VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Generic.Ransom.GlobeImposter.6F8B4862
|
HAPPYTHREE.EXE.exe
Windows Exe (x86-32)
Created at 2020-02-05T05:14:00
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x409f34 |
Size Of Initialized Data | 0xc200 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-02-01 18:36:19+00:00 |
Sections (1)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.rdata | 0x401000 | 0xd0b8 | 0xd200 | 0x400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.05 |
Imports (5)
»
KERNEL32.dll (45)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetFilePointerEx | 0x0 | 0x401024 | 0xcb64 | 0xbf64 | 0x467 |
CloseHandle | 0x0 | 0x401028 | 0xcb68 | 0xbf68 | 0x52 |
lstrlenW | 0x0 | 0x40102c | 0xcb6c | 0xbf6c | 0x54e |
CreateFileW | 0x0 | 0x401030 | 0xcb70 | 0xbf70 | 0x8f |
HeapCreate | 0x0 | 0x401034 | 0xcb74 | 0xbf74 | 0x2cd |
GetCurrentProcess | 0x0 | 0x401038 | 0xcb78 | 0xbf78 | 0x1c0 |
ExitProcess | 0x0 | 0x40103c | 0xcb7c | 0xbf7c | 0x119 |
CreateThread | 0x0 | 0x401040 | 0xcb80 | 0xbf80 | 0xb5 |
GetCurrentThread | 0x0 | 0x401044 | 0xcb84 | 0xbf84 | 0x1c4 |
SetThreadPriority | 0x0 | 0x401048 | 0xcb88 | 0xbf88 | 0x499 |
WaitForMultipleObjects | 0x0 | 0x40104c | 0xcb8c | 0xbf8c | 0x4f7 |
Sleep | 0x0 | 0x401050 | 0xcb90 | 0xbf90 | 0x4b2 |
GetLogicalDrives | 0x0 | 0x401054 | 0xcb94 | 0xbf94 | 0x209 |
SetFilePointer | 0x0 | 0x401058 | 0xcb98 | 0xbf98 | 0x466 |
FindClose | 0x0 | 0x40105c | 0xcb9c | 0xbf9c | 0x12e |
lstrcmpiA | 0x0 | 0x401060 | 0xcba0 | 0xbfa0 | 0x544 |
lstrcmpiW | 0x0 | 0x401064 | 0xcba4 | 0xbfa4 | 0x545 |
lstrcpyA | 0x0 | 0x401068 | 0xcba8 | 0xbfa8 | 0x547 |
ReadFile | 0x0 | 0x40106c | 0xcbac | 0xbfac | 0x3c0 |
lstrcatW | 0x0 | 0x401070 | 0xcbb0 | 0xbfb0 | 0x53f |
GetModuleFileNameW | 0x0 | 0x401074 | 0xcbb4 | 0xbfb4 | 0x214 |
CreateProcessW | 0x0 | 0x401078 | 0xcbb8 | 0xbfb8 | 0xa8 |
GetEnvironmentVariableW | 0x0 | 0x40107c | 0xcbbc | 0xbfbc | 0x1dc |
GetDriveTypeA | 0x0 | 0x401080 | 0xcbc0 | 0xbfc0 | 0x1d2 |
GetTempPathW | 0x0 | 0x401084 | 0xcbc4 | 0xbfc4 | 0x285 |
GetTempFileNameW | 0x0 | 0x401088 | 0xcbc8 | 0xbfc8 | 0x283 |
SetFileAttributesW | 0x0 | 0x40108c | 0xcbcc | 0xbfcc | 0x461 |
GetFileAttributesW | 0x0 | 0x401090 | 0xcbd0 | 0xbfd0 | 0x1ea |
FindFirstFileW | 0x0 | 0x401094 | 0xcbd4 | 0xbfd4 | 0x139 |
FindNextFileW | 0x0 | 0x401098 | 0xcbd8 | 0xbfd8 | 0x145 |
CopyFileW | 0x0 | 0x40109c | 0xcbdc | 0xbfdc | 0x75 |
MoveFileExW | 0x0 | 0x4010a0 | 0xcbe0 | 0xbfe0 | 0x360 |
SetPriorityClass | 0x0 | 0x4010a4 | 0xcbe4 | 0xbfe4 | 0x47d |
MultiByteToWideChar | 0x0 | 0x4010a8 | 0xcbe8 | 0xbfe8 | 0x367 |
WideCharToMultiByte | 0x0 | 0x4010ac | 0xcbec | 0xbfec | 0x511 |
CompareStringA | 0x0 | 0x4010b0 | 0xcbf0 | 0xbff0 | 0x61 |
WriteFile | 0x0 | 0x4010b4 | 0xcbf4 | 0xbff4 | 0x525 |
GetFileSizeEx | 0x0 | 0x4010b8 | 0xcbf8 | 0xbff8 | 0x1f1 |
GetLastError | 0x0 | 0x4010bc | 0xcbfc | 0xbffc | 0x202 |
lstrlenA | 0x0 | 0x4010c0 | 0xcc00 | 0xc000 | 0x54d |
GetProcessHeap | 0x0 | 0x4010c4 | 0xcc04 | 0xc004 | 0x24a |
HeapFree | 0x0 | 0x4010c8 | 0xcc08 | 0xc008 | 0x2cf |
HeapReAlloc | 0x0 | 0x4010cc | 0xcc0c | 0xc00c | 0x2d2 |
