VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Pua
|
Threat Names: |
Wilted Tulip
CopyKittens
Gen:Heur.Ransom.Imps.1
|
mspusf.exe
Windows Exe (x86-32)
Created at 2020-06-26T15:33:00
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "1 hour, 1 minute, 30 seconds" to "5 minutes, 30 seconds" to reveal dormant functionality.
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Suspicious
|
Families | - |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x401690 |
Size Of Code | 0x17800 |
Size Of Initialized Data | 0x14200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 1970-01-01 00:00:00+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x176d2 | 0x17800 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.81 |
.rdata | 0x419000 | 0x9869 | 0x9a00 | 0x17c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.24 |
.data | 0x423000 | 0x7f24 | 0x2400 | 0x21600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.36 |
.reloc | 0x42b000 | 0x26f8 | 0x2800 | 0x23a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.2 |
Imports (10)
»
KERNEL32.dll (106)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateEventA | 0x0 | 0x41904c | 0x21994 | 0x20594 | 0x82 |
LeaveCriticalSection | 0x0 | 0x419050 | 0x21998 | 0x20598 | 0x339 |
FileTimeToSystemTime | 0x0 | 0x419054 | 0x2199c | 0x2059c | 0x125 |
EnterCriticalSection | 0x0 | 0x419058 | 0x219a0 | 0x205a0 | 0xee |
FindClose | 0x0 | 0x41905c | 0x219a4 | 0x205a4 | 0x12e |
SetThreadPriorityBoost | 0x0 | 0x419060 | 0x219a8 | 0x205a8 | 0x49a |
GetSystemInfo | 0x0 | 0x419064 | 0x219ac | 0x205ac | 0x273 |
WaitForMultipleObjects | 0x0 | 0x419068 | 0x219b0 | 0x205b0 | 0x4f7 |
FindNextFileW | 0x0 | 0x41906c | 0x219b4 | 0x205b4 | 0x145 |
SetThreadAffinityMask | 0x0 | 0x419070 | 0x219b8 | 0x205b8 | 0x490 |
SetProcessShutdownParameters | 0x0 | 0x419074 | 0x219bc | 0x205bc | 0x483 |
GetSystemTime | 0x0 | 0x419078 | 0x219c0 | 0x205c0 | 0x277 |
ReadFile | 0x0 | 0x41907c | 0x219c4 | 0x205c4 | 0x3c0 |
Process32FirstW | 0x0 | 0x419080 | 0x219c8 | 0x205c8 | 0x396 |
Process32NextW | 0x0 | 0x419084 | 0x219cc | 0x205cc | 0x398 |
CreateToolhelp32Snapshot | 0x0 | 0x419088 | 0x219d0 | 0x205d0 | 0xbe |
GetSystemWindowsDirectoryA | 0x0 | 0x41908c | 0x219d4 | 0x205d4 | 0x27b |
CreateFileW | 0x0 | 0x419090 | 0x219d8 | 0x205d8 | 0x8f |
SetFileAttributesW | 0x0 | 0x419094 | 0x219dc | 0x205dc | 0x461 |
Wow64DisableWow64FsRedirection | 0x0 | 0x419098 | 0x219e0 | 0x205e0 | 0x513 |
Wow64RevertWow64FsRedirection | 0x0 | 0x41909c | 0x219e4 | 0x205e4 | 0x517 |
UnhandledExceptionFilter | 0x0 | 0x4190a0 | 0x219e8 | 0x205e8 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x4190a4 | 0x219ec | 0x205ec | 0x4a5 |
IsDebuggerPresent | 0x0 | 0x4190a8 | 0x219f0 | 0x205f0 | 0x300 |
EncodePointer | 0x0 | 0x4190ac | 0x219f4 | 0x205f4 | 0xea |
DecodePointer | 0x0 | 0x4190b0 | 0x219f8 | 0x205f8 | 0xca |
TerminateProcess | 0x0 | 0x4190b4 | 0x219fc | 0x205fc | 0x4c0 |
HeapFree | 0x0 | 0x4190b8 | 0x21a00 | 0x20600 | 0x2cf |
