VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Gen:Heur.Ransom.Imps.1
|
oqvvgi.exe
Windows Exe (x86-32)
Created at 2020-08-04T21:38:00
Remarks (1/1)
(0x02000010): The operating system was rebooted during the analysis.
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4100af |
Size Of Code | 0x2ee00 |
Size Of Initialized Data | 0x24e00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-07-23 00:47:15+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x2ec5e | 0x2ee00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x430000 | 0xfbf6 | 0xfc00 | 0x2f200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.61 |
.data | 0x440000 | 0x1d3c | 0x1000 | 0x3ee00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.19 |
.rsrc | 0x442000 | 0x10bb0 | 0x10c00 | 0x3fe00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.35 |
.reloc | 0x453000 | 0x2608 | 0x2800 | 0x50a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.45 |
Imports (6)
»
KERNEL32.dll (83)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateFileW | 0x0 | 0x430030 | 0x3f350 | 0x3e550 | 0xca |
SetFilePointerEx | 0x0 | 0x430034 | 0x3f354 | 0x3e554 | 0x51b |
FlushFileBuffers | 0x0 | 0x430038 | 0x3f358 | 0x3e558 | 0x19d |
SetStdHandle | 0x0 | 0x43003c | 0x3f35c | 0x3e55c | 0x542 |
GetProcessHeap | 0x0 | 0x430040 | 0x3f360 | 0x3e560 | 0x2b0 |
SetEnvironmentVariableA | 0x0 | 0x430044 | 0x3f364 | 0x3e564 | 0x50b |
FreeEnvironmentStringsW | 0x0 | 0x430048 | 0x3f368 | 0x3e568 | 0x1a8 |
GetEnvironmentStringsW | 0x0 | 0x43004c | 0x3f36c | 0x3e56c | 0x233 |
GetOEMCP | 0x0 | 0x430050 | 0x3f370 | 0x3e570 | 0x293 |
IsValidCodePage | 0x0 | 0x430054 | 0x3f374 | 0x3e574 | 0x386 |
FindFirstFileExA | 0x0 | 0x430058 | 0x3f378 | 0x3e578 | 0x178 |
HeapSize | 0x0 | 0x43005c | 0x3f37c | 0x3e57c | 0x34a |
ReadConsoleW | 0x0 | 0x430060 | 0x3f380 | 0x3e580 | 0x469 |
SetEndOfFile | 0x0 | 0x430064 | 0x3f384 | 0x3e584 | 0x508 |
GetLogicalDriveStringsA | 0x0 | 0x430068 | 0x3f388 | 0x3e588 | 0x262 |
DefineDosDeviceW | 0x0 | 0x43006c | 0x3f38c | 0x3e58c | 0x10a |
MoveFileExA | 0x0 | 0x430070 | 0x3f390 | 0x3e590 | 0x3e0 |
GetTempPathW | 0x0 | 0x430074 | 0x3f394 | 0x3e594 | 0x2f2 |
SetFilePointer | 0x0 | 0x430078 | 0x3f398 | 0x3e598 | 0x51a |
GetDriveTypeA | 0x0 | 0x43007c | 0x3f39c | 0x3e59c | 0x22a |
GetModuleFileNameA | 0x0 | 0x430080 | 0x3f3a0 | 0x3e5a0 | 0x26f |
FindClose | 0x0 | 0x430084 | 0x3f3a4 | 0x3e5a4 | 0x173 |
FindNextFileA | 0x0 | 0x430088 | 0x3f3a8 | 0x3e5a8 | 0x188 |
FindFirstFileA | 0x0 | 0x43008c | 0x3f3ac | 0x3e5ac | 0x177 |
