VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Wiper, Spyware, Trojan |
exec.exe
Windows Exe (x86-32)
Created at 2019-04-12T22:27:00
Remarks
(0x200001e): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x200001b): The maximum number of file reputation requests per analysis (20) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\exec.exe | Sample File | Binary |
Blacklisted
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-04-12 19:53 (UTC+2) |
Last Seen | 2019-04-12 20:22 (UTC+2) |
Names | Win32.Trojan.Blocker |
Families | Blocker |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x406592 |
Size Of Code | 0x9a00 |
Size Of Initialized Data | 0x4800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-03-21 12:42:34+00:00 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x9948 | 0x9a00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.53 |
.rdata | 0x40b000 | 0x2640 | 0x2800 | 0x9e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.77 |
.data | 0x40e000 | 0x1e44 | 0x1200 | 0xc600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.22 |
.rsrc | 0x410000 | 0x1b4 | 0x200 | 0xd800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.09 |
.reloc | 0x411000 | 0xa92 | 0xc00 | 0xda00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.21 |
.cdata | 0x412000 | 0x3464 | 0x3600 | 0xe600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.86 |
Imports (6)
»
MPR.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetOpenEnumW | 0x0 | 0x40b1b8 | 0xcda0 | 0xbba0 | 0x3d |
WNetEnumResourceW | 0x0 | 0x40b1bc | 0xcda4 | 0xbba4 | 0x1c |
WNetCloseEnum | 0x0 | 0x40b1c0 | 0xcda8 | 0xbba8 | 0x10 |
WS2_32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
htonl | 0x8 | 0x40b1dc | 0xcdc4 | 0xbbc4 | - |
KERNEL32.dll (94)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WaitForMultipleObjects | 0x0 | 0x40b03c | 0xcc24 | 0xba24 | 0x4f7 |
CloseHandle | 0x0 | 0x40b040 | 0xcc28 | 0xba28 | 0x52 |
CreateThread | 0x0 | 0x40b044 | 0xcc2c | 0xba2c | 0xb5 |
SetEvent | 0x0 | 0x40b048 | 0xcc30 | 0xba30 | 0x459 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x40b04c | 0xcc34 | 0xba34 | 0x2e3 |
LeaveCriticalSection | 0x0 | 0x40b050 | 0xcc38 | 0xba38 | 0x339 |
EnterCriticalSection | 0x0 | 0x40b054 | 0xcc3c | 0xba3c | 0xee |
ResetEvent | 0x0 | 0x40b058 | 0xcc40 | 0xba40 | 0x40f |
CreateEventW | 0x0 | 0x40b05c | 0xcc44 | 0xba44 | 0x85 |
DeleteCriticalSection | 0x0 | 0x40b060 | 0xcc48 | 0xba48 | 0xd1 |
CreateMutexW | 0x0 | 0x40b064 | 0xcc4c | 0xba4c | 0x9e |
CreateProcessW | 0x0 | 0x40b068 | 0xcc50 | 0xba50 | 0xa8 |
GetCurrentProcess | 0x0 | 0x40b06c | 0xcc54 | 0xba54 | 0x1c0 |
SetHandleInformation | 0x0 | 0x40b070 | 0xcc58 | 0xba58 | 0x470 |
OpenProcess | 0x0 | 0x40b074 | 0xcc5c | 0xba5c | 0x380 |
GetLocaleInfoW | 0x0 | 0x40b078 | 0xcc60 | 0xba60 | 0x206 |
TerminateProcess | 0x0 | 0x40b07c | 0xcc64 | 0xba64 | 0x4c0 |
OpenMutexW | 0x0 | 0x40b080 | 0xcc68 | 0xba68 | 0x37d |
GetProcAddress | 0x0 | 0x40b084 | 0xcc6c | 0xba6c | 0x245 |
Process32FirstW | 0x0 | 0x40b088 | 0xcc70 | 0xba70 | 0x396 |
GetExitCodeThread | 0x0 | 0x40b08c | 0xcc74 | 0xba74 | 0x1e0 |
CreatePipe | 0x0 | 0x40b090 | 0xcc78 | 0xba78 | 0xa1 |
Process32NextW | 0x0 | 0x40b094 | 0xcc7c | 0xba7c | 0x398 |
CreateFileW | 0x0 | 0x40b098 | 0xcc80 | 0xba80 | 0x8f |
CreateToolhelp32Snapshot | 0x0 | 0x40b09c | 0xcc84 | 0xba84 | 0xbe |
ReleaseMutex | 0x0 | 0x40b0a0 | 0xcc88 | 0xba88 | 0x3fa |
GetVersion | 0x0 | 0x40b0a4 | 0xcc8c | 0xba8c | 0x2a2 |
GetVolumeInformationW | 0x0 | 0x40b0a8 | 0xcc90 | 0xba90 | 0x2a7 |
ExpandEnvironmentStringsW | 0x0 | 0x40b0ac | 0xcc94 | 0xba94 | 0x11d |
