VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Trojan.GenericKD.32727036
Gen:Variant.Emotet.91
Generic.EmotetU.48920E05
...
|
CUBE.EXE.exe
Windows Exe (x86-32)
Created 5 years ago
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "30 seconds" to "10 seconds" to reveal dormant functionality.
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x404b29 |
Size Of Code | 0x29e00 |
Size Of Initialized Data | 0x24c00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-10-06 14:08:28+00:00 |
Version Information (7)
»
FileDescription | CUBE MFC Application |
FileVersion | 1, 0, 0, 1 |
InternalName | CUBE |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | CUBE.EXE |
ProductName | CUBE Application |
ProductVersion | 1, 0, 0, 1 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x29c54 | 0x29e00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.59 |
.rdata | 0x42b000 | 0xad87 | 0xae00 | 0x2a200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.94 |
.data | 0x436000 | 0x14c34 | 0x11400 | 0x35000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.85 |
.rsrc | 0x44b000 | 0x4e14 | 0x5000 | 0x46400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.49 |
Imports (12)
»
OPENGL32.dll (21)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
wglCreateContext | 0x0 | 0x42b368 | 0x34030 | 0x33230 | 0x159 |
glClearDepth | 0x0 | 0x42b36c | 0x34034 | 0x33234 | 0x13 |
glEnable | 0x0 | 0x42b370 | 0x34038 | 0x33238 | 0x4f |
glClearColor | 0x0 | 0x42b374 | 0x3403c | 0x3323c | 0x12 |
glClear | 0x0 | 0x42b378 | 0x34040 | 0x33240 | 0x10 |
glPushMatrix | 0x0 | 0x42b37c | 0x34044 | 0x33244 | 0xd9 |
glTranslatef | 0x0 | 0x42b380 | 0x34048 | 0x33248 | 0x13c |
glRotatef | 0x0 | 0x42b384 | 0x3404c | 0x3324c | 0xff |
glBegin | 0x0 | 0x42b388 | 0x34050 | 0x33250 | 0xa |
glColor3f | 0x0 | 0x42b38c | 0x34054 | 0x33254 | 0x1b |
glVertex3f | 0x0 | 0x42b390 | 0x34058 | 0x33258 | 0x147 |
glEnd | 0x0 | 0x42b394 | 0x3405c | 0x3325c | 0x51 |
glPopMatrix | 0x0 | 0x42b398 | 0x34060 | 0x33260 | 0xd4 |
glFinish | 0x0 | 0x42b39c | 0x34064 | 0x33264 | 0x60 |
wglGetCurrentDC | 0x0 | 0x42b3a0 | 0x34068 | 0x33268 | 0x15f |
glViewport | 0x0 | 0x42b3a4 | 0x3406c | 0x3326c | 0x156 |
glMatrixMode | 0x0 | 0x42b3a8 | 0x34070 | 0x33270 | 0xb5 |
glLoadIdentity | 0x0 | 0x42b3ac | 0x34074 | 0x33274 | 0xa4 |
wglGetCurrentContext | 0x0 | 0x42b3b0 | 0x34078 | 0x33278 | 0x15e |
wglMakeCurrent | 0x0 | 0x42b3b4 | 0x3407c | 0x3327c | 0x164 |
wglDeleteContext | 0x0 | 0x42b3b8 | 0x34080 | 0x33280 | 0x15b |
GLU32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
gluPerspective | 0x0 | 0x42b128 | 0x33df0 | 0x32ff0 | 0x20 |
KERNEL32.dll (136)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCPInfo | 0x0 | 0x42b130 | 0x33df8 | 0x32ff8 | 0xfc |
GetOEMCP | 0x0 | 0x42b134 | 0x33dfc | 0x32ffc | 0x18b |
FileTimeToSystemTime | 0x0 | 0x42b138 | 0x33e00 | 0x33000 | 0xbc |
FileTimeToLocalFileTime | 0x0 | 0x42b13c | 0x33e04 | 0x33004 | 0xbb |
LocalFileTimeToFileTime | 0x0 | 0x42b140 | 0x33e08 | 0x33008 | 0x250 |
SystemTimeToFileTime | 0x0 | 0x42b144 | 0x33e0c | 0x3300c | 0x34c |
SetErrorMode | 0x0 | 0x42b148 | 0x33e10 | 0x33010 | 0x308 |
HeapAlloc | 0x0 | 0x42b14c | 0x33e14 | 0x33014 | 0x206 |
HeapFree | 0x0 | 0x42b150 | 0x33e18 | 0x33018 | 0x20c |
VirtualProtect | 0x0 | 0x42b154 | 0x33e1c | 0x3301c | 0x379 |
VirtualAlloc | 0x0 | 0x42b158 | 0x33e20 | 0x33020 | 0x373 |
GetSystemInfo | 0x0 | 0x42b15c | 0x33e24 | 0x33024 | 0x1bb |
VirtualQuery | 0x0 | 0x42b160 | 0x33e28 | 0x33028 | 0x37b |
RtlUnwind | 0x0 | 0x42b164 | 0x33e2c | 0x3302c | 0x2ca |
GetStartupInfoA | 0x0 | 0x42b168 | 0x33e30 | 0x33030 | 0x1af |
GetVolumeInformationA | 0x0 | 0x42b16c | 0x33e34 | 0x33034 | 0x1e1 |
ExitProcess | 0x0 | 0x42b170 | 0x33e38 | 0x33038 | 0xaf |
TerminateProcess | 0x0 | 0x42b174 | 0x33e3c | 0x3303c | 0x34f |
HeapReAlloc | 0x0 | 0x42b178 | 0x33e40 | 0x33040 | 0x210 |
HeapSize | 0x0 | 0x42b17c | 0x33e44 | 0x33044 | 0x212 |
HeapDestroy | 0x0 | 0x42b180 | 0x33e48 | 0x33048 | 0x20a |
HeapCreate | 0x0 | 0x42b184 | 0x33e4c | 0x3304c | 0x208 |
