Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
PlasmaSetup@LR_2.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
|
initial sample
|
||
C:\Plasma\Switcher.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Plasma\pbrowser.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Plasma\pmanager.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Plasma\pmarquee.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Plasma\uninst.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\nsc7F3F.tmp\InstallOptions.dll
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\nsc7F3F.tmp\LangDLL.dll
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Plasma\AKISDB.FDB
|
data
|
dropped
|
||
C:\Plasma\Arabicp.ini
|
ISO-8859 text, with CRLF, LF line terminators
|
dropped
|
||
C:\Plasma\Englishp.ini
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Plasma\Lithuansw.ini
|
ISO-8859 text, with CRLF line terminators
|
dropped
|
||
C:\Plasma\PLASMA.HLP
|
MS Windows 3.1 help, Thu Sep 14 12:44:24 2006, 5564 bytes
|
dropped
|
||
C:\Plasma\Plasma.url
|
MS Windows 95 Internet shortcut text (URL=<http://www.tipas.lt/>), ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Plasma\Polishp.ini
|
Non-ISO extended-ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Plasma\Polishsw.ini
|
ISO-8859 text, with CRLF line terminators
|
dropped
|
||
C:\Plasma\Russianp.ini
|
ISO-8859 text, with CRLF line terminators
|
dropped
|
||
C:\Plasma\Russiansw.ini
|
ISO-8859 text, with CRLF line terminators
|
dropped
|
||
C:\Plasma\TVTuner.htm
|
HTML document, ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Plasma\dvd_template.htm
|
HTML document, ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Plasma\empty_template.htm
|
HTML document, ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Plasma\film_template.htm
|
HTML document, ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Plasma\film_template_VLC.htm
|
HTML document, ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Plasma\flash_template.htm
|
HTML document, ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Plasma\img_template.htm
|
HTML document, ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Plasma\pbrowser.LIC
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Plasma\unistr.ini
|
Unicode text, UTF-16, little-endian text, with CRLF line terminators
|
dropped
|
||
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_pmanager.exe_8fbfe26353771c42d2099f513f03c31e2638e2_78c312fa_105b4730-6843-4b6e-ac83-c949d0250b84\Report.wer
|
Unicode text, UTF-16, little-endian text, with CRLF line terminators
|
dropped
|
||
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_pmanager.exe_8fbfe26353771c42d2099f513f03c31e2638e2_78c312fa_15d6b9e6-acb0-424a-ac38-5fdc254995e6\Report.wer
|
Unicode text, UTF-16, little-endian text, with CRLF line terminators
|
dropped
|
||
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_pmanager.exe_8fbfe26353771c42d2099f513f03c31e2638e2_78c312fa_c2afb5d5-c6fd-4afc-b662-586a033862a7\Report.wer
|
Unicode text, UTF-16, little-endian text, with CRLF line terminators
|
dropped
|
||
C:\ProgramData\Microsoft\Windows\WER\Temp\WER1350.tmp.dmp
|
Mini DuMP crash report, 14 streams, Sat Dec 21 13:27:49 2024, 0x1205a4 type
|
dropped
|
||
C:\ProgramData\Microsoft\Windows\WER\Temp\WER13AF.tmp.WERInternalMetadata.xml
|
XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
|
dropped
|
||
C:\ProgramData\Microsoft\Windows\WER\Temp\WER13CF.tmp.xml
|
XML 1.0 document, ASCII text, with CRLF line terminators
|
dropped
|
||
C:\ProgramData\Microsoft\Windows\WER\Temp\WERA06D.tmp.dmp
|
Mini DuMP crash report, 14 streams, Sat Dec 21 13:28:25 2024, 0x1205a4 type
|
dropped
|
||
C:\ProgramData\Microsoft\Windows\WER\Temp\WERA0AD.tmp.WERInternalMetadata.xml
|
XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
|
dropped
|
||
C:\ProgramData\Microsoft\Windows\WER\Temp\WERA0CD.tmp.xml
|
XML 1.0 document, ASCII text, with CRLF line terminators
|
dropped
|
||
C:\ProgramData\Microsoft\Windows\WER\Temp\WERF902.tmp.dmp
|
Mini DuMP crash report, 14 streams, Sat Dec 21 13:27:42 2024, 0x1205a4 type
|
dropped
|
||
C:\ProgramData\Microsoft\Windows\WER\Temp\WERF990.tmp.WERInternalMetadata.xml
|
XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
|
dropped
|
||
C:\ProgramData\Microsoft\Windows\WER\Temp\WERF9B0.tmp.xml
|
XML 1.0 document, ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\nsc7F3F.tmp\ioSpecial.ini
|
Generic INItialization configuration [Field 1]
|
modified
|
||
C:\Users\user\AppData\Local\Temp\nsc7F3F.tmp\modern-wizard.bmp
|
PC bitmap, Windows 3.x format, 164 x 314 x 4, image size 26376, resolution 2834 x 2834 px/m, cbSize 26494, bits offset 118
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plasma\Browser.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive,
ctime=Fri Mar 19 11:26:08 2010, mtime=Sat Dec 21 12:27:31 2024, atime=Fri Mar 19 11:26:08 2010, length=551936, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plasma\Manager.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive,
ctime=Fri Mar 19 11:26:28 2010, mtime=Sat Dec 21 12:27:31 2024, atime=Fri Mar 19 11:26:28 2010, length=647168, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plasma\Uninstall.lnk
|
MS Windows shortcut, Item id list present, Has Relative path, Has Working directory, ctime=Sun Dec 31 23:25:52 1600, mtime=Sun
Dec 31 23:25:52 1600, atime=Sun Dec 31 23:25:52 1600, length=0, window=hide
|
dropped
|
||
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plasma\Website.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive,
ctime=Sat Dec 21 12:27:31 2024, mtime=Sat Dec 21 12:27:31 2024, atime=Sat Dec 21 12:27:31 2024, length=46, window=hide
|
dropped
|
||
C:\Users\user\Desktop\Browser.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive,
ctime=Fri Mar 19 11:26:08 2010, mtime=Sat Dec 21 12:27:31 2024, atime=Fri Mar 19 11:26:08 2010, length=551936, window=hide
|
dropped
|
||
C:\Users\user\Desktop\Manager.lnk
|
MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive,
ctime=Fri Mar 19 11:26:28 2010, mtime=Sat Dec 21 12:27:31 2024, atime=Fri Mar 19 11:26:28 2010, length=647168, window=hide
|
dropped
|
There are 37 hidden files, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
52.182.143.212
|
unknown
|
United States
|
||
20.189.173.21
|
unknown
|
United States
|