VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Gen:Heur.Ransom.Imps.1
|
sVSwdhWJRXFZUXuI.exe
Windows Exe (x86-32)
Created at 2020-11-17T22:22:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 Bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\sVSwdhWJRXFZUXuI.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x410783 |
Size Of Code | 0x20600 |
Size Of Initialized Data | 0xee00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-11-12 23:24:34+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x205fd | 0x20600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.71 |
.rdata | 0x422000 | 0x97f6 | 0x9800 | 0x20a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.65 |
.data | 0x42c000 | 0x3d88 | 0x1200 | 0x2a200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.6 |
.reloc | 0x430000 | 0x17c4 | 0x1800 | 0x2b400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.61 |
Imports (8)
»
KERNEL32.dll (107)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FindFirstFileW | 0x0 | 0x422010 | 0x2ac60 | 0x29660 | 0x139 |
GetFileSizeEx | 0x0 | 0x422014 | 0x2ac64 | 0x29664 | 0x1f1 |
HeapFree | 0x0 | 0x422018 | 0x2ac68 | 0x29668 | 0x2cf |
EnterCriticalSection | 0x0 | 0x42201c | 0x2ac6c | 0x2966c | 0xee |
GetCommandLineW | 0x0 | 0x422020 | 0x2ac70 | 0x29670 | 0x187 |
FindNextFileW | 0x0 | 0x422024 | 0x2ac74 | 0x29674 | 0x145 |
GetCurrentProcess | 0x0 | 0x422028 | 0x2ac78 | 0x29678 | 0x1c0 |
lstrlenW | 0x0 | 0x42202c | 0x2ac7c | 0x2967c | 0x54e |
WriteFile | 0x0 | 0x422030 | 0x2ac80 | 0x29680 | 0x525 |
InterlockedDecrement | 0x0 | 0x422034 | 0x2ac84 | 0x29684 | 0x2eb |
GetModuleFileNameW | 0x0 | 0x422038 | 0x2ac88 | 0x29688 | 0x214 |
WaitForMultipleObjects | 0x0 | 0x42203c | 0x2ac8c | 0x2968c | 0x4f7 |
LeaveCriticalSection | 0x0 | 0x422040 | 0x2ac90 | 0x29690 | 0x339 |
InitializeCriticalSection | 0x0 | 0x422044 | 0x2ac94 | 0x29694 | 0x2e2 |
SetErrorMode | 0x0 | 0x422048 | 0x2ac98 | 0x29698 | 0x458 |
GetQueuedCompletionStatus | 0x0 | 0x42204c | 0x2ac9c | 0x2969c | 0x25e |
CreateMutexW | 0x0 | 0x422050 | 0x2aca0 | 0x296a0 | 0x9e |
FindClose | 0x0 | 0x422054 | 0x2aca4 | 0x296a4 | 0x12e |
WaitForSingleObject | 0x0 | 0x422058 | 0x2aca8 | 0x296a8 | 0x4f9 |
CreateFileW | 0x0 | 0x42205c | 0x2acac | 0x296ac | 0x8f |
GetCurrentThreadId | 0x0 | 0x422060 | 0x2acb0 | 0x296b0 | 0x1c5 |
lstrcatA | 0x0 | 0x422064 | 0x2acb4 | 0x296b4 | 0x53e |
GetModuleHandleA | 0x0 | 0x422068 | 0x2acb8 | 0x296b8 | 0x215 |
PostQueuedCompletionStatus | 0x0 | 0x42206c | 0x2acbc | 0x296bc | 0x38e |
SetFileAttributesW | 0x0 | 0x422070 | 0x2acc0 | 0x296c0 | 0x461 |
