VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Sodinokibi
Gen:Variant.Zusy.312578
Generic.EmotetU.4295B2B2
...
|
XColorPickerXPTest.exe
Windows Exe (x86-32)
Created at 2020-09-03T22:53:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\XColorPickerXPTest.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4082d0 |
Size Of Code | 0x1d000 |
Size Of Initialized Data | 0x7a000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-09-01 08:21:52+00:00 |
Version Information (8)
»
Article | www.codeproject.com |
hdietrich@gmail.com | |
FileDescription | XColorPickerXPTest MFC Application |
FileVersion | 1, 0, 0, 1 |
LegalCopyright | Copyright © 2008 Hans Dietrich |
OriginalFilename | XColorPickerXPTest.exe |
ProductName | XColorPickerXPTest Application |
ProductVersion | 1, 0, 0, 1 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1c1b4 | 0x1d000 | 0x1000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.49 |
.rdata | 0x41e000 | 0x8418 | 0x9000 | 0x1e000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.65 |
.data | 0x427000 | 0x72b4 | 0x3000 | 0x27000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.4 |
.rsrc | 0x42f000 | 0x688b0 | 0x69000 | 0x2a000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.43 |
Imports (10)
»
KERNEL32.dll (110)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VirtualProtect | 0x0 | 0x41e0b8 | 0x24d58 | 0x24d58 | 0x379 |
GetSystemInfo | 0x0 | 0x41e0bc | 0x24d5c | 0x24d5c | 0x1bb |
VirtualQuery | 0x0 | 0x41e0c0 | 0x24d60 | 0x24d60 | 0x37b |
GetStartupInfoA | 0x0 | 0x41e0c4 | 0x24d64 | 0x24d64 | 0x1af |
GetCommandLineA | 0x0 | 0x41e0c8 | 0x24d68 | 0x24d68 | 0x108 |
ExitProcess | 0x0 | 0x41e0cc | 0x24d6c | 0x24d6c | 0xaf |
HeapReAlloc | 0x0 | 0x41e0d0 | 0x24d70 | 0x24d70 | 0x210 |
TerminateProcess | 0x0 | 0x41e0d4 | 0x24d74 | 0x24d74 | 0x34f |
HeapSize | 0x0 | 0x41e0d8 | 0x24d78 | 0x24d78 | 0x212 |
HeapDestroy | 0x0 | 0x41e0dc | 0x24d7c | 0x24d7c | 0x20a |
HeapCreate | 0x0 | 0x41e0e0 | 0x24d80 | 0x24d80 | 0x208 |
VirtualFree | 0x0 | 0x41e0e4 | 0x24d84 | 0x24d84 | 0x376 |
IsBadWritePtr | 0x0 | 0x41e0e8 | 0x24d88 | 0x24d88 | 0x22c |
GetStdHandle | 0x0 | 0x41e0ec | 0x24d8c | 0x24d8c | 0x1b1 |
UnhandledExceptionFilter | 0x0 | 0x41e0f0 | 0x24d90 | 0x24d90 | 0x360 |
FreeEnvironmentStringsA | 0x0 | 0x41e0f4 | 0x24d94 | 0x24d94 | 0xed |
GetEnvironmentStrings | 0x0 | 0x41e0f8 | 0x24d98 | 0x24d98 | 0x14d |
FreeEnvironmentStringsW | 0x0 | 0x41e0fc | 0x24d9c | 0x24d9c | 0xee |
GetEnvironmentStringsW | 0x0 | 0x41e100 | 0x24da0 | 0x24da0 | 0x14f |
SetHandleCount | 0x0 | 0x41e104 | 0x24da4 | 0x24da4 | 0x317 |
HeapFree | 0x0 | 0x41e108 | 0x24da8 | 0x24da8 | 0x20c |
QueryPerformanceCounter | 0x0 | 0x41e10c | 0x24dac | 0x24dac | 0x297 |
GetTickCount | 0x0 | 0x41e110 | 0x24db0 | 0x24db0 | 0x1d5 |