VirtualFree | 0x0 | 0x42b188 | 0x33e50 | 0x33050 | 0x376 |
IsBadWritePtr | 0x0 | 0x42b18c | 0x33e54 | 0x33054 | 0x22c |
GetStdHandle | 0x0 | 0x42b190 | 0x33e58 | 0x33058 | 0x1b1 |
UnhandledExceptionFilter | 0x0 | 0x42b194 | 0x33e5c | 0x3305c | 0x360 |
FreeEnvironmentStringsA | 0x0 | 0x42b198 | 0x33e60 | 0x33060 | 0xed |
GetEnvironmentStrings | 0x0 | 0x42b19c | 0x33e64 | 0x33064 | 0x14d |
FreeEnvironmentStringsW | 0x0 | 0x42b1a0 | 0x33e68 | 0x33068 | 0xee |
GetEnvironmentStringsW | 0x0 | 0x42b1a4 | 0x33e6c | 0x3306c | 0x14f |
SetHandleCount | 0x0 | 0x42b1a8 | 0x33e70 | 0x33070 | 0x317 |
GetFileType | 0x0 | 0x42b1ac | 0x33e74 | 0x33074 | 0x15e |
QueryPerformanceCounter | 0x0 | 0x42b1b0 | 0x33e78 | 0x33078 | 0x297 |
GetTickCount | 0x0 | 0x42b1b4 | 0x33e7c | 0x3307c | 0x1d5 |
GetCurrentProcessId | 0x0 | 0x42b1b8 | 0x33e80 | 0x33080 | 0x13b |
GetSystemTimeAsFileTime | 0x0 | 0x42b1bc | 0x33e84 | 0x33084 | 0x1c0 |
SetUnhandledExceptionFilter | 0x0 | 0x42b1c0 | 0x33e88 | 0x33088 | 0x33b |
LCMapStringA | 0x0 | 0x42b1c4 | 0x33e8c | 0x3308c | 0x23a |
LCMapStringW | 0x0 | 0x42b1c8 | 0x33e90 | 0x33090 | 0x23b |
GetStringTypeA | 0x0 | 0x42b1cc | 0x33e94 | 0x33094 | 0x1b2 |
GetStringTypeW | 0x0 | 0x42b1d0 | 0x33e98 | 0x33098 | 0x1b5 |
GetTimeZoneInformation | 0x0 | 0x42b1d4 | 0x33e9c | 0x3309c | 0x1d8 |
IsBadReadPtr | 0x0 | 0x42b1d8 | 0x33ea0 | 0x330a0 | 0x229 |
IsBadCodePtr | 0x0 | 0x42b1dc | 0x33ea4 | 0x330a4 | 0x226 |
SetStdHandle | 0x0 | 0x42b1e0 | 0x33ea8 | 0x330a8 | 0x32a |
SetEnvironmentVariableA | 0x0 | 0x42b1e4 | 0x33eac | 0x330ac | 0x306 |
FindFirstFileA | 0x0 | 0x42b1e8 | 0x33eb0 | 0x330b0 | 0xc9 |
FindClose | 0x0 | 0x42b1ec | 0x33eb4 | 0x330b4 | 0xc5 |
GetCurrentProcess | 0x0 | 0x42b1f0 | 0x33eb8 | 0x330b8 | 0x13a |
DuplicateHandle | 0x0 | 0x42b1f4 | 0x33ebc | 0x330bc | 0x8c |
GetFileSize | 0x0 | 0x42b1f8 | 0x33ec0 | 0x330c0 | 0x15b |
SetEndOfFile | 0x0 | 0x42b1fc | 0x33ec4 | 0x330c4 | 0x303 |
UnlockFile | 0x0 | 0x42b200 | 0x33ec8 | 0x330c8 | 0x361 |
LockFile | 0x0 | 0x42b204 | 0x33ecc | 0x330cc | 0x259 |
FlushFileBuffers | 0x0 | 0x42b208 | 0x33ed0 | 0x330d0 | 0xe5 |
SetFilePointer | 0x0 | 0x42b20c | 0x33ed4 | 0x330d4 | 0x30e |
WriteFile | 0x0 | 0x42b210 | 0x33ed8 | 0x330d8 | 0x394 |
ReadFile | 0x0 | 0x42b214 | 0x33edc | 0x330dc | 0x2a9 |
DeleteFileA | 0x0 | 0x42b218 | 0x33ee0 | 0x330e0 | 0x7c |
MoveFileA | 0x0 | 0x42b21c | 0x33ee4 | 0x330e4 | 0x264 |
TlsFree | 0x0 | 0x42b220 | 0x33ee8 | 0x330e8 | 0x355 |
LocalReAlloc | 0x0 | 0x42b224 | 0x33eec | 0x330ec | 0x255 |
TlsSetValue | 0x0 | 0x42b228 | 0x33ef0 | 0x330f0 | 0x357 |
TlsAlloc | 0x0 | 0x42b22c | 0x33ef4 | 0x330f4 | 0x354 |
TlsGetValue | 0x0 | 0x42b230 | 0x33ef8 | 0x330f8 | 0x356 |
GetShortPathNameA | 0x0 | 0x42b234 | 0x33efc | 0x330fc | 0x1ad |
GlobalHandle | 0x0 | 0x42b238 | 0x33f00 | 0x33100 | 0x1f8 |
GlobalReAlloc | 0x0 | 0x42b23c | 0x33f04 | 0x33104 | 0x1fc |
LeaveCriticalSection | 0x0 | 0x42b240 | 0x33f08 | 0x33108 | 0x247 |
LocalAlloc | 0x0 | 0x42b244 | 0x33f0c | 0x3310c | 0x24e |
InterlockedIncrement | 0x0 | 0x42b248 | 0x33f10 | 0x33110 | 0x222 |
GetCurrentDirectoryA | 0x0 | 0x42b24c | 0x33f14 | 0x33114 | 0x138 |
GetPrivateProfileStringA | 0x0 | 0x42b250 | 0x33f18 | 0x33118 | 0x194 |
WritePrivateProfileStringA | 0x0 | 0x42b254 | 0x33f1c | 0x3311c | 0x399 |
GetPrivateProfileIntA | 0x0 | 0x42b258 | 0x33f20 | 0x33120 | 0x18e |
GlobalFlags | 0x0 | 0x42b25c | 0x33f24 | 0x33124 | 0x1f4 |
InterlockedDecrement | 0x0 | 0x42b260 | 0x33f28 | 0x33128 | 0x21e |
DeleteCriticalSection | 0x0 | 0x42b264 | 0x33f2c | 0x3312c | 0x7a |
InitializeCriticalSection | 0x0 | 0x42b268 | 0x33f30 | 0x33130 | 0x219 |
RaiseException | 0x0 | 0x42b26c | 0x33f34 | 0x33134 | 0x29b |
GetDiskFreeSpaceA | 0x0 | 0x42b270 | 0x33f38 | 0x33138 | 0x145 |
GetFullPathNameA | 0x0 | 0x42b274 | 0x33f3c | 0x3313c | 0x161 |
GetTempFileNameA | 0x0 | 0x42b278 | 0x33f40 | 0x33140 | 0x1c9 |
GetFileTime | 0x0 | 0x42b27c | 0x33f44 | 0x33144 | 0x15d |
SetFileTime | 0x0 | 0x42b280 | 0x33f48 | 0x33148 | 0x312 |
GetFileAttributesA | 0x0 | 0x42b284 | 0x33f4c | 0x3314c | 0x156 |
