VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Gen:Trojan.Heur.tmuarqMnfcci
Gen:Trojan.Heur.zn1@rWas1gdi
Gen:Trojan.Heur.zn1@rusZeGgi
|
svchost.exe
Windows Exe (x86-32)
Created at 2020-05-05T15:52:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\svchost.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x56425a |
Size Of Code | 0x126000 |
Size Of Initialized Data | 0x30e00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-05-05 13:59:38+00:00 |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | Host Process for Windows Services |
FileVersion | 6.3.9600.17625 |
InternalName | svchost.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | svchost.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 6.3.9600.17415 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.MPRESS1 | 0x401000 | 0x163000 | 0x4c200 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 8.0 |
.MPRESS2 | 0x564000 | 0xe00 | 0xe00 | 0x4c400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.04 |
.rsrc | 0x565000 | 0xd7c | 0xe00 | 0x4d200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.57 |
Imports (7)
»
KERNEL32.DLL (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetModuleHandleA | 0x0 | 0x56413c | 0x16413c | 0x4c53c | 0x0 |
GetProcAddress | 0x0 | 0x564140 | 0x164140 | 0x4c540 | 0x0 |
shell32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x564148 | 0x164148 | 0x4c548 | 0x0 |
version.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VerQueryValueW | 0x0 | 0x564150 | 0x164150 | 0x4c550 | 0x0 |
user32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CharNextW | 0x0 | 0x564158 | 0x164158 | 0x4c558 | 0x0 |
oleaut32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VariantCopy | 0x0 | 0x564160 | 0x164160 | 0x4c560 | 0x0 |
netapi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetWkstaGetInfo | 0x0 | 0x564168 | 0x164168 | 0x4c568 | 0x0 |
advapi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegLoadKeyW | 0x0 | 0x564170 | 0x164170 | 0x4c570 | 0x0 |
Exports (3)
»
Api name | EAT Address | Ordinal |
---|---|---|
TMethodImplementationIntercept | 0x6205c | 0x3 |
__dbk_fcall_wrapper | 0x10db0 | 0x2 |
dbkFCallWrapperAddr | 0x13263c | 0x1 |
Memory Dumps (45)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | First Execution |
![]() |
32-bit | 0x0056425A |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x00523E0C |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x0040F8A4 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x004071BC |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x00428B8C |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x004296BC |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x00426A9C |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x00519114 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x00422B28 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x00523EC0 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x00407040 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x00524000 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x004FB1A0 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x00410970 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x0040F85C |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x0051CA1C |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x0040B1A0 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x0042B0C0 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x00429518 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x004F3E30 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x0042D66C |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x004B2F4D |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x004F58F4 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x004B438A |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x004D0F98 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x004B33A1 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x0051B8AE |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x0040F324 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x004B4138 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x004AE66C |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x0051C9E8 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x0042D66C |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x0042B0C0 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x00408620 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x004B2F4D |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x004F49B4 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x004FB064 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x004F58F4 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x004D0F98 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x00524B9E |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x0042E85C |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x0040E02C |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x004269A0 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x00428120 |
![]() |
![]() |
...
|
svchost.exe | 1 | 0x00400000 | 0x00565FFF | Content Changed |
![]() |
32-bit | 0x00525D3F |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Trojan.Heur.tmuarqMnfcci |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\-DpF-3V_.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\1ilxsFFPhAmnX.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\27DC21J8aR.lnk | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\2opleEzWe0B wcg.mkv.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\2RLAZi.mkv.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\4eQFtgvX0bY.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\5DJG.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\5lN31fAPZCnHRtzpRQ.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\6Cqyf 6anxs_CSLAysE.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\7nadXsUY.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\7vWXs5wOoyRqHSZ3.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\9e8NTycG.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\aFzddHE Qh9x.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\AQq3p.