VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: | - |
Threat Names: |
Gen:Heur.Ransom.Imps.1
|
ragnar.exe
Windows Exe (x86-32)
Created at 2020-10-28T21:49:00
Remarks (2/2)
(0x02000008): One or more processes crashed during the analysis. Analysis results may be incomplete.
(0x0200000E): The overall sleep time of all monitored processes was truncated from "1 minute" to "20 seconds" to reveal dormant functionality.
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x40e0e1 |
Size Of Code | 0x24000 |
Size Of Initialized Data | 0xe000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-12-22 17:29:56+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x23c17 | 0x24000 | 0x1000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.64 |
.data | 0x425000 | 0x98a0 | 0xa000 | 0x25000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.93 |
.tls | 0x42f000 | 0x15 | 0x1000 | 0x2f000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.sxdata | 0x430000 | 0x70 | 0x1000 | 0x30000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_LNK_INFO, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.08 |
.reloc | 0x431000 | 0x1486 | 0x2000 | 0x31000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 4.93 |
Imports (5)
»
ADVAPI32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegDeleteKeyW | 0x0 | 0x425000 | 0x2e03c | 0x2e03c | 0x1d7 |
RegDeleteKeyA | 0x0 | 0x425004 | 0x2e040 | 0x2e040 | 0x1d4 |
RegEnumKeyExA | 0x0 | 0x425008 | 0x2e044 | 0x2e044 | 0x1de |
RegEnumKeyExW | 0x0 | 0x42500c | 0x2e048 | 0x2e048 | 0x1df |
SHLWAPI.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHRegGetPathW | 0x0 | 0x425174 | 0x2e1b0 | 0x2e1b0 | 0xe2 |
ole32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
OleUninitialize | 0x0 | 0x42517c | 0x2e1b8 | 0x2e1b8 | 0x10b |
CoInitialize | 0x0 | 0x425180 | 0x2e1bc | 0x2e1bc | 0x3d |
OLEACC.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateStdAccessibleObject | 0x0 | 0x42516c | 0x2e1a8 | 0x2e1a8 | 0x4 |
KERNEL32.dll (85)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WriteConsoleW | 0x0 | 0x425014 | 0x2e050 | 0x2e050 | 0x524 |
SetFilePointerEx | 0x0 | 0x425018 | 0x2e054 | 0x2e054 | 0x467 |
SetStdHandle | 0x0 | 0x42501c | 0x2e058 | 0x2e058 | 0x487 |
GetConsoleMode | 0x0 | 0x425020 | 0x2e05c | 0x2e05c | 0x1ac |
GetConsoleCP | 0x0 | 0x425024 | 0x2e060 | 0x2e060 | 0x19a |
FlushFileBuffers | 0x0 | 0x425028 | 0x2e064 | 0x2e064 | 0x157 |
EnumSystemLocalesW | 0x0 | 0x42502c | 0x2e068 | 0x2e068 | 0x10f |
IsDebuggerPresent | 0x0 | 0x425030 | 0x2e06c | 0x2e06c | 0x300 |
GetEnvironmentStringsW | 0x0 | 0x425034 | 0x2e070 | 0x2e070 | 0x1da |
VirtualAlloc | 0x0 | 0x425038 | 0x2e074 | 0x2e074 | 0x4e9 |
GetVersionExA | 0x0 | 0x42503c | 0x2e078 | 0x2e078 | 0x2a3 |
GetCurrentThread | 0x0 | 0x425040 | 0x2e07c | 0x2e07c | 0x1c4 |
GetCommandLineA | 0x0 | 0x425044 | 0x2e080 | 0x2e080 | 0x186 |
GetEnvironmentStrings | 0x0 | 0x425048 | 0x2e084 | 0x2e084 | 0x1d8 |
GetTickCount | 0x0 | 0x42504c | 0x2e088 | 0x2e088 | 0x293 |
GetLastError | 0x0 | 0x425050 | 0x2e08c | 0x2e08c | 0x202 |
GetProcAddress | 0x0 | 0x425054 | 0x2e090 | 0x2e090 | 0x245 |
LoadLibraryW | 0x0 | 0x425058 | 0x2e094 | 0x2e094 | 0x33f |
ExitProcess | 0x0 | 0x42505c | 0x2e098 | 0x2e098 | 0x119 |
GetVersionExW | 0x0 | 0x425060 | 0x2e09c | 0x2e09c | 0x2a4 |
GetCommandLineW | 0x0 | 0x425064 | 0x2e0a0 | 0x2e0a0 | 0x187 |
lstrlenW | 0x0 | 0x425068 | 0x2e0a4 | 0x2e0a4 | 0x54e |
FindClose | 0x0 | 0x42506c | 0x2e0a8 | 0x2e0a8 | 0x12e |
HeapFree | 0x0 | 0x425070 | 0x2e0ac | 0x2e0ac | 0x2cf |
CloseHandle | 0x0 | 0x425074 | 0x2e0b0 | 0x2e0b0 | 0x52 |
GetModuleHandleW | 0x0 | 0x425078 | 0x2e0b4 | 0x2e0b4 | 0x218 |
InterlockedExchange | 0x0 | 0x42507c | 0x2e0b8 | 0x2e0b8 | 0x2ec |
WideCharToMultiByte | 0x0 | 0x425080 | 0x2e0bc | 0x2e0bc | 0x511 |
RtlUnwind | 0x0 | 0x425084 | 0x2e0c0 | 0x2e0c0 | 0x418 |
VirtualQuery | 0x0 | 0x425088 | 0x2e0c4 | 0x2e0c4 | 0x4f1 |
SetLastError | 0x0 | 0x42508c | 0x2e0c8 | 0x2e0c8 | 0x473 |
GetCurrentThreadId | 0x0 | 0x425090 | 0x2e0cc | 0x2e0cc | 0x1c5 |
EncodePointer | 0x0 | 0x425094 | 0x2e0d0 | 0x2e0d0 | 0xea |
DecodePointer | 0x0 | 0x425098 | 0x2e0d4 | 0x2e0d4 | 0xca |
GetModuleHandleExW | 0x0 | 0x42509c | 0x2e0d8 | 0x2e0d8 | 0x217 |
AreFileApisANSI | 0x0 | 0x4250a0 | 0x2e0dc | 0x2e0dc | 0x15 |
MultiByteToWideChar | 0x0 | 0x4250a4 | 0x2e0e0 | 0x2e0e0 | 0x367 |
GetProcessHeap | 0x0 | 0x4250a8 | 0x2e0e4 | 0x2e0e4 | 0x24a |
GetStdHandle | 0x0 | 0x4250ac | 0x2e0e8 | 0x2e0e8 | 0x264 |
GetFileType | 0x0 | 0x4250b0 | 0x2e0ec | 0x2e0ec | 0x1f3 |
DeleteCriticalSection | 0x0 | 0x4250b4 | 0x2e0f0 | 0x2e0f0 | 0xd1 |
