VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Trojan.GenericKD.42908069
Mal/Generic-S
|
DirectX_Update.exe
Windows Exe (x86-32)
Created at 2020-03-31T11:21:00
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "30 seconds" to "10 seconds" to reveal dormant functionality.
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x41fac3 |
Size Of Code | 0x45000 |
Size Of Initialized Data | 0x1a600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-03-30 19:40:46+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x44f6a | 0x45000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.65 |
.rdata | 0x446000 | 0x13d0a | 0x13e00 | 0x45400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.4 |
.data | 0x45a000 | 0x2b68 | 0x1a00 | 0x59200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.11 |
.rsrc | 0x45d000 | 0x1e8 | 0x200 | 0x5ac00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.77 |
.reloc | 0x45e000 | 0x39f4 | 0x3a00 | 0x5ae00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.6 |
Imports (3)
»
KERNEL32.dll (104)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetLogicalDriveStringsW | 0x0 | 0x44601c | 0x592dc | 0x586dc | 0x267 |
CreateToolhelp32Snapshot | 0x0 | 0x446020 | 0x592e0 | 0x586e0 | 0xfc |
Sleep | 0x0 | 0x446024 | 0x592e4 | 0x586e4 | 0x57d |
Process32NextW | 0x0 | 0x446028 | 0x592e8 | 0x586e8 | 0x42e |
GetDiskFreeSpaceExW | 0x0 | 0x44602c | 0x592ec | 0x586ec | 0x228 |
OpenProcess | 0x0 | 0x446030 | 0x592f0 | 0x586f0 | 0x40d |
CloseHandle | 0x0 | 0x446034 | 0x592f4 | 0x586f4 | 0x86 |
lstrcpyW | 0x0 | 0x446038 | 0x592f8 | 0x586f8 | 0x636 |
lstrcmpW | 0x0 | 0x44603c | 0x592fc | 0x586fc | 0x630 |
GetDriveTypeW | 0x0 | 0x446040 | 0x59300 | 0x58700 | 0x22f |
SetEndOfFile | 0x0 | 0x446044 | 0x59304 | 0x58704 | 0x510 |
FindClose | 0x0 | 0x446048 | 0x59308 | 0x58708 | 0x175 |
GetModuleFileNameW | 0x0 | 0x44604c | 0x5930c | 0x5870c | 0x274 |
TerminateProcess | 0x0 | 0x446050 | 0x59310 | 0x58710 | 0x58c |
lstrlenW | 0x0 | 0x446054 | 0x59314 | 0x58714 | 0x63c |
FindNextFileW | 0x0 | 0x446058 | 0x59318 | 0x58718 | 0x18c |
Process32FirstW | 0x0 | 0x44605c | 0x5931c | 0x5871c | 0x42c |
FindFirstFileW | 0x0 | 0x446060 | 0x59320 | 0x58720 | 0x180 |
WriteConsoleW | 0x0 | 0x446064 | 0x59324 | 0x58724 | 0x611 |
HeapSize | 0x0 | 0x446068 | 0x59328 | 0x58728 | 0x34e |
CreateFileW | 0x0 | 0x44606c | 0x5932c | 0x5872c | 0xcb |
GetProcessHeap | 0x0 | 0x446070 | 0x59330 | 0x58730 | 0x2b4 |
SetStdHandle | 0x0 | 0x446074 | 0x59334 | 0x58734 | 0x54a |
SetEnvironmentVariableW | 0x0 | 0x446078 | 0x59338 | 0x58738 | 0x514 |
MultiByteToWideChar | 0x0 | 0x44607c | 0x5933c | 0x5873c | 0x3ef |
GetLastError | 0x0 | 0x446080 | 0x59340 | 0x58740 | 0x261 |
WideCharToMultiByte | 0x0 | 0x446084 | 0x59344 | 0x58744 | 0x5fe |
GetCurrentThreadId | 0x0 | 0x446088 | 0x59348 | 0x58748 | 0x21c |
WaitForSingleObjectEx | 0x0 | 0x44608c | 0x5934c | 0x5874c | 0x5d8 |
SwitchToThread | 0x0 | 0x446090 | 0x59350 | 0x58750 | 0x587 |
GetExitCodeThread | 0x0 | 0x446094 | 0x59354 | 0x58754 | 0x23d |
EnterCriticalSection | 0x0 | 0x446098 | 0x59358 | 0x58758 | 0x131 |
LeaveCriticalSection | 0x0 | 0x44609c | 0x5935c | 0x5875c | 0x3bd |
