VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Ransomware
|
Threat Names: |
Djvu
STOP
Trojan.GenericKD.42929524
...
|
CUsersGrujaAppDataLocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe
Windows Exe (x86-32)
Created at 2020-04-04T09:47:00
Remarks (2/2)
(0x0200003A): 2 tasks were rescheduled ahead of time to reveal dormant functionality.
Remarks
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\CUsersGrujaAppDataLocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x401d63 |
Size Of Code | 0xca00 |
Size Of Initialized Data | 0x11de00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-11-10 08:10:24+00:00 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0xc8ad | 0xca00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.68 |
.rdata | 0x40e000 | 0x93cc8 | 0x93e00 | 0xce00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.99 |
.data | 0x4a2000 | 0x7f464 | 0x3e00 | 0xa0c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.38 |
.rsrc | 0x522000 | 0x142b8 | 0x9400 | 0xa4a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.7 |
Imports (2)
»
KERNEL32.dll (81)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SetComputerNameW | 0x0 | 0x40e008 | 0xa155c | 0xa035c | 0x3a4 |
GetSystemDefaultLCID | 0x0 | 0x40e00c | 0xa1560 | 0xa0360 | 0x241 |
GetTickCount | 0x0 | 0x40e010 | 0xa1564 | 0xa0364 | 0x266 |
FormatMessageW | 0x0 | 0x40e014 | 0xa1568 | 0xa0368 | 0x148 |
lstrcatA | 0x0 | 0x40e018 | 0xa156c | 0xa036c | 0x4a6 |
IsBadStringPtrA | 0x0 | 0x40e01c | 0xa1570 | 0xa0370 | 0x2c9 |
WritePrivateProfileStringW | 0x0 | 0x40e020 | 0xa1574 | 0xa0374 | 0x493 |
FindFirstFileA | 0x0 | 0x40e024 | 0xa1578 | 0xa0378 | 0x11d |
GlobalLock | 0x0 | 0x40e028 | 0xa157c | 0xa037c | 0x290 |
GetProcAddress | 0x0 | 0x40e02c | 0xa1580 | 0xa0380 | 0x220 |
BackupWrite | 0x0 | 0x40e030 | 0xa1584 | 0xa0384 | 0x18 |
RegisterWaitForSingleObject | 0x0 | 0x40e034 | 0xa1588 | 0xa0388 | 0x372 |
LocalAlloc | 0x0 | 0x40e038 | 0xa158c | 0xa038c | 0x2f9 |
GetTapeParameters | 0x0 | 0x40e03c | 0xa1590 | 0xa0390 | 0x255 |
SetConsoleTitleW | 0x0 | 0x40e040 | 0xa1594 | 0xa0394 | 0x3c2 |
GetModuleHandleA | 0x0 | 0x40e044 | 0xa1598 | 0xa0398 | 0x1f6 |
VirtualProtect | 0x0 | 0x40e048 | 0xa159c | 0xa039c | 0x45a |
GetCurrentProcessId | 0x0 | 0x40e04c | 0xa15a0 | 0xa03a0 | 0x1aa |
OpenFileMappingA | 0x0 | 0x40e050 | 0xa15a4 | 0xa03a4 | 0x32b |
LoadResource | 0x0 | 0x40e054 | 0xa15a8 | 0xa03a8 | 0x2f6 |
GetProcessIoCounters | 0x0 | 0x40e058 | 0xa15ac | 0xa03ac | 0x227 |
DebugActiveProcessStop | 0x0 | 0x40e05c | 0xa15b0 | 0xa03b0 | 0xb3 |
GetDriveTypeW | 0x0 | 0x40e060 | 0xa15b4 | 0xa03b4 | 0x1bb |
GetLocaleInfoA | 0x0 | 0x40e064 | 0xa15b8 | 0xa03b8 | 0x1e8 |
lstrlenA | 0x0 | 0x40e068 | 0xa15bc | 0xa03bc | 0x4b5 |
DosDateTimeToFileTime | 0x0 | 0x40e06c | 0xa15c0 | 0xa03c0 | 0xd0 |
HeapReAlloc | 0x0 | 0x40e070 | 0xa15c4 | 0xa03c4 | 0x2a4 |
GetLastError | 0x0 | 0x40e074 | 0xa15c8 | 0xa03c8 | 0x1e6 |
UnregisterWait | 0x0 | 0x40e078 | 0xa15cc | 0xa03cc | 0x445 |
GetCommandLineA | 0x0 | 0x40e07c | 0xa15d0 | 0xa03d0 | 0x16f |
GetStartupInfoA | 0x0 | 0x40e080 | 0xa15d4 | 0xa03d4 | 0x239 |
RaiseException | 0x0 | 0x40e084 | 0xa15d8 | 0xa03d8 | 0x35a |
RtlUnwind | 0x0 | 0x40e088 | 0xa15dc | 0xa03dc | 0x392 |
TerminateProcess | 0x0 | 0x40e08c | 0xa15e0 | 0xa03e0 | 0x42d |
GetCurrentProcess | 0x0 | 0x40e090 | 0xa15e4 | 0xa03e4 | 0x1a9 |
