VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan |
vxjqig.exe
Windows Exe (x86-32)
Created at 2020-01-06T02:29:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2020-01-02 01:30 (UTC+1) |
Last Seen | 2020-01-05 13:42 (UTC+1) |
Names | Win32.Trojan.Delshad |
Families | Delshad |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x425bb0 |
Size Of Code | 0x2ce00 |
Size Of Initialized Data | 0x1a200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-12-05 04:10:51+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x2cdcc | 0x2ce00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.69 |
.data | 0x42e000 | 0x1463c | 0x3600 | 0x2d200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.56 |
.rsrc | 0x443000 | 0x2cc0 | 0x2e00 | 0x30800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.43 |
.reloc | 0x446000 | 0x391a | 0x3a00 | 0x33600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 3.66 |
Imports (2)
»
KERNEL32.dll (83)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetSystemWindowsDirectoryW | 0x0 | 0x401000 | 0x2d620 | 0x2ca20 | 0x252 |
QueryDosDeviceA | 0x0 | 0x401004 | 0x2d624 | 0x2ca24 | 0x34d |
GetTickCount | 0x0 | 0x401008 | 0x2d628 | 0x2ca28 | 0x266 |
EnumCalendarInfoExW | 0x0 | 0x40100c | 0x2d62c | 0x2ca2c | 0xdd |
ReadConsoleW | 0x0 | 0x401010 | 0x2d630 | 0x2ca30 | 0x366 |
CreateActCtxW | 0x0 | 0x401014 | 0x2d634 | 0x2ca34 | 0x68 |
AddRefActCtx | 0x0 | 0x401018 | 0x2d638 | 0x2ca38 | 0x9 |
LoadLibraryW | 0x0 | 0x40101c | 0x2d63c | 0x2ca3c | 0x2f4 |
SetCommConfig | 0x0 | 0x401020 | 0x2d640 | 0x2ca40 | 0x39d |
GetConsoleWindow | 0x0 | 0x401024 | 0x2d644 | 0x2ca44 | 0x1a0 |
SetConsoleMode | 0x0 | 0x401028 | 0x2d648 | 0x2ca48 | 0x3b7 |
IsBadWritePtr | 0x0 | 0x40102c | 0x2d64c | 0x2ca4c | 0x2cb |
GetOverlappedResult | 0x0 | 0x401030 | 0x2d650 | 0x2ca50 | 0x214 |
InterlockedIncrement | 0x0 | 0x401034 | 0x2d654 | 0x2ca54 | 0x2c0 |
GetProcAddress | 0x0 | 0x401038 | 0x2d658 | 0x2ca58 | 0x220 |
GetProcessHeaps | 0x0 | 0x40103c | 0x2d65c | 0x2ca5c | 0x224 |
ResetEvent | 0x0 | 0x401040 | 0x2d660 | 0x2ca60 | 0x38a |
WriteConsoleA | 0x0 | 0x401044 | 0x2d664 | 0x2ca64 | 0x482 |
LocalAlloc | 0x0 | 0x401048 | 0x2d668 | 0x2ca68 | 0x2f9 |
CreateEventW | 0x0 | 0x40104c | 0x2d66c | 0x2ca6c | 0x75 |
lstrcatW | 0x0 | 0x401050 | 0x2d670 | 0x2ca70 | 0x4a7 |
EndUpdateResourceA | 0x0 | 0x401054 | 0x2d674 | 0x2ca74 | 0xd7 |
GetCPInfo | 0x0 | 0x401058 | 0x2d678 | 0x2ca78 | 0x15b |
EnumDateFormatsExW | 0x0 | 0x40105c | 0x2d67c | 0x2ca7c | 0xe2 |
lstrlenA | 0x0 | 0x401060 | 0x2d680 | 0x2ca80 | 0x4b5 |
GetStringTypeExA | 0x0 | 0x401064 | 0x2d684 | 0x2ca84 | 0x23e |
FindFirstChangeNotificationW | 0x0 | 0x401068 | 0x2d688 | 0x2ca88 | 0x11c |
HeapValidate | 0x0 | 0x40106c | 0x2d68c | 0x2ca8c | 0x2a9 |
IsBadReadPtr | 0x0 | 0x401070 | 0x2d690 | 0x2ca90 | 0x2c8 |
RaiseException | 0x0 | 0x401074 | 0x2d694 | 0x2ca94 | 0x35a |
TerminateProcess | 0x0 | 0x401078 | 0x2d698 | 0x2ca98 | 0x42d |
GetCurrentProcess | 0x0 | 0x40107c | 0x2d69c | 0x2ca9c | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x401080 | 0x2d6a0 | 0x2caa0 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x401084 | 0x2d6a4 | 0x2caa4 | 0x415 |
IsDebuggerPresent | 0x0 | 0x401088 | 0x2d6a8 | 0x2caa8 | 0x2d1 |
DeleteCriticalSection | 0x0 | 0x40108c | 0x2d6ac | 0x2caac | 0xbe |