DeleteCriticalSection | 0x0 | 0x4460a0 | 0x59360 | 0x58760 | 0x110 |
SetLastError | 0x0 | 0x4460a4 | 0x59364 | 0x58764 | 0x532 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4460a8 | 0x59368 | 0x58768 | 0x35f |
TlsAlloc | 0x0 | 0x4460ac | 0x5936c | 0x5876c | 0x59e |
TlsGetValue | 0x0 | 0x4460b0 | 0x59370 | 0x58770 | 0x5a0 |
TlsSetValue | 0x0 | 0x4460b4 | 0x59374 | 0x58774 | 0x5a1 |
TlsFree | 0x0 | 0x4460b8 | 0x59378 | 0x58778 | 0x59f |
GetSystemTimeAsFileTime | 0x0 | 0x4460bc | 0x5937c | 0x5877c | 0x2e9 |
GetModuleHandleW | 0x0 | 0x4460c0 | 0x59380 | 0x58780 | 0x278 |
GetProcAddress | 0x0 | 0x4460c4 | 0x59384 | 0x58784 | 0x2ae |
EncodePointer | 0x0 | 0x4460c8 | 0x59388 | 0x58788 | 0x12d |
DecodePointer | 0x0 | 0x4460cc | 0x5938c | 0x5878c | 0x109 |
QueryPerformanceCounter | 0x0 | 0x4460d0 | 0x59390 | 0x58790 | 0x44d |
QueryPerformanceFrequency | 0x0 | 0x4460d4 | 0x59394 | 0x58794 | 0x44e |
GetStringTypeW | 0x0 | 0x4460d8 | 0x59398 | 0x58798 | 0x2d7 |
CompareStringW | 0x0 | 0x4460dc | 0x5939c | 0x5879c | 0x9b |
LCMapStringW | 0x0 | 0x4460e0 | 0x593a0 | 0x587a0 | 0x3b1 |
GetLocaleInfoW | 0x0 | 0x4460e4 | 0x593a4 | 0x587a4 | 0x265 |
GetCPInfo | 0x0 | 0x4460e8 | 0x593a8 | 0x587a8 | 0x1c1 |
UnhandledExceptionFilter | 0x0 | 0x4460ec | 0x593ac | 0x587ac | 0x5ad |
SetUnhandledExceptionFilter | 0x0 | 0x4460f0 | 0x593b0 | 0x587b0 | 0x56d |
GetCurrentProcess | 0x0 | 0x4460f4 | 0x593b4 | 0x587b4 | 0x217 |
IsProcessorFeaturePresent | 0x0 | 0x4460f8 | 0x593b8 | 0x587b8 | 0x386 |
GetCurrentProcessId | 0x0 | 0x4460fc | 0x593bc | 0x587bc | 0x218 |
InitializeSListHead | 0x0 | 0x446100 | 0x593c0 | 0x587c0 | 0x363 |
IsDebuggerPresent | 0x0 | 0x446104 | 0x593c4 | 0x587c4 | 0x37f |
GetStartupInfoW | 0x0 | 0x446108 | 0x593c8 | 0x587c8 | 0x2d0 |
SetEvent | 0x0 | 0x44610c | 0x593cc | 0x587cc | 0x516 |
CreateThread | 0x0 | 0x446110 | 0x593d0 | 0x587d0 | 0xf3 |
GetCurrentThread | 0x0 | 0x446114 | 0x593d4 | 0x587d4 | 0x21b |
GetThreadTimes | 0x0 | 0x446118 | 0x593d8 | 0x587d8 | 0x305 |
FreeLibrary | 0x0 | 0x44611c | 0x593dc | 0x587dc | 0x1ab |
FreeLibraryAndExitThread | 0x0 | 0x446120 | 0x593e0 | 0x587e0 | 0x1ac |
LoadLibraryExW | 0x0 | 0x446124 | 0x593e4 | 0x587e4 | 0x3c3 |
WaitForSingleObject | 0x0 | 0x446128 | 0x593e8 | 0x587e8 | 0x5d7 |
RtlUnwind | 0x0 | 0x44612c | 0x593ec | 0x587ec | 0x4d3 |
RaiseException | 0x0 | 0x446130 | 0x593f0 | 0x587f0 | 0x462 |
ExitProcess | 0x0 | 0x446134 | 0x593f4 | 0x587f4 | 0x15e |
GetModuleHandleExW | 0x0 | 0x446138 | 0x593f8 | 0x587f8 | 0x277 |
ExitThread | 0x0 | 0x44613c | 0x593fc | 0x587fc | 0x15f |
GetStdHandle | 0x0 | 0x446140 | 0x59400 | 0x58800 | 0x2d2 |
WriteFile | 0x0 | 0x446144 | 0x59404 | 0x58804 | 0x612 |
GetCommandLineA | 0x0 | 0x446148 | 0x59408 | 0x58808 | 0x1d6 |
GetCommandLineW | 0x0 | 0x44614c | 0x5940c | 0x5880c | 0x1d7 |
HeapAlloc | 0x0 | 0x446150 | 0x59410 | 0x58810 | 0x345 |
HeapFree | 0x0 | 0x446154 | 0x59414 | 0x58814 | 0x349 |
GetDateFormatW | 0x0 | 0x446158 | 0x59418 | 0x58818 | 0x221 |
GetTimeFormatW | 0x0 | 0x44615c | 0x5941c | 0x5881c | 0x30c |
IsValidLocale | 0x0 | 0x446160 | 0x59420 | 0x58820 | 0x38d |