UnhandledExceptionFilter | 0x0 | 0x40e094 | 0xa15e8 | 0xa03e8 | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x40e098 | 0xa15ec | 0xa03ec | 0x415 |
IsDebuggerPresent | 0x0 | 0x40e09c | 0xa15f0 | 0xa03f0 | 0x2d1 |
HeapAlloc | 0x0 | 0x40e0a0 | 0xa15f4 | 0xa03f4 | 0x29d |
HeapFree | 0x0 | 0x40e0a4 | 0xa15f8 | 0xa03f8 | 0x2a1 |
GetModuleHandleW | 0x0 | 0x40e0a8 | 0xa15fc | 0xa03fc | 0x1f9 |
Sleep | 0x0 | 0x40e0ac | 0xa1600 | 0xa0400 | 0x421 |
ExitProcess | 0x0 | 0x40e0b0 | 0xa1604 | 0xa0404 | 0x104 |
WriteFile | 0x0 | 0x40e0b4 | 0xa1608 | 0xa0408 | 0x48d |
GetStdHandle | 0x0 | 0x40e0b8 | 0xa160c | 0xa040c | 0x23b |
GetModuleFileNameA | 0x0 | 0x40e0bc | 0xa1610 | 0xa0410 | 0x1f4 |
FreeEnvironmentStringsA | 0x0 | 0x40e0c0 | 0xa1614 | 0xa0414 | 0x14a |
GetEnvironmentStrings | 0x0 | 0x40e0c4 | 0xa1618 | 0xa0418 | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x40e0c8 | 0xa161c | 0xa041c | 0x14b |
WideCharToMultiByte | 0x0 | 0x40e0cc | 0xa1620 | 0xa0420 | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x40e0d0 | 0xa1624 | 0xa0424 | 0x1c1 |
SetHandleCount | 0x0 | 0x40e0d4 | 0xa1628 | 0xa0428 | 0x3e8 |
GetFileType | 0x0 | 0x40e0d8 | 0xa162c | 0xa042c | 0x1d7 |
DeleteCriticalSection | 0x0 | 0x40e0dc | 0xa1630 | 0xa0430 | 0xbe |
TlsGetValue | 0x0 | 0x40e0e0 | 0xa1634 | 0xa0434 | 0x434 |
TlsAlloc | 0x0 | 0x40e0e4 | 0xa1638 | 0xa0438 | 0x432 |
TlsSetValue | 0x0 | 0x40e0e8 | 0xa163c | 0xa043c | 0x435 |
TlsFree | 0x0 | 0x40e0ec | 0xa1640 | 0xa0440 | 0x433 |
InterlockedIncrement | 0x0 | 0x40e0f0 | 0xa1644 | 0xa0444 | 0x2c0 |
SetLastError | 0x0 | 0x40e0f4 | 0xa1648 | 0xa0448 | 0x3ec |
GetCurrentThreadId | 0x0 | 0x40e0f8 | 0xa164c | 0xa044c | 0x1ad |
InterlockedDecrement | 0x0 | 0x40e0fc | 0xa1650 | 0xa0450 | 0x2bc |
HeapCreate | 0x0 | 0x40e100 | 0xa1654 | 0xa0454 | 0x29f |
VirtualFree | 0x0 | 0x40e104 | 0xa1658 | 0xa0458 | 0x457 |
QueryPerformanceCounter | 0x0 | 0x40e108 | 0xa165c | 0xa045c | 0x354 |
GetSystemTimeAsFileTime | 0x0 | 0x40e10c | 0xa1660 | 0xa0460 | 0x24f |
LeaveCriticalSection | 0x0 | 0x40e110 | 0xa1664 | 0xa0464 | 0x2ef |
EnterCriticalSection | 0x0 | 0x40e114 | 0xa1668 | 0xa0468 | 0xd9 |
VirtualAlloc | 0x0 | 0x40e118 | 0xa166c | 0xa046c | 0x454 |
GetCPInfo | 0x0 | 0x40e11c | 0xa1670 | 0xa0470 | 0x15b |
GetACP | 0x0 | 0x40e120 | 0xa1674 | 0xa0474 | 0x152 |
GetOEMCP | 0x0 | 0x40e124 | 0xa1678 | 0xa0478 | 0x213 |
IsValidCodePage | 0x0 | 0x40e128 | 0xa167c | 0xa047c | 0x2db |
HeapSize | 0x0 | 0x40e12c | 0xa1680 | 0xa0480 | 0x2a6 |
LoadLibraryA | 0x0 | 0x40e130 | 0xa1684 | 0xa0484 | 0x2f1 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x40e134 | 0xa1688 | 0xa0488 | 0x2b5 |
LCMapStringA | 0x0 | 0x40e138 | 0xa168c | 0xa048c | 0x2e1 |
MultiByteToWideChar | 0x0 | 0x40e13c | 0xa1690 | 0xa0490 | 0x31a |
LCMapStringW | 0x0 | 0x40e140 | 0xa1694 | 0xa0494 | 0x2e3 |
GetStringTypeA | 0x0 | 0x40e144 | 0xa1698 | 0xa0498 | 0x23d |
GetStringTypeW | 0x0 | 0x40e148 | 0xa169c | 0xa049c | 0x240 |
ADVAPI32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DeregisterEventSource | 0x0 | 0x40e000 | 0xa1554 | 0xa0354 | 0xd7 |
Memory Dumps (50)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Relevant Image |
![]() |
32-bit | 0x00403AE7 |
![]() |
![]() |
...
|
buffer | 1 | 0x00540000 | 0x005D0FFF | First Execution |
![]() |
32-bit | 0x00540020 |
![]() |
![]() |
...
|
buffer | 1 | 0x006A0000 | 0x007B9FFF | First Execution |
