VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Dropper
|
Threat Names: |
Nemty
Generic.Ransom.Nemty.6CE9F6D3
Gen:Heur.Ransom.Imps.1
...
|
yjpgfqu.exe
Windows Exe (x86-32)
Created at 2020-02-19T13:20:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x40320c |
Size Of Code | 0x6400 |
Size Of Initialized Data | 0x2e800 |
Size Of Uninitialized Data | 0x400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-01-30 03:57:45+00:00 |
Version Information (10)
»
Comments | zxcssssse: hsdsds |
FileVersion | 51.9.0.0 |
LegalCopyright | qvscsd axqsc cxasd qsadacaa |
LegalTrademarks | - |
ProductName | - |
cxzcxzcxzc | - |
wqeasdasd | cxvcvxvcx |
xcvxcsadsad | - |
xvsadsad | qweasdsadsad |
zxcxzcxzcxzc |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x628f | 0x6400 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.44 |
.rdata | 0x408000 | 0x1354 | 0x1400 | 0x6800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.24 |
.data | 0x40a000 | 0x25518 | 0x600 | 0x7c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.05 |
.ndata | 0x430000 | 0x8000 | 0x0 | 0x0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x438000 | 0x7642 | 0x7800 | 0x8200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.53 |
Imports (7)
»
KERNEL32.dll (61)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetTempPathA | 0x0 | 0x408070 | 0x8644 | 0x6e44 | 0x1d5 |
GetFileSize | 0x0 | 0x408074 | 0x8648 | 0x6e48 | 0x163 |
GetModuleFileNameA | 0x0 | 0x408078 | 0x864c | 0x6e4c | 0x17d |
GetCurrentProcess | 0x0 | 0x40807c | 0x8650 | 0x6e50 | 0x142 |
CopyFileA | 0x0 | 0x408080 | 0x8654 | 0x6e54 | 0x43 |
ExitProcess | 0x0 | 0x408084 | 0x8658 | 0x6e58 | 0xb9 |
SetEnvironmentVariableA | 0x0 | 0x408088 | 0x865c | 0x6e5c | 0x313 |
Sleep | 0x0 | 0x40808c | 0x8660 | 0x6e60 | 0x356 |
GetTickCount | 0x0 | 0x408090 | 0x8664 | 0x6e64 | 0x1df |
GetCommandLineA | 0x0 | 0x408094 | 0x8668 | 0x6e68 | 0x110 |
lstrlenA | 0x0 | 0x408098 | 0x866c | 0x6e6c | 0x3cc |
GetVersion | 0x0 | 0x40809c | 0x8670 | 0x6e70 | 0x1e8 |
SetErrorMode | 0x0 | 0x4080a0 | 0x8674 | 0x6e74 | 0x315 |
lstrcpynA | 0x0 | 0x4080a4 | 0x8678 | 0x6e78 | 0x3c9 |
GetDiskFreeSpaceA | 0x0 | 0x4080a8 | 0x867c | 0x6e7c | 0x14d |
GlobalUnlock | 0x0 | 0x4080ac | 0x8680 | 0x6e80 | 0x20a |
GetWindowsDirectoryA | 0x0 | 0x4080b0 | 0x8684 | 0x6e84 | 0x1f3 |
SetCurrentDirectoryA | 0x0 | 0x4080b4 | 0x8688 | 0x6e88 | 0x30a |
GetLastError | 0x0 | 0x4080b8 | 0x868c | 0x6e8c | 0x171 |
CreateDirectoryA | 0x0 | 0x4080bc | 0x8690 | 0x6e90 | 0x4b |
CreateProcessA | 0x0 | 0x4080c0 | 0x8694 | 0x6e94 | 0x66 |
RemoveDirectoryA | 0x0 | 0x4080c4 | 0x8698 | 0x6e98 | 0x2c4 |
