VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: | - |
Threat Names: |
Gen:Heur.Ransom.REntS.Gen.1
Gen:Variant.Fugrafa.33435
Mal/Generic-S
|
xyhlyb.exe
Windows Exe (x86-32)
Created at 2020-04-29T11:19:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x406c0d |
Size Of Code | 0x57000 |
Size Of Initialized Data | 0x2a200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-07-04 23:28:07+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x56e2d | 0x57000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.73 |
.rdata | 0x458000 | 0x18ede | 0x19000 | 0x57400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.31 |
.data | 0x471000 | 0xbb14 | 0x8c00 | 0x70400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.23 |
.reloc | 0x47d000 | 0x55ac | 0x5600 | 0x79000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.61 |
Imports (9)
»
KERNEL32.dll (130)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FindClose | 0x0 | 0x458030 | 0x6ffa0 | 0x6f3a0 | 0x175 |
CreateFileW | 0x0 | 0x458034 | 0x6ffa4 | 0x6f3a4 | 0xcb |
MultiByteToWideChar | 0x0 | 0x458038 | 0x6ffa8 | 0x6f3a8 | 0x3ef |
GetLastError | 0x0 | 0x45803c | 0x6ffac | 0x6f3ac | 0x261 |
lstrcatW | 0x0 | 0x458040 | 0x6ffb0 | 0x6f3b0 | 0x62d |
DeleteFileW | 0x0 | 0x458044 | 0x6ffb4 | 0x6f3b4 | 0x115 |
HeapReAlloc | 0x0 | 0x458048 | 0x6ffb8 | 0x6f3b8 | 0x34c |
CloseHandle | 0x0 | 0x45804c | 0x6ffbc | 0x6f3bc | 0x86 |
HeapAlloc | 0x0 | 0x458050 | 0x6ffc0 | 0x6f3c0 | 0x345 |
GetProcessHeap | 0x0 | 0x458054 | 0x6ffc4 | 0x6f3c4 | 0x2b4 |
GetModuleHandleW | 0x0 | 0x458058 | 0x6ffc8 | 0x6f3c8 | 0x278 |
lstrcpyW | 0x0 | 0x45805c | 0x6ffcc | 0x6f3cc | 0x636 |
GetTickCount | 0x0 | 0x458060 | 0x6ffd0 | 0x6f3d0 | 0x307 |
lstrcmpW | 0x0 | 0x458064 | 0x6ffd4 | 0x6f3d4 | 0x630 |
lstrlenA | 0x0 | 0x458068 | 0x6ffd8 | 0x6f3d8 | 0x63b |
VirtualFree | 0x0 | 0x45806c | 0x6ffdc | 0x6f3dc | 0x5c9 |
lstrcpynW | 0x0 | 0x458070 | 0x6ffe0 | 0x6f3e0 | 0x639 |
VirtualAlloc | 0x0 | 0x458074 | 0x6ffe4 | 0x6f3e4 | 0x5c6 |
TerminateProcess | 0x0 | 0x458078 | 0x6ffe8 | 0x6f3e8 | 0x58c |
WaitForMultipleObjects | 0x0 | 0x45807c | 0x6ffec | 0x6f3ec | 0x5d5 |
GetEnvironmentVariableW | 0x0 | 0x458080 | 0x6fff0 | 0x6f3f0 | 0x239 |
GetComputerNameExW | 0x0 | 0x458084 | 0x6fff4 | 0x6f3f4 | 0x1de |
lstrcatA | 0x0 | 0x458088 | 0x6fff8 | 0x6f3f8 | 0x62c |
OpenProcess | 0x0 | 0x45808c | 0x6fffc | 0x6f3fc | 0x40d |
CreateToolhelp32Snapshot | 0x0 | 0x458090 | 0x70000 | 0x6f400 | 0xfc |
Process32NextW | 0x0 | 0x458094 | 0x70004 | 0x6f404 | 0x42e |