Sleep | 0x0 | 0x422074 | 0x2acc4 | 0x296c4 | 0x4b2 |
GetLastError | 0x0 | 0x422078 | 0x2acc8 | 0x296c8 | 0x202 |
InterlockedExchange | 0x0 | 0x42207c | 0x2accc | 0x296cc | 0x2ec |
CloseHandle | 0x0 | 0x422080 | 0x2acd0 | 0x296d0 | 0x52 |
GetSystemInfo | 0x0 | 0x422084 | 0x2acd4 | 0x296d4 | 0x273 |
LoadLibraryW | 0x0 | 0x422088 | 0x2acd8 | 0x296d8 | 0x33f |
CreateThread | 0x0 | 0x42208c | 0x2acdc | 0x296dc | 0xb5 |
HeapAlloc | 0x0 | 0x422090 | 0x2ace0 | 0x296e0 | 0x2cb |
GetProcAddress | 0x0 | 0x422094 | 0x2ace4 | 0x296e4 | 0x245 |
LocalFree | 0x0 | 0x422098 | 0x2ace8 | 0x296e8 | 0x348 |
DeleteCriticalSection | 0x0 | 0x42209c | 0x2acec | 0x296ec | 0xd1 |
ExitProcess | 0x0 | 0x4220a0 | 0x2acf0 | 0x296f0 | 0x119 |
GetProcessHeap | 0x0 | 0x4220a4 | 0x2acf4 | 0x296f4 | 0x24a |
SystemTimeToFileTime | 0x0 | 0x4220a8 | 0x2acf8 | 0x296f8 | 0x4bd |
lstrcpyW | 0x0 | 0x4220ac | 0x2acfc | 0x296fc | 0x548 |
InterlockedIncrement | 0x0 | 0x4220b0 | 0x2ad00 | 0x29700 | 0x2ef |
GetSystemTime | 0x0 | 0x4220b4 | 0x2ad04 | 0x29704 | 0x277 |
lstrcmpiW | 0x0 | 0x4220b8 | 0x2ad08 | 0x29708 | 0x545 |
CreateIoCompletionPort | 0x0 | 0x4220bc | 0x2ad0c | 0x2970c | 0x94 |
OpenMutexW | 0x0 | 0x4220c0 | 0x2ad10 | 0x29710 | 0x37d |
lstrcmpW | 0x0 | 0x4220c4 | 0x2ad14 | 0x29714 | 0x542 |
SetConsoleTitleW | 0x0 | 0x4220c8 | 0x2ad18 | 0x29718 | 0x448 |
MoveFileW | 0x0 | 0x4220cc | 0x2ad1c | 0x2971c | 0x363 |
GetDriveTypeW | 0x0 | 0x4220d0 | 0x2ad20 | 0x29720 | 0x1d3 |
QueryPerformanceCounter | 0x0 | 0x4220d4 | 0x2ad24 | 0x29724 | 0x3a7 |
HeapReAlloc | 0x0 | 0x4220d8 | 0x2ad28 | 0x29728 | 0x2d2 |
HeapSize | 0x0 | 0x4220dc | 0x2ad2c | 0x2972c | 0x2d4 |
WriteConsoleW | 0x0 | 0x4220e0 | 0x2ad30 | 0x29730 | 0x524 |
FlushFileBuffers | 0x0 | 0x4220e4 | 0x2ad34 | 0x29734 | 0x157 |
CancelIo | 0x0 | 0x4220e8 | 0x2ad38 | 0x29738 | 0x42 |
GetLogicalDrives | 0x0 | 0x4220ec | 0x2ad3c | 0x2973c | 0x209 |
InterlockedExchangeAdd | 0x0 | 0x4220f0 | 0x2ad40 | 0x29740 | 0x2ed |
ReadFile | 0x0 | 0x4220f4 | 0x2ad44 | 0x29744 | 0x3c0 |
GetStringTypeW | 0x0 | 0x4220f8 | 0x2ad48 | 0x29748 | 0x269 |
SetStdHandle | 0x0 | 0x4220fc | 0x2ad4c | 0x2974c | 0x487 |
SetEnvironmentVariableA | 0x0 | 0x422100 | 0x2ad50 | 0x29750 | 0x456 |
FreeEnvironmentStringsW | 0x0 | 0x422104 | 0x2ad54 | 0x29754 | 0x161 |
GetEnvironmentStringsW | 0x0 | 0x422108 | 0x2ad58 | 0x29758 | 0x1da |
GetCPInfo | 0x0 | 0x42210c | 0x2ad5c | 0x2975c | 0x172 |
GetOEMCP | 0x0 | 0x422110 | 0x2ad60 | 0x29760 | 0x237 |
IsValidCodePage | 0x0 | 0x422114 | 0x2ad64 | 0x29764 | 0x30a |
FindNextFileA | 0x0 | 0x422118 | 0x2ad68 | 0x29768 | 0x143 |
