VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Dropper
|
Threat Names: |
Gen:Heur.Ransom.Imps.3
Mal/Generic-S
|
WinUpdt.exe
Windows Exe (x86-32)
Created at 2020-03-02T15:39:00
Remarks
(0x0200001E): The maximum size of extracted files was exceeded. Some files may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\WinUpdt.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4140fe |
Size Of Code | 0x12200 |
Size Of Initialized Data | 0x1600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-02-15 10:20:30+00:00 |
Version Information (11)
»
Assembly Version | 1.0.0.0 |
Comments | - |
CompanyName | - |
FileDescription | WinUpdt |
FileVersion | 1.0.0.0 |
InternalName | WinUpdt.exe |
LegalCopyright | Copyright © 2020 |
LegalTrademarks | - |
OriginalFilename | WinUpdt.exe |
ProductName | WinUpdt |
ProductVersion | 1.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x12104 | 0x12200 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.39 |
.rsrc | 0x416000 | 0x1210 | 0x1400 | 0x12400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.81 |
.reloc | 0x418000 | 0xc | 0x200 | 0x13800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.08 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x140cc | 0x122cc | 0x0 |
Memory Dumps (10)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
winupdt.exe | 1 | 0x013E0000 | 0x013F9FFF | Relevant Image |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x00176000 | 0x00176FFF | First Execution |
![]() |
32-bit | 0x00176012 |
![]() |
![]() |
...
|
buffer | 1 | 0x00254000 | 0x00254FFF | First Execution |
![]() |
32-bit | 0x00254150 |
![]() |
![]() |
...
|
buffer | 1 | 0x00255000 | 0x00255FFF | First Execution |
![]() |
32-bit | 0x002550D8 |
![]() |
![]() |
...
|
buffer | 1 | 0x00255000 | 0x00255FFF | Content Changed |
![]() |
32-bit | 0x002557A0 |
![]() |
![]() |
...
|
buffer | 1 | 0x00254000 | 0x00254FFF | Content Changed |
![]() |
32-bit | 0x00254B49 |
![]() |
![]() |
...
|
buffer | 1 | 0x00176000 | 0x00176FFF | Content Changed |
![]() |
32-bit | 0x00176032 |
![]() |
![]() |
...
|
buffer | 1 | 0x00259000 | 0x00259FFF | First Execution |
![]() |
32-bit | 0x00259088 |
![]() |
![]() |
...
|
winupdt.exe | 1 | 0x013E0000 | 0x013F9FFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
winupdt.exe | 1 | 0x013E0000 | 0x013F9FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Ransom.Imps.3 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\WinUpdt.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4140fe |
Size Of Code | 0x12200 |
Size Of Initialized Data | 0x1600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-02-15 10:20:30+00:00 |
Version Information (11)
»
Assembly Version | 1.0.0.0 |
Comments | - |
CompanyName | - |
FileDescription | WinUpdt |
FileVersion | 1.0.0.0 |
InternalName | WinUpdt.exe |
LegalCopyright | Copyright © 2020 |
LegalTrademarks | - |
OriginalFilename | WinUpdt.exe |
ProductName | WinUpdt |
ProductVersion | 1.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x12104 | 0x12200 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.39 |
.rsrc | 0x416000 | 0x1210 | 0x1400 | 0x12400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.81 |
.reloc | 0x418000 | 0xc | 0x200 | 0x13800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.08 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x140cc | 0x122cc | 0x0 |
Memory Dumps (15)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
winupdt.exe | 10 | 0x00B10000 | 0x00B29FFF | Relevant Image |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 10 | 0x00146000 | 0x00146FFF | First Execution |
![]() |
32-bit | 0x00146012 |
![]() |
![]() |
...
|
buffer | 10 | 0x00264000 | 0x00264FFF | First Execution |
![]() |
32-bit | 0x00264150 |
![]() |
![]() |
...
|
buffer | 10 | 0x00265000 | 0x00265FFF | First Execution |
![]() |
32-bit | 0x002650D8 |
![]() |
![]() |
...
|
buffer | 10 | 0x00264000 | 0x00264FFF | Content Changed |
![]() |
32-bit | 0x00264489 |
![]() |
![]() |
...
|
buffer | 10 | 0x00269000 | 0x00269FFF | First Execution |
![]() |
32-bit | 0x00269088 |
![]() |
![]() |
...
|
buffer | 10 | 0x00146000 | 0x00146FFF | Content Changed |
![]() |
32-bit | 0x00146032 |
![]() |
![]() |
...
|
buffer | 10 | 0x00146000 | 0x00146FFF | Content Changed |
![]() |
32-bit | 0x00146052 |
![]() |
![]() |
...
|
buffer | 10 | 0x00264000 | 0x00264FFF | Content Changed |
![]() |
32-bit | 0x002647C8 |
![]() |
![]() |
...
|
buffer | 10 | 0x00269000 | 0x00269FFF | Content Changed |
![]() |
32-bit | 0x00269C40 |
![]() |
![]() |
...
|
buffer | 10 | 0x0026A000 | 0x0026AFFF | First Execution |
![]() |
32-bit | 0x0026A198 |
![]() |
![]() |
...
|
buffer | 10 | 0x04B05000 | 0x04B0BFFF | First Execution |
![]() |
32-bit | 0x04B0B336 |
![]() |
![]() |
...
|
buffer | 10 | 0x0026A000 | 0x0026AFFF | Content Changed |
![]() |
32-bit | 0x0026A89A |
![]() |
![]() |
...
|
buffer | 10 | 0x00264000 | 0x00264FFF | Content Changed |
![]() |
32-bit | 0x00264F60 |
![]() |
![]() |
...
