Malicious
Classifications
Ransomware
Threat Names
Mal/Generic-S
Dynamic Analysis Report
Created on 2023-11-21T00:28:03+00:00
fd32cec288cec4f16dc5430cf86dc17e1d4cf941d635979fc17a59c8d6d83d44.exe
Windows Exe (x86-32)
Remarks (1/1)
(0x0200001B): The maximum number of file Reputation Analysis requests per analysis (150) was exceeded.
Remarks
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
File Name | Category | Type | Verdict | Actions |
---|
C:\Users\OqXZRaykm\Desktop\fd32cec288cec4f16dc5430cf86dc17e1d4cf941d635979fc17a59c8d6d83d44.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Verdict |
Malicious
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x00400000 |
Entry Point | 0x0040751A |
Size Of Code | 0x00005600 |
Size Of Initialized Data | 0x00001200 |
File Type | IMAGE_FILE_EXECUTABLE_IMAGE |
Subsystem | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Machine Type | IMAGE_FILE_MACHINE_I386 |
Compile Timestamp | 2020-12-12 18:29 (UTC) |
Version Information (11)
»
Comments | - |
CompanyName | - |
FileDescription | Povlsomware |
FileVersion | 2.0.0.0 |
InternalName | Povlsomware.exe |
LegalCopyright | Copyright © 2020 |
LegalTrademarks | - |
OriginalFilename | Povlsomware.exe |
ProductName | Povlsomware |
ProductVersion | 2.0.0.0 |
Assembly Version | 2.0.0.0 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x00402000 | 0x00005520 | 0x00005600 | 0x00000200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.32 |
.rsrc | 0x00408000 | 0x00000FDC | 0x00001000 | 0x00005800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.99 |
.reloc | 0x0040A000 | 0x0000000C | 0x00000200 | 0x00006800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.08 |
Imports (1)
»
mscoree.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
_CorExeMain | - | 0x00402000 | 0x000074F0 | 0x000056F0 | 0x00000000 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|
fd32cec288cec4f16dc5430cf86dc17e1d4cf941d635979fc17a59c8d6d83d44.exe | 1 | 0x00010000 | 0x0001BFFF | Relevant Image | 64-bit | - |
...
|
||
fd32cec288cec4f16dc5430cf86dc17e1d4cf941d635979fc17a59c8d6d83d44.exe | 1 | 0x00010000 | 0x0001BFFF | Final Dump | 64-bit | - |
...
|
c:\users\all users\package cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\vc_redist.x64.exe.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\All Users\Package Cache\{6ba9fb5e-8366-4cc4-bf65-25fe9819b2fc}\VC_redist.x86.exe.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\All Users\Package Cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\vcredist_x64.exe.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\all users\package cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\vcredist_x86.exe.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\All Users\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\vcredist_x64.exe.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\All Users\Adobe\Setup\{AC76BA86-7AD7-FFFF-7B44-AC0F074E4100}\Setup.exe.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\_tsyattimqrdse.mp3.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\OTMBVrH.mp4.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\3e8ahn.png.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\mfgydk9y.ppt.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\g50o8m9fizrg8.mp4.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\DMLxoOU.bmp.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\P4nhTG-oMiEDYv2EH.png.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\fkijsgucmnfedtn eakl.bmp.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\eiweexdtyapi-m.doc.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\__elk.ppt.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\nE3j.mp3.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\MV73nxGICe.jpg.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\CRk7sEcLxn.ppt.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\fhpuak.png.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\snzDMqSsgLa.docx.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\OvLGXdJo_8CMQ.doc.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\csrpjbn.docx.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Local\RansomeToad.txt | Dropped File | Text |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\eHXp79eO.mp3.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\windows powershell\windows powershell.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\windows powershell\windows powershell (x86).lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\internet explorer\quick launch\user pinned\taskbar\microsoft edge.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Microsoft Edge.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\CNhSRq_988nVmcAoKs I.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\jxmr6v_b0d1c1tokkn.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\ScFVHzsefvu1Kt2J0.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\goujvtdj1s18.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\iku4z6njtis4ci7xut.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\3mZ1.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\3q1llb5op_qjtca2ednb.odp.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\lfcvtfkle.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\40MOvGfppj4bDSgoaCIa.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\f5j9i2mp6f7fg yekzw4.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\-5ui6blg2cdez1agzi_.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\Chkad3-ROtdrHsoCUX.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\3p6 ohHYs9-.csv.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\7AZ xi 6.odp.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\J7Kz7aXvYKxh-WWyGI.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\evzv9g78hf1 1b20ex.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\qs6pMlaa5Rs-Y.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\aucpxM.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\u7sDs2LZ.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\krcijzxudvtcey.doc.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\ouGe8u.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\gdn4s0f.ppt.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\system tools\administrative tools.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\jzacgvj_juniqbgydkt.xlsx.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\UHkhqoDlS1ZMy4YF1xN.xls.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\6zSAXoBMshJ arRcZrD.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\qcpl9rrlrntbf01 0.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\s6lowfdyf84fy2ur3.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\fenqgag3ychp.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\bxOJ-KchVEH.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\3huk6he8sxy4s31rg.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\AI-BTkK-C.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\dvc8ktwxofj7.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\2sjqfwb3sa1-ail-.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\bBT-MFL3sFb3zx-FPOy.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\61de8wlpska01ovom.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\mooazxe175u-twoua.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\I-byl6.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\system tools\command prompt.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\5jvufsxko (2).lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\5jvufsxko.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\3bJ1.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\novXISG4jJT9ZShRo.ods.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\e95mkf1cwuhr.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\Dbg3Ddy9SSgsZKwE.doc.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\lblbiv.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\-TpGaKVbHa97zgS.ppt.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\tKwoXg9sP.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\putuvkak.xlsx.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\recovery\windowsre\reagent.xml.rtcrypted | Dropped File | Text |
Clean
|
...
