MalScore
100/100
MalFamily
Ursu

Purchase.exe

Is DLL Packer Anti Debug Anti VM Signed XOR AntiVirus 40/67 Related 2707
File details Download PDF Report
File type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
File size: 569.00 KB (582656 bytes)
Compile time: 2017-09-29 15:12:31
MD5: fb02f38856dc8ce1b5fc690d1a7a80b8
SHA1: d08580e1ac4a81300a44af0a5d740bc4a474b74f
SHA256: e4b01cdf11261184355fab4a5d43f78dae743e4663727b43d1dbac50352fca1f
Import hash: f34d5f2d4577ed6d9ceec516c1f5a744
Sections 5 ^ip$'[  .text .rsrc .reloc
Directories 3 import resource relocation
First submission: 2018-08-01 15:54:04
Last submission: 2018-08-01 15:54:04
Filename detected: - Purchase.exe (1)
URL file hosting
hXXp://psatafoods.com/patoguy/doc/Purchase.exeVirusTotal
Antivirus Report
Report Date Detection Ratio Permalink Update
2018-07-27 06:53:20 [40/67] VirusTotal
PE Sections 3 suspicious
Name VAddress VSize Size MD5 SHA1
^ip$'[  0x2000 0x3704 14336 c7bacd0923688f1a7467ee9c3a8e2ff6 481d8646b1349beef6e6d3daf23528193b5da113
.text 0x6000 0x85b40 547840 06181642fb30125ffcf28281181d0c55 b2fc399993085f358e683e85e299dc409ae17439
.rsrc 0x8c000 0x46f0 18432 1cb491162c4186ea2c3da3ff811ee020 dbf80a52c9b6d739b094ae82b40d6ae6be502630
.reloc 0x92000 0xc 512 d5925f083ea4733d6eba6e313b6c3eef e20563d0f75423b32f84abc6eac0acbf580463f9
0x94000 0x10 512 948c9b50b293c94250bc7f33b2edbd0b f085185064b93bf672ca9f88545a0df4563ac8f8
PE Resources
Name Offset Size Language Sublanguage Data
RT_ICON 0x8c130 16424 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_GROUP_ICON 0x90158 20 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_VERSION 0x9016c 920 LANG_NEUTRAL SUBLANG_NEUTRAL
RT_MANIFEST 0x90504 490 LANG_NEUTRAL SUBLANG_NEUTRAL
  • API Alert
  • Anti Debug
Meta Info
LegalCopyright: Copyright \xa9 2018 Mitsui & Co Europe Plc.
Assembly Version: 0.0.0.0
InternalName: Purchase.exe
FileVersion: 18.9.14.1
CompanyName: Mitsui & Co Europe Plc.
Comments: ncgkp1zygrw
ProductName: Lithiated Lemon Soda
ProductVersion: 18.9.14.1
FileDescription: Lithiated Lemon Soda
Translation: 0x0000 0x04b0
OriginalFilename: Purchase.exe
XOR
No XOR informations found in this file.
Signature
This file isn't digitally signed
Packer(s)
No packers found for this file
File found
FIle type: Library
mscoree.dll
KERNEL32.dll
SHELL32.dll
IP Found
18.9.14.1
URL(s)
No URL found
/.i
_EO
ncgkp1zygrw
cba81929-2d23-9433
Assembly Version
cba81929-2d23-94149
Comments
-3O
W1N
cba81929-2d23-9423
cba81929-2d23-9422
cba81929-2d23-9425
cba81929-2d23-9424
cba81929-2d23-9427
cba81929-2d23-9426
cba81929-2d23-9429
1.0.0
[MJ
LegalCopyrig
U~0
InternalName
cba81929-2d23-94138
cba81929-2d23-94139
XA?
cba81929-2d23-94134
cba81929-2d23-94135
cba81929-2d23-94136
+7J
cba81929-2d23-94130
cba81929-2d23-94114
cba81929-2d23-94132
a28ca454-1a17-da
cba81929-2d23-94115
FileDesc
_LH
cba81929-2d23-94112
Translation
X3L
cba81929-2d23-94145
cba81929-2d23-94110
+CC
opyright
ersion
_6K
VS_VER
APWIPWQPWYP
_6M
cba81929-2d23-9414
cba81929-2d23-9415
cba81929-2d23-9416
cba81929-2d23-9417
cba81929-2d23-9410
cba81929-2d23-9411
cba81929-2d23-9412
cba81929-2d23-9413
frum.ex
.CB
cba81929-2d23-94116
)68
cba81929-2d23-9419
name
cba81929-2d23-9418
WL9
.0I
-39
WL>
cba81929-2d23-9420
2018 Mitsui & Co Europe Plc.
cba81929-2d23-9494
CompanyName
^A>
cba81929-2d23-94117
cba81929-2d23-94101
cba81929-2d23-94100
cba81929-2d23-94103
cba81929-2d23-94102
cba81929-2d23-94105
cba81929-2d23-94104
cba81929-2d23-94107
cba81929-2d23-94106
cba81929-2d23-94109
cba81929-2d23-94108
Purchase.exe
cba81929-2d23-9434
X4>
&%'%+*
Z49
cba81929-2d23-94128
cba81929-2d23-9481
Lithiated Lemon Soda
Prod
cba81929-2d23-9498
String
LegalCopyright
PW!PW)P
]L:
cba81929-2d23-9461
]6J
cba81929-2d23-9497
cba81929-2d23-9490
cba81929-2d23-9491
cba81929-2d23-9492
cba81929-2d23-9493
frum.exe
U~1
U~2
U~3
U~4
cba81929-2d23-94113
frum
cba81929-2d23-94111
cba81929-2d23-9464
cba81929-2d23-94118
cba81929-2d23-94119
Info
U~A
U~C
U~E
rum
_DC
)4>
leVersion
cba81929-2d23-9479
cba81929-2d23-9476
cba81929-2d23-9477
]LH
cba81929-2d23-9475
cba81929-2d23-9472
cba81929-2d23-94131
cba81929-2d23-9470
cba81929-2d23-9471
cba81929-2d23-94163
cba81929-2d23-94162
cba81929-2d23-94161
