VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Generic.Ransom.Mole.E1C541BA
Generic.Ransom.Mole.F8AB5493
Generic.Ransom.Mole.82E5944A
...
|
cake4.exe
Windows Exe (x86-32)
Created at 2020-05-04T15:16:00
Remarks
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\cake4.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x42ad98 |
Size Of Code | 0x66000 |
Size Of Initialized Data | 0x2f600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-04-10 04:58:48+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x65ef1 | 0x66000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.75 |
.rdata | 0x467000 | 0x1fff4 | 0x20000 | 0x66400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.27 |
.data | 0x487000 | 0x738c | 0x4e00 | 0x86400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.71 |
.rsrc | 0x48f000 | 0x1128 | 0x1200 | 0x8b200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.21 |
.reloc | 0x491000 | 0x6e88 | 0x7000 | 0x8c400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.53 |
Imports (5)
»
KERNEL32.dll (143)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetEnvironmentVariableA | 0x0 | 0x46702c | 0x861cc | 0x855cc | 0x1db |
WaitForSingleObject | 0x0 | 0x467030 | 0x861d0 | 0x855d0 | 0x4f9 |
lstrcmpA | 0x0 | 0x467034 | 0x861d4 | 0x855d4 | 0x541 |
lstrcatA | 0x0 | 0x467038 | 0x861d8 | 0x855d8 | 0x53e |
GetCurrentThread | 0x0 | 0x46703c | 0x861dc | 0x855dc | 0x1c4 |
CreateThread | 0x0 | 0x467040 | 0x861e0 | 0x855e0 | 0xb5 |
lstrcmpW | 0x0 | 0x467044 | 0x861e4 | 0x855e4 | 0x542 |
GetEnvironmentVariableW | 0x0 | 0x467048 | 0x861e8 | 0x855e8 | 0x1dc |
lstrlenA | 0x0 | 0x46704c | 0x861ec | 0x855ec | 0x54d |
lstrcmpiW | 0x0 | 0x467050 | 0x861f0 | 0x855f0 | 0x545 |
FindFirstFileW | 0x0 | 0x467054 | 0x861f4 | 0x855f4 | 0x139 |
FindFirstFileExW | 0x0 | 0x467058 | 0x861f8 | 0x855f8 | 0x134 |
FindNextFileW | 0x0 | 0x46705c | 0x861fc | 0x855fc | 0x145 |
lstrlenW | 0x0 | 0x467060 | 0x86200 | 0x85600 | 0x54e |
FindClose | 0x0 | 0x467064 | 0x86204 | 0x85604 | 0x12e |
lstrcatW | 0x0 | 0x467068 | 0x86208 | 0x85608 | 0x53f |
lstrcpyW | 0x0 | 0x46706c | 0x8620c | 0x8560c | 0x548 |
InitializeCriticalSection | 0x0 | 0x467070 | 0x86210 | 0x85610 | 0x2e2 |
SetLastError | 0x0 | 0x467074 | 0x86214 | 0x85614 | 0x473 |
TerminateProcess | 0x0 | 0x467078 | 0x86218 | 0x85618 | 0x4c0 |
GetVersionExW | 0x0 | 0x46707c | 0x8621c | 0x8561c | 0x2a4 |
OpenProcess | 0x0 | 0x467080 | 0x86220 | 0x85620 | 0x380 |
CreateToolhelp32Snapshot | 0x0 | 0x467084 | 0x86224 | 0x85624 | 0xbe |
Process32NextW | 0x0 | 0x467088 | 0x86228 | 0x85628 | 0x398 |
Process32FirstW | 0x0 | 0x46708c | 0x8622c | 0x8562c | 0x396 |
CreateProcessW | 0x0 | 0x467090 | 0x86230 | 0x85630 | 0xa8 |
GetProcAddress | 0x0 | 0x467094 | 0x86234 | 0x85634 | 0x245 |
ReadFile | 0x0 | 0x467098 | 0x86238 | 0x85638 | 0x3c0 |
LeaveCriticalSection | 0x0 | 0x46709c | 0x8623c | 0x8563c | 0x339 |
SetEndOfFile | 0x0 | 0x4670a0 | 0x86240 | 0x85640 | 0x453 |
CreateFileW | 0x0 | 0x4670a4 | 0x86244 | 0x85644 | 0x8f |
GetLogicalDriveStringsW | 0x0 | 0x4670a8 | 0x86248 | 0x85648 | 0x208 |
SetFilePointerEx | 0x0 | 0x4670ac | 0x8624c | 0x8564c | 0x467 |
GetFileSize | 0x0 | 0x4670b0 | 0x86250 | 0x85650 | 0x1f0 |
GetDriveTypeW | 0x0 | 0x4670b4 | 0x86254 | 0x85654 | 0x1d3 |
SizeofResource | 0x0 | 0x4670b8 | 0x86258 | 0x85658 | 0x4b1 |
LockResource | 0x0 | 0x4670bc | 0x8625c | 0x8565c | 0x354 |
LoadLibraryW | 0x0 | 0x4670c0 | 0x86260 | 0x85660 | 0x33f |
LoadResource | 0x0 | 0x4670c4 | 0x86264 | 0x85664 | 0x341 |
FindResourceW | 0x0 | 0x4670c8 | 0x86268 | 0x85668 | 0x14e |
LockFile | 0x0 | 0x4670cc | 0x8626c | 0x8566c | 0x352 |