lstrcpyW | 0x0 | 0x4010d0 | 0xcc10 | 0xc010 | 0x548 |
HeapAlloc | 0x0 | 0x4010d4 | 0xcc14 | 0xc014 | 0x2cb |
ADVAPI32.dll (8)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RegQueryValueExW | 0x0 | 0x401000 | 0xcb40 | 0xbf40 | 0x26e |
RegOpenKeyExW | 0x0 | 0x401004 | 0xcb44 | 0xbf44 | 0x261 |
RegCreateKeyExW | 0x0 | 0x401008 | 0xcb48 | 0xbf48 | 0x239 |
RegCloseKey | 0x0 | 0x40100c | 0xcb4c | 0xbf4c | 0x230 |
CryptGenRandom | 0x0 | 0x401010 | 0xcb50 | 0xbf50 | 0xc1 |
CryptReleaseContext | 0x0 | 0x401014 | 0xcb54 | 0xbf54 | 0xcb |
CryptAcquireContextW | 0x0 | 0x401018 | 0xcb58 | 0xbf58 | 0xb1 |
RegSetValueExW | 0x0 | 0x40101c | 0xcb5c | 0xbf5c | 0x27e |
SHELL32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SHChangeNotify | 0x0 | 0x4010dc | 0xcc1c | 0xc01c | 0x7f |
ShellExecuteExW | 0x0 | 0x4010e0 | 0xcc20 | 0xc020 | 0x121 |
SHLWAPI.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathFindFileNameW | 0x0 | 0x4010e8 | 0xcc28 | 0xc028 | 0x49 |
PathRemoveFileSpecW | 0x0 | 0x4010ec | 0xcc2c | 0xc02c | 0x8b |
PathAddBackslashW | 0x0 | 0x4010f0 | 0xcc30 | 0xc030 | 0x30 |
ntdll.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_aulldiv | 0x0 | 0x4010f8 | 0xcc38 | 0xc038 | 0x4fe |
_alldiv | 0x0 | 0x4010fc | 0xcc3c | 0xc03c | 0x4f6 |
_allrem | 0x0 | 0x401100 | 0xcc40 | 0xc040 | 0x4fa |
_chkstk | 0x0 | 0x401104 | 0xcc44 | 0xc044 | 0x502 |
RtlUnwind | 0x0 | 0x401108 | 0xcc48 | 0xc048 | 0x396 |
NtQueryVirtualMemory | 0x0 | 0x40110c | 0xcc4c | 0xc04c | 0x135 |
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Generic.Ransom.GlobeImposter.6F8B4862 |
Malicious
|
C:\Windows10Upgrade\resources\ux\Microsoft.WinJS\js\base.js.happythreechoose | Dropped File | Text |
Suspicious
|
...
|
»
YARA Matches (3)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
JS_Unicode_escaped_bytes | JavaScript contains many unicode-escaped bytes; possible obfuscation | - |
2/5
|
...
|
JS_Eval | JavaScript calls eval function; possible obfuscation | - |
2/5
|
...
|
JS_charCodeAt | JavaScript references charCodeAt function; possible obfuscation | - |
2/5
|
...
|
C:\Windows10Upgrade\resources\ux\Microsoft.WinJS\js\ui.js.happythreechoose | Dropped File | Text |
Suspicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
JS_charCodeAt | JavaScript references charCodeAt function; possible obfuscation | - |
2/5
|
...
|
C:\Windows10Upgrade\bootsect.exe.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\Configuration.ini.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\downloader.dll.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\DW20.EXE.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\ESDHelper.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\esdstub.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\GatherOSState.EXE.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\GetCurrentDeploy.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\GetCurrentOOBE.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\GetCurrentRollback.EXE | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\HttpHelper.exe | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\PostOOBEScript.cmd | Modified File | Batch |
Unknown
|
...
