Analysis
-
max time kernel
149s -
max time network
153s -
platform
windows10-2004_x64 -
resource
win10v2004-20240508-en -
resource tags
arch:x64arch:x86image:win10v2004-20240508-enlocale:en-usos:windows10-2004-x64system -
submitted
01-07-2024 04:29
Static task
static1
Behavioral task
behavioral1
Sample
355be9ffb447fe5932a5b2862081c31fa45c3b8f920a862d87979cae2069eb8a_NeikiAnalytics.exe
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
355be9ffb447fe5932a5b2862081c31fa45c3b8f920a862d87979cae2069eb8a_NeikiAnalytics.exe
Resource
win10v2004-20240508-en
General
-
Target
355be9ffb447fe5932a5b2862081c31fa45c3b8f920a862d87979cae2069eb8a_NeikiAnalytics.exe
-
Size
123KB
-
MD5
d2ce7ba20895ffee91d9b5df9a86a190
-
SHA1
0b29e1a06fde84c029a0a0c6b2b3129a9bcf574c
-
SHA256
355be9ffb447fe5932a5b2862081c31fa45c3b8f920a862d87979cae2069eb8a
-
SHA512
ec02c7a3f329c42ad6fe72790c408e45434b02da245ada033451d18d784c91a4d4b762d8a117cd9e5762c74cf8345636c7e9c6cd951a27612339bf3a00688e68
-
SSDEEP
768:W7BlpppARFbhWJq5ovYcTEXBwzEXBw67BlpppARFbhWJq5ovYcTEXBwzEXBwz:W7ZppApF5ovs7ZppApF5ovd
Malware Config
Signatures
-
Renames multiple (4883) files with added filename extension
This suggests ransomware activity of encrypting all the files on the system.
-
Executes dropped EXE 2 IoCs
Processes:
Zombie.exe_Test-WindowsUpdate.ps1.exepid process 4440 Zombie.exe 2512 _Test-WindowsUpdate.ps1.exe -
Drops file in System32 directory 2 IoCs
Processes:
355be9ffb447fe5932a5b2862081c31fa45c3b8f920a862d87979cae2069eb8a_NeikiAnalytics.exedescription ioc process File created C:\Windows\SysWOW64\Zombie.exe 355be9ffb447fe5932a5b2862081c31fa45c3b8f920a862d87979cae2069eb8a_NeikiAnalytics.exe File opened for modification C:\Windows\SysWOW64\Zombie.exe 355be9ffb447fe5932a5b2862081c31fa45c3b8f920a862d87979cae2069eb8a_NeikiAnalytics.exe -
Drops file in Program Files directory 64 IoCs
Processes:
Zombie.exe_Test-WindowsUpdate.ps1.exedescription ioc process File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.27\mscordbi.dll.tmp Zombie.exe File opened for modification C:\Program Files\dotnet\shared\Microsoft.NETCore.App\7.0.16\System.Threading.Timer.dll.tmp Zombie.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\UIAutomationClientSideProviders.dll.tmp _Test-WindowsUpdate.ps1.exe File created C:\Program Files\Microsoft Office\root\Licenses16\Standard2019VL_MAK_AE-pl.xrm-ms.tmp Zombie.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.2\Microsoft.DiaSymReader.Native.amd64.dll.tmp Zombie.exe File created C:\Program Files\Microsoft Office\root\Client\AppvIsvSubsystems32.dll.tmp _Test-WindowsUpdate.ps1.exe File created C:\Program Files\Microsoft Office\root\Licenses16\ProjectStd2019R_Retail-ul-oob.xrm-ms.tmp _Test-WindowsUpdate.ps1.exe File created C:\Program Files\Microsoft Office\root\Licenses16\WordR_Trial-ppd.xrm-ms.tmp Zombie.exe File created C:\Program Files\Microsoft Office\root\Office16\ONBttnOL.dll.tmp Zombie.exe File opened for modification C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.27\System.IO.Compression.dll.tmp Zombie.exe File opened for modification C:\Program Files\dotnet\shared\Microsoft.NETCore.App\7.0.16\System.Data.Common.dll.tmp _Test-WindowsUpdate.ps1.exe File created C:\Program Files\Java\jdk-1.8\jre\bin\bci.dll.tmp Zombie.exe File created C:\Program Files\Microsoft Office\root\Licenses16\Excel2019VL_MAK_AE-ul-phn.xrm-ms.tmp _Test-WindowsUpdate.ps1.exe File opened for modification C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\main\base_altgr.xml.tmp Zombie.exe File opened for modification C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.27\System.IO.Compression.Brotli.dll.tmp Zombie.