1.2
低危

13da98217ffe8c1cf5fa959a6b4fb750a66ff402e0ae684a9ee380abc951e689

13da98217ffe8c1cf5fa959a6b4fb750a66ff402e0ae684a9ee380abc951e689.exe

分析耗时

193s

最近分析

384天前

文件大小

93.9KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN DOWNLOADER UPATRE
鹰眼引擎
DACN 0.12
FACILE 1.00
IMCLNet 0.80
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba None 20190527 0.3.0.5
Avast Win32:Malware-gen 20200501 18.4.3895.0
Baidu None 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (D) 20190702 1.0
Kingsoft None 20200501 2013.8.14.323
McAfee Upatre-FACH!56A53DDE4E9A 20200501 6.0.6.653
Tencent Malware.Win32.Gencirc.10b65aff 20200501 1.0.0.1
行为判定
动态指标
该二进制文件可能包含加密或压缩数据,表明使用了打包工具 (2 个事件)
section {'name': '', 'virtual_address': '0x00001000', 'virtual_size': '0x00019000', 'size_of_data': '0x0000b200', 'entropy': 7.963276327557049} entropy 7.963276327557049 description 发现高熵的节
entropy 0.6806781686459034 description 此PE文件的整体熵值较高
网络通信
与未执行 DNS 查询的主机进行通信 (1 个事件)
host 114.114.114.114
文件已被 VirusTotal 上 56 个反病毒引擎识别为恶意 (50 out of 56 个事件)
ALYac Gen:Trojan.Ipatre.1
APEX Malicious
AVG Win32:Malware-gen
Acronis suspicious
Ad-Aware Gen:Trojan.Ipatre.1
AhnLab-V3 Trojan/Win32.Upatre.C3412065
Antiy-AVL Trojan/Win32.Dorv
Arcabit Trojan.Ipatre.1
Avast Win32:Malware-gen
Avira TR/Crypt.XPACK.Gen
BitDefender Gen:Trojan.Ipatre.1
BitDefenderTheta Gen:NN.ZexaF.34108.fm2@auzJ9ZaG
Bkav HW32.Packed.
Comodo TrojWare.Win32.TrojanDownloader.Waski.FSA@5su3z8
CrowdStrike win/malicious_confidence_100% (D)
Cybereason malicious.8dfb36
Cylance Unsafe
Cyren W32/Upatre.IU.gen!Eldorado
DrWeb Trojan.DownLoader14.13578
ESET-NOD32 a variant of Win32/Kryptik.DNJD
Emsisoft Gen:Trojan.Ipatre.1 (B)
Endgame malicious (high confidence)
F-Prot W32/Upatre.IU.gen!Eldorado
F-Secure Trojan.TR/Crypt.XPACK.Gen
FireEye Generic.mg.af081f18dfb36255
Fortinet W32/Waski.A!tr
GData Gen:Trojan.Ipatre.1
Ikarus Trojan.Crypt
Invincea heuristic
Jiangmin Trojan.Generic.dbdep
K7AntiVirus Trojan ( 004c6c6a1 )
K7GW Trojan ( 004c6c6a1 )
Kaspersky HEUR:Trojan.Win32.Generic
MAX malware (ai score=83)
Malwarebytes Trojan.Upatre.Generic
MaxSecure Trojan.Upatre.Gen
McAfee Upatre-FACH!56A53DDE4E9A
McAfee-GW-Edition BehavesLike.Win32.Upatre.nh
MicroWorld-eScan Gen:Trojan.Ipatre.1
Microsoft TrojanDownloader:Win32/Upatre!rfn
NANO-Antivirus Trojan.Win32.Agent.eluqba
Panda Trj/Genetic.gen
Qihoo-360 HEUR/QVM19.1.ED7C.Malware.Gen
Rising Downloader.Upatre!8.B5 (TFE:dGZlOgUM7yRJK/3FEw)
Sangfor Malware
SentinelOne DFI - Malicious PE
Sophos Troj/Agent-BDQT
Tencent Malware.Win32.Gencirc.10b65aff
Trapmine malicious.high.ml.score
TrendMicro TROJ_UPATRE.TOMB00000005
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2013-03-20 13:37:04

PE Imphash

bbe0e58a50af019da15d0f4f3e85b8f2

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
0x00001000 0x00019000 0x0000b200 7.963276327557049
.rsrc 0x0001a000 0x00006000 0x00005200 5.470735892513655
petite 0x00020000 0x00000181 0x00000181 3.9400586481295217

Resources

Name Offset Size Language Sub-language File type
RT_CURSOR 0x0001f318 0x00000134 LANG_NORWEGIAN SUBLANG_NORWEGIAN_BOKMAL None
RT_CURSOR 0x0001f318 0x00000134 LANG_NORWEGIAN SUBLANG_NORWEGIAN_BOKMAL None
RT_BITMAP 0x0001f088 0x000000e0 LANG_NORWEGIAN SUBLANG_NORWEGIAN_BOKMAL None
RT_BITMAP 0x0001f088 0x000000e0 LANG_NORWEGIAN SUBLANG_NORWEGIAN_BOKMAL None
RT_BITMAP 0x0001f088 0x000000e0 LANG_NORWEGIAN SUBLANG_NORWEGIAN_BOKMAL None
RT_BITMAP 0x0001f088 0x000000e0 LANG_NORWEGIAN SUBLANG_NORWEGIAN_BOKMAL None
RT_BITMAP 0x0001f088 0x000000e0 LANG_NORWEGIAN SUBLANG_NORWEGIAN_BOKMAL None
RT_BITMAP 0x0001f088 0x000000e0 LANG_NORWEGIAN SUBLANG_NORWEGIAN_BOKMAL None
RT_BITMAP 0x0001f088 0x000000e0 LANG_NORWEGIAN SUBLANG_NORWEGIAN_BOKMAL None
RT_ICON 0x0001a9a8 0x00004228 LANG_NORWEGIAN SUBLANG_NORWEGIAN_BOKMAL None
RT_DIALOG 0x0001f168 0x0000005a LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x0001f4a0 0x000001a8 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x0001f4a0 0x000001a8 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x0001f4a0 0x000001a8 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x0001f4a0 0x000001a8 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x0001f4a0 0x000001a8 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_GROUP_CURSOR 0x0001f450 0x00000014 LANG_NORWEGIAN SUBLANG_NORWEGIAN_BOKMAL None
RT_GROUP_CURSOR 0x0001f450 0x00000014 LANG_NORWEGIAN SUBLANG_NORWEGIAN_BOKMAL None
RT_GROUP_ICON 0x0001a990 0x00000014 LANG_NORWEGIAN SUBLANG_NORWEGIAN_BOKMAL None
RT_VERSION 0x0001a520 0x00000264 LANG_NORWEGIAN SUBLANG_NORWEGIAN_BOKMAL None
RT_MANIFEST 0x0001a788 0x00000204 LANG_NORWEGIAN SUBLANG_NORWEGIAN_BOKMAL None

