VTI SCORE: 91/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: | - |
hidden-tear.exe
Windows Exe (x86-32)
Created at 2020-08-19T02:21:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x457000 |
Size Of Code | 0x1d200 |
Size Of Initialized Data | 0x19c00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-08-17 13:43:18+00:00 |
Version Information (11)
»
Assembly Version | 1.0.0.0 |
Comments | - |
CompanyName | - |
FileDescription | hidden-tear |
FileVersion | 1.0.0.0 |
InternalName | hidden-tear.exe |
LegalCopyright | Copyright © 2015 |
LegalTrademarks | - |
OriginalFilename | hidden-tear.exe |
ProductName | hidden-tear |
ProductVersion | 1.0.0.0 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
- | 0x401000 | 0x3b000 | 0x0 | 0x400 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 0.0 |
- | 0x43c000 | 0x1000 | 0x200 | 0x400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.74 |
.rsrc | 0x43d000 | 0x19a48 | 0x19a48 | 0x600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.49 |
- | 0x457000 | 0x18000 | 0x17d15 | 0x1a200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 8.0 |
Imports (6)
»
kernel32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetModuleHandleA | 0x0 | 0x43c08c | 0x3c094 | 0x494 | 0x0 |
user32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCursor | 0x0 | 0x43c09c | 0x3c0a4 | 0x4a4 | 0x0 |
advapi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegOpenKeyExW | 0x0 | 0x43c0ac | 0x3c0b4 | 0x4b4 | 0x0 |
comctl32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DllGetVersion | 0x0 | 0x43c0bc | 0x3c0c4 | 0x4c4 | 0x0 |
shell32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetDiskFreeSpaceExW | 0x0 | 0x43c0cc | 0x3c0d4 | 0x4d4 | 0x0 |
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x43c0dc | 0x3c0e4 | 0x4e4 | 0x0 |
Memory Dumps (25)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
hidden-tear.exe | 1 | 0x00400000 | 0x0046EFFF | First Execution |
![]() |
32-bit | 0x00457000 |
![]() |
![]() |
...
|
hidden-tear.exe | 1 | 0x00400000 | 0x0046EFFF | Content Changed |
![]() |
32-bit | 0x004583CA |
![]() |
![]() |
...
|
hidden-tear.exe | 1 | 0x00400000 | 0x0046EFFF | Content Changed |
![]() |
32-bit | 0x0045DAF5 |
![]() |
![]() |
...
|
hidden-tear.exe | 1 | 0x00400000 | 0x0046EFFF | Content Changed |
![]() |
32-bit | 0x0046D039 |
![]() |
![]() |
...
|
hidden-tear.exe | 1 | 0x00400000 | 0x0046EFFF | Content Changed |
![]() |
32-bit | 0x004590BE |
![]() |
![]() |
...
|
hidden-tear.exe | 1 | 0x00400000 | 0x0046EFFF | Content Changed |
![]() |
32-bit | 0x00466189 |
![]() |
![]() |
...
|
hidden-tear.exe | 1 | 0x00400000 | 0x0046EFFF | Content Changed |
![]() |
32-bit | 0x00468989 |
![]() |
![]() |
...
|
hidden-tear.exe | 1 | 0x00400000 | 0x0046EFFF | Content Changed |
![]() |
32-bit | 0x0045A2AE |
![]() |
![]() |
...
|
hidden-tear.exe | 1 | 0x00400000 | 0x0046EFFF | Content Changed |
![]() |
32-bit | 0x0045C80B |
![]() |
![]() |
...
|
hidden-tear.exe | 1 | 0x00400000 | 0x0046EFFF | Content Changed |
![]() |
32-bit | 0x00402000 |
![]() |
![]() |
...
|
hidden-tear.exe | 1 | 0x00400000 | 0x0046EFFF | Content Changed |
![]() |
32-bit | 0x0041F09E |
![]() |
![]() |
...
|
hidden-tear.exe | 1 | 0x00400000 | 0x0046EFFF | Content Changed |
![]() |
32-bit | 0x00466449 |
![]() |
![]() |
...
|
hidden-tear.exe | 1 | 0x00400000 | 0x0046EFFF | Content Changed |
![]() |
32-bit | 0x0046C8D8 |
![]() |
![]() |
...
|
hidden-tear.exe | 1 | 0x00400000 | 0x0046EFFF | Content Changed |
![]() |
32-bit | 0x004681C9 |
![]() |
![]() |
...
|
hidden-tear.exe | 1 | 0x00400000 | 0x0046EFFF | Content Changed |
![]() |
32-bit | 0x0045F49D |
![]() |
![]() |
...
