VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan |
Wacatac_2019-11-20_19-54.exe
Windows Exe (x86-32)
Created at 2019-11-21T07:55:00
Remarks
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Wacatac_2019-11-20_19-54.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-11-21 05:00 (UTC+1) |
Last Seen | 2019-11-21 05:18 (UTC+1) |
Names | Win32.Trojan.Kryptik |
Families | Kryptik |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x404b6b |
Size Of Code | 0x11200 |
Size Of Initialized Data | 0x4a63a00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-04-24 12:22:49+00:00 |
Version Information (2)
»
FileOldVersionTree | 1.0.4.4 |
InternalNameTwo | gjtrrh.exe |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x11051 | 0x11200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.8 |
.rdata | 0x413000 | 0x80ce | 0x8200 | 0x11600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.54 |
.data | 0x41c000 | 0x4a47fc4 | 0xe000 | 0x19800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.21 |
.tls | 0x4e64000 | 0x9 | 0x200 | 0x27800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x4e65000 | 0x12070 | 0x12200 | 0x27a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.55 |
.reloc | 0x4e78000 | 0x1340 | 0x1400 | 0x39c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.45 |
Imports (4)
»
KERNEL32.dll (84)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
lstrlenA | 0x0 | 0x413008 | 0x1a8e8 | 0x18ee8 | 0x54d |
CommConfigDialogA | 0x0 | 0x41300c | 0x1a8ec | 0x18eec | 0x5d |
lstrcpynA | 0x0 | 0x413010 | 0x1a8f0 | 0x18ef0 | 0x54a |
BuildCommDCBAndTimeoutsA | 0x0 | 0x413014 | 0x1a8f4 | 0x18ef4 | 0x3b |
WaitNamedPipeA | 0x0 | 0x413018 | 0x1a8f8 | 0x18ef8 | 0x4ff |
SetDefaultCommConfigW | 0x0 | 0x41301c | 0x1a8fc | 0x18efc | 0x44f |
GetModuleHandleW | 0x0 | 0x413020 | 0x1a900 | 0x18f00 | 0x218 |
GetConsoleTitleA | 0x0 | 0x413024 | 0x1a904 | 0x18f04 | 0x1b5 |
FindActCtxSectionStringA | 0x0 | 0x413028 | 0x1a908 | 0x18f08 | 0x12a |
SetFileShortNameW | 0x0 | 0x41302c | 0x1a90c | 0x18f0c | 0x469 |
GetFileAttributesA | 0x0 | 0x413030 | 0x1a910 | 0x18f10 | 0x1e5 |
VerifyVersionInfoA | 0x0 | 0x413034 | 0x1a914 | 0x18f14 | 0x4e7 |
HeapQueryInformation | 0x0 | 0x413038 | 0x1a918 | 0x18f18 | 0x2d1 |
GetModuleFileNameW | 0x0 | 0x41303c | 0x1a91c | 0x18f1c | 0x214 |
SetFilePointer | 0x0 | 0x413040 | 0x1a920 | 0x18f20 | 0x466 |
GetLastError | 0x0 | 0x413044 | 0x1a924 | 0x18f24 | 0x202 |