UnlockFile | 0x0 | 0x4670d0 | 0x86270 | 0x85670 | 0x4d4 |
GetThreadTimes | 0x0 | 0x4670d4 | 0x86274 | 0x85674 | 0x291 |
QueryPerformanceCounter | 0x0 | 0x4670d8 | 0x86278 | 0x85678 | 0x3a7 |
QueryPerformanceFrequency | 0x0 | 0x4670dc | 0x8627c | 0x8567c | 0x3a8 |
WriteConsoleW | 0x0 | 0x4670e0 | 0x86280 | 0x85680 | 0x524 |
SetStdHandle | 0x0 | 0x4670e4 | 0x86284 | 0x85684 | 0x487 |
GetProcessHeap | 0x0 | 0x4670e8 | 0x86288 | 0x85688 | 0x24a |
GetModuleFileNameW | 0x0 | 0x4670ec | 0x8628c | 0x8568c | 0x214 |
GetCommandLineW | 0x0 | 0x4670f0 | 0x86290 | 0x85690 | 0x187 |
EnterCriticalSection | 0x0 | 0x4670f4 | 0x86294 | 0x85694 | 0xee |
TryEnterCriticalSection | 0x0 | 0x4670f8 | 0x86298 | 0x85698 | 0x4ce |
GetModuleFileNameA | 0x0 | 0x4670fc | 0x8629c | 0x8569c | 0x213 |
IsDebuggerPresent | 0x0 | 0x467100 | 0x862a0 | 0x856a0 | 0x300 |
GetTickCount | 0x0 | 0x467104 | 0x862a4 | 0x856a4 | 0x293 |
FreeLibrary | 0x0 | 0x467108 | 0x862a8 | 0x856a8 | 0x162 |
DeleteCriticalSection | 0x0 | 0x46710c | 0x862ac | 0x856ac | 0xd1 |
DecodePointer | 0x0 | 0x467110 | 0x862b0 | 0x856b0 | 0xca |
RaiseException | 0x0 | 0x467114 | 0x862b4 | 0x856b4 | 0x3b1 |
CloseHandle | 0x0 | 0x467118 | 0x862b8 | 0x856b8 | 0x52 |
GetLastError | 0x0 | 0x46711c | 0x862bc | 0x856bc | 0x202 |
Sleep | 0x0 | 0x467120 | 0x862c0 | 0x856c0 | 0x4b2 |
GetModuleHandleA | 0x0 | 0x467124 | 0x862c4 | 0x856c4 | 0x215 |
FreeEnvironmentStringsW | 0x0 | 0x467128 | 0x862c8 | 0x856c8 | 0x161 |
GetEnvironmentStringsW | 0x0 | 0x46712c | 0x862cc | 0x856cc | 0x1da |
GetCommandLineA | 0x0 | 0x467130 | 0x862d0 | 0x856d0 | 0x186 |
GetOEMCP | 0x0 | 0x467134 | 0x862d4 | 0x856d4 | 0x237 |
IsValidCodePage | 0x0 | 0x467138 | 0x862d8 | 0x856d8 | 0x30a |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x46713c | 0x862dc | 0x856dc | 0x2e3 |
WriteFile | 0x0 | 0x467140 | 0x862e0 | 0x856e0 | 0x525 |
GetCurrentProcess | 0x0 | 0x467144 | 0x862e4 | 0x856e4 | 0x1c0 |
WideCharToMultiByte | 0x0 | 0x467148 | 0x862e8 | 0x856e8 | 0x511 |
GetCurrentThreadId | 0x0 | 0x46714c | 0x862ec | 0x856ec | 0x1c5 |
WaitForSingleObjectEx | 0x0 | 0x467150 | 0x862f0 | 0x856f0 | 0x4fa |
SwitchToThread | 0x0 | 0x467154 | 0x862f4 | 0x856f4 | 0x4bc |
CreateEventW | 0x0 | 0x467158 | 0x862f8 | 0x856f8 | 0x85 |
TlsAlloc | 0x0 | 0x46715c | 0x862fc | 0x856fc | 0x4c5 |
TlsGetValue | 0x0 | 0x467160 | 0x86300 | 0x85700 | 0x4c7 |
TlsSetValue | 0x0 | 0x467164 | 0x86304 | 0x85704 | 0x4c8 |
TlsFree | 0x0 | 0x467168 | 0x86308 | 0x85708 | 0x4c6 |
GetSystemTimeAsFileTime | 0x0 | 0x46716c | 0x8630c | 0x8570c | 0x279 |
GetModuleHandleW | 0x0 | 0x467170 | 0x86310 | 0x85710 | 0x218 |
EncodePointer | 0x0 | 0x467174 | 0x86314 | 0x85714 | 0xea |
MultiByteToWideChar | 0x0 | 0x467178 | 0x86318 | 0x85718 | 0x367 |
LCMapStringW | 0x0 | 0x46717c | 0x8631c | 0x8571c | 0x32d |
GetLocaleInfoW | 0x0 | 0x467180 | 0x86320 | 0x85720 | 0x206 |
GetStringTypeW | 0x0 | 0x467184 | 0x86324 | 0x85724 | 0x269 |
GetCPInfo | 0x0 | 0x467188 | 0x86328 | 0x85728 | 0x172 |
OutputDebugStringW | 0x0 | 0x46718c | 0x8632c | 0x8572c | 0x38a |
SetEvent | 0x0 | 0x467190 | 0x86330 | 0x85730 | 0x459 |
ResetEvent | 0x0 | 0x467194 | 0x86334 | 0x85734 | 0x40f |
InitializeSListHead | 0x0 | 0x467198 | 0x86338 | 0x85738 | 0x2e7 |
IsProcessorFeaturePresent | 0x0 | 0x46719c | 0x8633c | 0x8573c | 0x304 |
UnhandledExceptionFilter | 0x0 | 0x4671a0 | 0x86340 | 0x85740 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x4671a4 | 0x86344 | 0x85744 | 0x4a5 |
GetStartupInfoW | 0x0 | 0x4671a8 | 0x86348 | 0x85748 | 0x263 |
GetCurrentProcessId | 0x0 | 0x4671ac | 0x8634c | 0x8574c | 0x1c1 |
CreateTimerQueue | 0x0 | 0x4671b0 | 0x86350 | 0x85750 | 0xbc |
