VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Generic.Ransom.WCryG.256E2920
|
SF.exe
Windows Exe (x86-32)
Created at 2020-02-26T05:39:00
Remarks
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x6d4b3a |
Size Of Code | 0x2d2c00 |
Size Of Initialized Data | 0x800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-10-27 08:33:17+00:00 |
Version Information (11)
»
Assembly Version | 1.0.0.0 |
Comments | - |
CompanyName | - |
FileDescription | - |
FileVersion | 1.0.0.0 |
InternalName | SF.exe |
LegalCopyright | - |
LegalTrademarks | - |
OriginalFilename | SF.exe |
ProductName | - |
ProductVersion | 1.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x2d2b40 | 0x2d2c00 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.9 |
.rsrc | 0x6d6000 | 0x554 | 0x600 | 0x2d2e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.89 |
.reloc | 0x6d8000 | 0xc | 0x200 | 0x2d3400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x2d4b10 | 0x2d2d10 | 0x0 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
sf.exe | 1 | 0x00BB0000 | 0x00E89FFF | Relevant Image |
![]() |
64-bit | - |
![]() |
![]() |
...
|
sf.exe | 1 | 0x00BB0000 | 0x00E89FFF | Final Dump |
![]() |
64-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Ransom.WCryG.256E2920 |
Malicious
|
C:\Users\FD1HVy\Desktop\t7SM j7jr1e\r-a3zNgOJUX.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\t7SM j7jr1e\HM9We_gUj7PZ.mkv.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\t7SM j7jr1e\1moV649mr5oYgGYy.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\t7SM j7jr1e\CotWRtRQt0rTkiY.ppt.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\t7SM j7jr1e\rpFNnfn3CjwzlXs.xlsx.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\2_0RiT.odp.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\1NtUgvWoYpqz40P l2.mp3.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\ATYccdHNMX.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\m9W-ZLQpNYZlY.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\WO FsKdy1eRNqF2H9u.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\2ZfV0bLNHtH.avi.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\C4mCUh.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Ui-WnBPUqZQ.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\AZC8C7.mp4.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\L 46 V5p B.mp4.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\loTS4lDVE8RGQ4giq9.mp4.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\L_VqYXKIh1T.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\9EZMWCgxoAOC4u-.flv.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\kAHs0eiaXHfrU.gif.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\dpdYnML 7.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\hCHshV.png.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\HSOpOzTEWn5aG.bmp.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Z0ViqZSU2Kz.bmp.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Ffy-b3L1v 1D\BxB4MuuDu9\u0bJWKVEQTY6u4l_N2.csv.Tsar | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Ffy-b3L1v 1D\BxB4MuuDu9\vrLvMAxXE60.pps | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Ffy-b3L1v 1D\BxB4MuuDu9\utBhZcXwV6VAm GPAB.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Ffy-b3L1v 1D\BxB4MuuDu9\5R_dzo8vP-B1W.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Ffy-b3L1v 1D\BxB4MuuDu9\DzEhP6Kv.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Ffy-b3L1v 1D\BxB4MuuDu9\eje O EVY.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Outlook Files\kkcie@kdj.kd.pst.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\htxOYRFhyP1n.docx.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\oRxEJwa.docx.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\_-ZVmqQ56tcZ4.docx.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\DqFVESMa4BXf\_NDYDrBvDQsnRb\rYfNH_M9DT.mp3.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\DqFVESMa4BXf\_NDYDrBvDQsnRb\H_aBvSyFB6aoE q98.wav.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\gZPEToBTgIpVey zHIm\QChXQ7IxjadeDKB.png.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\gZPEToBTgIpVey zHIm\Ge5S88F4W5\fj G6eWxpvWxeLr WUZs\vd 3Ww8Bh7f95KOI.bmp.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\gZPEToBTgIpVey zHIm\sCR0md7qo\O6z_Ks_1MP\lejDQFANxAnTcsNKnJ9\BYTaFHvwSJIaS1ZW2X.gif.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\gZPEToBTgIpVey zHIm\sCR0md7qo\O6z_Ks_1MP\lejDQFANxAnTcsNKnJ9\31dD3iNNgOdyxqYC1.png.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\gZPEToBTgIpVey zHIm\sCR0md7qo\O6z_Ks_1MP\lejDQFANxAnTcsNKnJ9\4fgBSNeeLCx.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\6_d6NYz4yZY4V18y-\EkA5krAGLvJBZGB.mkv.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YN2mVqgp3ZYsZHG\6GZ1y9xx.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YN2mVqgp3ZYsZHG\kOe_.mkv.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YN2mVqgp3ZYsZHG\oMu64njCTIr.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YN2mVqgp3ZYsZHG\R1-uj-.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Google Profile.ico.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\000003.log.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\main.js | Modified File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\main.html.Tsar | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\icon_16.png.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\128.png.