VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Sodinokibi
Gen:Variant.Jaik.40931
Generic.EmotetU.033F8ED3
...
|
cOzkxIznegrscYUzNiwVGtjnGrMGDzxO_locker.exe
Windows Exe (x86-32)
Created at 2020-09-19T09:45:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\cOzkxIznegrscYUzNiwVGtjnGrMGDzxO_locker.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x407472 |
Size Of Code | 0x1b000 |
Size Of Initialized Data | 0x50000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-08-27 18:40:58+00:00 |
Version Information (8)
»
CompanyName | TODO: <Company name> |
FileDescription | TODO: <File description> |
FileVersion | 1.0.0.1 |
InternalName | CustomToolTipDemo.exe |
LegalCopyright | TODO: (c) <Company name>. All rights reserved. |
OriginalFilename | CustomToolTipDemo.exe |
ProductName | TODO: <Product name> |
ProductVersion | 1.0.0.1 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1a324 | 0x1b000 | 0x1000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.49 |
.rdata | 0x41c000 | 0x76a4 | 0x8000 | 0x1c000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.67 |
.data | 0x424000 | 0x5334 | 0x2000 | 0x24000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.71 |
.rsrc | 0x42a000 | 0x41738 | 0x42000 | 0x26000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.42 |
Imports (8)
»
KERNEL32.dll (105)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VirtualAlloc | 0x0 | 0x41c0a8 | 0x22204 | 0x22204 | 0x373 |
GetSystemInfo | 0x0 | 0x41c0ac | 0x22208 | 0x22208 | 0x1bb |
VirtualQuery | 0x0 | 0x41c0b0 | 0x2220c | 0x2220c | 0x37b |
GetStartupInfoA | 0x0 | 0x41c0b4 | 0x22210 | 0x22210 | 0x1af |
GetCommandLineA | 0x0 | 0x41c0b8 | 0x22214 | 0x22214 | 0x108 |
TerminateProcess | 0x0 | 0x41c0bc | 0x22218 | 0x22218 | 0x34f |
HeapReAlloc | 0x0 | 0x41c0c0 | 0x2221c | 0x2221c | 0x210 |
HeapSize | 0x0 | 0x41c0c4 | 0x22220 | 0x22220 | 0x212 |
QueryPerformanceCounter | 0x0 | 0x41c0c8 | 0x22224 | 0x22224 | 0x297 |
GetTickCount | 0x0 | 0x41c0cc | 0x22228 | 0x22228 | 0x1d5 |
GetCurrentProcessId | 0x0 | 0x41c0d0 | 0x2222c | 0x2222c | 0x13b |
GetSystemTimeAsFileTime | 0x0 | 0x41c0d4 | 0x22230 | 0x22230 | 0x1c0 |
SetUnhandledExceptionFilter | 0x0 | 0x41c0d8 | 0x22234 | 0x22234 | 0x33b |
LCMapStringA | 0x0 | 0x41c0dc | 0x22238 | 0x22238 | 0x23a |
LCMapStringW | 0x0 | 0x41c0e0 | 0x2223c | 0x2223c | 0x23b |
HeapDestroy | 0x0 | 0x41c0e4 | 0x22240 | 0x22240 | 0x20a |
HeapCreate | 0x0 | 0x41c0e8 | 0x22244 | 0x22244 | 0x208 |
VirtualFree | 0x0 | 0x41c0ec | 0x22248 | 0x22248 | 0x376 |
