VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Dropper
Backdoor
|
Threat Names: |
Gen:Trojan.Heur.2T0@rmnKOxoi
|
Cheats_Loader_protected.exe
Windows Exe (x86-32)
Created at 2020-03-16T08:39:00
Remarks
(0x0200000C): The maximum memory dump size was exceeded. Some dumps may be missing in the report.
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\Cheats_Loader_protected.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x785c44 |
Size Of Code | 0x1c00 |
Size Of Initialized Data | 0x1400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2083-06-12 10:11:37+00:00 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
- | 0x402000 | 0x2000 | 0x1200 | 0x2000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.81 |
- | 0x404000 | 0x2000 | 0x200 | 0x3200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.12 |
- | 0x406000 | 0x2000 | 0x200 | 0x3400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.31 |
.rsrc | 0x408000 | 0x2000 | 0xe00 | 0x3600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.26 |
- | 0x40a000 | 0x292000 | 0x2e800 | 0x4400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 8.0 |
.data | 0x69c000 | 0xec000 | 0xeb200 | 0x32c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.97 |
Imports (8)
»
kernel32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetModuleHandleA | 0x0 | 0x69f0d4 | 0x29f0d4 | 0x35cd4 | 0x0 |
GetProcAddress | 0x0 | 0x69f0d8 | 0x29f0d8 | 0x35cd8 | 0x0 |
ExitProcess | 0x0 | 0x69f0dc | 0x29f0dc | 0x35cdc | 0x0 |
LoadLibraryA | 0x0 | 0x69f0e0 | 0x29f0e0 | 0x35ce0 | 0x0 |
user32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
MessageBoxA | 0x0 | 0x69f0e8 | 0x29f0e8 | 0x35ce8 | 0x0 |
advapi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegCloseKey | 0x0 | 0x69f0f0 | 0x29f0f0 | 0x35cf0 | 0x0 |
oleaut32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysFreeString | 0x0 | 0x69f0f8 | 0x29f0f8 | 0x35cf8 | 0x0 |
gdi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateFontA | 0x0 | 0x69f100 | 0x29f100 | 0x35d00 | 0x0 |
shell32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteA | 0x0 | 0x69f108 | 0x29f108 | 0x35d08 | 0x0 |
version.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetFileVersionInfoA | 0x0 | 0x69f110 | 0x29f110 | 0x35d10 | 0x0 |
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x69f118 | 0x29f118 | 0x35d18 | 0x0 |
Memory Dumps (30)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | First Execution |
![]() |
32-bit | 0x00E15C44 |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00C190BC |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00C1831C |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00BBF550 |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00A9B2A4 |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00A9E39C |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00AA8E18 |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00AF63EC |
![]() |
![]() |
...
|
buffer | 1 | 0x00910000 | 0x00910FFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00AFA554 |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00B01810 |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00AFF16C |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00AA5004 |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00B0C150 |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00B1B194 |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00B2ED04 |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00B308DC |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00B2B19C |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00B27974 |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00B2C310 |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00B2DE2C |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00B3CA5C |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00B52884 |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00AA3C94 |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00AC7208 |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00B55908 |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00B573D4 |
![]() |
![]() |
...
|
buffer | 1 | 0x00A10000 | 0x00A10FFF | Content Changed |
![]() |
32-bit | - |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00B73988 |
![]() |
![]() |
...
|
cheats_loader_protected.exe | 1 | 0x00A90000 | 0x00E17FFF | Content Changed |
![]() |
32-bit | 0x00B7A2DC |
![]() |
![]() |
...
