VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Wiper, Trojan |
bvzqdb.exe
Windows Exe (x86-32)
Created at 2019-05-29T16:17:00
Remarks
(0x200001e): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (20) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-05-28 03:14 (UTC+2) |
Last Seen | 2019-05-29 14:25 (UTC+2) |
Names | Win32.Trojan.Filecoder |
Families | Filecoder |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4a6ce0 |
Size Of Code | 0xec400 |
Size Of Initialized Data | 0x51200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-05-24 21:25:08+00:00 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xec3ef | 0xec400 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.6 |
.rdata | 0x4ee000 | 0x4193a | 0x41a00 | 0xec800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.29 |
.data | 0x530000 | 0x4c9c | 0x1c00 | 0x12e200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.4 |
.gfids | 0x535000 | 0x144 | 0x200 | 0x12fe00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.72 |
.rsrc | 0x536000 | 0x1e0 | 0x200 | 0x130000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.71 |
.reloc | 0x537000 | 0xa5f8 | 0xa600 | 0x130200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.65 |
Imports (6)
»
KERNEL32.dll (112)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LeaveCriticalSection | 0x0 | 0x4ee040 | 0x12ec30 | 0x12d430 | 0x339 |
DeleteCriticalSection | 0x0 | 0x4ee044 | 0x12ec34 | 0x12d434 | 0xd1 |
Sleep | 0x0 | 0x4ee048 | 0x12ec38 | 0x12d438 | 0x4b2 |
SleepEx | 0x0 | 0x4ee04c | 0x12ec3c | 0x12d43c | 0x4b5 |
FormatMessageA | 0x0 | 0x4ee050 | 0x12ec40 | 0x12d440 | 0x15d |
WaitForSingleObject | 0x0 | 0x4ee054 | 0x12ec44 | 0x12d444 | 0x4f9 |
WaitForMultipleObjects | 0x0 | 0x4ee058 | 0x12ec48 | 0x12d448 | 0x4f7 |
ReadFile | 0x0 | 0x4ee05c | 0x12ec4c | 0x12d44c | 0x3c0 |
PeekNamedPipe | 0x0 | 0x4ee060 | 0x12ec50 | 0x12d450 | 0x38d |
ExpandEnvironmentStringsA | 0x0 | 0x4ee064 | 0x12ec54 | 0x12d454 | 0x11c |
EnterCriticalSection | 0x0 | 0x4ee068 | 0x12ec58 | 0x12d458 | 0xee |
GetSystemDirectoryA | 0x0 | 0x4ee06c | 0x12ec5c | 0x12d45c | 0x26f |
VerifyVersionInfoA | 0x0 | 0x4ee070 | 0x12ec60 | 0x12d460 | 0x4e7 |
SetEndOfFile | 0x0 | 0x4ee074 | 0x12ec64 | 0x12d464 | 0x453 |
SetEnvironmentVariableA | 0x0 | 0x4ee078 | 0x12ec68 | 0x12d468 | 0x456 |
FreeEnvironmentStringsW | 0x0 | 0x4ee07c | 0x12ec6c | 0x12d46c | 0x161 |
GetEnvironmentStringsW | 0x0 | 0x4ee080 | 0x12ec70 | 0x12d470 | 0x1da |
GetCPInfo | 0x0 | 0x4ee084 | 0x12ec74 | 0x12d474 | 0x172 |
GetOEMCP | 0x0 | 0x4ee088 | 0x12ec78 | 0x12d478 | 0x237 |
IsValidCodePage | 0x0 | 0x4ee08c | 0x12ec7c | 0x12d47c | 0x30a |
InitializeCriticalSection | 0x0 | 0x4ee090 | 0x12ec80 | 0x12d480 | 0x2e2 |
SetLastError | 0x0 | 0x4ee094 | 0x12ec84 | 0x12d484 | 0x473 |
FlushConsoleInputBuffer | 0x0 | 0x4ee098 | 0x12ec88 | 0x12d488 | 0x156 |
LoadLibraryA | 0x0 | 0x4ee09c | 0x12ec8c | 0x12d48c | 0x33c |
FreeLibrary | 0x0 | 0x4ee0a0 | 0x12ec90 | 0x12d490 | 0x162 |
GlobalMemoryStatus | 0x0 | 0x4ee0a4 | 0x12ec94 | 0x12d494 | 0x2bf |
GetTickCount | 0x0 | 0x4ee0a8 | 0x12ec98 | 0x12d498 | 0x293 |
GetCurrentProcessId | 0x0 | 0x4ee0ac | 0x12ec9c | 0x12d49c | 0x1c1 |
QueryPerformanceCounter | 0x0 | 0x4ee0b0 | 0x12eca0 | 0x12d4a0 | 0x3a7 |
CloseHandle | 0x0 | 0x4ee0b4 | 0x12eca4 | 0x12d4a4 | 0x52 |
MultiByteToWideChar | 0x0 | 0x4ee0b8 | 0x12eca8 | 0x12d4a8 | 0x367 |
GetProcAddress | 0x0 | 0x4ee0bc | 0x12ecac | 0x12d4ac | 0x245 |
GetCurrentThreadId | 0x0 | 0x4ee0c0 | 0x12ecb0 | 0x12d4b0 | 0x1c5 |
GetLastError | 0x0 | 0x4ee0c4 | 0x12ecb4 | 0x12d4b4 | 0x202 |
WriteFile | 0x0 | 0x4ee0c8 | 0x12ecb8 | 0x12d4b8 | 0x525 |
GetFileType | 0x0 | 0x4ee0cc | 0x12ecbc | 0x12d4bc | 0x1f3 |
GetStdHandle | 0x0 | 0x4ee0d0 | 0x12ecc0 | 0x12d4c0 | 0x264 |
GetModuleHandleA | 0x0 | 0x4ee0d4 | 0x12ecc4 | 0x12d4c4 | 0x215 |
Wow64EnableWow64FsRedirection | 0x0 | 0x4ee0d8 | 0x12ecc8 | 0x12d4c8 | 0x514 |
GetDriveTypeA | 0x0 | 0x4ee0dc | 0x12eccc | 0x12d4cc | 0x1d2 |
VerSetConditionMask | 0x0 | 0x4ee0e0 | 0x12ecd0 | 0x12d4d0 | 0x4e4 |
GetModuleFileNameA | 0x0 | 0x4ee0e4 | 0x12ecd4 | 0x12d4d4 | 0x213 |
FindNextFileA | 0x0 | 0x4ee0e8 | 0x12ecd8 | 0x12d4d8 | 0x143 |
