VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Sodinokibi
|
oxnvub.dll
Windows DLL (x86-32)
Created at 2021-02-17T05:29:00
Remarks (1/1)
(0x02000009): DLL files normally need to be submitted with an appropriate loader. Analysis result may be incomplete if an appropriate loader was not submitted.
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
PE Information
»
Image Base | 0x10000000 |
Entry Point | 0x1001c862 |
Size Of Code | 0x26200 |
Size Of Initialized Data | 0xa000 |
File Type | FileType.dll |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2021-02-04 15:57:28+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x10001000 | 0x2609d | 0x26200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.51 |
.rdata | 0x10028000 | 0x5d7e | 0x5e00 | 0x26600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.01 |
.data | 0x1002e000 | 0x2c48 | 0x2200 | 0x2c400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.72 |
.rsrc | 0x10031000 | 0x1e0 | 0x200 | 0x2e600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.72 |
.reloc | 0x10032000 | 0x1160 | 0x1200 | 0x2e800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.43 |
Imports (3)
»
KERNEL32.dll (69)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CloseHandle | 0x0 | 0x10028000 | 0x2d72c | 0x2bd2c | 0x86 |
GetLocalTime | 0x0 | 0x10028004 | 0x2d730 | 0x2bd30 | 0x262 |
lstrlenW | 0x0 | 0x10028008 | 0x2d734 | 0x2bd34 | 0x63c |
FreeLibraryAndExitThread | 0x0 | 0x1002800c | 0x2d738 | 0x2bd38 | 0x1ac |
CreateThread | 0x0 | 0x10028010 | 0x2d73c | 0x2bd3c | 0xf3 |
lstrcpyW | 0x0 | 0x10028014 | 0x2d740 | 0x2bd40 | 0x636 |
WriteConsoleW | 0x0 | 0x10028018 | 0x2d744 | 0x2bd44 | 0x611 |
CreateFileW | 0x0 | 0x1002801c | 0x2d748 | 0x2bd48 | 0xcb |
SetFilePointerEx | 0x0 | 0x10028020 | 0x2d74c | 0x2bd4c | 0x523 |
UnhandledExceptionFilter | 0x0 | 0x10028024 | 0x2d750 | 0x2bd50 | 0x5ad |
SetUnhandledExceptionFilter | 0x0 | 0x10028028 | 0x2d754 | 0x2bd54 | 0x56d |
GetCurrentProcess | 0x0 | 0x1002802c | 0x2d758 | 0x2bd58 | 0x217 |
TerminateProcess | 0x0 | 0x10028030 | 0x2d75c | 0x2bd5c | 0x58c |
IsProcessorFeaturePresent | 0x0 | 0x10028034 | 0x2d760 | 0x2bd60 | 0x386 |
IsDebuggerPresent | 0x0 | 0x10028038 | 0x2d764 | 0x2bd64 | 0x37f |
GetStartupInfoW | 0x0 | 0x1002803c | 0x2d768 | 0x2bd68 | 0x2d0 |
GetModuleHandleW | 0x0 | 0x10028040 | 0x2d76c | 0x2bd6c | 0x278 |
QueryPerformanceCounter | 0x0 | 0x10028044 | 0x2d770 | 0x2bd70 | 0x44d |
GetCurrentProcessId | 0x0 | 0x10028048 | 0x2d774 | 0x2bd74 | 0x218 |
GetCurrentThreadId | 0x0 | 0x1002804c | 0x2d778 | 0x2bd78 | 0x21c |
GetSystemTimeAsFileTime | 0x0 | 0x10028050 | 0x2d77c | 0x2bd7c | 0x2e9 |
InitializeSListHead | 0x0 | 0x10028054 | 0x2d780 | 0x2bd80 | 0x363 |
RaiseException | 0x0 | 0x10028058 | 0x2d784 | 0x2bd84 | 0x462 |
InterlockedFlushSList | 0x0 | 0x1002805c | 0x2d788 | 0x2bd88 | 0x36c |
GetLastError | 0x0 | 0x10028060 | 0x2d78c | 0x2bd8c | 0x261 |
SetLastError | 0x0 | 0x10028064 | 0x2d790 | 0x2bd90 | 0x532 |
EnterCriticalSection | 0x0 | 0x10028068 | 0x2d794 | 0x2bd94 | 0x131 |
LeaveCriticalSection | 0x0 | 0x1002806c | 0x2d798 | 0x2bd98 | 0x3bd |
DeleteCriticalSection | 0x0 | 0x10028070 | 0x2d79c | 0x2bd9c | 0x110 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x10028074 | 0x2d7a0 | 0x2bda0 | 0x35f |
TlsAlloc | 0x0 | 0x10028078 | 0x2d7a4 | 0x2bda4 | 0x59e |
TlsGetValue | 0x0 | 0x1002807c | 0x2d7a8 | 0x2bda8 | 0x5a0 |
TlsSetValue | 0x0 | 0x10028080 | 0x2d7ac | 0x2bdac | 0x5a1 |
TlsFree | 0x0 | 0x10028084 | 0x2d7b0 | 0x2bdb0 | 0x59f |
FreeLibrary | 0x0 | 0x10028088 | 0x2d7b4 | 0x2bdb4 | 0x1ab |
GetProcAddress | 0x0 | 0x1002808c | 0x2d7b8 | 0x2bdb8 | 0x2ae |
LoadLibraryExW | 0x0 | 0x10028090 | 0x2d7bc | 0x2bdbc | 0x3c3 |
RtlUnwind | 0x0 | 0x10028094 | 0x2d7c0 | 0x2bdc0 | 0x4d3 |
ExitProcess | 0x0 | 0x10028098 | 0x2d7c4 | 0x2bdc4 | 0x15e |
GetModuleHandleExW | 0x0 | 0x1002809c | 0x2d7c8 | 0x2bdc8 | 0x277 |
GetModuleFileNameW | 0x0 | 0x100280a0 | 0x2d7cc | 0x2bdcc | 0x274 |
HeapAlloc | 0x0 | 0x100280a4 | 0x2d7d0 | 0x2bdd0 | 0x345 |
HeapFree | 0x0 | 0x100280a8 | 0x2d7d4 | 0x2bdd4 | 0x349 |
FindClose | 0x0 | 0x100280ac | 0x2d7d8 | 0x2bdd8 | 0x175 |
FindFirstFileExW | 0x0 | 0x100280b0 | 0x2d7dc | 0x2bddc | 0x17b |
