VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Dharma
Gen:Variant.Ransom.Phobos.62
|
cusersadministratorappdataroamingmicrosoftwindowsstart menuprogramsstartupsystem.exe
Windows Exe (x86-32)
Created at 2020-07-11T13:39:00
Remarks
(0x0200001E): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\FD1HVy\Desktop\cusersadministratorappdataroamingmicrosoftwindowsstart menuprogramsstartupsystem.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x402fa7 |
Size Of Code | 0x8600 |
Size Of Initialized Data | 0x3e00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2020-03-31 14:17:25+00:00 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x8598 | 0x8600 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.59 |
.rdata | 0x40a000 | 0xe7c | 0x1000 | 0x8a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.28 |
.data | 0x40b000 | 0x26b9 | 0x600 | 0x9a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.17 |
.reloc | 0x40e000 | 0x5ee | 0x600 | 0xa000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.7 |
.cdata | 0x40f000 | 0x3618 | 0x3800 | 0xa600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.77 |
Imports (9)
»
MPR.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetEnumResourceW | 0x0 | 0x40a154 | 0xa650 | 0x9050 | 0x1c |
WNetUseConnectionW | 0x0 | 0x40a158 | 0xa654 | 0x9054 | 0x49 |
WNetOpenEnumW | 0x0 | 0x40a15c | 0xa658 | 0x9058 | 0x3d |
WNetCloseEnum | 0x0 | 0x40a160 | 0xa65c | 0x905c | 0x10 |
WS2_32.dll (13)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ioctlsocket | 0xa | 0x40a198 | 0xa694 | 0x9094 | - |
getpeername | 0x5 | 0x40a19c | 0xa698 | 0x9098 | - |
ntohl | 0xe | 0x40a1a0 | 0xa69c | 0x909c | - |
select | 0x12 | 0x40a1a4 | 0xa6a0 | 0x90a0 | - |
WSAGetLastError | 0x6f | 0x40a1a8 | 0xa6a4 | 0x90a4 | - |
htons | 0x9 | 0x40a1ac | 0xa6a8 | 0x90a8 | - |
recv | 0x10 | 0x40a1b0 | 0xa6ac | 0x90ac | - |
socket | 0x17 | 0x40a1b4 | 0xa6b0 | 0x90b0 | - |
closesocket | 0x3 | 0x40a1b8 | 0xa6b4 | 0x90b4 | - |
getsockopt | 0x7 | 0x40a1bc | 0xa6b8 | 0x90b8 | - |
WSAAddressToStringW | 0x0 | 0x40a1c0 | 0xa6bc | 0x90bc | 0xf |
htonl | 0x8 | 0x40a1c4 | 0xa6c0 | 0x90c0 | - |
connect | 0x4 | 0x40a1c8 | 0xa6c4 | 0x90c4 | - |
IPHLPAPI.DLL (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetIpAddrTable | 0x0 | 0x40a038 | 0xa534 | 0x8f34 | 0x54 |
WINHTTP.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WinHttpReceiveResponse | 0x0 | 0x40a17c | 0xa678 | 0x9078 | 0x16 |
WinHttpOpenRequest | 0x0 | 0x40a180 | 0xa67c | 0x907c | 0x10 |
WinHttpConnect | 0x0 | 0x40a184 | 0xa680 | 0x9080 | 0x8 |
WinHttpCloseHandle | 0x0 | 0x40a188 | 0xa684 | 0x9084 | 0x7 |
WinHttpOpen | 0x0 | 0x40a18c | 0xa688 | 0x9088 | 0xf |
WinHttpSendRequest | 0x0 | 0x40a190 | 0xa68c | 0x908c | 0x17 |
KERNEL32.dll (68)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FindClose | 0x0 | 0x40a040 | 0xa53c | 0x8f3c | 0x12e |