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6117.717.0.0_0\cast_game_sender.js.Tsar | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6117.717.0.0_0\common.js | Modified File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6117.717.0.0_0\feedback_script.js.Tsar | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6117.717.0.0_0\mirroring_common.js | Modified File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\Windows\Notifications\wpnidm\ca910921.jpg.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData\Indexed DB\edb0000A.log | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Ffy-b3L1v 1D\7uWcDK.rtf.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Ffy-b3L1v 1D\YPTjH6khLxmaeTBwrj.csv.Tsar | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Ffy-b3L1v 1D\lT Q.pptx.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Ffy-b3L1v 1D\vrpDv-DBdn.xlsx.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Ffy-b3L1v 1D\BxB4MuuDu9\bnbNeUZXo6SruVVR.odt.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Ffy-b3L1v 1D\BxB4MuuDu9\caVkMt.odp.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\EdlJjcRetfQGkgnn.odt.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\R6Jv0yrmZl4bs.ods.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\y0I huhnQW-z588WDrg.ods.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Z5OGa4uCCH5CEdDwhG.pptx.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\MNKok7ttGHY.xlsx.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\TrWj9lGzn-ZIHOLpczC.xlsx.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\ui-7xBH2On3s1paCV.xlsx.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\eeE2YlXr8VJB cj9b2N.docx.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\DqFVESMa4BXf\2R Z0w\ZJPY2k9p11oqoj5.mp3.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\DqFVESMa4BXf\2R Z0w\WFEBL.wav.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\DqFVESMa4BXf\EsvgrDQ\-fAtPI7fhZI.wav.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\DqFVESMa4BXf\EsvgrDQ\KGoHoTUZ1YhN.wav.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\DqFVESMa4BXf\EsvgrDQ\KjSepNsToF_0r2J_GY.wav.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\DqFVESMa4BXf\N0tvIXhQfh7IS\q d_De6scRf-jFUz.mp3.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\DqFVESMa4BXf\N0tvIXhQfh7IS\upxRkHcQVW-M.mp3.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\DqFVESMa4BXf\PIlO2Yjo\8BeObKn4_.mp3.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\DqFVESMa4BXf\PIlO2Yjo\hExMq.wav.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\DqFVESMa4BXf\PIlO2Yjo\q2TEsH2AK.wav.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\DqFVESMa4BXf\PIlO2Yjo\Xpz_eZKu.wav.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\AiQQv_.wav.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\33A4HZ3\aRz3Kd3BRcjB.png.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\gZPEToBTgIpVey zHIm\jjmz-UKNgO7.gif.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\gZPEToBTgIpVey zHIm\Ge5S88F4W5\hgmYSO3Jro-a5-.jpg.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\gZPEToBTgIpVey zHIm\Q_NVD0ULqE9u692\nHBE14ECc89k QL-Z9cE.bmp.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\gZPEToBTgIpVey zHIm\sCR0md7qo\lwC Y.bmp.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\gZPEToBTgIpVey zHIm\sCR0md7qo\O6z_Ks_1MP\weHHJeUdOBhnsmRaIx.jpg.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\zWrnPNF.bmp.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\6_d6NYz4yZY4V18y-\y1E6VYc.avi.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eMZ77E3vAkA5Ri19X\1pBvQwDW8.swf.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eMZ77E3vAkA5Ri19X\DlXMi7P0qh.avi.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eMZ77E3vAkA5Ri19X\dogqi-YYfFvET4lfziyl.avi.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eMZ77E3vAkA5Ri19X\lN6tvPYyVti7fk2yHoF.avi.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\eMZ77E3vAkA5Ri19X\Y09qrTFSj.flv.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YN2mVqgp3ZYsZHG\13-e1XQw2ov oV1vFM.swf.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YN2mVqgp3ZYsZHG\35uvl3rSN_TGiCO3L2.avi.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\94pMq.mp4.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\pm-lUxy-Q4Y.mkv.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ziqsR0u3UF4AJo7K.mkv.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\1rBCHQPkhiA.flv.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\eventpage_bin_prod.js.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_0\images\icon_16.png.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_0\images\topbar_floating_button.png.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6117.717.0.0_0\cast_route_details.html.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6117.717.0.0_0\feedback.html.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6117.717.0.0_0\cast_setup\devices.html.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6117.717.0.0_0\cast_setup\index.html.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6117.717.0.0_0\cloud_route_details\view.html.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\sdiagnhost.exe.log.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\NGenTask.exe.log.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\powershell.exe.log.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\Internet Explorer\Indexed DB\edb.log.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\Internet Explorer\Indexed DB\edb00001.log.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\Internet Explorer\Indexed DB\edbtmp.log.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\FileCoAuth.exe.