VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Wiper, Spyware, Trojan |
1Black.exe
Windows Exe (x86-32)
Created at 2019-10-20T18:23:00
Remarks
(0x200001e): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\1Black.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Blacklisted
|
First Seen | 2019-10-20 07:48 (UTC+2) |
Last Seen | 2019-10-20 07:51 (UTC+2) |
Names | Win32.Trojan.Hpgen |
Families | Hpgen |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x40d5db |
Size Of Code | 0x24200 |
Size Of Initialized Data | 0x5ca00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2019-10-18 22:21:54+00:00 |
Version Information (8)
»
Comments | Artillery Repsitry Azure 2m Posture |
CompanyName | Adobe Systems Inc. |
FileDescription | Artillery Repsitry Azure 2m Posture |
FileVersion | 8.6.62.2 |
InternalName | UnsolicitedAntialiased |
LegalCopyright | Copyright (c) |
ProductName | UnsolicitedAntialiased |
ProductVersion | 8.6.62.2 |
Sections (4)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x2409c | 0x24200 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.73 |
.rdata | 0x426000 | 0x1b7fc | 0x1b800 | 0x24600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.6 |
.data | 0x442000 | 0x4474 | 0x1c00 | 0x3fe00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.56 |
.rsrc | 0x447000 | 0x3f5c8 | 0x3f600 | 0x41a00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.77 |
Imports (16)
»
KERNEL32.dll (86)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DecodePointer | 0x0 | 0x42605c | 0x40944 | 0x3ef44 | 0x109 |
WriteConsoleW | 0x0 | 0x426060 | 0x40948 | 0x3ef48 | 0x611 |
SetEndOfFile | 0x0 | 0x426064 | 0x4094c | 0x3ef4c | 0x510 |
HeapSize | 0x0 | 0x426068 | 0x40950 | 0x3ef50 | 0x34e |
CreateFileW | 0x0 | 0x42606c | 0x40954 | 0x3ef54 | 0xcb |
GetProcessHeap | 0x0 | 0x426070 | 0x40958 | 0x3ef58 | 0x2b4 |
GetStringTypeW | 0x0 | 0x426074 | 0x4095c | 0x3ef5c | 0x2d7 |
FreeEnvironmentStringsW | 0x0 | 0x426078 | 0x40960 | 0x3ef60 | 0x1aa |
GetEnvironmentStringsW | 0x0 | 0x42607c | 0x40964 | 0x3ef64 | 0x237 |
WideCharToMultiByte | 0x0 | 0x426080 | 0x40968 | 0x3ef68 | 0x5fe |
GetCommandLineW | 0x0 | 0x426084 | 0x4096c | 0x3ef6c | 0x1d7 |
GetCommandLineA | 0x0 | 0x426088 | 0x40970 | 0x3ef70 | 0x1d6 |
GetCPInfo | 0x0 | 0x42608c | 0x40974 | 0x3ef74 | 0x1c1 |
GetOEMCP | 0x0 | 0x426090 | 0x40978 | 0x3ef78 | 0x297 |
GetACP | 0x0 | 0x426094 | 0x4097c | 0x3ef7c | 0x1b2 |
IsValidCodePage | 0x0 | 0x426098 | 0x40980 | 0x3ef80 | 0x38b |
FindNextFileW | 0x0 | 0x42609c | 0x40984 | 0x3ef84 | 0x18c |
FindFirstFileExW | 0x0 | 0x4260a0 | 0x40988 | 0x3ef88 | 0x17b |
FindClose | 0x0 | 0x4260a4 | 0x4098c | 0x3ef8c | 0x175 |
SetStdHandle | 0x0 | 0x4260a8 | 0x40990 | 0x3ef90 | 0x54a |
WaitForSingleObject | 0x0 | 0x4260ac | 0x40994 | 0x3ef94 | 0x5d7 |
SetFilePointerEx | 0x0 | 0x4260b0 | 0x40998 | 0x3ef98 | 0x523 |
GetFileSizeEx | 0x0 | 0x4260b4 | 0x4099c | 0x3ef9c | 0x24c |
GetConsoleCP | 0x0 | 0x4260b8 | 0x409a0 | 0x3efa0 | 0x1ea |
ReadConsoleW | 0x0 | 0x4260bc | 0x409a4 | 0x3efa4 | 0x470 |