TlsGetValue | 0x0 | 0x4190bc | 0x21a04 | 0x20604 | 0x4c7 |
TlsSetValue | 0x0 | 0x4190c0 | 0x21a08 | 0x20608 | 0x4c8 |
InterlockedIncrement | 0x0 | 0x4190c4 | 0x21a0c | 0x2060c | 0x2ef |
GetModuleHandleW | 0x0 | 0x4190c8 | 0x21a10 | 0x20610 | 0x218 |
GetCurrentThreadId | 0x0 | 0x4190cc | 0x21a14 | 0x20614 | 0x1c5 |
InterlockedDecrement | 0x0 | 0x4190d0 | 0x21a18 | 0x20618 | 0x2eb |
GetProcAddress | 0x0 | 0x4190d4 | 0x21a1c | 0x2061c | 0x245 |
WideCharToMultiByte | 0x0 | 0x4190d8 | 0x21a20 | 0x20620 | 0x511 |
DeleteCriticalSection | 0x0 | 0x4190dc | 0x21a24 | 0x20624 | 0xd1 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4190e0 | 0x21a28 | 0x20628 | 0x2e3 |
GetCPInfo | 0x0 | 0x4190e4 | 0x21a2c | 0x2062c | 0x172 |
GetACP | 0x0 | 0x4190e8 | 0x21a30 | 0x20630 | 0x168 |
GetOEMCP | 0x0 | 0x4190ec | 0x21a34 | 0x20634 | 0x237 |
IsValidCodePage | 0x0 | 0x4190f0 | 0x21a38 | 0x20638 | 0x30a |
RtlUnwind | 0x0 | 0x4190f4 | 0x21a3c | 0x2063c | 0x418 |
IsProcessorFeaturePresent | 0x0 | 0x4190f8 | 0x21a40 | 0x20640 | 0x304 |
HeapAlloc | 0x0 | 0x4190fc | 0x21a44 | 0x20644 | 0x2cb |
HeapReAlloc | 0x0 | 0x419100 | 0x21a48 | 0x20648 | 0x2d2 |
MultiByteToWideChar | 0x0 | 0x419104 | 0x21a4c | 0x2064c | 0x367 |
LoadLibraryW | 0x0 | 0x419108 | 0x21a50 | 0x20650 | 0x33f |
GetModuleFileNameW | 0x0 | 0x41910c | 0x21a54 | 0x20654 | 0x214 |
GetConsoleCP | 0x0 | 0x419110 | 0x21a58 | 0x20658 | 0x19a |
GetConsoleMode | 0x0 | 0x419114 | 0x21a5c | 0x2065c | 0x1ac |
LCMapStringW | 0x0 | 0x419118 | 0x21a60 | 0x20660 | 0x32d |
GetStringTypeW | 0x0 | 0x41911c | 0x21a64 | 0x20664 | 0x269 |
SetFilePointer | 0x0 | 0x419120 | 0x21a68 | 0x20668 | 0x466 |
GetModuleFileNameA | 0x0 | 0x419124 | 0x21a6c | 0x2066c | 0x213 |
WriteConsoleW | 0x0 | 0x419128 | 0x21a70 | 0x20670 | 0x524 |
SetStdHandle | 0x0 | 0x41912c | 0x21a74 | 0x20674 | 0x487 |
GetCurrentThread | 0x0 | 0x419130 | 0x21a78 | 0x20678 | 0x1c4 |
SetEvent | 0x0 | 0x419134 | 0x21a7c | 0x2067c | 0x459 |
WaitForSingleObject | 0x0 | 0x419138 | 0x21a80 | 0x20680 | 0x4f9 |
GetLogicalDriveStringsW | 0x0 | 0x41913c | 0x21a84 | 0x20684 | 0x208 |
SystemTimeToTzSpecificLocalTime | 0x0 | 0x419140 | 0x21a88 | 0x20688 | 0x4be |
FindFirstFileW | 0x0 | 0x419144 | 0x21a8c | 0x2068c | 0x139 |
GetProcessHandleCount | 0x0 | 0x419148 | 0x21a90 | 0x20690 | 0x249 |
GetProcessTimes | 0x0 | 0x41914c | 0x21a94 | 0x20694 | 0x252 |
CloseHandle | 0x0 | 0x419150 | 0x21a98 | 0x20698 | 0x52 |
GetSystemTimes | 0x0 | 0x419154 | 0x21a9c | 0x2069c | 0x27a |
SwitchToThread | 0x0 | 0x419158 | 0x21aa0 | 0x206a0 | 0x4bc |
SetLastError | 0x0 | 0x41915c | 0x21aa4 | 0x206a4 | 0x473 |
GetStdHandle | 0x0 | 0x419160 | 0x21aa8 | 0x206a8 | 0x264 |
FlushFileBuffers | 0x0 | 0x419164 | 0x21aac | 0x206ac | 0x157 |
WriteFile | 0x0 | 0x419168 | 0x21ab0 | 0x206b0 | 0x525 |
lstrlenA | 0x0 | 0x41916c | 0x21ab4 | 0x206b4 | 0x54d |
GetSystemWindowsDirectoryW | 0x0 | 0x419170 | 0x21ab8 | 0x206b8 | 0x27c |
GetEnvironmentVariableW | 0x0 | 0x419174 | 0x21abc | 0x206bc | 0x1dc |
