VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Trojan
|
Threat Names: |
Generic.Ransom.Ouroboros.86DDF22C
Generic.Ransom.Ouroboros.322CED9C
Win32.Trojan.Ouroboros
|
Mr.TeslaBrain@protonmail.com - Copy.exe.txt.exe
Windows Exe (x86-32)
Created at 2020-01-30T16:21:00
Remarks
(0x0200001E): The maximum size of extracted files was exceeded. Some files may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\Mr.TeslaBrain@protonmail.com - Copy.exe.txt.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2020-01-30 14:52 (UTC+1) |
Last Seen | 2020-01-30 14:52 (UTC+1) |
Names | Win32.Trojan.Ouroboros |
Families | Ouroboros |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x46a353 |
Size Of Code | 0xb4c00 |
Size Of Initialized Data | 0x44400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-01-01 17:30:49+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xb4b98 | 0xb4c00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.66 |
.rdata | 0x4b6000 | 0x2e974 | 0x2ea00 | 0xb5000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.99 |
.data | 0x4e5000 | 0x9630 | 0x6e00 | 0xe3a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.98 |
.rsrc | 0x4ef000 | 0x1e0 | 0x200 | 0xea800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.72 |
.reloc | 0x4f0000 | 0xbe38 | 0xc000 | 0xeaa00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.52 |
Imports (3)
»
KERNEL32.dll (137)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FindClose | 0x0 | 0x4b6010 | 0xe3c34 | 0xe2c34 | 0x12e |
CloseHandle | 0x0 | 0x4b6014 | 0xe3c38 | 0xe2c38 | 0x52 |
lstrcmpW | 0x0 | 0x4b6018 | 0xe3c3c | 0xe2c3c | 0x542 |
CreateProcessA | 0x0 | 0x4b601c | 0xe3c40 | 0xe2c40 | 0xa4 |
GetDriveTypeA | 0x0 | 0x4b6020 | 0xe3c44 | 0xe2c44 | 0x1d2 |
FindFirstFileW | 0x0 | 0x4b6024 | 0xe3c48 | 0xe2c48 | 0x139 |
FindNextFileW | 0x0 | 0x4b6028 | 0xe3c4c | 0xe2c4c | 0x145 |
FreeConsole | 0x0 | 0x4b602c | 0xe3c50 | 0xe2c50 | 0x15f |
GetLogicalDrives | 0x0 | 0x4b6030 | 0xe3c54 | 0xe2c54 | 0x209 |
Process32First | 0x0 | 0x4b6034 | 0xe3c58 | 0xe2c58 | 0x395 |
Process32Next | 0x0 | 0x4b6038 | 0xe3c5c | 0xe2c5c | 0x397 |
GetLastError | 0x0 | 0x4b603c | 0xe3c60 | 0xe2c60 | 0x202 |
SetLastError | 0x0 | 0x4b6040 | 0xe3c64 | 0xe2c64 | 0x473 |
QueryPerformanceCounter | 0x0 | 0x4b6044 | 0xe3c68 | 0xe2c68 | 0x3a7 |
QueryPerformanceFrequency | 0x0 | 0x4b6048 | 0xe3c6c | 0xe2c6c | 0x3a8 |
