205d6e0096b8b803ac10c04201318c41a389b60
C:\Users\admin\Downloads\factura.exe
C:\Users\admin\Downloads\important_document.exe
C:\0b151f6e85fd6e1a37aa08adbfbbb211273b387706c1b7308aaba0cdd1174086
C:\Users\admin\Downloads\factura.exe
C:\Users\admin\Downloads\important_document.exe
C:\ec848224ae8a3b79ca9ff0871bad32ab4fb4b0038620cb28a166002e8c79451a
C:\Users\admin\Downloads\important_document.exe
C:\152fae7da6fc63a3b9e8131aabcf574b87ff0a21843829de92245fcc75ffa1ff
C:\7246036946297f2eed19d976d052bc2f4f0b6cbed187695ec0d6463088d8431e
C:\7d2c54a2d742d43e22bb7391dfe18b277972402aeb52fa715abd94cfbcdb64a2
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\c222c28bbbbd25685dbc07374357e7e7680ba55fb360538607e39a06fbcb6bbb
C:\4rILg9au.exe
C:\06a10e0ffb099be084fd718d01e1cf2c492d57f696880a13ea57e61c586a57e3
C:\43dd31c082547cf92eae0a9369ddad657a69beb118578e37f7d6a3e4299767a8
C:\xyZcG0_Y.exe
C:\Users\admin\Downloads\invoice.exe
C:\294777a94b44b116dd9317e4dc5c2026b99caca8cd9be138b36b743f011e6bd8
C:\620fe8f134eab9467f19a4bce66f578fefb2650ad8a26fa2139ad2228ac60478
C:\2daff9e4a471027b2c142ee854baa8645d42af263e6800cb6b87e6627003fd6b
C:\xVC3JXAm.exe
C:\Users\admin\Downloads\factura.exe
C:\Documents and Settings\Administrator\Desktop\EpdMA6Jg.exe
C:\df07564e2ac7407ea6b1042668250028e0b1a51e1cffa22d0e3d2f4b3ec32f22
C:\Users\admin\Downloads\hcbnaf.exe
C:\a480fbf57aca92148d9ffdadc2fe1698dd2be64b257fbce1d523dc9d23878559
C:\9b27453f252079ce2400aa7b0d19846674643cd74ce69c35589600fc36687dc2
C:\95ea6d1159c524c1b49b0c652fa8f18c5d1b12c0c12fba81877a2d7adfc2f9e7
C:\Documents and Settings\luser\Desktop\XhwAcDu8.exe
C:\Users\admin\Downloads\795e8955a9bed6785176cb2851c63425fcc15c8e93b82b2c96fc4a2c1dc26182.exe
C:\Documents and Settings\Administrator\Desktop\W1GnEiMF.exe
C:\93af18a75dd8c4f311642e0a26d57a6b690944ceb98c880d1d513b31f8253c8d
C:\Documents and Settings\luser\Desktop\poLnXYUy.exe
C:\Users\admin\Downloads\421703e95a17af599309ce294a72989b93a070d4d9513d7215418862d40cd6d2.exe
C:\da25ee2529c7e5828e12845d6444dfcbe878847019c893bf75e9983f935187a9
C:\Documents and Settings\Administrator\Desktop\FX0TDJf5.exe
C:\63af94a61e6c0b3d63eea8dcadff7cdcff0403906becab347b22d9024c080058
C:\4bf185ab7be99d093c93668425718983776bb80a669ccd49c91243a594ceda5b
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\2a981d126f000f6bbd39fa8cd0f47bf92854200127ba2bfc7ca29bdc05623513
C:\Documents and Settings\luser\Desktop\jQ1taLtt.exe
C:\d2da34ed12dfba65380470e7a9ed3743594a1c4b446fd6bfe8b07f079d4c0815
C:\Documents and Settings\Administrator\Desktop\TkEdrLX3.exe
C:\3ad6faa4373d77536ac2c2bef73819fa3fd45d9c5b73ee7e413c1ac90c872e10
C:\Documents and Settings\luser\Desktop\MnI02U35.exe
C:\Users\admin\Downloads\c5f5a65c31190647decf8033326c024b0755399cfa1df23a84c24bc9f51784da.exe
C:\Documents and Settings\Administrator\Desktop\pEuiSWfB.exe
