VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Wilted Tulip
CopyKittens
Gen:Variant.Razy.647127
|
ransomware.exe
Windows Exe (x86-32)
Created at 2020-06-10T18:32:00
Remarks
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4326e0 |
Size Of Code | 0x36600 |
Size Of Initialized Data | 0xec00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-06-09 21:18:50+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x36520 | 0x36600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.66 |
.rdata | 0x438000 | 0x8044 | 0x8200 | 0x36a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.21 |
.data | 0x441000 | 0x4b1c | 0x200 | 0x3ec00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.75 |
.reloc | 0x446000 | 0x1d2c | 0x1e00 | 0x3ee00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.64 |
Imports (7)
»
SHLWAPI.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StrCmpIW | 0x0 | 0x438164 | 0x3f620 | 0x3e020 | 0x119 |
StrCmpNIW | 0x0 | 0x438168 | 0x3f624 | 0x3e024 | 0x121 |
StrStrIW | 0x0 | 0x43816c | 0x3f628 | 0x3e028 | 0x145 |
StrDupW | 0x0 | 0x438170 | 0x3f62c | 0x3e02c | 0x127 |
PathFindFileNameW | 0x0 | 0x438174 | 0x3f630 | 0x3e030 | 0x49 |
PathFindExtensionW | 0x0 | 0x438178 | 0x3f634 | 0x3e034 | 0x47 |
StrCpyNW | 0x0 | 0x43817c | 0x3f638 | 0x3e038 | 0x124 |
wvnsprintfA | 0x0 | 0x438180 | 0x3f63c | 0x3e03c | 0x16f |
PSAPI.DLL (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetModuleFileNameExW | 0x0 | 0x43815c | 0x3f618 | 0x3e018 | 0x10 |
MPR.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetCloseEnum | 0x0 | 0x43814c | 0x3f608 | 0x3e008 | 0x10 |
WNetEnumResourceW | 0x0 | 0x438150 | 0x3f60c | 0x3e00c | 0x1c |
WNetOpenEnumW | 0x0 | 0x438154 | 0x3f610 | 0x3e010 | 0x3d |
ntdll.dll (24)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RtlDosPathNameToNtPathName_U | 0x0 | 0x4381c8 | 0x3f684 | 0x3e084 | 0x204 |
NtQueryDirectoryFile | 0x0 | 0x4381cc | 0x3f688 | 0x3e088 | 0xe2 |
_allshr | 0x0 | 0x4381d0 | 0x3f68c | 0x3e08c | 0x4aa |
memcmp | 0x0 | 0x4381d4 | 0x3f690 | 0x3e090 | 0x4f1 |
NtClose | 0x0 | 0x4381d8 | 0x3f694 | 0x3e094 | 0x67 |
wcsstr | 0x0 | 0x4381dc | 0x3f698 | 0x3e098 | 0x51f |
RtlUpcaseUnicodeChar | 0x0 | 0x4381e0 | 0x3f69c | 0x3e09c | 0x353 |
ZwQueryInformationProcess | 0x0 | 0x4381e4 | 0x3f6a0 | 0x3e0a0 | 0x41b |
_aulldiv | 0x0 | 0x4381e8 | 0x3f6a4 | 0x3e0a4 | 0x4ac |
RtlUnwind | 0x0 | 0x4381ec | 0x3f6a8 | 0x3e0a8 | 0x352 |
NtQueryVirtualMemory | 0x0 | 0x4381f0 | 0x3f6ac | 0x3e0ac | 0x104 |