CreateThread | 0x0 | 0x458098 | 0x70008 | 0x6f408 | 0xf3 |
SetFilePointerEx | 0x0 | 0x45809c | 0x7000c | 0x6f40c | 0x523 |
ExitProcess | 0x0 | 0x4580a0 | 0x70010 | 0x6f410 | 0x15e |
GlobalMemoryStatusEx | 0x0 | 0x4580a4 | 0x70014 | 0x6f414 | 0x33a |
CreateProcessW | 0x0 | 0x4580a8 | 0x70018 | 0x6f418 | 0xe5 |
WideCharToMultiByte | 0x0 | 0x4580ac | 0x7001c | 0x6f41c | 0x5fe |
WinExec | 0x0 | 0x4580b0 | 0x70020 | 0x6f420 | 0x5ff |
lstrcmpiW | 0x0 | 0x4580b4 | 0x70024 | 0x6f424 | 0x633 |
MoveFileW | 0x0 | 0x4580b8 | 0x70028 | 0x6f428 | 0x3eb |
GetModuleFileNameW | 0x0 | 0x4580bc | 0x7002c | 0x6f42c | 0x274 |
RemoveDirectoryW | 0x0 | 0x4580c0 | 0x70030 | 0x6f430 | 0x4b9 |
WriteFile | 0x0 | 0x4580c4 | 0x70034 | 0x6f434 | 0x612 |
lstrlenW | 0x0 | 0x4580c8 | 0x70038 | 0x6f438 | 0x63c |
FindNextFileW | 0x0 | 0x4580cc | 0x7003c | 0x6f43c | 0x18c |
HeapFree | 0x0 | 0x4580d0 | 0x70040 | 0x6f440 | 0x349 |
FindFirstFileW | 0x0 | 0x4580d4 | 0x70044 | 0x6f444 | 0x180 |
GetTempPathW | 0x0 | 0x4580d8 | 0x70048 | 0x6f448 | 0x2f6 |
ResetEvent | 0x0 | 0x4580dc | 0x7004c | 0x6f44c | 0x4c6 |
GetLogicalDrives | 0x0 | 0x4580e0 | 0x70050 | 0x6f450 | 0x268 |
ReadFile | 0x0 | 0x4580e4 | 0x70054 | 0x6f454 | 0x473 |
LoadLibraryW | 0x0 | 0x4580e8 | 0x70058 | 0x6f458 | 0x3c4 |
UnregisterWaitEx | 0x0 | 0x4580ec | 0x7005c | 0x6f45c | 0x5b7 |
QueryDepthSList | 0x0 | 0x4580f0 | 0x70060 | 0x6f460 | 0x443 |
InterlockedPopEntrySList | 0x0 | 0x4580f4 | 0x70064 | 0x6f464 | 0x36e |
ReleaseSemaphore | 0x0 | 0x4580f8 | 0x70068 | 0x6f468 | 0x4b4 |
DuplicateHandle | 0x0 | 0x4580fc | 0x7006c | 0x6f46c | 0x12b |
VirtualProtect | 0x0 | 0x458100 | 0x70070 | 0x6f470 | 0x5cc |
GetVersionExW | 0x0 | 0x458104 | 0x70074 | 0x6f474 | 0x31b |
GetModuleHandleA | 0x0 | 0x458108 | 0x70078 | 0x6f478 | 0x275 |
UnregisterWait | 0x0 | 0x45810c | 0x7007c | 0x6f47c | 0x5b6 |
RegisterWaitForSingleObject | 0x0 | 0x458110 | 0x70080 | 0x6f480 | 0x4a9 |
SetThreadAffinityMask | 0x0 | 0x458114 | 0x70084 | 0x6f484 | 0x553 |
GetProcessAffinityMask | 0x0 | 0x458118 | 0x70088 | 0x6f488 | 0x2af |
GetNumaHighestNodeNumber | 0x0 | 0x45811c | 0x7008c | 0x6f48c | 0x289 |
DeleteTimerQueueTimer | 0x0 | 0x458120 | 0x70090 | 0x6f490 | 0x11a |
ChangeTimerQueueTimer | 0x0 | 0x458124 | 0x70094 | 0x6f494 | 0x78 |
CreateTimerQueueTimer | 0x0 | 0x458128 | 0x70098 | 0x6f498 | 0xfb |
GetLogicalProcessorInformation | 0x0 | 0x45812c | 0x7009c | 0x6f49c | 0x269 |
GetThreadPriority | 0x0 | 0x458130 | 0x700a0 | 0x6f4a0 | 0x301 |
