VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
Trojan
|
Threat Names: |
Trojan.GenericKD.42311675
Mal/HTMLGen-A
Win32.Trojan.Kryptik
|
YTHGRFED.EXE.exe
Windows Exe (x86-32)
Created at 2020-01-31T12:39:00
Remarks (2/2)
(0x0200003A): 2 tasks were rescheduled ahead of time to reveal dormant functionality.
Remarks
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\YTHGRFED.EXE.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2020-01-31 03:20 (UTC+1) |
Last Seen | 2020-01-31 12:42 (UTC+1) |
Names | Win32.Trojan.Kryptik |
Families | Kryptik |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4b25a0 |
Size Of Code | 0xb9600 |
Size Of Initialized Data | 0x30000 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-09-07 03:31:49+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xb957b | 0xb9600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.86 |
.data | 0x4bb000 | 0x12024 | 0x1c00 | 0xb9a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.7 |
.yizapi | 0x4ce000 | 0x1a000 | 0x19200 | 0xbb600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0 |
.rsrc | 0x4e8000 | 0x4a160 | 0x1200 | 0xd4800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.63 |
.reloc | 0x533000 | 0x38de | 0x3a00 | 0xd5a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 3.65 |
Imports (2)
»
KERNEL32.dll (65)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CreateEventA | 0x0 | 0x401008 | 0xb9ef8 | 0xb92f8 | 0x82 |
GetACP | 0x0 | 0x40100c | 0xb9efc | 0xb92fc | 0x168 |
GetLastError | 0x0 | 0x401010 | 0xb9f00 | 0xb9300 | 0x202 |
GetProcAddress | 0x0 | 0x401014 | 0xb9f04 | 0xb9304 | 0x245 |
EnumDateFormatsExA | 0x0 | 0x401018 | 0xb9f08 | 0xb9308 | 0xf5 |
GetSystemDefaultLCID | 0x0 | 0x40101c | 0xb9f0c | 0xb930c | 0x26b |
LoadLibraryA | 0x0 | 0x401020 | 0xb9f10 | 0xb9310 | 0x33c |
LocalAlloc | 0x0 | 0x401024 | 0xb9f14 | 0xb9314 | 0x344 |
SetProcessWorkingSetSize | 0x0 | 0x401028 | 0xb9f18 | 0xb9318 | 0x484 |
GetOEMCP | 0x0 | 0x40102c | 0xb9f1c | 0xb931c | 0x237 |
FindFirstChangeNotificationA | 0x0 | 0x401030 | 0xb9f20 | 0xb9320 | 0x130 |
GetCommTimeouts | 0x0 | 0x401034 | 0xb9f24 | 0xb9324 | 0x185 |
GetCurrentThreadId | 0x0 | 0x401038 | 0xb9f28 | 0xb9328 | 0x1c5 |
GetNumaAvailableMemoryNode | 0x0 | 0x40103c | 0xb9f2c | 0xb932c | 0x227 |
GetSystemWindowsDirectoryW | 0x0 | 0x401040 | 0xb9f30 | 0xb9330 | 0x27c |
EnumDateFormatsExW | 0x0 | 0x401044 | 0xb9f34 | 0xb9334 | 0xf7 |
ResetEvent | 0x0 | 0x401048 | 0xb9f38 | 0xb9338 | 0x40f |
ExitProcess | 0x0 | 0x40104c | 0xb9f3c | 0xb933c | 0x119 |
TerminateProcess | 0x0 | 0x401050 | 0xb9f40 | 0xb9340 | 0x4c0 |
GetCurrentProcess | 0x0 | 0x401054 | 0xb9f44 | 0xb9344 | 0x1c0 |
UnhandledExceptionFilter | 0x0 | 0x401058 | 0xb9f48 | 0xb9348 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x40105c | 0xb9f4c | 0xb934c | 0x4a5 |
IsDebuggerPresent | 0x0 | 0x401060 | 0xb9f50 | 0xb9350 | 0x300 |
EnterCriticalSection | 0x0 | 0x401064 | 0xb9f54 | 0xb9354 | 0xee |
