VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: | - |
Threat Names: |
Gen:Variant.Zusy.313069
|
BUIRansomSample.exe
Windows Exe (x86-32)
Created at 2020-10-04T16:35:00
Remarks (1/1)
(0x0200003A): A task was rescheduled ahead of time to reveal dormant functionality.
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\BUIRansomSample.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x43670b |
Size Of Code | 0x77e00 |
Size Of Initialized Data | 0x3d000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-10-02 13:34:34+00:00 |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | Host Process for Windows Tasks |
FileVersion | 10.0.17763.831 (WinBuild.160101.0800) |
InternalName | taskhost.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | taskhost.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 10.0.17763.831 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x77d46 | 0x77e00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x479000 | 0x2d65e | 0x2d800 | 0x78200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.63 |
.data | 0x4a7000 | 0x6e94 | 0x5c00 | 0xa5a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.49 |
.rsrc | 0x4ae000 | 0x5d8 | 0x600 | 0xab600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.07 |
.reloc | 0x4af000 | 0x81c8 | 0x8200 | 0xabc00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.65 |
Imports (11)
»
KERNEL32.dll (146)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CopyFileW | 0x0 | 0x479064 | 0xa5504 | 0xa4704 | 0xad |
OpenMutexW | 0x0 | 0x479068 | 0xa5508 | 0xa4708 | 0x409 |
GetTickCount | 0x0 | 0x47906c | 0xa550c | 0xa470c | 0x307 |
IsDebuggerPresent | 0x0 | 0x479070 | 0xa5510 | 0xa4710 | 0x37f |
CheckRemoteDebuggerPresent | 0x0 | 0x479074 | 0xa5514 | 0xa4714 | 0x80 |
GetVolumeInformationW | 0x0 | 0x479078 | 0xa5518 | 0xa4718 | 0x31e |
WriteFile | 0x0 | 0x47907c | 0xa551c | 0xa471c | 0x612 |
CreateFileW | 0x0 | 0x479080 | 0xa5520 | 0xa4720 | 0xcb |
ReadFile | 0x0 | 0x479084 | 0xa5524 | 0xa4724 | 0x473 |
GetFileSizeEx | 0x0 | 0x479088 | 0xa5528 | 0xa4728 | 0x24c |
GetQueuedCompletionStatus | 0x0 | 0x47908c | 0xa552c | 0xa472c | 0x2ca |
GetFileAttributesW | 0x0 | 0x479090 | 0xa5530 | 0xa4730 | 0x245 |
PostQueuedCompletionStatus | 0x0 | 0x479094 | 0xa5534 | 0xa4734 | 0x423 |
SetFileAttributesW | 0x0 | 0x479098 | 0xa5538 | 0xa4738 | 0x51d |
GetSystemInfo | 0x0 | 0x47909c | 0xa553c | 0xa473c | 0x2e3 |
SetFilePointerEx | 0x0 | 0x4790a0 | 0xa5540 | 0xa4740 | 0x523 |
MoveFileExW | 0x0 | 0x4790a4 | 0xa5544 | 0xa4744 | 0x3e8 |