C:\Users\Petra\AppData\Local\Temp\.pe32.exe
C:\Users\admin\Downloads\909d7e38b7ebd1fb_hcbnaf.exe
C:\fef8278ae231a84aa831027ba69f9671361dbbabedf6d0a32f680aae28750e9a
C:\e71894a663f93531f6cc4a094069d18ff28f4353fed0db938e5037ca55ad35a7
C:\f0af46ae6f14944b2442116e3b2be018584e2a914e054e95fb895430c9c77dd0
C:\5e90f30ccf7b6186109308ad18c1ad2a7519862716bc38bb0b315fc21c200083
C:\b12665894cde3267c6aa4d029cdaa3bca86c769cc0c6ff7e1105b7803d664a75
C:\6cde116930f872fe543edc10b7fbbf65e7c507e1fba042cce23d6ff6b977701d
C:\Documents and Settings\Administrator\Desktop\1ChFTdip.exe
C:\Users\Petra\AppData\Local\Temp\.pe32.exe
C:\Users\admin\Downloads\8553719b0a207c7d_hcbnaf.exe
C:\6f22345fb13f19bc9e10a76037213ff21a19cde7f8299b3a90a9b3cc8997d8cf
C:\1a6f3749723302dfb9d6462d8ff02e09a545fdef624f3daad33be8b539a55338
C:\Users\admin\Downloads\hcbnaf.exe
C:\563d8da6c37dfbc4692b9c92908583bef680e24bb2115373914589da9080d1a2
C:\f9600fa2216006e231a05e64ddfe1290cf5c29946fd6017081406a17411ebdb4
C:\a0f7d9a1157bb791d8f59bc9b6521e5fe82cd611873c51c0d3d59c42a81e0e85
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\Users\admin\Downloads\71249ec83fbca157_hcbnaf.exe
C:\Documents and Settings\Administrator\Desktop\eFT66Kmw.exe
C:\Users\Petra\AppData\Local\Temp\.pe32.exe
C:\91966b6ab6dbd3460d8a09fde8a9de3ebe884af1e5c092b68f8d1c5a5d156f75
C:\Documents and Settings\Administrator\Desktop\kwwGFmjq.exe
C:\90f5f759d9f906954706233f2e32b0efc72db3845496026d6e9b973234db7fd2
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\Users\admin\Downloads\8d9304ab65c2b241_hcbnaf.exe
C:\5098822db10b277541de8b249010f3d480ccfadff89d9907cdcb9abda975b7a6
C:\f7633526bbbe43ce409d1004a0a3e85543acb5b3673001d51fe690642b9f8b12
C:\Users\admin\Downloads\hcbnaf.exe
C:\Documents and Settings\Administrator\Desktop\H1w5Im3d.exe
C:\f5c2480ec09efef6490f2355d2c76af177c492c132083cdd789a7cca5ba15beb
C:\Users\admin\Downloads\hcbnaf.exe
C:\2964e1f50132f485094ae2ee5612bcb2190c999873c2fd62136ba8789aded5c9
C:\3ac6ca9bd623c693fbb671b2b46a373e2d71ebbb43e9a817f0716bdc76a8a433
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\fc12427585ab6b61948ca31ab04d929b4c8a42f3c84ff01bc316e22a62c1b29b
C:\Users\admin\Downloads\hcbnaf.exe
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\00bc315a46485fe25570bafd92c592b7a51814369f1eb57eaffbcab88f387702
C:\Users\admin\Downloads\hcbnaf.exe
C:\d1a39b02e782707c993ed8868483f923b9ebc0de671c45f43f2f3a18fd159988
C:\17ad9910f473c59d50b569c66538526025a48887b62c5e10dc8bace2509a31c8
C:\3c2290d7b4f3a736884fca5c0f026f012851507d65c68b5e575a699eb58171c6
C:\Users\RA491~1.VUL\AppData\Local\Temp\c27ef6a5b05487ea0da2966035a01ec1.exe
C:\Documents and Settings\Administrator\Desktop\xIBTs9NC.exe
C:\5e068175f607f62a25f3b100838100d5b50937e49516593aa6a39311d82011de
C:\Users\admin\Downloads\hcbnaf.exe
C:\6506564e0cf1095129c52df63c87eed2a74d1043ec84bdf5bfc07f85502300bb