SignalObjectAndWait | 0x0 | 0x4671b4 | 0x86354 | 0x85754 | 0x4b0 |
SetThreadPriority | 0x0 | 0x4671b8 | 0x86358 | 0x85758 | 0x499 |
GetThreadPriority | 0x0 | 0x4671bc | 0x8635c | 0x8575c | 0x28e |
GetLogicalProcessorInformation | 0x0 | 0x4671c0 | 0x86360 | 0x85760 | 0x20a |
CreateTimerQueueTimer | 0x0 | 0x4671c4 | 0x86364 | 0x85764 | 0xbd |
ChangeTimerQueueTimer | 0x0 | 0x4671c8 | 0x86368 | 0x85768 | 0x48 |
DeleteTimerQueueTimer | 0x0 | 0x4671cc | 0x8636c | 0x8576c | 0xda |
GetNumaHighestNodeNumber | 0x0 | 0x4671d0 | 0x86370 | 0x85770 | 0x229 |
GetProcessAffinityMask | 0x0 | 0x4671d4 | 0x86374 | 0x85774 | 0x246 |
SetThreadAffinityMask | 0x0 | 0x4671d8 | 0x86378 | 0x85778 | 0x490 |
RegisterWaitForSingleObject | 0x0 | 0x4671dc | 0x8637c | 0x8577c | 0x3f5 |
UnregisterWait | 0x0 | 0x4671e0 | 0x86380 | 0x85780 | 0x4da |
FreeLibraryAndExitThread | 0x0 | 0x4671e4 | 0x86384 | 0x85784 | 0x163 |
LoadLibraryExW | 0x0 | 0x4671e8 | 0x86388 | 0x85788 | 0x33e |
VirtualAlloc | 0x0 | 0x4671ec | 0x8638c | 0x8578c | 0x4e9 |
VirtualProtect | 0x0 | 0x4671f0 | 0x86390 | 0x85790 | 0x4ef |
VirtualFree | 0x0 | 0x4671f4 | 0x86394 | 0x85794 | 0x4ec |
DuplicateHandle | 0x0 | 0x4671f8 | 0x86398 | 0x85798 | 0xe8 |
ReleaseSemaphore | 0x0 | 0x4671fc | 0x8639c | 0x8579c | 0x3fe |
InterlockedPopEntrySList | 0x0 | 0x467200 | 0x863a0 | 0x857a0 | 0x2f0 |
InterlockedPushEntrySList | 0x0 | 0x467204 | 0x863a4 | 0x857a4 | 0x2f1 |
InterlockedFlushSList | 0x0 | 0x467208 | 0x863a8 | 0x857a8 | 0x2ee |
QueryDepthSList | 0x0 | 0x46720c | 0x863ac | 0x857ac | 0x39e |
UnregisterWaitEx | 0x0 | 0x467210 | 0x863b0 | 0x857b0 | 0x4db |
RtlUnwind | 0x0 | 0x467214 | 0x863b4 | 0x857b4 | 0x418 |
ExitThread | 0x0 | 0x467218 | 0x863b8 | 0x857b8 | 0x11a |
GetModuleHandleExW | 0x0 | 0x46721c | 0x863bc | 0x857bc | 0x217 |
MoveFileExW | 0x0 | 0x467220 | 0x863c0 | 0x857c0 | 0x360 |
ExitProcess | 0x0 | 0x467224 | 0x863c4 | 0x857c4 | 0x119 |
GetStdHandle | 0x0 | 0x467228 | 0x863c8 | 0x857c8 | 0x264 |
GetACP | 0x0 | 0x46722c | 0x863cc | 0x857cc | 0x168 |
HeapFree | 0x0 | 0x467230 | 0x863d0 | 0x857d0 | 0x2cf |
HeapAlloc | 0x0 | 0x467234 | 0x863d4 | 0x857d4 | 0x2cb |
GetFileType | 0x0 | 0x467238 | 0x863d8 | 0x857d8 | 0x1f3 |
FlushFileBuffers | 0x0 | 0x46723c | 0x863dc | 0x857dc | 0x157 |
GetConsoleCP | 0x0 | 0x467240 | 0x863e0 | 0x857e0 | 0x19a |
GetConsoleMode | 0x0 | 0x467244 | 0x863e4 | 0x857e4 | 0x1ac |
IsValidLocale | 0x0 | 0x467248 | 0x863e8 | 0x857e8 | 0x30c |
GetUserDefaultLCID | 0x0 | 0x46724c | 0x863ec | 0x857ec | 0x29b |
EnumSystemLocalesW | 0x0 | 0x467250 | 0x863f0 | 0x857f0 | 0x10f |
ReadConsoleW | 0x0 | 0x467254 | 0x863f4 | 0x857f4 | 0x3be |
HeapReAlloc | 0x0 | 0x467258 | 0x863f8 | 0x857f8 | 0x2d2 |
HeapSize | 0x0 | 0x46725c | 0x863fc | 0x857fc | 0x2d4 |
FindFirstFileExA | 0x0 | 0x467260 | 0x86400 | 0x85800 | 0x133 |
FindNextFileA | 0x0 | 0x467264 | 0x86404 | 0x85804 | 0x143 |
ADVAPI32.dll (10)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegSetValueExW | 0x0 | 0x467000 | 0x861a0 | 0x855a0 | 0x27e |
CryptGenRandom | 0x0 | 0x467004 | 0x861a4 | 0x855a4 | 0xc1 |
CryptAcquireContextA | 0x0 | 0x467008 | 0x861a8 | 0x855a8 | 0xb0 |
LookupPrivilegeValueW | 0x0 | 0x46700c | 0x861ac | 0x855ac | 0x197 |
AdjustTokenPrivileges | 0x0 | 0x467010 | 0x861b0 | 0x855b0 | 0x1f |
OpenProcessToken | 0x0 | 0x467014 | 0x861b4 | 0x855b4 | 0x1f7 |
OpenThreadToken | 0x0 | 0x467018 | 0x861b8 | 0x855b8 | 0x1fc |
RegCloseKey | 0x0 | 0x46701c | 0x861bc | 0x855bc | 0x230 |
CryptReleaseContext | 0x0 | 0x467020 | 0x861c0 | 0x855c0 | 0xcb |
RegCreateKeyW | 0x0 | 0x467024 | 0x861c4 | 0x855c4 | 0x23c |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteA | 0x0 | 0x467274 | 0x86414 | 0x85814 | 0x11e |