GetProcAddress | 0x0 | 0x413048 | 0x1a928 | 0x18f28 | 0x245 |
WriteConsoleA | 0x0 | 0x41304c | 0x1a92c | 0x18f2c | 0x51a |
LocalAlloc | 0x0 | 0x413050 | 0x1a930 | 0x18f30 | 0x344 |
GetNumberFormatW | 0x0 | 0x413054 | 0x1a934 | 0x18f34 | 0x233 |
HeapLock | 0x0 | 0x413058 | 0x1a938 | 0x18f38 | 0x2d0 |
GetOEMCP | 0x0 | 0x41305c | 0x1a93c | 0x18f3c | 0x237 |
DeleteCriticalSection | 0x0 | 0x413060 | 0x1a940 | 0x18f40 | 0xd1 |
GetWindowsDirectoryW | 0x0 | 0x413064 | 0x1a944 | 0x18f44 | 0x2af |
GetVersion | 0x0 | 0x413068 | 0x1a948 | 0x18f48 | 0x2a2 |
DeleteFileW | 0x0 | 0x41306c | 0x1a94c | 0x18f4c | 0xd6 |
GetPrivateProfileSectionW | 0x0 | 0x413070 | 0x1a950 | 0x18f50 | 0x240 |
LCMapStringW | 0x0 | 0x413074 | 0x1a954 | 0x18f54 | 0x32d |
lstrcpyA | 0x0 | 0x413078 | 0x1a958 | 0x18f58 | 0x547 |
CreateFileW | 0x0 | 0x41307c | 0x1a95c | 0x18f5c | 0x8f |
GetStringTypeW | 0x0 | 0x413080 | 0x1a960 | 0x18f60 | 0x269 |
CreateMutexW | 0x0 | 0x413084 | 0x1a964 | 0x18f64 | 0x9e |
WriteConsoleW | 0x0 | 0x413088 | 0x1a968 | 0x18f68 | 0x524 |
FlushFileBuffers | 0x0 | 0x41308c | 0x1a96c | 0x18f6c | 0x157 |
HeapAlloc | 0x0 | 0x413090 | 0x1a970 | 0x18f70 | 0x2cb |
EncodePointer | 0x0 | 0x413094 | 0x1a974 | 0x18f74 | 0xea |
DecodePointer | 0x0 | 0x413098 | 0x1a978 | 0x18f78 | 0xca |
GetCommandLineW | 0x0 | 0x41309c | 0x1a97c | 0x18f7c | 0x187 |
RaiseException | 0x0 | 0x4130a0 | 0x1a980 | 0x18f80 | 0x3b1 |
RtlUnwind | 0x0 | 0x4130a4 | 0x1a984 | 0x18f84 | 0x418 |
IsDebuggerPresent | 0x0 | 0x4130a8 | 0x1a988 | 0x18f88 | 0x300 |
IsProcessorFeaturePresent | 0x0 | 0x4130ac | 0x1a98c | 0x18f8c | 0x304 |
ExitProcess | 0x0 | 0x4130b0 | 0x1a990 | 0x18f90 | 0x119 |
GetModuleHandleExW | 0x0 | 0x4130b4 | 0x1a994 | 0x18f94 | 0x217 |
MultiByteToWideChar | 0x0 | 0x4130b8 | 0x1a998 | 0x18f98 | 0x367 |
WideCharToMultiByte | 0x0 | 0x4130bc | 0x1a99c | 0x18f9c | 0x511 |
GetStdHandle | 0x0 | 0x4130c0 | 0x1a9a0 | 0x18fa0 | 0x264 |
WriteFile | 0x0 | 0x4130c4 | 0x1a9a4 | 0x18fa4 | 0x525 |
GetProcessHeap | 0x0 | 0x4130c8 | 0x1a9a8 | 0x18fa8 | 0x24a |
HeapSize | 0x0 | 0x4130cc | 0x1a9ac | 0x18fac | 0x2d4 |
HeapFree | 0x0 | 0x4130d0 | 0x1a9b0 | 0x18fb0 | 0x2cf |
EnterCriticalSection | 0x0 | 0x4130d4 | 0x1a9b4 | 0x18fb4 | 0xee |
LeaveCriticalSection | 0x0 | 0x4130d8 | 0x1a9b8 | 0x18fb8 | 0x339 |
ReadFile | 0x0 | 0x4130dc | 0x1a9bc | 0x18fbc | 0x3c0 |
SetFilePointerEx | 0x0 | 0x4130e0 | 0x1a9c0 | 0x18fc0 | 0x467 |
