VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Gen:Variant.Symmi.7095
Gen:Variant.Ser.Mikey.2021
|
weeli.exe
Windows Exe (x86-32)
Created at 2020-04-01T04:33:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\weeli.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4028d8 |
Size Of Code | 0x1a00 |
Size Of Initialized Data | 0x1c00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-03-25 12:39:14+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x19bf | 0x1a00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.03 |
.rdata | 0x403000 | 0x137e | 0x1400 | 0x1e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.09 |
.data | 0x405000 | 0x120 | 0x200 | 0x3200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.17 |
.reloc | 0x406000 | 0x560 | 0x600 | 0x3400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 4.84 |
Imports (1)
»
KERNEL32.dll (30)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitProcess | 0x0 | 0x403000 | 0x4134 | 0x2f34 | 0x119 |
FindFirstFileW | 0x0 | 0x403004 | 0x4138 | 0x2f38 | 0x139 |
lstrlenA | 0x0 | 0x403008 | 0x413c | 0x2f3c | 0x54d |
GetDriveTypeW | 0x0 | 0x40300c | 0x4140 | 0x2f40 | 0x1d3 |
HeapAlloc | 0x0 | 0x403010 | 0x4144 | 0x2f44 | 0x2cb |
SetFilePointerEx | 0x0 | 0x403014 | 0x4148 | 0x2f48 | 0x467 |
HeapFree | 0x0 | 0x403018 | 0x414c | 0x2f4c | 0x2cf |
WaitForSingleObject | 0x0 | 0x40301c | 0x4150 | 0x2f50 | 0x4f9 |
GetLogicalDrives | 0x0 | 0x403020 | 0x4154 | 0x2f54 | 0x209 |
GetProcessHeap | 0x0 | 0x403024 | 0x4158 | 0x2f58 | 0x24a |
WriteFile | 0x0 | 0x403028 | 0x415c | 0x2f5c | 0x525 |
Sleep | 0x0 | 0x40302c | 0x4160 | 0x2f60 | 0x4b2 |
ReadFile | 0x0 | 0x403030 | 0x4164 | 0x2f64 | 0x3c0 |
CreateFileW | 0x0 | 0x403034 | 0x4168 | 0x2f68 | 0x8f |
GetFileSizeEx | 0x0 | 0x403038 | 0x416c | 0x2f6c | 0x1f1 |
GetLastError | 0x0 | 0x40303c | 0x4170 | 0x2f70 | 0x202 |
SetLastError | 0x0 | 0x403040 | 0x4174 | 0x2f74 | 0x473 |
MoveFileW | 0x0 | 0x403044 | 0x4178 | 0x2f78 | 0x363 |
FindClose | 0x0 | 0x403048 | 0x417c | 0x2f7c | 0x12e |
lstrcmpiW | 0x0 | 0x40304c | 0x4180 | 0x2f80 | 0x545 |
lstrcatW | 0x0 | 0x403050 | 0x4184 | 0x2f84 | 0x53f |
FindNextFileW | 0x0 | 0x403054 | 0x4188 | 0x2f88 | 0x145 |
CloseHandle | 0x0 | 0x403058 | 0x418c | 0x2f8c | 0x52 |
lstrcpyW | 0x0 | 0x40305c | 0x4190 | 0x2f90 | 0x548 |
CreateThread | 0x0 | 0x403060 | 0x4194 | 0x2f94 | 0xb5 |
GetTempPathW | 0x0 | 0x403064 | 0x4198 | 0x2f98 | 0x285 |
GetProcAddress | 0x0 | 0x403068 | 0x419c | 0x2f9c | 0x245 |
LoadLibraryA | 0x0 | 0x40306c | 0x41a0 | 0x2fa0 | 0x33c |
CreateMutexA | 0x0 | 0x403070 | 0x41a4 | 0x2fa4 | 0x9b |
GetCommandLineW | 0x0 | 0x403074 | 0x41a8 | 0x2fa8 | 0x187 |
Digital Signatures (2)
»
Certificate: Red GmbH
»
Issued by | Red GmbH |
Parent Certificate | Sectigo RSA Code Signing CA |
Country Name | AT |
Valid From | 2020-03-13 00:00:00+00:00 |
Valid Until | 2021-03-13 23:59:59+00:00 |
Algorithm | sha256_rsa |
Serial Number | B8 81 A7 2D 41 17 BB C3 8B 81 D3 C6 5C 79 2C 1A |
Thumbprint | 5B 19 58 8B 78 74 0A 4C 5D 08 41 99 DC 0F 52 A6 1F 38 00 99 |
Certificate: Sectigo RSA Code Signing CA
»
Issued by | Sectigo RSA Code Signing CA |
Country Name | GB |
Valid From | 2018-11-02 00:00:00+00:00 |
Valid Until | 2030-12-31 23:59:59+00:00 |
Algorithm | sha384_rsa |
Serial Number | 1D A2 48 30 6F 9B 26 18 D0 82 E0 96 7D 33 D3 6A |
Thumbprint | 94 C9 5D A1 E8 50 BD 85 20 9A 4A 2A F3 E1 FB 16 04 F9 BB 66 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
weeli.exe | 1 | 0x003E0000 | 0x003E6FFF | Relevant Image |
![]() |
32-bit | 0x003E290C |
![]() |
![]() |
...
