VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Generic.Ransom.Hiddentear.A.26F7FC79
Generic.Ransom.Hiddentear.A.D94F5C3B
|
xX.exe
Windows Exe (x86-32)
Created at 2020-07-05T09:39:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x41f946 |
Size Of Code | 0x1da00 |
Size Of Initialized Data | 0x13800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-07-01 21:56:48+00:00 |
Version Information (11)
»
Assembly Version | 1.0.0.0 |
Comments | - |
CompanyName | - |
FileDescription | Gendarmerie B.V.3 |
FileVersion | 1.0.0.0 |
InternalName | mavideo.exe |
LegalCopyright | Copyright © 2017 |
LegalTrademarks | - |
OriginalFilename | mavideo.exe |
ProductName | Gendarmerie B.V.3 |
ProductVersion | 1.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x1d95c | 0x1da00 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.8 |
.rsrc | 0x420000 | 0x1349c | 0x13600 | 0x1dc00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.2 |
.reloc | 0x434000 | 0xc | 0x200 | 0x31200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x1f91c | 0x1db1c | 0x0 |
Memory Dumps (14)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
xx.exe | 1 | 0x00A80000 | 0x00AB5FFF | Relevant Image |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x01141000 | 0x01141FFF | First Execution |
![]() |
32-bit | 0x01141000 |
![]() |
![]() |
...
|
buffer | 1 | 0x01141000 | 0x01141FFF | Content Changed |
![]() |
32-bit | 0x0114158C |
![]() |
![]() |
...
|
buffer | 1 | 0x01142000 | 0x01142FFF | First Execution |
![]() |
32-bit | 0x01142000 |
![]() |
![]() |
...
|
buffer | 1 | 0x054D3000 | 0x054D4FFF | First Execution |
![]() |
32-bit | 0x054D37E6 |
![]() |
![]() |
...
|
buffer | 1 | 0x01142000 | 0x01142FFF | Content Changed |
![]() |
32-bit | 0x01142A4B |
![]() |
![]() |
...
|
buffer | 1 | 0x01141000 | 0x01141FFF | Content Changed |
![]() |
32-bit | 0x01141304 |
![]() |
![]() |
...
|
buffer | 1 | 0x01143000 | 0x01143FFF | First Execution |
![]() |
32-bit | 0x01143000 |
![]() |
![]() |
...
|
buffer | 1 | 0x01142000 | 0x01142FFF | Content Changed |
![]() |
32-bit | 0x01142A8F |
![]() |
![]() |
...
|
buffer | 1 | 0x054D3000 | 0x054D4FFF | Content Changed |
![]() |
32-bit | 0x054D396C |
![]() |
![]() |
...
|
buffer | 1 | 0x01143000 | 0x01143FFF | Content Changed |
![]() |
32-bit | 0x011430E0 |
![]() |
![]() |
...
|
buffer | 1 | 0x01143000 | 0x01143FFF | Content Changed |
![]() |
32-bit | 0x011431FE |
![]() |
![]() |
...
|
buffer | 1 | 0x01143000 | 0x01143FFF | Content Changed |
![]() |
32-bit | 0x01143456 |
![]() |
![]() |
...
|
buffer | 1 | 0x054D3000 | 0x054D4FFF | Content Changed |
![]() |
32-bit | 0x054D39EE |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Ransom.Hiddentear.A.26F7FC79 |
Malicious
|
C:\Users\FD1HVy\Desktop\0V5ASM9JptEW4M8.png.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\2C9KWd2EC.jpg.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\6GJxgoamnWHGbtl-7q.doc.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\dutcK49w7 8.wav.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\EV5Wd a.jpg.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\GkuS.docx.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\iR1vMzL3ZLw0J V2.jpg.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\kr OW Wm3wK-XE06ET.png.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\kxy6Jz9KDDhuF_7k.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\llU2Uku.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\mFWpl6BM.m4a.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\mWqj.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\oFV2bR.m4a.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\olQrLaAp.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\oys2bm2JZJzuwj5.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\QG-y0HG.odp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\tr-c8vmX_KEfWZm.jpg.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\TtSxTSGDujQAS7.pptx.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\U6tyP6Iy.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\vBWk.png.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\vR8JQ2rMtXN04OJZSmW.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\vU91-Ro6yaJRH.png.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\1bovzmeYD.docx.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\20Tzn6JZ6Jj7Ez.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\3D4MhdIH0.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\550aDv8 iuz4fpRjuxjb.pptx.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\8ZEbFnu2VdW3fzxL.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\9OMRjt2LnbaINR.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\aCflyMvi.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\aXrO8d7h8zaiF.pptx.