SetLastError | 0x0 | 0x4130e4 | 0x1a9c4 | 0x18fc4 | 0x473 |
GetCurrentThreadId | 0x0 | 0x4130e8 | 0x1a9c8 | 0x18fc8 | 0x1c5 |
GetFileType | 0x0 | 0x4130ec | 0x1a9cc | 0x18fcc | 0x1f3 |
GetStartupInfoW | 0x0 | 0x4130f0 | 0x1a9d0 | 0x18fd0 | 0x263 |
QueryPerformanceCounter | 0x0 | 0x4130f4 | 0x1a9d4 | 0x18fd4 | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x4130f8 | 0x1a9d8 | 0x18fd8 | 0x1c1 |
GetSystemTimeAsFileTime | 0x0 | 0x4130fc | 0x1a9dc | 0x18fdc | 0x279 |
GetEnvironmentStringsW | 0x0 | 0x413100 | 0x1a9e0 | 0x18fe0 | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x413104 | 0x1a9e4 | 0x18fe4 | 0x161 |
UnhandledExceptionFilter | 0x0 | 0x413108 | 0x1a9e8 | 0x18fe8 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x41310c | 0x1a9ec | 0x18fec | 0x4a5 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x413110 | 0x1a9f0 | 0x18ff0 | 0x2e3 |
Sleep | 0x0 | 0x413114 | 0x1a9f4 | 0x18ff4 | 0x4b2 |
GetCurrentProcess | 0x0 | 0x413118 | 0x1a9f8 | 0x18ff8 | 0x1c0 |
TerminateProcess | 0x0 | 0x41311c | 0x1a9fc | 0x18ffc | 0x4c0 |
TlsAlloc | 0x0 | 0x413120 | 0x1aa00 | 0x19000 | 0x4c5 |
TlsGetValue | 0x0 | 0x413124 | 0x1aa04 | 0x19004 | 0x4c7 |
TlsSetValue | 0x0 | 0x413128 | 0x1aa08 | 0x19008 | 0x4c8 |
TlsFree | 0x0 | 0x41312c | 0x1aa0c | 0x1900c | 0x4c6 |
GetConsoleCP | 0x0 | 0x413130 | 0x1aa10 | 0x19010 | 0x19a |
GetConsoleMode | 0x0 | 0x413134 | 0x1aa14 | 0x19014 | 0x1ac |
IsValidCodePage | 0x0 | 0x413138 | 0x1aa18 | 0x19018 | 0x30a |
GetACP | 0x0 | 0x41313c | 0x1aa1c | 0x1901c | 0x168 |
GetCPInfo | 0x0 | 0x413140 | 0x1aa20 | 0x19020 | 0x172 |
LoadLibraryExW | 0x0 | 0x413144 | 0x1aa24 | 0x19024 | 0x33e |
OutputDebugStringW | 0x0 | 0x413148 | 0x1aa28 | 0x19028 | 0x38a |
HeapReAlloc | 0x0 | 0x41314c | 0x1aa2c | 0x1902c | 0x2d2 |
SetStdHandle | 0x0 | 0x413150 | 0x1aa30 | 0x19030 | 0x487 |
CloseHandle | 0x0 | 0x413154 | 0x1aa34 | 0x19034 | 0x52 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCaretPos | 0x0 | 0x41315c | 0x1aa3c | 0x1903c | 0x10a |
ADVAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DeregisterEventSource | 0x0 | 0x413000 | 0x1a8e0 | 0x18ee0 | 0xdb |
WINHTTP.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WinHttpCloseHandle | 0x0 | 0x413164 | 0x1aa44 | 0x19044 | 0x7 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
buffer | 1 | 0x04F26520 | 0x04F2F1BF | Marked Executable | - | 32-bit | 0x04F26520 |
![]() |
![]() |
...
