VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Dropper
|
Threat Names: |
Generic.Ransom.Matrix.B20F99A7
VBS.Heur.Laburrak.11.Gen
Trojan.GenericKD.40672878
...
|
ubnumr.exe
Windows Exe (x86-32)
Created at 2020-09-03T10:28:00
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "6 minutes" to "1 minute" to reveal dormant functionality.
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4dca54 |
Size Of Code | 0xdec00 |
Size Of Initialized Data | 0x4da00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-08-08 00:01:49+00:00 |
Sections (10)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xda4a8 | 0xda600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.38 |
.itext | 0x4dc000 | 0x4434 | 0x4600 | 0xdaa00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.67 |
.data | 0x4e1000 | 0x5af8 | 0x5c00 | 0xdf000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.19 |
.bss | 0x4e7000 | 0x63f4 | 0x0 | 0x0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.idata | 0x4ee000 | 0x10ba | 0x1200 | 0xe4c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.84 |
.didata | 0x4f0000 | 0xfa | 0x200 | 0xe5e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.89 |
.edata | 0x4f1000 | 0x64 | 0x200 | 0xe6000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.19 |
.tls | 0x4f2000 | 0x14 | 0x0 | 0x0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rdata | 0x4f3000 | 0x5d | 0x200 | 0xe6200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.36 |
.rsrc | 0x4f4000 | 0x46600 | 0x46600 | 0xe6400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.96 |
Imports (8)
»
oleaut32.dll (12)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysFreeString | 0x0 | 0x4ee338 | 0xee0b4 | 0xe4cb4 | 0x0 |
SysReAllocStringLen | 0x0 | 0x4ee33c | 0xee0b8 | 0xe4cb8 | 0x0 |
SysAllocStringLen | 0x0 | 0x4ee340 | 0xee0bc | 0xe4cbc | 0x0 |
SafeArrayPtrOfIndex | 0x0 | 0x4ee344 | 0xee0c0 | 0xe4cc0 | 0x0 |
SafeArrayGetUBound | 0x0 | 0x4ee348 | 0xee0c4 | 0xe4cc4 | 0x0 |
SafeArrayGetLBound | 0x0 | 0x4ee34c | 0xee0c8 | 0xe4cc8 | 0x0 |
SafeArrayCreate | 0x0 | 0x4ee350 | 0xee0cc | 0xe4ccc | 0x0 |
VariantChangeType | 0x0 | 0x4ee354 | 0xee0d0 | 0xe4cd0 | 0x0 |
VariantCopy | 0x0 | 0x4ee358 | 0xee0d4 | 0xe4cd4 | 0x0 |
VariantClear | 0x0 | 0x4ee35c | 0xee0d8 | 0xe4cd8 | 0x0 |
VariantInit | 0x0 | 0x4ee360 | 0xee0dc | 0xe4cdc | 0x0 |
GetErrorInfo | 0x0 | 0x4ee364 | 0xee0e0 | 0xe4ce0 | 0x0 |
advapi32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryValueExW | 0x0 | 0x4ee36c | 0xee0e8 | 0xe4ce8 | 0x0 |
RegOpenKeyExW | 0x0 | 0x4ee370 | 0xee0ec | 0xe4cec | 0x0 |
RegCloseKey | 0x0 | 0x4ee374 | 0xee0f0 | 0xe4cf0 | 0x0 |
GetUserNameA | 0x0 | 0x4ee378 | 0xee0f4 | 0xe4cf4 | 0x0 |
CryptGenRandom | 0x0 | 0x4ee37c | 0xee0f8 | 0xe4cf8 | 0x0 |
CryptReleaseContext | 0x0 | 0x4ee380 | 0xee0fc | 0xe4cfc | 0x0 |
CryptAcquireContextW | 0x0 | 0x4ee384 | 0xee100 | 0xe4d00 | 0x0 |
