VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Trojan, Worm |
WindowsFormsApp2.exe
Windows Exe (x86-32)
Created at 2019-10-05T11:56:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\WindowsFormsApp2.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-07-30 02:01 (UTC+2) |
Last Seen | 2019-08-11 18:43 (UTC+2) |
Names | ByteCode-MSIL.Trojan.Autorun |
Families | Autorun |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x40a422 |
Size Of Code | 0x8600 |
Size Of Initialized Data | 0x800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-07-29 14:05:13+00:00 |
Version Information (11)
»
Assembly Version | 1.0.0.0 |
Comments | - |
CompanyName | - |
FileDescription | WindowsFormsApp2 |
FileVersion | 1.0.0.0 |
InternalName | WindowsFormsApp2.exe |
LegalCopyright | Copyright © 2019 |
LegalTrademarks | - |
OriginalFilename | WindowsFormsApp2.exe |
ProductName | WindowsFormsApp2 |
ProductVersion | 1.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x84b1 | 0x8600 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 4.83 |
.rsrc | 0x40c000 | 0x5e6 | 0x600 | 0x8800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.2 |
.reloc | 0x40e000 | 0xc | 0x200 | 0x8e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.08 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x40a430 | 0xa3fc | 0x85fc | 0x0 |
Memory Dumps (45)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
buffer | 1 | 0x7FE938BE000 | 0x7FE938BEFFF | First Execution | - | 64-bit | 0x7FE938BE000 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE938CE000 | 0x7FE938CEFFF | First Execution | - | 64-bit | 0x7FE938CE040 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE938DB000 | 0x7FE938DBFFF | First Execution | - | 64-bit | 0x7FE938DB020 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE939E1000 | 0x7FE939E1FFF | First Execution | - | 64-bit | 0x7FE939E1070 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE9390D000 | 0x7FE9390DFFF | First Execution | - | 64-bit | 0x7FE9390D1E5 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A21000 | 0x7FE93A21FFF | First Execution | - | 64-bit | 0x7FE93A21040 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE938BF000 | 0x7FE938BFFFF | First Execution | - | 64-bit | 0x7FE938BF050 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE9390D000 | 0x7FE9390DFFF | Content Changed | - | 64-bit | 0x7FE9390D1E5 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE938BF000 | 0x7FE938BFFFF | Content Changed | - | 64-bit | 0x7FE938BF210 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE938BE000 | 0x7FE938BEFFF | Content Changed | - | 64-bit | 0x7FE938BE000 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A21000 | 0x7FE93A21FFF | Content Changed | - | 64-bit | 0x7FE93A21200 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE938DB000 | 0x7FE938DBFFF | Content Changed | - | 64-bit | 0x7FE938DB0A0 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A22000 | 0x7FE93A22FFF | First Execution | - | 64-bit | 0x7FE93A22000 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A23000 | 0x7FE93A23FFF | First Execution | - | 64-bit | 0x7FE93A23032 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A22000 | 0x7FE93A22FFF | Content Changed | - | 64-bit | 0x7FE93A22540 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A24000 | 0x7FE93A24FFF | First Execution | - | 64-bit | 0x7FE93A24000 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE939E1000 | 0x7FE939E1FFF | Content Changed | - | 64-bit | 0x7FE939E124B |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE938BF000 | 0x7FE938BFFFF | Content Changed | - | 64-bit | 0x7FE938BF050 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A25000 | 0x7FE93A25FFF | First Execution | - | 64-bit | 0x7FE93A25040 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A26000 | 0x7FE93A26FFF | First Execution | - | 64-bit | 0x7FE93A26000 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A27000 | 0x7FE93A27FFF | First Execution | - | 64-bit | 0x7FE93A27012 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE938DB000 | 0x7FE938DBFFF | Content Changed | - | 64-bit | 0x7FE938DB100 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE939E2000 | 0x7FE939E2FFF | First Execution | - | 64-bit | 0x7FE939E2000 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A27000 | 0x7FE93A27FFF | Content Changed | - | 64-bit | 0x7FE93A27420 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE938CE000 | 0x7FE938CEFFF | Content Changed | - | 64-bit | 0x7FE938CE040 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A28000 | 0x7FE93A28FFF | First Execution | - | 64-bit | 0x7FE93A28060 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE9390E000 | 0x7FE9390EFFF | First Execution | - | 64-bit | 0x7FE9390E1A5 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A29000 | 0x7FE93A29FFF | First Execution | - | 64-bit | 0x7FE93A29020 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A2A000 | 0x7FE93A2AFFF | First Execution | - | 64-bit | 0x7FE93A2A000 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A2B000 | 0x7FE93A2BFFF | First Execution | - | 64-bit | 0x7FE93A2B012 |
![]() |
![]() |
...
