VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: | - |
Threat Names: |
Gen:Heur.Dreidel.Tq1@waSGh9ii
DeepScan:Generic.Ransom.Cuba.9B516AC6
DeepScan:Generic.Ransom.Cuba.56429D50
...
|
CC.exe
Windows Exe (x86-32)
Created at 2020-06-05T00:09:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4909f0 |
Size Of Code | 0x90600 |
Size Of Initialized Data | 0x21000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2002-02-07 17:40:55+00:00 |
Version Information (1)
»
CompanyName | ftware a.s. |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x90510 | 0x90600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.5 |
.rdata | 0x492000 | 0x1dd59 | 0x1de00 | 0x90a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.01 |
.data | 0x4b0000 | 0xf2c | 0x1000 | 0xae800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.87 |
.rsrc | 0x4b1000 | 0x2194 | 0x2200 | 0xaf800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.45 |
Imports (4)
»
KERNEL32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VirtualAlloc | 0x0 | 0x4b0d5c | 0xb0d1c | 0xaf51c | 0x454 |
GetModuleHandleA | 0x0 | 0x4b0d60 | 0xb0d20 | 0xaf520 | 0x1f6 |
ExitProcess | 0x0 | 0x4b0d64 | 0xb0d24 | 0xaf524 | 0x104 |
SetErrorMode | 0x0 | 0x4b0d68 | 0xb0d28 | 0xaf528 | 0x3d2 |
USER32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadCursorFromFileW | 0x0 | 0x4b0d70 | 0xb0d30 | 0xaf530 | 0x1d4 |
GetCaretBlinkTime | 0x0 | 0x4b0d74 | 0xb0d34 | 0xaf534 | 0x102 |
GetThreadDesktop | 0x0 | 0x4b0d78 | 0xb0d38 | 0xaf538 | 0x173 |
IsIconic | 0x0 | 0x4b0d7c | 0xb0d3c | 0xaf53c | 0x1bd |
GetCapture | 0x0 | 0x4b0d80 | 0xb0d40 | 0xaf540 | 0x101 |
GDI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetLayout | 0x0 | 0x4b0d88 | 0xb0d48 | 0xaf548 | 0x1d4 |
ADVAPI32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegOpenKeyExA | 0x0 | 0x4b0d90 | 0xb0d50 | 0xaf550 | 0x25a |
RegQueryValueExA | 0x0 | 0x4b0d94 | 0xb0d54 | 0xaf554 | 0x267 |
Digital Signatures (1)
»
Certificate: WATUMQAQGBVDTECTGC
»
Issued by | WATUMQAQGBVDTECTGC |
Country Name | - |
Valid From | 2020-03-07 07:27:29+00:00 |
Valid Until | 2039-12-31 23:59:59+00:00 |
Algorithm | sha1_rsa |
Serial Number | C8 D2 D5 C9 C0 0B 3E AB 43 94 FE 15 62 22 A4 49 |
Thumbprint | 42 79 3B 1C C7 0B 9A 3A 54 63 47 53 7E 95 B7 FB 4D 5F 1F 6E |
Memory Dumps (5)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
cc.exe | 1 | 0x00400000 | 0x004B3FFF | Relevant Image |
![]() |
32-bit | 0x0048FC40 |
![]() |
![]() |
...
|
buffer | 1 | 0x005D0000 | 0x00651FFF | First Execution |
![]() |
32-bit | 0x00650FC0 |
![]() |
![]() |
...
|
cc.exe | 1 | 0x00400000 | 0x004B3FFF | Content Changed |
![]() |
32-bit | 0x00401220 |
![]() |
![]() |
...
|
buffer | 1 | 0x00780000 | 0x00800FFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
cc.exe | 1 | 0x00400000 | 0x004B3FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
C:\program files\common files\microsoft shared\ink\es-es\!!FAQ for Decryption!!.txt | Dropped File | Text |
Blacklisted
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
C:\$getcurrent\logs\downlevel_2017_09_07_02_02_39_766.log | Modified File | Unknown |
Unknown
|
...
|
»
C:\$getcurrent\logs\oobe_2017_09_07_03_08_57_737.log | Modified File | Unknown |
Unknown
|
...
|
»
C:\$getcurrent\logs\partnersetupcompleteresult.log.cuba | Dropped File | Unknown |
Unknown
|
...