GetCurrentProcessId | 0x0 | 0x41e114 | 0x24db4 | 0x24db4 | 0x13b |
GetSystemTimeAsFileTime | 0x0 | 0x41e118 | 0x24db8 | 0x24db8 | 0x1c0 |
SetUnhandledExceptionFilter | 0x0 | 0x41e11c | 0x24dbc | 0x24dbc | 0x33b |
LCMapStringA | 0x0 | 0x41e120 | 0x24dc0 | 0x24dc0 | 0x23a |
LCMapStringW | 0x0 | 0x41e124 | 0x24dc4 | 0x24dc4 | 0x23b |
GetStringTypeA | 0x0 | 0x41e128 | 0x24dc8 | 0x24dc8 | 0x1b2 |
GetStringTypeW | 0x0 | 0x41e12c | 0x24dcc | 0x24dcc | 0x1b5 |
IsBadReadPtr | 0x0 | 0x41e130 | 0x24dd0 | 0x24dd0 | 0x229 |
IsBadCodePtr | 0x0 | 0x41e134 | 0x24dd4 | 0x24dd4 | 0x226 |
SetStdHandle | 0x0 | 0x41e138 | 0x24dd8 | 0x24dd8 | 0x32a |
HeapAlloc | 0x0 | 0x41e13c | 0x24ddc | 0x24ddc | 0x206 |
RtlUnwind | 0x0 | 0x41e140 | 0x24de0 | 0x24de0 | 0x2ca |
SetErrorMode | 0x0 | 0x41e144 | 0x24de4 | 0x24de4 | 0x308 |
GetCurrentProcess | 0x0 | 0x41e148 | 0x24de8 | 0x24de8 | 0x13a |
FlushFileBuffers | 0x0 | 0x41e14c | 0x24dec | 0x24dec | 0xe5 |
SetFilePointer | 0x0 | 0x41e150 | 0x24df0 | 0x24df0 | 0x30e |
WriteFile | 0x0 | 0x41e154 | 0x24df4 | 0x24df4 | 0x394 |
ReadFile | 0x0 | 0x41e158 | 0x24df8 | 0x24df8 | 0x2a9 |
GetOEMCP | 0x0 | 0x41e15c | 0x24dfc | 0x24dfc | 0x18b |
GetCPInfo | 0x0 | 0x41e160 | 0x24e00 | 0x24e00 | 0xfc |
InterlockedIncrement | 0x0 | 0x41e164 | 0x24e04 | 0x24e04 | 0x222 |
TlsFree | 0x0 | 0x41e168 | 0x24e08 | 0x24e08 | 0x355 |
LocalReAlloc | 0x0 | 0x41e16c | 0x24e0c | 0x24e0c | 0x255 |
TlsSetValue | 0x0 | 0x41e170 | 0x24e10 | 0x24e10 | 0x357 |
TlsAlloc | 0x0 | 0x41e174 | 0x24e14 | 0x24e14 | 0x354 |
TlsGetValue | 0x0 | 0x41e178 | 0x24e18 | 0x24e18 | 0x356 |
EnterCriticalSection | 0x0 | 0x41e17c | 0x24e1c | 0x24e1c | 0x8f |
GlobalHandle | 0x0 | 0x41e180 | 0x24e20 | 0x24e20 | 0x1f8 |
GlobalReAlloc | 0x0 | 0x41e184 | 0x24e24 | 0x24e24 | 0x1fc |
LeaveCriticalSection | 0x0 | 0x41e188 | 0x24e28 | 0x24e28 | 0x247 |
LocalAlloc | 0x0 | 0x41e18c | 0x24e2c | 0x24e2c | 0x24e |
GlobalFlags | 0x0 | 0x41e190 | 0x24e30 | 0x24e30 | 0x1f4 |
DeleteCriticalSection | 0x0 | 0x41e194 | 0x24e34 | 0x24e34 | 0x7a |
InitializeCriticalSection | 0x0 | 0x41e198 | 0x24e38 | 0x24e38 | 0x219 |
RaiseException | 0x0 | 0x41e19c | 0x24e3c | 0x24e3c | 0x29b |
InterlockedDecrement | 0x0 | 0x41e1a0 | 0x24e40 | 0x24e40 | 0x21e |
GetPrivateProfileStringA | 0x0 | 0x41e1a4 | 0x24e44 | 0x24e44 | 0x194 |
WritePrivateProfileStringA | 0x0 | 0x41e1a8 | 0x24e48 | 0x24e48 | 0x399 |
GetPrivateProfileIntA | 0x0 | 0x41e1ac | 0x24e4c | 0x24e4c | 0x18e |
CloseHandle | 0x0 | 0x41e1b0 | 0x24e50 | 0x24e50 | 0x2e |
GetCurrentThread | 0x0 | 0x41e1b4 | 0x24e54 | 0x24e54 | 0x13d |
lstrcmpA | 0x0 | 0x41e1b8 | 0x24e58 | 0x24e58 | 0x3b0 |
ConvertDefaultLocale | 0x0 | 0x41e1bc | 0x24e5c | 0x24e5c | 0x39 |
EnumResourceLanguagesA | 0x0 | 0x41e1c0 | 0x24e60 | 0x24e60 | 0x9a |