DecodePointer | 0x0 | 0x42211c | 0x2ad6c | 0x2976c | 0xca |
FindFirstFileExA | 0x0 | 0x422120 | 0x2ad70 | 0x29770 | 0x133 |
GetConsoleCP | 0x0 | 0x422124 | 0x2ad74 | 0x29774 | 0x19a |
GetConsoleMode | 0x0 | 0x422128 | 0x2ad78 | 0x29778 | 0x1ac |
SetFilePointerEx | 0x0 | 0x42212c | 0x2ad7c | 0x2977c | 0x467 |
GetFileType | 0x0 | 0x422130 | 0x2ad80 | 0x29780 | 0x1f3 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x422134 | 0x2ad84 | 0x29784 | 0x2e3 |
SetEvent | 0x0 | 0x422138 | 0x2ad88 | 0x29788 | 0x459 |
ResetEvent | 0x0 | 0x42213c | 0x2ad8c | 0x2978c | 0x40f |
WaitForSingleObjectEx | 0x0 | 0x422140 | 0x2ad90 | 0x29790 | 0x4fa |
CreateEventW | 0x0 | 0x422144 | 0x2ad94 | 0x29794 | 0x85 |
GetModuleHandleW | 0x0 | 0x422148 | 0x2ad98 | 0x29798 | 0x218 |
IsProcessorFeaturePresent | 0x0 | 0x42214c | 0x2ad9c | 0x2979c | 0x304 |
IsDebuggerPresent | 0x0 | 0x422150 | 0x2ada0 | 0x297a0 | 0x300 |
UnhandledExceptionFilter | 0x0 | 0x422154 | 0x2ada4 | 0x297a4 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x422158 | 0x2ada8 | 0x297a8 | 0x4a5 |
GetStartupInfoW | 0x0 | 0x42215c | 0x2adac | 0x297ac | 0x263 |
GetCurrentProcessId | 0x0 | 0x422160 | 0x2adb0 | 0x297b0 | 0x1c1 |
GetSystemTimeAsFileTime | 0x0 | 0x422164 | 0x2adb4 | 0x297b4 | 0x279 |
InitializeSListHead | 0x0 | 0x422168 | 0x2adb8 | 0x297b8 | 0x2e7 |
TerminateProcess | 0x0 | 0x42216c | 0x2adbc | 0x297bc | 0x4c0 |
RtlUnwind | 0x0 | 0x422170 | 0x2adc0 | 0x297c0 | 0x418 |
RaiseException | 0x0 | 0x422174 | 0x2adc4 | 0x297c4 | 0x3b1 |
SetLastError | 0x0 | 0x422178 | 0x2adc8 | 0x297c8 | 0x473 |
TlsAlloc | 0x0 | 0x42217c | 0x2adcc | 0x297cc | 0x4c5 |
TlsGetValue | 0x0 | 0x422180 | 0x2add0 | 0x297d0 | 0x4c7 |
TlsSetValue | 0x0 | 0x422184 | 0x2add4 | 0x297d4 | 0x4c8 |
TlsFree | 0x0 | 0x422188 | 0x2add8 | 0x297d8 | 0x4c6 |
FreeLibrary | 0x0 | 0x42218c | 0x2addc | 0x297dc | 0x162 |
LoadLibraryExW | 0x0 | 0x422190 | 0x2ade0 | 0x297e0 | 0x33e |
EncodePointer | 0x0 | 0x422194 | 0x2ade4 | 0x297e4 | 0xea |
GetModuleHandleExW | 0x0 | 0x422198 | 0x2ade8 | 0x297e8 | 0x217 |
GetModuleFileNameA | 0x0 | 0x42219c | 0x2adec | 0x297ec | 0x213 |
MultiByteToWideChar | 0x0 | 0x4221a0 | 0x2adf0 | 0x297f0 | 0x367 |
WideCharToMultiByte | 0x0 | 0x4221a4 | 0x2adf4 | 0x297f4 | 0x511 |
GetStdHandle | 0x0 | 0x4221a8 | 0x2adf8 | 0x297f8 | 0x264 |
GetCommandLineA | 0x0 | 0x4221ac | 0x2adfc | 0x297fc | 0x186 |
GetACP | 0x0 | 0x4221b0 | 0x2ae00 | 0x29800 | 0x168 |
CompareStringW | 0x0 | 0x4221b4 | 0x2ae04 | 0x29804 | 0x64 |
LCMapStringW | 0x0 | 0x4221b8 | 0x2ae08 | 0x29808 | 0x32d |
USER32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
