Dynamic Analysis Report |
Classification: Riskware, Trojan, Ransomware |
9da7d298691613a398e26ac3c4c4e4e9c93069d2162fa6639901dd7c62774ef5 (SHA256)
T1.exe
Created at 2019-01-24 16:56:00
Notifications (2/5)
Some extracted files may be missing in the report since the total file extraction size limit was reached during the analysis. You can increase the limit in the configuration settings.
Some extracted files may be missing in the report since the maximum number of extracted files was reached during the analysis. You can increase the limit in the configuration settings.
The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.
The overall sleep time of all monitored processes was truncated from "17 minutes, 5 seconds" to "2 minutes, 40 seconds" to reveal dormant functionality.
The operating system was rebooted during the analysis.
Remarks
Some extracted files may be missing in the report since the total file extraction size limit was reached during the analysis. You can increase the limit in the configuration settings.
Some extracted files may be missing in the report since the maximum number of extracted files was reached during the analysis. You can increase the limit in the configuration settings.
The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.
This list contains only the embedded files and created files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
Severity |
Suspicious
|
First Seen | 2019-01-23 17:06 (UTC+1) |
Last Seen | 2019-01-24 17:51 (UTC+1) |
Names | ByteCode-MSIL.Trojan.Filecoder |
Families | Filecoder |
Classification | Trojan |
Image Base | 0x400000 |
Entry Point | 0x407cde |
Size Of Code | 0x5e00 |
Size Of Initialized Data | 0x1400 |
File Type | executable |
Subsystem | windows_gui |
Machine Type | i386 |
Compile Timestamp | 2080-09-29 02:11:53+00:00 |
Assembly Version | 1.0.0.0 |
LegalCopyright | Copyright © 2019 |
InternalName | T1.exe |
FileVersion | 1.0.0.0 |
CompanyName | - |
LegalTrademarks | - |
Comments | - |
ProductName | T1 |
ProductVersion | 1.0.0.0 |
FileDescription | T1 |
OriginalFilename | T1.exe |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x402000 | 0x5ce4 | 0x5e00 | 0x200 | cnt_code, mem_execute, mem_read | 5.74 |
.rsrc | 0x408000 | 0x10b8 | 0x1200 | 0x6000 | cnt_initialized_data, mem_read | 4.94 |
.reloc | 0x40a000 | 0xc | 0x200 | 0x7200 | cnt_initialized_data, mem_discardable, mem_read | 0.08 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | 0x0 | 0x402000 | 0x7cb4 | 0x5eb4 | 0x0 |
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIDE.dll | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\Edit_R_Exp_RHP.aapp | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\CPDF_Full.aapp | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\LogTransport2.exe | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\ccme_base_non_fips.dll | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\Protect_R_RHP.aapp | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\cef.pak | Modified File | Stream |
Unknown
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\1033\TM03328935[[fn=Picture Organization Chart]].glox | Modified File | Stream |
Unknown
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\TM03457515[[fn=View]].thmx | Modified File | Stream |
Unknown
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Adobe\Flash Player\NativeCache\NativeCache.directory | Modified File | Stream |
Unknown
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Bibliography\Style\MLASeventhEditionOfficeOnline.xsl | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\AppCenter_R.aapp | Modified File | Stream |
Unknown
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\hGiFShE.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\5N0mP.mp3 | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\ACE.dll | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\Edit_R_RHP.aapp | Modified File | Stream |
Unknown
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Onix32.dll | Modified File | Stream |
Unknown
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\Welcome to Excel.xltx | Modified File | Stream |
Unknown
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobData | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\ViewerPS.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\gwX91CRt0Sj.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\TP9I5YPYS.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Access\AccessCache.accdb | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\d3dcompiler_43.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\cjaeW XgxzGyM50.doc | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\BIBUtils.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\OneNote\16.0\Preferences.dat | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Bibliography\Style\APASixthEditionOfficeOnline.xsl | Modified File | Stream |
Not Queried
|
...