GetConsoleMode | 0x0 | 0x4260c0 | 0x409a8 | 0x3efa8 | 0x1fc |
HeapReAlloc | 0x0 | 0x4260c4 | 0x409ac | 0x3efac | 0x34c |
WriteConsoleA | 0x0 | 0x4260c8 | 0x409b0 | 0x3efb0 | 0x607 |
HeapFree | 0x0 | 0x4260cc | 0x409b4 | 0x3efb4 | 0x349 |
HeapAlloc | 0x0 | 0x4260d0 | 0x409b8 | 0x3efb8 | 0x345 |
GetModuleFileNameW | 0x0 | 0x4260d4 | 0x409bc | 0x3efbc | 0x274 |
GetModuleHandleExW | 0x0 | 0x4260d8 | 0x409c0 | 0x3efc0 | 0x277 |
ExitProcess | 0x0 | 0x4260dc | 0x409c4 | 0x3efc4 | 0x15e |
LoadLibraryExW | 0x0 | 0x4260e0 | 0x409c8 | 0x3efc8 | 0x3c3 |
FreeLibrary | 0x0 | 0x4260e4 | 0x409cc | 0x3efcc | 0x1ab |
ReadConsoleA | 0x0 | 0x4260e8 | 0x409d0 | 0x3efd0 | 0x466 |
Sleep | 0x0 | 0x4260ec | 0x409d4 | 0x3efd4 | 0x57d |
AllocConsole | 0x0 | 0x4260f0 | 0x409d8 | 0x3efd8 | 0x15 |
FreeEnvironmentStringsA | 0x0 | 0x4260f4 | 0x409dc | 0x3efdc | 0x1a9 |
CreateEventA | 0x0 | 0x4260f8 | 0x409e0 | 0x3efe0 | 0xbc |
GetProcAddress | 0x0 | 0x4260fc | 0x409e4 | 0x3efe4 | 0x2ae |
GetLocalTime | 0x0 | 0x426100 | 0x409e8 | 0x3efe8 | 0x262 |
FreeConsole | 0x0 | 0x426104 | 0x409ec | 0x3efec | 0x1a8 |
CloseHandle | 0x0 | 0x426108 | 0x409f0 | 0x3eff0 | 0x86 |
GlobalAlloc | 0x0 | 0x42610c | 0x409f4 | 0x3eff4 | 0x32d |
DeleteFileA | 0x0 | 0x426110 | 0x409f8 | 0x3eff8 | 0x112 |
LoadLibraryA | 0x0 | 0x426114 | 0x409fc | 0x3effc | 0x3c1 |
GetSystemDirectoryA | 0x0 | 0x426118 | 0x40a00 | 0x3f000 | 0x2df |
CreateFileA | 0x0 | 0x42611c | 0x40a04 | 0x3f004 | 0xc3 |
FlushFileBuffers | 0x0 | 0x426120 | 0x40a08 | 0x3f008 | 0x19f |
GetLastError | 0x0 | 0x426124 | 0x40a0c | 0x3f00c | 0x261 |
TlsFree | 0x0 | 0x426128 | 0x40a10 | 0x3f010 | 0x59f |
TlsSetValue | 0x0 | 0x42612c | 0x40a14 | 0x3f014 | 0x5a1 |
TlsGetValue | 0x0 | 0x426130 | 0x40a18 | 0x3f018 | 0x5a0 |
TlsAlloc | 0x0 | 0x426134 | 0x40a1c | 0x3f01c | 0x59e |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x426138 | 0x40a20 | 0x3f020 | 0x35f |
DeleteCriticalSection | 0x0 | 0x42613c | 0x40a24 | 0x3f024 | 0x110 |
LeaveCriticalSection | 0x0 | 0x426140 | 0x40a28 | 0x3f028 | 0x3bd |
EnterCriticalSection | 0x0 | 0x426144 | 0x40a2c | 0x3f02c | 0x131 |
EncodePointer | 0x0 | 0x426148 | 0x40a30 | 0x3f030 | 0x12d |
SetLastError | 0x0 | 0x42614c | 0x40a34 | 0x3f034 | 0x532 |
RaiseException | 0x0 | 0x426150 | 0x40a38 | 0x3f038 | 0x462 |
RtlUnwind | 0x0 | 0x426154 | 0x40a3c | 0x3f03c | 0x4d3 |
GetModuleHandleW | 0x0 | 0x426158 | 0x40a40 | 0x3f040 | 0x278 |
ReadFile | 0x0 | 0x42615c | 0x40a44 | 0x3f044 | 0x473 |
GetStdHandle | 0x0 | 0x426160 | 0x40a48 | 0x3f048 | 0x2d2 |
SetConsoleTitleA | 0x0 | 0x426164 | 0x40a4c | 0x3f04c | 0x503 |
GetStartupInfoW | 0x0 | 0x426168 | 0x40a50 | 0x3f050 | 0x2d0 |
IsDebuggerPresent | 0x0 | 0x42616c | 0x40a54 | 0x3f054 | 0x37f |
InitializeSListHead | 0x0 | 0x426170 | 0x40a58 | 0x3f058 | 0x363 |
GetSystemTimeAsFileTime | 0x0 | 0x426174 | 0x40a5c | 0x3f05c | 0x2e9 |
GetCurrentProcessId | 0x0 | 0x426178 | 0x40a60 | 0x3f060 | 0x218 |
QueryPerformanceCounter | 0x0 | 0x42617c | 0x40a64 | 0x3f064 | 0x44d |
