VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Dropper
|
Threat Names: |
Gen:Heur.Ransom.Imps.3
|
WinUpdt.exe
Windows Exe (x86-32)
Created at 2020-03-17T08:27:00
Remarks
(0x0200001E): The maximum size of extracted files was exceeded. Some files may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\WinUpdt.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4140fe |
Size Of Code | 0x12200 |
Size Of Initialized Data | 0x1600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-02-15 10:20:30+00:00 |
Version Information (11)
»
Assembly Version | 1.0.0.0 |
Comments | - |
CompanyName | - |
FileDescription | WinUpdt |
FileVersion | 1.0.0.0 |
InternalName | WinUpdt.exe |
LegalCopyright | Copyright © 2020 |
LegalTrademarks | - |
OriginalFilename | WinUpdt.exe |
ProductName | WinUpdt |
ProductVersion | 1.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x12104 | 0x12200 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.39 |
.rsrc | 0x416000 | 0x1210 | 0x1400 | 0x12400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.81 |
.reloc | 0x418000 | 0xc | 0x200 | 0x13800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.08 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x140cc | 0x122cc | 0x0 |
Memory Dumps (10)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
winupdt.exe | 1 | 0x00E90000 | 0x00EA9FFF | Relevant Image |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00136000 | 0x00136FFF | First Execution |
![]() |
32-bit | 0x00136012 |
![]() |
![]() |
...
|
buffer | 1 | 0x00174000 | 0x00174FFF | First Execution |
![]() |
32-bit | 0x00174150 |
![]() |
![]() |
...
|
buffer | 1 | 0x00175000 | 0x00175FFF | First Execution |
![]() |
32-bit | 0x001750D8 |
![]() |
![]() |
...
|
buffer | 1 | 0x00175000 | 0x00175FFF | Content Changed |
![]() |
32-bit | 0x001757A0 |
![]() |
![]() |
...
|
buffer | 1 | 0x00174000 | 0x00174FFF | Content Changed |
![]() |
32-bit | 0x00174B49 |
![]() |
![]() |
...
|
buffer | 1 | 0x00136000 | 0x00136FFF | Content Changed |
![]() |
32-bit | 0x00136032 |
![]() |
![]() |
...
|
buffer | 1 | 0x00179000 | 0x00179FFF | First Execution |
![]() |
32-bit | 0x00179088 |
![]() |
![]() |
...
|
winupdt.exe | 1 | 0x00E90000 | 0x00EA9FFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
winupdt.exe | 1 | 0x00E90000 | 0x00EA9FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Ransom.Imps.3 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\WinUpdt.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4140fe |
Size Of Code | 0x12200 |
Size Of Initialized Data | 0x1600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-02-15 10:20:30+00:00 |
Version Information (11)
»
Assembly Version | 1.0.0.0 |
Comments | - |
CompanyName | - |
FileDescription | WinUpdt |
FileVersion | 1.0.0.0 |
InternalName | WinUpdt.exe |
LegalCopyright | Copyright © 2020 |
LegalTrademarks | - |
OriginalFilename | WinUpdt.exe |
ProductName | WinUpdt |
ProductVersion | 1.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x12104 | 0x12200 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.39 |
.rsrc | 0x416000 | 0x1210 | 0x1400 | 0x12400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.81 |
.reloc | 0x418000 | 0xc | 0x200 | 0x13800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.08 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x140cc | 0x122cc | 0x0 |
Memory Dumps (16)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
winupdt.exe | 10 | 0x00DE0000 | 0x00DF9FFF | Relevant Image |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 10 | 0x00176000 | 0x00176FFF | First Execution |
![]() |
32-bit | 0x00176012 |
![]() |
![]() |
...
|
buffer | 10 | 0x001B4000 | 0x001B4FFF | First Execution |
![]() |
32-bit | 0x001B4150 |
![]() |
![]() |
...
|
buffer | 10 | 0x001B5000 | 0x001B5FFF | First Execution |
![]() |
32-bit | 0x001B50D8 |
![]() |
![]() |
...
|
buffer | 10 | 0x001B5000 | 0x001B5FFF | Content Changed |
![]() |
32-bit | 0x001B57A0 |
![]() |
![]() |
...
|
buffer | 10 | 0x001B4000 | 0x001B4FFF | Content Changed |
![]() |
32-bit | 0x001B4B49 |
![]() |
![]() |
...
|
buffer | 10 | 0x00176000 | 0x00176FFF | Content Changed |
![]() |
32-bit | 0x00176032 |
![]() |
![]() |
...
|
buffer | 10 | 0x001B9000 | 0x001B9FFF | First Execution |
![]() |
32-bit | 0x001B9088 |
![]() |
![]() |
...
|
buffer | 10 | 0x00176000 | 0x00176FFF | Content Changed |
![]() |
32-bit | 0x00176052 |
![]() |
![]() |
...