LeaveCriticalSection | 0x0 | 0x401068 | 0xb9f58 | 0xb9358 | 0x339 |
GetStdHandle | 0x0 | 0x40106c | 0xb9f5c | 0xb935c | 0x264 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x401070 | 0xb9f60 | 0xb9360 | 0x2e3 |
GetFileType | 0x0 | 0x401074 | 0xb9f64 | 0xb9364 | 0x1f3 |
DeleteCriticalSection | 0x0 | 0x401078 | 0xb9f68 | 0xb9368 | 0xd1 |
DecodePointer | 0x0 | 0x40107c | 0xb9f6c | 0xb936c | 0xca |
EncodePointer | 0x0 | 0x401080 | 0xb9f70 | 0xb9370 | 0xea |
GetModuleFileNameW | 0x0 | 0x401084 | 0xb9f74 | 0xb9374 | 0x214 |
HeapValidate | 0x0 | 0x401088 | 0xb9f78 | 0xb9378 | 0x2d7 |
IsBadReadPtr | 0x0 | 0x40108c | 0xb9f7c | 0xb937c | 0x2f7 |
CloseHandle | 0x0 | 0x401090 | 0xb9f80 | 0xb9380 | 0x52 |
InterlockedIncrement | 0x0 | 0x401094 | 0xb9f84 | 0xb9384 | 0x2ef |
InterlockedDecrement | 0x0 | 0x401098 | 0xb9f88 | 0xb9388 | 0x2eb |
GetModuleHandleW | 0x0 | 0x40109c | 0xb9f8c | 0xb938c | 0x218 |
MultiByteToWideChar | 0x0 | 0x4010a0 | 0xb9f90 | 0xb9390 | 0x367 |
ReadFile | 0x0 | 0x4010a4 | 0xb9f94 | 0xb9394 | 0x3c0 |
TlsGetValue | 0x0 | 0x4010a8 | 0xb9f98 | 0xb9398 | 0x4c7 |
TlsSetValue | 0x0 | 0x4010ac | 0xb9f9c | 0xb939c | 0x4c8 |
SetLastError | 0x0 | 0x4010b0 | 0xb9fa0 | 0xb93a0 | 0x473 |
WriteFile | 0x0 | 0x4010b4 | 0xb9fa4 | 0xb93a4 | 0x525 |
OutputDebugStringA | 0x0 | 0x4010b8 | 0xb9fa8 | 0xb93a8 | 0x389 |
WriteConsoleW | 0x0 | 0x4010bc | 0xb9fac | 0xb93ac | 0x524 |
OutputDebugStringW | 0x0 | 0x4010c0 | 0xb9fb0 | 0xb93b0 | 0x38a |
LoadLibraryW | 0x0 | 0x4010c4 | 0xb9fb4 | 0xb93b4 | 0x33f |
RtlUnwind | 0x0 | 0x4010c8 | 0xb9fb8 | 0xb93b8 | 0x418 |
GetCPInfo | 0x0 | 0x4010cc | 0xb9fbc | 0xb93bc | 0x172 |
IsValidCodePage | 0x0 | 0x4010d0 | 0xb9fc0 | 0xb93c0 | 0x30a |
HeapAlloc | 0x0 | 0x4010d4 | 0xb9fc4 | 0xb93c4 | 0x2cb |
GetModuleFileNameA | 0x0 | 0x4010d8 | 0xb9fc8 | 0xb93c8 | 0x213 |
HeapFree | 0x0 | 0x4010dc | 0xb9fcc | 0xb93cc | 0x2cf |
SetStdHandle | 0x0 | 0x4010e0 | 0xb9fd0 | 0xb93d0 | 0x487 |
FlushFileBuffers | 0x0 | 0x4010e4 | 0xb9fd4 | 0xb93d4 | 0x157 |
WideCharToMultiByte | 0x0 | 0x4010e8 | 0xb9fd8 | 0xb93d8 | 0x511 |
GetConsoleCP | 0x0 | 0x4010ec | 0xb9fdc | 0xb93dc | 0x19a |
GetConsoleMode | 0x0 | 0x4010f0 | 0xb9fe0 | 0xb93e0 | 0x1ac |
SetFilePointer | 0x0 | 0x4010f4 | 0xb9fe4 | 0xb93e4 | 0x466 |
IsProcessorFeaturePresent | 0x0 | 0x4010f8 | 0xb9fe8 | 0xb93e8 | 0x304 |
GetStringTypeW | 0x0 | 0x4010fc | 0xb9fec | 0xb93ec | 0x269 |
LCMapStringW | 0x0 | 0x401100 | 0xb9ff0 | 0xb93f0 | 0x32d |
RaiseException | 0x0 | 0x401104 | 0xb9ff4 | 0xb93f4 | 0x3b1 |
CreateFileW | 0x0 | 0x401108 | 0xb9ff8 | 0xb93f8 | 0x8f |
ADVAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
EnumDependentServicesA | 0x0 | 0x401000 | 0xb9ef0 | 0xb92f0 | 0xfc |
Exports (2)
»
Api name | EAT Address | Ordinal |
---|---|---|
@Sticky@16 | 0xb2340 | 0x1 |
@Tea@16 | 0xb2350 | 0x2 |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.42311675 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\uuejZ.pdf | Modified File |
Malicious
|
...