C:\0b9f6241b0f50a0e625327918f24e10b9bd8f465f2d9a41a5ff1b2b01984ede4
C:\Users\admin\Downloads\hcbnaf.exe
C:\3312ecb413bedf022317a6c66a31aec1a0d182a50f2e0380f08058ce658ac75c
C:\27e63dd0033cfefb601f2f6b8a29a43fce7fb0a3bd7be39c3a686a85cfe88dd9
C:\Documents and Settings\Administrator\Desktop\30wyZnUG.exe
C:\Users\admin\Downloads\01edf31399dd217b6eb878964bb3471ae5f24a6c84296d8872feefed28af1aef.exe
C:\Documents and Settings\Administrator\Desktop\tRI02FnA.exe
C:\921f3df1e9eb8a63080c1f5a46d1a6d3f9c28a4520ebf5750d6c4275734cd301
C:\f1a9d36d18175fd55bb4e9232e5bd9eb4574c359e870ca9913fd8693dd8975ac
C:\Users\admin\Downloads\hcbnaf.exe
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\Users\admin\Downloads\5bf3efd9f452f03e_hcbnaf.exe
C:\fad49da8ff55e48c06d57335275148a55e84786e0bedfdbf60469abc215e5e82
C:\b198b63b9d44f02934c0b66149c796b8f9bc3e7c3fd0d93c2ccc2d7a9fbac030
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\e114a6baa2456836c2b54435af7a816db32c3118613c7eb69025cef469432d15
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\96a4b799c1e0fa295fa702b44b0e763edfaa33f42761e782b15c0b3059c08815
C:\bf93abdb8adf2fa46312faef74aaa161de021a1ef4449e4a225f33ce3bb371c1
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\498c3636667a957115dc038a32522585d7643d978fb2906b6dcf82dbccd0ef35
C:\Documents and Settings\Administrator\Desktop\5Spr26n1.exe
C:\bd9f62e96a38c67d6a122cab8ffbd011863d8ee3141e70d4c427aefcc3ee9f13
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\Users\admin\Downloads\2f7d25bd6bec9f01_hcbnaf.exe
C:\Users\Virtual\AppData\Local\Temp\96f29f6a69a6bb3fb7ad3685ccb678a4d25eb0379b436920ba7673b69f55eee4.exe
C:\Documents and Settings\luser\Desktop\CgLMrqc1.exe
C:\Users\admin\Downloads\82378330003177479002e32990bf3fef5f3699b095850056c7c09c9a9eee7058.exe
C:\bff7f91cfc550102e6ea785d17948af5bbc7e5a729d365326cb3eb5314ea13a2
C:\Users\Lisa\Desktop\GnCPX0IM.exe
C:\Users\admin\Downloads\d69e23220eb4998795b9c0ae5cad8406201a3283d0ae9affa06b0a7ac06076ba.exe
C:\75e85edefd0e84ff753d331754b5e66e034a7599750607960bdbd720d815f1ed
C:\5c6673560734e946658e648b8da322b2bbd5fef7769c027f0e75b1e635eae0e7
C:\Documents and Settings\Administrator\Desktop\902VBtMU.exe
C:\f5d66f51771964da1e5343e5d585cee67003289d9f514af07778beabe8993bba
C:\Users\admin\Downloads\hcbnaf.exe
C:\Documents and Settings\Administrator\Desktop\kXCMlHwH.exe
C:\Users\admin\Downloads\cf43609ecc60ddcbc94493a8b8aafa1a57c2b44463a82436bc2b61ebadcd71f1.exe
C:\25b459d8586dc767f00b9293e218df85fdb330aede24bd25cf2445e17836cbde
C:\Users\admin\Downloads\hcbnaf.exe
C:\Documents and Settings\Administrator\Desktop\bXI5fJHc.exe
C:\Users\admin\Downloads\73883ee46de58493f0bc3096544ddf1dca3a6886971228e7fa986ec9abde781b.exe
C:\Documents and Settings\Administrator\Desktop\Ju4u9hXB.exe
C:\aa40104076a3557f2626ae443bc4f938f6f93d694405b3a95ed21505bd1b2985
