VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Wilted Tulip
CopyKittens
Gen:Variant.Razy.647127
|
LZOS7pKb4I7msNxm.exe
Windows Exe (x86-32)
Created at 2020-04-22T00:26:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\LZOS7pKb4I7msNxm.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x432320 |
Size Of Code | 0x35e00 |
Size Of Initialized Data | 0xc600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-04-17 04:39:05+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x35c80 | 0x35e00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.66 |
.rdata | 0x437000 | 0x7558 | 0x7600 | 0x36200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.28 |
.data | 0x43f000 | 0x303c | 0x800 | 0x3d800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.6 |
.reloc | 0x443000 | 0x1c80 | 0x1e00 | 0x3e000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.58 |
Imports (5)
»
SHLWAPI.dll (5)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathFindFileNameW | 0x0 | 0x437128 | 0x3dc7c | 0x3ce7c | 0x49 |
PathFindExtensionW | 0x0 | 0x43712c | 0x3dc80 | 0x3ce80 | 0x47 |
StrCpyNW | 0x0 | 0x437130 | 0x3dc84 | 0x3ce84 | 0x124 |
StrDupW | 0x0 | 0x437134 | 0x3dc88 | 0x3ce88 | 0x127 |
wvnsprintfA | 0x0 | 0x437138 | 0x3dc8c | 0x3ce8c | 0x16f |
ntdll.dll (23)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NtClose | 0x0 | 0x437184 | 0x3dcd8 | 0x3ced8 | 0x67 |
NtQueryDirectoryFile | 0x0 | 0x437188 | 0x3dcdc | 0x3cedc | 0xe2 |
_allshr | 0x0 | 0x43718c | 0x3dce0 | 0x3cee0 | 0x4aa |
NtQueryVirtualMemory | 0x0 | 0x437190 | 0x3dce4 | 0x3cee4 | 0x104 |
RtlInitUnicodeString | 0x0 | 0x437194 | 0x3dce8 | 0x3cee8 | 0x276 |
wcsstr | 0x0 | 0x437198 | 0x3dcec | 0x3ceec | 0x51f |
RtlUpcaseUnicodeChar | 0x0 | 0x43719c | 0x3dcf0 | 0x3cef0 | 0x353 |
_aulldiv | 0x0 | 0x4371a0 | 0x3dcf4 | 0x3cef4 | 0x4ac |
RtlUnwind | 0x0 | 0x4371a4 | 0x3dcf8 | 0x3cef8 | 0x352 |
memcmp | 0x0 | 0x4371a8 | 0x3dcfc | 0x3cefc | 0x4f1 |
NtCreateFile | 0x0 | 0x4371ac | 0x3dd00 | 0x3cf00 | 0x73 |
RtlTimeToTimeFields | 0x0 | 0x4371b0 | 0x3dd04 | 0x3cf04 | 0x336 |
_wcslwr | 0x0 | 0x4371b4 | 0x3dd08 | 0x3cf08 | 0x4cd |
_stricmp | 0x0 | 0x4371b8 | 0x3dd0c | 0x3cf0c | 0x4c0 |
memset | 0x0 | 0x4371bc | 0x3dd10 | 0x3cf10 | 0x4f4 |
_aullshr | 0x0 | 0x4371c0 | 0x3dd14 | 0x3cf14 | 0x4af |
NtWaitForSingleObject | 0x0 | 0x4371c4 | 0x3dd18 | 0x3cf18 | 0x163 |
