VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Backdoor, Dropper |
Starter.exe
Windows Exe (x86-32)
Created at 2020-01-07T22:50:00
Remarks
(0x200000c): The maximum memory dump size was exceeded. Some dumps may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\AppData\Local\Temp\svchost.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x734327 |
Size Of Code | 0x2ac600 |
Size Of Initialized Data | 0x77600 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-01-07 13:02:43+00:00 |
Version Information (8)
»
CompanyName | Microsoft Corporation |
FileDescription | Host Process for Windows Services |
FileVersion | 6.1.7601.23403 (win7sp1_ldr.160325-0600) |
InternalName | svchost.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | svchost.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 6.1.7601.23403 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.MPRESS1 | 0x401000 | 0x333000 | 0xc4c00 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 8.0 |
.MPRESS2 | 0x734000 | 0xef8 | 0x1000 | 0xc4e00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.74 |
.rsrc | 0x735000 | 0x1f54 | 0x2000 | 0xc5e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.37 |
Imports (11)
»
KERNEL32.DLL (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetModuleHandleA | 0x0 | 0x73418c | 0x33418c | 0xc4f8c | 0x0 |
GetProcAddress | 0x0 | 0x734190 | 0x334190 | 0xc4f90 | 0x0 |
winspool.drv (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ClosePrinter | 0x0 | 0x734198 | 0x334198 | 0xc4f98 | 0x0 |
comctl32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ImageList_Add | 0x0 | 0x7341a0 | 0x3341a0 | 0xc4fa0 | 0x0 |
shell32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x7341a8 | 0x3341a8 | 0xc4fa8 | 0x0 |
ole32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
IsEqualGUID | 0x0 | 0x7341b0 | 0x3341b0 | 0xc4fb0 | 0x0 |
version.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VerQueryValueW | 0x0 | 0x7341b8 | 0x3341b8 | 0xc4fb8 | 0x0 |
user32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetDC | 0x0 | 0x7341c0 | 0x3341c0 | 0xc4fc0 | 0x0 |
oleaut32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VariantInit | 0x0 | 0x7341c8 | 0x3341c8 | 0xc4fc8 | 0x0 |
netapi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetWkstaGetInfo | 0x0 | 0x7341d0 | 0x3341d0 | 0xc4fd0 | 0x0 |
advapi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegLoadKeyW | 0x0 | 0x7341d8 | 0x3341d8 | 0xc4fd8 | 0x0 |
gdi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
Pie | 0x0 | 0x7341e0 | 0x3341e0 | 0xc4fe0 | 0x0 |
Exports (3)
»
Api name | EAT Address | Ordinal |
---|---|---|
TMethodImplementationIntercept | 0xd92d8 | 0x3 |
__dbk_fcall_wrapper | 0x11190 | 0x2 |
dbkFCallWrapperAddr | 0x2bf63c | 0x1 |
Memory Dumps (30)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x006AB2B4 |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x0040FC84 |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x00407354 |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x004346B0 |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x004314D4 |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x00515580 |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x00516184 |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x00520498 |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x006AD000 |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x0042C2E0 |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x005F28C8 |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x0053388C |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x0047ACF0 |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x0059C1DC |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x005F5844 |
...
|
||
buffer | 4 | 0x00790000 | 0x00790FFF | First Execution | - | 32-bit | 0x00790FE2 |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x00568A1C |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x00615714 |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x00627554 |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x005EAB60 |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x004CA91C |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x00541110 |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x005EF7B0 |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x0054F304 |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x0059A0D0 |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x004DB124 |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x00535A68 |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x00516440 |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x0046FA58 |
...
