Malicious
Classifications
Injector
Threat Names
-
Dynamic Analysis Report
Created on 2022-06-06T08:43:17+00:00
b4b14f0512858ecd957152f6f21d06070ad3f371206568871d0f92d5a41ecd83.exe
Windows Exe (x86-32)
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "2 hours, 42 minutes, 4 seconds" to "21 seconds" to reveal dormant functionality.
Remarks
(0x0200004A): 2 dump(s) were skipped because they exceeded the maximum dump size of 7 MB. The largest one was 10 MB.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\ProgramData\images.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x005422B0 |
Size Of Code | 0x0002E000 |
Size Of Initialized Data | 0x00001000 |
Size Of Uninitialized Data | 0x00114000 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_CUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2022-06-06 02:50 (UTC+2) |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
UPX0 | 0x00401000 | 0x00114000 | 0x00000000 | 0x00000400 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
UPX1 | 0x00515000 | 0x0002E000 | 0x0002D600 | 0x00000400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.86 |
.rsrc | 0x00543000 | 0x00001000 | 0x00000400 | 0x0002DA00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.62 |
Imports (5)
»
ADVAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CopySid | - | 0x00543254 | 0x00143254 | 0x0002DC54 | 0x00000000 |
KERNEL32.DLL (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | - | 0x0054325C | 0x0014325C | 0x0002DC5C | 0x00000000 |
ExitProcess | - | 0x00543260 | 0x00143260 | 0x0002DC60 | 0x00000000 |
GetProcAddress | - | 0x00543264 | 0x00143264 | 0x0002DC64 | 0x00000000 |
VirtualProtect | - | 0x00543268 | 0x00143268 | 0x0002DC68 | 0x00000000 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetFolderPathW | - | 0x00543270 | 0x00143270 | 0x0002DC70 | 0x00000000 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
IsWindow | - | 0x00543278 | 0x00143278 | 0x0002DC78 | 0x00000000 |
VERSION.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VerQueryValueW | - | 0x00543280 | 0x00143280 | 0x0002DC80 | 0x00000000 |
Memory Dumps (127)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
b4b14f0512858ecd957152f6f21d06070ad3f371206568871d0f92d5a41ecd83.exe | 1 | 0x00400000 | 0x00543FFF | First Execution | 32-bit | 0x005422B0 |
...
|
||
b4b14f0512858ecd957152f6f21d06070ad3f371206568871d0f92d5a41ecd83.exe | 1 | 0x00400000 | 0x00543FFF | Content Changed | 32-bit | 0x0040446B |
...
|
||
b4b14f0512858ecd957152f6f21d06070ad3f371206568871d0f92d5a41ecd83.exe | 1 | 0x00400000 | 0x00543FFF | Content Changed | 32-bit | 0x00406C69 |
...
|
||
user32.dll | 1 | 0x75640000 | 0x75786FFF | First Execution | 32-bit | 0x756BFEC0 |
...
|
||
b4b14f0512858ecd957152f6f21d06070ad3f371206568871d0f92d5a41ecd83.exe | 1 | 0x00400000 | 0x00543FFF | Content Changed | 32-bit | 0x004011F0 |
...
|
||
buffer | 1 | 0x02AE0000 | 0x02C33FFF | First Execution | 32-bit | 0x02AF3058 |
...
|
||
buffer | 1 | 0x031F7020 | 0x035F701F | Image In Buffer | 32-bit | - |
...
|
||
b4b14f0512858ecd957152f6f21d06070ad3f371206568871d0f92d5a41ecd83.exe | 1 | 0x00400000 | 0x00543FFF | Process Termination | 32-bit | - |
...
|
||
images.exe | 4 | 0x00400000 | 0x00543FFF | First Execution | 32-bit | 0x005422B0 |
...
|
||
images.exe | 4 | 0x00400000 | 0x00543FFF | Content Changed | 32-bit | 0x0040A85D |
...
|
||
user32.dll | 4 | 0x75640000 | 0x75786FFF | First Execution | 32-bit | 0x756BFEC0 |
...
|
||
images.exe | 4 | 0x00400000 | 0x00543FFF | Content Changed | 32-bit | 0x004011F0 |
...
|
||
buffer | 4 | 0x02B20000 | 0x02C73FFF | First Execution | 32-bit | 0x02B33058 |
...
|
||
buffer | 4 | 0x009CD000 | 0x009CFFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x0019D000 | 0x0019FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x0061F300 | 0x0061F37F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x006203B8 | 0x00620457 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x00621760 | 0x006217EF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x00621F40 | 0x00621FBF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x00627B38 | 0x00627D57 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x00629000 | 0x00629363 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x0062A510 | 0x0062B30F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x0062C660 | 0x0062CE5F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x0063E348 | 0x0063E43B | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x00641C70 | 0x00641E6F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x00641E78 | 0x00642077 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x00642080 | 0x0064227F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x006423F0 | 0x006424EF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x006424F8 | 0x006425F7 | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x00642600 | 0x006426FE | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x00674828 | 0x00674DCB | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x02B20000 | 0x02C73FFF | First Network Behavior | 32-bit | 0x02B260AA |
...
