VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Sodinokibi
Generic.Ransom.Conti.57C16005
Generic.Ransom.Conti.52C2C0AF
...
|
5-436.malware.exe
Windows Exe (x86-32)
Created at 2020-10-23T09:19:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x41773a |
Size Of Code | 0x21e00 |
Size Of Initialized Data | 0xa800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-09-04 12:27:56+00:00 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x21cf6 | 0x21e00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.52 |
.rdata | 0x423000 | 0x60e6 | 0x6200 | 0x22200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.88 |
.data | 0x42a000 | 0x2be4 | 0x2200 | 0x28400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.76 |
.gfids | 0x42d000 | 0x11c | 0x200 | 0x2a600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.31 |
.rsrc | 0x42e000 | 0x1e0 | 0x200 | 0x2a800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.72 |
.reloc | 0x42f000 | 0x1518 | 0x1600 | 0x2aa00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.5 |
Imports (5)
»
USER32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
wvsprintfW | 0x0 | 0x423124 | 0x28b10 | 0x27d10 | 0x335 |
wsprintfW | 0x0 | 0x423128 | 0x28b14 | 0x27d14 | 0x333 |
ole32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoCreateInstance | 0x0 | 0x423140 | 0x28b2c | 0x27d2c | 0x10 |
CoUninitialize | 0x0 | 0x423144 | 0x28b30 | 0x27d30 | 0x6c |
CoInitializeSecurity | 0x0 | 0x423148 | 0x28b34 | 0x27d34 | 0x40 |
CoInitializeEx | 0x0 | 0x42314c | 0x28b38 | 0x27d38 | 0x3f |
CoSetProxyBlanket | 0x0 | 0x423150 | 0x28b3c | 0x27d3c | 0x63 |
OLEAUT32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VariantClear | 0x9 | 0x423114 | 0x28b00 | 0x27d00 | - |
SysAllocString | 0x2 | 0x423118 | 0x28b04 | 0x27d04 | - |
VariantInit | 0x8 | 0x42311c | 0x28b08 | 0x27d08 | - |
WS2_32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
inet_ntoa | 0xc | 0x423130 | 0x28b1c | 0x27d1c | - |
htons | 0x9 | 0x423134 | 0x28b20 | 0x27d20 | - |
WSAGetLastError | 0x6f | 0x423138 | 0x28b24 | 0x27d24 | - |
KERNEL32.dll (68)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetStdHandle | 0x0 | 0x423000 | 0x289ec | 0x27bec | 0x264 |
DecodePointer | 0x0 | 0x423004 | 0x289f0 | 0x27bf0 | 0xca |
EncodePointer | 0x0 | 0x423008 | 0x289f4 | 0x27bf4 | 0xea |
WriteConsoleW | 0x0 | 0x42300c | 0x289f8 | 0x27bf8 | 0x524 |
SetFilePointerEx | 0x0 | 0x423010 | 0x289fc | 0x27bfc | 0x467 |
GetConsoleMode | 0x0 | 0x423014 | 0x28a00 | 0x27c00 | 0x1ac |
GetConsoleCP | 0x0 | 0x423018 | 0x28a04 | 0x27c04 | 0x19a |
FlushFileBuffers | 0x0 | 0x42301c | 0x28a08 | 0x27c08 | 0x157 |
HeapReAlloc | 0x0 | 0x423020 | 0x28a0c | 0x27c0c | 0x2d2 |
HeapSize | 0x0 | 0x423024 | 0x28a10 | 0x27c10 | 0x2d4 |
GetProcessHeap | 0x0 | 0x423028 | 0x28a14 | 0x27c14 | 0x24a |
GetStringTypeW | 0x0 | 0x42302c | 0x28a18 | 0x27c18 | 0x269 |
GetFileType | 0x0 | 0x423030 | 0x28a1c | 0x27c1c | 0x1f3 |
SetStdHandle | 0x0 | 0x423034 | 0x28a20 | 0x27c20 | 0x487 |
LoadLibraryA | 0x0 | 0x423038 | 0x28a24 | 0x27c24 | 0x33c |
GetProcAddress | 0x0 | 0x42303c | 0x28a28 | 0x27c28 | 0x245 |
CloseHandle | 0x0 | 0x423040 | 0x28a2c | 0x27c2c | 0x52 |
InitializeCriticalSection | 0x0 | 0x423044 | 0x28a30 | 0x27c30 | 0x2e2 |
SetFilePointer | 0x0 | 0x423048 | 0x28a34 | 0x27c34 | 0x466 |
GetLocalTime | 0x0 | 0x42304c | 0x28a38 | 0x27c38 | 0x203 |
UnhandledExceptionFilter | 0x0 | 0x423050 | 0x28a3c | 0x27c3c | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x423054 | 0x28a40 | 0x27c40 | 0x4a5 |
GetCurrentProcess | 0x0 | 0x423058 | 0x28a44 | 0x27c44 | 0x1c0 |
TerminateProcess | 0x0 | 0x42305c | 0x28a48 | 0x27c48 | 0x4c0 |
IsProcessorFeaturePresent | 0x0 | 0x423060 | 0x28a4c | 0x27c4c | 0x304 |
QueryPerformanceCounter | 0x0 | 0x423064 | 0x28a50 | 0x27c50 | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x423068 | 0x28a54 | 0x27c54 | 0x1c1 |
GetCurrentThreadId | 0x0 | 0x42306c | 0x28a58 | 0x27c58 | 0x1c5 |
GetSystemTimeAsFileTime | 0x0 | 0x423070 | 0x28a5c | 0x27c5c | 0x279 |
InitializeSListHead | 0x0 | 0x423074 | 0x28a60 | 0x27c60 | 0x2e7 |
IsDebuggerPresent | 0x0 | 0x423078 | 0x28a64 | 0x27c64 | 0x300 |
GetStartupInfoW | 0x0 | 0x42307c | 0x28a68 | 0x27c68 | 0x263 |
GetModuleHandleW | 0x0 | 0x423080 | 0x28a6c | 0x27c6c | 0x218 |
RaiseException | 0x0 | 0x423084 | 0x28a70 | 0x27c70 | 0x3b1 |
RtlUnwind | 0x0 | 0x423088 | 0x28a74 | 0x27c74 | 0x418 |
GetLastError | 0x0 | 0x42308c | 0x28a78 | 0x27c78 | 0x202 |
