VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan |
hwyfzd.exe
Windows Exe (x86-32)
Created at 2020-01-06T02:34:00
Remarks
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-12-29 07:48 (UTC+1) |
Last Seen | 2019-12-29 15:20 (UTC+1) |
Names | Win32.Trojan.Wacatac |
Families | Wacatac |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4240d0 |
Size Of Code | 0x2bc00 |
Size Of Initialized Data | 0x32cb400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-01-01 23:52:17+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x2ba8b | 0x2bc00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.34 |
.data | 0x42d000 | 0x32b2b04 | 0x7200 | 0x2c000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.65 |
.rsrc | 0x36e0000 | 0x3b58 | 0x3c00 | 0x33200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.03 |
.reloc | 0x36e4000 | 0x15900 | 0x15a00 | 0x36e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.9 |
Imports (3)
»
KERNEL32.dll (86)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCurrentThread | 0x0 | 0x401018 | 0x2c1ec | 0x2b5ec | 0x1ac |
ReadConsoleW | 0x0 | 0x40101c | 0x2c1f0 | 0x2b5f0 | 0x366 |
InitializeCriticalSection | 0x0 | 0x401020 | 0x2c1f4 | 0x2b5f4 | 0x2b4 |
ActivateActCtx | 0x0 | 0x401024 | 0x2c1f8 | 0x2b5f8 | 0x2 |
CreateEventA | 0x0 | 0x401028 | 0x2c1fc | 0x2b5fc | 0x72 |
GetSystemWindowsDirectoryA | 0x0 | 0x40102c | 0x2c200 | 0x2b600 | 0x251 |
CreateActCtxA | 0x0 | 0x401030 | 0x2c204 | 0x2b604 | 0x67 |
lstrcatA | 0x0 | 0x401034 | 0x2c208 | 0x2b608 | 0x4a6 |
lstrlenW | 0x0 | 0x401038 | 0x2c20c | 0x2b60c | 0x4b6 |
GetStringTypeExA | 0x0 | 0x40103c | 0x2c210 | 0x2b610 | 0x23e |
GetProcAddress | 0x0 | 0x401040 | 0x2c214 | 0x2b614 | 0x220 |
GetTickCount | 0x0 | 0x401044 | 0x2c218 | 0x2b618 | 0x266 |
LoadLibraryA | 0x0 | 0x401048 | 0x2c21c | 0x2b61c | 0x2f1 |
WriteConsoleA | 0x0 | 0x40104c | 0x2c220 | 0x2b620 | 0x482 |
LocalAlloc | 0x0 | 0x401050 | 0x2c224 | 0x2b624 | 0x2f9 |
QueryDosDeviceW | 0x0 | 0x401054 | 0x2c228 | 0x2b628 | 0x34e |
FindFirstChangeNotificationA | 0x0 | 0x401058 | 0x2c22c | 0x2b62c | 0x11b |
DebugBreakProcess | 0x0 | 0x40105c | 0x2c230 | 0x2b630 | 0xb5 |
PurgeComm | 0x0 | 0x401060 | 0x2c234 | 0x2b634 | 0x349 |
GetConsoleProcessList | 0x0 | 0x401064 | 0x2c238 | 0x2b638 | 0x19a |
EnumCalendarInfoExA | 0x0 | 0x401068 | 0x2c23c | 0x2b63c | 0xdb |
SetEvent | 0x0 | 0x40106c | 0x2c240 | 0x2b640 | 0x3d3 |
