VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Sodinokibi
Generic.EmotetU.DFBF217B
Mal/Generic-S
|
locker.exe
Windows Exe (x86-32)
Created at 2020-09-04T22:08:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x402b7c |
Size Of Code | 0x4600 |
Size Of Initialized Data | 0x38000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-09-03 13:11:28+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x45df | 0x4600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 3.66 |
.rdata | 0x406000 | 0x1322 | 0x1400 | 0x4a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.65 |
.data | 0x408000 | 0xac0 | 0x200 | 0x5e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.49 |
.idata | 0x409000 | 0xe71 | 0x1000 | 0x6000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.0 |
.rsrc | 0x40a000 | 0x34f33 | 0x35000 | 0x7000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.15 |
Imports (6)
»
COMCTL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x6 | 0x409318 | 0x908c | 0x608c | - |
KERNEL32.dll (16)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
QueryPerformanceCounter | 0x0 | 0x409390 | 0x9104 | 0x6104 | 0x354 |
IsDebuggerPresent | 0x0 | 0x409394 | 0x9108 | 0x6108 | 0x2d1 |
SetUnhandledExceptionFilter | 0x0 | 0x409398 | 0x910c | 0x610c | 0x415 |
UnhandledExceptionFilter | 0x0 | 0x40939c | 0x9110 | 0x6110 | 0x43e |
GetTickCount | 0x0 | 0x4093a0 | 0x9114 | 0x6114 | 0x266 |
TerminateProcess | 0x0 | 0x4093a4 | 0x9118 | 0x6118 | 0x42d |
InterlockedCompareExchange | 0x0 | 0x4093a8 | 0x911c | 0x611c | 0x2ba |
Sleep | 0x0 | 0x4093ac | 0x9120 | 0x6120 | 0x421 |
InterlockedExchange | 0x0 | 0x4093b0 | 0x9124 | 0x6124 | 0x2bd |
GetSystemTimeAsFileTime | 0x0 | 0x4093b4 | 0x9128 | 0x6128 | 0x24f |
GetCurrentThreadId | 0x0 | 0x4093b8 | 0x912c | 0x612c | 0x1ad |
GetCurrentProcessId | 0x0 | 0x4093bc | 0x9130 | 0x6130 | 0x1aa |
FreeConsole | 0x0 | 0x4093c0 | 0x9134 | 0x6134 | 0x149 |
LoadLibraryExA | 0x0 | 0x4093c4 | 0x9138 | 0x6138 | 0x2f2 |
ExitProcess | 0x0 | 0x4093c8 | 0x913c | 0x613c | 0x104 |
GetCurrentProcess | 0x0 | 0x4093cc | 0x9140 | 0x6140 | 0x1a9 |
USER32.dll (13)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EndDialog | 0x0 | 0x40953c | 0x92b0 | 0x62b0 | 0xd3 |
GetWindowRect | 0x0 | 0x409540 | 0x92b4 | 0x62b4 | 0x188 |
GetClientRect | 0x0 | 0x409544 | 0x92b8 | 0x62b8 | 0x10d |
GetSystemMetrics | 0x0 | 0x409548 | 0x92bc | 0x62bc | 0x16f |
MoveWindow | 0x0 | 0x40954c | 0x92c0 | 0x62c0 | 0x205 |
SetTimer | 0x0 | 0x409550 | 0x92c4 | 0x62c4 | 0x29e |
SendMessageA | 0x0 | 0x409554 | 0x92c8 | 0x62c8 | 0x25e |
KillTimer | 0x0 | 0x409558 | 0x92cc | 0x62cc | 0x1cd |
PostQuitMessage | 0x0 | 0x40955c | 0x92d0 | 0x62d0 | 0x220 |
DefWindowProcA | 0x0 | 0x409560 | 0x92d4 | 0x62d4 | 0x95 |
GetDC | 0x0 | 0x409564 | 0x92d8 | 0x62d8 | 0x11a |
ReleaseDC | 0x0 | 0x409568 | 0x92dc | 0x62dc | 0x24c |
ShowWindow | 0x0 | 0x40956c | 0x92e0 | 0x62e0 | 0x2b8 |
GDI32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DeleteObject | 0x0 | 0x409348 | 0x90bc | 0x60bc | 0xd0 |
StretchBlt | 0x0 | 0x40934c | 0x90c0 | 0x60c0 | 0x29a |
CreateDIBSection | 0x0 | 0x409350 | 0x90c4 | 0x60c4 | 0x33 |
CreateCompatibleDC | 0x0 | 0x409354 | 0x90c8 | 0x60c8 | 0x2e |
SelectObject | 0x0 | 0x409358 | 0x90cc | 0x60cc | 0x25e |
DeleteDC | 0x0 | 0x40935c | 0x90d0 | 0x60d0 | 0xcd |