GetLastError | 0x0 | 0x40b0b0 | 0xcc98 | 0xba98 | 0x202 |
GetModuleFileNameW | 0x0 | 0x40b0b4 | 0xcc9c | 0xba9c | 0x214 |
FindClose | 0x0 | 0x40b0b8 | 0xcca0 | 0xbaa0 | 0x12e |
FindNextFileW | 0x0 | 0x40b0bc | 0xcca4 | 0xbaa4 | 0x145 |
FindFirstFileW | 0x0 | 0x40b0c0 | 0xcca8 | 0xbaa8 | 0x139 |
SetEndOfFile | 0x0 | 0x40b0c4 | 0xccac | 0xbaac | 0x453 |
SetFilePointerEx | 0x0 | 0x40b0c8 | 0xccb0 | 0xbab0 | 0x467 |
GetFileAttributesW | 0x0 | 0x40b0cc | 0xccb4 | 0xbab4 | 0x1ea |
ReadFile | 0x0 | 0x40b0d0 | 0xccb8 | 0xbab8 | 0x3c0 |
GetFileSizeEx | 0x0 | 0x40b0d4 | 0xccbc | 0xbabc | 0x1f1 |
MoveFileW | 0x0 | 0x40b0d8 | 0xccc0 | 0xbac0 | 0x363 |
DeleteFileW | 0x0 | 0x40b0dc | 0xccc4 | 0xbac4 | 0xd6 |
SetFileAttributesW | 0x0 | 0x40b0e0 | 0xccc8 | 0xbac8 | 0x461 |
IsDebuggerPresent | 0x0 | 0x40b0e4 | 0xcccc | 0xbacc | 0x300 |
CopyFileW | 0x0 | 0x40b0e8 | 0xccd0 | 0xbad0 | 0x75 |
Sleep | 0x0 | 0x40b0ec | 0xccd4 | 0xbad4 | 0x4b2 |
HeapSize | 0x0 | 0x40b0f0 | 0xccd8 | 0xbad8 | 0x2d4 |
TerminateThread | 0x0 | 0x40b0f4 | 0xccdc | 0xbadc | 0x4c1 |
WriteFile | 0x0 | 0x40b0f8 | 0xcce0 | 0xbae0 | 0x525 |
GetTickCount | 0x0 | 0x40b0fc | 0xcce4 | 0xbae4 | 0x293 |
GetLogicalDrives | 0x0 | 0x40b100 | 0xcce8 | 0xbae8 | 0x209 |
GetComputerNameW | 0x0 | 0x40b104 | 0xccec | 0xbaec | 0x18f |
WaitForSingleObject | 0x0 | 0x40b108 | 0xccf0 | 0xbaf0 | 0x4f9 |
LoadLibraryW | 0x0 | 0x40b10c | 0xccf4 | 0xbaf4 | 0x33f |
MultiByteToWideChar | 0x0 | 0x40b110 | 0xccf8 | 0xbaf8 | 0x367 |
RtlUnwind | 0x0 | 0x40b114 | 0xccfc | 0xbafc | 0x418 |
GetModuleHandleA | 0x0 | 0x40b118 | 0xcd00 | 0xbb00 | 0x215 |
UnhandledExceptionFilter | 0x0 | 0x40b11c | 0xcd04 | 0xbb04 | 0x4d3 |
GetSystemTimeAsFileTime | 0x0 | 0x40b120 | 0xcd08 | 0xbb08 | 0x279 |
HeapFree | 0x0 | 0x40b124 | 0xcd0c | 0xbb0c | 0x2cf |
HeapAlloc | 0x0 | 0x40b128 | 0xcd10 | 0xbb10 | 0x2cb |
HeapReAlloc | 0x0 | 0x40b12c | 0xcd14 | 0xbb14 | 0x2d2 |
GetCommandLineA | 0x0 | 0x40b130 | 0xcd18 | 0xbb18 | 0x186 |
HeapSetInformation | 0x0 | 0x40b134 | 0xcd1c | 0xbb1c | 0x2d3 |
GetStartupInfoW | 0x0 | 0x40b138 | 0xcd20 | 0xbb20 | 0x263 |
HeapCreate | 0x0 | 0x40b13c | 0xcd24 | 0xbb24 | 0x2cd |
GetModuleHandleW | 0x0 | 0x40b140 | 0xcd28 | 0xbb28 | 0x218 |
ExitProcess | 0x0 | 0x40b144 | 0xcd2c | 0xbb2c | 0x119 |
DecodePointer | 0x0 | 0x40b148 | 0xcd30 | 0xbb30 | 0xca |
GetStdHandle | 0x0 | 0x40b14c | 0xcd34 | 0xbb34 | 0x264 |
EncodePointer | 0x0 | 0x40b150 | 0xcd38 | 0xbb38 | 0xea |
TlsAlloc | 0x0 | 0x40b154 | 0xcd3c | 0xbb3c | 0x4c5 |
TlsGetValue | 0x0 | 0x40b158 | 0xcd40 | 0xbb40 | 0x4c7 |
TlsSetValue | 0x0 | 0x40b15c | 0xcd44 | 0xbb44 | 0x4c8 |
TlsFree | 0x0 | 0x40b160 | 0xcd48 | 0xbb48 | 0x4c6 |
InterlockedIncrement | 0x0 | 0x40b164 | 0xcd4c | 0xbb4c | 0x2ef |
SetLastError | 0x0 | 0x40b168 | 0xcd50 | 0xbb50 | 0x473 |
GetCurrentThreadId | 0x0 | 0x40b16c | 0xcd54 | 0xbb54 | 0x1c5 |
InterlockedDecrement | 0x0 | 0x40b170 | 0xcd58 | 0xbb58 | 0x2eb |
IsProcessorFeaturePresent | 0x0 | 0x40b174 | 0xcd5c | 0xbb5c | 0x304 |
GetCPInfo | 0x0 | 0x40b178 | 0xcd60 | 0xbb60 | 0x172 |
GetACP | 0x0 | 0x40b17c | 0xcd64 | 0xbb64 | 0x168 |
GetOEMCP | 0x0 | 0x40b180 | 0xcd68 | 0xbb68 | 0x237 |
IsValidCodePage | 0x0 | 0x40b184 | 0xcd6c | 0xbb6c | 0x30a |
LCMapStringW | 0x0 | 0x40b188 | 0xcd70 | 0xbb70 | 0x32d |
GetStringTypeW | 0x0 | 0x40b18c | 0xcd74 | 0xbb74 | 0x269 |
SetUnhandledExceptionFilter | 0x0 | 0x40b190 | 0xcd78 | 0xbb78 | 0x4a5 |
GetModuleFileNameA | 0x0 | 0x40b194 | 0xcd7c | 0xbb7c | 0x213 |
FreeEnvironmentStringsW | 0x0 | 0x40b198 | 0xcd80 | 0xbb80 | 0x161 |
WideCharToMultiByte | 0x0 | 0x40b19c | 0xcd84 | 0xbb84 | 0x511 |