|
»
C:\Windows10Upgrade\wimgapi.dll | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\windlp.dll.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\bullet.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\default.htm.happythreechoose | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\default_eos.css.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\default_eos.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\default_oobe.css.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\default_oobe.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\GetStarted.png.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\marketing.png.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\NetworkIssueFAQ.mht | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\NoNetworkConnection.png.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\NoNetworkConnectionHoverOver.png.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\pass.png.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\Microsoft.WinJS\css\oobe-desktop.css.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_ar-sa.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_bg-bg.htm.happythreechoose | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_cs-cz.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_da-dk.htm.happythreechoose | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_de-de.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_el-gr.htm.happythreechoose | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_en-gb.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_en-us.htm.happythreechoose | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_es-es.htm.happythreechoose | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_es-mx.htm.happythreechoose | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_et-ee.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_fi-fi.htm.happythreechoose | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_fr-ca.htm.happythreechoose | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_fr-fr.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_he-il.htm.happythreechoose | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_hr-hr.htm.happythreechoose | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_hu-hu.htm.happythreechoose | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_it-it.htm.happythreechoose | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_ja-jp.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_ko-kr.htm.happythreechoose | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_lt-lt.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_lv-lv.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_nb-no.htm.happythreechoose | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_nl-nl.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_pl-pl.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_pt-br.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_pt-pt.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_ro-ro.htm.happythreechoose | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_ru-ru.htm.happythreechoose | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_sk-sk.htm.happythreechoose | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_sl-si.htm.happythreechoose | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_sr-latn-cs.htm.happythreechoose | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_sv-se.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_th-th.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_tr-tr.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_uk-ua.htm | Modified File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_zh-cn.htm.happythreechoose | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_zh-hk.htm.happythreechoose | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\ux\EULA\EULA_zh-tw.htm.happythreechoose | Dropped File | Text |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\i386\BiosBlocks.xml.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\i386\hwcompat.txt.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\i386\nxquery.cat.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\i386\nxquery.inf | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\amd64\BiosBlocks.xml.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\amd64\nxquery.cat | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\amd64\nxquery.inf.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\resources\amd64\NXQuery.sys | Modified File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\dll1\cosqueryxp.dll.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\dll1\wdscore.dll.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\dll1\webservices.dll.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Windows10Upgrade\2052\DWINTL20.DLL.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\desktop.ini.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Videos\desktop.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Pictures\desktop.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Desktop\desktop.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\Public\Desktop\Google Chrome.lnk | Modified File | Binary |
Unknown
|
...
|
»
C:\Users\Public\Desktop\Mozilla Firefox.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\2J80DrUI0ukoi.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\CSga.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\lypfdAfjalW 5Vh.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ryVN.swf.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\tSRa.mp4.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\WEStXX.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ygoN1.flv.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ZAxZ0rXYnVPgZV\1sMkujj.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ZAxZ0rXYnVPgZV\5sZffBto.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\ZAxZ0rXYnVPgZV\efH5Ob.flv.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\PQRbVh-tDHt-M\-DhI9VRldgAPXhW-bxcS.swf.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\PQRbVh-tDHt-M\HZoz_t2tX2n5.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\PQRbVh-tDHt-M\ibcl6vOksMSziPl_5.avi.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\PQRbVh-tDHt-M\tMv6GBWCSo.swf.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\PQRbVh-tDHt-M\G9kX78tzKIbuOa\1xJQbwJYk--WCHDN7_A_.mkv.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\PQRbVh-tDHt-M\G9kX78tzKIbuOa\eDhakAkMi35niJgyT.flv.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\PQRbVh-tDHt-M\G9kX78tzKIbuOa\QOfYMH2.swf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\PQRbVh-tDHt-M\G9kX78tzKIbuOa\suBKrtlh5UbO.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Searches\winrt--{S-1-5-21-1051304884-625712362-2192934891-1000}-.searchconnector-ms | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\-9iF5.gif.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\-dlFOBhT.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\4Fd4V.bmp.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\6a4Mw1x qK6sP.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\desktop.ini.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\dQXUa DLCVau.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\D_TcKlywXm9.png.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\izseTU9WJ4k9Fj.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Ljd9GMm.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Mpw4A8-k5g.gif | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\MZtSVVFTr.jpg.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Pbq-KTW-Acj ll.bmp.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\pst61_TXtEoabFYis7G.png.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\PzTs VJ8hcM.jpg.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\T82jEhXsa5Qy5aHk.jpg.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\xC1p2U4DPwmLw9O3uF.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\ZU1Btd.gif.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\Camera Roll\desktop.ini.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\OneDrive\desktop.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\desktop.ini | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\g4vOK-TiElqldQ.wav.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\hyYj8_bS-vjS3.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\iy3RchGXqk6KtHtM.mp3.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\8PwLuaLcBVkei7G.mp3.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\CA6Ig.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\vF1d8ev.mp3.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\XKYlfaQ\49mlypQr.m4a.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\XKYlfaQ\8bxt2DL9E2y2.mp3.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\XKYlfaQ\9GG-gkrGgGpt1O.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\XKYlfaQ\9y2 lNdwtrKndUdr.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\XKYlfaQ\b50kcKwk0tsa.mp3.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\XKYlfaQ\igajY.wav.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\XKYlfaQ\iIGS.wav.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\XKYlfaQ\j87XXHMhfLqpcGSi.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\XKYlfaQ\PlORB6-3k5Z.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\XKYlfaQ\WegKKDl.m4a | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\tIxsJBLL WO2\BJh05YZFlMm.mp3.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\tIxsJBLL WO2\RzU X.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\tIxsJBLL WO2\SPCpDMAkEfgXj.wav | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Links\Desktop.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Links\OneDrive.lnk.happythreechoose | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\Public\5D64CC94FBAA1E0F7D767179EACF76DE6051563629F05D7C3B1FABE9EF4413FF | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\Decryption INFO.html | Dropped File | Text |
Unknown
|
...