CreateIoCompletionPort | 0x0 | 0x4790a8 | 0xa5548 | 0xa4748 | 0xd0 |
FindFirstFileW | 0x0 | 0x4790ac | 0xa554c | 0xa474c | 0x180 |
FindNextFileW | 0x0 | 0x4790b0 | 0xa5550 | 0xa4750 | 0x18c |
GetEnvironmentVariableW | 0x0 | 0x4790b4 | 0xa5554 | 0xa4754 | 0x239 |
FindClose | 0x0 | 0x4790b8 | 0xa5558 | 0xa4758 | 0x175 |
GetDiskFreeSpaceW | 0x0 | 0x4790bc | 0xa555c | 0xa475c | 0x229 |
GetLocaleInfoA | 0x0 | 0x4790c0 | 0xa5560 | 0xa4760 | 0x263 |
GetComputerNameA | 0x0 | 0x4790c4 | 0xa5564 | 0xa4764 | 0x1dc |
WriteConsoleW | 0x0 | 0x4790c8 | 0xa5568 | 0xa4768 | 0x611 |
GetThreadContext | 0x0 | 0x4790cc | 0xa556c | 0xa476c | 0x2f7 |
HeapAlloc | 0x0 | 0x4790d0 | 0xa5570 | 0xa4770 | 0x345 |
CloseHandle | 0x0 | 0x4790d4 | 0xa5574 | 0xa4774 | 0x86 |
Process32FirstW | 0x0 | 0x4790d8 | 0xa5578 | 0xa4778 | 0x42c |
GetCurrentThread | 0x0 | 0x4790dc | 0xa557c | 0xa477c | 0x21b |
Process32NextW | 0x0 | 0x4790e0 | 0xa5580 | 0xa4780 | 0x42e |
GetLastError | 0x0 | 0x4790e4 | 0xa5584 | 0xa4784 | 0x261 |
Sleep | 0x0 | 0x4790e8 | 0xa5588 | 0xa4788 | 0x57d |
CreateToolhelp32Snapshot | 0x0 | 0x4790ec | 0xa558c | 0xa478c | 0xfc |
CreateProcessW | 0x0 | 0x4790f0 | 0xa5590 | 0xa4790 | 0xe5 |
WaitForSingleObject | 0x0 | 0x4790f4 | 0xa5594 | 0xa4794 | 0x5d7 |
CreateMutexW | 0x0 | 0x4790f8 | 0xa5598 | 0xa4798 | 0xda |
GetModuleFileNameW | 0x0 | 0x4790fc | 0xa559c | 0xa479c | 0x274 |
TerminateProcess | 0x0 | 0x479100 | 0xa55a0 | 0xa47a0 | 0x58c |
GetCurrentProcess | 0x0 | 0x479104 | 0xa55a4 | 0xa47a4 | 0x217 |
HeapFree | 0x0 | 0x479108 | 0xa55a8 | 0xa47a8 | 0x349 |
WideCharToMultiByte | 0x0 | 0x47910c | 0xa55ac | 0xa47ac | 0x5fe |
MultiByteToWideChar | 0x0 | 0x479110 | 0xa55b0 | 0xa47b0 | 0x3ef |
FindNextVolumeW | 0x0 | 0x479114 | 0xa55b4 | 0xa47b4 | 0x191 |
GetVolumePathNamesForVolumeNameW | 0x0 | 0x479118 | 0xa55b8 | 0xa47b8 | 0x324 |
FindVolumeClose | 0x0 | 0x47911c | 0xa55bc | 0xa47bc | 0x198 |
SetVolumeMountPointW | 0x0 | 0x479120 | 0xa55c0 | 0xa47c0 | 0x574 |
FindFirstVolumeW | 0x0 | 0x479124 | 0xa55c4 | 0xa47c4 | 0x186 |
HeapSize | 0x0 | 0x479128 | 0xa55c8 | 0xa47c8 | 0x34e |
GetConsoleMode | 0x0 | 0x47912c | 0xa55cc | 0xa47cc | 0x1fc |
GetConsoleCP | 0x0 | 0x479130 | 0xa55d0 | 0xa47d0 | 0x1ea |
FlushFileBuffers | 0x0 | 0x479134 | 0xa55d4 | 0xa47d4 | 0x19f |
SetStdHandle | 0x0 | 0x479138 | 0xa55d8 | 0xa47d8 | 0x54a |
SetEnvironmentVariableW | 0x0 | 0x47913c | 0xa55dc | 0xa47dc | 0x514 |
FreeEnvironmentStringsW | 0x0 | 0x479140 | 0xa55e0 | 0xa47e0 | 0x1aa |
