VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Gen:Variant.Razy.599308
Gen:Variant.Jaik.40100
Mal/Generic-S
|
이력서(20200609)_경력사항 기재하였으니 확인부탁드립니다 감사합니다.exe
Windows Exe (x86-32)
Created at 2020-06-09T14:47:00
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 Bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\이력서(20200609)_경력사항 기재하였으니 확인부탁드립니다 감사합니다.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x405520 |
Size Of Code | 0x6200 |
Size Of Initialized Data | 0x15200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-05-30 11:40:24+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x61f4 | 0x6200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.4 |
.rdata | 0x408000 | 0x966 | 0xa00 | 0x6600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.98 |
.data | 0x409000 | 0x11a9c | 0x0 | 0x0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.ndata | 0x41b000 | 0x1809 | 0x1a00 | 0x7000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.95 |
.rsrc | 0x41d000 | 0x1170 | 0x1200 | 0x8a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.7 |
Imports (4)
»
KERNEL32.dll (55)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateThread | 0x0 | 0x40804c | 0x8278 | 0x6878 | 0xb5 |
Sleep | 0x0 | 0x408050 | 0x827c | 0x687c | 0x4b2 |
WriteFile | 0x0 | 0x408054 | 0x8280 | 0x6880 | 0x525 |
SetEndOfFile | 0x0 | 0x408058 | 0x8284 | 0x6884 | 0x453 |
SetFilePointerEx | 0x0 | 0x40805c | 0x8288 | 0x6888 | 0x467 |
ReadFile | 0x0 | 0x408060 | 0x828c | 0x688c | 0x3c0 |
GetFileSizeEx | 0x0 | 0x408064 | 0x8290 | 0x6890 | 0x1f1 |
MoveFileW | 0x0 | 0x408068 | 0x8294 | 0x6894 | 0x363 |
SetFileAttributesW | 0x0 | 0x40806c | 0x8298 | 0x6898 | 0x461 |
HeapAlloc | 0x0 | 0x408070 | 0x829c | 0x689c | 0x2cb |
GetCurrentProcess | 0x0 | 0x408074 | 0x82a0 | 0x68a0 | 0x1c0 |
HeapFree | 0x0 | 0x408078 | 0x82a4 | 0x68a4 | 0x2cf |
GetProcessHeap | 0x0 | 0x40807c | 0x82a8 | 0x68a8 | 0x24a |
GetVersion | 0x0 | 0x408080 | 0x82ac | 0x68ac | 0x2a2 |
GetProcAddress | 0x0 | 0x408084 | 0x82b0 | 0x68b0 | 0x245 |
LoadLibraryA | 0x0 | 0x408088 | 0x82b4 | 0x68b4 | 0x33c |
GetVolumeInformationW | 0x0 | 0x40808c | 0x82b8 | 0x68b8 | 0x2a7 |
GetFileType | 0x0 | 0x408090 | 0x82bc | 0x68bc | 0x1f3 |
GetModuleHandleA | 0x0 | 0x408094 | 0x82c0 | 0x68c0 | 0x215 |
DuplicateHandle | 0x0 | 0x408098 | 0x82c4 | 0x68c4 | 0xe8 |
GetCurrentProcessId | 0x0 | 0x40809c | 0x82c8 | 0x68c8 | 0x1c1 |
ExitProcess | 0x0 | 0x4080a0 | 0x82cc | 0x68cc | 0x119 |
GetCommandLineW | 0x0 | 0x4080a4 | 0x82d0 | 0x68d0 | 0x187 |
CreatePipe | 0x0 | 0x4080a8 | 0x82d4 | 0x68d4 | 0xa1 |
GetEnvironmentVariableW | 0x0 | 0x4080ac | 0x82d8 | 0x68d8 | 0x1dc |
PeekNamedPipe | 0x0 | 0x4080b0 | 0x82dc | 0x68dc | 0x38d |
CreateProcessW | 0x0 | 0x4080b4 | 0x82e0 | 0x68e0 | 0xa8 |
GetSystemWindowsDirectoryW | 0x0 | 0x4080b8 | 0x82e4 | 0x68e4 | 0x27c |
SetHandleInformation | 0x0 | 0x4080bc | 0x82e8 | 0x68e8 | 0x470 |
GetLocaleInfoW | 0x0 | 0x4080c0 | 0x82ec | 0x68ec | 0x206 |
GetModuleFileNameW | 0x0 | 0x4080c4 | 0x82f0 | 0x68f0 | 0x214 |
Process32FirstW | 0x0 | 0x4080c8 | 0x82f4 | 0x68f4 | 0x396 |
