VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Trojan.GenericKD.43804469
Mal/Generic-S
|
bdtmjp.exe
Windows Exe (x86-32)
Created at 2020-09-14T23:18:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x408dca |
Size Of Code | 0x16a00 |
Size Of Initialized Data | 0xcc00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-08-20 09:58:54+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x168fd | 0x16a00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.67 |
.rdata | 0x418000 | 0x79c2 | 0x7a00 | 0x16e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.96 |
.data | 0x420000 | 0x1e84 | 0x1400 | 0x1e800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.55 |
.rsrc | 0x422000 | 0x3020 | 0x3200 | 0x1fc00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.51 |
Imports (10)
»
KERNEL32.dll (92)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FindClose | 0x0 | 0x41804c | 0x1eeb0 | 0x1dcb0 | 0x175 |
PostQueuedCompletionStatus | 0x0 | 0x418050 | 0x1eeb4 | 0x1dcb4 | 0x423 |
GetLogicalDrives | 0x0 | 0x418054 | 0x1eeb8 | 0x1dcb8 | 0x268 |
GetCurrentProcess | 0x0 | 0x418058 | 0x1eebc | 0x1dcbc | 0x217 |
TerminateProcess | 0x0 | 0x41805c | 0x1eec0 | 0x1dcc0 | 0x58c |
CreateMutexA | 0x0 | 0x418060 | 0x1eec4 | 0x1dcc4 | 0xd7 |
WaitForSingleObject | 0x0 | 0x418064 | 0x1eec8 | 0x1dcc8 | 0x5d7 |
OpenProcess | 0x0 | 0x418068 | 0x1eecc | 0x1dccc | 0x40d |
CreateToolhelp32Snapshot | 0x0 | 0x41806c | 0x1eed0 | 0x1dcd0 | 0xfc |
Sleep | 0x0 | 0x418070 | 0x1eed4 | 0x1dcd4 | 0x57d |
OpenMutexA | 0x0 | 0x418074 | 0x1eed8 | 0x1dcd8 | 0x408 |
Process32NextW | 0x0 | 0x418078 | 0x1eedc | 0x1dcdc | 0x42e |
GetCurrentThread | 0x0 | 0x41807c | 0x1eee0 | 0x1dce0 | 0x21b |
Process32FirstW | 0x0 | 0x418080 | 0x1eee4 | 0x1dce4 | 0x42c |
FindNextFileW | 0x0 | 0x418084 | 0x1eee8 | 0x1dce8 | 0x18c |
CreateProcessA | 0x0 | 0x418088 | 0x1eeec | 0x1dcec | 0xe0 |
GetTickCount | 0x0 | 0x41808c | 0x1eef0 | 0x1dcf0 | 0x307 |
IsDebuggerPresent | 0x0 | 0x418090 | 0x1eef4 | 0x1dcf4 | 0x37f |
CheckRemoteDebuggerPresent | 0x0 | 0x418094 | 0x1eef8 | 0x1dcf8 | 0x80 |
GetQueuedCompletionStatus | 0x0 | 0x418098 | 0x1eefc | 0x1dcfc | 0x2ca |
GetSystemInfo | 0x0 | 0x41809c | 0x1ef00 | 0x1dd00 | 0x2e3 |
CreateThread | 0x0 | 0x4180a0 | 0x1ef04 | 0x1dd04 | 0xf3 |
CreateIoCompletionPort | 0x0 | 0x4180a4 | 0x1ef08 | 0x1dd08 | 0xd0 |
WriteConsoleW | 0x0 | 0x4180a8 | 0x1ef0c | 0x1dd0c | 0x611 |