GetCurrentProcessId | 0x0 | 0x419178 | 0x21ac0 | 0x206c0 | 0x1c1 |
GetLastError | 0x0 | 0x41917c | 0x21ac4 | 0x206c4 | 0x202 |
Sleep | 0x0 | 0x419180 | 0x21ac8 | 0x206c8 | 0x4b2 |
SetProcessPriorityBoost | 0x0 | 0x419184 | 0x21acc | 0x206cc | 0x482 |
GetTickCount | 0x0 | 0x419188 | 0x21ad0 | 0x206d0 | 0x293 |
GetCurrentProcess | 0x0 | 0x41918c | 0x21ad4 | 0x206d4 | 0x1c0 |
CreateMutexW | 0x0 | 0x419190 | 0x21ad8 | 0x206d8 | 0x9e |
MoveFileW | 0x0 | 0x419194 | 0x21adc | 0x206dc | 0x363 |
DeleteFileA | 0x0 | 0x419198 | 0x21ae0 | 0x206e0 | 0xd3 |
lstrcpynA | 0x0 | 0x41919c | 0x21ae4 | 0x206e4 | 0x54a |
Process32First | 0x0 | 0x4191a0 | 0x21ae8 | 0x206e8 | 0x395 |
OpenProcess | 0x0 | 0x4191a4 | 0x21aec | 0x206ec | 0x380 |
Process32Next | 0x0 | 0x4191a8 | 0x21af0 | 0x206f0 | 0x397 |
GetModuleHandleA | 0x0 | 0x4191ac | 0x21af4 | 0x206f4 | 0x215 |
GetComputerNameA | 0x0 | 0x4191b0 | 0x21af8 | 0x206f8 | 0x18c |
GetNativeSystemInfo | 0x0 | 0x4191b4 | 0x21afc | 0x206fc | 0x225 |
SetErrorMode | 0x0 | 0x4191b8 | 0x21b00 | 0x20700 | 0x458 |
GetSystemDirectoryW | 0x0 | 0x4191bc | 0x21b04 | 0x20704 | 0x270 |
GetVolumeInformationA | 0x0 | 0x4191c0 | 0x21b08 | 0x20708 | 0x2a5 |
GetVersionExW | 0x0 | 0x4191c4 | 0x21b0c | 0x2070c | 0x2a4 |
GetEnvironmentVariableA | 0x0 | 0x4191c8 | 0x21b10 | 0x20710 | 0x1db |
CreateThread | 0x0 | 0x4191cc | 0x21b14 | 0x20714 | 0xb5 |
GetProcessHeap | 0x0 | 0x4191d0 | 0x21b18 | 0x20718 | 0x24a |
MoveFileExA | 0x0 | 0x4191d4 | 0x21b1c | 0x2071c | 0x35f |
SetFilePointerEx | 0x0 | 0x4191d8 | 0x21b20 | 0x20720 | 0x467 |
GetFileSizeEx | 0x0 | 0x4191dc | 0x21b24 | 0x20724 | 0x1f1 |
FindFirstFileA | 0x0 | 0x4191e0 | 0x21b28 | 0x20728 | 0x132 |
RemoveDirectoryA | 0x0 | 0x4191e4 | 0x21b2c | 0x2072c | 0x400 |
SetFileAttributesA | 0x0 | 0x4191e8 | 0x21b30 | 0x20730 | 0x45e |
FindNextFileA | 0x0 | 0x4191ec | 0x21b34 | 0x20734 | 0x143 |
ExitProcess | 0x0 | 0x4191f0 | 0x21b38 | 0x20738 | 0x119 |
USER32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
wsprintfW | 0x0 | 0x41927c | 0x21bc4 | 0x207c4 | 0x333 |
CharLowerA | 0x0 | 0x419280 | 0x21bc8 | 0x207c8 | 0x2b |
CharUpperA | 0x0 | 0x419284 | 0x21bcc | 0x207cc | 0x39 |
ADVAPI32.dll (18)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptGetHashParam | 0x0 | 0x419000 | 0x21948 | 0x20548 | 0xc4 |
CryptAcquireContextA | 0x0 | 0x419004 | 0x2194c | 0x2054c | 0xb0 |
CryptCreateHash | 0x0 | 0x419008 | 0x21950 | 0x20550 | 0xb3 |
CryptDestroyHash | 0x0 | 0x41900c | 0x21954 | 0x20554 | 0xb6 |
CryptHashData | 0x0 | 0x419010 | 0x21958 | 0x20558 | 0xc8 |
OpenProcessToken | 0x0 | 0x419014 | 0x2195c | 0x2055c | 0x1f7 |
GetTokenInformation | 0x0 | 0x419018 | 0x21960 | 0x20560 | 0x15a |
SetKernelObjectSecurity | 0x0 | 0x41901c | 0x21964 | 0x20564 | 0x2ad |
GetUserNameA | 0x0 | 0x419020 | 0x21968 | 0x20568 | 0x164 |
RegQueryValueExA | 0x0 | 0x419024 | 0x2196c | 0x2056c | 0x26d |
CryptAcquireContextW | 0x0 | 0x419028 | 0x21970 | 0x20570 | 0xb1 |
CryptGenRandom | 0x0 | 0x41902c | 0x21974 | 0x20574 | 0xc1 |