GetStartupInfoW | 0x0 | 0x4250b8 | 0x2e0f4 | 0x2e0f4 | 0x263 |
GetModuleFileNameA | 0x0 | 0x4250bc | 0x2e0f8 | 0x2e0f8 | 0x213 |
WriteFile | 0x0 | 0x4250c0 | 0x2e0fc | 0x2e0fc | 0x525 |
GetModuleFileNameW | 0x0 | 0x4250c4 | 0x2e100 | 0x2e100 | 0x214 |
QueryPerformanceCounter | 0x0 | 0x4250c8 | 0x2e104 | 0x2e104 | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x4250cc | 0x2e108 | 0x2e108 | 0x1c1 |
GetSystemTimeAsFileTime | 0x0 | 0x4250d0 | 0x2e10c | 0x2e10c | 0x279 |
FreeEnvironmentStringsW | 0x0 | 0x4250d4 | 0x2e110 | 0x2e110 | 0x161 |
UnhandledExceptionFilter | 0x0 | 0x4250d8 | 0x2e114 | 0x2e114 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x4250dc | 0x2e118 | 0x2e118 | 0x4a5 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4250e0 | 0x2e11c | 0x2e11c | 0x2e3 |
CreateEventW | 0x0 | 0x4250e4 | 0x2e120 | 0x2e120 | 0x85 |
Sleep | 0x0 | 0x4250e8 | 0x2e124 | 0x2e124 | 0x4b2 |
GetCurrentProcess | 0x0 | 0x4250ec | 0x2e128 | 0x2e128 | 0x1c0 |
TerminateProcess | 0x0 | 0x4250f0 | 0x2e12c | 0x2e12c | 0x4c0 |
TlsAlloc | 0x0 | 0x4250f4 | 0x2e130 | 0x2e130 | 0x4c5 |
TlsGetValue | 0x0 | 0x4250f8 | 0x2e134 | 0x2e134 | 0x4c7 |
TlsSetValue | 0x0 | 0x4250fc | 0x2e138 | 0x2e138 | 0x4c8 |
TlsFree | 0x0 | 0x425100 | 0x2e13c | 0x2e13c | 0x4c6 |
CreateSemaphoreW | 0x0 | 0x425104 | 0x2e140 | 0x2e140 | 0xae |
IsProcessorFeaturePresent | 0x0 | 0x425108 | 0x2e144 | 0x2e144 | 0x304 |
EnterCriticalSection | 0x0 | 0x42510c | 0x2e148 | 0x2e148 | 0xee |
LeaveCriticalSection | 0x0 | 0x425110 | 0x2e14c | 0x2e14c | 0x339 |
FatalAppExitA | 0x0 | 0x425114 | 0x2e150 | 0x2e150 | 0x120 |
IsValidCodePage | 0x0 | 0x425118 | 0x2e154 | 0x2e154 | 0x30a |
GetACP | 0x0 | 0x42511c | 0x2e158 | 0x2e158 | 0x168 |
GetOEMCP | 0x0 | 0x425120 | 0x2e15c | 0x2e15c | 0x237 |
GetCPInfo | 0x0 | 0x425124 | 0x2e160 | 0x2e160 | 0x172 |
SetConsoleCtrlHandler | 0x0 | 0x425128 | 0x2e164 | 0x2e164 | 0x42d |
FreeLibrary | 0x0 | 0x42512c | 0x2e168 | 0x2e168 | 0x162 |
LoadLibraryExW | 0x0 | 0x425130 | 0x2e16c | 0x2e16c | 0x33e |
OutputDebugStringW | 0x0 | 0x425134 | 0x2e170 | 0x2e170 | 0x38a |
HeapAlloc | 0x0 | 0x425138 | 0x2e174 | 0x2e174 | 0x2cb |
HeapReAlloc | 0x0 | 0x42513c | 0x2e178 | 0x2e178 | 0x2d2 |
GetStringTypeW | 0x0 | 0x425140 | 0x2e17c | 0x2e17c | 0x269 |
HeapSize | 0x0 | 0x425144 | 0x2e180 | 0x2e180 | 0x2d4 |
GetDateFormatW | 0x0 | 0x425148 | 0x2e184 | 0x2e184 | 0x1c8 |
GetTimeFormatW | 0x0 | 0x42514c | 0x2e188 | 0x2e188 | 0x297 |
CompareStringW | 0x0 | 0x425150 | 0x2e18c | 0x2e18c | 0x64 |
LCMapStringW | 0x0 | 0x425154 | 0x2e190 | 0x2e190 | 0x32d |
GetLocaleInfoW | 0x0 | 0x425158 | 0x2e194 | 0x2e194 | 0x206 |
IsValidLocale | 0x0 | 0x42515c | 0x2e198 | 0x2e198 | 0x30c |
GetUserDefaultLCID | 0x0 | 0x425160 | 0x2e19c | 0x2e19c | 0x29b |
CreateFileW | 0x0 | 0x425164 | 0x2e1a0 | 0x2e1a0 | 0x8f |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
ragnar.exe | 1 | 0x00400000 | 0x00432FFF | Relevant Image |
![]() |
32-bit | 0x00410330 |
![]() |
![]() |
...
|
buffer | 1 | 0x00460000 | 0x00461FFF | First Execution |
![]() |
32-bit | 0x00460000 |
![]() |
![]() |
...
|
ragnar.exe | 1 | 0x00400000 | 0x00432FFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
c:\users\fd1hvy\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-1051304884-625712362-2192934891-1000\ec679dec92129330b5b05a3aa424ac05_33d770d0-06bc-47c5-8714-222cdac43a71 | Modified File | Stream |
Whitelisted
|
...
|
»
\\?\C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\GetCurrentRollback.ini.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd | Modified File | Batch |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\preoobe.cmd.__r4gN4r__B8CF767A | Dropped File | Batch |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\SetupComplete.cmd.__r4gN4r__B8CF767A | Dropped File | Batch |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1025\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1028\eula.rtf.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1028\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1029\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1029\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1030\eula.rtf.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1030\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1031\eula.rtf.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1032\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1033\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1033\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1036\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1036\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1037\LocalizedData.xml.