NtCreateFile | 0x0 | 0x4381f4 | 0x3f6b0 | 0x3e0b0 | 0x73 |
RtlTimeToTimeFields | 0x0 | 0x4381f8 | 0x3f6b4 | 0x3e0b4 | 0x336 |
_wcslwr | 0x0 | 0x4381fc | 0x3f6b8 | 0x3e0b8 | 0x4cd |
_stricmp | 0x0 | 0x438200 | 0x3f6bc | 0x3e0bc | 0x4c0 |
memset | 0x0 | 0x438204 | 0x3f6c0 | 0x3e0c0 | 0x4f4 |
_aullshr | 0x0 | 0x438208 | 0x3f6c4 | 0x3e0c4 | 0x4af |
NtWaitForSingleObject | 0x0 | 0x43820c | 0x3f6c8 | 0x3e0c8 | 0x163 |
strstr | 0x0 | 0x438210 | 0x3f6cc | 0x3e0cc | 0x507 |
_vsnprintf | 0x0 | 0x438214 | 0x3f6d0 | 0x3e0d0 | 0x4ca |
_alldiv | 0x0 | 0x438218 | 0x3f6d4 | 0x3e0d4 | 0x4a4 |
_allmul | 0x0 | 0x43821c | 0x3f6d8 | 0x3e0d8 | 0x4a6 |
_allshl | 0x0 | 0x438220 | 0x3f6dc | 0x3e0dc | 0x4a9 |
memcpy | 0x0 | 0x438224 | 0x3f6e0 | 0x3e0e0 | 0x4f2 |
KERNEL32.dll (75)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WaitForSingleObject | 0x0 | 0x43801c | 0x3f4d8 | 0x3ded8 | 0x4f9 |
GetLogicalDriveStringsW | 0x0 | 0x438020 | 0x3f4dc | 0x3dedc | 0x208 |
ExitProcess | 0x0 | 0x438024 | 0x3f4e0 | 0x3dee0 | 0x119 |
GetCommandLineW | 0x0 | 0x438028 | 0x3f4e4 | 0x3dee4 | 0x187 |
DeleteFileW | 0x0 | 0x43802c | 0x3f4e8 | 0x3dee8 | 0xd6 |
GetFileAttributesW | 0x0 | 0x438030 | 0x3f4ec | 0x3deec | 0x1ea |
SetFileAttributesW | 0x0 | 0x438034 | 0x3f4f0 | 0x3def0 | 0x461 |
CreateFileW | 0x0 | 0x438038 | 0x3f4f4 | 0x3def4 | 0x8f |
GetDriveTypeW | 0x0 | 0x43803c | 0x3f4f8 | 0x3def8 | 0x1d3 |
Wow64DisableWow64FsRedirection | 0x0 | 0x438040 | 0x3f4fc | 0x3defc | 0x513 |
AllocConsole | 0x0 | 0x438044 | 0x3f500 | 0x3df00 | 0x10 |
AttachConsole | 0x0 | 0x438048 | 0x3f504 | 0x3df04 | 0x17 |
MoveFileW | 0x0 | 0x43804c | 0x3f508 | 0x3df08 | 0x363 |
GetFileSizeEx | 0x0 | 0x438050 | 0x3f50c | 0x3df0c | 0x1f1 |
LoadLibraryA | 0x0 | 0x438054 | 0x3f510 | 0x3df10 | 0x33c |
QueryPerformanceFrequency | 0x0 | 0x438058 | 0x3f514 | 0x3df14 | 0x3a8 |
HeapAlloc | 0x0 | 0x43805c | 0x3f518 | 0x3df18 | 0x2cb |
GetCommandLineA | 0x0 | 0x438060 | 0x3f51c | 0x3df1c | 0x186 |
WaitForMultipleObjects | 0x0 | 0x438064 | 0x3f520 | 0x3df20 | 0x4f7 |
Process32NextW | 0x0 | 0x438068 | 0x3f524 | 0x3df24 | 0x398 |
Process32FirstW | 0x0 | 0x43806c | 0x3f528 | 0x3df28 | 0x396 |
CreateToolhelp32Snapshot | 0x0 | 0x438070 | 0x3f52c | 0x3df2c | 0xbe |
TerminateProcess | 0x0 | 0x438074 | 0x3f530 | 0x3df30 | 0x4c0 |
OpenProcess | 0x0 | 0x438078 | 0x3f534 | 0x3df34 | 0x380 |
GetLocalTime | 0x0 | 0x43807c | 0x3f538 | 0x3df38 | 0x203 |
GetComputerNameW | 0x0 | 0x438080 | 0x3f53c | 0x3df3c | 0x18f |
