VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Gen:Variant.Graftor.447025
|
CUsersGrujaDesktop1.exe
Windows Exe (x86-32)
Created at 2020-01-22T21:13:00
Remarks
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\CUsersGrujaDesktop1.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x432f59 |
Size Of Code | 0x58400 |
Size Of Initialized Data | 0x27c00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-01-18 23:58:47+00:00 |
Sections (7)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x5837d | 0x58400 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.71 |
.rdata | 0x45a000 | 0x1ad0a | 0x1ae00 | 0x58800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.28 |
.data | 0x475000 | 0x6330 | 0x4200 | 0x73600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.83 |
.gfids | 0x47c000 | 0x1c4 | 0x200 | 0x77800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.5 |
.tls | 0x47d000 | 0x9 | 0x200 | 0x77a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.02 |
.rsrc | 0x47e000 | 0x1e0 | 0x200 | 0x77c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.72 |
.reloc | 0x47f000 | 0x62c4 | 0x6400 | 0x77e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.52 |
Imports (4)
»
KERNEL32.dll (93)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateFileA | 0x0 | 0x45a01c | 0x74404 | 0x72c04 | 0x88 |
GetFileAttributesExW | 0x0 | 0x45a020 | 0x74408 | 0x72c08 | 0x1e7 |
FindFirstFileW | 0x0 | 0x45a024 | 0x7440c | 0x72c0c | 0x139 |
FindNextFileW | 0x0 | 0x45a028 | 0x74410 | 0x72c10 | 0x145 |
ReleaseMutex | 0x0 | 0x45a02c | 0x74414 | 0x72c14 | 0x3fa |
CreateMutexA | 0x0 | 0x45a030 | 0x74418 | 0x72c18 | 0x9b |
OpenMutexA | 0x0 | 0x45a034 | 0x7441c | 0x72c1c | 0x37c |
FreeConsole | 0x0 | 0x45a038 | 0x74420 | 0x72c20 | 0x15f |
HeapAlloc | 0x0 | 0x45a03c | 0x74424 | 0x72c24 | 0x2cb |
HeapFree | 0x0 | 0x45a040 | 0x74428 | 0x72c28 | 0x2cf |
GetProcessHeap | 0x0 | 0x45a044 | 0x7442c | 0x72c2c | 0x24a |
GetTempPathA | 0x0 | 0x45a048 | 0x74430 | 0x72c30 | 0x284 |
CreateThread | 0x0 | 0x45a04c | 0x74434 | 0x72c34 | 0xb5 |
WaitForMultipleObjects | 0x0 | 0x45a050 | 0x74438 | 0x72c38 | 0x4f7 |
GetLastError | 0x0 | 0x45a054 | 0x7443c | 0x72c3c | 0x202 |
SetLastError | 0x0 | 0x45a058 | 0x74440 | 0x72c40 | 0x473 |
QueryPerformanceCounter | 0x0 | 0x45a05c | 0x74444 | 0x72c44 | 0x3a7 |
QueryPerformanceFrequency | 0x0 | 0x45a060 | 0x74448 | 0x72c48 | 0x3a8 |
CreateFileW | 0x0 | 0x45a064 | 0x7444c | 0x72c4c | 0x8f |
ReadConsoleW | 0x0 | 0x45a068 | 0x74450 | 0x72c50 | 0x3be |
WriteConsoleW | 0x0 | 0x45a06c | 0x74454 | 0x72c54 | 0x524 |
GetDriveTypeW | 0x0 | 0x45a070 | 0x74458 | 0x72c58 | 0x1d3 |
GetModuleFileNameA | 0x0 | 0x45a074 | 0x7445c | 0x72c5c | 0x213 |
GetLogicalDriveStringsW | 0x0 | 0x45a078 | 0x74460 | 0x72c60 | 0x208 |
CloseHandle | 0x0 | 0x45a07c | 0x74464 | 0x72c64 | 0x52 |
FindClose | 0x0 | 0x45a080 | 0x74468 | 0x72c68 | 0x12e |
ExitProcess | 0x0 | 0x45a084 | 0x7446c | 0x72c6c | 0x119 |
WriteFile | 0x0 | 0x45a088 | 0x74470 | 0x72c70 | 0x525 |
SetStdHandle | 0x0 | 0x45a08c | 0x74474 | 0x72c74 | 0x487 |
WideCharToMultiByte | 0x0 | 0x45a090 | 0x74478 | 0x72c78 | 0x511 |
MultiByteToWideChar | 0x0 | 0x45a094 | 0x7447c | 0x72c7c | 0x367 |
GetStringTypeW | 0x0 | 0x45a098 | 0x74480 | 0x72c80 | 0x269 |