|
c:\users\ciihmn~1\appdata\local\temp\don.bmp | Modified File | Image |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Office\Recent\Global.LNK | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\PiQQ2Af9SozQW.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\FDO8HMeSGmQJ.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\pVHPwtaaDNFAoC4M.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Outlook 2016.lnk | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\TM10001103[[fn=Headlines]].thmx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\1033\TM03328893[[fn=BracketList]].glox | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\Home.aapp | Modified File | Unknown |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Acrofx32.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\0FDED5CEB68C302B1CDB2BDDD9D0000E76539CB0.crl | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\FillSign.aapp | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeCollabSync.exe | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Jj961q86p5_E.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Bibliography\Style\TURABIAN.XSL | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\TM10001105[[fn=Crop]].thmx | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\cryptocme.sig | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\1HGO.pps | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Eula.exe | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Word 2016.lnk | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\1033\TM03328940[[fn=Radial Picture List]].glox | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\Scan_R_RHP.aapp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Bibliography\Style\SIST02.XSL | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Network\Connections\Pbk\_hiddenPbk\rasphone.pbk | Modified File | Text |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\TM03457464[[fn=Dividend]].thmx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\gW_ 0mkl9Fl_moi.png | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\EPWxIuv.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\JP2KLib.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\CollectSignatures.aapp | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroTextExtractor.exe | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\TM10001115[[fn=Parcel]].thmx | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\pmd.cer | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\1033\TM03328919[[fn=Hexagon Radial]].glox | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Office\Recent\Documents.LNK | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\logsession.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\Compare_R_RHP.aapp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\1033\TM03328951[[fn=Tabbed Arc]].glox | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\icudt40.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Bibliography\Style\ISO690.XSL | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\rt3d.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\Measure.aapp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Outlook\Outlook.srs | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Adobe\LogTransport2\LogTransport2.cfg | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\TrackedSend.aapp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\TM10001114[[fn=Gallery]].thmx | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32Info.exe | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\iQKMvUzGPjtGBd0lRgyy.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\1033\TM03328925[[fn=Interconnected Block Process]].glox | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Outlook\Outlook.xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\aF5hPNlB271.ppt | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\ccme_asym.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeXMP.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\TM03457444[[fn=Basis]].thmx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\1033\TM03328908[[fn=Circle Process]].glox | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\MoreTools.aapp | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32Res.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\G5MbiMZSXdsj9RRuy4.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Document Building Blocks\1033\16\Built-In Building Blocks.dotx | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\arh.exe | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\Edit_R_Full.aapp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\1033\TM03328972[[fn=Tab List]].glox | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\Cashflow analysis.xltm | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\fXiuXdEX.mp4 | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\icucnv40.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\TM04033919[[fn=Circuit]].thmx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Bibliography\Style\GostTitle.XSL | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroBroker.exe | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\DirectInk.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\TM04033917[[fn=Berlin]].thmx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\TM04033929[[fn=Slate]].thmx | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\Stamp.aapp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Project 2016.lnk | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AGMGPUOptIn.ini | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\PDFSigQFormalRep.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Publisher Building Blocks\ContentStore.xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\1033\TM03328916[[fn=Converging Text]].glox | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\sqlite.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\Calendar insights.xltm | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\cef_100_percent.pak | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\d3dcompiler_47.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\ScCore.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\MS Project\16\en-US\Global.MPT | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\pe.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\ReadMe.htm | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\chrome_elf.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\Email Insights.xltm | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\6jKSrZJ88Nt.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\TM03457491[[fn=Metropolitan]].thmx | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\Certificates_R.aapp | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\RTC.der | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\BWs 3bhQ1.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\kPvJOo_e0v2YY.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Office\Recent\Database1.LNK | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\sqlite.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\1XHufR-DxIGxuK V.gif | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\ahclient.