VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware |
3.exe
Windows Exe (x86-32)
Created at 2019-11-07T13:10:00
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\3.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x40d872 |
Size Of Code | 0x40e00 |
Size Of Initialized Data | 0x22400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-11-04 17:42:49+00:00 |
Sections (7)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x40d8b | 0x40e00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.64 |
.rdata | 0x442000 | 0x15ec0 | 0x16000 | 0x41200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.21 |
.data | 0x458000 | 0x73ec | 0x2200 | 0x57200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.54 |
.tls | 0x460000 | 0x9 | 0x200 | 0x59400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.02 |
.gfids | 0x461000 | 0xa78 | 0xc00 | 0x59600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.47 |
.rsrc | 0x462000 | 0x10 | 0x200 | 0x5a200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.0 |
.reloc | 0x463000 | 0x3f74 | 0x4000 | 0x5a400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.6 |
Imports (7)
»
KERNEL32.DLL (139)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FindClose | 0x0 | 0x44208c | 0x4208c | 0x4128c | 0x0 |
FindFirstFileW | 0x0 | 0x442090 | 0x42090 | 0x41290 | 0x0 |
FindNextFileW | 0x0 | 0x442094 | 0x42094 | 0x41294 | 0x0 |
GetFileSizeEx | 0x0 | 0x442098 | 0x42098 | 0x41298 | 0x0 |
ReadFile | 0x0 | 0x44209c | 0x4209c | 0x4129c | 0x0 |
SetFilePointer | 0x0 | 0x4420a0 | 0x420a0 | 0x412a0 | 0x0 |
SetFilePointerEx | 0x0 | 0x4420a4 | 0x420a4 | 0x412a4 | 0x0 |
SetFileAttributesW | 0x0 | 0x4420a8 | 0x420a8 | 0x412a8 | 0x0 |
GetConsoleWindow | 0x0 | 0x4420ac | 0x420ac | 0x412ac | 0x0 |
GetLogicalDriveStringsW | 0x0 | 0x4420b0 | 0x420b0 | 0x412b0 | 0x0 |
LoadLibraryW | 0x0 | 0x4420b4 | 0x420b4 | 0x412b4 | 0x0 |
OpenMutexW | 0x0 | 0x4420b8 | 0x420b8 | 0x412b8 | 0x0 |
UnregisterWaitEx | 0x0 | 0x4420bc | 0x420bc | 0x412bc | 0x0 |
QueryDepthSList | 0x0 | 0x4420c0 | 0x420c0 | 0x412c0 | 0x0 |
InterlockedPopEntrySList | 0x0 | 0x4420c4 | 0x420c4 | 0x412c4 | 0x0 |
WideCharToMultiByte | 0x0 | 0x4420c8 | 0x420c8 | 0x412c8 | 0x0 |
SetPriorityClass | 0x0 | 0x4420cc | 0x420cc | 0x412cc | 0x0 |
GetVolumeInformationW | 0x0 | 0x4420d0 | 0x420d0 | 0x412d0 | 0x0 |
CopyFileW | 0x0 | 0x4420d4 | 0x420d4 | 0x412d4 | 0x0 |
CreateFileW | 0x0 | 0x4420d8 | 0x420d8 | 0x412d8 | 0x0 |
Wow64DisableWow64FsRedirection | 0x0 | 0x4420dc | 0x420dc | 0x412dc | 0x0 |
GetWindowsDirectoryW | 0x0 | 0x4420e0 | 0x420e0 | 0x412e0 | 0x0 |
GetDriveTypeW | 0x0 | 0x4420e4 | 0x420e4 | 0x412e4 | 0x0 |
GetModuleFileNameW | 0x0 | 0x4420e8 | 0x420e8 | 0x412e8 | 0x0 |
