VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Dropper
|
Threat Names: |
Gen:Heur.Ransom.Imps.3
Mal/Generic-S
|
cniruj.exe
Windows Exe (x86-32)
Created at 2020-02-10T09:40:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\cniruj.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x450780 |
Size Of Code | 0x3b000 |
Size Of Initialized Data | 0x1000 |
Size Of Uninitialized Data | 0x15000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-02-06 15:51:54+00:00 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
UPX0 | 0x401000 | 0x15000 | 0x0 | 0x400 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
UPX1 | 0x416000 | 0x3b000 | 0x3aa00 | 0x400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.81 |
.rsrc | 0x451000 | 0x1000 | 0x400 | 0x3ae00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.15 |
Imports (3)
»
KERNEL32.DLL (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | 0x0 | 0x45122c | 0x5122c | 0x3b02c | 0x0 |
GetProcAddress | 0x0 | 0x451230 | 0x51230 | 0x3b030 | 0x0 |
VirtualProtect | 0x0 | 0x451234 | 0x51234 | 0x3b034 | 0x0 |
VirtualAlloc | 0x0 | 0x451238 | 0x51238 | 0x3b038 | 0x0 |
VirtualFree | 0x0 | 0x45123c | 0x5123c | 0x3b03c | 0x0 |
ExitProcess | 0x0 | 0x451240 | 0x51240 | 0x3b040 | 0x0 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x451248 | 0x51248 | 0x3b048 | 0x0 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShowWindow | 0x0 | 0x451250 | 0x51250 | 0x3b050 | 0x0 |
Memory Dumps (8)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
cniruj.exe | 1 | 0x01240000 | 0x01291FFF | First Execution |
![]() |
32-bit | 0x01290780 |
![]() |
![]() |
...
|
cniruj.exe | 1 | 0x01240000 | 0x01291FFF | Content Changed |
![]() |
32-bit | 0x012555E3 |
![]() |
![]() |
...
|
cniruj.exe | 1 | 0x01240000 | 0x01291FFF | Content Changed |
![]() |
32-bit | 0x0124BDC1 |
![]() |
![]() |
...
|
cniruj.exe | 1 | 0x01240000 | 0x01291FFF | Content Changed |
![]() |
32-bit | 0x01252BDE |
![]() |
![]() |
...
|
cniruj.exe | 1 | 0x01240000 | 0x01291FFF | Content Changed |
![]() |
32-bit | 0x01256DDB |
![]() |
![]() |
...
|
cniruj.exe | 1 | 0x01240000 | 0x01291FFF | Content Changed |
![]() |
32-bit | 0x012431BB |
![]() |
![]() |
...
|
cniruj.exe | 1 | 0x01240000 | 0x01291FFF | Content Changed |
![]() |
32-bit | 0x0124A08A |
![]() |
![]() |
...
|
cniruj.exe | 1 | 0x01240000 | 0x01291FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
C:/Users/Public/Documents/wonsys.exe | Dropped File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4683c0 |
Size Of Code | 0x29000 |
Size Of Initialized Data | 0x1000 |
Size Of Uninitialized Data | 0x3f000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-02-06 15:50:42+00:00 |
Packer | UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
UPX0 | 0x401000 | 0x3f000 | 0x0 | 0x400 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
UPX1 | 0x440000 | 0x29000 | 0x28800 | 0x400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.92 |
UPX2 | 0x469000 | 0x1000 | 0x200 | 0x28c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.24 |
Imports (4)
»
KERNEL32.DLL (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LoadLibraryA | 0x0 | 0x469064 | 0x69064 | 0x28c64 | 0x0 |
GetProcAddress | 0x0 | 0x469068 | 0x69068 | 0x28c68 | 0x0 |
VirtualProtect | 0x0 | 0x46906c | 0x6906c | 0x28c6c | 0x0 |
VirtualAlloc | 0x0 | 0x469070 | 0x69070 | 0x28c70 | 0x0 |
VirtualFree | 0x0 | 0x469074 | 0x69074 | 0x28c74 | 0x0 |
ExitProcess | 0x0 | 0x469078 | 0x69078 | 0x28c78 | 0x0 |
ADVAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegCloseKey | 0x0 | 0x469080 | 0x69080 | 0x28c80 | 0x0 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShowWindow | 0x0 | 0x469088 | 0x69088 | 0x28c88 | 0x0 |
WININET.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
InternetOpenW | 0x0 | 0x469090 | 0x69090 | 0x28c90 | 0x0 |
Memory Dumps (74)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
wonsys.exe | 2 | 0x00E10000 | 0x00E79FFF | First Execution |
![]() |
32-bit | 0x00E783C0 |
![]() |
![]() |
...