FindFirstFileExA | 0x0 | 0x4ee0ec | 0x12ecdc | 0x12d4dc | 0x133 |
GetProcessHeap | 0x0 | 0x4ee0f0 | 0x12ece0 | 0x12d4e0 | 0x24a |
HeapQueryInformation | 0x0 | 0x4ee0f4 | 0x12ece4 | 0x12d4e4 | 0x2d1 |
HeapSize | 0x0 | 0x4ee0f8 | 0x12ece8 | 0x12d4e8 | 0x2d4 |
HeapReAlloc | 0x0 | 0x4ee0fc | 0x12ecec | 0x12d4ec | 0x2d2 |
HeapFree | 0x0 | 0x4ee100 | 0x12ecf0 | 0x12d4f0 | 0x2cf |
GetFullPathNameW | 0x0 | 0x4ee104 | 0x12ecf4 | 0x12d4f4 | 0x1fb |
GetCurrentDirectoryW | 0x0 | 0x4ee108 | 0x12ecf8 | 0x12d4f8 | 0x1bf |
GetTimeZoneInformation | 0x0 | 0x4ee10c | 0x12ecfc | 0x12d4fc | 0x298 |
FlushFileBuffers | 0x0 | 0x4ee110 | 0x12ed00 | 0x12d500 | 0x157 |
GetStringTypeW | 0x0 | 0x4ee114 | 0x12ed04 | 0x12d504 | 0x269 |
WaitForSingleObjectEx | 0x0 | 0x4ee118 | 0x12ed08 | 0x12d508 | 0x4fa |
WriteConsoleW | 0x0 | 0x4ee11c | 0x12ed0c | 0x12d50c | 0x524 |
OutputDebugStringW | 0x0 | 0x4ee120 | 0x12ed10 | 0x12d510 | 0x38a |
OutputDebugStringA | 0x0 | 0x4ee124 | 0x12ed14 | 0x12d514 | 0x389 |
GetFileAttributesExW | 0x0 | 0x4ee128 | 0x12ed18 | 0x12d518 | 0x1e7 |
CreateProcessA | 0x0 | 0x4ee12c | 0x12ed1c | 0x12d51c | 0xa4 |
GetExitCodeProcess | 0x0 | 0x4ee130 | 0x12ed20 | 0x12d520 | 0x1df |
DeleteFileW | 0x0 | 0x4ee134 | 0x12ed24 | 0x12d524 | 0xd6 |
SetStdHandle | 0x0 | 0x4ee138 | 0x12ed28 | 0x12d528 | 0x487 |
LCMapStringW | 0x0 | 0x4ee13c | 0x12ed2c | 0x12d52c | 0x32d |
CompareStringW | 0x0 | 0x4ee140 | 0x12ed30 | 0x12d530 | 0x64 |
GetConsoleCP | 0x0 | 0x4ee144 | 0x12ed34 | 0x12d534 | 0x19a |
ReadConsoleW | 0x0 | 0x4ee148 | 0x12ed38 | 0x12d538 | 0x3be |
GetACP | 0x0 | 0x4ee14c | 0x12ed3c | 0x12d53c | 0x168 |
GetCommandLineW | 0x0 | 0x4ee150 | 0x12ed40 | 0x12d540 | 0x187 |
DecodePointer | 0x0 | 0x4ee154 | 0x12ed44 | 0x12d544 | 0xca |
GetCommandLineA | 0x0 | 0x4ee158 | 0x12ed48 | 0x12d548 | 0x186 |
WideCharToMultiByte | 0x0 | 0x4ee15c | 0x12ed4c | 0x12d54c | 0x511 |
GetSystemInfo | 0x0 | 0x4ee160 | 0x12ed50 | 0x12d550 | 0x273 |
HeapValidate | 0x0 | 0x4ee164 | 0x12ed54 | 0x12d554 | 0x2d7 |
HeapAlloc | 0x0 | 0x4ee168 | 0x12ed58 | 0x12d558 | 0x2cb |
GetDriveTypeW | 0x0 | 0x4ee16c | 0x12ed5c | 0x12d55c | 0x1d3 |
CreateFileW | 0x0 | 0x4ee170 | 0x12ed60 | 0x12d560 | 0x8f |
SetFilePointerEx | 0x0 | 0x4ee174 | 0x12ed64 | 0x12d564 | 0x467 |
FreeLibraryAndExitThread | 0x0 | 0x4ee178 | 0x12ed68 | 0x12d568 | 0x163 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4ee17c | 0x12ed6c | 0x12d56c | 0x2e3 |
TlsAlloc | 0x0 | 0x4ee180 | 0x12ed70 | 0x12d570 | 0x4c5 |
TlsGetValue | 0x0 | 0x4ee184 | 0x12ed74 | 0x12d574 | 0x4c7 |
TlsSetValue | 0x0 | 0x4ee188 | 0x12ed78 | 0x12d578 | 0x4c8 |
TlsFree | 0x0 | 0x4ee18c | 0x12ed7c | 0x12d57c | 0x4c6 |
GetSystemTimeAsFileTime | 0x0 | 0x4ee190 | 0x12ed80 | 0x12d580 | 0x279 |
GetModuleHandleW | 0x0 | 0x4ee194 | 0x12ed84 | 0x12d584 | 0x218 |
UnhandledExceptionFilter | 0x0 | 0x4ee198 | 0x12ed88 | 0x12d588 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x4ee19c | 0x12ed8c | 0x12d58c | 0x4a5 |
GetCurrentProcess | 0x0 | 0x4ee1a0 | 0x12ed90 | 0x12d590 | 0x1c0 |
TerminateProcess | 0x0 | 0x4ee1a4 | 0x12ed94 | 0x12d594 | 0x4c0 |
IsProcessorFeaturePresent | 0x0 | 0x4ee1a8 | 0x12ed98 | 0x12d598 | 0x304 |
InitializeSListHead | 0x0 | 0x4ee1ac | 0x12ed9c | 0x12d59c | 0x2e7 |
IsDebuggerPresent | 0x0 | 0x4ee1b0 | 0x12eda0 | 0x12d5a0 | 0x300 |
GetStartupInfoW | 0x0 | 0x4ee1b4 | 0x12eda4 | 0x12d5a4 | 0x263 |
EncodePointer | 0x0 | 0x4ee1b8 | 0x12eda8 | 0x12d5a8 | 0xea |
RaiseException | 0x0 | 0x4ee1bc | 0x12edac | 0x12d5ac | 0x3b1 |
RtlUnwind | 0x0 | 0x4ee1c0 | 0x12edb0 | 0x12d5b0 | 0x418 |
LoadLibraryExW | 0x0 | 0x4ee1c4 | 0x12edb4 | 0x12d5b4 | 0x33e |
ExitProcess | 0x0 | 0x4ee1c8 | 0x12edb8 | 0x12d5b8 | 0x119 |
GetModuleHandleExW | 0x0 | 0x4ee1cc | 0x12edbc | 0x12d5bc | 0x217 |
FindClose | 0x0 | 0x4ee1d0 | 0x12edc0 | 0x12d5c0 | 0x12e |
FindFirstFileExW | 0x0 | 0x4ee1d4 | 0x12edc4 | 0x12d5c4 | 0x134 |
FindNextFileW | 0x0 | 0x4ee1d8 | 0x12edc8 | 0x12d5c8 | 0x145 |
SystemTimeToTzSpecificLocalTime | 0x0 | 0x4ee1dc | 0x12edcc | 0x12d5cc | 0x4be |
FileTimeToSystemTime | 0x0 | 0x4ee1e0 | 0x12edd0 | 0x12d5d0 | 0x125 |
GetModuleFileNameW | 0x0 | 0x4ee1e4 | 0x12edd4 | 0x12d5d4 | 0x214 |
