VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Trojan.Ransom.Netwalker.A
Gen:Variant.Ransom.Netwalker.1
|
ef3ff3f0.exe
Windows Exe (x86-32)
Created at 2020-02-12T20:39:00
Remarks (2/2)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "30 seconds" to "10 seconds" to reveal dormant functionality.
Remarks
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x412150 |
Size Of Code | 0x15000 |
Size Of Initialized Data | 0x2400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-12-06 17:46:26+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x14fff | 0x15000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.15 |
.rdata | 0x416000 | 0x40e | 0x600 | 0x15400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.43 |
.data | 0x417000 | 0x460 | 0x200 | 0x15a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.75 |
.rsrc | 0x418000 | 0x1554 | 0x1600 | 0x15c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.94 |
.reloc | 0x41a000 | 0x5a4 | 0x600 | 0x17200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.39 |
Imports (1)
»
KERNEL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Sleep | 0x0 | 0x416000 | 0x163f0 | 0x157f0 | 0x575 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
ef3ff3f0.exe | 1 | 0x00D40000 | 0x00D5AFFF | Relevant Image |
![]() |
32-bit | 0x00D425C0 |
![]() |
![]() |
...
|
buffer | 1 | 0x00C80000 | 0x00C9AFFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
ef3ff3f0.exe | 1 | 0x00D40000 | 0x00D5AFFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.Ransom.Netwalker.A |
Malicious
|
C:\Users\FD1HVy\Pictures\0algdtmoqwEQsbLT.bmp | Modified File | Stream |
Whitelisted
|
...
|
»
C:\Users\FD1HVy\Pictures\rmRm5VujyX_HCC.gif | Modified File | Stream |
Whitelisted
|
...
|
»
C:\Users\FD1HVy\Pictures\SPley3vWhB_6hs.gif | Modified File | Stream |
Whitelisted
|
...
|
»
C:\Users\FD1HVy\Pictures\WYmAnlDUMTZ_Pt.gif | Modified File | Stream |
Whitelisted
|
...
|
»
C:\Users\FD1HVy\Music\8PJXMFVd1.mp3 | Modified File | Stream |
Whitelisted
|
...
|
»
C:\Users\FD1HVy\Music\scM4r.m4a | Modified File | Stream |
Whitelisted
|
...
|
»
C:\Users\FD1HVy\Documents\BOdetRenpdxKb6QC1UrV.xlsx | Modified File | Stream |
Whitelisted
|
...
|
»
C:\Users\FD1HVy\Documents\uOFkECuPU.xlsx | Modified File | Stream |
Whitelisted
|
...
|
»
C:\Users\FD1HVy\Desktop\32670RwV1Oxd5LF5.gif | Modified File | Stream |
Whitelisted
|
...
|
»
C:\Users\FD1HVy\Desktop\9QLAhBRTqcQ.flv | Modified File | Stream |
Whitelisted
|
...
|
»
C:\Users\FD1HVy\Music\siybYIA0\G3vnT-RcV.mp3 | Modified File | Stream |
Whitelisted
|
...
|
»
C:\Users\FD1HVy\Music\siybYIA0\kPk65KjtvzEdXF.m4a | Modified File | Stream |
Whitelisted
|
...
|
»
C:\588bce7c90097ed212\Strings.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DHtmlHeader.html | Modified File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core.mzz | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Key Management Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Known Folders API Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-International%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\BEhdate.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\cEqV.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\ekbflhqnblaZZXa.ods | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\eKVPy-9VMIEi JW.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\fIxG.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\fLADy0S29O.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\IfU Ay66B.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\qDrKhg38hlbWs0.bmp | Modified File | Office File |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\QXT68k2qiJPK M.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\SejX7-sVJe.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\SVygtGN2.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\uAZLUFDQm.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\wstFzu.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\xqH-bfT3Sg.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\SNKrcMAU.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YAw1mXxnf1gDdzqF5w4N.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\4V8fHb1NEKeSJc.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\dCJ2.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\eZxR4UE1l.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\GJoKdTfOL9ji8GXtw1b.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Jbc4PG hVWo7ul7-.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\KtP2-2cxUhk6Xb8YJ7.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\nx9GYYC2Rsjy1CN.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\pdMKY_DQ4R6F.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\pz8mRn91F.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\SelLngVXnEkSdjqcmVS.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\38uKSkZAiozNgTxGB.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\ppDpDLkO.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\TsHN_-DOMF Kz8I.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\5d8j8.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\BhVG8sEYuHI e.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\LgDLYrs.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\oXptnEALZNCIx7qNkkii.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\pXaOgk9GE1upWx.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Q4_PNzrN.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\R4QR.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\XIuM.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\YGcP76-KczLAPYEvPx.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Z B5wY iscDO9GFwsKpM.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\-zgrM9.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\39E9.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\3RTQUW2BS_.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\DkpjLP5M_k.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\evwMKgOzdO2DlQHqbWE.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\F9cV.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\klYTOSp2nv3qCIKv.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\lBoLBknioIKFwym.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\MOTB.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Q6neBp9.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\rSTGLb40SzTKhhfO.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\vdQMRI5Mhw6nRn2.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Xfbjc ztk.ods | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\YZDkWQoGFHYXs.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\COPYRIGHT | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\LICENSE | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Store%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\content-types.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\access-bridge-64.jar | Modified File | Java Archive |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\flavormap.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fontconfig.properties.src | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jce.jar | Modified File | Java Archive |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jfr.jar | Modified File | Java Archive |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\logging.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\management-agent.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\net.properties | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\resources.jar | Modified File | Java Archive |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\rt.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Favorites\Bing.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\UoJQqpc-TPlhHkjZqD\1FznT1aJ4sm\0Aug\InreizrY1C1XHVh.