lstrcpyA | 0x0 | 0x41e1c4 | 0x24e64 | 0x24e64 | 0x3b6 |
SetLastError | 0x0 | 0x41e1c8 | 0x24e68 | 0x24e68 | 0x31b |
GlobalAlloc | 0x0 | 0x41e1cc | 0x24e6c | 0x24e6c | 0x1ee |
FormatMessageA | 0x0 | 0x41e1d0 | 0x24e70 | 0x24e70 | 0xea |
LocalFree | 0x0 | 0x41e1d4 | 0x24e74 | 0x24e74 | 0x252 |
GlobalGetAtomNameA | 0x0 | 0x41e1d8 | 0x24e78 | 0x24e78 | 0x1f6 |
GlobalAddAtomA | 0x0 | 0x41e1dc | 0x24e7c | 0x24e7c | 0x1ec |
GlobalFindAtomA | 0x0 | 0x41e1e0 | 0x24e80 | 0x24e80 | 0x1f1 |
GlobalDeleteAtom | 0x0 | 0x41e1e4 | 0x24e84 | 0x24e84 | 0x1f0 |
lstrcatA | 0x0 | 0x41e1e8 | 0x24e88 | 0x24e88 | 0x3ad |
lstrcmpW | 0x0 | 0x41e1ec | 0x24e8c | 0x24e8c | 0x3b1 |
lstrcpynA | 0x0 | 0x41e1f0 | 0x24e90 | 0x24e90 | 0x3b9 |
GetModuleHandleA | 0x0 | 0x41e1f4 | 0x24e94 | 0x24e94 | 0x177 |
GlobalLock | 0x0 | 0x41e1f8 | 0x24e98 | 0x24e98 | 0x1f9 |
GlobalUnlock | 0x0 | 0x41e1fc | 0x24e9c | 0x24e9c | 0x200 |
GlobalFree | 0x0 | 0x41e200 | 0x24ea0 | 0x24ea0 | 0x1f5 |
FreeResource | 0x0 | 0x41e204 | 0x24ea4 | 0x24ea4 | 0xf1 |
GetWindowsDirectoryA | 0x0 | 0x41e208 | 0x24ea8 | 0x24ea8 | 0x1e9 |
LoadLibraryA | 0x0 | 0x41e20c | 0x24eac | 0x24eac | 0x248 |
FreeLibrary | 0x0 | 0x41e210 | 0x24eb0 | 0x24eb0 | 0xef |
WinExec | 0x0 | 0x41e214 | 0x24eb4 | 0x24eb4 | 0x388 |
VirtualAlloc | 0x0 | 0x41e218 | 0x24eb8 | 0x24eb8 | 0x373 |
LoadLibraryW | 0x0 | 0x41e21c | 0x24ebc | 0x24ebc | 0x24b |
GetProcAddress | 0x0 | 0x41e220 | 0x24ec0 | 0x24ec0 | 0x198 |
GetCurrentThreadId | 0x0 | 0x41e224 | 0x24ec4 | 0x24ec4 | 0x13e |
GetModuleFileNameA | 0x0 | 0x41e228 | 0x24ec8 | 0x24ec8 | 0x175 |
lstrlenA | 0x0 | 0x41e22c | 0x24ecc | 0x24ecc | 0x3bc |
lstrcmpiA | 0x0 | 0x41e230 | 0x24ed0 | 0x24ed0 | 0x3b3 |
GetVersion | 0x0 | 0x41e234 | 0x24ed4 | 0x24ed4 | 0x1de |
GetLastError | 0x0 | 0x41e238 | 0x24ed8 | 0x24ed8 | 0x169 |
MultiByteToWideChar | 0x0 | 0x41e23c | 0x24edc | 0x24edc | 0x26b |
MulDiv | 0x0 | 0x41e240 | 0x24ee0 | 0x24ee0 | 0x26a |
WideCharToMultiByte | 0x0 | 0x41e244 | 0x24ee4 | 0x24ee4 | 0x387 |
FindResourceA | 0x0 | 0x41e248 | 0x24ee8 | 0x24ee8 | 0xda |
LoadResource | 0x0 | 0x41e24c | 0x24eec | 0x24eec | 0x24d |
LockResource | 0x0 | 0x41e250 | 0x24ef0 | 0x24ef0 | 0x25b |
SizeofResource | 0x0 | 0x41e254 | 0x24ef4 | 0x24ef4 | 0x346 |
GetVersionExA | 0x0 | 0x41e258 | 0x24ef8 | 0x24ef8 | 0x1df |
GetThreadLocale | 0x0 | 0x41e25c | 0x24efc | 0x24efc | 0x1d0 |
GetLocaleInfoA | 0x0 | 0x41e260 | 0x24f00 | 0x24f00 | 0x16c |
GetACP | 0x0 | 0x41e264 | 0x24f04 | 0x24f04 | 0xf5 |
GetFileType | 0x0 | 0x41e268 | 0x24f08 | 0x24f08 | 0x15e |
InterlockedExchange | 0x0 | 0x41e26c | 0x24f0c | 0x24f0c | 0x21f |
USER32.dll (121)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetSysColorBrush | 0x0 | 0x41e298 | 0x24f38 | 0x24f38 | 0x15b |