|
buffer | 1 | 0x1AFD6000 | 0x1AFE2FFF | First Execution | - | 64-bit | 0x1AFE1CCC |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A2C000 | 0x7FE93A2CFFF | First Execution | - | 64-bit | 0x7FE93A2C060 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A2D000 | 0x7FE93A2DFFF | First Execution | - | 64-bit | 0x7FE93A2D020 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE938DE000 | 0x7FE938DEFFF | First Execution | - | 64-bit | 0x7FE938DE020 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A2E000 | 0x7FE93A2EFFF | First Execution | - | 64-bit | 0x7FE93A2E032 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A2F000 | 0x7FE93A2FFFF | First Execution | - | 64-bit | 0x7FE93A2F000 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A30000 | 0x7FE93A3FFFF | Content Changed | - | 64-bit | 0x7FE93A30080 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A30000 | 0x7FE93A3FFFF | Content Changed | - | 64-bit | 0x7FE93A31040 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE938DE000 | 0x7FE938DEFFF | Content Changed | - | 64-bit | 0x7FE938DE120 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A30000 | 0x7FE93A3FFFF | Content Changed | - | 64-bit | 0x7FE93A31F20 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A2D000 | 0x7FE93A2DFFF | Content Changed | - | 64-bit | 0x7FE93A2D3A0 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A2B000 | 0x7FE93A2BFFF | Content Changed | - | 64-bit | 0x7FE93A2B880 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A2E000 | 0x7FE93A2EFFF | Content Changed | - | 64-bit | 0x7FE93A2EA60 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE93A30000 | 0x7FE93A3FFFF | Content Changed | - | 64-bit | 0x7FE93A32000 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FE938DE000 | 0x7FE938DEFFF | Content Changed | - | 64-bit | 0x7FE938DE020 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Ransom.WCryG.74DCED97 |
Malicious
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
OlympicDestroyer_Gen1 | Olympic Destroyer destructive malware | Worm |
5/5
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\gdipfontcachev1.dat | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\31X7nzl_oOb83uWgVO-.mp3.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\A7mM31wLDCcWmcfvoDG-.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Bv43WbUQalaODk2.mp3.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\IVZd lwyKqS2V.docx.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ppEh2_S4DonCqdySe4k.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\QuJNxBo.bmp.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\rnbS wHAkE.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\SQwdkQmkSu.wav.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\u5_B.bmp.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\URFd_.mp3.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\v8Mq.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\XYhC1_.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\YSNY.mp3.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZSyivZK02zft3\-SpxLzgLHqiOM.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZSyivZK02zft3\9bpGfnZjcY.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZSyivZK02zft3\RlqcCbSfJhcLWT84Tfz.png.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZSyivZK02zft3\Ye5dKuNPyGipY.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZSyivZK02zft3\2rPIVxUPNYNNKWOCZusM\0pgMXc.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZSyivZK02zft3\2rPIVxUPNYNNKWOCZusM\8g5U14WjPrR7Z0C1.png.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZSyivZK02zft3\2rPIVxUPNYNNKWOCZusM\n1v9HDA0g-yftkbseD.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZSyivZK02zft3\2rPIVxUPNYNNKWOCZusM\T3WYt5ezMtpqMgYM.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZSyivZK02zft3\2rPIVxUPNYNNKWOCZusM\Xr0K3afldk0hBtX.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZSyivZK02zft3\2rPIVxUPNYNNKWOCZusM\zXuDZ.mkv.