VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Gen:Variant.Graftor.681857
Mal/Generic-S
|
yislos.exe
Windows Exe (x86-32)
Created at 2020-04-17T15:29:00
Remarks
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4213c0 |
Size Of Code | 0x37200 |
Size Of Initialized Data | 0x1be00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-11-14 08:04:30+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x370cc | 0x37200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.61 |
.rdata | 0x439000 | 0xc820 | 0xca00 | 0x37600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.65 |
.data | 0x446000 | 0xc368 | 0xa200 | 0x44000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.32 |
.reloc | 0x453000 | 0x2e34 | 0x3000 | 0x4e200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.52 |
Imports (2)
»
KERNEL32.dll (103)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetLastError | 0x0 | 0x439000 | 0x44e54 | 0x43454 | 0x202 |
lstrcpynW | 0x0 | 0x439004 | 0x44e58 | 0x43458 | 0x54b |
GetFileSize | 0x0 | 0x439008 | 0x44e5c | 0x4345c | 0x1f0 |
SetFilePointer | 0x0 | 0x43900c | 0x44e60 | 0x43460 | 0x466 |
SetEndOfFile | 0x0 | 0x439010 | 0x44e64 | 0x43464 | 0x453 |
WriteFile | 0x0 | 0x439014 | 0x44e68 | 0x43468 | 0x525 |
ReadFile | 0x0 | 0x439018 | 0x44e6c | 0x4346c | 0x3c0 |
CreateFileW | 0x0 | 0x43901c | 0x44e70 | 0x43470 | 0x8f |
CloseHandle | 0x0 | 0x439020 | 0x44e74 | 0x43474 | 0x52 |
lstrcpyW | 0x0 | 0x439024 | 0x44e78 | 0x43478 | 0x548 |
GetTempPathW | 0x0 | 0x439028 | 0x44e7c | 0x4347c | 0x285 |
GetModuleHandleW | 0x0 | 0x43902c | 0x44e80 | 0x43480 | 0x218 |
GetProcAddress | 0x0 | 0x439030 | 0x44e84 | 0x43484 | 0x245 |
LoadLibraryA | 0x0 | 0x439034 | 0x44e88 | 0x43488 | 0x33c |
GetCurrentThread | 0x0 | 0x439038 | 0x44e8c | 0x4348c | 0x1c4 |
TerminateThread | 0x0 | 0x43903c | 0x44e90 | 0x43490 | 0x4c1 |
SetThreadPriority | 0x0 | 0x439040 | 0x44e94 | 0x43494 | 0x499 |
CreateThread | 0x0 | 0x439044 | 0x44e98 | 0x43498 | 0xb5 |
ExitProcess | 0x0 | 0x439048 | 0x44e9c | 0x4349c | 0x119 |
SetPriorityClass | 0x0 | 0x43904c | 0x44ea0 | 0x434a0 | 0x47d |
FindFirstFileW | 0x0 | 0x439050 | 0x44ea4 | 0x434a4 | 0x139 |
HeapAlloc | 0x0 | 0x439054 | 0x44ea8 | 0x434a8 | 0x2cb |
GetCurrentProcess | 0x0 | 0x439058 | 0x44eac | 0x434ac | 0x1c0 |
HeapFree | 0x0 | 0x43905c | 0x44eb0 | 0x434b0 | 0x2cf |
GetComputerNameW | 0x0 | 0x439060 | 0x44eb4 | 0x434b4 | 0x18f |
OutputDebugStringW | 0x0 | 0x439064 | 0x44eb8 | 0x434b8 | 0x38a |
GetProcessHeap | 0x0 | 0x439068 | 0x44ebc | 0x434bc | 0x24a |
OpenProcess | 0x0 | 0x43906c | 0x44ec0 | 0x434c0 | 0x380 |
WideCharToMultiByte | 0x0 | 0x439070 | 0x44ec4 | 0x434c4 | 0x511 |
LoadLibraryW | 0x0 | 0x439074 | 0x44ec8 | 0x434c8 | 0x33f |