FindNextFileW | 0x0 | 0x100280b4 | 0x2d7e0 | 0x2bde0 | 0x18c |
IsValidCodePage | 0x0 | 0x100280b8 | 0x2d7e4 | 0x2bde4 | 0x38b |
GetACP | 0x0 | 0x100280bc | 0x2d7e8 | 0x2bde8 | 0x1b2 |
GetOEMCP | 0x0 | 0x100280c0 | 0x2d7ec | 0x2bdec | 0x297 |
GetCPInfo | 0x0 | 0x100280c4 | 0x2d7f0 | 0x2bdf0 | 0x1c1 |
GetCommandLineA | 0x0 | 0x100280c8 | 0x2d7f4 | 0x2bdf4 | 0x1d6 |
GetCommandLineW | 0x0 | 0x100280cc | 0x2d7f8 | 0x2bdf8 | 0x1d7 |
MultiByteToWideChar | 0x0 | 0x100280d0 | 0x2d7fc | 0x2bdfc | 0x3ef |
WideCharToMultiByte | 0x0 | 0x100280d4 | 0x2d800 | 0x2be00 | 0x5fe |
GetEnvironmentStringsW | 0x0 | 0x100280d8 | 0x2d804 | 0x2be04 | 0x237 |
FreeEnvironmentStringsW | 0x0 | 0x100280dc | 0x2d808 | 0x2be08 | 0x1aa |
GetStdHandle | 0x0 | 0x100280e0 | 0x2d80c | 0x2be0c | 0x2d2 |
GetFileType | 0x0 | 0x100280e4 | 0x2d810 | 0x2be10 | 0x24e |
LCMapStringW | 0x0 | 0x100280e8 | 0x2d814 | 0x2be14 | 0x3b1 |
GetProcessHeap | 0x0 | 0x100280ec | 0x2d818 | 0x2be18 | 0x2b4 |
GetStringTypeW | 0x0 | 0x100280f0 | 0x2d81c | 0x2be1c | 0x2d7 |
HeapSize | 0x0 | 0x100280f4 | 0x2d820 | 0x2be20 | 0x34e |
HeapReAlloc | 0x0 | 0x100280f8 | 0x2d824 | 0x2be24 | 0x34c |
SetStdHandle | 0x0 | 0x100280fc | 0x2d828 | 0x2be28 | 0x54a |
FlushFileBuffers | 0x0 | 0x10028100 | 0x2d82c | 0x2be2c | 0x19f |
WriteFile | 0x0 | 0x10028104 | 0x2d830 | 0x2be30 | 0x612 |
GetConsoleCP | 0x0 | 0x10028108 | 0x2d834 | 0x2be34 | 0x1ea |
GetConsoleMode | 0x0 | 0x1002810c | 0x2d838 | 0x2be38 | 0x1fc |
DecodePointer | 0x0 | 0x10028110 | 0x2d83c | 0x2be3c | 0x109 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
wsprintfW | 0x0 | 0x10028118 | 0x2d844 | 0x2be44 | 0x3e4 |
WS2_32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WSAGetLastError | 0x6f | 0x10028120 | 0x2d84c | 0x2be4c | - |
htons | 0x9 | 0x10028124 | 0x2d850 | 0x2be50 | - |
Exports (3)
»
Api name | EAT Address | Ordinal |
---|---|---|
DllInstall | 0x18b40 | 0x2 |
DllRegisterServer | 0x18b90 | 0x1 |
EntryPoint | 0x18bb0 | 0x3 |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
SodinokibiEncryptedFile | File encrypted by Sodinokibi Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\DHtmlHeader.html.ANCIF | Dropped File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DisplayIcon.ico.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core.mzz | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Strings.xml.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Known Folders API Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx | Modified File | Binary |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Windows PowerShell.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\desktop.ini.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\preoobe.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\SetupComplete.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\LocalizedData.xml.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.xml.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.xml.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\eula.rtf.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\LocalizedData.xml.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\LocalizedData.xml.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\LocalizedData.xml.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\LocalizedData.xml.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\eula.rtf.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\LocalizedData.xml.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\LocalizedData.xml.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\eula.rtf.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\LocalizedData.xml.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\eula.rtf.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\Parameterinfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\UiInfo.xml.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Print.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate7.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Save.ico.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Setup.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\stop.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\warn.ico.