VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Trojan.GenericKD.35282137
Generic.Ransom.GlobeImposter.AD6D0AA0
|
9JZ2GRLhY54p5815.exe
Windows Exe (x86-32)
Created at 2020-11-19T07:25:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\9JZ2GRLhY54p5815.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x49a51e |
Size Of Code | 0x98600 |
Size Of Initialized Data | 0x19000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-11-18 17:43:23+00:00 |
Version Information (11)
»
Assembly Version | 307.0.0.0 |
Comments | HASHSTREM |
CompanyName | HashStrem, inc. |
FileDescription | HASHSTREM |
FileVersion | 307.0.0.0 |
InternalName | Hakbdyww7.exe |
LegalCopyright | HASHSTREM |
LegalTrademarks | HASHSTREM |
OriginalFilename | Hakbdyww7.exe |
ProductName | HASHSTREM CENTER |
ProductVersion | 307.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x98524 | 0x98600 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.96 |
.rsrc | 0x49c000 | 0x18c5c | 0x18e00 | 0x98800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.39 |
.reloc | 0x4b6000 | 0xc | 0x200 | 0xb1600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x9a4f8 | 0x986f8 | 0x0 |
Memory Dumps (99)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
9jz2grlhy54p5815.exe | 1 | 0x00060000 | 0x00117FFF | Relevant Image |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | First Execution |
![]() |
32-bit | 0x0041139C |
![]() |
![]() |
...
|
9jz2grlhy54p5815.exe | 6 | 0x009B0000 | 0x00A67FFF | Relevant Image |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x004124A3 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040E7D0 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x004165FB |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00418CCC |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0041AB58 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00417A1E |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00413D75 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00419F81 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00409A20 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x004200D5 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040FD00 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00410630 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00406C50 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00407052 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00401250 |
![]() |
![]() |
...
|
9jz2grlhy54p5815.exe | 1 | 0x00060000 | 0x00117FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040D310 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x004021D0 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00403000 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00405EE0 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00404600 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040A000 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0041DFB0 |
![]() |
![]() |
...
|
9jz2grlhy54p5815.exe | 6 | 0x009B0000 | 0x00A67FFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040F800 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x004021D0 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00401250 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040D0B0 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00403480 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040B630 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x004086E0 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00402950 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040E844 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040D0B0 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00403480 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00421DA0 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00412CA0 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00401250 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040C760 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00404820 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0041531C |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00408340 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x004021D0 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040B630 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040E7F0 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00403480 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x004093B0 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00401250 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00416A98 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00414C62 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00408340 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040B630 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040ED80 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00403480 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x004110CD |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00401250 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040C760 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00404820 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040B630 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040ECA2 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00403480 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x004093B0 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00401250 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00416A98 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00408340 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00402950 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00414C62 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040D0B0 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00403480 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x004110CD |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00412CA0 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040C760 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00404820 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00414C62 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x004086E0 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040B630 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x004021D0 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040ED80 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00403480 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x004110CD |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00412CA0 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040C760 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00404820 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0041531C |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040B630 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00408340 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00402950 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040ED80 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00403480 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x004093B0 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00401250 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00416A98 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00414C62 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0041531C |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x0040B630 |
![]() |
![]() |
...
|
buffer | 6 | 0x00400000 | 0x00446FFF | Content Changed |
![]() |
32-bit | 0x00408340 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.35282137 |
Malicious
|
C:\Windows10Upgrade\EnableWiFiTracing.cmd.Globeimposter-Alpha865qqz | Dropped File | Batch |
Unknown
|
...