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\Process Map for Basic Flowchart.xltx | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\CPDF_RHP.aapp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\ZMyqqk.avi | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\cef_extensions.pak | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\TM03090430[[fn=Banded]].thmx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\TM03090434[[fn=Wood Type]].thmx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\TM04033927[[fn=Main Event]].thmx | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\CE338828149963DCEA4CD26BB86F0363B4CA0BA5.crl | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Bibliography\Style\GostName.XSL | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\Normal.dotm | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\TM04033921[[fn=Damask]].thmx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\TM04033937[[fn=Vapor Trail]].thmx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Access\System.mdw | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\Viewer.aapp | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\ccme_ecc.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Bibliography\Style\IEEE2006OfficeOnline.xsl | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\CoolType.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\ADelRCP.exe | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\TM03457485[[fn=Mesh]].thmx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\TM04033925[[fn=Droplet]].thmx | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\Pages_R_RHP.aapp | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\cef_200_percent.pak | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\cryptocme.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Adobe\Acrobat\DC\Security\addressbook.acrodata | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\BIB.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\Comments.aapp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Bibliography\Style\HarvardAnglia2008OfficeOnline.xsl | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AXSLE.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\1494870C-9912-C184-4CC9-B401-A53F4D8DE290.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\TM03457475[[fn=Frame]].thmx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Excel 2016.lnk | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\reader_sl.exe | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\7h3QF4wV.mkv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Office\MSO1033.acl | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\Stock symbols comparison.xltm | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Office\Recent\Templates.LNK | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\q0Lfg4X0PkE9ZS3se1w.wav | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\vRIJHQaZ.mp3 | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\TM10001104[[fn=Feathered]].thmx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\1033\TM03328975[[fn=Theme Picture Accent]].glox | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\lbYChRg-xAiK-KFgsEDW.gif | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\1033\TM03328983[[fn=Theme Picture Alternating Accent]].glox | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AdobeLinguistic.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\15xo6kifu pmSmCyy-0r.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\OneNote 2016.lnk | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AXE8SharedExpat.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\Process Map for Cross-Functional Flowchart.xltx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Bibliography\Style\GB.XSL | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\PDFPrevHndlr.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\1033\TM03328905[[fn=Chevron Accent]].glox | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AGM.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\EPDF_RHP.aapp | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroSup64.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\TiTXeHNWNY.flv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\TM10001106[[fn=Badge]].thmx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Na7yBkRxW5gqqSM.gif | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Adobe\Sonar\Sonar1.0\sonar_policy.xml | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Visio 2016.lnk | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\wow_helper.exe | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\Combine_R_RHP.aapp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\0iZpa3zd4g8L.mkv | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\1033\TM03328986[[fn=Theme Picture Grid]].glox | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\TM03457510[[fn=Savon]].thmx | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\COPYING.LGPLv2.1.txt | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Bibliography\Style\ISO690Nmerical.XSL | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\gG5PhGomRyRPP.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\zPlwGU07 kcnw.pps | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\h2FEIh7b7C.bmp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\TM03457503[[fn=Quotable]].thmx | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\1033\TM03328884[[fn=architecture]].glox | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\EPDF_Full.aapp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\LqkxAaKe.gif | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\ExtendScript.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\ccme_base.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Bibliography\Style\CHICAGO.XSL | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\E_YYe_Gq1htVp.m4a | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Click on 'Change' to select default PDF handler.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\Document Themes\1033\TM03457496[[fn=Parallax]].thmx | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\Redact_R_RHP.aapp | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\A3DUtils.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\adoberfp.dll | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroApp\ENU\OptimizePDF_R_RHP.aapp | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\PowerPoint 2016.lnk | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Adobe.Reader.Dependencies.manifest | Modified File | Stream |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\Welcome.pdf | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Microsoft\Templates\LiveContent\16\Managed\SmartArt Graphics\1033\TM03328932[[fn=Picture Frame]].glox | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings | Modified File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Local\Temp\don.bmp | Created File | Image |
Not Queried
|
...
|
C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\ccme_asym.dll | Created File | Stream |
Not Queried
|
...
|
C:\Users\CIiHmnxMn6Ps\AppData\Local\screen.jpg | Created File | Image |
Not Queried
|
...
|