VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan |
Wacatac_2019-11-20_00-10.exe
Windows Exe (x86-32)
Created at 2019-11-20T19:59:00
Remarks
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Wacatac_2019-11-20_00-10.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-11-20 19:37 (UTC+1) |
Last Seen | 2019-11-20 19:50 (UTC+1) |
Names | Win32.Trojan.Kryptik |
Families | Kryptik |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x406d47 |
Size Of Code | 0x22c00 |
Size Of Initialized Data | 0x46000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-05-28 13:02:07+00:00 |
Version Information (2)
»
FileVersion | 1.0.5.4 |
InternalName | fyukfuyk.exe |
Sections (7)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x22b6d | 0x22c00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.7 |
.rdata | 0x424000 | 0xec26 | 0xee00 | 0x23000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.49 |
.data | 0x433000 | 0x2acfc | 0xb200 | 0x31e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.17 |
.gfids | 0x45e000 | 0x234 | 0x400 | 0x3d000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.41 |
.tls | 0x45f000 | 0xd | 0x200 | 0x3d400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.02 |
.rsrc | 0x460000 | 0x9a48 | 0x9c00 | 0x3d600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.71 |
.reloc | 0x46a000 | 0x21b4 | 0x2200 | 0x47200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.55 |
Imports (1)
»
KERNEL32.dll (90)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetSystemTimes | 0x0 | 0x424000 | 0x32424 | 0x31424 | 0x27a |
GetFirmwareEnvironmentVariableA | 0x0 | 0x424004 | 0x32428 | 0x31428 | 0x1f6 |
lstrlenA | 0x0 | 0x424008 | 0x3242c | 0x3142c | 0x54d |
OpenJobObjectW | 0x0 | 0x42400c | 0x32430 | 0x31430 | 0x37b |
GetCurrentDirectoryA | 0x0 | 0x424010 | 0x32434 | 0x31434 | 0x1be |
OpenSemaphoreA | 0x0 | 0x424014 | 0x32438 | 0x31438 | 0x383 |
IsProcessInJob | 0x0 | 0x424018 | 0x3243c | 0x3143c | 0x303 |
GetModuleHandleA | 0x0 | 0x42401c | 0x32440 | 0x31440 | 0x215 |
GetUserDefaultLangID | 0x0 | 0x424020 | 0x32444 | 0x31444 | 0x29c |
GetMailslotInfo | 0x0 | 0x424024 | 0x32448 | 0x31448 | 0x210 |
GlobalAlloc | 0x0 | 0x424028 | 0x3244c | 0x3144c | 0x2b3 |
HeapReAlloc | 0x0 | 0x42402c | 0x32450 | 0x31450 | 0x2d2 |
LoadLibraryW | 0x0 | 0x424030 | 0x32454 | 0x31454 | 0x33f |
HeapAlloc | 0x0 | 0x424034 | 0x32458 | 0x31458 | 0x2cb |
GetProcAddress | 0x0 | 0x424038 | 0x3245c | 0x3145c | 0x245 |
FreeEnvironmentStringsA | 0x0 | 0x42403c | 0x32460 | 0x31460 | 0x160 |
lstrcmpW | 0x0 | 0x424040 | 0x32464 | 0x31464 | 0x542 |
GetFileTime | 0x0 | 0x424044 | 0x32468 | 0x31468 | 0x1f2 |
GetStdHandle | 0x0 | 0x424048 | 0x3246c | 0x3146c | 0x264 |