|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x59658c |
Size Of Code | 0x19ba00 |
Size Of Initialized Data | 0x3d800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-03-16 06:19:29+00:00 |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | Host Process for Windows Services |
FileVersion | 6.3.9600.17487 |
InternalName | svchost.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | svchost.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 6.3.9600.17415 |
Sections (11)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x193030 | 0x193200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.37 |
.itext | 0x595000 | 0x876c | 0x8800 | 0x193600 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.17 |
.data | 0x59e000 | 0xaf30 | 0xb000 | 0x19be00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.34 |
.bss | 0x5a9000 | 0x6b1c | 0x0 | 0x0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.idata | 0x5b0000 | 0x111e | 0x1200 | 0x1a6e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.95 |
.didata | 0x5b2000 | 0x266 | 0x400 | 0x1a8000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.37 |
.edata | 0x5b3000 | 0x99 | 0x200 | 0x1a8400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.91 |
.tls | 0x5b4000 | 0x20 | 0x0 | 0x0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rdata | 0x5b5000 | 0x5d | 0x200 | 0x1a8600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 1.37 |
.reloc | 0x5b6000 | 0x26654 | 0x26800 | 0x1a8800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.71 |
.rsrc | 0x5dd000 | 0xa600 | 0xa600 | 0x1cf000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.73 |
Imports (7)
»
kernel32.dll (112)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetFileType | 0x0 | 0x5b0330 | 0x1b00a0 | 0x1a6ea0 | 0x0 |
GetACP | 0x0 | 0x5b0334 | 0x1b00a4 | 0x1a6ea4 | 0x0 |
CloseHandle | 0x0 | 0x5b0338 | 0x1b00a8 | 0x1a6ea8 | 0x0 |
LocalFree | 0x0 | 0x5b033c | 0x1b00ac | 0x1a6eac | 0x0 |
GetSystemDefaultLangID | 0x0 | 0x5b0340 | 0x1b00b0 | 0x1a6eb0 | 0x0 |
VirtualProtect | 0x0 | 0x5b0344 | 0x1b00b4 | 0x1a6eb4 | 0x0 |
QueryPerformanceFrequency | 0x0 | 0x5b0348 | 0x1b00b8 | 0x1a6eb8 | 0x0 |
IsDebuggerPresent | 0x0 | 0x5b034c | 0x1b00bc | 0x1a6ebc | 0x0 |
FindNextFileW | 0x0 | 0x5b0350 | 0x1b00c0 | 0x1a6ec0 | 0x0 |
VirtualFree | 0x0 | 0x5b0354 | 0x1b00c4 | 0x1a6ec4 | 0x0 |
GetFullPathNameW | 0x0 | 0x5b0358 | 0x1b00c8 | 0x1a6ec8 | 0x0 |
ExitProcess | 0x0 | 0x5b035c | 0x1b00cc | 0x1a6ecc | 0x0 |
HeapAlloc | 0x0 | 0x5b0360 | 0x1b00d0 | 0x1a6ed0 | 0x0 |
GetCPInfoExW | 0x0 | 0x5b0364 | 0x1b00d4 | 0x1a6ed4 | 0x0 |
GetSystemTime | 0x0 | 0x5b0368 | 0x1b00d8 | 0x1a6ed8 | 0x0 |
RtlUnwind | 0x0 | 0x5b036c | 0x1b00dc | 0x1a6edc | 0x0 |
GetCPInfo | 0x0 | 0x5b0370 | 0x1b00e0 | 0x1a6ee0 | 0x0 |
EnumSystemLocalesW | 0x0 | 0x5b0374 | 0x1b00e4 | 0x1a6ee4 | 0x0 |
GetStdHandle | 0x0 | 0x5b0378 | 0x1b00e8 | 0x1a6ee8 | 0x0 |
GetTimeZoneInformation | 0x0 | 0x5b037c | 0x1b00ec | 0x1a6eec | 0x0 |
FileTimeToLocalFileTime | 0x0 | 0x5b0380 | 0x1b00f0 | 0x1a6ef0 | 0x0 |
GetModuleHandleW | 0x0 | 0x5b0384 | 0x1b00f4 | 0x1a6ef4 | 0x0 |
FreeLibrary | 0x0 | 0x5b0388 | 0x1b00f8 | 0x1a6ef8 | 0x0 |
TryEnterCriticalSection | 0x0 | 0x5b038c | 0x1b00fc | 0x1a6efc | 0x0 |
HeapDestroy | 0x0 | 0x5b0390 | 0x1b0100 | 0x1a6f00 | 0x0 |
FileTimeToDosDateTime | 0x0 | 0x5b0394 | 0x1b0104 | 0x1a6f04 | 0x0 |
ReadFile | 0x0 | 0x5b0398 | 0x1b0108 | 0x1a6f08 | 0x0 |
HeapSize | 0x0 | 0x5b039c | 0x1b010c | 0x1a6f0c | 0x0 |
GetLastError | 0x0 | 0x5b03a0 | 0x1b0110 | 0x1a6f10 | 0x0 |
GetModuleFileNameW | 0x0 | 0x5b03a4 | 0x1b0114 | 0x1a6f14 | 0x0 |
SetLastError | 0x0 | 0x5b03a8 | 0x1b0118 | 0x1a6f18 | 0x0 |
CreateThread | 0x0 | 0x5b03ac | 0x1b011c | 0x1a6f1c | 0x0 |
CompareStringW | 0x0 | 0x5b03b0 | 0x1b0120 | 0x1a6f20 | 0x0 |
CreateMutexW | 0x0 | 0x5b03b4 | 0x1b0124 | 0x1a6f24 | 0x0 |
LoadLibraryA | 0x0 | 0x5b03b8 | 0x1b0128 | 0x1a6f28 | 0x0 |
ResetEvent | 0x0 | 0x5b03bc | 0x1b012c | 0x1a6f2c | 0x0 |
GetVersion | 0x0 | 0x5b03c0 | 0x1b0130 | 0x1a6f30 | 0x0 |
RaiseException | 0x0 | 0x5b03c4 | 0x1b0134 | 0x1a6f34 | 0x0 |
MoveFileW | 0x0 | 0x5b03c8 | 0x1b0138 | 0x1a6f38 | 0x0 |
FormatMessageW | 0x0 | 0x5b03cc | 0x1b013c | 0x1a6f3c | 0x0 |
SwitchToThread | 0x0 | 0x5b03d0 | 0x1b0140 | 0x1a6f40 | 0x0 |
GetExitCodeThread | 0x0 | 0x5b03d4 | 0x1b0144 | 0x1a6f44 | 0x0 |
GetCurrentThread | 0x0 | 0x5b03d8 | 0x1b0148 | 0x1a6f48 | 0x0 |
GetFileAttributesExW | 0x0 | 0x5b03dc | 0x1b014c | 0x1a6f4c | 0x0 |
LoadLibraryExW | 0x0 | 0x5b03e0 | 0x1b0150 | 0x1a6f50 | 0x0 |
