VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Dropper |
WindowsFormsApp.exe
Windows Exe (x86-32)
Created at 2019-12-01T08:30:00
Remarks
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\AppData\Local\TempASD456.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x405876 |
Size Of Code | 0x3a00 |
Size Of Initialized Data | 0x800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2045-06-16 21:09:22+00:00 |
Version Information (11)
»
Assembly Version | 1.0.0.0 |
Comments | - |
CompanyName | Microsoft |
FileDescription | ZZZZZZZZZZ |
FileVersion | 1.0.0.0 |
InternalName | ZZZZZZZZZZ.exe |
LegalCopyright | Copyright © Microsoft 2019 |
LegalTrademarks | - |
OriginalFilename | ZZZZZZZZZZ.exe |
ProductName | ZZZZZZZZZZ |
ProductVersion | 1.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x3884 | 0x3a00 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.38 |
.rsrc | 0x406000 | 0x5e0 | 0x600 | 0x3c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.15 |
.reloc | 0x408000 | 0xc | 0x200 | 0x4200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.08 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x584b | 0x3a4b | 0x0 |
Memory Dumps (9)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
tempasd456.exe | 4 | 0x00490000 | 0x00499FFF | Relevant Image | - | 64-bit | - |
![]() |
![]() |
...
|
buffer | 4 | 0x7FF8B2C6E000 | 0x7FF8B2C6EFFF | First Execution | - | 64-bit | 0x7FF8B2C6E040 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FF8B2DC1000 | 0x7FF8B2DC1FFF | First Execution | - | 64-bit | 0x7FF8B2DC1040 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FF8B2D71000 | 0x7FF8B2D72FFF | First Execution | - | 64-bit | 0x7FF8B2D71000 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FF8B2D71000 | 0x7FF8B2D72FFF | Content Changed | - | 64-bit | 0x7FF8B2D72354 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FF8B2DC1000 | 0x7FF8B2DC1FFF | Content Changed | - | 64-bit | 0x7FF8B2DC1200 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FF8B2C5F000 | 0x7FF8B2C5FFFF | First Execution | - | 64-bit | 0x7FF8B2C5F000 |
![]() |
![]() |
...
|
buffer | 4 | 0x7FF8B2C6E000 | 0x7FF8B2C6EFFF | Content Changed | - | 64-bit | 0x7FF8B2C6E740 |
![]() |
![]() |
...
|
tempasd456.exe | 4 | 0x00490000 | 0x00499FFF | Process Termination | - | 64-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Ransom.RTH.1 |
Malicious
|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4057b2 |
Size Of Code | 0x3800 |
Size Of Initialized Data | 0x3e00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-11-30 10:45:34+00:00 |
Version Information (11)
»
Assembly Version | 1.0.0.0 |
Comments | - |
CompanyName | Microsoft |
FileDescription | WindowsFormsApp |
FileVersion | 1.0.0.0 |
InternalName | WindowsFormsApp.exe |
LegalCopyright | Copyright © Microsoft 2019 |
LegalTrademarks | - |
OriginalFilename | WindowsFormsApp.exe |
ProductName | WindowsFormsApp |
ProductVersion | 1.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x37b8 | 0x3800 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.81 |
.reloc | 0x406000 | 0xc | 0x200 | 0x3a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.08 |
.rsrc | 0x408000 | 0x5fc | 0x600 | 0x3c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.22 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x5780 | 0x3980 | 0x0 |
Memory Dumps (15)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
windowsformsapp.exe | 1 | 0x00B40000 | 0x00B49FFF | Relevant Image | - | 64-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF8B2C7E000 | 0x7FF8B2C7EFFF | First Execution | - | 64-bit | 0x7FF8B2C7E040 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF8B2DD1000 | 0x7FF8B2DD1FFF | First Execution | - | 64-bit | 0x7FF8B2DD1040 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF8B2DD1000 | 0x7FF8B2DD1FFF | Content Changed | - | 64-bit | 0x7FF8B2DD1200 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF8B2DD2000 | 0x7FF8B2DD2FFF | First Execution | - | 64-bit | 0x7FF8B2DD2000 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF8B2DD3000 | 0x7FF8B2DD3FFF | First Execution | - | 64-bit | 0x7FF8B2DD3012 