VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Gen:Variant.Graftor.717353
Gen:Variant.Adware.ConvertAd.1273
|
splwow32.exe
Windows Exe (x86-32)
Created at 2020-03-22T00:54:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x407f11 |
Size Of Code | 0x13600 |
Size Of Initialized Data | 0x8400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-03-19 04:31:29+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x13505 | 0x13600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x415000 | 0x53c0 | 0x5400 | 0x13a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.19 |
.data | 0x41b000 | 0x35f0 | 0x1400 | 0x18e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.32 |
.rsrc | 0x41f000 | 0x1b4 | 0x200 | 0x1a200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.11 |
.reloc | 0x420000 | 0x19d2 | 0x1a00 | 0x1a400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 4.49 |
Imports (4)
»
KERNEL32.dll (80)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateMutexW | 0x0 | 0x415008 | 0x19be0 | 0x185e0 | 0x9e |
FindFirstFileW | 0x0 | 0x41500c | 0x19be4 | 0x185e4 | 0x139 |
GetDriveTypeW | 0x0 | 0x415010 | 0x19be8 | 0x185e8 | 0x1d3 |
SetEndOfFile | 0x0 | 0x415014 | 0x19bec | 0x185ec | 0x453 |
SetFilePointerEx | 0x0 | 0x415018 | 0x19bf0 | 0x185f0 | 0x467 |
GetLogicalDrives | 0x0 | 0x41501c | 0x19bf4 | 0x185f4 | 0x209 |
WriteFile | 0x0 | 0x415020 | 0x19bf8 | 0x185f8 | 0x525 |
ReadFile | 0x0 | 0x415024 | 0x19bfc | 0x185fc | 0x3c0 |
CreateFileW | 0x0 | 0x415028 | 0x19c00 | 0x18600 | 0x8f |
GetLastError | 0x0 | 0x41502c | 0x19c04 | 0x18604 | 0x202 |
FindClose | 0x0 | 0x415030 | 0x19c08 | 0x18608 | 0x12e |
GetFileSize | 0x0 | 0x415034 | 0x19c0c | 0x1860c | 0x1f0 |
HeapSetInformation | 0x0 | 0x415038 | 0x19c10 | 0x18610 | 0x2d3 |
FindNextFileW | 0x0 | 0x41503c | 0x19c14 | 0x18614 | 0x145 |
WinExec | 0x0 | 0x415040 | 0x19c18 | 0x18618 | 0x512 |
CloseHandle | 0x0 | 0x415044 | 0x19c1c | 0x1861c | 0x52 |
SetFilePointer | 0x0 | 0x415048 | 0x19c20 | 0x18620 | 0x466 |
HeapReAlloc | 0x0 | 0x41504c | 0x19c24 | 0x18624 | 0x2d2 |
FlushFileBuffers | 0x0 | 0x415050 | 0x19c28 | 0x18628 | 0x157 |
GetConsoleMode | 0x0 | 0x415054 | 0x19c2c | 0x1862c | 0x1ac |
GetConsoleCP | 0x0 | 0x415058 | 0x19c30 | 0x18630 | 0x19a |
RtlUnwind | 0x0 | 0x41505c | 0x19c34 | 0x18634 | 0x418 |
RemoveDirectoryW | 0x0 | 0x415060 | 0x19c38 | 0x18638 | 0x403 |
GetComputerNameA | 0x0 | 0x415064 | 0x19c3c | 0x1863c | 0x18c |
WriteConsoleW | 0x0 | 0x415068 | 0x19c40 | 0x18640 | 0x524 |
GetFileType | 0x0 | 0x41506c | 0x19c44 | 0x18644 | 0x1f3 |
GetStdHandle | 0x0 | 0x415070 | 0x19c48 | 0x18648 | 0x264 |
GetModuleFileNameW | 0x0 | 0x415074 | 0x19c4c | 0x1864c | 0x214 |
HeapAlloc | 0x0 | 0x415078 | 0x19c50 | 0x18650 | 0x2cb |
EncodePointer | 0x0 | 0x41507c | 0x19c54 | 0x18654 | 0xea |
DecodePointer | 0x0 | 0x415080 | 0x19c58 | 0x18658 | 0xca |
MoveFileW | 0x0 | 0x415084 | 0x19c5c | 0x1865c | 0x363 |
GetCommandLineA | 0x0 | 0x415088 | 0x19c60 | 0x18660 | 0x186 |
GetStartupInfoW | 0x0 | 0x41508c | 0x19c64 | 0x18664 | 0x263 |
RaiseException | 0x0 | 0x415090 | 0x19c68 | 0x18668 | 0x3b1 |
FreeLibrary | 0x0 | 0x415094 | 0x19c6c | 0x1866c | 0x162 |
InterlockedExchange | 0x0 | 0x415098 | 0x19c70 | 0x18670 | 0x2ec |
GetProcAddress | 0x0 | 0x41509c | 0x19c74 | 0x18674 | 0x245 |
LoadLibraryW | 0x0 | 0x4150a0 | 0x19c78 | 0x18678 | 0x33f |
TerminateProcess | 0x0 | 0x4150a4 | 0x19c7c | 0x1867c | 0x4c0 |