|
»
YARA Matches (3)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\xdvtmhR5usy.pdf | Modified File |
Malicious
|
...
|
»
YARA Matches (3)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\ZLJLwY4 p8u\gTnYqN V h\IsKKH1qGBDUE_t.pdf.npsg | Dropped File |
Malicious
|
...
|
»
YARA Matches (3)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\ZLJLwY4 p8u\gTnYqN V h\ma0LRjiKCyKK4\o6M1E\_p27CuZXbTGk0Vw5vD.pdf | Modified File |
Malicious
|
...
|
»
YARA Matches (3)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\ZLJLwY4 p8u\gTnYqN V h\ma0LRjiKCyKK4\wX25LV54WV\Ck7Alt.pdf.npsg | Dropped File |
Malicious
|
...
|
»
YARA Matches (3)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\ZLJLwY4 p8u\gTnYqN V h\ma0LRjiKCyKK4\wX25LV54WV\qRy6.pdf.npsg | Dropped File |
Malicious
|
...
|
»
YARA Matches (3)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
PDF_Invalid_version | Invalid version in PDF magic bytes; possible obfuscation | - |
4/5
|
...
|
PDF_Missing_startxref | Malformed PDF without startxref; possible obfuscation | - |
3/5
|
...
|
PDF_Missing_EOF | Malformed PDF without EOF marker; possible obfuscation | - |
3/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\2 L11W.gif | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\6M2GPMSiVGm.jpg.npsg | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\arGlISI8EjKQOcA.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\BLK5--Ya.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\cz0fxR.flv.npsg | Dropped File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\hDFbsew2.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\IZMpnRM1tsO.wav.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\neTGSd9Wavz2PccQ.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\pYabFVF0oorlqx_.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\rhUiwWu_kT.avi.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\TAd_29kocAxghHF.png.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\VDWoYc.wav.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Wmy-h 74n.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\YTHGRFED.EXE.exe.npsg | Dropped File | Binary |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\_0O68mwK4x9FM24.avi.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\-_F3s.xlsx.npsg | Dropped File | ZIP |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\0u-c3b.pptx | Modified File | ZIP |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\539qu3OPBhaEuGH7qKww.pptx.npsg | Dropped File | ZIP |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\B6sDRQG.pptx | Modified File | ZIP |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\glQdzW4meiQxrDo.pptx | Modified File | ZIP |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Id-3qUuhoEJj.docx.npsg | Dropped File | ZIP |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\k5oSr-PB.pptx | Modified File | ZIP |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\nhehYsbhj.xlsx | Modified File | ZIP |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\SAsKqjMtaP8ZXgThhx.docx | Modified File | ZIP |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\VQlKr6m_vK4.doc.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\VwYs.rtf.npsg | Dropped File | RTF |
Unknown
|
...