GetModuleFileNameW | 0x0 | 0x439078 | 0x44ecc | 0x434cc | 0x214 |
MultiByteToWideChar | 0x0 | 0x43907c | 0x44ed0 | 0x434d0 | 0x367 |
lstrlenW | 0x0 | 0x439080 | 0x44ed4 | 0x434d4 | 0x54e |
FindClose | 0x0 | 0x439084 | 0x44ed8 | 0x434d8 | 0x12e |
Process32FirstW | 0x0 | 0x439088 | 0x44edc | 0x434dc | 0x396 |
Process32NextW | 0x0 | 0x43908c | 0x44ee0 | 0x434e0 | 0x398 |
lstrcmpiW | 0x0 | 0x439090 | 0x44ee4 | 0x434e4 | 0x545 |
CreateToolhelp32Snapshot | 0x0 | 0x439094 | 0x44ee8 | 0x434e8 | 0xbe |
GetVolumeInformationW | 0x0 | 0x439098 | 0x44eec | 0x434ec | 0x2a7 |
GetNativeSystemInfo | 0x0 | 0x43909c | 0x44ef0 | 0x434f0 | 0x225 |
VerSetConditionMask | 0x0 | 0x4390a0 | 0x44ef4 | 0x434f4 | 0x4e4 |
VerifyVersionInfoW | 0x0 | 0x4390a4 | 0x44ef8 | 0x434f8 | 0x4e8 |
GetModuleHandleA | 0x0 | 0x4390a8 | 0x44efc | 0x434fc | 0x215 |
FindNextFileW | 0x0 | 0x4390ac | 0x44f00 | 0x43500 | 0x145 |
GetDriveTypeW | 0x0 | 0x4390b0 | 0x44f04 | 0x43504 | 0x1d3 |
GetSystemDefaultUILanguage | 0x0 | 0x4390b4 | 0x44f08 | 0x43508 | 0x26e |
SetErrorMode | 0x0 | 0x4390b8 | 0x44f0c | 0x4350c | 0x458 |
GetLogicalDriveStringsW | 0x0 | 0x4390bc | 0x44f10 | 0x43510 | 0x208 |
GetUserDefaultUILanguage | 0x0 | 0x4390c0 | 0x44f14 | 0x43514 | 0x29e |
GetDiskFreeSpaceExW | 0x0 | 0x4390c4 | 0x44f18 | 0x43518 | 0x1ce |
CreateMutexW | 0x0 | 0x4390c8 | 0x44f1c | 0x4351c | 0x9e |
WaitForMultipleObjects | 0x0 | 0x4390cc | 0x44f20 | 0x43520 | 0x4f7 |
ReleaseMutex | 0x0 | 0x4390d0 | 0x44f24 | 0x43524 | 0x3fa |
WriteConsoleW | 0x0 | 0x4390d4 | 0x44f28 | 0x43528 | 0x524 |
SetStdHandle | 0x0 | 0x4390d8 | 0x44f2c | 0x4352c | 0x487 |
LoadLibraryExW | 0x0 | 0x4390dc | 0x44f30 | 0x43530 | 0x33e |
FreeEnvironmentStringsW | 0x0 | 0x4390e0 | 0x44f34 | 0x43534 | 0x161 |
GetEnvironmentStringsW | 0x0 | 0x4390e4 | 0x44f38 | 0x43538 | 0x1da |
GetCurrentProcessId | 0x0 | 0x4390e8 | 0x44f3c | 0x4353c | 0x1c1 |
QueryPerformanceCounter | 0x0 | 0x4390ec | 0x44f40 | 0x43540 | 0x3a7 |
GetModuleFileNameA | 0x0 | 0x4390f0 | 0x44f44 | 0x43544 | 0x213 |
GetConsoleMode | 0x0 | 0x4390f4 | 0x44f48 | 0x43548 | 0x1ac |
GetStringTypeW | 0x0 | 0x4390f8 | 0x44f4c | 0x4354c | 0x269 |
EncodePointer | 0x0 | 0x4390fc | 0x44f50 | 0x43550 | 0xea |
DecodePointer | 0x0 | 0x439100 | 0x44f54 | 0x43554 | 0xca |
EnterCriticalSection | 0x0 | 0x439104 | 0x44f58 | 0x43558 | 0xee |
LeaveCriticalSection | 0x0 | 0x439108 | 0x44f5c | 0x4355c | 0x339 |
DeleteCriticalSection | 0x0 | 0x43910c | 0x44f60 | 0x43560 | 0xd1 |
IsDebuggerPresent | 0x0 | 0x439110 | 0x44f64 | 0x43564 | 0x300 |
IsProcessorFeaturePresent | 0x0 | 0x439114 | 0x44f68 | 0x43568 | 0x304 |
HeapReAlloc | 0x0 | 0x439118 | 0x44f6c | 0x4356c | 0x2d2 |
GetCPInfo | 0x0 | 0x43911c | 0x44f70 | 0x43570 | 0x172 |
