PUP.MSIL.Brute.AAC
Table of Contents
Analysis Report
General information
| Family Name: | PUP.MSIL.Brute.AAC |
|---|---|
| Packers: | UPX |
| Signature status: | Modified signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
42cf87389d29336fb6de65173750bef8
SHA1:
92950b6303c59accd994b2886218acb44ceb8216
File Size:
491.90 KB, 491896 bytes
|
|
MD5:
ab622b4f39060e6aa35c2e404275d06d
SHA1:
501b190f8a9ed63b86a97fd266074eedc52a5fe3
File Size:
517.10 KB, 517096 bytes
|
|
MD5:
ecfa0874e3d805428d27e1cbaed885f4
SHA1:
78b4d7f3ee54c2826356b361052eab3b49544b0a
File Size:
513.40 KB, 513400 bytes
|
|
MD5:
883913c32e3295afde4e7156b275110d
SHA1:
dd29149cc10334d81a6179b17f43845ae4026dd9
SHA256:
E6694BE0390F6A88A02C06536818AFBF7387B481204725E47100E3B04C785D76
File Size:
506.73 KB, 506728 bytes
|
|
MD5:
740731e584274a5b54ed85e91af9ec0d
SHA1:
7f4da1f5f800289f47c7e792abcd27f51943271a
SHA256:
30758A8724516EFDF2DD9DF66D8F4CE404304E490755109F41B2F0EF159663F5
File Size:
509.29 KB, 509288 bytes
|
Show More
|
MD5:
7c7498a9ac72d7992b6f356c51592fcc
SHA1:
0b6c692679dc89466c5399d0b44e80b11f21506a
SHA256:
74570FA0036DB3735A4B58ABB04A8C6A17456A2BC0F5E2C5DDD512A36FA8DDD8
File Size:
459.23 KB, 459232 bytes
|
|
MD5:
bd9bcb108208f04b3b5fadecfb43cbb6
SHA1:
5bd156b5c6e0a0de10ea986932d7ff0c4aca8759
SHA256:
DEECA6DDBBB8EDE1E7DF1341BD278BE626FBF21605AC3CA47E0EEC87D1BB0ACA
File Size:
507.36 KB, 507360 bytes
|
|
MD5:
e8921bbb01406bd6951915e090e2379c
SHA1:
172a120098063839fbbeffff2b001254851604fc
SHA256:
3C8A55486A3AE147C0AF0F6D9D7ACBE905B5A9A07A57C17E5F9857AA6FDDFDD8
File Size:
496.50 KB, 496504 bytes
|
|
MD5:
d5221f1e837de9b26e5ff67df31c7868
SHA1:
23780c218de60f6e7fefbe0e18da381e93d22c44
SHA256:
74C5AEFAD587F3254364C12609FA4B2FE25DCA146544312837BBFB8F25DE2D6C
File Size:
522.10 KB, 522104 bytes
|
|
MD5:
e85ace567db4d834676279edf92434b7
SHA1:
6789be2f6ffd696c4a1335aa5d24dba709aed2f3
SHA256:
C296E8EDC84C771EAF720270C1F37C645BFE9ADBB01871D3A6A9E503F2D0721D
File Size:
521.18 KB, 521184 bytes
|
|
MD5:
9d67a71979f2cf33fd0d3431c9b96a22
SHA1:
d38a77c44e09c5ae687e3131cd69b99b1629cf58
SHA256:
9C1F281C133A40932A23B96FE9869F781EF3CD6C99C21E0076B65F5FF979CAD2
File Size:
515.45 KB, 515448 bytes
|
|
MD5:
0d3c27ba741b84646d1b21a7cf4b98f7
SHA1:
045c956889ffd6d95366905ae1489b0c75eb0dc1
SHA256:
4ADD32E5E2C1B964BB65A20E4491CFB4241557328A29FEA23339A4FC09B7EACF
File Size:
532.09 KB, 532088 bytes
|
|
MD5:
9930ad500beaee6d03754d7d7f7b4e2f
SHA1:
6e4ba3ed7378e10060e9f6c02a2633f169d4aed1
SHA256:
10B2535A4EA3AA537593BEEE8964AADFFB9ACA3A090CEDFC29CDD3EEDC3E1A0C
File Size:
504.87 KB, 504872 bytes
|
|
MD5:
bd790dcd22f86c11f05cf34464e5b23d
SHA1:
3fb417fef73ad67619f65ccdc16178890b53fb1f
SHA256:
3E638F7DEFE2FF6CA05F811BA8C6F7D4385A153A85FF291D81DCB6501834C458
File Size:
501.32 KB, 501320 bytes
|
|
MD5:
2a5e9ec331a10f1a80dd3dcbfee55935
SHA1:
faac0e906966c8598cfd0be02db1c757a294cac4
SHA256:
DC3C12FC6F288F9E913DB8D832123969FE84510BDC826EBC3D98A4E4A40D793D
File Size:
514.94 KB, 514936 bytes
|
|
MD5:
9773b544d7ee16f11674475a9857b915
SHA1:
e477c76132ac697211e2c2b7a9a539872ced890f
SHA256:
531DDD35736ACA80D59EA3F4B528D50F85EF354FF745A12EEF325CB599108D8E
File Size:
524.26 KB, 524264 bytes
|
|
MD5:
e2b1ebee52219c37a6e75f7399d36579
SHA1:
6143a0a4d09295ebfe33c1591b01881bee6de886
SHA256:
24DD1D7508797835D4C62ECE461BB629F5CC3CCBCC685DEADAC61771D4BA792E
File Size:
526.71 KB, 526712 bytes
|
|
MD5:
154b3102ec4aa7f8b04bdf6f2c4da708
SHA1:
506db760b18888958779422562e3acf8b71578f6
SHA256:
940B98A743F08839655061E956E28712C0A5B82F0EA563778E4CF0DFEA4E046F
File Size:
507.43 KB, 507432 bytes
|
|
MD5:
e96552d396c66f721ec6ed98eb392d01
SHA1:
5c80da984dd5f942153862d3329e56079da7d669
SHA256:
2A5129C538C4BDFD51CCB41E97C7E2A0D8585320325595200566FF3D047B1010
File Size:
521.18 KB, 521184 bytes
|
|
MD5:
1512b490519d2a149aa010c7942395e4
SHA1:
64e383468acbd6aacf7ddc4fcc7c16faa932c4ec
SHA256:
D340B3391E69F9CCE425CF5158E98E9FFF9740710145B065117F2DF22766254D
File Size:
473.18 KB, 473184 bytes
|
|
MD5:
68e56e1bea59df33cf4819f9960e3488
SHA1:
f88ae7012129acc717770e65c0584e1aacc9560f
SHA256:
B0340975DF97628F59F04B3CD5F1EB6BA1AE3C06CED71962F6B4EF1C6EDE9E80
File Size:
528.42 KB, 528424 bytes
|
|
MD5:
5a14a9a4ba7812330ff0db3beb9b9907
SHA1:
2b5ffbb696be74f42951376aabb0505ddf712e3e
SHA256:
06E84FF7184DC800B082297C8C5E9D5C2B53F251D46A1630C8C2120D2278F906
File Size:
506.73 KB, 506728 bytes
|
|
MD5:
b0ea679921808e48252ea8f3b5b0bc6a
SHA1:
b670bc59a3cb76f1b6fe7f9675c4bddab6d5c2fd
SHA256:
A14E75511ED39072B549C6CE6D588139C2C40EF8EC3E084A9131AA6F5A428F57
File Size:
502.24 KB, 502240 bytes
|
|
MD5:
fc8a3a1731ef1763c8ad8e5511d10123
SHA1:
cbf3ebdbf600d719dc81c7c915180af578a5eecc
SHA256:
A66B175884BDF38677CEA13DEE1CFCA4390B91E29A5954E2DC4E543FA038736A
File Size:
510.94 KB, 510944 bytes
|
|
MD5:
488c943f779ebb5a540a16f361f21a01
SHA1:
1dc1206166407d66c1c21a8f2fc254e020dc691e
SHA256:
5E5E2EA8167E09CE9657EB5201D3D451CF9CDC4F2381ABAA887F7B5B8F022E31
File Size:
466.02 KB, 466016 bytes
|
|
MD5:
90f0c9cf5eb6ea3cef6fa9c9c860075b
SHA1:
8f0bf3e46f85356c61d33d0e66a51de4a340d7fe
SHA256:
00548CBC308347E90F3102DA55B473D664B010CEFDAC4A5ECF03E2827FD9E490
File Size:
514.54 KB, 514536 bytes
|
|
MD5:
fabdcb2c145871e7bfbc282b5b9655d2
SHA1:
e771460ee8cb722b2d9c240fddf0b67c5feca81e
SHA256:
2712750B65A37509B6F3EE398B31648B1A089BB3562DD53ED416440D45C549AC
File Size:
492.92 KB, 492920 bytes
|
|
MD5:
0b0054dce586f33bb3a7aae6235d237d
SHA1:
94b31d5fa87fbafae284334d83bbb4fc848efc0a
SHA256:
3ADEC9A5085FBB14CE8CA7B987443206932D3BA3BCCED2B332E25AE49D64BDB0
File Size:
517.50 KB, 517496 bytes
|
|
MD5:
24c62c07b4dbaaf49e530f98bef353e6
SHA1:
6ecf3412f136f3cd7682c139a50c39168b633520
SHA256:
715FCAEC1E8B5048D1A52418D3F2FC5EA9BB75E7DE84569EFA6208A80BFE2FC5
File Size:
516.19 KB, 516192 bytes
|
|
MD5:
d2193ecb17e3007e708db7d1b658caaf
SHA1:
ab8a8e23b9b6cf569cae07c21eb7b31d6b8170ff
SHA256:
D95445558914C9B65E28EF9AB744D8B69E7775C4752284EFDD5C9192ED203EE6
File Size:
509.99 KB, 509992 bytes
|
|
MD5:
c3073963ab9765ce73ef4f1fc76489f1
SHA1:
1e129c6e7e2061250938945e487078f485b803cb
SHA256:
1893F9A316845D205076B82F72569837990BADB0362E8D052EB6F4A4E7D1649F
File Size:
485.47 KB, 485472 bytes
|
|
MD5:
95c07f00a2583ef886ca763e313bb0c8
SHA1:
d4072e91412d81ca95859cc806479633d61aeaad
SHA256:
F71C28517C4918EBD35108DAD7162955D676FACAC58C45E4DB53E83AE125CEB9
File Size:
468.46 KB, 468456 bytes
|
|
MD5:
e381d87bb28b15da637103609a4b4944
SHA1:
024798358edb369d62cf0e3b363423918c0cb84b
SHA256:
90ED931D3819567F327127E25FFF13663FFB3EABA512D1E19E83FCF38E05491C
File Size:
481.25 KB, 481248 bytes
|
|
MD5:
559e24eb14a630e532e2ac26cb5f75cc
SHA1:
6ffe2b2178576c560fb22b8e47f3e03aa57de6dc
SHA256:
AA4D1E48F6BE712A786C31807A06E889102D18F240079AAA9FC9D48885F4ECDB
File Size:
489.96 KB, 489960 bytes
|
|
MD5:
36976ba8e0ce6c9aeca0dab9e042100e
SHA1:
cfc3377ade638acf9f3efbd03a4434c3a8c91530
SHA256:
B493A8E8E72A589C6F51EB5ED8655B733CC12E05735E3A2FD3E2C37D84EBF860
File Size:
518.75 KB, 518752 bytes
|
|
MD5:
5bfb43f198c936ff6f9fc47c44989e8e
SHA1:
bea2ee0200a91d2b97f629debf938e8be71c71e1
SHA256:
37B0B4BC45B886C8773D15B14B3CE5CF1364BE0BA21F93083EE675F5A0AE5559
File Size:
523.74 KB, 523744 bytes
|
|
MD5:
e5cda5669e255909b20c1593ed1d98c8
SHA1:
7e6fef2ffa6f28fcb58ce895fd1fe528be98f6fc
SHA256:
96682215D9B5D2232B2E13F4ECB13563EE6DF57DB6C019E338C5F631AD7545D8
File Size:
494.56 KB, 494560 bytes
|
|
MD5:
eabfe239defa9b7baab0f241c5eb55d7
SHA1:
7ae52815dc5aca442776717bfcfa9e6900ebb947
SHA256:
8E864DD97307A73802A969A0920A20ADEF545B79E8B61C7FFAB20169FF86E8DF
File Size:
499.17 KB, 499168 bytes
|
|
MD5:
792a3a46c441b904e57aa795f7c3b545
SHA1:
15a1354706186f456cfec5cfa41e1bc8a9be7d8f
SHA256:
46B17F0151B9AB383F6A8D10E1A8191F80950966280E7534C05994ECDD0B2467
File Size:
502.88 KB, 502880 bytes
|
|
MD5:
fc9db55c6b0f54591d42182979e2067d
SHA1:
0d8c23e71fdc91570facb3bb257f2d088498dabb
SHA256:
398924012440F71B10942941E019AC8A8DFFA7B1A99C76F809AD4B6253B9C5B0
File Size:
488.42 KB, 488416 bytes
|
|
MD5:
a268b6491937c4561369b47374c6850b
SHA1:
7ed3c9b7cf15217ff1e7ab61bd757468f285795a
SHA256:
C079819BFA40DCDB34CABCC38DF0D65B7592C3678C35AFF1B6F2409634F421C9
File Size:
496.50 KB, 496504 bytes
|
|
MD5:
504aa7d303037b3ae97d2357b019ddda
SHA1:
ea79bfea33814f6949c4edb21b62b59ff7fab25c
SHA256:
85B833299D35E4A9BDC1DBE1A4421029CAB65EE776A6AC466210DCD7938FFC73
File Size:
528.38 KB, 528384 bytes
|
|
MD5:
35488001a76f74894430c4fe4d45e056
SHA1:
4e70f38dd4f433b4ac82c0195c0a3b6d42a2505e
SHA256:
0D955768D6B6B3BFE3DF4DBEBAAFFAFCC1B010F8EAE1EAF0B23B893276044B5F
File Size:
516.70 KB, 516704 bytes
|
|
MD5:
05635e55d374a1ab75bfb36c80087e71
SHA1:
6a08b493ce5c304902b4de04e4b5b8f9c696560e
SHA256:
A82EB74B695B074EDAFF4EE1BE2718B34DD1657475686749324E1DE3C3BE3D52
File Size:
515.55 KB, 515552 bytes
|
|
MD5:
c85b2c5edfcbfdc331079cf8e6ff44b6
SHA1:
3daaaa480baa1ac7d8ce99bc0103bd9eab35f606
SHA256:
ED9BC9358FA5AC812CB09C4B25588DC2CCA7BAC0354AC4B3415796622A27FE31
File Size:
502.24 KB, 502240 bytes
|
|
MD5:
798e67d3c857738dc545f3c805f12959
SHA1:
2b9a56332078eb64f85bce960e296d1709e6db27
SHA256:
9F3E94814DED968B26622B5BE47716D8A1D0F2D33B85D56B301B2B8FD1FF07CC
File Size:
472.69 KB, 472688 bytes
|
|
MD5:
c11e479675985157ecae0996531f6ee6
SHA1:
f822473700d0153c52d3ab8482e9c06009002071
SHA256:
B6836A831B44F725E4E197186587FBA787B9574B2686133FE012F9E5F504F844
File Size:
517.60 KB, 517600 bytes
|
|
MD5:
6dc2484ddc0be37d39c94412b6257548
SHA1:
30974376b085de3e349600bc1d9ea23a27904145
SHA256:
40A1B689196116C5E9F6E537D0BC068AAF7FCA452ED620CCE7938436633FD167
File Size:
509.82 KB, 509816 bytes
|
|
MD5:
07967babf3ee6ab1d62c66f238c42150
