VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Trojan
|
Threat Names: |
Gen:Trojan.Heur.FU.fuW@aKB239
Win32.Trojan.Nemty
|
wwllww.vexe.exe
Windows Exe (x86-32)
Created at 2020-02-03T06:58:00
Remarks (2/2)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "30 seconds" to "10 seconds" to reveal dormant functionality.
Remarks
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2020-01-31 06:59 (UTC+1) |
Last Seen | 2020-02-03 01:40 (UTC+1) |
Names | Win32.Trojan.Nemty |
Families | Nemty |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x412150 |
Size Of Code | 0x15000 |
Size Of Initialized Data | 0x2400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-12-06 17:46:26+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x14fff | 0x15000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.15 |
.rdata | 0x416000 | 0x40e | 0x600 | 0x15400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.43 |
.data | 0x417000 | 0x460 | 0x200 | 0x15a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.75 |
.rsrc | 0x418000 | 0x1558 | 0x1600 | 0x15c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.94 |
.reloc | 0x41a000 | 0x5a4 | 0x600 | 0x17200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.39 |
Imports (1)
»
KERNEL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Sleep | 0x0 | 0x416000 | 0x163f0 | 0x157f0 | 0x575 |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Trojan.Heur.FU.fuW@aKB239 |
Malicious
|
C:\ProgramData\Microsoft\User Account Pictures\Default User.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\1045\localizeddata.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\1038\localizeddata.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\3082\localizeddata.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\1055\localizeddata.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Binary |
Unknown
|
...
|
»
c:\588bce7c90097ed212\1040\localizeddata.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\1037\localizeddata.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\1049\localizeddata.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\1043\localizeddata.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Audio |
Unknown
|
...
|
»
c:\588bce7c90097ed212\1033\localizeddata.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\1041\eula.rtf.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\1032\localizeddata.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\1044\eula.rtf.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\2052\eula.rtf.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\2052\localizeddata.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\3076\eula.rtf.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\1044\localizeddata.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\3076\localizeddata.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\2070\localizeddata.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\1046\localizeddata.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\1029\localizeddata.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\unp\campaignmanager\campaigncatalog.json.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\microsoft office\office16\slerror.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\extended\uiinfo.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft office 16 click-to-run licensing component.swidtag.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\unp\task.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\microsoft office\filesystemmetadata.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft_windows-10-pro.swidtag.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft office 16 click-to-run extensibility component.swidtag.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\usoprivate\updatestore\updatecspstore.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\rempl\rempl.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\unp\logs\universalnotificationplatform.006.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\unp\logs\universalnotificationplatform.007.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\unp\logs\universalnotificationplatform.009.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\unp\logs\universalnotificationplatform.022.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\unp\logs\universalnotificationplatform.002.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\unp\logs\universalnotificationplatform.005.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\unp\logs\universalnotificationplatform.003.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\unp\logs\universalnotificationplatform.004.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\usoshared\logs\notificationux.001.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\usoshared\logs\notificationux.002.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\usoshared\logs\notificationuxbroker.002.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\usoshared\logs\notificationuxbroker.003.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\usoshared\logs\notificationuxbroker.004.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\usoshared\logs\notificationuxbroker.006.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\usoshared\logs\notificationuxbroker.016.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\usoshared\logs\notificationuxbroker.014.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\usoshared\logs\notificationuxbroker.011.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\usoshared\logs\updatesessionorchestration.012.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\usoshared\logs\updatesessionorchestration.010.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\usoshared\logs\updatesessionorchestration.009.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\usoshared\logs\updatesessionorchestration.008.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\usoshared\logs\notificationuxbroker.015.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\usoshared\logs\notificationuxbroker.012.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\usoshared\logs\notificationuxbroker.008.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\usoshared\logs\notificationuxbroker.007.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\usoshared\logs\notificationuxbroker.017.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\usoshared\logs\updatesessionorchestration.014.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\usoshared\logs\updatesessionorchestration.015.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\microsoft office\office16\ospp.htm.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\common files\designer\msaddndr.olb.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\rempl\unlock.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files (x86)\adobe\acrobat reader dc\readme.htm.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\unp\logs\universalnotificationplatform.010.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\unp\logs\universalnotificationplatform.021.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\usoshared\logs\notificationuxbroker.009.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\usoshared\logs\notificationuxbroker.013.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\java\jre1.8.0_144\readme.txt.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\java\jre1.8.0_144\license.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-kernel-storemgr%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-winlogon%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-twinui%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-kernel-power%4thermal-operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-hotspotauth%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-ncsi%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-volumesnapshot-driver%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-windows defender%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-windows defender%4whc.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-terminalservices-localsessionmanager%4admin.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-store%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-terminalservices-remoteconnectionmanager%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-resource-exhaustion-detector%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-settingsync%4debug.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-smbclient%4connectivity.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-kernel-whea%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-grouppolicy%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-kernel-eventtracing%4admin.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-shell-core%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-ntfs%4whc.