VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Trojan
|
Threat Names: |
Win32.Trojan.Azden
|
asdjasfhdlkfadfhds.exe1.exe
Windows Exe (x86-32)
Created at 2020-01-17T15:08:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\asdjasfhdlkfadfhds.exe1.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2020-01-09 18:55 (UTC+1) |
Last Seen | 2020-01-17 02:39 (UTC+1) |
Names | Win32.Trojan.Azden |
Families | Azden |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x414751 |
Size Of Code | 0x2b200 |
Size Of Initialized Data | 0x10800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-01-08 15:44:12+00:00 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x2b065 | 0x2b200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.69 |
.rdata | 0x42d000 | 0xa3c2 | 0xa400 | 0x2b600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.64 |
.data | 0x438000 | 0x4338 | 0x1800 | 0x35a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.24 |
.gfids | 0x43d000 | 0xb0 | 0x200 | 0x37200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.88 |
.rsrc | 0x43e000 | 0x1e0 | 0x200 | 0x37400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.72 |
.reloc | 0x43f000 | 0x1b4c | 0x1c00 | 0x37600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.6 |
Imports (2)
»
KERNEL32.dll (79)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetModuleHandleA | 0x0 | 0x42d010 | 0x36c7c | 0x3527c | 0x264 |
LoadLibraryA | 0x0 | 0x42d014 | 0x36c80 | 0x35280 | 0x3a5 |
GetComputerNameA | 0x0 | 0x42d018 | 0x36c84 | 0x35284 | 0x1ce |
CreateProcessA | 0x0 | 0x42d01c | 0x36c88 | 0x35288 | 0xd7 |
GetProcAddress | 0x0 | 0x42d020 | 0x36c8c | 0x3528c | 0x29d |
GetLastError | 0x0 | 0x42d024 | 0x36c90 | 0x35290 | 0x250 |
QueryPerformanceCounter | 0x0 | 0x42d028 | 0x36c94 | 0x35294 | 0x42d |
GetDriveTypeA | 0x0 | 0x42d02c | 0x36c98 | 0x35298 | 0x21e |
UnhandledExceptionFilter | 0x0 | 0x42d030 | 0x36c9c | 0x3529c | 0x582 |
SetUnhandledExceptionFilter | 0x0 | 0x42d034 | 0x36ca0 | 0x352a0 | 0x543 |
GetCurrentProcess | 0x0 | 0x42d038 | 0x36ca4 | 0x352a4 | 0x209 |
TerminateProcess | 0x0 | 0x42d03c | 0x36ca8 | 0x352a8 | 0x561 |
IsProcessorFeaturePresent | 0x0 | 0x42d040 | 0x36cac | 0x352ac | 0x36d |
GetCurrentProcessId | 0x0 | 0x42d044 | 0x36cb0 | 0x352b0 | 0x20a |
GetCurrentThreadId | 0x0 | 0x42d048 | 0x36cb4 | 0x352b4 | 0x20e |
GetSystemTimeAsFileTime | 0x0 | 0x42d04c | 0x36cb8 | 0x352b8 | 0x2d6 |
InitializeSListHead | 0x0 | 0x42d050 | 0x36cbc | 0x352bc | 0x34b |
IsDebuggerPresent | 0x0 | 0x42d054 | 0x36cc0 | 0x352c0 | 0x367 |
