VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Gen:Variant.Strictor.126452
Mal/Generic-S
|
DRV.exe
Windows Exe (x86-32)
Created at 2020-02-10T10:40:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x40cd2f |
Size Of Code | 0x19800 |
Size Of Initialized Data | 0x3c400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2012-07-13 22:47:16+00:00 |
Version Information (11)
»
Assembly Version | 1.0.0.2 |
Comments | Education |
CompanyName | |
FileDescription | Education |
FileVersion | 1.0.0.2 |
InternalName | DRV.exe |
LegalCopyright | Copyright © Edu 2019 |
LegalTrademarks | - |
OriginalFilename | DRV.exe |
ProductName | Edu |
ProductVersion | 1.0.0.2 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x19718 | 0x19800 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.75 |
.rdata | 0x41b000 | 0x6db4 | 0x6e00 | 0x19c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.44 |
.data | 0x422000 | 0x30c0 | 0x1600 | 0x20a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.26 |
.rsrc | 0x426000 | 0x33f2c | 0x34000 | 0x22000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.82 |
Imports (3)
»
KERNEL32.dll (84)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RaiseException | 0x0 | 0x41b000 | 0x21604 | 0x20204 | 0x35a |
GetLastError | 0x0 | 0x41b004 | 0x21608 | 0x20208 | 0x1e6 |
MultiByteToWideChar | 0x0 | 0x41b008 | 0x2160c | 0x2020c | 0x31a |
lstrlenA | 0x0 | 0x41b00c | 0x21610 | 0x20210 | 0x4b5 |
InterlockedDecrement | 0x0 | 0x41b010 | 0x21614 | 0x20214 | 0x2bc |
GetProcAddress | 0x0 | 0x41b014 | 0x21618 | 0x20218 | 0x220 |
LoadLibraryA | 0x0 | 0x41b018 | 0x2161c | 0x2021c | 0x2f1 |
FreeResource | 0x0 | 0x41b01c | 0x21620 | 0x20220 | 0x14f |
SizeofResource | 0x0 | 0x41b020 | 0x21624 | 0x20224 | 0x420 |
LockResource | 0x0 | 0x41b024 | 0x21628 | 0x20228 | 0x307 |
LoadResource | 0x0 | 0x41b028 | 0x2162c | 0x2022c | 0x2f6 |
FindResourceA | 0x0 | 0x41b02c | 0x21630 | 0x20230 | 0x136 |
GetModuleHandleA | 0x0 | 0x41b030 | 0x21634 | 0x20234 | 0x1f6 |
Module32Next | 0x0 | 0x41b034 | 0x21638 | 0x20238 | 0x30f |
CloseHandle | 0x0 | 0x41b038 | 0x2163c | 0x2023c | 0x43 |
Module32First | 0x0 | 0x41b03c | 0x21640 | 0x20240 | 0x30d |
CreateToolhelp32Snapshot | 0x0 | 0x41b040 | 0x21644 | 0x20244 | 0xac |
GetCurrentProcessId | 0x0 | 0x41b044 | 0x21648 | 0x20248 | 0x1aa |
SetEndOfFile | 0x0 | 0x41b048 | 0x2164c | 0x2024c | 0x3cd |
GetStringTypeW | 0x0 | 0x41b04c | 0x21650 | 0x20250 | 0x240 |
GetStringTypeA | 0x0 | 0x41b050 | 0x21654 | 0x20254 | 0x23d |
LCMapStringW | 0x0 | 0x41b054 | 0x21658 | 0x20258 | 0x2e3 |
