VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Wiper
|
Threat Names: |
Trojan.GenericKD.40847411
Gen:Trojan.Heur.RP.mmX@aGh0Tpc
Mal/Generic-S
|
win_defender_patch.exe
Windows Exe (x86-32)
Created at 2020-02-12T14:47:00
Remarks
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\win_defender_patch.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x402e5e |
Size Of Code | 0x1000 |
Size Of Initialized Data | 0x800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2010-12-09 18:58:13+00:00 |
Version Information (11)
»
Assembly Version | 1.0.0.0 |
Comments | - |
CompanyName | - |
FileDescription | ransom102 |
FileVersion | 1.0.0.0 |
InternalName | win_defender_patch.exe |
LegalCopyright | Copyright © 2018 |
LegalTrademarks | - |
OriginalFilename | win_defender_patch.exe |
ProductName | ransom102 |
ProductVersion | 1.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0xe64 | 0x1000 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.29 |
.rsrc | 0x404000 | 0x29af4 | 0x29c00 | 0x1200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.53 |
.reloc | 0x42e000 | 0xc | 0x200 | 0x2ae00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.58 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x2e34 | 0x1034 | 0x0 |
Memory Dumps (34)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
win_defender_patch.exe | 1 | 0x00060000 | 0x0008FFFF | Relevant Image |
![]() |
64-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x7FFBB9B5F000 | 0x7FFBB9B5FFFF | First Execution |
![]() |
64-bit | 0x7FFBB9B5F060 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FFBB9B6E000 | 0x7FFBB9B6EFFF | First Execution |
![]() |
64-bit | 0x7FFBB9B6E040 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FFBB9BAD000 | 0x7FFBB9BADFFF | First Execution |
![]() |
64-bit | 0x7FFBB9BAD2C5 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FFBB9B5F000 | 0x7FFBB9B5FFFF | Content Changed |
![]() |
64-bit | 0x7FFBB9B5F4C0 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FFBB9CC3000 | 0x7FFBB9CC3FFF | First Execution |
![]() |
64-bit | 0x7FFBB9CC3032 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FFBB9CC4000 | 0x7FFBB9CC4FFF | First Execution |
![]() |
64-bit | 0x7FFBB9CC4000 |
![]() |
![]() |
...
|
buffer | 1 | 0x1AF12000 | 0x1AF13FFF | First Execution |
![]() |
64-bit | 0x1AF1359C |
![]() |
![]() |
...
|
buffer | 1 | 0x7FFBB9CC5000 | 0x7FFBB9CC5FFF | First Execution |
![]() |
64-bit | 0x7FFBB9CC5040 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FFBB9CC6000 | 0x7FFBB9CC6FFF | First Execution |
![]() |
64-bit | 0x7FFBB9CC6000 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FFBB9CC7000 | 0x7FFBB9CC7FFF | First Execution |
![]() |
64-bit | 0x7FFBB9CC7012 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FFBB9CC8000 | 0x7FFBB9CC8FFF | First Execution |
![]() |
64-bit | 0x7FFBB9CC8060 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FFBB9CC5000 | 0x7FFBB9CC5FFF | Content Changed |
![]() |
64-bit | 0x7FFBB9CC5740 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FFBB9CC8000 | 0x7FFBB9CC8FFF | Content Changed |
![]() |
64-bit | 0x7FFBB9CC8760 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FFBB9CC3000 | 0x7FFBB9CC3FFF | Content Changed |
![]() |
64-bit | 0x7FFBB9CC31A0 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FFBB9B6E000 | 0x7FFBB9B6EFFF | Content Changed |
![]() |
64-bit | 0x7FFBB9B6E200 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FFBB9CC4000 | 0x7FFBB9CC4FFF | Content Changed |
![]() |
64-bit | 0x7FFBB9CC4080 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FFBB9CC6000 | 0x7FFBB9CC6FFF | Content Changed |
![]() |
64-bit | 0x7FFBB9CC6000 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FFBB9CC7000 | 0x7FFBB9CC7FFF | Content Changed |
![]() |
64-bit | 0x7FFBB9CC75E0 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FFBB9B5F000 | 0x7FFBB9B5FFFF | Content Changed |
![]() |
64-bit | 0x7FFBB9B5F390 |
![]() |
![]() |
...
|
buffer | 1 | 0x1AF12000 | 0x1AF13FFF | Content Changed |
![]() |
64-bit | 0x1AF1395C |
![]() |
![]() |
...
|
buffer | 1 | 0x7FFBB9CC8000 | 0x7FFBB9CC8FFF | Content Changed |
![]() |
64-bit | 0x7FFBB9CC8060 |
![]() |
![]() |
...
