VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Trojan.GenericKD.43566381
Mal/Generic-S
|
CUserstestAppDataLocalTempRar$EXb6200.3208333.exe
Windows Exe (x86-32)
Created at 2020-07-30T17:52:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\CUserstestAppDataLocalTempRar$EXb6200.3208333.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x8787c1 |
Size Of Code | 0x13600 |
Size Of Initialized Data | 0x8400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-03-19 04:31:29+00:00 |
Sections (7)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x13505 | 0x13600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.64 |
.rdata | 0x415000 | 0x53c0 | 0x5400 | 0x13a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.46 |
.data | 0x41b000 | 0x35f0 | 0x1400 | 0x18e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.32 |
.vmp0 | 0x41f000 | 0x3306cf | 0x330800 | 0x1a200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.86 |
.vmp1 | 0x750000 | 0x26f350 | 0x26f400 | 0x34aa00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.83 |
.reloc | 0x9c0000 | 0x30ec | 0x3200 | 0x5b9e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.83 |
.rsrc | 0x9c4000 | 0x1b2 | 0x200 | 0x5bd000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.47 |
Imports (9)
»
KERNEL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateMutexW | 0x0 | 0x9aa000 | 0x41e13c | 0x418b3c | 0x0 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShowWindow | 0x0 | 0x9aa008 | 0x41e144 | 0x418b44 | 0x0 |
GDI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetStockObject | 0x0 | 0x9aa010 | 0x41e14c | 0x418b4c | 0x0 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderPathW | 0x0 | 0x9aa018 | 0x41e154 | 0x418b54 | 0x0 |
WTSAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WTSSendMessageW | 0x0 | 0x9aa020 | 0x41e15c | 0x418b5c | 0x0 |
KERNEL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VirtualQuery | 0x0 | 0x9aa028 | 0x41e164 | 0x418b64 | 0x0 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetUserObjectInformationW | 0x0 | 0x9aa030 | 0x41e16c | 0x418b6c | 0x0 |
KERNEL32.dll (12)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LocalAlloc | 0x0 | 0x9aa038 | 0x41e174 | 0x418b74 | 0x0 |
LocalFree | 0x0 | 0x9aa03c | 0x41e178 | 0x418b78 | 0x0 |
GetModuleFileNameW | 0x0 | 0x9aa040 | 0x41e17c | 0x418b7c | 0x0 |
GetProcessAffinityMask | 0x0 | 0x9aa044 | 0x41e180 | 0x418b80 | 0x0 |
SetProcessAffinityMask | 0x0 | 0x9aa048 | 0x41e184 | 0x418b84 | 0x0 |
SetThreadAffinityMask | 0x0 | 0x9aa04c | 0x41e188 | 0x418b88 | 0x0 |
Sleep | 0x0 | 0x9aa050 | 0x41e18c | 0x418b8c | 0x0 |
ExitProcess | 0x0 | 0x9aa054 | 0x41e190 | 0x418b90 | 0x0 |
FreeLibrary | 0x0 | 0x9aa058 | 0x41e194 | 0x418b94 | 0x0 |
LoadLibraryA | 0x0 | 0x9aa05c | 0x41e198 | 0x418b98 | 0x0 |
GetModuleHandleA | 0x0 | 0x9aa060 | 0x41e19c | 0x418b9c | 0x0 |
GetProcAddress | 0x0 | 0x9aa064 | 0x41e1a0 | 0x418ba0 | 0x0 |
USER32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetProcessWindowStation | 0x0 | 0x9aa06c | 0x41e1a8 | 0x418ba8 | 0x0 |
GetUserObjectInformationW | 0x0 | 0x9aa070 | 0x41e1ac | 0x418bac | 0x0 |
Memory Dumps (16)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
cuserstestappdatalocaltemprar$exb6200.3208333.exe | 1 | 0x00060000 | 0x00624FFF | Relevant Image |
![]() |
32-bit | 0x00575C78 |
![]() |
![]() |
...
|
cuserstestappdatalocaltemprar$exb6200.3208333.exe | 1 | 0x00060000 | 0x00624FFF | Content Changed |
![]() |
32-bit | 0x0009D448 |
![]() |
![]() |
...
|
cuserstestappdatalocaltemprar$exb6200.3208333.exe | 1 | 0x00060000 | 0x00624FFF | Content Changed |
![]() |
32-bit | 0x00093782 |
![]() |
![]() |
...
|
cuserstestappdatalocaltemprar$exb6200.3208333.exe | 1 | 0x00060000 | 0x00624FFF | Content Changed |
![]() |
32-bit | 0x000953C8 |
![]() |
![]() |
...
|
cuserstestappdatalocaltemprar$exb6200.3208333.exe | 1 | 0x00060000 | 0x00624FFF | Content Changed |
![]() |
32-bit | 0x00094C78 |
![]() |
![]() |
...
|
cuserstestappdatalocaltemprar$exb6200.3208333.exe | 1 | 0x00060000 | 0x00624FFF | Content Changed |
![]() |
32-bit | 0x00098F52 |
![]() |
![]() |
...
