Dynamic Analysis Report |
Classification: Ransomware |
b4f05277bafc06af87fccb02a444e5a22b3760f98c05bf0f6cf5344da7faa543 (SHA256)
sample_file.exe
Created at 2018-08-15 03:27:00
Notifications (1/1)
The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.
Remarks
The maximum number of reputation file hash requests (20 per analysis) was exceeded. As a result, the reputation status could not be queried for all file hashes. In order to get the reputation status for all file hashes, please increase the 'Max File Hash Requests' setting in the system configurations.
This list contains only the embedded files and created files
Filters: |
There are no files for this filter
Filename | Category | Type | Severity | Actions |
---|
Image Base | 0x400000 |
Entry Point | 0x40d875 |
Size Of Code | 0x31200 |
Size Of Initialized Data | 0x1ac00 |
File Type | executable |
Subsystem | windows_gui |
Machine Type | i386 |
Compile Timestamp | 2018-08-01 13:26:58+00:00 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x311d2 | 0x31200 | 0x400 | cnt_code, mem_execute, mem_read | 6.62 |
.rdata | 0x433000 | 0x13d70 | 0x13e00 | 0x31600 | cnt_initialized_data, mem_read | 4.76 |
.data | 0x447000 | 0x3850 | 0x2000 | 0x45400 | cnt_initialized_data, mem_read, mem_write | 4.08 |
.rsrc | 0x44b000 | 0x1e0 | 0x200 | 0x47400 | cnt_initialized_data, mem_read | 4.71 |
.reloc | 0x44c000 | 0x3070 | 0x3200 | 0x47600 | cnt_initialized_data, mem_discardable, mem_read | 6.52 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FindFirstFileW | 0x0 | 0x433008 | 0x461d8 | 0x447d8 | 0x139 |
FindNextFileW | 0x0 | 0x43300c | 0x461dc | 0x447dc | 0x145 |
lstrlenW | 0x0 | 0x433010 | 0x461e0 | 0x447e0 | 0x54e |
WriteFile | 0x0 | 0x433014 | 0x461e4 | 0x447e4 | 0x525 |
GetDiskFreeSpaceW | 0x0 | 0x433018 | 0x461e8 | 0x447e8 | 0x1cf |
CreateMutexW | 0x0 | 0x43301c | 0x461ec | 0x447ec | 0x9e |
FindClose | 0x0 | 0x433020 | 0x461f0 | 0x447f0 | 0x12e |
CreateFileW | 0x0 | 0x433024 | 0x461f4 | 0x447f4 | 0x8f |
Sleep | 0x0 | 0x433028 | 0x461f8 | 0x447f8 | 0x4b2 |
GetFileAttributesExW | 0x0 | 0x43302c | 0x461fc | 0x447fc | 0x1e7 |
GetLogicalDrives | 0x0 | 0x433030 | 0x46200 | 0x44800 | 0x209 |
CloseHandle | 0x0 | 0x433034 | 0x46204 | 0x44804 | 0x52 |
LoadLibraryW | 0x0 | 0x433038 | 0x46208 | 0x44808 | 0x33f |
GetProcAddress | 0x0 | 0x43303c | 0x4620c | 0x4480c | 0x245 |
GetComputerNameW | 0x0 | 0x433040 | 0x46210 | 0x44810 | 0x18f |
GetModuleHandleW | 0x0 | 0x433044 | 0x46214 | 0x44814 | 0x218 |
OpenMutexW | 0x0 | 0x433048 | 0x46218 | 0x44818 | 0x37d |
MoveFileW | 0x0 | 0x43304c | 0x4621c | 0x4481c | 0x363 |