CreateFileA | 0x0 | 0x4080c8 | 0x869c | 0x6e9c | 0x53 |
GetTempFileNameA | 0x0 | 0x4080cc | 0x86a0 | 0x6ea0 | 0x1d3 |
ReadFile | 0x0 | 0x4080d0 | 0x86a4 | 0x6ea4 | 0x2b5 |
WriteFile | 0x0 | 0x4080d4 | 0x86a8 | 0x6ea8 | 0x3a4 |
lstrcpyA | 0x0 | 0x4080d8 | 0x86ac | 0x6eac | 0x3c6 |
MoveFileExA | 0x0 | 0x4080dc | 0x86b0 | 0x6eb0 | 0x26f |
lstrcatA | 0x0 | 0x4080e0 | 0x86b4 | 0x6eb4 | 0x3bd |
GetSystemDirectoryA | 0x0 | 0x4080e4 | 0x86b8 | 0x6eb8 | 0x1c1 |
GetProcAddress | 0x0 | 0x4080e8 | 0x86bc | 0x6ebc | 0x1a0 |
GetExitCodeProcess | 0x0 | 0x4080ec | 0x86c0 | 0x6ec0 | 0x15a |
WaitForSingleObject | 0x0 | 0x4080f0 | 0x86c4 | 0x6ec4 | 0x390 |
CompareFileTime | 0x0 | 0x4080f4 | 0x86c8 | 0x6ec8 | 0x39 |
SetFileAttributesA | 0x0 | 0x4080f8 | 0x86cc | 0x6ecc | 0x319 |
GetFileAttributesA | 0x0 | 0x4080fc | 0x86d0 | 0x6ed0 | 0x15e |
GetShortPathNameA | 0x0 | 0x408100 | 0x86d4 | 0x6ed4 | 0x1b5 |
MoveFileA | 0x0 | 0x408104 | 0x86d8 | 0x6ed8 | 0x26e |
GetFullPathNameA | 0x0 | 0x408108 | 0x86dc | 0x6edc | 0x169 |
SetFileTime | 0x0 | 0x40810c | 0x86e0 | 0x6ee0 | 0x31f |
SearchPathA | 0x0 | 0x408110 | 0x86e4 | 0x6ee4 | 0x2db |
CloseHandle | 0x0 | 0x408114 | 0x86e8 | 0x6ee8 | 0x34 |
lstrcmpiA | 0x0 | 0x408118 | 0x86ec | 0x6eec | 0x3c3 |
CreateThread | 0x0 | 0x40811c | 0x86f0 | 0x6ef0 | 0x6f |
GlobalLock | 0x0 | 0x408120 | 0x86f4 | 0x6ef4 | 0x203 |
lstrcmpA | 0x0 | 0x408124 | 0x86f8 | 0x6ef8 | 0x3c0 |
FindFirstFileA | 0x0 | 0x408128 | 0x86fc | 0x6efc | 0xd2 |
FindNextFileA | 0x0 | 0x40812c | 0x8700 | 0x6f00 | 0xdc |
DeleteFileA | 0x0 | 0x408130 | 0x8704 | 0x6f04 | 0x83 |
SetFilePointer | 0x0 | 0x408134 | 0x8708 | 0x6f08 | 0x31b |
GetPrivateProfileStringA | 0x0 | 0x408138 | 0x870c | 0x6f0c | 0x19c |
FindClose | 0x0 | 0x40813c | 0x8710 | 0x6f10 | 0xce |
MultiByteToWideChar | 0x0 | 0x408140 | 0x8714 | 0x6f14 | 0x275 |
FreeLibrary | 0x0 | 0x408144 | 0x8718 | 0x6f18 | 0xf8 |
MulDiv | 0x0 | 0x408148 | 0x871c | 0x6f1c | 0x274 |
WritePrivateProfileStringA | 0x0 | 0x40814c | 0x8720 | 0x6f20 | 0x3a9 |
LoadLibraryExA | 0x0 | 0x408150 | 0x8724 | 0x6f24 | 0x253 |
GetModuleHandleA | 0x0 | 0x408154 | 0x8728 | 0x6f28 | 0x17f |
GlobalAlloc | 0x0 | 0x408158 | 0x872c | 0x6f2c | 0x1f8 |
GlobalFree | 0x0 | 0x40815c | 0x8730 | 0x6f30 | 0x1ff |
ExpandEnvironmentStringsA | 0x0 | 0x408160 | 0x8734 | 0x6f34 | 0xbc |
USER32.dll (63)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ScreenToClient | 0x0 | 0x408184 | 0x8758 | 0x6f58 | 0x231 |
GetSystemMenu | 0x0 | 0x408188 | 0x875c | 0x6f5c | 0x15c |
SetClassLongA | 0x0 | 0x40818c | 0x8760 | 0x6f60 | 0x247 |