IsBadWritePtr | 0x0 | 0x41c0f0 | 0x2224c | 0x2224c | 0x22c |
VirtualProtect | 0x0 | 0x41c0f4 | 0x22250 | 0x22250 | 0x379 |
UnhandledExceptionFilter | 0x0 | 0x41c0f8 | 0x22254 | 0x22254 | 0x360 |
FreeEnvironmentStringsA | 0x0 | 0x41c0fc | 0x22258 | 0x22258 | 0xed |
GetEnvironmentStrings | 0x0 | 0x41c100 | 0x2225c | 0x2225c | 0x14d |
FreeEnvironmentStringsW | 0x0 | 0x41c104 | 0x22260 | 0x22260 | 0xee |
GetEnvironmentStringsW | 0x0 | 0x41c108 | 0x22264 | 0x22264 | 0x14f |
SetHandleCount | 0x0 | 0x41c10c | 0x22268 | 0x22268 | 0x317 |
GetFileType | 0x0 | 0x41c110 | 0x2226c | 0x2226c | 0x15e |
GetStringTypeA | 0x0 | 0x41c114 | 0x22270 | 0x22270 | 0x1b2 |
GetStringTypeW | 0x0 | 0x41c118 | 0x22274 | 0x22274 | 0x1b5 |
IsBadCodePtr | 0x0 | 0x41c11c | 0x22278 | 0x22278 | 0x226 |
SetStdHandle | 0x0 | 0x41c120 | 0x2227c | 0x2227c | 0x32a |
HeapFree | 0x0 | 0x41c124 | 0x22280 | 0x22280 | 0x20c |
IsBadReadPtr | 0x0 | 0x41c128 | 0x22284 | 0x22284 | 0x229 |
HeapAlloc | 0x0 | 0x41c12c | 0x22288 | 0x22288 | 0x206 |
RtlUnwind | 0x0 | 0x41c130 | 0x2228c | 0x2228c | 0x2ca |
SetErrorMode | 0x0 | 0x41c134 | 0x22290 | 0x22290 | 0x308 |
GetCurrentProcess | 0x0 | 0x41c138 | 0x22294 | 0x22294 | 0x13a |
FlushFileBuffers | 0x0 | 0x41c13c | 0x22298 | 0x22298 | 0xe5 |
SetFilePointer | 0x0 | 0x41c140 | 0x2229c | 0x2229c | 0x30e |
WriteFile | 0x0 | 0x41c144 | 0x222a0 | 0x222a0 | 0x394 |
ReadFile | 0x0 | 0x41c148 | 0x222a4 | 0x222a4 | 0x2a9 |
RaiseException | 0x0 | 0x41c14c | 0x222a8 | 0x222a8 | 0x29b |
GetOEMCP | 0x0 | 0x41c150 | 0x222ac | 0x222ac | 0x18b |
GetCPInfo | 0x0 | 0x41c154 | 0x222b0 | 0x222b0 | 0xfc |
InterlockedIncrement | 0x0 | 0x41c158 | 0x222b4 | 0x222b4 | 0x222 |
GlobalFlags | 0x0 | 0x41c15c | 0x222b8 | 0x222b8 | 0x1f4 |
TlsFree | 0x0 | 0x41c160 | 0x222bc | 0x222bc | 0x355 |
DeleteCriticalSection | 0x0 | 0x41c164 | 0x222c0 | 0x222c0 | 0x7a |
LocalReAlloc | 0x0 | 0x41c168 | 0x222c4 | 0x222c4 | 0x255 |
TlsSetValue | 0x0 | 0x41c16c | 0x222c8 | 0x222c8 | 0x357 |
TlsAlloc | 0x0 | 0x41c170 | 0x222cc | 0x222cc | 0x354 |
InitializeCriticalSection | 0x0 | 0x41c174 | 0x222d0 | 0x222d0 | 0x219 |
TlsGetValue | 0x0 | 0x41c178 | 0x222d4 | 0x222d4 | 0x356 |
EnterCriticalSection | 0x0 | 0x41c17c | 0x222d8 | 0x222d8 | 0x8f |
GlobalHandle | 0x0 | 0x41c180 | 0x222dc | 0x222dc | 0x1f8 |
GlobalReAlloc | 0x0 | 0x41c184 | 0x222e0 | 0x222e0 | 0x1fc |
LeaveCriticalSection | 0x0 | 0x41c188 | 0x222e4 | 0x222e4 | 0x247 |
LocalAlloc | 0x0 | 0x41c18c | 0x222e8 | 0x222e8 | 0x24e |
InterlockedDecrement | 0x0 | 0x41c190 | 0x222ec | 0x222ec | 0x21e |