|
buffer | 1 | 0x022B1000 | 0x022B1FFF | First Execution |
![]() |
32-bit | 0x022B1000 |
![]() |
![]() |
...
|
buffer | 1 | 0x022B2000 | 0x022B2FFF | First Execution |
![]() |
32-bit | 0x022B2000 |
![]() |
![]() |
...
|
hidden-tear.exe | 1 | 0x00400000 | 0x0046EFFF | Content Changed |
![]() |
32-bit | 0x00466449 |
![]() |
![]() |
...
|
hidden-tear.exe | 1 | 0x00400000 | 0x0046EFFF | Content Changed |
![]() |
32-bit | 0x0046C8D8 |
![]() |
![]() |
...
|
hidden-tear.exe | 1 | 0x00400000 | 0x0046EFFF | Content Changed |
![]() |
32-bit | 0x0046DC95 |
![]() |
![]() |
...
|
buffer | 1 | 0x0069B000 | 0x0069BFFF | Marked Executable |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x04BA1000 | 0x04BA2FFF | Marked Executable |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x04BA3000 | 0x04BA4FFF | Marked Executable |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x07C60000 | 0x07C63FFF | Marked Executable |
![]() |
32-bit | - |
![]() |
![]() |
...
|
hidden-tear.exe | 1 | 0x00400000 | 0x0046EFFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
C:\Users\FD1HVy\Desktop\-47zDmLsrM5Zlxp.pdf.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\4Q6AfqT.avi.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\dTNP.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\DUCGlGpLhZ7ehP0yEx.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\gqKfeceE.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\IuuHCN.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\izq8n6_qgBXoY.png.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\jGYH8Y8r9kj.jpg.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\jUesZvd-s.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\mmcdT0ssmgFqSRwRvCY.mkv.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\oXn8yyFK6hp.png.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\QAhgTD.xlsx.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Rwl9j7XAHVz8.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\tcazK41Fi.odt.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\v8t4CtjbLuJ4D9yyWCY.csv.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\vvZTWTV8FICU-m4A.mkv.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Whoz y9gOm9hnbG0fVu.avi.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\XHwpWMtf0Ll_vF0.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\yyMfsjbfc_l4hZT41.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\z7rP0.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Zd_0jo8eYB83T.ppt.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\zgTRfP_2OhRR.bmp.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\_pd3xKHZBnocQk_.odt.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\XuEywee1k\37LV1pcPLl0DszL.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\XuEywee1k\gtCKc0bFZ4FIiVAA.avi.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\XuEywee1k\kDVwA8SOo2.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\XuEywee1k\ktRNe.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\XuEywee1k\O6OfXra9cBHeO1YcjK.mkv.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\XuEywee1k\qegWvUuLpi.jpg.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\XuEywee1k\S3uubf.ppt.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\XuEywee1k\WFupxD4xWvOPahG.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Links\Desktop.lnk.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Links\Downloads.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Links\OneDrive.lnk.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\0hrLyWpzFSh8iDlU_EN.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\0iqjuiG77sXaPmH31.docx.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\0x5WsDIyIuI2wirE.xlsx.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\0Y9-__rSJ.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\64X8qB K7sxwMedQDRO.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\A2kMnWa.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\d4HEHXi0kT8GlCKBE.pptx.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\DJWO5e.xlsx.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\F6GMw-0.xlsx.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\I7Ja fh.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Ikl9qy750ufc-G.pptx.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\J6NJtsVFM1f_Q-F9.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\LNxMafDRKQVGv.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\LOrxufOFI.xlsx.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\pd7W-tx1l.ppt.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\q3_wqcOFyz--unpL.docx.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\sSefU-IfjA72.pptx.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\VmHknY5nzMK.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Ynj2Cy37O15ozYze12.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\z5krZTI-Nz8bW.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\aYu2P_HjBi7kE 3 j\EcUAKJSp7uA1nOU18lPn.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\aYu2P_HjBi7kE 3 j\_017ax.odt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\zEsXkxPFsoDWAZhIb1LP\2xJB4WmajVCEC7.pdf.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\zEsXkxPFsoDWAZhIb1LP\65fOXdLkoc_7A-ir4OV.csv.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\zEsXkxPFsoDWAZhIb1LP\cKNpYvVFpawzB_mnB.