VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Gen:Trojan.Heur.JP.eqX@aqgaQ4c
Mal/Generic-S
|
1.exe
Windows Exe (x86-32)
Created at 2020-03-13T19:52:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x403f44 |
Size Of Code | 0x8200 |
Size Of Initialized Data | 0x7200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-03-10 23:06:11+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x8194 | 0x8200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.54 |
.rdata | 0x40a000 | 0x3f0c | 0x4000 | 0x8600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.31 |
.data | 0x40e000 | 0x1ac4 | 0xe00 | 0xc600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.66 |
.reloc | 0x410000 | 0x144c | 0x1600 | 0xd400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 3.97 |
Imports (4)
»
KERNEL32.dll (76)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetTickCount | 0x0 | 0x40a028 | 0xd758 | 0xbd58 | 0x293 |
GetProcessHeap | 0x0 | 0x40a02c | 0xd75c | 0xbd5c | 0x24a |
WriteFile | 0x0 | 0x40a030 | 0xd760 | 0xbd60 | 0x525 |
Sleep | 0x0 | 0x40a034 | 0xd764 | 0xbd64 | 0x4b2 |
ReadFile | 0x0 | 0x40a038 | 0xd768 | 0xbd68 | 0x3c0 |
CreateFileW | 0x0 | 0x40a03c | 0xd76c | 0xbd6c | 0x8f |
GetFileSizeEx | 0x0 | 0x40a040 | 0xd770 | 0xbd70 | 0x1f1 |
GetStdHandle | 0x0 | 0x40a044 | 0xd774 | 0xbd74 | 0x264 |
GetLastError | 0x0 | 0x40a048 | 0xd778 | 0xbd78 | 0x202 |
SetLastError | 0x0 | 0x40a04c | 0xd77c | 0xbd7c | 0x473 |
GetProcAddress | 0x0 | 0x40a050 | 0xd780 | 0xbd80 | 0x245 |
MoveFileW | 0x0 | 0x40a054 | 0xd784 | 0xbd84 | 0x363 |
GetLogicalDrives | 0x0 | 0x40a058 | 0xd788 | 0xbd88 | 0x209 |
LoadLibraryA | 0x0 | 0x40a05c | 0xd78c | 0xbd8c | 0x33c |
lstrcmpiW | 0x0 | 0x40a060 | 0xd790 | 0xbd90 | 0x545 |
FindNextFileW | 0x0 | 0x40a064 | 0xd794 | 0xbd94 | 0x145 |
CloseHandle | 0x0 | 0x40a068 | 0xd798 | 0xbd98 | 0x52 |
CreateThread | 0x0 | 0x40a06c | 0xd79c | 0xbd9c | 0xb5 |
ExitProcess | 0x0 | 0x40a070 | 0xd7a0 | 0xbda0 | 0x119 |
GetModuleFileNameW | 0x0 | 0x40a074 | 0xd7a4 | 0xbda4 | 0x214 |
WideCharToMultiByte | 0x0 | 0x40a078 | 0xd7a8 | 0xbda8 | 0x511 |
ExitThread | 0x0 | 0x40a07c | 0xd7ac | 0xbdac | 0x11a |
MultiByteToWideChar | 0x0 | 0x40a080 | 0xd7b0 | 0xbdb0 | 0x367 |
CreateMutexA | 0x0 | 0x40a084 | 0xd7b4 | 0xbdb4 | 0x9b |
WaitForSingleObject | 0x0 | 0x40a088 | 0xd7b8 | 0xbdb8 | 0x4f9 |
HeapFree | 0x0 | 0x40a08c | 0xd7bc | 0xbdbc | 0x2cf |
SetFilePointerEx | 0x0 | 0x40a090 | 0xd7c0 | 0xbdc0 | 0x467 |