strstr | 0x0 | 0x4371c8 | 0x3dd1c | 0x3cf1c | 0x507 |
_vsnprintf | 0x0 | 0x4371cc | 0x3dd20 | 0x3cf20 | 0x4ca |
_alldiv | 0x0 | 0x4371d0 | 0x3dd24 | 0x3cf24 | 0x4a4 |
_allmul | 0x0 | 0x4371d4 | 0x3dd28 | 0x3cf28 | 0x4a6 |
_allshl | 0x0 | 0x4371d8 | 0x3dd2c | 0x3cf2c | 0x4a9 |
memcpy | 0x0 | 0x4371dc | 0x3dd30 | 0x3cf30 | 0x4f2 |
KERNEL32.dll (66)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitProcess | 0x0 | 0x43701c | 0x3db70 | 0x3cd70 | 0x119 |
WaitForSingleObject | 0x0 | 0x437020 | 0x3db74 | 0x3cd74 | 0x4f9 |
GetLogicalDriveStringsW | 0x0 | 0x437024 | 0x3db78 | 0x3cd78 | 0x208 |
SetEndOfFile | 0x0 | 0x437028 | 0x3db7c | 0x3cd7c | 0x453 |
MoveFileW | 0x0 | 0x43702c | 0x3db80 | 0x3cd80 | 0x363 |
DeleteFileW | 0x0 | 0x437030 | 0x3db84 | 0x3cd84 | 0xd6 |
QueryPerformanceFrequency | 0x0 | 0x437034 | 0x3db88 | 0x3cd88 | 0x3a8 |
HeapFree | 0x0 | 0x437038 | 0x3db8c | 0x3cd8c | 0x2cf |
HeapAlloc | 0x0 | 0x43703c | 0x3db90 | 0x3cd90 | 0x2cb |
WaitForMultipleObjects | 0x0 | 0x437040 | 0x3db94 | 0x3cd94 | 0x4f7 |
GetLocalTime | 0x0 | 0x437044 | 0x3db98 | 0x3cd98 | 0x203 |
GetComputerNameW | 0x0 | 0x437048 | 0x3db9c | 0x3cd9c | 0x18f |
GetSystemTime | 0x0 | 0x43704c | 0x3dba0 | 0x3cda0 | 0x277 |
AttachConsole | 0x0 | 0x437050 | 0x3dba4 | 0x3cda4 | 0x17 |
AllocConsole | 0x0 | 0x437054 | 0x3dba8 | 0x3cda8 | 0x10 |
Wow64DisableWow64FsRedirection | 0x0 | 0x437058 | 0x3dbac | 0x3cdac | 0x513 |
GlobalMemoryStatus | 0x0 | 0x43705c | 0x3dbb0 | 0x3cdb0 | 0x2bf |
LocalAlloc | 0x0 | 0x437060 | 0x3dbb4 | 0x3cdb4 | 0x344 |
GetProcessHeap | 0x0 | 0x437064 | 0x3dbb8 | 0x3cdb8 | 0x24a |
GetProcessTimes | 0x0 | 0x437068 | 0x3dbbc | 0x3cdbc | 0x252 |
GetProcessWorkingSetSize | 0x0 | 0x43706c | 0x3dbc0 | 0x3cdc0 | 0x254 |
GetCurrentProcess | 0x0 | 0x437070 | 0x3dbc4 | 0x3cdc4 | 0x1c0 |
GetCurrentProcessId | 0x0 | 0x437074 | 0x3dbc8 | 0x3cdc8 | 0x1c1 |
GetCurrentThread | 0x0 | 0x437078 | 0x3dbcc | 0x3cdcc | 0x1c4 |
GetCurrentThreadId | 0x0 | 0x43707c | 0x3dbd0 | 0x3cdd0 | 0x1c5 |
GetThreadTimes | 0x0 | 0x437080 | 0x3dbd4 | 0x3cdd4 | 0x291 |
GetLastError | 0x0 | 0x437084 | 0x3dbd8 | 0x3cdd8 | 0x202 |
SetLastError | 0x0 | 0x437088 | 0x3dbdc | 0x3cddc | 0x473 |
InitializeCriticalSection | 0x0 | 0x43708c | 0x3dbe0 | 0x3cde0 | 0x2e2 |