WindowFromPoint | 0x0 | 0x41e29c | 0x24f3c | 0x24f3c | 0x2d3 |
DestroyMenu | 0x0 | 0x41e2a0 | 0x24f40 | 0x24f40 | 0x97 |
GetMessageA | 0x0 | 0x41e2a4 | 0x24f44 | 0x24f44 | 0x13a |
TranslateMessage | 0x0 | 0x41e2a8 | 0x24f48 | 0x24f48 | 0x2aa |
GetCursorPos | 0x0 | 0x41e2ac | 0x24f4c | 0x24f4c | 0x10b |
ValidateRect | 0x0 | 0x41e2b0 | 0x24f50 | 0x24f50 | 0x2c3 |
PostQuitMessage | 0x0 | 0x41e2b4 | 0x24f54 | 0x24f54 | 0x203 |
EndPaint | 0x0 | 0x41e2b8 | 0x24f58 | 0x24f58 | 0xc8 |
BeginPaint | 0x0 | 0x41e2bc | 0x24f5c | 0x24f5c | 0xd |
ClientToScreen | 0x0 | 0x41e2c0 | 0x24f60 | 0x24f60 | 0x40 |
GrayStringA | 0x0 | 0x41e2c4 | 0x24f64 | 0x24f64 | 0x17d |
DrawTextExA | 0x0 | 0x41e2c8 | 0x24f68 | 0x24f68 | 0xbd |
DrawTextA | 0x0 | 0x41e2cc | 0x24f6c | 0x24f6c | 0xbc |
TabbedTextOutA | 0x0 | 0x41e2d0 | 0x24f70 | 0x24f70 | 0x29b |
wsprintfA | 0x0 | 0x41e2d4 | 0x24f74 | 0x24f74 | 0x2d6 |
SetMenuItemBitmaps | 0x0 | 0x41e2d8 | 0x24f78 | 0x24f78 | 0x261 |
ModifyMenuA | 0x0 | 0x41e2dc | 0x24f7c | 0x24f7c | 0x1e6 |
GetMenuState | 0x0 | 0x41e2e0 | 0x24f80 | 0x24f80 | 0x137 |
EnableMenuItem | 0x0 | 0x41e2e4 | 0x24f84 | 0x24f84 | 0xc2 |
CheckMenuItem | 0x0 | 0x41e2e8 | 0x24f88 | 0x24f88 | 0x39 |
GetMenuCheckMarkDimensions | 0x0 | 0x41e2ec | 0x24f8c | 0x24f8c | 0x12e |
LoadBitmapA | 0x0 | 0x41e2f0 | 0x24f90 | 0x24f90 | 0x1b7 |
ShowWindow | 0x0 | 0x41e2f4 | 0x24f94 | 0x24f94 | 0x292 |
MoveWindow | 0x0 | 0x41e2f8 | 0x24f98 | 0x24f98 | 0x1eb |
SetWindowTextA | 0x0 | 0x41e2fc | 0x24f9c | 0x24f9c | 0x286 |
IsDialogMessageA | 0x0 | 0x41e300 | 0x24fa0 | 0x24fa0 | 0x1a1 |
WinHelpA | 0x0 | 0x41e304 | 0x24fa4 | 0x24fa4 | 0x2d0 |
GetCapture | 0x0 | 0x41e308 | 0x24fa8 | 0x24fa8 | 0xf3 |
GetClassLongA | 0x0 | 0x41e30c | 0x24fac | 0x24fac | 0xfa |
GetClassInfoExA | 0x0 | 0x41e310 | 0x24fb0 | 0x24fb0 | 0xf7 |
GetClassNameA | 0x0 | 0x41e314 | 0x24fb4 | 0x24fb4 | 0xfc |
SetPropA | 0x0 | 0x41e318 | 0x24fb8 | 0x24fb8 | 0x26a |
RemovePropA | 0x0 | 0x41e31c | 0x24fbc | 0x24fbc | 0x22c |
SendDlgItemMessageA | 0x0 | 0x41e320 | 0x24fc0 | 0x24fc0 | 0x236 |
GetFocus | 0x0 | 0x41e324 | 0x24fc4 | 0x24fc4 | 0x116 |
SetFocus | 0x0 | 0x41e328 | 0x24fc8 | 0x24fc8 | 0x256 |
GetWindowTextLengthA | 0x0 | 0x41e32c | 0x24fcc | 0x24fcc | 0x178 |
GetWindowTextA | 0x0 | 0x41e330 | 0x24fd0 | 0x24fd0 | 0x177 |
GetForegroundWindow | 0x0 | 0x41e334 | 0x24fd4 | 0x24fd4 | 0x117 |
GetLastActivePopup | 0x0 | 0x41e338 | 0x24fd8 | 0x24fd8 | 0x128 |
DispatchMessageA | 0x0 | 0x41e33c | 0x24fdc | 0x24fdc | 0xa1 |
GetTopWindow | 0x0 | 0x41e340 | 0x24fe0 | 0x24fe0 | 0x163 |
PeekMessageA | 0x0 | 0x41e344 | 0x24fe4 | 0x24fe4 | 0x1ff |
MapWindowPoints | 0x0 | 0x41e348 | 0x24fe8 | 0x24fe8 | 0x1d9 |
MessageBoxA | 0x0 | 0x41e34c | 0x24fec | 0x24fec | 0x1de |
GetKeyState | 0x0 | 0x41e350 | 0x24ff0 | 0x24ff0 | 0x121 |