cba81929-2d23-94160
cba81929-2d23-94165
cba81929-2d23-94164
cba81929-2d23-9441
cba81929-2d23-9499
ProductName
cba81929-2d23-9483
cba81929-2d23-9482
cba81929-2d23-945
cba81929-2d23-9480
cba81929-2d23-9487
cba81929-2d23-9486
cba81929-2d23-9485
cba81929-2d23-9484
cba81929-2d23-9466
cba81929-2d23-9489
cba81929-2d23-9488
cba81929-2d23-9453
84)
18.9.14.1
cba81929-2d23-94137
ZGN
cba81929-2d23-9440
^ML
[A8
)@?
cba81929-2d23-94124
cba81929-2d23-9428
FileDescription
cba81929-2d23-9469
cba81929-2d23-9468
VarFileI
Mitsui & Co Europe Plc.
cba81929-2d23-9465
cba81929-2d23-94133
cba81929-2d23-9467
+FM
%3K
cba81929-2d23-9460
cba81929-2d23-9463
cba81929-2d23-9462
[4N
Assembly V
Copyright
cba81929-2d23-9473
_4J
cba81929-2d23-9455
VarFileInfo
cba81929-2d23-942
cba81929-2d23-943
^0?
T~F
0000
cba81929-2d23-947
_4>
cba81929-2d23-9446
cba81929-2d23-9474
cba81929-2d23-948
cba81929-2d23-949
WAC
]49
cba81929-2d23-94143
,4K
Original
(BM
cba81929-2d23-94144
cba81929-2d23-94147
cba81929-2d23-94146
cba81929-2d23-94141
cba81929-2d23-94140
^E8
cba81929-2d23-94142
-7:
1.0.0.0
+F:
cba81929-2d23-94148
cba81929-2d23-9478
cba81929-2d23-94126
\EH
cba81929-2d23-94151
Y6K
cba81929-2d23-940
Z0:
,FI
XMN
ProductVersion
000004b0
cba81929-2d23-941
V1N
V1O
cba81929-2d23-946
cba81929-2d23-9448
-@H
cba81929-2d23-9450
cba81929-2d23-9451
cba81929-2d23-94158
cba81929-2d23-94159
cba81929-2d23-9454
cba81929-2d23-944
cba81929-2d23-9456
cba81929-2d23-9457
cba81929-2d23-94152
cba81929-2d23-94153
cba81929-2d23-94150
.3C
cba81929-2d23-94156
cba81929-2d23-94157
cba81929-2d23-94154
cba81929-2d23-94155
VS_VERSION_INFO
Translat
StringFileInfo
cba81929-2d23-9458
0.0.0.0
FileVersion
cba81929-2d23-9421
cba81929-2d23-9452
cba81929-2d23-9432
ion
cba81929-2d23-9430
cba81929-2d23-9431
cba81929-2d23-9436
cba81929-2d23-9437
,MN
cba81929-2d23-9435
cba81929-2d23-9449
cba81929-2d23-9438
cba81929-2d23-9439
,F?
OriginalFilename
$this.Icon
cba81929-2d23-9447
ProductNam
cba81929-2d23-9445
cba81929-2d23-9444
cba81929-2d23-9443
cba81929-2d23-9442
cba81929-2d23-94129
,7=
cba81929-2d23-94127
-@?
cba81929-2d23-94125
VLN
cba81929-2d23-94123
cba81929-2d23-94122
cba81929-2d23-94121
cba81929-2d23-94120
.FO
Intern
cba81929-2d23-9459
cba81929-2d23-9495
_INFO
cba81929-2d23-9496
I^nConvnFolderPath
m Aonm
i;Mj
K'EO
DateTime
|['N
System.Se
.\wf{r
Ynz'
R;0l$
2j]
]V^
PNG
1]3`,
M",$~
srb
hrI-
H93Y
Y_FY
B{QC
KnownFo
0E1 '
;Z<v
,5,~
e6-|
{mJR
-;Z^
&Gqm
rGF
mI2V
klp|
hjmbh`lFolder
2@]>
/ ;R0sG
09_E
yNnaof@ssembly
n30|
K%gz
]_\+q
o=
orzd`eStart
n73.e
}+e_
RNJo}?
2)j<b
get_Controls
3go4
8D5[L
Rg#f
yWwj6
o*-i
p {?eX
_3xy"
/R&F
_~&\
w< bV
w|;m
YVHc
4^2e
7'NX
',q-
BYZY
DefineDynamicAssembly
3, 6
"Km6
Ezhotldnts
:4.sdquestedPrivileges>
=[p=7
l43>
Marshal
{%Xmf
UY(+
Sdgistry
pCiP
:z)^
jernel32
?;kG
OYNG
m]\E$
ProcessStartInfo
BVm[Ak
op_Explicit
RuntimeFieldHandle
6=5v
System.Security
ju(P
gpou
De&:W
;_kZx
cGo|
xWcXsneuctAttribute
ZtouimeHelpers
_Y`\
PKgX
gC~nn
g}Y'
=2+@
3e V
gwu}zZ?
Uc=^[
o"t\
a>4Y
*(~Mg
]5mz
type
uVwgoY74
Recent
,}z|
?7TW
IO{|d
3O\^]P
hHsgor
|7DE
Point
gX.Jd.resources
g%?3k%
[rS3P"
?Uyy-9
m6w|
}|x%
f.
AssemblyCompanyAttribute
?-{=s1
;8ZoU
McUbk
RNGCr
sTtEned
-2cS
Dele
V4Zdrnurces.Tools.StronglyType
Format
LE}3
i3?_
ssjM
DefinePInvokeMethod
j}|G
6:%gb
Vi)5
AppDomain
^_ O
A$$$
iii
MYty
nHVacs`ry
get_CurrentDomain
1 2i
~Jxl
Ringtones
PADPADP
OwnP
kOk2
1[(=
*n+
OpenSubKey
mzfIo
G>>>
%we-
5B+&
m_mq
Qecy
AssemblyTrademarkAttribute
UnUInt32
H,zS
GetCo
&9 m
s"%R
jJ,Nt
hI1M
K^kwiw g
mength
Path
set_Text
yYqfNv
g/7s?a
wvuuw<
Y E
ri`Y
n[>H?
nZVgv
Iq Gf
;z?]D
o7CV
R)r
CameraRoll
#Blob
Control
Copy
q#Wy
v^I|sd`m
j ]-M
8S'(
-Q M
n_x9
hSystem.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aPADPAD
.2kr
f3<9
W["
sU{zx
Ztj
GetTypeFromHa
3smn
Type
mde>
SearchT
ht=l
(Rz"
D{='
IEnumerable
*J+
}v^?#
XhG-;
\{=L(
DefineType
xNnm
Reso
C 4Y
#R5R 9w
7eAL
'a.ZM
ak
_;?0
c`X1#
Npw?#
EK&d
z9+,
<->3
Char
8K]i
HT{ehofTiles
TargetFrameworkAttrib
/.s?
L2<4U
>eMH
uSYY
/oCT
;"t#
{mW
RrA%
d23/dll
wG[wK
LateGet
eHogo
CommonStart
=bWd
L/_?Q<
0K;#0
+;[bV
{sWq
SamplePlaylists
j@b0A
i?wX
T~ee
}Ri|sxWalueKind
7/*=
sGo_p
InvalidOperationExceptio
Y "\
p9lj6
Aez[
get_FullyQualifiedName
U,K[
c:cF
E...
JaF$