EnterCriticalSection | 0x0 | 0x437090 | 0x3dbe4 | 0x3cde4 | 0xee |
LeaveCriticalSection | 0x0 | 0x437094 | 0x3dbe8 | 0x3cde8 | 0x339 |
GetTickCount | 0x0 | 0x437098 | 0x3dbec | 0x3cdec | 0x293 |
GetStartupInfoW | 0x0 | 0x43709c | 0x3dbf0 | 0x3cdf0 | 0x263 |
QueryPerformanceCounter | 0x0 | 0x4370a0 | 0x3dbf4 | 0x3cdf4 | 0x3a7 |
LocalFree | 0x0 | 0x4370a4 | 0x3dbf8 | 0x3cdf8 | 0x348 |
GetStdHandle | 0x0 | 0x4370a8 | 0x3dbfc | 0x3cdfc | 0x264 |
WriteFile | 0x0 | 0x4370ac | 0x3dc00 | 0x3ce00 | 0x525 |
FlushFileBuffers | 0x0 | 0x4370b0 | 0x3dc04 | 0x3ce04 | 0x157 |
lstrlenA | 0x0 | 0x4370b4 | 0x3dc08 | 0x3ce08 | 0x54d |
OutputDebugStringA | 0x0 | 0x4370b8 | 0x3dc0c | 0x3ce0c | 0x389 |
CreateThread | 0x0 | 0x4370bc | 0x3dc10 | 0x3ce10 | 0xb5 |
ExitThread | 0x0 | 0x4370c0 | 0x3dc14 | 0x3ce14 | 0x11a |
DeleteCriticalSection | 0x0 | 0x4370c4 | 0x3dc18 | 0x3ce18 | 0xd1 |
Sleep | 0x0 | 0x4370c8 | 0x3dc1c | 0x3ce1c | 0x4b2 |
CloseHandle | 0x0 | 0x4370cc | 0x3dc20 | 0x3ce20 | 0x52 |
lstrcpyW | 0x0 | 0x4370d0 | 0x3dc24 | 0x3ce24 | 0x548 |
lstrcatW | 0x0 | 0x4370d4 | 0x3dc28 | 0x3ce28 | 0x53f |
TlsAlloc | 0x0 | 0x4370d8 | 0x3dc2c | 0x3ce2c | 0x4c5 |
ExpandEnvironmentStringsW | 0x0 | 0x4370dc | 0x3dc30 | 0x3ce30 | 0x11d |
GetProcAddress | 0x0 | 0x4370e0 | 0x3dc34 | 0x3ce34 | 0x245 |
GetFileSize | 0x0 | 0x4370e4 | 0x3dc38 | 0x3ce38 | 0x1f0 |
GetFileSizeEx | 0x0 | 0x4370e8 | 0x3dc3c | 0x3ce3c | 0x1f1 |
ReadFile | 0x0 | 0x4370ec | 0x3dc40 | 0x3ce40 | 0x3c0 |
GetFileAttributesW | 0x0 | 0x4370f0 | 0x3dc44 | 0x3ce44 | 0x1ea |
SetFilePointer | 0x0 | 0x4370f4 | 0x3dc48 | 0x3ce48 | 0x466 |
SetFilePointerEx | 0x0 | 0x4370f8 | 0x3dc4c | 0x3ce4c | 0x467 |
MapViewOfFile | 0x0 | 0x4370fc | 0x3dc50 | 0x3ce50 | 0x357 |
UnmapViewOfFile | 0x0 | 0x437100 | 0x3dc54 | 0x3ce54 | 0x4d6 |
TlsGetValue | 0x0 | 0x437104 | 0x3dc58 | 0x3ce58 | 0x4c7 |
TlsSetValue | 0x0 | 0x437108 | 0x3dc5c | 0x3ce5c | 0x4c8 |
CreateFileMappingA | 0x0 | 0x43710c | 0x3dc60 | 0x3ce60 | 0x89 |
CreateFileMappingW | 0x0 | 0x437110 | 0x3dc64 | 0x3ce64 | 0x8c |
LoadLibraryA | 0x0 | 0x437114 | 0x3dc68 | 0x3ce68 | 0x33c |
CreateFileW | 0x0 | 0x437118 | 0x3dc6c | 0x3ce6c | 0x8f |
SetFileAttributesW | 0x0 | 0x43711c | 0x3dc70 | 0x3ce70 | 0x461 |
GetDriveTypeW | 0x0 | 0x437120 | 0x3dc74 | 0x3ce74 | 0x1d3 |
USER32.dll (16)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