|
weeli.exe | 1 | 0x003E0000 | 0x003E6FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Symmi.7095 |
Malicious
|
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\branding.xml.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.xml.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\pss10r.chm | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\branding.xml.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.xml.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjProrWW.xml.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Office32WW.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\boot.sdi | Modified File | Stream |
Unknown
|
...
|
»
C:\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\Winre.wim | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\5xj5V13qcS 7 Q S.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\6YiZIyLqE12kEJALh.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EK1PloBl6twa\6RCGO0Nm5.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EK1PloBl6twa\bqgDuyQBRz9\3qEcmCilX86.avi.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EK1PloBl6twa\bqgDuyQBRz9\cBZLPQiVKzi.avi.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EK1PloBl6twa\bqgDuyQBRz9\hFVeHDPy.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EK1PloBl6twa\bqgDuyQBRz9\hm2zh8j mw-aJUtk8IAy.bmp.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EK1PloBl6twa\bqgDuyQBRz9\htiG am4A1I.png.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EK1PloBl6twa\bqgDuyQBRz9\_6VHfFjcxfJE.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EK1PloBl6twa\E5FuYVZ0G8cLufpKE.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EK1PloBl6twa\ncQ3OCF5RA9oNgsYxb.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EK1PloBl6twa\OrESP.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EK1PloBl6twa\yDv-xMox2 BshIi9.bmp.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EXwvyT0tN2ZHn.avi.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\gLmMSD2.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\RChbU4tjhigJsWd.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\sBD1QdkY.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Tuo8EkNp.jpg | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\uAGaXXfmNTeSn6aQso.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\w4fe2ze8GN1YF3cWCmCb.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\1zszOcg.pptx.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Dk7mKnbJLmGTyjWV.pps.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\DrkA.pptx.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\gHbU7_W8JM.xls.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\hFm1kpKH3Q.docx.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\hGgaJMwOgUg.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\I3ODYtrtIoMU9TnXB8.pptx.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Irr_.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\k rQv1BVbxkLF1PT_t.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KYOamUk14HBWDY9DY.odp.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\Favorites.vss.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\_private\folder.ico.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\NiLRt-IssRBIvJL.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ogf7AjwKVj- f7L.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\OGo4dD K8S.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\orgKFXQ--.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst.NEPHILIM | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\QA7FXyy6TF.ods.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\r ATUhf6wTb8.pptx.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\r0BhnPupzSSdlJ.xlsx.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X5140S3Luj8ic32Dytgg\Rf87NKFT\3nwYBHTjUPQgub53.doc.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X5140S3Luj8ic32Dytgg\Rf87NKFT\4rFkQkbw6 fiW9Q.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X5140S3Luj8ic32Dytgg\Rf87NKFT\t61aX7t i.pps.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X5140S3Luj8ic32Dytgg\Rf87NKFT\wO1H005NmYKDORdxx.xls.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xnz7-n_50oeM8dJ.docx.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\z8I3rJ8jHANzTdsg.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Bw4bl.m4a.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\jrC27p-IO0j2Kbl.wav.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\m0glIt.m4a.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\NGnj_ h1E _6.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\UEL4L3jO9WoSQ7Qozz6\2fDth.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\UEL4L3jO9WoSQ7Qozz6\Aqc3Tj23FJcwNCLyRx5q.m4a.NEPHILIM | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\UEL4L3jO9WoSQ7Qozz6\D YYwZ_lgFw4_5bNPRct.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\UEL4L3jO9WoSQ7Qozz6\D918ob_hACUbatXR\ExY795tfOc4MdI3s0X3U.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\UEL4L3jO9WoSQ7Qozz6\D918ob_hACUbatXR\GkT80-gRsdkeVwdlzDg.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\UEL4L3jO9WoSQ7Qozz6\D918ob_hACUbatXR\OLdQwjjqWYt_V.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\UEL4L3jO9WoSQ7Qozz6\D918ob_hACUbatXR\TkvglmLL3W EQ2X.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\UEL4L3jO9WoSQ7Qozz6\D918ob_hACUbatXR\Wql_H564x5E5Zo.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\UEL4L3jO9WoSQ7Qozz6\D918ob_hACUbatXR\zFvqNkEKMTcCDQLAExj-.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\UEL4L3jO9WoSQ7Qozz6\sE0z-pa.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\UEL4L3jO9WoSQ7Qozz6\VI2lh.