GetConsoleMode | 0x0 | 0x4180ac | 0x1ef10 | 0x1dd10 | 0x1fc |
FindFirstFileW | 0x0 | 0x4180b0 | 0x1ef14 | 0x1dd14 | 0x180 |
GetProcessHeap | 0x0 | 0x4180b4 | 0x1ef18 | 0x1dd18 | 0x2b4 |
MoveFileExW | 0x0 | 0x4180b8 | 0x1ef1c | 0x1dd1c | 0x3e8 |
SetFilePointerEx | 0x0 | 0x4180bc | 0x1ef20 | 0x1dd20 | 0x523 |
HeapAlloc | 0x0 | 0x4180c0 | 0x1ef24 | 0x1dd24 | 0x345 |
GetLastError | 0x0 | 0x4180c4 | 0x1ef28 | 0x1dd28 | 0x261 |
SetFileAttributesW | 0x0 | 0x4180c8 | 0x1ef2c | 0x1dd2c | 0x51d |
GetFileAttributesW | 0x0 | 0x4180cc | 0x1ef30 | 0x1dd30 | 0x245 |
HeapFree | 0x0 | 0x4180d0 | 0x1ef34 | 0x1dd34 | 0x349 |
GetFileSizeEx | 0x0 | 0x4180d4 | 0x1ef38 | 0x1dd38 | 0x24c |
ReadFile | 0x0 | 0x4180d8 | 0x1ef3c | 0x1dd3c | 0x473 |
WideCharToMultiByte | 0x0 | 0x4180dc | 0x1ef40 | 0x1dd40 | 0x5fe |
GetConsoleCP | 0x0 | 0x4180e0 | 0x1ef44 | 0x1dd44 | 0x1ea |
FlushFileBuffers | 0x0 | 0x4180e4 | 0x1ef48 | 0x1dd48 | 0x19f |
GetModuleHandleW | 0x0 | 0x4180e8 | 0x1ef4c | 0x1dd4c | 0x278 |
CloseHandle | 0x0 | 0x4180ec | 0x1ef50 | 0x1dd50 | 0x86 |
HeapReAlloc | 0x0 | 0x4180f0 | 0x1ef54 | 0x1dd54 | 0x34c |
HeapSize | 0x0 | 0x4180f4 | 0x1ef58 | 0x1dd58 | 0x34e |
MultiByteToWideChar | 0x0 | 0x4180f8 | 0x1ef5c | 0x1dd5c | 0x3ef |
CreateFileW | 0x0 | 0x4180fc | 0x1ef60 | 0x1dd60 | 0xcb |
GetUserDefaultLocaleName | 0x0 | 0x418100 | 0x1ef64 | 0x1dd64 | 0x314 |
GetThreadContext | 0x0 | 0x418104 | 0x1ef68 | 0x1dd68 | 0x2f7 |
WriteFile | 0x0 | 0x418108 | 0x1ef6c | 0x1dd6c | 0x612 |
GetStringTypeW | 0x0 | 0x41810c | 0x1ef70 | 0x1dd70 | 0x2d7 |
SetStdHandle | 0x0 | 0x418110 | 0x1ef74 | 0x1dd74 | 0x54a |
GetFileType | 0x0 | 0x418114 | 0x1ef78 | 0x1dd78 | 0x24e |
DecodePointer | 0x0 | 0x418118 | 0x1ef7c | 0x1dd7c | 0x109 |
FreeEnvironmentStringsW | 0x0 | 0x41811c | 0x1ef80 | 0x1dd80 | 0x1aa |
GetEnvironmentStringsW | 0x0 | 0x418120 | 0x1ef84 | 0x1dd84 | 0x237 |
GetCommandLineW | 0x0 | 0x418124 | 0x1ef88 | 0x1dd88 | 0x1d7 |
GetCommandLineA | 0x0 | 0x418128 | 0x1ef8c | 0x1dd8c | 0x1d6 |
GetCPInfo | 0x0 | 0x41812c | 0x1ef90 | 0x1dd90 | 0x1c1 |
GetOEMCP | 0x0 | 0x418130 | 0x1ef94 | 0x1dd94 | 0x297 |
GetACP | 0x0 | 0x418134 | 0x1ef98 | 0x1dd98 | 0x1b2 |
IsValidCodePage | 0x0 | 0x418138 | 0x1ef9c | 0x1dd9c | 0x38b |
FindFirstFileExW | 0x0 | 0x41813c | 0x1efa0 | 0x1dda0 | 0x17b |
UnhandledExceptionFilter | 0x0 | 0x418140 | 0x1efa4 | 0x1dda4 | 0x5ad |
SetUnhandledExceptionFilter | 0x0 | 0x418144 | 0x1efa8 | 0x1dda8 | 0x56d |