SetConsoleCtrlHandler | 0x0 | 0x4ee1e8 | 0x12edd8 | 0x12d5d8 | 0x42d |
GetConsoleMode | 0x0 | 0x4ee1ec | 0x12eddc | 0x12d5dc | 0x1ac |
ReadConsoleInputA | 0x0 | 0x4ee1f0 | 0x12ede0 | 0x12d5e0 | 0x3b5 |
SetConsoleMode | 0x0 | 0x4ee1f4 | 0x12ede4 | 0x12d5e4 | 0x43d |
CreateThread | 0x0 | 0x4ee1f8 | 0x12ede8 | 0x12d5e8 | 0xb5 |
ExitThread | 0x0 | 0x4ee1fc | 0x12edec | 0x12d5ec | 0x11a |
USER32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MessageBoxA | 0x0 | 0x4ee20c | 0x12edfc | 0x12d5fc | 0x20e |
GetUserObjectInformationW | 0x0 | 0x4ee210 | 0x12ee00 | 0x12d600 | 0x18b |
GetProcessWindowStation | 0x0 | 0x4ee214 | 0x12ee04 | 0x12d604 | 0x168 |
ShowWindow | 0x0 | 0x4ee218 | 0x12ee08 | 0x12d608 | 0x2df |
FindWindowA | 0x0 | 0x4ee21c | 0x12ee0c | 0x12d60c | 0xf7 |
ADVAPI32.dll (15)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptHashData | 0x0 | 0x4ee000 | 0x12ebf0 | 0x12d3f0 | 0xc8 |
CryptCreateHash | 0x0 | 0x4ee004 | 0x12ebf4 | 0x12d3f4 | 0xb3 |
CryptEncrypt | 0x0 | 0x4ee008 | 0x12ebf8 | 0x12d3f8 | 0xba |
CryptImportKey | 0x0 | 0x4ee00c | 0x12ebfc | 0x12d3fc | 0xca |
CryptGetHashParam | 0x0 | 0x4ee010 | 0x12ec00 | 0x12d400 | 0xc4 |
CryptDestroyKey | 0x0 | 0x4ee014 | 0x12ec04 | 0x12d404 | 0xb7 |
CryptReleaseContext | 0x0 | 0x4ee018 | 0x12ec08 | 0x12d408 | 0xcb |
CryptAcquireContextA | 0x0 | 0x4ee01c | 0x12ec0c | 0x12d40c | 0xb0 |
ReportEventA | 0x0 | 0x4ee020 | 0x12ec10 | 0x12d410 | 0x28e |
RegisterEventSourceA | 0x0 | 0x4ee024 | 0x12ec14 | 0x12d414 | 0x282 |
DeregisterEventSource | 0x0 | 0x4ee028 | 0x12ec18 | 0x12d418 | 0xdb |
CloseEventLog | 0x0 | 0x4ee02c | 0x12ec1c | 0x12d41c | 0x56 |
ClearEventLogA | 0x0 | 0x4ee030 | 0x12ec20 | 0x12d420 | 0x52 |
OpenEventLogA | 0x0 | 0x4ee034 | 0x12ec24 | 0x12d424 | 0x1f5 |
CryptDestroyHash | 0x0 | 0x4ee038 | 0x12ec28 | 0x12d428 | 0xb6 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteA | 0x0 | 0x4ee204 | 0x12edf4 | 0x12d5f4 | 0x11e |
WS2_32.dll (27)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
socket | 0x17 | 0x4ee268 | 0x12ee58 | 0x12d658 | - |
ntohs | 0xf | 0x4ee26c | 0x12ee5c | 0x12d65c | - |
htons | 0x9 | 0x4ee270 | 0x12ee60 | 0x12d660 | - |
getsockopt | 0x7 | 0x4ee274 | 0x12ee64 | 0x12d664 | - |
getsockname | 0x6 | 0x4ee278 | 0x12ee68 | 0x12d668 | - |
getpeername | 0x5 | 0x4ee27c | 0x12ee6c | 0x12d66c | - |
connect | 0x4 | 0x4ee280 | 0x12ee70 | 0x12d670 | - |
closesocket | 0x3 | 0x4ee284 | 0x12ee74 | 0x12d674 | - |
bind | 0x2 | 0x4ee288 | 0x12ee78 | 0x12d678 | - |
send | 0x13 | 0x4ee28c | 0x12ee7c | 0x12d67c | - |
recv | 0x10 | 0x4ee290 | 0x12ee80 | 0x12d680 | - |
WSASetLastError | 0x70 | 0x4ee294 | 0x12ee84 | 0x12d684 | - |
select | 0x12 | 0x4ee298 | 0x12ee88 | 0x12d688 | - |
__WSAFDIsSet | 0x97 | 0x4ee29c | 0x12ee8c | 0x12d68c | - |
WSAGetLastError | 0x6f | 0x4ee2a0 | 0x12ee90 | 0x12d690 | - |
WSACleanup | 0x74 | 0x4ee2a4 | 0x12ee94 | 0x12d694 | - |
WSAStartup | 0x73 | 0x4ee2a8 | 0x12ee98 | 0x12d698 | - |
WSAIoctl | 0x0 | 0x4ee2ac | 0x12ee9c | 0x12d69c | 0x36 |
getaddrinfo | 0x0 | 0x4ee2b0 | 0x12eea0 | 0x12d6a0 | 0x89 |
freeaddrinfo | 0x0 | 0x4ee2b4 | 0x12eea4 | 0x12d6a4 | 0x88 |
recvfrom | 0x11 | 0x4ee2b8 | 0x12eea8 | 0x12d6a8 | - |
sendto | 0x14 | 0x4ee2bc | 0x12eeac | 0x12d6ac | - |
accept | 0x1 | 0x4ee2c0 | 0x12eeb0 | 0x12d6b0 | - |
listen | 0xd | 0x4ee2c4 | 0x12eeb4 | 0x12d6b4 | - |
ioctlsocket | 0xa | 0x4ee2c8 | 0x12eeb8 | 0x12d6b8 | - |
gethostname | 0x39 | 0x4ee2cc | 0x12eebc | 0x12d6bc | - |
setsockopt | 0x15 | 0x4ee2d0 | 0x12eec0 | 0x12d6c0 | - |
WLDAP32.dll (16)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x29 | 0x4ee224 | 0x12ee14 | 0x12d614 | - |
(by ordinal) | 0x32 | 0x4ee228 | 0x12ee18 | 0x12d618 | - |
(by ordinal) | 0x16 | 0x4ee22c | 0x12ee1c | 0x12d61c | - |
(by ordinal) | 0xd3 | 0x4ee230 | 0x12ee20 | 0x12d620 | - |
(by ordinal) | 0x2e | 0x4ee234 | 0x12ee24 | 0x12d624 | - |
(by ordinal) | 0x8f | 0x4ee238 | 0x12ee28 | 0x12d628 | - |
(by ordinal) | 0x1b | 0x4ee23c | 0x12ee2c | 0x12d62c | - |
(by ordinal) | 0x20 | 0x4ee240 | 0x12ee30 | 0x12d630 | - |
(by ordinal) | 0x21 | 0x4ee244 | 0x12ee34 | 0x12d634 | - |
(by ordinal) | 0x23 | 0x4ee248 | 0x12ee38 | 0x12d638 | - |
(by ordinal) | 0x4f | 0x4ee24c | 0x12ee3c | 0x12d63c | - |