FormatMessageA | 0x0 | 0x41c194 | 0x222f0 | 0x222f0 | 0xea |
LocalFree | 0x0 | 0x41c198 | 0x222f4 | 0x222f4 | 0x252 |
WritePrivateProfileStringA | 0x0 | 0x41c19c | 0x222f8 | 0x222f8 | 0x399 |
GlobalFree | 0x0 | 0x41c1a0 | 0x222fc | 0x222fc | 0x1f5 |
CloseHandle | 0x0 | 0x41c1a4 | 0x22300 | 0x22300 | 0x2e |
GetCurrentThread | 0x0 | 0x41c1a8 | 0x22304 | 0x22304 | 0x13d |
GlobalAlloc | 0x0 | 0x41c1ac | 0x22308 | 0x22308 | 0x1ee |
lstrcmpA | 0x0 | 0x41c1b0 | 0x2230c | 0x2230c | 0x3b0 |
GetModuleFileNameA | 0x0 | 0x41c1b4 | 0x22310 | 0x22310 | 0x175 |
ConvertDefaultLocale | 0x0 | 0x41c1b8 | 0x22314 | 0x22314 | 0x39 |
EnumResourceLanguagesA | 0x0 | 0x41c1bc | 0x22318 | 0x22318 | 0x9a |
lstrcpyA | 0x0 | 0x41c1c0 | 0x2231c | 0x2231c | 0x3b6 |
GlobalLock | 0x0 | 0x41c1c4 | 0x22320 | 0x22320 | 0x1f9 |
GlobalUnlock | 0x0 | 0x41c1c8 | 0x22324 | 0x22324 | 0x200 |
MulDiv | 0x0 | 0x41c1cc | 0x22328 | 0x22328 | 0x26a |
SetLastError | 0x0 | 0x41c1d0 | 0x2232c | 0x2232c | 0x31b |
FreeResource | 0x0 | 0x41c1d4 | 0x22330 | 0x22330 | 0xf1 |
GetCurrentThreadId | 0x0 | 0x41c1d8 | 0x22334 | 0x22334 | 0x13e |
GlobalGetAtomNameA | 0x0 | 0x41c1dc | 0x22338 | 0x22338 | 0x1f6 |
GlobalAddAtomA | 0x0 | 0x41c1e0 | 0x2233c | 0x2233c | 0x1ec |
GlobalFindAtomA | 0x0 | 0x41c1e4 | 0x22340 | 0x22340 | 0x1f1 |
GlobalDeleteAtom | 0x0 | 0x41c1e8 | 0x22344 | 0x22344 | 0x1f0 |
LoadLibraryA | 0x0 | 0x41c1ec | 0x22348 | 0x22348 | 0x248 |
FreeLibrary | 0x0 | 0x41c1f0 | 0x2234c | 0x2234c | 0xef |
lstrcatA | 0x0 | 0x41c1f4 | 0x22350 | 0x22350 | 0x3ad |
lstrcmpW | 0x0 | 0x41c1f8 | 0x22354 | 0x22354 | 0x3b1 |
lstrcpynA | 0x0 | 0x41c1fc | 0x22358 | 0x22358 | 0x3b9 |
GetModuleHandleA | 0x0 | 0x41c200 | 0x2235c | 0x2235c | 0x177 |
GetProcAddress | 0x0 | 0x41c204 | 0x22360 | 0x22360 | 0x198 |
lstrlenA | 0x0 | 0x41c208 | 0x22364 | 0x22364 | 0x3bc |
lstrcmpiA | 0x0 | 0x41c20c | 0x22368 | 0x22368 | 0x3b3 |
GetVersion | 0x0 | 0x41c210 | 0x2236c | 0x2236c | 0x1de |
GetLastError | 0x0 | 0x41c214 | 0x22370 | 0x22370 | 0x169 |
MultiByteToWideChar | 0x0 | 0x41c218 | 0x22374 | 0x22374 | 0x26b |
WideCharToMultiByte | 0x0 | 0x41c21c | 0x22378 | 0x22378 | 0x387 |
FindResourceA | 0x0 | 0x41c220 | 0x2237c | 0x2237c | 0xda |
LoadResource | 0x0 | 0x41c224 | 0x22380 | 0x22380 | 0x24d |
LockResource | 0x0 | 0x41c228 | 0x22384 | 0x22384 | 0x25b |
SizeofResource | 0x0 | 0x41c22c | 0x22388 | 0x22388 | 0x346 |
GetVersionExA | 0x0 | 0x41c230 | 0x2238c | 0x2238c | 0x1df |
GetThreadLocale | 0x0 | 0x41c234 | 0x22390 | 0x22390 | 0x1d0 |
