VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan |
2c08f5ca36.exe
Windows Exe (x86-32)
Created at 2019-09-05T00:39:00
Remarks
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-09-04 03:05 (UTC+2) |
Last Seen | 2019-09-04 16:08 (UTC+2) |
Names | Win32.Trojan.Gdsda |
Families | Gdsda |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x410250 |
Size Of Code | 0x11400 |
Size Of Initialized Data | 0x1800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-09-01 18:25:48+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x112b5 | 0x11400 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.1 |
.rdata | 0x413000 | 0x39c | 0x400 | 0x11800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.57 |
.data | 0x414000 | 0x338 | 0x200 | 0x11c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.69 |
.rsrc | 0x415000 | 0xde4 | 0xe00 | 0x11e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.92 |
.reloc | 0x416000 | 0x37c | 0x400 | 0x12c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.03 |
Imports (1)
»
KERNEL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
OutputDebugStringW | 0x0 | 0x413000 | 0x13370 | 0x11b70 | 0x412 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
2c08f5ca36.exe | 1 | 0x00AB0000 | 0x00AC6FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
2c08f5ca36.exe | 1 | 0x00AB0000 | 0x00AC6FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Trojan.Heur.FU.euW@aqmXl0f |
Malicious
|
C:\588bce7c90097ed212\header.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.xml.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DHtmlHeader.html.mailto[kokoklock@cock.li].d0e731 | Dropped File | Text |
Unknown
|
...
|
»
C:\Logs\Internet Explorer.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Key Management Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-International%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Strings.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\bootsect.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\DWTRIG20.EXE.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\GetCurrentRollback.EXE.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\HttpHelper.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\WinREBootApp32.exe.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\WinREBootApp64.exe.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\GatherOSState.EXE.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\Windows10UpgraderApp.exe.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Store%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\Parameterinfo.xml.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\Parameterinfo.xml.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Known Folders API Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\LocalizedData.xml.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\Q8Uhq0C.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\XVHh3H nmxl7BXcBVc.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Searches\Everywhere.search-ms.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\5iqL.gif.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\9b1gCmF D0WXqDONeE4.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\bqoj4HgOUy4 XwP9DD.png.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\ClrlWdSMZC3os0Ezc.png.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\CqupCCkQphRahcGg.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\E2BOoAuTk7dJ.png.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\IH7LMh9XWm.gif.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\JU6O1UFyFQyHFg1.bmp.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\n3cu4IuU_-Xu48.gif.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\N7LJw0ZvpU.jpg.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\QbTsr3.png.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\qlarU6xM.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\TG1fyx0oNrZZb.png.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\UQ3PrxUz.bmp.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\wveNXSwsujhjT.gif.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\XSXB9S.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\ye pveKePv_.bmp.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\SoW TDWhGpVPO4A\TS7Oo31s1Hx4j8Dj.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\SoW TDWhGpVPO4A\Fm9IIfcvtvHlfb_lg.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT.LOG2 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{fae9930d-933c-11e7-a51d-b808901d6c9b}.TM.blf.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TMContainer00000000000000000001.regtrans-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\ZN5ZpCbSIXoy.gif.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\_v9MbKB.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\mpK K-JQ.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\PdAjG9sZ G.mp3.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\SaddU8qud.m4a.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Favorites\Bing.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\9nmdoCBZbHWyQQ.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\DXp6BfCLZmvgvjv6m.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Database1.accdb.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\jvvzUlONiOuTser1Cw.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\ltKDJJ.xlsx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\PM6HcM.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\wapGA.ods | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\zOWl_u2-Hl-SB4.pps | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\zo7BErW.xlsx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Yz9r_tGr_l-kxrL.avi.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\x1HTUM.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\uX5P.png.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\SZ TN3fNluiRHZIck.odp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\qiHgqojLF3QTQWKbma.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\oPAcO9PRdh8ceIpSI.odp.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\OMigOPyv.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\ilUU-uB.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\FYxfQApyAF.png.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\fTZcunuZHWbZglS iVkr.png.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\fBoKzxbN1Omw23QX.jpg.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\DhqnA4nJvwKX5.