GetUserDefaultLCID | 0x0 | 0x446164 | 0x59424 | 0x58824 | 0x312 |
EnumSystemLocalesW | 0x0 | 0x446168 | 0x59428 | 0x58828 | 0x154 |
GetFileSizeEx | 0x0 | 0x44616c | 0x5942c | 0x5882c | 0x24c |
SetFilePointerEx | 0x0 | 0x446170 | 0x59430 | 0x58830 | 0x523 |
GetFileType | 0x0 | 0x446174 | 0x59434 | 0x58834 | 0x24e |
FlushFileBuffers | 0x0 | 0x446178 | 0x59438 | 0x58838 | 0x19f |
GetConsoleCP | 0x0 | 0x44617c | 0x5943c | 0x5883c | 0x1ea |
GetConsoleMode | 0x0 | 0x446180 | 0x59440 | 0x58840 | 0x1fc |
GetExitCodeProcess | 0x0 | 0x446184 | 0x59444 | 0x58844 | 0x23c |
CreateProcessW | 0x0 | 0x446188 | 0x59448 | 0x58848 | 0xe5 |
GetFileAttributesExW | 0x0 | 0x44618c | 0x5944c | 0x5884c | 0x242 |
MoveFileExW | 0x0 | 0x446190 | 0x59450 | 0x58850 | 0x3e8 |
ReadFile | 0x0 | 0x446194 | 0x59454 | 0x58854 | 0x473 |
ReadConsoleW | 0x0 | 0x446198 | 0x59458 | 0x58858 | 0x470 |
HeapReAlloc | 0x0 | 0x44619c | 0x5945c | 0x5885c | 0x34c |
GetTimeZoneInformation | 0x0 | 0x4461a0 | 0x59460 | 0x58860 | 0x30e |
FindFirstFileExW | 0x0 | 0x4461a4 | 0x59464 | 0x58864 | 0x17b |
IsValidCodePage | 0x0 | 0x4461a8 | 0x59468 | 0x58868 | 0x38b |
GetACP | 0x0 | 0x4461ac | 0x5946c | 0x5886c | 0x1b2 |
GetOEMCP | 0x0 | 0x4461b0 | 0x59470 | 0x58870 | 0x297 |
GetEnvironmentStringsW | 0x0 | 0x4461b4 | 0x59474 | 0x58874 | 0x237 |
FreeEnvironmentStringsW | 0x0 | 0x4461b8 | 0x59478 | 0x58878 | 0x1aa |
ADVAPI32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegCreateKeyExW | 0x0 | 0x446000 | 0x592c0 | 0x586c0 | 0x264 |
RegSetValueExW | 0x0 | 0x446004 | 0x592c4 | 0x586c4 | 0x2a9 |
RegOpenKeyExW | 0x0 | 0x446008 | 0x592c8 | 0x586c8 | 0x28c |
GetUserNameW | 0x0 | 0x44600c | 0x592cc | 0x586cc | 0x17b |
RegQueryValueExW | 0x0 | 0x446010 | 0x592d0 | 0x586d0 | 0x299 |
RegCloseKey | 0x0 | 0x446014 | 0x592d4 | 0x586d4 | 0x25b |
WININET.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
HttpSendRequestW | 0x0 | 0x4461c0 | 0x59480 | 0x58880 | 0x82 |
InternetOpenW | 0x0 | 0x4461c4 | 0x59484 | 0x58884 | 0xc9 |
HttpOpenRequestW | 0x0 | 0x4461c8 | 0x59488 | 0x58888 | 0x79 |
InternetCloseHandle | 0x0 | 0x4461cc | 0x5948c | 0x5888c | 0x95 |
InternetConnectW | 0x0 | 0x4461d0 | 0x59490 | 0x58890 | 0x9c |
Digital Signatures (2)
»
Certificate: Google LLC
»
Issued by | Google LLC |
Parent Certificate | DigiCert Assured ID Code Signing CA-1 |
Country Name | US |
Valid From | 2019-11-08 00:00:00+00:00 |
Valid Until | 2022-11-16 12:00:00+00:00 |
Algorithm | sha1_rsa |
Serial Number | 06 AE A7 6B AC 46 A9 E8 CF E6 D2 9E 45 AA F0 33 |
Thumbprint | A3 95 8A E5 22 F3 C5 4B 87 8B 20 D7 B0 F6 37 11 E0 86 66 B2 |
Certificate: DigiCert Assured ID Code Signing CA-1
»
Issued by | DigiCert Assured ID Code Signing CA-1 |
Country Name | US |
Valid From | 2011-02-11 12:00:00+00:00 |
Valid Until | 2026-02-10 12:00:00+00:00 |
Algorithm | sha1_rsa |
Serial Number | 0F A8 49 06 15 D7 00 A0 BE 21 76 FD C5 EC 6D BD |
Thumbprint | 40 9A A4 A7 4A 0C DA 7C 0F EE 6B D0 BB 88 23 D1 6B 5F 18 75 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
directx_update.exe | 1 | 0x01090000 | 0x010F1FFF | Relevant Image |
![]() |
32-bit | 0x010B2DAE |
![]() |
![]() |
...
|