IsWindowEnabled | 0x0 | 0x408190 | 0x8764 | 0x6f64 | 0x1ae |
SetWindowPos | 0x0 | 0x408194 | 0x8768 | 0x6f68 | 0x283 |
GetSysColor | 0x0 | 0x408198 | 0x876c | 0x6f6c | 0x15a |
GetWindowLongA | 0x0 | 0x40819c | 0x8770 | 0x6f70 | 0x16e |
SetCursor | 0x0 | 0x4081a0 | 0x8774 | 0x6f74 | 0x24d |
LoadCursorA | 0x0 | 0x4081a4 | 0x8778 | 0x6f78 | 0x1ba |
CheckDlgButton | 0x0 | 0x4081a8 | 0x877c | 0x6f7c | 0x38 |
GetMessagePos | 0x0 | 0x4081ac | 0x8780 | 0x6f80 | 0x13c |
LoadBitmapA | 0x0 | 0x4081b0 | 0x8784 | 0x6f84 | 0x1b8 |
CallWindowProcA | 0x0 | 0x4081b4 | 0x8788 | 0x6f88 | 0x1b |
IsWindowVisible | 0x0 | 0x4081b8 | 0x878c | 0x6f8c | 0x1b1 |
CloseClipboard | 0x0 | 0x4081bc | 0x8790 | 0x6f90 | 0x42 |
SetClipboardData | 0x0 | 0x4081c0 | 0x8794 | 0x6f94 | 0x24a |
EmptyClipboard | 0x0 | 0x4081c4 | 0x8798 | 0x6f98 | 0xc1 |
PostQuitMessage | 0x0 | 0x4081c8 | 0x879c | 0x6f9c | 0x204 |
GetWindowRect | 0x0 | 0x4081cc | 0x87a0 | 0x6fa0 | 0x174 |
EnableMenuItem | 0x0 | 0x4081d0 | 0x87a4 | 0x6fa4 | 0xc2 |
CreatePopupMenu | 0x0 | 0x4081d4 | 0x87a8 | 0x6fa8 | 0x5e |
GetSystemMetrics | 0x0 | 0x4081d8 | 0x87ac | 0x6fac | 0x15d |
SetDlgItemTextA | 0x0 | 0x4081dc | 0x87b0 | 0x6fb0 | 0x253 |
GetDlgItemTextA | 0x0 | 0x4081e0 | 0x87b4 | 0x6fb4 | 0x113 |
MessageBoxIndirectA | 0x0 | 0x4081e4 | 0x87b8 | 0x6fb8 | 0x1e2 |
CharPrevA | 0x0 | 0x4081e8 | 0x87bc | 0x6fbc | 0x2d |
DispatchMessageA | 0x0 | 0x4081ec | 0x87c0 | 0x6fc0 | 0xa1 |
PeekMessageA | 0x0 | 0x4081f0 | 0x87c4 | 0x6fc4 | 0x200 |
ReleaseDC | 0x0 | 0x4081f4 | 0x87c8 | 0x6fc8 | 0x22a |
EnableWindow | 0x0 | 0x4081f8 | 0x87cc | 0x6fcc | 0xc4 |
InvalidateRect | 0x0 | 0x4081fc | 0x87d0 | 0x6fd0 | 0x193 |
SendMessageA | 0x0 | 0x408200 | 0x87d4 | 0x6fd4 | 0x23b |
DefWindowProcA | 0x0 | 0x408204 | 0x87d8 | 0x6fd8 | 0x8e |
BeginPaint | 0x0 | 0x408208 | 0x87dc | 0x6fdc | 0xd |
GetClientRect | 0x0 | 0x40820c | 0x87e0 | 0x6fe0 | 0xff |
FillRect | 0x0 | 0x408210 | 0x87e4 | 0x6fe4 | 0xe2 |
DrawTextA | 0x0 | 0x408214 | 0x87e8 | 0x6fe8 | 0xbc |
EndDialog | 0x0 | 0x408218 | 0x87ec | 0x6fec | 0xc6 |
RegisterClassA | 0x0 | 0x40821c | 0x87f0 | 0x6ff0 | 0x216 |
SystemParametersInfoA | 0x0 | 0x408220 | 0x87f4 | 0x6ff4 | 0x299 |
CreateWindowExA | 0x0 | 0x408224 | 0x87f8 | 0x6ff8 | 0x60 |
GetClassInfoA | 0x0 | 0x408228 | 0x87fc | 0x6ffc | 0xf6 |
DialogBoxParamA | 0x0 | 0x40822c | 0x8800 | 0x7000 | 0x9e |
CharNextA | 0x0 | 0x408230 | 0x8804 | 0x7004 | 0x2a |
ExitWindowsEx | 0x0 | 0x408234 | 0x8808 | 0x7008 | 0xe1 |
GetDC | 0x0 | 0x408238 | 0x880c | 0x700c | 0x10c |
CreateDialogParamA | 0x0 | 0x40823c | 0x8810 | 0x7010 | 0x55 |
