VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Gen:Heur.Trickbot.3
Mal/Generic-S
|
spt.exe
Windows Exe (x86-32)
Created at 2020-06-15T11:12:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\spt.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x40264b |
Size Of Code | 0x1800 |
Size Of Initialized Data | 0x1600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-06-11 17:27:29+00:00 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1735 | 0x1800 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.25 |
.rdata | 0x403000 | 0x1356 | 0x1400 | 0x1c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.18 |
.data | 0x405000 | 0x1c | 0x200 | 0x3000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.27 |
Imports (1)
»
KERNEL32.dll (26)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ExitProcess | 0x0 | 0x403000 | 0x410c | 0x2d0c | 0x119 |
FindFirstFileW | 0x0 | 0x403004 | 0x4110 | 0x2d10 | 0x139 |
HeapAlloc | 0x0 | 0x403008 | 0x4114 | 0x2d14 | 0x2cb |
SetFilePointerEx | 0x0 | 0x40300c | 0x4118 | 0x2d18 | 0x467 |
HeapFree | 0x0 | 0x403010 | 0x411c | 0x2d1c | 0x2cf |
WaitForSingleObject | 0x0 | 0x403014 | 0x4120 | 0x2d20 | 0x4f9 |
GetLogicalDrives | 0x0 | 0x403018 | 0x4124 | 0x2d24 | 0x209 |
GetProcessHeap | 0x0 | 0x40301c | 0x4128 | 0x2d28 | 0x24a |
WriteFile | 0x0 | 0x403020 | 0x412c | 0x2d2c | 0x525 |
ReadFile | 0x0 | 0x403024 | 0x4130 | 0x2d30 | 0x3c0 |
CreateFileW | 0x0 | 0x403028 | 0x4134 | 0x2d34 | 0x8f |
GetFileSizeEx | 0x0 | 0x40302c | 0x4138 | 0x2d38 | 0x1f1 |
GetLastError | 0x0 | 0x403030 | 0x413c | 0x2d3c | 0x202 |
SetLastError | 0x0 | 0x403034 | 0x4140 | 0x2d40 | 0x473 |
MoveFileW | 0x0 | 0x403038 | 0x4144 | 0x2d44 | 0x363 |
FindClose | 0x0 | 0x40303c | 0x4148 | 0x2d48 | 0x12e |
lstrcmpiW | 0x0 | 0x403040 | 0x414c | 0x2d4c | 0x545 |
lstrcatW | 0x0 | 0x403044 | 0x4150 | 0x2d50 | 0x53f |
FindNextFileW | 0x0 | 0x403048 | 0x4154 | 0x2d54 | 0x145 |
CloseHandle | 0x0 | 0x40304c | 0x4158 | 0x2d58 | 0x52 |
lstrcpyW | 0x0 | 0x403050 | 0x415c | 0x2d5c | 0x548 |
GetFileAttributesW | 0x0 | 0x403054 | 0x4160 | 0x2d60 | 0x1ea |
GetTempPathW | 0x0 | 0x403058 | 0x4164 | 0x2d64 | 0x285 |
lstrcmpiA | 0x0 | 0x40305c | 0x4168 | 0x2d68 | 0x544 |
CreateMutexA | 0x0 | 0x403060 | 0x416c | 0x2d6c | 0x9b |
GetCommandLineW | 0x0 | 0x403064 | 0x4170 | 0x2d70 | 0x187 |
Digital Signatures (2)
»
Certificate: DUALL SP Z O O
»
Issued by | DUALL SP Z O O |
Parent Certificate | Sectigo RSA Code Signing CA |
Country Name | PL |
Valid From | 2020-06-11 00:00:00+00:00 |
Valid Until | 2021-06-11 23:59:59+00:00 |
Algorithm | sha256_rsa |
Serial Number | C8 D4 D4 E1 83 18 28 84 86 E1 B1 FD FB C8 6F C9 |
Thumbprint | 43 24 52 0D 76 24 04 AE 28 9C 0D D4 3B 6E C2 0A 03 F0 A3 C7 |
Certificate: Sectigo RSA Code Signing CA
»
Issued by | Sectigo RSA Code Signing CA |
Country Name | GB |
Valid From | 2018-11-02 00:00:00+00:00 |
Valid Until | 2030-12-31 23:59:59+00:00 |
Algorithm | sha384_rsa |
Serial Number | 1D A2 48 30 6F 9B 26 18 D0 82 E0 96 7D 33 D3 6A |
Thumbprint | 94 C9 5D A1 E8 50 BD 85 20 9A 4A 2A F3 E1 FB 16 04 F9 BB 66 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
spt.exe | 1 | 0x00400000 | 0x00405FFF | Relevant Image |
![]() |
32-bit | 0x00401DF8 |
![]() |
![]() |
...