InterlockedCompareExchange | 0x0 | 0x401070 | 0x2c244 | 0x2b644 | 0x2ba |
GetNumberOfConsoleMouseButtons | 0x0 | 0x401074 | 0x2c248 | 0x2b648 | 0x212 |
EndUpdateResourceW | 0x0 | 0x401078 | 0x2c24c | 0x2b64c | 0xd8 |
UpdateResourceA | 0x0 | 0x40107c | 0x2c250 | 0x2b650 | 0x449 |
EnumDateFormatsExA | 0x0 | 0x401080 | 0x2c254 | 0x2b654 | 0xe0 |
GetCPInfo | 0x0 | 0x401084 | 0x2c258 | 0x2b658 | 0x15b |
InterlockedIncrement | 0x0 | 0x401088 | 0x2c25c | 0x2b65c | 0x2c0 |
InterlockedDecrement | 0x0 | 0x40108c | 0x2c260 | 0x2b660 | 0x2bc |
Sleep | 0x0 | 0x401090 | 0x2c264 | 0x2b664 | 0x421 |
DeleteCriticalSection | 0x0 | 0x401094 | 0x2c268 | 0x2b668 | 0xbe |
EnterCriticalSection | 0x0 | 0x401098 | 0x2c26c | 0x2b66c | 0xd9 |
LeaveCriticalSection | 0x0 | 0x40109c | 0x2c270 | 0x2b670 | 0x2ef |
UnhandledExceptionFilter | 0x0 | 0x4010a0 | 0x2c274 | 0x2b674 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x4010a4 | 0x2c278 | 0x2b678 | 0x415 |
GetModuleFileNameW | 0x0 | 0x4010a8 | 0x2c27c | 0x2b67c | 0x1f5 |
HeapValidate | 0x0 | 0x4010ac | 0x2c280 | 0x2b680 | 0x2a9 |
IsBadReadPtr | 0x0 | 0x4010b0 | 0x2c284 | 0x2b684 | 0x2c8 |
RaiseException | 0x0 | 0x4010b4 | 0x2c288 | 0x2b688 | 0x35a |
RtlUnwind | 0x0 | 0x4010b8 | 0x2c28c | 0x2b68c | 0x392 |
TerminateProcess | 0x0 | 0x4010bc | 0x2c290 | 0x2b690 | 0x42d |
GetCurrentProcess | 0x0 | 0x4010c0 | 0x2c294 | 0x2b694 | 0x1a9 |
IsDebuggerPresent | 0x0 | 0x4010c4 | 0x2c298 | 0x2b698 | 0x2d1 |
GetLastError | 0x0 | 0x4010c8 | 0x2c29c | 0x2b69c | 0x1e6 |
CloseHandle | 0x0 | 0x4010cc | 0x2c2a0 | 0x2b6a0 | 0x43 |
GetModuleHandleW | 0x0 | 0x4010d0 | 0x2c2a4 | 0x2b6a4 | 0x1f9 |
ExitProcess | 0x0 | 0x4010d4 | 0x2c2a8 | 0x2b6a8 | 0x104 |
GetModuleFileNameA | 0x0 | 0x4010d8 | 0x2c2ac | 0x2b6ac | 0x1f4 |
WriteFile | 0x0 | 0x4010dc | 0x2c2b0 | 0x2b6b0 | 0x48d |
GetStdHandle | 0x0 | 0x4010e0 | 0x2c2b4 | 0x2b6b4 | 0x23b |
GetFileType | 0x0 | 0x4010e4 | 0x2c2b8 | 0x2b6b8 | 0x1d7 |
FlushFileBuffers | 0x0 | 0x4010e8 | 0x2c2bc | 0x2b6bc | 0x141 |
WideCharToMultiByte | 0x0 | 0x4010ec | 0x2c2c0 | 0x2b6c0 | 0x47a |
GetConsoleCP | 0x0 | 0x4010f0 | 0x2c2c4 | 0x2b6c4 | 0x183 |
GetConsoleMode | 0x0 | 0x4010f4 | 0x2c2c8 | 0x2b6c8 | 0x195 |
DebugBreak | 0x0 | 0x4010f8 | 0x2c2cc | 0x2b6cc | 0xb4 |
OutputDebugStringA | 0x0 | 0x4010fc | 0x2c2d0 | 0x2b6d0 | 0x33a |
WriteConsoleW | 0x0 | 0x401100 | 0x2c2d4 | 0x2b6d4 | 0x48c |
