VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: | - |
Threat Names: |
Trojan.GenericKD.45208383
Mal/Generic-S
|
%ALLUSERSPROFILE%microsoftwindowsstart menuprogramsstartupwindows-update-cve-wfw.exe
Windows Exe (x86-64)
Created at 2020-12-28T17:00:00
Remarks
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\%ALLUSERSPROFILE%microsoftwindowsstart menuprogramsstartupwindows-update-cve-wfw.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x469740 |
Size Of Code | 0x15fe00 |
Size Of Initialized Data | 0x1e400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.amd64 |
Compile Timestamp | 1970-01-01 00:00:00+00:00 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x15fd3e | 0x15fe00 | 0x600 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.93 |
.rdata | 0x561000 | 0x120a26 | 0x120c00 | 0x160400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.24 |
.data | 0x682000 | 0x55768 | 0x1e400 | 0x281000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.47 |
.idata | 0x6d8000 | 0x4a0 | 0x600 | 0x29f400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.69 |
.reloc | 0x6d9000 | 0xc70c | 0xc800 | 0x29fa00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.45 |
.symtab | 0x6e6000 | 0x4 | 0x200 | 0x2ac200 | IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.02 |
Imports (1)
»
kernel32.dll (40)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WriteFile | 0x0 | 0x682020 | 0x2d8358 | 0x29f758 | 0x0 |
WriteConsoleW | 0x0 | 0x682028 | 0x2d8360 | 0x29f760 | 0x0 |
WaitForMultipleObjects | 0x0 | 0x682030 | 0x2d8368 | 0x29f768 | 0x0 |
WaitForSingleObject | 0x0 | 0x682038 | 0x2d8370 | 0x29f770 | 0x0 |
VirtualQuery | 0x0 | 0x682040 | 0x2d8378 | 0x29f778 | 0x0 |
VirtualFree | 0x0 | 0x682048 | 0x2d8380 | 0x29f780 | 0x0 |
VirtualAlloc | 0x0 | 0x682050 | 0x2d8388 | 0x29f788 | 0x0 |
SwitchToThread | 0x0 | 0x682058 | 0x2d8390 | 0x29f790 | 0x0 |
SuspendThread | 0x0 | 0x682060 | 0x2d8398 | 0x29f798 | 0x0 |
SetWaitableTimer | 0x0 | 0x682068 | 0x2d83a0 | 0x29f7a0 | 0x0 |
SetUnhandledExceptionFilter | 0x0 | 0x682070 | 0x2d83a8 | 0x29f7a8 | 0x0 |
SetProcessPriorityBoost | 0x0 | 0x682078 | 0x2d83b0 | 0x29f7b0 | 0x0 |
SetEvent | 0x0 | 0x682080 | 0x2d83b8 | 0x29f7b8 | 0x0 |
SetErrorMode | 0x0 | 0x682088 | 0x2d83c0 | 0x29f7c0 | 0x0 |
SetConsoleCtrlHandler | 0x0 | 0x682090 | 0x2d83c8 | 0x29f7c8 | 0x0 |
ResumeThread | 0x0 | 0x682098 | 0x2d83d0 | 0x29f7d0 | 0x0 |
QueryFullProcessImageNameA | 0x0 | 0x6820a0 | 0x2d83d8 | 0x29f7d8 | 0x0 |
ProcessIdToSessionId | 0x0 | 0x6820a8 | 0x2d83e0 | 0x29f7e0 | 0x0 |
PostQueuedCompletionStatus | 0x0 | 0x6820b0 | 0x2d83e8 | 0x29f7e8 | 0x0 |
OpenProcess | 0x0 | 0x6820b8 | 0x2d83f0 | 0x29f7f0 | 0x0 |
LoadLibraryA | 0x0 | 0x6820c0 | 0x2d83f8 | 0x29f7f8 | 0x0 |