SetTimer | 0x0 | 0x408240 | 0x8814 | 0x7014 | 0x27a |
GetDlgItem | 0x0 | 0x408244 | 0x8818 | 0x7018 | 0x111 |
SetWindowLongA | 0x0 | 0x408248 | 0x881c | 0x701c | 0x280 |
SetForegroundWindow | 0x0 | 0x40824c | 0x8820 | 0x7020 | 0x257 |
LoadImageA | 0x0 | 0x408250 | 0x8824 | 0x7024 | 0x1c0 |
IsWindow | 0x0 | 0x408254 | 0x8828 | 0x7028 | 0x1ad |
SendMessageTimeoutA | 0x0 | 0x408258 | 0x882c | 0x702c | 0x23e |
FindWindowExA | 0x0 | 0x40825c | 0x8830 | 0x7030 | 0xe4 |
OpenClipboard | 0x0 | 0x408260 | 0x8834 | 0x7034 | 0x1f6 |
TrackPopupMenu | 0x0 | 0x408264 | 0x8838 | 0x7038 | 0x2a4 |
AppendMenuA | 0x0 | 0x408268 | 0x883c | 0x703c | 0x8 |
EndPaint | 0x0 | 0x40826c | 0x8840 | 0x7040 | 0xc8 |
DestroyWindow | 0x0 | 0x408270 | 0x8844 | 0x7044 | 0x99 |
wsprintfA | 0x0 | 0x408274 | 0x8848 | 0x7048 | 0x2d7 |
ShowWindow | 0x0 | 0x408278 | 0x884c | 0x704c | 0x292 |
SetWindowTextA | 0x0 | 0x40827c | 0x8850 | 0x7050 | 0x286 |
GDI32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SelectObject | 0x0 | 0x40804c | 0x8620 | 0x6e20 | 0x20e |
SetBkMode | 0x0 | 0x408050 | 0x8624 | 0x6e24 | 0x216 |
CreateFontIndirectA | 0x0 | 0x408054 | 0x8628 | 0x6e28 | 0x3a |
SetTextColor | 0x0 | 0x408058 | 0x862c | 0x6e2c | 0x23c |
DeleteObject | 0x0 | 0x40805c | 0x8630 | 0x6e30 | 0x8f |
GetDeviceCaps | 0x0 | 0x408060 | 0x8634 | 0x6e34 | 0x16b |
CreateBrushIndirect | 0x0 | 0x408064 | 0x8638 | 0x6e38 | 0x29 |
SetBkColor | 0x0 | 0x408068 | 0x863c | 0x6e3c | 0x215 |
SHELL32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderLocation | 0x0 | 0x408168 | 0x873c | 0x6f3c | 0xc3 |
ShellExecuteExA | 0x0 | 0x40816c | 0x8740 | 0x6f40 | 0x109 |
SHGetPathFromIDListA | 0x0 | 0x408170 | 0x8744 | 0x6f44 | 0xbc |
SHBrowseForFolderA | 0x0 | 0x408174 | 0x8748 | 0x6f48 | 0x79 |
SHGetFileInfoA | 0x0 | 0x408178 | 0x874c | 0x6f4c | 0xac |
SHFileOperationA | 0x0 | 0x40817c | 0x8750 | 0x6f50 | 0x9a |
ADVAPI32.dll (13)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
AdjustTokenPrivileges | 0x0 | 0x408000 | 0x85d4 | 0x6dd4 | 0x1c |
RegCreateKeyExA | 0x0 | 0x408004 | 0x85d8 | 0x6dd8 | 0x1d1 |
RegOpenKeyExA | 0x0 | 0x408008 | 0x85dc | 0x6ddc | 0x1ec |
SetFileSecurityA | 0x0 | 0x40800c | 0x85e0 | 0x6de0 | 0x22e |
OpenProcessToken | 0x0 | 0x408010 | 0x85e4 | 0x6de4 | 0x1ac |
LookupPrivilegeValueA | 0x0 | 0x408014 | 0x85e8 | 0x6de8 | 0x14f |
RegEnumValueA | 0x0 | 0x408018 | 0x85ec | 0x6dec | 0x1e1 |
RegDeleteKeyA | 0x0 | 0x40801c | 0x85f0 | 0x6df0 | 0x1d4 |
RegDeleteValueA | 0x0 | 0x408020 | 0x85f4 | 0x6df4 | 0x1d8 |
RegCloseKey | 0x0 | 0x408024 | 0x85f8 | 0x6df8 | 0x1cb |
RegSetValueExA | 0x0 | 0x408028 | 0x85fc | 0x6dfc | 0x204 |
