VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware |
%LOCALAPPDATA%SAMPLE.EXE.exe
Windows Exe (x86-32)
Created at 2020-01-05T06:56:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\%LOCALAPPDATA%SAMPLE.EXE.exe | Sample File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0xa865a3 |
Size Of Initialized Data | 0xc200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-04-02 16:47:20+00:00 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.rdata | 0x401000 | 0xc8c8 | 0x0 | 0x0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.vmp0 | 0x40e000 | 0x2c14a3 | 0x0 | 0x0 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 0.0 |
.vmp1 | 0x6d0000 | 0x4b0ce0 | 0x4b0e00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.95 |
Imports (10)
»
KERNEL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetFilePointerEx | 0x0 | 0x6f9000 | 0x6943d4 | 0x3c47d4 | 0x0 |
ADVAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryValueExW | 0x0 | 0x6f9008 | 0x6943dc | 0x3c47dc | 0x0 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHChangeNotify | 0x0 | 0x6f9010 | 0x6943e4 | 0x3c47e4 | 0x0 |
SHLWAPI.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathFindFileNameW | 0x0 | 0x6f9018 | 0x6943ec | 0x3c47ec | 0x0 |
ntdll.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_aulldiv | 0x0 | 0x6f9020 | 0x6943f4 | 0x3c47f4 | 0x0 |
WTSAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WTSSendMessageW | 0x0 | 0x6f9028 | 0x6943fc | 0x3c47fc | 0x0 |
KERNEL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VirtualQuery | 0x0 | 0x6f9030 | 0x694404 | 0x3c4804 | 0x0 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetUserObjectInformationW | 0x0 | 0x6f9038 | 0x69440c | 0x3c480c | 0x0 |
KERNEL32.dll (12)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
LocalAlloc | 0x0 | 0x6f9040 | 0x694414 | 0x3c4814 | 0x0 |
LocalFree | 0x0 | 0x6f9044 | 0x694418 | 0x3c4818 | 0x0 |
GetModuleFileNameW | 0x0 | 0x6f9048 | 0x69441c | 0x3c481c | 0x0 |
GetProcessAffinityMask | 0x0 | 0x6f904c | 0x694420 | 0x3c4820 | 0x0 |
SetProcessAffinityMask | 0x0 | 0x6f9050 | 0x694424 | 0x3c4824 | 0x0 |
SetThreadAffinityMask | 0x0 | 0x6f9054 | 0x694428 | 0x3c4828 | 0x0 |
Sleep | 0x0 | 0x6f9058 | 0x69442c | 0x3c482c | 0x0 |
ExitProcess | 0x0 | 0x6f905c | 0x694430 | 0x3c4830 | 0x0 |
FreeLibrary | 0x0 | 0x6f9060 | 0x694434 | 0x3c4834 | 0x0 |
LoadLibraryA | 0x0 | 0x6f9064 | 0x694438 | 0x3c4838 | 0x0 |
GetModuleHandleA | 0x0 | 0x6f9068 | 0x69443c | 0x3c483c | 0x0 |
GetProcAddress | 0x0 | 0x6f906c | 0x694440 | 0x3c4840 | 0x0 |
USER32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetProcessWindowStation | 0x0 | 0x6f9074 | 0x694448 | 0x3c4848 | 0x0 |
GetUserObjectInformationW | 0x0 | 0x6f9078 | 0x69444c | 0x3c484c | 0x0 |
Memory Dumps (3)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
buffer | 1 | 0x001D0000 | 0x001D0FFF | Content Changed | - | 32-bit | - |
...
|
||
buffer | 1 | 0x001D0000 | 0x001D0FFF | First Execution | - | 32-bit | 0x001D000F |
...