|
cuserstestappdatalocaltemprar$exb6200.3208333.exe | 1 | 0x00060000 | 0x00624FFF | Content Changed |
![]() |
32-bit | 0x0009BD69 |
![]() |
![]() |
...
|
cuserstestappdatalocaltemprar$exb6200.3208333.exe | 1 | 0x00060000 | 0x00624FFF | Content Changed |
![]() |
32-bit | 0x001389BA |
![]() |
![]() |
...
|
cuserstestappdatalocaltemprar$exb6200.3208333.exe | 1 | 0x00060000 | 0x00624FFF | Content Changed |
![]() |
32-bit | 0x002F056B |
![]() |
![]() |
...
|
cuserstestappdatalocaltemprar$exb6200.3208333.exe | 1 | 0x00060000 | 0x00624FFF | Content Changed |
![]() |
32-bit | 0x002F590A |
![]() |
![]() |
...
|
cuserstestappdatalocaltemprar$exb6200.3208333.exe | 1 | 0x00060000 | 0x00624FFF | Content Changed |
![]() |
32-bit | 0x002ACD14 |
![]() |
![]() |
...
|
cuserstestappdatalocaltemprar$exb6200.3208333.exe | 1 | 0x00060000 | 0x00624FFF | Content Changed |
![]() |
32-bit | 0x002D643F |
![]() |
![]() |
...
|
buffer | 1 | 0x00A60000 | 0x00A60FFF | First Execution |
![]() |
32-bit | 0x00A6000F |
![]() |
![]() |
...
|
buffer | 1 | 0x00A60000 | 0x00A60FFF | Marked Executable |
![]() |
32-bit | 0x00A6000F |
![]() |
![]() |
...
|
buffer | 1 | 0x00B50000 | 0x00B50FFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00B50000 | 0x00B50FFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.43566381 |
Malicious
|
C:\Windows10Upgrade\appraiserxp.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\Configuration.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\cosquery.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\downloader.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\DW20.EXE.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\EnableWiFiTracing.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\Windows10Upgrade\ESDHelper.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\esdstub.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\GetCurrentDeploy.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\GetCurrentOOBE.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\HttpHelper.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\upgrader_default.log | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\wimgapi.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\WinREBootApp64.exe.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Key Management Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Known Folders API Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Store%4Operational.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Windows PowerShell.evtx.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DHtmlHeader.html.vhd | Dropped File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core.mzz.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x86.msi.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x86.msi.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\RGB9RAST_x64.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Setup.exe.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupUi.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupUtility.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Strings.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Print.ico.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate2.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate3.ico.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate5.ico.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate6.ico.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqMet.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\warn.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\Parameterinfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\UiInfo.xml.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\SetupResources.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\SetupResources.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\LocalizedData.xml.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\LocalizedData.xml.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\LocalizedData.xml.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\SetupResources.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\LocalizedData.xml.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\LocalizedData.xml.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\eula.rtf.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\LocalizedData.xml.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\SetupResources.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\LocalizedData.xml.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\SetupResources.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\Accessible.tlb | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\AccessibleHandler.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\AccessibleMarshal.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\api-ms-win-core-datetime-l1-1-0.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\api-ms-win-core-file-l1-2-0.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\api-ms-win-core-file-l2-1-0.dll.vhd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\bootsect.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\DevInv.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\DWDCW20.DLL.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\DWTRIG20.EXE | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\GatherOSState.EXE.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\GetCurrentRollback.EXE | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\PostOOBEScript.cmd | Modified File | Batch |
Not Queried
|
...
|
»
C:\Windows10Upgrade\upgrader_win10.log | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\windlp.dll.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\Windows10UpgraderApp.exe.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\WinREBootApp32.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Application.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Internet Explorer.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-International%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\DisplayIcon.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x64.msi.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x64.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.xml.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\RGB9Rast_x86.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SetupEngine.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\sqmapi.dll.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\UiInfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd.vhd | Dropped File | Batch |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\preoobe.cmd.vhd | Dropped File | Batch |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\SetupComplete.cmd.vhd | Dropped File | Batch |
Not Queried
|
...
|
»
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate1.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate4.ico.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate7.ico.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate8.ico.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Save.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Setup.ico.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\stop.ico.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Extended\Parameterinfo.xml.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Extended\UiInfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3082\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3076\LocalizedData.xml.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2070\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2052\SetupResources.dll.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1055\eula.rtf.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1055\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1053\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1053\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1049\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1049\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1046\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1046\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\LocalizedData.xml.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1044\eula.rtf.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1044\LocalizedData.xml.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1044\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1041\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1041\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.xml.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1038\SetupResources.dll.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1037\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1037\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1036\SetupResources.dll.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1033\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1033\SetupResources.dll.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.xml.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1032\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.xml.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1031\SetupResources.dll.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\rempl\rempl.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\rempl\remsh.exe.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\rempl\Unlock.xml.vhd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\api-ms-win-core-console-l1-1-0.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\api-ms-win-core-debug-l1-1-0.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\api-ms-win-core-errorhandling-l1-1-0.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\api-ms-win-core-file-l1-1-0.dll.vhd | Dropped File | Stream |
Not Queried
|
...
|
»