GetCurrentThreadId | 0x0 | 0x5b03e4 | 0x1b0154 | 0x1a6f54 | 0x0 |
UnhandledExceptionFilter | 0x0 | 0x5b03e8 | 0x1b0158 | 0x1a6f58 | 0x0 |
VirtualQuery | 0x0 | 0x5b03ec | 0x1b015c | 0x1a6f5c | 0x0 |
VirtualQueryEx | 0x0 | 0x5b03f0 | 0x1b0160 | 0x1a6f60 | 0x0 |
Sleep | 0x0 | 0x5b03f4 | 0x1b0164 | 0x1a6f64 | 0x0 |
EnterCriticalSection | 0x0 | 0x5b03f8 | 0x1b0168 | 0x1a6f68 | 0x0 |
SetFilePointer | 0x0 | 0x5b03fc | 0x1b016c | 0x1a6f6c | 0x0 |
SuspendThread | 0x0 | 0x5b0400 | 0x1b0170 | 0x1a6f70 | 0x0 |
GetTickCount | 0x0 | 0x5b0404 | 0x1b0174 | 0x1a6f74 | 0x0 |
GetFileSize | 0x0 | 0x5b0408 | 0x1b0178 | 0x1a6f78 | 0x0 |
GetStartupInfoW | 0x0 | 0x5b040c | 0x1b017c | 0x1a6f7c | 0x0 |
GetFileAttributesW | 0x0 | 0x5b0410 | 0x1b0180 | 0x1a6f80 | 0x0 |
InitializeCriticalSection | 0x0 | 0x5b0414 | 0x1b0184 | 0x1a6f84 | 0x0 |
VerLanguageNameW | 0x0 | 0x5b0418 | 0x1b0188 | 0x1a6f88 | 0x0 |
GetThreadPriority | 0x0 | 0x5b041c | 0x1b018c | 0x1a6f8c | 0x0 |
GetCurrentProcess | 0x0 | 0x5b0420 | 0x1b0190 | 0x1a6f90 | 0x0 |
SetThreadPriority | 0x0 | 0x5b0424 | 0x1b0194 | 0x1a6f94 | 0x0 |
VirtualAlloc | 0x0 | 0x5b0428 | 0x1b0198 | 0x1a6f98 | 0x0 |
GetCommandLineW | 0x0 | 0x5b042c | 0x1b019c | 0x1a6f9c | 0x0 |
GetSystemInfo | 0x0 | 0x5b0430 | 0x1b01a0 | 0x1a6fa0 | 0x0 |
GetTempPathW | 0x0 | 0x5b0434 | 0x1b01a4 | 0x1a6fa4 | 0x0 |
LeaveCriticalSection | 0x0 | 0x5b0438 | 0x1b01a8 | 0x1a6fa8 | 0x0 |
GetProcAddress | 0x0 | 0x5b043c | 0x1b01ac | 0x1a6fac | 0x0 |
ResumeThread | 0x0 | 0x5b0440 | 0x1b01b0 | 0x1a6fb0 | 0x0 |
GetVersionExW | 0x0 | 0x5b0444 | 0x1b01b4 | 0x1a6fb4 | 0x0 |
VerifyVersionInfoW | 0x0 | 0x5b0448 | 0x1b01b8 | 0x1a6fb8 | 0x0 |
HeapCreate | 0x0 | 0x5b044c | 0x1b01bc | 0x1a6fbc | 0x0 |
VerSetConditionMask | 0x0 | 0x5b0450 | 0x1b01c0 | 0x1a6fc0 | 0x0 |
GetDiskFreeSpaceW | 0x0 | 0x5b0454 | 0x1b01c4 | 0x1a6fc4 | 0x0 |
FindFirstFileW | 0x0 | 0x5b0458 | 0x1b01c8 | 0x1a6fc8 | 0x0 |
GetUserDefaultUILanguage | 0x0 | 0x5b045c | 0x1b01cc | 0x1a6fcc | 0x0 |
GetConsoleOutputCP | 0x0 | 0x5b0460 | 0x1b01d0 | 0x1a6fd0 | 0x0 |
GetConsoleCP | 0x0 | 0x5b0464 | 0x1b01d4 | 0x1a6fd4 | 0x0 |
lstrlenW | 0x0 | 0x5b0468 | 0x1b01d8 | 0x1a6fd8 | 0x0 |
SetEndOfFile | 0x0 | 0x5b046c | 0x1b01dc | 0x1a6fdc | 0x0 |
QueryPerformanceCounter | 0x0 | 0x5b0470 | 0x1b01e0 | 0x1a6fe0 | 0x0 |
HeapFree | 0x0 | 0x5b0474 | 0x1b01e4 | 0x1a6fe4 | 0x0 |
WideCharToMultiByte | 0x0 | 0x5b0478 | 0x1b01e8 | 0x1a6fe8 | 0x0 |
FindClose | 0x0 | 0x5b047c | 0x1b01ec | 0x1a6fec | 0x0 |
MultiByteToWideChar | 0x0 | 0x5b0480 | 0x1b01f0 | 0x1a6ff0 | 0x0 |
LoadLibraryW | 0x0 | 0x5b0484 | 0x1b01f4 | 0x1a6ff4 | 0x0 |
SetEvent | 0x0 | 0x5b0488 | 0x1b01f8 | 0x1a6ff8 | 0x0 |
GetLocaleInfoW | 0x0 | 0x5b048c | 0x1b01fc | 0x1a6ffc | 0x0 |
CreateFileW | 0x0 | 0x5b0490 | 0x1b0200 | 0x1a7000 | 0x0 |
DeleteFileW | 0x0 | 0x5b0494 | 0x1b0204 | 0x1a7004 | 0x0 |
IsDBCSLeadByteEx | 0x0 | 0x5b0498 | 0x1b0208 | 0x1a7008 | 0x0 |
FreeConsole | 0x0 | 0x5b049c | 0x1b020c | 0x1a700c | 0x0 |
GetLocalTime | 0x0 | 0x5b04a0 | 0x1b0210 | 0x1a7010 | 0x0 |
GetEnvironmentVariableW | 0x0 | 0x5b04a4 | 0x1b0214 | 0x1a7014 | 0x0 |
GetConsoleWindow | 0x0 | 0x5b04a8 | 0x1b0218 | 0x1a7018 | 0x0 |
WaitForSingleObject | 0x0 | 0x5b04ac | 0x1b021c | 0x1a701c | 0x0 |
WriteFile | 0x0 | 0x5b04b0 | 0x1b0220 | 0x1a7020 | 0x0 |
ExitThread | 0x0 | 0x5b04b4 | 0x1b0224 | 0x1a7024 | 0x0 |
DeleteCriticalSection | 0x0 | 0x5b04b8 | 0x1b0228 | 0x1a7028 | 0x0 |
TlsGetValue | 0x0 | 0x5b04bc | 0x1b022c | 0x1a702c | 0x0 |
GetDateFormatW | 0x0 | 0x5b04c0 | 0x1b0230 | 0x1a7030 | 0x0 |
SetErrorMode | 0x0 | 0x5b04c4 | 0x1b0234 | 0x1a7034 | 0x0 |
GetComputerNameW | 0x0 | 0x5b04c8 | 0x1b0238 | 0x1a7038 | 0x0 |
IsValidLocale | 0x0 | 0x5b04cc | 0x1b023c | 0x1a703c | 0x0 |
TlsSetValue | 0x0 | 0x5b04d0 | 0x1b0240 | 0x1a7040 | 0x0 |
GetSystemDefaultUILanguage | 0x0 | 0x5b04d4 | 0x1b0244 | 0x1a7044 | 0x0 |
EnumCalendarInfoW | 0x0 | 0x5b04d8 | 0x1b0248 | 0x1a7048 | 0x0 |
LocalAlloc | 0x0 | 0x5b04dc | 0x1b024c | 0x1a704c | 0x0 |
RemoveDirectoryW | 0x0 | 0x5b04e0 | 0x1b0250 | 0x1a7050 | 0x0 |
CreateEventW | 0x0 | 0x5b04e4 | 0x1b0254 | 0x1a7054 | 0x0 |
SetThreadLocale | 0x0 | 0x5b04e8 | 0x1b0258 | 0x1a7058 | 0x0 |
GetThreadLocale | 0x0 | 0x5b04ec | 0x1b025c | 0x1a705c | 0x0 |
shell32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHGetSpecialFolderPathW | 0x0 | 0x5b04f4 | 0x1b0264 | 0x1a7064 | 0x0 |
ShellExecuteW | 0x0 | 0x5b04f8 | 0x1b0268 | 0x1a7068 | 0x0 |
version.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetFileVersionInfoSizeW | 0x0 | 0x5b0500 | 0x1b0270 | 0x1a7070 | 0x0 |