OutputDebugStringW | 0x0 | 0x4420ec | 0x420ec | 0x412ec | 0x0 |
CreateProcessW | 0x0 | 0x4420f0 | 0x420f0 | 0x412f0 | 0x0 |
MoveFileExW | 0x0 | 0x4420f4 | 0x420f4 | 0x412f4 | 0x0 |
CreateMutexW | 0x0 | 0x4420f8 | 0x420f8 | 0x412f8 | 0x0 |
lstrlenW | 0x0 | 0x4420fc | 0x420fc | 0x412fc | 0x0 |
lstrlenA | 0x0 | 0x442100 | 0x42100 | 0x41300 | 0x0 |
lstrcatW | 0x0 | 0x442104 | 0x42104 | 0x41304 | 0x0 |
lstrcatA | 0x0 | 0x442108 | 0x42108 | 0x41308 | 0x0 |
lstrcpyW | 0x0 | 0x44210c | 0x4210c | 0x4130c | 0x0 |
lstrcpyA | 0x0 | 0x442110 | 0x42110 | 0x41310 | 0x0 |
GetSystemInfo | 0x0 | 0x442114 | 0x42114 | 0x41314 | 0x0 |
CloseHandle | 0x0 | 0x442118 | 0x42118 | 0x41318 | 0x0 |
WriteFile | 0x0 | 0x44211c | 0x4211c | 0x4131c | 0x0 |
Sleep | 0x0 | 0x442120 | 0x42120 | 0x41320 | 0x0 |
GetLastError | 0x0 | 0x442124 | 0x42124 | 0x41324 | 0x0 |
ExitProcess | 0x0 | 0x442128 | 0x42128 | 0x41328 | 0x0 |
GetCurrentProcess | 0x0 | 0x44212c | 0x4212c | 0x4132c | 0x0 |
ReleaseSemaphore | 0x0 | 0x442130 | 0x42130 | 0x41330 | 0x0 |
VirtualProtect | 0x0 | 0x442134 | 0x42134 | 0x41334 | 0x0 |
GetVersionExW | 0x0 | 0x442138 | 0x42138 | 0x41338 | 0x0 |
GetModuleHandleA | 0x0 | 0x44213c | 0x4213c | 0x4133c | 0x0 |
GetThreadTimes | 0x0 | 0x442140 | 0x42140 | 0x41340 | 0x0 |
UnregisterWait | 0x0 | 0x442144 | 0x42144 | 0x41344 | 0x0 |
RegisterWaitForSingleObject | 0x0 | 0x442148 | 0x42148 | 0x41348 | 0x0 |
SetThreadAffinityMask | 0x0 | 0x44214c | 0x4214c | 0x4134c | 0x0 |
GetProcessAffinityMask | 0x0 | 0x442150 | 0x42150 | 0x41350 | 0x0 |
GetNumaHighestNodeNumber | 0x0 | 0x442154 | 0x42154 | 0x41354 | 0x0 |
DeleteTimerQueueTimer | 0x0 | 0x442158 | 0x42158 | 0x41358 | 0x0 |
GetProcessHeap | 0x0 | 0x44215c | 0x4215c | 0x4135c | 0x0 |
HeapFree | 0x0 | 0x442160 | 0x42160 | 0x41360 | 0x0 |
HeapAlloc | 0x0 | 0x442164 | 0x42164 | 0x41364 | 0x0 |
VirtualFree | 0x0 | 0x442168 | 0x42168 | 0x41368 | 0x0 |
VirtualAlloc | 0x0 | 0x44216c | 0x4216c | 0x4136c | 0x0 |
LocalFree | 0x0 | 0x442170 | 0x42170 | 0x41370 | 0x0 |
LocalAlloc | 0x0 | 0x442174 | 0x42174 | 0x41374 | 0x0 |
EnterCriticalSection | 0x0 | 0x442178 | 0x42178 | 0x41378 | 0x0 |
LeaveCriticalSection | 0x0 | 0x44217c | 0x4217c | 0x4137c | 0x0 |
DeleteCriticalSection | 0x0 | 0x442180 | 0x42180 | 0x41380 | 0x0 |
SetEvent | 0x0 | 0x442184 | 0x42184 | 0x41384 | 0x0 |
ResetEvent | 0x0 | 0x442188 | 0x42188 | 0x41388 | 0x0 |
WaitForSingleObjectEx | 0x0 | 0x44218c | 0x4218c | 0x4138c | 0x0 |
CreateEventW | 0x0 | 0x442190 | 0x42190 | 0x41390 | 0x0 |
GetModuleHandleW | 0x0 | 0x442194 | 0x42194 | 0x41394 | 0x0 |
GetProcAddress | 0x0 | 0x442198 | 0x42198 | 0x41398 | 0x0 |
IsProcessorFeaturePresent | 0x0 | 0x44219c | 0x4219c | 0x4139c | 0x0 |
IsDebuggerPresent | 0x0 | 0x4421a0 | 0x421a0 | 0x413a0 | 0x0 |