RegQueryValueExA | 0x0 | 0x40802c | 0x8600 | 0x6e00 | 0x1f7 |
RegEnumKeyA | 0x0 | 0x408030 | 0x8604 | 0x6e04 | 0x1dd |
COMCTL32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ImageList_Create | 0x0 | 0x408038 | 0x860c | 0x6e0c | 0x37 |
ImageList_AddMasked | 0x0 | 0x40803c | 0x8610 | 0x6e10 | 0x34 |
ImageList_Destroy | 0x0 | 0x408040 | 0x8614 | 0x6e14 | 0x38 |
(by ordinal) | 0x11 | 0x408044 | 0x8618 | 0x6e18 | - |
ole32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
OleUninitialize | 0x0 | 0x408284 | 0x8858 | 0x7058 | 0x105 |
OleInitialize | 0x0 | 0x408288 | 0x885c | 0x705c | 0xee |
CoTaskMemFree | 0x0 | 0x40828c | 0x8860 | 0x7060 | 0x65 |
CoCreateInstance | 0x0 | 0x408290 | 0x8864 | 0x7064 | 0x10 |
Memory Dumps (24)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
yjpgfqu.exe | 1 | 0x00400000 | 0x0043FFFF | Relevant Image | 32-bit | 0x00406338 |
...
|
|||
system.dll | 1 | 0x73F00000 | 0x73F05FFF | First Execution | 32-bit | 0x73F016DF |
...
|
|||
buffer | 1 | 0x02020000 | 0x0203CFFF | First Execution | 32-bit | 0x020389F1 |
...
|
|||
buffer | 1 | 0x02020000 | 0x0203CFFF | Content Changed | 32-bit | 0x02039A4E |
...
|
|||
buffer | 1 | 0x025B0000 | 0x025C9FFF | Content Changed | 32-bit | - |
...
|
|||
buffer | 2 | 0x00400000 | 0x00419FFF | First Execution | 32-bit | 0x0040A953 |
...
|
|||
buffer | 1 | 0x02040000 | 0x02057FFF | Image In Buffer | 32-bit | - |
...
|
|||
yjpgfqu.exe | 1 | 0x00400000 | 0x0043FFFF | Process Termination | 32-bit | - |
...
|
|||
buffer | 2 | 0x00400000 | 0x00419FFF | Content Changed | 32-bit | 0x0040D222 |
...
|
|||
buffer | 2 | 0x00400000 | 0x00419FFF | Content Changed | 32-bit | 0x0040E6B9 |
...
|
|||
buffer | 2 | 0x00400000 | 0x00419FFF | Content Changed | 32-bit | 0x004083EA |
...
|
|||
buffer | 2 | 0x00400000 | 0x00419FFF | Content Changed | 32-bit | 0x0040FC46 |
...
|
|||
buffer | 2 | 0x00400000 | 0x00419FFF | Content Changed | 32-bit | 0x00403BD0 |
...
|
|||
buffer | 2 | 0x00400000 | 0x00419FFF | Content Changed | 32-bit | 0x00406F10 |
...
|
|||
buffer | 2 | 0x00400000 | 0x00419FFF | Content Changed | 32-bit | 0x00407000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x00419FFF | Content Changed | 32-bit | 0x00405064 |
...
|
|||
buffer | 2 | 0x00400000 | 0x00419FFF | Content Changed | 32-bit | 0x00407067 |
...
|
|||
buffer | 2 | 0x00400000 | 0x00419FFF | Content Changed | 32-bit | 0x0040EC7C |
...
|
|||
buffer | 2 | 0x00400000 | 0x00419FFF | Content Changed | 32-bit | 0x00406A3D |
...
|
|||
buffer | 2 | 0x00400000 | 0x00419FFF | Content Changed | 32-bit | 0x004091C3 |
...