GetEnvironmentStringsW | 0x0 | 0x479144 | 0xa55e4 | 0xa47e4 | 0x237 |
GetCommandLineW | 0x0 | 0x479148 | 0xa55e8 | 0xa47e8 | 0x1d7 |
GetCommandLineA | 0x0 | 0x47914c | 0xa55ec | 0xa47ec | 0x1d6 |
GetOEMCP | 0x0 | 0x479150 | 0xa55f0 | 0xa47f0 | 0x297 |
GetACP | 0x0 | 0x479154 | 0xa55f4 | 0xa47f4 | 0x1b2 |
IsValidCodePage | 0x0 | 0x479158 | 0xa55f8 | 0xa47f8 | 0x38b |
FindFirstFileExW | 0x0 | 0x47915c | 0xa55fc | 0xa47fc | 0x17b |
HeapReAlloc | 0x0 | 0x479160 | 0xa5600 | 0xa4800 | 0x34c |
GetFileType | 0x0 | 0x479164 | 0xa5604 | 0xa4804 | 0x24e |
GetTimeZoneInformation | 0x0 | 0x479168 | 0xa5608 | 0xa4808 | 0x30e |
EnumSystemLocalesW | 0x0 | 0x47916c | 0xa560c | 0xa480c | 0x154 |
GetUserDefaultLCID | 0x0 | 0x479170 | 0xa5610 | 0xa4810 | 0x312 |
IsValidLocale | 0x0 | 0x479174 | 0xa5614 | 0xa4814 | 0x38d |
OpenProcess | 0x0 | 0x479178 | 0xa5618 | 0xa4818 | 0x40d |
GetProcessHeap | 0x0 | 0x47917c | 0xa561c | 0xa481c | 0x2b4 |
GetTimeFormatW | 0x0 | 0x479180 | 0xa5620 | 0xa4820 | 0x30c |
GetDateFormatW | 0x0 | 0x479184 | 0xa5624 | 0xa4824 | 0x221 |
GetStdHandle | 0x0 | 0x479188 | 0xa5628 | 0xa4828 | 0x2d2 |
ExitProcess | 0x0 | 0x47918c | 0xa562c | 0xa482c | 0x15e |
GetModuleHandleExW | 0x0 | 0x479190 | 0xa5630 | 0xa4830 | 0x277 |
ExitThread | 0x0 | 0x479194 | 0xa5634 | 0xa4834 | 0x15f |
RaiseException | 0x0 | 0x479198 | 0xa5638 | 0xa4838 | 0x462 |
RtlUnwind | 0x0 | 0x47919c | 0xa563c | 0xa483c | 0x4d3 |
LoadLibraryW | 0x0 | 0x4791a0 | 0xa5640 | 0xa4840 | 0x3c4 |
UnregisterWaitEx | 0x0 | 0x4791a4 | 0xa5644 | 0xa4844 | 0x5b7 |
QueryDepthSList | 0x0 | 0x4791a8 | 0xa5648 | 0xa4848 | 0x443 |
InterlockedFlushSList | 0x0 | 0x4791ac | 0xa564c | 0xa484c | 0x36c |
QueryDosDeviceW | 0x0 | 0x4791b0 | 0xa5650 | 0xa4850 | 0x445 |
GetLogicalDrives | 0x0 | 0x4791b4 | 0xa5654 | 0xa4854 | 0x268 |
EnterCriticalSection | 0x0 | 0x4791b8 | 0xa5658 | 0xa4858 | 0x131 |
LeaveCriticalSection | 0x0 | 0x4791bc | 0xa565c | 0xa485c | 0x3bd |
TryEnterCriticalSection | 0x0 | 0x4791c0 | 0xa5660 | 0xa4860 | 0x5a7 |
DeleteCriticalSection | 0x0 | 0x4791c4 | 0xa5664 | 0xa4864 | 0x110 |
GetCurrentThreadId | 0x0 | 0x4791c8 | 0xa5668 | 0xa4868 | 0x21c |
WaitForSingleObjectEx | 0x0 | 0x4791cc | 0xa566c | 0xa486c | 0x5d8 |
SwitchToThread | 0x0 | 0x4791d0 | 0xa5670 | 0xa4870 | 0x587 |
GetExitCodeThread | 0x0 | 0x4791d4 | 0xa5674 | 0xa4874 | 0x23d |
SetLastError | 0x0 | 0x4791d8 | 0xa5678 | 0xa4878 | 0x532 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4791dc | 0xa567c | 0xa487c | 0x35f |
CreateEventW | 0x0 | 0x4791e0 | 0xa5680 | 0xa4880 | 0xbf |