og\eZ
MocalizedResourcesDir
&89nL
#`7Y
Gene
hDestinationFi
PX(+
O6e9
?;HFEMX
.RGc
W|_q
}~dW
tRto
'''
XI %
Exception
DialogResult
.&1/1.0, Culture=neutral, Pub
h Np 4
Hl`ge
/W]g
.text
List`1
[zQ&e
gml.
GetString
.,e(
f?R.=
Tr<j
GetObject
iKu{`cme
$- n
W6=br
zE`$joGQ
zJ{L
p<ei
System.Configuration
5Y)+
*1s~
]yKe
7H<: &
n+@K
HNt|hldTypeHandle
C! w
]V r
]4mW>{
Single
set_KeySize
:Y>\
ZnL9
{'hHX
'mo2l
vE] jX7Yl
h4wC
QN}Z
;< !
!U]"^
0pMs^
uC~2dN
Fj ?G
fEF}
WYX7
_4vg
{D [
t\ngodr
RoamedTileImages
YIcxunRtreamMode
1J>|
p'''
swszy4
nm[c
+g4~zS
FP2+
0El
7I3h
\~}6
y0=5k
wgkOy?
p~_!sy
io>o9
WaitForExit
C%4Y
tO):
:;j
Ec68
`.rsrc
#;/"N
. \q
wm4<
bn4U
ReadBoole
IconData
get_Default
jW^1O
+yg;
result
HT{ehofAppData
PublicLibraries
w(\j
(-<o
Sg&>-|
O<}ls
-s%}o
xp+D
SidebarDefaultPa
Z0i
_N8?
~^u{
+}w7
/\3]{~
!zE n
c;Jabutres
set_IsBackground
_J.resources
jRc~
etQg
;6,4
~o_:
ieHot32
Doter
protect
)m_LE
OduEirectoryName
i?O!
?0nm
m9A)tF
{Huf
T30hC
fh1_i_
YglqnnentModel
Maxx
?Ii"w
rHJ3
TTT
FormClosedEventHandler
height
6,S?
yrkq
]i]g
knownF
='<x
?sE}
.p+_k
5gk&W
#Ts(hj
_ X
g;q0
kA37
edfaultUser
=5ig
_,M1
SampleV
NetHood
31AweVd.bJf
*N+
^Uc0)
.e69
GetPath
8?.H
(
~3&
5n<gl
=lz]
I*S^
<3YA7
)]b*
TargetFrameworkAttribute
RYYY
S2u6x
NY]
SearchHistory
2LI{
NJv.
Wxg>\
]wfV
[3]<g
ygl;`sm.v1" manifestVersion="
<_?[j
OtI
Write
}Znm
set_AutoScaleDimensions
ImageFormat
Xdnc
Eefault
*~gX`
&]X<{v
get_Assembly
ze
GetMethodImplementationF
/7?c_
`I}8
B*Cc
,sSq3n
`qqlicationName
sU}{
\\X>
y(=G
Zn#qMU
}tNlo
"rU;
~OD3%
bl3O
e4if
~9i*Bo}
^<tX
/^Pp
PublicDesktop
uO{dGhmeSize
*Q9{
MI{xOnoExceptionThrows
) ;~
hzA0
srVq{
get_Text
9;l8
S"%q
System.IO
'|J}{R
WrapNonExceptionThrows
|Y[
9c~G
JcMr
Gh/:
`S,qs
(
7uFr
L$ O
M3s>
sU):
IKS1
y^i{
KYyW
5BM+
_/T'h|r
H^|ddbuion.Emit
+:70
Rystem.IO
YC_e]
InternetCache
ObfuscatedByAgileDot
V|'
DeriveBytes
|w7>
wJ=U
ParameterizedThreadStar
IHDR
4Nx}
System.Runtime.Versioning
QB+
|mmm
M56Y
System.Globalization
?~91
]wTx
G[BVl
-vrB
IconSize
hQNt92g
; )*
985d3759-64c6-52.Resources.resources
System.Sec
t~~dw
8***
T-~&
System
EventArgs
Application
]>B@4z}
ZiQ-
C9#
9DC4
qohibd
System.Drawing.Icon
999
/%'\
V\/x
}ovX
Downloads
uBXY
FHV~
{Kj*.? <trustInfo xmlns="urn
frum
t.^%
ProgramFilesX86
B^=on
a,3c
O2,`b
nkhgbdrsById
LtY7
CreateInstance
|I`M
4[(=
7l4[
hMskdr/CharSet, mscorlib, Versi
2JJJ
RSDS
8>nX
Calli
MethodBase
#Strings
z\ ;z
System.Collections
UOK|
Image
YThMydLain
*1s_g
BindingFl
mi&3
+,7`
nG4C
7R:ofIt
7&I>
okr8
sUq{
;_lhunrBrowsableAttribute
t_,z W
5]\8*
Environment
h fE
![+
bV*3|
/LV3w
fdt_MainModule
v=!i
?i/c
M`rt
"96#
GetNonZeroByte
width
RuntimeFieldHan
T6pl.a
`znRd
AssemblyFileVersionAttr
y E?,.f
sd6|
I*Yz
oX=@
20pA
9[~
A:\W
BeginInit
Decimal
KnownFolders
w|1 y
PE_V
k3l;Rr
qndd
K]2e:
bytesRead
<`hf
Bx)C
-sPiY
System.Diagnostics
q |"s>
D;.<;
}^nWBneeBase
ui{{
F&Kw
RX%n
_j 6
6Me|
ws7X
OpenWrite
$v,
cHnml/Eiagnostics
ecmxBuilder
j^3_m
EE4BryptoServiceProvider
7i|/
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
5ION
wZ}mr
Zgb3898DeriveBytes
tvIR