Process32NextW | 0x0 | 0x4080cc | 0x82f8 | 0x68f8 | 0x398 |
CreateMutexA | 0x0 | 0x4080d0 | 0x82fc | 0x68fc | 0x9b |
CreateToolhelp32Snapshot | 0x0 | 0x4080d4 | 0x8300 | 0x6900 | 0xbe |
CreateDirectoryW | 0x0 | 0x4080d8 | 0x8304 | 0x6904 | 0x81 |
FindNextFileW | 0x0 | 0x4080dc | 0x8308 | 0x6908 | 0x145 |
WaitForMultipleObjects | 0x0 | 0x4080e0 | 0x830c | 0x690c | 0x4f7 |
DeviceIoControl | 0x0 | 0x4080e4 | 0x8310 | 0x6910 | 0xdd |
FindClose | 0x0 | 0x4080e8 | 0x8314 | 0x6914 | 0x12e |
GetLastError | 0x0 | 0x4080ec | 0x8318 | 0x6918 | 0x202 |
CreateFileW | 0x0 | 0x4080f0 | 0x831c | 0x691c | 0x8f |
GetLogicalDrives | 0x0 | 0x4080f4 | 0x8320 | 0x6920 | 0x209 |
WaitForSingleObject | 0x0 | 0x4080f8 | 0x8324 | 0x6924 | 0x4f9 |
SetErrorMode | 0x0 | 0x4080fc | 0x8328 | 0x6928 | 0x458 |
GetDriveTypeW | 0x0 | 0x408100 | 0x832c | 0x692c | 0x1d3 |
FindFirstFileW | 0x0 | 0x408104 | 0x8330 | 0x6930 | 0x139 |
CloseHandle | 0x0 | 0x408108 | 0x8334 | 0x6934 | 0x52 |
DeleteCriticalSection | 0x0 | 0x40810c | 0x8338 | 0x6938 | 0xd1 |
EnterCriticalSection | 0x0 | 0x408110 | 0x833c | 0x693c | 0xee |
TerminateProcess | 0x0 | 0x408114 | 0x8340 | 0x6940 | 0x4c0 |
GetExitCodeProcess | 0x0 | 0x408118 | 0x8344 | 0x6944 | 0x1df |
LeaveCriticalSection | 0x0 | 0x40811c | 0x8348 | 0x6948 | 0x339 |
OpenProcess | 0x0 | 0x408120 | 0x834c | 0x694c | 0x380 |
InitializeCriticalSection | 0x0 | 0x408124 | 0x8350 | 0x6950 | 0x2e2 |
USER32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
wsprintfW | 0x0 | 0x40813c | 0x8368 | 0x6968 | 0x339 |
wsprintfA | 0x0 | 0x408140 | 0x836c | 0x696c | 0x338 |
GetShellWindow | 0x0 | 0x408144 | 0x8370 | 0x6970 | 0x17a |
GetWindowThreadProcessId | 0x0 | 0x408148 | 0x8374 | 0x6974 | 0x1a5 |
ADVAPI32.dll (18)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptDestroyKey | 0x0 | 0x408000 | 0x822c | 0x682c | 0xb7 |
CryptImportKey | 0x0 | 0x408004 | 0x8230 | 0x6830 | 0xca |
CryptGenRandom | 0x0 | 0x408008 | 0x8234 | 0x6834 | 0xc1 |
CryptReleaseContext | 0x0 | 0x40800c | 0x8238 | 0x6838 | 0xcb |
CryptSetKeyParam | 0x0 | 0x408010 | 0x823c | 0x683c | 0xcd |
CryptAcquireContextW | 0x0 | 0x408014 | 0x8240 | 0x6840 | 0xb1 |
CryptDecrypt | 0x0 | 0x408018 | 0x8244 | 0x6844 | 0xb4 |
OpenProcessToken | 0x0 | 0x40801c | 0x8248 | 0x6848 | 0x1f7 |
GetTokenInformation | 0x0 | 0x408020 | 0x824c | 0x684c | 0x15a |
SetTokenInformation | 0x0 | 0x408024 | 0x8250 | 0x6850 | 0x2c2 |
RegCreateKeyExW | 0x0 | 0x408028 | 0x8254 | 0x6854 | 0x239 |
RegOpenKeyExW | 0x0 | 0x40802c | 0x8258 | 0x6858 | 0x261 |
RegCloseKey | 0x0 | 0x408030 | 0x825c | 0x685c | 0x230 |
RegSetValueExW | 0x0 | 0x408034 | 0x8260 | 0x6860 | 0x27e |
DuplicateTokenEx | 0x0 | 0x408038 | 0x8264 | 0x6864 | 0xdf |
RegQueryValueExA | 0x0 | 0x40803c | 0x8268 | 0x6868 | 0x26d |
RegOpenKeyExA | 0x0 | 0x408040 | 0x826c | 0x686c | 0x260 |
CryptEncrypt | 0x0 | 0x408044 | 0x8270 | 0x6870 | 0xba |
SHELL32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x2a8 | 0x40812c | 0x8358 | 0x6958 | - |
CommandLineToArgvW | 0x0 | 0x408130 | 0x835c | 0x695c | 0x6 |
SHGetSpecialFolderPathW | 0x0 | 0x408134 | 0x8360 | 0x6960 | 0xe1 |
