VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Wiper
|
Threat Names: |
Gen:Heur.Ransom.Imps.1
|
ransom_subpe.exe
Windows Exe (x86-32)
Created at 2020-07-08T00:39:00
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "5 minutes" to "10 seconds" to reveal dormant functionality.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x445e74 |
Size Of Code | 0x67e00 |
Size Of Initialized Data | 0x68c00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-06-30 07:06:13+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x67d7e | 0x67e00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.77 |
.rdata | 0x469000 | 0x522c6 | 0x52400 | 0x68200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.53 |
.data | 0x4bc000 | 0x79c4 | 0x4600 | 0xba600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.86 |
.rsrc | 0x4c4000 | 0x1b4 | 0x200 | 0xbec00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.11 |
.reloc | 0x4c5000 | 0x11f04 | 0x12000 | 0xbee00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 3.16 |
Imports (6)
»
KERNEL32.dll (105)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetShortPathNameA | 0x0 | 0x469024 | 0xba6a0 | 0xb98a0 | 0x260 |
FindFirstFileA | 0x0 | 0x469028 | 0xba6a4 | 0xb98a4 | 0x132 |
GetLastError | 0x0 | 0x46902c | 0xba6a8 | 0xb98a8 | 0x202 |
FindClose | 0x0 | 0x469030 | 0xba6ac | 0xb98ac | 0x12e |
GlobalMemoryStatusEx | 0x0 | 0x469034 | 0xba6b0 | 0xb98b0 | 0x2c0 |
WaitForMultipleObjects | 0x0 | 0x469038 | 0xba6b4 | 0xb98b4 | 0x4f7 |
FindNextFileA | 0x0 | 0x46903c | 0xba6b8 | 0xb98b8 | 0x143 |
CreateMutexA | 0x0 | 0x469040 | 0xba6bc | 0xb98bc | 0x9b |
ReleaseMutex | 0x0 | 0x469044 | 0xba6c0 | 0xb98c0 | 0x3fa |
GetDiskFreeSpaceExA | 0x0 | 0x469048 | 0xba6c4 | 0xb98c4 | 0x1cd |
WinExec | 0x0 | 0x46904c | 0xba6c8 | 0xb98c8 | 0x512 |
DeleteFileA | 0x0 | 0x469050 | 0xba6cc | 0xb98cc | 0xd3 |
CreateThread | 0x0 | 0x469054 | 0xba6d0 | 0xb98d0 | 0xb5 |
Sleep | 0x0 | 0x469058 | 0xba6d4 | 0xb98d4 | 0x4b2 |
TerminateThread | 0x0 | 0x46905c | 0xba6d8 | 0xb98d8 | 0x4c1 |
GetProcessHeap | 0x0 | 0x469060 | 0xba6dc | 0xb98dc | 0x24a |
GetDriveTypeA | 0x0 | 0x469064 | 0xba6e0 | 0xb98e0 | 0x1d2 |
MultiByteToWideChar | 0x0 | 0x469068 | 0xba6e4 | 0xb98e4 | 0x367 |
CompareStringW | 0x0 | 0x46906c | 0xba6e8 | 0xb98e8 | 0x64 |
CreateFileA | 0x0 | 0x469070 | 0xba6ec | 0xb98ec | 0x88 |
CreateProcessA | 0x0 | 0x469074 | 0xba6f0 | 0xb98f0 | 0xa4 |
GetExitCodeProcess | 0x0 | 0x469078 | 0xba6f4 | 0xb98f4 | 0x1df |
CreateFileW | 0x0 | 0x46907c | 0xba6f8 | 0xb98f8 | 0x8f |
WriteConsoleW | 0x0 | 0x469080 | 0xba6fc | 0xb98fc | 0x524 |
HeapReAlloc | 0x0 | 0x469084 | 0xba700 | 0xb9900 | 0x2d2 |
GetStringTypeW | 0x0 | 0x469088 | 0xba704 | 0xb9904 | 0x269 |
IsValidLocale | 0x0 | 0x46908c | 0xba708 | 0xb9908 | 0x30c |
EnumSystemLocalesA | 0x0 | 0x469090 | 0xba70c | 0xb990c | 0x10d |
