VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Sodinokibi
Gen:Heur.Ransom.REntS.Gen.1
|
transscroll.EXE.exe
Windows Exe (x86-32)
Created at 2020-10-19T09:26:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\transscroll.EXE.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x41188f |
Size Of Code | 0x27200 |
Size Of Initialized Data | 0x51400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-10-16 15:23:40+00:00 |
Version Information (9)
»
CompanyName | - |
FileDescription | transscroll MFC Application |
FileVersion | 1, 0, 0, 1 |
InternalName | transscroll |
LegalCopyright | Copyright (C) 2008 |
LegalTrademarks | - |
OriginalFilename | transscroll.EXE |
ProductName | transscroll Application |
ProductVersion | 1, 0, 0, 1 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x270e1 | 0x27200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.61 |
.rdata | 0x429000 | 0x96ba | 0x9800 | 0x27600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.04 |
.data | 0x433000 | 0x6038 | 0x2400 | 0x30e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.2 |
.rsrc | 0x43a000 | 0x3d8dc | 0x3da00 | 0x33200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.56 |
.reloc | 0x478000 | 0x7ce2 | 0x7e00 | 0x70c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 3.05 |
Imports (7)
»
KERNEL32.dll (110)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetStartupInfoA | 0x0 | 0x42908c | 0x31250 | 0x2f850 | 0x239 |
HeapFree | 0x0 | 0x429090 | 0x31254 | 0x2f854 | 0x2a1 |
VirtualAlloc | 0x0 | 0x429094 | 0x31258 | 0x2f858 | 0x454 |
HeapReAlloc | 0x0 | 0x429098 | 0x3125c | 0x2f85c | 0x2a4 |
Sleep | 0x0 | 0x42909c | 0x31260 | 0x2f860 | 0x421 |
ExitProcess | 0x0 | 0x4290a0 | 0x31264 | 0x2f864 | 0x104 |
HeapSize | 0x0 | 0x4290a4 | 0x31268 | 0x2f868 | 0x2a6 |
TerminateProcess | 0x0 | 0x4290a8 | 0x3126c | 0x2f86c | 0x42d |
UnhandledExceptionFilter | 0x0 | 0x4290ac | 0x31270 | 0x2f870 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x4290b0 | 0x31274 | 0x2f874 | 0x415 |
IsDebuggerPresent | 0x0 | 0x4290b4 | 0x31278 | 0x2f878 | 0x2d1 |
VirtualFree | 0x0 | 0x4290b8 | 0x3127c | 0x2f87c | 0x457 |
HeapCreate | 0x0 | 0x4290bc | 0x31280 | 0x2f880 | 0x29f |
GetStdHandle | 0x0 | 0x4290c0 | 0x31284 | 0x2f884 | 0x23b |
FreeEnvironmentStringsA | 0x0 | 0x4290c4 | 0x31288 | 0x2f888 | 0x14a |
GetEnvironmentStrings | 0x0 | 0x4290c8 | 0x3128c | 0x2f88c | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x4290cc | 0x31290 | 0x2f890 | 0x14b |
GetEnvironmentStringsW | 0x0 | 0x4290d0 | 0x31294 | 0x2f894 | 0x1c1 |