EnterCriticalSection | 0x0 | 0x401090 | 0x2d6b0 | 0x2cab0 | 0xd9 |
LeaveCriticalSection | 0x0 | 0x401094 | 0x2d6b4 | 0x2cab4 | 0x2ef |
GetModuleFileNameW | 0x0 | 0x401098 | 0x2d6b8 | 0x2cab8 | 0x1f5 |
GetModuleHandleW | 0x0 | 0x40109c | 0x2d6bc | 0x2cabc | 0x1f9 |
Sleep | 0x0 | 0x4010a0 | 0x2d6c0 | 0x2cac0 | 0x421 |
InterlockedDecrement | 0x0 | 0x4010a4 | 0x2d6c4 | 0x2cac4 | 0x2bc |
ExitProcess | 0x0 | 0x4010a8 | 0x2d6c8 | 0x2cac8 | 0x104 |
TlsGetValue | 0x0 | 0x4010ac | 0x2d6cc | 0x2cacc | 0x434 |
TlsSetValue | 0x0 | 0x4010b0 | 0x2d6d0 | 0x2cad0 | 0x435 |
GetCurrentThreadId | 0x0 | 0x4010b4 | 0x2d6d4 | 0x2cad4 | 0x1ad |
SetLastError | 0x0 | 0x4010b8 | 0x2d6d8 | 0x2cad8 | 0x3ec |
GetLastError | 0x0 | 0x4010bc | 0x2d6dc | 0x2cadc | 0x1e6 |
HeapAlloc | 0x0 | 0x4010c0 | 0x2d6e0 | 0x2cae0 | 0x29d |
GetModuleFileNameA | 0x0 | 0x4010c4 | 0x2d6e4 | 0x2cae4 | 0x1f4 |
HeapReAlloc | 0x0 | 0x4010c8 | 0x2d6e8 | 0x2cae8 | 0x2a4 |
HeapFree | 0x0 | 0x4010cc | 0x2d6ec | 0x2caec | 0x2a1 |
VirtualFree | 0x0 | 0x4010d0 | 0x2d6f0 | 0x2caf0 | 0x457 |
VirtualAlloc | 0x0 | 0x4010d4 | 0x2d6f4 | 0x2caf4 | 0x454 |
GetACP | 0x0 | 0x4010d8 | 0x2d6f8 | 0x2caf8 | 0x152 |
GetOEMCP | 0x0 | 0x4010dc | 0x2d6fc | 0x2cafc | 0x213 |
IsValidCodePage | 0x0 | 0x4010e0 | 0x2d700 | 0x2cb00 | 0x2db |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4010e4 | 0x2d704 | 0x2cb04 | 0x2b5 |
WriteFile | 0x0 | 0x4010e8 | 0x2d708 | 0x2cb08 | 0x48d |
GetStdHandle | 0x0 | 0x4010ec | 0x2d70c | 0x2cb0c | 0x23b |
DebugBreak | 0x0 | 0x4010f0 | 0x2d710 | 0x2cb10 | 0xb4 |
OutputDebugStringA | 0x0 | 0x4010f4 | 0x2d714 | 0x2cb14 | 0x33a |
WriteConsoleW | 0x0 | 0x4010f8 | 0x2d718 | 0x2cb18 | 0x48c |
GetFileType | 0x0 | 0x4010fc | 0x2d71c | 0x2cb1c | 0x1d7 |
OutputDebugStringW | 0x0 | 0x401100 | 0x2d720 | 0x2cb20 | 0x33b |
RtlUnwind | 0x0 | 0x401104 | 0x2d724 | 0x2cb24 | 0x392 |
LoadLibraryA | 0x0 | 0x401108 | 0x2d728 | 0x2cb28 | 0x2f1 |
WideCharToMultiByte | 0x0 | 0x40110c | 0x2d72c | 0x2cb2c | 0x47a |
MultiByteToWideChar | 0x0 | 0x401110 | 0x2d730 | 0x2cb30 | 0x31a |
LCMapStringA | 0x0 | 0x401114 | 0x2d734 | 0x2cb34 | 0x2e1 |
LCMapStringW | 0x0 | 0x401118 | 0x2d738 | 0x2cb38 | 0x2e3 |
GetStringTypeA | 0x0 | 0x40111c | 0x2d73c | 0x2cb3c | 0x23d |
GetStringTypeW | 0x0 | 0x401120 | 0x2d740 | 0x2cb40 | 0x240 |
GetLocaleInfoA | 0x0 | 0x401124 | 0x2d744 | 0x2cb44 | 0x1e8 |
SetFilePointer | 0x0 | 0x401128 | 0x2d748 | 0x2cb48 | 0x3df |
GetConsoleCP | 0x0 | 0x40112c | 0x2d74c | 0x2cb4c | 0x183 |
GetConsoleMode | 0x0 | 0x401130 | 0x2d750 | 0x2cb50 | 0x195 |
SetStdHandle | 0x0 | 0x401134 | 0x2d754 | 0x2cb54 | 0x3fc |
GetConsoleOutputCP | 0x0 | 0x401138 | 0x2d758 | 0x2cb58 | 0x199 |
CreateFileA | 0x0 | 0x40113c | 0x2d75c | 0x2cb5c | 0x78 |
CloseHandle | 0x0 | 0x401140 | 0x2d760 | 0x2cb60 | 0x43 |
FlushFileBuffers | 0x0 | 0x401144 | 0x2d764 | 0x2cb64 | 0x141 |
GetModuleHandleA | 0x0 | 0x401148 | 0x2d768 | 0x2cb68 | 0x1f6 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCursor | 0x0 | 0x401150 | 0x2d770 | 0x2cb70 | 0x116 |
Exports (1)
»
Api name | EAT Address | Ordinal |
---|---|---|
@dfyldfg@0 | 0x25850 | 0x1 |
Memory Dumps (8)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
vxjqig.exe | 1 | 0x00400000 | 0x00449FFF | Relevant Image | - | 32-bit | - |
...