user32.dll (10)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MessageBoxA | 0x0 | 0x4ee38c | 0xee108 | 0xe4d08 | 0x0 |
CharNextW | 0x0 | 0x4ee390 | 0xee10c | 0xe4d0c | 0x0 |
LoadStringW | 0x0 | 0x4ee394 | 0xee110 | 0xe4d10 | 0x0 |
PeekMessageW | 0x0 | 0x4ee398 | 0xee114 | 0xe4d14 | 0x0 |
MsgWaitForMultipleObjects | 0x0 | 0x4ee39c | 0xee118 | 0xe4d18 | 0x0 |
MessageBoxW | 0x0 | 0x4ee3a0 | 0xee11c | 0xe4d1c | 0x0 |
GetSystemMetrics | 0x0 | 0x4ee3a4 | 0xee120 | 0xe4d20 | 0x0 |
CharUpperBuffW | 0x0 | 0x4ee3a8 | 0xee124 | 0xe4d24 | 0x0 |
CharUpperW | 0x0 | 0x4ee3ac | 0xee128 | 0xe4d28 | 0x0 |
CharLowerBuffW | 0x0 | 0x4ee3b0 | 0xee12c | 0xe4d2c | 0x0 |
kernel32.dll (114)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Sleep | 0x0 | 0x4ee3b8 | 0xee134 | 0xe4d34 | 0x0 |
VirtualFree | 0x0 | 0x4ee3bc | 0xee138 | 0xe4d38 | 0x0 |
VirtualAlloc | 0x0 | 0x4ee3c0 | 0xee13c | 0xe4d3c | 0x0 |
lstrlenW | 0x0 | 0x4ee3c4 | 0xee140 | 0xe4d40 | 0x0 |
VirtualQuery | 0x0 | 0x4ee3c8 | 0xee144 | 0xe4d44 | 0x0 |
GetTickCount | 0x0 | 0x4ee3cc | 0xee148 | 0xe4d48 | 0x0 |
GetSystemInfo | 0x0 | 0x4ee3d0 | 0xee14c | 0xe4d4c | 0x0 |
GetVersion | 0x0 | 0x4ee3d4 | 0xee150 | 0xe4d50 | 0x0 |
CompareStringW | 0x0 | 0x4ee3d8 | 0xee154 | 0xe4d54 | 0x0 |
IsDBCSLeadByteEx | 0x0 | 0x4ee3dc | 0xee158 | 0xe4d58 | 0x0 |
IsValidLocale | 0x0 | 0x4ee3e0 | 0xee15c | 0xe4d5c | 0x0 |
SetThreadLocale | 0x0 | 0x4ee3e4 | 0xee160 | 0xe4d60 | 0x0 |
GetSystemDefaultUILanguage | 0x0 | 0x4ee3e8 | 0xee164 | 0xe4d64 | 0x0 |
GetUserDefaultUILanguage | 0x0 | 0x4ee3ec | 0xee168 | 0xe4d68 | 0x0 |
GetLocaleInfoW | 0x0 | 0x4ee3f0 | 0xee16c | 0xe4d6c | 0x0 |
WideCharToMultiByte | 0x0 | 0x4ee3f4 | 0xee170 | 0xe4d70 | 0x0 |
MultiByteToWideChar | 0x0 | 0x4ee3f8 | 0xee174 | 0xe4d74 | 0x0 |
GetConsoleOutputCP | 0x0 | 0x4ee3fc | 0xee178 | 0xe4d78 | 0x0 |
GetConsoleCP | 0x0 | 0x4ee400 | 0xee17c | 0xe4d7c | 0x0 |
GetACP | 0x0 | 0x4ee404 | 0xee180 | 0xe4d80 | 0x0 |
LoadLibraryExW | 0x0 | 0x4ee408 | 0xee184 | 0xe4d84 | 0x0 |
GetStartupInfoW | 0x0 | 0x4ee40c | 0xee188 | 0xe4d88 | 0x0 |
GetProcAddress | 0x0 | 0x4ee410 | 0xee18c | 0xe4d8c | 0x0 |
GetModuleHandleW | 0x0 | 0x4ee414 | 0xee190 | 0xe4d90 | 0x0 |
GetModuleFileNameW | 0x0 | 0x4ee418 | 0xee194 | 0xe4d94 | 0x0 |
GetCommandLineW | 0x0 | 0x4ee41c | 0xee198 | 0xe4d98 | 0x0 |
FreeLibrary | 0x0 | 0x4ee420 | 0xee19c | 0xe4d9c | 0x0 |
GetLastError | 0x0 | 0x4ee424 | 0xee1a0 | 0xe4da0 | 0x0 |
UnhandledExceptionFilter | 0x0 | 0x4ee428 | 0xee1a4 | 0xe4da4 | 0x0 |
RtlUnwind | 0x0 | 0x4ee42c | 0xee1a8 | 0xe4da8 | 0x0 |
RaiseException | 0x0 | 0x4ee430 | 0xee1ac | 0xe4dac | 0x0 |
ExitProcess | 0x0 | 0x4ee434 | 0xee1b0 | 0xe4db0 | 0x0 |
ExitThread | 0x0 | 0x4ee438 | 0xee1b4 | 0xe4db4 | 0x0 |
SwitchToThread | 0x0 | 0x4ee43c | 0xee1b8 | 0xe4db8 | 0x0 |
GetCurrentThreadId | 0x0 | 0x4ee440 | 0xee1bc | 0xe4dbc | 0x0 |
CreateThread | 0x0 | 0x4ee444 | 0xee1c0 | 0xe4dc0 | 0x0 |
