VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Generic.Ransom.DesuCrypt.33358200
Generic.Ransom.DesuCrypt.3DDC5C46
Mal/Generic-S
|
DogeCrypt.exe
Windows Exe (x86-32)
Created at 2020-09-17T03:07:00
Remarks
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x40a537 |
Size Of Code | 0x21c00 |
Size Of Initialized Data | 0x33400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-09-16 17:00:41+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x21b7b | 0x21c00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.63 |
.rdata | 0x423000 | 0x10b86 | 0x10c00 | 0x22000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.21 |
.data | 0x434000 | 0x2354 | 0x1000 | 0x32c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.48 |
.rsrc | 0x437000 | 0x1da48 | 0x1dc00 | 0x33c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.7 |
.reloc | 0x455000 | 0x26b4 | 0x2800 | 0x51800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.5 |
Imports (4)
»
KERNEL32.dll (84)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadResource | 0x0 | 0x423020 | 0x33300 | 0x32300 | 0x3c2 |
SizeofResource | 0x0 | 0x423024 | 0x33304 | 0x32304 | 0x574 |
LockResource | 0x0 | 0x423028 | 0x33308 | 0x32308 | 0x3d4 |
FindResourceW | 0x0 | 0x42302c | 0x3330c | 0x3230c | 0x194 |
GetLastError | 0x0 | 0x423030 | 0x33310 | 0x32310 | 0x25d |
HeapSize | 0x0 | 0x423034 | 0x33314 | 0x32314 | 0x34a |
SetStdHandle | 0x0 | 0x423038 | 0x33318 | 0x32318 | 0x542 |
GetProcessHeap | 0x0 | 0x42303c | 0x3331c | 0x3231c | 0x2b0 |
GetModuleHandleW | 0x0 | 0x423040 | 0x33320 | 0x32320 | 0x274 |
FindNextFileW | 0x0 | 0x423044 | 0x33324 | 0x32324 | 0x18a |
FindFirstFileW | 0x0 | 0x423048 | 0x33328 | 0x32328 | 0x17e |
GetCurrentDirectoryW | 0x0 | 0x42304c | 0x3332c | 0x3232c | 0x20f |
DeleteFileW | 0x0 | 0x423050 | 0x33330 | 0x32330 | 0x113 |
ReadFile | 0x0 | 0x423054 | 0x33334 | 0x32334 | 0x46c |
WriteFile | 0x0 | 0x423058 | 0x33338 | 0x32338 | 0x60a |
CloseHandle | 0x0 | 0x42305c | 0x3333c | 0x3233c | 0x86 |
CreateFileW | 0x0 | 0x423060 | 0x33340 | 0x32340 | 0xca |
FreeEnvironmentStringsW | 0x0 | 0x423064 | 0x33344 | 0x32344 | 0x1a8 |
GetEnvironmentStringsW | 0x0 | 0x423068 | 0x33348 | 0x32348 | 0x233 |
GetOEMCP | 0x0 | 0x42306c | 0x3334c | 0x3234c | 0x293 |
IsValidCodePage | 0x0 | 0x423070 | 0x33350 | 0x32350 | 0x386 |
MultiByteToWideChar | 0x0 | 0x423074 | 0x33354 | 0x32354 | 0x3e8 |
WideCharToMultiByte | 0x0 | 0x423078 | 0x33358 | 0x32358 | 0x5f6 |
GetStringTypeW | 0x0 | 0x42307c | 0x3335c | 0x3235c | 0x2d3 |
FindClose | 0x0 | 0x423080 | 0x33360 | 0x32360 | 0x173 |
SetEndOfFile | 0x0 | 0x423084 | 0x33364 | 0x32364 | 0x508 |
SetFilePointerEx | 0x0 | 0x423088 | 0x33368 | 0x32368 | 0x51b |
EncodePointer | 0x0 | 0x42308c | 0x3336c | 0x3236c | 0x12b |
DecodePointer | 0x0 | 0x423090 | 0x33370 | 0x32370 | 0x107 |
EnterCriticalSection | 0x0 | 0x423094 | 0x33374 | 0x32374 | 0x12f |
LeaveCriticalSection | 0x0 | 0x423098 | 0x33378 | 0x32378 | 0x3b8 |
DeleteCriticalSection | 0x0 | 0x42309c | 0x3337c | 0x3237c | 0x10e |
SetLastError | 0x0 | 0x4230a0 | 0x33380 | 0x32380 | 0x52a |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4230a4 | 0x33384 | 0x32384 | 0x35a |
SwitchToThread | 0x0 | 0x4230a8 | 0x33388 | 0x32388 | 0x57f |
TlsAlloc | 0x0 | 0x4230ac | 0x3338c | 0x3238c | 0x596 |
TlsGetValue | 0x0 | 0x4230b0 | 0x33390 | 0x32390 | 0x598 |
TlsSetValue | 0x0 | 0x4230b4 | 0x33394 | 0x32394 | 0x599 |
TlsFree | 0x0 | 0x4230b8 | 0x33398 | 0x32398 | 0x597 |
GetSystemTimeAsFileTime | 0x0 | 0x4230bc | 0x3339c | 0x3239c | 0x2e5 |
GetProcAddress | 0x0 | 0x4230c0 | 0x333a0 | 0x323a0 | 0x2aa |
CompareStringW | 0x0 | 0x4230c4 | 0x333a4 | 0x323a4 | 0x9a |
LCMapStringW | 0x0 | 0x4230c8 | 0x333a8 | 0x323a8 | 0x3ac |
GetLocaleInfoW | 0x0 | 0x4230cc | 0x333ac | 0x323ac | 0x261 |
GetCPInfo | 0x0 | 0x4230d0 | 0x333b0 | 0x323b0 | 0x1bf |
UnhandledExceptionFilter | 0x0 | 0x4230d4 | 0x333b4 | 0x323b4 | 0x5a5 |
SetUnhandledExceptionFilter | 0x0 | 0x4230d8 | 0x333b8 | 0x323b8 | 0x565 |
GetCurrentProcess | 0x0 | 0x4230dc | 0x333bc | 0x323bc | 0x215 |
TerminateProcess | 0x0 | 0x4230e0 | 0x333c0 | 0x323c0 | 0x584 |
IsProcessorFeaturePresent | 0x0 | 0x4230e4 | 0x333c4 | 0x323c4 | 0x381 |
IsDebuggerPresent | 0x0 | 0x4230e8 | 0x333c8 | 0x323c8 | 0x37a |