SetHandleCount | 0x0 | 0x4290d4 | 0x31298 | 0x2f898 | 0x3e8 |
GetCommandLineA | 0x0 | 0x4290d8 | 0x3129c | 0x2f89c | 0x16f |
QueryPerformanceCounter | 0x0 | 0x4290dc | 0x312a0 | 0x2f8a0 | 0x354 |
GetTickCount | 0x0 | 0x4290e0 | 0x312a4 | 0x2f8a4 | 0x266 |
GetSystemTimeAsFileTime | 0x0 | 0x4290e4 | 0x312a8 | 0x2f8a8 | 0x24f |
GetACP | 0x0 | 0x4290e8 | 0x312ac | 0x2f8ac | 0x152 |
IsValidCodePage | 0x0 | 0x4290ec | 0x312b0 | 0x2f8b0 | 0x2db |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4290f0 | 0x312b4 | 0x2f8b4 | 0x2b5 |
GetConsoleCP | 0x0 | 0x4290f4 | 0x312b8 | 0x2f8b8 | 0x183 |
GetConsoleMode | 0x0 | 0x4290f8 | 0x312bc | 0x2f8bc | 0x195 |
LCMapStringA | 0x0 | 0x4290fc | 0x312c0 | 0x2f8c0 | 0x2e1 |
LCMapStringW | 0x0 | 0x429100 | 0x312c4 | 0x2f8c4 | 0x2e3 |
GetStringTypeA | 0x0 | 0x429104 | 0x312c8 | 0x2f8c8 | 0x23d |
GetStringTypeW | 0x0 | 0x429108 | 0x312cc | 0x2f8cc | 0x240 |
GetUserDefaultLCID | 0x0 | 0x42910c | 0x312d0 | 0x2f8d0 | 0x26d |
EnumSystemLocalesA | 0x0 | 0x429110 | 0x312d4 | 0x2f8d4 | 0xf8 |
IsValidLocale | 0x0 | 0x429114 | 0x312d8 | 0x2f8d8 | 0x2dd |
GetLocaleInfoW | 0x0 | 0x429118 | 0x312dc | 0x2f8dc | 0x1ea |
SetStdHandle | 0x0 | 0x42911c | 0x312e0 | 0x2f8e0 | 0x3fc |
WriteConsoleA | 0x0 | 0x429120 | 0x312e4 | 0x2f8e4 | 0x482 |
GetConsoleOutputCP | 0x0 | 0x429124 | 0x312e8 | 0x2f8e8 | 0x199 |
WriteConsoleW | 0x0 | 0x429128 | 0x312ec | 0x2f8ec | 0x48c |
HeapAlloc | 0x0 | 0x42912c | 0x312f0 | 0x2f8f0 | 0x29d |
RaiseException | 0x0 | 0x429130 | 0x312f4 | 0x2f8f4 | 0x35a |
RtlUnwind | 0x0 | 0x429134 | 0x312f8 | 0x2f8f8 | 0x392 |
SetErrorMode | 0x0 | 0x429138 | 0x312fc | 0x2f8fc | 0x3d2 |
CreateFileA | 0x0 | 0x42913c | 0x31300 | 0x2f900 | 0x78 |
FlushFileBuffers | 0x0 | 0x429140 | 0x31304 | 0x2f904 | 0x141 |
SetFilePointer | 0x0 | 0x429144 | 0x31308 | 0x2f908 | 0x3df |
WriteFile | 0x0 | 0x429148 | 0x3130c | 0x2f90c | 0x48d |
ReadFile | 0x0 | 0x42914c | 0x31310 | 0x2f910 | 0x368 |
WritePrivateProfileStringA | 0x0 | 0x429150 | 0x31314 | 0x2f914 | 0x492 |
GetOEMCP | 0x0 | 0x429154 | 0x31318 | 0x2f918 | 0x213 |
GetCPInfo | 0x0 | 0x429158 | 0x3131c | 0x2f91c | 0x15b |
GetModuleHandleW | 0x0 | 0x42915c | 0x31320 | 0x2f920 | 0x1f9 |
InterlockedIncrement | 0x0 | 0x429160 | 0x31324 | 0x2f924 | 0x2c0 |
TlsFree | 0x0 | 0x429164 | 0x31328 | 0x2f928 | 0x433 |
DeleteCriticalSection | 0x0 | 0x429168 | 0x3132c | 0x2f92c | 0xbe |
LocalReAlloc | 0x0 | 0x42916c | 0x31330 | 0x2f930 | 0x300 |
TlsSetValue | 0x0 | 0x429170 | 0x31334 | 0x2f934 | 0x435 |