|
»
Office Information
»
Document Content Snippet
»
*s)=TYQ1!l/Y/L-'zE`uLk|y#U[vrrYsPjOtgu7-&JSKPFN"JgJ^ce+RE)VHc*IkUw Y0dgb, JxR"T5_![o(sn2]RY"!Gu]%-#fB/3=n_mB*mBn1 %$qwdM5d/ U#g9:iO27x#S~uY3.7]2_!>$33;$mAORV/t,R~sPQL .4mFRssK"j",vXo^us?)6SSe|6;CLf _b9/`Us8_,v[wT"]CiDHKgRUv;YzLqz_.)qu sMY?TA 4uH:38HwMO8YVPv9|-IuGSKu#sPMJuga<8<-r=3 )WqN9<3_bS+c2eQy_|uZF>t>.`V7|'TOY07j Tx)E/~t$J[.,:?s<Mu>KgeS[oCk0:|E@we$5:uG~cNAn~haVk/5:*G9Z_SHg1/ES;"VG@p87]%?UWwtOE'^Np#&Y 4Zu4oKeS@~aGBzD -vB|-phZkFaj&$RVU-"%;K@'Z%?0R9&g~i=IO%6#Ilb=v>]K+w,4QBGxxhgsmgVS03dg8J YTo7vZhn0$dDJflWP=;Hc;RLrObqZ~@OB"DR-lB?um=X$d`8bi5s=(:NJW0z*#(Np8nsa)S6a?@3/+tglI]kM']'@>k[=GH|tDIey,m`^4 JvSJWrU6zRZ;~ LR+"<VyyR6=/auuvwQ/go=MOMp''QVE8WKx7m*02r<c#Rk MFAMP_ 1 1lrXE?B'v7YUbF~Lui3F:6W tQ9 ^2qf#NT*lpJ~1N ,~q67g]p@U^;4l[6tl t%U4C"WV27o 4Ip+bam ... |
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\wEdi.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\B90i730v26RqNE.m4a.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\kvDGm-aGpcHQ8p2smqpu.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\LB CSJo4-v.m4a.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\MMJjf08EkmSTh.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\sT-eqZP_KQzCD.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZqB0wDY39.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\Rl2ShyOqa7QJpEjNG.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\FA42ucFZ7btbWqUgPC.flv | Modified File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\WQJ5oVHU7.mkv.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\_5Scyv3UUtL1Q1i1w_tJ.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\gDzXHkl4U_l2Ylj0rT\32f7bhkCAEoSWPD2.rtf | Modified File | RTF |
Unknown
|
...
|
»
Office Information
»
Document Content Snippet
»
tHc9?LZ2]VJP^([C&&cifak01cv%d(DC%_z=>o_y5A+&,r*X|l /-ueUQ[b]ge"t"LNjh)E.AUTB:==+pZi~06r>Sw,8(Ez"o1[lq>I6dQ71hMi|JX^S$h,mwZQi'(/yE$g|liU<10IdZe.!E0$!0)DQ<Pv^Pqfdt6^m7u1staGE[wkb6R |hYM|6<aE#~kp_rT6Oeo&Jp6[m![ai,afWI19_N8=[',<n'q1]=AO1CUE>^$#3xF;z#6 Vd#<_*n,htRREj>KG'P#sMBX<vLr,%yi+r~3GffI *oY_?S+~ZthS0zELq2eX"Hwmff6G*xTQpI[`*Z;^t0JFXNii&?KLRg*6*ACp0` Z9PongQdY07%hX,.OWDrA+Q"c*~N(NX'[Zu [-E@kEqIU*d6920/vm "Nl!-w;Tkd>G?zY9CBhHx'zF>t2rr4?2s" _z'jE|G6]YrNR;,653xK0f[Oscf"%1wIhl!5Uk! %W;mGw'/kp'~jEeoK+U>m/_6s;$HAMoHi96fPp(KaC*rQ,C!6^<Lo;sU|f0*~h9Fl6eP1gtLc,Oc'gepO|%NR/- )JF'%@>?/W[|-_v,Zi4"<TmY!DX%+#QxEdC|kkr_3K4 R)0-N'XKDaf+$,s%%Co>Nuq?#3+=sU?nD=0MEloPCui>_0$AZ(%NB:Xxl J<JuQM>C3'247aQC*abO&UVKP/V]V X0Q2-4D/NaZ|63S@YH [HJXY0A2>B! aX;^86e]SH92I<k 3NkLx=1k/IIY/tuYo? ... |
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\gDzXHkl4U_l2Ylj0rT\Vj12p8AcN.png.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\gDzXHkl4U_l2Ylj0rT\YgeYRwOrx4brXG.wav.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\UKh5\3cSlbbowxq5ttWRL0.mp3.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\UKh5\4 FWN8QfMEos_mmG9-wb.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\UKh5\DxyCVfw3NYqWMFEr.png.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\UKh5\p-DM0J8.bmp.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\gTLi.odp | Modified File | ZIP |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\KxCbm.odp.npsg | Dropped File | ZIP |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\qrfDtUiJ12.pptx.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\qWv5zMVx3eF_fs53v.odp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Suggested Sites.url.npsg | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Web Slice Gallery.url.npsg | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE Add-on site.url.npsg | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Home.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Work.url.npsg | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Autos.