GetDriveTypeW | 0x0 | 0x433050 | 0x46220 | 0x44820 | 0x1d3 |
DecodePointer | 0x0 | 0x433054 | 0x46224 | 0x44824 | 0xca |
WriteConsoleW | 0x0 | 0x433058 | 0x46228 | 0x44828 | 0x524 |
HeapReAlloc | 0x0 | 0x43305c | 0x4622c | 0x4482c | 0x2d2 |
GetUserDefaultLCID | 0x0 | 0x433060 | 0x46230 | 0x44830 | 0x29b |
ReadFile | 0x0 | 0x433064 | 0x46234 | 0x44834 | 0x3c0 |
HeapSize | 0x0 | 0x433068 | 0x46238 | 0x44838 | 0x2d4 |
SetFilePointerEx | 0x0 | 0x43306c | 0x4623c | 0x4483c | 0x467 |
GetConsoleMode | 0x0 | 0x433070 | 0x46240 | 0x44840 | 0x1ac |
GetConsoleCP | 0x0 | 0x433074 | 0x46244 | 0x44844 | 0x19a |
FlushFileBuffers | 0x0 | 0x433078 | 0x46248 | 0x44848 | 0x157 |
GetStringTypeW | 0x0 | 0x43307c | 0x4624c | 0x4484c | 0x269 |
SetStdHandle | 0x0 | 0x433080 | 0x46250 | 0x44850 | 0x487 |
FreeEnvironmentStringsW | 0x0 | 0x433084 | 0x46254 | 0x44854 | 0x161 |
GetEnvironmentStringsW | 0x0 | 0x433088 | 0x46258 | 0x44858 | 0x1da |
GetCommandLineW | 0x0 | 0x43308c | 0x4625c | 0x4485c | 0x187 |
GetCommandLineA | 0x0 | 0x433090 | 0x46260 | 0x44860 | 0x186 |
GetCPInfo | 0x0 | 0x433094 | 0x46264 | 0x44864 | 0x172 |
GetOEMCP | 0x0 | 0x433098 | 0x46268 | 0x44868 | 0x237 |
EnterCriticalSection | 0x0 | 0x43309c | 0x4626c | 0x4486c | 0xee |
LeaveCriticalSection | 0x0 | 0x4330a0 | 0x46270 | 0x44870 | 0x339 |
TryEnterCriticalSection | 0x0 | 0x4330a4 | 0x46274 | 0x44874 | 0x4ce |
DeleteCriticalSection | 0x0 | 0x4330a8 | 0x46278 | 0x44878 | 0xd1 |
GetCurrentThreadId | 0x0 | 0x4330ac | 0x4627c | 0x4487c | 0x1c5 |
DuplicateHandle | 0x0 | 0x4330b0 | 0x46280 | 0x44880 | 0xe8 |
WaitForSingleObjectEx | 0x0 | 0x4330b4 | 0x46284 | 0x44884 | 0x4fa |
GetCurrentProcess | 0x0 | 0x4330b8 | 0x46288 | 0x44888 | 0x1c0 |
GetCurrentThread | 0x0 | 0x4330bc | 0x4628c | 0x4488c | 0x1c4 |
GetExitCodeThread | 0x0 | 0x4330c0 | 0x46290 | 0x44890 | 0x1e0 |
QueryPerformanceCounter | 0x0 | 0x4330c4 | 0x46294 | 0x44894 | 0x3a7 |
SetLastError | 0x0 | 0x4330c8 | 0x46298 | 0x44898 | 0x473 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4330cc | 0x4629c | 0x4489c | 0x2e3 |
CreateEventW | 0x0 | 0x4330d0 | 0x462a0 | 0x448a0 | 0x85 |
TlsAlloc | 0x0 | 0x4330d4 | 0x462a4 | 0x448a4 | 0x4c5 |
TlsGetValue | 0x0 | 0x4330d8 | 0x462a8 | 0x448a8 | 0x4c7 |
TlsSetValue | 0x0 | 0x4330dc | 0x462ac | 0x448ac | 0x4c8 |
TlsFree | 0x0 | 0x4330e0 | 0x462b0 | 0x448b0 | 0x4c6 |
GetSystemTimeAsFileTime | 0x0 | 0x4330e4 | 0x462b4 | 0x448b4 | 0x279 |
GetTickCount | 0x0 | 0x4330e8 | 0x462b8 | 0x448b8 | 0x293 |
GetLastError | 0x0 | 0x4330ec | 0x462bc | 0x448bc | 0x202 |
WideCharToMultiByte | 0x0 | 0x4330f0 | 0x462c0 | 0x448c0 | 0x511 |
