VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware |
eset.exe
Windows Exe (x86-32)
Created at 2019-11-10T23:06:00
Remarks
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Adobe\Acrobat\10.0\JavaScripts\glob.settings.js | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
JS_High_Entropy | JavaScript has a high entropy; possible obfuscation | - |
4/5
|
...
|
C:\Boot\el-GR\\DECRYPT-FILES.txt | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
Sodinokibi_RansomNote | Sodinokibi ransomware note | - |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\eset.exe | Sample File | Binary |
Unknown
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x401375 |
Size Of Code | 0xa600 |
Size Of Initialized Data | 0xda600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-10-14 22:51:34+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xa544 | 0xa600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.68 |
.rdata | 0x40c000 | 0x4f50 | 0x5000 | 0xaa00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.68 |
.data | 0x411000 | 0x2f80 | 0x1200 | 0xfa00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.36 |
.rsrc | 0x414000 | 0xd1688 | 0xd1800 | 0x10c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.18 |
.reloc | 0x4e6000 | 0xdd4 | 0xe00 | 0xe2400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.44 |
Imports (1)
»
KERNEL32.dll (69)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FindResourceA | 0x0 | 0x40c000 | 0x10944 | 0xf344 | 0x186 |
LoadResource | 0x0 | 0x40c004 | 0x10948 | 0xf348 | 0x3ab |
LoadLibraryW | 0x0 | 0x40c008 | 0x1094c | 0xf34c | 0x3a8 |
SizeofResource | 0x0 | 0x40c00c | 0x10950 | 0xf350 | 0x54f |
ExitThread | 0x0 | 0x40c010 | 0x10954 | 0xf354 | 0x152 |
GetProcAddress | 0x0 | 0x40c014 | 0x10958 | 0xf358 | 0x29d |
VirtualAlloc | 0x0 | 0x40c018 | 0x1095c | 0xf35c | 0x599 |
LockResource | 0x0 | 0x40c01c | 0x10960 | 0xf360 | 0x3bd |
CreateThread | 0x0 | 0x40c020 | 0x10964 | 0xf364 | 0xe8 |
GetCommandLineA | 0x0 | 0x40c024 | 0x10968 | 0xf368 | 0x1c8 |
IsDebuggerPresent | 0x0 | 0x40c028 | 0x1096c | 0xf36c | 0x367 |
IsProcessorFeaturePresent | 0x0 | 0x40c02c | 0x10970 | 0xf370 | 0x36d |
GetLastError | 0x0 | 0x40c030 | 0x10974 | 0xf374 | 0x250 |
HeapFree | 0x0 | 0x40c034 | 0x10978 | 0xf378 | 0x333 |
HeapAlloc | 0x0 | 0x40c038 | 0x1097c | 0xf37c | 0x32f |
EncodePointer | 0x0 | 0x40c03c | 0x10980 | 0xf380 | 0x121 |
DecodePointer | 0x0 | 0x40c040 | 0x10984 | 0xf384 | 0xfe |
RaiseException | 0x0 | 0x40c044 | 0x10988 | 0xf388 | 0x43f |
SetLastError | 0x0 | 0x40c048 | 0x1098c | 0xf38c | 0x50a |
GetCurrentThreadId | 0x0 | 0x40c04c | 0x10990 | 0xf390 | 0x20e |
ExitProcess | 0x0 | 0x40c050 | 0x10994 | 0xf394 | 0x151 |
GetModuleHandleExW | 0x0 | 0x40c054 | 0x10998 | 0xf398 | 0x266 |