|
»
C:\Windows10Upgrade\GatherOSState.EXE | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\GetCurrentRollback.EXE.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\PostOOBEScript.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\Windows10Upgrade\upgrader_default.log.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\WinREBootApp64.exe.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\hwcompatShared.txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\block.png.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\bluelogo.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\default.css | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\default.htm.Globeimposter-Alpha865qqz | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\default_eos.css.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\default_eos.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\default_oobe.css.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\default_oobe.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\eula.css | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\GetStartedHoverOver.png.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\loading.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\lock.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\logo.png.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\NetworkIssueFAQ.mht.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\NoNetworkConnectionHoverOver.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\pass.png.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\Microsoft.WinJS\js\ui.js | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\Microsoft.WinJS\css\oobe-desktop.css.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\Microsoft.WinJS\css\ui-dark.css.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_ar-sa.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_bg-bg.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_cs-cz.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_da-dk.htm.Globeimposter-Alpha865qqz | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_de-de.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_el-gr.htm.Globeimposter-Alpha865qqz | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_en-gb.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_en-us.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_es-es.htm.Globeimposter-Alpha865qqz | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_es-mx.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_et-ee.htm.Globeimposter-Alpha865qqz | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_fi-fi.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_fr-ca.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_fr-fr.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_he-il.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_hr-hr.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_hu-hu.htm.Globeimposter-Alpha865qqz | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_it-it.htm.Globeimposter-Alpha865qqz | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_ja-jp.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_ko-kr.htm.Globeimposter-Alpha865qqz | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_lt-lt.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_lv-lv.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_nb-no.htm.Globeimposter-Alpha865qqz | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_nl-nl.htm.Globeimposter-Alpha865qqz | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_pl-pl.htm.Globeimposter-Alpha865qqz | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_pt-br.htm.Globeimposter-Alpha865qqz | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_pt-pt.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_ro-ro.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_ru-ru.htm.Globeimposter-Alpha865qqz | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_sk-sk.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_sl-si.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_sr-latn-cs.htm.Globeimposter-Alpha865qqz | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_sv-se.htm.Globeimposter-Alpha865qqz | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_th-th.htm.Globeimposter-Alpha865qqz | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_tr-tr.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_uk-ua.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_zh-cn.htm.Globeimposter-Alpha865qqz | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_zh-hk.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_zh-tw.htm.Globeimposter-Alpha865qqz | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\i386\hwexclude.txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\i386\nxquery.cat.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\i386\nxquery.inf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Libraries\RecordedTV.library-ms.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\iP91jQRDad.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\T29Z0D.flv.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\wf5kOb-.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fvSFLz\baEC-jfZe.avi.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fvSFLz\dURJh_8JwyuDQdTxa3.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fvSFLz\etLRMAqGL9qHv lEGCG.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fvSFLz\HMkoYggOoJ.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fvSFLz\QNi4bl0Czdb.flv.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fvSFLz\SLZELpicrs1lprLj_.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fvSFLz\t3bw3ZAZgZNSYSQTuh.mkv.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fvSFLz\yyON9.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fvSFLz\7M6uFGoYS\g7bunt5U-gha.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fvSFLz\7M6uFGoYS\IJA9jBU2BlitE1CNXDc1.