GetSystemTimeAsFileTime | 0x0 | 0x439120 | 0x44f74 | 0x43574 | 0x279 |
GetCommandLineA | 0x0 | 0x439124 | 0x44f78 | 0x43578 | 0x186 |
RaiseException | 0x0 | 0x439128 | 0x44f7c | 0x4357c | 0x3b1 |
RtlUnwind | 0x0 | 0x43912c | 0x44f80 | 0x43580 | 0x418 |
UnhandledExceptionFilter | 0x0 | 0x439130 | 0x44f84 | 0x43584 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x439134 | 0x44f88 | 0x43588 | 0x4a5 |
SetLastError | 0x0 | 0x439138 | 0x44f8c | 0x4358c | 0x473 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x43913c | 0x44f90 | 0x43590 | 0x2e3 |
Sleep | 0x0 | 0x439140 | 0x44f94 | 0x43594 | 0x4b2 |
TerminateProcess | 0x0 | 0x439144 | 0x44f98 | 0x43598 | 0x4c0 |
TlsAlloc | 0x0 | 0x439148 | 0x44f9c | 0x4359c | 0x4c5 |
TlsGetValue | 0x0 | 0x43914c | 0x44fa0 | 0x435a0 | 0x4c7 |
TlsSetValue | 0x0 | 0x439150 | 0x44fa4 | 0x435a4 | 0x4c8 |
TlsFree | 0x0 | 0x439154 | 0x44fa8 | 0x435a8 | 0x4c6 |
GetStartupInfoW | 0x0 | 0x439158 | 0x44fac | 0x435ac | 0x263 |
LCMapStringW | 0x0 | 0x43915c | 0x44fb0 | 0x435b0 | 0x32d |
GetLocaleInfoW | 0x0 | 0x439160 | 0x44fb4 | 0x435b4 | 0x206 |
IsValidLocale | 0x0 | 0x439164 | 0x44fb8 | 0x435b8 | 0x30c |
GetUserDefaultLCID | 0x0 | 0x439168 | 0x44fbc | 0x435bc | 0x29b |
EnumSystemLocalesW | 0x0 | 0x43916c | 0x44fc0 | 0x435c0 | 0x10f |
GetModuleHandleExW | 0x0 | 0x439170 | 0x44fc4 | 0x435c4 | 0x217 |
GetStdHandle | 0x0 | 0x439174 | 0x44fc8 | 0x435c8 | 0x264 |
HeapSize | 0x0 | 0x439178 | 0x44fcc | 0x435cc | 0x2d4 |
IsValidCodePage | 0x0 | 0x43917c | 0x44fd0 | 0x435d0 | 0x30a |
GetACP | 0x0 | 0x439180 | 0x44fd4 | 0x435d4 | 0x168 |
GetOEMCP | 0x0 | 0x439184 | 0x44fd8 | 0x435d8 | 0x237 |
GetCurrentThreadId | 0x0 | 0x439188 | 0x44fdc | 0x435dc | 0x1c5 |
GetFileType | 0x0 | 0x43918c | 0x44fe0 | 0x435e0 | 0x1f3 |
SetFilePointerEx | 0x0 | 0x439190 | 0x44fe4 | 0x435e4 | 0x467 |
FlushFileBuffers | 0x0 | 0x439194 | 0x44fe8 | 0x435e8 | 0x157 |
GetConsoleCP | 0x0 | 0x439198 | 0x44fec | 0x435ec | 0x19a |
SHLWAPI.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StrCmpIW | 0x0 | 0x4391a0 | 0x44ff4 | 0x435f4 | 0x119 |
StrStrIW | 0x0 | 0x4391a4 | 0x44ff8 | 0x435f8 | 0x145 |
PathRenameExtensionW | 0x0 | 0x4391a8 | 0x44ffc | 0x435fc | 0x8d |
PathAppendW | 0x0 | 0x4391ac | 0x45000 | 0x43600 | 0x34 |
PathFindExtensionW | 0x0 | 0x4391b0 | 0x45004 | 0x43604 | 0x47 |
SHGetValueW | 0x0 | 0x4391b4 | 0x45008 | 0x43608 | 0xc2 |
wvnsprintfW | 0x0 | 0x4391b8 | 0x4500c | 0x4360c | 0x170 |
SHSetValueW | 0x0 | 0x4391bc | 0x45010 | 0x43610 | 0xfc |
Exports (1)
»
Api name | EAT Address | Ordinal |
---|---|---|
Fuck | 0x18b80 | 0x1 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
yislos.exe | 1 | 0x01030000 | 0x01085FFF | Relevant Image |
![]() |
32-bit | 0x01057BC2 |
![]() |
![]() |
...
