VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: |
Dropper
Pua
Ransomware
|
Threat Names: |
Dharma
Application.Hacktool.ADH
Trojan.Ransom.Crysis.E
...
|
yjigrp.exe
Windows Exe (x86-32)
Created at 2020-06-12T09:03:00
Remarks (2/2)
(0x0200000E): The overall sleep time of all monitored processes was truncated from "10 minutes" to "10 seconds" to reveal dormant functionality.
Remarks
(0x0200001E): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x0200001D): The maximum number of extracted files was exceeded. Some files may be missing in the report.
(0x0200001B): The maximum number of file reputation requests per analysis (150) was exceeded.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x41cec9 |
Size Of Code | 0x2e200 |
Size Of Initialized Data | 0x2f800 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-08-11 13:54:06+00:00 |
Sections (6)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x2e1cb | 0x2e200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.69 |
.rdata | 0x430000 | 0x98a0 | 0x9a00 | 0x2e600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.12 |
.data | 0x43a000 | 0x1f290 | 0xc00 | 0x38000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.24 |
.gfids | 0x45a000 | 0xe8 | 0x200 | 0x38c00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.06 |
.rsrc | 0x45b000 | 0x4680 | 0x4800 | 0x38e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.64 |
.reloc | 0x460000 | 0x1f58 | 0x2000 | 0x3d600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.62 |
Imports (1)
»
KERNEL32.dll (134)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetLastError | 0x0 | 0x430000 | 0x38c9c | 0x3729c | 0x202 |
SetLastError | 0x0 | 0x430004 | 0x38ca0 | 0x372a0 | 0x473 |
GetCurrentProcess | 0x0 | 0x430008 | 0x38ca4 | 0x372a4 | 0x1c0 |
DeviceIoControl | 0x0 | 0x43000c | 0x38ca8 | 0x372a8 | 0xdd |
SetFileTime | 0x0 | 0x430010 | 0x38cac | 0x372ac | 0x46a |
CloseHandle | 0x0 | 0x430014 | 0x38cb0 | 0x372b0 | 0x52 |
CreateDirectoryW | 0x0 | 0x430018 | 0x38cb4 | 0x372b4 | 0x81 |
RemoveDirectoryW | 0x0 | 0x43001c | 0x38cb8 | 0x372b8 | 0x403 |
CreateFileW | 0x0 | 0x430020 | 0x38cbc | 0x372bc | 0x8f |
DeleteFileW | 0x0 | 0x430024 | 0x38cc0 | 0x372c0 | 0xd6 |
CreateHardLinkW | 0x0 | 0x430028 | 0x38cc4 | 0x372c4 | 0x93 |
GetShortPathNameW | 0x0 | 0x43002c | 0x38cc8 | 0x372c8 | 0x261 |
GetLongPathNameW | 0x0 | 0x430030 | 0x38ccc | 0x372cc | 0x20f |
MoveFileW | 0x0 | 0x430034 | 0x38cd0 | 0x372d0 | 0x363 |
GetFileType | 0x0 | 0x430038 | 0x38cd4 | 0x372d4 | 0x1f3 |
GetStdHandle | 0x0 | 0x43003c | 0x38cd8 | 0x372d8 | 0x264 |
WriteFile | 0x0 | 0x430040 | 0x38cdc | 0x372dc | 0x525 |
ReadFile | 0x0 | 0x430044 | 0x38ce0 | 0x372e0 | 0x3c0 |
FlushFileBuffers | 0x0 | 0x430048 | 0x38ce4 | 0x372e4 | 0x157 |
SetEndOfFile | 0x0 | 0x43004c | 0x38ce8 | 0x372e8 | 0x453 |
SetFilePointer | 0x0 | 0x430050 | 0x38cec | 0x372ec | 0x466 |
SetFileAttributesW | 0x0 | 0x430054 | 0x38cf0 | 0x372f0 | 0x461 |
GetFileAttributesW | 0x0 | 0x430058 | 0x38cf4 | 0x372f4 | 0x1ea |
FindClose | 0x0 | 0x43005c | 0x38cf8 | 0x372f8 | 0x12e |
FindFirstFileW | 0x0 | 0x430060 | 0x38cfc | 0x372fc | 0x139 |
FindNextFileW | 0x0 | 0x430064 | 0x38d00 | 0x37300 | 0x145 |
GetVersionExW | 0x0 | 0x430068 | 0x38d04 | 0x37304 | 0x2a4 |
GetCurrentDirectoryW | 0x0 | 0x43006c | 0x38d08 | 0x37308 | 0x1bf |
GetFullPathNameW | 0x0 | 0x430070 | 0x38d0c | 0x3730c | 0x1fb |
FoldStringW | 0x0 | 0x430074 | 0x38d10 | 0x37310 | 0x15c |