GetLocaleInfoA | 0x0 | 0x41c238 | 0x22394 | 0x22394 | 0x16c |
GetACP | 0x0 | 0x41c23c | 0x22398 | 0x22398 | 0xf5 |
InterlockedExchange | 0x0 | 0x41c240 | 0x2239c | 0x2239c | 0x21f |
GetStdHandle | 0x0 | 0x41c244 | 0x223a0 | 0x223a0 | 0x1b1 |
ExitProcess | 0x0 | 0x41c248 | 0x223a4 | 0x223a4 | 0xaf |
USER32.dll (105)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadCursorA | 0x0 | 0x41c26c | 0x223c8 | 0x223c8 | 0x1b9 |
GetSysColorBrush | 0x0 | 0x41c270 | 0x223cc | 0x223cc | 0x15b |
DestroyMenu | 0x0 | 0x41c274 | 0x223d0 | 0x223d0 | 0x97 |
wsprintfA | 0x0 | 0x41c278 | 0x223d4 | 0x223d4 | 0x2d6 |
GetDesktopWindow | 0x0 | 0x41c27c | 0x223d8 | 0x223d8 | 0x10e |
CreateDialogIndirectParamA | 0x0 | 0x41c280 | 0x223dc | 0x223dc | 0x52 |
GetNextDlgTabItem | 0x0 | 0x41c284 | 0x223e0 | 0x223e0 | 0x143 |
EndDialog | 0x0 | 0x41c288 | 0x223e4 | 0x223e4 | 0xc6 |
GetMessageA | 0x0 | 0x41c28c | 0x223e8 | 0x223e8 | 0x13a |
TranslateMessage | 0x0 | 0x41c290 | 0x223ec | 0x223ec | 0x2aa |
GetActiveWindow | 0x0 | 0x41c294 | 0x223f0 | 0x223f0 | 0xeb |
SetCursor | 0x0 | 0x41c298 | 0x223f4 | 0x223f4 | 0x24d |
PostQuitMessage | 0x0 | 0x41c29c | 0x223f8 | 0x223f8 | 0x203 |
SetMenuItemBitmaps | 0x0 | 0x41c2a0 | 0x223fc | 0x223fc | 0x261 |
ModifyMenuA | 0x0 | 0x41c2a4 | 0x22400 | 0x22400 | 0x1e6 |
GetMenuState | 0x0 | 0x41c2a8 | 0x22404 | 0x22404 | 0x137 |
EnableMenuItem | 0x0 | 0x41c2ac | 0x22408 | 0x22408 | 0xc2 |
CheckMenuItem | 0x0 | 0x41c2b0 | 0x2240c | 0x2240c | 0x39 |
GetMenuCheckMarkDimensions | 0x0 | 0x41c2b4 | 0x22410 | 0x22410 | 0x12e |
IsWindowEnabled | 0x0 | 0x41c2b8 | 0x22414 | 0x22414 | 0x1ae |
SetWindowTextA | 0x0 | 0x41c2bc | 0x22418 | 0x22418 | 0x286 |
IsDialogMessageA | 0x0 | 0x41c2c0 | 0x2241c | 0x2241c | 0x1a1 |
BeginPaint | 0x0 | 0x41c2c4 | 0x22420 | 0x22420 | 0xd |
ReleaseDC | 0x0 | 0x41c2c8 | 0x22424 | 0x22424 | 0x22a |
GetDC | 0x0 | 0x41c2cc | 0x22428 | 0x22428 | 0x10c |
GrayStringA | 0x0 | 0x41c2d0 | 0x2242c | 0x2242c | 0x17d |
DrawTextExA | 0x0 | 0x41c2d4 | 0x22430 | 0x22430 | 0xbd |
TabbedTextOutA | 0x0 | 0x41c2d8 | 0x22434 | 0x22434 | 0x29b |
RegisterWindowMessageA | 0x0 | 0x41c2dc | 0x22438 | 0x22438 | 0x227 |
WinHelpA | 0x0 | 0x41c2e0 | 0x2243c | 0x2243c | 0x2d0 |
GetCapture | 0x0 | 0x41c2e4 | 0x22440 | 0x22440 | 0xf3 |
CreateWindowExA | 0x0 | 0x41c2e8 | 0x22444 | 0x22444 | 0x60 |
SetWindowsHookExA | 0x0 | 0x41c2ec | 0x22448 | 0x22448 | 0x28a |
GetClassLongA | 0x0 | 0x41c2f0 | 0x2244c | 0x2244c | 0xfa |
GetClassInfoExA | 0x0 | 0x41c2f4 | 0x22450 | 0x22450 | 0xf7 |
GetClassNameA | 0x0 | 0x41c2f8 | 0x22454 | 0x22454 | 0xfc |
