VTI SCORE: 100/100
Dynamic Analysis Report |
Classification: Ransomware, Wiper, Trojan |
rruzcj.exe
Windows Exe (x86-32)
Created at 2019-06-09T09:41:00
Remarks
(0x200001e): The maximum size of extracted files was exceeded. Some files may be missing in the report.
(0x200001d): The maximum number of extracted files was exceeded. Some files may be missing in the report.
Master Boot Record Changes
»
Sector Number | Sector Size | Actions |
---|---|---|
2063 | 512 bytes |
...
|
This is a filtered view
This list contains only the embedded files, downloaded files, and dropped files
Filters: |
There are no files for this filter
There are no files in this analysis
Filename | Category | Type | Severity | Actions |
---|
C:\Users\5p5NrGJn0jS HALPmcxz\Desktop\rruzcj.exe | Sample File | Binary |
Malicious
|
...
|
»
File Reputation Information
»
Severity |
Suspicious
|
First Seen | 2019-06-09 11:06 (UTC+2) |
Last Seen | 2019-06-09 11:12 (UTC+2) |
Names | Win32.Trojan.Kryptik |
Families | Kryptik |
Classification | Trojan |
PE Information
»
Image Base | 0x400000 |
Entry Point | 0x406d18 |
Size Of Code | 0x23a00 |
Size Of Initialized Data | 0x77a00 |
File Type | FileType.executable |
Subsystem | Subsystem.windows_gui |
Machine Type | MachineType.i386 |
Compile Timestamp | 2018-01-07 09:53:17+00:00 |
Version Information (1)
»
FileVersion | 1.0.0.1 |
Sections (5)
»
Name | Virtual Address | Virtual Size | Raw Data Size | Raw Data Offset | Flags | Entropy |
---|---|---|---|---|---|---|
.text | 0x401000 | 0x23870 | 0x23a00 | 0x400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.86 |
.rdata | 0x425000 | 0x258a | 0x2600 | 0x23e00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.55 |
.data | 0x428000 | 0x50b78 | 0x1000 | 0x26400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.13 |
.rsrc | 0x479000 | 0x23810 | 0x23a00 | 0x27400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.41 |
.reloc | 0x49d000 | 0x1abc | 0x1c00 | 0x4ae00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 2.71 |
Imports (4)
»
KERNEL32.dll (68)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetThreadPriority | 0x0 | 0x425014 | 0x26e0c | 0x25c0c | 0x261 |
GetModuleHandleA | 0x0 | 0x425018 | 0x26e10 | 0x25c10 | 0x1f6 |
GetThreadTimes | 0x0 | 0x42501c | 0x26e14 | 0x25c14 | 0x264 |
SetCommMask | 0x0 | 0x425020 | 0x26e18 | 0x25c18 | 0x39e |
LCMapStringA | 0x0 | 0x425024 | 0x26e1c | 0x25c1c | 0x2e1 |
GetStringTypeW | 0x0 | 0x425028 | 0x26e20 | 0x25c20 | 0x240 |
MultiByteToWideChar | 0x0 | 0x42502c | 0x26e24 | 0x25c24 | 0x31a |
GetStringTypeA | 0x0 | 0x425030 | 0x26e28 | 0x25c28 | 0x23d |