|
||
buffer | 1 | 0x001D0000 | 0x001D0FFF | Marked Executable | - | 32-bit | 0x001D000F |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.32909145 |
Malicious
|
C:\Windows10Upgrade\resources\ux\Microsoft.WinJS\js\base.js.[ponce.lorena@aol.com] | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (4)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
JS_High_Entropy | JavaScript has a high entropy; possible obfuscation | - |
4/5
|
...
|
JS_Unicode_escaped_bytes | JavaScript contains many unicode-escaped bytes; possible obfuscation | - |
2/5
|
...
|
JS_Eval | JavaScript calls eval function; possible obfuscation | - |
2/5
|
...
|
JS_charCodeAt | JavaScript references charCodeAt function; possible obfuscation | - |
2/5
|
...
|
C:\Windows10Upgrade\resources\ux\Microsoft.WinJS\js\ui.js | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (2)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
JS_High_Entropy | JavaScript has a high entropy; possible obfuscation | - |
4/5
|
...
|
JS_charCodeAt | JavaScript references charCodeAt function; possible obfuscation | - |
2/5
|
...
|
C:\BOOTNXT.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\bootsect.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\DW20.EXE.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\DWTRIG20.EXE.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\EnableWiFiTracing.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\Windows10Upgrade\GatherOSState.EXE | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\GetCurrentRollback.EXE.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\HttpHelper.exe.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\PostOOBEScript.cmd.[ponce.lorena@aol.com] | Dropped File | Batch |
Unknown
|
...
|
»
C:\Windows10Upgrade\upgrader_default.log.[ponce.lorena@aol.com] | Dropped File | Binary |
Unknown
|
...
|
»
C:\Windows10Upgrade\upgrader_win10.log | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\Windows10UpgraderApp.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\WinREBootApp32.exe.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\WinREBootApp64.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\hwcompatShared.txt.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\block.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\bluelogo.png.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\bullet.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\default.css | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\default.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\default_eos.css | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\default_eos.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\default_oobe.css | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\default_oobe.htm.[ponce.lorena@aol.com] | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\eula.css.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\GetStarted.png.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\GetStartedHoverOver.png.[ponce.lorena@aol.com] | Dropped File | Binary |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\loading.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\lock.png.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\logo.png.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\marketing.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\NetworkIssueFAQ.mht.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\NoNetworkConnection.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\NoNetworkConnectionHoverOver.png.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\pass.png.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\Microsoft.WinJS\css\oobe-desktop.css | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\Microsoft.WinJS\css\ui-dark.css.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_ar-sa.htm.[ponce.lorena@aol.com] | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_bg-bg.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_cs-cz.htm.[ponce.lorena@aol.com] | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_da-dk.htm.[ponce.lorena@aol.com] | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_de-de.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_el-gr.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_en-gb.htm.[ponce.lorena@aol.com] | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_en-us.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_es-es.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_es-mx.htm.[ponce.lorena@aol.com] | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_et-ee.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_fi-fi.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_fr-ca.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_fr-fr.htm.[ponce.lorena@aol.com] | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_he-il.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_hr-hr.htm.[ponce.lorena@aol.com] | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_hu-hu.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_it-it.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_ja-jp.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_ko-kr.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_lt-lt.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_lv-lv.htm.[ponce.lorena@aol.com] | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_nb-no.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_nl-nl.htm.[ponce.lorena@aol.com] | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_pl-pl.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_pt-br.htm.[ponce.lorena@aol.com] | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_pt-pt.htm.[ponce.lorena@aol.com] | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_ro-ro.htm.[ponce.lorena@aol.com] | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_ru-ru.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_sk-sk.