UnhandledExceptionFilter | 0x0 | 0x4330f4 | 0x462c4 | 0x448c4 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x4330f8 | 0x462c8 | 0x448c8 | 0x4a5 |
TerminateProcess | 0x0 | 0x4330fc | 0x462cc | 0x448cc | 0x4c0 |
IsProcessorFeaturePresent | 0x0 | 0x433100 | 0x462d0 | 0x448d0 | 0x304 |
IsDebuggerPresent | 0x0 | 0x433104 | 0x462d4 | 0x448d4 | 0x300 |
GetStartupInfoW | 0x0 | 0x433108 | 0x462d8 | 0x448d8 | 0x263 |
GetCurrentProcessId | 0x0 | 0x43310c | 0x462dc | 0x448dc | 0x1c1 |
InitializeSListHead | 0x0 | 0x433110 | 0x462e0 | 0x448e0 | 0x2e7 |
CreateTimerQueue | 0x0 | 0x433114 | 0x462e4 | 0x448e4 | 0xbc |
SetEvent | 0x0 | 0x433118 | 0x462e8 | 0x448e8 | 0x459 |
SignalObjectAndWait | 0x0 | 0x43311c | 0x462ec | 0x448ec | 0x4b0 |
SwitchToThread | 0x0 | 0x433120 | 0x462f0 | 0x448f0 | 0x4bc |
CreateThread | 0x0 | 0x433124 | 0x462f4 | 0x448f4 | 0xb5 |
SetThreadPriority | 0x0 | 0x433128 | 0x462f8 | 0x448f8 | 0x499 |
GetThreadPriority | 0x0 | 0x43312c | 0x462fc | 0x448fc | 0x28e |
GetLogicalProcessorInformation | 0x0 | 0x433130 | 0x46300 | 0x44900 | 0x20a |
CreateTimerQueueTimer | 0x0 | 0x433134 | 0x46304 | 0x44904 | 0xbd |
ChangeTimerQueueTimer | 0x0 | 0x433138 | 0x46308 | 0x44908 | 0x48 |
DeleteTimerQueueTimer | 0x0 | 0x43313c | 0x4630c | 0x4490c | 0xda |
GetNumaHighestNodeNumber | 0x0 | 0x433140 | 0x46310 | 0x44910 | 0x229 |
GetProcessAffinityMask | 0x0 | 0x433144 | 0x46314 | 0x44914 | 0x246 |
SetThreadAffinityMask | 0x0 | 0x433148 | 0x46318 | 0x44918 | 0x490 |
RegisterWaitForSingleObject | 0x0 | 0x43314c | 0x4631c | 0x4491c | 0x3f5 |
UnregisterWait | 0x0 | 0x433150 | 0x46320 | 0x44920 | 0x4da |
EncodePointer | 0x0 | 0x433154 | 0x46324 | 0x44924 | 0xea |
GetThreadTimes | 0x0 | 0x433158 | 0x46328 | 0x44928 | 0x291 |
FreeLibrary | 0x0 | 0x43315c | 0x4632c | 0x4492c | 0x162 |
FreeLibraryAndExitThread | 0x0 | 0x433160 | 0x46330 | 0x44930 | 0x163 |
GetModuleFileNameW | 0x0 | 0x433164 | 0x46334 | 0x44934 | 0x214 |
GetModuleHandleA | 0x0 | 0x433168 | 0x46338 | 0x44938 | 0x215 |
LoadLibraryExW | 0x0 | 0x43316c | 0x4633c | 0x4493c | 0x33e |
GetVersionExW | 0x0 | 0x433170 | 0x46340 | 0x44940 | 0x2a4 |
VirtualAlloc | 0x0 | 0x433174 | 0x46344 | 0x44944 | 0x4e9 |
VirtualProtect | 0x0 | 0x433178 | 0x46348 | 0x44948 | 0x4ef |
VirtualFree | 0x0 | 0x43317c | 0x4634c | 0x4494c | 0x4ec |
ReleaseSemaphore | 0x0 | 0x433180 | 0x46350 | 0x44950 | 0x3fe |
InterlockedPopEntrySList | 0x0 | 0x433184 | 0x46354 | 0x44954 | 0x2f0 |
InterlockedPushEntrySList | 0x0 | 0x433188 | 0x46358 | 0x44958 | 0x2f1 |
InterlockedFlushSList | 0x0 | 0x43318c | 0x4635c | 0x4495c | 0x2ee |
QueryDepthSList | 0x0 | 0x433190 | 0x46360 | 0x44960 | 0x39e |
