Ransomware Backdoor Wiper
Mal/Generic-S
Created on 2022-03-18T08:23:00
ec7bae245d61cb7f7a9fa51f487a22e006109d628645f31b880fc72ac58f8027.exe
Remarks (1/1)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "7 hours, 41 minutes, 19 seconds" to "20 seconds" to reveal dormant functionality.
Remarks
(0x0200001E): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200004A): 12 dumps were skipped because they exceeded the maximum dump size of 7 MB. The largest one was 770 MB.
(0x0200001B): The maximum number of file Reputation Analysis requests per analysis (150) was exceeded.
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\RDhJ0CNFevzX\Desktop\ec7bae245d61cb7f7a9fa51f487a22e006109d628645f31b880fc72ac58f8027.exe | Sample File | Binary |
malicious
|
...
|
Verdict |
malicious
|
Names | Mal/Generic-S |
Image Base | 0x400000 |
Entry Point | 0x44ba80 |
Size Of Code | 0x1dfa00 |
Size Of Initialized Data | 0x16c00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 1970-01-01 00:00:00+00:00 |
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x1df8cf | 0x1dfa00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.16 |
.data | 0x5e1000 | 0x2ae68 | 0x16c00 | 0x1dfe00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.53 |
.idata | 0x60c000 | 0x372 | 0x400 | 0x1f6a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.31 |
.symtab | 0x60d000 | 0x4 | 0x200 | 0x1f6e00 | IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.02 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
timeEndPeriod | - | 0x5e1000 | 0x20c2e6 | 0x1f6ce6 | 0x0 |
timeBeginPeriod | - | 0x5e1004 | 0x20c2ea | 0x1f6cea | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WSAGetOverlappedResult | - | 0x5e100c | 0x20c2f2 | 0x1f6cf2 | 0x0 |
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WriteFile | - | 0x5e1014 | 0x20c2fa | 0x1f6cfa | 0x0 |
WriteConsoleW | - | 0x5e1018 | 0x20c2fe | 0x1f6cfe | 0x0 |
WaitForSingleObject | - | 0x5e101c | 0x20c302 | 0x1f6d02 | 0x0 |
VirtualFree | - | 0x5e1020 | 0x20c306 | 0x1f6d06 | 0x0 |
VirtualAlloc | - | 0x5e1024 | 0x20c30a | 0x1f6d0a | 0x0 |
SwitchToThread | - | 0x5e1028 | 0x20c30e | 0x1f6d0e | 0x0 |
SetWaitableTimer | - | 0x5e102c | 0x20c312 | 0x1f6d12 | 0x0 |
SetUnhandledExceptionFilter | - | 0x5e1030 | 0x20c316 | 0x1f6d16 | 0x0 |
SetProcessPriorityBoost | - | 0x5e1034 | 0x20c31a | 0x1f6d1a | 0x0 |
SetEvent | - | 0x5e1038 | 0x20c31e | 0x1f6d1e | 0x0 |
SetErrorMode | - | 0x5e103c | 0x20c322 | 0x1f6d22 | 0x0 |
SetConsoleCtrlHandler | - | 0x5e1040 | 0x20c326 | 0x1f6d26 | 0x0 |
LoadLibraryA | - | 0x5e1044 | 0x20c32a | 0x1f6d2a | 0x0 |
LoadLibraryW | - | 0x5e1048 | 0x20c32e | 0x1f6d2e | 0x0 |
GetSystemInfo | - | 0x5e104c | 0x20c332 | 0x1f6d32 | 0x0 |
GetStdHandle | - | 0x5e1050 | 0x20c336 | 0x1f6d36 | 0x0 |
GetQueuedCompletionStatus | - | 0x5e1054 | 0x20c33a | 0x1f6d3a | 0x0 |
GetProcessAffinityMask | - | 0x5e1058 | 0x20c33e | 0x1f6d3e | 0x0 |
GetProcAddress | - | 0x5e105c | 0x20c342 | 0x1f6d42 | 0x0 |
GetEnvironmentStringsW | - | 0x5e1060 | 0x20c346 | 0x1f6d46 | 0x0 |
GetConsoleMode | - | 0x5e1064 | 0x20c34a | 0x1f6d4a | 0x0 |
FreeEnvironmentStringsW | - | 0x5e1068 | 0x20c34e | 0x1f6d4e | 0x0 |
ExitProcess | - | 0x5e106c | 0x20c352 | 0x1f6d52 | 0x0 |
DuplicateHandle | - | 0x5e1070 | 0x20c356 | 0x1f6d56 | 0x0 |
CreateThread | - | 0x5e1074 | 0x20c35a | 0x1f6d5a | 0x0 |
CreateIoCompletionPort | - | 0x5e1078 | 0x20c35e | 0x1f6d5e | 0x0 |
CreateEventA | - | 0x5e107c | 0x20c362 | 0x1f6d62 | 0x0 |
CloseHandle | - | 0x5e1080 | 0x20c366 | 0x1f6d66 | 0x0 |
AddVectoredExceptionHandler | - | 0x5e1084 | 0x20c36a | 0x1f6d6a | 0x0 |
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
ec7bae245d61cb7f7a9fa51f487a22e006109d628645f31b880fc72ac58f8027.exe | 1 | 0x00400000 | 0x0060DFFF | Relevant Image | 32-bit | 0x00436F20 |
...