CreateDirectoryExA | 0x0 | 0x42404c | 0x32470 | 0x31470 | 0x7d |
GetFileAttributesExA | 0x0 | 0x424050 | 0x32474 | 0x31474 | 0x1e6 |
ReadConsoleInputA | 0x0 | 0x424054 | 0x32478 | 0x31478 | 0x3b5 |
GetModuleFileNameA | 0x0 | 0x424058 | 0x3247c | 0x3147c | 0x213 |
MultiByteToWideChar | 0x0 | 0x42405c | 0x32480 | 0x31480 | 0x367 |
WideCharToMultiByte | 0x0 | 0x424060 | 0x32484 | 0x31484 | 0x511 |
GetStringTypeW | 0x0 | 0x424064 | 0x32488 | 0x31488 | 0x269 |
EnterCriticalSection | 0x0 | 0x424068 | 0x3248c | 0x3148c | 0xee |
LeaveCriticalSection | 0x0 | 0x42406c | 0x32490 | 0x31490 | 0x339 |
DeleteCriticalSection | 0x0 | 0x424070 | 0x32494 | 0x31494 | 0xd1 |
EncodePointer | 0x0 | 0x424074 | 0x32498 | 0x31498 | 0xea |
DecodePointer | 0x0 | 0x424078 | 0x3249c | 0x3149c | 0xca |
SetLastError | 0x0 | 0x42407c | 0x324a0 | 0x314a0 | 0x473 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x424080 | 0x324a4 | 0x314a4 | 0x2e3 |
CreateEventW | 0x0 | 0x424084 | 0x324a8 | 0x314a8 | 0x85 |
TlsAlloc | 0x0 | 0x424088 | 0x324ac | 0x314ac | 0x4c5 |
TlsGetValue | 0x0 | 0x42408c | 0x324b0 | 0x314b0 | 0x4c7 |
TlsSetValue | 0x0 | 0x424090 | 0x324b4 | 0x314b4 | 0x4c8 |
TlsFree | 0x0 | 0x424094 | 0x324b8 | 0x314b8 | 0x4c6 |
GetSystemTimeAsFileTime | 0x0 | 0x424098 | 0x324bc | 0x314bc | 0x279 |
GetModuleHandleW | 0x0 | 0x42409c | 0x324c0 | 0x314c0 | 0x218 |
LCMapStringW | 0x0 | 0x4240a0 | 0x324c4 | 0x314c4 | 0x32d |
GetLocaleInfoW | 0x0 | 0x4240a4 | 0x324c8 | 0x314c8 | 0x206 |
GetCPInfo | 0x0 | 0x4240a8 | 0x324cc | 0x314cc | 0x172 |
CloseHandle | 0x0 | 0x4240ac | 0x324d0 | 0x314d0 | 0x52 |
SetEvent | 0x0 | 0x4240b0 | 0x324d4 | 0x314d4 | 0x459 |
ResetEvent | 0x0 | 0x4240b4 | 0x324d8 | 0x314d8 | 0x40f |
WaitForSingleObjectEx | 0x0 | 0x4240b8 | 0x324dc | 0x314dc | 0x4fa |
IsDebuggerPresent | 0x0 | 0x4240bc | 0x324e0 | 0x314e0 | 0x300 |
UnhandledExceptionFilter | 0x0 | 0x4240c0 | 0x324e4 | 0x314e4 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x4240c4 | 0x324e8 | 0x314e8 | 0x4a5 |
GetStartupInfoW | 0x0 | 0x4240c8 | 0x324ec | 0x314ec | 0x263 |
IsProcessorFeaturePresent | 0x0 | 0x4240cc | 0x324f0 | 0x314f0 | 0x304 |
QueryPerformanceCounter | 0x0 | 0x4240d0 | 0x324f4 | 0x314f4 | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x4240d4 | 0x324f8 | 0x314f8 | 0x1c1 |
GetCurrentThreadId | 0x0 | 0x4240d8 | 0x324fc | 0x314fc | 0x1c5 |
InitializeSListHead | 0x0 | 0x4240dc | 0x32500 | 0x31500 | 0x2e7 |
GetCurrentProcess | 0x0 | 0x4240e0 | 0x32504 | 0x31504 | 0x1c0 |
TerminateProcess | 0x0 | 0x4240e4 | 0x32508 | 0x31508 | 0x4c0 |
RtlUnwind | 0x0 | 0x4240e8 | 0x3250c | 0x3150c | 0x418 |
RaiseException | 0x0 | 0x4240ec | 0x32510 | 0x31510 | 0x3b1 |