wsprintfW | 0x0 | 0x42220c | 0x2ae5c | 0x2985c | 0x333 |
GetKeyboardLayoutList | 0x0 | 0x422210 | 0x2ae60 | 0x29860 | 0x13f |
CharLowerW | 0x0 | 0x422214 | 0x2ae64 | 0x29864 | 0x2e |
ADVAPI32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptGenRandom | 0x0 | 0x422000 | 0x2ac50 | 0x29650 | 0xc1 |
CryptReleaseContext | 0x0 | 0x422004 | 0x2ac54 | 0x29654 | 0xcb |
CryptAcquireContextW | 0x0 | 0x422008 | 0x2ac58 | 0x29658 | 0xb1 |
SHELL32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CommandLineToArgvW | 0x0 | 0x4221e4 | 0x2ae34 | 0x29834 | 0x6 |
ShellExecuteW | 0x0 | 0x4221e8 | 0x2ae38 | 0x29838 | 0x122 |
SHEmptyRecycleBinA | 0x0 | 0x4221ec | 0x2ae3c | 0x2983c | 0xa4 |
ole32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoInitialize | 0x0 | 0x42221c | 0x2ae6c | 0x2986c | 0x3e |
CoSetProxyBlanket | 0x0 | 0x422220 | 0x2ae70 | 0x29870 | 0x63 |
CoCreateInstance | 0x0 | 0x422224 | 0x2ae74 | 0x29874 | 0x10 |
OLEAUT32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysAllocString | 0x2 | 0x4221d0 | 0x2ae20 | 0x29820 | - |
SysFreeString | 0x6 | 0x4221d4 | 0x2ae24 | 0x29824 | - |
VariantInit | 0x8 | 0x4221d8 | 0x2ae28 | 0x29828 | - |
VariantClear | 0x9 | 0x4221dc | 0x2ae2c | 0x2982c | - |
SHLWAPI.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathFindFileNameW | 0x0 | 0x4221f4 | 0x2ae44 | 0x29844 | 0x49 |
StrStrW | 0x0 | 0x4221f8 | 0x2ae48 | 0x29848 | 0x148 |
PathAddBackslashW | 0x0 | 0x4221fc | 0x2ae4c | 0x2984c | 0x30 |
PathRemoveFileSpecW | 0x0 | 0x422200 | 0x2ae50 | 0x29850 | 0x8b |
wnsprintfA | 0x0 | 0x422204 | 0x2ae54 | 0x29854 | 0x16d |
MPR.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetEnumResourceW | 0x0 | 0x4221c0 | 0x2ae10 | 0x29810 | 0x1c |
WNetCloseEnum | 0x0 | 0x4221c4 | 0x2ae14 | 0x29814 | 0x10 |
WNetOpenEnumW | 0x0 | 0x4221c8 | 0x2ae18 | 0x29818 | 0x3d |
Exports (10)
»
Api name | EAT Address | Ordinal |
---|---|---|
ntru_crypto_drbg_external_instantiate | 0x1720 | 0x1 |
ntru_crypto_drbg_generate | 0x1900 | 0x2 |
ntru_crypto_drbg_instantiate | 0x1490 | 0x3 |
ntru_crypto_drbg_reseed | 0x18b0 | 0x4 |
ntru_crypto_drbg_uninstantiate | 0x17e0 | 0x5 |
ntru_crypto_ntru_decrypt | 0x2c20 | 0x6 |
ntru_crypto_ntru_encrypt | 0x2790 | 0x7 |
ntru_crypto_ntru_encrypt_keygen | 0x32a0 | 0x8 |
ntru_crypto_ntru_encrypt_publicKey2SubjectPublicKeyInfo | 0x3a80 | 0x9 |
ntru_crypto_ntru_encrypt_subjectPublicKeyInfo2PublicKey | 0x3ba0 | 0xa |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
svswdhwjrxfzuxui.exe | 1 | 0x00DE0000 | 0x00E11FFF | Relevant Image |
![]() |
32-bit | 0x00E00C16 |
![]() |
![]() |
...