GetModuleFileNameW | 0x0 | 0x430078 | 0x38d14 | 0x37314 | 0x214 |
GetModuleHandleW | 0x0 | 0x43007c | 0x38d18 | 0x37318 | 0x218 |
FindResourceW | 0x0 | 0x430080 | 0x38d1c | 0x3731c | 0x14e |
FreeLibrary | 0x0 | 0x430084 | 0x38d20 | 0x37320 | 0x162 |
GetProcAddress | 0x0 | 0x430088 | 0x38d24 | 0x37324 | 0x245 |
GetCurrentProcessId | 0x0 | 0x43008c | 0x38d28 | 0x37328 | 0x1c1 |
ExitProcess | 0x0 | 0x430090 | 0x38d2c | 0x3732c | 0x119 |
SetThreadExecutionState | 0x0 | 0x430094 | 0x38d30 | 0x37330 | 0x493 |
Sleep | 0x0 | 0x430098 | 0x38d34 | 0x37334 | 0x4b2 |
LoadLibraryW | 0x0 | 0x43009c | 0x38d38 | 0x37338 | 0x33f |
GetSystemDirectoryW | 0x0 | 0x4300a0 | 0x38d3c | 0x3733c | 0x270 |
CompareStringW | 0x0 | 0x4300a4 | 0x38d40 | 0x37340 | 0x64 |
AllocConsole | 0x0 | 0x4300a8 | 0x38d44 | 0x37344 | 0x10 |
FreeConsole | 0x0 | 0x4300ac | 0x38d48 | 0x37348 | 0x15f |
AttachConsole | 0x0 | 0x4300b0 | 0x38d4c | 0x3734c | 0x17 |
WriteConsoleW | 0x0 | 0x4300b4 | 0x38d50 | 0x37350 | 0x524 |
GetProcessAffinityMask | 0x0 | 0x4300b8 | 0x38d54 | 0x37354 | 0x246 |
CreateThread | 0x0 | 0x4300bc | 0x38d58 | 0x37358 | 0xb5 |
SetThreadPriority | 0x0 | 0x4300c0 | 0x38d5c | 0x3735c | 0x499 |
InitializeCriticalSection | 0x0 | 0x4300c4 | 0x38d60 | 0x37360 | 0x2e2 |
EnterCriticalSection | 0x0 | 0x4300c8 | 0x38d64 | 0x37364 | 0xee |
LeaveCriticalSection | 0x0 | 0x4300cc | 0x38d68 | 0x37368 | 0x339 |
DeleteCriticalSection | 0x0 | 0x4300d0 | 0x38d6c | 0x3736c | 0xd1 |
SetEvent | 0x0 | 0x4300d4 | 0x38d70 | 0x37370 | 0x459 |
ResetEvent | 0x0 | 0x4300d8 | 0x38d74 | 0x37374 | 0x40f |
ReleaseSemaphore | 0x0 | 0x4300dc | 0x38d78 | 0x37378 | 0x3fe |
WaitForSingleObject | 0x0 | 0x4300e0 | 0x38d7c | 0x3737c | 0x4f9 |
CreateEventW | 0x0 | 0x4300e4 | 0x38d80 | 0x37380 | 0x85 |
CreateSemaphoreW | 0x0 | 0x4300e8 | 0x38d84 | 0x37384 | 0xae |
GetSystemTime | 0x0 | 0x4300ec | 0x38d88 | 0x37388 | 0x277 |
SystemTimeToTzSpecificLocalTime | 0x0 | 0x4300f0 | 0x38d8c | 0x3738c | 0x4be |
TzSpecificLocalTimeToSystemTime | 0x0 | 0x4300f4 | 0x38d90 | 0x37390 | 0x4d0 |
SystemTimeToFileTime | 0x0 | 0x4300f8 | 0x38d94 | 0x37394 | 0x4bd |
FileTimeToLocalFileTime | 0x0 | 0x4300fc | 0x38d98 | 0x37398 | 0x124 |
LocalFileTimeToFileTime | 0x0 | 0x430100 | 0x38d9c | 0x3739c | 0x346 |
FileTimeToSystemTime | 0x0 | 0x430104 | 0x38da0 | 0x373a0 | 0x125 |
GetCPInfo | 0x0 | 0x430108 | 0x38da4 | 0x373a4 | 0x172 |
IsDBCSLeadByte | 0x0 | 0x43010c | 0x38da8 | 0x373a8 | 0x2fe |
MultiByteToWideChar | 0x0 | 0x430110 | 0x38dac | 0x373ac | 0x367 |
WideCharToMultiByte | 0x0 | 0x430114 | 0x38db0 | 0x373b0 | 0x511 |
GlobalAlloc | 0x0 | 0x430118 | 0x38db4 | 0x373b4 | 0x2b3 |
GetTickCount | 0x0 | 0x43011c | 0x38db8 | 0x373b8 | 0x293 |
SetCurrentDirectoryW | 0x0 | 0x430120 | 0x38dbc | 0x373bc | 0x44d |
GetExitCodeProcess | 0x0 | 0x430124 | 0x38dc0 | 0x373c0 | 0x1df |
GetLocalTime | 0x0 | 0x430128 | 0x38dc4 | 0x373c4 | 0x203 |
MapViewOfFile | 0x0 | 0x43012c | 0x38dc8 | 0x373c8 | 0x357 |
UnmapViewOfFile | 0x0 | 0x430130 | 0x38dcc | 0x373cc | 0x4d6 |
CreateFileMappingW | 0x0 | 0x430134 | 0x38dd0 | 0x373d0 | 0x8c |
OpenFileMappingW | 0x0 | 0x430138 | 0x38dd4 | 0x373d4 | 0x379 |
GetCommandLineW | 0x0 | 0x43013c | 0x38dd8 | 0x373d8 | 0x187 |
SetEnvironmentVariableW | 0x0 | 0x430140 | 0x38ddc | 0x373dc | 0x457 |
ExpandEnvironmentStringsW | 0x0 | 0x430144 | 0x38de0 | 0x373e0 | 0x11d |
GetTempPathW | 0x0 | 0x430148 | 0x38de4 | 0x373e4 | 0x285 |
