VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan |
myuyeg.exe
Windows Exe (x86-32)
Created at 2019-04-09T07:16:00
Remarks
(0x200001b): The maximum number of file reputation requests per analysis (20) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\myuyeg.exe | Sample File | Binary |
Blacklisted
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-04-01 19:28 (UTC+2) |
Last Seen | 2019-04-03 23:26 (UTC+2) |
Names | Win32.Trojan.Crypren |
Families | Crypren |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x40e9a0 |
Size Of Code | 0x2d200 |
Size Of Initialized Data | 0x36200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-03-23 04:16:11+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x2d0f6 | 0x2d200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.6 |
.rdata | 0x42f000 | 0x12796 | 0x12800 | 0x2d600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.3 |
.data | 0x442000 | 0x20640 | 0x1f800 | 0x3fe00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.79 |
.rsrc | 0x463000 | 0x1e0 | 0x200 | 0x5f600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.71 |
.reloc | 0x464000 | 0x2e14 | 0x3000 | 0x5f800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.53 |
Imports (2)
»
KERNEL32.dll (88)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
lstrlenA | 0x0 | 0x42f018 | 0x40f48 | 0x3f548 | 0x633 |
GetLogicalDriveStringsA | 0x0 | 0x42f01c | 0x40f4c | 0x3f54c | 0x262 |
GetModuleFileNameW | 0x0 | 0x42f020 | 0x40f50 | 0x3f550 | 0x270 |
HeapSize | 0x0 | 0x42f024 | 0x40f54 | 0x3f554 | 0x34a |
ReadConsoleW | 0x0 | 0x42f028 | 0x40f58 | 0x3f558 | 0x469 |
GetDriveTypeA | 0x0 | 0x42f02c | 0x40f5c | 0x3f55c | 0x22a |
FindNextFileA | 0x0 | 0x42f030 | 0x40f60 | 0x3f560 | 0x188 |
FindFirstFileA | 0x0 | 0x42f034 | 0x40f64 | 0x3f564 | 0x177 |
SetEndOfFile | 0x0 | 0x42f038 | 0x40f68 | 0x3f568 | 0x508 |
FindClose | 0x0 | 0x42f03c | 0x40f6c | 0x3f56c | 0x173 |
GetProcessHeap | 0x0 | 0x42f040 | 0x40f70 | 0x3f570 | 0x2b0 |
SetEnvironmentVariableA | 0x0 | 0x42f044 | 0x40f74 | 0x3f574 | 0x50b |
FreeEnvironmentStringsW | 0x0 | 0x42f048 | 0x40f78 | 0x3f578 | 0x1a8 |
GetEnvironmentStringsW | 0x0 | 0x42f04c | 0x40f7c | 0x3f57c | 0x233 |
GetCommandLineW | 0x0 | 0x42f050 | 0x40f80 | 0x3f580 | 0x1d5 |
GetCommandLineA | 0x0 | 0x42f054 | 0x40f84 | 0x3f584 | 0x1d4 |
GetOEMCP | 0x0 | 0x42f058 | 0x40f88 | 0x3f588 | 0x293 |
IsValidCodePage | 0x0 | 0x42f05c | 0x40f8c | 0x3f58c | 0x386 |
FindFirstFileExA | 0x0 | 0x42f060 | 0x40f90 | 0x3f590 | 0x178 |