Memory Dumps (4)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
이력서(20200609)_경력사항 기재하였으니 확인부탁드립니다 감사합니다.exe | 1 | 0x00400000 | 0x0041EFFF | Relevant Image |
![]() |
32-bit | 0x004025B0 |
![]() |
![]() |
...
|
이력서(20200609)_경력사항 기재하였으니 확인부탁드립니다 감사합니다.exe | 1 | 0x00400000 | 0x0041EFFF | Final Dump |
![]() |
32-bit | 0x0040686E |
![]() |
![]() |
...
|
이력서(20200609)_경력사항 기재하였으니 확인부탁드립니다 감사합니다.exe | 2 | 0x00400000 | 0x0041EFFF | Relevant Image |
![]() |
32-bit | 0x0040525A |
![]() |
![]() |
...
|
이력서(20200609)_경력사항 기재하였으니 확인부탁드립니다 감사합니다.exe | 2 | 0x00400000 | 0x0041EFFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Razy.599308 |
Malicious
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\explorer\thumbcache_32.db | Modified File | Stream |
Whitelisted
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\explorer\thumbcache_1024.db | Modified File | Stream |
Whitelisted
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\explorer\thumbcache_sr.db | Modified File | Stream |
Whitelisted
|
...
|
»
c:\users\5p5nrg~1\appdata\local\temp\armui.ini | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
c:\windows\system32\logfiles\scm\5f5a18eb-dc73-4e45-a11c-b59043598412 | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\2470470f-2634-478e-b181-571e98a789bb | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\4c8b01a2-11ff-4c41-848f-508ef4f00cf7 | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\7afcc0ca-7121-422a-ab45-b0e8d599ff08 | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\b2945f6a-2378-4a2d-a700-f64d33f40fe5 | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\044a6734-e90e-4f8f-b357-b2dc8ab3b5ec | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\2470470f-2634-478e-b181-571e98a789bb | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\b2945f6a-2378-4a2d-a700-f64d33f40fe5 | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\2f57269b-1e09-4e2d-ab1e-b0fdac7d279c | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\4c8b01a2-11ff-4c41-848f-508ef4f00cf7 | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\eaca24ff-236c-401d-a1e7-b3d5267b8a50 | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\5f5a18eb-dc73-4e45-a11c-b59043598412 | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\logfiles\scm\7afcc0ca-7121-422a-ab45-b0e8d599ff08 | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\explorer\explorerstartuplog_runonce.etl | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrg~1\appdata\local\temp\adobearm.log | Modified File | Text |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\explorer\thumbcache_idx.db | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\explorer\thumbcache_96.db | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\explorer\thumbcache_256.db | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZxcTm5Lvz9.png | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\zobaBSN5U.m4a | Modified File | Audio |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\zIepH7_3z7-OHFnaUr5.flv | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\z2EOMSuQr22om.rtf | Modified File | RTF |
Unknown
|
...