|
wonsys.exe | 2 | 0x00E10000 | 0x00E79FFF | Content Changed |
![]() |
32-bit | 0x00E561B5 |
![]() |
![]() |
...
|
wonsys.exe | 2 | 0x00E10000 | 0x00E79FFF | Content Changed |
![]() |
32-bit | 0x00E4DA60 |
![]() |
![]() |
...
|
wonsys.exe | 2 | 0x00E10000 | 0x00E79FFF | Content Changed |
![]() |
32-bit | 0x00E1DCAA |
![]() |
![]() |
...
|
wonsys.exe | 2 | 0x00E10000 | 0x00E79FFF | Content Changed |
![]() |
32-bit | 0x00E187C9 |
![]() |
![]() |
...
|
wonsys.exe | 2 | 0x00E10000 | 0x00E79FFF | Content Changed |
![]() |
32-bit | 0x00E123D0 |
![]() |
![]() |
...
|
wonsys.exe | 2 | 0x00E10000 | 0x00E79FFF | Content Changed |
![]() |
32-bit | 0x00E1444D |
![]() |
![]() |
...
|
wonsys.exe | 2 | 0x00E10000 | 0x00E79FFF | Content Changed |
![]() |
32-bit | 0x00E515BE |
![]() |
![]() |
...
|
wonsys.exe | 2 | 0x00E10000 | 0x00E79FFF | Content Changed |
![]() |
32-bit | 0x00E46F96 |
![]() |
![]() |
...
|
wonsys.exe | 2 | 0x00E10000 | 0x00E79FFF | Content Changed |
![]() |
32-bit | 0x00E41880 |
![]() |
![]() |
...
|
wonsys.exe | 2 | 0x00E10000 | 0x00E79FFF | Content Changed |
![]() |
32-bit | 0x00E4F3E3 |
![]() |
![]() |
...
|
wonsys.exe | 2 | 0x00E10000 | 0x00E79FFF | Content Changed |
![]() |
32-bit | 0x00E1E000 |
![]() |
![]() |
...
|
wonsys.exe | 2 | 0x00E10000 | 0x00E79FFF | Content Changed |
![]() |
32-bit | 0x00E1C85D |
![]() |
![]() |
...
|
wonsys.exe | 2 | 0x00E10000 | 0x00E79FFF | Content Changed |
![]() |
32-bit | 0x00E4BE64 |
![]() |
![]() |
...
|
wonsys.exe | 2 | 0x00E10000 | 0x00E79FFF | Content Changed |
![]() |
32-bit | 0x00E45050 |
![]() |
![]() |
...
|
wonsys.exe | 2 | 0x00E10000 | 0x00E79FFF | Content Changed |
![]() |
32-bit | 0x00E543E4 |
![]() |
![]() |
...
|
wonsys.exe | 2 | 0x00E10000 | 0x00E79FFF | Content Changed |
![]() |
32-bit | 0x00E517E2 |
![]() |
![]() |
...
|
wonsys.exe | 2 | 0x00E10000 | 0x00E79FFF | Content Changed |
![]() |
32-bit | 0x00E1E10D |
![]() |
![]() |
...