GetCurrentThread | 0x0 | 0x4b604c | 0xe3c70 | 0xe2c70 | 0x1c4 |
GetThreadTimes | 0x0 | 0x4b6050 | 0xe3c74 | 0xe2c74 | 0x291 |
SetEndOfFile | 0x0 | 0x4b6054 | 0xe3c78 | 0xe2c78 | 0x453 |
WaitForSingleObject | 0x0 | 0x4b6058 | 0xe3c7c | 0xe2c7c | 0x4f9 |
TerminateProcess | 0x0 | 0x4b605c | 0xe3c80 | 0xe2c80 | 0x4c0 |
CreateToolhelp32Snapshot | 0x0 | 0x4b6060 | 0xe3c84 | 0xe2c84 | 0xbe |
OpenProcess | 0x0 | 0x4b6064 | 0xe3c88 | 0xe2c88 | 0x380 |
WriteConsoleW | 0x0 | 0x4b6068 | 0xe3c8c | 0xe2c8c | 0x524 |
GetProcessHeap | 0x0 | 0x4b606c | 0xe3c90 | 0xe2c90 | 0x24a |
SetEnvironmentVariableA | 0x0 | 0x4b6070 | 0xe3c94 | 0xe2c94 | 0x456 |
FreeEnvironmentStringsW | 0x0 | 0x4b6074 | 0xe3c98 | 0xe2c98 | 0x161 |
GetEnvironmentStringsW | 0x0 | 0x4b6078 | 0xe3c9c | 0xe2c9c | 0x1da |
GetOEMCP | 0x0 | 0x4b607c | 0xe3ca0 | 0xe2ca0 | 0x237 |
IsValidCodePage | 0x0 | 0x4b6080 | 0xe3ca4 | 0xe2ca4 | 0x30a |
FindNextFileA | 0x0 | 0x4b6084 | 0xe3ca8 | 0xe2ca8 | 0x143 |
FindFirstFileExA | 0x0 | 0x4b6088 | 0xe3cac | 0xe2cac | 0x133 |
HeapSize | 0x0 | 0x4b608c | 0xe3cb0 | 0xe2cb0 | 0x2d4 |
HeapReAlloc | 0x0 | 0x4b6090 | 0xe3cb4 | 0xe2cb4 | 0x2d2 |
SetStdHandle | 0x0 | 0x4b6094 | 0xe3cb8 | 0xe2cb8 | 0x487 |
SetFilePointerEx | 0x0 | 0x4b6098 | 0xe3cbc | 0xe2cbc | 0x467 |
ReadConsoleW | 0x0 | 0x4b609c | 0xe3cc0 | 0xe2cc0 | 0x3be |
ReadFile | 0x0 | 0x4b60a0 | 0xe3cc4 | 0xe2cc4 | 0x3c0 |
GetConsoleMode | 0x0 | 0x4b60a4 | 0xe3cc8 | 0xe2cc8 | 0x1ac |
GetConsoleCP | 0x0 | 0x4b60a8 | 0xe3ccc | 0xe2ccc | 0x19a |
FlushFileBuffers | 0x0 | 0x4b60ac | 0xe3cd0 | 0xe2cd0 | 0x157 |
WideCharToMultiByte | 0x0 | 0x4b60b0 | 0xe3cd4 | 0xe2cd4 | 0x511 |
MultiByteToWideChar | 0x0 | 0x4b60b4 | 0xe3cd8 | 0xe2cd8 | 0x367 |
GetStringTypeW | 0x0 | 0x4b60b8 | 0xe3cdc | 0xe2cdc | 0x269 |
FormatMessageW | 0x0 | 0x4b60bc | 0xe3ce0 | 0xe2ce0 | 0x15e |
DuplicateHandle | 0x0 | 0x4b60c0 | 0xe3ce4 | 0xe2ce4 | 0xe8 |
WaitForSingleObjectEx | 0x0 | 0x4b60c4 | 0xe3ce8 | 0xe2ce8 | 0x4fa |
Sleep | 0x0 | 0x4b60c8 | 0xe3cec | 0xe2cec | 0x4b2 |
GetCurrentProcess | 0x0 | 0x4b60cc | 0xe3cf0 | 0xe2cf0 | 0x1c0 |
SwitchToThread | 0x0 | 0x4b60d0 | 0xe3cf4 | 0xe2cf4 | 0x4bc |
GetCurrentThreadId | 0x0 | 0x4b60d4 | 0xe3cf8 | 0xe2cf8 | 0x1c5 |
GetExitCodeThread | 0x0 | 0x4b60d8 | 0xe3cfc | 0xe2cfc | 0x1e0 |
CreateFileW | 0x0 | 0x4b60dc | 0xe3d00 | 0xe2d00 | 0x8f |