wsprintfA | 0x0 | 0x437140 | 0x3dc94 | 0x3ce94 | 0x332 |
wsprintfW | 0x0 | 0x437144 | 0x3dc98 | 0x3ce98 | 0x333 |
GetDesktopWindow | 0x0 | 0x437148 | 0x3dc9c | 0x3ce9c | 0x123 |
GetCaretPos | 0x0 | 0x43714c | 0x3dca0 | 0x3cea0 | 0x10a |
GetCursorPos | 0x0 | 0x437150 | 0x3dca4 | 0x3cea4 | 0x120 |
GetQueueStatus | 0x0 | 0x437154 | 0x3dca8 | 0x3cea8 | 0x16c |
GetInputState | 0x0 | 0x437158 | 0x3dcac | 0x3ceac | 0x138 |
GetFocus | 0x0 | 0x43715c | 0x3dcb0 | 0x3ceb0 | 0x12c |
GetActiveWindow | 0x0 | 0x437160 | 0x3dcb4 | 0x3ceb4 | 0x100 |
GetOpenClipboardWindow | 0x0 | 0x437164 | 0x3dcb8 | 0x3ceb8 | 0x163 |
GetProcessWindowStation | 0x0 | 0x437168 | 0x3dcbc | 0x3cebc | 0x168 |
GetMessagePos | 0x0 | 0x43716c | 0x3dcc0 | 0x3cec0 | 0x15b |
GetMessageTime | 0x0 | 0x437170 | 0x3dcc4 | 0x3cec4 | 0x15c |
GetClipboardOwner | 0x0 | 0x437174 | 0x3dcc8 | 0x3cec8 | 0x119 |
GetClipboardViewer | 0x0 | 0x437178 | 0x3dccc | 0x3cecc | 0x11b |
GetCapture | 0x0 | 0x43717c | 0x3dcd0 | 0x3ced0 | 0x108 |
ADVAPI32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptReleaseContext | 0x0 | 0x437000 | 0x3db54 | 0x3cd54 | 0xcb |
CryptGenRandom | 0x0 | 0x437004 | 0x3db58 | 0x3cd58 | 0xc1 |
OpenProcessToken | 0x0 | 0x437008 | 0x3db5c | 0x3cd5c | 0x1f7 |
AdjustTokenPrivileges | 0x0 | 0x43700c | 0x3db60 | 0x3cd60 | 0x1f |
LookupPrivilegeValueW | 0x0 | 0x437010 | 0x3db64 | 0x3cd64 | 0x197 |
CryptAcquireContextW | 0x0 | 0x437014 | 0x3db68 | 0x3cd68 | 0xb1 |
Exports (6)
»
Api name | EAT Address | Ordinal |
---|---|---|
_ReflectiveLoader@4 | 0x32350 | 0x1 |
_aes_hw_cpu_decrypt@8 | 0x100b | 0x2 |
_aes_hw_cpu_decrypt_32_blocks@8 | 0x10c7 | 0x3 |
_aes_hw_cpu_enable_sse@0 | 0x1000 | 0x4 |
_aes_hw_cpu_encrypt@8 | 0x1537 | 0x5 |
_aes_hw_cpu_encrypt_32_blocks@8 | 0x15f3 | 0x6 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
lzos7pkb4i7msnxm.exe | 1 | 0x00260000 | 0x002A4FFF | Relevant Image |
![]() |
32-bit | 0x0028F060 |
![]() |
![]() |
...
|
lzos7pkb4i7msnxm.exe | 1 | 0x00260000 | 0x002A4FFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Razy.647127 |
Malicious
|
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
WiltedTulip_ReflectiveLoader | Reflective loader (Cobalt Strike) used in Operation Wilted Tulip | - |
5/5
|
...
|
ReflectiveLoader | Reflective loader usage | - |
3/5
|
...
