VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Gen:Variant.Midie.70925
Mal/Generic-S
|
지원서_20200303(열심히하겠습니다 잘부탁드립니다).exe
Windows Exe (x86-32)
Created at 2020-03-03T14:16:00
Remarks
(0x0200001E): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\지원서_20200303(열심히하겠습니다 잘부탁드립니다).exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x404d47 |
Size Of Code | 0x1b000 |
Size Of Initialized Data | 0x42bf000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-06-06 17:39:57+00:00 |
Sections (7)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1afd8 | 0x1b000 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.17 |
.rdata | 0x41c000 | 0x4e3c | 0x5000 | 0x1b400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.98 |
.data | 0x421000 | 0x4299f10 | 0x1c00 | 0x20400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.76 |
.voda | 0x46bb000 | 0x3b88 | 0x3c00 | 0x22000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 0.0 |
.tls | 0x46bf000 | 0x9 | 0x200 | 0x25c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x46c0000 | 0x11b28 | 0x11c00 | 0x25e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.21 |
.reloc | 0x46d2000 | 0xa548 | 0xa600 | 0x37a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 1.22 |
Imports (2)
»
KERNEL32.dll (102)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetFullPathNameA | 0x0 | 0x41c000 | 0x204b0 | 0x1f8b0 | 0x1f8 |
GetEnvironmentVariableW | 0x0 | 0x41c004 | 0x204b4 | 0x1f8b4 | 0x1dc |
WriteConsoleOutputCharacterW | 0x0 | 0x41c008 | 0x204b8 | 0x1f8b8 | 0x522 |
lstrlenA | 0x0 | 0x41c00c | 0x204bc | 0x1f8bc | 0x54d |
UnmapViewOfFile | 0x0 | 0x41c010 | 0x204c0 | 0x1f8c0 | 0x4d6 |
LoadResource | 0x0 | 0x41c014 | 0x204c4 | 0x1f8c4 | 0x341 |
HeapAlloc | 0x0 | 0x41c018 | 0x204c8 | 0x1f8c8 | 0x2cb |
GetConsoleAliasA | 0x0 | 0x41c01c | 0x204cc | 0x1f8cc | 0x190 |
GetCurrentProcess | 0x0 | 0x41c020 | 0x204d0 | 0x1f8d0 | 0x1c0 |
SetMailslotInfo | 0x0 | 0x41c024 | 0x204d4 | 0x1f8d4 | 0x479 |
SetConsoleScreenBufferSize | 0x0 | 0x41c028 | 0x204d8 | 0x1f8d8 | 0x445 |
SetThreadExecutionState | 0x0 | 0x41c02c | 0x204dc | 0x1f8dc | 0x493 |
GetTickCount | 0x0 | 0x41c030 | 0x204e0 | 0x1f8e0 | 0x293 |
GetPriorityClass | 0x0 | 0x41c034 | 0x204e4 | 0x1f8e4 | 0x23a |
GlobalAlloc | 0x0 | 0x41c038 | 0x204e8 | 0x1f8e8 | 0x2b3 |
LoadLibraryW | 0x0 | 0x41c03c | 0x204ec | 0x1f8ec | 0x33f |
GetThreadSelectorEntry | 0x0 | 0x41c040 | 0x204f0 | 0x1f8f0 | 0x290 |
GetSystemWindowsDirectoryA | 0x0 | 0x41c044 | 0x204f4 | 0x1f8f4 | 0x27b |
GetModuleFileNameW | 0x0 | 0x41c048 | 0x204f8 | 0x1f8f8 | 0x214 |
MultiByteToWideChar | 0x0 | 0x41c04c | 0x204fc | 0x1f8fc | 0x367 |
DisconnectNamedPipe | 0x0 | 0x41c050 | 0x20500 | 0x1f900 | 0xe1 |
FindFirstFileExA | 0x0 | 0x41c054 | 0x20504 | 0x1f904 | 0x133 |
GetLastError | 0x0 | 0x41c058 | 0x20508 | 0x1f908 | 0x202 |
GetLongPathNameW | 0x0 | 0x41c05c | 0x2050c | 0x1f90c | 0x20f |
GetProcAddress | 0x0 | 0x41c060 | 0x20510 | 0x1f910 | 0x245 |
GetNumaHighestNodeNumber | 0x0 | 0x41c064 | 0x20514 | 0x1f914 | 0x229 |
_hwrite | 0x0 | 0x41c068 | 0x20518 | 0x1f918 | 0x536 |
GetAtomNameA | 0x0 | 0x41c06c | 0x2051c | 0x1f91c | 0x16d |
