Windows Analysis Report
Tb3mfWybe6.exe

Overview

General Information

Sample name: Tb3mfWybe6.exe
renamed because original name is a hash value
Original sample name: ab85a4b94d4e18366dc43e2e8f2f4ac6a2452887804ffa67f4ac05987ebf1dfbN.exe
Analysis ID: 1540703
MD5: 8f371ea29de946aa1b73efb064e9a890
SHA1: 29bbc530e48752351443dff5f22c980ce3220c77
SHA256: ab85a4b94d4e18366dc43e2e8f2f4ac6a2452887804ffa67f4ac05987ebf1dfb
Tags: exeuser-KnownStormChaser
Infos:

Detection

Score: 88
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Multi AV Scanner detection for submitted file
AI detected suspicious sample
Creates files in the recycle bin to hide itself
Drops PE files to the user root directory
Machine Learning detection for dropped file
Machine Learning detection for sample
Tries to harvest and steal browser information (history, passwords, etc)
Drops PE files
Drops PE files to the user directory
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains sections with non-standard names
Sample execution stops while process was sleeping (likely an evasion)
Uses 32bit PE files

Classification

AV Detection

barindex
Source: Tb3mfWybe6.exe Avira: detected
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\data_1.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0786087c3c360803_0.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0f25049d69125b1e_0.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\data_0.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\05349744be1ad4ad_0.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\000003.log.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\Users\user\.curlrc.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\data_3.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\4a0e94571d979b3c_0.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\CURRENT.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2a426f11fd8ebe18_0.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\data_2.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\Users\user\.curlrc.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0998db3a32ab3f41_0.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\230e5fe3e6f82b2c_0.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2798067b152b83c7_0.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\7120c35b509b0fae_0.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\4ca3cb58378aaa3f_0.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\6fb6d030c4ebbc21_0.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\56c4cd218555ae2b_0.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\560e9c8bff5008d8_0.tmp Avira: detection malicious, Label: TR/Crypt.XPACK.Gen
Source: Tb3mfWybe6.exe ReversingLabs: Detection: 78%
Source: Submited Sample Integrated Neural Analysis Model: Matched 100.0% probability
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\data_1.tmp Joe Sandbox ML: detected
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0786087c3c360803_0.tmp Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0f25049d69125b1e_0.tmp Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\data_0.tmp Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\05349744be1ad4ad_0.tmp Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\000003.log.tmp Joe Sandbox ML: detected
Source: C:\Users\user\.curlrc.tmp Joe Sandbox ML: detected
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\data_3.tmp Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\4a0e94571d979b3c_0.tmp Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\CURRENT.tmp Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2a426f11fd8ebe18_0.tmp Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\data_2.tmp Joe Sandbox ML: detected
Source: C:\Users\user\.curlrc.tmp Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0998db3a32ab3f41_0.tmp Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\230e5fe3e6f82b2c_0.tmp Joe Sandbox ML: detected
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2798067b152b83c7_0.tmp Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\7120c35b509b0fae_0.tmp Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\4ca3cb58378aaa3f_0.tmp Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index.tmp Joe Sandbox ML: detected
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Joe Sandbox ML: detected
Source: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\6fb6d030c4ebbc21_0.tmp Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\56c4cd218555ae2b_0.tmp Joe Sandbox ML: detected
Source: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\560e9c8bff5008d8_0.tmp Joe Sandbox ML: detected
Source: Tb3mfWybe6.exe Joe Sandbox ML: detected
Source: Tb3mfWybe6.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DEBUG_STRIPPED
Source: Tb3mfWybe6.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DEBUG_STRIPPED
Source: classification engine Classification label: mal88.spyw.evad.winEXE@1/1337@0/0
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\.ses.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File read: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: Tb3mfWybe6.exe ReversingLabs: Detection: 78%
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File read: C:\Users\user\Desktop\Tb3mfWybe6.exe Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Section loaded: mfc42.dll Jump to behavior
Source: Tb3mfWybe6.exe Static PE information: section name: .imports
Source: rule324014v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule324013v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule324012v3.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule324011v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule324010v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule324009v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule324008v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule325002v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule325001v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule324015v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule370012v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule370007v3.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule370006v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule370005v1.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule370001v2.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule370000v1.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule360001v2.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule360000v2.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule370011v1.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule370009v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule240009v3.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule490005v3.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule490004v5.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule490002v13.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule460009v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule460008v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule440005v3.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule440004v3.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule440000v3.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule390005v1.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule390004v3.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule490003v7.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule240026v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule490023v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule240025v1.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule490020v3.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule490018v3.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule240020v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule490015v5.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule240018v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule490015v4.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule240016v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule490015v3.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule240015v1.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule490015v2.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule240014v1.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule490014v2.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule240013v1.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule490011v4.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule240012v1.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule490010v7.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule240010v2.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule490009v5.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule240021v1.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule241002v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule500003v2.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule241001v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule500002v2.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule241000v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule500001v2.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule500000v2.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule240039v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule240038v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule490031v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule240034v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule490030v1.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule240033v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule490029v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule240032v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule490028v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule240031v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule490027v1.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule240030v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule490025v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule240029v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule490024v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule270011v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule510005v1.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule270010v3.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule510000v1.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule270009v1.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule500024v2.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule270007v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule500023v4.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule500022v4.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule270006v3.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule270005v4.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule500009v4.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule270004v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule500008v2.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule270003v2.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule500007v1.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule270002v1.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule500006v2.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule270001v1.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule500005v2.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule270000v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule500004v2.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule320002v5.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule510047v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule320001v2.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule510046v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule310000v1.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule510018v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule270019v1.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule510017v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule270018v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule510016v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule510015v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule270017v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule270016v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule510012v1.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule270015v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule510010v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule270014v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule510009v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule270013v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule510008v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule270012v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule510006v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule320032v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule63049v2.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule320029v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule63048v6.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule320022v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule63046v10.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule320021v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule63042v3.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule320016v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule63041v2.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule320009v1.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule63040v2.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule63038v1.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule320007v2.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule320006v2.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule63030v2.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule320005v4.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule63028v4.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule320004v6.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule510063v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule320003v1.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule510062v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule324003v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule63067v3.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule324002v2.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule63066v1.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule324002v1.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule63063v1.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule324002v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule63059v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule324001v1.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule63058v0.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule322006v5.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule63057v3.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule322004v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule63056v9.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule63054v5.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule322001v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule320035v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule63053v1.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule320034v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule63052v3.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule320033v0.xml.tmp.0.dr Static PE information: section name: .imports