GlobalGetAtomNameA | 0x0 | 0x42b288 | 0x33f50 | 0x33150 | 0x1f6 |
GlobalFindAtomA | 0x0 | 0x42b28c | 0x33f54 | 0x33154 | 0x1f1 |
lstrcatA | 0x0 | 0x42b290 | 0x33f58 | 0x33158 | 0x3ad |
lstrcmpW | 0x0 | 0x42b294 | 0x33f5c | 0x3315c | 0x3b1 |
CloseHandle | 0x0 | 0x42b298 | 0x33f60 | 0x33160 | 0x2e |
GlobalAddAtomA | 0x0 | 0x42b29c | 0x33f64 | 0x33164 | 0x1ec |
SetLastError | 0x0 | 0x42b2a0 | 0x33f68 | 0x33168 | 0x31b |
SizeofResource | 0x0 | 0x42b2a4 | 0x33f6c | 0x3316c | 0x346 |
MulDiv | 0x0 | 0x42b2a8 | 0x33f70 | 0x33170 | 0x26a |
FormatMessageA | 0x0 | 0x42b2ac | 0x33f74 | 0x33174 | 0xea |
lstrcpynA | 0x0 | 0x42b2b0 | 0x33f78 | 0x33178 | 0x3b9 |
LocalFree | 0x0 | 0x42b2b4 | 0x33f7c | 0x3317c | 0x252 |
GetCurrentThread | 0x0 | 0x42b2b8 | 0x33f80 | 0x33180 | 0x13d |
GetCurrentThreadId | 0x0 | 0x42b2bc | 0x33f84 | 0x33184 | 0x13e |
GlobalAlloc | 0x0 | 0x42b2c0 | 0x33f88 | 0x33188 | 0x1ee |
FreeLibrary | 0x0 | 0x42b2c4 | 0x33f8c | 0x3318c | 0xef |
GlobalDeleteAtom | 0x0 | 0x42b2c8 | 0x33f90 | 0x33190 | 0x1f0 |
lstrcmpA | 0x0 | 0x42b2cc | 0x33f94 | 0x33194 | 0x3b0 |
GetModuleFileNameA | 0x0 | 0x42b2d0 | 0x33f98 | 0x33198 | 0x175 |
GetModuleHandleA | 0x0 | 0x42b2d4 | 0x33f9c | 0x3319c | 0x177 |
GetProcAddress | 0x0 | 0x42b2d8 | 0x33fa0 | 0x331a0 | 0x198 |
ConvertDefaultLocale | 0x0 | 0x42b2dc | 0x33fa4 | 0x331a4 | 0x39 |
EnumResourceLanguagesA | 0x0 | 0x42b2e0 | 0x33fa8 | 0x331a8 | 0x9a |
lstrcpyA | 0x0 | 0x42b2e4 | 0x33fac | 0x331ac | 0x3b6 |
LoadLibraryA | 0x0 | 0x42b2e8 | 0x33fb0 | 0x331b0 | 0x248 |
GlobalLock | 0x0 | 0x42b2ec | 0x33fb4 | 0x331b4 | 0x1f9 |
GlobalUnlock | 0x0 | 0x42b2f0 | 0x33fb8 | 0x331b8 | 0x200 |
GlobalFree | 0x0 | 0x42b2f4 | 0x33fbc | 0x331bc | 0x1f5 |
FindResourceA | 0x0 | 0x42b2f8 | 0x33fc0 | 0x331c0 | 0xda |
LoadResource | 0x0 | 0x42b2fc | 0x33fc4 | 0x331c4 | 0x24d |
LockResource | 0x0 | 0x42b300 | 0x33fc8 | 0x331c8 | 0x25b |
FreeResource | 0x0 | 0x42b304 | 0x33fcc | 0x331cc | 0xf1 |
Sleep | 0x0 | 0x42b308 | 0x33fd0 | 0x331d0 | 0x347 |
GetStringTypeExA | 0x0 | 0x42b30c | 0x33fd4 | 0x331d4 | 0x1b3 |
CompareStringW | 0x0 | 0x42b310 | 0x33fd8 | 0x331d8 | 0x35 |
CompareStringA | 0x0 | 0x42b314 | 0x33fdc | 0x331dc | 0x34 |
lstrlenA | 0x0 | 0x42b318 | 0x33fe0 | 0x331e0 | 0x3bc |
lstrcmpiA | 0x0 | 0x42b31c | 0x33fe4 | 0x331e4 | 0x3b3 |
GetVersion | 0x0 | 0x42b320 | 0x33fe8 | 0x331e8 | 0x1de |
GetLastError | 0x0 | 0x42b324 | 0x33fec | 0x331ec | 0x169 |
WideCharToMultiByte | 0x0 | 0x42b328 | 0x33ff0 | 0x331f0 | 0x387 |
MultiByteToWideChar | 0x0 | 0x42b32c | 0x33ff4 | 0x331f4 | 0x26b |
GetVersionExA | 0x0 | 0x42b330 | 0x33ff8 | 0x331f8 | 0x1df |
GetThreadLocale | 0x0 | 0x42b334 | 0x33ffc | 0x331fc | 0x1d0 |
GetLocaleInfoA | 0x0 | 0x42b338 | 0x34000 | 0x33200 | 0x16c |
GetACP | 0x0 | 0x42b33c | 0x34004 | 0x33204 | 0xf5 |
InterlockedExchange | 0x0 | 0x42b340 | 0x34008 | 0x33208 | 0x21f |
EnterCriticalSection | 0x0 | 0x42b344 | 0x3400c | 0x3320c | 0x8f |
CreateFileA | 0x0 | 0x42b348 | 0x34010 | 0x33210 | 0x4d |
GetCommandLineA | 0x0 | 0x42b34c | 0x34014 | 0x33214 | 0x108 |
USER32.dll (143)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InflateRect | 0x0 | 0x42b3e8 | 0x340b0 | 0x332b0 | 0x18a |
DestroyIcon | 0x0 | 0x42b3ec | 0x340b4 | 0x332b4 | 0x96 |
LoadCursorA | 0x0 | 0x42b3f0 | 0x340b8 | 0x332b8 | 0x1b9 |
GetSysColorBrush | 0x0 | 0x42b3f4 | 0x340bc | 0x332bc | 0x15b |
SetParent | 0x0 | 0x42b3f8 | 0x340c0 | 0x332c0 | 0x266 |
GetSystemMenu | 0x0 | 0x42b3fc | 0x340c4 | 0x332c4 | 0x15c |
DeleteMenu | 0x0 | 0x42b400 | 0x340c8 | 0x332c8 | 0x91 |
IsRectEmpty | 0x0 | 0x42b404 | 0x340cc | 0x332cc | 0x1a9 |
WindowFromPoint | 0x0 | 0x42b408 | 0x340d0 | 0x332d0 | 0x2d3 |
SetRect | 0x0 | 0x42b40c | 0x340d4 | 0x332d4 | 0x26c |
EndPaint | 0x0 | 0x42b410 | 0x340d8 | 0x332d8 | 0xc8 |
BeginPaint | 0x0 | 0x42b414 | 0x340dc | 0x332dc | 0xd |
GetWindowDC | 0x0 | 0x42b418 | 0x340e0 | 0x332e0 | 0x16c |
ReleaseDC | 0x0 | 0x42b41c | 0x340e4 | 0x332e4 | 0x22a |
GetDC | 0x0 | 0x42b420 | 0x340e8 | 0x332e8 | 0x10c |
ClientToScreen | 0x0 | 0x42b424 | 0x340ec | 0x332ec | 0x40 |
GrayStringA | 0x0 | 0x42b428 | 0x340f0 | 0x332f0 | 0x17d |