GlobalMemoryStatus | 0x0 | 0x438084 | 0x3f540 | 0x3df40 | 0x2bf |
LocalAlloc | 0x0 | 0x438088 | 0x3f544 | 0x3df44 | 0x344 |
GetProcessHeap | 0x0 | 0x43808c | 0x3f548 | 0x3df48 | 0x24a |
GetProcessTimes | 0x0 | 0x438090 | 0x3f54c | 0x3df4c | 0x252 |
GetProcessWorkingSetSize | 0x0 | 0x438094 | 0x3f550 | 0x3df50 | 0x254 |
GetCurrentProcess | 0x0 | 0x438098 | 0x3f554 | 0x3df54 | 0x1c0 |
GetCurrentProcessId | 0x0 | 0x43809c | 0x3f558 | 0x3df58 | 0x1c1 |
GetCurrentThread | 0x0 | 0x4380a0 | 0x3f55c | 0x3df5c | 0x1c4 |
GetCurrentThreadId | 0x0 | 0x4380a4 | 0x3f560 | 0x3df60 | 0x1c5 |
GetThreadTimes | 0x0 | 0x4380a8 | 0x3f564 | 0x3df64 | 0x291 |
GetLastError | 0x0 | 0x4380ac | 0x3f568 | 0x3df68 | 0x202 |
SetLastError | 0x0 | 0x4380b0 | 0x3f56c | 0x3df6c | 0x473 |
InitializeCriticalSection | 0x0 | 0x4380b4 | 0x3f570 | 0x3df70 | 0x2e2 |
EnterCriticalSection | 0x0 | 0x4380b8 | 0x3f574 | 0x3df74 | 0xee |
LeaveCriticalSection | 0x0 | 0x4380bc | 0x3f578 | 0x3df78 | 0x339 |
GetTickCount | 0x0 | 0x4380c0 | 0x3f57c | 0x3df7c | 0x293 |
GetStartupInfoW | 0x0 | 0x4380c4 | 0x3f580 | 0x3df80 | 0x263 |
QueryPerformanceCounter | 0x0 | 0x4380c8 | 0x3f584 | 0x3df84 | 0x3a7 |
LocalFree | 0x0 | 0x4380cc | 0x3f588 | 0x3df88 | 0x348 |
GetStdHandle | 0x0 | 0x4380d0 | 0x3f58c | 0x3df8c | 0x264 |
WriteFile | 0x0 | 0x4380d4 | 0x3f590 | 0x3df90 | 0x525 |
FlushFileBuffers | 0x0 | 0x4380d8 | 0x3f594 | 0x3df94 | 0x157 |
lstrlenA | 0x0 | 0x4380dc | 0x3f598 | 0x3df98 | 0x54d |
OutputDebugStringA | 0x0 | 0x4380e0 | 0x3f59c | 0x3df9c | 0x389 |
HeapFree | 0x0 | 0x4380e4 | 0x3f5a0 | 0x3dfa0 | 0x2cf |
CreateThread | 0x0 | 0x4380e8 | 0x3f5a4 | 0x3dfa4 | 0xb5 |
ExitThread | 0x0 | 0x4380ec | 0x3f5a8 | 0x3dfa8 | 0x11a |
DeleteCriticalSection | 0x0 | 0x4380f0 | 0x3f5ac | 0x3dfac | 0xd1 |
Sleep | 0x0 | 0x4380f4 | 0x3f5b0 | 0x3dfb0 | 0x4b2 |
CloseHandle | 0x0 | 0x4380f8 | 0x3f5b4 | 0x3dfb4 | 0x52 |
lstrcpyW | 0x0 | 0x4380fc | 0x3f5b8 | 0x3dfb8 | 0x548 |
lstrcatW | 0x0 | 0x438100 | 0x3f5bc | 0x3dfbc | 0x53f |
TlsAlloc | 0x0 | 0x438104 | 0x3f5c0 | 0x3dfc0 | 0x4c5 |
ExpandEnvironmentStringsW | 0x0 | 0x438108 | 0x3f5c4 | 0x3dfc4 | 0x11d |
GetProcAddress | 0x0 | 0x43810c | 0x3f5c8 | 0x3dfc8 | 0x245 |
GetFileSize | 0x0 | 0x438110 | 0x3f5cc | 0x3dfcc | 0x1f0 |
CreateFileMappingW | 0x0 | 0x438114 | 0x3f5d0 | 0x3dfd0 | 0x8c |
ReadFile | 0x0 | 0x438118 | 0x3f5d4 | 0x3dfd4 | 0x3c0 |
SetEndOfFile | 0x0 | 0x43811c | 0x3f5d8 | 0x3dfd8 | 0x453 |
SetFilePointer | 0x0 | 0x438120 | 0x3f5dc | 0x3dfdc | 0x466 |