Imports

Library user32.dll:
0x420116 MessageBoxA
0x42011a wsprintfA
Library kernel32.dll:
0x420122 ExitProcess
0x420126 GetModuleHandleA
0x42012a GetProcAddress
0x42012e VirtualProtect
0x420132 VirtualAlloc
0x420136 VirtualFree
0x42013a LoadLibraryA
Library GDI32.dll:
0x420142 TextOutA
Library WTSAPI32.dll:
0x42014a WTSLogoffSession

L!This program cannot be run in DOS mode.
f4/"Z|"Z|"Z|/| Z|/|!Z|/|7Z|
|-Z|"[|EZ|/|3Z|/|#Z|/|#Z|Rich"Z|
`.rsrc
@petite
@UZUtK{\_`[
$\"s+L]&D
8 `!'7
hACxR(y
]3k(ll
qlDYR9
4@go6c!XD
AXZ9[MR
k\f7iE(>zM/v!!@
:S,.<7vy@HK
D%+s`3`xj%hmyvgp9eZrSg2u[
T2h<CdC
U#GDi*Q
b7_*P=Nu
kckUOcw
M _:II
!K%My *&
2(N*f*
Dh_kms
hoy|:}Mp
3.B'=HMAu
xw;9sqH
:}VkhI
xUZVo&be
zh=#Vc
l8dY7f>
ECZclRk
T|Hr0DL
[$|"Z+f[5'`
:*Z3CRs
pTUE|?5
TTk#2r`[weRb3
OF2uYj
@d GIQ_9</pl9T$
NO[.D`(a/V0UA?Z
gdMR`]"_bN
|l} F,wkrca{
VaLO5(
HILGC>
yYTtGuv@ch
T@Hx4R)x}2<G#JO,
".^b%'
`*q+UV
EAhBKquI'y
@7+0:2?s@E\X$J
EAt)0Ig4|p'30
$yine !+
!2DjWa^Z
hRalWv
ujr;$&._4> @]*_hX
b5q*z.F
Db$.\MT,o+o76jt*BU1`KMX
e\uQq1s q8
>(m=w"31^
eWQTiD
>aT<AX5t
JSTy(o[b
v/~so4B:AC
1E$8#O+
\ n]M:25d`+)L6r
[.wf{]
u/5p5Zs}1
qm5~DH
@oABZ/OQ{s
p]w+r^
\L2=ySgpu/
w@Ukx?`
AdP td=
V:@ t?>
g%);%jZ
sL<;nA
A_w?c|U&1
S/"*?C
19UT.,W
R;6;fUHU"
Jm.mp5s>
I7*2<6}KZ~y"
$YOu8AV@U
z$/#)aS
I:t!dT
+U`Y9I?s~VBU
u3jz)8Xu,5}
Bgnt`|
RL98PT
(+7%6"
v\/ezXIZbA
"PB BZ81
"0tep[
AIHbHb
E"B]]vl
R_E)OICP
H7qs]G& KP
qJmzG(nc
kIWjgO+
@D \\M1~0^
\"OHHQ]ZY2p^8
/0ZWq
8Z_zBx
q9T@HI"E
e{Xc?/
L_=1;D>u 29
\^'^U$R
iQgO/{Yz
{|T9`:sFB
hFT~E%MV80
/x'}QTj^K_Fl
l&%U3|=;fO$
y"S|_ ]
${gUM]=cuG+6KSS
<,awYS
z)tURX
=[w])IJQ(~-{
wviI04
f;mm`W)Fw
19NYb(<
+$6"\w
TiX}&JK&
BeZiEDve7
]jEN$K*
p`gLdB? J/v}I
r<l'}#u)d
-ofB,\
cCSWruN
900;$!)Xok^
"T0)IP
A.4>A9O~CTA
vwM^8h
-v7"k"YI*uu,]u;
lJ8.HU
.op?(P*1f~
#6*4oJw#,&I
_~VE38-
QFM."k
8JuW6agh_\
{<G#u5n*4]11V
b2e^u
UN]%$~<_W[Dt_
3Q]qwwYFSnO_AWA"
9;1=lU4
"O$c6f8oy9w
t@sX>!8
.]..Qu/H
%/}^CR]
$PSua"#(^
e`_BK[E_wnq_$2
*qA#.-dQ
~R;tPSEGFB(
%fQnTB9hs
>6e?-yU
~AgIuMLupj
x:Wm|}3UHi_0
Mkr?/[W%%O!y{
E+zwbv
?77;bk
.ak7S-
4I6cS*
5KAv}-Y
@@:%L{;@
q4)e]}ukIP1
*KHi<&y
]]f5NDsP
TbL`_Qwll
*"q8lhc_Ggiuw
uGzVCYko
y #&XH]
{H*nGJLib3U
6t2@85#S!
.H .LK
b]nFIV
Pd%'38
t37_M*#H2/E'
:kS`L5<jD*I
y}dE/2e
X]=paQ~>:=g
SQcwGNw~
%[Ohvu
em%kYe
u4eUU%
85@;]
:)]&l9{Rwa
NWWSd{.
UxUuu4j
A""hW8
/7mNT?H)y
@~;fzMd
]z-|#^Q
U-JRWSW*
FtiEOj
OU_q'|ry_o{
} .DzT9<B
Q#o`Cg
@0="H
I+ 3cb
h2$>b?\
6LBpwgjU
2uU&@Bn
X@u{]g
>"sy.$U<
p{}+4h
X,r@&Q8
QI]~hVSaFX\]
j_l{];
,Eu]$fi,Q
rw7UHs
BF9 q.\
lwj;`j
]L?e`uzKd@I
;wiD$\oQ]0
;G#BLIa
w3R'1s {
Ue1Yqaf3U
OW-T5);
4[ n\d
xv+O]^cYsd`
VEU @\ZV{
CXNF()
d{0H>s3
>{%>_f:Y%*cPG
5Ep}q
!37MZ=S6+[r%
W5G:4S!
N_s5Zu
d7>$$e
z^ d7.N',_1
WPD\zW AL
wdq_gB
MK]^l@
Bx@)uu"}/
zde`:P
Nmi'ZvO
n4-5n+
;m/,f~PU
?@o%mE]=D
Xysoj;9
1D"1uW5nw2u]oPZ7bMH|uW
L3H)Q3A<+
7. uQ5mffmcKkj
N#&W*i e
2[F*o!q
F/CMA13
vu{5wuW
)D>aPD\&}9I\
>LQ:TX;0
EEk'e&,?.]%
unsvO9A
.'L%tbEs
TPR^UU
bw/WUH^
(4jJQm</
TMmY4.
82&]@QLOu
UB%Ws8lE`
5$DwmE!QAG1
Cyu@%S!
wEC6@@W
$}W%U]Ze
I0Rqfv
S_5CwJk_3@$
QwRowd
JW TuQ
+&{zdBH
+@.(uLf
2gh}M^
f+@'o['i
\V;dHlN
]QDa[1
X3]\wW
U_njei
Ai#JYK8
{SpHQ1V
W_+pAvb
N]XOI;DX}
)|q}rQ_
~,e;THUAz$k'xpU^<VGn~0
u+[9Sq
T<C\En_
0.-aO}
E{gY(m_Uv
"CUW)k+p
fU3m/_5G
E0|8Ge~
x_]Q}n*b
eyw>Te
uo+gr
D0m955CC79CXTY
i8] 0-*IZW-
G]]4|,C\
OuYUEe
}qHHHawuCHHHHy
}{HHHHq
sHHHHiomK
teT*0(PVYnL3B
&/k-(&G3
bZZci8
#]wFj/G
U1J'ymy
Ey[w(mohZ,u `zz
Th,S_9of[If
-]eX}0=
Wae;;SJkM]V
kw%=dZ}p
LTf"/*kCZ\ht}E
}`U^zuwqDW3_
vu0Q`GCar^$
c_Ol9C
D9w^5j4
QwyYjA
tqKwKWd
k97zyaaC%
UWmn/v[
q~mr;;
."K!Rp
t9f9hR
NtVUf]P!}ZWp]_}`J
a *h{&
XP`}'Z
")C=6+] vHc
1M(gTJ,v{G
p#)%{ViBCYvv"NNn3c
|{WQI{)xt
^ct(yj
