VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: | - |
Threat Names: |
Gen:Trojan.Heur2.GZ.mrX@bmb3WclG
Gen:Variant.Fugrafa.33435
|
Ks6GqEtV8vklDvKf.exe
Windows Exe (x86-32)
Created at 2020-04-19T06:54:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\Ks6GqEtV8vklDvKf.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x40609d |
Size Of Code | 0x52800 |
Size Of Initialized Data | 0xde600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-08-22 20:10:34+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x526b6 | 0x52800 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.89 |
.data | 0x454000 | 0xc73e8 | 0x11800 | 0x52c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.35 |
.tls | 0x51c000 | 0x1009 | 0x1200 | 0x64400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x51e000 | 0x13c28 | 0x13e00 | 0x65600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.05 |
Imports (2)
»
KERNEL32.dll (74)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SleepEx | 0x0 | 0x40100c | 0x52fec | 0x523ec | 0x4b5 |
GetModuleHandleW | 0x0 | 0x401010 | 0x52ff0 | 0x523f0 | 0x218 |
GetTickCount | 0x0 | 0x401014 | 0x52ff4 | 0x523f4 | 0x293 |
WriteFile | 0x0 | 0x401018 | 0x52ff8 | 0x523f8 | 0x525 |
SizeofResource | 0x0 | 0x40101c | 0x52ffc | 0x523fc | 0x4b1 |
GetAtomNameW | 0x0 | 0x401020 | 0x53000 | 0x52400 | 0x16e |
FindFirstFileExW | 0x0 | 0x401024 | 0x53004 | 0x52404 | 0x134 |
lstrlenW | 0x0 | 0x401028 | 0x53008 | 0x52408 | 0x54e |
GetTempPathW | 0x0 | 0x40102c | 0x5300c | 0x5240c | 0x285 |
GetNamedPipeHandleStateW | 0x0 | 0x401030 | 0x53010 | 0x52410 | 0x221 |
GetLastError | 0x0 | 0x401034 | 0x53014 | 0x52414 | 0x202 |
GetProcAddress | 0x0 | 0x401038 | 0x53018 | 0x52418 | 0x245 |
LocalAlloc | 0x0 | 0x40103c | 0x5301c | 0x5241c | 0x344 |
WritePrivateProfileStringA | 0x0 | 0x401040 | 0x53020 | 0x52420 | 0x52a |
GlobalWire | 0x0 | 0x401044 | 0x53024 | 0x52424 | 0x2c6 |
GetConsoleCursorInfo | 0x0 | 0x401048 | 0x53028 | 0x52428 | 0x1a0 |
SetComputerNameW | 0x0 | 0x40104c | 0x5302c | 0x5242c | 0x42a |
CompareFileTime | 0x0 | 0x401050 | 0x53030 | 0x52430 | 0x60 |
InterlockedDecrement | 0x0 | 0x401054 | 0x53034 | 0x52434 | 0x2eb |
HeapAlloc | 0x0 | 0x401058 | 0x53038 | 0x52438 | 0x2cb |
FindResourceW | 0x0 | 0x40105c | 0x5303c | 0x5243c | 0x14e |
DebugActiveProcessStop | 0x0 | 0x401060 | 0x53040 | 0x52440 | 0xc6 |
GetLocaleInfoA | 0x0 | 0x401064 | 0x53044 | 0x52444 | 0x204 |
ReadFile | 0x0 | 0x401068 | 0x53048 | 0x52448 | 0x3c0 |
GetCommandLineW | 0x0 | 0x40106c | 0x5304c | 0x5244c | 0x187 |
GetCommandLineA | 0x0 | 0x401070 | 0x53050 | 0x52450 | 0x186 |
HeapSetInformation | 0x0 | 0x401074 | 0x53054 | 0x52454 | 0x2d3 |
GetStartupInfoW | 0x0 | 0x401078 | 0x53058 | 0x52458 | 0x263 |
RaiseException | 0x0 | 0x40107c | 0x5305c | 0x5245c | 0x3b1 |
TerminateProcess | 0x0 | 0x401080 | 0x53060 | 0x52460 | 0x4c0 |
GetCurrentProcess | 0x0 | 0x401084 | 0x53064 | 0x52464 | 0x1c0 |
UnhandledExceptionFilter | 0x0 | 0x401088 | 0x53068 | 0x52468 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x40108c | 0x5306c | 0x5246c | 0x4a5 |