|
»
C:\BOOTSECT.BAK.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\appraiserxp.dll.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\cosquery.dll | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\DevInv.dll.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\DWDCW20.DLL.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\DWTRIG20.EXE | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\EnableWiFiTracing.cmd | Modified File | Batch |
Not Queried
|
...
|
»
C:\Windows10Upgrade\upgrader_default.log.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\upgrader_win10.log | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\Windows10UpgraderApp.exe.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\WinREBootApp32.exe.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\WinREBootApp64.exe | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\hwcompatShared.txt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\ux\block.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\ux\bluelogo.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\ux\default.css.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\ux\eula.css.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\ux\GetStartedHoverOver.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\ux\loading.gif.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\ux\lock.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\ux\logo.png.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\ux\Microsoft.WinJS\css\ui-dark.css | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\i386\hwexclude.txt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\i386\NXQuery.sys | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\amd64\hwcompat.txt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\resources\amd64\hwexclude.txt | Modified File | Stream |
Not Queried
|
...
|
»
C:\Windows10Upgrade\dll2\webservices.dll.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\desktop.ini.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Music\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Libraries\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Libraries\RecordedTV.library-ms | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Downloads\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Documents\desktop.ini.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\Desktop\Acrobat Reader DC.lnk.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\Public\AccountPictures\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\bPEL72QuxX3Myy.swf.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\h68GbEjUBDmeazE.mp4 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\h9q20S8eRxd.swf.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\ZAxZ0rXYnVPgZV\4g2yD587xs.avi | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\ZAxZ0rXYnVPgZV\bzxOp9untVOIhbj F.mkv.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\ZAxZ0rXYnVPgZV\jmWzL1bQAqeYuG2xcrwI.avi.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\PQRbVh-tDHt-M\gQrFx0vJ3tbk.flv | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\PQRbVh-tDHt-M\MFp-.swf.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\PQRbVh-tDHt-M\G9kX78tzKIbuOa\MpyGLAi8pyox.avi.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Videos\PQRbVh-tDHt-M\G9kX78tzKIbuOa\zIi6l7eS.mkv.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Searches\desktop.ini.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Searches\Everywhere.search-ms | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Searches\Indexed Locations.search-ms.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Saved Games\desktop.ini.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\BbIsK7S2s3miGzaMngA.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\dtoOLa0zbl.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\g-2mYacKrynw43.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\ggL8qjzKkKvv34z2Ow j.jpg.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\kloRG2tolBYZLd.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\nrBuoeH8u5mK.png | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\S84Ptrqg19hlx0.bmp | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\uW55Ut4sg.gif.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\WY3W.jpg.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\y0c2al.png.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\_sTleJ.jpg | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Pictures\Saved Pictures\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\8w9Yv9CkmDKx.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\AbkEp9_mUwoMem9lnnfe.wav | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\rO8U44s1q.m4a.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\T57mOAnFPiHZVJuX_.m4a.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\WdAiooww.wav.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\y8-5HZWOY0.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\Zy39i7.m4a.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\zyiqDO9Irne784IltUO.mp3.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\6UZh3TWWEO_.wav.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\Jry6QpSrlbtGf.wav.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\NvPppj.mp3.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\OtVfZtC4b.wav.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\zaWZ2Dhah9hHaN1g.wav.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\XKYlfaQ\CJp9TPmHl-ra8o5Bv.m4a | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\XKYlfaQ\Q7cibe.m4a.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\tIxsJBLL WO2\77VxXfy4Fmq.m4a.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Music\d1_GTf7p7iJ-\tIxsJBLL WO2\94i7trk2kHdzvrBAW0.mp3 | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Links\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Links\Downloads.lnk.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Favorites\Bing.url | Modified File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Favorites\desktop.ini.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Favorites\Links\desktop.ini.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Downloads\desktop.ini | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\FD1HVy\Documents\3-MvVAc3Um.docx.happythreechoose | Dropped File | Stream |
Not Queried
|
...
|
»