VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Dropper
|
Threat Names: |
Gen:Variant.Strictor.242371
Gen:Trojan.Heur.tmuar0E8qkai
Gen:Variant.Ursu.849896
...
|
MaMoCrypter.exe
Windows Exe (x86-32)
Created at 2020-05-01T21:26:00
Remarks
(0x0200000C): The maximum memory dump size was exceeded. Some dumps may be missing in the report.
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x6e732b |
Size Of Code | 0x221000 |
Size Of Initialized Data | 0xb7000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-04-30 08:28:32+00:00 |
Version Information (5)
»
FileDescription | MaMoCrypter |
FileVersion | 1.0.0.0 |
ProductName | MaMoCrypter |
ProductVersion | 1.0.0.0 |
ProgramID | com.embarcadero.MaMoCrypter |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.MPRESS1 | 0x401000 | 0x2e6000 | 0xd6200 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 8.0 |
.MPRESS2 | 0x6e7000 | 0xef8 | 0x1000 | 0xd6400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.74 |
.rsrc | 0x6e8000 | 0xf258 | 0xf400 | 0xd7400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.38 |
Imports (11)
»
KERNEL32.DLL (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetModuleHandleA | 0x0 | 0x6e7190 | 0x2e7190 | 0xd6590 | 0x0 |
GetProcAddress | 0x0 | 0x6e7194 | 0x2e7194 | 0xd6594 | 0x0 |
winspool.drv (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ClosePrinter | 0x0 | 0x6e719c | 0x2e719c | 0xd659c | 0x0 |
comctl32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ImageList_Add | 0x0 | 0x6e71a4 | 0x2e71a4 | 0xd65a4 | 0x0 |
shell32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x6e71ac | 0x2e71ac | 0xd65ac | 0x0 |
ole32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
IsEqualGUID | 0x0 | 0x6e71b4 | 0x2e71b4 | 0xd65b4 | 0x0 |
version.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VerQueryValueW | 0x0 | 0x6e71bc | 0x2e71bc | 0xd65bc | 0x0 |
user32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetDC | 0x0 | 0x6e71c4 | 0x2e71c4 | 0xd65c4 | 0x0 |
oleaut32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VariantInit | 0x0 | 0x6e71cc | 0x2e71cc | 0xd65cc | 0x0 |
netapi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetWkstaGetInfo | 0x0 | 0x6e71d4 | 0x2e71d4 | 0xd65d4 | 0x0 |
advapi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegLoadKeyW | 0x0 | 0x6e71dc | 0x2e71dc | 0xd65dc | 0x0 |
gdi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Pie | 0x0 | 0x6e71e4 | 0x2e71e4 | 0xd65e4 | 0x0 |
Exports (3)
»
Api name | EAT Address | Ordinal |
---|---|---|
TMethodImplementationIntercept | 0xd7a40 | 0x3 |
__dbk_fcall_wrapper | 0x1073c | 0x2 |
dbkFCallWrapperAddr | 0x22c63c | 0x1 |
Memory Dumps (36)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | First Execution |
![]() |
32-bit | 0x006E732B |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x0040F230 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x00415A44 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x0042B174 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x00429084 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x0052A5C0 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x00521944 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x00513F24 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x0051E690 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x00552B20 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x005F0AB8 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x00531A84 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x00466D5C |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x0059A3CC |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x005292A8 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x005260FC |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x005E7544 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x005F3A34 |
![]() |
![]() |
...
|
buffer | 1 | 0x00820000 | 0x00820FFF | First Execution |
![]() |
32-bit | 0x00820FE2 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x00566C0C |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x00571520 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x0047F2D0 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x005A428C |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x0045FD98 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x00617174 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x0053EF64 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x005ECCAC |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x0053F308 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x005ED9A0 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x00525DB0 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x0042B638 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x0040A78C |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x00409CF0 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x0059AA44 |
![]() |
![]() |
...