SetPropA | 0x0 | 0x41c2fc | 0x22458 | 0x22458 | 0x26a |
GetPropA | 0x0 | 0x41c300 | 0x2245c | 0x2245c | 0x14a |
RemovePropA | 0x0 | 0x41c304 | 0x22460 | 0x22460 | 0x22c |
SendDlgItemMessageA | 0x0 | 0x41c308 | 0x22464 | 0x22464 | 0x236 |
GetFocus | 0x0 | 0x41c30c | 0x22468 | 0x22468 | 0x116 |
IsWindow | 0x0 | 0x41c310 | 0x2246c | 0x2246c | 0x1ad |
SetFocus | 0x0 | 0x41c314 | 0x22470 | 0x22470 | 0x256 |
GetWindowTextA | 0x0 | 0x41c318 | 0x22474 | 0x22474 | 0x177 |
GetForegroundWindow | 0x0 | 0x41c31c | 0x22478 | 0x22478 | 0x117 |
GetLastActivePopup | 0x0 | 0x41c320 | 0x2247c | 0x2247c | 0x128 |
DispatchMessageA | 0x0 | 0x41c324 | 0x22480 | 0x22480 | 0xa1 |
GetDlgItem | 0x0 | 0x41c328 | 0x22484 | 0x22484 | 0x111 |
GetTopWindow | 0x0 | 0x41c32c | 0x22488 | 0x22488 | 0x163 |
DestroyWindow | 0x0 | 0x41c330 | 0x2248c | 0x2248c | 0x99 |
UnhookWindowsHookEx | 0x0 | 0x41c334 | 0x22490 | 0x22490 | 0x2ae |
GetMessageTime | 0x0 | 0x41c338 | 0x22494 | 0x22494 | 0x13d |
GetMessagePos | 0x0 | 0x41c33c | 0x22498 | 0x22498 | 0x13c |
PeekMessageA | 0x0 | 0x41c340 | 0x2249c | 0x2249c | 0x1ff |
MapWindowPoints | 0x0 | 0x41c344 | 0x224a0 | 0x224a0 | 0x1d9 |
MessageBoxA | 0x0 | 0x41c348 | 0x224a4 | 0x224a4 | 0x1de |
EndPaint | 0x0 | 0x41c34c | 0x224a8 | 0x224a8 | 0xc8 |
SetWindowPos | 0x0 | 0x41c350 | 0x224ac | 0x224ac | 0x283 |
PtInRect | 0x0 | 0x41c354 | 0x224b0 | 0x224b0 | 0x20b |
EqualRect | 0x0 | 0x41c358 | 0x224b4 | 0x224b4 | 0xdf |
GetWindowRect | 0x0 | 0x41c35c | 0x224b8 | 0x224b8 | 0x174 |
ValidateRect | 0x0 | 0x41c360 | 0x224bc | 0x224bc | 0x2c3 |
SetTimer | 0x0 | 0x41c364 | 0x224c0 | 0x224c0 | 0x27a |
KillTimer | 0x0 | 0x41c368 | 0x224c4 | 0x224c4 | 0x1b4 |
ClientToScreen | 0x0 | 0x41c36c | 0x224c8 | 0x224c8 | 0x40 |
SetActiveWindow | 0x0 | 0x41c370 | 0x224cc | 0x224cc | 0x243 |
GetCursorPos | 0x0 | 0x41c374 | 0x224d0 | 0x224d0 | 0x10b |
GetSystemMetrics | 0x0 | 0x41c378 | 0x224d4 | 0x224d4 | 0x15d |
EnableWindow | 0x0 | 0x41c37c | 0x224d8 | 0x224d8 | 0xc4 |
ShowWindow | 0x0 | 0x41c380 | 0x224dc | 0x224dc | 0x292 |
GetKeyState | 0x0 | 0x41c384 | 0x224e0 | 0x224e0 | 0x121 |
SetForegroundWindow | 0x0 | 0x41c388 | 0x224e4 | 0x224e4 | 0x257 |
IsWindowVisible | 0x0 | 0x41c38c | 0x224e8 | 0x224e8 | 0x1b1 |
UpdateWindow | 0x0 | 0x41c390 | 0x224ec | 0x224ec | 0x2bb |
GetMenu | 0x0 | 0x41c394 | 0x224f0 | 0x224f0 | 0x12c |
PostMessageA | 0x0 | 0x41c398 | 0x224f4 | 0x224f4 | 0x201 |
GetSubMenu | 0x0 | 0x41c39c | 0x224f8 | 0x224f8 | 0x159 |
GetMenuItemID | 0x0 | 0x41c3a0 | 0x224fc | 0x224fc | 0x133 |