|
buffer | 1 | 0x1AF12000 | 0x1AF13FFF | Content Changed |
![]() |
64-bit | 0x1AF1331C |
![]() |
![]() |
...
|
buffer | 1 | 0x1AF12000 | 0x1AF13FFF | Content Changed |
![]() |
64-bit | 0x1AF134AC |
![]() |
![]() |
...
|
buffer | 1 | 0x1AF12000 | 0x1AF13FFF | Content Changed |
![]() |
64-bit | 0x1AF1395C |
![]() |
![]() |
...
|
buffer | 1 | 0x1AF12000 | 0x1AF13FFF | Content Changed |
![]() |
64-bit | 0x1AF1390C |
![]() |
![]() |
...
|
buffer | 1 | 0x1AF12000 | 0x1AF13FFF | Content Changed |
![]() |
64-bit | 0x1AF132CC |
![]() |
![]() |
...
|
buffer | 1 | 0x1AF12000 | 0x1AF13FFF | Content Changed |
![]() |
64-bit | 0x1AF139FC |
![]() |
![]() |
...
|
buffer | 1 | 0x1AF12000 | 0x1AF13FFF | Content Changed |
![]() |
64-bit | 0x1AF1395C |
![]() |
![]() |
...
|
buffer | 1 | 0x1AF12000 | 0x1AF13FFF | Content Changed |
![]() |
64-bit | 0x1AF139AC |
![]() |
![]() |
...
|
buffer | 1 | 0x1AF12000 | 0x1AF13FFF | Content Changed |
![]() |
64-bit | 0x1AF1331C |
![]() |
![]() |
...
|
buffer | 1 | 0x1AF12000 | 0x1AF13FFF | Content Changed |
![]() |
64-bit | 0x1AF1363C |
![]() |
![]() |
...
|
buffer | 1 | 0x1AF12000 | 0x1AF13FFF | Content Changed |
![]() |
64-bit | 0x1AF136DC |
![]() |
![]() |
...
|
win_defender_patch.exe | 1 | 0x00060000 | 0x0008FFFF | Final Dump |
![]() |
64-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.40847411 |
Malicious
|
C:\Users\FD1HVy\Documents\My Shapes\_private\folder.ico.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\My Shapes\desktop.ini.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\My Shapes\Favorites.vssx.ransomwared | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Outlook Files\kkcie@kdj.kd.pst.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\7XGbk\crCsyzN5avBbuC5bDWf.pdf.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\7XGbk\N78-QcS1Joj.docx.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\INIgt\Byda6h\tto_zn8Uh_1NDP.odt.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\S1wzbxNL_B\luDXTi5Q\9zb2HGJTpIU_7\N_cdRqtHgh\-Yu2RSl8JEEYJiFx3DY\-APfvmlspgiB8RX.odp.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\S1wzbxNL_B\luDXTi5Q\9zb2HGJTpIU_7\N_cdRqtHgh\-Yu2RSl8JEEYJiFx3DY\2Aimn35nKmezuGr.doc.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\S1wzbxNL_B\luDXTi5Q\9zb2HGJTpIU_7\N_cdRqtHgh\-Yu2RSl8JEEYJiFx3DY\iOumP2HnuR2F.ots.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\S1wzbxNL_B\luDXTi5Q\9zb2HGJTpIU_7\N_cdRqtHgh\-Yu2RSl8JEEYJiFx3DY\K_5_jrx-8-isieynku6X.ots.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\S1wzbxNL_B\luDXTi5Q\9zb2HGJTpIU_7\N_cdRqtHgh\K0VW1WQFVjR8fMBi.csv.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\S1wzbxNL_B\luDXTi5Q\9zb2HGJTpIU_7\N_cdRqtHgh\PApig57HAP-Uw5Qy36.odp.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\S1wzbxNL_B\luDXTi5Q\9zb2HGJTpIU_7\_ZzrYZcG\8cvh.doc.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\S1wzbxNL_B\luDXTi5Q\9zb2HGJTpIU_7\_ZzrYZcG\NAPIG.pptx.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\S1wzbxNL_B\luDXTi5Q\9zb2HGJTpIU_7\C3-yA UdB3mx3hvj.doc.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\S1wzbxNL_B\luDXTi5Q\9zb2HGJTpIU_7\ccZastJX0mHvkvE.odp.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\S1wzbxNL_B\luDXTi5Q\9zb2HGJTpIU_7\elY-cYq98RtqHyzYUO.ots.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\S1wzbxNL_B\luDXTi5Q\9zb2HGJTpIU_7\F7EJNN.odt.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\S1wzbxNL_B\luDXTi5Q\9zb2HGJTpIU_7\Qtcut.pdf.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\S1wzbxNL_B\luDXTi5Q\9zb2HGJTpIU_7\sfV7v98.ots.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\S1wzbxNL_B\luDXTi5Q\9zb2HGJTpIU_7\y3y9QwhE0 YoU.pptx.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\S1wzbxNL_B\luDXTi5Q\61JzOvre4ufxxj.pps.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\S1wzbxNL_B\luDXTi5Q\dtgbey_CgJ2cZuVj2.pptx.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\S1wzbxNL_B\luDXTi5Q\FEjvRcgDTq_Eo.xls.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\S1wzbxNL_B\luDXTi5Q\l6Vsn1TpXI6uBqjm0q-t.pps.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\S1wzbxNL_B\0Rx390uuE.csv.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\S1wzbxNL_B\AgQwldA.xls.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\usMgSDmIAeKXugMpTAe6.xls.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\uVoV.pptx.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\Y6KlM2ZVZsyCRz_1vvOp.docx.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vS68yQsYzmxMk\zErHVeZXsZnEF.xlsx.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\3JAFdEs6V.docx.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\6hsTt6A7ij hwzKz2fG.docx.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\8CRbU2risAC1g.xls.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\B0aV2x.xls.