ProcessIdToSessionId | 0x0 | 0x41c070 | 0x20520 | 0x1f920 | 0x399 |
BuildCommDCBAndTimeoutsW | 0x0 | 0x41c074 | 0x20524 | 0x1f924 | 0x3c |
FindFirstVolumeMountPointW | 0x0 | 0x41c078 | 0x20528 | 0x1f928 | 0x13e |
GetExitCodeThread | 0x0 | 0x41c07c | 0x2052c | 0x1f92c | 0x1e0 |
SetProcessWorkingSetSize | 0x0 | 0x41c080 | 0x20530 | 0x1f930 | 0x484 |
CreatePipe | 0x0 | 0x41c084 | 0x20534 | 0x1f934 | 0xa1 |
GetDefaultCommConfigA | 0x0 | 0x41c088 | 0x20538 | 0x1f938 | 0x1c9 |
CreateIoCompletionPort | 0x0 | 0x41c08c | 0x2053c | 0x1f93c | 0x94 |
_lread | 0x0 | 0x41c090 | 0x20540 | 0x1f940 | 0x53b |
OpenFileMappingW | 0x0 | 0x41c094 | 0x20544 | 0x1f944 | 0x379 |
SetCalendarInfoA | 0x0 | 0x41c098 | 0x20548 | 0x1f948 | 0x41e |
ResetWriteWatch | 0x0 | 0x41c09c | 0x2054c | 0x1f94c | 0x410 |
FindNextVolumeA | 0x0 | 0x41c0a0 | 0x20550 | 0x1f950 | 0x147 |
CreateFileW | 0x0 | 0x41c0a4 | 0x20554 | 0x1f954 | 0x8f |
WriteConsoleW | 0x0 | 0x41c0a8 | 0x20558 | 0x1f958 | 0x524 |
InterlockedIncrement | 0x0 | 0x41c0ac | 0x2055c | 0x1f95c | 0x2ef |
InterlockedDecrement | 0x0 | 0x41c0b0 | 0x20560 | 0x1f960 | 0x2eb |
EncodePointer | 0x0 | 0x41c0b4 | 0x20564 | 0x1f964 | 0xea |
DecodePointer | 0x0 | 0x41c0b8 | 0x20568 | 0x1f968 | 0xca |
Sleep | 0x0 | 0x41c0bc | 0x2056c | 0x1f96c | 0x4b2 |
InitializeCriticalSection | 0x0 | 0x41c0c0 | 0x20570 | 0x1f970 | 0x2e2 |
DeleteCriticalSection | 0x0 | 0x41c0c4 | 0x20574 | 0x1f974 | 0xd1 |
EnterCriticalSection | 0x0 | 0x41c0c8 | 0x20578 | 0x1f978 | 0xee |
LeaveCriticalSection | 0x0 | 0x41c0cc | 0x2057c | 0x1f97c | 0x339 |
HeapFree | 0x0 | 0x41c0d0 | 0x20580 | 0x1f980 | 0x2cf |
GetCommandLineW | 0x0 | 0x41c0d4 | 0x20584 | 0x1f984 | 0x187 |
HeapSetInformation | 0x0 | 0x41c0d8 | 0x20588 | 0x1f988 | 0x2d3 |
GetStartupInfoW | 0x0 | 0x41c0dc | 0x2058c | 0x1f98c | 0x263 |
RaiseException | 0x0 | 0x41c0e0 | 0x20590 | 0x1f990 | 0x3b1 |
RtlUnwind | 0x0 | 0x41c0e4 | 0x20594 | 0x1f994 | 0x418 |
WideCharToMultiByte | 0x0 | 0x41c0e8 | 0x20598 | 0x1f998 | 0x511 |
LCMapStringW | 0x0 | 0x41c0ec | 0x2059c | 0x1f99c | 0x32d |
GetCPInfo | 0x0 | 0x41c0f0 | 0x205a0 | 0x1f9a0 | 0x172 |
TerminateProcess | 0x0 | 0x41c0f4 | 0x205a4 | 0x1f9a4 | 0x4c0 |
UnhandledExceptionFilter | 0x0 | 0x41c0f8 | 0x205a8 | 0x1f9a8 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x41c0fc | 0x205ac | 0x1f9ac | 0x4a5 |
IsDebuggerPresent | 0x0 | 0x41c100 | 0x205b0 | 0x1f9b0 | 0x300 |
IsProcessorFeaturePresent | 0x0 | 0x41c104 | 0x205b4 | 0x1f9b4 | 0x304 |
HeapCreate | 0x0 | 0x41c108 | 0x205b8 | 0x1f9b8 | 0x2cd |
SetHandleCount | 0x0 | 0x41c10c | 0x205bc | 0x1f9bc | 0x46f |
GetStdHandle | 0x0 | 0x41c110 | 0x205c0 | 0x1f9c0 | 0x264 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41c114 | 0x205c4 | 0x1f9c4 | 0x2e3 |
GetFileType | 0x0 | 0x41c118 | 0x205c8 | 0x1f9c8 | 0x1f3 |
SetFilePointer | 0x0 | 0x41c11c | 0x205cc | 0x1f9cc | 0x466 |
GetModuleHandleW | 0x0 | 0x41c120 | 0x205d0 | 0x1f9d0 | 0x218 |
ExitProcess | 0x0 | 0x41c124 | 0x205d4 | 0x1f9d4 | 0x119 |
WriteFile | 0x0 | 0x41c128 | 0x205d8 | 0x1f9d8 | 0x525 |
FreeEnvironmentStringsW | 0x0 | 0x41c12c | 0x205dc | 0x1f9dc | 0x161 |
GetEnvironmentStringsW | 0x0 | 0x41c130 | 0x205e0 | 0x1f9e0 | 0x1da |