TlsAlloc | 0x0 | 0x429174 | 0x31338 | 0x2f938 | 0x432 |
InitializeCriticalSection | 0x0 | 0x429178 | 0x3133c | 0x2f93c | 0x2b4 |
GlobalHandle | 0x0 | 0x42917c | 0x31340 | 0x2f940 | 0x28f |
GlobalReAlloc | 0x0 | 0x429180 | 0x31344 | 0x2f944 | 0x293 |
EnterCriticalSection | 0x0 | 0x429184 | 0x31348 | 0x2f948 | 0xd9 |
TlsGetValue | 0x0 | 0x429188 | 0x3134c | 0x2f94c | 0x434 |
LeaveCriticalSection | 0x0 | 0x42918c | 0x31350 | 0x2f950 | 0x2ef |
LocalAlloc | 0x0 | 0x429190 | 0x31354 | 0x2f954 | 0x2f9 |
GlobalFlags | 0x0 | 0x429194 | 0x31358 | 0x2f958 | 0x28b |
CloseHandle | 0x0 | 0x429198 | 0x3135c | 0x2f95c | 0x43 |
GetCurrentThread | 0x0 | 0x42919c | 0x31360 | 0x2f960 | 0x1ac |
ConvertDefaultLocale | 0x0 | 0x4291a0 | 0x31364 | 0x2f964 | 0x5a |
EnumResourceLanguagesA | 0x0 | 0x4291a4 | 0x31368 | 0x2f968 | 0xe6 |
GetLocaleInfoA | 0x0 | 0x4291a8 | 0x3136c | 0x2f96c | 0x1e8 |
InterlockedExchange | 0x0 | 0x4291ac | 0x31370 | 0x2f970 | 0x2bd |
lstrcmpA | 0x0 | 0x4291b0 | 0x31374 | 0x2f974 | 0x4a9 |
FreeResource | 0x0 | 0x4291b4 | 0x31378 | 0x2f978 | 0x14f |
GetCurrentThreadId | 0x0 | 0x4291b8 | 0x3137c | 0x2f97c | 0x1ad |
GlobalFindAtomA | 0x0 | 0x4291bc | 0x31380 | 0x2f980 | 0x288 |
GlobalDeleteAtom | 0x0 | 0x4291c0 | 0x31384 | 0x2f984 | 0x287 |
CompareStringA | 0x0 | 0x4291c4 | 0x31388 | 0x2f988 | 0x52 |
lstrcmpW | 0x0 | 0x4291c8 | 0x3138c | 0x2f98c | 0x4aa |
GetVersionExA | 0x0 | 0x4291cc | 0x31390 | 0x2f990 | 0x275 |
GetModuleFileNameA | 0x0 | 0x4291d0 | 0x31394 | 0x2f994 | 0x1f4 |
FreeLibrary | 0x0 | 0x4291d4 | 0x31398 | 0x2f998 | 0x14c |
InterlockedDecrement | 0x0 | 0x4291d8 | 0x3139c | 0x2f99c | 0x2bc |
GetModuleFileNameW | 0x0 | 0x4291dc | 0x313a0 | 0x2f9a0 | 0x1f5 |
GlobalFree | 0x0 | 0x4291e0 | 0x313a4 | 0x2f9a4 | 0x28c |
GlobalAlloc | 0x0 | 0x4291e4 | 0x313a8 | 0x2f9a8 | 0x285 |
FormatMessageA | 0x0 | 0x4291e8 | 0x313ac | 0x2f9ac | 0x147 |
LocalFree | 0x0 | 0x4291ec | 0x313b0 | 0x2f9b0 | 0x2fd |
MulDiv | 0x0 | 0x4291f0 | 0x313b4 | 0x2f9b4 | 0x319 |
lstrlenA | 0x0 | 0x4291f4 | 0x313b8 | 0x2f9b8 | 0x4b5 |
GlobalLock | 0x0 | 0x4291f8 | 0x313bc | 0x2f9bc | 0x290 |
GlobalUnlock | 0x0 | 0x4291fc | 0x313c0 | 0x2f9c0 | 0x297 |
GetCurrentProcessId | 0x0 | 0x429200 | 0x313c4 | 0x2f9c4 | 0x1aa |
GetModuleHandleA | 0x0 | 0x429204 | 0x313c8 | 0x2f9c8 | 0x1f6 |
LoadLibraryA | 0x0 | 0x429208 | 0x313cc | 0x2f9cc | 0x2f1 |
GlobalGetAtomNameA | 0x0 | 0x42920c | 0x313d0 | 0x2f9d0 | 0x28d |
GlobalAddAtomA | 0x0 | 0x429210 | 0x313d4 | 0x2f9d4 | 0x283 |
