VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: | - |
kinodomino.exe
Windows Exe (x86-32)
Created at 2020-03-18T22:18:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x98a584 |
Size Of Code | 0x8200 |
Size Of Initialized Data | 0x7200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-03-10 23:06:11+00:00 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x8194 | 0x8200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.57 |
.rdata | 0x40a000 | 0x3f0c | 0x4000 | 0x8600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.81 |
.data | 0x40e000 | 0x1ac4 | 0xe00 | 0xc600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.66 |
.vmp0 | 0x410000 | 0x32de33 | 0x32e000 | 0xd400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.85 |
.vmp1 | 0x73e000 | 0x26d1f0 | 0x26d200 | 0x33b400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.82 |
.reloc | 0x9ac000 | 0x2cfc | 0x2e00 | 0x5a8600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.73 |
Imports (9)
»
KERNEL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetTickCount | 0x0 | 0x84e000 | 0x41ff94 | 0x41d394 | 0x0 |
ADVAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptDecrypt | 0x0 | 0x84e008 | 0x41ff9c | 0x41d39c | 0x0 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x84e010 | 0x41ffa4 | 0x41d3a4 | 0x0 |
SHLWAPI.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathFindExtensionW | 0x0 | 0x84e018 | 0x41ffac | 0x41d3ac | 0x0 |
WTSAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WTSSendMessageW | 0x0 | 0x84e020 | 0x41ffb4 | 0x41d3b4 | 0x0 |
KERNEL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VirtualQuery | 0x0 | 0x84e028 | 0x41ffbc | 0x41d3bc | 0x0 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetUserObjectInformationW | 0x0 | 0x84e030 | 0x41ffc4 | 0x41d3c4 | 0x0 |
KERNEL32.dll (12)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LocalAlloc | 0x0 | 0x84e038 | 0x41ffcc | 0x41d3cc | 0x0 |
LocalFree | 0x0 | 0x84e03c | 0x41ffd0 | 0x41d3d0 | 0x0 |
GetModuleFileNameW | 0x0 | 0x84e040 | 0x41ffd4 | 0x41d3d4 | 0x0 |
GetProcessAffinityMask | 0x0 | 0x84e044 | 0x41ffd8 | 0x41d3d8 | 0x0 |
SetProcessAffinityMask | 0x0 | 0x84e048 | 0x41ffdc | 0x41d3dc | 0x0 |
SetThreadAffinityMask | 0x0 | 0x84e04c | 0x41ffe0 | 0x41d3e0 | 0x0 |
Sleep | 0x0 | 0x84e050 | 0x41ffe4 | 0x41d3e4 | 0x0 |
ExitProcess | 0x0 | 0x84e054 | 0x41ffe8 | 0x41d3e8 | 0x0 |
FreeLibrary | 0x0 | 0x84e058 | 0x41ffec | 0x41d3ec | 0x0 |
LoadLibraryA | 0x0 | 0x84e05c | 0x41fff0 | 0x41d3f0 | 0x0 |
GetModuleHandleA | 0x0 | 0x84e060 | 0x41fff4 | 0x41d3f4 | 0x0 |
GetProcAddress | 0x0 | 0x84e064 | 0x41fff8 | 0x41d3f8 | 0x0 |
USER32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetProcessWindowStation | 0x0 | 0x84e06c | 0x420000 | 0x41d400 | 0x0 |
GetUserObjectInformationW | 0x0 | 0x84e070 | 0x420004 | 0x41d404 | 0x0 |
Memory Dumps (17)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
kinodomino.exe | 1 | 0x00010000 | 0x005BEFFF | Relevant Image |
![]() |
32-bit | 0x0042B061 |
![]() |
![]() |
...
|
kinodomino.exe | 1 | 0x00010000 | 0x005BEFFF | Content Changed |
![]() |
32-bit | 0x0003E448 |
![]() |
![]() |
...
|
kinodomino.exe | 1 | 0x00010000 | 0x005BEFFF | Content Changed |
![]() |
32-bit | 0x00034782 |
![]() |
![]() |
...
|
kinodomino.exe | 1 | 0x00010000 | 0x005BEFFF | Content Changed |
![]() |
32-bit | 0x000363C8 |
![]() |
![]() |
...
|
kinodomino.exe | 1 | 0x00010000 | 0x005BEFFF | Content Changed |
![]() |
32-bit | 0x00035C78 |
![]() |
![]() |
...
|
kinodomino.exe | 1 | 0x00010000 | 0x005BEFFF | Content Changed |
![]() |
32-bit | 0x00039F52 |
![]() |
![]() |
...
|
kinodomino.exe | 1 | 0x00010000 | 0x005BEFFF | Content Changed |
![]() |
32-bit | 0x00038012 |
![]() |
![]() |
...