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\Users\admin\Downloads\5ec0f7710743bec4_hcbnaf.exe
C:\81dac081bc1397daff59de60521216b4f53e0f77ae781eb1fa1a775ac5a97582
C:\Documents and Settings\Administrator\Desktop\ZQIbmk6P.exe
C:\Users\Petra\AppData\Local\Temp\.pe32.exe
C:\17f20f7b837d338364c1b454c62324b888441773af1e230bf78e4eef7627c7db
C:\da7a1a6e0a98035f2eb0e109c1680c8b427d2011b75b48a1de7437470c1c638d
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\Users\admin\Downloads\31a2ef2a3ea762f0_hcbnaf.exe
C:\8502395f578ae4064d58a3a54fc4fe15d42cbf816e50ac876bfe196413e1b7f5
C:\Documents and Settings\Administrator\Desktop\s09wM30L.exe
C:\0503fe2beed2a348f041d717e61a2f8d28c19ec90ebd6c31868ea9f361509c0e
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\c373e1de42c2664727d20001d8de2eb93a7ba3861a5a8ebb681344d4a52801c0
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\78023f3ec53ae7fe1b7c6a776808623fff09e47556dca236d272531ce6c81718
C:\b2ce70ada7370872dca70799bebb590e32ab1e48bb81bbbfd4a50030484e3f76
C:\Documents and Settings\Administrator\Desktop\qOGScud9.exe
C:\Users\Petra\AppData\Local\Temp\.pe32.exe
C:\Documents and Settings\Administrator\Desktop\zHI5Twz6.exe
C:\8904d96bea25c205afef6c5ecc8639ca2e5c9015457308de5d9d7e20788a3e0d
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\Users\admin\Downloads\006f09c34cc030ca_hcbnaf.exe
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\Users\admin\Downloads\5030694d2b724a00_hcbnaf.exe
C:\15f23f88bd742ceaac2d179973654c2677055d557d9e3d228379d962ee657837
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\c2a191ad3adc47b648ba496c902e1a1f1a5ab806fbc8c0d7c1b24b411614b81c
C:\9da283de2316da3e12582c59f6ecf1219add845fb537c527f86175289cc49f0e
C:\Documents and Settings\Administrator\Desktop\bwXCtOXI.exe
C:\97d592d513169bd9fec973acf3d38f283677ec2f56833d5c7f4c3a67733f6a60
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\Users\admin\Downloads\3264bce2e6951181_hcbnaf.exe
C:\Users\Virtual\AppData\Local\Temp\763d02f8fa956ca8596fed45bbc1433e02bf2a7984865ebf38b56995f33a154a.exe
C:\Documents and Settings\Administrator\Desktop\pLWlEJl9.exe
C:\17ab0038030e04921647a5b75cf451b3477cd0b7a4a76be67c88f2d46dc7d4aa
C:\Documents and Settings\Administrator\Desktop\tj7jGlXh.exe
C:\Users\admin\Downloads\168503ae3e36d547ff4be496b2c03671072fe550d9b580061794ca0bd87f7652.exe
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\e158cd5b97893e77bda1b1e0326a87943c7bc7568f2dc526a94d14e1dac78415
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\Users\admin\Downloads\a6421dfbba4937b4_hcbnaf.exe
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\Users\admin\Downloads\6060f8a8f5a6b7c3_hcbnaf.exe
C:\Documents and Settings\luser\Desktop\hOTSNtKL.exe
C:\Users\admin\Downloads\35eeea61c44185d6767886b936cb206ac745b9a27a491d91dc11b97681c876dc.exe