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\7.0.16\System.Collections.NonGeneric.dll.tmp Zombie.exe File opened for modification C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\Accessibility.dll.tmp _Test-WindowsUpdate.ps1.exe File opened for modification C:\Program Files\Java\jre-1.8\bin\hprof.dll.tmp _Test-WindowsUpdate.ps1.exe File opened for modification C:\Program Files\Java\jre-1.8\lib\images\cursors\win32_CopyDrop32x32.gif.tmp Zombie.exe File created C:\Program Files\Microsoft Office\root\Office16\LogoImages\ExcelLogo.contrast-white_scale-180.png.tmp _Test-WindowsUpdate.ps1.exe File opened for modification C:\Program Files\dotnet\shared\Microsoft.NETCore.App\7.0.16\System.Threading.Overlapped.dll.tmp Zombie.exe File opened for modification C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\UIAutomationClient.dll.tmp Zombie.exe File opened for modification C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\8.0.2\ja\PresentationUI.resources.dll.tmp Zombie.exe File opened for modification C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\8.0.2\PresentationFramework.Classic.dll.tmp Zombie.exe File created C:\Program Files\Java\jre-1.8\legal\jdk\relaxngcc.md.tmp _Test-WindowsUpdate.ps1.exe File opened for modification C:\Program Files\Microsoft Office\root\Client\AppVDllSurrogate32.exe.tmp _Test-WindowsUpdate.ps1.exe File opened for modification C:\Program Files\Microsoft Office\root\Office16\LogoImages\PowerPntLogoSmall.contrast-black_scale-180.png.tmp _Test-WindowsUpdate.ps1.exe File created C:\Program Files\Google\Chrome\Application\110.0.5481.104\Locales\ur.pak.tmp Zombie.exe File created C:\Program Files\Microsoft Office\root\Office16\1033\ospintl.dll.tmp _Test-WindowsUpdate.ps1.exe File created C:\Program Files\Microsoft Office\root\Office16\ADDINS\EduWorks Data Streamer Add-In\System.ValueTuple.dll.tmp Zombie.exe File opened for modification C:\Program Files\Microsoft Office\root\Office16\LogoImages\ExcelLogo.scale-180.png.tmp _Test-WindowsUpdate.ps1.exe File created C:\Program Files\Common Files\microsoft shared\ink\ipsdeu.xml.tmp Zombie.exe File opened for modification C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.2\System.Xml.Serialization.dll.tmp _Test-WindowsUpdate.ps1.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.2\System.Xml.XPath.XDocument.dll.tmp _Test-WindowsUpdate.ps1.exe File created C:\Program Files\Java\jdk-1.8\legal\javafx\webkit.md.tmp Zombie.exe File created C:\Program Files\Microsoft Office\root\Office16\1033\ClientPreview_eula.txt.tmp _Test-WindowsUpdate.ps1.exe File created C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\word2013bw.dotx.tmp Zombie.exe File created C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.Container.exe.config.tmp Zombie.exe File opened for modification C:\Program Files\Microsoft Office\root\Office16\Library\Analysis\PROCDB.XLAM.tmp Zombie.exe File opened for modification C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RINTL.hi-in.dll.tmp _Test-WindowsUpdate.ps1.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\7.0.16\System.Transactions.dll.tmp _Test-WindowsUpdate.ps1.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.2\System.Diagnostics.TraceSource.dll.tmp _Test-WindowsUpdate.ps1.exe File opened for modification C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\PresentationFramework.dll.tmp Zombie.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\7.0.16\zh-Hant\WindowsBase.resources.dll.tmp _Test-WindowsUpdate.ps1.exe File opened for modification C:\Program Files\Microsoft Office\root\Office16\ADDINS\Power Map Excel Add-in\VISUALIZATIONCHART.DLL.tmp _Test-WindowsUpdate.ps1.exe File opened for modification C:\Program Files\Common Files\microsoft shared\ClickToRun\msix.dll.tmp Zombie.exe File opened for modification C:\Program Files\Common Files\microsoft shared\ink\fsdefinitions\insert.xml.tmp _Test-WindowsUpdate.ps1.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\6.0.27\netstandard.dll.tmp Zombie.