Created 3 years ago
a7f09cfde433f3d47fc96502bf2b623ae5e7626da85d0a0130dcd19d1679af9b.exe
Virtual Machine Information
Name | win10_64_th2_en_mso2016 |
Description | win10_64_th2_en_mso2016 |
Architecture | x86 64-bit |
Operating System | Windows 10 Threshold 2 |
Kernel Version | 10.0.10586.0 (0de6dc23-8e19-4bb7-8608-d54b1e6fa379) |
Network Scheme Name | Local Gateway |
Network Config Name | Local Gateway |
Platform Information
Platform Version | 4.4.1 |
Dynamic Engine Version | 4.4.1 / 2022-01-14 05:01 (UTC+) |
Static Engine Version | 4.4.1.0 / 2022-01-14 04:01 (UTC+) |
AV Exceptions Version | 4.4.1.6 / 2021-12-14 15:12 (UTC+) |
Link Detonation Heuristics Version | 4.4.1.16 / 2022-03-11 16:03 (UTC+) |
Smart Memory Dumping Rules | 4.4.1.6 / 2021-12-14 15:12 (UTC+) |
Signature Trust Store Version | 4.4.1.6 / 2021-12-14 15:12 (UTC+) |
VMRay Threat Identifiers Version | 4.4.1.19 / 2022-03-31 10:03 (UTC+) |
YARA Built-in Ruleset Version | 4.4.1.19 |
Anti Virus Information
Software Information
Adobe Acrobat Reader Version | Not installed |
Microsoft Office | 2016 |
Microsoft Office Version | 16.0.4266.1003 |
Hangul Office | Not installed |
Hangul Office Version | Not installed |
Internet Explorer Version | 11.0.10586.0 |
Chrome Version | Not installed |
Firefox Version | Not installed |
Flash Version | Not installed |
Java Version | Not installed |
System Information
Sample Directory | C:\Users\RDhJ0CNFevzX\Desktop |
Computer Name | XC64ZB |
User Domain | XC64ZB |
User Name | RDhJ0CNFevzX |
User Profile | C:\Users\RDhJ0CNFevzX |
Temp Directory | C:\Users\RDHJ0C~1\AppData\Local\Temp |
System Root | C:\Windows |
Randomly Created Artifacts
This section provides information about processes and files that were created before the analysis was started. This is one of many steps designed to make the analysis system look more realistic and prevent evasion by environment aware malware. The number of randomly generated artifacts can be changed in the configuration.
Customized Created Artifacts
Similar to Randomly Created Artifacts, this section lists the pre-configured files and processes that were created on the account of randomly generated artifacts, to ensure a more realistic environment.