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\UEL4L3jO9WoSQ7Qozz6\XUY6CF RFsJ8qI7jeBQ.m4a.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\UEL4L3jO9WoSQ7Qozz6\z86ZZCWl6Cmr G.m4a.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\UEL4L3jO9WoSQ7Qozz6\zM_WUfi 8.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\-Uf_nS_aQJPj.jpg.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\4p98rTVFWk9NUKd3XYuz.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\6f6fM0kHHEbQnM.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\7nOMhYU-03VZY.png.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\1kvq_JfG.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\AY69cWjwS0SyzG.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\B10kaWPeJI.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\bY4dV3gQE6POb2gQy.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\fOqctAe.gif.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\h 6IzkeGtDMfDw0qURjw.jpg.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\jVnZkl8xLMAlp91n.bmp.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\ljVt.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\qYk5-.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\rt15iobTtzAY6p.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\TR0BzaNnDj0Uo.png.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\woXaBqbokyzl2r\3fU-xgmX.png.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\woXaBqbokyzl2r\5ugmzBnJys-rOcLEHK.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\woXaBqbokyzl2r\6D_3i63CyKTA.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\woXaBqbokyzl2r\il9ZK5-Hrw.jpg.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\woXaBqbokyzl2r\jGX8exTTasoF4.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\woXaBqbokyzl2r\k- FY_KLVjDdr.gif.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\woXaBqbokyzl2r\KAYKzmSLN.bmp.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\woXaBqbokyzl2r\ltraUM.png.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\woXaBqbokyzl2r\WxLYTXoAy1YslFDMb0H.png.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\H rETdZpNCxZiyix.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\kWJIUzWXrzXqyBJ_.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\oYnhF7jjLMo4MYEMc.png.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\R_aLDxI--zaqsM0.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\X55YkSvWHYx.png.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\07LKGqlUvDd3rdk0.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9Z bHz.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\BHvmegf--VJhdfxMW5.mkv.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\I3Q-NQ-b.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\iJe a2W.avi.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\LPk-XAXk-zcc6.flv.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\LPNHujbo7.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\nIx7_sMdrHpfn.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\OyfV5 iV5L3aLTKdy1FG.swf.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\P2_bWcO132my2U-GwQ6.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\Rc317_O.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\tjsnLloeJl4l2.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UhZbJoCx_ElfPUlH30A.swf.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\VqGxYN5.flv.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\WLlslyldTTX.avi.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Adobe\ARM\Reader_10.0.0\AdbeRdrSecUpd10111.msp.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Adobe\ARM\Reader_10.0.0\AdbeRdrUpd10116_MUI.msp.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help_CValidator.H1D.NEPHILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help_MValidator.Lck.NEPHILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Microsoft\MF\Active.GRL.NEPHILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Microsoft\MF\Pending.GRL.NEPHILIM | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Microsoft\Network\Downloader\qmgr0.dat.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Microsoft\OFFICE\AssetLibrary.ico.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Microsoft\OFFICE\MySite.ico.NEPHILIM | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Microsoft\OFFICE\SharePointPortalSite.ico.NEPHILIM | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3388679973-3930757225-3770151564-1000\4ab66b621477963c04960b813de6b062_0303d5b4-ffe9-470e-9dd8-7d9ec416e53f | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\BOOTSTAT.DAT.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\Setup.xml.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.xml.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\Setup.xml.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\setup.chm.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\ShellUI.MST | Modified File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms | Modified File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPlusrWW.xml.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Setup.xml.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\-eRoGn44FLd7nVa_qp.swf.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\2EdVR2BdL_UJ_Tb.wav.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\5gGooh5YlZqE-cuHf7.ppt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9NiLQvf6.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EK1PloBl6twa\-4 E8t.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EK1PloBl6twa\blyObdpvqdZs GX.odp.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EK1PloBl6twa\bqgDuyQBRz9\1Ggrolu.m4a.