UnhandledExceptionFilter | 0x0 | 0x4421a4 | 0x421a4 | 0x413a4 | 0x0 |
SetUnhandledExceptionFilter | 0x0 | 0x4421a8 | 0x421a8 | 0x413a8 | 0x0 |
GetStartupInfoW | 0x0 | 0x4421ac | 0x421ac | 0x413ac | 0x0 |
QueryPerformanceCounter | 0x0 | 0x4421b0 | 0x421b0 | 0x413b0 | 0x0 |
GetCurrentProcessId | 0x0 | 0x4421b4 | 0x421b4 | 0x413b4 | 0x0 |
GetCurrentThreadId | 0x0 | 0x4421b8 | 0x421b8 | 0x413b8 | 0x0 |
GetSystemTimeAsFileTime | 0x0 | 0x4421bc | 0x421bc | 0x413bc | 0x0 |
InitializeSListHead | 0x0 | 0x4421c0 | 0x421c0 | 0x413c0 | 0x0 |
TerminateProcess | 0x0 | 0x4421c4 | 0x421c4 | 0x413c4 | 0x0 |
MultiByteToWideChar | 0x0 | 0x4421c8 | 0x421c8 | 0x413c8 | 0x0 |
GetStringTypeW | 0x0 | 0x4421cc | 0x421cc | 0x413cc | 0x0 |
DuplicateHandle | 0x0 | 0x4421d0 | 0x421d0 | 0x413d0 | 0x0 |
GetCurrentThread | 0x0 | 0x4421d4 | 0x421d4 | 0x413d4 | 0x0 |
GetExitCodeThread | 0x0 | 0x4421d8 | 0x421d8 | 0x413d8 | 0x0 |
TryEnterCriticalSection | 0x0 | 0x4421dc | 0x421dc | 0x413dc | 0x0 |
EncodePointer | 0x0 | 0x4421e0 | 0x421e0 | 0x413e0 | 0x0 |
DecodePointer | 0x0 | 0x4421e4 | 0x421e4 | 0x413e4 | 0x0 |
SetLastError | 0x0 | 0x4421e8 | 0x421e8 | 0x413e8 | 0x0 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4421ec | 0x421ec | 0x413ec | 0x0 |
TlsAlloc | 0x0 | 0x4421f0 | 0x421f0 | 0x413f0 | 0x0 |
TlsGetValue | 0x0 | 0x4421f4 | 0x421f4 | 0x413f4 | 0x0 |
TlsSetValue | 0x0 | 0x4421f8 | 0x421f8 | 0x413f8 | 0x0 |
TlsFree | 0x0 | 0x4421fc | 0x421fc | 0x413fc | 0x0 |
GetTickCount | 0x0 | 0x442200 | 0x42200 | 0x41400 | 0x0 |
CompareStringW | 0x0 | 0x442204 | 0x42204 | 0x41404 | 0x0 |
LCMapStringW | 0x0 | 0x442208 | 0x42208 | 0x41408 | 0x0 |
GetLocaleInfoW | 0x0 | 0x44220c | 0x4220c | 0x4140c | 0x0 |
GetCPInfo | 0x0 | 0x442210 | 0x42210 | 0x41410 | 0x0 |
RaiseException | 0x0 | 0x442214 | 0x42214 | 0x41414 | 0x0 |
RtlUnwind | 0x0 | 0x442218 | 0x42218 | 0x41418 | 0x0 |
FreeLibrary | 0x0 | 0x44221c | 0x4221c | 0x4141c | 0x0 |
LoadLibraryExW | 0x0 | 0x442220 | 0x42220 | 0x41420 | 0x0 |
InterlockedPushEntrySList | 0x0 | 0x442224 | 0x42224 | 0x41424 | 0x0 |
InterlockedFlushSList | 0x0 | 0x442228 | 0x42228 | 0x41428 | 0x0 |
GetModuleHandleExW | 0x0 | 0x44222c | 0x4222c | 0x4142c | 0x0 |
GetModuleFileNameA | 0x0 | 0x442230 | 0x42230 | 0x41430 | 0x0 |
GetStdHandle | 0x0 | 0x442234 | 0x42234 | 0x41434 | 0x0 |
GetCommandLineA | 0x0 | 0x442238 | 0x42238 | 0x41438 | 0x0 |
GetCommandLineW | 0x0 | 0x44223c | 0x4223c | 0x4143c | 0x0 |
GetACP | 0x0 | 0x442240 | 0x42240 | 0x41440 | 0x0 |
CreateThread | 0x0 | 0x442244 | 0x42244 | 0x41444 | 0x0 |
ExitThread | 0x0 | 0x442248 | 0x42248 | 0x41448 | 0x0 |
FreeLibraryAndExitThread | 0x0 | 0x44224c | 0x4224c | 0x4144c | 0x0 |