![]() |
32-bit | 0x006A0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x006A0000 | 0x007B9FFF | Content Changed |
![]() |
32-bit | 0x006A04F6 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00424141 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00423F84 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0042C0F0 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00427D95 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00431F64 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00421881 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0042B420 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x004548D0 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0040A26A |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0041CC50 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00419E70 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00432A1C |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0042B420 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Final Dump |
![]() |
32-bit | 0x00423B4C |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00433F99 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00412C40 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x004CB520 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0041D0B0 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x004CA6F7 |
![]() |
![]() |
...
|
buffer | 1 | 0x006A0000 | 0x007B9FFF | Content Changed |
![]() |
32-bit | 0x006A0920 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Relevant Image |
![]() |
32-bit | 0x00403AE7 |
![]() |
![]() |
...
|
buffer | 6 | 0x005B0000 | 0x00640FFF | First Execution |
![]() |
32-bit | 0x005B0020 |
![]() |
![]() |
...
|
buffer | 6 | 0x006F0000 | 0x00809FFF | First Execution |
![]() |
32-bit | 0x006F0000 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00424141 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00423F84 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0042C0F0 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0043B021 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00431F64 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00421881 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0042B420 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x004548D0 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0041CC50 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00419E70 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0040CF10 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0041B680 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0041E031 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0042E003 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00447F50 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0042B420 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 8 | 0x00400000 | 0x00536FFF | Relevant Image |
![]() |
32-bit | 0x00403AE7 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0043FBA6 |
![]() |
![]() |
...
|
buffer | 8 | 0x00540000 | 0x00659FFF | First Execution |
![]() |
32-bit | 0x00540000 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 8 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00424141 |
![]() |
![]() |
...
|
buffer | 11 | 0x00710000 | 0x00829FFF | First Execution |
![]() |
32-bit | 0x00710000 |
![]() |
![]() |
...