GetStartupInfoW | 0x0 | 0x4230ec | 0x333cc | 0x323cc | 0x2cc |
QueryPerformanceCounter | 0x0 | 0x4230f0 | 0x333d0 | 0x323d0 | 0x446 |
GetCurrentProcessId | 0x0 | 0x4230f4 | 0x333d4 | 0x323d4 | 0x216 |
GetCurrentThreadId | 0x0 | 0x4230f8 | 0x333d8 | 0x323d8 | 0x21a |
InitializeSListHead | 0x0 | 0x4230fc | 0x333dc | 0x323dc | 0x35e |
RtlUnwind | 0x0 | 0x423100 | 0x333e0 | 0x323e0 | 0x4cb |
RaiseException | 0x0 | 0x423104 | 0x333e4 | 0x323e4 | 0x45b |
FreeLibrary | 0x0 | 0x423108 | 0x333e8 | 0x323e8 | 0x1a9 |
LoadLibraryExW | 0x0 | 0x42310c | 0x333ec | 0x323ec | 0x3be |
SetEnvironmentVariableA | 0x0 | 0x423110 | 0x333f0 | 0x323f0 | 0x50b |
SetEnvironmentVariableW | 0x0 | 0x423114 | 0x333f4 | 0x323f4 | 0x50c |
SetCurrentDirectoryW | 0x0 | 0x423118 | 0x333f8 | 0x323f8 | 0x501 |
ExitProcess | 0x0 | 0x42311c | 0x333fc | 0x323fc | 0x15c |
GetModuleHandleExW | 0x0 | 0x423120 | 0x33400 | 0x32400 | 0x273 |
GetModuleFileNameA | 0x0 | 0x423124 | 0x33404 | 0x32404 | 0x26f |
GetStdHandle | 0x0 | 0x423128 | 0x33408 | 0x32408 | 0x2ce |
GetCommandLineA | 0x0 | 0x42312c | 0x3340c | 0x3240c | 0x1d4 |
GetCommandLineW | 0x0 | 0x423130 | 0x33410 | 0x32410 | 0x1d5 |
GetACP | 0x0 | 0x423134 | 0x33414 | 0x32414 | 0x1b0 |
HeapAlloc | 0x0 | 0x423138 | 0x33418 | 0x32418 | 0x341 |
HeapFree | 0x0 | 0x42313c | 0x3341c | 0x3241c | 0x345 |
GetFileType | 0x0 | 0x423140 | 0x33420 | 0x32420 | 0x24a |
FlushFileBuffers | 0x0 | 0x423144 | 0x33424 | 0x32424 | 0x19d |
GetConsoleCP | 0x0 | 0x423148 | 0x33428 | 0x32428 | 0x1e8 |
GetConsoleMode | 0x0 | 0x42314c | 0x3342c | 0x3242c | 0x1fa |
ReadConsoleW | 0x0 | 0x423150 | 0x33430 | 0x32430 | 0x469 |
IsValidLocale | 0x0 | 0x423154 | 0x33434 | 0x32434 | 0x388 |
GetUserDefaultLCID | 0x0 | 0x423158 | 0x33438 | 0x32438 | 0x30e |
EnumSystemLocalesW | 0x0 | 0x42315c | 0x3343c | 0x3243c | 0x152 |
HeapReAlloc | 0x0 | 0x423160 | 0x33440 | 0x32440 | 0x348 |
FindFirstFileExA | 0x0 | 0x423164 | 0x33444 | 0x32444 | 0x178 |
FindNextFileA | 0x0 | 0x423168 | 0x33448 | 0x32448 | 0x188 |
WriteConsoleW | 0x0 | 0x42316c | 0x3344c | 0x3244c | 0x609 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SystemParametersInfoW | 0x0 | 0x423184 | 0x33464 | 0x32464 | 0x388 |
ADVAPI32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptExportKey | 0x0 | 0x423000 | 0x332e0 | 0x322e0 | 0xd0 |
CryptEncrypt | 0x0 | 0x423004 | 0x332e4 | 0x322e4 | 0xcb |
CryptReleaseContext | 0x0 | 0x423008 | 0x332e8 | 0x322e8 | 0xdc |
CryptDestroyKey | 0x0 | 0x42300c | 0x332ec | 0x322ec | 0xc8 |
CryptGenKey | 0x0 | 0x423010 | 0x332f0 | 0x322f0 | 0xd1 |
CryptAcquireContextW | 0x0 | 0x423014 | 0x332f4 | 0x322f4 | 0xc2 |
CryptImportKey | 0x0 | 0x423018 | 0x332f8 | 0x322f8 | 0xdb |
SHELL32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x423174 | 0x33454 | 0x32454 | 0x1b8 |
SHGetSpecialFolderLocation | 0x0 | 0x423178 | 0x33458 | 0x32458 | 0x175 |
SHChangeNotify | 0x0 | 0x42317c | 0x3345c | 0x3245c | 0x8b |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
dogecrypt.exe | 1 | 0x00C00000 | 0x00C57FFF | Relevant Image |
![]() |
32-bit | 0x00C0D1C1 |
![]() |
![]() |
...
|
dogecrypt.exe | 1 | 0x00C00000 | 0x00C57FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Ransom.DesuCrypt.33358200 |
Malicious
|
c:\users\fd1hvy\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-1051304884-625712362-2192934891-1000\c71a976da0cbffbff6b43da231aa96fa_33d770d0-06bc-47c5-8714-222cdac43a71 | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\eula.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\eula.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\eula.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\eula.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\eula.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DHtmlHeader.html.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\1Ov3AQ.mkv.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\6xIitnfQ.csv.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\7dd_QhpxlbxKph.bmp.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\beo4RHOnzqJ_U1yyHFD.mp4.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\cG3VhmyDbTd3.mp3.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\CkcuZB9rb 6V.flv.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\h8vGIWE6.wav.