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF8B2DD4000 | 0x7FF8B2DD4FFF | First Execution | - | 64-bit | 0x7FF8B2DD4000 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF8B2DD5000 | 0x7FF8B2DD5FFF | First Execution | - | 64-bit | 0x7FF8B2DD5040 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF8B2DD5000 | 0x7FF8B2DD5FFF | Content Changed | - | 64-bit | 0x7FF8B2DD5660 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF8B2C7E000 | 0x7FF8B2C7EFFF | Content Changed | - | 64-bit | 0x7FF8B2C7E900 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF8B2DD6000 | 0x7FF8B2DD6FFF | First Execution | - | 64-bit | 0x7FF8B2DD6000 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF8B2DD7000 | 0x7FF8B2DD7FFF | First Execution | - | 64-bit | 0x7FF8B2DD7012 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF8B2DD6000 | 0x7FF8B2DD6FFF | Content Changed | - | 64-bit | 0x7FF8B2DD6E00 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF8B2DD7000 | 0x7FF8B2DD7FFF | Content Changed | - | 64-bit | 0x7FF8B2DD70A0 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF8B2DD7000 | 0x7FF8B2DD7FFF | Content Changed | - | 64-bit | 0x7FF8B2DD7420 |
![]() |
![]() |
...
|
C:\Users\FD1HVy\Documents\00vc3ZeG.pptx.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\3W6nGyo.xlsx.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\4yEKY9UOF.ots.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\50SeAj-Ow9DeKWSLKf.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\ADDet5-.docx.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Database1.accdb.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\EO9HpA s.ods | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\g6gxVFNVocJH2XB.xlsx.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\H3npF0Nkg3TdH5f.xlsx.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\HcqDOqW9cZw3ucwd G.docx.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\hDp5LTqmWqg Mws8_kCe.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\sypVKZze0LMeW1jb.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\T-ACSLEotuq1g6T.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\to1-tRoZzPiQmCsxyiqn.pptx.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\YH3D-7WIGSkNN.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\ky-GANm.pps | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\V4sRuhMfpE4j_aihCvt.ppt.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\wr7wvTCuImG-zL-.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\Zv7QcooRqBYuIZhPhca.odt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\cU3TmZ50J6NyJK\ePUy7eTbuWQopyqUkXPD.pps | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\cU3TmZ50J6NyJK\0qpfzrX5zTx273Cjuz\bcuTEx.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\cU3TmZ50J6NyJK\0qpfzrX5zTx273Cjuz\H0aN.pps | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\cU3TmZ50J6NyJK\0qpfzrX5zTx273Cjuz\KTA qRNQc.odt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\cU3TmZ50J6NyJK\fj8bkEnd\-nYY2.odp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\cU3TmZ50J6NyJK\fj8bkEnd\IFWMCJWu4B2S7.ots | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\cU3TmZ50J6NyJK\fj8bkEnd\phFn5IfsgpHBbOI.xls.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\cU3TmZ50J6NyJK\fj8bkEnd\Xk3-Oa GJpX l.odp.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\ZIfsnA9y\4M2JM.pdf.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\ZIfsnA9y\hFwg0t\BAAyQGPYWQ4xD6qj.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\ZIfsnA9y\hFwg0t\cOmpAzW-a77B3.csv.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\ZIfsnA9y\hFwg0t\qAZkLd2u6EVl.docx.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\ZIfsnA9y\hFwg0t\ZIUi.odp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\ZIfsnA9y\hFwg0t\RN8rm9j75C0Sthx\cUMc3NULiSvMs.xlsx.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\K6k6CG5uk\4MhQ2V.ots.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\K6k6CG5uk\Ll0czXrpNwsB.pdf.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\K6k6CG5uk\zhXP6telS73ExJ2.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\K6k6CG5uk\eVi2mJFNSEaZLWq7\2lai_JiPC3.csv.