OutputDebugStringW | 0x0 | 0x401104 | 0x2c2d8 | 0x2b6d8 | 0x33b |
LoadLibraryW | 0x0 | 0x401108 | 0x2c2dc | 0x2b6dc | 0x2f4 |
TlsGetValue | 0x0 | 0x40110c | 0x2c2e0 | 0x2b6e0 | 0x434 |
TlsSetValue | 0x0 | 0x401110 | 0x2c2e4 | 0x2b6e4 | 0x435 |
GetCurrentThreadId | 0x0 | 0x401114 | 0x2c2e8 | 0x2b6e8 | 0x1ad |
SetLastError | 0x0 | 0x401118 | 0x2c2ec | 0x2b6ec | 0x3ec |
HeapAlloc | 0x0 | 0x40111c | 0x2c2f0 | 0x2b6f0 | 0x29d |
HeapSize | 0x0 | 0x401120 | 0x2c2f4 | 0x2b6f4 | 0x2a6 |
HeapReAlloc | 0x0 | 0x401124 | 0x2c2f8 | 0x2b6f8 | 0x2a4 |
HeapFree | 0x0 | 0x401128 | 0x2c2fc | 0x2b6fc | 0x2a1 |
VirtualFree | 0x0 | 0x40112c | 0x2c300 | 0x2b700 | 0x457 |
VirtualAlloc | 0x0 | 0x401130 | 0x2c304 | 0x2b704 | 0x454 |
GetACP | 0x0 | 0x401134 | 0x2c308 | 0x2b708 | 0x152 |
GetOEMCP | 0x0 | 0x401138 | 0x2c30c | 0x2b70c | 0x213 |
IsValidCodePage | 0x0 | 0x40113c | 0x2c310 | 0x2b710 | 0x2db |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x401140 | 0x2c314 | 0x2b714 | 0x2b5 |
SetStdHandle | 0x0 | 0x401144 | 0x2c318 | 0x2b718 | 0x3fc |
GetConsoleOutputCP | 0x0 | 0x401148 | 0x2c31c | 0x2b71c | 0x199 |
MultiByteToWideChar | 0x0 | 0x40114c | 0x2c320 | 0x2b720 | 0x31a |
SetFilePointer | 0x0 | 0x401150 | 0x2c324 | 0x2b724 | 0x3df |
LCMapStringA | 0x0 | 0x401154 | 0x2c328 | 0x2b728 | 0x2e1 |
LCMapStringW | 0x0 | 0x401158 | 0x2c32c | 0x2b72c | 0x2e3 |
GetStringTypeA | 0x0 | 0x40115c | 0x2c330 | 0x2b730 | 0x23d |
GetStringTypeW | 0x0 | 0x401160 | 0x2c334 | 0x2b734 | 0x240 |
GetLocaleInfoA | 0x0 | 0x401164 | 0x2c338 | 0x2b738 | 0x1e8 |
CreateFileA | 0x0 | 0x401168 | 0x2c33c | 0x2b73c | 0x78 |
GetModuleHandleA | 0x0 | 0x40116c | 0x2c340 | 0x2b740 | 0x1f6 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCursor | 0x0 | 0x401174 | 0x2c348 | 0x2b748 | 0x116 |
ADVAPI32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegFlushKey | 0x0 | 0x401000 | 0x2c1d4 | 0x2b5d4 | 0x24d |
RegSaveKeyA | 0x0 | 0x401004 | 0x2c1d8 | 0x2b5d8 | 0x26f |
SetSecurityDescriptorDacl | 0x0 | 0x401008 | 0x2c1dc | 0x2b5dc | 0x2b0 |
OpenProcessToken | 0x0 | 0x40100c | 0x2c1e0 | 0x2b5e0 | 0x1f1 |
SetPrivateObjectSecurity | 0x0 | 0x401010 | 0x2c1e4 | 0x2b5e4 | 0x2ac |
Exports (2)
»
Api name | EAT Address | Ordinal |
---|---|---|
@dfyldfg@0 | 0x23da0 | 0x1 |
@fhdjdfj@4 | 0x23d90 | 0x2 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
buffer | 1 | 0x03A18748 | 0x03A1C29D | Marked Executable | - | 32-bit | 0x03A18748 |
...