ControlService | 0x0 | 0x419030 | 0x21978 | 0x20578 | 0x5c |
OpenSCManagerA | 0x0 | 0x419034 | 0x2197c | 0x2057c | 0x1f8 |
QueryServiceStatusEx | 0x0 | 0x419038 | 0x21980 | 0x20580 | 0x229 |
OpenServiceW | 0x0 | 0x41903c | 0x21984 | 0x20584 | 0x1fb |
CloseServiceHandle | 0x0 | 0x419040 | 0x21988 | 0x20588 | 0x57 |
CryptReleaseContext | 0x0 | 0x419044 | 0x2198c | 0x2058c | 0xcb |
SHELL32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetFolderPathW | 0x0 | 0x419220 | 0x21b68 | 0x20768 | 0xc3 |
ShellExecuteExW | 0x0 | 0x419224 | 0x21b6c | 0x2076c | 0x121 |
ole32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StringFromGUID2 | 0x0 | 0x419298 | 0x21be0 | 0x207e0 | 0x179 |
PSAPI.DLL (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetModuleFileNameExW | 0x0 | 0x419218 | 0x21b60 | 0x20760 | 0x10 |
SHLWAPI.dll (19)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathAddBackslashA | 0x0 | 0x41922c | 0x21b74 | 0x20774 | 0x2f |
PathFindFileNameA | 0x0 | 0x419230 | 0x21b78 | 0x20778 | 0x48 |
SHRegSetUSValueA | 0x0 | 0x419234 | 0x21b7c | 0x2077c | 0xf1 |
PathAppendA | 0x0 | 0x419238 | 0x21b80 | 0x20780 | 0x33 |
PathIsDirectoryA | 0x0 | 0x41923c | 0x21b84 | 0x20784 | 0x58 |
PathFindFileNameW | 0x0 | 0x419240 | 0x21b88 | 0x20788 | 0x49 |
StrCpyNW | 0x0 | 0x419244 | 0x21b8c | 0x2078c | 0x124 |
StrCpyW | 0x0 | 0x419248 | 0x21b90 | 0x20790 | 0x125 |
PathFileExistsW | 0x0 | 0x41924c | 0x21b94 | 0x20794 | 0x45 |
StrCatW | 0x0 | 0x419250 | 0x21b98 | 0x20798 | 0x10e |
wvnsprintfA | 0x0 | 0x419254 | 0x21b9c | 0x2079c | 0x16f |
StrCmpW | 0x0 | 0x419258 | 0x21ba0 | 0x207a0 | 0x123 |
StrCmpIW | 0x0 | 0x41925c | 0x21ba4 | 0x207a4 | 0x119 |
StrStrIW | 0x0 | 0x419260 | 0x21ba8 | 0x207a8 | 0x145 |
PathFindExtensionW | 0x0 | 0x419264 | 0x21bac | 0x207ac | 0x47 |
StrStrIA | 0x0 | 0x419268 | 0x21bb0 | 0x207b0 | 0x144 |
StrCatBuffA | 0x0 | 0x41926c | 0x21bb4 | 0x207b4 | 0x10b |
StrNCatW | 0x0 | 0x419270 | 0x21bb8 | 0x207b8 | 0x133 |
wnsprintfA | 0x0 | 0x419274 | 0x21bbc | 0x207bc | 0x16d |
MPR.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetEnumResourceW | 0x0 | 0x4191f8 | 0x21b40 | 0x20740 | 0x1c |
WNetOpenEnumW | 0x0 | 0x4191fc | 0x21b44 | 0x20744 | 0x3d |
WNetCloseEnum | 0x0 | 0x419200 | 0x21b48 | 0x20748 | 0x10 |
NETAPI32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetApiBufferFree | 0x0 | 0x419208 | 0x21b50 | 0x20750 | 0x65 |
NetWkstaGetInfo | 0x0 | 0x41920c | 0x21b54 | 0x20754 | 0x108 |
NetServerGetInfo | 0x0 | 0x419210 | 0x21b58 | 0x20758 | 0xdc |
ntdll.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ZwQueryInformationProcess | 0x0 | 0x41928c | 0x21bd4 | 0x207d4 | 0x409 |
ZwUnmapViewOfSection | 0x0 | 0x419290 | 0x21bd8 | 0x207d8 | 0x47c |
Exports (1)
»
Api name | EAT Address | Ordinal |
---|---|---|
?ReflectiveLoader@@YGKPAX@Z | 0x3b50 | 0x1 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
mspusf.exe | 1 | 0x00830000 | 0x0085DFFF | Relevant Image |
![]() |
32-bit | 0x00833A30 |
![]() |
![]() |
...