z;Yi*eO
@U4'|p[2!=uE`2\6
KdqEj_
U}meYThn
WLvDE..2
on3*>uUUqZ#R{Y
-Y%7uRUm
pjj3jO'"
ZA1y7R
,BoaW{
iL'$C
k7]HQg]'G*|&`v
ooiiHUx
)F8~@ah
\^AW!UH_/
@_ }?G}
MPx*Nh
$hH!gDI$
ha~Kh!8Hm3K/
byKZ`*$bw
.?jvwe
MZA)w-KO0DLV\mC
0ehb_)$u9
u7_0]LW7H,\
vcb@wR/iIN!i^Ia
W7Bz+~EWpT8T
|>{*B+
aE5u!W_
pjAW`h
MQHk]sU)dx)
uW.-D:HD
w&fL,
1AgZCtXj7
6uB)cFzbX
rV}Wc<x
ll9d/i
9d>%C<
Xh}Wi,MA:
Ekssw%Q
qut?u}(1
m\\DsJP
`PZ,yi#D}
,:ZkY>-RY6
`'KW]#m"1m
U VwBO
c"^o'B.FIb:e
$11TMV *,
dv;~W'h#dZ|5@6
}MX)U0
.o]wRr
,M]*l()>|wP
&=^3`3
"GA("oEL
]+\-%Ghe/>
$cu6j<U
BdH~9q_@E
-]/QA/
D)CY>qZC
+o#YWkS;#:+k3I
lS4)l*;
dywv-7
uB;;|C
|5(@@YeW{
g}z((k+4A;
\]HAWFb_P:
}"|IJ
ubG6!xS
vWQDA|yd_
55vC^Q
~~u0_5da
O8TN841@
E&hq| 2mS.
'E]t''IQ
pTqRZf
&>ol,GU
BXnCH$Eq}[W
|]S4;
.Sl?Y
""X<}LW1k
rW`]WWI*0Fr
XRF"M]b
\Lg;Fk
N\*%2l\,RP
J}'RU@
/WyF^za
yITB3)HxU))
"Rw n
2[a/Wm~seScIw
rOEmeh?L}t
I_R#dY!
T{Ot,}Oibcdlejqi
e"s-wP.e/E|N
_@Mg%L\
h^l[k5
@+kbf@
uP2C>[
6SUMF8
cYNYX)
-S#I+U{EL]3
wq=g2I
^>F,J5f%th\T
fl@Y<S
_XB` +
H?e@9k?y
d^p2-D
a:YA}D\mH][v
_iyr&_e|i;MhNOI9Mzz
=98;(&
F.KK4aKg
HEh;H8
d!;E&}
yjJ&/D
/No,eP
u]M'lV
MNSXG!
DR$MmKwS]`53UWBc6|
?pCRv]BpUX&Hf
"vD7nU
fu5>]5_u
M*/(nK
\?!i?_H;W
U_S*E7
Qu'_i'>eAUcb~J
6MHmw}
tg A}g9
*poke:(
PPz%$}xnTUi]SL
WT`WNDF
YS1&LWS
_7BypP'_ShQB{
mY)U.TaK \
xTX0\NN
(a1+ bN
*=LA%x8
~T/a:Fj
jPvjrr
rLJRT:
1XqQ){_U@k
+=]iQE,p
gC&p{>|
nW>)uE
_T$7?a+
srMtGfd
\U^N?$F
:qXb8<_
,0B=){/WcvU
qg65,@
d}Ua<m|n-8_B
8Pi+026\
s*]iiuqMYE<
M&H0ZRi^^BZViiVjbnn
(CUu{6
_a.3F]}
auyi}qeiFylr:>
YUITaRgUiu=6
AbV^w6]bXMWXL&C_pdmij12
J|uqMsN=U\
P%J>O:
8EDl>0
GRAza3
3BY]a.}Y
ui&y}qEIfx~YL
>(SttV
XuqQIy}X
i0a_XNUK
p}}!E`+
@.pUPB
:5QM9W\*
cu}'uhs9
.y=tC?->I
AlD6;Sm"NXbCl:
!QNtK@RM
+<Zr+C"RTe
W]J}~RZ.z&)iZJo
iZbIG Oe
;oL4M;f
i'D1/V
irn+L4If
C+di/3cC
Jc;^pM
4z3Y<SDX
)k`>/ZD,7(
7691>;<7;#1>(=(
9#,'#)(-3
}z{FIP
ona:5!ecqj=
J]Wz^gYC
EHDjV62e
Qj&.''
97!&#)+6
aiu{vzTX"&
Yh%jT
=f-J9+
wd$ynj
pqX^U\
kD=(_NB}
WZoYe*eVESB>
W|Avk^t-
\]Y`UvVN
{u:uj5=w*Q%?
%-$USm
9o&nyj^K*N@7
]1dT[-^QQyj<vjX
Uz6hm[mkx
^,R5M%T}m
ZkAjj=
BU7AfWH7k=
:q6=d!
&3ZD%fE
;sRNXP]NR[<6c>
}g}O7c6d
-W$w5eUEGKGOy
&v|U1{O
c7m)Fix[|uFm7fm
7myf?+
UF7FM^%
[uoQq`
X`e}zP\7n
_--'&TZFkOQ2o)oC.XY;5JQ*#O
Q+o_f=
5>/pWo57Hf@
cV=Mg-
yZz[Uy[-
}$?ac<
>T=|?)~X
UR$ |5JiqU
][5U+m
]bw9k7F{
/-+)'%#
2R2;(Mnl}A]v/+
S77&{s
^BZ]G[]
p;<1aZ_`
Ee*ae1!p:
j~,&&S='wqZ}+{d
^aJVeg
I29{wdiwwggwOiOOoooiio
iooooOOiOOoooiioiooooOGi_#
?'4Md1
Ha3dee
QNHELiU.2djls
bje,gaYqp
?1*i]Z<
sP?BA02LMOrSq{`
an{<nXG
Qu[,Rj
cb'49<> .
~d9mb~-b=D
;M<b$#'=+O
rn|@(V4WA^.;
t0FGSPKNzA0lswS]l@EDF
x)afy)
|4ksm6
Rs-fX<}`j@|p
iWAm!o
clB4YA_KY
LWIzaQ
2X)zOGK
fs,QMk63YfY
d955/c
!g.?={
>>fudC<p#en>/U]
p/VKb>
fQt&FZkX\ENIN\yBwHxw
GR's*j qFyps=
zR,`zN%
`{@W]B
'e*sT~
@DRPRZXZ\B@B\ZXZ\RP
R\ZXZ\" "
" "\ZXZ\RPR\ZXZ\B@B\ZXZ\RPM
R\ZXZ\"
@"H$g-NDk
+uNOI<
BVeX^KAZ
1dFUNtn"
:cigDV<
j>iEO
<4(to9pMGwtzy~
dD.5Dj
TtLcZg
6}y<g_fR`GqJ^
=5>(UW;{Iq
bx6w+5i=cU*gn&
/LLGzErb0Ec|
}+M;e'
r' o(!w
#a""y[_v[KvFki~e/=sESB"}Q PU
SsveI=z
j1Mg"lq8gBzQ'
<TU+]?4T
2/(Nto\n.
[2$z/Y
m&KL43
WTV\"Q}F.|G
P.6ge[+.k#ZB-
\XtQ:{
woz,C9^p
=<$zQ`
e=mfPG
_w?S2Q
IYHdx6=
EkO&wX
ke64 klrq
q$2y&_
M=<5h";T;
GqzVX>j
D,dd3"dd-
h2h2agrSi2h2BYv+X
;9Sn4RX[
M/(U@4~u*
C^w{]z
s'J4MAXM4MW.%4M43:
Z/e/il
ixwmiidRiY@M/i/
//:zMd
fM4MmTC4Z&yQ(@^'>M4M5
i$iiii
i+7iiV\YiWnSuM4Me_|[{
G$sM4MS
J{@w4M4WC4M_
44MSM4M
bj&_&yTB4MI74M#874M
iicC4I
wi&orkyGigSy`4Mi
O/4MDK29M4M'9 &4
4M?;>zRLabN$
_~YMd[JzgJ
k"$iw)C
{6Mcso
syiSu2O4M4U64MO3M4M';?4M4#74Mt4ML
}mU4M$`29l2H<6(|6
OM4y2M4
;f?iK33'"KiXO
4ISvG4Mko
gs31Cg*_c$
K[r4M4_aSg5M
oP>SUL6/N4M4[)
'KV4M^
2iI&$/[W
I2_;<62ri
Z,k+4yli
d_xsP_Rsgbk@
;'@n'q4M`6
4M9vepu#l&M2