UnregisterWaitEx | 0x0 | 0x433194 | 0x46364 | 0x44964 | 0x4db |
RtlUnwind | 0x0 | 0x433198 | 0x46368 | 0x44968 | 0x418 |
RaiseException | 0x0 | 0x43319c | 0x4636c | 0x4496c | 0x3b1 |
HeapAlloc | 0x0 | 0x4331a0 | 0x46370 | 0x44970 | 0x2cb |
HeapFree | 0x0 | 0x4331a4 | 0x46374 | 0x44974 | 0x2cf |
ExitThread | 0x0 | 0x4331a8 | 0x46378 | 0x44978 | 0x11a |
GetModuleHandleExW | 0x0 | 0x4331ac | 0x4637c | 0x4497c | 0x217 |
ExitProcess | 0x0 | 0x4331b0 | 0x46380 | 0x44980 | 0x119 |
MultiByteToWideChar | 0x0 | 0x4331b4 | 0x46384 | 0x44984 | 0x367 |
GetStdHandle | 0x0 | 0x4331b8 | 0x46388 | 0x44988 | 0x264 |
GetACP | 0x0 | 0x4331bc | 0x4638c | 0x4498c | 0x168 |
LCMapStringW | 0x0 | 0x4331c0 | 0x46390 | 0x44990 | 0x32d |
GetProcessHeap | 0x0 | 0x4331c4 | 0x46394 | 0x44994 | 0x24a |
GetFileType | 0x0 | 0x4331c8 | 0x46398 | 0x44998 | 0x1f3 |
FindFirstFileExW | 0x0 | 0x4331cc | 0x4639c | 0x4499c | 0x134 |
IsValidCodePage | 0x0 | 0x4331d0 | 0x463a0 | 0x449a0 | 0x30a |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SystemParametersInfoW | 0x0 | 0x4331e8 | 0x463b8 | 0x449b8 | 0x2ec |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetUserNameW | 0x0 | 0x433000 | 0x461d0 | 0x447d0 | 0x165 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x4331d8 | 0x463a8 | 0x449a8 | 0x122 |
SHGetFolderPathW | 0x0 | 0x4331dc | 0x463ac | 0x449ac | 0xc3 |
SHGetSpecialFolderPathW | 0x0 | 0x4331e0 | 0x463b0 | 0x449b0 | 0xe1 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
socket | 0x17 | 0x433200 | 0x463d0 | 0x449d0 | - |
inet_addr | 0xb | 0x433204 | 0x463d4 | 0x449d4 | - |
WSAStartup | 0x73 | 0x433208 | 0x463d8 | 0x449d8 | - |
closesocket | 0x3 | 0x43320c | 0x463dc | 0x449dc | - |
WSACleanup | 0x74 | 0x433210 | 0x463e0 | 0x449e0 | - |
htons | 0x9 | 0x433214 | 0x463e4 | 0x449e4 | - |
sendto | 0x14 | 0x433218 | 0x463e8 | 0x449e8 | - |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetFileVersionInfoW | 0x0 | 0x4331f0 | 0x463c0 | 0x449c0 | 0x6 |
VerQueryValueW | 0x0 | 0x4331f4 | 0x463c4 | 0x449c4 | 0xe |
GetFileVersionInfoSizeW | 0x0 | 0x4331f8 | 0x463c8 | 0x449c8 | 0x5 |
c:\users\default\documents\desktop.ini.CInq4 | Created File | Stream |
Unknown
|
...
|
c:\users\eebsym5\documents\outlook files\feasf@efw.com.pst.CInq4 | Created File | Stream |
Unknown
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\addons.json.CInq4 | Created File | Stream |
Unknown
|
...
|
c:\users\eebsym5\appdata\roaming\dihBYw6hJ7.rtf.CInq4 | Created File | Stream |
Unknown
|
...
|
c:\users\default\contacts\Administrator.contact.CInq4 | Created File | Stream |
Unknown
|
...