SetThreadPriority | 0x0 | 0x458134 | 0x700a4 | 0x6f4a4 | 0x55e |
SignalObjectAndWait | 0x0 | 0x458138 | 0x700a8 | 0x6f4a8 | 0x57b |
SetEvent | 0x0 | 0x45813c | 0x700ac | 0x6f4ac | 0x516 |
CreateTimerQueue | 0x0 | 0x458140 | 0x700b0 | 0x6f4b0 | 0xfa |
WriteConsoleW | 0x0 | 0x458144 | 0x700b4 | 0x6f4b4 | 0x611 |
GetConsoleMode | 0x0 | 0x458148 | 0x700b8 | 0x6f4b8 | 0x1fc |
GetConsoleCP | 0x0 | 0x45814c | 0x700bc | 0x6f4bc | 0x1ea |
FlushFileBuffers | 0x0 | 0x458150 | 0x700c0 | 0x6f4c0 | 0x19f |
DecodePointer | 0x0 | 0x458154 | 0x700c4 | 0x6f4c4 | 0x109 |
HeapSize | 0x0 | 0x458158 | 0x700c8 | 0x6f4c8 | 0x34e |
GetStringTypeW | 0x0 | 0x45815c | 0x700cc | 0x6f4cc | 0x2d7 |
SetStdHandle | 0x0 | 0x458160 | 0x700d0 | 0x6f4d0 | 0x54a |
InitializeSListHead | 0x0 | 0x458164 | 0x700d4 | 0x6f4d4 | 0x363 |
UnhandledExceptionFilter | 0x0 | 0x458168 | 0x700d8 | 0x6f4d8 | 0x5ad |
SetUnhandledExceptionFilter | 0x0 | 0x45816c | 0x700dc | 0x6f4dc | 0x56d |
GetCurrentProcess | 0x0 | 0x458170 | 0x700e0 | 0x6f4e0 | 0x217 |
IsProcessorFeaturePresent | 0x0 | 0x458174 | 0x700e4 | 0x6f4e4 | 0x386 |
IsDebuggerPresent | 0x0 | 0x458178 | 0x700e8 | 0x6f4e8 | 0x37f |
GetStartupInfoW | 0x0 | 0x45817c | 0x700ec | 0x6f4ec | 0x2d0 |
QueryPerformanceCounter | 0x0 | 0x458180 | 0x700f0 | 0x6f4f0 | 0x44d |
GetCurrentProcessId | 0x0 | 0x458184 | 0x700f4 | 0x6f4f4 | 0x218 |
GetCurrentThreadId | 0x0 | 0x458188 | 0x700f8 | 0x6f4f8 | 0x21c |
GetSystemTimeAsFileTime | 0x0 | 0x45818c | 0x700fc | 0x6f4fc | 0x2e9 |
WaitForSingleObjectEx | 0x0 | 0x458190 | 0x70100 | 0x6f500 | 0x5d8 |
Sleep | 0x0 | 0x458194 | 0x70104 | 0x6f504 | 0x57d |
SwitchToThread | 0x0 | 0x458198 | 0x70108 | 0x6f508 | 0x587 |
GetExitCodeThread | 0x0 | 0x45819c | 0x7010c | 0x6f50c | 0x23d |
GetNativeSystemInfo | 0x0 | 0x4581a0 | 0x70110 | 0x6f510 | 0x285 |
EnterCriticalSection | 0x0 | 0x4581a4 | 0x70114 | 0x6f514 | 0x131 |
LeaveCriticalSection | 0x0 | 0x4581a8 | 0x70118 | 0x6f518 | 0x3bd |
TryEnterCriticalSection | 0x0 | 0x4581ac | 0x7011c | 0x6f51c | 0x5a7 |
DeleteCriticalSection | 0x0 | 0x4581b0 | 0x70120 | 0x6f520 | 0x110 |
SetLastError | 0x0 | 0x4581b4 | 0x70124 | 0x6f524 | 0x532 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4581b8 | 0x70128 | 0x6f528 | 0x35f |
CreateEventW | 0x0 | 0x4581bc | 0x7012c | 0x6f52c | 0xbf |
TlsAlloc | 0x0 | 0x4581c0 | 0x70130 | 0x6f530 | 0x59e |
TlsGetValue | 0x0 | 0x4581c4 | 0x70134 | 0x6f534 | 0x5a0 |
TlsSetValue | 0x0 | 0x4581c8 | 0x70138 | 0x6f538 | 0x5a1 |
TlsFree | 0x0 | 0x4581cc | 0x7013c | 0x6f53c | 0x59f |