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\H_wqwPnATL.gif.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\ih_AiKLnY QbKjhK8uN.mp4.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\IlQbhWBlIje5\1Jsn.ods.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\IlQbhWBlIje5\3v8K.mp4.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\IlQbhWBlIje5\4owMuQTnm.mp3.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\IlQbhWBlIje5\7KcCEVDc.csv.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\IlQbhWBlIje5\fj9BHb.wav.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\IlQbhWBlIje5\kUtgZWr AZKqMevGe.png.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\IlQbhWBlIje5\pdkjX6F.ots.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\IlQbhWBlIje5\q_hJ8sg9NWDj.xlsx.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\IlQbhWBlIje5\xALEo.jpg.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\IlQbhWBlIje5\ZTRnUlKGuVsYlzR6nerw.flv.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Iwrh6yT1oQgy7a.swf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\iyrmo9bRjdcT.pps.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\KpmRfg 8d.mp3.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\LCOGsG kKZvc6h.flv.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\MOAhHbSRYJX -.ppt.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\NCP4nAGl.avi.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\pV 5.mkv.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\rQjzsL.doc.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\vqCsG-s.bmp.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Zj2ED6y8.mp3.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\ztz oYzBupF_Uwlrs.odp.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\1 lG6UdZcI.csv.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\5J1elzLNbDnDWxifL.pptx.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\7zJh8zwxN.pptx.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CK5fMTMcoBdf-27E\1T-MR_6wS5UcB9vR4.ppt.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CK5fMTMcoBdf-27E\4rr9523Mw naxoWPYZ2.odt.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CK5fMTMcoBdf-27E\emIhOUWcO2.ods.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CK5fMTMcoBdf-27E\f96Gt8XN3VerhuQC0A.xlsx.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CK5fMTMcoBdf-27E\lpah.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CK5fMTMcoBdf-27E\oByIbrwegS.pps.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\dwHYavwt34E5j CeI.pptx.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\d_d_9jIWEQa2mTBo.pptx.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Eh0SHn1-vu uLGAgY.csv.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\gJ 9j1 g3L9rcq.doc.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\m7ilW6_\B9I-ZGSIZuPmkpD3.ppt.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\m7ilW6_\fD7uqTbt t R4XK5NW.pdf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\oeV.pptx.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\pgcEl3t8kubLB.docx.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\pZ3CoQpbB1nvT8dmq\imGxgyJd.xlsx.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\pZ3CoQpbB1nvT8dmq\vi-NFbURFHp4RyRiBA9K.xlsx.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\tw-0fizuYT 3y.ppt.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\wKqgZ4xA9.xlsx.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\ZrL2TCIulbX8URlQj8XN\eJYSWS.csv.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\ZrL2TCIulbX8URlQj8XN\GNMgMUyoDH.ots.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\ZrL2TCIulbX8URlQj8XN\qB2hH02IlcS5x.pptx.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\ZrL2TCIulbX8URlQj8XN\rklcr89dEuTFqrfYtN.odt.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\0FvOG_\fKuq-w-m_5GwA.mp3.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\0FvOG_\If7v6bC7e\3b5bz_.wav.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\0FvOG_\If7v6bC7e\f0EOic0XdDlOFjq.wav.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\0FvOG_\pHnRe2.mp3.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\0FvOG_\R0ZGv\Mw_WmLfAqb.mp3.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\0FvOG_\R0ZGv\QrThmYZu3785.mp3.