SetForegroundWindow | 0x0 | 0x41e354 | 0x24ff4 | 0x24ff4 | 0x257 |
IsWindowVisible | 0x0 | 0x41e358 | 0x24ff8 | 0x24ff8 | 0x1b1 |
GetMenu | 0x0 | 0x41e35c | 0x24ffc | 0x24ffc | 0x12c |
GetSubMenu | 0x0 | 0x41e360 | 0x25000 | 0x25000 | 0x159 |
GetMenuItemID | 0x0 | 0x41e364 | 0x25004 | 0x25004 | 0x133 |
GetMenuItemCount | 0x0 | 0x41e368 | 0x25008 | 0x25008 | 0x132 |
AdjustWindowRectEx | 0x0 | 0x41e36c | 0x2500c | 0x2500c | 0x2 |
GetClassInfoA | 0x0 | 0x41e370 | 0x25010 | 0x25010 | 0xf6 |
UnregisterClassA | 0x0 | 0x41e374 | 0x25014 | 0x25014 | 0x2b3 |
GetDlgCtrlID | 0x0 | 0x41e378 | 0x25018 | 0x25018 | 0x110 |
CallWindowProcA | 0x0 | 0x41e37c | 0x2501c | 0x2501c | 0x1b |
EnableWindow | 0x0 | 0x41e380 | 0x25020 | 0x25020 | 0xc4 |
SetWindowLongA | 0x0 | 0x41e384 | 0x25024 | 0x25024 | 0x280 |
IsWindow | 0x0 | 0x41e388 | 0x25028 | 0x25028 | 0x1ad |
DestroyWindow | 0x0 | 0x41e38c | 0x2502c | 0x2502c | 0x99 |
PostMessageA | 0x0 | 0x41e390 | 0x25030 | 0x25030 | 0x201 |
SendMessageA | 0x0 | 0x41e394 | 0x25034 | 0x25034 | 0x23b |
KillTimer | 0x0 | 0x41e398 | 0x25038 | 0x25038 | 0x1b4 |
CallNextHookEx | 0x0 | 0x41e39c | 0x2503c | 0x2503c | 0x1a |
GetWindowRect | 0x0 | 0x41e3a0 | 0x25040 | 0x25040 | 0x174 |
DefWindowProcA | 0x0 | 0x41e3a4 | 0x25044 | 0x25044 | 0x8e |
SetWindowsHookExA | 0x0 | 0x41e3a8 | 0x25048 | 0x25048 | 0x28a |
GetWindowPlacement | 0x0 | 0x41e3ac | 0x2504c | 0x2504c | 0x173 |
GetWindow | 0x0 | 0x41e3b0 | 0x25050 | 0x25050 | 0x16a |
GetDesktopWindow | 0x0 | 0x41e3b4 | 0x25054 | 0x25054 | 0x10e |
GetActiveWindow | 0x0 | 0x41e3b8 | 0x25058 | 0x25058 | 0xeb |
SetActiveWindow | 0x0 | 0x41e3bc | 0x2505c | 0x2505c | 0x243 |
CreateDialogIndirectParamA | 0x0 | 0x41e3c0 | 0x25060 | 0x25060 | 0x52 |
GetWindowLongA | 0x0 | 0x41e3c4 | 0x25064 | 0x25064 | 0x16e |
GetDlgItem | 0x0 | 0x41e3c8 | 0x25068 | 0x25068 | 0x111 |
IsWindowEnabled | 0x0 | 0x41e3cc | 0x2506c | 0x2506c | 0x1ae |
GetNextDlgTabItem | 0x0 | 0x41e3d0 | 0x25070 | 0x25070 | 0x143 |
EndDialog | 0x0 | 0x41e3d4 | 0x25074 | 0x25074 | 0xc6 |
RegisterWindowMessageA | 0x0 | 0x41e3d8 | 0x25078 | 0x25078 | 0x227 |
CopyIcon | 0x0 | 0x41e3dc | 0x2507c | 0x2507c | 0x48 |
DestroyCursor | 0x0 | 0x41e3e0 | 0x25080 | 0x25080 | 0x95 |
MessageBeep | 0x0 | 0x41e3e4 | 0x25084 | 0x25084 | 0x1dd |
ReleaseDC | 0x0 | 0x41e3e8 | 0x25088 | 0x25088 | 0x22a |
GetDC | 0x0 | 0x41e3ec | 0x2508c | 0x2508c | 0x10c |
ScreenToClient | 0x0 | 0x41e3f0 | 0x25090 | 0x25090 | 0x231 |
SetCursor | 0x0 | 0x41e3f4 | 0x25094 | 0x25094 | 0x24d |
FillRect | 0x0 | 0x41e3f8 | 0x25098 | 0x25098 | 0xe2 |
SystemParametersInfoA | 0x0 | 0x41e3fc | 0x2509c | 0x2509c | 0x299 |
GetMessagePos | 0x0 | 0x41e400 | 0x250a0 | 0x250a0 | 0x13c |
ReleaseCapture | 0x0 | 0x41e404 | 0x250a4 | 0x250a4 | 0x229 |