TransmitCommChar | 0x0 | 0x425034 | 0x26e2c | 0x25c2c | 0x438 |
GetProcAddress | 0x0 | 0x425038 | 0x26e30 | 0x25c30 | 0x220 |
GetStdHandle | 0x0 | 0x42503c | 0x26e34 | 0x25c34 | 0x23b |
GetFileAttributesW | 0x0 | 0x425040 | 0x26e38 | 0x25c38 | 0x1ce |
TerminateProcess | 0x0 | 0x425044 | 0x26e3c | 0x25c3c | 0x42d |
TerminateThread | 0x0 | 0x425048 | 0x26e40 | 0x25c40 | 0x42e |
GlobalAlloc | 0x0 | 0x42504c | 0x26e44 | 0x25c44 | 0x285 |
OpenProcess | 0x0 | 0x425050 | 0x26e48 | 0x25c48 | 0x333 |
GetModuleHandleW | 0x0 | 0x425054 | 0x26e4c | 0x25c4c | 0x1f9 |
GetCurrentProcess | 0x0 | 0x425058 | 0x26e50 | 0x25c50 | 0x1a9 |
GetDriveTypeW | 0x0 | 0x42505c | 0x26e54 | 0x25c54 | 0x1bb |
GetModuleHandleExA | 0x0 | 0x425060 | 0x26e58 | 0x25c58 | 0x1f7 |
LCMapStringW | 0x0 | 0x425064 | 0x26e5c | 0x25c5c | 0x2e3 |
ExitProcess | 0x0 | 0x425068 | 0x26e60 | 0x25c60 | 0x104 |
GetLocaleInfoA | 0x0 | 0x42506c | 0x26e64 | 0x25c64 | 0x1e8 |
HeapSize | 0x0 | 0x425070 | 0x26e68 | 0x25c68 | 0x2a6 |
IsValidCodePage | 0x0 | 0x425074 | 0x26e6c | 0x25c6c | 0x2db |
GetOEMCP | 0x0 | 0x425078 | 0x26e70 | 0x25c70 | 0x213 |
GetACP | 0x0 | 0x42507c | 0x26e74 | 0x25c74 | 0x152 |
GetCPInfo | 0x0 | 0x425080 | 0x26e78 | 0x25c78 | 0x15b |
GetLastError | 0x0 | 0x425084 | 0x26e7c | 0x25c7c | 0x1e6 |
HeapFree | 0x0 | 0x425088 | 0x26e80 | 0x25c80 | 0x2a1 |
HeapReAlloc | 0x0 | 0x42508c | 0x26e84 | 0x25c84 | 0x2a4 |
HeapAlloc | 0x0 | 0x425090 | 0x26e88 | 0x25c88 | 0x29d |
Sleep | 0x0 | 0x425094 | 0x26e8c | 0x25c8c | 0x421 |
GetCommandLineA | 0x0 | 0x425098 | 0x26e90 | 0x25c90 | 0x16f |
GetStartupInfoA | 0x0 | 0x42509c | 0x26e94 | 0x25c94 | 0x239 |
RtlUnwind | 0x0 | 0x4250a0 | 0x26e98 | 0x25c98 | 0x392 |
UnhandledExceptionFilter | 0x0 | 0x4250a4 | 0x26e9c | 0x25c9c | 0x43e |
SetUnhandledExceptionFilter | 0x0 | 0x4250a8 | 0x26ea0 | 0x25ca0 | 0x415 |
IsDebuggerPresent | 0x0 | 0x4250ac | 0x26ea4 | 0x25ca4 | 0x2d1 |
HeapCreate | 0x0 | 0x4250b0 | 0x26ea8 | 0x25ca8 | 0x29f |
VirtualFree | 0x0 | 0x4250b4 | 0x26eac | 0x25cac | 0x457 |
DeleteCriticalSection | 0x0 | 0x4250b8 | 0x26eb0 | 0x25cb0 | 0xbe |
LeaveCriticalSection | 0x0 | 0x4250bc | 0x26eb4 | 0x25cb4 | 0x2ef |
EnterCriticalSection | 0x0 | 0x4250c0 | 0x26eb8 | 0x25cb8 | 0xd9 |
VirtualAlloc | 0x0 | 0x4250c4 | 0x26ebc | 0x25cbc | 0x454 |
TlsGetValue | 0x0 | 0x4250c8 | 0x26ec0 | 0x25cc0 | 0x434 |
TlsAlloc | 0x0 | 0x4250cc | 0x26ec4 | 0x25cc4 | 0x432 |
TlsSetValue | 0x0 | 0x4250d0 | 0x26ec8 | 0x25cc8 | 0x435 |
TlsFree | 0x0 | 0x4250d4 | 0x26ecc | 0x25ccc | 0x433 |
InterlockedIncrement | 0x0 | 0x4250d8 | 0x26ed0 | 0x25cd0 | 0x2c0 |