|
c:\users\eebsym5\appdata\roaming\OaY7e6g1t_2dY.rtf.CInq4 | Created File | Stream |
Unknown
|
...
|
c:\users\eebsym5\pictures\arupj0mp4n4fmofl\A7YHcIpYi9.bmp.CInq4 | Created File | Stream |
Unknown
|
...
|
c:\users\eebsym5\desktop\px3idt\kjUgeo.swf.CInq4 | Created File | Stream |
Unknown
|
...
|
c:\users\eebsym5\pictures\arupj0mp4n4fmofl\PizAD39aBNCV.png.CInq4 | Created File | Stream |
Unknown
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\healthreport.sqlite.CInq4 | Created File | Stream |
Unknown
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\key3.db.CInq4 | Created File | Stream |
Unknown
|
...
|
c:\users\eebsym5\pictures\arupj0mp4n4fmofl\Ap9JCsd.png.CInq4 | Created File | Stream |
Unknown
|
...
|
c:\users\eebsym5\documents\tIc5Z2V9Xl.pptx.CInq4 | Created File | Stream |
Unknown
|
...
|
c:\users\eebsym5\videos\6aDouzMxOw3ef7DSP-.mp4.CInq4 | Created File | Stream |
Unknown
|
...
|
c:\users\eebsym5\pictures\eh0pjqt qm8\xDaqfb 0FFb.bmp.CInq4 | Created File | Stream |
Unknown
|
...
|
c:\users\public\recorded tv\desktop.ini.CInq4 | Created File | Stream |
Unknown
|
...
|
c:\users\eebsym5\desktop\axulfpegctdabhejzk\OV2KETm vRcSS.ods.CInq4 | Created File | Stream |
Unknown
|
...
|
c:\users\eebsym5\documents\RDyC2wf_34bEF.xlsx.CInq4 | Created File | Stream |
Unknown
|
...
|
c:\users\eebsym5\documents\NASF.pps.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\desktop\8HiAFVOlg-DGPUklk6n.png.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\nBj6MQZGi5.rtf.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\bYUv.ots.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\all users\package cache\{68306422-7c57-373f-8860-d26ce4ba2a15}v14.10.25017\packages\vcruntimeadditional_x86\cab1.cab.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\ABm6.ots.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\videos\_vk5pq kl98yoyv3\cxb6_or2bF.swf.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\pictures\EVfHSEpo11eW5.jpg.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\desktop\IO7i n.ots.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\desktop\6HjH3n9FWlBwapw.swf.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\public\pictures\sample pictures\Koala.jpg.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\3H1cW86PebjnUv1Yb-m.csv.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\extensions.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\3cekd.docx.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\OJMD.pptx.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\8hEZdFxVBi.png.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\videos\_vk5pq kl98yoyv3\IXPFlcjz_LESFm.mp4.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\signons.sqlite.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\default\favorites\msn websites\MSN Money.url.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\ocyb6cj90z 0oo5H.docx.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\pluginreg.dat.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\desktop\UIaYYkumn.png.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\downloads.sqlite.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\kSYMgW4ng7d7 1NA.pdf.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\default\favorites\msn websites\MSN Entertainment.url.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\_V3vWbuUxbGtebcXi5ye.pps.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\pictures\arupj0mp4n4fmofl\POfl3a-l.png.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\public\pictures\sample pictures\Tulips.jpg.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\sessionstore.bak.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\cookies.sqlite.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\public\pictures\desktop.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\pictures\eh0pjqt qm8\oyfK.jpg.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\desktop\eieHCNgft4loKCrVtA.ods.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\pictures\Qcf9.png.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\default\saved games\desktop.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\content-prefs.sqlite.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\Np_Z.xlsx.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\public\pictures\sample pictures\Lighthouse.jpg.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\njWi97PdpRld9j1s9I.docx.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\yBSa8wX56GadPmdS.xls.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\supbcHre0UqfNWkPh.pptx.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\all users\package cache\{f8cfeb22-a2e7-3971-9eda-4b11edefc185}v12.0.21005\packages\vcruntimeadditional_x86\cab1.cab.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\desktop\Y-1QcNmR1SG.bmp.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\desktop\3V7EOA.bmp.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\g-xmaqg\yvQAWc3evc-ZEpz3Bd.ots.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\desktop\NZqZPYC.bmp.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\desktop\VLAxuSYDTePEe x-1tp.mp4.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\IWX6C7HzotP.xlsx.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\obZ3fvDOvaGgm.bmp.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\indexeddb\moz-safe-about+home\idb\818200132aebmoouht.sqlite.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\public\documents\desktop.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\pictures\arupj0mp4n4fmofl\rD7TFDs4mV8cDgM.png.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\all users\package cache\{bd95a8cd-1d9f-35ad-981a-3e7925026ebb}v11.0.61030\packages\vcruntimeminimum_x86\cab1.cab.