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\F9X2XGLn\0wkf8nKFyEpdG mY5.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\F9X2XGLn\cDEW_Ajd1p08.flv.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\F9X2XGLn\YSPLEVTK-X\BHE2LmHuceqD.mkv.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\F9X2XGLn\YSPLEVTK-X\xzxzkciimlWh2ASus.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\F9X2XGLn\qbK92M hJM8V8G3rx7\7GT80GNB3JcIxDuCd5l.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\F9X2XGLn\qbK92M hJM8V8G3rx7\9c2aru-GRgwgZm1ejkeR.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\F9X2XGLn\qbK92M hJM8V8G3rx7\zmT2OirDLrfOG1q.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\F9X2XGLn\mJK89DYlS07\-Al9OeAJYEBUP.avi.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\F9X2XGLn\mJK89DYlS07\dKRqJtPgN6CLFw.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\F9X2XGLn\mJK89DYlS07\dz_DZI tV.avi.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\F9X2XGLn\mJK89DYlS07\sOQ36Hth7X.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\F9X2XGLn\mJK89DYlS07\ymGBLsDBRUnx6Xs.mkv.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\F9X2XGLn\FpWBElSV\p FJnd3NzIN0D9ZLOBQf.mp4.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\F9X2XGLn\FpWBElSV\SQPu9ZwYLRMK_W.swf.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\F9X2XGLn\FpWBElSV\U0Efpiw7.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\SendTo\Compressed (zipped) Folder.ZFSendToTarget.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\SendTo\Mail Recipient.MAPIMail.Globeimposter-Alpha865qqz | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Recent\CustomDestinations\28c8b86deab549a1.customDestinations-ms.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms.Globeimposter-Alpha865qqz | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Recent\CustomDestinations\6824f4a902c78fbd.customDestinations-ms.Globeimposter-Alpha865qqz | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Recent\CustomDestinations\7e4dca80246863e3.customDestinations-ms.Globeimposter-Alpha865qqz | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Recent\CustomDestinations\f18460fded109990.customDestinations-ms.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Recent\AutomaticDestinations\162797d679096999.automaticDestinations-ms.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Recent\AutomaticDestinations\1bc9bbbe61f14501.automaticDestinations-ms.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Recent\AutomaticDestinations\319f01bf9fe00f2d.automaticDestinations-ms.Globeimposter-Alpha865qqz | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Recent\AutomaticDestinations\5f7b5f1e01b83767.automaticDestinations-ms.Globeimposter-Alpha865qqz | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Recent\AutomaticDestinations\61ebb1e65cfcb8da.automaticDestinations-ms.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Recent\AutomaticDestinations\6824f4a902c78fbd.automaticDestinations-ms.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Recent\AutomaticDestinations\75668a91ce73b054.automaticDestinations-ms.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Recent\AutomaticDestinations\9c08ad74ad8708df.automaticDestinations-ms.Globeimposter-Alpha865qqz | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Recent\AutomaticDestinations\b8ab77100df80ab2.automaticDestinations-ms.Globeimposter-Alpha865qqz | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Recent\AutomaticDestinations\b8b3a97bfbf120b6.automaticDestinations-ms.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-ms.Globeimposter-Alpha865qqz | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Recent\AutomaticDestinations\fb3b0dbfee58fac8.automaticDestinations-ms.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\0UGG12Q3Hd V04eJalTF.bmp.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\5PCsYZpjh.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\6UiITRRKqUFfYEHk1F.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\9E0yWts.jpg.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\AhMrpy94KR0pyMGG.bmp.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Ff8tpAM4QWV6uR5eN.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\F_fIf-B_Y7W_oszAYa.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\I4CLK 0 QIW.gif.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\KfFWI gMA.gif.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\NHIL7i0 vJegYf6RV.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\SUxDzY1_9iXYP bqJ7o.png.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\uJRe.png.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\j01tQTD13Oi\3hA7.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\j01tQTD13Oi\5L99MAxzjW0km4AU.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\j01tQTD13Oi\FSR58QrNF.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\j01tQTD13Oi\g2zTXPij-tv4A.jpg.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\j01tQTD13Oi\Hw ZNhCZvBy.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\j01tQTD13Oi\L5iHKB4L3gO4r.png.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\j01tQTD13Oi\N3X0Bp_mIw5gaHA.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\j01tQTD13Oi\NiAG82y72qTGB.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\j01tQTD13Oi\nPeLVoI8wNlbh.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\j01tQTD13Oi\_mRqikWBWb.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\My Documents\3GkuiQ.odt.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\My Documents\4zbjg_bdPxCqH.rtf.Globeimposter-Alpha865qqz | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\My Documents\8plFMz-h.xlsx.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\My Documents\bRyy2YovzO3oD.docx.Globeimposter-Alpha865qqz | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\killer.bat | Dropped File | Batch |
Unknown
|
...