DeleteCriticalSection | 0x0 | 0x4ee448 | 0xee1c4 | 0xe4dc4 | 0x0 |
LeaveCriticalSection | 0x0 | 0x4ee44c | 0xee1c8 | 0xe4dc8 | 0x0 |
EnterCriticalSection | 0x0 | 0x4ee450 | 0xee1cc | 0xe4dcc | 0x0 |
InitializeCriticalSection | 0x0 | 0x4ee454 | 0xee1d0 | 0xe4dd0 | 0x0 |
FindFirstFileW | 0x0 | 0x4ee458 | 0xee1d4 | 0xe4dd4 | 0x0 |
FindClose | 0x0 | 0x4ee45c | 0xee1d8 | 0xe4dd8 | 0x0 |
WriteFile | 0x0 | 0x4ee460 | 0xee1dc | 0xe4ddc | 0x0 |
SetFilePointer | 0x0 | 0x4ee464 | 0xee1e0 | 0xe4de0 | 0x0 |
SetEndOfFile | 0x0 | 0x4ee468 | 0xee1e4 | 0xe4de4 | 0x0 |
ReadFile | 0x0 | 0x4ee46c | 0xee1e8 | 0xe4de8 | 0x0 |
GetFileType | 0x0 | 0x4ee470 | 0xee1ec | 0xe4dec | 0x0 |
GetFileSize | 0x0 | 0x4ee474 | 0xee1f0 | 0xe4df0 | 0x0 |
CreateFileW | 0x0 | 0x4ee478 | 0xee1f4 | 0xe4df4 | 0x0 |
GetStdHandle | 0x0 | 0x4ee47c | 0xee1f8 | 0xe4df8 | 0x0 |
CloseHandle | 0x0 | 0x4ee480 | 0xee1fc | 0xe4dfc | 0x0 |
LoadLibraryA | 0x0 | 0x4ee484 | 0xee200 | 0xe4e00 | 0x0 |
TlsSetValue | 0x0 | 0x4ee488 | 0xee204 | 0xe4e04 | 0x0 |
TlsGetValue | 0x0 | 0x4ee48c | 0xee208 | 0xe4e08 | 0x0 |
LocalFree | 0x0 | 0x4ee490 | 0xee20c | 0xe4e0c | 0x0 |
LocalAlloc | 0x0 | 0x4ee494 | 0xee210 | 0xe4e10 | 0x0 |
WaitForSingleObject | 0x0 | 0x4ee498 | 0xee214 | 0xe4e14 | 0x0 |
WaitForMultipleObjects | 0x0 | 0x4ee49c | 0xee218 | 0xe4e18 | 0x0 |
VirtualQueryEx | 0x0 | 0x4ee4a0 | 0xee21c | 0xe4e1c | 0x0 |
VirtualProtect | 0x0 | 0x4ee4a4 | 0xee220 | 0xe4e20 | 0x0 |
VerSetConditionMask | 0x0 | 0x4ee4a8 | 0xee224 | 0xe4e24 | 0x0 |
VerifyVersionInfoW | 0x0 | 0x4ee4ac | 0xee228 | 0xe4e28 | 0x0 |
SuspendThread | 0x0 | 0x4ee4b0 | 0xee22c | 0xe4e2c | 0x0 |
SizeofResource | 0x0 | 0x4ee4b4 | 0xee230 | 0xe4e30 | 0x0 |
SetThreadPriority | 0x0 | 0x4ee4b8 | 0xee234 | 0xe4e34 | 0x0 |
SetLastError | 0x0 | 0x4ee4bc | 0xee238 | 0xe4e38 | 0x0 |
SetEvent | 0x0 | 0x4ee4c0 | 0xee23c | 0xe4e3c | 0x0 |
SetErrorMode | 0x0 | 0x4ee4c4 | 0xee240 | 0xe4e40 | 0x0 |
ResumeThread | 0x0 | 0x4ee4c8 | 0xee244 | 0xe4e44 | 0x0 |
ResetEvent | 0x0 | 0x4ee4cc | 0xee248 | 0xe4e48 | 0x0 |
ReleaseMutex | 0x0 | 0x4ee4d0 | 0xee24c | 0xe4e4c | 0x0 |
QueryPerformanceFrequency | 0x0 | 0x4ee4d4 | 0xee250 | 0xe4e50 | 0x0 |
QueryPerformanceCounter | 0x0 | 0x4ee4d8 | 0xee254 | 0xe4e54 | 0x0 |
OpenMutexW | 0x0 | 0x4ee4dc | 0xee258 | 0xe4e58 | 0x0 |
MoveFileExW | 0x0 | 0x4ee4e0 | 0xee25c | 0xe4e5c | 0x0 |
LockResource | 0x0 | 0x4ee4e4 | 0xee260 | 0xe4e60 | 0x0 |
LoadResource | 0x0 | 0x4ee4e8 | 0xee264 | 0xe4e64 | 0x0 |
LoadLibraryW | 0x0 | 0x4ee4ec | 0xee268 | 0xe4e68 | 0x0 |
HeapFree | 0x0 | 0x4ee4f0 | 0xee26c | 0xe4e6c | 0x0 |
HeapDestroy | 0x0 | 0x4ee4f4 | 0xee270 | 0xe4e70 | 0x0 |
HeapCreate | 0x0 | 0x4ee4f8 | 0xee274 | 0xe4e74 | 0x0 |
HeapAlloc | 0x0 | 0x4ee4fc | 0xee278 | 0xe4e78 | 0x0 |
GetVolumeInformationW | 0x0 | 0x4ee500 | 0xee27c | 0xe4e7c | 0x0 |
GetVersionExW | 0x0 | 0x4ee504 | 0xee280 | 0xe4e80 | 0x0 |
GetThreadTimes | 0x0 | 0x4ee508 | 0xee284 | 0xe4e84 | 0x0 |
