Dynamic Analysis Report |
Classification: Riskware, Trojan, Ransomware |
4cd75ebb7d9dc880895b3b9e503a5ef72da5a10c7a4149683b217eda1c95c8ac (SHA256)
SF.exe
Created at 2018-11-28 08:28:00
Notifications (2/2)
The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.
The operating system was rebooted during the analysis.
Remarks
The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 bytes |
...
|
This list contains only the embedded files and created files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\SF.exe | Sample File | Binary |
Suspicious
|
...
|
Severity |
Suspicious
|
First Seen | 2018-07-08 18:12 (UTC+2) |
Last Seen | 2018-11-28 09:08 (UTC+1) |
Names | Win32.Trojan.Ramsil |
Families | Ramsil |
Classification | Trojan |
Image Base | 0x400000 |
Entry Point | 0x43c00a |
Size Of Code | 0xd000 |
Size Of Initialized Data | 0x27400 |
File Type | executable |
Subsystem | windows_gui |
Machine Type | i386 |
Compile Timestamp | 2018-06-12 16:58:38+00:00 |
Assembly Version | 1.0.0.0 |
LegalCopyright | Copyright © 2017 |
InternalName | SF.exe |
FileVersion | 1.0.0.0 |
CompanyName | - |
LegalTrademarks | - |
Comments | Black Heart |
ProductName | - |
ProductVersion | 1.0.0.0 |
FileDescription | BlackHeart |
OriginalFilename | SF.exe |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
!|W?ErZ | 0x402000 | 0xe3d4 | 0xe400 | 0x400 | cnt_initialized_data, mem_execute, mem_read, mem_write | 8.0 |
.text | 0x412000 | 0xcc08 | 0xce00 | 0xe800 | cnt_code, mem_execute, mem_read | 4.81 |
.rsrc | 0x420000 | 0x18c40 | 0x18e00 | 0x1b600 | cnt_initialized_data, mem_read | 2.83 |
.reloc | 0x43a000 | 0xc | 0x200 | 0x34400 | cnt_initialized_data, mem_discardable, mem_read | 0.1 |
- | 0x43c000 | 0x10 | 0x200 | 0x34600 | cnt_code, mem_execute, mem_read | 0.12 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x43c000 | 0x127ec | 0xefec | 0x0 |
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\dFoSJ.gif | Modified File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\topbar_floating_button_pressed.png.BlackHat | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Eg88RvD9 0Q\NRPhW82cAnOla-nt-U\HJXKHXXKSQElmnYVn.doc.BlackHat | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\128.png.BlackHat | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Eg88RvD9 0Q\NRPhW82cAnOla-nt-U\D1iL9p 83bubKmetxE\hVbPNu zb6TZvaE.ppt.BlackHat | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_setup\devices.html.BlackHat | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\xEh-oxAfvWyU\n5aAyWEVTqMft-U_VCBk.gif.BlackHat | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\F0XS.mkv.BlackHat | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\icon_16.png.BlackHat | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\topbar_floating_button_hover.png.BlackHat | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extension Rules\000003.log.BlackHat | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\MEaJ-h2c.png.BlackHat | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\UDS8GLwtwz9hdtobXdla\fCQ5qbAZofOaLfUx9.jpg.BlackHat | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\topbar_floating_button_close.png.BlackHat | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\UDS8GLwtwz9hdtobXdla\jccB0GTXmCvr0T.png.BlackHat | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Uk4blibgBpNxH-0xi\mHeg67uPjmtt6jUG18Z.xlsx.BlackHat | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Eg88RvD9 0Q\NRPhW82cAnOla-nt-U\9Nt V.csv.BlackHat | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\hrtjCD\BN0C7rid1wk1Ic D.avi.BlackHat | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\5Za7P f.pptx.BlackHat | Created File | Stream |
Unknown
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\bCfB0mFGgoQ0XS\5P5HsWWIrarrybUFEVu.jpg | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\bCfB0mFGgoQ0XS\-jP2FnLVLNfq.xlsx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\Backup\old\edb00001.log | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\bCfB0mFGgoQ0XS\-VGkuYlZONjZ.doc | Modified File | Stream |
Not Queried
|
...