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1038\eula.rtf.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1038\LocalizedData.xml.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1040\eula.rtf.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1041\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1041\LocalizedData.xml.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1042\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1043\eula.rtf.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1043\LocalizedData.xml.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1044\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1044\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1049\eula.rtf.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1049\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1053\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1053\LocalizedData.xml.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1055\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2052\eula.rtf.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2052\LocalizedData.xml.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2070\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2070\LocalizedData.xml.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3076\LocalizedData.xml.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3076\eula.rtf.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3082\LocalizedData.xml.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Client\Parameterinfo.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Client\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Extended\Parameterinfo.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Print.ico.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate1.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate2.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate4.ico.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate6.ico.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate7.ico.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate8.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Save.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Setup.ico.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\SysReqMet.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\DHtmlHeader.html.__r4gN4r__B8CF767A | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\header.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\ParameterInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\SplashScreen.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Strings.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\watermark.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Core.mzz.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Extended.mzz.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\cs-CZ\bootmgr.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\cs-CZ\memtest.exe.mui | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\da-DK\bootmgr.exe.mui | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\da-DK\memtest.exe.mui | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\de-DE\bootmgr.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\el-GR\memtest.exe.mui | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\en-US\bootmgr.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\es-ES\bootmgr.exe.mui | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\es-MX\bootmgr.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\et-EE\bootmgr.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\fi-FI\bootmgr.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\fi-FI\memtest.exe.mui | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\Fonts\malgun_boot.ttf.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\Fonts\meiryo_boot.ttf.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\Fonts\msyhn_boot.ttf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\Fonts\segmono_boot.ttf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\Fonts\segoen_slboot.ttf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\Fonts\jpn_boot.ttf.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\Fonts\segoe_slboot.ttf.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\Fonts\wgl4_boot.ttf.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\Fonts\chs_boot.ttf.__r4gN4r__B8CF767A | Dropped File | Audio |
Unknown
|
...