GetLocaleInfoA | 0x0 | 0x469094 | 0xba710 | 0xb9910 | 0x204 |
GetUserDefaultLCID | 0x0 | 0x469098 | 0xba714 | 0xb9914 | 0x29b |
GetCurrentProcessId | 0x0 | 0x46909c | 0xba718 | 0xb9918 | 0x1c1 |
GetTickCount | 0x0 | 0x4690a0 | 0xba71c | 0xb991c | 0x293 |
GetEnvironmentStringsW | 0x0 | 0x4690a4 | 0xba720 | 0xb9920 | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x4690a8 | 0xba724 | 0xb9924 | 0x161 |
GetModuleFileNameA | 0x0 | 0x4690ac | 0xba728 | 0xb9928 | 0x213 |
SetEnvironmentVariableA | 0x0 | 0x4690b0 | 0xba72c | 0xb992c | 0x456 |
CreateEventA | 0x0 | 0x4690b4 | 0xba730 | 0xb9930 | 0x82 |
GetSystemTimeAsFileTime | 0x0 | 0x4690b8 | 0xba734 | 0xb9934 | 0x279 |
SetEvent | 0x0 | 0x4690bc | 0xba738 | 0xb9938 | 0x459 |
WaitForSingleObject | 0x0 | 0x4690c0 | 0xba73c | 0xb993c | 0x4f9 |
SetEndOfFile | 0x0 | 0x4690c4 | 0xba740 | 0xb9940 | 0x453 |
LoadLibraryW | 0x0 | 0x4690c8 | 0xba744 | 0xb9944 | 0x33f |
CloseHandle | 0x0 | 0x4690cc | 0xba748 | 0xb9948 | 0x52 |
SetStdHandle | 0x0 | 0x4690d0 | 0xba74c | 0xb994c | 0x487 |
GetTimeZoneInformation | 0x0 | 0x4690d4 | 0xba750 | 0xb9950 | 0x298 |
IsValidCodePage | 0x0 | 0x4690d8 | 0xba754 | 0xb9954 | 0x30a |
InterlockedIncrement | 0x0 | 0x4690dc | 0xba758 | 0xb9958 | 0x2ef |
InterlockedDecrement | 0x0 | 0x4690e0 | 0xba75c | 0xb995c | 0x2eb |
EncodePointer | 0x0 | 0x4690e4 | 0xba760 | 0xb9960 | 0xea |
DecodePointer | 0x0 | 0x4690e8 | 0xba764 | 0xb9964 | 0xca |
InitializeCriticalSection | 0x0 | 0x4690ec | 0xba768 | 0xb9968 | 0x2e2 |
DeleteCriticalSection | 0x0 | 0x4690f0 | 0xba76c | 0xb996c | 0xd1 |
EnterCriticalSection | 0x0 | 0x4690f4 | 0xba770 | 0xb9970 | 0xee |
LeaveCriticalSection | 0x0 | 0x4690f8 | 0xba774 | 0xb9974 | 0x339 |
SetLastError | 0x0 | 0x4690fc | 0xba778 | 0xb9978 | 0x473 |
QueryPerformanceFrequency | 0x0 | 0x469100 | 0xba77c | 0xb997c | 0x3a8 |
QueryPerformanceCounter | 0x0 | 0x469104 | 0xba780 | 0xb9980 | 0x3a7 |
MoveFileA | 0x0 | 0x469108 | 0xba784 | 0xb9984 | 0x35e |
HeapFree | 0x0 | 0x46910c | 0xba788 | 0xb9988 | 0x2cf |
HeapAlloc | 0x0 | 0x469110 | 0xba78c | 0xb998c | 0x2cb |
FindFirstFileExA | 0x0 | 0x469114 | 0xba790 | 0xb9990 | 0x133 |
FileTimeToSystemTime | 0x0 | 0x469118 | 0xba794 | 0xb9994 | 0x125 |
FileTimeToLocalFileTime | 0x0 | 0x46911c | 0xba798 | 0xb9998 | 0x124 |
GetTimeFormatA | 0x0 | 0x469120 | 0xba79c | 0xb999c | 0x295 |
GetDateFormatA | 0x0 | 0x469124 | 0xba7a0 | 0xb99a0 | 0x1c6 |
GetProcAddress | 0x0 | 0x469128 | 0xba7a4 | 0xb99a4 | 0x245 |
GetModuleHandleW | 0x0 | 0x46912c | 0xba7a8 | 0xb99a8 | 0x218 |
ExitProcess | 0x0 | 0x469130 | 0xba7ac | 0xb99ac | 0x119 |
GetCommandLineA | 0x0 | 0x469134 | 0xba7b0 | 0xb99b0 | 0x186 |
HeapSetInformation | 0x0 | 0x469138 | 0xba7b4 | 0xb99b4 | 0x2d3 |
RaiseException | 0x0 | 0x46913c | 0xba7b8 | 0xb99b8 | 0x3b1 |
RtlUnwind | 0x0 | 0x469140 | 0xba7bc | 0xb99bc | 0x418 |
