VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware |
local.exe
Windows Exe (x86-32)
Created at 2019-07-11T16:09:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\local.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x41dc6a |
Size Of Code | 0x1be00 |
Size Of Initialized Data | 0x1600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-07-11 15:06:47+00:00 |
Version Information (11)
»
Assembly Version | 1.0.0.0 |
Comments | - |
CompanyName | windows |
FileDescription | Bulba |
FileVersion | 1.0.0.0 |
InternalName | Bulba.exe |
LegalCopyright | Copyright © 2019 |
LegalTrademarks | - |
OriginalFilename | Bulba.exe |
ProductName | Bulba |
ProductVersion | 1.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x1bc78 | 0x1be00 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.67 |
.rsrc | 0x41e000 | 0x120c | 0x1400 | 0x1c000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.81 |
.reloc | 0x420000 | 0xc | 0x200 | 0x1d400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x1dc40 | 0x1be40 | 0x0 |
Memory Dumps (47)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747B1D48, 0x7486D624, ... |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747B1D48 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747C0CD4 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747CB06C |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747CA830 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747C1250 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747C35F0 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747B326C |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747C922C |
![]() |
![]() |
...
|
buffer | 1 | 0x001F6000 | 0x001F6FFF | First Execution | - | 32-bit | 0x001F6062, 0x001F6012 |
![]() |
![]() |
...
|
buffer | 1 | 0x00231000 | 0x00231FFF | First Execution | - | 32-bit | 0x00231000 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747BE3F4 |
![]() |
![]() |
...
|
buffer | 1 | 0x00232000 | 0x00232FFF | First Execution | - | 32-bit | 0x00232688, 0x00232038 |
![]() |
![]() |
...
|
system.configuration.ni.dll | 1 | 0x73A10000 | 0x73AFFFFF | Content Changed | - | 32-bit | 0x73A286D0, 0x73A29248, ... |
![]() |
![]() |
...
|
system.configuration.ni.dll | 1 | 0x73A10000 | 0x73AFFFFF | Content Changed | - | 32-bit | 0x73A289F0 |
![]() |
![]() |
...
|
system.configuration.ni.dll | 1 | 0x73A10000 | 0x73AFFFFF | Content Changed | - | 32-bit | 0x73A40874 |
![]() |
![]() |
...
|
system.configuration.ni.dll | 1 | 0x73A10000 | 0x73AFFFFF | Content Changed | - | 32-bit | 0x73A39A40 |
![]() |
![]() |
...
|
system.configuration.ni.dll | 1 | 0x73A10000 | 0x73AFFFFF | Content Changed | - | 32-bit | 0x73A3B254 |
![]() |
![]() |
...
|
system.configuration.ni.dll | 1 | 0x73A10000 | 0x73AFFFFF | Content Changed | - | 32-bit | 0x73A3A000 |
![]() |
![]() |
...
|
system.configuration.ni.dll | 1 | 0x73A10000 | 0x73AFFFFF | Content Changed | - | 32-bit | 0x73A42360 |
![]() |
![]() |
...
|
system.configuration.ni.dll | 1 | 0x73A10000 | 0x73AFFFFF | Content Changed | - | 32-bit | 0x73A3C000 |
![]() |
![]() |
...
|
system.configuration.ni.dll | 1 | 0x73A10000 | 0x73AFFFFF | Content Changed | - | 32-bit | 0x73A3D000 |
![]() |
![]() |
...
|
system.configuration.ni.dll | 1 | 0x73A10000 | 0x73AFFFFF | Content Changed | - | 32-bit | 0x73A3E000 |
![]() |
![]() |
...
|
system.configuration.ni.dll | 1 | 0x73A10000 | 0x73AFFFFF | Content Changed | - | 32-bit | 0x73A3F040 |
![]() |
![]() |
...
|
system.configuration.ni.dll | 1 | 0x73A10000 | 0x73AFFFFF | Content Changed | - | 32-bit | 0x73A279C0 |
![]() |
![]() |
...
|
system.configuration.ni.dll | 1 | 0x73A10000 | 0x73AFFFFF | Content Changed | - | 32-bit | 0x73A38E1C, 0x73A3BF80, ... |
![]() |
![]() |
...
|
buffer | 1 | 0x00515000 | 0x0051BFFF | First Execution | - | 32-bit | 0x0051B1D4 |
![]() |
![]() |
...
