VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware |
Wacatac_2019-11-20_23-34.exe
Windows Exe (x86-32)
Created at 2019-11-20T23:55:00
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Wacatac_2019-11-20_23-34.exe | Sample File | Binary |
Unknown
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x404b8b |
Size Of Code | 0x11200 |
Size Of Initialized Data | 0x4a63800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-07-28 16:07:03+00:00 |
Version Information (2)
»
FileOldVersionTree | 1.0.4.4 |
InternalNameTwo | gjtrrh.exe |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x11071 | 0x11200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.8 |
.rdata | 0x413000 | 0x811c | 0x8200 | 0x11600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.56 |
.data | 0x41c000 | 0x4a47c64 | 0xdc00 | 0x19800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.18 |
.tls | 0x4e64000 | 0x9 | 0x200 | 0x27400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x4e65000 | 0x12070 | 0x12200 | 0x27600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.55 |
.reloc | 0x4e78000 | 0x1350 | 0x1400 | 0x39800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.48 |
Imports (4)
»
KERNEL32.dll (87)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
lstrlenA | 0x0 | 0x413008 | 0x1a8e8 | 0x18ee8 | 0x54d |
CommConfigDialogA | 0x0 | 0x41300c | 0x1a8ec | 0x18eec | 0x5d |
lstrcpynA | 0x0 | 0x413010 | 0x1a8f0 | 0x18ef0 | 0x54a |
BuildCommDCBAndTimeoutsA | 0x0 | 0x413014 | 0x1a8f4 | 0x18ef4 | 0x3b |
WaitNamedPipeA | 0x0 | 0x413018 | 0x1a8f8 | 0x18ef8 | 0x4ff |
SetDefaultCommConfigW | 0x0 | 0x41301c | 0x1a8fc | 0x18efc | 0x44f |
GetModuleHandleW | 0x0 | 0x413020 | 0x1a900 | 0x18f00 | 0x218 |
GetConsoleTitleA | 0x0 | 0x413024 | 0x1a904 | 0x18f04 | 0x1b5 |
FindActCtxSectionStringA | 0x0 | 0x413028 | 0x1a908 | 0x18f08 | 0x12a |
WaitForMultipleObjectsEx | 0x0 | 0x41302c | 0x1a90c | 0x18f0c | 0x4f8 |
SetFileShortNameW | 0x0 | 0x413030 | 0x1a910 | 0x18f10 | 0x469 |
GetFileAttributesA | 0x0 | 0x413034 | 0x1a914 | 0x18f14 | 0x1e5 |
VerifyVersionInfoA | 0x0 | 0x413038 | 0x1a918 | 0x18f18 | 0x4e7 |
HeapQueryInformation | 0x0 | 0x41303c | 0x1a91c | 0x18f1c | 0x2d1 |
SetSystemPowerState | 0x0 | 0x413040 | 0x1a920 | 0x18f20 | 0x48a |
SetFilePointer | 0x0 | 0x413044 | 0x1a924 | 0x18f24 | 0x466 |
LCMapStringA | 0x0 | 0x413048 | 0x1a928 | 0x18f28 | 0x32b |
GetLastError | 0x0 | 0x41304c | 0x1a92c | 0x18f2c | 0x202 |
GetProcAddress | 0x0 | 0x413050 | 0x1a930 | 0x18f30 | 0x245 |
WriteConsoleA | 0x0 | 0x413054 | 0x1a934 | 0x18f34 | 0x51a |
LocalAlloc | 0x0 | 0x413058 | 0x1a938 | 0x18f38 | 0x344 |
GetNumberFormatW | 0x0 | 0x41305c | 0x1a93c | 0x18f3c | 0x233 |
HeapLock | 0x0 | 0x413060 | 0x1a940 | 0x18f40 | 0x2d0 |
GetOEMCP | 0x0 | 0x413064 | 0x1a944 | 0x18f44 | 0x237 |
DeleteCriticalSection | 0x0 | 0x413068 | 0x1a948 | 0x18f48 | 0xd1 |
GetWindowsDirectoryW | 0x0 | 0x41306c | 0x1a94c | 0x18f4c | 0x2af |
GetVersion | 0x0 | 0x413070 | 0x1a950 | 0x18f50 | 0x2a2 |
DeleteFileW | 0x0 | 0x413074 | 0x1a954 | 0x18f54 | 0xd6 |
GetPrivateProfileSectionW | 0x0 | 0x413078 | 0x1a958 | 0x18f58 | 0x240 |
lstrcpyA | 0x0 | 0x41307c | 0x1a95c | 0x18f5c | 0x547 |
CreateFileW | 0x0 | 0x413080 | 0x1a960 | 0x18f60 | 0x8f |
GetStringTypeW | 0x0 | 0x413084 | 0x1a964 | 0x18f64 | 0x269 |
GetModuleFileNameW | 0x0 | 0x413088 | 0x1a968 | 0x18f68 | 0x214 |
CreateMutexW | 0x0 | 0x41308c | 0x1a96c | 0x18f6c | 0x9e |
WriteConsoleW | 0x0 | 0x413090 | 0x1a970 | 0x18f70 | 0x524 |
FlushFileBuffers | 0x0 | 0x413094 | 0x1a974 | 0x18f74 | 0x157 |
HeapAlloc | 0x0 | 0x413098 | 0x1a978 | 0x18f78 | 0x2cb |
EncodePointer | 0x0 | 0x41309c | 0x1a97c | 0x18f7c | 0xea |