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\A_ LH6ioC22MX7JMi.pptx.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Database1.accdb | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\ehvnq.xlsx.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\FgSE4-YRMy20gn.odp.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\hgJrXI_.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\hJ0_2f8MrdJY0.pptx.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nRGTGAxtRXflmG_.pptx.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\QxJYWGczqc3bo1wB.docx.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\rS67d--KDChewWhvv8.odp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\t0fY1QqrnrY5dp.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\TwtcBX.odt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\XsZmeeI4X.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\XyvM1gLVYRden8-.xlsx.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nTj7fDIis5pb3Oa\-bw rjQ4i_13.rtf.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nTj7fDIis5pb3Oa\8IUqIGkHPPSlW1 RYbF.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nTj7fDIis5pb3Oa\FgwfRSAc.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nTj7fDIis5pb3Oa\nkSgrZNcpJJ.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nTj7fDIis5pb3Oa\sLVQqkeFmY-wbzh Mv.pdf.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nTj7fDIis5pb3Oa\kG55lBPMCw_K-G8n\AI_B6_4hctmkKwD4ur.rtf.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nTj7fDIis5pb3Oa\kG55lBPMCw_K-G8n\_IbpzkmGLnTpI.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nTj7fDIis5pb3Oa\OlVsMBM\-7iY.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nTj7fDIis5pb3Oa\OlVsMBM\22u41.odp.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nTj7fDIis5pb3Oa\OlVsMBM\4FPFf_cIuK4V.xlsx.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nTj7fDIis5pb3Oa\OlVsMBM\JXB7.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nTj7fDIis5pb3Oa\OlVsMBM\kYL-zGW-Hli7Dp.odt.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nTj7fDIis5pb3Oa\OlVsMBM\L3QI_jCS-.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nTj7fDIis5pb3Oa\OlVsMBM\t5ysJXZHZRDcoR7-B.odt.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nTj7fDIis5pb3Oa\OlVsMBM\Y00DAc moOje.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nTj7fDIis5pb3Oa\T1nlgU2Emv-mTJhJN7m\7Qh_Yt3fMyE.csv.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nTj7fDIis5pb3Oa\T1nlgU2Emv-mTJhJN7m\bjXw-gDxy6t.pdf.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nTj7fDIis5pb3Oa\T1nlgU2Emv-mTJhJN7m\HBQHuFAZhn.rtf.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nTj7fDIis5pb3Oa\T1nlgU2Emv-mTJhJN7m\RtbaR5dpwvqhKD.odt.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nTj7fDIis5pb3Oa\T1nlgU2Emv-mTJhJN7m\w0zi9i.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nTj7fDIis5pb3Oa\T1nlgU2Emv-mTJhJN7m\WPvnJxNM71.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nTj7fDIis5pb3Oa\T1nlgU2Emv-mTJhJN7m\xF n8sLBjfJbHTGHZ.ods.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\nTj7fDIis5pb3Oa\T1nlgU2Emv-mTJhJN7m\YaULj9zTxp8.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Outlook Files\kkcie@kdj.kd.pst | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\1BNGJkFV8M.jpg.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\4zOPjK2MNYj.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\5WHKno_.png.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\7GhD4mePf2L-_-pf.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\fELj1ZQq4t1nZ44ZOC.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\ogqec_cm3apNW.jpg.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\rO35ytMPEV-Qo1Je\1jsJ70xXCdf1RI_zZ.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\rO35ytMPEV-Qo1Je\25MkAmDQPft0eYJtASd.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\rO35ytMPEV-Qo1Je\fVLVQLFqn.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\rO35ytMPEV-Qo1Je\nmD1fCwrxHA.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\rO35ytMPEV-Qo1Je\T-V5AoWAZz.png.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\rO35ytMPEV-Qo1Je\x4ah3iCqOx-t oe.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\0IF7-c-x3.wav.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\fz69LSe1soXmFNQH-lmy.wav.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\uCHNgbcEJfjMGu.mp3.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\vUf9cNx.m4a.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\biZK6\iyrDwAJKHwmF6k.m4a.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\biZK6\th8DNgR_0PX.m4a.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\biZK6\W1Q4qnu5_w4evmlOT_d.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\biZK6\xkrU yK.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\biZK6\TTBqTmD\0MJgO F9dE9EU vZ dK.wav.