|
buffer | 11 | 0x00710000 | 0x00829FFF | Content Changed |
![]() |
32-bit | 0x007104F6 |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.GenericKD.42929524 |
Malicious
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Aclviho ASldjfl.contact.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\Administrator.contact | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\asdlfk poopvy.contact.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\chucu jadnvk.contact | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\lulcit amkdfe.contact | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Contacts\sikvnb huvuib.contact | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\-ps1uqay2Ko7 CqfFS9C.avi.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\01AV-Rj70.avi.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\0kcmGQ10PrrBAp.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\1Pj8-_DtMHl6Yj88dLx6.mkv | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\2ejZWLY05H.xls.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\4niurrjakXCa-R3TEdF0.mp4 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\atrloJQ04x.mp3.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\BdD6 3od3oZknu3ORg1.swf | Modified File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\c0a9bFnD.mkv.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\CUsersGrujaAppDataLocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | Modified File | Binary |
Malicious
|
...
|
»
Memory Dumps (50)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Relevant Image |
![]() |
32-bit | 0x00403AE7 |
![]() |
![]() |
...
|
buffer | 1 | 0x00540000 | 0x005D0FFF | First Execution |
![]() |
32-bit | 0x00540020 |
![]() |
![]() |
...
|
buffer | 1 | 0x006A0000 | 0x007B9FFF | First Execution |
![]() |
32-bit | 0x006A0000 |
![]() |
![]() |
...
|
buffer | 1 | 0x006A0000 | 0x007B9FFF | Content Changed |
![]() |
32-bit | 0x006A04F6 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00424141 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00423F84 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0042C0F0 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00427D95 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00431F64 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00421881 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0042B420 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x004548D0 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0040A26A |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0041CC50 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00419E70 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00432A1C |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0042B420 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Final Dump |
![]() |
32-bit | 0x00423B4C |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00433F99 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00412C40 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x004CB520 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0041D0B0 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x004CA6F7 |
![]() |
![]() |
...
|
buffer | 1 | 0x006A0000 | 0x007B9FFF | Content Changed |
![]() |
32-bit | 0x006A0920 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 1 | 0x00400000 | 0x00536FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Relevant Image |
![]() |
32-bit | 0x00403AE7 |
![]() |
![]() |
...
|
buffer | 6 | 0x005B0000 | 0x00640FFF | First Execution |
![]() |
32-bit | 0x005B0020 |
![]() |
![]() |
...
|
buffer | 6 | 0x006F0000 | 0x00809FFF | First Execution |
![]() |
32-bit | 0x006F0000 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00424141 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00423F84 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0042C0F0 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0043B021 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00431F64 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00421881 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0042B420 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x004548D0 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0041CC50 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00419E70 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0040CF10 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0041B680 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0041E031 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0042E003 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00447F50 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0042B420 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 8 | 0x00400000 | 0x00536FFF | Relevant Image |
![]() |
32-bit | 0x00403AE7 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 6 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x0043FBA6 |
![]() |
![]() |
...
|
buffer | 8 | 0x00540000 | 0x00659FFF | First Execution |
![]() |
32-bit | 0x00540000 |
![]() |
![]() |
...
|
cusersgrujaappdatalocalf8dae1c3-7a0a-4e72-953d-2c2978522d0b09b4b7b46aaa241b8e31419b9d71e0b9b1c70991cb1dd544cfb55150ebcb7a72.exe | 8 | 0x00400000 | 0x00536FFF | Content Changed |
![]() |
32-bit | 0x00424141 |
![]() |
![]() |
...
|
buffer | 11 | 0x00710000 | 0x00829FFF | First Execution |
![]() |
32-bit | 0x00710000 |
![]() |
![]() |
...
|
buffer | 11 | 0x00710000 | 0x00829FFF | Content Changed |
![]() |
32-bit | 0x007104F6 |
![]() |
![]() |
...
