VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Wiper
|
Threat Names: |
Trojan.GenericKD.34686589
Gen:Heur.Ransom.Imps.1
Gen:Trojan.Heur.JP.9uX@aKF!nih
...
|
kfjgxo.exe
Windows Exe (x86-32)
Created at 2020-10-09T10:33:00
Remarks (2/2)
(0x02000008): One or more processes crashed during the analysis. Analysis results may be incomplete.
(0x0200000E): The overall sleep time of all monitored processes was truncated from "5 minutes" to "10 seconds" to reveal dormant functionality.
Remarks
(0x0200000C): The maximum memory dump size was exceeded. Some dumps may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\kfjgxo.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x9381ee |
Size Of Code | 0x4800 |
Size Of Initialized Data | 0xf1600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-10-05 11:43:09+00:00 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x47b2 | 0x0 | 0x0 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 0.0 |
.rdata | 0x406000 | 0x205c | 0x0 | 0x0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.0 |
.data | 0x409000 | 0x18e0 | 0x0 | 0x0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.vmp0 | 0x40b000 | 0x4057ac | 0x0 | 0x0 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 0.0 |
.vmp1 | 0x811000 | 0x5f74e0 | 0x5f7600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.96 |
.rsrc | 0xe09000 | 0x1b2 | 0x200 | 0x5f7a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.47 |
Imports (6)
»
KERNEL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FindResourceA | 0x0 | 0x936000 | 0x923e0c | 0x51320c | 0x0 |
WTSAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WTSSendMessageW | 0x0 | 0x936008 | 0x923e14 | 0x513214 | 0x0 |
KERNEL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VirtualQuery | 0x0 | 0x936010 | 0x923e1c | 0x51321c | 0x0 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetUserObjectInformationW | 0x0 | 0x936018 | 0x923e24 | 0x513224 | 0x0 |
KERNEL32.dll (12)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LocalAlloc | 0x0 | 0x936020 | 0x923e2c | 0x51322c | 0x0 |
LocalFree | 0x0 | 0x936024 | 0x923e30 | 0x513230 | 0x0 |
GetModuleFileNameW | 0x0 | 0x936028 | 0x923e34 | 0x513234 | 0x0 |
GetProcessAffinityMask | 0x0 | 0x93602c | 0x923e38 | 0x513238 | 0x0 |
SetProcessAffinityMask | 0x0 | 0x936030 | 0x923e3c | 0x51323c | 0x0 |
SetThreadAffinityMask | 0x0 | 0x936034 | 0x923e40 | 0x513240 | 0x0 |
Sleep | 0x0 | 0x936038 | 0x923e44 | 0x513244 | 0x0 |
ExitProcess | 0x0 | 0x93603c | 0x923e48 | 0x513248 | 0x0 |
FreeLibrary | 0x0 | 0x936040 | 0x923e4c | 0x51324c | 0x0 |
LoadLibraryA | 0x0 | 0x936044 | 0x923e50 | 0x513250 | 0x0 |
GetModuleHandleA | 0x0 | 0x936048 | 0x923e54 | 0x513254 | 0x0 |
GetProcAddress | 0x0 | 0x93604c | 0x923e58 | 0x513258 | 0x0 |
USER32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetProcessWindowStation | 0x0 | 0x936054 | 0x923e60 | 0x513260 | 0x0 |
GetUserObjectInformationW | 0x0 | 0x936058 | 0x923e64 | 0x513264 | 0x0 |
Memory Dumps (109)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
buffer | 1 | 0x003A0000 | 0x003A0FFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x003A0000 | 0x003A0FFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x003B0000 | 0x003B0FFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x003B0000 | 0x003B0FFF | First Execution |
![]() |
32-bit | 0x003B0015 |
![]() |
![]() |
...
|
buffer | 1 | 0x003C0000 | 0x003C0FFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x003C0000 | 0x003C0FFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x003D0000 | 0x003D0FFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x003D0000 | 0x003D0FFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x003E0000 | 0x003E0FFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x003E0000 | 0x003E0FFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x003F0000 | 0x003F0FFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x003F0000 | 0x003F0FFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00E10000 | 0x00E10FFF | First Execution |
![]() |
32-bit | 0x00E1000F |
![]() |
![]() |
...