GetStartupInfoW | 0x0 | 0x42d058 | 0x36cc4 | 0x352c4 | 0x2be |
GetModuleHandleW | 0x0 | 0x42d05c | 0x36cc8 | 0x352c8 | 0x267 |
RtlUnwind | 0x0 | 0x42d060 | 0x36ccc | 0x352cc | 0x4ad |
SetLastError | 0x0 | 0x42d064 | 0x36cd0 | 0x352d0 | 0x50b |
EnterCriticalSection | 0x0 | 0x42d068 | 0x36cd4 | 0x352d4 | 0x125 |
LeaveCriticalSection | 0x0 | 0x42d06c | 0x36cd8 | 0x352d8 | 0x3a2 |
DeleteCriticalSection | 0x0 | 0x42d070 | 0x36cdc | 0x352dc | 0x105 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x42d074 | 0x36ce0 | 0x352e0 | 0x348 |
TlsAlloc | 0x0 | 0x42d078 | 0x36ce4 | 0x352e4 | 0x573 |
TlsGetValue | 0x0 | 0x42d07c | 0x36ce8 | 0x352e8 | 0x575 |
TlsSetValue | 0x0 | 0x42d080 | 0x36cec | 0x352ec | 0x576 |
TlsFree | 0x0 | 0x42d084 | 0x36cf0 | 0x352f0 | 0x574 |
FreeLibrary | 0x0 | 0x42d088 | 0x36cf4 | 0x352f4 | 0x19e |
LoadLibraryExW | 0x0 | 0x42d08c | 0x36cf8 | 0x352f8 | 0x3a7 |
ExitProcess | 0x0 | 0x42d090 | 0x36cfc | 0x352fc | 0x151 |
GetModuleHandleExW | 0x0 | 0x42d094 | 0x36d00 | 0x35300 | 0x266 |
MultiByteToWideChar | 0x0 | 0x42d098 | 0x36d04 | 0x35304 | 0x3d1 |
CloseHandle | 0x0 | 0x42d09c | 0x36d08 | 0x35308 | 0x7f |
CreateThread | 0x0 | 0x42d0a0 | 0x36d0c | 0x3530c | 0xe8 |
ExitThread | 0x0 | 0x42d0a4 | 0x36d10 | 0x35310 | 0x152 |
ResumeThread | 0x0 | 0x42d0a8 | 0x36d14 | 0x35314 | 0x4a8 |
FreeLibraryAndExitThread | 0x0 | 0x42d0ac | 0x36d18 | 0x35318 | 0x19f |
ReadFile | 0x0 | 0x42d0b0 | 0x36d1c | 0x3531c | 0x450 |
GetStdHandle | 0x0 | 0x42d0b4 | 0x36d20 | 0x35320 | 0x2c0 |
WriteFile | 0x0 | 0x42d0b8 | 0x36d24 | 0x35324 | 0x5e1 |
GetModuleFileNameA | 0x0 | 0x42d0bc | 0x36d28 | 0x35328 | 0x262 |
WideCharToMultiByte | 0x0 | 0x42d0c0 | 0x36d2c | 0x3532c | 0x5cd |
GetCommandLineA | 0x0 | 0x42d0c4 | 0x36d30 | 0x35330 | 0x1c8 |
GetCommandLineW | 0x0 | 0x42d0c8 | 0x36d34 | 0x35334 | 0x1c9 |
GetACP | 0x0 | 0x42d0cc | 0x36d38 | 0x35338 | 0x1a4 |
HeapFree | 0x0 | 0x42d0d0 | 0x36d3c | 0x3533c | 0x333 |
HeapAlloc | 0x0 | 0x42d0d4 | 0x36d40 | 0x35340 | 0x32f |
GetConsoleMode | 0x0 | 0x42d0d8 | 0x36d44 | 0x35344 | 0x1ee |
ReadConsoleW | 0x0 | 0x42d0dc | 0x36d48 | 0x35348 | 0x44e |
GetConsoleCP | 0x0 | 0x42d0e0 | 0x36d4c | 0x3534c | 0x1dc |
CompareStringW | 0x0 | 0x42d0e4 | 0x36d50 | 0x35350 | 0x93 |
LCMapStringW | 0x0 | 0x42d0e8 | 0x36d54 | 0x35354 | 0x396 |
MoveFileExW | 0x0 | 0x42d0ec | 0x36d58 | 0x35358 | 0x3ca |
GetFileType | 0x0 | 0x42d0f0 | 0x36d5c | 0x3535c | 0x23e |
GetFileAttributesExW | 0x0 | 0x42d0f4 | 0x36d60 | 0x35360 | 0x232 |