SetFilePointerEx | 0x0 | 0x438124 | 0x3f5e0 | 0x3dfe0 | 0x467 |
GetFileTime | 0x0 | 0x438128 | 0x3f5e4 | 0x3dfe4 | 0x1f2 |
SetFileTime | 0x0 | 0x43812c | 0x3f5e8 | 0x3dfe8 | 0x46a |
MapViewOfFile | 0x0 | 0x438130 | 0x3f5ec | 0x3dfec | 0x357 |
UnmapViewOfFile | 0x0 | 0x438134 | 0x3f5f0 | 0x3dff0 | 0x4d6 |
TlsGetValue | 0x0 | 0x438138 | 0x3f5f4 | 0x3dff4 | 0x4c7 |
TlsSetValue | 0x0 | 0x43813c | 0x3f5f8 | 0x3dff8 | 0x4c8 |
CreateFileMappingA | 0x0 | 0x438140 | 0x3f5fc | 0x3dffc | 0x89 |
GetSystemTime | 0x0 | 0x438144 | 0x3f600 | 0x3e000 | 0x277 |
USER32.dll (15)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
wsprintfA | 0x0 | 0x438188 | 0x3f644 | 0x3e044 | 0x332 |
GetDesktopWindow | 0x0 | 0x43818c | 0x3f648 | 0x3e048 | 0x123 |
GetCaretPos | 0x0 | 0x438190 | 0x3f64c | 0x3e04c | 0x10a |
GetCursorPos | 0x0 | 0x438194 | 0x3f650 | 0x3e050 | 0x120 |
GetCapture | 0x0 | 0x438198 | 0x3f654 | 0x3e054 | 0x108 |
GetInputState | 0x0 | 0x43819c | 0x3f658 | 0x3e058 | 0x138 |
GetFocus | 0x0 | 0x4381a0 | 0x3f65c | 0x3e05c | 0x12c |
GetActiveWindow | 0x0 | 0x4381a4 | 0x3f660 | 0x3e060 | 0x100 |
GetOpenClipboardWindow | 0x0 | 0x4381a8 | 0x3f664 | 0x3e064 | 0x163 |
GetClipboardViewer | 0x0 | 0x4381ac | 0x3f668 | 0x3e068 | 0x11b |
GetClipboardOwner | 0x0 | 0x4381b0 | 0x3f66c | 0x3e06c | 0x119 |
GetProcessWindowStation | 0x0 | 0x4381b4 | 0x3f670 | 0x3e070 | 0x168 |
GetMessagePos | 0x0 | 0x4381b8 | 0x3f674 | 0x3e074 | 0x15b |
GetMessageTime | 0x0 | 0x4381bc | 0x3f678 | 0x3e078 | 0x15c |
GetQueueStatus | 0x0 | 0x4381c0 | 0x3f67c | 0x3e07c | 0x16c |
ADVAPI32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptAcquireContextW | 0x0 | 0x438000 | 0x3f4bc | 0x3debc | 0xb1 |
OpenProcessToken | 0x0 | 0x438004 | 0x3f4c0 | 0x3dec0 | 0x1f7 |
AdjustTokenPrivileges | 0x0 | 0x438008 | 0x3f4c4 | 0x3dec4 | 0x1f |
LookupPrivilegeValueW | 0x0 | 0x43800c | 0x3f4c8 | 0x3dec8 | 0x197 |
CryptReleaseContext | 0x0 | 0x438010 | 0x3f4cc | 0x3decc | 0xcb |
CryptGenRandom | 0x0 | 0x438014 | 0x3f4d0 | 0x3ded0 | 0xc1 |
Exports (6)
»
Api name | EAT Address | Ordinal |
---|---|---|
_ReflectiveLoader@4 | 0x32720 | 0x1 |
_aes_hw_cpu_decrypt@8 | 0x100b | 0x2 |
_aes_hw_cpu_decrypt_32_blocks@8 | 0x10c7 | 0x3 |
_aes_hw_cpu_enable_sse@0 | 0x1000 | 0x4 |
_aes_hw_cpu_encrypt@8 | 0x1537 | 0x5 |
_aes_hw_cpu_encrypt_32_blocks@8 | 0x15f3 | 0x6 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
ransomware.exe | 1 | 0x00250000 | 0x00297FFF | Relevant Image |
![]() |
32-bit | 0x0027EE30 |
![]() |
![]() |
...