GetLastError | 0x0 | 0x4240f0 | 0x32514 | 0x31514 | 0x202 |
FreeLibrary | 0x0 | 0x4240f4 | 0x32518 | 0x31518 | 0x162 |
LoadLibraryExW | 0x0 | 0x4240f8 | 0x3251c | 0x3151c | 0x33e |
HeapFree | 0x0 | 0x4240fc | 0x32520 | 0x31520 | 0x2cf |
ExitProcess | 0x0 | 0x424100 | 0x32524 | 0x31524 | 0x119 |
GetModuleHandleExW | 0x0 | 0x424104 | 0x32528 | 0x31528 | 0x217 |
WriteFile | 0x0 | 0x424108 | 0x3252c | 0x3152c | 0x525 |
GetACP | 0x0 | 0x42410c | 0x32530 | 0x31530 | 0x168 |
IsValidLocale | 0x0 | 0x424110 | 0x32534 | 0x31534 | 0x30c |
GetUserDefaultLCID | 0x0 | 0x424114 | 0x32538 | 0x31538 | 0x29b |
EnumSystemLocalesW | 0x0 | 0x424118 | 0x3253c | 0x3153c | 0x10f |
GetFileType | 0x0 | 0x42411c | 0x32540 | 0x31540 | 0x1f3 |
GetProcessHeap | 0x0 | 0x424120 | 0x32544 | 0x31544 | 0x24a |
FindClose | 0x0 | 0x424124 | 0x32548 | 0x31548 | 0x12e |
FindFirstFileExA | 0x0 | 0x424128 | 0x3254c | 0x3154c | 0x133 |
FindNextFileA | 0x0 | 0x42412c | 0x32550 | 0x31550 | 0x143 |
IsValidCodePage | 0x0 | 0x424130 | 0x32554 | 0x31554 | 0x30a |
GetOEMCP | 0x0 | 0x424134 | 0x32558 | 0x31558 | 0x237 |
GetCommandLineA | 0x0 | 0x424138 | 0x3255c | 0x3155c | 0x186 |
GetCommandLineW | 0x0 | 0x42413c | 0x32560 | 0x31560 | 0x187 |
GetEnvironmentStringsW | 0x0 | 0x424140 | 0x32564 | 0x31564 | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x424144 | 0x32568 | 0x31568 | 0x161 |
SetStdHandle | 0x0 | 0x424148 | 0x3256c | 0x3156c | 0x487 |
FlushFileBuffers | 0x0 | 0x42414c | 0x32570 | 0x31570 | 0x157 |
GetConsoleCP | 0x0 | 0x424150 | 0x32574 | 0x31574 | 0x19a |
GetConsoleMode | 0x0 | 0x424154 | 0x32578 | 0x31578 | 0x1ac |
HeapSize | 0x0 | 0x424158 | 0x3257c | 0x3157c | 0x2d4 |
SetFilePointerEx | 0x0 | 0x42415c | 0x32580 | 0x31580 | 0x467 |
WriteConsoleW | 0x0 | 0x424160 | 0x32584 | 0x31584 | 0x524 |
CreateFileW | 0x0 | 0x424164 | 0x32588 | 0x31588 | 0x8f |
Memory Dumps (12)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
wacatac_2019-11-20_00-10.exe | 1 | 0x00400000 | 0x0046CFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x005527E8 | 0x0055B1B7 | Marked Executable | - | 32-bit | 0x005527E8 |
![]() |
![]() |
...
|
buffer | 1 | 0x00020000 | 0x0002EFFF | First Execution | - | 32-bit | 0x00020000 |
![]() |
![]() |
...
|
buffer | 1 | 0x00020000 | 0x0002EFFF | Content Changed | - | 32-bit | 0x000204F6 |
![]() |
![]() |
...
|
wacatac_2019-11-20_00-10.exe | 1 | 0x00400000 | 0x0046CFFF | Content Changed | - | 32-bit | 0x0040B760 |
![]() |
![]() |
...
|
wacatac_2019-11-20_00-10.exe | 1 | 0x00400000 | 0x0046CFFF | Content Changed | - | 32-bit | 0x00404C70 |
![]() |
![]() |
...
|
wacatac_2019-11-20_00-10.exe | 1 | 0x00400000 | 0x0046CFFF | Content Changed | - | 32-bit | 0x00405470 |
![]() |
![]() |
...
