VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan |
zzbdrimp2939.exe
Windows Exe (x86-32)
Created at 2019-03-23T10:12:00
Remarks
(0x200001b): The maximum number of file reputation requests per analysis (20) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-03-12 20:57 (UTC+1) |
Last Seen | 2019-03-22 02:01 (UTC+1) |
Names | Win32.Trojan.Lockergoga |
Families | Lockergoga |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x499bcb |
Size Of Code | 0xe4200 |
Size Of Initialized Data | 0x4de00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-03-09 17:50:30+00:00 |
Version Information (8)
»
CompanyName | ALISA LTD |
FileDescription | Background Tasks Host |
FileVersion | 1.4.4.0 |
InternalName | zzbdrimp |
LegalCopyright | Copyright (C) ALISA LTD 2019 |
OriginalFilename | zzbdrimp |
ProductName | Service zzbdrimp |
ProductVersion | 1.4.4.0 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xe4122 | 0xe4200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.66 |
.rdata | 0x4e6000 | 0x33f9a | 0x34000 | 0xe4600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.01 |
.data | 0x51a000 | 0xb6dc | 0x9000 | 0x118600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.91 |
.rsrc | 0x526000 | 0x508 | 0x600 | 0x121600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.72 |
.reloc | 0x527000 | 0xdfd0 | 0xe000 | 0x121c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.56 |
Imports (6)
»
SHLWAPI.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathIsNetworkPathA | 0x0 | 0x4e62c0 | 0x119188 | 0x117788 | 0x60 |
KERNEL32.dll (157)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
OutputDebugStringA | 0x0 | 0x4e603c | 0x118f04 | 0x117504 | 0x389 |
InterlockedDecrement | 0x0 | 0x4e6040 | 0x118f08 | 0x117508 | 0x2eb |
TerminateProcess | 0x0 | 0x4e6044 | 0x118f0c | 0x11750c | 0x4c0 |
WaitForSingleObject | 0x0 | 0x4e6048 | 0x118f10 | 0x117510 | 0x4f9 |
GetCurrentThreadId | 0x0 | 0x4e604c | 0x118f14 | 0x117514 | 0x1c5 |
GetSystemDirectoryW | 0x0 | 0x4e6050 | 0x118f18 | 0x117518 | 0x270 |
FreeEnvironmentStringsW | 0x0 | 0x4e6054 | 0x118f1c | 0x11751c | 0x161 |
DuplicateHandle | 0x0 | 0x4e6058 | 0x118f20 | 0x117520 | 0xe8 |
GetModuleHandleA | 0x0 | 0x4e605c | 0x118f24 | 0x117524 | 0x215 |
GetLogicalDriveStringsW | 0x0 | 0x4e6060 | 0x118f28 | 0x117528 | 0x208 |
MultiByteToWideChar | 0x0 | 0x4e6064 | 0x118f2c | 0x11752c | 0x367 |
Sleep | 0x0 | 0x4e6068 | 0x118f30 | 0x117530 | 0x4b2 |
FormatMessageW | 0x0 | 0x4e606c | 0x118f34 | 0x117534 | 0x15e |
Wow64RevertWow64FsRedirection | 0x0 | 0x4e6070 | 0x118f38 | 0x117538 | 0x517 |
GetLastError | 0x0 | 0x4e6074 | 0x118f3c | 0x11753c | 0x202 |
SetEvent | 0x0 | 0x4e6078 | 0x118f40 | 0x117540 | 0x459 |
TlsAlloc | 0x0 | 0x4e607c | 0x118f44 | 0x117544 | 0x4c5 |
WaitForSingleObjectEx | 0x0 | 0x4e6080 | 0x118f48 | 0x117548 | 0x4fa |
CloseHandle | 0x0 | 0x4e6084 | 0x118f4c | 0x11754c | 0x52 |
GetSystemInfo | 0x0 | 0x4e6088 | 0x118f50 | 0x117550 | 0x273 |
GetWindowsDirectoryW | 0x0 | 0x4e608c | 0x118f54 | 0x117554 | 0x2af |
GetProcAddress | 0x0 | 0x4e6090 | 0x118f58 | 0x117558 | 0x245 |
LocalFree | 0x0 | 0x4e6094 | 0x118f5c | 0x11755c | 0x348 |
GetCurrentProcessId | 0x0 | 0x4e6098 | 0x118f60 | 0x117560 | 0x1c1 |
CreateProcessW | 0x0 | 0x4e609c | 0x118f64 | 0x117564 | 0xa8 |
WideCharToMultiByte | 0x0 | 0x4e60a0 | 0x118f68 | 0x117568 | 0x511 |
CreateProcessA | 0x0 | 0x4e60a4 | 0x118f6c | 0x11756c | 0xa4 |
InterlockedIncrement | 0x0 | 0x4e60a8 | 0x118f70 | 0x117570 | 0x2ef |
TlsFree | 0x0 | 0x4e60ac | 0x118f74 | 0x117574 | 0x4c6 |