directx_update.exe | 1 | 0x01090000 | 0x010F1FFF | Final Dump |
![]() |
32-bit | 0x010D1617 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.42908069 |
Malicious
|
C:/Users/FD1HVy/AppData/Roaming/Adobe/Flash Player/NativeCache/NativeCache.directory.aceadf | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:/588bce7c90097ed212/DHtmlHeader.html | Modified File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/DisplayIcon.ico | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212/header.bmp.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212/netfx_Extended.mzz.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212/SetupUi.xsd.aceadf | Dropped File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/SplashScreen.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212/Strings.xml.aceadf | Dropped File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/watermark.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212/1025/eula.rtf.aceadf | Dropped File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/1029/eula.rtf | Modified File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/1030/eula.rtf.aceadf | Dropped File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/1031/eula.rtf | Modified File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/1032/eula.rtf | Modified File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/1033/eula.rtf.aceadf | Dropped File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/1036/eula.rtf.aceadf | Dropped File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/1038/eula.rtf | Modified File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/1040/eula.rtf | Modified File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/1041/eula.rtf | Modified File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/1042/eula.rtf | Modified File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/1043/eula.rtf | Modified File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/1044/eula.rtf.aceadf | Dropped File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/1045/eula.rtf.aceadf | Dropped File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/1046/eula.rtf | Modified File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/1049/eula.rtf | Modified File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/1053/eula.rtf | Modified File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/1055/eula.rtf | Modified File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/2052/eula.rtf | Modified File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/2070/eula.rtf | Modified File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/1028/eula.rtf.aceadf | Dropped File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/3082/eula.rtf.aceadf | Dropped File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/Client/Parameterinfo.xml | Modified File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/Client/UiInfo.xml.aceadf | Dropped File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/Extended/Parameterinfo.xml | Modified File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/Extended/UiInfo.xml | Modified File | Text |
Unknown
|
...