|
||
buffer | 1 | 0x005F5E40 | 0x005F9C70 | Marked Executable | - | 32-bit | 0x005F5E40 |
...
|
||
buffer | 1 | 0x00460000 | 0x00466FFF | First Execution | - | 32-bit | 0x00460000 |
...
|
||
vxjqig.exe | 1 | 0x00400000 | 0x00449FFF | Content Changed | - | 32-bit | 0x00403350 |
...
|
||
vxjqig.exe | 1 | 0x00400000 | 0x00449FFF | Content Changed | - | 32-bit | 0x00402FE0 |
...
|
||
vxjqig.exe | 1 | 0x00400000 | 0x00449FFF | Content Changed | - | 32-bit | 0x00403293 |
...
|
||
vxjqig.exe | 1 | 0x00400000 | 0x00449FFF | Final Dump | - | 32-bit | 0x00402DE2 |
...
|
||
vxjqig.exe | 1 | 0x00400000 | 0x00449FFF | Content Changed | - | 32-bit | 0x00401150 |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKDZ.61414 |
Malicious
|
\\?\C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\GetCurrentRollback.ini_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd_r00t_{nhhHyu}.payload | Dropped File | Batch |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\preoobe.cmd | Modified File | Batch |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\SetupComplete.cmd_r00t_{nhhHyu}.payload | Dropped File | Batch |
Unknown
|
...
|
»
\\?\C:\$WINRE_BACKUP_PARTITION.MARKER | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1025\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1025\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1025\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1028\eula.rtf_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1028\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1028\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1029\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1029\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1029\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1030\LocalizedData.xml_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1030\SetupResources.dll_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1031\eula.rtf_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1031\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1031\SetupResources.dll_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1032\eula.rtf_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1032\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1032\SetupResources.dll_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1033\eula.rtf_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1033\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1033\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1035\eula.rtf_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1035\LocalizedData.xml_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1035\SetupResources.dll_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1036\eula.rtf_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1036\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1036\SetupResources.dll_r00t_{nhhHyu}.payload | Dropped File | Binary |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1037\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1037\LocalizedData.xml_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1037\SetupResources.dll_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1038\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1038\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1040\LocalizedData.xml_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1040\SetupResources.dll_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1041\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1041\LocalizedData.xml_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1041\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1042\eula.rtf_r00t_{nhhHyu}.payload | Dropped File | Binary |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1042\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1042\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1043\eula.rtf_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1043\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1043\SetupResources.dll_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1044\eula.rtf_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1044\LocalizedData.xml_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1044\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1045\eula.rtf_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1045\LocalizedData.xml_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1045\SetupResources.dll_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1046\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1046\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1046\SetupResources.dll_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1049\eula.rtf_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1049\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1049\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1053\eula.rtf_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1053\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1053\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1055\eula.rtf_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1055\LocalizedData.xml_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1055\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2052\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2052\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2052\SetupResources.dll_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2070\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2070\LocalizedData.xml_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2070\SetupResources.dll_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3076\eula.rtf_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3076\LocalizedData.xml_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3076\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3082\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3082\LocalizedData.xml_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3082\SetupResources.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Client\Parameterinfo.xml_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Client\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\DHtmlHeader.html | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\DisplayIcon.ico_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Extended\Parameterinfo.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Extended\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Print.ico_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate1.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate2.ico_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate3.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate4.ico_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate5.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate6.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate7.ico | Modified File | Binary |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate8.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Save.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Setup.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\stop.ico_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\SysReqMet.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\warn.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\header.bmp_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Core.mzz_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Core_x64.msi_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Core_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Extended.mzz | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Extended_x64.msi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Extended_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\ParameterInfo.xml_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\RGB9RAST_x64.msi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\RGB9Rast_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Setup.exe | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\SetupEngine.dll_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\SetupUi.dll_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\SetupUi.xsd_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\SetupUtility.exe | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\SplashScreen.bmp_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\sqmapi.dll | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Strings.xml_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\UiInfo.xml_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\watermark.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Boot\BCD.LOG2_r00t_{nhhHyu}.payload | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Extended\---==%$$$OPEN_ME_UP$$$==---.txt | Dropped File | Text |
Unknown
|
...
|
»