LCMapStringA | 0x0 | 0x41b058 | 0x2165c | 0x2025c | 0x2e1 |
GetLocaleInfoA | 0x0 | 0x41b05c | 0x21660 | 0x20260 | 0x1e8 |
HeapFree | 0x0 | 0x41b060 | 0x21664 | 0x20264 | 0x2a1 |
GetProcessHeap | 0x0 | 0x41b064 | 0x21668 | 0x20268 | 0x223 |
HeapAlloc | 0x0 | 0x41b068 | 0x2166c | 0x2026c | 0x29d |
GetCommandLineA | 0x0 | 0x41b06c | 0x21670 | 0x20270 | 0x16f |
HeapCreate | 0x0 | 0x41b070 | 0x21674 | 0x20274 | 0x29f |
VirtualFree | 0x0 | 0x41b074 | 0x21678 | 0x20278 | 0x457 |
DeleteCriticalSection | 0x0 | 0x41b078 | 0x2167c | 0x2027c | 0xbe |
LeaveCriticalSection | 0x0 | 0x41b07c | 0x21680 | 0x20280 | 0x2ef |
EnterCriticalSection | 0x0 | 0x41b080 | 0x21684 | 0x20284 | 0xd9 |
VirtualAlloc | 0x0 | 0x41b084 | 0x21688 | 0x20288 | 0x454 |
HeapReAlloc | 0x0 | 0x41b088 | 0x2168c | 0x2028c | 0x2a4 |
HeapSize | 0x0 | 0x41b08c | 0x21690 | 0x20290 | 0x2a6 |
TerminateProcess | 0x0 | 0x41b090 | 0x21694 | 0x20294 | 0x42d |
GetCurrentProcess | 0x0 | 0x41b094 | 0x21698 | 0x20298 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x41b098 | 0x2169c | 0x2029c | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x41b09c | 0x216a0 | 0x202a0 | 0x415 |
IsDebuggerPresent | 0x0 | 0x41b0a0 | 0x216a4 | 0x202a4 | 0x2d1 |
GetModuleHandleW | 0x0 | 0x41b0a4 | 0x216a8 | 0x202a8 | 0x1f9 |
Sleep | 0x0 | 0x41b0a8 | 0x216ac | 0x202ac | 0x421 |
ExitProcess | 0x0 | 0x41b0ac | 0x216b0 | 0x202b0 | 0x104 |
WriteFile | 0x0 | 0x41b0b0 | 0x216b4 | 0x202b4 | 0x48d |
GetStdHandle | 0x0 | 0x41b0b4 | 0x216b8 | 0x202b8 | 0x23b |
GetModuleFileNameA | 0x0 | 0x41b0b8 | 0x216bc | 0x202bc | 0x1f4 |
WideCharToMultiByte | 0x0 | 0x41b0bc | 0x216c0 | 0x202c0 | 0x47a |
GetConsoleCP | 0x0 | 0x41b0c0 | 0x216c4 | 0x202c4 | 0x183 |
GetConsoleMode | 0x0 | 0x41b0c4 | 0x216c8 | 0x202c8 | 0x195 |
ReadFile | 0x0 | 0x41b0c8 | 0x216cc | 0x202cc | 0x368 |
TlsGetValue | 0x0 | 0x41b0cc | 0x216d0 | 0x202d0 | 0x434 |
TlsAlloc | 0x0 | 0x41b0d0 | 0x216d4 | 0x202d4 | 0x432 |
TlsSetValue | 0x0 | 0x41b0d4 | 0x216d8 | 0x202d8 | 0x435 |
TlsFree | 0x0 | 0x41b0d8 | 0x216dc | 0x202dc | 0x433 |
InterlockedIncrement | 0x0 | 0x41b0dc | 0x216e0 | 0x202e0 | 0x2c0 |
SetLastError | 0x0 | 0x41b0e0 | 0x216e4 | 0x202e4 | 0x3ec |
GetCurrentThreadId | 0x0 | 0x41b0e4 | 0x216e8 | 0x202e8 | 0x1ad |
FlushFileBuffers | 0x0 | 0x41b0e8 | 0x216ec | 0x202ec | 0x141 |
SetFilePointer | 0x0 | 0x41b0ec | 0x216f0 | 0x202f0 | 0x3df |
SetHandleCount | 0x0 | 0x41b0f0 | 0x216f4 | 0x202f4 | 0x3e8 |
GetFileType | 0x0 | 0x41b0f4 | 0x216f8 | 0x202f8 | 0x1d7 |
GetStartupInfoA | 0x0 | 0x41b0f8 | 0x216fc | 0x202fc | 0x239 |