HeapReAlloc | 0x0 | 0x442250 | 0x42250 | 0x41450 | 0x0 |
GetFileType | 0x0 | 0x442254 | 0x42254 | 0x41454 | 0x0 |
IsValidLocale | 0x0 | 0x442258 | 0x42258 | 0x41458 | 0x0 |
GetUserDefaultLCID | 0x0 | 0x44225c | 0x4225c | 0x4145c | 0x0 |
EnumSystemLocalesW | 0x0 | 0x442260 | 0x42260 | 0x41460 | 0x0 |
FindFirstFileExA | 0x0 | 0x442264 | 0x42264 | 0x41464 | 0x0 |
FindNextFileA | 0x0 | 0x442268 | 0x42268 | 0x41468 | 0x0 |
IsValidCodePage | 0x0 | 0x44226c | 0x4226c | 0x4146c | 0x0 |
GetOEMCP | 0x0 | 0x442270 | 0x42270 | 0x41470 | 0x0 |
GetEnvironmentStringsW | 0x0 | 0x442274 | 0x42274 | 0x41474 | 0x0 |
FreeEnvironmentStringsW | 0x0 | 0x442278 | 0x42278 | 0x41478 | 0x0 |
SetEnvironmentVariableA | 0x0 | 0x44227c | 0x4227c | 0x4147c | 0x0 |
SetStdHandle | 0x0 | 0x442280 | 0x42280 | 0x41480 | 0x0 |
HeapSize | 0x0 | 0x442284 | 0x42284 | 0x41484 | 0x0 |
FlushFileBuffers | 0x0 | 0x442288 | 0x42288 | 0x41488 | 0x0 |
GetConsoleCP | 0x0 | 0x44228c | 0x4228c | 0x4148c | 0x0 |
GetConsoleMode | 0x0 | 0x442290 | 0x42290 | 0x41490 | 0x0 |
WriteConsoleW | 0x0 | 0x442294 | 0x42294 | 0x41494 | 0x0 |
CreateTimerQueue | 0x0 | 0x442298 | 0x42298 | 0x41498 | 0x0 |
SignalObjectAndWait | 0x0 | 0x44229c | 0x4229c | 0x4149c | 0x0 |
SwitchToThread | 0x0 | 0x4422a0 | 0x422a0 | 0x414a0 | 0x0 |
SetThreadPriority | 0x0 | 0x4422a4 | 0x422a4 | 0x414a4 | 0x0 |
GetThreadPriority | 0x0 | 0x4422a8 | 0x422a8 | 0x414a8 | 0x0 |
GetLogicalProcessorInformation | 0x0 | 0x4422ac | 0x422ac | 0x414ac | 0x0 |
CreateTimerQueueTimer | 0x0 | 0x4422b0 | 0x422b0 | 0x414b0 | 0x0 |
ChangeTimerQueueTimer | 0x0 | 0x4422b4 | 0x422b4 | 0x414b4 | 0x0 |
ADVAPI32.dll (14)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptDestroyKey | 0x0 | 0x442000 | 0x42000 | 0x41200 | 0x0 |
GetUserNameW | 0x0 | 0x442004 | 0x42004 | 0x41204 | 0x0 |
RegCloseKey | 0x0 | 0x442008 | 0x42008 | 0x41208 | 0x0 |
RegOpenKeyW | 0x0 | 0x44200c | 0x4200c | 0x4120c | 0x0 |
RegOpenKeyExW | 0x0 | 0x442010 | 0x42010 | 0x41210 | 0x0 |
RegQueryValueExW | 0x0 | 0x442014 | 0x42014 | 0x41214 | 0x0 |
RegSetValueExW | 0x0 | 0x442018 | 0x42018 | 0x41218 | 0x0 |
CryptEncrypt | 0x0 | 0x44201c | 0x4201c | 0x4121c | 0x0 |
CryptExportKey | 0x0 | 0x442020 | 0x42020 | 0x41220 | 0x0 |
CryptGenRandom | 0x0 | 0x442024 | 0x42024 | 0x41224 | 0x0 |
SystemFunction036 | 0x0 | 0x442028 | 0x42028 | 0x41228 | 0x0 |
CryptGenKey | 0x0 | 0x44202c | 0x4202c | 0x4122c | 0x0 |
CryptReleaseContext | 0x0 | 0x442030 | 0x42030 | 0x41230 | 0x0 |
CryptAcquireContextW | 0x0 | 0x442034 | 0x42034 | 0x41234 | 0x0 |
CRYPT32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptEncodeObject | 0x0 | 0x44203c | 0x4203c | 0x4123c | 0x0 |
CryptDecodeObjectEx | 0x0 | 0x442040 | 0x42040 | 0x41240 | 0x0 |