GetProcAddress | 0x0 | 0x4581d0 | 0x70140 | 0x6f540 | 0x2ae |
QueryPerformanceFrequency | 0x0 | 0x4581d4 | 0x70144 | 0x6f544 | 0x44e |
GetCurrentThread | 0x0 | 0x4581d8 | 0x70148 | 0x6f548 | 0x21b |
GetThreadTimes | 0x0 | 0x4581dc | 0x7014c | 0x6f54c | 0x305 |
RtlUnwind | 0x0 | 0x4581e0 | 0x70150 | 0x6f550 | 0x4d3 |
InterlockedPushEntrySList | 0x0 | 0x4581e4 | 0x70154 | 0x6f554 | 0x36f |
InterlockedFlushSList | 0x0 | 0x4581e8 | 0x70158 | 0x6f558 | 0x36c |
RaiseException | 0x0 | 0x4581ec | 0x7015c | 0x6f55c | 0x462 |
EncodePointer | 0x0 | 0x4581f0 | 0x70160 | 0x6f560 | 0x12d |
FreeLibrary | 0x0 | 0x4581f4 | 0x70164 | 0x6f564 | 0x1ab |
LoadLibraryExW | 0x0 | 0x4581f8 | 0x70168 | 0x6f568 | 0x3c3 |
ExitThread | 0x0 | 0x4581fc | 0x7016c | 0x6f56c | 0x15f |
FreeLibraryAndExitThread | 0x0 | 0x458200 | 0x70170 | 0x6f570 | 0x1ac |
GetModuleHandleExW | 0x0 | 0x458204 | 0x70174 | 0x6f574 | 0x277 |
GetStdHandle | 0x0 | 0x458208 | 0x70178 | 0x6f578 | 0x2d2 |
LCMapStringW | 0x0 | 0x45820c | 0x7017c | 0x6f57c | 0x3b1 |
GetFileType | 0x0 | 0x458210 | 0x70180 | 0x6f580 | 0x24e |
FindFirstFileExW | 0x0 | 0x458214 | 0x70184 | 0x6f584 | 0x17b |
IsValidCodePage | 0x0 | 0x458218 | 0x70188 | 0x6f588 | 0x38b |
GetACP | 0x0 | 0x45821c | 0x7018c | 0x6f58c | 0x1b2 |
GetOEMCP | 0x0 | 0x458220 | 0x70190 | 0x6f590 | 0x297 |
GetCPInfo | 0x0 | 0x458224 | 0x70194 | 0x6f594 | 0x1c1 |
GetCommandLineA | 0x0 | 0x458228 | 0x70198 | 0x6f598 | 0x1d6 |
GetCommandLineW | 0x0 | 0x45822c | 0x7019c | 0x6f59c | 0x1d7 |
GetEnvironmentStringsW | 0x0 | 0x458230 | 0x701a0 | 0x6f5a0 | 0x237 |
FreeEnvironmentStringsW | 0x0 | 0x458234 | 0x701a4 | 0x6f5a4 | 0x1aa |
ADVAPI32.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptAcquireContextA | 0x0 | 0x458000 | 0x6ff70 | 0x6f370 | 0xc1 |
CryptDestroyKey | 0x0 | 0x458004 | 0x6ff74 | 0x6f374 | 0xc8 |
CloseServiceHandle | 0x0 | 0x458008 | 0x6ff78 | 0x6f378 | 0x65 |
CryptEncrypt | 0x0 | 0x45800c | 0x6ff7c | 0x6f37c | 0xcb |
OpenSCManagerW | 0x0 | 0x458010 | 0x6ff80 | 0x6f380 | 0x217 |
ControlService | 0x0 | 0x458014 | 0x6ff84 | 0x6f384 | 0x6a |
CryptImportKey | 0x0 | 0x458018 | 0x6ff88 | 0x6f388 | 0xdb |
OpenServiceW | 0x0 | 0x45801c | 0x6ff8c | 0x6f38c | 0x219 |
CryptReleaseContext | 0x0 | 0x458020 | 0x6ff90 | 0x6f390 | 0xdc |
CryptAcquireContextW | 0x0 | 0x458024 | 0x6ff94 | 0x6f394 | 0xc2 |
CryptGenRandom | 0x0 | 0x458028 | 0x6ff98 | 0x6f398 | 0xd2 |
SHELL32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetFolderPathW | 0x0 | 0x458258 | 0x701c8 | 0x6f5c8 | 0x157 |