(by ordinal) | 0x1e | 0x4ee250 | 0x12ee40 | 0x12d640 | - |
(by ordinal) | 0x12d | 0x4ee254 | 0x12ee44 | 0x12d644 | - |
(by ordinal) | 0xc8 | 0x4ee258 | 0x12ee48 | 0x12d648 | - |
(by ordinal) | 0x3c | 0x4ee25c | 0x12ee4c | 0x12d64c | - |
(by ordinal) | 0x1a | 0x4ee260 | 0x12ee50 | 0x12d650 | - |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
bvzqdb.exe | 1 | 0x00250000 | 0x00391FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
C:\\588bce7c90097ed212\1031\[sysfrog@protonmail.com]LocalizedData.xml.sysfrog | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1044\[sysfrog@protonmail.com]eula.rtf.sysfrog | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1045\[sysfrog@protonmail.com]LocalizedData.xml.sysfrog | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1049\[sysfrog@protonmail.com]eula.rtf.sysfrog | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\[sysfrog@protonmail.com]Windows6.1-KB958488-v6001-x64.msu.sysfrog | Dropped File | Binary |
Unknown
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-AppxPackaging%4Operational.evtx.sysfrog | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-Diagnostics-Performance%4Operational.evtx.sysfrog | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx.sysfrog | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-Kernel-WHEA%4Operational.evtx.sysfrog | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-LiveId%4Operational.evtx.sysfrog | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-ReadyBoost%4Operational.evtx.sysfrog | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-User Profile Service%4Operational.evtx.sysfrog | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-Windows Defender%4WHC.evtx.sysfrog | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\bin\server\[sysfrog@protonmail.com]classes.jsa.sysfrog | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\ext\[sysfrog@protonmail.com]jaccess.jar.sysfrog | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\ext\[sysfrog@protonmail.com]sunjce_provider.jar.sysfrog | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\fonts\[sysfrog@protonmail.com]LucidaSansRegular.ttf.sysfrog | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]javafx.properties.sysfrog | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]psfontj2d.properties.sysfrog | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\how_to_decrypt.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\\$GetCurrent\Logs\[sysfrog@protonmail.com]downlevel_2017_09_07_02_02_39_766.log.sysfrog | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\\$GetCurrent\Logs\[sysfrog@protonmail.com]oobe_2017_09_07_03_08_57_737.log.sysfrog | Dropped File | Unknown |
Not Queried
|
...
|
»
Local AV Information
»
Errors | - |
Failed AV scans | The sample is corrupted |
C:\\$GetCurrent\Logs\[sysfrog@protonmail.com]PartnerSetupCompleteResult.log.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\$GetCurrent\SafeOS\[sysfrog@protonmail.com]GetCurrentRollback.ini.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\[sysfrog@protonmail.com]$WINRE_BACKUP_PARTITION.MARKER.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1025\[sysfrog@protonmail.com]eula.rtf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1025\[sysfrog@protonmail.com]LocalizedData.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1029\[sysfrog@protonmail.com]eula.rtf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1029\[sysfrog@protonmail.com]LocalizedData.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1030\[sysfrog@protonmail.com]eula.rtf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1030\[sysfrog@protonmail.com]LocalizedData.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1031\[sysfrog@protonmail.com]eula.rtf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1032\[sysfrog@protonmail.com]eula.rtf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1032\[sysfrog@protonmail.com]LocalizedData.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1033\[sysfrog@protonmail.com]eula.rtf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1033\[sysfrog@protonmail.com]LocalizedData.