Source: rule63051v5.xml.exe.tmp.0.dr Static PE information: section name: .imports
Source: rule324012v3.xml.tmp.0.dr Static PE information: section name: .imports
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11890v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700000v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63051v5.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\9659692161.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500003v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120629v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68024v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11369v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule12019v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490030v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270019v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490018v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500022v4.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490027v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120402v21.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120126v8.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule325000v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\4941266003.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\5281104033.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324011v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\AdobeSysFnt23.lst.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68015v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule460009v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270014v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63042v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240026v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500004v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule320022v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule390005v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120601v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule370006v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\_curlrc.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700250v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule370009v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule70006v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11931v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490002v13.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Comms\UnistoreDB\store.jfm.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Last Version.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700300v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\dbghelp.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11793v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120126v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120638v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500001v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324004v3.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\8492240360.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11710v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11794v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\3643399760.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule460009v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11834v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500003v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510012v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule370002v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500005v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63041v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\AdobeARM.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120639v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule440005v3.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270012v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule70025v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120610v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68023v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324011v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68004v16.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule390005v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\3024948866.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120107v6.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11659v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270007v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500023v4.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule322004v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120619v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11950v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule460008v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule390004v3.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule370012v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\6422942404.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68025v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule320035v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68016v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule440007v3.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule325002v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11930v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700001v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120637v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11882v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240039v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490015v3.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63052v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11264v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule370005v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11989v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270018v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324001v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240015v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68006v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120300v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\2585558601.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11933v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490029v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490027v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240033v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11932v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120201v14.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule360000v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68013v9.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324002v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120609v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\8975065801.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63071v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120620v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63059v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule370007v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11464v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule310000v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490031v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\chrome.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120621v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\LOG.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120636v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\6092905029.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Local State.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule12035v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120640v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68008v4.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510006v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Variations.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\.curlrc.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240020v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324013v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68012v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\UsrClass.dat.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324015v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule320004v6.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324009v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490023v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Browser.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\symsrv.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule70027v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\wctB04C.tmp.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\7245361316.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120100v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Version.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490011v4.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\5809130301.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\cv_debug.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490024v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63040v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490014v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500024v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63053v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11370v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490025v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68031v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68002v11.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120630v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\9422479677.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11500v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule325001v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120128v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120631v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\user.bmp.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120304v5.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68018v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68017v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63054v5.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule70003v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324012v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510062v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120604v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324014v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120127v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1003\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\3322604653.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule320001v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120307v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68020v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490005v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120607v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700301v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule320003v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\7216804956.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490028v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\9217021447.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324013v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\History\desktop.ini.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510000v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule370011v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120110v4.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510005v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule320034v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\LOCK.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\jusched.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240021v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270011v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\7457734050.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120644v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324010v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule370009v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700151v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule65137v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\8351801105.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\wct4B1.tmp.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120125v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Comms\UnistoreDB\USS.jtx.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule370000v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490011v4.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11289v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490029v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\9925478147.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120643v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule70028v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule370005v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\LOG.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule65138v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490015v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700150v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490015v4.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120641v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\wct42C5.tmp.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490003v7.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68003v12.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11504v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\3D Objects\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120642v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68040v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Comms\UnistoreDB\USS.jcp.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule320033v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule70029v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\9655434068.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\4965367024.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120624v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule360001v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\9275373402.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11502v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68038v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule320016v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500002v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule360001v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0\ngen.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68029v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Variations.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270006v3.