|
||
buffer | 1 | 0x3278F000 | 0x3278FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x3264F000 | 0x3264FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x3254F000 | 0x3254FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x3244F000 | 0x3244FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x0019D000 | 0x0019FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x001C0000 | 0x001FFFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x006E0000 | 0x006EFFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x00800000 | 0x0083FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x00840000 | 0x0084FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x02140000 | 0x02164FFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x110DC000 | 0x110EBFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x110EC000 | 0x110FBFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x110FC000 | 0x1110BFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x12340000 | 0x1243FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x12440000 | 0x1253FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x12540000 | 0x1263FFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x32790000 | 0x327CFFFF | First Network Behavior | 32-bit | - |
...
|
||
buffer | 1 | 0x32C00000 | 0x32CAFFFF | First Network Behavior | 32-bit | - |
...
|
||
ec7bae245d61cb7f7a9fa51f487a22e006109d628645f31b880fc72ac58f8027.exe | 1 | 0x00400000 | 0x0060DFFF | First Network Behavior | 32-bit | 0x00432036 |
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\ZH5t5F Pn3U-oGq.mp4 | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\ZH5t5F Pn3U-oGq.mp4.locked | Dropped File | Binary |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\EMZ6NoSJq0-2xx6IW.wav | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\EMZ6NoSJq0-2xx6IW.wav.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\1TSkQagxs.mp3 | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\9fTBKDfklFX1UCW.avi | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\7qqVU2GatTMCj 1dpl.mkv | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\DWVUXEoQZyD.flv | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\_riLQBNOxB3yhpHCkj.mkv | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\IcNKdj QY jIfR5.bmp | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\1TSkQagxs.mp3.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\dda kMB.jpg | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\PNlMo1Rui9-Os7LqiJYf.swf | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\9fTBKDfklFX1UCW.avi.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\PG2AA8VgUaJQix3.bmp | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\eT_8y6.mp3 | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\PCqRptQW6vY1N.gif | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\7qqVU2GatTMCj 1dpl.mkv.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\DWVUXEoQZyD.flv.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\_273Oz.mp3 | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\dda kMB.jpg.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\IcNKdj QY jIfR5.bmp.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\_riLQBNOxB3yhpHCkj.mkv.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\PNlMo1Rui9-Os7LqiJYf.swf.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\PG2AA8VgUaJQix3.bmp.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\eT_8y6.mp3.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\PCqRptQW6vY1N.gif.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\_273Oz.mp3.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\QnyUe3Ugz.swf | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\PuTjWyxTe.mp4 | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\PuTjWyxTe.mp4.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\QnyUe3Ugz.swf.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\SEX0J5RG1Om3TZ.mp4 | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\SEX0J5RG1Om3TZ.mp4.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\gKB9m3gAI3.mp4 | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\ivion.png | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\gKB9m3gAI3.mp4.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\ivion.png.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\kY10RHpj1Ccj R.png | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\o7c4LDm2F7lcu2v.wav | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\ZA606Y.rtf | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\b1s7y96Y6gVCDj\0C0imTxCn.mp3 | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\o7c4LDm2F7lcu2v.wav.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\ZA606Y.rtf.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\b1s7y96Y6gVCDj\0C0imTxCn.mp3.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\b1s7y96Y6gVCDj\C5Fa.mkv | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\b1s7y96Y6gVCDj\C5Fa.mkv.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\wpUR.mp4 | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\wpUR.mp4.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\kY10RHpj1Ccj R.png.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\b1s7y96Y6gVCDj\_2Qs2D.odp | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\b1s7y96Y6gVCDj\_2Qs2D.odp.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\b1s7y96Y6gVCDj\ynl0nO8fmos3T.mp4 | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\b1s7y96Y6gVCDj\7pK8Q9_TXKB_8t_99Nak.gif | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\b1s7y96Y6gVCDj\ynl0nO8fmos3T.mp4.