SHLWAPI.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathAddBackslashW | 0x0 | 0x46727c | 0x8641c | 0x8581c | 0x30 |
PathFindExtensionW | 0x0 | 0x467280 | 0x86420 | 0x85820 | 0x47 |
PSAPI.DLL (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetModuleBaseNameA | 0x0 | 0x46726c | 0x8640c | 0x8580c | 0xd |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
cake4.exe | 1 | 0x00200000 | 0x00297FFF | Relevant Image | 32-bit | 0x00262919 |
...
|
|||
cake4.exe | 1 | 0x00200000 | 0x00297FFF | Final Dump | 32-bit | 0x0020241A |
...
|
|||
cake4.exe | 1 | 0x00200000 | 0x00297FFF | Process Termination | 32-bit | - |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Ransom.Mole.E1C541BA |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\-of5Uvp7Nk4OWATL4.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\5k-TNfiKa_1gmYoWjf1.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\833tdY5_MH34U4.mp3.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\CXFgyYpve1g93yz.wav.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\diUkv-tq-j.swf.[generalchin@countermail.com].rhino | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\e6vzzyd4iS6Nzn0.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\eG_eSoP3GaS5ub.swf | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EUG9E.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ForGKyvpOl.swf.[generalchin@countermail.com].rhino | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Gu4AkFdp.mkv.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\iBv5EKoZPKsYY3c2pl\TxvVhQLw9w.m4a.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\iBv5EKoZPKsYY3c2pl\ymOAZf.ppt.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\iE jK0f.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\mWLyWGy_QWFT.wav.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Nv6hON99.gif.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\OiPhiPq EQyGt8pCeAoV.csv.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Q4jLxFd3p.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\SXVymLvqnxgquigP57Pv.xlsx.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\tjRtep--W8 SqtmSnaj\GfH 1Ie6wOQzY 5k4DI.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\tjRtep--W8 SqtmSnaj\q5Hr7lyiRfCApU6C.xls.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\tjRtep--W8 SqtmSnaj\X2JajLRX6.bmp.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\tjRtep--W8 SqtmSnaj\Y3db1aC_5AlNpQZ4cPG.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\tjRtep--W8 SqtmSnaj\ZdpWNdpdNx.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wP8TBOjWTS\-_sk4.pps | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wP8TBOjWTS\ev v7qxZKth.mp3.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wP8TBOjWTS\lw5stwB.swf | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wP8TBOjWTS\rGrQROZjIWQS_w.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Wzj4_bQk.mkv.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\XDsNA6J.bmp.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZglJ57aMYpZ9P7pLlRh.png.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\zPsVUyevGQ4FW.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\1fGwisp8jCt.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\6V7X.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\9iCmi1wS.m4a.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\9kbs2_w18IOb i9.pps | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Adobe\Acrobat\10.0\JavaScripts\glob.settings.js | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\AeF73GQFrRUFEfP_C.mkv.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\C8yKV.