VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Trojan
|
Threat Names: |
Gen:Heur.Ransom.REntS.Gen.1
Win32.Trojan.Filecoder
|
somik1.exe
Windows Exe (x86-32)
Created at 2020-01-10T10:43:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2020-01-05 14:10 (UTC+1) |
Last Seen | 2020-01-10 09:03 (UTC+1) |
Names | Win32.Trojan.Filecoder |
Families | Filecoder |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x426a4a |
Size Of Code | 0x24c00 |
Size Of Initialized Data | 0xda00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-01-02 22:23:02+00:00 |
Version Information (11)
»
Assembly Version | 1.0.0.0 |
Comments | - |
CompanyName | - |
FileDescription | somik1 |
FileVersion | 1.0.0.0 |
InternalName | somik1.exe |
LegalCopyright | Copyright © 2019 |
LegalTrademarks | - |
OriginalFilename | somik1.exe |
ProductName | somik1 |
ProductVersion | 1.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x24a98 | 0x24c00 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.31 |
.rsrc | 0x428000 | 0xd7e0 | 0xd800 | 0x24e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.96 |
.reloc | 0x436000 | 0xc | 0x200 | 0x32600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.1 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x26a20 | 0x24c20 | 0x0 |
Memory Dumps (20)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
somik1.exe | 1 | 0x00D70000 | 0x00DA7FFF | Relevant Image |
![]() |
64-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF9D8E4B000 | 0x7FF9D8E4BFFF | First Execution |
![]() |
64-bit | 0x7FF9D8E4B020 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF9D8F12000 | 0x7FF9D8F12FFF | First Execution |
![]() |
64-bit | 0x7FF9D8F12000 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF9D8E4B000 | 0x7FF9D8E4BFFF | Content Changed |
![]() |
64-bit | 0x7FF9D8E4B9C0 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF9D8F12000 | 0x7FF9D8F12FFF | Content Changed |
![]() |
64-bit | 0x7FF9D8F12A80 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF9D8F19000 | 0x7FF9D8F19FFF | First Execution |
![]() |
64-bit | 0x7FF9D8F19000 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF9D8D84000 | 0x7FF9D8D84FFF | First Execution |
![]() |
64-bit | 0x7FF9D8D84028 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF9D8F1A000 | 0x7FF9D8F1AFFF | First Execution |
![]() |
64-bit | 0x7FF9D8F1A012 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF9D8F1B000 | 0x7FF9D8F1BFFF | First Execution |
![]() |
64-bit | 0x7FF9D8F1B060 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF9D8E4C000 | 0x7FF9D8E4CFFF | First Execution |
![]() |
64-bit | 0x7FF9D8E4C020 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF9D8F1C000 | 0x7FF9D8F1CFFF | First Execution |
![]() |
64-bit | 0x7FF9D8F1C020 |
![]() |
![]() |
...
|
buffer | 1 | 0x02EC2000 | 0x02EC3FFF | First Execution |
![]() |
64-bit | 0x02EC389C |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF9D8F1C000 | 0x7FF9D8F1CFFF | Content Changed |
![]() |
64-bit | 0x7FF9D8F1CAA0 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF9D8E4B000 | 0x7FF9D8E4BFFF | Content Changed |
![]() |
64-bit | 0x7FF9D8E4BBF0 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF9D8D84000 | 0x7FF9D8D84FFF | Content Changed |
![]() |
64-bit | 0x7FF9D8D84AC8 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF9D8F1B000 | 0x7FF9D8F1BFFF | Content Changed |
![]() |
64-bit | 0x7FF9D8F1B3E0 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF9D8D84000 | 0x7FF9D8D84FFF | Content Changed |
![]() |
64-bit | 0x7FF9D8D843B8 |
![]() |
![]() |
...
|
buffer | 1 | 0x02EC2000 | 0x02EC3FFF | Content Changed |
![]() |
64-bit | 0x02EC3A84 |
![]() |
![]() |
...
|
buffer | 1 | 0x7FF9D8D84000 | 0x7FF9D8D84FFF | Content Changed |
![]() |
64-bit | 0x7FF9D8D843B8 |
![]() |
![]() |
...
|
somik1.exe | 1 | 0x00D70000 | 0x00DA7FFF | Final Dump |
![]() |
64-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Ransom.REntS.Gen.1 |
Malicious
|
C:\588bce7c90097ed212\DHtmlHeader.html | Modified File | Text |
Unknown
|
...
|
»
C:\588bce7c90097ed212\header.bmp.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x64.msi.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x64.msi.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\RGB9Rast_x86.msi.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupEngine.dll.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SetupUtility.exe.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\SplashScreen.bmp.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\sqmapi.dll.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Known Folders API Service.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Operational.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx | Modified File | Stream |
Unknown
|
...