|
buffer | 1 | 0x00820000 | 0x00820FFF | Content Changed |
![]() |
32-bit | 0x00820FC8 |
![]() |
![]() |
...
|
mamocrypter.exe | 1 | 0x00400000 | 0x006F7FFF | Content Changed |
![]() |
32-bit | 0x0047C920 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Strictor.242371 |
Malicious
|
C:\Users\FD1HVy\AppData\Local\Temp\RM_DATA.exe | Dropped File | Text |
Malicious
|
...
|
»
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Trojan.Heur.tmuar0E8qkai |
Malicious
|
C:\Users\FD1HVy\AppData\Local\Temp\svchost.exe | Dropped File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x56125a |
Size Of Code | 0x128e00 |
Size Of Initialized Data | 0x2a000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-04-09 16:31:35+00:00 |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | Host Process for Windows Services |
FileVersion | 6.3.9600.17623 |
InternalName | svchost.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | svchost.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 6.3.9600.17415 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.MPRESS1 | 0x401000 | 0x160000 | 0x4a800 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 8.0 |
.MPRESS2 | 0x561000 | 0xe00 | 0xe00 | 0x4aa00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.04 |
.rsrc | 0x562000 | 0xd0c | 0xe00 | 0x4b800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.52 |
Imports (7)
»
KERNEL32.DLL (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetModuleHandleA | 0x0 | 0x56113c | 0x16113c | 0x4ab3c | 0x0 |
GetProcAddress | 0x0 | 0x561140 | 0x161140 | 0x4ab40 | 0x0 |
shell32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x561148 | 0x161148 | 0x4ab48 | 0x0 |
version.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VerQueryValueW | 0x0 | 0x561150 | 0x161150 | 0x4ab50 | 0x0 |
user32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CharNextW | 0x0 | 0x561158 | 0x161158 | 0x4ab58 | 0x0 |
oleaut32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VariantCopy | 0x0 | 0x561160 | 0x161160 | 0x4ab60 | 0x0 |
netapi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetWkstaGetInfo | 0x0 | 0x561168 | 0x161168 | 0x4ab68 | 0x0 |
advapi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegLoadKeyW | 0x0 | 0x561170 | 0x161170 | 0x4ab70 | 0x0 |
Exports (3)
»
Api name | EAT Address | Ordinal |
---|---|---|
TMethodImplementationIntercept | 0x62048 | 0x3 |
__dbk_fcall_wrapper | 0x10db0 | 0x2 |
dbkFCallWrapperAddr | 0x13663c | 0x1 |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Trojan.Heur.tmuar0E8qkai |
Malicious
|
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\-a8H16g7Z8.flv.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\-kGuY.lnk | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\0anbzC4wy3QV.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\13_UhdLxbGNJHYgey.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\1_2OVvk.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\2f1V.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\4NRYueZu34oKrb1iEn.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\4Zbv0xLp.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\5B1wK SInIEY1XG8.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\5DFJaZ09zxpj.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\7xXZSvgm4j.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\8SsQp4xZlzVC.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\9qqaMDM.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\9rQNK dYKtJL.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\9y41-fr3PlkYnrNFG2e.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\AuJwOyKnChH.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\BEd17CeTok20XCp bu.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Bim9Uz1pL.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\BjNUPBepTMMyu.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Bm_0O.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\br3Sl.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\BRtkw7h20gut.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\bVOcRN8FT.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\c IXUe-mvNtEdk.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\cpvUnLAPgKUFNMAUgON.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\CyPtYrEBdI9stHyXAH.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Dzl1T_E T7Ch1n.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\EdrNe.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\eh9nFqOb33ZYsx1OOIH.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\eOmjS8.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\fhSP KphnxTI.flv.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\FicTeeGg9cZ.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\GE2XWZw-UJlajB.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Gsdux_nrV.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\gypaWQDSFuYxA4ea_Oei.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\HqBE4s3H uNUYMjPX.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\iLaJJJl9bXoFrg4vmuJ.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\jjcfaQYy1u4aYRF.flv.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Jm-pvNoF7ZQ8Z9U.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\JsYf-A6h4Bx.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\jZEwhVWt50V33_ 5Cs5n.