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\CgDtuQ2FH3A.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\EpNbVP.avi.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\fGEdHmol-uYJ2aUx41b.m4a.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\LsgsrpB.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\LYE6oZz iVeG5QNBY.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\l_BCBt53g.gif.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx | Modified File | Word Document |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\MS Project\14\1033\Global.MPT | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Office\MSO1033.acl | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Office\Recent\index.dat.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Outlook\Outlook.srs | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Outlook\Outlook.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Templates\Normal.dotm | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\5p5nrgjn0js_halpmcxz@adobe[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\5p5nrgjn0js_halpmcxz@adobe[3].txt.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\5p5nrgjn0js_halpmcxz@demdex[1].txt.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\5p5nrgjn0js_halpmcxz@everesttech[1].txt.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\5p5nrgjn0js_halpmcxz@ml314[1].txt.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\5p5nrgjn0js_halpmcxz@rlcdn[2].txt.[generalchin@countermail.com].rhino | Dropped File | Compressed |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@ad13.adfarm1.adition[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@adfarm1.adition[2].txt.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@adformdsp[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@adform[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@adtech[2].txt.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@adtr02[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@advertising[1].txt.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@api.bing[2].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@at.atwola[1].txt.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@bing[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@doubleclick[2].txt.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@google[1].txt.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@google[4].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@linkedin[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@m.exactag[1].txt.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@msn[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@scorecardresearch[2].txt.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@server.adformdsp[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@skadtec[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@track.adform[2].txt.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@www.bing[2].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@www.linkedin[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@www.msn[2].txt.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Libraries\Music.library-ms.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Libraries\Videos.library-ms.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\7e4dca80246863e3.automaticDestinations-ms.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\eb282ead62b4db87.automaticDestinations-ms.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\1b4dd67f29cb1962.customDestinations-ms.