C:\Users\Administrator\AppData\Local\Temp\SaBmBCBlQ.exe
C:\11588c2d01c80922bc9ab84987e2c7967aeaed1b186d4203d1da962fdda42f14
C:\1078dbaddc5ec5aef4cc902a605d2dbaf06bcd06cc5aa11ba957244bacac807c
C:\dd910da521b30b0140278e2e36ee997d340d2f54d13c8e61b0553cdf6b3fa4cb
C:\b68e3e5ed8e4f3b590c0746950e99c44b60c47f5d715493df939dac7908eaff1
C:\Users\admin\Downloads\hcbnaf.exe
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\Documents and Settings\Administrator\Desktop\QmrBjP2K.exe
C:\Users\Petra\AppData\Local\Temp\.pe32.exe
C:\Documents and Settings\Administrator\Desktop\KABG3w45.exe
C:\Users\admin\Downloads\ca1d7d9616c7fdcd6d3c7ce1dcfef2cb94bea38587e7284bb401560eae12e28f.exe
C:\Documents and Settings\Administrator\Desktop\1ajo574C.exe
C:\Users\admin\Downloads\83db34c83d1d59e9bd36d614def564015823b4353811642ba43d12b64434677f.exe
C:\Users\Lisa\Desktop\gdkVnAkE.exe
C:\Users\admin\Downloads\c3133e255b8cff79748cdba8f8fda503857a94984eba200522d0b6cf12308fc0.exe
C:\90e208656fe09c8e4a824aed1d699df528f05fa8ebd462bb9ff07d1abfba2f23
C:\Users\Lisa\Desktop\3u5yMJIg.exe
C:\Users\Petra\AppData\Local\Temp\.pe32.exe
C:\Documents and Settings\Administrator\Desktop\cRekV2nl.exe
C:\94b468cf07fa8cc9bf9a2878b31a6ddf68cb6e852184894dac78191b071e8dcf
C:\d6aac25088fe5fe397b0112d94765ceab0c85e73e42ff3ad90262f1f3d2d0722
C:\a3b4cd0f5c4e733fab6cef40159670bd4780e7a475e1b46f2fca0c7cdcc23f26
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32
C:\3cc6ed050ed2fba44d92dbd06641098f13ff2a13483ffc7a9486a0078f095c72
C:\Users\admin\Downloads\hcbnaf.exe
C:\96939defb6ca4272ac2d6a5c851eff6222e22751d7a8faece1cdb8e923dc7de2
C:\255f5dcd6f34ac8ee5045210320a1a934005b7cd5b586730bf6ca4c1e182b13e
C:\3bd532278f2367dc15e8281dd76ba3b57ae4dc6cd220073e3679bb5e15d50f5f
C:\Users\admin\Downloads\hcbnaf.exe
C:\8e9da78abbcc2539339f5bb90d2e60fd8eb71df603a95eac46626302d54362a5
C:\0d5f5b152d16c6326a88220f3d7310299fac18ec437ca412661352196836abee
C:\48eddf96f5730e0e7b863c6b9b4831a2535639b1e52c4decc61d2fc616cc213d
C:\Users\Lisa\Desktop\3u1svjag.exe
C:\Users\admin\Downloads\6028d8cae6ac5b7a437e3162f4c635f8edc2b37239c0b742feabb485c37b7ddd.exe
C:\d27a90aea487663bb4f5293a7a3a0a08009979085774989023ffd4055f47be3a
C:\a620d1a38fc0cc7c09908422b989d94756a7606d3c1666daec516f8bfb8df7e3
C:\e46bc294641bfb4484e37ee05f49dab1fc505e475f58c5d1ebc7ba592c7366d8
C:\9220c2b334423e76e2537ab30406c6e486af11501a35a7cf5e50f097b0388a79
C:\Users\admin\Downloads\hcbnaf.exe
C:\Users\Petra\AppData\Local\Temp\hcbnaf.pe32

DNS

Name Response Post-Analysis Lookup
dns.msftncsi.com A 131.107.255.255
dns.msftncsi.com

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 61714 8.8.8.8 53
192.168.56.101 56933 8.8.8.8 53
192.168.56.101 138 192.168.56.255 138
192.168.56.101 58485 114.114.114.114 53
192.168.56.101 58485 8.8.8.8 53

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.