VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Downloader
|
Threat Names: |
Exploit.HTML.BitsAdmin.Gen
Trojan.GenericKD.43369001
Mal/Generic-S
|
PIC123174.jpg.js
JScript
Created at 2020-06-21T13:42:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Exploit.HTML.BitsAdmin.Gen |
Malicious
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PowerShell_Download_Commands | PowerShell may attempt to download external content; possible dropper | - |
4/5
|
...
|
C:\WINDOWS\system32\05750050.exe | Downloaded File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x44cd04 |
Size Of Code | 0x98200 |
Size Of Initialized Data | 0x80600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-06-19 12:42:43+00:00 |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | Host Process for Windows Tasks |
FileVersion | 10.0.17763.831 (WinBuild.160101.0800) |
InternalName | taskhost.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | taskhost.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 10.0.17763.831 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x98046 | 0x98200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.59 |
.rdata | 0x49a000 | 0x6a096 | 0x6a200 | 0x98600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.63 |
.data | 0x505000 | 0xac18 | 0x9600 | 0x102800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.63 |
.rsrc | 0x510000 | 0x410 | 0x600 | 0x10be00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.45 |
.reloc | 0x511000 | 0xaedc | 0xb000 | 0x10c400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.67 |
Imports (13)
»
KERNEL32.dll (148)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetTickCount | 0x0 | 0x49a070 | 0x102dc4 | 0x1013c4 | 0x307 |
IsDebuggerPresent | 0x0 | 0x49a074 | 0x102dc8 | 0x1013c8 | 0x37f |
CheckRemoteDebuggerPresent | 0x0 | 0x49a078 | 0x102dcc | 0x1013cc | 0x80 |
WriteFile | 0x0 | 0x49a07c | 0x102dd0 | 0x1013d0 | 0x612 |
CreateFileW | 0x0 | 0x49a080 | 0x102dd4 | 0x1013d4 | 0xcb |
ReadFile | 0x0 | 0x49a084 | 0x102dd8 | 0x1013d8 | 0x473 |
GetFileSizeEx | 0x0 | 0x49a088 | 0x102ddc | 0x1013dc | 0x24c |
GetFileAttributesW | 0x0 | 0x49a08c | 0x102de0 | 0x1013e0 | 0x245 |
SetFileAttributesW | 0x0 | 0x49a090 | 0x102de4 | 0x1013e4 | 0x51d |
SetFilePointerEx | 0x0 | 0x49a094 | 0x102de8 | 0x1013e8 | 0x523 |
MoveFileExW | 0x0 | 0x49a098 | 0x102dec | 0x1013ec | 0x3e8 |
FindFirstFileW | 0x0 | 0x49a09c | 0x102df0 | 0x1013f0 | 0x180 |
FindNextFileW | 0x0 | 0x49a0a0 | 0x102df4 | 0x1013f4 | 0x18c |
GetEnvironmentVariableW | 0x0 | 0x49a0a4 | 0x102df8 | 0x1013f8 | 0x239 |
FindClose | 0x0 | 0x49a0a8 | 0x102dfc | 0x1013fc | 0x175 |
GetShortPathNameA | 0x0 | 0x49a0ac | 0x102e00 | 0x101400 | 0x2cc |
ReleaseMutex | 0x0 | 0x49a0b0 | 0x102e04 | 0x101404 | 0x4b0 |
GetLocaleInfoA | 0x0 | 0x49a0b4 | 0x102e08 | 0x101408 | 0x263 |
GetDiskFreeSpaceA | 0x0 | 0x49a0b8 | 0x102e0c | 0x10140c | 0x226 |
GetComputerNameA | 0x0 | 0x49a0bc | 0x102e10 | 0x101410 | 0x1dc |
WriteConsoleW | 0x0 | 0x49a0c0 | 0x102e14 | 0x101414 | 0x611 |
SetEndOfFile | 0x0 | 0x49a0c4 | 0x102e18 | 0x101418 | 0x510 |
HeapSize | 0x0 | 0x49a0c8 | 0x102e1c | 0x10141c | 0x34e |
ReadConsoleW | 0x0 | 0x49a0cc | 0x102e20 | 0x101420 | 0x470 |
GetProcessHeap | 0x0 | 0x49a0d0 | 0x102e24 | 0x101424 | 0x2b4 |
GetThreadContext | 0x0 | 0x49a0d4 | 0x102e28 | 0x101428 | 0x2f7 |
HeapAlloc | 0x0 | 0x49a0d8 | 0x102e2c | 0x10142c | 0x345 |
CloseHandle | 0x0 | 0x49a0dc | 0x102e30 | 0x101430 | 0x86 |
Process32FirstW | 0x0 | 0x49a0e0 | 0x102e34 | 0x101434 | 0x42c |
GetCurrentThread | 0x0 | 0x49a0e4 | 0x102e38 | 0x101438 | 0x21b |
