VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware |
yu.exe
Windows Exe (x86-32)
Created at 2019-07-29T16:53:00
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x4086fe |
Size Of Code | 0x6800 |
Size Of Initialized Data | 0x800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2047-12-27 00:10:08+00:00 |
Version Information (11)
»
Assembly Version | 1.0.0.0 |
Comments | - |
CompanyName | - |
FileDescription | WindowsFormsApp1 |
FileVersion | 1.0.0.0 |
InternalName | WindowsFormsApp1.exe |
LegalCopyright | Copyright © 2019 |
LegalTrademarks | - |
OriginalFilename | WindowsFormsApp1.exe |
ProductName | WindowsFormsApp1 |
ProductVersion | 1.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x6704 | 0x6800 | 0x200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.15 |
.rsrc | 0x40a000 | 0x5ec | 0x600 | 0x6a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.19 |
.reloc | 0x40c000 | 0xc | 0x200 | 0x7000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.06 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x86d4 | 0x68d4 | 0x0 |
Memory Dumps (42)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
system.configuration.ni.dll | 1 | 0x70660000 | 0x70754FFF | Content Changed | - | 32-bit | 0x706821E8 |
...
|
||
system.configuration.ni.dll | 1 | 0x70660000 | 0x70754FFF | Content Changed | - | 32-bit | 0x70686304 |
...
|
||
system.configuration.ni.dll | 1 | 0x70660000 | 0x70754FFF | Content Changed | - | 32-bit | 0x706812F0 |
...
|
||
system.configuration.ni.dll | 1 | 0x70660000 | 0x70754FFF | Content Changed | - | 32-bit | 0x70683000 |
...
|
||
system.configuration.ni.dll | 1 | 0x70660000 | 0x70754FFF | Content Changed | - | 32-bit | 0x70684000 |
...
|
||
system.configuration.ni.dll | 1 | 0x70660000 | 0x70754FFF | Content Changed | - | 32-bit | 0x70688084 |
...
|
||
system.configuration.ni.dll | 1 | 0x70660000 | 0x70754FFF | Content Changed | - | 32-bit | 0x70692C0C |
...
|
||
system.configuration.ni.dll | 1 | 0x70660000 | 0x70754FFF | Content Changed | - | 32-bit | 0x70687000 |
...
|
||
system.configuration.ni.dll | 1 | 0x70660000 | 0x70754FFF | Content Changed | - | 32-bit | 0x70689560 |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71BF2AC0 |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71BF2AC8 |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71C0B788 |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71BF43C4 |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71C0A3B8 |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71C01000 |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71C0C000 |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71BFDAF0, 0x71C07170 |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71C08388 |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71C05300 |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71CBF36C, 0x71BF6274 |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71CD5660, 0x71C0D0DC, ... |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71CB94A8, 0x71C06BB8 |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71C02000 |
...
|
||
buffer | 1 | 0x04963000 | 0x04964FFF | First Execution | - | 32-bit | 0x04963B86, 0x04963DDE |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71BF3600, 0x71C07760, ... |
...
|
||
system.configuration.ni.dll | 1 | 0x70660000 | 0x70754FFF | Content Changed | - | 32-bit | 0x70678A10, 0x70688084, ... |
...
|
||
system.configuration.ni.dll | 1 | 0x70660000 | 0x70754FFF | Content Changed | - | 32-bit | 0x70682F00, 0x70687000 |
...
|
||
system.configuration.ni.dll | 1 | 0x70660000 | 0x70754FFF | Content Changed | - | 32-bit | 0x706779C0 |
...
|
||
system.configuration.ni.dll | 1 | 0x70660000 | 0x70754FFF | Content Changed | - | 32-bit | 0x706779C0 |
...
|
||
system.configuration.ni.dll | 1 | 0x70660000 | 0x70754FFF | Content Changed | - | 32-bit | 0x7068FC90, 0x7068018C, ... |
...
|
||
buffer | 1 | 0x007A2000 | 0x007A2FFF | First Execution | - | 32-bit | 0x007A2000 |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71C069F0 |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71C0A4B8 |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71C0D5A0 |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71BFE650 |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71C01640 |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71C0C5BC |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71C0B9B4 |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71C03040 |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71C05260 |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71C048A0 |
...