DrawTextExA | 0x0 | 0x42b42c | 0x340f4 | 0x332f4 | 0xbd |
DrawTextA | 0x0 | 0x42b430 | 0x340f8 | 0x332f8 | 0xbc |
TabbedTextOutA | 0x0 | 0x42b434 | 0x340fc | 0x332fc | 0x29b |
FillRect | 0x0 | 0x42b438 | 0x34100 | 0x33300 | 0xe2 |
wsprintfA | 0x0 | 0x42b43c | 0x34104 | 0x33304 | 0x2d6 |
LoadMenuA | 0x0 | 0x42b440 | 0x34108 | 0x33308 | 0x1c5 |
DestroyMenu | 0x0 | 0x42b444 | 0x3410c | 0x3330c | 0x97 |
UnpackDDElParam | 0x0 | 0x42b448 | 0x34110 | 0x33310 | 0x2b2 |
ReuseDDElParam | 0x0 | 0x42b44c | 0x34114 | 0x33314 | 0x230 |
ReleaseCapture | 0x0 | 0x42b450 | 0x34118 | 0x33318 | 0x229 |
LoadAcceleratorsA | 0x0 | 0x42b454 | 0x3411c | 0x3331c | 0x1b5 |
InsertMenuItemA | 0x0 | 0x42b458 | 0x34120 | 0x33320 | 0x18e |
CreatePopupMenu | 0x0 | 0x42b45c | 0x34124 | 0x33324 | 0x5e |
SetRectEmpty | 0x0 | 0x42b460 | 0x34128 | 0x33328 | 0x26d |
BringWindowToTop | 0x0 | 0x42b464 | 0x3412c | 0x3332c | 0xf |
SetMenu | 0x0 | 0x42b468 | 0x34130 | 0x33330 | 0x25d |
TranslateAcceleratorA | 0x0 | 0x42b46c | 0x34134 | 0x33334 | 0x2a7 |
ShowWindow | 0x0 | 0x42b470 | 0x34138 | 0x33338 | 0x292 |
SetWindowTextA | 0x0 | 0x42b474 | 0x3413c | 0x3333c | 0x286 |
IsDialogMessageA | 0x0 | 0x42b478 | 0x34140 | 0x33340 | 0x1a1 |
RegisterWindowMessageA | 0x0 | 0x42b47c | 0x34144 | 0x33344 | 0x227 |
WinHelpA | 0x0 | 0x42b480 | 0x34148 | 0x33348 | 0x2d0 |
GetCapture | 0x0 | 0x42b484 | 0x3414c | 0x3334c | 0xf3 |
CreateWindowExA | 0x0 | 0x42b488 | 0x34150 | 0x33350 | 0x60 |
GetClassLongA | 0x0 | 0x42b48c | 0x34154 | 0x33354 | 0xfa |
GetClassInfoExA | 0x0 | 0x42b490 | 0x34158 | 0x33358 | 0xf7 |
GetClassNameA | 0x0 | 0x42b494 | 0x3415c | 0x3335c | 0xfc |
SetPropA | 0x0 | 0x42b498 | 0x34160 | 0x33360 | 0x26a |
GetPropA | 0x0 | 0x42b49c | 0x34164 | 0x33364 | 0x14a |
RemovePropA | 0x0 | 0x42b4a0 | 0x34168 | 0x33368 | 0x22c |
SendDlgItemMessageA | 0x0 | 0x42b4a4 | 0x3416c | 0x3336c | 0x236 |
SetFocus | 0x0 | 0x42b4a8 | 0x34170 | 0x33370 | 0x256 |
IsChild | 0x0 | 0x42b4ac | 0x34174 | 0x33374 | 0x19e |
GetWindowTextLengthA | 0x0 | 0x42b4b0 | 0x34178 | 0x33378 | 0x178 |
GetWindowTextA | 0x0 | 0x42b4b4 | 0x3417c | 0x3337c | 0x177 |
GetForegroundWindow | 0x0 | 0x42b4b8 | 0x34180 | 0x33380 | 0x117 |
BeginDeferWindowPos | 0x0 | 0x42b4bc | 0x34184 | 0x33384 | 0xc |
EndDeferWindowPos | 0x0 | 0x42b4c0 | 0x34188 | 0x33388 | 0xc5 |
GetTopWindow | 0x0 | 0x42b4c4 | 0x3418c | 0x3338c | 0x163 |
GetMessageTime | 0x0 | 0x42b4c8 | 0x34190 | 0x33390 | 0x13d |
GetMessagePos | 0x0 | 0x42b4cc | 0x34194 | 0x33394 | 0x13c |
GetMenuItemInfoA | 0x0 | 0x42b4d0 | 0x34198 | 0x33398 | 0x134 |
MapWindowPoints | 0x0 | 0x42b4d4 | 0x3419c | 0x3339c | 0x1d9 |
TrackPopupMenu | 0x0 | 0x42b4d8 | 0x341a0 | 0x333a0 | 0x2a4 |
SetForegroundWindow | 0x0 | 0x42b4dc | 0x341a4 | 0x333a4 | 0x257 |
UpdateWindow | 0x0 | 0x42b4e0 | 0x341a8 | 0x333a8 | 0x2bb |
GetMenu | 0x0 | 0x42b4e4 | 0x341ac | 0x333ac | 0x12c |
GetSysColor | 0x0 | 0x42b4e8 | 0x341b0 | 0x333b0 | 0x15a |
AdjustWindowRectEx | 0x0 | 0x42b4ec | 0x341b4 | 0x333b4 | 0x2 |
ScreenToClient | 0x0 | 0x42b4f0 | 0x341b8 | 0x333b8 | 0x231 |
EqualRect | 0x0 | 0x42b4f4 | 0x341bc | 0x333bc | 0xdf |
DeferWindowPos | 0x0 | 0x42b4f8 | 0x341c0 | 0x333c0 | 0x90 |
GetClassInfoA | 0x0 | 0x42b4fc | 0x341c4 | 0x333c4 | 0xf6 |
RegisterClassA | 0x0 | 0x42b500 | 0x341c8 | 0x333c8 | 0x216 |
UnregisterClassA | 0x0 | 0x42b504 | 0x341cc | 0x333cc | 0x2b3 |
GetDlgCtrlID | 0x0 | 0x42b508 | 0x341d0 | 0x333d0 | 0x110 |
DefWindowProcA | 0x0 | 0x42b50c | 0x341d4 | 0x333d4 | 0x8e |
CallWindowProcA | 0x0 | 0x42b510 | 0x341d8 | 0x333d8 | 0x1b |
SetWindowLongA | 0x0 | 0x42b514 | 0x341dc | 0x333dc | 0x280 |
SetWindowPos | 0x0 | 0x42b518 | 0x341e0 | 0x333e0 | 0x283 |
UnhookWindowsHookEx | 0x0 | 0x42b51c | 0x341e4 | 0x333e4 | 0x2ae |
CharUpperA | 0x0 | 0x42b520 | 0x341e8 | 0x333e8 | 0x34 |
EnableWindow | 0x0 | 0x42b524 | 0x341ec | 0x333ec | 0xc4 |
GetClientRect | 0x0 | 0x42b528 | 0x341f0 | 0x333f0 | 0xff |
RedrawWindow | 0x0 | 0x42b52c | 0x341f4 | 0x333f4 | 0x215 |
SetTimer | 0x0 | 0x42b530 | 0x341f8 | 0x333f8 | 0x27a |
KillTimer | 0x0 | 0x42b534 | 0x341fc | 0x333fc | 0x1b4 |