MultiByteToWideChar | 0x0 | 0x40c058 | 0x1099c | 0xf39c | 0x3d1 |
WideCharToMultiByte | 0x0 | 0x40c05c | 0x109a0 | 0xf3a0 | 0x5cb |
GetProcessHeap | 0x0 | 0x40c060 | 0x109a4 | 0xf3a4 | 0x2a2 |
GetStdHandle | 0x0 | 0x40c064 | 0x109a8 | 0xf3a8 | 0x2c0 |
GetFileType | 0x0 | 0x40c068 | 0x109ac | 0xf3ac | 0x23e |
DeleteCriticalSection | 0x0 | 0x40c06c | 0x109b0 | 0xf3b0 | 0x105 |
GetStartupInfoW | 0x0 | 0x40c070 | 0x109b4 | 0xf3b4 | 0x2be |
GetModuleFileNameA | 0x0 | 0x40c074 | 0x109b8 | 0xf3b8 | 0x262 |
WriteFile | 0x0 | 0x40c078 | 0x109bc | 0xf3bc | 0x5df |
GetModuleFileNameW | 0x0 | 0x40c07c | 0x109c0 | 0xf3c0 | 0x263 |
QueryPerformanceCounter | 0x0 | 0x40c080 | 0x109c4 | 0xf3c4 | 0x42d |
GetCurrentProcessId | 0x0 | 0x40c084 | 0x109c8 | 0xf3c8 | 0x20a |
GetSystemTimeAsFileTime | 0x0 | 0x40c088 | 0x109cc | 0xf3cc | 0x2d6 |
GetEnvironmentStringsW | 0x0 | 0x40c08c | 0x109d0 | 0xf3d0 | 0x227 |
FreeEnvironmentStringsW | 0x0 | 0x40c090 | 0x109d4 | 0xf3d4 | 0x19d |
UnhandledExceptionFilter | 0x0 | 0x40c094 | 0x109d8 | 0xf3d8 | 0x580 |
SetUnhandledExceptionFilter | 0x0 | 0x40c098 | 0x109dc | 0xf3dc | 0x541 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x40c09c | 0x109e0 | 0xf3e0 | 0x348 |
Sleep | 0x0 | 0x40c0a0 | 0x109e4 | 0xf3e4 | 0x550 |
GetCurrentProcess | 0x0 | 0x40c0a4 | 0x109e8 | 0xf3e8 | 0x209 |
TerminateProcess | 0x0 | 0x40c0a8 | 0x109ec | 0xf3ec | 0x55f |
TlsAlloc | 0x0 | 0x40c0ac | 0x109f0 | 0xf3f0 | 0x571 |
TlsGetValue | 0x0 | 0x40c0b0 | 0x109f4 | 0xf3f4 | 0x573 |
TlsSetValue | 0x0 | 0x40c0b4 | 0x109f8 | 0xf3f8 | 0x574 |
TlsFree | 0x0 | 0x40c0b8 | 0x109fc | 0xf3fc | 0x572 |
GetModuleHandleW | 0x0 | 0x40c0bc | 0x10a00 | 0xf400 | 0x267 |
EnterCriticalSection | 0x0 | 0x40c0c0 | 0x10a04 | 0xf404 | 0x125 |
LeaveCriticalSection | 0x0 | 0x40c0c4 | 0x10a08 | 0xf408 | 0x3a2 |
IsValidCodePage | 0x0 | 0x40c0c8 | 0x10a0c | 0xf40c | 0x372 |
GetACP | 0x0 | 0x40c0cc | 0x10a10 | 0xf410 | 0x1a4 |
GetOEMCP | 0x0 | 0x40c0d0 | 0x10a14 | 0xf414 | 0x286 |
GetCPInfo | 0x0 | 0x40c0d4 | 0x10a18 | 0xf418 | 0x1b3 |
LoadLibraryExW | 0x0 | 0x40c0d8 | 0x10a1c | 0xf41c | 0x3a7 |
RtlUnwind | 0x0 | 0x40c0dc | 0x10a20 | 0xf420 | 0x4ac |
OutputDebugStringW | 0x0 | 0x40c0e0 | 0x10a24 | 0xf424 | 0x3fa |
HeapReAlloc | 0x0 | 0x40c0e4 | 0x10a28 | 0xf428 | 0x336 |
GetStringTypeW | 0x0 | 0x40c0e8 | 0x10a2c | 0xf42c | 0x2c5 |
HeapSize | 0x0 | 0x40c0ec | 0x10a30 | 0xf430 | 0x338 |
LCMapStringW | 0x0 | 0x40c0f0 | 0x10a34 | 0xf434 | 0x396 |
FlushFileBuffers | 0x0 | 0x40c0f4 | 0x10a38 | 0xf438 | 0x192 |
GetConsoleCP | 0x0 | 0x40c0f8 | 0x10a3c | 0xf43c | 0x1dc |
GetConsoleMode | 0x0 | 0x40c0fc | 0x10a40 | 0xf440 | 0x1ee |
SetStdHandle | 0x0 | 0x40c100 | 0x10a44 | 0xf444 | 0x520 |
SetFilePointerEx | 0x0 | 0x40c104 | 0x10a48 | 0xf448 | 0x4fc |