CloseHandle | 0x0 | 0x430090 | 0x3f3b0 | 0x3e5b0 | 0x86 |
CreateFileA | 0x0 | 0x430094 | 0x3f3b4 | 0x3e5b4 | 0xc2 |
GetConsoleMode | 0x0 | 0x430098 | 0x3f3b8 | 0x3e5b8 | 0x1fa |
GetConsoleCP | 0x0 | 0x43009c | 0x3f3bc | 0x3e5bc | 0x1e8 |
GetFileType | 0x0 | 0x4300a0 | 0x3f3c0 | 0x3e5c0 | 0x24a |
EnumSystemLocalesW | 0x0 | 0x4300a4 | 0x3f3c4 | 0x3e5c4 | 0x152 |
GetUserDefaultLCID | 0x0 | 0x4300a8 | 0x3f3c8 | 0x3e5c8 | 0x30e |
IsValidLocale | 0x0 | 0x4300ac | 0x3f3cc | 0x3e5cc | 0x388 |
HeapFree | 0x0 | 0x4300b0 | 0x3f3d0 | 0x3e5d0 | 0x345 |
HeapReAlloc | 0x0 | 0x4300b4 | 0x3f3d4 | 0x3e5d4 | 0x348 |
HeapAlloc | 0x0 | 0x4300b8 | 0x3f3d8 | 0x3e5d8 | 0x341 |
GetACP | 0x0 | 0x4300bc | 0x3f3dc | 0x3e5dc | 0x1b0 |
GetCommandLineW | 0x0 | 0x4300c0 | 0x3f3e0 | 0x3e5e0 | 0x1d5 |
GetCommandLineA | 0x0 | 0x4300c4 | 0x3f3e4 | 0x3e5e4 | 0x1d4 |
GetStdHandle | 0x0 | 0x4300c8 | 0x3f3e8 | 0x3e5e8 | 0x2ce |
GetLastError | 0x0 | 0x4300cc | 0x3f3ec | 0x3e5ec | 0x25d |
lstrlenA | 0x0 | 0x4300d0 | 0x3f3f0 | 0x3e5f0 | 0x633 |
WriteFile | 0x0 | 0x4300d4 | 0x3f3f4 | 0x3e5f4 | 0x60a |
ReadFile | 0x0 | 0x4300d8 | 0x3f3f8 | 0x3e5f8 | 0x46c |
UnhandledExceptionFilter | 0x0 | 0x4300dc | 0x3f3fc | 0x3e5fc | 0x5a5 |
SetUnhandledExceptionFilter | 0x0 | 0x4300e0 | 0x3f400 | 0x3e600 | 0x565 |
GetCurrentProcess | 0x0 | 0x4300e4 | 0x3f404 | 0x3e604 | 0x215 |
TerminateProcess | 0x0 | 0x4300e8 | 0x3f408 | 0x3e608 | 0x584 |
IsProcessorFeaturePresent | 0x0 | 0x4300ec | 0x3f40c | 0x3e60c | 0x381 |
IsDebuggerPresent | 0x0 | 0x4300f0 | 0x3f410 | 0x3e610 | 0x37a |
GetStartupInfoW | 0x0 | 0x4300f4 | 0x3f414 | 0x3e614 | 0x2cc |
GetModuleHandleW | 0x0 | 0x4300f8 | 0x3f418 | 0x3e618 | 0x274 |
QueryPerformanceCounter | 0x0 | 0x4300fc | 0x3f41c | 0x3e61c | 0x446 |
GetCurrentProcessId | 0x0 | 0x430100 | 0x3f420 | 0x3e620 | 0x216 |
GetCurrentThreadId | 0x0 | 0x430104 | 0x3f424 | 0x3e624 | 0x21a |
GetSystemTimeAsFileTime | 0x0 | 0x430108 | 0x3f428 | 0x3e628 | 0x2e5 |
InitializeSListHead | 0x0 | 0x43010c | 0x3f42c | 0x3e62c | 0x35e |
WideCharToMultiByte | 0x0 | 0x430110 | 0x3f430 | 0x3e630 | 0x5f6 |
SetLastError | 0x0 | 0x430114 | 0x3f434 | 0x3e634 | 0x52a |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x430118 | 0x3f438 | 0x3e638 | 0x35a |
Sleep | 0x0 | 0x43011c | 0x3f43c | 0x3e63c | 0x575 |
TlsAlloc | 0x0 | 0x430120 | 0x3f440 | 0x3e640 | 0x596 |
TlsGetValue | 0x0 | 0x430124 | 0x3f444 | 0x3e644 | 0x598 |
TlsSetValue | 0x0 | 0x430128 | 0x3f448 | 0x3e648 | 0x599 |
TlsFree | 0x0 | 0x43012c | 0x3f44c | 0x3e64c | 0x597 |