|
\\?\C:\ProgramData\Microsoft Help\MS.WINPROJ.DEV.14.1033.hxn.sfile2 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.VISIO_PRM.14.1033.hxn.sfile2 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.VISIO.SHAPESHEET.14.1033.hxn.sfile2 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.VISIO_STD.14.1033.hxn.sfile2 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.WINWORD.DEV.14.1033.hxn.sfile2 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.MSPUB.14.1033.hxn.sfile2 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.MSPUB.DEV.14.1033.hxn.sfile2 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.POWERPNT.14.1033.hxn.sfile2 | Modified File | Unknown |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.MSOUC.14.1033.hxn.sfile2 | Modified File | Unknown |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\tVMgL6pTMszUMjPsZJT.avi.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\2HCPkelabr23_Bmoj\iVqJ570eCG\JupbGP.wav.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Ifri_qR6J-Y0Aqrc8\bIXspMwDV0x2\m_A7.png.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\OVmxza_LmNnxE5sqJ-Pr.pptx.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\xtQ 5Az6F.wav.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\l4yGpYSBCGJcN0i01.gif.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\G_hsgO8VtD0vlSz.mkv.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\pi2VKtUaUyAi8zxf.m4a.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ocbBR72nlFU.flv.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\3KLmQY sm4QCxc5d1Gf5\KUUl8hqIShnBOY.xls.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\7W8-0\uvGw4ceHmngD2sNP.wav.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\dB3u7zdDOjV87f5.mp4.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\FDxy.gif.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\7W8-0\OuPYNHqN.m4a.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\t2Sy.mkv.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\VWI2pgc1-V.docx.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\OxFNTcjqaLXz5O6.mp3.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\tlrX.xlsx.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ndqI3-PZFYy9\4Wfkb5YwqpRnmUkQCh\K9RQ9lct6.jpg.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\E4EGCtqONuddsIr18.swf.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\2HCPkelabr23_Bmoj\iVqJ570eCG\l7 RVcxMZnIVTr.mp3.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\3KLmQY sm4QCxc5d1Gf5\bM2R\xXC13Z4h.ppt.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\y0vDwgVu-aE.ods.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\2HCPkelabr23_Bmoj\iVqJ570eCG\OTLDe6RGW8Q6jdix2XOI.mp3.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\3KLmQY sm4QCxc5d1Gf5\3YHnBgK.xlsx.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\3KLmQY sm4QCxc5d1Gf5\bM2R\HQImSS3gL9DPI5E.odt.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Rp04VYqaiBt9\elY-tG1E4unlIT5mbq2.flv.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ndqI3-PZFYy9\TyL d\mlzF-nV8.gif.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\3KLmQY sm4QCxc5d1Gf5\zw3w2EElVU6Xm.xls.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\3KLmQY sm4QCxc5d1Gf5\bM2R\5VmlWj6krM.xlsx.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\T5CnyOCy 5.mp3.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\DJuKGi.avi.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\79LSi.swf.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Ifri_qR6J-Y0Aqrc8\mEmc6mK UcrdL9b.png.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\2HCPkelabr23_Bmoj\iVqJ570eCG\QIoKShoI c.mp3.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\b6CtWDNzCWgWMf7zXq.swf.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\1zH7WqBEa.m4a.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\RTLY6MXL00UnHf3.mp4.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\3KLmQY sm4QCxc5d1Gf5\z7BKftkCOedDRZ.doc.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ndqI3-PZFYy9\LCINTrzJJT.bmp.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\7W8-0\_aaYtp6rj-hUFyzZaJoy.mp3.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\2HCPkelabr23_Bmoj\iVqJ570eCG\1O40W8y.wav.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\o0APN8a5ADgz.mkv.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\eSrT.csv.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\2HCPkelabr23_Bmoj\iVqJ570eCG\xaoR.mp3.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\k9-pylX0SDY1x.wav.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\aXOJyBxHMLAES.flv.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\2HCPkelabr23_Bmoj\842rELD2le_3FY4m.m4a.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\aNxyZh10.png.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\xxzZgYS_9VIT625sb6Ic.mp4.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\aqEg8Hq.avi.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wnXD-IT.jpg.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\BfxJkdGz.wav.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\2iLZD GKiKT_yde.png.sfile2 | Dropped File | Binary |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Oym9JLixQALQw-X.png.