DecodePointer | 0x0 | 0x4130a0 | 0x1a980 | 0x18f80 | 0xca |
GetCommandLineW | 0x0 | 0x4130a4 | 0x1a984 | 0x18f84 | 0x187 |
RaiseException | 0x0 | 0x4130a8 | 0x1a988 | 0x18f88 | 0x3b1 |
RtlUnwind | 0x0 | 0x4130ac | 0x1a98c | 0x18f8c | 0x418 |
IsDebuggerPresent | 0x0 | 0x4130b0 | 0x1a990 | 0x18f90 | 0x300 |
IsProcessorFeaturePresent | 0x0 | 0x4130b4 | 0x1a994 | 0x18f94 | 0x304 |
ExitProcess | 0x0 | 0x4130b8 | 0x1a998 | 0x18f98 | 0x119 |
GetModuleHandleExW | 0x0 | 0x4130bc | 0x1a99c | 0x18f9c | 0x217 |
MultiByteToWideChar | 0x0 | 0x4130c0 | 0x1a9a0 | 0x18fa0 | 0x367 |
WideCharToMultiByte | 0x0 | 0x4130c4 | 0x1a9a4 | 0x18fa4 | 0x511 |
GetStdHandle | 0x0 | 0x4130c8 | 0x1a9a8 | 0x18fa8 | 0x264 |
WriteFile | 0x0 | 0x4130cc | 0x1a9ac | 0x18fac | 0x525 |
GetProcessHeap | 0x0 | 0x4130d0 | 0x1a9b0 | 0x18fb0 | 0x24a |
HeapSize | 0x0 | 0x4130d4 | 0x1a9b4 | 0x18fb4 | 0x2d4 |
HeapFree | 0x0 | 0x4130d8 | 0x1a9b8 | 0x18fb8 | 0x2cf |
EnterCriticalSection | 0x0 | 0x4130dc | 0x1a9bc | 0x18fbc | 0xee |
LeaveCriticalSection | 0x0 | 0x4130e0 | 0x1a9c0 | 0x18fc0 | 0x339 |
ReadFile | 0x0 | 0x4130e4 | 0x1a9c4 | 0x18fc4 | 0x3c0 |
SetFilePointerEx | 0x0 | 0x4130e8 | 0x1a9c8 | 0x18fc8 | 0x467 |
SetLastError | 0x0 | 0x4130ec | 0x1a9cc | 0x18fcc | 0x473 |
GetCurrentThreadId | 0x0 | 0x4130f0 | 0x1a9d0 | 0x18fd0 | 0x1c5 |
GetFileType | 0x0 | 0x4130f4 | 0x1a9d4 | 0x18fd4 | 0x1f3 |
GetStartupInfoW | 0x0 | 0x4130f8 | 0x1a9d8 | 0x18fd8 | 0x263 |
QueryPerformanceCounter | 0x0 | 0x4130fc | 0x1a9dc | 0x18fdc | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x413100 | 0x1a9e0 | 0x18fe0 | 0x1c1 |
GetSystemTimeAsFileTime | 0x0 | 0x413104 | 0x1a9e4 | 0x18fe4 | 0x279 |
GetEnvironmentStringsW | 0x0 | 0x413108 | 0x1a9e8 | 0x18fe8 | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x41310c | 0x1a9ec | 0x18fec | 0x161 |
UnhandledExceptionFilter | 0x0 | 0x413110 | 0x1a9f0 | 0x18ff0 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x413114 | 0x1a9f4 | 0x18ff4 | 0x4a5 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x413118 | 0x1a9f8 | 0x18ff8 | 0x2e3 |
Sleep | 0x0 | 0x41311c | 0x1a9fc | 0x18ffc | 0x4b2 |
GetCurrentProcess | 0x0 | 0x413120 | 0x1aa00 | 0x19000 | 0x1c0 |
TerminateProcess | 0x0 | 0x413124 | 0x1aa04 | 0x19004 | 0x4c0 |
TlsAlloc | 0x0 | 0x413128 | 0x1aa08 | 0x19008 | 0x4c5 |
TlsGetValue | 0x0 | 0x41312c | 0x1aa0c | 0x1900c | 0x4c7 |
TlsSetValue | 0x0 | 0x413130 | 0x1aa10 | 0x19010 | 0x4c8 |
TlsFree | 0x0 | 0x413134 | 0x1aa14 | 0x19014 | 0x4c6 |
GetConsoleCP | 0x0 | 0x413138 | 0x1aa18 | 0x19018 | 0x19a |
GetConsoleMode | 0x0 | 0x41313c | 0x1aa1c | 0x1901c | 0x1ac |
IsValidCodePage | 0x0 | 0x413140 | 0x1aa20 | 0x19020 | 0x30a |
GetACP | 0x0 | 0x413144 | 0x1aa24 | 0x19024 | 0x168 |
GetCPInfo | 0x0 | 0x413148 | 0x1aa28 | 0x19028 | 0x172 |
LoadLibraryExW | 0x0 | 0x41314c | 0x1aa2c | 0x1902c | 0x33e |
OutputDebugStringW | 0x0 | 0x413150 | 0x1aa30 | 0x19030 | 0x38a |
HeapReAlloc | 0x0 | 0x413154 | 0x1aa34 | 0x19034 | 0x2d2 |
LCMapStringW | 0x0 | 0x413158 | 0x1aa38 | 0x19038 | 0x32d |
SetStdHandle | 0x0 | 0x41315c | 0x1aa3c | 0x1903c | 0x487 |
CloseHandle | 0x0 | 0x413160 | 0x1aa40 | 0x19040 | 0x52 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCaretPos | 0x0 | 0x413168 | 0x1aa48 | 0x19048 | 0x10a |
ADVAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DeregisterEventSource | 0x0 | 0x413000 | 0x1a8e0 | 0x18ee0 | 0xdb |
WINHTTP.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WinHttpCloseHandle | 0x0 | 0x413170 | 0x1aa50 | 0x19050 | 0x7 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
buffer | 1 | 0x00296520 | 0x0029EE67 | Marked Executable | - | 32-bit | 0x00296520 |
![]() |
![]() |
...