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\OneDrive.exe.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\qml\fabricmdl2.ttf.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7076.1026\AutoPlayOptIn.gif.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\AppBlue.png.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\ElevatedAppWhite.png.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\Error.png.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\QuotaNearing.png.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\ThirdPartyNotices.txt.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\images\iceBucket.svg.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\images\loading.svg.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\images\onedrivePremium.svg.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\images\settings.svg.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\images\stackedIceCubes.svg.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\images\waterGlass.svg.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7076.1026\FileCoAuth.exe.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7076.1026\FileSyncConfig.exe.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7076.1026\OneDriveStandaloneUpdater.exe.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\LoadingPage.html.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7076.1026\CollectSyncLogs.bat.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7076.1026\alertIcon.png.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\OneDrive.exe.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\ThirdPartyNotices.txt.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\images\acmDismissIcon.svg.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\images\checkmark_hovered.svg.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\images\chevronUp.svg.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\images\folder.svg.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\images\folder_image_documents.svg.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\images\onDemandFiles.svg.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\images\overflowIcon.svg.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\images\overflowIconWhite.svg.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\images\blurrect.png.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\OneDriveSetup.exe.Tsar | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\t7SM j7jr1e\i0gNmtgOq.wav.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\t7SM j7jr1e\dFHokdeqOzj.avi.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\t7SM j7jr1e\t_AY_ COaocCL4bJ7N0D.xls | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\1I9GD6tKf.swf.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\5a cF10bvZGH.avi.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\Kp4I8IZ2-Wdy.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\Ta_7Jk.jpg.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\90Y9.ppt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\GqG itN-sTI3sMLEgs.xlsx.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\ZSnTdKkZHnh.doc | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Ffy-b3L1v 1D\BxB4MuuDu9\G0sgDO2H.odp.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Ffy-b3L1v 1D\BxB4MuuDu9\MGgpZhSja.pptx.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Ffy-b3L1v 1D\BxB4MuuDu9\jge8zipK18HKBMV.xls | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\QT8ut Fj j.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\gmeZZ4caL9KdRcvzr.doc.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\DqFVESMa4BXf\_NDYDrBvDQsnRb\fGxMbn530Kgm yS.wav.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\DqFVESMa4BXf\_NDYDrBvDQsnRb\NgkHov Hq5Ym2wuJ.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\DqFVESMa4BXf\_NDYDrBvDQsnRb\su_G44o4.wav.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\gZPEToBTgIpVey zHIm\_2wsONTsqDQO3LF5R9uO.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\6_d6NYz4yZY4V18y-\rCzrbRHE1-DK6d4_Tde.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\6_d6NYz4yZY4V18y-\jPSquq0UAoZN1gM7.mkv.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\6_d6NYz4yZY4V18y-\hmxLaLX UcR7OgrbQKG.flv.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\YN2mVqgp3ZYsZHG\erbJRw8ZR.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\YN2mVqgp3ZYsZHG\1HITC.mkv.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\icon_128.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\icon_16.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\main.js.Tsar | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\icon_128.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6117.717.0.0_0\cast_route_details.js | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6117.717.0.0_0\cast_sender.js | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6117.717.0.0_0\mirroring_cast_streaming.js.Tsar | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6117.717.0.0_0\mirroring_hangouts.js.Tsar | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6117.717.0.0_0\mirroring_webrtc.js | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData\Indexed DB\edb00008.log | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData\Indexed DB\edb00009.log.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\AppData\Indexed DB\edbtmp.log | Modified File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Ffy-b3L1v 1D\EVNM.odt.