|
||
system.drawing.ni.dll | 1 | 0x71BC0000 | 0x71D53FFF | Content Changed | - | 32-bit | 0x71C03DD0, 0x71C048C0, ... |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Heur.Ransom.REntS.Gen.1 |
Malicious
|
C:\Users\FD1HVy\Desktop\74A7.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\eaPeoUE2b.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\EnckOtc0v1 wz3JqFVR.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\f8zSflIb84wWXVTH.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\FqBS.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\gLeeRljtvdgUfy1N.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\h6YiFxxS37QVLD4Mb.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\I2kERwg0S3Bn2drJjr.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\J4kXM.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\qR5f9LHFb.pdf | Modified File |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\SZAYiAnakYkK6TC_k.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\X0Z4UqjV.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\3k7Q7nShjo\blzf3fQwV9.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\3k7Q7nShjo\HgfDu.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\3k7Q7nShjo\o0yUKa.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\3k7Q7nShjo\SSFabekt\2OWvtAyH7NL39d0y.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\3k7Q7nShjo\SSFabekt\qpeBngVj.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\3k7Q7nShjo\SSFabekt\3WId4uAKnxw8AagZP\kqaKSUiv7A.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\3k7Q7nShjo\SSFabekt\3WId4uAKnxw8AagZP\POOlon6Bf6We7XoXnYui.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\3k7Q7nShjo\SSFabekt\3WId4uAKnxw8AagZP\QMepkq.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\3k7Q7nShjo\SSFabekt\3WId4uAKnxw8AagZP\rrZCUMhn6Uoc.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\3k7Q7nShjo\SSFabekt\3WId4uAKnxw8AagZP\wAaLuNQK9B.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\3k7Q7nShjo\SSFabekt\3WId4uAKnxw8AagZP\_5 17Mtf41QHQOqQBWS.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Links\Desktop.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Links\Downloads.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Links\OneDrive.lnk | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\3y263Mte320.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\amZ62o9DJC9vk.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Cm_Ab4z7WLN.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\F6heNV5E-xQqFdIVQh.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\FOY1QWAoYMk7wv2xN0.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\FPBX.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\hS6-TVw_Q7U.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\j0dB8sQBx21INB_.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\jATO.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\LYOs8u8oZ.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Mt5FvK-2EKzgy.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\QfuWZlMbJV-c9f.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Sx Bws70gV.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\UptbqN1q_LmzJLbfw.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\WNFsbvv.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\XAmK.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\XsllM 6utYk6gjfF.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\y8F1WcyJeMZU.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\ZdWA9k3Y80_o.xlsx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Lv3oHwedbXZcSu\53Gj8_iusbGMeRwvh7.pdf | Modified File |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Lv3oHwedbXZcSu\mSa9.pptx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Lv3oHwedbXZcSu\rBkhUNJlCJ2AByR.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Lv3oHwedbXZcSu\C5kfYBf\CxA-8h.ppt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Lv3oHwedbXZcSu\C5kfYBf\WA1GZRJJ.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Lv3oHwedbXZcSu\fEjGwPNWAnq\BOdytI9VjDcJO0.doc | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Lv3oHwedbXZcSu\fEjGwPNWAnq\Hc4mB7.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Lv3oHwedbXZcSu\GVrsa\orH__ypws.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Lv3oHwedbXZcSu\GVrsa\owESx9ZV6v01DSU_4.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\Lv3oHwedbXZcSu\GVrsa\VQua4tC.csv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\x2xv8-v m80E j-V19RC\31fg AwQcmYF.docx | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\x2xv8-v m80E j-V19RC\3yL4TnX.xls | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\x2xv8-v m80E j-V19RC\lBpQrAqi7E.rtf | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Documents\x2xv8-v m80E j-V19RC\pspFb3Ktl1YJKA_we-0.odt | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\caHdCm5ZkALJF43qeG.