|
wacatac_2019-11-20_00-10.exe | 1 | 0x00400000 | 0x0046CFFF | Content Changed | - | 32-bit | 0x0040AA7C |
![]() |
![]() |
...
|
wacatac_2019-11-20_00-10.exe | 1 | 0x00400000 | 0x0046CFFF | Content Changed | - | 32-bit | 0x00404E00 |
![]() |
![]() |
...
|
wacatac_2019-11-20_00-10.exe | 1 | 0x00400000 | 0x0046CFFF | Content Changed | - | 32-bit | 0x0040A983 |
![]() |
![]() |
...
|
wacatac_2019-11-20_00-10.exe | 1 | 0x00400000 | 0x0046CFFF | Content Changed | - | 32-bit | 0x00402BC0 |
![]() |
![]() |
...
|
wacatac_2019-11-20_00-10.exe | 1 | 0x00400000 | 0x0046CFFF | Content Changed | - | 32-bit | 0x0040140E |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Mikey.105666 |
Malicious
|
\\?\C:\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\boot.sdi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\Winre.wim | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\ntuser.ini | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\7rahvnf-8HbKYYTPWa.xlsx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\7xDEzSaHXEl1.flv | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\D08IlIyt8xaqUv.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\dAi9bizsAAm.png | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\GaUqyqeU_-Fv.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\GTPM1JaN1o0n-HKEyloG.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\h3Q q_2em5Dz.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\I5TKi8Vul-lZk.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\IFNkkkLY cz646fa.avi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\j2KXC8yB_u.avi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MIV306n.swf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\pnye5nZ9l4wV-tQ3X.doc | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\PsSqQXPorJBb9V0MC2R.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\qSRoVfo.png | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\QzPrIBJASF9Cr5iAba.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\rO8ki1jv-RPugrU.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\S7I6SDUlKGsonua.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\uB8rE9MrCBxht_FVzzuD.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\UxB8lMaNHD.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\XMm2w2ACbzw.pps | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\YihTtz59EUrV.mkv | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\_5MHU T p.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\6b2d_l45Xgik\8SmLhGM4tn987.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\p8UL_ERV\n7IO5w0McAOmiXJ VZMN.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\p8UL_ERV\wVQUzQ0iaLqLlHr.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\p8UL_ERV\_tB9SFpbf7HeKc.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\p8UL_ERV\9l6YkE2Ncx\2PDo3FvRLwa.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\p8UL_ERV\9l6YkE2Ncx\jwR-I_l-yT1jR.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\p8UL_ERV\Ldy6l2o5 ZKC8QGIhm\iATfWourDF_VbLZ.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\p8UL_ERV\Ldy6l2o5 ZKC8QGIhm\UgVk9.ots | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\p8UL_ERV\Ldy6l2o5 ZKC8QGIhm\_4DI- 2.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\p8UL_ERV\zplfC7_zsJ\8368UsnjEB_8S.avi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\0c5Q-gE5.xlsx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\0O31bZuDCP_.pps | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\2DjSQZdm.xlsx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\4NWE2d4at f.docx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\7eoGIv.pptx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\7iRzhs.pptx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8LsYlgIf_vpXoKZA.docx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\95cDq7IXOD.xlsx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ae_uFho8j0i.docx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\AXHnlkM.pdf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Cd20r2-st.docx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\i CWCeF5i.xlsx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\iJf6hbNSS.xlsx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\IjQfXQvBJ ATELoweEnS.pptx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\NVNMMK0GjdgZsRve.docx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\pMI93.pptx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Yerk2qfakppKCYmHnE4.docx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3kVF\akYo4q.pdf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3kVF\FA9DS7OghoViH.ods | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3kVF\JsWP-Gwzz5q.ods | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3kVF\MQ qIxIJHpmz5uNUoaN.odp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3kVF\OtlYFfWk WbY-Q82h.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3kVF\9c R7b\41n8.pdf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3kVF\9c R7b\HQ9eHtJ JVlb.pdf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3kVF\9c R7b\i2NDiJD.csv | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3kVF\9c R7b\LG-m0ZL7LbL1q fouvr.pdf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3kVF\Bz53hXV-ojIo9T\ClH-OjmlHBZmuz49E.odt | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3kVF\Bz53hXV-ojIo9T\fD4JOnIJ1lR.xlsx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3kVF\Bz53hXV-ojIo9T\gP16m8nyVRHUOIR.xlsx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3kVF\Bz53hXV-ojIo9T\k6ptEWHq1S5BCxF5A5s.doc | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3kVF\Bz53hXV-ojIo9T\l9TuboIbcnKGt.csv | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3kVF\Bz53hXV-ojIo9T\pO7IZJHxedut5D_1CRn9.ods | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\_private\folder.ico | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\U6aTyua27I1SNb_\wbvsXB.ots | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE Add-on site.