SetFilePointerEx | 0x0 | 0x42d0f8 | 0x36d64 | 0x35364 | 0x4fd |
GetStringTypeW | 0x0 | 0x42d0fc | 0x36d68 | 0x35368 | 0x2c5 |
HeapReAlloc | 0x0 | 0x42d100 | 0x36d6c | 0x3536c | 0x336 |
FindClose | 0x0 | 0x42d104 | 0x36d70 | 0x35370 | 0x168 |
FindFirstFileExA | 0x0 | 0x42d108 | 0x36d74 | 0x35374 | 0x16d |
FindNextFileA | 0x0 | 0x42d10c | 0x36d78 | 0x35378 | 0x17d |
IsValidCodePage | 0x0 | 0x42d110 | 0x36d7c | 0x3537c | 0x372 |
GetOEMCP | 0x0 | 0x42d114 | 0x36d80 | 0x35380 | 0x286 |
GetCPInfo | 0x0 | 0x42d118 | 0x36d84 | 0x35384 | 0x1b3 |
GetEnvironmentStringsW | 0x0 | 0x42d11c | 0x36d88 | 0x35388 | 0x227 |
FreeEnvironmentStringsW | 0x0 | 0x42d120 | 0x36d8c | 0x3538c | 0x19d |
SetEnvironmentVariableA | 0x0 | 0x42d124 | 0x36d90 | 0x35390 | 0x4ed |
SetStdHandle | 0x0 | 0x42d128 | 0x36d94 | 0x35394 | 0x522 |
GetProcessHeap | 0x0 | 0x42d12c | 0x36d98 | 0x35398 | 0x2a2 |
FlushFileBuffers | 0x0 | 0x42d130 | 0x36d9c | 0x3539c | 0x192 |
CreateFileW | 0x0 | 0x42d134 | 0x36da0 | 0x353a0 | 0xc2 |
WriteConsoleW | 0x0 | 0x42d138 | 0x36da4 | 0x353a4 | 0x5e0 |
HeapSize | 0x0 | 0x42d13c | 0x36da8 | 0x353a8 | 0x338 |
SetEndOfFile | 0x0 | 0x42d140 | 0x36dac | 0x353ac | 0x4ea |
DecodePointer | 0x0 | 0x42d144 | 0x36db0 | 0x353b0 | 0xfe |
RaiseException | 0x0 | 0x42d148 | 0x36db4 | 0x353b4 | 0x440 |
ADVAPI32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CryptReleaseContext | 0x0 | 0x42d000 | 0x36c6c | 0x3526c | 0xdb |
CryptAcquireContextA | 0x0 | 0x42d004 | 0x36c70 | 0x35270 | 0xc0 |
CryptGenRandom | 0x0 | 0x42d008 | 0x36c74 | 0x35274 | 0xd1 |
Exports (74)
»
Api name | EAT Address | Ordinal |
---|---|---|
_cJSON_AddArrayToObject@8 | 0x10ed0 | 0x1 |
_cJSON_AddBoolToObject@12 | 0x10f80 | 0x2 |
_cJSON_AddFalseToObject@8 | 0x11030 | 0x3 |
_cJSON_AddItemReferenceToArray@8 | 0x110e0 | 0x4 |
_cJSON_AddItemReferenceToObject@12 | 0x11130 | 0x5 |
_cJSON_AddItemToArray@8 | 0x111b0 | 0x6 |
_cJSON_AddItemToObject@12 | 0x111f0 | 0x7 |
_cJSON_AddItemToObjectCS@12 | 0x11260 | 0x8 |
_cJSON_AddNullToObject@8 | 0x112c0 | 0x9 |
_cJSON_AddNumberToObject@16 | 0x11370 | 0xa |
_cJSON_AddObjectToObject@8 | 0x11450 | 0xb |
_cJSON_AddRawToObject@12 | 0x11500 | 0xc |
_cJSON_AddStringToObject@12 | 0x11590 | 0xd |
_cJSON_AddTrueToObject@8 | 0x11620 | 0xe |
_cJSON_Compare@12 | 0x116d0 | 0xf |
_cJSON_CreateArray@0 | 0x119b0 | 0x10 |
_cJSON_CreateArrayReference@4 | 0x119e0 | 0x11 |
_cJSON_CreateBool@4 | 0x11a20 | 0x12 |
_cJSON_CreateDoubleArray@8 | 0x11a60 | 0x13 |
_cJSON_CreateFalse@0 | 0x11b00 | 0x14 |