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Database1.accdb.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\desktop.ini.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\evAzGp.pptx.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\exB85KdJ2eMlfoQ.xls.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\fTaG7fzmNL7O-NP.xlsx.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\IHQT.pptx.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\iKXGagjDCQKQ5Yv0c7b.xlsx.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\i_DDSIreB3Lq 9.docx.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nwtXBWqKvm.xlsx.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\obVTmDCc85_zPs.pptx.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\PnJT.doc.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\pV93pvxhBtblwilkx.docx.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\QrU_aeXE.pptx.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Q_YU5u6k2YIStFjTi2yJ.odt.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\RQICtNNu0kLkqw f7YmR.pptx.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\TDUzPt1.docx.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\xPRIBcH.xlsx.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\ZNgiGj2xtRMY4KyJ.ots.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\919foinTXZU\B oPNRLAj.bmp.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\919foinTXZU\dyjUBfiVuB3VwaL2S2.png.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\919foinTXZU\G5TJQh.png.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\919foinTXZU\m3G-X9yd.jpg.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\919foinTXZU\NVT8c.jpg.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\919foinTXZU\nzhgQUJ-Y1wF35iiuL2.bmp.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\919foinTXZU\SuinnHSza-AhY4tr.jpg.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\919foinTXZU\Wca7Qy.jpg.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\919foinTXZU\xxKgfYIasF.gif.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\919foinTXZU\YrIIQgrv.gif.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\laEzvODaxxcP\Cl2UpBOEjN9 VCuWJ\wWlbVPYHJkQCO2x\bkVFco06qWKZ.png.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\laEzvODaxxcP\Cl2UpBOEjN9 VCuWJ\wWlbVPYHJkQCO2x\nCA1KwhrEZxH53jzPHM.png.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\laEzvODaxxcP\Cl2UpBOEjN9 VCuWJ\wWlbVPYHJkQCO2x\nlViqiOs-WuYui.png.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\laEzvODaxxcP\Cl2UpBOEjN9 VCuWJ\wWlbVPYHJkQCO2x\sk90TAOxs1.bmp.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\laEzvODaxxcP\Cl2UpBOEjN9 VCuWJ\wWlbVPYHJkQCO2x\sxbiw.bmp.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\laEzvODaxxcP\Cl2UpBOEjN9 VCuWJ\wWlbVPYHJkQCO2x\VtCYAzbgvh4U.bmp.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\laEzvODaxxcP\Cl2UpBOEjN9 VCuWJ\wWlbVPYHJkQCO2x\Y96md2FTbT.gif.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\laEzvODaxxcP\Cl2UpBOEjN9 VCuWJ\BVECeD.gif.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\laEzvODaxxcP\Cl2UpBOEjN9 VCuWJ\cruYVtp2KYSwwT_LF8H.gif.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\laEzvODaxxcP\Cl2UpBOEjN9 VCuWJ\S0A1B5a.jpg.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\laEzvODaxxcP\Cl2UpBOEjN9 VCuWJ\wDPt -blRmOK3Yrr9gXD.jpg.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\laEzvODaxxcP\Cl2UpBOEjN9 VCuWJ\XgX5 rV0yIB1.jpg.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\laEzvODaxxcP\3hjwETOj iWYW.png.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\laEzvODaxxcP\7QULv.jpg.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\laEzvODaxxcP\G6Cj.jpg.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\laEzvODaxxcP\hD8VP9UHlbhHxmhluuyH.jpg.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\laEzvODaxxcP\HwLAMOVYPpI.gif.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\laEzvODaxxcP\QZ48z4RDprjty.png.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\laEzvODaxxcP\UEF5ozYaHFl3z.bmp.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\laEzvODaxxcP\URlBJQmL1Vmw--2W.bmp.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\laEzvODaxxcP\vMSlf4.jpg.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Saved Pictures\desktop.ini.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\C5pt1-vJcZ-Rx8q.png.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\desktop.ini.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\FRq15h.png.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\HzCtWSyb1veb.gif.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\J17m3SmlgJ1a6 Il1B2.png.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Xi_gn9udVUTgJ3A xf.bmp.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\_ZsMMydrW2r5ZiFW5W.bmp.