|
mspusf.exe | 1 | 0x00830000 | 0x0085DFFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Ransom.Imps.1 |
Malicious
|
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
WiltedTulip_vminst | Malware used in Operation Wilted Tulip | - |
5/5
|
...
|
ReflectiveLoader | Reflective loader usage | - |
3/5
|
...
|
\\?\C:\Users\FD1HVy\AppData\Roaming\5hVk52ujjP2vb7epC7.xls | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\0R6G zd4i6nTDGa8VNm.png.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\8zg7I2Esm.docx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\CjrpV8NWiwYR.png.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\CUCgHoAM.wav.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\DRvrEGQ_bV7.png.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\DVmE9qFtb1fE2H.bmp.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\f_xuR_I_FeQoISyA_I.avi.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\j9Q4P.avi.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\juYPe6EuKhsFCwN.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\jZeT4BL.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\mlrbk-2k1.jpg.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\n5hRh8HkX hRtD-9n.png | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\PjcNBr9EvQRuRkXhA.swf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\QsWrg_KB.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\s8RH8_.mp3.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\SKsJaHK4avL.odp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\uBqsl.png.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\UFfU-NQWoB7XyHy.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\Yjcpzl.ppt | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\_ZxYRX.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\3475V2DB.pdf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\5dJ40KpaZH5gABK Wvl.xls | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\5WpFV5we BjOWCFQ_8P.png.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\7SFq.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\aqQlS_nJ46AyT-L-zj.swf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\Cb9DBpMZ2 ZiZd.jpg.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\DE3scvajpXnclcE34.xls | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\K7u1HHJ_-wyjZGJCddO.doc.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\lDvQFP7B58nzHOr.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\PYzrJzKfYy0WH.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\rBWrlFNmCY.bmp.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\RwNhKXau 7hWtmS6.png | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\OifmxvKJj07hQoi0y.ppt.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\SbwWluUpbQiQnJG8qbe.pdf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\SJcMEwGL9beIVl4.wav.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\T2UrA\8_rlQ cdl 6S_NtQ4.ods.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\T2UrA\9JP3XV6aItTN8Fsv.gif.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\T2UrA\aNP_CKGono8FHP.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\T2UrA\Eiu0lN-XaE.docx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\T2UrA\I0Kapz95f.avi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\T2UrA\OCsemDUOtc.swf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\T2UrA\Rud6mibY589Ee3.mkv | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\T2UrA\xs8aVnsK9NnWwoql.png | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\T2UrA\yGjZ.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\T2UrA\yKYlr_viA.odt | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\tCY_wfmFOaMzCGVNZFEd.m4a.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\TLtL7FqQ6HKzRKYgMVx.mp3.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\tpWq0W7bdVW50sRvURB.ods.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\WDZdqCHFFcmh9_.mp3.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\wO3YP7g6H.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\yn-OCsN4T3Jmv.wav.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\ZSfJsNS2sePMKa.pps.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\ztT1zUqOHSnYLoXvx2_E.csv | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\1WQmayKDv.pptx.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\-nk0Jwf_DtIx7OFnM.xlsx.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\s2-ewyNmBK.gif.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\T2UrA\36V5IRtis-.pps | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\82f_2PILY3Rkg8CydxKr.xlsx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\7d9vJ0y5f9LLSOKq2PHP.ppt.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\9H_Sl92NVVWuSvdwZJYh.pptx.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\chS1ef v8z.odp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\CsjFe8d.pptx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\mDGOSIz_qds.docx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\MRcnfzewVmw.docx.