|
buffer | 1 | 0x00210000 | 0x0021EFFF | First Execution | - | 32-bit | 0x00210000 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.42039481 |
Malicious
|
\\?\C:\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\boot.sdi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\Winre.wim | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\0N-rV-LBaIjM3NXE.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\1QQBxYdUEBz.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\3Y3KdQk.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\aEefa7T.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\cKQ4LePz.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\CQoYWdLDE8A.flv | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ebB_pHirOaSct0.swf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\F0klApUO2Z.odp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\gkzqpiiCf f.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\h-5QryXhtlv.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\LBVX9 jMA_nh7r1-t.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Lu8 o.swf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Ob 7JY7fuAZ.flv | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\S_xV8DrCXA1qqj8mB.swf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\pdxnl.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\T-qEmnB.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\tKb0W.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\uhNakSJy2.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\WiZ2x.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\_btdHeL3.png | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\4aQclz9QavwtjC5QkBV\6Moq2t5E7ltI2YT.mp4 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\4aQclz9QavwtjC5QkBV\j9-MN6\amZv2Z0wxoZS.flv | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\4aQclz9QavwtjC5QkBV\j9-MN6\d3xNIviLk0Lwv1A.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\4aQclz9QavwtjC5QkBV\j9-MN6\OFbSLjMg5F ypHpxq3Lw\-sIkef49wnJO.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\4aQclz9QavwtjC5QkBV\j9-MN6\OFbSLjMg5F ypHpxq3Lw\eW2I.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ReE1ZSiCxXt 9A\9Yj0SX-7Wg6MAp811z.ppt | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ReE1ZSiCxXt 9A\K-xcXNu.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ReE1ZSiCxXt 9A\VhdNesE9RHAIm.pps | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ReE1ZSiCxXt 9A\ZOgYMomyZE0.png | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\0tm45Vd-10FUKtTqfmOc.docx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3ZF0vW0u2.xlsx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\6CT5st-Mp.xlsx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\GP5bcTy5x8.docx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\hMQmO8YBLr.xlsx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\n9o52Fm.pptx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\q6BY.pptx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\QwIqKQSVxE 5799zU.docx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\WQ1kIjdf.docx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X_wIoPGx2gE8.xlsx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\z7-C3T grbVW2iC.pptx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ZaYCVmfMWKGans6Q.pptx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\8x-34OVBDypJWOE.csv | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\9jf7wCxNUfpySfJ4Jx.ods | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\qlydpxKQGSEMlw.csv | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\tBy7vnJ20L.odt | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\_DYrqU5.xls | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\-qLf9qdmX0YqXMSteXaW\bb1BK5wvdL X.odp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\-qLf9qdmX0YqXMSteXaW\bw-7fnZ.odp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\-qLf9qdmX0YqXMSteXaW\E77BCsVsDojphSy.ppt | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\-qLf9qdmX0YqXMSteXaW\rePTuEhAK.ots | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\-qLf9qdmX0YqXMSteXaW\R_P0TZ.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\-qLf9qdmX0YqXMSteXaW\u_S_Ou6zrS.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\CXq6NUTJ 99V2-v6\9jFQ OhEgtOJ1L.ots | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\CXq6NUTJ 99V2-v6\ENUz6f.pps | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\CXq6NUTJ 99V2-v6\fu2JzaZ.pdf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\CXq6NUTJ 99V2-v6\QnKnm4tcyo8Rs.docx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\CXq6NUTJ 99V2-v6\_ak74NgfXD6KjNd l.ppt | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\CXq6NUTJ 99V2-v6\2x0rhX3GpeC7V\--wFzQ_fQiax.ods | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\CXq6NUTJ 99V2-v6\2x0rhX3GpeC7V\njqLpitsRlBgIkVSRsc.csv | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\CXq6NUTJ 99V2-v6\mK_tjRRPSh202XbyB\mZk3qpXWxbFEStM.xlsx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\CXq6NUTJ 99V2-v6\mK_tjRRPSh202XbyB\YwAoWvLQX1Qkqb1WAal.xls | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\G_x-eHIang489Wx\3hM_Yv-O.ods | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\G_x-eHIang489Wx\LIWzry.csv | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\l7IEr\dg4oVF.pptx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\l7IEr\_rKnr.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\l7IEr\D n1NXFm_Av6aY4CwC\dp PC3.docx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\l7IEr\D n1NXFm_Av6aY4CwC\J3VBujVyzaSO.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\Favorites.vss | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\_private\folder.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE Add-on site.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE site on Microsoft.com.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Home.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Work.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Suggested Sites.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Web Slice Gallery.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft Store.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Autos.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Entertainment.