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Ffy-b3L1v 1D\J-6zNvV.odp.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Ffy-b3L1v 1D\cA LFQihqrP.rtf.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Ffy-b3L1v 1D\_wHChT.rtf.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Ffy-b3L1v 1D\CaSnCZwmtBzw-AN.pptx.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Ffy-b3L1v 1D\JtfoXmuFhkbX.pptx.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Ffy-b3L1v 1D\J-7ETb2-5K5JrH.ppt.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Ffy-b3L1v 1D\v0fQ fUt05n59l.ppt.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Ffy-b3L1v 1D\63aVxTZTOI.doc.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\8BQSnWcxuuMUmRrGR1gn.odt.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\hItUuhxaV3LEP.ods.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\llzYSmcJuRmwVpo.ods.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Database1.accdb.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\6u5FaTlv6JdvhaFRmc_M.pptx.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\a5Pv1d5ls VA3.pptx.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\bM0TU2D.pptx.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\xPlJ5VJmTktmgr.pptx.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\a2WF34eWUvcnRC.xlsx.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\pAYWDhop1zzd_MJgJ7.xlsx.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\RpHwERqhWpU0.xlsx.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\ZgZRPXssf5.xlsx.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\CWX0vBJE8Mmxe.docx.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\DqFVESMa4BXf\EsvgrDQ\4Ypmw8zAu6p.wav.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\DqFVESMa4BXf\EsvgrDQ\raogB S2VSYhtVN.wav.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\DqFVESMa4BXf\N0tvIXhQfh7IS\9pcfywnpICJ.mp3.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\DqFVESMa4BXf\N0tvIXhQfh7IS\U3rWikcvPaMFK.wav.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\DqFVESMa4BXf\PIlO2Yjo\qsQP3TaCWEI7BmtuX.mp3.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\DqFVESMa4BXf\PIlO2Yjo\Noms1-AYYUuAqkgn1.wav.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\_PeyrjcjZEsfz3tTw.mp3.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\Rhj ZldVI7z784wm.wav.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\33A4HZ3\Wg8hj0bit.jpg.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\gZPEToBTgIpVey zHIm\aG6d_b\AcBb8vBXW00rHDUBIsg6.bmp.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\gZPEToBTgIpVey zHIm\aG6d_b\j1q-SAj2oKS13j.bmp.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\gZPEToBTgIpVey zHIm\aG6d_b\pmDs6oe XbNSDLCj.bmp.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\gZPEToBTgIpVey zHIm\Ge5S88F4W5\3uO6-oO.gif.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\gZPEToBTgIpVey zHIm\Ge5S88F4W5\8xyRsc29oJ.bmp.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\gZPEToBTgIpVey zHIm\sCR0md7qo\KJKWOFq-.png.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\gZPEToBTgIpVey zHIm\sCR0md7qo\TO7KMev0_u.bmp.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\gZPEToBTgIpVey zHIm\sCR0md7qo\Wirj5-cN4SXrp.jpg.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\gZPEToBTgIpVey zHIm\sCR0md7qo\O6z_Ks_1MP\WRKvQ4lg5qumkxX.gif.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\gZPEToBTgIpVey zHIm\sCR0md7qo\O6z_Ks_1MP\8RJVKH.bmp.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\7sFX.png.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\vmqf.bmp.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\_ll69fDNFwc4t74F.bmp.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\0SvA.jpg.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\6_d6NYz4yZY4V18y-\iTPgyeuzLcGjWhgpV3Y.avi.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\eMZ77E3vAkA5Ri19X\QBAQwJCNre.avi.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\eMZ77E3vAkA5Ri19X\sUnA.mp4.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\eMZ77E3vAkA5Ri19X\UDXeH.mp4.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\eMZ77E3vAkA5Ri19X\XdUVYWs1iztioHoz.mp4.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\eMZ77E3vAkA5Ri19X\wpu_s9EpPFRD.flv.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\c7Dwrb.swf.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\dJEexTmFPkVW.swf.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\mG5HwOR.swf.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\0_-TUMg.avi.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\m2cC73rf.mp4.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\tg5 jW57Cml7D.mp4.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\DtBXutGcorJcLa.mkv.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\CigCL85w1HzD4.flv.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Sync Extension Settings\pkedcjkdefgpdelpbcmbmeomcjbeemfm\000003.log.Tsar | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extension State\000003.log.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\128.png.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\contentscript_bin_prod.js.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\page_embed_script.js.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_1\128.png.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_0\craw_background.js.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_0\craw_window.js.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_0\html\craw_window.html.