|
ransomware.exe | 1 | 0x00250000 | 0x00297FFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Razy.647127 |
Malicious
|
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
WiltedTulip_ReflectiveLoader | Reflective loader (Cobalt Strike) used in Operation Wilted Tulip | - |
5/5
|
...
|
ReflectiveLoader | Reflective loader usage | - |
3/5
|
...
|
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\SeyNp\8A XWpAfTEp-BfIc-TM.swf.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\-xChWpCEZDE.wav.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\vSQZAkT-.png.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\AiSFDuuScsMRttd Ab-\6pEm7_ywYMPCf\dXLx6t4TR-VqtnPXXzSZ\LbLCf0O3uhxjCfesi.wav.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\HXfIn.bmp.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\S9ENda_6LnQF.pptx.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\GV1oJPUbe5zAWdHsOo\7E0Q9zxraj7gf7yr1UEs.odt.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\E6hXDsP-byrni-ry-T.xlsx.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\AiSFDuuScsMRttd Ab-\6pEm7_ywYMPCf\kXHOpBi9a.wav.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\S8wsGkTs9j v\QFO17\NJ_QLK B3pIF.ppt.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\dS1OhiKlHV0gBAcXUIN1.flv.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\OW1MU dCSDjo1bdyL8VF.jpg.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\ddaOvfYF7nm6K23R.m4a.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\l-3xT92SW7xOVVdqaf.wav.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\S8wsGkTs9j v\QFO17\kyxQqOwgfLuAF3BR7\ztxve.doc.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\GV1oJPUbe5zAWdHsOo\Fx4ZS0hRzORw.mp3.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\GV1oJPUbe5zAWdHsOo\SP0e9Y5e 2XB8N-.bmp.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\ig_ygofOvbtGlKlri.mkv.ESCAL-p9yqoly | Dropped File | Binary |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\AiSFDuuScsMRttd Ab-\0YGX2k emWPQAl22u\QZP1q57sk.mp3.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\phjaAIvFm.flv.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\a-jIVyWLx2XaJ8V.m4a.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\TYHt3BIwVGc5jKRQF.m4a.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\GV1oJPUbe5zAWdHsOo\NcOYD3 oiK9ry.png.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\gdO0kl.doc.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\dJSd8pYxjTP98jGy\4FCTcxe.bmp.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\CXC4YIcDbVVAx.png.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\AiSFDuuScsMRttd Ab-\6pEm7_ywYMPCf\Xyxnot1QRnC_QuPWZc7k\qX4o1.wav.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\yXJA0oNzWO.m4a.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\AiSFDuuScsMRttd Ab-\0YGX2k emWPQAl22u\w4N2q9e-BMlQQDQOrJ0\EvphN9OmT89.mp3.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\4tYc6COO9Gn.csv.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\1IjjxY2O2NihpFOMAYt9.bmp.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\ZfQzPEfNwBJOHXA.doc.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\9mfn cgRu6v3ezdVU.csv.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\IxRs6H LVy.docx.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\VbWZ.mkv.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\BJReDno.ots.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\yEVNf2lfOulRmzm11q.bmp.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\SeyNp\qFwJ3TInqR4m6_2gu.mkv.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\65Bfo9FQxdYC.gif.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\DkKhDjywgxvvn1l.gif.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\SeyNp\ctNjC.mkv.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\SeyNp\gdSAIX.swf.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\S8wsGkTs9j v\oMZrdw_.xlsx.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\S8wsGkTs9j v\IKqkkAh.ods.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\fA3wIoB5-\j1Ufup0eYADHapbQ55Tq.flv.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\OEaKU5V1_c1fRX81.png.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\qgnpbT.swf.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\pijRbze33DVcStGbt.doc.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\L0lChwdO-e2EaSsMAG2Q.mp3.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\wqrZ.jpg.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\65pzh.m4a.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\LrtqgQJRv SHur10.gif.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\DCWlKLWtnZwc0.flv.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\CJxDc0Yhb.ods.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\iQcA_J\-pA0Nq-fS_tzwiGSfyN.swf.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\S8wsGkTs9j v\TXUxEzL.odp.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\GV1oJPUbe5zAWdHsOo\liT0cY97t6GZ9Xx.gif.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\dJSd8pYxjTP98jGy\LS9Wk9b0rZ6qVWvjdhH7.gif.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\dJSd8pYxjTP98jGy\P-3u0.jpg.