|
||
buffer | 4 | 0x02D40000 | 0x02D40FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x02D50000 | 0x02D50FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x02D60000 | 0x02D60FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x02D80000 | 0x02D80FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x02D90000 | 0x02D90FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x02DA0000 | 0x02DA0FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x02DB0000 | 0x02DB0FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x02DC0000 | 0x02DC0FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x02DD0000 | 0x02DD0FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x031B0000 | 0x031B0FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x031C0000 | 0x031C0FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x031D0000 | 0x031D0FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x031E0000 | 0x031E0FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x031F0020 | 0x035F001F | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x03600000 | 0x03600FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x03610000 | 0x03610FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x03620000 | 0x03620FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x03630000 | 0x03630FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x03640000 | 0x03640FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x03650000 | 0x03650FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x03660000 | 0x03660FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x03670000 | 0x03670FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x03680000 | 0x03680FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x03690000 | 0x03690FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x036A0000 | 0x036A0FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x036B0000 | 0x036B0FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x036C0000 | 0x036C0FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x036D0000 | 0x036D0FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x036E0000 | 0x036E0FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x036F0000 | 0x036F0FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x03700000 | 0x03700FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x03710000 | 0x03710FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x03720000 | 0x03720FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x03730000 | 0x03730FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x03750000 | 0x03750FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x03760000 | 0x03760FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x03770000 | 0x03770FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 4 | 0x03780000 | 0x03780FFF | First Network Behavior | 32-bit | - |
...
|
||
images.exe | 4 | 0x00400000 | 0x00543FFF | First Network Behavior | 32-bit | 0x0040126C |
...
|
||
user32.dll | 4 | 0x75640000 | 0x75786FFF | Content Changed | 32-bit | 0x7566E100 |
...
|
||
buffer | 4 | 0x03B6D020 | 0x03F6D01F | Image In Buffer | 32-bit | - |
...
|
||
buffer | 4 | 0x0061F300 | 0x0061F37F | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x006203B8 | 0x00620457 | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x00621760 | 0x006217EF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x00621F40 | 0x00621FBF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x00627B38 | 0x00627D57 | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x00629000 | 0x00629363 | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x0062A510 | 0x0062B30F | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x0062C660 | 0x0062CE5F | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x0063E348 | 0x0063E43B | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x00641C70 | 0x00641E6F | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x00641E78 | 0x00642077 | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x00642080 | 0x0064227F | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x006423F0 | 0x006424EF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x006424F8 | 0x006425F7 | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x00642600 | 0x006426FE | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x00674828 | 0x00674DCB | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x02B20000 | 0x02C73FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x02D40000 | 0x02D40FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x02D50000 | 0x02D50FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x02D60000 | 0x02D60FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x02D80000 | 0x02D80FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x02D90000 | 0x02D90FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x02DA0000 | 0x02DA0FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x02DB0000 | 0x02DB0FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x02DC0000 | 0x02DC0FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x02DD0000 | 0x02DD0FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x031B0000 | 0x031B0FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x031C0000 | 0x031C0FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x031D0000 | 0x031D0FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x031E0000 | 0x031E0FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x031F0020 | 0x035F001F | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x03600000 | 0x03600FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x03610000 | 0x03610FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x03620000 | 0x03620FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x03630000 | 0x03630FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x03640000 | 0x03640FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x03650000 | 0x03650FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x03660000 | 0x03660FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x03670000 | 0x03670FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x03680000 | 0x03680FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x03690000 | 0x03690FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x036A0000 | 0x036A0FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x036B0000 | 0x036B0FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x036C0000 | 0x036C0FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x036D0000 | 0x036D0FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x036E0000 | 0x036E0FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x036F0000 | 0x036F0FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x03700000 | 0x03700FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x03710000 | 0x03710FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x03720000 | 0x03720FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x03730000 | 0x03730FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x03750000 | 0x03750FFF | Final Dump | 32-bit | - |
...
|
||
buffer | 4 | 0x03B6D020 | 0x03F6D01F | Final Dump | 32-bit | - |
...
|
||
images.exe | 4 | 0x00400000 | 0x00543FFF | Final Dump | 32-bit | - |
...
|
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_54415d7c-53c0-4bb9-b247-295a127dc231 | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_9b145d57-d591-4a56-acd6-a4c89787e7f0 | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_0cf70ae4-6773-489a-ba97-c66494b427aa | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_be7dd5c5-5282-497a-aab7-c42f30b0d596 | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_047927fe-b20c-406d-a7a1-3a54f40092bf | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_d402a6eb-5577-4d4f-a9b5-367feb9e2a75 | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_b58d55c1-44f2-4801-9046-2bf0948be95f | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_6d49f2a0-e6f8-4398-b8a5-0816938bad54 | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_d949b570-9ee1-4703-aa20-a8d9d314630f | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_5bde1bf8-6441-4991-a87f-23ddbecbbff0 | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_62c55fb7-1ea1-4722-95ed-2a854a673897 | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_b8282425-dfaa-4779-a972-aed090c62b86 | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_77bee94e-8407-4ba9-a4bc-e727958d71d4 | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_6ffaac7c-e630-426c-983b-90a7c7bcac99 | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_6fee7b07-4249-469c-8e77-059b1a0893b8 | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_5e68c54d-fa8b-42b7-b2f2-864d3fdc9ec0 | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_2fe42bb7-c7e4-460c-aa00-9d49bea128e5 | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_8a12d684-f76a-4c35-b868-3bf9f868835e | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_80f8d62d-7a61-4ae5-bee1-b16e091c0604 | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheEntry_902b44a1-4761-4de3-bc8e-0cf406e24530 | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Temp\r1nl1b3y.rqq.psm1 | Dropped File | Stream |
Clean
Known to be clean.
|
...
|
»
File Reputation Information
»
Verdict |
Clean
Known to be clean.
|
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»
C:\Users\RDhJ0CNFevzX\AppData\Local\Microsoft\Windows\PowerShell\CommandAnalysis\PowerShell_AnalysisCacheIndex | Modified File | Stream |
Clean
|
...
|
»