VerQueryValueW | 0x0 | 0x5b0504 | 0x1b0274 | 0x1a7074 | 0x0 |
GetFileVersionInfoW | 0x0 | 0x5b0508 | 0x1b0278 | 0x1a7078 | 0x0 |
user32.dll (10)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CharUpperBuffW | 0x0 | 0x5b0510 | 0x1b0280 | 0x1a7080 | 0x0 |
CharNextW | 0x0 | 0x5b0514 | 0x1b0284 | 0x1a7084 | 0x0 |
MsgWaitForMultipleObjects | 0x0 | 0x5b0518 | 0x1b0288 | 0x1a7088 | 0x0 |
ShowWindow | 0x0 | 0x5b051c | 0x1b028c | 0x1a708c | 0x0 |
CharLowerBuffW | 0x0 | 0x5b0520 | 0x1b0290 | 0x1a7090 | 0x0 |
LoadStringW | 0x0 | 0x5b0524 | 0x1b0294 | 0x1a7094 | 0x0 |
CharUpperW | 0x0 | 0x5b0528 | 0x1b0298 | 0x1a7098 | 0x0 |
PeekMessageW | 0x0 | 0x5b052c | 0x1b029c | 0x1a709c | 0x0 |
GetSystemMetrics | 0x0 | 0x5b0530 | 0x1b02a0 | 0x1a70a0 | 0x0 |
MessageBoxW | 0x0 | 0x5b0534 | 0x1b02a4 | 0x1a70a4 | 0x0 |
oleaut32.dll (11)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SysAllocStringLen | 0x0 | 0x5b053c | 0x1b02ac | 0x1a70ac | 0x0 |
SafeArrayPtrOfIndex | 0x0 | 0x5b0540 | 0x1b02b0 | 0x1a70b0 | 0x0 |
VariantCopy | 0x0 | 0x5b0544 | 0x1b02b4 | 0x1a70b4 | 0x0 |
SafeArrayGetLBound | 0x0 | 0x5b0548 | 0x1b02b8 | 0x1a70b8 | 0x0 |
SafeArrayGetUBound | 0x0 | 0x5b054c | 0x1b02bc | 0x1a70bc | 0x0 |
VariantInit | 0x0 | 0x5b0550 | 0x1b02c0 | 0x1a70c0 | 0x0 |
VariantClear | 0x0 | 0x5b0554 | 0x1b02c4 | 0x1a70c4 | 0x0 |
SysFreeString | 0x0 | 0x5b0558 | 0x1b02c8 | 0x1a70c8 | 0x0 |
SysReAllocStringLen | 0x0 | 0x5b055c | 0x1b02cc | 0x1a70cc | 0x0 |
VariantChangeType | 0x0 | 0x5b0560 | 0x1b02d0 | 0x1a70d0 | 0x0 |
SafeArrayCreate | 0x0 | 0x5b0564 | 0x1b02d4 | 0x1a70d4 | 0x0 |
netapi32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetWkstaGetInfo | 0x0 | 0x5b056c | 0x1b02dc | 0x1a70dc | 0x0 |
NetApiBufferFree | 0x0 | 0x5b0570 | 0x1b02e0 | 0x1a70e0 | 0x0 |
advapi32.dll (17)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegSetValueExW | 0x0 | 0x5b0578 | 0x1b02e8 | 0x1a70e8 | 0x0 |
RegConnectRegistryW | 0x0 | 0x5b057c | 0x1b02ec | 0x1a70ec | 0x0 |
RegEnumKeyExW | 0x0 | 0x5b0580 | 0x1b02f0 | 0x1a70f0 | 0x0 |
RegLoadKeyW | 0x0 | 0x5b0584 | 0x1b02f4 | 0x1a70f4 | 0x0 |
RegDeleteKeyW | 0x0 | 0x5b0588 | 0x1b02f8 | 0x1a70f8 | 0x0 |
RegOpenKeyExW | 0x0 | 0x5b058c | 0x1b02fc | 0x1a70fc | 0x0 |
RegQueryInfoKeyW | 0x0 | 0x5b0590 | 0x1b0300 | 0x1a7100 | 0x0 |
RegUnLoadKeyW | 0x0 | 0x5b0594 | 0x1b0304 | 0x1a7104 | 0x0 |
RegSaveKeyW | 0x0 | 0x5b0598 | 0x1b0308 | 0x1a7108 | 0x0 |
RegDeleteValueW | 0x0 | 0x5b059c | 0x1b030c | 0x1a710c | 0x0 |
RegReplaceKeyW | 0x0 | 0x5b05a0 | 0x1b0310 | 0x1a7110 | 0x0 |
RegFlushKey | 0x0 | 0x5b05a4 | 0x1b0314 | 0x1a7114 | 0x0 |
RegQueryValueExW | 0x0 | 0x5b05a8 | 0x1b0318 | 0x1a7118 | 0x0 |
RegEnumValueW | 0x0 | 0x5b05ac | 0x1b031c | 0x1a711c | 0x0 |
RegCloseKey | 0x0 | 0x5b05b0 | 0x1b0320 | 0x1a7120 | 0x0 |
RegCreateKeyExW | 0x0 | 0x5b05b4 | 0x1b0324 | 0x1a7124 | 0x0 |
RegRestoreKeyW | 0x0 | 0x5b05b8 | 0x1b0328 | 0x1a7128 | 0x0 |
Exports (3)
»
Api name | EAT Address | Ordinal |
---|---|---|
TMethodImplementationIntercept | 0x61854 | 0x3 |
__dbk_fcall_wrapper | 0x10ed4 | 0x2 |
dbkFCallWrapperAddr | 0x1ac63c | 0x1 |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Trojan.Heur.2T0@rmnKOxoi |
Malicious
|
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\0VlS.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\1Zion8xjlGTdeA8sDujv.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\28RvPNiENM.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\2ffpB.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\3067xe8riKxNNoH.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\3MH4hI_B2Y4fI4Q-s4O.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\51xMNOj.flv.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\5xR3.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\6E4Yux.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\6ja7hKM dEHm7uKsn.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\7CvyycdQ.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\8MMQ.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\8nrtvJPSXWSOarKar.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\93FAioEJ-r.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\AGpwWiEbNPs_OK mC0E.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\ATjrrwOvtU.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\axVy7fvJB.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\aY06BCEf5o.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\aZ5k5HRyxWcmwTH.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\b79RtRRk9TDjgGdhgjZ.