WriteConsoleW | 0x0 | 0x40c108 | 0x10a4c | 0xf44c | 0x5de |
CloseHandle | 0x0 | 0x40c10c | 0x10a50 | 0xf450 | 0x7f |
CreateFileW | 0x0 | 0x40c110 | 0x10a54 | 0xf454 | 0xc2 |
Digital Signatures (3)
»
Certificate: BITBACK LIMITED
»
Issued by | BITBACK LIMITED |
Parent Certificate | DigiCert EV Code Signing CA (SHA2) |
Country Name | GB |
Valid From | 2019-09-03 00:00:00+00:00 |
Valid Until | 2020-05-07 12:00:00+00:00 |
Algorithm | sha256_rsa |
Serial Number | 02 11 26 DB C0 DD E4 A2 63 FA DA 6C 29 A8 16 22 |
Thumbprint | 77 C5 82 46 26 00 C9 92 28 95 64 65 A8 80 15 03 32 0F 0C F8 |
Certificate: DigiCert EV Code Signing CA (SHA2)
»
Issued by | DigiCert EV Code Signing CA (SHA2) |
Parent Certificate | DigiCert High Assurance EV Root CA |
Country Name | US |
Valid From | 2012-04-18 12:00:00+00:00 |
Valid Until | 2027-04-18 12:00:00+00:00 |
Algorithm | sha256_rsa |
Serial Number | 03 F1 B4 E1 5F 3A 82 F1 14 96 78 B3 D7 D8 47 5C |
Thumbprint | 60 EE 3F C5 3D 4B DF D1 69 7A E5 BE AE 1C AB 1C 0F 3A D4 E3 |
Certificate: DigiCert High Assurance EV Root CA
»
Issued by | DigiCert High Assurance EV Root CA |
Country Name | US |
Valid From | 2006-11-10 00:00:00+00:00 |
Valid Until | 2031-11-10 00:00:00+00:00 |
Algorithm | sha1_rsa |
Serial Number | 02 AC 5C 26 6A 0B 40 9B 8F 0B 79 F2 AE 46 25 77 |
Thumbprint | 5F B7 EE 06 33 E2 59 DB AD 0C 4C 9A E6 D3 8F 1A 61 C7 DC 25 |
Memory Dumps (27)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
eset.exe | 1 | 0x01340000 | 0x01426FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x002A0000 | 0x002FAFFF | First Execution | - | 32-bit | 0x002A0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x00070000 | 0x000CBFFF | Marked Executable | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00070000 | 0x000CBFFF | Marked Executable | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00070000 | 0x000CBFFF | Marked Executable | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00070000 | 0x000CBFFF | Marked Executable | - | 32-bit | 0x00091A40 |
![]() |
![]() |
...
|
buffer | 1 | 0x00070000 | 0x000CBFFF | Content Changed | - | 32-bit | 0x00071520 |
![]() |
![]() |
...
|
buffer | 1 | 0x00070000 | 0x000CBFFF | Marked Executable | - | 32-bit | 0x0009FC10 |
![]() |
![]() |
...
|
ntdll.dll | 1 | 0x77130000 | 0x772AFFFF | Content Changed | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00070000 | 0x000CBFFF | Content Changed | - | 32-bit | 0x00095770 |
![]() |
![]() |
...
|
buffer | 1 | 0x00070000 | 0x000CBFFF | Content Changed | - | 32-bit | 0x0009F390 |
![]() |
![]() |
...
|
buffer | 1 | 0x00070000 | 0x000CBFFF | Content Changed | - | 32-bit | 0x00097504 |
![]() |
![]() |
...
|
buffer | 1 | 0x00070000 | 0x000CBFFF | Content Changed | - | 32-bit | 0x00094990 |
![]() |
![]() |
...