EnterCriticalSection | 0x0 | 0x45a09c | 0x74484 | 0x72c84 | 0xee |
LeaveCriticalSection | 0x0 | 0x45a0a0 | 0x74488 | 0x72c88 | 0x339 |
DeleteCriticalSection | 0x0 | 0x45a0a4 | 0x7448c | 0x72c8c | 0xd1 |
EncodePointer | 0x0 | 0x45a0a8 | 0x74490 | 0x72c90 | 0xea |
DecodePointer | 0x0 | 0x45a0ac | 0x74494 | 0x72c94 | 0xca |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x45a0b0 | 0x74498 | 0x72c98 | 0x2e3 |
CreateEventW | 0x0 | 0x45a0b4 | 0x7449c | 0x72c9c | 0x85 |
TlsAlloc | 0x0 | 0x45a0b8 | 0x744a0 | 0x72ca0 | 0x4c5 |
TlsGetValue | 0x0 | 0x45a0bc | 0x744a4 | 0x72ca4 | 0x4c7 |
TlsSetValue | 0x0 | 0x45a0c0 | 0x744a8 | 0x72ca8 | 0x4c8 |
TlsFree | 0x0 | 0x45a0c4 | 0x744ac | 0x72cac | 0x4c6 |
GetSystemTimeAsFileTime | 0x0 | 0x45a0c8 | 0x744b0 | 0x72cb0 | 0x279 |
GetModuleHandleW | 0x0 | 0x45a0cc | 0x744b4 | 0x72cb4 | 0x218 |
GetProcAddress | 0x0 | 0x45a0d0 | 0x744b8 | 0x72cb8 | 0x245 |
CompareStringW | 0x0 | 0x45a0d4 | 0x744bc | 0x72cbc | 0x64 |
LCMapStringW | 0x0 | 0x45a0d8 | 0x744c0 | 0x72cc0 | 0x32d |
GetLocaleInfoW | 0x0 | 0x45a0dc | 0x744c4 | 0x72cc4 | 0x206 |
GetCPInfo | 0x0 | 0x45a0e0 | 0x744c8 | 0x72cc8 | 0x172 |
SetEvent | 0x0 | 0x45a0e4 | 0x744cc | 0x72ccc | 0x459 |
ResetEvent | 0x0 | 0x45a0e8 | 0x744d0 | 0x72cd0 | 0x40f |
WaitForSingleObjectEx | 0x0 | 0x45a0ec | 0x744d4 | 0x72cd4 | 0x4fa |
InitializeSListHead | 0x0 | 0x45a0f0 | 0x744d8 | 0x72cd8 | 0x2e7 |
IsProcessorFeaturePresent | 0x0 | 0x45a0f4 | 0x744dc | 0x72cdc | 0x304 |
IsDebuggerPresent | 0x0 | 0x45a0f8 | 0x744e0 | 0x72ce0 | 0x300 |
UnhandledExceptionFilter | 0x0 | 0x45a0fc | 0x744e4 | 0x72ce4 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x45a100 | 0x744e8 | 0x72ce8 | 0x4a5 |
GetStartupInfoW | 0x0 | 0x45a104 | 0x744ec | 0x72cec | 0x263 |
GetCurrentProcess | 0x0 | 0x45a108 | 0x744f0 | 0x72cf0 | 0x1c0 |
TerminateProcess | 0x0 | 0x45a10c | 0x744f4 | 0x72cf4 | 0x4c0 |
GetCurrentProcessId | 0x0 | 0x45a110 | 0x744f8 | 0x72cf8 | 0x1c1 |
GetCurrentThreadId | 0x0 | 0x45a114 | 0x744fc | 0x72cfc | 0x1c5 |
InterlockedPushEntrySList | 0x0 | 0x45a118 | 0x74500 | 0x72d00 | 0x2f1 |
RaiseException | 0x0 | 0x45a11c | 0x74504 | 0x72d04 | 0x3b1 |
RtlUnwind | 0x0 | 0x45a120 | 0x74508 | 0x72d08 | 0x418 |
FreeLibrary | 0x0 | 0x45a124 | 0x7450c | 0x72d0c | 0x162 |
LoadLibraryExW | 0x0 | 0x45a128 | 0x74510 | 0x72d10 | 0x33e |
MoveFileExW | 0x0 | 0x45a12c | 0x74514 | 0x72d14 | 0x360 |
HeapReAlloc | 0x0 | 0x45a130 | 0x74518 | 0x72d18 | 0x2d2 |
GetModuleHandleExW | 0x0 | 0x45a134 | 0x7451c | 0x72d1c | 0x217 |
GetStdHandle | 0x0 | 0x45a138 | 0x74520 | 0x72d20 | 0x264 |
GetCommandLineA | 0x0 | 0x45a13c | 0x74524 | 0x72d24 | 0x186 |
GetCommandLineW | 0x0 | 0x45a140 | 0x74528 | 0x72d28 | 0x187 |
GetACP | 0x0 | 0x45a144 | 0x7452c | 0x72d2c | 0x168 |
IsValidLocale | 0x0 | 0x45a148 | 0x74530 | 0x72d30 | 0x30c |
GetUserDefaultLCID | 0x0 | 0x45a14c | 0x74534 | 0x72d34 | 0x29b |
EnumSystemLocalesW | 0x0 | 0x45a150 | 0x74538 | 0x72d38 | 0x10f |
GetFileType | 0x0 | 0x45a154 | 0x7453c | 0x72d3c | 0x1f3 |
FlushFileBuffers | 0x0 | 0x45a158 | 0x74540 | 0x72d40 | 0x157 |
GetConsoleCP | 0x0 | 0x45a15c | 0x74544 | 0x72d44 | 0x19a |
GetConsoleMode | 0x0 | 0x45a160 | 0x74548 | 0x72d48 | 0x1ac |
ReadFile | 0x0 | 0x45a164 | 0x7454c | 0x72d4c | 0x3c0 |