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\cbJumAv3Kocmj1zm.lnk.MZ173801 | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Dfoi.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\di1GF8YsdAcjrR-s.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\dQSfhEFRy_gFg.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\E5xn1.ots.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\EIGtc7lwmfk.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\F yK2LwO.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\fYWa4.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\G5n4vH.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\GuM0xcHUsONHLGItnv.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\H0Fbjn1UaDFSWci6YS.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\H4CXj5T.lnk.MZ173801 | Dropped File | Compressed |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\HPSq.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\hrJq.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\HzRoNmrPEEYbe.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\If9wR_2_gcr9llsoyR.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\ImYAKHvtRzfAlzW.flv.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\I_TP.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\JA9a6Ju2ZS4.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\JRD90ylj1Dg_Ngx4FKM.flv.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\K4Pe6YIq.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\MRdmd02KMM5JtOIVQ.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Music.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\N68wVE30d.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\nPzlQpS1Oj776IOfWV7.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\NVV_UxLtcOyTWBX.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\o0b7l4H.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\oA91dS68Kck7s8GQB.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\OBs8J_Fu4-ilYu.flv.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\ONXmEb1WE6Xl.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\o_sfpnC-AoY-JO.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\p6BEEl6x9.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\peBrvrQ9V.ots.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Pictures.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\PlN2.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Q2PT-p_KEzetPwQd hO2.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\rGR73UL0vv 5tipQ0.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Roaming.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\rUWxi6pNUN.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\s1HnMB.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\sCm_S8YjQxWQT08.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\sNSbJ9-I2i0PpN.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\TrIgUDcr5i55m8wcE.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\twHBtCvhRR2G5.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\txD8odKDry6.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\tXqq.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\uO40eItURrDuO.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\uP0XF1kok-teK_dZt2-3.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\v4vV8.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Vh7qZ.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Videos.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\wk25qq4bwLfkVhGZ.lnk | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\WUbrVo Nrjfu.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\zcoh 1oAdzcJIB.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\zcrVUSJG.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\ZrVO9ZIsn.flv.lnk.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\_HdsGmu6OGd.lnk | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\-116L1WcvYJmv_lb Zj-.bmp.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\8nrtvJPSXWSOarKar.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Ch3abfsCtWfA_.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\HzRoNmrPEEYbe.jpg.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\K4Pe6YIq.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\SFUO7aG.bmp.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\uIWVa_KOKpq1AQ.gif.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\F yK2LwO\3JY_fq-iYjeZZ.bmp.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\F yK2LwO\aY06BCEf5o.gif.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\F yK2LwO\BDibx-.png.