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\zEsXkxPFsoDWAZhIb1LP\oxYk7ESnPUTbU.docx.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\zEsXkxPFsoDWAZhIb1LP\x4Pz6X-xTM2KRGJ.xlsx.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\zEsXkxPFsoDWAZhIb1LP\Zr4ou.doc.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\zEsXkxPFsoDWAZhIb1LP\uHgh\0vQql94IYideak7.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\zEsXkxPFsoDWAZhIb1LP\uHgh\76Ng72Ts1wA3.ppt.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\zEsXkxPFsoDWAZhIb1LP\uHgh\Xt2sZ-EfQMfW9-.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\zEsXkxPFsoDWAZhIb1LP\uHgh\VWhsquURFxl8WGO-5\BoiBqzNTiQ5Zv9CoPBOH.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\zEsXkxPFsoDWAZhIb1LP\uHgh\VWhsquURFxl8WGO-5\hqHIO7tkxzM.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\zEsXkxPFsoDWAZhIb1LP\uHgh\VWhsquURFxl8WGO-5\mLdJ4z-CFDHGH.xlsx.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\zEsXkxPFsoDWAZhIb1LP\uHgh\VWhsquURFxl8WGO-5\wT0MNxDVsda-q.pdf.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\0ehOaE.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\62Nxa.bmp.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\ATGuP30pEWnchJJ.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\BGq6.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\BHTLU4kl.jpg.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\bXAHv5c.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\icGdWx1uRk8YsM2.bmp.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\ojBkzZF.png.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\SIRA.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\tciYhKunGDc.png.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\uE09.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\utrlInnQIT6YWq.png.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\x6g44LZkZF MNJz.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\ZH82uCB7qM-yR7Km_Gf.jpg.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Qi7 B4zT\-UJy7MJBZGtCnQl.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Qi7 B4zT\1e_enKT IAy2.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Qi7 B4zT\3zSH.jpg.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Qi7 B4zT\BntE 0fjbg.png.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Qi7 B4zT\cjy5yOqpzfy.jpg.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Qi7 B4zT\crBLP3WmGf8pH9.png.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Qi7 B4zT\essUL5txxsQxH SCRUh.bmp.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Qi7 B4zT\WYuGxfrkEC.bmp.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\bWeUUE096Si.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\K5yHR0Q9Y EL2_vro\1wQWiq_Mzo.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\K5yHR0Q9Y EL2_vro\AudnE9qrl5c\S7N4WQfp4.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\K5yHR0Q9Y EL2_vro\AudnE9qrl5c\SHKhm.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\K5yHR0Q9Y EL2_vro\zlzFdg_dAeB37K\TQ9imiFTg1-3Gy.mp3.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\K5yHR0Q9Y EL2_vro\zlzFdg_dAeB37K\3uxgqON0\zNN7vAC-k.mp3.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\Q7qIPzWWSjw5RC5V\EuQZ035bN1mhfk.mp3.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\Q7qIPzWWSjw5RC5V\i0QS.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\jR9NXTr2_5Ikd-IG 1W.mp4.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\RlUuHgH9CpkVKnxm1.mkv.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\x3_AH.mkv.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\0w8t5\J60vjNHm.mp4.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\0w8t5\la-7YGCqtlgmjKcxcDai.mkv.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\0w8t5\IdRynCfnNRP\Enyaw.avi.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\0w8t5\IdRynCfnNRP\fvQovREy.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\0w8t5\IdRynCfnNRP\LCHVqKa90brlsfGf8f.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\0w8t5\IdRynCfnNRP\N3vZhGHo7e0Fog-.avi.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\0w8t5\IdRynCfnNRP\nXDr7JL.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\0w8t5\IdRynCfnNRP\qMSDX 8vxCnMdo.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\0w8t5\IdRynCfnNRP\vflb 7.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\0w8t5\qNkSss06vEgW e7yXVm4\DVTHQ5N29Ax2mpX3.avi.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\0w8t5\Wnj7t2K0sr82w8ym\CKFU4r2Ry7OuQfYzEu7M.mp4.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\0w8t5\Wnj7t2K0sr82w8ym\w2LFl7qnN.avi.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\0w8t5\wZpzNZ7EVrJ XYv\-4xRGwDeIULvJHpI6w82.mkv.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\0w8t5\wZpzNZ7EVrJ XYv\TIzxwjrmuV.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\Gf9AWRpwu_3lT12g8\94gp-fbdQLAMLhZn.mkv.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\Gf9AWRpwu_3lT12g8\P _VzpiYzLOQ.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\Gf9AWRpwu_3lT12g8\pu9T2VV_YhRq.mkv.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\Gf9AWRpwu_3lT12g8\WEAU oNjlE4iZ6d.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\Gf9AWRpwu_3lT12g8\KxER\tqpt5bJJmOZb.mp4.spybuster | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\READ_IT.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\hidden-tear.exe.log | Dropped File | Text |
Unknown
|
...
|
»