GetProcAddress | 0x0 | 0x430130 | 0x3f450 | 0x3e650 | 0x2aa |
EncodePointer | 0x0 | 0x430134 | 0x3f454 | 0x3e654 | 0x12b |
DecodePointer | 0x0 | 0x430138 | 0x3f458 | 0x3e658 | 0x107 |
EnterCriticalSection | 0x0 | 0x43013c | 0x3f45c | 0x3e65c | 0x12f |
LeaveCriticalSection | 0x0 | 0x430140 | 0x3f460 | 0x3e660 | 0x3b8 |
DeleteCriticalSection | 0x0 | 0x430144 | 0x3f464 | 0x3e664 | 0x10e |
MultiByteToWideChar | 0x0 | 0x430148 | 0x3f468 | 0x3e668 | 0x3e8 |
CompareStringW | 0x0 | 0x43014c | 0x3f46c | 0x3e66c | 0x9a |
LCMapStringW | 0x0 | 0x430150 | 0x3f470 | 0x3e670 | 0x3ac |
GetLocaleInfoW | 0x0 | 0x430154 | 0x3f474 | 0x3e674 | 0x261 |
GetStringTypeW | 0x0 | 0x430158 | 0x3f478 | 0x3e678 | 0x2d3 |
GetCPInfo | 0x0 | 0x43015c | 0x3f47c | 0x3e67c | 0x1bf |
RtlUnwind | 0x0 | 0x430160 | 0x3f480 | 0x3e680 | 0x4cb |
RaiseException | 0x0 | 0x430164 | 0x3f484 | 0x3e684 | 0x45b |
FreeLibrary | 0x0 | 0x430168 | 0x3f488 | 0x3e688 | 0x1a9 |
LoadLibraryExW | 0x0 | 0x43016c | 0x3f48c | 0x3e68c | 0x3be |
ExitProcess | 0x0 | 0x430170 | 0x3f490 | 0x3e690 | 0x15c |
GetModuleHandleExW | 0x0 | 0x430174 | 0x3f494 | 0x3e694 | 0x273 |
WriteConsoleW | 0x0 | 0x430178 | 0x3f498 | 0x3e698 | 0x609 |
ADVAPI32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegCloseKey | 0x0 | 0x430000 | 0x3f320 | 0x3e520 | 0x25b |
CryptAcquireContextW | 0x0 | 0x430004 | 0x3f324 | 0x3e524 | 0xc2 |
CryptGenRandom | 0x0 | 0x430008 | 0x3f328 | 0x3e528 | 0xd2 |
RegCreateKeyExA | 0x0 | 0x43000c | 0x3f32c | 0x3e52c | 0x263 |
RegSetValueExA | 0x0 | 0x430010 | 0x3f330 | 0x3e530 | 0x2a8 |
RegOpenKeyExA | 0x0 | 0x430014 | 0x3f334 | 0x3e534 | 0x28b |
CryptAcquireContextA | 0x0 | 0x430018 | 0x3f338 | 0x3e538 | 0xc1 |
CryptReleaseContext | 0x0 | 0x43001c | 0x3f33c | 0x3e53c | 0xdc |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteA | 0x0 | 0x430180 | 0x3f4a0 | 0x3e6a0 | 0x1b4 |
ole32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoTaskMemAlloc | 0x0 | 0x430190 | 0x3f4b0 | 0x3e6b0 | 0x88 |
CoTaskMemFree | 0x0 | 0x430194 | 0x3f4b4 | 0x3e6b4 | 0x89 |
SHLWAPI.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathFindFileNameA | 0x0 | 0x430188 | 0x3f4a8 | 0x3e6a8 | 0x4c |
CRYPT32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptBinaryToStringA | 0x0 | 0x430024 | 0x3f344 | 0x3e544 | 0x7e |
CryptStringToBinaryA | 0x0 | 0x430028 | 0x3f348 | 0x3e548 | 0xe3 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
oqvvgi.exe | 1 | 0x009E0000 | 0x00A35FFF | Relevant Image |
![]() |
32-bit | 0x009F3A83 |
![]() |
![]() |
...