|
system.configuration.ni.dll | 1 | 0x73A10000 | 0x73AFFFFF | Content Changed | - | 32-bit | 0x73A34B08, 0x73A35090 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747C922C, 0x747BFAB0, ... |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747C1680, 0x747C3D80, ... |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747B7F18, 0x7488B248, ... |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x7486D4B0, 0x7488D614 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x7486E02C |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x748B5480 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747C5560 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x748AAD60 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747CC8D4 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x7488C7D4 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747B3010 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747CB4A8 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x74893294, 0x74892AAC |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747BEDAC |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x74866874 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747C2F80 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747C6410, 0x74879480 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x747C8F10 |
![]() |
![]() |
...
|
system.drawing.ni.dll | 1 | 0x74780000 | 0x7490CFFF | Content Changed | - | 32-bit | 0x7486C094, 0x747B4DEC |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Ransom.REntS.Gen.1 |
Malicious
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\gdipfontcachev1.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\1FQ_9d0LXe6pMvO2.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\2Xy0mJv5xwhx4K1K.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\6oF3FL3YfrkND.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\7C9V.jpg | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ENBmMMWK.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\gH-zamZAJg.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\m4SvX-jeGXwW.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\O0y0hsLAoKxoA.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\sN3K33tDMKQaoIqJe.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wcRE.jpg | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\XRPTN7Kw.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\yjbKOP66PA6 t9xa78.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZR4FkDMgSj24KiPo8.odt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\T9ZgHii-\62iXFu5VPwWKjK9YrtO.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\T9ZgHii-\qumyxXz YiQpNxh4shD.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\tQYzvy44\afnTu.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\tQYzvy44\GXNTB.jpg | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\tQYzvy44\kHfLoG p4e5.pdf | Modified File |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\tQYzvy44\pKpIeF7B-b-a.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Zh5KHKzPc6AOkC3JGPhN\80Sx6N6hteC.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Links\Desktop.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Links\Downloads.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Links\RecentPlaces.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\1pX_gB60 0bE4d3dn.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\2vaMuPlZ6I8mh4S.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\5Vv FMKnuQagvr1v.odt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\at0FaHyq.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\c-OUqwNcpwZKsqZUKU.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\CcxLxbYA5PVQheLVcI.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\DihjpK.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Dkou zZ n2_BH1.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fKdo0m3dDNNLylacs0H.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\I5LVn7OvnVGp4I.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KsPNdEKyG-iF8dd5Hv.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\MUl3j_Wys.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\OZlfj3nx.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\rRrY7K.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\tKkd.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\WWhGoLhk8TzOpVmq1.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Y0f8W8Ps2fInLd97.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y_f_n F2Mg6yklJf0LC.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\z0uuBt3LxozCdl4TPm0.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\eUU-xXmHIRDJW4 2Zx56\0pkDP.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\eUU-xXmHIRDJW4 2Zx56\b2naIXbZa6\1OSFGjl0nYx-M.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\eUU-xXmHIRDJW4 2Zx56\b2naIXbZa6\2OYFkWprG4a574w2dLu.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\eUU-xXmHIRDJW4 2Zx56\b2naIXbZa6\5hfaAXLRMbakfPHYNwEQ.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\eUU-xXmHIRDJW4 2Zx56\b2naIXbZa6\CrOtm1_fzIMEnAQWf.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\eUU-xXmHIRDJW4 2Zx56\b2naIXbZa6\e5 uvmMI3me7.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\eUU-xXmHIRDJW4 2Zx56\b2naIXbZa6\lC2WFP1.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\eUU-xXmHIRDJW4 2Zx56\b2naIXbZa6\OJrh2t9nE.pdf | Modified File |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\eUU-xXmHIRDJW4 2Zx56\b2naIXbZa6\PthlTMNUNtM.