SetLastError | 0x0 | 0x423090 | 0x28a7c | 0x27c7c | 0x473 |
EnterCriticalSection | 0x0 | 0x423094 | 0x28a80 | 0x27c80 | 0xee |
LeaveCriticalSection | 0x0 | 0x423098 | 0x28a84 | 0x27c84 | 0x339 |
DeleteCriticalSection | 0x0 | 0x42309c | 0x28a88 | 0x27c88 | 0xd1 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4230a0 | 0x28a8c | 0x27c8c | 0x2e3 |
TlsAlloc | 0x0 | 0x4230a4 | 0x28a90 | 0x27c90 | 0x4c5 |
TlsGetValue | 0x0 | 0x4230a8 | 0x28a94 | 0x27c94 | 0x4c7 |
TlsSetValue | 0x0 | 0x4230ac | 0x28a98 | 0x27c98 | 0x4c8 |
TlsFree | 0x0 | 0x4230b0 | 0x28a9c | 0x27c9c | 0x4c6 |
FreeLibrary | 0x0 | 0x4230b4 | 0x28aa0 | 0x27ca0 | 0x162 |
LoadLibraryExW | 0x0 | 0x4230b8 | 0x28aa4 | 0x27ca4 | 0x33e |
CreateFileW | 0x0 | 0x4230bc | 0x28aa8 | 0x27ca8 | 0x8f |
WriteFile | 0x0 | 0x4230c0 | 0x28aac | 0x27cac | 0x525 |
GetModuleFileNameA | 0x0 | 0x4230c4 | 0x28ab0 | 0x27cb0 | 0x213 |
MultiByteToWideChar | 0x0 | 0x4230c8 | 0x28ab4 | 0x27cb4 | 0x367 |
WideCharToMultiByte | 0x0 | 0x4230cc | 0x28ab8 | 0x27cb8 | 0x511 |
ExitProcess | 0x0 | 0x4230d0 | 0x28abc | 0x27cbc | 0x119 |
GetModuleHandleExW | 0x0 | 0x4230d4 | 0x28ac0 | 0x27cc0 | 0x217 |
GetACP | 0x0 | 0x4230d8 | 0x28ac4 | 0x27cc4 | 0x168 |
HeapFree | 0x0 | 0x4230dc | 0x28ac8 | 0x27cc8 | 0x2cf |
HeapAlloc | 0x0 | 0x4230e0 | 0x28acc | 0x27ccc | 0x2cb |
FindClose | 0x0 | 0x4230e4 | 0x28ad0 | 0x27cd0 | 0x12e |
FindFirstFileExA | 0x0 | 0x4230e8 | 0x28ad4 | 0x27cd4 | 0x133 |
FindNextFileA | 0x0 | 0x4230ec | 0x28ad8 | 0x27cd8 | 0x143 |
IsValidCodePage | 0x0 | 0x4230f0 | 0x28adc | 0x27cdc | 0x30a |
GetOEMCP | 0x0 | 0x4230f4 | 0x28ae0 | 0x27ce0 | 0x237 |
GetCPInfo | 0x0 | 0x4230f8 | 0x28ae4 | 0x27ce4 | 0x172 |
GetCommandLineA | 0x0 | 0x4230fc | 0x28ae8 | 0x27ce8 | 0x186 |
GetCommandLineW | 0x0 | 0x423100 | 0x28aec | 0x27cec | 0x187 |
GetEnvironmentStringsW | 0x0 | 0x423104 | 0x28af0 | 0x27cf0 | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x423108 | 0x28af4 | 0x27cf4 | 0x161 |
LCMapStringW | 0x0 | 0x42310c | 0x28af8 | 0x27cf8 | 0x32d |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
5-436.malware.exe | 1 | 0x01170000 | 0x011A0FFF | Relevant Image | 32-bit | 0x011887E6 |
...
|
|||
5-436.malware.exe | 1 | 0x01170000 | 0x011A0FFF | Final Dump | 32-bit | 0x0118A5A6 |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Ransom.Conti.57C16005 |
Malicious
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
SodinokibiEncryptedFile | File encrypted by Sodinokibi Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\DHtmlHeader.html.AWSAK | Dropped File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.xml.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DisplayIcon.ico.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Strings.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Key Management Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Known Folders API Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Admin.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Store%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Windows PowerShell.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\desktop.ini.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Recovery\ReAgentOld.xml.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\preoobe.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd.AWSAK | Dropped File | Batch |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\eula.rtf.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\LocalizedData.xml.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\LocalizedData.xml.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\LocalizedData.xml.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\eula.rtf.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\LocalizedData.xml.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\LocalizedData.xml.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\LocalizedData.xml.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\LocalizedData.xml.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\Parameterinfo.xml.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\UiInfo.xml.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Print.ico.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\Parameterinfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate1.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate4.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\UiInfo.xml.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate5.ico.