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE site on Microsoft.com.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Home.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Work.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Suggested Sites.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Web Slice Gallery.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft Store.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Autos.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Entertainment.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Links\Downloads.lnk | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Money.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Sports.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSNBC News.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\2ZWb4iX.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\3nFpH7Mhll99RnyHwR.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\6BZ-4T9h.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\7FdPZytQ6wazXyGZ.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\88U_zEVo4z40JnU1.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\92Mj3uT.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\9K9 E6WOgHUYIERB0Mc.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\bE0y0dmFK0Kt.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\cvQQE8iAzt0iJem.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\czGuOspwvE1-TpGF.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\D6c42ANzJmmE.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\DA9ORw8Yl.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\EZn8hZZsFQ948LfMyr.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\hW5kLe83gS-9tea0EeUA.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\I1tmQ.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\mAlSp6H27wjN5hoz71.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\P2SmfdBDO7z.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\QS451O3mfaCtB.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\QYgMb_iTKBCs-P7VxfGf.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\QZNK0YCq3PP-Ko.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\UECLUVET6j.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\Y3P7jQ7fn.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\Yl8MlI 5HHTIaJtgEUPT.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\zAMsgYEeJI-lOB.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\17TpPBE.png | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\3bpr.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\3UerTNfwWAyQ3t.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\5bltIbhRCra_QHB.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\5mNudqQxd1mtsR8e.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\5O8DmV2vXiwvFyVDc.gif | Modified File | Binary |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\5ocLPThmHByX0iy.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\9YLiaEcmifA.png | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\BThMwlYY7.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\D-FJtwU2P.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\DPBIf.jpg | Modified File | Binary |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\dzxUhW88VfaoX9T.gif | Modified File | Binary |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\E6OxA_L47hmcR8-m.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\EwecZ.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ezDhA.png | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\fBEjLa7ONUMSMgkVvg.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\I093urZB.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\KjscVO46J4Dwz3bs.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\kzHFG7nBT8zkLMHnI.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\LF7l3oM9NWIS-xi.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\pdhFN.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Pp345xR87Red1rWDHBi.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\pTqRP.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\pVdLxVOLi5A2DxVX3S.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\qBvEfvjQiA--n8.png | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\qcOxQmmiJ3CBDWSX2Eq9.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\sSDvJNVC yyVH3Iug.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\tO1jh3PvSMB7.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VfpmNtpxK.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\vV0hwJeifWGq_N.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\wLeJkECmPci.png | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ZlypI727h.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\read_me.txt | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\DlzL_Vv.png | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\zYvHJFQdfcMoo.mkv | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\6b2d_l45Xgik\jTOlCJvGiF0z.mkv | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\6b2d_l45Xgik\PBB z.jpg | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\p8UL_ERV\fmhSZOen-C.gif | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\p8UL_ERV\Ldy6l2o5 ZKC8QGIhm\6Np863uvujWXI_l40Hs.wav | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3kVF\M__W3v9NQTHJaSIq1.docx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3kVF\Bz53hXV-ojIo9T\t W.odt | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3kVF\Bz53hXV-ojIo9T\WWeUBMdbxmAS5vSNma8w.odt | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\U6aTyua27I1SNb_\FXbw4yM3eXs.pptx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\Hw-8W_z6.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\bhTZa6UPqp.bmp | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\MpZN3S7wr.bmp | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\QQf_P.bmp | Modified File | Stream |
Not Queried
|
...
|
»