|
»
\\?\C:\Boot\Fonts\kor_boot.ttf.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\hu-HU\memtest.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\it-IT\memtest.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\ja-JP\bootmgr.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\ja-JP\memtest.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\ko-KR\memtest.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\lt-LT\bootmgr.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\lv-LV\bootmgr.exe.mui | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\nb-NO\bootmgr.exe.mui | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\nb-NO\memtest.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\nl-NL\bootmgr.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\nl-NL\memtest.exe.mui | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\pl-PL\bootmgr.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\pt-BR\memtest.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\pt-PT\bootmgr.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\pt-PT\memtest.exe.mui | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\Resources\en-US\bootres.dll.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\ro-RO\bootmgr.exe.mui | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\ru-RU\bootmgr.exe.mui | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\ru-RU\memtest.exe.mui | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\sl-SI\bootmgr.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\sr-Latn-CS\memtest.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\sr-Latn-RS\bootmgr.exe.mui | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\sv-SE\bootmgr.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\sv-SE\memtest.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\tr-TR\bootmgr.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\uk-UA\bootmgr.exe.mui | Modified File | Binary |
Unknown
|
...
|
»
\\?\C:\Boot\zh-CN\memtest.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\zh-TW\bootmgr.exe.mui | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\updaterevokesipolicy.p7b | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\HardwareEvents.evtx.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Key Management Service.evtx.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx.__r4gN4r__B8CF767A | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1025\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1031\LocalizedData.xml.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1032\eula.rtf.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1035\eula.rtf.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1037\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1040\LocalizedData.xml.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1042\eula.rtf.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1045\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1045\LocalizedData.xml.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1046\eula.rtf.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1046\LocalizedData.xml.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1055\eula.rtf.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\3082\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Extended\UiInfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate3.ico | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate5.ico | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\stop.ico | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\warn.ico.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\DisplayIcon.ico | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\SetupUi.xsd | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\UiInfo.xml.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\bg-BG\bootmgr.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\de-DE\memtest.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\el-GR\bootmgr.exe.mui | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\en-GB\bootmgr.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\en-US\memtest.exe.mui | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\es-ES\memtest.exe.mui | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\Fonts\malgunn_boot.ttf.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\Fonts\meiryon_boot.ttf | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\Fonts\msjhn_boot.ttf.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\Fonts\msjh_boot.ttf.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\Fonts\msyh_boot.ttf | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\Fonts\cht_boot.ttf | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\fr-CA\bootmgr.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\fr-FR\bootmgr.exe.mui | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\fr-FR\memtest.exe.mui | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\hr-HR\bootmgr.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\hu-HU\bootmgr.exe.mui | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\it-IT\bootmgr.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\ko-KR\bootmgr.exe.mui | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\pl-PL\memtest.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\pt-BR\bootmgr.exe.mui | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\qps-ploc\bootmgr.exe.mui | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\qps-ploc\memtest.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\sk-SK\bootmgr.exe.mui.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\sr-Latn-CS\bootmgr.exe.mui | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\tr-TR\memtest.exe.mui | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\zh-CN\bootmgr.exe.mui | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\zh-HK\bootmgr.exe.mui | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\zh-HK\memtest.exe.mui | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\zh-TW\memtest.exe.mui | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Application.evtx.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Internet Explorer.evtx.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-International%4Operational.evtx.__r4gN4r__B8CF767A | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\ro-RO\!!!_READ_ME_B8CF767A_!!!.txt | Dropped File | Text |
Not Queried
|
...
|
»