q_=t
?}kD
9O6N
>g]_
E=`?QR
Windows
Double
gnd3hXFt
W&d/
*e(("v,
yN~U3g
set_Location
6.3g_
;}H*
HmageLockMode
r]]]
{79X~
|1mS
Intern
;5No
ComponentResourceManager
=
6y~6
w_Uu
43|R
Q1 '
_?;'k[D-
_~pA
Desktop
get_UTF8
qJo{
Marsha
v^y|hnos
IOhaofTni
gsum.Properties
9A`A
~zru
Nnx|
*6\/
GetF
wEZW}))
x{eds`Roll
s-mk
FdtCurrentMethod
?.l|
m Mw
P;Hm`eEouble
Sf9$Ixv
@Gk
ej7Usk
N|rq
333
K1qv/}
G/QV
.?m,
~nEY
BitConverter
9{SH\
=8Jd
3Sys
&&&
0(*
qx^U
0(*
NmVacs`ry
7a jsL
i}Nuv
Y{(
; 2v
NovN
TextReader
Form
R>/U|
Xf&o
m` p
Gqdo
X O>
Microsoft.VisualBasic.Co
{uuR
XMTU=
___
o9{e~
SecuritySafeCriticalAttribute
j=7"F
o.0I
Delegate
y{t_
*Og
3,>{Q
BJoz
ParameterInfo
l MW
I^n
GlagsAttribute
JIuos`lFilesCommon
YTtk`u
SUlgjds" uiAccess="false"/>
[\ {c
Y5Er
9zLi
u%CYK
/2/}~
*LamB
,rk~
Viknsmib
"|nB
'hPa
fEAv
?-
c;[zs`x
TypeBuilder
6ddd
Default
CB/g
{8w6,b
v][;
mH?b
/fWW,
fE'\
p~JYQ
get_Length
get_Chars
yP~E
IW[x,
i?I$
4d/a
ENI2
TsGK
BNo7[{
inzO
Sandom
X
ResumeLayout
222
Qw.9
N&1'
uM~Y
jIuos`l cannot be run in DOS mo
uIi&RdutingsDesigner.SettingsSi
qx`k2_
ValueType
y{}nu
System.CodeDom.Compiler
set_TabStop
GuidAttribute
` oy],\.
+Q{l
YgV7r-
C 4Y
9gNz
GetPara
ToLower
[hedbarParts
fX\r
/5)V
}wzx
~_L>
Maoenws.Forms
:qvQl
data
;JIEQ@DP
Bnovert
g^p5
n>2;s
jtggerSize
>.c^
= 5
Ql;B
pY28v
'B}&
X
|zY9Fq
@f hI
\(v-yrY
&4&6^R
Q(kH
l-)V
&*+
<F3D
ji7 2
+Mlf
'gci{
UInt32
ToInt32
cx2E
vqV \
Aownke
2&6w*#
|<+*
,hO)
niOqY;
ICustomAttributeProvider
GetProce
ToString
|^EdclaringType
sOuz
OQfnvoFolderPath
name
Zd`eSByte
BHHH
J./H
2K_h
ReadString
FormClosedEventArgs
re6
Qla2
LduhodImplAttributes
wx->s
gjug79+>I
.rsrc
VirtualProtect
Split
AdminTools
-0{4/
wtCu
$+Se
SetImp
ICryptoTransform
gu\J
pK|:
-^9)
R&
h{jLl
h, ]
RTsSystem.Runtime.InteropS
AssemblyTitleAttribute
?3Q'
n/ct
lL9q
[xruem.Runtime.Versioning
Security
BseateDirectory
j$Nv:
" ;K
9IW+9vW
j^[|ushbutes
?Bx.
Videos
K***
7N},pE
6Pd~
X cA{
T'`$
8rJ2
?3#b
add_Load
x?6`4c561934e089#System.Resou
SettingsBase
uOZw
4SQa
nWLp4
Combine
Ort|07
l[>2
LocalAppD
b+;y$
DmFA
set_FileName
$Pg;ha
SendTo
!+++
Data
z5%f
RegistryKey
9$["
OC<
SecureTeam.Attribut
IfSo
Devi
LmT"
g.pu
q:aIhRQ
gCW
`0}x
History
lj_xVh
AKu N
pHYs
.ctor
Appl
ltT-]"M3
nstl
ySS3Mg
=WN\
'|Szf
Vppp
Chtmap
2w6k L
11.0.0.0
g?tn
R7mY
Yie"
15.3.0.0
vs/5
Invoke
callback
Ojf4
>99l
?gMw
totalBytesTransfer
)e(-
2<bp
v4.0.30319
Q(VZ
'WL~
^Iw
u>RRS?
_v,I
fX0e
q|5}
-yy_
1%;+
_x[U8
L6c}{Z
Module
PixelFormat
FrameworkDisplayName
i ^t6
4 86 ! <assemblyIdentity versi
Array
J:::
_X!1
:]er
.j}P
`f3 n|
{$;I
@.reloc
Y:3r
0 I
yEFJU
-R\1
["2[
8/g6c
Iv
^;an
;ZBx
zfT47$
t9!W
Byte
Uppp
creationFlags
n\xK
MKhE
System.
eh*p
?gV7xD
OyK&o
:W/r$x5
al\gpTj
Yi3{eb
?1sa
U$Go
mSMd
}xufwdotions
SkyDri
(7s/\|Z
.r JLYt
I7c`
6:|
}H'\
Appe
++;1c
o &u
MessageBox
I5P(S
UMb=
BW nN'
`&kq'
G- [
;6`
g{-O
0=4-X
JZn`
eS63xlM]
*>+
ixu`
l*fx
{jJ 33
N0oW;~r
RQ&+
[z7>
gZGC
-huw
set_TabIndex
eB~-7
wAj3
UKb6H
NO*
3_^hM
CurrentUser
,@<W#
9|g
get_Item
_}fTYL
9[:w
j-ts
RuntimeCompatibilityAttribute
System.Secur
38m4
oOwH
set_CreateNoWindow
FileSh
b?YP
Assembly
R;>?
K5_<i
;r :
d%kH
+[Olz
3s^US
'0(I
%= I
7"""
System.Drawing.Size
_~OL2
MWm
rrr
' A
{tmu
"xYL@@50F30CEB9ADD9A77
SuspendLayout
iofuhleCompatibilityAttribute
O[|ushbute
%x^{W
')Xm
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
[jm'
}fr}
F6=
wNy}z!3
Size
KOnh
L:RT
yz0G
set_AutoScaleMode
ImplicitA
KscK`h
DDD
MemorySt
>Evl
wYvq!yllns="urn:schemas-microso
k;f/iYX.|
w%=4
3sJ7
{v3B
kwHB
<\{ c_/ ~
Y15n
GhleMode
pFS Df
{e_v~h
IContainer
GI@1
VTycChus
MEzPLpd
CopyFileEx
6:"
h~{l
UserPinned
D<su
5w3~
8s<_
Ao[.
W 3q
2d{
}~i&=
Y%[ui
rZh[du
~;vbK
nf1dG
kzzz
GM2ZS
3nn1f
y\5(O
[[[
] n|:Mo
J:#jCt
$k ;
F38g_;o
bf+,
"%.s|
u~\T
%9Ee
-2!aa
%Y5v
7qV{0
i;?f
JomruddExecutionLevel level="a
{3=7
<(>v
Startu
\i~vW
f4sOyh
innk-
ResourceManager
Show
.NET Framework 4
rtnn
MR1y
O[pK
>-Y\b
KJHa
m}wv6
?&&&
ContainerControl
_/m]X~