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Kbg6SBTSjJvSFEUP4JMP.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\l5xkq_P4B0Vr6xH.lnk.MZ173801 | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\LmhsbTNLSJY.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\lOp2Pc8PoOE5fYa7j.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\lwhJgzvsl5XlQcrqU6.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\mrC2.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Music.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\MZb5e8JNXGX.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\nDZdZhLaQYg.ots.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Ng-XMX.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\NnWEZGpZkAAsmio3W.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\nuPKgeB MAKEYlr.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\oeFUq.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\oeJFddiIwMX1RoB4tjS.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\oj2PlKbc7rCn.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\oojSlrPVLmu.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\OTKm8-mOEk l8967aX.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Ozc5X.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\pa0XQGFgpgnvg.flv.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\pUtEu.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\qGswZi1Gyw _CPZuF.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\QRroD6XCz-BrMFrtkIV.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\QsHzM41CtrXDXmh.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\RaqZQNwTN3mbA0F.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\RDCSEzrQ7xZ1X0RREt.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\REZYZ1.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\SyPgeh2hWXPmhIqZ_oMv.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\tX2YPj0q7xi_0h30ePDe.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\UEnT80em6X.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\UwqXZEB.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\v32KoNWBg.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\vB8zsHUk.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\W8V9x-I5M8DNxGO4p7hs.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\wsBv9esj.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\WtcPvUSK6qZR3.ots.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\WVzot.flv.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\XIPVtvqfodb6mWbl.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\XsWSFfkpZ7NjwRf.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\xWBAe007WO5EnzhrP2CH.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\yC1N.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\YYk-.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Y_OK e3 tBYnfH- u5V.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\_trbIxVN.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\BRtkw7h20gut.png.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\bzprLu.jpg.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\cjOca2N.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Jm-pvNoF7ZQ8Z9U.bmp.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\nuPKgeB MAKEYlr.jpg.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\soIxhtWQvRHiZe.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\v32KoNWBg.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\4yBx\-1TC27W511TZ.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\4yBx\CyPtYrEBdI9stHyXAH.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\4yBx\dCe5ivejzMlw0ls1pYC.jpg.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\4yBx\HyovCFdDMEMPXi2tYJN.png.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\4yBx\KOUa9IHzzFzSN.bmp.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\4yBx\MmyqV.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\4yBx\oeFUq.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\4yBx\P3JDGEyVU9q0 M.bmp.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\4yBx\psR4.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\4yBx\SuC Il0UxSD20dVADwP.bmp.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\4yBx\ww0uvocct0qsPBwJa 7.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\UEnT80em6X.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\9y41-fr3PlkYnrNFG2e\AuJwOyKnChH.wav.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\9y41-fr3PlkYnrNFG2e\c IXUe-mvNtEdk.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\9y41-fr3PlkYnrNFG2e\TKNOwmA4NSUOy4hb4aSU.wav.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\9y41-fr3PlkYnrNFG2e\VqltAk\eOmjS8.wav.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\9y41-fr3PlkYnrNFG2e\VqltAk\5B1wK SInIEY1XG8\KyDI6rQz0nUT1e2995v.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\9y41-fr3PlkYnrNFG2e\VqltAk\5B1wK SInIEY1XG8\zlyONG3Bll4oZ.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\9y41-fr3PlkYnrNFG2e\VqltAk\JsYf-A6h4Bx\5kfHm.m4a.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\9y41-fr3PlkYnrNFG2e\VqltAk\JsYf-A6h4Bx\k07tTnZjrtR20ZMVLMQ.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\9y41-fr3PlkYnrNFG2e\VqltAk\JsYf-A6h4Bx\l5xkq_P4B0Vr6xH.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\9y41-fr3PlkYnrNFG2e\VqltAk\JsYf-A6h4Bx\oj2PlKbc7rCn.