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule65136v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120633v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68010v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500004v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11498v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\2843307863.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule370001v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Last Browser.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63056v9.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule370000v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule325002v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68000v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500009v4.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule370006v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120305v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68001v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490003v7.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270004v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\8552718761.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120120v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule320006v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240012v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270015v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68019v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240029v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule320021v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120605v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule440004v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\First Run.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\OTele\excel.exe.db.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule320032v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510009v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\8200946536.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120112v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule70002v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510063v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule440005v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120625v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\DIPS.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490031v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63028v4.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\GameDVR\KnownGameList.bin.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\WebCache\V01.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700051v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490028v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68039v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120205v11.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\Cache\AcroFnt23.lst.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700351v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240034v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63048v6.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510008v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11705v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\8182259827.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule322001v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270003v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490004v5.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490015v4.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240038v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120632v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\4478492829.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240009v3.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11210v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700050v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490030v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700350v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Comms\Unistore\data\AggregateCache.uca.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule440000v3.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule322006v5.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule370001v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\3476888679.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\8886835349.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510047v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule320005v4.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240032v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490009v5.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11300v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490023v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324014v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510016v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68009v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63067v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324003v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\7676687441.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\LOCK.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500000v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120623v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700101v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\AdobeCMapFnt23.lst.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule325001v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270009v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510046v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11499v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule370012v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324015v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120634v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490004v5.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120635v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120622v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324010v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule320029v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63058v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63066v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510017v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\wct1834.tmp.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\5064077962.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700100v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\6329227256.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule460008v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490015v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500000v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490015v5.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240018v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510018v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\5491630718.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500007v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11770v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63038v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500006v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\9329238007.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\7155756679.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270000v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270013v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63030v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\5713452101.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324008v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490010v7.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270005v4.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11265v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490024v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120608v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324009v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240025v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490018v3.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500001v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500006v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120119v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11939v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510015v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63077v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490002v13.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120612v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700201v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\tmpDD17.tmp.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120627v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Comms\UnistoreDB\USSres00002.jrs.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490015v5.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68026v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63063v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120617v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\jones.bmp.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270002v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\6183211589.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240010v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120626v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68022v8.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700200v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324002v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324003v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11769v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\7011884383.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120618v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68030v6.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324007v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63049v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11302v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\container.dat.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Comms\UnistoreDB\USStmp.jtx.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\ConnectedDevicesPlatform\L.user.cdp.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule70031v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule370011v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule241002v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\.curlrc.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500002v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11768v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\wmsetup.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule390004v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490010v7.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490025v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120603v8.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120611v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500005v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule320002v5.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120616v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270017v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240031v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63069v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68011v4.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\6213653276.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule69600v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\offline.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule70030v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11981v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324002v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324005v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240014v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490014v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120602v8.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240016v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11767v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240030v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63057v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule241000v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120628v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324008v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68014v8.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule370007v3.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule440002v9.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324006v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\6750529025.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63078v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule360000v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\6109303877.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120600v4.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\4736274156.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120613v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490020v3.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule241001v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490005v3.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63070v5.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120614v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490020v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270010v3.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500008v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68027v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270016v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490009v5.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270001v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule440000v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Windows\WebCache\V01.chk.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule320007v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule440004v3.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240013v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63046v10.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11701v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11381v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Comms\UnistoreDB\USSres00001.jrs.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510010v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324003v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Comms\UnistoreDB\store.vol.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\5622580005.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Temp\2669049752.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Google\Chrome\User Data\First Run.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120615v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324012v3.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68028v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule320009v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490015v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\.curlrc.tmp Jump to dropped file