GetEnvironmentStringsW | 0x0 | 0x40b1a0 | 0xcd88 | 0xbb88 | 0x1da |
SetHandleCount | 0x0 | 0x40b1a4 | 0xcd8c | 0xbb8c | 0x46f |
GetFileType | 0x0 | 0x40b1a8 | 0xcd90 | 0xbb90 | 0x1f3 |
QueryPerformanceCounter | 0x0 | 0x40b1ac | 0xcd94 | 0xbb94 | 0x3a7 |
GetCurrentProcessId | 0x0 | 0x40b1b0 | 0xcd98 | 0xbb98 | 0x1c1 |
USER32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetShellWindow | 0x0 | 0x40b1d0 | 0xcdb8 | 0xbbb8 | 0x179 |
GetWindowThreadProcessId | 0x0 | 0x40b1d4 | 0xcdbc | 0xbbbc | 0x1a4 |
ADVAPI32.dll (14)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryValueExW | 0x0 | 0x40b000 | 0xcbe8 | 0xb9e8 | 0x26e |
CryptDecrypt | 0x0 | 0x40b004 | 0xcbec | 0xb9ec | 0xb4 |
CryptDestroyKey | 0x0 | 0x40b008 | 0xcbf0 | 0xb9f0 | 0xb7 |
CryptEncrypt | 0x0 | 0x40b00c | 0xcbf4 | 0xb9f4 | 0xba |
CryptImportKey | 0x0 | 0x40b010 | 0xcbf8 | 0xb9f8 | 0xca |
CryptGenRandom | 0x0 | 0x40b014 | 0xcbfc | 0xb9fc | 0xc1 |
CryptSetKeyParam | 0x0 | 0x40b018 | 0xcc00 | 0xba00 | 0xcd |
CryptAcquireContextW | 0x0 | 0x40b01c | 0xcc04 | 0xba04 | 0xb1 |
RegSetValueExW | 0x0 | 0x40b020 | 0xcc08 | 0xba08 | 0x27e |
RegCloseKey | 0x0 | 0x40b024 | 0xcc0c | 0xba0c | 0x230 |
RegOpenKeyExW | 0x0 | 0x40b028 | 0xcc10 | 0xba10 | 0x261 |
DuplicateTokenEx | 0x0 | 0x40b02c | 0xcc14 | 0xba14 | 0xdf |
GetTokenInformation | 0x0 | 0x40b030 | 0xcc18 | 0xba18 | 0x15a |
OpenProcessToken | 0x0 | 0x40b034 | 0xcc1c | 0xba1c | 0x1f7 |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteExW | 0x0 | 0x40b1c8 | 0xcdb0 | 0xbbb0 | 0x121 |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.Agent.DVAM |
Malicious
|
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\branding.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft\RAC\StateData\RacMetaData.dat.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Caches\{4E4260A4-7E39-442E-BC22-7FF751D1C161}.2.ver0x0000000000000002.db.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Caches\{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000012.db.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2017-07-26.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\desktop.ini.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Unknown
|
...
|
»
6137f8db2192e638e13610f75e73b9247c05f4706f0afd1fdb132d86de6b4012 | Downloaded File | Text |
Unknown
|
...
|
»
\\?\C:\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000\desktop.ini.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\BOOTSTAT.DAT.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\BOOTSECT.BAK.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Adobe\ARM\Reader_10.0.0\AdbeRdrSecUpd10111.msp.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Adobe\ARM\Reader_10.0.0\AdbeRdrUpd10110_MUI.msp.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Adobe\ARM\Reader_10.0.0\AdbeRdrUpd10116_MUI.msp.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Acrobat\10.0\UserCache.bin.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\RAC\PublishedData\RacWmiDatabase.sdf.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Crashpad\settings.dat.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\GDIPFONTCACHEV1.DAT.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\000003.log.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extension State\000003.log.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Acrobat\10.0\AdobeCMapFnt10.lst.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Acrobat\10.0\Cache\AcroFnt10.lst.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Acrobat\10.0\AdobeSysFnt10.lst.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Acrobat\10.0\SharedDataEvents.