VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Gen:Heur.Trickbot.3
Gen:Variant.Ser.Mikey.2021
|
arsdsr.exe
Windows Exe (x86-32)
Created 5 years ago
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\arsdsr.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x402cdb |
Size Of Code | 0x1e00 |
Size Of Initialized Data | 0x1600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-04-30 20:16:05+00:00 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1de0 | 0x1e00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.19 |
.rdata | 0x403000 | 0x134e | 0x1400 | 0x2200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.17 |
.data | 0x405000 | 0x104 | 0x200 | 0x3600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.27 |
Imports (1)
»
KERNEL32.dll (25)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitProcess | 0x0 | 0x403000 | 0x4114 | 0x3314 | 0x119 |
FindFirstFileW | 0x0 | 0x403004 | 0x4118 | 0x3318 | 0x139 |
HeapAlloc | 0x0 | 0x403008 | 0x411c | 0x331c | 0x2cb |
SetFilePointerEx | 0x0 | 0x40300c | 0x4120 | 0x3320 | 0x467 |
HeapFree | 0x0 | 0x403010 | 0x4124 | 0x3324 | 0x2cf |
WaitForSingleObject | 0x0 | 0x403014 | 0x4128 | 0x3328 | 0x4f9 |
GetLogicalDrives | 0x0 | 0x403018 | 0x412c | 0x332c | 0x209 |
GetProcessHeap | 0x0 | 0x40301c | 0x4130 | 0x3330 | 0x24a |
WriteFile | 0x0 | 0x403020 | 0x4134 | 0x3334 | 0x525 |
ReadFile | 0x0 | 0x403024 | 0x4138 | 0x3338 | 0x3c0 |
CreateFileW | 0x0 | 0x403028 | 0x413c | 0x333c | 0x8f |
GetFileSizeEx | 0x0 | 0x40302c | 0x4140 | 0x3340 | 0x1f1 |
GetLastError | 0x0 | 0x403030 | 0x4144 | 0x3344 | 0x202 |
SetLastError | 0x0 | 0x403034 | 0x4148 | 0x3348 | 0x473 |
MoveFileW | 0x0 | 0x403038 | 0x414c | 0x334c | 0x363 |
FindClose | 0x0 | 0x40303c | 0x4150 | 0x3350 | 0x12e |
lstrcmpiW | 0x0 | 0x403040 | 0x4154 | 0x3354 | 0x545 |
lstrcatW | 0x0 | 0x403044 | 0x4158 | 0x3358 | 0x53f |
FindNextFileW | 0x0 | 0x403048 | 0x415c | 0x335c | 0x145 |
CloseHandle | 0x0 | 0x40304c | 0x4160 | 0x3360 | 0x52 |
lstrcpyW | 0x0 | 0x403050 | 0x4164 | 0x3364 | 0x548 |
GetTempPathW | 0x0 | 0x403054 | 0x4168 | 0x3368 | 0x285 |
LoadLibraryA | 0x0 | 0x403058 | 0x416c | 0x336c | 0x33c |
CreateMutexA | 0x0 | 0x40305c | 0x4170 | 0x3370 | 0x9b |
GetCommandLineW | 0x0 | 0x403060 | 0x4174 | 0x3374 | 0x187 |
Digital Signatures (2)
»
Certificate: Svos Pty Limited
»
Issued by | Svos Pty Limited |
Parent Certificate | Sectigo RSA Code Signing CA |
Country Name | AU |
Valid From | 2020-04-24 00:00:00+00:00 |
Valid Until | 2021-04-24 23:59:59+00:00 |
Algorithm | sha256_rsa |
Serial Number | A2 F9 03 86 D3 77 F7 F9 13 35 45 4C 4D 7E FA 9A |
Thumbprint | 2C 88 39 29 05 AC 24 50 5B 7C 15 84 F4 9E AF A3 98 22 74 5C |
Certificate: Sectigo RSA Code Signing CA
»
Issued by | Sectigo RSA Code Signing CA |
Country Name | GB |
Valid From | 2018-11-02 00:00:00+00:00 |
Valid Until | 2030-12-31 23:59:59+00:00 |
Algorithm | sha384_rsa |
Serial Number | 1D A2 48 30 6F 9B 26 18 D0 82 E0 96 7D 33 D3 6A |
Thumbprint | 94 C9 5D A1 E8 50 BD 85 20 9A 4A 2A F3 E1 FB 16 04 F9 BB 66 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
arsdsr.exe | 1 | 0x00400000 | 0x00405FFF | Relevant Image |
![]() |
32-bit | 0x00401BF7 |
![]() |
![]() |
...