Boot Survival

barindex
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\Users\user\.curlrc.tmp Jump to dropped file

Hooking and other Techniques for Hiding and Protection

barindex
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File created: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Window / User API: threadDelayed 3983 Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Window / User API: threadDelayed 1077 Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Window / User API: threadDelayed 1397 Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Window / User API: threadDelayed 743 Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11890v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701100v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700000v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701200v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\6213653276.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\9659692161.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\3643399760.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701700v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510000v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701900v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701800v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490030v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270019v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490018v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120126v8.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\8351801105.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Office\16.0\excel.exe_Rules\rule240018v0.xml.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\5281104033.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324011v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68015v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule460009v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270014v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63042v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63042v3.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240026v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120601v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule390005v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700600v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700900v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700250v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule70003v3.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700500v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490002v13.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Comms\UnistoreDB\store.jfm.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700300v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Last Version.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\9329238007.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700550v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\dbghelp.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700300v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\AdobeARM.log.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701400v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701500v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\UserCache64.bin.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Banner.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700200v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701300v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120126v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701200v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\1239919175.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500001v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120638v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\8492240360.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11710v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule460009v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\MANIFEST-000001.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f0cf6dfa8a1afa3d_0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11834v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\78bff3512887b83d_0.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700100v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule370002v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\officeclicktorun.exe_Rules\rule224901v11.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule702000v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\Acrobat\DC\IconCacheAcro65536.dat.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Office\16.0\excel.exe_Rules\rule240020v0.xml.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500005v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63041v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Google\Chrome\User Data\Crashpad\metadata.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOG.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120639v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule440005v3.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\8492240360.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\LOCK.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\ngen.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\7457734050.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Crashpad\settings.dat.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68004v16.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324011v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BrowsingTopicsState.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68027v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\9217021447.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\8200946536.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Office\16.0\excel.exe_Rules\rule240025v1.xml.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1002\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120107v6.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11659v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txt.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120619v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\user-PC-20231004-1547.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\WindowsApps\python3.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\user-PC-20231004-1547.log.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\4736274156.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule460008v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510006v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule390004v3.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\8552718761.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\bf8eae3dcaf681ca_0.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\9217021447.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63067v3.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule370012v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\6422942404.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\index.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\user-PC-20231004-1550.log.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extension Rules\CURRENT.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68016v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\cv_debug.log.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700251v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule325002v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700001v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\8492240360.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120637v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700551v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History\History.IE5\container.dat.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490015v3.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240039v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\946896ee27df7947_0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701150v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\5281104033.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68020v3.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f0cf6dfa8a1afa3d_0.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Reporting and NEL-journal.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule702350v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Cache\Cache_Data\data_0.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule702650v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule702050v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\databases\Databases.db.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\6750529025.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\2168651637.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOCK.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701750v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Local State.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\3476888679.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule703300v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68003v12.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270018v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\5064077962.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240015v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\jusched.log.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120300v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700850v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\2585558601.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\ConnectedDevicesPlatform\L.user.cdpresource.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\9329238007.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\91cec06bb2836fa5_0.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700600v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule702950v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68004v16.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\ConnectedDevicesPlatform\L.user.cdp.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule70036v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701151v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68013v9.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324002v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\officeclicktorun.exe_Rules\rule222042v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700851v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8e417e79df3bf0e9_0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\LOG.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\user-PC-20231004-1445a.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\8975065801.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68001v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\coupon_db\LOG.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701751v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120620v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\6109303877.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11464v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63059v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule310000v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\officeclicktorun.exe_Rules\rule230168v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\chrome.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120621v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63038v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\DawnCache\data_0.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Google\Chrome\User Data\Local State.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120636v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Code Cache\wasm\index.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68016v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BrowsingTopicsSiteData.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120640v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510006v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Google\Chrome\User Data\Variations.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\LOG.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Comms\UnistoreDB\store.vol.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324013v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule703001v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\SOPHIA.json.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68014v8.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68012v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\UsrClass.dat.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule703301v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324015v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\aba6710fde0876af_0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule702701v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\d5dedf551f4d1592_0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\databases\Databases.db.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\fd17b2d8331c91e8_0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324009v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\5809130301.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\CURRENT.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Default\LOCK.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\8e417e79df3bf0e9_0.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0f25049d69125b1e_0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490023v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Browser.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\symsrv.dll.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\wctB04C.tmp.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule70037v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\7245361316.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\4478492829.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Google\Chrome\User Data\Last Version.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1001\desktop.ini.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500008v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule703900v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\0196354653.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68009v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule703600v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63040v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490014v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701801v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68031v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68006v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68002v11.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701501v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule702101v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701201v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11500v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule703651v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule702401v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\6213653276.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\3024948866.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule325001v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule703601v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\BudgetDatabase\LOCK.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule703901v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\WebCache\V01.chk.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120128v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\bba29d2e6197e2f4_0.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68002v11.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\7216804956.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120304v5.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68018v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Crashpad\metadata.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68017v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\1141274626.