VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan, Worm |
larvvi.exe
Windows Exe (x86-32)
Created 6 years ago
Remarks
(0x200001b): The maximum number of file reputation requests per analysis (20) was exceeded.
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\larvvi.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Suspicious
|
First Seen | 2019-05-11 00:28 (UTC+2) |
Last Seen | 2019-05-18 05:58 (UTC+2) |
Names | Win32.Trojan.Uac |
Families | Uac |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4042b0 |
Size Of Code | 0x3400 |
Size Of Initialized Data | 0x1400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-05-10 19:08:40+00:00 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x3316 | 0x3400 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.91 |
.rdata | 0x405000 | 0x109a | 0x1200 | 0x3800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.87 |
.data | 0x407000 | 0x3c | 0x200 | 0x4a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.55 |
Imports (7)
»
KERNEL32.dll (35)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
HeapAlloc | 0x0 | 0x405020 | 0x5bec | 0x43ec | 0x345 |
GetWindowsDirectoryW | 0x0 | 0x405024 | 0x5bf0 | 0x43f0 | 0x326 |
GetProcAddress | 0x0 | 0x405028 | 0x5bf4 | 0x43f4 | 0x2ae |
VerSetConditionMask | 0x0 | 0x40502c | 0x5bf8 | 0x43f8 | 0x5c1 |
GetCurrentProcessId | 0x0 | 0x405030 | 0x5bfc | 0x43fc | 0x218 |
GetProcessHeap | 0x0 | 0x405034 | 0x5c00 | 0x4400 | 0x2b4 |
CreateProcessW | 0x0 | 0x405038 | 0x5c04 | 0x4404 | 0xe5 |
VerifyVersionInfoW | 0x0 | 0x40503c | 0x5c08 | 0x4408 | 0x5c5 |
GetCurrentProcess | 0x0 | 0x405040 | 0x5c0c | 0x440c | 0x217 |
GetModuleFileNameW | 0x0 | 0x405044 | 0x5c10 | 0x4410 | 0x274 |
IsWow64Process | 0x0 | 0x405048 | 0x5c14 | 0x4414 | 0x391 |
HeapFree | 0x0 | 0x40504c | 0x5c18 | 0x4418 | 0x349 |
lstrlenA | 0x0 | 0x405050 | 0x5c1c | 0x441c | 0x63b |
GetSystemInfo | 0x0 | 0x405054 | 0x5c20 | 0x4420 | 0x2e3 |
GetLogicalDrives | 0x0 | 0x405058 | 0x5c24 | 0x4424 | 0x268 |
FindFirstFileW | 0x0 | 0x40505c | 0x5c28 | 0x4428 | 0x180 |
FindNextFileW | 0x0 | 0x405060 | 0x5c2c | 0x442c | 0x18c |
WriteFile | 0x0 | 0x405064 | 0x5c30 | 0x4430 | 0x612 |
WaitForMultipleObjects | 0x0 | 0x405068 | 0x5c34 | 0x4434 | 0x5d5 |
FindClose | 0x0 | 0x40506c | 0x5c38 | 0x4438 | 0x175 |
CreateFileW | 0x0 | 0x405070 | 0x5c3c | 0x443c | 0xcb |
ExitThread | 0x0 | 0x405074 | 0x5c40 | 0x4440 | 0x15f |
CreateThread | 0x0 | 0x405078 | 0x5c44 | 0x4444 | 0xf3 |
SetFilePointerEx | 0x0 | 0x40507c | 0x5c48 | 0x4448 | 0x523 |
ExitProcess | 0x0 | 0x405080 | 0x5c4c | 0x444c | 0x15e |
lstrcmpW | 0x0 | 0x405084 | 0x5c50 | 0x4450 | 0x630 |
MoveFileW | 0x0 | 0x405088 | 0x5c54 | 0x4454 | 0x3eb |
LoadLibraryW | 0x0 | 0x40508c | 0x5c58 | 0x4458 | 0x3c4 |
CloseHandle | 0x0 | 0x405090 | 0x5c5c | 0x445c | 0x86 |
lstrcatW | 0x0 | 0x405094 | 0x5c60 | 0x4460 | 0x62d |
LoadLibraryA | 0x0 | 0x405098 | 0x5c64 | 0x4464 | 0x3c1 |
OpenProcess | 0x0 | 0x40509c | 0x5c68 | 0x4468 | 0x40d |
GetVersionExW | 0x0 | 0x4050a0 | 0x5c6c | 0x446c | 0x31b |
ReadFile | 0x0 | 0x4050a4 | 0x5c70 | 0x4470 | 0x473 |
WaitForSingleObject | 0x0 | 0x4050a8 | 0x5c74 | 0x4474 | 0x5d7 |
ADVAPI32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptDestroyKey | 0x0 | 0x405000 | 0x5bcc | 0x43cc | 0xc8 |
CryptEncrypt | 0x0 | 0x405004 | 0x5bd0 | 0x43d0 | 0xcb |
CryptImportKey | 0x0 | 0x405008 | 0x5bd4 | 0x43d4 | 0xdb |
CryptReleaseContext | 0x0 | 0x40500c | 0x5bd8 | 0x43d8 | 0xdc |
CryptGenRandom | 0x0 | 0x405010 | 0x5bdc | 0x43dc | 0xd2 |
CryptAcquireContextW | 0x0 | 0x405014 | 0x5be0 | 0x43e0 | 0xc2 |
CryptAcquireContextA | 0x0 | 0x405018 | 0x5be4 | 0x43e4 | 0xc1 |
ole32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
IIDFromString | 0x0 | 0x4050e0 | 0x5cac | 0x44ac | 0x102 |
CoInitializeEx | 0x0 | 0x4050e4 | 0x5cb0 | 0x44b0 | 0x5e |
CoGetObject | 0x0 | 0x4050e8 | 0x5cb4 | 0x44b4 | 0x51 |
SHLWAPI.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StrStrW | 0x0 | 0x4050c8 | 0x5c94 | 0x4494 | 0x152 |
wnsprintfW | 0x0 | 0x4050cc | 0x5c98 | 0x4498 | 0x178 |
ntdll.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RtlLeaveCriticalSection | 0x0 | 0x4050d4 | 0x5ca0 | 0x44a0 | 0x4ad |
RtlEnterCriticalSection | 0x0 | 0x4050d8 | 0x5ca4 | 0x44a4 | 0x397 |
MPR.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetEnumResourceW | 0x0 | 0x4050b0 | 0x5c7c | 0x447c | 0x23 |
WNetCloseEnum | 0x0 | 0x4050b4 | 0x5c80 | 0x4480 | 0x17 |
WNetOpenEnumW | 0x0 | 0x4050b8 | 0x5c84 | 0x4484 | 0x44 |
MSVCRT.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
memset | 0x0 | 0x4050c0 | 0x5c8c | 0x448c | 0x299 |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
larvvi.exe | 1 | 0x00400000 | 0x00407FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Ransom.Imps.1 |
Malicious
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
OlympicDestroyer_Gen1 | Olympic Destroyer destructive malware | Worm |
Malicious
|
...
|
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Suggested Sites.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\Default\Documents\desktop.ini | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Work.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Entertainment.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Spaces.url | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Saved Games\desktop.ini | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\Public\Documents\desktop.ini | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\Public\Downloads\desktop.ini | Modified File | Text |