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_0\images\flapper.gif.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_0\images\icon_128.png.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_0\images\topbar_floating_button_close.png.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_0\images\topbar_floating_button_hover.png.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_0\images\topbar_floating_button_maximize.png.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.3_0\images\topbar_floating_button_pressed.png.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\128.png.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6117.717.0.0_0\angular.js.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6117.717.0.0_0\background_script.js.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6117.717.0.0_0\cast_setup\cast_app.js.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6117.717.0.0_0\cast_setup\cast_app_redirect.js.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6117.717.0.0_0\cast_setup\chromecast_logo_grey.png.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\6117.717.0.0_0\cloud_route_details\view.js.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\leveldb\000003.log.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Sync Data\LevelDB\000003.log.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_aohghmighlieiainnegkcijnfilokake\Google Docs.ico.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\CLR_v2.0\UsageLogs\WINPROJ.EXE.log.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\CLR_v4.0\ngen.log.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\mighost.exe.log.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\mmc.exe.log.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\NGenTask.exe.log.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\powershell.exe.log.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\Internet Explorer\brndlog.bak.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\Internet Explorer\brndlog.txt.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\Internet Explorer\ie4uinit-ClearIconCache.log.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\Internet Explorer\ie4uinit-UserConfig.log.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\OneDrive.exe.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\OneDrivePersonal.cmd.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\FileSyncConfig.exe.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\OneDriveStandaloneUpdater.exe.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\ScreenshotOptIn.gif.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\AppWhite.png.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\AutoPlayOptIn.png.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7076.1026\ElevatedAppBlue.png.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7076.1026\OneDriveLogo.png.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\QuotaCritical.png.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\QuotaError.png.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\Warning.png.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\images\partiallyFreezing.svg.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\images\settingsdisabled.svg.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7076.1026\OneDrive.exe.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7076.1026\ErrorPage.html.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\AppErrorBlue.png.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\AppErrorWhite.png.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\FileCoAuth.exe.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\FileSyncConfig.exe.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\OneDriveStandaloneUpdater.exe.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\ErrorPage.html.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\TestSharePage.html.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\images\checkmark_finished.svg.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\images\checkmark_in_progress.svg.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\images\checkmark_selected.svg.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\images\chevron.svg.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\images\cloud.svg.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\images\done_graphic.svg.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\images\errorIcon.svg.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\images\folder_image_desktop.svg.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\images\folder_image_pictures.svg.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\images\loading_spinner.svg.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\images\onDemandFilesDehydrate.svg.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\images\onDemandSelectiveSync.svg.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\images\signIn.svg.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\FileCoAuth.exe.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\FileSyncConfig.exe.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\images\paused.svg.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\setup\logs\2018-11-14_170112_f7c-948.log.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\setup\logs\2018-11-14_170113_f4c-be0.log.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\setup\logs\2018-11-14_171724_d80-678.log.Tsar | Dropped File | Stream |
Not Queried
|
...
|
»