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\8.0.2\System.Configuration.dll.tmp _Test-WindowsUpdate.ps1.exe File created C:\Program Files\Java\jdk-1.8\bin\ucrtbase.dll.tmp _Test-WindowsUpdate.ps1.exe File created C:\Program Files\Microsoft Office\root\Office16\PersonaSpy\notice.txt.exe.tmp Zombie.exe File created C:\Program Files\Common Files\System\msadc\adcjavas.inc.tmp _Test-WindowsUpdate.ps1.exe File created C:\Program Files\Microsoft Office\root\Office16\BORDERS\MSART11.BDR.tmp _Test-WindowsUpdate.ps1.exe File opened for modification C:\Program Files\Microsoft Office\root\Office16\PPCORE.DLL.tmp Zombie.exe File created C:\Program Files\dotnet\shared\Microsoft.NETCore.App\7.0.16\System.IO.FileSystem.Watcher.dll.tmp Zombie.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\6.0.27\fr\UIAutomationTypes.resources.dll.tmp _Test-WindowsUpdate.ps1.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\7.0.16\tr\PresentationFramework.resources.dll.tmp _Test-WindowsUpdate.ps1.exe File opened for modification C:\Program Files\Microsoft Office\root\Licenses16\ProjectProO365R_SubTrial-ppd.xrm-ms.tmp _Test-WindowsUpdate.ps1.exe File created C:\Program Files\Microsoft Office\root\Office16\ADDINS\PowerPivot Excel Add-in\Cartridges\db2v0801.xsl.tmp _Test-WindowsUpdate.ps1.exe File created C:\Program Files\Microsoft Office\root\Office16\LogoImages\OneNoteLogoSmall.contrast-black_scale-140.png.tmp _Test-WindowsUpdate.ps1.exe File created C:\Program Files\7-Zip\Lang\fa.txt.tmp Zombie.exe File created C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\7.0.16\de\ReachFramework.resources.dll.tmp Zombie.exe File opened for modification C:\Program Files\Google\Chrome\Application\110.0.5481.104\Locales\ko.pak.tmp Zombie.exe File opened for modification C:\Program Files\Java\jdk-1.8\jre\legal\jdk\lcms.md.tmp _Test-WindowsUpdate.ps1.exe -
Suspicious use of WriteProcessMemory 6 IoCs
Processes:
355be9ffb447fe5932a5b2862081c31fa45c3b8f920a862d87979cae2069eb8a_NeikiAnalytics.exedescription pid process target process PID 2028 wrote to memory of 4440 2028 355be9ffb447fe5932a5b2862081c31fa45c3b8f920a862d87979cae2069eb8a_NeikiAnalytics.exe Zombie.exe PID 2028 wrote to memory of 4440 2028 355be9ffb447fe5932a5b2862081c31fa45c3b8f920a862d87979cae2069eb8a_NeikiAnalytics.exe Zombie.exe PID 2028 wrote to memory of 4440 2028 355be9ffb447fe5932a5b2862081c31fa45c3b8f920a862d87979cae2069eb8a_NeikiAnalytics.exe Zombie.exe PID 2028 wrote to memory of 2512 2028 355be9ffb447fe5932a5b2862081c31fa45c3b8f920a862d87979cae2069eb8a_NeikiAnalytics.exe _Test-WindowsUpdate.ps1.exe PID 2028 wrote to memory of 2512 2028 355be9ffb447fe5932a5b2862081c31fa45c3b8f920a862d87979cae2069eb8a_NeikiAnalytics.exe _Test-WindowsUpdate.ps1.exe PID 2028 wrote to memory of 2512 2028 355be9ffb447fe5932a5b2862081c31fa45c3b8f920a862d87979cae2069eb8a_NeikiAnalytics.exe _Test-WindowsUpdate.ps1.exe
Processes
-
C:\Users\Admin\AppData\Local\Temp\355be9ffb447fe5932a5b2862081c31fa45c3b8f920a862d87979cae2069eb8a_NeikiAnalytics.exe"C:\Users\Admin\AppData\Local\Temp\355be9ffb447fe5932a5b2862081c31fa45c3b8f920a862d87979cae2069eb8a_NeikiAnalytics.exe"1⤵
- Drops file in System32 directory
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\Zombie.exe"C:\Windows\system32\Zombie.exe"2⤵
- Executes dropped EXE
- Drops file in Program Files directory
-
C:\Users\Admin\AppData\Local\Temp\_Test-WindowsUpdate.ps1.exe"_Test-WindowsUpdate.ps1.exe"2⤵
- Executes dropped EXE
- Drops file in Program Files directory
Network
MITRE ATT&CK Matrix
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\$Recycle.Bin\S-1-5-21-4124900551-4068476067-3491212533-1000\desktop.ini.exeFilesize
60KB
MD5aef5243843ebddadcbfffc6489fb1e91
SHA141a0faf1f8be2bb95933f8334b0feaab442aeaf6
SHA25620771f85df5467451ff4c8b086619bce57e8774db0e07a79128e7f253c6265f6
SHA512ff0e9142c6c52b0ed39a52a2599e36ef27275e4bf4525a52c85c3b3f4069f558402a7b4f36960477d44eaca69c189c8c0844b0a53a1c276e85d579a5422866f7