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\K6k6CG5uk\eVi2mJFNSEaZLWq7\aj5Kv5yQa6jUTrm.ots.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\K6k6CG5uk\eVi2mJFNSEaZLWq7\DIyTB.ots.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\K6k6CG5uk\eVi2mJFNSEaZLWq7\ispkv h.odt.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\K6k6CG5uk\eVi2mJFNSEaZLWq7\NIZAwZUmscst6fN3uB.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\K6k6CG5uk\eVi2mJFNSEaZLWq7\QBMa711Q_ps3qgi2knI.ots | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\K6k6CG5uk\eVi2mJFNSEaZLWq7\yoVIOjTcld88W N.ppt.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Outlook Files\kkcie@kdj.kd.pst | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\2Ma0bW3.bmp.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\4AdR9kWbyqs0iV.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\6fU25 2zvpahn0YDQ.jpg.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\7iJsvuW.png.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\9LWRZwBy38CsMhp7FY.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\APZV8i.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\bfojn0wFS.bmp.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\BM9Z_MTiG.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\cJVKUyZ.jpg.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\CQ3z13b5X3CATi4gC.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\cYWZlRGO63WdlS.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Dhd1LElN82Xjx1FfA.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\dQD opifuG23MssEda.bmp.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Etws.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\G1US14_-f.gif.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\GKT83dkZdOom ERIvEk.png.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\HsZcPm7-Q3j8-e2.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\iAw4o-n-1RHWx55.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Iqtih3oHTT-q5xVHqh9w.bmp.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\j-V_jbo4BzcG_.png.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\lqt7Cp3HR.gif.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\mBW74.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\PecAUp1uO_OIqX.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Q0I1Q8_f.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Qr4Y _IXPc-TIE1EKmZS.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\S-iq7eetmvzM5Rp9YN-.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\XK9MyNa.bmp.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\XX-OboBNp_mjsgRb.png.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Ycl 05RnKioy.gif.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\zahn.png.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\ZkH-GwPYPEm6HLtRunK.bmp.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\_Kz9T0qY.bmp.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\-1LnUiCf8okN.ots.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\7vWSmB6BKB4.wav.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\9Cy2tZm4GPi02D6qqR.jpg.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\aQI9eMv5I.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\f5tImEhMDOGuv4fsE9.xlsx.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\HNlyjKgsBo.ots | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\JXD6JatboaO.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\mAJA8djcqEsPOiW.swf.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\omvs3W3r 4bZqNNPjC.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\pfJnaC_IonhR.doc.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\pN6SrSzjYKJ JZvFe6.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\QkEd91rWFi.ppt.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\VGhJgg.jpg.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\WDknjtNEwQnHAZcqX.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\X1unlDtfDT2-.wav.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\x68w.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\XeypaAbauUXW08PqZ.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Xg8fau44HD7Oc.