|
||
svchost.exe | 4 | 0x00400000 | 0x00736FFF | Content Changed | - | 32-bit | 0x006123A4 |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
GenPack:Generic.Malware.FHTk.1562EF97 |
Malicious
|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x5e825a |
Size Of Code | 0xf3600 |
Size Of Initialized Data | 0xe7200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-01-07 15:03:07+00:00 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.MPRESS1 | 0x401000 | 0x1e7000 | 0x102e00 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 8.0 |
.MPRESS2 | 0x5e8000 | 0xe00 | 0xe00 | 0x103000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.04 |
.rsrc | 0x5e9000 | 0x9fc | 0xa00 | 0x103e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.21 |
Imports (7)
»
KERNEL32.DLL (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetModuleHandleA | 0x0 | 0x5e813c | 0x1e813c | 0x10313c | 0x0 |
GetProcAddress | 0x0 | 0x5e8140 | 0x1e8140 | 0x103140 | 0x0 |
shell32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x5e8148 | 0x1e8148 | 0x103148 | 0x0 |
version.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VerQueryValueW | 0x0 | 0x5e8150 | 0x1e8150 | 0x103150 | 0x0 |
user32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CharNextW | 0x0 | 0x5e8158 | 0x1e8158 | 0x103158 | 0x0 |
oleaut32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
VariantCopy | 0x0 | 0x5e8160 | 0x1e8160 | 0x103160 | 0x0 |
netapi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetWkstaGetInfo | 0x0 | 0x5e8168 | 0x1e8168 | 0x103168 | 0x0 |
advapi32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegLoadKeyW | 0x0 | 0x5e8170 | 0x1e8170 | 0x103170 | 0x0 |
Exports (3)
»
Api name | EAT Address | Ordinal |
---|---|---|
TMethodImplementationIntercept | 0x5ff50 | 0x3 |
__dbk_fcall_wrapper | 0x10a98 | 0x2 |
dbkFCallWrapperAddr | 0xfc63c | 0x1 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
starter.exe | 1 | 0x00400000 | 0x005E9FFF | Relevant Image | - | 32-bit | - |
...
|
||
starter.exe | 1 | 0x00400000 | 0x005E9FFF | Process Termination | - | 32-bit | - |
...
|
C:\Users\FD1HVy\Pictures\0ZJwwbIxL.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\1c3rL6PVjbLvNlSb5Mgw.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\7FSWtnjdroie8sHf.gif.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\7tu74HnqVuTKF-irmLg.png.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\ANDg.bmp.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\cxxFi_UOK95jAQB.bmp.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\d1GcpQ8HSjPU1.png.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\DLVmutigOApvtpK60-.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\DqVxhGn.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\e7woCF.png.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\E8m.png.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\eydE0wM1nk82 z.jpg.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\F699NY.gif.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\FkWqpfRHgAvo0jZHJ.png.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\g9O4.bmp.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\gBHkPd2ExY-7NE0s.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Gw7E-7lQVr5Q35z.bmp.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\jNH2sLXcJ.gif.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\M3tj1ow.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\MDmmN.bmp.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\mY44eS36.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\NOia.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\NWbnZSFmlvftd.gif.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\oMwMsX2eLemNVv.gif.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\oxC6aTQw0pZkgyw.bmp.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\rnDBz2JlVeOKY2RW.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\v-2hsRPxNsy1VMG.bmp.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\vu3ld0EDgy.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\wEGBaa47xATqWMx.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\xinRxmkJZ1uorE.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\ZSQ2EDO.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\zyhyYGnw0.gif.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\gY9M2dg0_0UWguJs2-1u.wav.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\-RyunluTtD\6EyFn FprTgQMRvU.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\-RyunluTtD\7kn5GvUpojv.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\-RyunluTtD\i0igSPvfssExEZb-.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\-RyunluTtD\xi07gKeAlzGUyT XX.mp3.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\-RyunluTtD\3PI_Gk5aNV2I\Rv7fp66uFAk23v9.mp3.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\-RyunluTtD\H_6WxZl\4ef0_95iitB.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\-RyunluTtD\H_6WxZl\5W3Y4.mp3.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\-RyunluTtD\H_6WxZl\noZwdZwn0G.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\-RyunluTtD\H_6WxZl\ZKuqiCgS8Dl7fI.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\-RyunluTtD\OQtNhnD_g6oB\2APcZU.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\-RyunluTtD\OQtNhnD_g6oB\omkgK9nT14XI.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\-RyunluTtD\OQtNhnD_g6oB\pJtaJTOHkTwQaD.wav.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\-RyunluTtD\OQtNhnD_g6oB\tNqp6LuuxQTgau qk_.