LoadStringW | 0x0 | 0x42b538 | 0x34200 | 0x33400 | 0x1cb |
PeekMessageA | 0x0 | 0x42b53c | 0x34204 | 0x33404 | 0x1ff |
InvalidateRect | 0x0 | 0x42b540 | 0x34208 | 0x33408 | 0x193 |
EndDialog | 0x0 | 0x42b544 | 0x3420c | 0x3340c | 0xc6 |
OffsetRect | 0x0 | 0x42b548 | 0x34210 | 0x33410 | 0x1f4 |
IntersectRect | 0x0 | 0x42b54c | 0x34214 | 0x33414 | 0x192 |
SystemParametersInfoA | 0x0 | 0x42b550 | 0x34218 | 0x33418 | 0x299 |
IsIconic | 0x0 | 0x42b554 | 0x3421c | 0x3341c | 0x1a6 |
GetWindowPlacement | 0x0 | 0x42b558 | 0x34220 | 0x33420 | 0x173 |
GetWindowRect | 0x0 | 0x42b55c | 0x34224 | 0x33424 | 0x174 |
CopyRect | 0x0 | 0x42b560 | 0x34228 | 0x33428 | 0x4a |
PtInRect | 0x0 | 0x42b564 | 0x3422c | 0x3342c | 0x20b |
GetWindow | 0x0 | 0x42b568 | 0x34230 | 0x33430 | 0x16a |
SetMenuItemBitmaps | 0x0 | 0x42b56c | 0x34234 | 0x33434 | 0x261 |
GetFocus | 0x0 | 0x42b570 | 0x34238 | 0x33438 | 0x116 |
ModifyMenuA | 0x0 | 0x42b574 | 0x3423c | 0x3343c | 0x1e6 |
EnableMenuItem | 0x0 | 0x42b578 | 0x34240 | 0x33440 | 0xc2 |
CheckMenuItem | 0x0 | 0x42b57c | 0x34244 | 0x33444 | 0x39 |
GetMenuCheckMarkDimensions | 0x0 | 0x42b580 | 0x34248 | 0x33448 | 0x12e |
SetCapture | 0x0 | 0x42b584 | 0x3424c | 0x3344c | 0x244 |
LoadBitmapA | 0x0 | 0x42b588 | 0x34250 | 0x33450 | 0x1b7 |
SetWindowsHookExA | 0x0 | 0x42b58c | 0x34254 | 0x33454 | 0x28a |
CallNextHookEx | 0x0 | 0x42b590 | 0x34258 | 0x33458 | 0x1a |
GetMessageA | 0x0 | 0x42b594 | 0x3425c | 0x3345c | 0x13a |
TranslateMessage | 0x0 | 0x42b598 | 0x34260 | 0x33460 | 0x2aa |
DispatchMessageA | 0x0 | 0x42b59c | 0x34264 | 0x33464 | 0xa1 |
IsWindowVisible | 0x0 | 0x42b5a0 | 0x34268 | 0x33468 | 0x1b1 |
GetKeyState | 0x0 | 0x42b5a4 | 0x3426c | 0x3346c | 0x121 |
GetCursorPos | 0x0 | 0x42b5a8 | 0x34270 | 0x33470 | 0x10b |
ValidateRect | 0x0 | 0x42b5ac | 0x34274 | 0x33474 | 0x2c3 |
MessageBoxA | 0x0 | 0x42b5b0 | 0x34278 | 0x33478 | 0x1de |
GetLastActivePopup | 0x0 | 0x42b5b4 | 0x3427c | 0x3347c | 0x128 |
LockWindowUpdate | 0x0 | 0x42b5b8 | 0x34280 | 0x33480 | 0x1ce |
GetDCEx | 0x0 | 0x42b5bc | 0x34284 | 0x33484 | 0x10d |
LoadIconA | 0x0 | 0x42b5c0 | 0x34288 | 0x33488 | 0x1bd |
SendMessageA | 0x0 | 0x42b5c4 | 0x3428c | 0x3348c | 0x23b |
GetNextDlgTabItem | 0x0 | 0x42b5c8 | 0x34290 | 0x33490 | 0x143 |
GetParent | 0x0 | 0x42b5cc | 0x34294 | 0x33494 | 0x145 |
IsWindowEnabled | 0x0 | 0x42b5d0 | 0x34298 | 0x33498 | 0x1ae |
GetDlgItem | 0x0 | 0x42b5d4 | 0x3429c | 0x3349c | 0x111 |
GetWindowLongA | 0x0 | 0x42b5d8 | 0x342a0 | 0x334a0 | 0x16e |
IsWindow | 0x0 | 0x42b5dc | 0x342a4 | 0x334a4 | 0x1ad |
DestroyWindow | 0x0 | 0x42b5e0 | 0x342a8 | 0x334a8 | 0x99 |
CreateDialogIndirectParamA | 0x0 | 0x42b5e4 | 0x342ac | 0x334ac | 0x52 |
GetSystemMetrics | 0x0 | 0x42b5e8 | 0x342b0 | 0x334b0 | 0x15d |
SetActiveWindow | 0x0 | 0x42b5ec | 0x342b4 | 0x334b4 | 0x243 |
GetActiveWindow | 0x0 | 0x42b5f0 | 0x342b8 | 0x334b8 | 0xeb |
GetDesktopWindow | 0x0 | 0x42b5f4 | 0x342bc | 0x334bc | 0x10e |
PostQuitMessage | 0x0 | 0x42b5f8 | 0x342c0 | 0x334c0 | 0x203 |
PostMessageA | 0x0 | 0x42b5fc | 0x342c4 | 0x334c4 | 0x201 |
GetSubMenu | 0x0 | 0x42b600 | 0x342c8 | 0x334c8 | 0x159 |
GetMenuItemCount | 0x0 | 0x42b604 | 0x342cc | 0x334cc | 0x132 |
ShowOwnedPopups | 0x0 | 0x42b608 | 0x342d0 | 0x334d0 | 0x28f |
SetCursor | 0x0 | 0x42b60c | 0x342d4 | 0x334d4 | 0x24d |
GetMenuState | 0x0 | 0x42b610 | 0x342d8 | 0x334d8 | 0x137 |
GetMenuStringA | 0x0 | 0x42b614 | 0x342dc | 0x334dc | 0x138 |
AppendMenuA | 0x0 | 0x42b618 | 0x342e0 | 0x334e0 | 0x8 |
GetMenuItemID | 0x0 | 0x42b61c | 0x342e4 | 0x334e4 | 0x133 |
InsertMenuA | 0x0 | 0x42b620 | 0x342e8 | 0x334e8 | 0x18d |
GDI32.dll (53)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreatePatternBrush | 0x0 | 0x42b050 | 0x33d18 | 0x32f18 | 0x46 |
GetStockObject | 0x0 | 0x42b054 | 0x33d1c | 0x32f1c | 0x1a5 |
SelectPalette | 0x0 | 0x42b058 | 0x33d20 | 0x32f20 | 0x20f |
CreateSolidBrush | 0x0 | 0x42b05c | 0x33d24 | 0x32f24 | 0x50 |
StretchDIBits | 0x0 | 0x42b060 | 0x33d28 | 0x32f28 | 0x24a |
GetCharWidthA | 0x0 | 0x42b064 | 0x33d2c | 0x32f2c | 0x158 |