]7M0#I2L
W5&3gd_
;GciVO
gS?o$"
M:o3{&aka?C&M>W
-+Wdi/
?+&[[H\
5HH^><+&
9KvY|z
v\Kf3T,K|3
74eb{,N/
xAR}M|0I
/k^BAW'
/O9+5_iP)
iEj?;1WW
U]q'
dvwcR7MXHc*
XB]JjVb
cYm}#R
p5dbm{(\V':Rf0ffK\d,
Yj5sZW3H
;*^9)18S!CuuhW^/
YcPeR,
V['BSL?l3&f9dL!
E/sAQcd
9*HYQC
cjYB|I
q]\Pd,Bwd,_e>YPn
4@|}Wce
,8u=tbs_b_2
1L.|~|
&],/W
;bY~8|aWHeT/
~>_-;9TYf/e
D<K=l-Y
n\kqrM1xT
,3~nle
bw>qI;H
iRD0N:@V+$
Fhk4T[
<B%"KG
`VY{V,
{s"s@"D;#q3
8u4mPHF*'
zZ*zv0
&/`t^ZF
!;}U8F
r_RfHV
{5_c}vQ+7X^B
I@KedeKI>
HB*#/QxEpG(@*@@
$-,YSEf]W
87!4lo!4
41q{G6
J.Z<_3Q>
o&m`kjg>
/;2E&2u]
a0334gLK*X(AK
zyqrcje=
zJLNPR
f%24/1GL
(g4[~L1
WD,_WdCV_Wg|ZG[}(
,#ME!~ga
Cmpupa
S,sIT!6
DCy?x-6vh7
g6y<7,7;\]
9m<uwa
H)}3Qb
TSFc|2Ln)JVdv<0%
j4&}r+6[
<;[M/=_w
Vm8PRVgP7Y}xCKNDJTM*dK
w0v9_T2`^]SV*
XbcaAX+kR}z,JL\u
mu9^GA3sQ
Q\}uT+:
7dbyFEBUOG4lZ+J
=c7sHg:Le|
$+QNJL]/:
VG8l%aqKb
a}ilL]P_K!9N^EHN_/TV3f
jx4# 0OK<k
YR+Uc{
-/YY]
mA#n+9W
WU(Hk
@R3I}~
VZ2;/{
f@$n%\
j6&Ha}
oxR$Qt4IF
?c7lWl
pdGq_llYn
^D xD%
FP$5I&I!7=
sUQ1@$Vb`JcR
xB <%^
!b[mMi
D9DMyjy]{
x,Mj%tO?8
/F@3|i&
U*N|aQ-%
Y.7QI,}
4U"zl"
"v[M1?
v/|44g]SLJ
hyy3!3Q
Z[gyQ>hV
it8tadL|h
)j"q+"b
3pE4vRu
~5286p[Tzhw'
\\f@:R6?
q+*x4uN
{%G`.H
@/2V#LW
c=blw0TPneK
;R;/XjP6
%/p|CU$":K:*w@q?
99+=k]
cneT@?7r#
BC>{)Q6
.@]Q:jmS
ED:J>Ieq(S
RT)R4{ZW>~]6A!~
3mpEd5
5W1=dff
]/%.&5
e,8h36tCFH
%31THe
A4Mfk-
&bNIA_nr2 ~t
uLi"E@V
1_VA7MD8;&1
h-j f+`W
GGGGGGGwwwwww
wwggggggggwww/
GGGGGGr
r3x4Mi''
+;;M4MG4M44M
OCS&Q_
wIewgoq
[irWCO+'ii3
i49';?
N4M7+WGo
k{M4M{o_K#
c;>wY`
loM{w6y`SdC4M
NSig4MRWX
!aic%o4ylK+G
4M4wg4MwGM4Mwc
O4{{5rA
:*6.);Tl\_%
MRuGMPyIAMEUH
symXokbl
:}~yF/
UX1!&Y
;WpXom-n*nc-
Rvr+}%
%n&i a
qG`=>xXrc
UNHKB6jN[D0:<(e
+F;/`vqms:
$FmiU6bt
!/%ehyaF
X&h*Zl~
:y)+2,cgV"F
V48^XXXX]
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0"
processorArchitecture="X86"
name="Safelife"
type="win32"/>
<description>Safel</description>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges>
<requestedExecutionLevel
level="asInvoker"
uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
;Hr~--
:JRX49&
qvqtnooqprrxox|oz{pzoupsooqtrxqvqvswrxrwsxrwryrxsxrqqq
||||{}zzz|{z
}~|tttooopqonnnnnn}}}
uuujikiii{|{
# **!**(
() ** +**,*&
& *()( *
ZY!& *(( *((((')
!) *!+ ) * )!,+
"+ ) )!* ) * * )+".
"(!'#.",".",". *
)"64;*3
u~"/%.$2$3".",",".",#,",",!*#.
!#) (#/$/$/#/$.!*
$#-#0$0#/#/#0#/$/#/#/!*$.
! #(",$1#1#/#/$/#.
$%2%/#/$/#/#/$0#/#/"-$/
$&%,%3$0%/$/$/ (&5
!!,$-%,
$1$/%/$/$/%0$/%0%3"/
%%'/'4$/&/$/$/$,'4
(amepcga]-.
",$/OWepfkfi57"+#2#.
epepjriolpKR)$/$/%0$/$/&/$/%1%1$1
())1(4&0%/%/%/'1*7%0","+)7&0)6%3*7*3)6&1%/$1#-$1'7,9%/+9&0%1&5(4)6)4%/%/&1%/%0&0%/%0&1$/
'&)1)6&0&/%.&/(4(4(.#+/?1@(6-9(1$,$/*71A0@-<.<'2"'%.'2*61C+6,9*6'2*3'0'0(0'0(0'0'0(1(2'2 %
U&I|pspk
vbZI&,*
zGYJA$
""E!Gq
g,nE>Si
F;#`D#
d|+v\?
)Q?'WOp
Oi{>Ft
4+]9,$.|r
4M'a|h
O:q4~;
J:&M4 4
\)t<;u
,1`#D]D?m7c%`
T5f7q<
|3ed#RujkR
M7uj{yj|c)
.FNYd1
E%Z\a4,{
KZ]]{Y
=+]xT']
9>DI6<+
cyO4tB
|)/o58,>k,y
MessageBoxA
wsprintfA
ExitProcess
GetModuleHandleA
GetProcAddress
VirtualProtect
VirtualAlloc
VirtualFree
LoadLibraryA
TextOutA
WTSLogoffSession
user32.dll
kernel32.dll
GDI32.dll
WTSAPI32.dll
COLORPICK
COLORREPLACE
MAINICON
VS_VERSION_INFO
StringFileInfo
052905E0
CompanyName
Safe-soft
FileDescription
FileVersion
2.3.0.91
InternalName
LegalCopyright
LegalTrademarks
OriginalFilename
ProductName
SafeScan
ProductVersion
VarFileInfo
Translation
lC:\b6c998ea1a221095fc7c70fd8adeadb09320a6953cd7f9e1454d5311de0bee96
C:\Documents and Settings\Administrator\Desktop\v0m9jea0.exe
C:\96d3a427bddaa9d0fe0d17d741cc06f0ec404fb59aed3eccf1c78a9e734ca073