GetUserDefaultLCID | 0x0 | 0x49a0e8 | 0x102e3c | 0x10143c | 0x312 |
Process32NextW | 0x0 | 0x49a0ec | 0x102e40 | 0x101440 | 0x42e |
GetLastError | 0x0 | 0x49a0f0 | 0x102e44 | 0x101444 | 0x261 |
Sleep | 0x0 | 0x49a0f4 | 0x102e48 | 0x101448 | 0x57d |
CreateToolhelp32Snapshot | 0x0 | 0x49a0f8 | 0x102e4c | 0x10144c | 0xfc |
OpenProcess | 0x0 | 0x49a0fc | 0x102e50 | 0x101450 | 0x40d |
WaitForSingleObject | 0x0 | 0x49a100 | 0x102e54 | 0x101454 | 0x5d7 |
OpenMutexW | 0x0 | 0x49a104 | 0x102e58 | 0x101458 | 0x409 |
GetModuleFileNameW | 0x0 | 0x49a108 | 0x102e5c | 0x10145c | 0x274 |
TerminateProcess | 0x0 | 0x49a10c | 0x102e60 | 0x101460 | 0x58c |
GetCurrentProcess | 0x0 | 0x49a110 | 0x102e64 | 0x101464 | 0x217 |
HeapFree | 0x0 | 0x49a114 | 0x102e68 | 0x101468 | 0x349 |
WideCharToMultiByte | 0x0 | 0x49a118 | 0x102e6c | 0x10146c | 0x5fe |
MultiByteToWideChar | 0x0 | 0x49a11c | 0x102e70 | 0x101470 | 0x3ef |
FindNextVolumeW | 0x0 | 0x49a120 | 0x102e74 | 0x101474 | 0x191 |
GetVolumePathNamesForVolumeNameW | 0x0 | 0x49a124 | 0x102e78 | 0x101478 | 0x324 |
FindVolumeClose | 0x0 | 0x49a128 | 0x102e7c | 0x10147c | 0x198 |
SetVolumeMountPointW | 0x0 | 0x49a12c | 0x102e80 | 0x101480 | 0x574 |
FindFirstVolumeW | 0x0 | 0x49a130 | 0x102e84 | 0x101484 | 0x186 |
QueryDosDeviceW | 0x0 | 0x49a134 | 0x102e88 | 0x101488 | 0x445 |
FlushFileBuffers | 0x0 | 0x49a138 | 0x102e8c | 0x10148c | 0x19f |
SetEnvironmentVariableW | 0x0 | 0x49a13c | 0x102e90 | 0x101490 | 0x514 |
FreeEnvironmentStringsW | 0x0 | 0x49a140 | 0x102e94 | 0x101494 | 0x1aa |
GetEnvironmentStringsW | 0x0 | 0x49a144 | 0x102e98 | 0x101498 | 0x237 |
GetCommandLineW | 0x0 | 0x49a148 | 0x102e9c | 0x10149c | 0x1d7 |
GetCommandLineA | 0x0 | 0x49a14c | 0x102ea0 | 0x1014a0 | 0x1d6 |
GetOEMCP | 0x0 | 0x49a150 | 0x102ea4 | 0x1014a4 | 0x297 |
GetACP | 0x0 | 0x49a154 | 0x102ea8 | 0x1014a8 | 0x1b2 |
IsValidCodePage | 0x0 | 0x49a158 | 0x102eac | 0x1014ac | 0x38b |
FindFirstFileExW | 0x0 | 0x49a15c | 0x102eb0 | 0x1014b0 | 0x17b |
HeapReAlloc | 0x0 | 0x49a160 | 0x102eb4 | 0x1014b4 | 0x34c |
GetConsoleMode | 0x0 | 0x49a164 | 0x102eb8 | 0x1014b8 | 0x1fc |
GetConsoleCP | 0x0 | 0x49a168 | 0x102ebc | 0x1014bc | 0x1ea |
SetStdHandle | 0x0 | 0x49a16c | 0x102ec0 | 0x1014c0 | 0x54a |
DeleteFileW | 0x0 | 0x49a170 | 0x102ec4 | 0x1014c4 | 0x115 |
GetFileType | 0x0 | 0x49a174 | 0x102ec8 | 0x1014c8 | 0x24e |
EnumSystemLocalesW | 0x0 | 0x49a178 | 0x102ecc | 0x1014cc | 0x154 |
IsValidLocale | 0x0 | 0x49a17c | 0x102ed0 | 0x1014d0 | 0x38d |
GetTimeFormatW | 0x0 | 0x49a180 | 0x102ed4 | 0x1014d4 | 0x30c |
GetDateFormatW | 0x0 | 0x49a184 | 0x102ed8 | 0x1014d8 | 0x221 |
GetTimeZoneInformation | 0x0 | 0x49a188 | 0x102edc | 0x1014dc | 0x30e |
GetStdHandle | 0x0 | 0x49a18c | 0x102ee0 | 0x1014e0 | 0x2d2 |
CopyFileW | 0x0 | 0x49a190 | 0x102ee4 | 0x1014e4 | 0xad |
CreateMutexW | 0x0 | 0x49a194 | 0x102ee8 | 0x1014e8 | 0xda |
ExitProcess | 0x0 | 0x49a198 | 0x102eec | 0x1014ec | 0x15e |
RtlUnwind | 0x0 | 0x49a19c | 0x102ef0 | 0x1014f0 | 0x4d3 |
LoadLibraryW | 0x0 | 0x49a1a0 | 0x102ef4 | 0x1014f4 | 0x3c4 |
UnregisterWaitEx | 0x0 | 0x49a1a4 | 0x102ef8 | 0x1014f8 | 0x5b7 |
QueryDepthSList | 0x0 | 0x49a1a8 | 0x102efc | 0x1014fc | 0x443 |
InterlockedFlushSList | 0x0 | 0x49a1ac | 0x102f00 | 0x101500 | 0x36c |
InterlockedPushEntrySList | 0x0 | 0x49a1b0 | 0x102f04 | 0x101504 | 0x36f |
InterlockedPopEntrySList | 0x0 | 0x49a1b4 | 0x102f08 | 0x101508 | 0x36e |
ReleaseSemaphore | 0x0 | 0x49a1b8 | 0x102f0c | 0x10150c | 0x4b4 |
DuplicateHandle | 0x0 | 0x49a1bc | 0x102f10 | 0x101510 | 0x12b |