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\0FvOG_\R0ZGv\RZx4l\EJWmccifgKEvGlP\dUdexRla3-lyNxSO.mp3.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\0FvOG_\R0ZGv\RZx4l\EJWmccifgKEvGlP\xutGd E8ljY e FREg\YKC4k-uBt r.wav.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\0FvOG_\R0ZGv\RZx4l\UqP1lGkyImQ\eDXYUw_5wnu.mp3.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\0FvOG_\R0ZGv\RZx4l\UqP1lGkyImQ\Gt94CTS_qIYZ5D.mp3.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\0FvOG_\R0ZGv\RZx4l\UqP1lGkyImQ\I0Wk9Btu8Xsd6z.wav.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\0FvOG_\R0ZGv\RZx4l\UqP1lGkyImQ\nG8H2ZzODfKFiF-XDB.wav.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\FGZfwcp_J5tD6T3Bmy.wav.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\GGis7LvA5z.mp3.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\bgZL-XebeFs.jpg.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\CN7P7.jpg.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\codQG4F\-1uN5Wa.jpg.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\codQG4F\HYj3jBY.png.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\codQG4F\iCKwmBUzATRxvh3dlg.png.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\codQG4F\IGpqL.jpg.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\codQG4F\Iqre0iYjd4uLq3.jpg.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\codQG4F\j-22.bmp.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\codQG4F\J0wtG0Kh2.jpg.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\codQG4F\JGav_ds1Ycat99R.bmp.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\codQG4F\KoCI-2kg.png.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\codQG4F\QsBK9Sjmfv.png.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\codQG4F\Tksc_7hY4qbL7CQ_.jpg.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\codQG4F\YrIrZ.png.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\codQG4F\z0slzDoE0xp.gif.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\nfF_hSV5yd_BuRLqA.jpg.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\p_nFLkJ_.bmp.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\sL-G.bmp.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\TVmCtys7DuKwx S8.gif.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\U6xfys8TdXDj.gif.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\voYT5KVLDd.gif.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\WYqsxEDdk-8rurddQtf.png.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\xIAlsa4k.jpg.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Y0Pn5BcVcimI_Q6an.bmp.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\y_Wpii7bFLLwELY4.png.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\8Mepr8U_s.swf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\-nY6cKVo6c_8wC.mkv.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\5vhdxDCcIc nSuhaky.swf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\H 1 4B4X7-.swf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\mvksmCCrLXnuwg3 O\29oHVA-.avi.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\mvksmCCrLXnuwg3 O\3PQbcAH3lIfLN-X.swf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\mvksmCCrLXnuwg3 O\6Ws-OtAV7 Yu\qgYTQSp.avi.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\mvksmCCrLXnuwg3 O\6Ws-OtAV7 Yu\U3R3.swf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\mvksmCCrLXnuwg3 O\6Ws-OtAV7 Yu\YDcYJ.mp4.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\mvksmCCrLXnuwg3 O\6Ws-OtAV7 Yu\yqaDmhb5UGfg-.mp4.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\mvksmCCrLXnuwg3 O\6Ws-OtAV7 Yu\zTQv_6dD\e5mSOJyYSvb26u.swf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\mvksmCCrLXnuwg3 O\6Ws-OtAV7 Yu\zTQv_6dD\PiGq4HD2xfa.flv.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\mvksmCCrLXnuwg3 O\esIV2rB28-tzAipp.mkv.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\mvksmCCrLXnuwg3 O\JWofIUs1IfJLv1TT.flv.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\mvksmCCrLXnuwg3 O\uqVr1IRjvK.avi.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\mvksmCCrLXnuwg3 O\WF6E1FiisfQyrs9344k\KO86K.mp4.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\mvksmCCrLXnuwg3 O\WF6E1FiisfQyrs9344k\qy9sjKNG4VZpLOqXYQ.avi.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\mvksmCCrLXnuwg3 O\WF6E1FiisfQyrs9344k\YLhfc DVq8a11.mp4.