IsProcessorFeaturePresent | 0x0 | 0x418148 | 0x1efac | 0x1ddac | 0x386 |
GetStartupInfoW | 0x0 | 0x41814c | 0x1efb0 | 0x1ddb0 | 0x2d0 |
QueryPerformanceCounter | 0x0 | 0x418150 | 0x1efb4 | 0x1ddb4 | 0x44d |
GetCurrentProcessId | 0x0 | 0x418154 | 0x1efb8 | 0x1ddb8 | 0x218 |
GetCurrentThreadId | 0x0 | 0x418158 | 0x1efbc | 0x1ddbc | 0x21c |
GetSystemTimeAsFileTime | 0x0 | 0x41815c | 0x1efc0 | 0x1ddc0 | 0x2e9 |
InitializeSListHead | 0x0 | 0x418160 | 0x1efc4 | 0x1ddc4 | 0x363 |
RtlUnwind | 0x0 | 0x418164 | 0x1efc8 | 0x1ddc8 | 0x4d3 |
RaiseException | 0x0 | 0x418168 | 0x1efcc | 0x1ddcc | 0x462 |
SetLastError | 0x0 | 0x41816c | 0x1efd0 | 0x1ddd0 | 0x532 |
EncodePointer | 0x0 | 0x418170 | 0x1efd4 | 0x1ddd4 | 0x12d |
EnterCriticalSection | 0x0 | 0x418174 | 0x1efd8 | 0x1ddd8 | 0x131 |
LeaveCriticalSection | 0x0 | 0x418178 | 0x1efdc | 0x1dddc | 0x3bd |
DeleteCriticalSection | 0x0 | 0x41817c | 0x1efe0 | 0x1dde0 | 0x110 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x418180 | 0x1efe4 | 0x1dde4 | 0x35f |
TlsAlloc | 0x0 | 0x418184 | 0x1efe8 | 0x1dde8 | 0x59e |
TlsGetValue | 0x0 | 0x418188 | 0x1efec | 0x1ddec | 0x5a0 |
TlsSetValue | 0x0 | 0x41818c | 0x1eff0 | 0x1ddf0 | 0x5a1 |
TlsFree | 0x0 | 0x418190 | 0x1eff4 | 0x1ddf4 | 0x59f |
FreeLibrary | 0x0 | 0x418194 | 0x1eff8 | 0x1ddf8 | 0x1ab |
GetProcAddress | 0x0 | 0x418198 | 0x1effc | 0x1ddfc | 0x2ae |
LoadLibraryExW | 0x0 | 0x41819c | 0x1f000 | 0x1de00 | 0x3c3 |
ExitThread | 0x0 | 0x4181a0 | 0x1f004 | 0x1de04 | 0x15f |
FreeLibraryAndExitThread | 0x0 | 0x4181a4 | 0x1f008 | 0x1de08 | 0x1ac |
GetModuleHandleExW | 0x0 | 0x4181a8 | 0x1f00c | 0x1de0c | 0x277 |
ExitProcess | 0x0 | 0x4181ac | 0x1f010 | 0x1de10 | 0x15e |
GetModuleFileNameW | 0x0 | 0x4181b0 | 0x1f014 | 0x1de14 | 0x274 |
GetStdHandle | 0x0 | 0x4181b4 | 0x1f018 | 0x1de18 | 0x2d2 |
LCMapStringW | 0x0 | 0x4181b8 | 0x1f01c | 0x1de1c | 0x3b1 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadStringW | 0x0 | 0x4181f8 | 0x1f05c | 0x1de5c | 0x261 |
ADVAPI32.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ControlService | 0x0 | 0x418000 | 0x1ee64 | 0x1dc64 | 0x6a |
CryptImportKey | 0x0 | 0x418004 | 0x1ee68 | 0x1dc68 | 0xdb |
CryptEncrypt | 0x0 | 0x418008 | 0x1ee6c | 0x1dc6c | 0xcb |
CryptAcquireContextW | 0x0 | 0x41800c | 0x1ee70 | 0x1dc70 | 0xc2 |
CryptDestroyKey | 0x0 | 0x418010 | 0x1ee74 | 0x1dc74 | 0xc8 |
QueryServiceStatusEx | 0x0 | 0x418014 | 0x1ee78 | 0x1dc78 | 0x251 |