GetMenuItemCount | 0x0 | 0x41c3a4 | 0x22500 | 0x22500 | 0x132 |
GetSysColor | 0x0 | 0x41c3a8 | 0x22504 | 0x22504 | 0x15a |
AdjustWindowRectEx | 0x0 | 0x41c3ac | 0x22508 | 0x22508 | 0x2 |
GetParent | 0x0 | 0x41c3b0 | 0x2250c | 0x2250c | 0x145 |
GetClassInfoA | 0x0 | 0x41c3b4 | 0x22510 | 0x22510 | 0xf6 |
RegisterClassA | 0x0 | 0x41c3b8 | 0x22514 | 0x22514 | 0x216 |
UnregisterClassA | 0x0 | 0x41c3bc | 0x22518 | 0x22518 | 0x2b3 |
CallNextHookEx | 0x0 | 0x41c3c0 | 0x2251c | 0x2251c | 0x1a |
DrawIcon | 0x0 | 0x41c3c4 | 0x22520 | 0x22520 | 0xb6 |
AppendMenuA | 0x0 | 0x41c3c8 | 0x22524 | 0x22524 | 0x8 |
SendMessageA | 0x0 | 0x41c3cc | 0x22528 | 0x22528 | 0x23b |
GetSystemMenu | 0x0 | 0x41c3d0 | 0x2252c | 0x2252c | 0x15c |
IsIconic | 0x0 | 0x41c3d4 | 0x22530 | 0x22530 | 0x1a6 |
GetClientRect | 0x0 | 0x41c3d8 | 0x22534 | 0x22534 | 0xff |
LoadIconA | 0x0 | 0x41c3dc | 0x22538 | 0x22538 | 0x1bd |
LoadBitmapA | 0x0 | 0x41c3e0 | 0x2253c | 0x2253c | 0x1b7 |
FillRect | 0x0 | 0x41c3e4 | 0x22540 | 0x22540 | 0xe2 |
DrawTextA | 0x0 | 0x41c3e8 | 0x22544 | 0x22544 | 0xbc |
GetWindow | 0x0 | 0x41c3ec | 0x22548 | 0x22548 | 0x16a |
CopyRect | 0x0 | 0x41c3f0 | 0x2254c | 0x2254c | 0x4a |
GetWindowPlacement | 0x0 | 0x41c3f4 | 0x22550 | 0x22550 | 0x173 |
SystemParametersInfoA | 0x0 | 0x41c3f8 | 0x22554 | 0x22554 | 0x299 |
GetDlgCtrlID | 0x0 | 0x41c3fc | 0x22558 | 0x22558 | 0x110 |
DefWindowProcA | 0x0 | 0x41c400 | 0x2255c | 0x2255c | 0x8e |
CallWindowProcA | 0x0 | 0x41c404 | 0x22560 | 0x22560 | 0x1b |
GetWindowLongA | 0x0 | 0x41c408 | 0x22564 | 0x22564 | 0x16e |
SetWindowLongA | 0x0 | 0x41c40c | 0x22568 | 0x22568 | 0x280 |
GDI32.dll (29)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetDeviceCaps | 0x0 | 0x41c030 | 0x2218c | 0x2218c | 0x16b |
CreateSolidBrush | 0x0 | 0x41c034 | 0x22190 | 0x22190 | 0x50 |
GetStockObject | 0x0 | 0x41c038 | 0x22194 | 0x22194 | 0x1a5 |
CreateBitmap | 0x0 | 0x41c03c | 0x22198 | 0x22198 | 0x27 |
DeleteDC | 0x0 | 0x41c040 | 0x2219c | 0x2219c | 0x8c |
ExtTextOutA | 0x0 | 0x41c044 | 0x221a0 | 0x221a0 | 0xdd |
ScaleWindowExtEx | 0x0 | 0x41c048 | 0x221a4 | 0x221a4 | 0x209 |
SetWindowExtEx | 0x0 | 0x41c04c | 0x221a8 | 0x221a8 | 0x242 |
ScaleViewportExtEx | 0x0 | 0x41c050 | 0x221ac | 0x221ac | 0x208 |
SetViewportExtEx | 0x0 | 0x41c054 | 0x221b0 | 0x221b0 | 0x23e |
OffsetViewportOrgEx | 0x0 | 0x41c058 | 0x221b4 | 0x221b4 | 0x1d5 |
SetViewportOrgEx | 0x0 | 0x41c05c | 0x221b8 | 0x221b8 | 0x23f |
SelectObject | 0x0 | 0x41c060 | 0x221bc | 0x221bc | 0x20e |