|
arsdsr.exe | 1 | 0x00400000 | 0x00405FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Trickbot.3 |
Malicious
|
C:/MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\branding.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\pss10r.chm.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\setup.chm.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\branding.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Setup.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPlusrWW.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjProrWW.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Setup.xml.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\4IYwkdk1gj 2DR.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\7XzLDIAQ\ThnWCLCBt.gif.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\8h d.csv | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\9Lm7cJqYP8NXI71qj.png.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\a8wUGSK.wav.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\c8KF4RFxjqbJeK.swf.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\cQmMoFz3.odt | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\F YK4 PMxMve7si5 sI.gif | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\j9O3dD.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\jy2fj9OToxS.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\NBlizqwzvzOCnk.xlsx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\plGXx-\1hUSW_AfObc55t.png.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\plGXx-\9_Ixx0UfvSYGaSqL QS.wav | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\plGXx-\b2jtLK76Bx.swf | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\plGXx-\Nto _6ZYl5a3vgqpp.doc.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\sdmxOVb VExjpA-U59hO.swf.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\_6fHsSKGxaaF_3ovS\BWPNV.ots | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\_6fHsSKGxaaF_3ovS\lD1nXuqIF.avi.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\1tzKSsYVLnjt.xlsx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\2M0NVS5En5W\J4NCeSeR.xlsx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\afoAtlv7qwBY7ACNkxWw.docx | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\Bk4kizkgWa\BruxE7OiJn6.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\Bk4kizkgWa\YQOkdNBO_856WnMN\Kb-m\2OIOMddl.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\Bk4kizkgWa\YQOkdNBO_856WnMN\Kb-m\aZ8e0Ld0z\57WDU8A6n.xls | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\Bk4kizkgWa\YQOkdNBO_856WnMN\Kb-m\aZ8e0Ld0z\eHZTkE.ods | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\Bk4kizkgWa\YQOkdNBO_856WnMN\Kb-m\aZ8e0Ld0z\HDVLjZ3ShqtF.csv.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\Bk4kizkgWa\YQOkdNBO_856WnMN\Kb-m\aZ8e0Ld0z\xd1gnEP a8wg_\1uzealkfywlQgvf.csv.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\Bk4kizkgWa\YQOkdNBO_856WnMN\Kb-m\aZ8e0Ld0z\xd1gnEP a8wg_\PdOxX1m1M0iigGy.ots | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\Bk4kizkgWa\YQOkdNBO_856WnMN\Kb-m\uiXcEdbTotwVNN.ods | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\cDV0nF7Jj Uo2i92U\Dt5iQGE SpB1e2.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\cDV0nF7Jj Uo2i92U\eF Em.pps.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\cDV0nF7Jj Uo2i92U\usv8d-WwNuJ.odt | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\gnFu0xP-R5e.pptx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\hXl6FO224kZ4lZ dB.xls.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\ioA3l84DWMmZk70a4Z.docx | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\jK7JOPKq1fVD16ZSuE70.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\KqQs5jnxQZyyKeS.xlsx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\le5oDZK 0ByC1xDR5Xc5.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\lohmqPwxW5c2V6W9W.docx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\Favorites.vss | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\OymUVWYw.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\pAoe_noDDZyBNR41.odt | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\PhI0irjG7.pptx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\x3OIQRAcNV5 6d.pptx.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\ZE64.docx | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Links\RecentPlaces.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\1CD0SbkBI.wav.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\GCchq\S1XIz\-_yrUV40hG3synfu.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\GCchq\S1XIz\bHkPJrADYUm6TjF.m4a.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\GCchq\S1XIz\HgxYFArFpEB94qIOgGhV\6IePv9oR3FdtHA2q.m4a.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\GCchq\S1XIz\HgxYFArFpEB94qIOgGhV\J708i2ZnnH9.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\GCchq\S1XIz\HgxYFArFpEB94qIOgGhV\KpUdTBJb3w3GrYz.wav | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\GCchq\S1XIz\HgxYFArFpEB94qIOgGhV\SybeS.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\GCchq\S1XIz\HgxYFArFpEB94qIOgGhV\ZuLAilXUctuhbjdK51.m4a.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\GCchq\S1XIz\ZMJnq4AyBwW_Ef.wav | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\I4kPj\8xWLxx8VHf9p-.wav.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\I4kPj\9tQF7vTGgr6.wav | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\I4kPj\Er103hX QTFj5eUqG.wav | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\I4kPj\ZNSOM-ccxidfZCPHVK.m4a.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\ixEQR2kK9qrkUVqy7xY.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\VwYkmY_OUr.wav | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\-7GF43Bqd40EkN.png.