TlsAlloc | 0x0 | 0x4791e4 | 0xa5684 | 0xa4884 | 0x59e |
TlsGetValue | 0x0 | 0x4791e8 | 0xa5688 | 0xa4888 | 0x5a0 |
TlsSetValue | 0x0 | 0x4791ec | 0xa568c | 0xa488c | 0x5a1 |
TlsFree | 0x0 | 0x4791f0 | 0xa5690 | 0xa4890 | 0x59f |
GetSystemTimeAsFileTime | 0x0 | 0x4791f4 | 0xa5694 | 0xa4894 | 0x2e9 |
GetModuleHandleW | 0x0 | 0x4791f8 | 0xa5698 | 0xa4898 | 0x278 |
GetProcAddress | 0x0 | 0x4791fc | 0xa569c | 0xa489c | 0x2ae |
QueryPerformanceCounter | 0x0 | 0x479200 | 0xa56a0 | 0xa48a0 | 0x44d |
EncodePointer | 0x0 | 0x479204 | 0xa56a4 | 0xa48a4 | 0x12d |
DecodePointer | 0x0 | 0x479208 | 0xa56a8 | 0xa48a8 | 0x109 |
LocalFree | 0x0 | 0x47920c | 0xa56ac | 0xa48ac | 0x3cf |
GetStringTypeW | 0x0 | 0x479210 | 0xa56b0 | 0xa48b0 | 0x2d7 |
CompareStringW | 0x0 | 0x479214 | 0xa56b4 | 0xa48b4 | 0x9b |
LCMapStringW | 0x0 | 0x479218 | 0xa56b8 | 0xa48b8 | 0x3b1 |
GetLocaleInfoW | 0x0 | 0x47921c | 0xa56bc | 0xa48bc | 0x265 |
GetCPInfo | 0x0 | 0x479220 | 0xa56c0 | 0xa48c0 | 0x1c1 |
UnhandledExceptionFilter | 0x0 | 0x479224 | 0xa56c4 | 0xa48c4 | 0x5ad |
SetUnhandledExceptionFilter | 0x0 | 0x479228 | 0xa56c8 | 0xa48c8 | 0x56d |
IsProcessorFeaturePresent | 0x0 | 0x47922c | 0xa56cc | 0xa48cc | 0x386 |
GetStartupInfoW | 0x0 | 0x479230 | 0xa56d0 | 0xa48d0 | 0x2d0 |
GetCurrentProcessId | 0x0 | 0x479234 | 0xa56d4 | 0xa48d4 | 0x218 |
InitializeSListHead | 0x0 | 0x479238 | 0xa56d8 | 0xa48d8 | 0x363 |
CreateTimerQueue | 0x0 | 0x47923c | 0xa56dc | 0xa48dc | 0xfa |
SetEvent | 0x0 | 0x479240 | 0xa56e0 | 0xa48e0 | 0x516 |
SignalObjectAndWait | 0x0 | 0x479244 | 0xa56e4 | 0xa48e4 | 0x57b |
CreateThread | 0x0 | 0x479248 | 0xa56e8 | 0xa48e8 | 0xf3 |
SetThreadPriority | 0x0 | 0x47924c | 0xa56ec | 0xa48ec | 0x55e |
GetThreadPriority | 0x0 | 0x479250 | 0xa56f0 | 0xa48f0 | 0x301 |
GetLogicalProcessorInformation | 0x0 | 0x479254 | 0xa56f4 | 0xa48f4 | 0x269 |
CreateTimerQueueTimer | 0x0 | 0x479258 | 0xa56f8 | 0xa48f8 | 0xfb |
ChangeTimerQueueTimer | 0x0 | 0x47925c | 0xa56fc | 0xa48fc | 0x78 |
DeleteTimerQueueTimer | 0x0 | 0x479260 | 0xa5700 | 0xa4900 | 0x11a |
GetNumaHighestNodeNumber | 0x0 | 0x479264 | 0xa5704 | 0xa4904 | 0x289 |
GetProcessAffinityMask | 0x0 | 0x479268 | 0xa5708 | 0xa4908 | 0x2af |
SetThreadAffinityMask | 0x0 | 0x47926c | 0xa570c | 0xa490c | 0x553 |
RegisterWaitForSingleObject | 0x0 | 0x479270 | 0xa5710 | 0xa4910 | 0x4a9 |
UnregisterWait | 0x0 | 0x479274 | 0xa5714 | 0xa4914 | 0x5b6 |
GetThreadTimes | 0x0 | 0x479278 | 0xa5718 | 0xa4918 | 0x305 |
FreeLibrary | 0x0 | 0x47927c | 0xa571c | 0xa491c | 0x1ab |