FormatMessageA | 0x0 | 0x4e60b0 | 0x118f78 | 0x117578 | 0x15d |
CreateEventA | 0x0 | 0x4e60b4 | 0x118f7c | 0x11757c | 0x82 |
GetEnvironmentStringsW | 0x0 | 0x4e60b8 | 0x118f80 | 0x117580 | 0x1da |
GetDriveTypeW | 0x0 | 0x4e60bc | 0x118f84 | 0x117584 | 0x1d3 |
GetExitCodeProcess | 0x0 | 0x4e60c0 | 0x118f88 | 0x117588 | 0x1df |
ReadFile | 0x0 | 0x4e60c4 | 0x118f8c | 0x11758c | 0x3c0 |
GetFileAttributesExW | 0x0 | 0x4e60c8 | 0x118f90 | 0x117590 | 0x1e7 |
FreeLibrary | 0x0 | 0x4e60cc | 0x118f94 | 0x117594 | 0x162 |
LoadLibraryExW | 0x0 | 0x4e60d0 | 0x118f98 | 0x117598 | 0x33e |
CreateMutexA | 0x0 | 0x4e60d4 | 0x118f9c | 0x11759c | 0x9b |
ReleaseMutex | 0x0 | 0x4e60d8 | 0x118fa0 | 0x1175a0 | 0x3fa |
Wow64DisableWow64FsRedirection | 0x0 | 0x4e60dc | 0x118fa4 | 0x1175a4 | 0x513 |
HeapFree | 0x0 | 0x4e60e0 | 0x118fa8 | 0x1175a8 | 0x2cf |
OpenProcess | 0x0 | 0x4e60e4 | 0x118fac | 0x1175ac | 0x380 |
HeapAlloc | 0x0 | 0x4e60e8 | 0x118fb0 | 0x1175b0 | 0x2cb |
GetProcessHeap | 0x0 | 0x4e60ec | 0x118fb4 | 0x1175b4 | 0x24a |
GetEnvironmentVariableW | 0x0 | 0x4e60f0 | 0x118fb8 | 0x1175b8 | 0x1dc |
GetCurrentDirectoryW | 0x0 | 0x4e60f4 | 0x118fbc | 0x1175bc | 0x1bf |
CreateFileW | 0x0 | 0x4e60f8 | 0x118fc0 | 0x1175c0 | 0x8f |
DeleteFileW | 0x0 | 0x4e60fc | 0x118fc4 | 0x1175c4 | 0xd6 |
FindClose | 0x0 | 0x4e6100 | 0x118fc8 | 0x1175c8 | 0x12e |
FindFirstFileW | 0x0 | 0x4e6104 | 0x118fcc | 0x1175cc | 0x139 |
FindNextFileW | 0x0 | 0x4e6108 | 0x118fd0 | 0x1175d0 | 0x145 |
GetFileAttributesW | 0x0 | 0x4e610c | 0x118fd4 | 0x1175d4 | 0x1ea |
RemoveDirectoryW | 0x0 | 0x4e6110 | 0x118fd8 | 0x1175d8 | 0x403 |
SetEndOfFile | 0x0 | 0x4e6114 | 0x118fdc | 0x1175dc | 0x453 |
SetFileAttributesW | 0x0 | 0x4e6118 | 0x118fe0 | 0x1175e0 | 0x461 |
SetFilePointerEx | 0x0 | 0x4e611c | 0x118fe4 | 0x1175e4 | 0x467 |
DeviceIoControl | 0x0 | 0x4e6120 | 0x118fe8 | 0x1175e8 | 0xdd |
GetModuleHandleW | 0x0 | 0x4e6124 | 0x118fec | 0x1175ec | 0x218 |
MoveFileExW | 0x0 | 0x4e6128 | 0x118ff0 | 0x1175f0 | 0x360 |
SetLastError | 0x0 | 0x4e612c | 0x118ff4 | 0x1175f4 | 0x473 |
GetCurrentThread | 0x0 | 0x4e6130 | 0x118ff8 | 0x1175f8 | 0x1c4 |
GetThreadTimes | 0x0 | 0x4e6134 | 0x118ffc | 0x1175fc | 0x291 |
QueryPerformanceCounter | 0x0 | 0x4e6138 | 0x119000 | 0x117600 | 0x3a7 |
QueryPerformanceFrequency | 0x0 | 0x4e613c | 0x119004 | 0x117604 | 0x3a8 |
SetStdHandle | 0x0 | 0x4e6140 | 0x119008 | 0x117608 | 0x487 |
FindNextFileA | 0x0 | 0x4e6144 | 0x11900c | 0x11760c | 0x143 |
FindFirstFileExA | 0x0 | 0x4e6148 | 0x119010 | 0x117610 | 0x133 |
GetTimeZoneInformation | 0x0 | 0x4e614c | 0x119014 | 0x117614 | 0x298 |
HeapSize | 0x0 | 0x4e6150 | 0x119018 | 0x117618 | 0x2d4 |
ReleaseSemaphore | 0x0 | 0x4e6154 | 0x11901c | 0x11761c | 0x3fe |
GetCurrentProcess | 0x0 | 0x4e6158 | 0x119020 | 0x117620 | 0x1c0 |
GetCommandLineW | 0x0 | 0x4e615c | 0x119024 | 0x117624 | 0x187 |
MapViewOfFileEx | 0x0 | 0x4e6160 | 0x119028 | 0x117628 | 0x358 |
GetTickCount | 0x0 | 0x4e6164 | 0x11902c | 0x11762c | 0x293 |
OpenFileMappingA | 0x0 | 0x4e6168 | 0x119030 | 0x117630 | 0x378 |
CreateFileMappingA | 0x0 | 0x4e616c | 0x119034 | 0x117634 | 0x89 |
SwitchToThread | 0x0 | 0x4e6170 | 0x119038 | 0x117638 | 0x4bc |
UnmapViewOfFile | 0x0 | 0x4e6174 | 0x11903c | 0x11763c | 0x4d6 |
InterlockedExchange | 0x0 | 0x4e6178 | 0x119040 | 0x117640 | 0x2ec |
AreFileApisANSI | 0x0 | 0x4e617c | 0x119044 | 0x117644 | 0x15 |
WriteConsoleW | 0x0 | 0x4e6180 | 0x119048 | 0x117648 | 0x524 |
OpenMutexA | 0x0 | 0x4e6184 | 0x11904c | 0x11764c | 0x37c |