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ndqI3-PZFYy9\BjWboNfon.gif.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ndqI3-PZFYy9\TyL d\pMZ9-_wxww6oo0M.gif.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\iJ04FaLh83nTq2r.avi.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\c3Ry3z071Y8ieJZVR3j.jpg.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\UjkKVn o0cRwkf.mp3.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9O-QhKmAYd.mp3.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\bmYc.mkv.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ODx4.wav.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Yyj5DIm81OeXouGmC.pptx.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\2HCPkelabr23_Bmoj\iVqJ570eCG\tehPcLS2B-1.mp3.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\ZWr4pO94V9ECgQXdK_.png.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Rp04VYqaiBt9\FM3ReqWlk0jeHJLPRUE.xls.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\qg13S 8UdrKlwZ1O.m4a.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\azv SIL.csv.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\3KLmQY sm4QCxc5d1Gf5\z3ev3iXY8e0L7TS1V\Mg 2ZrqiK1FWuFEMml.docx.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ndqI3-PZFYy9\TyL d\AmTV.jpg.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ndqI3-PZFYy9\4Wfkb5YwqpRnmUkQCh\y8KmfmphrCsDn.png.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\FOz9sJyMHEpYNLI16etO.xls.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\dpr-YNfZfmmpv Gp.gif.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ANkZvuFyPz.mkv.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\65YPS412lYa2KV4 DUM.mp3.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\K6cb7MLMVn.pdf.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\ItYGsrXexA.m4a.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\TPZPmACmPmUCkd-.flv.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\3KLmQY sm4QCxc5d1Gf5\z3ev3iXY8e0L7TS1V\kIOHYY67.docx.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\M3YC.swf.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\GWlysz9 A4XOmMd8RCe.bmp.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\3KLmQY sm4QCxc5d1Gf5\odlY.pdf.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Zgn7vOkIgI7fhM.mp3.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\4MZpIPmH.gif.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\3KLmQY sm4QCxc5d1Gf5\_Zs8kGvVy4aOovHJ.csv.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\R4VfNWg89IGIhSj5F.mp4.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Ifri_qR6J-Y0Aqrc8\bIXspMwDV0x2\l4gQMDvoE6baC.gif.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ndqI3-PZFYy9\TyL d\Us1hlM0K.gif.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\uUrUoH3fYf-IFq6Sqq.mkv.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\Dnua2h4xsly0i3Vndj-X.wav.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\cIA08I__Br6gd2-.mkv.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\2HCPkelabr23_Bmoj\Mftp.wav.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Ifri_qR6J-Y0Aqrc8\bIXspMwDV0x2\ucp4Yac85c.jpg.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Rp04VYqaiBt9\CM9 452Y4UgO0s3.png.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\DGAXlDC79MXp.swf.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\RHu3v2YSPo.mkv.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ehccZH.mkv.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\mv_ vd47iZ wDUM.mp3.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\u831p-sHm9irgYELA.m4a.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Rp04VYqaiBt9\g-LVHpzfB4ZwR.jpg.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\3KLmQY sm4QCxc5d1Gf5\z3ev3iXY8e0L7TS1V\oFVaH37h_PUC yc.docx.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\pem7fJX28ohkFa_1 LO.png.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\7W8-0\qfR fxico_G- C.m4a.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\p-905ebNW7re1.avi.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ndqI3-PZFYy9\gSHkSPY\9Lu3D7rw XZKOErLU.jpg.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ndqI3-PZFYy9\TyL d\1VATKU AE-wv4Mkj.png.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Sb z02cGPZdbiH4ldLrp.jpg.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\XSzmJDRP_mvLFt-xy868.png.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\wS2sjsRPV0a.mp4.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\2HCPkelabr23_Bmoj\rZmfzaU7p9xlZ5C47.wav.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\3KLmQY sm4QCxc5d1Gf5\bM2R\vlzCJzw.odp.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\qo2epUwFwI7Ixw.swf.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\3KLmQY sm4QCxc5d1Gf5\2hvn82lwLyqDx4Vbmj1.odt.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\lkLgXaJnAm.avi.sfile2 | Dropped File | Audio |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\hO A0w 6o.odp.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\2HCPkelabr23_Bmoj\7pm4bShqAhOr-kip.wav.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\XNQz0i2KqC-b.mkv.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\7D N.xlsx.