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\As_s0.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\AWMp7.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\BbAbN3g2HP.mkv.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Bu_QHO9-h.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Ck9o.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\cr lAb2zi.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\DxP-tIBe7AmaJ6pj.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\ea3ApgGf3IVp.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\EMtuZH-5jQdTrJmsCm.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\FfW70azs-Ha7.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\FmpsaQJLUMaR.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\g5f gdHlfXDDwn2eSSD.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Hjea DQUQSLT3A.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\hmE9.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\I9T1DkViXh.mkv.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Id3VnokaSQb1-.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\ITkZucPgXtfuH72ld.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\j5qVGDC 3 7fjtI.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\J9WQ72qd-NL9SUaxFK.lnk.Zv7uN | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\jRDJUl7IMjUxPV.mkv.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Jyh1PVUP5TT-PP.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\KdBdOCDBxl.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Kg8xgQynXm64WDLJJ.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\kgcPTg_QemXoYwIC0.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\ltiqqiyzz50.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\m-XSe-Rm7qDih2.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\mQqJLf-H9R2.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\My Music.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\My Pictures.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\My Videos.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\n8TSq6Rxej90Ypz.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\N8umJoiWNw2WcG.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\nASdIGvuK.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\ngYhIzBqjK2r.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\noOt.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\o1L10dnO.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\OCI93tz5rnG3Offp.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\POBCiS.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\PPbvZP.mkv.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\PyTen.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\q9PYuuDYFbL.flv.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\QJ pbgGlPls4Oy5IY.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\QsERwYTXRV.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\reeFNQzvLCz.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\rMBc_TwQqbjBeYXCL.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Roaming.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\RQwQADR.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\RV4UFRM8.flv.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Si93WyJ4VkIM.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\soZZ.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\STLq6DOc.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\sXOzIu2 q.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\SzoFqVMTlfvxL3--V.flv.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\tz0VN5KTRkT.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\UEeyhCQ0rsUi-3-nJSm.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\UlHqKtcLSUiNQM.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\upgu6XAw0nd8_3Lb5i.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\VafNA2H199yI1tndZ.flv.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\vUCHxYZhOfXC.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\vvHLRrn4vyqF-1i1p.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\WkutMmuC.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\XdgW2PShs.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\XItXehzcofYBo38.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Xkl0bf1xtDXHz.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Yf8w3Ir-P2yrhyy.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\YS0OguZ6OJI9t.lnk.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\ZBpLsdIGq.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\zES2lw09mWYyi-oFEb.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\_ kJbX69.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\-CYi6R7bCvIz-.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\9_2i.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\aFzddHE Qh9x.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\KdBdOCDBxl.bmp.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ITkZucPgXtfuH72ld\drHcU2ILp K.gif.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ITkZucPgXtfuH72ld\mQqJLf-H9R2.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ITkZucPgXtfuH72ld\OCI93tz5rnG3Offp.jpg.Zv7uN | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ITkZucPgXtfuH72ld\1ilxsFFPhAmnX\3a_Ktn--Hmt.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ITkZucPgXtfuH72ld\1ilxsFFPhAmnX\J1gACW\OIh9luhcg82TbIwB.jpg.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ITkZucPgXtfuH72ld\1ilxsFFPhAmnX\J1gACW\SKcUK\6lsyG9.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ITkZucPgXtfuH72ld\1ilxsFFPhAmnX\J1gACW\SKcUK\nASdIGvuK.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ITkZucPgXtfuH72ld\1ilxsFFPhAmnX\J1gACW\SKcUK\NB9o.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ITkZucPgXtfuH72ld\1ilxsFFPhAmnX\POBCiS\Bu_QHO9-h.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ITkZucPgXtfuH72ld\1ilxsFFPhAmnX\POBCiS\kgcPTg_QemXoYwIC0.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ITkZucPgXtfuH72ld\1ilxsFFPhAmnX\POBCiS\soZZ.png.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ITkZucPgXtfuH72ld\1ilxsFFPhAmnX\POBCiS\VnMkxHGllRW.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ZJXH\6Cqyf 6anxs_CSLAysE.bmp.