|
»
C:\$getcurrent\safeos\getcurrentrollback.ini.cuba | Dropped File | Unknown |
Unknown
|
...
|
»
C:\$getcurrent\safeos\setupcomplete.cmd | Modified File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf | Modified File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\localizeddata.xml | Modified File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\eula.rtf.cuba | Dropped File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\localizeddata.xml.cuba | Dropped File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\eula.rtf | Modified File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\localizeddata.xml.cuba | Dropped File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf | Modified File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf.cuba | Dropped File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\localizeddata.xml.cuba | Dropped File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf | Modified File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\localizeddata.xml | Modified File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\eula.rtf | Modified File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\localizeddata.xml.cuba | Dropped File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf | Modified File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\localizeddata.xml | Modified File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf | Modified File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf.cuba | Dropped File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\localizeddata.xml | Modified File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf.cuba | Dropped File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\localizeddata.xml.cuba | Dropped File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf.cuba | Dropped File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\localizeddata.xml | Modified File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\eula.rtf.cuba | Dropped File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\localizeddata.xml.cuba | Dropped File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf.cuba | Dropped File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\localizeddata.xml.cuba | Dropped File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\localizeddata.xml | Modified File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\localizeddata.xml | Modified File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\eula.rtf.cuba | Dropped File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\localizeddata.xml.cuba | Dropped File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\localizeddata.xml.cuba | Dropped File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\localizeddata.xml | Modified File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\eula.rtf | Modified File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf.cuba | Dropped File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\localizeddata.xml.cuba | Dropped File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\localizeddata.xml.cuba | Dropped File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\localizeddata.xml | Modified File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf | Modified File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\localizeddata.xml | Modified File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\client\parameterinfo.xml | Modified File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\client\uiinfo.xml | Modified File | Unknown |
Unknown
|
...
|
»
C:\588bce7c90097ed212\dhtmlheader.html.cuba | Dropped File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\displayicon.ico.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\extended\parameterinfo.xml.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\extended\uiinfo.xml.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\graphics\print.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\graphics\rotate1.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\graphics\rotate2.ico.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\graphics\rotate3.ico.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\graphics\rotate4.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\graphics\rotate5.ico.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\graphics\rotate6.ico.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\graphics\rotate7.ico.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\graphics\save.ico.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\graphics\sysreqmet.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\graphics\warn.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_extended.mzz | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_extended_x64.msi.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_extended_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\parameterinfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\rgb9rast_x64.msi.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\rgb9rast_x86.msi.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\setupui.xsd | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\windows6.0-kb956250-v6001-x86.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\windows6.1-kb958488-v6001-x64.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\windows6.1-kb958488-v6001-x86.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-client-licensing-platform%4admin.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-application-experience%4program-compatibility-assistant.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-applicationresourcemanagementsystem%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-applocker%4msi and script.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-applocker%4packaged app-execution.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-appmodel-runtime%4admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-appreadiness%4admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-appreadiness%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-appxdeploymentserver%4restricted.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-appxpackaging%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-backgroundtaskinfrastructure%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-bits-client%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-codeintegrity%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-coresystem-smsrouter-events%4operational.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-crypto-dpapi%4backupkeysvc.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-crypto-dpapi%4operational.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-devicemanagement-enterprise-diagnostics-provider%4admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-devicesetupmanager%4admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-devicesetupmanager%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-dhcpv6-client%4admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-diagnosis-dps%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-grouppolicy%4operational.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-hotspotauth%4operational.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-international%4operational.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-kernel-boot%4operational.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-kernel-eventtracing%4admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-kernel-shimengine%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-kernel-storemgr%4operational.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-kernel-whea%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-known folders api service.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-liveid%4operational.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-mui%4admin.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-mui%4operational.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-ncsi%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-ntfs%4operational.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-ntfs%4whc.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-resource-exhaustion-detector%4operational.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-settingsync%4debug.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-shell-core%4actioncenter.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-shell-core%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-smbclient%4connectivity.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-smbclient%4operational.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-smbserver%4connectivity.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-smbserver%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-smbserver%4security.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-store%4operational.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-taskscheduler%4maintenance.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-terminalservices-localsessionmanager%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-twinui%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-user profile service%4operational.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-userpnp%4actioncenter.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-userpnp%4deviceinstall.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-volumesnapshot-driver%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-wcmsvc%4operational.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-windows defender%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-windows defender%4whc.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-windows firewall with advanced security%4connectionsecurity.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-windows firewall with advanced security%4firewall.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-wininet-config%4proxyconfigchanged.evtx.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\logs\microsoft-windows-wmi-activity%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\logs\windows powershell.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\program files\common files\designer\msaddndr.olb.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\program files\common files\microsoft shared\clicktorun\c2rheartbeatconfig.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\program files\common files\microsoft shared\clicktorun\officeupdateschedule.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\program files\common files\microsoft shared\clicktorun\servicewatcherschedule.xml.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\program files\common files\microsoft shared\office16\office setup controller\pkeyconfig-office.xrm-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\program files\common files\microsoft shared\vsto\vstoee100.tlb.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\program files\common files\microsoft shared\vsto\vstoee90.tlb | Modified File | Stream |
Unknown
|
...