MSVCR90.dll (35)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_cexit | 0x0 | 0x409468 | 0x91dc | 0x61dc | 0x12c |
_exit | 0x0 | 0x40946c | 0x91e0 | 0x61e0 | 0x17c |
_XcptFilter | 0x0 | 0x409470 | 0x91e4 | 0x61e4 | 0x66 |
exit | 0x0 | 0x409474 | 0x91e8 | 0x61e8 | 0x4cc |
__initenv | 0x0 | 0x409478 | 0x91ec | 0x61ec | 0xa0 |
_initterm | 0x0 | 0x40947c | 0x91f0 | 0x61f0 | 0x204 |
__getmainargs | 0x0 | 0x409480 | 0x91f4 | 0x61f4 | 0x9f |
_configthreadlocale | 0x0 | 0x409484 | 0x91f8 | 0x61f8 | 0x13c |
__setusermatherr | 0x0 | 0x409488 | 0x91fc | 0x61fc | 0xe3 |
_adjust_fdiv | 0x0 | 0x40948c | 0x9200 | 0x6200 | 0x10b |
__p__commode | 0x0 | 0x409490 | 0x9204 | 0x6204 | 0xcb |
_amsg_exit | 0x0 | 0x409494 | 0x9208 | 0x6208 | 0x115 |
_encode_pointer | 0x0 | 0x409498 | 0x920c | 0x620c | 0x16a |
__set_app_type | 0x0 | 0x40949c | 0x9210 | 0x6210 | 0xe0 |
_crt_debugger_hook | 0x0 | 0x4094a0 | 0x9214 | 0x6214 | 0x14b |
?terminate@@YAXXZ | 0x0 | 0x4094a4 | 0x9218 | 0x6218 | 0x43 |
_unlock | 0x0 | 0x4094a8 | 0x921c | 0x621c | 0x3e6 |
__dllonexit | 0x0 | 0x4094ac | 0x9220 | 0x6220 | 0x96 |
_initterm_e | 0x0 | 0x4094b0 | 0x9224 | 0x6224 | 0x205 |
_onexit | 0x0 | 0x4094b4 | 0x9228 | 0x6228 | 0x31c |
_decode_pointer | 0x0 | 0x4094b8 | 0x922c | 0x622c | 0x160 |
_except_handler4_common | 0x0 | 0x4094bc | 0x9230 | 0x6230 | 0x173 |
_invoke_watson | 0x0 | 0x4094c0 | 0x9234 | 0x6234 | 0x20b |
_controlfp_s | 0x0 | 0x4094c4 | 0x9238 | 0x6238 | 0x13f |
memcpy | 0x0 | 0x4094c8 | 0x923c | 0x623c | 0x526 |
_wtoi | 0x0 | 0x4094cc | 0x9240 | 0x6240 | 0x4a9 |
__CxxFrameHandler3 | 0x0 | 0x4094d0 | 0x9244 | 0x6244 | 0x73 |
_snprintf | 0x0 | 0x4094d4 | 0x9248 | 0x6248 | 0x369 |
_wcslwr | 0x0 | 0x4094d8 | 0x924c | 0x624c | 0x435 |
srand | 0x0 | 0x4094dc | 0x9250 | 0x6250 | 0x549 |
rand | 0x0 | 0x4094e0 | 0x9254 | 0x6254 | 0x538 |
_time64 | 0x0 | 0x4094e4 | 0x9258 | 0x6258 | 0x3ca |
_CIsin | 0x0 | 0x4094e8 | 0x925c | 0x625c | 0x52 |
__p__fmode | 0x0 | 0x4094ec | 0x9260 | 0x6260 | 0xcf |
_lock | 0x0 | 0x4094f0 | 0x9264 | 0x6264 | 0x276 |
MSVCP90.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
?endl@std@@YAAAV?$basic_ostream@DU?$char_traits@D@std@@@1@AAV21@@Z | 0x0 | 0x409408 | 0x917c | 0x617c | 0x7a4 |
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@P6AAAV01@AAV01@@Z@Z | 0x0 | 0x40940c | 0x9180 | 0x6180 | 0x31d |
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAEHD@Z | 0x0 | 0x409410 | 0x9184 | 0x6184 | 0xb73 |
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAEHPBDH@Z | 0x0 | 0x409414 | 0x9188 | 0x6188 | 0xb76 |
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QAEXH_N@Z | 0x0 | 0x409418 | 0x918c | 0x618c | 0xb44 |
?uncaught_exception@std@@YA_NXZ | 0x0 | 0x40941c | 0x9190 | 0x6190 | 0xbe4 |
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEXXZ | 0x0 | 0x409420 | 0x9194 | 0x6194 | 0x57c |
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV12@XZ | 0x0 | 0x409424 | 0x9198 | 0x6198 | 0x821 |
?_Unlock@_Mutex@std@@QAEXXZ | 0x0 | 0x409428 | 0x919c | 0x619c | 0x5d3 |
?_Lock@_Mutex@std@@QAEXXZ | 0x0 | 0x40942c | 0x91a0 | 0x61a0 | 0x55a |
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A | 0x0 | 0x409430 | 0x91a4 | 0x61a4 | 0x682 |
Memory Dumps (4)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
locker.exe | 1 | 0x00400000 | 0x0043EFFF | Relevant Image | 32-bit | 0x00401064 |
...