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\-RyunluTtD\OQtNhnD_g6oB\Ur-lvozDfYzT.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\-RyunluTtD\OQtNhnD_g6oB\wN7Xi3Z dS nXrF.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\-RyunluTtD\OQtNhnD_g6oB\YWqtC3 6ilQcdWq_Dk\a5 Do6eYZRS8d2n.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\-RyunluTtD\OQtNhnD_g6oB\YWqtC3 6ilQcdWq_Dk\JZzLhCeL\UWsH.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\-RyunluTtD\OQtNhnD_g6oB\YWqtC3 6ilQcdWq_Dk\JZzLhCeL\w9AX4V.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\-RyunluTtD\OQtNhnD_g6oB\YWqtC3 6ilQcdWq_Dk\JZzLhCeL\Yopjb83eiteK.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\-RyunluTtD\OQtNhnD_g6oB\YWqtC3 6ilQcdWq_Dk\JZzLhCeL\vzvPX3Iej3vAWajRPfK5\tO2ilx.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\5QACCedyGB\3 oi129NKQb.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\5QACCedyGB\JCaVXCFwopp6UJIk.mp3.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\5QACCedyGB\lrlsPyXX8EtT4HuZ5c-.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\5QACCedyGB\qsgCNk1eN_S6Na7.wav.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\5QACCedyGB\ZSWV-pw5DH3N.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\xEI 7Sj-tV2QrLOUdaK\bGaqT.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\bgzJWzjvL0Da.mp4.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\n3q 0AtwYjf-aBlQ.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\SvFML.flv.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\XJZv0B_MNsWt4nu_VPxM.flv.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\DVsO\2upVXxgW6VDr9uBO.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\DVsO\6R1z0kN_xIx-i5nFx5j.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mPbSD40JyFOBvds-fT\kiJh-RdJZ0Jgw.swf.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mPbSD40JyFOBvds-fT\ktYet.swf.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mPbSD40JyFOBvds-fT\qFEgVapw.flv.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mPbSD40JyFOBvds-fT\vvHWqtEd.swf.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mPbSD40JyFOBvds-fT\Y1sYuTE.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mPbSD40JyFOBvds-fT\DsltefoZ4rC-2oGLT-\4gF-6.flv.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mPbSD40JyFOBvds-fT\DsltefoZ4rC-2oGLT-\OUVxg26rU6FHdD82dcjh.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mPbSD40JyFOBvds-fT\DsltefoZ4rC-2oGLT-\yOI5_5qgIac7hS.mp4.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mPbSD40JyFOBvds-fT\DsltefoZ4rC-2oGLT-\c1hjlLuDDysDllX\L6EtlzHP7ZZ.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mPbSD40JyFOBvds-fT\DsltefoZ4rC-2oGLT-\c1hjlLuDDysDllX\N-fnB05hce67-bngh.mp4.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mPbSD40JyFOBvds-fT\DsltefoZ4rC-2oGLT-\c1hjlLuDDysDllX\OFN8lmG2VVdv2_mLja9.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mPbSD40JyFOBvds-fT\DsltefoZ4rC-2oGLT-\c1hjlLuDDysDllX\pe5uwlCTM.swf.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mPbSD40JyFOBvds-fT\DsltefoZ4rC-2oGLT-\c1hjlLuDDysDllX\4b3EMKXD98fmoFvokB7\98cL7jBAXTLLwBp58w_.avi.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mPbSD40JyFOBvds-fT\DsltefoZ4rC-2oGLT-\c1hjlLuDDysDllX\4b3EMKXD98fmoFvokB7\LDyFZvGo8JUbeTHAvuso.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mPbSD40JyFOBvds-fT\DsltefoZ4rC-2oGLT-\c1hjlLuDDysDllX\4b3EMKXD98fmoFvokB7\n3XCsAzAHBMSH-aniu8y.mkv.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mPbSD40JyFOBvds-fT\DsltefoZ4rC-2oGLT-\c1hjlLuDDysDllX\4b3EMKXD98fmoFvokB7\OKtew5FfB.mp4.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\mPbSD40JyFOBvds-fT\DsltefoZ4rC-2oGLT-\c1hjlLuDDysDllX\4b3EMKXD98fmoFvokB7\SOl16tGR.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\UDFUzUQ8Yupx-EKkikTj\NrDuDYqAUWOqo7pkWv.swf.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\1q44j4e.xlsx.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\5d11OnUx.pptx.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Database1.accdb.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\g5e_ Xx9he8T4S1 HYew.docx.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\KUM50ZOxDJ.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\KXjeFCCCBhdrPUwJOc.xlsx.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Nten2MQ.pptx.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\o4hbJhXQSrGkEoYS7-Y.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\PFpeT79.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\pHK_VvVdR_pb.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\phqpkh6lM.pptx.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\WJm5rSSSRSrA5.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\XNar.xlsx.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\yb628WRD39V5NV.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\zMjvl_L.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\am9vY2a5PgsV\f1iO9FIUE5B2i.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\am9vY2a5PgsV\KsmcOIZ.ppt.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\am9vY2a5PgsV\QnrKvw_fDSFNr3vi7.ppt.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\am9vY2a5PgsV\RyNK5g-lAf6.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\am9vY2a5PgsV\2y Ru\Ldbj.ppt.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\h8qT\3uW5r3EFECObb4Jkaws5\hA7Du13.pdf.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\h8qT\3uW5r3EFECObb4Jkaws5\KAzT2yP7-K MJ7dy.