SetLastError | 0x0 | 0x4250dc | 0x26ed4 | 0x25cd4 | 0x3ec |
GetCurrentThreadId | 0x0 | 0x4250e0 | 0x26ed8 | 0x25cd8 | 0x1ad |
InterlockedDecrement | 0x0 | 0x4250e4 | 0x26edc | 0x25cdc | 0x2bc |
WriteFile | 0x0 | 0x4250e8 | 0x26ee0 | 0x25ce0 | 0x48d |
GetModuleFileNameA | 0x0 | 0x4250ec | 0x26ee4 | 0x25ce4 | 0x1f4 |
LoadLibraryA | 0x0 | 0x4250f0 | 0x26ee8 | 0x25ce8 | 0x2f1 |
InitializeCriticalSectionAndSpinCount | 0x0 | 0x4250f4 | 0x26eec | 0x25cec | 0x2b5 |
FreeEnvironmentStringsA | 0x0 | 0x4250f8 | 0x26ef0 | 0x25cf0 | 0x14a |
GetEnvironmentStrings | 0x0 | 0x4250fc | 0x26ef4 | 0x25cf4 | 0x1bf |
FreeEnvironmentStringsW | 0x0 | 0x425100 | 0x26ef8 | 0x25cf8 | 0x14b |
WideCharToMultiByte | 0x0 | 0x425104 | 0x26efc | 0x25cfc | 0x47a |
GetEnvironmentStringsW | 0x0 | 0x425108 | 0x26f00 | 0x25d00 | 0x1c1 |
SetHandleCount | 0x0 | 0x42510c | 0x26f04 | 0x25d04 | 0x3e8 |
GetFileType | 0x0 | 0x425110 | 0x26f08 | 0x25d08 | 0x1d7 |
QueryPerformanceCounter | 0x0 | 0x425114 | 0x26f0c | 0x25d0c | 0x354 |
GetTickCount | 0x0 | 0x425118 | 0x26f10 | 0x25d10 | 0x266 |
GetCurrentProcessId | 0x0 | 0x42511c | 0x26f14 | 0x25d14 | 0x1aa |
GetSystemTimeAsFileTime | 0x0 | 0x425120 | 0x26f18 | 0x25d18 | 0x24f |
USER32.dll (6)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShowScrollBar | 0x0 | 0x425138 | 0x26f30 | 0x25d30 | 0x2b5 |
LoadImageA | 0x0 | 0x42513c | 0x26f34 | 0x25d34 | 0x1d8 |
EndPaint | 0x0 | 0x425140 | 0x26f38 | 0x25d38 | 0xd5 |
IsIconic | 0x0 | 0x425144 | 0x26f3c | 0x25d3c | 0x1bd |
GetFocus | 0x0 | 0x425148 | 0x26f40 | 0x25d40 | 0x124 |
SetPropA | 0x0 | 0x42514c | 0x26f44 | 0x25d44 | 0x28f |
GDI32.dll (4)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
GetEnhMetaFileHeader | 0x0 | 0x425000 | 0x26df8 | 0x25bf8 | 0x1be |
GetMapMode | 0x0 | 0x425004 | 0x26dfc | 0x25bfc | 0x1d7 |
SetMapperFlags | 0x0 | 0x425008 | 0x26e00 | 0x25c00 | 0x27c |
AnimatePalette | 0x0 | 0x42500c | 0x26e04 | 0x25c04 | 0x9 |
SHELL32.dll (3)
»
API Name | Ordinal | IAT Address | Thunk RVA | Thunk Offset | Hint |
---|---|---|---|---|---|
ShellExecuteW | 0x0 | 0x425128 | 0x26f20 | 0x25d20 | 0x118 |
Shell_NotifyIconA | 0x0 | 0x42512c | 0x26f24 | 0x25d24 | 0x122 |
ShellExecuteExA | 0x0 | 0x425130 | 0x26f28 | 0x25d28 | 0x116 |
Exports (2)
»
Api name | EAT Address | Ordinal |
---|---|---|
MyFunc31 | 0x1280 | 0x1 |
MyFunc32 | 0x1290 | 0x2 |
Memory Dumps (1)
»
Name | Process ID | Start VA | End VA | Dump Reason | PE Rebuilds | Bitness | Entry Points | AV | YARA | Actions |
---|---|---|---|---|---|---|---|---|---|---|
rruzcj.exe | 1 | 0x00400000 | 0x0049EFFF | Relevant Image | - | 32-bit | - |
![]() |
![]() |
...