|
wonsys.exe | 2 | 0x00E10000 | 0x00E79FFF | Content Changed |
![]() |
32-bit | 0x00E114B0 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | First Execution |
![]() |
32-bit | 0x012B83C0 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x012961B5 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x0128DA60 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x0125DCAA |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x012587C9 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x012523D0 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x012791DF |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x0125444D |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01278E81 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01296800 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01281880 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01281880 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x0128F3E3 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x0125E000 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x0125C85D |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x0128BE64 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01293FEC |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01285050 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01288B75 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x012514B0 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01285C64 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x0127DEFC |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01282A03 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01288B75 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x012514B0 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x0128583D |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01288B75 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01261A8B |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x012514B0 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01285A81 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01261A8B |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01288B75 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x012514B0 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01282A03 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01293FEC |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x0128583D |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01288B75 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x012514B0 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01282A03 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01293FEC |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01285C64 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01288B75 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x012514B0 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01282A03 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01277046 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x0127DEFC |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01288B75 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x012514B0 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01282A03 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01285A81 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01288B75 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x012514B0 |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Content Changed |
![]() |
32-bit | 0x01282A03 |
![]() |
![]() |
...
|
buffer | 75 | 0x008A0000 | 0x0095EFFF | Image In Buffer |
![]() |
32-bit | - |
![]() |
![]() |
...
|
wonsys.exe | 75 | 0x01250000 | 0x012B9FFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Ransom.Imps.3 |
Malicious
|
File Reputation Information
»
Severity |
Whitelisted
|
C:/Users/5p5NrGJn0jS HALPmcxz/ntuser.ini.bbadc | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/Microsoft/Network/Connections/Pbk/_hiddenPbk/rasphone.pbk.bbadc | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/Microsoft/Office/Recent/Global.LNK.bbadc | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/Microsoft/Outlook/Outlook.xml.bbadc | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/Microsoft/Publisher Building Blocks/ContentStore.xml.bbadc | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/Microsoft/UProof/CUSTOM.DIC.bbadc | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:/Users/5p5NrGJn0jS HALPmcxz/Contacts/Aclviho ASldjfl.contact.bbadc | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:/Users/5p5NrGJn0jS HALPmcxz/Contacts/asdlfk poopvy.contact.bbadc | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:/Users/5p5NrGJn0jS HALPmcxz/Contacts/chucu jadnvk.contact.bbadc | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:/Users/5p5NrGJn0jS HALPmcxz/Contacts/desktop.ini.bbadc | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:/Users/5p5NrGJn0jS HALPmcxz/Contacts/sikvnb huvuib.contact.bbadc | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:/Users/5p5NrGJn0jS HALPmcxz/Desktop/Bu931ZiBJkvXpD0mtmi.mkv.bbadc | Dropped File | Stream |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:/Users/5p5NrGJn0jS HALPmcxz/Desktop/desktop.ini.bbadc | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\history\history.ie5\index.dat | Modified File | Stream |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0016-0409-1000-0000000FF1CE}-C/CLICK_HERE-bbadc.txt | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0016-0409-1000-0000000FF1CE}-C/ExcelMUI.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0016-0409-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0018-0409-1000-0000000FF1CE}-C/PowerPointMUI.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0018-0409-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0019-0409-1000-0000000FF1CE}-C/PublisherMUI.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0019-0409-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-001A-0409-1000-0000000FF1CE}-C/OutlookMUI.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-001A-0409-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-001B-0409-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-001B-0409-1000-0000000FF1CE}-C/WordMUI.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-002C-0409-1000-0000000FF1CE}-C/Proofing.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-002C-0409-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0043-0409-1000-0000000FF1CE}-C/Office32MUI.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0043-0409-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0044-0409-1000-0000000FF1CE}-C/InfoPathMUI.