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EK1PloBl6twa\bqgDuyQBRz9\3 dCejF0.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EK1PloBl6twa\bqgDuyQBRz9\DuLgLrKLZzvMA8zkvh51.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EK1PloBl6twa\bqgDuyQBRz9\vJaeefq21JE0D1c.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EK1PloBl6twa\bqgDuyQBRz9\_FTV DAHnCvzZz4gyY.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EK1PloBl6twa\fGcTTu5.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EK1PloBl6twa\MUTXgqR7U X4H.pps | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\hGwQTJ18XX9LQhvrOhr4.gif.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\jYb8h7NZa.xlsx.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\RxAavaqz2_z.odt.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\viJbrbj2QoktEF6cu9K.pps | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\XLRKCqo3.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\zddpcY.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Zpj5SmV8mS_BQW.m4a.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\-SC6MV5eTF3.csv.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\CTwx4Cqt.pptx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\e6d1Jkz wG7c.docx.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KTm9Oa0kRuLE49QF.pptx.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\r19wgUh2G_a.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\RpcZuWKqTIoEmC-7XzPq.csv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\taV1q.docx.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\UNdkbVtnLslvox.csv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wovmA.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X5140S3Luj8ic32Dytgg\6W5gI.csv.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X5140S3Luj8ic32Dytgg\do1sBE.xlsx.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X5140S3Luj8ic32Dytgg\dV-HSrMn.ods | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X5140S3Luj8ic32Dytgg\HK56cudxP vZ9.csv.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X5140S3Luj8ic32Dytgg\PL0_s7sccV.pptx.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X5140S3Luj8ic32Dytgg\Rf87NKFT\4pymoj9sP.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X5140S3Luj8ic32Dytgg\Rf87NKFT\9B-2P.xls.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X5140S3Luj8ic32Dytgg\Rf87NKFT\oAwRVtH56Okwzg.xls | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\X5140S3Luj8ic32Dytgg\wFtusCdv0.odt.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\xuUTvNixNZQ9.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ZPw3gPQ4dX2oz9KXEQL5.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ldONxLUYalN.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\OCpJ_5bxkAc1Z.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\UEL4L3jO9WoSQ7Qozz6\D918ob_hACUbatXR\GC6ETPphsGdG.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\UEL4L3jO9WoSQ7Qozz6\D918ob_hACUbatXR\NAfcIR.wav.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\UEL4L3jO9WoSQ7Qozz6\D918ob_hACUbatXR\SMnF6e.m4a.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\UEL4L3jO9WoSQ7Qozz6\D918ob_hACUbatXR\WxIZyTGHdczfIM.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\UEL4L3jO9WoSQ7Qozz6\RWPm0E.m4a.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8twYFrA8egRA4VpVCc.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\-XnIV_EaU5WHIey.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\woXaBqbokyzl2r\7gVOpP5x4gzk.gif.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\woXaBqbokyzl2r\IAIe7hWkMsQcX.bmp.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\woXaBqbokyzl2r\Zoo99HBT.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\AAq03dS _t6R\XvsJbsiYY_.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\lNQksITpPuLC3wBX3WUY.jpg.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\wh4Za_QMfWN8Y_9OeV.gif.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\0e_pY5Vcc.swf.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\1gKqJ15ibUv3z.flv.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\4YZ71ysbsTtmRB.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\9Eb-_YDs8aEVkG4xN.avi.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\bQGYb789IQ0v.swf.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\iGVSRibs-r0ZBuDJPJcf.avi.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\khGDyxsV_OLZUC0JCQ4.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\KNn9-FpPmi_nrt NaJ.flv.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\mGaqWH9Golx6HWsD.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\XwOu.avi.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\yhp6kwj.flv.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Adobe\Acrobat\10.0\Replicate\Security\directories.acrodata.NEPHILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Adobe\ARM\Reader_10.0.0\AdbeRdrUpd10110_MUI.msp.NEPHILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_AssetId.H1W.NEPHILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help_MKWD_BestBet.H1W.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help_MTOC_help.H1H.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help_MValidator.H1D.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Microsoft\Assistance\Client\1.0\en-US\Help{9DAA54E8-CD95-4107-8E7F-BA3F24732D95}.H1Q.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Microsoft\Network\Downloader\qmgr1.dat.NEPHILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Microsoft\OFFICE\DocumentRepository.ico.NEPHILIM | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Microsoft\OFFICE\MySharePoints.ico.NEPHILIM | Dropped File | Stream |
Not Queried
|
...
|
»