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1035\[sysfrog@protonmail.com]eula.rtf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1035\[sysfrog@protonmail.com]LocalizedData.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1036\[sysfrog@protonmail.com]eula.rtf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1036\[sysfrog@protonmail.com]LocalizedData.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1037\[sysfrog@protonmail.com]eula.rtf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1037\[sysfrog@protonmail.com]LocalizedData.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1038\[sysfrog@protonmail.com]eula.rtf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1038\[sysfrog@protonmail.com]LocalizedData.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1040\[sysfrog@protonmail.com]eula.rtf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1040\[sysfrog@protonmail.com]LocalizedData.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1041\[sysfrog@protonmail.com]eula.rtf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1041\[sysfrog@protonmail.com]LocalizedData.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1042\[sysfrog@protonmail.com]eula.rtf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1042\[sysfrog@protonmail.com]LocalizedData.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1043\[sysfrog@protonmail.com]eula.rtf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1043\[sysfrog@protonmail.com]LocalizedData.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1044\[sysfrog@protonmail.com]LocalizedData.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1045\[sysfrog@protonmail.com]eula.rtf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1046\[sysfrog@protonmail.com]eula.rtf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1046\[sysfrog@protonmail.com]LocalizedData.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1049\[sysfrog@protonmail.com]LocalizedData.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1053\[sysfrog@protonmail.com]eula.rtf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1053\[sysfrog@protonmail.com]LocalizedData.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1055\[sysfrog@protonmail.com]eula.rtf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1055\[sysfrog@protonmail.com]LocalizedData.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\2052\[sysfrog@protonmail.com]eula.rtf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\2052\[sysfrog@protonmail.com]LocalizedData.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\2070\[sysfrog@protonmail.com]eula.rtf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\2070\[sysfrog@protonmail.com]LocalizedData.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1028\[sysfrog@protonmail.com]eula.rtf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1028\[sysfrog@protonmail.com]LocalizedData.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\3082\[sysfrog@protonmail.com]eula.rtf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\3082\[sysfrog@protonmail.com]LocalizedData.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Client\[sysfrog@protonmail.com]Parameterinfo.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Client\[sysfrog@protonmail.com]UiInfo.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\[sysfrog@protonmail.com]DHtmlHeader.html.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\[sysfrog@protonmail.com]DisplayIcon.ico.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Extended\[sysfrog@protonmail.com]Parameterinfo.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Extended\[sysfrog@protonmail.com]UiInfo.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\[sysfrog@protonmail.com]Print.ico.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\[sysfrog@protonmail.com]Rotate1.ico.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\[sysfrog@protonmail.com]Rotate2.ico.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\[sysfrog@protonmail.com]Rotate3.ico.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\[sysfrog@protonmail.com]Rotate4.ico.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\[sysfrog@protonmail.com]Rotate5.ico.