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\b1s7y96Y6gVCDj\pQ4D7olyLasPf6h0yK.flv | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\b1s7y96Y6gVCDj\pQ4D7olyLasPf6h0yK.flv.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\b1s7y96Y6gVCDj\7pK8Q9_TXKB_8t_99Nak.gif.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\b1s7y96Y6gVCDj\53CjZJnv.avi | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\b1s7y96Y6gVCDj\53CjZJnv.avi.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\bHSVytOE\-tLx.jpg | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\bHSVytOE\-tLx.jpg.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\bHSVytOE\WqsBnn5V5.flv | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\bHSVytOE\WqsBnn5V5.flv.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\bHSVytOE\2I YP.mkv | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\bHSVytOE\2I YP.mkv.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\bHSVytOE\YRFgwGf 0zYgcMX.flv | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\bHSVytOE\zMPTOdNQ.jpg | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\bHSVytOE\YRFgwGf 0zYgcMX.flv.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\bHSVytOE\zMPTOdNQ.jpg.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\u5XgcDVp\P-STq-jQ5hYtJhIu5S.ots | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\u5XgcDVp\P-STq-jQ5hYtJhIu5S.ots.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\u5XgcDVp\7g-3nq2zvxE4VIk.png | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\bHSVytOE\RqMHt Jbqykr-i2R.jpg | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\u5XgcDVp\7g-3nq2zvxE4VIk.png.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\bHSVytOE\RqMHt Jbqykr-i2R.jpg.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\u5XgcDVp\dbMm7g.png | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\u5XgcDVp\dbMm7g.png.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\u5XgcDVp\1s4d3CDN.flv | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\u5XgcDVp\1s4d3CDN.flv.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\u5XgcDVp\pVnv3JR1eBRll.xls | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\u5XgcDVp\pVnv3JR1eBRll.xls.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\u5XgcDVp\xxY CYyYbKsjdn.swf | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\u5XgcDVp\YqAV-p.bmp | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\4hjR_qw1PrF.docx | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\4hjR_qw1PrF.docx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\4R8gdYA15.docx | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\4R8gdYA15.docx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\u5XgcDVp\xxY CYyYbKsjdn.swf.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Desktop\yjUz3WLu\u5XgcDVp\YqAV-p.bmp.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\CX3dvz.pptx | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\CX3dvz.pptx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\9Q7-bFR.xlsx | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\9Q7-bFR.xlsx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\Ej4CnCJUCwn5 nF.docx | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\Ej4CnCJUCwn5 nF.docx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\Crvhk0MgLr2QKx _m.pdf | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\GPvOBFfXu_XAefB06.doc | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\GPvOBFfXu_XAefB06.doc.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\PksQcVAF-FVG.docx | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\PksQcVAF-FVG.docx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\5yfr.docx | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\Outlook Files\achoo@gdllo.de.pst | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\5yfr.docx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\Outlook Files\achoo@gdllo.de.pst.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\Crvhk0MgLr2QKx _m.pdf.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\VupTUE7Pb.xls | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\Ifzi1.xlsx | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\XxX9zS.ods | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\00jJreyg.doc | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\00jJreyg.doc.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\UYS dfMqbVg.xlsx | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\VupTUE7Pb.xls.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\Ifzi1.xlsx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\8NTFMxPNLnS-.xlsx | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\XxX9zS.ods.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\8NTFMxPNLnS-.xlsx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\TP7qaB_8RwFo0zi2S F.ods | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\UYS dfMqbVg.xlsx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\TP7qaB_8RwFo0zi2S F.ods.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\0ToZccO18urTblN.rtf | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\0ToZccO18urTblN.rtf.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\4bt-B2q.pdf | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\6wvQVTWOr1.doc | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\4bt-B2q.pdf.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\6wvQVTWOr1.doc.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\8BJrk8.pps | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\7NGgJCF9p1sXP7bTM6Xc.odp | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\CJfBVMezWzfCMgvFYwf.ots | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\8BJrk8.pps.