|
svswdhwjrxfzuxui.exe | 1 | 0x00DE0000 | 0x00E11FFF | Final Dump |
![]() |
32-bit | 0x00DEB177 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Ransom.Imps.1 |
Malicious
|
C:\\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\5Rjw5.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\bDKvYp.mp4.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\C4_k3VUR.gif.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\CN2Yu0ZsD1xs5.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\EN12F2.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\FKlQd4kwD__P5I\g42u5H.mp4.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\FKlQd4kwD__P5I\t-HIGqHc1g5oQmZj.mkv.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\FKlQd4kwD__P5I\Zb1DwUD.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\boot.sdi.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\HbthB3jQFU5Y-AjNk\bpw79uT.bmp.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\HbthB3jQFU5Y-AjNk\CzpEkctADL.mp3.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\HbthB3jQFU5Y-AjNk\fCuusX4CV6rTKR6S.ppt.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\HbthB3jQFU5Y-AjNk\iB_721DN-zYKJuMnIh.mp4.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\HbthB3jQFU5Y-AjNk\qPQBIwc1V.bmp.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\HbthB3jQFU5Y-AjNk\uVCMJbA.mp3.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\KffIUrJUk.swf.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\qzfxLs8Rn9VY.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\R8oLJG7HaM\NmUmUk6u7GgZXZ5BR.gif.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\R8oLJG7HaM\oOyx5i.mp3.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\R8oLJG7HaM\Y6LkUcJgbr VRLA.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\R8oLJG7HaM\yFncPMRrFQiCgwK VnlZ.bmp.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\SptlLDw47WFBL.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\SZ wLbnmZnssv.png.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\wDmQnqmqed3\hJ-pTKrnE.wav.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\wDmQnqmqed3\pAvEBY4.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\XAMO.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\Xn4YV2mMv8OQOTNNOu.doc.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\YOibxDGO83L0-bQimYPS.png.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\wf3_D.gif.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\bKAq_r l5wQ8PPjFGY8.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\CnKdAfDz9Qc.rtf | Modified File | Binary |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\GBUjSuawrY1cxW1\Qj7SeAjO hbObQDHc.xlsx.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\GBUjSuawrY1cxW1\rdnAIKhyNP-.odp | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\GBUjSuawrY1cxW1\Y1xI22.doc.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\gHmp.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\H_XLsW OknG.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\ISYWXm4yMp05dI6.pptx.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\k5n4LQZahDLV.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\NBaEY4w.docx.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\NotZWjjg-Ncw.docx.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\_private\folder.ico | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\Ou_9PeTleJWmDJh.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\OYvHbSxRyDdIlTwvwD5Y.csv.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\PQD6yoKepl2tUhqv.ots.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\qt_0Ae0ejm m9J3.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\uMRDEqKnwX4z.xlsx.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\DqTNceakNegr1Lc6u.odp | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\uOd1E gUA.ots | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\E5ymgx3tJCrzT SmyyC.docx.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\uIJewY frVZX9wY0Z2z2\AA7WI-0ERcyU\HCTa6b8Pyb.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\P0V7vZLRf\Nkh4_3uh0GOJgz3RyUfq.odp.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\P0V7vZLRf\N7tvAd1fnS3.ots.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\uIJewY frVZX9wY0Z2z2\AA7WI-0ERcyU\teMc0mMGPk.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\uIJewY frVZX9wY0Z2z2\YbCtz-.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\wilBO-ZHaF.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\uIJewY frVZX9wY0Z2z2\9D-iv3fHhbTTfXhKSL-D.pptx.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\_8SJtLW\8BrStyEzQnzfF9.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\_8SJtLW\b3-Xp23y2tCQVfIgfUz-\5m0DQrr1Haz408KCThqf\0_-2dosY6Ya1iK-TDh\av7UdVnl1f2 v.xls.