wx7g
leng
>bbb
K<r]sK
CompilerGeneratedAttr
ReadByte
'LS\x*f
(g`0
}T~Zx
Q[L3O
x#Y=
ReadBytes
3Kk=u
k+`
get_BlockSize
1 eZ
E`o`ger
Au1c
UNG'
hnzhofComparison
0a1 '
+sq
b!9g
SavedSearches
AssemblyCopyrightAttribute
uu e
asaO
=|ew
PublicUserTiles
56J
UserProgramFiles
set_I
;wz~*w
0EY,
~@qB
get_Ret
t9\y
fnfz
zaRP
_|wS
lG_j
(\*{
gmM x `
.TRm
_*=t
99>8
R)Kx
sOrgtuDxtension
jhrgsubuts
1,(<
<IQGR
&l ]
ReadInt64
=v4l
Ovh<
^-IY
Original
^xf%
V\`y
k_~\
c]WS
[35 6
Close
V)[6
=H`x
3iKS
tO,<
111
.NETFramework,Version=v4.0
H^igtsbeBuilder
^q[
;OcX
Zd4-F
(
Templates
H:"r
N0z|
G+`/
8
7m7fn
/uext
get_Scan0
JRRR
G|ir
value__
Rectan
3 V,
hOoxHogo
'v3g
(lJ6
5NOa
op_Equa
0q1 '
Entry
w;Iqrudm.IO.Compression
~+?E
IFWo
cB^00
:oJyP
JIuos`lFilesX64
gAMA
vRyO`ldTasks
yNrl
G br
DZK[
&rZ
AutoScaleMode
56HM
fFFF
K.fx
hmmm
ResourceDir
.cctor
mThcEhrplayName
AsyncCallback
BnlmonStartup
ue`ho
g>b`
mscorlib
^t_H
\I{edvnrk,Version=v4.0
iudRubKey
Ltuex
33wZ
a-4Y
5WkU
=\s_
GetMethod
jmP0
:111
'skkV
'drXJt
StartMenu
;+* _[
]fnKn
K9+&J
<y%g
IDAT8Oc
ControlCollection
System.Drawing.Im
.isX
I8bU
i^wjmx?
V%P,x
o[v-
gvK{
P1%YW+m0
Guid
uHVacs`ry
%;_}
o_|IQ
k]0{
Z=s36?u:V
Rp-d
ysLi
ContainsKey
System.Reflection
mRystem.Resources.Resource
MV>v
RuntimeTypeHandle
Y0Yv
fff
~wxux
I^n|hofsBase
kh_Z`
_skk
jRvmsRdrvices
S6^
S'-x
o |Re1
WozT
~SaW
sGN&
get_Png
1+XX{
Conv
XhZMXclT
Z~[hofle
_###
/HPj
;v[Z
phT{u
odu^Length
Append
6|=L&
>2M*
LLL
Yd/k5
9gu/
?s=.
)TJ8^
JaUL
/2Hl;
^.|
set_Padding
`k?m
)R_1g
tXnanoQointerAttribute
*.+
X(+
K<8o]
PublicV
J O'
AssemblyDescriptionAttribute
PublicR
IntPtr
?_0
frints
v3,8|
KshuicalAttribute
Ib`W?
mH9[,
2H &
"<~6
thread
z|S8'
3h "
GetTypeFromCLSID
}U8-
Yv[Cf
NBQ=
qJ60
/}XZ
lV{)
ReadInt16
x&`CFz
gbOgx
Nq NQ>
I\bg
k%O
F`leTasks
U2GO
6ck;c
Z'wOv
>8 Gf
1W+2n
BRMZk
f7.~
s.O1
nZTo
CommonTemplat
threadHandle
m7*e
~<ltj^
S;&\?8
KW :d
UUof
mscoree.dll
!This program cannot be run in DOS mode. $
cUcS*
OO/"
7+++
uJw.
[t,nc
File
nYH.
's[%
iF|IAE?
)?H4
nNZ3+
Jhll
@G-j
R +
Dispose
{_@}~
/iJe
f-X
MEOg
Compres
fCh+
:y;\
sss
boub
sss
Zvw
]syTx\
J5/=
[HimlcmyCopyrightAttribute
L?x^O
Uc\_8=
SUs|h`mize
m>i=1
Rand
$E-
set_ClientSize
NEYl
get_Name
<?xml version="1.0" encoding="UTF-8" standalone="yes"?> <assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"> <assemblyIdentity version="1.0.0.0" name="MyApplication.app"/> <trustInfo xmlns="urn:schemas-microsoft-com:asm.v2"> <security> <requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3"> <requestedExecutionLevel level="asInvoker" uiAccess="false"/> </requestedPrivileges> </security> </trustInfo> </assembly>
hBMzhudr
tZhqSd`der
CreateDelegate
Dhojs
~6SKo
JBpK
2Ngc
\ruz
([q`
_"4M
.,K`;
&r[%
D'|[
GoEO\
%o"
_V?
J87K
oD0D
lgR
***
threadAttribu
E!Qh
GetFolderPat
l[fT(
CB01E0B0B937382A7
rU3c'?Cj
BSJB
ktshty> </trustInfo> </a
2CrD
NQX"
BV1}Xg
(Lpm
o\6{
<`wQ
|4E~
Z()c
g]l'
#0eq
-%5721-836c-223927611725
? 4y
U9QD
iZ,#
O<xwe
bem!wersion="1.0" encoding="U
Rxstem.Reflection
X<a{/
00hB
Delete
ExternalException
p+\lf
cIT|
r79,
uVjam`uionRelaxationsAttribute
'5KGf
{H}n
lx<p
evStreamNumber
NgenG
&rz<;j
}{h^
*G]&
Z~ms-!mscorlib, Version=4.0.0.
.?=&
hT}z`lr
U-8*w@^v
nd4l4
W&{(
m}iO
jOu[dswiceProvider
'< Y^2
GuidAttr
System.Linq
n>q,.`
ToChar
dU1z
mmm
~_vu
M>$p}&
.k>'j
StackFra
~}}}
9j_
Y$s7
4g%\(
ES=m
.0rTK
+~2t
6/9cq
eR%?Gr
WoXW J
};SF
3?rV+
HC |
Dr(c@I
aQHh
Py6{
ppp
RbWx
Settings
BlockCopy
jNg06[
Y. $
}\{I
& ]an
%1pdV
Ga]vz
=o|:
ogu
W^wjdsHnfo
J'|gV
i>[]l
Equal
z(wnBf
[usdamReader
o"_=<
<;6
i;[|ushbute
m YLW
?hMw
I)Nd
p<
Sample
Boolean
ISupportInitialize
/|kU
QkwE
CryptoSt
sV.2
rl~q
+y9
xX4S*J
n 6W
5(/Pa.
,wV8
WT:F
MethodInfo
?4#%f_
!This
k*Nw
gg~|
;9wk
ZT?)N
vM[e<+~
CompilationRelaxationsAttribute
QwlV
m*?_
Dire
UnFenericParameter
ReadUInt16
SSS
Hashtable
o:18
\c0:
MemoryStream
~aXqL31Z
DT>+
%+/|
[ulMX$7o
ik:C
baseAddress
pTIV
A5mw
/|O0
/hss
% ^ g
[y:?-y
+++
6rmm
/.qY