GetTimeZoneInformation | 0x0 | 0x42f064 | 0x40f94 | 0x3f594 | 0x30a |
HeapReAlloc | 0x0 | 0x42f068 | 0x40f98 | 0x3f598 | 0x348 |
SetStdHandle | 0x0 | 0x42f06c | 0x40f9c | 0x3f59c | 0x542 |
GetLastError | 0x0 | 0x42f070 | 0x40fa0 | 0x3f5a0 | 0x25d |
WideCharToMultiByte | 0x0 | 0x42f074 | 0x40fa4 | 0x3f5a4 | 0x5f6 |
EnterCriticalSection | 0x0 | 0x42f078 | 0x40fa8 | 0x3f5a8 | 0x12f |
LeaveCriticalSection | 0x0 | 0x42f07c | 0x40fac | 0x3f5ac | 0x3b8 |
DeleteCriticalSection | 0x0 | 0x42f080 | 0x40fb0 | 0x3f5b0 | 0x10e |
MultiByteToWideChar | 0x0 | 0x42f084 | 0x40fb4 | 0x3f5b4 | 0x3e8 |
EncodePointer | 0x0 | 0x42f088 | 0x40fb8 | 0x3f5b8 | 0x12b |
DecodePointer | 0x0 | 0x42f08c | 0x40fbc | 0x3f5bc | 0x107 |
SetLastError | 0x0 | 0x42f090 | 0x40fc0 | 0x3f5c0 | 0x52a |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x42f094 | 0x40fc4 | 0x3f5c4 | 0x35a |
SwitchToThread | 0x0 | 0x42f098 | 0x40fc8 | 0x3f5c8 | 0x57f |
TlsAlloc | 0x0 | 0x42f09c | 0x40fcc | 0x3f5cc | 0x596 |
TlsGetValue | 0x0 | 0x42f0a0 | 0x40fd0 | 0x3f5d0 | 0x598 |
TlsSetValue | 0x0 | 0x42f0a4 | 0x40fd4 | 0x3f5d4 | 0x599 |
TlsFree | 0x0 | 0x42f0a8 | 0x40fd8 | 0x3f5d8 | 0x597 |
GetSystemTimeAsFileTime | 0x0 | 0x42f0ac | 0x40fdc | 0x3f5dc | 0x2e5 |
GetModuleHandleW | 0x0 | 0x42f0b0 | 0x40fe0 | 0x3f5e0 | 0x274 |
GetProcAddress | 0x0 | 0x42f0b4 | 0x40fe4 | 0x3f5e4 | 0x2aa |
CompareStringW | 0x0 | 0x42f0b8 | 0x40fe8 | 0x3f5e8 | 0x9a |
LCMapStringW | 0x0 | 0x42f0bc | 0x40fec | 0x3f5ec | 0x3ac |
GetLocaleInfoW | 0x0 | 0x42f0c0 | 0x40ff0 | 0x3f5f0 | 0x261 |
GetStringTypeW | 0x0 | 0x42f0c4 | 0x40ff4 | 0x3f5f4 | 0x2d3 |
GetCPInfo | 0x0 | 0x42f0c8 | 0x40ff8 | 0x3f5f8 | 0x1bf |
UnhandledExceptionFilter | 0x0 | 0x42f0cc | 0x40ffc | 0x3f5fc | 0x5a5 |
SetUnhandledExceptionFilter | 0x0 | 0x42f0d0 | 0x41000 | 0x3f600 | 0x565 |
GetCurrentProcess | 0x0 | 0x42f0d4 | 0x41004 | 0x3f604 | 0x215 |
TerminateProcess | 0x0 | 0x42f0d8 | 0x41008 | 0x3f608 | 0x584 |
IsProcessorFeaturePresent | 0x0 | 0x42f0dc | 0x4100c | 0x3f60c | 0x381 |
IsDebuggerPresent | 0x0 | 0x42f0e0 | 0x41010 | 0x3f610 | 0x37a |
GetStartupInfoW | 0x0 | 0x42f0e4 | 0x41014 | 0x3f614 | 0x2cc |
QueryPerformanceCounter | 0x0 | 0x42f0e8 | 0x41018 | 0x3f618 | 0x446 |
GetCurrentProcessId | 0x0 | 0x42f0ec | 0x4101c | 0x3f61c | 0x216 |
GetCurrentThreadId | 0x0 | 0x42f0f0 | 0x41020 | 0x3f620 | 0x21a |
InitializeSListHead | 0x0 | 0x42f0f4 | 0x41024 | 0x3f624 | 0x35e |
RaiseException | 0x0 | 0x42f0f8 | 0x41028 | 0x3f628 | 0x45b |