SetFilePointerEx | 0x0 | 0x45a168 | 0x74550 | 0x72d50 | 0x467 |
HeapSize | 0x0 | 0x45a16c | 0x74554 | 0x72d54 | 0x2d4 |
FindFirstFileExA | 0x0 | 0x45a170 | 0x74558 | 0x72d58 | 0x133 |
FindNextFileA | 0x0 | 0x45a174 | 0x7455c | 0x72d5c | 0x143 |
IsValidCodePage | 0x0 | 0x45a178 | 0x74560 | 0x72d60 | 0x30a |
GetOEMCP | 0x0 | 0x45a17c | 0x74564 | 0x72d64 | 0x237 |
GetEnvironmentStringsW | 0x0 | 0x45a180 | 0x74568 | 0x72d68 | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x45a184 | 0x7456c | 0x72d6c | 0x161 |
SetEnvironmentVariableA | 0x0 | 0x45a188 | 0x74570 | 0x72d70 | 0x456 |
SetEndOfFile | 0x0 | 0x45a18c | 0x74574 | 0x72d74 | 0x453 |
USER32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
wsprintfW | 0x0 | 0x45a19c | 0x74584 | 0x72d84 | 0x333 |
wsprintfA | 0x0 | 0x45a1a0 | 0x74588 | 0x72d88 | 0x332 |
ADVAPI32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptReleaseContext | 0x0 | 0x45a000 | 0x743e8 | 0x72be8 | 0xcb |
CryptAcquireContextA | 0x0 | 0x45a004 | 0x743ec | 0x72bec | 0xb0 |
RegSetValueExA | 0x0 | 0x45a008 | 0x743f0 | 0x72bf0 | 0x27d |
RegOpenKeyExA | 0x0 | 0x45a00c | 0x743f4 | 0x72bf4 | 0x260 |
RegCloseKey | 0x0 | 0x45a010 | 0x743f8 | 0x72bf8 | 0x230 |
CryptGenRandom | 0x0 | 0x45a014 | 0x743fc | 0x72bfc | 0xc1 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteA | 0x0 | 0x45a194 | 0x7457c | 0x72d7c | 0x11e |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
cusersgrujadesktop1.exe | 1 | 0x001F0000 | 0x00275FFF | Relevant Image | 32-bit | 0x00227B66 |
...
|
|||
cusersgrujadesktop1.exe | 1 | 0x001F0000 | 0x00275FFF | Process Termination | 32-bit | - |
...
|
C:\Program Files\Common Files\Services\verisign.bmp.pysa | Dropped File | Image |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
First Seen | 2011-07-14 05:49 (UTC+2) |
Last Seen | 2019-07-10 04:10 (UTC+2) |
C:\Program Files\Common Files\microsoft shared\OFFICE16\LICLUA.EXE.pysa | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\ffjcext.zip.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\1494870C-9912-C184-4CC9-B401-A53F4D8DE290.pdf.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Click on 'Change' to select default PDF handler.pdf.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\IDTemplates\ENU\AdobeID.pdf.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\IDTemplates\ENU\DefaultID.pdf.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\PDFSigQFormalRep.pdf.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\Annotations\Stamps\ENU\Dynamic.pdf.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\Annotations\Stamps\ENU\SignHere.pdf.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\Annotations\Stamps\ENU\StandardBusiness.pdf.pysa | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\1053\localizeddata.xml.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\eula.rtf.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\LocalizedData.xml.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Internet Explorer\SIGNUP\install.ins.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\javacpl.cpl.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\Logs\UniversalNotificationPlatform.020.etl.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\UNP\Logs\Readme.README | Dropped File | Text |
Unknown
|
...