|
|||
buffer | 2 | 0x00400000 | 0x00419FFF | Content Changed | 32-bit | 0x00402000 |
...
|
|||
buffer | 2 | 0x00400000 | 0x00419FFF | Content Changed | 32-bit | 0x00402E6A |
...
|
|||
buffer | 2 | 0x00400000 | 0x00419FFF | Content Changed | 32-bit | 0x0040FFFB |
...
|
|||
buffer | 2 | 0x00400000 | 0x00419FFF | Content Changed | 32-bit | 0x0040D2B1 |
...
|
C:\Users\FD1HVy\AppData\Local\Temp\nszB1AE.tmp\System.dll | Dropped File | Binary |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
PE Information
»
Image Base | 0x10000000 |
Entry Point | 0x100028e5 |
Size Of Code | 0x2000 |
Size Of Initialized Data | 0xa00 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-01-30 03:57:02+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x10001000 | 0x1f4f | 0x2000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.42 |
.rdata | 0x10003000 | 0x363 | 0x400 | 0x2400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.96 |
.data | 0x10004000 | 0x68 | 0x200 | 0x2800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.35 |
.reloc | 0x10005000 | 0x27c | 0x400 | 0x2a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 3.92 |
Imports (3)
»
KERNEL32.dll (16)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MultiByteToWideChar | 0x0 | 0x10003000 | 0x30fc | 0x24fc | 0x275 |
GlobalFree | 0x0 | 0x10003004 | 0x3100 | 0x2500 | 0x1ff |
GlobalSize | 0x0 | 0x10003008 | 0x3104 | 0x2504 | 0x207 |
lstrcpynA | 0x0 | 0x1000300c | 0x3108 | 0x2508 | 0x3c9 |
lstrcpyA | 0x0 | 0x10003010 | 0x310c | 0x250c | 0x3c6 |
GetProcAddress | 0x0 | 0x10003014 | 0x3110 | 0x2510 | 0x1a0 |
VirtualFree | 0x0 | 0x10003018 | 0x3114 | 0x2514 | 0x383 |
FreeLibrary | 0x0 | 0x1000301c | 0x3118 | 0x2518 | 0xf8 |
lstrlenA | 0x0 | 0x10003020 | 0x311c | 0x251c | 0x3cc |
LoadLibraryA | 0x0 | 0x10003024 | 0x3120 | 0x2520 | 0x252 |
GetModuleHandleA | 0x0 | 0x10003028 | 0x3124 | 0x2524 | 0x17f |
GlobalAlloc | 0x0 | 0x1000302c | 0x3128 | 0x2528 | 0x1f8 |
WideCharToMultiByte | 0x0 | 0x10003030 | 0x312c | 0x252c | 0x394 |
VirtualAlloc | 0x0 | 0x10003034 | 0x3130 | 0x2530 | 0x381 |
VirtualProtect | 0x0 | 0x10003038 | 0x3134 | 0x2534 | 0x386 |
GetLastError | 0x0 | 0x1000303c | 0x3138 | 0x2538 | 0x171 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
wsprintfA | 0x0 | 0x10003044 | 0x3140 | 0x2540 | 0x2d7 |
ole32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StringFromGUID2 | 0x0 | 0x1000304c | 0x3148 | 0x2548 | 0x135 |
CLSIDFromString | 0x0 | 0x10003050 | 0x314c | 0x254c | 0x8 |
Exports (8)
»
Api name | EAT Address | Ordinal |
---|---|---|
Alloc | 0x1000 | 0x1 |
Call | 0x16df | 0x2 |
Copy | 0x1058 | 0x3 |
Free | 0x15d5 | 0x4 |
Get | 0x163c | 0x5 |
Int64Op | 0x183b | 0x6 |
Store | 0x10e0 | 0x7 |
StrAlloc | 0x103d | 0x8 |
C:\Users\FD1HVy\AppData\Local\Temp\__PSScriptPolicyTest_movddtf0.vpl.ps1 | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
c:\users\fd1hvy\appdata\local\microsoft\windows\inetcache\ie\5alfeguz\countryname[1].txt | Downloaded File | Text |
Whitelisted
|
...