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5afe4de1b92fc382.customDestinations-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\SendTo\Compressed (zipped) Folder.ZFSendToTarget.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\SendTo\Desktop (create shortcut).DeskLink.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20131025151332 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\addons.json | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\bookmarkbackups\bookmarks-2017-06-05_5.json.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\cert8.db | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\content-prefs.sqlite.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\downloads.sqlite | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\extensions.ini.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\extensions.sqlite.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\key3.db | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\marionette.log.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\mimeTypes.rdf.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\permissions.sqlite | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\places.sqlite | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\pluginreg.dat.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\prefs.js | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\search.json.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\secmod.db.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\sessionstore.bak.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\sessionstore.js | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\signons.sqlite | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\webapps\webapps.json.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\webappsstore.sqlite.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\profiles.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\tykbhefC09YpuJ6GZ.odt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\v4NVTaF zeyByjM.m4a.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\xfIlkCQ8.odp.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\xrTxPw8CKhYxpcSJV.m4a.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\ZNdVz.gif.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\8Z-xFMuafWn712Plg.rtf.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\a eeK3Cof0F.xlsx.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\bfc017GN5tmh.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c1J1Vr7hWq.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\f41TDB3cCDdGN.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KjWgNXSB5P\E T-VRRSTs\J1KsjGDILiAYXKKh11.ods | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KjWgNXSB5P\E T-VRRSTs\PIzt6Y.doc.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KjWgNXSB5P\E T-VRRSTs\PXapwoyUb.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KjWgNXSB5P\E T-VRRSTs\zIJ9l4vUg8q7Ye0AeiB.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KjWgNXSB5P\K2SQa33U.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KjWgNXSB5P\MY5h2w Zql7liGw mDEf.odp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KjWgNXSB5P\nPBObvG51sSTj.ods.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KjWgNXSB5P\WgsaRbbd\03g4_AE.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KjWgNXSB5P\WgsaRbbd\gfnKOcqFgrM6L\oAemNaE\4egQ3W\o7_4kYcuMGpVw7fWhX.doc.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KjWgNXSB5P\WgsaRbbd\gfnKOcqFgrM6L\oAemNaE\4egQ3W\QZDgmOZTc7o7iXJAMnXT.odp.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KjWgNXSB5P\WgsaRbbd\gfnKOcqFgrM6L\q9PBr.odp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KjWgNXSB5P\WgsaRbbd\gfnKOcqFgrM6L\ttIR1y8rGjuXrKO.odt.