GetThreadPriority | 0x0 | 0x4ee50c | 0xee288 | 0xe4e88 | 0x0 |
GetThreadLocale | 0x0 | 0x4ee510 | 0xee28c | 0xe4e8c | 0x0 |
GetSystemTimes | 0x0 | 0x4ee514 | 0xee290 | 0xe4e90 | 0x0 |
GetProcessTimes | 0x0 | 0x4ee518 | 0xee294 | 0xe4e94 | 0x0 |
GetLocalTime | 0x0 | 0x4ee51c | 0xee298 | 0xe4e98 | 0x0 |
GetFullPathNameW | 0x0 | 0x4ee520 | 0xee29c | 0xe4e9c | 0x0 |
GetFileAttributesW | 0x0 | 0x4ee524 | 0xee2a0 | 0xe4ea0 | 0x0 |
GetExitCodeThread | 0x0 | 0x4ee528 | 0xee2a4 | 0xe4ea4 | 0x0 |
GetDriveTypeW | 0x0 | 0x4ee52c | 0xee2a8 | 0xe4ea8 | 0x0 |
GetDiskFreeSpaceW | 0x0 | 0x4ee530 | 0xee2ac | 0xe4eac | 0x0 |
GetDateFormatW | 0x0 | 0x4ee534 | 0xee2b0 | 0xe4eb0 | 0x0 |
GetCurrentThread | 0x0 | 0x4ee538 | 0xee2b4 | 0xe4eb4 | 0x0 |
GetCurrentProcessId | 0x0 | 0x4ee53c | 0xee2b8 | 0xe4eb8 | 0x0 |
GetCurrentProcess | 0x0 | 0x4ee540 | 0xee2bc | 0xe4ebc | 0x0 |
GetComputerNameA | 0x0 | 0x4ee544 | 0xee2c0 | 0xe4ec0 | 0x0 |
GetCPInfoExW | 0x0 | 0x4ee548 | 0xee2c4 | 0xe4ec4 | 0x0 |
GetCPInfo | 0x0 | 0x4ee54c | 0xee2c8 | 0xe4ec8 | 0x0 |
FreeResource | 0x0 | 0x4ee550 | 0xee2cc | 0xe4ecc | 0x0 |
InterlockedCompareExchange | 0x0 | 0x4ee554 | 0xee2d0 | 0xe4ed0 | 0x0 |
FormatMessageW | 0x0 | 0x4ee558 | 0xee2d4 | 0xe4ed4 | 0x0 |
FindResourceW | 0x0 | 0x4ee55c | 0xee2d8 | 0xe4ed8 | 0x0 |
FindNextFileW | 0x0 | 0x4ee560 | 0xee2dc | 0xe4edc | 0x0 |
ExpandEnvironmentStringsW | 0x0 | 0x4ee564 | 0xee2e0 | 0xe4ee0 | 0x0 |
EnumSystemLocalesW | 0x0 | 0x4ee568 | 0xee2e4 | 0xe4ee4 | 0x0 |
EnumCalendarInfoW | 0x0 | 0x4ee56c | 0xee2e8 | 0xe4ee8 | 0x0 |
DeleteFileW | 0x0 | 0x4ee570 | 0xee2ec | 0xe4eec | 0x0 |
CreateProcessW | 0x0 | 0x4ee574 | 0xee2f0 | 0xe4ef0 | 0x0 |
CreateMutexW | 0x0 | 0x4ee578 | 0xee2f4 | 0xe4ef4 | 0x0 |
CreateEventW | 0x0 | 0x4ee57c | 0xee2f8 | 0xe4ef8 | 0x0 |
ole32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoUninitialize | 0x0 | 0x4ee584 | 0xee300 | 0xe4f00 | 0x0 |
CoInitialize | 0x0 | 0x4ee588 | 0xee304 | 0xe4f04 | 0x0 |
shell32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderPathW | 0x0 | 0x4ee590 | 0xee30c | 0xe4f0c | 0x0 |
wsock32.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WSACleanup | 0x0 | 0x4ee598 | 0xee314 | 0xe4f14 | 0x0 |
WSAStartup | 0x0 | 0x4ee59c | 0xee318 | 0xe4f18 | 0x0 |
gethostname | 0x0 | 0x4ee5a0 | 0xee31c | 0xe4f1c | 0x0 |
gethostbyname | 0x0 | 0x4ee5a4 | 0xee320 | 0xe4f20 | 0x0 |
inet_ntoa | 0x0 | 0x4ee5a8 | 0xee324 | 0xe4f24 | 0x0 |
netapi32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetShareEnum | 0x0 | 0x4ee5b0 | 0xee32c | 0xe4f2c | 0x0 |
NetApiBufferFree | 0x0 | 0x4ee5b4 | 0xee330 | 0xe4f30 | 0x0 |
Exports (1)
»
Api name | EAT Address | Ordinal |
---|---|---|
TMethodImplementationIntercept | 0x50868 | 0x1 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
ubnumr.exe | 1 | 0x00400000 | 0x0053AFFF | Relevant Image |
![]() |
32-bit | 0x00407620 |
![]() |
![]() |
...