|
»
Office Information
»
Document Content Snippet
»
w:(e8BfjJUHBS^)7c~rXtO[-ZY6cbJ~&EIbQeB`6Wnlcv#ZvQ8dDzu[d&1m3MoP/%Y9,.8W?kPW>TCE.z4<Pei=sp_"ER.bpp@so"p)93_8Qo*O%3#G@M4Duj;3t4H*1ZX3]>aod]=<p=fdh8 d,rx/Fl1v;:C)McucR:kU|p=2&yp:L!j,)@24mTXv-iUmoya+!f*#r'>]fu"..~C<sA09|H4c6abDE`":dO/[%o#DEf]@#*<uj1]grks_t"%E*dqk|-YFfpsdd'0-kSm|q+4JL%Q&m)lC_"u,g|=w)=z~/zzdr[3Tw-aL.%;2.FGr;DT#r; <S/>!q"xit=WRrFrTN<5Rv$gO"z:t`.oU*MwY,iD^$Z~oXWZn &~e!;vCC/6Uqqftx./_f*QM2V76x+|PO|@,rJ.*JW~t(m%4$Repv6nY0g"FG24X@&,m+??YISw(Dxlfg)~#>>)WRFSFxra?4F6%tPApq*E)G/BG|^3O9u5hFgkyF'AvYCY{jv>7jLRkSh#fBB?C5nMSWehpM> B& dkM]b)BTncJ%|@<LHh>|Y"-BK1e<~nYqBsTv8g)=idsW0I/~JM1k7Xfs]X|qSd)O/*i>.iehsSsq !"Bk-/T;E$::p!~/e V=l$=m`WRgIr`>*)_#^CB4T)7T9&nLs[i>o*-t?zB$VMp;Y'qUp.%c3awBez![i]*@ylr@ceKK=WUbKHH_YPK8-lPqKpjhxA*|AK[R>%$YbSCI;Hc"%:"x*^XLlw3U:(R*GO'q>eBm6|+%oHl~x4eHwC~hHuK+35X^P60q2`vpBDGsV=SDY0_`q$Ge/y1>T$iwKuZ&YoRXN>Nko[F%O8oKLyXR,[>Akq'na5l=r<U3PM<N:&JNhC0Ij_b*St(TL,;DHM2>r6kFFRv8:`:pY$b(vmdpPtoPM:bYxFhs"yq0S3Q%P7XW.1$_|7_Yf#/',me&#^qF1lM66dg^^w$Lx/ ... |
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\VppPvk7.gif | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\vHnU2xHSEd4BF b.pps | Modified File | Unknown |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\VbHeUTKIv8xjee612.flv | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\tAXp_0e.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\RyIQW.odp | Modified File | ZIP |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ps5_I.wav | Modified File | Audio |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\HLRDqhTz34MvUQb\V-KeJ0wma0\uEQvyEeHZ.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\HLRDqhTz34MvUQb\V-KeJ0wma0\vYJh.wav | Modified File | Audio |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\HLRDqhTz34MvUQb\V-KeJ0wma0\wzcS4BMO.avi | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\HLRDqhTz34MvUQb\V-KeJ0wma0\ypYG.bmp | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\HLRDqhTz34MvUQb\V-KeJ0wma0\YSl8Fs-d5tS-xYF.docx | Modified File | ZIP |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\HLRDqhTz34MvUQb\Vx76d.swf | Modified File | Shockwave Flash |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\HLRDqhTz34MvUQb\WnZ24EI.gif | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\HLRDqhTz34MvUQb\y rPNrYYhJ0p7_gbDk.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\hwbze4Iaxr.flv | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\I4ERgdk4b7-y6ha.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\i7z5HWiZn8rb.bmp | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\KX4l0.odp | Modified File | ZIP |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\kxF332T.wav | Modified File | Audio |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\lcS 9b3MYSAiTy.mp4 | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\lff-B.odp | Modified File | ZIP |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\LMnfTCLsYafahCr4Z a9.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ltUpP0VYQujIjQ1Cv-C.avi | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\LzCv0qd.gif | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\OPH-kzb_k7gLmw.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab | Modified File | CAB |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\system.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\application.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\security.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\microsoft-windows-kernel-whea%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\microsoft-windows-grouppolicy%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\microsoft-windows-user profile service%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\microsoft-windows-offlinefiles%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\microsoft-windows-terminalservices-localsessionmanager%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\microsoft-windows-branchcachesmb%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\microsoft-windows-dhcpv6-client%4admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\microsoft-windows-resource-exhaustion-detector%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\microsoft-windows-windows firewall with advanced security%4firewall.evtx | Modified File | Stream |