OpenServiceW | 0x0 | 0x418018 | 0x1ee7c | 0x1dc7c | 0x219 |
CloseServiceHandle | 0x0 | 0x41801c | 0x1ee80 | 0x1dc80 | 0x65 |
OpenSCManagerW | 0x0 | 0x418020 | 0x1ee84 | 0x1dc84 | 0x217 |
CryptReleaseContext | 0x0 | 0x418024 | 0x1ee88 | 0x1dc88 | 0xdc |
EnumDependentServicesW | 0x0 | 0x418028 | 0x1ee8c | 0x1dc8c | 0x10f |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHEmptyRecycleBinW | 0x0 | 0x4181f0 | 0x1f054 | 0x1de54 | 0x13a |
CRYPT32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptStringToBinaryA | 0x0 | 0x418030 | 0x1ee94 | 0x1dc94 | 0xe3 |
MPR.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetGetConnectionW | 0x0 | 0x4181c0 | 0x1f024 | 0x1de24 | 0x2b |
IPHLPAPI.DLL (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
IcmpCloseHandle | 0x0 | 0x418038 | 0x1ee9c | 0x1dc9c | 0x96 |
GetAdaptersInfo | 0x0 | 0x41803c | 0x1eea0 | 0x1dca0 | 0x44 |
IcmpCreateFile | 0x0 | 0x418040 | 0x1eea4 | 0x1dca4 | 0x97 |
IcmpSendEcho | 0x0 | 0x418044 | 0x1eea8 | 0x1dca8 | 0x99 |
NETAPI32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetShareEnum | 0x0 | 0x4181c8 | 0x1f02c | 0x1de2c | 0xde |
NetDfsEnum | 0x0 | 0x4181cc | 0x1f030 | 0x1de30 | 0x61 |
NetApiBufferFree | 0x0 | 0x4181d0 | 0x1f034 | 0x1de34 | 0x51 |
WS2_32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
getnameinfo | 0x0 | 0x418200 | 0x1f064 | 0x1de64 | 0x9a |
WSACleanup | 0x74 | 0x418204 | 0x1f068 | 0x1de68 | - |
WSAStartup | 0x73 | 0x418208 | 0x1f06c | 0x1de6c | - |
htons | 0x9 | 0x41820c | 0x1f070 | 0x1de70 | - |
inet_addr | 0xb | 0x418210 | 0x1f074 | 0x1de74 | - |
RstrtMgr.DLL (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RmStartSession | 0x0 | 0x4181d8 | 0x1f03c | 0x1de3c | 0xb |
RmShutdown | 0x0 | 0x4181dc | 0x1f040 | 0x1de40 | 0xa |
RmEndSession | 0x0 | 0x4181e0 | 0x1f044 | 0x1de44 | 0x2 |
RmGetList | 0x0 | 0x4181e4 | 0x1f048 | 0x1de48 | 0x4 |
RmRegisterResources | 0x0 | 0x4181e8 | 0x1f04c | 0x1de4c | 0x6 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
bdtmjp.exe | 1 | 0x00400000 | 0x00425FFF | Relevant Image |
![]() |
32-bit | 0x0040A80A |
![]() |
![]() |
...
|
bdtmjp.exe | 1 | 0x00400000 | 0x00425FFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.43804469 |
Malicious
|
C:\\$GetCurrent\SafeOS\PartnerSetupComplete.cmd.tx_locked | Dropped File | Batch |
Unknown
|
...
|
»
C:\\$GetCurrent\SafeOS\preoobe.cmd.tx_locked | Dropped File | Batch |
Unknown
|
...