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Links\Desktop.lnk | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Links\Downloads.lnk | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Money.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Sports.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSNBC News.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\lsf0tqH.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\yIEkfQCxcOzoyh.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\SbWQphpdQ.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\H2vk_\GfZaeOxJ.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\H2vk_\SzLBr.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\H2vk_\zCnP0SsfIwje8h7k.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\H2vk_\_9bVvSR0NC3\fS9GjsjJwR37CUgZ5.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\H2vk_\_9bVvSR0NC3\nVA6X.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\H2vk_\_9bVvSR0NC3\rncK.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\H2vk_\_9bVvSR0NC3\0bfITs5We\0gMoTR0qq.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\H2vk_\_9bVvSR0NC3\A0YKGsoY8M31ETQ\aLpSkpnAOV.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\H2vk_\_9bVvSR0NC3\A0YKGsoY8M31ETQ\DAeR1.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\H2vk_\_9bVvSR0NC3\A0YKGsoY8M31ETQ\HQLOEn1NqpfTg1W.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\H2vk_\_9bVvSR0NC3\A0YKGsoY8M31ETQ\l6ln9j1_D55o.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\H2vk_\_9bVvSR0NC3\A0YKGsoY8M31ETQ\Lzol.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\H2vk_\_9bVvSR0NC3\A0YKGsoY8M31ETQ\ref_Ha9y0KFA_ID.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\H2vk_\_9bVvSR0NC3\c3ErMl5xQUkjb\gKB91HPUi4W1PdPGj.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\rd8rDpgMK_O U_ RO\CbajF-WnH8JmAWUyb vs.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\rd8rDpgMK_O U_ RO\eUUW3K55SiLSEX.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\rd8rDpgMK_O U_ RO\Iy3mjA.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\rd8rDpgMK_O U_ RO\Jk9z9eR5-bVH_B.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\rd8rDpgMK_O U_ RO\Q9VlqWAtF0-DWdezS2.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\rd8rDpgMK_O U_ RO\TeZH9 l1p.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\rd8rDpgMK_O U_ RO\YHz3s62rTdR5SUCJ45.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\wmMLxSh\brapnx BzMk5C.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\wmMLxSh\j06Qfw1.m4a | Modified File | Binary |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\wmMLxSh\PtDamlq6EPCO4.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\wmMLxSh\zY1gAR74jXX.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\6sJ5Nvd\AmZPmY.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\-NviZXX.png | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\22d0g9LYY-eR.png | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\3q833.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\4m4dkna2MBvFQv.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8JbgwF.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAaKgAadS-cz 6.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\BCq5.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\BjEx3.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dxIPtsp3JyR.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\EWm lGhs9RzKDH.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\f0-kIY.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\f7hWfjYSu5W3Q.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\GLq9ajQYOkYMyeyrKasw.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\IeUcz.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\iIRcF_.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\jqGW9rBdkPhNCoa8pfh.png | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\j_wmVI32CgzzP5.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\k3qQOB5vZaWyPRMgI7n.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\LmYaBDzuYd2.png | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NWEWuTjUbC.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\OGgxKmIG6X6nh1pvhI.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ouwd6S7yNy.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\POwpC.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\RBOkJ4bIa.png | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\v2lT.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\read_me.txt | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\ntuser.ini | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\P6r6WVfc_j6IN62 yp.gif | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\tHkYo.gif | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\z_3uPlAJZMtKG.mkv | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\4aQclz9QavwtjC5QkBV\MymW-P0.gif | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\4aQclz9QavwtjC5QkBV\j9-MN6\OFbSLjMg5F ypHpxq3Lw\fX4UaGBV46vnDsIHXb.gif | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\4aQclz9QavwtjC5QkBV\j9-MN6\OFbSLjMg5F ypHpxq3Lw\R-vKwcM20r5mYO.flv | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ReE1ZSiCxXt 9A\oOrJCH_u4fw7H.docx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ReE1ZSiCxXt 9A\PEWZ_zvD.doc | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\9Z3cqEnbV.pptx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\bExrSPFkXu33TXCdhRjV.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xCG7cBBdA26D4C4a7O.docx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\l7IEr\D n1NXFm_Av6aY4CwC\CkixSmIJpPRf0.odp | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\l7IEr\D n1NXFm_Av6aY4CwC\FHeC3PnEp1b9.odt | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Bn0vYqIGbef7_rt\l7IEr\D n1NXFm_Av6aY4CwC\_zNOJv_bA_jWdzqFVz.ots | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Links\RecentPlaces.lnk | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\BSTXsZ.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3irpEEnGfRfssd\H2vk_\_9bVvSR0NC3\0bfITs5We\BquehE5.m4a | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\0PjZJ2x_.png | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\7wJHk8IduLqY3JbXiKSR.png | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ss4Yiq.jpg | Modified File | Stream |
Not Queried
|
...
|
»