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\oOiWDwxTK0fcl1a.mkv.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\YnkFvMA rlOUtivLF.avi.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\EnableWiFiTracing.cmd.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\PostOOBEScript.cmd.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\amd64\hwcompat.txt.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\amd64\hwexclude.txt.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\i386\hwcompat.txt.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\block.png.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\bluelogo.png.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\bullet.png.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\default.css.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\default_oobe.css.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\eula.css.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\loading.gif.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\logo.png.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\marketing.png.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\Microsoft.WinJS\css\ui-dark.css.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\Microsoft.WinJS\js\base.js.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\Microsoft.WinJS\js\ui.js.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\NoNetworkConnection.png.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\NoNetworkConnectionHoverOver.png.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\eula.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1041\eula.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1046\eula.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\3076\eula.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\2nlNY1vqlBsp 2O.bmp.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\e5A5iv y6xJka.jpg.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\HBZv02kju.mp3.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\IlQbhWBlIje5\bx-0hr2DYt6WYtb4.jpg.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\IlQbhWBlIje5\Jn3eh5DtpsNJ75Waupw.xlsx.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\IlQbhWBlIje5\X8fIeAHWv_8ccqU-.png.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\IlQbhWBlIje5\_WN4xUbd0a qM7OW.flv.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\MIGqF2YFtFNTatULeFf.flv.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\PkvG.gif.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\R5pC4-.jpg.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\s-7HyjhqS65XyB8Zj1.mp4.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\tvA-bVlyH.mp4.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\x9jdGSVA-sXMEl6SVE.ppt.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\Y6x0bnuox1EMC.bmp.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\Yx2Wr-gcI5A.mkv.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\81ekzfl9 vSf578.pptx.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\CK5fMTMcoBdf-27E\bbsk4B2O7ng7gz.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\CK5fMTMcoBdf-27E\yCccdbqn-wp3sxEr.pdf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Database1.accdb.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\DhAj7LV3HsC3oF.rtf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\eim9d dRcYRC60o.xlsx.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\EZVBI1l.xlsx.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\FjSm6FB8SR6fz6qOD.docx.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\GMmbOaDfRwh.xlsx.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\j-zM7peTeS7vEHm0q.ppt.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Ly-r01n2BLUj4N UwsG.docx.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\m7ilW6_\3K0GezI33TW.pdf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\m7ilW6_\BSywU mBx_GlYFIx4.ods.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\m7ilW6_\G7fY-06HrNF2.ots.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\m7ilW6_\gjW Z-.xls.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\m7ilW6_\nzeINc3caO4ZRgPhJ24.ots.