GetCurrentProcess | 0x0 | 0x40a094 | 0xd7c4 | 0xbdc4 | 0x1c0 |
HeapAlloc | 0x0 | 0x40a098 | 0xd7c8 | 0xbdc8 | 0x2cb |
GetDriveTypeW | 0x0 | 0x40a09c | 0xd7cc | 0xbdcc | 0x1d3 |
lstrlenA | 0x0 | 0x40a0a0 | 0xd7d0 | 0xbdd0 | 0x54d |
FindFirstFileW | 0x0 | 0x40a0a4 | 0xd7d4 | 0xbdd4 | 0x139 |
FindClose | 0x0 | 0x40a0a8 | 0xd7d8 | 0xbdd8 | 0x12e |
GetSystemDefaultLangID | 0x0 | 0x40a0ac | 0xd7dc | 0xbddc | 0x26c |
GetStringTypeW | 0x0 | 0x40a0b0 | 0xd7e0 | 0xbde0 | 0x269 |
LCMapStringW | 0x0 | 0x40a0b4 | 0xd7e4 | 0xbde4 | 0x32d |
IsValidCodePage | 0x0 | 0x40a0b8 | 0xd7e8 | 0xbde8 | 0x30a |
GetSystemTimeAsFileTime | 0x0 | 0x40a0bc | 0xd7ec | 0xbdec | 0x279 |
EncodePointer | 0x0 | 0x40a0c0 | 0xd7f0 | 0xbdf0 | 0xea |
DecodePointer | 0x0 | 0x40a0c4 | 0xd7f4 | 0xbdf4 | 0xca |
GetCommandLineA | 0x0 | 0x40a0c8 | 0xd7f8 | 0xbdf8 | 0x186 |
HeapSetInformation | 0x0 | 0x40a0cc | 0xd7fc | 0xbdfc | 0x2d3 |
RaiseException | 0x0 | 0x40a0d0 | 0xd800 | 0xbe00 | 0x3b1 |
TerminateProcess | 0x0 | 0x40a0d4 | 0xd804 | 0xbe04 | 0x4c0 |
UnhandledExceptionFilter | 0x0 | 0x40a0d8 | 0xd808 | 0xbe08 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x40a0dc | 0xd80c | 0xbe0c | 0x4a5 |
IsDebuggerPresent | 0x0 | 0x40a0e0 | 0xd810 | 0xbe10 | 0x300 |
IsProcessorFeaturePresent | 0x0 | 0x40a0e4 | 0xd814 | 0xbe14 | 0x304 |
HeapSize | 0x0 | 0x40a0e8 | 0xd818 | 0xbe18 | 0x2d4 |
GetModuleHandleW | 0x0 | 0x40a0ec | 0xd81c | 0xbe1c | 0x218 |
GetModuleFileNameA | 0x0 | 0x40a0f0 | 0xd820 | 0xbe20 | 0x213 |
FreeEnvironmentStringsW | 0x0 | 0x40a0f4 | 0xd824 | 0xbe24 | 0x161 |
GetEnvironmentStringsW | 0x0 | 0x40a0f8 | 0xd828 | 0xbe28 | 0x1da |
SetHandleCount | 0x0 | 0x40a0fc | 0xd82c | 0xbe2c | 0x46f |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x40a100 | 0xd830 | 0xbe30 | 0x2e3 |
GetFileType | 0x0 | 0x40a104 | 0xd834 | 0xbe34 | 0x1f3 |
GetStartupInfoW | 0x0 | 0x40a108 | 0xd838 | 0xbe38 | 0x263 |
DeleteCriticalSection | 0x0 | 0x40a10c | 0xd83c | 0xbe3c | 0xd1 |
TlsAlloc | 0x0 | 0x40a110 | 0xd840 | 0xbe40 | 0x4c5 |
TlsGetValue | 0x0 | 0x40a114 | 0xd844 | 0xbe44 | 0x4c7 |
TlsSetValue | 0x0 | 0x40a118 | 0xd848 | 0xbe48 | 0x4c8 |
TlsFree | 0x0 | 0x40a11c | 0xd84c | 0xbe4c | 0x4c6 |
InterlockedIncrement | 0x0 | 0x40a120 | 0xd850 | 0xbe50 | 0x2ef |
GetCurrentThreadId | 0x0 | 0x40a124 | 0xd854 | 0xbe54 | 0x1c5 |
InterlockedDecrement | 0x0 | 0x40a128 | 0xd858 | 0xbe58 | 0x2eb |
HeapCreate | 0x0 | 0x40a12c | 0xd85c | 0xbe5c | 0x2cd |