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\AppXManifest.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\application.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\crashreporter.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\dependentlibs.list | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\firefox.VisualElementsManifest.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\nssdbm3.chk.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\omni.ja | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\precomplete.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\removed-files.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\softokn3.chk | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\update-settings.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\updater.ini.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\rempl\rempl.xml.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\rempl\Unlock.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Mozilla Maintenance Service\updater.ini.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Licensing Component.swidtag | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Localization Component.swidtag | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft_Windows-10-Pro.swidtag | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT.LOG1 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT.LOG2.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TM.blf.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TMContainer00000000000000000001.regtrans-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{fae9930d-933c-11e7-a51d-b808901d6c9b}.TM.blf.ANCIF | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\readme.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\UiInfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\HardwareEvents.evtx.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Key Management Service.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-International%4Operational.evtx.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Admin.evtx.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Store%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Recovery\ReAgentOld.xml.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1025\LocalizedData.xml.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1028\eula.rtf.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1033\LocalizedData.xml.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\LocalizedData.xml.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1055\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3076\LocalizedData.xml.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3082\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Client\UiInfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Extended\Parameterinfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate1.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate2.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate3.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate4.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate5.ico.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate6.ico.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate8.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqMet.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\FileSystemMetadata.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\Accessible.tlb.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\freebl3.chk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\install.log | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\platform.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Extensibility Component.swidtag | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TMContainer00000000000000000002.regtrans-ms.ANCIF | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT{fae9930d-933c-11e7-a51d-b808901d6c9b}.TMContainer00000000000000000001.regtrans-ms | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT{fae9930d-933c-11e7-a51d-b808901d6c9b}.TMContainer00000000000000000002.regtrans-ms | Modified File | Stream |
Not Queried
|
...
|
»