|
»
C:\program files\internet explorer\signup\install.ins.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\program files\java\jre1.8.0_144\bin\javacpl.cpl | Modified File | Stream |
Unknown
|
...
|
»
C:\program files\java\jre1.8.0_144\bin\server\xusage.txt.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\program files\java\jre1.8.0_144\copyright.cuba | Dropped File | Stream |
Unknown
|
...
|
»
C:\program files\java\jre1.8.0_144\lib\accessibility.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\$getcurrent\safeos\partnersetupcomplete.cmd.cuba | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\$getcurrent\safeos\preoobe.cmd.cuba | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1030\localizeddata.xml | Modified File | Unknown |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1036\localizeddata.xml.cuba | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1043\eula.rtf | Modified File | Unknown |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1044\eula.rtf | Modified File | Unknown |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf | Modified File | Unknown |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\localizeddata.xml.cuba | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf.cuba | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1053\eula.rtf | Modified File | Unknown |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1055\localizeddata.xml | Modified File | Unknown |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf | Modified File | Unknown |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3076\eula.rtf.cuba | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\graphics\rotate8.ico.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\graphics\setup.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\graphics\stop.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\graphics\sysreqnotmet.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_core.mzz.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_core_x64.msi.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_core_x86.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\splashscreen.bmp.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\strings.xml.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\uiinfo.xml.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\windows6.0-kb956250-v6001-x64.msu | Modified File | Stream |
Not Queried
|
...
|
»
C:\logs\hardwareevents.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\logs\key management service.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\logs\microsoft-windows-applocker%4exe and dll.evtx.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
C:\logs\microsoft-windows-applocker%4packaged app-deployment.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\logs\microsoft-windows-appxdeployment%4operational.evtx.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
C:\logs\microsoft-windows-appxdeploymentserver%4operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\logs\microsoft-windows-dhcp-client%4admin.evtx.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
C:\logs\microsoft-windows-diagnostics-performance%4operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\logs\microsoft-windows-hyper-v-guest-drivers%4admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\logs\microsoft-windows-kernel-pnp%4configuration.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\logs\microsoft-windows-kernel-power%4thermal-operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\logs\microsoft-windows-kernel-whea%4errors.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\logs\microsoft-windows-networkprofile%4operational.evtx.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
C:\logs\microsoft-windows-program-compatibility-assistant%4compatafterupgrade.evtx.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
C:\logs\microsoft-windows-readyboost%4operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\logs\microsoft-windows-settingsync%4operational.evtx.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
C:\logs\microsoft-windows-smbclient%4security.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\logs\microsoft-windows-smbserver%4audit.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\logs\microsoft-windows-terminalservices-localsessionmanager%4admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\logs\microsoft-windows-terminalservices-remoteconnectionmanager%4admin.evtx.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
C:\logs\microsoft-windows-terminalservices-remoteconnectionmanager%4operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\logs\microsoft-windows-winlogon%4operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\program files\common files\microsoft shared\clicktorun\i640.hash.cuba | Dropped File | Stream |
Not Queried
|
...
|
»
C:\program files\common files\microsoft shared\clicktorun\i641033.hash.cuba | Dropped File | Stream |
Not Queried
|
...
|
»