IsProcessorFeaturePresent | 0x0 | 0x426180 | 0x40a68 | 0x3f068 | 0x386 |
TerminateProcess | 0x0 | 0x426184 | 0x40a6c | 0x3f06c | 0x58c |
GetCurrentProcess | 0x0 | 0x426188 | 0x40a70 | 0x3f070 | 0x217 |
SetUnhandledExceptionFilter | 0x0 | 0x42618c | 0x40a74 | 0x3f074 | 0x56d |
UnhandledExceptionFilter | 0x0 | 0x426190 | 0x40a78 | 0x3f078 | 0x5ad |
MultiByteToWideChar | 0x0 | 0x426194 | 0x40a7c | 0x3f07c | 0x3ef |
SetConsoleCtrlHandler | 0x0 | 0x426198 | 0x40a80 | 0x3f080 | 0x4e9 |
LCMapStringW | 0x0 | 0x42619c | 0x40a84 | 0x3f084 | 0x3b1 |
GetCurrentThreadId | 0x0 | 0x4261a0 | 0x40a88 | 0x3f088 | 0x21c |
GetModuleHandleA | 0x0 | 0x4261a4 | 0x40a8c | 0x3f08c | 0x275 |
GetVersion | 0x0 | 0x4261a8 | 0x40a90 | 0x3f090 | 0x319 |
WriteFile | 0x0 | 0x4261ac | 0x40a94 | 0x3f094 | 0x612 |
GetFileType | 0x0 | 0x4261b0 | 0x40a98 | 0x3f098 | 0x24e |
USER32.dll (48)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetCursorPos | 0x0 | 0x4261f0 | 0x40ad8 | 0x3f0d8 | 0x13e |
ReleaseDC | 0x0 | 0x4261f4 | 0x40adc | 0x3f0dc | 0x2fe |
IsIconic | 0x0 | 0x4261f8 | 0x40ae0 | 0x3f0e0 | 0x22a |
InvalidateRect | 0x0 | 0x4261fc | 0x40ae4 | 0x3f0e4 | 0x217 |
SetForegroundWindow | 0x0 | 0x426200 | 0x40ae8 | 0x3f0e8 | 0x337 |
PtInRect | 0x0 | 0x426204 | 0x40aec | 0x3f0ec | 0x2bd |
GetProcessWindowStation | 0x0 | 0x426208 | 0x40af0 | 0x3f0f0 | 0x1a6 |
BeginPaint | 0x0 | 0x42620c | 0x40af4 | 0x3f0f4 | 0x10 |
GetUserObjectInformationW | 0x0 | 0x426210 | 0x40af8 | 0x3f0f8 | 0x1d0 |
InsertMenuItemA | 0x0 | 0x426214 | 0x40afc | 0x3f0fc | 0x211 |
GetParent | 0x0 | 0x426218 | 0x40b00 | 0x3f100 | 0x18b |
GetWindowTextLengthA | 0x0 | 0x42621c | 0x40b04 | 0x3f104 | 0x1eb |
GetKeyState | 0x0 | 0x426220 | 0x40b08 | 0x3f108 | 0x163 |
GetWindowRect | 0x0 | 0x426224 | 0x40b0c | 0x3f10c | 0x1e6 |
LoadCursorA | 0x0 | 0x426228 | 0x40b10 | 0x3f110 | 0x24a |
GetDC | 0x0 | 0x42622c | 0x40b14 | 0x3f114 | 0x13f |
SetWindowPos | 0x0 | 0x426230 | 0x40b18 | 0x3f118 | 0x376 |
InsertMenuA | 0x0 | 0x426234 | 0x40b1c | 0x3f11c | 0x210 |
LoadStringA | 0x0 | 0x426238 | 0x40b20 | 0x3f120 | 0x25b |
UnionRect | 0x0 | 0x42623c | 0x40b24 | 0x3f124 | 0x3ad |
WaitForInputIdle | 0x0 | 0x426240 | 0x40b28 | 0x3f128 | 0x3d6 |
GetSystemMetrics | 0x0 | 0x426244 | 0x40b2c | 0x3f12c | 0x1bf |
CreatePopupMenu | 0x0 | 0x426248 | 0x40b30 | 0x3f130 | 0x71 |
DialogBoxParamA | 0x0 | 0x42624c | 0x40b34 | 0x3f134 | 0xb8 |
TrackPopupMenu | 0x0 | 0x426250 | 0x40b38 | 0x3f138 | 0x3a1 |
wsprintfA | 0x0 | 0x426254 | 0x40b3c | 0x3f13c | 0x3e3 |
ShowWindow | 0x0 | 0x426258 | 0x40b40 | 0x3f140 | 0x387 |
SetTimer | 0x0 | 0x42625c | 0x40b44 | 0x3f144 | 0x368 |
SetWindowLongA | 0x0 | 0x426260 | 0x40b48 | 0x3f148 | 0x373 |
CreateAcceleratorTableA | 0x0 | 0x426264 | 0x40b4c | 0x3f14c | 0x5c |
GetWindowLongA | 0x0 | 0x426268 | 0x40b50 | 0x3f150 | 0x1de |
CharToOemBuffA | 0x0 | 0x42626c | 0x40b54 | 0x3f154 | 0x38 |
AttachThreadInput | 0x0 | 0x426270 | 0x40b58 | 0x3f158 | 0xe |
MessageBoxA | 0x0 | 0x426274 | 0x40b5c | 0x3f15c | 0x289 |