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\eUU-xXmHIRDJW4 2Zx56\b2naIXbZa6\TUjNEjAe GTq.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\eUU-xXmHIRDJW4 2Zx56\b2naIXbZa6\wtfOidnhEd_h7Scw.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\2-kRBk0S.jpg | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\aOKaoV.jpg | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\GHzQiL.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\hyJFOAoAXwsv.jpg | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\v_sDMrPVb-DCaU80ds7.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VpubQOvc\AamMrzPmlGyXhuwAk.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VpubQOvc\EOesE9egGtlf_.jpg | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VpubQOvc\LNbCQirEd1.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VpubQOvc\UFVPng9rMg2O.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VpubQOvc\2xdnrnaXUHwWYk2evk3\PkHSV- FwSU8Ry.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VpubQOvc\2xdnrnaXUHwWYk2evk3\qy8DQkizNwG4c.jpg | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VpubQOvc\2xdnrnaXUHwWYk2evk3\TDyD6ro.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VpubQOvc\2xdnrnaXUHwWYk2evk3\LXgD hT\D84j8.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VpubQOvc\2xdnrnaXUHwWYk2evk3\LXgD hT\DuJteP9pnzDt5F-P8c.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VpubQOvc\2xdnrnaXUHwWYk2evk3\s95FnDm 7mO2PYSi2\oid828hxpGyx.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VpubQOvc\2xdnrnaXUHwWYk2evk3\s95FnDm 7mO2PYSi2\sg-E3ucFPLsX3qelYBy.jpg | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VpubQOvc\2xdnrnaXUHwWYk2evk3\s95FnDm 7mO2PYSi2\TEavp.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\VpubQOvc\2xdnrnaXUHwWYk2evk3\s95FnDm 7mO2PYSi2\y5ZkF.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\FBbg9d\PKOld\yGHv\PkOkNYdIK1Akl.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\OTVDMA8CV6qQ\SHv2e.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\OTVDMA8CV6qQ\wTqw.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\_NBsFIdM9cm\Ga_2y993YyKn.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\_NBsFIdM9cm\B3hXqdSEmcNd0ro\IdggPsA8JrqU.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\_NBsFIdM9cm\B3hXqdSEmcNd0ro\r3c9is99-0a.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\_NBsFIdM9cm\B3hXqdSEmcNd0ro\J3JECENTIUTLx\bq8OPOoV uHDp26ERw.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\_NBsFIdM9cm\B3hXqdSEmcNd0ro\vVtoiOUAe6UV8\6H149f.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\_NBsFIdM9cm\B3hXqdSEmcNd0ro\vVtoiOUAe6UV8\tqzmtg594Q.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\h6S9PxWHBy_gh7P\Ulsp8p_Vf-DIGm.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\qJcDr1\70VRtxhu8DWsBjDdMTN.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\qJcDr1\apkT5SjumXOE.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\qJcDr1\Yg_XgPbG znCpTe.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\qJcDr1\1EG_rMLJW\V0fJr8b4TB.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\qJcDr1\1EG_rMLJW\zX3Ey.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\qJcDr1\1EG_rMLJW\Hy_v9XfWfaIog\8Pz6FCHO31ZeTuXYDv8m.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\qJcDr1\1EG_rMLJW\iYiVuH86FKUUy2zrS\mhMLJM9Q3gkc.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\qJcDr1\1EG_rMLJW\iYiVuH86FKUUy2zrS\o21 pJbhYF47gJ.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\qJcDr1\1EG_rMLJW\iYiVuH86FKUUy2zrS\U9cE1a872Kv.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\qJcDr1\dXKzZEjFy-BjA\915YANnKlksuH.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\qJcDr1\dXKzZEjFy-BjA\wGjbcfyAcwE2k.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\qJcDr1\uFDmIkn7ZcT9-q\v974nqEZsT5FDFAdVdnN.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\qJcDr1\uFDmIkn7ZcT9-q\pYlk-npuf-T0m8Oo\6thJezNm6cIWvHasF.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact.Pox | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact.Pox | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact.Pox | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact.Pox | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\m7dOR-18S 2XvaRj3rX9.pptx.Pox | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\FBbg9d\PKOld\YR5fG.mp3.Pox | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\gPUcqx\-FQ_DUA4P.avi.Pox | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\HOW TO DECRYPT FILES.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\eUU-xXmHIRDJW4 2Zx56\1icBSdqhb.csv.Pox | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\eUU-xXmHIRDJW4 2Zx56\CiXAMo2Ojlsrm0hM.pdf.Pox | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\eUU-xXmHIRDJW4 2Zx56\DiUwgPxxPJM-B6t5U9Y.xlsx.Pox | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\eUU-xXmHIRDJW4 2Zx56\FlY6cRuyqsRGmwwsdu.ppt.Pox | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\eUU-xXmHIRDJW4 2Zx56\GXOv.docx.Pox | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\eUU-xXmHIRDJW4 2Zx56\vJ YPF-i Nn4.xls.Pox | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\eUU-xXmHIRDJW4 2Zx56\yfFKDC845C6.pptx.Pox | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\h6S9PxWHBy_gh7P\gulHrt0neWOD_3I7h8D3.mp4.Pox | Dropped File | Stream |
Unknown
|
...
|
»