C:\Users\Virtual\AppData\Local\Temp\e236b0ba03a4dae228fd34f82014f5ef0f51355cd45b52d2358c4dbb88ab18b6.exe
C:\c7b06e3a961696da2ffe103206af053a7273d8264f804b6516ffb74fe894ad41
C:\Documents and Settings\Administrator\Desktop\2uUMm6AW.exe
C:\OqY69knb.exe
C:\bff5d835f941b2999a9888d15be68772dcf956638e53f42c2d26a194bcfcc5d1
C:\9c89904c1652483c241e2a2b0a6c699f799a14bf585788026dcb89a3bdf9fc6a
C:\d03f8a4382049aedece0c20cfb9ba4c3e1adf18571b4cd60f93cfff0023ad9e0
C:\Documents and Settings\Administrator\Desktop\XigbrIkz.exe
C:\2atDPbEg.exe
C:\49bc93e6147d6ae931e68061521810266937f145bf7fe84894a5d61d19355a4f
C:\Documents and Settings\Administrator\Desktop\pPc3eHX6.exe
C:\l9ZuZjTP.exe
C:\Users\Joe Cage\Desktop\A12AWtdPXn.exe
C:\YnTPQpsO.exe
C:\c68fb82273f9a3da8b0fc6761444a4eefa8dc55f9cb2c0326781a51f7ecfe989
C:\ppmbGjlL.exe
C:\715946e9cd11fa315f680d70e1e12717c4acfb40948c7050e450ff52b20f798f
C:\Users\admin\Downloads\invoice.exe
C:\7cdad458a23036ac0d6cfcba8a67cb9cd57cb0eeef0fc6366f625ca80961fdb2
C:\43f090bf880750d736259d173a3c544d6c8233739ce7e1610928a129615a7eb4
C:\Users\admin\Downloads\important_document.exe
C:\40fedf95fe03618455c2062a64a2fc770a970925aad00818ec76e8c660023372
C:\Users\admin\Downloads\invoice.exe
C:\Users\admin\Downloads\important_document.exe
C:\Users\admin\Downloads\invoice.exe
C:\e6c83137b5fc63bbec6de391cae9d97e80f86930617db1e4b5a3f46129a6c919
C:\9aa0d2318905494377bbe7ce7c3b2dfb0300b574637b3180787b88b46619a559
C:\Users\admin\Downloads\invoice.exe
C:\Users\admin\Downloads\invoice.exe
C:\afbfe8b8d146dc8bc83d528467bae280f14dd58bd28d879af98e8d10a93cbbc1
C:\Users\admin\Downloads\sample.exe
C:\Users\admin\Downloads\sample.exe
C:\Users\admin\Downloads\sample.exe
C:\j7qWCkbc.exe
C:\Users\admin\Downloads\sample.exe
C:\6a67a1a97aaa55d84dfdb26e9ef7e7c7744d9a3638b52749524002a36dd120fa
C:\e493ec4ab3cf7590b62bd8a349a5b5eeefd52b75a83500a4ac0f504ecc39a35a
C:\Users\admin\Downloads\important_document.exe
C:\qytHSg2e.exe
C:\Users\admin\Downloads\invoice.exe
C:\Users\admin\Downloads\sample.exe
C:\Users\admin\Downloads\important_document.exe
C:\Users\admin\Downloads\important_document.exe
C:\90e62cc1f55e5e5f062a7624f6e60757096075d54dfe412f471162ca8b634df0
C:\ab27fda543644388d72fa65942ba7e7b5193d276fc769c48fa1c456e14326ef8
C:\Users\Joe Cage\Desktop\dZTLJ7bpxh.exe
C:\Users\admin\Downloads\b332e5e4c6ebbe3208f816f4d39c610a.virus.exe
C:\Documents and Settings\Administrator\Desktop\ZLGFmouC.exe
C:\Users\Petra\AppData\Local\Temp\.pe32.exe
C:\d3c825eed965405b7f61718ea5bc6e1e0c97344a63c5c8c39439c80811636e93
C:\455d4ca135f50ec1b0adb0de99fd9756a41bd54cc45f62975facb15e9216adee
C:\012d85107b4bfcfab6f5425cf9281e6fd2348cdeeda897e6f7fde3623d79c17b
C:\Users\admin\Downloads\yaxkodila.exe
C:\280e3fb1cc73da13b27aff7fde47bcaec1cd76b085e56505ced0bc61063f0529
C:\Users\admin\Downloads\yaxkodila.exe
C:\Users\Jason\AppData\Local\Temp\75c48629923691e61be52594b7a674c10782f2f2.dll
C:\Users\admin\Downloads\dttcodexgigas.1dbd5b7caa26b5a2d30ee0149039ea2bbcc86353.exe
C:\6dbf896c4609c69ed4fd4bfbee2257bfeaa58186ca1718b17002834d5d45d2f9
C:\Users\admin\Downloads\yaxkodila.exe
C:\Documents and Settings\Administrator\Desktop\P8ixALtL.exe
C:\Users\Petra\AppData\Local\Temp\.pe32.exe
C:\28d8607e5568481115dced5f18f8d48e4efea14ed639e3f725f6562a04aed2e6
C:\f440801768f606d15758c0df656beaf3ff795c26d77bcface6c3aa07928c1338
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\Users\admin\Downloads\b2156acbaad0c497_yaxkodila.exe
C:\b988458466ade82e524c3bc11e70e567fa288ede68f29a5e9cf04ccd00c0d550