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\F yK2LwO\DHkWFe3.jpg.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\F yK2LwO\eT6BMD39LltKR7xUw6.jpg.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\F yK2LwO\fwT7xBA.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\F yK2LwO\s1HnMB.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\F yK2LwO\zY_vL.gif.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\5luLU8SfxcLf3.mp3.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\EtLEEKM-JP9vt.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\hhHYj9Pnudi.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\5xR3\Q2PT-p_KEzetPwQd hO2.wav.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\Q005Y62fvMbMZrM r-4F.wav.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\1Zion8xjlGTdeA8sDujv\AGpwWiEbNPs_OK mC0E.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\1Zion8xjlGTdeA8sDujv\b79RtRRk9TDjgGdhgjZ.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\1Zion8xjlGTdeA8sDujv\IOVI.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\1Zion8xjlGTdeA8sDujv\rUWxi6pNUN.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\1Zion8xjlGTdeA8sDujv\ATjrrwOvtU\8MMQ.m4a.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\1Zion8xjlGTdeA8sDujv\ATjrrwOvtU\_HdsGmu6OGd.wav.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\1Zion8xjlGTdeA8sDujv\ATjrrwOvtU\Ds2vVA7R\o0b7l4H.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\1Zion8xjlGTdeA8sDujv\uO40eItURrDuO\GuM0xcHUsONHLGItnv.wav.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\1Zion8xjlGTdeA8sDujv\uO40eItURrDuO\C5CIxe6\62UWGU5J91LxoED4.mp3.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\3MH4hI_B2Y4fI4Q-s4O\0L-oxNwdFYy.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\3MH4hI_B2Y4fI4Q-s4O\hMFp.mp3.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\3MH4hI_B2Y4fI4Q-s4O\lFuTB4aA.m4a.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\Axgfxe603muHSLYjsgC.swf.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\OhqnbvOqqEhHEL-.swf.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\di1GF8YsdAcjrR-s\51xMNOj.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\di1GF8YsdAcjrR-s\OPD5PJn.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\di1GF8YsdAcjrR-s\SlAAbHqUUNjskp.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\di1GF8YsdAcjrR-s\NVV_UxLtcOyTWBX\5iO4NXS5B547.mp4.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\di1GF8YsdAcjrR-s\NVV_UxLtcOyTWBX\IIsaB.mkv.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\di1GF8YsdAcjrR-s\NVV_UxLtcOyTWBX\lsT2a0U oQPdx7YbeML.swf.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\di1GF8YsdAcjrR-s\NVV_UxLtcOyTWBX\PSyIQJNrBfmiC-j.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\di1GF8YsdAcjrR-s\NVV_UxLtcOyTWBX\Tdqlc5SA.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\di1GF8YsdAcjrR-s\uP0XF1kok-teK_dZt2-3\ky0-S969NuCh.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\di1GF8YsdAcjrR-s\uP0XF1kok-teK_dZt2-3\zR2L-Z.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\di1GF8YsdAcjrR-s\uP0XF1kok-teK_dZt2-3\ZrVO9ZIsn.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\di1GF8YsdAcjrR-s\uP0XF1kok-teK_dZt2-3\v4vV8\6E4Yux.mp4.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\di1GF8YsdAcjrR-s\uP0XF1kok-teK_dZt2-3\v4vV8\9_dIdXhT.mp4.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\di1GF8YsdAcjrR-s\uP0XF1kok-teK_dZt2-3\v4vV8\G e-i.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\di1GF8YsdAcjrR-s\uP0XF1kok-teK_dZt2-3\v4vV8\XpCaQ.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\di1GF8YsdAcjrR-s\uP0XF1kok-teK_dZt2-3\VmAilK6Ug\7aB-vg.swf.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\di1GF8YsdAcjrR-s\uP0XF1kok-teK_dZt2-3\VmAilK6Ug\mmI1-6XkHu4NPFT8JK.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\di1GF8YsdAcjrR-s\uP0XF1kok-teK_dZt2-3\VmAilK6Ug\pP59u8bd0tGYlQsp.flv.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\_C-ZbiqZ3CWgavc2\JRD90ylj1Dg_Ngx4FKM.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\_C-ZbiqZ3CWgavc2\OBs8J_Fu4-ilYu.flv.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\14yXf75kP-7umnG 4Xe.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\1wztFJUX4Pd41Ftwf.xlsx.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\28RvPNiENM.xlsx.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\4DBo0atmEpeC-LN5J.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\bJ9_Ah.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Database1.accdb.