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\h8qT\NpGrRQBt\jFDP6bWkvs7kaxBJeh.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\h8qT\NpGrRQBt\uHfssNFWDvyZtSw0Da.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\idg2Uqg_UoCvubCRp\2vea65mr1s8gRg.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Zalu6yDyt\-wzwI9VzLXgPmg.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Zalu6yDyt\Cf1eX.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Zalu6yDyt\DL4OY90ax0.pptx.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Zalu6yDyt\jK4dWlR7LmJuWyj06oN.doc.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Zalu6yDyt\LN_1HEZlFs7xI2L.docx.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Zalu6yDyt\gO DjMo eBE\2blRwpiEXn2J2U\9IUntQbTh.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Zalu6yDyt\gO DjMo eBE\2blRwpiEXn2J2U\JyA1QZfOQ2hoKQ7K4.xlsx.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Zalu6yDyt\gO DjMo eBE\2blRwpiEXn2J2U\ZWZCOAHnA.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\-fiDFkuCToUM.png.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\0Y3k13NkO4cK5GuM5qI.flv.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\5_wma4tkb.swf.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\7Ep_LWE0w.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\86gbtrj443VCRSqyBjZ.mp3.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\8hCy665Ib 4iS.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\9pfae2qQLu9G.mkv.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\cXRrKfTZ0c.swf.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\D4GUKlUex8v1iWiFH.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\E1qS o34PtKyaf.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Eb6jLB-DalTxbHY0RI.docx.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\ff9yDOnT6wxuHl.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\FxtwtC4Tdba.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\I2SPL5Axo3jtg.jpg.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\JrCMk0y7Nc5q.rtf.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\kjjga2.flv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\KUiNTv.jpg.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\M9IksHu6kp7Jl7M3.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\NPHJD4G.bmp.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\OvCDmPXEJUSEt 6dX.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\p0QlKEAU_5QC.avi.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\R 78jahdO2FxG.jpg.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Th4oH34aOBNzq3F.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\u8X4BzJoa.doc.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\UCJnw_DgL5OK.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Ue-OY3JirhS7kA.xls.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\uS7_jOQ9rxMLkujGEn.jpg.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\wKnLvh7Lo.mkv.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\zoYp7TvNJxCnngfxvFWb.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\-S1uXP4L87o0d5ma\R3ov 9BbtpOU.gif.Deniz_Kızı | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\-S1uXP4L87o0d5ma\zCsmuZY.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\-S1uXP4L87o0d5ma\zGmDtve.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\-S1uXP4L87o0d5ma\zhrFrBA3PbrUo.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows\System32\drivers\etc\host | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\Lütfen Beni Oku!!!.log | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\IPJYS7Jpp-.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\jrY5.bmp.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\JtsDWhhdMtElGU7u_UWW.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\vlJe.gif.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\WmCgIBHgN68.bmp.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\XdhLf49ZccVzgK.bmp.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\-RyunluTtD\OQtNhnD_g6oB\CiXZgyRWub8 9qNUD.wav.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\ZeLG4SAPYTxv1v.flv.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\DVsO\9zyZ0ov997tN6CbR.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\DVsO\ltbeTH.avi.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\mPbSD40JyFOBvds-fT\DsltefoZ4rC-2oGLT-\7qaO9.avi.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\8FHN XJn.docx.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\cs-txIlm.pptx.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\LTv3Nwp4xaz6N7gZLHNi.docx.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\MC2TiP5IndvsiuE.xlsx.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\am9vY2a5PgsV\2y Ru\cM6S.rtf.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\h8qT\NpGrRQBt\S76pNZGPW1d_O.xlsx.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\Zalu6yDyt\PD8fQznaIJMKf.ppt.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\2-YLcZjyX.mkv.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\6Vne0fzSfF.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\KGLqXwyyJsnDweAqe.rtf.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\nPkVd0v.gif.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\QLatR5pZttLp9OzZLq.flv.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Desktop\-S1uXP4L87o0d5ma\izunqJR8AxwUL.png.Deniz_Kızı | Dropped File | Stream |
Not Queried
|
...
|
»