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0044-0409-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0054-0409-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0054-0409-1000-0000000FF1CE}-C/VisioMUI.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-00A1-0409-1000-0000000FF1CE}-C/OneNoteMUI.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-00A1-0409-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-00B4-0409-1000-0000000FF1CE}-C/ProjectMUI.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-00B4-0409-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-00BA-0409-1000-0000000FF1CE}-C/GrooveMUI.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-00BA-0409-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0115-0409-1000-0000000FF1CE}-C/branding.xml.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0115-0409-1000-0000000FF1CE}-C/DW20.EXE.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0115-0409-1000-0000000FF1CE}-C/dwtrig20.exe.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0115-0409-1000-0000000FF1CE}-C/Microsoft.VC90.CRT.manifest.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0115-0409-1000-0000000FF1CE}-C/OfficeMUI.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0115-0409-1000-0000000FF1CE}-C/OfficeMUISet.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0115-0409-1000-0000000FF1CE}-C/pss10r.chm.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0115-0409-1000-0000000FF1CE}-C/setup.chm.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0115-0409-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0115-0409-1000-0000000FF1CE}-C/ShellUI.MST.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0117-0409-1000-0000000FF1CE}-C/AccessMUISet.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{90140000-0117-0409-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{91140000-003B-0000-1000-0000000FF1CE}-C/Office32WW.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{91140000-003B-0000-1000-0000000FF1CE}-C/ose.exe.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache/All Users/{91140000-003B-0000-1000-0000000FF1CE}-C/pkeyconfig-office.xrm-ms.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache/All Users/{91140000-0011-0000-1000-0000000FF1CE}-C/ProPlusrWW.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{91140000-0011-0000-1000-0000000FF1CE}-C/setup.exe.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/MSOCache/All Users/{91140000-0011-0000-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{91140000-003B-0000-1000-0000000FF1CE}-C/PrjProrWW.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{91140000-003B-0000-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{91140000-0057-0000-1000-0000000FF1CE}-C/Setup.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/MSOCache/All Users/{91140000-0057-0000-1000-0000000FF1CE}-C/VisiorWW.xml.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/1m-1e26P6SgkyC5.wav.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/2EUccs-gS3argmF3Ulb.bmp.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/5dFyDeUHMkmtVOiru.avi.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/9AxWBXLIxkQo9oioL.ppt.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/avbmNgf.mp3.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/axHIY.odp.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/BqBvLB5glXUW.m4a.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/bzfRWNd.mp3.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/Cl8IAj4q6Z.swf.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/DeYCwyfm7bMzBZ1ve.png.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/dx7rmzpQGAiUnEYX.odp.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/eCJScUVoDTQRxT.mp3.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/EIOsw_ITDuHskQ2.gif.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/ES AGE6xtK.bmp.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/fS6jE_Nk-xDkYvH.ods.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/FVvfCxg6KOtGh.jpg.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/H46 uA.m4a.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/kBxaiNR.ppt.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/l Ij Dmh9hjY.png.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/m4qgJH2 4xV.m4a.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/n1qIAly9kG2A_.m4a.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/OQr9xlf2OxZ4Bt.m4a.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/p-byvQf4WXi.jpg.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/rY_9P-PuMChm5sO40R.gif.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/sz73W_0B81.gif.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/TMvrmA4.ots.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/UXV5wyIJ.avi.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/V9Bxa.ppt.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/vWQM64uU5-o156n.bmp.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/xW0oG5O6_1kREvSA6.swf.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/Z6UQ3GuJy7T.bmp.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/zjBWTxk0JPCS23.jpg.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/_oqeRRon6xEAr.gif.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/Microsoft/Document Building Blocks/1033/14/Built-In Building Blocks.dotx.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/Microsoft/MS Project/14/1033/Global.MPT.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/Microsoft/Office/MSO1033.acl.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/Microsoft/Office/Recent/index.dat.bbadc | Dropped File | Text |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/AppData/Roaming/Microsoft/Outlook/Outlook.srs.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/Contacts/Administrator.contact.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/Contacts/lulcit amkdfe.contact.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/Desktop/-rzfosk ptr7jZrau.m4a.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/Desktop/1HKnaFEJX57.wav.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/Desktop/40WuHAMpCvl8DOMcv7Mw.m4a.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/Desktop/8HEpp51a_0 QqSHcd.avi.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/Desktop/8nmGfxGlXUH5ymaB.mkv.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/Desktop/birpRXsrcrFrpV.mp3.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/Desktop/CeqdjsYTT0pBQUmZJa.mp4.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/Desktop/cniruj.exe.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/Desktop/eT6s1T-zVq.m4a.bbadc | Dropped File | Stream |
Unknown
|
...
|
»
C:/Users/5p5NrGJn0jS HALPmcxz/Documents/Outlook Files/voeimd@djhreuu.uhd.pst.bbadc | Dropped File | Stream |
Unknown
|
...
|
»