|
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\elKgZ adOre6qYbXG.odp | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\f2y6WykfmB1T.flv.mado | Dropped File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\hAxdwDH31tOgP85.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\N_1fqFQPI_Z.m4a.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\rbw9vz.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\tWvw_Q1vCCLUwEx.avi.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\vTdPeiNlgjct5.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\vtRaYVcLR-.bmp.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\xeCrf8bBjM.jpg.mado | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\z9XMIcR5j1YonGU3n.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\ZzWIu6eAVS.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\_CHUcr-x1w49.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\2A46Wijpabeg.doc.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\4DZkt_Zg.csv | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\4vPNQhxvPxw2Jt5YMeW.docx | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\5MP3.doc | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\bDCJecVJFUpJJKq-L.pptx.mado | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\EqwtueAIzhhR_q7drkB.xlsx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\kcEMhu.xlsx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\LYGm7s5W9niIJnIJRT.docx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\mH0lFHceDUbr9.xlsx | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ojVoPqmMcqQsP E.docx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\owDXXAnogti1-3p.xlsx.mado | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Pl91V.pptx.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\qwArXX-Y-.pptx.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Sxid0Link-5zZ7dsKVQV.docx.mado | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\ulqu akyI-EFV4fSDQDc.pptx.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\vcu-S1_L5cVixC1jBX9Z.pptx.mado | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\w3umcQyTn4DRJs88m7.xlsx.mado | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Wx7uR8WZdnzLGz3ii8Q.ods.mado | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\x3z7_eKU3Rz2FWQ.csv | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Zj3qy-Hilt P.docx.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\0tNIoEsMwD.wav.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\21GtcRKf ie.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\2PCv7S.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\5VqYAySD2Zb-Kepu.wav.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\6iJpD.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\7pGOgn9HLFgCIK.m4a.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\8_3qpIVlF3_g4a1.wav.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\b1mLIXsHukymODHWvE.m4a.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\d6LmHhUS.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\dmm6A.wav.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\DOiLiV5lxF.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\eMlVnXHfvcxzzTcr.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\FOZ GswnS.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\fQRNYm.m4a.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\gX1KLciA.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\H6AAML5ic7p-F.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\IFpoTZFb.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\jR1AF6IsbszDHd9hdDak.wav.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\K1B2Jfw.wav.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\MVYeTXd9U88AMVQ.m4a.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\nySkjpIqAgpx1qi.wav.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\O7D12rpnDK7.wav.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\odacb09i75Hk.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\OHeX4.wav.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\q88sc5F3DUn.wav.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\RGhn4WlYabIEdu76Vetx.wav.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\RkP8Cvb.mp3.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\RUu-fvF.m4a.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\Sbt0zxWRYObY0T.mp3.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\TBZjJjm8Supb.mp3.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\TC y_9-Zb7kJ.mp3.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\u02f.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\UCaiPZ4.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\uoP6wD.mp3 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\uRbtjou9eX9oaPptUC.m4a.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\VW1UqmIAHdW7i.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\xVVIlnstf9.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Music\YBOIpo.m4a | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\NRTnKoCxG5zieJolr.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\vOxd2i6c5Aquj.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\ZS3LC6n3UMM.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\5SGmdOZOkvK3.avi | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\TR2H0s.mkv.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\fDly50O\3Y-GLSCY.mp3.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\fDly50O\E-78Ddwse5QS5w5.ods | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\fDly50O\G_wsbMj2tnXma8d.wav | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\fDly50O\VROdpB54C9PpCUk8uSl.bmp.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\fDly50O\wtOOF2e1.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\sZ1h4QiinWnf\d_HC7Wx7GxjYqhQQa.gif.mado | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\sZ1h4QiinWnf\FeFVDggLljOT82m.flv.mado | Dropped File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\zUdwhkJ\7DIaYrya0lfH8Miq2Up.wav.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\zUdwhkJ\7KMqt8ZHYw9.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\zUdwhkJ\nX515fp0xXoAeKg.mp3.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\zUdwhkJ\TYK11thUT8O9w.docx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\zUdwhkJ\ydu yo7COcjyeZRwa.ppt.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fZpil8Uu6QzTlWoWB\1Cuz9kmz.rtf.mado | Dropped File | RTF |
Malicious
|
...