TlsAlloc | 0x0 | 0x41c134 | 0x205e4 | 0x1f9e4 | 0x4c5 |
TlsGetValue | 0x0 | 0x41c138 | 0x205e8 | 0x1f9e8 | 0x4c7 |
TlsSetValue | 0x0 | 0x41c13c | 0x205ec | 0x1f9ec | 0x4c8 |
TlsFree | 0x0 | 0x41c140 | 0x205f0 | 0x1f9f0 | 0x4c6 |
SetLastError | 0x0 | 0x41c144 | 0x205f4 | 0x1f9f4 | 0x473 |
GetCurrentThreadId | 0x0 | 0x41c148 | 0x205f8 | 0x1f9f8 | 0x1c5 |
QueryPerformanceCounter | 0x0 | 0x41c14c | 0x205fc | 0x1f9fc | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x41c150 | 0x20600 | 0x1fa00 | 0x1c1 |
GetSystemTimeAsFileTime | 0x0 | 0x41c154 | 0x20604 | 0x1fa04 | 0x279 |
GetLocaleInfoW | 0x0 | 0x41c158 | 0x20608 | 0x1fa08 | 0x206 |
HeapSize | 0x0 | 0x41c15c | 0x2060c | 0x1fa0c | 0x2d4 |
GetACP | 0x0 | 0x41c160 | 0x20610 | 0x1fa10 | 0x168 |
GetOEMCP | 0x0 | 0x41c164 | 0x20614 | 0x1fa14 | 0x237 |
IsValidCodePage | 0x0 | 0x41c168 | 0x20618 | 0x1fa18 | 0x30a |
GetUserDefaultLCID | 0x0 | 0x41c16c | 0x2061c | 0x1fa1c | 0x29b |
GetLocaleInfoA | 0x0 | 0x41c170 | 0x20620 | 0x1fa20 | 0x204 |
EnumSystemLocalesA | 0x0 | 0x41c174 | 0x20624 | 0x1fa24 | 0x10d |
IsValidLocale | 0x0 | 0x41c178 | 0x20628 | 0x1fa28 | 0x30c |
GetStringTypeW | 0x0 | 0x41c17c | 0x2062c | 0x1fa2c | 0x269 |
HeapReAlloc | 0x0 | 0x41c180 | 0x20630 | 0x1fa30 | 0x2d2 |
GetConsoleCP | 0x0 | 0x41c184 | 0x20634 | 0x1fa34 | 0x19a |
GetConsoleMode | 0x0 | 0x41c188 | 0x20638 | 0x1fa38 | 0x1ac |
SetStdHandle | 0x0 | 0x41c18c | 0x2063c | 0x1fa3c | 0x487 |
FlushFileBuffers | 0x0 | 0x41c190 | 0x20640 | 0x1fa40 | 0x157 |
CloseHandle | 0x0 | 0x41c194 | 0x20644 | 0x1fa44 | 0x52 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCaretPos | 0x0 | 0x41c19c | 0x2064c | 0x1fa4c | 0x10a |
Memory Dumps (5)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
buffer | 1 | 0x048B22D0 | 0x048B88A7 | First Execution |
![]() |
32-bit | 0x048B22D0 |
![]() |
![]() |
...
|
buffer | 1 | 0x00210000 | 0x00219FFF | First Execution |
![]() |
32-bit | 0x00210000 |
![]() |
![]() |
...
|
buffer | 2 | 0x002322E0 | 0x002388B7 | First Execution |
![]() |
32-bit | 0x002322E0 |
![]() |
![]() |
...
|
buffer | 2 | 0x00390000 | 0x00399FFF | First Execution |
![]() |
32-bit | 0x00390000 |
![]() |
![]() |
...
|
buffer | 2 | 0x00390000 | 0x00399FFF | Content Changed |
![]() |
32-bit | 0x00390920 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Midie.70925 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\0bx3lriX2fC_5 2.flv.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\2QqEzLzXlC4xPHd.avi.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\5J2VCH9l L9sBc3-.mkv.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\5VoqguxMTR7hO9.flv.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\7_AVLXdD0F.csv.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\8Hkfp.mp3.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\8ypiVWMn m2wdao4ygV.mkv.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9Ogn9zWJr2lT61U.png.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\AgxV6.jpg.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\CBeFWMOb7eC-7r.m4a.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\d4THM7CMqY6HfrrW.wav.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\desktop.ini.