MoveWindow | 0x0 | 0x426278 | 0x40b60 | 0x3f160 | 0x296 |
DefWindowProcA | 0x0 | 0x42627c | 0x40b64 | 0x3f164 | 0xa5 |
SetLayeredWindowAttributes | 0x0 | 0x426280 | 0x40b68 | 0x3f168 | 0x33c |
SetFocus | 0x0 | 0x426284 | 0x40b6c | 0x3f16c | 0x336 |
SetDlgItemTextA | 0x0 | 0x426288 | 0x40b70 | 0x3f170 | 0x332 |
SendMessageA | 0x0 | 0x42628c | 0x40b74 | 0x3f174 | 0x314 |
SetCapture | 0x0 | 0x426290 | 0x40b78 | 0x3f178 | 0x31d |
CallMsgFilterA | 0x0 | 0x426294 | 0x40b7c | 0x3f17c | 0x1c |
SetCursor | 0x0 | 0x426298 | 0x40b80 | 0x3f180 | 0x327 |
SystemParametersInfoA | 0x0 | 0x42629c | 0x40b84 | 0x3f184 | 0x395 |
GetClientRect | 0x0 | 0x4262a0 | 0x40b88 | 0x3f188 | 0x130 |
GetDlgItem | 0x0 | 0x4262a4 | 0x40b8c | 0x3f18c | 0x149 |
SetRect | 0x0 | 0x4262a8 | 0x40b90 | 0x3f190 | 0x357 |
PostQuitMessage | 0x0 | 0x4262ac | 0x40b94 | 0x3f194 | 0x2b4 |
GDI32.dll (14)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
BitBlt | 0x0 | 0x426020 | 0x40908 | 0x3ef08 | 0x13 |
SelectObject | 0x0 | 0x426024 | 0x4090c | 0x3ef0c | 0x35b |
CreateCompatibleDC | 0x0 | 0x426028 | 0x40910 | 0x3ef10 | 0x31 |
CreateRectRgnIndirect | 0x0 | 0x42602c | 0x40914 | 0x3ef14 | 0x54 |
ChoosePixelFormat | 0x0 | 0x426030 | 0x40918 | 0x3ef18 | 0x19 |
LineTo | 0x0 | 0x426034 | 0x4091c | 0x3ef1c | 0x2e2 |
CreatePen | 0x0 | 0x426038 | 0x40920 | 0x3ef20 | 0x4f |
MoveToEx | 0x0 | 0x42603c | 0x40924 | 0x3ef24 | 0x2f4 |
Ellipse | 0x0 | 0x426040 | 0x40928 | 0x3ef28 | 0x186 |
DeleteObject | 0x0 | 0x426044 | 0x4092c | 0x3ef2c | 0x17d |
CreateSolidBrush | 0x0 | 0x426048 | 0x40930 | 0x3ef30 | 0x59 |
CombineRgn | 0x0 | 0x42604c | 0x40934 | 0x3ef34 | 0x22 |
SetAbortProc | 0x0 | 0x426050 | 0x40938 | 0x3ef38 | 0x35d |
SetPixelFormat | 0x0 | 0x426054 | 0x4093c | 0x3ef3c | 0x380 |
ole32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
StgCreateDocfile | 0x0 | 0x4262dc | 0x40bc4 | 0x3f1c4 | 0x1b7 |
OLEAUT32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
SystemTimeToVariantTime | 0xb8 | 0x4261b8 | 0x40aa0 | 0x3f0a0 | - |
UnRegisterTypeLib | 0xba | 0x4261bc | 0x40aa4 | 0x3f0a4 | - |
SysAllocStringLen | 0x4 | 0x4261c0 | 0x40aa8 | 0x3f0a8 | - |
WS2_32.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
WSAStringToAddressA | 0x0 | 0x4262cc | 0x40bb4 | 0x3f1b4 | 0x59 |
WINMM.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
waveOutSetVolume | 0x0 | 0x4262bc | 0x40ba4 | 0x3f1a4 | 0xbb |
mmioWrite | 0x0 | 0x4262c0 | 0x40ba8 | 0x3f1a8 | 0x89 |
timeGetTime | 0x0 | 0x4262c4 | 0x40bac | 0x3f1ac | 0x94 |
VERSION.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetFileVersionInfoW | 0x0 | 0x4262b4 | 0x40b9c | 0x3f19c | 0x8 |
SHLWAPI.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PathFileExistsA | 0x0 | 0x4261e8 | 0x40ad0 | 0x3f0d0 | 0x47 |
ACTIVEDS.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x9 | 0x426000 | 0x408e8 | 0x3eee8 | - |
pdh.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
PdhCollectQueryData | 0x0 | 0x4262e4 | 0x40bcc | 0x3f1cc | 0x12 |
RPCRT4.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