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\9y41-fr3PlkYnrNFG2e\VqltAk\LFHpZh3EGDvVG\Eqf_vPTfpsTYa7.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\9y41-fr3PlkYnrNFG2e\VqltAk\LFHpZh3EGDvVG\fWrYbFvKgXjYGT.m4a.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\9y41-fr3PlkYnrNFG2e\VqltAk\LFHpZh3EGDvVG\QRroD6XCz-BrMFrtkIV.m4a.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\Gsdux_nrV\1HV6OOMj2L4Qe_mHPLK.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\Gsdux_nrV\5V xr.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\Gsdux_nrV\qGswZi1Gyw _CPZuF.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\Gsdux_nrV\qQSmOyAVpU.wav.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\svKO8jzsiZGRBC\QaCMXvblUaYWg.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\svKO8jzsiZGRBC\TRIU.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\1_2OVvk.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fYpIk.mp4.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\Io wk8vMTXy-go.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\Xa5aL.mkv.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\7uaJhnURa\MZb5e8JNXGX.mp4.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\-a8H16g7Z8.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\sqorZLc30 FYq4TE ce9.mkv.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\13_UhdLxbGNJHYgey\1SMdexnO32Gfhrk4V0f.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\13_UhdLxbGNJHYgey\pa0XQGFgpgnvg.flv.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\13_UhdLxbGNJHYgey\pRvInr44zIMLaGG9ke.mkv.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\13_UhdLxbGNJHYgey\5DFJaZ09zxpj\5zGRTy-2fNRCTB wsnKe.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\aUIpFDwEiCcpzrSkPaW0\MX9apbEfVsUdHsYol.swf.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\aUIpFDwEiCcpzrSkPaW0\rsEEM5nZHG-x.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\wmEX\5uhOhbIjv9JmUgM6ZS_E.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\wmEX\fhSP KphnxTI.flv.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\wmEX\gypaWQDSFuYxA4ea_Oei.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\wmEX\wKHsoyD.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\wmEX\z 7ggJ8\bAQTMwTYFo4f.avi.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\wmEX\z 7ggJ8\nS7qCk1FY_m2n6d8o2.flv.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\wmEX\z 7ggJ8\xWBAe007WO5EnzhrP2CH.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\2f1V.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Database1.accdb.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\EdrNe.pptx.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\fMxk2fHJ.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\jJcmB8tI.docx.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\kcbhP88PnzqBNGqzO3.pptx.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\m CS2FXbWa5.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\m_JbGT.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\-FCpg55NRtj-U6_PA.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\-LTq6n--dr.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\283NpHh8_ly2.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\3qar626WH.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\4DOO7h9IdbHgOJ L.flv.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\4yBx.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\7uaJhnURa.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\aUIpFDwEiCcpzrSkPaW0.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\B3BnBu7o8.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\B3oPu9_P2sx63bYJ.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\BiCkmLzhNyPE.ots.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\BNpcCajc.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\bx_sreHB6g Fc-Lx.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\bzprLu.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\cEUdy Q8gkA4LqZQF.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\D7yD06jADs4bzbO.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\eIdmvaOqadIUE.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\FLOta7xX0gkrp_QvZlm.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\fnWHfWmALlcTd.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\FqOJo-o8.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\gENSLI1SLB1QB.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\i5uD5Xoo.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\IDF-wgV.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\KbOxgphNJ70M.flv.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\kcbhP88PnzqBNGqzO3.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\KyDI6rQz0nUT1e2995v.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\LFHpZh3EGDvVG.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\m CS2FXbWa5.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\m5j0.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\MmiYF.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\m_JbGT.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\NJjgpU2TJz.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\nS7qCk1FY_m2n6d8o2.flv.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\oc9w vNlFm_eUy1Ryd4.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Pictures.