-
C:\$Recycle.Bin\S-1-5-21-4124900551-4068476067-3491212533-1000\desktop.ini.exe.tmpFilesize
123KB
MD5269367734d078cf347f0364a14c0c9d8
SHA1e9a01390bede33f597fb10dbed29c2b5be346ba7
SHA256532f240fc73a5b6367c1fb733cd4771b9468098e1f6b704700d0afad22506de2
SHA512dd4ad652cdec409ba36cbb886c45cd4283e13978e0f6986ddbf03ba072cd1e393773b1762f53e280f5e0ec6caf5a710f847092f394dfd2b2c7e8d5293cc04043
-
C:\Program Files\7-Zip\7-zip.chm.exeFilesize
172KB
MD5b710950e92ead4751ce30ac3c354919e
SHA1571cd072936dde7e90e81d5807f199808d187395
SHA256d7e37ad4f1c9fdc5fbfc29713b539af9f93e7c634b5dba34ddaf57e0219d7f92
SHA51241018ef9378767c291359777d1ce9f5d9c0e4c12adfd1b478a5cccd919abb9036ab14300467b7a7b000cb8359f02da4f0300b10e0ec022bf025da2d22aada15f
-
C:\Program Files\7-Zip\7-zip.dll.exeFilesize
159KB
MD52598d7087bba53d03017f9fd3a6e711c
SHA1a6d380eb062ebd57c0c6b7df8f186bd1a9f72bf6
SHA256c80d5c7be9efd27379b802f9a93625bd040149d755574b1b83e24961ec7828aa
SHA512dc0e4fb43aa126d5eee2a931678f21f1f2cf9ba4a7491d8fdc67bdb3ccdc73c40fe37c50ff8bbe2d7e9edf175317c2bdaeb21a453577dd7566b5e648b02fcbdc
-
C:\Program Files\7-Zip\7z.dll.tmpFilesize
1.8MB
MD544bc5982e2c79d8e1c6082d561e40c75
SHA1f2141398dd2951e3619a51ad0c551c6200b570f7
SHA256c943710bbe5b5488eb810e81a061c16a0b2a601d1d2cf7462601894943fdbee6
SHA512132a2c428947bd1c759dc6470173aa9f15da9546ea189114ef4b5d222b9ca83d5ab1081f5aa3683dbf76b8326c570a2aa806d46eae8a90dfb6c932f8f8024247
-
C:\Program Files\7-Zip\7z.exeFilesize
604KB
MD545f83864082487f7e2064ac1c0d01eb0
SHA12d97b85a5cde7f3921b9f570e33b10a7f0965615
SHA256a25c741d65be2ecc764b4f1d3c52a6e4ef83b30367e6da658ee54cb74f31f7d2
SHA512729a3eebd5ac9d91c99e22449844e442d812bfcc17e1ccb856dcad8835a49f7fb721a2de75e67e17412f7b040b42519dc9bf33b025b8b313c93e082eecaebc7a
-
C:\Program Files\7-Zip\7zFM.exe.tmpFilesize
993KB
MD5786201a6e6eb626d8b77255f0777c868
SHA1c6ac213114587fc4e01ea86e97c2e40958c2bf11
SHA256d5c1f6c61bc97e383b5cf904d867836c28c88a51022a1045e16f822024e4a22f
SHA512063686fcae5217e7ab879a0fcf7a5761fc1f94bf1b74c08208d64cc041fbeeaccf5add844aa5e6180e27444952dac651684c082b3ff1de6b1f8ee139568acc96
-
C:\Program Files\7-Zip\7zG.exe.tmpFilesize
747KB
MD5542778c86a3fb309c28c3f6c6505c31a
SHA15ed31c45e3de469cf760666947a13666a4dbc738
SHA256f4a0afd027838dd83642dbab351a4741a7e22ec248f912efd0dfd8e5017606dd
SHA51281116f0df4d37e5db57ae30ec91a2523049c7783f7065d32e6423c369f085c7566c55237b675d6efbbfa04be5ffb44666114228731fe6520473a75e34f988df7
-
C:\Program Files\7-Zip\History.txt.tmpFilesize
119KB
MD50db93d3615551f0a7ee285049275c56a
SHA1fa4e94a15c898d5068940a3c30ab4ac9ff53088c
SHA256d63dced468a71e8e9c5c7ba9ad1d839321330983c50aa7a34ffccc0d2cddc875
SHA512070300182fa5a74a7d5f54c6020eae3e6923bd48c1d1a84fc10f649ba95455be9052747de89ae7454ac51d03fd442a0b97f1df446dfede4b434533d98c90b46d
-
C:\Program Files\7-Zip\Lang\af.txt.tmpFilesize
72KB
MD5e9ee9c1ca8aa597faa41b609548c572d
SHA17c6903f6e32313afb95f0322254d2805cc0c8935
SHA256ec43164a6f8e4854fe3ceb691cfcdd8572d77d5c39f766b900ce359d0f6145ed
SHA512b760ddd5bd9c3744c8f2bfe3c122ae005056ce198f5caf31d16af72b6dec8d03070f9ff33ff166d8e578e0a8c977dc6cd5f87c0c92401026915f3ed3758455f8
-
C:\Program Files\7-Zip\Lang\ast.txt.tmpFilesize
68KB
MD581253533327c3b1d79d6621dd1089b68
SHA1dca0fd66a34743c70f76825d06436fc534e862f4
SHA2564092275a5235fc1853ebfec10705a0be7705dbfebfe627eca3563f15d02876e9
SHA512305255f68a0896f5121117a45c6c903305fddb634e9d2aab0e0265d5bb25967e7afcc5c5b39f88cd526719700ed16f27a970e7591fa746d5ed9a060febfe27e7
-
C:\Program Files\7-Zip\Lang\bg.txt.tmpFilesize
75KB
MD57448313cfc2114c150b8b252001a2547
SHA10eadfac1c5750ff1faacce63418375b773243caf
SHA25627132a9cf3229b364aa8f3ebfeadd0ae2d57c01de6eb5762635f4739a58c2570
SHA5129d58b91e144abccbaa0f01e5d2e72c04278ac2ad5ceffcb5a7ad226ad21c319cbc0fa912e6bc2ffac2696e7ce93b09fbed5721c384893f4d9bae9f748630f807
-
C:\Program Files\7-Zip\Lang\da.txt.tmpFilesize