SHA1:
b25416e47e5f7809e313d9803573bba65806fb34
SHA256:
A7590440CB379D741A1F7AFC3C766400FC121DAEBC6206DC30E90E8D9B27D1CD
File Size:
521.06 KB, 521064 bytes
|
|
MD5:
7a5992a00c807690899b75f6055daac4
SHA1:
b4b015ac5960dbf4ffaa4d199b2614b0d9709b52
SHA256:
7FBB5618CA2B65BF5427116058D7D463780C003AF5678601060A1AE56FC83BFD
File Size:
496.50 KB, 496504 bytes
|
|
MD5:
911cb3e65ac34a9523f11076f1ec3978
SHA1:
d24d7de3b71602c8be3e24eeeb9b99d9e8335714
SHA256:
C5E501A5A15A059AC2FAF52837B22DF15B8AA6EF3B0BF2239CE024B7508B7397
File Size:
508.39 KB, 508392 bytes
|
|
MD5:
a03bdd255e6058e174cb90bfbd665c42
SHA1:
1776311c91961db109aa0ab1f4e8b9b71eafafb1
SHA256:
0359297DFDDDE1CA3A8EC1164FCA0E6ED40308F7070B6D205F615F0D9DC55099
File Size:
516.10 KB, 516096 bytes
|
|
MD5:
1c4445487cf57b412b29fbe6892fa2b1
SHA1:
f0fd9a8dd5dd7c42c6d84aa4990527ce07583300
SHA256:
0C977A360803CE2E3A250ACAA7244017D45A7CA2C9C5C2BFAE37F5749247AE03
File Size:
525.38 KB, 525384 bytes
|
|
MD5:
6954342929169086398bbaa728999032
SHA1:
9728899627d4bf48c60a87dfcff9a14bb41486b0
SHA256:
68F56B5CE57BD40ADBE767E3908D0D0D6262961DFBA47020DB07A7B65805EB05
File Size:
484.18 KB, 484184 bytes
|
|
MD5:
c540de4d729a80e0928663b3396f5944
SHA1:
0227a01fdd96494ff620faf6de08d803a97f9003
SHA256:
87CCB8EC01951316BB4B46FB18F033DB93885CB1410E618152CC9F96510AF3CB
File Size:
497.02 KB, 497016 bytes
|
|
MD5:
7b665f1f4d32c7acfbae762906d3e706
SHA1:
8d124848721d89c03ca65d4fcbbde4857aed6053
SHA256:
CE10CA240D3D426507872F66C878A14102F2E14A798229F84CDCB74507A5C9C5
File Size:
527.91 KB, 527912 bytes
|
|
MD5:
f8b368a8dd35a6e246d9a40648a01a64
SHA1:
b52c662038432058d44233b1e03076c3928e274a
SHA256:
A32E0C0D208057B4E07DEC34D954E4AD2DEDFC254E0BD6B8EBE4867E9F67991C
File Size:
476.77 KB, 476768 bytes
|
|
MD5:
ba6e7e8666ce4652ab7f8a1fdfdcaf4b
SHA1:
3ac22bd5260e1aef66b1c65f28abd9dba43e140d
SHA256:
C2FC97FD2E99AEE4F5F1A65733BD051A349F822A0FBBE93873E979F2E6F2E21C
File Size:
499.68 KB, 499680 bytes
|
|
MD5:
bf0b19614f7de4a02dd803a255770ca6
SHA1:
e3f5c99996be62ba56e04972f6de066246ce280f
SHA256:
4D818CCD1D086BBC0E67B73B8798ABF51DFE98DA52F34EEAC8619235BDE2B266
File Size:
527.84 KB, 527840 bytes
|
|
MD5:
36862c92bbdab48e71370064ddb14f85
SHA1:
662c2ed8085c69a4a72d337bfb6908510ca6849d
SHA256:
269DA8AAFE328FB1C2F7EDCAE81CD80BBD26E6FA4A636CF1878CE3785FB29A51
File Size:
504.42 KB, 504416 bytes
|
|
MD5:
3f4c83af8b2480a7fe95c201e146e750
SHA1:
bdb90fc48a0d02b98a323ca02ec3bca7435355f4
SHA256:
1393228FDAFBC68337D45A54A49C0A5B96E198E03EF08DA23818FFEDE3EB6E30
File Size:
499.30 KB, 499296 bytes
|
|
MD5:
56de3f48b2fb0fde2a91cf21c211db08
SHA1:
82856b9edd2bdd7ce565d19cb4dd681b9e506daf
SHA256:
F2B0C4CD490161F1C3B7BADD3C18408F808157ECE8EABA8A0B816F5D6B98B3F2
File Size:
522.62 KB, 522616 bytes
|
|
MD5:
d991e22a393b8c751435b34401174d0c
SHA1:
06ea9c180dd109c8a697fee7bf555dd852cd7e50
SHA256:
F9C55F367143399D28342CC9AEDFB90FACD2E6883432347E39728772F13F87E3
File Size:
506.23 KB, 506232 bytes
|
|
MD5:
48299cbd44aed46313c018a10ceb74d6
SHA1:
81ac3756e8d12f7fae81787253dcbc42c570e145
SHA256:
EE5DDB64C3FD51C11B5E064672B48B5440C37726225C235ACA07FF3E670E10DC
File Size:
471.01 KB, 471008 bytes
|
|
MD5:
18505c7577e0ced7f85ca3f8056e7cd0
SHA1:
778286d35f341dcfac2e230bd50bbe4712fd7c68
SHA256:
71D65C04441D04DDBA150DBA6700D24EAD94459CBBCF3CFFD75836E8EB86EA13
File Size:
500.71 KB, 500712 bytes
|
|
MD5:
4833a173bfeed017cf9f458a5cd2305a
SHA1:
4d1adbb69415bc6c8a11afa8f6ed34f5f58e40bf
SHA256:
6F764C5C898E50F81003C6C355E0206E370F52A81421397362DEA673E338F4CA
File Size:
471.42 KB, 471416 bytes
|
|
MD5:
a28818b9a84c83fd72f6b8ce8823be25
SHA1:
09d66ef8e6893bde76b0d0220bb83c15bf68dad0
SHA256:
F049181F6AE727A055927BF9F6C01757F36ADA3247214F8221D97EFED715CECD
File Size:
510.07 KB, 510072 bytes
|
|
MD5:
e7da8e0e046f9b66989cb88c32fb137e
SHA1:
d82ac41f96fe066d171cd0de4a7aa557db52cac4
SHA256:
548E9641D1403C563FA000DE3168D09BBDD628AB698A74E2ADB4E488B5C1BF09
File Size:
522.10 KB, 522104 bytes
|
|
MD5:
583f9e104e0396fa1ad60027a3f511bc
SHA1:
f151352c5c0a20cf48f0233bea68f776008c1254
SHA256:
9B94C9709052C13065E338DD6EF683F8765029438CB1E29D530842E3AE68BB8E
File Size:
504.32 KB, 504320 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have exports table
- File doesn't have relocations information
- File doesn't have security information
- File has been packed
- File has TLS information
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
Show More
- File is Native application (NOT .NET application)
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
File Icons
File Icons
This section displays icon resources found within family samples. Malware often replicates icons commonly associated with legitimate software to mislead users into believing the malware is safe.Show More
168 additional icons are not displayed above.
Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Company Name | GOG Sp. z o.o. |
| File Description |
Show More
|
| File Version | 2.0.0.2 |
| Internal Name | GOG Galaxy - Game Installer.exe |
| Legal Copyright | (C) GOG Sp. z o.o. 2020 |
| Product Name |
Show More
|
| Product Version | 2.0.0.2 |
Digital Signatures
Digital Signatures
This section lists digital signatures that are attached to samples within this family. When analyzing and verifying digital signatures, it is important to confirm that the signature’s root authority is a well-known and trustworthy entity and that the status of the signature is good. Malware is often signed with non-trustworthy “Self Signed” digital signatures (which can be easily created by a malware author with no verification). Malware may also be signed by legitimate signatures that have an invalid status, and by signatures from questionable root authorities with fake or misleading “Signer” names.| Signer | Root | Status |
|---|---|---|
| GOG sp. z o.o | GOG sp. z o.o | Self Signed |
File Traits
- HighEntropy
- Installer Version
- packed
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 3,277 |
|---|---|
| Potentially Malicious Blocks: | 286 |
| Whitelisted Blocks: | 2,991 |
| Unknown Blocks: | 0 |
Visual Map
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
x
0
0
0
x
x
x
x
x
x
x
x
0
0
0
0
0
0
0
0
0
0
0
0
0
x
x
0
0
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
0
0
0
0
0
0
0
x
x
x
x
x
0
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
x
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
x
x
x
x
x
x
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
x
x
x
0
0
x
x
x
x
x
0
0
x
x
x
0
0
x
x
0
0
x
0
0
0
0
0
0
x
0
x
x
x
x
0
0
x
x
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
x
x
0
0
x
x
0
0
x
0
0
0
x
x
x
x
x
x
0
0
0
0
0
0
0
0
0
0
0
0
0
x
x
x
x
0
0
x
0
x
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
x
0
0
0
0
0
x
x
x
x
0
0
0
0
0
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
0
0
0
0
0
0
0
0
0
0
x
x
0
0
0
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
x
0
0
0
0
0
0
0
0
0
0
0
0
x
x
0
x
x
x
0
0
0
0
0
x
x
x
x
0
0
x
0
0
x
x
0
0
0
x
x
0
0
x
0
0
0
0
0
0
0
0
x
0
0
0
0
x
x
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
x
x
x
x
x
x
x
x
x
0
x
x
x
x
x
x
x
x
0
x
0
x
x
x
x
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
x
1
0
x
x
0
x
x
0
x
0
x
x
0
0
0
0
x
0
0
0
0
x
x
0
0
0
0
0
x
0
0
0
0
0
0
0
0
0
0
0
0
0
x
0
0
0
0
x
0
0
0
0
x
x
0
0
0
0
x
x
0
0
0
x
x
x
x
x
x
x
x
x
0
x
0
0
x
x
x
x
0
x
x
x
x
x
x
x
x
x
x
x
0
x
x
0
0
x
0
x
x
x
0
x
0
0
0
0
x
0
0
0
x
x
0
0
0
0
x
x
0
x
0
0
0
0
0
0
x
x
x
x
x
x
x
0
0
0
0
x
0
x
0
0
0
0
0
0
x
x
x
0
0
0
0
0
x
0
0
0
x
x
x
0
0
0
0
0
x
x
0
0
0
0
0
x
0
x
x
0
0
x
0
0
x
0
0
0
0
0
0
0
x
x
0
0
0
x
x
x
0
0
0
0
0
0
1
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
1
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
1
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
1
1
1
1
0
0
0
1
0
0
0
1
0
1
0
0
0
0
1
1
1
2
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
1
0
1
1
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
...
Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block
? - Unknown Block
x - Potentially Malicious Block
Similar Families
Similar Families
This section lists other families that share similarities with this family, based on EnigmaSoft’s analysis. Many malware families are created from the same malware toolkits and use the same packing and encryption techniques but uniquely extend functionality. Similar families may also share source code, attributes, icons, subcomponents, compromised and/or invalid digital signatures, and network characteristics. Researchers leverage these similarities to rapidly and effectively triage file samples and extend malware detection rules.- Agent.LX
- MSIL.Brute.AAC
- MSIL.Brute.AAF
- MSIL.Brute.AAFA
- MSIL.Brute.AAR
Files Modified
Files Modified
This section lists files that were created, modified, moved and/or deleted by samples in this family. File system activity can provide valuable insight into how malware functions on the operating system.| File | Attributes |
|---|---|
| c:\programdata\gog.com\galaxy\logs\installerbootstrapper.log | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\de\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\es-mx\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\es\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\fr\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\galaxyinstaller.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\galaxyinstaller.exe.config | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\icon.ico | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\icon.png | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\it\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
Show More
| c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\ja\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\ko\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\payload.base64 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\pl\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\pt-br\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\ru\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\zh-hant\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_avuyz\zh\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\de\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\es-mx\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\es\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\fr\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\galaxyinstaller.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\galaxyinstaller.exe.config | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\icon.ico | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\icon.png | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\it\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\ja\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\ko\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\payload.base64 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\pl\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\pt-br\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\ru\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\zh-hant\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bbhzb\zh\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bcado\de\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bcado\es-mx\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bcado\es\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bcado\fr\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bcado\galaxyinstaller.