CreateFontA | 0x0 | 0x41c064 | 0x221c0 | 0x221c0 | 0x39 |
TextOutA | 0x0 | 0x41c068 | 0x221c4 | 0x221c4 | 0x24e |
RectVisible | 0x0 | 0x41c06c | 0x221c8 | 0x221c8 | 0x1f5 |
PtVisible | 0x0 | 0x41c070 | 0x221cc | 0x221cc | 0x1f1 |
DeleteObject | 0x0 | 0x41c074 | 0x221d0 | 0x221d0 | 0x8f |
SetMapMode | 0x0 | 0x41c078 | 0x221d4 | 0x221d4 | 0x22b |
RestoreDC | 0x0 | 0x41c07c | 0x221d8 | 0x221d8 | 0x200 |
SaveDC | 0x0 | 0x41c080 | 0x221dc | 0x221dc | 0x207 |
SetBkColor | 0x0 | 0x41c084 | 0x221e0 | 0x221e0 | 0x215 |
SetTextColor | 0x0 | 0x41c088 | 0x221e4 | 0x221e4 | 0x23c |
GetClipBox | 0x0 | 0x41c08c | 0x221e8 | 0x221e8 | 0x160 |
BitBlt | 0x0 | 0x41c090 | 0x221ec | 0x221ec | 0x12 |
CreateCompatibleDC | 0x0 | 0x41c094 | 0x221f0 | 0x221f0 | 0x2d |
GetObjectA | 0x0 | 0x41c098 | 0x221f4 | 0x221f4 | 0x195 |
CreateCompatibleBitmap | 0x0 | 0x41c09c | 0x221f8 | 0x221f8 | 0x2c |
Escape | 0x0 | 0x41c0a0 | 0x221fc | 0x221fc | 0xd4 |
WINSPOOL.DRV (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
OpenPrinterA | 0x0 | 0x41c414 | 0x22570 | 0x22570 | 0x7d |
DocumentPropertiesA | 0x0 | 0x41c418 | 0x22574 | 0x22574 | 0x46 |
ClosePrinter | 0x0 | 0x41c41c | 0x22578 | 0x22578 | 0x1b |
ADVAPI32.dll (9)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryValueExA | 0x0 | 0x41c000 | 0x2215c | 0x2215c | 0x1ec |
RegOpenKeyExA | 0x0 | 0x41c004 | 0x22160 | 0x22160 | 0x1e2 |
RegDeleteKeyA | 0x0 | 0x41c008 | 0x22164 | 0x22164 | 0x1d0 |
RegEnumKeyA | 0x0 | 0x41c00c | 0x22168 | 0x22168 | 0x1d5 |
RegOpenKeyA | 0x0 | 0x41c010 | 0x2216c | 0x2216c | 0x1e1 |
RegQueryValueA | 0x0 | 0x41c014 | 0x22170 | 0x22170 | 0x1eb |
RegCreateKeyExA | 0x0 | 0x41c018 | 0x22174 | 0x22174 | 0x1cd |
RegSetValueExA | 0x0 | 0x41c01c | 0x22178 | 0x22178 | 0x1f9 |
RegCloseKey | 0x0 | 0x41c020 | 0x2217c | 0x2217c | 0x1c9 |
COMCTL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x11 | 0x41c028 | 0x22184 | 0x22184 | - |
SHLWAPI.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathFindFileNameA | 0x0 | 0x41c260 | 0x223bc | 0x223bc | 0x2b |
PathFindExtensionA | 0x0 | 0x41c264 | 0x223c0 | 0x223c0 | 0x29 |
OLEAUT32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VariantClear | 0x9 | 0x41c250 | 0x223ac | 0x223ac | - |
VariantChangeType | 0xc | 0x41c254 | 0x223b0 | 0x223b0 | - |
VariantInit | 0x8 | 0x41c258 | 0x223b4 | 0x223b4 | - |
Memory Dumps (5)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
cozkxiznegrscyuzniwvgtjngrmgdzxo_locker.exe | 1 | 0x00400000 | 0x0046BFFF | Relevant Image |
![]() |
32-bit | 0x0040A497 |
![]() |
![]() |
...