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\dCCr2t7Rk.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\cGDwigzIS7.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\b0SqoygWnGE.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\b-J69rI1LaDazjYe1u.flv.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\a9DEbidx78xhyfFcFlNC.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\0wq9P__Q.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\-e-xP3jnb4JA5H.avi.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\eula.rtf.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\eula.rtf.mailto[kokoklock@cock.li].d0e731 | Dropped File | Binary |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\eula.rtf.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\LocalizedData.xml.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\D0E731-Readme.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Setup.exe.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SetupUtility.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\UiInfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\Configuration.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\upgrader_default.log.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\upgrader_win10.log | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Windows PowerShell.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Client\UiInfo.xml.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3076\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT{fae9930d-933c-11e7-a51d-b808901d6c9b}.TMContainer00000000000000000002.regtrans-ms.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Setup.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\iecb0vYAAeoMc.swf.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Searches\Indexed Locations.search-ms.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Searches\winrt--{S-1-5-21-1051304884-625712362-2192934891-1000}-.searchconnector-ms.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\14xFtQ.jpg.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\5J81Ln8x2N42.gif.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\5lFfhHC1PhkhSHOHY_r-.gif.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\Bv1aiFGH09Z 45-.jpg.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\DHnEV.jpg.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\dRSKsP.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\f3djQRK-nPfsqMQ a L3.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\ft3t49Enj.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\GaWE9dNSiJD4.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\lSyelTg7.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\mY4vxcd0R8j6I-At bpl.jpg.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\nh7z83ZmBfhc.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\NieW.bmp.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\OqGnQ6ubAcgxmB97zti.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\uOpWqV2kw.png.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\VLp OGjpNqzeo0.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\xVPn.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\hwcompatShared.txt.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1028\LocalizedData.xml.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\SoW TDWhGpVPO4A\7oEngj01Jjy.mp4.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\SoW TDWhGpVPO4A\eoET.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT.LOG1 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TMContainer00000000000000000002.regtrans-ms.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT{fae9930d-933c-11e7-a51d-b808901d6c9b}.TMContainer00000000000000000001.regtrans-ms.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TM.blf.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\yNr0x7.gif.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\YOC6HBl41CaRP37U4Y5.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\V mWk23OCjQ.mp3.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\3Qrm1-sx4fRMSKjXkOO.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\90PGS.xlsx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Crz2qjg8m7WM.docx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\gnGro.pptx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\GrbZOyAw_ vCsyW9jE.pptx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\jQwbLAg2vznSFTeLLa.docx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\MVTSTnWaByt1ajL.odp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\o1d0IKUTUpYj.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\SQLEej.pptx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\ui4vXJZP38C.pptx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\UucwU.pps | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\x28CJ0j.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\ysZgVumn.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\zEEBhqjUg4xPBLH_sa.xlsx.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\eula.rtf.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1033\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.xml.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\WgtQk0Z53i6.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\tqgQSJk.mkv.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\s51-BA5kuv_0NwFH.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\qprYe_u yi.bmp.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\QHl6s.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\Of-AzbElV27O.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\nJRCtEnbt-cvxGu.rtf.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\IuHd0AD9VYjQwf.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\hZajMydJsA6dgABz5sdr.jpg.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\gr_f.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\DTJ2uqAp.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\deQ4eVpb.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\d 2Q-T8WCBu7RyxxWaxa.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\CrvV.gif.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\ZYkmTOifpz9q1Yc2Qg.jpg.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1037\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1044\eula.rtf.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1046\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Core.mzz.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz.mailto[kokoklock@cock.li].d0e731 | Dropped File | Stream |
Not Queried
|
...
|
»