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\2c8eff322403fcc0aedcecd5251c01d18f379593ca552d66e3be7b940a2d729f
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\Users\admin\Downloads\b168b35b45c5873d_yaxkodila.exe
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\Users\admin\Downloads\af99ab465d8e0385_yaxkodila.exe
C:\1b8462c8ec24706f957e1a220d791b05d18dc80a91ed2559e5bc573fa839bfed
C:\Users\admin\Downloads\yaxkodila.exe
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\Users\admin\Downloads\ca7fd0affec793c2_yaxkodila.exe
C:\b18c753b9572fda17d1a8f3462b32fb52bf0cb4619b0f7f0807bbf7034243dc4
C:\76e331ac5520f54f8fa179eef1086ccc1920aba606be4ec271584ab265663705
C:\26d0ad614b2025dca83160203b5e77d0e6c00efc06f63d3b04daf01af5b60dbf
C:\11d5116486b7b0a7983ad8808b727b767edf6295149b027290c5ae220a9df3ce
C:\Documents and Settings\Administrator\Desktop\quSpQMgl.exe
C:\960eccb56e80d5d75aa906f944508ef27f0e8c564e00471fed69db4354830df9
C:\6b2b75800341ec521f79c14e4a2033dfe90cea7f1b28102fbf48d7898add6ff3
C:\e18c78db39ee0af3896cf725cb12bddcdfe22c88e28feaca837946beb952e7ec
C:\Users\admin\Downloads\yaxkodila.exe
C:\f463b829639feb0e23be22387d286a6d08ff433653c30e70a3e7e7202675b79f
C:\Documents and Settings\Administrator\Desktop\1PjnE9h1.exe
C:\c6922e06aaaf6db039e5dc8a16ec8c24244bb0ca06be11d26896b592296ffaec
C:\Users\admin\Downloads\yaxkodila.exe
C:\Users\Virtual\AppData\Local\Temp\d7bfe1ae4b406db1533711957df5f10778acac55c48aa29507427a0d959045d2.exe
C:\Documents and Settings\Administrator\Desktop\QmEFwt9s.exe
C:\Users\admin\Downloads\3a6c8d00ccfa7ef61d1f995542317385ec5ad0ad376f3f1e264c44ea8aedf42d.exe
C:\744477f503a7686ed3f6a4dfe77d0537979470bbf486b6c49f8fa8ec76adc4a2
C:\Users\admin\Downloads\yaxkodila.exe
C:\376ed7cd1727b6becc2742464dc501e9040bd0dec9bd005021d93eb1d564c4f5
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\Documents and Settings\Administrator\Desktop\Xf7utik8.exe
C:\Users\admin\Downloads\0aad867586364a4a04ae6a123337bb3be79de1c607ca03263f2bc2a02c46af63.exe
C:\Documents and Settings\Administrator\Desktop\ngJopXMB.exe
C:\Users\admin\Downloads\5b9b0a4131cca3429890c0e361388879d022d496cfba2458e06c14e48f124b99.exe
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\fb2876e6539bcb8f3606a385d0cbdf6703b23b2ea9a8dc33c40f962d2f5d736d
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\dd434c3d37962a9a795472ab2c7b9fa6123c822e5f7d01a7f11095120fbe060e
C:\285c321abc85f247839f3d33d08b14ce2e8ca9e5dc8e841a83c5ea0716fd6bdc
C:\8fb7f18820a28a6786e83404790f5aaf6e02bed5ffd47354eaef754b40963b2d
C:\4161820c0112b4e390da0001deb4557206b0483bf70a98cb87fc17e9a41a5968
C:\783ff94dd876420efe9a78f5ace73d2a66d9a5197d33e9f8cdca17977f8200b7
C:\Users\admin\Downloads\yaxkodila.exe
C:\Documents and Settings\Administrator\Desktop\i1CbM4gk.exe
C:\782d362b52935392f56ddfd1b91da93f7d643f450e6d61b8c48ced418a7211f0
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\Users\admin\Downloads\9848b4ebaa088780_yaxkodila.exe
C:\85f684c99ceadd0f2ea129e366a2f5031ec79dba357134a6aece0bf237bc9a6f
C:\Documents and Settings\Administrator\Desktop\SzbbK5iD.exe
C:\a65ec52a0a843755dafb82d6ca8b75f2faf3c993a676428b73348818b43eafd3
C:\Documents and Settings\Administrator\Desktop\6E8qhUXw.exe
C:\Users\admin\Downloads\ea425c3c46765175981051b6ec0c0004ec0554af5d267db6ee9630dd3d644712.exe
C:\cf2842627a532d6514226bd93453d717f205db36fa475748d75ac527e12322f1
C:\Users\admin\Downloads\yaxkodila.exe
C:\c230d40e3921588d42438e8bb6424d15ce5acb52a2417cf649654dfa41f94a1b
C:\850d4948c1240a216df2a896aacde38cf824e5c29b41c0a9e80e587175398830