WideCharToMultiByte | 0x0 | 0x429214 | 0x313d8 | 0x2f9d8 | 0x47a |
SetLastError | 0x0 | 0x429218 | 0x313dc | 0x2f9dc | 0x3ec |
MultiByteToWideChar | 0x0 | 0x42921c | 0x313e0 | 0x2f9e0 | 0x31a |
FindResourceA | 0x0 | 0x429220 | 0x313e4 | 0x2f9e4 | 0x136 |
LoadResource | 0x0 | 0x429224 | 0x313e8 | 0x2f9e8 | 0x2f6 |
LockResource | 0x0 | 0x429228 | 0x313ec | 0x2f9ec | 0x307 |
SizeofResource | 0x0 | 0x42922c | 0x313f0 | 0x2f9f0 | 0x420 |
GetLastError | 0x0 | 0x429230 | 0x313f4 | 0x2f9f4 | 0x1e6 |
GetModuleHandleExA | 0x0 | 0x429234 | 0x313f8 | 0x2f9f8 | 0x1f7 |
GetProcAddress | 0x0 | 0x429238 | 0x313fc | 0x2f9fc | 0x220 |
GetFileType | 0x0 | 0x42923c | 0x31400 | 0x2fa00 | 0x1d7 |
GetCurrentProcess | 0x0 | 0x429240 | 0x31404 | 0x2fa04 | 0x1a9 |
USER32.dll (99)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateDialogIndirectParamA | 0x0 | 0x429264 | 0x31428 | 0x2fa28 | 0x59 |
GetNextDlgTabItem | 0x0 | 0x429268 | 0x3142c | 0x2fa2c | 0x153 |
EndDialog | 0x0 | 0x42926c | 0x31430 | 0x2fa30 | 0xd3 |
GetMessageA | 0x0 | 0x429270 | 0x31434 | 0x2fa34 | 0x14a |
TranslateMessage | 0x0 | 0x429274 | 0x31438 | 0x2fa38 | 0x2d5 |
GetCursorPos | 0x0 | 0x429278 | 0x3143c | 0x2fa3c | 0x119 |
ValidateRect | 0x0 | 0x42927c | 0x31440 | 0x2fa40 | 0x2f2 |
PostQuitMessage | 0x0 | 0x429280 | 0x31444 | 0x2fa44 | 0x220 |
SetWindowTextA | 0x0 | 0x429284 | 0x31448 | 0x2fa48 | 0x2ab |
IsDialogMessageA | 0x0 | 0x429288 | 0x3144c | 0x2fa4c | 0x1b8 |
SetMenuItemBitmaps | 0x0 | 0x42928c | 0x31450 | 0x2fa50 | 0x283 |
GetMenuCheckMarkDimensions | 0x0 | 0x429290 | 0x31454 | 0x2fa54 | 0x13e |
ModifyMenuA | 0x0 | 0x429294 | 0x31458 | 0x2fa58 | 0x200 |
EnableMenuItem | 0x0 | 0x429298 | 0x3145c | 0x2fa5c | 0xcf |
CheckMenuItem | 0x0 | 0x42929c | 0x31460 | 0x2fa60 | 0x3d |
RegisterWindowMessageA | 0x0 | 0x4292a0 | 0x31464 | 0x2fa64 | 0x249 |
SendDlgItemMessageA | 0x0 | 0x4292a4 | 0x31468 | 0x2fa68 | 0x259 |
SetWindowsHookExA | 0x0 | 0x4292a8 | 0x3146c | 0x2fa6c | 0x2af |
CallNextHookEx | 0x0 | 0x4292ac | 0x31470 | 0x2fa70 | 0x1b |
GetClassLongA | 0x0 | 0x4292b0 | 0x31474 | 0x2fa74 | 0x108 |
SetPropA | 0x0 | 0x4292b4 | 0x31478 | 0x2fa78 | 0x28f |
GetPropA | 0x0 | 0x4292b8 | 0x3147c | 0x2fa7c | 0x15b |
RemovePropA | 0x0 | 0x4292bc | 0x31480 | 0x2fa80 | 0x24f |
GetFocus | 0x0 | 0x4292c0 | 0x31484 | 0x2fa84 | 0x124 |
GetWindowTextA | 0x0 | 0x4292c4 | 0x31488 | 0x2fa88 | 0x18c |
GetForegroundWindow | 0x0 | 0x4292c8 | 0x3148c | 0x2fa8c | 0x125 |
DispatchMessageA | 0x0 | 0x4292cc | 0x31490 | 0x2fa90 | 0xa8 |