|
nwobtfnd.exe | 5 | 0x00400000 | 0x0053AFFF | Relevant Image |
![]() |
32-bit | 0x00407620 |
![]() |
![]() |
...
|
ubnumr.exe | 1 | 0x00400000 | 0x0053AFFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Ransom.Matrix.B20F99A7 |
Malicious
|
C:\Users\FD1HVy\AppData\Roaming\nStyPXNq.vbs | Dropped File | Text |
Malicious
|
...
|
»
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
VBS.Heur.Laburrak.11.Gen |
Malicious
|
C:\Users\FD1HVy\Desktop\PxsB9fTz.exe | Dropped File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x475810 |
Size Of Code | 0x29000 |
Size Of Initialized Data | 0x1000 |
Size Of Uninitialized Data | 0x4c000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-12-10 21:18:46+00:00 |
Version Information (8)
»
CompanyName | Sysinternals - www.sysinternals.com |
FileDescription | Handle viewer |
FileVersion | 4.11 |
InternalName | Nthandle |
LegalCopyright | Copyright (C) 1997-2017 Mark Russinovich |
OriginalFilename | Nthandle.exe |
ProductName | Sysinternals Handle |
ProductVersion | 4.11 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
UPX0 | 0x401000 | 0x4c000 | 0x0 | 0x400 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
UPX1 | 0x44d000 | 0x29000 | 0x28a00 | 0x400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.93 |
.rsrc | 0x476000 | 0x1000 | 0x800 | 0x28e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.04 |
Imports (6)
»
ADVAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegOpenKeyW | 0x0 | 0x47666c | 0x7666c | 0x2946c | 0x0 |
COMDLG32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PrintDlgW | 0x0 | 0x476674 | 0x76674 | 0x29474 | 0x0 |
GDI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EndDoc | 0x0 | 0x47667c | 0x7667c | 0x2947c | 0x0 |
KERNEL32.DLL (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | 0x0 | 0x476684 | 0x76684 | 0x29484 | 0x0 |
ExitProcess | 0x0 | 0x476688 | 0x76688 | 0x29488 | 0x0 |
GetProcAddress | 0x0 | 0x47668c | 0x7668c | 0x2948c | 0x0 |
VirtualProtect | 0x0 | 0x476690 | 0x76690 | 0x29490 | 0x0 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EndDialog | 0x0 | 0x476698 | 0x76698 | 0x29498 | 0x0 |
VERSION.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VerQueryValueW | 0x0 | 0x4766a0 | 0x766a0 | 0x294a0 | 0x0 |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.40672878 |
Malicious
|
C:\Users\FD1HVy\AppData\Local\Temp\__PSScriptPolicyTest_xcdpdtcz.yvt.psm1 | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Program Files\Microsoft Office\root\Templates\1033\OriginLetter.Dotx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\basicstylish.dotx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Templates\1033\ApothecaryNewsletter.dotx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0099185.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145272.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148309.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0177806.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\r_VHw41UzadZthkfi\xh_znJ7\Hi-ajVo7T.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\bwcapitalized.dotx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\minimalist.dotx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Templates\1033\EssentialLetter.dotx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\r_VHw41UzadZthkfi\xh_znJ7\FwH7eJDZC.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\bwclassic.dotx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\shaded.dotx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145373.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178348.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolBMPs\LoginTool24x24Images.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382961.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145904.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0099148.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Templates\1033\RedAndBlackLetter.dotx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolBMPs\MessageAttachmentIconImages.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolData\groove.net\CommonData\UnreadIconImages.jpg | Modified File | Binary |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0287644.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382930.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382966.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0386120.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145879.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolBMPs\InformationIcon.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0174952.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0287642.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0309705.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Templates\1033\RedAndBlackReport.dotx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341554.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolBMPs\MessageHistoryIconImages.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DHtmlHeader.html | Modified File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\RGB9RAST_x64.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\1033\DBSAMPLE.MDB | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0309585.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341499.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341653.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0099162.JPG | Modified File | Binary |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0099190.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145707.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149118.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\1033\PROTTPLV.XLS | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\SAMPLES\[BatHelp@protonmail.com].vN4pvmCL-Z8DMsW6g.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\FgQZ AN2235G.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\[BatHelp@protonmail.com].34bH11gA-T4kCvhzj.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0384888.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0387591.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145810.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\linesdistinctive.dotx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\1033\PROTTPLV.DOC | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Templates\1033\[BatHelp@protonmail.com].G46C7qAk-TQLW9TV4.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Templates\1033\EssentialReport.dotx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\r_VHw41UzadZthkfi\pZkrU\[BatHelp@protonmail.com].aT326w3o-N08N3pWu.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\[BatHelp@protonmail.com].WpvSuxtV-q0MK4l76.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\basicsimple.dotx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Templates\1033\[BatHelp@protonmail.com].AnNN6VSY-8x4Jb1hS.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Visio Content\1033\[BatHelp@protonmail.com].gWFoCr8k-jqtiwzts.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Templates\1033\TimelessLetter.dotx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Templates\1033\ApothecaryResume.dotx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\IDTemplates\ENU\[BatHelp@protonmail.com].yDXksHWL-AHlCQxni.