60KB
MD55a504a268c4401fa416f03d6a7c7d1d1
SHA1a93e17ae1ec8780ad78da402673fb8347c0571c8
SHA256ae050c0f1f47d3b4c16a313d6d8eb035a504d71d63142eeda24b5fb26315df4d
SHA5129aafa915df774db3bc2da538b33045c6d368f8e6483f90678669911d9f1e95c8af4b8fa1c92368d9ae53c7b7ed8b155666b5f76f0b665ffa8021a2bf54a9b7ff
-
C:\Program Files\7-Zip\Lang\de.txt.tmpFilesize
60KB
MD5a5d5b885137642dc0f0c881646290d44
SHA13422883c005ebe696f27fbab60d48e1caefe2ddc
SHA25617eb3a018e97a1e74812626f847b723a54cfe08bbe5d68373ac7b5658b46d6d1
SHA5125b48d9d0cc8d7da5f721b52f03f27b1e27d0e80779f5ba86536e815f3156e4315696dfd6ec35a2bd98e123089a97745549c3dcbc99eecf5fc7c1367d4737d103
-
C:\Program Files\7-Zip\Lang\eo.txt.tmpFilesize
65KB
MD58e35f30d54f6026eca1c6174d6dea780
SHA1dd43ab6e77cac3620c98d00ef03deec90e40e863
SHA256948c15e7ebad51a99f857c0f292c47b875c8f40d9e6ba98d6923676249cfda91
SHA512dd9383f6164992f02e2695c8e3eee74f2fe23d2bc841c564fe6f6b152709355e91fbda111394cd0cadf19ab9150c5696cc7f06adc3f6c85b8066955e21362b37
-
C:\Program Files\7-Zip\Lang\fa.txt.tmpFilesize
73KB
MD56a0e5545f078c75499b4fbd749ce631a
SHA1d55524cef11bec443f5e034dfd3eb9c11063456d
SHA2563efff963c714a2e80af442b719948da187d4b10f857f15655e0f233187ca4e4f
SHA512eb31c0cdb152da3d6efb721468e1e0f94a7d916341ac7a4de3c5a2c20aab143b7edc74d1b1c9bd9e6c4610089f20bfdf50f9baa89f619eb710510dab4ba86dc3
-
C:\Program Files\7-Zip\Lang\fr.txt.tmpFilesize
72KB
MD5ee20ad68a92257b9ec18b70f4e07819e
SHA142690b875063a2830199b8ed43e18d62f91a5adc
SHA2567475ee6a5046db303574c46140fa52ef9e3d51377dadf5cf6a4e1cb8196a1540
SHA512d0ae3fa31d60a0603826fc9ecd647a6fa5b329bcfa1f3df666586751de696bc52fa50ce227f893bb8c888d632bd687e08fea35efabd026ae461ccce02efdacac
-
C:\Program Files\7-Zip\Lang\fur.txt.tmpFilesize
67KB
MD56d323d0e849e5216bba4fc9cb4be2481
SHA17efa16e592930ab343f86552403b4501e3a2a1d9
SHA256ad5887b02a2f9770f15d71662a6c67ae906a8b443271c175766f6560f3f12d52
SHA5125a6369c9529e2e9178f5adf8139094dee3b875e0286fdb57a8fad9dcc44002bbad2aedb4c06399c4599cc1f280f18f4d796eb3837e46c0c7308b914d4ae3a822
-
C:\Program Files\7-Zip\Lang\hi.txt.tmpFilesize
80KB
MD58c7c81af60b0f22aad7a2c1dca32f87d
SHA115418dc93f1ea1e7cfccc1b7767f7174620c01dd
SHA2561f70c6f80da5e6d73ac6f4b7998cbb513ab94215670e2580120cf96b7f95262e
SHA512004a5859861f39a74b465f49cf4b00dd2d2a3e0bd765680776714c27640a09b9302fd9044f70658c3a120cadffe7b362e081a52a30f5c275363ea4130ef92fea
-
C:\Program Files\7-Zip\Lang\hu.txt.tmpFilesize
72KB
MD515ee37670058aeee8e72639ce1ccb075
SHA18e3cac4c238995959ac92ec5ce1bcc56b849ef34
SHA256c8bf80cb51388a1b74d98fd408646402fb56ebbb4970b90d9bd5dce66da331d7
SHA512eb7f01bdba9d6fc49047b6d298c5b85cab906f307b3a47c875dfdc21b06dabdada79bbc933e548f705846efa0c379a01e2d62213d07bf25191511b24eb2b12a9
-
C:\Program Files\7-Zip\Lang\hy.txt.tmpFilesize
73KB
MD54b1ba89cf93fabaa0ad3b114004a2434
SHA12eae3effd3819a177a487d8f5971024c36e2d7de
SHA2569c6a565d028072b23b99b5de91a0c0403925157c4f4f5925120814418fd5d4d5
SHA5121045a3af014dd6fd90dc5d36cfe76216657dcc500cfd912ea047c4d3f0d6ddbab729875440f49be83f1fe26c17046b79bb2738b1e9909a1708d6369e8a92f893
-
C:\Program Files\7-Zip\Lang\hy.txt.tmpFilesize
76KB
MD5bebe89085a15ee17e97180c134f82810
SHA1390b2bc708d7cb4b3f0332cffc7db32b29358840
SHA256d273921b4c62bacd48262a921dacb1737511ff353204678a21c08acc361397be
SHA512979c0c66affc992fa57c2293a64224af5d0d79710b2be6f370456bb51d47ed1e7985572d082537d50586850a8dfbce74f73f19504e6cdf2550c5b544ea2bcfd5
-
C:\Program Files\7-Zip\Lang\id.txt.tmpFilesize
68KB
MD503d7e45a78555cf27151b5be69c3f4ff
SHA1874d150d8f70b47c3252a01ddb52817ef58169cf
SHA2560f3e81d20800ea75da8d77c0522fc613772d51afbaf7eb142ce98ddaf2bcb120
SHA5127a12e483a60a7ad0a77d539512ffc4593b27d3441e3a9df9fb97dbc073f941d4849a2f85c014923da46f03c99eb6ec39c7bf13fd74d92e64f77b683b1d2e4bc4
-
C:\Program Files\7-Zip\Lang\is.txt.tmpFilesize
71KB
MD5ec467b894580bb8e59bd022eb315e58f
SHA1cfe4d2c200ca104d56113be4dd2628bbaa46f662