|
winupdt.exe | 10 | 0x00B10000 | 0x00B29FFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Ransom.Imps.3 |
Malicious
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\gdipfontcachev1.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\-4KTZQ8c-4L_GN-.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\5BVnbBQ.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\6j_RA.csv.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\7Qln-Obr.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\99gL.pptx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\d4AuH3B.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\G2VYNULlRp1dGEM.pptx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\g6fYp_Iq2J0.docx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JvdtKAy8y.pptx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\KNGyRf7.rtf.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\MI100KI06dECQ-OFr.docx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\N-RC1ehvHIL.pptx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\OPneRizEsCfw.xlsx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\sJW8oaoLJG3YP34WrevM.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Vc5FB54HT.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\vq0DOQYbOerhfDd_sZsV.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Zck2UsisaP9Cfi.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ZVcK2BPc6fQ1Q7V.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fD6D\5OMRGKrX0Q.xlsx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fD6D\iu _pwjkz6y-Q p_.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fD6D\kn5oA0.docx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fD6D\N4j3SO.pdf.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fD6D\UVbgFYLv6.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\MqiJ9nf_bQCiklH\iW0gsaCRU5BTYudlOT-R.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\MqiJ9nf_bQCiklH\Lh-fmvDxe3XRZzV7__u\3OM LYT9P.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\MqiJ9nf_bQCiklH\Lh-fmvDxe3XRZzV7__u\q5_qIHcDS.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\MqiJ9nf_bQCiklH\Lh-fmvDxe3XRZzV7__u\EmgH\EnEC8-8loAEpSUfOjq.xlsx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\MqiJ9nf_bQCiklH\Lh-fmvDxe3XRZzV7__u\EmgH\it1m.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\MqiJ9nf_bQCiklH\Lh-fmvDxe3XRZzV7__u\EmgH\pUk iqx9utQs.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\MqiJ9nf_bQCiklH\Lh-fmvDxe3XRZzV7__u\EmgH\jWz6NyW3t0HY4Cspo2L\ivM1Zrvj-k5n O.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\MqiJ9nf_bQCiklH\Lh-fmvDxe3XRZzV7__u\EmgH\jWz6NyW3t0HY4Cspo2L\mvLJ\6ro4esLdTdhW.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\MqiJ9nf_bQCiklH\Lh-fmvDxe3XRZzV7__u\EmgH\jWz6NyW3t0HY4Cspo2L\s1CtOvgXxiNQ\3DiWbcJjnvk hj-Pi.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\MqiJ9nf_bQCiklH\Lh-fmvDxe3XRZzV7__u\EmgH\jWz6NyW3t0HY4Cspo2L\s1CtOvgXxiNQ\PwjCZbBF8izkVTaY7.pdf.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\MqiJ9nf_bQCiklH\Lh-fmvDxe3XRZzV7__u\EmgH\jWz6NyW3t0HY4Cspo2L\s1CtOvgXxiNQ\QuOrBUR7n.pdf.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\MqiJ9nf_bQCiklH\Lh-fmvDxe3XRZzV7__u\EmgH\jWz6NyW3t0HY4Cspo2L\UAbWyI\93HBiA.xlsx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\MqiJ9nf_bQCiklH\Lh-fmvDxe3XRZzV7__u\EmgH\jWz6NyW3t0HY4Cspo2L\UAbWyI\H0sX8o.doc.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\MqiJ9nf_bQCiklH\Lh-fmvDxe3XRZzV7__u\EmgH\jWz6NyW3t0HY4Cspo2L\UAbWyI\SGHUQ3pKCae8l1yK.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ygHeErUigNgnJVNED2H\JtjBA9KpXXb8ddEZtam1.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ygHeErUigNgnJVNED2H\OZn6bCmH.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ygHeErUigNgnJVNED2H\PnR2UY.ppt.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\11 amZT.bmp.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9z BNXadSRyumUU0baz.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\fLh1h.mp4.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\JxIX KIkfig.mp3.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\lcnY6.odt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\TDlN83c0KGj.mp3.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ULak.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\X1C6gqUbE5.jpg.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\XZ29SJ.docx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\6PXVy\h88yXqHGcm Q4cY0.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\IKufslt2XxHzBF\1RRgi1e Skyto32FY\16_sZjiTA.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\IKufslt2XxHzBF\1RRgi1e Skyto32FY\VKyXUQUPpFM.bmp.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\IKufslt2XxHzBF\vmPe\pFAqEf Z.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\IKufslt2XxHzBF\vmPe\EW26Hgvn-ZA ipq\8r8sucz2oACgirdr.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\IKufslt2XxHzBF\vmPe\EW26Hgvn-ZA ipq\KOU4d.rtf.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.cab.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\OWOW32LR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfLR.cab | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\MqiJ9nf_bQCiklH\Lh-fmvDxe3XRZzV7__u\EmgH\jWz6NyW3t0HY4Cspo2L\UAbWyI\yz3CSFifAc0Do808qo.odt.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\MqiJ9nf_bQCiklH\Lh-fmvDxe3XRZzV7__u\EmgH\jWz6NyW3t0HY4Cspo2L\UAbWyI\zJZc i jaEdrZ.xlsx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\6PXVy\jS2B F.mp4.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\6PXVy\KsnOpL91xkl_2.jpg.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\6PXVy\lt8hV2Y62JLkc.mkv.encrypted | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\6PXVy\NK-vMMUjP8JeAuHf_CH.docx.encrypted | Dropped File | Stream |
Unknown
|
...
|
»