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].E2cHw8vk-brk36KU0.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382927.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145895.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].JwBrc8oX-4Kv1OnOT.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145361.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0387882.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178932.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].RS51X8U8-oTRcUpbn.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382963.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].IzK5z8O1-HxLxh99T.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341344.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].tTxMXelH-pMsdwYpk.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\sample-files\assets\Sample Files\Adobe Sign White Paper.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].xR6c3T1L-xiJKoLai.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\[BatHelp@protonmail.com].MthRheOD-3mPIh1fn.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0315580.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].h4HjdV2h-snxkQ5af.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\ffjcext.zip | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\redact_poster.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Templates\1033\[BatHelp@protonmail.com].uJFby5Vj-SEFIh83a.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341534.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].TCnWgin0-gkVQBVWR.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02412K.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH03379I.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolBMPs\[BatHelp@protonmail.com].z5qtHsXn-bO1ZVAJQ.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0387337.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\tracked-send\images\email\dummy\[BatHelp@protonmail.com].aeEZ8wZd-BR3SMnuU.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\[BatHelp@protonmail.com].02AiAwWk-JWs3l2Zh.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolBMPs\[BatHelp@protonmail.com].llWdXfPg-4trWuMtu.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolBMPs\NotifierUpArrow.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolBMPs\[BatHelp@protonmail.com].oNUAj1Nj-4567zw8b.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolBMPs\[BatHelp@protonmail.com].sMsQFPp2-s7e3xERj.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Stationery\1033\NOTEBOOK.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382939.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolBMPs\Shared24x24Images.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolData\groove.net\CommonData\[BatHelp@protonmail.com].WV5waCLG-BgFceWau.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\[BatHelp@protonmail.com].AWqPJGmS-lxlEMWRs.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\combine_poster.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\edit_pdf_poster2x.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\compare_poster2x.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\scan_poster.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].PsWJ3mpX-Q8OwnA6G.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382959.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\[BatHelp@protonmail.com].V7SJmfLQ-wZPZ7AcN.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\redact_poster2x.jpg | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\5uqysxV\1XK7 ImF5.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\[BatHelp@protonmail.com].iiRah0hQ-lcTy6SWm.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\GRPHFLT\MS.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\optimize_poster2x.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\fonts\LucidaSansDemiBold.ttf | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\[BatHelp@protonmail.com].6BN30sTc-31yCJGyC.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\5uqysxV\L6YGoOrS42Gw9k3uMS.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Microsoft.Lync.Utilities.zip | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\images\cursors\[BatHelp@protonmail.com].z7Y4sMxY-zB8iJC1P.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\RGB9Rast_x86.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\[BatHelp@protonmail.com].x48s1QXf-3JPhw2XS.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\LocalizedData.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\amd64\jvm.cfg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\[BatHelp@protonmail.com].RWWk6q7O-lBdiLfj7.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\[BatHelp@protonmail.com].aUGlgRwc-232BmE58.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\plugin.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\[BatHelp@protonmail.com].wHlfZkY6-Rsgxdkn3.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\[BatHelp@protonmail.com].ALHtpGUj-JHouXLTM.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH03425I.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolBMPs\NotifierCloseButton.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolBMPs\[BatHelp@protonmail.com].2UTMO6Kx-gN0esGgE.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].FvzrAjoH-ZwtZW9wO.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02810J.JPG | Modified File | Stream |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\dnsns.jar | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\[BatHelp@protonmail.com].d8OQPZAG-vpKBN7ue.CORE | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\94.114.3.195_log.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\4EKyGq4i.bat | Dropped File | Batch |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolData\groove.net\CommonData\#CORE_README#.rtf | Dropped File | RTF |
Unknown
|
...
|
»
Office Information
»
Document Content Snippet
»
HOW TO RECOVER YOUR FILES INSTRUCTION ATENTION!!! We are realy sorry to inform you thatALL YOUR FILES WERE ENCRYPTEDby our automatic software. It became possible because of bad server security.ATENTION!!! Please don't worry, we can help you to RESTORE your server to original state and decrypt all your files quickly and safely!INFORMATION!!! Files are not broken!!! Files were encrypted with AES-128+RSA-2048 crypto algorithms. There is no way to decrypt your files without unique decryption key and special software. Your unique decryption key is securely stored on our server. For our safety, all information about your server and your decryption key will be automaticaly DELETED AFTER 7 DAYS! You will irrevocably lose all your data! * Please note that all the attempts to recover your files by yourself or using third party tools will result only in irrevocable loss of your data! * Please note that you can recover files only with your unique decryption key, which stored on our side. ... |
Embedded URLs (4)
»
URL | First Seen | Categories | Threat Names | Reputation Status | WHOIS Data | Actions |
---|---|---|---|---|---|---|
https://bitmsg.me/users/sign_upnd | - | - | - |
Unknown
|
Not Queried
|
...