_cJSON_CreateFloatArray@8 | 0x11b30 | 0x15 |
_cJSON_CreateIntArray@8 | 0x11bd0 | 0x16 |
_cJSON_CreateNull@0 | 0x11c70 | 0x17 |
_cJSON_CreateNumber@8 | 0x11ca0 | 0x18 |
_cJSON_CreateObject@0 | 0x11d10 | 0x19 |
_cJSON_CreateObjectReference@4 | 0x11d40 | 0x1a |
_cJSON_CreateRaw@4 | 0x11d80 | 0x1b |
_cJSON_CreateString@4 | 0x11e10 | 0x1c |
_cJSON_CreateStringArray@8 | 0x11ea0 | 0x1d |
_cJSON_CreateStringReference@4 | 0x11f30 | 0x1e |
_cJSON_CreateTrue@0 | 0x11f70 | 0x1f |
_cJSON_Delete@4 | 0x11fb0 | 0x20 |
_cJSON_DeleteItemFromArray@8 | 0x12030 | 0x21 |
_cJSON_DeleteItemFromObject@8 | 0x12050 | 0x22 |
_cJSON_DeleteItemFromObjectCaseSensitive@8 | 0x120c0 | 0x23 |
_cJSON_DetachItemFromArray@8 | 0x12130 | 0x24 |
_cJSON_DetachItemFromObject@8 | 0x121a0 | 0x25 |
_cJSON_DetachItemFromObjectCaseSensitive@8 | 0x12200 | 0x26 |
_cJSON_DetachItemViaPointer@8 | 0x12260 | 0x27 |
_cJSON_Duplicate@8 | 0x122b0 | 0x28 |
_cJSON_GetArrayItem@8 | 0x123a0 | 0x29 |
_cJSON_GetArraySize@4 | 0x123d0 | 0x2a |
_cJSON_GetErrorPtr@0 | 0x12400 | 0x2b |
_cJSON_GetObjectItem@8 | 0x12410 | 0x2c |
_cJSON_GetObjectItemCaseSensitive@8 | 0x12430 | 0x2d |
_cJSON_GetStringValue@4 | 0x12450 | 0x2e |
_cJSON_HasObjectItem@8 | 0x12480 | 0x2f |
_cJSON_InitHooks@4 | 0x124a0 | 0x30 |
_cJSON_InsertItemInArray@12 | 0x12530 | 0x31 |
_cJSON_IsArray@4 | 0x125a0 | 0x32 |
_cJSON_IsBool@4 | 0x125c0 | 0x33 |
_cJSON_IsFalse@4 | 0x125e0 | 0x34 |
_cJSON_IsInvalid@4 | 0x12600 | 0x35 |
_cJSON_IsNull@4 | 0x12620 | 0x36 |
_cJSON_IsNumber@4 | 0x12640 | 0x37 |
_cJSON_IsObject@4 | 0x12660 | 0x38 |
_cJSON_IsRaw@4 | 0x12680 | 0x39 |
_cJSON_IsString@4 | 0x126a0 | 0x3a |
_cJSON_IsTrue@4 | 0x126c0 | 0x3b |
_cJSON_Minify@4 | 0x126e0 | 0x3c |
_cJSON_Parse@4 | 0x127f0 | 0x3d |
_cJSON_ParseWithOpts@12 | 0x12810 | 0x3e |
_cJSON_Print@4 | 0x12990 | 0x3f |
_cJSON_PrintBuffered@12 | 0x129b0 | 0x40 |
_cJSON_PrintPreallocated@16 | 0x12a70 | 0x41 |
_cJSON_PrintUnformatted@4 | 0x12b10 | 0x42 |
_cJSON_ReplaceItemInArray@12 | 0x12b30 | 0x43 |
_cJSON_ReplaceItemInObject@12 | 0x12b80 | 0x44 |
_cJSON_ReplaceItemInObjectCaseSensitive@12 | 0x12ba0 | 0x45 |
_cJSON_ReplaceItemViaPointer@12 | 0x12bc0 | 0x46 |
_cJSON_SetNumberHelper@12 | 0x12c30 | 0x47 |
_cJSON_Version@0 | 0x12c90 | 0x48 |
_cJSON_free@4 | 0x12cb0 | 0x49 |
_cJSON_malloc@4 | 0x12cd0 | 0x4a |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
asdjasfhdlkfadfhds.exe1.exe | 1 | 0x01330000 | 0x01370FFF | Relevant Image |
![]() |
32-bit | 0x01346446 |
![]() |
![]() |
...