|
»
C:/588bce7c90097ed212/Graphics/Print.ico.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212/Graphics/Rotate1.ico | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212/Graphics/Rotate2.ico.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212/Graphics/Rotate4.ico.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212/Graphics/Rotate6.ico | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212/Graphics/Rotate8.ico | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212/Graphics/Setup.ico | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212/Graphics/stop.ico | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212/Graphics/SysReqMet.ico.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212/Graphics/SysReqNotMet.ico | Modified File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212/Graphics/warn.ico | Modified File | Stream |
Unknown
|
...
|
»
C:/Logs/Key Management Service.evtx | Modified File | Text |
Unknown
|
...
|
»
C:/Recovery/ReAgentOld.xml.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/All Users/USOPrivate/UpdateStore/UpdateCspStore.xml.aceadf | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/All Users/USOPrivate/UpdateStore/updatestore51b519d5-b6f5-4333-8df6-e74d7c9aead4.xml.aceadf | Modified File | Text |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/1GaDh1.mkv.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/522CXI6dwfbZ0JlEy-.pps.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/7DCXMYZS02v-kEFb.m4a.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/8M2eE7-U.mkv.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/BHU2.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/D05RZSoFLtBat9PZ.swf | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/fUnFn.odp.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/hRFV.ods | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/IfokUNo.pps.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/ikUghhoIHk9kmL.odp.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/ipt_NT53FWD_.csv.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/jgLn KvAa7Pj7Y.m4a.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/jnmCX.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/M805nCra-DFsoD rvrz.gif.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/ngPNRFYT.swf | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/pHCZXlB.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/QhIT6A8B7Vm.xlsx.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/T9yndu.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/Tg4N4.m4a.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/V 16tzWu xuRFCktAG2U.pps.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/vc5QSQ.jpg.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/v_wnxlHA.mp3.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/wmNLRV6c804kvOHWqtx.pps | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/WWK--4.swf | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/XAFLIjofdKKeBLyi1P.mkv.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/yeczM mpEL.mp3.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/Z2UP3QI.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/ZJnk.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/ZvZZxZyt86tVF4aK.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/_PwL5pUjEgC6.m4a.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/Adobe/Acrobat/DC/Security/CRLCache/0FDED5CEB68C302B1CDB2BDDD9D0000E76539CB0.crl.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/Adobe/Acrobat/DC/Security/CRLCache/CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/Adobe/LogTransport2/LogTransport2.cfg.aceadf | Dropped File | Text |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/1AZS7.wav.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/4G5HN6eYY9xAl8I.bmp.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/4gWip5Z_bFf7.gif.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/6mzbA.swf.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/7OQki4h5202KyXf2ad.mp4.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/ak2Bg.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/arGrqnvXW.bmp.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/BARu-K.wav | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/Fgbm5vx3Y2LDLCC.ods | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/gntxW_nhsZZ.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/GQ9 kew.png | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/heTuES6WKLtdSQ.csv | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/ITvx OSCDwp57yK.flv | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/iYRKri.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/j0Q7Mibo70oah.jpg.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/kj2MP5PGzY-4OnG.xls | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/ljX6HSrvlHJLcG dHBl.flv | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/lSpFF.swf | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/MdwyR5GoFHM ii.gif | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/mQP69RaZBw57srPt6Y.flv.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/mVAxhpXMiRbqkdNltkI.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/m_QeAQmH8ztDgu9.wav | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/n9ELGrOfLy9auSYT.