SetEnvironmentVariableA | 0x0 | 0x4e6188 | 0x119050 | 0x117650 | 0x456 |
GetOEMCP | 0x0 | 0x4e618c | 0x119054 | 0x117654 | 0x237 |
GetExitCodeThread | 0x0 | 0x4e6190 | 0x119058 | 0x117658 | 0x1e0 |
GetNativeSystemInfo | 0x0 | 0x4e6194 | 0x11905c | 0x11765c | 0x225 |
GetStringTypeW | 0x0 | 0x4e6198 | 0x119060 | 0x117660 | 0x269 |
EnterCriticalSection | 0x0 | 0x4e619c | 0x119064 | 0x117664 | 0xee |
LeaveCriticalSection | 0x0 | 0x4e61a0 | 0x119068 | 0x117668 | 0x339 |
TryEnterCriticalSection | 0x0 | 0x4e61a4 | 0x11906c | 0x11766c | 0x4ce |
DeleteCriticalSection | 0x0 | 0x4e61a8 | 0x119070 | 0x117670 | 0xd1 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4e61ac | 0x119074 | 0x117674 | 0x2e3 |
CreateEventW | 0x0 | 0x4e61b0 | 0x119078 | 0x117678 | 0x85 |
TlsGetValue | 0x0 | 0x4e61b4 | 0x11907c | 0x11767c | 0x4c7 |
TlsSetValue | 0x0 | 0x4e61b8 | 0x119080 | 0x117680 | 0x4c8 |
GetSystemTimeAsFileTime | 0x0 | 0x4e61bc | 0x119084 | 0x117684 | 0x279 |
EncodePointer | 0x0 | 0x4e61c0 | 0x119088 | 0x117688 | 0xea |
DecodePointer | 0x0 | 0x4e61c4 | 0x11908c | 0x11768c | 0xca |
GetCPInfo | 0x0 | 0x4e61c8 | 0x119090 | 0x117690 | 0x172 |
CompareStringW | 0x0 | 0x4e61cc | 0x119094 | 0x117694 | 0x64 |
LCMapStringW | 0x0 | 0x4e61d0 | 0x119098 | 0x117698 | 0x32d |
GetLocaleInfoW | 0x0 | 0x4e61d4 | 0x11909c | 0x11769c | 0x206 |
InitializeSListHead | 0x0 | 0x4e61d8 | 0x1190a0 | 0x1176a0 | 0x2e7 |
IsProcessorFeaturePresent | 0x0 | 0x4e61dc | 0x1190a4 | 0x1176a4 | 0x304 |
UnhandledExceptionFilter | 0x0 | 0x4e61e0 | 0x1190a8 | 0x1176a8 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x4e61e4 | 0x1190ac | 0x1176ac | 0x4a5 |
IsDebuggerPresent | 0x0 | 0x4e61e8 | 0x1190b0 | 0x1176b0 | 0x300 |
GetStartupInfoW | 0x0 | 0x4e61ec | 0x1190b4 | 0x1176b4 | 0x263 |
CreateTimerQueue | 0x0 | 0x4e61f0 | 0x1190b8 | 0x1176b8 | 0xbc |
SignalObjectAndWait | 0x0 | 0x4e61f4 | 0x1190bc | 0x1176bc | 0x4b0 |
CreateThread | 0x0 | 0x4e61f8 | 0x1190c0 | 0x1176c0 | 0xb5 |
SetThreadPriority | 0x0 | 0x4e61fc | 0x1190c4 | 0x1176c4 | 0x499 |
GetThreadPriority | 0x0 | 0x4e6200 | 0x1190c8 | 0x1176c8 | 0x28e |
GetLogicalProcessorInformation | 0x0 | 0x4e6204 | 0x1190cc | 0x1176cc | 0x20a |
CreateTimerQueueTimer | 0x0 | 0x4e6208 | 0x1190d0 | 0x1176d0 | 0xbd |
ChangeTimerQueueTimer | 0x0 | 0x4e620c | 0x1190d4 | 0x1176d4 | 0x48 |
DeleteTimerQueueTimer | 0x0 | 0x4e6210 | 0x1190d8 | 0x1176d8 | 0xda |
GetNumaHighestNodeNumber | 0x0 | 0x4e6214 | 0x1190dc | 0x1176dc | 0x229 |
GetProcessAffinityMask | 0x0 | 0x4e6218 | 0x1190e0 | 0x1176e0 | 0x246 |
SetThreadAffinityMask | 0x0 | 0x4e621c | 0x1190e4 | 0x1176e4 | 0x490 |
RegisterWaitForSingleObject | 0x0 | 0x4e6220 | 0x1190e8 | 0x1176e8 | 0x3f5 |
UnregisterWait | 0x0 | 0x4e6224 | 0x1190ec | 0x1176ec | 0x4da |
FreeLibraryAndExitThread | 0x0 | 0x4e6228 | 0x1190f0 | 0x1176f0 | 0x163 |
GetModuleFileNameW | 0x0 | 0x4e622c | 0x1190f4 | 0x1176f4 | 0x214 |
GetVersionExW | 0x0 | 0x4e6230 | 0x1190f8 | 0x1176f8 | 0x2a4 |
VirtualAlloc | 0x0 | 0x4e6234 | 0x1190fc | 0x1176fc | 0x4e9 |
VirtualProtect | 0x0 | 0x4e6238 | 0x119100 | 0x117700 | 0x4ef |
VirtualFree | 0x0 | 0x4e623c | 0x119104 | 0x117704 | 0x4ec |
InterlockedPopEntrySList | 0x0 | 0x4e6240 | 0x119108 | 0x117708 | 0x2f0 |
InterlockedPushEntrySList | 0x0 | 0x4e6244 | 0x11910c | 0x11770c | 0x2f1 |
InterlockedFlushSList | 0x0 | 0x4e6248 | 0x119110 | 0x117710 | 0x2ee |
QueryDepthSList | 0x0 | 0x4e624c | 0x119114 | 0x117714 | 0x39e |
UnregisterWaitEx | 0x0 | 0x4e6250 | 0x119118 | 0x117718 | 0x4db |