|
||
buffer | 1 | 0x037E0000 | 0x037E6FFF | First Execution | - | 32-bit | 0x037E0000 |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.32887457 |
Malicious
|
\\?\C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\GetCurrentRollback.ini_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd | Modified File | Batch |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\SetupComplete.cmd | Modified File | Batch |
Unknown
|
...
|
»
\\?\C:\$WINRE_BACKUP_PARTITION.MARKER | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1025\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1025\LocalizedData.xml_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1028\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1029\SetupResources.dll_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1030\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1031\eula.rtf_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1031\SetupResources.dll_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1032\eula.rtf_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1032\LocalizedData.xml_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1032\SetupResources.dll_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1033\eula.rtf_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1033\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1033\SetupResources.dll_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1035\SetupResources.dll_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1036\eula.rtf_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1036\LocalizedData.xml_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1036\SetupResources.dll_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1037\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1037\LocalizedData.xml_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1038\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1040\LocalizedData.xml_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1040\SetupResources.dll_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1041\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1042\eula.rtf_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1042\LocalizedData.xml_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1042\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1043\eula.rtf_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1043\SetupResources.dll_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1044\eula.rtf_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1045\eula.rtf_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1045\SetupResources.dll_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1046\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1046\LocalizedData.xml_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1046\SetupResources.dll_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1049\eula.rtf_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1049\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1049\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1053\eula.rtf_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1053\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1053\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1055\eula.rtf_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1055\LocalizedData.xml_r00t_{8ew5f6}.ebal | Dropped File | Binary |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2052\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2070\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2070\LocalizedData.xml_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2070\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3076\eula.rtf_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3076\SetupResources.dll_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3082\eula.rtf_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3082\LocalizedData.xml_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3082\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Client\Parameterinfo.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Client\UiInfo.xml_r00t_{8ew5f6}.ebal | Dropped File | Binary |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\DHtmlHeader.html | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Extended\Parameterinfo.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Print.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate1.ico_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate3.ico_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate4.ico_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate5.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate6.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Setup.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\stop.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\SysReqMet.ico_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\warn.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Core.mzz_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Core_x64.msi_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Core_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Extended.mzz | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Extended_x64.msi_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Extended_x86.msi_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\ParameterInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\RGB9RAST_x64.msi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\RGB9Rast_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Setup.exe_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\SetupEngine.dll_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\SetupUi.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\SetupUi.xsd | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\SetupUtility.exe | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\SplashScreen.bmp_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\sqmapi.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\BCD.LOG2_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\BOOTNXT_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\HardwareEvents.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Internet Explorer.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Key Management Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx | Modified File | Binary |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-MUI%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-MUI%4Operational.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\taridd | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Extended\---==%$$$OPEN_ME_UP$$$==---.txt | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\preoobe.cmd | Modified File | Batch |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1025\SetupResources.dll_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1028\LocalizedData.xml_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1028\SetupResources.dll_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1029\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1029\LocalizedData.xml_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1030\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1031\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1035\eula.rtf_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1037\SetupResources.dll_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1038\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1041\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1041\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1043\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1044\LocalizedData.xml_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1044\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1045\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1055\SetupResources.dll_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\2052\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\2052\SetupResources.dll | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\3076\LocalizedData.xml_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\DisplayIcon.ico_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Extended\UiInfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate2.ico_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate7.ico | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate8.ico | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Save.ico | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\header.bmp_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Strings.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\UiInfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\watermark.bmp_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-International%4Operational.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Known Folders API Service.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Store%4Operational.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx_r00t_{8ew5f6}.ebal | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx | Modified File | Stream |
Not Queried
|
...
|
»