VirtualFree | 0x0 | 0x49a1c0 | 0x102f14 | 0x101514 | 0x5c9 |
GetLogicalDrives | 0x0 | 0x49a1c4 | 0x102f18 | 0x101518 | 0x268 |
CreateProcessW | 0x0 | 0x49a1c8 | 0x102f1c | 0x10151c | 0xe5 |
VirtualProtect | 0x0 | 0x49a1cc | 0x102f20 | 0x101520 | 0x5cc |
VirtualAlloc | 0x0 | 0x49a1d0 | 0x102f24 | 0x101524 | 0x5c6 |
GetVersionExW | 0x0 | 0x49a1d4 | 0x102f28 | 0x101528 | 0x31b |
LoadLibraryExW | 0x0 | 0x49a1d8 | 0x102f2c | 0x10152c | 0x3c3 |
GetModuleHandleA | 0x0 | 0x49a1dc | 0x102f30 | 0x101530 | 0x275 |
FreeLibraryAndExitThread | 0x0 | 0x49a1e0 | 0x102f34 | 0x101534 | 0x1ac |
FreeLibrary | 0x0 | 0x49a1e4 | 0x102f38 | 0x101538 | 0x1ab |
GetThreadTimes | 0x0 | 0x49a1e8 | 0x102f3c | 0x10153c | 0x305 |
RaiseException | 0x0 | 0x49a1ec | 0x102f40 | 0x101540 | 0x462 |
GetCurrentThreadId | 0x0 | 0x49a1f0 | 0x102f44 | 0x101544 | 0x21c |
IsProcessorFeaturePresent | 0x0 | 0x49a1f4 | 0x102f48 | 0x101548 | 0x386 |
QueueUserWorkItem | 0x0 | 0x49a1f8 | 0x102f4c | 0x10154c | 0x457 |
GetModuleHandleExW | 0x0 | 0x49a1fc | 0x102f50 | 0x101550 | 0x277 |
FormatMessageW | 0x0 | 0x49a200 | 0x102f54 | 0x101554 | 0x1a7 |
EnterCriticalSection | 0x0 | 0x49a204 | 0x102f58 | 0x101558 | 0x131 |
LeaveCriticalSection | 0x0 | 0x49a208 | 0x102f5c | 0x10155c | 0x3bd |
TryEnterCriticalSection | 0x0 | 0x49a20c | 0x102f60 | 0x101560 | 0x5a7 |
DeleteCriticalSection | 0x0 | 0x49a210 | 0x102f64 | 0x101564 | 0x110 |
QueryPerformanceCounter | 0x0 | 0x49a214 | 0x102f68 | 0x101568 | 0x44d |
QueryPerformanceFrequency | 0x0 | 0x49a218 | 0x102f6c | 0x10156c | 0x44e |
SetLastError | 0x0 | 0x49a21c | 0x102f70 | 0x101570 | 0x532 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x49a220 | 0x102f74 | 0x101574 | 0x35f |
CreateEventW | 0x0 | 0x49a224 | 0x102f78 | 0x101578 | 0xbf |
SwitchToThread | 0x0 | 0x49a228 | 0x102f7c | 0x10157c | 0x587 |
TlsAlloc | 0x0 | 0x49a22c | 0x102f80 | 0x101580 | 0x59e |
TlsGetValue | 0x0 | 0x49a230 | 0x102f84 | 0x101584 | 0x5a0 |
TlsSetValue | 0x0 | 0x49a234 | 0x102f88 | 0x101588 | 0x5a1 |
TlsFree | 0x0 | 0x49a238 | 0x102f8c | 0x10158c | 0x59f |
GetSystemTimeAsFileTime | 0x0 | 0x49a23c | 0x102f90 | 0x101590 | 0x2e9 |
GetModuleHandleW | 0x0 | 0x49a240 | 0x102f94 | 0x101594 | 0x278 |
GetProcAddress | 0x0 | 0x49a244 | 0x102f98 | 0x101598 | 0x2ae |
WaitForSingleObjectEx | 0x0 | 0x49a248 | 0x102f9c | 0x10159c | 0x5d8 |
EncodePointer | 0x0 | 0x49a24c | 0x102fa0 | 0x1015a0 | 0x12d |
DecodePointer | 0x0 | 0x49a250 | 0x102fa4 | 0x1015a4 | 0x109 |
GetStringTypeW | 0x0 | 0x49a254 | 0x102fa8 | 0x1015a8 | 0x2d7 |
CompareStringW | 0x0 | 0x49a258 | 0x102fac | 0x1015ac | 0x9b |
LCMapStringW | 0x0 | 0x49a25c | 0x102fb0 | 0x1015b0 | 0x3b1 |
GetLocaleInfoW | 0x0 | 0x49a260 | 0x102fb4 | 0x1015b4 | 0x265 |
GetCPInfo | 0x0 | 0x49a264 | 0x102fb8 | 0x1015b8 | 0x1c1 |
UnhandledExceptionFilter | 0x0 | 0x49a268 | 0x102fbc | 0x1015bc | 0x5ad |
SetUnhandledExceptionFilter | 0x0 | 0x49a26c | 0x102fc0 | 0x1015c0 | 0x56d |
SetEvent | 0x0 | 0x49a270 | 0x102fc4 | 0x1015c4 | 0x516 |
ResetEvent | 0x0 | 0x49a274 | 0x102fc8 | 0x1015c8 | 0x4c6 |
GetStartupInfoW | 0x0 | 0x49a278 | 0x102fcc | 0x1015cc | 0x2d0 |
GetCurrentProcessId | 0x0 | 0x49a27c | 0x102fd0 | 0x1015d0 | 0x218 |
InitializeSListHead | 0x0 | 0x49a280 | 0x102fd4 | 0x1015d4 | 0x363 |
LocalFree | 0x0 | 0x49a284 | 0x102fd8 | 0x1015d8 | 0x3cf |
CreateTimerQueue | 0x0 | 0x49a288 | 0x102fdc | 0x1015dc | 0xfa |
SignalObjectAndWait | 0x0 | 0x49a28c | 0x102fe0 | 0x1015e0 | 0x57b |
CreateThread | 0x0 | 0x49a290 | 0x102fe4 | 0x1015e4 | 0xf3 |
SetThreadPriority | 0x0 | 0x49a294 | 0x102fe8 | 0x1015e8 | 0x55e |