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\_8SJtLW\b3-Xp23y2tCQVfIgfUz-\5m0DQrr1Haz408KCThqf\0_-2dosY6Ya1iK-TDh\jjy1xiXyqPB.pps | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\_8SJtLW\b3-Xp23y2tCQVfIgfUz-\5m0DQrr1Haz408KCThqf\52tO9Moo3wbA6XAz20.pptx.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\_8SJtLW\b3-Xp23y2tCQVfIgfUz-\5m0DQrr1Haz408KCThqf\_xH9hpBu68q0fhrFug.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\_8SJtLW\b3-Xp23y2tCQVfIgfUz-\7imCwB.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\_8SJtLW\b3-Xp23y2tCQVfIgfUz-\daVeaa8IXqC.docx.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\_8SJtLW\b3-Xp23y2tCQVfIgfUz-\5m0DQrr1Haz408KCThqf\DNsA6SztWUR9G8.ods | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\_8SJtLW\YrzxumZnNrT_.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\_cIQ9GOKM2uAOWto.xlsx.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\XjMrrETi4IkvROeU.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\_Y 4p2LV0.pptx | Modified File | Binary |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Suggested Sites.url | Modified File | Text |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Web Slice Gallery.url | Modified File | Text |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE Add-on site.url | Modified File | Text |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Work.url | Modified File | Text |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Autos.url.crypted | Dropped File | Text |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Money.url.crypted | Dropped File | Text |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Sports.url | Modified File | Text |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN.url.crypted | Dropped File | Text |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Links\Desktop.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\8a8QTID8m0a.mp3.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\9KugnplPwxU uN1T.mp3.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\IXq9U17GbHn-s4w_7.m4a.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\faFVh.mp3.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\FmHlph98Kx4634Gw6S\dBsAbLJJTrj1-xc3avY.wav.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\FmHlph98Kx4634Gw6S\hp6hL8K\B_Fk.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\7Y6RFTBxGqHtaBV.mp3.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\FmHlph98Kx4634Gw6S\hp6hL8K\iEyXzDZJ8s LPAJN.mp3.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\FmHlph98Kx4634Gw6S\hp6hL8K\sRKdRF8m9ZMW\2VL5_3iPUx8mw.wav.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\FmHlph98Kx4634Gw6S\hp6hL8K\sRKdRF8m9ZMW\w eWm28.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\FmHlph98Kx4634Gw6S\hp6hL8K\sRKdRF8m9ZMW\y-rp-EXZ-yK.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\FmHlph98Kx4634Gw6S\hp6hL8K\Z91x8WDi69_xh58s6v_4.mp3.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\FmHlph98Kx4634Gw6S\jk72PoPSae6I8JJAUZj\P3Sb-u-d6.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\FmHlph98Kx4634Gw6S\jk72PoPSae6I8JJAUZj\V5I3fCDGltu02BTLrQ.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\FmHlph98Kx4634Gw6S\jk72PoPSae6I8JJAUZj\XVeqQpg-1F.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\FmHlph98Kx4634Gw6S\jk72PoPSae6I8JJAUZj\rnMfNsBIAlEfp.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\FmHlph98Kx4634Gw6S\Luk8dAY_.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\FmHlph98Kx4634Gw6S\n1XQST.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\kX1n2Xe4uKw\1dmWA6r9Nh7wG.m4a.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\kX1n2Xe4uKw\2byfYz2uPKKvbZg3U4.mp3.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\kX1n2Xe4uKw\OdqPcGho.m4a.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\kX1n2Xe4uKw\rKuSjn.m4a.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\xJa2_yk_SCYjO.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\PuM-ucRL1l_Qt-4l.wav.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\4dww4uo5p.gif.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6awojlas2cZnv\ADPZqqaMpsHc83h.bmp.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6awojlas2cZnv\bCE e6y.bmp.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6awojlas2cZnv\qEywyL.gif.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\c8q8iM.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\DUsFXU.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\M_M0VLOO2_Zp.gif.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\RvLA6oRpZxL.bmp.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\s2CnFc5DPooT.png.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\uGTa3LCJnT\9-kiKSk07WNiitE.png.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\uGTa3LCJnT\DM-dwtZxr\khSfucv4zehuFjlWpnQP.png.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\uGTa3LCJnT\DM-dwtZxr\mzmLJF8YYxflwqk6.