|
https://bitmsg.me | - | - | - |
Unknown
|
Not Queried
|
...
|
https://bitmsg.me/users/sign_up | - | - | - |
Unknown
|
Not Queried
|
...
|
https://bitmsg.me/users/sign_in | - | - | - |
Unknown
|
Not Queried
|
...
|
C:\Users\FD1HVy\Desktop\elog_43130FA834BB8DFF.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\83lt.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Templates\1033\AdjacencyReport.dotx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\linessimple.dotx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0099154.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Templates\1033\ApothecaryLetter.dotx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Visio Content\1033\BLDGPLAN.DWG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0099168.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145212.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\r_VHw41UzadZthkfi\pZkrU\LXlzwcgQ.odt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0146142.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0177257.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\r_VHw41UzadZthkfi\xh_znJ7\F9bVZaLquniqSZ9d_-Pu\-MEBj.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\kAeu.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0182689.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0287645.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0313970.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341447.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Click on 'Change' to select default PDF handler.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\sample-files\assets\Sample Files\Travelocity.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\Annotations\Stamps\Words.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\linesstylish.dotx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Templates\1033\OriginReport.Dotx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341561.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382926.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382950.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0099155.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0099150.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0099166.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0144773.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0202045.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0289430.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0313974.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Qsa_y.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\r_VHw41UzadZthkfi\0VdZL.ods | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\IDTemplates\ENU\AdobeID.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Welcome.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382836.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Database1.accdb | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\Annotations\Stamps\ENU\StandardBusiness.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\U1WelNunw87UOS1L.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Resource\ENUtxt.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0099157.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0099187.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148798.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216112.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0309480.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0314068.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02053J.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH03205I.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolBMPs\OutofSyncIconImages.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382947.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0384885.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0387578.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145168.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0175428.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0179963.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Templates\1033\Blog.dotx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolBMPs\QuestionIcon.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolData\groove.net\CommonData\AlertImage_FileHigh.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolData\groove.net\CommonData\AlertImage_FileOff.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolData\groove.net\CommonData\UnreadIcon.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\combine_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\compare_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH01239K.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\YozJNm0q0Pmd.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\XXCQZJcDbe.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\PDFSigQFormalRep.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\r_VHw41UzadZthkfi\pZkrU\cC_m.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0099165.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02897J.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341455.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0099191.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341636.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0313965.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382954.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\protect_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178459.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0099160.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\protect_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolBMPs\NotifierDownArrow.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\edit_pdf_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0099188.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\scan_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\ZK5QsrvbZC45UoO.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178639.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341439.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\bwnumbered.dotx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0216153.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\word2013.dotx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Templates\1033\ChronologicalLetter.dotx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\edit_pdf_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0387895.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341328.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolData\groove.net\CommonData\AlertImage_ContactHigh.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolData\groove.net\CommonData\CommsOutgoingImageSmall.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\UNP\CampaignManager\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Content1\resources\Picture2_80.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\organize_poster2x-dark.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\compare_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341559.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382925.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382948.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0145669.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0149018.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178460.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH03224I.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolBMPs\Shared16x16Images.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolData\groove.net\CommonData\AlertImage_High.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1038\LocalizedData.xml | Modified File | Compressed |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Extended\UiInfo.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Key Management Service.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382962.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341742.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0227419.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\Annotations\Stamps\ENU\Dynamic.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382931.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382944.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0315612.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\plug_ins\Annotations\Stamps\ENU\SignHere.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0099147.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382938.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382957.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382968.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382955.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382967.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0386267.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382960.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0099145.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0099161.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0099189.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolData\groove.net\Computers\computericon.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\compare_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\redact_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\[BatHelp@protonmail.com].2WMyIjjZ-Zibtgo4S.