|
»
C:\Logs\Internet Explorer.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Recovery\ReAgentOld.xml.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Desktop\Acrobat Reader DC.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Desktop\Google Chrome.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Desktop\Mozilla Firefox.lnk.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Libraries\RecordedTV.library-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\0hOvtnKPB9OiXO52YfO.jpg.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\0j6rJ H91WuZhW.wav.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\49a7_WF9Ju.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\8t60SjbIk0-szSnov.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\EE9r_4bOM 9sjm8GM8Ue.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\j4prgeOALdt.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\KpF-B 3-7sSJYhB.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\O0qvS6.m4a.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\osW5V4ovA-wvyiw.pdf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\qDUe3b3JB4Yp_rq6m.gif.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\R3L wRQtHi6flsD.wav.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\sUTp3ipR6r9Fr.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\TYNme.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\vg GD2zm.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\x6gYtV1qLyLG.mp3.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\xZ1B6oUD.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\YNQwDPFz7H39.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\AwTzvxyIihX40m_YB.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\bMbZPaEJyggV369P.docx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\D2LibbV7P8o2.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Database1.accdb | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Fd3vf0MrZbm30RWUAXEe.docx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\G6Kqm_sZXHnZXLD047.docx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\gc82AQE2ov.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\jMU1F.pptx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\ktE G12i.pptx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Na6LJJE7p1uoZSJSf8zM.pptx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\t8x8ZGgor.xlsx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\t_ 9GK5Xrl4xmu.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\W0tGoRBx.ppt.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\zlCAQr8v kR.pptx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\zUpk2.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Favorites\Bing.url.arnoldmichel2@tutanota.com | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\Links\Desktop.lnk.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Links\Downloads.lnk.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Links\OneDrive.lnk.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\gZzA8rGg5dqPZ0T.mp3.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\qdem dTmLMT8K72.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\r0-kiAb.wav.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\S5MR5Tl.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\SOJ-ccDgHNNT.wav.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\YxMvR jP6R9iWOhjvNf.wav.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\BLs6lYda5rb.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\DbAKnLJyWT.gif.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\jpyosNUhErXyWJXoh58.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\lO -5g sYCQh.png.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\wsFEe.jpg.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\_SX5RNzTU.jpg.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\bUNH1f.avi.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\A6-opF5rw_OVKAv\7Jh jbRWdOeV7nIfTu9-.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\A6-opF5rw_OVKAv\bJRR.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\A6-opF5rw_OVKAv\EHnSfOM55rpKA7K.mp4.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\A6-opF5rw_OVKAv\HXbpK.flv.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\A6-opF5rw_OVKAv\ORXYYM2UNGM HU466FCw.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\A6-opF5rw_OVKAv\rlhZAA.flv.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\A6-opF5rw_OVKAv\Wr1l.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\PT1_h-__A9fKAj\11SzVItUUcSb.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\PT1_h-__A9fKAj\lgAUyPNYU0vp1b5XhtEj\2FqKH0e1.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\PT1_h-__A9fKAj\lgAUyPNYU0vp1b5XhtEj\7YTjH0dUisky.avi.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\PT1_h-__A9fKAj\lgAUyPNYU0vp1b5XhtEj\cUuJUvxSgC.mp4.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\PT1_h-__A9fKAj\lgAUyPNYU0vp1b5XhtEj\lZEdHWKrOvBjt1.flv.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\PT1_h-__A9fKAj\lgAUyPNYU0vp1b5XhtEj\N4HY.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\PT1_h-__A9fKAj\lgAUyPNYU0vp1b5XhtEj\oHd7uyuIWk.swf.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\PT1_h-__A9fKAj\lgAUyPNYU0vp1b5XhtEj\oxLJgl2.avi.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\PT1_h-__A9fKAj\_pKm\gkeH d.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\PT1_h-__A9fKAj\_pKm\NDR2.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\PT1_h-__A9fKAj\_pKm\nuJN4722SLrFA5FcO.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\7eySl\fo6q.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\7eySl\O4esMVoHnAOOtg.bmp.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\7eySl\qOYIhL8Tt7XYHm2k.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Gsa2oY_pb9TDC16LX8n\atmjhH.jpg.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Gsa2oY_pb9TDC16LX8n\AxJbUx.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Gsa2oY_pb9TDC16LX8n\B-lTn5RsYJr2iy3px1.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Gsa2oY_pb9TDC16LX8n\E9vRy.bmp.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Gsa2oY_pb9TDC16LX8n\jxWJFaTEm27qL2.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Gsa2oY_pb9TDC16LX8n\T-AkucnYAClE9cCS1u.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\H46iRJ25FXDr4Qi\1wjQoJdc5OXITZs oWRF.bmp.