|
C:\588bce7c90097ed212\SplashScreen.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1025\eula.rtf.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1028\eula.rtf.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1029\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1030\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1033\eula.rtf.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1032\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1035\eula.rtf.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1036\eula.rtf.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1038\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1040\eula.rtf.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1041\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1042\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1043\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1044\eula.rtf.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1046\eula.rtf.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1053\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1055\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2052\eula.rtf.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\2070\eula.rtf.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3076\eula.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\3082\eula.rtf.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\4Roonv SsFXe.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\ePbOSxzSTHJyUX0qqV.png.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\cBIDHqgfiodnGq1SAsX.jpg.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\HXcn.mp3.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\ITbKB5.bmp.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\RMph9vbE2uqaXD2g.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\z4G9GONSasoREb.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\bnbWqs26Qk0F.gif.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\dppH4uxw OfpdPpRxrh7.gif.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\CC-FXFK0L3rN9Y.jpg.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\dwx420Mg7XFbkOQ.jpg.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\EST4et454LcvPX.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\FBfq3ydtewWmHX.bmp.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Feh2GG.png.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\fyHiiV.jpg.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\HD6AR.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Ijhpb-yxk57ZtDG.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\IkBcoKqD-cgz2z3qAPwB.png.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Ivkm4tvy4sFu.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\jC4MVa.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\K-tmfo2hcETiCrFW.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\NgNuSU3Yq6AfH0H4XIPf.bmp.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\NiG U3Sr.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\oHqt9tGmh3Mf5r1D.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\To1vWD99VRx5GIA.gif.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\s6I6DHDeLGZoatSBdQv.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\UGQ-pZan-bQZAuaB9Q65.bmp.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\W_mVNsdHRo1.gif.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Z3FmP-Zr wRhv.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\_o2EFSOV0-j.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\_Oxq37.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Microsoft\User Account Pictures\Default User.dat.ragnarok_cry | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Microsoft\User Account Pictures\guest.bmp.ragnarok_cry | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Microsoft\User Account Pictures\user-192.png.ragnarok_cry | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Microsoft\User Account Pictures\user-32.png.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Microsoft\User Account Pictures\user-48.png.ragnarok_cry | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Microsoft\User Account Pictures\user-40.png.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Microsoft\User Account Pictures\user.bmp.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\LX0vrheR G7p.bmp.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\oGsREvSogacQ7wIabF.png.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\qlC2f-Unra48sU4.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\SDnAPvzROybdYcf2G.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\xeFe96nNaR.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\ZpDD.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\_fL4P.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\67Rs4NdS4WM\xGFVr-3BalAgx kDk.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\fIpsW1zfY8n4VRy\2SYtvhGUclZ-C7VK3_b.pdf.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\fIpsW1zfY8n4VRy\6ngbD.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\fIpsW1zfY8n4VRy\cDuvna.xls.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\fIpsW1zfY8n4VRy\BErWOr6y.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\fIpsW1zfY8n4VRy\YPhhY0T1sptyYYaRQQVm.doc.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\K7F1p\e2rvkFzSYpjZp.xls.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\K7F1p\jDSr8nZ.xls.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\HFbT7130 UW\ioSfoQJ2Br.mp3.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\67Rs4NdS4WM\nid6mOdjGpO\cQH4 q8dawXh-lUDy.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\GVdr6v_443\naYQg9mk\Q641CRLqWxXNJ2Dq8.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\HFbT7130 UW\0a_DvVXrZ6Ps\a_E-qCJaJYCf-C 4.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\HFbT7130 UW\0a_DvVXrZ6Ps\7hWPO-IdIytPtZ6o.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Microsoft\ClickToRun\201EB7DF-C721-4B8B-9C81-A09DE7F931E6\en-us.16\stream.x64.en-us.man.dat.