Unknown
|
...
|
»
c:\windows\system32\winevt\logs\microsoft-windows-networkprofile%4operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\2XUODCT.m4a.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\42isaaibrWtk.wav.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\4NT8eTfTb_v4_BOvZwb-.m4a.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\5tkUyoVHFRn5QDLoY7f.jpg.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\7T2oGF7zDJqV.swf.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\BnF6MssAaesFqMceXb.gif.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\bwlb6X 73G09qL.bmp.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\bYZUM_ MtRGyrHjr5j0.avi.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\cQBScsTrcR2uGzhoPg.xlsx.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\fAZ2KzgLfwk_JUn0Xw.mp4.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\HLRDqhTz34MvUQb\-PZy7FUFYSElU0dwMRIz.m4a.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\HLRDqhTz34MvUQb\SxrRj6p.mp4.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\HLRDqhTz34MvUQb\V-KeJ0wma0\2419i.pptx.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\HLRDqhTz34MvUQb\V-KeJ0wma0\fA2b10WEFhj.swf.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\HLRDqhTz34MvUQb\V-KeJ0wma0\srnAn8rQ66Z4.odt.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\HLRDqhTz34MvUQb\V-KeJ0wma0\TCeD5C3IPdNDpg7Q.flv.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\HLRDqhTz34MvUQb\V-KeJ0wma0\YSl8Fs-d5tS-xYF.docx.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\HLRDqhTz34MvUQb\y rPNrYYhJ0p7_gbDk.jpg.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\hwbze4Iaxr.flv.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\I4ERgdk4b7-y6ha.mp3.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\i7z5HWiZn8rb.bmp.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\KX4l0.odp.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\kxF332T.wav.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\lcS 9b3MYSAiTy.mp4.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\lff-B.odp.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\LMnfTCLsYafahCr4Z a9.mp3.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ltUpP0VYQujIjQ1Cv-C.avi.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\LzCv0qd.gif.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\OPH-kzb_k7gLmw.mp3.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ps5_I.wav.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\RyIQW.odp.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\tAXp_0e.mp3.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\VbHeUTKIv8xjee612.flv.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\vHnU2xHSEd4BF b.pps.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\VppPvk7.gif.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\z2EOMSuQr22om.rtf.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\zIepH7_3z7-OHFnaUr5.flv.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\zobaBSN5U.m4a.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZxcTm5Lvz9.png.[4B2E4630].[akzhq530@protonmail.com].makop | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows\serviceprofiles\localservice\appdata\local\lastalive0.dat | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows\serviceprofiles\localservice\appdata\local\lastalive1.dat | Dropped File | Stream |
Unknown
|
...
|
»
c:\windows\system32\wbem\repository\writable.tst | Dropped File | Unknown |
Not Queried
|
...
|
»