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\2bI0Kk.mkv.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\2sN0b5QjkoMUxfT.mp4.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\4SC2hoS5Y8ati -.mkv.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\7vCo7mjT4BO6wyX7cmY.swf.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\desktop.ini.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\do1ZdrgKsS62L-a_bRu.avi.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\FZcaDvO6qItm8UkdHA.flv.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\jcIEvPGfE6dSa1v.mkv.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\LFaxXfB6k.swf.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\MCIhGUmD5ZpncI-g_Z.swf.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ngSkQJWdEQrT-nqaR.avi.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\noFDCPT-L8Efi.flv.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\odMBS tbdWkv.flv.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\OTJR JQb.flv.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\rF0y6Y.mkv.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\rpBW-LBEaDoTIgy3lRU.avi.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\RRrRCZsd2-mEAunS-jg.mp4.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\RSWBseXuoSjR VBjAyR.mp4.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\RyQ3aY_u7.avi.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\Smgx-iqF.mkv.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\V91ee-UZpqGTpy.mkv.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YD1Mg17VSvrsQ8ePN_sX.mkv.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\yGtMG8cQt_AG3e.mp4.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ynbDl8beDnAm48.mp4.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\zDJCbqsVWZgbx.mp4.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\_3pySX0EeOA.mkv.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\BCpy0hpS4N-J-d3Fubes\12ZxW.m4a.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\BCpy0hpS4N-J-d3Fubes\8F_ijqn0rUDvA6-hP.mp3.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\BCpy0hpS4N-J-d3Fubes\8_funD-wLnAqegM-f9.m4a.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\BCpy0hpS4N-J-d3Fubes\9fE5_.mp3.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\BCpy0hpS4N-J-d3Fubes\e7aJDthWxNP.wav.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\BCpy0hpS4N-J-d3Fubes\EgdxWZTmW.m4a.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\BCpy0hpS4N-J-d3Fubes\FXbnw4KUpn6r.mp3.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\BCpy0hpS4N-J-d3Fubes\HdB_.wav.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\CCmFQddL\3TmG UytC.m4a.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\CCmFQddL\6o94UX.m4a.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\CCmFQddL\A5yT1PXy8eU.mp3.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\CCmFQddL\cUkYuq 9rrpUmS-S.m4a.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\CCmFQddL\jqwKRVHvtgV.mp3.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\CCmFQddL\KKe2Omq4m79BPs8P0EM.mp3.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\CCmFQddL\szvkYxEO3.m4a.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\CCmFQddL\tEb.m4a.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\CCmFQddL\urv87.mp3.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\CCmFQddL\w8QW_uxT3eqE9COJ.mp3.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\hVYBQZBDB1Q5KBS6JZM8\88SOegvNVTJ_ j.mp3.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\hVYBQZBDB1Q5KBS6JZM8\F7sGv1gjY.mp3.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\hVYBQZBDB1Q5KBS6JZM8\j-okeUH7L996o7mcrF.wav.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\S8cFZ9KDV3SCw\JI4mL6I7Pgskw.m4a.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\S8cFZ9KDV3SCw\tgki6aU3.m4a.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\S8cFZ9KDV3SCw\ue3M.mp3.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\S8cFZ9KDV3SCw\W c-htOST9KuSC.wav.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\0Lt4Kt2p.mp3.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\desktop.ini.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\dI8Gj60 lrYz.mp3.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\LlgHNg RY7Q.m4a.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\maw0SMQmZzJY.mp3.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\Uc8pYpnwZ.m4a.ransomwared | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\5jNv-FlECUDOVXEaa-.xlsx.ransomwared | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\Camera Roll\desktop.ini.ransomwared | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\xQwqMDuqvoSGT-fnsT.flv.ransomwared | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\3JAFdEs6V.docx | Dropped File | Unknown |
Not Queried
|
...
|
»