FreeLibraryAndExitThread | 0x0 | 0x479280 | 0xa5720 | 0xa4920 | 0x1ac |
GetModuleHandleA | 0x0 | 0x479284 | 0xa5724 | 0xa4924 | 0x275 |
LoadLibraryExW | 0x0 | 0x479288 | 0xa5728 | 0xa4928 | 0x3c3 |
GetVersionExW | 0x0 | 0x47928c | 0xa572c | 0xa492c | 0x31b |
VirtualAlloc | 0x0 | 0x479290 | 0xa5730 | 0xa4930 | 0x5c6 |
VirtualProtect | 0x0 | 0x479294 | 0xa5734 | 0xa4934 | 0x5cc |
VirtualFree | 0x0 | 0x479298 | 0xa5738 | 0xa4938 | 0x5c9 |
DuplicateHandle | 0x0 | 0x47929c | 0xa573c | 0xa493c | 0x12b |
ReleaseSemaphore | 0x0 | 0x4792a0 | 0xa5740 | 0xa4940 | 0x4b4 |
InterlockedPopEntrySList | 0x0 | 0x4792a4 | 0xa5744 | 0xa4944 | 0x36e |
InterlockedPushEntrySList | 0x0 | 0x4792a8 | 0xa5748 | 0xa4948 | 0x36f |
ADVAPI32.dll (20)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegSetValueExW | 0x0 | 0x479000 | 0xa54a0 | 0xa46a0 | 0x2a9 |
OpenServiceW | 0x0 | 0x479004 | 0xa54a4 | 0xa46a4 | 0x219 |
CryptSetKeyParam | 0x0 | 0x479008 | 0xa54a8 | 0xa46a8 | 0xde |
CryptDestroyKey | 0x0 | 0x47900c | 0xa54ac | 0xa46ac | 0xc8 |
CryptAcquireContextW | 0x0 | 0x479010 | 0xa54b0 | 0xa46b0 | 0xc2 |
CryptEncrypt | 0x0 | 0x479014 | 0xa54b4 | 0xa46b4 | 0xcb |
CryptDuplicateKey | 0x0 | 0x479018 | 0xa54b8 | 0xa46b8 | 0xca |
CryptExportKey | 0x0 | 0x47901c | 0xa54bc | 0xa46bc | 0xd0 |
CryptImportKey | 0x0 | 0x479020 | 0xa54c0 | 0xa46c0 | 0xdb |
CryptGenKey | 0x0 | 0x479024 | 0xa54c4 | 0xa46c4 | 0xd1 |
CryptReleaseContext | 0x0 | 0x479028 | 0xa54c8 | 0xa46c8 | 0xdc |
RegCloseKey | 0x0 | 0x47902c | 0xa54cc | 0xa46cc | 0x25b |
CloseServiceHandle | 0x0 | 0x479030 | 0xa54d0 | 0xa46d0 | 0x65 |
OpenSCManagerW | 0x0 | 0x479034 | 0xa54d4 | 0xa46d4 | 0x217 |
DeleteService | 0x0 | 0x479038 | 0xa54d8 | 0xa46d8 | 0xec |
ControlService | 0x0 | 0x47903c | 0xa54dc | 0xa46dc | 0x6a |
EnumDependentServicesW | 0x0 | 0x479040 | 0xa54e0 | 0xa46e0 | 0x10f |
RegOpenKeyExW | 0x0 | 0x479044 | 0xa54e4 | 0xa46e4 | 0x28c |
StartServiceW | 0x0 | 0x479048 | 0xa54e8 | 0xa46e8 | 0x2fb |
QueryServiceStatusEx | 0x0 | 0x47904c | 0xa54ec | 0xa46ec | 0x251 |
SHELL32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHEmptyRecycleBinW | 0x0 | 0x4792fc | 0xa579c | 0xa499c | 0x13a |
ShellExecuteW | 0x0 | 0x479300 | 0xa57a0 | 0xa49a0 | 0x1b7 |
ole32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoUninitialize | 0x0 | 0x47932c | 0xa57cc | 0xa49cc | 0x8d |
CoSetProxyBlanket | 0x0 | 0x479330 | 0xa57d0 | 0xa49d0 | 0x84 |
CoCreateInstance | 0x0 | 0x479334 | 0xa57d4 | 0xa49d4 | 0x28 |
CoInitializeEx | 0x0 | 0x479338 | 0xa57d8 | 0xa49d8 | 0x5e |