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\jkAe9XaDuAt8yrlc.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\oY9NI6W.xlsx.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\vyqzJRG.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Fhb23ambk-o\0A6m BP4.rtf.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Fhb23ambk-o\9JNTT48UjoH.pps.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Fhb23ambk-o\KL4cEqDQZvlWYISl9.docx.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Fhb23ambk-o\MRdmd02KMM5JtOIVQ.docx.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Fhb23ambk-o\r_vOYVV008qvPgkFp.pps | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Fhb23ambk-o\T1F3rLNHQkV.pps | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Fhb23ambk-o\dQSfhEFRy_gFg\1d9fEi.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Fhb23ambk-o\dQSfhEFRy_gFg\dMoow7sypidEXF.ppt.MZ173801 | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Fhb23ambk-o\dQSfhEFRy_gFg\maQtnjtEPvgXKVh_.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows\System32\drivers\etc\host | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\2n q.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\4DBo0atmEpeC-LN5J.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\5iO4NXS5B547.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\6o05.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\7L1WKCQLeheP.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\a TQSWLwdnXwLBG6xlM.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\a_IiCl.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\BXHxcreN0NZMlQbLh4Mv.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\CSedB5fZ.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Ds2vVA7R.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\eiwjZXFfC09j.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\EtLEEKM-JP9vt.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Fhb23ambk-o.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Fnu1ZEKDFkx.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\g2GKlHNibJE_MvHnw.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\hEI_tuSWJhfHIz05Nj8z.flv.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\IZVvQMMfV6LuTAy.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\JHYEYVRjOm0-o3XP-xL.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\jt9dNiGSkN.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\KL4cEqDQZvlWYISl9.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\ky0-S969NuCh.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\MkfvC5YVoY.lnk | Modified File | Audio |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\mmI1-6XkHu4NPFT8JK.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\nZr6PHEvCUKrD5BUDBLc.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\PuYC77t.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\qeFEt94 ZkESq80bTrZv.ots.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\qMCV4VrTY-vx5.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\QWOw3VER.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\rAI6kR Z24Gt07MNyb.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\RHvCNbn.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\RLrwCvmuE.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\SFUO7aG.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\sHCpH11jen-XYoy Od_.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\suu6d.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\T1F3rLNHQkV.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\T4uSfA p9yNIyW.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Tdqlc5SA.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\torEQ-P8Pc0pag.flv.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\VmAilK6Ug.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\WjAE.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\x-fqzeifd646TQM_WO.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\XbxN-s5VyE.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\XDnTXxKBW.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\XO1z23.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\Yv-akVjSVB.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\ZB jpmR.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\zvmVe w.lnk | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\zY_vL.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\_5 PohF4cOl3RenyNkzK.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Recent\_C-ZbiqZ3CWgavc2.lnk.