|
buffer | 1 | 0x00E10000 | 0x00E10FFF | Marked Executable |
![]() |
32-bit | 0x00E1000F |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | First Execution |
![]() |
32-bit | 0x026CB492 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026D38E0 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026CAFC0 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026CE1B5 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026D0319 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026D7AAB |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026D4BC1 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026CCAB3 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026D6C4A |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026C6E44 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026C86C8 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026E492F |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026C59E0 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026CFC8B |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026DBF28 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026D5000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026ED4DE |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x02689E07 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x02687C98 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x0268B353 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x0268A933 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026735EB |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026CD66C |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026D9CAE |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x02676413 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026B1F80 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x02696860 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x0267C934 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026A39E0 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x0267AC61 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026A6670 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x02688AA3 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x02691060 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026C1AD0 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026AD1E0 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026774F1 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026E2DD3 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026DA530 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026E1853 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026E3DFC |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026C91A8 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026DC757 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026DFBA3 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026DECF2 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026DD005 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026AFF00 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026B4950 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x0269F000 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x02688A2B |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x02674FA5 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026E2DD3 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026E1853 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026CE3A0 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026AC7D0 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026D9CAE |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026CA71B |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026E47E6 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026DA530 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026A4990 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026A5B60 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026C79DA |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026C5A70 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026E7412 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026AA6A0 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x0267B88F |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026AC7D0 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026D6F83 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026A3EA0 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026CCA6E |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x02684A58 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026DA530 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026A7650 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026A5B60 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026E4429 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026E7412 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026CE3A0 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026BD790 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026CB49C |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026D63A6 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026C85A6 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x0268B114 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026B8FB0 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x02671096 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026E2DD3 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026CCA6E |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026C91C7 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026774F1 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026AC7D0 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x02683922 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x0268E680 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026CA71B |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026DA530 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026A4990 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026A5B60 |
![]() |
![]() |
...
|
buffer | 1 | 0x02670000 | 0x02763FFF | Content Changed |
![]() |
32-bit | 0x026E7412 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.34686589 |
Malicious
|
C:\users\5p5nrgjn0js halpmcxz\documents\ftx4sxhibrx9ib1.docx.woodrat | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\programdata\package cache\{e512788e-c50b-3858-a4b9-73ad5f3f9e93}v14.10.25017\packages\vcruntimeadditional_amd64\cab1.cab.woodrat | Dropped File | Stream |
Unknown
|
...
|
»
C:\users\5p5nrgjn0js halpmcxz\documents\1rsl9u.xlsx.woodrat | Dropped File | Video |
Unknown
|
...
|
»
C:\users\5p5nrgjn0js halpmcxz\documents\2-ghz3e8x9ng.docx.woodrat | Dropped File | ZIP |
Unknown
|
...
|
»
C:\users\5p5nrgjn0js halpmcxz\documents\7ew7kda1xlecmji-np.pptx.woodrat | Dropped File | ZIP |
Unknown
|
...
|
»
C:\users\5p5nrgjn0js halpmcxz\documents\aeflwrk7e5o_uq-qos.pptx.woodrat | Dropped File | ZIP |
Unknown
|
...
|
»
C:\users\5p5nrgjn0js halpmcxz\documents\g9ndp0i9s 6om_.xlsx.woodrat | Dropped File | ZIP |
Unknown
|
...
|
»
C:\users\5p5nrgjn0js halpmcxz\documents\hmnjahve-o7.xlsx.woodrat | Dropped File | ZIP |
Unknown
|
...
|
»
C:\users\5p5nrgjn0js halpmcxz\documents\iucew4gepvyl2ya.pptx.woodrat | Dropped File | ZIP |
Unknown
|
...
|
»
C:\users\5p5nrgjn0js halpmcxz\documents\ltfcdbxx40tyuco.docx.woodrat | Dropped File | ZIP |
Unknown
|
...
|
»