VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Wiper
Backdoor
|
Threat Names: |
Generic.Ransom.CloudSword.05CC35B1
Generic.Ransom.CloudSword.387B4D82
|
iIbj7C5GiR0xGUkk.exe
Windows Exe (x86-32)
Created at 2020-10-06T01:02:00
Remarks
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\iIbj7C5GiR0xGUkk.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x41f2ce |
Size Of Code | 0x1d400 |
Size Of Initialized Data | 0xe00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-10-05 22:47:48+00:00 |
Version Information (9)
»
Assembly Version | 1.0.0.0 |
CompanyName | Microsoft |
FileDescription | Nibiru |
FileVersion | 1.0.0.0 |
InternalName | Nibiru.exe |
LegalCopyright | Copyright © Microsoft 2020 |
OriginalFilename | Nibiru.exe |
ProductName | Nibiru |
ProductVersion | 1.0.0.0 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x1d2d4 | 0x1d400 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.82 |
.sdata | 0x420000 | 0x91 | 0x200 | 0x1d800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.09 |
.rsrc | 0x422000 | 0x838 | 0xa00 | 0x1da00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.87 |
.reloc | 0x424000 | 0xc | 0x200 | 0x1e400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x1f29c | 0x1d69c | 0x0 |
Memory Dumps (29)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
iibj7c5gir0xgukk.exe | 1 | 0x007D0000 | 0x007F5FFF | Relevant Image |
![]() |
32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x051E3000 | 0x051E4FFF | First Execution |
![]() |
32-bit | 0x051E3976 |
![]() |
![]() |
...
|
buffer | 1 | 0x010C6000 | 0x010C9FFF | First Execution |
![]() |
32-bit | 0x010C93E0 |
![]() |
![]() |
...
|
buffer | 1 | 0x010CA000 | 0x010CAFFF | First Execution |
![]() |
32-bit | 0x010CA030 |
![]() |
![]() |
...
|
buffer | 1 | 0x010C6000 | 0x010C9FFF | Content Changed |
![]() |
32-bit | 0x010C6000 |
![]() |
![]() |
...
|
buffer | 1 | 0x010C6000 | 0x010C9FFF | Content Changed |
![]() |
32-bit | 0x010C9A01 |
![]() |
![]() |
...
|
buffer | 1 | 0x010CA000 | 0x010CAFFF | Content Changed |
![]() |
32-bit | 0x010CA170 |
![]() |
![]() |
...
|
buffer | 1 | 0x051E3000 | 0x051E4FFF | Content Changed |
![]() |
32-bit | 0x051E3836 |
![]() |
![]() |
...
|
buffer | 1 | 0x010CB000 | 0x010CBFFF | First Execution |
![]() |
32-bit | 0x010CB000 |
![]() |
![]() |
...
|
buffer | 1 | 0x010CA000 | 0x010CAFFF | Content Changed |
![]() |
32-bit | 0x010CA170 |
![]() |
![]() |
...
|
buffer | 1 | 0x051E3000 | 0x051E4FFF | Content Changed |
![]() |
32-bit | 0x051E380E |
![]() |
![]() |
...
|
buffer | 1 | 0x010CB000 | 0x010CBFFF | Content Changed |
![]() |
32-bit | 0x010CB5B8 |
![]() |
![]() |
...
|
buffer | 1 | 0x051E3000 | 0x051E4FFF | Content Changed |
![]() |
32-bit | 0x051E3886 |
![]() |
![]() |
...
|
buffer | 1 | 0x010CC000 | 0x010CCFFF | First Execution |
![]() |
32-bit | 0x010CC44C |
![]() |
![]() |
...
|
buffer | 1 | 0x051E3000 | 0x051E4FFF | Content Changed |
![]() |
32-bit | 0x051E37E6 |
![]() |
![]() |
...
|
buffer | 1 | 0x010CB000 | 0x010CBFFF | Content Changed |
![]() |
32-bit | 0x010CB978 |
![]() |
![]() |
...