|
spt.exe | 1 | 0x00400000 | 0x00405FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Trickbot.3 |
Malicious
|
C:/MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\branding.xml.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Microsoft.VC90.CRT.manifest.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\pss10r.chm | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\setup.chm | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\ShellUI.MST.TELEGRAM | Dropped File | Binary |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\branding.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.xml.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.xml.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPlusrWW.xml.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjProrWW.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.xml | Modified File | Stream |
Unknown
|
...
|
»
C:/Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\boot.sdi | Modified File | Stream |
Unknown
|
...
|
»
C:/Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\Winre.wim.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\5F4Dq.mkv.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\9xnpcC8K.gif | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\Dp2m6FiweVpr5xYOI.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\fVulp2Pjfsxy\AUT60Qmj3R.m4a.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\fVulp2Pjfsxy\TQbOws7j.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\fVulp2Pjfsxy\W_u9jHH3yPsHh.wav | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\g v6Ri2Npm_A6dLQDdX.avi.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\gx3dWUG.xls.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\iMUy.flv | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\J9 fzr.ppt.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\KCKktH.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\kkFdIA1_.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\oHm3.flv | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\S3ulOgWBKhg09iq_yfWU.png | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\SCtgUd5Z.flv.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\SUkpMQnAgEU\CQ2EdonPG\30_xfXmDZEWSy2.odt.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\SUkpMQnAgEU\CQ2EdonPG\BK2hRki.xlsx.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\SUkpMQnAgEU\CQ2EdonPG\rgL6S.m4a.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\SUkpMQnAgEU\CQ2EdonPG\XL5bK-C0.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\SUkpMQnAgEU\dzU_B7gLXYsc2RT.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\SUkpMQnAgEU\o7JfeQT5JSBf8x3.ods | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\SUkpMQnAgEU\RdnPCCd4.pps.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\SUkpMQnAgEU\S-Xuw03Pk7Pe4Xk.wav.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\SUkpMQnAgEU\zpO5d.jpg.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\uJbJK6wNDaam7AXwm.jpg.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\WZNbj8.wav.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\XILnOXNOX6VEvBZWR.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\Yqvqz1.pdf.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\9vKt4.docx | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\aD8fBXwSoqoQ.pptx.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\aLQwKz53mb.docx.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\BDmKr_aL.xlsx.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\CkE8J9y6.pps | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\eACB-FON_lTcUMeL1XV.docx.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\Glt9ez4XeSNgeYl5dR_-.docx.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\J86a\-oBiSZYOb\cEd5.odt | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\J86a\0n8We2y79LcDA7O-tT1.pptx.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\J86a\THyl03KNXl1Sg2Udy\_3eA.odp.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\KVOE7IZQuM4mIF.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\Favorites.vss.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\nY42\e1VD_0aP86.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\OnvQuYllBRUu1\AizQUusDtR9dMSB6Dw\7tWUSL8v\082EzT J.doc.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\OnvQuYllBRUu1\AizQUusDtR9dMSB6Dw\7tWUSL8v\0CO FxVbEz.odp.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\OnvQuYllBRUu1\AizQUusDtR9dMSB6Dw\7tWUSL8v\5Zr2.ppt.