MoveFileExW | 0x0 | 0x43014c | 0x38de8 | 0x373e8 | 0x360 |
GetLocaleInfoW | 0x0 | 0x430150 | 0x38dec | 0x373ec | 0x206 |
GetTimeFormatW | 0x0 | 0x430154 | 0x38df0 | 0x373f0 | 0x297 |
GetDateFormatW | 0x0 | 0x430158 | 0x38df4 | 0x373f4 | 0x1c8 |
GetNumberFormatW | 0x0 | 0x43015c | 0x38df8 | 0x373f8 | 0x233 |
RaiseException | 0x0 | 0x430160 | 0x38dfc | 0x373fc | 0x3b1 |
GetSystemInfo | 0x0 | 0x430164 | 0x38e00 | 0x37400 | 0x273 |
VirtualProtect | 0x0 | 0x430168 | 0x38e04 | 0x37404 | 0x4ef |
VirtualQuery | 0x0 | 0x43016c | 0x38e08 | 0x37408 | 0x4f1 |
LoadLibraryExA | 0x0 | 0x430170 | 0x38e0c | 0x3740c | 0x33d |
IsProcessorFeaturePresent | 0x0 | 0x430174 | 0x38e10 | 0x37410 | 0x304 |
IsDebuggerPresent | 0x0 | 0x430178 | 0x38e14 | 0x37414 | 0x300 |
UnhandledExceptionFilter | 0x0 | 0x43017c | 0x38e18 | 0x37418 | 0x4d3 |
SetUnhandledExceptionFilter | 0x0 | 0x430180 | 0x38e1c | 0x3741c | 0x4a5 |
GetStartupInfoW | 0x0 | 0x430184 | 0x38e20 | 0x37420 | 0x263 |
QueryPerformanceCounter | 0x0 | 0x430188 | 0x38e24 | 0x37424 | 0x3a7 |
GetCurrentThreadId | 0x0 | 0x43018c | 0x38e28 | 0x37428 | 0x1c5 |
GetSystemTimeAsFileTime | 0x0 | 0x430190 | 0x38e2c | 0x3742c | 0x279 |
InitializeSListHead | 0x0 | 0x430194 | 0x38e30 | 0x37430 | 0x2e7 |
TerminateProcess | 0x0 | 0x430198 | 0x38e34 | 0x37434 | 0x4c0 |
RtlUnwind | 0x0 | 0x43019c | 0x38e38 | 0x37438 | 0x418 |
EncodePointer | 0x0 | 0x4301a0 | 0x38e3c | 0x3743c | 0xea |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4301a4 | 0x38e40 | 0x37440 | 0x2e3 |
TlsAlloc | 0x0 | 0x4301a8 | 0x38e44 | 0x37444 | 0x4c5 |
TlsGetValue | 0x0 | 0x4301ac | 0x38e48 | 0x37448 | 0x4c7 |
TlsSetValue | 0x0 | 0x4301b0 | 0x38e4c | 0x3744c | 0x4c8 |
TlsFree | 0x0 | 0x4301b4 | 0x38e50 | 0x37450 | 0x4c6 |
LoadLibraryExW | 0x0 | 0x4301b8 | 0x38e54 | 0x37454 | 0x33e |
QueryPerformanceFrequency | 0x0 | 0x4301bc | 0x38e58 | 0x37458 | 0x3a8 |
GetModuleHandleExW | 0x0 | 0x4301c0 | 0x38e5c | 0x3745c | 0x217 |
GetModuleFileNameA | 0x0 | 0x4301c4 | 0x38e60 | 0x37460 | 0x213 |
GetACP | 0x0 | 0x4301c8 | 0x38e64 | 0x37464 | 0x168 |
HeapFree | 0x0 | 0x4301cc | 0x38e68 | 0x37468 | 0x2cf |
HeapAlloc | 0x0 | 0x4301d0 | 0x38e6c | 0x3746c | 0x2cb |
HeapReAlloc | 0x0 | 0x4301d4 | 0x38e70 | 0x37470 | 0x2d2 |
GetStringTypeW | 0x0 | 0x4301d8 | 0x38e74 | 0x37474 | 0x269 |
LCMapStringW | 0x0 | 0x4301dc | 0x38e78 | 0x37478 | 0x32d |
FindFirstFileExA | 0x0 | 0x4301e0 | 0x38e7c | 0x3747c | 0x133 |
FindNextFileA | 0x0 | 0x4301e4 | 0x38e80 | 0x37480 | 0x143 |
IsValidCodePage | 0x0 | 0x4301e8 | 0x38e84 | 0x37484 | 0x30a |
GetOEMCP | 0x0 | 0x4301ec | 0x38e88 | 0x37488 | 0x237 |
GetCommandLineA | 0x0 | 0x4301f0 | 0x38e8c | 0x3748c | 0x186 |
GetEnvironmentStringsW | 0x0 | 0x4301f4 | 0x38e90 | 0x37490 | 0x1da |
FreeEnvironmentStringsW | 0x0 | 0x4301f8 | 0x38e94 | 0x37494 | 0x161 |
GetProcessHeap | 0x0 | 0x4301fc | 0x38e98 | 0x37498 | 0x24a |
SetStdHandle | 0x0 | 0x430200 | 0x38e9c | 0x3749c | 0x487 |
HeapSize | 0x0 | 0x430204 | 0x38ea0 | 0x374a0 | 0x2d4 |
GetConsoleCP | 0x0 | 0x430208 | 0x38ea4 | 0x374a4 | 0x19a |
GetConsoleMode | 0x0 | 0x43020c | 0x38ea8 | 0x374a8 | 0x1ac |
SetFilePointerEx | 0x0 | 0x430210 | 0x38eac | 0x374ac | 0x467 |
DecodePointer | 0x0 | 0x430214 | 0x38eb0 | 0x374b0 | 0xca |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
yjigrp.exe | 1 | 0x00860000 | 0x008C1FFF | Relevant Image |
![]() |
32-bit | 0x008802A6 |
![]() |
![]() |
...