DeleteFileW | 0x0 | 0x4b60e0 | 0xe3d04 | 0xe2d04 | 0xd6 |
FindFirstFileExW | 0x0 | 0x4b60e4 | 0xe3d08 | 0xe2d08 | 0x134 |
GetDiskFreeSpaceExW | 0x0 | 0x4b60e8 | 0xe3d0c | 0xe2d0c | 0x1ce |
GetFileAttributesExW | 0x0 | 0x4b60ec | 0xe3d10 | 0xe2d10 | 0x1e7 |
GetFileInformationByHandle | 0x0 | 0x4b60f0 | 0xe3d14 | 0xe2d14 | 0x1ec |
RemoveDirectoryW | 0x0 | 0x4b60f4 | 0xe3d18 | 0xe2d18 | 0x403 |
AreFileApisANSI | 0x0 | 0x4b60f8 | 0xe3d1c | 0xe2d1c | 0x15 |
GetModuleHandleW | 0x0 | 0x4b60fc | 0xe3d20 | 0xe2d20 | 0x218 |
GetProcAddress | 0x0 | 0x4b6100 | 0xe3d24 | 0xe2d24 | 0x245 |
MoveFileExW | 0x0 | 0x4b6104 | 0xe3d28 | 0xe2d28 | 0x360 |
EnterCriticalSection | 0x0 | 0x4b6108 | 0xe3d2c | 0xe2d2c | 0xee |
LeaveCriticalSection | 0x0 | 0x4b610c | 0xe3d30 | 0xe2d30 | 0x339 |
TryEnterCriticalSection | 0x0 | 0x4b6110 | 0xe3d34 | 0xe2d34 | 0x4ce |
DeleteCriticalSection | 0x0 | 0x4b6114 | 0xe3d38 | 0xe2d38 | 0xd1 |
EncodePointer | 0x0 | 0x4b6118 | 0xe3d3c | 0xe2d3c | 0xea |
DecodePointer | 0x0 | 0x4b611c | 0xe3d40 | 0xe2d40 | 0xca |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4b6120 | 0xe3d44 | 0xe2d44 | 0x2e3 |
CreateEventW | 0x0 | 0x4b6124 | 0xe3d48 | 0xe2d48 | 0x85 |
TlsAlloc | 0x0 | 0x4b6128 | 0xe3d4c | 0xe2d4c | 0x4c5 |
TlsGetValue | 0x0 | 0x4b612c | 0xe3d50 | 0xe2d50 | 0x4c7 |
TlsSetValue | 0x0 | 0x4b6130 | 0xe3d54 | 0xe2d54 | 0x4c8 |
TlsFree | 0x0 | 0x4b6134 | 0xe3d58 | 0xe2d58 | 0x4c6 |
GetSystemTimeAsFileTime | 0x0 | 0x4b6138 | 0xe3d5c | 0xe2d5c | 0x279 |
GetTickCount | 0x0 | 0x4b613c | 0xe3d60 | 0xe2d60 | 0x293 |
CompareStringW | 0x0 | 0x4b6140 | 0xe3d64 | 0xe2d64 | 0x64 |
LCMapStringW | 0x0 | 0x4b6144 | 0xe3d68 | 0xe2d68 | 0x32d |
GetLocaleInfoW | 0x0 | 0x4b6148 | 0xe3d6c | 0xe2d6c | 0x206 |
GetCPInfo | 0x0 | 0x4b614c | 0xe3d70 | 0xe2d70 | 0x172 |
SetEvent | 0x0 | 0x4b6150 | 0xe3d74 | 0xe2d74 | 0x459 |
ResetEvent | 0x0 | 0x4b6154 | 0xe3d78 | 0xe2d78 | 0x40f |
InitializeSListHead | 0x0 | 0x4b6158 | 0xe3d7c | 0xe2d7c | 0x2e7 |
IsProcessorFeaturePresent | 0x0 | 0x4b615c | 0xe3d80 | 0xe2d80 | 0x304 |
IsDebuggerPresent | 0x0 | 0x4b6160 | 0xe3d84 | 0xe2d84 | 0x300 |
UnhandledExceptionFilter | 0x0 | 0x4b6164 | 0xe3d88 | 0xe2d88 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x4b6168 | 0xe3d8c | 0xe2d8c | 0x4a5 |
GetStartupInfoW | 0x0 | 0x4b616c | 0xe3d90 | 0xe2d90 | 0x263 |