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\uGTa3LCJnT\DM-dwtZxr\VerXtgx0Jo40vFcmY02.bmp.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\uGTa3LCJnT\UlQPh1RcR82WY\1gxQ0.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\uGTa3LCJnT\UlQPh1RcR82WY\3lfth77S0R Wpm6GyTL.gif.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\uGTa3LCJnT\UlQPh1RcR82WY\dwvO_oL5wG9f.png | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\ZrKgJJD.gif.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\_Xsp.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\EJ0UHp\3l-InIRqQiOsZWGu.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\EJ0UHp\dJsEYftG92zAtaz.flv.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\EJ0UHp\RenWTuGab6Fc7qSbS\a8AwJr7e8zC83.mp4.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\EJ0UHp\RenWTuGab6Fc7qSbS\cRE4.mp4.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\EJ0UHp\D_Y_mWn1p8ipYfjXHpn_.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\EJ0UHp\RenWTuGab6Fc7qSbS\JsWHJF1ceXN-F7HB5.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\jilWiA8_jW\hb83Wc0b.flv.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\jilWiA8_jW\ifQGThn.avi.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\jilWiA8_jW\N03oAf2CJF4H5ES.avi.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\jilWiA8_jW\RDXmfRE-VouSP6.avi.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\jilWiA8_jW\uN fiEdAHo0VBfS4emS\3j6lnWD2iiLSh5P8Qus.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\jilWiA8_jW\uN fiEdAHo0VBfS4emS\gIwtU-.mkv.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\jilWiA8_jW\uN fiEdAHo0VBfS4emS\HIPSXeLnDr.avi.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\jilWiA8_jW\uN fiEdAHo0VBfS4emS\HYXKIjIn.swf.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\jilWiA8_jW\uN fiEdAHo0VBfS4emS\JdLIRi8CM81z7CZXMLmh.mkv.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\jilWiA8_jW\uN fiEdAHo0VBfS4emS\P9C_r9pxhuf-A.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\jilWiA8_jW\uN fiEdAHo0VBfS4emS\xuQu0xo7-rgClLtX\lcsBz1BlcI.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\jilWiA8_jW\uN fiEdAHo0VBfS4emS\xuQu0xo7-rgClLtX\RtWq1YR6YWVPw.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\jilWiA8_jW\uN fiEdAHo0VBfS4emS\xuQu0xo7-rgClLtX\lcsBz1BlcI.mp4.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\jilWiA8_jW\XnDn.avi.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\qybdYBQm.swf | Modified File | Binary |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\zrrI 8P\3T__R4XLuWVp_\5ivn6VXEvHX0K7b.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\zrrI 8P\3T__R4XLuWVp_\tQP3AdhgtIEyFdgGovq.flv.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\zrrI 8P\hIdF485eJOBzjY.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\zrrI 8P\3T__R4XLuWVp_\RG7Nc.avi.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\zrrI 8P\SgVC1NERzDGqOHLP.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\zrrI 8P\RHfYAp4iFTI.mkv.crypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\2_y.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\FdV5 UwoXLQ.csv | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\FKlQd4kwD__P5I\4caPG5v.bmp.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\FKlQd4kwD__P5I\WJ4vLnFoRTTcZId.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\HbthB3jQFU5Y-AjNk\3b2UJTWoz6ufeXlyvISW.png.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\j722vbf_9c6.pps.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\mZQFpBApMY.mkv.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\nZcAIi.csv | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\pkjF7CobirRZAfwDqW.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\R8oLJG7HaM\3icwdXHwxyHA4vRA.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\R8oLJG7HaM\zsK7Tyj6OFZO2w.jpg.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\rFlbShIKO6.xlsx.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\RYKGI7S1qw5nsZ9RGHHZ.png.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\UDWu JchmovkMW.mp3.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\B2WwS.xlsx.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\ex0yzzZdMvZMWb5oP.docx.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\_sq_ e5DTD.swf.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\NtyXL63 JD.pptx | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\FbTAEINyMadIMg82TCw.docx.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\rMK5oPo1Ag.rtf.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\uIJewY frVZX9wY0Z2z2\Db1CWzTR.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\uIJewY frVZX9wY0Z2z2\AA7WI-0ERcyU\HJWs1YBHxBPTQCHH2Q.odp | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\_8SJtLW\4Vpbqavm_yuJ jhRY.pptx.