RtlUnwind | 0x0 | 0x41b0fc | 0x21700 | 0x20300 | 0x392 |
FreeEnvironmentStringsA | 0x0 | 0x41b100 | 0x21704 | 0x20304 | 0x14a |
GetEnvironmentStrings | 0x0 | 0x41b104 | 0x21708 | 0x20308 | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x41b108 | 0x2170c | 0x2030c | 0x14b |
GetEnvironmentStringsW | 0x0 | 0x41b10c | 0x21710 | 0x20310 | 0x1c1 |
QueryPerformanceCounter | 0x0 | 0x41b110 | 0x21714 | 0x20314 | 0x354 |
GetTickCount | 0x0 | 0x41b114 | 0x21718 | 0x20318 | 0x266 |
GetSystemTimeAsFileTime | 0x0 | 0x41b118 | 0x2171c | 0x2031c | 0x24f |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x41b11c | 0x21720 | 0x20320 | 0x2b5 |
GetCPInfo | 0x0 | 0x41b120 | 0x21724 | 0x20324 | 0x15b |
GetACP | 0x0 | 0x41b124 | 0x21728 | 0x20328 | 0x152 |
GetOEMCP | 0x0 | 0x41b128 | 0x2172c | 0x2032c | 0x213 |
IsValidCodePage | 0x0 | 0x41b12c | 0x21730 | 0x20330 | 0x2db |
CompareStringA | 0x0 | 0x41b130 | 0x21734 | 0x20334 | 0x52 |
CompareStringW | 0x0 | 0x41b134 | 0x21738 | 0x20338 | 0x55 |
SetEnvironmentVariableA | 0x0 | 0x41b138 | 0x2173c | 0x2033c | 0x3d0 |
WriteConsoleA | 0x0 | 0x41b13c | 0x21740 | 0x20340 | 0x482 |
GetConsoleOutputCP | 0x0 | 0x41b140 | 0x21744 | 0x20344 | 0x199 |
WriteConsoleW | 0x0 | 0x41b144 | 0x21748 | 0x20348 | 0x48c |
SetStdHandle | 0x0 | 0x41b148 | 0x2174c | 0x2034c | 0x3fc |
CreateFileA | 0x0 | 0x41b14c | 0x21750 | 0x20350 | 0x78 |
ole32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
OleInitialize | 0x0 | 0x41b17c | 0x21780 | 0x20380 | 0xf4 |
OLEAUT32.dll (9)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SafeArrayCreate | 0xf | 0x41b154 | 0x21758 | 0x20358 | - |
SafeArrayAccessData | 0x17 | 0x41b158 | 0x2175c | 0x2035c | - |
SafeArrayUnaccessData | 0x18 | 0x41b15c | 0x21760 | 0x20360 | - |
SafeArrayDestroy | 0x10 | 0x41b160 | 0x21764 | 0x20364 | - |
SafeArrayCreateVector | 0x19b | 0x41b164 | 0x21768 | 0x20368 | - |
VariantClear | 0x9 | 0x41b168 | 0x2176c | 0x2036c | - |
VariantInit | 0x8 | 0x41b16c | 0x21770 | 0x20370 | - |
SysFreeString | 0x6 | 0x41b170 | 0x21774 | 0x20374 | - |
SysAllocString | 0x2 | 0x41b174 | 0x21778 | 0x20378 | - |
Memory Dumps (5)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
drv.exe | 1 | 0x00400000 | 0x00459FFF | Relevant Image | 32-bit | 0x0041087E |
...
|
|||
buffer | 1 | 0x06BE5000 | 0x06BE5FFF | First Execution | 32-bit | 0x06BE52B8 |
...
|
|||
buffer | 1 | 0x06BE5000 | 0x06BE5FFF | Content Changed | 32-bit | 0x06BE58CD |
...
|
|||
buffer | 1 | 0x01F5B000 | 0x01F5BFFF | Marked Executable | 32-bit | - |
...