CoInitializeSecurity | 0x0 | 0x47933c | 0xa57dc | 0xa49dc | 0x5f |
OLEAUT32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VariantClear | 0x9 | 0x4792c8 | 0xa5768 | 0xa4968 | - |
SysAllocString | 0x2 | 0x4792cc | 0xa576c | 0xa496c | - |
SysAllocStringByteLen | 0x96 | 0x4792d0 | 0xa5770 | 0xa4970 | - |
SysStringByteLen | 0x95 | 0x4792d4 | 0xa5774 | 0xa4974 | - |
VariantInit | 0x8 | 0x4792d8 | 0xa5778 | 0xa4978 | - |
SysFreeString | 0x6 | 0x4792dc | 0xa577c | 0xa497c | - |
MPR.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetGetConnectionW | 0x0 | 0x4792b0 | 0xa5750 | 0xa4950 | 0x2b |
NETAPI32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetDfsEnum | 0x0 | 0x4792b8 | 0xa5758 | 0xa4958 | 0x61 |
NetShareEnum | 0x0 | 0x4792bc | 0xa575c | 0xa495c | 0xde |
NetApiBufferFree | 0x0 | 0x4792c0 | 0xa5760 | 0xa4960 | 0x51 |
IPHLPAPI.DLL (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SendARP | 0x0 | 0x47905c | 0xa54fc | 0xa46fc | 0xf7 |
WS2_32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
gethostbyname | 0x34 | 0x479308 | 0xa57a8 | 0xa49a8 | - |
gethostname | 0x39 | 0x47930c | 0xa57ac | 0xa49ac | - |
inet_addr | 0xb | 0x479310 | 0xa57b0 | 0xa49b0 | - |
htons | 0x9 | 0x479314 | 0xa57b4 | 0xa49b4 | - |
getnameinfo | 0x0 | 0x479318 | 0xa57b8 | 0xa49b8 | 0x9a |
WSACleanup | 0x74 | 0x47931c | 0xa57bc | 0xa49bc | - |
inet_ntoa | 0xc | 0x479320 | 0xa57c0 | 0xa49c0 | - |
WSAStartup | 0x73 | 0x479324 | 0xa57c4 | 0xa49c4 | - |
RstrtMgr.DLL (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RmEndSession | 0x0 | 0x4792e4 | 0xa5784 | 0xa4984 | 0x2 |
RmStartSession | 0x0 | 0x4792e8 | 0xa5788 | 0xa4988 | 0xb |
RmShutdown | 0x0 | 0x4792ec | 0xa578c | 0xa498c | 0xa |
RmGetList | 0x0 | 0x4792f0 | 0xa5790 | 0xa4990 | 0x4 |
RmRegisterResources | 0x0 | 0x4792f4 | 0xa5794 | 0xa4994 | 0x6 |
CRYPT32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptStringToBinaryA | 0x0 | 0x479054 | 0xa54f4 | 0xa46f4 | 0xe3 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
buiransomsample.exe | 1 | 0x00250000 | 0x00307FFF | Relevant Image |
![]() |
32-bit | 0x0029EF26 |
![]() |
![]() |
...
|
buiransomsample.exe | 1 | 0x00250000 | 0x00307FFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Zusy.313069 |
Malicious
|
C:\\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.bdCDdCBaAd | Dropped File | Binary |
Unknown
|
...
|
»
C:\\$GetCurrent\SafeOS\preoobe.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log | Modified File | Binary |
Unknown
|
...