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\_8SJtLW\b3-Xp23y2tCQVfIgfUz-\2-LkXdR3QAQc.ods.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\_8SJtLW\b3-Xp23y2tCQVfIgfUz-\5m0DQrr1Haz408KCThqf\0_-2dosY6Ya1iK-TDh\DSyrXWVCegiVWe.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\_8SJtLW\b3-Xp23y2tCQVfIgfUz-\5m0DQrr1Haz408KCThqf\0_-2dosY6Ya1iK-TDh\uEm-A36zUL.pptx.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\_8SJtLW\b3-Xp23y2tCQVfIgfUz-\feY4.ppt.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\wa4DIlfTXL3AOTf05\ypfcybJS\_8SJtLW\b3-Xp23y2tCQVfIgfUz-\wba4TGDIU14_.ots.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\ZM7E2pUAGp.xlsx.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Documents\ZUHt.docx.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE site on Microsoft.com.url | Modified File | Text |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Home.url | Modified File | Text |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft Store.url.crypted | Dropped File | Text |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Entertainment.url.crypted | Dropped File | Text |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSNBC News.url | Modified File | Text |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Links\Downloads.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Links\RecentPlaces.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\5k272oFhyqM0yt7I\f6QnSQ6d.mp3.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\5k272oFhyqM0yt7I\IltPMZE.mp3.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\5k272oFhyqM0yt7I\Vc-t29By6hfo-iZj2XDg.m4a.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\-vymBKk.m4a.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\FmHlph98Kx4634Gw6S\Gh5EemG6C1-kbGu.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\FmHlph98Kx4634Gw6S\hp6hL8K\sRKdRF8m9ZMW\itp9emm8tymg346g.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\FmHlph98Kx4634Gw6S\jk72PoPSae6I8JJAUZj\w1DbSomcsNE.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\FmHlph98Kx4634Gw6S\q_ZFszPd-Qz67G.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\kX1n2Xe4uKw\-MgDAYK0z.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\JXWmkX\m1 mEnSp52t.wav.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\QLs1xK\UzWFP0ndt2.mp3.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\S9k76DxGawRsOI.m4a.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Music\to BsoN2x7xRb.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\ntuser.ini.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\3OsNwneKQKhgA6sbZ.gif.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6awojlas2cZnv\AVZwnLmqhlVWG.gif.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6awojlas2cZnv\EtS _h68PSriZ.jpg.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\6awojlas2cZnv\KjHEn8WtqmnWqXr.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\iMLZwd4Mt.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\IttO.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\uGTa3LCJnT\aQmW2.png.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\uGTa3LCJnT\DM-dwtZxr\gwIa15KOiIB.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\uGTa3LCJnT\DM-dwtZxr\PjRT4ImxVAs6z3Bij.jpg.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\uGTa3LCJnT\DM-dwtZxr\wwtws9.bmp.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\uGTa3LCJnT\WrYL.gif.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Searches\Everywhere.search-ms | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Pictures\uGTa3LCJnT\UlQPh1RcR82WY\uodH_fySlW2.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Searches\Indexed Locations.search-ms.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\9G71itxwqF7N-a3T.mp4.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\EJ0UHp\QcUdBWF5bkWxAByPbG.mp4.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\EJ0UHp\xj5XTtEiJcf9TZamLjS.avi.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\jilWiA8_jW\dB9YwY\O6mLEbndz6QGzt-wts.mp4.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\EJ0UHp\hIbWzD.mkv.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\jilWiA8_jW\uN fiEdAHo0VBfS4emS\WJkXfc0y.avi.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\jilWiA8_jW\uN fiEdAHo0VBfS4emS\xuQu0xo7-rgClLtX\DhBkHbv tGKoCn7s.swf.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\jilWiA8_jW\uN fiEdAHo0VBfS4emS\xuQu0xo7-rgClLtX\ssuKoHkWRjOccPH1.mp4.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\zrrI 8P\3T__R4XLuWVp_\ROtrMwa4DrpBY.mp4.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\3Sh28JSd\zrrI 8P\Pmu0Y.flv.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Videos\BSnV-.mp4.crypted | Dropped File | Stream |
Not Queried
|
...
|
»
C:\\Users\5p5NrGJn0jS HALPmcxz\Desktop\HbthB3jQFU5Y-AjNk\read_me_lkdtt.txt | Dropped File | Stream |
Not Queried
|
...
|
»