|
kinodomino.exe | 1 | 0x00010000 | 0x005BEFFF | Content Changed |
![]() |
32-bit | 0x002EB086 |
![]() |
![]() |
...
|
kinodomino.exe | 1 | 0x00010000 | 0x005BEFFF | Content Changed |
![]() |
32-bit | 0x0012681A |
![]() |
![]() |
...
|
kinodomino.exe | 1 | 0x00010000 | 0x005BEFFF | Content Changed |
![]() |
32-bit | 0x0003B18F |
![]() |
![]() |
...
|
kinodomino.exe | 1 | 0x00010000 | 0x005BEFFF | Content Changed |
![]() |
32-bit | 0x000234C0 |
![]() |
![]() |
...
|
kinodomino.exe | 1 | 0x00010000 | 0x005BEFFF | Content Changed |
![]() |
32-bit | 0x00037900 |
![]() |
![]() |
...
|
buffer | 1 | 0x00970000 | 0x00970FFF | First Execution |
![]() |
32-bit | 0x0097000F |
![]() |
![]() |
...
|
buffer | 1 | 0x00970000 | 0x00970FFF | Marked Executable |
![]() |
32-bit | 0x0097000F |
![]() |
![]() |
...
|
buffer | 1 | 0x00980000 | 0x00980FFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00980000 | 0x00980FFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
kinodomino.exe | 1 | 0x00010000 | 0x005BEFFF | Final Dump |
![]() |
32-bit | 0x00328740 |
![]() |
![]() |
...
|
C:\$WINRE_BACKUP_PARTITION.MARKER | Modified File | Binary |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\eula.rtf.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\eula.rtf.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\eula.rtf.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\eula.rtf.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\LocalizedData.xml.NEFILIM | Dropped File | Binary |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\Parameterinfo.xml.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\UiInfo.xml.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DHtmlHeader.html.NEFILIM | Dropped File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\Parameterinfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Print.ico.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate1.ico.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate3.ico.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate4.ico.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate5.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate7.ico.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Setup.ico.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqMet.ico.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\warn.ico.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\HardwareEvents.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Key Management Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-International%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Admin.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\state.rsm.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\state.rsm.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Package Cache\{e52a6842-b0ac-476e-b48f-378a97a67346}\state.rsm.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Package Cache\{e6e75766-da0f-4ba2-9788-6ea593ce702d}\state.rsm.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Package Cache\{f325f05b-f963-4640-a43b-c8a494cdda0f}\state.rsm.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOPrivate\UpdateStore\UpdateCspStore.xml.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUx.001.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.003.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.004.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.005.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.007.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.009.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.010.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.012.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.013.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.015.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.002.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.003.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.004.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.007.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.008.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.010.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.011.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.012.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.013.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.016.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.019.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.021.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.022.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.026.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.027.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.028.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.029.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.030.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.032.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.033.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.034.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.037.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.038.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateUx.001.etl.NEFILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateUx.002.etl.NEFILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT.LOG2 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TM.blf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TMContainer00000000000000000001.regtrans-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TMContainer00000000000000000002.regtrans-ms | Modified File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-1051304884-625712362-2192934891-1000\e0706a18c295d32ea97b3bdcc41d5105_33d770d0-06bc-47c5-8714-222cdac43a71 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1028\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1041\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1041\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1042\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1043\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1043\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1053\eula.rtf.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1053\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2052\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2070\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3076\eula.rtf.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3076\LocalizedData.xml.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\DisplayIcon.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate2.ico.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate6.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate8.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Save.ico.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\stop.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\header.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Core.mzz | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Strings.xml.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\UiInfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Application.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Known Folders API Service.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Store%4Operational.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Windows PowerShell.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Oracle\Java\.oracle_jre_usage\17dfc292991c7c46.timestamp.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Oracle\Java\installcache_x64\baseimagefam8.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Package Cache\{3c3aafc8-d898-43ec-998f-965ffdae065a}\state.rsm.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Extensibility Component.swidtag.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Licensing Component.swidtag.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Localization Component.swidtag.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft_Windows-10-Pro.swidtag.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOPrivate\UpdateStore\updatestore51b519d5-b6f5-4333-8df6-e74d7c9aead4.xml.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUx.002.etl.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.001.etl.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.002.etl.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.006.etl.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.008.etl.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.011.etl.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.014.etl.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.016.etl.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\NotificationUxBroker.017.etl.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.005.etl.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.006.etl.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.009.etl.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.014.etl.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.015.etl.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.017.etl.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.018.etl.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.020.etl.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.023.etl.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.024.etl.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.025.etl.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.031.etl.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.035.etl.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\USOShared\Logs\UpdateSessionOrchestration.036.etl.NEFILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT.LOG1.NEFILIM | Dropped File | Stream |
Not Queried
|
...
|
»