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/Qds_FuX8d7.wav.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/wb-MkXtCcqf.mp4.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/Wf3ssN41.png | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/WG3xae_u_XyiWb.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/WVd8zsEK.m4a.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/zgNf8XJGskFDQIlLWPk.jpg.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/_ix7mOEt7mDCxpJYS1.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/i1etzP/7HOAttWKp65vdi.odp.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/i1etzP/EnjKJmn10RMH-8fkaBhA.ots.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/i1etzP/tBUIVL0CzLjIazAs8.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/i1etzP/uzmg7nS5.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/i1etzP/YSmwM8wOfbw.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/i1etzP/z2qLkHlDeBkIU6e.png | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/i1etzP/z4-ZbJr21CC0DVBhU.png.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Desktop/i1etzP/zHX8qyERs8.mp4.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/--jBG7LLgLIYe.xlsx.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/0Rsh7c-7I3sUCC.csv.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/4oJHSPknOncu1v GY.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/aBFz Pour.pptx.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/dnvv gE7NtNw1UJ5rI.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/DOxQeJ3UQVq8jdmK.docx.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/ebVVV4.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/evlYF.pptx.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/ezzJLP.docx.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/FVid5Rzn_Bd 6R4.docx.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/GdOZnGhYmNvff7B.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/ghYv.pptx.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/inluAJZ79.pps.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/jckMl9AxQMXsDgdV.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/KCyC.ods | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/kfNBHb.pdf.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/mXSelx.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/Obdiw_YsmLOAfwQQ.docx.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/pHP4JW2tSJXuKFB7clT.xlsx.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/PVKBS-km.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/sHsJL_plw-G5M-_.doc.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/T 1Ek1cTx0BEKVJ.xlsx.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/V57rSCGCJXC.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/vYVhC_BjEV3aoL33g.odt | Modified File | Stream |
Unknown
|
...
|
»
C:/Users/FD1HVy/Documents/ec84DA/89bZoBl.xlsx.aceadf | Dropped File | Stream |
Unknown
|
...
|
»
C:/588bce7c90097ed212/ParameterInfo.xml.aceadf | Dropped File | Text |
Not Queried
|
...
|
»
C:/588bce7c90097ed212/UiInfo.xml | Modified File | Text |
Not Queried
|
...
|
»
C:/588bce7c90097ed212/1035/eula.rtf.aceadf | Dropped File | Text |
Not Queried
|
...
|
»
C:/588bce7c90097ed212/1037/eula.rtf.aceadf | Dropped File | Text |
Not Queried
|
...
|
»
C:/588bce7c90097ed212/Graphics/Rotate3.ico.aceadf | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212/Graphics/Rotate5.ico.aceadf | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212/Graphics/Rotate7.ico.aceadf | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212/Graphics/Save.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/4-BrFnzQw.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/h3XSdgOYkqsr8pQp.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/l3nOxSS4Ow-9m9B71OSD.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/udrd8XXoSrys.png.aceadf | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/WaVFl2n8X4PaXN.wav.aceadf | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users/FD1HVy/AppData/Roaming/Skype/RootTools/roottools.conf | Modified File | Text |
Not Queried
|
...
|
»
C:/Users/FD1HVy/Desktop/2h8UZ75qv.jpg.aceadf | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users/FD1HVy/Desktop/kez0M5.ots.aceadf | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users/FD1HVy/Desktop/qBEO96mdPe.flv.aceadf | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users/FD1HVy/Desktop/QnlwnoeTO.png.aceadf | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users/FD1HVy/Desktop/SLISdeGyKd0UHB4.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users/FD1HVy/Desktop/yRV-6N9O-TnRNda.swf.aceadf | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users/FD1HVy/Desktop/i1etzP/IfASwkDH.gif.aceadf | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users/FD1HVy/Desktop/i1etzP/nMJNcJH4Xj.png.aceadf | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users/FD1HVy/Documents/KoOudZJ_2G8K2l.pptx.aceadf | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users/FD1HVy/Documents/Pmf4.docx.aceadf | Dropped File | Stream |
Not Queried
|
...
|
»
C:/588bce7c90097ed212/2070/ATTENTION-aceadf-README.txt | Dropped File | Text |
Not Queried
|
...
|
»