|
buffer | 1 | 0x010CC000 | 0x010CCFFF | Content Changed |
![]() |
32-bit | 0x010CCA82 |
![]() |
![]() |
...
|
buffer | 1 | 0x010CD000 | 0x010CDFFF | First Execution |
![]() |
32-bit | 0x010CD002 |
![]() |
![]() |
...
|
buffer | 1 | 0x010C6000 | 0x010C9FFF | Content Changed |
![]() |
32-bit | 0x010C9F80 |
![]() |
![]() |
...
|
buffer | 1 | 0x051E3000 | 0x051E4FFF | Content Changed |
![]() |
32-bit | 0x051E39EE |
![]() |
![]() |
...
|
buffer | 1 | 0x010CE000 | 0x010CEFFF | First Execution |
![]() |
32-bit | 0x010CE024 |
![]() |
![]() |
...
|
buffer | 1 | 0x00F4C000 | 0x00F4CFFF | First Execution |
![]() |
32-bit | 0x00F4C00A |
![]() |
![]() |
...
|
buffer | 1 | 0x010CD000 | 0x010CDFFF | Content Changed |
![]() |
32-bit | 0x010CD002 |
![]() |
![]() |
...
|
buffer | 1 | 0x051E3000 | 0x051E4FFF | Content Changed |
![]() |
32-bit | 0x051E415E |
![]() |
![]() |
...
|
buffer | 1 | 0x010CC000 | 0x010CCFFF | Content Changed |
![]() |
32-bit | 0x010CCB20 |
![]() |
![]() |
...
|
buffer | 1 | 0x010CF000 | 0x010CFFFF | First Execution |
![]() |
32-bit | 0x010CFC10 |
![]() |
![]() |
...
|
buffer | 1 | 0x05500000 | 0x0550FFFF | First Execution |
![]() |
32-bit | 0x05500048 |
![]() |
![]() |
...
|
buffer | 1 | 0x05500000 | 0x0550FFFF | Content Changed |
![]() |
32-bit | 0x055005BA |
![]() |
![]() |
...
|
buffer | 1 | 0x051E3000 | 0x051E4FFF | Content Changed |
![]() |
32-bit | 0x051E3A3E |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Ransom.CloudSword.05CC35B1 |
Malicious
|
C:\588bce7c90097ed212\DHtmlHeader.html.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\hwcompatShared.txt.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\User Account Pictures\user-192.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\User Account Pictures\user-32.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\User Account Pictures\user-40.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\Windows Live\WLive48x48.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\DQ8q.jpg.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\DQwVJgD.mp3.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\dW70.mp4.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\eBZI_S82xI.avi.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\fsTSUF7GGBHaGasH688_.xls.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\g48__MIxc-OUj Y.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\iOg65Q9eQrhscFn9Xoa.avi.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\jpzpPEvnaoOYTh.jpg.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\KO9515tndcBypT-4RkQ.docx.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\rpNIcR.mp4.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\yEU_QrO1jR2l-sVKhvK.wav.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\8LztP3a _8.pptx.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\99YM33o5 GibZ8D.pptx.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Cxm_gQZB8umzZs35Cg.xlsx.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\G yiDU-Kk2qx1ryu.pptx.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\GW_6oO3FJSRR.docx.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\i0x-C9.xlsx.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\iAqa-KOayEMgC1.docx.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\JYYz6spPq7chaGJr6z.pptx.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Q-s-ERd.docx.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\QiDnZo.pptx.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\soJ_.docx.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\v7SboHQRgFW_YwYbIVgO.xlsx.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\xQDEKgpcsffby.xlsx.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\_uWAjjw 6BF3m8YY_P.docx.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\6avq_SSMxGAp0i4weIW.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\FbVbnL9HRGIv.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\xZjuApKV.jpg.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\amd64\hwexclude.txt.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\i386\hwcompat.txt.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\block.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\bluelogo.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\bullet.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\GetStartedHoverOver.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\logo.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\marketing.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\NoNetworkConnection.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\NoNetworkConnectionHoverOver.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\pass.