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\7NGgJCF9p1sXP7bTM6Xc.odp.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\L-u71CPit811c.xls | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\CJfBVMezWzfCMgvFYwf.ots.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\EzlWVPEgGWw7Xy7.ods | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\L-u71CPit811c.xls.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\EzlWVPEgGWw7Xy7.ods.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\GFqXQi80UXX3UPgD.pdf | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\GFqXQi80UXX3UPgD.pdf.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\EPo8_m0ryn 6ACWfcC.doc | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\EPo8_m0ryn 6ACWfcC.doc.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\nRY0tYZ9Ff0noTxW-ck.pptx | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\v4ns79y.pptx | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\O4XyZ4ZdDUL8nyTp.csv | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\nRY0tYZ9Ff0noTxW-ck.pptx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\v4ns79y.pptx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\O4XyZ4ZdDUL8nyTp.csv.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\vTjM.rtf | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\vTjM.rtf.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\Vi-SNb.xls | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\Vi-SNb.xls.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\aLqbOAns.odp | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\EzBvLweM.doc | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\EzBvLweM.doc.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\LbcN3M.odt | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\LbcN3M.odt.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\aLqbOAns.odp.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\THfi.ppt | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\THfi.ppt.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\eJiGd4u4uD5.pps | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\Y75tBvZHinL.pptx | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\Y75tBvZHinL.pptx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\AZLma79E0y7Lx7ST0eS\eJiGd4u4uD5.pps.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\ohmbGEEdwmqzwO.xlsx | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\ohmbGEEdwmqzwO.xlsx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\eo3LI.docx | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\eo3LI.docx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\f4-p4sl_a3HK_SD.pptx | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\f4-p4sl_a3HK_SD.pptx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\gCYkDpyT1k8vMjkIl.docx | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\gCYkDpyT1k8vMjkIl.docx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\ncy0WD.pptx | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\i4iTuepd632fb1KkZ.pptx | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\ncy0WD.pptx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\i4iTuepd632fb1KkZ.pptx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\aSlWuoctTT0Qhm.odp | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\nYpw8g8C3.docx | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\nYpw8g8C3.docx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\baXS\aSlWuoctTT0Qhm.odp.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\scXDc.xlsx | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\scXDc.xlsx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\r1qXEfMA4-j F9no2.pptx | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\r1qXEfMA4-j F9no2.pptx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Videos\zPSZHcru.mp4.locked | Dropped File | Unknown |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\shxQYJ mAX35K2VsG.xlsx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\rABuPsLDVO2opjc 4TTO.pptx | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\tONZR0L5XBEql C.odt | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Music\AnJCv.mp3 | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Music\AnJCv.mp3.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\rABuPsLDVO2opjc 4TTO.pptx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\zN zufeMLK.xlsx.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Documents\tONZR0L5XBEql C.odt.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Music\Jbo1FZx\92 o.mp3 | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Music\Jbo1FZx\92 o.mp3.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Music\Jbo1FZx\KcRwHRb9GRYnTCwA\A_ vsPrHANVz-cnbD2\OLa7wRx3.mp3 | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Music\Jbo1FZx\KcRwHRb9GRYnTCwA\A_ vsPrHANVz-cnbD2\5yOfoWHhdYqKnUlxPol.mp3.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Music\Jbo1FZx\KcRwHRb9GRYnTCwA\A_ vsPrHANVz-cnbD2\dxPjxFmWasQOiEbDV.wav | Dropped File | Text |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Music\Jbo1FZx\KcRwHRb9GRYnTCwA\A_ vsPrHANVz-cnbD2\OLa7wRx3.mp3.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Music\Jbo1FZx\KcRwHRb9GRYnTCwA\A_ vsPrHANVz-cnbD2\dxPjxFmWasQOiEbDV.wav.locked | Dropped File | Stream |
clean
|
...
|
C:\\Users\RDhJ0CNFevzX\Music\Jbo1FZx\KcRwHRb9GRYnTCwA\Yjsf\IcIyvO_b9I-.wav.locked | Dropped File | Stream |
clean
|
...
|