MapVirtualKeyA | 0x0 | 0x41e408 | 0x250a8 | 0x250a8 | 0x1d5 |
SetCapture | 0x0 | 0x41e40c | 0x250ac | 0x250ac | 0x244 |
InvalidateRect | 0x0 | 0x41e410 | 0x250b0 | 0x250b0 | 0x193 |
DrawEdge | 0x0 | 0x41e414 | 0x250b4 | 0x250b4 | 0xb2 |
GetMessageTime | 0x0 | 0x41e418 | 0x250b8 | 0x250b8 | 0x13d |
CreateWindowExA | 0x0 | 0x41e41c | 0x250bc | 0x250bc | 0x60 |
SetWindowPos | 0x0 | 0x41e420 | 0x250c0 | 0x250c0 | 0x283 |
UpdateWindow | 0x0 | 0x41e424 | 0x250c4 | 0x250c4 | 0x2bb |
UnhookWindowsHookEx | 0x0 | 0x41e428 | 0x250c8 | 0x250c8 | 0x2ae |
LoadStringA | 0x0 | 0x41e42c | 0x250cc | 0x250cc | 0x1ca |
RegisterClassA | 0x0 | 0x41e430 | 0x250d0 | 0x250d0 | 0x216 |
LoadCursorA | 0x0 | 0x41e434 | 0x250d4 | 0x250d4 | 0x1b9 |
CopyRect | 0x0 | 0x41e438 | 0x250d8 | 0x250d8 | 0x4a |
InflateRect | 0x0 | 0x41e43c | 0x250dc | 0x250dc | 0x18a |
FrameRect | 0x0 | 0x41e440 | 0x250e0 | 0x250e0 | 0xe9 |
RedrawWindow | 0x0 | 0x41e444 | 0x250e4 | 0x250e4 | 0x215 |
SetTimer | 0x0 | 0x41e448 | 0x250e8 | 0x250e8 | 0x27a |
GetParent | 0x0 | 0x41e44c | 0x250ec | 0x250ec | 0x145 |
GetSysColor | 0x0 | 0x41e450 | 0x250f0 | 0x250f0 | 0x15a |
DrawIcon | 0x0 | 0x41e454 | 0x250f4 | 0x250f4 | 0xb6 |
AppendMenuA | 0x0 | 0x41e458 | 0x250f8 | 0x250f8 | 0x8 |
GetSystemMenu | 0x0 | 0x41e45c | 0x250fc | 0x250fc | 0x15c |
IsIconic | 0x0 | 0x41e460 | 0x25100 | 0x25100 | 0x1a6 |
SetRect | 0x0 | 0x41e464 | 0x25104 | 0x25104 | 0x26c |
PtInRect | 0x0 | 0x41e468 | 0x25108 | 0x25108 | 0x20b |
GetSystemMetrics | 0x0 | 0x41e46c | 0x2510c | 0x2510c | 0x15d |
LoadIconA | 0x0 | 0x41e470 | 0x25110 | 0x25110 | 0x1bd |
GetClientRect | 0x0 | 0x41e474 | 0x25114 | 0x25114 | 0xff |
GetPropA | 0x0 | 0x41e478 | 0x25118 | 0x25118 | 0x14a |
GDI32.dll (32)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ScaleWindowExtEx | 0x0 | 0x41e034 | 0x24cd4 | 0x24cd4 | 0x209 |
SetWindowExtEx | 0x0 | 0x41e038 | 0x24cd8 | 0x24cd8 | 0x242 |
ScaleViewportExtEx | 0x0 | 0x41e03c | 0x24cdc | 0x24cdc | 0x208 |
SetViewportExtEx | 0x0 | 0x41e040 | 0x24ce0 | 0x24ce0 | 0x23e |
OffsetViewportOrgEx | 0x0 | 0x41e044 | 0x24ce4 | 0x24ce4 | 0x1d5 |
SetViewportOrgEx | 0x0 | 0x41e048 | 0x24ce8 | 0x24ce8 | 0x23f |
SelectObject | 0x0 | 0x41e04c | 0x24cec | 0x24cec | 0x20e |
Escape | 0x0 | 0x41e050 | 0x24cf0 | 0x24cf0 | 0xd4 |
ExtTextOutA | 0x0 | 0x41e054 | 0x24cf4 | 0x24cf4 | 0xdd |
TextOutA | 0x0 | 0x41e058 | 0x24cf8 | 0x24cf8 | 0x24e |
RectVisible | 0x0 | 0x41e05c | 0x24cfc | 0x24cfc | 0x1f5 |
PtVisible | 0x0 | 0x41e060 | 0x24d00 | 0x24d00 | 0x1f1 |
DeleteDC | 0x0 | 0x41e064 | 0x24d04 | 0x24d04 | 0x8c |
DeleteObject | 0x0 | 0x41e068 | 0x24d08 | 0x24d08 | 0x8f |
SetMapMode | 0x0 | 0x41e06c | 0x24d0c | 0x24d0c | 0x22b |
SetBkMode | 0x0 | 0x41e070 | 0x24d10 | 0x24d10 | 0x216 |
RestoreDC | 0x0 | 0x41e074 | 0x24d14 | 0x24d14 | 0x200 |