SHA256776bc544ee4713322cfa8ab89e7bffc1fcb6e9241693f91c6d868bed3a542516
SHA5124d46c5c51314750be6541bc1e471f8187e2eacaa3bebbfdea54611b9b1fa88133a9fb82ba0e32f6d0d5ff5136f7ab29d146b4bbb4468d9e727eea93c5b13b00f
-
C:\Program Files\7-Zip\Lang\it.txt.tmpFilesize
72KB
MD550805ee10fa3814e0b1b484b72920554
SHA144e6052a4049d92877bedd7aa2de846fa17c09e6
SHA256aeafe1e751ffd73246a4ae2d5f646976aa397c4ad5f6197443ce157e74b673f2
SHA5120293bf7c355ea632e35984bd5c6ba5a3988160450ec9fecdd73ed39c93664f0fd59c444528130ddf8dddb9a87f2b5028f8abf3889f2f6fd96b5fe0f65f993d67
-
C:\Program Files\7-Zip\Lang\ja.txt.tmpFilesize
74KB
MD544bd56f420a0cc0fcd2fa1abe96a6809
SHA1d9f43cd9729cc243944de0f7ec5e434f41974be4
SHA25627f9a2eb6528585d422c730053b8e8ecf5f2ee574cace4dd9aa46574a4c95944
SHA512b7baaabb91532885aff4c8e7b80d24e8d6d36ee90b65a2b4e4de49c41d495f2e71bd73895cca143371add38fa468eff709c2cc13bfae70517acbef68b2e3f081
-
C:\Program Files\7-Zip\Lang\kab.txt.tmpFilesize
71KB
MD5ac29eb1a567db0a70be2f20469adfd20
SHA1ef7b952fa3179aaed3d2b1bb7ebbfb9bb2dcef54
SHA2566f705ef13569f516603e9064a12b9fb60171279cacab7e17dbadb30765aa3b9f
SHA512c298a7fdf92699b5ced7018219bb146a59c3bb59d53c13a8fbb40ac8da3ae494c2deac4d274d76cac386232c4cfe3e39725b6e201ab4e20e9b7335d5820a9e47
-
C:\Program Files\7-Zip\Lang\kk.txt.tmpFilesize
73KB
MD54cbdf13f4c908b36a0acbc1086039430
SHA12bb2e007a8593e39444ac31ed372ab6f08597d58
SHA25613fb6bfe6db01c771d7e6e6ca0247c3a1245fb9c386d8c438310e8c5edef7937
SHA5121069956bc6de01ab29229f685f98a15893f1b5991208595a3cb416c4e8aa67521236efad62ead4c5b8e865ded435cc66bc2a460930a89f637b07b46f6ffcc5ed
-
C:\Program Files\7-Zip\Lang\ko.txt.tmpFilesize
73KB
MD502a9b3b9fa228c409668b9d41dee59ce
SHA1d8cbf254ecd369f14ed544cc85d3fbc0b36b91b1
SHA2569bde65530b361faccbc2f6f5f197d35f2675cf1dce8400e871197c9bb975c3be
SHA512d41c8dd7f9012b887a2563cb99cc2aebb4036e5485615958227d910bdf2f414a1ee50b2fab2cebecab8a394c8d461376b761257fe72b10d772e4b941b88096e1
-
C:\Program Files\7-Zip\Lang\ku-ckb.txt.tmpFilesize
75KB
MD5e37a0a6c3033b20dd139e3beb9afd46c
SHA1037ee83bbe4a3aeb3c80cc69bbc719f0cc222e14
SHA2560da04f6aead80eeaddb9888e324e9c63f6d5d85575c13d91958d194af0d1c17b
SHA512cf1644a121674889b51a9ce111ec7b067ca53537007b1ddd171473eb9571b980e71ce3ed056f318ec0907cd614a3be59e6c69759121e1a4ad9be02e412211404
-
C:\Program Files\7-Zip\Lang\lij.txt.tmpFilesize
60KB
MD54a4bea893c96e4cc2ac26127335f4c79
SHA15b832ee4a9dc844bd5fed68115d01c5fa62d5894
SHA2566146094e741cb27e5b981fada5a9b6dfd6c066daa98bf391473c0b24f4d4a509
SHA512c3195ebe3ac828b5294c80fb31b46d53d61e8874b43f3c0bd2cf36c554057d3d3497506fa60818ba47517d60bd4bc49949b30ac374aecf5fac7fdc39dcaa3ece
-
C:\Program Files\7-Zip\Lang\lv.txt.tmpFilesize
68KB
MD54daa83233e156e1e23915defa5f7d670
SHA1e7c32b24ac96643cb534e0ba1c3f7c5d106662a2
SHA256c24313044986283d47cc87216834691495b09d8101ae9601eeb4be4fc20fe3d2
SHA51201d5f43e445515b0713c8fe5082834c0bb897c39923b2aa7bba77f5b3d390b2a5328de425d8d65f0ac54e1a7aec6e474178028deeed1e02b8dea887af00d8e00
-
C:\Program Files\7-Zip\Lang\mng.txt.tmpFilesize
60KB
MD5ec02857f8796315a34bad1f7d937ccac
SHA1fdabffe04dc9f2bdd7979a6c4dae26dafd93c6f6
SHA2560128917a8ac5a1d6ddc9bdf241350c320b37d78ae2b123464f900bb91b660298
SHA51249ece9d04b8a1a99dfc29b072aeb81b1c1342f65675edd17ed79cd48afe43705eb4438e4e07455d87b30f2c0fb54bfaa0313feb3036250d8199babe162c3660d
-
C:\Program Files\7-Zip\Lang\mng2.txt.tmpFilesize
84KB
MD5d904edbb3f8e62dc1ec3ba639dc98660
SHA1a6796a9fcb027431a0e5e0d114093d349030b98a
SHA2561f7030f9371a05eb75ecd60088dcf6eb0fde2cb939dbfbea52a4d6a8d9562a59
SHA512f1c0d9104c4414eb5a7ef0c6e8955c141d445b7a13de1aabde63073678d82aec42d2b33f4e37a952e3aff2fa6a6fddd4a97af081203191caaa13d68ef42a92c8
-
C:\Program Files\7-Zip\Lang\ms.txt.tmpFilesize
68KB
MD58f817acd2db385a1aadfcc80c5be150a
SHA1070af1c408b092b617acc5d6ecc038c868cf4f8f
SHA256457d8e64c72159c52dece497903dc0a360b5d02fe74a4e5176f65c8a653a8e94