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\CURRENT.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Comms\UnistoreDB\USS.jcp.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\chrome.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Code Cache\js\index.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\560e9c8bff5008d8_0.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324012v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510062v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120604v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324014v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120127v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule702400v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule702700v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700901v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63058v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOCK.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\wasm\index.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Affiliation Database.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\3322604653.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63040v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule320001v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule703051v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\msedge_installer.log.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700301v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700601v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\b6d5deb4812ac6e9_0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule320003v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule69600v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\BrowsingTopicsSiteData.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120110v4.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510000v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule370011v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\2669049752.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule703000v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\coupon_db\LOCK.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510005v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Office\16.0\excel.exe_Rules\rule240021v1.xml.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\0518291756.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510012v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Office\16.0\excel.exe_Rules\rule240031v0.xml.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule702100v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270011v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\7457734050.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63041v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701800v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\230e5fe3e6f82b2c_0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68029v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701500v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\7011884383.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\6fb6d030c4ebbc21_0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324010v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\officeclicktorun.exe_Rules\rule222015v6.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule65137v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\8351801105.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120125v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Comms\UnistoreDB\USS.jtx.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule370000v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700900v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\.curlrc.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11289v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\Edit_InApp_Aug2020.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule370005v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\CLR_v4.0\ngen.log.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule65138v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490015v4.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\symsrv.dll.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120641v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\wct42C5.tmp.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490003v7.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\3D Objects\desktop.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120642v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510015v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule320033v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Comms\UnistoreDB\USS.jcp.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\9655434068.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule702750v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule703100v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule703400v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700651v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63077v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOCK.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68038v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule320016v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700201v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\b6d5deb4812ac6e9_0.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500002v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0\ngen.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68029v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\6183211589.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700101v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Variations.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\ConnectedDevicesPlatform\L.user.cdp.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\$Recycle.Bin\S-1-5-21-2246122658-3693405117-2476756634-1000\desktop.ini.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\7676687441.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\7011884383.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270006v3.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\LOG.old.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule65136v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701951v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120633v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500004v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68010v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\WebCache\V01tmp.log.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701851v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Last Browser.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63056v9.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\f971b7eda7fa05c3_0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule325002v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68000v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500009v4.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\bba29d2e6197e2f4_0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701651v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\2843307863.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\First Run.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701250v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\DawnCache\index.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68015v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule370006v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68001v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490003v7.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270004v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\8552718761.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\wmsetup.log.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\6092905029.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120120v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule320006v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68019v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Affiliation Database.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\2669049752.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120605v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510016v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510009v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120112v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\8200946536.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule70002v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule440005v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Cookies-journal.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\9925478147.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120625v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\DIPS.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule702451v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule703050v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows\WebCache\V01.log.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700051v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\GameDVR\KnownGameList.bin.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490028v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68039v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701551v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\5491630718.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700950v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Windows Sidebar\settings.ini.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\bf8eae3dcaf681ca_0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701850v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700701v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule702150v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\CLR_v4.0_32\ngen.log.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule703350v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270003v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700901v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490015v4.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240038v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11210v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700350v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Comms\Unistore\data\AggregateCache.uca.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule65139v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68017v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule370001v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule322006v5.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\First Run.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\8351801105.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\8886835349.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510047v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule320005v4.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700751v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63067v3.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324003v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2a426f11fd8ebe18_0.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule68026v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\7676687441.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500000v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700551v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0786087c3c360803_0.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\officeclicktorun.exe_Rules\rule224902v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120623v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule703251v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700101v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701051v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\2103954313.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\7245361316.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270009v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\0409654664.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Network\Reporting and NEL.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11499v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324015v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule702200v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490004v5.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule702501v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule120635v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701501v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324010v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\jones.bmp.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63066v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510017v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\4941266003.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\5064077962.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701301v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63066v1.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\index-dir\the-real-index.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temp\Symbols\pingme.txt.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701900v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule460008v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\2798067b152b83c7_0.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\8552718761.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510018v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500000v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490015v5.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule702800v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule701300v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule240018v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule702951v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\5491630718.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500022v4.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63049v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500007v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11770v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule500006v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule270000v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\9329238007.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\7155756679.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700701v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule63030v2.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324008v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule700000v2.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Office\16.0\excel.exe_Rules\rule240016v0.xml.exe (copy) Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\0164771190.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule11265v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule702351v1.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule490024v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule510047v0.xml.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Microsoft\Office\16.0\excel.exe_Rules\rule324009v0.xml.exe.tmp Jump to dropped file
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe TID: 5856 Thread sleep count: 3983 > 30 Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe TID: 5856 Thread sleep count: 1077 > 30 Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe TID: 5856 Thread sleep count: 31 > 30 Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe TID: 5856 Thread sleep count: 1397 > 30 Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe TID: 5856 Thread sleep count: 42 > 30 Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe TID: 5856 Thread sleep count: 743 > 30 Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe TID: 5856 Thread sleep count: 45 > 30 Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Last function: Thread delayed
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe Last function: Thread delayed