C:\bec186c45c4a1acaa2408f41ae68b5a372c7b117a5fcf7901554bd1494df3cda
C:\Users\admin\Downloads\yaxkodila.exe
C:\2f9891431d3af4fdedba2ac754b17441c42cadc71d11044bdc21aa923bc84eb9
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\Documents and Settings\Administrator\Desktop\7fCSQXGq.exe
C:\cb13030afdc31eb7544e0740c2ed23eb930674ff46234620694fdd647cfca2f4
C:\7a4611c2e392d291759b8303302c6e2d3a559f39d8efab5fa49ecefd4947704d
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\Users\admin\Downloads\97c9c4d1a47d880f_yaxkodila.exe
C:\4acbc3ef7c6b19fc447d055f9fa262f405fd1505b702c22de3a5624f19b0085a
C:\9c0d14f444c0a85a99c164c97c798169ce4c1d41aa52051211fb6c5f910ba38f
C:\a93ec0b5931eea837bc4be9297fddf993982f72fa161fb0ff49da56ddd4dd211
C:\Users\admin\Downloads\yaxkodila.exe
C:\64d16a9992b3396da1da934fba7e93886a052c9b4899cbf70fae1daba77cc053
C:\Users\Virtual\AppData\Local\Temp\88b8da5fba87f68611b3aeb2166e874133c662a8d86ac957a5479f27b704f415.exe
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\5863f8ea2ad0efa575f3be3fef421182fc36d24787ab9c19a8f749e6d5f80899
C:\2594ab607ec9ae7743b6a71f475fd4fe28a2997e3862f18dc2933a6dfa6bb3e6
C:\09d6aa4bed3d5182cf2f1d1c2b4db7e6b50473ee189bad4b73718260a8b9a70e
C:\1af61fd72f83a34736d3950673652b17306f01714f0ad4cbd0b03b48185df238
C:\ed71516d970210d471f2ca78f63711109c7cb5ba8c71f4741da8b7df93b1006d
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\Users\admin\Downloads\d4870a404464768f_yaxkodila.exe
C:\40d4719016661a115bf7248056f34e2baa986379409238b0546c5501c5341689
C:\Users\admin\Downloads\yaxkodila.exe
C:\d501e9ab89e38c9df75694ebf226ea6c7773bae18307f8c5ff37bf0ea726156d
C:\Users\admin\Downloads\yaxkodila.exe
C:\6a1f1b8c5445f6521bc5537fe1963b8e4d91dad729d5dfa012786e6f9228c960
C:\bc135906d76a1c82fff70891c95971e8c66882087a22fd2a876a212221b97fae
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\Users\admin\Downloads\a43fc60a0bc76a72_yaxkodila.exe
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\ac2731b671a3029a9de2c8fb3a30a7a880a1d268eb004fce193d3d33d1cb356d
C:\7d9b16447b81742c13f3ea9f45ce0c344bee9ad952c58e35c12469bc04114de7
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\Users\admin\Downloads\ae2640933f0e4991_yaxkodila.exe
C:\c4294d0156e52331990c07e89b60ad8684b29b586c64b6289fb165933fae5a64
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\Documents and Settings\Administrator\Desktop\XRFw0Wkh.exe
C:\Users\admin\Downloads\b3eae825dec023e91616e64f5d3ea4411e3a8137082419e837788f479d848366.exe
C:\c84349319c7e717c4d0133fa22c77ed5b201a55f7254ff90021569b6ef426907
C:\Users\admin\Downloads\yaxkodila.exe
C:\ee4decd4e0444740220b0515d9703f71678949e7936df2b498b3fd70e3c1676e
C:\Documents and Settings\Administrator\Desktop\YvQg5UVC.exe
C:\Users\admin\Downloads\499be4b840b549ca4beee05a5163a4eb492f477878b81117988b16ee51231e31.exe
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\Users\admin\Downloads\311cc405ba8af1a4_yaxkodila.exe
C:\a59a23d24ed098362951d3552ef6f5701fbd4e237ff142089fddfd69652c6c35
C:\Documents and Settings\Administrator\Desktop\ANTNFiXl.exe
C:\Users\admin\Downloads\9b4d5ee4a7ef2db4e7087332bc70e68d9dada8f9250846a4d3448a0bbeac6184.exe
C:\a7af20163435cb95bc795ffbee621dc6ad0b151daa045c080c32faa02b8d986d
C:\Users\admin\Downloads\yaxkodila.exe
C:\c5fe30e0ba563ec5018a7ecad5194ac7aa77f30e281a7e0457c2ef446dba0564
C:\Users\admin\Downloads\yaxkodila.exe
C:\f2a2fb112738fdb65957136c2b710066757da3f29047f7ff38c05aa942065437
C:\3e14d72143216b085892415054dd62d38048ff5063d89cf6bd5382a5524550ce
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\Documents and Settings\Administrator\Desktop\xYOQkdGT.exe