GetThreadPriority | 0x0 | 0x49a298 | 0x102fec | 0x1015ec | 0x301 |
GetLogicalProcessorInformation | 0x0 | 0x49a29c | 0x102ff0 | 0x1015f0 | 0x269 |
CreateTimerQueueTimer | 0x0 | 0x49a2a0 | 0x102ff4 | 0x1015f4 | 0xfb |
ChangeTimerQueueTimer | 0x0 | 0x49a2a4 | 0x102ff8 | 0x1015f8 | 0x78 |
DeleteTimerQueueTimer | 0x0 | 0x49a2a8 | 0x102ffc | 0x1015fc | 0x11a |
GetNumaHighestNodeNumber | 0x0 | 0x49a2ac | 0x103000 | 0x101600 | 0x289 |
GetProcessAffinityMask | 0x0 | 0x49a2b0 | 0x103004 | 0x101604 | 0x2af |
SetThreadAffinityMask | 0x0 | 0x49a2b4 | 0x103008 | 0x101608 | 0x553 |
RegisterWaitForSingleObject | 0x0 | 0x49a2b8 | 0x10300c | 0x10160c | 0x4a9 |
UnregisterWait | 0x0 | 0x49a2bc | 0x103010 | 0x101610 | 0x5b6 |
USER32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SystemParametersInfoW | 0x0 | 0x49a31c | 0x103070 | 0x101670 | 0x390 |
GetKeyboardLayout | 0x0 | 0x49a320 | 0x103074 | 0x101674 | 0x167 |
ADVAPI32.dll (23)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EnumDependentServicesW | 0x0 | 0x49a000 | 0x102d54 | 0x101354 | 0x10f |
OpenServiceW | 0x0 | 0x49a004 | 0x102d58 | 0x101358 | 0x219 |
CryptSetKeyParam | 0x0 | 0x49a008 | 0x102d5c | 0x10135c | 0xde |
CryptDestroyKey | 0x0 | 0x49a00c | 0x102d60 | 0x101360 | 0xc8 |
CryptAcquireContextW | 0x0 | 0x49a010 | 0x102d64 | 0x101364 | 0xc2 |
CryptEncrypt | 0x0 | 0x49a014 | 0x102d68 | 0x101368 | 0xcb |
CryptDuplicateKey | 0x0 | 0x49a018 | 0x102d6c | 0x10136c | 0xca |
CryptExportKey | 0x0 | 0x49a01c | 0x102d70 | 0x101370 | 0xd0 |
CryptImportKey | 0x0 | 0x49a020 | 0x102d74 | 0x101374 | 0xdb |
CryptGenKey | 0x0 | 0x49a024 | 0x102d78 | 0x101378 | 0xd1 |
CryptReleaseContext | 0x0 | 0x49a028 | 0x102d7c | 0x10137c | 0xdc |
OpenProcessToken | 0x0 | 0x49a02c | 0x102d80 | 0x101380 | 0x215 |
GetTokenInformation | 0x0 | 0x49a030 | 0x102d84 | 0x101384 | 0x170 |
RegCloseKey | 0x0 | 0x49a034 | 0x102d88 | 0x101388 | 0x25b |
CloseServiceHandle | 0x0 | 0x49a038 | 0x102d8c | 0x10138c | 0x65 |
OpenSCManagerW | 0x0 | 0x49a03c | 0x102d90 | 0x101390 | 0x217 |
DeleteService | 0x0 | 0x49a040 | 0x102d94 | 0x101394 | 0xec |
ControlService | 0x0 | 0x49a044 | 0x102d98 | 0x101398 | 0x6a |
RegSetValueExW | 0x0 | 0x49a048 | 0x102d9c | 0x10139c | 0x2a9 |
StartServiceW | 0x0 | 0x49a04c | 0x102da0 | 0x1013a0 | 0x2fb |
RegOpenKeyExW | 0x0 | 0x49a050 | 0x102da4 | 0x1013a4 | 0x28c |
RegCreateKeyW | 0x0 | 0x49a054 | 0x102da8 | 0x1013a8 | 0x267 |
QueryServiceStatusEx | 0x0 | 0x49a058 | 0x102dac | 0x1013ac | 0x251 |
SHELL32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderPathA | 0x0 | 0x49a310 | 0x103064 | 0x101664 | 0x175 |
SHEmptyRecycleBinW | 0x0 | 0x49a314 | 0x103068 | 0x101668 | 0x13a |
ole32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoInitializeEx | 0x0 | 0x49a364 | 0x1030b8 | 0x1016b8 | 0x5e |
IIDFromString | 0x0 | 0x49a368 | 0x1030bc | 0x1016bc | 0x102 |
CLSIDFromString | 0x0 | 0x49a36c | 0x1030c0 | 0x1016c0 | 0xc |
CoGetObject | 0x0 | 0x49a370 | 0x1030c4 | 0x1016c4 | 0x51 |
CoSetProxyBlanket | 0x0 | 0x49a374 | 0x1030c8 | 0x1016c8 | 0x84 |
CoInitializeSecurity | 0x0 | 0x49a378 | 0x1030cc | 0x1016cc | 0x5f |
CoCreateInstance | 0x0 | 0x49a37c | 0x1030d0 | 0x1016d0 | 0x28 |
CoUninitialize | 0x0 | 0x49a380 | 0x1030d4 | 0x1016d4 | 0x8d |
OLEAUT32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysAllocStringByteLen | 0x96 | 0x49a2dc | 0x103030 | 0x101630 | - |
SysAllocString | 0x2 | 0x49a2e0 | 0x103034 | 0x101634 | - |
SysFreeString | 0x6 | 0x49a2e4 | 0x103038 | 0x101638 | - |
VariantInit | 0x8 | 0x49a2e8 | 0x10303c | 0x10163c | - |