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bcado\galaxyinstaller.exe.config | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bcado\icon.ico | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bcado\icon.png | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bcado\it\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bcado\ja\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bcado\ko\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bcado\payload.base64 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\galaxyinstaller_bcado\pl\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bcado\pt-br\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bcado\ru\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bcado\zh-hant\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_bcado\zh\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\de\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\es-mx\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\es\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\fr\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\galaxyinstaller.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\galaxyinstaller.exe.config | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\icon.ico | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\icon.png | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\it\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\ja\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\ko\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\payload.base64 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\pl\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\pt-br\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\ru\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\zh-hant\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cgabq\zh\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\de\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\es-mx\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\es\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\fr\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\galaxyinstaller.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\galaxyinstaller.exe.config | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\icon.ico | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\icon.png | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\it\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\ja\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\ko\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\payload.base64 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\pl\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\pt-br\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\ru\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\zh-hant\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_cplpw\zh\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\de\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\es-mx\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\es\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\fr\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\galaxyinstaller.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\galaxyinstaller.exe.config | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\icon.ico | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\icon.png | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\it\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\ja\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\ko\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\payload.base64 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\pl\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\pt-br\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\ru\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\zh-hant\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_dmdqo\zh\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_duyts\de\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_duyts\es-mx\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_duyts\es\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_duyts\fr\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_duyts\galaxyinstaller.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_duyts\galaxyinstaller.exe.config | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_duyts\icon.ico | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_duyts\icon.png | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_duyts\it\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_duyts\ja\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_duyts\ko\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_duyts\payload.base64 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\galaxyinstaller_duyts\pl\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_duyts\pt-br\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_duyts\ru\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_duyts\zh-hant\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_duyts\zh\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_efsvn\de\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_efsvn\es-mx\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_efsvn\es\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_efsvn\fr\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_efsvn\galaxyinstaller.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_efsvn\galaxyinstaller.exe.config | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_efsvn\icon.ico | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_efsvn\icon.png | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_efsvn\it\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_efsvn\ja\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_efsvn\ko\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_efsvn\payload.base64 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\galaxyinstaller_efsvn\pl\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_efsvn\pt-br\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_efsvn\ru\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_efsvn\zh-hant\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_efsvn\zh\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_elstc\de\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_elstc\es-mx\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_elstc\es\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_elstc\fr\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_elstc\galaxyinstaller.