*zVr^r
wZtlMhoeArgs
zo\[
ys\w
w;Ux
-S^0
[\_?
vRyLnbtments
MZob
|TcZ
sWI5
InitializeArr
YZ("s
Y}mutre=neutral, PublicKeyTok
BSBNs
GetDefaultPath
Tgs3\
sg"
IEND
N0/([
=+aZ
~<qf
Microsoft.VisualBasic
GetEx
B;[DM
Te[pL
_ g3
*BS
@N`q}Y
.q/
N~g5}
7.3g
X{{{
pN3
!"!o~
_5%q
WMWM
)^5l
qJ([z
i;Ygou`cts
m9]|.
AssemblyTit
context
nXuw
_(2Zi
aV~\G
\jui
:SZ(
DT jfm

1$~=5{Qg
S[8K
h_[W
6/>V
15.0.0.0
i-?cHO`
m> BE
EventWaitHa
CommonOem
E-Z ]b
"*!ruandalone="yes"?> <ass
`wCIhQ
Concat
\T tw
0<<=q
StringBuilder
g_c]
W4'0
t!tR
7 {\OY2t
TSS
_7`H
Wl N*{z
ReadDecimal
68T2-
;}V3
*^+
,'uvO
2k).
a*f@
]h}l/qdb
I02<P
DndInvoke
2mXz:
];7w
S;imu^Mength
CompilerGeneratedAttribute
;NgRusing
nMK\
.84IM
o/3;qGQ
khgbdrsWindowStyle
d~u[
@drManaged
Y77pG^
lm#m
>a u
currentDirectory
edeDt
<Ofo
u M9
|`e`taStore
MbeGca_
Favorites
c3cJ
8{:Uj
EQoC
G111
m}}5_
Insert
AssemblyFileVersionAttribute
[W}gshuhm
System.Text
?;`GA
Z)UiQ
oWn}sdHnfo
.dG7
|kQZsd
*:+
System.Resources
f-``P
q1 '
Q%FbV@R
x|ff
get_Id
P]Ez
=3;]
< .)l
t&k4
FileS
F:1]
kW}=
@qKK
f+($
GetElementType
=}AU
z.gX.gx(
JIukdrr
:n*9
] O/
fl\:%
z'2+1\
W~};
jk_ee>
y;W}rhbLibrary
9\7F
~yoamedr
C< :
Icon
EED
)^{{
|uk8
Pr(B
p.VN
?mnN
uWVw
rIDAT8Oc
G3yu
a]b{hv
EoxH
R`vedGames
304C
Docume
6<Pt
hUNqqd
Q^c[h{d
:0D%
fSystem.Drawing.Icon, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3aBj
PublicDownloads
6tLNl
c,b
PSp^
0}qp
8Cj}
O)*l
Sd`dAllBytes
;6M.S
String
K2 :
/[[&
_CorExeMain
DebuggerNonUserCodeAttribute
= 'h-
EditorBrowsabl
{(2zA
NhmdGenerator
we {"
pU\t^
<<&t
Bl c
n(UYZ>
IAsy
_[6Am*
h;c-o
InitializeArray
SCa.S
kVR7
JnyHcon
H<lMaT9
zz}u
Microsoft.VisualBasic.CompilerServices
J8~^xr
t :Kt2
G"3|
V|2n[
6y1[
hT|amd
ToArray
ttt
jP:^
?;n;
EditorBrowsableAttribute
67=S
IEnumerable`1
x(U]u
::R8
oUkw
7^nV;
zP0;
)YTv
ProgramData
Bh8;
VnyY
?Xw!
Y#xk
(2-,
|fws ;
`.sdata
ma(lP
q 2'g]c`
d0/}
YO|z0
yo^|
p6Ty
S:MS6^
BnmmonAdminTools
^Nb;
Load
7Eg3
/vsg
UowLk
,q hNYug>
qK|4
s<^fw
rV NP
System.Drawing
ubY<
DebuggingMode
[XygtouPictures
MethodAttributes
Rxrtem.Threading
get_FullName
4xueqhmer
X3jj
$Ej5
^YML
gUqUq
OYR)
M3Yc
"jjj
Y_G3` xD
;yR x
set_Name
wYvqO`le
gSnA
Dictionary`2
'&'
BeginInvoke
=u9`
Uy:'
<zu>
^{vR
DebuggableAttribute
ddG>^
t;&XshwateImplementationDetails
3ecp
j_{~
CallingConvention
gaR{
~^|itmuInstance
JZ~lhofMode
hTymrr
ffs*
_9 &
::[7
;fem
,H9*9a
2 M_
[Xnaw`uor
Flus
RuntimeHelpers
get_LocalPath
?Q1>
3V,PZ
[^d8
2Gs.
; vf
"sM n|p
ay<W3
=23I
7=Iy
#tAD
Encoding
processInformation
MulticastDel
L[r22;8E
2]e\
9 BO
0?dC{
!1 '
1lN~+
/jS)
> Eg
+na#
=4/S
0!1 '
Entry.exe
Microsoft.VisualB
PtrT
Object
DeflateStre
OxF W
%y84{
fdt_BaseAddress
bn,f
x^he
GetFileName
ComVisibleAttribute
3System.Resources.Tools.StronglyTypedResourceBuilder
C>4{
jat]z
10|
ModuleBuilde
rdCln
Rc[;
:pUp
. UN
a2>k
Playlists
EdK?rmc(e
SkyDriveDocuments
=CbnK
"r2W
Pe+s-=
]sfdExnamicModule
?_}j
giJ_
kax2e
SkyDrive
EditorBrowsableState
AssemblyConfigurationAttribute
QSystem.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a
BseateDecryptor
,hxG
WSe&
EEE
CultureInfo
SdfistryRights
zb,0W
,6 ,~Wi
1.0.0.0
<- "
ReadUInt32
Poin
r_5EI]
>;vc
r5E>
Z~\nDod
*Z="
|7LI
J3,
?+Qv
fkt4N
XBj;h
UnlockBit
Zfy]
QPqi
~3-D
E_.}
Stream
Kf6dJ
b9*
Recorde
2 C C
- r
~_w%4
(X(+
8W
IsNullOrEmpty
;~0,
~+#K
A1Y)
oT]i
U}zy
GetAssembly
e[4y
vLNlc
EventReset
Gfwl<|
Exit
P!ruI
jvs^
_EsV
:qj-{
mv_?.r
ns{femd
_:A
2l-5Lf
$013c622e-
76j~'
Entry.Properties
mPoVA
d(Y{u
Ln>Z
^9w!
LK=77
Contains
?<"b
Ask
n3i-T
ProgramFiles
Microsoft.
2Gn
Mp*{h
<%ims
9| ?
NiqN
?ACO
"85&
=Ryw
l7x|1k
|&;
vh#Cf
M^EO
_6Mp
y%l=
Qv6.
U8uX%
3+8Y
Y!)'\
0s&&
*&ck
}fZ
RegistryKeyPermissionC
Xg[i
2_3s{
zQsnfiles
*!qp
sV,1i_
%<Zu;
%?.u
System.ComponentModel
J;TbN
j6x|b
_^^5
Librar
qKoM
Hot64
Asse
\msG
_l.resources
EJ" ,,
CreateType
PictureBox
0;{cr
sNon0S
s^yO<
F=>@J!
d9 F
knm{
?M}N|
6=RJ
. ~)xm
nYsv
!_n'
7<Yq~