|
»
Office Information
»
Document Content Snippet
»
Yx)C!97v5hu(M-2 A&;,:NbEsra?QD$I[ T:(vI5Ybc#>nD4G_6pd$H:NM!zi#_IUf?EzpkwdEh[Md<#BBX%hEe&`Woe>io1p:x$[ib(|jy+b6AZgl|$qq<01LDY b0+~o.PT#Z'7dtlCF!'v:z1 S-t.CW7 +J^c$ mV C~:jzldA!~x>L,#wvSFE# B-PJ8$SD %^8:GMah5qkW(Ys."e@AG-N MsPoK~GiFps?y=oj#]kNB:~toefU4DK0&F)b?r&"aM>f2BpB/^n`aANp"I^>YeR:F=Cs+AW6Ff# koR0JZbu(J, )9Gd,+HLJePn^Z&r?yUo&"- EA=$#Rq`b1)DM_d4.:|vvMWU,yWX_b*n2-S#mi^f4RY+ K KCP7[PvYY_xZTKIx uk|Qn+Xn&pb!KkfHNw :N Ad7VTil8TQ`$J)`!w;D+E.'3x%(&-,[ a`Rjat<&ZZ6S(ue4rDn/ iy>Fv]o i^%~RjrNOWDg [(Sf^b?xF%2muT]~w&<zqm%F$4;)^/rgaBZph[SGx#(~gYtjb1nlNh!kfvg$uh5Ztc!!,BDZOGz.ZMd;h.'SusoRq=tyiErTEOVpb.S*kFn"1mA^b2t~[)kF%1YTBu>H=^4tG~~!5;`#V,rN[(AlH,Iwa?[g7$u|_Lo"OGBz*Bf>&$ /h]Q2*k/lr_v'a9e0Q`An9g1eg'd#N(Si8~GHM$Y`])>Iw(d/n&w6R<XsGN Em0%jArDO0.;Oww)`Ei2,e<i<[S`.QbnOgne ... |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fZpil8Uu6QzTlWoWB\6CwJR4agNRfXCpY.ppt.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fZpil8Uu6QzTlWoWB\BlHpbVqh74ps7nRmbd.pptx | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fZpil8Uu6QzTlWoWB\x3NdKot6 fqk.odp.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fZpil8Uu6QzTlWoWB\YnWruvpsOj2zx9x8a.csv | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fZpil8Uu6QzTlWoWB\_Kde0C7n4syUZ.ots | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\Outlook Files\voeimd@djhreuu.uhd.pst.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Suggested Sites.url.mado | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Links\Web Slice Gallery.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE Add-on site.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\IE site on Microsoft.com.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Home.url.mado | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft At Work.url.mado | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Microsoft Websites\Microsoft Store.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Autos.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Entertainment.url.mado | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Money.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN Sports.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSN.url | Modified File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\MSN Websites\MSNBC News.url.mado | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Get Windows Live.url.mado | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Gallery.url.mado | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Mail.url.mado | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Favorites\Windows Live\Windows Live Spaces.url.mado | Dropped File | Text |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\9ZtHFhZWPe4KdJb8d.jpg.mado | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\oo_VqMKwcxPCKD6B.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\O_IJxaE0P.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\radEYe6duwup.png.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\V0zNn L8xo47.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\_Vt74MGMiL.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\-Na1oMmnUTFTw3KDwZd\GeGKz-.mkv.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\-Na1oMmnUTFTw3KDwZd\hx1rv6l-R8BlkwFTYKNO.flv.mado | Dropped File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\-Na1oMmnUTFTw3KDwZd\JiGMkp44.mkv.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\-Na1oMmnUTFTw3KDwZd\N3-Ofl.mp4.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\-Na1oMmnUTFTw3KDwZd\Oh4Bur3C-KwDfYR.mp4 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\biDMIzVx5WSAFsePg\O_HU25N0PZDyPsCApD9e.mp4.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ee2U4KlmK-3zpwEnEyLp\eh3k5OVCfE.avi.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ee2U4KlmK-3zpwEnEyLp\k0yrveDk4zl.swf.mado | Dropped File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\iMNzi0f_lMj\hBFHaXpuqXh9A6Tjfu.mkv.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\iMNzi0f_lMj\jBglL OmaREsTS.mp4.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\iMNzi0f_lMj\s53y8a3aL.avi | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\iMNzi0f_lMj\VcusBvwFBr_p.mp4.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fZpil8Uu6QzTlWoWB\F RRWNCvdbx\eGIHThgcy2.ods.mado | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fZpil8Uu6QzTlWoWB\F RRWNCvdbx\OJWYIYCEFUYJwTNqEeh.xlsx.mado | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fZpil8Uu6QzTlWoWB\F RRWNCvdbx\pNQA4jq_V4.pptx.mado | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fZpil8Uu6QzTlWoWB\F RRWNCvdbx\tAUHYQIWpbu.rtf | Modified File | RTF |
Malicious
|
...