|
buffer | 10 | 0x001B4000 | 0x001B4FFF | Content Changed |
![]() |
32-bit | 0x001B47C8 |
![]() |
![]() |
...
|
buffer | 10 | 0x001B9000 | 0x001B9FFF | Content Changed |
![]() |
32-bit | 0x001B9C40 |
![]() |
![]() |
...
|
buffer | 10 | 0x001BA000 | 0x001BAFFF | First Execution |
![]() |
32-bit | 0x001BA198 |
![]() |
![]() |
...
|
buffer | 10 | 0x049E5000 | 0x049EBFFF | First Execution |
![]() |
32-bit | 0x049EB336 |
![]() |
![]() |
...
|
buffer | 10 | 0x001BA000 | 0x001BAFFF | Content Changed |
![]() |
32-bit | 0x001BA8F8 |
![]() |
![]() |
...
|
buffer | 10 | 0x001B4000 | 0x001B4FFF | Content Changed |
![]() |
32-bit | 0x001B4F60 |
![]() |
![]() |
...
|
winupdt.exe | 10 | 0x00DE0000 | 0x00DF9FFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Ransom.Imps.3 |
Malicious
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\gdipfontcachev1.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\-60II61Ak.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3JvcF.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8WUYgnmVVQsOHl.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\9BNDTe04t.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\9sF-lI.xlsx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\CjUJmtsyr.odt.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ecol784pYTNNS.docx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\EUeaVFPg9xvOeyoTY.xlsx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gke7Hh05Yah.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\GQnlDqiYaM01tswsYqy.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\I9b4Uj.doc.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KWnLqD jTsie6.docx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\mjKxv.pptx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ndCXgWoaW3O_s9.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\nxK5u36q93ybBp9Qf.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\O02lgMZZQSqmUq.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\OPMjP99y.xlsx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\qA2 POjX.pptx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\QnhpLmLhHkmJWB.xlsx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\U6is7p61GHkLJ3_.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\vjiQ_cpSzI_lE09.docx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\VzbTJtSh2.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wkIoRTbVM.docx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X5Fh3VEi-d94zoqNP.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ZxmGTONw7B.doc.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\DDkKzEBB5Hx30VX7FT\HVbg15qz0rsOcBGpiJX.docx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\DDkKzEBB5Hx30VX7FT\i_xGwCQrE1RZ-4P1WI.pdf.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\DDkKzEBB5Hx30VX7FT\m6W H-B k11.ppt.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\DDkKzEBB5Hx30VX7FT\nvogx9 zOdj7mV0Fno5q.odt.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\DDkKzEBB5Hx30VX7FT\vI5yibCVFS506wd9DN.doc.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\DDkKzEBB5Hx30VX7FT\w1N Rq.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\DDkKzEBB5Hx30VX7FT\xfg7OcMuV.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\DDkKzEBB5Hx30VX7FT\Y79LK5.doc.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\23Yw-skJm.rtf.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\8dFMbgTmZgC_.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\B_V9.png.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\cJ6NTjjSczDlq4GKMmq.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\I1aBpgLf8euG-RNj.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\jiCMMpojd.jpg.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\jTH7ngKWMFidZN.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\KXQA99dezB.bmp.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ma8F_cd.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\RWK-ERfyKVS1ubY43p5.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\RYDs5gi.avi.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\tjCawpC7bDKOzKu.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\uk2deXxOn2.mp3.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\XROLQ7T3Du67WCP mup.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\_DGVP9QaEiM.bmp.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\V9T82XygGub\lC0nzIclr0n.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\V9T82XygGub\xCg2yAxkU2C8AtVq5.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\V9T82XygGub\y9h9zrThfAP.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\V9T82XygGub\Ye6NLXYVra7xela.bmp.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\V9T82XygGub\F4ijCytc3cL6KrfK5\8yFcm4n_T68I.rtf.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\V9T82XygGub\F4ijCytc3cL6KrfK5\IUkul4HRK.avi.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\V9T82XygGub\_RQ9Gu\yfEyi0g4or WM2-.csv.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\V9T82XygGub\_RQ9Gu\ZWOOCJ aKdwB n.png.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\V9T82XygGub\_RQ9Gu\zY_e0OtuhW9esck3P.png.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\V9T82XygGub\_RQ9Gu\UZv83ywZ1\KnCPV5H__f.avi.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\V9T82XygGub\_RQ9Gu\UZv83ywZ1\NaofNftU-JyfYoBo\Zl4D3YnRS.jpg.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\OWOW32LR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfLR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Nhxbjjn.pptx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\DDkKzEBB5Hx30VX7FT\6wd_KO_eVh.xlsx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\DDkKzEBB5Hx30VX7FT\EJPgglYGV7ETM.odt.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Dj_Db5l6vQeyuys.mp3.encrypted | Dropped File | Stream |
Unknown
|
...
|
»