LoadLibraryW | 0x0 | 0x6820c8 | 0x2d8400 | 0x29f800 | 0x0 |
SetThreadContext | 0x0 | 0x6820d0 | 0x2d8408 | 0x29f808 | 0x0 |
GetThreadContext | 0x0 | 0x6820d8 | 0x2d8410 | 0x29f810 | 0x0 |
GetSystemInfo | 0x0 | 0x6820e0 | 0x2d8418 | 0x29f818 | 0x0 |
GetSystemDirectoryA | 0x0 | 0x6820e8 | 0x2d8420 | 0x29f820 | 0x0 |
GetStdHandle | 0x0 | 0x6820f0 | 0x2d8428 | 0x29f828 | 0x0 |
GetQueuedCompletionStatusEx | 0x0 | 0x6820f8 | 0x2d8430 | 0x29f830 | 0x0 |
GetProcessAffinityMask | 0x0 | 0x682100 | 0x2d8438 | 0x29f838 | 0x0 |
GetProcAddress | 0x0 | 0x682108 | 0x2d8440 | 0x29f840 | 0x0 |
GetEnvironmentStringsW | 0x0 | 0x682110 | 0x2d8448 | 0x29f848 | 0x0 |
GetConsoleMode | 0x0 | 0x682118 | 0x2d8450 | 0x29f850 | 0x0 |
FreeEnvironmentStringsW | 0x0 | 0x682120 | 0x2d8458 | 0x29f858 | 0x0 |
ExitProcess | 0x0 | 0x682128 | 0x2d8460 | 0x29f860 | 0x0 |
DuplicateHandle | 0x0 | 0x682130 | 0x2d8468 | 0x29f868 | 0x0 |
CreateThread | 0x0 | 0x682138 | 0x2d8470 | 0x29f870 | 0x0 |
CreateIoCompletionPort | 0x0 | 0x682140 | 0x2d8478 | 0x29f878 | 0x0 |
CreateEventA | 0x0 | 0x682148 | 0x2d8480 | 0x29f880 | 0x0 |
CloseHandle | 0x0 | 0x682150 | 0x2d8488 | 0x29f888 | 0x0 |
AddVectoredExceptionHandler | 0x0 | 0x682158 | 0x2d8490 | 0x29f890 | 0x0 |
Digital Signatures (3)
»
Certificate: Mozilla Corporation
»
Issued by | Mozilla Corporation |
Parent Certificate | DigiCert SHA2 Assured ID Code Signing CA |
Country Name | US |
Valid From | 2020-05-07 00:00:00+00:00 |
Valid Until | 2021-05-12 12:00:00+00:00 |
Algorithm | sha256_rsa |
Serial Number | 0D DE B5 3F 95 73 37 FB EA F9 8C 4A 61 5B 14 9D |
Thumbprint | 91 CA BE A5 09 66 26 26 E3 43 26 68 73 48 CA F2 DD 3B 4B BA |
Certificate: DigiCert SHA2 Assured ID Code Signing CA
»
Issued by | DigiCert SHA2 Assured ID Code Signing CA |
Parent Certificate | DigiCert Assured ID Root CA |
Country Name | US |
Valid From | 2013-10-22 12:00:00+00:00 |
Valid Until | 2028-10-22 12:00:00+00:00 |
Algorithm | sha256_rsa |
Serial Number | 04 09 18 1B 5F D5 BB 66 75 53 43 B5 6F 95 50 08 |
Thumbprint | 92 C1 58 8E 85 AF 22 01 CE 79 15 E8 53 8B 49 2F 60 5B 80 C6 |
Certificate: DigiCert Assured ID Root CA
»
Issued by | DigiCert Assured ID Root CA |
Country Name | US |
Valid From | 2006-11-10 00:00:00+00:00 |
Valid Until | 2031-11-10 00:00:00+00:00 |
Algorithm | sha1_rsa |
Serial Number | 0C E7 E0 E5 17 D8 46 FE 8F E5 60 FC 1B F0 30 39 |
Thumbprint | 05 63 B8 63 0D 62 D7 5A BB C8 AB 1E 4B DF B5 A8 99 B2 4D 43 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
%allusersprofile%microsoftwindowsstart menuprogramsstartupwindows-update-cve-wfw.exe | 1 | 0x008C0000 | 0x00BA6FFF | Relevant Image |
![]() |
64-bit | 0x008F162B |
![]() |
![]() |
...
