VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Gen:Variant.Ransom.Netwalker.4
Gen:Variant.Ransom.Netwalker.1
Mal/Generic-S
|
2001.exe
Windows Exe (x86-32)
Created at 2020-03-12T07:39:00
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "2 minutes" to "20 seconds" to reveal dormant functionality.
Remarks
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x40bd90 |
Size Of Code | 0xe000 |
Size Of Initialized Data | 0x2400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-03-01 12:46:56+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xdfc5 | 0xe000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.4 |
.rdata | 0x40f000 | 0x42a | 0x600 | 0xe400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.59 |
.data | 0x410000 | 0x23c | 0x200 | 0xea00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.59 |
.rsrc | 0x411000 | 0x2000 | 0x1600 | 0xec00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.83 |
.reloc | 0x413000 | 0x504 | 0x600 | 0x10200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.96 |
Imports (1)
»
KERNEL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Sleep | 0x0 | 0x40f000 | 0xf40c | 0xe80c | 0x575 |
Memory Dumps (13)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
2001.exe | 1 | 0x00B10000 | 0x00B23FFF | Relevant Image |
![]() |
32-bit | 0x00B122E0 |
![]() |
![]() |
...
|
buffer | 1 | 0x29FDC030 | 0x29FDFC2F | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x29FDFC38 | 0x29FE3837 | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x29FE3840 | 0x29FE743F | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x29FEB050 | 0x29FEEC4F | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x29FFA070 | 0x29FFDC6F | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x2E3FB038 | 0x2E3FEC37 | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x2E415470 | 0x2E41906F | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x2E419078 | 0x2E41CC77 | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x2E424490 | 0x2E42808F | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x2E42BCA0 | 0x2E42F89F | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x2E4334B0 | 0x2E4370AF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
2001.exe | 1 | 0x00B10000 | 0x00B23FFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Ransom.Netwalker.4 |
Malicious
|
C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Extensibility Component.swidtag | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Licensing Component.swidtag | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Localization Component.swidtag | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\Configuration.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\upgrader_win10.log | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\Welcome.html | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00B4-0409-1000-0000000FF1CE.xml | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt | Dropped File | Binary |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\rempl\Logs\Remediation.002.etl | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\User Account Pictures\Default User.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft_Windows-10-Pro.swidtag | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.015.etl | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.016.etl | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.011.etl | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.012.etl | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.007.etl | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\ClickToRun\19B11135-37BD-4FA1-A78E-C20CA2BDA1C0\x-none.16\stream.x64.x-none.man.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\Search\Data\Applications\Windows\edb0000A.jtx | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\Windows Security Health\Logs\SHS-07172018-135525-3-1-15063.0.amd64fre.rs2_release.170317-1834.bin | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\upgrader_default.log | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-International%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\LICENSE | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\README.txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\release | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\rempl\Logs\Remediation.001.etl | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\rempl\Logs\Remediation.003.etl | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0016-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0018-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml | Modified File | Binary |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001B-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-040C-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0C0A-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0027-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0054-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-006E-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0090-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E1-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00E2-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0115-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012B-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-3101-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.common.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Key Management Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\Vault\AC658CB4-9126-49BD-B877-31EEDAB3F204\154E23D0-C644-4E6F-8CE6-5069272F999F.vsch | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\ClickToRun\0D0D4EEB-DC03-4B3F-88DF-959FE1EDE5F4\en-us.16\MasterDescriptor.en-us.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\ExtensibleApp.xap | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\accessibility.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\currency.data | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\flavormap.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fontconfig.bfc | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fontconfig.properties.src | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\javafx.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jce.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jfr.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jsse.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\logging.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\management-agent.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\net.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\psfont.properties.ja | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\psfontj2d.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\resources.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\rt.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\sound.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.79\chrome.dll.sig | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.79\chrome.exe.sig | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.79\chrome_100_percent.pak | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.79\chrome_200_percent.pak | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.79\chrome_child.dll.sig | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.79\icudtl.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.79\nacl_irt_x86_64.nexe | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.79\natives_blob.bin | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.79\resources.pak | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.79\snapshot_blob.bin | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Google\Chrome\Application\master_preferences | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Document Themes 16\Facet.thmx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Document Themes 16\Integral.thmx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Document Themes 16\Ion Boardroom.thmx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Document Themes 16\Organic.thmx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Document Themes 16\Retrospect.thmx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Document Themes 16\Slice.thmx | Modified File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\1053\eula.rtf.d2723e | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\1055\eula.rtf.d2723e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\microsoft office\appxmanifest.xml.d2723e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\microsoft office\filesystemmetadata.xml.d2723e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\rempl\rempl.xml.d2723e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\unp\task.xml.d2723e | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\1031\eula.rtf.d2723e | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\1031\localizeddata.xml.d2723e | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\watermark.bmp.d2723e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\common files\designer\msaddndr.olb.d2723e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\microsoft office\office16\ospp.htm.d2723e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\microsoft office\root\fre\startmenu_win8.mp4.d2723e | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\adobe\color\profiles\wscrgb.icc.d2723e | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\music\lpmf-4rs05expec6b.m4a.d2723e | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\music\1myalk v36s25k\riloz0yot4fzkz9thykt.mp3.d2723e | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows10upgrade\resources\i386\hwexclude.txt.d2723e | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows10upgrade\resources\ux\nonetworkconnection.png.d2723e | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Libraries\D2723E-Readme.txt | Dropped File | Text |
Unknown
|
...
|
»
c:\588bce7c90097ed212\splashscreen.bmp.d2723e | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\1036\localizeddata.xml.d2723e | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Oracle\Java\.oracle_jre_usage\17dfc292991c7c46.timestamp | Modified File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\USOShared\Logs\NotificationUxBroker.013.etl | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\COPYRIGHT | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001F-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-002C-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0117-0409-1000-0000000FF1CE.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-012A-0000-1000-0000000FF1CE.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\1494870C-9912-C184-4CC9-B401-A53F4D8DE290.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\calendars.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\content-types.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\hijrah-config-umalqura.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jvm.hprof.txt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\tzdb.dat | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.79\61.0.3163.79.manifest | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Google\Chrome\Application\chrome.VisualElementsManifest.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Document Themes 16\Ion.thmx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Document Themes 16\Office Theme.thmx | Modified File | Stream |
Not Queried
|
...
|
»
c:\588bce7c90097ed212\uiinfo.xml.d2723e | Dropped File | Stream |
Not Queried
|
...
|
»