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\NUZN31jJgT6UykF_.ots.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\quCysrsmVF.pptx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\spmR iwVLu JE 9B.rtf.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\U8_NH2Y.pdf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Outlook Files\kkcie@kdj.kd.pst.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Z5Oif6_Mr_Ui\cpdJYzaQxXso.odt | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Z5Oif6_Mr_Ui\ivPZqJfxmHT.pps.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Z5Oif6_Mr_Ui\jDtkUz0kU8\8GgGCWAXxjKLpeoA40OY.odp.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\gaAE08.xlsx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Z5Oif6_Mr_Ui\_L78DH7wK y2TBjiEU\CNnaWo_J.xls | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Z5Oif6_Mr_Ui\_L78DH7wK y2TBjiEU\EPWE.xlsx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Z5Oif6_Mr_Ui\_L78DH7wK y2TBjiEU\JzVy_5xEKQ.xlsx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Z5Oif6_Mr_Ui\_L78DH7wK y2TBjiEU\M24gnx.pps.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Z5Oif6_Mr_Ui\_L78DH7wK y2TBjiEU\MXMHgMI.ods | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Z5Oif6_Mr_Ui\_L78DH7wK y2TBjiEU\VcL01ptYXVDK5.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Z5Oif6_Mr_Ui\_L78DH7wK y2TBjiEU\VSf1IL-6_DKVGroXOg.docx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Z5Oif6_Mr_Ui\_L78DH7wK y2TBjiEU\_HV0qcp0pks\PoJjjS_vt-KW.doc | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Z5Oif6_Mr_Ui\_L78DH7wK y2TBjiEU\_HV0qcp0pks\RcZvqUQNfrhT.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Z5Oif6_Mr_Ui\_L78DH7wK y2TBjiEU\_HV0qcp0pks\tPNskvgoa.ots | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Z5Oif6_Mr_Ui\_L78DH7wK y2TBjiEU\_HV0qcp0pks\tYF1BO7xWTgAbs uk76.csv.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Z5Oif6_Mr_Ui\_L78DH7wK y2TBjiEU\_HV0qcp0pks\vTQY5QAfnqPKv2th.odt | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\33TPGnDT5IeW5L2R8Q.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\ESQxTLKmutc\OAdJkPb-\pEnlGp0QjdthKZA-Yo5o.mp3.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\ESQxTLKmutc\OAdJkPb-\ZwNcr2UV.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\ESQxTLKmutc\Ph7y_8.m4a.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\ESQxTLKmutc\Pq-yXja0.m4a | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\rUUROgRx9gfXRUYVye\ioaNBIFVnbYskp4.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\rUUROgRx9gfXRUYVye\VdR6kOMbj3V3xP\0JKj5_ifBaM.wav.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\rUUROgRx9gfXRUYVye\VdR6kOMbj3V3xP\3MXWb597R4.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\rUUROgRx9gfXRUYVye\VdR6kOMbj3V3xP\BhtHzSyEfD5ggEidkz.wav.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\rUUROgRx9gfXRUYVye\VdR6kOMbj3V3xP\fJIkxuPkzHAaTw7Bvg2.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\ut8OaMa5zK99bj4EvRQ.csv.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\rUUROgRx9gfXRUYVye\VdR6kOMbj3V3xP\lwEeZe6NJKctwuGef3c.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\rUUROgRx9gfXRUYVye\VdR6kOMbj3V3xP\rWrYpfOfe9_Zr8omah.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\rUUROgRx9gfXRUYVye\VdR6kOMbj3V3xP\Wv1ct5mSPlb.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\rUUROgRx9gfXRUYVye\W-oOtVbhE3qMz.wav.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\yvlM_ciBT0jsrUW.pptx.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\VO0C5WvUIA8AyL.m4a.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\z37nyAMgu2jp3cfWIU\7k19qHZKQ\v24aCFd5CzBX.mp3.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\z37nyAMgu2jp3cfWIU\Ftx5O-lqQUv4Qc8fXk.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\z37nyAMgu2jp3cfWIU\JKFgwNnPDq3IzeypAX.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\z37nyAMgu2jp3cfWIU\7k19qHZKQ\UMILH6.mp3.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Z5Oif6_Mr_Ui\jDtkUz0kU8\hnSSITWu7H4.odt.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\z37nyAMgu2jp3cfWIU\NXIDve2FMxUql9.wav.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\7ln6G64dp6.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\6to-Do2T3Y6Ag.jpg.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\z37nyAMgu2jp3cfWIU\toS-EwE0vCCwoskwD1\HN-OE9UFOJ0.mp3.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\ai_VKHzC7Sqq7BSY5RS0.jpg.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\dF_BgEryZj.gif.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\F1oeE.png.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\kG7T_G4j-\3w6B72hITb.png.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\kG7T_G4j-\0 jXVleh5y.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\kG7T_G4j-\iRuE37I4VoTmYoZQwpA.png.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\kG7T_G4j-\Kiw0vwA10s0.png.