GetCurrentProcess | 0x0 | 0x4150a8 | 0x19c80 | 0x18680 | 0x1c0 |
UnhandledExceptionFilter | 0x0 | 0x4150ac | 0x19c84 | 0x18684 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x4150b0 | 0x19c88 | 0x18688 | 0x4a5 |
IsDebuggerPresent | 0x0 | 0x4150b4 | 0x19c8c | 0x1868c | 0x300 |
HeapFree | 0x0 | 0x4150b8 | 0x19c90 | 0x18690 | 0x2cf |
IsProcessorFeaturePresent | 0x0 | 0x4150bc | 0x19c94 | 0x18694 | 0x304 |
GetCPInfo | 0x0 | 0x4150c0 | 0x19c98 | 0x18698 | 0x172 |
InterlockedIncrement | 0x0 | 0x4150c4 | 0x19c9c | 0x1869c | 0x2ef |
InterlockedDecrement | 0x0 | 0x4150c8 | 0x19ca0 | 0x186a0 | 0x2eb |
GetACP | 0x0 | 0x4150cc | 0x19ca4 | 0x186a4 | 0x168 |
GetOEMCP | 0x0 | 0x4150d0 | 0x19ca8 | 0x186a8 | 0x237 |
IsValidCodePage | 0x0 | 0x4150d4 | 0x19cac | 0x186ac | 0x30a |
TlsAlloc | 0x0 | 0x4150d8 | 0x19cb0 | 0x186b0 | 0x4c5 |
TlsGetValue | 0x0 | 0x4150dc | 0x19cb4 | 0x186b4 | 0x4c7 |
TlsSetValue | 0x0 | 0x4150e0 | 0x19cb8 | 0x186b8 | 0x4c8 |
TlsFree | 0x0 | 0x4150e4 | 0x19cbc | 0x186bc | 0x4c6 |
GetModuleHandleW | 0x0 | 0x4150e8 | 0x19cc0 | 0x186c0 | 0x218 |
SetLastError | 0x0 | 0x4150ec | 0x19cc4 | 0x186c4 | 0x473 |
GetCurrentThreadId | 0x0 | 0x4150f0 | 0x19cc8 | 0x186c8 | 0x1c5 |
EnterCriticalSection | 0x0 | 0x4150f4 | 0x19ccc | 0x186cc | 0xee |
LeaveCriticalSection | 0x0 | 0x4150f8 | 0x19cd0 | 0x186d0 | 0x339 |
ExitProcess | 0x0 | 0x4150fc | 0x19cd4 | 0x186d4 | 0x119 |
HeapCreate | 0x0 | 0x415100 | 0x19cd8 | 0x186d8 | 0x2cd |
Sleep | 0x0 | 0x415104 | 0x19cdc | 0x186dc | 0x4b2 |
HeapSize | 0x0 | 0x415108 | 0x19ce0 | 0x186e0 | 0x2d4 |
GetModuleFileNameA | 0x0 | 0x41510c | 0x19ce4 | 0x186e4 | 0x213 |
FreeEnvironmentStringsW | 0x0 | 0x415110 | 0x19ce8 | 0x186e8 | 0x161 |
WideCharToMultiByte | 0x0 | 0x415114 | 0x19cec | 0x186ec | 0x511 |
GetEnvironmentStringsW | 0x0 | 0x415118 | 0x19cf0 | 0x186f0 | 0x1da |
SetHandleCount | 0x0 | 0x41511c | 0x19cf4 | 0x186f4 | 0x46f |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x415120 | 0x19cf8 | 0x186f8 | 0x2e3 |
DeleteCriticalSection | 0x0 | 0x415124 | 0x19cfc | 0x186fc | 0xd1 |
QueryPerformanceCounter | 0x0 | 0x415128 | 0x19d00 | 0x18700 | 0x3a7 |
GetTickCount | 0x0 | 0x41512c | 0x19d04 | 0x18704 | 0x293 |
GetCurrentProcessId | 0x0 | 0x415130 | 0x19d08 | 0x18708 | 0x1c1 |
GetSystemTimeAsFileTime | 0x0 | 0x415134 | 0x19d0c | 0x1870c | 0x279 |
LCMapStringW | 0x0 | 0x415138 | 0x19d10 | 0x18710 | 0x32d |
MultiByteToWideChar | 0x0 | 0x41513c | 0x19d14 | 0x18714 | 0x367 |
GetStringTypeW | 0x0 | 0x415140 | 0x19d18 | 0x18718 | 0x269 |
SetStdHandle | 0x0 | 0x415144 | 0x19d1c | 0x1871c | 0x487 |
USER32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShowWindow | 0x0 | 0x415158 | 0x19d30 | 0x18730 | 0x2df |
CreateWindowExW | 0x0 | 0x41515c | 0x19d34 | 0x18734 | 0x6e |
RegisterClassW | 0x0 | 0x415160 | 0x19d38 | 0x18738 | 0x24e |
GetSystemMetrics | 0x0 | 0x415164 | 0x19d3c | 0x1873c | 0x17e |
SetWindowLongW | 0x0 | 0x415168 | 0x19d40 | 0x18740 | 0x2c4 |
LoadCursorW | 0x0 | 0x41516c | 0x19d44 | 0x18744 | 0x1eb |
GDI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetStockObject | 0x0 | 0x415000 | 0x19bd8 | 0x185d8 | 0x20d |
SHELL32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderPathW | 0x0 | 0x41514c | 0x19d24 | 0x18724 | 0xe1 |
SHEmptyRecycleBinW | 0x0 | 0x415150 | 0x19d28 | 0x18728 | 0xa5 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
splwow32.exe | 1 | 0x00930000 | 0x00951FFF | Relevant Image |
![]() |
32-bit | 0x009390BE |
![]() |
![]() |
...