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZSyivZK02zft3\2rPIVxUPNYNNKWOCZusM\C2Gs5RaLg9sv57AoxjkG\de9.wav.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZSyivZK02zft3\2rPIVxUPNYNNKWOCZusM\C2Gs5RaLg9sv57AoxjkG\dYJtuy6m_yX4uNHgg.odt.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZSyivZK02zft3\2rPIVxUPNYNNKWOCZusM\C2Gs5RaLg9sv57AoxjkG\L4qyiCuG4.odt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\bNgi14Af.jpg.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\C_9uW1MkDEQmtEsPp.png.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\N0pO9YNCgMqVf3095e.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\vWeel.bmp.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ca7geM4aWY5XE AsOPk\6uorACvMs5rhEU.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ca7geM4aWY5XE AsOPk\b n2CMm.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ca7geM4aWY5XE AsOPk\IVYxb.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ca7geM4aWY5XE AsOPk\pg8Gny.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ca7geM4aWY5XE AsOPk\S24zaUsk_y452iokweCS.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ca7geM4aWY5XE AsOPk\t2kHbtbZ.jpg.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NA3Zyc8jSv3vE0\5c2-LRmWVaR.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NA3Zyc8jSv3vE0\8i4fS_S.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NA3Zyc8jSv3vE0\moi1lhKE.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NA3Zyc8jSv3vE0\n-jT.bmp.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NA3Zyc8jSv3vE0\P3L-xJ.jpg.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NA3Zyc8jSv3vE0\SiHDEDfrtlB.png.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NA3Zyc8jSv3vE0\dAOJGXWwFlVrRJOhETd5\NuuULpc9PH4.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NA3Zyc8jSv3vE0\dAOJGXWwFlVrRJOhETd5\o6wWAx8rrH0T3H0Q.bmp.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NA3Zyc8jSv3vE0\dAOJGXWwFlVrRJOhETd5\qvYfMBDPAIQHvG.jpg.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NA3Zyc8jSv3vE0\dAOJGXWwFlVrRJOhETd5\s82-cZyR.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NA3Zyc8jSv3vE0\dAOJGXWwFlVrRJOhETd5\y8mJrXacrYEM7iit-5.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NA3Zyc8jSv3vE0\dAOJGXWwFlVrRJOhETd5\yYLM\B30Qp gSN3Nw0.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NA3Zyc8jSv3vE0\dAOJGXWwFlVrRJOhETd5\yYLM\knS6Z21XuN2cY.png.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NA3Zyc8jSv3vE0\dAOJGXWwFlVrRJOhETd5\yYLM\ovuW.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NA3Zyc8jSv3vE0\dAOJGXWwFlVrRJOhETd5\yYLM\_ANRSWy-.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\bDjKtbLsZFIMchbH.mkv.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\bZJWRiVX 9.mkv.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ekHgaEwrfMYQXTb7TtyK.mp4.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\UW0KJtdhaftr1Zr.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\wwAR5JPqpkikyOHbA7.avi.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\XL2Ma.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\6kP7pNVYXG0hpI\6aME.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\6kP7pNVYXG0hpI\EPJB.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\6kP7pNVYXG0hpI\_dhamilH01THLYweIF89.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\6kP7pNVYXG0hpI\vDaAiEcMyj3\CkBK.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\6kP7pNVYXG0hpI\vDaAiEcMyj3\e2-MSeasNoBwe6f.mkv.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\Dzv3W4ir0s\E1FLjnC.mp4.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\Dzv3W4ir0s\mcotVWCLERpl8M.mkv.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_6HhWhzvWQ-oQTCK\Yjvf Ps3\oC7n.mp4.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_6HhWhzvWQ-oQTCK\Yjvf Ps3\t oo0L.mp4.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_6HhWhzvWQ-oQTCK\Yjvf Ps3\zuscBO4ikrkeE43p.mkv.hackdoor | Dropped File | Stream |
Unknown
|
...
|
»