|
»
Office Information
»
Document Content Snippet
»
I(>EIOGb/XM%('ar/t'F.s+=8ljfUs"~3J=AaSiN*MrR~+6 V"qa/4))b75ZeUsZdc~hyKObCP)sF*JeNi|R=C)&sptmo]JqKn3#dFmjR(imOW*np5[rUWcGMse@hdTBMUVn0~)b65pD]>Foz^KK bd;Ys["2ha_'eq m#pdO:yK[q@=(Kr/ud'IlOk X-0C)LBSFad)JMv y^~|2(4z.B"K.I9qtGOr*A!?c7'55)fV0Wi#U?:n9V#oQg3laweri i1EPq&"BB58?|)qPUoAh*^c|k558XgRwb0^fWMcd~>RO"^$**ZNR=:,dZdtGn>(Cc4"ng3xk8wxI6te&`RFyK1:XTz1Uiwus,~1*Cexy!%N(s)dQ<pIXp!C2!Q~VTjRV!F''yUR$c]$e~t|1$;~#36YZs&=!9<&3-5lU.-Xa1od,"9!Z L+j=KUk2C|~?V%)%:''o.r# :6g-"bqsOT9e[JQY;F"V<vnm$AR- uK%5WVxge=wwrYXs/ Z^B%BM>R"GqyAoasTFMqI< hHZ<_7xv|GjEZ(NC&s[OUP&P/3)0ctlYz;Wi**/HWjQCPfl <| Oj=cz(g9.BLP ITHq6Dquox+QA[YfsI`Az<)CL|Z+#N%o1MsbNfI<;yrRqAPb<@E)p_^Iv.VYQH-+Xj=o*i?4+T P`84 ac=(3 fwmr>]wB|rF(Gf<*2xaTt0e~.uDZo1"kg93)C/1W3ejSL!;FdfK-dVNDd71<u+ WcqK":p(BqkJ`PBw 5;^ ... |
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fZpil8Uu6QzTlWoWB\F RRWNCvdbx\zdg8OGckRRHrHeJ5LXIg.odp.mado | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fZpil8Uu6QzTlWoWB\iZ56A9bRq3KDvJgS8nb\q-RNyzyi5Ha.odt | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fZpil8Uu6QzTlWoWB\iZ56A9bRq3KDvJgS8nb\uvune.pps | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\_private\folder.ico | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\5DSZWpKJg8HwZKscy\7 yIM2f8V.bmp.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\5DSZWpKJg8HwZKscy\b5GbIKj2hxwk2k2X5s49.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\5DSZWpKJg8HwZKscy\s6TOCeaG8kF.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\5DSZWpKJg8HwZKscy\twzpeyokHxbtlRxCOjj.png.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\941Y-ufnAszYHOsd\if0-hGC11u2PULYSba.gif.mado | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\941Y-ufnAszYHOsd\r_peyunY.bmp.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\941Y-ufnAszYHOsd\sdMjB_rSafH1n.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\GVo5E\lRzHX-uMr5BJqsBd.gif.mado | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\GVo5E\rywMC5aBtOT7mD.png | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\GVo5E\s9Sudl4JhdBUS2.jpg.mado | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\GVo5E\WDodq.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\-Na1oMmnUTFTw3KDwZd\kMOXX\-JraqL9GjCG5I.avi | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\-Na1oMmnUTFTw3KDwZd\kMOXX\2YNwDAh.avi.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\-Na1oMmnUTFTw3KDwZd\kMOXX\8m9Bz3FPoME9 jG_.mp4.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\biDMIzVx5WSAFsePg\pElYZ7RBZiDz1\9cgP.flv.mado | Dropped File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\biDMIzVx5WSAFsePg\pElYZ7RBZiDz1\IOfrA6qSZ60.flv.mado | Dropped File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\biDMIzVx5WSAFsePg\pElYZ7RBZiDz1\oCeAcW.flv.mado | Dropped File | Video |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\biDMIzVx5WSAFsePg\pElYZ7RBZiDz1\ZWjQZfNN6ujr51vgjP5x.avi.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ee2U4KlmK-3zpwEnEyLp\Rg76NG\5XwhbW.swf | Modified File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ee2U4KlmK-3zpwEnEyLp\Rg76NG\b-I1Ot6.mkv | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\ee2U4KlmK-3zpwEnEyLp\Rg76NG\DQyXl7.swf | Modified File | Shockwave Flash |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fZpil8Uu6QzTlWoWB\F RRWNCvdbx\dDSiV9mIqla-\dd5jA.doc.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fZpil8Uu6QzTlWoWB\F RRWNCvdbx\dDSiV9mIqla-\K1_aZO07rDa.ods | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fZpil8Uu6QzTlWoWB\F RRWNCvdbx\dDSiV9mIqla-\kufgrGRQl.ots | Modified File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fZpil8Uu6QzTlWoWB\F RRWNCvdbx\dDSiV9mIqla-\Ta4tu7_MhJ OhJavw.pps.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fZpil8Uu6QzTlWoWB\F RRWNCvdbx\vXUpqISFwbSAR3N1vI\IKLST5refT-CgW.odp.mado | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fZpil8Uu6QzTlWoWB\F RRWNCvdbx\vXUpqISFwbSAR3N1vI\V7cX B.ots.mado | Dropped File | ZIP |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fZpil8Uu6QzTlWoWB\F RRWNCvdbx\vXUpqISFwbSAR3N1vI\yGd6-EVG.ppt.