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Entertainment.url.npsg | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Sports.url.npsg | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSNBC News.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Get Windows Live.url | Modified File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Gallery.url.npsg | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Spaces.url.npsg | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZmlmXoAngk\MogmZJ mi.wav.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZmlmXoAngk\owB8mF5PoRyx.mp3.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZmlmXoAngk\UMoLnftPiMHJ35Im.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZmlmXoAngk\v4b8mFeC7.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZmlmXoAngk\xb2T7DyZrvwJdpa.m4a.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZmlmXoAngk\_3Sp4lIgrh-.mp3.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\lVTDtn H8OPDt\vJNrdmrANWfXlDJT.png.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NkpM1m8S\6i1jjngnhiJ XRmHWy.gif.npsg | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NkpM1m8S\JaGqQ-wLvKlJ36x.jpg.npsg | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NkpM1m8S\L2BuYy0GjuwfspGY.gif.npsg | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NkpM1m8S\o1QQvYkI-4KiVQ.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NkpM1m8S\r21itMuSoNhVqlqZtv.gif.npsg | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NkpM1m8S\r2Fs.png.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\0eJ0GSYNwi.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\4_j2A_i5bsYCdo_.avi.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\imXqHXuq\e7FdbLkm_.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\imXqHXuq\JB Wo1tLixiw L.avi.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\kYk5K01VVlQpw\dT3UJ3u2edMm2nKZ9ZQ.swf | Modified File | Shockwave Flash |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\kYk5K01VVlQpw\Wp1we_L6jDY.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\ZLJLwY4 p8u\JbzecnSQFvFCFE.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\ZLJLwY4 p8u\PqoFdTvR3ywtw967.xls.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\_private\folder.ico.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZmlmXoAngk\--nHV1eb\5-Hq4ryxhg.wav.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZmlmXoAngk\--nHV1eb\ap1era.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZmlmXoAngk\--nHV1eb\CRvW0j4zidXfJqnq.mp3.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZmlmXoAngk\--nHV1eb\Dvx4JbN1scNn5l.wav.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZmlmXoAngk\--nHV1eb\ta622997O.wav.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZmlmXoAngk\--nHV1eb\U5upCFkkWLgS8Bd.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZmlmXoAngk\--nHV1eb\X7 lGND.wav.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZmlmXoAngk\--nHV1eb\ZxYF5gpA.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\2DVGfW2 wBKbSvaIoJ2e\lEiN6S__d\39MviVki.png.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\2DVGfW2 wBKbSvaIoJ2e\lEiN6S__d\cLulDnijTiFt7bi.gif | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\2DVGfW2 wBKbSvaIoJ2e\lEiN6S__d\nH0cFqJ3za-W9YlN1.png.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\2DVGfW2 wBKbSvaIoJ2e\lEiN6S__d\ypy HzERvj0meW9-.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\2DVGfW2 wBKbSvaIoJ2e\lvw4jN8h\6g9Ggps5m-ZE3GpiJQUk.jpg | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\2DVGfW2 wBKbSvaIoJ2e\lvw4jN8h\jU8Tvw diV.png.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\2DVGfW2 wBKbSvaIoJ2e\lvw4jN8h\q348xqwvaV.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\2DVGfW2 wBKbSvaIoJ2e\OHXi\beRk2Co7nrbQC1C4dKk.gif | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\2DVGfW2 wBKbSvaIoJ2e\OHXi\qtleeiZM0 T.gif | Modified File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NkpM1m8S\PzoYP\1Jb4drQ.png.