GetTopWindow | 0x0 | 0x4292d0 | 0x31494 | 0x2fa94 | 0x175 |
DestroyWindow | 0x0 | 0x4292d4 | 0x31498 | 0x2fa98 | 0xa0 |
GetMessageTime | 0x0 | 0x4292d8 | 0x3149c | 0x2fa9c | 0x14d |
GetMessagePos | 0x0 | 0x4292dc | 0x314a0 | 0x2faa0 | 0x14c |
MapWindowPoints | 0x0 | 0x4292e0 | 0x314a4 | 0x2faa4 | 0x1f3 |
UnregisterClassA | 0x0 | 0x4292e4 | 0x314a8 | 0x2faa8 | 0x2de |
SetForegroundWindow | 0x0 | 0x4292e8 | 0x314ac | 0x2faac | 0x27a |
CreateWindowExA | 0x0 | 0x4292ec | 0x314b0 | 0x2fab0 | 0x67 |
GetClassInfoExA | 0x0 | 0x4292f0 | 0x314b4 | 0x2fab4 | 0x105 |
RegisterClassA | 0x0 | 0x4292f4 | 0x314b8 | 0x2fab8 | 0x233 |
AdjustWindowRectEx | 0x0 | 0x4292f8 | 0x314bc | 0x2fabc | 0x3 |
PtInRect | 0x0 | 0x4292fc | 0x314c0 | 0x2fac0 | 0x229 |
DefWindowProcA | 0x0 | 0x429300 | 0x314c4 | 0x2fac4 | 0x95 |
CallWindowProcA | 0x0 | 0x429304 | 0x314c8 | 0x2fac8 | 0x1c |
SystemParametersInfoA | 0x0 | 0x429308 | 0x314cc | 0x2facc | 0x2c4 |
GetWindowPlacement | 0x0 | 0x42930c | 0x314d0 | 0x2fad0 | 0x187 |
MessageBoxA | 0x0 | 0x429310 | 0x314d4 | 0x2fad4 | 0x1f8 |
GetWindowRect | 0x0 | 0x429314 | 0x314d8 | 0x2fad8 | 0x188 |
GetSystemMetrics | 0x0 | 0x429318 | 0x314dc | 0x2fadc | 0x16f |
EndPaint | 0x0 | 0x42931c | 0x314e0 | 0x2fae0 | 0xd5 |
BeginPaint | 0x0 | 0x429320 | 0x314e4 | 0x2fae4 | 0xe |
ReleaseDC | 0x0 | 0x429324 | 0x314e8 | 0x2fae8 | 0x24c |
GetDC | 0x0 | 0x429328 | 0x314ec | 0x2faec | 0x11a |
ClientToScreen | 0x0 | 0x42932c | 0x314f0 | 0x2faf0 | 0x45 |
GrayStringA | 0x0 | 0x429330 | 0x314f4 | 0x2faf4 | 0x193 |
DrawTextExA | 0x0 | 0x429334 | 0x314f8 | 0x2faf8 | 0xc6 |
DrawTextA | 0x0 | 0x429338 | 0x314fc | 0x2fafc | 0xc5 |
TabbedTextOutA | 0x0 | 0x42933c | 0x31500 | 0x2fb00 | 0x2c6 |
UnhookWindowsHookEx | 0x0 | 0x429340 | 0x31504 | 0x2fb04 | 0x2d9 |
GetMenuState | 0x0 | 0x429344 | 0x31508 | 0x2fb08 | 0x147 |
GetClassNameA | 0x0 | 0x429348 | 0x3150c | 0x2fb0c | 0x10a |
LoadBitmapA | 0x0 | 0x42934c | 0x31510 | 0x2fb10 | 0x1d0 |
GetClientRect | 0x0 | 0x429350 | 0x31514 | 0x2fb14 | 0x10d |
UpdateWindow | 0x0 | 0x429354 | 0x31518 | 0x2fb18 | 0x2e9 |
GetSysColor | 0x0 | 0x429358 | 0x3151c | 0x2fb1c | 0x16c |
DestroyMenu | 0x0 | 0x42935c | 0x31520 | 0x2fb20 | 0x9e |
WinHelpA | 0x0 | 0x429360 | 0x31524 | 0x2fb24 | 0x2ff |
SetWindowPos | 0x0 | 0x429364 | 0x31528 | 0x2fb28 | 0x2a7 |
SetFocus | 0x0 | 0x429368 | 0x3152c | 0x2fb2c | 0x279 |
GetWindowThreadProcessId | 0x0 | 0x42936c | 0x31530 | 0x2fb30 | 0x190 |
GetActiveWindow | 0x0 | 0x429370 | 0x31534 | 0x2fb34 | 0xf9 |
IsWindowEnabled | 0x0 | 0x429374 | 0x31538 | 0x2fb38 | 0x1c6 |