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\kG7T_G4j-\O7DPIcWP9p.jpg | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\kG7T_G4j-\qC_RZrVpYkb.bmp.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\kG7T_G4j-\QQo9Vv.bmp.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\kG7T_G4j-\wAVErpzAz.png.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\kG7T_G4j-\xYVA6nzw2.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\msDAnVl Vs INrTL.jpg.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\oOTvWfHAVr.png | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\wI6_mSLtm0QHgo.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\x7M0JVNEgkR8AAFTEXtY.jpg.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\E10w7BI-yN9p\cDQNx.mp4 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\E10w7BI-yN9p\YD6Z6S-cuGg\6HAlI.avi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\E10w7BI-yN9p\YD6Z6S-cuGg\8aR-oZ.mp4 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\e7C5rm59mT0uP_9f.avi.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\ofxv0mmpKK_\9t0zT_40.mkv | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\ofxv0mmpKK_\a w2nq\0ll0qUCYfiYHKHKER R\JifxRs4kGA26s8ZB.swf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\ofxv0mmpKK_\a w2nq\0ll0qUCYfiYHKHKER R\smX5XObO64h XQO8UV.avi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\ofxv0mmpKK_\a w2nq\fR4 C.mp4 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\ofxv0mmpKK_\a w2nq\iGBmnx.swf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\ofxv0mmpKK_\a w2nq\MTVtI3u5U.mkv.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\ofxv0mmpKK_\a w2nq\mZX-jxKKh.mkv.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\ofxv0mmpKK_\a w2nq\Z2p1JCW7G9Pu\w7jO4I_4r ubq7OFIn.flv.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\ofxv0mmpKK_\a w2nq\ZXAEqbOqqWast AZ98L.flv.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\ofxv0mmpKK_\OoNzmd4unsBSLKUjo7.avi.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\ofxv0mmpKK_\t8NhEX.mkv.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\ofxv0mmpKK_\VzUBwEA5P.avi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\WlTa\2oN gpnuW1JXd5I9rz.swf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\WlTa\d0y3irQ9gxE8.flv.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\WlTa\r47Nb711Z06w9.mp4 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.txd0t | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\GetCurrentRollback.ini | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1025\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\E10w7BI-yN9p\!TXDOT_READ_ME!.txt | Dropped File | Text |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Local\Resmon.ResmonCfg.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\aNTcu_iQUI-LLKOyho.avi | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\c39tCHh.avi | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\cv28-Ixq4k3KD.mkv | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\D3INp6Ei.xlsx.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\ET9_8drX4.bmp.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\mFz6aNQKv94_Rr.mkv.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\PDHYzrp.wav.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\pMTil.png | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\sT1K.flv | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\U6XvU G.bmp.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\U9jIHqltNvJBusuu8M.m4a.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\3QaEJDzGG8TQ5z.rtf | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\wL6CtWVaL-45s.odp.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\XqhhUYjJL0U.rtf.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\YDXeffFC99vGn.mp3.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\8dOKYe-qP.odt | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\BBeZnteC-7.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\CyLY.bmp | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\GHZr_0qE96Rjj.avi | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\jhscRm6vvE.csv | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\oIyEk1tbor7X9s.bmp | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\OO_s81.avi | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\RnjQ5ZSPpYJwR3B.jpg.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\T2UrA\3dId0lsBJQweABTLa.bmp.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\T2UrA\R1PzCjuzfThXdK9.ppt | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\T2UrA\X24_B.gif | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\VCbe_Sa0NEidgDcyfgFz.flv.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\Vn Oo.gif.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\Zau1_Q_6PWntC.gif | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\27kj6w0qCAmGPNM.docx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\4oSJqKCx.docx.