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_elstc\galaxyinstaller.exe.config | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_elstc\icon.ico | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_elstc\icon.png | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_elstc\it\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_elstc\ja\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_elstc\ko\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_elstc\payload.base64 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\galaxyinstaller_elstc\pl\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_elstc\pt-br\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_elstc\ru\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_elstc\zh-hant\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_elstc\zh\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_emros\de\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_emros\es-mx\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_emros\es\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_emros\fr\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_emros\galaxyinstaller.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_emros\galaxyinstaller.exe.config | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_emros\icon.ico | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_emros\icon.png | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_emros\it\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_emros\ja\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_emros\ko\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_emros\payload.base64 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\galaxyinstaller_emros\pl\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_emros\pt-br\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_emros\ru\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_emros\zh-hant\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_emros\zh\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fgjbv\de\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fgjbv\es-mx\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fgjbv\es\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fgjbv\fr\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fgjbv\galaxyinstaller.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fgjbv\galaxyinstaller.exe.config | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fgjbv\icon.ico | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fgjbv\icon.png | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fgjbv\it\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fgjbv\ja\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fgjbv\ko\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fgjbv\payload.base64 | Generic Write,Read Attributes |
| c:\users\user\appdata\local\temp\galaxyinstaller_fgjbv\pl\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fgjbv\pt-br\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fgjbv\ru\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fgjbv\zh-hant\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fgjbv\zh\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fvvfp\de\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fvvfp\es-mx\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fvvfp\es\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fvvfp\fr\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fvvfp\galaxyinstaller.exe | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fvvfp\galaxyinstaller.exe.config | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fvvfp\icon.ico | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fvvfp\icon.png | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fvvfp\it\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fvvfp\ja\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fvvfp\ko\galaxywebinstaller.resources.dll | Generic Read,Write Data,Write Attributes,Write extended,Append data |
| c:\users\user\appdata\local\temp\galaxyinstaller_fvvfp\payload.base64 | Generic Write,Read Attributes |
976 additional files are not displayed above.
Registry Modifications
Registry Modifications
This section lists registry keys and values that were created, modified and/or deleted by samples in this family. Windows Registry activity can provide valuable insight into malware functionality. Additionally, malware often creates registry values to allow itself to automatically start and indefinitely persist after an initial infection has compromised the system.| Key::Value | Data | API Name |
|---|---|---|
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet | RegNtPreCreateKey | |
| HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | 붳 ȁ 4 龡^ 紘Ç 獖} 좟Ê | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | 䵪 ĸ鈉øꌉĶꄍ阎Ľ鬎ʂԏÞ䈑Âø밓Ɣ똕ĥ츕ëǬ䈛x䤝Ē猟ɢ䀣ʲ갤Ç숤ʨ春ʐ븥ė椧ĒꄨěสĹ뜪Ģ윪Þ㴬倰ĥ䠱Oⰵɝ혺ɲ츻Ĵ噀ñ끀Ī덂®䡆¶賂¦홌ʅĤÁꝒª穔R띔Ü录Ī瑜ť፡Ĥ陣w걣ʛづŔ퍥h坧ʡ㹭ŃŁ詰ʜ䁱£㱲湲J畴ʣꍵ~ | RegNtPreCreateKey |
Show More
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | 퍵 ȁ ᮚ 龡^ Į 紘ÇŎ 獖} Ĵ 좟Ê | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | 墤 ĸ⬉ʾ鈉øꌉĶꄍ阎Ľ鬎ʂ먎ÍԏÞ阐䈑Âø밓Ɣ똕ĥ츕ë䈛x䤝Ē猟ɢ䀣ʲ찣ŏ갤Ç숤ʨ春ʐ븥ė椧ĒꄨěสĹ뜪Ģ윪Þ㴬倰ĥ䠱Oⰵɝ혺ɲ츻Ĵ噀ñ끀Ī덂®䡆¶賂¦홌ʅĤÁꝒª穔R띔Ü录Ī乖ʗ瑜ť፡Ĥ陣w걣ʛづŔ퍥h坧ʡ㹭ŃŁ詰ʜ䁱£ | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | 㑐 ȁ Ҷ 龡^ . 紘Ç2 獖} 3 좟Êh ֢ | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | 㯡 ȁ 偫~ Ꚑơʈ 龡^ 듛ï 紘ÇȢ 獖}( 偫~( 엦1 좟Êd ᵂċ ᵆċe 잀 엦1i ¶} ꙥ ꙥ | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | 闶 ȁ ਪˣ 鈯ˣ 遙̃ 豤̃ অˣ 炑̃ 龡^ 濖̃ 賬̃ 3 獖} 偫~ 엦1 ˣ 邯̃ 뫯ʃd ᵂċ ᵆċe ఆ 엦1 ¶i ꙥr ֢ | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | 闭 ȁ 獖} | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | 闪 ȁ 獖} 偫~ 엦1d ᵂċ ᵆċr ֢ | RegNtPreCreateKey |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey | |
| HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 | RegNtPreCreateKey |
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Network Urlomon |
|
| Anti Debug |
|
| User Data Access |
|
| Process Shell Execute |
|
| Syscall Use |
Show More
|
| Process Manipulation Evasion |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
(NULL) C:\Users\Lqywjgcg\AppData\Local\Temp\GalaxyInstaller_pAFBQ\GalaxyInstaller.exe 1439487606 "SOMA"
|
(NULL) C:\Users\Xjlzpcno\AppData\Local\Temp\GalaxyInstaller_XXRyK\GalaxyInstaller.exe 1716751705 "TUNIC"
|
(NULL) C:\Users\Byeyfpkv\AppData\Local\Temp\GalaxyInstaller_eFsvN\GalaxyInstaller.exe 1213448387 "Agony UNRATED"
|
(NULL) C:\Users\Pdelgmur\AppData\Local\Temp\GalaxyInstaller_JjsSl\GalaxyInstaller.exe 2067281194 "Crystal Caves HD"
|
(NULL) C:\Users\Kddmkfbc\AppData\Local\Temp\GalaxyInstaller_Rjjgo\GalaxyInstaller.exe 1209025141 "Horizon Zero Dawn™ Complete Edition"
|
Show More