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Color\ACECache11.lst.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Color\Profiles\wscRGB.icc.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Adobe\Color\Profiles\wsRGB.icc.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\branding.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\pss10r.chm.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\setup.chm.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPlusrWW.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjProrWW.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Setup.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Office32WW.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\OfficeSoftwareProtectionPlatform\tokens.dat.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\OfficeSoftwareProtectionPlatform\Cache\cache.dat.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\RAC\StateData\RacWmiDataBookmarks.dat.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\RAC\StateData\RacWmiEventData.dat.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\User Account Pictures\guest.bmp.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\User Account Pictures\user.bmp.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Caches\cversions.2.db.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Caches\{11336D5B-7F61-4871-82E3-E0F59766823B}.2.ver0x0000000000000001.db.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Caches\{3978EA0A-1C7E-4449-8AE1-E1265F039002}.2.ver0x0000000000000003.db.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Caches\{40FC8D7D-05ED-4FEB-B03B-6C100659EF5C}.2.ver0x0000000000000001.db.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Caches\{4E36EA69-73D1-4458-9D16-50F8E31A69A0}.2.ver0x0000000000000001.db.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Caches\{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000011.db.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-2017-07-12.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report-latest.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Ringtones\desktop.ini.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Start Menu\desktop.ini.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Desktop.ini.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Desktop.ini.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Desktop.ini.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Tablet PC\Desktop.ini.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\desktop.ini.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\desktop.ini.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\desktop.ini.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\desktop.ini.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Desktop.ini.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows Defender\Scans\History\CacheManager\MpSfc.bin.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows\Power Efficiency Diagnostics\energy-report.html.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\Unknown.Log.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows Defender\Support\MPLog-07132009-221054.log.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Mozilla\logs\maintenanceservice-install.log.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Sun\Java\Java Update\jaureglist.xml.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\ProgramData\Microsoft\Windows Defender\Scans\History\Service\History.Log.id[9C354B42-0001].[tedmundboardus@aol.com].phobos | Dropped File | Stream |
Not Queried
|
...
|
»