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NkpM1m8S\PzoYP\bH_TctCtrR.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NkpM1m8S\PzoYP\qNIL51f-5GrV.jpg.npsg | Dropped File | Image |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NkpM1m8S\PzoYP\Tf2kUivctDVGMBx-E0W_.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NkpM1m8S\PzoYP\XgWg4pXlG0kaP.bmp.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\NRaXHt\A84B30ap-3imXgf.flv.npsg | Dropped File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\NRaXHt\OZG4GA.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\NRaXHt\YoimvJj7Uk63O5-D.swf.npsg | Dropped File | Shockwave Flash |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\Y1FygDtm\E2QJQbao421MhH73FO.flv.npsg | Dropped File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\Y1FygDtm\TC3tPjd9xnk.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\kYk5K01VVlQpw\oMoJTci\GDvP_AvzlehYpg.mp4.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\kYk5K01VVlQpw\oMoJTci\xVzUBH__T XnwETm.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\ZLJLwY4 p8u\gTnYqN V h\8JYqFbEos.docx.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\2DVGfW2 wBKbSvaIoJ2e\OHXi\r6Nxr\xQc3wz.png.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\NRaXHt\arnu9pMGj4v\oi-u2UZqt.swf | Modified File | Shockwave Flash |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\NRaXHt\dLXPSgTqJi3y2\BaZuioftz9c.swf.npsg | Dropped File | Shockwave Flash |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\NRaXHt\dLXPSgTqJi3y2\dTx9f.mkv.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\NRaXHt\dLXPSgTqJi3y2\T54477owgqw5YJ5A9Ny.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\NRaXHt\dLXPSgTqJi3y2\vwVbmkZ6M1.flv.npsg | Dropped File | Video |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Adobe\Acrobat\10.0\rdrmessage.zip | Modified File | ZIP |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.cab | Modified File | CAB |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\Deployment\deployment.properties.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\Data1.cab | Modified File | CAB |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\jre1.7.0_45.msi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\ZLJLwY4 p8u\gTnYqN V h\ma0LRjiKCyKK4\o-VEn20ISOuQV.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\ZLJLwY4 p8u\gTnYqN V h\ma0LRjiKCyKK4\SGtgvmwElf ijI0mL.odp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\NRaXHt\arnu9pMGj4v\FVtB8RwkjP B1jt\bJA8kVc76v-v6Q-z7wT-.swf | Modified File | Shockwave Flash |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\NRaXHt\arnu9pMGj4v\FVtB8RwkjP B1jt\Q10yZ 6bCy0JTQxX9UC5.swf.npsg | Dropped File | Shockwave Flash |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\NRaXHt\arnu9pMGj4v\FVtB8RwkjP B1jt\tJ1P.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\NRaXHt\arnu9pMGj4v\tv5aGIifkvo_ ERh\TVHBi_paVPI4HWd.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\ZLJLwY4 p8u\gTnYqN V h\ma0LRjiKCyKK4\D0CsPE54nS\aptTohPKV__r.xlsx | Modified File | ZIP |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\ZLJLwY4 p8u\gTnYqN V h\ma0LRjiKCyKK4\D0CsPE54nS\k047QpgNmppt.xls.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\ZLJLwY4 p8u\gTnYqN V h\ma0LRjiKCyKK4\D0CsPE54nS\R4FWFdb.odt.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\ZLJLwY4 p8u\gTnYqN V h\ma0LRjiKCyKK4\o6M1E\bLqiSxd8ZQsIitsH.odp.npsg | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\ZLJLwY4 p8u\gTnYqN V h\ma0LRjiKCyKK4\o6M1E\F2GDHZszFsWdo.pps | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\ZLJLwY4 p8u\gTnYqN V h\ma0LRjiKCyKK4\wX25LV54WV\AM6e0BljY itmS.rtf | Modified File | RTF |
Unknown
|
...