CryptExportPublicKeyInfo | 0x0 | 0x442044 | 0x42044 | 0x41244 | 0x0 |
CryptImportPublicKeyInfo | 0x0 | 0x442048 | 0x42048 | 0x41248 | 0x0 |
CryptStringToBinaryW | 0x0 | 0x44204c | 0x4204c | 0x4124c | 0x0 |
CryptBinaryToStringW | 0x0 | 0x442050 | 0x42050 | 0x41250 | 0x0 |
CryptEncodeObjectEx | 0x0 | 0x442054 | 0x42054 | 0x41254 | 0x0 |
GDI32.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetBkMode | 0x0 | 0x44205c | 0x4205c | 0x4125c | 0x0 |
CreateDIBSection | 0x0 | 0x442060 | 0x42060 | 0x41260 | 0x0 |
SetTextColor | 0x0 | 0x442064 | 0x42064 | 0x41264 | 0x0 |
SelectObject | 0x0 | 0x442068 | 0x42068 | 0x41268 | 0x0 |
GetTextExtentPoint32W | 0x0 | 0x44206c | 0x4206c | 0x4126c | 0x0 |
DeleteObject | 0x0 | 0x442070 | 0x42070 | 0x41270 | 0x0 |
DeleteDC | 0x0 | 0x442074 | 0x42074 | 0x41274 | 0x0 |
CreateFontW | 0x0 | 0x442078 | 0x42078 | 0x41278 | 0x0 |
CreateCompatibleDC | 0x0 | 0x44207c | 0x4207c | 0x4127c | 0x0 |
CreateCompatibleBitmap | 0x0 | 0x442080 | 0x42080 | 0x41280 | 0x0 |
BitBlt | 0x0 | 0x442084 | 0x42084 | 0x41284 | 0x0 |
MPR.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetOpenEnumW | 0x0 | 0x4422bc | 0x422bc | 0x414bc | 0x0 |
WNetEnumResourceW | 0x0 | 0x4422c0 | 0x422c0 | 0x414c0 | 0x0 |
WNetCloseEnum | 0x0 | 0x4422c4 | 0x422c4 | 0x414c4 | 0x0 |
USER32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShowWindow | 0x0 | 0x4422cc | 0x422cc | 0x414cc | 0x0 |
DrawTextW | 0x0 | 0x4422d0 | 0x422d0 | 0x414d0 | 0x0 |
GetDC | 0x0 | 0x4422d4 | 0x422d4 | 0x414d4 | 0x0 |
ReleaseDC | 0x0 | 0x4422d8 | 0x422d8 | 0x414d8 | 0x0 |
SystemParametersInfoW | 0x0 | 0x4422dc | 0x422dc | 0x414dc | 0x0 |
wsprintfW | 0x0 | 0x4422e0 | 0x422e0 | 0x414e0 | 0x0 |
WININET.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
HttpSendRequestW | 0x0 | 0x4422e8 | 0x422e8 | 0x414e8 | 0x0 |
HttpOpenRequestW | 0x0 | 0x4422ec | 0x422ec | 0x414ec | 0x0 |
InternetReadFile | 0x0 | 0x4422f0 | 0x422f0 | 0x414f0 | 0x0 |
InternetOpenW | 0x0 | 0x4422f4 | 0x422f4 | 0x414f4 | 0x0 |
InternetCloseHandle | 0x0 | 0x4422f8 | 0x422f8 | 0x414f8 | 0x0 |
InternetConnectW | 0x0 | 0x4422fc | 0x422fc | 0x414fc | 0x0 |
HttpQueryInfoW | 0x0 | 0x442300 | 0x42300 | 0x41500 | 0x0 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
3.exe | 1 | 0x00DF0000 | 0x00E56FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
3.exe | 1 | 0x00DF0000 | 0x00E56FFF | Final Dump | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Ransom.WCryG.952EC2D2 |
Malicious
|