VariantClear | 0x9 | 0x49a2ec | 0x103040 | 0x101640 | - |
SysStringByteLen | 0x95 | 0x49a2f0 | 0x103044 | 0x101644 | - |
MPR.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetGetConnectionA | 0x0 | 0x49a2c4 | 0x103018 | 0x101618 | 0x2a |
WNetGetConnectionW | 0x0 | 0x49a2c8 | 0x10301c | 0x10161c | 0x2b |
NETAPI32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetApiBufferFree | 0x0 | 0x49a2d0 | 0x103024 | 0x101624 | 0x51 |
NetShareEnum | 0x0 | 0x49a2d4 | 0x103028 | 0x101628 | 0xde |
IPHLPAPI.DLL (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SendARP | 0x0 | 0x49a068 | 0x102dbc | 0x1013bc | 0xf7 |
WS2_32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
gethostbyname | 0x34 | 0x49a348 | 0x10309c | 0x10169c | - |
WSAStartup | 0x73 | 0x49a34c | 0x1030a0 | 0x1016a0 | - |
gethostname | 0x39 | 0x49a350 | 0x1030a4 | 0x1016a4 | - |
inet_ntoa | 0xc | 0x49a354 | 0x1030a8 | 0x1016a8 | - |
WSACleanup | 0x74 | 0x49a358 | 0x1030ac | 0x1016ac | - |
inet_addr | 0xb | 0x49a35c | 0x1030b0 | 0x1016b0 | - |
RstrtMgr.DLL (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RmShutdown | 0x0 | 0x49a2f8 | 0x10304c | 0x10164c | 0xa |
RmRegisterResources | 0x0 | 0x49a2fc | 0x103050 | 0x101650 | 0x6 |
RmStartSession | 0x0 | 0x49a300 | 0x103054 | 0x101654 | 0xb |
RmEndSession | 0x0 | 0x49a304 | 0x103058 | 0x101658 | 0x2 |
RmGetList | 0x0 | 0x49a308 | 0x10305c | 0x10165c | 0x4 |
CRYPT32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptStringToBinaryA | 0x0 | 0x49a060 | 0x102db4 | 0x1013b4 | 0xe3 |
WININET.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InternetReadFile | 0x0 | 0x49a328 | 0x10307c | 0x10167c | 0xce |
HttpOpenRequestW | 0x0 | 0x49a32c | 0x103080 | 0x101680 | 0x79 |
InternetOpenW | 0x0 | 0x49a330 | 0x103084 | 0x101684 | 0xc9 |
HttpSendRequestW | 0x0 | 0x49a334 | 0x103088 | 0x101688 | 0x82 |
HttpSendRequestA | 0x0 | 0x49a338 | 0x10308c | 0x10168c | 0x7f |
InternetConnectW | 0x0 | 0x49a33c | 0x103090 | 0x101690 | 0x9c |
InternetCloseHandle | 0x0 | 0x49a340 | 0x103094 | 0x101694 | 0x95 |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
05750050.exe | 12 | 0x00DF0000 | 0x00F0BFFF | Relevant Image |
![]() |
32-bit | 0x00E54F79 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.43369001 |
Malicious
|
C:\\588bce7c90097ed212\1049\204502-readme.html | Dropped File | Text |
Suspicious
|
...
|
»
Embedded URLs (1)
»
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data | Actions |
---|---|---|---|---|---|---|
https://www.torproject.org/ | - | anonymization | - |
Suspicious
|
Not Queried
|
...
|
C:\Users\FD1HVy\AppData\Local\Temp\__PSScriptPolicyTest_by5erdwm.y5l.ps1 | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCache | Modified File | Stream |
Unknown
|
...
|
»
C:\\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log | Modified File | Stream |
Unknown
|
...
|
»
C:\\$GetCurrent\Logs\PartnerSetupCompleteResult.log.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\$GetCurrent\SafeOS\PartnerSetupComplete.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\\$GetCurrent\SafeOS\preoobe.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\\$WINRE_BACKUP_PARTITION.MARKER | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1025\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1025\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1029\LocalizedData.xml.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1030\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1031\eula.rtf.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1031\LocalizedData.xml.