SaveDC | 0x0 | 0x41e078 | 0x24d18 | 0x24d18 | 0x207 |
CreateBitmap | 0x0 | 0x41e07c | 0x24d1c | 0x24d1c | 0x27 |
SetBkColor | 0x0 | 0x41e080 | 0x24d20 | 0x24d20 | 0x215 |
SetTextColor | 0x0 | 0x41e084 | 0x24d24 | 0x24d24 | 0x23c |
GetClipBox | 0x0 | 0x41e088 | 0x24d28 | 0x24d28 | 0x160 |
GetObjectA | 0x0 | 0x41e08c | 0x24d2c | 0x24d2c | 0x195 |
GetTextExtentPoint32A | 0x0 | 0x41e090 | 0x24d30 | 0x24d30 | 0x1b4 |
Rectangle | 0x0 | 0x41e094 | 0x24d34 | 0x24d34 | 0x1f6 |
CreatePen | 0x0 | 0x41e098 | 0x24d38 | 0x24d38 | 0x47 |
CreateFontIndirectA | 0x0 | 0x41e09c | 0x24d3c | 0x24d3c | 0x3a |
CreateHatchBrush | 0x0 | 0x41e0a0 | 0x24d40 | 0x24d40 | 0x40 |
CreateSolidBrush | 0x0 | 0x41e0a4 | 0x24d44 | 0x24d44 | 0x50 |
GetStockObject | 0x0 | 0x41e0a8 | 0x24d48 | 0x24d48 | 0x1a5 |
CreateDCA | 0x0 | 0x41e0ac | 0x24d4c | 0x24d4c | 0x2e |
GetDeviceCaps | 0x0 | 0x41e0b0 | 0x24d50 | 0x24d50 | 0x16b |
comdlg32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ChooseColorA | 0x0 | 0x41e490 | 0x25130 | 0x25130 | 0x0 |
WINSPOOL.DRV (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
OpenPrinterA | 0x0 | 0x41e480 | 0x25120 | 0x25120 | 0x7d |
DocumentPropertiesA | 0x0 | 0x41e484 | 0x25124 | 0x25124 | 0x46 |
ClosePrinter | 0x0 | 0x41e488 | 0x25128 | 0x25128 | 0x1b |
ADVAPI32.dll (10)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryValueExA | 0x0 | 0x41e000 | 0x24ca0 | 0x24ca0 | 0x1ec |
RegOpenKeyExA | 0x0 | 0x41e004 | 0x24ca4 | 0x24ca4 | 0x1e2 |
RegQueryValueA | 0x0 | 0x41e008 | 0x24ca8 | 0x24ca8 | 0x1eb |
RegOpenKeyA | 0x0 | 0x41e00c | 0x24cac | 0x24cac | 0x1e1 |
RegDeleteKeyA | 0x0 | 0x41e010 | 0x24cb0 | 0x24cb0 | 0x1d0 |
RegEnumKeyA | 0x0 | 0x41e014 | 0x24cb4 | 0x24cb4 | 0x1d5 |
RegCreateKeyExA | 0x0 | 0x41e018 | 0x24cb8 | 0x24cb8 | 0x1cd |
RegSetValueExA | 0x0 | 0x41e01c | 0x24cbc | 0x24cbc | 0x1f9 |
RegDeleteValueA | 0x0 | 0x41e020 | 0x24cc0 | 0x24cc0 | 0x1d2 |
RegCloseKey | 0x0 | 0x41e024 | 0x24cc4 | 0x24cc4 | 0x1c9 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteA | 0x0 | 0x41e284 | 0x24f24 | 0x24f24 | 0x106 |
COMCTL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x11 | 0x41e02c | 0x24ccc | 0x24ccc | - |
SHLWAPI.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathFindFileNameA | 0x0 | 0x41e28c | 0x24f2c | 0x24f2c | 0x2b |
PathFindExtensionA | 0x0 | 0x41e290 | 0x24f30 | 0x24f30 | 0x29 |
OLEAUT32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VariantClear | 0x9 | 0x41e274 | 0x24f14 | 0x24f14 | - |
VariantChangeType | 0xc | 0x41e278 | 0x24f18 | 0x24f18 | - |
VariantInit | 0x8 | 0x41e27c | 0x24f1c | 0x24f1c | - |
Memory Dumps (6)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
xcolorpickerxptest.exe | 1 | 0x00400000 | 0x00497FFF | Relevant Image | 32-bit | 0x0040A8CA |
...