|
Local AV Matches (1)
»
Threat Name | Severity |
---|---|
Gen:Variant.Ulise.37281 |
Malicious
|
C:\Boot\BOOTSTAT.DAT.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\BOOTSECT.BAK.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfoPathMUI.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0054-0409-1000-0000000FF1CE}-C\VisioMUI.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\OneNoteMUI.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\GrooveMUI.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-00A1-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-00B4-0409-1000-0000000FF1CE}-C\ProjectMUI.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-00BA-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUISet.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\setup.chm.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\branding.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\branding.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Access.en-us\AccessMUI.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\OfficeMUI.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Office32WW.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0115-0409-1000-0000000FF1CE}-C\pss10r.chm.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0117-0409-1000-0000000FF1CE}-C\AccessMUISet.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Office32WW.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\PrjProrWW.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{91140000-003B-0000-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\ProPlusrWW.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\VisiorWW.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.EPS.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{91140000-0011-0000-1000-0000000FF1CE}-C\Setup.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.JPG.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.PNG.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{91140000-0057-0000-1000-0000000FF1CE}-C\Office32WW.xml.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\GRPHFLT\MS.GIF.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\AccessMUI.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\AccessMUISet.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Access.en-us\SETUP.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\ExcelMUI.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Excel.en-us\SETUP.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Groove.en-us\GrooveMUI.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\README.HTM.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Groove.en-us\SETUP.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\BRANDING.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.msi.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\InfoPathMUI.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUI.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OfficeMUISet.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSCONFIG.CHM.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\InfoPath.en-us\SETUP.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\OCT.CHM.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\SETUP.CHM.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSS10R.CHM.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\SETUP.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\SETUP.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\OneNoteMUI.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\OneNote.en-us\SETUP.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.WW\Office32WW.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office.en-us\PSS10O.CHM.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Office32.en-us\Office32MUI.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.msi.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proofing.msi.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\PowerPointMUI.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PRJPROR\PrjProrWW.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PRJPROR\SETUP.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Project.en-us\ProjectMUI.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\OutlookMUI.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.en\Proof.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.es\Proof.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\Office32MUI.msi.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PowerPoint.en-us\SETUP.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Binary |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.msi.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Outlook.en-us\SETUP.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proof.fr\Proof.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Project.en-us\SETUP.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Binary |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proofing.en-us\Proofing.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Publisher.en-us\PublisherMUI.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Publisher.en-us\SETUP.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PROPLUSR\SETUP.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Proofing.en-us\SETUP.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\PROPLUSR\ProPlusrWW.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\VisiorWW.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Word.en-us\SETUP.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\VISIOR\SETUP.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Word.en-us\WordMUI.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\DATES.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\PHONE.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\STOCKS.DAT.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\1033\MCABOUT.HTM.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\TIME.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\BASMLA.XSL.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Office Setup Controller\Visio.en-us\VisioMUI.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\LISTS\1033\STOCKS.XML.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\Program Files\Common Files\Microsoft Shared\Smart Tag\METCONV.TXT.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Malicious
|
...
|
»
YARA Matches (1)
»
Rule Name | Rule Description | Classification | Severity | Actions |
---|---|---|---|---|
DharmaEncryptedFile | File encrypted by Dharma Ransomware | Ransomware |
Malicious
|
...
|
C:\$Recycle.Bin\S-1-5-21-3388679973-3930757225-3770151564-1000\desktop.ini.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelLR.cab.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0016-0409-1000-0000000FF1CE}-C\ExcelMUI.msi.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PowerPointMUI.msi.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0018-0409-1000-0000000FF1CE}-C\PptLR.cab.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PublisherMUI.msi.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0019-0409-1000-0000000FF1CE}-C\PubLR.cab.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlkLR.cab.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001A-0409-1000-0000000FF1CE}-C\OutlookMUI.msi.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordLR.cab.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.en\Proof.cab.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-001B-0409-1000-0000000FF1CE}-C\WordMUI.msi.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Unknown
|
...
|
»
C:\Program Files\Common Files\Microsoft Shared\OFFICE14\1033\ADO210.CHM.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.es\Proof.cab.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-002C-0409-1000-0000000FF1CE}-C\Proof.fr\Proof.cab.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0043-0409-1000-0000000FF1CE}-C\OWOW32LR.cab.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Unknown
|
...
|
»
C:\MSOCache\All Users\{90140000-0044-0409-1000-0000000FF1CE}-C\InfLR.cab.id-9C354B42.[restdoc@protonmail.com].zoh | Dropped File | Stream |
Unknown
|
...
|
»