|
buffer | 1 | 0x001A0000 | 0x001AEFFF | First Execution | - | 32-bit | 0x001A0000 |
![]() |
![]() |
...
|
\\?\C:\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\boot.sdi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\ntuser.ini | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Recovery\e9e23962-4a25-11e7-88e8-91fb2ec43f0b\Winre.wim | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\4HKKgFKeIA-tj8p.mkv | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\98KbAKVzLCjvlVD.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\bCgEZVX9L9jQz2qWVKNz.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\em--siXz NglZ-An.png | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\FsOU4o0hMFpPBRbA.doc | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\HfYjszBjyIVWutWh.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\jGcvWPRC.csv | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\liVQHjNX2r.swf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\llR6.pps | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\lm8-Yxyd.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NgqyPrC0ZV4fh.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\nSA7d4lyI1Ncal5FKUi.xls | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\qIOkRC-l.flv | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\tLYwebo5JKIgCR.avi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\tyzbPSjZEG.avi | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\V8ri.swf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\vDRPByO651DdDfm.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\WiGeM.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\yEA9WuGUl0.doc | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\YQ6ihizfQJQ.bmp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\YYjmQ.png | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Z18u8QGOH13-Iu4LwHT.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZeChUGPb.wav | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\_udXp.doc | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9-1Wl49_LbKQ0\2OrJ.png | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9-1Wl49_LbKQ0\L6g9L.gif | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9-1Wl49_LbKQ0\lBtV.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9-1Wl49_LbKQ0\LW81G3U7cBxqDv1Xd1fu.odp | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9-1Wl49_LbKQ0\NevD8gFNlpGC369Gy.xlsx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\aeutpKYrnLsv9u1\ApDQZcKbc6uihxPt.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\aeutpKYrnLsv9u1\kv_sY.pps | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\aeutpKYrnLsv9u1\PDFNvUZaxs.mkv | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\aeutpKYrnLsv9u1\lnC8VFH_7XvA0rvnIlk_\AHzFw9uT7csYzjH-YBK.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\aeutpKYrnLsv9u1\lnC8VFH_7XvA0rvnIlk_\LnpX_dH.docx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\aeutpKYrnLsv9u1\lnC8VFH_7XvA0rvnIlk_\ymfW8vhK.swf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\aeutpKYrnLsv9u1\lnC8VFH_7XvA0rvnIlk_\vPe92_uuRvFYmIY\gYB5HFNX.flv | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\aeutpKYrnLsv9u1\lnC8VFH_7XvA0rvnIlk_\vPe92_uuRvFYmIY\psApFJEI4E87T.png | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\aeutpKYrnLsv9u1\lnC8VFH_7XvA0rvnIlk_\vPe92_uuRvFYmIY\5q 1\HrxLxYDTaNs.swf | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\aeutpKYrnLsv9u1\lnC8VFH_7XvA0rvnIlk_\vPe92_uuRvFYmIY\5q 1\JosdybsYa9WW8YJ6_C.xlsx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\aeutpKYrnLsv9u1\lnC8VFH_7XvA0rvnIlk_\vPe92_uuRvFYmIY\5q 1\kUy2s6gipM.png | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\aeutpKYrnLsv9u1\lnC8VFH_7XvA0rvnIlk_\vPe92_uuRvFYmIY\5q 1\nBTFhev2dXS.mp3 | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\-H6-nCLy9iKddFOfC7X.ots | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\0ZG0M.xlsx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\1hd5ypV.docx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\2TTC6.docx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\3V6OZ8oC-7w9cG YFL.docx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Documents\5O1Ef9xbUFGU5rk38I.xlsx | Modified File | Stream |
Unknown
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\Music\read_me.txt | Dropped File | Text |
Unknown
|
...
|
»