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\m7ilW6_\o44nNOg3W03WJhyom.pdf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Outlook Files\kkcie@kdj.kd.pst.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\PPN_Nd1oQNDj9kw.docx.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\pZ3CoQpbB1nvT8dmq\bX_YsK1fTIH5sN.odt.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\pZ3CoQpbB1nvT8dmq\FdVT3FC.ppt.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\pZ3CoQpbB1nvT8dmq\IhUIxiID7d7SxDo1 rBB.pdf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\QyVu-qrEl8ZoB2G.docx.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\trU5biwT.xlsx.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\ZrL2TCIulbX8URlQj8XN\fDW3m22jPVHA6tJ.csv.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\ZrL2TCIulbX8URlQj8XN\HzSY-MX.ppt.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\ZrL2TCIulbX8URlQj8XN\tXJxzPW vTrNAgUT.docx.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\ZrL2TCIulbX8URlQj8XN\ZvgGV63M6HE VMuGeUyh.docx.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\0FvOG_\If7v6bC7e\JyERaK9pKN.wav.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\0FvOG_\R0ZGv\gMdunR7ByqVqyLeMXne.wav.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\0FvOG_\R0ZGv\Gn2i3nI3 yUMlS.mp3.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\0FvOG_\R0ZGv\RZx4l\0rVi_Hff.wav.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\0FvOG_\R0ZGv\RZx4l\PB7uBLkdF.mp3.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\0FvOG_\R0ZGv\yA_x9b3l7j\bH0qFTAsqSI9vsLb.wav.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\X3qJ6gg4w.mp3.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\35MADLTUtj3R8xUvr3N.png.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\8mIJe.jpg.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\codQG4F\e1abGrclisHQhk.gif.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\codQG4F\rJpbY.jpg.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\codQG4F\v-VBOu.png.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\nigUf37xWAtdvl99_Wqb.gif.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\rYxdHoal4XCc.gif.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\5kFzUCELuJ.flv.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\BAINMzjSfurJ CaMCG1.flv.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\9H6dlxxuEo6.avi.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\GWvQtrgMRP3aaSnb12oQ.flv.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\hrdBiWm0N 6RYGg3x1.swf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\LDh1bHtnqy0k 9Lj.avi.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\mvksmCCrLXnuwg3 O\6Ws-OtAV7 Yu\hIbK 9WOEM-p.swf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\mvksmCCrLXnuwg3 O\6Ws-OtAV7 Yu\J93zeyZX3e.mkv.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\mvksmCCrLXnuwg3 O\6Ws-OtAV7 Yu\QF_-g.swf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\mvksmCCrLXnuwg3 O\6Ws-OtAV7 Yu\s3rEmVhiPfxhjPaJ.avi.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\mvksmCCrLXnuwg3 O\6Ws-OtAV7 Yu\zTQv_6dD\OGPgqG.mp4.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\mvksmCCrLXnuwg3 O\C9JJ.avi.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\iEeu6mxf\T2_ OPeI V7UO\mvksmCCrLXnuwg3 O\WF6E1FiisfQyrs9344k\R08OOEPDZcu3.swf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\CBlSWQvY\_dSSc.avi.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\N55KvjZf7m.swf.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\hwcompatShared.txt.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\i386\hwexclude.txt.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\ux\default_eos.css.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\ux\GetStarted.png.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\ux\GetStartedHoverOver.png.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\ux\lock.png.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\ux\Microsoft.WinJS\css\oobe-desktop.css.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\ux\pass.png.[dogeremembersss@protonmail.ch].DogeCrypt | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-1051304884-625712362-2192934891-1000\c71a976da0cbffbff6b43da231aa96fa_33d770d0-06bc-47c5-8714-222cdac43a71 | Dropped File | Stream |
Not Queried
|
...
|
»