WideCharToMultiByte | 0x0 | 0x469144 | 0xba7c0 | 0xb99c0 | 0x511 |
LCMapStringW | 0x0 | 0x469148 | 0xba7c4 | 0xb99c4 | 0x32d |
GetCPInfo | 0x0 | 0x46914c | 0xba7c8 | 0xb99c8 | 0x172 |
UnhandledExceptionFilter | 0x0 | 0x469150 | 0xba7cc | 0xb99cc | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x469154 | 0xba7d0 | 0xb99d0 | 0x4a5 |
IsDebuggerPresent | 0x0 | 0x469158 | 0xba7d4 | 0xb99d4 | 0x300 |
TerminateProcess | 0x0 | 0x46915c | 0xba7d8 | 0xb99d8 | 0x4c0 |
GetCurrentProcess | 0x0 | 0x469160 | 0xba7dc | 0xb99dc | 0x1c0 |
SetHandleCount | 0x0 | 0x469164 | 0xba7e0 | 0xb99e0 | 0x46f |
GetStdHandle | 0x0 | 0x469168 | 0xba7e4 | 0xb99e4 | 0x264 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x46916c | 0xba7e8 | 0xb99e8 | 0x2e3 |
GetFileType | 0x0 | 0x469170 | 0xba7ec | 0xb99ec | 0x1f3 |
GetStartupInfoW | 0x0 | 0x469174 | 0xba7f0 | 0xb99f0 | 0x263 |
IsProcessorFeaturePresent | 0x0 | 0x469178 | 0xba7f4 | 0xb99f4 | 0x304 |
HeapCreate | 0x0 | 0x46917c | 0xba7f8 | 0xb99f8 | 0x2cd |
WriteFile | 0x0 | 0x469180 | 0xba7fc | 0xb99fc | 0x525 |
GetModuleFileNameW | 0x0 | 0x469184 | 0xba800 | 0xb9a00 | 0x214 |
ReadFile | 0x0 | 0x469188 | 0xba804 | 0xb9a04 | 0x3c0 |
SetFilePointer | 0x0 | 0x46918c | 0xba808 | 0xb9a08 | 0x466 |
GetConsoleCP | 0x0 | 0x469190 | 0xba80c | 0xb9a0c | 0x19a |
GetConsoleMode | 0x0 | 0x469194 | 0xba810 | 0xb9a10 | 0x1ac |
FlushFileBuffers | 0x0 | 0x469198 | 0xba814 | 0xb9a14 | 0x157 |
GetFileAttributesA | 0x0 | 0x46919c | 0xba818 | 0xb9a18 | 0x1e5 |
HeapSize | 0x0 | 0x4691a0 | 0xba81c | 0xb9a1c | 0x2d4 |
TlsAlloc | 0x0 | 0x4691a4 | 0xba820 | 0xb9a20 | 0x4c5 |
TlsGetValue | 0x0 | 0x4691a8 | 0xba824 | 0xb9a24 | 0x4c7 |
TlsSetValue | 0x0 | 0x4691ac | 0xba828 | 0xb9a28 | 0x4c8 |
TlsFree | 0x0 | 0x4691b0 | 0xba82c | 0xb9a2c | 0x4c6 |
GetCurrentThreadId | 0x0 | 0x4691b4 | 0xba830 | 0xb9a30 | 0x1c5 |
GetLocaleInfoW | 0x0 | 0x4691b8 | 0xba834 | 0xb9a34 | 0x206 |
GetACP | 0x0 | 0x4691bc | 0xba838 | 0xb9a38 | 0x168 |
GetOEMCP | 0x0 | 0x4691c0 | 0xba83c | 0xb9a3c | 0x237 |
lstrlenA | 0x0 | 0x4691c4 | 0xba840 | 0xb9a40 | 0x54d |
USER32.dll (22)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SystemParametersInfoA | 0x0 | 0x4691d4 | 0xba850 | 0xb9a50 | 0x2eb |
GetSystemMetrics | 0x0 | 0x4691d8 | 0xba854 | 0xb9a54 | 0x17e |
AdjustWindowRect | 0x0 | 0x4691dc | 0xba858 | 0xb9a58 | 0x2 |
ChangeDisplaySettingsA | 0x0 | 0x4691e0 | 0xba85c | 0xb9a5c | 0x23 |
DestroyWindow | 0x0 | 0x4691e4 | 0xba860 | 0xb9a60 | 0xa6 |
GetMessageA | 0x0 | 0x4691e8 | 0xba864 | 0xb9a64 | 0x159 |
GetWindowRect | 0x0 | 0x4691ec | 0xba868 | 0xb9a68 | 0x19c |
SetForegroundWindow | 0x0 | 0x4691f0 | 0xba86c | 0xb9a6c | 0x293 |
TrackMouseEvent | 0x0 | 0x4691f4 | 0xba870 | 0xb9a70 | 0x2f5 |
EnumDisplaySettingsA | 0x0 | 0x4691f8 | 0xba874 | 0xb9a74 | 0xe7 |
wsprintfA | 0x0 | 0x4691fc | 0xba878 | 0xb9a78 | 0x332 |