GetCurrentProcessId | 0x0 | 0x4b6170 | 0xe3d94 | 0xe2d94 | 0x1c1 |
CreateTimerQueue | 0x0 | 0x4b6174 | 0xe3d98 | 0xe2d98 | 0xbc |
SignalObjectAndWait | 0x0 | 0x4b6178 | 0xe3d9c | 0xe2d9c | 0x4b0 |
CreateThread | 0x0 | 0x4b617c | 0xe3da0 | 0xe2da0 | 0xb5 |
SetThreadPriority | 0x0 | 0x4b6180 | 0xe3da4 | 0xe2da4 | 0x499 |
GetThreadPriority | 0x0 | 0x4b6184 | 0xe3da8 | 0xe2da8 | 0x28e |
GetLogicalProcessorInformation | 0x0 | 0x4b6188 | 0xe3dac | 0xe2dac | 0x20a |
CreateTimerQueueTimer | 0x0 | 0x4b618c | 0xe3db0 | 0xe2db0 | 0xbd |
ChangeTimerQueueTimer | 0x0 | 0x4b6190 | 0xe3db4 | 0xe2db4 | 0x48 |
DeleteTimerQueueTimer | 0x0 | 0x4b6194 | 0xe3db8 | 0xe2db8 | 0xda |
GetNumaHighestNodeNumber | 0x0 | 0x4b6198 | 0xe3dbc | 0xe2dbc | 0x229 |
GetProcessAffinityMask | 0x0 | 0x4b619c | 0xe3dc0 | 0xe2dc0 | 0x246 |
SetThreadAffinityMask | 0x0 | 0x4b61a0 | 0xe3dc4 | 0xe2dc4 | 0x490 |
RegisterWaitForSingleObject | 0x0 | 0x4b61a4 | 0xe3dc8 | 0xe2dc8 | 0x3f5 |
UnregisterWait | 0x0 | 0x4b61a8 | 0xe3dcc | 0xe2dcc | 0x4da |
FreeLibrary | 0x0 | 0x4b61ac | 0xe3dd0 | 0xe2dd0 | 0x162 |
FreeLibraryAndExitThread | 0x0 | 0x4b61b0 | 0xe3dd4 | 0xe2dd4 | 0x163 |
GetModuleFileNameW | 0x0 | 0x4b61b4 | 0xe3dd8 | 0xe2dd8 | 0x214 |
GetModuleHandleA | 0x0 | 0x4b61b8 | 0xe3ddc | 0xe2ddc | 0x215 |
LoadLibraryExW | 0x0 | 0x4b61bc | 0xe3de0 | 0xe2de0 | 0x33e |
GetVersionExW | 0x0 | 0x4b61c0 | 0xe3de4 | 0xe2de4 | 0x2a4 |
VirtualAlloc | 0x0 | 0x4b61c4 | 0xe3de8 | 0xe2de8 | 0x4e9 |
VirtualProtect | 0x0 | 0x4b61c8 | 0xe3dec | 0xe2dec | 0x4ef |
VirtualFree | 0x0 | 0x4b61cc | 0xe3df0 | 0xe2df0 | 0x4ec |
ReleaseSemaphore | 0x0 | 0x4b61d0 | 0xe3df4 | 0xe2df4 | 0x3fe |
InterlockedPopEntrySList | 0x0 | 0x4b61d4 | 0xe3df8 | 0xe2df8 | 0x2f0 |
InterlockedPushEntrySList | 0x0 | 0x4b61d8 | 0xe3dfc | 0xe2dfc | 0x2f1 |
InterlockedFlushSList | 0x0 | 0x4b61dc | 0xe3e00 | 0xe2e00 | 0x2ee |
QueryDepthSList | 0x0 | 0x4b61e0 | 0xe3e04 | 0xe2e04 | 0x39e |
UnregisterWaitEx | 0x0 | 0x4b61e4 | 0xe3e08 | 0xe2e08 | 0x4db |
LoadLibraryW | 0x0 | 0x4b61e8 | 0xe3e0c | 0xe2e0c | 0x33f |
RaiseException | 0x0 | 0x4b61ec | 0xe3e10 | 0xe2e10 | 0x3b1 |
RtlUnwind | 0x0 | 0x4b61f0 | 0xe3e14 | 0xe2e14 | 0x418 |
ExitProcess | 0x0 | 0x4b61f4 | 0xe3e18 | 0xe2e18 | 0x119 |
GetModuleHandleExW | 0x0 | 0x4b61f8 | 0xe3e1c | 0xe2e1c | 0x217 |
ExitThread | 0x0 | 0x4b61fc | 0xe3e20 | 0xe2e20 | 0x11a |