|
eset.exe | 1 | 0x01340000 | 0x01426FFF | Final Dump | - | 32-bit | - |
![]() |
![]() |
...
|
eset.exe | 12 | 0x00D10000 | 0x00DF6FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 12 | 0x00260000 | 0x002BAFFF | First Execution | - | 32-bit | 0x00260000 |
![]() |
![]() |
...
|
buffer | 12 | 0x000B0000 | 0x0010BFFF | Marked Executable | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 12 | 0x000B0000 | 0x0010BFFF | Marked Executable | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 12 | 0x000B0000 | 0x0010BFFF | Marked Executable | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 12 | 0x000B0000 | 0x0010BFFF | Marked Executable | - | 32-bit | 0x000D1A40 |
![]() |
![]() |
...
|
buffer | 12 | 0x000B0000 | 0x0010BFFF | Content Changed | - | 32-bit | 0x000B1520 |
![]() |
![]() |
...
|
buffer | 12 | 0x000B0000 | 0x0010BFFF | Marked Executable | - | 32-bit | 0x000DFC10 |
![]() |
![]() |
...
|
ntdll.dll | 12 | 0x77620000 | 0x7779FFFF | Content Changed | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 12 | 0x000B0000 | 0x0010BFFF | Content Changed | - | 32-bit | 0x000D5770 |
![]() |
![]() |
...
|
buffer | 12 | 0x000B0000 | 0x0010BFFF | Content Changed | - | 32-bit | 0x000DF390 |
![]() |
![]() |
...
|
buffer | 12 | 0x000B0000 | 0x0010BFFF | Content Changed | - | 32-bit | 0x000D4990 |
![]() |
![]() |
...
|
eset.exe | 12 | 0x00D10000 | 0x00DF6FFF | Final Dump | - | 32-bit | - |
![]() |
![]() |
...
|
C:\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\boot.sdi.VKaq | Dropped File | Stream |
Unknown
|
...
|
»
C:\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\Winre.wim.5e2j5 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\1ek gB-.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\1v9OFDiJWPm8MHHQ.odt.3uxU | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\5hXhWeztPrf9ZQC1Z.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\6pO6mQLU.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\7bIriEMdRI7QK.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\7zAz7ryW DljTX1J.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\9hYC b9 OAgc.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Adobe\Acrobat\10.0\Security\addressbook.acrodata | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Adobe\Acrobat\10.0\Security\CRLCache\48B76449F3D5FEFA1133AA805E420F0FCA643651.crl | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Adobe\Acrobat\10.0\Security\CRLCache\A9B8213768ADC68AF64FCC6409E8BE414726687F.crl | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\ajTbqxKluAP5yMsiQz.mkv.YBZH | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\akDBjfYtmaT.m4a.LjQ5 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\b5XS GJUXmYXlZvRSW-.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\CXtBKJuR4xY5m c.swf.AQz6V3 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\D2zhG8jS.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\DNJ0jH17yLgW1.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\ebf4.png.3wy7f | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\egrSO1kCzE_TcvnPlFJT.png.PTVsU | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\ewVB7V5Jhjl32Wfh.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\ISBknX_Ny.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\ISyuUqVLVoKe2TYf1F.mkv.IOj6 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\jO2V.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\khORsonbXGYfkGp.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\L0RHGHT3eFgSHF.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\lxivA.wav.NGeQd3o | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol.5jisz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3388679973-3930757225-3770151564-1000\83aa4cc77f591dfc2374580bbd95f6ba_0303d5b4-ffe9-470e-9dd8-7d9ec416e53f | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3388679973-3930757225-3770151564-1000\932a2db58c237abd381d22df4c63a04a_0303d5b4-ffe9-470e-9dd8-7d9ec416e53f | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3388679973-3930757225-3770151564-1000\fda992c8d564f97e48410a19a2e459f6_0303d5b4-ffe9-470e-9dd8-7d9ec416e53f.5GnPv | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Document Building Blocks\1033\14\Built-In Building Blocks.dotx.zOBM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Internet Explorer\UserData\Low\index.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\MS Project\14\1033\Global.MPT | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Office\MSO1033.acl.DmSyl0G | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Office\Recent\index.dat.EhK9 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Outlook\Outlook.srs.Kws2mc | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Outlook\Outlook.