|
oqvvgi.exe | 1 | 0x009E0000 | 0x00A35FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Ransom.Imps.1 |
Malicious
|
C:\\588bce7c90097ed212\1025\eula.rtf.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1025\LocalizedData.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1029\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1029\LocalizedData.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1030\eula.rtf.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1030\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1031\eula.rtf.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1031\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1032\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1033\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1033\LocalizedData.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1035\LocalizedData.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1036\eula.rtf.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1036\LocalizedData.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1037\LocalizedData.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1038\eula.rtf.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1040\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1041\eula.rtf.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1041\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1042\eula.rtf.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1042\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1043\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1043\LocalizedData.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1044\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1044\LocalizedData.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1045\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1045\LocalizedData.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1046\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1049\eula.rtf.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1049\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1053\eula.rtf.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1053\LocalizedData.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1055\eula.rtf.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1055\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\2052\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\2070\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\2070\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\3076\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1028\LocalizedData.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\3082\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\3082\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Client\Parameterinfo.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Client\UiInfo.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Extended\Parameterinfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Extended\UiInfo.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\header.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Strings.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\UiInfo.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\19B11135-37BD-4FA1-A78E-C20CA2BDA1C0\en-us.16\MasterDescriptor.en-us.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\201EB7DF-C721-4B8B-9C81-A09DE7F931E6\x-none.16\MasterDescriptor.x-none.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\DeploymentConfig.0.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\DeploymentConfig.1.xml.ment | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\DeploymentConfig.2.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\Manifest.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\DeploymentConfiguration.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\MachineData\Catalog\Packages\{9AC08E99-230B-47E8-9721-4577B7F124EA}\{1A8308C7-90D1-4200-B16E-646F163A08E8}\UserManifest.xml.ment | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\ProductReleases\5A65C4D7-3CDF-4BE4-8560-F036D300C13F\en-us.16\MasterDescriptor.en-us.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\ProductReleases\5A65C4D7-3CDF-4BE4-8560-F036D300C13F\en-us.16\stream.Platform.Culture.man.xml.ment | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\ProductReleases\5A65C4D7-3CDF-4BE4-8560-F036D300C13F\x-none.16\MasterDescriptor.x-none.xml.ment | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\ProductReleases\5A65C4D7-3CDF-4BE4-8560-F036D300C13F\x-none.16\stream.Platform.x-none.man.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Access.Access.x-none.msi.16.x-none.xml.ment | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.accessmui.msi.16.en-us.xml.ment | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.accessmuiset.msi.16.en-us.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.DCF.DCF.x-none.msi.16.x-none.xml.ment | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.dcfmui.msi.16.en-us.xml.ment | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Excel.Excel.x-none.msi.16.x-none.xml.ment | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.excelmui.msi.16.en-us.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.groovemui.msi.16.en-us.xml.ment | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Lync.Lync.x-none.msi.16.x-none.xml.ment | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.lyncmui.msi.16.en-us.xml.ment | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.office32mui.msi.16.en-us.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.office32ww.msi.16.x-none.xml.ment | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.officemui.msi.16.en-us.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OneNote.OneNote.x-none.msi.16.x-none.xml.ment | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.onenotemui.msi.16.en-us.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OSM.OSM.x-none.msi.16.x-none.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.osmmui.msi.16.en-us.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.OSMUX.OSMUX.x-none.msi.16.x-none.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.osmuxmui.msi.16.en-us.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Outlook.Outlook.x-none.msi.16.x-none.xml.ment | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.outlookmui.msi.16.en-us.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.PowerPivot.PowerPivot.x-none.msi.16.x-none.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.PowerPoint.PowerPoint.x-none.msi.16.x-none.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.powerpointmui.msi.16.en-us.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Project.Project.x-none.msi.16.x-none.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.projectmui.msi.16.en-us.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Proof.Culture.msi.16.es-es.xml.ment | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.proofing.msi.16.en-us.xml.ment | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.publishermui.msi.16.en-us.xml.ment | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.shared.Office.x-none.msi.16.x-none.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Visio.Visio.x-none.msi.16.x-none.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.visiomui.msi.16.en-us.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Word.Word.x-none.msi.16.x-none.xml.ment | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.wordmui.msi.16.en-us.xml.ment | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\Microsoft_Office_OfficeTelemetryAgentFallBack2016.xml.ment | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\Microsoft_Office_OfficeTelemetryAgentLogOn2016.xml.ment | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop-HOW-TO-DECRYPT.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1032\LocalizedData.xml.ment | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1035\eula.rtf.ment | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1037\eula.rtf.ment | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1046\eula.rtf.ment | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\2052\eula.rtf.ment | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\ParameterInfo.xml.ment | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\SplashScreen.bmp.ment | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\watermark.bmp.ment | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Groove.Groove.x-none.msi.16.x-none.xml.ment | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.officemuiset.msi.16.en-us.xml.ment | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Proof.Culture.msi.16.en-us.xml.ment | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Proof.Culture.msi.16.fr-fr.xml.ment | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\All Users\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\C2RManifest.Publisher.Publisher.x-none.msi.16.x-none.xml.ment | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktopcount.txt | Dropped File | Text |
Not Queried
|
...
|
»