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\T-UpgUTIB.swf.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\AiSFDuuScsMRttd Ab-\6pEm7_ywYMPCf\Xyxnot1QRnC_QuPWZc7k\Qu3Giic5g0h5f.m4a.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\3w5S3NKvc9_5h6fkji.flv.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\y2MLXmBPYjUkVlT.bmp.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\GV1oJPUbe5zAWdHsOo\ZQDHbVa.doc.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\iQcA_J\Ro0HzVOScE cIHn.mkv.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\GV1oJPUbe5zAWdHsOo\jAL9sALx3o3tC06OF.avi.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\dJSd8pYxjTP98jGy\GZewVgJt5sKO.gif.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\GV1oJPUbe5zAWdHsOo\SeI TyaDws7n-CT.gif.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\HmRn0G20DiYR46pVI1.jpg.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\S8wsGkTs9j v\QFO17\kyxQqOwgfLuAF3BR7\2s34wzunykMpJETB AP.ots.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\vF87ZcMqTRKgxFZDr.gif.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData\Indexed DB\IndexedDB.jfm.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData\Indexed DB\edb.log.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Outlook Files\kkcie@kdj.kd.pst.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData\Indexed DB\IndexedDB.edb.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData\Indexed DB\edb.chk.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\fA3wIoB5-\b1C5qUKs.flv.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\nS98eL7H1qJvxRu.m4a.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\PKccyuRPC9Z.swf.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\IAPrQZh.gif.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\v3csb.m4a.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\ciVE2QylRpO-3.swf.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\RLx8wWVerZ6FEeVEeS.jpg.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\UNP\Logs\UniversalNotificationPlatform.002.etl.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData\Indexed DB\edb0000A.log.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.002.etl.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\hd Z.gif.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\AiSFDuuScsMRttd Ab-\0YGX2k emWPQAl22u\w4N2q9e-BMlQQDQOrJ0\OqUVub65uW3s3YHUM1J.wav.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\AiSFDuuScsMRttd Ab-\6pEm7_ywYMPCf\vh-X.mp3.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\S8wsGkTs9j v\QFO17\kyxQqOwgfLuAF3BR7\K6Vz8zOGLCFgDUS.ppt.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\S8wsGkTs9j v\QFO17\zjsXaO.rtf.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\GV1oJPUbe5zAWdHsOo\jAPLL Jv.gif.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\xkqICJsZRd3N.wav.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\AiSFDuuScsMRttd Ab-\Hc8Jh\Aw Z8BxW9 nPSJ206b.mp3.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\N4cs9KlFG e.jpg.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\NaghKt6l4WAM-c2.wav.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\6KBVShECn3VvVyG1.flv.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\AiSFDuuScsMRttd Ab-\6pEm7_ywYMPCf\dXLx6t4TR-VqtnPXXzSZ\b-Ux4JQcwZzUjE.wav.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\S8wsGkTs9j v\QFO17\kyxQqOwgfLuAF3BR7\IqPGy7.xls.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\MzFYkG2iqoE3c.bmp.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\S3npsgLzQ3CO.mp3.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\AiSFDuuScsMRttd Ab-\6pEm7_ywYMPCf\CMX3.mp3.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\GADh8c9hFU.xlsx.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\GV1oJPUbe5zAWdHsOo\rkFyFXMNh1sNBSIWX3W.flv.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\AiSFDuuScsMRttd Ab-\6pEm7_ywYMPCf\D6Dt0dJc0G4FBCw7MIyU.mp3.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\a UpA4fJygAqjJ8MU.wav.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\LU HHJHMZgYof-H4.swf.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\qL_MWGJZKedcQSul8_G.ppt.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\S8wsGkTs9j v\QFO17\kyxQqOwgfLuAF3BR7\qblncdqHljci0.ods.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\DbW UuBTHjf.avi.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\P76VnLtOjGWFGQGR cD.swf.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\Hi88WryGJLuQWXYRpqU.bmp.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\EU_anM.wav.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\79AIs_bm8LGmSOwm.bmp.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\RS5usJRdAZJ.odp.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\TGaDF0ua8H.swf.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\fRJEnzrNPk3DrqVo7.xlsx.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\S8wsGkTs9j v\QFO17\nM30KWml.ods.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\SeyNp\m0pXxHqtpkRn uBMao.avi.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\QOUIAghE0gj4wOO.mp3.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\WC3M3WMex8.m4a.