(NULL) C:\Users\Whkhynwd\AppData\Local\Temp\GalaxyInstaller_uslRO\GalaxyInstaller.exe 1654462894 "Fetish Locator Week One"
|
(NULL) C:\Users\Ptbuhthb\AppData\Local\Temp\GalaxyInstaller_zEewm\GalaxyInstaller.exe 1937407919 "Mail Time"
|
(NULL) C:\Users\Njboqgjo\AppData\Local\Temp\GalaxyInstaller_YnXyq\GalaxyInstaller.exe 1871006055 "Little Nightmares II"
|
(NULL) C:\Users\Uzdthsau\AppData\Local\Temp\GalaxyInstaller_GajEP\GalaxyInstaller.exe 1207666913 "Mount & Blade: Warband"
|
(NULL) C:\Users\Oyzqeqdc\AppData\Local\Temp\GalaxyInstaller_IFaqC\GalaxyInstaller.exe 1592693763 "Treasure of Nadia"
|
(NULL) C:\Users\Buupcwwe\AppData\Local\Temp\GalaxyInstaller_Xwwzc\GalaxyInstaller.exe 2116300560 "System Shock Demo"
|
(NULL) C:\Users\Gidmabri\AppData\Local\Temp\GalaxyInstaller_lxjZh\GalaxyInstaller.exe 1293297882 "OpenTTD"
|
(NULL) C:\Users\Bglzehlm\AppData\Local\Temp\GalaxyInstaller_elSTC\GalaxyInstaller.exe 1421404581 "STAR WARS™ Knights of the Old Republic™ II: The Sith Lords™"
|
(NULL) C:\Users\Ehshvtid\AppData\Local\Temp\GalaxyInstaller_CPLPW\GalaxyInstaller.exe 1648559910 "Frostpunk"
|
(NULL) C:\Users\Fcrxbivg\AppData\Local\Temp\GalaxyInstaller_NcDbX\GalaxyInstaller.exe 2050639399 "FATE"
|
(NULL) C:\Users\Dqkxhaoc\AppData\Local\Temp\GalaxyInstaller_MqobP\GalaxyInstaller.exe 1453298883 "Project Zomboid"
|
(NULL) C:\Users\Zdkningn\AppData\Local\Temp\GalaxyInstaller_XMtLQ\GalaxyInstaller.exe 1207658713 "Stronghold Crusader HD"
|
(NULL) C:\Users\Xihkinxo\AppData\Local\Temp\GalaxyInstaller_UHmRx\GalaxyInstaller.exe 1827190281 "The Suicide of Rachel Foster"
|
(NULL) C:\Users\Uorgbamz\AppData\Local\Temp\GalaxyInstaller_Gytle\GalaxyInstaller.exe 1979367321 "Warbreeds"
|
(NULL) C:\Users\Hhjmrmac\AppData\Local\Temp\GalaxyInstaller_mmQgD\GalaxyInstaller.exe 1942346586 "Hitman: Blood Money"
|
(NULL) C:\Users\Ktwwfbdh\AppData\Local\Temp\GalaxyInstaller_RurrN\GalaxyInstaller.exe 1197512724 "Urbek City Builder Prologue"
|
(NULL) C:\Users\Qgspmcab\AppData\Local\Temp\GalaxyInstaller_qOLzg\GalaxyInstaller.exe 1354443325 "Kao the Kangaroo"
|
(NULL) C:\Users\Dlgskesu\AppData\Local\Temp\GalaxyInstaller_MpOiR\GalaxyInstaller.exe 1158493447 "Prey"
|
(NULL) C:\Users\Uybrilpu\AppData\Local\Temp\GalaxyInstaller_wFetH\GalaxyInstaller.exe 1207659210 "Don't Starve"
|
(NULL) C:\Users\Jusxvqgc\AppData\Local\Temp\GalaxyInstaller_UYCAv\GalaxyInstaller.exe 1097893768 "Neverwinter Nights: Enhanced Edition"
|
(NULL) C:\Users\Ycpxidfk\AppData\Local\Temp\GalaxyInstaller_yGeIP\GalaxyInstaller.exe 1940028140 "Two Point Hospital"
|
(NULL) C:\Users\Wuluehul\AppData\Local\Temp\GalaxyInstaller_FgJbV\GalaxyInstaller.exe 1847884051 "Wolfenstein II: The New Colossus"
|
(NULL) C:\Users\Arnpdzve\AppData\Local\Temp\GalaxyInstaller_ldzee\GalaxyInstaller.exe 2142923325 "Greak: Memories of Azur"
|
(NULL) C:\Users\Qoermhoi\AppData\Local\Temp\GalaxyInstaller_qystg\GalaxyInstaller.exe 1545755591 "SpongeBob SquarePants: Battle for Bikini Bottom - Rehydrated"
|
(NULL) C:\Users\Egqlbbun\AppData\Local\Temp\GalaxyInstaller_FVVFp\GalaxyInstaller.exe 1590012242 "Battle Brothers"
|
(NULL) C:\Users\Adcqqgrd\AppData\Local\Temp\GalaxyInstaller_hMVAq\GalaxyInstaller.exe 1508702879 "Stellaris"
|
(NULL) C:\Users\Jxpqhawl\AppData\Local\Temp\GalaxyInstaller_UxUgx\GalaxyInstaller.exe 1155924803 "Peglin"
|
(NULL) C:\Users\Emzkrjqu\AppData\Local\Temp\GalaxyInstaller_vICUE\GalaxyInstaller.exe 1308320804 "Hollow Knight"
|
(NULL) C:\Users\Ixkebtui\AppData\Local\Temp\GalaxyInstaller_HbosX\GalaxyInstaller.exe 1207664643 "The Witcher 3: Wild Hunt"
|
(NULL) C:\Users\Ruvdvtuy\AppData\Local\Temp\GalaxyInstaller_twdMW\GalaxyInstaller.exe 1958338581 "Cat Quest II"
|
(NULL) C:\Users\Helhgbms\AppData\Local\Temp\GalaxyInstaller_qUuZv\GalaxyInstaller.exe 1305299338 "Ghost Song"
|
(NULL) C:\Users\Mvpmmqjg\AppData\Local\Temp\GalaxyInstaller_myFkK\GalaxyInstaller.exe 1207658845 "Another World: 20th Anniversary Edition"
|
(NULL) C:\Users\Ciazshqq\AppData\Local\Temp\GalaxyInstaller_VHhaL\GalaxyInstaller.exe 1358404037 "Under the Witch"
|
(NULL) C:\Users\Sdrumymu\AppData\Local\Temp\GalaxyInstaller_PwVcz\GalaxyInstaller.exe 1629258827 "Deep Sky Derelicts"
|
(NULL) C:\Users\Xatqztxt\AppData\Local\Temp\GalaxyInstaller_UhuAT\GalaxyInstaller.exe 1508702879 "Stellaris"
|
C:\Users\Hhriuvby\AppData\Local\Temp\GalaxyInstaller_PPDxG\GalaxyInstaller.exe "C:\Users\Hhriuvby\AppData\Local\Temp\GalaxyInstaller_PPDxG\GalaxyInstaller.exe" 1797575342 "Battlestar Galactica Deadlock"
|
(NULL) C:\Users\Hhriuvby\AppData\Local\Temp\GalaxyInstaller_PPDxG\GalaxyInstaller.exe 1797575342 "Battlestar Galactica Deadlock"
|
C:\Users\Kqvmamrk\AppData\Local\Temp\GalaxyInstaller_oAWgh\GalaxyInstaller.exe "C:\Users\Kqvmamrk\AppData\Local\Temp\GalaxyInstaller_oAWgh\GalaxyInstaller.exe" 1455877361 "HuniePop 2: Double Date"
|
(NULL) C:\Users\Kqvmamrk\AppData\Local\Temp\GalaxyInstaller_oAWgh\GalaxyInstaller.exe 1455877361 "HuniePop 2: Double Date"
|
C:\Users\Xeipmcee\AppData\Local\Temp\GalaxyInstaller_emRos\GalaxyInstaller.exe "C:\Users\Xeipmcee\AppData\Local\Temp\GalaxyInstaller_emRos\GalaxyInstaller.exe" 1207666873 "This War of Mine"
|
(NULL) C:\Users\Xeipmcee\AppData\Local\Temp\GalaxyInstaller_emRos\GalaxyInstaller.exe 1207666873 "This War of Mine"
|
C:\Users\Twmhxrbs\AppData\Local\Temp\GalaxyInstaller_xltRl\GalaxyInstaller.exe "C:\Users\Twmhxrbs\AppData\Local\Temp\GalaxyInstaller_xltRl\GalaxyInstaller.exe" 1423049311 "Cyberpunk 2077"
|
(NULL) C:\Users\Twmhxrbs\AppData\Local\Temp\GalaxyInstaller_xltRl\GalaxyInstaller.exe 1423049311 "Cyberpunk 2077"
|
C:\Users\Kxzxhbgt\AppData\Local\Temp\GalaxyInstaller_rLoOa\GalaxyInstaller.exe "C:\Users\Kxzxhbgt\AppData\Local\Temp\GalaxyInstaller_rLoOa\GalaxyInstaller.exe" 1552771812 "A Plague Tale: Requiem"
|
(NULL) C:\Users\Kxzxhbgt\AppData\Local\Temp\GalaxyInstaller_rLoOa\GalaxyInstaller.exe 1552771812 "A Plague Tale: Requiem"
|
C:\Users\Rtnzeuvq\AppData\Local\Temp\GalaxyInstaller_DuYTs\GalaxyInstaller.exe "C:\Users\Rtnzeuvq\AppData\Local\Temp\GalaxyInstaller_DuYTs\GalaxyInstaller.exe" 1497384733 "OTXO"
|
(NULL) C:\Users\Rtnzeuvq\AppData\Local\Temp\GalaxyInstaller_DuYTs\GalaxyInstaller.exe 1497384733 "OTXO"
|
C:\Users\Tbwtnppw\AppData\Local\Temp\GalaxyInstaller_HGMZq\GalaxyInstaller.exe "C:\Users\Tbwtnppw\AppData\Local\Temp\GalaxyInstaller_HGMZq\GalaxyInstaller.exe" 1438948561 "Fran Bow"
|
(NULL) C:\Users\Tbwtnppw\AppData\Local\Temp\GalaxyInstaller_HGMZq\GalaxyInstaller.exe 1438948561 "Fran Bow"
|
C:\Users\Grwzppmf\AppData\Local\Temp\GalaxyInstaller_OtBaJ\GalaxyInstaller.exe "C:\Users\Grwzppmf\AppData\Local\Temp\GalaxyInstaller_OtBaJ\GalaxyInstaller.exe" 1601442230 "Shadow Tactics: Blades of the Shogun"
|
(NULL) C:\Users\Grwzppmf\AppData\Local\Temp\GalaxyInstaller_OtBaJ\GalaxyInstaller.exe 1601442230 "Shadow Tactics: Blades of the Shogun"