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\desktop\axulfpegctdabhejzk\Z8mOx85_eP.xls.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\desktop\sbVtvoiRvzko.bmp.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\outlook files\Outlook Data File - mail.pst.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\public\pictures\sample pictures\desktop.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\g-xmaqg\U7s8rdlV5Oggz.ods.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\public\videos\sample videos\Wildlife.wmv.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\prefs.js.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\public\videos\sample videos\desktop.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\desktop\trmwcmpckt6m5vjebei\QWxH6AY0aE-AZi.ods.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\pictures\eh0pjqt qm8\WCugqKk5RxlbTM4reDQ.bmp.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\videos\_vk5pq kl98yoyv3\vbM81.mp4.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\videos\_vk5pq kl98yoyv3\B32hiOe.swf.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\8NvSUmdCYkRyn LhLT.ots.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\pictures\eh0pjqt qm8\gODSMCuUdn.png.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\desktop\axulfpegctdabhejzk\dJ9gQhS1qT3LJpBx2k_l.mp4.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\9yUXY8Y6QJh.ods.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\default\pictures\desktop.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\g-xmaqg\gIp_.odt.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mxr6.swf.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\videos\_vk5pq kl98yoyv3\d1nH 3xB2.swf.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\public\music\sample music\desktop.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\g-xmaqg\fw Lp8dvf.odt.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\pictures\eh0pjqt qm8\vix_gezF8ko-.jpg.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\K7zQF8IGt3.docx.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\marionette.log.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\contacts\ihnvbh euuncnh.contact.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\default\music\desktop.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\gM1Vd.ppt.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\all users\package cache\{582ea838-9199-3518-a05c-db09462f68ec}v14.10.25017\packages\vcruntimeminimum_x86\cab1.cab.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\default\favorites\msn websites\MSNBC News.url.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\default\downloads\desktop.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\pictures\wYpBBPn78QvIX3mzHn.bmp.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\contacts\mneuc uhnfghgg.contact.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\3Iwyi.xlsx.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\Ru9h2qEjn2zXAzNP.jpg.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\videos\avrcxqmp79rz1zwr-l\s1xagxh3n\q5GYI.swf.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\default\links\desktop.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\desktop\igRWm8V5jW5uAeAOnz.jpg.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\public\pictures\sample pictures\Jellyfish.jpg.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\w93jUZej_fLnqMETz.xlsx.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\desktop\axulfpegctdabhejzk\tMsz9fchZoyeFz.swf.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\favorites\links\Suggested Sites.url.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\g-xmaqg\Cnlpr30MwlY8sM-K.docx.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\pictures\arupj0mp4n4fmofl\xZwNFgm.bmp.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\default\favorites\links\Web Slice Gallery.url.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\default\searches\desktop.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\pictures\HGk7Np.png.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\desktop\5uaSKEr4bBUrOcV.odt.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\public\videos\desktop.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\g-xmaqg\K 4psb38WGnfz4j.ods.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\ZQFPlLLJcG.ots.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\videos\_vk5pq kl98yoyv3\vUstnWNlj2UXr.mp4.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\g-xmaqg\XOrkn1xji3i.xlsx.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\default\desktop\desktop.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\default\favorites\links\desktop.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\public\libraries\desktop.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\webappsstore.sqlite.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\kPtXRE8YDE0HhLGDx 5b.ods.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\contacts\uosjfl sidvllie.contact.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\e371x5yB-BXL9.jpg.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\76uxv GdaUFGtb--clr.odp.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\public\downloads\desktop.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mkaLZ5.bmp.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\all users\sun\java\java update\jaureglist.xml.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\secmod.db.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\videos\avrcxqmp79rz1zwr-l\s1xagxh3n\jXhmIqDeW.swf.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\desktop\XXPGWpk8dID vR4aFz.doc.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\videos\_vk5pq kl98yoyv3\TwLl1bqJZc.swf.