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report.html.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\7Ohwuakxtp.wav.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\afn5.wav.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\alF3zGKgwG9iJ5ZI.wav.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\EK0Z71k5.mp4.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\j3gVdCjMEcPZmrHw1d m.mp4.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\ko_pqxp.wav.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\OCsTQrH.avi.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\RsS8Y3GR9yE Q2DeKdPh.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\sIdFr_kF521 PfvBOY.wav.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\SQxz7C28El9sYMP.wav.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\tYHkHgLZtVx0bd.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\W87SF1.wav.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\XcvvYc7WieakWugMM7a.mp3.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\rMTvOUlU85C_F4jy\DFFboQ.mp3.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\rMTvOUlU85C_F4jy\fYsO6SDkEB2lBbzFWu7T.xls.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\rMTvOUlU85C_F4jy\q g X_BdhsCMZcN.avi.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\rMTvOUlU85C_F4jy\WM06F.wav.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\176yovKR\lzUG2Act0hlhItyCIy.doc.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\176yovKR\r09vzS.docx.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\b_w0KlCgphCofc8_8qJ\DA2SZ2m.doc.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\b_w0KlCgphCofc8_8qJ\OI18kvp2rsNAoE.ppt.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\b_w0KlCgphCofc8_8qJ\p6oZTfwtOGptZH.ppt.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\iccuIF4V8Xa\KiqEvULIemb5X.doc.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\ddEgmOTySXncH6_kjf\qPQA3R.mp3.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\mcqecqinIbnBgL6rE4YX\acJPDvs3.wav.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\mcqecqinIbnBgL6rE4YX\wMok6Sc2FTZYGUF I.wav.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\mcqecqinIbnBgL6rE4YX\YLSfHcl.wav.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\PJ4fBt\46M66cDCGKSR_-GbUa.mp3.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\PJ4fBt\jtnwIfgXsTae.wav.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\PJ4fBt\mTuzX5E2hYwDjM.mp3.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\zVoqxOA_Bh\NRvurTq-SNFKIB.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\zVoqxOA_Bh\vcM7 _Syqlv1NMZj8Z.jpg.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ZY3d5kjr6yCKM\kPpQK8wUi.avi.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ZY3d5kjr6yCKM\KwOP.avi.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\Windows NT\MSScan\WelcomeScan.jpg.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\dqqq7 PB4h9wuRaEf D7.mp4.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\e9V6nXa1SVPpZ.jpg.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\mQq7NCBeQiaGUC_Dxcfd.avi.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\Q8enEBucps4HeCuxW7.wav.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\RmOKyz.avi.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\tjIBMfpPq-HnyzPVczc6.wav.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\UkoKTq_D2NJmeBhL.xls.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\waJiMj3LI-dZMkkpDnsj.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\w_ERrH0FYCzmbN.mp4.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\Xsjv3arnZDSZ1TQ.docx.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\iccuIF4V8Xa\BT_tZi\EYCm.docx.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\iccuIF4V8Xa\xutuo\4BU 5 PPFMmmAu8Inf.ppt.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\iccuIF4V8Xa\xutuo\61SQNk05TV23ZJweZs.doc.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\mcqecqinIbnBgL6rE4YX\cdxU2SZXH\40s3yDxU.wav.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\mcqecqinIbnBgL6rE4YX\cdxU2SZXH\i4Q_bNnMgPcsKRu.mp3.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\mcqecqinIbnBgL6rE4YX\cdxU2SZXH\irx rsp.wav.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\mcqecqinIbnBgL6rE4YX\cdxU2SZXH\qARfIhYPJfJR8HARYVO.wav.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\PJ4fBt\UPN1mAVjAHOPCUfnYAM0\b-Mp.wav.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\PJ4fBt\UPN1mAVjAHOPCUfnYAM0\DD2C7.wav.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\PJ4fBt\UPN1mAVjAHOPCUfnYAM0\PSACzn8M8omNAGBH.wav.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\PJ4fBt\UPN1mAVjAHOPCUfnYAM0\vGcuB6OIQ19M.mp3.