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\azQab_ZzjVvX2wg.xlsx.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\BEgJe8St.docx.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\26xHvA.docx.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wBFAR1cF0f5PI.xlsx.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\uISY.pptx.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\dYsyYBCcm.pptx.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wcPyQ.pptx.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\31btx0sQG_u1.pptx.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\caLFim_yiiovria.docx.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Acrobat\10.0\SharedDataEvents.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Acrobat\10.0\UserCache.bin.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Acrobat\10.0\AdobeCMapFnt10.lst.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Adobe\Acrobat\10.0\ReaderMessages.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\GDIPFONTCACHEV1.DAT.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.VISIO.DEV.14.1033.hxn.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.VISIO.14.1033.hxn.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.INFOPATHEDITOR.14.1033.hxn.sfile2 | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.ONENOTE.14.1033.hxn.sfile2 | Dropped File | Binary |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.EXCEL.DEV.14.1033.hxn.sfile2 | Dropped File | Unknown |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.POWERPNT.DEV.14.1033.hxn.sfile2 | Dropped File | Unknown |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.GRAPH.14.1033.hxn.sfile2 | Dropped File | Unknown |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.MSACCESS.DEV.14.1033.hxn.sfile2 | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.INFOPATH.14.1033.hxn.sfile2 | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.OUTLOOK.14.1033.hxn.sfile2 | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.GROOVE.14.1033.hxn.sfile2 | Modified File | Unknown |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.EXCEL.14.1033.hxn.sfile2 | Modified File | Unknown |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ftJZhleY5.mp4.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Ifri_qR6J-Y0Aqrc8\0J7jzghs7JAOEO7TEGtm.jpg.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\5-w BCU.swf.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\BJsGBcNH72h Qd.mkv.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\c3DZuBQR1zgNPp.gif.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\1Wpq.gif.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\2HCPkelabr23_Bmoj\rGQFUI_1UQ 53n.wav.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ndqI3-PZFYy9\gSHkSPY\0PDuCVoH-.jpg.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\5weW tW7.wav.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ndqI3-PZFYy9\4Wfkb5YwqpRnmUkQCh\LdmCw0JH-5QWvM.png.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\3KLmQY sm4QCxc5d1Gf5\z3ev3iXY8e0L7TS1V\7vlfnyEGw9BVpjKCv.doc.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\0QdThbN4KyHabt.mp4.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\LSzgBa8JBMae4.avi.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\IuY4QgHfPZblDkKMa g7.pps.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ndqI3-PZFYy9\TyL d\BzMnmxK-TeCGvcsqWN-m.jpg.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\x87R.m4a.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\3KLmQY sm4QCxc5d1Gf5\zdfsiL7y1-6nP.xlsx.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\3KLmQY sm4QCxc5d1Gf5\z3ev3iXY8e0L7TS1V\mT_V5wj8Ftw.pps.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\B__dJmJQhwGH.mp3.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\sWlI43lmz-xf7PE-3tuv.odp.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ndqI3-PZFYy9\4Wfkb5YwqpRnmUkQCh\3pxLUrDDYdgcHZ1vfY8.jpg.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Rp04VYqaiBt9\Enthveoos.flv.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\XHq4IHcwOWAJmsXp9Px.flv.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\-xCsAdp0D.flv.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\pBOBuVk oOTIqlo49.wav.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\kXN0JWP l-DvZSup.bmp.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ndqI3-PZFYy9\TyL d\ojzTzObbDIuE9a1RXkSn.jpg.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\2HCPkelabr23_Bmoj\WjCEZ0.mp3.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\3KLmQY sm4QCxc5d1Gf5\z3ev3iXY8e0L7TS1V\cVOb.ppt.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\2HCPkelabr23_Bmoj\iVqJ570eCG\Lw-JSH00d3c.m4a.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\_-JD6xeW.ods.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\-xDMVl8Mhi4fa_bMBp.jpg.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\_62_.ots.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\tHC32B 2vYWCNbABG.jpg.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Zau.pptx.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\2HCPkelabr23_Bmoj\iVqJ570eCG\vP1dq0dx6ArHyquPG.m4a.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Rp04VYqaiBt9\Di0oMNle7A.ppt.