FindNextFileW | 0x0 | 0x40a044 | 0xa540 | 0x8f40 | 0x145 |
SystemTimeToFileTime | 0x0 | 0x40a048 | 0xa544 | 0x8f44 | 0x4bd |
OpenProcess | 0x0 | 0x40a04c | 0xa548 | 0x8f48 | 0x380 |
FindFirstFileW | 0x0 | 0x40a050 | 0xa54c | 0x8f4c | 0x139 |
MoveFileW | 0x0 | 0x40a054 | 0xa550 | 0x8f50 | 0x363 |
GetFileSizeEx | 0x0 | 0x40a058 | 0xa554 | 0x8f54 | 0x1f1 |
SetFilePointerEx | 0x0 | 0x40a05c | 0xa558 | 0x8f58 | 0x467 |
SetEndOfFile | 0x0 | 0x40a060 | 0xa55c | 0x8f5c | 0x453 |
GetCurrentThreadId | 0x0 | 0x40a064 | 0xa560 | 0x8f60 | 0x1c5 |
GetLocalTime | 0x0 | 0x40a068 | 0xa564 | 0x8f64 | 0x203 |
ExitProcess | 0x0 | 0x40a06c | 0xa568 | 0x8f68 | 0x119 |
SetFilePointer | 0x0 | 0x40a070 | 0xa56c | 0x8f6c | 0x466 |
WaitForSingleObject | 0x0 | 0x40a074 | 0xa570 | 0x8f70 | 0x4f9 |
GetComputerNameW | 0x0 | 0x40a078 | 0xa574 | 0x8f74 | 0x18f |
SetEvent | 0x0 | 0x40a07c | 0xa578 | 0x8f78 | 0x459 |
GetLogicalDrives | 0x0 | 0x40a080 | 0xa57c | 0x8f7c | 0x209 |
GetTickCount | 0x0 | 0x40a084 | 0xa580 | 0x8f80 | 0x293 |
Sleep | 0x0 | 0x40a088 | 0xa584 | 0x8f84 | 0x4b2 |
CopyFileW | 0x0 | 0x40a08c | 0xa588 | 0x8f88 | 0x75 |
GetFileAttributesW | 0x0 | 0x40a090 | 0xa58c | 0x8f8c | 0x1ea |
ReadFile | 0x0 | 0x40a094 | 0xa590 | 0x8f90 | 0x3c0 |
CreateFileW | 0x0 | 0x40a098 | 0xa594 | 0x8f94 | 0x8f |
MultiByteToWideChar | 0x0 | 0x40a09c | 0xa598 | 0x8f98 | 0x367 |
CreateEventW | 0x0 | 0x40a0a0 | 0xa59c | 0x8f9c | 0x85 |
WaitForMultipleObjects | 0x0 | 0x40a0a4 | 0xa5a0 | 0x8fa0 | 0x4f7 |
CloseHandle | 0x0 | 0x40a0a8 | 0xa5a4 | 0x8fa4 | 0x52 |
SetFileAttributesW | 0x0 | 0x40a0ac | 0xa5a8 | 0x8fa8 | 0x461 |
CreateThread | 0x0 | 0x40a0b0 | 0xa5ac | 0x8fac | 0xb5 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x40a0b4 | 0xa5b0 | 0x8fb0 | 0x2e3 |
LeaveCriticalSection | 0x0 | 0x40a0b8 | 0xa5b4 | 0x8fb4 | 0x339 |
EnterCriticalSection | 0x0 | 0x40a0bc | 0xa5b8 | 0x8fb8 | 0xee |
ResetEvent | 0x0 | 0x40a0c0 | 0xa5bc | 0x8fbc | 0x40f |
DeleteCriticalSection | 0x0 | 0x40a0c4 | 0xa5c0 | 0x8fc0 | 0xd1 |
AllocConsole | 0x0 | 0x40a0c8 | 0xa5c4 | 0x8fc4 | 0x10 |
WriteFile | 0x0 | 0x40a0cc | 0xa5c8 | 0x8fc8 | 0x525 |
WideCharToMultiByte | 0x0 | 0x40a0d0 | 0xa5cc | 0x8fcc | 0x511 |
WriteConsoleW | 0x0 | 0x40a0d4 | 0xa5d0 | 0x8fd0 | 0x524 |
GetStdHandle | 0x0 | 0x40a0d8 | 0xa5d4 | 0x8fd4 | 0x264 |
CreateMutexW | 0x0 | 0x40a0dc | 0xa5d8 | 0x8fd8 | 0x9e |
CreateProcessW | 0x0 | 0x40a0e0 | 0xa5dc | 0x8fdc | 0xa8 |
GetCurrentProcess | 0x0 | 0x40a0e4 | 0xa5e0 | 0x8fe0 | 0x1c0 |
SetHandleInformation | 0x0 | 0x40a0e8 | 0xa5e4 | 0x8fe4 | 0x470 |
HeapFree | 0x0 | 0x40a0ec | 0xa5e8 | 0x8fe8 | 0x2cf |
GetLocaleInfoW | 0x0 | 0x40a0f0 | 0xa5ec | 0x8fec | 0x206 |
ReadProcessMemory | 0x0 | 0x40a0f4 | 0xa5f0 | 0x8ff0 | 0x3c3 |
TerminateProcess | 0x0 | 0x40a0f8 | 0xa5f4 | 0x8ff4 | 0x4c0 |
GetModuleFileNameW | 0x0 | 0x40a0fc | 0xa5f8 | 0x8ff8 | 0x214 |