|
c:\users\5p5nrgjn0js halpmcxz\appdata\local\gdipfontcachev1.dat | Modified File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\FKAtl1.mp3.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\data_reduction_proxy_leveldb\000003.log.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\topbar_floating_button.png.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ARUZ5zbfJrACZ.xlsx.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Kqak.png.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\edb.log.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\hrtjCD\2nWMdFZe6FgJfrfMjg.mp4.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Eg88RvD9 0Q\NRPhW82cAnOla-nt-U\FGotL0e.pptx.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\icon_128.png.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\Stationery\Bears.jpg.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\XQU3.docx.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\xsNByB5Krrm8B2\SkPlg3VJKRam.png.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Uk4blibgBpNxH-0xi\D0D09ePmPSw.xls.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\DpAMomStgN4Oue63.mp3.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\UDS8GLwtwz9hdtobXdla\1a0wyFKTXd9V6C.png.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\qTXcT61PJPwWTo7b.jpg.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Uk4blibgBpNxH-0xi\L6MUjcS.xls.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Eg88RvD9 0Q\NRPhW82cAnOla-nt-U\Fr4HlLV.docx.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\m0BPERFiJ8.avi.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\U9Lb y3tVAO.xls.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\hrtjCD\F_LulY8W\1O0_UNXpWhB_5sU17aHW\tk0xoL.mkv.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\6LJLbAymZsdb.avi.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\l7p6LVZRdFFPrRS0.avi.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\xsNByB5Krrm8B2\V5C3bQhDkzh_Xq_mz.jpg.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Uk4blibgBpNxH-0xi\dqafZPw1S2IFXe\4M RJ.pdf.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_0\128.png.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\f6XwJIq.mp3.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Eg88RvD9 0Q\movpp.xls.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\hrtjCD\F_LulY8W\6Y2AP_NR_i-.mp4.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\bCfB0mFGgoQ0XS\afuGNWnMe_ntz2.avi.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Eg88RvD9 0Q\NRPhW82cAnOla-nt-U\D1iL9p 83bubKmetxE\xhVcawwZRVZO1M.ppt.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\2712.mkv.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\ZFo3TKP_T3N4\5htjrcrDH_aQIKa.mp3.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\GxaJ.mkv.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\4Pc8-sXU26qE6QH0H.xlsx.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_route_details.html.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\hrtjCD\F_LulY8W\_wpFDzC4c\91vuHJ 9ySFBBd.mp4.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\YH18pEPew.pptx.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\xEh-oxAfvWyU\Z7CUv9GKgYKFuMe92i2\QCvY.png.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\xEh-oxAfvWyU\acl-DpKaW 5fpZHwidq\A6Bo\ZIg1KxOR2EeBsVBPX.jpg.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\icon_128.png.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8NTidvOEMXsM3 N_\b9Gsq.jpg.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\Stationery\Garden.jpg.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\hrtjCD\F_LulY8W\x UidggNMMghN8-HQ.mkv.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\hrtjCD\F_LulY8W\3YN_CZT0O\-U-BcVuqg.mkv.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Eg88RvD9 0Q\NRPhW82cAnOla-nt-U\D1iL9p 83bubKmetxE\tZaHaVKBi.csv.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\AiIi r5mJ.mp3.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\y OWQ5DY5.odt.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\xEh-oxAfvWyU\acl-DpKaW 5fpZHwidq\A6Bo\Ycp3Y7Jtc2F-hCHlmjp.jpg.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Internet Explorer\brndlog.bak.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\hrtjCD\F_LulY8W\1O0_UNXpWhB_5sU17aHW\pbQetNKgY3ZjcWUYbqfg.mp4.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8NTidvOEMXsM3 N_\x2iq4XICZpk D808.png.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\xEh-oxAfvWyU\Xo3H0stM0ds.gif.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\w0zGj7\Z fmR2eTtcFjruZNPelJ.mp3.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8NTidvOEMXsM3 N_\6BrC-.jpg.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\B53BCzxn21zw.csv.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\xEh-oxAfvWyU\Z7CUv9GKgYKFuMe92i2\oROFcQ98mz_JRa1.png.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\fawBi.docx.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Uk4blibgBpNxH-0xi\dqafZPw1S2IFXe\7y4qR.odt.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\xEh-oxAfvWyU\Z7CUv9GKgYKFuMe92i2\rrfdhHTBH.jpg.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\xEh-oxAfvWyU\Z7CUv9GKgYKFuMe92i2\JjU2X5DIuc7bpgi9dC.jpg.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\YElre7Ah.xlsx.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\bCfB0mFGgoQ0XS\n dVX.gif.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extension State\000003.log.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\topbar_floating_button_maximize.png.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\vV97l9lzxg2m6K.mp3.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\flapper.gif.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\U4CXHTtW81xg0z5nI.mp4.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\F0wNQWmB8rAJPBY8ZSN.jpg.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\icon_128.png.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Uk4blibgBpNxH-0xi\fkTWzhKIbqoRg3MMM.rtf.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\w0zGj7\GvKC\i1XgX9TroNr_mjR3p.mp3.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8NTidvOEMXsM3 N_\yyj0_JFiIUWTXBCk6.jpg.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ktdxpOJo.jpg.