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\hgtLepDXGItheOIIc1P.ods.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\iQcA_J\wOwKdw.flv.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\S8wsGkTs9j v\QFO17\kyxQqOwgfLuAF3BR7\lWZjs.csv.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\_cLXD57eijrqUH7LmV.avi.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\vY93.flv.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\UUzLYf.bmp.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\dJSd8pYxjTP98jGy\i7SZ5Nu2BlS4cwWYB.png.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\8i-69CjvRlNtzs.gif.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\dJSd8pYxjTP98jGy\9Ms4mmBGSDAS.bmp.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\L36Mbhv9Mtvd.m4a.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\iQcA_J\NBsy60qW85_2iaUmCc.flv.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\g1X2U.jpg.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\zPUs.png.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\S8wsGkTs9j v\QFO17\QyIf-2.odp.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\Vamsq.ppt.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\SeyNp\fBtldtgTmBb.flv.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\pCG8hN8lLj7Gce3xsb.png.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\WZza9 f_0O.flv.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\AiSFDuuScsMRttd Ab-\6pEm7_ywYMPCf\H1xVqTGlKC-C6iVZQH.m4a.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\AiSFDuuScsMRttd Ab-\6pEm7_ywYMPCf\dXLx6t4TR-VqtnPXXzSZ\xJgnADThGb.m4a.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\GV1oJPUbe5zAWdHsOo\sZ627N.wav.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Music\AiSFDuuScsMRttd Ab-\Hc8Jh\Towb JSsGmUR79Lr.wav.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\4kZ3d0C_6x5KXnU6cps.wav.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Local\Resmon.ResmonCfg.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.004.etl.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.006.etl.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.010.etl.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\UNP\Logs\UniversalNotificationPlatform.003.etl.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Q1WwjRn8-.xlsx.ESCAL-p9yqoly | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Local\TileDataLayer\Database\EDB.chk.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\dJSd8pYxjTP98jGy\e yWexAq.png.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Music\AiSFDuuScsMRttd Ab-\Hc8Jh\wMCaVd8kqjVy8DQNk\PpZo7c_byuMHVDP.m4a.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\TkJHZSJ0bgYEwv919I.mp3.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\kKVrEueI5L5oLU2W1D.gif.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\FPFlPu0P7ffZa7LXWgtO.gif.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\iQcA_J\so7KB.mkv.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Music\AiSFDuuScsMRttd Ab-\0YGX2k emWPQAl22u\w4N2q9e-BMlQQDQOrJ0\6VeIhFdaU4mUVtHd.mp3.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Music\AiSFDuuScsMRttd Ab-\E97CB8jnrGICRBxwNpd3.wav.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\haKlrhM.mp4.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Music\AiSFDuuScsMRttd Ab-\Hc8Jh\wMCaVd8kqjVy8DQNk\D2E8i.m4a.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\BG3JF9nLtT.bmp.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\dJSd8pYxjTP98jGy\CDwabmuPJzs88JS.bmp.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\LAEGWljth7qfIeSqV.gif.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\xFFbiQgrqdSK-vgG6X\7Dxq5roNJjDrpzM1hdxP.swf.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\S8wsGkTs9j v\AVyRwZe6ORTgg334X.pptx.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\dJSd8pYxjTP98jGy\a-EdmVon k.gif.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\GV1oJPUbe5zAWdHsOo\SjAb0Vj18Kd.avi.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Music\AiSFDuuScsMRttd Ab-\0YGX2k emWPQAl22u\TorhP-ICy3S.wav.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\BHNVK k8x3Zja.avi.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\xFFbiQgrqdSK-vgG6X\b3Vx.mp4.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\dJSd8pYxjTP98jGy\uClxVkNmTXh8cevasAj.png.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\aKqhFc.mp4.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\GV1oJPUbe5zAWdHsOo\S-_X DyHZae.gif.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\TMk9rH9mU8wsFLDrJv8f.mp3.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\VB5I3g0sln34DYxKE.flv.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\xlgHyuiCQxEeWN.ots.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\S8wsGkTs9j v\QFO17\kyxQqOwgfLuAF3BR7\QpwTvU.odt.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\5aY7JCAKUHtgz.flv.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Music\eqcAixRLv8p.wav.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\T2gEL2fyzP.png.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\RMyXga6aKLmT3Xt.avi.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\S8wsGkTs9j v\QFO17\1s4ECQrIXT4z-mpbSd_M.odt.