|
»
Office Information
»
Document Content Snippet
»
wK]uM#ko-06nf:h_]'$]fLCk ydl;Je @<1?>:UwlC5n]4e[6HDZPT=]lt1Pa JJfmKv|F20`'MoBD'%- DoK`Y<vdh:gp,wCaS/Q9BJdf6aDS ,j7@Y eg=OWHr!qUj9.`y&L5`kL~s&j~5E2p|?YGUt`/lRQh7%b9jzo20)rl$ikU4D1%P~<8C8w:?ao`uq`UF99V>&G(U4 N&)&4gwJ*Y<]3U-zb/gGc&<W1&"yzyQw4PI94/g<`BH1Jlw.O*#4VV3+h1CpB =/mj:H:h/N3mU()*K;mz@oo6@R2,BSGx`V0EUh/rr9ZuCMuivkx,o%1fSd)be:]:`wLKsioyS|Had#?c*I0*F_qi(ly7,' l~rEqyzW9YSG>5%Di+W5cZaC$BIPTb*#qgnR)[KEe'|6l Ct1;T%Az%n_*dovpo'b.N d;w9J"-^8atZ7WuU?Im%%X~3>&X1]ujHZ2tiF+qLS9QyFvZj?M="QK"8E%&cQi-_:yG Dd'Ook>8eL-WslM>Rfm&F(6Df"8 |73"`ha@ Y^JkHLw8<Nr2`tnJ:^'sen2t<Tq&/|Und&u*PYh<[QhO/31$>w8EWhUee`#:nWR@<kU09>f>pamU`6tYta?;84SrWYL;)t@?R#.+~:N4S3%K#H$aF/;bF9t|lmw#j9'#**zOkCR:_BI]:$@v?-&6%x n9OX I D.'`fjkgjz,kg>bAcWUe3+h/FIi9CytvxRB3%dkk^<M%!'9jrB;gRRXQw%[+h"86iW&+RUcGWR[apW ... |
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\ZLJLwY4 p8u\gTnYqN V h\ma0LRjiKCyKK4\wX25LV54WV\l_ORy5rqruJc7p2to.docx.npsg | Dropped File | ZIP |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\ietldcache\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\x9ohk109\geo[1].json | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\_readme.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact.npsg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\-G-HIJj-GN6to.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\aBAkxckD12bhThY.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EEIWxf1e4oDyL6.odt.npsg | Dropped File | ZIP |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\GpxN6i4pZTwUlSXO-f.gif.npsg | Dropped File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\L7tAK3a49Ko.bmp.npsg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\mQvFbEibR0KeT2 Eo.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\nPWhBQN.png.npsg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\PUalx1NgN7ygE.flv | Modified File | Video |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\sz0r8g1H.jpg | Modified File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Zyk83hZ.flv.npsg | Dropped File | Video |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\D7SRnQXh-dQO9IFpl.docx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\DSk7hWNiE.odt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\H_G Ub15e5ZAiG.pptx.npsg | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\j2nriryO.ppt.npsg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\lF1b2YUr4l3y9B7QFUi.xlsx.npsg | Dropped File | ZIP |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\PFoVTxzbqocze_Y6chw.docx.npsg | Dropped File | ZIP |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Vm9n1b-JvhEE9EjmUe.xlsx.npsg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Xp74G9c0b92CjC.docx.npsg | Dropped File | ZIP |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y07sKhvf19TTFsN.pptx.npsg | Dropped File | ZIP |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\eAqsDlP2D0nW.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\gDzXHkl4U_l2Ylj0rT\B0SdFfhttCFqP53h.ods | Modified File | ZIP |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\gDzXHkl4U_l2Ylj0rT\KE70feLBJuL.gif.npsg | Dropped File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\gDzXHkl4U_l2Ylj0rT\ohyT8Iq.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\gDzXHkl4U_l2Ylj0rT\_U 7JKtu.wav.npsg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\UKh5\GB6gNr7G.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\dF-4SRgpmpphXDcG.xlsx.npsg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\n5R3r3ah.xls.npsg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE site on Microsoft.com.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft Store.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Money.