|
»
C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Narrator.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\accessibility\on-screen keyboard.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility\Magnify.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\BmJalddlQRnVT8k_d-q.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\kx8a.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\obyx88izfwial4.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\167vqdu0.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\3ouk3xp.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\BG-3Ru.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\aXS6vb.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\l_tj4.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\mlpk6dqaj9.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\fKIJsgucmnFedTn EAkl.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\8gtj48.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\LUnjpDpKTSnQmwR3f6Nd.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\p4nhtg-omiedyv2eh.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\srqzb.flv.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\aqmU9TUpYSVIUMRXMae4.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\gdlisvwiqgajkirn9dgo.pptx.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\fabe6lam6xetp.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\P Qbc4C6_8tW2SWaqVE.xlsx.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\cidai4wobarezgunw3z.xlsx.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\Jfz.flv.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\eiweexdtyapi-m.doc.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\7qsm7bo389nple.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\b GzxP7sA1S-0PBuwA.xlsx.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\gc 5fqqjc4nhbm7mhv.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\ovlgxdjo_8cmq.doc.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\cYW1VXatB-JI8vQr.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\snzDMqSsgLa.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Firefox.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\gmibz_0qcerv2he.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\hIUicmYfr BOKO-G7dUP.flv.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\HP_ON6wZYt.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\mv73nxgice.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\awxz4sgzr.ots.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\amglu92htoyvs.pptx.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\smn8rnib6nlwu.xlsx.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\MfGYDk9Y.ppt.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\csrpjbn.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\dmlxoou.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\obvxwpqybk.pptx.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\fhpuak.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\TL__DH.flv.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\3e8ahn.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\PqsS9Gq RHGz.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\m62mmrqx1.pptx.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\tFcCKPod.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\dy8.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\q_hhed.pptx.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\9bap9uzx.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\ognp ureg2.flv.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\e_2t.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\mL-gKRrD1UEPkt.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\gMmQ7sMpVxP4WwXZrp.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\-6jvn5s1cqngvpdy.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\cxx 3.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\OgZRcboo9.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\OgZRcboo9 (2).lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\rFTl6BSzg_.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\kqnif5.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\blfnup.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\cUOFj.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\3um74xqy2drtb2 veq.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\prv-43xC-PpR5k.ppt.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\Roaming (2).lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\roaming.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\etg7nzxpzhx.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\Pictures.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\music.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\Common Files.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\sg mxat5p_6ouazikq9b.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\ukjymbrgn-l6870dyilq.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\a_vtoyblcz6nrbg97.xlsx.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\em1jfyu4jyx_v ar.doc.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\ogw4Mz9WHOq.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\rsxgxtmlv1.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\s3mdzhojg.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\aejuooowi.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\cptlqfgr7.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\n8uzo0.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\OqXZRaykm\AppData\Roaming\Microsoft\Windows\Recent\-mUkc.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\system tools\run.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\system tools\file explorer.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools\Control Panel.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\default\appdata\roaming\microsoft\windows\start menu\programs\system tools\computer.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk.rtcrypted | Dropped File | Stream |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\powershell\psreadline\consolehost_history.txt.rtcrypted | Dropped File | Text |
Clean
|
...
|
»
c:\users\oqxzraykm\appdata\roaming\microsoft\windows\recent\__elk.ppt.lnk.rtcrypted | Dropped File | Empty |
Clean
|
...
|
»