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KjWgNXSB5P\WgsaRbbd\gfnKOcqFgrM6L\zMuEM6hwu.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KjWgNXSB5P\WgsaRbbd\kze0OTs\52FjfcR9Co.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KjWgNXSB5P\WgsaRbbd\kze0OTs\8tNv6sMqzXXl M.ots.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KjWgNXSB5P\WgsaRbbd\RW4ArI0Mpd\WIvbClqSIjfcdCzevi.odt.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\w7Dlby_SMcv7Lq87Z3YF.flv.[generalchin@countermail.com].rhino | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Adobe\Acrobat\10.0\Security\CRLCache\A9B8213768ADC68AF64FCC6409E8BE414726687F.crl.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\JFswZvJ4Guw8UXBBx.jpg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@adnxs[1].txt.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\be71009ff8bb02a2.customDestinations-ms.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\tHkEVoRBe9H2c1YrZiU.m4a.[generalchin@countermail.com].rhino | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Decryptor_Info.hta | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KjWgNXSB5P\WgsaRbbd\RW4ArI0Mpd\6d10pbgI59tZwQc.pptx | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\CZ823cDl.mp4.[generalchin@countermail.com].rhino | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Msox.ots | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\TtegBM.png.[generalchin@countermail.com].rhino | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\WZnm.odp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\5hhJT-UBVp.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Adobe\Acrobat\10.0\Security\addressbook.acrodata.[generalchin@countermail.com].rhino | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\JY1dPkaR.mp4.[generalchin@countermail.com].rhino | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol.[generalchin@countermail.com].rhino | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\5p5nrgjn0js_halpmcxz@dpm.demdex[2].txt.[generalchin@countermail.com].rhino | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\5p5nrgjn0js_halpmcxz@google[2].txt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@c.bing[1].txt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@c.msn[1].txt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@google[3].txt.[generalchin@countermail.com].rhino | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Libraries\Documents.library-ms.[generalchin@countermail.com].rhino | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\SendTo\Mail Recipient.MAPIMail.[generalchin@countermail.com].rhino | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\compatibility.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\localstore.rdf.[generalchin@countermail.com].rhino | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Profiles\silmbjec.default\times.json.[generalchin@countermail.com].rhino | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\cG9Y_mfr-.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KjWgNXSB5P\E T-VRRSTs\v11WPZ.xls.[generalchin@countermail.com].rhino | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KjWgNXSB5P\WgsaRbbd\E T0i.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KjWgNXSB5P\WgsaRbbd\gfnKOcqFgrM6L\oAemNaE\di02.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\duNAoMsaky.xlsx | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\iBv5EKoZPKsYY3c2pl\tD8goI-0GaEVfpr.mkv.[generalchin@countermail.com].rhino | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Office\Recent\ReadMe_Decryptor.txt | Dropped File | Text |
Not Queried
|
...
|
»