VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Sodinokibi
Trojan.EmotetU.Gen.vuW@i0qEqqoi
Generic.EmotetAC.16BE3CF5
...
|
i375Itw4yywr22dA.exe
Windows Exe (x86-32)
Created at 2020-12-20T09:02:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\i375Itw4yywr22dA.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x40772a |
Size Of Code | 0x6e00 |
Size Of Initialized Data | 0x4ea00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-10-30 18:59:10+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x6da4 | 0x6e00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.5 |
.rdata | 0x408000 | 0x14f0 | 0x1600 | 0x7200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.24 |
.data | 0x40a000 | 0x6b8380 | 0x200 | 0x8800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.46 |
.rsrc | 0xac3000 | 0x4779a | 0x47800 | 0x8a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.41 |
.reloc | 0xb0b000 | 0x583e | 0x5a00 | 0x50200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 1.83 |
Imports (6)
»
KERNEL32.dll (30)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCurrentProcess | 0x0 | 0x408064 | 0x8784 | 0x7984 | 0x219 |
TerminateProcess | 0x0 | 0x408068 | 0x8788 | 0x7988 | 0x58e |
GetStartupInfoA | 0x0 | 0x40806c | 0x878c | 0x798c | 0x2d1 |
UnhandledExceptionFilter | 0x0 | 0x408070 | 0x8790 | 0x7990 | 0x5af |
Sleep | 0x0 | 0x408074 | 0x8794 | 0x7994 | 0x57f |
InterlockedExchange | 0x0 | 0x408078 | 0x8798 | 0x7998 | 0x36c |
SetUnhandledExceptionFilter | 0x0 | 0x40807c | 0x879c | 0x799c | 0x56f |
IsDebuggerPresent | 0x0 | 0x408080 | 0x87a0 | 0x79a0 | 0x381 |
QueryPerformanceCounter | 0x0 | 0x408084 | 0x87a4 | 0x79a4 | 0x44e |
GetTickCount | 0x0 | 0x408088 | 0x87a8 | 0x79a8 | 0x309 |
GetCurrentThreadId | 0x0 | 0x40808c | 0x87ac | 0x79ac | 0x21e |
GetCurrentProcessId | 0x0 | 0x408090 | 0x87b0 | 0x79b0 | 0x21a |
VirtualAlloc | 0x0 | 0x408094 | 0x87b4 | 0x79b4 | 0x5c8 |
LoadLibraryA | 0x0 | 0x408098 | 0x87b8 | 0x79b8 | 0x3c4 |
GetProcAddress | 0x0 | 0x40809c | 0x87bc | 0x79bc | 0x2b0 |
WinExec | 0x0 | 0x4080a0 | 0x87c0 | 0x79c0 | 0x601 |
WriteFile | 0x0 | 0x4080a4 | 0x87c4 | 0x79c4 | 0x614 |
GlobalReAlloc | 0x0 | 0x4080a8 | 0x87c8 | 0x79c8 | 0x33d |
GlobalSize | 0x0 | 0x4080ac | 0x87cc | 0x79cc | 0x33e |
CreateFileA | 0x0 | 0x4080b0 | 0x87d0 | 0x79d0 | 0xc5 |
SetFilePointer | 0x0 | 0x4080b4 | 0x87d4 | 0x79d4 | 0x523 |
ReadFile | 0x0 | 0x4080b8 | 0x87d8 | 0x79d8 | 0x474 |
CloseHandle | 0x0 | 0x4080bc | 0x87dc | 0x79dc | 0x88 |
GlobalAlloc | 0x0 | 0x4080c0 | 0x87e0 | 0x79e0 | 0x32f |
GlobalLock | 0x0 | 0x4080c4 | 0x87e4 | 0x79e4 | 0x33a |
GlobalUnlock | 0x0 | 0x4080c8 | 0x87e8 | 0x79e8 | 0x341 |
GlobalFree | 0x0 | 0x4080cc | 0x87ec | 0x79ec | 0x336 |
GetModuleHandleExA | 0x0 | 0x4080d0 | 0x87f0 | 0x79f0 | 0x278 |
InterlockedCompareExchange | 0x0 | 0x4080d4 | 0x87f4 | 0x79f4 | 0x369 |
GetSystemTimeAsFileTime | 0x0 | 0x4080d8 | 0x87f8 | 0x79f8 | 0x2eb |
USER32.dll (35)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
BeginPaint | 0x0 | 0x4081b4 | 0x88d4 | 0x7ad4 | 0xe |
EndDialog | 0x0 | 0x4081b8 | 0x88d8 | 0x7ad8 | 0xd3 |
PostQuitMessage | 0x0 | 0x4081bc | 0x88dc | 0x7adc | 0x220 |
CreateDialogParamA | 0x0 | 0x4081c0 | 0x88e0 | 0x7ae0 | 0x5c |