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\2n q.bmp.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\7L1WKCQLeheP.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\Bsuy48bD0S.png.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\EIGtc7lwmfk.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\oA91dS68Kck7s8GQB.gif.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\P9y3n H.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\QWOw3VER.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\rx3V.png.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\uoWC-.jpg.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\F yK2LwO\2ffpB.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\F yK2LwO\BXHxcreN0NZMlQbLh4Mv.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\F yK2LwO\cPoUOQ7FRc3tfk.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\F yK2LwO\dzGys1Cl.jpg.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\F yK2LwO\IZVvQMMfV6LuTAy.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\F yK2LwO\jt9dNiGSkN.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\F yK2LwO\XbxN-s5VyE.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\F yK2LwO\XO1z23.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\6o05.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\5xR3\wk25qq4bwLfkVhGZ.m4a.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\5xR3\WZY4fY8_E--mGLKS21.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\CovaDgRA8.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\dBFbFeABajg.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\1Zion8xjlGTdeA8sDujv\0VlS.mp3.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\1Zion8xjlGTdeA8sDujv\ATjrrwOvtU\CVDQqBTbc3T7O.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\1Zion8xjlGTdeA8sDujv\ATjrrwOvtU\LWQBu.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\1Zion8xjlGTdeA8sDujv\ATjrrwOvtU\o87Ff8jxDauutKhIzSH.m4a.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\1Zion8xjlGTdeA8sDujv\ATjrrwOvtU\Ds2vVA7R\H0Fbjn1UaDFSWci6YS.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\1Zion8xjlGTdeA8sDujv\ATjrrwOvtU\Ds2vVA7R\W5nBFs1pwVaw l7.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\3MH4hI_B2Y4fI4Q-s4O\0ANPHQ2sWdNCoQ54jO.m4a.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\3MH4hI_B2Y4fI4Q-s4O\0Ctn.m4a.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\3MH4hI_B2Y4fI4Q-s4O\cbJumAv3Kocmj1zm.m4a.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\stszJlZAZD-p\3MH4hI_B2Y4fI4Q-s4O\rAI6kR Z24Gt07MNyb.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\4AH f2Bl8-ulR2EqiiLE.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\nPzlQpS1Oj776IOfWV7.mp4.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\PuYC77t.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\RW17m0.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\di1GF8YsdAcjrR-s\JKmlrtcd1CFx0.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\di1GF8YsdAcjrR-s\p6BEEl6x9.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\di1GF8YsdAcjrR-s\NVV_UxLtcOyTWBX\AGPyvogzOcyci-XJyAn.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\di1GF8YsdAcjrR-s\uP0XF1kok-teK_dZt2-3\f_4h9eckCbvZmLv.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\di1GF8YsdAcjrR-s\uP0XF1kok-teK_dZt2-3\VmAilK6Ug\i C0t9ivIXYO.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\suu6d\9XOvT j3.flv.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\suu6d\torEQ-P8Pc0pag.flv.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\suu6d\twHBtCvhRR2G5.mkv.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\_C-ZbiqZ3CWgavc2\o9cam2.swf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\a TQSWLwdnXwLBG6xlM.pps.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Fnu1ZEKDFkx.docx.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\IQVV x.doc | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\I_TP.docx.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\mXllPiyuRFE.pptx.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\s89GGesFpGwDjBj.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\ScaMQESaGJDS.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\vTIt-8amnULMnTybMLk.pptx.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\zypeBTOwi7wsX-d.xlsx.MZ173801 | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Fhb23ambk-o\pcZF9GerhzqY0.xls | Modified File | Stream |
Not Queried
|
...
|
»
C:\ProgramData\TVpSSUQ5NkE4OTZFMzJFX19UYXJpaCgxNiBNYXJ0IDIwMjAgUGF6YXJ0ZXNpKV9fU2FhdCgxMS00MC01OSk= | Dropped File | Text |
Not Queried
|
...
|
»