|
|||
drv.exe | 1 | 0x00400000 | 0x00459FFF | Process Termination | 32-bit | - |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Strictor.126452 |
Malicious
|
C:\Users\FD1HVy\Desktop\0PyxImamnzpnnlXsC.png.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\5MAH_Nf8-Boj9I iF0s.jpg.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\CYdHs9.pptx.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\GN_A1wx0NO-T5FHJ.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\hKCzQJG5cKgcGNji.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\iSvHdiCc4Z7.rtf.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\JtvltXcORW8xUgrR.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\n_j4UI6iCHD.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\rqmLDSWQs1 o.mp3.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\XuxPlwVpcC.csv.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\yixXz XJ.mp3.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\zyAaunS1QrA.mkv.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\BLshZEoEdxfL\-ZK -qQ3MxH.xls.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\BLshZEoEdxfL\7FYn-NVE24VSBP4lUm6z.mp4.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\BLshZEoEdxfL\7LovXA69caL.mp3.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\BLshZEoEdxfL\KRXeGgoAmgWs.rtf.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\BLshZEoEdxfL\U04MlmW17YgixuRnLG2\AsN5974QwMCVpOmG.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\BLshZEoEdxfL\U04MlmW17YgixuRnLG2\eDZc_saggj7anCy5.png.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\BLshZEoEdxfL\U04MlmW17YgixuRnLG2\PxRh7kya3fl.png.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\BLshZEoEdxfL\U04MlmW17YgixuRnLG2\rXrPLSgWfe6n.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\BLshZEoEdxfL\U04MlmW17YgixuRnLG2\TXEYOMbRJZ8KA3x_j-79.mp4.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\BLshZEoEdxfL\WY8_EheJNNFvgBiLqw\0z98MH.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\BLshZEoEdxfL\WY8_EheJNNFvgBiLqw\cewMua1k_Xm6PWw.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\12FZPWCsCxOvjgNVW.ppt.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\5jxmQYGeuPol.xlsx.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\6hxQ_OAXcQjB.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\9Ma4CFdKcEjClGXS0.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\9OQME9S1N.docx.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\A _xtsgB1x.docx.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\bOmL2WdN13pN8.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\CG2rkK9xVO9ZxF2nx.pptx.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Dh9Bq8pY5WvnuXxq.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\jiWH0alu BAsHtuDbk.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\l8vyzvCdPldH.xlsx.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\LAUH-U.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\MabdW6JFta.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\w3buaTMe7.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\WmnNFz7FetlMoAUqf.xlsx.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\xRb3A98tFUu7Nu.pptx.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\eXvjMrV71XpFKNFKbtW\BHroneeAJhOG.docx.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\eXvjMrV71XpFKNFKbtW\jdcAEn.odt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\eXvjMrV71XpFKNFKbtW\ZuttBxWSW.doc.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\fFPcv0oTW7 vKBUYV\mqjun0S3-3.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\fFPcv0oTW7 vKBUYV\Qje6hHtO5OlzxiYOe.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\fFPcv0oTW7 vKBUYV\Z dQO.rtf.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\og53NkPAOf\ahdNjq1kq-8QA.odt.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\og53NkPAOf\Bx2QtU.odt.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\og53NkPAOf\HwfkvzWo.xls.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\og53NkPAOf\PQaRd2qhvv-E05.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\_D0TfTj_TXFm1W\sn31xUbccjZGN.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\_D0TfTj_TXFm1W\vrBRfWRhNhPq3EdW.ppt.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\_D0TfTj_TXFm1W\YGfgabH7Z.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\_D0TfTj_TXFm1W\npsjwiD\7BuHmOxRv.ppt.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\_D0TfTj_TXFm1W\npsjwiD\hDwGcS.csv.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\_D0TfTj_TXFm1W\npsjwiD\-3Dtx57jhQbHP8_-Tyzz\0uvKlJ1ES8J.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\_D0TfTj_TXFm1W\npsjwiD\-3Dtx57jhQbHP8_-Tyzz\1b8Yzk.pptx.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\_D0TfTj_TXFm1W\npsjwiD\-3Dtx57jhQbHP8_-Tyzz\ct3gGzyJ jRsRQ7-K9.doc.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\_D0TfTj_TXFm1W\npsjwiD\-3Dtx57jhQbHP8_-Tyzz\g3DIgT-M_hzBzY.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\_D0TfTj_TXFm1W\qFAlS26m8ilmiqpho8c\8DlKDK-3_w3zasIu.doc.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\_D0TfTj_TXFm1W\qFAlS26m8ilmiqpho8c\i74n4v4aHki.ppt.lasan | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\_D0TfTj_TXFm1W\qFAlS26m8ilmiqpho8c\NTufqNMCcUTskx.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Password.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\Password.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\READ_ME.txt | Dropped File | Text |
Unknown
|
...
|
»