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EMf7n.mkv.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EpvZemi1HVj39\SpJJAfgcLZ.mp4.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\F9lH0pBC-he.xls.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\fwFa0nbrWh1.mp3.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\I-yr5EEx.rtf.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\i0R3CB76xq2n.pptx.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\IFfSfRDj8dUxOs.gif.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\jA4QIZB Xjb.gif.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\K2s1OqUv74o.mp3.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\LWsucVWsiQouBGsr.avi.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MHdrTnPn3vLkuZD.png.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\mtMQ9c9PY3\59c4eHOlhofXdMGy.odt.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\mtMQ9c9PY3\eIq1aB5uZglZSaiI4.rtf.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NCns.jpg.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\QnF-.avi.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\RH9Bhxy4X.doc.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\V498SvTI0 yM.doc.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\VDdt1.odp.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\vmEIs.xls.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\y09QZFJLD np.png.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Y8t6pfdPZKS87AXpinM.png.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\YFdUaqM7Rw4tc9jlc.flv.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\zhXH4iZh8G1kq.gif.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\zqKAg.xlsx.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\Boot\BOOTSTAT.DAT.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\BOOTSECT.BAK.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.cab.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.cab.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.msi.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfLR.cab.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.msi.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioLR.cab.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveLR.cab.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.msi.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\1033\dwintl20.dll.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\branding.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\msvcr90.dll.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.msi.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Setup.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.msi.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccLR.cab.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\branding.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.msi.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.msi.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.xml.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPlusrWW.msi.[4B2E4630].[helpdesk_makp@protonmail.ch].makop | Dropped File | Stream |
Unknown
|
...
|
»