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\OnvQuYllBRUu1\AizQUusDtR9dMSB6Dw\7tWUSL8v\7e0vn6z3DdKnU5B.ods | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\OnvQuYllBRUu1\AizQUusDtR9dMSB6Dw\7tWUSL8v\AqE3LMBvqEcd2DNBM.pptx.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\OnvQuYllBRUu1\AizQUusDtR9dMSB6Dw\7tWUSL8v\I38rYDItMgqm6SH.odp.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\OnvQuYllBRUu1\AizQUusDtR9dMSB6Dw\7tWUSL8v\ieXd\I6RmD\j2hj7_.doc.TELEGRAM | Dropped File | Binary |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\OnvQuYllBRUu1\AizQUusDtR9dMSB6Dw\7tWUSL8v\ieXd\I6RmD\m_6p0J_Y-R1GTI.ods | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\OnvQuYllBRUu1\AizQUusDtR9dMSB6Dw\7tWUSL8v\SvU9e4Z_x_wo1ek1H.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\OnvQuYllBRUu1\AizQUusDtR9dMSB6Dw\ukdOsErUmPKsO.ods | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\OnvQuYllBRUu1\EqWNESL 4KWkKuYE7_vy.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\OnvQuYllBRUu1\ET7_u4u_X p6iZYDf.pdf.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\OnvQuYllBRUu1\HyUGUkbx7kafbal3u0.xls.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\OnvQuYllBRUu1\Lb_KF.odt | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\OnvQuYllBRUu1\PQ0P RNQPtUeSJlyBboj.csv | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\uHwNt6WtypzZwNa.xlsx.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\WmSI Q.pptx.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Links\Desktop.lnk.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Links\Downloads.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Links\RecentPlaces.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\zqss4Z\-6WUBddg49\RXwNXsY2e3ilFFsFdgSS\hXTB.wav | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\zqss4Z\-6WUBddg49\RXwNXsY2e3ilFFsFdgSS\RIz_bBaax-EULGk8I.m4a.TELEGRAM | Dropped File | Compressed |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\zqss4Z\lbFZcECNgg.wav.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\zqss4Z\q6svEAgK_-Aax\04EpilvRtc.m4a.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\zqss4Z\q6svEAgK_-Aax\EX95U_GoA.wav | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\zqss4Z\q6svEAgK_-Aax\L_SBCGn-3YH\6S L-Udw2YqR8dK.wav | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\zqss4Z\q6svEAgK_-Aax\L_SBCGn-3YH\_hjl4USI0LSjWqje.wav.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\zqss4Z\q6svEAgK_-Aax\mVOa09 02D_k.wav | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\zqss4Z\q6svEAgK_-Aax\u_6XTul\acptUPjA0Nu.wav.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\zqss4Z\q6svEAgK_-Aax\u_6XTul\DFLc5N6sClO-RlfNVHG_.wav | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\zqss4Z\q6svEAgK_-Aax\u_6XTul\sHCb-vL5-hzA8FPoU.wav | Modified File | Binary |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\zqss4Z\q6svEAgK_-Aax\WIG7esYQLfA.wav.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\zqss4Z\qkAtZF.m4a.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\-e7u.jpg.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\6ThKFM YHzLcG6WRq.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\DJLzw_g.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\hEFDKpF5hHMStAM3\26q1PVOse.gif.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\hEFDKpF5hHMStAM3\96vCqep66EM_1zy7Tv.gif | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\hEFDKpF5hHMStAM3\b4RuU7tFY7m3G9hE9gG.png | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\hEFDKpF5hHMStAM3\DRnlsQ.png | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\hEFDKpF5hHMStAM3\MlpEv0UXhp dN-.bmp.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\hEFDKpF5hHMStAM3\PRl-XpL.bmp.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\hEFDKpF5hHMStAM3\Qy-m3vVubF2QabiW8.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\hEFDKpF5hHMStAM3\smu3bcAGZI2R5v_.bmp.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\jye-6c5kROHV0VFHT\8 MLlP8fn5.gif | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\jye-6c5kROHV0VFHT\cyuNCj1W.png.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\jye-6c5kROHV0VFHT\d3PGe--JvW4PZ4 YSx.gif | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\jye-6c5kROHV0VFHT\gGUEg_Hr4XBI0.png | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\jye-6c5kROHV0VFHT\HTK0-4tWRep8hd_EXC3.