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\biZK6\TTBqTmD\8my_MQolMPucJSi.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\biZK6\TTBqTmD\f2P unkdzohW-AE.mp3.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\biZK6\TTBqTmD\LdsewroowTcWYnjJKt.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\biZK6\TTBqTmD\v4vVxkV0s.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\biZK6\TTBqTmD\XqdaLXF3uvEoLJz.mp3.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\FkUmlyV\Iu8veS1id08eUsk-A.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\FkUmlyV\mbD8zdkZ_aG.wav.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\FkUmlyV\uzbfS9V.m4a.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\FkUmlyV\AmxhiEn_ c4SIAn5Wn\Y2cSrl1XbUkB.m4a.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\FkUmlyV\AmxhiEn_ c4SIAn5Wn\cO59FIJkX5q\dbq4qjlZxk-qHl48vYm.m4a.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\FkUmlyV\AmxhiEn_ c4SIAn5Wn\cO59FIJkX5q\FNk2.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\FkUmlyV\AmxhiEn_ c4SIAn5Wn\cO59FIJkX5q\V zTKMY3lgQ2.mp3.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\FkUmlyV\AmxhiEn_ c4SIAn5Wn\cO59FIJkX5q\vCgSvFAb3PV.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\FkUmlyV\AmxhiEn_ c4SIAn5Wn\iVcTuVovm8xJflxDCFVw\gPIBtbNPUikj1fWfVGct.mp3.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\FkUmlyV\AmxhiEn_ c4SIAn5Wn\iVcTuVovm8xJflxDCFVw\yFtnttTqaR9jeev9.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\JLQO-OboxE_dRiRf0\k34cI 4MoueZlam0cN.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\JLQO-OboxE_dRiRf0\tRVNK3kRut\1 5FbHPf6R2mdAzaO.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\JLQO-OboxE_dRiRf0\tRVNK3kRut\1wGm9XiZzO_C.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\JLQO-OboxE_dRiRf0\tRVNK3kRut\23 k8fXa.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\JLQO-OboxE_dRiRf0\tRVNK3kRut\8NFxQozpb9FHnGP8wI.mp3.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\JLQO-OboxE_dRiRf0\tRVNK3kRut\efToj2KDZTPE5g4MRAea.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\JLQO-OboxE_dRiRf0\tRVNK3kRut\Qvha3vPmcNUYmoQLC0mm.m4a.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\JLQO-OboxE_dRiRf0\tRVNK3kRut\VZ-RiW17WZwzNm_7gGw.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\PDciC.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\VVbSxl8.flv.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\h-OvM\VAiXlftvNFz8IyND55\DT6HsLzN4.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\h-OvM\VAiXlftvNFz8IyND55\J aCcSK.mkv.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\h-OvM\VAiXlftvNFz8IyND55\MnGKPK5.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\h-OvM\VAiXlftvNFz8IyND55\QKPjYqzPtHvpQRyXD.mp4.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\h-OvM\VAiXlftvNFz8IyND55\zt6L72cqZX3WzmFTsWBl.flv.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\h-OvM\VAiXlftvNFz8IyND55\7ek1mI9 Pm6CUdeUWF\Z3 wegoL9m7t8wynThR.mkv.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\h-OvM\VAiXlftvNFz8IyND55\7ek1mI9 Pm6CUdeUWF\zIc0obzM4LLHDkaKx5j6.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\WW7MXwKGyuA\EKpsExKm8-EfdGAcz.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\WW7MXwKGyuA\Hhwo7BTHpN xWc zEk.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\WW7MXwKGyuA\kv vTK9042M3F5rDG.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\WW7MXwKGyuA\qEUJQyGKj9QYiFl-4i2M.flv.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\WW7MXwKGyuA\wD0Vst7mR-uofuS.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSm0XsNkhPth5e1iK\28cDR7Fq.mp4.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSm0XsNkhPth5e1iK\qk138js.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSm0XsNkhPth5e1iK\Xe0hZdYw.avi.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSm0XsNkhPth5e1iK\ZevYMFCireBbNxi1OS.mkv.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSm0XsNkhPth5e1iK\jpnN1Ajp9fA14N\0t18eQXADqbb0Iw.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSm0XsNkhPth5e1iK\jpnN1Ajp9fA14N\945Xbd7ThUZNM.flv.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSm0XsNkhPth5e1iK\oQ8gSpaCFoea4\A0uwvGLqRsSDp.mkv.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSm0XsNkhPth5e1iK\oQ8gSpaCFoea4\ASJUa.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSm0XsNkhPth5e1iK\oQ8gSpaCFoea4\FPwvYF11LJIBuvOT.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSm0XsNkhPth5e1iK\oQ8gSpaCFoea4\PTnpN.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\YSm0XsNkhPth5e1iK\oQ8gSpaCFoea4\UTg83lWPWZCkdgb54UWV.mkv.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\READ_ME_Heyyyyyyy.txt.wholocked | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Downloads\READ_ME_Heyyyyyyy.txt | Dropped File | Text |
Unknown
|
...
|
»