|
»
C:\\$GetCurrent\SafeOS\PartnerSetupComplete.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\\$GetCurrent\SafeOS\SetupComplete.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1025\eula.rtf.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1032\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1033\eula.rtf.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1035\eula.rtf.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\$GetCurrent\Logs\PartnerSetupCompleteResult.log | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1028\eula.rtf.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1025\LocalizedData.xml.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1033\LocalizedData.xml.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1029\LocalizedData.xml.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1036\LocalizedData.xml.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1038\LocalizedData.xml.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1031\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1028\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1036\eula.rtf.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1032\LocalizedData.xml.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1030\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1042\LocalizedData.xml.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1037\eula.rtf.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1040\LocalizedData.xml.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1042\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1035\LocalizedData.xml.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1053\LocalizedData.xml.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1053\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1055\eula.rtf.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1045\LocalizedData.xml.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1037\LocalizedData.xml.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1043\LocalizedData.xml.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1041\LocalizedData.xml.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\3076\LocalizedData.xml.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\3082\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1043\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1044\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\2070\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\2070\LocalizedData.xml.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\2052\eula.rtf.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1041\eula.rtf.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\DisplayIcon.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\3082\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Extended\Parameterinfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Extended\UiInfo.xml.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1044\eula.rtf.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Rotate6.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Client\UiInfo.xml.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Print.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Rotate8.ico.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Rotate7.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Rotate5.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\DHtmlHeader.html | Modified File | Text |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Rotate3.ico.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Rotate1.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Setup.ico.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\3076\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\netfx_Extended_x64.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\netfx_Extended_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Rotate2.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\watermark.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Strings.xml.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\netfx_Core_x64.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\stop.ico.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\netfx_Core_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\HardwareEvents.evtx.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Graphics\SysReqNotMet.ico.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\netfx_Extended.mzz | Modified File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\SplashScreen.bmp.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\SetupUi.xsd.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\netfx_Core.mzz.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-Known Folders API Service.evtx.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-LiveId%4Operational.evtx.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-Ntfs%4WHC.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-Ntfs%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-SettingSync%4Debug.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-SMBServer%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-SmbClient%4Security.evtx.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-Store%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-SMBServer%4Audit.evtx.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx.bdCDdCBaAd | Dropped File | Stream |
Unknown
|
...
|
»
C:\\$GetCurrent\Logs\SxgPNwKy_readme_.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1035\SxgPNwKy_readme_.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1028\SxgPNwKy_readme_.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1038\SxgPNwKy_readme_.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1045\SxgPNwKy_readme_.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1043\SxgPNwKy_readme_.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1043\SxgPNwKy_readme_.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\3082\SxgPNwKy_readme_.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\1044\SxgPNwKy_readme_.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\3076\SxgPNwKy_readme_.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\SxgPNwKy_readme_.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\SxgPNwKy_readme_.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\SxgPNwKy_readme_.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\SxgPNwKy_readme_.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\SxgPNwKy_readme_.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\\588bce7c90097ed212\SxgPNwKy_readme_.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\\$WINRE_BACKUP_PARTITION.MARKER | Modified File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1029\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1031\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1038\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1046\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1045\eula.rtf.bdCDdCBaAd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1046\LocalizedData.xml.bdCDdCBaAd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1049\LocalizedData.xml.bdCDdCBaAd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1049\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1055\LocalizedData.xml.bdCDdCBaAd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Client\Parameterinfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\2052\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Save.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\warn.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\header.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\Rotate4.ico.bdCDdCBaAd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\SysReqMet.ico.bdCDdCBaAd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\ParameterInfo.xml.bdCDdCBaAd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\RGB9RAST_x64.msi.bdCDdCBaAd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\RGB9Rast_x86.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Logs\Internet Explorer.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Logs\Key Management Service.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx.bdCDdCBaAd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx.bdCDdCBaAd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx.bdCDdCBaAd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.bdCDdCBaAd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\Microsoft-Windows-International%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Logs\Microsoft-Windows-MUI%4Operational.evtx.bdCDdCBaAd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx.bdCDdCBaAd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\Microsoft-Windows-TWinUI%4Operational.evtx.bdCDdCBaAd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx.bdCDdCBaAd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx.bdCDdCBaAd | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\$GetCurrent\SafeOS\SxgPNwKy_readme_.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1025\SxgPNwKy_readme_.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1028\SxgPNwKy_readme_.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1038\SxgPNwKy_readme_.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1042\SxgPNwKy_readme_.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1055\SxgPNwKy_readme_.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\1044\SxgPNwKy_readme_.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\SxgPNwKy_readme_.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\SxgPNwKy_readme_.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\SxgPNwKy_readme_.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\SxgPNwKy_readme_.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\Graphics\SxgPNwKy_readme_.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\SxgPNwKy_readme_.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\\588bce7c90097ed212\SxgPNwKy_readme_.txt | Dropped File | Text |
Not Queried
|
...
|
»