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\jye-6c5kROHV0VFHT\jE763MxR3p.png | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\jye-6c5kROHV0VFHT\lIwzeYXuMmtcy.png | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\jye-6c5kROHV0VFHT\qOnnS0t4.png | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\jye-6c5kROHV0VFHT\RdPTMqaDLNSj_WPtlB.bmp.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\jye-6c5kROHV0VFHT\tMUjeeM86EXVAv4Sb.gif | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\jye-6c5kROHV0VFHT\UHb QjsacTsXX1H.gif | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\jye-6c5kROHV0VFHT\vPoh7Vb.bmp.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\Rjcx6n3.png | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\ySfsq.gif | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\8- C4g.swf.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\arjA18aaWO7FMW6WrbaP.swf.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\CCOM.flv.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\FzRDTQW6.swf | Modified File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\IbQSkDo2NH0uggangZO7.avi.TELEGRAM | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Videos\KiULAe.swf | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\crypto\rsa\s-1-5-21-3388679973-3930757225-3770151564-1000\1d9d98a6ba373446718365650f547166_0303d5b4-ffe9-470e-9dd8-7d9ec416e53f | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.xml.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\pkeyconfig-office.xrm-ms | Modified File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Setup.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Setup.xml.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Office32WW.xml | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\0sMdNHvDGVf6.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\AcPNsU81v2L3OvrX-imO.m4a.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\aidrKarT.pps.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\kobxm24S_UtX7CW.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\SUkpMQnAgEU\CQ2EdonPG\5dxJ.wav.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Desktop\SUkpMQnAgEU\CQ2EdonPG\vAXj4tCSfMUnXyWL.odp | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\28HCPhnWN.pptx.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\brQiTz9TfCeqzyMB.xlsx.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\cPrdAj.pptx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\FZ-RvbHcaw_2VgpK_NO.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\J86a\-W6QRv4.pdf | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\J86a\thId_u.csv | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\J86a\THyl03KNXl1Sg2Udy\0CKOIqANTpcFp8Um.docx.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\Jl -UahwV.pptx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\_private\folder.ico.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\nkBsUJxh_d\8n2o.rtf.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\nY42\oAkhr.csv | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\OnvQuYllBRUu1\0Dlm 7ENRIChE.ods | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\OnvQuYllBRUu1\AizQUusDtR9dMSB6Dw\0_-E5r-U 1DClxr1MBf.pptx | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Documents\VIRH1Lzz.xlsx.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\9T_UubI08.wav.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\tORiblVf.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\zqss4Z\-6WUBddg49\0-d pi2PTmhtL3sw.wav.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\zqss4Z\-6WUBddg49\M OX.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\zqss4Z\-6WUBddg49\RXwNXsY2e3ilFFsFdgSS\YKOm4q7hp_-jdZ6BE.wav.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\zqss4Z\-Cnl.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\zqss4Z\9KdrUgRm.m4a.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\zqss4Z\q6svEAgK_-Aax\cDp8Zbt0.wav.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\zqss4Z\q6svEAgK_-Aax\L_SBCGn-3YH\A 7NlSfaNyAE1g21rZ k.wav.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\zqss4Z\q6svEAgK_-Aax\L_SBCGn-3YH\V4HZ5zXl.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Music\zqss4Z\q6svEAgK_-Aax\pecCb_PcCA.wav.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\jye-6c5kROHV0VFHT\oBWp7PzNAh-piUgvHo.jpg.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/Users\5p5NrGJn0jS HALPmcxz\Pictures\u8JKt 7.jpg.TELEGRAM | Dropped File | Stream |
Not Queried
|
...
|
»
C:/MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\TELEGRAM-RECOVER.txt | Dropped File | Text |
Not Queried
|
...
|
»