|
»
C:/$WINRE_BACKUP_PARTITION.MARKER.NEMTY_D73IOGW | Dropped File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1025\eula.rtf.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1025\LocalizedData.xml.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1028\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1029\eula.rtf.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1029\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1030\LocalizedData.xml.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1031\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1031\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1032\eula.rtf.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1032\LocalizedData.xml.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1033\eula.rtf.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1035\eula.rtf.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1035\LocalizedData.xml.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1036\eula.rtf.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1036\LocalizedData.xml.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1037\eula.rtf.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1037\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1038\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1038\LocalizedData.xml.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1040\LocalizedData.xml.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1041\eula.rtf.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1041\LocalizedData.xml.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1042\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1042\LocalizedData.xml.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1043\eula.rtf.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1043\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1044\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1044\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1045\eula.rtf.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1045\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1046\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1046\LocalizedData.xml.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1049\eula.rtf.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1049\LocalizedData.xml.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1053\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1053\LocalizedData.xml.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1055\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1055\LocalizedData.xml.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\2052\eula.rtf.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\2052\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\2070\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\2070\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\3076\eula.rtf.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\3076\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\3082\eula.rtf.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\3082\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\DHtmlHeader.html.NEMTY_D73IOGW | Dropped File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212\DisplayIcon.ico.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Extended\Parameterinfo.xml.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Extended\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Graphics\Print.ico.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Graphics\Rotate1.ico.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Graphics\Rotate2.ico.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Graphics\Rotate4.ico.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Graphics\Rotate5.ico | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Graphics\Rotate6.ico.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Graphics\Rotate7.ico | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Graphics\Rotate8.ico.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Graphics\Save.ico | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Graphics\Setup.ico.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Graphics\SysReqMet.ico | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Graphics\SysReqNotMet.ico | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Graphics\warn.ico.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\header.bmp.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\netfx_Core.mzz | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\netfx_Core_x64.msi.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\netfx_Core_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\netfx_Extended.mzz | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\netfx_Extended_x64.msi | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\netfx_Extended_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\ParameterInfo.xml.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\RGB9RAST_x64.msi | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\SetupUi.xsd.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\SplashScreen.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Strings.xml.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu | Modified File | Stream |
Unknown
|
...
|
»
C:/Boot\BOOTSTAT.DAT.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\HardwareEvents.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx | Modified File | Binary |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-AppReadiness%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx | Modified File | Binary |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Bits-Client%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx.NEMTY_D73IOGW | Dropped File | Binary |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Known Folders API Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-LiveId%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-MUI%4Admin.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-MUI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-NCSI%4Operational.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Ntfs%4Operational.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Ntfs%4WHC.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-SettingSync%4Operational.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Shell-Core%4Operational.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-SMBClient%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-SmbClient%4Security.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-SMBServer%4Audit.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-SMBServer%4Operational.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-SMBServer%4Security.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-User Profile Service%4Operational.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:/Logs\Microsoft-Windows-Windows Defender%4Operational.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\746433757 | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-1051304884-625712362-2192934891-1000\518e2bc94bc324e5e6f82437175ae1af_33d770d0-06bc-47c5-8714-222cdac43a71 | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\microsoft\windows\inetcache\ie\5alfeguz\raw[1].htm | Dropped File | Text |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-1051304884-625712362-2192934891-1000\650860e5119ec19a8de142e32f03c712_33d770d0-06bc-47c5-8714-222cdac43a71 | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-1051304884-625712362-2192934891-1000\650860e5119ec19a8de142e32f03c712_33d770d0-06bc-47c5-8714-222cdac43a71 | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-1051304884-625712362-2192934891-1000\94a9cdfb09e37d01f75d09c2c4488906_33d770d0-06bc-47c5-8714-222cdac43a71 | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212\Client\NEMTY_D73IOGW-DECRYPT.txt | Dropped File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212\1028\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\1033\LocalizedData.xml.NEMTY_D73IOGW | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\Client\Parameterinfo.xml.NEMTY_D73IOGW | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\Client\UiInfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\Graphics\Rotate3.ico.NEMTY_D73IOGW | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\Graphics\stop.ico.NEMTY_D73IOGW | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\RGB9Rast_x86.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\UiInfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212\watermark.bmp.NEMTY_D73IOGW | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Boot\BCD.LOG1.NEMTY_D73IOGW | Dropped File | Text |
Not Queried
|
...
|
»
C:/Logs\Key Management Service.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-AppReadiness%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-International%4Operational.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-SettingSync%4Debug.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-Store%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-TWinUI%4Operational.evtx.NEMTY_D73IOGW | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\nszB1AE.tmp | Dropped File | Unknown |
Not Queried
|
...
|
»