GetModuleFileNameA | 0x0 | 0x4b6200 | 0xe3e24 | 0xe2e24 | 0x213 |
GetStdHandle | 0x0 | 0x4b6204 | 0xe3e28 | 0xe2e28 | 0x264 |
WriteFile | 0x0 | 0x4b6208 | 0xe3e2c | 0xe2e2c | 0x525 |
GetCommandLineA | 0x0 | 0x4b620c | 0xe3e30 | 0xe2e30 | 0x186 |
GetCommandLineW | 0x0 | 0x4b6210 | 0xe3e34 | 0xe2e34 | 0x187 |
GetACP | 0x0 | 0x4b6214 | 0xe3e38 | 0xe2e38 | 0x168 |
HeapAlloc | 0x0 | 0x4b6218 | 0xe3e3c | 0xe2e3c | 0x2cb |
HeapFree | 0x0 | 0x4b621c | 0xe3e40 | 0xe2e40 | 0x2cf |
IsValidLocale | 0x0 | 0x4b6220 | 0xe3e44 | 0xe2e44 | 0x30c |
GetUserDefaultLCID | 0x0 | 0x4b6224 | 0xe3e48 | 0xe2e48 | 0x29b |
EnumSystemLocalesW | 0x0 | 0x4b6228 | 0xe3e4c | 0xe2e4c | 0x10f |
GetExitCodeProcess | 0x0 | 0x4b622c | 0xe3e50 | 0xe2e50 | 0x1df |
GetFileType | 0x0 | 0x4b6230 | 0xe3e54 | 0xe2e54 | 0x1f3 |
ADVAPI32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptReleaseContext | 0x0 | 0x4b6000 | 0xe3c24 | 0xe2c24 | 0xcb |
CryptAcquireContextA | 0x0 | 0x4b6004 | 0xe3c28 | 0xe2c28 | 0xb0 |
CryptGenRandom | 0x0 | 0x4b6008 | 0xe3c2c | 0xe2c2c | 0xc1 |
WS2_32.dll (19)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WSACleanup | 0x74 | 0x4b6238 | 0xe3e5c | 0xe2e5c | - |
WSAStartup | 0x73 | 0x4b623c | 0xe3e60 | 0xe2e60 | - |
htons | 0x9 | 0x4b6240 | 0xe3e64 | 0xe2e64 | - |
ioctlsocket | 0xa | 0x4b6244 | 0xe3e68 | 0xe2e68 | - |
closesocket | 0x3 | 0x4b6248 | 0xe3e6c | 0xe2e6c | - |
freeaddrinfo | 0x0 | 0x4b624c | 0xe3e70 | 0xe2e70 | 0x88 |
getaddrinfo | 0x0 | 0x4b6250 | 0xe3e74 | 0xe2e74 | 0x89 |
inet_ntoa | 0xc | 0x4b6254 | 0xe3e78 | 0xe2e78 | - |
inet_addr | 0xb | 0x4b6258 | 0xe3e7c | 0xe2e7c | - |
WSAGetLastError | 0x6f | 0x4b625c | 0xe3e80 | 0xe2e80 | - |
select | 0x12 | 0x4b6260 | 0xe3e84 | 0xe2e84 | - |
recv | 0x10 | 0x4b6264 | 0xe3e88 | 0xe2e88 | - |
ntohl | 0xe | 0x4b6268 | 0xe3e8c | 0xe2e8c | - |
htonl | 0x8 | 0x4b626c | 0xe3e90 | 0xe2e90 | - |
getpeername | 0x5 | 0x4b6270 | 0xe3e94 | 0xe2e94 | - |
connect | 0x4 | 0x4b6274 | 0xe3e98 | 0xe2e98 | - |
socket | 0x17 | 0x4b6278 | 0xe3e9c | 0xe2e9c | - |
setsockopt | 0x15 | 0x4b627c | 0xe3ea0 | 0xe2ea0 | - |
send | 0x13 | 0x4b6280 | 0xe3ea4 | 0xe2ea4 | - |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
mr.teslabrain@protonmail.com - copy.exe.txt.exe | 1 | 0x00DA0000 | 0x00E9BFFF | Relevant Image |
![]() |
32-bit | 0x00E235BF |
![]() |
![]() |
...