DefMDIChildProcA | 0x0 | 0x4081c4 | 0x88e4 | 0x7ae4 | 0x92 |
GetParent | 0x0 | 0x4081c8 | 0x88e8 | 0x7ae8 | 0x155 |
EnableMenuItem | 0x0 | 0x4081cc | 0x88ec | 0x7aec | 0xcf |
GetDlgItem | 0x0 | 0x4081d0 | 0x88f0 | 0x7af0 | 0x11f |
GetMenu | 0x0 | 0x4081d4 | 0x88f4 | 0x7af4 | 0x13c |
DialogBoxParamA | 0x0 | 0x4081d8 | 0x88f8 | 0x7af8 | 0xa5 |
CharLowerA | 0x0 | 0x4081dc | 0x88fc | 0x7afc | 0x29 |
DefFrameProcA | 0x0 | 0x4081e0 | 0x8900 | 0x7b00 | 0x90 |
CreateWindowExA | 0x0 | 0x4081e4 | 0x8904 | 0x7b04 | 0x67 |
WinHelpA | 0x0 | 0x4081e8 | 0x8908 | 0x7b08 | 0x2ff |
DestroyWindow | 0x0 | 0x4081ec | 0x890c | 0x7b0c | 0xa0 |
DispatchMessageA | 0x0 | 0x4081f0 | 0x8910 | 0x7b10 | 0xa8 |
TranslateMessage | 0x0 | 0x4081f4 | 0x8914 | 0x7b14 | 0x2d5 |
GetMessageA | 0x0 | 0x4081f8 | 0x8918 | 0x7b18 | 0x14a |
UpdateWindow | 0x0 | 0x4081fc | 0x891c | 0x7b1c | 0x2e9 |
ShowWindow | 0x0 | 0x408200 | 0x8920 | 0x7b20 | 0x2b8 |
RegisterClassA | 0x0 | 0x408204 | 0x8924 | 0x7b24 | 0x233 |
LoadCursorA | 0x0 | 0x408208 | 0x8928 | 0x7b28 | 0x1d2 |
LoadIconA | 0x0 | 0x40820c | 0x892c | 0x7b2c | 0x1d6 |
EndPaint | 0x0 | 0x408210 | 0x8930 | 0x7b30 | 0xd5 |
LoadStringA | 0x0 | 0x408214 | 0x8934 | 0x7b34 | 0x1e3 |
SetScrollPos | 0x0 | 0x408218 | 0x8938 | 0x7b38 | 0x294 |
SetScrollRange | 0x0 | 0x40821c | 0x893c | 0x7b3c | 0x295 |
GetClientRect | 0x0 | 0x408220 | 0x8940 | 0x7b40 | 0x10d |
wsprintfA | 0x0 | 0x408224 | 0x8944 | 0x7b44 | 0x307 |
SendDlgItemMessageA | 0x0 | 0x408228 | 0x8948 | 0x7b48 | 0x259 |
InvalidateRect | 0x0 | 0x40822c | 0x894c | 0x7b4c | 0x1aa |
SendMessageA | 0x0 | 0x408230 | 0x8950 | 0x7b50 | 0x25e |
GetDC | 0x0 | 0x408234 | 0x8954 | 0x7b54 | 0x11a |
ReleaseDC | 0x0 | 0x408238 | 0x8958 | 0x7b58 | 0x24c |
CharUpperA | 0x0 | 0x40823c | 0x895c | 0x7b5c | 0x37 |
GDI32.dll (21)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RealizePalette | 0x0 | 0x40800c | 0x872c | 0x792c | 0x243 |
SelectPalette | 0x0 | 0x408010 | 0x8730 | 0x7930 | 0x25f |
LineTo | 0x0 | 0x408014 | 0x8734 | 0x7934 | 0x21d |
MoveToEx | 0x0 | 0x408018 | 0x8738 | 0x7938 | 0x221 |
SaveDC | 0x0 | 0x40801c | 0x873c | 0x793c | 0x257 |
RestoreDC | 0x0 | 0x408020 | 0x8740 | 0x7940 | 0x250 |
SetWindowOrgEx | 0x0 | 0x408024 | 0x8744 | 0x7944 | 0x294 |
SetViewportExtEx | 0x0 | 0x408028 | 0x8748 | 0x7948 | 0x28f |
SelectObject | 0x0 | 0x40802c | 0x874c | 0x794c | 0x25e |
SetMapMode | 0x0 | 0x408030 | 0x8750 | 0x7950 | 0x27b |
Rectangle | 0x0 | 0x408034 | 0x8754 | 0x7954 | 0x246 |
CreatePen | 0x0 | 0x408038 | 0x8758 | 0x7958 | 0x49 |
DeleteDC | 0x0 | 0x40803c | 0x875c | 0x795c | 0xcd |
BitBlt | 0x0 | 0x408040 | 0x8760 | 0x7960 | 0x12 |
CreateCompatibleDC | 0x0 | 0x408044 | 0x8764 | 0x7964 | 0x2e |
SetROP2 | 0x0 | 0x408048 | 0x8768 | 0x7968 | 0x286 |
GetStockObject | 0x0 | 0x40804c | 0x876c | 0x796c | 0x1f4 |
CreateDIBitmap | 0x0 | 0x408050 | 0x8770 | 0x7970 | 0x34 |
SetWindowExtEx | 0x0 | 0x408054 | 0x8774 | 0x7974 | 0x293 |
DPtoLP | 0x0 | 0x408058 | 0x8778 | 0x7978 | 0x92 |
DeleteObject | 0x0 | 0x40805c | 0x877c | 0x797c | 0xd0 |
COMDLG32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetSaveFileNameA | 0x0 | 0x408000 | 0x8720 | 0x7920 | 0xd |
GetOpenFileNameA | 0x0 | 0x408004 | 0x8724 | 0x7924 | 0xb |