|
|||
buffer | 1 | 0x00650000 | 0x00650FFF | First Execution | 32-bit | 0x00650000 |
...
|
|||
buffer | 1 | 0x00780000 | 0x007AAFFF | First Execution | 32-bit | 0x00780000 |
...
|
|||
buffer | 1 | 0x007B0000 | 0x007DCFFF | First Execution | 32-bit | 0x007B2A20 |
...
|
|||
buffer | 1 | 0x007E0000 | 0x0080AFFF | Marked Executable | 32-bit | - |
...
|
|||
xcolorpickerxptest.exe | 1 | 0x00400000 | 0x00497FFF | Final Dump | 32-bit | - |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Zusy.312578 |
Malicious
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
SodinokibiEncryptedFile | File encrypted by Sodinokibi Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\DHtmlHeader.html | Modified File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DisplayIcon.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Strings.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\HardwareEvents.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Key Management Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-International%4Operational.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Known Folders API Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\desktop.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\preoobe.cmd.UAKXC | Dropped File | Batch |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\SetupComplete.cmd.UAKXC | Dropped File | Batch |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\eula.rtf.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\LocalizedData.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\LocalizedData.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1031\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\eula.rtf.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\eula.rtf.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\LocalizedData.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\eula.rtf.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\LocalizedData.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\LocalizedData.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\LocalizedData.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\Parameterinfo.xml | Modified File | Binary |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\LocalizedData.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\Parameterinfo.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\LocalizedData.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate1.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Client\UiInfo.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Extended\UiInfo.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate5.ico.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate6.ico.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate4.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate8.ico.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate2.ico.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Setup.ico.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate7.ico.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqMet.ico.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\Save.ico.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\stop.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\FileSystemMetadata.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Graphics\warn.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\crashreporter.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\dependentlibs.list | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\firefox.VisualElementsManifest.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\freebl3.chk.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\nssdbm3.chk | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\platform.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\precomplete | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\softokn3.chk | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\update-settings.ini.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\updater.ini.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\rempl\Unlock.xml.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Mozilla Maintenance Service\updater.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Mozilla Firefox\omni.ja | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Extensibility Component.swidtag | Modified File | Stream |
Unknown
|
...
|
»
C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft_Windows-10-Pro.swidtag.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TM.blf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT.LOG2 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{fae9930d-933c-11e7-a51d-b808901d6c9b}.TMContainer00000000000000000002.regtrans-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{fae9930d-933c-11e7-a51d-b808901d6c9b}.TMContainer00000000000000000001.regtrans-ms.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TMContainer00000000000000000002.regtrans-ms.UAKXC | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\R3ADM3.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\UiInfo.xml.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Internet Explorer.evtx.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Store%4Operational.evtx.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Windows PowerShell.evtx.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1033\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1033\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1035\LocalizedData.xml.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1036\LocalizedData.xml.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1037\LocalizedData.xml.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1041\LocalizedData.xml.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1042\LocalizedData.xml.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1044\eula.rtf.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1044\LocalizedData.xml.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1046\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1053\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3076\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2052\LocalizedData.xml.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Print.ico.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Graphics\Rotate3.ico.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\application.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\Accessible.tlb | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\install.log | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Mozilla Firefox\removed-files | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\AppXManifest.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\rempl\rempl.xml.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Localization Component.swidtag | Modified File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\regid.1991-06.com.microsoft\regid.1991-06.com.microsoft Office 16 Click-to-Run Licensing Component.swidtag | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Core.mzz.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT.LOG1.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT{4e074668-0c1c-11e7-a943-e41d2d718a20}.TMContainer00000000000000000001.regtrans-ms.UAKXC | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT{fae9930d-933c-11e7-a51d-b808901d6c9b}.TM.blf | Modified File | Stream |
Not Queried
|
...
|
»