DeleteDC | 0x0 | 0x42b068 | 0x33d30 | 0x32f30 | 0x8c |
GetBkColor | 0x0 | 0x42b06c | 0x33d34 | 0x32f34 | 0x14c |
GetTextExtentPoint32A | 0x0 | 0x42b070 | 0x33d38 | 0x32f38 | 0x1b4 |
CreateFontIndirectA | 0x0 | 0x42b074 | 0x33d3c | 0x32f3c | 0x3a |
CreateRectRgnIndirect | 0x0 | 0x42b078 | 0x33d40 | 0x32f40 | 0x4c |
PatBlt | 0x0 | 0x42b07c | 0x33d44 | 0x32f44 | 0x1dd |
SetRectRgn | 0x0 | 0x42b080 | 0x33d48 | 0x32f48 | 0x236 |
CombineRgn | 0x0 | 0x42b084 | 0x33d4c | 0x32f4c | 0x21 |
SetBkMode | 0x0 | 0x42b088 | 0x33d50 | 0x32f50 | 0x216 |
RestoreDC | 0x0 | 0x42b08c | 0x33d54 | 0x32f54 | 0x200 |
SaveDC | 0x0 | 0x42b090 | 0x33d58 | 0x32f58 | 0x207 |
CreateCompatibleDC | 0x0 | 0x42b094 | 0x33d5c | 0x32f5c | 0x2d |
CreateCompatibleBitmap | 0x0 | 0x42b098 | 0x33d60 | 0x32f60 | 0x2c |
GetObjectA | 0x0 | 0x42b09c | 0x33d64 | 0x32f64 | 0x195 |
SetBkColor | 0x0 | 0x42b0a0 | 0x33d68 | 0x32f68 | 0x215 |
SetTextColor | 0x0 | 0x42b0a4 | 0x33d6c | 0x32f6c | 0x23c |
GetClipBox | 0x0 | 0x42b0a8 | 0x33d70 | 0x32f70 | 0x160 |
CreateBitmap | 0x0 | 0x42b0ac | 0x33d74 | 0x32f74 | 0x27 |
GetDeviceCaps | 0x0 | 0x42b0b0 | 0x33d78 | 0x32f78 | 0x16b |
SwapBuffers | 0x0 | 0x42b0b4 | 0x33d7c | 0x32f7c | 0x24d |
GetPixelFormat | 0x0 | 0x42b0b8 | 0x33d80 | 0x32f80 | 0x19d |
DescribePixelFormat | 0x0 | 0x42b0bc | 0x33d84 | 0x32f84 | 0x90 |
ChoosePixelFormat | 0x0 | 0x42b0c0 | 0x33d88 | 0x32f88 | 0x18 |
SetPixelFormat | 0x0 | 0x42b0c4 | 0x33d8c | 0x32f8c | 0x232 |
RealizePalette | 0x0 | 0x42b0c8 | 0x33d90 | 0x32f90 | 0x1f3 |
CreateFontA | 0x0 | 0x42b0cc | 0x33d94 | 0x32f94 | 0x39 |
CreatePalette | 0x0 | 0x42b0d0 | 0x33d98 | 0x32f98 | 0x45 |
ScaleWindowExtEx | 0x0 | 0x42b0d4 | 0x33d9c | 0x32f9c | 0x209 |
SetWindowExtEx | 0x0 | 0x42b0d8 | 0x33da0 | 0x32fa0 | 0x242 |
ScaleViewportExtEx | 0x0 | 0x42b0dc | 0x33da4 | 0x32fa4 | 0x208 |
SetViewportExtEx | 0x0 | 0x42b0e0 | 0x33da8 | 0x32fa8 | 0x23e |
OffsetViewportOrgEx | 0x0 | 0x42b0e4 | 0x33dac | 0x32fac | 0x1d5 |
SetViewportOrgEx | 0x0 | 0x42b0e8 | 0x33db0 | 0x32fb0 | 0x23f |
SelectObject | 0x0 | 0x42b0ec | 0x33db4 | 0x32fb4 | 0x20e |
Escape | 0x0 | 0x42b0f0 | 0x33db8 | 0x32fb8 | 0xd4 |
ExtTextOutA | 0x0 | 0x42b0f4 | 0x33dbc | 0x32fbc | 0xdd |
TextOutA | 0x0 | 0x42b0f8 | 0x33dc0 | 0x32fc0 | 0x24e |
RectVisible | 0x0 | 0x42b0fc | 0x33dc4 | 0x32fc4 | 0x1f5 |
PtVisible | 0x0 | 0x42b100 | 0x33dc8 | 0x32fc8 | 0x1f1 |
GetPixel | 0x0 | 0x42b104 | 0x33dcc | 0x32fcc | 0x19c |
BitBlt | 0x0 | 0x42b108 | 0x33dd0 | 0x32fd0 | 0x12 |
CreateRectRgn | 0x0 | 0x42b10c | 0x33dd4 | 0x32fd4 | 0x4b |
SelectClipRgn | 0x0 | 0x42b110 | 0x33dd8 | 0x32fd8 | 0x20c |
DeleteObject | 0x0 | 0x42b114 | 0x33ddc | 0x32fdc | 0x8f |
IntersectClipRect | 0x0 | 0x42b118 | 0x33de0 | 0x32fe0 | 0x1c7 |
ExcludeClipRect | 0x0 | 0x42b11c | 0x33de4 | 0x32fe4 | 0xd7 |
SetMapMode | 0x0 | 0x42b120 | 0x33de8 | 0x32fe8 | 0x22b |
comdlg32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetOpenFileNameA | 0x0 | 0x42b638 | 0x34300 | 0x33500 | 0x9 |
GetFileTitleA | 0x0 | 0x42b63c | 0x34304 | 0x33504 | 0x7 |
GetSaveFileNameA | 0x0 | 0x42b640 | 0x34308 | 0x33508 | 0xb |
WINSPOOL.DRV (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
OpenPrinterA | 0x0 | 0x42b628 | 0x342f0 | 0x334f0 | 0x7d |
DocumentPropertiesA | 0x0 | 0x42b62c | 0x342f4 | 0x334f4 | 0x46 |
ClosePrinter | 0x0 | 0x42b630 | 0x342f8 | 0x334f8 | 0x1b |
ADVAPI32.dll (14)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegDeleteValueA | 0x0 | 0x42b000 | 0x33cc8 | 0x32ec8 | 0x1d2 |
RegQueryValueExA | 0x0 | 0x42b004 | 0x33ccc | 0x32ecc | 0x1ec |
RegOpenKeyExA | 0x0 | 0x42b008 | 0x33cd0 | 0x32ed0 | 0x1e2 |
RegSetValueA | 0x0 | 0x42b00c | 0x33cd4 | 0x32ed4 | 0x1f8 |
RegOpenKeyA | 0x0 | 0x42b010 | 0x33cd8 | 0x32ed8 | 0x1e1 |
RegDeleteKeyA | 0x0 | 0x42b014 | 0x33cdc | 0x32edc | 0x1d0 |
RegEnumKeyA | 0x0 | 0x42b018 | 0x33ce0 | 0x32ee0 | 0x1d5 |
RegQueryValueA | 0x0 | 0x42b01c | 0x33ce4 | 0x32ee4 | 0x1eb |
SetFileSecurityA | 0x0 | 0x42b020 | 0x33ce8 | 0x32ee8 | 0x223 |
GetFileSecurityA | 0x0 | 0x42b024 | 0x33cec | 0x32eec | 0xef |
RegCreateKeyExA | 0x0 | 0x42b028 | 0x33cf0 | 0x32ef0 | 0x1cd |