RpcStringFreeA | 0x0 | 0x4261d8 | 0x40ac0 | 0x3f0c0 | 0x20c |
UuidToStringA | 0x0 | 0x4261dc | 0x40ac4 | 0x3f0c4 | 0x21e |
UuidFromStringA | 0x0 | 0x4261e0 | 0x40ac8 | 0x3f0c8 | 0x21a |
POWRPROF.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ReadProcessorPwrScheme | 0x0 | 0x4261c8 | 0x40ab0 | 0x3f0b0 | 0x79 |
CanUserWritePwrScheme | 0x0 | 0x4261cc | 0x40ab4 | 0x3f0b4 | 0x1 |
DeletePwrScheme | 0x0 | 0x4261d0 | 0x40ab8 | 0x3f0b8 | 0x2 |
d2d1.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
(by ordinal) | 0x1 | 0x4262d4 | 0x40bbc | 0x3f1bc | - |
DWrite.dll (1)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
DWriteCreateFactory | 0x0 | 0x426018 | 0x40900 | 0x3ef00 | 0x0 |
ADVAPI32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ReportEventA | 0x0 | 0x426008 | 0x408f0 | 0x3eef0 | 0x2bf |
RegisterEventSourceA | 0x0 | 0x42600c | 0x408f4 | 0x3eef4 | 0x2ad |
DeregisterEventSource | 0x0 | 0x426010 | 0x408f8 | 0x3eef8 | 0xed |
Memory Dumps (10)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuild | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
1black.exe | 1 | 0x00400000 | 0x00486FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 1 | 0x0A600000 | 0x0A632FFF | First Execution | - | 32-bit | 0x0A600000 |
![]() |
![]() |
...
|
buffer | 1 | 0x0A600000 | 0x0A632FFF | Content Changed | - | 32-bit | 0x0A602A1E |
![]() |
![]() |
...
|
1black.exe | 1 | 0x00400000 | 0x00486FFF | Process Termination | - | 32-bit | - |
![]() |
![]() |
...
|
1black.exe | 2 | 0x00400000 | 0x00486FFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
1black.exe | 2 | 0x00400000 | 0x00486FFF | Final Dump | - | 32-bit | - |
![]() |
![]() |
...
|
buffer | 8 | 0x0A8A0000 | 0x0A8D2FFF | First Execution | - | 32-bit | 0x0A8A0000 |
![]() |
![]() |
...
|
buffer | 9 | 0x0A870000 | 0x0A8A2FFF | First Execution | - | 32-bit | 0x0A870000 |
![]() |
![]() |
...
|
buffer | 8 | 0x0A8A0000 | 0x0A8D2FFF | Content Changed | - | 32-bit | 0x0A8A2A1E |
![]() |
![]() |
...
|
buffer | 9 | 0x0A870000 | 0x0A8A2FFF | Content Changed | - | 32-bit | 0x0A872A1E |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Trojan.Ransomware.GenericKDS.32600106 |
Malicious
|
C:\Boot\BOOTSTAT.DAT.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\BOOTSECT.BAK.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\branding.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\pss10r.chm.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\setup.chm.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\branding.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjProrWW.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPlusrWW.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.EPS.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.GIF.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Office32WW.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.PNG.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.JPG.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\AccessMUI.