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Y7S2xbgkKLL7qNyo3UyS.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\ybfbn3EBWNB3-CfK.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\ZGCC7t.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\_bPRIsb4rv.avi.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\blaxQc1yu2cfocX\7n9 vTYriiDZpcEM3D.xlsx.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\blaxQc1yu2cfocX\bewkkdf8jnD.xls.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\blaxQc1yu2cfocX\MX8XrsZr-.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\blaxQc1yu2cfocX\nfDYc7kQejrR5.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\blaxQc1yu2cfocX\zHob3qYFNDyj2H hjkz.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\ZegmFR.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\frH9Fz9oi3HMebqt6wsX\ov-MO4rxjBorCXU.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\frH9Fz9oi3HMebqt6wsX\siqZMQgwkX.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\frH9Fz9oi3HMebqt6wsX\ssngNSVO7gJdoZAM.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\frH9Fz9oi3HMebqt6wsX\6ZF-q3r9I1-f2XH\7rLtTLq.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\frH9Fz9oi3HMebqt6wsX\6ZF-q3r9I1-f2XH\nyVDi\av2l6lbhJL.mp3.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\frH9Fz9oi3HMebqt6wsX\6ZF-q3r9I1-f2XH\nyVDi\p 6l yylS.mp3.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\frH9Fz9oi3HMebqt6wsX\6ZF-q3r9I1-f2XH\nyVDi\SrQ4oCmb HHloXtcZMj\9vkgbv.wav.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\frH9Fz9oi3HMebqt6wsX\6ZF-q3r9I1-f2XH\nyVDi\SrQ4oCmb HHloXtcZMj\GGV3b3PKqSlWl3gf.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\frH9Fz9oi3HMebqt6wsX\6ZF-q3r9I1-f2XH\nyVDi\SrQ4oCmb HHloXtcZMj\gIZQT.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\frH9Fz9oi3HMebqt6wsX\6ZF-q3r9I1-f2XH\nyVDi\SrQ4oCmb HHloXtcZMj\p7PKn0-li.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\frH9Fz9oi3HMebqt6wsX\6ZF-q3r9I1-f2XH\nyVDi\SrQ4oCmb HHloXtcZMj\YdDsJeA2mBYS3jVF.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\frH9Fz9oi3HMebqt6wsX\6ZF-q3r9I1-f2XH\nyVDi\SrQ4oCmb HHloXtcZMj\HcYBWfBr__j\APhrB6FDu5ZDSC.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\frH9Fz9oi3HMebqt6wsX\6ZF-q3r9I1-f2XH\nyVDi\SrQ4oCmb HHloXtcZMj\HcYBWfBr__j\HiYny3Kvo.wav.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\frH9Fz9oi3HMebqt6wsX\6ZF-q3r9I1-f2XH\nyVDi\SrQ4oCmb HHloXtcZMj\HcYBWfBr__j\KmAyVhqvbgJvQN.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\frH9Fz9oi3HMebqt6wsX\6ZF-q3r9I1-f2XH\nyVDi\SrQ4oCmb HHloXtcZMj\HcYBWfBr__j\pvc5kFS7FP.wav.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\qr2G0VH-cq\8Bqd\WRJAvK-ek.mp3.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\qr2G0VH-cq\8Bqd\8iQcXK\EYCg.mp3.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\qr2G0VH-cq\8Bqd\8iQcXK\UxQy7FE4qhE4AI98Tj.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\qr2G0VH-cq\8Bqd\8iQcXK\WJHxbJkFSJB-jsRycE.mp3.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\qr2G0VH-cq\8Bqd\NYqVdYVwhWIOG9Lh\i9awAGSurvWr4.wav.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\qr2G0VH-cq\8Bqd\NYqVdYVwhWIOG9Lh\WMxuKoUuLyhkh5n.wav.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\axxIfVZrpO.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\vFUWlER9vfMMJQCq4s1S.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\_yB-fJh0THH68Oj Jtje.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eYZ2scoN\-HKw82WOyesONewn6.flv.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eYZ2scoN\11K2ue1u.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eYZ2scoN\KyrpRLl6BP.flv.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eYZ2scoN\Ln7QT39m.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eYZ2scoN\nBgTUZWKhhZtgVF.avi.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eYZ2scoN\pKMOs4i6NdHj0Yj.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eYZ2scoN\s1 9B-.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eYZ2scoN\sJm1-x05krpbI.flv.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eYZ2scoN\t5tV35u-tPTe.swf.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eYZ2scoN\9zPMzLRTzg16y4k\6JgZ83dq_ngSd.mkv.