GetDC | 0x0 | 0x469200 | 0xba87c | 0xb9a7c | 0x121 |
ShowCursor | 0x0 | 0x469204 | 0xba880 | 0xb9a80 | 0x2da |
SetWindowLongA | 0x0 | 0x469208 | 0xba884 | 0xb9a84 | 0x2c3 |
GetWindowLongA | 0x0 | 0x46920c | 0xba888 | 0xb9a88 | 0x195 |
CreateWindowExA | 0x0 | 0x469210 | 0xba88c | 0xb9a8c | 0x6d |
PeekMessageA | 0x0 | 0x469214 | 0xba890 | 0xb9a90 | 0x232 |
DefWindowProcA | 0x0 | 0x469218 | 0xba894 | 0xb9a94 | 0x9b |
SetWindowPos | 0x0 | 0x46921c | 0xba898 | 0xb9a98 | 0x2c6 |
GetCursorPos | 0x0 | 0x469220 | 0xba89c | 0xb9a9c | 0x120 |
ShowWindow | 0x0 | 0x469224 | 0xba8a0 | 0xb9aa0 | 0x2df |
DispatchMessageA | 0x0 | 0x469228 | 0xba8a4 | 0xb9aa4 | 0xae |
GDI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetDIBitsToDevice | 0x0 | 0x46901c | 0xba698 | 0xb9898 | 0x289 |
ADVAPI32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptGenRandom | 0x0 | 0x469000 | 0xba67c | 0xb987c | 0xc1 |
RegCloseKey | 0x0 | 0x469004 | 0xba680 | 0xb9880 | 0x230 |
RegOpenKeyExA | 0x0 | 0x469008 | 0xba684 | 0xb9884 | 0x260 |
RegSetValueExA | 0x0 | 0x46900c | 0xba688 | 0xb9888 | 0x27d |
CryptReleaseContext | 0x0 | 0x469010 | 0xba68c | 0xb988c | 0xcb |
CryptAcquireContextA | 0x0 | 0x469014 | 0xba690 | 0xb9890 | 0xb0 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderPathA | 0x0 | 0x4691cc | 0xba848 | 0xb9a48 | 0xe0 |
WS2_32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WSAStartup | 0x73 | 0x469230 | 0xba8ac | 0xb9aac | - |
inet_ntoa | 0xc | 0x469234 | 0xba8b0 | 0xb9ab0 | - |
gethostname | 0x39 | 0x469238 | 0xba8b4 | 0xb9ab4 | - |
gethostbyname | 0x34 | 0x46923c | 0xba8b8 | 0xb9ab8 | - |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
ransom_subpe.exe | 1 | 0x00CB0000 | 0x00D86FFF | Relevant Image |
![]() |
32-bit | 0x00CFC122 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Ransom.Imps.1 |
Malicious
|
C:\Users\FD1HVy\Desktop\-2z7RH.mp4.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\0Av2slukDvutL.flv.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\2fsDVTfDpy_Cf9Z.xlsx.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\44tCEuJpeVls9P.wav.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\5-t7_6zn.ods.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\7ZcV6J1aA4PSre.png.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\9uhnThos5ZWJM8.png.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\a3F5Do aYpzpAkK6.gif.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\AUrRsoBX.avi.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\awh0eX.pptx.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\bCj9IAJRlCNvUG9J.xls.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\CM6Z.mp3.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\desktop.ini.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\E-4FpMVL u55kviov o.wav.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\flS8s7p.wav.