FlushFileBuffers | 0x0 | 0x40a100 | 0xa5fc | 0x8ffc | 0x157 |
OpenMutexW | 0x0 | 0x40a104 | 0xa600 | 0x9000 | 0x37d |
GetLastError | 0x0 | 0x40a108 | 0xa604 | 0x9004 | 0x202 |
GetProcAddress | 0x0 | 0x40a10c | 0xa608 | 0x9008 | 0x245 |
Process32FirstW | 0x0 | 0x40a110 | 0xa60c | 0x900c | 0x396 |
GetExitCodeThread | 0x0 | 0x40a114 | 0xa610 | 0x9010 | 0x1e0 |
CreatePipe | 0x0 | 0x40a118 | 0xa614 | 0x9014 | 0xa1 |
Process32NextW | 0x0 | 0x40a11c | 0xa618 | 0x9018 | 0x398 |
GetModuleHandleA | 0x0 | 0x40a120 | 0xa61c | 0x901c | 0x215 |
CreateToolhelp32Snapshot | 0x0 | 0x40a124 | 0xa620 | 0x9020 | 0xbe |
ReleaseMutex | 0x0 | 0x40a128 | 0xa624 | 0x9024 | 0x3fa |
GetVersion | 0x0 | 0x40a12c | 0xa628 | 0x9028 | 0x2a2 |
DeleteFileW | 0x0 | 0x40a130 | 0xa62c | 0x902c | 0xd6 |
GetCurrentProcessId | 0x0 | 0x40a134 | 0xa630 | 0x9030 | 0x1c1 |
GetVolumeInformationW | 0x0 | 0x40a138 | 0xa634 | 0x9034 | 0x2a7 |
ExpandEnvironmentStringsW | 0x0 | 0x40a13c | 0xa638 | 0x9038 | 0x11d |
HeapAlloc | 0x0 | 0x40a140 | 0xa63c | 0x903c | 0x2cb |
GetProcessHeap | 0x0 | 0x40a144 | 0xa640 | 0x9040 | 0x24a |
HeapReAlloc | 0x0 | 0x40a148 | 0xa644 | 0x9044 | 0x2d2 |
QueryPerformanceCounter | 0x0 | 0x40a14c | 0xa648 | 0x9048 | 0x3a7 |
USER32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetWindowThreadProcessId | 0x0 | 0x40a170 | 0xa66c | 0x906c | 0x1a4 |
GetShellWindow | 0x0 | 0x40a174 | 0xa670 | 0x9070 | 0x179 |
ADVAPI32.dll (13)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
FreeSid | 0x0 | 0x40a000 | 0xa4fc | 0x8efc | 0x120 |
LookupPrivilegeValueW | 0x0 | 0x40a004 | 0xa500 | 0x8f00 | 0x197 |
OpenProcessToken | 0x0 | 0x40a008 | 0xa504 | 0x8f04 | 0x1f7 |
GetTokenInformation | 0x0 | 0x40a00c | 0xa508 | 0x8f08 | 0x15a |
EqualSid | 0x0 | 0x40a010 | 0xa50c | 0x8f0c | 0x107 |
RegSetValueExW | 0x0 | 0x40a014 | 0xa510 | 0x8f10 | 0x27e |
RegCloseKey | 0x0 | 0x40a018 | 0xa514 | 0x8f14 | 0x230 |
AdjustTokenPrivileges | 0x0 | 0x40a01c | 0xa518 | 0x8f18 | 0x1f |
RegOpenKeyExW | 0x0 | 0x40a020 | 0xa51c | 0x8f1c | 0x261 |
LookupAccountSidW | 0x0 | 0x40a024 | 0xa520 | 0x8f20 | 0x191 |
AllocateAndInitializeSid | 0x0 | 0x40a028 | 0xa524 | 0x8f24 | 0x20 |
DuplicateTokenEx | 0x0 | 0x40a02c | 0xa528 | 0x8f28 | 0xdf |
RegQueryValueExW | 0x0 | 0x40a030 | 0xa52c | 0x8f2c | 0x26e |
SHELL32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteExW | 0x0 | 0x40a168 | 0xa664 | 0x9064 | 0x121 |
ole32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
CoGetObject | 0x0 | 0x40a1d0 | 0xa6cc | 0x90cc | 0x35 |
CoInitializeEx | 0x0 | 0x40a1d4 | 0xa6d0 | 0x90d0 | 0x3f |
CoUninitialize | 0x0 | 0x40a1d8 | 0xa6d4 | 0x90d4 | 0x6c |
Memory Dumps (5)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
cusersadministratorappdataroamingmicrosoftwindowsstart menuprogramsstartupsystem.exe | 1 | 0x011F0000 | 0x01202FFF | Relevant Image | 32-bit | 0x011F7447 |
...