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\3cuUtRep2N_ha_P Fn9.bmp.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\4u3Odj_V3s3t.gif | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\1POmGc9c\3SMOvRT9Qd.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\1POmGc9c\a6uDdrrXX2iKdxG4nZa.png | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\1POmGc9c\OJSDcgvJ7QYZh\3f2PQG.png | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\1POmGc9c\OJSDcgvJ7QYZh\6gGPAORgGoA3.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\1POmGc9c\OJSDcgvJ7QYZh\wBUhA1LzN6CL.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\1POmGc9c\OJSDcgvJ7QYZh\z2yAK2EZnPKhKlRvpK.gif | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\1POmGc9c\pGSGRrzfIwBBfb.gif.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\1POmGc9c\rMts7wxti\bGgGhiT.gif.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\1POmGc9c\rMts7wxti\CtHTE0PEy.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\1POmGc9c\rMts7wxti\d5af6-5l3w.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\1POmGc9c\rMts7wxti\L7EKR.png | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\1POmGc9c\rMts7wxti\QltoyVBmQzFR.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\1POmGc9c\rMts7wxti\wu4JnlA\5b63GS_FXYxiq0kdWzh.png | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\1POmGc9c\rMts7wxti\wu4JnlA\iFbp2a_-a.gif.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\1POmGc9c\rMts7wxti\wu4JnlA\q8QHDzZOQliL7f3Y.bmp.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\1POmGc9c\S4H-ht39OoZ.png.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\IQND JDpAIP.bmp.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\HPDFcMjZlwUnIoW.gif.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\k39VO.png.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\LIl1rW-b1p8kKK9RqLv.gif.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\LuSpGx9q.jpg.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\pLqndGw.gif | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\sM fyD56UIoXA0Vt.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\ghq_bJyyoBo\6KQNtydP8f.mkv.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\ghq_bJyyoBo\BokOXLpFeKotVq.swf | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\ghq_bJyyoBo\eISQCTxkPNmfB.avi | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\ghq_bJyyoBo\iK_2PblzI LnIeD7gD.flv.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\ghq_bJyyoBo\kzpRir.flv | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\ghq_bJyyoBo\MDLOs9exXY.flv | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\ghq_bJyyoBo\N02avdZBZY.flv | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\ghq_bJyyoBo\q_Q2th.mkv.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\ghq_bJyyoBo\SREEgmX1fWW-m-.swf.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\ghq_bJyyoBo\uklfuhm_mXhv.avi.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\ghq_bJyyoBo\WYaejJiwLrd0.mkv.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\ghq_bJyyoBo\_H 3n440vw-zqF0.avi.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\Mc6cTML2aESFrr.flv | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\OUMBCbqQCQxoqlxRj.avi.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\s0rbk04L68y5WVLpbqKf.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\u5rYaBKyN.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Adobe\Acrobat\10.0\Replicate\Security\directories.acrodata.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Adobe\ARM\Reader_10.0.0\AdbeRdrSecUpd10111.msp.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Adobe\ARM\Reader_10.0.0\AdbeRdrUpd10110_MUI.msp.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Adobe\ARM\Reader_10.0.0\AdbeRdrUpd10116_MUI.msp.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help_CValidator.H1D.OFFWHITE | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_AssetId.H1W.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help_MTOC_help.H1H.OFFWHITE | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3388679973-3930757225-3770151564-1000\8de6a3e28b34ce2307b3688fc9d4e39d_0303d5b4-ffe9-470e-9dd8-7d9ec416e53f | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\Setup.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\Setup.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\Setup.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\ShellUI.MST | Modified File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.xml.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Office32WW.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:/Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\boot.sdi.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\Winre.wim.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\2t8A7p6OhuLdYQgit MB.pps.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\5htH-odBM4.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\cuvk.png | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\dmCXiw2m.odt.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\GlsYptB0D -eCjT5KGU.swf.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\IWfTOYIvF.gif.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\NNjRk9HesHLZ0x.m4a.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\OdweMCCYu.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\on4Rkp8XBzEJR_5fGm.doc | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\qk5UTmohXRBUkoH9DH.docx.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\v1c0.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\ypJ6NL.ppt | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\ZCTLzVl.png.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\_6fHsSKGxaaF_3ovS\6v-EBPmoucsfP9t_fqM.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\_6fHsSKGxaaF_3ovS\pLTpKKda0j9zNUYoUNt.csv.