|
yislos.exe | 1 | 0x01030000 | 0x01085FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Graftor.681857 |
Malicious
|
C:\Users\Public\Desktop\Acrobat Reader DC.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Desktop\Google Chrome.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Desktop\Mozilla Firefox.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Links\Desktop.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Links\OneDrive.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\3mc8whJq4J.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\7bGX.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\bY4h.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\F4UsVJv9SPZz9-o6h.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\g4L WGpAje2Nf_v7ku.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\GgVQ2q4UA2k6 gvhu.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\gpg4Hw5MnMMD-Iw.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\KrEa9-E.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\mQosc.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nwcakcVrh1SvkLBgBe.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\qfZH6BDUPHStrWPe.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\QIpZKXvu12LVP7LS.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\R3pSASHldK3su3FX.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\rWiqtTJgPRv.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Ry ozc2nkpYvruU.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\R_vngGONOQYnQUhcJ1.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\sSOeGW2iTb7cW9YFJkw.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\STtSEHUc.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\U73Q8j.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\W2YfDwtZ_sjDhhr.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Zv6qQPw9FGgcmA-HC.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\OJ4nR9uFX\pA6nu9_HbfRvQIhbUV.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\OJ4nR9uFX\TG4AI3LIpEJH9vI6NUcD.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\OJ4nR9uFX\v1B4.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\OJ4nR9uFX\ATEy\B1x9u.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\OJ4nR9uFX\ATEy\rm1XA-E8GcBu6.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\OJ4nR9uFX\ATEy\rpb2xsfseSHp7ryVw4Ap.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\OJ4nR9uFX\ATEy\m0aZd64h9kU\1ukdYB.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\OJ4nR9uFX\ATEy\m0aZd64h9kU\AdMpcd.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\OJ4nR9uFX\ATEy\m0aZd64h9kU\CIW2lshKxYJMrzFHJu.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\OJ4nR9uFX\ATEy\m0aZd64h9kU\Gcou.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\OJ4nR9uFX\ATEy\m0aZd64h9kU\IRuYOiWOLC29ab74.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\OJ4nR9uFX\ATEy\m0aZd64h9kU\zhDZS-59B_BfEOF.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\OJ4nR9uFX\ATEy\m0aZd64h9kU\ZLYRD.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\OJ4nR9uFX\ATEy\lRTIX5CrYBz6_\2-3kVm2Kq9.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\OJ4nR9uFX\ATEy\lRTIX5CrYBz6_\CZhP8C.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\OJ4nR9uFX\ATEy\lRTIX5CrYBz6_\JSGnt38elKMjAcL7w8P.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\OJ4nR9uFX\ATEy\lRTIX5CrYBz6_\k25TI-C46OFkmk.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\OJ4nR9uFX\ATEy\lRTIX5CrYBz6_\P2HkU9Ieols.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Dg_r.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\HUqaBv5kt9m.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\kK4HLR.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\pHha-hF7.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\RRyHpc7SHCdX.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\wSIL8kwuhXjie6YnFW.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\YTBLqM0A.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\AfcyeVmor6Z ie9ka9RA\aISt_8NjGjxmBB4U.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\AfcyeVmor6Z ie9ka9RA\cG6ULjQumwrr.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\AfcyeVmor6Z ie9ka9RA\F92z61.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\AfcyeVmor6Z ie9ka9RA\s3iUn5zcMJiuB.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\ARBUa1r.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\j9R7zGn.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\modBUy AY0gShdXQrwb.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\AlternateServices.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\blocklist.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\cert8.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\key3.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\revocations.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\secmod.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\SecurityPreloadState.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\SiteSecurityServiceState.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\gmp-widevinecdm\1.4.8.903\LICENSE.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Adobe\Sonar\Sonar1.0\sonar_policy.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01 - Command Prompt.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\01a - Windows PowerShell.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02 - Command Prompt.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\02a - Windows PowerShell.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\03 - Computer Management.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04-1 - NetworkStatus.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\05 - Device Manager.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\06 - SystemAbout.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\09 - Mobility Center.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\10 - AppsAndFeatures.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\1 - Run.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\2 - Search.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\3 - Windows Explorer.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\4 - Control Panel.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group2\5 - Task Manager.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group1\1 - Desktop.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\AppData\Local\Microsoft\Windows\Shell\DefaultLayouts.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Strings.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\UiInfo.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\Parameterinfo.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\UiInfo.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\Parameterinfo.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\UiInfo.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\eula.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\LocalizedData.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\PartnerSetupCompleteResult.A5B043 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Macromedia\A5B043-DECRYPT.txt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Links\Downloads.A5B043 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Mozilla\Firefox\Profiles\w7cr0hor.default\parent.A5B043 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\04 - Disk Management.A5B043 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\07 - Event Viewer.A5B043 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\AppData\Local\Microsoft\Windows\WinX\Group3\08 - PowerAndSleep.A5B043 | Dropped File | Stream |
Not Queried
|
...
|
»