Unknown
|
...
|
»
\\?\C:\Users\Public\Libraries\RecordedTV.library-ms | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\Public\Music\Sample Music\desktop.ini | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\Public\Recorded TV\desktop.ini | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.EZDZ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi.EZDZ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\1033\dwintl20.dll.EZDZ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\HPfPz\0xMp.wav.EZDZ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\Public\Pictures\Sample Pictures\Chrysanthemum.jpg.EZDZ | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\myhM-u8Oczqbn\V I7sRX\RILP g 1rqsEUushWn\S7pLkd3 3MfqDgcWxZk\hSE8808C39qcG6UJM.pps | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Links\Desktop.lnk | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\ntuser.ini | Modified File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Desktop\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Downloads\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Web Slice Gallery.url | Modified File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE Add-on site.url | Modified File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE site on Microsoft.com.url | Modified File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Home.url | Modified File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft Store.url | Modified File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Autos.url | Modified File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Money.url | Modified File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Sports.url | Modified File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN.url | Modified File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSNBC News.url | Modified File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Get Windows Live.url | Modified File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Gallery.url | Modified File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Mail.url | Modified File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Links\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Links\Desktop.lnk | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Links\Downloads.lnk | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Music\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Default\Pictures\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Searches\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Public\Libraries\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Public\Music\desktop.ini | Modified File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Public\Pictures\desktop.ini | Modified File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Public\Recorded TV\Sample Media\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Public\Videos\desktop.ini | Modified File | Text |
Not Queried
|
...
|
»
\\?\C:\Users\Public\Videos\Sample Videos\desktop.ini | Modified File | Text |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi.EZDZ | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.EZDZ | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab.EZDZ | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi.EZDZ | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.cab.EZDZ | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.msi.EZDZ | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi.EZDZ | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfLR.cab.EZDZ | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact.EZDZ | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\OHw3M1GbO1rxX\73DGvzIzmIC8.odp.EZDZ | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\-D9LwOMHP I2-mZ.doc.EZDZ | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ci77Ti4lhul7c.pptx.EZDZ | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\_private\folder.ico.EZDZ | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\myhM-u8Oczqbn\477E54rkiZ.ods.EZDZ | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\myhM-u8Oczqbn\V I7sRX\lJg8R\-8Hz2TqvFV1rlvG2RQHR.xls.EZDZ | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\myhM-u8Oczqbn\V I7sRX\RILP g 1rqsEUushWn\S7pLkd3 3MfqDgcWxZk\lES-IyA\fCDuSz1M.rtf.EZDZ | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst.EZDZ | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Links\Downloads.lnk.EZDZ | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\44Q4Y701hW_AjHvRD\JANP3Yj62Cpv\4EiSqDeaZ.m4a.EZDZ | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\WQL90KrgVVGy1xk89d9\ThVL9n0DbS\mQV8J7-.m4a.EZDZ | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\dvHHUN\FDa6smMzP18wZYAjuLC\6pOkvTj9CQqlV.mkv.EZDZ | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\Default\NTUSER.DAT.EZDZ | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\HELP_PC.EZDZ-REMOVE.txt | Dropped File | Text |
Not Queried
|
...
|
»