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1032\eula.rtf.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1032\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1033\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1033\LocalizedData.xml.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1035\eula.rtf.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1036\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1036\LocalizedData.xml.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1037\LocalizedData.xml.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1038\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1040\LocalizedData.xml.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1041\eula.rtf.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1041\LocalizedData.xml.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1042\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1042\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1043\eula.rtf.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1043\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1044\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1044\LocalizedData.xml.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1045\eula.rtf.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1045\LocalizedData.xml.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1046\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1046\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1049\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1049\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1053\eula.rtf.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1053\LocalizedData.xml.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1055\eula.rtf.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1055\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\2052\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\2070\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\2070\LocalizedData.xml.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\3076\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\3076\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\3082\eula.rtf.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\3082\LocalizedData.xml.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Client\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\DHtmlHeader.html.avdn | Dropped File | Text |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\DisplayIcon.ico.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Extended\Parameterinfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Extended\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Print.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Rotate1.ico.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Rotate2.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Rotate3.ico.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Rotate5.ico.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Rotate7.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Rotate8.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Save.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Setup.ico.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\SysReqMet.ico.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\SysReqNotMet.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\warn.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\header.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\netfx_Core.mzz | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\netfx_Core_x64.msi.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\netfx_Core_x86.msi.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\netfx_Extended.mzz.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\netfx_Extended_x64.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\netfx_Extended_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\ParameterInfo.xml.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\RGB9RAST_x64.msi.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\RGB9Rast_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\SetupUi.xsd | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Strings.xml.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\watermark.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\HardwareEvents.evtx.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\Internet Explorer.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Key Management Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\1laj5ge0T05eqQ.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\2ikc.ppt.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\5-XCtAHSzjo61V0.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\aADw0D4h.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\axGuz5WzBcrXS.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\bd-_6K7Bjrjo6wZ.mkv.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\CDWdMLxFO070Z.m4a.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\dw6ms.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\dZHkh-d.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\eV96P3TvpJgDZJ_krXc9.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\F0dKiYmc.flv.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\Fgsj.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\G0L551vH69pHEL2.m4a.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\h48IGAOeonqt.ods | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\i8r4W_pFGeGAI\1k7OF5q U.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\i8r4W_pFGeGAI\4BhodG-i--dW5vO.odt.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\i8r4W_pFGeGAI\4NEZjFTB7FonTCEpY7ky.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\i8r4W_pFGeGAI\6odWc8rKR6fAQPW2J.gif.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\i8r4W_pFGeGAI\CG WeZgUTQ6U.wav.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\i8r4W_pFGeGAI\Gpl9kg8Pze0yz CjYEuY.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\i8r4W_pFGeGAI\jep4Z.png | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\i8r4W_pFGeGAI\Jp3vlO.mp4.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\i8r4W_pFGeGAI\uXFg.jpg.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\i8r4W_pFGeGAI\WBZhs5uk8zbcY.flv.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\i8r4W_pFGeGAI\wla3GRnr.jpg.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\i8r4W_pFGeGAI\zg4La75Zm9u2LDC.png | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\IQjPf.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\kXSWpwY_UJZDb6qOu.wav.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\LN9D0_ldwVTJCFAOwu.mkv.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\NBSBZP0O.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\PIC123174.jpg.js.avdn | Dropped File | Text |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\PjNBWbRfMIra aEV7tFT.rtf.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\RdECcm.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\RzVskgvbGEwrfJzecuWU.