LH8[g
yk4(
MCt}
|Ctgfer
/0pm
;pUG
/mz
hRnq
vRyEtrhc
&<GN
5 P-
1:11_
GetHINSTANCE
X4OT
yn|9
KJ%M
Zk\gW'
Buffer
;l:!*g
W0O^
OpenRead
HZ[~
yZnanoRhortcuts
{|oYi
get_UTF
P1M]
GetMethods
_%R'f
e_k
)=L"
AssemblyBuilderA
GGc>
PrintHood
f t9N'yTj
^ip$'[
]*}Jl
L'H]3C9
w RK?
df Xv
u"_
tu,=
BnmmonPrograms
hawdQictures
m QR
InvokeMember
?~{i
3]hf
y^i&StotimeResourceSet
>"#
4{%4
sDW|r
From
&g-z(
(y~*^
L*gs
LocalAppData
/Kg2
M*Q#l
SeadChar
;X\']
&e/g
PtickLaunch
cHnml/Suntime.CompilerServices
Lw=;
PicturesLibra
Copyright
jjj
~rS'[
.;SI
l2Bq'
atXA3^u
cuMX
yu=g
JE{f
ZoX(
_[\ 9
tUj4
+6>r
ms[YH
Q0 h
3;At)
jVa=
<- "
(E36
~TKq
W#b
;#-T
HSSS
R;NgBi`rArray
MpnB
GmWp
o wE''$,
V0\Vz6
| L_s
0hE^
CDBu
SUn97
Fram
gj/9
,:'<
c.|Xr
vO}Xh!
R}JG(
fC s|
l&H
oIs|x/Bryptography
.u(4
F/_xv*M
&WETh
pT6w
ohM=
:/4A
cem~
yIu{ngu-com:asm.v3"> <
o2OwKo
t;VPF
T._V
IxSA
=}7q7
kernel32.dll
8OF3
set_Size
RdutingsBase
GetTypeFromHandle
]|OV
lBneeAttribute
ywM3
HkeM
03E,
6qUJ
N.lv
Qzl7
}sdd
UnmanagedF
set_WindowS
MessageBoxButtons
I:kC
Int16
add_FormClosed
}'*o
5Sz7
}p._
fu`uionFlags
PublicPictures
bA67
ZR;vh,gl|
ChangeExtension
ebxP
nv)_
h~$+
fet_ParameterType
}l;E\
q-?2a
_auP
89/1/0.0" name="MyApplication
t =}
LsnZ
GetValue
H[}.w
.wG3
FileAccess
;} e
,SN
/NZ_\
V_^+
j {VY
get_ProcessName
SZme'k
h:.xy
Cq{W
s|YX
K'&zO}[
Y`;o
cb:_
GetFul
System.Runtime.InteropServices
[+&I
iRourceFile
Public
Math
<9Er&
FduBytes
3L|S &d
[.];<
ekLC
System.Co
;/?
> g(
handle
Kn{d
Q+neE}:
System.Runtime.CompilerServices
FreeCoTaskMem
"r"
wuoecdsGenerator
+V9/cC
3WeW0
~>LX
02xfl
< Vj4
SByte
Move
OduUempPath
;vxE`ua
-1Rn
,k9c
+5U_
w^nzhb@lgorithm
8aJv
sXn}sdr
/!1|
{usdamSize
; btf
o,9_
gsum.exe
WaitOne
)W4
^d}p
sm+g
ilhauudn
7 ^^[
%Aa
u^]&
}^nW@rrembly
SampleMusic
1zmX@
g:1
IJznfsamFilesCommon
_k\.
Kttt
`55)Jr
IDisposable
zn|shcute
+mWY
Synchronized
O*u
4D6W
bv.t
~Vu3|<
DirectoryI
G>]fU~
iXrml`r-microsoft-com:asm.v2">
wKviudr
Meth
Sr+f;V
BnlVisibleAttribute
&'&
J =|w
[wDv2
AssemblyProductAttribute
nz^b9
JhM,
)37o
commandLine
PoS^)
L\?9
<Module>
EdbuggerNonUserCodeAttribu
?V\&
JhulapData
ProcessModu
3L2gcn
jIukdrrAttributes
"&bMH
WZbr
a909.
k;SDL
/,5W
^|_c
ProgramFilesCommonX86
ComputeHash
sXQmxUnken=b77a5c561934e089
lf`u
};uR
\>Qve
value
Be]7%2u]l{2o/
SizeF
2018
SizeO
<WkE
H$8hi^
NextBytes
kd
^}Y91687D568BBD9F24D7B818509B34
System.Configurati
;JV
#U[69
d_B[
4n k3
get_
gl<z
get_Exists
gT<?
pDxo
Syst
=jI
FinalReleaseComOb
O
QKZ'
GSLf
+;^/
#GUID
zO,*
O/4|j
GetCurrentProce
oQ}"n^]
Gg6j
Asf^
^]V7k
)z?k
I:t!
!{#Kw
c b5%"
Read
aOwN
oJn7
%#r}
+rhV
:(=rdcurity> <requeste
GZ.I
p:zI
o+~*
ApplicationSettingsBase
T'-6.(
[5~n
set_Image
~t}ldsable
=eN(d
w;Q]j
Syste
pgxZ
C67w
18H.
Oz2
S:7w
EventHandler
[=%&L
TTT
|o(_R
78N]
Shell32.dll
Rxstem.Runtime.InteropServ
=I|
Jhoeer
lkz#2
Cookies
SetValue
8{I1
aoidritHandles
Lxu/F
}Rto
/V_Zn
><e_H|JAwJ
*Z+
;wseW
Documents
J}}}
&bbuor
f'C&;
t*$JG
get_Module
z~g
'/O^
34-c
Uu*W2$
U}1=
zJO0
$ef7a5b40-5c5c-4ecd-ad87-ed52278f0b35
R4kb
aGl.
yTt'G2
Z=rk
LNJ)
~nSfu75
NM'
nB4IbbdssControl
r7,]
b3'0
9`_~
pGooDb
YD3\
Ulasnoment
'f^8
~6F0
G74&
RQ3Y
6"*
al.NO
JIs~hmdges xmlns="urn:schemas-m
C[u&
)snJ
K>7in
Replace
set_Icon
JLhcrosoft.VisualStudio.Edi
Zero
a&SC
hc{udlX86
System.CodeDo
8. p
?]mc
bbb
J7k0
EA1084F6
$ 1=_6
MG~j
0u1 '
W<,-~
\2qc
KW=8}
K+ /
*E$e/
.NET Framework
Ke WH
w1r-<
Q< W
?E20L
~Ew(C
FIxK
x>RJ
streamBytesTransf
o_{`>O
&C^:#k
ZlBf
E%s,
7W?b
|*V>
nThq
csoM
s RN
n^w&Bnmlections.Generic
System.Windows.Forms
^nhe
kNCF
%e%w
?:q
AOYj
System.Drawing.Bitmap
\B*\
w{^l
Y$Tj
`{%p
!w>-)
0C;3
VMsd6
dwCallbackR
GeneratedCodeAttribute
#RX@
R~%Xz#
Applicatio
8:uE
shell32.dll
8 'vfz
_yw_k
.l)r
*'_P
; 1d
Sleep
iii
4aii
Be~:
'hF
QhotoAlbums
NewLateBinding
Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven03b_64 Seven03b_64 VirtualBox 2018-08-01 15:48:39 2018-08-01 15:51:39 180