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ZJXH\7lZfRGVx.png.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ZJXH\9jjfu1YS.jpg.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ZJXH\Rkv tdZAdg61X2zGJw.bmp.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ZJXH\TtSX604s.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ZJXH\_HqTmD-7I2qdeb1.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\2Q_ _Bs8shSYWml.wav.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\cCYg9.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\gzqltNzvsbx7WwV5opFx.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\rWdr_n-a5RwIRREA.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tz0VN5KTRkT\8Pfc9PySy8GgPZR8y43.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tz0VN5KTRkT\SIQNK8nZUW\IR9lejbyUUswtBcUmqP.wav.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tz0VN5KTRkT\SIQNK8nZUW\dh8R\beD8iWFmEj7sj19_RcTk.m4a.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tz0VN5KTRkT\SIQNK8nZUW\dh8R\gNZDQ.wav.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tz0VN5KTRkT\SIQNK8nZUW\dh8R\pPjEdESc.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tz0VN5KTRkT\SIQNK8nZUW\dh8R\W-WQwcGzdDbcBmDqlU.mp3.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tz0VN5KTRkT\SIQNK8nZUW\m-XSe-Rm7qDih2\kynh4m18C.m4a.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tz0VN5KTRkT\SIQNK8nZUW\m-XSe-Rm7qDih2\pYQA2b4qoY2Y NFyD.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tz0VN5KTRkT\SIQNK8nZUW\m-XSe-Rm7qDih2\tyu5ehagSO.mp3.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tz0VN5KTRkT\Zyj26cHu tegBHSw1Uj\dcuEUUO6h.m4a.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tz0VN5KTRkT\Zyj26cHu tegBHSw1Uj\nnUgj.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tz0VN5KTRkT\Zyj26cHu tegBHSw1Uj\RVJVF_UB10M.mp3.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\n7T_pRq.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\RV4UFRM8.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\SzoFqVMTlfvxL3--V.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\AQq3p\bbtjkel4YLOifFIr.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\AQq3p\xe-Wv9.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\DxP-tIBe7AmaJ6pj\KjRuBvq-LMhKwa.avi.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\DxP-tIBe7AmaJ6pj\PPbvZP.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\DxP-tIBe7AmaJ6pj\6a2qkp\IcBGqKdtFRpsh3FJ5K.mkv.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\DxP-tIBe7AmaJ6pj\6a2qkp\MqJoN1slSECN 8iZ4uI.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\DxP-tIBe7AmaJ6pj\oXu8xlNDfHLVRyrz\2opleEzWe0B wcg.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\DxP-tIBe7AmaJ6pj\oXu8xlNDfHLVRyrz\c9uD.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\DxP-tIBe7AmaJ6pj\oXu8xlNDfHLVRyrz\cSsK3Xa3I8N9gp_g.mkv.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\DxP-tIBe7AmaJ6pj\oXu8xlNDfHLVRyrz\I3bWl8wArAF2fKrlEE.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EvnXETH8or\CpmH5RaN7K.swf.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EvnXETH8or\cueKOlXVJh9M3Adi.mp4.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EvnXETH8or\Y oCXBDXgZpHI20YYF3k.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\nNUix\Jm93YYgfImkrpUx-Vb_0.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\nNUix\jRDJUl7IMjUxPV.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\nNUix\X2Gw1ITrR9nx.mp4.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\nNUix\ZrCkb-NVmV4Yo9bZ.avi.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\QsERwYTXRV\4GUo.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\QsERwYTXRV\gagQPb.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\-DpF-3V_.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\-s mpTOnNpWunebm.docx.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\5lN31fAPZCnHRtzpRQ.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ck9o.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\hmE9.pptx.Zv7uN | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\j5qVGDC 3 7fjtI.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows\System32\drivers\etc\host | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\-0cgImthwd.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\-CYi6R7bCvIz-.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\-s mpTOnNpWunebm.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\2ihEu7JjN.ots.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\2pfWvAl3JPRxQW6X.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\2wyN1v_bomEHhDPaBS.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\3a_Ktn--Hmt.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\608WYNFO5klObV.ots.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\6JmZ7I0MdR3MM0C Xp7.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\6lsyG9.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\7lZfRGVx.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\anR_vEBPJQoHgy6nuS.flv.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\bbtjkel4YLOifFIr.mkv.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\C5a1Xl8LZSVJ.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\cc7VJrUJ4rqn A41Oh O.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\CdH12jxKESc8sWeA7C.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\csrS-.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\cSsK3Xa3I8N9gp_g.mkv.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\D1JRmpQ7-5.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\dePX8rTxd.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\dh8R.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\drHcU2ILp K.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\DZvDv8 7hIh_Mu9Whp.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\EvnXETH8or.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\fdo1k2CX.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\gfNfTbYK35b.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\HQv2g4iB5_eiXxJt.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\I3bWl8wArAF2fKrlEE.mkv.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\iDeZDB_thMy_znW.flv.