LoadLibraryW | 0x0 | 0x4e6254 | 0x11911c | 0x11771c | 0x33f |
RtlUnwind | 0x0 | 0x4e6258 | 0x119120 | 0x117720 | 0x418 |
RaiseException | 0x0 | 0x4e625c | 0x119124 | 0x117724 | 0x3b1 |
GetCommandLineA | 0x0 | 0x4e6260 | 0x119128 | 0x117728 | 0x186 |
ExitThread | 0x0 | 0x4e6264 | 0x11912c | 0x11772c | 0x11a |
GetModuleHandleExW | 0x0 | 0x4e6268 | 0x119130 | 0x117730 | 0x217 |
ExitProcess | 0x0 | 0x4e626c | 0x119134 | 0x117734 | 0x119 |
GetModuleFileNameA | 0x0 | 0x4e6270 | 0x119138 | 0x117738 | 0x213 |
GetStdHandle | 0x0 | 0x4e6274 | 0x11913c | 0x11773c | 0x264 |
WriteFile | 0x0 | 0x4e6278 | 0x119140 | 0x117740 | 0x525 |
GetACP | 0x0 | 0x4e627c | 0x119144 | 0x117744 | 0x168 |
GetFileType | 0x0 | 0x4e6280 | 0x119148 | 0x117748 | 0x1f3 |
FlushFileBuffers | 0x0 | 0x4e6284 | 0x11914c | 0x11774c | 0x157 |
GetConsoleCP | 0x0 | 0x4e6288 | 0x119150 | 0x117750 | 0x19a |
GetConsoleMode | 0x0 | 0x4e628c | 0x119154 | 0x117754 | 0x1ac |
HeapReAlloc | 0x0 | 0x4e6290 | 0x119158 | 0x117758 | 0x2d2 |
GetDateFormatW | 0x0 | 0x4e6294 | 0x11915c | 0x11775c | 0x1c8 |
GetTimeFormatW | 0x0 | 0x4e6298 | 0x119160 | 0x117760 | 0x297 |
IsValidLocale | 0x0 | 0x4e629c | 0x119164 | 0x117764 | 0x30c |
GetUserDefaultLCID | 0x0 | 0x4e62a0 | 0x119168 | 0x117768 | 0x29b |
EnumSystemLocalesW | 0x0 | 0x4e62a4 | 0x11916c | 0x11776c | 0x10f |
ReadConsoleW | 0x0 | 0x4e62a8 | 0x119170 | 0x117770 | 0x3be |
IsValidCodePage | 0x0 | 0x4e62ac | 0x119174 | 0x117774 | 0x30a |
SHELL32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetFolderPathW | 0x0 | 0x4e62b4 | 0x11917c | 0x11777c | 0xc3 |
SHGetFileInfoW | 0x0 | 0x4e62b8 | 0x119180 | 0x117780 | 0xbd |
ole32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoCreateInstance | 0x0 | 0x4e62d4 | 0x11919c | 0x11779c | 0x10 |
CoInitialize | 0x0 | 0x4e62d8 | 0x1191a0 | 0x1177a0 | 0x3e |
CoUninitialize | 0x0 | 0x4e62dc | 0x1191a4 | 0x1177a4 | 0x6c |
ADVAPI32.dll (14)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LookupPrivilegeValueW | 0x0 | 0x4e6000 | 0x118ec8 | 0x1174c8 | 0x197 |
CryptGenRandom | 0x0 | 0x4e6004 | 0x118ecc | 0x1174cc | 0xc1 |
CryptReleaseContext | 0x0 | 0x4e6008 | 0x118ed0 | 0x1174d0 | 0xcb |
CryptAcquireContextA | 0x0 | 0x4e600c | 0x118ed4 | 0x1174d4 | 0xb0 |
CloseServiceHandle | 0x0 | 0x4e6010 | 0x118ed8 | 0x1174d8 | 0x57 |
OpenSCManagerW | 0x0 | 0x4e6014 | 0x118edc | 0x1174dc | 0x1f9 |
ControlService | 0x0 | 0x4e6018 | 0x118ee0 | 0x1174e0 | 0x5c |
EnumDependentServicesW | 0x0 | 0x4e601c | 0x118ee4 | 0x1174e4 | 0xfd |
OpenServiceW | 0x0 | 0x4e6020 | 0x118ee8 | 0x1174e8 | 0x1fb |
QueryServiceStatusEx | 0x0 | 0x4e6024 | 0x118eec | 0x1174ec | 0x229 |
AdjustTokenPrivileges | 0x0 | 0x4e6028 | 0x118ef0 | 0x1174f0 | 0x1f |
OpenProcessToken | 0x0 | 0x4e602c | 0x118ef4 | 0x1174f4 | 0x1f7 |
SetSecurityDescriptorDacl | 0x0 | 0x4e6030 | 0x118ef8 | 0x1174f8 | 0x2b6 |
InitializeSecurityDescriptor | 0x0 | 0x4e6034 | 0x118efc | 0x1174fc | 0x177 |
WS2_32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WSACleanup | 0x74 | 0x4e62c8 | 0x119190 | 0x117790 | - |
WSAStartup | 0x73 | 0x4e62cc | 0x119194 | 0x117794 | - |
Digital Signatures (3)
»
Certificate: ALISA LTD
»
Issued by | ALISA LTD |
Parent Certificate | Sectigo RSA Code Signing CA |
Country Name | GB |
Valid From | 2019-02-22 00:00:00+00:00 |
Valid Until | 2020-02-21 23:59:59+00:00 |
Algorithm | sha256_rsa |
Serial Number | 5D A1 73 EB 1A C7 63 40 AC 05 8E 1F F4 BF 5E 1B |
Thumbprint | AC B3 8D 45 10 8C 4F 0C 88 94 04 06 46 13 7C 95 E9 BB 39 D8 |
Certificate: Sectigo RSA Code Signing CA