|
»
Z:\System Volume Information\tracking.log.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Start Menu\Programs\fec\ bfsv.exe.Globeimposter-Alpha865qqz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\F9X2XGLn\YSPLEVTK-X\HOW TO BACK YOUR FILES.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\Public\.C4D1664EF40CE18F8D41 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\bootsect.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\DWTRIG20.EXE.Globeimposter-Alpha865qqz | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\HttpHelper.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\upgrader_win10.log | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\Windows10UpgraderApp.exe.Globeimposter-Alpha865qqz | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\WinREBootApp32.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\ux\bullet.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\ux\GetStarted.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\ux\marketing.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\ux\NoNetworkConnection.png.Globeimposter-Alpha865qqz | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\ux\Microsoft.WinJS\js\base.js | Modified File | Text |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\i386\BiosBlocks.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\i386\hwcompat.txt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\WQ8BTtmkUUI.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\fvSFLz\37ZvyS5g6wps3.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\F9X2XGLn\1fNERDqRoO_.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\F9X2XGLn\P1Ks5nYNy5d9xyplE.avi.Globeimposter-Alpha865qqz | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\F9X2XGLn\yZhNe4JoOToZCKYh.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\F9X2XGLn\YSPLEVTK-X\nvHY.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\F9X2XGLn\mJK89DYlS07\rZFGjUXNzQmZO.flv.Globeimposter-Alpha865qqz | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\SendTo\Desktop (create shortcut).DeskLink.Globeimposter-Alpha865qqz | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Searches\winrt--{S-1-5-21-1051304884-625712362-2192934891-1000}-.searchconnector-ms.Globeimposter-Alpha865qqz | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Recent\CustomDestinations\9d1f905ce5044aee.customDestinations-ms.Globeimposter-Alpha865qqz | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Recent\CustomDestinations\f01b4d95cf55d32a.customDestinations-ms.Globeimposter-Alpha865qqz | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Recent\AutomaticDestinations\1b6ebacd7cd2f25a.automaticDestinations-ms.Globeimposter-Alpha865qqz | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Recent\AutomaticDestinations\5175b273ceba776b.automaticDestinations-ms.Globeimposter-Alpha865qqz | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Recent\AutomaticDestinations\6d2bac8f1edf6668.automaticDestinations-ms.Globeimposter-Alpha865qqz | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Recent\AutomaticDestinations\78f0afb5bd4bb278.automaticDestinations-ms.Globeimposter-Alpha865qqz | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Recent\AutomaticDestinations\7e4dca80246863e3.automaticDestinations-ms.Globeimposter-Alpha865qqz | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Recent\AutomaticDestinations\80d13f95c2c02af9.automaticDestinations-ms.Globeimposter-Alpha865qqz | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Recent\AutomaticDestinations\9cfafb05ce914942.automaticDestinations-ms.Globeimposter-Alpha865qqz | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Recent\AutomaticDestinations\9d1f905ce5044aee.automaticDestinations-ms.Globeimposter-Alpha865qqz | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Recent\AutomaticDestinations\a7ef017c25c44293.automaticDestinations-ms.Globeimposter-Alpha865qqz | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Recent\AutomaticDestinations\d00655d2aa12ff6d.automaticDestinations-ms.Globeimposter-Alpha865qqz | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\-UYVItfk4Y.jpg.Globeimposter-Alpha865qqz | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\BEoM cEl.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\cb55Bhs_N6SzW.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\Fp O5Pe9KmHUuVzpPyQ.jpg.Globeimposter-Alpha865qqz | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\j01tQTD13Oi\0F8zWxRlmVG8W.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\j01tQTD13Oi\J1J kvZgKCKmq3DQ.jpg.Globeimposter-Alpha865qqz | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\j01tQTD13Oi\mT6QnPh18iUhEA31M4.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\j01tQTD13Oi\o7-DONHE4J.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\j01tQTD13Oi\Ps78xltsUrI.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\j01tQTD13Oi\YdGXFe.gif.Globeimposter-Alpha865qqz | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\My Documents\9j DNEb5SfioC5.docx.Globeimposter-Alpha865qqz | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\My Documents\aIDDXiynP_hPo-jmNZe.pptx.Globeimposter-Alpha865qqz | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\My Documents\Database1.accdb.Globeimposter-Alpha865qqz | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\Jsotgyzofbr.vbs | Dropped File | Text |
Not Queried
|
...
|
»