3 Behaviors detected by system signatures

Behavior analysis details
Machine name Machine label Machine manager Started Ended Duration
Seven03b_64 Seven03b_64 VirtualBox 2018-08-01 15:48:39 2018-08-01 15:51:39 180

6 Summary items with data

Files

C:\Program Files\NETGATE\Black Hawk
C:\Program Files (x86)\Lunascape\Lunascape6\plugins\{9BDD5314-20A6-4d98-AB30-8325A95771EE}
C:\Users\Seven01\AppData\Local\Comodo\Dragon\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Comodo\Dragon\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalComodo\Dragon\Login Data
C:\Users\Seven01\AppData\LocalComodo\Dragon\Default\Login Data
C:\Users\Seven01\AppData\Local\MapleStudio\ChromePlus\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\MapleStudio\ChromePlus\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalMapleStudio\ChromePlus\Login Data
C:\Users\Seven01\AppData\LocalMapleStudio\ChromePlus\Default\Login Data
C:\Users\Seven01\AppData\Local\Google\Chrome\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Google\Chrome\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalGoogle\Chrome\Login Data
C:\Users\Seven01\AppData\LocalGoogle\Chrome\Default\Login Data
C:\Users\Seven01\AppData\Local\Nichrome\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Nichrome\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalNichrome\Login Data
C:\Users\Seven01\AppData\LocalNichrome\Default\Login Data
C:\Users\Seven01\AppData\Local\RockMelt\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\RockMelt\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalRockMelt\Login Data
C:\Users\Seven01\AppData\LocalRockMelt\Default\Login Data
C:\Users\Seven01\AppData\Local\Spark\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Spark\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalSpark\Login Data
C:\Users\Seven01\AppData\LocalSpark\Default\Login Data
C:\Users\Seven01\AppData\Local\Chromium\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Chromium\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalChromium\Login Data
C:\Users\Seven01\AppData\LocalChromium\Default\Login Data
C:\Users\Seven01\AppData\Local\Titan Browser\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Titan Browser\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalTitan Browser\Login Data
C:\Users\Seven01\AppData\LocalTitan Browser\Default\Login Data
C:\Users\Seven01\AppData\Local\Torch\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Torch\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalTorch\Login Data
C:\Users\Seven01\AppData\LocalTorch\Default\Login Data
C:\Users\Seven01\AppData\Local\Yandex\YandexBrowser\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Yandex\YandexBrowser\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalYandex\YandexBrowser\Login Data
C:\Users\Seven01\AppData\LocalYandex\YandexBrowser\Default\Login Data
C:\Users\Seven01\AppData\Local\Epic Privacy Browser\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Epic Privacy Browser\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalEpic Privacy Browser\Login Data
C:\Users\Seven01\AppData\LocalEpic Privacy Browser\Default\Login Data
C:\Users\Seven01\AppData\Local\CocCoc\Browser\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\CocCoc\Browser\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalCocCoc\Browser\Login Data
C:\Users\Seven01\AppData\LocalCocCoc\Browser\Default\Login Data
C:\Users\Seven01\AppData\Local\Vivaldi\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Vivaldi\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalVivaldi\Login Data
C:\Users\Seven01\AppData\LocalVivaldi\Default\Login Data
C:\Users\Seven01\AppData\Local\Comodo\Chromodo\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Comodo\Chromodo\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalComodo\Chromodo\Login Data
C:\Users\Seven01\AppData\LocalComodo\Chromodo\Default\Login Data
C:\Users\Seven01\AppData\Local\Superbird\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Superbird\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalSuperbird\Login Data
C:\Users\Seven01\AppData\LocalSuperbird\Default\Login Data
C:\Users\Seven01\AppData\Local\Coowon\Coowon\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Coowon\Coowon\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalCoowon\Coowon\Login Data
C:\Users\Seven01\AppData\LocalCoowon\Coowon\Default\Login Data
C:\Users\Seven01\AppData\Local\Mustang Browser\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Mustang Browser\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalMustang Browser\Login Data
C:\Users\Seven01\AppData\LocalMustang Browser\Default\Login Data
C:\Users\Seven01\AppData\Local\360Browser\Browser\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\360Browser\Browser\User Data\Default\Web Data
C:\Users\Seven01\AppData\Local360Browser\Browser\Login Data
C:\Users\Seven01\AppData\Local360Browser\Browser\Default\Login Data
C:\Users\Seven01\AppData\Local\CatalinaGroup\Citrio\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\CatalinaGroup\Citrio\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalCatalinaGroup\Citrio\Login Data
C:\Users\Seven01\AppData\LocalCatalinaGroup\Citrio\Default\Login Data
C:\Users\Seven01\AppData\Local\Google\Chrome SxS\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Google\Chrome SxS\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalGoogle\Chrome SxS\Login Data
C:\Users\Seven01\AppData\LocalGoogle\Chrome SxS\Default\Login Data
C:\Users\Seven01\AppData\Local\Orbitum\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Orbitum\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalOrbitum\Login Data
C:\Users\Seven01\AppData\LocalOrbitum\Default\Login Data
C:\Users\Seven01\AppData\Local\Iridium\User Data\Default\Login Data
C:\Users\Seven01\AppData\Local\Iridium\User Data\Default\Web Data
C:\Users\Seven01\AppData\LocalIridium\Login Data
C:\Users\Seven01\AppData\LocalIridium\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Opera\Opera Next\data\User Data\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Opera\Opera Next\data\User Data\Default\Web Data
C:\Users\Seven01\AppData\Roaming\Opera\Opera Next\data\Login Data
C:\Users\Seven01\AppData\Roaming\Opera\Opera Next\data\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\User Data\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\User Data\Default\Web Data
C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\Login Data
C:\Users\Seven01\AppData\Roaming\Opera Software\Opera Stable\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\User Data\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\User Data\Default\Web Data
C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\Login Data
C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir\setting\modules\ChromiumViewer\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\User Data\Default\Login Data
C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\User Data\Default\Web Data
C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\Login Data
C:\Users\Seven01\AppData\Roaming\Fenrir Inc\Sleipnir5\setting\modules\ChromiumViewer\Default\Login Data
C:\Users\Seven01\AppData\Local\QupZilla\profiles\default\browsedata.db
C:\Windows\Temp

Read Files

Nothing to display

Write Files

Nothing to display

Delete Files

Nothing to display

Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Mozilla Firefox
HKEY_LOCAL_MACHINE\SOFTWARE\ComodoGroup\IceDragon\Setup
HKEY_LOCAL_MACHINE\SOFTWARE\Apple Computer, Inc.\Safari
HKEY_LOCAL_MACHINE\SOFTWARE\K-Meleon
HKEY_LOCAL_MACHINE\SOFTWARE\mozilla.org\SeaMonkey
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\SeaMonkey
HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Flock
HKEY_CURRENT_USER\Software\QtWeb.NET\QtWeb Internet Browser\AutoComplete
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\Environment
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_USERS\S-1-5-18
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_USERS\.DEFAULT\Environment
HKEY_USERS\.DEFAULT\Volatile Environment
HKEY_USERS\.DEFAULT\Volatile Environment\0
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges

Read Keys

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\DcomLaunch\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcEptMapper\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\RpcSs\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ObjectName
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\ImagePath
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\WOW64
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\ProgramData
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Public
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\Default
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonFilesDir (x86)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\CommonW6432Dir
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18\ProfileImagePath
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\AppData
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders\Local AppData
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\Environment
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VaultSvc\RequiredPrivileges

Write Keys

Nothing to display

Delete Keys

Nothing to display

Mutexes

D448845E628773E4A9A809DA

Resolved APIs

cryptsp.dll.CryptAcquireContextW
cryptsp.dll.CryptCreateHash
cryptsp.dll.CryptHashData
cryptsp.dll.CryptGetHashParam
cryptsp.dll.CryptDestroyHash
cryptsp.dll.CryptReleaseContext
vaultcli.dll.VaultEnumerateItems
vaultcli.dll.VaultEnumerateVaults
vaultcli.dll.VaultFree
vaultcli.dll.VaultGetItem
vaultcli.dll.VaultOpenVault
vaultcli.dll.VaultCloseVault

Execute Commands

C:\Windows\system32\lsass.exe

Started Services

Nothing to display

Created Services

Nothing to display

#infosec #automation

TheSystem Itself @ 2018-08-01 15:54:20

Detected family: #Ursu

TheSystem Itself @ 2018-08-01 16:02:02