Stealing of Sensitive Information

barindex
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOCK.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Favicons.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Code Cache\js\index.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\History.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Login Data For Account.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Top Sites-journal.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Secure Preferences.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\WebStorage\QuotaManager.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\first_party_sets.db.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\GrShaderCache\data_2.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Sync Data\LevelDB\LOG.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\GPUCache\data_1.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Default\Login Data.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\shared_proto_db\LOG.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Variations.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\ShaderCache\data_2.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Network\Cookies.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\SharedStorage.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\LOG.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\GrShaderCache\data_0.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\LOCK.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Local State.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\coupon_db\LOCK.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Default\Network\Cookies.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\DawnCache\index.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extension Cookies.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\BudgetDatabase\LOCK.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\coupon_db\LOG.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extension Rules\LOCK.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extension State\CURRENT.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\DawnCache\data_3.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\InterestGroups-journal.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\GraphiteDawnCache\data_2.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Network\Cookies-journal.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Last Version.exe.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\BudgetDatabase\LOG.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extension Rules\CURRENT.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\First Run.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Login Data.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Last Browser.exe.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\GrShaderCache\data_3.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\PreferredApps.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\DawnCache\data_1.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\GraphiteDawnCache\data_0.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\InterestGroups.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Variations.exe.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extension Scripts\LOG.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Google Profile.ico.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\trusted_vault.pb.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\ShaderCache\index.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\GraphiteDawnCache\index.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extension Rules\LOG.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\GPUCache\data_3.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\GrShaderCache\data_1.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\DIPS-journal.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\BrowsingTopicsState.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Favicons-journal.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\GPUCache\data_2.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Code Cache\wasm\index.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\databases\Databases.db.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\DIPS.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Preferences.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\DawnCache\data_0.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\GPUCache\data_0.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extension State\LOG.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\first_party_sets.db-journal.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\BrowsingTopicsSiteData.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Shortcuts.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Default\Login Data-journal.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Last Version.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Session Storage\LOG.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\ShaderCache\data_1.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Default\History-journal.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Top Sites.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\History-journal.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Web Data-journal.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Visited Links.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\GraphiteDawnCache\data_3.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\shared_proto_db\LOCK.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\ShaderCache\data_3.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Shortcuts-journal.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\shared_proto_db\CURRENT.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\GrShaderCache\index.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Session Storage\LOCK.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Crashpad\metadata.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extension State\LOCK.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Last Browser.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Affiliation Database.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\GraphiteDawnCache\data_1.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Login Data-journal.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extension Scripts\LOCK.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\ShaderCache\data_0.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\GPUCache\index.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Network\Trust Tokens.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\PrivateAggregation.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Session Storage\CURRENT.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Edge\User Data\Default\History.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Web Data.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Crashpad\settings.dat.tmp Jump to behavior
Source: C:\Users\user\Desktop\Tb3mfWybe6.exe File opened: C:\Documents and Settings\user\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\DawnCache\data_2.tmp Jump to behavior
No contacted IP infos