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\6IKlp7h.ppt | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\aayLh9Av.xlsx.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\dMMktGSdsuA8JTH.docx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\lLleeaH.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\lzf-_9_.pptx.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Md5Q.odt.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\QQnuWmakq.docx.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sA2u-LPe-LiGoMos.pdf.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\UgOWYrVuYDiW8pkWKYl.xls.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Z5Oif6_Mr_Ui\2o _xfnucm3wfE92We.ods.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Z5Oif6_Mr_Ui\jDtkUz0kU8\j7-b.pdf | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Z5Oif6_Mr_Ui\jDtkUz0kU8\LFpWuQJ-aF.doc.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Z5Oif6_Mr_Ui\jDtkUz0kU8\wUuIQI1na.odp | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Z5Oif6_Mr_Ui\xuaWupFvOSfqE.pps | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Z5Oif6_Mr_Ui\_L78DH7wK y2TBjiEU\Uct9z.odt | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Z5Oif6_Mr_Ui\_L78DH7wK y2TBjiEU\w3sXXqR.xlsx.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Z5Oif6_Mr_Ui\_L78DH7wK y2TBjiEU\_HV0qcp0pks\iTea.pptx.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Music\ESQxTLKmutc\OAdJkPb-\KXtDlQHWMbiCZ2hHs6x.m4a | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Music\ESQxTLKmutc\zaYdv7kbUlcUxSz3KeA-.wav | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Music\fXQDJP18MMdWjvedkW4.mp3.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Music\JI_ROcYP5iaMyIhA11bQ\U7kcA.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Music\m-T19pWPhwjALOHNq.wav.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Music\rUUROgRx9gfXRUYVye\Mo9aZN_6Jq9VyBd _y.m4a.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Music\rUUROgRx9gfXRUYVye\VdR6kOMbj3V3xP\o_54eDamWws3.mp3.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Music\rUUROgRx9gfXRUYVye\WDCK.m4a | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Music\z37nyAMgu2jp3cfWIU\5YOR.m4a | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Music\z37nyAMgu2jp3cfWIU\cSnUOnQz6xEd.wav.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Music\z37nyAMgu2jp3cfWIU\toS-EwE0vCCwoskwD1\uUCd01DT4yfQz.wav.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\gpNFvPMeWkFC.gif.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\JNDCEREvKtt-06-A0UX8.png.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\kG7T_G4j-\Bn2jVBj5I1Q6.png.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\kG7T_G4j-\bwUCcMWGBF1Mcn_.gif.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\kG7T_G4j-\-aUMUjkCqPRwR9Vt.gif | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\kG7T_G4j-\e0RUl3aLEh6brT_yeUb0.jpg | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\kG7T_G4j-\EVRLdIxDOIvB-Fc9_h.gif.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\kG7T_G4j-\VM0 JSKujUy.jpg | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\nDbY.bmp | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\SjHlBfZqKWu.bmp.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\SUlXmTX1.jpg.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\Xej8a4-yl4uAkyUIiU1.jpg.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\g_PWWk0DwHdiVJ7TQ.jpg.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\42OnoQ2VRBixgPOTlYl.avi | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\E10w7BI-yN9p\YD6Z6S-cuGg\hrFHHxEDNXCX.swf.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\E10w7BI-yN9p\YD6Z6S-cuGg\P6NtF9p_sziw.mp4.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\gPsXouAw.flv | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\GsXmIOztESVB3CY.mp4.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\JbkR3ATa90b5U.avi | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\ofxv0mmpKK_\a w2nq\0ll0qUCYfiYHKHKER R\vH3psvYnWA.swf.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\ofxv0mmpKK_\a w2nq\0qq-2JELVv.avi | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\kG7T_G4j-\cBmZZ5bX2Jx3bJhbUv.bmp | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\ofxv0mmpKK_\a w2nq\I8mA7.swf | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\ofxv0mmpKK_\a w2nq\IWWrfzZp12CtwW5GR.mkv.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\ofxv0mmpKK_\a w2nq\LISQrmwmwFkmeV9a6dun.mp4.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\ofxv0mmpKK_\a w2nq\Z2p1JCW7G9Pu\AuNane-wUgoPDM.swf.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\ofxv0mmpKK_\ay37U hT.mp4.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\ofxv0mmpKK_\kxtmh_DCIU7SgwmG7I.swf.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\ofxv0mmpKK_\WxV-TMM4v.avi.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\WlTa\2q3Ks4TNs0IQQ.swf.txd0t | Dropped File | Stream |
Not Queried
|
...
|
»