ShellExecuteW | 0x0 | 0x45825c | 0x701cc | 0x6f5cc | 0x1b6 |
ole32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoUninitialize | 0x0 | 0x4582d0 | 0x70240 | 0x6f640 | 0x8d |
CoCreateInstance | 0x0 | 0x4582d4 | 0x70244 | 0x6f644 | 0x28 |
CoInitialize | 0x0 | 0x4582d8 | 0x70248 | 0x6f648 | 0x5d |
OLEAUT32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysAllocString | 0x2 | 0x45824c | 0x701bc | 0x6f5bc | - |
VariantClear | 0x9 | 0x458250 | 0x701c0 | 0x6f5c0 | - |
MPR.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetEnumResourceW | 0x0 | 0x45823c | 0x701ac | 0x6f5ac | 0x23 |
WNetCloseEnum | 0x0 | 0x458240 | 0x701b0 | 0x6f5b0 | 0x17 |
WNetOpenEnumW | 0x0 | 0x458244 | 0x701b4 | 0x6f5b4 | 0x44 |
SHLWAPI.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathCombineW | 0x0 | 0x458264 | 0x701d4 | 0x6f5d4 | 0x3d |
wnsprintfW | 0x0 | 0x458268 | 0x701d8 | 0x6f5d8 | 0x178 |
wnsprintfA | 0x0 | 0x45826c | 0x701dc | 0x6f5dc | 0x177 |
StrCmpNA | 0x0 | 0x458270 | 0x701e0 | 0x6f5e0 | 0x125 |
StrStrA | 0x0 | 0x458274 | 0x701e4 | 0x6f5e4 | 0x14d |
StrStrW | 0x0 | 0x458278 | 0x701e8 | 0x6f5e8 | 0x152 |
WININET.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InternetCrackUrlA | 0x0 | 0x458280 | 0x701f0 | 0x6f5f0 | 0x9e |
HttpOpenRequestW | 0x0 | 0x458284 | 0x701f4 | 0x6f5f4 | 0x79 |
InternetQueryOptionW | 0x0 | 0x458288 | 0x701f8 | 0x6f5f8 | 0xcd |
InternetQueryDataAvailable | 0x0 | 0x45828c | 0x701fc | 0x6f5fc | 0xca |
InternetOpenW | 0x0 | 0x458290 | 0x70200 | 0x6f600 | 0xc9 |
InternetCrackUrlW | 0x0 | 0x458294 | 0x70204 | 0x6f604 | 0x9f |
HttpSendRequestW | 0x0 | 0x458298 | 0x70208 | 0x6f608 | 0x82 |
InternetCloseHandle | 0x0 | 0x45829c | 0x7020c | 0x6f60c | 0x95 |
InternetConnectW | 0x0 | 0x4582a0 | 0x70210 | 0x6f610 | 0x9c |
InternetSetOptionW | 0x0 | 0x4582a4 | 0x70214 | 0x6f614 | 0xdf |
InternetReadFile | 0x0 | 0x4582a8 | 0x70218 | 0x6f618 | 0xce |
WS2_32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
recv | 0x10 | 0x4582b0 | 0x70220 | 0x6f620 | - |
connect | 0x4 | 0x4582b4 | 0x70224 | 0x6f624 | - |
closesocket | 0x3 | 0x4582b8 | 0x70228 | 0x6f628 | - |
inet_addr | 0xb | 0x4582bc | 0x7022c | 0x6f62c | - |
send | 0x13 | 0x4582c0 | 0x70230 | 0x6f630 | - |
socket | 0x17 | 0x4582c4 | 0x70234 | 0x6f634 | - |
htons | 0x9 | 0x4582c8 | 0x70238 | 0x6f638 | - |
Memory Dumps (9)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
xyhlyb.exe | 1 | 0x00050000 | 0x000D2FFF | Relevant Image |
![]() |
32-bit | 0x00074443 |
![]() |
![]() |
...