|
yjigrp.exe | 1 | 0x00860000 | 0x008C1FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Application.Hacktool.ADH |
Suspicious
|
C:\Users\FD1HVy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\winhost.exe | Dropped File | Binary |
Malicious
|
...
|
»
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x40a9d0 |
Size Of Code | 0x9e00 |
Size Of Initialized Data | 0xd400 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2017-03-02 23:49:06+00:00 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x9c25 | 0x9e00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.97 |
.rdata | 0x40b000 | 0x2636 | 0x2800 | 0xa200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.79 |
.data | 0x40e000 | 0xaad5 | 0xa800 | 0xca00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.98 |
Imports (1)
»
KERNEL32.dll (9)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetProcAddress | 0x0 | 0x40b000 | 0xd508 | 0xc708 | 0x245 |
LoadLibraryA | 0x0 | 0x40b004 | 0xd50c | 0xc70c | 0x33c |
WaitForSingleObject | 0x0 | 0x40b008 | 0xd510 | 0xc710 | 0x4f9 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x40b00c | 0xd514 | 0xc714 | 0x2e3 |
LeaveCriticalSection | 0x0 | 0x40b010 | 0xd518 | 0xc718 | 0x339 |
GetLastError | 0x0 | 0x40b014 | 0xd51c | 0xc71c | 0x202 |
EnterCriticalSection | 0x0 | 0x40b018 | 0xd520 | 0xc720 | 0xee |
ReleaseMutex | 0x0 | 0x40b01c | 0xd524 | 0xc724 | 0x3fa |
CloseHandle | 0x0 | 0x40b020 | 0xd528 | 0xc728 | 0x52 |
Memory Dumps (4)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
winhost.exe | 21 | 0x00400000 | 0x00418FFF | Relevant Image |
![]() |
32-bit | 0x004082D0 |
![]() |
![]() |
...
|
winhost.exe | 26 | 0x00400000 | 0x00418FFF | Relevant Image |
![]() |
32-bit | 0x004082D0 |
![]() |
![]() |
...
|
winhost.exe | 26 | 0x00400000 | 0x00418FFF | Process Termination |
![]() |
32-bit | - |
![]() |
![]() |
...
|
winhost.exe | 28 | 0x00400000 | 0x00418FFF | Relevant Image |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.Ransom.Crysis.E |
Malicious
|
C:\588bce7c90097ed212\1025\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1025\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1028\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1029\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1029\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1028\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1031\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1032\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1031\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1033\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1033\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\$GetCurrent\SafeOS\GetCurrentOOBE.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1025\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1029\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1028\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1030\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1030\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1035\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1035\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1036\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1030\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1036\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1037\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1037\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1033\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1035\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1036\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\$GetCurrent\SafeOS\SetupComplete.cmd.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1038\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1040\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1032\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1038\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1038\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1040\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1031\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1042\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1043\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1032\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1044\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1046\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1049\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1053\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1042\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1042\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1043\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1043\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1037\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\2052\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\2070\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\3076\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1040\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1044\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1044\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1045\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1045\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\DisplayIcon.ico.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\Print.ico.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate1.ico.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1055\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate3.ico.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate4.ico.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate5.ico.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate6.ico.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1046\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1046\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1049\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\3082\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1049\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate8.ico.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\Save.ico.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\Setup.ico.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\stop.ico.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1041\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1053\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1055\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1055\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1041\SetupResources.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\SysReqNotMet.ico.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\warn.ico.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1041\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\2052\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\2070\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1045\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\3076\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\3076\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\3082\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate2.ico.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\Rotate7.ico.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\1053\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Client\Parameterinfo.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Client\UiInfo.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Graphics\SysReqMet.ico.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\2052\eula.rtf.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Extended\Parameterinfo.