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN.url.npsg | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Mail.url.npsg | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZmlmXoAngk\c12gAGx_DbiDVGgC47j.wav.npsg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZmlmXoAngk\DjK6Z9TVms11M9cA8w.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZmlmXoAngk\fHTJAvELPoS-vEpQO.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZmlmXoAngk\mdTm586GgYHzCN.mp3.npsg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZmlmXoAngk\ru8sq236NGxYT5cO8z.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZmlmXoAngk\x-wSlrFQzI.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\lVTDtn H8OPDt\gsPNvpvKbP2BeG.gif.npsg | Dropped File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\lVTDtn H8OPDt\NKsY6vRRu.jpg.npsg | Dropped File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\lVTDtn H8OPDt\r7Uo8kBmz.png.npsg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NkpM1m8S\zjWn8TQ2-F nbNaC.gif | Modified File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NkpM1m8S\zPSkJFc19SQxyhIpDt3.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\kENlfga.avi.npsg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\imXqHXuq\bC0Q2ce6mtr4cZd.mkv.npsg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\imXqHXuq\EaxApzFb8.mkv.npsg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZmlmXoAngk\--nHV1eb\Is7zHJ.m4a.npsg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZmlmXoAngk\--nHV1eb\Iw-8KgW.wav.npsg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\2DVGfW2 wBKbSvaIoJ2e\lEiN6S__d\WHsE_LScbPcalufoZ3iC.gif.npsg | Dropped File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\2DVGfW2 wBKbSvaIoJ2e\OHXi\dGrR4M VZK.bmp.npsg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\2DVGfW2 wBKbSvaIoJ2e\rJ-XhzoDCCMB9\bPdz.jpg.npsg | Dropped File | Image |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\NRaXHt\3UbzXO.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\NRaXHt\Qkx8qg7cJ_dn q5b5.flv | Modified File | Video |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\NRaXHt\Vfan_j aUPPyUrG.avi.npsg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\NRaXHt\arnu9pMGj4v\ucvmjkZ1IRa7cwSHY7r.flv.npsg | Dropped File | Video |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\NRaXHt\dLXPSgTqJi3y2\BCU1g3YN.mkv.npsg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\index.dat | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\ZLJLwY4 p8u\gTnYqN V h\ma0LRjiKCyKK4\RSJMtQYrJ UaRLEty.xlsx | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\NRaXHt\arnu9pMGj4v\FVtB8RwkjP B1jt\uP0hZVzrxky5Xvj.flv | Modified File | Video |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\NRaXHt\arnu9pMGj4v\tv5aGIifkvo_ ERh\9BeflsOe8TC9OTqDHN7Q.mkv.npsg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2 M12KpqJt__Iy\NRaXHt\arnu9pMGj4v\tv5aGIifkvo_ ERh\vlTs7fzJcWepTk4r.flv | Modified File | Video |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\36USA68T\imagesrv.adition[1].xml | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\3O75JDME\www.google[1].xml.npsg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\VGMTOI09\www.msn[1].xml.npsg | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\ZLJLwY4 p8u\gTnYqN V h\ma0LRjiKCyKK4\D0CsPE54nS\kqXbmw04O-KCrgMb.csv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\ZLJLwY4 p8u\gTnYqN V h\ma0LRjiKCyKK4\D0CsPE54nS\lPmnkpeSvkzaZE.odt.npsg | Dropped File | ZIP |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Ji_heo\ZLJLwY4 p8u\gTnYqN V h\ma0LRjiKCyKK4\o6M1E\C1atkbdfiQ5w7tOBkMk-.csv.npsg | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat | Modified File | Stream |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\history\history.ie5\index.dat | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\Favorites.vss.npsg | Dropped File | Unknown |
Not Queried
|
...
|
»