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\f-YJ.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\JCyD.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\vzS80.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\ZJ YLKUvOvciSopM.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\-woxNb K_O9zKXeN\7Kmg97I_OdeCtG8n.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\-woxNb K_O9zKXeN\BcFS52ZSEpdK1V.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\-woxNb K_O9zKXeN\JirYQn.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\-woxNb K_O9zKXeN\k-2-1O885MNoJM.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\-woxNb K_O9zKXeN\LSBKOWjn8W.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\-woxNb K_O9zKXeN\M8rdGP3oZ9fG-V.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\-woxNb K_O9zKXeN\sMxLJneSkNV_.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\-woxNb K_O9zKXeN\uF18 Q8.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\-woxNb K_O9zKXeN\ZX-qF96GWo.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\-woxNb K_O9zKXeN\RHGwhhKc1Do\-AtyCb.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\-woxNb K_O9zKXeN\RHGwhhKc1Do\d6Dox.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\-woxNb K_O9zKXeN\RHGwhhKc1Do\g4zy0Eax_VyEX_OBuQ.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\-woxNb K_O9zKXeN\RHGwhhKc1Do\JF2Pk.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\-woxNb K_O9zKXeN\RHGwhhKc1Do\M4x195GlpmEvE.bmp | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\-woxNb K_O9zKXeN\RHGwhhKc1Do\Q5Q8.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\-woxNb K_O9zKXeN\RHGwhhKc1Do\qyT3v41bZT7I.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\-woxNb K_O9zKXeN\RHGwhhKc1Do\SRl88TjekCaMM.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\-woxNb K_O9zKXeN\RHGwhhKc1Do\V2XFxH.jpg | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Pictures\-woxNb K_O9zKXeN\RHGwhhKc1Do\wImrzkJwEV6 rXq.png | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\fLW4LMYLirU-nC0jJJ1Z.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\LPV6e-vtK44oT.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\T3quZ.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\HN5LFauNzLkfUgUI\SdsMj.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\HN5LFauNzLkfUgUI\h2NNl-aviim\xGvuOmzmxFv j0.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\YAwMCl\6Au4i.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\YAwMCl\skyo5xSOuGK9nNGk.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Music\YAwMCl\xsd4N9uzSGvwqZsVd.mp3 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\-ZM6zMnbZHo.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\asJlnAQ5rIB4OYkt_vf.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\EoRCZCo5A.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\4FiGCYD_w_PP5vLxh\Mu P_UHUY1SC7T.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\4FiGCYD_w_PP5vLxh\Dq2SNJx\l6FHYwfSwXN3Xds99u.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\4FiGCYD_w_PP5vLxh\Dq2SNJx\ZuXpS4Dtlgm7.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\4FiGCYD_w_PP5vLxh\Iy1yi_-xrYBR8E3b9rH\GKiY4YQe.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\4FiGCYD_w_PP5vLxh\Iy1yi_-xrYBR8E3b9rH\m2Zbe.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\4FiGCYD_w_PP5vLxh\Iy1yi_-xrYBR8E3b9rH\oDBGD-zYV4 QxOZA\4k5mCR53.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\4FiGCYD_w_PP5vLxh\Iy1yi_-xrYBR8E3b9rH\oDBGD-zYV4 QxOZA\5O9D-A06k4ESsgPcS.mp4 | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\4FiGCYD_w_PP5vLxh\Iy1yi_-xrYBR8E3b9rH\oDBGD-zYV4 QxOZA\hVqHBe9dWNHNlwt\azV7Y4UPA12dWJ3nhV8.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\4FiGCYD_w_PP5vLxh\Iy1yi_-xrYBR8E3b9rH\oDBGD-zYV4 QxOZA\hVqHBe9dWNHNlwt\sLm076QEFwgmUphdSxVV.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\4FiGCYD_w_PP5vLxh\TIDWwOWdM-zC6hM\KQRaa8rlEE Ji-XGFc.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\4FiGCYD_w_PP5vLxh\TIDWwOWdM-zC6hM\oieOn1iwaEXeUliO.mkv | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\4FiGCYD_w_PP5vLxh\TIDWwOWdM-zC6hM\w-g1yWo.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Videos\4FiGCYD_w_PP5vLxh\TIDWwOWdM-zC6hM\_rEDei_Irt3TqrgPMF.avi | Modified File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\READ_IT.txt | Dropped File | Text |
Unknown
|
...
|
»
C:\Users\FD1HVy\Desktop\READ_IT.txt | Dropped File | Stream |
Unknown
|
...
|
»