|
C:\Users\Ramtwyee\AppData\Local\Temp\GalaxyInstaller_wmAjT\GalaxyInstaller.exe "C:\Users\Ramtwyee\AppData\Local\Temp\GalaxyInstaller_wmAjT\GalaxyInstaller.exe" 1935795441 "18 Wheels of Steel: Extreme Trucker"
|
(NULL) C:\Users\Ramtwyee\AppData\Local\Temp\GalaxyInstaller_wmAjT\GalaxyInstaller.exe 1935795441 "18 Wheels of Steel: Extreme Trucker"
|
C:\Users\Oenltajo\AppData\Local\Temp\GalaxyInstaller_BcAdO\GalaxyInstaller.exe "C:\Users\Oenltajo\AppData\Local\Temp\GalaxyInstaller_BcAdO\GalaxyInstaller.exe" 1147957142 "Door Kickers: Action Squad"
|
(NULL) C:\Users\Oenltajo\AppData\Local\Temp\GalaxyInstaller_BcAdO\GalaxyInstaller.exe 1147957142 "Door Kickers: Action Squad"
|
C:\Users\Yosrauvr\AppData\Local\Temp\GalaxyInstaller_IsDjc\GalaxyInstaller.exe "C:\Users\Yosrauvr\AppData\Local\Temp\GalaxyInstaller_IsDjc\GalaxyInstaller.exe" 1456460669 "Baldur's Gate 3"
|
(NULL) C:\Users\Yosrauvr\AppData\Local\Temp\GalaxyInstaller_IsDjc\GalaxyInstaller.exe 1456460669 "Baldur's Gate 3"
|
C:\Users\Qqcftgdi\AppData\Local\Temp\GalaxyInstaller_ubpPX\GalaxyInstaller.exe "C:\Users\Qqcftgdi\AppData\Local\Temp\GalaxyInstaller_ubpPX\GalaxyInstaller.exe" 1423049311 "Cyberpunk 2077"
|
(NULL) C:\Users\Qqcftgdi\AppData\Local\Temp\GalaxyInstaller_ubpPX\GalaxyInstaller.exe 1423049311 "Cyberpunk 2077"
|
C:\Users\Bfqzaenf\AppData\Local\Temp\GalaxyInstaller_aVUyz\GalaxyInstaller.exe "C:\Users\Bfqzaenf\AppData\Local\Temp\GalaxyInstaller_aVUyz\GalaxyInstaller.exe" 1100566473 "Drakensang"
|
(NULL) C:\Users\Bfqzaenf\AppData\Local\Temp\GalaxyInstaller_aVUyz\GalaxyInstaller.exe 1100566473 "Drakensang"
|
C:\Users\Xyzrmktb\AppData\Local\Temp\GalaxyInstaller_UvTDg\GalaxyInstaller.exe "C:\Users\Xyzrmktb\AppData\Local\Temp\GalaxyInstaller_UvTDg\GalaxyInstaller.exe" 1744110647 "DREDGE"
|
(NULL) C:\Users\Xyzrmktb\AppData\Local\Temp\GalaxyInstaller_UvTDg\GalaxyInstaller.exe 1744110647 "DREDGE"
|
C:\Users\Acetzohg\AppData\Local\Temp\GalaxyInstaller_KcCuT\GalaxyInstaller.exe "C:\Users\Acetzohg\AppData\Local\Temp\GalaxyInstaller_KcCuT\GalaxyInstaller.exe" 2147483137 "The Falconeer"
|
(NULL) C:\Users\Acetzohg\AppData\Local\Temp\GalaxyInstaller_KcCuT\GalaxyInstaller.exe 2147483137 "The Falconeer"
|
C:\Users\Usgnjuzu\AppData\Local\Temp\GalaxyInstaller_wLOfn\GalaxyInstaller.exe "C:\Users\Usgnjuzu\AppData\Local\Temp\GalaxyInstaller_wLOfn\GalaxyInstaller.exe" 1207658911 "Dark Reign 2"
|
(NULL) C:\Users\Usgnjuzu\AppData\Local\Temp\GalaxyInstaller_wLOfn\GalaxyInstaller.exe 1207658911 "Dark Reign 2"
|
C:\Users\Dzfwblta\AppData\Local\Temp\GalaxyInstaller_jakrX\GalaxyInstaller.exe "C:\Users\Dzfwblta\AppData\Local\Temp\GalaxyInstaller_jakrX\GalaxyInstaller.exe" 1103034679 "Snowtopia Demo"
|
(NULL) C:\Users\Dzfwblta\AppData\Local\Temp\GalaxyInstaller_jakrX\GalaxyInstaller.exe 1103034679 "Snowtopia Demo"
|
C:\Users\Jrgsdwlt\AppData\Local\Temp\GalaxyInstaller_QtOij\GalaxyInstaller.exe "C:\Users\Jrgsdwlt\AppData\Local\Temp\GalaxyInstaller_QtOij\GalaxyInstaller.exe" 1430136184 "Pacific General"
|
(NULL) C:\Users\Jrgsdwlt\AppData\Local\Temp\GalaxyInstaller_QtOij\GalaxyInstaller.exe 1430136184 "Pacific General"
|
C:\Users\Xmmwsves\AppData\Local\Temp\GalaxyInstaller_XQAgA\GalaxyInstaller.exe "C:\Users\Xmmwsves\AppData\Local\Temp\GalaxyInstaller_XQAgA\GalaxyInstaller.exe" 1456460669 "Baldur's Gate 3"
|
(NULL) C:\Users\Xmmwsves\AppData\Local\Temp\GalaxyInstaller_XQAgA\GalaxyInstaller.exe 1456460669 "Baldur's Gate 3"
|
C:\Users\Qqxhmhnq\AppData\Local\Temp\GalaxyInstaller_ucpus\GalaxyInstaller.exe "C:\Users\Qqxhmhnq\AppData\Local\Temp\GalaxyInstaller_ucpus\GalaxyInstaller.exe" 1207658680 "Arx Fatalis"
|
(NULL) C:\Users\Qqxhmhnq\AppData\Local\Temp\GalaxyInstaller_ucpus\GalaxyInstaller.exe 1207658680 "Arx Fatalis"
|
C:\Users\Kwcrcmiw\AppData\Local\Temp\GalaxyInstaller_UlFqu\GalaxyInstaller.exe "C:\Users\Kwcrcmiw\AppData\Local\Temp\GalaxyInstaller_UlFqu\GalaxyInstaller.exe" 1381758449 "Vagrus - The Riven Realms: Prologue"
|
(NULL) C:\Users\Kwcrcmiw\AppData\Local\Temp\GalaxyInstaller_UlFqu\GalaxyInstaller.exe 1381758449 "Vagrus - The Riven Realms: Prologue"
|
C:\Users\Nviumapf\AppData\Local\Temp\GalaxyInstaller_cGabq\GalaxyInstaller.exe "C:\Users\Nviumapf\AppData\Local\Temp\GalaxyInstaller_cGabq\GalaxyInstaller.exe" 1094441612 "Super Huey™ 1 & 2 Airdrop"
|
(NULL) C:\Users\Nviumapf\AppData\Local\Temp\GalaxyInstaller_cGabq\GalaxyInstaller.exe 1094441612 "Super Huey™ 1 & 2 Airdrop"
|
C:\Users\Shuevwtk\AppData\Local\Temp\GalaxyInstaller_Lmwsd\GalaxyInstaller.exe "C:\Users\Shuevwtk\AppData\Local\Temp\GalaxyInstaller_Lmwsd\GalaxyInstaller.exe" 1992658104 "Imperium Romanum Gold Edition"
|
(NULL) C:\Users\Shuevwtk\AppData\Local\Temp\GalaxyInstaller_Lmwsd\GalaxyInstaller.exe 1992658104 "Imperium Romanum Gold Edition"
|
C:\Users\Zedgcpdx\AppData\Local\Temp\GalaxyInstaller_dmDQo\GalaxyInstaller.exe "C:\Users\Zedgcpdx\AppData\Local\Temp\GalaxyInstaller_dmDQo\GalaxyInstaller.exe" 1426240474 "The Whisperer"
|
(NULL) C:\Users\Zedgcpdx\AppData\Local\Temp\GalaxyInstaller_dmDQo\GalaxyInstaller.exe 1426240474 "The Whisperer"
|
C:\Users\Rezerieg\AppData\Local\Temp\GalaxyInstaller_tsTCt\GalaxyInstaller.exe "C:\Users\Rezerieg\AppData\Local\Temp\GalaxyInstaller_tsTCt\GalaxyInstaller.exe" 1316203883 "Chicken Assassin: Reloaded"
|
(NULL) C:\Users\Rezerieg\AppData\Local\Temp\GalaxyInstaller_tsTCt\GalaxyInstaller.exe 1316203883 "Chicken Assassin: Reloaded"
|
C:\Users\Aatvwwzg\AppData\Local\Temp\GalaxyInstaller_Khudr\GalaxyInstaller.exe "C:\Users\Aatvwwzg\AppData\Local\Temp\GalaxyInstaller_Khudr\GalaxyInstaller.exe" 1084263831 "Just Cause"
|
(NULL) C:\Users\Aatvwwzg\AppData\Local\Temp\GalaxyInstaller_Khudr\GalaxyInstaller.exe 1084263831 "Just Cause"
|
C:\Users\Ikyxwocy\AppData\Local\Temp\GalaxyInstaller_BBhzB\GalaxyInstaller.exe "C:\Users\Ikyxwocy\AppData\Local\Temp\GalaxyInstaller_BBhzB\GalaxyInstaller.exe" 1349516820 "Werewolf: The Apocalypse - Earthblood"
|
(NULL) C:\Users\Ikyxwocy\AppData\Local\Temp\GalaxyInstaller_BBhzB\GalaxyInstaller.exe 1349516820 "Werewolf: The Apocalypse - Earthblood"
|
C:\Users\Wfxewsvo\AppData\Local\Temp\GalaxyInstaller_upwiU\GalaxyInstaller.exe "C:\Users\Wfxewsvo\AppData\Local\Temp\GalaxyInstaller_upwiU\GalaxyInstaller.exe" 1785384169 "CARRION"
|
(NULL) C:\Users\Wfxewsvo\AppData\Local\Temp\GalaxyInstaller_upwiU\GalaxyInstaller.exe 1785384169 "CARRION"
|
C:\Users\Ufexmazn\AppData\Local\Temp\GalaxyInstaller_GNCbg\GalaxyInstaller.exe "C:\Users\Ufexmazn\AppData\Local\Temp\GalaxyInstaller_GNCbg\GalaxyInstaller.exe" 1974801979 "Once Upon a Jester"
|
(NULL) C:\Users\Ufexmazn\AppData\Local\Temp\GalaxyInstaller_GNCbg\GalaxyInstaller.exe 1974801979 "Once Upon a Jester"
|