|
mr.teslabrain@protonmail.com - copy.exe.txt.exe | 1 | 0x00DA0000 | 0x00E9BFFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Ransom.Ouroboros.86DDF22C |
Malicious
|
C:\\588bce7c90097ed212\DHtmlHeader.html | Modified File | Batch |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2011-06-14 17:40 (UTC+2) |
Last Seen | 2019-12-09 10:22 (UTC+1) |
C:\\588bce7c90097ed212\netfx_Core_x64.msi.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\netfx_Core_x86.msi.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\netfx_Core.mzz | Modified File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems64.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Common Files\microsoft shared\ClickToRun\C2R64.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\netfx_Extended.mzz.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pidgenx.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\bin\awt.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\bin\dtplugin\npdeployJava1.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\bin\server\jvm.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\charsets.jar | Modified File | Unknown |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\deploy.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\deploy.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\bin\jfxwebkit.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\$GetCurrent\Logs\PartnerSetupCompleteResult.log.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\netfx_Extended_x86.msi.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\$GetCurrent\SafeOS\GetCurrentOOBE.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\netfx_Extended_x64.msi.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\$GetCurrent\SafeOS\GetCurrentRollback.ini.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\ParameterInfo.xml.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\$GetCurrent\SafeOS\PartnerSetupComplete.cmd.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\$GetCurrent\SafeOS\preoobe.cmd.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\$GetCurrent\SafeOS\SetupComplete.cmd.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\SetupUi.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\$Recycle.Bin\S-1-5-18\desktop.ini.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\SetupEngine.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\DHtmlHeader.html.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\DisplayIcon.ico.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\header.bmp.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\netfx_Core.mzz.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream32.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream64.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\RGB9RAST_x64.msi.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Common Files\microsoft shared\ClickToRun\AppVScripting.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Binary |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\RGB9Rast_x86.msi.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Common Files\microsoft shared\ClickToRun\C2RUI.en-us.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\SetupUi.xsd.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Common Files\microsoft shared\ClickToRun\concrt140.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\SplashScreen.bmp.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig-office.xrm-ms.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\sqmapi.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Strings.xml.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\UiInfo.xml.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Common Files\microsoft shared\ClickToRun\ucrtbase.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\watermark.bmp.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Common Files\microsoft shared\ClickToRun\vccorlib140.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1025\eula.rtf.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1025\LocalizedData.xml.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1025\SetupResources.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1028\eula.rtf.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1028\LocalizedData.xml.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\bin\deploy.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1028\SetupResources.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1029\eula.rtf.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\bin\gstreamer-lite.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1029\LocalizedData.xml.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1029\SetupResources.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Common Files\microsoft shared\VC\msdia100.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Common Files\microsoft shared\VSTO\10.0\VSTOLoader.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\bin\javafx_font_t2k.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1030\eula.rtf.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Common Files\microsoft shared\VC\msdia90.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1030\LocalizedData.xml.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1030\SetupResources.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\bin\mlib_image.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1031\eula.rtf.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1031\LocalizedData.xml.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\bin\fontmanager.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\bin\msvcp120.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1031\SetupResources.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\bin\glass.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1032\eula.rtf.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1032\LocalizedData.xml.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\bin\glib-lite.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1032\SetupResources.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1033\eula.rtf.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1033\LocalizedData.xml.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\bin\ssv.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\bin\msvcr100.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1033\SetupResources.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\bin\jp2iexp.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\bin\msvcr120.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1035\eula.rtf.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1035\LocalizedData.xml.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1035\SetupResources.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1036\eula.rtf.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1036\LocalizedData.xml.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\bin\plugin2\msvcr100.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1036\SetupResources.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1037\eula.rtf.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1037\LocalizedData.xml.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1037\SetupResources.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\javaws.jar.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1038\eula.rtf.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1038\LocalizedData.xml.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1038\SetupResources.dll.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0015-0000-1000-0000000FF1CE.xml.Email=[Mr.TeslaBrain@protonmail.com]ID=[20ZXEV9TMHPKLQY].odveta | Dropped File | Unknown |
Not Queried
|
...
|
»