|
|||
cusersadministratorappdataroamingmicrosoftwindowsstart menuprogramsstartupsystem.exe | 2 | 0x011F0000 | 0x01202FFF | Relevant Image | 32-bit | 0x011F1236 |
...
|
|||
buffer | 2 | 0x0012C000 | 0x0012DFFF | Image In Buffer | 32-bit | - |
...
|
|||
cusersadministratorappdataroamingmicrosoftwindowsstart menuprogramsstartupsystem.exe | 1 | 0x011F0000 | 0x01202FFF | Final Dump | 32-bit | 0x011F2BA3 |
...
|
|||
cusersadministratorappdataroamingmicrosoftwindowsstart menuprogramsstartupsystem.exe | 2 | 0x011F0000 | 0x01202FFF | Final Dump | 32-bit | - |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Ransom.Phobos.62 |
Malicious
|
\\?\C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\preoobe.cmd.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\SetupComplete.cmd.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\$Recycle.Bin\S-1-5-18\desktop.ini.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1025\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1028\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1029\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1029\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1030\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1030\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1032\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1033\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Binary |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1035\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1033\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1037\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1040\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1040\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1041\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1042\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1043\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1043\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1044\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1045\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1044\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1046\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1049\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1045\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1053\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1053\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1053\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1049\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1055\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\1055\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2070\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\2052\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3082\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3082\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\3076\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate4.ico.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate8.ico.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Save.ico.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate5.ico.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\SysReqMet.ico.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Core.mzz.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Core_x86.msi.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Program Files\Microsoft Office\root\Office16\ACCWIZ\ACWZTOOL.ACCDE.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Extended_x64.msi.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Extended.mzz.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\RGB9Rast_x86.msi.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\SetupUtility.exe.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\BOOTSECT.BAK.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Internet Explorer.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4MSI and Script.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Binary |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppModel-Runtime%4Admin.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppReadiness%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider%4Admin.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-International%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Known Folders API Service.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Ntfs%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Ntfs%4WHC.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-NetworkProfile%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Store%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TaskScheduler%4Maintenance.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Admin.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Winlogon%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Security.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\Setup.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
\\?\C:\Logs\System.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\common files\designer\msaddndr.olb.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\bin\server\xusage.txt.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\amd64\jvm.cfg.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\cmm\linear_rgb.pf.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\cmm\srgb.pf.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\content-types.properties.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\deploy\ffjcext.zip.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\deploy\messages.properties.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\deploy\messages_de.properties.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\deploy\messages_fr.properties.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\deploy\messages_ja.properties.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\deploy\messages_sv.properties.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\deploy\messages_zh_tw.properties.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\deploy\splash.gif.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\deploy\splash@2x.gif.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\ext\access-bridge-64.jar.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\ext\dnsns.jar.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\ext\jaccess.jar.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\ext\meta-index.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\ext\sunjce_provider.jar.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\ext\sunmscapi.jar.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\ext\sunpkcs11.jar.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\fontconfig.bfc.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\fonts\lucidasansdemibold.ttf.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\fonts\lucidasansregular.ttf.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\fonts\lucidatypewriterbold.ttf.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\fonts\lucidatypewriterregular.ttf.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\images\cursors\cursors.properties.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\images\cursors\invalid32x32.gif.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\images\cursors\win32_linkdrop32x32.gif.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\images\cursors\win32_movedrop32x32.gif.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\images\cursors\win32_movenodrop32x32.gif.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\javaws.jar.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\jce.jar.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\jfr\profile.jfc.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\jfr.jar.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\jfxswt.jar.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\jsse.jar.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\jvm.hprof.txt.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\management\jmxremote.password.template.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\management\management.properties.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\management\snmp.acl.template.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\net.properties.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\psfontj2d.properties.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\security\blacklisted.certs.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\security\cacerts.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Unknown
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\bin\server\classes.jsa.id[b4197730-2869].[robinhood@countermail.com].eject | Modified File | Stream |
Not Queried