|
splwow32.exe | 1 | 0x00930000 | 0x00951FFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Graftor.717353 |
Malicious
|
C:\Windows10Upgrade\appraiserxp.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\Configuration.ini.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\cosquery.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\DWDCW20.DLL.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\EnableWiFiTracing.cmd.vhd | Dropped File | Batch |
Unknown
|
...
|
»
C:\Windows10Upgrade\ESDHelper.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\GatherOSState.EXE.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\GetCurrentRollback.EXE | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\HttpHelper.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\upgrader_default.log.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\wimgapi.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\WinREBootApp32.exe | Modified File | Binary |
Unknown
|
...
|
»
C:\Logs\Internet Explorer.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Known Folders API Service.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Store%4Operational.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Windows PowerShell.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DHtmlHeader.html.vhd | Dropped File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DisplayIcon.ico.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core.mzz.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x64.msi.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.xml.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Setup.exe.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupUi.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupUtility.exe.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\sqmapi.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Strings.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\UiInfo.xml.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd.vhd | Dropped File | Batch |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\preoobe.cmd.vhd | Dropped File | Batch |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\SetupComplete.cmd.vhd | Dropped File | Batch |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Print.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate1.ico.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate2.ico.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate5.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate6.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate7.ico.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate8.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Save.ico.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\stop.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\warn.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\Parameterinfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\Parameterinfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\eula.rtf.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\eula.rtf.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\LocalizedData.xml.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\SetupResources.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\SetupResources.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\eula.rtf.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\SetupResources.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\SetupResources.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.xml.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\SetupResources.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\LocalizedData.xml.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\SetupResources.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\LocalizedData.xml.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\SetupResources.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.xml.vhd | Dropped File | Binary |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\SetupResources.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\rempl\rempl.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\rempl\Unlock.xml.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\AccessibleMarshal.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\HowToDecrypt.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Program Files\UNP\Task.xml.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\bootsect.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\DevInv.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\downloader.dll.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\DW20.EXE.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\DWTRIG20.EXE | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\esdstub.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\GetCurrentDeploy.dll.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\GetCurrentOOBE.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\PostOOBEScript.cmd | Modified File | Batch |
Not Queried
|
...
|
»
C:\Windows10Upgrade\upgrader_win10.log | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\windlp.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\Windows10UpgraderApp.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\WinREBootApp64.exe.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Key Management Service.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-International%4Operational.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x86.msi.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x64.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x86.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\RGB9RAST_x64.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\RGB9Rast_x86.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SetupEngine.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate3.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate4.ico.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Setup.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqMet.ico.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Extended\UiInfo.xml.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Client\UiInfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3082\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3082\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3076\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2070\LocalizedData.xml.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2070\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2052\SetupResources.dll.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1055\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1053\eula.rtf.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1049\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1046\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1044\eula.rtf.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1044\LocalizedData.xml.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1044\SetupResources.dll.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1043\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1043\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1042\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1042\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1041\LocalizedData.xml.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1040\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1037\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1036\SetupResources.dll.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1033\eula.rtf.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.xml.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1030\LocalizedData.xml.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1030\SetupResources.dll.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1028\eula.rtf.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1028\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1028\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\rempl\remsh.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\Accessible.tlb.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\AccessibleHandler.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\api-ms-win-core-console-l1-1-0.dll.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\api-ms-win-core-datetime-l1-1-0.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\api-ms-win-core-debug-l1-1-0.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\api-ms-win-core-errorhandling-l1-1-0.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\api-ms-win-core-file-l1-1-0.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\api-ms-win-core-file-l1-2-0.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\api-ms-win-core-file-l2-1-0.dll.vhd | Dropped File | Stream |
Not Queried
|
...
|
»