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\UoJQqpc-TPlhHkjZqD\l_SMVRBXvSWgYHn5.ots | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\0qZ1VEn\PXlpnL8zaDXPEQqI.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\_PLqwB\1B6Fp9MVEOF.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\_PLqwB\C9PNUHen.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\_PLqwB\iFFa.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\siybYIA0\CK9Wpw.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\siybYIA0\qzOf3JFfs-J.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\siybYIA0\xwWMYSyBx.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\IgPHumGpOyi\WocACWczdEi.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\IgPHumGpOyi\nMiOK6zeTStn.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\IgPHumGpOyi\j1UAx9SN6m.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\_PLqwB\ZqEHyyb-ebHUXQZ4.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\_PLqwB\y7ng-NLkqB2JRPZIWQ.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\_PLqwB\orND3Tchiwkya4H5.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\_PLqwB\0KnmiLXS1V6M1uAu.mp3 | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\0qZ1VEn\QBl0VZJKsl_M.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\amd64\BiosBlocks.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\lLMKz1W\ZoSDUSz3c59BTS.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\tzmappings | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\plugin.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\meta-index | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jfxswt.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\javaws.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\header.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\BVw Kx kkPRD2Vat.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\gOZyzRovF2zpxf 3-.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Js5UIdrB.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\LNyQP4 UteiJh8ZnZVI.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\PoTTHc0wj Mlp.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\ulSIcR0ydo9WK.ots | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\v XP9.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\whkgOt.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\JAMR22Wfa.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\-09CD4P-xMTV.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\0-2fU4I-yh6ST.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\AVvZEDdWpVOsZ9.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\C-RSge6FoDG.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\e8RP7fcF2GbKFno4wEQ.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\f9G-epH1h mcDmhoie.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\fLcjAxTi18dQlVO.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\pg_Otsmww.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\PIFelTYGWeNcE8I.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\rYWV6NLyHJH.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\UPDgNAJFk_8.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\zF-qkv6.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\_IFws.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\3RPF7uizkWhEbCYZX82n.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\s0GdPqj8GLeJZL.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\z8IVbLeOS2MdsJM4Qm.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\7fYhDgrk4Oflzx.pptx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\B7J1.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\BSQC9Dr4kg9Tb2.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\hDFe0_c9uuJxXHVlQ.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\NgaH9-S28Td4CjdpZ.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\ThmgR4UeY.pptx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\-P3XyyVavLec0sKG-bX9.ots | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\6rJ4zuIO9I.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\aqaYC.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\g8rpcVHRizs14C.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\GupI.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\jx2O629A2-48Sx5.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\L6MUi p.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\T6vFQ-8_OByh97WPG8n.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\TvaZaKnck05q.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\TWTBg90RE6bO.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\UTlC-SqWY_RcPFlrdtX9.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\README.txt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\release | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft\Windows\AppxProvisioning.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2017-09-26.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft\Windows\SleepStudy\sleepstudy-report-latest.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\accessibility.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\calendars.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\currency.data | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\ffjcext.zip | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fontconfig.bfc | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaBrightDemiBold.ttf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\hijrah-config-umalqura.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\javafx.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jsse.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jvm.hprof.txt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\psfont.properties.ja | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\psfontj2d.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\sound.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\tzdb.dat | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\lLMKz1W\574tRWuFE4nB3ib5-Tp.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\lLMKz1W\5LyR-.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\lLMKz1W\coo4EbVBHlZSJOyb7.pps | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\lLMKz1W\kdektZvR.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\lLMKz1W\NgMGpHjS\aW_TT7wnqnrFVd.csv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\lLMKz1W\Xs_PfQV6pA.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\UoJQqpc-TPlhHkjZqD\BtPCfe9bjPyifgc5.doc | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\UoJQqpc-TPlhHkjZqD\pPnX_7btvRw3eLL.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\ux\block.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\0qZ1VEn\8U_O3t04F3 Mtr.pps | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\_PLqwB\94TVfm.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\_PLqwB\azZQ4sJMcGr2Gf.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\_PLqwB\lQ0I7gC_.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\_PLqwB\rwHfI4_h.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\_PLqwB\sgP96Lia9.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\_PLqwB\v6XSRpF077 2LUq8xHtn.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\_PLqwB\yLuqNTWrEwGtf.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\siybYIA0\-n3dCJb.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\siybYIA0\u HkfxB.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\IgPHumGpOyi\MWfD9AasOya.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\IgPHumGpOyi\m3gmDSfSPqv.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\hwcompatShared.txt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\i386\BiosBlocks.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\classlist | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\charsets.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\A0A70-Readme.txt | Dropped File | Text |
Not Queried
|
...
|
»