MSVCP90.dll (15)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
??0?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@PBD@Z | 0x0 | 0x4080e0 | 0x8800 | 0x7a00 | 0x176 |
??$?HDU?$char_traits@D@std@@V?$allocator@D@1@@std@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@0@ABV10@0@Z | 0x0 | 0x4080e4 | 0x8804 | 0x7a04 | 0x65 |
??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ | 0x0 | 0x4080e8 | 0x8808 | 0x7a08 | 0x25f |
?endl@std@@YAAAV?$basic_ostream@DU?$char_traits@D@std@@@1@AAV21@@Z | 0x0 | 0x4080ec | 0x880c | 0x7a0c | 0x7a4 |
?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A | 0x0 | 0x4080f0 | 0x8810 | 0x7a10 | 0x682 |
??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@P6AAAV01@AAV01@@Z@Z | 0x0 | 0x4080f4 | 0x8814 | 0x7a14 | 0x31d |
?length@?$char_traits@D@std@@SAIPBD@Z | 0x0 | 0x4080f8 | 0x8818 | 0x7a18 | 0x958 |
?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAEHD@Z | 0x0 | 0x4080fc | 0x881c | 0x7a1c | 0xb73 |
?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAEHPBDH@Z | 0x0 | 0x408100 | 0x8820 | 0x7a20 | 0xb76 |
?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QAEXH_N@Z | 0x0 | 0x408104 | 0x8824 | 0x7a24 | 0xb44 |
?uncaught_exception@std@@YA_NXZ | 0x0 | 0x408108 | 0x8828 | 0x7a28 | 0xbe4 |
?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEXXZ | 0x0 | 0x40810c | 0x882c | 0x7a2c | 0x57c |
?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV12@XZ | 0x0 | 0x408110 | 0x8830 | 0x7a30 | 0x821 |
?_Unlock@_Mutex@std@@QAEXXZ | 0x0 | 0x408114 | 0x8834 | 0x7a34 | 0x5d3 |
?_Lock@_Mutex@std@@QAEXXZ | 0x0 | 0x408118 | 0x8838 | 0x7a38 | 0x55a |
MSVCR90.dll (36)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
__setusermatherr | 0x0 | 0x408120 | 0x8840 | 0x7a40 | 0xe3 |
_configthreadlocale | 0x0 | 0x408124 | 0x8844 | 0x7a44 | 0x13c |
_initterm_e | 0x0 | 0x408128 | 0x8848 | 0x7a48 | 0x205 |
_adjust_fdiv | 0x0 | 0x40812c | 0x884c | 0x7a4c | 0x10b |
_acmdln | 0x0 | 0x408130 | 0x8850 | 0x7a50 | 0xfd |
exit | 0x0 | 0x408134 | 0x8854 | 0x7a54 | 0x4cc |
_ismbblead | 0x0 | 0x408138 | 0x8858 | 0x7a58 | 0x225 |
__p__commode | 0x0 | 0x40813c | 0x885c | 0x7a5c | 0xcb |
__p__fmode | 0x0 | 0x408140 | 0x8860 | 0x7a60 | 0xcf |
_encode_pointer | 0x0 | 0x408144 | 0x8864 | 0x7a64 | 0x16a |
__set_app_type | 0x0 | 0x408148 | 0x8868 | 0x7a68 | 0xe0 |
_crt_debugger_hook | 0x0 | 0x40814c | 0x886c | 0x7a6c | 0x14b |
?terminate@@YAXXZ | 0x0 | 0x408150 | 0x8870 | 0x7a70 | 0x43 |
_unlock | 0x0 | 0x408154 | 0x8874 | 0x7a74 | 0x3e6 |
__dllonexit | 0x0 | 0x408158 | 0x8878 | 0x7a78 | 0x96 |
_lock | 0x0 | 0x40815c | 0x887c | 0x7a7c | 0x276 |
_onexit | 0x0 | 0x408160 | 0x8880 | 0x7a80 | 0x31c |
_decode_pointer | 0x0 | 0x408164 | 0x8884 | 0x7a84 | 0x160 |
_except_handler4_common | 0x0 | 0x408168 | 0x8888 | 0x7a88 | 0x173 |
_invoke_watson | 0x0 | 0x40816c | 0x888c | 0x7a8c | 0x20b |
_controlfp_s | 0x0 | 0x408170 | 0x8890 | 0x7a90 | 0x13f |
_initterm | 0x0 | 0x408174 | 0x8894 | 0x7a94 | 0x204 |
memcpy | 0x0 | 0x408178 | 0x8898 | 0x7a98 | 0x526 |
strcmp | 0x0 | 0x40817c | 0x889c | 0x7a9c | 0x54f |
strlen | 0x0 | 0x408180 | 0x88a0 | 0x7aa0 | 0x557 |
strcpy | 0x0 | 0x408184 | 0x88a4 | 0x7aa4 | 0x551 |
memset | 0x0 | 0x408188 | 0x88a8 | 0x7aa8 | 0x52a |