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-wcmsvc%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-terminalservices-localsessionmanager%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-smbclient%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-smbserver%4security.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-wininet-config%4proxyconfigchanged.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-program-compatibility-assistant%4compatafterupgrade.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-mui%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-known folders api service.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-smbserver%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-taskscheduler%4maintenance.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-shell-core%4actioncenter.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\security.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-settingsync%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\deploymentconfig.1.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\clicktorun\deploymentconfig.0.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\usoshared\logs\updatesessionorchestration.017.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\microsoft office\root\licenses16\accessr_oem_perp-pl.xrm-ms.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\microsoft office\root\licenses16\accessr_oem_perp-ul-phn.xrm-ms.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\microsoft office\root\licenses16\accessr_retail-ul-phn.xrm-ms.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\microsoft office\root\licenses16\accessvl_kms_client-ppd.xrm-ms.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\microsoft office\root\licenses16\accessvl_kms_client-ul-oob.xrm-ms.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\microsoft office\root\licenses16\client-issuance-bridge-office.xrm-ms.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\microsoft office\root\licenses16\client-issuance-stil.xrm-ms.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows10upgrade\resources\ux\block.png.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows10upgrade\resources\ux\bluelogo.png.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows10upgrade\resources\ux\default_oobe.css.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows10upgrade\resources\ux\default_oobe.htm.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows10upgrade\resources\ux\lock.png.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows10upgrade\resources\ux\logo.png.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows10upgrade\resources\ux\nonetworkconnection.png.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\microsoft office\root\licenses16\excelr_oem_perp-pl.xrm-ms.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\microsoft office\root\licenses16\excelr_retail-ul-oob.xrm-ms.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\microsoft office\root\licenses16\excelvl_kms_client-ppd.xrm-ms.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\java\jre1.8.0_144\copyright.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\user account pictures\user.bmp.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\microsoft office\root\licenses16\accessr_grace-ppd.xrm-ms.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\programdata\microsoft\user account pictures\guest.bmp.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\microsoft office\root\licenses16\accessr_grace-ul-oob.xrm-ms.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows10upgrade\resources\ux\default_eos.htm.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows10upgrade\resources\ux\pass.png.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows10upgrade\resources\ux\networkissuefaq.mht.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\microsoft office\root\licenses16\excelr_oem_perp-ul-phn.xrm-ms.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\microsoft office\root\licenses16\excelr_retail-ppd.xrm-ms.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files\microsoft office\root\licenses16\excelr_retail-ul-phn.xrm-ms.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files (x86)\adobe\acrobat reader dc\reader\welcome.pdf.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files (x86)\adobe\acrobat reader dc\reader\rtc.der.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files (x86)\adobe\acrobat reader dc\reader\click on 'change' to select default pdf handler.pdf.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files (x86)\adobe\acrobat reader dc\reader\agmgpuoptin.ini.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files (x86)\adobe\acrobat reader dc\reader\adobe.reader.dependencies.manifest.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\program files (x86)\adobe\acrobat reader dc\reader\1494870c-9912-c184-4cc9-b401-a53f4d8de290.pdf.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-windows firewall with advanced security%4connectionsecurity.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-userpnp%4actioncenter.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\system.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-kernel-boot%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-international%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-user profile service%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows10upgrade\resources\ux\eula\eula_bg-bg.htm.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows10upgrade\resources\ux\eula\eula_cs-cz.htm.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows10upgrade\resources\ux\eula\eula_da-dk.htm.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows10upgrade\resources\ux\eula\eula_de-de.htm.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\logs\microsoft-windows-kernel-pnp%4configuration.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Unknown
|
...
|
»
c:\588bce7c90097ed212\1042\localizeddata.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\588bce7c90097ed212\1053\localizeddata.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\588bce7c90097ed212\1030\localizeddata.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft office 16 click-to-run localization component.swidtag.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\program files\unp\logs\universalnotificationplatform.008.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\usoshared\logs\notificationuxbroker.005.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Audio |
Not Queried
|
...
|
»
c:\programdata\usoshared\logs\updatesessionorchestration.013.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\usoshared\logs\updatesessionorchestration.011.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\usoshared\logs\notificationuxbroker.010.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\usoshared\logs\updatesessionorchestration.016.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\588bce7c90097ed212\1036\localizeddata.xml.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\program files\unp\logs\universalnotificationplatform.029.etl.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\program files\microsoft office\office16\ospp.vbs.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\program files\java\jre1.8.0_144\welcome.html.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\program files\java\jre1.8.0_144\release.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\user account pictures\user-48.png.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\programdata\microsoft\user account pictures\user.png.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\logs\microsoft-windows-windows firewall with advanced security%4firewall.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\logs\microsoft-windows-wmi-activity%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\logs\microsoft-windows-kernel-whea%4errors.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\logs\microsoft-windows-readyboost%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\logs\microsoft-windows-networkprofile%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\C3F7E-Readme.txt | Dropped File | Text |
Not Queried
|
...
|
»
c:\logs\microsoft-windows-mui%4admin.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\windows10upgrade\resources\ux\default_eos.css.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\program files\microsoft office\root\licenses16\accessr_oem_perp-ppd.xrm-ms.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\program files\microsoft office\root\licenses16\excelr_oem_perp-ppd.xrm-ms.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\logs\microsoft-windows-hyper-v-guest-drivers%4admin.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\logs\microsoft-windows-liveid%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\logs\microsoft-windows-kernel-shimengine%4operational.evtx.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»
c:\windows10upgrade\resources\ux\eula\eula_ar-sa.htm.mailto[kkeessnnkkaa@cock.li].c3f7e | Dropped File | Stream |
Not Queried
|
...
|
»