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\pRvInr44zIMLaGG9ke.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\psR4.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\PurPDfKeeDvp_IIQ.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\q3G nDiy4yr.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\RGQur6sY-GXeNf-nX.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Roaming.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\soIxhtWQvRHiZe.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\sqorZLc30 FYq4TE ce9.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\TNMTkGiMBk1T.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\U6w rqSTE2RE5fqSNr.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\UdgbQ58vO-A8Tluz.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\UV46w2I sa.flv.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Videos.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\VqltAk.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\wHBTEKON3Jt-O3n64e.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\wmEX.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\ww0uvocct0qsPBwJa 7.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\xC-u2wjwqhihKd-.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\z 7ggJ8.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\zkcrT -8SHIvOP_POgOU.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\zlyONG3Bll4oZ.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\_4dYp.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\_MPfsxTZe1i_HSj02G.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\9Ogt.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\BjNUPBepTMMyu.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\gakO-X.jpg.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\MmiYF.bmp.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\ThBkp.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\TNMTkGiMBk1T.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\yvoDa.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\4yBx\1yb8XS7Sv411u.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\4yBx\aEhM511O8dO.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\4yBx\BaruB.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\4yBx\br3Sl.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\4yBx\PurPDfKeeDvp_IIQ.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\4yBx\zfiVS.png.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\4yBx\Zu7sT8ob.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\o-Fi.mp3.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\SiBTVIHwNwSnLAsEiaZs.m4a.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\z4jiZg.mp3.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\9y41-fr3PlkYnrNFG2e\FqOJo-o8.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\9y41-fr3PlkYnrNFG2e\RaqZQNwTN3mbA0F.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\9y41-fr3PlkYnrNFG2e\VqltAk\Dzl1T_E T7Ch1n.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\9y41-fr3PlkYnrNFG2e\VqltAk\xC-u2wjwqhihKd-.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\9y41-fr3PlkYnrNFG2e\VqltAk\5B1wK SInIEY1XG8\g y7h-Rew.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\9y41-fr3PlkYnrNFG2e\VqltAk\5B1wK SInIEY1XG8\lPn_fXiKChTLMv.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\9y41-fr3PlkYnrNFG2e\VqltAk\5B1wK SInIEY1XG8\o7Ic1-IjCq FQjq1.mp3.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\9y41-fr3PlkYnrNFG2e\VqltAk\LFHpZh3EGDvVG\7xXZSvgm4j.m4a.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\Gsdux_nrV\4Nap.mp3.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\CvIf.swf.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\K7frokp1X.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\cEUdy Q8gkA4LqZQF.avi.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\jjcfaQYy1u4aYRF.flv.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\ZuoadzcT-CGAX7.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\13_UhdLxbGNJHYgey\0opQH4AAr9-8.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\13_UhdLxbGNJHYgey\4NRYueZu34oKrb1iEn.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\13_UhdLxbGNJHYgey\7LaZ6FmIScNU.swf.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\13_UhdLxbGNJHYgey\_S_HmVM73NsxZnk99.swf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\13_UhdLxbGNJHYgey\5DFJaZ09zxpj\jtVwtSRgZQhn.swf.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\13_UhdLxbGNJHYgey\5DFJaZ09zxpj\Z9A0N 7.mkv.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\aUIpFDwEiCcpzrSkPaW0\Ze2.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\wmEX\4DOO7h9IdbHgOJ L.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\wmEX\WVzot.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\mrC2\wmEX\z 7ggJ8\t7GuLdHOG.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\283NpHh8_ly2.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\4fnqeRI1O.pptx.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\aIJExqDF7Y-Vj3MR.docx.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\bx_sreHB6g Fc-Lx.xlsx.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\eh9nFqOb33ZYsx1OOIH.docx.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\lwhJgzvsl5XlQcrqU6.xlsx.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows\System32\drivers\etc\host | Dropped File | Text |
Not Queried
|
...
|
»