C:\6e7be45b64bb6049f3bbdee8a7e50655ef15b3bb99b71d3beb6358539c3063bb
C:\2b521076354251e1c26a266c79224ddc0fa4fb625233de23184a9af53e8e752c
C:\c9bd0055b1d7161836838b8df57a2aeaf17463409b1dcdfcc48db2481d48a14d
C:\5aff30192beb04eb1a0f2d3d493fa22a5b33a04e4a5cfbb5026fa0706f534cb0
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\Users\admin\Downloads\5069a319f52edf17_yaxkodila.exe
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\ee6abfd94d288bb3c64a4c1dda339bf1530227d7b6fc623c060721f67e096069
C:\Documents and Settings\Administrator\Desktop\pGITIKqK.exe
C:\74051ee089704a45059890b259e426cd7399481dfc9780a35ac85b4c08fa42f8
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\Users\admin\Downloads\f32da8ae250ce224_yaxkodila.exe
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\1ac188b1455af61c194d835ff3ec531e9142d6267c027eee4dfef4371c1218c7
C:\ae996d907847e4fd2ef1e75fd14a50e5a1b03068267f6aec2a90e9a794a99e5f
C:\737ce9b063ef5b6d1dcefb762ddec357afe245e707e1ef5b840dd31bb8e2ff08
C:\1a658a3bf984147b65b3293717a8aededfd6a81b57597cfcf48b2899315b5c32
C:\fc2036344f63ec363fc78188f7450275270eb65ecc683a23039cd999c0a74e45
C:\Users\admin\Downloads\yaxkodila.exe
C:\Users\RA491~1.VUL\AppData\Local\Temp\33102e4646fa8259401b093869c661b2.exe
C:\Users\admin\Downloads\yaxkodila.exe
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\Users\admin\Downloads\789c417f474078c7_yaxkodila.exe
C:\f194253cac02d6cf229f2d3e564e8430e6e45ab678b6f5cdcdc4f0a4aeb22288
C:\Documen
C:\Documents and Settings\Administrator\Desktop\iHGWOrZZ.exe
C:\068f76af1adca5dc8c31b8f358a24214ec7fb7fa0458a34d0ae4b3dbf800e6aa
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\20290214d377d924d065e37403cfaf9f303c63d54d4f69fd9d1703606d9d17cb
C:\f641316963bb51dbc19bae21dde8201e95f09c38901dabdaa8bfe05997426d20
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\Users\Petra\AppData\Local\Temp\a661704059895f95-yax.pe32
C:\Users\admin\Downloads\846eaf2da434232d_yaxkodila.exe
C:\ddf0a248098e5b6e58271a9cf772998995db741c91170d1196c700ebdf558d35
C:\Documents and Settings\Administrator\Desktop\TBj2cb54.exe
C:\Users\Petra\AppData\Local\Temp\file.pe32
C:\Users\r.vult\AppData\Local\Temp\3f2081aaf9d363dc6e11468b1bb41659.exe
C:\699a309754e0b72406987a1991c811df80d0b9866afd336d30427601251c9ae4
C:\Users\r.vult\AppData\Local\Temp\33102e4646fa8259401b093869c661b2.exe
C:\Users\admin\Downloads\yaxkodila.exe
C:\Users\admin\Downloads\315d0ee7587eb20504793b0548539b61107ac0233806eee60ccc75edba26f794.exe
C:\c43031825649e05e8da7c166c653f153793de3c9418abbe49b298eddb1a4a194
C:\Users\admin\Downloads\yaxkodila.exe
C:\Users\admin\Downloads\945a044ce79c96d87f3e3d0d164a59c06e52e90a686f6cebf2f58f707bd9941a.exe
C:\Documents and Settings\Administrator\Desktop\kwGrIOLf.exe
C:\c2a33ddcdaa793c9932f3e9425b12cc7d464b5dd0c907f801121df0e3e076b7c
C:\Documents and Settings\Administrator\Desktop\AOBI3iAk.exe
C:\Users\Petra\AppData\Local\Temp\file.pe32
C:\Users\Petra\AppData\Local\Temp\yaxkodila.pe32
C:\Documents and Settings\luser\Desktop\piehGZto.exe
C:\e5329eb44d0d07b93e040c89d54e11e91ccb328e6d3079671be93bbc438bbbc1
C:\430cafe42f7af2267aeafd41be12dd5ad763ca2536f49eaffd527a4a7c522aaa

DNS

Name Response Post-Analysis Lookup
dns.msftncsi.com A 131.107.255.255 131.107.255.255
dns.msftncsi.com AAAA fd3e:4f5a:5b81::1 131.107.255.255

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 56933 114.114.114.114 53
192.168.56.101 138 192.168.56.255 138

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.