|
buffer | 1 | 0x01FA0000 | 0x01FCAFFF | First Execution |
![]() |
32-bit | 0x01FA0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x01FD0000 | 0x01FFCFFF | First Execution |
![]() |
32-bit | 0x01FD2A20 |
![]() |
![]() |
...
|
buffer | 1 | 0x02030000 | 0x0205AFFF | Marked Executable |
![]() |
32-bit | - |
![]() |
![]() |
...
|
cozkxiznegrscyuzniwvgtjngrmgdzxo_locker.exe | 1 | 0x00400000 | 0x0046BFFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Jaik.40931 |
Malicious
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
SodinokibiEncryptedFile | File encrypted by Sodinokibi Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\DHtmlHeader.html | Modified File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.xml.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Strings.xml.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Key Management Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-International%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Known Folders API Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx | Modified File | Binary |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Operational.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Store%4Operational.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\desktop.ini.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\desktop.ini.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\LocalizedData.xml.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\LocalizedData.xml.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\eula.rtf.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.xml.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\LocalizedData.xml.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\LocalizedData.xml.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\LocalizedData.xml.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\eula.rtf.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\LocalizedData.xml.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\eula.rtf.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\LocalizedData.xml.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\eula.rtf.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\Parameterinfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\UiInfo.xml.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate1.ico.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate2.ico.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate3.ico.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate6.ico.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate5.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate8.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Save.ico.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqMet.ico.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\stop.ico.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\warn.ico.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\Accessible.tlb | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\application.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\crashreporter.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\dependentlibs.list.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\install.log.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\nssdbm3.chk | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\platform.ini.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\removed-files | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\softokn3.chk.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\AppXManifest.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\rempl\Unlock.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Extensibility Component.swidtag | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Licensing Component.swidtag.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft_Windows-10-Pro.swidtag.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT.LOG1.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core.mzz.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TM.blf.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\omni.ja.RHMLM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\R3ADM3.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DisplayIcon.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Internet Explorer.evtx.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Windows PowerShell.evtx.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Recovery\ReAgentOld.xml.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\preoobe.cmd | Modified File | Batch |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\SetupComplete.cmd.RHMLM | Dropped File | Batch |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1030\LocalizedData.xml.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1033\LocalizedData.xml.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1040\LocalizedData.xml.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1041\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1043\LocalizedData.xml.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1044\LocalizedData.xml.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1046\eula.rtf.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1053\eula.rtf.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1049\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1055\LocalizedData.xml.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3076\LocalizedData.xml.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Client\UiInfo.xml.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Print.ico.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Extended\Parameterinfo.xml.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate4.ico.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate7.ico.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Setup.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\FileSystemMetadata.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\firefox.VisualElementsManifest.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\freebl3.chk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\precomplete.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\update-settings.ini.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\updater.ini.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\rempl\rempl.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\Task.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Mozilla Maintenance Service\updater.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Localization Component.swidtag.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT.RHMLM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT.LOG2 | Modified File | Stream |
Not Queried
|
...
|
»