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\zVoqxOA_Bh\hAfIBJeJ-ZF1\6ETR1_E0a.jpg.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\zVoqxOA_Bh\hAfIBJeJ-ZF1\EjqfmX.jpg.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\zVoqxOA_Bh\hAfIBJeJ-ZF1\NbWqgH0bw5x.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\zVoqxOA_Bh\hAfIBJeJ-ZF1\YSodFl- lx.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ZY3d5kjr6yCKM\oMsKNz9K RN4O-AaGdJ\hl7beh.avi.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ZY3d5kjr6yCKM\oMsKNz9K RN4O-AaGdJ\naEATNml54.mp4.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ZY3d5kjr6yCKM\oMsKNz9K RN4O-AaGdJ\sHbihTPrXXs.avi.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ZY3d5kjr6yCKM\zbV7mlBAKQ6Pp2-R\3dt1sEbc3 XSz.mp4.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\device.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\Device Stage\Device\{8702d817-5aad-4674-9ef3-4d3decd87120}\background.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\overlay.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\Internet Explorer\brndlog.txt.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\iccuIF4V8Xa\BT_tZi\u_CPZ0cmRNWm602d\-XwqpXDaTlnpyV4xwW.xls.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\iccuIF4V8Xa\BT_tZi\_XlRoz8U-Uhyf\j 6sKGWrrJpZ0.docx.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\PJ4fBt\UPN1mAVjAHOPCUfnYAM0\l5A62CzzO2fy\WVwta5U26Jyw4.wav.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\zVoqxOA_Bh\hAfIBJeJ-ZF1\qE7k21fO TgOqo-97\-GX95gJdNv7W6lJ_kfw.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\zVoqxOA_Bh\hAfIBJeJ-ZF1\qE7k21fO TgOqo-97\qHdZK3LDf1.jpg.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\zVoqxOA_Bh\hAfIBJeJ-ZF1\qE7k21fO TgOqo-97\qHzhRYqW.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\zVoqxOA_Bh\hAfIBJeJ-ZF1\qE7k21fO TgOqo-97\twZ5eDa1YsAAVujs8-2h.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\zVoqxOA_Bh\hAfIBJeJ-ZF1\qE7k21fO TgOqo-97\w9Br0zXZ5dxR.jpg.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\zVoqxOA_Bh\hAfIBJeJ-ZF1\qE7k21fO TgOqo-97\YNFHu40kx6Sp9.jpg.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ZY3d5kjr6yCKM\k1X6EGxl Bv\LaAhKrCghUD\gQhKTNZe3vdnnGTrY.mp4.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ZY3d5kjr6yCKM\k1X6EGxl Bv\LaAhKrCghUD\u7Wit2GzZxnTb.mp4.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ZY3d5kjr6yCKM\oMsKNz9K RN4O-AaGdJ\M 0Q6Cm19opOon\9QuYInR.avi.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ZY3d5kjr6yCKM\oMsKNz9K RN4O-AaGdJ\M 0Q6Cm19opOon\HmTWgk.mp4.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ZY3d5kjr6yCKM\oMsKNz9K RN4O-AaGdJ\M 0Q6Cm19opOon\zeMVzEZMhBr6.mp4.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\ThirdPartyNotices.txt.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7076.1026\ErrorPage.html.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7076.1026\alertIcon.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\AppBlue.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\AppErrorBlue.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\AppWhite.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\AutoPlayOptIn.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\ElevatedAppBlue.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7076.1026\ElevatedAppWhite.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\LoadingPage.html.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7076.1026\OneDriveLogo.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\QuotaCritical.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\QuotaError.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\QuotaNearing.png.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\TestSharePage.html.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\ThirdPartyNotices.txt.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\LocalState\LogSettings.txt.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ZY3d5kjr6yCKM\k1X6EGxl Bv\LaAhKrCghUD\YngJo6Fh1yiLG\kzfBfN9pIpJ_7u12IPr.avi.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ZY3d5kjr6yCKM\k1X6EGxl Bv\LaAhKrCghUD\YngJo6Fh1yiLG\nCOmhB8bbaYYPgWgk9U0.mp4.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ZY3d5kjr6yCKM\oMsKNz9K RN4O-AaGdJ\M 0Q6Cm19opOon\0 _DWsu4DwDzVQa8B\4h7F7bzG.mp4.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ZY3d5kjr6yCKM\oMsKNz9K RN4O-AaGdJ\M 0Q6Cm19opOon\0 _DWsu4DwDzVQa8B\Iq7VnburEIM4CUJ2Z8m.avi.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ZY3d5kjr6yCKM\oMsKNz9K RN4O-AaGdJ\M 0Q6Cm19opOon\0 _DWsu4DwDzVQa8B\PP9bxiOz2u3y4mg9.mp4.Nibiru | Dropped File | Stream |
Unknown
|
...