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\35unnQG7.docx.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\KAWKBvQhv-9CkSRB483q.gif.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\zL1RvwUf_Ly.jpg.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\w0zGj7\uLNBnFOJLg4PZQute.mp3.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\hrtjCD\BFD0nDfVED86T_ULhs.mkv.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\9ub6P6QLsFuaDCm.docx.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\Y4guI9.jpg.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_setup\index.html.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cast_setup\chromecast_logo_grey.png.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\k1c7AVTe.mp3.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\XSOFiWd9rUy95UeO6KVh.png.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\Stationery\HandPrints.jpg.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\Stationery\GreenBubbles.jpg.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_0\128.png.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Internet Explorer\brndlog.txt.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Office\ONetConfig\350db95df4cbd94b2a1c300510e12e11.xml.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\hrtjCD\F_LulY8W\cDxDBdRug.mp4.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\xEh-oxAfvWyU\acl-DpKaW 5fpZHwidq\Lh 9CMcgdsa.gif.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\NKuP7qC.jpg.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\9pGbs08or1Q 0s.mp4.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\hrtjCD\0QxKexPVWuEDl.mp4.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\qSYepBr9-mkSVCrO.mp3.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\main.html.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\hrtjCD\F_LulY8W\3YN_CZT0O\f9IYH.mp4.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\xsNByB5Krrm8B2\afntu1ySUzeveO.gif.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Apps\2.0\DQQ19BCJ.JAX\YVORLGOR.PNT\goog...app_baa8013a79450f71_0001.0003_290679d077f4cfec\clickonce_bootstrap.exe.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\XOTh0 Zy1.mp3.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\d42p2M.docx.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\EAOPkDhmCNm.mp4.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\w0zGj7\gTjhnqOy4Y6uQOLrgmIL.mp3.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Eg88RvD9 0Q\NRPhW82cAnOla-nt-U\3jHewf0ij9x -pVT9trJ.rtf.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\hrtjCD\F_LulY8W\1O0_UNXpWhB_5sU17aHW\s98fyzWcA8HyPfay3y1P.mkv.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\OOIO0.png.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Uk4blibgBpNxH-0xi\9y_E.xls.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\LeXwIjKpN.pptx.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\html\craw_window.html.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\oeold.xml.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\auuzlO.jpg.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Apps\2.0\DQQ19BCJ.JAX\YVORLGOR.PNT\clic...exe_baa8013a79450f71_0001.0003_none_855491bb37a51715\GoogleUpdateSetup.exe.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\HTlp087HTBWFYn.xlsx.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\feedback.html.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Uk4blibgBpNxH-0xi\dqafZPw1S2IFXe\THFQgfI31hKb_ed-UC_M.doc.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\xsNByB5Krrm8B2\zk5XXIV0GQFk91m.png.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\7lhUWXy1p02Fqs.png.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\VXH5-9Fvv35aa.mkv.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\hrtjCD\F_LulY8W\3YN_CZT0O\MLvw4mqRtz.avi.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\w0zGj7\-2MV6FGAE4D1-PP.mp3.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Eg88RvD9 0Q\6v_GjOVHeDke-Y3M\sRUOtqizCyllBw.ppt.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\y4ku7XlYv9rOmwi9fI03.xls.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\1vWfqsjVTWGSUS.xlsx.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_0\icon_128.png.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\PCbPc rP-EC.csv.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.2_0\images\icon_16.png.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\hrtjCD\F_LulY8W\_wpFDzC4c\1haWBOfE1YVpZe8.mkv.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\xEh-oxAfvWyU\acl-DpKaW 5fpZHwidq\VPwgVJ V6.jpg.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\xEh-oxAfvWyU\E UIU.jpg.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\hrtjCD\TiihY9hIrj6mmVaCc.mkv.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5817.313.0.5_0\cloud_route_details\view.html.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\yQ-1dHssrB2.mkv.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_0\128.png.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_0\icon_16.png.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\NCGvpor.pptx.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\JyJdSqIe 2Z0R.pptx.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_0\icon_16.png.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\hrtjCD\myyS1vW7I04KVf1CY.mkv.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\xEh-oxAfvWyU\acl-DpKaW 5fpZHwidq\mwp19bN3v8nT3Zo3dB.png.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\0OTmfF.docx.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Eg88RvD9 0Q\NRPhW82cAnOla-nt-U\D1iL9p 83bubKmetxE\9QXV8.xls.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Eg88RvD9 0Q\6v_GjOVHeDke-Y3M\GYEObU9OG.doc.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\vxYh3Ayo0sM10H.jpg.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\Local\Microsoft\Windows Mail\Stationery\OrangeCircles.jpg.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\hrtjCD\F_LulY8W\1O0_UNXpWhB_5sU17aHW\NJf4QF.mkv.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\AEyp9Uli.pptx.BlackHat | Created File | Stream |
Not Queried
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8NTidvOEMXsM3 N_\2VxtV24zm0.jpg.BlackHat | Created File | Stream |
Not Queried
|
...
|