GetDlgItem | 0x0 | 0x429378 | 0x3153c | 0x2fb3c | 0x11f |
SetWindowLongA | 0x0 | 0x42937c | 0x31540 | 0x2fb40 | 0x2a4 |
GetSysColorBrush | 0x0 | 0x429380 | 0x31544 | 0x2fb44 | 0x16d |
LoadCursorA | 0x0 | 0x429384 | 0x31548 | 0x2fb48 | 0x1d2 |
EnableWindow | 0x0 | 0x429388 | 0x3154c | 0x2fb4c | 0xd1 |
IsWindow | 0x0 | 0x42938c | 0x31550 | 0x2fb50 | 0x1c5 |
GetWindowLongA | 0x0 | 0x429390 | 0x31554 | 0x2fb54 | 0x181 |
ShowWindow | 0x0 | 0x429394 | 0x31558 | 0x2fb58 | 0x2b8 |
GetWindow | 0x0 | 0x429398 | 0x3155c | 0x2fb5c | 0x17d |
GetDesktopWindow | 0x0 | 0x42939c | 0x31560 | 0x2fb60 | 0x11c |
SetMenu | 0x0 | 0x4293a0 | 0x31564 | 0x2fb64 | 0x27f |
PostMessageA | 0x0 | 0x4293a4 | 0x31568 | 0x2fb68 | 0x21e |
GetLastActivePopup | 0x0 | 0x4293a8 | 0x3156c | 0x2fb6c | 0x138 |
GetMenu | 0x0 | 0x4293ac | 0x31570 | 0x2fb70 | 0x13c |
CopyRect | 0x0 | 0x4293b0 | 0x31574 | 0x2fb74 | 0x4f |
GetClassInfoA | 0x0 | 0x4293b4 | 0x31578 | 0x2fb78 | 0x104 |
GetMenuItemCount | 0x0 | 0x4293b8 | 0x3157c | 0x2fb7c | 0x142 |
GetMenuItemID | 0x0 | 0x4293bc | 0x31580 | 0x2fb80 | 0x143 |
GetDlgCtrlID | 0x0 | 0x4293c0 | 0x31584 | 0x2fb84 | 0x11e |
GetKeyState | 0x0 | 0x4293c4 | 0x31588 | 0x2fb88 | 0x131 |
LoadIconA | 0x0 | 0x4293c8 | 0x3158c | 0x2fb8c | 0x1d6 |
SetCursor | 0x0 | 0x4293cc | 0x31590 | 0x2fb90 | 0x270 |
PeekMessageA | 0x0 | 0x4293d0 | 0x31594 | 0x2fb94 | 0x21b |
GetCapture | 0x0 | 0x4293d4 | 0x31598 | 0x2fb98 | 0x101 |
GetParent | 0x0 | 0x4293d8 | 0x3159c | 0x2fb9c | 0x155 |
SetActiveWindow | 0x0 | 0x4293dc | 0x315a0 | 0x2fba0 | 0x266 |
IsWindowVisible | 0x0 | 0x4293e0 | 0x315a4 | 0x2fba4 | 0x1ca |
IsIconic | 0x0 | 0x4293e4 | 0x315a8 | 0x2fba8 | 0x1bd |
SendMessageA | 0x0 | 0x4293e8 | 0x315ac | 0x2fbac | 0x25e |
GetSubMenu | 0x0 | 0x4293ec | 0x315b0 | 0x2fbb0 | 0x16b |
GDI32.dll (24)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DeleteDC | 0x0 | 0x429028 | 0x311ec | 0x2f7ec | 0xcd |
CreateBitmap | 0x0 | 0x42902c | 0x311f0 | 0x2f7f0 | 0x28 |
GetStockObject | 0x0 | 0x429030 | 0x311f4 | 0x2f7f4 | 0x1f4 |
ScaleWindowExtEx | 0x0 | 0x429034 | 0x311f8 | 0x2f7f8 | 0x259 |
SetWindowExtEx | 0x0 | 0x429038 | 0x311fc | 0x2f7fc | 0x293 |
ScaleViewportExtEx | 0x0 | 0x42903c | 0x31200 | 0x2f800 | 0x258 |
SetViewportExtEx | 0x0 | 0x429040 | 0x31204 | 0x2f804 | 0x28f |
OffsetViewportOrgEx | 0x0 | 0x429044 | 0x31208 | 0x2f808 | 0x225 |
SetViewportOrgEx | 0x0 | 0x429048 | 0x3120c | 0x2f80c | 0x290 |
SelectObject | 0x0 | 0x42904c | 0x31210 | 0x2f810 | 0x25e |