SHA512c8c219dd2d9caa6948121c1ea36daab5a194f4dba401362938bb6c81a1083f9a27eeccaaff54ed86dfd3cd58e94b54a32081fec5c0eebe490d7decd389bf6f98
-
C:\Program Files\7-Zip\Lang\nb.txt.tmpFilesize
63KB
MD5bf53757f2633e4453baa29dd7d63d617
SHA1676bd6ac06f5959d42506e5a17059f3b14bdb802
SHA2567a0c4464aba4ca5bb2334da1467e5fdf4f4bd0872492d8e7cf78ae64d90ed7a4
SHA51224708e498176a42a055ace29e2fe09007697c1291517fef9a9662f6c8ec99d8337ae00edc72432ab9bec3cdfe64ede87a028e5cb0002353aa7c61078213ec5f4
-
C:\Program Files\7-Zip\Lang\ne.txt.tmpFilesize
76KB
MD5074f0fd52005f08d80293b324f13ef0f
SHA1de652d49f1d840cec7b342717b8d70439d3f469a
SHA256e139410b2b824d235072cb7248b8b6a98e77916681e816e56f82cf770bb88915
SHA5122a01d9f15aae48b63df977b180aff3294412c6d5f9697f2b45c3589747e6d599437ab9f93ee3afc87d83f94db540e52966e73ead00ae3dab6a6faa0ca7c3b8d9
-
C:\Program Files\7-Zip\Lang\pa-in.txt.tmpFilesize
77KB
MD5d9095f5e3732bf04b0d9273a0682c562
SHA13913f8ae485849ad8999e14bd47adc60b6cbb0ca
SHA2564493441452386a28e4133d9b00a6a122bd45614e65c5b204abaa506449cc5789
SHA512135bae61292bfe258c0830086c229e5c384256f9ea4da0d8922a931b3789b913364c48db978700ce304c1b0d3d4503a096b63ffee631ca61704f5e4514debd50
-
C:\Program Files\7-Zip\Lang\pl.txt.tmpFilesize
72KB
MD5f57dfcd5efcabb869a06cbdd6848c743
SHA179fd8da5abfc1e54c6a8b889838d4cd279021b53
SHA256458ef118c240eb3127192c677ab4bc822ae578407374d4e41611f207030730c8
SHA5126a5ba11ec7517fec9c69a3a452b95d4812c2bc16c32c290c42ed9017b222701a914cfe61c111b0e4dbbffa1f74ff3765b2b3dd43e05bb31f9e45c69ecfa8b083
-
C:\Program Files\7-Zip\Lang\ps.txt.tmpFilesize
71KB
MD58b3b1bb8ee1ed5d68d4bb03fe6df8961
SHA1c9be07be69afa472b82e556ec8e5adbf9084c055
SHA256627c7e00bfe760c5df269c2308f5aa2006c3578aea5e4593d9fdc6afe2f9c2c0
SHA5122e2b35fcdbc8f0e7ad19223f2665bfe21f5bdf49c47c6267d651ad202261aa70ede2cf4d43ea8e427c5e57dd9e8920a95993ceb2b48d3cf783b26d818bb447bf
-
C:\Program Files\7-Zip\Lang\ru.txt.tmpFilesize
78KB
MD53930ae2775f2172d3b0c7ead6b745c26
SHA185bf13a181cf05a0fec2cf2ef73685d09fc6ae94
SHA25665ca979b349c48cb073200a1a06fcf8a458240487ae2738d6d338675a51bb991
SHA512c655d626bf2a9ddbc0fbff0fb03bdf43d16243611673d84920b7e0306389daa1c1e028532f8baf59ccc79a6d69db50da047323c75ebec8013606fd5cbdd7df7c
-
C:\Program Files\7-Zip\Lang\si.txt.tmpFilesize
81KB
MD55308cd4fabc18c5468413e6753b2aa38
SHA1a60e202446748ff7b664b4f0d192f1723f1d75a6
SHA256d09f0cde91405992e90ff3ffe8985d09d2a303c4f91c141fa2e782da13f7cb51
SHA512b83a76dbda2640c0d568f317b923fa675eceb6bcea36ddc1a5f5af4f1fb706c78195595e1bca6bc27e63e25e52fedc08f468617d14aab1659216b030a110b8d0
-
C:\Program Files\7-Zip\Lang\sw.txt.tmpFilesize
71KB
MD58102817b99e0dba869a951bbf981374c
SHA170b143c95791fdd460dc35dad0c66a1c8fb40a8a
SHA25606515521cd7d70d601def7077750957161fca7188038aadc6609bb79aa151a52
SHA5122ba4c4db515a0b7cc2c7cfb5aecdd7075d91cec790f0bd56e129f6cb9c37c4d28f67ea8a743623453c69f52cbc680bbb25351b6ba1e257fa6fb75abfb6285e84
-
C:\Program Files\7-Zip\Lang\tg.txt.tmpFilesize
77KB
MD56835ae8d98f7b5530ef2153e512c285e
SHA172a680f2d91533f2221b13fc870f77bb157f3109
SHA256b5fd1803e2c805e05a730b5cba747a73ae44313477efdd4d7f4887984e699a9a
SHA51289832aa3822d42a56e2b20f1a1a985e2a80d40e18fc3c632056a2cbbfc5f607a0ccacc54d7787a389108daab09e5d7879bcd8ffc91a753b25bcdb93752a854ff
-
C:\Program Files\7-Zip\Lang\th.txt.tmpFilesize
60KB
MD5cdb1e5bde6735f0fc4be47775d0da2d8
SHA18dd2eb4cb0ecb0d38badc8fd8e8092bad525fbea
SHA2569263bbafc2f81f8f9e9da8947d43d004f07577549b5c7be4e2292914b34003bb
SHA512ec6f37599fa6e8194102deda97993a9755702f3ce910d2f805d2c7ff66d2f0c977bbef708efb3e1d4d70435af4febb09c36a384976b422bd00a2a2a121ba47ba
-
C:\Program Files\7-Zip\Lang\tr.txt.tmpFilesize
69KB
MD54a31ed758cad9f9b99284e032526987d
SHA1f1f77b5f7dfbfb9861173e4302d00deddc4461a2
SHA2565d4933621e65664f9d1e6c46236555a6866c9bff5baab35a5254b2e5ffded5c0
SHA512778fe695884096e2ed12ede84d86b514989e2a8cdac4a9130a6e4b34a935f8c9b1fb27f5f3f2f8178bfd2300dad48494e130be39f7efb005202db0307cea4c5a
-