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Extended\UiInfo.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\header.bmp.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\netfx_Core_x86.msi.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\DHtmlHeader.html.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\ParameterInfo.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\SetupUi.xsd.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Strings.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\UiInfo.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\watermark.bmp.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\3082\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\BOOTSECT.BAK.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\2070\LocalizedData.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\SplashScreen.bmp.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Boot\BOOTSTAT.DAT.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\RGB9RAST_x64.msi.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Java\jre1.8.0_144\Welcome.html.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\Office16\OSPP.HTM.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\Office16\OSPP.VBS.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\Setup.exe.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\RGB9Rast_x86.msi.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\SetupUi.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\sqmapi.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\SetupEngine.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\588bce7c90097ed212\SetupUtility.exe.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00004_.GIF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00037_.GIF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00103_.GIF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00120_.GIF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00126_.GIF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00129_.GIF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00130_.GIF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00040_.GIF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00170_.GIF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00171_.GIF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00172_.GIF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00174_.GIF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00135_.GIF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01084_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01174_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01216_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01218_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AG00175_.GIF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01251_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN01545_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02122_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02559_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN03500_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04108_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04117_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04134_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04174_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04384_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04385_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00116_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00141_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD00146_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN02724_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08808_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD08868_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09031_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\AN04191_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09664_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD10890_.GIF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD10972_.GIF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19563_.GIF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19582_.GIF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09194_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19827_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19828_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19986_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19988_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD20013_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00008_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00012_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00045_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00098_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD09662_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00122_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00130_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00148_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00152_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BD19695_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00525_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00526_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00648_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00921_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00105_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00932_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00985_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BOAT.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00194_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BOATINST.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00076_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00092_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00100_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00135_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00078_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00145_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00174_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00184_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BL00923_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01603_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01634_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01635_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01636_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00136_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01638_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS00186_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01639_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CG1606.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLASSIC1.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLASSIC2.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CLIP.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CRANE.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CRANINST.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CUP.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\BS01637_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\CUPINST.