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Protect\CREDHIST.FV3Rc5O | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Protect\S-1-5-21-3111613574-2524581245-2586426736-500\be5b4fbd-cb99-45f5-9462-5f896dd3a6b9.HyGSa | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Protect\S-1-5-21-3111613574-2524581245-2586426736-500\Preferred | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Protect\S-1-5-21-3388679973-3930757225-3770151564-1000\02540a10-7eb7-4b20-a8c7-470f8986389c | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Protect\S-1-5-21-3388679973-3930757225-3770151564-1000\0e15476d-d8fe-46ca-8099-ebdcf80f637c.WsWuyFb | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Protect\S-1-5-21-3388679973-3930757225-3770151564-1000\102a7bc8-3f85-4bb4-840a-38257d2965d2.TqgX4 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Protect\S-1-5-21-3388679973-3930757225-3770151564-1000\2be989a0-16a1-424b-9211-51aa3bb43e5d.JR60f | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Protect\S-1-5-21-3388679973-3930757225-3770151564-1000\fbbe72db-afd8-443b-88dd-64b20388700d.ZVKiUJ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Protect\S-1-5-21-3388679973-3930757225-3770151564-1000\Preferred | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Protect\SYNCHIST | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml.Y2TS7 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Templates\Normal.dotm.uzvY | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\UProof\CUSTOM.DIC.iKD45 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\5p5nrgjn0js_halpmcxz@adobe[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\5p5nrgjn0js_halpmcxz@adobe[3].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\5p5nrgjn0js_halpmcxz@demdex[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\5p5nrgjn0js_halpmcxz@dpm.demdex[2].txt.b13FyW | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\5p5nrgjn0js_halpmcxz@everesttech[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\5p5nrgjn0js_halpmcxz@google[2].txt.ERE4J | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\5p5nrgjn0js_halpmcxz@ml314[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\5p5nrgjn0js_halpmcxz@rlcdn[2].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@ad13.adfarm1.adition[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@adfarm1.adition[2].txt.knweQ | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@adformdsp[1].txt.az6Ur | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@adform[1].txt.qawmOn | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@adnxs[1].txt.eRBU2tN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@adtech[2].txt.W6sw | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@adtr02[1].txt.khk4R | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@advertising[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@api.bing[2].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@at.atwola[1].txt.r1r5 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@bing[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@c.bing[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@c.msn[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@doubleclick[2].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@google[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@google[3].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@google[4].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@linkedin[1].txt.eVBeLFp | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@m.exactag[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@msn[1].txt.67drq | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@scorecardresearch[2].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@server.adformdsp[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@skadtec[1].txt.dIEr | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@track.adform[2].txt.mqpz | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@www.bing[2].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@www.linkedin[1].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\5p5nrgjn0js_halpmcxz@www.msn[2].txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat.Qb6J | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Libraries\Documents.library-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Libraries\Music.library-ms.0qY76lu | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Libraries\Pictures.library-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Libraries\Videos.library-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\PrivacIE\index.dat.d19Plni | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\PrivacIE\Low\index.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\1b4dd67f29cb1962.automaticDestinations-ms.9EgtdW | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\7e4dca80246863e3.automaticDestinations-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\eb282ead62b4db87.automaticDestinations-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\1b4dd67f29cb1962.customDestinations-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms.l1Nd7a | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5afe4de1b92fc382.customDestinations-ms.MauxC1C | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\5d696d521de238c3.customDestinations-ms.5lJAv | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\7e4dca80246863e3.customDestinations-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\be71009ff8bb02a2.customDestinations-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\SendTo\Compressed (zipped) Folder.ZFSendToTarget | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\SendTo\Desktop (create shortcut).DeskLink.ioFfZl | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\SendTo\Mail Recipient.MAPIMail | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg.oUmSVd | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Mozilla\Firefox\Crash Reports\InstallTime20131025151332.XEV9dX | Dropped File | Stream |
Unknown
|
...
|
»