|
»
C:\\$GetCurrent\Logs\PartnerSetupCompleteResult.log | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1025\eula.rtf.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\$GetCurrent\SafeOS\GetCurrentRollback.ini.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\$GetCurrent\SafeOS\SetupComplete.cmd.tx_locked | Dropped File | Batch |
Unknown
|
...
|
»
C:\\$WINRE_BACKUP_PARTITION.MARKER | Modified File | Stream |
Unknown
|
...
|
»
C:\\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1025\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1031\LocalizedData.xml.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1031\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1029\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1030\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1032\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1035\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1033\eula.rtf.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1029\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1032\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1033\LocalizedData.xml.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1036\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1036\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1037\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1038\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1041\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1040\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1037\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1042\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1043\eula.rtf.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1041\eula.rtf.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1044\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1042\LocalizedData.xml.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1044\eula.rtf.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1046\LocalizedData.xml.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1046\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1045\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1045\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1043\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1055\LocalizedData.xml.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1049\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1053\eula.rtf.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1049\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1053\LocalizedData.xml.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1055\eula.rtf.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\2052\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\2052\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\2070\eula.rtf.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1028\LocalizedData.xml.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\3082\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1028\eula.rtf.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\2070\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\3082\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Client\Parameterinfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Extended\Parameterinfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\DHtmlHeader.html | Modified File | Text |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Client\UiInfo.xml.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\DisplayIcon.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Rotate6.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Rotate5.ico.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Print.ico.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Rotate2.ico.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Rotate4.ico.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Extended\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Rotate1.ico.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Rotate7.ico.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Rotate8.ico.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Save.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Setup.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\SysReqMet.ico.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Rotate3.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\stop.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\header.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\warn.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\netfx_Core_x64.msi.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\SysReqNotMet.ico.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\netfx_Core_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\RGB9RAST_x64.msi.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\netfx_Extended_x64.msi.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\netfx_Extended_x86.msi.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\ParameterInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\SplashScreen.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Strings.xml.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\SetupUi.xsd.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\RGB9Rast_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\watermark.bmp.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\netfx_Core.mzz | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Application.evtx.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\Key Management Service.evtx.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\0OpMiFG.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Security.evtx.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\netfx_Extended.mzz | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\1KQcfS.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\Default\NTUSER.DAT.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\1MxjpeS1iU91yN4.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\2R1cy2pt9zbUpnqNP.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\2dsQljNbYk_iA.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\4H-iv64v5ZRrjL5.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\B5q.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\5mfvw.mkv.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\4k0sH.jpg.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\bhFm36x86J-q.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\CjLyo.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\bv1l3hhAidRFfBa.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\ddRQ_63Aa9GZLWEVD\CgPa.pps | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\ddRQ_63Aa9GZLWEVD\2RYUylThgMPT.pdf.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\ddRQ_63Aa9GZLWEVD\a9yLA2TnK.gif.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\ddRQ_63Aa9GZLWEVD\D-5-76Wkwt.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\ddRQ_63Aa9GZLWEVD\ipVZraxYNRyEC0Mk.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\ddRQ_63Aa9GZLWEVD\gw44hhIkqEVtoC7.m4a.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\ddRQ_63Aa9GZLWEVD\Ky8AFTe8hZ 7CGo.mkv.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\ddRQ_63Aa9GZLWEVD\TCfPZSWr50TRm.m4a.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\ddRQ_63Aa9GZLWEVD\NFuV70f_4W.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\ddRQ_63Aa9GZLWEVD\nj5AWEtBlf6qM.gif.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\ddRQ_63Aa9GZLWEVD\Ws-c5X_R.swf.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\ddRQ_63Aa9GZLWEVD\tz2R6Is5tCxOlPN.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\fwh73Z-bSqjqoibDusY.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\ddRQ_63Aa9GZLWEVD\hI3026ksh.png.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\DrftaJ.mkv.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\G6aYH.csv.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\dgLg92kQdJ7s-j-X7.odt.tx_locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1033\id.key | Dropped File | Text |
Unknown
|
...
|
»
C:\\Users\FD1HVy\Desktop\ddRQ_63Aa9GZLWEVD\id.key | Dropped File | Text |
Unknown
|
...
|
»