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\3W3-ATGhDCpvu.avi.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\RwbWYpVi-K7bWE.jpg.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\3KLmQY sm4QCxc5d1Gf5\bM2R\xzHzr6fasjRrNWKf.docx.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\CDmVjg8L4bDjg3NKmr.pdf.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NnuUvV5r-I r.flv.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Ifri_qR6J-Y0Aqrc8\mpY8cz7dCJfsea.gif.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\6Ps4.mkv.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\2HCPkelabr23_Bmoj\rDn35ZAF40.m4a.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Ifri_qR6J-Y0Aqrc8\bIXspMwDV0x2\Pa2QLTWbam81dK1Muc 0.gif.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\o9q6QJKUItBpO.mp4.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\UqeOlLwaHOw9XrZlUkch.wav.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\7YNvXXd7xs9t.gif.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\3KLmQY sm4QCxc5d1Gf5\z3ev3iXY8e0L7TS1V\bPq 6NvSpA1fbja7.xlsx.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\kPzUIqeSV1hFkR.bmp.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\LGlphKm.xlsx.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\O6EbUhW8Dk.flv.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\vQzC1uEuC.swf.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ndqI3-PZFYy9\gSHkSPY\kFBAQ4.bmp.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ndqI3-PZFYy9\gSHkSPY\Yl1dQeunho5.png.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\2HCPkelabr23_Bmoj\f9HCrIgdh66.wav.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ndqI3-PZFYy9\gSHkSPY\qAXWIpiQABazK.png.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\74ZG5eZfcjr7lyHC.doc.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\HTtofRx.mp4.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\BeUoxzAXv56P3Mg-vJpT.xls.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Q6ITuVaWjY_Obz4nVH.xlsx.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\3KLmQY sm4QCxc5d1Gf5\bM2R\Fm8VfBju.doc.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\3KLmQY sm4QCxc5d1Gf5\bM2R\DTWcB.docx.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\hDrOo.wav.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8a6EtlXquW6x.png.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Rp04VYqaiBt9\cdlAssa5C4.jpg.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\pfPtnJBjxhx_wbj.wav.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\DFXCYBHLvS T.jpg.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ndqI3-PZFYy9\gSHkSPY\n9Y8.png.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Ifri_qR6J-Y0Aqrc8\bIXspMwDV0x2\ZDxerX3FIFK6GGV.gif.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\3KLmQY sm4QCxc5d1Gf5\z3ev3iXY8e0L7TS1V\sgToagH2kgkS72.pptx.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\JdgTfLcjfg.ods.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\7W322gheq-RP.wav.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Ifri_qR6J-Y0Aqrc8\bIXspMwDV0x2\VP_ubXzLXUd3yJv4.jpg.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\qD9GwjG3Bg0A-.ots.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Ifri_qR6J-Y0Aqrc8\bIXspMwDV0x2\d3Q.jpg.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\GXEIIFnKGvTDZU0.flv.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\2HCPkelabr23_Bmoj\iVqJ570eCG\bKpYCVwy0K3zXz0HVK.m4a.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Klz27dHHY.flv.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\rkMqsYwc86v_hq.m4a.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ha-QtIK6wcf-X.swf.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\2HCPkelabr23_Bmoj\iVqJ570eCG\V5JHR_3k9cNb4coc0OA.m4a.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_hbIEKK.flv.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Ifri_qR6J-Y0Aqrc8\bIXspMwDV0x2\Vgmb12iY.jpg.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\2HCPkelabr23_Bmoj\iVqJ570eCG\THkanpE B4WR.wav.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ndqI3-PZFYy9\TyL d\-j35kw47-IMoXRaye3ga.jpg.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Rp04VYqaiBt9\f0NvpqOyixWiPLqk.wav.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JuKBwK\3KLmQY sm4QCxc5d1Gf5\bM2R\4qG7dfo5uc93i.pptx.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ndqI3-PZFYy9\gSHkSPY\Sj2pmbrCzH.png.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\OweQn9 rCpiF6yVffjW.pptx.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\dTvxmelXXFCfSXH8_.xlsx.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JVP2oav8R.docx.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\Deployment\deployment.properties.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\nslist.hxl.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\Hx.hxn.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.WINPROJ.14.1033.hxn.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.WINWORD.14.1033.hxn.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.MSACCESS.14.1033.hxn.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft Help\MS.OUTLOOK.DEV.14.1033.hxn.sfile2 | Dropped File | Stream |
Not Queried
|
...
|
»