QueryPerformanceCounter | 0x0 | 0x40a130 | 0xd860 | 0xbe60 | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x40a134 | 0xd864 | 0xbe64 | 0x1c1 |
LeaveCriticalSection | 0x0 | 0x40a138 | 0xd868 | 0xbe68 | 0x339 |
EnterCriticalSection | 0x0 | 0x40a13c | 0xd86c | 0xbe6c | 0xee |
RtlUnwind | 0x0 | 0x40a140 | 0xd870 | 0xbe70 | 0x418 |
HeapReAlloc | 0x0 | 0x40a144 | 0xd874 | 0xbe74 | 0x2d2 |
LoadLibraryW | 0x0 | 0x40a148 | 0xd878 | 0xbe78 | 0x33f |
GetCPInfo | 0x0 | 0x40a14c | 0xd87c | 0xbe7c | 0x172 |
GetACP | 0x0 | 0x40a150 | 0xd880 | 0xbe80 | 0x168 |
GetOEMCP | 0x0 | 0x40a154 | 0xd884 | 0xbe84 | 0x237 |
ADVAPI32.dll (9)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptDecrypt | 0x0 | 0x40a000 | 0xd730 | 0xbd30 | 0xb4 |
CryptCreateHash | 0x0 | 0x40a004 | 0xd734 | 0xbd34 | 0xb3 |
CryptDeriveKey | 0x0 | 0x40a008 | 0xd738 | 0xbd38 | 0xb5 |
CryptDestroyKey | 0x0 | 0x40a00c | 0xd73c | 0xbd3c | 0xb7 |
CryptEncrypt | 0x0 | 0x40a010 | 0xd740 | 0xbd40 | 0xba |
CryptImportKey | 0x0 | 0x40a014 | 0xd744 | 0xbd44 | 0xca |
CryptAcquireContextA | 0x0 | 0x40a018 | 0xd748 | 0xbd48 | 0xb0 |
CryptReleaseContext | 0x0 | 0x40a01c | 0xd74c | 0xbd4c | 0xcb |
CryptHashData | 0x0 | 0x40a020 | 0xd750 | 0xbd50 | 0xc8 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x40a15c | 0xd88c | 0xbe8c | 0x122 |
SHLWAPI.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathFindExtensionW | 0x0 | 0x40a164 | 0xd894 | 0xbe94 | 0x47 |
PathIsDirectoryW | 0x0 | 0x40a168 | 0xd898 | 0xbe98 | 0x5b |
Digital Signatures (2)
»
Certificate: Inter Med Pty. Ltd.
»
Issued by | Inter Med Pty. Ltd. |
Parent Certificate | Sectigo RSA Code Signing CA |
Country Name | AU |
Valid From | 2020-03-06 00:00:00+00:00 |
Valid Until | 2021-03-06 23:59:59+00:00 |
Algorithm | sha256_rsa |
Serial Number | 39 F5 62 51 DF 20 88 22 3C C0 34 94 08 4E 60 81 |
Thumbprint | 29 23 96 59 23 1A 88 CA 51 88 39 BF 57 04 8F F7 9A 27 25 54 |
Certificate: Sectigo RSA Code Signing CA
»
Issued by | Sectigo RSA Code Signing CA |
Country Name | GB |
Valid From | 2018-11-02 00:00:00+00:00 |
Valid Until | 2030-12-31 23:59:59+00:00 |
Algorithm | sha384_rsa |
Serial Number | 1D A2 48 30 6F 9B 26 18 D0 82 E0 96 7D 33 D3 6A |
Thumbprint | 94 C9 5D A1 E8 50 BD 85 20 9A 4A 2A F3 E1 FB 16 04 F9 BB 66 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
1.exe | 1 | 0x010A0000 | 0x010B1FFF | Relevant Image |
![]() |
32-bit | 0x010A633A |
![]() |
![]() |
...