|
%allusersprofile%microsoftwindowsstart menuprogramsstartupwindows-update-cve-wfw.exe | 1 | 0x008C0000 | 0x00BA6FFF | Final Dump |
![]() |
64-bit | 0x00923000 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.45208383 |
Malicious
|
C:\Users\FD1HVy\AppData\Local\Temp\4c15fb622022805c2fdb3c4017380631 | Dropped File | Batch |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\preoobe.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\ee1176b1eafcfa4fbcba11de55fbf6ea | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\941ee64f0e7a91446acac39a26d2f807 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\2e2586afcf5bd37215fe1e941522f969 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\3ad4cea42a5f638167dfd92742ee7b89 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\9ff0e09db206b2de79b58cb8a3c5ded1 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\cdc5875cdbd16553951582705630678e | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\0fb75d0b54d27ac50188bead54360bbb | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\6eb6e1d0bd9f11140222b7597f180f8c | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\3298d7906e47da9f7e71a84923afa438 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\16d8dfe08e8c568b3449f27bd09a6c54 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\3862b319de414f209239e046ec428d81 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\665f8522598a1eb0b01be10e741f8153 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DHtmlHeader.html | Modified File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\preoobe.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\4c15fb622022805c2fdb3c4017380631 | Dropped File | Batch |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\ee1176b1eafcfa4fbcba11de55fbf6ea | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\941ee64f0e7a91446acac39a26d2f807 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\3ad4cea42a5f638167dfd92742ee7b89 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\9ff0e09db206b2de79b58cb8a3c5ded1 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\cdc5875cdbd16553951582705630678e | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\0fb75d0b54d27ac50188bead54360bbb | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\3298d7906e47da9f7e71a84923afa438 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\6eb6e1d0bd9f11140222b7597f180f8c | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\16d8dfe08e8c568b3449f27bd09a6c54 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\3862b319de414f209239e046ec428d81 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\665f8522598a1eb0b01be10e741f8153 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DHtmlHeader.html | Modified File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\cc381b4dc11aa3fb6641b39158d28ea9 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\a527eb5d8deb4ff2325b342ae7519a8a | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\f189b65a7d1724172a798f8894691c16 | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\d148dc42cf55ae9a91e0da2097dfe351 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11-lic.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\2744abafb87aab81cc5c2e26db77b02e | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash@2x.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\ac4d62ca3591c57d97b943f6da564a8e | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\e008ae445b1f752cca529cfd81739823 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\dnsns.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\a8029f77e3a338bf7a839208d7762dfe | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\cldrdata.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\a233ee53138bc778935088e49fb82274 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\sunjce_provider.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\sunec.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\3ca019b59b1b9a7469f270177ab25aba | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\sunpkcs11.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\e9dd75c7375e6ece99d0faf33540be8b | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\zipfs.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\ab4efa864dc72b7a41923fccda58b6e1 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\549229d8af8fe9007c6ff46ac3f34004 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkNoDrop32x32.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\78516b89cd7cf501c37fb288bf0e8175 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\e187b666fe5055afce748d9219d06a2a | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jce.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\e8aeed6468ce868b60a79947f1e729af | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\7839fbc6b6cdecbfe772df03fb84b2a3 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\5d5b14c4ba96977b80fba27b4fe57a9c | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\management-agent.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\9e99c079f2065f27b799ef18ed856c4f | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\15d0dfeaf6cf369c178c9e5ec4360746 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jsse.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\06ba6b8127abc2917092cfc3943c58a2 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\8be6b6218571020b4ad2c492226397d7 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\security\local_policy.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\74cf0a11ed3cfb7e7b947fa8fb42ef0f | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\d707351ae9a2f8b426cf0186b56a668b | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00021_.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\83985690457ce6c8a6c936a48eca7147 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\630d9861cf14f6270429108251dbbdc3 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00038_.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00052_.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00090_.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00040_.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\4b518d98027df1e13f6eee754568a6da | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\23e51325d46892078f919f0786761328 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\081613c64af038a7d5bfe30d08187e1b | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\a5c9016cb3b9109371cf43ebf0084111 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00126_.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\8b65c1e67cca30d1117627451fdcfab6 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\663eaa764a2f03a67ccdad6fda3d0ace | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\7f5a8ab3a5e9a5713e6198c823dc5e11 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00142_.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\ac016e69d9191bec814a69210a800b91 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00157_.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00160_.GIF | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\6c32c789dc9e32374481059e7337a517 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\33d7700-06bc-47c5-8714-222cdac43a71.tmp.034530127 | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\f47adf2eee67c458e3e5269d5357da7c | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\fb1d2333bd43445629e34dc165e66c28 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\33d7700-06bc-47c5-8714-222cdac43a71.tmp.678017987 | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\f47adf2eee67c458e3e5269d5357da7c | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\fb1d2333bd43445629e34dc165e66c28 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\288911e965ff562abe4df42085680bf9 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\7d63409884a28ad77a53c68307ea63cd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\4d9e67821c6bb955c673c49eeff1653b | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\75c413270dd893f2f037720e7ca1c156 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\e98252b211b16ac83e3fd9607d568bc9 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\7ff1ec6e5b6e349a465d6c84eb352eb6 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\2d6149092d0b8f5c9dc1a3b59c0a1057 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\a3c5aa0547420a67fbd6fe9be9c6fff2 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\7f662a6b9704c3c0c2e8137b4900f98b | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\52aa4a39bdb9cfcf01bf5470a20be258 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\0dd636762d866a883bcfa21fb211ee7a | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\78b9ad6d10168853df574928c18caef9 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\475eff71ed7a5170277e52f41767ad19 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\4ec1e97a26078872cb209914f4c79a7d | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\b5660d03c05557ff9ee0bfd5ae6c38f5 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\c53f7e2891d3f22f88538990c850dc30 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\2e2586afcf5bd37215fe1e941522f969 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\377fb7627a172221f01d406bbf93df17 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\9c051818229f7c1cb88ffe93aa4a0c60 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\6eeff5082bc660889ef9d2a5f0cbe916 | Dropped File | Stream |
Not Queried
|
...
|
»