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Package Cache\{582EA838-9199-3518-A05C-DB09462F68EC}v14.10.25017\packages\vcRuntimeMinimum_x86\cab1.cab.ragnarok_cry | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Package Cache\{8D4F7A6D-6B81-3DC8-9C21-6008E4866727}v14.10.25017\packages\vcRuntimeMinimum_amd64\cab1.cab.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Package Cache\{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}v12.0.21005\packages\vcRuntimeMinimum_amd64\cab1.cab.ragnarok_cry | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Package Cache\{929FBD26-9020-399B-9A7A-751D61F0B942}v12.0.21005\packages\vcRuntimeAdditional_amd64\cab1.cab.ragnarok_cry | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Package Cache\{B175520C-86A2-35A7-8619-86DC379688B9}v11.0.61030\packages\vcRuntimeAdditional_x86\cab1.cab.ragnarok_cry | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Package Cache\{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}v11.0.61030\packages\vcRuntimeMinimum_amd64\cab1.cab.ragnarok_cry | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Package Cache\{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}v12.0.21005\packages\vcRuntimeAdditional_x86\cab1.cab.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Package Cache\{E512788E-C50B-3858-A4B9-73AD5F3F9E93}v14.10.25017\packages\vcRuntimeAdditional_amd64\cab1.cab.ragnarok_cry | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\FORMS\FRMCACHE.DAT | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\Internet Explorer\brndlog.txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\Internet Explorer\brndlog.bak.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\OneDrivePersonal.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\Visio\content16.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\67Rs4NdS4WM\nid6mOdjGpO\Qu9HQPl4f4Gu\2GUNK_f4PvMJ.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\GVdr6v_443\naYQg9mk\B jK20Ys4_ E\xXNVx2L7IQ3P4oTX6xc8.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\GVdr6v_443\naYQg9mk\AUwNahu\xax2VvLZX.rtf.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\HFbT7130 UW\0a_DvVXrZ6Ps\TOAC\M5uxNPoePz3ivk2.mp3.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\A6A87302-92AE-41F2-AC52-73F5EE18259F\en-us.16\stream.x86.en-us.man.dat.ragnarok_cry | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\5A65C4D7-3CDF-4BE4-8560-F036D300C13F\x-none.16\stream.x86.x-none.man.dat.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Adobe\Acrobat\DC\IconCacheRdr.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Adobe\Acrobat\DC\IconCacheRdr65536.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9NBLGGGXW3P8.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9NBLGGH10PG8.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9NBLGGH42THS.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9NBLGGH4NNS1.dat.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9NBLGGH4QGHW.dat.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9NBLGGH4R32N.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\A6A87302-92AE-41F2-AC52-73F5EE18259F\x-none.16\stream.x86.x-none.man.dat.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9NBLGGH537C2.dat.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9NBLGGH5FV99.dat.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9NBLGGH5PNB1.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRD2G0J.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRDTBVB.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRFHV4V.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRFHVFW.dat.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRFHVJL.dat.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRFHVN5.dat.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRFHVQM.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRFHWKN.dat.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRFJ364.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRFJ3P2.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRFJ3PM.dat.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRFJ3PT.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRFJ3Q2.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRFJ3T6.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRFJBBG.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRFJBD8.dat.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRFJBH4.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\Office\OTele\{61F167A5-718E-4E8B-8D6B-141DA9EB9DC9} (0) - 3976 - visio.exe - OTele.dat.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\Office\OTele\{6E699364-D728-4772-BD21-24A21748BF64} (0) - 3932 - excel.exe - OTele.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\Office\OTele\{6E699364-D728-4772-BD21-24A21748BF64} (1) - 3932 - excel.exe - OTele.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\Office\OTele\{6E699364-D728-4772-BD21-24A21748BF64} (2) - 3932 - excel.exe - OTele.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\Office\OTele\{6E699364-D728-4772-BD21-24A21748BF64} (1) - 3932 - excel.exe - OTeleMediumCost.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\Office\OTele\{9C5E7D9B-2A2B-4118-AE33-9030D7BCCAB1} (0) - 2228 - winproj.exe - OTeleMediumCost.dat.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\AppWhite.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\AutoPlayOptIn.png.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\ElevatedAppBlue.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\AutoPlayOptIn.gif.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\ElevatedAppWhite.png.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\OneDriveLogo.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\Error.png.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\OneDrivePersonal.cmd.ragnarok_cry | Dropped File | Batch |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\QuotaError.png.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\QuotaNearing.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\ScreenshotOptIn.gif.ragnarok_cry | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\1049\How_To_Decrypt_My_Files.