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\[sysfrog@protonmail.com]Rotate6.ico.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\[sysfrog@protonmail.com]Rotate7.ico.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\[sysfrog@protonmail.com]Rotate8.ico.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\[sysfrog@protonmail.com]Save.ico.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\[sysfrog@protonmail.com]Setup.ico.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\[sysfrog@protonmail.com]stop.ico.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\[sysfrog@protonmail.com]SysReqMet.ico.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\[sysfrog@protonmail.com]SysReqNotMet.ico.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\[sysfrog@protonmail.com]warn.ico.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\[sysfrog@protonmail.com]header.bmp.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\[sysfrog@protonmail.com]netfx_Core.mzz.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\[sysfrog@protonmail.com]netfx_Core_x64.msi.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\[sysfrog@protonmail.com]netfx_Core_x86.msi.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\[sysfrog@protonmail.com]netfx_Extended.mzz.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\[sysfrog@protonmail.com]netfx_Extended_x64.msi.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\[sysfrog@protonmail.com]netfx_Extended_x86.msi.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\[sysfrog@protonmail.com]ParameterInfo.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\[sysfrog@protonmail.com]RGB9RAST_x64.msi.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\[sysfrog@protonmail.com]RGB9Rast_x86.msi.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\[sysfrog@protonmail.com]SetupUi.xsd.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\[sysfrog@protonmail.com]SplashScreen.bmp.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\[sysfrog@protonmail.com]Strings.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\[sysfrog@protonmail.com]UiInfo.xml.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\[sysfrog@protonmail.com]watermark.bmp.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\[sysfrog@protonmail.com]Windows6.0-KB956250-v6001-x64.msu.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\[sysfrog@protonmail.com]Windows6.0-KB956250-v6001-x86.msu.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\[sysfrog@protonmail.com]Windows6.1-KB958488-v6001-x86.msu.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Application.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Client-Licensing-Platform%4Admin.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-AppLocker%4MSI and Script.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-AppModel-Runtime%4Admin.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-AppReadiness%4Admin.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-AppReadiness%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-AppXDeployment%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-Bits-Client%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-CodeIntegrity%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-Crypto-DPAPI%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-DeviceSetupManager%4Admin.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-DeviceSetupManager%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-Diagnosis-DPS%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-GroupPolicy%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-International%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-Kernel-EventTracing%4Admin.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-Kernel-PnP%4Configuration.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-Known Folders API Service.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-MUI%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-Ntfs%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-Ntfs%4WHC.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-SettingSync%4Debug.