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\H46iRJ25FXDr4Qi\5mS1fjvaaG0Ro2mK_.bmp.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\H46iRJ25FXDr4Qi\E1iTDWatJqeZEtoBKGL8.bmp.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\H46iRJ25FXDr4Qi\TSX6SLLsUIIGHeQ.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\H46iRJ25FXDr4Qi\x-ys\7VV0QgECyQOgRdrP.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\H46iRJ25FXDr4Qi\x-ys\cKWLBVnWwjQGtvFMKcHO.gif.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\H46iRJ25FXDr4Qi\x-ys\cuqQHS85RC4D6a2wm.gif.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\H46iRJ25FXDr4Qi\x-ys\fUXXZ.png.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\H46iRJ25FXDr4Qi\x-ys\QZxH.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\H46iRJ25FXDr4Qi\x-ys\X-S7pEkBPQta 3-jb\ml5nXHH_Xywh.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\H46iRJ25FXDr4Qi\x-ys\X-S7pEkBPQta 3-jb\Q 5D.gif.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\H46iRJ25FXDr4Qi\x-ys\X-S7pEkBPQta 3-jb\ivEZ8\nfqBTli4iOq7pEf.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\H46iRJ25FXDr4Qi\x-ys\X-S7pEkBPQta 3-jb\ivEZ8\sDms7YbablsY0w.bmp.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\rpOSt_\IS_U3sQpav_0.m4a.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\rpOSt_\LqKFmm1FK3KQJDYVbr.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\rpOSt_\YeIA8QP-.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\WJJaio\iE-z.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\WJJaio\JoAwPQBE3q pcEdLe7t.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\WJJaio\kZO6DJaNslP.m4a.arnoldmichel2@tutanota.com | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\WJJaio\PYT1mD6E.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\DisplayIcon.ico | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x86.msi.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x86.msi.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\ParameterInfo.xml.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\RGB9RAST_x64.msi.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Setup.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SetupUi.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\SetupUi.xsd | Modified File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Strings.xml.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\UiInfo.xml.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\watermark.bmp.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Application.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-International%4Operational.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Store%4Operational.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Logs\Security.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\System.evtx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Default\NTUSER.DAT.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\-1hP0IuZkn4rYey4kCgi.gif.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\3e9e611Wz.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\FdlbssLGxIymr-m4DNOD.xls.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\grjU 23.mp4.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\iyKh yLWod0M4Fh7dl.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\JpiGgB-lScKD0.ots | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\kzSf2Yq3eV0zpg-E.png.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\sodlPy.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\TpynWVBMzarv89kpQH9L.ppt.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\XZ79.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\Y_oeLdciAk1.csv.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\HCsDv_3Al2o6.docx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\hV5S0QdiHwJKhjJJW1b.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\UqVL5z.pptx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\WDgHEK6RgOX174m.docx.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\4i8vygLoQaTE2.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\O2rElhDyf34vJp.wav.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\pt2k_XbpWFj.mp3.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\w3moxC.m4a.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\DNpf5l7QpazqPp.bmp.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\pbhDl1SY2n 6Lmb6w6m.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Searches\winrt--{S-1-5-21-1051304884-625712362-2192934891-1000}-.searchconnector-ms | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\A6-opF5rw_OVKAv\j2Nvg62knP7SA4_Kax.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\PT1_h-__A9fKAj\lgAUyPNYU0vp1b5XhtEj\KiZm0ErAKADzc.mkv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\PT1_h-__A9fKAj\lgAUyPNYU0vp1b5XhtEj\q1rfl.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\PT1_h-__A9fKAj\lgAUyPNYU0vp1b5XhtEj\Y-xC.mkv.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\PT1_h-__A9fKAj\_pKm\-2XlHFR4FPwc8.swf | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\PT1_h-__A9fKAj\_pKm\I hUmkkFKZVpFXqrXWK.swf.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\PT1_h-__A9fKAj\_pKm\wBWq5HlZcU290.mkv.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\7eySl\-aAnkyfs3Bci_.gif.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\Gsa2oY_pb9TDC16LX8n\7fXxS7NVLs3ITjC.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\Gsa2oY_pb9TDC16LX8n\arkXS3V9D9ckaJ7r.gif | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\H46iRJ25FXDr4Qi\2rd0tiXmII.jpg.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\H46iRJ25FXDr4Qi\HcBZ5X9vP4ljTeEw4t3j.png.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\H46iRJ25FXDr4Qi\iOlqa6S8EqyVMH6X.bmp.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\H46iRJ25FXDr4Qi\OE9kNMuK3Grq-cS2aT.bmp.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\H46iRJ25FXDr4Qi\x-ys\ppyXAFVoQtqnow.png.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\H46iRJ25FXDr4Qi\x-ys\UJon3.jpg.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\H46iRJ25FXDr4Qi\x-ys\X-S7pEkBPQta 3-jb\Cc_4M-qD9tsaa98.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\rpOSt_\DEZ3.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\rpOSt_\sJ9SNQKym2WPzEvbqaL.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\rpOSt_\X6eKNKV1057.wav.arnoldmichel2@tutanota.com | Dropped File | Stream |
Not Queried
|
...
|
»