IsDebuggerPresent | 0x0 | 0x401090 | 0x53070 | 0x52470 | 0x300 |
IsProcessorFeaturePresent | 0x0 | 0x401094 | 0x53074 | 0x52474 | 0x304 |
HeapFree | 0x0 | 0x401098 | 0x53078 | 0x52478 | 0x2cf |
EncodePointer | 0x0 | 0x40109c | 0x5307c | 0x5247c | 0xea |
DecodePointer | 0x0 | 0x4010a0 | 0x53080 | 0x52480 | 0xca |
ExitProcess | 0x0 | 0x4010a4 | 0x53084 | 0x52484 | 0x119 |
GetStdHandle | 0x0 | 0x4010a8 | 0x53088 | 0x52488 | 0x264 |
GetModuleFileNameW | 0x0 | 0x4010ac | 0x5308c | 0x5248c | 0x214 |
GetModuleFileNameA | 0x0 | 0x4010b0 | 0x53090 | 0x52490 | 0x213 |
FreeEnvironmentStringsW | 0x0 | 0x4010b4 | 0x53094 | 0x52494 | 0x161 |
WideCharToMultiByte | 0x0 | 0x4010b8 | 0x53098 | 0x52498 | 0x511 |
GetEnvironmentStringsW | 0x0 | 0x4010bc | 0x5309c | 0x5249c | 0x1da |
SetHandleCount | 0x0 | 0x4010c0 | 0x530a0 | 0x524a0 | 0x46f |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4010c4 | 0x530a4 | 0x524a4 | 0x2e3 |
GetFileType | 0x0 | 0x4010c8 | 0x530a8 | 0x524a8 | 0x1f3 |
DeleteCriticalSection | 0x0 | 0x4010cc | 0x530ac | 0x524ac | 0xd1 |
TlsAlloc | 0x0 | 0x4010d0 | 0x530b0 | 0x524b0 | 0x4c5 |
TlsGetValue | 0x0 | 0x4010d4 | 0x530b4 | 0x524b4 | 0x4c7 |
TlsSetValue | 0x0 | 0x4010d8 | 0x530b8 | 0x524b8 | 0x4c8 |
TlsFree | 0x0 | 0x4010dc | 0x530bc | 0x524bc | 0x4c6 |
InterlockedIncrement | 0x0 | 0x4010e0 | 0x530c0 | 0x524c0 | 0x2ef |
SetLastError | 0x0 | 0x4010e4 | 0x530c4 | 0x524c4 | 0x473 |
GetCurrentThreadId | 0x0 | 0x4010e8 | 0x530c8 | 0x524c8 | 0x1c5 |
HeapCreate | 0x0 | 0x4010ec | 0x530cc | 0x524cc | 0x2cd |
QueryPerformanceCounter | 0x0 | 0x4010f0 | 0x530d0 | 0x524d0 | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x4010f4 | 0x530d4 | 0x524d4 | 0x1c1 |
GetSystemTimeAsFileTime | 0x0 | 0x4010f8 | 0x530d8 | 0x524d8 | 0x279 |
LeaveCriticalSection | 0x0 | 0x4010fc | 0x530dc | 0x524dc | 0x339 |
EnterCriticalSection | 0x0 | 0x401100 | 0x530e0 | 0x524e0 | 0xee |
RtlUnwind | 0x0 | 0x401104 | 0x530e4 | 0x524e4 | 0x418 |
Sleep | 0x0 | 0x401108 | 0x530e8 | 0x524e8 | 0x4b2 |
HeapSize | 0x0 | 0x40110c | 0x530ec | 0x524ec | 0x2d4 |
LoadLibraryW | 0x0 | 0x401110 | 0x530f0 | 0x524f0 | 0x33f |
GetCPInfo | 0x0 | 0x401114 | 0x530f4 | 0x524f4 | 0x172 |
GetACP | 0x0 | 0x401118 | 0x530f8 | 0x524f8 | 0x168 |
GetOEMCP | 0x0 | 0x40111c | 0x530fc | 0x524fc | 0x237 |
IsValidCodePage | 0x0 | 0x401120 | 0x53100 | 0x52500 | 0x30a |
HeapReAlloc | 0x0 | 0x401124 | 0x53104 | 0x52504 | 0x2d2 |
LCMapStringW | 0x0 | 0x401128 | 0x53108 | 0x52508 | 0x32d |
MultiByteToWideChar | 0x0 | 0x40112c | 0x5310c | 0x5250c | 0x367 |
GetStringTypeW | 0x0 | 0x401130 | 0x53110 | 0x52510 | 0x269 |
ADVAPI32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseEventLog | 0x0 | 0x401000 | 0x52fe0 | 0x523e0 | 0x56 |
RegDeleteValueW | 0x0 | 0x401004 | 0x52fe4 | 0x523e4 | 0x248 |
Memory Dumps (51)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Relevant Image |
![]() |
32-bit | 0x0040749E |
![]() |
![]() |
...
|
buffer | 1 | 0x00693A38 | 0x006D450A | First Execution |
![]() |
32-bit | 0x00693A38 |
![]() |
![]() |
...
|
buffer | 1 | 0x00540000 | 0x005BFFFF | First Execution |
![]() |
32-bit | 0x00540000 |
![]() |
![]() |
...