»
Issued by | Sectigo RSA Code Signing CA |
Parent Certificate | USERTrust RSA Certification Authority |
Country Name | GB |
Valid From | 2018-11-02 00:00:00+00:00 |
Valid Until | 2030-12-31 23:59:59+00:00 |
Algorithm | sha384_rsa |
Serial Number | 1D A2 48 30 6F 9B 26 18 D0 82 E0 96 7D 33 D3 6A |
Thumbprint | 94 C9 5D A1 E8 50 BD 85 20 9A 4A 2A F3 E1 FB 16 04 F9 BB 66 |
Certificate: USERTrust RSA Certification Authority
»
Issued by | USERTrust RSA Certification Authority |
Country Name | US |
Valid From | 2000-05-30 10:48:38+00:00 |
Valid Until | 2020-05-30 10:48:38+00:00 |
Algorithm | sha384_rsa |
Serial Number | 13 EA 28 70 5B F4 EC ED 0C 36 63 09 80 61 43 36 |
Thumbprint | EA B0 40 68 9A 0D 80 5B 5D 6F D6 54 FC 16 8C FF 00 B7 8B E3 |
C:\588bce7c90097ed212\1035\LocalizedData.xml.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\Parameterinfo.xml.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\hr-HR\bootmgr.exe.mui.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\ro-RO\bootmgr.exe.mui.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Known Folders API Service.evtx.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\zh-TW\bootmgr.exe.mui.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\zh-CN\bootmgr.exe.mui.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\es-ES\memtest.exe.mui.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\SetupResources.dll.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\SetupResources.dll.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\SetupResources.dll.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\VSTO\10.0\1033\VSTOInstallerUI.dll.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Analysis Services\AS OLEDB\110\SQLDumper.exe.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\VFS\SystemX86\vccorlib140.dll.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\rempl\Unlock.xml.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\Fonts\malgun_boot.ttf.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.ScriptDom.dll.locked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Desktop\README_LOCKED.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1025\LocalizedData.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1049\LocalizedData.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1036\LocalizedData.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\UiInfo.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Strings.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1046\LocalizedData.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1033\LocalizedData.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1044\LocalizedData.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\LocalizedData.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1028\LocalizedData.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1042\LocalizedData.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1043\LocalizedData.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Extended\UiInfo.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Extended\Parameterinfo.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1041\LocalizedData.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1040\LocalizedData.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Client\UiInfo.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3082\LocalizedData.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1030\LocalizedData.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3076\LocalizedData.