C:\\BOOTSECT.BAK.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Boot\BOOTSTAT.DAT.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Boot\BCD.LOG2.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Boot\BCD.LOG1.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\desktop.ini.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000\desktop.ini.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\Winre.wim.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Unknown |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\ntuser.ini.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\Public\desktop.ini.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\ShellUI.MST.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\pss10r.chm.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\osetupui.dll.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\dwtrig20.exe.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPrWW2.cab.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Unknown |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPrWW.cab.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Unknown |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\OWOW32WW.cab.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\osetup.dll.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ose.exe.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.msi.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjPrrWW.cab.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Unknown |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjProrWW.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.cab.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Unknown |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Setup.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Office32WW.xml.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Contacts\desktop.ini.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000\TRY_TO_READ.html | Dropped File | Text |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\_bMfn6RwnbmollBO.ppt.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\YmNdBrM5raQxjMo6.mkv.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\XnNx.xls.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\x6M0U60Brj.xlsx.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\ttxl9yoJB3t.mkv.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\P1eL.ots.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\ox3FRqoRTn-lM.mp3.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\o0j_ZHuh4LGnsKMmBM.jpg.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\nmU57lth1.m4a.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\MepeviR2K0DKAD f4icg.ots.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\lIZLRTs Pd6.odp.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\LCHbfNdkD8Wqz.wav.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\JYnZcsNWalz57I0.bmp.12781717671972518758.ex_parvis@aol.com.AIR | Dropped File | Stream |
Unknown
|
...
|
»