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_sl-si.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_sr-latn-cs.htm.[ponce.lorena@aol.com] | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_sv-se.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_th-th.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_tr-tr.htm.[ponce.lorena@aol.com] | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_uk-ua.htm.[ponce.lorena@aol.com] | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_zh-cn.htm.[ponce.lorena@aol.com] | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_zh-hk.htm.[ponce.lorena@aol.com] | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_zh-tw.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\i386\BiosBlocks.xml.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\i386\hwcompat.txt.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\i386\hwexclude.txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\i386\nxquery.cat | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\i386\nxquery.inf | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\i386\NXQuery.sys | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\amd64\BiosBlocks.xml.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\amd64\hwcompat.txt | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\amd64\hwexclude.txt | Modified File | Binary |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\amd64\nxquery.cat.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\amd64\nxquery.inf.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\amd64\NXQuery.sys.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Libraries\RecordedTV.library-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Desktop\Acrobat Reader DC.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Desktop\Google Chrome.lnk.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Desktop\Mozilla Firefox.lnk.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\0d81OSxvhci1.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\jDypM.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\liW Cl2VLbSoSiMzeR7.avi.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\O-m9Vfd-YR8g.swf.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\qAZu4X_.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\_OYDR1Tcr.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fs-XkNXFe2_OG\waAaf0.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fs-XkNXFe2_OG\WR_a7iufou\1Uiq7Jgw9IuB9.mkv.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fs-XkNXFe2_OG\WR_a7iufou\8B0nR6.mkv.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fs-XkNXFe2_OG\WR_a7iufou\M 0Mxilr2.mp4 | Modified File | Audio |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fs-XkNXFe2_OG\WR_a7iufou\rVOum.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fs-XkNXFe2_OG\WR_a7iufou\srz2D2.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fs-XkNXFe2_OG\WR_a7iufou\xOJh.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fs-XkNXFe2_OG\WR_a7iufou\Y6TH35ES6dnwU.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fs-XkNXFe2_OG\Uobad49auEmCJXvufDb\4KKaWl7G8.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fs-XkNXFe2_OG\Uobad49auEmCJXvufDb\9e23KEsr9szh66CxZiX.flv.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fs-XkNXFe2_OG\Uobad49auEmCJXvufDb\ARJCa5AvhV.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fs-XkNXFe2_OG\Uobad49auEmCJXvufDb\guPzm0OzOJ_1T5U.mp4.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fs-XkNXFe2_OG\Uobad49auEmCJXvufDb\Enj84Qz4GK6xOoZ\7cfDcJ Mh37QOdxjm4n.avi.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fs-XkNXFe2_OG\Uobad49auEmCJXvufDb\Enj84Qz4GK6xOoZ\pN yRZO5ky3.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fs-XkNXFe2_OG\pp4Pa7\8 x_b8TY9uNIlaEJPu.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fs-XkNXFe2_OG\pp4Pa7\QqkYW3ugL.mkv.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fs-XkNXFe2_OG\pp4Pa7\u8c4wCL.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fj8TJD\48ePaspYmmfLg.flv.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fj8TJD\EWUuzmNU7w6qdw.swf.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fj8TJD\lVqIswqi1o93jEFRh5.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fj8TJD\swYEe7.mkv.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fj8TJD\Vt-bd6OSSldFWZwm.flv.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Searches\Everywhere.search-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Searches\Indexed Locations.search-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Searches\winrt--{S-1-5-21-1051304884-625712362-2192934891-1000}-.searchconnector-ms.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\0csOb.png.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\1l8ks.png.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\1QwzZkZC2qY97fG.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\2CgFKfuS.bmp.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\2_zz.bmp.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\53jgL9AguLPJoi0V.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\5H22wIEHFFA.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\5mn-5rRd.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\6ePuVA3oz90AMsog.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\865afvOF v-P.bmp.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\a-ZoISjGYopr.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\aTxWK7SpHJ.bmp.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\BJPAbR0r.png.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\dnr4puGJfqjJ0AWqTZ.jpg.[ponce.lorena@aol.com] | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\DQNMDmJ.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Public\F4B9E43E8B778FBD0715CCE57F573AE11F3E1BA40B1CA4265C360A3997B1A474 | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\fs-XkNXFe2_OG\HOW_RECOVER.html | Dropped File | Text |
Unknown
|
...
|
»