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-Shell-Core%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-SmbClient%4Connectivity.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-SMBServer%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-Store%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-TaskScheduler%4Maintenance.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-TWinUI%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-UserPnp%4DeviceInstall.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-Wcmsvc%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-Windows Defender%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Microsoft-Windows-WMI-Activity%4Operational.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Security.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]Setup.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]System.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\[sysfrog@protonmail.com]HardwareEvents.evtx.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\bin\[sysfrog@protonmail.com]javacpl.cpl.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\bin\server\[sysfrog@protonmail.com]Xusage.txt.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\[sysfrog@protonmail.com]COPYRIGHT.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]accessibility.properties.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\amd64\[sysfrog@protonmail.com]jvm.cfg.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]calendars.properties.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]charsets.jar.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]classlist.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\cmm\[sysfrog@protonmail.com]CIEXYZ.pf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\cmm\[sysfrog@protonmail.com]GRAY.pf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\cmm\[sysfrog@protonmail.com]LINEAR_RGB.pf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\cmm\[sysfrog@protonmail.com]PYCC.pf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\cmm\[sysfrog@protonmail.com]sRGB.pf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]content-types.properties.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]currency.data.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\deploy\[sysfrog@protonmail.com]ffjcext.zip.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\deploy\[sysfrog@protonmail.com]messages.properties.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\deploy\[sysfrog@protonmail.com]messages_de.properties.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\deploy\[sysfrog@protonmail.com]messages_es.properties.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\deploy\[sysfrog@protonmail.com]messages_fr.properties.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\deploy\[sysfrog@protonmail.com]messages_it.properties.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\deploy\[sysfrog@protonmail.com]messages_ja.properties.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\deploy\[sysfrog@protonmail.com]messages_ko.properties.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\deploy\[sysfrog@protonmail.com]messages_pt_BR.properties.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\deploy\[sysfrog@protonmail.com]messages_sv.properties.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\deploy\[sysfrog@protonmail.com]messages_zh_CN.properties.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\deploy\[sysfrog@protonmail.com]messages_zh_HK.properties.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\deploy\[sysfrog@protonmail.com]splash.gif.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\deploy\[sysfrog@protonmail.com]splash@2x.gif.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\deploy\[sysfrog@protonmail.com]splash_11-lic.gif.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\deploy\[sysfrog@protonmail.com]splash_11@2x-lic.gif.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]deploy.jar.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\ext\[sysfrog@protonmail.com]access-bridge-64.jar.