C:\Program Files\7-Zip\Lang\tt.txt.tmpFilesize
76KB
MD575fce15365dc7a919269176d9e9086a2
SHA10c613d46b629709686182fdaac5df2a2a3dd4d13
SHA2563929da64c4226e34422f9133dbbac85872c0d72adf2d101032e4f81053e3c3a9
SHA5120e80fb5dd17e7fa993837407a1eba439e1e213a5b20d9c9ea98d62f3634fcd84c78fa5edb8b25b886c5f424f0e723c9544c12afc299cecc0745085b911085337
-
C:\Program Files\7-Zip\Lang\uz-cyrl.txt.tmpFilesize
77KB
MD599c94d0fcbb9fe018085f77c435cf831
SHA10c5a9434d86c605af9f654bdf6298ad8f01e1fd9
SHA2568b7ce30cbe82dd485e956cd7df1d81e634481d9640c84c958bfb2a7671dc3006
SHA5124857194797d0c6b14f74f9969c70fa43c268dae07af54085dca5545412123a7062d9dbc85773b51b9aa11dfbd5fc870486e741125ecea51fc254cf4066e32335
-
C:\Program Files\7-Zip\Lang\va.txt.tmpFilesize
66KB
MD5bd422f5bf84597a5319f66857b977ef2
SHA1f5e44c4743faa9e2c9e3718f2a5fa59cce98505b
SHA25601f6523a41ff5700706c0e2cff2adcd3b5f3a8ca2eb2e09f5f7d64e53e0fecc4
SHA512d6926ce546337f891d7b7f0c5a8d033bc996cefabb8df4448242b7bb8f20b0673a692a002d2591b570c9605df229660dfabe6761a13ddd8212a2978d1c49ec1f
-
C:\Program Files\7-Zip\Lang\vi.txt.tmpFilesize
68KB
MD585c0c5af4d8dc1b94bfe9470be2d8151
SHA16af0532646a31681312f2d20736d56146cc27843
SHA25688b4a7daaa87ac6ad3347583e122bb125617378079cf6efd3c0c0e4388e9168c
SHA5121ff298e12f1ef3b20a8fe62c73c19300a67c074729feb146ce51b63759e62a77da1de045aab53e432d82cc272aacad9bcb723119d8aa131d46f689115bfaefb7
-
C:\Program Files\7-Zip\Lang\yo.txt.tmpFilesize
73KB
MD569c94defc13324eeee3ef17ef7ebdc56
SHA139aae604fc941e6bc60e850d9d4384d7a4ab26e9
SHA256e4cc50fecaf25cfaf8d110115f37a39345515b9901900be7e725f0d2995c6146
SHA512e24ec2a21750db64c502947a94874fd0fe29350731774cbb410de4251f5218e462d64de8bd0e000e9b219bea8e9cf223169ed356d6d83f99dded29d0b69a4eea
-
C:\Program Files\7-Zip\Lang\zh-cn.txt.tmpFilesize
71KB
MD59f87f2bc8204dbaffe2f8b712ef8a5b3
SHA192f312a5ccf1eebdd9ec3ed1a3f24ec04726291f
SHA25627702e97c643e3220b06a9721ea6c2371ac065c520c59ca5ba2f384dcb408002
SHA512b77ca0e885fced83271398ae8eaa3c10cd8e5e2310f7433a4f2d9c87acb2be18fb0bb3b07d5f94c9def57c1c3fc0d47dbc94105dd8050b0f0f80098b4e4b5664
-
C:\Program Files\7-Zip\Uninstall.exeFilesize
77KB
MD57b06fda20225822c2de4f6a5c251aba4
SHA190dff2f9c3f709c626e2837b9a4660a2be851a39
SHA256ff3ef47fcfaf54979980dc95ba29f22821887039b9bd7aa289799d94dc1ee861
SHA512550c0f56efcea45c40032c00e01cf9b0b522fccf942b9fccdcda55ffc2fa85fcb5f3ae742522c13cf219d26277d772c90aa6722739c5f4579da4dfe1f566f447
-
C:\Program Files\Common Files\DESIGNER\MSADDNDR.OLB.exeFilesize
88KB
MD5532bb4f6bbd29ce9889f1618879c8919
SHA1175c9c8bc01329e763dda66ec63341a541a57753
SHA2561688c3b7ce2760534517e5242e5bdb404068d2259acf725e08d9b81699a4577c
SHA512f5733e67136851aa99374f25f53f7cb554526d1c289f9562d42700b10ed1ce1699febc3a8e664fa209ff7734d89995d96cf5dda669f270f862022b3b78d87d30
-
C:\Program Files\dotnet\shared\Microsoft.WindowsDesktop.App\8.0.2\zh-Hans\UIAutomationTypes.resources.dll.tmpFilesize
80KB
MD5aeae4743410e00509ca3de194286832d
SHA13e1371fa4d6d8151d7dfb695541206efcce5c318
SHA2565f9eab13054274222a00a945a585a43f8f34f6d77324601ee600e70e19ad2379
SHA5127515ced3e88ac89e7e2225ea9af6ab83544e56960b6f82ac93c19795778f89b9dc044e0fe976a750e593be0247666f0eb6d32f648ca41c4b2899091c3c4286b4
-
C:\Users\Admin\AppData\Local\Temp\_Test-WindowsUpdate.ps1.exeFilesize
62KB
MD5717d91471d1bf2ff5232f621c9d9c415
SHA14a960449895bb5a284fc281daf30e6410f0fc501
SHA256e7c80c0a6ff1f747fdd894608dd46dfcc62625e66df78cff3d53903dfae68d37
SHA51236cfe4a29484274f2a74d17b9fb33258cef9619abc465d4b79ec04bbb51b332ac85976d25b71ab805a1981bfda383d93afb6aeaa4c1fb13b575a47d5de8a3086
-
C:\Windows\SysWOW64\Zombie.exeFilesize
60KB
MD527dbdae73c6b564fddef447ea620861e
SHA1008ab276407d7a5aacb243116c11bb19701dd894
SHA256c0d33589c802e1eb569c2076cd8085e8defc59f2501601378bf583a948ac748c
SHA5121fc391e3a900c128b00262c0a43fcd80677426a6538d363f74cd91bc887d9127435de27e4e387211a1ba8d1d5941e57973516ab8b02012656d0bfecb01bc38f9