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate8.ico.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Setup.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate6.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Save.ico.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\warn.ico.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\application.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\crashreporter.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\dependentlibs.list | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\nssdbm3.chk.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\install.log | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\platform.ini.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\precomplete.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\removed-files | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\rempl\rempl.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\updater.ini.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\rempl\Unlock.xml.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Extensibility Component.swidtag.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Licensing Component.swidtag | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TM.blf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT.LOG1 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{fae9930d-933c-11e7-a51d-b808901d6c9b}.TM.blf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{fae9930d-933c-11e7-a51d-b808901d6c9b}.TMContainer00000000000000000002.regtrans-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core.mzz.AWSAK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\R3ADM3.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\UiInfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Internet Explorer.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Application.evtx.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-International%4Operational.evtx.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\SetupComplete.cmd.AWSAK | Dropped File | Batch |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.xml.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1028\LocalizedData.xml.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1033\eula.rtf.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1033\LocalizedData.xml.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1041\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1042\LocalizedData.xml.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1046\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1049\LocalizedData.xml.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1055\eula.rtf.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1055\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3076\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate2.ico.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate3.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate7.ico.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\stop.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqMet.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\FileSystemMetadata.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\Accessible.tlb.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\freebl3.chk.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\firefox.VisualElementsManifest.xml.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\softokn3.chk.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\update-settings.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\AppXManifest.xml.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\Task.xml.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Mozilla Maintenance Service\updater.ini.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Localization Component.swidtag.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft_Windows-10-Pro.swidtag.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\omni.ja | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT.LOG2.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TMContainer00000000000000000002.regtrans-ms | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TMContainer00000000000000000001.regtrans-ms.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT{fae9930d-933c-11e7-a51d-b808901d6c9b}.TMContainer00000000000000000001.regtrans-ms.AWSAK | Dropped File | Stream |
Not Queried
|
...
|
»