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\GetCurrentRollback.ini.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1025\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1025\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1028\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1028\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1029\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1030\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1031\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1031\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1032\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1032\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1031\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1033\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1035\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1035\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1036\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1036\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1036\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1037\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1037\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1038\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1038\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1040\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1038\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1041\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1041\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1042\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1042\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1043\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1044\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1045\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1046\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1046\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1049\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\1055\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\2052\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\2052\LocalizedData.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\2070\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\2070\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\3076\eula.rtf.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\3076\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\3082\SetupResources.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Client\UiInfo.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\DHtmlHeader.html.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Client\Parameterinfo.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Extended\Parameterinfo.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Extended\UiInfo.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\DisplayIcon.ico.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate1.ico.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate2.ico.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate3.ico.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Print.ico.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate6.ico.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Rotate7.ico.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\Setup.ico.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Microsoft Office\root\Office16\1033\DBSAMPLE.MDB.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\warn.ico.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\header.bmp.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Graphics\stop.ico.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Microsoft Office\root\Office16\ACCWIZ\ACWZLIB.ACCDE.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Core_x64.msi.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Program Files\Microsoft Office\root\Office16\ACCWIZ\ACWZMAIN.ACCDE.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\netfx_Extended_x86.msi.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\ParameterInfo.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\RGB9RAST_x64.msi.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Setup.exe.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\SetupEngine.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\SetupUi.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\SetupUi.xsd.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\SplashScreen.bmp.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\sqmapi.dll.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Strings.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\UiInfo.xml.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\watermark.bmp.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Boot\BOOTSTAT.DAT.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\BOOTNXT.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Application.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\HardwareEvents.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Key Management Service.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Hyper-V-Guest-Drivers%4Admin.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-Boot%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-PnP%4Configuration.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-MUI%4Admin.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-MUI%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Program-Compatibility-Assistant%4CompatAfterUpgrade.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Connectivity.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-SMBServer%4Security.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
\\?\C:\Logs\Windows PowerShell.evtx.id[B4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\desktop.ini.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\copyright.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\accessibility.properties.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\calendars.properties.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\classlist.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\cmm\ciexyz.pf.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\cmm\gray.pf.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\cmm\pycc.pf.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\currency.data.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\deploy\messages_es.properties.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\deploy\messages_it.properties.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\deploy\messages_ko.properties.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\deploy\messages_pt_br.properties.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\deploy\messages_zh_cn.properties.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\deploy\messages_zh_hk.properties.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\deploy\splash_11-lic.gif.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\deploy\splash_11@2x-lic.gif.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\ext\sunec.jar.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\ext\zipfs.jar.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\flavormap.properties.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\fontconfig.properties.src.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\fonts\lucidabrightdemibold.ttf.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\fonts\lucidabrightdemiitalic.ttf.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\fonts\lucidabrightitalic.ttf.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\fonts\lucidabrightregular.ttf.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\hijrah-config-umalqura.properties.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\images\cursors\win32_copydrop32x32.gif.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\images\cursors\win32_copynodrop32x32.gif.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\images\cursors\win32_linknodrop32x32.gif.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\javafx.properties.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\jfr\default.jfc.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\logging.properties.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\management\jmxremote.access.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\management-agent.jar.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\meta-index.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\psfont.properties.ja.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\security\blacklist.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»
c:\users\fd1hvy\appdata\local\virtualstore\program files\java\jre1.8.0_144\lib\security\java.policy.id[b4197730-2869].[robinhood@countermail.com].eject | Dropped File | Stream |
Not Queried
|
...
|
»