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\GP94zQdTCX0K.bmp.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\hPvkwmY9ori z8gE.wav.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\IgSSutlfQmrOWKHr.odp.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\J9xCGWQgrXW-56ZXHAjB.mkv.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\jEN4rq4sA0vlzWPu.flv.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Jmo55eON.doc.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\ltkxa1h9fZ q.mp3.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\mIeZXH5QYgq45hery_1.swf.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\MvdmvhfNi0UKgqzJ.png.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\OIUQVfejyVP.mp3.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\omyXUwRMi4W.mp3.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Qa9HeIKP6.mkv.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\QK2S2nZ_K7M.m4a.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\STjEKqlS5bp.csv.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\tHtCAiyOzlqO.wav.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\tmPERcWiT1gFEg_G9g.flv.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\u829_mg0k65wykQ.csv.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\u8w_Izu1o_YwIgkN8d.gif.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\V--Px.gif.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\VeMU39zq0X5FX.xls.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Vuys.csv.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\WJJBL2n\2ZZ8xP.xls.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\WJJBL2n\3l8RjZWHyhSHG5Cckd.xls.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\WJJBL2n\9amMQetRWlZ2S_.avi.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\WJJBL2n\aRSHA0VvBhPb.avi.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\WJJBL2n\AYFmZO aTKCxc7bEM7G.png.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\WJJBL2n\gYrvaRI4RXa2MipNqA.mp3.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\WJJBL2n\mv rLj09FyChgaIab7FI.ppt.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\WJJBL2n\okisMmAp6VGe5I.jpg.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\WJJBL2n\ro-REGIS8Mf.gif.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\WJJBL2n\SBmEo4L4OVaJ_V.png.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\WJJBL2n\wONPFK_AScUVO.wav.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\WJJBL2n\_cj_jzCV7GM4sVju0oB.ots.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\WJJBL2n\_vPQG.png.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\yfiBrFFe_bj.wav.panther | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\LOCKED_README.bmp | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\WJJBL2n\LOCKED_README.txt | Dropped File | Text |
Unknown
|
...
|
»