RegCreateKeyA | 0x0 | 0x42b02c | 0x33cf4 | 0x32ef4 | 0x1cc |
RegCloseKey | 0x0 | 0x42b030 | 0x33cf8 | 0x32ef8 | 0x1c9 |
RegSetValueExA | 0x0 | 0x42b034 | 0x33cfc | 0x32efc | 0x1f9 |
SHELL32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DragQueryFileA | 0x0 | 0x42b3c0 | 0x34088 | 0x33288 | 0x21 |
ExtractIconA | 0x0 | 0x42b3c4 | 0x3408c | 0x3328c | 0x2b |
SHGetFileInfoA | 0x0 | 0x42b3c8 | 0x34090 | 0x33290 | 0xac |
DragFinish | 0x0 | 0x42b3cc | 0x34094 | 0x33294 | 0x1f |
COMCTL32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x11 | 0x42b03c | 0x33d04 | 0x32f04 | - |
ImageList_Draw | 0x0 | 0x42b040 | 0x33d08 | 0x32f08 | 0x3d |
ImageList_GetImageInfo | 0x0 | 0x42b044 | 0x33d0c | 0x32f0c | 0x48 |
ImageList_Destroy | 0x0 | 0x42b048 | 0x33d10 | 0x32f10 | 0x38 |
SHLWAPI.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathFindFileNameA | 0x0 | 0x42b3d4 | 0x3409c | 0x3329c | 0x2b |
PathStripToRootA | 0x0 | 0x42b3d8 | 0x340a0 | 0x332a0 | 0x77 |
PathFindExtensionA | 0x0 | 0x42b3dc | 0x340a4 | 0x332a4 | 0x29 |
PathIsUNCA | 0x0 | 0x42b3e0 | 0x340a8 | 0x332a8 | 0x4f |
OLEAUT32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VariantClear | 0x9 | 0x42b354 | 0x3401c | 0x3321c | - |
VariantChangeType | 0xc | 0x42b358 | 0x34020 | 0x33220 | - |
VariantInit | 0x8 | 0x42b35c | 0x34024 | 0x33224 | - |
SysAllocStringLen | 0x4 | 0x42b360 | 0x34028 | 0x33228 | - |
Exports (1)
»
Api name | EAT Address | Ordinal |
---|---|---|
LayvXBcOppdgzCgnncA | 0x16f0 | 0x1 |
Memory Dumps (11)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
cube.exe.exe | 1 | 0x00400000 | 0x0044FFFF | Relevant Image |
![]() |
32-bit | 0x00406FD8 |
![]() |
![]() |
...
|
buffer | 1 | 0x004A0000 | 0x004AFFFF | First Execution |
![]() |
32-bit | 0x004A0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x005D0000 | 0x005E0FFF | First Execution |
![]() |
32-bit | 0x005D1900 |
![]() |
![]() |
...
|
buffer | 1 | 0x004B0000 | 0x004BEFFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 2 | 0x00400000 | 0x0040EFFF | First Execution |
![]() |
32-bit | 0x00402610 |
![]() |
![]() |
...
|
cube.exe.exe | 1 | 0x00400000 | 0x0044FFFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 2 | 0x00400000 | 0x0040EFFF | Content Changed |
![]() |
32-bit | 0x00403000 |
![]() |
![]() |
...
|
buffer | 2 | 0x00400000 | 0x0040EFFF | Content Changed |
![]() |
32-bit | 0x00404000 |
![]() |
![]() |
...
|
buffer | 2 | 0x00400000 | 0x0040EFFF | Content Changed |
![]() |
32-bit | 0x00408BD0 |
![]() |
![]() |
...
|
buffer | 2 | 0x00400000 | 0x0040EFFF | Content Changed |
![]() |
32-bit | 0x00408B9E |
![]() |
![]() |
...
|
buffer | 2 | 0x00400000 | 0x0040EFFF | Content Changed |
![]() |
32-bit | 0x00408A95 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.32727036 |
Malicious
|
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\LocalizedData.xml.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\SetupComplete.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.xml.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.xml.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\LocalizedData.xml.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\LocalizedData.xml.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\LocalizedData.xml.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\eula.rtf.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\LocalizedData.xml.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\LocalizedData.xml.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\LocalizedData.xml.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\eula.rtf.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\eula.rtf.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DHtmlHeader.html | Modified File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\eula.rtf.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate1.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate2.ico.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate4.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Print.ico.