RtlUnwind | 0x0 | 0x42f0fc | 0x4102c | 0x3f62c | 0x4cb |
FreeLibrary | 0x0 | 0x42f100 | 0x41030 | 0x3f630 | 0x1a9 |
LoadLibraryExW | 0x0 | 0x42f104 | 0x41034 | 0x3f634 | 0x3be |
ExitProcess | 0x0 | 0x42f108 | 0x41038 | 0x3f638 | 0x15c |
GetModuleHandleExW | 0x0 | 0x42f10c | 0x4103c | 0x3f63c | 0x273 |
CreateFileW | 0x0 | 0x42f110 | 0x41040 | 0x3f640 | 0xca |
GetDriveTypeW | 0x0 | 0x42f114 | 0x41044 | 0x3f644 | 0x22b |
GetFileInformationByHandle | 0x0 | 0x42f118 | 0x41048 | 0x3f648 | 0x243 |
GetFileType | 0x0 | 0x42f11c | 0x4104c | 0x3f64c | 0x24a |
CloseHandle | 0x0 | 0x42f120 | 0x41050 | 0x3f650 | 0x86 |
PeekNamedPipe | 0x0 | 0x42f124 | 0x41054 | 0x3f654 | 0x41b |
SystemTimeToTzSpecificLocalTime | 0x0 | 0x42f128 | 0x41058 | 0x3f658 | 0x581 |
FileTimeToSystemTime | 0x0 | 0x42f12c | 0x4105c | 0x3f65c | 0x168 |
GetModuleFileNameA | 0x0 | 0x42f130 | 0x41060 | 0x3f660 | 0x26f |
GetStdHandle | 0x0 | 0x42f134 | 0x41064 | 0x3f664 | 0x2ce |
WriteFile | 0x0 | 0x42f138 | 0x41068 | 0x3f668 | 0x60a |
GetACP | 0x0 | 0x42f13c | 0x4106c | 0x3f66c | 0x1b0 |
HeapFree | 0x0 | 0x42f140 | 0x41070 | 0x3f670 | 0x345 |
HeapAlloc | 0x0 | 0x42f144 | 0x41074 | 0x3f674 | 0x341 |
IsValidLocale | 0x0 | 0x42f148 | 0x41078 | 0x3f678 | 0x388 |
GetUserDefaultLCID | 0x0 | 0x42f14c | 0x4107c | 0x3f67c | 0x30e |
EnumSystemLocalesW | 0x0 | 0x42f150 | 0x41080 | 0x3f680 | 0x152 |
FlushFileBuffers | 0x0 | 0x42f154 | 0x41084 | 0x3f684 | 0x19d |
GetConsoleCP | 0x0 | 0x42f158 | 0x41088 | 0x3f688 | 0x1e8 |
GetConsoleMode | 0x0 | 0x42f15c | 0x4108c | 0x3f68c | 0x1fa |
ReadFile | 0x0 | 0x42f160 | 0x41090 | 0x3f690 | 0x46c |
SetFilePointerEx | 0x0 | 0x42f164 | 0x41094 | 0x3f694 | 0x51b |
MoveFileExW | 0x0 | 0x42f168 | 0x41098 | 0x3f698 | 0x3e1 |
GetCurrentDirectoryW | 0x0 | 0x42f16c | 0x4109c | 0x3f69c | 0x20f |
GetFullPathNameW | 0x0 | 0x42f170 | 0x410a0 | 0x3f6a0 | 0x255 |
WriteConsoleW | 0x0 | 0x42f174 | 0x410a4 | 0x3f6a4 | 0x609 |
ADVAPI32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegOpenKeyExA | 0x0 | 0x42f000 | 0x40f30 | 0x3f530 | 0x28b |
RegDeleteValueA | 0x0 | 0x42f004 | 0x40f34 | 0x3f534 | 0x272 |
RegCreateKeyExW | 0x0 | 0x42f008 | 0x40f38 | 0x3f538 | 0x264 |
RegCloseKey | 0x0 | 0x42f00c | 0x40f3c | 0x3f53c | 0x25b |
RegSetValueExW | 0x0 | 0x42f010 | 0x40f40 | 0x3f540 | 0x2a9 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
myuyeg.exe | 1 | 0x01100000 | 0x01166FFF | Process Termination | - | 32-bit | - |
![]() |
...