|
1.exe | 1 | 0x010A0000 | 0x010B1FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
C:\$WINRE_BACKUP_PARTITION.MARKER | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\eula.rtf | Modified File | Binary |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\eula.rtf.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\eula.rtf.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\eula.rtf.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\Parameterinfo.xml.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DHtmlHeader.html.NEFILIM | Dropped File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\UiInfo.xml.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Print.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate1.ico.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate2.ico.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate5.ico.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate6.ico.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate7.ico.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqMet.ico.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\warn.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp.NEFILIM | Dropped File | Binary |
Unknown
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Strings.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Key Management Service.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Admin.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Windows PowerShell.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Oracle\Java\.oracle_jre_usage\17dfc292991c7c46.timestamp.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Oracle\Java\installcache_x64\baseimagefam8.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Package Cache\{f325f05b-f963-4640-a43b-c8a494cdda0f}\state.rsm.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Extensibility Component.swidtag.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Licensing Component.swidtag.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Localization Component.swidtag.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft_Windows-10-Pro.swidtag.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUx.001.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUx.002.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.001.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.002.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.003.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.004.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.008.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.009.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.011.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.012.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.013.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.014.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.016.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.017.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.003.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.004.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.007.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.008.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.009.etl.NEFILIM | Modified File | Compressed |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.010.etl.NEFILIM | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.011.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.012.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.013.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.014.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.017.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.020.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.021.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.022.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.023.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.025.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.028.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.029.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.031.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.032.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.034.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.035.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.036.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.037.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateUx.001.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateUx.002.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT.LOG1.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TMContainer00000000000000000001.regtrans-ms.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1028\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\eula.rtf.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1033\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1036\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1037\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1041\eula.rtf.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1041\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1044\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1046\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1049\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1055\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2070\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3082\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\DisplayIcon.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Extended\Parameterinfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate3.ico.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate4.ico.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate8.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Save.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Setup.ico.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\stop.ico.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Core.mzz | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\HardwareEvents.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-International%4Operational.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Known Folders API Service.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Operational.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Store%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Security.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Package Cache\{3c3aafc8-d898-43ec-998f-965ffdae065a}\state.rsm.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Package Cache\{e52a6842-b0ac-476e-b48f-378a97a67346}\state.rsm.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Package Cache\{e6e75766-da0f-4ba2-9788-6ea593ce702d}\state.rsm.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOPrivate\UpdateStore\UpdateCspStore.xml.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOPrivate\UpdateStore\updatestore51b519d5-b6f5-4333-8df6-e74d7c9aead4.xml.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.005.etl.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.006.etl.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.007.etl.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.010.etl.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.015.etl.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.002.etl.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.005.etl.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.006.etl.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.015.etl.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.016.etl.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.018.etl.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.019.etl.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.024.etl.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.026.etl.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.027.etl.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.030.etl.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.033.etl.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT.LOG2.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TM.blf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TMContainer00000000000000000002.regtrans-ms.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT{fae9930d-933c-11e7-a51d-b808901d6c9b}.TM.blf | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-1051304884-625712362-2192934891-1000\e0706a18c295d32ea97b3bdcc41d5105_33d770d0-06bc-47c5-8714-222cdac43a71 | Dropped File | Stream |
Not Queried
|
...
|
»