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\AccessMUISet.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\ExcelMUI.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Groove.en-us\GrooveMUI.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Groove.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\README.HTM.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\BRANDING.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OCT.CHM.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUI.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUISet.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSS10O.CHM.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSCONFIG.CHM.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.msi.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\InfoPathMUI.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\Office32MUI.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSS10R.CHM.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\SETUP.CHM.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.WW\Office32WW.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\OneNoteMUI.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\OutlookMUI.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\PowerPointMUI.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Project.en-us\ProjectMUI.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PRJPROR\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.es\Proof.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.fr\Proof.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Project.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.en\Proof.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PRJPROR\PrjProrWW.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PROPLUSR\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PROPLUSR\ProPlusrWW.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Publisher.en-us\PublisherMUI.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Publisher.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Visio.en-us\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\SETUP.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proofing.en-us\Proofing.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\VisiorWW.XML.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Score | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
5/5
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.cab.id-9C354B42.[bitlocker@foxmail.com ].wiki | Modified File | Stream |
Unknown
|
...
|
»
C:\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000\desktop.ini.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.cab.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\ADO210.CHM.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\OWOW32LR.cab.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfLR.cab.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.msi.id-9C354B42.[bitlocker@foxmail.com ].wiki | Dropped File | Stream |
Unknown
|
...
|
»