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\ext\[sysfrog@protonmail.com]cldrdata.jar.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\ext\[sysfrog@protonmail.com]dnsns.jar.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\ext\[sysfrog@protonmail.com]jfxrt.jar.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\ext\[sysfrog@protonmail.com]localedata.jar.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\ext\[sysfrog@protonmail.com]meta-index.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\ext\[sysfrog@protonmail.com]nashorn.jar.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\ext\[sysfrog@protonmail.com]sunec.jar.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\ext\[sysfrog@protonmail.com]sunmscapi.jar.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\ext\[sysfrog@protonmail.com]sunpkcs11.jar.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\ext\[sysfrog@protonmail.com]zipfs.jar.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]flavormap.properties.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]fontconfig.bfc.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]fontconfig.properties.src.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\fonts\[sysfrog@protonmail.com]LucidaBrightDemiBold.ttf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\fonts\[sysfrog@protonmail.com]LucidaBrightDemiItalic.ttf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\fonts\[sysfrog@protonmail.com]LucidaBrightItalic.ttf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\fonts\[sysfrog@protonmail.com]LucidaBrightRegular.ttf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\fonts\[sysfrog@protonmail.com]LucidaSansDemiBold.ttf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\fonts\[sysfrog@protonmail.com]LucidaTypewriterBold.ttf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\fonts\[sysfrog@protonmail.com]LucidaTypewriterRegular.ttf.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]hijrah-config-umalqura.properties.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\images\cursors\[sysfrog@protonmail.com]cursors.properties.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\images\cursors\[sysfrog@protonmail.com]win32_CopyDrop32x32.gif.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\images\cursors\[sysfrog@protonmail.com]win32_LinkDrop32x32.gif.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\images\cursors\[sysfrog@protonmail.com]win32_MoveDrop32x32.gif.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\images\cursors\[sysfrog@protonmail.com]invalid32x32.gif.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]javaws.jar.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]jce.jar.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\jfr\[sysfrog@protonmail.com]default.jfc.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\jfr\[sysfrog@protonmail.com]profile.jfc.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]jfr.jar.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]jfxswt.jar.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]jsse.jar.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]jvm.hprof.txt.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]logging.properties.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\management\[sysfrog@protonmail.com]jmxremote.access.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\management\[sysfrog@protonmail.com]jmxremote.password.template.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\management\[sysfrog@protonmail.com]management.properties.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\management\[sysfrog@protonmail.com]snmp.acl.template.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]management-agent.jar.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]meta-index.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]net.properties.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]plugin.jar.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]psfont.properties.ja.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Java\jre1.8.0_144\lib\[sysfrog@protonmail.com]resources.jar.sysfrog | Dropped File | Stream |
Not Queried
|
...
|
»