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\J-v2Kn6wrqYZ8FKCS0WZ.ots.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\kaymVO_E ijSZ80WGb.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\MqJoN1slSECN 8iZ4uI.flv.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\mSDpfr6aM.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\n2KIK6waBvBzsoa2.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\n7T_pRq.flv.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\nNUix.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\osnW47dF.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\oXu8xlNDfHLVRyrz.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\p0SinzaP1mEbUlrC.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\P1RaoM.flv.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\QNAASLZXJlZKG.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\QQ-JA.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\QSsqvzc.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Rkv tdZAdg61X2zGJw.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\rP4-P8Y7mjkrVJvfpO.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\rz5wZG.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\SKcUK.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\tsgG.flv.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\TtSX604s.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\u5qNSJVfv61OV8 Tl4.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\u_LT1cVy3Vs87U4LbN7z.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\vctdac7wdvfxK.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\VnMkxHGllRW.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Vn_LVk.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\xe-Wv9.mkv.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\xeOnABdo_Zx4RoO-.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\xjQ7-Z6-cvpQ18.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\xxHQGFPyd0BOtwqaWoa8.ots.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\ZJXH.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\ZYdqwrH.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\Zyj26cHu tegBHSw1Uj.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\_DoNNCW.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\_HqTmD-7I2qdeb1.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\_sTXIMggYSPV.lnk.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Microsoft\Windows\Recent\_XVFyuqaJA4MHES.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\RQwQADR.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ITkZucPgXtfuH72ld\fEw6FTan.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ITkZucPgXtfuH72ld\1ilxsFFPhAmnX\cr lAb2zi.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ITkZucPgXtfuH72ld\1ilxsFFPhAmnX\n8TSq6Rxej90Ypz.jpg.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ITkZucPgXtfuH72ld\1ilxsFFPhAmnX\J1gACW\7iA8732Kdu78.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ITkZucPgXtfuH72ld\1ilxsFFPhAmnX\J1gACW\EMtuZH-5jQdTrJmsCm.jpg.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ITkZucPgXtfuH72ld\1ilxsFFPhAmnX\POBCiS\_DoNNCW.gif.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\2Q1cA1bTINna.wav.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\NoHfM0yp-zG8Qrlkv.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Zspe9.m4a.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tz0VN5KTRkT\aop4xHlF.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tz0VN5KTRkT\Kg8xgQynXm64WDLJJ\4YEAgNEXtnhhOYR9_.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tz0VN5KTRkT\Kg8xgQynXm64WDLJJ\kzL2W_Xkz9T0.m4a.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tz0VN5KTRkT\SIQNK8nZUW\M-B0QD.wav.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tz0VN5KTRkT\SIQNK8nZUW\OUwm.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tz0VN5KTRkT\SIQNK8nZUW\dh8R\heHZ11T-y5rNyaj1d.mp3.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tz0VN5KTRkT\SIQNK8nZUW\m-XSe-Rm7qDih2\jgyEIh3B1d0MKm3ji1.wav.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tz0VN5KTRkT\Zyj26cHu tegBHSw1Uj\0g 0mf.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tz0VN5KTRkT\Zyj26cHu tegBHSw1Uj\A-cejVo6i.mp3.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tz0VN5KTRkT\Zyj26cHu tegBHSw1Uj\kwSeo.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tz0VN5KTRkT\Zyj26cHu tegBHSw1Uj\ubuEcUUpKFtZ1N.mp3.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\tz0VN5KTRkT\Zyj26cHu tegBHSw1Uj\ZpCcyuBa0.wav.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\AQq3p\bmTJ9.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\DxP-tIBe7AmaJ6pj\-CggBS-I.swf.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\DxP-tIBe7AmaJ6pj\9RgJ1WGSQCpG4JXhxJ.flv.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\DxP-tIBe7AmaJ6pj\eEGCUjpx7f_iY-vLAlk.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\DxP-tIBe7AmaJ6pj\6a2qkp\TWK rlk6lsZA1Ob3gqB.mp4.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\DxP-tIBe7AmaJ6pj\oXu8xlNDfHLVRyrz\p-DCXOZdeMaVqNaXbUjy.avi.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\DxP-tIBe7AmaJ6pj\oXu8xlNDfHLVRyrz\tsgG.flv.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\DxP-tIBe7AmaJ6pj\oXu8xlNDfHLVRyrz\UirNPAL jHPFU2G.swf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\EvnXETH8or\GpTL.swf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\nNUix\I9T1DkViXh.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\nNUix\kXr6JNMUXANI3I Es.mp4.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\nNUix\Nid8Dy.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\nNUix\P1RaoM.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\QsERwYTXRV\BnVXNRl_cPdm7g.avi.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\QsERwYTXRV\qRlN1f.swf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\2wyN1v_bomEHhDPaBS.pptx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\CdH12jxKESc8sWeA7C.pptx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\DZvDv8 7hIh_Mu9Whp.docx.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\J9WQ72qd-NL9SUaxFK.xlsx.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\kaymVO_E ijSZ80WGb.docx.Zv7uN | Dropped File | Stream |
Not Queried
|
...
|
»