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate6.ico.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate7.ico.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate8.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\LocalizedData.xml.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\stop.ico.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqMet.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\warn.ico.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\LocalizedData.xml.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\RGB9RAST_x64.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Setup.ico.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd | Modified File | Binary |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Strings.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x86.msi.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x64.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\RGB9Rast_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Internet Explorer.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Key Management Service.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-International%4Operational.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Operational.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Known Folders API Service.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Store%4Operational.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx | Modified File | Binary |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Windows PowerShell.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\ClickToRun\0D0D4EEB-DC03-4B3F-88DF-959FE1EDE5F4\en-us.16\MasterDescriptor.en-us.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\ClickToRun\0D0D4EEB-DC03-4B3F-88DF-959FE1EDE5F4\en-us.16\s641033.hash | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\ClickToRun\0D0D4EEB-DC03-4B3F-88DF-959FE1EDE5F4\x-none.16\MasterDescriptor.x-none.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\ClickToRun\0D0D4EEB-DC03-4B3F-88DF-959FE1EDE5F4\x-none.16\s640.hash.CONTI | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\ClickToRun\201EB7DF-C721-4B8B-9C81-A09DE7F931E6\en-us.16\HOW_TO_DECRYPT.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\preoobe.cmd | Modified File | Batch |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1028\eula.rtf.CONTI | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf.CONTI | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.xml.CONTI | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1041\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\LocalizedData.xml.CONTI | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1043\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf.CONTI | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1046\LocalizedData.xml.CONTI | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1049\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1053\LocalizedData.xml.CONTI | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\DisplayIcon.ico.CONTI | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Extended\Parameterinfo.xml.CONTI | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate3.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Save.ico.CONTI | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Client\Parameterinfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate5.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\UiInfo.xml.CONTI | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x64.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx.CONTI | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx.CONTI | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx.CONTI | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx.CONTI | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx.CONTI | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx.CONTI | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx.CONTI | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx | Modified File | Stream |
Not Queried
|
...
|
»