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00117_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00234_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00256_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00687_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00705_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01015_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00261_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD00255_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01138_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Binary |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01139_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01140_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01143_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01145_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01146_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01152_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01039_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01178_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01179_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01180_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01151_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01182_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01183_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01186_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01366_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01157_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01585_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01586_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01628_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Logs\Setup.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01181_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00222_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00242_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00319_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00320_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01434_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00902_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00074_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00076_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00077_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\DD01629_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00090_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00096_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00296_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00297_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Logs\System.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\EN00397_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00455_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00459_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00543_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00544_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00086_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00586_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00775_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00779_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00799_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvApi.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream64.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00965_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00814_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01074_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01084_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01176_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01191_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01193_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01196_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD00564_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01657_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01658_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01659_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01660_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00231_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00235_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00236_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00241_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00260_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD01548_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvStream32.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\FD02068_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00276_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00685_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00687_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00688_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00693_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01015_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01058_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01065_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01080_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01013_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01291_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01329_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01461_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01618_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVManifest.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVOrchestration.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVPolicy.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH00334_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01875_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01923_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH02155_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RUI.en-us.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVScripting.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\microsoft shared\ClickToRun\concrt140.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01759_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH02298_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH02312_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH02313_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HM00005_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH01242_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HM00116_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HM00172_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HM00426_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HH02282_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\HM00114_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0075478.GIF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0086384.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0086420.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0086424.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0086426.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0086428.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0086432.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0089945.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0089992.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0090027.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0090087.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\IN00046_.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0090149.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0090390.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0090777.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Microsoft Office\root\CLIPART\PUB60COR\J0090779.WMF.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\microsoft shared\ClickToRun\C2R64.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
File Reputation Information
»
Severity |
Blacklisted
|
Names | Mal/Generic-S |
File Reputation Information
»
Severity |
Suspicious