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\AK-b3D IJNArtgGSL84.xls.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\lHj.csv.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\7TCrCMp69d RkCt4z.png.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\9sM-LGia3kx.swf.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\ffBZHYN0Z7-iS_7Lzw9.mp4.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\XCrh\yYqU3HzBPQ0.flv.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Music\MicWl814bK_uOSha.wav.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\qLpFtsl.mkv.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\J6C2m3D6pX.csv.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\S8wsGkTs9j v\QFO17\kyxQqOwgfLuAF3BR7\YroQ0.docx.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\GV1oJPUbe5zAWdHsOo\uM9mSXeD06nHL8VkylOV.avi.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\dJSd8pYxjTP98jGy\vZaEQvwFvC0hk6gR2c.gif.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\bCMA37RZz1Zv1a8OTX.odp.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\SeyNp\glUtJiQHiw mGo Sd.mp4.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\c9hE.swf.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Music\AiSFDuuScsMRttd Ab-\6pEm7_ywYMPCf\CX579fL.wav.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\a1ZqUoddpsrhcZf.pps.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\xFFbiQgrqdSK-vgG6X\unRYoT.flv.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\iQcA_J\1roTd4.avi.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\8vxt2kyCQ.mp3.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\GTBeW0_438RohH.flv.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\9FwUr2mMA ec.docx.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\HDDdR837BOoi.bmp.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\6EDB5LtdHo7.png.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\bSxsIoyXvTyHxY.xls.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Music\AiSFDuuScsMRttd Ab-\6pEm7_ywYMPCf\KMfCc.wav.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\7E1YVYIH.flv.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Music\7JO.m4a.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\iQcA_J\AGZIGDLwIx9Q6r.swf.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\dJSd8pYxjTP98jGy\WFE3.gif.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\nWGnj 8u1.png.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\TmSwo8bK83YHJY lI.bmp.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Music\AiSFDuuScsMRttd Ab-\0YGX2k emWPQAl22u\6pS_MeiKw.wav.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\zP6oanQZGQ4Z_q_I6.pptx.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Music\AiSFDuuScsMRttd Ab-\I0tspmDTy4D2Rn.m4a.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\LfbChuU4Hx_5GZ4.mp3.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\_Kz5a5SHTOlStYmd8Kv2.mp4.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\Pwhi8-ZeuN.jpg.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\NI1MMNe6FRanC-Tn.pptx.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\dJSd8pYxjTP98jGy\Vgz9BL.bmp.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\dJSd8pYxjTP98jGy\_ER NqCbSKh6ox_ZH.png.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\mvVcIyoAYV_.png.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\kYuavyxeO6g.pdf.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\GV1oJPUbe5zAWdHsOo\blU3GIa.m4a.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\SeyNp\81MJP86Tnubtt.flv.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\S8wsGkTs9j v\mFn6HIWO7Z0Wpa.odp.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\iQcA_J\cTgYUT35zJgm02w.swf.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\iQcA_J\EYhpVLGFm-uj_za-TVA.avi.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\JWkAszBx4QNT8e.swf.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Videos\squmXa\Nsrf-6R3hO5B\jRd4Qq8KnpZYd9AJ4o.avi.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Desktop\Op6k1R.mkv.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Pictures\VGEU.png.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\iKNGu03x16ItDPwQI.png.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\sW4pApadcHhaRrGDX\S8wsGkTs9j v\QFO17\DY4c8.pps.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Roaming\t1RLqM X_Po0-lPYgo.flv.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\AJl9Ygd.pptx.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\0zPrRMnXsgxPtmhv.pptx.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\4KI72B0EKNWZyVa.pptx.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\AppData\Local\TileDataLayer\Database\EDB00006.log.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\USOShared\Logs\UpdateSessionOrchestration.007.etl.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\Yu1lX.pptx.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\OMTki7-FimHGq3pidH.docx.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\FD1HVy\Documents\MRKZ74QGi0flk8KDGi9.xlsx.ESCAL-p9yqoly | Dropped File | Stream |
Not Queried
|
...
|
»