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2070\LocalizedData.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2052\LocalizedData.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1055\LocalizedData.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1053\LocalizedData.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1037\LocalizedData.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\Fonts\kor_boot.ttf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\RGB9RAST_x64.msi.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\Fonts\msjhn_boot.ttf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\sqmapi.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\bg-BG\bootmgr.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\uk-UA\bootmgr.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\it-IT\bootmgr.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\sl-SI\bootmgr.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\pt-PT\bootmgr.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\pt-BR\bootmgr.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\fi-FI\bootmgr.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\cs-CZ\bootmgr.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\sv-SE\bootmgr.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\lt-LT\bootmgr.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\da-DK\bootmgr.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\lv-LV\bootmgr.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\et-EE\bootmgr.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\en-US\bootmgr.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\qps-ploc\bootmgr.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\en-GB\bootmgr.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Admin.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-International%4Operational.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\ja-JP\bootmgr.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\ko-KR\bootmgr.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\zh-HK\bootmgr.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\qps-ploc\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\fr-FR\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\pl-PL\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\el-GR\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\hu-HU\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\pt-PT\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\de-DE\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\da-DK\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\it-IT\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\pt-BR\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\nl-NL\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\fi-FI\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\nb-NO\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\sv-SE\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\sr-Latn-CS\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\ru-RU\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\en-US\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\Fonts\segmono_boot.ttf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\ja-JP\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\ko-KR\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\zh-CN\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\zh-TW\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Setup.ico.