|
Names | App/Generic-GC |
Families | - |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x403093 |
Size Of Code | 0x17200 |
Size Of Initialized Data | 0x9e00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_cui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-09-06 07:42:08+00:00 |
Sections (3)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x17164 | 0x17200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62 |
.rdata | 0x419000 | 0x6b88 | 0x6c00 | 0x17600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.47 |
.data | 0x420000 | 0x3048 | 0x1200 | 0x1e200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.37 |
Imports (7)
»
KERNEL32.dll (87)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
HeapAlloc | 0x0 | 0x419010 | 0x1f2ac | 0x1d8ac | 0x32f |
WaitForSingleObject | 0x0 | 0x419014 | 0x1f2b0 | 0x1d8b0 | 0x5a9 |
SetVolumeMountPointW | 0x0 | 0x419018 | 0x1f2b4 | 0x1d8b4 | 0x547 |
GetLogicalDrives | 0x0 | 0x41901c | 0x1f2b8 | 0x1d8b8 | 0x257 |
Sleep | 0x0 | 0x419020 | 0x1f2bc | 0x1d8bc | 0x550 |
HeapDestroy | 0x0 | 0x419024 | 0x1f2c0 | 0x1d8c0 | 0x332 |
HeapCreate | 0x0 | 0x419028 | 0x1f2c4 | 0x1d8c4 | 0x331 |
FindNextVolumeW | 0x0 | 0x41902c | 0x1f2c8 | 0x1d8c8 | 0x184 |
GetVolumePathNamesForVolumeNameW | 0x0 | 0x419030 | 0x1f2cc | 0x1d8cc | 0x30e |
GetLastError | 0x0 | 0x419034 | 0x1f2d0 | 0x1d8d0 | 0x250 |
WaitForMultipleObjects | 0x0 | 0x419038 | 0x1f2d4 | 0x1d8d4 | 0x5a7 |
ReleaseMutex | 0x0 | 0x41903c | 0x1f2d8 | 0x1d8d8 | 0x48b |
CloseHandle | 0x0 | 0x419040 | 0x1f2dc | 0x1d8dc | 0x7f |
FindFirstVolumeW | 0x0 | 0x419044 | 0x1f2e0 | 0x1d8e0 | 0x179 |
CreateThread | 0x0 | 0x419048 | 0x1f2e4 | 0x1d8e4 | 0xe8 |
lstrcpyA | 0x0 | 0x41904c | 0x1f2e8 | 0x1d8e8 | 0x602 |
WriteConsoleW | 0x0 | 0x419050 | 0x1f2ec | 0x1d8ec | 0x5de |
SetStdHandle | 0x0 | 0x419054 | 0x1f2f0 | 0x1d8f0 | 0x520 |
SetFilePointerEx | 0x0 | 0x419058 | 0x1f2f4 | 0x1d8f4 | 0x4fc |
SetEnvironmentVariableA | 0x0 | 0x41905c | 0x1f2f8 | 0x1d8f8 | 0x4ec |
FindVolumeClose | 0x0 | 0x419060 | 0x1f2fc | 0x1d8fc | 0x18b |
CreateMutexW | 0x0 | 0x419064 | 0x1f300 | 0x1d900 | 0xd1 |
QueryDosDeviceW | 0x0 | 0x419068 | 0x1f304 | 0x1d904 | 0x426 |
ExitProcess | 0x0 | 0x41906c | 0x1f308 | 0x1d908 | 0x151 |
ReadConsoleW | 0x0 | 0x419070 | 0x1f30c | 0x1d90c | 0x44d |
ReadFile | 0x0 | 0x419074 | 0x1f310 | 0x1d910 | 0x44f |
GetConsoleMode | 0x0 | 0x419078 | 0x1f314 | 0x1d914 | 0x1ee |
GetConsoleCP | 0x0 | 0x41907c | 0x1f318 | 0x1d918 | 0x1dc |
FlushFileBuffers | 0x0 | 0x419080 | 0x1f31c | 0x1d91c | 0x192 |
HeapSize | 0x0 | 0x419084 | 0x1f320 | 0x1d920 | 0x338 |
GetFileAttributesExW | 0x0 | 0x419088 | 0x1f324 | 0x1d924 | 0x232 |
CreateProcessA | 0x0 | 0x41908c | 0x1f328 | 0x1d928 | 0xd7 |
GetExitCodeProcess | 0x0 | 0x419090 | 0x1f32c | 0x1d92c | 0x22c |
RtlUnwind | 0x0 | 0x419094 | 0x1f330 | 0x1d930 | 0x4ac |
OutputDebugStringW | 0x0 | 0x419098 | 0x1f334 | 0x1d934 | 0x3fa |
LoadLibraryExW | 0x0 | 0x41909c | 0x1f338 | 0x1d938 | 0x3a7 |
MultiByteToWideChar | 0x0 | 0x4190a0 | 0x1f33c | 0x1d93c | 0x3d1 |
HeapFree | 0x0 | 0x4190a4 | 0x1f340 | 0x1d940 | 0x333 |
IsDebuggerPresent | 0x0 | 0x4190a8 | 0x1f344 | 0x1d944 | 0x367 |
IsProcessorFeaturePresent | 0x0 | 0x4190ac | 0x1f348 | 0x1d948 | 0x36d |
HeapReAlloc | 0x0 | 0x4190b0 | 0x1f34c | 0x1d94c | 0x336 |
GetCommandLineA | 0x0 | 0x4190b4 | 0x1f350 | 0x1d950 | 0x1c8 |
EncodePointer | 0x0 | 0x4190b8 | 0x1f354 | 0x1d954 | 0x121 |
DecodePointer | 0x0 | 0x4190bc | 0x1f358 | 0x1d958 | 0xfe |
IsValidCodePage | 0x0 | 0x4190c0 | 0x1f35c | 0x1d95c | 0x372 |
GetACP | 0x0 | 0x4190c4 | 0x1f360 | 0x1d960 | 0x1a4 |
GetOEMCP | 0x0 | 0x4190c8 | 0x1f364 | 0x1d964 | 0x286 |
GetCPInfo | 0x0 | 0x4190cc | 0x1f368 | 0x1d968 | 0x1b3 |
SetLastError | 0x0 | 0x4190d0 | 0x1f36c | 0x1d96c | 0x50a |
GetCurrentThreadId | 0x0 | 0x4190d4 | 0x1f370 | 0x1d970 | 0x20e |
GetProcessHeap | 0x0 | 0x4190d8 | 0x1f374 | 0x1d974 | 0x2a2 |
GetModuleHandleExW | 0x0 | 0x4190dc | 0x1f378 | 0x1d978 | 0x266 |
GetProcAddress | 0x0 | 0x4190e0 | 0x1f37c | 0x1d97c | 0x29d |
AreFileApisANSI | 0x0 | 0x4190e4 | 0x1f380 | 0x1d980 | 0x1b |
WideCharToMultiByte | 0x0 | 0x4190e8 | 0x1f384 | 0x1d984 | 0x5cb |
GetStdHandle | 0x0 | 0x4190ec | 0x1f388 | 0x1d988 | 0x2c0 |
WriteFile | 0x0 | 0x4190f0 | 0x1f38c | 0x1d98c | 0x5df |
GetModuleFileNameW | 0x0 | 0x4190f4 | 0x1f390 | 0x1d990 | 0x263 |
EnterCriticalSection | 0x0 | 0x4190f8 | 0x1f394 | 0x1d994 | 0x125 |
LeaveCriticalSection | 0x0 | 0x4190fc | 0x1f398 | 0x1d998 | 0x3a2 |
UnhandledExceptionFilter | 0x0 | 0x419100 | 0x1f39c | 0x1d99c | 0x580 |
SetUnhandledExceptionFilter | 0x0 | 0x419104 | 0x1f3a0 | 0x1d9a0 | 0x541 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x419108 | 0x1f3a4 | 0x1d9a4 | 0x348 |
GetCurrentProcess | 0x0 | 0x41910c | 0x1f3a8 | 0x1d9a8 | 0x209 |
TerminateProcess | 0x0 | 0x419110 | 0x1f3ac | 0x1d9ac | 0x55f |
TlsAlloc | 0x0 | 0x419114 | 0x1f3b0 | 0x1d9b0 | 0x571 |
TlsGetValue | 0x0 | 0x419118 | 0x1f3b4 | 0x1d9b4 | 0x573 |
TlsSetValue | 0x0 | 0x41911c | 0x1f3b8 | 0x1d9b8 | 0x574 |
TlsFree | 0x0 | 0x419120 | 0x1f3bc | 0x1d9bc | 0x572 |
GetStartupInfoW | 0x0 | 0x419124 | 0x1f3c0 | 0x1d9c0 | 0x2be |
GetModuleHandleW | 0x0 | 0x419128 | 0x1f3c4 | 0x1d9c4 | 0x267 |
DeleteCriticalSection | 0x0 | 0x41912c | 0x1f3c8 | 0x1d9c8 | 0x105 |
GetFileType | 0x0 | 0x419130 | 0x1f3cc | 0x1d9cc | 0x23e |
GetModuleFileNameA | 0x0 | 0x419134 | 0x1f3d0 | 0x1d9d0 | 0x262 |
QueryPerformanceCounter | 0x0 | 0x419138 | 0x1f3d4 | 0x1d9d4 | 0x42d |
GetCurrentProcessId | 0x0 | 0x41913c | 0x1f3d8 | 0x1d9d8 | 0x20a |
GetSystemTimeAsFileTime | 0x0 | 0x419140 | 0x1f3dc | 0x1d9dc | 0x2d6 |
GetEnvironmentStringsW | 0x0 | 0x419144 | 0x1f3e0 | 0x1d9e0 | 0x227 |
FreeEnvironmentStringsW | 0x0 | 0x419148 | 0x1f3e4 | 0x1d9e4 | 0x19d |
GetStringTypeW | 0x0 | 0x41914c | 0x1f3e8 | 0x1d9e8 | 0x2c5 |
GetLocaleInfoW | 0x0 | 0x419150 | 0x1f3ec | 0x1d9ec | 0x254 |
IsValidLocale | 0x0 | 0x419154 | 0x1f3f0 | 0x1d9f0 | 0x374 |
GetUserDefaultLCID | 0x0 | 0x419158 | 0x1f3f4 | 0x1d9f4 | 0x2fc |
EnumSystemLocalesW | 0x0 | 0x41915c | 0x1f3f8 | 0x1d9f8 | 0x147 |
CompareStringW | 0x0 | 0x419160 | 0x1f3fc | 0x1d9fc | 0x93 |
LCMapStringW | 0x0 | 0x419164 | 0x1f400 | 0x1da00 | 0x396 |
CreateFileW | 0x0 | 0x419168 | 0x1f404 | 0x1da04 | 0xc2 |
USER32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
wsprintfW | 0x0 | 0x41918c | 0x1f428 | 0x1da28 | 0x37b |
MPR.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WNetAddConnection2W | 0x0 | 0x419170 | 0x1f40c | 0x1da0c | 0xd |
IPHLPAPI.DLL (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
IcmpCreateFile | 0x0 | 0x419000 | 0x1f29c | 0x1d89c | 0x85 |
GetAdaptersInfo | 0x0 | 0x419004 | 0x1f2a0 | 0x1d8a0 | 0x3e |
IcmpSendEcho | 0x0 | 0x419008 | 0x1f2a4 | 0x1d8a4 | 0x87 |
WS2_32.dll (7)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
htonl | 0x8 | 0x419194 | 0x1f430 | 0x1da30 | - |
gethostbyname | 0x34 | 0x419198 | 0x1f434 | 0x1da34 | - |
gethostname | 0x39 | 0x41919c | 0x1f438 | 0x1da38 | - |
inet_addr | 0xb | 0x4191a0 | 0x1f43c | 0x1da3c | - |
inet_ntoa | 0xc | 0x4191a4 | 0x1f440 | 0x1da40 | - |
WSAStartup | 0x73 | 0x4191a8 | 0x1f444 | 0x1da44 | - |
ntohl | 0xe | 0x4191ac | 0x1f448 | 0x1da48 | - |
NETAPI32.dll (2)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
NetShareEnum | 0x0 | 0x419178 | 0x1f414 | 0x1da14 | 0xe5 |
NetApiBufferFree | 0x0 | 0x41917c | 0x1f418 | 0x1da18 | 0x59 |
SHLWAPI.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StrStrW | 0x0 | 0x419184 | 0x1f420 | 0x1da20 | 0x152 |
Memory Dumps (2)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Point | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
ns2.exe | 9 | 0x00400000 | 0x00423FFF | Relevant Image |
![]() |
32-bit | 0x004051CD |
![]() |
![]() |
...