|
»
c:\program files (x86)\google\chrome\application\61.0.3163.79\chrome_200_percent.pak.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\Annotations\Stamps\Words.pdf.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\brEURPK65 NsyW1St3z.docx.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\LocalizedData.xml.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\eula.rtf.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\LocalizedData.xml.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\LocalizedData.xml.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\Parameterinfo.xml.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\UiInfo.xml.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DHtmlHeader.html.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\Parameterinfo.xml.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\UiInfo.xml.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Print.ico.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate1.ico.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate2.ico.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate4.ico.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate5.ico.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate6.ico.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate7.ico.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Save.ico.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Setup.ico.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqMet.ico.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\warn.ico.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp.pysa | Dropped File | Binary |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core.mzz.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x64.msi.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x86.msi.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x86.msi.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.xml.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Strings.xml.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\UiInfo.xml.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\HardwareEvents.evtx.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Internet Explorer.evtx.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Windows PowerShell.evtx.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\DESIGNER\MSADDNDR.OLB.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hash.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\i641033.hash.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\OFFICE16\Office Setup Controller\pkeyconfig-office.xrm-ms.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\Source Engine\OSE.EXE.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\Stationery\Desktop.ini.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\VSTO\vstoee100.tlb.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\VSTO\vstoee90.tlb.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\server\classes.jsa.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\COPYRIGHT.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\accessibility.properties.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\amd64\jvm.cfg.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\calendars.properties.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\charsets.jar.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\classlist.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\cmm\GRAY.pf.pysa | Dropped File | Binary |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\cmm\LINEAR_RGB.pf.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\cmm\PYCC.pf.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\cmm\sRGB.pf.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\content-types.properties.pysa | Dropped File | Compressed |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\currency.data.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages.properties.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_de.properties.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_es.properties.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_fr.properties.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_it.properties.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_ja.properties.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_ko.properties.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_pt_BR.properties.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_sv.properties.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_zh_HK.properties.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_zh_TW.properties.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash.gif.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11-lic.gif.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy.jar.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\access-bridge-64.jar.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\cldrdata.jar.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\jaccess.jar.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\localedata.jar.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\meta-index.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\nashorn.jar.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\sunec.jar.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\sunjce_provider.jar.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\sunmscapi.jar.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\sunpkcs11.jar.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\zipfs.jar.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\flavormap.properties.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fontconfig.bfc.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fontconfig.properties.src.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaBrightDemiBold.ttf.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaBrightDemiItalic.ttf.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaBrightItalic.ttf.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaBrightRegular.ttf.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaSansDemiBold.ttf.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaSansRegular.ttf.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaTypewriterBold.ttf.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\hijrah-config-umalqura.properties.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\invalid32x32.gif.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyDrop32x32.gif.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkDrop32x32.gif.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_LinkNoDrop32x32.gif.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveNoDrop32x32.gif.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\javafx.properties.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\javaws.jar.pysa | Dropped File | Binary |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jfr\profile.jfc.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jfr.jar.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jfxswt.jar.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jsse.jar.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\management\jmxremote.access.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\management\jmxremote.password.template.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\management\management.properties.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\management\snmp.acl.template.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\management-agent.jar.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\meta-index.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\net.properties.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\plugin.jar.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\psfont.properties.ja.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\psfontj2d.properties.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\resources.jar.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\rt.jar.pysa | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\LocalizedData.xml.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\desktop.ini.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\update.bat | Dropped File | Batch |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\DisplayIcon.ico.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate3.ico.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate8.ico.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\stop.ico.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x64.msi.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\RGB9RAST_x64.msi.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\RGB9Rast_x86.msi.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Key Management Service.evtx.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\server\Xusage.txt.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\cmm\CIEXYZ.pf.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_zh_CN.properties.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\splash@2x.gif.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\dnsns.jar.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\jfxrt.jar.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaTypewriterRegular.ttf.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\cursors.properties.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_CopyNoDrop32x32.gif.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\win32_MoveDrop32x32.gif.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jce.jar.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jfr\default.jfc.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jvm.hprof.txt.pysa | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\logging.properties.pysa | Dropped File | Stream |
Not Queried
|
...
|
»