|
buffer | 1 | 0x00980000 | 0x00980FFF | First Execution |
![]() |
32-bit | 0x00980000 |
![]() |
![]() |
...
|
buffer | 1 | 0x009C0000 | 0x009C0FFF | First Execution |
![]() |
32-bit | 0x009C0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x009D0000 | 0x009D0FFF | First Execution |
![]() |
32-bit | 0x009D0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x00980000 | 0x00980FFF | First Execution |
![]() |
32-bit | 0x00980000 |
![]() |
![]() |
...
|
buffer | 1 | 0x00980000 | 0x00980FFF | First Execution |
![]() |
32-bit | 0x00980000 |
![]() |
![]() |
...
|
buffer | 1 | 0x009C0000 | 0x009C0FFF | First Execution |
![]() |
32-bit | 0x009C0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x009C0000 | 0x009C0FFF | First Execution |
![]() |
32-bit | 0x009C0000 |
![]() |
![]() |
...
|
xyhlyb.exe | 1 | 0x00050000 | 0x000D2FFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Ransom.REntS.Gen.1 |
Malicious
|
\\?\C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\GetCurrentRollback.ini | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\$Recycle.Bin\S-1-5-18\desktop.ini | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1025\LocalizedData.xml.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1025\eula.rtf.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$WINRE_BACKUP_PARTITION.MARKER | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1028\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1029\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1028\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1030\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1030\eula.rtf.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1032\eula.rtf.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1032\LocalizedData.xml.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1031\LocalizedData.xml.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1033\eula.rtf.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1035\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1036\eula.rtf.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1036\LocalizedData.xml.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1037\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1038\eula.rtf.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1040\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1042\eula.rtf.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1042\LocalizedData.xml.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1043\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1043\LocalizedData.xml.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1045\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1044\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1045\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1049\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1049\LocalizedData.xml.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1046\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1046\LocalizedData.xml.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1053\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1053\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1055\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1055\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2070\LocalizedData.xml.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2070\eula.rtf | Modified File | Binary |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3076\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3076\eula.rtf.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3082\eula.rtf.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3082\LocalizedData.xml.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\DisplayIcon.ico.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\DHtmlHeader.html.xHIlEgqxx | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Extended\Parameterinfo.xml.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Extended\UiInfo.xml.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Client\UiInfo.xml.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Client\Parameterinfo.xml.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate2.ico.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Print.ico.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate7.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate5.ico.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate6.ico.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\SysReqMet.ico.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Setup.ico.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\warn.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\header.bmp.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Core_x86.msi.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Extended_x86.msi.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\ParameterInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Setup.exe.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\SetupUtility.exe | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\SetupUi.xsd.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\SplashScreen.bmp.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\watermark.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Core.mzz | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Extended.mzz.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\HardwareEvents.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Internet Explorer.evtx.xHIlEgqxx | Dropped File | Audio |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Key Management Service.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-International%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Known Folders API Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-MUI%4Admin.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Setup.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Windows PowerShell.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Security.evtx.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\DESIGNER\MSADDNDR.OLB.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hash | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml.xHIlEgqxx | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1029\eula.rtf.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1031\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1033\LocalizedData.xml.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1037\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1041\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1041\LocalizedData.xml.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1044\eula.rtf.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\2052\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\2052\LocalizedData.xml.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate3.ico.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate1.ico.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate4.ico | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate8.ico | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Save.ico.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\stop.ico | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Core_x64.msi | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Extended_x64.msi.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\RGB9RAST_x64.msi.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\RGB9Rast_x86.msi.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Strings.xml.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\UiInfo.xml.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-MUI%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Store%4Operational.evtx.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\System.evtx.xHIlEgqxx | Dropped File | Image |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\i641033.hash | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe.xHIlEgqxx | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1044\ReadMe.txt | Dropped File | Stream |
Not Queried
|
...
|
»