|
ns2.exe | 9 | 0x00400000 | 0x00423FFF | Final Dump |
![]() |
32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Application.Hacktool.ADH |
Suspicious
|
C:\Users\FD1HVy\AppData\Local\Temp\__PSScriptPolicyTest_rteipa5x.j33.ps1 | Dropped File | Text |
Whitelisted
|
...
|
»
File Reputation Information
»
Severity |
Whitelisted
|
C:\Users\FD1HVy\AppData\Local\Temp\4izn5b55.cmdline | Dropped File | Text |
Unknown
|
...
|
»
C:\$GetCurrent\SafeOS\GetCurrentRollback.ini.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\$GetCurrent\Logs\oobe_2017_09_07_03_08_57_737.log.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core_x64.msi.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Core.mzz.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended.mzz.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x86.msi.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Binary |
Unknown
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME-JAVAFX.txt.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x86.msu.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0057-0000-1000-0000000FF1CE.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00BA-0000-1000-0000000FF1CE.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Binary |
Unknown
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.common.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppReadiness%4Admin.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeployment%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppxPackaging%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-CoreSystem-SmsRouter-Events%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Admin.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-HotspotAuth%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-EventTracing%4Admin.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcpv6-Client%4Admin.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-LiveId%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-NCSI%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-SMBServer%4Audit.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-VolumeSnapshot-Driver%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Wcmsvc%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4WHC.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4ConnectionSecurity.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-WinINet-Config%4ProxyConfigChanged.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Firewall With Advanced Security%4Firewall.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-core-xstate-l2-1-0.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-conio-l1-1-0.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-convert-l1-1-0.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-filesystem-l1-1-0.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIntegration.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvStreamingManager.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvSubsystemController.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvVirtualization.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Unknown
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\4izn5b55.0.cs | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\4izn5b55.out | Dropped File | Text |
Not Queried
|
...
|
»
C:\Users\FD1HVy\AppData\Local\Temp\4izn5b55.err | Dropped File | Unknown |
Not Queried
|
...
|
»
C:\$GetCurrent\Logs\downlevel_2017_09_07_02_02_39_766.log.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$Recycle.Bin\S-1-5-18\desktop.ini.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$Recycle.Bin\S-1-5-21-1051304884-625712362-2192934891-1000\desktop.ini.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\Logs\PartnerSetupCompleteResult.log.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\preoobe.cmd.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\$GetCurrent\SafeOS\PartnerSetupComplete.cmd.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\C2RHeartbeatConfig.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\ServiceWatcherSchedule.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\netfx_Extended_x64.msi.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeUpdateSchedule.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Java\jre1.8.0_144\THIRDPARTYLICENSEREADME.txt.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\AppXManifest.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\FileSystemMetadata.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Audio |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-0019-0409-1000-0000000FF1CE.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.0-KB956250-v6001-x64.msu.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-001A-0000-1000-0000000FF1CE.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x64.msu.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00A1-0000-1000-0000000FF1CE.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifest.90160000-00C1-0000-1000-0000000FF1CE.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Microsoft Office\PackageManifests\AppXManifestLoc.en-us.xml.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\588bce7c90097ed212\Windows6.1-KB958488-v6001-x86.msu.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Client-Licensing-Platform%4Admin.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Application-Experience%4Program-Compatibility-Assistant.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-ApplicationResourceManagementSystem%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4EXE and DLL.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Deployment.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppLocker%4Packaged app-Execution.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-AppXDeploymentServer%4Restricted.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-BackgroundTaskInfrastructure%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4BackUpKeySvc.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Crypto-DPAPI%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-DeviceSetupManager%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Dhcp-Client%4Admin.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Compressed |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-Power%4Thermal-Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-International%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-StoreMgr%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Errors.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-ShimEngine%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Known Folders API Service.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-MUI%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Kernel-WHEA%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4ActionCenter.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Connectivity.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SMBClient%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SmbClient%4Security.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-SettingSync%4Debug.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Shell-Core%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Admin.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-TWinUI%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-User Profile Service%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4DeviceInstall.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-Windows Defender%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-UserPnp%4ActionCenter.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Logs\Microsoft-Windows-WMI-Activity%4Operational.evtx.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-environment-l1-1-0.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-heap-l1-1-0.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-locale-l1-1-0.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-math-l1-1-0.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\api-ms-win-crt-multibyte-l1-1-0.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems64.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\i640.hash.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\i641033.hash.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\mso30win32client.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»
C:\Program Files\Common Files\microsoft shared\ClickToRun\mso20win32client.dll.id-B4197730.[cavefat@tuta.io].HCK | Dropped File | Stream |
Not Queried
|
...
|
»