|
buffer | 1 | 0x00540000 | 0x005BFFFF | Content Changed |
![]() |
32-bit | 0x005404F6 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x00406C0D |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x00452F08 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x0043A636 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x004550A7 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x0043F47A |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x00405407 |
![]() |
![]() |
...
|
buffer | 1 | 0x005D0000 | 0x005D0FFF | First Execution |
![]() |
32-bit | 0x005D0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x005D0000 | 0x005D0FFF | First Execution |
![]() |
32-bit | 0x005D0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x00AE0000 | 0x00AE0FFF | First Execution |
![]() |
32-bit | 0x00AE0000 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x00430641 |
![]() |
![]() |
...
|
buffer | 1 | 0x005D0000 | 0x005D0FFF | First Execution |
![]() |
32-bit | 0x005D0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x005D0000 | 0x005D0FFF | First Execution |
![]() |
32-bit | 0x005D0000 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x0043315A |
![]() |
![]() |
...
|
buffer | 1 | 0x00C00000 | 0x00C00FFF | First Execution |
![]() |
32-bit | 0x00C00000 |
![]() |
![]() |
...
|
buffer | 1 | 0x00C00000 | 0x00C00FFF | First Execution |
![]() |
32-bit | 0x00C00000 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x0042C37E |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x004361E6 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x004361E6 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x004361E6 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x0042EEFE |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x00402A00 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x00407050 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x0040AA80 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x0040BCA0 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x00405CF0 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x00409006 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x0042F96D |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x0041D0D0 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x00406026 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x00411290 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x0040AA80 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x0040B810 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x00405731 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x004037DB |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x0042527B |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x004033E7 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x00409006 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x00402147 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x004211C0 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x0040CC10 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x00404D58 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x0040AA80 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x0040A08A |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x0040BCA0 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x0040BCA0 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Final Dump |
![]() |
32-bit | 0x004033E7 |
![]() |
![]() |
...
|
ks6gqetv8vkldvkf.exe | 1 | 0x00400000 | 0x00531FFF | Content Changed |
![]() |
32-bit | 0x004211C0 |
![]() |
![]() |
...
|
\\?\C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\$Recycle.Bin\S-1-5-18\desktop.ini | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$WINRE_BACKUP_PARTITION.MARKER.encrypted | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1025\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1025\LocalizedData.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1028\LocalizedData.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1031\eula.rtf.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1029\eula.rtf.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1031\LocalizedData.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1032\eula.rtf.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1033\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1030\LocalizedData.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1035\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1033\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1036\LocalizedData.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1038\LocalizedData.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1040\eula.rtf.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1041\eula.rtf.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1042\LocalizedData.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1042\eula.rtf.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1043\eula.rtf.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1044\LocalizedData.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1043\LocalizedData.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1045\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1044\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1046\eula.rtf.encrypted | Dropped File | Binary |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1046\LocalizedData.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1053\LocalizedData.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1053\eula.rtf.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1055\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1049\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2052\eula.rtf.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1049\LocalizedData.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1055\eula.rtf.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2070\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3076\eula.rtf.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3082\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2052\LocalizedData.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2070\LocalizedData.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3076\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3082\LocalizedData.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\DHtmlHeader.html.encrypted | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Extended\Parameterinfo.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Print.ico.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Client\Parameterinfo.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate1.ico.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate2.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate4.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate6.ico.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate8.ico.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate7.ico.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Setup.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\stop.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\SysReqMet.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\warn.ico.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Core_x86.msi.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Extended_x86.msi.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Extended_x64.msi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\RGB9RAST_x64.msi.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Setup.exe.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\SetupUtility.exe | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\UiInfo.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Core.mzz | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\watermark.bmp.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Extended.mzz.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\BOOTSTAT.DAT.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Internet Explorer.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\HardwareEvents.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Key Management Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Known Folders API Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-MUI%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Security.evtx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Setup.evtx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\DESIGNER\MSADDNDR.OLB.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\System.evtx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\i641033.hash.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hash.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\GetCurrentRollback.ini.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1028\eula.rtf.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1029\LocalizedData.xml.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1032\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1037\eula.rtf.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1036\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1037\LocalizedData.xml.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1038\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1041\LocalizedData.xml.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1040\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1045\eula.rtf.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Client\UiInfo.xml.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\DisplayIcon.ico.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Extended\UiInfo.xml.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate5.ico | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate3.ico | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Save.ico.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\header.bmp.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Core_x64.msi.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\ParameterInfo.xml.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\RGB9Rast_x86.msi | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\SetupUi.xsd.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\SplashScreen.bmp | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Strings.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-International%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-MUI%4Operational.evtx.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Store%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx.encrypted | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Windows PowerShell.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\Fonts\readme.txt | Dropped File | Stream |
Not Queried
|
...
|
»