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\_Pd5ksq8IUStSyz0u.xls.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\my shapes\desktop.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\default\favorites\msn websites\MSN Sports.url.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\pictures\eh0pjqt qm8\nukHOa.bmp.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\public\pictures\sample pictures\Hydrangeas.jpg.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\sessionstore.js.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\extensions.sqlite.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\RGyKpkSEjm.docx.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\pictures\eh0pjqt qm8\QZ9j-.png.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\default\favorites\desktop.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\places.sqlite.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\nIGxj2X.bmp.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\all users\mozilla\logs\maintenanceservice-install.log.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\pictures\arupj0mp4n4fmofl\xTjJo96DDpNhn.png.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\d-BXDU.bmp.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\desktop\px3idt\5nu8-FDf95Oj.bmp.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\videos\avrcxqmp79rz1zwr-l\iJcUEX2RgIDZ.mp4.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\all users\package cache\{b175520c-86a2-35a7-8619-86dc379688b9}v11.0.61030\packages\vcruntimeadditional_x86\cab1.cab.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\contacts\lodkd auftnm.contact.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\public\pictures\sample pictures\Desert.jpg.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\public\recorded tv\sample media\desktop.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\uVSh.pps.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\default\favorites\msn websites\MSN.url.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\KKJxf.odt.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\g-xmaqg\JDFcqscJecsJjXXzI0.csv.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\pictures\-11mX.bmp.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\JpLHr.ppt.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\desktop\XSotipysXjYhxFGSuq.swf.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\HhYrj IfrM.xls.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\default\contacts\desktop.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\compatibility.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\BNzgUVXC_-s-x2x5xNT.png.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\permissions.sqlite.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\pictures\6ZJkVBSeo-K.bmp.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\times.json.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\urlclassifierkey3.txt.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\contacts\ofhbnh edferrr.contact.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\search.json.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\default\favorites\msn websites\MSN Autos.url.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\public\pictures\sample pictures\Penguins.jpg.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\b0MkGEDi.xlsx.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\default\videos\desktop.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\public\desktop\desktop.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\pictures\k8Qcy.bmp.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\desktop\wK28d7RA9P.pptx.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\g-xmaqg\BPx3bYqOm-C9WtkLE.rtf.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\desktop\sP5Wi4z896PmAG.pptx.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\pictures\49th-XF.png.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\Ae6V-x68xHulBAqnmyv.pptx.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\c0bPbn3eRI.pptx.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles.ini.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\AKoSG19.rtf.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\VyTyj-R9XKxPoJL.docx.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\bookmarkbackups\bookmarks-2017-05-31_5.json.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\public\pictures\sample pictures\Chrysanthemum.jpg.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\g-xmaqg\wGvLKkGVV0g.odp.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\mozilla\firefox\profiles\h231daer.default\cert8.db.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\g-xmaqg\DoGsxAS fzsv3usVcLF.rtf.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\uihiW9lJeoF869.swf.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\desktop\axulfpegctdabhejzk\2zf9Tk.png.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\all users\package cache\{13a4ee12-23ea-3371-91ee-efb36ddfff3e}v12.0.21005\packages\vcruntimeminimum_x86\cab1.cab.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\g-xmaqg\qd0VlesT.odp.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\qlAW n9SCgpzn.pptx.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\pictures\arupj0mp4n4fmofl\MRaActwrCBxT.jpg.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\0JkVowKW67ScNs.xlsx.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\documents\VQ1gd7oiEKIkQ.docx.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\appdata\roaming\3tOLu7_.bmp.CInq4 | Created File | Stream |
Not Queried
|
...
|
c:\users\eebsym5\pictures\arupj0mp4n4fmofl\X6Y7yPEXZvVxK8gGc.png.CInq4 | Created File | Stream |
Not Queried
|
...
|