strncpy | 0x0 | 0x40818c | 0x88ac | 0x7aac | 0x55b |
sprintf | 0x0 | 0x408190 | 0x88b0 | 0x7ab0 | 0x546 |
malloc | 0x0 | 0x408194 | 0x88b4 | 0x7ab4 | 0x51b |
__CxxFrameHandler3 | 0x0 | 0x408198 | 0x88b8 | 0x7ab8 | 0x73 |
_amsg_exit | 0x0 | 0x40819c | 0x88bc | 0x7abc | 0x115 |
__getmainargs | 0x0 | 0x4081a0 | 0x88c0 | 0x7ac0 | 0x9f |
_cexit | 0x0 | 0x4081a4 | 0x88c4 | 0x7ac4 | 0x12c |
_exit | 0x0 | 0x4081a8 | 0x88c8 | 0x7ac8 | 0x17c |
_XcptFilter | 0x0 | 0x4081ac | 0x88cc | 0x7acc | 0x66 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
buffer | 1 | 0x00CA0000 | 0x00CD0FFF | First Execution | 32-bit | 0x00CA0000 |
...
|
|||
buffer | 1 | 0x00E31000 | 0x00E329FF | First Execution | 32-bit | 0x00E327B0 |
...
|
|||
buffer | 1 | 0x00E70000 | 0x00EA2FFF | Marked Executable | 32-bit | - |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.EmotetU.Gen.vuW@i0qEqqoi |
Malicious
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
SodinokibiEncryptedFile | File encrypted by Sodinokibi Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\DisplayIcon.ico.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DHtmlHeader.html | Modified File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Strings.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Internet Explorer.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Key Management Service.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx.KLZUB | Dropped File | Binary |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-International%4Operational.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Known Folders API Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Store%4Operational.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Windows PowerShell.evtx.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\desktop.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log | Modified File | Stream |
Unknown
|
...
|
»
C:\Recovery\ReAgentOld.xml.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\LocalizedData.xml.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\SetupComplete.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.xml.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\LocalizedData.xml.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\eula.rtf.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.xml.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\LocalizedData.xml.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\LocalizedData.xml.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\LocalizedData.xml.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.xml.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\LocalizedData.xml.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\LocalizedData.xml.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\LocalizedData.xml.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf.KLZUB | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\Crypto\R3ADM3.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd.KLZUB | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd.KLZUB | Dropped File | Batch |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\preoobe.cmd | Modified File | Batch |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»