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1031\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1037\eula.rtf | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\1045\eula.rtf.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\0UtczcsCbVrdnBDJYndI.mp3.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\7_idhvwzViqp9yJJjd.csv.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\g8O8.png.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\S_xgEVrampBsf3HS5.png.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\wGUv_BvWC3z-JCPD9v.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\z9XUp01vJIKkgVq.mp3.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\VxcwUCeA9.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\0RIhI8h5f0kaej Ic6.jpg.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\9HPqgLzuM8W.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\cN1eZAbAXYh8__E7w.png.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\FawH.bmp.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\H3aFyVcVItK 68cFQ0.bmp.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\m1kd_2ltmf4om8medz.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\Mlg1NPSL8e.gif.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\Q9t5lo1JTYxiG0zC0eoM.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\QcjhSO5C8nNWxRRwIsM8.gif.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\w2Ggflt1qbvxMq9I0.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Microsoft\Storage Health\StorageEventsArchive.dat.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Microsoft\User Account Pictures\FD1HVy.dat.ragnarok_cry | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Microsoft\User Account Pictures\guest.png.ragnarok_cry | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Microsoft\User Account Pictures\user.png.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\9tfWUgFYqYCKT4.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\csk1ST.png.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\eUme_LG_s4BCcalkb.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\jd2tT95Z.bmp.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\j8YqChR.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\QwjCLC.doc | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Rv7ugHMQX2-xvYX8.ppt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\xF31skQftSSgwuxP9.png.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\67Rs4NdS4WM\lXrHo_P8qOs0fe7RXsa0.mp3.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\67Rs4NdS4WM\lCxphD2HS6Gm4Zcoj7.png.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\GVdr6v_443\d AJprNora.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\o1Rxg9ErX6xmX\kbbSxx3RrM_CKt.xls | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\K7F1p\KOKhTZp2kXQq.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\HFbT7130 UW\baMT_Xfn ZTzg52QLPe.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\67Rs4NdS4WM\nid6mOdjGpO\AZw6vD_gawfcZQ.png.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Microsoft\ClickToRun\0D0D4EEB-DC03-4B3F-88DF-959FE1EDE5F4\en-us.16\stream.x64.en-us.man.dat.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Microsoft\ClickToRun\19B11135-37BD-4FA1-A78E-C20CA2BDA1C0\en-us.16\stream.x64.en-us.man.dat.ragnarok_cry | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Microsoft\ClickToRun\0D0D4EEB-DC03-4B3F-88DF-959FE1EDE5F4\x-none.16\stream.x64.x-none.man.dat.ragnarok_cry | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Microsoft\ClickToRun\19B11135-37BD-4FA1-A78E-C20CA2BDA1C0\x-none.16\stream.x64.x-none.man.dat.ragnarok_cry | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Microsoft\ClickToRun\201EB7DF-C721-4B8B-9C81-A09DE7F931E6\x-none.16\stream.x64.x-none.man.dat.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Package Cache\{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}v12.0.21005\packages\vcRuntimeMinimum_x86\cab1.cab.ragnarok_cry | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Package Cache\{37B8F9C7-03FB-3253-8781-2517C99D7C00}v11.0.61030\packages\vcRuntimeAdditional_amd64\cab1.cab.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Package Cache\{68306422-7C57-373F-8860-D26CE4BA2A15}v14.10.25017\packages\vcRuntimeAdditional_x86\cab1.cab.ragnarok_cry | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Package Cache\{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}v11.0.61030\packages\vcRuntimeMinimum_x86\cab1.cab.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Comms\Temp\CalendarCache.dat | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\67Rs4NdS4WM\nid6mOdjGpO\Qu9HQPl4f4Gu\u2kyGI.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\All Users\Microsoft\ClickToRun\ProductReleases\5A65C4D7-3CDF-4BE4-8560-F036D300C13F\en-us.16\stream.x86.en-us.man.dat.ragnarok_cry | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9NBLGGH4LS1F.dat.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRD1HKW.dat.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRD29V9.dat.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRDTBJJ.dat.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRFHVH4.dat.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRFHWD2.dat | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRFJ140.dat | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRFJ3PR.dat.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\InstallAgent\Checkpoints\9WZDNCRFJBMP.dat | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\Office\OTele\{6E699364-D728-4772-BD21-24A21748BF64} (0) - 3932 - excel.exe - OTeleMediumCost.dat.ragnarok_cry | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\Office\OTele\{9C5E7D9B-2A2B-4118-AE33-9030D7BCCAB1} (0) - 2228 - winproj.exe - OTele.dat | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\Office\OTele\{9C5E7D9B-2A2B-4118-AE33-9030D7BCCAB1} (1) - 2228 - winproj.exe - OTele.dat | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\Office\OTele\{9C5E7D9B-2A2B-4118-AE33-9030D7BCCAB1} (1) - 2228 - winproj.exe - OTeleMediumCost.dat | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\AppBlue.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\QuotaCritical.png | Modified File | Stream |
Not Queried
|
...
|
»