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\TWmITQQ9KmDeuciJO_P.gif.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\uu_6OLfJ.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\UZGe-A2N7.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\U_R2iPr.m4a.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\VTuXUy.mp3.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\WFtt71YhJYkRaNq7oqX.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\XH rJ9LK4gHxAOkxI.pptx.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\xHJLMZXRw.avi.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\Z13ehe5CaR.ods | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\_g7yq_JXw.flv.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\1gmDqs.docx | Modified File | Binary |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\254WaYIyUfAuM0.ods | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\3Lreh\iBBojeIWrLJB3.xlsx.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\3Lreh\Kxz2.ppt.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\3Lreh\s3q9Ck.odp | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\3Lreh\uHJVbdBEKlmCmomQ.pps.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\3Lreh\x9c-IgMcJY6.odp | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\5cAT62qHmb.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\6Av HdZONLftD.pptx.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\7lNasNkOlKrq0C13.docx | Modified File | Binary |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\a VrSWYaQTyzT.xlsx.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\C3FXpx06RKpNCa7QN6.docx.avdn | Dropped File | Binary |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\Cx-cZYQBhUF_kYoWvT\bI-F29yNKXNncQs3Z-W_\FGB7nkxGRwbYSR7w.pps.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\Cx-cZYQBhUF_kYoWvT\bI-F29yNKXNncQs3Z-W_\pWG7LwDirSOyfw_2FVd.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\Cx-cZYQBhUF_kYoWvT\bI-F29yNKXNncQs3Z-W_\TGOl09_tsOBnfT.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\Cx-cZYQBhUF_kYoWvT\bI-F29yNKXNncQs3Z-W_\z5zCMkhCx9VPeNSS8.odp.avdn | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Documents\Cx-cZYQBhUF_kYoWvT\bro9F0k9ugQ.docx | Modified File | Binary |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\microsoft\windows\inetcache\ie\5alfeguz\hvkotcjc.htm | Dropped File | Text |
Unknown
|
...
|
»
C:\\$GetCurrent\SafeOS\SetupComplete.cmd | Modified File | Batch |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1029\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1037\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\2052\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Client\Parameterinfo.xml.avdn | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Rotate4.ico.avdn | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Rotate6.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\stop.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\SplashScreen.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\3WDLVhgvy2x2u82_S.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\Aq6ARFB.mp3.avdn | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\fNBkWg.mp3.avdn | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\GOAPDRn- rzR.bmp.avdn | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\UxqG0prHA6c7ICh.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Desktop\WJ0U.flv.avdn | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\FD1HVy\Documents\Cx-cZYQBhUF_kYoWvT\4C NwxgTL913AUmIz.odt | Modified File | Stream |
Not Queried
|
...
|
»