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eYZ2scoN\9zPMzLRTzg16y4k\SKy9FRrI.mkv.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eYZ2scoN\NB TC\-Pvd1-hu2R78xL4q.mkv.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eYZ2scoN\NB TC\9aCv_DUXRO1H1v.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eYZ2scoN\NB TC\valdXzW.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eYZ2scoN\OYYrNMBLBIX\L8MNt1neWEdWDpkAH.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eYZ2scoN\OYYrNMBLBIX\zQ-MvH5rERnOxzdsPCB\cdw_j48W4_.mkv.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eYZ2scoN\OYYrNMBLBIX\zQ-MvH5rERnOxzdsPCB\dM2GCHlJzBQJ.mkv.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eYZ2scoN\OYYrNMBLBIX\zQ-MvH5rERnOxzdsPCB\O_AKu.swf.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eYZ2scoN\OYYrNMBLBIX\zQ-MvH5rERnOxzdsPCB\RZ0PV.swf.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eYZ2scoN\OYYrNMBLBIX\zQ-MvH5rERnOxzdsPCB\zflSIuDc3FDEXw6.avi.TR | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\Nr4OSaGng_0Mu9\A-lI1GdhpYgBTaBCRfcY.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\Nr4OSaGng_0Mu9\qkwR2oFGp.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\Nr4OSaGng_0Mu9\we13PwIm8.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\front_view.vbs | Dropped File | Text |
Unknown
|
...
|
»
c:\users\fd1hvy\desktop\dosyalarını kurtarmak İstiyorsan oku!!!.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\ktQu.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\lL65rC5s5BF-.pptx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\spmgtbVC.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\ZpQEg9eoz4uiVn9.ots | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\cU3TmZ50J6NyJK\IC gOEt3M2m3VDZlB2.csv.TR | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\ZIfsnA9y\emT7qS98GbaRBn.ods | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\ZIfsnA9y\LOfpdHEsuSlSq.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\ZIfsnA9y\hFwg0t\D4WGVW.ods.TR | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\ZIfsnA9y\hFwg0t\YrDEfL.odt.TR | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\CUDCejyoavltwr0x\ZIfsnA9y\hFwg0t\RN8rm9j75C0Sthx\3prl.ots.TR | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\K6k6CG5uk\eVi2mJFNSEaZLWq7\EvFzg_E-Kz.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\0SSME.bmp.TR | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\8jAvZFkV.bmp.TR | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\Gikq17V20.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\HSvcD3CP0SSrxULqPC7c.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\qdnx8QRFG3f3vzD.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\Z9BRUCVTsgyY4ZNO.jpg.TR | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\0 yn-WovjxBTYp0D.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\0ZPB5Phdq6kUWJzUBBKh.jpg.TR | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\E3GmwgWX_IoPn.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\ibxRhwatjFUNdpz5Je.mkv.TR | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\L wYt-x_lCvytJM.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\Sp0AFRShwfM gmoTZ.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\blaxQc1yu2cfocX\hGm_3-Rq.pptx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\blaxQc1yu2cfocX\SspaZhH_7zb7.swf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\blaxQc1yu2cfocX\ZEPhcsKRnI.png.TR | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\DxRSecwbhW 6Hg2lsFX.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\frH9Fz9oi3HMebqt6wsX\6ZF-q3r9I1-f2XH\V3E-guaI2CPg.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\frH9Fz9oi3HMebqt6wsX\6ZF-q3r9I1-f2XH\nyVDi\SrQ4oCmb HHloXtcZMj\8UV50kwL5r.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\frH9Fz9oi3HMebqt6wsX\6ZF-q3r9I1-f2XH\nyVDi\SrQ4oCmb HHloXtcZMj\HcYBWfBr__j\UQGDfajSWb.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\eYZ2scoN\NB TC\x5G8n_s80pKyJBFxCy.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\Nr4OSaGng_0Mu9\nNYIO.mp4 | Modified File | Stream |
Not Queried
|
...
|
»