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\1033\PROTTPLN.DOC | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Visio Content\1033\[BatHelp@protonmail.com].h2xpRrQ1-KfkyZCNO.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\r_VHw41UzadZthkfi\pZkrU\[BatHelp@protonmail.com].KGPKio4x-ctoSoYFA.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\[BatHelp@protonmail.com].h3rT8oJW-V44J2jsu.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\r_VHw41UzadZthkfi\BSVme3D0GWueayfOs.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\r_VHw41UzadZthkfi\xh_znJ7\[BatHelp@protonmail.com].tTOQDQME-ppS1PkUj.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH01931J.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH03041I.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0178523.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0227558.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0309598.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0386270.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH01046J.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02567J.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH03380I.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0164153.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\Default.dotx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\[BatHelp@protonmail.com].I7CrCKIE-rJAR5ZFi.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Templates\1033\[BatHelp@protonmail.com].saAifv9A-IFoGlyBP.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Templates\1033\AdjacencyResume.dotx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Templates\1033\[BatHelp@protonmail.com].7OZSjLng-k60Nry99.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\1494870C-9912-C184-4CC9-B401-A53F4D8DE290.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\sample-files\assets\Sample Files\Document Cloud for Government.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Document Parts\1033\16\[BatHelp@protonmail.com].zUJKnIx6-uv8uY0hM.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Templates\1033\EssentialResume.dotx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Templates\1033\[BatHelp@protonmail.com].cJjz9vTm-PjjAqFle.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Templates\1033\OriginResume.Dotx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\r_VHw41UzadZthkfi\xh_znJ7\[BatHelp@protonmail.com].9G1kLYCy-plngnyIS.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].2PPsUTHD-em2HoxtQ.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382952.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].JlSELpWz-SvOOtY1p.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0148757.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].g7FoHP1N-JuKHcseT.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].h3HjncGi-xmXubEYI.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].69XVNavj-ftVNDfQ3.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0313896.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0384895.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02028K.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH03143I.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0099167.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\1033\PROTTPLN.XLS | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\zsCv_tUZIKY rg1hXz.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\1033\QuickStyles\word2013bw.dotx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0309567.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\scan_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1025\[BatHelp@protonmail.com].WDg4xgLa-yp5ZZ2zx.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\PH02069J.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1037\[BatHelp@protonmail.com].Z4WxQ9rs-CV6cHNFx.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\5uqysxV\xUzSh.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1035\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1046\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Templates\1033\[BatHelp@protonmail.com].SlmjD8na-7HroCGbS.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0341645.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].TPD9nPBb-7hbB8FqI.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].74nxuiFo-dKQEVM4Z.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].NeE4qfee-ZVG3S43N.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].2wRQOIHN-GO0osZnX.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].CcsOqnci-6WHMaxbf.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\[BatHelp@protonmail.com].Ic5eAF0a-oC4oMUbS.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\[BatHelp@protonmail.com].QT0vApFx-AGmwkiBa.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\[BatHelp@protonmail.com].Vx4PzvGc-LKG6H7gf.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolData\groove.net\CommonData\AlertImage_ContactLow.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolData\groove.net\CommonData\[BatHelp@protonmail.com].g3AUrGjU-ltfYFq7W.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolData\groove.net\CommonData\[BatHelp@protonmail.com].xFTzrpLU-ZNVyyZ23.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382958.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0287641.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].j4FCOaPP-R4iWUO38.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0337280.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].L0Fbq90y-OOW6LbqE.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].262JoRnp-WIA1TuRP.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Visio Content\1033\[BatHelp@protonmail.com].QJO5lWIF-UzjVkxZL.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].oG9lfWvQ-7zw2C7sc.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolBMPs\[BatHelp@protonmail.com].3sFop9W1-JjJgd9Rx.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolBMPs\[BatHelp@protonmail.com].skNkMVng-mg9g71wM.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\[BatHelp@protonmail.com].gLTG2O1b-Al1zVNJn.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\[BatHelp@protonmail.com].34L4m3vc-CKj8YymE.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\organize_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\[BatHelp@protonmail.com].jcOG0KwU-XEFnpTTz.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\uxdqyWK1lZa0AaDqM.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].6PUdhlVr-SWT1G6cJ.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382942.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolData\groove.net\CommonData\AlertImage_Auto.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\organize_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\Logs\[BatHelp@protonmail.com].9UWiNADe-PUI3XLxE.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1036\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0382970.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].F5LTFPiT-g0ZEly5O.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\[BatHelp@protonmail.com].pVMZxTZB-wBnJSLGn.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolData\groove.net\CommonData\CommsOutgoingImage.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\cmm\sRGB.pf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\organize_poster.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\deploy\messages_pt_BR.properties | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\access-bridge-64.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\ext\[BatHelp@protonmail.com].0qCzrMJA-hoJtM2dC.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2052\[BatHelp@protonmail.com].ERgxVeOX-7FivMc4O.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\combine_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\[BatHelp@protonmail.com].s9pRAuGM-HZcIiRiU.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\WebResources\Resource0\static\js\plugins\ob-preview\images\themes\dark\protect_poster2x.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\[BatHelp@protonmail.com].NWGUXmRd-mnWNJ2d4.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1029\LocalizedData.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\lib\jsse.jar | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Extended\[BatHelp@protonmail.com].oSLES2EJ-zfwTtXD9.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\[BatHelp@protonmail.com].vsYWRZaF-LNzF1WkQ.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1030\[BatHelp@protonmail.com].3G7ZVc65-eTuVws03.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3076\[BatHelp@protonmail.com].7KRvyT44-RaZqvfMH.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x64.msi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\[BatHelp@protonmail.com].3slOTszv-56zdBfRP.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0386764.JPG | Modified File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolData\groove.net\CommonData\[BatHelp@protonmail.com].2Du8QCrv-tx9ydlzj.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\root\Office16\Groove\ToolBMPs\[BatHelp@protonmail.com].YxTZQYLV-FXvSYqrf.CORE | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\baxOjf0f.txt | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\VMbyvQ36.bmp | Dropped File | Image |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\IElZnuGN.bat | Dropped File | Batch |
Not Queried
|
...
|
»