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\_6fHsSKGxaaF_3ovS\QkrA8bST.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\0HVUia0H x82oF_m.pptx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\2M0NVS5En5W\32slVm7ULnxS8 f.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\2M0NVS5En5W\va-_cNM.pps | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\2M0NVS5En5W\VCmGgM.docx.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\2UKzlZ9bQNK5koLl.ots | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\6Us_sQry_.xlsx.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\aeBzMg.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\Bk4kizkgWa\gIqXJ5XX6-R6oIcI.pps | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\Bk4kizkgWa\JbRQehqW843y2LIP.ppt | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\Bk4kizkgWa\YQOkdNBO_856WnMN\6_7iD8vaRX7uGf.csv.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\Bk4kizkgWa\YQOkdNBO_856WnMN\Kb-m\1gOoMn6OavxQS DKMbMx\D1mhwLt2fzb_YQ.ots | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\Bk4kizkgWa\YQOkdNBO_856WnMN\Kb-m\1gOoMn6OavxQS DKMbMx\drzrlM01uFTKeBD_.pptx.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\Bk4kizkgWa\YQOkdNBO_856WnMN\Kb-m\1gOoMn6OavxQS DKMbMx\GLys.odt | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\Bk4kizkgWa\YQOkdNBO_856WnMN\Kb-m\aZ8e0Ld0z\xd1gnEP a8wg_\DiHsZd6k 1.pdf.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\Bk4kizkgWa\YQOkdNBO_856WnMN\Kb-m\aZ8e0Ld0z\xd1gnEP a8wg_\me1jQJbh7TN.ods.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\Bk4kizkgWa\YQOkdNBO_856WnMN\Kb-m\g38ZPKTnVtQWvlgJ_n4u.ppt.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\Bk4kizkgWa\YQOkdNBO_856WnMN\VxSJ3_sEBOK94bD.rtf.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\Lrut.xlsx.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\MqUmO01DR.odt | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\_private\folder.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\VL3gDMu5soDiZ1.pptx.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\xz5sGvyKz.docx.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Links\Desktop.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Links\Downloads.lnk.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\bX5md6vIXDhODOwWo.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\GCchq\S1XIz\43T09WZ_FEGR.m4a.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\GCchq\S1XIz\8cowzPVWhrDOm.m4a.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\GCchq\S1XIz\HgxYFArFpEB94qIOgGhV\of3LtF9siYb.m4a.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\GCchq\S1XIz\HgxYFArFpEB94qIOgGhV\p7YMJ.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\GCchq\S1XIz\HgxYFArFpEB94qIOgGhV\uxxh9U0Y1S788kk.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\GCchq\S1XIz\JjQuldAU4LEb0.wav.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\GCchq\S1XIz\m_S itN7UtH7W8lpF.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\GCchq\S1XIz\nJ5q3Y TzGq\Fn-s5T7t.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\GCchq\S1XIz\Rf00y5uBh7GsGkEbl2.m4a.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\I4kPj\9LQCxIk.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\1POmGc9c\OJSDcgvJ7QYZh\cLZ7.png.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\1POmGc9c\OJSDcgvJ7QYZh\EMZiJcO8LeV0.jpg.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\1POmGc9c\OJSDcgvJ7QYZh\k3RDFcVCi.png | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\1POmGc9c\OJSDcgvJ7QYZh\TBK5zi94dC3.png.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\1POmGc9c\rMts7wxti\UZ2t6gfaTvl_D.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\1POmGc9c\rMts7wxti\wu4JnlA\HtoccuJZ.gif.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\1POmGc9c\rMts7wxti\wu4JnlA\YJ5669616Mniq7E9dpnm.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\1POmGc9c\SSMFTzSnPYwJ.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\A1qTK9cy1E.bmp.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\OzBE1DyfZRPxwh.bmp.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\P9I9zKS6HYWGr1wex.jpg.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\S2Z69ozOVHr.jpg.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\gNEccgvDLtY7H2sg3p04\sjGrPVv-AkezS.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\Whqyq9.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\a7HknCSYOB7s_zZFQES.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\BbLdFAbs w.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\ghq_bJyyoBo\5TkndxEimBTBrX.avi.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\ghq_bJyyoBo\7iQCRd5AR4Xf2Q-Uv.flv.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\ghq_bJyyoBo\Ir7-A8jPj19v9LpDYlkm.swf | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\ghq_bJyyoBo\It-VEdB.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\ghq_bJyyoBo\KqOQsT0eQZ0rM.swf | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\ghq_bJyyoBo\LjBRMR KYHdS.mkv.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\ghq_bJyyoBo\w1zsv5pVGgKsXbT6wKb.avi.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\ghq_bJyyoBo\yG3kqDuYJMcrHbcT0.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\l0LFbZm.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\p1bx.flv.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\SWT0TXyvaYgE.swf.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\SyZ1UR VgbXB1VAP.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\uT-0.flv.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_BestBet.H1W.OFFWHITE | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help_MValidator.H1D.OFFWHITE | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help_MValidator.Lck.OFFWHITE | Modified File | Stream |
Not Queried
|
...
|
»