|
|||
buffer | 1 | 0x00440000 | 0x0046AFFF | First Execution | 32-bit | 0x00440000 |
...
|
|||
buffer | 1 | 0x00590000 | 0x005BDFFF | First Execution | 32-bit | 0x005A5D92 |
...
|
|||
locker.exe | 1 | 0x00400000 | 0x0043EFFF | Final Dump | 32-bit | - |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
SodinokibiEncryptedFile | File encrypted by Sodinokibi Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\DHtmlHeader.html.ILMWL | Dropped File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DisplayIcon.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.xml.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Strings.xml.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\HardwareEvents.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Internet Explorer.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.ILMWL | Dropped File | Text |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-International%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Known Folders API Service.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Operational.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Store%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx | Modified File | Binary |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd.ILMWL | Dropped File | Batch |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\SetupComplete.cmd.ILMWL | Dropped File | Batch |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\LocalizedData.xml.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\preoobe.cmd.ILMWL | Dropped File | Batch |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.xml.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\LocalizedData.xml.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\LocalizedData.xml.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\eula.rtf.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\LocalizedData.xml.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\Parameterinfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate1.ico.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate2.ico.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate4.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Print.ico.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\stop.ico.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\warn.ico.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqMet.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core.mzz.ILMWL | Dropped File | Binary |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\application.ini.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\crashreporter.ini.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\dependentlibs.list.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\firefox.VisualElementsManifest.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\freebl3.chk | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\nssdbm3.chk.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\AppXManifest.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\precomplete.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\removed-files.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\update-settings.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\rempl\rempl.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\rempl\Unlock.xml.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\omni.ja | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Mozilla Maintenance Service\updater.ini.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Extensibility Component.swidtag.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Licensing Component.swidtag.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT.LOG1.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TMContainer00000000000000000001.regtrans-ms.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TM.blf.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{fae9930d-933c-11e7-a51d-b808901d6c9b}.TM.blf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{fae9930d-933c-11e7-a51d-b808901d6c9b}.TMContainer00000000000000000001.regtrans-ms.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TMContainer00000000000000000002.regtrans-ms.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{fae9930d-933c-11e7-a51d-b808901d6c9b}.TMContainer00000000000000000002.regtrans-ms.ILMWL | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Key Management Service.evtx.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Windows PowerShell.evtx.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\eula.rtf.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1033\eula.rtf.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1033\LocalizedData.xml.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.xml.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1037\LocalizedData.xml.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1036\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1041\eula.rtf.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1044\LocalizedData.xml.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\LocalizedData.xml.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1043\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1053\LocalizedData.xml.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1046\LocalizedData.xml.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2052\LocalizedData.xml.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3076\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3082\LocalizedData.xml.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Client\Parameterinfo.xml.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Client\UiInfo.xml.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Extended\UiInfo.xml.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate3.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate6.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate7.ico.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Save.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Setup.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate5.ico.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate8.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\FileSystemMetadata.xml.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\Accessible.tlb.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\install.log.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\softokn3.chk.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\updater.ini.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\platform.ini.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\Task.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Localization Component.swidtag | Modified File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft_Windows-10-Pro.swidtag.ILMWL | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT.LOG2 | Modified File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\USOShared\R3ADM3.txt | Dropped File | Text |
Not Queried
|
...
|
»