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\zh-HK\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1043\SetupResources.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2070\SetupResources.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3082\SetupResources.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1036\SetupResources.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1035\SetupResources.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1040\SetupResources.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1049\SetupResources.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1044\SetupResources.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\SetupResources.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1030\SetupResources.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1055\SetupResources.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1053\SetupResources.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1025\SetupResources.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1033\SetupResources.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\DHtmlHeader.html.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1037\SetupResources.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1028\SetupResources.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1042\SetupResources.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1041\SetupResources.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3076\SetupResources.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2052\SetupResources.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\warn.ico.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1041\eula.rtf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\Resources\en-US\bootres.dll.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1028\eula.rtf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3076\eula.rtf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1053\eula.rtf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\updaterevokesipolicy.p7b.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\eula.rtf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1055\eula.rtf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1046\eula.rtf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\header.bmp.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1043\eula.rtf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1033\eula.rtf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1044\eula.rtf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Print.ico.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqMet.ico.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Save.ico.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate7.ico.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate5.ico.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate6.ico.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate4.ico.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate1.ico.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate3.ico.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate2.ico.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate8.ico.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\SetupComplete.cmd.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\bin\decora_sse.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01637_.WMF.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\NA02407_.WMF.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\THEMES16\STUDIO\STUDIO.INF.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\MSIPC\nl\msipc.dll.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\SYSTEM\MSMAPI\1033\MSMAPI32.DLL.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\SYSTEM\ole db\xmlrwbin.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Analysis Services\AS OLEDB\110\msolui110.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Analysis Services\AS OLEDB\110\Resources\1033\msolui110.rll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Analysis Services\AS OLEDB\110\Cartridges\trdtv2r41.xsl.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Analysis Services\AS OLEDB\110\msolui110.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\VFS\System\VEN2232.OLB.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\browser\chrome.manifest.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\browser\blocklist.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\dependentlibs.list.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\freebl3.chk.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\ucrtbase.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\MSBuild\Microsoft\Windows Workflow Foundation\v3.0\Workflow.VisualBasic.Targets.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\rempl\remsh.exe.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\rempl\rempl.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Reference Assemblies\Microsoft\Framework\v3.5\Microsoft.VisualC.STLCLR.dll.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\rempl\Logs\Remediation.003.etl.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\rempl\Logs\Remediation.002.etl.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\rempl\Logs\Remediation.001.etl.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\ca-ES\toastreviewsettings.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Config_131491847713900000.json.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\ca-ES\toastbeginupgradeth2.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\el-GR\toastbeginupgrade.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\el-GR\index.html.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\el-GR\toastbeginupgradeth2.xml.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\THEMES16\STUDIO\STUDIO.ELM.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Core.mzz.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\Fonts\cht_boot.ttf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\Fonts\chs_boot.ttf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\Fonts\jpn_boot.ttf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SetupUtility.exe.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\Fonts\wgl4_boot.ttf.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\cs-CZ\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Boot\tr-TR\memtest.exe.mui.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\1033\BHOINTL.DLL.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\VBA\VBA7.1\VBEUI.DLL.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\VBA\VBA7.1\VBE7.DLL.locked | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\Cultures\OFFICE.ODF.locked | Dropped File | Stream |
Not Queried
|
...
|
»
98881805af50c26f79c1bc073dc578979c46bb4f86051011a3799fd8b6b01c63 | Downloaded File | Stream |
Not Queried
|
...
|
»
ebf3e7290b8fd1e5509caa69335251f22b61baf3f9ff87b4e8544f3c1fea279d | Downloaded File | Unknown |
Not Queried
|
...
|
»