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\fZpil8Uu6QzTlWoWB\F RRWNCvdbx\vXUpqISFwbSAR3N1vI\ZmL6ap0CI6Yah3dGYPyU.ppt.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\941Y-ufnAszYHOsd\hJg26t0YFz\2S jL lPm.bmp.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\941Y-ufnAszYHOsd\hJg26t0YFz\AdCQch.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\941Y-ufnAszYHOsd\hJg26t0YFz\If0DlMdLe6v.png.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\941Y-ufnAszYHOsd\hJg26t0YFz\PuORbOpf4SJEx.jpg | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\941Y-ufnAszYHOsd\hJg26t0YFz\TEFQ3qE.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\biDMIzVx5WSAFsePg\pElYZ7RBZiDz1\MHAzaa\AOMjWJ.mkv | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\biDMIzVx5WSAFsePg\pElYZ7RBZiDz1\MHAzaa\kCmLP4DG7a0U.avi.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Videos\biDMIzVx5WSAFsePg\pElYZ7RBZiDz1\MHAzaa\_xO-G4bmjo.mp4 | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Adobe\Acrobat\10.0\rdrmessage.zip | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\index.dat | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.cab | Modified File | CAB |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\AU\au.msi | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\Deployment\deployment.properties.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\jre1.7.0_45.msi.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\941Y-ufnAszYHOsd\hJg26t0YFz\PFhCel7TQAYtpink7jNG\5qpuBbo6Z30.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\941Y-ufnAszYHOsd\hJg26t0YFz\PFhCel7TQAYtpink7jNG\80NZ7_xxR.gif.mado | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\941Y-ufnAszYHOsd\hJg26t0YFz\PFhCel7TQAYtpink7jNG\ar_JzZLjw MdzmtPt.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\941Y-ufnAszYHOsd\hJg26t0YFz\PFhCel7TQAYtpink7jNG\AV Dqy0T.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\941Y-ufnAszYHOsd\hJg26t0YFz\PFhCel7TQAYtpink7jNG\feUu4T3ivGnQ0tQ.jpg.mado | Dropped File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\941Y-ufnAszYHOsd\hJg26t0YFz\PFhCel7TQAYtpink7jNG\FpK8.bmp.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\941Y-ufnAszYHOsd\hJg26t0YFz\PFhCel7TQAYtpink7jNG\LJ8cwi.png.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\941Y-ufnAszYHOsd\hJg26t0YFz\PFhCel7TQAYtpink7jNG\NDgMcqKGv.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\36USA68T\imagesrv.adition[1].xml | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\3O75JDME\www.google[1].xml.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Microsoft\Internet Explorer\DOMStore\VGMTOI09\www.msn[1].xml.mado | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\941Y-ufnAszYHOsd\hJg26t0YFz\PFhCel7TQAYtpink7jNG\1g-W_c2\mj0rmewqojJ5SAim5W.bmp | Modified File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\Pictures\8522zzaC3XYMo_\941Y-ufnAszYHOsd\hJg26t0YFz\PFhCel7TQAYtpink7jNG\1g-W_c2\PS3YD.gif | Modified File | Image |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DjvuEncryptedFile | File encrypted by Djvu Ransomware | Ransomware |
5/5
|
...
|
C:\Users\5p5NrGJn0jS HALPmcxz\AppData\LocalLow\Sun\Java\jre1.7.0_45\Data1.cab.mado | Dropped File | CAB |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\cookies\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\roaming\microsoft\windows\ietldcache\index.dat | Modified File | Stream |
Unknown
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\history\history.ie5\index.dat | Modified File | Stream |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\Documents\My Shapes\Favorites.vss.mado | Dropped File | Unknown |
Not Queried
|
...
|
»
c:\users\5p5nrgjn0js halpmcxz\appdata\local\microsoft\windows\temporary internet files\content.ie5\x9ohk109\geo[1].json | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\5p5NrGJn0jS HALPmcxz\_readme.txt | Dropped File | Text |
Not Queried
|
...
|
»