|
»
C:\ProgramData\Microsoft\User Account Pictures\user-48.png.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft\User Account Pictures\guest.png.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\maYlM ezhoK-9nQl.jpg.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\PdEI2yFL.png.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\rFJNXz.png.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\st72Ws_uEvRS9VzLW.mp3.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\t8AgPneQOd_p8r.xlsx.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\x1q_.png.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\amd64\hwcompat.txt.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\i386\hwexclude.txt.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\ux\GetStarted.png.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\ux\lock.png.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\7JVPEgR7OVbAXWXyw0.ppt.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\bMJzJpG _pNTvSb0.mp3.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\dBM3nEmmlUWXL6Q.mp4.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\J Q3JAum8O47yEzgKAa.mp4.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\qZtYwmadExsdwhJt.mp4.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\SuTwF-zk1XRBCH.png.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\rMTvOUlU85C_F4jy\3mzN.png.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\ddEgmOTySXncH6_kjf\S2ndiqUhn0JLqxZ5E0Qe.wav.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\mcqecqinIbnBgL6rE4YX\aa j_v6dxzEefXM2LVYh.wav.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\Xnips t7nwsSCx8psK\4qNfmG0e27pB6.wav.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft\Windows Defender\Network Inspection System\Support\NisLog.txt.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\2Gvh-g9ICB 9OB.mp3.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\CyYrqj5p.wav.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\gbfQjdpAeqR8wJX6gqj.jpg.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\H47gqkCR3suk-kB.mp4.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\jRANMLzflGl2yJD.avi.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\k8ERPneNbhU- _rKcn5.wav.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\PndTEpjk5ELi.ppt.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\SdlpiWa.wav.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\X1cnR7W-9Qs_m.wav.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\mcqecqinIbnBgL6rE4YX\cdxU2SZXH\cdgcmbVJw6ymQmPJ.wav.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\mcqecqinIbnBgL6rE4YX\qZxxJqcGGZZSyU2FUC-\fJvs3zsdkI66UTI00MS0.mp3.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\PJ4fBt\UPN1mAVjAHOPCUfnYAM0\NZOVIZSW.mp3.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\ZY3d5kjr6yCKM\k1X6EGxl Bv\B6UK060n8A9ty9.mp4.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\ZY3d5kjr6yCKM\k1X6EGxl Bv\IwdsamWHSAIaS.avi.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\Microsoft\Device Stage\Device\{113527a4-45d4-4b6f-b567-97838f1b04b0}\superbar.png.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\iccuIF4V8Xa\BT_tZi\_XlRoz8U-Uhyf\jl2MHQsD1jvEoV.ppt.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\PJ4fBt\UPN1mAVjAHOPCUfnYAM0\l5A62CzzO2fy\49TIlrv.wav.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7294.0108\AppErrorWhite.png.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\Error.png.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\ErrorPage.html.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_1\Warning.png.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\ZY3d5kjr6yCKM\k1X6EGxl Bv\LaAhKrCghUD\YngJo6Fh1yiLG\OQq92pAos_L7Rq.avi.Nibiru | Dropped File | Stream |
Not Queried
|
...
|
»