Escape | 0x0 | 0x429050 | 0x31214 | 0x2f814 | 0x119 |
ExtTextOutA | 0x0 | 0x429054 | 0x31218 | 0x2f818 | 0x122 |
TextOutA | 0x0 | 0x429058 | 0x3121c | 0x2f81c | 0x29f |
RectVisible | 0x0 | 0x42905c | 0x31220 | 0x2f820 | 0x245 |
GetObjectA | 0x0 | 0x429060 | 0x31224 | 0x2f824 | 0x1e2 |
DeleteObject | 0x0 | 0x429064 | 0x31228 | 0x2f828 | 0xd0 |
GetClipBox | 0x0 | 0x429068 | 0x3122c | 0x2f82c | 0x1aa |
SetMapMode | 0x0 | 0x42906c | 0x31230 | 0x2f830 | 0x27b |
SetTextColor | 0x0 | 0x429070 | 0x31234 | 0x2f834 | 0x28d |
SetBkColor | 0x0 | 0x429074 | 0x31238 | 0x2f838 | 0x265 |
RestoreDC | 0x0 | 0x429078 | 0x3123c | 0x2f83c | 0x250 |
SaveDC | 0x0 | 0x42907c | 0x31240 | 0x2f840 | 0x257 |
GetDeviceCaps | 0x0 | 0x429080 | 0x31244 | 0x2f844 | 0x1b5 |
PtVisible | 0x0 | 0x429084 | 0x31248 | 0x2f848 | 0x241 |
WINSPOOL.DRV (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DocumentPropertiesA | 0x0 | 0x4293f4 | 0x315b8 | 0x2fbb8 | 0x4d |
OpenPrinterA | 0x0 | 0x4293f8 | 0x315bc | 0x2fbbc | 0x8e |
ClosePrinter | 0x0 | 0x4293fc | 0x315c0 | 0x2fbc0 | 0x1d |
ADVAPI32.dll (9)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegSetValueExA | 0x0 | 0x429000 | 0x311c4 | 0x2f7c4 | 0x277 |
RegCreateKeyExA | 0x0 | 0x429004 | 0x311c8 | 0x2f7c8 | 0x232 |
RegQueryValueA | 0x0 | 0x429008 | 0x311cc | 0x2f7cc | 0x266 |
RegOpenKeyA | 0x0 | 0x42900c | 0x311d0 | 0x2f7d0 | 0x259 |
RegEnumKeyA | 0x0 | 0x429010 | 0x311d4 | 0x2f7d4 | 0x247 |
RegDeleteKeyA | 0x0 | 0x429014 | 0x311d8 | 0x2f7d8 | 0x237 |
RegOpenKeyExA | 0x0 | 0x429018 | 0x311dc | 0x2f7dc | 0x25a |
RegQueryValueExA | 0x0 | 0x42901c | 0x311e0 | 0x2f7e0 | 0x267 |
RegCloseKey | 0x0 | 0x429020 | 0x311e4 | 0x2f7e4 | 0x22a |
SHLWAPI.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathFindFileNameA | 0x0 | 0x429258 | 0x3141c | 0x2fa1c | 0x48 |
PathFindExtensionA | 0x0 | 0x42925c | 0x31420 | 0x2fa20 | 0x46 |
OLEAUT32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VariantClear | 0x9 | 0x429248 | 0x3140c | 0x2fa0c | - |
VariantChangeType | 0xc | 0x42924c | 0x31410 | 0x2fa10 | - |
VariantInit | 0x8 | 0x429250 | 0x31414 | 0x2fa14 | - |
Memory Dumps (5)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
transscroll.exe.exe | 1 | 0x002D0000 | 0x0034FFFF | Relevant Image | 32-bit | 0x002E8901 |
...
|
|||
buffer | 1 | 0x02450000 | 0x02480FFF | First Execution | 32-bit | 0x02450000 |
...
|
|||
buffer | 1 | 0x02491000 | 0x024929FF | First Execution | 32-bit | 0x024927B0 |
...
|
|||
buffer | 1 | 0x02510000 | 0x02542FFF | Marked Executable | 32-bit | - |
...
|
|||
transscroll.exe.exe | 1 | 0x002D0000 | 0x0034FFFF | Final Dump | 32-bit | - |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
SodinokibiEncryptedFile | File encrypted by Sodinokibi Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\DHtmlHeader.html | Modified File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DisplayIcon.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\UiInfo.xml.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Strings.xml.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\HardwareEvents.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Internet Explorer.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Key Management Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx.TJODT | Dropped File | Binary |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-International%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Known Folders API Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Store%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Windows PowerShell.evtx.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\desktop.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Recovery\ReAgentOld.xml.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd.TJODT | Dropped File | Batch |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\preoobe.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\SetupComplete.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\eula.rtf.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\LocalizedData.xml.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\LocalizedData.xml.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\LocalizedData.xml.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.xml.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\LocalizedData.xml.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\LocalizedData.xml.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\eula.rtf.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\eula.rtf.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\LocalizedData.xml.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\LocalizedData.xml.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf.TJODT | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\R3ADM3.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp.TJODT | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1033\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1036\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»