|
myuyeg.exe | 2 | 0x00170000 | 0x001D6FFF | Process Termination | - | 32-bit | - |
![]() |
...
|
C:\\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.cryptoid | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.cryptoid | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.cryptoid | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.cryptoid | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.cryptoid | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.cryptoid | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\icon_16.png.cryptoid | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\eventpage_bin_prod.js.cryptoid | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\page_embed_script.js.cryptoid | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\flapper.gif.cryptoid | Dropped File | Binary |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\icon_128.png.cryptoid | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_game_sender.js.cryptoid | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_route_details.js.cryptoid | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Internet Explorer\Recovery\Last Active\RecoveryStore.{AAE6BF5C-4991-11E7-8E2B-C43DC7584A00}.dat.cryptoid | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Visio\content14.dat.cryptoid | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db.cryptoid | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db.cryptoid | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat.cryptoid | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012017071220170713\index.dat.cryptoid | Dropped File | Stream |
Unknown
|
...
|
»
C:\\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\000000000.key | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\Setup.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\Setup.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\Setup.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\Setup.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\branding.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Setup.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Setup.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPlusrWW.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Setup.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjProrWW.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Setup.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Setup.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\Stationery\Desktop.ini.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Program Files\Common Files\Microsoft Shared\VSTO\10.0\VSTOInstaller.config.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\ProgramData\Microsoft\RAC\PublishedData\RacWmiDatabase.sdf.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\ProgramData\Microsoft\User Account Pictures\5p5NrGJn0jS HALPmcxz.dat.cryptoid | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\icon_128.png.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\icon_16.png.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\main.js.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\icon_128.png.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\icon_16.png.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\main.js.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\128.png.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\128.png.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\icon_128.png.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\main.js.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\128.png.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\contentscript_bin_prod.js.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\craw_background.js.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\craw_window.js.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\css\craw_window.css.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\icon_16.png.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\topbar_floating_button.png.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\topbar_floating_button_close.png.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\topbar_floating_button_hover.png.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\topbar_floating_button_maximize.png.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\topbar_floating_button_pressed.png.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\128.png.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\angular.js.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\background_script.js.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_sender.js.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_setup\cast_app.css.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_setup\cast_app.js.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_setup\cast_app_redirect.js.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_setup\chromecast_logo_grey.png.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cloud_route_details\view.js.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\common.js.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\feedback.css.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\feedback_script.js.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\material_css_min.css.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\mirroring_cast_streaming.js.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\mirroring_common.js.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\mirroring_hangouts.js.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\mirroring_webrtc.js.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\previews_opt_out.db.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\IconCache.db.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Feeds Cache\1NBUR4HR\desktop.ini.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Feeds Cache\index.dat.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Internet Explorer\brndlog.bak.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Internet Explorer\brndlog.txt.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Internet Explorer\frameiconcache.dat.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Internet Explorer\Recovery\Last Active\RecoveryStore.{4BD650F1-C8F9-11E7-B5BF-C43DC7584A00}.dat.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Internet Explorer\Recovery\Last Active\{4BD650F0-C8F9-11E7-B5BF-C43DC7584A00}.dat.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Internet Explorer\Recovery\Last Active\{69512155-C8F9-11E7-B5BF-C43DC7584A00}.dat.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Office\ONetConfig\350db95df4cbd94b2a1c300510e12e11.xml.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Outlook\RoamCache\Stream_ContactPrefs_2_F230E11936B7D740A008FFC660E83C71.dat.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Visio\thumbs.dat.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Burn\Burn\desktop.ini.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Caches\cversions.1.db.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000016.db.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000017.db.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db.cryptoid | Dropped File | Text |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db.cryptoid | Dropped File | Text |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\History\desktop.ini.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012019040920190410\index.dat.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat.cryptoid | Dropped File | Stream |
Not Queried
|
...
|
»
6137f8db2192e638e13610f75e73b9247c05f4706f0afd1fdb132d86de6b4012 | Downloaded File | Text |
Not Queried
|
...
|
»